Ada Lerner

dblp:136/8449 · also Adam Lerner · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-3238-2109ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 8 · 1 first-author · 7 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 "How would I know what I would want from or with them?': Supporting A-Spec Approaches to Developing Relationships Through Online Platforms
abstract
Online platforms have become a key avenue for forming new relationships, especially for queer individuals. However, some individuals, such as those in asexual and aromantic communities (A-Spec), seek forms of relationships that trouble existing frameworks assumed by online platforms, such as dating apps. To investigate A-Spec needs, we conducted an 8-week ARC study with 38 A-Spec participants who have used online platforms for developing relationships. Participants described a mismatch between the design of dating apps and their approach to building relationships, suggesting platform design that combines affordances of dating apps and other social platforms. We thus outline a “process-oriented” paradigm for relationship-building platforms inspired by community design suggestions, supporting participants’ process of first establishing a low-stakes relationship and then co-constructing its properties. We also argue for a “pluralized” approach to defining identity and relationship in the design of online systems, upsetting default assumptions surrounding any given label.
Kelly Wang, Ashlee Milton, Leah Namisa Rosenbloom, Erika Melder, Ada Lerner, Michael A. DeVito
CHI5
2026 "A Source of Hope Online": Membership Curation by Staff to Protect Guarded Cliques Limits Access to Resources for Marginalized Communities on Discord CSCW002
abstract
The Discord platform allows marginalized people access to critical communities and resources unavailable elsewhere. Discord server staff often protect these communities through membership curation , which encompasses acts intended to deny or gate server access to certain users. Using a constructivist grounded theory approach, we interviewed fourteen Discord staff members to better understand the tensions between membership curation and open access to communities and resources. We found that excessive curation promotes a pattern of insular, atomized guarded cliques , which jeopardizes access to critical Discord spaces for marginalized users who clash with cultural or group norms, sometimes translating into severe offline harms. We determined that membership curation often functions as resistance against cultural change, and it is also used to minimize the need for active moderation. Based on these findings, we offer a series of transferable design recommendations and best practices for both the Discord platform and for server staff.
Erika Melder, Emma Vonbuelow, Ada Lerner, Michael A. DeVito
Proc. ACM Hum. Comput. Interact.3
2026 Precarious But Active: A Look At Privacy Behaviors in Chinese Transformative Fandom on a Censored and Surveilled Internet
abstract
Chinese transformative fandom has had to adapt to increasing censorship and surveillance on the Chinese internet in recent years, working around censorship on domestic platforms in order to continue participating in fandom. To investigate this phenomenon from a privacy perspective, we interviewed 10 overseas members of Chinese transformative fandom about their experiences with privacy and censorship, and we supplemented this with 153 social media comments from Weibo and Xiaohongshu (RedNote) on the same topic. We found that our data perceived the current state of Chinese online fandom as, at best, frustrating, and at worst unsafe. Fans could be discouraged as the platform prevented them from sharing their fanworks while within-fandom disagreements led some fans to silence or report each other. The censored state of Chinese platforms, however, could also make it difficult for the community to learn how to move to a blocked overseas platform. They responded to risks from both the state and their peers by leveraging precarious techniques of obscurity and anonymity, seeking strategies that would still allow engagement with fandom. We identify three key takeaways for privacy scholarship: the harms of censorship were felt at a community level, which created a tension with expected privacy solutions; faced with inevitable surveillance, fans nonetheless actively modeled threats as a community to inform their behaviors; and the sociotechnical environment of fans influenced how blocking and reporting other fans seemed necessary for curation, contributing to why they might expose each other to state-level harm.
Kelly Wang, Ada Lerner, Abigail Marsh, Tianshi Li 0001
Proc. Priv. Enhancing Technol.3
2025 "As Someone Who is Disabled, I am so thankful for Sex Work": Alternative Approaches to Access Among Disabled Sex-Workers
abstract
Accessibility research can only serve the needs of marginalized populations by considering intersectional and critical frameworks that provide a complete picture of how access is created in different contexts.To identify the novel assistive practices of often ignored disabled communities, we present findings from 12 interviews with disabled sex workers (i.e., people who sell their own erotic labor) (e.g., escorting, webcamming, lap dancing).Based on their experiences, we present systems of access as a framework to analyze how disabled people develop access strategies in contexts that include stakeholders that actively intend them harm.By applying this framework, we call on researchers to: presume the presence of adversarial stakeholders in the lives of marginalized disabled communities, respect the consequence-based and harm-reduction practices of disabled people in these contexts, and seek out these marginalized communities with safe practices that prevent undue harm.
Jay Rodolitz, Vaughn Hamilton, Madiha Tabassum, Ada Lerner, Megan Hofmann
ASSETS4
2025 "A Blocklist is a Boundary": Tensions between Community Protection and Mutual Aid on Federated Social Networks
abstract
The Fediverse (the network encompassing Mastodon, Pleroma, Lemmy, etc.) provides a decentralized alternative to traditional social media platforms, making it both an important refuge for marginalized users and a platform which is well-suited for conducting mutual aid. One emergent type of moderation action for maintaining mutual aid spaces on the Fediverse is the use of community boundary blocklists, which we define as shared lists of Fediverse servers intended to be imported as a common blocklist. However, the use of community boundary blocklists has incited conflict on the Fediverse, with many users left cut off from their communities and sources of support due to actions outside of their control. Using an approach rooted in constructivist grounded theory, we interviewed nine Fediverse users, including a mix of community boundary blocklist curators, server staff, and regular users, to determine key tensions between community moderation and mutual aid practices. From our interviews, we identify the novel perspective of community stewardship as an act of mutual aid. We extend existing collective action and mutual aid frameworks to understand why this perspective conflicts with more typical mutual aid activities. We also observe how federation as a protocol encodes a negative form of consent, allowing users to interact by default and individuals to consent for their entire instance, leading to consent violations. From these insights, we develop a series of community-sourced suggestions for Fediverse platform designers, blocklist curators, and community staff to help address these conflicts and protect marginalized users.
Erika Melder, Ada Lerner, Michael A. DeVito
Proc. ACM Hum. Comput. Interact.2
2024 Counting Carrds: Investigating Personal Disclosure and Boundary Management in Transformative Fandom
abstract
The privacy practices of transformative fandom are of interest to HCI researchers both for the community’s high proportion of queer members and for the community’s sophisticated privacy norms and behaviors. We investigated fans’ use of single-serving websites on Carrd.co (“Carrds”) as personal profiles linked from Twitter accounts. We scraped Twitter to gather 5252 Carrds from fans in a variety of fandoms, which we analyzed using a combination of keyword searches and hand-coding. Fans’ Carrds frequently disclose queer identity, and articulate a complex system of community values and boundary management. Inspired by how these findings aren’t well-explained by individual theories of privacy, we articulate first steps towards a theory of collective privacy based in a communal process of values construction, trust building, and personal disclosure that we believe helps us to understand the sophisticated nature of fans’ observed behaviors.
Kelly Wang, Dan Bially Levy, Kien T. Nguyen, Ada Lerner, Abigail Marsh
CHI4
2024 "It's a Fair Game", or Is It? Examining How Users Navigate Disclosure Risks and Benefits When Using LLM-Based Conversational Agents
abstract
The widespread use of Large Language Model (LLM)-based conversational agents (CAs), especially in high-stakes domains, raises many privacy concerns. Building ethical LLM-based CAs that respect user privacy requires an in-depth understanding of the privacy risks that concern users the most. However, existing research, primarily model-centered, does not provide insight into users’ perspectives. To bridge this gap, we analyzed sensitive disclosures in real-world ChatGPT conversations and conducted semi-structured interviews with 19 LLM-based CA users. We found that users are constantly faced with trade-offs between privacy, utility, and convenience when using LLM-based CAs. However, users’ erroneous mental models and the dark patterns in system design limited their awareness and comprehension of the privacy risks. Additionally, the human-like interactions encouraged more sensitive disclosures, which complicated users’ ability to navigate the trade-offs. We discuss practical design guidelines and the needs for paradigm shifts to protect the privacy of LLM-based CA users.
Michelle Jia, Hao-Ping Lee, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, Tianshi Li 0001
CHI6
2024 SoK: Technical Implementation and Human Impact of Internet Privacy Regulations
abstract
Growing recognition of the potential for exploitation of personal data and of the shortcomings of prior privacy regimes has led to the passage of a multitude of new privacy regulations. Some of these laws—notably the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA)—have been the focus of large bodies of research by the computer science community, while others have received less attention. In this work, we analyze a set of 24 privacy laws and data protection regulations drawn from around the world—both those that have frequently been studied by computer scientists and those that have not—and develop a taxonomy of rights granted and obligations imposed by these laws. We then leverage this taxonomy to systematize 270 technical research papers published in computer science venues that investigate the impact of these laws and explore how technical solutions can complement legal protections. Finally, we analyze the results in this space through an inter-disciplinary lens and make recommendations for future work at the intersection of computer science and legal privacy.
Eleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee, Emily McReynolds, Jevan A. Hutson, Ada Lerner
SP7
2024 Investigating Moderation Challenges to Combating Hate and Harassment: The Case of Mod-Admin Power Dynamics and Feature Misuse on Reddit
Madiha Tabassum, Alana Mackey, Ashley Schuett, Ada Lerner
USENIX Security Symposium4
2024 Privacy Norms of Transformative Fandom: A Case Study of an Activity-Defined Community
abstract
Transformative media fandom is a remarkably coherent, long-lived, and diverse community united primarily by shared engagement in the varied activities of fandom. Its social norms are highly-developed and frequently debated, and have been studied by the CSCW and Media Studies communities in the past, but rarely using the tools and theories of privacy, despite fannish norms often bearing strongly on privacy. We use privacy scholarship and existing theories thereof to examine these norms and bring an additional perspective to understanding fandom communities. In this work, we analyze over 250,000 words of "meta'' essays and comments on those essays, reflecting the views and debates of hundreds of fans on these privacy norms. Drawing on Solove's theory of privacy as an aggregation of different ideas and on a variety of other academic theories of privacy, we analyze these norms as highly effective at protecting the integrity of fannish activities. We then articulate the value of studying these sorts of diverse "activity-defined'' communities, arguing that such approaches grant us greater power to understand privacy experiences in ways that are specific, contextual, and intersectional yet still generalizable where possible.
Abby Marsh, Ada Lerner
Proc. ACM Hum. Comput. Interact.2
2021 Defining Privacy: How Users Interpret Technical Terms in Privacy Policies
abstract
Abstract Recent privacy regulations such as GDPR and CCPA have emphasized the need for transparent, understandable privacy policies. This work investigates the role technical terms play in policy transparency. We identify potentially misunderstood technical terms that appear in privacy policies through a survey of current privacy policies and a pilot user study. We then run a user study on Amazon Mechanical Turk to evaluate whether users can accurately define these technical terms, to identify commonly held misconceptions, and to investigate how the use of technical terms affects users’ comfort with privacy policies. We find that technical terms are broadly misunderstood and that particular misconceptions are common. We also find that the use of technical terms affects users’ comfort with various privacy policies and their reported likeliness to accept those policies. We conclude that current use of technical terms in privacy policies poses a challenge to policy transparency and user privacy, and that companies should take steps to mitigate this effect.
Jenny Tang, Hannah Shoemaker, Ada Lerner, Eleanor Birrell
Proc. Priv. Enhancing Technol.3
2020 Privacy and Activism in the Transgender Community
abstract
Transgender people are marginalized, facing specific privacy concerns and high risk of online and offline harassment, discrimination, and violence. They also benefit tremendously from technology. We conducted semi-structured interviews with 18 transgender people from 3 U.S. cities about their computer security and privacy experiences broadly construed. Participants frequently returned to themes of activism and prosocial behavior, such as protest organization, political speech, and role-modeling transgender identities, so we focus our analysis on these themes. We identify several prominent risk models related to visibility, luck, and identity that participants used to analyze their own risk profiles, often as distinct or extreme. These risk perceptions may heavily influence transgender people's defensive behaviors and self-efficacy, jeopardizing their ability to defend themselves or gain technology's benefits. We articulate design lessons emerging from these ideas, contrasting and relating them to lessons about other marginalized groups whenever possible.
Ada Lerner, Helen Yuxun He, Anna Kawakami, Silvia Catherine Zeamer, Roberto Hoyle
CHI1
2018 Computer Security and Privacy for Refugees in the United States
abstract
In this work, we consider the computer security and privacy practices and needs of recently resettled refugees in the United States. We ask: How do refugees use and rely on technology as they settle in the US? What computer security and privacy practices do they have, and what barriers do they face that may put them at risk? And how are their computer security mental models and practices shaped by the advice they receive? We study these questions through in-depth qualitative interviews with case managers and teachers who work with refugees at a local NGO, as well as through focus groups with refugees themselves. We find that refugees must rely heavily on technology (e.g., email) as they attempt to establish their lives and find jobs; that they also rely heavily on their case managers and teachers for help with those technologies; and that these pressures can push security practices into the background or make common security "best practices" infeasible. At the same time, we identify fundamental challenges to computer security and privacy for refugees, including barriers due to limited technical expertise, language skills, and cultural knowledge-for example, we find that scams as a threat are a new concept for many of the refugees we studied, and that many common security practices (e.g., password creation techniques and security questions) rely on US cultural knowledge. From these and other findings, we distill recommendations for the computer security community to better serve the computer security and privacy needs and constraints of refugees, a potentially vulnerable population that has not been previously studied in this context.
Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, Tadayoshi Kohno
IEEE Symposium on Security and Privacy2
2017 Rewriting History: Changing the Archived Web from the Present
abstract
The Internet Archive's Wayback Machine is the largest modern web archive, preserving web content since 1996. We discover and analyze several vulnerabilities in how the Wayback Machine archives data, and then leverage these vulnerabilities to create what are to our knowledge the first attacks against a user's view of the archived web. Our vulnerabilities are enabled by the unique interaction between the Wayback Machine's archives, other websites, and a user's browser, and attackers do not need to compromise the archives in order to compromise users' views of a stored page. We demonstrate the effectiveness of our attacks through proof-of-concept implementations. Then, we conduct a measurement study to quantify the prevalence of vulnerabilities in the archive. Finally, we explore defenses which might be deployed by archives, website publishers, and the users of archives, and present the prototype of a defense for clients of the Wayback Machine, ArchiveWatcher.
Ada Lerner, Tadayoshi Kohno, Franziska Roesner
CCS1
2017 Confidante: Usable Encrypted Email: A Case Study with Lawyers and Journalists
abstract
Email encryption tools remain underused, even by people who frequently conduct sensitive business over email, such as lawyers and journalists. Usable encrypted email has remained out of reach largely because key management and verification remain difficult. However, key management has evolved in the age of social media: Keybase is a service that allows users to cryptographically link public keys to their social media accounts (e.g., Twitter), enabling key trust without out-of-band communication. We design and prototype Confidante, an encrypted email client that uses Keybase for automatic key management. We conduct a user study with 15 people (8 U. S. lawyers and 7 U. S. journalists) to evaluate Confidante's design decisions. We find that users complete an encrypted email task more quickly and with fewer errors using Confidante than with an existing email encryption tool, and that many users report finding Confidante comparable to using ordinary email. However, we also find that lawyers and journalists have diverse operational constraints and threat models, and thus that there may not be a one-size-fits-all solution to usable encrypted email. We reflect on our findings — both specifically about Confidante and more generally about the needs and constraints of lawyers and journalists—to identify lessons and remaining security and usability challenges for encrypted email.
Ada Lerner, Eric Zeng 0001, Franziska Roesner
EuroS&P1
2016 Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016
Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska Roesner
USENIX Security Symposium1
2015 Analyzing the Use of Quick Response Codes in the Wild
abstract
One- and two-dimensional barcodes, including Quick Response (QR) codes, have become a convenient way to communicate small amounts of information from physical objects to mobile devices. While there is much discussion, awareness, and proposed use of such barcodes, both in aca-demia and in industry, to our knowledge there has not been a systematic and in-depth analysis of the actual ecosystem surrounding these codes. To fill this gap, we analyze a log of all scans performed by users of a popular QR and barcode scanning app available for Android, iPhone, and Windows Phone. Our dataset includes over 87 million scans performed over a 10-month period from May 2013 to March 2014. We examine general use patterns of QR and barcodes in the wild and identify common and uncommon uses and misuses. We see the presence of both conventional (e.g., web) and emerging (e.g., Bitcoin) uses of QR codes, and develop an informed understanding of the types of QR codes being created and how users interact with QR and barcodes in the wild.
Ada Lerner, Alisha Saxena, Kirk Ouimet, Ben Turley, Anthony Vance, Tadayoshi Kohno, Franziska Roesner
MobiSys1
2013 Control-Alt-Hack: the design and evaluation of a card game for computer security awareness and education
abstract
We scoped, designed, produced, and evaluated the effectiveness of a recreational tabletop card game created to raise awareness of and alter perceptions regarding-computer security. We discuss our process, the challenges that arose, and the decisions we made to address those challenges. As of May 2013, we have shipped approximately 800 free copies to 150 educators. We analyze and report on feedback from 22 of these educators about their experiences using Control-Alt-Hack with over 450 students in classroom and non-classroom contexts. The responses from the 14 educators who reported on their use of the game in a classroom context variously indicated that: their students' awareness of computer security as a complex and interesting field was increased (11/14); they would use the game again in their classroom (10/14); and they would recommend the game to others (13/14). Of note, 2 of the 14 classroom educators reported that they would not have otherwise covered the material. Additionally, we present results from user studies with 11 individuals and find that their responses indicate that 8 of the 11 had an increased awareness of computer security or a changed perception; furthermore, all of our intended goals are touched upon in their responses.
Tamara Denning, Ada Lerner, Adam Shostack, Tadayoshi Kohno
CCS2