Norman M. Sadeh

dblp:18/5502 · also Norman Sadeh 0001, Norman Sadeh-Koniecpol · DBLP profile ↗
← Back
102ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0003-4829-5533ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 38 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 24 · 3 first-author · 4 since 2021Security and privacy · 24 · 1 first-author · 11 since 2021Databases, data management, data science and information retrieval · 15 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 9 · 1 since 2021Computer networks · 4Theory of computation · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Sequential Pattern Recognition Attacks against Deployed Topic-Based Mechanisms
Saranya Vijayakumar, Norman M. Sadeh, Matt Fredrikson
ICISSP (2)2
2025 Privacy Settings of Third-Party Libraries in Android Apps: A Study of Facebook SDKs
abstract
Previous studies have demonstrated that privacy issues in mobile apps often stem from the integration of third-party libraries (TPLs). To shed light on factors that contribute to these issues, we investigate the privacy-related configuration choices available to and made by Android app developers who incorporate the Facebook Android SDK and Facebook Audience Network SDK in their apps. We compile these Facebook SDKs' privacy-related settings and their defaults. Employing a multi-method approach that integrates static and dynamic analysis, we analyze more than 6,000 popular apps to determine whether the apps incorporate Facebook SDKs and, if so, whether and how developers modify settings. Finally, we assess how these settings align with the privacy practices that developers disclose in the apps’ privacy labels and policies. We observe widespread inconsistencies between practices and disclosures in popular apps. These inconsistencies often stem from privacy settings, including a substantial number of cases in which apps retain default settings over alternatives that offer greater privacy. We observe fewer possible compliance issues in potentially child-directed apps, but issues persist even in these apps. We discuss remediation strategies that SDK and TPL providers could employ to help developers, particularly developers with fewer resources who rely heavily on SDKs. Our recommendations include aligning default privacy settings with data minimization principles and other conservative practices and making privacy-related SDK information both easier to find and harder to miss.
David Rodríguez Torrado, Joseph A. Calandrino, José M. del Álamo, Norman M. Sadeh
Proc. Priv. Enhancing Technol.4
2024 Creation and Analysis of an International Corpus of Privacy Laws
abstract
The landscape of privacy laws and regulations around the world is complex and ever-changing. National and super-national laws, agreements, decrees, and other government-issued rules form a patchwork that companies must follow to operate internationally. To examine the status and evolution of this patchwork, we introduce the Privacy Law Corpus, of 1,043 privacy laws, regulations, and guidelines, covering 183 jurisdictions. This corpus enables a large-scale quantitative and qualitative examination of legal focus on privacy. We examine the temporal distribution of when privacy laws were created and illustrate the dramatic increase in privacy legislation over the past 50 years, although a finer-grained examination reveals that the rate of increase varies depending on the personal data types that privacy laws address. Our exploration also demonstrates that most privacy laws respectively address relatively few personal data types. Additionally, topic modeling results show the prevalence of common themes in privacy laws, such as finance, healthcare, and telecommunications. Finally, we release the corpus to the research community to promote further study.
Sonu Gupta, Geetika Gopi, Harish Balaji, Ellen Poplavska, Nora O'Toole, Siddhant Arora, Thomas B. Norton, Norman M. Sadeh, Shomir Wilson
LREC/COLING8
2024 "I was Diagnosed with ...": Sensitivity Detection and Rephrasing of Amazon Reviews with ChatGPT
abstract
The proliferation of platforms such as e-commerce and social networks has led to an increasing amount of personal health information being disclosed in user-generated content. This study investigates the use of Large Language Models (LLMs) to detect and sanitize sensitive health data disclosures in reviews posted on Amazon. Specifically, we present an approach that uses ChatGPT to evaluate both the sensitivity and informativeness of Amazon reviews. The approach uses prompt engineering to identify sensitive content and rephrase reviews to reduce sensitive disclosures while maintaining informativeness. Empirical results indicate that ChatGPT is capable of reliably assigning sensitivity scores and informativeness scores to user-generated reviews and can be used to generate sanitized reviews that remain informative.
Costanza Alfieri, Suriya Ganesh Ayyamperumal, Limin Ge, Jingxin Shi, Norman M. Sadeh
PST5
2024 Understanding How to Inform Blind and Low-Vision Users about Data Privacy through Privacy Question Answering Assistants
Yuanyuan Feng, Abhilasha Ravichander, Yaxing Yao, Shikun Zhang, Rex Chen, Shomir Wilson, Norman M. Sadeh
USENIX Security Symposium7
2024 Generating Effective Answers to People's Everyday Cybersecurity Questions: An Initial Study
Ananya Balaji, Lea Duesterwald, Ian Yang, Aman Priyanshu, Costanza Alfieri, Norman M. Sadeh
WISE (5)6
2024 Incorporating Taxonomic Reasoning and Regulatory Knowledge into Automated Privacy Question Answering
Abhilasha Ravichander, Ian Yang, Rex Chen, Shomir Wilson, Thomas B. Norton, Norman M. Sadeh
WISE (1)6
2023 Exploring Smart Commercial Building Occupants' Perceptions and Notification Preferences of Internet of Things Data Collection in the United States
abstract
Data collection through the Internet of Things (IoT) devices, or smart devices, in commercial buildings enables possibilities for increased convenience and energy efficiency. However, such benefits face a large perceptual challenge when being implemented in practice, due to the different ways occupants working in the buildings understand and trust in the data collection. The semi-public, pervasive, and multi-modal nature of data collection in smart buildings points to the need to study occupants’ understanding of data collection and notification preferences. We conduct an online study with 492 participants in the US who report working in smart commercial buildings regarding: 1) awareness and perception of data collection in smart commercial buildings, 2) privacy notification preferences, and 3) potential factors for privacy notification preferences. We find that around half of the participants are not fully aware of the data collection and use practices of IoT even though they notice the presence of IoT devices and sensors. We also discover many misunderstandings around different data practices. The majority of participants want to be notified of data practices in smart buildings, and they prefer push notifications to passive ones such as websites or physical signs. Surprisingly, mobile app notification, despite being a popular channel for smart homes, is the least preferred method for smart commercial buildings.
Tu Le, Alan Wang 0002, Yaxing Yao, Yuanyuan Feng, Arsalan Heydarian, Norman M. Sadeh, Yuan Tian 0001
EuroS&P6
2022 Explain, Edit, and Understand: Rethinking User Study Design for Evaluating Model Explanations
abstract
In attempts to "explain" predictions of machine learning models, researchers have proposed hundreds of techniques for attributing predictions to features that are deemed important. While these attributions are often claimed to hold the potential to improve human "understanding" of the models, surprisingly little work explicitly evaluates progress towards this aspiration. In this paper, we conduct a crowdsourcing study, where participants interact with deception detection models that have been trained to distinguish between genuine and fake hotel reviews. They are challenged both to simulate the model on fresh reviews, and to edit reviews with the goal of lowering the probability of the originally predicted class. Successful manipulations would lead to an adversarial example. During the training (but not the test) phase, input spans are highlighted to communicate salience. Through our evaluation, we observe that for a linear bag-of-words model, participants with access to the feature coefficients during training are able to cause a larger reduction in model confidence in the testing phase when compared to the no-explanation control. For the BERT-based classifier, popular local explanations do not improve their ability to reduce the model confidence over the no-explanation case. Remarkably, when the explanation for the BERT model is given by the (global) attributions of a linear model trained to imitate the BERT model, people can effectively manipulate the model.
Siddhant Arora, Danish Pruthi, Norman M. Sadeh, William W. Cohen, Zachary C. Lipton, Graham Neubig
AAAI3
2022 Why Usability Has Become Privacy's Biggest Challenge and What We Can Do About It
Norman M. Sadeh
ICISSP1
2022 A Tale of Two Regulatory Regimes: Creation and Analysis of a Bilingual Privacy Policy Corpus
abstract
Over the past decade, researchers have started to explore the use of NLP to develop tools aimed at helping the public, vendors, and regulators analyze disclosures made in privacy policies. With the introduction of new privacy regulations, the language of privacy policies is also evolving, and disclosures made by the same organization are not always the same in different languages, especially when used to communicate with users who fall under different jurisdictions. This work explores the use of language technologies to capture and analyze these differences at scale. We introduce an annotation scheme designed to capture the nuances of two new landmark privacy regulations, namely the EU’s GDPR and California’s CCPA/CPRA. We then introduce the first bilingual corpus of mobile app privacy policies consisting of 64 privacy policies in English (292K words) and 91 privacy policies in German (478K words), respectively with manual annotations for 8K and 19K fine-grained data practices. The annotations are used to develop computational methods that can automatically extract “disclosures” from privacy policies. Analysis of a subset of 59 “semi-parallel” policies reveals differences that can be attributed to different regulatory regimes, suggesting that systematic analysis of policies using automated language technologies is indeed a worthwhile endeavor.
Siddhant Arora, Henry Hosseini, Christine Utz, Vinayshekhar Bannihatti Kumar, Tristan Dhellemmes, Abhilasha Ravichander, Peter Story, Jasmine Mangat, Rex Chen, Martin Degeling, Thomas B. Norton, Thomas Hupperich, Shomir Wilson, Norman M. Sadeh
LREC14
2022 Increasing Adoption of Tor Browser Using Informational and Planning Nudges
abstract
Abstract Browsing privacy tools can help people protect their digital privacy. However, tools which provide the strongest protections—such as Tor Browser—have struggled to achieve widespread adoption. This may be due to usability challenges, misconceptions, behavioral biases, or mere lack of awareness. In this study, we test the effectiveness of nudging interventions that encourage the adoption of Tor Browser. First, we test an informational nudge based on protection motivation theory (PMT), designed to raise awareness of Tor Browser and help participants form accurate perceptions of it. Next, we add an action planning implementation intention, designed to help participants identify opportunities for using Tor Browser. Finally, we add a coping planning implementation intention, designed to help participants overcome challenges to using Tor Browser, such as extreme website slowness. We test these nudges in a longitudinal field experiment with 537 participants. We find that our PMT-based intervention increased use of Tor Browser in both the short- and long-term. Our coping planning nudge also increased use of Tor Browser, but only in the week following our intervention. We did not find statistically significant evidence of our action planning nudge increasing use of Tor Browser. Our study contributes to a greater understanding of factors influencing the adoption of Tor Browser, and how nudges might be used to encourage the adoption of Tor Browser and similar privacy enhancing technologies.
Peter Story, Daniel Smullen, Rex Chen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
Proc. Priv. Enhancing Technol.7
2022 How Usable Are iOS App Privacy Labels?
abstract
Standardized privacy labels that succinctly summarize those data practices that people are most commonly concerned about offer the promise of providing users with more effective privacy notices than full-length privacy policies. With their introduction by Apple in iOS 14 and Google’s recent adoption in its Play Store, mobile app privacy labels are for the first time available at scale to users. We report the first indepth interview study with 24 lay iPhone users to investigate their experiences, understanding, and perceptions of Apple’s privacy labels. We uncovered misunderstandings of and dissatisfaction with the iOS privacy labels that hinder their effectiveness, including confusing structure, unfamiliar terms, and disconnection from permission settings and controls. We identify areas where app privacy labels might be improved and propose suggestions to address shortcomings to make them more understandable, usable, and useful.
Shikun Zhang, Yuanyuan Feng, Yaxing Yao, Lorrie Faith Cranor, Norman M. Sadeh
Proc. Priv. Enhancing Technol.5
2021 Breaking Down Walls of Text: How Can NLP Benefit Consumer Privacy?
abstract
Abhilasha Ravichander, Alan W Black, Thomas Norton, Shomir Wilson, Norman Sadeh. Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers). 2021.
Abhilasha Ravichander, Alan W. Black, Thomas B. Norton, Shomir Wilson, Norman M. Sadeh
ACL/IJCNLP (1)5
2021 A Design Space for Privacy Choices: Towards Meaningful Privacy Control in the Internet of Things
abstract
“Notice and choice” is the predominant approach for data privacy protection today. There is considerable user-centered research on providing effective privacy notices but not enough guidance on designing privacy choices. Recent data privacy regulations worldwide established new requirements for privacy choices, but system practitioners struggle to implement legally compliant privacy choices that also provide users meaningful privacy control. We construct a design space for privacy choices based on a user-centered analysis of how people exercise privacy choices in real-world systems. This work contributes a conceptual framework that considers privacy choice as a user-centered process as well as a taxonomy for practitioners to design meaningful privacy choices in their systems. We also present a use case of how we leverage the design space to finalize the design decisions for a real-world privacy choice platform, the Internet of Things (IoT) Assistant, to provide meaningful privacy control in the IoT.
Yuanyuan Feng, Yaxing Yao, Norman M. Sadeh
CHI3
2021 Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link Texts
abstract
Increasingly, icons are being proposed to concisely convey privacy-related information and choices to users. However, complex privacy concepts can be difficult to communicate. We investigate which icons effectively signal the presence of privacy choices. In a series of user studies, we designed and evaluated icons and accompanying textual descriptions (link texts) conveying choice, opting-out, and sale of personal information — the latter an opt-out mandated by the California Consumer Privacy Act (CCPA). We identified icon-link text pairings that conveyed the presence of privacy choices without creating misconceptions, with a blue stylized toggle icon paired with “Privacy Options” performing best. The two CCPA-mandated link texts (“Do Not Sell My Personal Information” and “Do Not Sell My Info”) accurately communicated the presence of do-not-sell opt-outs with most icons. Our results provide insights for the design of privacy choice indicators and highlight the necessity of incorporating user testing into policy making.
Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Joel R. Reidenberg, Norman M. Sadeh, Florian Schaub
CHI7
2021 Managing Potentially Intrusive Practices in the Browser: A User-Centered Perspective
abstract
Abstract Browser users encounter a broad array of potentially intrusive practices: from behavioral profiling, to crypto-mining, fingerprinting, and more. We study people’s perception, awareness, understanding, and preferences to opt out of those practices. We conducted a mixed-methods study that included qualitative (n=186) and quantitative (n=888) surveys covering 8 neutrally presented practices, equally highlighting both their benefits and risks. Consistent with prior research focusing on specific practices and mitigation techniques, we observe that most people are unaware of how to effectively identify or control the practices we surveyed. However, our user-centered approach reveals diverse views about the perceived risks and benefits, and that the majority of our participants wished to both restrict and be explicitly notified about the surveyed practices. Though prior research shows that meaningful controls are rarely available, we found that many participants mistakenly assume opt-out settings are common but just too difficult to find. However, even if they were hypothetically available on every website, our findings suggest that settings which allow practices by default are more burdensome to users than alternatives which are contextualized to website categories instead. Our results argue for settings which can distinguish among website categories where certain practices are seen as permissible, proactively notify users about their presence, and otherwise deny intrusive practices by default. Standardizing these settings in the browser rather than being left to individual websites would have the advantage of providing a uniform interface to support notification, control, and could help mitigate dark patterns. We also discuss the regulatory implications of the findings.
Daniel Smullen, Yaxing Yao, Yuanyuan Feng, Norman M. Sadeh, Arthur Edelstein, Rebecca Weiss
Proc. Priv. Enhancing Technol.4
2021 Awareness, Adoption, and Misconceptions of Web Privacy Tools
abstract
Abstract Privacy and security tools can help users protect themselves online. Unfortunately, people are often unaware of such tools, and have potentially harmful misconceptions about the protections provided by the tools they know about. Effectively encouraging the adoption of privacy tools requires insights into people’s tool awareness and understanding. Towards that end, we conducted a demographically-stratified survey of 500 US participants to measure their use of and perceptions about five web browsing-related tools: private browsing, VPNs, Tor Browser, ad blockers, and antivirus software. We asked about participants’ perceptions of the protections provided by these tools across twelve realistic scenarios. Our thematic analysis of participants’ responses revealed diverse forms of misconceptions. Some types of misconceptions were common across tools and scenarios, while others were associated with particular combinations of tools and scenarios. For example, some participants suggested that the privacy protections offered by private browsing, VPNs, and Tor Browser would also protect them from security threats – a misconception that might expose them to preventable risks. We anticipate that our findings will help researchers, tool designers, and privacy advocates educate the public about privacy- and security-enhancing technologies.
Peter Story, Daniel Smullen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
Proc. Priv. Enhancing Technol.6
2021 "Did you know this camera tracks your mood?": Understanding Privacy Expectations and Preferences in the Age of Video Analytics
abstract
Abstract Cameras are everywhere, and are increasingly coupled with video analytics software that can identify our face, track our mood, recognize what we are doing, and more. We present the results of a 10-day in-situ study designed to understand how people feel about these capabilities, looking both at the extent to which they expect to encounter them as part of their everyday activities and at how comfortable they are with the presence of such technologies across a range of realistic scenarios. Results indicate that while some widespread deployments are expected by many (e.g., surveillance in public spaces), others are not, with some making people feel particularly uncomfortable. Our results further show that individuals’ privacy preferences and expectations are complicated and vary with a number of factors such as the purpose for which footage is captured and analyzed, the particular venue where it is captured, and whom it is shared with. Finally, we discuss the implications of people’s rich and diverse preferences on opt-in or opt-out rights for the collection and use (including sharing) of data associated with these video analytics scenarios as mandated by regulations. Because of the user burden associated with the large number of privacy decisions people could be faced with, we discuss how new types of privacy assistants could possibly be configured to help people manage these decisions.
Shikun Zhang, Yuanyuan Feng, Lujo Bauer, Lorrie Faith Cranor, Anupam Das 0001, Norman M. Sadeh
Proc. Priv. Enhancing Technol.6
2020 Informing the Design of a Personalized Privacy Assistant for the Internet of Things
abstract
Internet of Things (IoT) devices create new ways through which personal data is collected and processed by service providers. Frequently, end users have little awareness of, and even less control over, these devices' data collection. IoT Personalized Privacy Assistants (PPAs) can help overcome this issue by helping users discover and, when available, control the data collection practices of nearby IoT resources. We use semi-structured interviews with 17 participants to explore user perceptions of three increasingly more autonomous potential implementations of PPAs, identifying benefits and issues associated with each implementation. We find that participants weigh the desire for control against the fear of cognitive overload. We recommend solutions that address users' differing automation preferences and reduce notification overload. We discuss open issues related to opting out from public data collections, automated consent, the phenomenon of user resignation, and designing PPAs with at-risk communities in mind.
Jessica Colnago, Yuanyuan Feng, Tharangini Palanivel, Sarah Pearman, Megan Ung, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh
CHI8
2020 "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion Choices
abstract
We conducted an in-lab user study with 24 participants to explore the usefulness and usability of privacy choices offered by websites. Participants were asked to find and use choices related to email marketing, targeted advertising, or data deletion on a set of nine websites that differed in terms of where and how these choices were presented. They struggled with several aspects of the interaction, such as selecting the correct page from a site's navigation menu and understanding what information to include in written opt-out requests. Participants found mechanisms located in account settings pages easier to use than options contained in privacy policies, but many still consulted help pages or sent email to request assistance. Our findings indicate that, despite their prevalence, privacy choices like those examined in this study are difficult for consumers to exercise in practice. We provide design and policy recommendations for making these website opt-out and deletion choices more useful and usable for consumers.
Hana Habib, Sarah Pearman, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
CHI7
2020 From Prescription to Description: Mapping the GDPR to a Privacy Policy Corpus Annotation Scheme
abstract
The European Union’s General Data Protection Regulation (GDPR) has compelled businesses and other organizations to update their privacy policies to state specific information about their data practices. Simultaneously, researchers in natural language processing (NLP) have developed corpora and annotation schemes for extracting salient information from privacy policies, often independently of specific laws. To connect existing NLP research on privacy policies with the GDPR, we introduce a mapping from GDPR provisions to the OPP-115 annotation scheme, which serves as the basis for a growing number of projects to automatically classify privacy policy text. We show that assumptions made in the annotation scheme about the essential topics for a privacy policy reflect many of the same topics that the GDPR requires in these documents. This suggests that OPP-115 continues to be representative of the anatomy of a legally compliant privacy policy, and that the legal assumptions behind it represent the elements of data processing that ought to be disclosed within a policy for transparency. The correspondences we show between OPP-115 and the GDPR suggest the feasibility of bridging existing computational and legal research on privacy policies, benefiting both areas.
Ellen Poplavska, Thomas B. Norton, Shomir Wilson, Norman M. Sadeh
JURIX4
2020 Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy Text
abstract
Website privacy policies sometimes provide users the option to opt-out of certain collections and uses of their personal data. Unfortunately, many privacy policies bury these instructions deep in their text, and few web users have the time or skill necessary to discover them. We describe a method for the automated detection of opt-out choices in privacy policy text and their presentation to users through a web browser extension. We describe the creation of two corpora of opt-out choices, which enable the training of classifiers to identify opt-outs in privacy policies. Our overall approach for extracting and classifying opt-out choices combines heuristics to identify commonly found opt-out hyperlinks with supervised machine learning to automatically identify less conspicuous instances. Our approach achieves a precision of 0.93 and a recall of 0.9. We introduce Opt-Out Easy, a web browser extension designed to present available opt-out choices to users as they browse the web. We evaluate the usability of our browser extension with a user study. We also present results of a large-scale analysis of opt-outs found in the text of thousands of the most popular websites.
Vinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng, Hana Habib, Peter Story, Sushain Cherivirala, Margaret Hagan, Lorrie Faith Cranor, Shomir Wilson, Florian Schaub, Norman M. Sadeh
WWW12
2020 The Best of Both Worlds: Mitigating Trade-offs Between Accuracy and User Burden in Capturing Mobile App Privacy Preferences
abstract
Abstract In today’s data-centric economy, data flows are increasingly diverse and complex. This is best exemplified by mobile apps, which are given access to an increasing number of sensitive APIs. Mobile operating systems have attempted to balance the introduction of sensitive APIs with a growing collection of permission settings, which users can grant or deny. The challenge is that the number of settings has become unmanageable. Yet research also shows that existing settings continue to fall short when it comes to accurately capturing people’s privacy preferences. An example is the inability to control mobile app permissions based on the purpose for which an app is requesting access to sensitive data. In short, while users are already overwhelmed, accurately capturing their privacy preferences would require the introduction of an even greater number of settings. A promising approach to mitigating this trade-off lies in using machine learning to generate setting recommendations or bundle some settings. This article is the first of its kind to offer a quantitative assessment of how machine learning can help mitigate this trade-off, focusing on mobile app permissions. Results suggest that it is indeed possible to more accurately capture people’s privacy preferences while also reducing user burden.
Daniel Smullen, Yuanyuan Feng, Shikun Zhang, Norman M. Sadeh
Proc. Priv. Enhancing Technol.4
2019 Question Answering for Privacy Policies: Combining Computational and Legal Perspectives
abstract
Abhilasha Ravichander, Alan W Black, Shomir Wilson, Thomas Norton, Norman Sadeh. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). 2019.
Abhilasha Ravichander, Alan W. Black, Shomir Wilson, Thomas B. Norton, Norman M. Sadeh
EMNLP/IJCNLP (1)5
2019 MAPS: Scaling Privacy Compliance Analysis to a Million Apps
abstract
Abstract The app economy is largely reliant on data collection as its primary revenue model. To comply with legal requirements, app developers are often obligated to notify users of their privacy practices in privacy policies. However, prior research has suggested that many developers are not accurately disclosing their apps’ privacy practices. Evaluating discrepancies between apps’ code and privacy policies enables the identification of potential compliance issues. In this study, we introduce the Mobile App Privacy System (MAPS) for conducting an extensive privacy census of Android apps. We designed a pipeline for retrieving and analyzing large app populations based on code analysis and machine learning techniques. In its first application, we conduct a privacy evaluation for a set of 1,035,853 Android apps from the Google Play Store. We find broad evidence of potential non-compliance. Many apps do not have a privacy policy to begin with. Policies that do exist are often silent on the practices performed by apps. For example, 12.1% of apps have at least one location-related potential compliance issue. We hope that our extensive analysis will motivate app stores, government regulators, and app developers to more effectively review apps for potential compliance issues.
Sebastian Zimmeck, Peter Story, Daniel Smullen, Abhilasha Ravichander, Ziqi Wang 0007, Joel R. Reidenberg, N. Cameron Russell, Norman M. Sadeh
Proc. Priv. Enhancing Technol.8
2019 Analyzing Privacy Policies at Scale: From Crowdsourcing to Automated Annotations
abstract
Website privacy policies are often long and difficult to understand. While research shows that Internet users care about their privacy, they do not have the time to understand the policies of every website they visit, and most users hardly ever read privacy policies. Some recent efforts have aimed to use a combination of crowdsourcing, machine learning, and natural language processing to interpret privacy policies at scale, thus producing annotations for use in interfaces that inform Internet users of salient policy details. However, little attention has been devoted to studying the accuracy of crowdsourced privacy policy annotations, how crowdworker productivity can be enhanced for such a task, and the levels of granularity that are feasible for automatic analysis of privacy policies. In this article, we present a trajectory of work addressing each of these topics. We include analyses of crowdworker performance, evaluation of a method to make a privacy-policy oriented task easier for crowdworkers, a coarse-grained approach to labeling segments of policy text with descriptive themes, and a fine-grained approach to identifying user choices described in policy text. Together, the results from these efforts show the effectiveness of using automated and semi-automated methods for extracting from privacy policies the data practice details that are salient to Internet users’ interests.
Shomir Wilson, Florian Schaub, Frederick Liu, Kanthashree Mysore Sathyendra, Daniel Smullen, Sebastian Zimmeck, Rohan Ramanath, Peter Story, Fei Liu 0004, Norman M. Sadeh, Noah A. Smith
ACM Trans. Web10
2018 Stress Test Evaluation for Natural Language Inference
abstract
Natural language inference (NLI) is the task of determining if a natural language hypothesis can be inferred from a given premise in a justifiable manner. NLI was proposed as a benchmark task for natural language understanding. Existing models perform well at standard datasets for NLI, achieving impressive results across different genres of text. However, the extent to which these models understand the semantic content of sentences is unclear. In this work, we propose an evaluation methodology consisting of automatically constructed “stress tests” that allow us to examine whether systems have the ability to make real inferential decisions. Our evaluation of six sentence-encoder models on these stress tests reveals strengths and weaknesses of these models with respect to challenging linguistic phenomena, and suggests important directions for future work in this area.
Aakanksha Naik, Abhilasha Ravichander, Norman M. Sadeh, Carolyn P. Rosé, Graham Neubig
COLING3
2018 Supervised and Unsupervised Methods for Robust Separation of Section Titles and Prose Text in Web Documents
abstract
The text in many web documents is organized into a hierarchy of section titles and corresponding prose content, a structure which provides potentially exploitable information on discourse structure and topicality.However, this organization is generally discarded during text collection, and collecting it is not straightforward: the same visual organization can be implemented in a myriad of different ways in the underlying HTML.To remedy this, we present a flexible system for automatically extracting the hierarchical section titles and prose organization of web documents irrespective of differences in HTML representation.This system uses features from syntax, semantics, discourse and markup to build two models which classify HTML text into section titles and prose text.When tested on three different domains of web text, our domainindependent system achieves an overall precision of 0.82 and a recall of 0.98.The domaindependent variation produces very high precision (0.99) at the expense of recall (0.75).These results exhibit a robust level of accuracy suitable for enhancing question answering, information extraction, and summarization. 1
Abhijith Athreya Mysore Gopinath, Shomir Wilson, Norman M. Sadeh
EMNLP3
2018 Enabling Live Video Analytics with a Scalable and Privacy-Aware Framework
abstract
We show how to build the components of a privacy-aware, live video analytics ecosystem from the bottom up, starting with OpenFace, our new open-source face recognition system that approaches state-of-the-art accuracy. Integrating OpenFace with interframe tracking, we build RTFace, a mechanism for denaturing video streams that selectively blurs faces according to specified policies at full frame rates. This enables privacy management for live video analytics while providing a secure approach for handling retrospective policy exceptions. Finally, we present a scalable, privacy-aware architecture for large camera networks using RTFace and show how it can be an enabler for a vibrant ecosystem and marketplace of privacy-aware video streams and analytics services.
Brandon Amos, Anupam Das 0001, Padmanabhan Pillai, Norman M. Sadeh, Mahadev Satyanarayanan
ACM Trans. Multim. Comput. Commun. Appl.5
2017 Identifying the Provision of Choices in Privacy Policy Text
abstract
Websites' and mobile apps' privacy policies, written in natural language, tend to be long and difficult to understand. Information privacy revolves around the fundamental principle of Notice and choice, namely the idea that users should be able to make informed decisions about what information about them can be collected and how it can be used. Internet users want control over their privacy, but their choices are often hidden in long and convoluted privacy policy texts. Moreover, little (if any) prior work has been done to detect the provision of choices in text. We address this challenge of enabling user choice by automatically identifying and extracting pertinent choice language in privacy policies. In particular, we present a two-stage architecture of classification models to identify opt-out choices in privacy policy text, labelling common varieties of choices with a mean F1 score of 0.735. Our techniques enable the creation of systems to help Internet users to learn about their choices, thereby effectuating notice and choice and improving Internet privacy.
Kanthashree Mysore Sathyendra, Shomir Wilson, Florian Schaub, Sebastian Zimmeck, Norman M. Sadeh
EMNLP5
2017 A Scalable and Privacy-Aware IoT Service for Live Video Analytics
abstract
We present OpenFace, our new open-source face recognition system that approaches state-of-the-art accuracy. Integrating OpenFace with inter-frame tracking, we build RTFace, a mechanism for denaturing video streams that selectively blurs faces according to specified policies at full frame rates. This enables privacy management for live video analytics while providing a secure approach for handling retrospective policy exceptions. Finally, we present a scalable, privacy-aware architecture for large camera networks using RTFace.
Brandon Amos, Anupam Das 0001, Padmanabhan Pillai, Norman M. Sadeh, Mahadev Satyanarayanan
MMSys5
2017 Automated Analysis of Privacy Requirements for Mobile Apps
Sebastian Zimmeck, Ziqi Wang 0007, Lieyong Zou, Roger Iyengar, Bin Liu 0017, Florian Schaub, Shomir Wilson, Norman M. Sadeh, Steven M. Bellovin, Joel R. Reidenberg
NDSS8
2017 Privacy Expectations and Preferences in an IoT World
Pardis Emami Naeini, Sruti Bhagavatula, Hana Habib, Martin Degeling, Lujo Bauer, Lorrie Faith Cranor, Norman M. Sadeh
SOUPS7
2016 The Creation and Analysis of a Website Privacy Policy Corpus
abstract
Shomir Wilson, Florian Schaub, Aswarth Abhilash Dara, Frederick Liu, Sushain Cherivirala, Pedro Giovanni Leon, Mads Schaarup Andersen, Sebastian Zimmeck, Kanthashree Mysore Sathyendra, N. Cameron Russell, Thomas B. Norton, Eduard Hovy, Joel Reidenberg, Norman Sadeh. Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2016.
Shomir Wilson, Florian Schaub, Aswarth Abhilash Dara, Frederick Liu, Sushain Cherivirala, Pedro Giovanni Leon, Mads Schaarup Andersen, Sebastian Zimmeck, Kanthashree Mysore Sathyendra, N. Cameron Russell, Thomas B. Norton, Eduard H. Hovy, Joel R. Reidenberg, Norman M. Sadeh
ACL (1)14
2016 Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions
Bin Liu 0017, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Zhang, Norman M. Sadeh, Yuvraj Agarwal, Alessandro Acquisti
SOUPS6
2016 How Short Is Too Short? Implications of Length and Framing on the Effectiveness of Privacy Notices
Joshua Gluck, Florian Schaub, Amy Friedman, Hana Habib, Norman M. Sadeh, Lorrie Faith Cranor, Yuvraj Agarwal
SOUPS5
2016 Expecting the Unexpected: Understanding Mismatched Privacy Expectations Online
Ashwini Rao, Florian Schaub, Norman M. Sadeh, Alessandro Acquisti, Ruogu Kang
SOUPS3
2016 Crowdsourcing Annotations for Websites' Privacy Policies: Can It Really Work?
abstract
Website privacy policies are often long and difficult to understand. While research shows that Internet users care about their privacy, they do not have time to understand the policies of every website they visit, and most users hardly ever read privacy policies. Several recent efforts aim to crowdsource the interpretation of privacy policies and use the resulting annotations to build more effective user interfaces that provide users with salient policy summaries. However, very little attention has been devoted to studying the accuracy and scalability of crowdsourced privacy policy annotations, the types of questions crowdworkers can effectively answer, and the ways in which their productivity can be enhanced. Prior research indicates that most Internet users often have great difficulty understanding privacy policies, suggesting limits to the effectiveness of crowdsourcing approaches. In this paper, we assess the viability of crowdsourcing privacy policy annotations. Our results suggest that, if carefully deployed, crowdsourcing can indeed result in the generation of non-trivial annotations and can also help identify elements of ambiguity in policies. We further introduce and evaluate a method to improve the annotation process by predicting and highlighting paragraphs relevant to specific data practices.
Shomir Wilson, Florian Schaub, Rohan Ramanath, Norman M. Sadeh, Fei Liu 0004, Noah A. Smith, Frederick Liu
WWW4
2015 Your Location has been Shared 5, 398 Times!: A Field Study on Mobile App Privacy Nudging
abstract
Smartphone users are often unaware of the data collected by apps running on their devices. We report on a study that evaluates the benefits of giving users an app permission manager and sending them nudges intended to raise their awareness of the data collected by their apps. Our study provides both qualitative and quantitative evidence that these approaches are complementary and can each play a significant role in empowering users to more effectively control their privacy. For instance, even after a week with access to the permission manager, participants benefited from nudges showing them how often some of their sensitive data was being accessed by apps, with 95% of participants reassessing their permissions, and 58% of them further restricting some of their permissions. We discuss how participants interacted both with the permission manager and the privacy nudges, analyze the effectiveness of both solutions, and derive some recommendations.
Hazim Almuhimedi, Florian Schaub, Norman M. Sadeh, Idris Adjerid, Alessandro Acquisti, Joshua Gluck, Lorrie Faith Cranor, Yuvraj Agarwal
CHI3
2015 I Would Like To..., I Shouldn't..., I Wish I...: Exploring Behavior-Change Goals for Social Networking Sites
abstract
Despite benefits and uses of social networking sites (SNSs) users are not always satisfied with their behaviors on the sites. These desires for behavior change both provide insight into users' perceptions of how SNSs impact their lives (positively or negatively) and can inform tools for helping users achieve desired behavior changes. We use a 604-participant online survey to explore SNS users' behavior-change goals for Facebook, Instagram, and Twitter. While some participants want to reduce site use, others want to improve their use or increase a range of behaviors. These desired changes differ by SNS, and, for Twitter, by participants' levels of site use. Participants also expect a range of benefits from these goals, including increased time, contact with others, intrinsic benefits, better security/privacy, and improved self presentation. Based on these results we provide insights both into how participants perceive different SNSs, as well as potential designs for behavior-change mechanisms to target SNS behaviors.
Manya Sleeper, Alessandro Acquisti, Lorrie Faith Cranor, Patrick Gage Kelley, Sean A. Munson, Norman M. Sadeh
CSCW6
2015 Toward Abstractive Summarization Using Semantic Representations
abstract
Fei Liu, Jeffrey Flanigan, Sam Thomson, Norman Sadeh, Noah A. Smith. Proceedings of the 2015 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2015.
Fei Liu 0004, Jeffrey Flanigan, Sam Thomson, Norman M. Sadeh, Noah A. Smith
HLT-NAACL4
2014 A field trial of privacy nudges for facebook
abstract
Anecdotal evidence and scholarly research have shown that Internet users may regret some of their online disclosures. To help individuals avoid such regrets, we designed two modifications to the Facebook web interface that nudge users to consider the content and audience of their online disclosures more carefully. We implemented and evaluated these two nudges in a 6-week field trial with 28 Facebook users. We analyzed participants' interactions with the nudges, the content of their posts, and opinions collected through surveys. We found that reminders about the audience of posts can prevent unintended disclosures without major burden; however, introducing a time delay before publishing users' posts can be perceived as both beneficial and annoying. On balance, some participants found the nudges helpful while others found them unnecessary or overly intrusive. We discuss implications and challenges for designing and evaluating systems to assist users with online disclosures.
Yang Wang 0005, Pedro Giovanni Leon, Alessandro Acquisti, Lorrie Faith Cranor, Alain Forget, Norman M. Sadeh
CHI6
2014 Curated city: capturing individual city guides through social curation
abstract
We report on our design of Curated City, a website that lets people build their own personal guide to the city's neighborhoods by chronicling their favorite experiences. Although users make their own personal guides, they are immersed in a social curatorial experience where they are influenced directly and indirectly by the guides of others. We use a 2-week field trial involving 20 residents of Pittsburgh as a technological probe to explore the initial design decisions, and we further refine the design landscape through subject interviews. Based on this study, we identify a set of design recommendations for building scalable social platforms for curating the experiences of the city.
Justin Cranshaw, Kurt Luther, Patrick Gage Kelley, Norman M. Sadeh
CHI4
2014 A Step Towards Usable Privacy Policy: Automatic Alignment of Privacy Statements
Fei Liu 0004, Rohan Ramanath, Norman M. Sadeh, Noah A. Smith
COLING3
2014 Identifying Relevant Text Fragments to Help Crowdsource Privacy Policy Annotations
abstract
In today's age of big data, websites are collecting an increasingly wide variety of information about their users. The texts of websites' privacy policies, which serve as legal agreements between service providers and users, are often long and difficult to understand. Automated analysis of those texts has the potential to help users better understand the implications of agreeing to such policies. In this work, we present a technique that combines machine learning and crowdsourcing to semi-automatically extract key aspects of website privacy policies that is scalable, fast, and cost-effective.
Rohan Ramanath, Florian Schaub, Shomir Wilson, Fei Liu 0004, Norman M. Sadeh, Noah A. Smith
HCOMP5
2014 Crowdsourcing the Extraction of Data Practices from Privacy Policies
abstract
Website and mobile application privacy policies are intended to describe the system’s data practices. However, they are often written in non-standard formats and contain ambiguities that make it difficult for users to read and comprehend these documents. We propose a crowdsourcing approach to extract data practices from privacy policies to provide more concise and useable privacy notices to users and support the analysis of stated data practices. To that end, we designed a hierarchical task workflow for crowdsourcing the extraction of data practices from privacy policies. We discuss our workflow design and report preliminary results.
Florian Schaub, Travis D. Breaux, Norman M. Sadeh
HCOMP3
2014 Modeling Users' Mobile App Privacy Preferences: Restoring Usability in a Sea of Permission Settings
Jialiu Lin, Bin Liu 0017, Norman M. Sadeh, Jason I. Hong
SOUPS3
2014 Reconciling mobile app privacy and usability on smartphones: could user privacy profiles help?
abstract
As they compete for developers, mobile app ecosystems have been exposing a growing number of APIs through their software development kits. Many of these APIs involve accessing sensitive functionality and/or user data and require approval by users. Android for instance allows developers to select from over 130 possible permissions. Expecting users to review and possibly adjust settings related to these permissions has proven unrealistic. In this paper, we report on the results of a study analyzing people's privacy preferences when it comes to granting permissions to different mobile apps. Our results suggest that, while people's mobile app privacy preferences are diverse, a relatively small number of profiles can be identified that offer the promise of significantly simplifying the decisions mobile users have to make. Specifically, our results are based on the analysis of settings of 4.8 million smartphone users of a mobile security and privacy platform. The platform relies on a rooted version of Android where users are allowed to choose between "granting", "denying" or "requesting to be dynamically prompted" when it comes to granting 12 different Android permissions to mobile apps they have downloaded.
Bin Liu 0017, Jialiu Lin, Norman M. Sadeh
WWW3
2013 Privacy as part of the app decision-making process
abstract
Smartphones have unprecedented access to sensitive personal information. While users report having privacy concerns, they may not actively consider privacy while downloading apps from smartphone application marketplaces. Currently, Android users have only the Android permissions display, which appears after they have selected an app to download, to help them understand how applications access their information. We investigate how permissions and privacy could play a more active role in app-selection decisions. We designed a short "Privacy Facts' display, which we tested in a 20-participant lab study and a 366-participant online experiment. We found that by bringing privacy information to the user when they were making the decision and by presenting it in a clearer fashion, we could assist users in choosing applications that request fewer permissions.
Patrick Gage Kelley, Lorrie Faith Cranor, Norman M. Sadeh
CHI3
2013 "i read my Twitter the next morning and was astonished": a conversational perspective on Twitter regrets
abstract
We present the results of an online survey of 1,221 Twitter users, comparing messages individuals regretted either saying during in-person conversations or posting on Twitter. Participants generally reported similar types of regrets in person and on Twitter. In particular, they often regretted messages that were critical of others. However, regretted messages that were cathartic/expressive or revealed too much information were reported at a higher rate for Twitter. Regretted messages on Twitter also reached broader audiences. In addition, we found that participants who posted on Twitter became aware of, and tried to repair, regret more slowly than those reporting in-person regrets. From this comparison of Twitter and in-person regrets, we provide preliminary ideas for tools to help Twitter users avoid and cope with regret.
Manya Sleeper, Justin Cranshaw, Patrick Gage Kelley, Blase Ur, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh
CHI7
2013 Tweets are forever: a large-scale quantitative analysis of deleted tweets
abstract
This paper describes an empirical study of 1.6M deleted tweets collected over a continuous one-week period from a set of 292K Twitter users. We examine several aggregate properties of deleted tweets, including their connections to other tweets (e.g., whether they are replies or retweets), the clients used to produce them, temporal aspects of deletion, and the presence of geotagging information. Some significant differences were discovered between the two collections, namely in the clients used to post them, their conversational aspects, the sentiment vocabulary present in them, and the days of the week they were posted. However, in other dimensions for which analysis was possible, no substantial differences were found. Finally, we discuss some ramifications of this work for understanding Twitter usage and management of one's privacy.
Hazim Almuhimedi, Shomir Wilson, Bin Liu 0017, Norman M. Sadeh, Alessandro Acquisti
CSCW4
2013 Privacy manipulation and acclimation in a location sharing application
abstract
Location sharing is a popular feature of online social networks, but challenges remain in the effective presentation of privacy choices to users, whose location sharing preferences are complex and diverse. One proposed approach for capturing these nuances builds on the observation that key attributes of users' location sharing preferences can be represented by a small number of privacy profiles, which can provide a basis for configuring individual preferences. However, the impact of this approach on how users view their privacy is relatively unknown. We present a study evaluating the impact of this approach on users' location sharing preferences and their satisfaction with the decisions made by their resulting settings. The results suggest that this approach can influence users to share significantly more without a substantial difference in comfort. This further suggests that the provision of profiles for privacy settings must be carefully considered, as they can substantially alter sharing behavior.
Shomir Wilson, Justin Cranshaw, Norman M. Sadeh, Alessandro Acquisti, Lorrie Faith Cranor, Jay Springfield, Sae Young Jeong, Arun Balasubramanian
UbiComp3
2013 Decentralized Preemptive Scheduling Across Heterogeneous Multi-core Grid Resources
Arun Balasubramanian, Alan Sussman, Norman M. Sadeh
JSSPP3
2013 Why people hate your app: making sense of user feedback in a mobile app store
abstract
User review is a crucial component of open mobile app markets such as the Google Play Store. How do we automatically summarize millions of user reviews and make sense out of them? Unfortunately, beyond simple summaries such as histograms of user ratings, there are few analytic tools that can provide insights into user reviews. In this paper, we propose Wiscom, a system that can analyze tens of millions user ratings and comments in mobile app markets at three different levels of detail. Our system is able to (a) discover inconsistencies in reviews; (b) identify reasons why users like or dislike a given app, and provide an interactive, zoomable view of how users' reviews evolve over time; and (c) provide valuable insights into the entire app market, identifying users' major concerns and preferences of different types of apps. Results using our techniques are reported on a 32GB dataset consisting of over 13 million user reviews of 171,493 Android apps in the Google Play Store. We discuss how the techniques presented herein can be deployed to help a mobile app market operator such as Google as well as individual app developers and end-users.
Jialiu Lin, Lei Li 0005, Christos Faloutsos, Jason I. Hong, Norman M. Sadeh
KDD6
2013 A comparative study of location-sharing privacy preferences in the United States and China
Jialiu Lin, Michael Benisch, Norman M. Sadeh, Jianwei Niu 0002, Jason I. Hong, Banghui Lu, Shaohui Guo
Pers. Ubiquitous Comput.3
2012 Expectation and purpose: understanding users' mental models of mobile app privacy through crowdsourcing
abstract
Smartphone security research has produced many useful tools to analyze the privacy-related behaviors of mobile apps. However, these automated tools cannot assess people's perceptions of whether a given action is legitimate, or how that action makes them feel with respect to privacy. For example, automated tools might detect that a blackjack game and a map app both use one's location information, but people would likely view the map's use of that data as more legitimate than the game. Our work introduces a new model for privacy, namely privacy as expectations. We report on the results of using crowdsourcing to capture users' expectations of what sensitive resources mobile apps use. We also report on a new privacy summary interface that prioritizes and highlights places where mobile apps break people's expectations. We conclude with a discussion of implications for employing crowdsourcing as a privacy evaluation technique.
Jialiu Lin, Norman M. Sadeh, Shahriyar Amini, Janne Lindqvist, Jason I. Hong, Joy Zhang
UbiComp2
2012 The Livehoods Project: Utilizing Social Media to Understand the Dynamics of a City
Justin Cranshaw, Raz Schwartz, Jason I. Hong, Norman M. Sadeh
ICWSM4
2011 User-Controllable Learning of Location Privacy Policies With Gaussian Mixture Models
Justin Cranshaw, Jonathan Mugan, Norman M. Sadeh
AAAI3
2011 When are users comfortable sharing locations with advertisers?
abstract
As smartphones and other mobile computing devices have increased in ubiquity, advertisers have begun to realize a more effective way of targeting users and a promising area for revenue growth: location-based advertising. This trend brings to bear new questions about whether or not users will adopt products involving this potentially invasive form of advertising and what sorts of protections they should be given. Our real-world user study of 27 participants echoes earlier findings that users have significant privacy concerns regarding sharing their locations with advertisers. However, we examine these concerns in more detail and find that they are complex (e.g., relating not only to the quantity of ads, but the locations and times at which they are received). With advanced privacy settings, users stated they would feel more comfortable and share more information than with a simple opt-in/opt-out mechanism.
Patrick Gage Kelley, Michael Benisch, Lorrie Faith Cranor, Norman M. Sadeh
CHI4
2011 Who's your best friend?: targeted privacy attacks In location-sharing social networks
abstract
This paper presents a study that aims to answer two important questions related to targeted location-sharing privacy attacks: (1) given a group of users and their social graph, is it possible to predict which among them is likely to reveal most about their whereabouts, and (2) given a user, is it possible to predict which among her friends knows most about her whereabouts. To answer these questions we analyse the privacy policies of users of a real-time location sharing application, in which users actively shared their location with their contacts. The results show that users who are central to their network are more likely to reveal most about their whereabouts. Furthermore, we show that the friend most likely to know the whereabouts of a specific individual is the one with most common contacts and/or greatest number of contacts.
Vassilis Kostakos, Jayant Venkatanathan, Bernardo Reynolds, Norman M. Sadeh, Eran Toch, Siraj Ahmed Shaikh, Simon L. Jones
UbiComp4
2011 An Investigation into Facebook Friend Grouping
Patrick Gage Kelley, Robin Brewer, Yael Mayer, Lorrie Faith Cranor, Norman M. Sadeh
INTERACT (3)5
2011 Improving Users' Consistency When Recalling Location Sharing Preferences
Jayant Venkatanathan, Denzil Ferreira, Michael Benisch, Jialiu Lin, Evangelos Karapanos, Vassilis Kostakos, Norman M. Sadeh, Eran Toch
INTERACT (1)7
2011 Caché: caching location-enhanced content to improve user privacy
abstract
We present the design, implementation, and evaluation of Caché, a system that offers location privacy for certain classes of location-based applications. The core idea in Caché is to periodically pre-fetch potentially useful location-enhanced content well in advance. Applications then retrieve content from a local cache on the mobile device when it is needed. This approach allows an end-user to make use of location-enhanced content while only revealing to third-party content providers a large geographic region rather than a precise location. In this paper, we present an analysis that examines tradeoffs in terms of storage, bandwidth, and freshness of data. We then discuss the design and implementation of an Android service embodying these ideas. Finally, we provide two evaluations of Caché. One measures the performance of our approach with respect to privacy and mobile content availability using real-world mobility traces. The other focuses on our experiences using Caché to enhance user privacy in three open source Android applications.
Shahriyar Amini, Janne Lindqvist, Jason I. Hong, Jialiu Lin, Eran Toch, Norman M. Sadeh
MobiSys6
2011 Predict and spread: An efficient routing algorithm for opportunistic networking
abstract
With their proliferation and increasing capabilities, mobile devices with local wireless interfaces can be organized into opportunistic networks that exploit communication opportunities arising out of the movement of their users. Because the nodes are carried by people, these opportunistic networks can also be viewed as social networks. Unfortunately, existing routing algorithms for opportunistic networks rely on relatively simple mobility models that rarely consider these social network characteristics. In this paper, we propose PreS (Predict and Spread), an efficient routing algorithm for opportunistic networking that employs an adapted Markov chain to model a node's mobility pattern, and capture its social characteristics. A comparison with state-of-the-art algorithms suggests that PreS can yield better performance in terms of delivery ratio and delivery latency, and approaches the performance of the Epidemic algorithm with lower resource consumption.
Jianwei Niu 0002, Jinkai Guo, Qingsong Cai, Norman M. Sadeh, Shaohui Guo
WCNC4
2011 Capturing location-privacy preferences: quantifying accuracy and user-burden tradeoffs
Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh, Lorrie Faith Cranor
Pers. Ubiquitous Comput.3
2010 Bridging the gap between physical location and online social networks
abstract
This paper examines the location traces of 489 users of a location sharing social network for relationships between the users' mobility patterns and structural properties of their underlying social network. We introduce a novel set of location-based features for analyzing the social context of a geographic region, including location entropy, which measures the diversity of unique visitors of a location. Using these features, we provide a model for predicting friendship between two users by analyzing their location trails. Our model achieves significant gains over simpler models based only on direct properties of the co-location histories, such as the number of co-locations. We also show a positive relationship between the entropy of the locations the user visits and the number of social ties that user has in the network. We discuss how the offline mobility of users can have implications for both researchers and designers of online social networks.
Justin Cranshaw, Eran Toch, Jason I. Hong, Aniket Kittur, Norman M. Sadeh
UbiComp5
2010 Modeling people's place naming preferences in location sharing
abstract
Most location sharing applications display people's locations on a map. However, people use a rich variety of terms to refer to their locations, such as "home," "Starbucks," or "the bus stop near my house." Our long-term goal is to create a system that can automatically generate appropriate place names based on real-time context and user preferences. As a first step, we analyze data from a two-week study involving 26 participants in two different cities, focusing on how people refer to places in location sharing. We derive a taxonomy of different place naming methods, and show that factors such as a person's perceived familiarity with a place and the entropy of that place (i.e. the variety of people who visit it) strongly influence the way people refer to it when interacting with others. We also present a machine learning model for predicting how people name places. Using our data, this model is able to predict the place naming method people choose with an average accuracy higher than 85%.
Jialiu Lin, Guang Xiang, Jason I. Hong, Norman M. Sadeh
UbiComp4
2010 Rethinking location sharing: exploring the implications of social-driven vs. purpose-driven location sharing
abstract
The popularity of micro-blogging has made general-purpose information sharing a pervasive phenomenon. This trend is now impacting location sharing applications (LSAs) such that users are sharing their location data with a much wider and more diverse audience. In this paper, we describe this as social-driven sharing, distinguishing it from past examples of what we refer to as purpose-driven location sharing. We explore the differences between these two types of sharing by conducting a comparative two-week study with nine participants. We found significant differences in terms of users' decisions about what location information to share, their privacy concerns, and how privacy-preserving their disclosures were. Based on these results, we provide design implications for future LSAs.
Karen P. Tang, Jialiu Lin, Jason I. Hong, Daniel P. Siewiorek, Norman M. Sadeh
UbiComp5
2010 Empirical models of privacy in location sharing
abstract
The rapid adoption of location tracking and mobile social networking technologies raises significant privacy challenges. Today our understanding of people's location sharing privacy preferences remains very limited, including how these preferences are impacted by the type of location tracking device or the nature of the locations visited. To address this gap, we deployed Locaccino, a mobile location sharing system, in a four week long field study, where we examined the behavior of study participants (n=28) who shared their location with their acquaintances (n=373.) Our results show that users appear more comfortable sharing their presence at locations visited by a large and diverse set of people. Our study also indicates that people who visit a wider number of places tend to also be the subject of a greater number of requests for their locations. Over time these same people tend to also evolve more sophisticated privacy preferences, reflected by an increase in time- and location-based restrictions. We conclude by discussing the implications our findings.
Eran Toch, Justin Cranshaw, Paul Hankes Drielsma, Janice Y. Tsai, Patrick Gage Kelley, James Springfield, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh
UbiComp9
2009 Who's viewed you?: the impact of feedback in a mobile location-sharing application
abstract
Feedback is viewed as an essential element of ubiquitous computing systems in the HCI literature for helping people manage their privacy. However, the success of online social networks and existing commercial systems for mobile location sharing which do not incorporate feedback would seem to call the importance of feedback into question. We investigated this issue in the context of a mobile location sharing system. Specifically, we report on the findings of a field de-ployment of Locyoution, a mobile location sharing system. In our study of 56 users, one group was given feedback in the form of a history of location requests, and a second group was given no feedback at all. Our major contribution has been to show that feedback is an important contributing factor towards improving user comfort levels and allaying privacy concerns. Participants' privacy concerns were reduced after using the mobile location sharing system. Additionally,our study suggests that peer opinion and technical savviness contribute most to whether or not participants thought they would continue to use a mobile location technology.
Janice Y. Tsai, Patrick Gage Kelley, Paul Hankes Drielsma, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh
CHI6
2009 Methodology for Designing Reasonably Expressive Mechanisms with Application to Ad Auctions
Michael Benisch, Norman M. Sadeh, Tuomas Sandholm
IJCAI2
2009 A framework of energy efficient mobile sensing for automatic user state recognition
abstract
Urban sensing, participatory sensing, and user activity recognition can provide rich contextual information for mobile applications such as social networking and location-based services. However, continuously capturing this contextual information on mobile devices consumes huge amount of energy. In this paper, we present a novel design framework for an Energy Efficient Mobile Sensing System (EEMSS). EEMSS uses hierarchical sensor management strategy to recognize user states as well as to detect state transitions. By powering only a minimum set of sensors and using appropriate sensor duty cycles EEMSS significantly improves device battery life. We present the design, implementation, and evaluation of EEMSS that automatically recognizes a set of users' daily activities in real time using sensors on an off-the-shelf high-end smart phone. Evaluation of EEMSS with 10 users over one week shows that our approach increases the device battery life by more than 75% while maintaining both high accuracy and low latency in identifying transitions between end-user activities.
Yi Wang 0035, Jialiu Lin, Murali Annavaram, Quinn Jacobson, Jason I. Hong, Bhaskar Krishnamachari, Norman M. Sadeh
MobiSys7
2009 Capturing Social Networking Privacy Preferences: Can Default Policies Help Alleviate Tradeoffs between Expressiveness and User Burden?
Ramprasad Ravichandran, Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh
Privacy Enhancing Technologies4
2009 The impact of expressiveness on the effectiveness of privacy mechanisms for location-sharing
abstract
No abstract available.
Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh, Tuomas Sandholm, Janice Y. Tsai, Lorrie Faith Cranor, Paul Hankes Drielsma
SOUPS3
2009 Capturing social networking privacy preferences: can default policies help alleviate tradeoffs between expressiveness and user burden?
abstract
No abstract available.
Ramprasad Ravichandran, Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh
SOUPS4
2009 Analyzing use of privacy policy attributes in a location sharing application
abstract
No abstract available.
Eran Toch, Ramprasad Ravichandran, Lorrie Faith Cranor, Paul Hankes Drielsma, Jason I. Hong, Patrick Gage Kelley, Norman M. Sadeh, Janice Y. Tsai
SOUPS7
2009 Who's viewed you?: the impact of feedback in a mobile location-sharing application
abstract
Feedback is viewed as an essential element of ubiquitous computing systems in the HCI literature for helping people manage their privacy. However, the success of online social networks and existing commercial systems for mobile location sharing which do not incorporate feedback would seem to call the importance of feedback into question. We investigated this issue in the context of a mobile location sharing system. Specifically, we report on the findings of a field de-ployment of Locyoution, a mobile location sharing system. In our study of 56 users, one group was given feedback in the form of a history of location requests, and a second group was given no feedback at all. Our major contribution has been to show that feedback is an important contributing factor towards improving user comfort levels and allaying privacy concerns. Participants' privacy concerns were reduced after using the mobile location sharing system. Additionally,our study suggests that peer opinion and technical savviness contribute most to whether or not participants thought they would continue to use a mobile location technology.
Janice Y. Tsai, Patrick Gage Kelley, Paul Hankes Drielsma, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh
SOUPS6
2009 Understanding and capturing people's privacy policies in a mobile social networking application
Norman M. Sadeh, Jason I. Hong, Lorrie Faith Cranor, Ian Fette, Patrick Gage Kelley, Madhu K. Prabaker, Jinghai Rao
Pers. Ubiquitous Comput.1
2009 A meta-control architecture for orchestrating policy enforcement across heterogeneous information sources
Jinghai Rao, Alberto Sardinha, Norman M. Sadeh
J. Web Semant.3
2008 A Theory of Expressiveness in Mechanisms
Michael Benisch, Norman M. Sadeh, Tuomas Sandholm
AAAI2
2007 Publishing ecommerce research- or how to maintain quality and diversity
abstract
As the Web increasingly permeates all aspects of our daily lives, eCommerce research is also expanding to address an ever wider range of research issues. As such the eCommerce research community has grown to encompass methodologies from a diverse mix of disciplines, with activities spanning technology, business, management, policy and human factors. In fact, what often seems to define good eCommerce research is the ability to tie together perspectives from several of these disciplines. The objective of this panel is to provide a broad overview of available publication outlets for eCommerce research, looking at whether and how they accommodate the inherently multidisciplinary nature of this area, and to what extent they help foster the interdisciplinary perspective that often seems so critical to good research in this space. To shed light on these issues and encourage discussion, the panel will bring together a small number of senior ecommerce researchers, who will draw on their experience as both researchers and journal editors. Following statements by each panelist, we will open the floor to the audience for questions and discussion.
Norman M. Sadeh
ICEC1
2007 Learning to detect phishing emails
abstract
Each month, more attacks are launched with the aim of making web users believe that they are communicating with a trusted entity for the purpose of stealing account information, logon credentials, and identity information in general. This attack method, commonly known as "phishing," is most commonly initiated by sending out emails with links to spoofed websites that harvest information. We present a method for detecting these attacks, which in its most general form is an application of machine learning on a feature set designed to highlight user-targeted deception in electronic communication. This method is applicable, with slight modification, to detection of phishing websites, or the emails used to direct victims to these sites. We evaluate this method on a set of approximately 860 such phishing emails, and 6950 non-phishing emails, and correctly identify over 96% of the phishing emails while only mis-classifying on the order of 0.1% of the legitimate emails. We conclude with thoughts on the future for such techniques to specifically identify deception, specifically with respect to the evolutionary nature of the attacks and information available.
Ian Fette, Norman M. Sadeh, Anthony Tomasic
WWW2
2006 Pricing for customers with probabilistic valuations as a continuous knapsack problem
abstract
In this paper, we examine the problem of choosing discriminatory prices for customers with probabilistic valuations and a seller with indistinguishable copies of a good. We show that under certain assumptions this problem can be reduced to the continuous knapsack problem (CKP). We present a new fast ε-optimal algorithm for solving CKP instances with asymmetric concave reward functions. We also show that our algorithm can be extended beyond the CKP setting to handle pricing problems with overlapping goods (e.g.goods with common components or common resource requirements), rather than indistinguishable goods.We provide a framework for learning distributions over customer valuations from historical data that are accurate and compatible with our CKP algorithm, and we validate our techniques with experiments on pricing instances derived from the Trading Agent Competition in Supply Chain Management (TAC SCM). Our results confirm that our algorithm converges to an ε-optimal solution more quickly in practice than an adaptation of a previously proposed greedy heuristic.
Michael Benisch, James Andrews, Norman M. Sadeh
ICEC3
2006 CMieux: adaptive strategies for competitive supply chain trading
abstract
Supply chains are a central element of today's global economy. Existing management practices consist primarily of static interactions between established partners. Global competition, shorter product life cycles and the emergence of Internet-mediated business solutions create an incentive for exploring more dynamic supply chain practices. The Supply Chain Trading Agent Competition (TAC SCM) was designed to explore approaches to dynamic supply chain trading. TAC SCM pits against one another trading agents developed by teams from around the world. Each agent is responsible for running the procurement, planning and bidding operations of a PC assembly company, while competing with others for both customer orders and supplies under varying market conditions. This paper presents Carnegie Mellon University's 2005 TAC SCM entry, the CMieux supply chain trading agent. CMieux implements a novel approach to coordinating supply chain bidding, procurement and planning, with an emphasis on the ability to rapidly adapt to changing market conditions. We present empirical results based on 200 games involving agents entered by 25 different teams during what can be seen as the most competitive phase of the 2005 tournament. Not only did CMieux perform among the top five agents, it significantly outperformed these agents in procurement while matching their bidding performance.
Michael Benisch, Alberto Sardinha, James Andrews, Norman M. Sadeh
ICEC4
2006 A Mixed Initiative Approach to Semantic Web Service Discovery and Composition: SAP's Guided Procedures Framework
abstract
A central element of emerging service oriented architectures (SOA) is the ability to develop new applications by composing enterprise functionality encapsulated in the form of services - whether within a given organization or across multiple ones. Semantic service annotations, including annotations of both functional and non-functional attributes, offer the prospect of facilitating this process and of producing higher quality solutions. A significant body of work in this area has aimed to fully automate this process, while assuming that all services already have rich and accurate annotations. In this article, we argue that this assumption is often unrealistic. Instead, we describe a mixed initiative framework for semantic Web service discovery and composition that aims at flexibly interleaving human decision making and automated functionality in environments where annotations may be incomplete and even inconsistent. An initial version of this framework has been implemented in SAP's guided procedures, a key element of SAP's enterperise service architecture (ESA)
Jinghai Rao, Dimitar Dimitrov 0006, Paul Hofmann, Norman M. Sadeh
ICWS4
2006 A Mixed Initiative Semantic Web Framework for Process Composition
Jinghai Rao, Dimitar Dimitrov 0006, Paul Hofmann, Norman M. Sadeh
ISWC4
2005 Semantic Web Technologies for Context-Aware Museum Tour Guide Applications
abstract
Traditionally, visitors to museums have been left having to choose between finding their way around exhibits on their own or taking a standardized group tour with a guide. In this paper, we describe a context-aware museum tour guide that adjusts its recommendations to the interests and contexts of individual visitors and enables them to selectively share their experience with others. The tour guide is built around an innovative semantic Web framework that minimizes the development and maintenance costs associated with the introduction of new exhibits, new visitor-oriented services and new sources of contextual information. In particular, it features a semantic Web rule reasoning engine that enables visitor-oriented services to identify relevant sources of contextual information and to enforce user-specified privacy preferences about what information they are willing to share with others (e.g. "only members of my group can see my current location", or "only my friends can see how I rate exhibits"). While still in prototype stage, the tour guide's target environment is the National Museum of Natural Science, one of Taiwan's largest museums with over 3 million visitors per year.
Shih-Chun Chou, Wen-Tai Hsieh, Fabien Gandon, Norman M. Sadeh
AINA4
2004 The 2003 Supply Chain Management Trading Agent Competition
abstract
Supply Chain Management deals with the planning and coordination of bidding, production and procurement activities across the multiple organizations involved in the delivery of one or more products. With the emergence of electronic marketplaces, it is only natural to seek automated solutions that are capable of rapidly evaluating a large number of bidding and procurement options. In this paper, we present an integrated model that incorporates supply chain bidding, production and procurement. We discuss its computational complexity as well as the challenges that arise from the inherently stochastic and competitive nature of the resulting environment. A Web-based multi-agent simulation game based on this model was developed and validated in the context of the first Supply Chain Trading Agent Competition (TAC SCM 2003), where a total of 20 teams from around the world competed with one another. We review key agent strategies developed by competing teams and discuss the merits of competition-based research over more traditional research methodologies in this area.
Raghu Arunachalam, Norman M. Sadeh
ICEC2
2004 Applying case-based reasoning and multi-agent intelligent system to context-aware comparative shopping
Oh Byung Kwon, Norman M. Sadeh
Decis. Support Syst.2
2004 Semantic web technologies to reconcile privacy and context awareness
Fabien Gandon, Norman M. Sadeh
J. Web Semant.2
2003 Multi-attribute supply chain negotiation: coordinating reverse auctions subject to finite capacity considerations
abstract
Over the past few years, reverse auctions have attracted a lot of attention in the AI community. They offer the prospect of more efficiently matching suppliers and producers in the face of changing market conditions. Prior research has generally ignored the temporal and finite capacity constraints under which reverse auctioneers typically operate. In this paper, we consider the problem faced by a reverse auctioneer (e.g. a manufacturer) that can procure key components or services from a number of possible suppliers through multi-attribute reverse auctions. Bids submitted by prospective suppliers include a price and a delivery date. The reverse auctioneer has to select a combination of supplier bids that will maximize its overall profit, taking into account its own finite capacity and the prices and delivery dates offered by different suppliers for the same components/services. The auctioneer's profit is determined by the revenue generated by the products it sells, the costs of the components/services it purchases as well as late delivery penalties it incurs if it fails to deliver products/services in time to its own customers. We provide a formal model of this important class of problems, discuss its complexity and introduce rules that can be used to efficiently prune the resulting search space. We also introduce a branch-and-bound algorithm and an efficient heuristic search procedure for this class of problems. Empirical results show that our heuristic procedure typically yields solutions that are within 10 percent of the optimum. They also indicate that taking into account finite capacity considerations can significantly improve the reverse auctioneer's bottom line.
Norman M. Sadeh, Jiong Sun 0001
ICEC1
2003 A Semantic E-Wallet to Reconcile Privacy and Context Awareness
abstract
Increasingly, application developers are looking for ways to provide users with higher levels of personalization that capture different elements of a user’s operating context, such as her location, the task that she is currently engaged in, who her colleagues are, etc. While there are many sources of contextual information, they tend to vary from one user to another and also over time. Different users may rely on different location tracking functionality provided by different cell phone operators; they may use different calendar systems, etc. In this paper, we describe work on a Semantic e-Wallet aimed at supporting automated discovery and access of personal resources, each represented as a Semantic Web Service. A key objective is to provide a Semantic Web environment for open access to a user’s contextual resources, thereby reducing the costs associated with the development and maintenance of context-aware applications. A second objective is, through Semantic Web technologies, to empower users to selectively control who has access to their contextual information and under which conditions. This work has been carried out in the context of myCampus, a context-aware environment aimed at enhancing everyday campus life. Empirical results obtained on Carnegie Mellon’s campus are encouraging. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Fabien Gandon, Norman M. Sadeh
ISWC2
2003 A semantic web environment for context-aware m-commerce
abstract
In this paper, we introduce MyCampus, a Semantic Web environment for context-aware mobile services, which we are in the process of developing and validating on Carnegie Mellon University's campus. The environment revolves around a growing collection of customizable agents capable of (semi-) automatically discovering and accessing user personal resources (e.g. calendar, location tracking functionality, food preferences) and Web services as they assist their users in carrying out different tasks such as planning an evening out, organizing a study group or filtering incoming messages. The openness of the MyCampus architecture directly derives from a set of ontologies for describing personal resources, contextual attributes, user preferences and web services. Contextual information and other personal details about a user are accessed via a Semantic e-Wallet, subject to access privileges set by the user.
Norman M. Sadeh, Ting-Chak Chan, Linh Van, Oh Byung Kwon, Kazuaki Takizawa
EC1
2003 Dynamic supply chain formation: integrating multi-attribute auctions and finite capacity scheduling
abstract
Dynamic supply chain practices offer the prospect of more efficiently matching suppliers and producers in the face of changing market conditions. Prior research aimed at studying dynamic supply chain formation problems has generally ignored constraints imposed by the finite capacity of manufacturers. In this paper, we consider the problem faced by a manufacturer who can procure key components from a number of possible suppliers through multi-attribute reverse auction mechanisms. Bids submitted by prospective suppliers include a price and a delivery date. The manufacturer has to select a combination of supplier bids that will maximize its overall profit, taking into account the revenue generated by each product it has to deliver, the costs of the components it has to procure as well as late delivery penalties (incurred for missing promised delivery dates to its own customers).
Jiong Sun 0001, Norman M. Sadeh
EC2
1996 Variable and Value Ordering Heuristics for the Job Shop Scheduling Constraint Satisfaction Problem
Norman M. Sadeh, Mark S. Fox
Artif. Intell.1
1995 Backtracking Techniques for the Job Shop Scheduling Constraint Satisfaction Problem
Norman M. Sadeh, Katia P. Sycara, Yalin Xiong
Artif. Intell.1
1994 Increasing The Efficiency of Simulated Annealing Search by Learning to Recognize (Un)Promising Runs
Yoichiro Nakakuki, Norman M. Sadeh
AAAI2
1992 Intelligent Backtracking Techniques for Job Shop Scheduling
Yalin Xiong, Norman M. Sadeh, Katia P. Sycara
KR2
1991 Distributed constrained heuristic search
abstract
A model of decentralized problem solving, called distributed constrained heuristic search (DCHS), that provides both structure and focus in individual agent search spaces to optimize decisions in the global space, is presented. The model achieves this by integrating decentralized constraint satisfaction and heuristic search. It is a formalism suitable for describing a large set of distributed artificial intelligence problems. The notion of textures that allow agents to operate in an asynchronous concurrent manner is introduced. The use of textures coupled with distributed asynchronous backjumping, a type of distributed dependency-directed backtracking that the authors have developed, enables agents to instantiate variables in such a way as to substantially reduce backtracking. The approach has been tested experimentally in the domain of decentralized job-shop scheduling. A formulation of distributed job-shop scheduling as a DCHS and experimental results are presented.>
Katia P. Sycara, Steven P. Roth, Norman M. Sadeh, Mark S. Fox
IEEE Trans. Syst. Man Cybern.3
1990 Why is Scheduling Difficult? A CSP Perspective
Mark S. Fox, Norman M. Sadeh
ECAI2
1989 Constrained Heuristic Search
Mark S. Fox, Norman M. Sadeh, Can A. Baykan
IJCAI2