2015/02/11 by Yan Michalevsky, Gabi Nakibly, Michalevsky, Yan +7 · 3 voices · 95 citations
Computer Science · Engineering · Social Sciences · #Aggregate (composite) #Android (operating system) #Computer science #Computer security #GSM services #Green IT and Sustainability #Human Mobility and Location-Based Analysis #Location tracking #Mobile Crowdsensing and Crowdsourcing #Mobile device #Mobile phone #Mobile phone tracking #Mobile technology #Operating system #Permission #Phone #Power (physics) #Power consumption #Real-time computing #Telecommunications #World Wide Web #cs.CR
paper · pdf · doi:10.48550/arxiv.1502.03182
published in arXiv (Cornell University), 785-800 (Cornell University) · Usenix Security 2015
openalex publication_date 2015/02/11 · arxiv created 2015/08/18 · arxiv updated 2015/08/19 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Modern mobile platforms like Android enable applications to read aggregate power usage on the phone. This information is considered harmless and reading it requires no user permission or notification. We show that by simply reading the phone's aggregate power consumption over a period of a few minutes an application can learn information about the user's location. Aggregate phone power consumption data is extremely noisy due to the multitude of components and applications that simultaneously consume power. Nevertheless, by using machine learning algorithms we are able to successfully infer the phone's location. We discuss several ways in which this privacy leak can be remedied.