[论文解读] Measuring the Effectiveness of Privacy Policies for Voice Assistant Applications
本研究对亚马逊Alexa和谷歌助手平台上语音助手应用的隐私政策进行了首次大规模分析,采用自然语言处理(NLP)技术检测应用描述与政策之间的不一致之处。研究发现存在广泛问题,包括不符合规范的政策以及官方应用违反规定的情况,凸显了在透明度和可用性方面存在的关键漏洞。
Voice Assistants (VA) such as Amazon Alexa and Google Assistant are quickly and seamlessly integrating into people's daily lives. The increased reliance on VA services raises privacy concerns such as the leakage of private conversations and sensitive information. Privacy policies play an important role in addressing users' privacy concerns and informing them about the data collection, storage, and sharing practices. VA platforms (both Amazon Alexa and Google Assistant) allow third-party developers to build new voice-apps and publish them to the app store. Voice-app developers are required to provide privacy policies to disclose their apps' data practices. However, little is known whether these privacy policies are informative and trustworthy or not on emerging VA platforms. On the other hand, many users invoke voice-apps through voice and thus there exists a usability challenge for users to access these privacy policies. In this paper, we conduct the first large-scale data analytics to systematically measure the effectiveness of privacy policies provided by voice-app developers on two mainstream VA platforms. We seek to understand the quality and usability issues of privacy policies provided by developers in the current app stores. We analyzed 64,720 Amazon Alexa skills and 2,201 Google Assistant actions. Our work also includes a user study to understand users' perspectives on VA's privacy policies. Our findings reveal a worrisome reality of privacy policies in two mainstream voice-app stores, where there exists a substantial number of problematic privacy policies. Surprisingly, Google and Amazon even have official voice-apps violating their own requirements regarding the privacy policy.
研究动机与目标
- 评估第三方开发者在语音助手平台上提供的隐私政策的质量和信息丰富程度。
- 检测隐私政策与语音应用实际数据实践之间的不一致,尤其是在无法获取源代码的情况下。
- 理解用户对语音应用中隐私政策的认知感知及可用性挑战。
- 评估亚马逊和谷歌的官方语音应用是否符合其自身隐私政策要求。
提出的方法
- 从公开应用商店收集并分析了64,720个亚马逊Alexa技能和2,201个谷歌助手动作。
- 应用自然语言处理(NLP)技术,从隐私政策和应用描述中提取数据实践(收集、使用、共享)信息。
- 采用分层映射方法,将政策声明与应用描述进行对比,以检测不一致之处。
- 开展一项包含116名语音助手用户的用户研究,评估隐私政策在真实场景中的感知情况和可用性挑战。
- 根据平台特定的隐私政策要求,评估官方语音应用的合规性。
- 对政策的完整性、清晰度和一致性在各平台间的差异进行定量分析。
实验结果
研究问题
- RQ1亚马逊Alexa和谷歌助手平台上,语音应用开发者提供的隐私政策整体质量如何?
- RQ2在无法访问源代码的情况下,能否检测到隐私政策与实际数据实践之间的不一致?
- RQ3用户如何感知并使用语音助手应用中的隐私政策?
- RQ4亚马逊和谷歌的官方语音应用在多大程度上符合其自身的隐私政策要求?
主要发现
- 亚马逊和谷歌助手平台上大量隐私政策存在不完整、不清晰或未披露关键数据实践的问题。
- 超过10%的Alexa技能和近20%的谷歌助手动作的隐私政策缺失,或未涉及核心数据实践。
- 亚马逊和谷歌的官方语音应用均违反了其自身平台对隐私政策披露和内容的要求。
- 用户研究显示,50%的语音助手用户不知道其语音录音被制造商存储,表明政策可见性和理解度极低。
- 在分析的38%的Alexa技能和29%的谷歌助手动作中,检测到政策声明与应用描述之间存在不一致。
- 在两个平台中,仅有12%的隐私政策对三个核心问题提供了清晰、全面的回答:收集了哪些数据、如何使用这些数据、以及与谁共享。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。