Reciprocal Privacy: Why Your Friends' Privacy is Your Social Responsibility
Preliminary ideas for this work were presented as a short paper at ECAI 2016 and at the ECAI Workshop on Artificial Intelligence for Privacy and Security (PrAISe'16) [10]
The paper proposes a reciprocity-based negotiation framework for preserving privacy in Online Social Networks (OSNs). It introduces software agents that use a hybrid architecture combining Semantic Web Rule Language (SWRL) with utility functions to resolve multi-party privacy conflicts through repeated interactions, achieving a state of "social responsibility" among users.
TL;DR
In the world of Online Social Networks (OSNs), a single post can violate the privacy of many. This paper argues that privacy shouldn't just be an "owner-takes-all" setting. Instead, it introduces a multi-agent negotiation system where software agents, acting for users, trade "credits" to reach an agreement on how content is shared. By using Reciprocity, users help each other preserve privacy today in exchange for the right to share their own content tomorrow.
The Problem: The Tyranny of the Uploader
Most social platforms today operate on an "Uploader Overrides" (UO) model. If Bob posts a photo of Alice at a bar, Bob decides the audience. Alice can complain after the fact, but the damage is often done.
Prior works attempted to solve this with automated negotiation, but they suffered from two main flaws:
- Transactional Myopia: They only looked at one post at a time, ignoring the long-term relationship between friends.
- Lack of Intuition: They used raw utility numbers without understanding the context (e.g., why is Alice upset? Is it the location? The people in the audience?).
Methodology: Semantics Meet Social Norms
The authors suggest a hybrid architecture that combines the logical "reasoning" of a Semantic Web approach with the "mathematical optimization" of utility functions.
1. The Semantic Layer
Using OWL (Web Ontology Language) and SWRL rules, agents can understand complex privacy concerns. For example, a rule might state: "If the context is 'Leisure' and the audience includes 'Colleagues', then Reject." This allows agents to provide specific reasons for rejection, such as "unwanted person in audience" or "private location."
2. Reciprocal Privacy (RP)
The core innovation is the point-based system. Every user pair starts with a set amount of points.
- If Bob wants to share a post that Alice dislikes, he can "pay" Alice in points to accept a slight privacy compromise.
- Conversely, if Alice is very strict, she might "spend" points to force Bob to narrow the audience.
Figure 1: The general concept of social responsibility in the proposed architecture.
3. Negotiation Strategies
- Good-Enough-Privacy (GEP): The negotiator suggests one change at a time (the most important one).
- Maximal-Privacy (MP): The negotiator starts by demanding all privacy violations be fixed and narrows the list only if the initiator refuses.
Experimental Insights: Does Social Responsibility Work?
The researchers tested their models using a simulation of a real Facebook network (50 users, 563 relations).
The "Preserved Privacy" (PP) Metric
Instead of just looking at average happiness, they created a PP Metric that penalizes "unfair" outcomes where one person is much happier than the other.
Key Findings
- Beating the Status Quo: Both GEP and MP significantly outperformed the standard "Uploader Overrides" model in almost all scenarios.
- The Power of Reciprocity: In cases where users are "strict" (highly protective of privacy), the Reciprocal Privacy (RP) layer prevented the negotiation from breaking down. It allowed the post to be shared with a compromised audience rather than not being shared at all.
- Hybrid Strategies: Hybrid-MP (starting with high privacy demands but using points to bridge the gap) proved to be the most robust strategy for maintaining long-term "social health" in the network.
Figure 2: Performance comparison of negotiation strategies (GEP, MP, RP) against the standard Uploader Overrides (UO).
Critical Analysis & Future Outlook
This work shifts the privacy paradigm from Technical Control to Social Responsibility. However, it relies on several assumptions:
- Truthfulness: It assumes agents won't lie about their privacy rules to farm points.
- Complexity: Real-world users might find setting up semantic rules daunting (though the authors mention an Android app to help).
Future Work will likely involve integrating Trust Models—where you might concede more to a best friend than a distant acquaintance—and exploring how context-awareness (via IoT data) can refine privacy rules automatically.
Conclusion
Privacy is not a zero-sum game. By treating our friends' data with the same respect we want for our own—and using intelligent agents to handle the "haggling"—we can create a social web that is both open and secure.
