Prashanth Rajivan

dblp:130/9485 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0001-8596-085XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Analyzing instance representation in cognitive models of phishing decision-making
Tianhao Xu, Prashanth Rajivan
User Model. User Adapt. Interact.2
2024 Privacy Concerns of Student Data Shared with Instructors in an Online Learning Management System
abstract
Learning management systems are used for facilitating communication between instructors and students, dissemination of lecture materials, and grading of assignments. They collect large amounts of student data, necessary or otherwise, with or without explicit consent from students. Furthermore, they make the data visible to instructors, which could have significant implications for students’ grades and experience in the classroom. In this study, we interviewed 31 students enrolled in a large public university about their privacy concerns towards different data sharing practices related to the learning management system used at their university – Canvas. Data from the study was analyzed by two researchers using inductive thematic analysis methods. The results show concerns about misrepresentation, the justification for information being visible, and discrimination. We present the implications of this study on instruction, design of learning management systems, and policy.
Monika Blue Kwapisz, Avanya Kohli, Prashanth Rajivan
CHI3
2024 "We Have No Security Concerns": Understanding the Privacy-Security Nexus in Telehealth for Audiologists and Speech-Language Pathologists: Understanding the Privacy-Security Nexus in Telehealth
abstract
The advent of telehealth revolutionizes healthcare by enabling remote consultations, yet poses complex security and privacy challenges. These are often acutely felt by lower-resourced, allied-healthcare practices. To address this, our study focuses on audiologists and speech-language pathologists (SLPs) in private practice settings, often characterized by limited information technology resources. Over the course of six months, we conducted semi-structured interviews with ten audiologists and ten SLPs to understand their telehealth experiences and concerns. Key findings reveal a diversity of opinions on technology trustworthiness, data security concerns, implemented security protocols, and patient behaviors. Given the nature of the medical practitioners’ primary work, participants expressed varied concerns about data breaches and platform vulnerabilities, yet trusted third-party services like Zoom due to inadequate expertise and time to evaluate security protocols. This work underscores the imperative of bridging the technology-healthcare gap to foster secure, patient/provider-centered telehealth as the prevailing practice. It also emphasizes the need to synergize security, privacy, and usability to securely deliver care through telehealth.
Faiza Tazi, Josiah Dykstra, Prashanth Rajivan, Sanchari Das 0001
CHI3
2024 Large Language Models for Collective Problem-Solving: Insights into Group Consensus Decision-Making
Yinuo Du, Prashanth Rajivan, Cleotilde Gonzalez
CogSci2
2024 SoK: Analyzing Privacy and Security of Healthcare Data from the User Perspective
abstract
Interactions in healthcare, by necessity, involve sharing sensitive information to achieve high-quality patient outcomes. Therefore, sensitive data must be carefully protected. This article explores existing privacy and security research conducted in the context of healthcare organizations. We conducted a systematic literature review of N =1,553 articles that examine the security and privacy of healthcare data and focus on 80 articles addressing human factors. Key findings show that much of the healthcare security and privacy research is focused on technology (44.11%, 712 articles), with a lack of emphasis on the human element (4.96%, 80 articles). In the subset of user studies, we find that patients and the general public express concerns about privacy and security with technologies like electronic health records (EHRs). Furthermore, our analysis shows that healthcare professionals often have low awareness of risks related to data security. Additionally, our analysis revealed that most research focuses narrowly on large hospitals, neglecting private practices and the unique challenges they face. We conclude by identifying research gaps and providing potential solutions to enable robust data security for sensitive patient data.
Faiza Tazi, Archana Nandakumar, Josiah Dykstra, Prashanth Rajivan, Sanchari Das 0001
ACM Trans. Comput. Heal.4
2023 Cognitive elements of learning and discriminability in anti-phishing training
Kuldeep Singh 0005, Palvi Aggarwal, Prashanth Rajivan, Cleotilde Gonzalez
Comput. Secur.3
2023 Determining psycholinguistic features of deception in phishing messages
abstract
Purpose Distinguishing phishing emails from legitimate emails continues to be a difficult task for most individuals. This study aims to investigate the psycholinguistic factors associated with deception in phishing email text and their effect on end-user ability to discriminate phishing emails from legitimate emails. Design/methodology/approach Email messages and end-user decisions collected from a laboratory phishing study were validated and analyzed using natural language processing methods (Linguistic Inquiry Word Count) and penalized regression models (LASSO and Elastic Net) to determine the linguistic dimensions that attackers may use in phishing emails to deceive end-users and measure the impact of such choices on end-user susceptibility to phishing. Findings We found that most participants, who played the role of a phisher in the study, chose to deceive their end-user targets by pretending to be a familiar individual and presenting time pressure or deadlines. Results show that use of words conveying certainty (e.g. always, never) and work-related features in the phishing messages predicted higher end-user vulnerability. On the contrary, use of words that convey achievement (e.g. earn, win) or reward (cash, money) in the phishing messages predicted lower end-user vulnerability because such features are usually observed in scam-like messages. Practical implications Insights from this research show that analyzing emails for psycholinguistic features associated with computer-mediated deception could be used to fine-tune and improve spam and phishing detection technologies. This research also informs the kinds of phishing attacks that must be prioritized in antiphishing training programs. Originality/value Applying natural language processing and statistical modeling methods to analyze results from a laboratory phishing experiment to understand deception from both attacker and end-user is novel. Furthermore, results from this work advance our understanding of the linguistic factors associated with deception in phishing email text and its impact on end-user susceptibility.
Tianhao Xu, Prashanth Rajivan
Inf. Comput. Secur.2
2018 Human Decisions on Targeted and Non-Targeted Adversarial Sample
Samuel Harding, Prashanth Rajivan, Bennett I. Bertenthal, Cleotilde Gonzalez
CogSci2
2018 Sociometrics and observational assessment of teaming and leadership in a cyber security defense competition
Norbou Buchler, Prashanth Rajivan, Laura Marusich, Lewis Lightner, Cleotilde Gonzalez
Comput. Secur.2
2017 Factors in an end user security expertise instrument
abstract
Purpose The purpose of this study is to identify factors that determine computer and security expertise in end users. They can be significant determinants of human behaviour and interactions in the security and privacy context. Standardized, externally valid instruments for measuring end-user security expertise are non-existent. Design/methodology/approach A questionnaire encompassing skills and knowledge-based questions was developed to identify critical factors that constitute expertise in end users. Exploratory factor analysis was applied on the results from 898 participants from a wide range of populations. Cluster analysis was applied to characterize the relationship between computer and security expertise. Ordered logistic regression models were applied to measure efficacy of the proposed security and computing factors in predicting user comprehension of security concepts: phishing and certificates. Findings There are levels to peoples’ computer and security expertise that could be reasonably measured and operationalized. Four factors that constitute computer security-related skills and knowledge are, namely, basic computer skills, advanced computer skills, security knowledge and advanced security skills, and these are identified as determinants of computer expertise. Practical implications Findings from this work can be used to guide the design of security interfaces such that it caters to people with different expertise levels and does not force users to exercise more cognitive processes than required. Originality/value This work identified four factors that constitute security expertise in end users. Findings from this work were integrated to propose a framework called Security SRK for guiding further research on security expertise. This work posits that security expertise instrument for end user should measure three cognitive dimensions: security skills, rules and knowledge.
Prashanth Rajivan, Pablo Moriano, Timothy Kelley, L. Jean Camp
Inf. Comput. Secur.1