Share No More Than the Request Requires: Federated Disclosure for Perspective-Aware AI
This paper introduces Provenance Preserving Chronicles (PPC), a federated protocol that empowers users to maintain data sovereignty by transforming their personal information into temporal knowledge graphs and enforcing a "minimum-necessary disclosure" principle to share only strictly authorized, provenance-linked context with third parties.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine your digital life as a massive, ever-growing scrapbook. Every photo you take, every text you send, and every doctor's visit you have gets pasted into this book. Right now, most of the world's big tech companies act like they own the scrapbook. They keep it in a giant, locked vault, and when you want to show a friend a picture of your cat, you have to hand over the whole book—or at least let them peek at the whole thing. This is risky because if the vault gets hacked, or if the company decides to sell your secrets, your entire life is exposed.
To fix this, scientists are building a new kind of digital identity where you hold the scrapbook. In this new world, your data isn't a giant lump; it's broken down into tiny, organized snapshots called "Situation Graphs." Think of these as individual pages in your scrapbook, each capturing a specific moment in time with labels like "at the park," "eating pizza," or "feeling tired." When you stack all these pages together in order, they form a "Chronicle"—a complete, time-traveling story of who you are. The big question this paper tackles is: How do you let someone ask a specific question about your story (like "What medicine are you taking?") without accidentally handing them your entire scrapbook, including your diary entries about your crush or your bank statements?
The authors of this paper, Sourena Khanzadeh and his team, propose a clever solution called Provenance Preserving Chronicles (PPC). They suggest a system that acts like a super-smart, strict librarian who only hands you the exact page you need, nothing more.
Here is how their "librarian" works, using a playful analogy:
Imagine you are a doctor trying to figure out if a patient's new heart medication might clash with their old allergy medicine. You don't need to see the patient's entire life story. You don't need to know what they had for breakfast three years ago, or that they once wrote a sad poem about a broken heart. You just need the specific pages about their current meds and allergies.
In the old way, the patient might have to email you a PDF of their entire medical history. In the PPC system, the patient's "Chronicle" stays safely locked on their own device (their "sovereign" home). When you, the doctor's agent, send a request, it doesn't ask for "everything." It asks for a specific "evidence subgraph."
Think of the Chronicle as a giant, tangled ball of yarn where every knot is a piece of data. The PPC system is a robot that can instantly untangle only the red string (the meds) and the blue string (the allergies) that are connected to your question. It cuts away the green string (the poetry) and the yellow string (the bank records) before it even leaves the patient's house.
The paper introduces a two-step dance to make sure this happens safely:
- The Text First: The librarian (the system) sends you a summary written in plain text, like "The patient is taking Warfarin and is allergic to Penicillin." Crucially, this text comes with a "receipt" or a pointer that says, "I got this from the June 2024 visit page."
- The Artifact Later: If you really need to see the actual photo of the prescription bottle or the audio recording of the doctor's note, you have to ask for it specifically. The patient then has to give a second, explicit "Yes, I approve this specific file" before it is released. This prevents the system from accidentally dumping a whole folder of files just because you asked one question.
The researchers tested this idea in two very different worlds: medicine and law.
- In the medical scenario, they showed how a cardiologist could get a patient's heart medication list without accidentally seeing their psychiatric therapy notes. The system successfully filtered out the "psychiatric" pages because the doctor's request was only about "drug interactions," not mental health.
- In the legal scenario, they showed how a lawyer could ask for emails about a specific contract without getting privileged notes between the company and their own lawyers. The system knew to hide the "privileged" pages even if they were attached to the same email chain.
However, the paper is careful not to promise that this is a magic wand that solves every problem. The authors admit that while the system is great at finding the smallest set of facts needed to answer a question, sometimes "smallest" isn't always "most helpful." For example, if a doctor asks about a medication, the system might strip away the reason the medication was prescribed (like a heart rhythm issue) because the question didn't explicitly ask for the diagnosis. The paper suggests that while the system is mathematically efficient at hiding secrets, it might sometimes hide too much context that a human expert actually needs to make a good decision.
The team also warns that this isn't a "blockchain" solution in the traditional sense. They argue that putting this data on a giant, shared public ledger (like Bitcoin) is the wrong approach because it forces everyone to copy everyone else's data. Instead, they propose a "federated" approach where data stays on your own device, and only the tiny, approved snippets travel across the network.
In short, this paper suggests a new way to share our digital lives: Share no more than the request requires. It's like having a conversation where you only answer the specific question asked, rather than telling your whole life story just because someone asked, "How are you?" The authors have built a blueprint for this system, showing it works in theory and in simulated scenarios, but they note that the real challenge remains: figuring out exactly how to define "enough" information so that we stay safe without losing the context we need to be helpful.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.