Nalin Arachchilage

dblp:124/8007 · also Nalin A. G. Arachchilage, Nalin Asanka, Nalin Asanka Gamagedara Arachchilage · DBLP profile ↗
← Back
22ranked-venue papers
0as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 since 2021Human-computer interaction and ubiquitous computing · 8 · 5 since 2021Software engineering, systems software and programming languages · 5 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 From Trust to Compromise: Outcome-Verified LLM Phishing Simulation and Real-Time Defense
abstract
Tulika Tewari, Nalin Asanka Gamagedara Arachchilage, Jagat Sesh Challa, Dhruv Kumar. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Tulika Tewari, Nalin Arachchilage, Jagat Sesh Challa, Dhruv Kumar 0001
ACL (1)2
2026 AGentVLM: Access control policy generation and verification framework with language models
abstract
• We introduce AGentVLM, a novel access control policy generation and verification framework. • We introduce a novel access control-specific structured information extraction method for translating complex natural language access requirements into access control policies. • We introduce a novel access control policy verification technique. • We evaluate AGentVLM, showing it achieves state-of-the-art accuracy. • We release two annotated datasets, addressing the data scarcity. Manual generation of access control policies from high-level organizational requirements is labor-intensive and error-prone, often leading to critical failures and data breaches. While automated frameworks have been proposed, existing approaches struggle with complex access requirements due to poor domain adaptation, limiting their accuracy. To address these challenges, we propose AGentVLM, a novel access control policy generation and verification framework based on small, open-source language models (LMs). Our framework enables its efficient on-premise deployment, preserving data confidentiality by avoiding reliance on third-party black-box LMs. AGentVLM excels in identifying natural language access control policies (NLACPs) from high-level requirements, achieving an average F1 score of 90.6 %. Unlike existing frameworks limited to generating simple policies with three components (subject, action, resource), AGentVLM effectively extracts complex elements such as purposes and conditions using an access control-specific structured information extraction technique. This method captures both word-level and semantic information at the same time from NLACPs, leading to a state-of-the-art policy generation F1 score of 80.6 %. Additionally, AGentVLM introduces a verification technique that provides actionable feedback, allowing administrators to refine inaccurate policies before deployment. To support future research, we also release two annotated datasets addressing the scarcity of domain-specific data.
Sakuna Harinda Jayasundara, Nalin Arachchilage, Giovanni Russello
J. Inf. Secur. Appl.2
2025 How Are We Doing With Using AI-Based Programming Assistants For Privacy-Related Code Generation? The Developers' Experience
abstract
With generative AI becoming widespread, the existence of AI-based programming assistants for developers is no surprise. Developers increasingly use them for their work, including generating code to fulfil the data protection requirements (privacy) of the apps they build. We wanted to know if the reality is the same as expectations of AI-based programming assistants when trying to fulfil software privacy requirements, and the challenges developers face when using AI-based programming assistants and how these can be improved. To this end, we conducted a survey with 51 professional developers worldwide. We found that AI-based programming assistants need to be improved in order for developers to better trust them with generating code that ensures privacy. In this paper, we provide some recommendations including model and system-level improvements and some key further research directions to improve AI-based programming assistants for developing secure code.
Kashumi Madampe, John C. Grundy, Nalin Arachchilage
EASE3
2025 Real-time privacy vulnerability detection techniques in software development: A Systematic Literature Review
Nadisha Madhushanie, Sugandima Vidanagamachchi, Nalin Arachchilage
Comput. Secur.3
2025 PrivacyCube: Data Physicalization for Enhancing Privacy Awareness in IoT
abstract
People are increasingly bringing Internet of Things (IoT) devices into their homes without understanding how their data is gathered, processed, and used. We describe PrivacyCube, a novel data physicalization designed to increase privacy awareness within smart home environments. PrivacyCube visualizes IoT data consumption by displaying privacy-related notices. PrivacyCube aims at assisting smart home occupants to (i) understand their data privacy better and (ii) have conversations around data management practices of IoT devices used within their homes. Using PrivacyCube, households can learn and make informed privacy decisions collectively. To evaluate PrivacyCube, we used multiple research methods throughout the different stages of design. We first conducted a focus group study in two stages with six participants to compare PrivacyCube to text and state-of-the-art privacy policies. We then deployed PrivacyCube in a 14-day-long in-home field study with eight households. Lastly, we conducted an event-based field study comparing PrivacyCube with a mobile application, engaging 26 participants with diverse demographics. Our results show that PrivacyCube helps home occupants comprehend IoT privacy better with significantly increased privacy awareness at p < .05 (p = 0.00041, t = -5.57). Participants preferred PrivacyCube over text privacy policies because it was comprehensive and easier to use. PrivacyCube, Privacy Label, and the mobile application, all received positive reviews from participants, with PrivacyCube being preferred for its interactivity and ability to encourage conversations. PrivacyCube was also considered by home occupants as a piece of home furniture , encouraging them to socialize and discuss IoT privacy implications using this device. Watch the demo ( Demo Video ) ( Source Code ).
Bayan Al Muhander, Nalin Arachchilage, Yasar Majib, Mohammed Alosaimi, Omer F. Rana, Charith Perera
ACM Trans. Internet Things2
2021 A Serious Game Design Framework for Software Developers to Put GDPR into Practice
abstract
The growth of the internet has significantly increased data breaches (i.e. privacy breaches) in software systems. It could be argued that software developers failed to implement privacy into software systems with the appropriate privacy guidelines or laws such as the General Data Protection Regulation (GDPR). GDPR has a set of guidelines that enables software developers to implement privacy into software systems. Nevertheless, these guidelines have been developed with lawyers in mind, rather than software developers. This could hinder developers from putting GDPR into practice and eventually lead to data breaches through the systems they develop. On the other hand, software developers also need help (e.g. tooling support or educational interventions). Therefore, this paper proposes a game design framework, as an educational intervention, to teach software developers to implement privacy-preserving software systems taking GDPR on-board. The proposed framework focuses on improving developers’ security coding behavior through their motivation. It also ensures software developers can put GDPR into practice when developing privacy-preserving software systems.
Abdulrahman Alhazmi, Nalin Arachchilage
ARES2
2021 Better, Funner, Stronger: A Gameful Approach to Nudge People into Making Less Predictable Graphical Password Choices
abstract
Graphical user authentication (GUA) is a common alternative to text-based user authentication, where people are required to draw graphical passwords on background images. Such schemes are theoretically considered remarkably secure because they offer a large password space. However, people tend to create their passwords on salient image areas introducing high password predictability. Aiming to help people use the password space more effectively, we propose a gameful password creation process. In this paper, we present GamePass, a gamified mechanism that integrates the GUA password creation process. We provide the first evidence that it is possible to nudge people towards better password choices by gamifying the process. GamePass randomly guides participants’ attention to areas other than the salient areas of authentication images, makes the password creation process more fun, and people are more engaged. Gamifying the password creation process enables users to interact better and make less predictable graphical password choices instead of being forced to use a strict password policy.
George E. Raptis, Christina P. Katsini, Andrew Jian-lan Cen, Nalin Arachchilage, Lennart E. Nacke
CHI4
2021 Software developers need help too! Developing a methodology to analyse cognitive dimension-based feedback on usability
abstract
Software developers use various methods to evaluate usability and identify usability issues that exist in systems they develop. Cognitive dimensions framework (CDF) based usability evaluation is one of the popular usability evaluation methods. It uses an open-ended questionnaire to collect qualitative feedback from users after using a system. To identify usability issues, evaluators should analyse this qualitative feedback. However, the approach to follow when performing this analysis is not explored in detail. We conducted a systematic literature review and reviewed 70 studies that used various CDF questionnaires for usability evaluations and investigated how those studies have analysed CDF questionnaire responses to identify usability issues. This revealed five methods that previous research has used for data analysis and four methods for identifying usability issues from CDF questionnaire responses. We applied the results of the literature review to develop a methodology and a set of guidelines to analyse qualitative feedback collected via a CDF questionnaire that targets evaluating security application programming interfaces. We tested the developed guidelines by conducting an empirical investigation. The results of the experiment revealed that using the proposed guidelines helps to identify significantly more usability issues with a higher validity.
Chamila Wijayarathna, Marthie Grobler, Nalin Arachchilage
Behav. Inf. Technol.3
2021 I'm all ears! Listening to software developers on putting GDPR principles into software development practice
Abdulrahman Alhazmi, Nalin Arachchilage
Pers. Ubiquitous Comput.2
2021 The role of self-efficacy on the adoption of information systems security innovations: a meta-analysis assessment
Mumtaz Abdul Hameed, Nalin Arachchilage
Pers. Ubiquitous Comput.2
2021 Understanding users' perceptions to improve fallback authentication
Nicholas Micallef, Nalin Arachchilage
Pers. Ubiquitous Comput.2
2019 An Empirical Usability Analysis of the Google Authentication API
abstract
Millions of web users today use their Google accounts to sign into millions of relying party websites. This is enabled through the Google authentication API, which allows third party application developers to embed Google sign-in into their application. However, regardless to the strength of the Google authentication mechanism, the majority of these applications have been identified to be infected with broken authentication, which made them vulnerable to cyber attacks. A major reason for this is mistakes that developers make while embedding Google sign-in into their application. High complexity and lack of usability of the Google authentication API makes it difficult for programmers to use it correctly and lead them to make mistakes while using the API. In this study, we evaluated the usability of the Google authentication API by conducting a user study with 10 programmers, where they attempted to embed Google sign-in and sign-out into a web application via Google authentication API. We employed think-aloud approach to evaluate the experience of the programmers and they also provided their feedback by answering the cognitive dimension framework based questionnaire. Results of the experiment revealed 12 usability issues that exist in the Google authentication API. We discussed how these usability issues would affect the security of the application that are developed using the Google authentication API and how the API should be improved to provide a better experience to application developers.
Chamila Wijayarathna, Nalin Arachchilage
EASE2
2019 A data minimization model for embedding privacy into software systems
Awanthika Senarath, Nalin Arachchilage
Comput. Secur.2
2019 Why Johnny can't develop a secure application? A usability analysis of Java Secure Socket Extension API
Chamila Wijayarathna, Nalin Arachchilage
Comput. Secur.2
2019 Using cognitive dimensions to evaluate the usability of security APIs: An empirical investigation
Chamila Wijayarathna, Nalin Arachchilage
Inf. Softw. Technol.2
2019 Will They Use It or Not? Investigating Software Developers' Intention to Follow Privacy Engineering Methodologies
abstract
With the increasing concerns over privacy in software systems, there is a growing enthusiasm to develop methods to support the development of privacy aware software systems. Inadequate privacy in software system designs could result in users losing their sensitive data, such as health information and financial information, which may cause financial and reputation loss. Privacy Engineering Methodologies (PEMs) are introduced into the software development processes with the goal of guiding software developers to embed privacy into the systems they design. However, for PEMs to be successful it is imperative that software developers have a positive intention to use PEMs. Otherwise, developers may attempt to bypass the privacy methodologies or use them partially and hence develop software systems that may not protect user privacy appropriately. To investigate the factors that affect software developers’ behavioural intention to follow PEMs, in this article, we conducted a study with 149 software developers. Findings of the study show that the usefulness of the PEM to the developers’ existing work to be the strongest determinant that affects software developers’ intention to follow PEMs. Moreover, the compatibility of the PEM with their way of work and how the PEM demonstrates its results when used were also found to be significant. These findings provide important insights in understanding the behaviour of software developers and how they perceive PEMs. The findings could be used to assist organisations and researchers to deploy PEMs and design PEMs that are positively accepted by software developers.
Awanthika Senarath, Marthie Grobler, Nalin Arachchilage
ACM Trans. Priv. Secur.3
2018 Why developers cannot embed privacy into software systems?: An empirical investigation
abstract
Pervasive use of software applications continue to challenge user privacy when users interact with software systems. Even though privacy practices such as Privacy by Design (PbD), have clear instructions for software developers to embed privacy into software designs, those practices are yet to become a common practice among software developers. The difficulty of developing privacy preserving software systems highlights the importance of investigating software developers and the problems they face when they are asked to embed privacy into application designs. Software developers are the community who can put practices such as PbD into action. Therefore identifying the problems they face when embedding privacy into software applications and providing solutions to those problems are important to enable the development of privacy preserving software systems. This study investigates 36 software developers in a software design task with instructions to embed privacy in order to identify the problems they face. We derive recommendation guidelines to address the problems to enable the development of privacy preserving software systems.
Awanthika Senarath, Nalin Arachchilage
EASE2
2018 Why Johnny Can't Store Passwords Securely?: A Usability Evaluation of Bouncycastle Password Hashing
abstract
Lack of usability of security Application Programming Interfaces (APIs) is one of the main reasons for mistakes that programmers make that result in security vulnerabilities in software applications they develop. Especially, APIs that provide cryptographic functionalities such as password hashing are sometimes too complex for programmers to learn and use. To improve the usability of these APIs to make them easy to learn and use, it is important to identify the usability issues exist on those APIs that make those harder to learn and use. In this work, we evaluated the usability of SCrypt password hashing functionality of Bouncycastle API to identify usability issues in it that persuade programmers to make mistakes while developing applications that would result in security vulnerabilities. We conducted a study with 10 programmers where each of them spent around 2 hours for the study and attempted to develop a secure password storage solution using Bouncycastle API. From data we collected, we identified 63 usability issues that exist in the SCrypt implementation of Bouncycastle API. Results of our study provided useful insights about how security/cryptographic APIs should be designed, developed and improved to provide a better experience for programmers who use them. Furthermore, we expect that this work will provide a guidance on how to conduct usability evaluations for security APIs to identify usability issues exist in them.
Chamila Wijayarathna, Nalin Arachchilage
EASE2
2018 Security questions education: exploring gamified features and functionalities
abstract
Purpose Security questions are one of the techniques used to recover forgotten passwords. However, security questions have both security and memorability limitations. To limit their security vulnerabilities, stronger answers need to be used. As serious games can motivate users to change their security behaviour, the purpose of this paper is to explore the features and functionalities that users would require in a serious game that educates them to provide stronger answers to security questions. Design/methodology/approach A lab study was conducted to collect users’ feedback on the desired game features and functionalities. In Stage 1, participants selected security questions/answers. In Stage 2, participants played a game and evaluated the usability and the provided features. Findings The main findings reveal that most participants found the current features and functionalities to be desirable; socially oriented functionalities (e.g. getting help from other players) did not seem desirable because users feared that their acquaintances could gain access to their security questions. Originality/value This research recommends that designers of serious games for security education should: use intrinsic rewards to motivate users to have a better learning experience; provide easier challenges during the training period and provide harder challenges only when the game determines that the users learned to play the game; and design their games for mobile devices because even users who usually do not play games would play a security education game on a mobile device.
Nicholas Micallef, Nalin Arachchilage
Inf. Comput. Secur.2
2017 A Gamified Approach to Improve Users' Memorability of Fall-back Authentication
Nicholas Micallef, Nalin Arachchilage
SOUPS2
2015 On the Impact of Touch ID on iPhone Passcodes
Ivan Cherapau, Ildar Muslukhov, Nalin Arachchilage, Konstantin Beznosov
SOUPS3
2014 Assessing the Role of Conceptual Knowledge in an Anti-phishing Educational Game
abstract
Games can be used to support learning in several domains, including the secure use of computers. However, emphasizing different types of knowledge in a game design can lead to different outcomes. This study explores two game designs that aim to enhance students' ability to identify phishing hyperlinks. One design focuses on procedural knowledge: developing students' tacit ability to recognize phishing hyperlinks through systematic practice. The other design focuses on conceptual knowledge: helping students to explicitly reflect upon and identify the features of phishing hyperlinks. The results of a double-blind randomized trial with 66 participants suggests that using a game designed for conceptual knowledge leads to a greater increase in learners' ability to identify phishing hyperlinks. Hence, the use of strategies that develop conceptual knowledge can enhance the efficacy of anti-phishing educational games.
Michael 'Adrir' Scott, George Ghinea, Nalin Arachchilage
ICALT3