PrivacyAkinator: Articulating Key Privacy Design Decisions by Answering LLM-Generated Multiple-choice Questions
Qiyu Li, Yuen Sum Wong, Yuen Kei Wong, Longxuan Yu, Haojian Jin
Abstract
NIST’s Privacy Risk Assessment Methodology (PRAM) provides a structured framework for privacy experts to assess privacy risks. However, its complexity and reliance on expert knowledge make it difficult for novice developers to use effectively. This paper explores methods to lower these barriers. We first performed an observational study with 12 participants using PRAM in real-world scenarios, and found that novice developers struggled most with articulating privacy-related design decisions. We then developed PrivacyAkinator, an interactive tool that helps developers articulate key privacy decisions by answering LLM-generated multiple-choice questions. PrivacyAkinator introduces three innovations: a universal privacy representation that abstracts privacy-related design decisions into data flows and stakeholder interactions; a domain-aware design space mined from 10K privacy-related news articles; and a dynamic question-generation workflow to prioritize relevant questions. Our user study with 24 participants suggests that developers using PrivacyAkinator identified 47% more key decisions in 73% less time compared to PRAM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a35d2a45-34de-4ce1-9f19-c4e59b1a66f9Builds on16
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- A Design Space for Privacy Choices: Towards Meaningful Privacy Control in the Internet of ThingsYuanyuan Feng, Yaxing Yao, Norman M. SadehCHI 2021 · 114 citations
- Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy TextVinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng et al.WWW 2020 · 93 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- How Developers Talk About Personal Data and What It Means for User Privacy: A Case Study of a Developer Forum on RedditTianshi Li, Elizabeth Louie, Laura Dabbish, Jason I. HongCSCW 2020 · 64 citations
Related papers
- Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product ConceptsHao-Ping (Hank) Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek et al.CHI 2026 · 1 citation
- Helping Johnny Make Sense of Privacy Policies with LLMsVincent Freiberger, Arthur Fleig, Erik BuchmannCHI 2026 · 3 citations
- Teaching Data Science Students to Sketch Privacy Designs Through HeuristicsJinhe Wen, Yingxi Zhao, Wenqian Xu, Yaxing Yao et al.S&P 2025
- Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-MakingJian Jun, Yunjae Josephine Choi, Jeonghoon Han, Sangsu LeeCHI 2026 · 1 citation
- PolicyPulse: Precision Semantic Role Extraction for Enhanced Privacy Policy ComprehensionAndrick Adhikari, Sanchari Das, Rinku DewriNDSS 2025
