English

Understanding Mobile App Reviews to Guide Misuse Audits

Cryptography and Security 2024-11-11 v3

Abstract

Problem: We address the challenge in responsible computing where an exploitable mobile app is misused by one app user (an abuser) against another user or bystander (victim). We introduce the idea of a misuse audit of apps as a way of determining if they are exploitable without access to their implementation. Method: We leverage app reviews to identify exploitable apps and their functionalities that enable misuse. First, we build a computational model to identify alarming reviews (which report misuse). Second, using the model, we identify exploitable apps and their functionalities. Third, we validate them through manual inspection of reviews. Findings: Stories by abusers and victims mostly focus on past misuses, whereas stories by third parties mostly identify stories indicating the potential for misuse. Surprisingly, positive reviews by abusers, which exhibit language with high dominance, also reveal misuses. In total, we confirmed 156 exploitable apps facilitating the misuse. Based on our qualitative analysis, we found exploitable apps exhibiting four types of exploitable functionalities. Implications: Our method can help identify exploitable apps and their functionalities, facilitating misuse audits of a large pool of apps.

Keywords

Cite

@article{arxiv.2303.10795,
  title  = {Understanding Mobile App Reviews to Guide Misuse Audits},
  author = {Vaibhav Garg and Hui Guo and Nirav Ajmeri and Saikath Bhattacharya and Munindar P. Singh},
  journal= {arXiv preprint arXiv:2303.10795},
  year   = {2024}
}

Comments

Accepted at Communications of the ACM (CACM)

R2 v1 2026-06-28T09:23:14.997Z