课题基金 / 基金详情

CAREER: A Holistic Developer-Centered Approach to Enhance Privacy for Data-Driven Applications

CAREER: A Holistic Developer-Centered Approach to Enhance Privacy for Data-Driven Applications
职业:以开发人员为中心的整体方法来增强数据驱动应用程序的隐私
批准号:
2238047
负责人:
Sepideh Ghanavati
金额:
$67.48万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2028-06-30

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
在美国,侵犯隐私的数量急剧增加,许多公司都经历了有害且代价高昂的侵犯隐私的行为。此类违规行为对用户造成了负面影响,并给开发商带来了财务和声誉成本。它们的不利影响突显了在整个软件开发生命周期中需要全面的隐私工程解决方案。最近的隐私研究在这方面取得了进展,但仍然存在重大差距,包括实施准则不足和对侵犯隐私行为的事前检测。该项目通过调查新手和专家开发人员当前如何实施隐私规则、支持开发人员检测隐私行为、设计隐私保护解决方案以及自动执行代码中的隐私规则来解决这些差距。该项目将产生模型和工具,以增强所有类型的软件应用程序的隐私。因此,该项目将通过(I)帮助保护包括缅因州青年、移民和寻求庇护者在内的弱势群体的隐私,(Ii)支持软件业和美国经济,以及(Iii)扩大女孩、妇女、少数族裔、第一代学生和其他代表性不足群体获得STEM和计算机科学教育和职业的机会,从而使社会受益。这个跨学科的项目通过研究在开发之前描述软件隐私行为的新理论、方法和工具,并确保它们在代码中的有效实现,从根本上促进了隐私和软件工程方面的知识。通过三项努力,该项目将:(1)产生关于开发人员的隐私意识和专门知识及其面临的挑战的新的科学知识;(2)通过开发新的与隐私有关的代码生成模型,减少在代码中手动实施隐私要求的努力;(3)通过审查编写与隐私有关的代码的现行做法并创造新的解决办法来改进此类做法,尽量减少侵犯隐私的行为;以及(Iv)通过开发共享基础设施,从技术和政策角度定义和论证隐私解决方案,从而加强法律和技术专家之间的沟通。该项目由软件和硬件基础(SHF)计划、安全和值得信赖的网络空间(SATC)和既定的激励竞争研究计划(EPSCoR)联合资助。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The number of privacy violations in the U.S. has increased dramatically, with many companies experiencing harmful and costly breaches. Such breaches negatively impact users and lead to financial and reputational costs for developers. Their adverse effects underscore the need for holistic privacy engineering solutions throughout the software development lifecycle. Recent privacy research has made progress in this regard, yet significant gaps remain, including insufficient implementation guidelines and ex-ante detection of privacy violations. This project addresses these gaps by investigating how novice and expert developers currently implement privacy rules, supporting the developers in detecting privacy behaviors, designing privacy-preserving solutions, and automating the implementation of privacy rules in code. This project will result in models and tools to enhance privacy for all types of software applications. Hence, the project will benefit society by (i) helping to protect the privacy of vulnerable groups, including Maine youth, migrants, and asylum seekers, (ii) supporting the software industry and the U.S. economy, and (iii) broadening access to STEM and computer science education and careers for girls, women, minorities, first-generation students, and other underrepresented groups. This interdisciplinary project fundamentally advances knowledge in privacy and software engineering by investigating new theories, methods, and tools to describe software privacy behaviors prior to development and then ensure their effective implementation in code. Through three thrusts, the project will: (i) generate new scientific knowledge about the privacy awareness and expertise of developers and the challenges they face; (ii) reduce the effort of manually implementing privacy requirements in code via the development of novel privacy-related code generation models; (iii) minimize privacy violations through examining the current practices for writing privacy-related code and creating novel solutions to improve such practices; and (iv) strengthen communications between legal and technical experts by developing a shared infrastructure for defining and reasoning about privacy solutions from both technical and policy perspectives.This project is jointly funded by the Software and Hardware Foundations (SHF) program, the Secure and Trustworthy Cyberspace (SaTC), and the the Established Program to Stimulate Competitive Research (EPSCoR).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金