Title
Toward Automatically Generating Privacy Policy for Android Apps.
Abstract
A privacy policy is a statement informing users how their information will be collected, used, and disclosed. Failing to provide a correct privacy policy may result in a fine. However, writing privacy policy is tedious and error-prone, because the author may not understand the source code well as it could have been written by others (e.g., outsourcing), or the author does not know the internal working of third-party libraries used. In this paper, we propose and develop a novel system named AutoPPG to automatically construct correct and readable descriptions to facilitate the generation of privacy policy for Android applications (i.e., apps). Given an app, AutoPPG first conducts static code analysis to characterize its behaviors related to users’ personal information, and then applies natural language processing techniques to generating correct and accessible sentences for describing these behaviors. The experimental results using real apps and crowdsourcing indicate that: 1) AutoPPG creates correct and easy-to-understand descriptions for privacy policies; 2) the privacy policies constructed by AutoPPG usually reveal more operations related to users’ personal information than existing privacy policies; and 3) most developers, who reply us, would like to use AutoPPG to facilitate them.
Year
DOI
Venue
2017
10.1109/TIFS.2016.2639339
IEEE Trans. Information Forensics and Security
Keywords
Field
DocType
Privacy,Text analysis,Androids,Humanoid robots,Libraries,Smart phones,Google
Static program analysis,World Wide Web,Internet privacy,Android (operating system),Crowdsourcing,Source code,Computer science,Privacy policy,Personally identifiable information,Information privacy,Privacy software
Journal
Volume
Issue
ISSN
12
4
1556-6013
Citations 
PageRank 
References 
11
0.53
34
Authors
5
Name
Order
Citations
PageRank
le yu1283.17
Tao Zhang212814.89
Xiapu Luo31302110.23
Lei Xue410316.03
Henry Chang5110.53