Wed 6 Sep 2023 15:45 - 16:15 at f142 - Security & Privacy Chair(s): Seok-Won Lee

Mobile applications (apps) provide users valuable benefits at the risk of exposing users to privacy harms. Improving privacy in mobile apps faces several challenges, in particular, that many apps are developed by low resourced software development teams, such as end-user programmers or in startups. In addition, privacy risks are primarily known to users, which can make it difficult for developers to prioritize privacy for sensitive data. In this paper, we introduce a novel, lightweight method that allows app developers to elicit scenarios and privacy risk scores from users directly using only an app screenshot. The technique relies on named entity recognition (NER) to identify information types in user-authored scenarios, which are then fed in real-time to a privacy risk survey that users complete. The best-performing NER model predicts information types with a weighted average precision of 0.70 and recall of 0.72, after post-processing to remove false positives. The model was trained on a labeled 300-scenario corpus, and evaluated in an end-to-end evaluation using an additional 203 scenarios yielding 2,338 user-provided privacy risk scores. Finally, we discuss how developers can use the risk scores to prioritize, select and apply privacy design strategies in the context of four user-authored scenarios.

Wed 6 Sep

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

15:45 - 16:45
Security & PrivacyJournal-First / Research Papers at f142
Chair(s): Seok-Won Lee Ajou University
15:45
30m
Paper
Mobile Application Privacy Risk Assessments from User-authored ScenariosArtifact Available
Research Papers
A: Tianjian Huang Carnegie Mellon University, A: Vaishnavi Kaulagi Carnegie Mellon University, A: Mitra Bokaei Hosseini University of Texas at San Antonio, A: Travis Breaux Carnegie Mellon University
Pre-print
16:15
30m
Talk
The Importance of Security is in the Eye of the Beholder: Cultural, Organizational, and Personal Factors Affecting the Implementation of Security by Design
Journal-First
A: Renana Arizon-Peretz University of Haifa, A: Irit Hadar University of Haifa, A: Gil Luria University of Haifa