论文标题

“我是私人的吗,如果是的话,多少?” - 使用风险通信格式使差异隐私易于理解

"Am I Private and If So, how Many?" -- Using Risk Communication Formats for Making Differential Privacy Understandable

论文作者

Franzen, Daniel, von Voigt, Saskia Nuñez, Sörries, Peter, Tschorsch, Florian, Müller-Birn, Claudia

论文摘要

移动性数据对于城市和社区确定需要改进的领域至关重要。移动提供商收集的数据已经包含所有必要的信息,但是个人的隐私需要保留。差异隐私(DP)定义了一种数学属性,该属性保证在共享此类数据时保留某些隐私限制,但其功能和隐私保护很难向Laypeople解释。在本文中,我们将风险通信格式与DP的隐私风险结合使用。结果是隐私通知,这些通知可以解释使用DP而不是DP功能时个人隐私的风险。我们在众包研究中评估了这些新颖的隐私通信格式。我们发现,在客观理解方面,他们的性能与目前使用的最佳性能DP通信相似,但并没有使我们的参与者对他们的理解充满信心。我们还发现了统计算术对某些隐私通信格式和当前使用的DP通信格式的有效性的统计算术的影响,类似于邓宁·克鲁格效应。这些结果会在多个方向上产生假设,例如,使用风险可视化来提高格式的可理解性或针对自适应用户界面,从而将风险通信定制为读者的特征。

Mobility data is essential for cities and communities to identify areas for necessary improvement. Data collected by mobility providers already contains all the information necessary, but privacy of the individuals needs to be preserved. Differential privacy (DP) defines a mathematical property which guarantees that certain limits of privacy are preserved while sharing such data, but its functionality and privacy protection are difficult to explain to laypeople. In this paper, we adapt risk communication formats in conjunction with a model for the privacy risks of DP. The result are privacy notifications which explain the risk to an individual's privacy when using DP, rather than DP's functionality. We evaluate these novel privacy communication formats in a crowdsourced study. We find that they perform similarly to the best performing DP communications used currently in terms of objective understanding, but did not make our participants as confident in their understanding. We also discovered an influence, similar to the Dunning-Kruger effect, of the statistical numeracy on the effectiveness of some of our privacy communication formats and the DP communication format used currently. These results generate hypotheses in multiple directions, for example, toward the use of risk visualization to improve the understandability of our formats or toward adaptive user interfaces which tailor the risk communication to the characteristics of the reader.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源