There is a newer version of the record available.

Published June 12, 2023 | Version 1.0

Mobile Application Privacy Risk Assessments from User-authored Scenarios

  • 1. Carnegie Mellon University
  • 2. University of Texas at San Antonio

Description

Mobile applications (apps) provide users valuable benefits at the risk of exposing users to privacy harms. Improving privacy in mobile apps faces several challenges, in particular, that many apps are developed by low resourced software development teams, such as end-user programmers or in startups. In addition, privacy risks are primarily known to users, which can make it difficult for developers to prioritize privacy for sensitive data. In this paper, we introduce a novel, lightweight method that allows app developers to elicit scenarios and privacy risk scores from users directly using only an app screenshot. The technique relies on named entity recognition (NER) to identify information types in user-authored scenarios, which are then fed in real-time to a privacy risk survey that users complete. The best-performing NER model predicts information types with a weighted average precision of 0.70 and recall of 0.72, after post-processing to remove false positives. The model was trained on a labeled 300-scenario corpus, and evaluated in an end-to-end evaluation using an additional 203 scenarios yielding 2,338 user-provided privacy risk scores. Finally, we discuss how developers can use the risk scores to prioritize, select and apply privacy design strategies in
the context of four user-authored scenarios.

Files

re2023-privacy-risk-scoring.zip

Files (4.3 MB)

Name Size Download all
md5:a7b5a5fe2ca4894209b9d7a3f25cb006
4.3 MB Preview Download

Additional details

Funding

U.S. National Science Foundation
SHF:Small:Privacy Impact and Risk Assessment at Design-Time 2007298