Unveiling hidden permissions : an LLM framework for detecting privacy and security concerns in AI mobile apps reviews

Massenon, Rhodes, Gambo, Ishaya and Khan, Javed Ali (2026) Unveiling hidden permissions : an LLM framework for detecting privacy and security concerns in AI mobile apps reviews. Automated Software Engineering, 33 (2): 42. ISSN 0928-8910
Copy

Mobile AI applications enhance functionality but introduce complex privacy and security challenges. This research develops and evaluates an automated framework that leverages Large Language Models (LLMs) to analyze user reviews and unveil “hidden permissions” defined not as technically undeclared functionalities, but as declared permissions whose purpose or necessity is opaque to users, leading to perceived privacy risks. The framework integrates static analysis of permission manifests with a hybrid Natural Language Processing (NLP) pipeline that combines Term Frequency-Inverse Document Frequency (TF-IDF) with BERT embeddings. A fine-tuned RoBERTa model then classifies user-reported concerns into predefined risk categories. We correlate these user-reported behaviors with declared permissions to identify potential mismatches and prioritize them using a risk-scoring methodology validated against the MITRE Common Weakness Enumeration (CWE) database. In an evaluation against other LLM architectures (GPT-3.5, DistilBERT, XLNet, and LLaMA-2), our fine-tuned RoBERTa model demonstrates superior performance, achieving an F1-score of 0.90 in classifying reviews related to unauthorized tracking. The framework effectively surfaces and prioritizes user-perceived privacy risks, offering actionable insights for developers to address mismatches between an app’s declared permissions and its user-experienced behavior, thereby fostering a more secure and trustworthy AI mobile ecosystem.

mail Request Copy

picture_as_pdf
Unveiling_Hidden_Permissions_An_LLM_Framework_for_Detecting_Privacy_and_Security_Concerns_in_AI_App_Reviews-Revised.pdf
subject
Submitted Version
lock_clock
Restricted to Repository staff only until 9 January 2027

Request Copy

EndNote BibTeX Reference Manager Refer Atom Dublin Core OpenURL ContextObject HTML Citation MPEG-21 DIDL MODS RIOXX2 XML ASCII Citation OpenURL ContextObject in Span METS OPENAIRE Data Cite XML
Export

Downloads