VLDB 2026 Research / reviewers in the wild / expert
Oksana Kulyk
dblp:156/8523
· DBLP profile ↗
15ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0003-4218-1658ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security Under Pressure: How Agile Teams Experience and Manage Security Requirements
Dahlia Vingtoft Andreasen, Oksana Kulyk, Elda Paja |
REFSQ | 2 |
| 2026 | The whos, whats, and whys of issues related to personal data and data protection in open-source projects on GitHubabstractAbstract Data protection regulations such as the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the US affect how software may handle the personal data of its users. Prior literature focused on how data protection regulations are discussed for software in operation, or how this topic is discussed in various channels outside of the software development process. Yet, what is missing, is a perspective on the impact of such regulations on the software development process. In our work, we address this gap, and explore how discussions during the development of software are impacted by regulations, who reports and discusses issues related to personal data and data protection, and how developers react to those issues. To that end, we used inductive coding to analyze 652 issues from Open Source GitHub projects and used the codes to quantitatively analyze the relation between the roles, resolutions, and data protection issues to understand correlations and predict resolutions of issues. Most notably we observed a significant increase in reporting when GDPR came into effect. The most common issue types were feature requests for privacy enhancement, which were mainly reported and discussed by frequent reporters and frequent committers. But especially issues regarding privacy enhancement were also frequently reported by one-time reporters. Most of the requests were solved without opposing votes. All in all, our findings indicate that data protection regulations effectively start discussions about privacy within the software development community. Anne Hennig, Lukas Schulte, Steffen Herbold, Oksana Kulyk, Peter Mayer 0001 |
Empir. Softw. Eng. | 4 |
| 2025 | No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business ModelabstractSoftware developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration.It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration.In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-tobusiness model, conducting semi-structured interviews (𝑁 = 16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (𝑁 = 6).Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof.We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed. CCS Concepts• Security and privacy → Social aspects of security and privacy. Raha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk, Elda Paja |
CHI | 4 |
| 2024 | Cookie disclaimers: Dark patterns and lack of transparencyabstractWhile cookie disclaimers on websites have been proposed to ensure that users make informed decisions regarding consenting to data collection via cookies, such informed consent is hindered by several factors. One of them is the presence of so-called dark patterns, that is, design elements that are used to lead users to accept more cookies than needed and more than they are aware of. The second factor is lack of transparency on behalf of the service providers with regards to what happens if the user does not consent to cookie usage even despite dark patterns nudging them to do so. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behaviour; (2) identifying users' attitude towards cookie disclaimers including how they decide which cookies to accept or reject; (3) assessing the behaviour of websites regarding storing non-necessary cookies despite user's consent. We show that different visual representation of the reject/accept option have a significant impact on users' decision. We also found that the labelling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users' decision). Our results on users' attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We furthermore show that even without user's explicit consent, the majority of websites we investigated still uses non-necessary cookies. We provide recommendations on how to improve the situation for different stakeholders, namely, for developers and policy makers. Benjamin Berens, Mark Bohlender, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
Comput. Secur. | 5 |
| 2023 | People want reassurance when making privacy-related decisions - Not technicalitiesabstractOnline service users sometimes need support when making privacy-related decisions. Humans make decisions either slowly, by painstakingly consulting all possible information, or quickly, by relying on cues to trigger heuristics. Human emotions elicited by the decision context affects decisions, often without the decision maker being aware of it. We wanted to determine how an information-based decision can be supported, and also to understand which cues are used by a heuristics-based approach. Our first study enhanced understanding of underlying encryption mechanisms using metaphors. Our participants objected to efforts to make them ‘technical experts’, expressing a need for reassurance instead. We fed their free-text responses into a Q-sort, to determine which cues they rely on to make heuristic-based decisions. We confirmed the desire for reassurance. Our third study elicited ‘cyber stories’: Unprompted narratives about cyber-related experiences to detect emotional undertones in this domain. Responses revealed a general negativity, which is bound to influence cybersecurity-related decisions. Oksana Kulyk, Karen Renaud, Stefan Costica |
J. Syst. Softw. | 1 |
| 2022 | Cookie Disclaimers: Impact of Design and Users' AttitudeabstractDark patterns in cookie disclaimers are factors that are used to lead users to accept more cookies than needed and more than they are aware of. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behavior; (2) identifying users’ attitude towards cookie disclaimers including how they decide which cookies to accept or reject. We show that different visual representation of the reject/accept option have a significant impact on users’ decision. We also found that the labeling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users’ decision). Our results on users’ attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We provide recommendations on how to improve the situation for the different user groups. Benjamin Berens, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
ARES | 4 |
| 2022 | #34;You have been in Close Contact with a Person Infected with COVID-19 and you may have been Infected#34;: Understanding Privacy Concerns, Trust and Adoption in Mobile COVID-19 Tracing Across Four CountriesabstractThrough the past two and a half years, COVID-19 has swept through the world and new technologies for mitigating spread, such as exposure notification applications and contact tracing, have been implemented in many countries. However, the uptake has differed from country to country and it has not been clear if culture, death rates or information dissemination have been a factor in their adoption rate. However, these apps introduce issues of trust and privacy protection, which can create challenges in terms of adoptions and daily use. In this paper we present the results from a cross-country survey study of potential barriers to adoption of in particular COVID-19 contact tracing apps. We found that people's existing privacy concerns are an have a reverse correlation with adoption behavior but that the geographical location, as well as other demographics, such as age and gender, do not have significant effect on either adoption of the app or privacy concerns. Instead, a better understanding of what data is collected through the apps lead to a higher level of adoption. We provide suggestions for how to approach the development and deployment of contact tracing apps and more broadly health tracking apps. Oksana Kulyk, Lauren Britton-Steele, Elda Paja, Melanie Duckert, Louise Barkhuus |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2019 | Comparing "Challenge-Based" and "Code-Based" Internet Voting Verification Implementations
Oksana Kulyk, Jan Henzel, Karen Renaud, Melanie Volkamer |
INTERACT (1) | 1 |
| 2018 | What Did I Really Vote For?abstractE-voting has been embraced by a number of countries, delivering benefits in terms of efficiency and accessibility. End-to-end verifiable e-voting schemes facilitate verification of the integrity of individual votes during the election process. In particular, methods for cast-as-intended verification enable voters to confirm that their cast votes have not been manipulated by the voting client. A well-known technique for effecting cast-as-intended verification is the Benaloh Challenge. The usability of this challenge is crucial because voters have to be actively engaged in the verification process. In this paper, we report on a usability evaluation of three different approaches of the Benaloh Challenge in the remote e-voting context. We performed a comparative user study with 95 participants. We conclude with a recommendation for which approaches should be provided to afford verification in real-world elections and suggest usability improvements. Karola Marky, Oksana Kulyk, Karen Renaud, Melanie Volkamer |
CHI | 2 |
| 2017 | Security Proofs for Participation Privacy, Receipt-Freeness and Ballot Privacy for the Helios Voting SchemeabstractThe Helios voting scheme is well studied including formal proofs for verifiability and ballot privacy. However, depending on its version, the scheme provides either participation privacy (hiding who participated in the election) or verifiability against malicious bulletin board (preventing election manipulation by ballot stuffing), but not both at the same time. It also does not provide receipt-freeness, thus enabling vote buying by letting the voters construct receipts proving how they voted. Recently, an extension to Helios, further referred to as KTV-Helios, has been proposed that claims to provide these additional security properties. However, the authors of KTV-Helios did not prove their claims. Our contribution is to provide formal definitions for participation privacy and receipt-freeness that we applied to KTV-Helios. In order to evaluate the fulfillment of participation privacy and receipt-freeness, we furthermore applied the existing definition of ballot privacy, which was also used for evaluating the security of Helios, in order to show that ballot privacy also holds for KTV-Helios. David Bernhard, Oksana Kulyk, Melanie Volkamer |
ARES | 2 |
| 2017 | Coercion-resistant proxy voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
Comput. Secur. | 1 |
| 2016 | Introducing Proxy Voting to HeliosabstractProxy voting is a form of voting, where the voters can either vote on an issue directly, or delegate their voting right to a proxy. This proxy might for instance be a trusted expert on the particular issue. In this work, we extend the widely studied end-to-end verifiable Helios Internet voting system towards the proxy voting approach. Therefore, we introduce a new type of credentials, so-called delegation credentials. The main purpose of these credentials is to ensure that the proxy has been authorised by an eligible voter to cast a delegated vote. If voters, after delegating, change their mind and want to vote directly, cancelling a delegation is possible throughout the entire voting phase. We show that the proposed extension preserves the security requirements of the original Helios system for the votes that are cast directly, as well as security requirements tailored toward proxy voting. Oksana Kulyk, Karola Marky, Stephan Neumann, Melanie Volkamer |
ARES | 1 |
| 2016 | Coercion-Resistant Proxy Voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
SEC | 1 |
| 2015 | Efficiency Evaluation of Cryptographic Protocols for Boardroom VotingabstractEfficiency is the bottleneck of many cryptographic protocols towards their practical application in different contexts. This holds true also in the context of electronic voting, where cryptographic protocols are used to ensure a diversity of security requirements, e.g. Secrecy and integrity of cast votes. A new and promising application area of electronic voting is boardroom voting, which in practice takes place very frequently and often on simple issues such as approving or refusing a budget. Hence, it is not a surprise that a number of cryptographic protocols for boardroom voting have been already proposed. In this work, we introduce a security model adequate for the boardroom voting context. Further, we evaluate the efficiency of four boardroom voting protocols, which to best of our knowledge are the only boardroom voting protocols that satisfy our security model. Finally, we compare the performance of these protocols in different election settings. Oksana Kulyk, Stephan Neumann, Jurlind Budurushi, Melanie Volkamer, Rolf Haenni, Reto E. Koenig, Philémon von Bergen |
ARES | 1 |
| 2014 | A Usable Android Application Implementing Distributed Cryptography for Election AuthoritiesabstractAlthough many electronic voting protocols have been proposed, their practical application faces various challenges. One of these challenges is, that these protocols require election authorities to perform complex tasks like generating keys in a distributed manner and decrypting votes in a distributed and verifiable manner. Although corresponding key generation and decryption protocols exist, they are not used in real-world elections for several reasons: The few existing implementations of these protocols and their corresponding interfaces are not designed for people with non technical background and thus not suitable for use by most election authorities. In addition, it is difficult to explain the security model of the protocols, but legal provisions generally require transparency. We implemented a smartphone application for election authorities featuring distributed key generation and verifiable distributed decryption of votes. In addition, we prepared education material throughout based on formulated metaphors for election authorities in order to explain the security of the application. We evaluated the usability of the application and understanding of the underlying security model, concluding that the application is usable for non-experts in computer science. While the participants were able to carry out the tasks, it became clear, that they did not have a clear understanding of the underlying security model, despite having viewed our educational material. We suggest improvements to this material as future work. Stephan Neumann, Oksana Kulyk, Melanie Volkamer |
ARES | 2 |