Ambiguity and generality in natural language privacy policies

MB Hosseini, J Heaps, R Slavin, J Niu… - 2021 IEEE 29th …, 2021 - ieeexplore.ieee.org
2021 IEEE 29th International Requirements Engineering Conference (RE), 2021ieeexplore.ieee.org
Privacy policies are legal documents containing application data practices. These
documents are well-established sources of requirements in software engineering. However,
privacy policies are written in natural language, thus subject to ambiguity and abstraction.
Eliciting requirements from privacy policies is a challenging task as these ambiguities can
result in more than one interpretation of a given information type (eg, ambiguous information
type" device information" in the statement" we collect your device information"). To address …
Privacy policies are legal documents containing application data practices. These documents are well-established sources of requirements in software engineering. However, privacy policies are written in natural language, thus subject to ambiguity and abstraction. Eliciting requirements from privacy policies is a challenging task as these ambiguities can result in more than one interpretation of a given information type (e.g., ambiguous information type "device information" in the statement "we collect your device information"). To address this challenge, we propose an automated approach to infer semantic relations among information types and construct an ontology to guide requirements authors in the selection of the most appropriate information type terms. Our solution utilizes word embeddings and Convolutional Neural Networks (CNN) to classify information type pairs as either hypernymy, synonymy, or unknown. We evaluate our model on a manually-built ontology, yielding predictions that identify hypernymy relations in information type pairs with 0.904 F-1 score, suggesting a large reduction in effort required for ontology construction.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果