Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA App
Fuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng, Yanjun Zhang, Guangdong Bai
摘要
Virtual personal assistants (VPA) services encompass a large number of third-party applications (or apps) to enrich their functionalities. These apps have been well examined to scrutinize their data collection behaviors against their declared privacy policies. Nonetheless, it is often overlooked that most users tend to ignore privacy policies at the installation time. Dishonest developers thus can exploit this situation by embedding excessive declarations to cover their data collection behaviors during compliance auditing. In this work, we present Pico, a privacy inconsistency detector, which checks the VPA app's privacy compliance by analyzing (in)consistency between data requested and data essential for its functionality. Pico understands the app's functionality topics from its publicly available textual data, and leverages advanced GPTbased language models to address domain-specific challenges. Based on the counterparts with similar functionality, suspicious data collection can be detected through the lens of anomaly detection. We apply Pico to understand the status quo of data-functionality compliance among all 65,195 skills in the Alexa app store. Our study reveals that 21.7% of the analyzed skills exhibit suspicious data collection, including Top 10 popular Alexa skills that pose threats to 54,116 users. These findings should raise an alert to both developers and users, in the compliance with the purpose limitation principle in data regulations. CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Investigating Documented Privacy Changes in Android OSChuan Yan, Mark Huasong Meng, Fuman Xie, Guangdong BaiFSE 2024 · 被引用 6 次
- SKILLPoV: Towards Accessible and Effective Privacy Notice for Amazon Alexa SkillsJingwen Yan, Song Liao, Mohammed Aldeen, Luyi Xing 等NDSS 2025
它引用的顶会 Paper10
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang 等S&P 2019 · 被引用 160 次
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi 等CCS 2021 · 被引用 41 次
- Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsFuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li 等ASE 2022 · 被引用 31 次
- Measuring Alexa Skill Privacy Practices across Three YearsJide S. Edu, Xavier Ferrer Aran, Jose M. Such, Guillermo Suarez-TangilWWW 2022 · 被引用 29 次
- EDEFuzz: A Web API Fuzzer for Excessive Data ExposuresLianglu Pan, Shaanan Cohney, Toby Murray, Van-Thuan PhamICSE 2024 · 被引用 11 次
相关 Paper
- SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the WildJeffrey Young, Song Liao, Long Cheng, Hongxin Hu 等USENIX Security 2022
- Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesSong Liao, Mohammed Aldeen, Jingwen Yan, Long Cheng 等WWW 2024 · 被引用 9 次
- SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseSong Liao, Long Cheng, Haipeng Cai, Linke Guo 等CCS 2023 · 被引用 7 次
- Analyzing Ad Prevalence, Characteristics, and Compliance in Alexa SkillsAafaq Sabir, Abhinaya S. B., Dilawer Ahmed, Anupam DasS&P 2025
- Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsLong Cheng, Christin Wilson, Song Liao, Jeffrey Young 等CCS 2020 · 被引用 58 次
