Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Privacy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Access control and privacy in large distributed systems

Large scale distributed systems consists of workstations, mainframe computers, supercomputers and other types of servers, all connected by a computer network. These systems are being used in a variety of applications including the support of collaborative scientific research. In such an environment, issues of access control and privacy arise. Access control is required for several reasons, including the protection of sensitive resources and cost control. Privacy is also required for similar reasons, including the protection of a researcher's proprietary results. A possible architecture for integrating available computer and communications security technologies into a system that meet these requirements is described. This architecture is meant as a starting point for discussion, rather that the final answer.

Leiner, B. M.↗

Access control and privacy in large distributed systems

Large scale distributed systems consists of workstations, mainframe computers, supercomputers and other types of servers, all connected by a computer network. These systems are being used in a variety of applications including the support of collaborative scientific research. In such an environment, issues of access control and privacy arise. Access control is required for several reasons, including the protection of sensitive resources and cost control. Privacy is also required for similar reasons, including the protection of a researcher's proprietary results. A possible architecture for integrating available computer and communications security technologies into a system that meet these requirements is described. This architecture is meant as a starting point for discussion, rather that the final answer.

Leiner, B. M.↗

Watching Without Seeing a Tool to Surveil Astronaut Health Outcomes While Maintaining Astronaut Medical Privacy

BACKGROUND The Privacy Act of 1974 regulates the use a nd disclosure of personally identifiable information by US Federal agencies. The Act applies to biographical, financial, a nd other identity-linked information, a s well a s personal health information (PHI). As such, the use of astronaut PHI is limited to authorized personnel for preapproved uses, with data reporting often limited to aggregated information about groups. These limitations on the use a nd reporting of astronaut PHI complicates surveillance efforts, wherein epidemiologists a t the National Aeronautics and Space Administration (NASA)monitor the incidence of targeted health conditions in the astronaut population, or to discover emerging trends of aging and disease. Stratification on one or more covariates –particularly time-period, sex, a nd mission participation –can lead to extremely small datasets such that the reporting of results is potentially attributable to individuals. An additional challenge is the small size of the astronaut population, both in terms of numbers of individuals a s well a s in terms of density of exposure time. Such small datasets yield volatile rate estimates that are difficult to interpret. To a id the epidemiological surveillance efforts, a surveillance tool is required that can (a) satisfy the need for rapid computation of condition-specific incidence and mortality rates; (b) improve the statistical estimates of these estimated rates; and (c) maintain astronaut privacy. Here we describe a nd demonstrate such a tool. METHODS We devised a system that models incidence a nd mortality rates rather than calculating them directly. This ha s the advantage of using all the available data to derive the estimates, lea ding to rates that a re not attributable to any one individual, a nd a re a s numerically stable a s they can be given the extremely limited data. The system models disease endpoints using a Poisson regression model with exposure density (measured in person-years) a s a n offset term. By doing so the model is estimating event counts per person-year, equivalent to modeling the rates directly. It uses a standard (pre-specified)set of covariates; the system does not engage in “model-building” as model parsimony is not the goa l. Instead, it is explicitly recognized that if a covariate is not statistically significant a nd not a confounder then it will likely have very little effect on the estimate of the incidence a nd mortality rates. Users are able to specify the disease endpoint of interest and the covariates over which they would like to stratify. The system then uses the resulting model to compute the estimated rates for the user-chosen configuration of variables as visualizes those either over an age range within a specified time-period, or over time for astronauts with a specified age range. RESULTS The first iteration of the tool computes incidence a nd mortality rates for cardiovascular conditions and cancers. Code ha s been developed to retrieve the appropriate data from the IMPALA analysis platform, compute the models for incidence a nd mortality, a nd then use those models to generate the corresponding rate curves. A companion graphical user interface allows the user to specify the curves and visualize the results. CONCLUSIONS It is important to note that the rapid surveillance tool described here is neither meant to be a definitive assessment of the incidence or mortality of any particular disease or condition in the astronaut population, nor is it meant to be used for research purposes. Rather, it is meant as an early indicator that in-depth investigation may be warranted. By automating a repetitive process and leveraging carefully curated astronaut health outcomes, the tool makes possible a rapid “first look” into known areas of concern, and, if used judiciously, may surface new areas of concern for long-term astronaut health. This work is supported in part by the Translational Research Institute for Space Health (TRISH) through NASA Cooperative Agreement NNX16AO69A.

R J Reynolds↗

Privacy-Preserving Control of Partitioned Energy Resources

Distributed energy resources are an increasingly important part of the electric grid. We examine the problem of partitioning a distributed energy resource among many users while providing privacy to them. In this model, clients can send requests to a server, the server can verify that the requests are valid and aggregate them, but it cannot see the actual values in the requests. Without privacy, each user is forced to reveal their daily schedule or energy use. Energy resources add a novel challenge that prior systems do not address: they require verifying limits on private power (a rate over time) and energy (a sum) values. Furthermore, the cryptographic mechanisms must run on embedded energy control systems. We describe Weft, a novel cryptographic system that verifies both power (rate) and energy (integral) constraints on private client values and aggregates them. The key insight behind the approach is to rely on additively homomorphic secret shares, which allows servers to compute sums from rates. We present 3 cryptographic proof systems with different system trade-off for embedded systems: bit-splitting proofs minimize memory use, sorting proofs minimize computation, and commitment proofs minimize network communication. Using bit-splitting proofs, it takes an IoT client using a CortexM microcontroller 4 minutes of compute time to privately control its share of an energy resource for a day at 20s granularity.

Laufer, Evan↗

Privacy-Protected Simultaneous Provision of Energy and Primary Frequency Control Reserve

This paper investigates a Mixed Integer Linear Programming (MILP) model for simultaneous scheduling of energy and primary frequency control reserve. Given the model’s unique structure and growing concerns about privacy, we adopt Dantzig-Wolfe Decomposition (DWD) algorithm to solve the problem in a decentralized fashion while obfuscating the privacy of the energy and reserve resources. Additionally, we present a novel criterion for checking the model’s feasibility. Finally, simulation results are given and discussed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resource-Adaptive Federated Text Generation with Differential Privacy

In cross-silo federated learning (FL), sensitive text datasets remain confined to local organizations due to privacy regulations, making repeated training for each downstream task both communication-intensive and privacy-demanding. A promising alternative is to generate differentially private (DP) synthetic datasets that approximate the global distribution and can be reused across tasks. However, pretrained large language models (LLMs) often fail under domain shift, and federated finetuning is hindered by computational heterogeneity: only resource-rich clients can update the model, while weaker clients are excluded, amplifying data skew and the adverse effects of DP noise. We propose a flexible participation framework that adapts to client capacities. Strong clients perform DP federated finetuning, while weak clients contribute through a lightweight DP voting mechanism that refines synthetic text. To ensure the synthetic data mirrors the global dataset, we apply control codes (e.g., labels, topics, metadata) that represent each client’s data proportions and constrain voting to semantically coherent subsets. This two-phase approach requires only a single round of communication for weak clients and integrates contributions from all participants. Experiments show that our framework improves distribution alignment and downstream robustness under DP and heterogeneity.

Wang, Jiayi [ORNL]↗

Privacy Preservation from High-Performance Computing to Autonomous Science [Industrial and Governmental Activities]

High-Performance Computing (HPC) and Leadership-Class Supercomputing are driving forces behind scientific advancements, enabling researchers to tackle complex challenges in physics, chemistry, biology, and engineering. These systems power vast simulations and data analyses, fueling discoveries in fields ranging from materials science to climate modeling. However, their use often involves processing sensitive data—such as proprietary industry simulations, biomedical records, and national security computations—posing significant privacy concerns. In conclusion, this issue is amplified in collaborative environments like Department of Energy (DOE) user facilities, where HPC resources are shared across institutions to foster innovation.

Kotevska, Olivera [Oak Ridge National Laboratory (↗

Microcam: A Low Power and Privacy Preserving Multi-modal Platform for Occupancy Detection (Final Report)

Heating, ventilation, and air conditioning (HVAC) consumes a significant portion of the energy used in buildings. Much of this is wasted energy, used when buildings are either not occupied at all, or occupied well under their maximum design conditions. This project has focused on residential occupancy detection to autonomously control HVAC systems and save energy. Limitations of existing occupancy sensors include one or more of the following: (i) they employ sensors or algorithms that are not able to detect stationary occupants; (ii) they cannot classify the source of the motion (such as a pet); (iii) depending on the camera resolution and employed algorithms, they do not allow for embedded or onboard computation, and require external or cloud-based processing; (iv) many algorithms developed for camera-based systems are sensitive to lighting changes, and thus prone to missed detections or false alarms; (v) Most existing systems depend on adjustment of settings for different scenarios, complicating self-commissioning; (vi) they cannot provide high enough accuracy; (vii) they are costly; (viii) they are not battery-powered, thus limiting ease of use and installation. In this project, Syracuse University and its partner SRI have developed a low-cost, high accuracy, standalone residential occupancy sensing platform, referred to as the MicroCam, to address all of the aforementioned challenges. MicroCam can operate on typical alkaline batteries without relying on the “cloud” or external computing resources, and consists of low-power, Artificial Intelligence (AI)-based, IoT platforms. Each platform has multi-modal sensors and can process motion, audio and video data, and send binary occupancy result to a lead platform. All sensor data is processed locally on platforms, and the only transmitted data is the binary occupancy state. In addition, preliminary work has been done on images wherein occupants are not discernable. Thus, MicroCam is a standalone solution preserving privacy of the occupants.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Snowflake: An Adaptive Energy and Delay Efficient Scheme for Source Location Privacy in Wireless Sensor Networks

Wireless Sensor Networks (WSNs) consist of a number of resource-constrained sensor nodes and a designated node called a sink, which collects data from the sensor nodes. A WSN can be used in numerous applications such as subject tracking and monitoring, where it is often desirable to keep the location of the subject private. In these types of applications, an adversary can locate the monitored subject, if a location privacy protection scheme is not applied. In this paper, we propose an adaptive energy and delay efficient scheme, called Snowflake, that conceals the location of subjects from a global adversary. Snowflake can be adapted to make the delivery delay smaller, or to make the packet overhead low. The simulation results show that Snowflake performs better than an existing algorithm.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity and Privacy Aspects of Smart Contracts in the Energy Domain

Smart contracts (SCs) are a set of logical procedures that can run by individual peers participating within a Distributed Ledger Technology (DLT) network. By design, smart contracts inherit many of the benefits of DLT, including its immutability, scalability, and security properties. Nevertheless, they may introduce additional attack vectors, which can lead to cybersecurity explorations that could jeopardize the end-application ability to operate as intended or result in data leaks, and privacy violations. In this work, an exploration of known problems, and possible attack scenarios will be presented. This is followed by a set of proposed best practices and mitigation strategies that are intended to assist developers, researchers, and other relevant stakeholders to develop secure SC implementations.

Sebastian Cardenas, David J.↗

Low power and privacy preserving sensor platform for occupancy detection

A low-cost, low-power, stand-alone sensor platform having a visible-range camera sensor, a thermopile array, a microphone, a motion sensor, and a microprocessor that is configured to perform occupancy detection and counting while preserving the privacy of occupants. The platform is programmed to extract shape/texture from images in spatial domain; motion from video in time domain; and audio features in frequency domain. Embedded binarized neural networks are used for efficient object of interest detection. The platform is also programmed with advanced fusion algorithms for multiple sensor modalities addressing dependent sensor observations. The platform may be deployed for (i) residential use in detecting occupants for autonomously controlling building systems, such as HVAC and lighting systems, to provide energy savings, (ii) security and surveillance, such as to detect loitering and surveil places of interest, (iii) analyzing customer behavior and flows, (iv) identifying high performing stores by retailers.

Velipasalar, Senem↗

Faster approximate subgraph counts with privacy

One of the most common problems studied in the context of differential privacy for graph data is counting the number of non-induced embeddings of a subgraph in a given graph. These counts have very high global sensitivity. Therefore, adding noise based on powerful alternative techniques, such as smooth sensitivity and higher-order local sensitivity have been shown to give significantly better accuracy. However, all these alternatives to global sensitivity become computationally very expensive, and to date efficient polynomial time algorithms are known only for few selected subgraphs, such as triangles, k-triangles, and k-stars. In this paper, we show that good approximations to these sensitivity metrics can be still used to get private algorithms. Using this approach, we much faster algorithms for privately counting the number of triangles in real-world social networks, which can be easily parallelized. We also give a private polynomial time algorithm for counting any constant size subgraph using less noise than the global sensitivity; we show this can be improved significantly for counting paths in special classes of graphs

Nguyen, Dung↗

A Perspective on Data and Privacy for AI in Healthcare [Industrial and Governmental Activities]

As large language models continue to push the bounds of AI model size, they are also being trained on unprecedented volumes of data. While individual hospitals are estimated to produce petabytes of data per year, only a small fraction is currently being used for developing AI models. Additionally, with such data resources available, healthcare is well-positioned to benefit from the current trends in AI. Moreover, the inherently multi-modal and longitudinal nature of clinical data – from omics to imaging to unstructured notes – provides a fertile ground for the development and application of cutting-edge architectures like foundation models.

Gounley, John [Oak Ridge National Laboratory (ORNL↗