IDPFilter: Mitigating interdependent privacy issues in third-party apps

被引:0
|
作者
Liu, Shuaishuai [1 ]
Biczok, Gergely [1 ,2 ,3 ]
机构
[1] Budapest Univ Technol & Econ, Dept Networked Syst & Serv, CrySyS Lab, Budapest, Hungary
[2] HUN REN BME Informat Syst Res Grp, Bugapest, Hungary
[3] Univ Michigan, Dept EECS, Ann Arbor, MI USA
关键词
Interdependent privacy; Third-party apps; Permissions; Information filtering; Application programming interface;
D O I
10.1016/j.cose.2025.104321
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Third-party applications have become an essential part of today's online ecosystem, enhancing the functionality of popular platforms. However, the intensive data exchange underlying their proliferation has raised concerns about interdependent privacy (IDP). This paper investigates the IDP issues of third-party apps that were previously not studied comprehensively. Specifically, first, we analyze the permission structure of multiple app platforms, identifying permissions that have the potential to cause interdependent privacy issues by enabling a user to share someone else's personal data with an app. Second, we collect datasets and characterize the extent to which existing apps request these permissions, revealing the relationship between characteristics such as the respective app platform, the app's type, and the number of interdependent privacy-related permissions it requests. Third, we analyze why IDP is neglected by both data protection regulations and app platforms and then devise the principles that should be followed when designing a mitigation solution. Finally, based on these principles and satisfying clearly defined objectives, we propose IDPFilter, a platform-agnostic API that enables application providers to minimize collateral information collection by filtering out data collected from their users, but implicating others as data subjects. We implement a proof-of-concept prototype, IDPTextFilter, that implements the filtering logic on textual data, and provide its initial performance evaluation concerning privacy, accuracy, and efficiency.
引用
收藏
页数:17
相关论文
共 50 条
  • [21] Effective Privacy Preservation in Third-Party Cloud Storage Auditing
    Chuang, Po-Jen
    Chuang, Han-Chun
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2019, 35 (01) : 125 - 135
  • [22] Privacy challenges in third-party location services (Invited paper)
    Damiani, Maria Luisa
    Cuijpers, Colette
    2013 IEEE 14TH INTERNATIONAL CONFERENCE ON MOBILE DATA MANAGEMENT (MDM 2013), VOL 2, 2013, : 63 - 66
  • [23] Dynamic privacy leakage analysis of Android third-party libraries
    He, Yongzhong
    Yang, Xuejun
    Hu, Binghui
    Wang, Wei
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 46 : 259 - 270
  • [24] Dynamic Privacy Leakage Analysis of Android Third-party Libraries
    He, Yongzhong
    Hu, Binghui
    Han, Zhen
    2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 275 - 280
  • [25] Privacy, Property, and Third-Party Esteem in Arendt's Constitutionalism
    Mcgroarty, Emmett
    Mcgroarty, Brendan
    LAWS, 2023, 12 (05)
  • [26] Using third-party purchasing to push third-party logistics
    Long, JS
    Zhao, J
    THIRD WUHAN INTERNATIONAL CONFERENCE ON E-BUSINESS: GLOBAL BUSINESS INTERFACE, 2004, : 400 - 404
  • [27] Protection of privacy by third-party encryption in genetic research in Iceland
    Gulcher, JR
    Kristjánsson, K
    Gudbjartsson, H
    Stefánsson, K
    EUROPEAN JOURNAL OF HUMAN GENETICS, 2000, 8 (10) : 739 - 742
  • [28] Mitigating Third-Party Risks: The Benefits of Extending Quality to the Supply Chain
    Fortner, Zillery A.
    Pharmaceutical Technology, 2021, 45 (09): : 56 - 60
  • [29] Third-party Privacy Certification as an Online Advertising Strategy: An Investigation of the Factors Affecting the Relationship between Third-party Certification and Initial Trust
    Kim, Kyongseok
    Kim, Jooyoung
    JOURNAL OF INTERACTIVE MARKETING, 2011, 25 (03) : 145 - 158
  • [30] Research on Third-Party Libraries in Android Apps: A Taxonomy and Systematic Literature Review
    Zhan, Xian
    Liu, Tianming
    Fan, Lingling
    Li, Li
    Chen, Sen
    Luo, Xiapu
    Liu, Yang
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4181 - 4213