I'll summarize our study on the privacy implications of eye tracking, which was widely shared & discussed online over the last weeks 🥳 Time for a thread. #eyetracking #privacy #dataprotection #machinelearning #AI #inferences 1/19 ImageImage
Link to paper (open access): rd.springer.com/content/pdf/10…. In the paper, we present the results from sifting through a ton of literature and patents to answer one question: What categories of personal information can be inferred from eye-tracking (ET) data? 2/19
In short: recorded eye activity can reveal information about a user's sex, age, ethnicity, personality traits, drug-consumption habits, emotions, fears, skills, interests, sexual preferences, and physical and mental health. Details in the paper. Here are some examples: 3/19
Gaze abnormalities are a defining characteristic of various mental disorders, incl. depression & schizophrenia. Apart from detecting acute cases from ET data, researchers found biases in visual attention predictive of future depression scores at a delay of >2 years. 👀 4/19 Image
Pupil dilation & spontaneous attention to specific stimuli can reveal a lot about a user’s phobias and aversions (e.g., fear of spiders/needles) but also about interests & preferences, incl. sexual preferences towards specific faces, age groups, body shapes & body parts. 5/19 Image
ET can also allow inferences about a user's ethnic background, knowledge of certain cultural practices (e.g., eating with chopsticks) and native language (based on gaze patterns during reading). 6/19
As a basis for inferences, eye trackers capture not only the dispersion, duration, amplitude, acceleration, velocity and chronological sequence of eye movements … 7/19 Image
… but often also the distance between eyelids, blink duration, blink frequency, ocular microtremors, pupil size, pupil reactivity, iris texture, facial expressions and facial attributes (e.g., skin color, eye shape, wrinkles). 8/19
Eye movements cannot only be tracked in head-mounted devices (e.g., VR headsets) but also through built-in front cameras in laptops, tablets and smartphones. The latter is less accurate, but these methods will quickly improve & make eye tracking ubiquitous in everyday life. 9/19
Many aspects of gaze behavior are not under volitional control (e.g., stimulus-driven glances, pupil dilation, ocular tremor, spontaneous blinks). Thus, it’s impossible for users to understand or control what information is revealed. 10/19
Drawing inferences from ET data is not trivial & the cited inference methods are not perfect. However, for many attacks and profiling purposes, 100% accuracy is not needed. Inaccurate methods will be used nonetheless, which can cause additional discriminatory side-effects. 11/19
Inference methods are mostly developed & deployed behind closed doors, subject to non-disclosure agreements. Based on R&D investments, some companies likely have far greater capabilities than what is known from published research. 12/19 Image
ET has the potential to improve our lives in many ways. It is precisely the richness of gaze data that make the rising technology so valuable & useful. But to exploit this potential in a socially acceptable manner, adequate privacy protection is needed. 13/19
Existing technical & legal countermeasures are limited and don’t offer reliable protection against undesired inferences. Considering the rapid proliferation of eye tracking technology, more effective safeguards and means of enforcement are urgently needed. 14/19
Given the subject’s complexity, users cannot be expected to “defend themselves” or give truly “informed consent”, calling into question the prevalent legal paradigm of notice-and-consent (a.k.a. privacy self-management). 15/19
Since it is unlikely that companies will voluntarily refrain from using or selling personal information that can be extracted from already collected data, there should be strong regulatory incentives and controls. 16/19
Our paper received encouraging feedback, incl. 100s of tweets (e.g., @jordanbpeterson, @mserdark, @SteveStuWill), 100k downloads on Springer and numerous mentions across Facebook, Reddit, blogs, podcasts, policy reports and news outlets. altmetric.com/details/773833… 17/19 Image
Of course, the threat of undesired inferences goes far beyond ET, encompassing countless other sensors and data sources. In other recent work, we have examined inferences from voice recordings (e.g., voice messages, voice memos, voice commands): rd.springer.com/content/pdf/10… ... 18/19 Image
… and accelerometer data (dl.acm.org/doi/10.1145/33…). The accelerometer is the most widely used sensor in mobile devices and is commonly accessed by mobile apps without any request or notification to the user. 19/19 Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Jacob Leon Kröger

Jacob Leon Kröger Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @JL_Kroger

2 Dec
What can companies learn about you by analyzing your voice & manner of speaking (e.g., in voice commands/messages/calls/memos)? In this thread, I summarize our study on the largely overlooked privacy impacts of modern voice & speech analysis. #privacy #datamining #IoT #ethics 1/n
Link to paper (open access): link.springer.com/content/pdf/10…. The paper provides a structured overview of personal information that can be inferred from voice recordings by using machine learning techniques. 2/n
Through the lens of data analytics, certain speech characteristics can carry more information than the words themselves (e.g., accent, dialect, sociolect, lexical diversity, patterns of word use, speaking rate & rhythms, intonation, pitch, loudness, formant frequencies). 3/n
Read 25 tweets
5 Oct
“Are apps listening to people's conversations to improve ad targeting?” I was contacted by leading Italian newspaper @repubblica to comment on this controversy. Find my response in this thread.
#privacy #dataprotection #spying #smartphones #listening #ads #surveillance #apps 1/n Abstract of a paper we have written on the topicA simplified overview of the threat model
*** QUESTION 1 ***
Is it possible for apps (“commercial” apps, not surveillance apps used by law enforcement) to secretly record conversations of users? 2/n
Yes, this is theoretically possible. Apps regularly obtain from us the permission to use our smartphones’ microphones. And many apps are suspected to misuse this permission for dubious purposes (e.g., to track us via “ultrasonic beacons”). 3/n
Read 36 tweets
29 Jul
What can companies learn about you by analyzing how you hold and move your mobile devices (e.g., smartphone/-watch)? In this thread, I summarize our study on the astounding privacy implications of accelerometer sensors #privacy #dataprotection #machinelearning #AI #IoT 1/n
Link to paper (open access): dl.acm.org/doi/pdf/10.114…. In it, we provide a structured overview of personal information that can be inferred from accelerometer data by using machine learning techniques. 2/n
While this may sound like a topic for tech nerds, the paper is digestible for laypeople and relevant for anyone curious about the information we unknowingly reveal to companies through embedded sensors. 3/n
Read 23 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(