As AI systems increasingly rely on training data, assessing dataset trustworthiness has become critical, particularly for properties like fairness or bias that emerge at the dataset level. Prior work has used Subjective Logic to assess trustworthiness of individual data, but not to evaluate trustworthiness properties that emerge only at the level of the dataset as a whole. This paper introduces the first formal framework for assessing the trustworthiness of AI training datasets, enabling uncertainty-aware evaluation of global properties such as bias. Built on Subjective Logic, our approach supports trust propositions and quantifies uncertainty in scenarios where evidence is incomplete, distributed, and/or conflicting. We instantiate this framework on the trustworthiness property of bias, and we experimentally evaluate it based on a traffic sign recognition dataset. The results demonstrate that our method captures class imbalance and remains interpretable and robust in both centralized and federated contexts.
Trust assessment in multi-agent systems (MAS) is critical for ensuring reliable decision-making in dynamic, decentralized environments. However, existing methods for evaluating trust are domain-specific, fragmented, and difficult to generalize. To address this, we propose a generic methodology for trust level calculation that can be instantiated based on domain-specific requirements. We apply this methodology in a smart healthcare use case, where trust is assessed for medical data exchanged between smart ambulances and hospital backends. Through systematic experimentation, we evaluate the feasibility and effectiveness of our approach, identifying key challenges that arise when applying such a trust assessment methodology in practice. These insights allow us to analyze fundamental gaps that must be addressed to further advance the formalization of trust assessment methodologies, bridging the gap between domain-specific trust models and a harmonized approach to trust computation.
Subjective Logic-based trust reasoning requires the network to be a Directed Series-Parallel Graph (DSPG). However, most real-world trust graphs do not meet this condition, and existing transformation methods often remove uncertain edges, causing unnecessary information loss. In this paper, we propose a new DSPG synthesis framework that prioritizes structural integrity and information preservation. At its core is the concept of Parallel Non-intersecting Path Subnetworks (PNPS), which refines existing definitions and enables clearer identification of DSPG violations. We also introduce optimized synthesis criteria that admit more edges while maintaining DSPG compliance. In addition to the theoretical contributions from the framework, we also propose an algorithm for DSPG synthesis that ensures correctness, avoids edge removal, and enhances trust inference. Our experiments demonstrate reduced uncertainty in derived opinions and more reliable decision-making in trust-based systems.
Trustworthiness has become a key requirement for the deployment of artificial intelligence systems in safety-critical applications. Conventional evaluation metrics, such as accuracy and precision, fail to appropriately capture uncertainty or the reliability of model predictions, particularly under adversarial or degraded conditions. This paper introduces the Parallel Trust Assessment System (PaTAS), a framework for modeling and propagating trust in neural networks using Subjective Logic (SL). PaTAS operates in parallel with standard neural computation through Trust Nodes and Trust Functions that propagate input, parameter, and activation trust across the network. The framework defines a Parameter Trust Update mechanism to refine parameter reliability during training and an Inference-Path Trust Assessment (IPTA) method to compute instance-specific trust at inference. Experiments on real-world and adversarial datasets demonstrate that PaTAS produces interpretable, symmetric, and convergent trust estimates that complement accuracy and expose reliability gaps in poisoned, biased, or uncertain data scenarios. The results show that PaTAS effectively distinguishes between benign and adversarial inputs and identifies cases where model confidence diverges from actual reliability. By enabling transparent and quantifiable trust reasoning within neural architectures, PaTAS provides a foundation for evaluating model reliability across the AI lifecycle.
We propose an architectural design for a Trust Level Evaluation Engine. The engine is meant to work in a complex and dynamic environment of potentially untrustworthy sources of information where the situational knowledge is partial and subjective from the viewpoint of the information source, thus potentially inconsistent and contradictory. Consistently with a Zero-Trust approach, no initial trust between nodes should be assumed, since a decision-making module shall nevertheless figure out its level of confidence about the truth of a proposition over the reality. Our design is theory-agnostic and can be instantiated on different mathematical subjective model theories, but we demonstrate its feasibility by mapping it on the Subjective Logic. We also discuss critical design choices and algorithmic details that are only partially addressed in the abstract description of the theory, and we demonstrate how the engine effectively works on large and complex subjective trust networks. Additionally, we offer a proof-of-concept implementation to showcase the proposed architecture’s ability to handle intricate and complex networks.
Recent advances in Decentralized Digital Identity solutions, revolving around the use of Verifiable Credentials towards identity sovereignty, are centered around Identity Wallets for ensuring that identity data control remains with the user. However, such schemes still lack the capabilities to provide higher Level of Assurance (LoA) guarantees, for identity verification, which restricts their full potential. In this paper, we design and showcase DOOR; a library that enables Identity Wallets to leverage hardware Roots-of-Trust (RoT) for binding user authentication factors to HW-based keys, thus, allowing for both proof of (User) identity and (Wallet) integrity, bringing them in alignment with emerging regulations and standards that require higher LoA for services (e.g. eIDAS). At the same time, we make sure that privacy-enhancing properties like selective-disclosure are fully supported in order to make the Wallet compliant with privacy regulations (e.g. GDPR). To achieve all the above, we have designed an enhanced variant of Attribute-based Direct Anonymous Attestation (DAA-A) crypto protocol for offering anonymity, unlinkability, and unforgeability, while being the first to offer strong guarantees on the Wallet’s integrity when constructing attribute attestations. We formally prove the security properties of DOOR, offered by the underlying crypto primitives used to enable selective disclosure of attributes, by describing their construction while also benchmarking their computational footprint and comparing them with other widespread cryptographic mechanisms (adopted by the standards) in terms of performance, size of the associated verifiable presentations while safeguarding user anonymous authentication and unlinkability.
The emerging Cooperative Intelligent Transportation Systems (C-ITS) landscape is expanding in terms of security and trust requirements, to provide the necessary enablers for the safety of critical operations (i.e., collision avoidance). To this extend, Public Key Infrastructure (PKIs) and Direct Anonymous Attestation (DAA) schemes have been proposed by the literature, in order to provide authenticity over the exchanged messages. DAA schemes can help address several challenges of centralized PKIs by offering a more scalable solution for pseudonym certificate issuance, reloading and revocation. This paper is the first to implement a DAA-based solution and then perform a methodological comparison of the two schemes based on an experimental evaluation. The acquired results do not directly dictate one prevailing solution, but rather suggest the need for an integrated approach converging concepts from both schemes, in order to better accommodate the needs of future C-ITS systems.
This report documents the program and the outcomes of Dagstuhl Seminar 22042 “Privacy Protection of Automated and Self-Driving Vehicles”. The Seminar reviewed existing privacy-enhancing technologies, standards, tools, and frameworks for protecting personal information in the context of automated and self-driving vehicles (AVs). We specifically focused on where such existing techniques clash with requirements of an AV and its data processing and identified the major road blockers on the way to deployment of privacy protection in AVs from a legal, technical, business and ethical perspective. Therefore, the seminar took an interdisciplinary approach involving autonomous and connected driving, privacy protection, and legal data protection experts. This report summarizes the discussions and findings during the seminar, includes the abstracts of talks, and includes a report from the working groups. This talk opened the seminar with an overview over the field of automotive privacy and how it developed over the years. We started from early works on Car-to-Everything (C2X) and discussed how privacy was considered an important requirement from day one. From this perspective, C2X is an excellent example of privacy-by-design and privacy-by-default. We introduced how changing pseudonyms were designed as a mechanism to protect privacy and prevent location tracking, also highlighting its limitations and the need to balance and trade-off technical privacy against effort and efficiency of applications. As an example, we looked into tracking attacks that can easily reconstruct a vehicle’s path from anonymous position samples (if they are available with sufficiently high resolution).
Vehicular networks rely on Public Key Infrastructure (PKIs) to generate long-term and short-term pseudonyms that protect vehicle's privacy. Instead of relying on a complex and centralized ecosystem of PKI entities, a more scalable solution is to rely on Direct Anonymous Attestation (DAA) and the use of Trusted Computing elements. In particular, revocation based on DAA is very attractive in terms of efficiency and privacy: it does not require the use of Certificate Revocation Lists (CRLs) and revocation authorities can exclude misbehaving participants from a V2X system without resolving (i.e. learning) their long-term identity. In this paper, we present a novel revocation protocol based on the use of DAA and showcase a detailed design and modeling of the implementation on a real TPM platform in order to demonstrate its significant performance improvements compared to existing solutions.
Vehicular networks rely on Public Key Infrastructure (PKIs) to generate long-term and short-term pseudonyms that protect vehicle's privacy. Instead of relying on a complex and centralized ecosystem of PKI entities, a more scalable solution is to rely on Direct Anonymous Attestation (DAA) and the use of Trusted Computing elements. In particular, revocation based on DAA is very attractive in terms of efficiency and privacy: it does not require the use of Certificate Revocation Lists (CRLs) and revocation authorities can exclude misbehaving participants from a V2X system without resolving (i.e. learning) their long-term identity. In this paper, we present a novel revocation protocol based on the use of DAA and showcase a detailed design and modeling of the implementation on a real TPM platform in order to demonstrate its significant performance improvements compared to existing solutions.
With the rapidly evolving next-generation systems-of-systems, we face new security, resilience, and operational assurance challenges. In the face of the increasing attack landscape, it is necessary to cater to efficient mechanisms to verify software and device integrity to detect run-time modifications. Towards this direction, remote attestation is a promising defense mechanism that allows a third party, the verifier, to ensure a remote device's (the prover's) integrity. However, many of the existing families of attestation solutions have strong assumptions on the verifying entity's trustworthiness, thus not allowing for privacy preserving integrity correctness. Furthermore, they suffer from scalability and efficiency issues. This paper presents a lightweight dynamic configuration integrity verification that enables inter and intra-device attestation without disclosing any configuration information and can be applied on both resource-constrained edge devices and cloud services. Our goal is to enhance run-time software integrity and trustworthiness with a scalable solution eliminating the need for federated infrastructure trust.
Trust is a critical component of any identity system. Several incidents in the past have demonstrated the existence of possible harm that can arise from misuse of people's personal information. Giving credible and provable reassurances to people is required to build trust and make people feel secure to use the electronic services offered by companies or governments on-line. However, when it comes to privacy, typical identity management systems like PKI fail to provide strong reassurances. For example, in these systems, the so-called "Identity Provider" is able to trace and link all communications and transactions of the users. Strong cryptographic protocols can be used to increase trust, by not letting such privacy violations be technically possible. Over the past years, a number of technologies have been developed to build Privacy Preserving Attribute-based Credentials (Privacy-ABCs) in a way that they can be trusted, like normal cryptographic certificates, while at the same time they protect the privacy of their holder [3]. Such Privacy-ABCs are issued just like ordinary cryptographic credentials (e.g., X.509 credentials) using a digital secret signature key. However, Privacy-ABCs allow their holder to transform them into a new token, in such a way that the privacy of the user is protected. Bringing more control on the user side, created an interesting discussion on the acceptance factors and the cost-benefit trade-offs involved in adopting such technologies, as perceived by users [1]. As technology is progressing rapidly and moving towards the pervasive world, not only citizens but also objects get increasingly connected. For example, today's vehicles are already connected and in the very near future they will also interact directly with each other and with the road infrastructure giving rise to a new domain called Cooperative Intelligent Transport Systems (C-ITS). C-ITS needs to be secured and a trust architecture needs to be in place in order to protect messages. This also includes the necessity of authentication and authorization of participating vehicles, ensuring that messages originate from genuine vehicles without making individual vehicles traceable throughout the system. So, a security and trust architecture featuring a public key infrastructure (PKI) has been specified. The practical C-ITS systems which are currently considered for deployment in Europe, the US and China take this approach to authentication by letting vehicles sign outgoing V2X messages with short-lived pseudonym certificates. Some degree of privacy is obtained by letting vehicles frequently change or rotate their certificates from a pool of pseudonyms. However, the architecture is complex and exhibits several shortcomings [2]. Similar to the experiences from the online world, we argue that the pressing need for establishing federated trust between services and devices in a dynamic network of vehicles, gateways, services and applications cannot be solely secured with common centralized solutions like PKIs. We identify the need to move towards scalable and decentralized solutions, eliminating the need for federated infrastructure trust. We discuss how this can be done by adopting emerging technologies, such as the intersection of distributed edge and fog computing with the new 5G-enabled smart connectivity networks, decentralized PKI architectures and trusted computing technologies in the automotive context.
Autonomous vehicles (AVs) are increasingly becoming part of the emerging Intelligent Transportation Systems (ITS) and they are positioned to advance smart mobility. To enable this, new on-board sensors collect and transmit growing types and quantities of data. This raises new and unique privacy considerations around what happens with this data. As the automotive industry becomes more data-driven, getting consumer privacy rights will become increasingly important for establishing trust and customer acceptance of this technology. At the same time, the algorithmic decision making in AVs raises several new ethical issues that can create new safety risks and discriminatory outcomes. In this paper we analyze what are the new privacy and data protection challenges that emerge in AVs and investigate the ethical and liability concerns surrounding algorithmic decision-making, highlighting research gaps and the need to mitigate these issues by acting swiftly.
Autonomous vehicles, as part of the emerging Intelligent Transportation Systems (ITS), are positioned to transform the future of mobility — a change enabled by new on-board sensors, as well as the exchange of information between vehicles and between vehicles and transport infrastructure. This raises new and unique privacy considerations around what happens with the data. As the automotive industry becomes more data-driven, getting consumer privacy rights will become increasingly important for establishing trust and customer acceptance of this technology. In this paper we analyze what are the new privacy and data protection challenges that emerge in this domain and we put forth directions of research initiatives for overcoming these challenges. We build the discussion around legal compliance, identity management, in-vehicle data recording, and anonymization of vehicle data. We then debate on the advantages brought forth by emerging technologies (ranging from the intersection of distributed edge and fog computing to new 5G-enabled smart connectivity networks) and how such innovations can fulfill advanced privacy requirements in automotive industry.
Over recent years, emphasis in secure V2X communications research has converged on the use of Vehicular Public Key Infrastructures (VPKIs) for credential management and privacy-friendly authentication services. However, despite the security and privacy guarantees offered by such solutions, there are still a number of challenges to be conquered. By reflecting on state-of-the-art PKI-based architectures, in this paper, we identify their limitations focusing on scalability, interoperability, pseudonym reusage policies and revocation mechanisms. We argue that in their current form such mechanisms cannot capture the strict security, privacy, and trust requirements of all involved stakeholders. Motivated by these weaknesses, we then proceed on proposing the use of trusted computing technologies as an enabler for more decentralized approaches where trust is shifted from the back-end infrastructure to the edge. We debate on the advantages offered and underline the specifis of such a novel approach based on the use of advanced cryptographic primitives, using Direct Anonymous Attestation (DAA) as a concrete example. Our goal is to enhance run-time security, privacy and trustworthiness of edge devices with a scalable and decentralized solution eliminating the need for federated infrastructure trust. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them.
Mobile Crowdsensing (MCS) has emerged as a new paradigm for data collection and knowledge representation, where people use their devices to interact with the environment and create a more accurate picture of their surroundings. In many MCS scenarios it is desirable to give micro-payments to contributors as an incentive for their participation. However, to further encourage participants to use the system, one important requirement is protection of user privacy. In this work we present a multi-attribute reverse auction mechanism as an efficient way to offer incentives to users by allowing them to determine their own price for the data they provide, but also as a way to motivate them to submit better quality data. Our auction protocol guarantees bidders' anonymity and suggests a new rewarding mechanism that enables winners to claim their reward without being linked to the data they contributed. We have analyzed our protocol and showed that it offers strong security and privacy guarantees in all phases of the auction process, from bidding to rewarding. Additionally, we have implemented the protocol using off-the-shelf cryptographic primitives; our experiments show that the protocol is scalable, it can be applied to a large class of auctions and remains efficient from both a computation and communication point of view so that it can be run to the users' mobile devices.
The sensor nodes in the network are forming independent network. The limited range sensors maintain the link up to destination in Mobile Ad hoc Network (MANET). In this network nodes are communicate in open medium and by that the communication among the mobile nodes are perform without any centralized authority that's why network security is one of the most important issue in MANET. There are many attackers in MANET like sinkhole attack drop the data packets in network with the support of neighbor attacker. To overcome the disputes, there is a need to build a prevailing security solution i.e. IDS (Intrusion Detection System) that achieves both extensive protection and desirable network performance. The proposed work analyze the profile of each node in network by that malicious effect information is retrieve and IDS is block the malicious activities of attacker. This work analyzes the effect of sinkhole attack through malicious nodes which is probable attacks in MANET The data packets do not reach the destination by that due to this attack, data loss will occur. The damage will be serious if malicious node in a network working as an attacker node absorbs all data packets delivered through them. In this research we proposed a simple IDS Algorithm against dropping attack and measure the network performance after applying IDS. We simulated dropping attacks in network simulator 2 (ns-2) and measured the packet loss in the presence of attacker and in presence of Intrusion Detection System against malicious attack. Our solution improved the 90% network performance in the presence of a packer dropping
Although in the last years there has been a growing amount of research in the field of privacy-enhancing technologies (PETs), they are not yet widely adopted in practice. In this paper we discuss the socioeconomical aspects of how users and service providers make decisions about adopting PETs. The analysis is based on our experiences from the deployment of Privacy-respecting Attribute-based Credentials (Privacy-ABCs) in a real-world scenario. In particular, we consider the factors that affect the adoption of Privacy-ABCs as well as the cost and benefit trade-offs involved in their deployment and usage, as perceived by both parties.
Zinaida Benenson合作论文数Laboratory for Dependable Distributed Systems at the University of Mannheim6
Felix Freiling合作论文数Computer Science 1 at University of Mannheim.3