arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向默认移动应用隐私控制的以用户为中心的上下文感知权限治理框架

A User-Centric Context-Aware Permission Governance Framework for Privacy Control in Default Mobile Applications

Asmau Yetunde Adeniran, Adeniran Kolade Ademuwagun, Fatimah Adamu-Fika, Samaila Musa Abdullahi, Freeman Bitrus, Fortune Daberechi Ifeanyi

arXiv 2608.27914首次发表:更新:

AI 中文总结

本文针对默认移动应用权限管控的不足,提出以用户为中心的上下文感知权限治理框架,引入“按需允许”功能级授权选项,通过模拟平台结合调查与可用性测试验证其可提升用户对权限的理解与决策清晰度。

AI 中文摘要

移动操作系统提供运行时权限控制,旨在提升用户对敏感数据的控制权。但默认或预装应用深度集成于系统,可能拥有更高权限,用户难以审查。现有权限模型通常在应用会话中授予永久或临时访问权限,未区分单个功能,导致用户不确定数据何时被访问、为何被访问。本文提出一种面向默认移动应用的、上下文敏感且以用户为中心的权限治理框架,引入基于功能的授权选项“按需允许”,限制访问需数据的功能而非整个应用会话。该框架采用加权评分系统,根据权限敏感度和授权类型评估用户选择的隐私影响。研究开发了基于网页的模拟平台,对6类常用默认应用的30种真实权限请求场景建模,支持原生实现前的受控早期评估。探索性评估结合两项工作:一是对104名受访者的横断面调查,考察权限意识与行为;二是对8名参与者的形成性可用性测试,评估原型。调查结果显示,用户不会持续检查默认应用权限,授予访问前更倾向于上下文解释。研究结果提供初步证据,表明上下文感知权限治理可提升用户理解与决策清晰度。这项基于模拟的研究代表了在原生移动部署前评估功能级授权与隐私反馈机制的初始步骤。

英文摘要

Mobile operating systems provide runtime permission controls intended to improve user control over sensitive data. However, default or pre-installed applications are deeply integrated into the system, may operate with elevated privileges, and are difficult for users to scrutinize. Existing permission models generally grant persistent or temporary access for an application session without distinguishing among individual features, leaving users uncertain about when and why data are accessed. This paper presents a context-sensitive, user-focused permission governance framework for default mobile applications. It introduces a feature-based authorization option, "Allow When Needed," that restricts access to the functionality requiring the data rather than the entire application session. A weighted scoring system estimates the privacy implications of user choices based on permission sensitivity and authorization type. A web-based simulation platform was developed to model 30 realistic permission-request situations across six commonly used default application types and support controlled early-stage evaluation before native implementation. The exploratory assessment combined a cross-sectional survey of 104 respondents examining permission awareness and behavior with formative usability testing involving eight participants interacting with the prototype. Survey findings indicate that users do not consistently examine default-application permissions and prefer contextual explanations before granting access. The results provide preliminary evidence that context-aware permission governance can improve user understanding and decision clarity. This simulation-based study represents an initial step toward evaluating feature-level authorization and privacy-feedback mechanisms before native mobile deployment.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑