Stalkerware Data Protection via Safety Plan Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting data from stalkerware do not adequately address the unique safety needs of users in different situations, particularly those living with an abuser, as they may pose physical danger when attempting to remove stalkerware or require customized approaches to mitigate its effects without alerting the abuser.
Innovation Solution
A computer-implemented method that identifies stalkerware on a device, determines its transmission of private data to unauthorized devices, and allows users to select from customized safety plan options such as deleting, filtering, or spoofing data, based on their specific situation, to protect their data and safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If automated removal of stalkerware is implemented, then data protection effectiveness is improved, but user physical safety deteriorates when abuser is nearby
Solution Approach 1:
The system dynamically adjusts the stalkerware removal process based on real-time assessment of user safety conditions. When the abuser is determined to be nearby or posing physical threat, the system transitions from automated removal to controlled mitigation modes, allowing users to maintain stalkerware presence while protecting data through filtering and spoofing techniques.
Solution Approach 2:
The system changes the operational parameters of stalkerware interaction based on threat level. Instead of binary remove/keep decision, it implements gradient response levels: full removal when safe, partial removal with filtering when moderate risk, and spoofing mode when high risk. This transforms the protection mechanism from static to adaptive based on contextual parameters.
2Loss of information
If stalkerware is completely removed from device, then data privacy is improved, but user safety deteriorates when living with abuser
Solution Approach 1:
The system introduces intermediary mechanisms between the user and stalkerware. Instead of direct removal or direct access, it implements data filtering layers and spoofing intermediaries that intercept and modify data flows. These intermediaries allow stalkerware to remain installed while preventing actual data exfiltration to the abuser.
Solution Approach 2:
The system converts the harmful presence of stalkerware into a beneficial protective tool. By allowing stalkerware to remain installed under controlled conditions, it creates a decoy system that maintains the appearance of normal operation while actually protecting user data through filtering and spoofing. The harmful element becomes part of the protection strategy.
3Object-affected harmful factors
If customized safety plans are implemented, then user safety is improved, but system complexity increases
Solution Approach 1:
The system segments the safety plan into distinct modular components: assessment module, filtering module, spoofing module, and emergency contact module. Each component operates independently and can be activated based on specific conditions. This modular architecture reduces complexity by allowing selective activation of only necessary functions rather than requiring all features to be simultaneously managed.
Solution Approach 2:
The system performs preliminary safety assessment and plan generation before actual threats materialize. During setup, users complete safety questionnaires and define preferences in advance. When threats are detected, the pre-configured safety plans are automatically activated, eliminating the need for complex real-time decision-making and reducing operational complexity during critical moments.
4Object-affected harmful factors
If data filtering and spoofing are used instead of removal, then user safety is improved, but data protection effectiveness may deteriorate
Solution Approach 1:
The system applies partial data protection by filtering only the most critical data types (location, communications, financial information) while allowing less sensitive data to pass through. This selective filtering approach balances safety requirements with data protection effectiveness, protecting against immediate physical threats while maintaining normal device functionality and user awareness of data exposure.
Data Source
AI summary
A computer-implemented method for protecting data on devices may include (i) identifying a device that is operated by a user and that comprises private data pertaining to the user, (ii) determining that stalkerware on the device is sending the private data to an unauthorized device not operated by the user, (iii) requesting, in response to determining that the stalkerware is sending the private data to the unauthorized device, that the user select at least one safety plan step from a set of safety plan options, and (iv) modifying, at least in part based on the safety plan step selected by the user, outgoing data sent by the stalkerware to the unauthorized device. Various other methods, systems, and computer-readable media are also disclosed.


