Purdue research earns Andreas Pfitzmann Best Student Paper Award at Privacy Enhancing Technologies Symposium (PETS)
09-22-2026

Joshua Shinkle, undergraduate student in the Department of Computer Science
Mobile apps marketed specifically to military-affiliated users can create privacy and security risks that extend beyond individual users, according to research from Purdue University, the U.S. Military Academy at West Point and Florida International University.
The research received the Andreas Pfitzmann Best Student Paper Award at the Privacy Enhancing Technologies Symposium (PETS), a leading conference in privacy research. The award recognizes research judged to be both scientifically rigorous and significant to the privacy field.
The study examined the data practices and third-party software used by mobile apps marketed to military-affiliated users and surveyed 103 military-affiliated participants about their perceptions of privacy and security.
Researchers found that 64% of the military-marketed apps studied contained at least one third-party software library, primarily for analytics and advertising. These libraries can introduce additional code and data-sharing relationships that may not be apparent to users.
The researchers also found that 15 apps included Chinese third-party libraries, including 12 that incorporated Huawei Mobile Services Core. The finding is notable because the apps were marketed toward U.S. military-affiliated users and the DoD labeled the People's Republic of China and three other countries as "adversaries" in their 2023 Cyber Strategy Summary.
In one example, researchers found Huawei code in Hots&Cots, a military-marketed app, through OneSignal, a third-party library used for push notifications. The app’s developer was unaware the Huawei code was included. Following responsible disclosure from the research team, the developer re-engineered the notification system to remove the code.
The researchers said the case demonstrates how software supply-chain risks can be difficult for developers to identify, even when developers are acting in good faith.
“Supply-chain risks can be real and invisible even to well-intentioned developers,” the researchers said. “But they can also be fixable once those risks are surfaced.”
Users report broader security concerns
The user study revealed a gap between military-affiliated users’ expectations and the technical practices researchers observed.
83.5% of participants were already using at least one military-marketed app whose data practices they considered inappropriate, with participants using an average of more than three such apps.
Participants were also significantly less comfortable when their data was collected by a foreign or third party than when it was collected by a military-marketed app. Researchers said the findings suggest that an app’s military-oriented branding may create a level of trust that is not always supported by its underlying technology.
Participants identified risks extending beyond individual privacy. Among those surveyed:
- 91% identified personal safety as a potential risk.
- 77% identified operational and unit security.
- 67% identified national security.
The researchers said the findings demonstrate that mobile app data can have particularly serious consequences for military-affiliated users.
The study was motivated in part by the 2018 Strava incident, when a public heatmap of user activity revealed patterns that could expose the locations and patrol routes of service members at forward operating bases.
“When a fitness app leaks a civilian’s location, it’s a privacy concern, but when it leaks a service member’s location, it can threaten the physical safety of an entire unit,” the researchers said. “It’s the same data practice, but radically different stakes.”
Researchers identify potential protections
The team also proposed seven potential mitigations based on the technical findings and asked participants to rate their effectiveness.
The four highest-rated measures were an in-phone warning when an app contains foreign or unknown third-party code; federal restrictions on data brokers buying and selling military-affiliated data; federal requirements for independent audits of privacy disclosures; and stricter restrictions on foreign code in military-marketed apps.
The findings indicate that military-affiliated users favor systemic protections rather than relying solely on individuals to identify and manage privacy and security risks.
The research brought together expertise from Purdue, West Point and Florida International University. An active-duty military co-author provided insight into the military environment and how service members understand and interact with technology, while researchers at Purdue and Florida International University contributed expertise in mobile app analysis and user studies.
The research was conducted through Purdue’s PurSec Lab.
Next steps
The researchers proposed future work consisting of investigating how aware mobile app developers are of the third-party code incorporated into their applications and the development of tools to help developers better understand their software supply chains.
One potential direction is a software bill of materials (SBOM) for mobile apps, which could provide developers with a clearer record of the components and third-party code included in their applications.
The researchers hope the work will lead to greater transparency and stronger privacy and security protections for military-affiliated users while helping developers identify risks within their software supply chains.
About the Department of Computer Science at Purdue University
Founded in 1962, the Department of Computer Science was created to be an innovative base of knowledge in the emerging field of computing as the first degree-awarding program in the United States. The department continues to advance the computer science industry through research. U.S. News & World Report ranks the department No. 16 and No. 15 overall in undergraduate and graduate computer science, respectively. Graduates of the program are able to solve complex and challenging problems in many fields. Our consistent success in an ever-changing landscape is reflected in the record undergraduate enrollment, increased faculty hiring, innovative research projects, and the creation of new academic programs. Learn more at cs.purdue.edu.
Example
example content