Skip to main content

Showing 1–6 of 6 results for author: Finck, M

.
  1. arXiv:2503.01630  [pdf, ps, other

    cs.LG cs.AI cs.CY

    Machine Learners Should Acknowledge the Legal Implications of Large Language Models as Personal Data

    Authors: Henrik Nolte, Michèle Finck, Kristof Meding

    Abstract: Does GPT know you? The answer depends on your level of public recognition; however, if your information was available on a website, the answer could be yes. Most Large Language Models (LLMs) memorize training data to some extent. Thus, even when an LLM memorizes only a small amount of personal data, it typically falls within the scope of data protection laws. If a person is identified or identifia… ▽ More

    Submitted 18 June, 2025; v1 submitted 3 March, 2025; originally announced March 2025.

  2. arXiv:2502.16184  [pdf, other

    cs.AI cs.CR cs.CY cs.LG

    Robustness and Cybersecurity in the EU Artificial Intelligence Act

    Authors: Henrik Nolte, Miriam Rateike, Michèle Finck

    Abstract: The EU Artificial Intelligence Act (AIA) establishes different legal principles for different types of AI systems. While prior work has sought to clarify some of these principles, little attention has been paid to robustness and cybersecurity. This paper aims to fill this gap. We identify legal challenges and shortcomings in provisions related to robustness and cybersecurity for high-risk AI syste… ▽ More

    Submitted 28 May, 2025; v1 submitted 22 February, 2025; originally announced February 2025.

    Journal ref: The 2025 ACM Conference on Fairness, Accountability, and Transparency

  3. Post-Hoc Explanations Fail to Achieve their Purpose in Adversarial Contexts

    Authors: Sebastian Bordt, Michèle Finck, Eric Raidl, Ulrike von Luxburg

    Abstract: Existing and planned legislation stipulates various obligations to provide information about machine learning algorithms and their functioning, often interpreted as obligations to "explain". Many researchers suggest using post-hoc explanation algorithms for this purpose. In this paper, we combine legal, philosophical and technical arguments to show that post-hoc explanation algorithms are unsuitab… ▽ More

    Submitted 10 May, 2022; v1 submitted 25 January, 2022; originally announced January 2022.

    Comments: FAccT 2022

  4. arXiv:2107.08096  [pdf, other

    cs.LG cs.CY cs.IR

    Learning to Limit Data Collection via Scaling Laws: A Computational Interpretation for the Legal Principle of Data Minimization

    Authors: Divya Shanmugam, Samira Shabanian, Fernando Diaz, Michèle Finck, Asia Biega

    Abstract: Modern machine learning systems are increasingly characterized by extensive personal data collection, despite the diminishing returns and increasing societal costs of such practices. Yet, data minimisation is one of the core data protection principles enshrined in the European Union's General Data Protection Regulation ('GDPR') and requires that only personal data that is adequate, relevant and li… ▽ More

    Submitted 12 June, 2022; v1 submitted 16 July, 2021; originally announced July 2021.

    Comments: To appear at ACM Conference on Fairness, Accountability, and Transparency, 2022

  5. arXiv:2101.06203  [pdf

    cs.CY cs.IR cs.LG

    Reviving Purpose Limitation and Data Minimisation in Data-Driven Systems

    Authors: Asia J. Biega, Michèle Finck

    Abstract: This paper determines whether the two core data protection principles of data minimisation and purpose limitation can be meaningfully implemented in data-driven systems. While contemporary data processing practices appear to stand at odds with these principles, we demonstrate that systems could technically use much less data than they currently do. This observation is a starting point for our deta… ▽ More

    Submitted 16 December, 2021; v1 submitted 15 January, 2021; originally announced January 2021.

    Comments: In Technology and Regulation (2021): https://doi.org/10.26116/techreg.2021.004

    Journal ref: Technology and Regulation 2021 (August), 44-61

  6. arXiv:2005.13718  [pdf, other

    cs.CY cs.IR cs.LG

    Operationalizing the Legal Principle of Data Minimization for Personalization

    Authors: Asia J. Biega, Peter Potash, Hal Daumé III, Fernando Diaz, Michèle Finck

    Abstract: Article 5(1)(c) of the European Union's General Data Protection Regulation (GDPR) requires that "personal data shall be [...] adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (`data minimisation')". To date, the legal and computational definitions of `purpose limitation' and `data minimization' remain largely unclear. In particular, the… ▽ More

    Submitted 27 May, 2020; originally announced May 2020.

    Comments: SIGIR 2020 paper: In Proc. of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval