The Best of Both Worlds: Mitigating Trade-offs Between Accuracy and User Burden in Capturing Mobile App Privacy Preferences

The Best of Both Worlds: Mitigating Trade-offs Between Accuracy and User Burden in Capturing Mobile App Privacy Preferences
复制标题

DOI:
10.2478/popets-2020-0011
复制
发表时间:
2020-01
影响因子:
--
通讯作者:
Daniel Smullen;Yuanyuan Feng;Shikun Zhang;N. Sadeh
Daniel Smullen;Yuanyuan Feng;Shikun Zhang;N. Sadeh
中科院分区:
--
文献类型:
--
作者:
Daniel Smullen;Yuanyuan Feng;Shikun Zhang;N. Sadeh

文献摘要

被引文献

相似文献

摘要在当今以数据为中心的经济中,数据流越来越多样化和复杂化。移动的应用程序就是最好的例子,它们可以访问越来越多的敏感API。移动的操作系统已经尝试平衡敏感API的引入与用户可以授予或拒绝的权限设置的不断增长的集合。面临的挑战是,设置的数量已变得难以管理。然而,研究也表明,现有的设置在准确捕捉人们的隐私偏好方面仍然存在不足。例如,无法根据应用程序请求访问敏感数据的目的来控制移动的应用程序权限。简而言之,虽然用户已经不堪重负,但要准确捕捉他们的隐私偏好,需要引入更多的设置。减轻这种权衡的一种有希望的方法是使用机器学习来生成设置建议或捆绑一些设置。本文是第一篇对机器学习如何帮助减轻这种权衡进行定量评估的文章,重点关注移动的应用程序权限。结果表明,它确实可以更准确地捕捉人们的隐私偏好,同时也减轻了用户的负担。
Abstract In today’s data-centric economy, data flows are increasingly diverse and complex. This is best exemplified by mobile apps, which are given access to an increasing number of sensitive APIs. Mobile operating systems have attempted to balance the introduction of sensitive APIs with a growing collection of permission settings, which users can grant or deny. The challenge is that the number of settings has become unmanageable. Yet research also shows that existing settings continue to fall short when it comes to accurately capturing people’s privacy preferences. An example is the inability to control mobile app permissions based on the purpose for which an app is requesting access to sensitive data. In short, while users are already overwhelmed, accurately capturing their privacy preferences would require the introduction of an even greater number of settings. A promising approach to mitigating this trade-off lies in using machine learning to generate setting recommendations or bundle some settings. This article is the first of its kind to offer a quantitative assessment of how machine learning can help mitigate this trade-off, focusing on mobile app permissions. Results suggest that it is indeed possible to more accurately capture people’s privacy preferences while also reducing user burden.