About the position
About the research centre or Inria department Le centre de recherche Inria de l’Université Grenoble Alpes regroupe un peu moins de 600 personnes réparties au sein de 27 équipes de recherche et 8 services support à la recherche. Son effectif est distribué sur 3 campus à Grenoble, en lien étroit avec les laboratoires et les établissements de recherche et d'enseignement supérieur (Université Grenoble Alpes, CNRS, CEA, INRAE, …), mais aussi avec les acteurs économiques du territoire. Présent dans les domaines du calcul et grands systèmes distribués, logiciels sûrs et systèmes embarqués, la modélisation de l’environnement à différentes échelles et la science des données et intelligence artificielle, Inria Grenoble - Rhône-Alpes participe au meilleur niveau à la vie scientifique internationale par les résultats obtenus et les collaborations tant en Europe que dans le reste du monde. Context The collection of personal data and the associated privacy issues are a subject firmly grounded in public debates. The growing awareness of the population on privacy issues led to stronger regulations on data protection (e.g., GDPR, HIPAA) and contributed to the appearance of new services making privacy an incentive vector such as privacy-based search engine (e.g., Duckduckgo, Qwant), web browsing (e.g., Web Proxy, Tor, Brave), or mailing (e.g., Protonmail). However, the ever-increasing digitalization of our society exposes individuals to omnipresent data collection. This mas- sive collection of information exposes individuals to new risks ranging from the disclosure of sensitive information to increased manipulation through personal cognitive biases facilitated by the exposure of our personality. The emergence and development of AI have only amplified these risks despite the regulatory effort at different levels (e.g., AI Act) which highlights fundamental freedoms. Once collected, personal information of various natures (e.g., location, web search, web tracking, voice, pictures, motion data, ...) can reveal many sensitive information. For instance, recent works have demonstrated that mobility is a very rich contextual information in the sense that it has a strong inferential potential in terms of information that can be predicted about the individuals whose movements are recorded. Among other, researchers have shown that analyzing mobility traces can reveal personal data about individuals such as their points of interests (e.g., home and place of work) [1], their race and gender [2], their social network [3] as well as to predict their mobility [4], to link accounts of the same user across different datasets [5] and to uniquely identify users from anonymous datasets or to conduct a de-anonymization attack [6]. Moreover, it is possible to analyze the semantics of these mobility traces to infer even more sensitive information such as their religion [7]. In addition, other studies have also demonstrated that the location is used for price discrimination [8]. Effectively protecting personal data is challenging. A large number of protection mechanisms have been proposed in the academic literature but very few have been adopted by application providers and companies in the field and even fewer by users. Furthermore, protecting data inherently also comes with a loss of service and utility (i.e., there is no free food) Data anonymization is rarely perfect, we are talking more about the probability of risk depending on the means used by an adversary to carry out a re-identification attack (e.g., collection of auxiliary information, etc.). The risk is necessarily greater for atypical people than for people more similar to the rest of the population. However, before asking the question of how to effectively protect our location data and what risk remains, perhaps it is better to ask whether it is relevant to generate this data and let third parties collect it. Indeed, without collected personnal data, the risk of disclosing information in an uncontrolled manner does not exist. Raising user awareness by better explaining the risks would reduce the amount of data generated and collected. In this context, the goal of the project is to revisit the explanation mechanisms, often used to technically explain to designers the key factors of a decision, to better explain to end users which information generates more or less risk. By being fully aware of the risk, the user can choose in full knowledge, if he wishes to disclose such or such information. The goal is therefore to develop explainable mechanisms to 1) clearly inform end users about the different risks of inference, and 2) give the user control what risk is acceptable or not to them. If the user does not want to expose himself to a certain risk, the data must be cleaned or sanitized to eliminate this risk of inference. By the way, reducing the amount of information collected at the source (i.e., on the user side), the issues of protection of personal data downstream are seen to be reduced and fall within the axis of data frugality more in line with the finite planetary resources and the environmental issues. Assignment The main mission of the postdoc will be to develop software components to implement privacy risk analysis based on location data directly on the mobile, collect user preferences about the revealed information in the data, and then modify and protect data before sharing it with third parties. In this context, the postdoc will closely work with a PhD student on the team, who is working on a related topic. The postdoc will also collaborate with the rest of the team, to bring its expertise in energy consumption quantification and in the mobile ecosystem. Main activities Implementation of PETS on mobile with a focus on location data Quantification of privacy risks and energy consumption on mobile with a focus on location data State of the art on methods in AI to generate synthetic location data Writing papers / demonstration of the solutions Interviews and SHS stydies in relation of the developped solutions Participation in working groups related to team's projects Supervision of internships Skills 4hD in AI / Mobile / Privacy Fluency in English: ability to participate in complex technical discussions and argue to defend technical positions Interest for the privacy regulation and for bridging technical and legal considerations
This listing was collected from a public source and is reproduced here for
information only. Always confirm the details on the original posting before applying.
View the original posting