| 8 | 0 | 110 |
| 下载次数 | 被引频次 | 阅读次数 |
针对个人信息过度收集风险量化误差较大、告警等级划分精度低等问题,提出APP形式化程序个人信息过度收集风险告警算法研究。获取APP多源异构数据(静态数据、动态行为数据等),通过政策文本的形式化解析、权限信息类型映射与动态行为矢量化等环节将其转化为初始特征空间,提取APP形式化程序多维度特征,以此为基础,计算个人信息过度收集风险因子——个人信息敏感度、个人信息收集行为异常度与个人信息收集行为合规偏离度,通过广义线性模型与Sigmoid函数计算个人信息过度收集风险量化结果,依据个人信息过度收集风险量化结果分布情况,确定自适应阈值,制定个人信息过度收集风险分级告警机制,从而实现研究目标。实验结果显示:设计算法提取APP形式化程序多维度特征向量与实际特征向量的余弦相似度最大值达到了0.95,个人信息过度收集风险量化误差最小值达到了1%,个人信息过度收集风险告警等级划分结果与实验样本告警等级标注结果相同。
Abstract:To address the issues of large quantization errors in personal information over-collection risk and low precision in alarm level classification, this study proposes a formal program personal information over-collection risk alarm algorithm for APPs. Multi-source heterogeneous data of APPs(static data, dynamic behavior data, etc.) are obtained and transformed into an initial feature space through formal parsing of policy texts, permission-information type mapping, and dynamic behavior vectorization. Multi-dimensional features of APP formal programs are extracted, based on which the personal information over-collection risk factors are calculated-personal information sensitivity, personal information collection behavior abnormality, and personal information collection behavior compliance deviation. The personal information over-collection risk quantization result is calculated through a generalized linear model and Sigmoid function. According to the distribution of personal information overcollection risk quantization results, adaptive thresholds are determined and a graded alarm mechanism for personal information over-collection risk is established, thereby achieving the research objectives. Experimental results show that the maximum cosine similarity between the multi-dimensional feature vectors of APP formal programs extracted by the designed algorithm and the actual feature vectors reached 0.95, the minimum quantization error of personal information over-collection risk reached 1%, and the personal information over-collection risk alarm level classification results were identical to the annotated alarm level results of the experimental samples.
[1]孟醒,曾祥铭.数字经济视阈下App过度收集个人信息的治理对策——基于102份民事判决书的研究[J].重庆邮电大学学报(社会科学版), 2025, 37(1):68-79.MENG X, ZENG X M. Governance countermeasures for excessive collection of personal information by Apps from the perspective of digital economy:A study based on 102civil judgments[J]. Journal of Chongqing University of Posts and Telecommunications(Social Sciences Edition),2025, 37(1):68-79.(in Chinese)
[2]常宇豪.个人信息对公共安全的影响效应与风险应对[J].情报杂志, 2023, 42(5):184-191.CHANG Y H. The impact effect of personal information on public security and risk response[J]. Journal of Information, 2023, 42(5):184-191.(in Chinese)
[3]张丽,李秀峰.技术变革视域下个人信息保护政策的变迁审视——基于间断均衡理论的考察[J].云南行政学院学报,2023, 25(1):121-133.ZHANG L, LI X F. Examination of the changes in personal information protection policies from the perspective of technological transformation:Based on the study of discontinuous equilibrium theory[J]. Journal of Yunnan Administrative College, 2023, 25(1):121-133.(in Chinese)
[4]傅予,张卫,张溪.基于关联规则挖掘的移动应用程序个人信息过度收集治理研究[J].情报理论与实践, 2025, 48(2):56-65.FU Y, ZHANG W, ZHANG X. Research on governance of excessive collection of personal information by mobile applications based on association rule mining[J]. Information Theory and Practice, 2025, 48(2):56-65.(in Chinese)
[5]余立,张橦,黄萃.面向公共数据融合的个人信息风险演化与保护机制[J].现代情报, 2023, 43(2):158-167.YU L, ZHANG Z, HUANG C. Personal information risk evolution and protection mechanism for public data fusion[J].Modern Information, 2023, 43(2):158-167.(in Chinese)
[6]张德淼,李慧君.个人信息保护影响评估制度的优化路径——基于元治理理论视阈[J].中南民族大学学报(人文社会科学版), 2024, 44(5):147-155.ZHANG D M, LI H J. The optimization path of the personal information protection impact assessment system:Based on the perspective of meta-governance theory[J]. Journal of South-Central Minzu University(Humanities and Social Sciences Edition), 2024, 44(5):147-155.(in Chinese)
[7]孙茜,刘慧梁,王冀莲.卫星互联网信息安全风险分析与发展建议[J].中国电子科学研究院学报, 2023, 18(5):469-475.SUN X, LIU H L, WANG J L. Analysis of satellite internet information security risks and development suggestions[J]. Journal of the Chinese Academy of Electronic Sciences,2023, 18(5):469-475.(in Chinese)
[8]孙子文,周翔荣.基于攻击树的ICPS混合博弈风险评估[J].小型微型计算机系统, 2024, 45(8):2034-2040.SUN Z W, ZHOU X R. Risk assessment of ICPS hybrid game based on attack tree[J]. Small and Micro Computer Systems, 2024, 45(8):2034-2040.(in Chinese)
[9]熊强,练帅,李治文,等.双边道德风险下软件供应链信息安全责任协调契约设计[J].中国管理科学, 2024, 32(10):265-274.XIONG Q, LIAN S, LI Z W, et al. Design of information security responsibility coordination contracts in software supply chain under bilateral moral hazard[J]. Chinese Journal of Management Science, 2024, 32(10):265-274.(in Chinese)
[10]宣长春,陈素白.隐私侵犯经历对个人信息保护意愿的影响:基于“风险收益”和调节定向的理论视角[J].国际新闻界, 2023, 45(4):138-156.XUAN C C, CHEN S B. The impact of privacy infringement experiences on personal information protection intentions:From the theoretical perspectives of“risk-benefit”and regulatory direction[J]. International Journalism Review, 2023, 45(4):138-156.(in Chinese)
[11]赵强,李峰.物联网表箱智能网关的安全威胁与防护策略——评《智能电网信息安全风险与防范研究》[J].中国安全科学学报, 2025, 35(1):250-250.ZHAO Q, LI F. Security threats and protection strategies of the smart gateway for iot meter boxes—Review of“Research on Information Security Risks and Prevention in Smart Grid”[J]. Chinese Journal of Safety Science, 2025,35(1):250-250.(in Chinese)
[12]魏波,冯乃勤.基于入侵诱骗的网络拓扑污染攻击防御研究[J].计算机仿真, 2024, 41(5):410-414.WEI B, FENG N Q. Research on defense against network topology pollution attacks based on intrusion deception[J].Computer Simulation, 2024, 41(5):410-414.(in Chinese)
[13]苏和生.个人信息保护公益诉讼的程序构造——从损害救济模式向风险防控模式的转向[J].华中科技大学学报:社会科学版, 2023, 37(4):98-110.SU H S. The procedural construction of public interest litigation for personal information protection:A shift from damages relief model to risk prevention model[J]. Journal of Huazhong University of Science and Technology:Social Sciences Edition, 2023, 37(4):98-110.(in Chinese)
[14]和朝敦.基于数据融合的互联网网站群信息安全监测系统研究[J].电子设计工程, 2024, 32(14):159-164.HE C D. Research on internet website group information security monitoring system based on data fusion[J]. Electronic Design Engineering, 2024, 32(14):159-164.(in Chinese)
[15]黄锫.生成式AI对个人信息保护的挑战与风险规制[J].现代法学, 2024, 46(4):101-115.HUANG B. Challenges and risk regulation of generative AI on personal information protection[J]. Modern Law,2024, 46(4):101-115.(in Chinese)
基本信息:
DOI:10.27024/j.wlygc.2025.10.27.04
中图分类号:TP309
引用信息:
[1]宗锐,徐建.APP形式化程序个人信息过度收集风险告警算法[J].物理与工程().DOI:10.27024/j.wlygc.2025.10.27.04.
基金信息:
陕西省职业技术教育学会2025年度职业教育教学改革研究课题“《Java语言程序设计》课程思政案例库建设研究”(编号:2025SZX794); 陕西省教育厅2023年度自然科学一般专项科学研究计划项目“构建基于深度学习的舌体超声影像语言发音模型”(编号:23JK0329)
2026-07-24
2026-07-24
2026-07-24