Yan Shvartzshnaider

dblp:72/8176 · DBLP profile ↗
← Back
14ranked-venue papers
9as first author
5since 2021 · last 2026
0000-0001-5954-916XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 6 · 5 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 3 since 2021Computer networks · 4 · 3 first-authorSecurity and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Privacy Cards for Surfacing Mental Models and Exploring Privacy Concerns: A Case Study of Voice-First Ambient Interfaces with Older Adults
abstract
We investigate the ethical and privacy implications of voice-first ambient interfaces (VFAIs) for aging in place through an in-depth engagement with five older adults. Our participants were in the process of becoming experienced VFAI users, and had used a VFAI-based design probe for health data reporting. We create and iteratively refine an interview protocol using Privacy Cards. We customize Privacy Cards by drawing on participants’ previous interviews and device usage logs. Using Privacy Cards, we conduct interviews to surface their mental models, and explore their privacy concerns. We find insufficient mental models for proper consent. For example, participants did not know who could access their data, and experienced difficulty distinguishing built-in functionality from third-party apps. Participants initially expressed little worry about VFAI-related ethical concerns, but interviews with Privacy Cards revealed nuanced issues, resulting in various implications for future research and design.
Andrea Cuadra, Samar Sabie, Yan Shvartzshnaider, Deborah Estrin
CHI3
2026 Privacy Bias in Language Models: A Contextual Integrity-based Auditing Metric
abstract
As large language models (LLMs) are integrated into sociotechnical systems, it is crucial to examine the privacy biases they exhibit. We define privacy bias as the appropriateness value of information flows in LLM responses. A deviation between privacy biases and expected values, referred to as privacy bias delta, may indicate privacy violations. As an auditing metric, privacy bias can help (a) model trainers evaluate the ethical and societal impact of LLMs, (b) service providers select context-appropriate LLMs, and (c) policymakers assess the appropriateness of privacy biases in deployed LLMs. We formulate and answer a novel research question: how can we reliably examine privacy biases in LLMs and the factors that influence them? We present a novel approach for assessing privacy biases using a contextual integrity-based methodology to evaluate the responses from various LLMs. Our approach accounts for the sensitivity of responses across prompt variations, which hinders the evaluation of privacy biases. Finally, we investigate how privacy biases are affected by model capacities and optimizations.
Yan Shvartzshnaider, Vasisht Duddu
Proc. Priv. Enhancing Technol.1
2025 Measuring NIST Authentication Standards Compliance by Higher Education Institutions
Noah J. Apthorpe, Boen Beavers, Yan Shvartzshnaider, Brett Frischmann
SOUPS3
2025 Trust and Friction: Negotiating How Information Flows through Decentralized Social Media
abstract
Decentralized social media protocols enable users in independent, user-hosted servers (i.e., instances) to interact with each other while they self-govern. This community-based model of social media governance opens up new opportunities for tailored decision-making about information flows - i.e., what user data is shared to whom and when - and in turn, for protecting user privacy. To better understand how community governance shapes privacy expectations on decentralized social media, we conducted a semi-structured interview with 23 users of the Fediverse, a decentralized social media network. Our findings illustrate important factors that shape a community's understandings of information flows, such as rules and proactive efforts from admins who are perceived as trustworthy. We highlight ''governance frictions'' between communities that raise new privacy risks due to incompatibilities in values, security practices, and software. Our findings point to the unique challenges of decentralized social media, suggest design opportunities to address frictions, and outline the role of participatory decision-making to realize the full potential of decentralization.
Sohyeon Hwang, Priyanka Nanayakkara, Yan Shvartzshnaider
Proc. ACM Hum. Comput. Interact.3
2022 GKC-CI: A unifying framework for contextual norms and information governance
abstract
Abstract Privacy‐enhancing technologies that incorporate a socially meaningful conception of privacy, one that meets people's expectations and is ethically defensible, need to factor in contextual privacy norms and information governance as part of their design. This involves understanding what information handling practices users deem acceptable, what factors influence users' perceptions and behaviors, and how informational norms evolve. In this paper, we present GKC‐CI, a unifying framework for examining contextual privacy norms and information governance in a given context to help structure research inquiries around these questions.
Yan Shvartzshnaider, Madelyn Sanfilippo, Noah J. Apthorpe
J. Assoc. Inf. Sci. Technol.1
2020 Disaster privacy/privacy disaster
abstract
Abstract Privacy expectations during disasters differ significantly from nonemergency situations. This paper explores the actual privacy practices of popular disaster apps, highlighting location information flows. Our empirical study compares content analysis of privacy policies and government agency policies, structured by the contextual integrity framework, with static and dynamic app analysis documenting the personal data sent by 15 apps. We identify substantive gaps between regulation and guidance, privacy policies, and information flows, resulting from ambiguities and exploitation of exemptions. Results also indicate gaps between governance and practice, including the following: (a) Many apps ignore self‐defined policies; (b) while some policies state they “might” access location data under certain conditions, those conditions are not met as 12 apps included in our study capture location immediately upon initial launch under default settings; and (c) not all third‐party data recipients are identified in policy, including instances that violate expectations of trusted third parties.
Madelyn Sanfilippo, Yan Shvartzshnaider, Irwin Reyes, Helen Nissenbaum, Serge Egelman
J. Assoc. Inf. Sci. Technol.2
2019 Going against the (Appropriate) Flow: A Contextual Integrity Approach to Privacy Policy Analysis
abstract
We present a method for analyzing privacy policies using the framework of contextual integrity (CI). This method allows for the systematized detection of issues with privacy policy statements that hinder readers’ ability to understand and evaluate company data collection practices. These issues include missing contextual details, vague language, and overwhelming possible interpretations of described information transfers. We demonstrate this method in two different settings. First, we compare versions of Facebook’s privacy policy from before and after the Cambridge Analytica scandal. Our analysis indicates that the updated policy still contains fundamental ambiguities that limit readers’ comprehension of Facebook’s data collection practices. Second, we successfully crowdsourced CI annotations of 48 excerpts of privacy policies from 17 companies with 141 crowdworkers. This indicates that regular users are able to reliably identify contextual information in privacy policy statements and that crowdsourcing can help scale our CI analysis method to a larger number of privacy policy statements.
Yan Shvartzshnaider, Noah J. Apthorpe, Nick Feamster, Helen Nissenbaum
HCOMP1
2019 VACCINE: Using Contextual Integrity For Data Leakage Detection
abstract
Modern enterprises rely on Data Leakage Prevention (DLP) systems to enforce privacy policies that prevent unintentional flow of sensitive information to unauthorized entities. However, these systems operate based on rule sets that are limited to syntactic analysis and therefore completely ignore the semantic relationships between participants involved in the information exchanges. For similar reasons, these systems cannot enforce complex privacy policies that require temporal reasoning about events that have previously occurred.
Yan Shvartzshnaider, Zvonimir Pavlinovic, Ananth Balashankar, Thomas Wies, Lakshminarayanan Subramanian, Helen Nissenbaum, Prateek Mittal
WWW1
2016 Learning Privacy Expectations by Crowdsourcing Contextual Informational Norms
abstract
Designing programmable privacy logic frameworks that correspond to social, ethical, and legal norms has been a fundamentally hard problem. Contextual integrity (CI) (Nissenbaum, 2010) offers a model for conceptualizing privacy that is able to bridge technical design with ethical, legal, and policy approaches. While CI is capable of capturing the various components of contextual privacy in theory, it is challenging to discover and formally express these norms in operational terms. In the following, we propose a crowdsourcing method for the automated discovery of contextual norms. To evaluate the effectiveness and scalability of our approach, we conducted an extensive survey on Amazon's Mechanical Turk (AMT) with more than 450 participants and 1400 questions. The paper has three main takeaways: First, we demonstrate the ability to generate survey questions corresponding to privacy norms within any context. Second, we show that crowdsourcing enables the discovery of norms from these questions with strong majoritarian consensus among users. Finally, we demonstrate how the norms thus discovered can be encoded into a formal logic to automatically verify their consistency.
Yan Shvartzshnaider, Schrasing Tong, Thomas Wies, Paula Kift, Helen Nissenbaum, Lakshminarayanan Subramanian, Prateek Mittal
HCOMP1
2013 Design for change: Information-centric architecture to support agile disaster response
abstract
This paper presents a case for the adoption of an information-centric architecture for a global disaster management system. Drawing from a case study of the 2010/2011 Queensland floods, we describe the challenges in providing every participant with relevant and actionable information. We use various examples to argue for a more flexible information dissemination framework which is designed from the ground up to minimise the effort needed to fix the unexpected and unavoidable information acquisition, quality, and dissemination challenges posed by any real disaster.
Yan Shvartzshnaider, Maximilian Ott
ICC1
2013 Into the Moana1 - Hypergraph-based network layer indirection
abstract
In this paper, we introduce the Moana network infrastructure. It draws on well-adopted practices from the database and software engineering communities to provide a robust and expressive information-sharing service using hypergraph-based network indirection. Our proposal is twofold. First, we argue for the need for additional layers of indirection used in modern information systems to bring the network layer abstraction closer to the developer's world, allowing for expressiveness and flexibility in the creation of future services. Second, we present a modular and extensible design of the network fabric to support incremental architectural evolution and innovation, as well as its initial evaluation.
Yan Shvartzshnaider, Maximilian Ott, Olivier Mehani, Guillaume Jourjon, Thierry Rakotoarivelo, David Levy 0001
INFOCOM1
2012 Enabling Internet-of-Things services in the MobilityFirst Future Internet Architecture
abstract
In the emerging paradigm of pervasive computing, applications change their behaviors in response to their environmental context, which is provided by the smart objects in the Internet of Things (IoT). Due to the inherent heterogeneity of physical world objects, realizing the IoT requires service layers to fill the gap between the low level interfaces of networked objects and the applications which use them. In this paper, we show that the MobilityFirst Future Internet Architecture is an ideal platform for realizing pervasive computing in an IoT framework. In particular, MobilityFirst's identity based routing, overloaded identities, content caching and in-network compute plane are excellent building blocks for IoT applications. We then present a detailed example of a location based service built using MobilityFirst.
Jun Li 0034, Yan Shvartzshnaider, John-Austen Francisco, Richard P. Martin, Dipankar Raychaudhuri
WOWMOM2
2011 Towards a fully distributed n-tuple store
abstract
We present our work towards building a novel distributed n-tuple store by extending the Kademlia DHT [1] algorithm to support n dimensional keys as well as an multi get operator, where some of the dimensions of the "query" key can be left unspecified.
Yan Shvartzshnaider, Maximilian Ott
SIGCOMM1
2010 Global Semantic Graph as an Alternative Information and Collaboration Infrastructure
Yan Shvartzshnaider
ESWC (2)1