{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,5]],"date-time":"2026-02-05T07:42:16Z","timestamp":1770277336927,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T00:00:00Z","timestamp":1712880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,12]]},"DOI":"10.1145\/3597503.3639107","type":"proceedings-article","created":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T16:43:26Z","timestamp":1712940206000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA App"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5446-3081","authenticated-orcid":false,"given":"Fuman","family":"Xie","sequence":"first","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4855-1912","authenticated-orcid":false,"given":"Chuan","family":"Yan","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1039-2151","authenticated-orcid":false,"given":"Mark Huasong","family":"Meng","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, A*STAR, Singapore, Singapore"},{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-2912-4146","authenticated-orcid":false,"given":"Shaoming","family":"Teng","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Deakin University, Victoria, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6390-9890","authenticated-orcid":false,"given":"Guangdong","family":"Bai","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2023. OpenAI\/Models. Retrieved April 7 2023 from https:\/\/platform.openai.com\/docs\/models\/gpt-3-5"},{"key":"e_1_3_2_1_2_1","unstructured":"2024. PICO. Retrieved Janurary 9 2024 from https:\/\/github.com\/UQ-Trust-Lab\/PICO"},{"key":"e_1_3_2_1_3_1","unstructured":"Amazon Alexa. 2023. Set Up News and Flash Briefings for Alexa. https:\/\/www.amazon.com\/gp\/help\/customer\/display.html?nodeId=GXMFWZJ8FKRGLFFU"},{"key":"e_1_3_2_1_4_1","volume-title":"Alexa skills. Retrieved","year":"2023","unstructured":"Amazon. 2023. Alexa skills. Retrieved January 7, 2023 from https:\/\/www.amazon.com.au\/Alexa-Skills\/b?node=4931595051"},{"key":"e_1_3_2_1_5_1","unstructured":"Amazon Developer Documentation. 2022. Configure Permissions for Customer Information in Your Skill. https:\/\/developer.amazon.com\/en-US\/docs\/alexa\/custom-skills\/configure-permissions-for-customer-information-in-your-skill.html"},{"key":"e_1_3_2_1_6_1","volume-title":"Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie.","author":"Andow Benjamin","year":"2019","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie. 2019. PolicyLint: investigating internal privacy policy contradictions on google play. In 28th USENIX security symposium (USENIX security). 585--602."},{"key":"e_1_3_2_1_7_1","volume-title":"29th USENIX Security Symposium (USENIX Security).","author":"Andow Benjamin","year":"2020","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Serge Egelman. 2020. Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with POLICHECK. In 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484536"},{"key":"e_1_3_2_1_9_1","volume-title":"Practical Data Access Minimization in Trigger-Action Platforms. In 31st USENIX Security Symposium (USENIX Security)","author":"Chen Yunang","year":"2022","unstructured":"Yunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee, and Earlence Fernandes. 2022. Practical Data Access Minimization in Trigger-Action Platforms. In 31st USENIX Security Symposium (USENIX Security). Boston, MA, 2929--2945."},{"key":"e_1_3_2_1_10_1","volume-title":"Galactic ChitChat: Using Large Language Models to Converse with Astronomy Literature. Research Notes of the AAS 7 (09","author":"Ciuca Ioana","year":"2023","unstructured":"Ioana Ciuca and Yuan-Sen Ting. 2023. Galactic ChitChat: Using Large Language Models to Converse with Astronomy Literature. Research Notes of the AAS 7 (09 2023), 193."},{"key":"e_1_3_2_1_11_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In North American","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In North American Chapter of the Association for Computational Linguistics."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-023-32248-6"},{"key":"e_1_3_2_1_13_1","volume-title":"Jose Such, and Guillermo Suarez-Tangil.","author":"Edu Jide","year":"2021","unstructured":"Jide Edu, Xavi Ferrer Aran, Jose Such, and Guillermo Suarez-Tangil. 2021. SkillVet: Automated Traceability Analysis of Amazon Alexa Skills. IEEE Transactions on Dependable and Secure Computing (2021)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512289"},{"key":"e_1_3_2_1_15_1","volume-title":"Retrieved","author":"Parliament European","year":"2020","unstructured":"European Parliament. 2020. General Data Protection Regulation (GDPR). Retrieved July 26, 2023 from https:\/\/gdpr-info.eu\/"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568276"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","unstructured":"Maarten Grootendorst. 2020. KeyBERT: Minimal keyword extraction with BERT. 10.5281\/zenodo.4461265","DOI":"10.5281\/zenodo.4461265"},{"key":"e_1_3_2_1_18_1","volume-title":"BERTopic: Neural topic modeling with a class-based TF-IDF procedure. ArXiv abs\/2203.05794","author":"Grootendorst Maarten R.","year":"2022","unstructured":"Maarten R. Grootendorst. 2022. BERTopic: Neural topic modeling with a class-based TF-IDF procedure. ArXiv abs\/2203.05794 (2022)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Edward Guo Mehul Gupta Sarthak Sinha Karl R\u00f6ssler Marcos Tatagiba Ryojo Akagami Ossama Al-Mefty Taku Sugiyama Phillip E Stieg Gwynedd E Pickett et al. 2023. neuroGPT-X: Towards an Accountable Expert Opinion Tool for Vestibular Schwannoma. medRxiv (2023) 2023--02.","DOI":"10.1101\/2023.02.25.23286117"},{"key":"e_1_3_2_1_20_1","volume-title":"29th USENIX Security Symposium (USENIX Security). 2649--2666","author":"Guo Zhixiu","year":"2020","unstructured":"Zhixiu Guo, Zijin Lin, Pan Li, and Kai Chen. 2020. Skillexplorer: Understanding the behavior of skills in large scale. In 29th USENIX Security Symposium (USENIX Security). 2649--2666."},{"key":"e_1_3_2_1_21_1","volume-title":"spaCy 2: Natural language understanding with Bloom embeddings, convolutional neural networks and incremental parsing. To appear 7, 1","author":"Honnibal Matthew","year":"2017","unstructured":"Matthew Honnibal and Ines Montani. 2017. spaCy 2: Natural language understanding with Bloom embeddings, convolutional neural networks and incremental parsing. To appear 7, 1 (2017), 411--420."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539609"},{"key":"e_1_3_2_1_23_1","volume-title":"VITAS: Guided Model-based VUI Testing of VPA Apps. In 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE). 1--12","author":"Li Suwan","year":"2022","unstructured":"Suwan Li, Lei Bu, Guangdong Bai, Zhixiu Guo, Kai Chen, and Hanlin Wei. 2022. VITAS: Guided Model-based VUI Testing of VPA Apps. In 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE). 1--12."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.17"},{"key":"e_1_3_2_1_25_1","first-page":"543","article-title":"The cost of reading privacy policies","volume":"4","author":"McDonald Aleecia M","year":"2008","unstructured":"Aleecia M McDonald and Lorrie Faith Cranor. 2008. The cost of reading privacy policies. I\/S: A Journal of Law and Policy for the Information Society (ISJLP) 4 (2008), 543.","journal-title":"I\/S: A Journal of Law and Policy for the Information Society (ISJLP)"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.21105\/joss.00205"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1177\/0270467610365355"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1080\/1369118X.2018.1486870"},{"key":"e_1_3_2_1_29_1","unstructured":"OpenAI. 2021. GPT-3 powers the next generation of apps. https:\/\/openai.com\/blog\/gpt-3-apps"},{"key":"e_1_3_2_1_30_1","volume-title":"EDE-Fuzz: A Web API Fuzzer for Excessive Data Exposures. In 2024 IEEE\/ACM 46th International Conference on Software Engineering (ICSE). IEEE Computer Society, 519--530","author":"Pan Lianglu","year":"2023","unstructured":"Lianglu Pan, Shaanan Cohney, Toby Murray, and Van-Thuan Pham. 2023. EDE-Fuzz: A Web API Fuzzer for Excessive Data Exposures. In 2024 IEEE\/ACM 46th International Conference on Software Engineering (ICSE). IEEE Computer Society, 519--530."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355584"},{"key":"e_1_3_2_1_32_1","unstructured":"Mayk Caldas Ramos Shane S Michtavy Marc D Porosoff and Andrew D White. 2023. Bayesian Optimization of Catalysts With In-context Learning. (2023)."},{"key":"e_1_3_2_1_33_1","volume-title":"Retrieved","year":"2023","unstructured":"scikit-learn. 2023. sklearn.ensemble.IsolationForest. Retrieved July 26, 2023 from https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.ensemble.IsolationForest.html"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884855"},{"key":"e_1_3_2_1_35_1","volume-title":"Retrieved","author":"Thormundsson Bergur","year":"2023","unstructured":"Bergur Thormundsson. 2023. Virtual Assistant Technology - statistics & facts. Retrieved July 27, 2023 from https:\/\/www.statista.com\/topics\/5572\/virtual-assistants"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180196"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-95405-5_12"},{"key":"e_1_3_2_1_38_1","volume-title":"Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant Apps. In 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE).","author":"Xie Fuman","year":"2022","unstructured":"Fuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li, Lei Bu, Kai Chen, Zi Huang, and Guangdong Bai. 2022. Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant Apps. In 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE)."},{"key":"e_1_3_2_1_39_1","volume-title":"On the Quality of Privacy Policy Documents of Virtual Personal Assistant Applications. In 24th Privacy Enhancing Technologies Symposium (PETS).","author":"Yan Chuan","year":"2024","unstructured":"Chuan Yan, Fuman Xie, Mark Huasong Meng, Yanjun Zhang, and Guangdong Bai. 2024. On the Quality of Privacy Policy Documents of Virtual Personal Assistant Applications. In 24th Privacy Enhancing Technologies Symposium (PETS)."},{"key":"e_1_3_2_1_40_1","volume-title":"SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the Wild. In 31st USENIX Security Symposium (USENIX Security).","author":"Young Jeffrey","year":"2022","unstructured":"Jeffrey Young, Song Liao, Long Cheng, Hongxin Hu, and Huixing Deng. 2022. SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the Wild. In 31st USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.18293\/SEKE2018-180"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00016"},{"key":"e_1_3_2_1_43_1","volume-title":"POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Zhou Lu","year":"2023","unstructured":"Lu Zhou, Chengyongxiao Wei, Tong Zhu, Guoxing Chen, Xiaokuan Zhang, Suguo Du, Hui Cao, and Haojin Zhu. 2023. POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices. In 32nd USENIX Security Symposium (USENIX Security 23). 1073--1090."}],"event":{"name":"ICSE '24: IEEE\/ACM 46th International Conference on Software Engineering","location":"Lisbon Portugal","acronym":"ICSE '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639107","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639107","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:49:11Z","timestamp":1750286951000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639107"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,12]]},"references-count":43,"alternative-id":["10.1145\/3597503.3639107","10.1145\/3597503"],"URL":"https:\/\/doi.org\/10.1145\/3597503.3639107","relation":{},"subject":[],"published":{"date-parts":[[2024,4,12]]},"assertion":[{"value":"2024-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}