Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks
Hao-Ping (Hank) Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, Sauvik Das
Abstract
Fig. 1. We identify 12 privacy risks that the unique capabilities and/or requirements of AI can entail. For example, the capabilities of AI create new risks (purple) of identification, distortion, physiognomy, and unwanted disclosure; the data requirements of AI can exacerbate risks (light blue) of surveillance, exclusion, secondary use, and data breaches owing to insecurity.
Privacy is a key principle for developing ethical AI technologies, but how does including AI technologies in products and services change privacy risks? We constructed a taxonomy of AI privacy risks by analyzing 321 documented AI privacy incidents. We codified how the unique capabilities and requirements of AI technologies described in those incidents generated new privacy risks, exacerbated known ones, or otherwise did not meaningfully alter the risk. We present 12 high-level privacy risks that AI technologies either newly created (e.g., exposure risks from deepfake pornography) or exacerbated (e.g., surveillance risks from collecting training data). One upshot of our work is that incorporating AI technologies into a product can alter the privacy risks it entails. Yet, current approaches to privacy-preserving AI/ML (e.g., federated learning, differential privacy, checklists) only address a subset of the privacy risks arising from the capabilities and data requirements of AI.
CCS Concepts: • Security and privacy → Human and societal aspects of security and privacy; • Human-centered computing → Human computer interaction (HCI).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b092b65-0f67-4906-aa92-174de4d5ad99Cited by top-tier papers25
- The Dark Side of AI Companionship: A Taxonomy of Harmful Algorithmic Behaviors in Human-AI RelationshipsRenwen Zhang, Han Li, Han Meng, Jinyuan Zhan et al.CHI 2025 · 122 citations
- Privacy Perceptions of Custom GPTs by Users and CreatorsRongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist et al.CHI 2025 · 35 citations
- Sensible and Sensitive AI for Worker Wellbeing: Factors that Inform Adoption and Resistance for Information WorkersVedant Das Swain, Lan Gao, Abhirup Mondal, Gregory D. Abowd et al.CHI 2024 · 22 citations
- Understanding Adolescents' Perceptions of Benefits and Risks in Health AI Technologies through Design FictionJamie Lee, Kyuha Jung, Erin Gregg Newman, Emilie Chow et al.CHI 2025 · 17 citations
- Designing for Harm Reduction: Communication Repair for Multicultural Users' Voice InteractionsKimi Wenzel, Geoff KaufmanCHI 2024 · 17 citations
Builds on11
- Machine Learning with Membership Privacy using Adversarial RegularizationMilad Nasr, Reza Shokri, Amir HoumansadrCCS 2018 · 543 citations
- Learning temporal coherence via self-supervision for GAN-based video generationMengyu Chu, You Xie, Jonas Mayer, Laura Leal-Taixé et al.SIGGRAPH 2020 · 198 citations
- Seeing Like a Toolkit: How Toolkits Envision the Work of AI EthicsRichmond Y. Wong, Michael A. Madaio, Nick MerrillCSCW 2023 · 108 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
- Understanding Frontline Workers' and Unhoused Individuals' Perspectives on AI Used in Homeless ServicesTzu-Sheng Kuo, Hong Shen, Jisoo Geum, Nev Jones et al.CHI 2023 · 82 citations
Related papers
- "I Don't Know If We're Doing Good. I Don't Know If We're Doing Bad": Investigating How Practitioners Scope, Motivate, and Conduct Privacy Work When Developing AI ProductsHao-Ping (Hank) Lee, Lan Gao, Stephanie S. Yang, Jodi Forlizzi et al.USENIX Security 2024 · 14 citations
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 1 citation
- What's Privacy Good for? Measuring Privacy as a Shield from Harms due to AI Inference of Personal DataSri Harsha Gajavalli, Junichi Koizumi, Rakibul HasanCHI 2026 · 2 citations
- Privacy in Human-AI Romantic Relationships: Concerns, Boundaries, and AgencyRongjun Ma, Shijing He, Jose Luis Martin-Navarro, Xiao Zhan et al.CHI 2026 · 5 citations
- Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product ConceptsHao-Ping (Hank) Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek et al.CHI 2026 · 1 citation
