The Cost of Convenience: Identifying, Analyzing, and Mitigating Predatory Loan Applications on Android
Olawale Amos Akanji, Manuel Egele, and Gianluca Stringhini

TL;DR
This study measures and analyzes the compliance of digital loan apps across several countries, revealing widespread violations of regulations and policies, and demonstrating the need for improved enforcement and technical safeguards to protect users.
Contribution
Introduces a novel cross-country measurement methodology combining policy translation, static, and dynamic analysis to assess loan app compliance at scale.
Findings
Widespread non-compliance with regulations among approved apps
Apps transmit sensitive data before user consent
Google removed over 90 problematic apps after disclosures
Abstract
Digital lending applications, commonly referred to as loan apps, have become a primary channel for microcredit in emerging markets. However, many of these apps demand excessive permissions and misuse sensitive user data for coercive debt-recovery practices, including harassment, blackmail, and public shaming that affect both borrowers and their contacts. This paper presents the first cross-country measurement of loan app compliance against both national regulations and Google's Financial Services Policy. We analyze 434 apps drawn from official registries and app markets from Indonesia, Kenya, Nigeria, Pakistan, and the Philippines. To operationalize policy requirements at scale, we translate policy text into testable permission checks using LLM-assisted policy-to-permission mapping and combine this with static and dynamic analyses of loan apps' code and runtime behavior. Our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsICT in Developing Communities · Advanced Malware Detection Techniques · Mobile Health and mHealth Applications
