Ecosystem-Driven Privacy Exposure in Mobile Gaming Apps: A Configuration-Aware Empirical Analysis
This study addresses the limitations of permission-based privacy risk assessments in accurately capturing the actual privacy exposure of mobile games within complex third-party SDK ecosystems. To overcome the constraints of traditional permission-centric paradigms, the authors propose a configuration-aware static analysis framework that systematically evaluates privacy risks by integrating manifest configurations, exported components, and the structural characteristics of SDK ecosystems. Through SDK categorization and statistical analyses—including Spearman correlation, Mann-Whitney U tests, and chi-squared tests—the study reveals that children-targeted games exhibit privacy exposure levels comparable to those of general-audience games. Furthermore, it demonstrates that advertising SDKs and more extensive, diverse SDK ecosystems significantly amplify privacy leakage risks, underscoring the dominant role of ecosystem-level design in shaping privacy exposure.