中文版 | English
题名

Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps

作者
通讯作者Yu, Le
DOI
发表日期
2023
会议名称
45th IEEE/ACM International Conference on Software Engineering (ICSE)
ISSN
0270-5257
ISBN
978-1-6654-5702-6
会议录名称
页码
1583-1595
会议日期
MAY 14-20, 2023
会议地点
null,Melbourne,AUSTRALIA
出版地
10662 LOS VAQUEROS CIRCLE, PO BOX 3014, LOS ALAMITOS, CA 90720-1264 USA
出版者
摘要

The privacy of personal information has received significant attention in mobile software. Although researchers have designed methods to identify the conflict between app behavior and privacy policies, little is known about the privacy compliance issues relevant to third-party libraries (TPLs). The regulators enacted articles to regulate the usage of personal information for TPLs (e.g., the CCPA requires businesses clearly notify consumers if they share consumers' data with third parties or not). However, it remains challenging to investigate the privacy compliance issues of TPLs due to three reasons: 1) Difficulties in collecting TPLs' privacy policies. In contrast to Android apps, which are distributed through markets like Google Play and must provide privacy policies, there is no unique platform for collecting privacy policies of TPLs. 2) Difficulties in analyzing TPL's user privacy access behaviors. TPLs are mainly provided in binary files, such as jar or aar, and their whole functionalities usually cannot be executed independently without host apps. 3) Difficulties in identifying consistency between TPL's functionalities and privacy policies, and host app's privacy policy and data sharing with TPLs. This requires analyzing not only the privacy policies of TPLs and host apps but also their functionalities. In this paper, we propose an automated system named ATPChecker to analyze whether Android TPLs comply with the privacy-related regulations. We construct a data set that contains a list of 458 TPLs, 247 TPL's privacy policies, 187 TPL's binary files and 641 host apps and their privacy policies. Then, we analyze the bytecode of TPLs and host apps, design natural language processing systems to analyze privacy policies, and implement an expert system to identify TPL usage-related regulation compliance. The experimental results show that 23% TPLs violate regulation requirements for providing privacy policies. Over 47% TPLs miss disclosing data usage in their privacy policies. Over 65% host apps share user data with TPLs while 65% of them miss disclosing interactions with TPLs. Our findings remind developers to be mindful of TPL usage when developing apps or writing privacy policies to avoid violating regulations.

关键词
学校署名
其他
语种
英语
相关链接[来源记录]
收录类别
资助项目
Hong Kong RGC Projects[
WOS研究方向
Computer Science
WOS类目
Computer Science, Software Engineering ; Computer Science, Theory & Methods
WOS记录号
WOS:001032629800128
EI入藏号
20233914775291
EI主题词
Android (operating system) ; Automation ; Behavioral research ; Data privacy ; Expert systems ; Natural language processing systems
EI分类号
Ergonomics and Human Factors Engineering:461.4 ; Computer Software, Data Handling and Applications:723 ; Data Processing and Image Processing:723.2 ; Expert Systems:723.4.1 ; Automatic Control Principles and Applications:731 ; Libraries:903.4.1 ; Social Sciences:971
来源库
Web of Science
全文链接https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10172865
引用统计
被引频次[WOS]:2
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/553208
专题南方科技大学
作者单位
1.Hong Kong Polytechn Univ, Hong Kong, Peoples R China
2.Southern Univ Sci & Technol, Shenzhen, Peoples R China
3.Huazhong Univ Sci & Technol, Wuhan, Hubei, Peoples R China
推荐引用方式
GB/T 7714
Zhao, Kaifa,Zhan, Xian,Yu, Le,et al. Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps[C]. 10662 LOS VAQUEROS CIRCLE, PO BOX 3014, LOS ALAMITOS, CA 90720-1264 USA:IEEE COMPUTER SOC,2023:1583-1595.
条目包含的文件
条目无相关文件。
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Zhao, Kaifa]的文章
[Zhan, Xian]的文章
[Yu, Le]的文章
百度学术
百度学术中相似的文章
[Zhao, Kaifa]的文章
[Zhan, Xian]的文章
[Yu, Le]的文章
必应学术
必应学术中相似的文章
[Zhao, Kaifa]的文章
[Zhan, Xian]的文章
[Yu, Le]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。