用大模型检测手机应用安全风险,提升隐私保护效率
LLMs on support of privacy and security of mobile apps: state of the art and research directions
- 用大模型分析应用代码,识别常见安全漏洞
- 可有效检测用户分享图片时的数据泄露行为
- 适合研究移动安全与AI结合的学者参考
现代生活伴随着移动设备的爆发式增长。然而,除了为用户提供便利的功能外,安全和隐私风险仍威胁着移动应用用户。近年来威胁手段日益复杂,亟需更先进高效的检测方法。本文探讨大语言模型(LLMs)在识别和缓解移动应用生态中安全风险与隐私违规方面的应用。通过介绍将LLMs应用于解决智能手机平台前十大常见安全风险的最新研究,凸显其替代传统动态及混合分析方法的可行性和潜力。以大模型检测用户在线分享图像时敏感数据泄露为例,展示其实际应用效果。最后,讨论当前开放的研究挑战。
原文摘要 · Abstract (English)
Modern life has witnessed the explosion of mobile devices. However, besides the valuable features that bring convenience to end users, security and privacy risks still threaten users of mobile apps. The increasing sophistication of these threats in recent years has underscored the need for more advanced and efficient detection approaches. In this chapter, we explore the application of Large Language Models (LLMs) to identify security risks and privacy violations and mitigate them for the mobile application ecosystem. By introducing state-of-the-art research that applied LLMs to mitigate the top 10 common security risks of smartphone platforms, we highlight the feasibility and potential of LLMs to replace traditional analysis methods, such as dynamic and hybrid analysis of mobile apps. As a representative example of LLM-based solutions, we present an approach to detect sensitive data leakage when users share images online, a common behavior of smartphone users nowadays. Finally, we discuss open research challenges.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。