Goto

Collaborating Authors

 Law


Ontological Semantics for Data Privacy Compliance: The NEURONA Project

AAAI Conferences

Some of the top legal ontologies developed so far include the Functional Ontology for Law [FOLaw] The increasing need for legal information and content (Valente 1995), the Frame-Based Ontology (van Kralingen management caused by the growing amount of 1995), the LRI-Core ontology (Breuker 2004), unstructured (or poorly structured) legal data managed by DOLCE CLO [Core Legal Ontology] (Gangemi et al. legal publishing companies, law firms and public 2003), or the Ontology of Fundamental Concepts (Rubino administrations, or the increasing amount of legal et al. 2006, Sartor 2006) the basis for the LKIF-Core information directly available on the World Wide Web, Ontology (Breuker et al. 2007). Nevertheless, most legal have created an urgent need to construct conceptual ontologies are domain specific ontologies, which represent structures for knowledge representation to share and particular legal domains towards search, indexing and manage intelligently all this information, whilst making reasoning in a specific domain of national or European law human-machine communication and understanding (e.g. the IPRONTO ontology by Delgado et al. 2003, the possible.


Preprocessing Legal Text: Policy Parsing and Isomorphic Intermediate Representation

AAAI Conferences

One of the most significant challenges in achieving digital privacy is incorporating privacy policy directly in computer systems. While rule systems have long existed, translating privacy laws, regulations, policies, and contracts into processor amenable forms is slow and difficult because the legal text is scattered, run-on, and unstructured, antithetical to the lean and logical forms of computer science. We are using and developing intermediate isomorphic forms as a Rosetta Stone-like tool to accelerate the translation process and in hopes of providing support to future domain-specific Natural Language Processing technology. This report describes our experience, thoughts about how to improve the form, and discoveries about the form and logic of the legal text that will affect the successful development of a rules tool to implement real-world complex privacy policies.


Reasoning about the Appropriate Use of Private Data through Computational Workflows

AAAI Conferences

While there is a plethora of mechanisms to ensure lawful access to privacy-protected data, additional research is required in order to reassure individuals that their personal data is being used for the purpose that they consented to. This is particularly important in the context of new data mining approaches, as used, for instance, in biomedical research and commercial data mining. We argue for the use of computational workflows to ensure and enforce appropriate use of sensitive personal data. Computational workflows describe in a declarative manner the data processing steps and the expected results of complex data analysis processes such as data mining (Gil et al. 2007b; Taylor et al. 2006). We see workflows as an artifact that captures, among other things, how data is being used and for what purpose. Existing frameworks for computational workflows need to be extended to incorporate privacy policies that can govern the use of data.


Combining Privacy and Security Risk Assessment in Security Quality Requirements Engineering

AAAI Conferences

Functional or end user requirements are the tasks that the system - Protection and control of consolidated data under development is expected to perform. However, nonfunctional - Data retrieval requirements are the qualities that the system is - Equitable treatment of users to adhere to. Functional requirements are not as difficult - Data retention and disposal to tackle, as it is easier to test their implementation in the - User monitoring and protection against unauthorized system under development. Security and privacy requirements monitoring are considered nonfunctional requirements, although in many instances they do have functionality. To identify Several laws and regulations provide a set of guidelines privacy risks early in the design process, privacy requirements that can be used to assess privacy risks. For example, engineering is used (Chiasera et al. 2008). However, the Health Insurance Portability and Accountability Act unlike security requirements engineering, little attention is (HIPAA) addresses privacy concerns of health information paid to privacy requirements engineering, thus it is less mature systems by enforcing data exchange standards.


Privacy and Transparency

AAAI Conferences

In this essay I argue that it is logically and practically possible to secure the right to privacy under conditions of increasing social transparency. The argument is predicated on a particular analysis of the right to privacy as the right to the personal space required for the exercise of practical rationality. It also rests on the distinction between the unidirectional transparency required by repressive governments and the increasing omnidirectional transparency that liberal information societies are experiencing today. I claim that a properly administered omnidirectional transparency will not only enhance privacy and autonomy, but can also be a key development in the creation of a society that is more tolerant of harmless diversity and temperate in its punishment of anti-social behaviors.


Personalized Privacy Policies: Challenges for Data Loss Prevention

AAAI Conferences

Given the prevalence of data leaks, organizations appreciate the importance of implementing privacy policies to protect sensitive data. The growing field of Data Loss Prevention (DLP) offers tools to enforce such policies for both data stored within an organization and data being shared outside of an organization (e.g. through email). While the DLP community has given much attention to the problem of enforcing data privacy policies in a comprehensive manner, little has been done to support the development of such policies. We present a small user study demonstrating that developing such policies is also a very challenging problem. In our study, users were asked to evaluate various expressive file names for sensitivity; that it, they were asked to consider how broadly they were willing to share those filenames both inside and outside their place of employment. The study indicates that users interpret their employer’s privacy concerns in differing ways, resulting in complex, personalized privacy policies at the user end. These results suggest that it may be difficult for users to form a coherent organization-level privacy policy and that the results of a DLP-based enforcement of such policies (e.g. quarantined emails) may be confusing for many users in the organization.


A Step Towards Modeling and Destabilizing Human Trafficking Networks Using Machine Learning Methods

AAAI Conferences

Human trafficking is a multi-dimensional problem for which we have incomplete data, limited knowledge of the exploiters, and no understanding of the dynamics of the process. It is a problem that requires a larger, more complete database, understanding of key actors and their interactions in a dynamic environment. These methods exist in the areas of Data Mining, Machine Learning, Network Analysis, and Multi-agent systems. Using these methods, it is possible to create a model which is unique to detecting and preventing human trafficking. These methods can give applicable and successful solutions for different components of the problem of human trafficking. The goal is to build an intelligent system to enable collaboration and analysis, to identify and profile victims, traffickers, buyers, and exploiters, to predict human trafficking patterns, and to disrupt and destabilize human trafficking networks. In this paper, I will outline how some of these methods may be able to help analyze and model the dynamic phenomenon of human trafficking. The purpose is to see whether, using intelligent systems and appropriate collaboration and analysis tools, optimized intervention strategies can be created to profile victims and traffickers as well as impact, dissolve, and disrupt the human trafficking network in such a way that the network is unable to recover.


Selective Privacy in a Web-Based World: Challenges of Representing and Inferring Context

AAAI Conferences

There is a growing awareness and interest in the issues of accountability and transparency in the pursuit of digital privacy. In previous work, we asserted that systems needed to be “policy aware” and able to compute the likely compliance of any digital transaction with the associated privacy policies (law, rule, or contract). This paper focuses on one critical step in respecting privacy in a digital environment, that of understanding the context associated with each digital transaction. For any individual transaction, the pivotal fact may be context information about the data, the party seeking to use it, the specific action to be taken, or the associated rules. We believe that the granularity of semantic web representation is well suited to this challenge and we support this position in the paper.


The Privacy Paradox

AAAI Conferences

The present privacy legislation continue to be drafted on the basis of the Strasburg Convention of 1981. The mere fact that present privacy laws are based on principles drafted 29 years ago, when the web did not exist, shows that privacy legislation need to make a quantum leap to be in line with the realities of to-day’s real life operating environment. If the status quo is kept, the law and its application shall face serious (and sometimes insurmountable) obstacles to its implementation, making compliance costly for private business, at the same time jeopardizing effectiveness of privacy protection for individuals. A new set of rules should be drafted and established, addressing the changed environment of information and communication technology, in order to allow free flow of information at the same time assuring due protection of personal data.


Release ZERO.0.1 of package RefereeToolbox

arXiv.org Artificial Intelligence

RefereeToolbox is a java package implementing combination operators for fusing evidences. It is downloadable from: http://refereefunction.fredericdambreville.com/releases RefereeToolbox is based on an interpretation of the fusion rules by means of Referee Functions. This approach implies a dissociation between the definition of the combination and its actual implementation, which is common to all referee-based combinations. As a result, RefereeToolbox is designed with the aim to be generic and evolutive.