发表机构
University of California, Santa Cruz(加州大学圣克鲁兹分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
PrivAudit提出双视角自动化审计框架,结合大语言模型分析隐私政策与浏览器测量cookie行为,对998个网站审计发现CCPA强化披露但跟踪普遍且响应有限。
AI 中文摘要
在《加州消费者隐私法案》(CCPA)实施五年后,理解网站隐私实践如何在大规模范围内随法规演变,仍然是研究人员和监管机构面临的关键挑战。先前的工作和监管努力侧重于手动和针对具体案例的执法,但仍缺乏可扩展的方法来系统审计网站的两个关键用户可见方面,这些方面对CCPA至关重要:隐私披露和前端用户跟踪行为。在本文中,我们提出了PrivAudit,一个自动化审计框架,采用双视角方法捕获:(1)通过基于大型语言模型的分析,对以CCPA条款为基础的隐私政策进行隐私披露分析,以及(2)通过在不同隐私配置下对cookie写入进行自动化浏览器测量,观察用户可见的数据收集行为。我们将PrivAudit应用于998个网站,并报告了两个广泛的发现。该法律与更强的隐私披露相关:受CCPA约束的网站政策更可能披露退出机制、数据共享实践和用户权利。另一方面,基于cookie的跟踪仍然普遍存在,受CCPA约束和不受约束的网站共设置了6,392个定向cookie,其中49%是第三方写入。此外,cookie对隐私信号和同意选择的响应程度有限至中等,即使网站在其披露中声称会尊重这些信号和选择。我们的结果强调了需要结合政策分析与行为证据的多层次、可扩展审计方法。PrivAudit可以通过生成可操作的信号和模式来支持这些审计工作流的大规模进行,以供进一步手动审查。我们开源了PrivAudit,并正在与监管机构合作,以支持实际审计工作。
英文摘要
Five years after the enforcement of the California Consumer Privacy Act (CCPA), understanding how website privacy practices evolve at scale in response to regulation remains a key challenge for both researchers and regulators. Prior work and regulatory efforts have focused on manual and case-specific enforcement, but there remain no scalable approaches to systematically audit two key user-facing facets of websites that are crucial signals for the CCPA: privacy disclosures and front-end user tracking behavior. In this paper, we present PrivAudit, an automated auditing framework that adopts a dual-lens approach to capture: (1) privacy disclosures through large language model-based analysis of privacy policies grounded in CCPA provisions, and (2) user-observable data collection behavior through automated browser measurements of cookie writes under diverse privacy configurations. We apply PrivAudit to 998 websites and report two broad findings. The law is associated with stronger privacy disclosures: CCPA-subject policies are more likely to disclose opt-out mechanisms, data-sharing practices, and user rights. On the other hand, cookie-based tracking remains pervasive, with both CCPA-subject and not-subject websites setting a total of 6,392 targeting cookies, 49% of which are third-party writes. Moreover, cookies show limited-to-moderate responsiveness to privacy signals and consent choices, even when websites claim to honor them in their disclosures. Our results highlight the need for multi-layered and scalable auditing approaches that combine policy analysis with behavioral evidence. PrivAudit can support these auditing workflows at scale by generating actionable signals and patterns for further manual review. We open-source PrivAudit and are engaging with regulators to support auditing in practice.
CommentsExtended version of a paper accepted to the 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26)