Helping Users Automatically Find and Manage Sensitive, Expendable Files in Cloud Storage
Mohammad Taha Khan, Christopher Tran, Shubham Singh, Dimitri Vasilkov, Chris Kanich, Blase Ur, Elena Zheleva
摘要
With the ubiquity of data breaches, forgotten-about files stored in the cloud create latent privacy risks. We take a holistic approach to help users identify sensitive, unwanted files in cloud storage. We first conducted 17 qualitative interviews to characterize factors that make humans perceive a file as sensitive, useful, and worthy of either protection or deletion. Building on our findings, we conducted a primarily quantitative online study. We showed 108 long-term users of Google Drive or Dropbox a selection of files from their accounts. They labeled and explained these files' sensitivity, usefulness, and desired management (whether they wanted to keep, delete, or protect them). For each file, we collected many metadata and content features, building a training dataset of 3,525 labeled files. We then built Aletheia, which predicts a file's perceived sensitivity and usefulness, as well as its desired management. Aletheia improves over state-of-the-art baselines by 26% to 159%, predicting users' desired file-management decisions with 79% accuracy. Notably, predicting subjective perceptions of usefulness and sensitivity led to a 10% absolute accuracy improvement in predicting desired file-management decisions. Aletheia's performance validates a human-centric approach to feature selection when using inference techniques on subjective security-related tasks. It also improves upon the state of the art in minimizing the attack surface of cloud accounts. Usefulness Sensitivity
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li 等S&P 2024 · 被引用 13 次
- Files of a Feather Flock Together? Measuring and Modeling How Users Perceive File Similarity in Cloud StorageWill Brackenbury, Galen Harrison, Kyle Chard, Aaron J. Elmore 等SIGIR 2021 · 被引用 5 次
- Multiuser Privacy and Security Conflicts in the CloudEman Alhelali, Kopo M. Ramokapane, Jose M. SuchCHI 2023 · 被引用 3 次
- Summarizing Sets of Related ML-Driven Recommendations for Improving File Management in Cloud StorageWill Brackenbury, Kyle Chard, Aaron J. Elmore, Blase UrUIST 2022
它引用的顶会 Paper2
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 被引用 156 次
- Taking Data Out of Context to Hyper-Personalize Ads: Crowdworkers' Privacy Perceptions and Decisions to Disclose Private InformationJulia Hanson, Miranda Wei, Sophie Veys, Matthew Kugler 等CHI 2020 · 被引用 25 次
相关 Paper
- KondoCloud: Improving Information Management in Cloud Storage via Recommendations Based on File SimilarityWill Brackenbury, Andrew M. McNutt, Kyle Chard, Aaron J. Elmore 等UIST 2021 · 被引用 2 次
- Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant DataVandit Sharma, Mainack MondalUSENIX Security 2022
- Too Many Zombies: Exploring Challenges and Motivations for (Not) Deleting Unused Online AccountsFranziska Bumiller, Sarah Delgado Rodriguez, Lukas Mecke, Verena Distler 等CHI 2026 · 被引用 1 次
- What is Sensitive About (Sensitive) Data? Characterizing Sensitivity and Intimacy with Google Assistant UsersAlejandra Gómez Ortega, Jacky Bourgeois, Gerd KortuemCHI 2023 · 被引用 33 次
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
