Skip to main navigation Skip to search Skip to main content

Harnessing Language Models to Analyze Android App Permission Fidelity

  • Yunik Tamrakar
  • , Ritwik Banerjee
  • , Ethan Myers
  • , Lorenzo De Carli
  • , Indrakshi Ray
  • Colorado State University
  • University of Calgary

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Android's vast app ecosystem (over 2 million apps) poses significant privacy risks, as current methods for inferring permissions from descriptions - keyword matching, traditional natural language processing (NLP), and recurrent neural networks (RNNs) - struggle with accurate inference due to imprecise, ambiguous, or incomplete natural language descriptions. This gap undermines regulatory transparency and user trust, necessitating tools that reconcile stated functionality with actual data practices. We demonstrate that large language models like GPT-4o, applied in a zero-shot inference setting, leverage contextual reasoning to infer permissions competitively, while fine-tuned encoders (BERT, BART) surpass state-of-the-art performance when trained on minimally annotated datasets augmented with paraphrases, achieving 50-70% gains in weighted and macro F1 scores. By enabling precise permission auditing with reduced annotation costs, our work advances scalable, adaptable solutions for privacy compliance across resource-constrained and highstakes environments.

Original languageEnglish
Title of host publication2025 22nd Annual International Conference on Privacy, Security, and Trust, PST 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331503437
DOIs
StatePublished - 2025
Event22nd Annual International Conference on Privacy, Security, and Trust, PST 2025 - Hybrid, Fredericton, Canada
Duration: Aug 26 2025Aug 28 2025

Publication series

Name2025 22nd Annual International Conference on Privacy, Security, and Trust, PST 2025

Conference

Conference22nd Annual International Conference on Privacy, Security, and Trust, PST 2025
Country/TerritoryCanada
CityHybrid, Fredericton
Period08/26/2508/28/25

Keywords

  • Mobile applications
  • classifier design and evaluation
  • language models
  • machine learning
  • natural language processing
  • privacy
  • regulation

Fingerprint

Dive into the research topics of 'Harnessing Language Models to Analyze Android App Permission Fidelity'. Together they form a unique fingerprint.

Cite this