Consistency Analysis of Data-Usage Purposes in Mobile Apps
Duc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi, Junbum Shin
摘要
While privacy laws and regulations require apps and services to disclose the purposes of their data collection to the users (i.e., why do they collect my data?), the data usage in an app's actual behavior does not always comply with the purposes stated in its privacy policy. Automated techniques have been proposed to analyze apps' privacy policies and their execution behavior, but they often overlooked the purposes of the apps' data collection, use and sharing. To mitigate this oversight, we propose PurPliance, an automated system that detects the inconsistencies between the data-usage purposes stated in a natural language privacy policy and those of the actual execution behavior of an Android app. PurPliance analyzes the predicate-argument structure of policy sentences and classifies the extracted purpose clauses into a taxonomy of data purposes. Purposes of actual data usage are inferred from network data traffic. We propose a formal model to represent and verify the data usage purposes in the extracted privacy statements and data flows to detect policy contradictions in a privacy policy and flow-to-policy inconsistencies between network data flows and privacy statements. Our evaluation results of end-to-end contradiction detection have shown PurPliance to improve detection precision from 19% to 95% and recall from 10% to 50% compared to a state-of-the-art method. Our analysis of 23.1k Android apps has also shown PurPliance to detect contradictions in 18.14% of privacy policies and flow-to-policy inconsistencies in 69.66% of apps, indicating the prevalence of inconsistencies of data practices in mobile apps.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing 等USENIX Security 2024 · 被引用 18 次
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis 等USENIX Security 2024 · 被引用 13 次
- CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data PlaneZhaowei Tan, Jinghao Zhao, Boyan Ding, Songwu LuNSDI 2023 · 被引用 13 次
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee 等S&P 2024 · 被引用 11 次
它引用的顶会 Paper5
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar 等NDSS 2017 · 被引用 255 次
- FlowCog: Context-aware Semantics Extraction and Analysis of Information Flow Leaks in Android AppsXiang Pan, Yinzhi Cao, Xuechao Du, Boyuan He 等USENIX Security 2018 · 被引用 39 次
- TextExerciser: Feedback-driven Text Input Exercising for Android ApplicationsYuyu He, Lei Zhang, Zhemin Yang, Yinzhi Cao 等S&P 2020 · 被引用 30 次
- Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheckBenjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck 等USENIX Security 2020
相关 Paper
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker 等USENIX Security 2019 · 被引用 185 次
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 被引用 20 次
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- Giving without Notifying: Assessing Compliance of Data Transmission in Android AppsMing Fan, Jifei Shi, Yin Wang, Le Yu 等ASE 2024 · 被引用 4 次
- PoliCond: Condition-Aware Ontology-Driven LLMs for Privacy Policy Contradiction AnalysisYalin Feng, Yifei Lu, Minxue PanASE 2025
