Exploring Design and Governance Challenges in the Development of Privacy-Preserving Computation

Honorable Mention
Privacy by Design & User ControlPrivacy Perception & Decision-MakingSmart Home Privacy & SecurityAI/ML Researchers & EngineersPrivacy Policy MakersHCI Researchers

Document Title

Exploring Design and Governance Challenges in Privacy-Enhancing Computing Solutions

Document Information

  • Subject Area: Privacy-Enhancing Technologies (PETs) and Human-Computer Interaction (HCI)
  • Keywords: Privacy-Enhancing Technologies, expert interviews, cryptography, policy, computer privacy
  • Conference Source: CHI Conference on Human Factors in Computing Systems (CHI '21), Yokohama, Japan, 2021
  • Authors and Institutions:
    • Nitin Agrawal, Reuben Binns, Max Van Kleek (University of Oxford, UK)
    • Kim Laine (Microsoft Research)
    • Nigel Shadbolt (University of Oxford, UK)

Research Background and Issues

  • Issues and Challenges:

    1. Privacy-Enhancing Computing Technologies (PPCTs), including homomorphic encryption, secure multi-party computation (SMPC), and differential privacy, pose design and governance challenges due to their novelty, complexity, and opacity.
    2. Translating the abstract concept of privacy into technically executable solutions is highly challenging.
    3. Enhancing the usability of these technologies for developers and explaining them to stakeholders and society while ensuring accountability remains a significant issue.
  • Importance: Privacy is a fundamental human rights issue. The application and promotion of PPCTs involve a wide range of societal stakeholders and institutions, playing a crucial role in data regulation and privacy protection.

  • Research Motivation: The authors aim to explore the design and governance challenges of PPCTs through interviews with researchers, developers, policymakers, industry leaders, and designers, investigating motivations, expectations, opportunities, and adoption barriers, and proposing directions for future improvements.

Solutions

  • Methods and Framework:

    1. Interview Study: Conducted semi-structured interviews with nine experts to gain insights into the application barriers and potential opportunities of PPCTs. Interviewees included researchers, policymakers, industry experts, and designers.
    2. Thematic Analysis: Encoded and analyzed interview content to extract key themes and subthemes.
  • Research Objectives:

    1. Identify challenges faced by different stakeholders in adopting PPCTs.
    2. Explore the driving forces behind the motivations for adopting PPCTs.
    3. Analyze how PPCTs can be explained and made accountable to society and affected stakeholders.
  • Innovations:

    1. Propose interdisciplinary collaboration from technology to practice.
    2. Investigate multidimensional challenges of PPCTs in usability, governance, and public acceptance.
    3. Highlight the importance of designers and developers as indirect users of privacy-enhancing technologies.

Research Findings

Technical Challenges and Opportunities

  • Challenges in Moving from Theory to Practice:

    1. Significant gaps exist between foundational theories and practical applications of PPCTs; current research is largely experimental.
    2. Complex implementation details, vulnerabilities, and inefficiencies require developers to have deep understanding.
    3. Certain application scenarios (e.g., time-series data) reveal disconnects between theory and practice.
  • Importance of Interdisciplinary Collaboration:

    1. Integration of expertise from data science, computer engineering, cryptography, and other fields is essential.
    2. Multidisciplinary teams need to overcome differences in incentives and goals.
  • Usability and Standardization Issues:

    1. PPCTs impose high demands on developers. Existing libraries and tools require trade-offs between abstraction and flexibility.
    2. Some functionalities (e.g., performance optimization of homomorphic encryption) rely on "low-level techniques," making it difficult to encapsulate them into user-friendly libraries.

Motivations and Application Scenarios

  • Motivations for Privacy Protection and Extensions:

    1. The primary driver of PPCTs is the protection of individual privacy, along with new opportunities for data analysis and compliance needs (e.g., GDPR).
    2. PPCTs also have significant applications in national security, corporate competition, and intellectual property protection.
  • Integration of Policy and New Opportunities:

    1. PPCTs offer potential solutions to reconcile privacy regulations, such as balancing anti-money laundering efforts with privacy protection.
    2. Governments and enterprises could leverage PPCTs to overcome current legal constraints on data utilization.

Explanation and Accountability

  • Explanation Needs for Different Audiences:

    1. Simplifying complex technical language is crucial for public education and onboarding designers.
    2. Explanations for leaders and decision-makers should focus on relevance rather than excessive simplification.
  • Governance and Trust Mechanisms:

    1. Governments or organizations can enhance societal acceptance of the technology through certifications and trust marks.
    2. Expert consensus and collective agreement models are needed to address the challenge of individuals being unable to fully understand the technology.
  • Social Power and Transparency Issues:

    1. Attention must be paid to the potential of PPCTs to reinforce power imbalances of data owners (e.g., governments or enterprises).
    2. Systemic issues unrelated to privacy, such as risks of power abuse, need to be addressed comprehensively.

Limitations and Future Directions

  1. Limitations:
    • Current research is heavily theoretical, with insufficient validation in application scenarios.
    • More investment and research are needed for the development of general, scalable APIs and tools.
  2. Future Research Directions:
    • In-depth study of user experience for designers and developers.
    • Balancing high performance and usability in standardizing privacy-enhancing technologies.
    • Long-term investigations into societal transparency and public acceptance.

Conclusion

This study analyzes the dual technical and societal challenges of implementing privacy-enhancing computing technologies from a multi-stakeholder perspective, identifying key issues in design, explanation, and governance. It provides important insights for future research and proposes specific requirements for developers, designers, and decision-makers, guiding industry and policy development.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/47561/2021

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3411764.3445677
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2021
emoji_events
Award
Honorable Mention
group
Authors
5 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Smart Home Privacy & Security
work
Professions
AI/ML Researchers & Engineers, Privacy Policy Makers, HCI Researchers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers