论文标题
衡量语音助理申请的隐私政策的有效性
Measuring the Effectiveness of Privacy Policies for Voice Assistant Applications
论文作者
论文摘要
Amazon Alexa和Google Assistant等语音助手(VA)迅速而无缝地融入人们的日常生活中。对VA服务的依赖增加引起了隐私问题,例如私人对话和敏感信息的泄漏。隐私政策在解决用户的隐私问题以及向他们通报数据收集,存储和共享实践方面起着重要作用。 VA平台(Amazon Alexa和Google Assistant)允许第三方开发人员构建新的语音应用程序并将其发布到App Store。语音应用开发人员必须提供隐私政策,以披露其应用程序的数据实践。但是,这些隐私政策是否在新兴的VA平台上提供信息和值得信赖的知名度。另一方面,许多用户通过语音调用语音应用程序,因此对用户访问这些隐私政策的可用性挑战。在本文中,我们进行了第一个大规模数据分析,以系统地衡量语音应用程序开发人员在两个主流VA平台上提供的隐私政策的有效性。我们试图了解当前应用商店开发人员提供的隐私政策的质量和可用性问题。我们分析了64,720个亚马逊Alexa技能和2,201个Google Assistant Actions。我们的工作还包括一项用户研究,以了解用户对VA隐私政策的看法。我们的发现揭示了两个主流语音应用商店中隐私政策的令人担忧的现实,那里存在大量有问题的隐私政策。令人惊讶的是,Google和Amazon甚至有官方的语音应用程序违反了他们对隐私政策的要求。
Voice Assistants (VA) such as Amazon Alexa and Google Assistant are quickly and seamlessly integrating into people's daily lives. The increased reliance on VA services raises privacy concerns such as the leakage of private conversations and sensitive information. Privacy policies play an important role in addressing users' privacy concerns and informing them about the data collection, storage, and sharing practices. VA platforms (both Amazon Alexa and Google Assistant) allow third-party developers to build new voice-apps and publish them to the app store. Voice-app developers are required to provide privacy policies to disclose their apps' data practices. However, little is known whether these privacy policies are informative and trustworthy or not on emerging VA platforms. On the other hand, many users invoke voice-apps through voice and thus there exists a usability challenge for users to access these privacy policies. In this paper, we conduct the first large-scale data analytics to systematically measure the effectiveness of privacy policies provided by voice-app developers on two mainstream VA platforms. We seek to understand the quality and usability issues of privacy policies provided by developers in the current app stores. We analyzed 64,720 Amazon Alexa skills and 2,201 Google Assistant actions. Our work also includes a user study to understand users' perspectives on VA's privacy policies. Our findings reveal a worrisome reality of privacy policies in two mainstream voice-app stores, where there exists a substantial number of problematic privacy policies. Surprisingly, Google and Amazon even have official voice-apps violating their own requirements regarding the privacy policy.