{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T05:15:46Z","timestamp":1765862146629,"version":"3.48.0"},"reference-count":26,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T00:00:00Z","timestamp":1765497600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Research Grants Council of the Hong Kong Special Administrative Region","award":["UGC\/FDS14\/E01\/21"],"award-info":[{"award-number":["UGC\/FDS14\/E01\/21"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Smart phones have become an integral part of our lives in modern society, as we carry and use them throughout a day. However, this \u201cbody part\u201d may maliciously collect and leak our personal information without our knowledge. When we install mobile applications on our smart phones and grant their permission requests, these apps can use sensors embedded in the smart phones and the stored data to gather and infer our personal information, preferences, and habits. In this paper, we present our preliminary results on quantifying the privacy risk of mobile applications by assessing whether requested permissions are necessary based on app descriptions through textual entailment decided by language models (LMs). We observe that despite incorporating various improvements of LMs proposed in the literature for natural language processing (NLP) tasks, the performance of the trained model remains far from ideal.<\/jats:p>","DOI":"10.3390\/jcp5040111","type":"journal-article","created":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T15:27:20Z","timestamp":1765553240000},"page":"111","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Quantifying Privacy Risk of Mobile Apps as Textual Entailment Using Language Models"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1845-7597","authenticated-orcid":false,"given":"Chris Y. T.","family":"Ma","sequence":"first","affiliation":[{"name":"The Department of Computer Science, The Hang Seng University of Hong Kong, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Dagan, I., Glickman, O., and Magnini, B. (2005). The pascal recognising textual entailment challenge. Proceedings of the Machine Learning Challenges Workshop, Springer.","DOI":"10.1007\/11736790_9"},{"key":"ref_2","unstructured":"Dagan, I., Roth, D., Zanzotto, F., and Sammons, M. (2022). Recognizing Textual Entailment: Models and Applications, Springer Nature."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Finifter, M., Chin, E., Hanna, S., and Wagner, D. (2011, January 17). A survey of mobile malware in the wild. Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, Chicago, IL, USA.","DOI":"10.1145\/2046614.2046618"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Lin, J., Amini, S., Hong, J.I., Sadeh, N., Lindqvist, J., and Zhang, J. (2012, January 5\u20138). Expectation and purpose: Understanding users\u2019 mental models of mobile app privacy through crowdsourcing. Proceedings of the 2012 ACM Conference on Ubiquitous Computing, Pittsburgh, PA, USA.","DOI":"10.1145\/2370216.2370290"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Viennot, N., Garcia, E., and Nieh, J. (2014, January 16\u201320). A measurement study of google play. Proceedings of the 2014 ACM International Conference on Measurement and Modeling of Computer Systems, Austin, TX, USA.","DOI":"10.1145\/2591971.2592003"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"57829","DOI":"10.1109\/ACCESS.2019.2912210","article-title":"AC-Net: Assessing the consistency of description and permission in Android apps","volume":"7","author":"Feng","year":"2019","journal-title":"IEEE Access"},{"key":"ref_7","unstructured":"Devlin, J., Chang, M.W., Lee, K., and Toutanova, K. (2019, January 2\u20137). BERT: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the NAACL-HLT, Minneapolis, MN, USA."},{"key":"ref_8","first-page":"5998","article-title":"Attention is all you need","volume":"30","author":"Vaswani","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Gururangan, S., Marasovi\u0107, A., Swayamdipta, S., Lo, K., Beltagy, I., Downey, D., and Smith, N.A. (2020). Don\u2019t stop pretraining: Adapt language models to domains and tasks. arXiv.","DOI":"10.18653\/v1\/2020.acl-main.740"},{"key":"ref_10","unstructured":"Liu, Y. (2019). RoBERTa: A robustly optimized BERT pretraining approach. arXiv."},{"key":"ref_11","unstructured":"He, P., Liu, X., Gao, J., and Chen, W. (2020). DeBERTa: Decoding-enhanced BERT with disentangled attention. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Han, X., Liu, Z., Jiang, X., Sun, M., and Liu, Q. (2019). ERNIE: Enhanced language representation with informative entities. arXiv.","DOI":"10.18653\/v1\/P19-1139"},{"key":"ref_13","unstructured":"Zhou, J., You, C., Li, X., Liu, K., Liu, S., Qu, Q., and Zhu, Z. (2022). Are all losses created equal: A neural collapse perspective. arXiv."},{"key":"ref_14","unstructured":"Gunel, B., Du, J., Conneau, A., and Stoyanov, V. (2020). Supervised contrastive learning for pre-trained language model fine-tuning. arXiv."},{"key":"ref_15","unstructured":"Oord, A.v.d., Li, Y., and Vinyals, O. (2018). Representation learning with contrastive predictive coding. arXiv."},{"key":"ref_16","first-page":"18661","article-title":"Supervised contrastive learning","volume":"33","author":"Khosla","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Lin, T.Y., Goyal, P., Girshick, R., He, K., and Doll\u00e1r, P. (2017, January 22\u201329). Focal loss for dense object detection. Proceedings of the IEEE International Conference on Computer Vision, Venice, Italy.","DOI":"10.1109\/ICCV.2017.324"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Li, X., Sun, X., Meng, Y., Liang, J., Wu, F., and Li, J. (2019). Dice loss for data-imbalanced NLP tasks. arXiv.","DOI":"10.18653\/v1\/2020.acl-main.45"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic minority over-sampling technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_20","unstructured":"Ma, E.K. (2025, February 10). nlpaug: Data Augmentation for NLP. Available online: https:\/\/github.com\/makcedward\/nlpaug."},{"key":"ref_21","unstructured":"He, P., Gao, J., and Chen, W. (2021). DeBERTaV3: Improving deberta using electra-style pre-training with gradient-disentangled embedding sharing. arXiv."},{"key":"ref_22","unstructured":"Loshchilov, I., and Hutter, F. (2017). Decoupled weight decay regularization. arXiv."},{"key":"ref_23","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume":"35","author":"Wei","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_24","unstructured":"Brown, T.B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., and Askell, A. (2020). Language models are few-shot learners. arXiv."},{"key":"ref_25","unstructured":"Wei, J., Bosma, M., Zhao, V.Y., Guu, K., Yu, A.W., Lester, B., Du, N., Dai, A.M., and Le, Q.V. (2021). Finetuned language models are zero-shot learners. arXiv."},{"key":"ref_26","first-page":"22199","article-title":"Large language models are zero-shot reasoners","volume":"35","author":"Kojima","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/111\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T05:11:54Z","timestamp":1765861914000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/111"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,12]]},"references-count":26,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040111"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040111","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,12,12]]}}}