Helen Nissenbaum

dblp:15/4947 · DBLP profile ↗
← Back
17ranked-venue papers
1as first author
3since 2021 · last 2024
0000-0002-6485-6997ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 11 · 3 since 2021Databases, data management, data science and information retrieval · 5Security and privacy · 3 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Privacy for Groups Online: Context Matters
abstract
The pervasive influence of online activities in our lives, encompassing personal connections, professional engagements, and e-commerce, has amplified concerns about privacy. However, existing privacy research has predominantly concentrated on the individual level, paying less attention to the privacy practices and strategies adopted by online social groups. This research gap calls for a renewed focus on understanding and addressing privacy challenges specific to online group settings. In this paper we explore the privacy needs of online groups through the lens of Contextual Integrity. We perform two complementary studies: semi-structured qualitative interviews of Facebook Groups users (n=17), and a large-scale survey of individuals organizing in groups on Facebook, Discord, and Reddit (n=4486). We investigate the privacy needs of different contextual groups, and locate the presence of contextual norms, contextual member roles, explicit and implicit rules, and privacy concerns. We trace how this complex interplay informs privacy expectations, needs, and negotiations across groups. We find that technical systems provide limited tools to effectively enforce group privacy, allowing individuals to compromise privacy norms. Based on these findings, we offer recommendations to support the design of privacy controls for online groups.
Madiha Zahrah Choksi, Ero Balsa, Frauke Kreuter, Helen Nissenbaum
Proc. ACM Hum. Comput. Interact.4
2021 Computer Vision and Conflicting Values: Describing People with Automated Alt Text
abstract
Scholars have recently drawn attention to a range of controversial issues posed by the use of computer vision for automatically generating descriptions of people in images. Despite these concerns, automated image description has become an important tool to ensure equitable access to information for blind and low vision people. In this paper, we investigate the ethical dilemmas faced by companies that have adopted the use of computer vision for producing alt text: textual descriptions of images for blind and low vision people. We use Facebook's automatic alt text tool as our primary case study. First, we analyze the policies that Facebook has adopted with respect to identity categories, such as race, gender, age, etc., and the company's decisions about whether to present these terms in alt text. We then describe an alternative---and manual---approach practiced in the museum community, focusing on how museums determine what to include in alt text descriptions of cultural artifacts. We compare these policies, using notable points of contrast to develop an analytic framework that characterizes the particular apprehensions behind these policy choices. We conclude by considering two strategies that seem to sidestep some of these concerns, finding that there are no easy ways to avoid the normative dilemmas posed by the use of computer vision to automate alt text.
Margot J. Hanley, Solon Barocas, Karen Levy, Shiri Azenkot, Helen Nissenbaum
AIES5
2021 ACM UMAP 2021 Keynote Addresses
abstract
We are proud to present the following three keynote speakers, who will share their expertise with the participants of ACM UMAP 2021, the 29th Conference on User Modeling, Adaptation and Personalization. In this article, you find the speakers’ biographies and the titles of their keynote talks.
Judith Masthoff, Eelco Herder, Helen Nissenbaum, Maarten de Rijke, Julita Vassileva
UMAP3
2020 Disaster privacy/privacy disaster
abstract
Abstract Privacy expectations during disasters differ significantly from nonemergency situations. This paper explores the actual privacy practices of popular disaster apps, highlighting location information flows. Our empirical study compares content analysis of privacy policies and government agency policies, structured by the contextual integrity framework, with static and dynamic app analysis documenting the personal data sent by 15 apps. We identify substantive gaps between regulation and guidance, privacy policies, and information flows, resulting from ambiguities and exploitation of exemptions. Results also indicate gaps between governance and practice, including the following: (a) Many apps ignore self‐defined policies; (b) while some policies state they “might” access location data under certain conditions, those conditions are not met as 12 apps included in our study capture location immediately upon initial launch under default settings; and (c) not all third‐party data recipients are identified in policy, including instances that violate expectations of trusted third parties.
Madelyn Sanfilippo, Yan Shvartzshnaider, Irwin Reyes, Helen Nissenbaum, Serge Egelman
J. Assoc. Inf. Sci. Technol.4
2019 Going against the (Appropriate) Flow: A Contextual Integrity Approach to Privacy Policy Analysis
abstract
We present a method for analyzing privacy policies using the framework of contextual integrity (CI). This method allows for the systematized detection of issues with privacy policy statements that hinder readers’ ability to understand and evaluate company data collection practices. These issues include missing contextual details, vague language, and overwhelming possible interpretations of described information transfers. We demonstrate this method in two different settings. First, we compare versions of Facebook’s privacy policy from before and after the Cambridge Analytica scandal. Our analysis indicates that the updated policy still contains fundamental ambiguities that limit readers’ comprehension of Facebook’s data collection practices. Second, we successfully crowdsourced CI annotations of 48 excerpts of privacy policies from 17 companies with 141 crowdworkers. This indicates that regular users are able to reliably identify contextual information in privacy policy statements and that crowdsourcing can help scale our CI analysis method to a larger number of privacy policy statements.
Yan Shvartzshnaider, Noah J. Apthorpe, Nick Feamster, Helen Nissenbaum
HCOMP4
2019 VACCINE: Using Contextual Integrity For Data Leakage Detection
abstract
Modern enterprises rely on Data Leakage Prevention (DLP) systems to enforce privacy policies that prevent unintentional flow of sensitive information to unauthorized entities. However, these systems operate based on rule sets that are limited to syntactic analysis and therefore completely ignore the semantic relationships between participants involved in the information exchanges. For similar reasons, these systems cannot enforce complex privacy policies that require temporal reasoning about events that have previously occurred.
Yan Shvartzshnaider, Zvonimir Pavlinovic, Ananth Balashankar, Thomas Wies, Lakshminarayanan Subramanian, Helen Nissenbaum, Prateek Mittal
WWW6
2018 Achieving Meaningful Privacy in Digital Systems
abstract
Across a range of subfields, computer scientists and engineers have responded to society's call to safeguard privacy through technology, yielding scientific progress and impressive innovation. As the fields of privacy science and engineering mature, however, it's worth taking a moment to ask what ideas of privacy explicitly or implicitly underlie this work and whether they are meaningful, that is to say, whether they map onto ideas of privacy that provoked societal concerns, in the first place. If not, it is unclear, at best, what ends these scientific efforts are actually serving. In my lecture, I argue that privacy as Contextual Integrity (CI) is meaningful in this sense - philosophically sound while being accessible to formal representation. As such, CI could serve as a much-needed a bridge between technical approaches and ethical and policy approaches. I will identify promising directions for future work based on interesting technical applications of CI that have already emerged.
Helen Nissenbaum
CCS1
2016 Learning Privacy Expectations by Crowdsourcing Contextual Informational Norms
abstract
Designing programmable privacy logic frameworks that correspond to social, ethical, and legal norms has been a fundamentally hard problem. Contextual integrity (CI) (Nissenbaum, 2010) offers a model for conceptualizing privacy that is able to bridge technical design with ethical, legal, and policy approaches. While CI is capable of capturing the various components of contextual privacy in theory, it is challenging to discover and formally express these norms in operational terms. In the following, we propose a crowdsourcing method for the automated discovery of contextual norms. To evaluate the effectiveness and scalability of our approach, we conducted an extensive survey on Amazon's Mechanical Turk (AMT) with more than 450 participants and 1400 questions. The paper has three main takeaways: First, we demonstrate the ability to generate survey questions corresponding to privacy norms within any context. Second, we show that crowdsourcing enables the discovery of norms from these questions with strong majoritarian consensus among users. Finally, we demonstrate how the norms thus discovered can be encoded into a formal logic to automatically verify their consistency.
Yan Shvartzshnaider, Schrasing Tong, Thomas Wies, Paula Kift, Helen Nissenbaum, Lakshminarayanan Subramanian, Prateek Mittal
HCOMP5
2011 Grow-A-Game: A Tool for Values Conscious Design and Analysis of Digital Games
Jonathan Belman, Helen Nissenbaum, Mary Flanagan
DiGRA Conference2
2011 Values in Design - Building Bridges between RE, HCI and Ethics
Christian Detweiler, Alina Pommeranz, Jeroen van den Hoven, Helen Nissenbaum
INTERACT (4)4
2010 Adnostic: Privacy Preserving Targeted Advertising
Vincent Toubiana, Arvind Narayanan, Dan Boneh, Helen Nissenbaum, Solon Barocas
NDSS4
2007 A game design methodology to incorporate social activist themes
abstract
Can a set of articulated and tested methodologies be created whose endpoint is the reliable capacity for taking activist social themes into account? In this paper we explore a variety of educational and activist game approaches, and look specifically at the themes emerging from recent projects involving game design for young women. We articulate here design practices in a methodology, Values at Play (VAP), that could be used in the creation of games as well as the teaching of game design.
Mary Flanagan, Helen Nissenbaum
CHI2
2007 A Method For Discovering Values in Digital Games
Mary Flanagan, Jonathan Belman, Helen Nissenbaum, Jim Diamond
DiGRA Conference3
2006 Privacy and Contextual Integrity: Framework and Applications
abstract
Contextual integrity is a conceptual framework for understanding privacy expectations and their implications developed in the literature on law, public policy, and political philosophy. We formalize some aspects of contextual integrity in a logical framework for expressing and reasoning about norms of transmission of personal information. In comparison with access control and privacy policy frameworks such as RBAC, EPAL, and P3P, these norms focus on who personal information is about, how it is transmitted, and past and future actions by both the subject and the users of the information. Norms can be positive or negative depending on whether they refer to actions that are allowed or disallowed. Our model is expressive enough to capture naturally many notions of privacy found in legislation, including those found in HIPAA, COPPA, and GLBA. A number of important problems regarding compliance with privacy norms, future requirements associated with specific actions, and relations between policies and legal standards reduce to standard decision procedures for temporal logic.
Adam Barth, Anupam Datta, John C. Mitchell, Helen Nissenbaum
S&P4
2005 Values at play: design tradeoffs in socially-oriented game design
abstract
Significant work in the CHI community has focused on designing systems that support human values. Designers and engineers have also become increasingly aware of ways in which the artifacts they create can embody political, social, and ethical values. Despite such an awareness, there has been little work towards producing practical methodologies that systematically incorporate values into the design process. Many designers struggle to find a balance between their own values, those of users and other stakeholders, and those of the surrounding culture. In this paper, we present the RAPUNSEL project as a case study of game design in a values-rich context and describe our efforts toward navigating the complexities this entails. Additionally, we present initial steps toward the development of a systematic methodology for discovery, analysis, and integration of values in technology design in the hope that others may both benefit from and build upon this work.
Mary Flanagan, Daniel C. Howe, Helen Nissenbaum
CHI3
2005 New Design Methods for Activist Gaming
Mary Flanagan, Helen Nissenbaum, Daniel C. Howe
DiGRA Conference2
1996 Bias in Computer Systems
abstract
From an analysis of actual cases, three categories of bias in computer systems have been developed: preexisting, technical, and emergent. Preexisting bias has its roots in social institutions, practices, and attitudes. Technical bias arises from technical constraints of considerations. Emergent bias arises in a context of use. Although others have pointed to bias inparticular computer systems and have noted the general problem, we know of no comparable work that examines this phenomenon comprehensively and which offers a framework for understanding and remedying it. We conclude by suggesting that freedom from bias should by counted amoung the select set of criteria—including reliability, accuracy, and efficiency—according to which the quality of systems in use in society should be judged.
Batya Friedman, Helen Nissenbaum
ACM Trans. Inf. Syst.2