课题基金 / 基金详情

CAREER: A Holistic Developer-Centered Approach to Enhance Privacy for Data-Driven Applications

CAREER: A Holistic Developer-Centered Approach to Enhance Privacy for Data-Driven Applications
职业:以开发人员为中心的整体方法来增强数据驱动应用程序的隐私
批准号:
2238047
负责人:
Sepideh Ghanavati
金额:
$67.48万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2028-06-30

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
在美国,侵犯隐私的数量急剧增加,许多公司都遭受了损害和代价高昂的侵犯。这种违规行为会对用户产生负面影响,并给开发者带来财务和声誉成本。它们的负面影响强调了在整个软件开发生命周期中对整体隐私工程解决方案的需求。最近的隐私研究在这方面取得了进展,但仍然存在重大差距,包括实施指南不足和事先检测隐私侵犯。该项目通过调查新手和专家开发人员目前如何实现隐私规则,支持开发人员检测隐私行为,设计隐私保护解决方案,以及在代码中自动实现隐私规则来解决这些差距。该项目将产生模型和工具,以增强所有类型的软件应用程序的隐私。因此,该项目将通过以下方式造福社会:(i)帮助保护弱势群体的隐私,包括缅因州青年、移民和寻求庇护者;(ii)支持软件产业和美国经济;(iii)扩大女孩、妇女、少数民族、第一代学生和其他代表性不足的群体接受STEM和计算机科学教育和就业的机会。这个跨学科项目通过研究新的理论、方法和工具来描述开发前的软件隐私行为,然后确保它们在代码中有效实现,从根本上推进了隐私和软件工程方面的知识。通过三个重点,该项目将:(i)就开发人员的隐私意识和专业知识及其面临的挑战产生新的科学知识;(ii)通过开发与私隐有关的新型代码生成模型,减少在代码中手动实现私隐要求的工作量;(iii)通过审查当前编写隐私相关代码的做法,并创建新的解决方案来改进此类做法,最大限度地减少侵犯隐私的行为;(iv)通过开发从技术和政策角度定义和推理隐私解决方案的共享基础设施,加强法律和技术专家之间的沟通。该项目由软件和硬件基金会(SHF)计划、安全与可信网络空间(SaTC)和促进竞争研究的既定计划(EPSCoR)共同资助。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The number of privacy violations in the U.S. has increased dramatically, with many companies experiencing harmful and costly breaches. Such breaches negatively impact users and lead to financial and reputational costs for developers. Their adverse effects underscore the need for holistic privacy engineering solutions throughout the software development lifecycle. Recent privacy research has made progress in this regard, yet significant gaps remain, including insufficient implementation guidelines and ex-ante detection of privacy violations. This project addresses these gaps by investigating how novice and expert developers currently implement privacy rules, supporting the developers in detecting privacy behaviors, designing privacy-preserving solutions, and automating the implementation of privacy rules in code. This project will result in models and tools to enhance privacy for all types of software applications. Hence, the project will benefit society by (i) helping to protect the privacy of vulnerable groups, including Maine youth, migrants, and asylum seekers, (ii) supporting the software industry and the U.S. economy, and (iii) broadening access to STEM and computer science education and careers for girls, women, minorities, first-generation students, and other underrepresented groups. This interdisciplinary project fundamentally advances knowledge in privacy and software engineering by investigating new theories, methods, and tools to describe software privacy behaviors prior to development and then ensure their effective implementation in code. Through three thrusts, the project will: (i) generate new scientific knowledge about the privacy awareness and expertise of developers and the challenges they face; (ii) reduce the effort of manually implementing privacy requirements in code via the development of novel privacy-related code generation models; (iii) minimize privacy violations through examining the current practices for writing privacy-related code and creating novel solutions to improve such practices; and (iv) strengthen communications between legal and technical experts by developing a shared infrastructure for defining and reasoning about privacy solutions from both technical and policy perspectives.This project is jointly funded by the Software and Hardware Foundations (SHF) program, the Secure and Trustworthy Cyberspace (SaTC), and the the Established Program to Stimulate Competitive Research (EPSCoR).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金