Android 17's expanded Advanced Protection program adds six new defenses for people at elevated risk of targeted spyware. The most notable is Intrusion Logging, an optional feature that records security and network events and stores them encrypted on Google's servers, where the company says it cannot read them. Users can download and decrypt the logs and share them with security experts to investigate a suspected compromise.
Because the logs are synced off-device, they can survive an attacker wiping the phone. They include network activity from Chrome's Incognito tabs, revealing visited sites but not specific pages. Logs are kept on a rolling 12-month schedule and cannot be manually deleted by either the user or Google, so anyone who downloads a copy is responsible for protecting it.
The other additions are more defensive in nature. USB Protection blocks new data connections while the phone is locked, while Advanced Protection restricts AccessibilityService access to verified accessibility tools and disables WebGPU in Chrome. Failed Authentication Lock, previously a theft-protection feature, is now part of the program, and a new View Supporting Apps page shows which installed apps check whether Advanced Protection is enabled.
Google developed the features with civil liberties and press freedom organizations. Amnesty International's Security Lab head Donncha Ó Cearbhaill called Intrusion Logging a potential game-changer for spyware accountability, saying it is the first time a consumer mobile platform has offered purpose-built forensic logging for detecting targeted attacks.