[Paper Review] Ethical Frameworks and Computer Security Trolley Problems: Foundations for Conversations
This paper introduces computer security-themed trolley problems to foster ethical deliberation within the security research community. By applying consequentialist and deontological ethical frameworks to realistic dilemmas—such as disclosing vulnerabilities with no risk of exploitation—it demonstrates how differing moral reasoning leads to divergent conclusions, advocating for structured, framework-informed discussions in research, review, and education.
The computer security research community regularly tackles ethical questions. The field of ethics / moral philosophy has for centuries considered what it means to be "morally good" or at least "morally allowed / acceptable". Among philosophy's contributions are (1) frameworks for evaluating the morality of actions -- including the well-established consequentialist and deontological frameworks -- and (2) scenarios (like trolley problems) featuring moral dilemmas that can facilitate discussion about and intellectual inquiry into different perspectives on moral reasoning and decision-making. In a classic trolley problem, consequentialist and deontological analyses may render different opinions. In this research, we explicitly make and explore connections between moral questions in computer security research and ethics / moral philosophy through the creation and analysis of trolley problem-like computer security-themed moral dilemmas and, in doing so, we seek to contribute to conversations among security researchers about the morality of security research-related decisions. We explicitly do not seek to define what is morally right or wrong, nor do we argue for one framework over another. Indeed, the consequentialist and deontological frameworks that we center, in addition to coming to different conclusions for our scenarios, have significant limitations. Instead, by offering our scenarios and by comparing two different approaches to ethics, we strive to contribute to how the computer security research field considers and converses about ethical questions, especially when there are different perspectives on what is morally right or acceptable.
Motivation & Objective
- To bridge computer security research with moral philosophy by creating ethical dilemmas grounded in real-world security scenarios.
- To address the lack of consensus in ethical decision-making within security research, especially when conflicting principles (e.g., autonomy vs. beneficence) apply.
- To support the computer security community in having more informed, structured conversations about ethics by introducing comparative analysis using consequentialist and deontological frameworks.
- To provide educators with teachable, non-prescriptive ethical scenarios that encourage critical thinking without predetermined right answers.
- To advocate for institutionalizing ethical reflection in research processes, such as requiring multi-framework ethical considerations in submissions—similar to existing security review practices.
Proposed method
- Designing three original trolley problem-style ethical dilemmas (Scenarios A, B, and C) centered on computer security research decisions.
- Applying two major ethical frameworks—consequentialism (e.g., utilitarianism) and deontology (e.g., Kantian ethics)—to each scenario to compare outcomes and reasoning.
- Using simplified, hypothetical scenarios to isolate philosophical and ethical dimensions from real-world complexities, ensuring focus on moral reasoning.
- Validating the dilemmas through iterative discussion and expert feedback to ensure they present genuine moral conflicts with no obvious resolution.
- Creating a companion slide deck and public repository (https://securityethics.cs.washington.edu) to support community use and future scenario development.
- Proposing institutional changes such as requiring an "Ethical Considerations under Multiple Frameworks" section in Internet-Drafts, modeled after existing security review practices.
Experimental results
Research questions
- RQ1How can trolley problem analogies be adapted to reflect real ethical tensions in computer security research?
- RQ2To what extent do consequentialist and deontological ethical frameworks yield different conclusions when applied to security research dilemmas?
- RQ3What role can structured ethical frameworks play in improving decision-making for researchers, reviewers, and educators?
- RQ4How might the computer security community institutionalize multi-framework ethical reflection in research processes and peer review?
- RQ5What design criteria make a scenario effective for fostering ethical deliberation without prescribing a single 'correct' answer?
Key findings
- The three proposed scenarios—featuring a non-patchable medical device vulnerability, a privacy-preserving system with potential misuse, and a data-sharing dilemma—each present genuine moral conflicts with no universally agreed-upon resolution.
- Consequentialist and deontological frameworks often lead to different conclusions in the same scenario, illustrating that ethical reasoning is not monolithic and depends on foundational assumptions.
- The scenarios are effective for pedagogical use because they resist easy answers and encourage discussion of trade-offs between principles like autonomy, beneficence, and non-maleficence.
- The research demonstrates that ethical reasoning in security research benefits from explicit engagement with multiple frameworks, rather than defaulting to a single ethical lens.
- The authors advocate for integrating multi-framework ethical analysis into research workflows, such as requiring a dedicated ethical considerations section in submissions—mirroring existing security review practices.
- The work has already been validated through expert review and classroom use, with a public repository established for ongoing community contribution and scenario development.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.