Pith. sign in

REVIEW 3 major objections 5 minor 1 cited by

SoK: Usability Studies in Differential Privacy

T0 review · 3 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This systematic review of 27 empirical studies argues that differential privacy's practical adoption is blocked less by its mathematics than by usability gaps: DP tools demand significant expertise even from technical users, and…

desk verdict A genuinely useful first map of DP usability evidence, but the 'systematic' claim rests on a search protocol narrow enough to matter; worth reviewing with a request for more auditable screening details. read the letter →

arxiv 2412.16825 v2 pith:NYNVCHCL submitted 2024-12-22 cs.HC cs.CR

classification cs.HCcs.CR
keywords differentialprivacyusabilityhuman-computerinteractionepsilonprivacy-utilitytradeoffDPtoolssystematicreviewusable
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper works to establish that the main obstacle to real-world differential privacy (DP) adoption is not the underlying mathematics but usability: DP tools place heavy cognitive demands on technical users, and explanations of DP guarantees fail to land with end users. The authors review 27 empirical studies, split between studies of DP software tools and studies of DP communication, and argue that across both strands the same problems recur: epsilon and other privacy parameters are unintuitive, messaging is inconsistent, and there are no standardized explanations or measurement instruments. If the synthesis is right, then making DP usable is a tractable human-computer interaction problem with concrete next steps: automated parameter setting, standardized communication formats, visual explanations, and tools that check correctness for the user. The paper matters because it turns scattered evidence into a map of best practices and prioritized research gaps for a technology increasingly deployed by government and industry.

What carries the argument

The argument is carried by the two-strata framework that splits DP usability into 'DP tools' and 'DP communication', with a distinct codebook for each. The tool stratum is analyzed in terms of target expertise (technical users with or without DP expertise), parameter-setting support, utility analysis, automation, flexibility, correctness checking, and deployment model; the communication stratum is analyzed in terms of text, visualizations, and pictures or diagrams for conveying epsilon and deployment models like central versus local DP. Applying this framework to 27 double-coded studies is what generates the paper's recurring findings, namely that parameter-setting is the pain point, visual formats outperform text for end users, and standardization is missing at every level, including how 'understanding' is measured.

What would settle it

A concrete counterexample would be a follow-up search using alternative terms such as 'comprehension', 'perceptions', and 'accessibility', or covering non-English venues, that uncovered a substantial body of studies showing that a standardized textual risk-communication format yields comprehension comparable to visual formats across audiences, or that a specific DP tool can be used correctly by novices without parameter adjustments, weakening the paper's claims about the universality of parameter-setting difficulties and the superiority of visuals. More directly, a large-scale preregistered replication of the epsilon-communication experiment that fails to reproduce the visual-format advantage would settle the question.

Watch

Extended reading notes

Core claim

The paper claims to be the first systemization of knowledge on DP usability, and its central discovery is that existing evidence, taken together, points to a stable set of failure modes. Everyone, including experienced data practitioners, struggles to configure or interpret DP parameters, because epsilon expresses a probabilistic guarantee with no intuitive real-world analogue. Text alone rarely suffices; visualizations, icon arrays, and metaphors reliably improve comprehension, but no single format works for all audiences. Current DP tools, whether API-based or visual, still require substantial DP expertise, manual parameter setting, and often lack correctness checking, meaning that even experts can silently produce broken privacy implementations. The paper also documents that the research base itself is narrow: all 27 studies recruited participants in the US or EU, mostly via crowdwork platforms or professional networks, and the field lacks standardized evaluation metrics, making cross-study comparison nearly impossible.

Load-bearing premise

The review assumes that the 27 papers found by one keyword string across four libraries, with a first-200-results cutoff and English-only inclusion, adequately represent the full population of DP usability studies; if relevant studies were systematically missed, the synthesized best practices and research gaps could be skewed.

Editorial extensions

If this is right

  • Adoption barriers in DP are primarily design problems, not mathematical ones; improving tool and communication design would remove the main obstacle to deployment in small and medium organizations.
  • Visualization should become the default for explaining DP to end users: icon arrays, interactive sliders, and data-flow diagrams consistently outperformed text-only descriptions in the reviewed studies.
  • Tool designers should add automation for parameter setting and visible correctness checking, since even DP experts make errors that silently violate the privacy guarantee.
  • The field needs standardized evaluation instruments, including shared quiz questions, consistent metrics like task success rate, and common definitions of objective versus subjective understanding, to make future studies comparable.
  • Attention should shift from end users to other stakeholders, especially policymakers and downstream data users, who are underrepresented in the 27 studies.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the synthesis holds, the research agenda it implies is testable: a head-to-head study that standardizes metrics across multiple explanation formats for the same DP scenario would allow the community to converge on a single best-practice format, which no reviewed study alone provides.
  • The review's emphasis on Western, educated samples suggests that the usability findings may not transfer across cultures; a direct extension would be replicating the most-cited communication experiments, such as the epsilon explanation study, with non-Western participants.
  • A practical corollary the paper leaves implicit is that because 'safe' epsilon values lack agreed benchmarks, regulators and policymakers cannot currently hold DP deployers to a clear standard; standardizing parameter communication is a prerequisite for any legal accountability regime.
  • The paper's central tension, that simplified explanations risk distortion while formal definitions remain inaccessible, suggests that the next generation of tools should embed explanations inside workflows, such as wizards that explain the privacy-utility trade-off at the moment a parameter is set, rather than relying on standalone educational materials.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This paper is a systematization-of-knowledge (SoK) review of empirical usability research on differential privacy (DP). The authors define DP usability along two strata: usability of DP software tools for technical users and effectiveness of DP communication for end users. They report a structured literature search across four digital libraries that yielded 27 included papers, code these studies for methodology (recruitment, sample, instruments, evaluation metrics) and findings, organize the results into tables, and derive takeaways in three areas: methodology, communication, and software tools. The stated contributions are a synthesis of current evidence, a set of best practices for conducting and reporting DP usability studies, and a prioritized list of open research questions.

Significance. The paper addresses a genuine gap: DP has matured theoretically and algorithmically, but no prior SoK paper systematically synthesizes the human-factors evidence. If the corpus is representative, the review is a valuable map for both the DP and HCI communities. The authors followed a recognizable systematic-review protocol: a predefined search string, four digital libraries, inclusion criteria, iterative codebook development, double coding, and consensus-based resolution of disagreements. They also explicitly acknowledge limitations in keyword choice, database selection, and the English-language filter. The recommendations in Section 6 are actionable and, for the most part, calibrated to the evidence presented. I give credit for the structured presentation of methodologies in Tables 1-4 and for the honest Limitations paragraph in Section 3. There are no equations or fitted parameters in this literature review, so circularity is not a natural concern; the use of the authors' own prior study [35] as one evidence point is transparent and does not by itself undermine the synthesis.

major comments (3)
  1. [Section 3] The search protocol is not auditable enough to support the paper's central claim of being a systematic review. The query requires 'participants' as a term, the Google Scholar and Semantic Scholar sweeps are capped at the first 200 results, and the search is limited to English-language publications. The authors state that a manual review of alternative strings 'did not reveal additional relevant papers,' but no screening counts, excluded-paper tallies, or details of the alternative queries are provided. Since the takeaway claims in Sections 6.2 and 6.3 are synthesized from the 27 included papers, a systematically missed segment of the literature (for example, studies using terms like 'users,' 'respondents,' 'comprehension,' or 'crowdworkers,' or studies published in other languages) could skew the conclusions. I request a PRISMA-style screening record or, at minimum, a documented table of the number of records retrieved, screened, excluded, and included, together with a description of the alternative search strings and their result counts.
  2. [Section 4 and Tables 1-4] The reported total of 27 included studies is not reconciled with the tables. By my count, the union of citation keys appearing in Tables 1-4 is 26 distinct papers, and several papers appear in more than one table (for example, [19], [16], and [29]), while [25] appears in Table 3 but not in Table 1. Table 2 also contains an unlabeled row ('Con EU End 243 SURV, EB') and lists five separate sample-size rows for [49] without explaining whether these are separate studies or conditions. Because the evidence tables are the backbone of a SoK paper, readers need a supplementary list of the 27 included papers, their stratum assignments (tool, communication, or both), and clear cross-references from the tables to that list.
  3. [Sections 5.2.2 and 6.2] The takeaway that 'visual descriptions are more effective for end users' is stated more strongly than the underlying evidence warrants. The reviewed studies contain important qualifications: Bullek et al. [3] found that visual explanations increased trust and comfort but also led some participants to make riskier data-sharing choices, and Karegar et al. [21] report that metaphor-based visuals produced overgeneralized or inaccurate mental models of DP guarantees. Section 5.2.2 mentions some of these caveats, but Section 6.2 presents visual formats as an unqualified best practice. The synthesis should carry the conditional nature of the evidence into the headline takeaway, for example by stating that visuals can improve comprehension but may also create inaccurate confidence unless carefully anchored.
minor comments (5)
  1. [Section 3] The sentence 'Here, we detailed our review procedure' should be 'we detail our review procedure' to match the present tense used elsewhere in the paper.
  2. [Section 4.1] The phrase 'to reach the their targeted populations' contains a typo; it should be 'to reach their targeted populations.'
  3. [Section 6.1] The phrase 'Theses measures of users' understanding' should be 'These measures of users' understanding.'
  4. [Tables 1-4] The symbol '•◦' appears in many cells without a legend. Please define it in the table captions (for example, as 'partially present or mixed evidence') so that readers can interpret the tables correctly.
  5. [References] Reference [23] is missing a year and publication venue; please provide the full bibliographic details so that readers can locate the study.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the SoK's findings are syntheses of an independently identified corpus, not consequences of its search criteria, definitions, or self-citations.

full rationale

This is a literature review (SoK) with no equations, fitted parameters, or derived quantities; its conclusions are narrative syntheses of the 27 included studies. The corpus was assembled via an explicit search protocol in Section 3, and every central takeaway, such as 'visual descriptions are more effective for end users' and 'tools require DP expertise', is anchored to cited studies (e.g., [32, 48, 51] for visuals; [35, 40] for tool expertise) rather than being a consequence of how DP usability is defined. The two-pronged usability definition and inclusion criteria constrain which papers enter the corpus, but they do not force the qualitative findings. The paper's own Limitations paragraph discloses that keyword choice, database selection (omitting DBLP), and English-language filtering 'could have inadvertently excluded some papers,' which is an honest auditability limitation rather than a circularity. The self-cited earlier user study [35] (Ngong et al.) is used as empirical evidence, but it is an independent, externally falsifiable usability evaluation, not a parameter fitted for this paper, and the review's main claims are corroborated by non-self-cited studies such as Franzen et al. [15], Xiong et al. [50, 51], Nanayakkara et al. [32], and Karegar et al. [21]. The unsupported assertion in Section 3 that alternative search strings 'did not reveal additional relevant papers' is an auditability concern, not a circular step. Therefore no load-bearing circular step (self-definition, fitted prediction, imported uniqueness, renaming, or ansatz-via-citation) is present.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

No free parameters, axioms, or invented entities: the paper is a literature review and performs no mathematical derivation, model fitting, or new theoretical postulates. Background definitions of differential privacy and Nielsen's usability components are standard inputs from cited prior work.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: Usability Studies in Differential Privacy." pith.science (2026). https://pith.science/paper/NYNVCHCL

@misc{pith2026241216825,
  author       = {Pith},
  title        = {Pith review of: SoK: Usability Studies in Differential Privacy},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/NYNVCHCL}},
  note         = {Machine review of arXiv:2412.16825}
}
abstract

Differential Privacy (DP) has emerged as a pivotal approach for safeguarding individual privacy in data analysis, yet its practical adoption is often hindered by challenges in the implementation and communication of DP. This paper presents a comprehensive systematization of existing research studies around the usability of DP, synthesizing insights from studies on both the practical use of DP tools and strategies for conveying DP parameters that determine privacy protection levels, such as epsilon($\varepsilon$). By reviewing and analyzing these studies, we identify core usability challenges, best practices, and critical gaps in current DP tools that affect adoption across diverse user groups, including developers, data analysts, and non-technical stakeholders. Our analysis highlights actionable insights and pathways for future research that emphasizes user-centered design and clear communication, fostering the development of more accessible DP tools that meet practical needs and support broader adoption.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Interpreting Differential Privacy in Terms of Disclosure Risk

    cs.CR 2025-07 accept novelty 6.0 of 10

    Shows that (epsilon,delta)-differential privacy bounds an adversary's posterior probability, posterior-to-prior ratio, and posterior-to-prior difference with high probability.

Reference graph

Works this paper leans on

52 extracted references · 35 canonical work pages · cited by 1 Pith paper

  1. [35]

    Ngong, Brad Stenger, Joseph P

    Ivoline C. Ngong, Brad Stenger, Joseph P. Near, and Yuanyuan Feng. Evaluating the usability of differential privacy tools with data practitioners, 2024

  2. [19]

    Mark F. St. John, Grit Denker, Peeter Laud, Karsten Martiny, Alisa Pankova, and Dusko Pavlovic. Decision support for sharing data using differential privacy. In 2021 IEEE Symposium on Visualization for Cyber Security (VizSec) , pages 26–35, 2021

  3. [16]

    Psi ( Ψ): a private data sharing interface, 2018

    Marco Gaboardi, James Honaker, Gary King, Jack Murtagh, Kobbi Nissim, Jonathan Ullman, and Salil Vadhan. Psi ( Ψ): a private data sharing interface, 2018

  4. [29]

    Usable differ- ential privacy: A case study with psi

    Jack Murtagh, Kathryn Taylor, George Kellaris, and Salil Vadhan. Usable differ- ential privacy: A case study with psi. arXiv preprint arXiv:1809.04103, 2018

  5. [25]

    User acceptance criteria for privacy preserving machine learning techniques

    Sascha Löbner, Sebastian Pape, and Vanessa Bracamonte. User acceptance criteria for privacy preserving machine learning techniques. In Proceedings of the 18th International Conference on A vailability, Reliability and Security, pages 1–8, 2023

  6. [49]

    Towards effective differential privacy communication for users’ data sharing decision and compre- hension

    Aiping Xiong, Tianhao Wang, Ninghui Li, and Somesh Jha. Towards effective differential privacy communication for users’ data sharing decision and compre- hension. In 2020 IEEE Symposium on Security and Privacy (SP) , pages 392–410. IEEE, 2020

  7. [3]

    Brooke Bullek, Stephanie Garboski, Darakhshan J Mir, and Evan M Peck. Towards understanding differential privacy: When do people trust randomized response technique? In Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems, pages 3833–3837, 2017

  8. [21]

    Exploring {User-Suitable} metaphors for differentially private data analyses

    Farzaneh Karegar, Ala Sarah Alaqra, and Simone Fischer-Hübner. Exploring {User-Suitable} metaphors for differentially private data analyses. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022) , pages 175–193, 2022

Show all 52 references
  1. [1]

    Understanding natality data users’ perceptions and preferences towards a query based noise addition approach based on differential privacy

    Mayda Alrige. Understanding natality data users’ perceptions and preferences towards a query based noise addition approach based on differential privacy . Uni- versity of Maryland, Baltimore County, 2013

  2. [2]

    Deductive and inductive approaches to qualitative data analysis

    Andrea J Bingham and Patricia Witkowsky. Deductive and inductive approaches to qualitative data analysis. Analyzing and interpreting qualitative data: After the interview, 1:133–146, 2021. 13 Onyinye Dibia, Prianka Bhattacharjee, Brad Stenger, Steven Baldasty, Mako Bates, Ivol...

  3. [4]

    Distributed differential privacy via shuffling

    Albert Cheu, Adam Smith, Jonathan Ullman, David Zeber, and Maxim Zhilyaev. Distributed differential privacy via shuffling. In Advances in Cryptology– EUROCRYPT 2019: 38th Annual International Conference on the Theory and Ap- plications of Cryptographic Techniques, Darmstadt, G...

  4. [5]

    Differential privacy as a response to the reidentification threat: The facebook advertiser case study

    Andrew Chin and Anne Klinefelter. Differential privacy as a response to the reidentification threat: The facebook advertiser case study. NCL Rev., 90:1417, 2011

  5. [6]

    Private numbers in public policy: Census, differential privacy, and redistricting

    Aloni Cohen, Moon Duchin, J Matthews, and Bhushan Suwal. Private numbers in public policy: Census, differential privacy, and redistricting. Harvard Data Science Review, (Special Issue 2), 2022

  6. [7]

    Towards formalizing the gdpr’s notion of singling out

    Aloni Cohen and Kobbi Nissim. Towards formalizing the gdpr’s notion of singling out. Proceedings of the National Academy of Sciences , 117(15):8344–8352, 2020

  7. [8]

    Advancing differential privacy: Where we are now and future directions for real-world deployment

    Rachel Cummings, Damien Desfontaines, David Evans, Roxana Geambasu, Yangsibo Huang, Matthew Jagielski, Peter Kairouz, Gautam Kamath, Sewoong Oh, Olga Ohrimenko, et al. Advancing differential privacy: Where we are now and future directions for real-world deployment. arXiv prepr...

  8. [9]

    I need a better description

    Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. "I need a better description": An investigation into user expectations for differential privacy. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pages 3037–3052, 2021

  9. [10]

    Centering policy and practice: Research gaps around usable differential privacy

    Rachel Cummings and Jayshree Sarathy. Centering policy and practice: Research gaps around usable differential privacy. In 2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA) , pages 122–135. IEEE, 2023

  10. [11]

    Sok: Differential privacies

    Damien Desfontaines and Balázs Pejó. Sok: Differential privacies. Proceedings on Privacy Enhancing Technologies, 2020(2):288–313, 2020

  11. [12]

    Calibrating noise to sensitivity in private data analysis

    Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7,

  12. [13]

    The algorithmic foundations of differential privacy

    Cynthia Dwork, Aaron Roth, et al. The algorithmic foundations of differential privacy. Foundations and Trends® in Theoretical Computer Science, 9(3–4):211–407, 2014

  13. [14]

    Communicating the privacy-utility trade-off: Supporting informed data donation with privacy decision interfaces for differential privacy

    Daniel Franzen, Claudia Müller-Birn, and Odette Wegwarth. Communicating the privacy-utility trade-off: Supporting informed data donation with privacy decision interfaces for differential privacy. Proceedings of the ACM on Human- Computer Interaction, 8(CSCW1):1–56, 2024

  14. [15]

    Am I private and if so, how many?

    Daniel Franzen, Saskia Nuñez von Voigt, Peter Sörries, Florian Tschorsch, and Claudia Müller-Birn. "Am I private and if so, how many?"—Using risk communi- cation formats for making differential privacy understandable. arXiv preprint arXiv:2204.04061, 2022

  15. [17]

    Lessons learned: Surveying the practicality of differential privacy in the industry

    Gonzalo Munilla Garrido, Xiaoyuan Liu, Florian Matthes, and Dawn Song. Lessons learned: Surveying the practicality of differential privacy in the industry. arXiv preprint arXiv:2211.03898, 2022

  16. [18]

    Differential privacy and the gdpr

    Julian Holzel. Differential privacy and the gdpr. Eur. Data Prot. L. Rev. , 5:184, 2019

  17. [20]

    Comprehension from chaos: Towards informed consent for private computation

    Bailey Kacsmar, Vasisht Duddu, Kyle Tilbury, Blase Ur, and Florian Kerschbaum. Comprehension from chaos: Towards informed consent for private computation. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communi- cations Security, CCS ’23, page 210–224, New Yor...

  18. [22]

    Replication: the effect of differential privacy communication on german users’ comprehension and data sharing attitudes

    Patrick Kühtreiber, Viktoriya Pak, and Delphine Reinhardt. Replication: the effect of differential privacy communication on german users’ comprehension and data sharing attitudes. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022), pages 117–134, 2022

  19. [23]

    Supporting diverse stakeholders to make informed decisions about the use of differential privacy with a web-based e-learning application

    Marcus Land. Supporting diverse stakeholders to make informed decisions about the use of differential privacy with a web-based e-learning application

  20. [24]

    Salience bias in crowdsourcing contests

    Ho Cheung Brian Lee, Sulin Ba, Xinxin Li, and Jan Stallaert. Salience bias in crowdsourcing contests. Information Systems Research, 29(2):401–418, 2018

  21. [26]

    Hardware-based trusted computing architectures for isolation and attestation

    Pieter Maene, Johannes Götzfried, Ruan De Clercq, Tilo Müller, Felix Freiling, and Ingrid Verbauwhede. Hardware-based trusted computing architectures for isolation and attestation. IEEE Transactions on Computers , 67(3):361–374, 2017

  22. [27]

    Sok: differentially private publication of trajectory data

    Àlex Miranda-Pascual, Patricia Guerra-Balboa, Javier Parra-Arnau, Jordi Forné, and Thorsten Strufe. Sok: differentially private publication of trajectory data. Proceedings on Privacy Enhancing Technologies , 2023

  23. [28]

    Sok: Differential privacy on graph-structured data

    Tamara T Mueller, Dmitrii Usynin, Johannes C Paetzold, Daniel Rueckert, and Georgios Kaissis. Sok: Differential privacy on graph-structured data. arXiv preprint arXiv:2203.09205, 2022

  24. [30]

    Visualizing privacy-utility trade-offs in differentially private data releases

    Priyanka Nanayakkara, Johes Bater, Xi He, Jessica Hullman, and Jennie Rogers. Visualizing privacy-utility trade-offs in differentially private data releases. arXiv preprint arXiv:2201.05964, 2022

  25. [31]

    Measure-observe-remeasure: An inter- active paradigm for differentially-private exploratory analysis

    Priyanka Nanayakkara, Hyeok Kim, Yifan Wu, Ali Sarvghad, Narges Mahyar, Gerome Miklau, and Jessica Hullman. Measure-observe-remeasure: An inter- active paradigm for differentially-private exploratory analysis. arXiv preprint arXiv:2406.01964, 2024

  26. [32]

    What are the chances? explaining the epsilon parameter in differential privacy

    Priyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. What are the chances? explaining the epsilon parameter in differential privacy. In 32nd USENIX Security Symposium (USENIX Security 23), pages 1613–1630, 2023

  27. [33]

    Differential privacy for databases

    Joseph P Near, Xi He, et al. Differential privacy for databases. Foundations and Trends® in Databases, 11(2):109–225, 2021

  28. [34]

    Sok: Chasing accuracy and privacy, and catching both in differentially private histogram publication

    Boel Nelson and Jenni Reuben. Sok: Chasing accuracy and privacy, and catching both in differentially private histogram publication. arXiv preprint arXiv:1910.14028, 2019

  29. [36]

    Measuring usability: preference vs

    Jakob Nielsen and Jonathan Levy. Measuring usability: preference vs. perfor- mance. Communications of the ACM, 37(4):66–75, 1994

  30. [37]

    Privacy as contextual integrity

    Helen Nissenbaum. Privacy as contextual integrity. Wash. L. Rev., 79:119, 2004

  31. [38]

    Is privacy privacy? Philosophical Trans- actions of the Royal Society A: Mathematical, Physical and Engineering Sciences , 376(2128):20170358, 2018

    Kobbi Nissim and Alexandra Wood. Is privacy privacy? Philosophical Trans- actions of the Royal Society A: Mathematical, Physical and Engineering Sciences , 376(2128):20170358, 2018

  32. [39]

    Combining differential privacy and secure multi- party computation

    Martin Pettai and Peeter Laud. Combining differential privacy and secure multi- party computation. InProceedings of the 31st annual computer security applications conference, pages 421–430, 2015

  33. [40]

    Don’t look at the data! how differential privacy reconfigures the practices of data science

    Jayshree Sarathy, Sophia Song, Audrey Haque, Tania Schlatter, and Salil Vadhan. Don’t look at the data! how differential privacy reconfigures the practices of data science. In Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems, pages 1–19, 2023

  34. [41]

    Understanding risks of privacy theater with differential privacy

    Mary Anne Smart, Dhruv Sood, and Kristen Vaccaro. Understanding risks of privacy theater with differential privacy. Proceedings of the ACM on Human- Computer Interaction, 6(CSCW2):1–24, 2022

  35. [42]

    Integrating technical and legal concepts of privacy

    Ana Sokolovska and Ljupco Kocarev. Integrating technical and legal concepts of privacy. Ieee Access, 6:26543–26557, 2018

  36. [43]

    A taxonomy of privacy

    Daniel J Solove. A taxonomy of privacy. U. Pa. l. Rev., 154:477, 2005

  37. [44]

    Privacy-aware eye tracking using differential privacy

    Julian Steil, Inken Hagestedt, Michael Xuelin Huang, and Andreas Bulling. Privacy-aware eye tracking using differential privacy. In Proceedings of the 11th ACM Symposium on Eye Tracking Research & Applications , pages 1–9, 2019

  38. [45]

    How weird is hci? extending hci principles to other countries and cultures

    Christian Sturm, Alice Oh, Sebastian Linxen, Jose Abdelnour Nocera, Susan Dray, and Katharina Reinecke. How weird is hci? extending hci principles to other countries and cultures. In Proceedings of the 33rd Annual ACM Conference Extended Abstracts on Human Factors in Computing...

  39. [46]

    Sok: Differential privacy as a causal property

    Michael Carl Tschantz, Shayak Sen, and Anupam Datta. Sok: Differential privacy as a causal property. In 2020 IEEE Symposium on Security and Privacy (SP) , pages 354–371. IEEE, 2020

  40. [47]

    The users’ perspective on the privacy- utility trade-offs in health recommender systems.International Journal of Human- Computer Studies, 121:108–121, 2019

    André Calero Valdez and Martina Ziefle. The users’ perspective on the privacy- utility trade-offs in health recommender systems.International Journal of Human- Computer Studies, 121:108–121, 2019

  41. [48]

    The influence of explanation designs on user understanding differential privacy and making data-sharing decision

    Zikai Alex Wen, Jingyu Jia, Hongyang Yan, Yaxing Yao, Zheli Liu, and Changyu Dong. The influence of explanation designs on user understanding differential privacy and making data-sharing decision. Information Sciences, 642:118799, 2023

  42. [50]

    Using illustrations to communicate differential privacy trust models: an investigation of users’ comprehension, perception, and data sharing decision

    Aiping Xiong, Chuhao Wu, Tianhao Wang, Robert W Proctor, Jeremiah Blocki, Ninghui Li, and Somesh Jha. Using illustrations to communicate differential privacy trust models: an investigation of users’ comprehension, perception, and data sharing decision. arXiv preprint arXiv:220...

  43. [51]

    Exploring use of explanative illustrations to com- municate differential privacy models

    Aiping Xiong, Chuhao Wu, Tianhao Wang, Robert W Proctor, Jeremiah Blocki, Ninghui Li, and Somesh Jha. Exploring use of explanative illustrations to com- municate differential privacy models. In Proceedings of the Human Factors and 14 SoK: Usability Studies in Differential Priv...

  44. [2006]

    Springer, 2006

    Proceedings 3, pages 265–284. Springer, 2006

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.