Source-linked AI summary
A Human-LLM Teaming Framework for Privacy Risk Analysis: An Illustration with CBDC-Based Welfare Schemes
Sourya Joyee De, Abdessamad Imine
TL;DR
Privacy risk analysis for CBDC-based welfare schemes is demanding and expert-dependent, motivating a human–LLM teaming framework for PRIAM. The framework iteratively combines LLM-generated analyses with human evaluation and refinement, illustrated through data characterization in a welfare-scheme case study.
Problem
Applying PRIAM to complex CBDC welfare ecosystems requires extensive information gathering, synthesis, risk exploration, scenario analysis, and expert knowledge.
Method
The framework assigns LLMs large-scale evidence processing and initial analysis, while human experts evaluate accuracy, assumptions, completeness, and evidence and direct refinements.
Results
In the data-characterization illustration, human feedback refined LLM-generated data categories and attributes by separating evidence from inferences and flagging gaps or ambiguous outputs.
Takeaways & Limitations
The framework provides a foundation for human–LLM teaming in privacy risk analysis by combining large-scale information synthesis with contextual human evaluation.
Takeaways & Limitations
The framework is illustrated only for PRIAM’s data-characterization activity, and future work must examine all PRIAM activities and compare team performance empirically with human experts alone.
Abstract
from arXiv · showhide
Central Bank Digital Currency (CBDC)-based welfare schemes may be potentially privacy invasive as they process significant volumes of beneficiary personal data and lead to privacy harms such as surveillance, discrimination and stigmatization. Such welfare delivery schemes involve complex digital ecosystems and large number of stakeholders. Consequently, to examine their privacy risks, privacy risk assessments require extensive information gathering and synthesis, complex reasoning, scenario explorations, contextual evaluation and human judgement. Thus, they present ideal scenarios for human-LLM teaming, where effective integration of complementary human and LLM capabilities can yield an outcome far superior to either human-only or LLM-only assessments. In this paper, we propose a first human-LLM teaming framework for the systematic privacy risk analysis methodology called PRIAM. The framework specifies an iterative collaborative process in which the LLM processes large-scale documentary evidence to produce initial outputs, which are then interpreted and evaluated by human experts who direct their further refinement by the LLM and exercise their judgement to finalize the output. We illustrate the framework on the data characterization activity of PRIAM using a CBDC-based welfare scheme use case. The illustration demonstrates that while LLMs generate the initial data categories and assign initial values to data attributes, human experts evaluate and provide feedback to refine them, distinguishing documented evidence from inferences, identifying information gaps, and flagging unsupported or ambiguous outputs. This framework serves as a foundational contribution towards human-AI teaming for privacy risk assessments.
1. Introduction
CBDC-based welfare schemes offer efficient, targeted and accountable digital welfare, but their complex digital ecosystems require systematic privacy risk assessment to identify weaknesses, exploiters and potential harms.
- CBDC-based welfare delivery: CBDC enables efficient, targeted and accountable digital welfare delivery, with India piloting eRupee-linked food subsidies across several states and union territories.The cited pilots include Gujarat, Puducherry and Chandigarh.
- CBDC-based welfare delivery: eRupee features such as traceability and programmability shape the digital welfare infrastructure.
- Privacy risk assessment: Privacy risk assessment must systematically examine processed data, digital infrastructure and stakeholders to identify protection weaknesses, potential exploiters and unacceptable privacy incidents and harms.The passage frames this as necessary for comprehensively identifying privacy risks in complex digital ecosystems such as CBDC-based welfare schemes.
2. Privacy Risks of CBDC-based Welfare Schemes
The case study examines a women-targeted welfare scheme that distributes annual eRupee payouts through digital wallets. It involves multiple institutional stakeholders and digital infrastructures supporting identity verification, scheme management, and payments.
- Use case: The scheme targets women and provides each eligible beneficiary an annual eRupee payout in a digital wallet.Beneficiaries can spend the payout via QR codes, transfer it to a bank account, or withdraw cash.
- Stakeholder ecosystem: Stakeholders include scheme administrators, eligibility-verifying government agencies, banks, payment intermediaries, identity infrastructure, digital service providers, and enrolment and verification intermediaries.
- Digital infrastructure: The digital infrastructure includes applications for identity verification and scheme management, alongside payment channels for QR spending, bank transfers, and cash withdrawals.
3. A Framework for Human-LLM Teaming for PRIAM
The framework integrates LLM-supported evidence processing with human interpretation, evaluation, refinement, and final judgment throughout PRIAM’s privacy risk analysis activities. It applies this collaboration first to information gathering across seven components and then to risk assessment through harm-tree generation and risk-level assessment.
- Human-LLM collaboration: The framework uses LLMs to process heterogeneous documentary evidence and generate initial outputs for PRIAM activities, which human experts interpret, evaluate, and direct for refinement.Human experts can identify omissions, challenge assumptions and evidence, and provide additional assumptions before refined information is supplied back to the LLM.
- Information gathering: Information gathering is cognitively demanding because it requires exhaustive collection from heterogeneous sources while identifying relevant entities, categories, and attributes without overlooking consequential information.This motivates collaborative support for the first phase of PRIAM.
- Information gathering: PRIAM’s information-gathering phase specifies attributes and categories for seven components: system, stakeholders, data, risk sources, privacy weaknesses, feared events, and privacy harms.The knowledge base can include scheme guidelines, official documentation, FAQs, government circulars, RBI CBDC documents, privacy policies, terms and conditions, and payment documentation.
- Risk assessment: Risk assessment uses information-gathering outputs for harm-tree generation and risk-level assessment, with the LLM combining risk sources, privacy weaknesses, and feared events to assess harm likelihood.The human expert may request LLM-based refinement of severity values.
- Risk assessment: The human expert retains final judgment over assigned risk, including both likelihood and severity, after any LLM-based refinement of severity values.Final severity values are reached through refinement, but the final risk judgment remains with the human expert.
4. Illustration using CBDC-based Welfare Schemes
The section illustrates PRIAM’s data-characterization activity through a hypothetical CBDC-based women’s welfare scheme. It shows how an LLM can use documentation from multiple sources to identify processed data categories and assess attributes such as sensitivity, volume, origin, purpose, and retention.
- Case study: The illustration applies human-LLM PRIAM data characterization to a hypothetical CBDC-based women’s welfare scheme.The case study is based on the scheme discussed earlier in the paper.
- Initial LLM outputs: Government websites and other available documentation can support initial LLM outputs for data categorization.The section presents separate tables for initial data categorization and data attributes.
- Initial LLM outputs: The LLM may identify data categories and assign attributes including sensitivity, volume, origin, purpose, and retention.These attributes are specified as part of PRIAM’s data-characterization activity.
5. Related Works
Related work frames human-AI teaming as collaboration between interdependent contributors that complements human and AI strengths. Privacy Impact Assessments are multidisciplinary and therefore well suited to human-AI teaming, with AI supporting knowledge-intensive tasks and humans contributing expertise.
- Human-AI Teaming: Human-AI teaming treats humans and AI as interdependent contributors who collaborate by complementing strengths and compensating for weaknesses.LLMs can function as flexible, on-demand cognitive aids that augment rather than replace human experts.
- Privacy Impact Assessments: Privacy Impact Assessments examine privacy implications of potentially privacy-invasive systems or services that process personal data.The cited literature defines PIAs as a process for assessing privacy implications.
- Privacy Impact Assessments: PIAs require legal interpretation, technical analysis, domain-specific knowledge and stakeholder engagement, making them an ideal application area for human-AI teaming.AI can support knowledge-intensive tasks within this inherently multidisciplinary activity.
6. Conclusion and Future Work
The paper proposes a human–LLM teaming framework for PRIAM that assigns tasks according to the complementary capabilities of LLMs and human experts. It identifies broader illustration and empirical comparison as key directions for future work.
- Framework contribution: The framework allocates PRIAM tasks between LLMs and human experts according to their complementary capabilities.LLMs generate initial outputs using large-scale information extraction, while human experts provide contextual evaluation and iterative feedback.
- Framework contribution: The proposed integration may improve privacy risk analysis depth and efficiency by combining LLM information synthesis with human contextual evaluation.The passage states that LLMs synthesize large volumes of information more efficiently than humans, while experts refine outputs beyond LLM capabilities.
- Future work: Future work should apply the framework across all PRIAM activities and empirically compare human–LLM teams with human expert-only privacy risk analysis.The comparison is intended to examine whether and how team performance differs from expert-only analysis.