Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant Apps

被引:4
|
作者
Xie, Fuman [1 ]
Zhang, Yanjun [2 ]
Yan, Chuan [1 ]
Li, Suwan [3 ]
Bu, Lei [3 ]
Chen, Kai [4 ]
Huang, Zi [1 ]
Bai, Guangdong [1 ]
机构
[1] Univ Queensland, Brisbane, Qld, Australia
[2] Deakin Univ, Geelong, Vic, Australia
[3] Nanjing Univ, Nanjing, Peoples R China
[4] Chinese Acad Sci, Beijing, Peoples R China
基金
中国国家自然科学基金; 北京市自然科学基金; 澳大利亚研究理事会;
关键词
Virtual Personal Assistant; privacy compliance; Alexa skills;
D O I
10.1145/3551349.3560416
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A large number of functionality-rich and easily accessible applications have become popular among various virtual personal assistant (VPA) services such as Amazon Alexa. VPA applications (or VPA apps for short) are accompanied by a privacy policy document that informs users of their data handling practices. These documents are usually lengthy and complex for users to comprehend, and developers may intentionally or unintentionally fail to comply with them. In this work, we conduct the first systematic study on the privacy policy compliance issue of VPA apps. We develop Skipper, which targets Amazon Alexa skills. It automatically depicts the skill into the declared privacy profile by analyzing their privacy policy documents with Natural Language Processing (NLP) and machine learning techniques, and derives the behavioral privacy profile of the skill through a black-box testing. We conduct a large-scale analysis on all skills listed on Alexa store, and find that a large number of skills suffer from the privacy policy noncompliance issues.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Evaluating the Privacy Policy of Android Apps: A Privacy Policy Compliance Study for Popular Apps in China and Europe
    Liu, Kaijun
    Xu, Guoai
    Zhang, Xiaomei
    Xu, Guosheng
    Zhao, Zhangjie
    [J]. Scientific Programming, 2022, 2022
  • [2] Evaluating the Privacy Policy of Android Apps: A Privacy Policy Compliance Study for Popular Apps in China and Europe
    Liu, Kaijun
    Xu, Guoai
    Zhang, Xiaomei
    Xu, Guosheng
    Zhao, Zhangjie
    [J]. SCIENTIFIC PROGRAMMING, 2022, 2022
  • [3] Personal Information Protection and Privacy Policy Compliance of Health Code Apps in China: Scale Development and Content Analysis
    Jiang, Jiayi
    Zheng, Zexing
    [J]. JMIR MHEALTH AND UHEALTH, 2023, 11
  • [4] Investigating Users' Understanding of Privacy Policies of Virtual Personal Assistant Applications
    Chen, Baiqi
    Wu, Tingmin
    Zhang, Yanjun
    Chhetri, Mohan Baruwal
    Bai, Guangdong
    [J]. PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 65 - 79
  • [5] Poster: A First Look at the Privacy Risks of Voice Assistant Apps
    Natatsuka, Atsuko
    Iijima, Ryo
    Watanabe, Takuya
    Akiyama, Mitsuaki
    Sakai, Tetsuya
    Mori, Tatsuya
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 2633 - 2635
  • [6] Privacy Policy Compliance of Chronic Disease Management Apps in China: Scale Development and Content Evaluation
    Ni, Zhenni
    Wang, Yiying
    Qian, Yuxing
    [J]. JMIR MHEALTH AND UHEALTH, 2021, 9 (01):
  • [7] IoTPrivComp: A Measurement Study of Privacy Compliance in IoT Apps
    Ahmad, Javaria
    Li, Fengjun
    Luo, Bo
    [J]. COMPUTER SECURITY - ESORICS 2022, PT II, 2022, 13555 : 589 - 609
  • [8] PANOLA: A Personal Assistant for Supporting Users in Preserving Privacy
    Ulusoy, Onuralp
    Yolum, Pinar
    [J]. ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2022, 22 (01)
  • [9] Personal Voice Assistant Security and Privacy-A Survey
    Cheng, Peng
    Roedig, Utz
    [J]. PROCEEDINGS OF THE IEEE, 2022, 110 (04) : 476 - 507
  • [10] VIRTUAL PERSONAL ASSISTANT TOWARDS SUICIDE PREVENTION
    Martins, Marcos Vinnicius
    Beque Guerra, Lucieli Tolfo
    [J]. TEXTO LIVRE-LINGUAGEM E TECNOLOGIA, 2020, 13 (02): : 216 - 237