The rise of Artificial Intelligence (AI) has impacted the development of mobile health (mHealth) apps, most notably with the advent of AI-based chatbots used as ubiquitous ``companions'' for various services, from fitness to mental health assistants. While these mHealth chatbots offer clear benefits, such as personalized health information and predictive diagnoses, they also raise significant concerns regarding security and privacy. This study empirically assesses 16 AI-based mHealth chatbots identified from the Google Play Store. The empirical assessment follows a three-phase approach (manual inspection, static code analysis, and dynamic analysis) to evaluate technical robustness and how design and implementation choices impact end users. Our findings revealed security vulnerabilities (e.g., enabling Remote WebView debugging), privacy issues, and non-compliance with Google Play policies (e.g., failure to provide publicly accessible privacy policies). Based on our findings, we offer several recommendations to enhance the security and privacy of mHealth chatbots. These recommendations focus on improving data handling processes, disclosure, and user security. Therefore, this work also seeks to support mHealth developers and security/privacy engineers in designing more transparent, privacy-friendly, and secure mHealth chatbots.
翻译:人工智能的兴起深刻影响了移动健康应用的发展,其中最显著的是基于人工智能的聊天机器人作为无处不在的“伴侣”应用于从健身到心理健康辅助等多种服务。尽管这些移动健康聊天机器人带来了个性化健康信息和预测性诊断等明显益处,但也引发了严重的安全与隐私担忧。本研究通过实证方法评估了从Google Play商店中识别出的16款基于人工智能的移动健康聊天机器人。实证评估采用三阶段方法(人工检查、静态代码分析和动态分析),以评估技术鲁棒性,以及设计与实现选择如何影响终端用户。我们的研究结果揭示了安全漏洞(例如启用远程WebView调试)、隐私问题以及违反Google Play政策的行为(例如未提供公开可访问的隐私政策)。基于这些发现,我们提出了若干建议以增强移动健康聊天机器人的安全与隐私保护。这些建议侧重于改进数据处理流程、信息披露和用户安全。因此,本研究也旨在支持移动健康开发人员及安全/隐私工程师设计更透明、隐私友好且安全的移动健康聊天机器人。