@inproceedings{6b53c955c8d843a28acaaa65ae82b958,
title = "RightsGen: Automated Generation of User Rights Declaration on Android via LLM-Guided UI Traversal",
abstract = "Ensuring compliance with privacy regulations, such as GDPR and CCPA, has become a critical challenge for mobile applications. These regulations mandate that apps provide accessible paths for users to exercise rights, such as account deletion and data export. However, these paths are often buried deep within complex UI hierarchies, making manual auditing unscalable. In this paper, we introduce RightsGen, a framework that leverages Large Language Models (LLMs) to automate the discovery and documentation of user rights declarations in Android applications. Unlike traditional random UI fuzzers, RightsGen utilizes the semantic reasoning capabilities of LLMs to navigate dynamic UI states. It employs a path-oriented mechanism and a GUI Agent acting as a rights tester guided by structured rights tuples. In our evaluation across 144 popular apps, RightsGen demonstrated high efficiency in dynamic testing, achieving a recall rate of 92.5\% in recognizing user rights paths and 87.3\% in extracting rights tuples. These results highlight the effectiveness of RightsGen in automating the generation of user rights declarations.",
keywords = "automated privacy compliance, large language models, mobile application, UI agent",
author = "Chengjun Li and Tao Liu and Yi Wu and Ming Fan",
note = "Publisher Copyright: {\textcopyright} 2026 Copyright held by the owner/author(s).; ACM International Conference on the Foundations of Software Engineering, FSE 2026 ; Conference date: 05-07-2026 Through 09-07-2026",
year = "2026",
month = jul,
day = "17",
doi = "10.1145/3803437.3805538",
language = "英语",
series = "FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering",
publisher = "Association for Computing Machinery, Inc",
pages = "1599--1604",
editor = "Tan, \{Shin Hwei\} and Foutse Khomh",
booktitle = "FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering",
}