"I need a better description": An Investigation Into User Expectations For Differential Privacy

"I need a better description": An Investigation Into User Expectations For Differential Privacy
复制标题

DOI:
10.1145/3460120.3485252
复制
发表时间:
2021-10
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Rachel Cummings;Gabriel Kaptchuk;Elissa M. Redmiles
Rachel Cummings;Gabriel Kaptchuk;Elissa M. Redmiles
中科院分区:
其他
文献类型:
--
作者:
Rachel Cummings;Gabriel Kaptchuk;Elissa M. Redmiles

文献摘要

被引文献

相似文献

尽管最近广泛部署的差异隐私,相对较少的是知道用户认为的差异隐私。在这项工作中,我们试图探索用户的隐私期望相关的差异隐私。具体来说,我们调查(1)用户是否关心差异隐私提供的保护,以及(2)他们是否因此更愿意与差异隐私系统共享他们的数据。此外,我们试图了解(3)用户的隐私期望的不同的私人系统,他们可能会遇到在实践中和(4)他们愿意在这样的系统中共享数据。为了回答这些问题,我们使用了一系列严格进行的调查(n=2424)。我们发现,用户关心的信息泄漏的种类,对差分隐私保护,更愿意分享他们的私人信息时,这些泄漏的风险不太可能发生。此外,我们发现,差异隐私描述的方式,在野外随意设置用户的隐私期望,这可能是误导性的部署。我们将我们的结果合成到一个框架中,以了解用户的意愿,分享信息与差分私人系统,它考虑到用户的先前隐私问题和如何描述差分隐私之间的相互作用。
Despite recent widespread deployment of differential privacy, relatively little is known about what users think of differential privacy. In this work, we seek to explore users' privacy expectations related to differential privacy. Specifically, we investigate (1) whether users care about the protections afforded by differential privacy, and (2) whether they are therefore more willing to share their data with differentially private systems. Further, we attempt to understand (3) users' privacy expectations of the differentially private systems they may encounter in practice and (4) their willingness to share data in such systems. To answer these questions, we use a series of rigorously conducted surveys (n=2424). We find that users care about the kinds of information leaks against which differential privacy protects and are more willing to share their private information when the risks of these leaks are less likely to happen. Additionally, we find that the ways in which differential privacy is described in-the-wild haphazardly set users' privacy expectations, which can be misleading depending on the deployment. We synthesize our results into a framework for understanding a user's willingness to share information with differentially private systems, which takes into account the interaction between the user's prior privacy concerns and how differential privacy is described.