Arosha K. Bandara

dblp:12/360 · DBLP profile ↗
← Back
42ranked-venue papers
3as first author
11since 2021 · last 2025
0000-0001-8974-0555ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 15 · 6 since 2021Software engineering, systems software and programming languages · 12 · 2 since 2021Computer networks · 5 · 3 first-author · 1 since 2021Security and privacy · 5Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2025 Labeling Synthetic Content: User Perceptions of Label Designs for AI-Generated Content on Social Media
abstract
In this research, we explored the efficacy of various warning label designs for AI-generated content on social media platforms—e.g., deepfakes. We devised and assessed ten distinct label design samples that varied across the dimensions of sentiment, color/iconography, positioning, and level of detail. Our experimental study involved 911 participants randomly assigned to these ten label designs and a control group evaluating social media content. We explored their perceptions relating to 1) Belief in the content being AI-generated, 2) Trust in the labels and 3) Social Media engagement perceptions of the content. The results demonstrate that the presence of labels had a significant effect on the user’s belief that the content is AI-generated, deepfake, or edited by AI. However their trust in the label significantly varied based on the label design. Notably, having labels did not significantly change their engagement behaviors, such as ’like’, comment, and sharing. However, there were significant differences in engagement based on content type: political and entertainment. This investigation contributes to the field of human-computer interaction by defining a design space for label implementation and providing empirical support for the strategic use of labels to mitigate the risks associated with synthetically generated media.
Dilrukshi Gamage, Dilki Sewwandi, Min Zhang 0027, Arosha K. Bandara
CHI4
2025 Predicting Loneliness Using Machine Learning and Self-Logged Behavioural Data
abstract
Loneliness is a growing public health concern, particularly among older adults, and has been linked to adverse physical and mental health outcomes. This study presents a machine learning approach to predict levels of loneliness using behavioural and emotional data collected from 124 participants through a mobile phone application over a 71-day period. The dataset includes 27 features derived from self-logged information such as wellbeing scores, mood fluctuations, and time spent in various home locations. Feature selection was applied to identify the most discriminative indicators, with classification and regression models evaluated using both Support Vector Machine (SVM), and Random Forest (RF). We applied feature selection to identify the most discriminative indicators and evaluated both Support Vector Machine (SVM) and Random Forest (RF) models for classification and regression. The highest classification accuracy—69.19% on a 7-point loneliness scale—was achieved using a five-fold SVM with the top 13 features. In the regression task, the best performance was observed using 26 features, resulting in a minimum Mean Squared Error (MSE) of 0.6752. These findings indicate that a selected subset of behavioural and emotional features can offer a meaningful estimation of loneliness levels. This has potential to inform the design of real-time, personalised digital tools aimed at identifying and supporting individuals at risk of loneliness.
Mohamed Bennasar, Dmitri S. Katz, Avelie Stuart, Amel Bennaceur, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
KES6
2025 Co-creating an Ontology of Online Gender-Based Harms: An Interdisciplinary Perspective
Miriam Fernández, Alba Catalina Morales Tirado, Ángel Pavón Pérez, Keely Duddin, Min Zhang 0027, Ksenia Bakina, Arosha K. Bandara, Rose Capdevila, Lisa Lazard, Olga Jurasz
ISWC (2)7
2024 Understanding Pedestrians' Perception of Safety and Safe Mobility Practices
abstract
Walking is one of the greenest and most common travel modes. However, evidence shows a trend of decreased walking, and safety is a key barrier preventing many people from walking. Additionally, there is a limited understanding of pedestrians’ safe mobility practices and safety perception. Drawing on 449 survey responses from a representative sample in the United Kingdom, our work highlights how identities and walking situations intersect with individuals’ safety perceptions and diverse practices of pedestrians’ safe mobility. The role of technology used for negotiating safety and current challenges in both safe route planning and walking are also highlighted. Our work extends existing insights into pedestrians’ perception of safety and practices by adding empirical evidence and more nuanced contexts. This paper proposes two implications for design in response to design opportunities that surfaced from our mixed-method data analysis. Both the contributions and limitations of our work are also discussed.
Min Zhang 0027, Arosha K. Bandara
CHI2
2024 Taming App Reliability: Mobile Analytics "in the wild"
abstract
The importance of mobile apps in people’s lives places a responsibility on app developers to ensure that their software is reliable. Despite the widespread use of mobile analytics tools to support this task, there is limited understanding of their use in industrial app development contexts. This paper reports on industry experiences of using mobile analytics tools through a case study based approach. The key findings highlight four main factors that affect developers’ practice and identify ways of improving the effectiveness of mobile analytics to help developers make their apps more reliable.
Julian Harty, Arosha K. Bandara
EASE2
2024 Reflections on using the story completion method in designing tangible user interfaces
abstract
There are many design techniques to support the co-design of tangible technologies. However, few of these design methods allow the involvement of users at scale and across diverse geographic locations. While popular in psychology, the story completion method (SCM) has only recently started to be adopted within the HCI community. We explore whether SCM can generate meaningful design insights from large, diverse study populations for the design of Tangible User Interfaces (TUIs). Based on the results of two questionnaire studies using SCM, we conclude that the method can be used to generate meaningful design insights. Drawing on a systematic review of 870 TUI papers, we then contextualise the strengths and weaknesses of SCM against commonly used design methods, before reflecting on our experience of using the method across two distinct domains. We discuss the advantages of the method (particularly in terms of the scale and diversity of participation) and the challenges (particularly around constructing meaningful story stems, and developing the correct level of scaffolding to support creativity). We conclude that SCM is particularly suitable to be used in the early stages of the design process to understand the socio-cultural context of deployment.
Daniel Gooch, Arosha K. Bandara, Amel Bennaceur, Emilie Giles, Lydia Harkin, Dmitri S. Katz, Mark Levine, Vikram Mehta, Bashar Nuseibeh, Clifford Stevenson, Avelie Stuart, Catherine V. Talbot, Blaine A. Price
Int. J. Hum. Comput. Stud.2
2023 Towards a Socio-Technical Understanding of Police-Citizen Interactions
Min Zhang 0027, Arosha K. Bandara, Richard Philpot, Avelie Stuart, Zoe Walkington, Camilla Elphick, Lara Frumkin, Graham Pike, Blaine A. Price, Mark Levine, Bashar Nuseibeh
INTERACT (3)2
2023 A Card-based Ideation Toolkit to Generate Designs for Tangible Privacy Management Tools
abstract
Effective privacy protection in dynamic UbiComp environments requires users to be able to manage their privacy seamlessly across diverse contexts. To support this, designers need to go beyond GUI-based interactions and utilise tangible and embodied interactions. To help designers in such endeavours, we present the TTP toolkit: a card-based ideation kit to generate designs for tangible privacy management tools. The toolkit translates the Privacy Care framework for tangible-supported privacy management into a game intended to support designers in developing TUI privacy management tools. We demonstrate use of our toolkit through 10 online participatory workshops with 22 interaction designers. Our results demonstrate that the toolkit was effective in supporting the participants to creatively and collaboratively generate meaningful conceptual designs of tangible tools for privacy management.
Vikram Mehta, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
TEI3
2023 Security Responses in Software Development
abstract
The pressure on software developers to produce secure software has never been greater. But what does security look like in environments that do not produce security-critical software? In answer to this question, this multi-sited ethnographic study characterizes security episodes and identifies five typical behaviors in software development. Using theory drawn from information security and motivation research in software engineering, this article characterizes key ways in which individual developers form security responses to meet the demands of particular circumstances, providing a framework managers and teams can use to recognize, understand, and alter security activity in their environments.
Tamara Lopez, Helen Sharp, Arosha K. Bandara, Thein Tun, Mark Levine, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.3
2021 Up Close & Personal: Exploring User-preferred Image Schemas for Intuitive Privacy Awareness and Control
abstract
Effective end-user privacy management in everyday ubiquitous computing environments requires giving users complex, contextual information about potential privacy breaches and enabling management of these breaches in a timely, engaging and intuitive manner. In this paper, we propose using empirically grounded image schema-based metaphors to help design these interactions. Results from our exploratory user study (N=22) demonstrate end users’ preferences for changes in physical attributes and spatial properties of objects for privacy awareness. For privacy control, end users prefer to exert force and create spatial movement. The study also explores user preferences for wearable vs. ambient form-factors for managing privacy and concludes that a hybrid solution would work for more users across more contexts. We thus provide a combination of form factor preferences, and a focused set of image schemas for designers to use when designing metaphor-based tangible privacy management tools.
Vikram Mehta, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh, Daniel Gooch
TEI2
2021 Privacy Care: A Tangible Interaction Framework for Privacy Management
abstract
The emergence of ubiquitous computing (UbiComp) environments has increased the risk of undesired access to individuals’ physical space or their information, anytime and anywhere, raising potentially serious privacy concerns. Individuals lack awareness and control of the vulnerabilities in everyday contexts and need support and care in regulating disclosures to their physical and digital selves. Existing GUI-based solutions, however, often feel physically interruptive, socially disruptive, time-consuming and cumbersome. To address such challenges, we investigate the user interaction experience and discuss the need for more tangible and embodied interactions for effective and seamless natural privacy management in everyday UbiComp settings. We propose the Privacy Care interaction framework, which is rooted in the literature of privacy management and tangible computing. Keeping users at the center,AwarenessandControlare established as the core parts of our framework. This is supported with three interrelated interaction tenets:Direct, Ready-to-Hand,andContextual. Direct refers to intuitiveness through metaphor usage. Ready-to-Hand supports granularity, non-intrusiveness, and ad hoc management, through periphery-to-center style attention transitions. Contextual supports customization through modularity and configurability. Together, they aim to provide experience of an embodied privacy care with varied interactions that are calming and yet actively empowering. The framework provides designers of such care with a basis to refer to, to generate effective tangible tools for privacy management in everyday settings. Through five semi-structured focus groups, we explore the privacy challenges faced by a sample set of 15 older adults (aged 60+) across their cyber-physical-social spaces. The results show conformity to our framework, demonstrating the relevance of the facets of the framework to the design of privacy management tools in everyday UbiComp contexts.
Vikram Mehta, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
ACM Trans. Internet Techn.3
2020 How are you feeling?: Using Tangibles to Log the Emotions of Older Adults
abstract
The global population is ageing, leading to shifts in healthcare needs. Home healthcare monitoring systems currently focus on physical health, but there is an increasing recognition that psychological wellbeing also needs support. This raises the question of how to design devices that older adults can interact with to log their feelings. We designed three tangible prototypes, based on existing paper-based scales of affect. We report findings from a lab study in which participants used the prototypes to log the emotion from standardised emotional vignettes. We found that the prototypes allowed participants to accurately record identified emotions in a reasonable time. Our participants expressed a perceived need to record emotions, either to share with family/carers or for self-reflection. We conclude that our work demonstrates the potential for in-home tangible devices for recording the emotions of older adults to support wellbeing.
Daniel Gooch, Vikram Mehta, Blaine A. Price, Ciaran McCormick, Arosha K. Bandara, Amel Bennaceur, Mohamed Bennasar, Avelie Stuart, Linda Clare, Mark Levine, Jessica Cohen, Bashar Nuseibeh
TEI5
2020 Designing privacy-aware internet of things applications
Charith Perera, Mahmoud Barhamgi, Arosha K. Bandara, Muhammad Ajmal Azad, Blaine A. Price, Bashar Nuseibeh
Inf. Sci.3
2020 EUD-MARS: End-user development of model-driven adaptive robotics software systems
Pierre A. Akiki, Paul A. Akiki, Arosha K. Bandara, Yijun Yu 0001
Sci. Comput. Program.3
2019 Knowledge-Based Architecture for Recognising Activities of Older People
abstract
The world is facing an ageing population phenomenon, coupled with health and social problems, which affect older people’s ability to live independently. This situation challenges the viability of health and social services. Smart home technology can play a significant role in easing the pressure on caregivers, as well as reduce the financial costs of health and social services. Activity of Daily Living (ADL) recognition is an essential step to translate sensor data into activities at high semantic levels. Supervised Machine Learning (ML) algorithms are the most commonly used techniques for this application. However, a common problem is a lack of availability of enough annotated data to train these algorithms. Collecting annotated data is expensive, time consuming, and may violate people’s privacy. Intra- and inter-personal variation in performing complex activities is another challenge for an ML-based activity recognition approach. In this paper, a multi-layered knowledge-based architecture for recognising ADL in real-time is proposed. At the first stage, sensor data is pre-processed; events that describe changes in the environment are detected at the second stage, in which the sequence of events is used to recognise more semantically complex activities at the third stage. A new ADL ontology is proposed to model the knowledge related to the sensor platform and the targeted activities as the previously proposed ontologies were either designed to deal with specific sensor data, or they ignored the context environment information which is important in recognising complex activities.
Mohamed Bennasar, Blaine A. Price, Avelie Stuart, Daniel Gooch, Ciaran McCormick, Vikram Mehta, Linda Clare, Amel Bennaceur, Jessica Cohen, Arosha K. Bandara, Mark Levine, Bashar Nuseibeh
KES10
2018 Feature-Driven Mediator Synthesis: Supporting Collaborative Security in the Internet of Things
abstract
As the number, complexity, and heterogeneity of connected devices in the Internet of Things (IoT) increase, so does our need to secure these devices, the environment in which they operate, and the assets they manage or control. Collaborative security exploits the capabilities of these connected devices and opportunistically composes them to protect assets from potential harm. By dynamically composing these capabilities, collaborative security implements the security controls that satisfy both security and non-security requirements. However, this dynamic composition is often hampered by the heterogeneity of the devices available in the environment and the diversity of their behaviours. In this article, we present a systematic, tool-supported approach for collaborative security where the analysis of requirements drives the opportunistic composition of capabilities to realise the appropriate security control in the operating environment. This opportunistic composition is supported through a combination of feature modelling and mediator synthesis. We use features and transition systems to represent and reason about capabilities and requirements. We formulate the selection of the optimal set of features to implement adequate security control as a multi-objective constrained optimisation problem and use constraint programming to solve it efficiently. The selected features are then used to scope the behaviours of the capabilities and thereby restrict the state space for synthesising the appropriate mediator. The synthesised mediator coordinates the behaviours of the capabilities to satisfy the behaviour specified by the security control. Our approach ensures that the implemented security controls are the optimal ones, given the capabilities available in the operating environment. We demonstrate the validity of our approach by implementing a feature-driven mediation for collaborative security tool and applying it to a collaborative robots case study.
Amel Bennaceur, Thein Than Tun, Arosha K. Bandara, Yijun Yu 0001, Bashar Nuseibeh
ACM Trans. Cyber Phys. Syst.3
2017 Enabling End-Users to Protect their Privacy
abstract
In this paper we present our ongoing work to build an approach to empower users of IoT-based cyber physical systems to protect their privacy by themselves. Our approach allows users to identify the privacy risks involved in sharing private data with a data consumer, assess the value of their private data based on identified risks and take a pragmatic data sharing decision balancing the risks with the benefits generated by the sharing. Our approach features a knowledgebase, called the Privacy Oracle, that exploits the power of the Semantic Web to determine how raw metadata can be combined by data consumers to infer privacy-sensitive information as well as the privacy risks associated with the disclosure of inferred information.
Mahmoud Barhamgi, Mu Yang, Chia-Mu Yu, Yijun Yu 0001, Arosha K. Bandara, Djamal Benslimane, Bashar Nuseibeh
AsiaCCS5
2017 Learning to share: engineering adaptive decision-support for online social networks
abstract
Some online social networks (OSNs) allow users to define friendship-groups as reusable shortcuts for sharing information with multiple contacts. Posting exclusively to a friendship-group gives some privacy control, while supporting communication with (and within) this group. However, recipients of such posts may want to reuse content for their own social advantage, and can bypass existing controls by copy-pasting into a new post; this cross-posting poses privacy risks. This paper presents a learning to share approach that enables the incorporation of more nuanced privacy controls into OSNs. Specifically, we propose a reusable, adaptive software architecture that uses rigorous runtime analysis to help OSN users to make informed decisions about suitable audiences for their posts. This is achieved by supporting dynamic formation of recipient-groups that benefit social interactions while reducing privacy risks. We exemplify the use of our approach in the context of Facebook.
Yasmin Rafiq, Luke Dickens, Alessandra Russo, Arosha K. Bandara, Mu Yang, Avelie Stuart, Mark Levine, Gül Çalikli, Blaine A. Price, Bashar Nuseibeh
ASE4
2017 Identifying Conflicting Requirements in Systems of Systems
abstract
A System of Systems (SoS) is an arrangement of useful and independent sub-systems, which are integrated into a larger system. Examples are found in transport systems, nutritional systems, smart homes and smart cities. The composition of component sub-systems into an SoS enables support for complex functionalities that cannot be provided by individual sub-systems on their own. However, to realize the benefits of these functionalities it is necessary to address several software engineering chal-lenges including, but not limited to, the specification, design, construction, deployment, and management of an SoS. The various component sub-systems in an SoS environment are often concerned with distinct domains; are developed by different stake-holders under different circumstances and time; provide distinct functionalities; and are used by different stakeholders, which allow for the existence of conflicting requirements. In this paper, we present a framework to support management of emerging conflicting requirements in an SoS. In particular, we describe an approach to support identification of conflicts between resource-based requirements (i.e. requirements concerned with the con-sumption of different resources). In order to illustrate and evaluate the work, we use an example of a pilot study of an IoT SoS ecosystem designed to support food security at different levels of granularity, namely individuals, groups, cities, and nations.
Thiago Viana, Andrea Zisman, Arosha K. Bandara
RE3
2017 Visual Simple Transformations: Empowering End-Users to Wire Internet of Things Objects
abstract
Empowering end-users to wire Internet of Things (IoT) objects (things and services) together would allow them to more easily conceive and realize interesting IoT solutions. A challenge lies in devising a simple end-user development approach to support the specification of transformations, which can bridge the mismatch in the data being exchanged among IoT objects. To tackle this challenge, we present Visual Simple Transformations (ViSiT) as an approach that allows end-users to use a jigsaw puzzle metaphor for specifying transformations that are automatically converted into underlying executable workflows. ViSiT is explained by presenting meta-models and an architecture for implementing a system of connected IoT objects. A tool is provided for supporting end-users in visually developing and testing transformations. Another tool is also provided for allowing software developers to modify, if they wish, a transformation's underlying implementation. This work was evaluated from a technical perspective by developing transformations and measuring ViSiT's efficiency and scalability and by constructing an example application to show ViSiT's practicality. A study was conducted to evaluate this work from an end-user perspective, and its results showed positive indications of perceived usability, learnability, and the ability to conceive real-life scenarios for ViSiT.
Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001
ACM Trans. Comput. Hum. Interact.2
2016 Engineering Adaptive Model-Driven User Interfaces
abstract
Software applications that are very large-scale, can encompass hundreds of complex user interfaces (UIs). Such applications are commonly sold as feature-bloated off-the-shelf products to be used by people with variable needs in the required features and layout preferences. Although many UI adaptation approaches were proposed, several gaps and limitations including: extensibility and integration in legacy systems, still need to be addressed in the state-of-the-art adaptive UI development systems. This paper presents Role-Based UI Simplification (RBUIS) as a mechanism for increasing usability through adaptive behavior by providing end-users with a minimal feature-set and an optimal layout, based on the context-of-use. RBUIS uses an interpreted runtime model-driven approach based on the Cedar Architecture, and is supported by the integrated development environment (IDE), Cedar Studio. RBUIS was evaluated by integrating it into OFBiz, an open-source ERP system. The integration method was assessed and measured by establishing and applying technical metrics. Afterwards, a usability study was carried out to evaluate whether UIs simplified with RBUIS show an improvement over their initial counterparts. This study leveraged questionnaires, checking task completion times and output quality, and eye-tracking. The results showed that UIs simplified with RBUIS significantly improve end-user efficiency, effectiveness, and perceived usability.
Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001
IEEE Trans. Software Eng.2
2015 Teaching Software Systems Thinking at The Open University
abstract
The Open University is a distance-based higher education institution. Most of our students are in employment and study from home, contacting their tutor and fellow students via e-mail and discussion forums. In this paper, we describe our undergraduate and postgraduate modules in the software systems area, how we teach them at a distance, and our focus on shifting our students' minds into a reflective, critical, holistic socio-technical view of software systems that is relevant to their particular professional contexts.
Michel Wermelinger, Jon G. Hall, Lucia Rapanotti, Leonor Barroca 0001, Magnus Ramage, Arosha K. Bandara
ICSE (2)6
2014 Traceability for Adaptive Information Security in the Cloud
abstract
One of the key challenges in cloud computing is the security of the consumer data stored and processed by cloud machines. When the usage context of a cloud application changes, or when the context is unknown, there is a risk that security policies are violated. To minimize this risk, cloud applications need to be engineered to adapt their security policies to maintain satisfaction of security requirements despite changes in their usage context. We call such adaptation capability Adaptive Information Security. The paper argues that one of the prerequisites to adaptive information security is the use of traceability as a means to understanding the relationship between security requirements and security policies. Using an example, we motivate the need for improving traceability in the development of cloud applications.
Armstrong Nhlabatsi, Thein Than Tun, Niamul Khan, Yijun Yu 0001, Arosha K. Bandara, Khaled M. Khan, Bashar Nuseibeh
IEEE CLOUD5
2014 Integrating adaptive user interface capabilities in enterprise applications
abstract
Many existing enterprise applications are at a mature stage in their development and are unable to easily benefit from the usability gains offered by adaptive user interfaces (UIs). Therefore, a method is needed for integrating adaptive UI capabilities into these systems without incurring a high cost or significantly disrupting the way they function. This paper presents a method for integrating adaptive UI behavior in enterprise applications based on CEDAR, a model-driven, service-oriented, and tool-supported architecture for devising adaptive enterprise application UIs. The proposed integration method is evaluated with a case study, which includes establishing and applying technical metrics to measure several of the method’s properties using the open-source enterprise application OFBiz as a test-case. The generality and flexibility of the integration method are also evaluated based on an interview and discussions with practitioners about their real-life projects.
Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001
ICSE2
2014 Distilling privacy requirements for mobile applications
abstract
As mobile computing applications have become commonplace, it is increasingly important for them to address end-users’ privacy requirements. Privacy requirements depend on a number of contextual socio-cultural factors to which mobility adds another level of contextual variation. However, traditional requirements elicitation methods do not sufficiently account for contextual factors and therefore cannot be used effectively to represent and analyse the privacy requirements of mobile end users. On the other hand, methods that do investigate contextual factors tend to produce data that does not lend itself to the process of requirements extraction. To address this problem we have developed a Privacy Requirements Distillation approach that employs a problem analysis framework to extract and refine privacy requirements for mobile applications from raw data gathered through empirical studies involving end users. Our approach introduces privacy facets that capture patterns of privacy concerns which are matched against the raw data. We demonstrate and evaluate our approach using qualitative data from an empirical study of a mobile social networking application.
Keerthi Thomas, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
ICSE2
2014 Adaptive Sharing for Online Social Networks: A Trade-off Between Privacy Risk and Social Benefit
abstract
Online social networks such as Facebook allow users to control which friend sees what information, but it can be a laborious process for users to specify every receiver for each piece of information they share. Therefore, users usually group their friends into social circles, and select the most appropriate social circle to share particular information with. However, social circles are not formed for setting privacy policies, and even the most appropriate social circle still cannot adapt to the changes of users' privacy requirements influenced by the changes in context. This problem drives the need for better privacy control which can adaptively filter the members in a selected social circle to satisfy users' requirements while maintaining users' social needs. To enable such adaptive sharing, this paper proposes a utility-based trade-off framework that models users' concerns (i.e. Potential privacy risks) and incentives of sharing (i.e. Potential social benefits), and quantifies users' requirements as a trade-off between these two types of utilities. By balancing these two metrics, our framework suggests a subset of a selected circle that aims to maximise users' overall utility of sharing. Numerical simulation results compare the outcome of three sharing strategies in randomly changing contexts.
Mu Yang, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh
TrustCom3
2012 Privacy arguments: Analysing selective disclosure requirements for mobile applications
abstract
Privacy requirements for mobile applications offer a distinct set of challenges for requirements engineering. First, they are highly dynamic, changing over time and locations, and across the different roles of agents involved and the kinds of information that may be disclosed. Second, although some general privacy requirements can be elicited a priori, users often refine them at runtime as they interact with the system and its environment. Selectively disclosing information to appropriate agents is therefore a key privacy management challenge, requiring carefully formulated privacy requirements amenable to systematic reasoning. In this paper, we introduce privacy arguments as a means of analysing privacy requirements in general and selective disclosure requirements (that are both content- and context-sensitive) in particular. Privacy arguments allow individual users to express personal preferences, which are then used to reason about privacy for each user under different contexts. At runtime, these arguments provide a way to reason about requirements satisfaction and diagnosis. Our proposed approach is demonstrated and evaluated using the privacy requirements of BuddyTracker, a mobile application we developed as part of our overall research programme.
Thein Than Tun, Arosha K. Bandara, Blaine A. Price, Yijun Yu 0001, Charles B. Haley, Inah Omoronyia, Bashar Nuseibeh
RE2
2012 Starting with Ubicomp: using the senseboard to introduce computing
abstract
In this paper, we describe a new undergraduate module for novice students conducted entirely through distance learning: My Digital Life (TU100). The module has been designed to lower the barriers to creating programs that interact with the world; TU100's materials have been designed to excite, encourage, reassure and support learners who explore the novel topic of ubiquitous computing through playful experimentation. It introduces the fundamentals of computing by giving students the capability for programming a device, the SenseBoard, which has built-in input/output and sensors. Programming is done in Sense, an extension of Scratch, which scaffolds programming and reduces the syntax burden. TU100 has taken inspiration from childhood learning and commercial product design to produce compelling, yet academically rigorous study materials.
Mike Richards, Marian Petre, Arosha K. Bandara
SIGCSE3
2012 Analysing monitoring and switching problems for adaptive systems
Mohammed Salifu, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh
J. Syst. Softw.3
2011 In the best families: tracking and relationships
abstract
A growing body of research has been exploring the use of control mechanisms to address the privacy concerns raised by location-tracking technology. We report on a qualitative study of two family groups who used a custom-built tracking application for an extended period of time. Akin to sociological breaching experiments, the study focuses on the interferences between location tracking and relationship management. We analyze the tensions that can arise between affordances of the technology and uses that the contracts between family members legitimize. We describe how, by fostering misperceptions and 'nudging' behaviors, location-tracking technology can generate anxieties and conflicts even in close relationships. We discuss their vulnerability to the overreaching effects of tracking, against which the use of mechanisms such as location-sharing preferences and feedback may not be socially viable.
Clara Mancini, Yvonne Rogers, Keerthi Thomas, Adam N. Joinson, Blaine A. Price, Arosha K. Bandara, Lukasz Jedrzejczyk, Bashar Nuseibeh
CHI6
2010 Contravision: exploring users' reactions to futuristic technology
abstract
How can we best explore the range of users' reactions when developing future technologies that may be controversial, such as personal healthcare systems? Our approach -- ContraVision -- uses futuristic videos, or other narrative forms, that convey either negative or positive aspects of the proposed technology for the same scenarios. We conducted a user study to investigate what range of responses the different versions elicited. Our findings show that the use of two systematically comparable representations of the same technology can elicit a wider spectrum of reactions than a single representation can. We discuss why this is so and the value of obtaining breadth in user feedback for potentially controversial technologies.
Clara Mancini, Yvonne Rogers, Arosha K. Bandara, Tony Coe, Lukasz Jedrzejczyk, Adam N. Joinson, Blaine A. Price, Keerthi Thomas, Bashar Nuseibeh
CHI3
2010 "Privacy-shake", : a haptic interface for managing privacy settings in mobile location sharing applications
abstract
We describe the "Privacy-Shake", a novel interface for managing coarse grained privacy settings. We built a prototype that enables users of Buddy Tracker, an example location sharing application, to change their privacy preferences by shaking their phone. Users can enable or disable location sharing and change the level of granularity of disclosed location by shaking and sweeping their phone. In this poster we present and motivate our work on Privacy-Shake and report on a lab-based evaluation of the interface with 16 participants.
Lukasz Jedrzejczyk, Blaine A. Price, Arosha K. Bandara, Bashar Nuseibeh
Mobile HCI3
2010 On the impact of real-time feedback on users' behaviour in mobile location-sharing applications
abstract
Effective privacy management requires that mobile systems' users be able to make informed privacy decisions as their experience and knowledge of a system progresses. Prior work has shown that making such privacy decisions is a difficult task for users because systems do not provide support for awareness, visibility and accountability when sharing privacy-sensitive information. This paper reports results of our investigation into the efficacy of real-time feedback as a mechanism for incorporating these features of social translucence in location-sharing applications, in order to help users make better privacy decisions. We explored the role of real-time feedback in the context of Buddy Tracker, a mobile location-sharing application. Our work focuses on ways in which real-time feedback affects people's behaviour in order to identify the main criteria for acceptance of this technology. Based on the data from a three week field trial of Buddy Tracker, a focus group session, and interviews, we found that when using a system that provided real-time feedback, people were more accountable for their actions and reduced the number of unreasonable location requests. We have used the results of our study to propose high-level design criteria for incorporating real-time feedback into information sharing applications in a manner that ensures social acceptance of the technology.
Lukasz Jedrzejczyk, Blaine A. Price, Arosha K. Bandara, Bashar Nuseibeh
SOUPS3
2010 Commentary on 'Software architectures and mobility: A Roadmap'
Michel Wermelinger, Arosha K. Bandara
J. Syst. Softw.2
2009 Expressive policy analysis with enhanced system dynamicity
abstract
Despite several research studies, the effective analysis of policy based systems remains a significant challenge. Policy analysis should at least (i) be expressive (ii) take account of obligations and authorizations, (iii) include a dynamic system model, and (iv) give useful diagnostic information. We present a logic-based policy analysis framework which satisfies these requirements, showing how many significant policy-related properties can be analysed, and we give details of a prototype implementation.
Robert Craven, Jorge Lobo 0001, Jiefei Ma, Alessandra Russo, Emil C. Lupu, Arosha K. Bandara
AsiaCCS6
2009 From spaces to places: emerging contexts in mobile privacy
abstract
Mobile privacy concerns are central to Ubicomp and yet remain poorly understood. We advocate a diversified approach, enabling the cross-interpretation of data from complementary methods. However, mobility imposes a number of limitations on the methods that can be effectively employed. We discuss how we addressed this problem in an empirical study of mobile social networking. We report on how, by combining a variation of experience sampling and contextual interviews, we have started focusing on a notion of context in relation to privacy, which is subjectively defined by emerging socio-cultural knowledge, functions, relations and rules. With reference to Gieryn's sociological work, we call this place, as opposed to a notion of context that is objectively defined by physical and factual elements, which we call space. We propose that the former better describes the context for mobile privacy.
Clara Mancini, Keerthi Thomas, Yvonne Rogers, Blaine A. Price, Lukasz Jedrzejczyk, Arosha K. Bandara, Adam N. Joinson, Bashar Nuseibeh
UbiComp6
2009 Using argumentation logic for firewall configuration management
abstract
Firewalls remain the main perimeter security protection for corporate networks. However, network size and complexity make firewall configuration and maintenance notoriously difficult. Tools are needed to analyse firewall configurations for errors, to verify that they correctly implement security requirements and to generate configurations from higher-level requirements. In this paper we extend our previous work on the use of formal argumentation and preference reasoning for firewall policy analysis and develop means to automatically generate firewall policies from higher-level requirements. This permits both analysis and generation to be done within the same framework, thus accommodating a wide variety of scenarios for authoring and maintaining firewall configurations. We validate our approach by applying it to both examples from the literature and real firewall configurations of moderate size (ap 150 rules).
Arosha K. Bandara, Antonis C. Kakas, Emil C. Lupu, Alessandra Russo
Integrated Network Management1
2009 Studying location privacy in mobile applications: 'predator vs. prey' probes
abstract
No abstract available.
Keerthi Thomas, Clara Mancini, Lukasz Jedrzejczyk, Arosha K. Bandara, Adam N. Joinson, Blaine A. Price, Yvonne Rogers, Bashar Nuseibeh
SOUPS4
2009 Policy conflict analysis for diffserv quality of service management
abstract
Policy-based management provides the ability to (re-)configure differentiated services networks so that desired Quality of Service (QoS) goals are achieved. This requires implementing network provisioning decisions, performing admission control, and adapting bandwidth allocation to emerging traffic demands. A policy-based approach facilitates flexibility and adaptability as policies can be dynamically changed without modifying the underlying implementation. However, inconsistencies may arise in the policy specification. In this paper we provide a comprehensive set of QoS policies for managing Differentiated Services (DiffServ) networks, and classify the possible conflicts that can arise between them. We demonstrate the use of Event Calculus and formal reasoning for the analysis of both static and dynamic conflicts in a semi-automated fashion. In addition, we present a conflict analysis tool that provides network administrators with a user-friendly environment for determining and resolving potential inconsistencies. The tool has been extensively tested with large numbers of policies over a range of conflict types.
Marinos Charalambides, Paris Flegkas, George Pavlou, Javier Rubio-Loyola, Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman
IEEE Trans. Netw. Serv. Manag.5
2006 Dynamic Policy Analysis and Conflict Resolution for DiffServ Quality of Service Management
abstract
Policy-based dynamic resource management may involve interaction between independent decision-making components which can lead to conflicts. For example, conflicts can occur between the policies for allocating resources and those setting quotas for users or classes of service. These policy conflicts cannot be detected by static analysis of the policies at specification-time as the conflicts arise from the current state of the resources within the system and so can only be detected at run-time. In this paper we use policies related to quality of service (QoS) provisioning for configuring differentiated services (DiffServ) networks to illustrate techniques for the dynamic detection and resolution of conflicts. Configuration includes implementing network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically according to emerging traffic demands. We identify possible conflicts between policies that manage the allocation of resources, and we also investigate conflicts that may arise between these policies and higher-level directives refined at the dynamic resource management level, acting as constraints. The paper shows how event calculus can be used to detect conflicts, focusing on the ones that emerge at run-time, and provides an approach for specifying policies to automate conflict resolution. The latter is demonstrated through our initial implementation of a dynamic conflict analysis tool
Marinos Charalambides, Paris Flegkas, George Pavlou, Javier Rubio-Loyola, Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Morris Sloman, Naranker Dulay
NOMS5
2006 Policy refinement for IP differentiated services Quality of Service management
abstract
Policy-based management provides the ability to dynamically re-configure DiffServ networks such that desired Quality of Service (QoS) goals are achieved. This includes network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically. QoS management aims to satisfy the Service Level Agreements (SLAs) contracted by the provider and therefore QoS policies are derived from SLA specifications and the provider's business goals. This policy refinement is usually performed manually with no means of verifying that the policies written are supported by the network devices and actually achieve the desired QoS goals. Tool support is lacking and policy refinement has rarely been addressed in the literature. This paper extends our previous approach to policy refinement and shows how to apply it to the domain of DiffServ QoS management. We make use of goal elaboration and abductive reasoning to derive strategies that will achieve a given high-level goal. By combining these strategies with events and constraints, we show how policies can be refined, and what tool support can be provided for the refinement process using examples from the QoS management domain. The approach presented here can be used in other application domains such as storage area networks or security management.
Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman, Paris Flegkas, Marinos Charalambides, George Pavlou
IEEE Trans. Netw. Serv. Manag.1
2005 Policy refinement for DiffServ quality of service management
abstract
Policy-based management provides the ability to dynamically re-configure DiffServ networks such that desired quality of service (QoS) goals are achieved. This includes network provisioning decisions, performing admission control, and adapting bandwidth allocation dynamically. QoS management aims to satisfy the service level agreements (SLAs) contracted by the provider and therefore QoS policies are derived from SLA specifications and the provider's business goals. This policy refinement is usually performed manually with no means of verifying that the policies written are supported by the network devices and actually achieve the desired QoS goals. Tool support is lacking and policy refinement has rarely been addressed in the literature. This paper extends our previous approach to policy refinement and shows how to apply it to the domain of DiffServ QoS management. We make use of goal elaboration and abductive reasoning to derive strategies that achieves a given high-level goal. By combining these strategies with events and constraints, we show how policies can be refined, and what tool support can be provided for the refinement process using examples from the QoS management domain. However, the approach presented here can be used in other application domains such as storage area networks or security management.
Arosha K. Bandara, Emil C. Lupu, Alessandra Russo, Naranker Dulay, Morris Sloman, Paris Flegkas, Marinos Charalambides, George Pavlou
Integrated Network Management1