Umeå University's logo

umu.sePublications
Change search
Link to record
Permanent link

Direct link
Baura, Divya
Publications (3 of 3) Show all publications
Baura, D. & Calvanese, D. (2026). Assessing privacy requirements for controlled query evaluation in OBDA. In: Vicenç Torra; Yasuo Narukawa; Josep Domingo-Ferrer (Ed.), Modeling decisions for artificial intelligence: 22nd International Conference, MDAI 2025, València, Spain, September 15–18, 2025, Proceedings. Paper presented at 22nd International Conference on Modeling Decisions for Artificial Intelligence, MDAI 2025, València, Spain, September 15-18, 2025 (pp. 183-197). Cham: Springer Nature
Open this publication in new window or tab >>Assessing privacy requirements for controlled query evaluation in OBDA
2026 (English)In: Modeling decisions for artificial intelligence: 22nd International Conference, MDAI 2025, València, Spain, September 15–18, 2025, Proceedings / [ed] Vicenç Torra; Yasuo Narukawa; Josep Domingo-Ferrer, Cham: Springer Nature, 2026, p. 183-197Conference paper, Published paper (Refereed)
Abstract [en]

Within the Ontology Based Data Access (OBDA) framework, users can query relational data sources using an ontology to which the source is linked via declarative mappings. In a world where data sharing is widespread, ensuring privacy while managing data poses a significant challenge. Controlled Query Evaluation (CQE) is a privacy preserving query answering framework in the presence of ontologies, where policies representing confidential information are used to devise suitable censors that enforce data protection. The integration of CQE within OBDA was recently proposed through the Policy-Protected OBDA (PPOBDA) framework, which is based on embedding policies into mappings. Such framework is essentially theoretical, and the effectiveness with which PPOBDA policies are able to capture real-world privacy requirements has not been assessed so far. In this work, we carry out such an evaluation, utilizing the well-known MIMIC-III hospital dataset, which recently has been mapped, by adopting the OBDA framework, to the Fast Healthcare Interoperability Resources (FHIR) ontology. We identify relevant privacy requirements by analyzing the legal regulations on data sharing expressed in HIPAA of US Federal Law and GDPR of the EU, show how they can be expressed via PPOBA policies, and analyze the impact of these policies on the answers to a set of representative queries. Our analysis exposes both strengths and weaknesses of the PPOBA framework in relation to these practically relevant privacy regulations. Furthermore, we perform a performance evaluation of the OBDA framework implemented over the MIMIC-III dataset via the FHIR ontology, assessing the overhead introduced by the PPOBDA policies and its implications on such real-world use case.

Place, publisher, year, edition, pages
Cham: Springer Nature, 2026
Series
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349 ; 15957
Keywords
Controlled Query Evaluation, FHIR ontology, MIMIC-III Dataset, OMOP-CDM Data Model, Policy-Protected OBDA
National Category
Computer Sciences
Identifiers
urn:nbn:se:umu:diva-243632 (URN)10.1007/978-3-032-00891-6_15 (DOI)2-s2.0-105013616409 (Scopus ID)978-3-032-00890-9 (ISBN)978-3-032-00891-6 (ISBN)
Conference
22nd International Conference on Modeling Decisions for Artificial Intelligence, MDAI 2025, València, Spain, September 15-18, 2025
Available from: 2025-08-29 Created: 2025-08-29 Last updated: 2025-08-29Bibliographically approved
Baura, D. & Calvanese, D. (2026). User access control in policy-protected virtual knowledge graphs. In: Hideaki Takeda; Yannis Tzitzikas; Giorgos Flouris; Shizhu He; Dimitris Plexousakis; Sébastien Ferré; Ran Yu; Vasilis Efthymiou; Eleni Ilkou; Ernesto Jiménez-Ruiz; Xin Wang (Ed.), Knowledge Graphs: 14th International Joint Conference, IJCKG 2025, Heraklion, Crete, Greece, October 15–17, 2025, Proceedings. Paper presented at 14th International Joint Conference, IJCKG 2025, Heraklion, Crete, Greece, October 15–17, 2025 (pp. 204-219). Springer Nature
Open this publication in new window or tab >>User access control in policy-protected virtual knowledge graphs
2026 (English)In: Knowledge Graphs: 14th International Joint Conference, IJCKG 2025, Heraklion, Crete, Greece, October 15–17, 2025, Proceedings / [ed] Hideaki Takeda; Yannis Tzitzikas; Giorgos Flouris; Shizhu He; Dimitris Plexousakis; Sébastien Ferré; Ran Yu; Vasilis Efthymiou; Eleni Ilkou; Ernesto Jiménez-Ruiz; Xin Wang, Springer Nature, 2026, p. 204-219Conference paper, Published paper (Refereed)
Abstract [en]

Virtual Knowledge Graph (VKG) is a well-established framework in which users can access a relational data source through an ontology and declarative mappings. VKG systems traditionally assume uniform access rights for all users, an assumption that does not always hold in real-world scenarios involving diverse user roles and sensitive information requiring protection. Controlled Query Evaluation (CQE) provides a privacy-preserving framework by enforcing policies that define confidential information and implementing censors to prevent policy violations. However, it does not account for differences in user privileges during query answering. To address this gap, we extend the Policy-Protected VKG (PPVKG) framework, which embeds CQE policies into VKG mappings, by enabling role-sensitive query answering. Specifically, we incorporate Role-Based Access Control (RBAC) into PPVKG, by associating to each user role a specific set of policies, and ensuring that during query evaluation, only the policies relevant to the user’s role are applied. We validate our RBAC enhanced PPVKG approach using the MIMIC-III critical-care database, mapped to the Fast Healthcare Interoperability Resources (FHIR) ontology. Our experiments, conducted with the open-source VKG system Ontop, demonstrate effective policy enforcement with RBAC.

Place, publisher, year, edition, pages
Springer Nature, 2026
Series
Lecture Notes in Computer Science (LNCS), ISSN 0302-9743, E-ISSN 1611-3349 ; 16297
Keywords
Controlled Query Evaluation, Policy-protected VKG, Role-Based Access Control, Virtual Knowledge Graph
National Category
Computer Sciences
Identifiers
urn:nbn:se:umu:diva-252867 (URN)10.1007/978-981-95-5009-8_14 (DOI)2-s2.0-105035328357 (Scopus ID)9789819550081 (ISBN)9789819550098 (ISBN)
Conference
14th International Joint Conference, IJCKG 2025, Heraklion, Crete, Greece, October 15–17, 2025
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)
Available from: 2026-05-07 Created: 2026-05-07 Last updated: 2026-05-07Bibliographically approved
Baura, D., Calvanese, D. & Marconi, L. (2024). Implementing controlled query evaluation in OBDA. In: JOWO 2024. The Joint Ontology Workshops: Proceedings of the Joint Ontology Workshops (JOWO) - Episode X: The Tukker Zomer of Ontology, and satellite events co-located with the 14th International Conference on Formal Ontology in Information Systems (FOIS 2024). Paper presented at 2024 Joint Ontology Workshops (JOWO) - Episode X: The Tukker Zomer of Ontology, and satellite events co-located with the 14th International Conference on Formal Ontology in Information Systems (FOIS 2024), Enschede, The Netherlands, July 15-19, 2024. CEUR-WS, Article ID st4cm-1.
Open this publication in new window or tab >>Implementing controlled query evaluation in OBDA
2024 (English)In: JOWO 2024. The Joint Ontology Workshops: Proceedings of the Joint Ontology Workshops (JOWO) - Episode X: The Tukker Zomer of Ontology, and satellite events co-located with the 14th International Conference on Formal Ontology in Information Systems (FOIS 2024), CEUR-WS , 2024, article id st4cm-1Conference paper, Published paper (Refereed)
Abstract [en]

In the Ontology Based Data Access (OBDA) framework, users access a relational data source by querying a domain ontology, whose classes and properties are connected to the data via declarative mappings. OBDA is adopted for data management in various sectors, notably healthcare, where confidentiality of information is a key concern that requires data to be properly protected from unauthorized accesses. Controlled Query Evaluation (CQE) is a framework for privacy-preserving query answering in the presence of an ontology. In CQE, policies are used to represent the information that should be kept confidential, and the aim is to devise from policy specifications suitable censors that enforce data protection. Therefore, it is desirable to integrate CQE in OBDA to obtain a robust privacy-aware data management framework. This has been done in the recently proposed Policy-Protected OBDA (PPOBDA) framework, which ensures the integration of CQE within OBDA by embedding policies into mappings. In this paper, we present an open-source solution that implements PPOBDA and a simplified algorithm for policy embedding, compared to previously proposed ones. This facilitates the adoption of PPOBDA using any OBDA query engine capable of translating SPARQL queries into SQL. In our implementation, we rely on Ontop, a state-of-the-art open-source OBDA tool.

Place, publisher, year, edition, pages
CEUR-WS, 2024
Series
CEUR workshop proceedings, ISSN 1613-0073 ; 3882
Keywords
Controlled Query Evaluation, Ontology Based Data Access, Ontop, Policy-Protected OBDA, Privacy
National Category
Computer Sciences Computer Systems
Identifiers
urn:nbn:se:umu:diva-234314 (URN)2-s2.0-85214567303 (Scopus ID)
Conference
2024 Joint Ontology Workshops (JOWO) - Episode X: The Tukker Zomer of Ontology, and satellite events co-located with the 14th International Conference on Formal Ontology in Information Systems (FOIS 2024), Enschede, The Netherlands, July 15-19, 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)German Research Foundation (DFG)
Available from: 2025-01-23 Created: 2025-01-23 Last updated: 2025-01-23Bibliographically approved
Organisations

Search in DiVA

Show all publications