Symposium On Usable Privacy and Security

Draft Program

Subject to change

Day 1 - Monday Day 2 - Tuesday Day 3 - Wednesday
Monday begins at 12:30
9:00
Privacy Notices, Permissions & Labels
Session Chair: Maximiliane Windl
  • How Effective are Privacy Labels at Informing Users About App Data Handling Practices?
    • Sophia Walsh, University of Bristol
    • Lukasz Piwek, University of Bath
    • Kopo Marvin Ramokapane, University of Bristol
  • I don't know what I've all granted. Does it really matter? - Understanding Users' Awareness of Different Permission Types on Android
    • Verena Winterhalter, LMU Munich
    • Sarah Prange, LMU Munich
    • Anouk Moreno, LMU Munich
    • Harel Israel Berger, Ariel University
    • Florian Alt, LMU Munich and University of the Bundeswehr Munich
  • Nudging Developers Toward Privacy: Evaluating the Impact of Personalized App Review Reports
    • Sai Teja Peddinti, Google
    • Omer Akgul, RSAC Research
    • Michelle L. Mazurek, University of Maryland
    • Nina Taft, Google
10:00
Lightning talks
  • Jody Jacobs, Developing Human-Centered Cybersecurity Guidelines and Resources
  • Eman Alashwali, When Cybersecurity Meets Art
  • Lorin Schöni, The end of human heuristics in phishing defence?
  • Dimitri Staufer, What Should LLMs Forget? Why Machine Unlearning Needs Human-Centred Privacy Audits
  • Luisa Jansen, Do Researchers Meet Their Own Data Protection Requirements? An Opportunity for Usable Privacy Research
9:00
Usable Security Mechanisms & Emerging Threats
Session Chair: Florian Schaub
  • IdentitySign: Design and User Study of a Prototype Application for Digitally Signing Documents Using an Identity Wallet
    • Yorick Last, Paderborn University
    • Hanna Schraffenberger, Radboud University
    • Daniel Ostkamp, Radboud University
    • Jorrit Geels, Radboud University
    • Patricia Arias Cabarcos, European Commission Joint Research Centre (JRC)
  • Is It Real? Exploiting Virtual-Physical Discrimination Vulnerability in Mixed Reality
    • Xueyang Wang, Tsinghua University
    • Xihuan Yao, Tsinghua University
    • Yanming Xiu, Duke University
    • Xin Yi, Tsinghua University and Beijing Academy of Artificial Intelligence
    • Maria Gorlatova, Duke University
    • Hewu Li, Tsinghua University
  • Clear, Actionable and Confidence-Inspiring Recommendations? Comparative Study of AI-Generated and Human-Written Penetration Testing Reports
    • Katarina Galanska, Masaryk University
    • Maria Pibilota Murumaa, University of Tartu
    • Vashek Matyas, Masaryk University
    • Agata Kruzikova, Masaryk University
    • Mike Just, Heriot-Watt University
    • Tomas Cerny, The University of Arizona
10:00
Lightning talks
  • Florin Martius, Registered Reports at SOUPS: Call for Discussion
  • Simon Althaus, PIONEER - A PrIvacy companion for mOtivatioN and knowlEdge transfER
  • Christina Detsika and Julia Justen, Age Groups for Security and Privacy Studies with Children
  • Twain Byrnes, Toward Design Principles for Information-flow Security Tools
  • Camille Cobb, How do we encourage students (and ourselves) to take meaningful action against dystopian technologies?
  • Nicole Dircksen and Yasemin Acar, What should the security researchers do?
BREAK
BREAK
11:15
Security Operations & Practitioners
Session Chair: Gretchen (Jo) Hallett
  • Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit
    • Souradip Nath, Arizona State University
    • Chih-Yi Huang, Arizona State University
    • Aditi Ganapathi, Arizona State University
    • Kashyap Thimmaraju, Technische Universitat Berlin
    • Jaron Mink, Arizona State University
    • Gail-Joon Ahn, Arizona State University
  • The Impact of Emerging AI Practices on the Cybersecurity Workforce
    • Miuyin Yong Wong, University of Maryland
    • Alan Luo, University of Maryland
    • Yunze Zhao, University of Maryland
    • Shubham Bhatnagar, University of Maryland
    • Fabian Monrose, Georgia Institute of Technology
    • Michelle L. Mazurek, University of Maryland
  • From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
    • Faisal Haque Bappy, University of Maryland Baltimore County
    • Tahrim Hossain, University of Maryland Baltimore County
    • Sidratul Muntaher Meheraj, University of Dhaka
    • Annoor Sharara Akhand, University of Dhaka
    • Tasfia Tabassum, University of Dhaka
    • Tarannum Shaila Zaman, University of Maryland Baltimore County
    • Raiful Hasan, Kent State University
    • Tariqul Islam, University of Maryland Baltimore County
  • I See DNS People: DNS Resolver Security, Through Operator Perspectives and Practices
    • Wisdom Obinna, Georgetown University
    • Katharina Barlage, LMU Munich
    • Florian Alt, LMU Munich and University of the Bundeswehr Munich
    • Harel Israel Berger, Ariel University
11:15
Scams, Fraud & Misinformation
Session Chair: Mike Just
  • "You Have Been Selected as the Winner": Characterizing User-Reported Scams on TikTok
    • Smirity Kaushik, The George Washington University
    • Kyle Beadle, University College London
    • Gauri Nayak, Cornell University
    • Madelyn Rose Sanfilippo, University of Illinois at Urbana-Champaign
    • Mainack Mondal, Indian Institute of Technology, Kharagpur
    • Yang Wang, University of Illinois at Urbana-Champaign
    • Sai Teja Peddinti, Google
    • Jingjie Li, University of Edinburgh
    • Yixin Zou, Max Planck Institute for Security and Privacy
  • Source-Level Disengagement: A Usable Security Defense Against Misinformation
    • Zaid Hakami, Florida International University and Jazan University
    • Yuzhou Feng, Florida International University
    • Bogdan Carbunar, Florida International University
  • A Penny for Your Prompts: Experiments Detecting and Mitigating LLM Usage by Survey Respondents
    • Zane Xu, New Jersey Institute of Technology
    • Nathan Malkin, New Jersey Institute of Technology
  • SoK: Mapping Threats to Defenses in Online Survey Fraud
    • Shiza Ali, The George Washington University
    • Wellington Esposito Barbosa, The George Washington University
    • Matthias Fassl, The George Washington University
    • Aditi Ganapathi, Arizona State University
    • Jaron Mink, Arizona State University
    • Adam J. Aviv, The George Washington University
12:30
Opening remarks and awards
12:30
in-person speed mentoring / lunch
12:30
lunch
(town hall starts at 1:30)
13:00
Authentication & Credentials
Session Chair: Maximilian Golla
  • An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites
    • Alexander Krause, CISPA Helmholtz Center for Information Security
    • Jacques Suray, CISPA Helmholtz Center for Information Security
    • Lea Schmüser, CISPA Helmholtz Center for Information Security
    • Marten Oltrogge, CISPA Helmholtz Center for Information Security
    • Oliver Wiese, CISPA Helmholtz Center for Information Security
    • Maximillian Golla, CISPA Helmholtz Center for Information Security
    • Sascha Fahl, CISPA Helmholtz Center for Information Security
  • Passkeys in the Wild: A Systematic Study of FIDO2 User Experience Consistency Across Websites
    • Bernhardt Ramat, Brigham Young University
    • Dave Kartchner, Brigham Young University
    • Michael Clark, Brigham Young University
    • Kent Seamons, Brigham Young University
  • How Users Enter Generated Passwords on Non-Desktop Devices
    • John Sadik, The University of Tennessee, Knoxville
    • Joshoua Rodriguez, The University of Tennessee, Knoxville
    • Hector Santos Villalobos, The University of Tennessee, Knoxville
    • Scott Ruoti, The University of Tennessee, Knoxville
  • Not All Is Lost: Partial Recovery & Memorability in Self-Sovereign Digital Identity
    • Sushanth Ambati, Rowan University
    • Dylan Jablonski, Rowan University
    • Charalampos Papachristou, Rowan University
    • Brian Pugliese, Rowan University
    • Jack Myers, Rowan University
    • Nikolay Ivanov, Rowan University
14:00
Phishing & Social Engineering
Session Chair: Karola Marky
  • "I didn't know I would be this excited not to be scammed." Exploring Emotional and Behavioral Responses During Phishing Attacks
    • Raphael Weidhaas, Aalto University
    • Alexandra von Preuschen, CISPA Helmholtz Center for Information Security
    • Verena Distler, Aalto University
  • Anxious and Aware: Examining the Effects of Social Anxiety on Social Engineering Resilience and Vulnerability
    • Martin Dechant, University College London
    • Victoria Woo, University College London
    • Florence Tomlin, University College London
    • Bettina Moltrecht, University College London
    • Mark Warner, University College London
  • Quantifying Risk Perception and Scam Response Among International and Domestic US University Students
    • Alexandra Xinran Li, Carnegie Mellon University
    • Elijah Bouma-Sims, Carnegie Mellon University
    • Lily Klucinec, Carnegie Mellon University
    • Ray Liu, Carnegie Mellon University
    • Ayesha Binte Mostofa, University of Massachusetts, Amherst
    • Arjun Arunasalam, Florida International University
    • Lorrie Faith Cranor, Carnegie Mellon University
    • Pubali Datta, University of Massachusetts, Amherst
    • Lucy Simko, Barnard College, Columbia University
    • Karen Sowon, Indiana University
  • Experiences with Digital Scams Post-Incarceration in the U.S.
    • Yael Eiger, University of Washington
    • Candice Baughman, Interaction Transition
    • Rory Andes, Communities of Belonging
    • Bryan Glant, Project Rise
    • Franziska Roesner, University of Washington
14:00
GenAI Privacy & Risks
Session Chair: Nathan Malkin
  • AI've Got a Bad Feeling About This: A Privacy Threat Modeling Framework for GenAI
    • Qianying Liao, DistriNet, KU Leuven
    • Jonah Bellemans, DistriNet, KU Leuven
    • Laurens Sion, DistriNet, KU Leuven
    • Xue Jiang, Huawei Heisenberg Research Center (Munich)
    • Dmitrii Usynin, Huawei Heisenberg Research Center (Munich)
    • Xuebing Zhou, Huawei Heisenberg Research Center (Munich)
    • Dimitri Van Landuyt, LIRIS, KU Leuven
    • Lieven Desmet, DistriNet, KU Leuven
    • Wouter Joosen, DistriNet, KU Leuven
  • Understanding U.S. Users' Security and Privacy Transparency Needs for Consumer-Facing Generative AI
    • Jiaxun Cao, Duke University
    • Yu Dong, Duke University
    • Chunxi Zhan, Duke Kunshan University
    • Rithvik Neti, Duke University
    • Sai Teja Peddinti, Google
    • Pardis Emami-Naeini, Duke University
  • Maybe... I Don't Really Wanna Clone: Attitudes and Anticipated Harms of (Consensual) After-Death Cloning of One's Own and Voices of Entrusted Others
    • Jennifer Vander Loop, DePaul University
    • Filipo Sharevski, DePaul University
    • Lucy Davies, University of Bristol
    • Partha Das Chowdhury, University of Bristol
14:15
BREAK (30 minutes)
15:15
BREAK (30 minutes)
15:00
BREAK (45 minutes)
14:45
Families & Shared Devices
Session Chair: Miranda Wei
  • SoK: The Design Space of Usable Privacy Interventions for Parents: A Systematization of Knowledge
    • Ann-Kristin Lieberknecht, Goethe University Frankfurt
    • Sascha Loebner, University of Hamburg
  • "They are not my children to post": Examining Non-Parental Sharenting Practices in In-home Childcare
    • Meghna Gupta, University of Washington
    • Sophie Stephenson, University of Wisconsin-Madison
    • Apu Kapadia, Indiana University Bloomington
    • Julie Kientz, University of Washington
    • Franziska Roesner, University of Washington
  • Sharing Digital Devices is Normal and Cultural: Privacy and Security Challenges in Collectivist Immigrant Households
    • S. Shanza, University of Waterloo
    • Ameemah Humayun, Lahore University of Management Sciences
    • Urs Hengartner, University of Waterloo
    • Leah Zhang-Kennedy, University of Waterloo
  • From Thrift Stores to Digital Storefronts: Users' Perspectives on Privacy and Security of Online Second-Hand Shopping in Germany
    • Darya Zarkalam, Paderborn University
    • Anna Lena Rotthaler, Paderborn University
    • Lucy Simko, Barnard College
    • Yasemin Acar, Paderborn University
16:15
Keynote

Usable Security in Practice - How Tuta Makes Email Encryption Usable

  • Followed by a panel discussion with Matthew Smith and Carmela Troncoso
18:00
Poster session
15:45
At-Risk & Vulnerable Users
Session Chair: Zinaida Benenson
  • Usability Determines Safety for At-Risk Users: Evaluating Hidden Device Detectors for Intimate Partner Surveillance
    • Akhil Polamarasetty, University College London (UCL)
    • Leonie Maria Tanczer, University College London (UCL)
    • Enrico Costanza, University College London (UCL)
    • Kevin Chetty, University College London (UCL)
  • Goals, Risks, and Safety Practices in Online Labor Abuse Disclosures
    • Veronica A. Rivera, Max Planck Institute for Security and Privacy, Stanford University, and Georgia Institute of Technology
    • Tracy Li, Stanford University
    • Alex Ozdemir, Max Planck Institute for Security and Privacy and Georgia Institute of Technology
    • Catherine Han, Stanford University
    • Zakir Durumeric, Stanford University
    • Elissa M. Redmiles, Georgetown University
  • "I feel as though my privacy is being violated": Privacy Risks and Barriers in Instant Messaging for Blind and Low-Vision Users
    • Sohana Akter, University of Texas at San Antonio
    • Wejdan Al Sarih, University of Bristol
    • Blessy Kalluri, University of Texas at San Antonio
    • Kopo M. Ramokapane, University of Bristol
    • Taslima Akter, University of Texas at San Antonio
  • "Don't Let Them Get To You": Understanding the Role of TikTok as a Source of Support for Cyberbullying Victims
    • Saba Iqbal, Brigham Young University
    • Warda Usman, Brigham Young University
    • Daniel Zappala, Brigham Young University
  • Reproductive Security & Privacy Advice on TikTok after the Overturn of Roe
    • Harshini Sri Ramulu, Paderborn University
    • Rachel Gonzalez Rodriguez, Paderborn University
    • Yasemin Acar, Paderborn University
    • Lucy Simko, Barnard College
15:45
Security Advice & Education
Session Chair: Yixin Zou
  • Who Can Actually Follow IT-Security Advice? Exploring the Usability of IT-Security Advice
    • Dennis Lawo, University of Siegen
    • Jenny Hindrichs, University of Siegen
    • Gunnar Stevens, University of Siegen
  • CyQured: Design, Development, and Empirical Evaluation of a Tabletop Game for Personal Cybersecurity Education
    • Utsho Das, Shahjalal University of Science and Technology
    • Argha Pratim Saha, Shahjalal University of Science and Technology
    • Md Sadek Ferdous, BRAC University
    • Md Masum, Shahjalal University of Science and Technology
    • Farida Chowdhury, BRAC University
  • Nice to Know You're Not Alone: Co-designing Community-centered Online Safety and Privacy Education with Librarians
    • Tanisha Afnan, University of Michigan
    • Sheza Naveed, University of Michigan
    • Griffin Christie, University of Michigan
    • Jackie Hu, University of Michigan
    • Byron M. Lowens, Indiana University Indianapolis
    • Allison McDonald, Boston University
    • Florian Schaub, University of Michigan
  • Security versus Productivity: A Case Study of Email Management Practices with Job Task Analysis
    • Philip Shumway, University of Tulsa
    • Yi Ting Chua, University of Tulsa
    • Simon Parkin, Delft University of Technology
17:00
Closing + Poster Awards