Search papers, labs, and topics across Lattice.
This paper introduces the PRIAM framework, a novel human-LLM teaming approach designed for privacy risk analysis in Central Bank Digital Currency (CBDC)-based welfare schemes. By leveraging the strengths of both human experts and language models, the framework facilitates a systematic assessment of privacy risks through iterative collaboration, where LLMs generate preliminary outputs that are refined by human judgment. The results illustrate that this method not only enhances the accuracy of data categorization but also improves the identification of information gaps and ambiguous outputs, ultimately leading to more robust privacy risk assessments.
Human-LLM collaboration can significantly enhance the accuracy and depth of privacy risk assessments in complex welfare schemes, revealing critical insights that neither could achieve alone.
Central Bank Digital Currency (CBDC)-based welfare schemes may be potentially privacy invasive as they process significant volumes of beneficiary personal data and lead to privacy harms such as surveillance, discrimination and stigmatization. Such welfare delivery schemes involve complex digital ecosystems and large number of stakeholders. Consequently, to examine their privacy risks, privacy risk assessments require extensive information gathering and synthesis, complex reasoning, scenario explorations, contextual evaluation and human judgement. Thus, they present ideal scenarios for human-LLM teaming, where effective integration of complementary human and LLM capabilities can yield an outcome far superior to either human-only or LLM-only assessments. In this paper, we propose a first human-LLM teaming framework for the systematic privacy risk analysis methodology called PRIAM. The framework specifies an iterative collaborative process in which the LLM processes large-scale documentary evidence to produce initial outputs, which are then interpreted and evaluated by human experts who direct their further refinement by the LLM and exercise their judgement to finalize the output. We illustrate the framework on the data characterization activity of PRIAM using a CBDC-based welfare scheme use case. The illustration demonstrates that while LLMs generate the initial data categories and assign initial values to data attributes, human experts evaluate and provide feedback to refine them, distinguishing documented evidence from inferences, identifying information gaps, and flagging unsupported or ambiguous outputs. This framework serves as a foundational contribution towards human-AI teaming for privacy risk assessments.