Lin Kyi

dblp:344/8877 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-4753-3889ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 5 · 4 first-author · 5 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 When Feasibility of Fairness Audits Relies on Willingness to Share Data: Examining User Acceptance of Multi-Party Computation Protocols for Fairness Monitoring
abstract
Fairness monitoring is critical for detecting algorithmic bias, as mandated by the EU AI Act. Since such monitoring requires sensitive user data (e.g., ethnicity), the AI Act permits its processing only with strict privacy measures, such as multi-party computation (MPC), in compliance with the GDPR. However, the effectiveness of such secure monitoring protocols ultimately depends on people’s willingness to share their data. Little is known about how different MPC protocol designs shape user acceptance. To address this, we conducted an online survey with 833 participants in Europe, examining user acceptance of various MPC protocol designs for fairness monitoring. Findings suggest that users prioritized risk-related attributes (e.g., privacy protection mechanism) in direct evaluation but benefit-related attributes (e.g., fairness objective) in simulated choices, with acceptance shaped by their fairness and privacy orientations. We derive implications for deploying and communicating privacy-preserving protocols in ways that foster informed consent and align with user expectations.
Changyang He, Parnian Jahangirirad, Lin Kyi, Asia J. Biega
CHI3
2026 From Clicks to Consensus: Collective Consent Assemblies for Data Governance
abstract
Obtaining meaningful and informed consent from users is essential for ensuring autonomy and control over one’s data. Notice and consent, the standard for collecting consent, has been criticized. While other individualized solutions have been proposed, this paper argues that a collective approach to consent is worth exploring. First, individual consent is not always feasible to collect for all data collection scenarios. Second, harms resulting from data processing are often communal in nature, given the interconnected nature of some data. Finally, ensuring truly informed consent for every individual has proven impractical.
Lin Kyi, Paul Gölz, Robin Berjon, Asia J. Biega
CHI1
2025 Governance of Generative AI in Creative Work: Consent, Credit, Compensation, and Beyond
Lin Kyi, Amruta Mahuli, Michael Six Silberman, Reuben Binns, Jun Zhao 0003, Asia J. Biega
CHI1
2024 "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection Purposes
abstract
Data collection purposes and their descriptions are presented on almost all privacy notices under the GDPR, yet there is a lack of research focusing on how effective they are at informing users about data practices. We fill this gap by investigating users’ perceptions of data collection purposes and their descriptions, a crucial aspect of informed consent. We conducted 23 semi-structured interviews with European users to investigate user perceptions of six common purposes (Strictly Necessary, Statistics and Analytics, Performance and Functionality, Marketing and Advertising, Personalized Advertising, and Personalized Content) and identified elements of an effective purpose name and description.
Lin Kyi, Abraham H. Mhaidli, Cristiana Teixeira Santos, Franziska Roesner, Asia J. Biega
CHI1
2024 "I'm not convinced that they don't collect more than is necessary": User-Controlled Data Minimization Design in Search Engines
Tanusree Sharma, Lin Kyi, Yang Wang 0005, Asia J. Biega
USENIX Security Symposium2
2023 Investigating Deceptive Design in GDPR's Legitimate Interest
abstract
Legitimate interest is one of the six grounds for processing data under the European Union’s General Data Protection Regulation (GDPR). The flexibility and ambiguity of the term "legitimate interests" can be problematic; coupled with the lack of enforcement from legal authorities and different interpretations from the various data protection authorities, legitimate interests can be taken advantage of as a loophole to collect more user data.
Lin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner, Frederike Zufall, Asia J. Biega
CHI1