{"id":625052,"date":"2023-04-03T09:49:25","date_gmt":"2023-04-03T14:49:25","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/04\/03\/inside-the-bitter-campus-privacy-battle-over-smart-building-sensors\/"},"modified":"2023-04-03T09:49:25","modified_gmt":"2023-04-03T14:49:25","slug":"inside-the-bitter-campus-privacy-battle-over-smart-building-sensors","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/04\/03\/inside-the-bitter-campus-privacy-battle-over-smart-building-sensors\/","title":{"rendered":"Inside the bitter campus privacy battle over smart building sensors"},"content":{"rendered":"<div>\n<div>\n<header id=\"inside-the-bitter-campus-privacy-battle-over-smart-building-sensors\">\n<div>\n<div>\n<p>These computer scientists were trying to create privacy-preserving smart sensors. But then they were accused of violating their colleagues\u2019 privacy.<\/p>\n<\/div>\n<p><figure><span><video autoplay muted loop src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/03\/FINAL2.mp4\" playsinline><\/video><\/span><figcaption><span>Ari Liloan<\/span><\/figcaption><\/figure>\n<\/p>\n<\/div>\n<\/header>\n<\/div>\n<div id=\"content--body\">\n<div>\n<p>When computer science students and faculty at Carnegie Mellon University\u2019s Institute for Software Research returned to campus in the summer of 2020, there was a lot to adjust to.\u00a0<\/p>\n<p>Beyond the inevitable strangeness of being around colleagues again after months of social distancing, the department was also moving into a brand-new building: the 90,000-square-foot, state-of-the-art TCS Hall.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>The hall\u2019s futuristic features included carbon dioxide sensors that automatically pipe in fresh air, a rain garden, a yard for robots and drones, and experimental super-sensing devices called Mites. Mounted in more than 300 locations throughout the building, these light-switch-size devices can measure 12 types of data\u2014including motion and sound. Mites were embedded on the walls and ceilings of hallways, in conference rooms, and in private offices, all as part of a research project on smart buildings led by CMU professor Yuvraj Agarwal and PhD student Sudershan Boovaraghavan and including another professor, Chris Harrison.\u00a0<\/p>\n<p>\u201cThe overall goal of this project,\u201d Agarwal explained at an April 2021 town hall meeting for students and faculty, is to \u201cbuild a safe, secure, and easy-to-use IoT [Internet of Things] infrastructure,\u201d referring to a network of sensor-equipped physical objects like smart light bulbs, thermostats, and TVs that can connect to the internet and share information wirelessly.\u00a0<\/p>\n<p>Not everyone was pleased to find the building full of Mites. Some in the department felt that the project violated their privacy rather than protected it. In particular, students and faculty whose research focused more on the social impacts of technology felt that the device\u2019s microphone, infrared sensor, thermometer, and six other sensors, which together could at least sense when a space was occupied, would subject them to experimental surveillance without their consent.\u00a0<\/p>\n<p>\u201cIt\u2019s not okay to install these by default,\u201d says David Widder, a final-year PhD candidate in software engineering, who became one of the department\u2019s most vocal voices against Mites. \u201cI don\u2019t want to live in a world where one\u2019s employer installing networked sensors in your office without asking you first is a model for other organizations to follow.\u201d\u00a0<\/p>\n<div>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/04\/GettyImages-1310253517.jpeg?w=2342\" alt=\"aerial view of students walking past the Walk to the Sky Monument in Pittsburgh Carnegie Private University\"><figcaption>Students pass by the Walk to the Sky monument on Carnegie Mellon&#8217;s campus.<\/figcaption><p>GETTY IMAGES<\/p>\n<\/figure><\/div>\n<p>All technology users face similar questions about how and where to draw a personal line when it comes to privacy. But outside of our own homes (and sometimes within them), we increasingly lack autonomy over these decisions. Instead, our privacy is determined by the choices of the people around us. Walking into a friend\u2019s house, a retail store, or just down a public street leaves us open to many different types of surveillance over which we have little control.\u00a0<\/p>\n<p>Against a backdrop of skyrocketing <a href=\"https:\/\/www.nytimes.com\/2022\/08\/24\/podcasts\/the-daily\/workplace-surveillance-productivity-tracking.html\">workplace surveillance<\/a>, prolific <a href=\"https:\/\/policyreview.info\/concepts\/datafication\">data collection<\/a>, increasing <a href=\"https:\/\/www2.deloitte.com\/us\/en\/pages\/technology-media-and-telecommunications\/articles\/cyber-risk-in-an-internet-of-things-world-emerging-trends.html\">cybersecurity risks<\/a>, rising concerns about<a href=\"https:\/\/www.technologyreview.com\/2022\/12\/19\/1065306\/roomba-irobot-robot-vacuums-artificial-intelligence-training-data-privacy\/\"> privacy and smart<\/a> technologies, and fraught power dynamics around<a href=\"https:\/\/www.insidehighered.com\/blogs\/higher-ed-gamma\/academic-freedom-under-attack\"> free speech in academic institutions<\/a>, Mites became a lightning rod within the Institute for Software Research.<\/p>\n<p>Voices on both sides of the issue were aware that the Mites project could have an impact far beyond TCS Hall. After all, Carnegie Mellon is a top-tier research university in science, technology, and engineering, and how it handles this research may influence how sensors will be deployed elsewhere. \u201cWhen we do something, companies \u2026 [and] other universities listen,\u201d says Widder.<\/p>\n<p>Indeed, the Mites researchers hoped that the process they\u2019d gone through \u201ccould actually be a blueprint for smaller universities\u201d looking to do similar research, says Agarwal, an associate professor in computer science who has been developing and testing machine learning for IoT devices for a decade.<\/p>\n<\/p><\/div>\n<div>\n<p>But the crucial question is what happens if\u2014or when\u2014the super-sensors graduate from Carnegie Mellon, are commercialized, and make their way into smart buildings the world over.\u00a0<\/p>\n<p>The conflict is, in essence, an attempt by one of the world\u2019s top computer science departments to litigate thorny questions around privacy, anonymity, and consent. But it has deteriorated from an academic discussion into a bitter dispute, complete with accusations of bullying, vandalism, misinformation, and workplace retaliation. As in so many conversations about privacy, the two sides have been talking past each other, with seemingly incompatible conceptions of what privacy means and when consent should be required.\u00a0<\/p>\n<p>Ultimately, if the people whose research sets the agenda for technology choices are unable to come to a consensus on privacy, where does that leave the rest of us?\u00a0<\/p>\n<h3><strong>The future, according to Mites<\/strong><\/h3>\n<p>The Mites project was based on two basic premises: First, that buildings everywhere are already collecting data without standard privacy protections and will continue to do so. And second, that the best solution is to build better sensors\u2014more useful, more efficient, more secure, and better-intentioned.<\/p>\n<p>In other words, Mites.\u00a0\u00a0<\/p>\n<p>\u201cWhat we really need,\u201d Agarwal explains, is to \u201cbuild out security-, privacy-, safety-first systems \u2026 make sure that users have trust in these systems and understand the clear value proposition.\u201d\u00a0<\/p>\n<p>\u201cI would rather [we] be leading it than Google or ExxonMobil,\u201d adds Harrison, an associate professor of human-computer interaction and a faculty collaborator on the project, referring to sensor research. (Google funded early iterations of the research that led to Mites, while JPMorgan Chase is providing \u201cgenerous support of smart building research at TCS Hall,\u201d as noted on plaques hung around the building.)<\/p>\n<p>Mites\u2014the name refers to both the individual devices and the overall platform\u2014are all-in-one sensors supported by a hardware stack and on-device data processing. While Agarwal says they were not named after the tiny creature, the logo on the project\u2019s <a href=\"http:\/\/mites.io\" data-type=\"URL\" data-id=\"mites.io\" target=\"_blank\" rel=\"noopener\">website<\/a> depicts a bug.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>According to the researchers, Mites represent a significant improvement over current building sensors, which<strong> <\/strong>typically have a singular purpose\u2014like motion detectors or thermometers. In addition, many smart devices today often only working in isolation or with specific platforms like Google\u2019s Nest or Amazon\u2019s Alexa; they can\u2019t interact with each other.\u00a0\u00a0\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/04\/DSC_0841-redacted.jpeg?w=2500\" alt=\"\"\"\"><figcaption>A Mites sensor installed in a wall panel in TCS Hall.<\/figcaption><\/figure>\n<p>Additionally, current IoT systems offer little transparency about exactly what data is being collected, how it is being transmitted, and what security protocols are in place\u2014while erring on the side of over-collection.\u00a0<\/p>\n<p>The researchers hoped Mites would address these shortcomings and facilitate new uses and applications for IoT sensors. For example, microphones on Mites could help students find a quiet room to study, they said\u2014and Agarwal suggested at the town hall meeting in April 2021 that the motion sensor could tell an office occupant whether custodial staff were actually cleaning offices each night. (The researchers have since said this was a suggested use case specific to covid-19 protocols and that it could help cleaning staff focus on high-traffic areas\u2014but they have moved away from the possibility.)<\/p>\n<p>The researchers also believe that in the long term, Mites\u2014and building sensors more generally\u2014are key to environmental sustainability. They see other, more ambitious use cases too. A university <a href=\"https:\/\/sc.cs.cmu.edu\/research-detail\/144-mites\">write-up describes<\/a> this scenario: In 2050, a woman starts experiencing memory loss. Her doctor suggests installing Mites around her home to \u201cconnect to \u2026 smart speakers and tell her when her laundry is done and when she\u2019s left the oven on\u201d or to evaluate her sleep by noting the sound of sheets ruffling or nighttime trips to the bathroom. \u201cThey are helpful to Emily, but even more helpful to her doctor,\u201d the article claims.<\/p>\n<p>As multipurpose devices integrated with a platform, Mites were supposed to solve all sorts of problems without going overboard on data collection. Each device contains nine sensors that can pick up all sorts of ambient information about a room, including sound, light, vibrations, motion, temperature, and humidity\u2014a dozen different types of data in all. To protect privacy, it does not capture video or photos.<\/p>\n<p>The CMU researchers are not the first to attempt such a project. An IoT research initiative out of the Massachusetts Institute of Technology, similarly called MITes, designed portable sensors to collect environmental data like movement and temperature. It ran from 2005 to 2016, primarily as part of <a href=\"http:\/\/alumni.media.mit.edu\/~emunguia\/pdf\/PlaceLab.pdf\">PlaceLab<\/a>, a experimental laboratory modeled after an apartment in which carefully vetted volunteers consented to live and have their interactions studied. The MIT and CMU projects are unrelated. (MIT Technology Review is funded in part by MIT but maintains editorial independence.)<\/p>\n<p>The Carnegie Mellon researchers say the Mites system extracts only some of the data the devices collect, through a technical process called \u201cfeaturization.\u201d This should make it more difficult to trace, say, a voice back to an individual.\u00a0<\/p>\n<p>Machine learning\u2014which, through a technique called edge computing, would eventually take place on the device rather than on a centralized server\u2014then recognizes the incoming data as the result of certain activities. The hope is that a particular set of vibrations could be translated in real time into, for example, a train passing by.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>The researchers say that featurization and other types of edge computing will make Mites more privacy-protecting, since these technologies minimize the amount of data that must be sent, processed, and stored in the cloud. (At the moment, machine learning is still taking place on a separate server on campus.)<\/p>\n<p>\u201cOur vision is that there\u2019s one sensor to rule them all, if you\u2019ve seen <em>Lord of the Rings<\/em>. The idea is rather than this heterogeneous collection of sensors, you have one sensor that\u2019s in a two-inch-by-two-inch package,\u201d Agarwal explained in the April 2021 town hall, according to a recording of the meeting shared with MIT Technology Review.\u00a0<\/p>\n<p>But if the departmental response is any indication, maybe a ring of power that let its wearer achieve domination over others wasn\u2019t the best analogy.\u00a0<\/p>\n<h3><strong>A tense town hall<\/strong><\/h3>\n<p>Unless you are looking for them, you might not know that the bright and airy TCS Hall, on the western edge of Carnegie Mellon\u2019s Pittsburgh campus, is covered in Mites devices\u2014314 of them as of February 2023, according to Agarwal.\u00a0<\/p>\n<p>But look closely, and they are there: small square circuit boards encased in plastic and mounted onto standard light switch plates. They\u2019re situated inside the entrances of common rooms and offices, by the thermostats and light controls, and in the ceilings.\u00a0<\/p>\n<p>The only locations in TCS Hall that are Mites-free, in fact, are the bathrooms\u2014and the fifth floor, where Tata Consultancy Services, the Indian multinational IT company that donated $35 million to fund the building bearing its name, runs a research and innovation center. (A spokesperson said, \u201cTCS is not involved in the Mites project.\u201d)<\/p>\n<p>Widder, whose PhD thesis focuses on how to help AI developers think about their responsibility for the harm their work could cause, remembers finding out about the Mites sensors in his office sometime in fall of 2020. And once he noticed them, he couldn\u2019t unsee the blinking devices mounted on his wall and ceiling, or the two on the hallway ceiling just outside his door.\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/04\/DSC_0744.jpeg?w=2500\" alt><figcaption>A Mites sensor installed on the ceiling in TCS Hall<\/figcaption><\/figure>\n<p>Nor was Widder immediately aware of how to turn the devices off; they did not have an on-off switch. (Ultimately, his attempts to force that opt-out would threaten to derail his career.)<\/p>\n<\/div>\n<div>\n<p>This was a problem for the budding tech ethicist. Widder\u2019s academic work explores how software developers think about the ethical implications of the products that they build; he\u2019s particularly interested in helping computer scientists understand the social consequences of technology. And so Mites was of both professional and personal concern. The same issues of surveillance and informed consent that he helped computer scientists grapple with had found their way into his very office.\u00a0<\/p>\n<p>CMU isn\u2019t the only university to test out new technologies on campus before sending them into the wider world. University campuses have long been a hotbed for research\u2014with sometimes questionable policies around consent. Timnit Gebru, a tech ethicist and the founder of the Distributed AI Research Institute, cites early research on facial recognition that was built on surveillance data collected by academic researchers. \u201cSo many of the problematic data practices we see in industry were first done in the research world, and they then get transported to industry,\u201d she says.\u00a0<\/p>\n<p>It was through that lens that Widder viewed Mites. \u201cI think nonconsensual data collection for research \u2026 is usually unethical. Pervasive sensors installed in private and public spaces make increasingly pervasive surveillance normal, and that is a future that I don\u2019t want to make easier,\u201d he says.\u00a0<\/p>\n<p>He<strong> <\/strong>voiced his concerns in the department\u2019s Slack channel, in emails, and in conversations with other students and faculty members\u2014and discovered that he wasn\u2019t alone. Many other people were surprised to learn about the project, he says, and many shared his questions about what the sensor data would be used for and when collection would start.\u00a0<\/p>\n<p>\u201cI haven\u2019t been to TCS Hall yet, but I feel the same way \u2026 about the Mites,\u201d another department member wrote on Slack in April 2021. \u201cI know I would feel most comfortable if I could unplug the one in my office.\u201d<\/p>\n<p>The researchers say that they followed the university\u2019s required processes for data collection and received sign-off after a review by its institutional review board (IRB) and lawyers. The IRB\u2014which oversees research in which human subjects are involved, as required by US federal regulation\u2014had provided feedback on the Mites research proposal before ultimately approving the project in March. According to a public FAQ about the project, the board determined that simply installing Mites and collecting data about the environment did not require IRB approval or prior consent from occupants of TCS Hall\u2014with an exception for audio data collection in private offices, which would be based on an \u201copt-in\u201d consent process. Approval and consent would be required for later stages of the project, when office occupants would use a mobile app allowing them to interact with Mites data.\u00a0<\/p>\n<p>The Mites researchers also ran the project by the university\u2019s general counsel to review whether the use of microphones in the sensors violated Pennsylvania state law, which mandates two-party consent in audio recording. \u201cWe have had extensive discussions with the CMU-Office of the General Counsel and they have verified that we are not violating the PA wiretap law,\u201d the project\u2019s FAQ reads.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>Overall, the Institute for Software Research, since renamed Software and Societal Systems, was split. Some of its most powerful voices, including the department chair (and Widder\u2019s thesis co-advisor), James Herbsleb, encouraged department members to support the research. \u201cI want to repeat that this is a very important project \u2026 if you want to avoid a future where surveillance is routine and unavoidable!\u201d he wrote in an email shortly after the town hall.\u00a0<\/p>\n<\/div>\n<div>\n<p>\u201cThe initial step was to \u2026 see how these things behave,\u201d says Herbsleb, comparing the Mites sensors to motion detectors that people might want to test out. \u201cIt\u2019s purely just, \u2018How well does it work as a motion detector?\u2019 And, you know, nobody\u2019s asked to consent. It\u2019s just trying out a piece of hardware.\u201d<\/p>\n<p>Of course, the system\u2019s advanced capabilities meant that Mites were not <em>just<\/em> motion detectors\u2014and other department members saw things differently. \u201cIt\u2019s a lot to ask of people to have a sensor with a microphone that is running in their office,\u201d says Jonathan Aldrich, a computer science professor,\u00a0 even if \u201cI trust my coworkers as a general principle and I believe they deserve that trust.\u201d He adds, \u201cTrusting someone to be a good colleague is not the same as giving them a key to your office or having them install something in your office that can record private things.\u201d Allowing someone else to control a microphone in your office, he says, is \u201cvery much like giving someone else a key.\u201d<\/p>\n<p>As the debate built over the next year, it pitted students against their advisors and academic heroes as well\u2014although many objected in private, fearing the consequences of speaking out against a well-funded, university-backed project.\u00a0<\/p>\n<p>In the video recording of the town hall obtained by MIT Technology Review, attendees asked how researchers planned to notify building occupants and visitors about data collection. Jessica Colnago, then a PhD student, was concerned about how the Mites\u2019 mere presence would affect studies she was conducting on privacy. \u201cAs a privacy researcher, I would feel morally obligated to tell my participant about the technology in the room,\u201d she said in the meeting. While \u201cwe are all colleagues here\u201d and \u201ctrust each other,\u201d she added, \u201coutside participants might not.\u201d<\/p>\n<p>Attendees also wanted to know whether the sensors could track how often they came into their offices and at what time. \u201cI&#8217;m in office [X],\u201d Widder said. \u201cThe Mite knows that it&#8217;s recording something from office [X], and therefore identifies me as an occupant of the office.\u201d Agarwal responded that none of the analysis on the raw data would attempt to match that data with specific people.\u00a0<\/p>\n<p>At one point, Agarwal also mentioned that he had gotten buy-in on the idea of using Mites sensors to monitor cleaning staff\u2014which some people in the audience interpreted as facilitating algorithmic surveillance or, at the very least, clearly demonstrating the unequal power dynamics at play.\u00a0<\/p>\n<p>A sensor system that could be used to surveil workers concerned Jay Aronson, a professor of science, technology, and society in the history department and the founder of the Center for Human Rights Science, who became aware of Mites after Widder brought the project to his attention. University staff like administrative and facilities workers are more likely to be negatively impacted and less likely to reap any benefits, said Aronson. \u201cThe harms and the benefits are not equally distributed,\u201d he added.\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/04\/privacy-not-dead-2023-02-01-123002.jpeg?w=1891\" alt><figcaption>A sign reading &#8220;Privacy is NOT dead, Carnegie Mellon University Privacy Engineering&#8221; is displayed on the wall a few feet from a Mites sensor.<\/figcaption><\/figure>\n<p>Similarly, students and nontenured faculty seemingly had very little to directly gain from the Mites project and faced potential repercussions both from the data collection itself and, they feared, from speaking up against it. We spoke with five students in addition to Widder who felt uncomfortable both with the research project and with voicing their concerns.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>One of those students was part of a small cohort of 45 undergraduates who spent time at TCS Hall in 2021 as part of a summer program meant to introduce them to the department as they considered applying for graduate programs. The town hall meeting was the first time some of them learned about the Mites. Some became upset, concerned they were being captured on video or recorded.<\/p>\n<p>But the Mites weren\u2019t actually recording any video. And any audio captured by the microphones was scrambled so that it could not be reconstructed.\u00a0<\/p>\n<p>In fact, the researchers say that the Mites were not\u2014and are not yet\u2014capturing any usable data at all.\u00a0<\/p>\n<p>For the researchers, this \u201cmisinformation\u201d  about the data being collected, as Boovaraghavan described it in an interview with MIT Technology Review, was one of the project\u2019s biggest frustrations.\u00a0<\/p>\n<p>But if the town hall was meant to clarify details about the project, it exacerbated some of that confusion instead. Although a previous interdepartment email thread had made clear that the sensors were not yet collecting data, that was lost in the tense discussion. At some points, the researchers indicated that no data was or would be collected without IRB approval (which had been received the previous month), and at other points they said that the sensors were only collecting \u201ctelemetry data\u201d (basically to ensure they were powered up and connected) and that the microphone \u201cis off in all private offices.\u201d (In an emailed statement to MIT Technology Review, Boovaraghavan clarified that \u201cdata has been captured in the research teams\u2019 own private or public spaces but never in other occupants\u2019 spaces.\u201d)<\/p>\n<p>For some who were unhappy, exactly what data the sensors were <em>currently<\/em> capturing was beside the point. It didn\u2019t matter that the project was not yet fully operational. Instead, the concern was that sensors more powerful than anything previously available had been installed in offices without consent. Sure, the Mites were not collecting data at that moment. But at some date still unspecified by the researchers, they could be. And those affected might not get a say.<\/p>\n<p>Widder says the town hall\u2014and follow-up one-on-one meetings with the researchers\u2014actually made him \u201cmore concerned.\u201d He grabbed his Phillips screwdriver. He unplugged the Mites in his office, unscrewed the sensors from the wall and ceiling, and removed the ethernet cables from their jacks.\u00a0<\/p>\n<p>He put his Mite in a plexiglass box on his shelf and sent an email to the research team, his advisors, and the department\u2019s leadership letting them know he\u2019d unplugged the sensors, kept them intact, and wanted to give them back. With others in the department, he penned an anonymous open letter that detailed more of his concerns.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<h3><strong>Is it possible to clearly define \u201cprivacy\u201d?<\/strong><\/h3>\n<p>The conflict at TCS Hall illustrates what makes privacy so hard to grapple with: it\u2019s subjective. There isn\u2019t one agreed-upon standard for what privacy means or when exactly consent should be required for personal data to be collected\u2014or what even counts as personal data. People have different conceptions of what is acceptable. The Mites debate highlighted the discrepancies between technical approaches to collecting data in a more privacy-preserving way and the \u201clarger philosophical and social science side of privacy,\u201d as Kyle Jones, a professor of library and information science at Indiana University who studies student privacy in higher education, puts it.\u00a0\u00a0<\/p>\n<p>Some key issues in the broader debates about privacy were particularly potent throughout the Mites dispute. What does informed consent mean, and under what circumstances is it necessary? What data can actually identify someone, even if it does not meet the most common definitions of \u201cpersonally identifiable data\u201d? And is building privacy-protecting technology and processes adequate if they\u2019re not communicated clearly enough to users?\u00a0<\/p>\n<p>For the researchers, these questions had a straightforward answer: \u201cMy privacy can\u2019t be invaded if, literally, there\u2019s no data collected about me,\u201d says Harrison.\u00a0<\/p>\n<p>Even so, the researchers say, consent mechanisms were in place. \u201cThe ability to power off the sensor by requesting it was built in from the start. Similarly, the ability to turn on\/off any individual sensor on any Mites board was also built in from the get-go,\u201d they wrote in an email.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>But though the functionality may have existed, it wasn\u2019t well communicated to the department, as an internal Slack exchange showed. \u201cThe one general email that was sent did not provide a procedure to turn them off,\u201d noted Aldrich.\u00a0<\/p>\n<p>Students we spoke with highlighted the reality that requiring them to opt out of a high-profile research project, rather than giving them the chance to opt in, fails to account for university power dynamics. In an email to MIT Technology Review, Widder said he doesn\u2019t believe that the option to opt out via email request was valid, because many building occupants were not aware of it and because opting out would identify anyone who essentially disagreed with the research.\u00a0<\/p>\n<p>Aldrich was additionally concerned about the technology itself.\u00a0<\/p>\n<p>\u201cCan you \u2026 reconstruct speech from what they\u2019ve done? There\u2019s enough bits that it\u2019s theoretically possible,\u201d he says. \u201cThe [research team] thinks it\u2019s impossible, but we don\u2019t have proof of this, right?\u201d\u00a0\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>But a second concern was social: Aldrich says he didn\u2019t mind the project until a colleague outside the department asked not to meet in TCS Hall because of the sensors. That changed his mind. \u201cDo I really want to have something in my office that is going to keep a colleague from coming and meeting with me in my office? The answer was pretty clearly no. However I felt about it, I didn\u2019t want it to be a deterrent for someone else to meet with me in my office, or to [make them] feel uncomfortable,\u201d he says.\u00a0<\/p>\n<p>The Mites team posted signs around the building\u2014in hallways, common areas, stairwells, and some rooms\u2014explaining what the devices were and what they would collect. Eventually, the researchers added a QR code linking to the project\u2019s<a href=\"https:\/\/mites.io\/TCSDeployment\/Mites-FAQs.pdf\"> 20-page FAQ document<\/a>. The signs were small, laminated letter-size papers that some visitors said were easy to miss and hard to understand.\u00a0<\/p>\n<p>\u201cWhen I saw that, I was just thinking, wow, that\u2019s a very small description of what\u2019s going on,\u201d noted one such visitor, Se A Kim, an undergraduate student who made multiple visits to TCS Hall in the spring of 2022 for a design school assignment to explore how to make visitors aware of data collection in TCS&#8217;s public spaces. When she interviewed a number of them, she was surprised by how many were still unaware of the sensors.\u00a0<\/p>\n<p>One concern repeated by Mites opponents is that even if the current Mites deployment is not set up to collect the most sensitive data, like photos or videos, and is not meant to identify individuals, this says little about what data it might collect\u2014or what that data might be combined with\u2014in the future. Privacy researchers have <a href=\"https:\/\/www.nature.com\/articles\/s41467-019-10933-3\/\">repeatedly<\/a> <a href=\"http:\/\/science.sciencemag.org\/content\/347\/6221\/536.full?ijkey=4rZ2eFPUrlLGw&#038;keytype=ref&#038;siteid=sci\">shown<\/a> that aggregated, anonymized data can easily be de-anonymized.\u00a0<\/p>\n<div>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/03\/230223_MITTech_Mites_SPOT2.png?w=1500\" alt=\"mites stylized to look like crawling insects creep on desktop items\"><\/p>\n<p>ARI LILOAN<\/p>\n<\/figure><\/div>\n<p>This is most often the case with far larger data sets\u2014collected, for example, by smartphones. Apps and websites might not have the phone number or the name of the phone\u2019s owner, but they often have access to location data that makes it easy to reverse-engineer those identifying details. (Mites researchers have since changed how they handle data collection in private offices by grouping multiple offices together. This makes it harder to ascertain the behavior of individual occupants.)\u00a0\u00a0<\/p>\n<p>Beyond the possibility of reidentification, who exactly can access a user\u2019s data<strong> <\/strong>is often unknown with IoT devices\u2014whether by accident or by system design. Incidents abound in which consumer smart-home devices, from baby monitors to <a href=\"https:\/\/www.businessinsider.in\/tech\/news\/google-home-can-be-hacked-and-snooped-on-listening-conversations\/articleshow\/96704649.cms#:~:text=Researcher%20finds%20Google%20Home%20speaker%20vulnerable%20of%20getting%20hacked%20and%20snooping%20on%20conversations,-Advertisement&#038;text=The%20device%20can%20be%20used,a%20researcher%20named%20Matt%20Kunze.\">Google Home speakers<\/a> to <a href=\"https:\/\/www.technologyreview.com\/2022\/12\/19\/1065306\/roomba-irobot-robot-vacuums-artificial-intelligence-training-data-privacy\/\">robot vacuums<\/a>, have been hacked or <a href=\"https:\/\/community.robotshop.com\/t\/roomba-testers-feel-misled-after-intimate-images-ended-up-on-facebook-https-www-technologyreview-com-2023-01-10-1066500-roomba-irobot-robot-vacuum-beta-product-testers-consent-agreement-misled\/95848\">their data has been shared without their users\u2019 knowledge or consent<\/a>.\u00a0<\/p>\n<p>The Mites research team was aware of these well-known privacy issues and security breaches, but unlike their critics, who saw these precedents as a reason not to trust the installation of even more powerful IoT devices, Agarwal, Boovaraghavan, and Harrison saw them as motivation to create something better. \u201cAlexa and Google Homes are really interesting technology, but some people refuse to have them because that trust is broken,\u201d Harrison says. He felt the researchers\u2019 job was to figure out how to build a new device that was trustworthy from the start.\u00a0<\/p>\n<p>Unlike the devices that came before, theirs would be privacy-protecting.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<h3><strong>Tampering and bullying claims<\/strong><\/h3>\n<p>In the spring of 2021, Widder received a letter informing him he was being investigated for alleged misconduct for tampering with university computing equipment. It also warned him that the way he had acted could be seen as bullying.<\/p>\n<p>Department-wide email threads, shared with MIT Technology Review, hint at just how personal the Mites debate had become\u2014and how Widder had, in the eyes of some of his colleagues, become the bad guy. \u201cPeople taking out sensors on their own (what\u2019s the point of these deep conversations if we are going to just literally take matters in our hands?) and others posting on social media is *not ethical*,\u201d one professor wrote. (Though the professor did not name Widder, it was widely known that he had done both.)\u00a0<\/p>\n<p>\u201cI do believe some people felt bullied here, and I take that to heart,\u201d Widder says, though he also wonders, \u201cWhat does it say about our field if we\u2019re not used to having these kinds of discussions and \u2026 when we do, they\u2019re either not taken seriously or \u2026 received as bullying?\u201d (The researchers did not respond to questions about the bullying allegations.)\u00a0<\/p>\n<p>The disciplinary action was dropped after Widder plugged the sensors back in and apologized, but to Aldrich, \u201cthe letter functions as a way to punish David for speaking up about an issue that is inconvenient to the faculty, and to silence criticism from him and others in the future,\u201d as he wrote in an official response to Widder\u2019s doctoral review.\u00a0<\/p>\n<p>Herbsleb, the department chair and Widder\u2019s advisor, declined to comment on what he called a \u201cprivate internal document,\u201d citing student privacy.\u00a0<\/p>\n<p>While Widder believes that he was punished for his criticisms, the researchers had taken into account some of those critiques already. For example, the researchers offered to let building occupants turn off the Mites sensors in their offices by asking to opt out via email. But this remained impossible in public spaces, in part because \u201cthere\u2019s no way for us to even know who\u2019s in the public space,\u201d the researchers told us.\u00a0<\/p>\n<p>By February 2023, occupants in nine offices out of 110\u00a0had written to the researchers to disable the Mites sensors in their own offices\u2014including Widder and Aldrich.\u00a0<\/p>\n<p>The researchers point to this small number as proof that most people are okay with Mites. But Widder disagrees; all it proves, he says, is that people saw how he was retaliated against for removing his own Mites sensors and were dissuaded from asking to have theirs turned off. \u201cWhether or not this was intended to be coercive, I think it has that effect,\u201d he says.<\/p>\n<\/p><\/div>\n<div>\n<h3><strong>\u201cThe high-water mark\u201d<\/strong><\/h3>\n<p>On a rainy day last October, in a glass conference room on the fourth floor of TCS Hall,\u00a0 the Mites research team argued that the simmering tensions over their project\u2014the heated and sometimes personal all-department emails, Slack exchanges, and town halls\u2014were a normal part of the research process.\u00a0<\/p>\n<p>\u201cYou may see this discord \u2026 through a negative lens; we don\u2019t,\u201d Harrison said.\u00a0<\/p>\n<p>\u201c<em>I<\/em> think it\u2019s great that we\u2019ve been able to foster a project where people can legitimately \u2026 raise issues with it \u2026 That\u2019s a good thing,\u201d he added.\u00a0<\/p>\n<p>\u201cI\u2019m hoping that we become the high-water mark for how to do this [sensor research] in a very deliberate way,\u201d said Agarwal.\u00a0<\/p>\n<p>Other faculty members\u2014even those who have become staunch supporters of the Mites project, like Lorrie Cranor, a professor of privacy engineering and a renowned privacy expert\u2014say things could have been done differently. \u201cIn hindsight, there should have been more communication upfront,\u201d Cranor acknowledges\u2014and those conversations should have been ongoing so that current students could be part of them. Because of the natural turnover in academia, she says, many of them had never had a chance to participate in these discussions, even though long-standing faculty were informed about the project years ago.<\/p>\n<p>She also has suggestions for how the project could improve. \u201cMaybe we need a Mites sensor in a public area that\u2019s hooked up to a display that gives you a livestream, and you can jump up and down and whistle and do all sorts of stuff in front of it and see what data is coming through,\u201d she says. Or let people download the data and figure out, \u201cWhat can you reconstruct from this? \u2026 If it\u2019s possible to reverse-engineer it and figure something out, someone here probably will.\u201d And if not, people might be more inclined to trust the project.\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/wp.technologyreview.com\/wp-content\/uploads\/2023\/04\/DSC_0769.jpeg?w=2553\" alt><figcaption>Widder&#8217;s disabled Mites sensors, which he placed in a plexiglass box on his shelf after unscrewing the device<\/figcaption><\/figure>\n<p>The devices could also have an on-off switch, Herbsleb, the department chair, acknowledges: \u201cI think if those concerns had been recognized earlier, I\u2019m sure Yuvraj [Agarwal] would have designed it that way.\u201d (Widder still thinks the devices should have an off switch.)<\/p>\n<p>But still, for critics, these actual and suggested improvements do not change the fact that \u201cthe public conversation is happening <em>because<\/em> of a controversy, rather than before,\u201d Aronson says.\u00a0<\/p>\n<\/p><\/div>\n<div>\n<p>Nor do the research improvements take away what Widder experienced. \u201cWhen I raised concerns, especially early on,\u201d he says, \u201cI was treated as an attention seeker \u2026 as a bully, a vandal. And so if now people are suggesting that this has made the process better?\u201d He pauses in frustration. \u201cOkay.\u201d\u00a0<\/p>\n<p>Besides, beyond any improvements made in the research process at CMU, there is still the question of how the technology might be used in the real world. That commercialized version of the technology might have \u201chigher-quality cameras and higher-quality microphones and more sensors and \u2026 more information being sucked in,\u201d notes Aronson. Before something like Mites rolls out to the public, \u201cwe need to have this big conversation\u201d about whether it is necessary or desired, he says.\u00a0<\/p>\n<p>\u201cThe big picture is, can we trust employers or the companies that produce these devices not to use them to spy on us?\u201d adds Aldrich. \u201cSome employers have proved they don\u2019t deserve such trust.\u201d\u00a0<\/p>\n<p>The researchers, however, believe that worrying about commercial applications may be premature. \u201cThis is research, not a commercial product,\u201d they wrote in an emailed statement. \u201cConducting this kind of research in a highly controlled environment enables us to learn and advance discovery and innovation. The Mites project is still in its early phases.\u201d<\/p>\n<p>But there\u2019s a problem with that framing, says Aronson. \u201cThe experimental location is not a lab or a petri dish. It\u2019s not a simulation. It\u2019s a building that real human beings go into every day and live their lives.\u201d<\/p>\n<p>Widder, the project\u2019s most vocal critic, can imagine an alternative scenario where perhaps he could have felt differently about Mites, had it been more participatory and \u201ccollaborative.\u201d Perhaps, he suggests, the researchers could have left the devices, along with an introduction and instruction booklet, on department members\u2019 desks so they could decide if they wanted to participate. That would have ensured that the research was done \u201cbased on the principle of opt-in consent to even have these in the office in the first place.\u201d In other words, he doesn\u2019t think technical features like encryption and edge computing can replace meaningful consent.<\/p>\n<p>Even these sorts of adjustments wouldn\u2019t fundamentally change how Widder feels, however. \u201cI\u2019m not willing to accept the premise of \u2026 a future where there are all of these kinds of sensors everywhere,\u201d he says.\u00a0<\/p>\n<p>The 314 Mites that remain in the walls and ceilings of TCS Hall are, at this point, unlikely to be ripped out. But if the fight over this project may well have wound down, debates about privacy are really just beginning.\u00a0<svg viewBox=\"0 0 1091.84 1091.84\"><polygon fill=\"#6d6e71\" points=\"363.95 0 363.95 1091.84 727.89 1091.84 727.89 363.95 363.95 0\" \/><polygon fill=\"#939598\" points=\"363.95 0 728.24 365.18 1091.84 364.13 1091.84 0 363.95 0\" \/><polygon fill=\"#414042\" points=\"0 0 0 0.03 0 363.95 363.95 363.95 363.95 0 0 0\" \/><\/svg> <\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/www.technologyreview.com\/2023\/04\/03\/1070665\/cmu-university-privacy-battle-smart-building-sensors-mites\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Eileen Guo, Tate Ryan-Mosley<\/p>\n","protected":false},"excerpt":{"rendered":"<p>These computer scientists were trying to create privacy-preserving smart sensors. But then they were accused of violating their colleagues\u2019 privacy.Ari Liloan When computer science students and faculty at Carnegie Mellon University\u2019s Institute for Software Research returned to campus in the summer of 2020, there was a lot to adjust to.\u00a0 Beyond the inevitable strangeness of<\/p>\n","protected":false},"author":1,"featured_media":625053,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1710,118,46],"tags":[],"class_list":{"0":"post-625052","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-bitter","8":"category-inside","9":"category-technology"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/625052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=625052"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/625052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/625053"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=625052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=625052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=625052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}