Consistency Analysis of Data-Usage Purposes in Mobile Apps
Duc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi, Junbum Shin
Abstract
While privacy laws and regulations require apps and services to disclose the purposes of their data collection to the users (i.e., why do they collect my data?), the data usage in an app's actual behavior does not always comply with the purposes stated in its privacy policy. Automated techniques have been proposed to analyze apps' privacy policies and their execution behavior, but they often overlooked the purposes of the apps' data collection, use and sharing. To mitigate this oversight, we propose PurPliance, an automated system that detects the inconsistencies between the data-usage purposes stated in a natural language privacy policy and those of the actual execution behavior of an Android app. PurPliance analyzes the predicate-argument structure of policy sentences and classifies the extracted purpose clauses into a taxonomy of data purposes. Purposes of actual data usage are inferred from network data traffic. We propose a formal model to represent and verify the data usage purposes in the extracted privacy statements and data flows to detect policy contradictions in a privacy policy and flow-to-policy inconsistencies between network data flows and privacy statements. Our evaluation results of end-to-end contradiction detection have shown PurPliance to improve detection precision from 19% to 95% and recall from 10% to 50% compared to a state-of-the-art method. Our analysis of 23.1k Android apps has also shown PurPliance to detect contradictions in 18.14% of privacy policies and flow-to-policy inconsistencies in 69.66% of apps, indicating the prevalence of inconsistencies of data practices in mobile apps.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 835cade5-80aa-47fd-8461-46faa6f1ed07Cited by top-tier papers29
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data PlaneZhaowei Tan, Jinghao Zhao, Boyan Ding, Songwu LuNSDI 2023 · 13 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
Builds on5
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- FlowCog: Context-aware Semantics Extraction and Analysis of Information Flow Leaks in Android AppsXiang Pan, Yinzhi Cao, Xuechao Du, Boyuan He et al.USENIX Security 2018 · 39 citations
- TextExerciser: Feedback-driven Text Input Exercising for Android ApplicationsYuyu He, Lei Zhang, Zhemin Yang, Yinzhi Cao et al.S&P 2020 · 30 citations
- Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheckBenjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck et al.USENIX Security 2020
Related papers
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- Giving without Notifying: Assessing Compliance of Data Transmission in Android AppsMing Fan, Jifei Shi, Yin Wang, Le Yu et al.ASE 2024 · 4 citations
- PoliCond: Condition-Aware Ontology-Driven LLMs for Privacy Policy Contradiction AnalysisYalin Feng, Yifei Lu, Minxue PanASE 2025
