Cybersecurity — 2026-05-15

Android Adds Intrusion Logging to Help Detect Sophisticated Spyware

BLUFIntrusion Logging sets a meaningful precedent for designing forensic capability into commercial devices, but its real-world impact stays marginal until Google extends it beyond opt-in Pixel users.

Google on May 12 began rolling out Intrusion Logging, an opt-in feature within Android Advanced Protection Mode that records device unlocking, ADB connections, app installations and removals, and network activity as encrypted logs uploaded daily to the user's Google account and inaccessible to Google itself. Amnesty International's Security Lab, which served as a design partner throughout the feature's development, described it in a concurrent technical briefing as the first time a major device vendor has released a feature specifically to enable forensic detection of advanced digital threats. The rollout is currently limited to Pixel devices running the Android 16 December update linked to a Google account. Amnesty simultaneously released updates to its AndroidQF and Mobile Verification Toolkit to support automatic collection and analysis of the logs.

Analysis
The encrypted-log architecture shifts evidence-preservation advantage toward defenders by surviving device seizure and operator-initiated trace deletion, a gap Android's short-lived developer buffers left open for years. The Amnesty-Google design partnership, absent independent corroboration, offers a replicable model for embedding civil society forensic requirements at the design stage rather than retrofitting after deployment. Coverage remains narrow: opt-in, Android 16, and Pixel hardware hold a small fraction of global Android installations, leaving operators targeting the broader population with no change in forensic exposure until the feature expands. Root access defeats log preservation even on covered devices. The mandatory cloud upload creates a legal-compulsion surface governments could exploit even where Google cannot decrypt the content, a risk the encryption architecture does not eliminate.
1 sources
  1. Android Intrusion Logging for Spyware Detection - Google Security Blog

View in full brief →

UNCLASSIFIED // OPEN SOURCE