Elissa M. Redmiles

dblp:141/9244 · DBLP profile ↗
← Back
63ranked-venue papers
17as first author
38since 2021 · last 2026
0000-0003-3930-8128ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 33 · 8 first-author · 21 since 2021Human-computer interaction and ubiquitous computing · 23 · 7 first-author · 15 since 2021Databases, data management, data science and information retrieval · 8 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 "Having Confidence in My Confidence Intervals": How Data Users Engage with Privacy-Protected Wikipedia Data
abstract
In response to calls for open data and growing privacy threats, organizations are increasingly adopting privacy-preserving techniques that add noise to published datasets. These techniques seek to protect privacy of data subjects while enabling useful analyses. With expert feedback, we developed empirically-driven documentation explaining the noise characteristics of two Wikipedia pageview datasets: one using rounding (heuristic privacy) and another using differential privacy (DP, formal privacy). We then used these documents to conduct a task-based contextual inquiry (n=15) exploring how data users—largely unfamiliar with these methods—perceive, interact with, and interpret privacy-preserving noise during data analysis.
Harold Triedman, Jayshree Sarathy, Priyanka Nanayakkara, Rachel Cummings, Gabriel Kaptchuk, Sean Kross, Elissa M. Redmiles
CHI7
2026 The Role of Privacy Guarantees in Voluntary Donation of Private Health Data for Altruistic Goals
Ruizhe Wang 0003, Roberta De Viti, Aarushi Dubey, Elissa M. Redmiles
NDSS4
2026 Goals, Risks, and Safety Practices in Online Labor Abuse Disclosures
Veronica A. Rivera, Tracy Li, Alex Ozdemir, Catherine Han, Zakir Durumeric, Elissa M. Redmiles
SOUPS6
2026 Evaluating Concept Filtering Defenses against Child Sexual Abuse Material Generation by Text-to-Image Models
abstract
We evaluate the effectiveness of filtering child images from training datasets of text-to-image models to prevent model misuse to create child sexual abuse material (CSAM). First, we capture the complexity of preventing CSAM generation using a game-based security definition. Second, we show that current detection methods cannot remove all children from a dataset. Third, using an ethical proxy for CSAM (a child wearing glasses), we show that even when only a small percentage of child images are left in the training dataset after filtering, there exist prompting strategies that generate a child wearing glasses using only a few more queries than when the model is trained on the unfiltered data. Fine-tuning the filtered model on child images further reduces the additional query overhead. We also show that re-introducing a concept is possible via fine-tuning even if filtering is perfect. Our results show that current child filtering methods offer limited protection to closed-weight models and no protection to open-weight models, while reducing the generality of the model by hindering the generation of child-related concepts or changing their representation. We conclude by outlining challenges in conducting evaluations that establish robust evidence on the impact of concept filtering defenses for CSAM.
Ana-Maria Cretu 0002, Klim Kireev, Amro Abdalla, Wisdom Obinna, Raphael Meier, Sarah Adel Bargal, Elissa M. Redmiles, Carmela Troncoso
SP7
2026 "I Wonder if These Warnings are Accurate": Security and Privacy Advice in Nine Majority World Countries
abstract
Security and privacy (S&P) advice plays a crucial role in how people stay safe online. While prior work shows that the plethora of advice from varied sources makes it difficult for users to prioritize advice, the insights are primarily based on studies conducted in Western contexts. Other work shows that users outside the West have different S&P needs and thus, we cannot simply rely on advice curated in the West to generalize to the majority world - regions of Africa, Asia, Latin America, and the Middle East, where most of the world's population lives. We fill this gap by investigating S&P advice across nine majority world countries via 70 semi-structured interviews with local experts: cybercafe operators, tech repair specialists, and other community figures that people commonly rely on for tech support and S&P advice. We find that the advice provided by local experts in the majority world largely matches the advice they provide to their constituents and the advice from the West. However, we surface various significant barriers that hinder majority world users from implementing advice, including economic constraints, language barriers, and social friction from taking protective measures. Our findings further show how factors such as social norms and gender shape advice practices, e.g., by driving gendered advice-seeking. We discuss how S&P advice in the majority world can be improved and reflect on how the S&P community can better engage with local communities in conducting similar research.
Collins W. Munyendo, Veronica A. Rivera, Jackie Hu, Emmanuel Tweneboah, Amna Shahnawaz, Karen Sowon, Dilara Keküllüoglu, Marcos Silva, Mercy Omeiza, Gayatri Priyadarsini Kancherla, Marianne Batista Diniz Da Silva, Abhishek Bichhawat, Maryam Mustafa, Francisco J. Marmolejo Cossío, Elissa M. Redmiles, Yixin Zou
SP16
2025 Public Opinions About Copyright for AI-Generated Art: The Role of Egocentricity, Competition, and Experience
Gabriel Lima, Nina Grgic-Hlaca, Elissa M. Redmiles
CHI3
2025 Stop the Nonconsensual Use of Nude Images in Research
abstract
In order to train, test, and evaluate nudity detection models, machine learning researchers typically rely on nude images scraped from the Internet. Our research finds that this content is collected and, in some cases, subsequently \emph{distributed} by researchers without consent, leading to potential misuse and exacerbating harm against the subjects depicted. \textbf{This position paper argues that the distribution of nonconsensually collected nude images by researchers perpetuates image-based sexual abuse and that the machine learning community should stop the nonconsensual use of nude images in research.} To characterize the scope and nature of this problem, we conducted a systematic review of papers published in computing venues that collect and use nude images. Our results paint a grim reality: norms around the usage of nude images are sparse, leading to a litany of problematic practices like distributing and publishing nude images with uncensored faces, and intentionally collecting and sharing abusive content. We conclude with a call-to-action for publishing venues and a vision for research in nudity detection that balances user agency with concrete research objectives.
Princessa Cintaqia, Arshia Arya, Elissa M. Redmiles, Deepak Kumar 0006, Allison McDonald, Lucy Qin
NeurIPS3
2025 Analyzing the AI Nudification Application Ecosystem
Cassidy Gibson, Daniel Olszewski, Natalie Grace Brigham, Anna Crowder, Kevin R. B. Butler, Patrick Traynor, Elissa M. Redmiles, Tadayoshi Kohno
USENIX Security Symposium7
2025 Models Matter: Setting Accurate Privacy Expectations for Local and Central Differential Privacy
abstract
Differential privacy is a popular privacy-enhancing technology that has been deployed both by industry and government agencies. Unfortunately, existing explanations of differential privacy fail to set accurate privacy expectations for data subjects, which depend on the choice of deployment model. We design and evaluate new explanations of differential privacy for the local and central models, drawing inspiration from prior work explaining other privacy-enhancing technologies such as encryption. We reflect on the challenges in evaluating explanations and on the tradeoffs between qualitative and quantitative evaluation strategies. These reflections offer guidance for other researchers seeking to design and evaluate explanations of privacy-enhancing technologies.
Mary Anne Smart, Priyanka Nanayakkara, Rachel Cummings, Gabriel Kaptchuk, Elissa M. Redmiles
Proc. Priv. Enhancing Technol.5
2024 "I Had Sort of a Sense that I Was Always Being Watched...Since I Was": Examining Interpersonal Discomfort From Continuous Location-Sharing Applications
abstract
Continuous location sharing (CLS) applications are widely used for safety and social convenience. However, these applications have privacy concerns that can be used for control and harm. To understand user concerns, we performed the largest user study of CLS application usage performed to date, with 1500 of 3000 users indicating they use CLS applications and 896 of these users completing surveys. From survey responses, we conducted 23 interviews with participants who had uncomfortable experiences. With these interviews, we perform thematic analysis grounded by sociological frameworks of power dynamics and social exchange theory. We observe that CLS application users face discomfort related to three primary categories that build on each other: (1) overstepped boundaries, (2) continued discomfort, and (3) lifestyle-impacting behaviors. With this foundational understanding, we suggest features that aim to reduce relationship imbalances that CLS applications enable. Our resulting study demonstrates that CLS applications contribute to interpersonal discomfort, highlighting the need for design changes.
Kevin Childs, Cassidy Gibson, Anna Crowder, Kevin Warren, Carson Stillman, Elissa M. Redmiles, Eakta Jain, Patrick Traynor, Kevin R. B. Butler
CCS6
2024 It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based Bias
abstract
Online platforms employ manual human moderation to distinguish human-created social media profiles from deepfake-generated ones. Biased misclassification of real profiles as artificial can harm general users as well as specific identity groups; however, no work has yet systematically investigated such mistakes and biases. We conducted a user study (n=695) that investigates how 1) the identity of the profile, 2) whether the moderator shares that identity, and 3) components of a profile shown affect the perceived artificiality of the profile. We find statistically significant biases in people’s moderation of LinkedIn profiles based on all three factors. Further, upon examining how moderators make decisions, we find they rely on mental models of AI and attackers, as well as typicality expectations (how they think the world works). The latter includes reliance on race/gender stereotypes. Based on our findings, we synthesize recommendations for the design of moderation interfaces, moderation teams, and security training.
Jaron Mink, Miranda Wei, Collins W. Munyendo, Kurt Hugenberg, Tadayoshi Kohno, Elissa M. Redmiles, Gang Wang 0011
CHI6
2024 Analyzing User Engagement with TikTok's Short Format Video Recommendations using Data Donations
abstract
Short-format videos have exploded on platforms like TikTok, Instagram, and YouTube. Despite this, the research community lacks large-scale empirical studies into how people engage with short-format videos and the role of recommendation systems that offer endless streams of such content. In this work, we analyze user engagement on TikTok using data we collect via a data donation system that allows TikTok users to donate their data. We recruited 347 TikTok users and collected 9.2M TikTok video recommendations they received. By analyzing user engagement, we find that the average daily usage time increases over the users’ lifetime while the user attention remains stable at around 45%. We also find that users like more videos uploaded by people they follow than those recommended by people they do not follow. Our study offers valuable insights into how users engage with short-format videos on TikTok and lessons learned from designing a data donation system.
Savvas Zannettou, Olivia Nemes Nemeth, Oshrat Ayalon, Angelica Goetzen, Krishna P. Gummadi, Elissa M. Redmiles, Franziska Roesner
CHI6
2024 "I chose to fight, be brave, and to deal with it": Threat Experiences and Security Practices of Pakistani Content Creators
Lea Gröber, Waleed Arshad, Shanza, Angelica Goetzen, Elissa M. Redmiles, Maryam Mustafa, Katharina Krombholz
USENIX Security Symposium5
2024 "Did They F***ing Consent to That?": Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual Abuse
Lucy Qin, Vaughn Hamilton, Sharon Wang, Yigit Aydinalp, Marin Scarlett, Elissa M. Redmiles
USENIX Security Symposium6
2024 "I feel physically safe but not politically safe": Understanding the Digital Threats and Safety Practices of OnlyFans Creators
Ananta Soneji, Vaughn Hamilton, Adam Doupé, Allison McDonald, Elissa M. Redmiles
USENIX Security Symposium5
2024 SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security Behaviors
Miranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno, Elissa M. Redmiles, Franziska Roesner
USENIX Security Symposium5
2024 Safer Algorithmically-Mediated Offline Introductions: Harms and Protective Behaviors
abstract
People are increasingly introduced to each other offline thanks to online platforms that make algorithmically-mediated introductions between their users. Such platforms include dating apps (e.g., Tinder) and in-person gig work websites (e.g., TaskRabbit, Care.com). Protecting the users of these online-offline systems requires answering calls from prior work to consider 'post-digital' orientations of safety: shifting from traditional technological security thinking to consider algorithm-driven consequences that emerge throughout online and offline contexts rather than solely acknowledging online threats. To support post-digital safety in platforms that make algorithmically-mediated offline introductions (AMOIs), we apply a mixed-methods approach to identify the core harms that AMOI users experience, the protective safety behaviors they employ, and the prevalence of those behaviors. First, we systematically review existing work (n=93), synthesizing the harms that threaten AMOIs and the protective behaviors people employ to combat these harms. Second, we validate prior work and fill gaps left by primarily qualitative inquiry through a survey of respondents' definitions of safety in AMOI and the prevalence and implementation of their protective behaviors. We focus on two exemplar populations who engage in AMOIs: online daters (n=476) and in-person gig workers (n=451). We draw on our systematization and prevalence data to identify several directions for designers and researchers to reimagine defensive tools to support safety in AMOIs.
Veronica A. Rivera, Daricia Wilkinson, Aurelia Augusta, Sophie Li, Elissa M. Redmiles, Angelika Strohmayer
Proc. ACM Hum. Comput. Interact.5
2023 "Nudes? Shouldn't I charge for these?": Motivations of New Sexual Content Creators on OnlyFans
abstract
With over 1.5 million content creators, OnlyFans is one of the fastest growing subscription-based social media platforms. The platform is primarily associated with sexual content. Thus, OnlyFans creators are uniquely positioned at the intersection of professional social media content creation and sex work. While the motivations of experienced sex workers to adopt OnlyFans have been studied, in this work we seek to understand the motivations of creators who had not previously done sex work. Through a qualitative interview study of 22 U.S.-based OnlyFans creators, we find that beyond the typical motivations for pursuing gig work (e.g., flexibility, autonomy), our participants were motivated by three key factors: (1) societal visibility and mainstream acceptance of OnlyFans; (2) platform design and affordances such as boundary-setting with clients, privacy from the public, and content archives; and (3) the pandemic, as OnlyFans provided an enormous opportunity to overcome lockdown-related issues.
Vaughn Hamilton, Ananta Soneji, Allison McDonald, Elissa M. Redmiles
CHI4
2023 Problematic Advertising and its Disparate Exposure on Facebook
Muhammad Ali 0014, Angelica Goetzen, Alan Mislove, Elissa M. Redmiles, Piotr Sapiezynski
USENIX Security Symposium4
2023 Exploring Privacy and Incentives Considerations in Adoption of COVID-19 Contact Tracing Apps
Oshrat Ayalon, Dana Turjeman, Elissa M. Redmiles
USENIX Security Symposium3
2023 What Are the Chances? Explaining the Epsilon Parameter in Differential Privacy
Priyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk, Elissa M. Redmiles
USENIX Security Symposium5
2022 A Large-Scale Measurement of Cybercrime Against Individuals
abstract
We know surprisingly little about the prevalence and severity of cybercrime in the U.S. Yet, in order to prioritize the development and distribution of advice and technology to protect end users, we require empirical evidence regarding cybercrime. Measuring crime, including cybercrime, is a challenging problem that relies on a combination of direct crime reports to the government – which have known issues of under-reporting – and assessment via carefully-designed self-report surveys. We report on the first large-scale, nationally representative academic survey (n=11,953) of consumer cybercrime experiences in the U.S. Our analysis answers four research questions: (1) What is the prevalence and (2) the monetary impact of these cybercrimes we measure in the U.S.?, (3) Do inequities exist in victimization?, and (4) Can we improve cybercrime measurement by leveraging social-reporting techniques used to measure physical crime? Our analysis also offers insight toward improving future measurement of cybercrime and protecting users.
Casey F. Breen, Cormac Herley, Elissa M. Redmiles
CHI3
2022 Field Evidence of the Effects of Privacy, Data Transparency, and Pro-social Appeals on COVID-19 App Attractiveness
abstract
COVID-19 exposure-notification apps have struggled to gain adoption. Existing literature posits as potential causes of this low adoption: privacy concerns, insufficient data transparency, and the type of appeal – collective- vs. individual-good – used to frame the app. As policy guidance suggests using tailored advertising to evaluate the effects of these factors, we present the first field study of COVID-19 contact tracing apps with a randomized, control trial of 14 different advertisements for CovidDefense, Louisiana’s COVID-19 exposure-notification app. We find that all three hypothesized factors – privacy, data transparency, and appeals framing – relate to app adoption, even when controlling for age, gender, and community density. Our results offer (1) the first field evidence supporting the use of collective-good appeals, (2) nuanced findings regarding the efficacy of data and privacy transparency, the effects of which are moderated by appeal framing and potential users’ demographics, and (3) field-evidence-based guidance for future efforts to encourage pro-social health technology adoption.
Samuel Dooley, Dana Turjeman, John Dickerson 0001, Elissa M. Redmiles
CHI4
2022 COVID-19 Information-Tracking Solutions: A Qualitative Investigation of the Factors Influencing People's Adoption Intention
abstract
Numerous information-tracking solutions have been implemented worldwide to fight the COVID-19 pandemic. While prior work has heavily explored the factors affecting people’s willingness to adopt contact-tracing solutions, which inform people when they have been exposed to someone positive for COVID-19, numerous countries have implemented other information-tracking solutions that use more data and more sensitive data than these commonly studied contact-tracing apps. In this work, we build on existing work focused on contact-tracing apps to explore adoption and design considerations for six representative information-tracking solutions for COVID-19, which differ in their goals and in the types of information they collect. To do so, we conducted semi-structured interviews with 44 participants to investigate the factors that influence their willingness to adopt these solutions. We find four main categories of influences on participants’ willingness to adopt such solutions: individual benefits of the solution, societal benefits of the solution, functionality concern, and digital safety (e.g., security and privacy) concerns. Further, we enumerate the factors that inform participants’ evaluations of these categories. Based on our findings, we make recommendations for the future design of information-tracking solutions and discuss how different factors may balance against benefits in future crisis situations.
Borke Obada-Obieh, Elissa M. Redmiles, Satya Lokam, Konstantin Beznosov
CHIIR3
2022 Community Under Surveillance: Impacts of Marginalization on an Online Labor Forum
Hanna Barakat, Elissa M. Redmiles
ICWSM2
2022 "Like Lesbians Walking the Perimeter": Experiences of U.S. LGBTQ+ Folks With Online Security, Safety, and Privacy Advice
Christine Geeng, Mike Harris, Elissa M. Redmiles, Franziska Roesner
USENIX Security Symposium3
2022 Ethics and Efficacy of Unsolicited Anti-Trafficking SMS Outreach
abstract
The sex industry exists on a continuum based on the degree of work autonomy present in one's labor conditions: a high degree of autonomy exists on one side of the continuum where certain independent sex workers have a great deal of agency, while much less autonomy exists on the other side, where sex is traded under conditions of human trafficking. Various organizations across North America perform outreach to sex workers to offer assistance in the form of services (e.g., healthcare, financial assistance, housing) as well as prayer and intervention. Increasingly, technology is used to look for trafficking victims and/or facilitate the provision of assistance or services, for example through scraping and parsing sex industry workers' advertisements into a database of contact information that can be used by outreach organizations. However, little is known about the efficacy of anti-trafficking outreach technology, nor the potential risks of using such technology to identify and contact the highly stigmatized and marginalized population of those working in the sex industry. In this work, we investigate the use, context, benefits, and harms of an anti-trafficking technology platform via qualitative interviews with multiple stakeholders: the technology developers (n=6), organizations that use the technology (n=17), and sex industry workers who have been contacted or wish to be contacted (n=24). Our findings illustrate misalignment between developers, users of the platform, and sex industry workers they are attempting to assist. In their current state, anti-trafficking outreach tools such as the one we investigate are ineffective and, at best, serve as a mechanism for spam and, at worst, scale and exacerbate harm against the population they aim to serve. We conclude with a discussion of best practices -- and the feasibility of their implementation -- for technology-facilitated outreach efforts to minimize risk or harm to sex industry workers while efficiently providing needed services.
Rasika Bhalerao, Nora McDonald, Hanna Barakat, Vaughn Hamilton, Damon McCoy, Elissa M. Redmiles
Proc. ACM Hum. Comput. Interact.6
2022 Risk, Resilience and Reward: Impacts of Shifting to Digital Sex Work
abstract
Workers from a variety of industries rapidly shifted to remote work at the onset of the COVID-19 pandemic. While existing work has examined the impact of this shift on office workers, little work has examined how shifting from in-person to online work affected workers in the informal labor sector. We examine the impact of shifting from in-person to online-only work on a particularly marginalized group of workers: sex workers. Through 34 qualitative interviews with sex workers from seven countries in the Global North, we examine how a shift to online-only sex work impacted: (1) working conditions, (2) risks and protective behaviors, and (3) labor rewards. We find that online work offers benefits to sex workers' financial and physical well-being. However, online-only work introduces new and greater digital and mental health risks as a result of the need to be publicly visible on more platforms and to share more explicit content. From our findings we propose design and platform governance suggestions for digital sex workers and for informal workers more broadly, particularly those who create and sell digital content.
Vaughn Hamilton, Hanna Barakat, Elissa M. Redmiles
Proc. ACM Hum. Comput. Interact.3
2022 Ctrl-Shift: How Privacy Sentiment Changed from 2019 to 2021
abstract
People’s privacy sentiments influence changes in legislation as well as technology design and use. While single-point-in-time investigations of privacy sentiment offer useful insight, study of people’s privacy sentiments over time is also necessary to better understand and anticipate evolving privacy attitudes. In this work, we build off of a 2019 Pew Research study and use repeated cross-sectional surveys (n=6,676) from 2019, 2020, and 2021 to model the sentiments of people in the U.S. toward collection and use of data for government- and health-related purposes. After the onset of COVID-19, we observe significant decreases in respondent acceptance of government data use and significant increases in acceptance of health-related data uses. While differences in privacy attitudes between sociodemographic groups largely decreased over this time period, following the 2020 U.S. national elections, we observe some of the first evidence that privacy sentiments may change based on the alignment between a user’s politics and the political party in power. Our results offer insight into how privacy attitudes may have been impacted by recent events and allow us to identify potential predictors of changes in privacy attitudes during times of geopolitical or national change.
Angelica Goetzen, Samuel Dooley, Elissa M. Redmiles
Proc. Priv. Enhancing Technol.3
2022 Analyzing Biases in Perception of Truth in News Stories and Their Implications for Fact Checking
abstract
Misinformation on social media has become a critical problem, particularly during a public health pandemic. Most social platforms today rely on users’ voluntary reports to determine which news stories to fact-check first. Despite the importance, no prior work has explored the potential biases in such a reporting process. This work proposes a novel methodology to assess how users perceive truth or misinformation in online news stories. By conducting a large-scale survey ($N =15$000), we identify the possible biases in news perceptions and explore how partisan leanings influence the news selection algorithm for fact checking. Our survey reveals several perception biases or inaccuracies in estimating the truth level of stories. The first kind, called the total perception bias (TPB), is the aggregate difference in the ground truth and perceived truth level. The next two are the false-positive bias (FPB) and false-negative bias (FNB), which measures users’ gullibility and cynicality of a given claim. We also propose ideological mean perception bias (IMPB), which quantifies a news story’s ideological disputability. Collectively, these biases indicate that user perceptions are not correlated with the ground truth of new stories; users believe some stories to be more false and vice versa. This calls for the need to fact-check news stories that exhibit the most considerable perception biases first, which the current voluntary reporting does not offer. Based on these observations, we propose a new framework that can best leverage users’ truth perceptions to remove false stories, correct misperceptions of users, or decrease ideological disagreements. We discuss how this new prioritizing scheme can aid platforms to significantly reduce the impact of fake news on user beliefs.
Mahmoudreza Babaei, Juhi Kulshrestha, Abhijnan Chakraborty, Elissa M. Redmiles, Meeyoung Cha, Krishna P. Gummadi
IEEE Trans. Comput. Soc. Syst.4
2021 "I need a better description": An Investigation Into User Expectations For Differential Privacy
abstract
Despite recent widespread deployment of differential privacy, relatively little is known about what users think of differential privacy. In this work, we seek to explore users' privacy expectations related to differential privacy. Specifically, we investigate (1) whether users care about the protections afforded by differential privacy, and (2) whether they are therefore more willing to share their data with differentially private systems. Further, we attempt to understand (3) users' privacy expectations of the differentially private systems they may encounter in practice and (4) their willingness to share data in such systems. To answer these questions, we use a series of rigorously conducted surveys (n=2424).
Rachel Cummings, Gabriel Kaptchuk, Elissa M. Redmiles
CCS3
2021 An Inside Look into the Practice of Malware Analysis
abstract
Malware analysis aims to understand how malicious software carries out actions necessary for a successful attack and identify the possible impacts of the attack. While there has been substantial research focused on malware analysis and it is an important tool for practitioners in industry, the overall malware analysis process used by practitioners has not been studied. As a result, an understanding of common malware analysis workflows and their goals is lacking. A better understanding of these workflows could help identify new research directions that are impactful in practice. In order to better understand malware analysis processes, we present the results of a user study with 21 professional malware analysts with diverse backgrounds who work at 18 different companies. The study focuses on answering three research questions: (1) What are the different objectives of malware analysts in practice?, (2) What comprises a typical professional malware analyst workflow, and (3) When analysts decide to conduct dynamic analysis, what factors do they consider when setting up a dynamic analysis system? Based on participant responses, we propose a taxonomy of malware analysts and identify five common analysis workflows. We also identify challenges that analysts face during the different stages of their workflow. From the results of the study, we propose two potential directions for future research, informed by challenges described by the participants. Finally, we recommend guidelines for developers of malware analysis tools to consider in order to improve the usability of such tools.
Miuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough, Elissa M. Redmiles, Mustaque Ahamad
CCS5
2021 "Disadvantaged in the American-dominated Internet": Sex, Work, and Technology
abstract
How do people in a precarious profession leverage technology to grow their business and improve their quality of life? Sex workers sit at the intersection of multiple marginalized identities and make up a sizeable workforce: the United Nations estimates that at least 42 million sex workers are conducting business across the globe. Yet, little research has examined how well technology fulfills sex workers’ business needs in the face of unique social, political, legal, and safety constraints.
Catherine Barwulor, Allison McDonald, Eszter Hargittai, Elissa M. Redmiles
CHI4
2021 AMP: authentication of media via provenance
abstract
Advances in graphics and machine learning have led to the general availability of easy-to-use tools for modifying and synthesizing media. The proliferation of these tools threatens to cast doubt on the veracity of all media. One approach to thwarting the flow of fake media is to detect modified or synthesized media through machine learning methods. While detection may help in the short term, we believe that it is destined to fail as the quality of fake media generation continues to improve. Soon, neither humans nor algorithms will be able to reliably distinguish fake versus real content. Thus, pipelines for assuring the source and integrity of media will be required---and increasingly relied upon. We present AMP, a system that ensures the authentication of media via certifying provenance. AMP creates one or more publisher-signed manifests for a media instance uploaded by a content provider. These manifests are stored in a database allowing fast lookup from applications such as browsers. For reference, the manifests are also registered and signed by a permissioned ledger, implemented using the Confidential Consortium Framework (CCF). CCF employs both software and hardware techniques to ensure the integrity and transparency of all registered manifests. AMP, through its use of CCF, enables a consortium of media providers to govern the service while making all its operations auditable. The authenticity of the media can be communicated to the user via visual elements in the browser, indicating that an AMP manifest has been successfully located and verified.
Paul England, Henrique S. Malvar, Eric Horvitz, Jack W. Stokes, Cédric Fournet, Rebecca Burke-Aguero, Amaury Chamayou, Sylvan Clebsch, Manuel Costa, John Deutscher, Shabnam Erfani, Matt Gaylor, Andrew Jenks, Kevin Kane, Elissa M. Redmiles, Alex Shamis, Isha Sharma, John C. Simmons, Sam Wenker, Anika Zaman
MMSys15
2021 Designing Media Provenance Indicators to Combat Fake Media
abstract
With the growth of technology that produces misinformation, there is a growing need to help users identify emerging types of fake media such as edited images and manipulated videos. In this work, we conduct a mixed-methods investigation into how we can provide provenance indicators to assist users in detecting newer forms of fake media. Specifically, we interview users regarding their experiences with different misinformation modes (text, image, video) to inform the design and content of indicators for previously unexplored media, especially fake videos. We find that media provenance – the source of the information – is a key heuristic used to evaluate all forms of fake media, and a heuristic that can be addressed by emerging technology. Thus, we subsequently design and investigate the use of provenance indicators to help users identify fake videos. We conduct a participatory design study to develop and design provenance indicators and evaluate participant-designed indicators via both expert evaluations and quantitative surveys (n=1,456) with end-users. Our results provide concrete design guidelines for the emerging issue of fake media. Our findings also raise concerns regarding users’ tendency to overgeneralize indicators used to assist users in identifying misinformation, suggesting the need for further research on warning design in the ongoing fight against misinformation.
Imani N. S. Munyaka, Jack W. Stokes, Elissa M. Redmiles
RAID3
2021 Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design Patterns
Maximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri, Elissa M. Redmiles
USENIX Security Symposium5
2021 "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices Online
Allison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub, Elissa M. Redmiles
USENIX Security Symposium5
2021 Characterizing the Online Learning Landscape: What and How People Learn Online
abstract
Hundreds of millions of people learn something new online every day. Simultaneously, the study of online education has blossomed within the human computer interaction community, with new systems, experiments, and observations creating and exploring previously undiscovered online learning environments. In this study we endeavor to characterize this entire landscape of online learning experiences using a national survey of 2260 US adults who are balanced to match the demographics of the U.S. We examine the online learning resources that they consult, and we analyze the subjects that they pursue using those resources. Furthermore, we compare both formal and informal online learning experiences on a larger scale than has ever been done before, to our knowledge, to better understand which subjects people are seeking for intensive study. We find that there is a core set of online learning experiences that are central to other experiences and these are shared among the majority of people who learn online. We conclude by showing how looking outside of these core online learning experiences can reveal opportunities for innovation in online education.
Sean Kross, Eszter Hargittai, Elissa M. Redmiles
Proc. ACM Hum. Comput. Interact.3
2020 Get Paid to Program: Evaluating an Employment-Aware After-School Program for High School Women of Color
abstract
After-school programs are one of the primary mechanisms used to introduce students to computing. Yet, such programs may leave behind students who need to work after-school jobs and earn an income. In this work we implement and evaluate a 10-week-long after-school program we call "Get Paid to Program", which uses research-based curriculum and pedagogical practices to introduce majority-minority, low-income high school women to computing. We evaluate the impact of this program on students' self-confidence around computing and their interest in STEM and computing careers. We evaluate the program with 30 high school women over two program implementations. Our evaluation shows a significant change in participants' computing self-efficacy. Additionally, we observe a refinement of career interests in computer science, programming, and engineering: participants become more certain of their interest, or lack thereof, after program completion. Interestingly, we find relatively little impact on career interest in other STEM fields, suggesting that computing-specific programs are critical for raising student awareness and interest.
Dana McFarlane, Elissa M. Redmiles
ITiCSE2
2020 A Comprehensive Quality Evaluation of Security and Privacy Advice on the Web
Elissa M. Redmiles, Noel Warford, Amritha Jayanti, Aravind Koneru, Sean Kross, Miraida Morales, Rock Stevens, Michelle L. Mazurek
USENIX Security Symposium1
2019 Comparing and Developing Tools to Measure the Readability of Domain-Specific Texts
abstract
Elissa Redmiles, Lisa Maszkiewicz, Emily Hwang, Dhruv Kuchhal, Everest Liu, Miraida Morales, Denis Peskov, Sudha Rao, Rock Stevens, Kristina Gligorić, Sean Kross, Michelle Mazurek, Hal Daumé III. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). 2019.
Elissa M. Redmiles, Lisa N. Maszkiewicz, Emily Hwang, Dhruv Kuchhal, Everest Liu, Miraida Morales, Denis Peskov, Sudha Rao, Rock Stevens, Kristina Gligoric, Sean Kross, Michelle L. Mazurek, Hal Daumé III
EMNLP/IJCNLP (1)1
2019 "I Just Want to Feel Safe": A Diary Study of Safety Perceptions on Social Media
Elissa M. Redmiles, Jessica E. Bodford, Lindsay Blackwell
ICWSM1
2019 "Should I Worry?" A Cross-Cultural Examination of Account Security Incident Response
abstract
Digital security technology is able to identify and prevent many threats to users accounts. However, some threats remain that, to provide reliable security, require human intervention: e.g., through users paying attention to warning messages or completing secondary authentication procedures. While prior work has broadly explored people's mental models of digital security threats, we know little about users' precise, in-the-moment response process to in-the-wild threats. In this work, we conduct a series of qualitative interviews (n=67) with users who had recently experienced suspicious login incidents on their real Facebook accounts in order to explore this process of account security incident response. We find a common process across participants from five countries - with differing online and offline cultures - allowing us to identify areas for future technical development to best support user security. We provide additional insights on the unique nature of incident-response information seeking, known attacker threat models, and lessons learned from a large, cross-cultural qualitative study of digital security.
Elissa M. Redmiles
IEEE Symposium on Security and Privacy1
2019 How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone Samples
abstract
Security and privacy researchers often rely on data collected from Amazon Mechanical Turk (MTurk) to evaluate security tools, to understand users' privacy preferences and to measure online behavior. Yet, little is known about how well Turkers' survey responses and performance on security- and privacy-related tasks generalizes to a broader population. This paper takes a first step toward understanding the generalizability of security and privacy user studies by comparing users' self-reports of their security and privacy knowledge, past experiences, advice sources, and behavior across samples collected using MTurk (n=480), a census-representative web-panel (n=428), and a probabilistic telephone sample (n=3,000) statistically weighted to be accurate within 2.7% of the true prevalence in the U.S. Surprisingly, the results suggest that: (1) MTurk responses regarding security and privacy experiences, advice sources, and knowledge are more representative of the U.S. population than are responses from the census-representative panel; (2) MTurk and general population reports of security and privacy experiences, knowledge, and advice sources are quite similar for respondents who are younger than 50 or who have some college education; and (3) respondents' answers to the survey questions we ask are stable over time and robust to relevant, broadly-reported news events. Further, differences in responses cannot be ameliorated with simple demographic weighting, possibly because MTurk and panel participants have more internet experience compared to their demographic peers. Together, these findings lend tempered support for the generalizability of prior crowdsourced security and privacy user studies; provide context to more accurately interpret the results of such studies; and suggest rich directions for future work to mitigate experience- rather than demographic-related sample biases.
Elissa M. Redmiles, Sean Kross, Michelle L. Mazurek
IEEE Symposium on Security and Privacy1
2019 Auditing Offline Data Brokers via Facebook's Advertising Platform
abstract
Data brokers such as Acxiom and Experian are in the business of collecting and selling data on people; the data they sell is commonly used to feed marketing as well as political campaigns. Despite the ongoing privacy debate, there is still very limited visibility into data collection by data brokers. Recently, however, online advertising services such as Facebook have begun to partner with data brokers-to add additional targeting features to their platform- providing avenues to gain insight into data broker information.
Giridhari Venkatadri, Piotr Sapiezynski, Elissa M. Redmiles, Alan Mislove, Oana Goga, Michelle L. Mazurek, Krishna P. Gummadi
WWW3
2019 New Phone, Who Dis? Modeling Millennials' Backup Behavior
abstract
Given the ever-rising frequency of malware attacks and other problems leading people to lose their files, backups are an important proactive protective behavior in which users can engage. Backing up files can prevent emotional and financial losses and improve overall user experience. Yet, we find that less than half of young adults perform mobile or computer backups regularly. To understand why, we model the factors that drive mobile and computer backup behavior, and changes in that behavior over time, using data from a panel survey of 384 diverse young adults. We develop a set of models that explain 37% and 38% of the variance in reported mobile and computer backup behaviors, respectively. These models show consistent relationships between Internet skills and backup frequency on both mobile and computer devices. We find that this relationship holds longitudinally: increases in Internet skills lead to increased frequency of computer backups. This article provides a foundation for understanding what drives young adults’ backup behavior. It concludes with recommendations for motivating people to back up, and for future work, modeling similar user behaviors.
Elissa M. Redmiles, Eszter Hargittai
ACM Trans. Web1
2018 "What was that site doing with my Facebook password?": Designing Password-Reuse Notifications
abstract
Password reuse is widespread, so a breach of one provider's password database threatens accounts on other providers. When companies find stolen credentials on the black market and notice potential password reuse, they may require a password reset and send affected users a notification. Through two user studies, we provide insight into such notifications. In Study 1, 180 respondents saw one of six representative notifications used by companies in situations potentially involving password reuse. Respondents answered questions about their reactions and understanding of the situation. Notifications differed in the concern they elicited and intended actions they inspired. Concerningly, less than a third of respondents reported intentions to change any passwords. In Study 2, 588 respondents saw one of 15 variations on a model notification synthesizing results from Study 1. While the variations' impact differed in small ways, respondents' intended actions across all notifications would leave them vulnerable to future password-reuse attacks. We discuss best practices for password-reuse notifications and how notifications alone appear insufficient in solving password reuse.
Maximilian Golla, Miranda Wei, Juliette Hainline, Lydia Filipe, Markus Dürmuth, Elissa M. Redmiles, Blase Ur
CCS6
2018 Equitable Security: Optimizing Distribution of Nudges and Resources
abstract
Security behaviors can help users avoid incidents, but can also increase costs, both to users -- in time and mental effort -- and to platforms -- in user engagement and engineering resources. As such, we should consider when it is most efficient and effective to encourage security behaviors. Recent work has shown that users attempt to make security decisions based on cost benefit tradeoffs (boundedly, rationally). Yet, sometimes security nudges (e.g., create unique passwords for every website) encourage users toward irrational behavior: creating strong, unique passwords even for those sites that contain no personal data. In this work-in-progress, we present a mechanism design (a framework) that can be used to optimize the distribution of security nudges and requirements among users with different levels of risk or different levels of investment in a given system. Further, we introduce a new paradigm: the distribution of resources (e.g., ubikeys) that can lower the cost of security behaviors to those users with the most need (the highest time cost from 2FA or lowest Internet skill). Future work will involve simulations showing the value of optimizing distribution of nudges and resources using this framework, and evaluating such an approach in a live test.
Elissa M. Redmiles, John Dickerson 0001, Krishna P. Gummadi, Michelle L. Mazurek
CCS1
2018 Asking for a Friend: Evaluating Response Biases in Security User Studies
abstract
The security field relies on user studies, often including survey questions, to query end users' general security behavior and experiences, or hypothetical responses to new messages or tools. Self-report data has many benefits -- ease of collection, control, and depth of understanding -- but also many well-known biases stemming from people's difficulty remembering prior events or predicting how they might behave, as well as their tendency to shape their answers to a perceived audience. Prior work in fields like public health has focused on measuring these biases and developing effective mitigations; however, there is limited evidence as to whether and how these biases and mitigations apply specifically in a computer-security context. In this work, we systematically compare real-world measurement data to survey results, focusing on an exemplar, well-studied security behavior: software updating. We align field measurements about specific software updates (n=517,932) with survey results in which participants respond to the update messages that were used when those versions were released (n=2,092). This allows us to examine differences in self-reported and observed update speeds, as well as examining self-reported responses to particular message features that may correlate with these results. The results indicate that for the most part, self-reported data varies consistently and systematically with measured data. However, this systematic relationship breaks down when survey respondents are required to notice and act on minor details of experimental manipulations. Our results suggest that many insights from self-report security data can, when used with care, translate to real-world environments; however, insights about specific variations in message texts or other details may be more difficult to assess with surveys.
Elissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal, Tudor Dumitras, Michelle L. Mazurek
CCS1
2018 Examining the Demand for Spam: Who Clicks?
abstract
Despite significant advances in automated spam detection, some spam content manages to evade detection and engage users. While the spam supply chain is well understood through previous research, there is little understanding of spam consumers. We focus on the demand side of the spam equation examining what drives users to click on spam via a large-scale analysis of de-identified, aggregated Facebook log data (n=600,000). We find (1) that the volume of spam and clicking norms in a users' network are significantly related to individual consumption behavior; (2) that more active users are less likely to click, suggesting that experience and internet skill (weakly correlated with activity level) may create more savvy consumers; and (3) we confirm previous findings about the gender effect in spam consumption, but find this effect largely corresponds to spam topics. Our findings provide practical insights to reduce demand for spam content, thereby affecting spam profitability.
Elissa M. Redmiles, Neha Chachra, Brian Waismeyer
CHI1
2018 Net Benefits: Digital Inequities in Social Capital, Privacy Preservation, and Digital Parenting Practices of U.S. Social Media Users
Elissa M. Redmiles
ICWSM1
2018 Dancing Pigs or Externalities?: Measuring the Rationality of Security Decisions
abstract
Accurately modeling human decision-making in security is critical to thinking about when, why, and how to recommend that users adopt certain secure behaviors. In this work, we conduct behavioral economics experiments to model the rationality of end-user security decision-making in a realistic online experimental system simulating a bank account. We ask participants to make a financially impactful security choice, in the face of transparent risks of account compromise and benefits offered by an optional security behavior (two-factor authentication). We measure the cost and utility of adopting the security behavior via measurements of time spent executing the behavior and estimates of the participant's wage. We find that more than 50% of our participants made rational (e.g., utility optimal) decisions, and we find that participants are more likely to behave rationally in the face of higher risk. Additionally, we find that users' decisions can be modeled well as a function of past behavior (anchoring effects), knowledge of costs, and to a lesser extent, users' awareness of risks and context (R2=0.61). We also find evidence of endowment effects, as seen in other areas of economic and psychological decision-science literature, in our digital-security setting. Finally, using our data, we show theoretically that a "one-size-fits-all" emphasis on security can lead to market losses, but that adoption by a subset of users with higher risks or lower costs can lead to market gains.
Elissa M. Redmiles, Michelle L. Mazurek, John Dickerson 0001
EC1
2018 Hackers vs. Testers: A Comparison of Software Vulnerability Discovery Processes
abstract
Identifying security vulnerabilities in software is a critical task that requires significant human effort. Currently, vulnerability discovery is often the responsibility of software testers before release and white-hat hackers (often within bug bounty programs) afterward. This arrangement can be ad-hoc and far from ideal; for example, if testers could identify more vulnerabilities, software would be more secure at release time. Thus far, however, the processes used by each group - and how they compare to and interact with each other - have not been well studied. This paper takes a first step toward better understanding, and eventually improving, this ecosystem: we report on a semi-structured interview study (n=25) with both testers and hackers, focusing on how each group finds vulnerabilities, how they develop their skills, and the challenges they face. The results suggest that hackers and testers follow similar processes, but get different results due largely to differing experiences and therefore different underlying knowledge of security concepts. Based on these results, we provide recommendations to support improved security training for testers, better communication between hackers and developers, and smarter bug bounty policies to motivate hacker participation.
Daniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu, Michelle L. Mazurek
IEEE Symposium on Security and Privacy3
2018 The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise Level
Rock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern, Patrick Sweeney, Michelle L. Mazurek
USENIX Security Symposium3
2018 Human Perceptions of Fairness in Algorithmic Decision Making: A Case Study of Criminal Risk Prediction
abstract
As algorithms are increasingly used to make important decisions that affect human lives, ranging from social benefit assignment to predicting risk of criminal recidivism, concerns have been raised about the fairness of algorithmic decision making. Most prior works on algorithmic fairness normatively prescribe how fair decisions ought to be made. In contrast, here, we descriptively survey users for how they perceive and reason about fairness in algorithmic decision making. A key contribution of this work is the framework we propose to understand why people perceive certain features as fair or unfair to be used in algorithms. Our framework identifies eight properties of features, such as relevance, volitionality and reliability, as latent considerations that inform people»s moral judgments about the fairness of feature use in decision-making algorithms. We validate our framework through a series of scenario-based surveys with 576 people. We find that, based on a person»s assessment of the eight latent properties of a feature in our exemplar scenario, we can accurately (> 85%) predict if the person will judge the use of the feature as fair. Our findings have important implications. At a high-level, we show that people»s unfairness concerns are multi-dimensional and argue that future studies need to address unfairness concerns beyond discrimination. At a low-level, we find considerable disagreements in people»s fairness judgments. We identify root causes of the disagreements, and note possible pathways to resolve them.
Nina Grgic-Hlaca, Elissa M. Redmiles, Krishna P. Gummadi, Adrian Weller
WWW2
2017 Where is the Digital Divide?: A Survey of Security, Privacy, and Socioeconomics
abstract
The behavior of the least-secure user can influence security and privacy outcomes for everyone else. Thus, it is important to understand the factors that influence the security and privacy of a broad variety of people. Prior work has suggested that users with differing socioeconomic status (SES) may behave differently; however, no research has examined how SES, advice sources, and resources relate to the security and privacy incidents users report. To address this question, we analyze a 3,000 respondent, census-representative telephone survey. We find that, contrary to prior assumptions, people with lower educational attainment report equal or fewer incidents as more educated people, and that users' experiences are significantly correlated with their advice sources, regardless of SES or resources.
Elissa M. Redmiles, Sean Kross, Michelle L. Mazurek
CHI1
2017 You Want Me To Do What? A Design Study of Two-Factor Authentication Messages
Elissa M. Redmiles, Everest Liu, Michelle L. Mazurek
SOUPS1
2017 Exploring User Perceptions of Discrimination in Online Targeted Advertising
Angelisa C. Plane, Elissa M. Redmiles, Michelle L. Mazurek, Michael Carl Tschantz
USENIX Security Symposium2
2016 Detecting fraud, corruption, and collusion in international development contracts: The design of a proof-of-concept automated system
abstract
International development banks provide low-interest loans to developing countries in an effort to stimulate social and economic development. These loans support key infrastructure projects including the building of roads, schools, and hospitals. However, despite the best efforts of development banks, these loan funds are often lost to fraud, corruption, and collusion. In an effort to sanction and deter this wrongdoing and to ensure proper use of funds, development banks conduct extensive, costly investigations that can take over a year to complete. This paper describes a proof-of-concept of a fully automated fraud, corruption, and collusion classification system for identifying risk in international development contracts. We developed this system in conjunction with the World Bank Group - the largest international development bank - to improve the time and cost efficiency of their investigation process. Using historical monetary award data and past investigation outcomes, our classifier assigns a “risk score” to World Bank contracts. This risk score is designed to enable World Bank investigators to identify the contracts most likely to lead to a substantiated investigation. If implemented, our automated system is predicted to successfully identify fraud, corruption, and collusion in 70% of cases.
Emily Grace, Ankit Rai, Elissa M. Redmiles, Rayid Ghani
IEEE BigData3
2016 How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and Behavior
abstract
Few users have a single, authoritative, source from whom they can request digital-security advice. Rather, digital-security skills are often learned haphazardly, as users filter through an overwhelming quantity of security advice. By understanding the factors that contribute to users' advice sources, beliefs, and security behaviors, we can help to pare down the quantity and improve the quality of advice provided to users, streamlining the process of learning key behaviors. This paper rigorously investigates how users' security beliefs, knowledge, and demographics correlate with their sources of security advice, and how all these factors influence security behaviors. Using a carefully pre-tested, U.S.-census-representative survey of 526 users, we present an overview of the prevalence of respondents' advice sources, reasons for accepting and rejecting advice from those sources, and the impact of these sources and demographic factors on security behavior. We find evidence of a "digital divide" in security: the advice sources of users with higher skill levels and socioeconomic status differ from those with fewer resources. This digital security divide may add to the vulnerability of already disadvantaged users. Additionally, we confirm and extend results from prior small-sample studies about why users accept certain digital-security advice (e.g., because they trust the source rather than the content) and reject other advice (e.g., because it is inconvenient and because it contains too much marketing material). We conclude with recommendations for combating the digital divide and improving the efficacy of digital-security advice.
Elissa M. Redmiles, Sean Kross, Michelle L. Mazurek
CCS1
2016 I Think They're Trying to Tell Me Something: Advice Sources and Selection for Digital Security
abstract
Users receive a multitude of digital-and physical-security advice every day. Indeed, if we implemented all the security advice we received, we would never leave our houses or use the Internet. Instead, users selectively choose some advice to accept and some (most) to reject, however, it is unclear whether they are effectively prioritizing what is most important or most useful. If we can understand from where and why users take security advice, we can develop more effective security interventions. As a first step, we conducted 25 semi-structured interviews of a demographically broad pool of users. These interviews resulted in several interesting findings: (1) participants evaluated digital-security advice based on the trustworthiness of the advice source, but evaluated physical-security advice based on their intuitive assessment of the advice content, (2) negative-security events portrayed in well-crafted fictional narratives with relatable characters (such as those shown in TV or movies) may be effective teaching tools for both digital-and physical-security behaviors, and (3) participants rejected advice for many reasons, including finding that the advice contains too much marketing material or threatens their privacy.
Elissa M. Redmiles, Amelia Malone, Michelle L. Mazurek
IEEE Symposium on Security and Privacy1
2015 A Classroom Tested Accessible Multimedia Resource for Engaging Underrepresented Students in Computing: The University of Maryland Curriculum In A Box
abstract
In 2012, women earned 18% of computer science degrees; African American and Hispanic students made up less than 20% of computing degree holders that year. Research shows that relatable role models and engaging curriculum are required to engage underrepresented students in computing. There is a need for engaging and relatable curriculum to be delivered to students at the middle school level, when these students first begin to lose interest in computing. Thus, based on the results of a survey of current and former middle school computing teachers and a comprehensive literature review, we developed the University of Maryland Curriculum In A Box (CIAB). The CIAB includes profiles of relatable computing role models, accessible video and text curriculum and challenge projects for HTML/CSS. To simulate a "real world" programming environment, the CIAB guides students through programming within open source social media frameworks and Github. The CIAB also includes teacher enablement resources such as assessments and a week-by-week implementation guide. The CIAB was successfully implemented with a group of 6th and 7th grade students in Prince Georges (PG) County, a majority minority county in Maryland. Our demo will provide a walk-through of the CIAB assets, accessibility features and design process, as well as implementation advice informed by our CIAB implementation in PG County.
Elissa M. Redmiles, Mary Allison Abad, Isabella Coronado, Sean Kross, Amelia Malone
SIGCSE1
2014 An exploration of mentor-protégé relationships and how to train future mentors (abstract only)
abstract
Mentors-protégé relationships have been shown to improve retention of women and under-represented students in computing (Cohoon, 2011). Mentorship relationships are also the driving factor in female students' selection and completion of a computing career (Ashcraft, Eger, & Friend, 2012). More generally, mentor-protégé relationships are a significant factor in retaining and encouraging under-represented students in many academic fields. Beginning with a brief discussion of our experience facilitating mentorship between female undergraduate and middle school computing students, this Birds of a Feather Session will provide a platform for the exploration of mentor training techniques and mentor-protégé relationships. We will discuss and share different strategies (e.g. readings, hands-on workshops) for training mentors and facilitating strong mentor-protégé relationships. We will also explore how mentorship relationships affect student performance in all school subjects and how to best create a broad mentorship experience that extends beyond computing. Using a summary of recent literature as a springboard, we will consider optimal mentor-protégé age gaps, experience levels and interaction frequencies. Finally, we will explore session participant's personal experiences as mentors/protégés and compile a list of "do's and don'ts" for those facilitating or participating in mentorship programs.
Elissa M. Redmiles, Jandelyn D. Plane
SIGCSE1