Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA App
Fuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng, Yanjun Zhang, Guangdong Bai
Abstract
Virtual personal assistants (VPA) services encompass a large number of third-party applications (or apps) to enrich their functionalities. These apps have been well examined to scrutinize their data collection behaviors against their declared privacy policies. Nonetheless, it is often overlooked that most users tend to ignore privacy policies at the installation time. Dishonest developers thus can exploit this situation by embedding excessive declarations to cover their data collection behaviors during compliance auditing. In this work, we present Pico, a privacy inconsistency detector, which checks the VPA app's privacy compliance by analyzing (in)consistency between data requested and data essential for its functionality. Pico understands the app's functionality topics from its publicly available textual data, and leverages advanced GPTbased language models to address domain-specific challenges. Based on the counterparts with similar functionality, suspicious data collection can be detected through the lens of anomaly detection. We apply Pico to understand the status quo of data-functionality compliance among all 65,195 skills in the Alexa app store. Our study reveals that 21.7% of the analyzed skills exhibit suspicious data collection, including Top 10 popular Alexa skills that pose threats to 54,116 users. These findings should raise an alert to both developers and users, in the compliance with the purpose limitation principle in data regulations. CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b3ee75ff-602f-4bab-b555-1700e33b8636Cited by top-tier papers2
- Investigating Documented Privacy Changes in Android OSChuan Yan, Mark Huasong Meng, Fuman Xie, Guangdong BaiFSE 2024 · 6 citations
- SKILLPoV: Towards Accessible and Effective Privacy Notice for Amazon Alexa SkillsJingwen Yan, Song Liao, Mohammed Aldeen, Luyi Xing et al.NDSS 2025
Builds on10
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi et al.CCS 2021 · 41 citations
- Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsFuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li et al.ASE 2022 · 31 citations
- Measuring Alexa Skill Privacy Practices across Three YearsJide S. Edu, Xavier Ferrer Aran, Jose M. Such, Guillermo Suarez-TangilWWW 2022 · 29 citations
- EDEFuzz: A Web API Fuzzer for Excessive Data ExposuresLianglu Pan, Shaanan Cohney, Toby Murray, Van-Thuan PhamICSE 2024 · 11 citations
Related papers
- SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the WildJeffrey Young, Song Liao, Long Cheng, Hongxin Hu et al.USENIX Security 2022
- Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesSong Liao, Mohammed Aldeen, Jingwen Yan, Long Cheng et al.WWW 2024 · 9 citations
- SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseSong Liao, Long Cheng, Haipeng Cai, Linke Guo et al.CCS 2023 · 7 citations
- Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa SkillsAafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam DasS&P 2025
- Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsLong Cheng, Christin Wilson, Song Liao, Jeffrey Young et al.CCS 2020 · 58 citations
