Privacy compliance detection method and device for vehicle-mounted application, equipment, medium and product

By reverse engineering and analyzing the APK files of in-vehicle applications using large-scale models, the problems of low accuracy and limited coverage in privacy compliance detection have been solved, enabling comprehensive detection of implicit permissions and generation of detailed reports.

CN120930175APending Publication Date: 2025-11-11BEIJING AUTOMOBILE RES GENERAL INST
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510802705.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies cannot effectively detect implicit permission calls in in-vehicle applications, resulting in low accuracy and limited coverage of privacy compliance detection.

Method used

By reverse engineering the APK file of an in-vehicle application, extracting Smali and assembly files, and using a pre-trained large model to perform privacy permission detection, a detailed compliance report is generated.

Benefits of technology

It achieves comprehensive and accurate detection of privacy permissions for in-vehicle applications, with a high degree of automation, and can adapt to the latest regulations in real time, reducing the possibility of missed detections and false detections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930175A_ABST
    Figure CN120930175A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent identification, in particular to a privacy compliance detection method, device and equipment for a vehicle-mounted application, a medium and a product, and the method comprises the following steps: judging whether a to-be-detected application is received or not; if the to-be-detected application is received, reverse analysis is carried out on the to-be-detected application, a to-be-detected file is extracted from an analysis result, the to-be-detected file is input into a pre-trained large model, a compliance analysis result of the to-be-detected file is obtained, and the pre-trained large model is obtained by training a preset deep learning network through a data set; and generating a privacy compliance detection report according to a compliance analysis result, thereby solving the problems of low detection precision, limited coverage, incapability of detecting implicit permission and the like in the privacy compliance detection in the prior art, and improving the comprehensiveness and accuracy of the privacy compliance detection of the vehicle-mounted application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent recognition technology, and in particular to a privacy compliance detection method, device, equipment, medium, and product for in-vehicle applications. Background Technology

[0002] With the rapid development of intelligent connected vehicle technology, vehicles are possessing increasingly powerful computing and communication capabilities, and in-vehicle applications are becoming increasingly abundant. These applications provide users with various convenient services, such as navigation, entertainment, and remote control, by collecting and processing large amounts of vehicle operation data and user personal information. At the same time, the amount of data generated and processed by vehicles is growing explosively, and the types of data are becoming more complex, including sensitive information such as the driver's biometric data, location information, and driving habits. This poses a greater risk to user privacy.

[0003] In related technologies, methods for detecting privacy compliance in in-vehicle applications typically include tools based on static code analysis, such as Lint and Programming Mistake Detector (PMD), which can scan application code and identify explicitly declared permissions.

[0004] However, the existing technologies cannot detect implicit permission calls and cannot handle complex Smali file analysis, which urgently needs to be addressed. Summary of the Invention

[0005] This invention provides a method, apparatus, device, medium, and product for detecting privacy compliance in vehicle applications, in order to solve the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in existing privacy compliance detection technologies, thereby improving the comprehensiveness and accuracy of privacy compliance detection for vehicle applications.

[0006] A first aspect of the present invention provides a privacy compliance detection method for in-vehicle applications, comprising the following steps: determining whether an application to be detected has been received; if the application to be detected is received, performing reverse analysis on the application to be detected, extracting the file to be detected from the analysis result, and inputting the file to be detected into a pre-trained large model to obtain a compliance analysis result of the file to be detected, wherein the pre-trained large model is obtained by training a preset deep learning network from a dataset; and generating a privacy compliance detection report based on the compliance analysis result.

[0007] Furthermore, in some embodiments, the step of inputting the file to be detected into a pre-trained large model to obtain the compliance analysis result of the file to be detected includes: inputting the file to be detected into the pre-trained large model to classify the file to be detected by the pre-trained large model, and verifying the privacy compliance of each category based on the classification result; if the privacy compliance of any category does not meet the preset verification conditions, the compliance analysis result is a detection failure; otherwise, the compliance analysis result is a detection pass.

[0008] Furthermore, in some embodiments, before inputting the file to be detected into the pre-trained large model, the method further includes: acquiring the dataset, wherein the dataset includes Smali files, assembly file samples, application regulatory standards, and dangerous permission standards; dividing the dataset into a training set and a validation set based on a preset partitioning ratio, and using the training set to train the preset deep learning network to obtain an initial large model, and using the validation set to validate the initial large model; if the validation result meets a preset pass condition, then the initial large model is used as the pre-trained large model.

[0009] Furthermore, in some embodiments, before performing reverse analysis on the application to be detected, the method further includes: determining whether the application to be detected meets preset detection conditions; if the application to be detected does not meet the preset detection conditions, generating detection error information, and generating the privacy compliance detection report based on the detection error information.

[0010] Furthermore, in some embodiments, the privacy compliance detection method for the in-vehicle application further includes: the application to be detected is uploaded via a webpage or application programming interface.

[0011] According to the privacy compliance detection method for in-vehicle applications provided in this embodiment of the invention, the APK file of the in-vehicle application is uploaded and decompiled and decoded to obtain privacy permission call data in Smali and assembly files. Privacy permissions are detected in real time through a large model, and the identified permission calls are compared with the latest regulations to generate a detailed privacy compliance detection report. This method solves the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in the existing privacy compliance detection technology, and improves the comprehensiveness and accuracy of privacy compliance detection for in-vehicle applications.

[0012] A second aspect of the present invention provides a privacy compliance detection device for in-vehicle applications, wherein the device includes: a judgment module for judging whether an application to be detected has been received; a data processing module for performing reverse analysis on the application to be detected when the application to be detected is received, extracting a file to be detected from the analysis result, and inputting the file to be detected into a pre-trained large model to obtain a compliance analysis result of the file to be detected, wherein the pre-trained large model is obtained by training a preset deep learning network from a dataset; and a generation module for generating a privacy compliance detection report based on the compliance analysis result.

[0013] Furthermore, in some embodiments, the data processing module is specifically used to: input the file to be detected into the pre-trained large model, so as to classify the file to be detected by the pre-trained large model, and verify the privacy compliance of each class based on the classification results; if the privacy compliance of any class does not meet the preset verification conditions, the compliance analysis result is detection failure, otherwise, the compliance analysis result is detection pass.

[0014] Furthermore, in some embodiments, before inputting the file to be detected into the pre-trained large model, the data processing module is further configured to: acquire the dataset, wherein the dataset includes Smali files, assembly file samples, application regulatory standards, and dangerous access standards; divide the dataset into a training set and a validation set based on a preset partitioning ratio, and train the preset deep learning network using the training set to obtain an initial large model, and validate the initial large model using the validation set; if the validation result meets the preset pass conditions, then the initial large model is used as the pre-trained large model.

[0015] Furthermore, in some embodiments, before performing reverse analysis on the application to be detected, the data processing module is further configured to: determine whether the application to be detected meets preset detection conditions; if the application to be detected does not meet the preset detection conditions, generate detection error information, and generate the privacy compliance detection report based on the detection error information.

[0016] Furthermore, in some embodiments, the application to be detected is uploaded via a webpage or an application programming interface (API).

[0017] The privacy compliance detection device for in-vehicle applications provided in this embodiment of the invention uploads the APK file of the in-vehicle application, decompiles and decodes it to obtain privacy permission call data in Smali and assembly files, performs real-time detection of privacy permissions through a large model, compares the identified permission calls with the latest regulations to generate a detailed privacy compliance detection report, solves the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in the existing privacy compliance detection technology, and improves the comprehensiveness and accuracy of privacy compliance detection for in-vehicle applications.

[0018] A third aspect of the present invention provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the privacy compliance detection method for in-vehicle applications described in the above embodiments.

[0019] A fourth aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the privacy compliance detection method for in-vehicle applications as described in the above embodiments.

[0020] A fifth aspect of the present invention provides a computer program product, including a computer program that is executed to implement the privacy compliance detection method for in-vehicle applications as described in the above embodiments.

[0021] Therefore, the present invention has the following advantages:

[0022] (1) High degree of automation: By introducing a large model, the privacy permission detection is fully automated, avoiding the tediousness and inefficiency of manual review.

[0023] (2) Wide detection range: Compared with traditional rule-driven tools, this invention can detect all forms of privacy permission calls in Smali files, including implicit and explicit permissions.

[0024] (3) The method of the present invention can adapt to the latest privacy protection regulations in real time through continuously updated large models and regulatory data, ensuring the accuracy and compliance of the detection results.

[0025] (4) Large models based on deep learning have powerful code understanding capabilities, which can effectively reduce the possibility of missed detections and false detections.

[0026] (5) This invention not only detects permission calls, but also provides a detailed compliance analysis report to help developers quickly identify and correct potential privacy issues. Attached Figure Description

[0027] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0028] Figure 1 This is a flowchart of a privacy compliance detection method for in-vehicle applications provided according to an embodiment of the present invention;

[0029] Figure 2 This is a schematic diagram of the architecture of a privacy compliance detection method for in-vehicle applications according to a specific embodiment of the present invention;

[0030] Figure 3 A flowchart of a privacy compliance detection method for in-vehicle applications according to a specific embodiment of the present invention;

[0031] Figure 4 This is a block diagram of a privacy compliance detection device for in-vehicle applications provided according to an embodiment of the present invention;

[0032] Figure 5 This is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present invention. Detailed Implementation

[0033] Embodiments of the present invention are described in detail below. Examples of these embodiments are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.

[0034] The following description, with reference to the accompanying drawings, outlines a method, apparatus, device, medium, and product for detecting privacy compliance in in-vehicle applications according to embodiments of the present invention. Addressing the issues of low detection accuracy, limited coverage, and inability to detect implicit permissions in existing privacy compliance detection technologies mentioned in the background section, the present invention provides a method for detecting privacy compliance in in-vehicle applications. This method involves uploading the APK file of the in-vehicle application, decompiling and decoding it to obtain privacy permission call data from Smali and assembly files, and using a large model to perform real-time detection of privacy permissions and generate a detailed privacy compliance detection report. This solves the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in existing privacy compliance detection technologies, thereby improving the comprehensiveness and accuracy of privacy compliance detection for in-vehicle applications.

[0035] Specifically, Figure 1 This is a flowchart of a privacy compliance detection method for in-vehicle applications provided according to an embodiment of the present invention.

[0036] like Figure 1 As shown, the privacy compliance testing method for this in-vehicle application includes the following steps:

[0037] In step S101, it is determined whether the application to be detected has been received.

[0038] The application to be detected is the in-vehicle application that the user is currently using. The in-vehicle application contains the user's personal information, such as name, mobile phone number or home address, and is stored in the form of a compiled APK file. When the user requests to use the in-vehicle program, the APK file is packaged and sent. At this time, it is determined that the application to be detected has been received. For example, when the user is using in-vehicle navigation software, it is determined that the application to be detected has been received.

[0039] In step S102, if an application to be detected is received, the application to be detected is reverse-analyzed, and the file to be detected is extracted from the parsing result. The file to be detected is then input into a pre-trained large model to obtain the compliance analysis result of the file to be detected. The pre-trained large model is obtained by training a preset deep learning network from the dataset.

[0040] Among them, reverse parsing is the decoding operation performed on the packaged APK file. The pre-trained large model is a deep learning model trained on a dataset constructed from Smali and assembly file samples. It can identify privacy permission calls in Smali and assembly files. The compliance analysis results include the in-vehicle application's calls to user privacy.

[0041] For example, to analyze the application you want to test, you first decode the packaged APK file, converting it into a Smali file. This Smali file is then decompiled into assembly language using the .so file. It's worth noting that the Smali file has the .smali extension and retains all opcodes and logic flow from the Android application. The assembly file retains the logic flow from the native layer, providing foundational data for subsequent large-scale model analysis. The parsed Smali and assembly files are then input into a trained large-scale model. By understanding the code structure, semantics, and call relationships, the large-scale model automatically identifies all privacy-related permission calls, yielding compliance analysis results for the application under test.

[0042] Furthermore, in some embodiments, the file to be detected is input into a pre-trained large model to obtain the compliance analysis result of the file to be detected, including: inputting the file to be detected into a pre-trained large model to classify the file to be detected by the pre-trained large model, and verifying the privacy compliance of each category based on the classification result; if the privacy compliance of any category does not meet the preset verification conditions, the compliance analysis result is a detection failure, otherwise, the compliance analysis result is a detection pass.

[0043] The classification result is the result of classifying the data after decoding the packaged APK file. The privacy compliance of each category is the result of detecting the data classification results through a large model. The preset verification condition is the condition for judging whether there are non-compliant items. If no non-compliant items are detected, the preset verification condition is not met, the analysis result is detection failure, and the detection result is returned. If non-compliant items are detected, the preset verification condition is met, the analysis result is detection success, and the analysis result is returned.

[0044] In step S103, a privacy compliance inspection report is generated based on the compliance analysis results.

[0045] The privacy compliance test report is a report that includes compliance data for each permission call.

[0046] For example, detected privacy permission calls will be compared with the latest laws and regulations. The compliance analysis module will evaluate the compliance of each permission call through a predefined set of rules (based on the regulations of the Ministry of Industry and Information Technology and industry standards) and generate a final privacy compliance test report. For non-compliant permission calls, the API can be replaced or the scope of permissions can be restricted to ensure that the application complies with the latest privacy protection requirements.

[0047] The privacy compliance test report can be transmitted to the terminal device via the network and displayed to remind the user. For example, the content of the privacy compliance test report can be displayed on a large screen in a car, or it can be displayed and reminded through the user's mobile APP. No specific restrictions are made here.

[0048] Furthermore, in some embodiments, before inputting the file to be detected into the pre-trained large model, the method further includes: acquiring a dataset, wherein the dataset includes Smali files, assembly file samples, application regulatory standards, and dangerous access standards; dividing the dataset into a training set and a validation set based on a preset partitioning ratio, and using the training set to train a preset deep learning network to obtain an initial large model, and using the validation set to validate the initial large model; if the validation result meets the preset pass conditions, then the initial large model is used as the pre-trained large model.

[0049] The dataset consists of a pre-prepared, labeled collection of data. The Smali files and assembly file samples are obtained by decompiling the target APK file into Smali files and then into assembly files using reverse engineering tools (such as JADX and Baksmali). The preset split ratio is the ratio of training and testing sets for the Smali files, assembly file samples, application regulatory standards, and dangerous permission standards datasets. The initial large model is trained on the dataset using deep learning techniques (such as Transformer and BERT) to ultimately generate a large model that can accurately identify privacy permission calls in Smali and assembly files.

[0050] It should be noted that, in order to avoid overfitting and improve the model's generalization ability, this invention uses data augmentation and cross-validation methods during the training process to ensure that the model can still maintain high accuracy when dealing with unknown samples.

[0051] Furthermore, in some embodiments, before performing reverse analysis on the application to be tested, the method further includes: determining whether the application to be tested meets preset detection conditions; if the application to be tested does not meet the preset detection conditions, generating detection error information, and generating a privacy compliance detection report based on the detection error information.

[0052] It should be noted that since information may be lost during the transmission of in-vehicle application information, it is necessary to check the integrity of the received APK file. If the detected APK file is incomplete, it may lead to errors in privacy detection. In this case, the application to be tested is determined to not meet the preset detection conditions, the detection fails, an error message is returned, and a corresponding privacy compliance detection report is generated.

[0053] In some embodiments, the application to be detected is uploaded via a webpage or an application programming interface (API).

[0054] In-vehicle applications are typically operated through the vehicle's central control screen or the user's mobile app. The central control screen or the user's mobile app can open web pages or in-vehicle applications. When browsing web pages, privacy information can be uploaded from the web pages. When opening in-vehicle applications, privacy information can also be uploaded through the corresponding application programming interface.

[0055] To enable those skilled in the art to better understand the privacy compliance detection method for in-vehicle applications according to embodiments of the present invention, the following explanation will be provided in conjunction with specific embodiments.

[0056] Figure 2 This is a schematic diagram of the architecture of a privacy compliance detection method for in-vehicle applications according to a specific embodiment of the present invention. Figure 3A flowchart illustrating a privacy compliance detection method for in-vehicle applications according to a specific embodiment of the present invention.

[0057] like Figure 2 As shown, the architecture of the privacy compliance detection method for in-vehicle applications includes a UI layer, an APK parsing layer, a large model logic layer, and a model layer. The UI layer is the process initiation module, which initiates the process by uploading the APK via a webpage or API request. The APK parsing layer is responsible for reverse engineering the APK file, extracting the decompiled product of the application. Smali files are the intermediate code format for Android applications, and assembly is the intermediate code format corresponding to .so files, which can intuitively display the application's internal logic and permission calls. The large model logic layer is responsible for classifying the reverse-engineered products of the APK, passing the classified products to the model layer for individual detection, and returning corresponding detailed information. The model layer deploys the trained model, which is responsible for analyzing each file, extracting all used permissions, and finally generating a compliance report using the latest trained regulatory model.

[0058] like Figure 3 As shown, the privacy compliance testing method for this in-vehicle application includes the following steps:

[0059] In step S301, the application APK file is entered.

[0060] In step S302, check if it is a complete APK file. If a complete APK file exists, proceed to step S303. If no complete APK file exists, proceed to step S304.

[0061] In step S303, the APK file is parsed, APK information is extracted, and step S305 is executed.

[0062] In step S304, an error message is returned indicating that the detection failed, and step S311 is executed.

[0063] In step S305, the APK is decompiled to extract Smail and assembly files.

[0064] In step S306, the input file is entered into the large model.

[0065] In step S307, all classification results are extracted and compliance analysis is performed.

[0066] In step S308, it is checked whether there are any non-compliant items. If there are non-compliant items, step S309 is executed. If there are no non-compliant items, step S310 is executed to exempt from liability.

[0067] In step S309, the detection result is returned. If the detection passes, step S311 is executed.

[0068] In step S310, the detection result is returned; if the detection fails, step S311 is executed.

[0069] In step S311, a test report is generated.

[0070] This enables the reverse compilation of APK files, accurate extraction and analysis of Smali and assembly files, and the identification and analysis of permission calls in Smali files based on a large deep learning model. The identified permission calls are then compared with the latest regulations to automatically generate compliance reports.

[0071] The privacy compliance detection method for in-vehicle applications provided by the present invention uploads the APK file of the in-vehicle application, decompiles and decodes it to obtain privacy permission call data in Smali and assembly files, performs real-time detection of privacy permissions through a large model, compares the identified permission calls with the latest regulations, and generates a detailed privacy compliance detection report. This method solves the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in the existing privacy compliance detection technology, and improves the comprehensiveness and accuracy of privacy compliance detection for in-vehicle applications.

[0072] Next, with reference to the accompanying drawings, a privacy compliance detection device for in-vehicle applications according to an embodiment of the present invention is described.

[0073] Figure 4 This is a block diagram of a privacy compliance detection device for in-vehicle applications provided according to an embodiment of the present invention.

[0074] like Figure 4 As shown, the privacy compliance detection device 10 for the in-vehicle application includes: a judgment module 100, a data processing module 200, and a generation module 300.

[0075] The judgment module 100 is used to determine whether the application to be detected has been received; the data processing module 200 is used to reverse analyze the application to be detected when it is received, extract the file to be detected from the analysis result, and input the file to be detected into a pre-trained large model to obtain the compliance analysis result of the file to be detected. The pre-trained large model is obtained by training a preset deep learning network from the dataset; the generation module 300 is used to generate a privacy compliance detection report based on the compliance analysis result.

[0076] Furthermore, in some embodiments, the data processing module 200 is specifically used to: input the file to be detected into a pre-trained large model, so as to classify the file to be detected by the pre-trained large model, and verify the privacy compliance of each class based on the classification results; if the privacy compliance of any class does not meet the preset verification conditions, the compliance analysis result is detection failure; otherwise, the compliance analysis result is detection pass.

[0077] Furthermore, in some embodiments, before inputting the file to be detected into the pre-trained large model, the data processing module 200 is also used to: acquire a dataset, wherein the dataset includes Smali files, assembly file samples, application regulatory standards, and dangerous access standards; divide the dataset into a training set and a validation set based on a preset partitioning ratio, and use the training set to train a preset deep learning network to obtain an initial large model, and use the validation set to validate the initial large model; if the validation result meets the preset pass conditions, then the initial large model is used as the pre-trained large model.

[0078] Furthermore, in some embodiments, before performing reverse analysis on the application to be tested, the data processing module 200 is also used to: determine whether the application to be tested meets preset detection conditions; if the application to be tested does not meet the preset detection conditions, generate detection error information, and generate a privacy compliance detection report based on the detection error information.

[0079] Furthermore, in some embodiments, the application to be detected is uploaded via a webpage or an application programming interface (API).

[0080] It should be noted that the above explanation of the privacy compliance detection method embodiment for in-vehicle applications also applies to the privacy compliance detection device for in-vehicle applications in this embodiment, and will not be repeated here.

[0081] The privacy compliance detection device for in-vehicle applications proposed in this embodiment of the invention uploads the APK file of the in-vehicle application, decompiles and decodes it to obtain privacy permission call data in Smali and assembly files, performs real-time detection of privacy permissions through a large model, compares the identified permission calls with the latest regulations, and generates a detailed privacy compliance detection report. This solves the problems of low detection accuracy, limited coverage, and inability to detect implicit permissions in existing privacy compliance detection technologies, and improves the comprehensiveness and accuracy of privacy compliance detection for in-vehicle applications.

[0082] Figure 5 This is a schematic diagram of an electronic device provided according to an embodiment of the present invention. The electronic device may include:

[0083] The memory 501, the processor 502, and the computer program stored on the memory 501 and capable of running on the processor 502.

[0084] When the processor 502 executes the program, it implements the privacy compliance detection method for in-vehicle applications provided in the above embodiments.

[0085] Furthermore, the electronic device also includes:

[0086] Communication interface 503 is used for communication between memory 501 and processor 502.

[0087] The memory 501 is used to store computer programs that can run on the processor 502.

[0088] The memory 501 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0089] If the memory 501, processor 502, and communication interface 503 are implemented independently, then the communication interface 503, memory 501, and processor 502 can be interconnected via a bus to complete communication between them. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0090] Optionally, in a specific implementation, if the memory 501, processor 502, and communication interface 503 are integrated on a single chip, then the memory 501, processor 502, and communication interface 503 can communicate with each other through an internal interface.

[0091] Processor 502 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.

[0092] In addition, embodiments of the present invention also provide a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described privacy compliance detection method for in-vehicle applications.

[0093] In addition, embodiments of the present invention also provide a computer program product, including a computer program, which is executed to implement the privacy compliance detection method for the above-mentioned in-vehicle application.

[0094] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0095] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0096] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more N executable instructions for implementing custom logic functions or processes, and the scope of preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of the invention pertain.

[0097] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0098] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

Claims

1. A method for detecting privacy compliance in vehicle applications, characterized in that, Includes the following steps: Determine whether the application to be detected has been received; If the application to be detected is received, the application to be detected is reverse parsed, and the file to be detected is extracted from the parsing result. The file to be detected is then input into a pre-trained large model to obtain the compliance analysis result of the file to be detected. The pre-trained large model is obtained by training a preset deep learning network from the dataset. A privacy compliance inspection report is generated based on the compliance analysis results.

2. The method according to claim 1, characterized in that, The step of inputting the file to be detected into a pre-trained large model to obtain the compliance analysis results of the file to be detected includes: The file to be detected is input into the pre-trained large model to classify the file to be detected through the pre-trained large model, and the privacy compliance of each class is verified based on the classification results. If any type of privacy compliance does not meet the preset verification conditions, the compliance analysis result is a failure; otherwise, the compliance analysis result is a pass.

3. The method according to claim 2, characterized in that, Before inputting the file to be detected into the pre-trained large model, the method further includes: Obtain the dataset, wherein the dataset includes Smali files, assembly file samples, application regulatory standards, and dangerous access standards; Based on a preset partitioning ratio, the dataset is divided into a training set and a validation set. The preset deep learning network is trained using the training set to obtain an initial large model, and the initial large model is validated using the validation set. If the verification result meets the preset pass conditions, then the initial large model will be used as the pre-trained large model.

4. The method according to claim 1, characterized in that, Before performing reverse engineering on the application to be detected, the process also includes: Determine whether the application to be detected meets the preset detection conditions; If the application to be tested does not meet the preset testing conditions, a testing error message is generated, and the privacy compliance testing report is generated based on the testing error message.

5. The method according to any one of claims 1-4, characterized in that, The application to be tested is uploaded via a webpage or application programming interface.

6. A privacy compliance detection device for in-vehicle applications, characterized in that, The device includes: The judgment module is used to determine whether the application to be detected has been received; The data processing module is used to perform reverse parsing on the application to be detected when it receives the application to be detected, extract the file to be detected from the parsing result, and input the file to be detected into a pre-trained large model to obtain the compliance analysis result of the file to be detected. The pre-trained large model is obtained by training a preset deep learning network from the dataset. The generation module is used to generate a privacy compliance detection report based on the compliance analysis results.

7. The privacy compliance detection device for in-vehicle applications according to claim 6, characterized in that, The data processing module is specifically used for: The file to be detected is input into the pre-trained large model to classify the file to be detected through the pre-trained large model, and the privacy compliance of each class is verified based on the classification results. If any type of privacy compliance does not meet the preset verification conditions, the compliance analysis result is a failure; otherwise, the compliance analysis result is a pass.

8. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the privacy compliance detection method for an in-vehicle application as described in any one of claims 1-5.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by the processor to implement the privacy compliance detection method for in-vehicle applications as described in any one of claims 1-5.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the privacy compliance detection method for in-vehicle applications as described in any one of claims 1-5.

Citation Information

Cited By

  • Application privacy compliance detection method based on large language model and related device

    CN121256817A