{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T23:17:50Z","timestamp":1777591070137,"version":"3.51.4"},"reference-count":53,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2024,6,13]],"date-time":"2024-06-13T00:00:00Z","timestamp":1718236800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,6,13]],"date-time":"2024-06-13T00:00:00Z","timestamp":1718236800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100010909","name":"Young Scientists Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100010909","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the continuous development of mobile devices, mobile applications bring a lot of convenience to people\u2019s lives. The abuse of mobile device permissions is prone to the risk of privacy leakage. The existing detection technology can detect the inconsistency between the declared authority and the actual use authority. But using the third-party privacy policy as the analysis basis for SDK permissions will result in a large set of extracted declaration permissions, which will lead to identifying risky applications as normal applications during consistency comparison. The prevailing approach involves utilizing models based on TextCNN to extract information from privacy policies. However, the training of TextCNN relies on large-scale annotated datasets, leading to high costs. This paper uses BERT as the word vector extraction model to obtain private phrases from the privacy policy. And then we use cosine similarity to automatically filter permission phrase samples, reducing the workload of manual labeling. On the other hand, existing methods do not support the analysis of Chinese privacy policies. In order to solve the problem of consistency judgment between Chinese privacy policy and permission usage, we implement a BERT-based Android privacy policy and permission usage consistency analysis engine. The engine first uses static analysis to obtain the permission list of Android applications, and then combines the BERT model to achieve consistency analysis. After functional and speed testing, we found that the engine can successfully run the consistency analysis function of Chinese declaration permissions and usage permissions, and it is better than the existing detection methods.<\/jats:p>","DOI":"10.1007\/s10462-024-10798-z","type":"journal-article","created":{"date-parts":[[2024,6,13]],"date-time":"2024-06-13T08:01:51Z","timestamp":1718265711000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Intelligent analysis of android application privacy policy and permission consistency"],"prefix":"10.1007","volume":"57","author":[{"given":"Tengfei","family":"Tu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0532-9783","authenticated-orcid":false,"given":"Hua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bei","family":"Gong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daizhong","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiaoyan","family":"Wen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,6,13]]},"reference":[{"key":"10798_CR1","doi-asserted-by":"crossref","unstructured":"Andow B, Acharya A, Li D, Enck W, Singh K, Xie T (2017) Uiref: analysis of sensitive user inputs in android applications. Proceedings of the 10th acm conference on security and privacy in wireless and mobile networks (pp. 23\u201334)","DOI":"10.1145\/3098243.3098247"},{"key":"10798_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106374","volume":"127","author":"L Ardito","year":"2020","unstructured":"Ardito L, Coppola R, Malnati G, Torchiano M (2020) Effectiveness of Kotlin vs. Java in android app development tasks. Inf Softw Technol 127:106374","journal-title":"Inf Softw Technol"},{"issue":"6","key":"10798_CR3","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, McDaniel P (2014) Flowdroid: precise context, flow, field, object sensitive and lifecycle-aware taint analysis for android apps. ACM Sigplan Notices 49(6):259\u2013269","journal-title":"ACM Sigplan Notices"},{"key":"10798_CR4","doi-asserted-by":"crossref","unstructured":"Ayala-Rivera V, Pasquale L (2018) The grace period has ended: an approach to operationalize GDPR requirements. In: 2018 IEEE 26th international requirements engineering conference (re). pp 136\u2013146","DOI":"10.1109\/RE.2018.00023"},{"key":"10798_CR5","doi-asserted-by":"crossref","unstructured":"Azim T, Neamtiu I (2013) Targeted and depth-first exploration for systematic testing of android apps. Proceedings of the 2013 ACM sigplan international conference on object oriented programming systems languages & applications pp 641\u2013660","DOI":"10.1145\/2509136.2509549"},{"key":"10798_CR6","doi-asserted-by":"crossref","unstructured":"Benats G, Bandara A, Yu Y, Colin J-N, Nuseibeh B (2011) Primandroid: privacy policy modelling and analysis for android applications. 2011 IEEE international symposium on policies for distributed systems and networks pp 129\u2013132","DOI":"10.1109\/POLICY.2011.25"},{"key":"10798_CR7","unstructured":"Bergsma S, Lin D, Goebel R (2009) Web-scale n-gram models for lexical disambiguation. Twenty-first international joint conference on artificial intelligence"},{"key":"10798_CR8","doi-asserted-by":"crossref","unstructured":"Bl\u00e4sing T, Batyuk L, Schmidt A-D, Camtepe SA, Albayrak S (2010) An android application sandbox system for suspicious software detection. 2010 5th international conference on malicious and unwanted software pp 55\u201362","DOI":"10.1109\/MALWARE.2010.5665792"},{"key":"10798_CR9","unstructured":"Cavnar WB, Trenkle JM et\u00a0al (1994) N-gram-based text categorization. Proceedings of SDAIR-94, 3rd annual symposium on document analysis and information retrieval, vol 161175"},{"key":"10798_CR10","unstructured":"Cui Y, Che W, Liu T, Qin B, Yang Z, Wang S, Hu G (2019) Pre-training with whole word masking for Chinese bert. arXiv:1906.08101"},{"key":"10798_CR11","doi-asserted-by":"crossref","unstructured":"Davi L, Dmitrienko A, Sadeghi A-R, Winandy M (2010) Privilege escalation attacks on android. International conference on information security. pp 346\u2013360","DOI":"10.1007\/978-3-642-18178-8_30"},{"key":"10798_CR12","unstructured":"Devlin J, Chang M-W, Lee K, Toutanova K (2018) Bert: pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805"},{"key":"10798_CR13","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1016\/j.neucom.2020.06.149","volume":"444","author":"H Elahi","year":"2021","unstructured":"Elahi H, Castiglione A, Wang G, Geman O (2021) A human-centered artificial intelligence approach for privacy protection of elderly app users in smart cities. Neurocomputing 444:189\u2013202","journal-title":"Neurocomputing"},{"key":"10798_CR14","doi-asserted-by":"crossref","unstructured":"Elluri L, Joshi KP, Kotal A (2020) Measuring semantic similarity across eu gdpr regulation and cloud privacy policies. 2020 IEEE international conference on big data (big data) pp 3963\u20133978","DOI":"10.1109\/BigData50022.2020.9377864"},{"issue":"1","key":"10798_CR15","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSP.2009.26","volume":"7","author":"W Enck","year":"2009","unstructured":"Enck W, Ongtang M, McDaniel P (2009) Understanding android security. IEEE Secur Privacy 7(1):50\u201357","journal-title":"IEEE Secur Privacy"},{"issue":"2","key":"10798_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2619091","volume":"32","author":"W Enck","year":"2014","unstructured":"Enck W, Gilbert P, Han S, Tendulkar V, Chun B-G, Cox LP, Sheth AN (2014) Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans Comput Syst (TOCS) 32(2):1\u201329","journal-title":"ACM Trans Comput Syst (TOCS)"},{"key":"10798_CR17","doi-asserted-by":"crossref","unstructured":"Fan M, Yu L, Chen S, Zhou H, Luo X, Li S, Liu T (2020) An empirical evaluation of GDPR compliance violations in android mhealth apps. 2020 IEEE 31st international symposium on software reliability engineering (ISSRE) pp 253\u2013264","DOI":"10.1109\/ISSRE5003.2020.00032"},{"key":"10798_CR18","doi-asserted-by":"crossref","unstructured":"Feichtner J, Gruber S (2020) Understanding privacy awareness in android app descriptions using deep learning. Proceedings of the tenth ACM conference on data and application security and privacy pp 203\u2013214","DOI":"10.1145\/3374664.3375730"},{"key":"10798_CR19","doi-asserted-by":"crossref","unstructured":"Felt AP, Chin E, Hanna S, Song D, Wagner D (2011) Android permissions demystified. Proceedings of the 18th ACM conference on computer and communications security pp 627\u2013638","DOI":"10.1145\/2046707.2046779"},{"key":"10798_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102386","volume":"109","author":"T Frenklach","year":"2021","unstructured":"Frenklach T, Cohen D, Shabtai A, Puzis R (2021) Android malware detection via an app similarity graph. Comput Secur 109:102386","journal-title":"Comput Secur"},{"key":"10798_CR21","doi-asserted-by":"crossref","unstructured":"Fu R, Zhang Z, Li L (2016) Using lstm and GRU neural network methods for traffic flow prediction. 2016 31st youth academic annual conference of Chinese association of automation (yac) pp 324\u2013328","DOI":"10.1109\/YAC.2016.7804912"},{"key":"10798_CR22","unstructured":"Gargenta M (2011) Learning android. \u201cO\u2019Reilly Media, Inc\u201d"},{"key":"10798_CR23","doi-asserted-by":"crossref","unstructured":"Ghaeini R, Hasan SA, Datla V, Liu J, Lee K, Qadir A, Farri O (2018) Dr-bilstm: dependent reading bidirectional lstm for natural language inference. arXiv:1802.05577","DOI":"10.18653\/v1\/N18-1132"},{"key":"10798_CR24","doi-asserted-by":"crossref","unstructured":"Gibler C, Crussell J, Erickson J, Chen H (2012) Androidleaks: automatically detecting potential privacy leaks in android applications on a large scale. International conference on trust and trustworthy computing pp 291\u2013307","DOI":"10.1007\/978-3-642-30921-2_17"},{"issue":"10","key":"10798_CR25","doi-asserted-by":"publisher","first-page":"2222","DOI":"10.1109\/TNNLS.2016.2582924","volume":"28","author":"K Greff","year":"2016","unstructured":"Greff K, Srivastava RK, Koutn\u0131k J, Steunebrink BR, Schmidhuber J (2016) Lstm: A search space odyssey. IEEE Trans Neural Netw Learning Syst 28(10):2222\u20132232","journal-title":"IEEE Trans Neural Netw Learning Syst"},{"key":"10798_CR26","doi-asserted-by":"crossref","unstructured":"Heid K, Heider J (2021) Automated, dynamic android app vulnerability and privacy leak analysis: design considerations, required components and available tools. European interdisciplinary cybersecurity conference pp 1\u20136","DOI":"10.1145\/3487405.3487652"},{"key":"10798_CR27","doi-asserted-by":"crossref","unstructured":"Hornyack P, Han S, Jung J, Schechter S, Wetherall D (2011) These aren\u2019t the droids you\u2019re looking for: retrofitting android to protect data from imperious applications. Proceedings of the 18th ACM conference on computer and communications security pp 639\u2013652","DOI":"10.1145\/2046707.2046780"},{"key":"10798_CR28","doi-asserted-by":"crossref","unstructured":"Huang J, Zhang X, Tan L, Wang P, Liang B (2014) Asdroid: Detecting stealthy behaviors in android applications by user interface and program behavior contradiction. Proceedings of the 36th international conference on software engineering pp 1036\u20131046","DOI":"10.1145\/2568225.2568301"},{"key":"10798_CR29","unstructured":"Huang J, Li Z, Xiao X, Wu Z, Lu K, Zhang X, Jiang G (2015) SUPOR: Precise and scalable sensitive user input detection for android apps. 24th USENIX security symposium (USENIX security 15) pp 977\u2013992"},{"key":"10798_CR30","first-page":"2017","volume":"28","author":"M Jaderberg","year":"2015","unstructured":"Jaderberg M, Simonyan K, Zisserman A et al (2015) Spatial transformer networks. Adv Neural Inf Process Syst 28:2017\u20132025","journal-title":"Adv Neural Inf Process Syst"},{"key":"10798_CR31","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1016\/j.isprsjprs.2020.12.010","volume":"173","author":"T Kattenborn","year":"2021","unstructured":"Kattenborn T, Leitloff J, Schiefer F, Hinz S (2021) Review on convolutional neural networks (CNN) in vegetation remote sensing. ISPRS J Photogram Remote Sens 173:24\u201349","journal-title":"ISPRS J Photogram Remote Sens"},{"issue":"1","key":"10798_CR32","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1075389.1075392","volume":"2","author":"M Lapata","year":"2005","unstructured":"Lapata M, Keller F (2005) Web-based models for natural language processing. ACM Trans Speech Lang Process (TSLP) 2(1):3","journal-title":"ACM Trans Speech Lang Process (TSLP)"},{"key":"10798_CR33","unstructured":"Liu Y, Ott M, Goyal N, Du J, Joshi M, Chen D, Stoyanov V (2019) Roberta: A robustly optimized bert pretraining approach. arXiv:1907.11692"},{"key":"10798_CR34","doi-asserted-by":"crossref","unstructured":"Mercaldo F, Visaggio CA, Canfora G, Cimitile A (2016) Mobile malware detection in the real world. 2016 IEEE\/ACM 38th international conference on software engineering companion (icse-c) pp 744\u2013746","DOI":"10.1145\/2889160.2892656"},{"key":"10798_CR35","doi-asserted-by":"crossref","unstructured":"Mulliner C, Robertson W, Kirda E (2014) Hidden gems: automated discovery of access control vulnerabilities in graphical user interfaces. 2014 IEEE symposium on security and privacy. pp 149\u2013162","DOI":"10.1109\/SP.2014.17"},{"key":"10798_CR36","unstructured":"Nan Y, Yang M, Yang Z, Zhou S, Gu G, Wang X (2015) Uipicker: User-input privacy identification in mobile applications. 24th USENIX security symposium (USENIX security 15) pp 993\u20131008"},{"key":"10798_CR37","unstructured":"Palmirani M, Governatori G (2018) Modelling legal knowledge for gdpr compliance checking. Jurix pp 101\u2013110"},{"key":"10798_CR38","unstructured":"Sanh V, Debut L, Chaumond J, Wolf T (2019) Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter. arXiv:1910.01108"},{"issue":"3","key":"10798_CR39","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1016\/j.istr.2012.10.006","volume":"17","author":"D Schreckling","year":"2013","unstructured":"Schreckling D, K\u00f6stler J, Schaff M (2013) Kynoid: real-time enforcement of fine-grained, user-defined, and data-centric security policies for android. Inf Secur Tech Rep 17(3):71\u201380","journal-title":"Inf Secur Tech Rep"},{"key":"10798_CR40","doi-asserted-by":"crossref","unstructured":"Slavin R, Wang X, Hosseini MB, Hester J, Krishnan R, Bhatia J, Niu J (2016) Toward a framework for detecting privacy policy violations in android application code. Proceedings of the 38th international conference on software engineering. pp 25\u201336","DOI":"10.1145\/2884781.2884855"},{"key":"10798_CR41","doi-asserted-by":"crossref","unstructured":"Tom J, Sing E, Matulevi\u010dius R (2018) Conceptual representation of the gdpr: model and application directions. International conference on business informatics research. pp 18\u201328","DOI":"10.1007\/978-3-319-99951-7_2"},{"key":"10798_CR42","doi-asserted-by":"crossref","unstructured":"Torre D, Soltana G, Sabetzadeh M, Briand LC, Auffinger Y, Goes P (2019) Using models to enable compliance checking against the gdpr: an experience report. 2019 ACM\/IEEE 22nd international conference on model driven engineering languages and systems (models). pp 1\u201311","DOI":"10.1109\/MODELS.2019.00-20"},{"key":"10798_CR43","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN, Polosukhin I (2017) Attention is all you need. Advances in Neural Information Processing Systems 30"},{"key":"10798_CR44","doi-asserted-by":"crossref","unstructured":"Vyas P, Shyamasundar R, Patil B (2021) App2secapp: privacy protection from android applications. Proceedings of the 36th annual ACM symposium on applied computing pp 908\u2013911","DOI":"10.1145\/3412841.3442102"},{"issue":"12","key":"10798_CR45","doi-asserted-by":"publisher","first-page":"2933","DOI":"10.1109\/TMC.2019.2934441","volume":"19","author":"R Wang","year":"2019","unstructured":"Wang R, Wang Z, Tang B, Zhao L, Wang L (2019) Smartpi: understanding permission implications of android apps from user reviews. IEEE Trans Mob Comput 19(12):2933\u20132945","journal-title":"IEEE Trans Mob Comput"},{"key":"10798_CR46","doi-asserted-by":"crossref","unstructured":"Wang X, Qin X, Hosseini MB, Slavin R, Breaux TD, Niu J (2018) Guileak: Tracing privacy policy claims on user input data for android applications. Proceedings of the 40th international conference on software engineering pp 37\u201347","DOI":"10.1145\/3180155.3180196"},{"key":"10798_CR47","doi-asserted-by":"crossref","unstructured":"Wang Z, Li C, Guan Y, Xue Y (2015) Droidchain: a novel malware detection method for android based on behavior chain. 2015 IEEE conference on communications and network security (CNS) pp 727\u2013728","DOI":"10.1109\/CNS.2015.7346906"},{"key":"10798_CR48","unstructured":"Xiao H (2018) bert-as-service. https:\/\/github.com\/hanxiao\/bert-as-service"},{"key":"10798_CR49","doi-asserted-by":"crossref","unstructured":"Yang Z, Yang M (2012) Leakminer: Detect information leakage on android with static taint analysis. 2012 third world congress on software engineering. pp 101\u2013104","DOI":"10.1109\/WCSE.2012.26"},{"key":"10798_CR50","doi-asserted-by":"crossref","unstructured":"Yu L, Luo X, Liu X, Zhang T (2016) Can we trust the privacy policies of android apps? 2016 46th annual IEEE\/IFIP international conference on dependable systems and networks (dsn) pp 538\u2013549","DOI":"10.1109\/DSN.2016.55"},{"issue":"9","key":"10798_CR51","doi-asserted-by":"publisher","first-page":"834","DOI":"10.1109\/TSE.2017.2730198","volume":"44","author":"L Yu","year":"2017","unstructured":"Yu L, Luo X, Qian C, Wang S, Leung HK (2017) Enhancing the description-to-behavior fidelity in android apps with privacy policy. IEEE Trans Softw Eng 44(9):834\u2013854","journal-title":"IEEE Trans Softw Eng"},{"key":"10798_CR52","doi-asserted-by":"crossref","unstructured":"Yu L, Zhang T, Luo X, Xue L (2015) Autoppg: Towards automatic generation of privacy policy for android applications. Proceedings of the 5th annual acm ccs workshop on security and privacy in smartphones and mobile devices pp 39\u201350","DOI":"10.1145\/2808117.2808125"},{"key":"10798_CR53","doi-asserted-by":"crossref","unstructured":"Zhao Z, Osono FCC (2012) \u201c$$\\text{trustdroid}^{\\text{ TM }}$$\u201d: Preventing the use of smartphones for information leaking in corporate networks through the used of static analysis taint tracking. 2012 7th international conference on malicious and unwanted software pp 135\u2013143","DOI":"10.1109\/MALWARE.2012.6461017"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-024-10798-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-024-10798-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-024-10798-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,15]],"date-time":"2024-07-15T10:17:23Z","timestamp":1721038643000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-024-10798-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,13]]},"references-count":53,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2024,7]]}},"alternative-id":["10798"],"URL":"https:\/\/doi.org\/10.1007\/s10462-024-10798-z","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,13]]},"assertion":[{"value":"23 April 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 June 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"172"}}