coordinated disclosure

Planning and executing ethical disclosure processes and safeguards for sensitive or malicious findings, including low-impact measurement techniques and responsible notification to affected operators. This skill covers risk mitigation, disclosure timing, redaction/scoping decisions, and protocols for safe sharing of results.

coordinateddisclosure

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

NLP Security and Ethics, in the Wild

Apr 09, 2025
HL
Heather Lent
🏛️ Aalborg University | NVIDIA Corporation | IT University of Copenhagen

This paper addresses the critical gap in research ethics within Natural Language Processing Security (NLPSec). Analyzing 2018–2023 mainstream literature, we identify significant shortcomings in core ethical dimensions—particularly harm minimization and responsible disclosure—and a persistent disconnect from established cybersecurity ethics norms. To bridge this gap, we conduct the first cross-domain ethical framework mapping between NLPSec and cybersecurity, introducing the “White-Hat NLP” conceptual framework that aligns NLP-specific characteristics with cybersecurity’s ethical paradigms. Based on this mapping, we formulate actionable, deployment-oriented responsible research guidelines and release the first operational practice checklist explicitly integrating security and ethics governance. Our work delivers the NLPSec community its first systematic ethical assessment pathway and implementation roadmap, enabling the development of ethically conscious, practically enforceable research practices.

Addressing gaps in harm minimization and responsible disclosureAssessing NLP model vulnerabilities to malicious attacksExploring ethical norms in NLP and cybersecurity integration

This work addresses the current lack of a systematic framework for evaluating ethical risks in data collection practices for large language models (LLMs). It proposes the first quantifiable assessment framework that integrates multiple prominent ethical theories, structuring evaluation around core ethical principles through a set of targeted questions and establishing a scoring system to measure ethical risk. This approach enables systematic, quantitative ethical auditing of LLM data curation processes. By offering a practical tool for assessing ethical compliance in AI development, the framework fills a critical gap in existing research—particularly in the integration of diverse ethical theories and the empirical evaluation of real-world data practices—thereby advancing the responsible development of artificial intelligence.

AI ethicsdata harnessingethical assessment

Towards a Principled Framework for Disclosure Avoidance

Feb 10, 2025
MB
Michael B. Hawes
🏛️ U.S. Census Bureau | Iowa State University | University of Virginia

This paper addresses the core challenge faced by statistical agencies in selecting and designing disclosure avoidance systems (DAS): the difficulty of distinguishing between inherent system properties and implementation-specific choices. We propose the first principled evaluation framework that explicitly decouples “system essential attributes” from “implementation decisions.” Methodologically, the framework integrates risk assessment theory, statistical disclosure control (SDC) paradigm analysis, multi-dimensional constraint modeling, and iterative systems engineering—enabling dynamic trade-offs among privacy protection strength, data utility, and system adaptability under concurrent constraints of legal compliance, scientific validity, resource limitations, and stakeholder requirements. Our primary contribution is filling a critical gap in standardized DAS evaluation by delivering a practical, actionable framework. It supports evidence-based system selection and customized deployment, thereby enhancing the usability and operational agility of official statistics while ensuring regulatory compliance.

adapting to legal and scientific requirementsdistinguishing system features from implementationframework for disclosure avoidance

Ethical Risk Analysis of L2 Rollups

Dec 14, 2025
GI
Georgy Ishmaev
🏛️ Univ Rennes | Inria | CNRS | IRISA

While Layer 2 (L2) rollups improve scalability and reduce costs, operator discretion and information asymmetry introduce novel ethical risks. Method: This paper introduces the first systematic ethical risk analysis framework for L2 scaling, proposing a role-based decision-power–risk-exposure classification model. It integrates role modeling, cross-sectional analysis of 129 L2 projects, a manually curated dataset of on-chain events (2022–2025) covering sequencer liveness and transaction inclusion failures, and mechanism mapping. Contribution/Results: We establish an empirically testable ethical risk metric system, revealing critical concerns—including near-universal absence of withdrawal grace periods for urgent upgrades (86%), single-point proposer control over withdrawal freezing (50%), and ethical vulnerabilities in data availability and forced transaction inclusion. We further propose co-designed technical–governance mitigation strategies to enhance accountability, transparency, and user sovereignty.

Analyzes ethical risks in L2 rollups from operator discretion and governanceExamines how design choices affect user fund risks like upgrades and withdrawalsIdentifies widespread hazards in upgrade controls and proposer liveness mechanisms

This study addresses two core challenges in large-scale security vulnerability notifications: fragmented multi-stakeholder coordination and persistent conflation between vulnerability disclosure and notification practices. Through cross-case qualitative meta-analysis, operational log reconstruction, and comparative analysis of policy evolution, we systematically distinguish—along objective, procedural, and ethical dimensions—the fundamental nature of vulnerability disclosure (repair-oriented, collaboration-centric) versus vulnerability notification (reach-oriented, scalability-focused). Building on this distinction, we propose the first “end-to-end notification operations framework” tailored for large-scale stakeholder outreach, encompassing message initiation, multi-channel adaptation, and response assessment, accompanied by a dedicated ethical guideline. The framework has been formally integrated into a draft revision of the industry-wide Vulnerability Notification Operations Standard.

Addressing challenges in notifying multiple stakeholders about vulnerabilitiesCompiling best practices for effective vulnerability communication strategiesDistinguishing between vulnerability disclosure and notification practices

Latest Papers

What's happening recently
View more

This work addresses the critical security and ethical risks arising from enterprise employees inadvertently leaking sensitive data or generating policy-violating, unethical content when using large language models. To mitigate these risks, we propose SafeGPT—the first unified dual-sided protection framework that integrates input-side sensitive information detection and sanitization with output-side content moderation and rewriting. SafeGPT further incorporates a human-in-the-loop feedback mechanism to jointly optimize safety and user experience. By combining red-teaming attacks with reinforcement learning from human feedback, the system significantly reduces the likelihood of data leakage and biased outputs while maintaining high user satisfaction.

data leakageenterprise LLMsethics

This study addresses the systemic exploitation of African content moderators in Kenya and Nigeria, who endure precarious working conditions, lack basic labor protections, and are routinely excluded from employment contracts and data transparency. Innovatively repurposing the extraterritorial reach of the European Union’s General Data Protection Regulation (GDPR), the research employs data subject access requests (DSARs), legal compliance analysis, and cross-jurisdictional strategies to successfully obtain critical documents—such as employment contracts and non-disclosure agreements—held by outsourcing firms. This approach not only transcends conventional data rights frameworks but also exposes the structural mechanisms through which technology companies evade accountability via outsourcing, thereby furnishing legally actionable evidence of digital labor rights violations affecting workers in the Global South.

content moderationGlobal Southlabour exploitation

This work addresses the challenge of timely and accurate reporting of personal data breaches under the GDPR, which mandates notification within 72 hours—a process often hindered by the labor-intensive and error-prone manual translation of forensic evidence into structured compliance reports. To streamline this workflow, the authors propose a hybrid analysis method tailored for Linux/ARM-based data-exfiltrating malware, integrating static and dynamic analysis techniques. Crucially, they introduce a large language model (LLM) constrained by a formal JSON Schema to automatically map heterogeneous forensic artifacts onto regulatory reporting templates, such as Italy’s Garante notification form. This approach significantly reduces cognitive load on analysts while enhancing the completeness, regulatory compliance, and speed of incident response.

data breach reportingforensic artefactsGDPR compliance

This work addresses the risk that online platforms may strategically generate semantically equivalent content variants to manipulate compliance metrics, creating a “gaming” problem where apparent metric improvements mask unmitigated harms. The authors model moderation protocols as transformation graphs and introduce a semantic envelope metric, theoretically proving it to be the pointwise minimal solution within the class of conservative repairs. They further develop a hierarchical certification mechanism that guarantees effective constraint of true harm under any policy. Experimental evaluation—combining finite-state mixed-strategy enumeration, SMT solving (using Z3 and cvc5), and bounded single-player MDP verification in PRISM-games—demonstrates that conventional metrics often exhibit significant violations and gaming gaps, whereas the semantic envelope metric remains violation-free across all test instances, effectively resisting strategic manipulation.

audit certificationmetric manipulationonline safety regulation

This study addresses the lack of empirical evidence on key operational metrics—such as latency, cost, fairness, and adversarial robustness—for deploying large language models (LLMs) in trust and safety workflows like fraud detection and content moderation. Through a systematic literature review of 49 operationally relevant studies, the authors propose the FORTE role framework and a minimal deployment evidence checklist encompassing dimensions like latency budgets and per-decision costs to structurally evaluate LLM roles and evidence completeness in real-world settings. The analysis reveals a structural imbalance in existing work: while content moderation exhibits relatively comprehensive operational evidence, fraud detection suffers from severe gaps. The paper concludes by outlining critical directions for empirical research necessary to support reliable LLM deployment in high-stakes applications.

deploymentfraud detectionLLMs

Hot Scholars

LL

Luca Luceri

Research Assistant Professor @University of Southern California - Information Sciences Institute
Computational Social ScienceNetwork ScienceMachine LearningSocial Media Manipulation
EF

Emilio Ferrara

Professor of Computer Science at the University of Southern California
Human-Centered AISocial ComputingNetwork ScienceAI Safety
KK

Konrad Kollnig

Assist. Professor (PhD Oxford), Maastricht University
Regulatory TechnologiesPrivacyAI Law
GT

Gene Tsudik

Peter & Lois Griffin Professor, Jolly Good Fellow of This & That
securitycryptographycomputer securityprivacy
PP

Pooja Prajod

Centrum Wiskunde & Informatica (CWI), Amsterdam
Affective ComputingHuman-Robot InteractionHuman-Centered AIMachine Learning