User-controllable learning of security and privacy policies

User-controllable learning of security and privacy policies
复制标题

用户可控的安全和隐私策略学习

DOI:
--
复制
发表时间:
2008
期刊:
Security and Artificial Intelligence
影响因子:
--
通讯作者:
L. Cranor
L. Cranor
中科院分区:
--
文献类型:
--
作者:
Patrick Gage Kelley;P. Drielsma;N. Sadeh;L. Cranor

文献摘要

被引文献

相似文献

研究表明,用户很难在各种应用领域中指定其安全和隐私策略。虽然机器学习技术已经成功地用于改进用户偏好的模型,例如在推荐系统中,但它们通常被配置为控制整个策略并严格限制用户可以操纵它的方式的“黑匣子”。它涉及在系统和用户改进公共策略模型的上下文中对策略的增量操作。用户定期提供基于当前策略所做决策的反馈。该反馈用于识别(学习)增量策略改进,这些改进作为建议呈现给用户。反过来,用户可以查看这些建议,并决定接受哪些建议(如果有的话)。建议的增量性质增强了可用性,并且因为用户和系统操纵公共策略表示,所以用户保留控制并且仍然可以手动进行策略修改。使用这种方法的邻域搜索实现获得的结果是在从朋友查找器应用程序的部署中获得的数据的上下文中呈现的,在该应用程序中,用户可以与其他人共享他们的位置,但受他们随着时间的推移而细化的隐私政策的约束。我们目前的结果显示,政策的准确性,平均60%的初始定义后,我们的用户攀升高达90%,使用我们的技术。
Studies have shown that users have great difficulty specifying their security and privacy policies in a variety of application domains. While machine learning techniques have successfully been used to refine models of user preferences, such as in recommender systems, they are generally configured as "black boxes" that take control over the entire policy and severely restrict the ways in which the user can manipulate it. This article presents an alternative approach, referred to as user-controllable policy learning. It involves the incremental manipulation of policies in a context where system and user refine a common policy model. The user regularly provides feedback on decisions made based on the current policy. This feedback is used to identify (learn) incremental policy improvements which are presented as suggestions to the user. The user, in turn, can review these suggestions and decide which, if any, to accept. The incremental nature of the suggestions enhances usability, and because the user and the system manipulate a common policy representation, the user retains control and can still make policy modifications by hand. Results obtained using a neighborhood search implementation of this approach are presented in the context of data derived from the deployment of a friend finder application, where users can share their locations with others, subject to privacy policies they refine over time. We present results showing policy accuracy, which averages 60% upon initial definition by our users climbing as high as 90% using our technique.