Exploring Design and Governance Challenges in the Development of Privacy-Preserving Computation
Honorable MentionAuthors
Document Title
Exploring Design and Governance Challenges in Privacy-Enhancing Computing Solutions
Document Information
- Subject Area: Privacy-Enhancing Technologies (PETs) and Human-Computer Interaction (HCI)
- Keywords: Privacy-Enhancing Technologies, expert interviews, cryptography, policy, computer privacy
- Conference Source: CHI Conference on Human Factors in Computing Systems (CHI '21), Yokohama, Japan, 2021
- Authors and Institutions:
- Nitin Agrawal, Reuben Binns, Max Van Kleek (University of Oxford, UK)
- Kim Laine (Microsoft Research)
- Nigel Shadbolt (University of Oxford, UK)
Research Background and Issues
-
Issues and Challenges:
- Privacy-Enhancing Computing Technologies (PPCTs), including homomorphic encryption, secure multi-party computation (SMPC), and differential privacy, pose design and governance challenges due to their novelty, complexity, and opacity.
- Translating the abstract concept of privacy into technically executable solutions is highly challenging.
- Enhancing the usability of these technologies for developers and explaining them to stakeholders and society while ensuring accountability remains a significant issue.
-
Importance: Privacy is a fundamental human rights issue. The application and promotion of PPCTs involve a wide range of societal stakeholders and institutions, playing a crucial role in data regulation and privacy protection.
-
Research Motivation: The authors aim to explore the design and governance challenges of PPCTs through interviews with researchers, developers, policymakers, industry leaders, and designers, investigating motivations, expectations, opportunities, and adoption barriers, and proposing directions for future improvements.
Solutions
-
Methods and Framework:
- Interview Study: Conducted semi-structured interviews with nine experts to gain insights into the application barriers and potential opportunities of PPCTs. Interviewees included researchers, policymakers, industry experts, and designers.
- Thematic Analysis: Encoded and analyzed interview content to extract key themes and subthemes.
-
Research Objectives:
- Identify challenges faced by different stakeholders in adopting PPCTs.
- Explore the driving forces behind the motivations for adopting PPCTs.
- Analyze how PPCTs can be explained and made accountable to society and affected stakeholders.
-
Innovations:
- Propose interdisciplinary collaboration from technology to practice.
- Investigate multidimensional challenges of PPCTs in usability, governance, and public acceptance.
- Highlight the importance of designers and developers as indirect users of privacy-enhancing technologies.
Research Findings
Technical Challenges and Opportunities
-
Challenges in Moving from Theory to Practice:
- Significant gaps exist between foundational theories and practical applications of PPCTs; current research is largely experimental.
- Complex implementation details, vulnerabilities, and inefficiencies require developers to have deep understanding.
- Certain application scenarios (e.g., time-series data) reveal disconnects between theory and practice.
-
Importance of Interdisciplinary Collaboration:
- Integration of expertise from data science, computer engineering, cryptography, and other fields is essential.
- Multidisciplinary teams need to overcome differences in incentives and goals.
-
Usability and Standardization Issues:
- PPCTs impose high demands on developers. Existing libraries and tools require trade-offs between abstraction and flexibility.
- Some functionalities (e.g., performance optimization of homomorphic encryption) rely on "low-level techniques," making it difficult to encapsulate them into user-friendly libraries.
Motivations and Application Scenarios
-
Motivations for Privacy Protection and Extensions:
- The primary driver of PPCTs is the protection of individual privacy, along with new opportunities for data analysis and compliance needs (e.g., GDPR).
- PPCTs also have significant applications in national security, corporate competition, and intellectual property protection.
-
Integration of Policy and New Opportunities:
- PPCTs offer potential solutions to reconcile privacy regulations, such as balancing anti-money laundering efforts with privacy protection.
- Governments and enterprises could leverage PPCTs to overcome current legal constraints on data utilization.
Explanation and Accountability
-
Explanation Needs for Different Audiences:
- Simplifying complex technical language is crucial for public education and onboarding designers.
- Explanations for leaders and decision-makers should focus on relevance rather than excessive simplification.
-
Governance and Trust Mechanisms:
- Governments or organizations can enhance societal acceptance of the technology through certifications and trust marks.
- Expert consensus and collective agreement models are needed to address the challenge of individuals being unable to fully understand the technology.
-
Social Power and Transparency Issues:
- Attention must be paid to the potential of PPCTs to reinforce power imbalances of data owners (e.g., governments or enterprises).
- Systemic issues unrelated to privacy, such as risks of power abuse, need to be addressed comprehensively.
Limitations and Future Directions
- Limitations:
- Current research is heavily theoretical, with insufficient validation in application scenarios.
- More investment and research are needed for the development of general, scalable APIs and tools.
- Future Research Directions:
- In-depth study of user experience for designers and developers.
- Balancing high performance and usability in standardizing privacy-enhancing technologies.
- Long-term investigations into societal transparency and public acceptance.
Conclusion
This study analyzes the dual technical and societal challenges of implementing privacy-enhancing computing technologies from a multi-stakeholder perspective, identifying key issues in design, explanation, and governance. It provides important insights for future research and proposes specific requirements for developers, designers, and decision-makers, guiding industry and policy development.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can design and governance challenges of privacy-enhancing computation technologies (e.g., homomorphic encryption, secure multi-party computation, differential privacy) be addressed?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- What usability and standardization issues do designers and developers face when using privacy-enhancing computation technologies?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- How can social acceptance and accountability of privacy-enhancing computation be explained and improved for different stakeholders (e.g., public and policymakers)?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
Practical Problems
1- 83%
Smart Home Security Cameras and Shifting Lines of Creepiness: A Design-Led Inquiry
CHI '19· Privacy by Design & User Control +2
- 83%
Privacy of Default Apps in Apple’s Mobile Ecosystem
CHI '24· Privacy by Design & User Control +2
- 71%
When Feasibility of Fairness Audits Relies on Willingness to Share Data: Examining User Acceptance of Multi-Party Computation Protocols for Fairness Monitoring
CHI '26· AI Ethics, Fairness & Accountability +2
- 71%
Investigating Bystander Privacy in Chinese Smart Home Apps
CHI '26· Smart Home Privacy & Security +2
- 71%
Do Citizens Agree with the EU AI Act? Public Perspectives on Risk and Regulation of AI Systems
CHI '26· AI Ethics, Fairness & Accountability +2
- 67%
Overlooking context: How do Defaults and Framing Reduce Deliberation in Smart Home Privacy Decision-Making?
CHI '21· Privacy by Design & User Control +1
- 67%
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
CHI '21· Privacy by Design & User Control +1
- 67%
Covert Embodied Choice: Decision-Making and the Limits of Privacy Under Biometric Surveillance
CHI '21· Privacy by Design & User Control +1
- 67%
“Our Users' Privacy is Paramount to Us”: A Discourse Analysis of How Period and Fertility Tracking App Companies Address the Roe v Wade Overturn
CHI '24· Privacy by Design & User Control +1
- 67%
Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)