AIセキュリティポータル K Program
Utilizing Large LanguageModels to Detect Privacy Leaks in Mini-App Code
Share
Abstract
Mini-applications, commonly referred to as mini-apps, are compact software programs embedded within larger applications or platforms, offering targeted functionality without the need for separate installations. Typically web-based or cloud-hosted, these mini-apps streamline user experiences by providing focused services accessible through web browsers or mobile apps. Their simplicity, speed, and integration capabilities make them valuable additions to messaging platforms, social media networks, e-commerce sites, and various digital environments. WeChat Mini Programs, a prominent feature of China's leading messaging app, exemplify this trend, offering users a seamless array of services without additional downloads. Leveraging WeChat's extensive user base and payment infrastructure, Mini Programs facilitate efficient transactions and bridge online and offline experiences, shaping China's digital landscape significantly. This paper investigates the potential of employing Large Language Models (LLMs) to detect privacy breaches within WeChat Mini Programs. Given the widespread use of Mini Programs and growing concerns about data privacy, this research seeks to determine if LLMs can effectively identify instances of privacy leakage within this ecosystem. Through meticulous analysis and experimentation, we aim to highlight the efficacy of LLMs in safeguarding user privacy and security within the WeChat Mini Program environment, thereby contributing to a more secure digital landscape.
Shared account problem in super apps
Y. Cai, Z. Zhang, D. Li, Y. Guo, X. Chen
Published: 2023
Uncovering and exploiting hidden apis in mobile super apps
W. Chao, Y. Zhang, Z. Lin
Published: 2023
The future landscape of large language models in medicine
J. Clusmann, F. R. Kolbinger, H. S. Muti, Z. I. Carrero, J.-N. Eckardt, N. G. Laleh, C. M. L. Löffler, S.-C. Schwarzkopf, M. Unger, G. P. Veldhuizen
Published: 2023
Large language models for software engineering: Survey and open problems
A. Fan, B. Gokkaya, M. Harman, M. Lyubarskiy, S. Sengupta, S. Yoo, J. M. Zhang
Published: 2023
A survey on large language models: Applications, challenges, limitations, and practical usage
M. U. Hadi, R. Qureshi, A. Shah, M. Irfan, A. Zafar, M. Shaikh, N. Akhtar, J. Wu, S. Mirjalili
Published: 2023
Demystifying resource management risks in emerging mobile app-in-app ecosystems
H. Lu, L. Xing, Y. Xiao, Y. Zhang, X. Liao, X. Wang, X. Wang
Published: 2020
Large language models in medicine
A. J. Thirunavukarasu, D. S. J. Ting, K. Elangovan, L. Gutierrez, T. F. Tan, D. S. W. Ting
Published: 2023
Taintmini: Detecting flow of sensitive data in mini-programs with static taint analysis
C. Wang, R. Ko, Y. Zhang, Y. Yang, Z. Lin
One size does not fit all: Uncovering and exploiting cross platform discrepant apis in wechat
C. Wang, Y. Zhang, Z. Lin
Published: 2023
Characterizing and detecting bugs in wechat mini-programs
T. Wang, Q. Xu, X. Chang, W. Dou, J. Zhu, J. Xie, Y. Deng, J. Yang, J. Yang, J. Wei
Published: 2022
Towards a better super-app architecture from a browser security perspective
Y. Wang, Y. Yao, S. Shi, W. Chen, L. Huang
Published: 2023
Cross miniapp request forgery: Root causes, attacks, and vulnerability detection
Y. Yang, Y. Zhang, Z. Lin
Published: 2022
Identity confusion in mobile app-in-app ecosystems
L. Zhang, Z. Zhang, A. Liu, Y. Cao, X. Zhang, Y. Chen, Y. Zhang, G. Yang, M. Yang
Published: 2022
Don’t leak your keys: Understanding, measuring, and exploiting the appsecret leaks in mini-programs
Y. Zhang, Y. Yang, Z. Lin
Published: 2023
Trusteddomain compromise attack in app-in-app ecosystems
Z. Zhang, Z. Zhang, K. Lian, G. Yang, L. Zhang, Y. Zhang, M. Yang
Published: 2023
knn-icl: Compositional task-oriented parsing generalization with nearest neighbor in-context learning
W. Zhao, Y. Liu, Y. Wan, Y. Wang, Q. Wu, Z. Deng, J. Du, S. Liu, Y. Xu, P. S. Yu
Published: 2023
Potential risks arising from the absence of signature verification in miniapp plugins
Y. Zhao, Y. Zhang, H. Wang
Published: 2023
Share