Isabel Wagner

dblp:159/1066 · also Isabel Dietrich · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
5since 2021 · last 2023
0000-0003-0242-6278ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 5 since 2021Computer networks · 6 · 2 first-authorSystems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2023 Privacy Policies across the Ages: Content of Privacy Policies 1996-2021
abstract
It is well known that most users do not read privacy policies but almost always tick the box to agree with them. While the length and readability of privacy policies have been well studied and many approaches for policy analysis based on natural language processing have been proposed, existing studies are limited in their depth and scope, often focusing on a small number of data practices at single point in time. In this article, we fill this gap by analyzing the 25-year history of privacy policies using machine learning and natural language processing and presenting a comprehensive analysis of policy contents. Specifically, we collect a large-scale longitudinal corpus of privacy policies from 1996 to 2021 and analyze their content in terms of the data practices they describe, the rights they grant to users, and the rights they reserve for their organizations. We pay particular attention to changes in response to recent privacy regulations such as the GDPR and CCPA. We observe some positive changes, such as reductions in data collection post-GDPR, but also a range of concerning data practices, such as widespread implicit data collection for which users have no meaningful choices or access rights. Our work is an important step toward making privacy policies machine readable on the user side, which would help users match their privacy preferences against the policies offered by web services.
Isabel Wagner
ACM Trans. Priv. Secur.1
2022 A Machine Learning Approach to Detect Differential Treatment of Anonymous Users
Isabel Wagner
ESORICS (2)1
2022 CAESAR8: An agile enterprise architecture approach to managing information security risks
abstract
In theory, implementing an Enterprise Architecture (EA) should enable organizations to increase the accuracy of information security risk assessments. In reality, however, organizations struggle to fully implement EA frameworks because the requirements for implementing an EA and the benefits of commercial frameworks are unclear, and the overhead of maintaining EA artifacts is unacceptable, especially for smaller organizations. In this paper, we describe a novel approach called CAESAR8 (Continuous Agile Enterprise Security Architecture Review in 8 domains) that supports dynamic and holistic reviews of information security risks in IT projects. CAESAR8’s nonlinear design supports continuous reassessment of information security risks, based on a checklist that assesses the maturity of security considerations in eight domains that often cause information security failures. CAESAR8 assessments can be completed by multiple stakeholders independently, thus ensuring consideration of their tacit knowledge while preventing groupthink. Our evaluation with experienced industry professionals showed that CAESAR8 successfully addresses real-world problems in information security risk management, with significant benefits particularly for smaller organizations.
Paul Loft, Ying He 0004, Iryna Yevseyeva, Isabel Wagner
Comput. Secur.4
2022 Using Metrics Suites to Improve the Measurement of Privacy in Graphs
abstract
Social graphs are widely used in research (e.g., epidemiology) and business (e.g., recommender systems). However, sharing these graphs poses privacy risks because they contain sensitive information about individuals. Graph anonymization techniques aim to protect individual users in a graph, while graph de-anonymization aims to re-identify users. The effectiveness of anonymization and de-anonymization algorithms is usually evaluated with privacy metrics. However, it is unclear how strong existing privacy metrics are when they are used in graph privacy. In this article, we study 26 privacy metrics for graph anonymization and de-anonymization and evaluate their strength in terms of three criteria:monotonicityindicates whether the metric indicates lower privacy for stronger adversaries; for within-scenario comparisons,evennessindicates whether metric values are spread evenly; and for between-scenario comparisons,shared value rangeindicates whether metrics use a consistent value range across scenarios. Our extensive experiments indicate that no single metric fulfills all three criteria perfectly. We therefore use methods from multi-criteria decision analysis to aggregate multiple metrics in a metrics suite, and we show that these metrics suites improve monotonicity compared to the best individual metric. This important result enables more monotonic, and thus more accurate, evaluations of new graph anonymization and de-anonymization algorithms.
Isabel Wagner
IEEE Trans. Dependable Secur. Comput.2
2021 Designing Strong Privacy Metrics Suites Using Evolutionary Optimization
abstract
The ability to measure privacy accurately and consistently is key in the development of new privacy protections. However, recent studies have uncovered weaknesses in existing privacy metrics, as well as weaknesses caused by the use of only a single privacy metric. Metrics suites, or combinations of privacy metrics, are a promising mechanism to alleviate these weaknesses, if we can solve two open problems: which metrics should be combined and how. In this article, we tackle the first problem, i.e., the selection of metrics for strong metrics suites, by formulating it as a knapsack optimization problem with both single and multiple objectives. Because solving this problem exactly is difficult due to the large number of combinations and many qualities/objectives that need to be evaluated for each metrics suite, we apply 16 existing evolutionary and metaheuristic optimization algorithms. We solve the optimization problem for three privacy application domains: genomic privacy, graph privacy, and vehicular communications privacy. We find that the resulting metrics suites have better properties, i.e., higher monotonicity, diversity, evenness, and shared value range, than previously proposed metrics suites.
Isabel Wagner, Iryna Yevseyeva
ACM Trans. Priv. Secur.1
2019 On the Strength of Privacy Metrics for Vehicular Communication
abstract
Vehicular communication plays a key role in near-future automotive transport, promising features such as increased traffic safety and wireless software updates. However, vehicular communication can expose drivers' locations and thus poses privacy risks. Many schemes have been proposed to protect privacy in vehicular communication, and their effectiveness is usually evaluated with privacy metrics. However, to the best of our knowledge, (1) different privacy metrics have never been compared to each other, and (2) it is unknown how strong the metrics are. In this paper, we evaluate and compare the strength of 41 privacy metrics in terms of four novel criteria: Privacy metrics should be monotonic, i.e., indicate decreasing privacy for increasing adversary strength; their values should be spread evenly over a large value range to support within-scenario comparability; and they should share a large portion of their value range between traffic conditions to support between-scenario comparability. We evaluate all four criteria on real and synthetic traffic with state-of-the-art adversary models and create a ranking of privacy metrics. Our results indicate that no single metric dominates across all criteria and traffic conditions. We therefore recommend to use metrics suites, i.e., combinations of privacy metrics, when evaluating new privacy-enhancing technologies.
Isabel Wagner
IEEE Trans. Mob. Comput.2
2018 POSTER: Evaluating Privacy Metrics for Graph Anonymization and De-anonymization
abstract
Many modern communication systems generate graph data, for example social networks and email networks. Such graph data can be used for recommender systems and data mining. However, because graph data contains sensitive information about individuals, sharing or publishing graph data may pose privacy risks. To protect graph privacy, data anonymization has been proposed to prevent individual users in a graph from being identified by adversaries. The effectiveness of both anonymization and de-anonymization techniques is usually evaluated using the adversary's success rate. However, the success rate does not measure privacy for individual users in a graph because it is an aggregate per-graph metric. In addition, it is unclear whether the success rate is monotonic, i.e. whether it indicates higher privacy for weaker adversaries, and lower privacy for stronger adversaries. To address these gaps, we propose a methodology to systematically evaluate the monotonicity of graph privacy metrics, and present preliminary results for the monotonicity of 25 graph privacy metrics.
Isabel Wagner
AsiaCCS2
2017 Measuring Privacy in Vehicular Networks
abstract
Vehicular communication plays a key role in nearfuture automotive transport, promising features like increased traffic safety or wireless software updates. However, vehicular communication can expose driver locations and thus poses important privacy risks. Many schemes have been proposed to protect privacy in vehicular communication, and their effectiveness is usually shown using privacy metrics. However, to the best of our knowledge, (1) different privacy metrics have never been compared to each other, and (2) it is unknown how strong the metrics are. In this paper, we argue that privacy metrics should be monotonic, i.e. that they indicate decreasing privacy for increasing adversary strength, and we evaluate the monotonicity of 32 privacy metrics on real and synthetic traffic with state-ofthe- art adversary models. Our results indicate that most privacy metrics are weak at least in some situations. We therefore recommend to use metrics suites, i.e. combinations of privacy metrics, when evaluating new privacy-enhancing technologies.
Isabel Wagner
LCN1
2017 Evaluating the Strength of Genomic Privacy Metrics
abstract
The genome is a unique identifier for human individuals. The genome also contains highly sensitive information, creating a high potential for misuse of genomic data (for example, genetic discrimination). In this article, we investigate how genomic privacy can be measured in scenarios where an adversary aims to infer a person’s genomic markers by constructing probability distributions on the values of genetic variations. We measured the strength of privacy metrics by requiring that metrics are monotonic with increasing adversary strength and uncovered serious problems with several existing metrics currently used to measure genomic privacy. We provide suggestions on metric selection, interpretation, and visualization and illustrate the work flow using case studies for three real-world diseases.
Isabel Wagner
ACM Trans. Priv. Secur.1
2016 User interface design for privacy awareness in eHealth technologies
abstract
In this paper we investigate privacy issues relating to Human Computer Interfaces for mobile eHealth technologies. We present the Inform-Alert-Mitigate (I-AM) cycle, a novel approach to address privacy concerns that are associated with the use of these technologies. The I-AM approach supports the responsible innovation of new technologies. We demonstrate the effectiveness of I-AM by applying it to examples taken from mobile applications relating to personal health. We discuss three classes of applications: a) fitness trackers b) personal wellbeing applications and c) medical applications, and evaluate the privacy exposure of their users using representative applications from these classes. The paper evaluates the current privacy enhancing features of these applications against the identified risks and demonstrates how the I-AM approach can be applied to yield additional and more effective privacy protection for these technologies.
Isabel Wagner, Ying He 0004, Duska Rosenberg, Helge Janicke
CCNC1
2016 POSTER: Design Ideas for Privacy-aware User Interfaces for Mobile Devices
abstract
Privacy in mobile applications is an important topic, especially when it concerns applications that gather and process health data. Using MyFitnessPal as an example eHealth app, we analyze how privacy-aware its user interface is, i.e. how well users are informed about privacy and how much control they have. We find several issues with the current interface and develop five design ideas that make the interface more privacy-aware. In a small pilot user study, we find that most of the design ideas seem to work well and enhance end users' understanding and awareness of privacy.
Neel Tailor, Ying He 0004, Isabel Wagner
WISEC3
2016 Gender and Performance in Computer Science
abstract
The term gender gap refers to the significant underrepresentation of females in many subjects. In Computer Science, the gender gap exists at all career levels. In this article, we study whether there is a performance gap in addition to the gender gap. To answer this question, we analyzed statistical data on student performance in Computer Science from 129 universities in the United Kingdom covering the years 2002 to 2013. We find that male students were awarded significantly more first-class degrees than female students. We evaluate four other subjects—Subjects Allied to Medicine, Business & Administrative Studies, Mathematical Sciences, and Engineering & Technology—and find that they do not exhibit this performance gap. From this finding, we review explanations for the gender and performance gaps, as well as potential solutions to eliminate the gaps. Most solutions do not require major institutional change and could thus be implemented easily.
Isabel Wagner
ACM Trans. Comput. Educ.1
2010 Simulation of Ad Hoc Routing Protocols using OMNeT++ - A Case Study for the DYMO Protocol
Christoph Sommer 0001, Isabel Wagner, Falko Dressler
Mob. Networks Appl.2
2010 Hybrid simulation of Sensor and Actor Networks with BARAKA
Thomas Halva Labella, Isabel Wagner, Falko Dressler
Wirel. Networks2
2009 A rule-based system for programming self-organized sensor and actor networks
Falko Dressler, Isabel Wagner, Reinhard German, Bettina Krüger
Comput. Networks2
2009 On the lifetime of wireless sensor networks
abstract
Network lifetime has become the key characteristic for evaluating sensor networks in an application-specific way. Especially the availability of nodes, the sensor coverage, and the connectivity have been included in discussions on network lifetime. Even quality of service measures can be reduced to lifetime considerations. A great number of algorithms and methods were proposed to increase the lifetime of a sensor network—while their evaluations were always based on a particular definition of network lifetime. Motivated by the great differences in existing definitions of sensor network lifetime that are used in relevant publications, we reviewed the state of the art in lifetime definitions, their differences, advantages, and limitations. This survey was the starting point for our work towards a generic definition of sensor network lifetime for use in analytic evaluations as well as in simulation models—focusing on a formal and concise definition of accumulated network lifetime and total network lifetime. Our definition incorporates the components of existing lifetime definitions, and introduces some additional measures. One new concept is the ability to express the service disruption tolerance of a network. Another new concept is the notion of time-integration: in many cases, it is sufficient if a requirement is fulfilled over a certain period of time, instead of at every point in time. In addition, we combine coverage and connectivity to form a single requirement called connected coverage. We show that connected coverage is different from requiring noncombined coverage and connectivity. Finally, our definition also supports the concept of graceful degradation by providing means of estimating the degree of compliance with the application requirements. We demonstrate the applicability of our definition based on the surveyed lifetime definitions as well as using some example scenarios to explain the various aspects influencing sensor network lifetime.
Isabel Wagner, Falko Dressler
ACM Trans. Sens. Networks1
2006 Lifetime Analysis in Heterogeneous Sensor Networks
abstract
Wireless sensor networks (WSN) are composed of battery-driven communication entities performing multiple, usually different tasks. In order to complete a given task, all sensor nodes, which are deployed in an ad-hoc fashion have to collaborate by exchanging and forwarding measurement data. We define the behavior of the overall sensor network based on the parameters lifetime and functional density. The functional density describes the distribution of all necessary tasks in a given geographical area. The lifetime is primarily given by the time each task is successfully performed by at least one node, i.e. the functional density of all necessary tasks. Nodes can become unavailable due to insufficient remaining energy. We assume that sensor nodes can be reconfigured or reprogrammed by a mobile robot system. There are various reasons for considering robots for this reconfiguration, e.g. reliability, security, and deployment issues. In this paper, we evaluate the advantages of exploiting reconfiguration and reprogramming schemes WSN using mobile robots. The primary objective is to increase the lifetime of the overall network. This goal is achieved by optimizing the functional density of heterogeneous tasks. Based on a developed simulation model, we discuss the advantages and performance characteristics
Falko Dressler, Isabel Wagner
DSD2