

An empirical study examining the relationship between mobile apps'permissions and ranking


移动应用权限的调用涉及用户个人信息,会影响用户对于隐私风险的判断,进而影响用户下载决策.本文基于隐私关注理论和隐私计算理论,提出移动应用设计中调用权限的合理度和敏感度会影响其市场绩效,而这一效应被移动应用的功能丰富性所调节.权限合理度以同类别应用的平均权限水平为依据,敏感度以调用危险权限的程度为度量标准.低于正常合理水平的移动应用可能存在功能缺陷,而高于正常敏感水平的应用则可能引发用户的隐私担忧,合理性和敏感度交互作用,最终影响用户的下载决策和应用市场绩效.为识别移动应用的权限合理性及敏感性,本研究利用移动应用权限说明文本构建了权限向量,再以类别平均水平和危险权限调用程度为分类依据将应用权限划分为四类,确定了移动应用的正常权限过度系数、正常权限不足系数、危险权限过度系数、危险权限不足系数.通过采集小米应用市场中移动应用的权限说明、市场表现等相关数据,构建了包含 33772 条记录的面板数据进行了实证检验.实证研究的结果显示:危险权限申请略低于类别平均水平能正向促进应用绩效,相反,权限申请量超出"最优权限"则会降低应用排名,尤其是危险权限.对于功能较为丰富的应用而言,权限属性对用户隐私风险感知的影响程度更高.本研究一方面拓展了移动应用隐私保护的相关理论,另一方面对于开发者开展移动应用权限设计有着重要的参考意义.

With the development of smart technology,mobile applications have become more universal and important in our daily life.Meanwhile,online privacy protection has attracted rich attention in both academia and practice.Mobile software functions require the authorization of user information.The misuse of private data poses a great threat to users'privacy safety.It is a difficult task for developers to mitigate users' concerns and sensitivity to various private data and improve their application performance based on access to the application permission. Based on the"minimum authority principle,"this paper explores the impact of permission sensitivity and rationality on software performance.The sample data includes 33,772 records of 5,304 software applications in the Xiaomi app store from January 2018 to December 2019.Firstly,according to whether sensitive information of users is involved,permissions are divided into dangerous and normal groups.Based on the permission lists,"0-1"vectors of various permissions are generated.Secondly,four different permission factors are calculated by the spatial distance algorithm to quantify rationality and sensitivity.Finally,this paper empirically explores the impact of permission factors on application ranking based on the panel data fixed effect regression model,which takes application ranking as the decision result of privacy response behavior.Based on the privacy concern theory,this paper links permission invocation with application performance,proving the negative impact of improper permission mechanisms on application performance. The first section introduces the generation method for the four permission factors.The sensitivity indicator refers to whether the permission requires access to users'private information or illegally shares or sends personal information to others.According to the classification system of the Android Developer Platform,we can quickly get the dummy variables for permission sensitivity.The reasonability indicator refers to whether the type and number of permissions requested by applications match their functional complexity and category average level.The average permission vector for every category is defined as an estimation of"the least privilege"that best matches the application function.Then,we use the distance from the"least privilege vector"to denote the irrationality degree.We can obtain four different permission factors by intersecting these two indicators.Mobile applications with too few normal permissions may have functional defects,while those with too many dangerous permissions may cause users' privacy concerns.The rationality and sensitivity of permissions jointly affect users' download decisions and application performance. The second part illustrates the influence mechanism of the four permission factors on application ranking.Dangerous and normal permissions have different impacts on mobile application rankings.Considering the particularity of ranking data,this study uses a rologit regression model combined with lag processing and fixed effect to eliminate the impact of other confounding variables.The results show that permission abuse will lower the ranking of applications in this category.The higher the abuse degree,the lower the ranking.With the same degree of rationality,highly sensitive permissions will increase users' concerns about privacy and security risks.The impact of insufficient permission application cannot be generalized.Insufficient dangerous permission has a positive impact on ranking;however,insufficient normal permission has no significant impact on app ranking. In the third part,the additional model discusses the regulatory effect of apps'functional descriptions on the influence mechanism.Software with rich functions usually needs to request more permissions.Users enjoy a high sense of self-anonymity in applications with simplified functions,which will reduce their privacy risk concerns.The consequences of security vulnerabilities will be more severe for complex software.Small changes in permissions may drastically affect the user's privacy risk estimation and the app ranking.In this case,labelling dangerous permissions lower than the average level and normal permissions higher than the average level both have a significant impact on the application ranking. In general,application permission data is closely related to its market performance.While designing software,developers should fully consider the user's privacy perception level and reduce the use of dangerous permission as much as possible.Without affecting the core functions of the application,a reasonable balance between normal permissions and dangerous permissions can effectively improve the application ranking and marketing performance.Analyzing the performance impact factors and permission evolution process is of great significance to improve app scores and word of mouth.


上海交通大学 安泰经济与管理学院,上海 200030南京大学 数据智能与交叉创新实验室、信息管理学院,江苏 南京 210093



Optimize permissionMobile appInformation privacyFixed effectRologit model

《管理工程学报》 2024 (003)

国家自然科学基金项目(72072087、71802017);国家哲学社会科学基金重大项目(20&ZD154) The Natural Science Foundation of China(72072087,71802017);The Key Project of Philosophy and Social Science Foundation of China(20&ZD154)

