Springe direkt zu Inhalt

Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential Privacy

Franzen, Daniel; Müller-Birn, Claudia; Wegwarth, Odette – 2024

Data collections, such as those from citizen science projects, can provide valuable scientific insights or help the public to make decisions based on real demand. At the same time, the collected data might cause privacy risks for their volunteers, for example, by revealing sensitive information. Similar but less apparent trade-offs exist for data collected while using social media or other internet-based services. One approach to addressing these privacy risks might be to anonymize the data, for example, by using Differential Privacy (DP). DP allows for tuning and, consequently, communicating the trade-off between the data contributors' privacy and the resulting data utility for insights. However, there is little research that explores how to communicate the existing trade-off to users. % We contribute to closing this research gap by designing interactive elements and visualizations that specifically support people's understanding of this privacy-utility trade-off. We evaluated our user interfaces in a user study (N=378). Our results show that a combination of graphical risk visualization and interactive risk exploration best supports the informed decision, \ie the privacy decision is consistent with users' privacy concerns. Additionally, we found that personal attributes, such as numeracy, and the need for cognition, significantly influence the decision behavior and the privacy usability of privacy decision interfaces. In our recommendations, we encourage data collectors, such as citizen science project coordinators, to communicate existing privacy risks to their volunteers since such communication does not impact donation rates. %Understanding such privacy risks can also be part of typical training efforts in citizen science projects. %DP allows volunteers to balance their privacy concerns with their wish to contribute to the project. From a design perspective, we emphasize the complexity of the decision situation and the resulting need to design with usability for all population groups in mind. % We hope that our study will inspire further research from the human-computer interaction community that will unlock the full potential of DP for a broad audience and ultimately contribute to a societal understanding of acceptable privacy losses in specific data contexts.

Title
Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential Privacy
Author
Franzen, Daniel; Müller-Birn, Claudia; Wegwarth, Odette
Publisher
ACM
Location
New York
Date
2024
Identifier
10.1145/3637309
Source(s)
Appeared in
Proceedings of the ACM on Human-Computer Interaction 8, Computer-Supported Cooperative Work and Social Computing 1
Citation
Daniel Franzen, Claudia Müller-Birn, and Odette Wegwarth. 2024. Communicating the Privacy-Utility Trade- off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential Privacy. Proc. ACM Hum.-Comput. Interact. 8, CSCW1, Article 32 (April 2024), 56 pages. https://doi.org/10.1145/3637309
Language
eng
Type
Text
Size or Duration
31 pages
Rights
Creative Commons Attribution-NonCommercial-ShareAlike International 4.0 License
BibTeX Code
@article{10.1145/3637309,
author = {Franzen, Daniel and M\"{u}ller-Birn, Claudia and Wegwarth, Odette},
title = {Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential Privacy},
year = {2024},
issue_date = {April 2024},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
volume = {8},
number = {CSCW1},
url = {https://doi.org/10.1145/3637309},
doi = {10.1145/3637309},
journal = {Proc. ACM Hum.-Comput. Interact.},
month = {apr},
articleno = {32},
numpages = {56},
keywords = {citizen science, differential privacy, informed choice, risk communication}
}