Shukun Tokas

dblp:222/3875 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0001-9893-6613ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2024 Ethical Design for Data Privacy and User Privacy Awareness in the Metaverse
abstract
The significance of the metaverse has been growing rapidly within the online realm. However, several challenges remain, including privacy, ethics, and governance. Extended reality (XR) devices used to access the metaverse are equipped with high-quality sensors that can collect large amounts of sensitive user data, including biometric data and spatial data. Such considerations raise major concerns about the extent and nature of user data that this massive platform could accumulate, the data collection awareness and transparency it will provide to its users, and the ethical nature of the informed user consent it will request. This research aims to document and analyze the privacy challenges that arise from a prevalent metaverse application, align them with the related literature, and present an initial set of ethical design suggestions that can mitigate these privacy challenges. To do so, a case study shapes and informs a set of ethical design suggestions. The user onboarding of a prev alent multi-user/remote working metaverse application, Meta Horizon Workrooms, was documented and modeled through a user journey modeling language, CJML. The walkthrough revealed certain challenges regarding data privacy awareness, such as long, legally worded privacy policies, a hard-to-use user interface that can affect privacy awareness, and ambiguous wording in data-collection notices. Several best practices regarding user privacy were examined to tackle these issues, and certain ethical design solutions (e.g., informed user interface, design privacy icons, anonymization, logging, revising all consent) are suggested.
Ophelia Prillard, Costas Boletsis, Shukun Tokas
ICISSP3
2024 ERG-AI: enhancing occupational ergonomics with uncertainty-aware ML and LLM feedback
abstract
Abstract Workers, especially those involved in jobs requiring extended standing or repetitive movements, often face significant health challenges due to Musculoskeletal Disorders (MSDs). To mitigate MSD risks, enhancing workplace ergonomics is vital, which includes forecasting long-term employee postures, educating workers about related occupational health risks, and offering relevant recommendations. However, research gaps remain, such as the lack of a sustainable AI/ML pipeline that combines sensor-based, uncertainty-aware posture prediction with large language models for natural language communication of occupational health risks and recommendations. We introduce ERG-AI, a machine learning pipeline designed to predict extended worker postures using data from multiple wearable sensors. Alongside providing posture prediction and uncertainty estimates, ERG-AI also provides personalized health risk assessments and recommendations by generating prompts based on its performance and prompting Large Language Model (LLM) APIs, like GPT-4, to obtain user-friendly output. We used the Digital Worker Goldicare dataset to assess ERG-AI, which includes data from 114 home care workers who wore five tri-axial accelerometers in various bodily positions for a cumulative 2913 hours. The evaluation focused on the quality of posture prediction under uncertainty, energy consumption and carbon footprint of ERG-AI and the effectiveness of personalized recommendations rendered in easy-to-understand language.
Sagar Sen, Erik Johannes Husom, Simeon Tverdal, Shukun Tokas, Svein O. Tjøsvoll
Appl. Intell.5
2023 Privacy-Aware IoT: State-of-the-Art and Challenges
abstract
The consumer IoT is now prevalent and creates an enormous amount of fine-grained, detailed information about consumers’ everyday actions, personalities, and preferences. Such detailed information brings new and unique privacy challenges. The consumers are not aware of devices that surround them. There is a lack of transparency and absence of support for consumers to control the collection and processing of their personal and sensitive data. This paper reports on a review of state-of-the-art on privacy protection in IoT, with respect to privacy enhancing technologies (PETs) and GDPR-specific privacy principles. Drawing on a thorough analysis of 36 full papers, we identify key privacy challenges in IoT that need to be addressed to provide consumers with transparency and control over their personal data. The privacy challenges we have identified are (1) the lack of technical expertise in privacy notice comprehension, (2) the lack of transparency and control of personal data, and (3) the lack of personalized privacy recommendations.
Shukun Tokas, Gencer Erdogan, Ketil Stølen
ICISSP1
2022 Needs and Challenges Concerning Cyber-risk Assessment in the Cyber-physical Smart Grid
abstract
Cyber-risk assessment methods are used by energy companies to manage security risks in smart grids. However, current standards, methods and tools do not adequately provide the support needed in practice and the industry is struggling to adopt and carry out cyber-risk assessments. The contribution of this paper is twofold. First, we interview six companies from the energy sector to better understand their needs and challenges. Based on the interviews, we identify seven success criteria cyber-risk assessment methods for the energy sector need to fulfill to provide adequate support. Second, we present the methods CORAS, VAF, TM-STRIDE, and DA-SAN and evaluate the extent to which they fulfill the identified success criteria. Based on the evaluation, we provide lessons learned in terms of gaps that need to be addressed in general to improve cyber-risk assessment in the context of smart grids. Our results indicate the need for the following improvements: 1) ease of use and comprehensible m ethods, 2) support to determine whether a method is a good match for a given context, 3) adequate preparation to conduct cyber-risk assessment, 4) manage complexity, 5) adequate support for risk estimation, 6) support for trustworthiness and uncertainty handling, and 7) support for maintaining risk assessments.
Gencer Erdogan, Inger Anne Tøndel, Shukun Tokas, Michele Garau, Martin Gilje Jaatun
ICSOFT3
2022 Static checking of GDPR-related privacy compliance for object-oriented distributed systems
abstract
The adoption of information technology in foremost sectors of human activity such as banking, healthcare, education, governance etc., increases the amount of data collected and processed to enable these services. With the convenience the technology offers, it also brings increased challenges pertaining to the privacy. In response to these emerging privacy concerns, the European Union has approved the General Data Protection Regulation (GDPR) to strengthen data protection across the European Union. This regulation requires individuals and organizations that process personal data of EU citizens or provide services in EU, to comply with the privacy requirements in the GDPR. However, the privacy policies stating how personal information will be handled to meet regulations as well as organizational objectives, are given in natural language statements. To demonstrate a program's compliance with privacy policies, a link should be established between policy statements and the program code, with the support of a formalized analysis. Based on this vision, we formalize a notion of privacy policies and a notion of compliance for the setting of object-oriented distributed systems. For this we provide explicit constructs to specify constituents of privacy policies (i.e., principal, purpose, access right) on personal data. We present a policy specification language and a formalization of privacy compliance, as well as a high-level modeling language for distributed systems extended with support for policies. We define a type and effect system for static checking of compliance of privacy policies and show soundness of this analysis based on an operational semantics. Finally, we prove a progress property.
Shukun Tokas, Olaf Owe, Toktam Ramezanifarkhani
J. Log. Algebraic Methods Program.1
2020 A Formal Framework for Consent Management
Shukun Tokas, Olaf Owe
FORTE1