research-article Open Access Share on Exploring the Profile of University Assessments Flagged as Containing AI-Generated Material Authors: Daniel Gooch The Open University The Open UniversitySearch about this author , Kevin Waugh The Open University The Open UniversitySearch about this author , Mike Richards The Open University The Open UniversitySearch about this author , Mark Slaymaker The Open University The Open UniversitySearch about this author , John Woodthorpe The Open University The Open UniversitySearch about this author Authors Info & Claims ACM InroadsVolume 15Issue 2June 2024pp 39–47https://doi.org/10.1145/3656478Published:10 May 2024Publication History 0citation0DownloadsMetricsTotal Citations0Total Downloads0Last 12 Months0Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Publisher SiteView all FormatsPDF
Cheating has been a long-standing issue in university assessments. However, the release of ChatGPT and other free-to-use generative AI tools has provided a new and distinct method for cheating. Students can run many assessment questions through the tool and generate a superficially compelling answer, which may or may not be accurate. We ran a dual-anonymous "quality assurance" marking exercise across four end-ofmodule assessments across a distance university computer science (CS) curriculum. Each marker received five ChatGPT-generated scripts alongside 10 student scripts. A total of 90 scripts were marked; every ChatGPTgenerated script for the undergraduate modules received at least a passing grade (> 40%), with all of the introductory module CS1 scripts receiving a distinction (> 85%). None of the ChatGPT-taught postgraduate scripts received a passing grade (> 50%). We also present the results of interviewing the markers and of running our sample scripts through a GPT-2 detector and the TurnItIn AI detector, which both identified every ChatGPT-generated script but differed in the number of false positives. As such, we contribute a baseline understanding of how the public release of generative AI is likely to significantly impact quality assurance processes. Our analysis demonstrates that in most cases, across a range of question formats, topics, and study levels, ChatGPT is at least capable of producing adequate answers for undergraduate assessment.
The overall aim in the development of the Local Ecological Footprinting Tool (LEFT) was to design a web‐based tool that could provide quickly obtained quantitative data on ecological risk to assist landowners when making land‐use change decisions. The Local Ecological Footprinting Tool works for almost any region in the world and uses freely available satellite imagery, biotic and abiotic data from existing global databases, models and algorithms to deliver a customised report for a selected area within one hour of job submission. Biotic data automatically obtained for a selected landscape includes terrestrial vertebrate and plant species occurrence data, information on their conservation status and remotely sensed vegetation productivity. Abiotic information obtained includes temperature, precipitation, water availability, insolation, topography, elevation, distribution of urban infrastructure and location of wetlands. The tool performs a number of analyses on the biotic and abiotic data to produce maps for the selected area at a 30 m resolution depicting land cover type, numbers of globally threatened terrestrial vertebrate and plant species, beta‐diversity of terrestrial vertebrates and plants, habitat intactness, wetland habitat connectivity, numbers of migratory species and vegetation resilience. Results are also aggregated to produce a summary map demonstrating areas of high and low ecological risk across the selected area. The Local Ecological Footprinting Tool has been designed to be intuitive to use, requiring no specialised software or user expertise. Input is extremely easy and requires the user to highlight the area of interest on a map or using grid co‐ordinates. Output is delivered via the web application and comprises a customised PDF containing the maps and a zip file of geographical information system (GIS) data for the area requested. Users may run an unlimited number of LEFT analyses and download reports free of charge. In addition to the free tool described in this paper, there is also a paid service: individual LEFT analyses can be upgraded for a charge to allow access to the geographically subsetted datasets generated for each report. These data are supplied as a zip file containing raster datasets for the layers in the LEFT analysis in GeoTIFF format. These can be opened and queried in a GIS software package.
Web-Based Social Networks (WBSNs) are used by millions of people worldwide. While WBSNs provide many benefits, privacy preservation is a concern. The management of access control can help to assure data is accessed by authorized users. However, it is critical to provide sufficient flexibility so that a rich set of conditions may be imposed by users. In this paper we coin the term user provenance to refer to tracing users actions to supplement the authorisation decision when users request access. For example restricting access to a particular photograph to those which have "liked" the owners profile. However, such a tracing of actions has the potential to impact the privacy of users requesting access. To mitigate this potential privacy loss the concept of translucency is applied. This paper extends SoNeUCON(ABC) model and presents SoNeUCON(ABC)Pro, an access control model which includes translucent user provenance. Entities and access control policies along with their enforcement procedure are formally defined. The evaluation demonstrates that the system satisfies the imposed goals and supports the feasibility of this model in different scenarios.
One of the key issues in computational biology is the way we integrate models and data, e.g. in model fitting, validation, or selection. Current approaches are typically ad-hoc and disconnected, and a more formal, integrated approach is urgently needed. A quantitative model should provide an unambiguous and testable description of a proposed mechanism. However, today the results obtained from model simulation and analysis are often not reproducible, and the models therefore are hard to re-use. Tasks such as comparing different hypotheses against experimental data, determining a model's suitability or limitations for a particular study, or incremental development of models, are still challenging and often performed inadequately. Various community standards for representing models themselves exist [e.g. 1,2] and so the models can be exchanged. However more information is needed. Virtual experiments are required in order to simulate in the models precisely the same protocols employed in generating the experimental data used to develop or test the models. Furthermore these protocol descriptions must also be sharable in standard formats (e.g. building on SED-ML [3]) with the models, in order to achieve effective re-use.
Access control policies are a crucial aspect of many security-critical software systems. It is generally accepted that the construction of access control policies is not a straightforward task. Further, any mistakes in the process have the potential to give rise both to security risks, due to the provision of inappropriate access, and to frustration on behalf of legitimate end-users when they are prevented from performing essential tasks. In this paper we describe a tool for constructing role-based access control (RBAC) policies, which are automatically checked for conformance with constraints described using predicate logic. These constraints may represent general healthiness conditions that should hold of all policies conforming to a general model, or capture requirements pertaining to a particular deployment.
In this article we report upon our experiences of developing Web-services based infrastructures within two e-health projects. The first—a small demonstrator project funded by the UK’s National Cancer Research Institute (NCRI)—is concerned with facilitating the aggregation of different types of data (specifically, MRI scans and histopathology slides) to aid the treatment of colorectal cancer; the second—a rather larger project funded by the UK’s Medical Research Council (MRC)—is concerned with the development of a virtual research environment to support neuro-imaging research. In both cases, the underlying infrastructures are being developed by a team that is based in Oxford; it is the experiences of this team that we report upon in this article. We also report upon how we have considered the future potential for our systems interoperating with other systems which are deployed within the UK’s National Health Service (NHS).
Cloud computing is a conceptual paradigm that is receiving a great deal of interest from a variety of major commercial organisations. By building systems which run within cloud computing infrastructures, problems related to scalability and availability can be reduced. At the time of writing, Amazon Web Services (AWS) [1] is one of the most widely used infrastructures. AWS consists of a number of different components, which can be used in combination or alone. One usage model is to use Elastic Compute Cloud instances to process information and to use the Simple Queue Service (SQS) to handle requests and responses.
The topic of access control has received a new lease of life in recent years as the need for assurance that the correct access control policy is in place is seen by many as crucial to providing assurance to individuals that their data is being treated appropriately. This trend is likely to continue with the increase in popularity of social networking sites and shifts to ‘cloud’-like commercial services: in both contexts, a clear statement of “who can do what” to one’s data is key in engendering trust. While approaches such as role-based access control (RBAC) provide a degree of abstraction, therefore increasing manageability and accessibility, policy languages such as the XML-based XACML provide greater degrees of expressibility—and, as a result, increased complexity. In this paper we explore how the mutual benefits of both RBAC and XACML, and Alloy and Z, may be used to best effect. RBAC is used as an accessible conceptual model; XACML is used as a language of implementation. Our concern is to facilitate the construction and reuse of role-based policies, which may subsequently be deployed in terms of XACML. We wish to provide assurance that these representations and transformations are, in some sense, correct. To this end, we consider formal models of both RBAC and XACML in terms of Z. We also describe how we have taken initial steps in utilising the Alloy Analyzer tool to provide a level of assurance that the two representations are consistent.
In keeping with the theme of this year's e-Science All Hands Meeting--past, present and future--we consider the motivation for, the current status of, and the future directions for, the technologies developed within the GIMI (Generic Infrastructure for Medical Informatics) project. This analysis provides insights into how some key problems in data federation may be addressed. GIMI was funded by the UK's Technology Strategy Board with the intention of developing a service-oriented framework to facilitate the secure sharing and aggregation of heterogeneous data from disparate sources to support a range of healthcare applications. The project, which was led by the University of Oxford, involved collaboration from the National Cancer Research Institute Informatics Initiative, Loughborough University, University College London, t+ Medical, Siemens Molecular Imaging and IBM UK.
The development of tools and technologies to facilitate appropriate and effective data sharing is becoming increasingly important in many academic disciplines. In particular, the 'data explosion' problem associated with the Life Sciences has been recognised by many researchers and commented upon widely, as have the associated data management problems. In this paper we describe how a middleware framework that supports the secure sharing and aggregation of data from heterogeneous data sources--developed initially to underpin the sharing of healthcare-related data--is being used to support Systems Biology research at the University of Oxford. As well as giving an overview of the framework and its application, we attempt to set our work within the wider context of the emerging challenges associated with data sharing within the Life Sciences.
The rise of service-oriented architectures and technology has, in recent years, started to lead to the opportunity for data sharing on a large-scale. In this paper we report upon how a service-oriented framework has been leveraged to support the development of a training application for radiologists. The application and framework have been developed separately - but sympathetically - with experience in both domains being leveraged to develop the prototype of an end-to-end training system. While the initial system utilises previously collected data, it is intended that in the future the system will interoperate with systems deployed within hospital environments.
We describe a framework for the secure sharing and aggregation of legacy data. The framework, sif (for service-oriented interoperability framework), has two key principles at its core: that it should be possible to expose data from any legacy data source, irrespective of the underlying technologies or data models, and that data owners should be afforded the opportunity for expressive access control policies. sif abstracts issues such as secure transport and heterogeneous federation from application developers via a Java API. Our particular focus in this paper is sif's plug-in mechanism, which gives rise to a simple and elegant means of facilitating interoperability.
Typically, access control policies are either static or depend on independently maintained external state to achieve some notion of dynamism. While it is possible to fully verify the properties of static policies, any reference to external state will necessarily limit the scope of such verification. In this paper we explore the feasibility of describing self-modifying policies which contain both rules for granting access and rules for the modification of the policy. Policy level constraints are used to define validity. Using these constraints it becomes possible to verify both the current state of the policy and any possible future states. A working prototype is described which utilises a relational model finder to perform the verification. The prototype is capable of generating instances of failure cases and presenting them via a simple user interface.
Role-based access control (RBAC) has emerged as the dominant access control paradigm for service-oriented systems, with this dominance being reflected by the popularity of RBAC both with the research community and with information technology vendors. RBAC's dominance was solidified in 2004 when an American National Standards Institute standard for RBAC was approved. In this paper, we consider some of the drawbacks of this standard and show how the formal description technique, Z, has been used to underpin a model of RBAC. The model builds on the work of Li et al. and adopts a modular approach. In particular, we consider the relationships between different types of inheritance within our model. We show our model can be used to define a notion of equivalence between different RBAC systems. Finally, we show how—via our model—a particular RBAC system can be normalized to produce a simpler—but semantically equivalent—representation. We illustrate this process via two examples.
The aggregation of data from disparate sources offers clear benefits for healthcare researchers and practitioners. Such aggregation, however, must satisfy ethical, legal and social requirements: data ownership must be respected; patient privacy must not be compromised; data storage and transfer must be secure; etc. In this paper we describe the query aspects of sif (for service-oriented interoperability framework), a system which has been developed to support healthcare-related applications that depend upon the secure aggregation of data from multiple legacy databases. Importantly, the system allows the federation of data stored in varying database management systems utilising varying schemas.
As an increasing amount of healthcare-related data is captured in both clinical and research contexts, the drive to provide appropriate access to such data becomes stronger. The very nature of such data means that simplistic approaches to authorisation—be they coarse-grained or role-based—are insufficient: the needs of the domain give rise to requirements for authorisation models capable of capturing fine-grained, expressive access control policies. We describe the development of a framework for the secure sharing and aggregation of healthcare-related data, called sif (for service-oriented interoperability framework). In particular, we concentrate on the access control aspects of the system and describe its utilisation of XACML in this respect.
Marian Petre合作论文数Centre for Research in Computing;Faculty of Maths & Computing;The Open University1