VLDB 2026 Research / reviewers in the wild / expert
Karola Marky
dblp:179/7489
· DBLP profile ↗
48ranked-venue papers
13as first author
39since 2021 · last 2026
0000-0001-7129-9642ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 33 · 9 first-author · 28 since 2021Security and privacy · 15 · 4 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | It Shouldn't Be This Difficult: Researcher Perspectives on Diversity and Inclusion in Usable Privacy and Security ResearchabstractWhile recent usable privacy and security (UPS) research has made progress in moving beyond “the average user,” a systematic account of how UPS researchers navigate diversity and inclusion in their work remains lacking. Through 20 in-depth semi-structured interviews with experienced researchers, we examine how and why they recruit diverse, underserved populations in their work, as well as the challenges they face in doing so, including conceptual difficulties in defining who is underserved, limited access to target populations, and inflexible peer review and publishing norms. Participants also reflected on their own positionality when planning and conducting studies, often expressing uncertainty about how to account for and articulate their positionality. We identify strategies researchers use to overcome challenges and highlight areas where collective action from the research community and institutions is needed to foster greater inclusion in UPS research practices. Priyasha Chatterjee, Smirity Kaushik, Karola Marky, Yixin Zou |
CHI | 3 |
| 2026 | Sensing Your Vocals: Exploring the Activity of Vocal Cord Muscles for Pitch Assessment Using Electromyography and UltrasonographyabstractVocal training is difficult because the muscles that control pitch, resonance, and phonation are internal and invisible to learners. This paper investigates how Electromyography (EMG) and ultrasonic imaging (UI) can make these muscles observable for training purposes. We report three studies. First, we analyze the EMG and UI data from 16 singers (beginners, experienced & professionals), revealing differences among three vocal groups of the muscle control proficiency. Second, we use the collected data to create a system that visualizes an expert’s muscle activity as reference. This system is tested in a user study with 12 novices, showing that EMG highlighted muscle activation nuances, while UI provided insights into vocal cord length and dynamics. Third, to compare our approach to traditional methods (audio analysis and coach instructions), we conducted a focus group study with 15 experienced singers. Our results suggest that EMG is promising for improving vocal skill development and enhancing feedback systems. We conclude the paper with a detailed comparison of the analyzed modalities (EMG, UI and traditional methods), resulting in recommendations to improve vocal muscle training systems. Kanyu Chen, Rebecca Panskus, Erwin Wu, Yichen Peng, Daichi Saito, Emiko Kamiyama, Ruiteng Li, Chen-Chieh Liao, Karola Marky, Kato Akira, Hideki Koike, Kai Kunze |
CHI | 9 |
| 2025 | A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations
Jan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha Fahl |
CHI | 3 |
| 2025 | Security Knight in Shining Armor: What and Who VPN Providers Claim to Shield Consumers Against
Felix Reichmann, Jens Christian Opdenbusch, Karola Marky, Marco Gutfleisch |
CHI | 3 |
| 2025 | The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfacesabstractfiltering snowball sampling search results final sample Figure 1: We searched for publications on tangible privacy and security interfaces (TaPSI) in 28 usable privacy and security (UPS)venues and used snowball sampling to broaden our sample further.Applying hybrid thematic analysis to our final sample (𝑛 = 80), we describe the used terminology and definitions, addressed UPS domains, contributions, methods, implementations, and opportunities or challenges inherent to TaPSI.Based on these findings, we present the TaPSI Research Framework, which gives recommendations for future researchers and describes a design space for TaPSI. Sarah Delgado Rodriguez, Maximiliane Windl, Florian Alt, Karola Marky |
CHI | 4 |
| 2025 | "What you think is private is no longer" - Investigating the Aftermath of Shoulder Surfing on Smartphones in Everyday Life through the Eyes of the VictimsabstractThis paper investigates how experiencing shoulder surfing impacts smartphone users: Through an in-depth survey in the UK (N=91), we specifically investigate how shoulder surfing affects (a) the privacy perceptions of victim users and (b) their interactions with smartphones. We found that the impact of being shoulder-surfed is highly individual. First, shoulder surfing is perceived as unavoidable and frequently occurring, leading to an increased time to complete tasks. Second, users are concerned about their own and other people’s privacy and even consider shoulder surfing a gateway to more serious threats (e.g., identity or device theft). Users are willing to alter their behaviour and use software-based protective measures to prevent shoulder surfing. Finally, we captured a set of user-defined criteria essential to software-based protective measures. Based on our results, we discuss future work directions for user-centred shoulder surfing mitigation. Habiba Farzand, Shaun Alexander Macdonald, Karola Marky, Mohamed Khamis |
MUM | 3 |
| 2025 | Investigating User Perceptions of Visualising Inferred Sensitive Information as Privacy AvatarsabstractCollecting user data is ubiquitous in the modern web, because it enables different kinds of services like personalised recommendations. Specific data shared by the users can be analysed further to infer additional information – e.g., gender, age, appearance, or preferences. Such inferences are challenging to predict for users when deciding on whether or not to share data. In this paper, we explore privacy avatars as a way to visualise collected and inferred data to users by a picture. For this, we conducted semi-structured interviews (N=20) where participants were shown privacy avatars based on products they bought in a fictitious online-shopping scenario and additional privacy avatars with a varied level of detail and information. Our results show that participants were shocked by avatars that accurately depicted parts of their visual appearance and perceived inaccurate avatars as privacy-preserving. However, participants preferred information they considered sensitive (e.g., gender) to be accurate creating a tension between privacy and accuracy of shared or inferred information. We conclude with a discussion on how such privacy avatars could be generated and used in practice to offer intuitive and informative privacy interfaces. Lena Swienty, Rebecca Panskus, Stefanie Miketta, Beyza Kircili, Sen Cheng, Karola Marky |
MUM | 6 |
| 2025 | Towards Secure and Usable XR Authentication Schemes for Head-Mounted Displays: A Co-Creation Study with ExpertsabstractHead-mounted displays (HMDs) are increasingly integrated into users’ daily lives to provide immersive extended reality (XR) interactions. However, authentication on HMDs can disrupt this immersion because unsuitable 2D methods (e.g., passwords or PINs) are used, or HMDs are not secured at all. This paper presents in-depth results of seven co-creation workshops with 24 security and HCI experts to develop novel authentication concepts specifically tailored for HMDs. First, we collected 123 authentication concept ideas. Second, we extracted critical properties to propose overall design requirements for secure and usable interactions (e.g., user awareness, discreetness, and re-purposing of body parts), and security (e.g., resilience to virtual observation) in HMD authentication. We conclude the paper by discussing how schemes can be tailored to the users’ circumstances and options to ease the tension between security, usability, and privacy in HMD authentication. Reyhan Duezguen, Philip Klostermeyer, Lena Swienty, Sascha Fahl, Karola Marky |
VRST | 5 |
| 2025 | A Systematic Deconstruction of Human-Centric Privacy & Security Threats on Mobile PhonesabstractMobile phones are most likely the subject of targeted attacks, such as software exploits. The resources needed to carry out such attacks are becoming increasingly available and, hence, easily executable, putting users’ privacy at risk. We conducted a systematic literature analysis to understand the relationship between resources and attack feasibility and present a categorisation of social engineering and side-channel attacks on mobile phones focusing on the resources attackers require. Our proposed categorisation levels facilitate an in-depth understanding of how mobile phone attacks can be executed using different combinations of partly simple resources. The analysis reveals that discrete protection mechanisms are insufficient to provide all-inclusive protection. The proposed categorisation assists in building novel solutions for safeguarding users’ privacy from diverse attacks by carefully considering the potential misuse of resources. We conclude by outlining future research directions highlighting the urgent need for a holistic user defense. Habiba Farzand, Melvin Abraham, Stephen A. Brewster, Mohamed Khamis, Karola Marky |
Int. J. Hum. Comput. Interact. | 5 |
| 2025 | "It's Not My Data Anymore": Exploring Non-Users' Privacy Perceptions of Medical Data Donation AppsabstractThis paper contributes an in-depth investigation (N=24) of privacy perceptions in the context of medical data donation apps. Medical data donation refers to the act of voluntarily sharing medical data with research institutions, which plays a crucial role in advancing healthcare research and personalized medicine. To design effective medical data donation apps, we need to understand how privacy expectations affect people's willingness to use such apps. We focus on non-users—those who have no experience with medical data donation apps—because gaining a deeper understanding of their perceptions is essential for fostering the adoption of these apps. Our findings highlight the importance of trust, transparency, and anonymity as driving factors. Participants expressed a willingness to share highly sensitive medical data with the apps if they were assured of complete anonymity, yet criticism regarding the risks of de-anonymization was also raised. Based on our results, we identify privacy awareness issues, especially concerning data sensitivity. Additionally, we explain the differences between participants' privacy expectations and preferences and what existing medical data donation apps offer. Finally, we provide guidance for the development of future user-centric medical data donation apps. Sarah Abdelwahab Gaballah, Lamya Abdullah, Ephraim Zimmer, Sascha Fahl, Max Mühlhäuser, Karola Marky |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | 'AI is from the devil.' Behaviors and Concerns Toward Personal Data Sharing with LLM-based Conversational AgentsabstractWith the increased performance of large language models (LLMs), conversational agents (CA), such as ChatGPT, are nowadays available to any individual requiring little technical knowledge and skills. Initial studies that have investigated related privacy risks primarily focused on either technical aspects and misuse of these tools, or captured overall perceptions of CA users in small-scale qualitative evaluations. Complementing and extending previous work, we used a quantitative user-centered approach to analyze and compare the behaviors and concerns of users and non-users. We conducted a survey study (N=422) with (1) service users, i.e., users of CA services, (2) local users, i.e., users of a local instance of CA (partially local users, or fully local users), and (3) non-users. We collected self-reported usage patterns and personal data-sharing behavior as well as privacy concerns related to different types of personal data (e.g., health data, demographics, or opinions). Furthermore, we analyze individuals' intention to use CA services in multiple scenarios. Our findings show that users of CA services generally have fewer privacy concerns than non-users. While users rarely share data related to personal identifiers and account credentials, they tend to often share data related to lifestyle, health, standard of living, and opinions. Surprisingly, partially local users tend to share more data with CA services as they also generally use CA services more often and for more diverse purposes. Also, while the majority of CA services users declared not being willing to prioritize CA services as an information source in the described scenarios such as seeking legal advice, between about one-quarter and one-third of partially local users would use CA services for all scenarios. Furthermore, half of the users were willing to stop using CA for privacy reasons (e.g., in case of data leaks), whereas a large majority of non-users reported not using CAs simply because they do not have the need or the opportunity. Our work highlights the high privacy risks for CA services users as CA services largely expand the amount of any type of personal information that can be collected by companies. Noé Zufferey, Sarah Abdelwahab Gaballah, Karola Marky, Verena Zimmermann |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Authenticate as You Go: From Exploring Smart Home Authentication with Daily Objects to Authenticating with Primary TasksabstractSmart home applications aim to increase convenience, yet often require authentication to protect sensitive data. This is non-trivial: effortful authentication contradicts intended convenience, the multitude of devices raises scalability issues, many devices lack suitable interfaces, and the presence of other inhabitants requires intentional and acceptable interactions. To address these issues, we explored new and creative authentication interactions with an interaction relabeling approach using everyday objects. We conducted six focus group workshops with 20 participants in a living room and a kitchen setting that resulted in a variety of creative authentication interactions with analogue and digital objects. Furthermore, participants created authentication interactions based on tasks that they have to or wish to perform anyway such as cleaning the kitchen—thus primary tasks. This led us to explore the option to transform authentication from being an additional, secondary task toward using primary tasks further in an online study with 194 participants. Relevant implications in terms of acceptable authentication task characteristics, user perceptions, arising security challenges, and psychological habit research are discussed. Verena Zimmermann, Stina Schäfer, Markus Dürmuth, Karola Marky |
ACM Trans. Comput. Hum. Interact. | 4 |
| 2024 | Let the Users Choose: Low Latency or Strong Anonymity? Investigating Mix Nodes with Paired Mixing TechniquesabstractCurrent anonymous communication systems either provide strong anonymity with significant delay or low latency with unreliable anonymity. This division leads to smaller user bases and reduced anonymity as users choose systems based on their specific requirements. To address this issue, we propose an approach based on mix networks that employs two mixing techniques on mix nodes. Each technique offers distinct anonymity and latency guarantees—one for users valuing strong anonymity and another for those with specific latency constraints. We conducted an in-depth empirical study to evaluate the effectiveness of our proposal. The evaluation results demonstrate that our approach provides much more protection than the traditional method of using just one mixing technique on mix nodes. It offers enhanced anonymity for all users without impacting any user’s latency requirements. Furthermore, our findings indicate that our proposal eliminates the need for generating cover traffic to improve anonymity, achieving this improvement without introducing the bandwidth overhead associated with cover traffic. Sarah Abdelwahab Gaballah, Lamya Abdullah, Max Mühlhäuser, Karola Marky |
ARES | 4 |
| 2024 | Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' PromisesabstractSecurity awareness and training (SAT) vendors operate in a growing multi-billion dollar market. They publish various marketing promises on their websites to their customers -- organizations of all sizes. This paper investigates how these promises align with customers' needs, how they relate to human-centered security challenges highlighted in prior research, and what narrative is presented regarding the role of employees (as SAT recipients). We also investigate the level of transparency in vendor promises, as to whether it constitutes an information asymmetry. We gathered search terms from n=30 awareness professionals to perform an automated Google search and scraping of SAT vendors' websites. We then performed a thematic analysis of 2,476 statements on 156 websites from 59 vendors. We found that the messaging from SAT vendors precisely targets customers' need for easy-to-implement and compliance-fulfilling SAT products; how SAT products are offered also means that some of the impacts of SAT go unmentioned and are transferred to the customer, such as user support. In this vendor-customer relationship, employees are portrayed as a source of weaknesses, needing an indefinite amount of training to be incorporated into the organization's protection. We conclude with suggestions for SAT vendors and regulators, notably toward an SAT ecosystem that directly links SAT solutions to usable security technologies within the organization environment. Jonas Hielscher, Markus Schöps, Jens Christian Opdenbusch, Felix Reichmann, Marco Gutfleisch, Karola Marky, Simon Edward Parkin |
CCS | 6 |
| 2024 | Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)abstractThis paper proposes an Out-of-Device Privacy Scale (ODPS) - a reliable, validated psychometric privacy scale that measures users’ importance of out-of-device privacy. In contrast to existing scales, ODPS is designed to capture the importance individuals attribute to protecting personal information from out-of-device threats in the physical world, which is essential when designing privacy protection mechanisms. We iteratively developed and refined ODPS in three high-level steps: item development, scale development, and scale validation, with a total of N=1378 participants. Our methodology included ensuring content validity by following various approaches to generate items. We collected insights from experts and target audiences to understand response variability. Next, we explored the underlying factor structure using multiple methods and performed dimensionality, reliability, and validity tests to finalise the scale. We discuss how ODPS can support future work predicting user behaviours and designing protection methods to mitigate privacy risks. Habiba Farzand, Karola Marky, Mohamed Khamis |
CHI | 2 |
| 2024 | Decide Yourself or Delegate - User Preferences Regarding the Autonomy of Personal Privacy Assistants in Private IoT-Equipped EnvironmentsabstractPersonalized privacy assistants (PPAs) communicate privacy-related decisions of their users to Internet of Things (IoT) devices. There are different ways to implement PPAs by varying the degree of autonomy or decision model. This paper investigates user perceptions of PPA autonomy models and privacy profiles – archetypes of individual privacy needs – as a basis for PPA decisions in private environments (e.g., a friend’s home). We first explore how privacy profiles can be assigned to users and propose an assignment method. Next, we investigate user perceptions in 18 usage scenarios with varying contexts, data types and number of decisions in a study with 1126 participants. We found considerable differences between the profiles in settings with few decisions. If the number of decisions gets high (> 1/h), participants exclusively preferred fully autonomous PPAs. Finally, we discuss implications and recommendations for designing scalable PPAs that serve as privacy interfaces for future IoT devices. Karola Marky, Alina Stöver, Sarah Prange, Kira Bleck, Paul Gerber, Verena Zimmermann, Florian Müller 0003, Florian Alt, Max Mühlhäuser |
CHI | 1 |
| 2024 | Do You Need to Touch? Exploring Correlations between Personal Attributes and Preferences for Tangible Privacy MechanismsabstractThis paper explores how personal attributes, such as age, gender, technological expertise, or “need for touch”, correlate with people’s preferences for properties of tangible privacy protection mechanisms, for example, physically covering a camera. For this, we conducted an online survey (N = 444) where we captured participants’ preferences of eight established tangible privacy mechanisms well-known in daily life, their perceptions of effective privacy protection, and personal attributes. We found that the attributes that correlated most strongly with participants’ perceptions of the established tangible privacy mechanisms were their “need for touch” and previous experiences with the mechanisms. We use our findings to identify desirable characteristics of tangible mechanisms to better inform future tangible, digital, and mixed privacy protections. We also show which individuals benefit most from tangibles, ultimately motivating a more individual and effective approach to privacy protection in the future. Sarah Delgado Rodriguez, Priyasha Chatterjee, Anh Dao Phuong, Florian Alt, Karola Marky |
CHI | 5 |
| 2024 | Perspectives on DeepFakes for Privacy: Comparing Perceptions of Photo Owners and Obfuscated Individuals towards DeepFake Versus Traditional Privacy-Enhancing ObfuscationabstractObfuscating people’s faces using synthetically generated faces, i.e., DeepFakes, has been shown to be effective at privacy preservation. While recent work showed that DeepFake obfuscation is well perceived by viewers, the perspectives of a) the owner of the obfuscated photo, and b) the person that is being obfuscated, remain unclear. This paper reports on the results of a user study where participants uploaded their own group photos, in which they appear, and applied obfuscation techniques to both themselves and others in the image. The obfuscation methods included DeepFakes and four traditional techniques: blurring, pixelating, masking, and avatars. Our findings show that both photo owners and obfuscated individuals perceive DeepFake obfuscation as significantly more effective in protecting privacy compared to the traditional methods, and was found to integrate well with the environment. Mohamed Khamis, Rebecca Panskus, Habiba Farzand, Marija Mumm, Shaun Alexander Macdonald, Karola Marky |
MUM | 6 |
| 2024 | Let me quickly share it - Time Pressure when Sharing on Social Media
Rebecca Panskus, Tangila Islam Tanni, Alexander Ponticello, Echo Meißner, Yan Solihin, Katharina Krombholz, Karola Marky |
MUM | 7 |
| 2024 | Soothing Sensations: Enhancing Interactions with a Socially Assistive Robot through Vibrotactile HeartbeatsabstractPhysical interactions with socially assistive robots (SARs) positively affect user wellbeing. However, haptic experiences when touching a SAR are typically limited to perceiving the robot’s movements or shell texture, while other modalities that could enhance the touch experience with the robot, such as vibrotactile stimulation, are under-explored. In this exploratory qualitative study, we investigate the potential of enhancing human interaction with the PARO robot through vibrotactile heartbeats, with the goal to regulate subjective wellbeing during stressful situations. We conducted in-depth one-on-one interviews with 30 participants, who watched three horror movie clips alone, with PARO, and with a PARO that displayed a vibrotactile heartbeat. Our findings show that PARO’s presence and its interactive capabilities can help users regulate emotions through attentional redeployment from a stressor toward the robot. The vibrotactile heartbeat further reinforced PARO’s physical and social presence, enhancing the socio-emotional support provided by the robot and its perceived life-likeness. We discuss the impact of individual differences in user experience and implications for the future design of life-like vibrotactile stimulation for SARs. Jacqueline Borgstedt, Shaun Alexander Macdonald, Karola Marky, Frank E. Pollick, Stephen A. Brewster |
RO-MAN | 3 |
| 2024 | Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsabstractTo increase open-source software supply chain security, protecting the development environment of contributors against attacks is crucial. For example, contributors must protect authentication credentials for software repositories, code-signing keys, and their systems from malware.Previous incidents illustrated that open-source contributors struggle with protecting their development environment. In contrast to companies, open-source software projects cannot easily enforce security guidelines for development environments. Instead, contributors’ security setups are likely heterogeneous regarding chosen technologies and strategies.To the best of our knowledge, we perform the first in-depth qualitative investigation of the security of open-source software contributors’ individual security setups, their motivation, decision-making, and sentiments, and the potential impact on open-source software supply chain security. Therefore, we conduct 20 semi-structured interviews with a diverse set of experienced contributors to critical open-source software projects.Overall, we find that contributors have a generally high affinity for security. However, security practices are rarely discussed in the community or enforced by projects. Furthermore, we see a strong influence of social mechanisms, such as trust, respect, or politeness, further impeding the sharing of security knowledge and best practices.We conclude our work with a discussion of the impact of our findings on open-source software and supply chain security, and make recommendations for the open-source software community. Sabrina Klivan, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky, Sascha Fahl |
SP | 4 |
| 2024 | Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingabstractOnline elections come with security challenges since digital votes do not produce physical audit trails that are easily verifiable. We present and investigate a hybrid online voting system that combines the benefits of voting from home via the internet with those of physical ballots, such as risk-limiting audits and verifiability. After voting online, the system generates a tracking code and a physical printout – either paper or 3D-printed – of the encrypted vote that can be visually verified by the voters through live video-broadcasts. Through an online experiment (N=150), we compared hybrid voting with paper and 3D-printed votes to a baseline (digitally stored votes), investigating perceived trust, UX, usability, and security readiness. Among our results, we show that paper printouts enhance trust without negatively impacting UX. 3D-printouts enhance perceived privacy, yet impact usability and UX. We conclude with recommendations and practical considerations to inform the implementation of hybrid online voting schemes. Karola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis, Max Mühlhäuser |
SP | 1 |
| 2024 | Anonify: Decentralized Dual-level Anonymity for Medical Data DonationabstractMedical data donation involves voluntarily sharing medical data with research institutions, which is crucial for advancing healthcare research. However, the sensitive nature of medical data poses privacy and security challenges. The primary concern is the risk of de-anonymization, where users can be linked to their donated data through background knowledge or communication metadata. In this paper, we introduce Anonify, a decentralized anonymity protocol offering strong user protection during data donation without reliance on a single entity. It achieves dual-level anonymity protection, covering both communication and data aspects by leveraging Distributed Point Functions, and incorporating k-anonymity and stratified sampling within a secret-sharing-based setting. Anonify ensures that the donated data is in a form that affords flexibility for researchers in their analyses. Our evaluation demonstrates the efficiency of Anonify in preserving privacy and optimizing data utility. Furthermore, the performance of machine learning algorithms on the anonymized datasets generated by the protocol shows high accuracy and precision. Sarah Abdelwahab Gaballah, Lamya Abdullah, Mina Alishahi, Thanh Hoang Long Nguyen, Ephraim Zimmer, Max Mühlhäuser, Karola Marky |
Proc. Priv. Enhancing Technol. | 7 |
| 2023 | Privacy Mental Models of Electronic Health Records: A German Case Study
Rebecca Panskus, Max Ninow, Sascha Fahl, Karola Marky |
SOUPS | 4 |
| 2023 | Tangible 2FA - An In-the-Wild Investigation of User-Defined Tangibles for Two-Factor Authentication
Mark Turner 0014, Martin Schmitz 0001, Morgan Masichi Bierey, Mohamed Khamis, Karola Marky |
SOUPS | 5 |
| 2023 | In the Quest to Protect Users from Side-Channel Attacks - A User-Centred Design Space to Mitigate Thermal Attacks on Public Payment Terminals
Karola Marky, Shaun Alexander Macdonald, Yasmeen Abdrabou, Mohamed Khamis |
USENIX Security Symposium | 1 |
| 2023 | Hybrid password meters for more secure passwords - a comprehensive study of password meters including nudges and password informationabstractSupporting users with secure password creation is a well-explored yet unresolved research topic. A promising intervention is the password meter, i.e. providing feedback on the user's password strength as and when it is created. However, findings related to the password meter's effectiveness are varied. An extensive literature review revealed that, besides password feedback, effective password meters often include: (a) feedback nudges to encourage stronger passwords choices and (b) additional guidance. A between-subjects study was carried out with 645 participants to test nine variations of password meters with different types of feedback nudges exploiting various heuristics and norms. This study explored differences in resulting passwords: (1) actual strength, (2) memorability, and (3) user perceptions. The study revealed that password feedback, in combination with a feedback nudge and additional guidance, labelled a hybrid password meter, was generally more efficacious than either intervention on its own, on all three metrics. Yet, the type of feedback nudge targeting either the person, the password creation task, or the social context, did not seem to matter much. The meters were nearly equally efficacious. Future work should explore the long-term effects of hybrid password meters in real-life settings to confirm the external validity of these findings. Verena Zimmermann, Karola Marky, Karen Renaud |
Behav. Inf. Technol. | 2 |
| 2023 | Linking Audience Physiology to ChoreographyabstractThe use of wearable sensor technology opens up exciting avenues for both art and HCI research, providing new ways to explore the invisible link between audience and performer. To be effective, such work requires close collaboration between performers and researchers. In this article, we report on the co-design process and research insights from our work integrating physiological sensing and live performance. We explore the connection between the audience’s physiological data and their experience during the performance, analyzing a multi-modal dataset collected from 98 audience members. We identify notable moments based on HRV and EDA, and show how the audience’s physiological responses can be linked to the choreography. The longitudinal changes in HRV features suggest a strong connection to the choreographer’s intended narrative arc, while EDA features appear to correspond with short-term audience responses to dramatic moments. We discuss the physiological phenomena and implications for designing feedback systems and interdisciplinary collaborations. Jiawen Han, George Chernyshov, Moe Sugawa, Dingding Zheng, Danny Hynds, Taichi Furukawa, Marcelo Padovani Macieira, Karola Marky, Kouta Minamizawa, Jamie A. Ward, Kai Kunze |
ACM Trans. Comput. Hum. Interact. | 8 |
| 2022 | DeepFakes for Privacy: Investigating the Effectiveness of State-of-the-Art Privacy-Enhancing Face Obfuscation MethodsabstractThere are many contexts in which a person’s face needs to be obfuscated for privacy, such as in social media posts. We present a user-centered analysis of the effectiveness of DeepFakes for obfuscation using synthetically generated faces, and compare it with state-of-the-art obfuscation methods: blurring, masking, pixelating, and replacement with avatars. For this, we conducted an online survey (N=110) and found that DeepFake obfuscation is a viable alternative to state-of-the-art obfuscation methods; it is as effective as masking and avatar obfuscation in concealing the identities of individuals in photos. At the same time, DeepFakes blend well with surroundings and are as aesthetically pleasing as blurring and pixelating. We discuss how DeepFake obfuscation can enhance privacy protection without negatively impacting the photo’s aesthetics. Mohamed Khamis, Habiba Farzand, Marija Mumm, Karola Marky |
AVI | 4 |
| 2022 | PIN Scrambler: Assessing the Impact of Randomized Layouts on the Usability and Security of PINsabstractRandomizing the layout of the keypad has been proposed to improve the security of PIN entry. However, there has been no empirical quantification of its impact on usability and security. We present the first usability (N=17) and security (N=24) evaluations to compare PIN entry with the standard vs randomized layout. Our results show that randomizing the layout increases resistance to shoulder surfing and thermal attacks significantly, and has a very minor impact on entry accuracy, but it increases entry time (from ≈ 1.4 seconds to ≈ 2 seconds). We discuss how this simple approach can improve security with little impact on usability. Daniel Kirkwood, Cagdas Tombul, Calum Firth, Finn Macdonald, Konstantinos Priftis, Florian Mathis, Mohamed Khamis, Karola Marky |
MUM | 8 |
| 2022 | Experiencing Tangible Privacy Control for Smart Homes with PriKeyabstractExisting software-based smart home privacy mechanisms are frequently indirect and cumbersome to use. We developed PriKey, a tangible privacy mechanism for smart homes that offers intuitive, device-independent, sensor-based, and user-centric privacy control. To render our concept comprehensible, we implemented a demonstration consisting of Wizard-of-Oz prototypes that show the envisioned form factor, size, and portability of our system, as well as a larger functional prototype of PriKey, which enables control of privacy-invasive sensors integrated into two exemplary smart devices, i.e., a smart speaker and a tablet. Sarah Delgado Rodriguez, Sarah Prange, Pascal Knierim, Karola Marky, Florian Alt |
MUM | 4 |
| 2022 | Investigating State-of-the-Art Practices for Fostering Subjective Trust in Online Voting through Interviews
Karola Marky, Paul Gerber, Sebastian Günther 0001, Mohamed Khamis, Maximilian Fries, Max Mühlhäuser |
USENIX Security Symposium | 1 |
| 2022 | User-centred multimodal authentication: securing handheld mobile devices using gaze and touch inputabstractHandheld mobile devices store a plethora of sensitive data, such as private emails, personal messages, photos, and location data. Authentication is essential to protect access to sensitive data. However, the majority of mobile devices are currently secured by singlemodal authentication schemes which are vulnerable to shoulder surfing, smudge attacks, and thermal attacks. While some authentication schemes protect against one of these attacks, only few schemes address all three of them. We propose multimodal authentication where touch and gaze input are combined to resist shoulder surfing, as well as smudge and thermal attacks. Based on a series of previously published works where we studied the usability of several user-centred multimodal authentication designs and their security against multiple threat models, we provide a comprehensive overview of multimodal authentication on handheld mobile devices. We further present guidelines on how to leverage multiple input modalities for enhancing the usability and security of user authentication on mobile devices. Mohamed Khamis, Karola Marky, Andreas Bulling, Florian Alt |
Behav. Inf. Technol. | 2 |
| 2022 | "You offer privacy like you offer tea": Investigating Mechanisms for Improving Guest Privacy in IoT-Equipped HouseholdsabstractIoT devices are becoming more common and prevalent in private households. Since guests can be present in IoT-equipped households, IoT devices can pose considerable privacy risks to them. In this paper, we present an in-depth evaluation of privacy protection for guests considering the perspectives of hosts and guests. First, we interviewed 21 IoT device owners about four classes of mechanisms obtained from the literature and social aspects. Second, we conducted an online survey (N=264) that investigates the perspective of guests in IoT-equipped households. From our results, we learn that protection mechanisms should not introduce privacy threats and require low resources. Further, hosts should keep control over their devices and the aesthetics of their living spaces. Guests, however, value feedback about the status of privacy protection which can interfere with aesthetics. Privacy protection should rather foster collaboration and not impact the visit of the guest too severely. We use our results to identify a design space for guest privacy protection in IoT-equipped households. Karola Marky, Nina Gerber, Michelle Gabriela Pelzer, Mohamed Khamis, Max Mühlhäuser |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | "Nah, it's just annoying!" A Deep Dive into User Perceptions of Two-Factor AuthenticationabstractTwo-factor authentication (2FA) is a recommended or imposed authentication mechanism for valuable online assets. However, 2FA mechanisms usually exhibit user experience issues that create user friction and even lead to poor acceptance, hampering the wider spread of 2FA. In this article, we investigate user perceptions of 2FA through in-depth interviews with 42 participants, revealing key requirements that are not well met today despite recently emerged 2FA solutions. First, we investigate past experiences with authentication mechanisms emphasizing problems and aspects that hamper good user experience. Second, we investigate the different authentication factors more closely. Our results reveal particularly interesting preferences regarding the authentication factor “ownership” in terms of properties, physical realizations, and interaction. These findings suggest a path toward 2FA mechanisms with considerably better user experience, promising to improve the acceptance and hence, the proliferation of 2FA for the benefit of security in the digital world. Karola Marky, Kirill Ragozin, George Chernyshov, Andrii Matviienko, Martin Schmitz 0001, Max Mühlhäuser, Chloe Eghtebas, Kai Kunze |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2021 | Let's Frets! Assisting Guitar Students During Practice via Capacitive SensingabstractLearning a musical instrument requires regular exercise. However, students are often on their own during their practice sessions due to the limited time with their teachers, which increases the likelihood of mislearning playing techniques. To address this issue, we present Let’s Frets - a modular guitar learning system that provides visual indicators and capturing of finger positions on a 3D-printed capacitive guitar fretboard. We based the design of Let’s Frets on requirements collected through in-depth interviews with professional guitarists and teachers. In a user study (N=24), we evaluated the feedback modules of Let’s Frets against fretboard charts. Our results show that visual indicators require the least time to realize new finger positions while a combination of visual indicators and position capturing yielded the highest playing accuracy. We conclude how Let’s Frets enables independent practice sessions that can be translated to other musical instruments. Karola Marky, Andreas Weiß, Andrii Matviienko, Florian Brandherm, Martin Schmitz 0001, Florian Krell, Florian Müller 0003, Max Mühlhäuser, Thomas Kosch |
CHI | 1 |
| 2021 | Roles Matter! Understanding Differences in the Privacy Mental Models of Smart Home Visitors and ResidentsabstractIn this paper, we contribute an in-depth study of the mental models of various roles in smart home ecosystems. In particular, we compared mental models regarding data collection among residents (primary users) and visitors of a smart home in a qualitative study (N=30) to better understand how their specific privacy needs can be addressed. Our results suggest that visitors have a limited understanding of how smart devices collect and store sensitive data about them. Misconceptions in visitors’ mental models result in missing awareness and ultimately limit their ability to protect their privacy. We discuss the limitations of existing solutions and challenges for the design of future smart home environments that reflect the privacy concerns of users and visitors alike, meant to inform the design of future privacy interfaces for IoT devices. Karola Marky, Sarah Prange, Max Mühlhäuser, Florian Alt |
MUM | 1 |
| 2021 | Boiling Mind: Amplifying the Audience-Performer Connection through Sonification and Visualization of Heart and Electrodermal ActivitiesabstractIn stage performances, an invisible wall in front of the stage often weakens the connections between the audience and performers. To amplify this performative connection, we present the concept ”Boiling Mind”. Our design concept is based on streaming sensor data related to heart and electrodermal activities from audience members and integrating this data into staging elements, such as visual projections, music, and lighting. Thus, the internal states of the audience directly influence the staging. Artists can have a more direct perception of the inner reactions of audience members and can create physical expressions in response to them. In this paper, we present the wearable sensing system as well as design considerations of mapping heart and electrodermal activity to changes in the staging elements. We evaluated our design and setup over three live performances. Moe Sugawa, Taichi Furukawa, George Chernyshov, Danny Hynds, Jiawen Han, Marcelo Padovani, Dingding Zheng, Karola Marky, Kai Kunze, Kouta Minamizawa |
TEI | 8 |
| 2021 | Investigating Usability and User Experience of Individually Verifiable Internet Voting SchemesabstractInternet voting can afford more inclusive and inexpensive elections. The flip side is that the integrity of the election can be compromised by adversarial attacks and malfunctioning voting infrastructure. Individual verifiability aims to protect against such risks by letting voters verify that their votes are correctly registered in the electronic ballot box. Therefore, voters need to carry out additional tasks making human factors crucial for security. In this article, we establish a categorization of individually verifiable Internet voting schemes based on voter interactions. For each category in our proposed categorization, we evaluate a voting scheme in a user study with a total of 100 participants. In our study, we assessed usability, user experience, trust, and further qualitative data to gain deeper insights into voting schemes. Based on our results, we conclude with recommendations for developers and policymakers to inform the choices and design of individually verifiable Internet voting schemes. Karola Marky, Marie-Laure Zollinger, Peter B. Rønne, Peter Y. A. Ryan, Tim Grube, Kai Kunze |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2020 | 3D-Auth: Two-Factor Authentication with Personalized 3D-Printed ItemsabstractTwo-factor authentication is a widely recommended security mechanism and already offered for different services. However, known methods and physical realizations exhibit considerable usability and customization issues. In this paper, we propose 3D-Auth, a new concept of two-factor authentication. 3D-Auth is based on customizable 3D-printed items that combine two authentication factors in one object. The object bottom contains a uniform grid of conductive dots that are connected to a unique embedded structure inside the item. Based on the interaction with the item, different dots turn into touch-points and form an authentication pattern. This pattern can be recognized by a capacitive touchscreen. Based on an expert design study, we present an interaction space with six categories of possible authentication interactions. In a user study, we demonstrate the feasibility of 3D-Auth items and show that the items are easy to use and the interactions are easy to remember. Karola Marky, Martin Schmitz 0001, Verena Zimmermann, Martin Herbers, Kai Kunze, Max Mühlhäuser |
CHI | 1 |
| 2020 | Improving the Usability and UX of the Swiss Internet Voting InterfaceabstractUp to 20% of residential votes and up to 70% of absentee votes in Switzerland are cast online. The Swiss system aims to provide individual verifiability by different verification codes. The voters have to carry out verification on their own, making the usability and UX of the interface of great importance. To improve the usability, we first performed an evaluation with 12 human-computer interaction experts to uncover usability weaknesses of the Swiss Internet voting interface. Based on the experts' findings, related work, and an exploratory user study with 36 participants, we propose a redesign that we evaluated in a user study with 49 participants. Our study confirmed that the redesign indeed improves the detection of incorrect votes by 33% and increases the trust and understanding of the voters. Our studies furthermore contribute important lessons for designing verifiable e-voting systems in general. Karola Marky, Verena Zimmermann, Markus Funk, Jörg Daubert, Kira Bleck, Max Mühlhäuser |
CHI | 1 |
| 2020 | "You just can't know about everything": Privacy Perceptions of Smart Home VisitorsabstractIoT devices can harvest personal information of any person in their surroundings and this includes data from visitors. Visitors often cannot protect their privacy in a foreign smart environment. This might be rooted in a poor awareness of privacy violations by IoT devices, a lack of knowledge, or a lack of coping strategies. Thus, visitors are typically unaware of being tracked by IoT devices or lack means to influence which data is collected about them. We interviewed 21 young adults to investigate which knowledge visitors of smart environments need and wish to be able and protect their privacy. We found that visitors consider their relation to the IoT device owner and familiarity with the environment and IoT devices when making decisions about data sharing that affect their privacy. Overall, the visitors of smart environments demonstrated similar privacy preferences like the owners of IoT devices but lacked means to judge consequences of data collection and means to express their privacy preferences. Based on our results, we discuss prerequisites for enabling visitor privacy in smart environments, demonstrate gaps in existing solutions and provide several methods to improve the awareness of smart environment visitors. Karola Marky, Sarah Prange, Florian Krell, Max Mühlhäuser, Florian Alt |
MUM | 1 |
| 2020 | VRSketchPen: Unconstrained Haptic Assistance for Sketching in Virtual 3D EnvironmentsabstractAccurate sketching in virtual 3D environments is challenging due to aspects like limited depth perception or the absence of physical support. To address this issue, we propose VRSketchPen – a pen that uses two haptic modalities to support virtual sketching without constraining user actions: (1) pneumatic force feedback to simulate the contact pressure of the pen against virtual surfaces and (2) vibrotactile feedback to mimic textures while moving the pen over virtual surfaces. To evaluate VRSketchPen, we conducted a lab experiment with 20 participants to compare (1) pneumatic, (2) vibrotactile and (3) a combination of both with (4) snapping and no assistance for flat and curved surfaces in a 3D virtual environment. Our findings show that usage of pneumatic, vibrotactile and their combination significantly improves 2D shape accuracy and leads to diminished depth errors for flat and curved surfaces. Qualitative results indicate that users find the addition of unconstraining haptic feedback to significantly improve convenience, confidence and user experience. Hesham Elsayed, Mayra Donaji Barrera Machuca, Christian Schaarschmidt, Karola Marky, Florian Müller 0003, Jan Riemann, Andrii Matviienko, Martin Schmitz 0001, Martin Weigel 0001, Max Mühlhäuser |
VRST | 4 |
| 2019 | You Invaded my Tracking Space! Using Augmented Virtuality for Spotting Passersby in Room-Scale Virtual RealityabstractWith the proliferation of room-scale Virtual Reality (VR), more and more users install a VR system in their homes. When users are in VR, they are usually completely immersed in their application. However, sometimes passersby invade these tracking spaces and walk up to users that are currently immersed in VR to try and interact with them. As this either scares the user in VR or breaks the user's immersion, research has yet to find a way to seamlessly represent physical passersby in virtual worlds. In this paper, we propose and evaluate three different ways to represent physical passersby in a Virtual Environment using Augmented Virtuality. The representations encompass showing a Pointcloud, showing a 3D-Model, and showing an Image Overlay of the passerby. Our results show that while an Image Overlay and a 3D-Model are the fastest representations to spot passersby, the 3D-Model and the Pointcloud representations were the most accurate. Julius von Willich, Markus Funk, Florian Müller 0003, Karola Marky, Jan Riemann, Max Mühlhäuser |
Conference on Designing Interactive Systems | 4 |
| 2018 | What Did I Really Vote For?abstractE-voting has been embraced by a number of countries, delivering benefits in terms of efficiency and accessibility. End-to-end verifiable e-voting schemes facilitate verification of the integrity of individual votes during the election process. In particular, methods for cast-as-intended verification enable voters to confirm that their cast votes have not been manipulated by the voting client. A well-known technique for effecting cast-as-intended verification is the Benaloh Challenge. The usability of this challenge is crucial because voters have to be actively engaged in the verification process. In this paper, we report on a usability evaluation of three different approaches of the Benaloh Challenge in the remote e-voting context. We performed a comparative user study with 95 participants. We conclude with a recommendation for which approaches should be provided to afford verification in real-world elections and suggest usability improvements. Karola Marky, Oksana Kulyk, Karen Renaud, Melanie Volkamer |
CHI | 1 |
| 2017 | Coercion-resistant proxy voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
Comput. Secur. | 3 |
| 2016 | Introducing Proxy Voting to HeliosabstractProxy voting is a form of voting, where the voters can either vote on an issue directly, or delegate their voting right to a proxy. This proxy might for instance be a trusted expert on the particular issue. In this work, we extend the widely studied end-to-end verifiable Helios Internet voting system towards the proxy voting approach. Therefore, we introduce a new type of credentials, so-called delegation credentials. The main purpose of these credentials is to ensure that the proxy has been authorised by an eligible voter to cast a delegated vote. If voters, after delegating, change their mind and want to vote directly, cancelling a delegation is possible throughout the entire voting phase. We show that the proposed extension preserves the security requirements of the original Helios system for the votes that are cast directly, as well as security requirements tailored toward proxy voting. Oksana Kulyk, Karola Marky, Stephan Neumann, Melanie Volkamer |
ARES | 2 |
| 2016 | Coercion-Resistant Proxy Voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
SEC | 3 |