User-oriented understandable App privacy report enhancement method and system
By capturing the sensitive permission calling behavior of apps and using large language models for purpose reasoning and whitelist database construction, the user-friendliness and system integration issues of app privacy reports are solved, and efficient and low-cost privacy reporting enhancements are achieved.
Patent Information
- Application Number
- CN202510829835.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-09-30
AI Technical Summary
Existing app privacy reports lack user-semantic friendly expression, lack the ability to perceive runtime context, are difficult to integrate with native system functions, and have high computational costs and poor scalability.
By capturing the sensitive permission call behavior of the App, extracting function call stack information, combining the privacy policy and application description, using a large language model to perform runtime purpose inference, and building a whitelist database, the comprehensibility and accuracy of the privacy report are enhanced.
It improves the transparency and compliance of users' App data behavior, enhances the user understandability and computational efficiency of privacy reports, and reduces development and deployment costs.
Smart Images

Figure CN120724477A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology and discloses a method and system for enhancing app privacy reports that are understandable to users. Background Art
[0002] The Application (App) privacy report is a system function that records an app's access to user privacy data and network activities. It is mainly used to help users intuitively monitor the app's use of sensitive permissions, improve data transparency and privacy protection awareness.
[0003] While existing app privacy reports can identify privacy usage purposes and conduct network analysis, they still face the following key challenges in improving user understandability, system integration capabilities, and computational scalability: (1) Lack of user-friendly semantic expression: Existing methods can only generate structured labels or static classification results, lacking user-oriented natural language expression and personalized context understanding. The generated explanations of usage purposes are often abstract, formulaic, mechanical, or general, making it difficult for ordinary users to truly understand the reasons behind data access behavior.
[0004] (2) Lack of awareness of runtime context: Existing methods rely on static code analysis, application market text, or predefined rules. They do not have the ability to dynamically perceive the behavior of apps when running on real devices, and cannot perform runtime interpretation based on the user's actual interactive behavior on the device, resulting in limited coverage and insufficient accuracy.
[0005] (3) Difficulty integrating with native system functions: Existing tools for identifying privacy usage purposes operate as independent analysis systems and cannot be directly integrated into native operating system privacy functions (such as iOS App privacy reports). This results in the inability to link purpose inference results with real user usage scenarios and lacks the ability to supplement the system's existing privacy data display.
[0006] (4) High computational cost and poor scalability: Existing methods rely on deep learning models or specialized classifiers, whose training typically requires high-quality labeled datasets, complex feature engineering, and extensive computing resources, resulting in high development and deployment costs. Furthermore, due to limitations in the source of training data, the models have poor generalization capabilities for new types of apps or cross-category behaviors, making them difficult to apply stably in real systems over the long term. This also leads to significant limitations in the scalability and continuous evolution capabilities of existing methods. Summary of the Invention
[0007] The purpose of the present invention is to provide a user-understandable App privacy report enhancement method and system to solve the technical problems of existing methods such as lack of user semantic-friendly expression, lack of perception of runtime context, difficulty in integration with system native functions, high computational cost and poor scalability.
[0008] A first aspect of the present invention provides a method for enhancing app privacy reporting to be understandable to users, comprising: Capture the app's call behavior for sensitive permissions and extract the function call stack information triggered by the call behavior in the current thread; Obtain the privacy policy and application description of the App, and determine the sensitive permission usage information of the App based on the privacy policy, where the sensitive permission usage information includes multiple triplets, each of which includes the user, permission type, and purpose of use; Inputting the function call stack information, the sensitive permission usage information, and the application description into a large language model to obtain the usage purpose corresponding to the calling behavior; The purpose of use corresponding to the calling behavior is expanded to the privacy report of the App.
[0009] Preferably, before capturing the App's call behavior for sensitive permissions, the following is also included: The application programming interface of the App is monitored using a dynamic instrumentation method.
[0010] Preferably, the reasoning method adopted by the large language model is the thought chain reasoning method.
[0011] Preferably, the sensitive permissions include at least one of location permissions, camera permissions, microphone permissions, contact permissions, photo library permissions, media library permissions and screen recording permissions.
[0012] Preferably, after expanding the usage purpose corresponding to the calling behavior to the privacy report of the App, it also includes: Acquire domain name information of multiple network domain names based on network intelligence resources, and build a whitelist database based on the domain name information; Collect the network domain names accessed by the App, and match the network domain names accessed by the App with the whitelist database to obtain domain name information of the network domain names accessed by the App; The domain name information of the network domain name accessed by the App is appended to the privacy report.
[0013] Preferably, after matching the network domain name accessed by the App with the whitelist database to obtain the domain name information of the network domain name accessed by the App, the method further includes: If the network domain name accessed by the App is not matched in the whitelist database, the network domain name accessed by the App is recorded in the candidate pool of the whitelist database.
[0014] Preferably, the network domain name accessed by the App is collected, specifically: The network domain names accessed by the App are collected from the privacy report of the App.
[0015] Preferably, the network domain name accessed by the App is collected, specifically: Monitor the application programming interface of the App to collect the network domain names accessed by the App.
[0016] Preferably, the domain name information includes the name of the organization to which the domain name belongs, the service type of the domain name, and the purpose of the domain name.
[0017] A second aspect of the present invention provides a system for enhancing user-understandable app privacy reports based on the above-mentioned method for enhancing user-understandable app privacy reports, comprising: A behavior capture module is used to capture the app's call behavior for sensitive permissions and extract the function call stack information triggered by the call behavior in the current thread; An information acquisition module, configured to obtain the privacy policy and application description of the App and determine sensitive permission usage information of the App based on the privacy policy, wherein the sensitive permission usage information includes multiple triples, each of which includes a user, a permission type, and a purpose of use; an enhancement module, the enhancement module being configured to input the function call stack information, the sensitive permission usage information, and the application description into a large language model to obtain a usage purpose corresponding to the calling behavior; An expansion module, which is used to expand the usage purpose corresponding to the calling behavior to the privacy report of the App.
[0018] Compared with the prior art, the user-understandable App privacy report enhancement method and system of the present invention have the following beneficial effects: (1) Enhance the understandability of the purpose of sensitive permission calls: Through runtime purpose inference, users can directly see the reasons or usage explanations behind each sensitive permission call in the privacy report. For example, the privacy report no longer simply displays "A certain app accessed location permissions 5 times today", but is accompanied by explanations such as "Used to provide nearby restaurant recommendations". This improvement makes up for the lack of purpose information in existing technologies, allowing users to have an intuitive understanding of why the app collects certain data.
[0019] (2) Clarifying the third-party entities involved in network requests: Domain name information including the name of the organization to which the domain name belongs, the type of domain name service, and the purpose of the domain name is added to the App privacy report, thereby enhancing the description of the domain name in the privacy report and providing users with friendly instructions, mapping the originally obscure domain name to a specific service or company name. Users can understand which third parties the App sends data to and the nature of these third parties' businesses (advertising, analysis, social networking, etc.). Important background information is added to the existing privacy report to help users identify potential data sharing behaviors.
[0020] (3) Improve the accuracy and compliance of user privacy decisions: The rich information provided by the embodiments of the present invention enables users to better understand the data behavior of the App, so that they can make more informed privacy decisions. For example, if it is found that the purpose of an App accessing data is unreasonable (such as a simple tool App frequently obtaining the address book for marketing purposes), the user can adjust the permission authorization or uninstall the App accordingly. At the same time, the user-understandable App privacy report enhancement method and system of the present invention better meet the transparency requirements of privacy regulations (such as the notification of data usage purpose required by GDPR) and enhance the performance in terms of privacy compliance. Overall, through the combination of the two major features of runtime purpose reasoning and network domain name description, users have obtained unprecedented transparency, which will significantly improve the user's ability to manage their own privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 2 is a flowchart of a method for enhancing user-understandable App privacy reports in an embodiment of the present invention. DETAILED DESCRIPTION
[0022] In the following description, specific details such as particular system structures and techniques are provided for purposes of illustration, not limitation, to facilitate a thorough understanding of the embodiments of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present invention with unnecessary detail.
[0023] The first aspect of the embodiment of the present invention provides a method for enhancing App privacy reports that are understandable to users, such as Figure 1 As shown, including: Step 1: Capture the app's call behavior for sensitive permissions and extract the function call stack information triggered by the call behavior in the current thread.
[0024] This embodiment of the present invention uses dynamic instrumentation to monitor the app's Application Programming Interface (API) before step 1, thereby capturing the app's calls to sensitive permissions. For example, the dynamic instrumentation toolkit Frida is used to perform runtime hooks on the API, and the Thread.backtrace([context, backtracer]) method is used to capture the function call stack information during the API call.
[0025] Based on the various sensitive permissions displayed in existing privacy reports, this embodiment of the present invention defines sensitive permissions as including at least one of location permissions, camera permissions, microphone permissions, contact permissions, photo library permissions, media library permissions, and screen recording permissions. When an app initiates a call for a sensitive permission, such as "get current location" or "access address book," Frida automatically captures the call and extracts the call stack information (Call Stack) triggered by the call in the current thread. This call stack information records the entire function path from the app's main function to the corresponding API, providing detailed dynamic context for subsequent behavior attribution.
[0026] In a weather app called ColorClouds, two different calls to the location API CLLocation-coordinate are shown: In the first call, the call stack shows that the CYNewSunMoonView:updateViewWithForecastCardVM method triggers the API call, indicating that location data may be used to update the weather forecast view. In the second call, it can be seen that the call originates from CYADFactory:adParam, followed by a series of method calls, including CYInsertADManager:requestHotOpenADfinished, etc., which means that the app is preparing and requesting ads, possibly for personalized ad push based on the user's location. This comparison highlights that even calls to the same API may have very different access purposes. If relying on static code analysis or text matching, it is difficult to accurately restore the actual usage scenario. However, because the present invention uses runtime function call stack information, it can accurately restore the actual data access scenario.
[0027] Step 2: Obtain the App's privacy policy and application description, and determine the App's sensitive permission usage information based on the privacy policy. The sensitive permission usage information includes multiple triplets, each of which includes the user, permission type, and purpose of use.
[0028] The embodiment of the present invention obtains the privacy policy of the corresponding App from the App Store page. Furthermore, the embodiment of the present invention also obtains the application description of the corresponding App from the App Store page to understand the main functions and services of the App.
[0029] Since privacy policies are often long, this paper divides the privacy policy into multiple segments, and then calls a large language model (such as GPT-4) to extract information segment by segment to extract the sensitive permission usage information of the App. The sensitive permission usage information includes multiple triplets, each of which includes the user, permission type, and purpose of use, i.e.<subject, object, scenario> The above-mentioned users are application developers or third-party services; the above-mentioned permission types are specifically location permissions, camera permissions, microphone permissions, contact permissions, photo library permissions, media library permissions and screen recording permissions; the above-mentioned usage purposes are mainly to indicate the purpose or scenario of the call, such as for navigation, advertising push, etc. For example, according to the privacy policy, the sentence "Developers will request access to location permissions for pushing local weather information" can be extracted and then converted into sensitive permission usage information in the form of "<Developers, location permissions, push weather information>".
[0030] Step 3: Input the function call stack information, sensitive permission usage information, and application description into the Large Language Model (LLM) to obtain the usage purpose corresponding to the calling behavior.
[0031] After obtaining function call stack information in step 1 and the app's sensitive permission usage information and application description in step 2, this embodiment of the present invention constructs a composite prompt for input into the large language model based on the function call stack information, sensitive permission usage information, and application description. In designing the composite prompt for the large language model, this embodiment of the present invention employs a Chain of Thought (COT) reasoning method to guide the reasoning process. Based on the composite prompt, the large language model gradually infers the motivation and purpose behind the sensitive permission call and outputs a concise natural language explanation. For example, for a backend call to obtain location permission, the large language model returns a concise description of the purpose: "This call is used to obtain the current location to push a weather forecast." If the method or class name in the function call stack information matches a third-party software development kit (SDK), this embodiment of the present invention can also use a pre-built third-party library database to assist in determining whether the user is a non-first-party module, further enhancing the accuracy of the reasoning and explanation.
[0032] The embodiment of the present invention inputs both the application description and the sensitive permission usage information into the large language model, thereby enabling the large language model to make more appropriate purpose inferences.
[0033] The reasoning process of the large language model in this embodiment of the present invention begins by parsing API function call stack information. By identifying the class and method names of the API calls in the function call stack, it preliminarily determines whether the data access originates from the application itself (first-party) or a third-party library, and constructs the corresponding reasoning path accordingly. Subsequently, the LLM cross-references relevant information in the application description and privacy policy to further verify and refine the inferred data access intent, namely, the purpose of use. Table 1 shows an example of inferring purpose based on the COT reasoning method. Table 1 includes prompt types and their corresponding instantiation methods, covering data preparation, example input, reasoning process, and final example output. Example 1 illustrates a scenario where the data serves the application itself and is included in the privacy policy, while Example 2 illustrates a scenario where the data serves a third party but is not included in the privacy policy. This step-by-step reasoning approach enables the LLM to progressively integrate various types of information, resulting in more accurate and interpretable inferences.
[0034] Table 1 Examples of inferences about usage purposes based on the COT reasoning method
[0035] Step 4: Expand the usage purpose corresponding to the calling behavior to the App's privacy report.
[0036] This embodiment of the present invention expands the usage purpose corresponding to the call behavior to the corresponding entry in the app privacy report and presents it to the user in natural language on the front-end interface. For example, the original information "App X accessed location permissions 3 times today" is expanded to include "Mainly used to provide route navigation and advertising recommendation services," significantly improving users' understanding of data usage behavior. The usage purpose corresponding to the call behavior can also be recorded in the log for subsequent behavior audits or compliance analysis.
[0037] This method for enhancing app privacy reporting for user understanding utilizes runtime code behavior data (i.e., function call stack information) and textual descriptions (i.e., privacy policy and app descriptions) to leverage the reasoning capabilities of large language models to interpret the intended use of sensitive permissions. This multi-source collaborative approach leverages the powerful knowledge and reasoning capabilities of LLMs by fusing dynamic code behavior data with static textual descriptions. This lightweight approach avoids the prior art's reliance on static code, exhibiting excellent scalability and cross-scenario adaptability, enabling efficient interpretation of runtime call behavior without the need for model training.
[0038] In addition to the aforementioned enhancements to the explanation of the purpose of use corresponding to the call behavior in the App privacy report, the embodiments of the present invention also include the following enhancements to the explanation of domain names in the App privacy report. The core of the relevant content for domain name explanation is to build a whitelist database with broad coverage, clear semantics, and sustainable evolution, and integrate it with the privacy reporting function to provide users with highly readable and context-friendly explanation information. Specifically: After expanding the purpose of use corresponding to the call behavior to the App privacy report, it also includes: Step 5: Obtain domain name information of multiple network domain names based on network intelligence resources, and build a whitelist database based on the domain name information.
[0039] The above domain name information includes the name of the organization to which the domain name belongs, the service type of the domain name (such as "behavioral analysis" or "advertising"), and the purpose of the domain name.
[0040] This embodiment of the present invention obtains domain name information for various network domains from multiple public network intelligence resources. These include, but are not limited to, the TrackerDB database provided by Ghostery, the Alexa website ranking database, and the Netify network service identification database. The process of obtaining domain name information requires standardizing the format of data from different sources, merging, cleaning, deduplicating, and normalizing multiple descriptions of the same domain name, and annotating them with the organization name, service type (e.g., advertising, analytics, CDN, login authentication), and purpose (e.g., "for counting page visit activity"). This process generates an initial whitelist database.
[0041] For new or long-tail domain names not covered by the aforementioned network intelligence resources, embodiments of the present invention use a large language model (such as GPT-4) for auxiliary identification. By constructing standardized prompts, the large language model infers the organization name, service type, and purpose behind the domain name and generates a concise natural language description. For example, if you input "ef-dongfeng.tanx.com," the large language model outputs "This domain name belongs to Alibaba Group and is used for advertising resource bidding and delivery services." After formatting and determining semantic rationality of the large language model output, it can be added to the aforementioned whitelist database as a supplement.
[0042] For domain names that cannot be reliably identified through existing network intelligence resources or large language models, the embodiment of the present invention marks them as "pending confirmation" and submits them to security analysts for review. Reviewers can determine the background of the domain name through WHOIS information, domain name registration agency data, IP attribution reverse lookup, web page content identification, etc., and provide standard description entries. The results of the review are written into the above-mentioned whitelist database, and the source and confirmation time are recorded to form a continuously evolving whitelist database. The database of the embodiment of the present invention supports regular automatic update tasks and manual supplementation collaborative mechanisms to ensure that mainstream and emerging domain names are always covered.
[0043] Step 6: Collect the network domain names accessed by the App, and match the network domain names accessed by the App with the whitelist database to obtain the domain name information of the network domain names accessed by the App.
[0044] In this embodiment of the present invention, collecting the network domain names accessed by an app includes directly extracting the "App Network Activity" item from the app's privacy report to obtain the network domain names accessed by the app, or using a network proxy tool to monitor the app's application programming interface in real time to collect the network domain names accessed by the app. All collected network domain names must be uniformly formatted, retaining only the primary domain portion (e.g., extracting "api.track.example.com:443 / path" to "example.com"), and deduplicating. This process is standardized.
[0045] Each standardized domain name is then queried against the aforementioned whitelist database. If a match is found, the domain name information is extracted and made visible to the user. If a match is not found, the large language model is used to generate a temporary explanation or prompt "Unknown domain name, awaiting further identification." This means that the domain name accessed by the app is recorded in the candidate pool of the whitelist database, which will be determined through regular batch updates or manual review to determine whether it will be added to the whitelist database.
[0046] Step 7. Append the domain name information of the network domain accessed by the App to the privacy report.
[0047] In the privacy report interface, users can view the external domain name entries connected to the app. This embodiment of the present invention adds the domain name information obtained using the above method to the original domain name. This display can be aggregated by organization, grouped by purpose, or displayed with a click-to-expand feature for detailed explanations, ensuring that users can quickly browse and deeply understand the network domains accessed by the app.
[0048] This embodiment of the present invention integrates existing network intelligence resources with the reasoning capabilities of LLM to identify the ownership and functional annotation of network domain names accessed by apps, and directly displays them in the app privacy report. This allows users to clearly understand the third-party entities and purposes behind each network domain name, enhancing the understandability of the network domain name list. Compared to static database lookup solutions, this invention has significant coverage and semantic interpretation capabilities, which can overcome the obscure domain name information in existing privacy reports, thereby allowing users to have greater control over the flow of their private data.
[0049] The second aspect of the present invention provides a user-understandable App privacy report enhancement system based on the above-mentioned user-understandable App privacy report enhancement method, including a behavior capture module, an information acquisition module, an enhancement module and an expansion module.
[0050] The behavior capture module is used to capture apps' calls to sensitive permissions and extract the function call stack information triggered by these calls in the current thread. The behavior capture module records all function call stack information and deduplicates it within a set time window to reduce redundant data.
[0051] The sensitive permissions in the embodiment of the present invention include at least one of location permission, camera permission, microphone permission, contact permission, photo library permission, media library permission and screen recording permission.
[0052] The information acquisition module is used to obtain the privacy policy of the App and determine the sensitive permission usage information of the App based on the privacy policy. The sensitive permission usage information includes multiple triplets, each of which includes the user, permission type, and purpose of use.
[0053] The enhancement module is used to input function call stack information and sensitive permission usage information into the large language model to obtain the usage purpose corresponding to the calling behavior.
[0054] The extension module is used to expand the usage purpose corresponding to the calling behavior to the App's privacy report.
[0055] Furthermore, the user-understandable App privacy report enhancement system of an embodiment of the present invention also includes a database construction module, a matching module and an additional module.
[0056] The database construction module is used to obtain domain name information of various network domain names based on network intelligence resources, and to build a whitelist database based on the domain name information.
[0057] The matching module is used to collect the network domain names accessed by the App, and match the network domain names accessed by the App with the whitelist database to obtain the domain name information of the network domain names accessed by the App.
[0058] The additional module is used to append the domain name information of the network domain name accessed by the App to the privacy report.
[0059] This invention focuses not only on technical reasoning capabilities but also on user-side interpretability, emphasizing the semantic friendliness and interface integration of the results. Outputting "App access to this permission / data is for..." in natural language is more easily accepted by users than traditional lengthy descriptions or tagged output. Furthermore, the purpose and domain name information corresponding to the call behavior are directly embedded in the app's privacy report interface, ensuring seamless integration with native privacy mechanisms.
[0060] The method and system for enhancing app privacy reporting for user comprehensibility according to the embodiments of the present invention have the following beneficial effects: (1) Enhance the understandability of the purpose of sensitive permission calls: Through runtime purpose inference, users can directly see the reasons or usage explanations behind each sensitive permission call in the privacy report. For example, the privacy report no longer simply displays "An app accessed location permissions 5 times today", but is accompanied by explanations such as "Used to provide nearby restaurant recommendations". This improvement makes up for the lack of purpose information in existing technologies, allowing users to have an intuitive understanding of why the App collects certain data.
[0061] (2) Clarifying the third-party entities involved in network requests: Domain name information including the name of the organization to which the domain name belongs, the type of domain name service, and the purpose of the domain name is added to the App privacy report, thereby enhancing the description of the domain name in the privacy report and providing users with friendly instructions, mapping the originally obscure domain name to a specific service or company name. Users can understand which third parties the App sends data to and the nature of these third parties' businesses (advertising, analysis, social networking, etc.). Important background information is added to the existing privacy report to help users identify potential data sharing behaviors.
[0062] (3) Improve the accuracy and compliance of user privacy decisions: The rich information provided by the embodiments of the present invention enables users to better understand the data behavior of the App, so that they can make more informed privacy decisions. For example, if it is found that the purpose of an App accessing data is unreasonable (such as a simple tool App frequently obtaining the address book for marketing), the user can adjust the permission authorization or uninstall the App accordingly. At the same time, the user-understandable App privacy report enhancement method and system of the present invention better meet the transparency requirements of privacy regulations (such as the notification of data usage purpose required by GDPR) and enhance the performance in privacy compliance. Overall, through the combination of the two major features of runtime purpose reasoning and network domain name description, users have unprecedented transparency, which will significantly improve their ability to manage their own privacy.
[0063] The above descriptions are merely several embodiments of the present invention and do not constitute any form of limitation to the present invention. Although the present invention is disclosed as above in terms of preferred embodiments, they are not intended to limit the present invention. Any technician familiar with the present profession, without departing from the scope of the technical solution of the present invention, who makes slight changes or modifications using the technical contents disclosed above, is equivalent to an equivalent implementation case and falls within the scope of the technical solution.
Claims
1. A method for enhancing user-understandable app privacy reports, characterized in that: include: Capture the app's call behavior for sensitive permissions and extract the function call stack information triggered by the call behavior in the current thread; Obtain the privacy policy and application description of the App, and determine the sensitive permission usage information of the App based on the privacy policy, where the sensitive permission usage information includes multiple triplets, each of which includes the user, permission type, and purpose of use; Inputting the function call stack information, the sensitive permission usage information, and the application description into a large language model to obtain the usage purpose corresponding to the calling behavior; The purpose of use corresponding to the calling behavior is expanded to the privacy report of the App.
2. The method for enhancing user-understandable app privacy reports according to claim 1, characterized in that: Before capturing the app's call behavior for sensitive permissions, it also includes: The application programming interface of the App is monitored using a dynamic instrumentation method.
3. The method for enhancing user-understandable app privacy reports according to claim 1, characterized in that: The reasoning method adopted by the large language model is the thought chain reasoning method.
4. The method for enhancing user-understandable app privacy reports according to claim 1, characterized in that: The sensitive permissions include at least one of location permissions, camera permissions, microphone permissions, contact permissions, photo library permissions, media library permissions, and screen recording permissions.
5. The method for enhancing user-understandable app privacy reports according to claim 1, characterized in that: After the usage purpose corresponding to the calling behavior is expanded to the privacy report of the App, it also includes: Acquire domain name information of multiple network domain names based on network intelligence resources, and build a whitelist database based on the domain name information; Collect the network domain names accessed by the App, and match the network domain names accessed by the App with the whitelist database to obtain domain name information of the network domain names accessed by the App; The domain name information of the network domain name accessed by the App is appended to the privacy report.
6. The method for enhancing user-understandable app privacy reports according to claim 5, characterized in that: After matching the network domain name accessed by the App with the whitelist database to obtain the domain name information of the network domain name accessed by the App, the method further includes: If the network domain name accessed by the App is not matched in the whitelist database, the network domain name accessed by the App is recorded in the candidate pool of the whitelist database.
7. The method for enhancing user-understandable app privacy reports according to claim 5, characterized in that: Collect the network domain names accessed by the App, specifically: The network domain names accessed by the App are collected from the privacy report of the App.
8. The method for enhancing user-understandable app privacy reports according to claim 5, characterized in that: Collect the network domain names accessed by the App, specifically: Monitor the application programming interface of the App to collect the network domain names accessed by the App.
9. The method for enhancing user-understandable app privacy reports according to claim 5, characterized in that: The domain name information includes the name of the organization to which the domain name belongs, the service type of the domain name, and the purpose of the domain name.
10. A user-friendly app privacy reporting enhancement system, characterized in that: The method for enhancing user-understandable app privacy reports according to any one of claims 1 to 9 comprises: A behavior capture module is used to capture the app's call behavior for sensitive permissions and extract the function call stack information triggered by the call behavior in the current thread; An information acquisition module, configured to obtain the privacy policy and application description of the App and determine sensitive permission usage information of the App based on the privacy policy, wherein the sensitive permission usage information includes multiple triples, each of which includes a user, a permission type, and a purpose of use; an enhancement module, the enhancement module being configured to input the function call stack information, the sensitive permission usage information, and the application description into a large language model to obtain a usage purpose corresponding to the calling behavior; An expansion module is used to expand the usage purpose corresponding to the calling behavior to the privacy report of the App.