Reference. Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming

Informed consent has become increasingly salient for data privacy and its regulation. Entities from governments to for-profit companies have addressed concerns about data privacy with policies that enumerate the conditions for personal data storage and transfer. However, increased enumeration of and transparency in data privacy policies has not improved end-users’ comprehension of how their data might be used: not only are privacy policies written in legal language that users may struggle to understand, but elements of these policies may compose in such a way that the consequences of the policy are not immediately apparent. We present a framework that uses Answer Set Programming (ASP) – a type of logic programming – to formalize privacy policies. Privacy policies thus become constraints on a narrative planning space, allowing end-users to forward-simulate possible consequences of the policy in terms of actors having roles and taking actions in a domain. We demonstrate through the example of the Health Insurance Portability and Accountability Act (HIPAA) how to use the system in various ways, including asking questions about possibilities and identifying which clauses of the law are broken by a given sequence of events.

Cite

Cite as @dabral-2022-exploring (helia, typst) · \cite{dabral-2022-exploring} (LaTeX)
BibTeX
bibtex · 8 lines
@misc{dabral-2022-exploring,
  author = {Chinmaya Dabral and Emma Tosch and Chris Martens},
  title = {Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming},
  year = {2022},
  month = {12},
  eprint = {2212.06719},
  archiveprefix = {arXiv}
}
hayagriva YAML (typst)
yaml · 10 lines
dabral-2022-exploring:
  type: misc
  title: Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming
  author:
  - Dabral, Chinmaya
  - Tosch, Emma
  - Martens, Chris
  date: 2022-12
  serial-number:
    arxiv: '2212.06719'
Cited by (2)

Finite-Choice Logic Programming martens-2025-finite

Logic programming, as exemplified by datalog, defines the meaning of a program as its unique smallest model: the deductive closure of its inference rules. However, many problems call for an enumeration of models that vary along some set of choices while maintaining structural and logical constraints—there is no single canonical model. The notion of stable models for logic programs with negation has successfully captured programmer intuition about the set of valid solutions for such problems, giving rise to a family of programming languages and associated solvers known as answer set programming. Unfortunately, the definition of a stable model is frustratingly indirect, especially in the presence of rules containing free variables. We propose a new formalism, finite-choice logic programming, that uses choice, not negation, to admit multiple solutions. Finite-choice logic programming contains all the expressive power of the stable model semantics, gives meaning to a new and useful class of programs, and enjoys a least-fixed-point interpretation over a novel domain. We present an algorithm for exploring the solution space and prove it correct with respect to our semantics. Our implementation, the Dusa logic programming language, has performance that compares favorably with state-of-the-art answer set solvers and exhibits more predictable scaling with problem size.
PDF · DOI · arXiv · pldb

Privacy Policies on the Fediverse: A Case Study of Mastodon Instances tosch-2024-privacy

Free and open source social platform software has dramatically lowered the barrier to entry for anyone to set up and administer their own social network. This new population of social network administrators thus assume data management responsibilities for sociotechnical systems. Administrators have the power to customize this software, including data collection and data retention, potentially leading to radically different privacy policies. To better understand the characteristics — e.g., the variability, prohibitions, and permissions — of privacy policies on these new social networking platforms, we have conducted a case study of Mastodon. We performed a text analysis of 351 privacy policies and a survey of 104 Mastodon administrators. While most administrators used the default policy that ships with the Mastodon software, we observed that approximately ten percent of our sample tailored their privacy policies to their instances and that some administrators conflated codes of conduct with privacy policies. Our findings suggest the existing market-based individualistic frameworks for thinking about privacy policies do not adequately address this emerging community.
DOI
dabral-2022-exploring reference entries/refs/dabral-2022-exploring/dabral-2022-exploring.hel