The Experts below are selected from a list of 72 Experts worldwide ranked by ideXlab platform

I. Govender - One of the best experts on this subject based on the ideXlab platform.

  • Mapping ‘Security Safeguard’ Requirements in a data Privacy legislation to an international Privacy framework: A compliance methodology
    2015 Information Security for South Africa (ISSA), 2015
    Co-Authors: I. Govender
    Abstract:

    It is commonplace for organisations to collect personal information to be processed and stored on their systems. Until recently, there was no comprehensive legislation that addressed the `processing' of personal information by organisations in South Africa. The Protection of Personal Information Bill (“POPI”) was signed into law in November 2013 and is expected to come into effect, later this year (2015). POPI is informed by international data Privacy legislation. The implications are that it will be incumbent for organisations to revisit how they `handle' peoples' personal information. This can be a daunting task as evidenced by countries that still find it a challenge to comply with data Privacy laws that have been enacted there, a while ago. This article proposes a methodology to comply with POPI. The Generally Accepted Privacy Principles (GAPP) is an American/Canadian framework containing international Privacy requirements with best Practices. Both, POPI and GAPP address a common purpose: `How personal information is collected, used, retained, disclosed, and disposed.' GAPP is reputed as a solid benchmark for good Privacy Practice, comprising of ten overarching Privacy principles which yields a set of criteria for effective management of Privacy risks and compliance. Much of the provisions in POPI is addressed in GAPP. A key condition (Security Safeguards) in POPI stipulates what aspects of personal information must be adequately secured, with limited insight on how to go about this process. Accordingly, this article proposes a methodology to fill this gap. All of the provisions under `Security Safeguards' in POPI is mapped onto GAPP, thereby contextualising GAPP to facilitate compliance with South Africa's data Privacy legislation and to the same end, complying with international Privacy laws. This framework could also be implemented as a checklist/auditing document, guiding the organisation in its implementation of data Privacy and POPI compliance.

  • ISSA - Mapping ‘Security Safeguard’ Requirements in a data Privacy legislation to an international Privacy framework: A compliance methodology
    2015 Information Security for South Africa (ISSA), 2015
    Co-Authors: I. Govender
    Abstract:

    It is commonplace for organisations to collect personal information to be processed and stored on their systems. Until recently, there was no comprehensive legislation that addressed the ‘processing’ of personal information by organisations in South Africa. The Protection of Personal Information Bill (“POPI”) was signed into law in November 2013 and is expected to come into effect, later this year (2015). POPI is informed by international data Privacy legislation. The implications are that it will be incumbent for organisations to revisit how they ‘handle’ peoples' personal information. This can be a daunting task as evidenced by countries that still find it a challenge to comply with data Privacy laws that have been enacted there, a while ago. This article proposes a methodology to comply with POPI. The Generally Accepted Privacy Principles (GAPP) is an American/Canadian framework containing international Privacy requirements with best Practices. Both, POPI and GAPP address a common purpose: ‘How personal information is collected, used, retained, disclosed, and disposed.’ GAPP is reputed as a solid benchmark for good Privacy Practice, comprising of ten overarching Privacy principles which yields a set of criteria for effective management of Privacy risks and compliance. Much of the provisions in POPI is addressed in GAPP. A key condition (Security Safeguards) in POPI stipulates what aspects of personal information must be adequately secured, with limited insight on how to go about this process. Accordingly, this article proposes a methodology to fill this gap. All of the provisions under ‘Security Safeguards’ in POPI is mapped onto GAPP, thereby contextualising GAPP to facilitate compliance with South Africa's data Privacy legislation and to the same end, complying with international Privacy laws. This framework could also be implemented as a checklist/auditing document, guiding the organisation in its implementation of data Privacy and POPI compliance.

Tülay Yildlnm - One of the best experts on this subject based on the ideXlab platform.

  • Differential Privacy Practice on Diagnosis of COVID-19 Radiology Imaging Using EfficientNet
    2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA), 2020
    Co-Authors: Zümrüt Müftüoğlu, Ayyüce M. Kizrak, Tülay Yildlnm
    Abstract:

    Medical sciences are an important application area of artificial intelligence. Healthcare requires meticulousness in the whole process from collecting data to processing. It should also be handled in terms of data quality, data size, and data Privacy. Various data are used within the scope of the COVID-19 outbreak struggle. Medical and location data collected from mobile phones and wearable devices are used to prevent the spread of the epidemic. In addition to this, artificial intelligence approaches are presented by using medical images in order to identify COVID-19 infected people. However, studies should be carried out by taking care not to endanger the security of the data, people, and countries needed for these useful applications. Therefore, differential Privacy (DP) application, which was an interesting research subject, has been included in this study. CXR images have been collected from COVID-19 infected 139 and a total of 373 public data sources were used for a diagnostic concept. It has been trained with EfficientNet- B0, a recent and robust deep learning model, and proposal the possibility of infected with an accuracy of 94.7%. Other evaluation parameters were also discussed in detail. Despite the data constraint, this performance showed that it can be improved by augmenting the dataset. The most important aspect of the study was the proposal of differential Privacy Practice for such applications to be reliable in real-life use cases. With this view, experiments were repeated with DP applied images and the results obtained were presented. Here, Private Aggregation of Teacher Ensembles (PATE) approach was used to ensure Privacy assurance.

  • INISTA - Differential Privacy Practice on Diagnosis of COVID-19 Radiology Imaging Using EfficientNet
    2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA), 2020
    Co-Authors: Zümrüt Müftüoğlu, M. Ayyuce Kizrak, Tülay Yildlnm
    Abstract:

    Medical sciences are an important application area of artificial intelligence. Healthcare requires meticulousness in the whole process from collecting data to processing. It should also be handled in terms of data quality, data size, and data Privacy. Various data are used within the scope of the COVID-19 outbreak struggle. Medical and location data collected from mobile phones and wearable devices are used to prevent the spread of the epidemic. In addition to this, artificial intelligence approaches are presented by using medical images in order to identify COVID-19 infected people. However, studies should be carried out by taking care not to endanger the security of the data, people, and countries needed for these useful applications. Therefore, differential Privacy (DP) application, which was an interesting research subject, has been included in this study. CXR images have been collected from COVID-19 infected 139 and a total of 373 public data sources were used for a diagnostic concept. It has been trained with EfficientNet- B0, a recent and robust deep learning model, and proposal the possibility of infected with an accuracy of 94.7%. Other evaluation parameters were also discussed in detail. Despite the data constraint, this performance showed that it can be improved by augmenting the dataset. The most important aspect of the study was the proposal of differential Privacy Practice for such applications to be reliable in real-life use cases. With this view, experiments were repeated with DP applied images and the results obtained were presented. Here, Private Aggregation of Teacher Ensembles (PATE) approach was used to ensure Privacy assurance.

Anthony Morton - One of the best experts on this subject based on the ideXlab platform.

  • Privacy Failures as Systems Failures: A Privacy-Specific Formal System Model
    Data Protection on the Move, 2016
    Co-Authors: Anthony Morton
    Abstract:

    There have been numerous cases of adverse publicity concerning the negative effect of technology services—the combination of a technology platform and providing organisation—on people’s Privacy. Privacy failures represent complex and cross-disciplinary failure situations, encompassing the design and development of technology services, and organisational Privacy Practice. Investigation of the root causes of Privacy failures requires a systemic and multi-perspective approach which views Privacy failures as systems failures. Systems thinking, tools and methods have been used for several decades to analyse and model failures, but have not been applied to Privacy failures. This chapter introduces the use of a systemic method—the Systems Failures Approach—to study Privacy failures. The Systems Failures Approach—founded on Soft Systems Methodology—compares a conceptual model of a failure situation with a Formal System Model (FSM)—a paradigm of a robust system capable of purposeful activity—to identify its causes, and recommend feasible and desirable changes. This chapter describes a Privacy-Specific Formal System Model (PSFSM), as part of the Systems Failures Approach, to identify the actual or potential causes of Privacy failures in technology services, and concludes with a brief proof-of-concept application of the PSFSM to the launch of Google Buzz.

  • Privacy is a process not a pet a theory for effective Privacy Practice
    New Security Paradigms Workshop, 2012
    Co-Authors: Anthony Morton, Angela M Sasse
    Abstract:

    Privacy research has not helped practitioners -- who struggle to reconcile users' demands for information Privacy with information security, legislation, information management and use -- to improve Privacy Practice. Beginning with the principle that information security is necessary but not sufficient for Privacy, we present an innovative layered framework - the Privacy Security Trust (PST) Framework - which integrates, in one model, the different activities practitioners must undertake for effective Privacy Practice. The PST Framework considers information security, information management and data protection legislation as Privacy hygiene factors, representing the minimum processes for effective Privacy Practice. The framework also includes Privacy influencers - developed from previous research in information security culture, information ethics and information culture - and Privacy by design principles. The framework helps to deliver good Privacy Practice by providing: 1) a clear hierarchy of the activities needed for effective Privacy Practice; 2) delineation of information security and Privacy; and 3) justification for placing data protection at the heart of those activities involved in maintaining information Privacy. We present a proof-of-concept application of the PST Framework to an example technology -- electricity smart meters.

  • NSPW - Privacy is a process, not a PET: a theory for effective Privacy Practice
    Proceedings of the 2012 workshop on New security paradigms - NSPW '12, 2012
    Co-Authors: Anthony Morton, M. Angela Sasse
    Abstract:

    Privacy research has not helped practitioners -- who struggle to reconcile users' demands for information Privacy with information security, legislation, information management and use -- to improve Privacy Practice. Beginning with the principle that information security is necessary but not sufficient for Privacy, we present an innovative layered framework - the Privacy Security Trust (PST) Framework - which integrates, in one model, the different activities practitioners must undertake for effective Privacy Practice. The PST Framework considers information security, information management and data protection legislation as Privacy hygiene factors, representing the minimum processes for effective Privacy Practice. The framework also includes Privacy influencers - developed from previous research in information security culture, information ethics and information culture - and Privacy by design principles. The framework helps to deliver good Privacy Practice by providing: 1) a clear hierarchy of the activities needed for effective Privacy Practice; 2) delineation of information security and Privacy; and 3) justification for placing data protection at the heart of those activities involved in maintaining information Privacy. We present a proof-of-concept application of the PST Framework to an example technology -- electricity smart meters.

Zümrüt Müftüoğlu - One of the best experts on this subject based on the ideXlab platform.

  • Differential Privacy Practice on Diagnosis of COVID-19 Radiology Imaging Using EfficientNet
    2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA), 2020
    Co-Authors: Zümrüt Müftüoğlu, Ayyüce M. Kizrak, Tülay Yildlnm
    Abstract:

    Medical sciences are an important application area of artificial intelligence. Healthcare requires meticulousness in the whole process from collecting data to processing. It should also be handled in terms of data quality, data size, and data Privacy. Various data are used within the scope of the COVID-19 outbreak struggle. Medical and location data collected from mobile phones and wearable devices are used to prevent the spread of the epidemic. In addition to this, artificial intelligence approaches are presented by using medical images in order to identify COVID-19 infected people. However, studies should be carried out by taking care not to endanger the security of the data, people, and countries needed for these useful applications. Therefore, differential Privacy (DP) application, which was an interesting research subject, has been included in this study. CXR images have been collected from COVID-19 infected 139 and a total of 373 public data sources were used for a diagnostic concept. It has been trained with EfficientNet- B0, a recent and robust deep learning model, and proposal the possibility of infected with an accuracy of 94.7%. Other evaluation parameters were also discussed in detail. Despite the data constraint, this performance showed that it can be improved by augmenting the dataset. The most important aspect of the study was the proposal of differential Privacy Practice for such applications to be reliable in real-life use cases. With this view, experiments were repeated with DP applied images and the results obtained were presented. Here, Private Aggregation of Teacher Ensembles (PATE) approach was used to ensure Privacy assurance.

  • INISTA - Differential Privacy Practice on Diagnosis of COVID-19 Radiology Imaging Using EfficientNet
    2020 International Conference on INnovations in Intelligent SysTems and Applications (INISTA), 2020
    Co-Authors: Zümrüt Müftüoğlu, M. Ayyuce Kizrak, Tülay Yildlnm
    Abstract:

    Medical sciences are an important application area of artificial intelligence. Healthcare requires meticulousness in the whole process from collecting data to processing. It should also be handled in terms of data quality, data size, and data Privacy. Various data are used within the scope of the COVID-19 outbreak struggle. Medical and location data collected from mobile phones and wearable devices are used to prevent the spread of the epidemic. In addition to this, artificial intelligence approaches are presented by using medical images in order to identify COVID-19 infected people. However, studies should be carried out by taking care not to endanger the security of the data, people, and countries needed for these useful applications. Therefore, differential Privacy (DP) application, which was an interesting research subject, has been included in this study. CXR images have been collected from COVID-19 infected 139 and a total of 373 public data sources were used for a diagnostic concept. It has been trained with EfficientNet- B0, a recent and robust deep learning model, and proposal the possibility of infected with an accuracy of 94.7%. Other evaluation parameters were also discussed in detail. Despite the data constraint, this performance showed that it can be improved by augmenting the dataset. The most important aspect of the study was the proposal of differential Privacy Practice for such applications to be reliable in real-life use cases. With this view, experiments were repeated with DP applied images and the results obtained were presented. Here, Private Aggregation of Teacher Ensembles (PATE) approach was used to ensure Privacy assurance.

Ken Barker - One of the best experts on this subject based on the ideXlab platform.

  • DBSec - P4A: A New Privacy Model for XML
    Lecture Notes in Computer Science, 2008
    Co-Authors: Angela Cristina Duta, Ken Barker
    Abstract:

    We propose a new Privacy model for XML data called Privacy for All (P4A) to capture collectors Privacy Practice and data providers Privacy preferences. Through P4A data collectors specify the purpose of data collection along with recipients, retention time and users. Data providers can agree to the collectors' Practice or impose their own Privacy preferences. P4A offers more flexibility to both data collectors and providers in specifying Privacy statements and preferences, including but not limited to full permission, denial, and conditional access to information. A Privacy Practice defines purposes, recipients, retention period, and uses of data collection. Data providers share their private information with data collectors under restrictions specified by Privacy preferences. P4A offers individualsmultiple options for restrictions such as conditional access, return results as range intervals for each data item and purpose.