REVIEW 5 major objections 5 minor 95 references
Privacy Bills of Materials: A Transparent Privacy Information Inventory for Collaborative Privacy Notice Generation in Mobile App Development
T0 review · 5 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read PriBOM, a UI-widget-indexed privacy information inventory, enables transparent, collaborative, and more accurate privacy notice generation in mobile app development, according to a 150-participant survey.
desk verdict Useful new privacy-inventory concept, but the 'accurate' claim outruns the evidence -- the survey only measures perceived usefulness, and the pre-fill is never validated against ground truth. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the PriBOM table: a privacy information inventory whose rows are UI widgets and whose columns are organized into four sections: UI Widget Identifier, Codebase and Permission, Third-Party Library, and Privacy Notice Disclosure. The UI widget is the pivot because it is the visible element users interact with, the component that triggers data-handling callbacks, and therefore a vocabulary that front-end developers, back-end developers, UI designers, and legal teams can share. The pre-fill is a modular static-analysis pipeline that disassembles the APK, extracts widgets and their callback methods, builds call graphs for those callbacks, extracts reachable Android permissions, maps permissions to data types, detects third-party libraries, and matches segmented privacy-policy sentences and privacy-label declarations back to those data types. This machinery operationalizes the paper's two named benefits: tracing from a reported UI problem back to code and disclosures, and tracking from a code change forward to every notice entry that needs updating.
What would settle it
Run the pre-fill on a set of Android apps known to access sensitive data through reflection or native code and check whether PriBOM's inventory omits the corresponding permissions and privacy-notice disclosures; any such omission would falsify the claim that the inventory supports accurate notice generation for sophisticated apps.
Extended reading notes
Core claim
The paper's central claim is that a UI-widget-indexed privacy inventory, called PriBOM, lets mobile development teams generate and keep privacy notices aligned with actual app behavior. Each widget anchors four sections of information: its identifier and source, the events and Android permissions in the codebase behind it, the third-party libraries it touches, and the corresponding statements in the privacy policy and privacy label disclosures. The authors provide a pre-fill that extracts widgets, callbacks, and permissions from an APK through static analysis, maps permissions to data types, detects third-party libraries, and segments existing privacy policies and labels to fill the disclosure fields. In a survey of 150 participants spanning developers, UI designers, project managers, and legal team members, they report positive perceived usefulness, with 83.33% agreement that PriBOM enhances privacy-related communication, 85.3% for design intuitiveness, 72% for traceability, and 78.76% for information relevance. They conclude that PriBOM is a systematic solution for privacy support in mobile app DevOps, while noting that real-world practicability still needs verification.
Load-bearing premise
The load-bearing premise is that Likert-scale agreement from 150 survey participants, many of them junior developers in teams of under ten people, predicts whether PriBOM will actually improve privacy-notice accuracy and be adopted in large, complex development teams.
Editorial extensions
If this is right
- When a user reports a privacy issue on a particular screen element, the team can trace from that widget back to the handler, permissions, and code paths involved.
- When a code change alters data practices, PriBOM lets the team track forward to every privacy policy and label entry that must be updated.
- Legal and non-technical roles gain a common widget-level vocabulary for privacy discussions, reducing reliance on a few privacy specialists who carry the work alone.
- The pre-fill pipeline can populate much of the inventory automatically from the APK and existing privacy notices, lowering the burden of initial setup.
- PriBOM is designed as a modifiable format and a modular pipeline, so teams can customize fields or swap in stronger analysis modules and adapt it beyond Android to iOS and other software contexts.
Reading between the lines
- The same widget-level index could be extended into an automated notice-diffing tool: when a code change alters a widget's call graph, the corresponding policy and label entries could be flagged for revision within the same commit; the paper motivates this need but does not build it.
- Because the pre-fill relies on static analysis, a runtime-monitoring companion could catch data practices that are invisible statically, such as reflection, native code, or permission circumvention; the paper explicitly sets these aside as a trade-off in favor of ease of use.
- Adoption may hinge less on the design than on maintenance cost: participants already flagged learning curves, team habits, and the effort to keep the inventory current, so the decisive test is whether teams sustain PriBOM after the initial pre-fill.
- The widget-as-pivot idea generalizes to any interactive software with a UI layer, such as web apps, desktop software, or IoT dashboards, although the paper only demonstrates the concept on Android.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces PriBOM (Privacy Bills of Materials), a UI-widget-indexed privacy information inventory intended to support transparent, collaborative, and accurate generation of privacy notices in mobile app development. The authors derive three developer-facing privacy challenges from a small literature review, design PriBOM with four sections (UI Widget Identifier, Codebase and Permission, Third-Party Library, and Privacy Notice Disclosure), and present a pre-fill pipeline combining static analysis and privacy notice analysis. They evaluate PriBOM through a 150-participant Prolific survey measuring perceived usefulness, finding positive agreement on intuitiveness, traceability, and communication. The paper claims that PriBOM enables accurate privacy notice generation, but the evaluation only supports perceived usefulness, and the authors themselves note that real practicability requires further verification.
Significance. If PriBOM's central claims were fully validated, the concept could provide a genuinely useful bridge between technical and non-technical roles in privacy documentation and maintenance, addressing a real gap in existing privacy notice tools. The paper's strengths include a clear and well-motivated artifact design, a modular pre-fill pipeline built from established tools (JADX, GATOR, AndroGuard, LibScan), a relatively large survey (150 participants), and public availability of the implementation and questionnaire. However, the headline claim of 'accurate' notice generation is not validated: the pre-fill is never checked against ground truth, and the survey measures only self-reported agreement. The sample also skews toward junior developers in small teams, which does not match the paper's motivating scenario of large, crowded development teams. The significance is therefore conditional on reframing the claims to match the evidence or adding objective validation.
major comments (5)
- [Abstract; Section 4.1] The central claim that PriBOM enables 'accurate' generation of privacy notices (Abstract and Section 1) is not supported by the evidence in the paper. The pre-fill pipeline (Section 4.1 static analysis and Section 4.2 privacy notice analysis) is never evaluated against ground-truth privacy practices; no precision/recall, no comparison with existing generators, and no user study using the actual pre-fill output are reported. The example in Table 2 is a single hand-picked row without verification of correctness. To support the accuracy claim, the authors should add an objective evaluation of pre-fill correctness on a benchmark of apps with known privacy practices, or substantially qualify the claim to perceived usefulness only.
- [Section 5.2; Table 3] The participant sample does not match the paper's motivating scenario. The authors motivate PriBOM for 'sophisticated mobile apps with complex features and in crowded development teams' (Section 1), but Table 3 shows that 39% of participants are junior developers and 59% work in teams of fewer than 10 people. The survey therefore provides limited evidence about the target population. The authors should either recruit participants from large, multi-role teams (e.g., with legal and design roles) or explicitly narrow the claimed scope of the findings.
- [Section 5.4; Table 4] The survey results are reported as mean Likert scores and agreement percentages without inferential statistics or a baseline comparison. Statements such as 'significantly higher' in Section 5.4.2 (e.g., legal team vs. UI designers on S10) are not backed by significance tests, and the absence of a control/baseline means the positive responses may reflect acquiescence bias or the participants' desire to please the researchers. The authors should report appropriate statistical tests and discuss the absence of a baseline, or explicitly frame the analysis as descriptive.
- [Section 6; Conclusion] The Limitations section candidly acknowledges that pre-fill quality depends on static analysis performance and that 'real practicability needs to be further verified,' but the abstract and conclusion repeat the unqualified claim that PriBOM supports 'accurate' notice generation. The main text should carry these qualifications forward, for example by replacing 'accurate' in the headline with 'transparent and collaborative' and stating that accuracy of the pre-fill is future work.
- [Section 3.1] The UI-widget granularity deliberately excludes non-UI components, and the authors acknowledge that this 'may lead to gaps in capturing practices that circumvent standard permission protocols.' Since privacy notices must be comprehensive to be accurate, this design trade-off directly threatens the 'accurate' part of the central claim. The paper should either evaluate the extent of such gaps (e.g., by analyzing how many privacy-relevant data flows are not reachable from UI widgets) or explicitly state that PriBOM targets a subset of privacy practices.
minor comments (5)
- [Section 1] In the contributions list, 'comprehsnsively' should be 'comprehensively'.
- [Section 5.4.2] The text states that 'senior developers agree more than junior developers' on S26, but then reports scores for senior developers (4.05) and UI designers (3.78); the comparison should be against junior developers, not UI designers, or the text should be corrected.
- [References] Reference [8] is titled 'Iubenda' but the URL points to termly.io; this appears to be a citation error and should be corrected to the appropriate service.
- [Section 6] The phrase 'access the usefulness' should be 'assess the usefulness'.
- [Table 4] The abbreviations 'Ave.' and 'Distr.' in Table 4's header are not defined in the caption; they should be spelled out or defined.
Circularity Check
No significant circularity: PriBOM's conclusion is a perception survey explicitly labeled as such, and the pre-fill reuses external tools without fitting parameters to its own claims.
full rationale
The paper's central claim is that PriBOM facilitates transparent, collaborative, and accurate privacy notice generation, supported by a 150-participant survey of perceived usefulness. This is a design-and-survey paper, not a quantitative derivation, so there is no fitted parameter or equation whose output is forced by an input. The pre-fill pipeline (Section 4.1) is assembled from external tools (JADX, GATOR, AndroGuard, LibScan) and prior policy-segmentation work [66, 84]; no parameter is fitted to the survey data, and no survey outcome is used to calibrate the pre-fill. The survey statements (Table 4) directly ask participants to rate the design's intuitiveness, traceability, relevance, and communication value, and the paper explicitly frames the result as 'perceived usefulness' (Section 5.1) and acknowledges that 'real practicability needs to be further verified' (Section 6). The self-citations [66, 67, 82] are used as module references and questionnaire-design references, not as a uniqueness theorem or as the sole justification for the central claim; they are not load-bearing in a circular sense. The main weakness is evidentiary—no ground-truth validation of the pre-fill's accuracy and only perceptual evidence for usefulness—but that is a correctness-risk limitation, not a circular derivation.
Assumptions & free parameters
assumptions (3)
- domain assumption UI widgets are an adequate pivot for capturing privacy-relevant data practices in mobile apps.
- domain assumption The pre-fill tools (JADX, GATOR, AndroGuard, LibScan, policy segmenter) produce accurate enough widget-permission-TPL-policy mappings.
- domain assumption Survey responses collected via Prolific are representative of real mobile development teams and reflect genuine usefulness.
invented entities (1)
-
PriBOM (Privacy Bills of Materials) inventory
Cite this review
Pith. "Pith review of Privacy Bills of Materials: A Transparent Privacy Information Inventory for Collaborative Privacy Notice Generation in Mobile App Development." pith.science (2026). https://pith.science/paper/L6I3HCCY
@misc{pith2026250101131,
author = {Pith},
title = {Pith review of: Privacy Bills of Materials: A Transparent Privacy Information Inventory for Collaborative Privacy Notice Generation in Mobile App Development},
year = {2026},
howpublished = {\url{https://pith.science/paper/L6I3HCCY}},
note = {Machine review of arXiv:2501.01131}
}
read the original abstract
Privacy regulations mandate that developers must provide authentic and comprehensive privacy notices, e.g., privacy policies or labels, to inform users of their apps' privacy practices. However, due to a lack of knowledge of privacy requirements, developers often struggle to create accurate privacy notices, especially for sophisticated mobile apps with complex features and in crowded development teams. To address these challenges, we introduce Privacy Bills of Materials (PriBOM), a systematic software engineering approach that leverages different development team roles to better capture and coordinate mobile app privacy information. PriBOM facilitates transparency-centric privacy documentation and specific privacy notice creation, enabling traceability and trackability of privacy practices. We present a pre-fill of PriBOM based on static analysis and privacy notice analysis techniques. We demonstrate the perceived usefulness of PriBOM through a human evaluation with 150 diverse participants. Our findings suggest that PriBOM could serve as a significant solution for providing privacy support in DevOps for mobile apps.
Figures
Figures from the paper (3 more)
Reference graph
Works this paper leans on
-
[1]
Australian Privacy Principles (APP)
2014. Australian Privacy Principles (APP) . https://www.oaic.gov.au/privacy/ australian-privacy-principles Accessed: 2022-05-03
2014
-
[2]
General Data Protection Regulation (GDPR)
2016. General Data Protection Regulation (GDPR). https://gdpr-info.eu/ Accessed: 2022-04-25
2016
-
[3]
California Consumer Privacy Act of 2018 (CCPA)
2018. California Consumer Privacy Act of 2018 (CCPA). https://oag.ca.gov/privacy/ ccpa Accessed: 2022-04-25
2018
-
[4]
2022. Iubenda. https://www.iubenda.com/en/ Accessed: 2022-03-28
2022
-
[5]
SPDX Overview
2023. SPDX Overview. https://spdx.dev/about/
2023
-
[6]
Androguard
2024. Androguard. https://github.com/androguard/androguard Accessed: 2024- 02-27
2024
-
[7]
App privacy policy generator
2024. App privacy policy generator . https://app-privacy-policy-generator. firebaseapp.com/ Accessed: 2024-02-27
2024
-
[8]
2024. Iubenda. https://termly.io/ Accessed: 2022-02-27
2024
Show all 95 references
-
[9]
2024. JADX. https://github.com/skylot/jadx Accessed: 2024-02-27
2024
-
[10]
Lep’s World 2
2024. Lep’s World 2 . https://play.google.com/store/apps/details?id=at.ner. lepsWorld2&hl=en_US Accessed: 2024-05-20
2024
-
[11]
LinkedIn Post Kuijt
2024. LinkedIn Post Kuijt . https://www.linkedin.com/posts/dr-emilie-kuijt- baa79a50_privacy-activity-7188786255558492160-KSxy?utm_source=share& utm_medium=member_desktop Accessed: 2024-06-07
2024
-
[12]
LinkedIn Post Nini
2024. LinkedIn Post Nini . https://www.linkedin.com/pulse/5-challenges-life- data-protection-officer-nini-prasad/ Accessed: 2024-06-07
2024
-
[13]
LinkedIn Post Tricia Higgins
2024. LinkedIn Post Tricia Higgins . https://www.linkedin.com/posts/ higginstricia_managing-gdpr-non-compliance-activity-7081663097794371584- aC20?utm_source=share&utm_medium=member_desktop Accessed: 2024-06-07
2024
-
[14]
Manifest.permission | Android Developers
2024. Manifest.permission | Android Developers. https://developer.android.com/ reference/android/Manifest.permission Accessed: 2024-03-31
2024
-
[15]
Matcha - A Google Play Safety Label Generator
2024. Matcha - A Google Play Safety Label Generator . https://plugins.jetbrains. com/plugin/20141-matcha--a-google-play-safety-label-generator Accessed: 2024-05-06
2024
-
[16]
Permissions on Android
2024. Permissions on Android . https://developer.android.com/guide/topics/ permissions/overview Accessed: 2024-04-1
2024
-
[17]
Privacy policy online
2024. Privacy policy online. https://www.privacypolicyonline.com/ Accessed: 2022-02-27
2024
-
[18]
Privacypolicies
2024. Privacypolicies. https://www.privacypolicies.com/ Accessed: 2022-02-27
2024
-
[19]
Prolific
2024. Prolific. https://www.prolific.com/ Accessed: 2024-03-25
2024
-
[20]
Provide information for Google Play’s Data safety section
2024. Provide information for Google Play’s Data safety section . https://support. google.com/googleplay/android-developer/answer/10787469?hl=en Accessed: 2024-03-25
2024
-
[21]
Qualtrics
2024. Qualtrics. https://www.qualtrics.com/au/ Accessed: 2024-03-25
2024
-
[22]
simplelegal
2024. simplelegal. https://www.simplelegal.com/blog/corporate-legal- departments-data-privacy Accessed: 2024-04-9
2024
-
[23]
Paul C Adams. 2020. Agreeing to surveillance: Digital news privacy policies. Journalism & Mass Communication Quarterly 97, 4 (2020), 868–889
2020
-
[24]
Vincent Zimmer Amy Nelson, Jiewen Yao. 2021. Traceable Firmware Bill of Materials Overview. https://uefi.org/node/4950
2021
-
[25]
Vitalii Avdiienko, Konstantin Kuznetsov, Isabelle Rommelfanger, Andreas Rau, Alessandra Gorla, and Andreas Zeller. 2017. Detecting behavior anomalies in graphical user interfaces. In 2017 IEEE/ACM 39th International Conference on Software Engineering Companion (ICSE-C) . IEEE, 201–203
2017
-
[26]
Rebecca Balebako and Lorrie Cranor. 2014. Improving app privacy: Nudging app developers to protect user privacy. IEEE Security & Privacy 12, 4 (2014), 55–58
2014
-
[27]
Rebecca Balebako, Abigail Marsh, Jialiu Lin, Jason Hong, and Lorrie Faith Cranor
-
[28]
Iain Barclay, Alun Preece, Ian Taylor, and Dinesh Verma. 2019. Towards trace- ability in data ecosystems using a bill of materials model. arXiv preprint arXiv:1904.04253 (2019)
2019 arXiv
-
[29]
Eliot Beer. 2022. Firmware security in the spotlight after novel ransomware attacks. https://thestack.technology/firmware-attacks-focus/
2022
-
[30]
Jarni Blakkarly and Daniel Graham. 2024. Privacy policy comparison reveals half have poor readability . https://www.choice.com.au/consumers-and- data/protecting-your-data/data-laws-and-regulation/articles/privacy-policy- comparison Accessed: 2024-03-25
2024
-
[31]
Virginia Braun and Victoria Clarke. 2006. Using thematic analysis in psychology. Qualitative research in psychology 3, 2 (2006), 77–101
2006
-
[32]
Harry Brignull. 2010. Types of deceptive design. Deceptive Design (2010)
2010
-
[33]
Duc Bui, Brian Tang, and Kang G Shin. 2023. Detection of inconsistencies in privacy practices of browser extensions. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE, 2780–2798
2023
-
[34]
João Caramujo and Alberto Manuel Rodrigues Da Silva. 2015. Analyzing privacy policies based on a privacy-aware profile: The Facebook and LinkedIn case studies. In 2015 IEEE 17th Conference on Business Informatics , Vol. 1. IEEE, 77–84
2015
-
[35]
Brian Ka Chan. 2017. Artificial Intelligence Bill of Materials (AI- BOM). https://minddata.org/bill-of-artificial-intelligence-materials-boaimBrian- Ka-Chan-AI
2017
-
[36]
Jieshan Chen, Jiamou Sun, Sidong Feng, Zhenchang Xing, Qinghua Lu, Xiwei Xu, and Chunyang Chen. 2023. Unveiling the Tricks: Automated Detection of Dark Patterns in Mobile Applications. In Proceedings of the 36th Annual ACM Symposium on User Interface Software and Technology . 1–20
2023
-
[37]
Andrei Costin. 2022. Securing Your Iot Device With Fboms From Devastating Cyberattacks. https://euhubs4data.eu/blog/securing-iot-device-with-fboms/
2022
-
[38]
Benjamin F Crabtree and William F Miller. 1992. A template approach to text analysis: developing and using codebooks. (1992)
1992
-
[39]
CycloneDX. 2022. Hardware Bill of Materials (HBOM). https://github.com/ CycloneDX/bom-examples/tree/master/HBOM
2022
-
[40]
Carlos Flavián and Miguel Guinalíu. 2006. Consumer trust, perceived security and privacy policy: three basic elements of loyalty to a web site. Industrial management & data Systems 106, 5 (2006), 601–620
2006
-
[41]
Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G Shin, and Karl Aberer. 2018. Polisis: Automated analysis and presentation of privacy policies using deep learning. In 27th{USENIX} security symposium ({USENIX} security 18). 531–548
2018
-
[42]
Stephen Hendrick. 2022. Software Bill of Materials (SBOM) and Cybersecurity Readiness. https://tinyurl.com/293v3xte
2022
-
[43]
We are a startup to the core
Dilara Keküllüoğlu and Yasemin Acar. 2023. " We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups. In 2023 IEEE Symposium on Security and Privacy (SP) . IEEE, 2015–2031
2023
-
[44]
Thomas Kelepouris, Katerina Pramatari, and Georgios Doukidis. 2007. RFID- enabled traceability in the food supply chain. Industrial Management & data systems 107, 2 (2007), 183–200
2007
-
[45]
Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder
-
[46]
Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, and Lorrie Faith Cranor. 2010. Standardizing privacy notices: an online study of the nutrition label approach. In Proceedings of the SIGCHI Conference on Human factors in Computing Systems . 1573–1582. 13 Proceedings on Privacy...
2010
-
[47]
Patrick Gage Kelley, Lorrie Faith Cranor, and Norman Sadeh. 2013. Privacy as part of the app decision-making process. In Proceedings of the SIGCHI conference on human factors in computing systems . 3393–3402
2013
-
[48]
Katharine Kemp. 2020. Concealed data practices and competition law: why privacy matters. European Competition Journal 16, 2-3 (2020), 628–672
2020
-
[49]
Rishabh Khandelwal, Asmit Nayak, Paul Chung, and Kassem Fawaz. 2023. Un- packing Privacy Labels: A Measurement and Developer Perspective on Google’s Data Safety Section. arXiv preprint arXiv:2306.08111 (2023)
2023 arXiv
-
[50]
Barbara A Kitchenham and Shari L Pfleeger. 2008. Personal opinion surveys. In Guide to advanced empirical software engineering . Springer, 63–92
2008
-
[51]
Patrick Lam, Eric Bodden, Ondrej Lhoták, and Laurie Hendren. 2011. The Soot framework for Java program analysis: a retrospective. InCetus Users and Compiler Infastructure Workshop (CETUS 2011), Vol. 15
2011
-
[52]
Hao-Ping Hank Lee, Lan Gao, Stephanie Yang, Jodi Forlizzi, and Sauvik Das
-
[53]
Tianshi Li, Yuvraj Agarwal, and Jason I Hong. 2018. Coconut: An IDE plugin for developing privacy-friendly apps. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 2, 4 (2018), 1–35
2018
-
[54]
Tianshi Li, Lorrie Faith Cranor, Yuvraj Agarwal, and Jason I Hong. 2024. Matcha: An IDE Plugin for Creating Accurate Privacy Nutrition Labels. arXiv preprint arXiv:2402.03582 (2024)
2024 arXiv
-
[55]
Tianshi Li, Elizabeth Louie, Laura Dabbish, and Jason I Hong. 2021. How devel- opers talk about personal data and what it means for user privacy: A case study of a developer forum on reddit. Proceedings of the ACM on Human-Computer Interaction 4, CSCW3 (2021), 1–28
2021
-
[56]
Tianshi Li, Elijah B Neundorfer, Yuvraj Agarwal, and Jason I Hong. 2021. Honey- suckle: Annotation-guided code generation of in-app privacy notices.Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies5, 3 (2021), 1–27
2021
-
[57]
Tianshi Li, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor, and Jason I Hong. 2022. Understanding challenges for developers to create accurate privacy nutrition labels. In Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems. 1–24
2022
-
[58]
Yanzi Lin, Jaideep Juneja, Eleanor Birrell, and Lorrie Cranor. 2023. Data Safety vs. App Privacy: Comparing the Usability of Android and iOS Privacy Labels. arXiv preprint arXiv:2312.03918 (2023)
2023 arXiv
-
[59]
Vikas K Malviya, Yan Naing Tun, Chee Wei Leow, Ailys Tee Xynyn, Lwin Khin Shar, and Lingxiao Jiang. 2023. Fine-Grained In-Context Permission Classification for Android Apps Using Control-Flow Graph Embedding. In 2023 38th IEEE/ACM International Conference on Automated Software...
2023
-
[60]
Ryan McConkey and Oluwafemi Olukoya. 2023. Runtime and design time com- pleteness checking of dangerous android app permissions against GDPR. IEEE Access (2023)
2023
-
[61]
Aleecia M McDonald and Lorrie Faith Cranor. 2008. The cost of reading privacy policies. Isjlp 4 (2008), 543
2008
-
[62]
Mehdi Mirakhorli, Derek Garcia, Schuyler Dillon, Kevin Laporte, Matthew Mor- rison, Henry Lu, Viktoria Koscinski, and Christopher Enoch. 2024. A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM). arXiv preprint arXiv:2402.11151 (2024)
2024 arXiv
-
[63]
2015.{UIPicker}:{User-Input} Privacy Identification in Mobile Applica- tions
Yuhong Nan, Min Yang, Zhemin Yang, Shunfan Zhou, Guofei Gu, and XiaoFeng Wang. 2015.{UIPicker}:{User-Input} Privacy Identification in Mobile Applica- tions. In 24th USENIX Security Symposium (USENIX Security 15) . 993–1008
2015
-
[64]
NTIA. 2019. Roles and Benefits for SBOM Across the Supply Chain. https://www.ntia.gov/files/ntia/publications/ntia_sbom_use_cases_roles_ benefits-nov2019.pdf
2019
-
[65]
Shidong Pan, Thong Hoang, Dawen Zhang, Zhenchang Xing, Xiwei Xu, Qinghua Lu, and Mark Staples. 2023. Toward the cure of privacy policy reading phobia: Automated generation of privacy nutrition labels from privacy policies. arXiv preprint arXiv:2306.10923 (2023)
2023 arXiv
-
[66]
Shidong Pan, Zhen Tao, Thong Hoang, Dawen Zhang, Tianshi Li, Zhenchang Xing, Xiwei Xu, Mark Staples, Thierry Rakotoarivelo, and David Lo. 2024. A NEW HOPE: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated Generation. In 33rd USENIX Security ...
2024
-
[67]
Shidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing, Jieshan Chen, Xiwei Xu, and Thong Hoang. 2024. Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile Apps. In 33rd USENIX Security Symposium (USE...
2024
-
[68]
Alfredo J Perez, Sherali Zeadally, and Jonathan Cochran. 2018. A review and an empirical analysis of privacy policy and notices for consumer Internet of things. Security and Privacy 1, 3 (2018), e15
2018
-
[69]
John N Petroff and Arthur V Hill. 1991. A framework for the design of lot-tracing systems for the 1990s. Production and Inventory Management Journal 32, 2 (1991), 55
1991
-
[70]
Muhammad Sajidur Rahman, Pirouz Naghavi, Blas Kojusner, Sadia Afroz, Byron Williams, Sara Rampazzi, and Vincent Bindschaedler. 2022. Permpress: Machine learning-based pipeline to evaluate permissions in app privacy policies. IEEE Access 10 (2022), 89248–89269
2022
-
[71]
Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina- Rodriguez, and Serge Egelman. 2019. 50 ways to leak your data: An exploration of apps’ circumvention of the android permissions system. In 28th USENIX security symposium (USENIX security 19) . 603–620
2019
-
[72]
Atanas Rountev and Dacong Yan. 2014. Static reference analysis for GUI objects in Android software. InProceedings of Annual IEEE/ACM International Symposium on Code Generation and Optimization . 143–153
2014
-
[73]
William Seymour, Noura Abdi, Kopo M Ramokapane, Jide Edu, Guillermo Suarez- Tangil, and Jose Such. 2023. Voice App Developer Experiences with Alexa and Google Assistant: Juggling Risks, Liability, and Security. arXiv preprint arXiv:2311.08879 (2023)
2023 arXiv
-
[74]
Trevor Stalnaker, Nathan Wintersgill, Oscar Chaparro, Massimiliano Di Penta, Daniel M German, and Denys Poshyvanyk. 2024. BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Sys- tems. In Proceedings of the 46th IEEE/ACM Intern...
2024
-
[75]
Mohammad Tahaei, Alisa Frik, and Kami Vaniea. 2021. Privacy champions in software teams: Understanding their motivations, strategies, and challenges. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems . 1–15
2021
-
[76]
Mohammad Tahaei, Kami Vaniea, and Naomi Saphra. 2020. Understanding privacy-related questions on stack overflow. In Proceedings of the 2020 CHI con- ference on human factors in computing systems . 1–14
2020
-
[77]
2022.{PrivGuard}: Privacy regulation compliance made easier
Lun Wang, Usmann Khan, Joseph Near, Qi Pang, Jithendaraa Subramanian, Neel Somani, Peng Gao, Andrew Low, and Dawn Song. 2022.{PrivGuard}: Privacy regulation compliance made easier. In 31st USENIX Security Symposium (USENIX Security 22). 3753–3770
2022
-
[78]
Xiaoyin Wang, Xue Qin, Mitra Bokaei Hosseini, Rocky Slavin, Travis D Breaux, and Jianwei Niu. 2018. Guileak: Tracing privacy policy claims on user input data for android applications. In Proceedings of the 40th International Conference on Software Engineering. 37–47
2018
-
[79]
Charles Weir, Ben Hermann, and Sascha Fahl. 2020. From needs to actions to secure apps? the effect of requirements and developer practices on app security. In 29th USENIX security symposium (USENIX security 20) . 289–305
2020
-
[80]
2023.{LibScan}: Towards More Precise{Third-Party} Library Identification for Android Applications
Yafei Wu, Cong Sun, Dongrui Zeng, Gang Tan, Siqi Ma, and Peicheng Wang. 2023.{LibScan}: Towards More Precise{Third-Party} Library Identification for Android Applications. In 32nd USENIX Security Symposium (USENIX Security 23) . 3385–3402
2023
-
[81]
Shengqu Xi, Shao Yang, Xusheng Xiao, Yuan Yao, Yayuan Xiong, Fengyuan Xu, Haoyu Wang, Peng Gao, Zhuotao Liu, Feng Xu, et al . 2019. Deepintent: Deep icon-behavior learning for detecting intention-behavior discrepancy in mobile apps. In Proceedings of the 2019 ACM SIGSAC Confer...
2019
-
[82]
Boming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu, and Liming Zhu. 2023. An empirical study on software bill of materials: Where we stand and the road ahead. In 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2630–2642
2023
-
[83]
Boming Xia, Dawen Zhang, Yue Liu, Qinghua Lu, Zhenchang Xing, and Liming Zhu. 2023. Trust in software supply chains: Blockchain-enabled sbom and the aibom future. arXiv preprint arXiv:2307.02088 (2023)
2023 arXiv
-
[84]
Fuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li, Lei Bu, Kai Chen, Zi Huang, and Guangdong Bai. 2022. Scrutinizing privacy policy compliance of virtual personal assistant apps. In Proceedings of the 37th IEEE/ACM international conference on automated software engineering. 1–13
2022
-
[85]
Shengqian Yang, Haowei Wu, Hailong Zhang, Yan Wang, Chandrasekar Swami- nathan, Dacong Yan, and Atanas Rountev. 2018. Static window transition graphs for Android. Automated Software Engineering 25 (2018), 833–873
2018
-
[86]
Shengqian Yang, Dacong Yan, Haowei Wu, Yan Wang, and Atanas Rountev. 2015. Static control-flow analysis of user-driven callbacks in Android applications. In 2015 IEEE/ACM 37th IEEE International Conference on Software Engineering , Vol. 1. IEEE, 89–99
2015
-
[87]
Le Yu, Xiapu Luo, Jiachi Chen, Hao Zhou, Tao Zhang, Henry Chang, and Hare- ton KN Leung. 2018. Ppchecker: Towards accessing the trustworthiness of android apps’ privacy policies. IEEE Transactions on Software Engineering 47, 2 (2018), 221–242
2018
-
[88]
Le Yu, Tao Zhang, Xiapu Luo, and Lei Xue. 2015. Autoppg: Towards automatic generation of privacy policy for android applications. In Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices. 39–50. 14 Privacy Bills of Materials (...
2015
-
[89]
Nusrat Zahan, Elizabeth Lin, Mahzabin Tamanna, William Enck, and Laurie Williams. 2023. Software Bills of Materials Are Required. Are We There Yet? IEEE Security & Privacy 21, 2 (2023), 82–88
2023
-
[90]
Yanjie Zhao, Li Li, Xiaoyu Sun, Pei Liu, and John Grundy. 2021. Icon2Code: Recommending code implementations for Android GUI components. Information and Software Technology 138 (2021), 106619
2021
-
[91]
2023.{POLICYCOMP}: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices
Lu Zhou, Chengyongxiao Wei, Tong Zhu, Guoxing Chen, Xiaokuan Zhang, Suguo Du, Hui Cao, and Haojin Zhu. 2023.{POLICYCOMP}: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices. In 32nd USENIX Security Symposium (USENIX Security 23) . ...
2023
-
[92]
Sebastian Zimmeck, Rafael Goldstein, and David Baraka. 2021. PrivacyFlash Pro: Automating Privacy Policy Generation for Mobile Apps.. In NDSS, Vol. 2. 4. 8 Appendix 8.1 The Methodology and Scope of Literature in Formative Study Table 6 presents the methodology and scope of stu...
2021
-
[2009]
nutrition label
A" nutrition label" for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security . 1–12
-
[2014]
In Workshop on Usable Security
The privacy and security behaviors of smartphone app developers. In Workshop on Usable Security. Citeseer, 1–10
-
[2024]
I Don’t Know If We’re Doing Good. I Don’t Know If We’re Doing Bad
“I Don’t Know If We’re Doing Good. I Don’t Know If We’re Doing Bad”: Investigating How Practitioners Scope, Motivate, and Conduct Privacy Work When Developing AI Products. In USENIX Security Symposium
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.