{"id":"73a9515e-002f-40c1-b5d9-6c49c21384c2","arxiv_id":"2507.08853","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Clio-X applies compute-to-data and distant reading so AI can analyze sensitive archives without exposing them; a 14-participant study finds the main barriers are trust, opacity, cost, and governance.","lead":"Clio-X is a proposed Web3-based platform that lets researchers run AI analyses on sensitive archival records without the records leaving the archive's control. The paper reports a small user study of a prototype and finds interest but serious barriers around trust, transparency, cost, and governance.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Privacy guarantee is asserted, not demonstrated: no threat model, no leakage test, no masking accuracy, so the affirmative conclusion is unsupported.","rationale":"The reader's weakest-assumption analysis and mine converge: the decisive uncertain link is the privacy guarantee, not the user-study findings. I agree that the adoption-barrier results are qualitatively useful but cannot carry the technical claim. The paper's own text provides the strongest evidence for the gap: it labels the algorithm 'rudimentary' (§4), lists TEEs as 'e.g.' without implementation (§3.2/Step 5a), and reports users asking whether the system can be gamed (§4.1.1). No leakage study, no accuracy numbers, no reproducible artifact is reported. The conclusion overreaches. Still, this is a design-stage paper with transparent methods and appropriate limitations; the appropriate remedy is the reader's CONDITIONAL verdict requiring a threat model plus leakage/accuracy evaluation, not outright rejection. Therefore I leave the verdict unchanged.","tokens_in":19755,"tokens_out":4517,"duration_ms":100869,"concrete_test":"Obtain the exact masking algorithm and prototype used in Section 4, then run the full workflow on a ground-truth Enron subset where names, addresses, and email addresses are known. Give an independent adversary access to the returned visualizations and aggregate outputs and attempt to recover those entities (e.g., by n-gram matching or by prompting an LLM with the visualization). Pre-register a maximum allowed recovery rate (ideally 0 at the entity level). If recovery exceeds that rate, or masking recall on the held-out entities is below a pre-registered threshold, the privacy claim fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing assumption is that the CtD/TEE environment and the privacy-masking algorithm prevent sensitive data from being exposed in outputs. This is asserted in Section 2.5 ('TEEs ... provide a hardware-based secure environment'), Section 3.2 (the CtD design 'data never leaves custody'), and Workflow Step 5(a), but no threat model, adversary model, or privacy definition is supplied. The only implementation evidence is a medium-fidelity mockup and a 'custom, but still rudimentary' masking algorithm (Section 4) with no accuracy or leakage measurements. Section 2.5 cites Intel SGX and AWS Nitro without discussing well-known side-channel attacks; Section 4 participants themselves asked 'can it be essentially gamed?' and questioned whether replacing a name with 'name' still leaves the name in the system. Because the conclusion (Section 6) turns this unvalidated assumption into 'the potential to affirmatively answer yes,' the central claim is currently unsupported. The gap is not a matter of consensus; it is missing evidence for a security property that the paper needs.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents Clio-X, a decentralized Web3 architecture intended to let archives offer AI-enabled access to sensitive holdings without losing control of the underlying records. The proposed design combines compute-to-data (CtD) infrastructure, trusted execution environments (TEEs), a custom privacy-masking AI algorithm, blockchain-based access management via Pontus-X/Ocean/Oasis, and distant-reading visualizations. The empirical core is a user study of a medium-fidelity prototype with 14 archival practitioners and academics, analyzed through Braun and Clarke thematic analysis and ATLAS.ti; the qualitative findings identify trust-as-process, technical friction, black-box opacity, privacy-for-psychological-safety, desire for analytical value, and governance as determinants of adoption. The paper interprets the results through Rogers' Diffusion of Innovations theory and concludes that Web3 'offers the potential to affirmatively answer yes' to the question of whether PETs and distant reading can increase access to sensitive archival documents.","tokens_in":19962,"tokens_out":5222,"duration_ms":62379,"significance":"The qualitative contribution is genuine and well-reported: the study uses direct quotes, describes an explicit coding method, and includes an unusually honest limitations section covering the small sample, the missed data-consumer role, and incomplete coverage of the interview guide. The Rogers-based analysis is a plausible interpretive lens and the design recommendations are concrete. If the user-study findings are taken as the paper's main contribution, the manuscript is a useful sociotechnical study of adoption barriers for PET-based archival access. The technical side, however, is not at the same standard: the privacy guarantee is asserted rather than demonstrated, and the central affirmative conclusion rests on unvalidated assumptions about TEEs and the masking algorithm. The paper would be strengthened by clearly separating the empirically supported adoption findings from the still-unverified technical privacy claims.","major_comments":[{"comment":"The paper's affirmative conclusion is load-bearing and currently unsupported: no threat model, adversary model, privacy definition, or leakage measurement is supplied for the claim that records 'never leave the custody and control of the archives' (§3.2) while being processed in 'a secure and privacy-preserving compute environment (e.g., a trusted execution environment)' (§3.3, Step 5a). The only implementation evidence in §4 is a 'custom, but still rudimentary privacy-preserving AI algorithm' and a medium-fidelity mockup, with no description of what the algorithm actually does, no masking-accuracy results, and no resistance-to-attack evaluation. Section 2.5 cites Intel SGX and AWS Nitro without discussing known side-channel considerations. Participants in the study themselves asked 'can it be essentially gamed?' and questioned whether replacing a name with 'name' still leaves the name in the system. Because §6 converts this unvalidated assumption into 'the potential to affirmatively answer yes,' the central privacy claim is not established. This is missing evidence for a security property the paper needs, not a disagreement with consensus.","section":"§3.2, §3.3 (Workflow Step 5a), §4, §6"},{"comment":"The claim that distant-reading visualizations 'can shield sensitive information in the underlying records from exposure and eliminate the need for archivists to conduct sensitivity reviews' is asserted without any adversarial analysis of aggregate outputs. There is no demonstration that the visualization or masking pipeline resists inference, membership, or mosaic attacks, even though §2.2 itself notes the mosaic effect as a known privacy risk. Since the value proposition for archives is precisely the ability to open 'dark archives' without a sensitivity review, this is a load-bearing assumption and needs at least a formal privacy argument or an empirical leakage test, not just a citation to prior work.","section":"§2.7, §3.2"}],"minor_comments":[{"comment":"The abbreviation 'TTEs' should be 'TEEs' for Trusted Execution Environments.","section":"§2.3"},{"comment":"There is a dangling citation '[? ]' after the description of Oasis Sapphire's off-chain computation support; please supply the reference.","section":"§3.2"},{"comment":"The section numbering is inconsistent: '4 Method' is followed by '4 Automated Analysis', and '4.1.4 Design Recommendations' appears after an unnumbered subsection. Please renumber the methods and results subsections.","section":"§4"},{"comment":"The text says Appendix A contains 'details of an early low fidelity prototype', but the appendix shows presentation slides; clarify which artifact was actually used or add the missing low-fidelity prototype material.","section":"§4, Appendix A"},{"comment":"There are typos in the captions: 'Presention' in Appendix A and 'visualizaiton' in Figure 4; the text also refers to Figure 5 for the sentiment analysis while Figure 6 is later described as showing sentiment voices, so please check the figure references.","section":"Captions and figures"},{"comment":"The CCS Concepts list repeats 'Domain-specific security and privacy architectures' four times, and Table 1 breaks 'Infrastruc-ture' across lines; clean these up.","section":"Front matter and Table 1"},{"comment":"Foundational claims about TEEs, PPML, and blockchain attitudes rely heavily on the authors' own prior work ([4], [25], [57]); adding independent sources would make the background more accessible and easier to assess for readers outside this group.","section":"§2.5, §2.6"}],"recommendation":"major_revision","confidential_remarks":"The qualitative user study is a real contribution and the limitations are handled honestly, but the paper is framed around a technical privacy claim that is not demonstrated. If it remains in a security-oriented venue, the authors should either substantially strengthen the technical evaluation or explicitly reframe the conclusion as an untested hypothesis with clear security assumptions. I would not reject outright because the sociotechnical findings are worth publishing after revision, but the affirmative 'Web3 offers the potential to affirmatively answer yes' must be conditioned on the missing evidence."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The part worth reading here is the user study. The architecture is a mapping of existing Web3/PET components (Pontus-X, Ocean Protocol, Oasis Sapphire, compute-to-data, distant reading) onto archival workflows, with a 'rudimentary' masking algorithm. That is a useful design exercise, but it is not a technical systems paper. What is genuinely new is the 14-participant evaluation of a medium-fidelity prototype, and the reporting is honest: direct quotes, explicit coding method, ATLAS.ti cross-check, and a limitations section that names the small n, the missing data-consumer role, and incomplete coverage.\n\nThe findings themselves are believable and useful for the archival community: trust attaches to process, not product; blockchain is a 'black box' to many practitioners; privacy concerns are about the specific mechanism ('can it be gamed?'), not a policy checkbox; governance and non-profit models matter; and Rogers' Diffusion of Innovations is a reasonable frame, though the paper itself notes where the theory under-predicts structural and political-economy factors.\n\nThe soft spot is the load-bearing privacy claim. The paper asserts that the CtD/TEE environment and the masking algorithm protect sensitive data, but gives no threat model, no adversary definition, no leakage test, and no accuracy measurement for the masker. The participants themselves question whether replacing a name with 'name' still leaves the name in the system, and the paper does not answer them. TEEs like SGX are cited without acknowledging known side-channel work. The conclusion says Web3 'offers the potential to affirmatively answer yes'—note the word 'potential'—but the framing still leans on the unvalidated technical assumption. That gap is real, and it is the difference between a design proposal and a demonstrated solution.\n\nThat said, the paper does not oversell as much as it could: it calls the algorithm rudimentary, and the future-work section promises a real-setting evaluation. The empirical content is independent of the self-citations, so the citation pattern is not a problem.\n\nWho is this for? Archivists, digital humanities researchers, and people building PET-based data spaces for cultural heritage. The study gives them preliminary evidence about adoption barriers, and the honest reporting makes it citable. It deserves a serious referee—conditions should be a threat model and leakage/accuracy evaluation, or a clearly narrowed scope that drops the affirmative conclusion. Do not desk reject; send it out with a push for technical substantiation.","headline":"Solid qualitative study of adoption barriers, wrapped in an architecture whose privacy claim is not substantiated.","tokens_in":20477,"tokens_out":2411,"would_cite":true,"duration_ms":24014,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Clio-X makes the case that archive-controlled compute can let AI read sensitive records without exposing them.","keywords":["Web3","privacy-enhancing technologies","compute-to-data","archives","distant reading","trusted execution environment","data sovereignty","AI access"],"falsifier":"Run a reconstruction attack against the Clio-X pipeline on the Enron email dataset: if a researcher can recover names, addresses, or other sensitive strings from the returned statistics and visualizations, or compromise the secure enclave through a known side-channel, then the central privacy guarantee is false. A simpler check is to test whether masking is reversible by comparing masked outputs against the original corpus.","tokens_in":19568,"feed_emoji":"🔐","tokens_out":5458,"duration_ms":58350,"temperature":0.7,"pith_summary":"The paper argues that archives can let researchers run AI over sensitive records without giving up custody of the records, by combining a compute-to-data architecture, hardware-based secure computation, privacy-masking AI, and distant-reading visualizations. It presents Clio-X, a Web3 data-space design built on this combination, and reports on a user evaluation of a medium-fidelity prototype. The evaluation finds genuine interest in the idea, but also recurring distrust of opaque blockchain components, anxiety about AI hype and job security, and a demand for transparent governance. The authors conclude that the technical approach can affirmatively answer their research question, while real adoption will depend on usability and trust-building, not just the privacy technology.","feed_headline":"Clio-X lets AI read sensitive records without exposing them","feed_subtitle":"A Web3 design keeps records in place and returns only visualizations; user tests say trust, not tech, is the barrier.","key_machinery":"The load-bearing mechanism is the compute-to-data (CtD) workflow: the archive publishes only encrypted pointers and access tokens; a secure proxy verifies payment and rights; the compute job runs in an access-controlled, trusted-execution-environment-backed clean room at the data holder's site; and the researcher receives the job output, never the raw records. Around this core, Clio-X layers a privacy-preserving AI algorithm that masks sensitive features before analytics, and a visualization hub that turns outputs into distant readings. A confidential blockchain layer provides tamper-evident logs and automated payments. The argument depends on the claim that each layer prevents raw sensitive content from appearing in outputs.","core_discovery":"The central claim is that a compute-to-data architecture wrapped in Web3 infrastructure can increase researcher access to sensitive archival documents while the archives retain control of the data. In Clio-X, data stays at the archive, AI algorithms visit it inside a secure compute environment, and researchers receive only aggregated statistics and visualizations; a privacy-masking step replaces sensitive features before analysis, and distant-reading outputs are designed to reveal patterns rather than individual records. The paper's user study shows that archival professionals and academics do not dispute this technical vision so much as they question whether the system can be understood, audited, and trusted; participants framed trust as a continuous process requiring transparency, provenance, and accountable governance. The conclusion stops short of claiming the system is proven, instead asserting that the architecture offers the potential to answer the research question affirmatively.","pith_inferences":["The paper does not provide adversarial evidence that its masking and trusted-execution layers resist real attacks; a natural next test would be to try to re-identify individuals from Clio-X outputs on a public corpus such as the Enron emails.","If leakage-resistance were validated, the same architecture could generalize beyond archives to other regulated data holders, such as medical records or indigenous knowledge, where data sovereignty is the deciding barrier to sharing.","The finding that trust is process-based suggests that technical privacy guarantees alone are insufficient; governance and transparency may be the decisive adoption variables, a hypothesis the paper's own data supports but does not test.","The DAO proposal could be evaluated as a concrete trust mechanism: a controlled follow-up study could ask whether visible community voting and oversight actually change adoption attitudes among archivists."],"forward_implications":["If Clio-X works, archives could allow AI analysis of holdings that are currently closed because manual sensitivity review cannot keep pace, reducing 'dark archives' without exposing personal data.","Researchers could run exploratory analyses, topic modelling, clustering, and sentiment analysis over records they cannot currently see, receiving patterns rather than documents.","Tamper-evident logging and granular access policies could give custodians auditability, consent controls, and a way to revoke access after each computation.","The evaluation implies that even a privacy-correct system will not be adopted unless interfaces are transparent, governance is community-based, and users can trace how outputs are derived.","A decentralized autonomous organization is proposed as the next step to provide the visible, collective oversight that the evaluation shows users expect."],"supporting_citations":[{"why":"Motivates the use of privacy-enhancing technologies and distant reading to address privacy risks in archival AI use.","marker":"[4]"},{"why":"Supports the claim that distant reading can unlock sensitive archival records without document-level inspection.","marker":"[21]"},{"why":"Supplies the open-source data-space technology stack that Clio-X builds upon.","marker":"[42]"},{"why":"Provides the Gaia-X trust framework that grounds the architecture's governance and data-sovereignty claims.","marker":"[43]"},{"why":"Underlies the compute-to-data data-sharing model used in the Clio-X workflow.","marker":"[44]"},{"why":"Provides the confidential blockchain and trusted-execution-environment capabilities that protect data during processing.","marker":"[46]"},{"why":"Supplies the Enron email dataset used in the prototype demonstration shown to evaluation participants.","marker":"[47]"},{"why":"Gives the diffusion-of-innovations lens used to interpret adoption barriers in the user evaluation.","marker":"[55]"}],"fun_headline_variants":["AI visits archives, not the other way: Clio-X's privacy","Archives keep data; AI gets stats and visuals with Clio-X","Web3 privacy for AI archives: trust is the barrier","Trust, not tech, is the barrier for AI-driven archives"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The central premise is that the trusted execution environment and the privacy-masking algorithm actually prevent sensitive information from leaking into outputs; the paper calls the algorithm 'rudimentary' and provides no adversarial tests or leakage measurements.","fun_headline_variants_meta":{"raw":{"variants":["AI visits archives, not the other way: Clio-X's privacy","Archives keep data; AI gets stats and visuals with Clio-X","Web3 privacy for AI archives: trust is the barrier","Trust, not tech, is the barrier for AI-driven archives"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000536,"raw_usage":{"total_tokens":2547,"prompt_tokens":892,"completion_tokens":1655,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":508,"completion_tokens_details":{"reasoning_tokens":1581}},"tokens_in":508,"tokens_out":1655,"duration_ms":13770,"temperature":1.0,"reasoning_tokens":1581,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T19:00:16.630831+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run a reconstruction attack against the Clio-X pipeline on the Enron email dataset: if a researcher can recover names, addresses, or other sensitive strings from the returned statistics and visualizations, or compromise the secure enclave through a known side-channel, then the central privacy guarantee is false. A simpler check is to test whether masking is reversible by comparing masked outputs against the original corpus.","supporting_citations":[{"cited_title":"Protecting privacy in digital records: the potential of privacy-enhancing technologies","cited_arxiv_id":null,"evidence_quote":"Motivates the use of privacy-enhancing technologies and distant reading to address privacy risks in archival AI use."},{"cited_title":"Ai to review government records: new work to unlock historically significant digital records","cited_arxiv_id":null,"evidence_quote":"Supports the claim that distant reading can unlock sensitive archival records without document-level inspection."},{"cited_title":"Pontus-x portal, 2025","cited_arxiv_id":null,"evidence_quote":"Supplies the open-source data-space technology stack that Clio-X builds upon."},{"cited_title":"Pontus-x becomes a gaia-x lighthouse data space, 2025, March 21","cited_arxiv_id":null,"evidence_quote":"Provides the Gaia-X trust framework that grounds the architecture's governance and data-sovereignty claims."},{"cited_title":"Next generation data and ai ecosystems, 2025","cited_arxiv_id":null,"evidence_quote":"Underlies the compute-to-data data-sharing model used in the Clio-X workflow."},{"cited_title":"Oasis sapphire, 2025","cited_arxiv_id":null,"evidence_quote":"Provides the confidential blockchain and trusted-execution-environment capabilities that protect data during processing."},{"cited_title":"Enron emails, 2015","cited_arxiv_id":null,"evidence_quote":"Supplies the Enron email dataset used in the prototype demonstration shown to evaluation participants."},{"cited_title":"M.(2003)","cited_arxiv_id":null,"evidence_quote":"Gives the diffusion-of-innovations lens used to interpret adoption barriers in the user evaluation."}],"review_version":1}