Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks
Best PaperAuthors
Title of the Paper
Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks
Paper Information
- Subject Area: Artificial Intelligence (AI), Privacy Risks, Privacy-Preserving Technologies
- Keywords: AI Privacy Risks, Deepfakes, Phrenology, Surveillance, Data Privacy, Privacy Taxonomy, Security, AI Ethics, User Privacy, Data Breaches
Research Background and Issues
-
Problems and Challenges:
- Traditional privacy concepts fail to comprehensively address the new privacy risks introduced by AI technologies.
- The unique capabilities of AI (e.g., media generation, user interest detection, anomaly detection) and its data requirements significantly alter or exacerbate privacy threats.
- AI technologies have driven the emergence of new privacy risks, such as deepfake pornography, identity verification, and privacy intrusions, which are inadequately addressed by existing privacy-preserving methods (e.g., differential privacy, federated learning).
-
Significance:
- The widespread application of AI technologies significantly impacts personal privacy. Approximately half of the public believes AI will lead to reduced privacy in the future, including concerns about expanded data collection, lack of user consent mechanisms, and continuous surveillance.
- Developing ethical AI products requires a systematic understanding of the formation and evolution of these privacy risks.
-
Research Motivation and Related Work:
- Using Solove's 2006 privacy taxonomy as a baseline, this study analyzes how modern AI technologies transform privacy risks through real-world cases.
- The research evaluates the specific impacts of AI on privacy threats using documented cases from the AI Incident Database (e.g., Clearview AI and deepfake cases).
Solutions
-
Methodology and Taxonomy Framework:
- Building a Privacy Risk Taxonomy: By analyzing 321 AI privacy-related cases recorded in the "AI, Algorithm, and Automation Incidents and Controversies" (AIAAIC) database, the study constructs a taxonomy encompassing 12 high-level privacy risks.
- Innovations:
- Extending Solove's traditional privacy taxonomy to include AI-specific risks, such as "phrenology/physiognomy."
- Providing detailed classifications for new risks created by AI and the exacerbation of known risks.
- Implementation Steps:
- Collect and filter 321 recent AI privacy incident cases.
- Categorize cases into three groups: creating new risks, exacerbating known risks, and not significantly altering risks.
- Based on case analysis, develop a privacy risk taxonomy comprising four subfields: data collection, processing, dissemination, and intrusion.
-
Taxonomy Results:
- Data Collection Risks: Surveillance.
- Data Processing Risks: Identification, data aggregation, phrenology, secondary use, non-disclosure/exclusion, insecurity.
- Data Dissemination Risks: Information exposure, distortion, disclosure, increased accessibility.
- Intrusion Risks: Spatial disruption.
Research Outcomes
-
Specific Findings:
- Developed a taxonomy structure encompassing 12 types of AI privacy risks.
- Identified new risks created by AI, such as the information exposure risks of "deepfake pornography" and the "phrenology risks" of inferring sexual orientation based on appearance.
- Highlighted exacerbated risks due to AI's data demands, including surveillance risks, secondary use risks, and security issues.
-
Comparison with Existing Methods:
- Existing privacy-preserving solutions (e.g., differential privacy, federated learning) fail to address new risks created by AI (e.g., phrenology and information distortion).
- AI ethics tools (e.g., ethical checklists) have limited capabilities in identifying and mitigating these new risks.
-
Experimental and Evaluation Results:
- Approximately 93% of cases demonstrate that AI significantly alters or exacerbates privacy risks.
- Experiments confirm the high consistency of the risk taxonomy (average Cohen's Kappa of 0.94).
-
Limitations and Future Directions:
- Limitations:
- The dataset may have sampling biases, potentially missing some risk types.
- The analysis focuses on documented cases, possibly overlooking emerging or anticipated future risks.
- Definitions and perceptions of privacy may vary across cultural and technological contexts.
- Future Directions:
- Develop a dynamic and scalable taxonomy system to continuously track and update new risks introduced by AI.
- Establish related incident databases and tools to help practitioners identify AI privacy risks.
- Design AI privacy guidelines targeting specific risks to enhance privacy protection during product development.
- Limitations:
Ultimately, this study reveals the extensive and profound impact of AI technologies on privacy risks and lays the foundation for developing AI privacy-preserving technologies.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How does AI technology change or exacerbate privacy risks?Category: Surveillance and Sensing PrivacySimilar questionsarrow_forward
- Can a systematic classification framework based on case analysis identify AI-specific privacy risks?Category: Surveillance and Sensing PrivacySimilar questionsarrow_forward
- Can existing privacy protection methods effectively address new privacy risks posed by AI?Category: Surveillance and Sensing PrivacySimilar questionsarrow_forward
Practical Problems
1- Users worry that AI technology expands data collection and surveillance, infringing on privacy.Category: Surveillance and Sensing PrivacySimilar questionsarrow_forward
- 71%
Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
CHI '24· AI Ethics, Fairness & Accountability +2
- 71%
When Feasibility of Fairness Audits Relies on Willingness to Share Data: Examining User Acceptance of Multi-Party Computation Protocols for Fairness Monitoring
CHI '26· AI Ethics, Fairness & Accountability +2
- 71%
Do Citizens Agree with the EU AI Act? Public Perspectives on Risk and Regulation of AI Systems
CHI '26· AI Ethics, Fairness & Accountability +2
- 67%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 67%
Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?
CHI '25· Privacy by Design & User Control +1
- 67%
A Visual Exploration of Cybersecurity Concepts
C&C '22· Privacy by Design & User Control +1
- 63%
What is Sensitive About (Sensitive) Data? Characterizing Sensitivity and Intimacy of Google Assistant Speech Records
CHI '23· Explainable AI (XAI) +3
- 63%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 63%
CLEAR: Towards Contextual LLM-Empowered Privacy Policy Analysis and Risk Generation for Large Language Model Applications
IUI '25· Generative AI (Text, Image, Music, Video) +3
Based on Jaccard similarity of research subtopics & professions (≥60%)