课题基金 / 基金详情

SaTC: CORE: Medium: Collaborative: Contextual Integrity: From Theory to Practice

SaTC: CORE: Medium: Collaborative: Contextual Integrity: From Theory to Practice
SaTC:核心:媒介:协作:上下文完整性:从理论到实践
批准号:
1801316
负责人:
Norman Sadeh
金额:
$39.95万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-01 至 2023-08-31

项目摘要

项目成果

Norman Sadeh的其他基金

相似基金

相关文献

中文摘要
翻译
当前面向用户的计算机系统采用“通知和同意”的方法来管理用户隐私:向用户呈现隐私通知,然后必须同意其条款。几十年的先前研究表明,这种方法是无法管理的:政策含糊其辞、模棱两可,而且经常包含使其非常难以理解的法律术语,如果它们甚至被阅读的话。这些问题在物联网(IoT)设备上被放大,这些设备可能不包括显示隐私信息的显示器,并且可能在环境中变得如此普遍,以至于用户不可能确定他们的数据实际被捕获的时间。该项目旨在通过设计新的隐私管理系统来解决这些问题,该系统可以自动推断用户特定于上下文的隐私预期,然后使用它们来管理用户环境中移动设备和物联网设备的数据捕获和数据共享行为。这项研究的目标是更好地了解隐私期望,设计需要最少用户干预的隐私控制,并演示如何设计新兴技术来使用户能够最好地管理他们的隐私。“隐私作为上下文完整性”(CI)的理论假设隐私期望基于上下文规范,当数据以违反这些规范的方式流动时,就会发生侵犯隐私的行为。该框架可以通过根据数据类型、发送方、接收方以及特定的上下文(即共享数据的目的)对数据流进行建模来应用。虽然这个模型有直观的意义,但有几个公开的研究问题阻碍了它在计算机系统中的应用。具体地说,该项目通过使用调查、访谈和行为研究来调查隐私预期如何在不同的背景下变化,并设计系统自动推断背景信息,以便可以自动确定数据流是否可能违背用户预期的过程。研究人员开发了新型隐私控制的原型,并通过迭代的实验室和现场实验验证了它们的可用性和隐私保护特性。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Current user-facing computer systems apply a "notice and consent" approach to managing user privacy: the user is presented with a privacy notice and then must consent to its terms. Decades of prior research show that this approach is unmanageable: policies are vague, ambiguous, and often include legal terms that make them very difficult to understand, if they are even read at all. These problems are magnified across Internet of Things (IoT) devices, which may not include displays to present privacy information, and may become so ubiquitous in the environment that users cannot possibly determine when their data is actually being captured. This project aims to solve these problems by designing new privacy management systems that automatically infer users' context-specific privacy expectations and then use them to manage the data-capture and data-sharing behaviors of mobile and IoT devices in users' environments. The goals of this research are to better understand privacy expectations, design privacy controls that require minimal user intervention, and demonstrate how emergent technologies can be designed to empower users to best manage their privacy.The theory of "Privacy as Contextual Integrity" (CI) postulates that privacy expectations are based on contextual norms, and that privacy violations occur when data flows in ways that defy these norms. The framework can be applied by modeling data flows in terms of the data type, sender, recipient, as well as the specific context (i.e., the purpose for which data is being shared). While this model makes intuitive sense, there are several open research questions that have prevented it from being applied in computer systems. Specifically, the project investigates how privacy expectations change across varying contexts through the use of surveys, interviews, and behavioral studies, and designs systems to automatically infer contextual information so that the process of determining whether or not a data flow is likely to defy user expectations can be automated. The investigators develop a prototype of the novel privacy controls and validate their usability and privacy-preserving properties through iterative laboratory and field experiments.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2021
期刊: PoPETS
影响因子: --
作者: [Zhang, S., Feng, Y., Bauer, L, Cranor, L., Das, A., Sadeh, N.]
通讯作者: Sadeh, N.
Managing Intrusive Practices In The Browser: A User Centered Perspective
管理浏览器中的侵入性实践:以用户为中心的视角
DOI: --
发表时间: 2021
期刊: PoPETS
影响因子: --
作者: [Smullen, D., Yao, Y., Sadeh, N.]
通讯作者: Sadeh, N.
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
切换开关、美元符号和三角形:如何有效地传达隐私选择
DOI: --
发表时间: 2021
期刊: ACM Conference on Human Factors in Computing Systems
影响因子: --
作者: [Habib, H., Zou, Y., Yao, Y., Acquisti, A., Cranor, L., Reidenberg, J., Sadeh, N., Schaub, F.]
通讯作者: Schaub, F.
Facial Recognition: Understanding Concerns and Privacy Attitudes Across Increasingly Diverse Deployment Scenarios
面部识别:了解日益多样化的部署场景中的担忧和隐私态度
DOI: --
发表时间: 2021
期刊: USENIX Symposium on Usable Privacy and Security
影响因子: --
作者: [Zhang, S., Feng, Y., Sadeh, N.]
通讯作者: Sadeh, N.
SaTC: CORE: Medium: Collaborative: Automatically Answering People's Privacy Questions
  • 批准号:
    1914486
  • 项目类别:
    Standard Grant
  • 资助金额:
    $61.24万
  • 财政年份:
    2019
  • 负责人:
    Norman Sadeh
  • 依托单位:
SBE: Medium: Towards Personalized Privacy Assistants
  • 批准号:
    1513957
  • 项目类别:
    Standard Grant
  • 资助金额:
    $48.32万
  • 财政年份:
    2015
  • 负责人:
    Norman Sadeh
  • 依托单位:
TWC SBE: Option: Frontier: Collaborative: Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Prospective
  • 批准号:
    1330596
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $284.26万
  • 财政年份:
    2013
  • 负责人:
    Norman Sadeh
  • 依托单位:
TC: Medium: Collaborative Research: User-Controllable Policy Learning
  • 批准号:
    0905562
  • 项目类别:
    Standard Grant
  • 资助金额:
    $72.38万
  • 财政年份:
    2009
  • 负责人:
    Norman Sadeh
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: