{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:38:54Z","timestamp":1784342334630,"version":"3.55.0"},"reference-count":77,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2024,7,12]],"date-time":"2024-07-12T00:00:00Z","timestamp":1720742400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2024,7,12]]},"abstract":"<jats:p>\n                    Android has empowered third-party apps to access data and services on mobile devices since its genesis.This involves a wide spectrum of user privacy-sensitive data, such as the device ID and location. In recent years, Android has taken proactive measures to adapt its access control policies for such data, in response to the increasingly strict privacy protection regulations around the world. When each new Android version is released, its privacy changes induced by the version evolution are transparently disclosed, and we refer to them as\n                    <jats:italic toggle=\"yes\">documented privacy changes<\/jats:italic>\n                    (DPCs). Implementing DPCs in Android OS is a non-trivial task, due to not only the dispersed nature of those access control points within the OS, but also the challenges posed by backward compatibility. As a result, whether the actual access control enforcement in the OS implementations aligns with the disclosed DPCs becomes a critical concern.\n                  <\/jats:p>\n                  <jats:p>\n                    In this work, we conduct the first systematic study on the consistency between the\n                    <jats:italic toggle=\"yes\">operational behaviors<\/jats:italic>\n                    of the OS at runtime and the\n                    <jats:italic toggle=\"yes\">officially disclosed<\/jats:italic>\n                    DPCs. We propose D\n                    <jats:sc>op<\/jats:sc>\n                    C\n                    <jats:sc>heck<\/jats:sc>\n                    , an automatic DPC-driven testing framework equipped with a large language model (LLM) pipeline. It features a serial of analysis to extract the ontology from the privacy change documents written in natural language, and then harnesses the few-shot capability of LLMs to construct test cases for the detection of\n                    <jats:italic toggle=\"yes\">DPC-compliance issues<\/jats:italic>\n                    in OS implementations.We apply D\n                    <jats:sc>op<\/jats:sc>\n                    C\n                    <jats:sc>heck<\/jats:sc>\n                    with the latest versions (10 to 13) of Android Open Source Project (AOSP). Our evaluation involving 79 privacy-sensitive APIs demonstrates that D\n                    <jats:sc>op<\/jats:sc>\n                    C\n                    <jats:sc>heck<\/jats:sc>\n                    can effectively recognize DPCs from Android documentation and generate rigorous test cases. Our study reveals that the\n                    <jats:italic toggle=\"yes\">status quo<\/jats:italic>\n                    of the DPC-compliance issues is concerning, evidenced by 19 bugs identified by D\n                    <jats:sc>op<\/jats:sc>\n                    C\n                    <jats:sc>heck<\/jats:sc>\n                    . Notably, 12 of them are discovered in Android 13 and 6 in Android 10 for the first time, posing more than 35% Android users to the risk of privacy leakage. Our findings should raise an alert to Android users and app developers on the DPC compliance issues when using or developing an app, and would also underscore the necessity for Google to comprehensively validate the actual implementation against its privacy documentation prior to the OS release.\n                  <\/jats:p>","DOI":"10.1145\/3660826","type":"journal-article","created":{"date-parts":[[2024,7,12]],"date-time":"2024-07-12T10:22:09Z","timestamp":1720779729000},"page":"2701-2724","source":"Crossref","is-referenced-by-count":8,"title":["Investigating Documented Privacy Changes in Android OS"],"prefix":"10.1145","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4855-1912","authenticated-orcid":false,"given":"Chuan","family":"Yan","sequence":"first","affiliation":[{"name":"University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1039-2151","authenticated-orcid":false,"given":"Mark Huasong","family":"Meng","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"},{"name":"Institute for Infocomm Research at A*STAR, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5446-3081","authenticated-orcid":false,"given":"Fuman","family":"Xie","sequence":"additional","affiliation":[{"name":"University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6390-9890","authenticated-orcid":false,"given":"Guangdong","family":"Bai","sequence":"additional","affiliation":[{"name":"University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7,12]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"2023. Beautiful Soup Documentations. https:\/\/www.crummy.com\/software\/BeautifulSoup\/bs4\/doc\/"},{"key":"e_1_3_1_3_2","unstructured":"2024. Investigating Documented Privacy Changes in Android OS (Source Code). https:\/\/github.com\/DopCheck\/DopCheck"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2310.07290"},{"key":"e_1_3_1_6_2","article-title":"PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play","author":"Andow Benjamin","year":"2019","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie. 2019. PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play. In USENIX Security Symposium (USENIX security).","journal-title":"USENIX Security Symposium (USENIX security)"},{"key":"e_1_3_1_7_2","unstructured":"AppBrain. 2023. The most common Android OS versions currently installed on Android devices (phones and tablets) used by AppBrain SDK users. https:\/\/www.appbrain.com\/stats\/top-android-sdk-versions"},{"key":"e_1_3_1_8_2","unstructured":"AppBrain. 2023. Number of Android apps on Google Play. https:\/\/www.appbrain.com\/stats\/number-of-android-apps"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2011.6100103"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-021-3414-7"},{"key":"e_1_3_1_11_2","unstructured":"Baidu. 2022. Awesome multilingual OCR toolkits based on PaddlePaddle. https:\/\/github.com\/PaddlePaddle\/PaddleOCR"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387469"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","unstructured":"Mark Chen Jerry Tworek Heewoo Jun Qiming Yuan Henrique Ponde de Oliveira Pinto Jared Kaplan Harri Edwards Yuri Burda Nicholas Joseph Greg Brockman et al. 2021. Evaluating large language models trained on code. (2021). https:\/\/doi.org\/10.48550\/arXiv.2107.03374 10.48550\/arXiv.2107.03374","DOI":"10.48550\/arXiv.2107.03374"},{"key":"e_1_3_1_14_2","unstructured":"Chinese people's congress. 2021. Personal Information Protection Law of the People\u2019s Republic of China.(2021). https:\/\/digichina.stanford.edu\/work\/translation-personal-information-protection-law-of-the-peoples-republic-of-china-effective-nov-1-2021\/"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.7980923"},{"key":"e_1_3_1_16_2","first-page":"1","article-title":"Privacy Analysis of Period Tracking Mobile Apps in the Post-Roe v. Wade Era","author":"Dong Zikan","year":"2022","unstructured":"Zikan Dong, Liu Wang, Hao Xie, Guoai Xu, and Haoyu Wang. 2022. Privacy Analysis of Period Tracking Mobile Apps in the Post-Roe v. Wade Era. In Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE). 1-6. https:\/\/doi.org\/10.5281\/zenodo.7980923","journal-title":"Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE)"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.02.007"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3608137"},{"key":"e_1_3_1_19_2","unstructured":"Google. 2019. Android 10 privacy change. https:\/\/developer.android.com\/about\/versions\/10\/privacy\/changes"},{"key":"e_1_3_1_20_2","unstructured":"Google. 2020. Android 11 privacy change. https:\/\/developer.android.com\/about\/versions\/11\/privacy"},{"key":"e_1_3_1_21_2","unstructured":"Google. 2021. Android 12 change: Request location access at runtime. https:\/\/developer.android.com\/develop\/sensors-and-location\/location\/permissions%23request-location-access-runtime"},{"key":"e_1_3_1_22_2","unstructured":"Google. 2021. Android 12 privacy change. https:\/\/developer.android.com\/about\/versions\/12\/summary"},{"key":"e_1_3_1_23_2","unstructured":"Google. 2021. Device Identifiers. https:\/\/source.android.com\/docs\/core\/connect\/device-identifiers?hl=en"},{"key":"e_1_3_1_24_2","unstructured":"Google. 2022. Android 13 change: Granular media permissions. https:\/\/developer.android.com\/about\/versions\/13\/behavior-changes-13#granular-media-permissions"},{"key":"e_1_3_1_25_2","unstructured":"Google. 2022. Android 13 privacy change. https:\/\/developer.android.com\/about\/versions\/13\/summary"},{"key":"e_1_3_1_26_2","unstructured":"Google. 2023. Android 12 change: Approximate location. When an app requests precise location permissions users can now opt to grant only approximate location permissions instead. https:\/\/developer.android.com\/training\/location\/permissions#accuracy"},{"key":"e_1_3_1_27_2","unstructured":"Google. 2023. Android 13 change: Hide sensitive content from clipboard. https:\/\/developer.android.com\/about\/versions\/13\/behavior-changes-all#copy-sensitive-content"},{"key":"e_1_3_1_28_2","unstructured":"Google. 2023. Android 14 Beta. https:\/\/developer.android.com\/about\/versions\/14"},{"key":"e_1_3_1_29_2","unstructured":"Google. 2023. Android 14 change: Schedule exact alarms are denied by defaul. https:\/\/developer.android.com\/about\/versions\/14\/changes\/schedule-exact-alarms"},{"key":"e_1_3_1_30_2","unstructured":"Google. 2023. Android 14 features and changes list. https:\/\/developer.android.com\/about\/versions\/14\/summary"},{"key":"e_1_3_1_31_2","unstructured":"Google. 2023. Determine sensitive data access needs. https:\/\/developer.android.com\/games\/develop\/permissions?hl=en"},{"key":"e_1_3_1_32_2","unstructured":"Google. 2023. Permissions updates in Android 11. https:\/\/developer.android.com\/about\/versions\/11\/privacy\/permissions"},{"key":"e_1_3_1_33_2","unstructured":"Google. 2023. Request runtime permissions. https:\/\/developer.android.com\/training\/permissions\/requesting"},{"key":"e_1_3_1_34_2","unstructured":"Google. 2023. TelephonyManager class summary. https:\/\/developer.android.com\/reference\/android\/telephony\/TelephonyManager"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238185"},{"key":"e_1_3_1_36_2","doi-asserted-by":"crossref","unstructured":"Marti A Hearst . 1992. Automatic acquisition of hyponyms from large text corpora. In COLING 1992 Volume 2: The 14th International Conference on Computational Linguistics.","DOI":"10.3115\/992133.992154"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556912"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510203"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3470133"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2988396"},{"key":"e_1_3_1_41_2","article-title":"Internet jones and the raiders of the lost trackers: An archaeological study of web tracking from 1996 to 2016","author":"Lerner Ada","year":"2016","unstructured":"Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, and Franziska Roesner. 2016. Internet jones and the raiders of the lost trackers: An archaeological study of web tracking from 1996 to 2016. In 25th USENIX Security Symposium (USENIX Security).","journal-title":"25th USENIX Security Symposium (USENIX Security)"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00028"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3213846.3213857"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09764-z"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643674"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3544968"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2305.09434"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3274153"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420958"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613097"},{"key":"e_1_3_1_51_2","article-title":"Post-GDPR threat hunting on android phones: dissecting OS-level safeguards of user-unresettable identifiers","author":"Zhang Qing","year":"2023","unstructured":"Mark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng, Yanjun Zhang, Guangdong Bai, Zhi Liu, Sin G Teo, and Jin Song Dong. 2023. Post-GDPR threat hunting on android phones: dissecting OS-level safeguards of user-unresettable identifiers. In The Network and Distributed System Security Symposium (NDSS).","journal-title":"The Network and Distributed System Security Symposium (NDSS)"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3025453.3025706"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/2742647.2742653"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2017.10.032"},{"key":"e_1_3_1_55_2","unstructured":"OpenAI. 2023. GPT-4 Technical Report."},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2304.03277"},{"key":"e_1_3_1_57_2","unstructured":"Personal Data Protection Commission. 2012. PERSONAL DATA PROTECTION ACT 2012. (2012). https:\/\/sso.agc.gov.sg\/Act\/PDPA2012"},{"key":"e_1_3_1_58_2","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2018.23353","article-title":"Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem","author":"Razaghpanah Abbas","year":"2018","unstructured":"Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill, et al. 2018. Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem. In The 25th Annual Network and Distributed System Security Symposium (NDSS).","journal-title":"The 25th Annual Network and Distributed System Security Symposium (NDSS)"},{"key":"e_1_3_1_59_2","article-title":"50 ways to leak your data: An exploration of apps' circumvention of the android permissions system","author":"Reardon Joel","year":"2019","unstructured":"Joel Reardon, Alvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina-Rodriguez, and Serge Egelman. 2019. 50 ways to leak your data: An exploration of apps' circumvention of the android permissions system. In 28th USENIX security symposium (USENIX security).","journal-title":"28th USENIX security symposium (USENIX security)"},{"key":"e_1_3_1_60_2","unstructured":"Spacy. 2020. SpaCy Documentations. https:\/\/spacy.io"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2017.2779824"},{"key":"e_1_3_1_62_2","unstructured":"State of California Department. 2018. California Consumer Privacy Act (CCPA). (2018). https:\/\/oag.ca.gov\/privacy\/ccpa"},{"key":"e_1_3_1_63_2","unstructured":"Statista. 2023. Global market share held by mobile operating systems from 1st quarter 2009 to 2nd quarter 2023. https:\/\/www.statista.com\/statistics\/272698\/global-market-share-held-by-mobile-operating-systems-since-2009\/"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/MOBILSoft59058.2023.00009"},{"key":"e_1_3_1_65_2","unstructured":"The European Parliament. 2016. GDPR-Right to be Informed. https:\/\/gdpr-info.eu\/issues\/right-to-be-informed\/"},{"key":"e_1_3_1_66_2","article-title":"General Data Protection Regulation","author":"The European Parliament","year":"2016","unstructured":"The European Parliament. 2016. General Data Protection Regulation. Official Journal of the European Union (2016).","journal-title":"Official Journal of the European Union"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2307.04346"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2303.03846"},{"key":"e_1_3_1_69_2","unstructured":"B. Wolford . 2022. What are the GDPR fines? https:\/\/gdpr.eu\/fines\/"},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380357"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639107"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3560416"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3520312.3534862"},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0028"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560607"},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0016"},{"key":"e_1_3_1_77_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2309.10253"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00137"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3660826","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3660826","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T07:53:56Z","timestamp":1770191636000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3660826"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,12]]},"references-count":77,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2024,7,12]]}},"alternative-id":["10.1145\/3660826"],"URL":"https:\/\/doi.org\/10.1145\/3660826","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7,12]]}}}