Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Data privacy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Finding MIDDLE Ground: Scalable and Secure Distributed Learning

Edge computing methods allow devices to efficiently train a high-performing, robust, and personalized model for predictive tasks. However, these methods succumb to privacy and scalability concerns such as adversarial data recovery and expensive model communication. Furthermore, edge computing methods unrealistically assume that all devices train an identical model. In practice, edge devices have varying computational and memory constraints which may not allow certain devices to have the space or speed to train a specific model. To overcome these issues, we propose MIDDLE: a model independent distributed learning algorithm which allows heterogeneous edge devices to assist each other’s training while communicating only non-sensitive information. MIDDLE unlocks the ability for edge devices, regardless of computational or memory constraints, to assist each other even with completely different model architectures. Furthermore, MIDDLE does not require model or gradient communication which greatly reduces communication size and time. We prove that MIDDLE attains the optimal convergence rate O(1/sqrt(TM)) of stochastic gradient descent for convex and non-convex smooth optimization (for total iterations T and batch size M). Finally, our experimental results demonstrate that MIDDLE (even in non-IID data settings) attains robust and high-performing models without model or gradient communication.

Bornstein, Marc I.↗

Does class matter? Understanding differential pandemic recovery via a building typology

This study investigates the recovery of building-level footfall from the COVID-19 pandemic using privacy-preserving mobile devices-based footfall data within 60 downtown areas in the USA and Canada. Using clustering, we identify five distinct building typologies based on their characteristics, including rent, quality and recovery rates. The results reveal significant variation of recovery rates by building features. We find negative relationships with footfall recovery for both the percentage of office and remote work tenants and building quality. In contrast, buildings with traditional work tenants and retail functions achieve higher recovery rates. We also test the ‘flight to quality’ hypothesis via on our typology results. High-quality office buildings (Class A+) continue to have high rents but experience low physical footfall recovery, which suggests that this class is not as resilient as portrayed. The findings thus suggest the importance of considering both economic and footfall resilience in evaluating the performance of office buildings.

Covid-19↗

Non-urban mobile radio market demand forecast

A national nonmetropolitan land mobile traffic model for 1990-2000 addresses user classes, density classes, traffic mix statistics, distance distribution, geographic distribution, price elasticity, and service quality elasticity. Traffic demands for business, special industrial, and police were determined on the basis of surveys in 73 randomly selected nonurban counties. The selected services represent 69% of total demand. The results were extrapolated to all services in the non-SMSA areas of the contiguous United States. Radiotelephone services were considered separately. Total non-SMSA mobile radio demand (one way) estimates are given. General functional requirements include: hand portability, privacy, reduction of blind spots, two way data transmission, position location, slow scan imagery.

Castruccio, P. A.↗

Differentially Private Map Matching (DPMM) v1.0

Human mobility trajectories provide valuable information for developing mobility applications, as they contain diverse and rich information about the users. User mobility data is valuable for various applications such as intelligent transportation systems (ITS), commercial business models, and disease-spread models. However, such spatio-temporal traces may pose a threat to user privacy. GPS trajectories in their raw form are not suitable for transportation studies, as they require matching locations with nearest road links — a process called map-matching. This software implements a differential privacy (DP)-based map-matching algorithm, called DPMM, that generates link-level location trajectories in a privacy-preserving manner to protect users' origin destinations (OD) and travel paths. OD privacy is achieved by injecting Planar Laplace noise to the user OD GPS points. Travel-path privacy is provided with randomized travel path construction using exponential DP mechanism. The injected noise level is selected adaptively, by considering the link density of the location and the functional category of the localized links. For path privacy, our mechanism samples waypoints and selects candidate paths between waypoints. DPMM provides privacy effectively with respect to link density instead of other trajectory samples in the database compared to other privacy mechanisms. Compared to the different baseline models our DP-based privacy model offers closer query responses to the raw data in terms of individual and aggregate trajectory-level statistics with an average at absolute deviation from the baseline for individual statistics on ϵ = 1.0. Beyond individual trajectory statistics, the DPMM outperforms the other benchmark DP-based mechanisms on different aggregate statistics with up to 8x improvement in utility.

Peisert, Sean [Lawrence Berkeley National Laborato↗

A Survey on Privacy in Graph Neural Networks: Attacks, Preservation, and Applications

Graph Neural Networks (GNNs) have gained significant attention owing to their ability to handle graph-structured data and the improvement in practical applications. However, many of these models prioritize high utility performance, such as accuracy, with a lack of privacy consideration, which is a major concern in modern society where privacy attacks are rampant. To address this issue, researchers have started to develop privacy-preserving GNNs. Despite this progress, there is a lack of a comprehensive overview of the attacks and the techniques for preserving privacy in the graph domain. In this survey, we aim to address this gap by summarizing the attacks on graph data according to the targeted information, categorizing the privacy preservation techniques in GNNs, and reviewing the datasets and applications that could be used for analyzing/solving privacy issues in GNNs. We also outline potential directions for future research in order to build better privacy-preserving GNNs.

97 MATHEMATICS AND COMPUTING↗

Differentially Private Adaptive Noise Injection (DP-ANI) v1.0

Location data is collected from users continuously to understand their mobility patterns. Releasing the user trajectories may compromise user privacy. Therefore, the general practice is to release aggregated location datasets. However, private information may still be inferred from an aggregated version of location trajectories. Differential privacy (DP) protects the query output against inference attacks regardless of background knowledge. This software implements a differential privacy-based privacy model that protects the user's origins and destinations from being inferred from aggregated mobility datasets. This is achieved by injecting Planar Laplace noise to the user origin and destination GPS points. The noisy GPS points are then transformed into a link representation using a link-matching algorithm. Finally, the link trajectories form an aggregated mobility network. The injected noise level is selected using the Sparse Vector Mechanism. This DP selection mechanism considers the link density of the location and the functional category of the localized links. Compared to the different baseline models, including a k-anonymity method, our differential privacy-based aggregation model offers query responses that are close to the raw data in terms of aggregate statistics at both the network and trajectory-levels with maximum 9% deviation from the baseline in terms of network length.

Peisert, Sean [Lawrence Berkeley National Laborato↗

Human Research Program Human Health Countermeasures Element Cardiovascular Risks Standing Review Panel (SRP)

The Cardiovascular Risk Standing Review Panel (SRP) evaluated several cardiovascular risks associated with space flight along with the ongoing and emerging plans to study these issues and potentially propose and/or develop countermeasures. The areas of focus included: 1) The risk of cardiac rhythm problems during prolonged space flight, and 2) Issues related to the risk of orthostatic intolerance during re-exposure to gravity. An emerging area of concern is radiation associated vascular injury. The risk of cardiac rhythm disturbances has emerged based on case reports only. No systematic study of this risk has been published. However, concerns about this risk are heightened by the age range of astronauts, the structural changes in the heart that occur during space flight, and the potential shifts in fluids and electrolytes. The current plan is to use prolonged Holter monitor EKG records made as part of the "Integrated Cardiovascular SMO" in space to determine more about the frequency and magnitude of this problem and to link this data to complementary data from the nutrition group on electrolytes. The SRP was supportive of this approach. The SRP also felt that any data related to cardiovascular risk in space should be better coordinated with the medical screening data that all astronauts undergo at regular intervals. Additionally, while there are potential privacy issues related to this suggestion, many of the current barriers to better coordination of experimental and clinical data appear to reflect longstanding cultural traditions at NASA that need rethinking. The risk of orthostatic intolerance during re-exposure to gravity was seen by the SRP as an area supported by a wealth of published physiological evidence. The SRP also felt that moving forward with the planned approach to countermeasures was reasonable and that extensive additional hypothesis testing on the physiology of orthostatic intolerance was not needed at this time. There was support for developing ground based models of limited (e.g. 1/6 th) G environments on Earth that generated a number of ideas for consideration by NASA investigators.

Joyner, Michael↗

Evolution of the Next Exploration Toilet through Human-in-the-Loop (HITL) Testing

Human waste collection in space is a unique and necessary function that all crewmembers must perform. The variability in how each crewmember uses the toilet to urinate and defecate introduces complexities and challenges with regards to overall hardware design. Because of this variability, it is important to consider crew inputs in all aspects of a toilet design especially with regards to crew interfaces that could impact overall waste collection. Access to crew feedback is essential to the design process and should be considered early and often through the various design phases. In 2020, NASA started a project for the Human Landing System (HLS) program to develop a Government Furnished Equipment (GFE) toilet option. The project is known as the Lavatory On-Orbit (LOO). During the early development of the LOO, the project team conducted several crew evaluations to collect and summarize valuable crew feedback on system design, function, and overall usability to influence the next design iteration. Because every person could use the system differently in space, it was extremely important to collect and analyze the data in a very methodical manner to appropriately influence the design based on the evaluation results. Establishing a standard process ensures consistent data collection from one evaluation to another, helps to maintain privacy for each test subject’s inputs and removes any potential bias from test subject to test subject. To date, the team has completed four crew evaluations on prototypes for the different LOO hardware. This paper will summarize the methodology used to conduct the evaluations as well as how data was collected and analyzed. The paper will also provide details on each of the evaluations and how the design was updated based on the results.

toilet↗

Evolution of the Next Exploration Toilet Through Human-in-the-Loop (HITL) Testing

Human waste collection in space is a unique and necessary function that all crewmembers must perform. The variability in how each crewmember uses the toilet to urinate and defecate introduces complexities and challenges with regards to overall hardware design. Because of this variability, it is important to consider crew inputs in all aspects of a toilet design especially with regards to crew interfaces that could impact overall waste collection. Access to crew feedback is essential to the design process and should be considered early and often through the various design phases. In 2020, NASA started a project for the Human Landing System (HLS) program to develop a Government Furnished Equipment (GFE) toilet option. The project is known as the Lavatory On-Orbit (LOO). During the early development of the LOO, the project team conducted several crew evaluations to collect and summarize valuable crew feedback on system design, function, and overall usability to influence the next design iteration. Because every person could use the system differently in space, it was extremely important to collect and analyze the data in a very methodical manner to appropriately influence the design based on the evaluation results. Establishing a standard process ensures consistent data collection from one evaluation to another, helps to maintain privacy for each test subject’s inputs and removes any potential bias from test subject to test subject. To date, the team has completed four crew evaluations on prototypes for the different LOO hardware. This paper will summarize the methodology used to conduct the evaluations as well as how data was collected and analyzed. The paper will also provide details on each of the evaluations and how the design was updated based on the results.

toilet↗

Protecting Astronaut Medical Privacy: Review of Presentations and Publications for Attributability

Retrospective research and medical data collected on astronauts can be a valuable resource for researchers. This data can be requested from two separate NASA Archives. The Lifetime Surveillance of Astronaut Health (LSAH) holds astronaut medical data, and the Life Sciences Data Archive (LSDA) holds research data. One condition of use of astronaut research and medical data is the requirement that all abstracts, publications and presentations using this data must be reviewed for attributability. All final versions of abstracts, presentations, posters, and manuscripts must be reviewed by LSDA/LSAH prior to submission to a conference, journal, or other entities outside the Principal Investigator (PI) laboratory [including the NASA Export Control Document Availability Authorization (DAA) system]. If material undergoes multiple revisions (e.g., journal editor comments), the new versions must also be reviewed by LSDA/LSAH prior to re-submission to the journal. The purpose of this review is to ensure that no personally identifiable information (PII) is included in materials that are presented in a public venue or posted to the public domain. The procedures for submitting materials for review will be outlined. The process that LSAH/LSDA follows for assessing attributability will be presented. Characteristics and parameter combinations that often prompt attributability concerns will be identified. A published case report for a National Football League (NFL) player will be used to demonstrate how, in a population of public interest, a combination of information can result in inadvertent release of private or sensitive information.

Wear, M. L.↗

Evolution of the Next Exploration Toilet Through Human-in-the-Loop (HITL) Testing

Human waste collection in space is a unique and necessary function that all crewmembers must perform. The variability in how each crewmember uses the toilet to urinate and defecate introduces complexities and challenges with regards to overall hardware design. Because of this variability, it is important to consider crew inputs in all aspects of a toilet design especially with regards to crew interfaces that could impact overall waste collection. Access to crew feedback is essential to the design process and should be considered early and often through the various design phases. In 2020, NASA started a project for the Human Landing System (HLS) program to develop a Government Furnished Equipment (GFE) toilet option. The project is known as the Lavatory On-Orbit (LOO). During the early development of the LOO, the project team conducted several crew evaluations to collect and summarize valuable crew feedback on system design, function, and overall usability to influence the next design iteration. Because every person could use the system differently in space, it was extremely important to collect and analyze the data in a very methodical manner to appropriately influence the design based on the evaluation results. Establishing a standard process ensures consistent data collection from one evaluation to another, helps to maintain privacy for each test subject’s inputs and removes any potential bias from test subject to test subject. To date, the team has completed four rounds of crew evaluations with multiple crewmembers on prototypes for the different LOO subsystems. This paper will summarize the methodology used to conduct the evaluations as well as how data was collected and analyzed. The paper will also provide details on each of the evaluations and how the design was updated based on the results.

toilet↗

Evolution of the Next Exploration Toilet Through Human-in-the-Loop (HITL) Testing

Human waste collection in space is a unique and necessary function that all crewmembers must perform. The variability in how each crewmember uses the toilet to urinate and defecate introduces complexities and challenges with regards to overall hardware design. Because of this variability, it is important to consider crew inputs in all aspects of a toilet design especially with regards to crew interfaces that could impact overall waste collection. Access to crew feedback is essential to the design process and should be considered early and often through the various design phases. In 2020, NASA started a project for the Human Landing System (HLS) program to develop a Government Furnished Equipment (GFE) toilet option. The project is known as the Lavatory On-Orbit (LOO). During the early development of the LOO, the project team conducted several crew evaluations to collect and summarize valuable crew feedback on system design, function, and overall usability to influence the next design iteration. Because every person could use the system differently in space, it was extremely important to collect and analyze the data in a very methodical manner to appropriately influence the design based on the evaluation results. Establishing a standard process ensures consistent data collection from one evaluation to another, helps to maintain privacy for each test subject’s inputs and removes any potential bias from test subject to test subject. To date, the team has completed four rounds of crew evaluations with multiple crewmembers on prototypes for the different LOO subsystems. This paper will summarize the methodology used to conduct the evaluations as well as how data was collected and analyzed. The paper will also provide details on each of the evaluations and how the design was updated based on the results.

toilet↗

Modeling Grid Data Flows for Transmission and Distribution Operations: Review, Design, Next Steps

Operational scenarios of the power grids grow multifold to accommodate the diverse needs of both the utilities and end consumers, and the various other stakeholders in-between. To comprehensively model and apply analytics to support objectives and business functions of grid sectors, a reliable approach to characterize and design data flows is crucial. The flows bridge business functions with communications protocols, stakeholders such as the grid actors, and data interfaces comprising different data objects. Additionally, constraints applied to the flow such as cybersecurity, trust, privacy, and ownership among others intersect these entities, requiring the delineation of their interactions under different scenarios. This paper aims to not only highlight relevant research in the space of grid data flows, but also proposes, for the transmission-distribution sector, a novel modeling approach that marries the aforementioned entities: objectives, business functions, data interfaces, communication protocols, data stakeholders, and flow constraints. It elaborates on the design philosophy and the significance of each entity within the model and applies it to an example function of fault location, isolation and service restoration (FLISR). Finally, the next steps to extend the application of this data flow model for other practical operational scenarios are discussed.

Sundararajan, Aditya [ORNL] (ORCID:000000033577854↗

DP-TwoLevel: two-stage gradient subspace learning for differentially private federated learning

Federated learning (FL) enables collaborative model training across distributed data sources without sharing raw data, but faces fundamental challenges in communication efficiency and privacy. Differentially private (DP) training mitigates information leakage but introduces noise that degrades model performance, especially in high-dimensional settings. We propose DP-TwoLevel, a hierarchical gradient projection method that improves utility under fixed DP constraints by exploiting low-dimensional structure in model updates. Our approach learns a two-level PCA-based representation of gradients and applies DP noise in a reduced-dimensional subspace, thereby lowering the effective noise magnitude while preserving dominant signal components. We evaluate the method across three datasets (MNIST, Fashion-MNIST, CIFAR-10) and three privacy regimes (ϵ∈0.5, 1.0, 2.0). Across nine experimental settings, DP-TwoLevel consistently outperforms DP-FedAvg, achieving an average accuracy improvement of 9.44%, with larger gains observed in lower ϵ(higher-noise) regimes (up to +22.31%). We further analyze scalability across models ranging from 100K to 1.49M parameters and identify a variance-based success criterion: performance remains strong when the projection preserves more than 75% of gradient variance, degrades in a marginal regime (65–75%), and fails below this threshold. Our results demonstrate that structure-aware dimensionality reduction can significantly improve the privacy–utility tradeoff in FL without modifying formal privacy guarantees. We also provide empirical evidence of scaling limitations for global projections and motivate per-layer extensions for larger models.

Kotevska, Olivera [ORNL] (ORCID:0000000316772243)↗

Assessing Membership Inference Attacks under Distribution Shifts

Membership inference attacks (MIAs) exploit machine learning models to infer whether a data point was in the training set, posing significant privacy risks even with limited black-box access. These attacks rely on the attacker approximating the target model’s training distribution, yet the impact of distribution shifts between target and shadow models on MIA success remains underexplored. We systematically evaluate five types of distribution shifts —-cutout, jitter, Gaussian noise, label shift, and attribute shift —- at varying intensities. Our results reveal that these shifts affect MIA effectiveness in nuanced ways, with some reducing attack success while others exacerbate vulnerabilities, and the same shift can have opposite effects depending on the type of MIA. This highlights the complex interplay between distributional differences and attack performance, offering critical insights for improving model defenses against MIAs.

Shi, Yichuan [Massachusetts Institute of Technolog↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

air traffic privacy & authentication↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

ADS-B cybersecurity↗

Privacy Preservation from High-Performance Computing to Autonomous Science [Industrial and Governmental Activities]

High-Performance Computing (HPC) and Leadership-Class Supercomputing are driving forces behind scientific advancements, enabling researchers to tackle complex challenges in physics, chemistry, biology, and engineering. These systems power vast simulations and data analyses, fueling discoveries in fields ranging from materials science to climate modeling. However, their use often involves processing sensitive data—such as proprietary industry simulations, biomedical records, and national security computations—posing significant privacy concerns. In conclusion, this issue is amplified in collaborative environments like Department of Energy (DOE) user facilities, where HPC resources are shared across institutions to foster innovation.

Kotevska, Olivera [Oak Ridge National Laboratory (↗