Ilja Nastjuk

dblp:160/2982 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-9543-8280ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Unveiling the hidden layer: Ambivalent cognitive effects of XAI in augmented decision-making under uncertainty
abstract
This study investigates whether explainable AI (XAI), although intended to improve calibrated reliance in augmented decision-making (ADM), may also increase negative consultations. In a between-subjects online experiment ( n = 200), participants completed a price classification task supported by AI, while we manipulated the presence of local feature-based explanations. Drawing on dual-process theory as an interpretive lens, we conceptualize explainability as a cognitively ambivalent intervention that reshapes reliance behavior. Our results show that XAI-induced transparency exerts competing effects: while it directly reduces negative consultations, it simultaneously increases competence-based trust and shifts responsibility attribution toward the AI. These mechanisms foster overreliance and significantly increase negative consultations, resulting in a competitive mediation pattern. Notably, comparable effects do not emerge for positive consultations, suggesting that transparency more readily amplifies reliance than it promotes corrective belief updating. By empirically demonstrating this paradox, our study develops IS and Decision Sciences research on automation bias in transparent ADM settings and identifies key psychological mechanisms through which explainability influences reliance. These findings inform the design of XAI systems that prioritize calibrated reliance rather than merely increasing perceived transparency.
Tizian Matschak, Ilja Nastjuk, Simon Trang 0001, Jose Benitez-Amado
Decis. Support Syst.2
2025 A field experiment on ISP training designs for enhancing employee information security compliance
abstract
Information security policy (ISP) training plays an important role in enhancing organisational resilience against cyber threats by providing employees with the necessary knowledge and skills to effectively identify, prevent, and respond to security breaches. This research aims to explore how the use of deterrence arguments and threat arguments can enhance the effectiveness of ISP training. We theorise how ISP training affects employees’ ISP compliance behaviour by arguing for a transfer of training lens to study the effectiveness of ISP training. The results of our field experiment with triangulated data suggest that the effect of argumentative-enhanced ISP training is twofold. First, employees who participated in enhanced training sessions with deterrence and threat arguments demonstrated superior training outputs after the training, which, in turn, translated into a sustained training outcome three weeks after the training. Second, we also find evidence that threat arguments can reinforce the application of training outputs in the maintenance stage of learned behaviours. With this applied research study, we contribute to the research and practice by providing empirical evidence of the effectiveness of ISP training designs.
Ilja Nastjuk, Florian Rampold, Simon Trang 0001, Jose Benitez-Amado
Eur. J. Inf. Syst.1
2024 Integrating and synthesising technostress research: a meta-analysis on technostress creators, outcomes, and IS usage contexts
abstract
The expansion of technostress research in the organisational and private IS usage contexts has generated substantial theoretical and empirical insights into the relationship between technostress creators and psychological and behavioural outcomes. However, we observe empirical inconsistencies in terms of effect sizes and conceptual inconsistencies regarding the aggregated and disaggregated treatment of technostress creators. Against this background, we argue that a fine-grained estimation and comparison of effect size strengths of technostress creators on outcomes can provide clarity on these essential matters. Using the Hunter and Schmidt method, we integrated and synthesised empirical data from 102 articles, encompassing 113 independent studies with a total of 49,955 observations. Our analysis offers four important contributions to the technostress literature. First, it confirms that technostress is meaningful in terms of its detrimental impact on both psychological and behavioural outcomes. Second, the results provide accurate effect size estimates for technostress creators on different outcomes in organisational and private usage contexts. Third, the results reveal that psychological outcomes are more immediate than behavioural outcomes. Fourth, the findings suggest that in certain contexts, a disaggregated account of technostress creators can reveal meaningful empirical information.
Ilja Nastjuk, Simon Trang 0001, Julius-Viktor Grummeck-Braamt, Marc T. P. Adam, Monideepa Tarafdar
Eur. J. Inf. Syst.1
2023 Should i really do that? Using quantile regression to examine the impact of sanctions on information security policy compliance behavior
abstract
Deterrence theory is one of the most commonly used theories to study information security policy non-compliance behavior. However, the results of studies in the information security field are ambiguous. To further address this heterogeneity, various influencing factors have been considered in the context of deterrence theory. However, a current challenge with these findings is that recent studies that quantitatively assess the effectiveness of deterrence have relied predominantly on methods that analyze the underlying data, starting from a regression-based approach. By applying quantile regression, we estimate the overall effect of deterrents, and uncover how their effect differs among employees with different inclinations toward ISP compliance behavior – a critical insight for determining security measures for specific employee groups. Based on longitudinal data gathered in the U.S., our findings show significantly different effects in the analyzed quantiles for both aspects of sanctions, namely certainty and severity.
Sebastian Hengstler, Stephan Kühnel, Kristin Masuch, Ilja Nastjuk, Simon Trang 0001
Comput. Secur.4
2021 Examining the role of stress and information security policy design in information security compliance behaviour: An experimental study of in-task behaviour
Simon Trang 0001, Ilja Nastjuk
Comput. Secur.2