arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.21469cs.CR

基于假设驱动搜索的移动应用数据库中可扩展个人身份信息(PII)发现

Scalable PII Discovery in Mobile App Databases via Hypothesis-Driven Search

Jeel Piyushkumar Khatiwala, Samad Afolabi, Ruoyao Xiao, Yu Luo, Dianxiang Xu, Weifeng Xu

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对移动应用数据库中PII发现的难题,提出假设驱动框架,在25个SQLite数据库上验证,Gemini 2.5 Pro取得94.5% F1,可缩减79.9%有效搜索空间,且模型性能受其能力影响显著。

中文摘要 AI 辅助

在移动取证数据库中发现个人身份信息(PII)十分困难,因为相关表-列区域未知、分布在异构SQLite模式中,且可能包含嵌入自由文本或半结构化字段中的值。我们提出一种假设驱动框架,将PII定位视为不确定性下的有界自适应搜索。智能体对候选表-列区域进行排名,探测采样值,并维护先前证据、置信度分数和决策的记忆以细化后续假设。该框架将轻量级PII探索与经过验证区域上的目标提取、标准化及去重分离,从而将详尽检查限制在有采样证据支持的区域。我们在Cellebrite CTF语料库中10款Android和iOS应用的25个SQLite数据库上评估该框架,目标为电子邮件地址、电话号码、域名、人名及邮政地址。针对语料库级别3751个实体的不同真实值集合,Gemini 2.5 Pro取得94.5%的F1分数,同时平均减少79.9%的有效提取搜索空间。对12种模型后端的结果显示,多款前沿模型表现出色,但对模型能力有显著敏感性。

英文摘要

Discovering personally identifiable information (PII) in mobile forensic databases is difficult because the relevant table-column regions are unknown, distributed across heterogeneous SQLite schemas, and may contain values embedded in free-text or semi-structured fields. We present a hypothesis-driven framework that treats PII localization as bounded, adaptive search under uncertainty. An agent ranks candidate table-column regions, probes sampled values, and maintains a memory of prior evidence, confidence scores, and decisions to refine subsequent hypotheses. The framework separates lightweight PII exploration from targeted extraction, normalization, and deduplication over validated regions, thereby limiting exhaustive inspection to regions supported by sampled evidence. We evaluate the framework on 25 SQLite databases from 10 Android and iOS applications in the Cellebrite CTF corpus, targeting email addresses, phone numbers, domain names, person names, and postal addresses. Against a corpus-level distinct ground-truth set of 3,751 entities, Gemini 2.5 Pro achieves 94.5% F1 while reducing the effective extraction search space by 79.9% on average. Results across 12 model backends show strong performance among several frontier models, but substantial sensitivity to model capability.

补充信息

↑