{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T11:39:49Z","timestamp":1784288389663,"version":"3.55.0"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"14","license":[{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Universidad Nacional de Educacion Distancia"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2025,11]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    The pervasive use of mobile applications and social networks has intensified privacy concerns due to the widespread collection, processing, and sharing of personal data. To address these challenges, we introduce\n                    <jats:italic>SafeMountain<\/jats:italic>\n                    , a novel AI-driven framework designed to systematically quantify, evaluate, and visualize privacy risks in mobile apps and social platforms, ensuring strict compliance with international regulations, particularly the General Data Protection Regulation (GDPR). SafeMountain combines static and dynamic code analyses to scrutinize real-world data handling practices and detect potential privacy breaches. It also employs advanced Natural Language Processing (NLP) techniques for automated interpretation and evaluation of privacy policies and Terms of Service. By mapping textual policy disclosures to actual app permissions and behaviors, it identifies discrepancies and highlights potential non-compliance and data misuse. The framework introduces an objective risk scoring mechanism aligned with international standards and regulatory requirements, offering a structured methodology to classify and visualize privacy risks. This risk assessment spans multiple dimensions (predictability, manageability, and disassociability) leveraging privacy engineering principles and regulatory risk factors, and uses an intuitive traffic-light system (Green, Yellow, Red) to enhance transparency and user comprehension. SafeMountain addresses major research gaps, notably the absence of standardized privacy risk scoring and comprehensive visualization tools. By delivering actionable insights into permission consistency, policy transparency, compliance gaps, and data leakage vulnerabilities, it empowers users, developers, and organizations to manage privacy risks proactively. Ultimately, SafeMountain fosters trust through more transparent and accountable data privacy practices across digital ecosystems.\n                  <\/jats:p>","DOI":"10.1007\/s10586-025-05624-2","type":"journal-article","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T20:17:15Z","timestamp":1759177035000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Comprehensive AI-driven privacy risk assessment in mobile apps and social networks"],"prefix":"10.1007","volume":"28","author":[{"given":"Daniel","family":"Blanco-Aza","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonio","family":"Robles-G\u00f3mez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rafael","family":"Pastor-Vargas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Llanos","family":"Tobarra","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pedro","family":"Vidal-Balboa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mariano","family":"M\u00e9ndez-Su\u00e1rez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,9,29]]},"reference":[{"key":"5624_CR1","unstructured":"Union, E.: Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (2016). https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"5624_CR2","unstructured":"Regulation (EU) 2022\/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services (Digital Services Act). https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2065\/oj. Accessed May 20, 2025 (2022)"},{"key":"5624_CR3","unstructured":"IBM: Natural language processing (NLP). https:\/\/www.ibm.com\/topics\/natural-language-processing. Retrieved December 19, 2024"},{"key":"5624_CR4","unstructured":"Malone, T., Rus, D., Laubacher, R.: Machine learning, explained. https:\/\/mitsloan.mit.edu\/ideas-made-to-matter\/machine-learning-explained. Retrieved December 19, 2024"},{"issue":"4","key":"5624_CR5","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1111\/j.1469-7610.2007.01846.x","volume":"49","author":"PK Smith","year":"2008","unstructured":"Smith, P.K., Mahdavi, J., Carvalho, M., Fisher, S., Russell, S., Tippett, N.: Cyberbullying: Its nature and impact in secondary school pupils. Journal of Child Psychology and Psychiatry 49(4), 376\u2013385 (2008). https:\/\/doi.org\/10.1111\/j.1469-7610.2007.01846.x","journal-title":"Journal of Child Psychology and Psychiatry"},{"key":"5624_CR6","doi-asserted-by":"publisher","unstructured":"Blanco-Aza, D., Robles-G\u00f3mez, A., Pastor-Vargas, R., Tobarra, L., Vidal-Balboa, P., M\u00e9ndez-Su\u00e1rez, M.: Privacy Analysis in Mobile Apps and Social Networks using AI Techniques. In: Proceedings of The Fourth Intelligent Cybersecurity Conference (ICSC 2024), Valencia, Spain (2024). https:\/\/doi.org\/10.1109\/ICSC63108.2024.10895037","DOI":"10.1109\/ICSC63108.2024.10895037"},{"key":"5624_CR7","unstructured":"California Privacy Rights Act (CPRA). State of California Department of Justice. Available: https:\/\/oag.ca.gov\/privacy\/ccpa (2020)"},{"key":"5624_CR8","doi-asserted-by":"publisher","unstructured":"Feng, Y., Chen, L., Zheng, A., Gao, C., Zheng, Z.: AC-Net: Assessing the Consistency of Description and Permission in Android Apps. IEEE Access 7, 57829\u201357842 (2019) https:\/\/doi.org\/10.1109\/ACCESS.2019.2912210","DOI":"10.1109\/ACCESS.2019.2912210"},{"key":"5624_CR9","doi-asserted-by":"crossref","unstructured":"Jain, A., Rodriguez, D., Alamo, J.M., Sadeh, N.: ATLAS: Automatically Detecting Discrepancies Between Privacy Policies and Privacy Labels. arXiv (2023) arxiv:2306.09247","DOI":"10.1109\/EuroSPW59978.2023.00016"},{"key":"5624_CR10","doi-asserted-by":"publisher","unstructured":"Zhao, K., Zhan, X., Yu, L., Zhou, S., Zhou, H., Luo, X., Wang, H., Liu, Y.: Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE), pp. 1583\u20131595 (2023). https:\/\/doi.org\/10.1109\/ICSE48619.2023.00137","DOI":"10.1109\/ICSE48619.2023.00137"},{"issue":"7","key":"5624_CR11","doi-asserted-by":"publisher","first-page":"769","DOI":"10.1016\/j.jksuci.2018.05.008","volume":"33","author":"AJ Bhatt","year":"2021","unstructured":"Bhatt, A.J., Gupta, C., Mittal, S.: iABC-AL: Active learning-based privacy leaks threat detection for iOS applications. Journal of King Saud University - Computer and Information Sciences 33(7), 769\u2013786 (2021). https:\/\/doi.org\/10.1016\/j.jksuci.2018.05.008","journal-title":"Journal of King Saud University - Computer and Information Sciences"},{"key":"5624_CR12","doi-asserted-by":"publisher","first-page":"89248","DOI":"10.1109\/ACCESS.2022.3199882","volume":"10","author":"MS Rahman","year":"2022","unstructured":"Rahman, M.S., Naghavi, P., Kojusner, B., Afroz, S., Williams, B., Rampazzi, S., Bindschaedler, V.: PermPress: Machine Learning-Based Pipeline to Evaluate Permissions in App Privacy Policies. IEEE Access 10, 89248\u201389269 (2022). https:\/\/doi.org\/10.1109\/ACCESS.2022.3199882","journal-title":"IEEE Access"},{"key":"5624_CR13","doi-asserted-by":"publisher","unstructured":"Xiang, A., Pei, W., Yue, C.: PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps\u2019 Privacy Policies. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 3373\u20133387 (2023). https:\/\/doi.org\/10.1145\/3576915.3623067","DOI":"10.1145\/3576915.3623067"},{"key":"5624_CR14","unstructured":"Andow, B., Mahmud, S.Y., Whitaker, J., Enck, W., Reaves, B., Wang, W., Singh, K., Xie, T.: PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/andow (2019)"},{"key":"5624_CR15","doi-asserted-by":"publisher","unstructured":"Yang, Y., Du, X., Yang, Z.: PRADroid: Privacy Risk Assessment for Android Applications. In: 2021 IEEE 5th International Conference on Cryptography, Security and Privacy (CSP), pp. 90\u201395 (2021). https:\/\/doi.org\/10.1109\/CSP51677.2021.9357608","DOI":"10.1109\/CSP51677.2021.9357608"},{"key":"5624_CR16","doi-asserted-by":"publisher","unstructured":"Atapattu, H.N., Fernando, W.S.N., Somasiri, J.P.A.K., Lokuge, P.M.K., Senarathne, A.N., Tissera, M.: A Sensitive Data Leakage Detection and Privacy Policy Analyzing Application for Android Systems (PriVot). In: 2021 3rd International Conference on Advancements in Computing (ICAC), pp. 300\u2013304 (2021). https:\/\/doi.org\/10.1109\/ICAC54203.2021.9671075","DOI":"10.1109\/ICAC54203.2021.9671075"},{"key":"5624_CR17","doi-asserted-by":"publisher","unstructured":"Li, S., Yang, Z., Hua, N., Liu, P., Zhang, X., Yang, G., Yang, M.: Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile Apps. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, pp. 1887\u20131900 (2022). https:\/\/doi.org\/10.1145\/3548606.3559371","DOI":"10.1145\/3548606.3559371"},{"key":"5624_CR18","doi-asserted-by":"publisher","unstructured":"Brooks, S., Garcia, M., Lefkovitz, N., Lightman, S., Nadeau, E.: An Introduction to Privacy Engineering and Risk Management in Federal Systems. NIST Interagency\/Internal Report 8062 (2017) https:\/\/doi.org\/10.6028\/NIST.IR.8062","DOI":"10.6028\/NIST.IR.8062"},{"key":"5624_CR19","unstructured":"Agencia Espa\u00f1ola de Protecci\u00f3n de Datos: Gesti\u00f3n del riesgo y evaluaci\u00f3n de impacto en tratamientos de datos personales. Accessed May 20, 2025 (2021). https:\/\/www.aepd.es\/guias\/gestion-riesgo-y-evaluacion-impacto-en-tratamientos-datos-personales.pdf"},{"key":"5624_CR20","doi-asserted-by":"publisher","unstructured":"Liu, S., Zhang, F., Zhao, B., Guo, R., Chen, T., Zhang, M.: APPCorp: A corpus for Android privacy policy document structure analysis. Frontiers of Computer Science 17(173320) (2023) https:\/\/doi.org\/10.1007\/s11704-023-173320","DOI":"10.1007\/s11704-023-173320"},{"issue":"4","key":"5624_CR21","doi-asserted-by":"publisher","first-page":"2272","DOI":"10.1109\/TSE.2023.3245213","volume":"49","author":"J Huang","year":"2023","unstructured":"Huang, J., Xue, B., Jiang, J., You, W., Liang, B., Wu, J., Wu, Y.: Scalably Detecting Third-Party Android Libraries With Two-Stage Bloom Filtering. IEEE Transactions on Software Engineering 49(4), 2272\u20132284 (2023). https:\/\/doi.org\/10.1109\/TSE.2023.3245213","journal-title":"IEEE Transactions on Software Engineering"},{"key":"5624_CR22","unstructured":"Sharma, S.: Building an Automated Machine for Discovering Privacy Violations at Scale. https:\/\/www.usenix.org\/conference\/enigma2023\/presentation\/sharma (2023)"},{"key":"5624_CR23","first-page":"97","volume":"5","author":"C Anwar","year":"2023","unstructured":"Anwar, C., Sumerli, C., Rahayu, N., Kraugusteeliana, K.: The Application of Mobile Security Framework (MOBSF) and Mobile Application Security Testing Guide to Ensure the Security in Mobile Commerce Applications. Jurnal Sistim Informasi dan Teknologi 5, 97\u2013102 (2023)","journal-title":"Jurnal Sistim Informasi dan Teknologi"},{"key":"5624_CR24","doi-asserted-by":"publisher","unstructured":"Garc\u00eda-Arias, E., Robles-G\u00f3mez, A., Pastor-Vargas, R., Tobarra, L., Vidal-Balboa, P., Blanco-Aza, D., Valtuille-Pacios, A.: Dataset de pol\u00edtica de privacidad y t\u00e9rminos de uso de aplicaciones m\u00f3viles en ingl\u00e9s y castellano. e-cienciaDatos (2025). https:\/\/doi.org\/10.21950\/HWQR0G","DOI":"10.21950\/HWQR0G"},{"key":"5624_CR25","unstructured":"Blanco-Aza, D., Robles-G\u00f3mez, A., Pastor-Vargas, R., Tobarra, L., Vidal-Balboa, P., Garc\u00eda-Arias, E., Valtuille-Pacios, A.: SafeMountain. https:\/\/github.com\/uned-cibergid-projects\/safemountain. Accessed May 21, 2025 (2025)"}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-025-05624-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10586-025-05624-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-025-05624-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T15:35:14Z","timestamp":1763134514000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10586-025-05624-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,29]]},"references-count":25,"journal-issue":{"issue":"14","published-print":{"date-parts":[[2025,11]]}},"alternative-id":["5624"],"URL":"https:\/\/doi.org\/10.1007\/s10586-025-05624-2","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,29]]},"assertion":[{"value":"16 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 May 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 July 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 September 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"914"}}