Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Privacy policy" patented technology

A privacy policy is a statement or a legal document (in privacy law) that discloses some or all of the ways a party gathers, uses, discloses, and manages a customer or client's data. It fulfills a legal requirement to protect a customer or client's privacy. Personal information can be anything that can be used to identify an individual, not limited to the person's name, address, date of birth, marital status, contact information, ID issue, and expiry date, financial records, credit information, medical history, where one travels, and intentions to acquire goods and services. In the case of a business it is often a statement that declares a party's policy on how it collects, stores, and releases personal information it collects. It informs the client what specific information is collected, and whether it is kept confidential, shared with partners, or sold to other firms or enterprises. Privacy policies typically represent a broader, more generalized treatment, as opposed to data use statements, which tend to be more detailed and specific.

Large model-oriented split privacy protection training method

The invention discloses a large model-oriented split privacy protection training method, which comprises the following steps that: a pre-trained large model is divided into a client side model bottom layer and a top layer and a cloud server side model middle layer along a network depth direction, a client only processes local private data, and a terminal cloud performs cooperative training through middle activation. The method is oriented to privacy protection of a large model, a privacy strategy adaptive to characteristics of the large model, application of a cross-model architecture, realization of accurate privacy-utility balance, noise injection of token importance perception, lightweight noise post-calibration, provision of privacy guarantee of theoretical constraints, a token-level differential privacy mechanism and parameterized adjustable privacy constraints. According to the method, deployment feasibility and system efficiency are optimized, extra calculation and storage overhead is low, an efficient parameter fine tuning technology is compatible, the communication traffic and calculation requirements are greatly reduced while the privacy protection effect is guaranteed, and efficient and practical privacy fine tuning of a large-scale model under a split learning architecture is supported.
Owner:ZHEJIANG UNIV +1

Method and device for identifying sensitive fields in SQL (Structured Query Language) statement and electronic equipment

The invention relates to a method and a device for identifying sensitive fields in SQL (Structured Query Language) statements and electronic equipment. The method comprises the following steps: analyzing an SQL statement to extract all fields in the SQL statement; performing sensitive identification on each field of the SQL statement by utilizing a semantic analysis model and a preset rule base to obtain a corresponding first identification result and a second identification result; under the condition that the first recognition result or the second recognition result of the target field is the sensitive field, the target field is determined to be the sensitive field, and the target field is any field in the SQL statement; and according to the field type of the target field and the query scene, selecting one or more privacy policies from a preset privacy policy set to perform privacy processing on the target field. The technical problems that manual labeling is prone to omission, a desensitization strategy is fixed, and sensitive fields cannot be automatically recognized and dynamically protected according to scenes are solved.
Owner:JINZHUAN INFORMATION TECHNOLOGY CO LTD

Block chain consensus protocol privacy protection method based on equity proof

The invention relates to the technical field of network space security, in particular to a block chain consensus protocol privacy protection method based on a right proof. Through a node capability construction mechanism, hardware acceleration data cache data, environment electromagnetic data and load data are acquired, a comprehensive influence value is calculated through an exponential attenuation correction model and the like, a real-time capability level is analyzed and output, and then a complete set of lightweight multi-level privacy policies and other multi-level privacy policies are matched, so that low-end nodes are prevented from being overloaded due to insufficient computing power, and the security of the low-end nodes is improved. High-end nodes are enabled to exert the computing power advantage, and the adaptability of privacy protection and node computing power is improved; according to the method, through an adaptive scheduling mechanism, attack protection monitoring, intermediate sensitive data and key data monitoring, comprehensive risk value calculation, risk level determination, low-risk maintenance generation, intermediate-risk degradation generation and other adjustment schemes, privacy execution is dynamically optimized, and the overall efficiency is balanced while privacy security is guaranteed.
Owner:ZHEJIANG FORESTRY UNIVERSITY

Mobile application privacy policy compliance detection method based on pre-training model

The invention discloses a mobile application privacy policy compliance detection method based on a pre-training model, and aims to realize efficient and intelligent privacy policy compliance automatic detection. The method comprises the following steps: firstly, constructing a hierarchical privacy policy compliance detection index system according to domestic related laws and regulations and standards; secondly, collecting an original text of the privacy policy through a web crawler technology, and constructing an unlabeled corpus after cleaning and structured processing; thirdly, constructing a multi-label classification data set based on a mode of combining a large language model and manual review; mapping the text and the label to a unified semantic vector space by adopting a text-label joint embedding strategy, and inputting the text and the label into a multi-granularity classification model; according to the model, on the basis of an ERNIE pre-training model, context feature enhancement and deep semantic interaction are realized through a bidirectional long-short-term memory network, a self-attention mechanism and a text-label cross attention mechanism, so that the multi-label classification performance is remarkably improved; finally, according to a label prediction result output by the model and a preset index system, compliance judgment is automatically completed, and a structured detection report is generated. According to the invention, the automation degree and efficiency of privacy policy compliance detection are effectively improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Method and device for detecting privacy disclosure of applet, electronic equipment and storage medium

The invention discloses a privacy leakage detection method and device for an applet, electronic equipment and a storage medium, the method and device are applied to the electronic equipment and are used for carrying out privacy leakage detection on the applet, specifically, an API in the applet is recognized according to a developer document, the API involving user personal data reading serves as a taint source, and the taint source is used for detecting privacy leakage of the applet. An API related to user sensitive information transmission is used as a taint convergence position; performing static taint analysis on the program code of the to-be-analyzed applet to obtain a behavior set of the applet for processing the user sensitive information; constructing a cue word list of the applet based on the behavior set, wherein cue words comprise a data type and an operation type of data accessed by the applet; and based on a chain thinking prompt strategy and a multi-query mechanism, performing compliance judgment on the prompt words in the prompt word list by utilizing a large language model in combination with an applet privacy policy to obtain judgment results, and forming a detection report based on all the judgment results. Whether the privacy data use behavior of the applet is consistent with the privacy policy of the applet can be confirmed through the detection report, so that whether the applet has privacy leakage or not is confirmed.
Owner:广州市公安局网络安全保卫支队

System and method for ensuring data protection and regulatory compliance

PCT designated stageWO2026150334A1Internet privacyData field
A system and a method for data privacy compliance are disclosed The system is configured to receive, from a client device, information associated with a data fiduciary, the information comprising a digital offering provided by the data fiduciary, a plurality of labels corresponding to a plurality of data fields associated with the digital offering, at least one reference data privacy policy document associated with the data fiduciary, or any combination thereof. Further, system determines one or more labels of the plurality of labels used for collecting personally identifiable information (PII) based on at least one predefined criteria, and determines one or more purposes associated with the collection of the PII and a compliance of the one or more determined labels with the one or more determined purposes. Based on the determined compliance of the one or more labels, the system performs at least one action.

Blockchain-based surgical data privacy protection system

The application relates to the technical field of medical data privacy protection, and discloses a surgical operation data privacy protection system based on a block chain. After a surgical operation data classification module obtains surgical operation data, the data content is analyzed, and data partitions are divided based on data attributes; a privacy policy mapping module obtains the data partitions, associates privacy policies stored in a block chain, and establishes a mapping relationship between the data partitions and the privacy policies; a key combination module extracts key partitions based on the mapping relationship, combines encryption keys, and calculates key matching degrees; a policy updating module updates the privacy policies and adjusts the mapping relationship based on the key combination and access records; and an access management module processes access requests and generates an access control library based on the updated mapping relationship. Through the collaborative operation of the multiple modules, the adaptability and reliability of surgical operation data privacy protection are improved.
Owner:丰城市人民医院

Agricultural decision support system based on multi-source data

The invention relates to the technical field of soil management, and discloses a multi-source data-based agricultural decision support system, which comprises a dialogue module, a land parcel module and a my module, and is characterized in that the dialogue module comprises trial questions, historical dialogues and voice questions and answers; the land parcel module comprises land parcel management, periphery matching, report generation and data analysis; the my module comprises members, fruit values, reward fruit values, account setting, privacy policies, message notification and system setting. According to the agricultural decision support system based on the multi-source data, scientific and rigorous investment decisions can be made based on detailed historical climate records, geographical environment characteristics, altitude differences, soil types, market trends and other factors of selected land parcels; meanwhile, information such as historical climate, real-time weather forecast, disaster early warning and minute-level rainfall prediction within the range of 3-6 kilometers around a specific land parcel can be timely acquired, and agricultural producers can flexibly arrange agricultural activities conveniently.
Owner:GUANGXI JIEJIARUN TECH CO LTD

System

An object of a system according to an embodiment is to facilitate legal interpretation and data linkage and to utilize data in real time.SOLUTION: A system according to an embodiment includes a legal interpretation part, a data cooperation part, and a real time data utilization part. The legal interpreter gets a comprehensive agreement on the privacy policy. The data collaboration unit integrates the data into a common data infrastructure based on the consent obtained by the legal interpretation unit. The real-time data utilization unit utilizes the data integrated by the data linkage unit in real time.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Tour system graphical user interface for electronic device

1. Name of the product in this design: Graphical User Interface for a Travel System for Electronic Devices. 2. Intended use of this design: for use in electronic devices. 3. The key design feature of this product is its graphical user interface. 4. The image or photograph that best illustrates the design's key points: the front view. 5. The design for which protection is sought includes color. 6. Due to the lack of design considerations, the rear view, left view, right view, top view, and bottom view are omitted. 7. Purpose of the graphical user interface: This design allows users to access the itinerary interface of the tourism system through operations on the interface, enabling them to plan their travel itinerary. 8. Description of the changing states of the graphical user interface: The user interface of the product is the tourism system APP interface. After opening the APP and entering the main view interface, wait a few seconds and then enter the interface changing state diagram 1. Enter your mobile phone number and verification code, check "I have read and agree to the (Privacy Policy) and (User Agreement)" below, and click "OK" to enter the interface changing state diagram 2. Click "Itinerary" to enter the interface changing state diagram 3. The logical changes between the above multiple interfaces are in a single direction. To enter interface change state diagram 3, you must pass through interface change state diagram 2; to enter interface change state diagram 2, you must pass through interface change state diagram 1; and to enter interface change state diagram 1, you must pass through the main view interface.
Owner:DALIAN JIAOTONG UNIVERSITY

A large model-oriented split privacy protection training method

ActiveCN121561979BAlleviating the problem of insufficient applicabilitySemantic analysisDigital data protectionPrivacy protectionLearning architecture
The application discloses a large model-oriented split privacy protection training method, which comprises dividing a pre-training large model into a client-side model bottom layer and a top layer and a cloud server-side model middle layer in the network depth direction, wherein the client only processes local private data, and the end cloud cooperatively trains through intermediate activation steps, the application is oriented to large model privacy protection, adapts to the privacy policy of large model characteristics, is applicable to cross-model architecture, realizes accurate privacy-utility balance, token importance-aware noise injection, lightweight noise post-calibration, provides a theoretical constraint privacy guarantee, a token-level differential privacy mechanism, a parameterized adjustable privacy constraint, optimizes deployment feasibility and system efficiency, has low additional calculation and storage overhead, and is compatible with a parameter efficient fine-tuning technology, while guaranteeing the privacy protection effect, greatly reduces communication and calculation requirements, and supports efficient and practical privacy fine-tuning of a large-scale model under a split learning architecture.
Owner:ZHEJIANG UNIV +1

Intelligent dialogue control device and method for desktop pets based on AI key

The invention discloses an interaction device and method for realizing dialogue of desktop pets through an AI key. The device comprises an AI key event identification unit, a function state detection unit, a desktop state verification unit, a control traversal unit, an event transmission unit and a session processing unit. When it is detected that the physical AI key is pressed for a long time and the function is in an enabled state, the system judges whether a current foreground is a desktop main interface, whether a desktop mode is a default mode, whether a screen is bright and whether a desktop is static; only when all conditions are met, traversing the desktop view hierarchy to position a target control with a pet identifier, and converting an AI key event into a recording start and stop instruction of the control, so as to realize recording control and voice data acquisition. And after the recording is finished, the system generates a session identifier and selects a local or cloud path to start the voice conversation of the pets according to the privacy policy and the network state. The method has the advantages of mistaken touch prevention, privacy protection, quick response and the like, and the interaction experience of the mobile terminal is improved.
Owner:SHENZHEN KUSAI INTELLIGENT CO LTD

Loan product content presentation interactive graphical user interface for a mobile phone

1. The name of the design product: loan product content display interactive graphical user interface for mobile phones. 2. The use of the design product: a mobile phone. 3. The design points of the design product: in the graphical user interface. 4. The picture or photo that best indicates the design points: interface change state diagram 1. 5. The use of the graphical user interface: the interface is used for loan product content display. 6. The human-computer interaction mode of the graphical user interface: after filling in the "account" information and "password" information in the main view, check the "I have agreed to the XXX service agreement and privacy policy" option, and click the "login" control to enter the interface change state diagram 1. Click the "employee welfare area" control in the interface change state diagram 1 to enter the interface change state diagram 2. Click "Exclusive Benefits" in the interface change state diagram 2 to enter the interface change state diagram 3.
Owner:BANK OF COMM CO LTD HUBEI PROVINCIAL BRANCH

Methods and apparatuses for managing a subscription to at least a first application programming interface

Embodiments described herein relate to methods and apparatuses for managing subscription to at least a first API dealing with privacy sensitive data provided by the API service provider, the API service provider having access to a plurality of privacy policy templates, wherein each privacy policy template comprises one or more values for a plurality of parameters comprising: an application context parameter, a purpose parameter, a data scope parameter a legal basis parameter. A method performed by an API service provider may comprise: receiving a subscription request to subscribe an application to a first API provided by the API service provider, wherein the application is associated with at least one first application context at the API service provider; and obtaining one or more suitable privacy policy templates from the plurality of privacy policy templates, wherein the one or more suitable privacy policy templates each comprise values for the plurality of parameters that correspond to the at least one first application context, one or more first data scopes and one or more first purposes; and selecting a first privacy policy template from the one or more suitable privacy policy templates; creating a first privacy policy from the first privacy policy template for use with the application, wherein the first privacy policy is associated with a first legal basis.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Information processing device, generation method, and generation program

An information processing device (10) comprises a collection unit (15B) that collects answers to a questionnaire which is set on the basis of a combination of a first item relating to the information type of personal information targeted for a privacy policy and a second item relating to handling of the personal information, and a generation unit (15D) that generates a privacy policy corresponding to the answers to the questionnaire.
Owner:NT T INC

Personal information synonym library construction and information collection automatic understanding method in Chinese privacy policy

The invention provides a personal information synonym library construction and information collection automatic understanding method in a Chinese privacy policy, which comprises the following steps: defining the type of personal information needing to be analyzed, appointing an initial synonym, constructing and training a Chinese text word vector model, and obtaining a Chinese text word vector model; constructing a personal information synonym library based on the similarity between each human information phrase and the word vector of the initial synonym; performing word segmentation, part-of-speech tagging and dependency syntactic analysis on a Chinese privacy policy to be analyzed by using a natural language processing technology, performing simplification based on verbs indicating personal information collection and a tagging result in the previous step, and extracting phrases describing personal information collection; and for each type of personal information in the personal information synonym library, generating a regular expression capable of covering the synonym expression of the personal information, matching the extracted phrases, and mapping the extracted phrases into uniform personal information representation. The method is helpful for analyzing the illegal collection behavior of the personal information in the application.
Owner:XIDIAN UNIV

Method for automatic extraction and structure restoration of privacy policy for online service

The application discloses a privacy policy automatic extraction and structure restoration method for online services, and relates to the technical field of online service privacy policy analysis, and aims at providing a privacy policy automatic extraction and structure restoration method for online services. The method comprises the following steps: positioning a privacy policy link in an online service website and jumping to a corresponding privacy policy webpage; inserting a plug-in to crawl an original HTML (Hyper Text Markup Language) document of the privacy policy webpage; and finally restoring a hierarchical structure of the privacy policy through title identification and title level identification. The application realizes automatic analysis and reconstruction of the privacy policy in the online service, and provides support for online service privacy policy compliance analysis and completeness analysis.
Owner:SHANGHAI JIAOTONG UNIV

GDPR-oriented privacy policy compliance detection method

A GDPR-oriented privacy policy compliance detection method, the requirements for privacy policy in GDPR are abstracted to form a three-level structure of GDPR knowledge graph, and the collected hierarchical privacy policy is labeled through the knowledge graph to form a GDPR-oriented privacy policy corpus; again through the GDPR-oriented privacy policy compliance detection model, whether the text in the privacy policy belongs to a certain clause in GDPR can be predicted. The present application realizes intelligent analysis and compliance detection of privacy policy covering GDPR comprehensively, and provides GDPR-oriented privacy policy compliance suggestion and detection support for online services, app and other internet services.
Owner:SHANGHAI JIAOTONG UNIV

A system for applet privacy policy and permission call consistency analysis

The application provides a system for analyzing the consistency between the privacy policy and the permission call of an applet, comprising: a privacy policy extraction module for extracting the privacy policy of the privacy page in the applet to be analyzed; a privacy policy automatic analysis module for identifying the privacy policy and extracting the sensitive permission to form a first sensitive permission call set; a program analysis module for constructing a guide page transition graph and a dynamic page transition graph, and combining the two to obtain an overall page transition graph; determining a second sensitive permission call set from the overall transition graph by simulating the call process of a specified page; and a consistency analysis module for performing consistency analysis on the first sensitive permission call set and the second sensitive permission call set to determine whether the applet to be analyzed has risks. The privacy policy analysis of the application is more comprehensive, the entity recognition model is more accurate, and the program analysis depth is combined, so that the permission call detection is more comprehensive and accurate.
Owner:XIDIAN UNIV

A Chinese privacy policy automatic labeling and abstract extraction method and device

The application discloses a kind of Chinese privacy policy automatic marking and abstract extraction method and device, including the division of privacy policy text into clause sentence, after the marking of each clause sentence is carried out category label, important clause label and potential risk clause label according to privacy policy marking criterion, carry out data enhancement and word segmentation processing to build training sample;Supervised learning training is carried out to category identification model, key sentence identification model and risk identification model respectively using training sample and corresponding label;After the privacy policy text to be marked is processed into test sample, at least one model in the three models trained is used to predict the label of test sample, and each clause sentence in privacy policy text is marked according to label prediction result;According to the label marking result, the clause sentence group meeting the demand is extracted from the privacy policy text to form abstract text.The method and device are high in marking quality, strong in universality and easy to use.
Owner:ZJU HANGZHOU GLOBAL SCI & TECH INNOVATION CENT

Data anonymization for service subscriber's privacy

PendingUS20260187284A1Third partyInternet privacy
An IoT / M2M service layer may be provided with the capability to protect user privacy. This functionality may allow the IoT / M2M service layer to anonymize user data, particularly when user data is shared with third party consumers. A privacy policy service may enable the IoT service layer system to generate anonymization (e.g., privacy) policies based on inputs such as legal obligations, subscriber privacy preferences, and an authorization level of the data consumer. Data anonymization policies may be output from the privacy policy service and may be sent to a data anonymization service, where raw data may be anonymized based on the one or more data anonymization policies. The output from the data anonymization service function may be a privatized (e.g., anonymized) version of data that may prevent the data consumer from discovering one or more identifying characteristics of a user.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Privacy protection in wireless communication network

Aspects of the present disclosure relate to a network function (NF) in a wireless communication network, the NF comprising: at least one memory; and at least one processor coupled to the at least one memory and configured to cause the NF to: retrieve input data, the input data including privacy sensitive data; identifying corresponding privacy adaptation data for the privacy sensitive data based on the privacy policy; processing the input data to replace or mask the privacy sensitive data with corresponding privacy adaptation data to produce privacy protected input data; and transmitting the privacy preserving input data to the second NF.
Owner:LENOVO (SINGAPORE) PTE LTD

A privacy policy compliance processing method and device, electronic equipment, storage medium and program product

The application discloses a privacy policy compliance processing method and device, electronic equipment, storage medium and program product. The method comprises the following steps: constructing a multi-dimensional constraint mode in advance based on laws and regulations and industry standards; in response to receiving a to-be-detected privacy policy text, structured semantic information is extracted from the text by using a large language model and according to the multi-dimensional constraint mode; at least one consistency detection is performed based on the structured semantic information, the consistency detection comprising semantic similarity detection for determining whether the minimum necessary principle is met and cross-chapter logic conflict detection for identifying semantic contradictions; and for the identified non-compliant items, a large language model is driven to generate a repair text in combination with context content and corresponding compliance judgment conditions. The application realizes full-process automation of privacy policy text from detection to repair by converting abstract legal requirements into computable constraints and combining the deep semantic understanding ability of the large language model, thereby improving the efficiency and accuracy of compliance management.
Owner:BEIJING BAIGEFEICHI TECH LLC

Data anonymization for service subscriber's privacy

An IoT / M2M service layer may be provided with the capability to protect user privacy. This functionality may allow the IoT / M2M service layer to anonymize user data, particularly when user data is shared with third party consumers. A privacy policy service may enable the IoT service layer system to generate anonymization (e.g., privacy) policies based on inputs such as legal obligations, subscriber privacy preferences, and an authorization level of the data consumer. Data anonymization policies may be output from the privacy policy service and may be sent to a data anonymization service, where raw data may be anonymized based on the one or more data anonymization policies. The output from the data anonymization service function may be a privatized (e.g., anonymized) version of data that may prevent the data consumer from discovering one or more identifying characteristics of a user.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Vehicle privacy authorization method and device, electronic equipment and medium

The invention discloses a privacy authorization method and device for a vehicle, electronic equipment and a medium, and relates to the technical field of vehicles. The method comprises the following steps: acquiring a system version and a current privacy policy version of a target vehicle; determining a target privacy policy version according to the system version; when it is determined that the current privacy policy version is not matched with the target privacy policy version, sending a target privacy policy to the target vehicle; the authorization instruction is responded, the processing authority of the vehicle function of the target vehicle is determined according to the authorization instruction, and the vehicle function is related to the user information of the target vehicle. According to the authorization method, the privacy policy version of the target vehicle is determined according to the system version of the target vehicle, the requirement of the intelligent network connection vehicle for vehicle data processing can be effectively met, the privacy policy can be updated from the vehicle privacy data management platform in time, and the privacy policy version is bound with the system version of the vehicle, so that the privacy policy management efficiency is improved. The problem of consistency of functions and privacy policies is solved.
Owner:BEIJING AUTOMOBILE RES GENERAL INST

Data privacy compliance for secondary data storage systems

Systems and methods are described relating to enforcing privacy constraints when data is transferred between data systems. In some examples, a request to transfer a dataset from a primary data system to a secondary data system may be obtained. A set of privacy policies May be enforced on the dataset to generate a modified dataset by performing one or more of: modifying values of quasi-identifiers (values that do not individually, uniquely identify a user) identified in the dataset such that the dataset satisfies one or more of an anonymity or a diversity test; or introducing inert data into the dataset to meet a differential privacy criteria, where the amount of inert data is generated based at least in part on the one or more quasi-identifiers in the dataset. The service may then cause the modified dataset to be accessible by the secondary data system.
Owner:AMAZON TECH INC

System and method for privately hosting machine learning models and collaborative computations

Systems and methods are disclosed for offering a secure model as a service. A system can be configured to implement, via a trusted execution environment comprising an enclave virtual machine and a customer key host, a distributed privacy policy in which a master decryption key is split-shared between the trusted execution environment the customer key host; perform a decryption of the master decryption key according to the distributed privacy policy to obtain a decrypted master key; and, based on the decrypted master key, perform, in the trusted execution environment, a private collaborative computation using one or more of customer data and a customer model. Secure multiparty computation can be used to perform the decryption of the master decryption key.
Owner:AGENTIC HEALTHCARE INC

Information processing device, information processing system, information processing method, and program

We provide information processing equipment that can achieve both high levels of user privacy protection and a balance between the convenience and security of the service. [Solution] The system comprises an audio input unit that acquires ambient sound, a processor that analyzes and deletes the audio data acquired by the audio input unit and generates deletion certification information, and a communication unit that transmits the deletion certification information generated by the processor to an external source. Preferably, the audio data is analyzed based on a predetermined privacy policy. The policy is generated by AI based on the user's abstract intentions, and the deletion certification information includes an identifier of the policy used for analysis, thereby achieving both privacy protection and transparency of processing.
Owner:MIXI INC

Mobile application malicious behavior detection method and system based on scene context driving

The invention relates to the field of mobile application security, and discloses a scene context driven mobile application malicious behavior detection method and system, and the method comprises the following steps: collecting multi-source information during application operation, and carrying out scene recognition; capturing sensitive behaviors in real time and performing standardized cleaning treatment; semantic information of the manifest permission declaration and the privacy policy text is extracted, a declaration triple is constructed, and declaration consistency judgment is carried out; constructing an application behavior graph, and calculating a plurality of risk indexes of nodes in the graph to obtain malicious scores; according to the method, a running scene is used as a core analysis dimension, a dynamic behavior sequence, a sensitive API call chain, application declaration semantics and a cross-source consistency comparison mechanism are combined, and the dynamic behavior sequence, the sensitive API call chain, the dynamic behavior sequence, the sensitive API call chain, the dynamic behavior sequence and the cross-source consistency comparison mechanism are combined, so that the dynamic behavior sequence and the sensitive API call chain are combined, and the high-risk nodes and the high-risk paths with malicious scores exceeding a threshold value are screened. And accurate identification of malicious operation of the mobile application is realized.
Owner:ZHEJIANG GONGSHANG UNIVERSITY