arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

增强隐私,忽视伤害:真实世界数字隐私事件分析

Enhancing Privacy, Neglecting Harms: An Analysis of Real-World Digital Privacy Incidents

Shannon Veitch, C. Shem, Lena Csomor, Oleksandr Dudiy, Naone Kim, Khoi Le, Lina Saha, Alexander Viand, Anwar Hithnawi, Bailey Kacsmar

arXiv 2609.07217首次发表:更新:

发表机构

ETH Zurich; University of Waterloo; University of Alberta; Belfort Labs; University of Cambridge; University of Toronto(苏黎世联邦理工学院; 滑铁卢大学; 阿尔伯塔大学; 贝尔福特实验室; 剑桥大学; 多伦多大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过分析257起真实世界隐私事件,提出新的信息流模型,揭示隐私增强技术与实际伤害间的错位,发现同意机制不足、伤害源于多实体复杂交互,且最有能力预防伤害的实体最缺乏动机。

AI 中文摘要

隐私增强技术(PETs)已成为一种为个人提供对其信息更大控制权的技术手段。然而,尽管PETs的部署日益增多,人们仍在经历隐私伤害。在本研究中,我们重新审视对隐私事件的理解以及遭受隐私伤害者的现实情况,以评估PETs的目标和能力是否与人们面临的伤害错位。为了开展研究,我们收集了与257起真实世界隐私事件样本相对应的新闻文章。我们对这些文章进行内容分析,开发了一个新的信息流模型,该模型涵盖了数据流的复杂性及其与由此产生的伤害之间的关系。我们证明,该模型既捕捉了隐私事件及其缓解措施的既有方面,也捕捉了新颖方面。特别是,它解释了为何同意往往不足以防止隐私侵犯,伤害如何源于多个实体和行动之间的复杂交互,并揭示了我们对PETs理解中的一个缺陷:专注于启用功能仍然允许这些功能固有的伤害发生。此外,我们发现,在我们的样本中,最有能力实施伤害预防措施的实体恰恰是实施动机最弱的实体。总体而言,我们的模型和分析指出了隐私技术研究在伤害预防方面的局限性,并进一步确定了改变我们推进这些技术方式的路径。

英文摘要

Privacy-enhancing technologies (PETs) have emerged as a technical means for providing individuals with greater control over their information. Yet despite the growing deployment of PETs, people continue to experience privacy harms. In this work, we revisit our understanding of privacy incidents and the realities of those experiencing privacy harms, to assess whether the goals and abilities of PETs are misaligned with the harms people face. For our study, we collect news articles that correspond to a sample of 257 real-world privacy incidents. We employ content analysis over the articles to develop a new information flow model that encompasses the complexity of data flows and their relation to resulting harms. We demonstrate that our model captures both established and novel aspects of privacy incidents and their mitigations. In particular, it captures why consent is often insufficient to prevent privacy violations, how harms emerge from complex interactions among multiple entities and actions, and reveals a flaw in our understanding of PETs: a focus on enabling functionalities still permits the harms inherent in those functionalities. Moreover, we find that the entities best positioned to implement harm-preventing measures for the incidents in our sample are the least incentivized to do so. Overall, our model and analysis identify limitations of privacy technology research for harm prevention and further identifies paths for transforming how we approach the advancement of these technologies.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑