VLDB 2026 Research / reviewers in the wild / expert
Yu-Ju Yang
dblp:00/8115
· DBLP profile ↗
4ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0005-1989-0044ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product ConceptsabstractAI creates and exacerbates privacy risks, yet practitioners lack effective resources to identify and mitigate these risks. We present Privy, a tool that guides practitioners without privacy expertise through structured privacy impact assessments to: (i) identify relevant risks in novel AI product concepts, and (ii) propose appropriate mitigations. Privy was shaped by a formative study with 11 practitioners, which informed two versions — one LLM-powered, the other template-based. We evaluated these two versions of Privy through a between-subjects, controlled study with 24 separate practitioners, whose assessments were reviewed by 13 independent privacy experts. Results show that Privy helps practitioners produce privacy assessments that experts deemed high quality: practitioners identified relevant risks and proposed appropriate mitigation strategies. These effects were augmented in the LLM-powered version. Practitioners themselves rated Privy as being useful and usable, and their feedback illustrates how it helps overcome long-standing awareness, motivation, and ability barriers in privacy work. Hao-Ping Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek, Thomas Serban Von Davier, Kyzyl Monteiro, Shivani Agarwal 0008, Jodi Forlizzi, Sauvik Das |
CHI | 2 |
| 2025 | Boundary Negotiating Artifacts to Envision the Desired Research Data Infrastructure Toward Reproducibility in Data-Intensive Science
Wei Jeng, Yu-Ju Yang, Hong-Chun Chen, Yi-Jie Yang, Yi-Ru Shih |
Comput. Support. Cooperative Work. | 2 |
| 2024 | Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy RisksabstractPrivacy is a key principle for developing ethical AI technologies, but how does including AI technologies in products and services change privacy risks? We constructed a taxonomy of AI privacy risks by analyzing 321 documented AI privacy incidents. We codified how the unique capabilities and requirements of AI technologies described in those incidents generated new privacy risks, exacerbated known ones, or otherwise did not meaningfully alter the risk. We present 12 high-level privacy risks that AI technologies either newly created (e.g., exposure risks from deepfake pornography) or exacerbated (e.g., surveillance risks from collecting training data). One upshot of our work is that incorporating AI technologies into a product can alter the privacy risks it entails. Yet, current approaches to privacy-preserving AI/ML (e.g., federated learning, differential privacy, checklists) only address a subset of the privacy risks arising from the capabilities and data requirements of AI. Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, Sauvik Das |
CHI | 2 |
| 2010 | A Personalized Rhythm Click-Based Authentication SystemabstractPurpose In keystroke-based authentication systems, an input device to enter a password is needed. Users are verified by checking the validity of the password and typing characteristics. However, some devices have no standard desktop keyboard such as personal digital assistants and mobile phones. With these types of electronics, the system cannot successfully work in the authentication phase while the registration process is implemented based on a computer keyboard. This results in a reduction of system portability. The purpose of this paper is to employ the rhythm clicked by a mouse as another identifiable factor to authenticate a user's identity. Design/methodology/approach Mouse click can be replaced by a stylus and fingers on touch screens or numeral buttons on mobile phones. A total of 25 users participated and the click data are based on time instances of pressing and releasing the mouse button, which are captured while the user clicks a rhythm. Three features are calculated using these click data, and a reasonable amount of results with neural networks and other classifiers shows the click characteristics are able to function as another identifiable factor. Findings A reasonable amount of results with neural networks and other classifiers shows the click characteristics are able to function as another identifiable factor. Originality/value The paper presents a personalized rhythm click-based authentication system. Ting-Yi Chang, Yu-Ju Yang, Chun-Cheng Peng |
Inf. Manag. Comput. Secur. | 2 |