Dayana Spagnuelo

dblp:149/7626 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0001-6882-6480ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author
YearPublicationVenuePosition
2024 The Trade-off Between Privacy & Quality for Counterfactual Explanations
abstract
Counterfactual explanations are a promising direction of explainable AI in many domains such as healthcare. These explanations produce a counterexample from the dataset that shows, for example, what should change about a patient to reduce their risk of developing diabetes type 2. However, this poses a clear privacy risk when the dataset contains information about people. Recent literature shows that this risk can be mitigated by using k-anonymity to generalise the explanation, such that it is not about a single person. In this paper, we investigate the trade-offs between privacy and explanation quality in the medical domain. Our results show that for around 40% of the explained cases, the real gain in privacy is limited as the generalisation increases while the explanations continue decreasing in quality. These findings suggest that this can be an unsuitable strategy in some situations, as its effectiveness depends on characteristics of the underlying dataset.
Sjoerd Berning, Vincent Dunning, Dayana Spagnuelo, Thijs Veugen, Jasper van der Waa
ARES3
2023 Data Security on the Ground: Investigating Technical and Legal Requirements under the GDPR
abstract
The GDPR has been in force since 2018, but there is still uncertainty about how to comply with several of its provisions, including Article 32 which sets forth the requirements for data security. While scholars in this field have previously analysed the law or the industry standards, we use the fines imposed so far for violation of Article 32 as our primary data. We annotate and analyse technical and legal aspects of a representative subset of cases. Using clustering, four groups of cases with distinct characteristics emerge from our research. Three of the four groups of cases suffer from data incidents, but for different reasons: a targeted attack, non-technical human mistakes, or a combination of mistakes. The final group includes cases where no actual data incident happened, but fines were still imposed due to insufficient organisational measures and high risk or imminent harm to the data subjects. We uncover from the cases different measures that apply to each of the groups, ranging from compliance with the highest industry standards to organisational measures and enhanced internal privacy awareness.
Tina Marjanov, Maria Konstantinou, Magdalena Józwiak, Dayana Spagnuelo
Proc. Priv. Enhancing Technol.4
2021 Property Inference Attacks on Convolutional Neural Networks: Influence and Implications of Target Model's Complexity
abstract
Copyright © 2021 by SCITEPRESS – Science and Technology Publications, Lda. All rights reservedMachine learning models’ goal is to make correct predictions for specific tasks by learning important properties and patterns from data. By doing so, there is a chance that the model learns properties that are unrelated to its primary task. Property Inference Attacks exploit this and aim to infer from a given model (i.e., the target model) properties about the training dataset seemingly unrelated to the model’s primary goal. If the training data is sensitive, such an attack could lead to privacy leakage. In this paper, we investigate the influence of the target model’s complexity on the accuracy of this type of attack, focusing on convolutional neural network classifiers. We perform attacks on models that are trained on facial images to predict whether someone’s mouth is open. Our attacks’ goal is to infer whether the training dataset is balanced gender-wise. Our findings reveal that the risk of a privacy breach is present independently of the target model’s complexity: for all studied architectures, the attack’s accuracy is clearly over the baseline.
Mathias P. M. Parisot, Balazs Pejo, Dayana Spagnuelo
SECRYPT3
2020 Iconified Representations of Privacy Policies: A GDPR Perspective
Sander de Jong, Dayana Spagnuelo
WorldCIST (2)2
2020 Qualifying and measuring transparency: A medical data system case study
Dayana Spagnuelo, Cesare Bartolini, Gabriele Lenzini
Comput. Secur.1
2019 Accomplishing Transparency within the General Data Protection Regulation
abstract
Transparency is a user-centric principle proposed to empower users to hold data processors accountable for the usage and the processing of the user’s personal data. Accomplishing transparency may come with some resistance because it requires significant architectural changes, but it is mandatory by law under the recently approved General Data Protection Regulation. To help the transition, we systematically review what Transparency Enhancing Technologies can help to accomplish transparency in agreement with technical requirements that we elicited from the Regulation’s articles. We discuss our findings in the domain of medical data systems, where accomplishing transparency looks particularly controversial due to sensitivity of the personal medical data.
Dayana Spagnuelo, Ana Ferreira 0001, Gabriele Lenzini
ICISSP1
2017 Modelling Metrics for Transparency in Medical Systems
Dayana Spagnuelo, Cesare Bartolini, Gabriele Lenzini
TrustBus1
2016 Patient-Centred Transparency Requirements for Medical Data Sharing Systems
Dayana Spagnuelo, Gabriele Lenzini
WorldCIST (1)1