Training Method of Privacy Compliance Detection Model, Privacy Compliance Detection Method and Device
By training the privacy compliance detection model, using deep learning technology to automatically analyze the privacy compliance of mobile applications, and synchronously update it when detecting changes in standards, it solves the problems of low efficiency and uncertainty in the existing technology, and achieves efficient and accurate automated detection.
Patent Information
- Application Number
- CN202111508825.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-10
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-12-10
AI Technical Summary
Privacy compliance detection for existing mobile applications mainly relies on manual methods, which are inefficient and difficult to guarantee.
By training privacy compliance detection models, use deep learning technology to automate the analysis of privacy compliance compliance in mobile applications and synchronous updates as privacy compliance detection standards change.
It improves the efficiency and accuracy of privacy compliance inspection, realizes automated inspection, and ensures the accuracy of inspection results and synchronization between inspection standards.
Smart Images

Figure CN114169006B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data security, and in particular, to a method for training a privacy compliance detection model, a privacy compliance detection method, and an apparatus. Background Art
[0002] With the wide popularization of mobile intelligent devices and the continuous penetration of the mobile Internet, mobile application programs have become the most relied-upon Internet access for users. While enjoying the convenience, the phenomenon of mobile application programs infringing on users' rights and interests is also very common. Many telecommunications fraud and privacy leakage incidents emerge in an endless stream, which has attracted extremely high social attention. Data security represented by the security of mobile application programs is related to the privacy protection at the individual user level. Mobile application developers need to conduct compliance detection on the privacy protection work of applications according to the compliance documents issued by relevant departments.
[0003] Currently, in the process of developing many mobile applications, manual compliance detection is still adopted. Developers confirm item by item according to the compliance documents whether a mobile application violates a certain compliance standard. This method has low efficiency and it is difficult to guarantee the accuracy. Summary of the Invention
[0004] The present application provides a method for training a privacy compliance detection model, a privacy compliance detection method, and an apparatus, which improve the efficiency and accuracy of privacy compliance detection.
[0005] In a first aspect, the present application provides a method for training a privacy compliance detection model, including:
[0006] Determine the function type of the application program sample;
[0007] Judge whether the change amount of the number of non-compliant application programs corresponding to the function type in the non-compliant application program library within a preset time period exceeds a preset value. If it exceeds, judge whether the privacy compliance detection standard corresponding to the function type has changed;
[0008] If the privacy compliance detection standard corresponding to the function type has changed, and it is determined that there is a data collection item in the changed text of the privacy compliance detection standard, obtain the privacy detection information sample corresponding to the application program sample. The label of the privacy detection information sample is marked according to the changed privacy compliance detection standard, and the label is used to represent whether the application program sample is compliant or non-compliant;
[0009] Update the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain a privacy compliance detection model.
[0010] In an implementation manner, the determining that there is a data collection item in the changed text of the privacy compliance detection standard includes:
[0011] Obtain the first text that has changed in the privacy compliance detection standard;
[0012] Perform semantic analysis on the first text to determine whether there is a second text containing data collection items in the first text;
[0013] If there is a second text, it is determined that there are data collection items in the text that has changed in the privacy compliance detection standard.
[0014] In one implementation, the determining whether the privacy compliance detection standard corresponding to the function type has changed includes:
[0015] Obtain the latest privacy compliance detection standard corresponding to the function type;
[0016] Determine whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard;
[0017] If they are not consistent, it is determined that the privacy compliance detection standard corresponding to the function type has changed.
[0018] In one implementation, the determining whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard includes:
[0019] Determine whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard by at least one of the following methods:
[0020] Determine whether the content of the currently adopted privacy compliance detection standard is consistent with the content of the latest privacy compliance detection standard;
[0021] Determine whether the version identifier of the currently adopted privacy compliance detection standard is consistent with the version identifier of the latest privacy compliance detection standard;
[0022] Determine whether the update time of the currently adopted privacy compliance detection standard is consistent with the update time of the latest privacy compliance detection standard.
[0023] In one implementation, the updating the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain a privacy compliance detection model includes:
[0024] Input the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector;
[0025] Input the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant;
[0026] Determine loss information according to the prediction result and the label corresponding to the privacy detection information sample;
[0027] Update the model parameters of the initial privacy compliance detection model according to the loss information to obtain a privacy compliance detection model.
[0028] In a second aspect, the present application provides a privacy compliance detection method, including:
[0029] Obtain privacy detection information of the application to be detected;
[0030] Input the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant, where the privacy compliance detection model is trained according to the method described in the first aspect.
[0031] In one implementation, the privacy detection information includes at least one of privacy policy text, call information of sensitive functions, transmission information of sensitive data, and acquisition information of sensitive permissions.
[0032] In one implementation, the privacy detection information includes call information of sensitive functions and / or acquisition information of sensitive permissions;
[0033] The obtaining of the privacy detection information of the application to be detected includes:
[0034] During the running of the application to be detected, obtain the call information of the sensitive functions and / or the acquisition information of the sensitive permissions through an automated decompilation method.
[0035] In one implementation, the privacy detection information includes transmission information of sensitive data;
[0036] The obtaining of the privacy detection information of the application to be detected includes:
[0037] During the running of the application to be detected, in the data transmission paths corresponding to the respective functions of the application to be detected, obtain the transmission information of the sensitive data through packet capture.
[0038] In one implementation, the inputting of the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant includes:
[0039] Input the privacy detection information into the feature extraction model of the privacy compliance detection model to obtain a feature vector corresponding to the privacy detection information;
[0040] Input the feature vector into the classification model of the privacy compliance detection model to obtain the detection result of whether the application to be detected is compliant.
[0041] In a third aspect, the present application provides a training device for a privacy compliance detection model, including:
[0042] A determination module, configured to determine the function type of the application sample;
[0043] A judgment module, configured to judge whether the change amount of the number of non-compliant application programs corresponding to the function type in the non-compliant application program library within a preset time period exceeds a preset value. If it exceeds, judge whether the privacy compliance detection standard corresponding to the function type has changed;
[0044] A training module, configured to, if the privacy compliance detection standard corresponding to the function type has changed and it is determined that there is a data collection item in the changed text of the privacy compliance detection standard, obtain the privacy detection information sample corresponding to the application sample. The label of the privacy detection information sample is marked according to the changed privacy compliance detection standard, and the label is used to represent that the application sample is compliant or non-compliant; update the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain the privacy compliance detection model.
[0045] In an implementation manner, the training module is configured to:
[0046] Obtain the first text that has changed in the privacy compliance detection standard;
[0047] Perform semantic analysis on the first text to judge whether there is a second text containing a data collection item in the first text;
[0048] If there is a second text, it is determined that there is a data collection item in the changed text of the privacy compliance detection standard.
[0049] In an implementation manner, the judgment module is configured to:
[0050] Obtain the latest privacy compliance detection standard corresponding to the function type;
[0051] Judge whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard;
[0052] If they are not consistent, it is determined that the privacy compliance detection standard corresponding to the function type has changed.
[0053] In an implementation manner, the judgment module is configured to:
[0054] Determine whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard in at least one of the following ways:
[0055] Determine whether the content of the currently adopted privacy compliance detection standard is consistent with the content of the latest privacy compliance detection standard;
[0056] Determine whether the version identifier of the currently adopted privacy compliance detection standard is consistent with the version identifier of the latest privacy compliance detection standard;
[0057] Determine whether the update time of the currently adopted privacy compliance detection standard is consistent with the update time of the latest privacy compliance detection standard.
[0058] In one implementation, the training module is used to:
[0059] Input the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector;
[0060] Input the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant;
[0061] Determine loss information according to the prediction result and the label corresponding to the privacy detection information sample;
[0062] Update the model parameters of the initial privacy compliance detection model according to the loss information to obtain a privacy compliance detection model.
[0063] In a fourth aspect, the present application provides a privacy compliance detection device, including:
[0064] An acquisition module, configured to acquire privacy detection information of an application to be detected;
[0065] A detection module, configured to input the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant, where the privacy compliance detection model is trained according to the method described in the first aspect.
[0066] In one implementation, the privacy detection information includes at least one of a privacy policy text, call information of sensitive functions, transmission information of sensitive data, and acquisition information of sensitive permissions.
[0067] In one implementation, the privacy detection information includes call information of sensitive functions and / or acquisition information of sensitive permissions;
[0068] The acquisition module is used to:
[0069] During the running of the application to be detected, call information of the sensitive function and / or acquisition information of the sensitive permission are obtained through an automated decompilation method.
[0070] In one implementation, the privacy detection information includes transmission information of sensitive data;
[0071] The acquisition module is used for:
[0072] During the running of the application to be detected, in the data transmission paths corresponding to the respective functions of the application to be detected, the transmission information of the sensitive data is obtained by packet capture.
[0073] In one implementation, the detection module is used for:
[0074] Input the privacy detection information into the feature extraction model of the privacy compliance detection model to obtain a feature vector corresponding to the privacy detection information;
[0075] Input the feature vector into the classification model of the privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant.
[0076] In a fifth aspect, the present application provides an electronic device, including a memory and a processor, the memory and the processor are connected;
[0077] The memory is used for storing a computer program;
[0078] The processor is used for implementing the method as described in the first aspect or the second aspect when the computer program is executed.
[0079] In a sixth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method as described in the first aspect or the second aspect above is implemented.
[0080] In a seventh aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method as described in the first aspect or the second aspect is implemented.
[0081] The present application provides a method for training a privacy compliance detection model, a privacy compliance detection method, and a device. In this method, when the change amount of the number of non-compliant application programs in the non-compliant application program library within a preset time period exceeds a preset value, it is determined whether the privacy compliance detection standard has changed. When the privacy compliance detection standard has changed, the initial privacy compliance detection model is trained with privacy detection information samples labeled according to the latest privacy compliance detection standard, so that the obtained privacy compliance detection model can not only achieve automated detection but also keep in sync with the privacy compliance detection standard, ensuring the accuracy of the results. BRIEF DESCRIPTION OF THE DRAWINGS
[0082] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0083] Figure 1 It is a schematic flowchart of a method for training a privacy compliance detection model provided by an embodiment of the present application;
[0084] Figure 2 It is a schematic flowchart of a privacy compliance detection method provided by an embodiment of the present application;
[0085] Figure 3 It is a schematic structural diagram of a device for training a privacy compliance detection model provided by an embodiment of the present application;
[0086] Figure 4 It is a schematic structural diagram of a privacy compliance detection device provided by an embodiment of the present application;
[0087] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0088] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0089] In the technical solution of this application, the collection, storage, use, processing, transmission, sharing, transfer, provision, and disclosure of the user's personal information comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0090] In the privacy compliance detection in the manual mode, due to reasons such as the lack of understanding of privacy protection compliance by product developers and the lack of professional ability to evaluate personal information security, it is easy to lead to difficult-to-grasp compliance scales, insufficient accuracy, and low efficiency in the manual mode.
[0091] Therefore, in the embodiments of this application, a method for automatically analyzing the privacy compliance of mobile applications based on deep learning is considered. By training a privacy compliance detection model through deep learning, automated privacy compliance detection is realized, and the efficiency of privacy compliance detection is improved. At the same time, considering that the privacy compliance detection standards issued by relevant departments, that is, compliance documents, are continuously updated over time, in order to ensure the accuracy of the privacy compliance detection model, it is also necessary to automatically iteratively train the privacy compliance detection model when the privacy compliance detection standards change to achieve synchronous updates of the privacy compliance detection standards.
[0092] Next, the training method of the privacy compliance detection model provided by this application will be described in detail through specific embodiments. It can be understood that these specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0093] Figure 1 It is a schematic flowchart of a training method for a privacy compliance detection model provided by an embodiment of this application. As Figure 1 shown, the method includes:
[0094] S101. Determine the function type of the application program sample.
[0095] The application program sample is an application program used for model training. The function types of the application program are such as map navigation, online car-hailing, instant messaging, online community, online payment, news and information, online shopping, express delivery, traffic ticket, etc. The specifications for collecting, storing, using, sharing, transferring, publicly disclosing, and deleting the user's personal information of application programs with different function types may be different, that is, the privacy compliance detection standards corresponding to application programs with different function types may be different. Therefore, when training the privacy compliance detection model, first determine the function type of the application program sample and perform subsequent steps based on the function type.
[0096] S102. Judge whether the change amount of the number of non-compliant application programs corresponding to the function type in the non-compliant application program library within a preset time period exceeds a preset value. If it exceeds, judge whether the privacy compliance detection standard corresponding to the function type has changed.
[0097] To achieve synchronous update of privacy compliance detection standards, it is necessary to monitor the latest privacy compliance detection standards corresponding to the function types of application samples. It can be understood that when the privacy compliance detection standards change, it is possible that a large number of applications will be determined as non-compliant applications according to the latest privacy compliance detection standards within a certain period of time, that is, the number of non-compliant applications in the non-compliant application library will increase significantly. Therefore, when the change amount of the number of non-compliant applications corresponding to the function type of the application sample in the non-compliant application library within a preset time period exceeds a preset value, it may be that the privacy compliance detection standards corresponding to this function type have changed. Therefore, at this time, obtain the latest privacy compliance detection standards corresponding to this function type; determine whether the currently adopted privacy compliance detection standards are consistent with the latest privacy compliance detection standards; if they are not consistent, it is determined that the privacy compliance detection standards corresponding to the function type have changed. When the privacy compliance detection standards change, it is necessary to perform iterative training on the privacy compliance detection model to ensure its accuracy.
[0098] Optionally, determine whether the currently adopted privacy compliance detection standards are consistent with the latest privacy compliance detection standards through at least one of the following methods:
[0099] In one implementation, determine whether the content of the currently adopted privacy compliance detection standards is consistent with the content of the latest privacy compliance detection standards. For example, perform a text comparison on the content of the currently adopted privacy compliance detection standards and the content of the latest privacy compliance detection standards to determine whether there is any changed text. If there is changed text, it is determined that the content of the currently adopted privacy compliance detection standards is inconsistent with the content of the latest privacy compliance detection standards; if there is no changed text, it is determined that the content of the currently adopted privacy compliance detection standards is consistent with the content of the latest privacy compliance detection standards.
[0100] In another implementation, determine whether the version identifier of the currently adopted privacy compliance detection standards is consistent with the version identifier of the latest privacy compliance detection standards. Each published privacy compliance detection standard can have a corresponding version identifier. If the version identifier of the currently adopted privacy compliance detection standards is different from the version identifier of the latest privacy compliance detection standards, it is determined that the two are inconsistent; if the version identifier of the currently adopted privacy compliance detection standards is the same as the version identifier of the latest privacy compliance detection standards, it is determined that the two are consistent.
[0101] In yet another embodiment, it is determined whether the update time of the currently adopted privacy compliance detection standard is the same as the update time of the latest privacy compliance detection standard. Each published privacy compliance detection standard may have a corresponding update time. If the update time of the currently adopted privacy compliance detection standard is different from the update time of the latest privacy compliance detection standard, it is determined that the two are inconsistent; if the update time of the currently adopted privacy compliance detection standard is the same as the update time of the latest privacy compliance detection standard, it is determined that the two are consistent.
[0102] S103. If the privacy compliance detection standard corresponding to the function type changes and it is determined that there is a data collection item in the text that has changed in the privacy compliance detection standard, obtain a privacy detection information sample corresponding to the application program sample, and update the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain a privacy compliance detection model.
[0103] Among them, the label of the privacy detection information sample is marked according to the changed privacy compliance detection standard, and the label is used to represent that the application program sample is compliant or non-compliant.
[0104] In the case where the privacy compliance detection standard changes, it is necessary to retrain the initial privacy compliance detection model using the privacy detection information sample to obtain the final privacy compliance detection model. It can be understood that when it is determined that the privacy compliance detection standard changes, some parts involving user personal information, privacy policies, etc. may not change, but only the text of other irrelevant parts changes. Therefore, in the embodiments of the present application, when the privacy compliance detection standard corresponding to the function type of the application program sample changes, it is also determined whether there is a data collection item in the changed text. If so, obtain the privacy detection information sample corresponding to the application program sample for iterative training.
[0105] Optionally, the privacy detection information sample of the application program sample includes at least one of the privacy policy text of the application program sample, the call information of sensitive functions, the transmission information of sensitive data, and the acquisition information of sensitive permissions.
[0106] It can be understood that due to the change in the privacy compliance detection standard, the annotation results of the same privacy detection information sample using the privacy compliance detection standards before and after the change may be different. Therefore, in this step, the privacy detection information sample corresponding to the application program sample obtained should be a sample marked using the changed privacy compliance detection standard, that is, the latest privacy compliance detection standard.
[0107] Optionally, when it is determined that the privacy compliance detection standard has changed, obtain the first text that has changed in the privacy compliance detection standard; perform semantic analysis on the first text to determine whether there is a second text containing a data collection item in the first text; if there is a second text, it is determined that there is a data collection item in the text that has changed in the privacy compliance detection standard. The data collection item may refer to obtaining user data or permissions, etc. By performing semantic analysis on the first text that has changed in the privacy compliance detection standard to determine whether there is a second text containing a data collection item, unnecessary model training can be avoided when the privacy compliance detection standard has not changed substantially.
[0108] Optionally, the privacy compliance detection model in the embodiments of the present application includes two parts, one part is a feature extraction model, and the other part is a classification model. Among them, the feature extraction model is used to extract the feature information of the privacy detection information sample, and the classification model is used to determine whether the privacy detection information sample is compliant or non-compliant according to the input feature information, that is, whether the application sample is compliant or non-compliant.
[0109] Input the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector; input the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant; determine the loss information according to the prediction result and the label corresponding to the privacy detection information sample; update the model parameters of the initial privacy compliance detection model according to the loss information to obtain the privacy compliance detection model. Since the privacy detection information sample is labeled using the latest privacy compliance detection standard, through this method, the obtained privacy compliance detection model can not only achieve automated detection but also keep in sync with the privacy compliance detection standard, ensuring the accuracy of the results.
[0110] Based on the above embodiments, optionally, the feature extraction model in the privacy compliance detection model can be a CNN model. For example, this CNN model includes two convolutional layers and two pooling layers. Among them, the convolutional layer has 64 convolutional kernels, which are two-dimensional matrices of size 8*8, and the pooling layer is a two-dimensional matrix of size 2*2. The feature information of the privacy detection information is extracted through this CNN model. Optionally, the classification model in the privacy compliance detection model can be a Support Vector Machines (SVM). Input the feature information of the privacy detection information into the SVM to obtain a classification result of compliant or non-compliant.
[0111] Based on the above embodiments, the application of the privacy compliance detection model is described.
[0112] Figure 2 It is a schematic flowchart of a privacy compliance detection method provided by the embodiments of the present application. AsFigure 2 As shown in the figure, the method includes:
[0113] S201. Obtain the privacy detection information of the application to be detected.
[0114] Optionally, the privacy detection information of the application to be detected includes at least one of the privacy policy text of the application to be detected, the call information of sensitive functions, the transmission information of sensitive data, and the acquisition information of sensitive permissions.
[0115] Optionally, during the running process of the application to be detected, the call information of sensitive functions and / or the acquisition information of sensitive permissions can be obtained through an automated decompilation method.
[0116] Optionally, during the running process of the application to be detected, in the data transmission paths corresponding to the respective functions of the application to be detected, the transmission information of sensitive data is obtained by packet capture.
[0117] Optionally, the privacy policy text is obtained in the corresponding storage path of the application to be detected.
[0118] S202. Input the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant.
[0119] Among them, the privacy compliance detection model is trained according to the method in the foregoing embodiment. For example, the privacy detection information is input into the feature extraction model of the privacy compliance detection model to obtain a feature vector corresponding to the privacy detection information; the feature vector is input into the classification model of the privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant.
[0120] In the embodiment of the present application, by using a deep learning model, the privacy compliance detection of mobile applications can be automatically realized. At the same time, since the deep learning model can be iteratively updated as the privacy compliance detection standard changes, the accuracy of the detection result can be guaranteed.
[0121] Figure 3 It is a schematic structural diagram of a training device for a privacy compliance detection model provided by an embodiment of the present application. As Figure 3 shown, the training device 300 of the privacy compliance detection model includes:
[0122] A determination module 301, configured to determine the function type of the application sample;
[0123] A judgment module 302, configured to judge whether the change amount of the number of non-compliant application programs corresponding to the function type in the non-compliant application program library within a preset time period exceeds a preset value. If it exceeds, judge whether the privacy compliance detection standard corresponding to the function type has changed;
[0124] A training module 303, configured to, if the privacy compliance detection standard corresponding to the function type changes and it is determined that there is a data collection item in the text that has changed in the privacy compliance detection standard, obtain a privacy detection information sample corresponding to the application program sample, where the label of the privacy detection information sample is marked according to the changed privacy compliance detection standard, and the label is used to represent whether the application program sample is compliant or non-compliant; update the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain a privacy compliance detection model.
[0125] In one implementation, the training module 303 is configured to:
[0126] Obtain a first text that has changed in the privacy compliance detection standard;
[0127] Perform semantic analysis on the first text to determine whether there is a second text containing a data collection item in the first text;
[0128] If there is a second text, determine that there is a data collection item in the text that has changed in the privacy compliance detection standard.
[0129] In one implementation, the judgment module 302 is configured to:
[0130] Obtain the latest privacy compliance detection standard corresponding to the function type;
[0131] Determine whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard;
[0132] If they are not consistent, determine that the privacy compliance detection standard corresponding to the function type has changed.
[0133] In one implementation, the judgment module 302 is configured to:
[0134] Determine whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard by at least one of the following methods:
[0135] Determine whether the content of the currently adopted privacy compliance detection standard is consistent with the content of the latest privacy compliance detection standard;
[0136] Determine whether the version identifier of the currently adopted privacy compliance detection standard is consistent with the version identifier of the latest privacy compliance detection standard;
[0137] Determine whether the update time of the currently adopted privacy compliance detection standard is consistent with the update time of the latest privacy compliance detection standard.
[0138] In one implementation, the training module 303 is configured to:
[0139] Input the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector;
[0140] Input the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant;
[0141] Determine the loss information according to the prediction result and the label corresponding to the privacy detection information sample;
[0142] Update the model parameters of the initial privacy compliance detection model according to the loss information to obtain a privacy compliance detection model.
[0143] The training device for the privacy compliance detection model provided by the embodiments of the present application can be used to execute the training method of the privacy compliance detection model in any of the above embodiments. The implementation principles and technical effects are similar and will not be elaborated here.
[0144] Figure 4 It is a structural schematic diagram of a privacy compliance detection device provided by the embodiments of the present application. As Figure 4 shown, the privacy compliance detection device 400 includes:
[0145] An acquisition module 401, configured to acquire the privacy detection information of the application to be detected;
[0146] A detection module 402, configured to input the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant. The privacy compliance detection model is trained according to the method in the first aspect.
[0147] In one implementation, the privacy detection information includes at least one of a privacy policy text, call information of sensitive functions, transmission information of sensitive data, and acquisition information of sensitive permissions.
[0148] In one implementation, the privacy detection information includes call information of sensitive functions and / or acquisition information of sensitive permissions;
[0149] The acquisition module 401 is configured to:
[0150] During the running of the application to be detected, obtain the call information of sensitive functions and / or the acquisition information of sensitive permissions through an automated decompilation method.
[0151] In one implementation, the privacy detection information includes transmission information of sensitive data;
[0152] The acquisition module 401 is configured to:
[0153] During the running of the application to be detected, in the data transmission paths corresponding to the functions of the application to be detected, the transmission information of sensitive data is obtained by packet capture.
[0154] In one implementation, the detection module 402 is configured to:
[0155] Input the privacy detection information into the feature extraction model of the privacy compliance detection model to obtain the feature vector corresponding to the privacy detection information;
[0156] Input the feature vector into the classification model of the privacy compliance detection model to obtain the detection result of whether the application to be detected is compliant.
[0157] The privacy compliance detection device provided by the embodiments of the present application can be used to execute the privacy compliance detection method in any of the above embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here.
[0158] Figure 5 It is a schematic structural diagram of an electronic device provided by the embodiments of the present application. As Figure 5 shown, the induction cooker 500 includes a memory 501 and a processor 502, and the memory 501 and the processor 502 are connected through a bus 503.
[0159] The memory 501 is used to store computer programs.
[0160] The processor 502 is configured to implement the training method or the privacy compliance detection method of the privacy compliance detection model in any of the above embodiments when the computer program is executed.
[0161] The embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the training method or the privacy compliance detection method of the privacy compliance detection model in any of the above embodiments is implemented.
[0162] The embodiments of the present application further provide a computer program product, including a computer program. When the computer program is executed by a processor, the training method or the privacy compliance detection method of the privacy compliance detection model in any of the above embodiments is implemented.
[0163] Optionally, the above-mentioned processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps in the method embodiments disclosed in conjunction with the present application may be directly embodied as being executed and completed by a hardware processor, or may be executed and completed by a combination of hardware and software modules in the processor.
[0164] Those of ordinary skill in the art can understand that all or part of the steps for implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: various media such as ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0165] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A training method for a privacy compliance detection model, characterized in that, Including: Determine the function type of the application sample; Judge whether the change amount of the number of non-compliant applications corresponding to the function type in the non-compliant application library within a preset time period exceeds a preset value. If it exceeds, judge whether the privacy compliance detection standard corresponding to the function type has changed; If the privacy compliance detection standard corresponding to the function type has changed, and it is determined that there is a data collection item in the changed text of the privacy compliance detection standard, obtain the privacy detection information sample corresponding to the application sample. The label of the privacy detection information sample is marked according to the changed privacy compliance detection standard, and the label is used to represent whether the application sample is compliant or non-compliant; Input the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector; Input the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant; Determine the loss information according to the prediction result and the label corresponding to the privacy detection information sample; Update the model parameters of the initial privacy compliance detection model according to the loss information to obtain a privacy compliance detection model.
2. The method according to claim 1, characterized in that, The determination that there is a data collection item in the changed text of the privacy compliance detection standard includes: Obtain the first text that has changed in the privacy compliance detection standard; Perform semantic analysis on the first text to judge whether there is a second text containing a data collection item in the first text; If there is a second text, determine that there is a data collection item in the changed text of the privacy compliance detection standard.
3. The method according to claim 1 or 2, characterized in that, The judgment on whether the privacy compliance detection standard corresponding to the function type has changed includes: Obtain the latest privacy compliance detection standard corresponding to the function type; Judge whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard; If they are not consistent, determine that the privacy compliance detection standard corresponding to the function type has changed.
4. The method according to claim 3, characterized in that, The judgment on whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard includes: Judge whether the currently adopted privacy compliance detection standard is consistent with the latest privacy compliance detection standard through at least one of the following methods: Judge whether the content of the currently adopted privacy compliance detection standard is consistent with the content of the latest privacy compliance detection standard; Judge whether the version identifier of the currently adopted privacy compliance detection standard is consistent with the version identifier of the latest privacy compliance detection standard; Judge whether the update time of the currently adopted privacy compliance detection standard is consistent with the update time of the latest privacy compliance detection standard.
5. A privacy compliance detection method, characterized in that, Including: Obtain the privacy detection information of the application to be detected; Input the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant. The privacy compliance detection model is trained according to the method described in any one of claims 1-4.
6. The method according to claim 5, characterized in that, The privacy detection information includes at least one of a privacy policy text, call information of sensitive functions, transmission information of sensitive data, and acquisition information of sensitive permissions.
7. The method according to claim 6, characterized in that, The privacy detection information includes call information of sensitive functions and / or acquisition information of sensitive permissions; The obtaining of the privacy detection information of the application to be detected includes: During the running of the application to be detected, obtaining the call information of the sensitive functions and / or the acquisition information of the sensitive permissions through an automated decompilation method.
8. The method according to claim 6 or 7, characterized in that, The privacy detection information includes transmission information of sensitive data; The obtaining of the privacy detection information of the application to be detected includes: During the running of the application to be detected, in the data transmission paths corresponding to the respective functions of the application to be detected, obtaining the transmission information of the sensitive data through packet capture.
9. The method according to any one of claims 5-7, characterized in that, The inputting of the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant includes: Inputting the privacy detection information into the feature extraction model of the privacy compliance detection model to obtain a feature vector corresponding to the privacy detection information; Inputting the feature vector into the classification model of the privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant.
10. A training device for a privacy compliance detection model, characterized in that, Including: A determination module for determining the function type of an application sample; A judgment module for judging whether the change amount of the number of non-compliant application programs corresponding to the function type in the non-compliant application program library within a preset time period exceeds a preset value. If it exceeds, it is judged whether the privacy compliance detection standard corresponding to the function type has changed; A training module for, if the privacy compliance detection standard corresponding to the function type has changed and it is determined that there is a data collection item in the text where the privacy compliance detection standard has changed, obtaining a privacy detection information sample corresponding to the application sample, the label of the privacy detection information sample being marked according to the changed privacy compliance detection standard, the label being used to represent whether the application sample is compliant or non-compliant; updating the model parameters of the initial privacy compliance detection model according to the privacy detection information sample and the corresponding label to obtain a privacy compliance detection model; The training module is specifically used for: Inputting the privacy detection information sample into the initial feature extraction model in the initial privacy compliance detection model to obtain a feature vector; Inputting the feature vector into the initial classification model in the initial privacy compliance detection model to obtain a prediction result on whether the privacy detection information sample is compliant; Determining loss information according to the prediction result and the label corresponding to the privacy detection information sample; Updating the model parameters of the initial privacy compliance detection model according to the loss information to obtain a privacy compliance detection model.
11. A privacy compliance detection device, characterized in that, Including: An obtaining module for obtaining the privacy detection information of the application to be detected; A detection module for inputting the privacy detection information into a pre-trained privacy compliance detection model to obtain a detection result on whether the application to be detected is compliant, the privacy compliance detection model being trained according to the method described in any one of claims 1-4.
12. An electronic device, characterized in that, Including a memory and a processor, the memory and the processor are connected; The memory is used for storing a computer program; The processor is configured to implement the method according to any one of claims 1-9 when the computer program is executed.
13. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1-9 above is implemented.
14. A computer program product, characterized in that, A computer program is included, and when the computer program is executed by the processor, the method according to any one of claims 1-9 is implemented.
Citation Information
Patent Citations
Systems and methods for computing data privacy-utility tradeoff
CN108885673A
Deep learning method and system based on privacy protection, server and storage medium
CN111325322A