Sh@re: Bridging the Privacy-Feedback Gap via Negotiated Audit

Sh@re: Negotiated audit in social networks

2009-10-01
Alejandro Gutierrez, Apeksha Godiyal, Matt Stockton, Michael LeMay, Carl A. Gunter, Roy H. Campbell
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces Sh@re, a novel social networking framework centered on the concept of Negotiated Audit. It implements a three-tier auditing system (No, Anonymous, and Complete Audit) to balance data access and privacy awareness through an Attribute-Based Access Control (ABAC) model.

TL;DR

Online privacy is often treated as a binary "who can see this" switch, but Sh@re introduces a dynamic social contract called Negotiated Audit. It forces a trade-off: if you want to access sensitive data, you must be willing to leave a "digital footprint" (Audit Log) for the owner. By categorizing access into No, Anonymous, and Complete audits, the system educates users on how their data flows through "weak ties" in a social graph.

Background: The Illusion of Privacy

In the era of massive social platforms, users frequently leak personally identifiable information (PII) to "weak ties"—acquaintances or strangers connected through a chain of friends. Most users have zero visibility into who is actually consuming their content, leading to a lack of situational awareness regarding identity theft or stalking.

The Core Insight: Privacy as a Negotiation

Instead of static permissions, the authors propose a Negotiated Audit mechanism. The core logic is simple but powerful:

  • Resource Owners set an "Audit Requirement" for their data.
  • Browsers (Viewers) set an "Allowable Disclosure Level."
  • The Conflict: If you aren't willing to be audited at the level the owner requires, the system simply hides the data from you.

This creates a self-regulating ecosystem where users must decide: Is seeing this content worth revealing my identity?

Methodology: The ABAC Framework

The system is built on an Attribute-Based Access Control (ABAC) model. Unlike traditional Role-Based Access (which is too rigid), ABAC allows for fluid attributes.

The Three Levels of Audit:

  1. No Audit: Total anonymity for the viewer; no log for the owner.
  2. Anonymous Audit: Uses metadata (e.g., "A friend of a friend viewed this") without revealing the specific name. This highlights the "Network Collision" problem—where data leaks across different social circles.
  3. Complete Audit: Full transparency. The owner sees exactly who, when, and what was accessed.

Mathematical Logic

The access rule is governed by the function: CanAccess(p, o) := (Owner(o) = Name(p)) ∨ (AllowableAuditLevel(p) ≥ ConfiguredAuditLevel(o))

Model Logic and Access Matrix Placeholder Table 1: Example of a mapped Access Control Matrix (ACM) showing how different principals interact with objects based on negotiated levels.

The Sh@re Prototype

The authors implemented this via the Sh@re prototype. The architecture includes a g@llery for managing resource audit levels and an @migo module for browsing friends' resources under the negotiation constraints.

Sample Audit Logs Table 2: Typical output of a Complete Audit log, providing users with actionable feedback on data consumption.

Deep Insight: Why This Matters

The most profound contribution of this work is addressing Weak Ties. Research shows that privacy violations rarely come from your best friends; they come from the fringe of your social network. By using Anonymous Auditing by Number of Connections, a user might see: "Someone with only 1 mutual friend viewed your photo." This is a powerful educational tool that prompts the user to tighten their settings without requiring them to parse complex permission menus.

Critical Analysis & Future Work

While innovative, the paper leaves some stones unturned:

  • The "Volume" Problem: Individual accesses might be harmless, but 100 accesses by the same person is stalking. The authors suggest "Threshold-based Auditing" as a future extension.
  • Multi-Ownership: If 5 people are in a photo, who decides the audit level? This remains an open research challenge in distributed privacy.

Conclusion

Sh@re moves us away from the "all-or-nothing" privacy model. It treats data access as a transaction where the currency is transparency. By forcing users to negotiate their level of anonymity, it naturally fosters a more privacy-literate digital society.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend Negotiated Audit or similar feedback-based privacy mechanisms in modern decentralized social networks (DeSo).
  • What are the foundational papers on Attribute-Based Access Control (ABAC) in social media, and how has the logic evolved to handle multi-party data ownership?
  • Explore how Differential Privacy or Zero-Knowledge Proofs are currently being used to implement the "Anonymous Audit" level described in this research.
Contents
Sh@re: Bridging the Privacy-Feedback Gap via Negotiated Audit
1. TL;DR
2. Background: The Illusion of Privacy
3. The Core Insight: Privacy as a Negotiation
4. Methodology: The ABAC Framework
4.1. The Three Levels of Audit:
4.2. Mathematical Logic
5. The Sh@re Prototype
6. Deep Insight: Why This Matters
7. Critical Analysis & Future Work
8. Conclusion