Score
Planning and executing ethical disclosure processes and safeguards for sensitive or malicious findings, including low-impact measurement techniques and responsible notification to affected operators. This skill covers risk mitigation, disclosure timing, redaction/scoping decisions, and protocols for safe sharing of results.
This paper addresses the critical gap in research ethics within Natural Language Processing Security (NLPSec). Analyzing 2018–2023 mainstream literature, we identify significant shortcomings in core ethical dimensions—particularly harm minimization and responsible disclosure—and a persistent disconnect from established cybersecurity ethics norms. To bridge this gap, we conduct the first cross-domain ethical framework mapping between NLPSec and cybersecurity, introducing the “White-Hat NLP” conceptual framework that aligns NLP-specific characteristics with cybersecurity’s ethical paradigms. Based on this mapping, we formulate actionable, deployment-oriented responsible research guidelines and release the first operational practice checklist explicitly integrating security and ethics governance. Our work delivers the NLPSec community its first systematic ethical assessment pathway and implementation roadmap, enabling the development of ethically conscious, practically enforceable research practices.
This work addresses the current lack of a systematic framework for evaluating ethical risks in data collection practices for large language models (LLMs). It proposes the first quantifiable assessment framework that integrates multiple prominent ethical theories, structuring evaluation around core ethical principles through a set of targeted questions and establishing a scoring system to measure ethical risk. This approach enables systematic, quantitative ethical auditing of LLM data curation processes. By offering a practical tool for assessing ethical compliance in AI development, the framework fills a critical gap in existing research—particularly in the integration of diverse ethical theories and the empirical evaluation of real-world data practices—thereby advancing the responsible development of artificial intelligence.
This paper addresses the core challenge faced by statistical agencies in selecting and designing disclosure avoidance systems (DAS): the difficulty of distinguishing between inherent system properties and implementation-specific choices. We propose the first principled evaluation framework that explicitly decouples “system essential attributes” from “implementation decisions.” Methodologically, the framework integrates risk assessment theory, statistical disclosure control (SDC) paradigm analysis, multi-dimensional constraint modeling, and iterative systems engineering—enabling dynamic trade-offs among privacy protection strength, data utility, and system adaptability under concurrent constraints of legal compliance, scientific validity, resource limitations, and stakeholder requirements. Our primary contribution is filling a critical gap in standardized DAS evaluation by delivering a practical, actionable framework. It supports evidence-based system selection and customized deployment, thereby enhancing the usability and operational agility of official statistics while ensuring regulatory compliance.
This study addresses the absence of unified and transparent research ethics guidelines in top-tier security and privacy conferences, which has led to ambiguous review criteria and inconsistent enforcement, thereby hindering the community’s ethical awareness. Through a systematic analysis of ethics policies across four leading conferences over multiple years and semi-structured interviews with 20 researchers, this work presents the first comprehensive account of the evolution of ethical practices in the field, identifying a critical gap in ethics education as the primary bottleneck. Drawing on qualitative findings and principles of community-based participatory design, the paper proposes an innovative framework featuring an inter-conference coordination mechanism and an open Ethics Wiki. It delineates current progress and key barriers to consensus-building and has already launched the Ethics Wiki as an initial step toward collaborative governance.
While Layer 2 (L2) rollups improve scalability and reduce costs, operator discretion and information asymmetry introduce novel ethical risks. Method: This paper introduces the first systematic ethical risk analysis framework for L2 scaling, proposing a role-based decision-power–risk-exposure classification model. It integrates role modeling, cross-sectional analysis of 129 L2 projects, a manually curated dataset of on-chain events (2022–2025) covering sequencer liveness and transaction inclusion failures, and mechanism mapping. Contribution/Results: We establish an empirically testable ethical risk metric system, revealing critical concerns—including near-universal absence of withdrawal grace periods for urgent upgrades (86%), single-point proposer control over withdrawal freezing (50%), and ethical vulnerabilities in data availability and forced transaction inclusion. We further propose co-designed technical–governance mitigation strategies to enhance accountability, transparency, and user sovereignty.
This work addresses the critical security and ethical risks arising from enterprise employees inadvertently leaking sensitive data or generating policy-violating, unethical content when using large language models. To mitigate these risks, we propose SafeGPT—the first unified dual-sided protection framework that integrates input-side sensitive information detection and sanitization with output-side content moderation and rewriting. SafeGPT further incorporates a human-in-the-loop feedback mechanism to jointly optimize safety and user experience. By combining red-teaming attacks with reinforcement learning from human feedback, the system significantly reduces the likelihood of data leakage and biased outputs while maintaining high user satisfaction.
This study uncovers an inherent tension among cybersecurity governance, data protection, and corporate reputation in digital transformation: despite high compliance readiness—75% of surveyed firms experienced at least one cyberattack within the past year—security incidents persist, with reputational damage and erosion of customer trust being the predominant consequences. Method: Drawing on an online diagnostic survey across multiple industries in Poland, the study applies the ISO/IEC 27001/27032 frameworks and a structured questionnaire, employing descriptive statistics and attributional analysis. Contribution/Results: It provides the first empirical identification of the “compliance–security paradox.” The study proposes a novel paradigm that integrates cybersecurity governance deeply into corporate communication and reputation management systems. It positions data protection as the cornerstone of digital trust and organizational resilience, reframing cybersecurity from a regulatory cost center to a strategic investment.
This study addresses the systemic exploitation of African content moderators in Kenya and Nigeria, who endure precarious working conditions, lack basic labor protections, and are routinely excluded from employment contracts and data transparency. Innovatively repurposing the extraterritorial reach of the European Union’s General Data Protection Regulation (GDPR), the research employs data subject access requests (DSARs), legal compliance analysis, and cross-jurisdictional strategies to successfully obtain critical documents—such as employment contracts and non-disclosure agreements—held by outsourcing firms. This approach not only transcends conventional data rights frameworks but also exposes the structural mechanisms through which technology companies evade accountability via outsourcing, thereby furnishing legally actionable evidence of digital labor rights violations affecting workers in the Global South.
This work addresses the challenge of timely and accurate reporting of personal data breaches under the GDPR, which mandates notification within 72 hours—a process often hindered by the labor-intensive and error-prone manual translation of forensic evidence into structured compliance reports. To streamline this workflow, the authors propose a hybrid analysis method tailored for Linux/ARM-based data-exfiltrating malware, integrating static and dynamic analysis techniques. Crucially, they introduce a large language model (LLM) constrained by a formal JSON Schema to automatically map heterogeneous forensic artifacts onto regulatory reporting templates, such as Italy’s Garante notification form. This approach significantly reduces cognitive load on analysts while enhancing the completeness, regulatory compliance, and speed of incident response.
This work addresses the risk that online platforms may strategically generate semantically equivalent content variants to manipulate compliance metrics, creating a “gaming” problem where apparent metric improvements mask unmitigated harms. The authors model moderation protocols as transformation graphs and introduce a semantic envelope metric, theoretically proving it to be the pointwise minimal solution within the class of conservative repairs. They further develop a hierarchical certification mechanism that guarantees effective constraint of true harm under any policy. Experimental evaluation—combining finite-state mixed-strategy enumeration, SMT solving (using Z3 and cvc5), and bounded single-player MDP verification in PRISM-games—demonstrates that conventional metrics often exhibit significant violations and gaming gaps, whereas the semantic envelope metric remains violation-free across all test instances, effectively resisting strategic manipulation.