Conference Agenda
Overview and details of the sessions of this conference. Please select a date or location to show only sessions at that day or location. Please select a single session for detailed view (with abstracts and downloads if available).
|
Daily Overview |
| Session | |
Pos: Poster Sessions
| |
| Presentations | |
The Kids Online Safety Act: Interrogating the Compatibility of Two Policy Goals Oxford Internet Institute This paper asks the research question: “Are the two goals of the US Kids Online Safety Act (KOSA) - to protect kids online and to hold Big Tech accountable - compatible?” These two distinct goals, as embedded into the legislation and promoted by policymakers, draw on sociocultural, historical, technical, and legislative discourses and mechanisms that are increasingly intertwined: child online safety and Big Tech accountability. Scholarship across disciplines provides relevant analyses of these discourses and mechanisms, but has not yet examined their confluence in one legislative setting. Additionally, direct examinations of KOSA (ex.: Angel & boyd, 2024) are limited in number but, along with recent studies of U.S. state-level online safety and platform regulation (ex.: Reid et al., 2025), they encourage, through conceptual and methodological insights, further analysis of KOSA’s legislative moment. This is a research question with interdisciplinary grounding and (potential) contributions. It is a research question that demands a dynamic methodology to address the discourses and mechanisms it seeks to examine. Through a qualitative case study of the Kids Online Safety Act, this paper seeks to identify and analyze the explicit and implicit ideas giving meaning and motivation to each goal, and how these ideas are put in relation to each other. These ideas are examined in the context of the different data types that build the study: versions of the KOSA text, Congressional hearings transcripts where KOSA and its goals have been discussed, and the communications about KOSA from the social media and official websites of its two primary Senate sponsors: Sen. Blumenthal and Sen. Blackburn. An abductive and interpretive thematic analysis, drawing on interpretive policy analysis and socio-legal analysis – two ways to examine law and policy settings with discursive and sociological tools and approaches - will be used to reach conclusions about the ‘compatibility’ of these two goals. The expectation for results and conclusions is not to definitively name the goals compatible or incompatible, but to have an exploration of both their synergies and tensions. For example, as a possible broad discussion point: in the KOSA setting, policymakers’ intense attention on and critique of Big Tech relieves a historical criticism that such policies and discourses overly pick at and pathologize youth online behavior, but in the same turn, shifts attention away from integrating youth perspectives on the issue, as generally advocated for by child digital rights scholars and activists. This would suggest how, in this pursuit of the goal of Big Tech accountability, ideas that currently inform the goal to protect kids online can be undermined, favorably or unfavorably. This intended analysis would be particularly relevant as KOSA is not only novel in the tradition of US online safety legislation, but also part of a current wave of online safety legislation and accountability-minded platform regulation moving through jurisdictions, such as in the UK, Australia, Brazil, and Singapore. As jurisdictions continue to develop legislation with these goals, interrogating how they are ideated, mobilized, and ultimately ‘compatible’ can hopefully productively inform policymakers pursuing these desired outcomes. Secrecy, Spectrum, and Certification: Evidence from Wireless Electronic Devices 1: Harvard University; 2: University of Pavia; 3: Boston College Intellectual property rights are a crucial means for firms to capture value in rapidly innovating, invention-intensive markets. Most of the literature focuses on formal exclusivity mechanisms, such as patents, which protect new technologies rather than specific products or inventions. We investigate a unique setting in which firms have the option to opt into secrecy at the product level due to deregulatory action from a governing body. The FCC began publishing its database of certified unlicensed spectrum products online after 1998, which required firms to submit technical and commercial information during the review process. Since some of it potentially involved trade secrets, long-term confidentiality (LTC) became an available option in 2001. LTC refers to the permanent protection of specific technical documents submitted by an applicant during the certification process. These documents typically contain proprietary information critical to a device’s functionality and design. Short-term confidentiality (STC) became an available option in 2007. It provides temporary protection (up to 180 days) for documents that might reveal a product’s physical design or functionality before its commercial release for sale to buyers. The FCC explicitly states the different goals of the two regimes: LTC is “intended to safeguard trade secrets,” while STC is “to allow for the preparation of marketing of devices” prior to a planned launch. The study compiles data on every product that underwent FCC review from 2001 to 2021 and documents the use of STC and LTC. We estimate probit models, dividing the analysis into three periods: when LTC first diffused (2001-2007), when both LTC and STC simultaneously diffused (2008-2010), and when they reached a plateau (2011-2021). Considering the novelty of the research question, we adopt a broad approach to measuring the importance of four different categories that shape the use of confidentiality. The first category reflects competitive pressures at the product level, while the second measures the firm's ability to capture value. A third category measures the role of a firm’s experience, and the fourth measures the role of regulatory capture and related regulatory institutions. Findings suggest that the determinants of confidentiality use differ sharply between LTC and STC. For the early period (2001-2007), LTC is strongly associated with product complexity (i.e. frequency range) and competitive market conditions. Compared to unintentional radiators (zero frequency ranges), products with one to five frequency ranges are more likely to use LTC by 30 to 40%. Furthermore, products that use Bluetooth and WiFi frequencies are 20% more likely to utilize LTC, and phones are 30% more likely to use LTC. Being in a competitive product market increases the usage probability by an additional 15%. On the other hand, commodity products such as modules and transceivers, which are often outsourced to Asia, decrease LTC usage by 12 to 25%. Firm institutional knowledge plays a role: Asian firms are 20% less likely to use confidentiality, whereas European and Silicon Valley firms are 10% more likely to do so. In contrast, STC (2011-2021) is primarily driven by branding and life-cycle considerations. Large North American firms based in Silicon Valley, with products that are regulatorily complex and likely to experience delays, are the most likely to use STC by a total of 45%. In contrast, product complexity, such as frequency ranges, WiFi, and Bluetooth, is not predictive of STC usage. Also, competitive markets are weakly predictive of decreased STC usage. It is still true that outsourcing testing to Asia decreases usage probability by 10%. We interpret this as concerns about product launch delays and the need to protect branding. Accessing the Wi-Fi standard essential patents (SEPs) filed under IEEE 802.11 and those of large members of the Bluetooth SIG, we then consider the natural question of how LTC and STC interact with formal IPRs, such as patenting. Findings suggest that patenting and LTC are substitutes, particularly in the case of Wi-Fi during its early period, when it was still an emerging technology. The effect is very different for STC, as products with Bluetooth and Wi-Fi SEPs are more likely to use STC. We view this evidence as confirmation that LTC primarily involves the protection of technical complexity and the appropriability of product value itself, serving as a substitute for traditional IPR, such as trade secrets or patents. On the other hand, STC is concerned with the protection of branding and commercialization delays, which affect specific types of firms rather than products. To our knowledge, no other study has provided empirical evidence on the subtle differences in secrecy between permanent IP protection and short-term time-to-market protection. Appropriate for Whom? A Participatory Study of Youth Perspectives on Age-Appropriate AI University of Illinois Urbana Champaign, United States of America This research asks how 11-17-year-olds understand, experience, and envision age-appropriate AI, and how they navigate the tension between being seen and being surveilled in determining what is appropriate for them? Three sub-questions investigate the mental models and metaphors youth use to make sense of AI, how their conceptions of privacy, autonomy, care, and trust align with or diverge from existing adult-led frameworks, and what elements they prioritize when determining whether AI is appropriate for them. The question matters because the governance landscape for children and AI is fragmented across jurisdictional, institutional, and disciplinary lines. Binding legislation, statutory codes (the UK Age-Appropriate Design Code), voluntary international guidance (UNICEF's Policy Guidance on AI for Children), industry self-regulatory checklists, and academic models each define 'age-appropriate' through different logics, apply different age thresholds, and embed different assumptions about children's capacities. They converge on a single underlying paradigm: adult-authored protectionism operationalized through restriction, assuming children's primary relationship to technology is one of vulnerability. Shouli et al. (2026) document how governance frameworks built around any single stakeholder perspective which currently favors adults systematically misalign with youth's own experience of AI engagement they deem appropriate. Even frameworks rooted in children's rights (UNCRC, AADC's "best interests" standard) default in practice to risk aversion rather than rights realization. Wang et al.'s (2022) review of 188 AI systems designed for children found that 64% failed to explicitly consider ethical or safety risks. Kumar et al.'s (2023) analysis of 90 HCI publications found that children's participation in privacy and security research was largely limited to providing feedback rather than shaping the inquiry itself. Sweigart et al. (2025) corroborate this from their synthesis of the youth online safety literature and found that nearly all existing safety software was developed without input from youth. Polycentric governance models call for broader stakeholder engagement in AI oversight (Lim & Lim, 2025), yet modalities for engaging young people in governance processes barely exist (Solyst et al., 2023). This study addresses this empirical and methodological gap through a three-phase participatory study with 20 youth aged 11-17, drawing on critical youth studies, critical data studies, and participatory design. The study is organized around the tension between being seen (recognized, supported) and being surveilled (monitored, sorted by adult-defined logics). In Phase 1, participants complete metaphor elicitation activities and discuss their artifacts in semi-structured interviews. In Phase 2, youth jury focus groups organized by age band evaluate the UK AADC's 15 principles through card sorting and deliberation. Phase 3 maps youth-generated themes against the UK AADC and UNICEF guidance through comparative framework analysis, identifying convergence, divergence, and complications. The research generates empirical data on young people's everyday AI experiences across educational, domestic, and social contexts, documenting misalignments between youth priorities and existing governance frameworks. The contribution is also methodological: the study proposes a replicable participatory approach which includes metaphor elicitation, youth juries, card sorting activities with the aim to move youth engagement beyond consultation toward evaluation and co-interpretation. Expected findings include a typology of youth mental models of AI, a systematic comparison of youth-derived and adult-defined priorities, and preliminary components of a youth-informed framework for age-appropriate AI. These findings carry direct policy implications. Parental controls and age-assurance are key features across current frameworks yet both are failing in practice. Emergent research suggests that parental control tools show less than 1% adoption on major platforms, up to two-thirds of underage social media accounts are created with parental assistance, and surveillance-based tools correlate with eroded family trust without measurable protective effect. Cross-national evidence reinforces this: Köhler-Dauner et al. (2025) find that restrictive age limits are largely ineffective as youth circumvent them through technical means, while education-oriented and rights-based models yield more sustainable outcomes. Stoilova et al. (2024) conclude that parental controls should promote children's agency and that children should be consulted during tool development. The disconnect in prior studies reflects the epistemological gap this study documents: protections built without substantive youth input produce mechanisms young people circumvent rather than adopt. The Role of Network Quality on Adoption of FinTech and Financial Inclusion in Sub-Saharan Africa Countries University of Botswana, Botswana; University of Witwatersrand The deployment of mobile technologies has helped bridge the economic and infrastructural gap between urban and rural areas and more specifically, it has improved financial inclusion in Sub Saharan Africa countries. In this paper, we analyse the effect of network quality on adoption of digital financial technologies and financial inclusion using a survey data of 12,735 individuals from nine sub-Saharan African countries conducted in 2017. Network quality is proxied by availability of overlapping technologies (2G, 3G and 4G). Household that are within a 2 Km radius of areas that is covered by multiple networks considered to have strong coverage. We use probit and instrumental variable techniques to identify the impact of network quality on adotpion of FinTech and Mobile money. After controlling for household and individual characteristics, we find a negative and statistically significant relationship between the quality of network, proxied by distance from an area with overlapping mobile technologies and adoption of financial services, with a larger magnitude for Fintech than mobile money services. Comparing the estimated magnitudes across probit estimations, improvements in network quality is found to exert a larger influence in the likelihood of adopting Fintech services relative to mobile money services. Moreover, access to banks and household banking status are found to be strong positive predictors of adoption for both FinTech and mobile money services. The results further show a strong and persistent gender gap in FinTech and mobile money adoption. Female-headed households and larger households are significantly less likely to adopt digital financial services, particularly FinTech. Moreover, the results from probit estimates show a positive and marginally significant effect of marital status on adoption of Fintech and Mobile money. These results might suggest a greater demand for transacional services when household financial responsibilities increases. The coefficient on self-employed is positve and statistically significant at 1% level for Fintech specification and 5% level of significance for mobile money services. This result suggest that self-employed individuals are more likely to adopt both FinTech and mobile money services; however, the relationship is stronger for FinTech adoption. A finding that could be driven by the fact that majority of the self-employed individuals operate in the informal or semi-formal markets which are characterized by irregular income streams and limited access to formal financial institutions. The greater reliance of self-employed individuals on flexible payment and credit mechanisms, as shown by the results, reinforces the role of digital financial services underscores the importance of mobile money as a financial inclusion tool, particularly for entrepreneurial and liquidity constrained populations. A further analysis show that Fintech and mobile money services exhibits both substitutability and complementary characteristics. While Fintech and mobile money act as a substitute for formal banking services among the self employed and the lower-income population who were previously excluded by the formal banking services, they exhibit complimentary services for formal banking services among individuals in the middle-and upper- income groups and the younger and prime working-age individuals who have access to formal banking services. This is evidenced by results which indicate that individusals in the middle- and upper-income groups are approximately 6-7 percentage points more likely to adopt FinTech relative to lowest income groups. In contrast, mobile money adoption is found to act as a substitute for formal banking services among the relatively poor households who do not have access to formal banking services. The results indicate that mobile money adoption is highest among the poorest households, with individuals in the second income group being significantly less likely to adopt mobile money. These patterns suggest that FinTech adoption is more income-selective, whereas mobile money continues to play a central role in serving lower-income populations. To obtain the causal effect we use an instrumental variable approach, with mobile network quality instrumented by geographical variation in terrain slope at the household level. After correcting for potential endogeneity, the marginal effects suggest that a one-kilometre improvement in proximity to areas with higher network quality leads to a substantial increase in adoption probabilities. In particular, the likelihood of adoption of FinTech rises by approximately 9.9 percentage points while that of mobile money increases by 9.6 percentage points. The results further indicate that while both fintech and mobile money adoption respond positively to improvements in network quality, the magnitude of the effect differs, with the effect on fintech adoption comparatively larger as compared to effect on mobile money. These findings imply that investments in broadband and mobile network infrastructure can significantly accelerate financial inclusion outcomes in Sub Saharan Africa. Leveraging Large Language Models to Build Lightweight DNS Filtering Systems: Technical and Educational Reflections University of Texas at San Antonio, United States of America ---Motivation--- Small organizations, such as schools, small businesses, and public-sector institutions, often lack the resources and expertise needed to deploy advanced machine learning-based security solutions. As a result, they frequently rely on external filtering services that provide limited customization and oversight. Recent advances in generative AI, particularly large language models (LLMs), raise the possibility that non-expert users could leverage these tools to assist in developing specialized machine learning systems. This study explores whether commercially available LLMs can assist in the development of lightweight, low-cost, locally deployable machine learning models for DNS domain classification. DNS-based filtering is widely used by organizations to enforce network security policies and restrict access to undesirable or harmful online content. In addition to evaluating technical performance, the study reflects on the experience of a student developer using LLMs as collaborative tools in the machine learning development process. ---Methodology--- The project developed two classification models. The first performs binary classification of domains (ALLOWED vs. BLOCKED). The second performs multi-class classification of blocked domains into five categories: advertising, gambling, social media, pornography, and fake news. These categories represent content types commonly restricted by organizational network policies. To construct the training dataset, publicly available domain lists were combined, including the Alexa Top 1M, Cisco Umbrella Top 1M, and the Majestic Million, along with widely used community blocklists. Custom preprocessing scripts were used to normalize and label domain data. LLMs, including ChatGPT, Claude, and Gemini, were used as assistants during dataset discovery, feature engineering, and model selection. After evaluating several architectures recommended by LLMs, XGBoost was selected due to its speed and strong classification performance. Model evaluation focused on precision, recall, F1-score, and inference speed, reflecting practical constraints in DNS filtering environments. ---Summary of Results--- The locally trained models outperformed direct zero-shot prompting with commercial LLMs on the same classification tasks. Compared to LLM-only classification, the models achieved approximately 25% higher precision and 13% higher F1-score. In addition, the models achieved high inference speeds suitable for real-time DNS filtering applications. These results suggest that while LLMs are not ideal for direct deployment in DNS filtering pipelines due to latency and cost constraints, they can be highly effective as development assistants when building specialized machine learning models. ---Student and Instructor Reflection on LLM-Assisted Development--- From a student developer’s perspective, LLMs functioned as collaborative design partners rather than automated solutions. During the early stages, LLM-generated feature suggestions were sometimes impractical due to missing contextual constraints in the dataset. Iterative prompting and human verification were therefore necessary to refine recommendations and ensure technical feasibility. The instructor found that, for LLM assistance to be effective, the student must have a baseline knowledge of the domain. For example, the LLM's suggested data preprocessing and labeling techniques were either impossible, inefficient, or simply over-engineered. For this task and many others, prior knowledge and careful human analysis were paramount for the efficacy and efficiency of this LLM-assisted workflow. At the same time, LLM assistance significantly lowered the barrier to implementing machine learning pipelines. Tasks such as identifying relevant datasets, designing feature extraction strategies, and selecting appropriate model architectures became more accessible. This suggests that generative AI tools may help students and practitioners without extensive machine learning backgrounds build specialized AI systems. ---Governance and Implications--- These findings highlight both technical and educational implications. Technically, LLM-assisted workflows can enable organizations to develop low-cost, customized cybersecurity tools without deploying LLMs or AI agents directly in production environments. Educationally, generative AI may transform how students learn applied machine learning by acting as interactive development partners. Most notably, leveraging LLMs as assistants in the development of customized cybersecurity solutions allows small- and medium-sized organizations to regain sovereignty over their cybersecurity data and infrastructure. This provides greater flexibility and specificity in policymaking, enabling individual organizations to develop enforceable, realistic policies that reflect their unique goals and constraints. However, effective use of LLMs still requires human oversight, domain knowledge, and critical evaluation. As generative AI becomes integrated into technical workflows, educators and organizations must develop guidelines that encourage responsible collaboration between human developers and AI tools.
| |
