Skip to main content
QUICK REVIEW

[论文解读] "If You Can't Beat them, Join them": A Usability Approach to Interdependent Privacy in Cloud Apps

Hamza Harkous, Karl Aberer|Infoscience (Ecole Polytechnique Fédérale de Lausanne)|Feb 27, 2017
Privacy, Security, and Data Protection参考文献 15被引用 4
一句话总结

本文提出一种以可用性为导向的方法,通过引入“基于历史的决策”——一种隐私指示器,帮助用户了解之前已授权的供应商,从而减轻云应用中相互依赖的隐私风险。在一项用户研究中,该指示器使用户选择低风险应用的可能性提高了40%;模拟结果显示,在无需合作或利他主义的前提下,协作网络中的隐私损失增长最高可减少70%。

ABSTRACT

Cloud storage services, like Dropbox and Google Drive, have growing ecosystems of 3rd party apps that are designed to work with users' cloud files. Such apps often request full access to users' files, including files shared with collaborators. Hence, whenever a user grants access to a new vendor, she is inflicting a privacy loss on herself and on her collaborators too. Based on analyzing a real dataset of 183 Google Drive users and 131 third party apps, we discover that collaborators inflict a privacy loss which is at least 39% higher than what users themselves cause. We take a step toward minimizing this loss by introducing the concept of History-based decisions. Simply put, users are informed at decision time about the vendors which have been previously granted access to their data. Thus, they can reduce their privacy loss by not installing apps from new vendors whenever possible. Next, we realize this concept by introducing a new privacy indicator, which can be integrated within the cloud apps' authorization interface. Via a web experiment with 141 participants recruited from CrowdFlower, we show that our privacy indicator can significantly increase the user's likelihood of choosing the app that minimizes her privacy loss. Finally, we explore the network effect of History-based decisions via a simulation on top of large collaboration networks. We demonstrate that adopting such a decision-making process is capable of reducing the growth of users' privacy loss by 70% in a Google Drive-based network and by 40% in an author collaboration network. This is despite the fact that we neither assume that users cooperate nor that they exhibit altruistic behavior. To our knowledge, our work is the first to provide quantifiable evidence of the privacy risk that collaborators pose in cloud apps. We are also the first to mitigate this problem via a usable privacy approach.

研究动机与目标

  • 量化合作者在云存储生态系统中对用户隐私损失的影响是否超过用户自身应用选择的影响。
  • 探究在授权时刻向用户展示历史授权数据,是否可引导其做出更低隐私风险的决策。
  • 评估基于历史的隐私指示器在降低协作型云环境中累积隐私损失方面的有效性。
  • 模拟大规模协作网络中采用此类可用性干预措施的全局网络影响。
  • 证明一种非强制性、非利他主义的可用性机制可显著减少相互依赖的隐私损害。

提出的方法

  • 分析了183名Google Drive用户和131个第三方应用的真实数据集,以衡量用户及合作者授权应用所导致的隐私损失。
  • 提出“基于历史的决策”——一种在应用授权过程中显示先前已授权供应商的隐私指示器,以帮助用户了解现有访问风险。
  • 在CrowdFlower平台上开展基于网络的用户实验,共141名参与者,评估隐私指示器对决策影响。
  • 在大规模协作图(Google Drive和作者网络)上模拟基于历史的决策的网络效应,以评估可扩展性和影响。
  • 采用博弈论和基于网络的建模方法,量化用户基于历史数据避免新供应商时,隐私损失增长的减少程度。
  • 将隐私指示器集成到授权界面中,以在接近真实世界条件下测试其可用性和有效性。

实验结果

研究问题

  • RQ1在云存储平台中,合作者对用户隐私损失的贡献程度是否显著高于用户自身应用选择?
  • RQ2在应用授权过程中向用户告知之前已授权的供应商,是否可降低其授予新潜在高风险供应商访问权限的可能性?
  • RQ3在协作型云生态系统中,采用基于历史的决策流程对隐私损失累积增长的全局网络影响如何?
  • RQ4当用户仅出于自利动机且不具利他行为时,所提出的可用性干预措施是否仍有效?
  • RQ5该隐私指示器是否可推广至Google Drive以外的其他云和协作生态系统?

主要发现

  • 当合作者授予第三方应用访问权限时,其造成的隐私损失至少比用户自身选择高39%。
  • 基于历史的隐私指示器在受控用户研究中显著提高了用户选择最小化隐私损失应用的可能性。
  • 在模拟的基于Google Drive的协作网络中,采用基于历史的决策使用户隐私损失的增长减少了70%。
  • 在模拟的作者协作网络中,即使不假设用户之间存在合作或利他行为,该方法仍使隐私损失增长减少了40%。
  • 用户往往不会主动考虑历史授权决策,凸显了主动型可用性干预的必要性。
  • 所提出的方法可与现有关注过度授权的隐私指示器互补,并可与其并行部署以进一步降低风险。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。