Score
Designs, builds, and evaluates mechanisms, systems, and analyses that prevent unauthorized disclosure or inference about individuals or sensitive attributes from collected information, including threat modeling, risk assessment, and measurement of privacy leakage. Implements and tests privacy controls and privacy‑enhancing technologies—such as access controls, anonymization, differential privacy, secure multi‑party computation, consent and audit mechanisms—and balances privacy guarantees against utility, performance, and compliance tradeoffs.
To address the challenges of sustaining long-term auditing of differential privacy (DP) mechanisms, low sampling efficiency of static auditing methods, and diminishing reliability of audits over time, this paper proposes the first sustainable monitoring framework specifically designed for DP. The framework dynamically accumulates audit evidence from historical audit logs and integrates statistical hypothesis testing with DP theory to establish a formally verifiable correctness guarantee over time. It employs adaptive sampling and online parameter updating to substantially reduce sampling overhead while preserving high-accuracy estimation of privacy parameters. Theoretical analysis establishes formal soundness and rigor. Extensive experiments across multiple canonical DP mechanisms demonstrate its effectiveness: compared to static auditing, it reduces sampling requirements by over 60%, achieves superior privacy budget consumption, and exhibits strong robustness and practicality.
Foundational models face an inherent tension among privacy preservation, verifiability, and auditability. Method: This paper proposes a trustworthy AI system architecture integrating cryptography and secure computation. It introduces, for the first time, a zero-knowledge proof–based mechanism for verifying AI behavioral assertions, synergistically combining secure multi-party computation (SMPC) and trusted execution environments (TEEs) to enable private yet auditable inference. Additionally, it designs an enhanced credential-based access control framework supporting decentralized identity and fine-grained policy enforcement. Contribution: The work establishes the first deployment framework for large language models (LLMs) and information retrieval systems that simultaneously guarantees confidentiality, verifiability, and traceability. It delivers a technically viable blueprint—grounded in cryptographic primitives and hardware-enforced security—that directly supports real-world AI governance practices and informs regulatory policy development.
Smart home systems suffer from inadequate protection of user and device identity data privacy, coupled with fragmented threat analysis and risk management practices. Method: This paper proposes the first privacy engineering framework that centrally incorporates device identity privacy. It integrates Data Flow Diagrams (DFDs) with LINDDUN PRO for end-to-end threat modeling, and combines Privacy Impact Assessments (PIAs) with Privacy-Enhancing Technologies (PETs) to systematically identify, quantitatively assess, and prioritize privacy risks. Contributions: (1) It establishes— for the first time—the critical role of device identity privacy within smart home privacy engineering; (2) it introduces an actionable risk prioritization matrix and standardized mitigation strategies; and (3) it delivers implementable privacy governance pathways for device manufacturers, cloud service providers, end users, and regulatory authorities.
Existing privacy research is fragmented across isolated technical domains (e.g., CV, NLP, networking), failing to address real-world, cross-contextual privacy concerns. Method: We propose a human-centered privacy modeling framework grounded in Contextual Integrity (CI) theory—first systematically integrating CI into large language models (LLMs). Our approach constructs the first multi-ontology privacy checklist incorporating social identities, sensitive attributes, and the full HIPAA regulatory framework. Leveraging expert-annotated, multi-source ontology fusion, it extends beyond traditional PII definitions to enable context-aware, human-interpretable privacy assessment. Contribution/Results: Experiments demonstrate LLMs’ efficacy in structured regulatory comprehension and context-sensitive privacy reasoning. Our framework establishes a novel paradigm for generalizable, cross-domain privacy risk identification—bridging theoretical privacy principles with scalable, deployable AI-driven assessment.
This work addresses the practical adoption barriers of Privacy-Enhancing Technologies (PETs), which stem from their technical complexity and the fragmentation among engineering, legal, and business perspectives. To bridge these disciplinary divides, the paper innovatively integrates multidisciplinary viewpoints into a systematic requirements engineering framework. By formally modeling and specifying the diverse needs of developers, integrators, and adopters, the proposed approach effectively aligns cross-domain concerns. The resulting requirements engineering–driven framework not only fills a critical gap in multidisciplinary collaboration for PET deployment but also substantially enhances the efficiency and regulatory compliance of integrating PETs into software systems.
This work addresses the challenge non-technical users face in understanding the trade-off between privacy loss parameters and the reliability of statistical inference in differential privacy. By reframing the privacy–utility trade-off within a hypothesis testing framework, the paper introduces the concept of “relative disclosure risk,” which directly links privacy loss parameters to the validity of statistical inference. Through theoretical analysis of how differentially private mechanisms affect the significance of hypothesis tests, the study quantifies the uncertainty introduced by randomization and its effectiveness in mitigating membership inference attacks. The resulting insights yield an actionable guideline for non-expert users to select appropriate privacy mechanisms, thereby promoting transparent deployment and principled configuration of differential privacy in practical applications.
Developers face significant practical challenges in implementing data privacy regulations (e.g., GDPR, CPRA) and lack adequate automated tooling to support compliance. Method: We conducted a mixed-methods study with 68 software developers—including structured surveys, in-depth interviews, and statistical modeling—to systematically identify their core requirements for privacy-compliance tools and the factors influencing those needs. Contribution/Results: We find that developers strongly prefer integrated, context-aware tooling; moreover, those with greater privacy experience place higher emphasis on tool reliability and legal alignment. Our analysis reveals a statistically significant positive association between developers’ privacy expertise and their demand for sophisticated, regulation-aware tool features. This study is the first empirical investigation centered explicitly on developers’ privacy-compliance enablement needs, thereby filling a critical gap in the literature. The findings provide foundational, evidence-based guidance for designing next-generation, generative-AI–powered privacy compliance automation tools.
This study addresses the lack of effective privacy protection mechanisms and contextual judgment support for users interacting with chatbots. To bridge this gap, the authors design and implement an interactive privacy support tool that integrates into a ChatGPT-like interface, featuring a privacy-aware panel capable of intercepting messages, detecting sensitive content, and offering anonymization options. Using a mixed-methods approach—including simulated tasks, think-aloud protocols, interaction log analysis, and post-task surveys—the research systematically examines users’ disclosure behaviors and decision-making processes in realistic scenarios. Findings indicate that the tool significantly enhances users’ privacy awareness, enabling them to accurately assess information sensitivity based on context and adopt appropriate protective measures, thereby strengthening their privacy agency in human–AI interactions.
To address privacy leakage risks arising from adversarial reverse inference of sensitive attributes in AI decision-making, this paper proposes the first abductive reasoning–based post-hoc privacy auditing framework. The framework employs formal logical modeling to generate minimal sufficient evidence identifying sensitive features upon which decisions critically depend, and introduces “Potentially Applicable Explanations” (PAEs)—an actionable, individual-centric privacy protection mechanism. It is the first work to systematically integrate abductive explanation into privacy assessment, unifying individual-level and system-level leakage analysis while jointly ensuring interpretability and privacy guarantees. Experiments on the German Credit dataset demonstrate that the framework precisely localizes privacy leakage pathways, quantifies the influence of sensitive features, and significantly enhances decision transparency and privacy controllability. This work establishes a novel paradigm for synergizing explainable AI with privacy-preserving design.