privacy risk quantification

Designs and implements metrics, measurement procedures, and assessment tools that quantify privacy risk by measuring information leakage and attack success (e.g., membership-inference-style metrics), computing privacy-amplification effects, and estimating threat likelihood and impact. Builds privacy threat models, conducts privacy audits and compliance checks, and develops engineering controls and risk assessments to compare and mitigate privacy risk across models, architectures, datasets, and data-processing pipelines.

privacyriskquantification

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.14
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$208K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Smart home systems suffer from inadequate protection of user and device identity data privacy, coupled with fragmented threat analysis and risk management practices. Method: This paper proposes the first privacy engineering framework that centrally incorporates device identity privacy. It integrates Data Flow Diagrams (DFDs) with LINDDUN PRO for end-to-end threat modeling, and combines Privacy Impact Assessments (PIAs) with Privacy-Enhancing Technologies (PETs) to systematically identify, quantitatively assess, and prioritize privacy risks. Contributions: (1) It establishes— for the first time—the critical role of device identity privacy within smart home privacy engineering; (2) it introduces an actionable risk prioritization matrix and standardized mitigation strategies; and (3) it delivers implementable privacy governance pathways for device manufacturers, cloud service providers, end users, and regulatory authorities.

Addressing privacy threats in smart home systems through comprehensive analysisFocusing on neglected device data and identity privacy protectionImplementing risk management via threat prioritization and mitigation techniques

To See or Not to See: A Privacy Threat Model for Digital Forensics in Crime Investigation

Mar 30, 2025
MR
Mario Raciti
🏛️ IMT School for Advanced Studies Lucca | Università di Catania | KU Leuven

Digital forensics is critical in criminal investigations, yet evidence acquisition, processing, and storage frequently entail significant privacy risks; existing research lacks systematic threat identification and modeling, leading to regulatory noncompliance and rights violations. This paper introduces the SPADA methodology—previously unapplied in digital forensics—to establish the first privacy threat model that rigorously integrates legal compliance and ethical requirements. Through legal compliance analysis, cross-jurisdictional comparative assessment, and structured threat elicitation, we identify 298 domain-specific threats alongside several cross-cutting, generic threats. The resulting model enables threat classification, provenance tracing, and automated compliance evaluation. It has been operationalized in forensic tool design and policy development, thereby bridging a critical gap between privacy protection theory and judicial practice.

Applies SPADA methodology for privacy-oriented threat modelingIdentifies privacy threats in digital forensics investigationsProposes model for ethical, legally compliant investigative practices

Real-world Security Operations Center (SOC) data is rarely accessible for research due to privacy constraints, leading existing studies to rely on synthetic or outdated datasets. This work proposes a high-fidelity anonymization method that extracts and structures SIEM logs from a financial-sector SOC, preserving temporal ordering and entity consistency while enforcing strict privacy guarantees—thereby establishing the first quantifiable privacy-utility trade-off boundary. Leveraging this approach, we construct 37 HIKARI evaluation challenges and develop a deterministic validator alongside a large language model (LLM) behavioral compliance detection mechanism. In experiments involving 200 SOCpilot incidents, our framework uncovered LLM non-compliant actions undetected by human baselines, enabling reproducible and verifiable evaluation of autonomous defense systems.

autonomous cyber defenseprivacy-preserving dataSecurity Operations Center

The Good, the Bad, and the (Un)Usable: A Rapid Literature Review on Privacy as Code

Dec 21, 2024
NE
Nicolás E. Díaz Ferreyra
🏛️ Hamburg University of Technology | RMIT University

This paper addresses the practical challenge of implementing privacy protection in software development—particularly in settings lacking cybersecurity training or sufficient privacy awareness—by systematically reviewing the state of “Privacy as Code” (PaC) research. Through a rapid literature review and thematic analysis, we identify two critical bottlenecks: (1) weak capabilities in automated source-code-level privacy property detection and privacy-preserving code generation; and (2) a widespread absence of rigorous performance evaluation and empirical validation of developer usability. We formally define the maturity bottleneck in PaC research and propose three evolutionary pathways: (i) conducting empirical studies in real-world development contexts; (ii) establishing standardized privacy benchmark datasets; and (iii) integrating generative AI techniques. Our findings yield three actionable research agendas, providing theoretical foundations and methodological guidance to advance PaC from conceptual frameworks toward scalable, engineering-ready practice.

Lack of tools for automatic privacy property detection in code.Limited research on generating privacy-friendly code automatically.Need for empirical studies and benchmarks in Privacy as Code.

Latest Papers

What's happening recently
View more

This work addresses the scarcity of production-grade Security Operations Center (SOC) logs for research due to stringent privacy constraints, which has led prior studies to rely on synthetic or outdated data. To bridge this gap, the authors propose a methodology that, for the first time, transforms real-world financial-sector SIEM logs into reusable research artifacts while adhering to strict privacy boundaries. The approach preserves investigation-relevant structures through structured anonymization, mapping to the MITRE ATT&CK framework, deterministic validation, and large language model (LLM)-based behavioral compliance checks. The resulting artifact comprises 37 HIKARI challenges suitable for effective model training and demonstrates its utility by accurately identifying LLM policy violations across 200 SOCpilot incidents, thereby validating its balanced trade-off between privacy preservation and analytical fidelity.

cybersecurity artifactsdata anonymizationprivacy-preserving

This study addresses the challenge of balancing data privacy and analytical utility in threat intelligence sharing by systematically introducing differential privacy into cybersecurity analysis. The work proposes injecting calibrated noise into SIEM system outputs to preserve the privacy of event logs while maintaining effective threat detection capabilities. It rigorously characterizes the pivotal role of the privacy budget ε in governing the trade-off between privacy guarantees and analytical utility. Through evaluation on real-world systems, the research demonstrates that the proposed approach enables meaningful collaborative threat analysis even under stringent privacy constraints, thereby establishing differential privacy as a foundational mechanism for privacy-preserving threat intelligence sharing.

Cybersecurity AnalyticsData UtilityDifferential Privacy

This study systematically evaluates whether off-the-shelf large language models (LLMs) can serve as viable alternatives to specialized tools for privacy policy analysis without fine-tuning or additional engineering. Using a newly curated dataset of ten privacy policies, the authors compare state-of-the-art LLMs—including GPT-5.2 and Gemini-2.5—against six representative privacy analysis tools across three core tasks (contradiction detection, compliance analysis, and summary aggregation) and three intermediate tasks. Results demonstrate that LLMs match or even surpass dedicated tools on most tasks, achieving precision and recall of 81.8%/70.9% for first-party entities and 91.4%/70.8% for third-party entities in entity recognition. This work provides the first empirical validation of the end-to-end feasibility of general-purpose LLMs in privacy policy analysis.

large language modelsprivacy policy analysisregulatory compliance

This study addresses a critical gap in existing privacy evaluation methods, which overlook the risk of excessive data collection by large language model (LLM) agents during the information acquisition phase. To tackle this issue, the authors introduce PrivacyPeek, a novel benchmark that systematically examines privacy leakage in this stage through 1,182 test cases spanning seven acquisition behaviors and sixteen domains. The framework incorporates a Probe Elicitation mechanism to quantify the risk of adversaries eliciting undisclosed sensitive information via adversarial probes. Through tool-call trajectory analysis, sensitive information detection, and multi-model comparative experiments, the study reveals that ten agents across four model families consistently exhibit over-collection behaviors, with task performance positively correlated with the degree of privacy leakage. Furthermore, current prompt-level defense strategies demonstrate limited efficacy against such risks.

data acquisitionLLM-based agentsprivacy benchmark

Hot Scholars

SZ

Shuning Zhang

Tsinghua University
HCIUsable Privacy and SecurityAI
TL

Tianshi Li

Assistant Professor, Northeastern University
Human-Computer InteractionPrivacyHuman-Centered AI Privacy
CM

Chien-Ming Huang

Johns Hopkins University
Human-Robot InteractionHuman-Computer InteractionSocial Robotics
GF

Giulia Fanti

Carnegie Mellon University, ECE Department
performance evaluation
SM

Stephen Meisenbacher

Research Associate and PhD Candidate, Technical University of Munich
Privacy-Preserving NLPPrivate NLPPrivacy-Enhancing TechnologiesData Privacy