Automated Analysis of Privacy Requirements for Mobile Apps
Sebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar, Bin Liu, Florian Schaub, Shomir Wilson, Norman M. Sadeh, Steven M. Bellovin, Joel R. Reidenberg
Abstract
Mobile apps have to satisfy various privacy requirements. Notably, app publishers are often obligated to provide a privacy policy and notify users of their apps' privacy practices. But how can a user tell whether an app behaves as its policy promises? In this study we introduce a scalable system to help analyze and predict Android apps' compliance with privacy requirements. We discuss how we customized our system in a collaboration with the California Office of the Attorney General. Beyond its use by regulators and activists our system is also meant to assist app publishers and app store owners in their internal assessments of privacy requirement compliance. Our analysis of 17,991 free Android apps shows the viability of combining machine learning-based privacy policy analysis with static code analysis of apps. Results suggest that 71% of apps that lack a privacy policy should have one. Also, for 9,050 apps that have a policy, we find many instances of potential inconsistencies between what the app policy seems to state and what the code of the app appears to do. In particular, as many as 41% of these apps could be collecting location information and 17% could be sharing such with third parties without disclosing so in their policies. Overall, each app exhibits a mean of 1.83 potential privacy requirement inconsistencies. I. INTRODUCTION "We do not ask for, track, or access any location-specific information [...]." This is what Snapchat's privacy policy stated. 1 However, its Android app transmitted Wi-Fi-and cell-based location data from users' devices to analytics service providers. These discrepancies remained undetected before they eventually surfaced when a researcher examined • Part of this work was conducted while Sebastian Zimmeck was a PhD student at
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers47
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
- Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy TextVinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng et al.WWW 2020 · 93 citations
Builds on2
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio et al.NDSS 2016 · 119 citations
- Free for All! Assessing User Data Exposure to Advertising Libraries on AndroidSoteris Demetriou, Whitney Merrill, Wei Yang, Aston Zhang et al.NDSS 2016 · 95 citations
Related papers
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi et al.CCS 2021 · 41 citations
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
- Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK IntegrationsZhaojie Hu, Xueqiang WangS&P 2026
- PrivacyFlash Pro: Automating Privacy Policy Generation for Mobile AppsSebastian Zimmeck, Rafael Goldstein, David BarakaNDSS 2021
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
