Mental Models, Expectations and Implications of Client-Side Scanning: An Interview Study with Experts
Authors
Literature Title
Mental Models, Expectations, and Implications of Client-Side Scanning: An Interview Study with Experts
Literature Information
- Subject Area: Information security and privacy protection, specifically the application of client-side scanning (CSS) technology in preventing the dissemination of child sexual abuse material (CSAM).
- Keywords: Client-Side Scanning (CSS), Child Sexual Abuse Material (CSAM), Privacy Protection, Security and Privacy, Crime Prevention.
Research Background and Issues
-
Identified Problems or Challenges:
- Under the current legal and technical frameworks, the widespread use of encrypted communication has made traditional server-side scanning difficult to implement, while client-side scanning (CSS) is viewed as a potential solution.
- CSS is a deeply socially contextualized issue, with significant disagreements among stakeholders regarding the technology, its application scenarios, and potential societal impacts.
- Current discussions on CSS lack a comprehensive definition, and there are inconsistencies in understanding its technical capabilities, expected applications, and potential impacts.
-
Significance:
- This issue involves balancing privacy and rights with preventing the dissemination of CSAM, making it a globally significant and highly sensitive topic.
- A clear definition of CSS and an understanding of its potential societal interactions are crucial for shaping future social and technological policies.
-
Research Motivation and Preliminary Basis:
- To explore the definition of CSS and the mental models of experts on this issue, filling the research gap and providing a foundation for interdisciplinary discussions.
- The data source consists of semi-structured interviews with 28 experts from various fields, including child protection, law, privacy protection, and technology companies.
Solution
-
Methods and Research Objectives:
- The authors conducted qualitative interview research, analyzing the conceptual understanding, expectations, and potential impacts of CSS as perceived by 28 domain experts, and summarized their mental models.
- The main research objectives include:
- Establishing and analyzing experts' multidimensional understanding of CSS (how it works, what content is scanned, etc.).
- Exploring their expectations for CSS technology and its practical challenges.
- Analyzing the potential impacts of CSS on individual and societal levels.
-
Research Innovations:
- Structuring CSS into a data-driven framework, clarifying its key technical dimensions (input, output, algorithms, user interaction, reporting, etc.).
- Proposing universally applicable mental model dimensions for CSS to facilitate discussions on technology, privacy, and ethics among stakeholders.
- Incorporating diverse stakeholder perspectives, including privacy preservation interests and the feasibility of technical implementation, to achieve a balanced discussion.
-
Implementation Steps and Key Techniques:
- Designed a detailed, multidimensional interview framework, collecting expert data related to structured goals through open-ended questions.
- Visualized experts' abstract understanding of CSS using flowcharts and event sequence analysis, forming technical mental models.
- Employed a hybrid coding method for qualitative analysis (including open coding and selective coding).
Research Findings
-
Specific Findings:
- Extracted a mental model framework for CSS, including:
- Inputs during system construction (e.g., scanning algorithms, triggering conditions, operational levels).
- Key outputs (e.g., match results, false positive possibilities).
- User interaction aspects (e.g., whether users are notified, whether user consent is required).
- Interaction with third-party reporting modules (e.g., minimum reporting thresholds).
- Identified technical and societal risks, such as potential false positives, trust risks due to lack of transparency, and the danger of misuse for expanded scanning purposes.
- Extracted a mental model framework for CSS, including:
-
Comparative Advantages Over Existing Solutions:
- In global privacy debates, CSS is the only method that enables pre-scanning on the client side while preserving the integrity of E2EE (end-to-end encryption).
- The study goes beyond a single technical discussion, using multiple case scenarios (CSAM, copyright protection, advertising) to comprehensively evaluate the risks of technical implementation.
-
Experimental or Validation Results:
- Expert input validated the cross-domain complexity of CSS, highlighting the difficulty of establishing a single definition and pointing out the need for different implementation norms in varying social contexts.
-
Limitations and Future Directions:
- Limitations:
- Most participants were German experts, introducing a cultural bias in the sample.
- Data was based solely on interviews, without experimental validation, making it impossible to quantify the technology's effectiveness.
- The authors' backgrounds in information technology may have introduced a bias favoring privacy protection.
- Future Directions:
- Explore more advanced non-invasive technologies, such as heuristic encryption-based non-intrusive scanning.
- Expand the scope of policy-level discussions to more diverse regions and include the perspectives of non-technical experts.
- Design "low-intrusion" CSS for addressing societal issues beyond child protection.
- Limitations:
Conclusion
This study, through the perspectives of experts from multiple fields, provides a foundational analytical framework for the feasibility, societal risks, and ethical trade-offs of CSS technology. Despite its potential privacy risks and societal controversies, its promise in combating major crimes such as CSAM warrants continued exploration.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How should the core technical capabilities, scan content, and user interaction of client-side scanning (CSS) be defined?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- What do experts expect from CSS technology, and what challenges does it face in practice?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- What potential privacy and societal impacts might CSS technology have?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
Practical Problems
1- It is difficult to effectively prevent child sexual abuse material distribution in the face of end-to-end encryption.Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- 83%
Us and Them (and It): Social Orientation, Privacy Concerns, and Expected Use of Pandemic-Tracking Apps in the United States
CHI '21· Privacy by Design & User Control +2
- 80%
The Politics of Privacy Theories: Moving from Norms to Vulnerabilities
CHI '20· Privacy by Design & User Control +1
- 80%
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
CHI '21· Privacy by Design & User Control +1
- 80%
Covert Embodied Choice: Decision-Making and the Limits of Privacy Under Biometric Surveillance
CHI '21· Privacy by Design & User Control +1
- 80%
“Our Users' Privacy is Paramount to Us”: A Discourse Analysis of How Period and Fertility Tracking App Companies Address the Roe v Wade Overturn
CHI '24· Privacy by Design & User Control +1
- 80%
Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)
CHI '24· Privacy by Design & User Control +1
- 80%
Disconnecting: Towards a Semiotic Framework for Personal Data Trails
DIS '20· Privacy by Design & User Control +1
- 71%
It Shouldn't Be This Difficult: Researcher Perspectives on Diversity and Inclusion in Usable Privacy and Security Research
CHI '26· Privacy by Design & User Control +3
- 67%
Webcam Covering as Planned Behavior
CHI '18· Privacy by Design & User Control +2
- 67%
Bringing Design to the Privacy Table: Broadening
CHI '19· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)