Sarah Turner

dblp:144/7958 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0003-1246-1528ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 The Everything Tool Problem: A Scoping Review of Empirical Research with Young People and Generative AI
abstract
The empirical evidence base on young people and generative AI is growing rapidly. This paper presents a scoping review of seventeen empirical studies published since the public release of ChatGPT in November 2022 that have explored young people’s lived engagement with generative AI. The review finds a corpus that is geographically concentrated in the US, predominantly single-context and single-session in design. This makes for limited interrogation of the cross-context nature of general-purpose AI chatbots. Lived harms from generative AI use are largely absent from the literature, despite increasing public awareness. Regulatory and policy context shapes young people’s engagement with AI but is rarely tracked as a research variable. As a response to the findings, we present CAISE (Children and AI in School and Elsewhere), a longitudinal, cross-context, co-researcher study following young people aged 13–14 in the UK.
Sarah Turner
IDC1
2026 Agency in Child-AI Interaction: A Review of How It Is Conceptualised, Studied, and Supported in HCI
abstract
Children’s lives are increasingly intertwined with AI systems, from recommender algorithms to generative models, raising concerns about potential impacts on children’s agency. Although supporting human agency, autonomy, and empowerment is a widely shared HCI goal, we lack clear definitions of these concepts in designing child-AI interaction. Through a review of 25 recent HCI studies, we find agency is rarely explicitly defined and its conceptualisation varies across something children innately possess and something to be developed. Our literature mapping shows that researchers observed agency through children’s planning and self-regulation, asserting control over AI systems, and critique and re-design of the status quo. Conditions reported by researchers that enable or constrain agency span epistemic conditions, interactional design, social context, and motivational orientation. Our review highlights gaps in research on designing for children’s agency. We advocate for conceptual clarity by drawing upon existing frameworks and highlight the importance of considering children’s agency through a relational lens.
Isobel Voysey, Vidminas Vizgirda, Sarah Turner, Leslye Denisse Dias Duran, Zaki Pauzi, Manolis Mavrikis, Carina Prunkl, Jun Zhao 0003
IDC3
2025 Doing cybersecurity at home: A human-centred approach for mitigating attacks in AI-enabled home devices
abstract
• To identify cyber-attacks on the AI, users must have some prior understanding of the AI parameters and their normativity. • Multimodal indicators embedded across the ecosystem of AI-enabled devices are an effective way in raising users’ attention to cyber-attacks. • Engaging users to actively diagnose and resolve cyber-attacks on AI-enabled devices in the home context must take into consideration the home routines, and be designed to avoid cognitive overload. • One way to minimise overload is to make use of users’ propensity to generalise their cybersecurity knowledge and skills where possible. AI-enabled devices are increasingly introduced in the home context and cyber-attacks targeting their AI component are becoming more frequent. Moving away from seeing the user as the problem to recognising the user as part of the solution, our research reports on a novel cybersecurity intervention (comprising Explainable AI features, assisted remediation) designed to support users to identify, diagnose and mitigate cyber-attacks on the AI component of their smart devices. We carried out a case study of a bespoke smart heating device inclusive of this intervention and conducted fieldwork with ten households who experienced simulated integrity cyber-attacks over a month. Our research contributes an understanding of how to design AI-enabled devices and their ecosystems to support users to perceive integrity cyber-attacks, offering new considerations for intervention design that exploits multimodal indicators and supports users to troubleshoot themselves the causes as well as actions of cyber-attacks. Contributing to the growing area of human-centred cybersecurity, we evidence the distinctive challenges users face when evaluating integrity attacks on the AI component in the home context.
Asimina Vasalou, Laura Benton, Ana Luisa Serta, Andrea Gauthier, Ceylan Besevli, Sarah Turner, Rea Gill, Rachael Payler, Etienne B. Roesch, Kevin McAreavey, Kim Bauters, Weiru Liu, Hsueh-Ju Chen, Dennis Ivory, Emmanouil A. Panaousis, George Loukas
Comput. Secur.6
2024 In principle vs in practice: User, expert and policymaker attitudes towards the right to data portability in the internet of things
abstract
The right to data portability (RtDP) was enshrined in law with the introduction of the EU's General Data Orotection Regulation (GDPR, Article 20) in 2018. RtDP gives a user the right to obtain and transfer their data to a different service, and the data controller the obligation to facilitate this transfer. Since GDPR's implementation, RtDP has been highlighted in the Digital Markets Act (DMA; 2022) and the proposed Data Act. Despite these reinforcements, there are gaps in understanding of RtDP amongst digital service users. Additionally, many organisations struggle to facilitate data transfer, particularly when it comes to the Internet of Things (IoT). This study examines the attitudes towards IoT data portability by conducting semi-structured interviews with users of consumer IoT devices (n = 28), academics/industry experts (n = 11) and policymakers (n = 8). Results indicate that whilst policymakers and consumers value this right in principle, it is rendered meaningless without a data subject's ability to exercise it in practice. A lack of guidance for data controllers and consumers has created an atmosphere of uncertainty which urgently needs to be addressed.
Sarah Turner, Leonie Maria Tanczer
Comput. Law Secur. Rev.1
2024 In pursuit of thermal comfort: An exploration of smart heating in everyday life
abstract
Smart Home Heating Technologies (SHHT) have been designed to improve demand flexibility and energy conservation. SHHT rely on rational theories of energy use postulating that people will use less energy when the energy cost is higher. The inclusion of AI within SHHT is poised to optimise energy use in the future as the introduction of lower carbon energy sources place new demands on the grid. When SHHT is introduced in the home, however, they become situated in temporal heating practices that are shaped by an interplay of materiality, meanings, and competencies. We report findings from a mixed methods field study involving eleven households utilising an AI-enabled SHHT probe ‘Squid’. Taking a temporal focus throughout, our study contributes a new lens as to why households may not fully engage with SHHT's rational design, given that energy conversation is already embedded in their ongoing socio-material practices with heating. Focusing on the AI-human relation, we articulate the necessity for human agency where heating is involved, whilst also advancing an understanding of the new forms of hidden labour that households incur before they can engage with the AI. Crucially, our research informs the ongoing HCI concern over how humans understand AI, raising the question of who is responsible to assess the appropriateness of AI when the effects of human-AI performance remain opaque. Our findings contribute a new theoretical perspective into the intricate relationship between individuals and AI in the home and raise several new design implications for SHHT.
Asimina Vasalou, Andrea Gauthier, Ana Luisa Serta, Ceylan Besevli, Sarah Turner, Rachael Payler, Rea Gill, Kevin McAreavey, George Loukas, Weiru Liu, Roser Beneito-Montagut
Int. J. Hum. Comput. Stud.5
2023 Location, Location, Security? Exploring Location-Based Smart Device Security Concerns and Mitigations within Low-Rent Homes
abstract
The increasing adoption of smart devices in the home introduce new security implications for tenants, with previous research showing the significance of where the devices are placed. This paper examines the relationship between device location and security: we ask how users’ security concerns shape where they place their smart devices and how they attempt to mitigate their concerns. The research focuses on an underrepresented group, those people living in social (low-rent) housing, motivated by the growing interest of housing providers to install smart devices within tenants’ homes. Using speculative design as a probe followed by interviews with eleven tenants, we find that security concerns are centred around ‘intimate places’, ‘social responsibility’ and ‘surveillance’ with users combining social practices and technical security features to mitigate these. Our research contributes new ethical implications for deploying and designing smart home devices addressed to social housing providers and smart device designers.
Laura Benton, Asimina Vasalou, Sarah Turner
Conference on Designing Interactive Systems3
2023 Between a rock and a hard(ening) place: Cyber insurance in the ransomware era
abstract
Cyber insurance and ransomware are two of the most studied areas within security research and practice to date, and their interplay continues to raise concerns in industry and government. This article offers substantial new insights and analysis into the complex question of whether cyber insurance can help organisations in mitigating the threat of ransomware, particularly its impacts. Having conducted an interview or workshop with 96 industry professionals spanning the cyber insurance, cyber security, ransomware negotiations, policy, and law enforcement sectors, we identify that ransomware has been a key cause of the ‘hardening’ of the cyber insurance market, which is exhibited at almost all levels of the market. Such hardening has been beneficial in raising the security standards required prior to purchase, but has also created a situation where some organisations may not be able to acquire viable cyber insurance at all. In presenting the outcomes of our thematic analysis of the interview and workshop outputs, the paper provides significant new empirical evidence to support the theory that cyber insurance can act as a form of governance for improving cyber security amongst organisations. Nonetheless, the hardening market does nothing to increase the penetration of cyber insurance. Questions were also raised as to the likelihood of unintended unethical – and potentially illegal – outcomes given the professionalisation of a remediation process that has to determine the most cost-effective solution to an organisation being held ransom. We conclude that insurance, at best, can help to mitigate the ransomware threat for those that can access it, as part of a wider basket of actions that must also come from different stakeholders.
Gareth Mott, Sarah Turner, Jason R. C. Nurse, Jamie MacColl, James Sullivan, Anna Cartwright 0001, Edward J. Cartwright
Comput. Secur.2
2022 "You Just Assume It Is In There, I Guess": Understanding UK Families' Application and Knowledge of Smart Home Cyber Security
abstract
The Internet of Things (IoT) is increasingly present in many family homes, yet it is unclear precisely how well families understand the cyber security threats and risks of using such devices, and how possible it is for them to educate themselves on these topics. Using a survey of 553 parents and interviews with 25 families in the UK, we find that families do not consider home IoT devices to be significantly different in terms of threats than more traditional home computers, and believe the major risks to be largely mitigated through consumer protection regulation. As a result, parents focus on teaching being careful with devices to prolong device life use, exposing their families to additional security risks and modeling incorrect security behaviors to their children. This is a risk for the present and also one for the future, as children are not taught about the IoT, and appropriate cyber security management of such devices, at school. We go on to suggest that steps must be taken by manufacturers and governments or appropriate trusted institutions to improve the cyber security knowledge and behaviors of both adults and children in relation to the use of home IoT devices.
Sarah Turner, Nandita Pattnaik, Jason R. C. Nurse, Shujun Li 0001
Proc. ACM Hum. Comput. Interact.1