PrivacyFlash Pro: Automating Privacy Policy Generation for Mobile Apps
Sebastian Zimmeck, Rafael Goldstein, David Baraka
摘要
—Various privacy laws require mobile apps to have privacy policies. Questionnaire-based policy generators are intended to help developers with the task of policy creation. However, generated policies depend on the generators’ designs as well as developers’ abilities to correctly answer privacy questions on their apps. In this study we show that policies generated with popular policy generators are often not reflective of apps’ privacy practices. We believe that policy generation can be improved by supplementing the questionnaire-based approach with code analysis. We design and implement PrivacyFlash Pro, a privacy policy generator for iOS apps that leverages static analysis. PrivacyFlash Pro identifies code signatures — composed of Plist permission strings, framework imports, class instantiations, authorization methods, and other evidence — that are mapped to privacy practices expressed in privacy policies. Resources from package managers are used to identify libraries. We tested PrivacyFlash Pro in a usability study with 40 iOS app developers and received promising results both in terms of reliably identifying apps’ privacy practices as well as on its usability. We measured an F-1 score of 0.95 for identifying permission uses. 24 of 40 developers rated PrivacyFlash Pro with at least 9 points on a scale of 0 to 10 for a Net Promoter Score of 42.5. The mean System Usability Score of 83.4 is close to excellent. We provide PrivacyFlash Pro as an open source project to the iOS developer community. In principle, our approach is platform-agnostic and adaptable to the Android and web platforms as well. To increase privacy transparency and reduce compliance issues we make the case for privacy policies as software development artifacts. Privacy policy creation should become a native extension of the software development process and adhere to the mental model of software developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- A NEW HOPE: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated GenerationShidong Pan, Zhen Tao, Thong Hoang, Dawen Zhang 等USENIX Security 2024 · 被引用 24 次
- Demystifying Privacy Policy of Third-Party Libraries in Mobile AppsKaifa Zhao, Xian Zhan, Le Yu, Shiyao Zhou 等ICSE 2023 · 被引用 22 次
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing 等USENIX Security 2024 · 被引用 18 次
- Matcha: An IDE Plugin for Creating Accurate Privacy Nutrition LabelsTianshi Li, Lorrie Faith Cranor, Yuvraj Agarwal, Jason I. HongUbiComp 2024 · 被引用 17 次
- Are they Toeing the Line? Diagnosing Privacy Compliance Violations among Browser ExtensionsYuxi Ling, Kailong Wang, Guangdong Bai, Haoyu Wang 等ASE 2022 · 被引用 17 次
它引用的顶会 Paper11
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub 等CCS 2019 · 被引用 429 次
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
相关 Paper
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar 等NDSS 2017 · 被引用 255 次
- Honeysuckle: Annotation-Guided Code Generation of In-App Privacy NoticesTianshi Li, Elijah B. Neundorfer, Yuvraj Agarwal, Jason I. HongUbiComp 2021 · 被引用 18 次
- Measuring Compliance Implications of Third-party Libraries' Privacy Label Disclosure GuidelinesYue Xiao, Chaoqi Zhang, Yue Qin, Fares Fahad S. Alharbi 等CCS 2024 · 被引用 3 次
- Assessing Privacy Compliance Awareness and Practices Among Mobile Third-party Library DevelopersFares F. Alharbi, Ece Gumusel, Luyi Xing, Xiaojing LiaoCCS 2026
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong 等USENIX Security 2024 · 被引用 3 次
