[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-116949-en":3,"doc-seo-116949-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},116949,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Perceptions and Practicalities for Private Machine Learning","Privacy in machine learning enables organizations to analyze data held alone or jointly while protecting data subjects. This thesis shows that private computation, including private machine learning, can improve end-users’ acceptance of data sharing, but only under certain conditions. It identifies key drivers of privacy perceptions such as the number of organizations involved and whether data sharing practices show reciprocity. End-users value clear purpose specification and assurance that inputs are not exchanged across organizations, and they recognize that protections may not be guaranteed.","Perceptions and Practicalities for Private Machine Learning  \nby  \nBailey Kacsmar  \nA thesis  \npresented to the University of Waterloo in ful􀀌llment of the thesis requirement for the degree of  \nDoctor of Philosophy  \nin  \nComputer Science  \nWaterloo, Ontario, Canada, 2023  \n© Bailey Kacsmar 2023  \nExamining Committee Membership  \nThe following served on the Examining Committee for this thesis. The decision of the Examining Committee is by majority vote.  \nExternal Examiner: Michelle Mazurek  \nAssociate Professor, Department of Computer Science University of Maryland  \nSupervisor: Florian Kerschbaum  \nAssociate Professor, Cheriton School of Computer Science University of Waterloo  \nInternal Members: N. Asokan  \nProfessor, Cheriton School of Computer Science  \nUniversity of Waterloo  \nGautam Kamath  \nAssistant Professor, Cheriton School of Computer Science University of Waterloo  \nInternal-External Member: Mahesh Tripunitara  \nProfessor, Electrical and Computer Engineering  \nUniversity of Waterloo  \nAuthor's Declaration  \nThis thesis consists of material all of which I authored or co-authored: see Statement of Contributions included in the thesis. This is a true copy of the thesis, including any required 􀀌nal revisions, as accepted by my examiners.  \nI understand that my thesis may be made electronically available to the public.  \nStatement of Contributions  \nChapter 3 of this thesis was co-authored with Kyle Tilbury, Miti Mazmudar, and Florian Kerschbaum [110] . In particular, the statistical analysis and 􀀌gures were generated by Kyle Tilbury. Miti Mazmudar and I performed the qualitative coding analysis and all parties collaborated on the study design.  \nChapter 4 of this thesis was co-authored with Chelsea H. Komlo, Florian Kerschbaum, and Ian Goldberg [109] Chelsea and I worked collaboratively on the writing and analysis for this work. Ian and I worked on additional writing and the case study analyses included in the appendix. Florian contributed to the threat model development.  \nChapter 5 of this thesis was co-authored with Mark R. Thomas, Thomas Humphries, Diwen Zhu, and Florian Kerschbaum. Implementation and experiment execution was done by Mark, Thomas, and Diwen.  \nChapter 6 of this thesis was co-authored with Vasisht Duddu, Kyle Tilbury, Blase Ur, and Florian Kerschbaum. Vasisht and I performed all of the data analysis while Kyle and I processed all the interview transcriptions. Florian contributed an early version of the section describing private set intersection and Blase contributed to writing the introduction and background section as well as study design.  \nAll other chapters in this thesis contain original work authored under the supervision of Florian Kerschbaum.  \nAbstract  \nPrivacy in machine learning holds great promise for enabling organizations to analyze data they and their partners hold while maintaining data subjects' privacy. In this thesis I show that private computation, such as private machine learning, can increase endusers' acceptance of data sharing practices, but not unconditionally. There are many factors that in􀀍uence end-users' privacy perceptions in this space; including the number of organizations involved and the reciprocity of any data sharing practices. End-users emphasized the importance of detailing the purpose of a computation and clarifying that inputs to private computation are not shared across organizations. End-users also struggled with the notion of protections not being guaranteed 100%, such as in statistical based schemes, thus demonstrating a need for a thorough understanding of the risk form attacks in such applications. When training a machine learning model on private data, it is critical to understand the conditions under which that data can be protected; and when it cannot. For instance, membership inference attacks aim to violate privacy protections by determining whether speci􀀌c data was used to train a particular machine learning model. Further, the successful trans","cbCaih1AtxAMNUsf","https://ap.wps.com/l/cbCaih1AtxAMNUsf","pdf",1381371,1,179,"English","en",105,"# List of Figures\n# List of Tables\n# 1 Introduction\n# 2 Background\n## 2.1 Technical Privacy\n## 2.2 Theories of Privacy\n## 2.3 Legal Privacy\n## 2.4 Usable Privacy\n## 2.5 Privacy in Machine Learning\n## 2.5.1 Data Sharing in Machine Learning\n## 2.5.2 Privacy Protection in Machine Learning\n# 3 Perceptions\n## 3.1 Introduction\n## 3.2 Related Work","[{\"question\":\"How does the thesis relate private machine learning to end-user privacy acceptance?\",\"answer\":\"It argues that private computation can increase end-users’ acceptance of data sharing practices, but only in non-unconditional ways that depend on multiple contextual factors.\"},{\"question\":\"Which factors influence end-users’ privacy perceptions in private machine learning?\",\"answer\":\"The thesis highlights factors such as the number of participating organizations and whether any data sharing practices are reciprocal.\"},{\"question\":\"Why does the thesis emphasize understanding risks like membership inference attacks?\",\"answer\":\"End-users struggle with the idea that protections are guaranteed 100%, especially for statistical-based schemes. The work motivates a thorough understanding of attack risks, including membership inference attacks that test whether specific data was used for training.\"}]","Perceptions and Practicalities for Private Machine Learning | PDF",1785672767,451,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"perceptions-and-practicalities-for-private-machine-learning","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/perceptions-and-practicalities-for-private-machine-learning/116949/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"How does the thesis relate private machine learning to end-user privacy acceptance?","Question",{"text":76,"@type":77},"It argues that private computation can increase end-users’ acceptance of data sharing practices, but only in non-unconditional ways that depend on multiple contextual factors.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Which factors influence end-users’ privacy perceptions in private machine learning?",{"text":81,"@type":77},"The thesis highlights factors such as the number of participating organizations and whether any data sharing practices are reciprocal.",{"name":83,"@type":74,"acceptedAnswer":84},"Why does the thesis emphasize understanding risks like membership inference attacks?",{"text":85,"@type":77},"End-users struggle with the idea that protections are guaranteed 100%, especially for statistical-based schemes. The work motivates a thorough understanding of attack risks, including membership inference attacks that test whether specific data was used for training.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]