Source-linked AI summary

Position: Robot Privacy as Embodied Boundary Work. Connecting Capabilities, Contexts, and Design Responses in Everyday Robotics

Liwen He, Shuning Zhang, Chengwen Zhang, Xin Yi, Chun Yu, Jihong Jeung, Xin Tong

arXiv:2608.21410v1cs.ROcs.HC

TL;DR

Everyday robots reshape privacy through embodied action, while existing framings often center on data flows, settings, or one-time consent. The paper proposes a capability-by-context framework and uses it to derive embodied privacy mechanisms and future research directions. Its scope is privacy change produced through physically situated robotic action, with protections calibrated to contextual and task trade-offs.

  • Problem

    Robot privacy needs a framing that accounts for spatial, bodily, social, and relational boundaries alongside data practices and one-time consent.

  • Method

    The paper develops embodied boundary privacy as a capability-by-context framework for analyzing how robot capabilities enact or reshape access and privacy boundaries in situated interaction.

  • Results

    The framework organizes robot privacy risks around embodied boundary crossings and translates them into mechanisms such as checkpoints, viewpoint-aware sensing control, remote-presence disclosure, access rules, and interruption rights.

  • Takeaways & Limitations

    Robot movement, orientation, proximity, object access, remote presence, and social expression should be treated as privacy-relevant actions whose meaning depends on context.

  • Takeaways & Limitations

    Restricting sensing, movement, or access may reduce task performance, accessibility, or safety, so protections must be calibrated to context and task.

Abstract

from arXiv · show

Robots are increasingly entering everyday environments where privacy is shaped not only by data practices, but also by spatial, bodily, social, and relational boundaries. Their embodied capabilities allow them to reshape these boundaries through situated action, challenging privacy framings centered on data flows, interface settings, or one-time consent. Prior work has examined robot privacy through sensing, data collection, telepresence, transparency, consent, bystander awareness, and multi-stakeholder governance. Building on this work, we propose embodied boundary privacy as a capability-by-context framing for examining how physically present robots may reshape privacy boundaries in situated interaction. Specifically, this framing organizes privacy risks across seven robot capabilities and five deployment contexts, asking how embodied capabilities enable boundary crossings and how situated contexts shape who is affected, how these crossings are interpreted, and when they become contested. We use this perspective to outline design and research implications for embodied privacy mechanisms, including boundary checkpoints, viewpoint-aware sensing control, remote-presence disclosure, object- and body-level access rules, constraints on socially persuasive privacy influence, and local interruption rights. We encourage HRI research, design, and governance to treat robot movement, orientation, proximity, object access, remote presence, and social expression as privacy-relevant actions whose meaning depends on context.

1 Introduction

Robot privacy concerns arise not only from data practices but also from how embodied robots reshape spatial, bodily, social, and relational boundaries. The paper proposes embodied boundary privacy to analyze these risks through robot capabilities and situated interaction.

  • Everyday robots raise privacy questions about room entry, proximity, observation, object access, and participation in interactions.
  • Existing robot-privacy work covers sensing, data collection, processing, transparency, consent, telepresence, bystander awareness, and governance, but remains organized largely around data practices.
  • Embodied boundary privacy frames risk as the interaction between a robot’s capabilities and the context, people, and social conditions in which those capabilities are enacted.
  • The framing shifts attention from isolated data flows and one-time permissions to how people perceive, negotiate, maintain, accept, refuse, interrupt, or renegotiate privacy boundaries during interaction.
  • The paper contributes a capability-by-context account of seven capability categories and a design agenda including boundary checkpoints, sensing control, remote-presence disclosure, access rules, and interruption rights.

2 Existing Framings of Robot Privacy

Prior robot-privacy research can be organized around data processing, networked mediated access, and social-contextual relationships. Together, these framings establish the foundation for organizing privacy around embodied capabilities and boundary work.

  • Data-centered research examines privacy across sensing, inference, storage, access control, disclosure, and secondary use.
  • For physically present robots, sensing risks are tied to movement, location, orientation, proximity, approached activities, and whether people can notice or control sensing.
  • Telepresence research treats robots as proxies that mediate access between local environments and remote actors, including through visual privacy interventions such as blurring, redaction, replacement, and abstraction.
  • Social and contextual research shows that privacy expectations vary with relationships, roles, locations, urgency, vulnerability, and power, including for bystanders, households, children, elders, and other stakeholders.
  • The paper builds on these three framings by foregrounding how robots sense, move, orient, approach, manipulate, express social roles, and connect local environments to remote actors or institutions.

3 Embodied Boundary Privacy Framework

The embodied boundary privacy framework explains privacy-boundary crossings through robot capabilities enacted in situated contexts. It asks which capability enables access, which boundary is crossed, and who can negotiate or repair that crossing.

  • Embodiment is treated as the mechanism through which robots cross, blur, or renegotiate privacy boundaries, including by moving cameras, approaching bodies, opening containers, or presenting trusted social roles.
  • The framework analyzes each situation by asking what capability enables access, what boundary is crossed or reshaped, and who can perceive, negotiate, refuse, or repair it.
  • The capability × context view complements relational and bystander privacy by focusing on privacy change produced through physically situated robotic action rather than independent downstream data use.
  • The context axis captures how capabilities acquire different meanings across homes, care settings, telepresence, public services, accessibility situations, and bystander encounters.
  • Capabilities define possible forms of access, while contexts determine affected stakeholders, authority relations, and whether crossings are permitted, normalized, or contested.
  • The capability axis distinguishes mechanisms including stationary sensing, mobile vision, remote operation, social expression, aerial mobility, and multimodal networking.
  • The framework reframes robot privacy as asking which boundary a capability crosses in context and who has power to negotiate it, requiring design beyond transparency and settings.

4 Design Implications: Toward Embodied Privacy Mechanisms

The paper translates embodied boundary privacy into six design implications that regulate robot movement, sensing, remote presence, manipulation, social expression, and interruption. These mechanisms must be calibrated to context because privacy protections can trade off against task performance, accessibility, or safety.

  • The capability × context matrix shifts robot privacy protection from data settings toward embodied behavior and context-sensitive boundary negotiation.Mobility, viewpoint control, remote operation, manipulation, and social expression each motivate distinct privacy mechanisms.
  • Spatial entry: Robots should treat entering, approaching, and looking into sensitive spaces as privacy events requiring checkpoints, disclosure, and permission or lower-access alternatives.Possible responses include stopping at thresholds, waiting outside, leaving items at boundaries, or sending non-visual notifications.
  • Sensing control: Viewpoint-aware sensing should constrain field of view and sensing resolution according to robot position, orientation, and environmental sensitivity.Examples include avoiding screens or beds, using downward-facing navigation, and making sensing direction visible.
  • Remote presence: Remote-presence modes should disclose when operators can see, hear, move, or act through the robot and provide nearby people with local override controls.Controls may pause video, freeze movement, block private-room entry, or return the robot to a neutral location.
  • Object and body access: Manipulation requires object- and body-level privacy rules with differentiated defaults for permission, logging, supervision, and fallback behavior.The framework distinguishes public, personal, sensitive, and restricted objects alongside varying forms of bodily contact.
  • Social expression: Social expression should be evaluated as privacy influence because persuasive or relational behavior can shape disclosure, privacy judgments, and willingness to refuse.Designs may limit emotionally persuasive cues, separate companionship from monitoring, and clarify institutional roles and remote operators.
  • Shared spaces: Privacy mechanisms must recognize local claims from cohabitants, children, visitors, patients, workers, and bystanders, including simple interruption rights without prior setup.When claims conflict, robots should default to stopping, stepping back, looking away, leaving, or requesting human mediation.
  • Restricting sensing, movement, or access may reduce task performance, accessibility, or safety, so protections should be calibrated to context and task.

5 Research agenda and conclusion

The paper frames future robot-privacy research as an embodied boundary problem spanning shared spaces, sensing, remote presence, manipulation, and social interaction. It calls for prospective studies that specify how capabilities create particular boundary crossings and how affected people perceive, negotiate, and respond to them.

  • Future research should study how privacy boundaries are perceived, crossed, negotiated, and repaired as robots move, change viewpoints, manipulate objects, mediate remote presence, and act socially.
  • Research should identify privacy-relevant boundaries in everyday environments, where thresholds such as bedrooms, bathrooms, desks, bedsides, and care areas may require different socially defined entry rules.
  • The agenda includes making viewpoint, sensing direction, and remote presence legible to nearby people, including bystanders and people with limited ability to perceive sensors.
  • Deployment contexts: Deployment contexts raise distinct concerns, including bodily privacy and safety–autonomy–privacy tensions in intimate care, and bystander exposure and ambiguous public/private boundaries in service settings.
  • A central open question is how to provide interruption rights at the moment of exposure without requiring prior setup, ownership, or technical expertise.
  • Future work should specify pathways from capabilities to boundary crossings and evaluate them through scenario-based experiments, Wizard-of-Oz studies, interviews, and in-situ deployments.
Loading 2608.21410v1…