Towards Fine-Grained Localization of Privacy Behaviors

Towards Fine-Grained Localization of Privacy Behaviors
复制标题

DOI:
10.1109/eurosp57164.2023.00024
复制
发表时间:
2023-05
期刊:
2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Vijayanta Jain;S. Ghanavati;Sai Teja Peddinti;Collin McMillan
Vijayanta Jain;S. Ghanavati;Sai Teja Peddinti;Collin McMillan
中科院分区:
其他
文献类型:
--
作者:
Vijayanta Jain;S. Ghanavati;Sai Teja Peddinti;Collin McMillan

文献摘要

相似文献

隐私标签帮助开发人员传达他们的应用程序的隐私行为(即,应用程序如何以及为什么使用个人信息)。但是,研究表明,开发人员在创建它们时面临着一些挑战,并且生成的标签通常与其应用程序的隐私行为不一致。在本文中,我们创建了一种新的方法,称为细粒度本地化的隐私行为,以定位源代码中的个人语句编码的隐私行为,并预测他们的隐私标签。我们设计并开发了一个基于注意力的多头编码器模型,该模型创建了多种方法的个体表示,并使用注意力来识别实现隐私行为的相关语句。然后,这些声明用于预测应用程序源代码的隐私标签,并可以帮助开发人员编写可用作通知的隐私声明。我们的定量分析表明,我们的方法可以达到较高的准确率在识别隐私标签,最低的准确率为91.41%,最高的98.45%。我们还评估了我们的方法的有效性与六个软件专业人士从我们的大学。结果表明,我们的方法减少了开发人员创建高质量的隐私声明所需的时间和精力,并可以很好地本地化实现隐私行为的方法中的声明。
Privacy labels help developers communicate their application’s privacy behaviors (i.e., how and why an application uses personal information) to users. But, studies show that developers face several challenges in creating them and the resultant labels are often inconsistent with their application’s privacy behaviors. In this paper, we create a novel methodology called fine-grained localization of privacy behaviors to locate individual statements in source code which encode privacy behaviors and predict their privacy labels. We design and develop an attention-based multi-head encoder model which creates individual representations of multiple methods and uses attention to identify relevant statements that implement privacy behaviors. These statements are then used to predict privacy labels for the application’s source code and can help developers write privacy statements that can be used as notices. Our quantitative analysis shows that our approach can achieve high accuracy in identifying privacy labels, with the lowest accuracy of 91.41% and the highest of 98.45%. We also evaluate the efficacy of our approach with six software professionals from our university. The results demonstrate that our approach reduces the time and mental effort required by developers to create high-quality privacy statements and can finely localize statements in methods that implement privacy behaviors.