A Large Scale Study of User Behavior, Expectations and Engagement with Android Permissions
Weicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie, Nina Taft, Lisa M. Austin
摘要
We conduct a global study on the behaviors, expectations and engagement of 1,719 participants across 10 countries and regions towards Android application permissions. Participants were recruited using mobile advertising and used an application we designed for 30 days. Our app samples user behaviors (decisions made), rationales (via in-situ surveys), expectations, and attitudes, as well as some app provided explanations. We study the grant and deny decisions our users make, and build mixed effect logistic regression models to illustrate the many factors that influence this decision making. Among several interesting findings, we observed that users facing an unexpected permission request are more than twice as likely to deny it compared to a user who expects it, and that permission requests accompanied by an explanation have a deny rate that is roughly half the deny rate of app permission requests without explanations. These findings remain true even when controlling for other factors. To the best of our knowledge, this may be the first study of actual privacy behavior (not stated behavior) for Android apps, with users using their own devices, across multiple continents.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsMohammad Tahaei, Ruba Abu-Salma, Awais RashidCHI 2023 · 被引用 36 次
- How WEIRD is Usable Privacy and Security Research?Ayako Akiyama Hasegawa, Daisuke Inoue, Mitsuaki AkiyamaUSENIX Security 2024 · 被引用 26 次
- A Decade of Privacy-Relevant Android App Reviews: Large Scale TrendsOmer Akgul, Sai Teja Peddinti, Nina Taft, Michelle L. Mazurek 等USENIX Security 2024 · 被引用 14 次
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in WearablesDoguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh 等S&P 2024 · 被引用 12 次
- Action Required: A Mixed-Methods Study of Security Practices in GitHub ActionsYusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai 等NDSS 2026 · 被引用 3 次
它引用的顶会 Paper2
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App VersionsJingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao 等NDSS 2018 · 被引用 91 次
相关 Paper
- Explanation Beats Context: The Effect of Timing & Rationales on Users' Runtime Permission DecisionsYusra Elbitar, Michael Schilling, Trung Tin Nguyen, Michael Backes 等USENIX Security 2021 · 被引用 25 次
- Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission ModelBingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu 等USENIX Security 2021 · 被引用 45 次
- The Power of Words: A Comprehensive Analysis of Rationales and Their Effects on Users' Permission DecisionsYusra Elbitar, Alexander Hart, Sven BugielNDSS 2025
- From Discovery to Decisions: Archetypal Journeys of Mobile App Users and Their Implications on PrivacyH. T. M. A. Riyadh, Divyanshu Bhardwaj, Maria Victoria Hellenthal, Alexander Hart 等CHI 2026 · 被引用 1 次
- Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design PatternsYusra Elbitar, Soheil Khodayari, Marian Harbach, Gianluca De Stefano 等CHI 2025 · 被引用 3 次
