Sarah Prange

dblp:210/8238 · DBLP profile ↗
← Back
20ranked-venue papers
8as first author
12since 2021 · last 2026
0000-0001-8303-1600ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 20 · 8 first-author · 12 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 I don't know what I've all granted. Does it really matter? - Understanding Users' Awareness of Different Permission Types on Android
Verena Winterhalter, Sarah Prange, Anouk Moreno, Harel Israel Berger, Florian Alt
SOUPS2
2024 Decide Yourself or Delegate - User Preferences Regarding the Autonomy of Personal Privacy Assistants in Private IoT-Equipped Environments
abstract
Personalized privacy assistants (PPAs) communicate privacy-related decisions of their users to Internet of Things (IoT) devices. There are different ways to implement PPAs by varying the degree of autonomy or decision model. This paper investigates user perceptions of PPA autonomy models and privacy profiles – archetypes of individual privacy needs – as a basis for PPA decisions in private environments (e.g., a friend’s home). We first explore how privacy profiles can be assigned to users and propose an assignment method. Next, we investigate user perceptions in 18 usage scenarios with varying contexts, data types and number of decisions in a study with 1126 participants. We found considerable differences between the profiles in settings with few decisions. If the number of decisions gets high (> 1/h), participants exclusively preferred fully autonomous PPAs. Finally, we discuss implications and recommendations for designing scalable PPAs that serve as privacy interfaces for future IoT devices.
Karola Marky, Alina Stöver, Sarah Prange, Kira Bleck, Paul Gerber, Verena Zimmermann, Florian Müller 0003, Florian Alt, Max Mühlhäuser
CHI3
2024 Act2Auth - A Novel Authentication Concept based on Embedded Tangible Interaction at Desks
abstract
Authentication (e.g., entering a password) is frequently perceived as an annoying obstacle when interacting with computational devices, but still essential to protect sensitive data from unauthorized access. We present Act2Auth, a novel concept for embedding authentication into users’ established routines by sensing tangible interactions at desks. With Act2Auth, users can authenticate by performing (secret) routines, such as putting a cup on their desk, rearranging their keyboard, and touching their mouse. The Act2Auth concept is informed by (1) an object analysis of 107 desk photos from Reddit, (2) an online survey (N = 65) investigating users’ strategies for creating touch-based authentication secrets, and (3) a technical exploration of capacitive touch-sensing at desks. We then (4) implemented a prototype and evaluated the usability as well as the memorability of Act2Auth compared to textual passwords (N = 8). With Act2Auth, we provide fundamental work on how to embed authentication tasks into our daily tangible interactions.
Sarah Delgado Rodriguez, Sarah Prange, Lukas Mecke, Florian Alt
TEI2
2022 "Secure settings are quick and easy!" - Motivating End-Users to Choose Secure Smart Home Configurations
abstract
While offering many useful features, novel smart home devices also provide an attack surface to users’ allegedly secure place: their homes. Thus, it is essential to employ effective threat mitigation strategies, such as securely configuring devices. We investigate how users can be motivated to do so. To foster secure actions, we designed two types of nudges based on the Protection Motivation Theory (PMT): one with low and one with high level of detail. As such, our nudges particularly target users’ threat appraisal (including perceived severity and likelihood of threats) and self-efficacy to take action. In a randomized online experiment (N = 210), we simulated a smart home setup procedure. Participants chose significantly more secure configurations when being provided with detailed nudges, and indicated higher perceived threat and coping appraisal (i.e., higher protection motivation) after the experiment. Based on our results, we discuss the design and deployment of nudges for (future) smart home setup procedures. Our work can help to a) increase users’ threat awareness in general, and b) motivate users to take actions such as securely configuring their devices.
Sarah Prange, Niklas Thiem, Michael Fröhlich, Florian Alt
AVI1
2022 "I saw your partner naked": Exploring Privacy Challenges During Video-based Online Meetings
abstract
Video-based online meetings and, ultimately, the amount of private information that is shared – intentionally or accidentally – increased as a result of the COVID-19 pandemic. For example, online teaching might reveal lecturers’ private environment to students or business meetings might provide insights about employees’ family relationships. This raises the need to understand users’ perception towards privacy intrusion during online video conferences to inform concepts that better protect meeting participants’ privacy. We present the results of an online survey (N = 140) in which we investigate user stories of privacy-invasive situations in their homes during such meetings. Our results show that online meetings reveal private information that would not have become available during physical meetings. This often involves third parties (e.g., children, spouse, colleague), who might not even be aware of this. We discuss potential means to support users in protecting their and others’ privacy before, during, and after video-based online meetings.
Sarah Prange, Sarah Delgado Rodriguez, Lukas Mecke, Florian Alt
MUM1
2022 Experiencing Tangible Privacy Control for Smart Homes with PriKey
abstract
Existing software-based smart home privacy mechanisms are frequently indirect and cumbersome to use. We developed PriKey, a tangible privacy mechanism for smart homes that offers intuitive, device-independent, sensor-based, and user-centric privacy control. To render our concept comprehensible, we implemented a demonstration consisting of Wizard-of-Oz prototypes that show the envisioned form factor, size, and portability of our system, as well as a larger functional prototype of PriKey, which enables control of privacy-invasive sensors integrated into two exemplary smart devices, i.e., a smart speaker and a tablet.
Sarah Delgado Rodriguez, Sarah Prange, Pascal Knierim, Karola Marky, Florian Alt
MUM2
2021 SpatialProto: Exploring Real-World Motion Captures for Rapid Prototyping of Interactive Mixed Reality
abstract
Spatial computing devices that blend virtual and real worlds have the potential to soon become ubiquitous. Yet, creating experiences for spatial computing is non-trivial and needs skills in programming and 3D content creation, rendering them inaccessible to a wider group of users. We present SpatialProto, an in-situ spatial prototyping system for lowering the barrier to engage in spatial prototyping. With a depth-sensing capable mixed reality headset, SpatialProto lets users record animated objects of the real-world environment (e.g. paper, clay, people, or any other prop), extract only the relevant parts, and directly place and transform these recordings in their physical environment. We describe the design and implementation of SpatialProto, a user study evaluating the system’s prototype with non-expert users (n = 9), and demonstrate applications where multiple captures are fused for compelling augmented reality experiences.
Leon Müller, Ken Pfeuffer, Jan Gugenheimer, Bastian Pfleging, Sarah Prange, Florian Alt
CHI5
2021 PriView- Exploring Visualisations to Support Users' Privacy Awareness
abstract
We present PriView, a concept that allows privacy-invasive devices in the users’ vicinity to be visualised. PriView is motivated by an ever-increasing number of sensors in our environments tracking potentially sensitive data (e.g., audio and video). At the same time, users are oftentimes unaware of this, which violates their privacy. Knowledge about potential recording would enable users to avoid accessing such areas or not to disclose certain information. We built two prototypes: a) a mobile application capable of detecting smart devices in the environment using a thermal camera, and b) VR mockups of six scenarios where PriView might be useful (e.g., a rental apartment). In both, we included several types of visualisation. Results of our lab study (N=24) indicate that users prefer simple, permanent indicators while wishing for detailed visualisations on demand. Our exploration is meant to support future designs of privacy visualisations for varying smart environments.
Sarah Prange, Robin Piening, Yomna Abdelrahman, Florian Alt
CHI1
2021 Looking for Info: Evaluation of Gaze Based Information Retrieval in Augmented Reality
Robin Piening, Ken Pfeuffer, Augusto Esteves, Tim Mittermeier, Sarah Prange, Philippe Schröder, Florian Alt
INTERACT (1)5
2021 Investigating User Perceptions Towards Wearable Mobile Electromyography
Sarah Prange, Sven Mayer, Maria-Lena Bittl, Mariam Hassib, Florian Alt
INTERACT (4)1
2021 Roles Matter! Understanding Differences in the Privacy Mental Models of Smart Home Visitors and Residents
abstract
In this paper, we contribute an in-depth study of the mental models of various roles in smart home ecosystems. In particular, we compared mental models regarding data collection among residents (primary users) and visitors of a smart home in a qualitative study (N=30) to better understand how their specific privacy needs can be addressed. Our results suggest that visitors have a limited understanding of how smart devices collect and store sensitive data about them. Misconceptions in visitors’ mental models result in missing awareness and ultimately limit their ability to protect their privacy. We discuss the limitations of existing solutions and challenges for the design of future smart home environments that reflect the privacy concerns of users and visitors alike, meant to inform the design of future privacy interfaces for IoT devices.
Karola Marky, Sarah Prange, Max Mühlhäuser, Florian Alt
MUM2
2021 Remote VR Studies: A Framework for Running Virtual Reality Studies Remotely Via Participant-Owned HMDs
abstract
We investigate opportunities and challenges of running virtual reality (VR) studies remotely. Today, many consumers own head-mounted displays (HMDs), allowing them to participate in scientific studies from their homes using their own equipment. Researchers can benefit from this approach by being able to recruit study populations normally out of their reach, and to conduct research at times when it is difficult to get people into the lab (cf. the COVID pandemic). In an initial online survey ( N = 227), we assessed HMD owners’ demographics, their VR setups and their attitudes toward remote participation. We then identified different approaches to running remote studies and conducted two case studies for an in-depth understanding. We synthesize our findings into a framework for remote VR studies, discuss strengths and weaknesses of the different approaches, and derive best practices. Our work is valuable for Human-Computer Interaction (HCI) researchers conducting VR studies outside labs.
Radiah Rivu, Ville Mäkelä, Sarah Prange, Sarah Delgado Rodriguez, Robin Piening, Yumeng Zhou, Kay Köhle, Ken Pfeuffer, Yomna Abdelrahman, Matthias Hoppe 0001, Albrecht Schmidt 0001, Florian Alt
ACM Trans. Comput. Hum. Interact.3
2020 Don't Use Fingerprint, it's Raining!: How People Use and Perceive Context-Aware Selection of Mobile Authentication
abstract
This paper investigates how smartphone users perceive switching from their primary authentication mechanism to a fallback one, based on the context. This is useful in cases where the primary mechanism fails (e.g., wet fingers when using fingerprint). While prior work introduced the concept, we are the first to investigate its perception by users and their willingness to follow a system's suggestion for a switch. We present findings from a two-week field study (N=29) using an Android app, showing that users are willing to adopt alternative mechanisms when prompted. We discuss how context-awareness can improve the perception of authentication reliability and potentially improve usability and security.
Sarah Prange, Lukas Mecke, Alice Nguyen, Mohamed Khamis, Florian Alt
AVI1
2020 "You just can't know about everything": Privacy Perceptions of Smart Home Visitors
abstract
IoT devices can harvest personal information of any person in their surroundings and this includes data from visitors. Visitors often cannot protect their privacy in a foreign smart environment. This might be rooted in a poor awareness of privacy violations by IoT devices, a lack of knowledge, or a lack of coping strategies. Thus, visitors are typically unaware of being tracked by IoT devices or lack means to influence which data is collected about them. We interviewed 21 young adults to investigate which knowledge visitors of smart environments need and wish to be able and protect their privacy. We found that visitors consider their relation to the IoT device owner and familiarity with the environment and IoT devices when making decisions about data sharing that affect their privacy. Overall, the visitors of smart environments demonstrated similar privacy preferences like the owners of IoT devices but lacked means to judge consequences of data collection and means to express their privacy preferences. Based on our results, we discuss prerequisites for enabling visitor privacy in smart environments, demonstrate gaps in existing solutions and provide several methods to improve the awareness of smart environment visitors.
Karola Marky, Sarah Prange, Florian Krell, Max Mühlhäuser, Florian Alt
MUM2
2019 Behavioural Biometrics in VR: Identifying People from Body Motion and Relations in Virtual Reality
abstract
Every person is unique, with individual behavioural characteristics: how one moves, coordinates, and uses their body. In this paper we investigate body motion as behavioural biometrics for virtual reality. In particular, we look into which behaviour is suitable to identify a user. This is valuable in situations where multiple people use a virtual reality environment in parallel, for example in the context of authentication or to adapt the VR environment to users' preferences. We present a user study (N=22) where people perform controlled VR tasks (pointing, grabbing, walking, typing), monitoring their head, hand, and eye motion data over two sessions. These body segments can be arbitrarily combined into body relations, and we found that these movements and their combination lead to characteristic behavioural patterns. We present an extensive analysis of which motion/relation is useful to identify users in which tasks using classification methods. Our findings are beneficial for researchers and practitioners alike who aim to build novel adaptive and secure user interfaces in virtual reality.
Ken Pfeuffer, Matthias J. Geiger, Sarah Prange, Lukas Mecke, Daniel Buschek, Florian Alt
CHI3
2019 Securing personal items in public space: stories of attacks and threats
abstract
While we put great effort in protecting digital devices and data, there is a lack of research on usable techniques to secure personal items that we carry in public space. To better understand situations where ubiquitous technologies could help secure personal items, we conducted an online survey (N=101) in which we collected real-world stories from users reporting on personal items, either at risk of, or actually being lost, damaged or stolen. We found that the majority of cases occurred in (semi-)public spaces during afternoon and evening times, when users left their items. From these results, we derived a model of incidents involving personal items in public space as well as a set of properties to describe situations where personal items may be at risk. We discuss reoccurring properties of the scenarios, potential multimedia-based protection mechanisms for securing personal items in public space as well as future research suggestions.
Sarah Prange, Lukas Mecke, Michael Stadler, Maximilian Balluff, Mohamed Khamis, Florian Alt
MUM1
2018 Open Sesame!: User Perception of Physical, Biometric, and Behavioural Authentication Concepts to Open Doors
abstract
In usable security (e.g., smartphone authentication), a lot of emphasis is put on low-effort authentication and access concepts. Yet, only very few approaches exist where such concepts are applied beyond digital devices. We investigate and explore seamless authentication systems at doors, where most currently used systems for seamless access rely on the use of tokens. In a Wizard-of-Oz study, we investigate three different authentication schemes, namely (1) key, (2) palm vein scanner and (3) gait-based authentication (compare Fig. 1). Most participants in our study (N=15) preferred the palm vein scanner, while ranking unlocking with a key and gait-based recognition second and third. Our results propose that recovery costs for a failed authentication attempt have an impact on user perception. Furthermore, while the participants appreciated seamless authentication via biometrics, they also valued the control they gain from the possession of a physical token.
Lukas Mecke, Ken Pfeuffer, Sarah Prange, Florian Alt
MUM3
2018 An Exploratory Study on Correlations of Hand Size and Mobile Touch Interactions
abstract
We report on an exploratory study investigating the relationship of users' hand sizes and aspects of their mobile touch interactions. Estimating hand size from interaction could inform, for example, UI adaptation, occlusion-aware UIs, and biometrics. We recorded touch data from 62 participants performing six touch tasks on a smartphone. Our results reveal considerable correlations between hand size and aspects of touch interaction, both for tasks with unrestricted "natural" postures and restricted hand locations. We discuss implications for applications and ideas for future work.
Sarah Prange, Daniel Buschek, Florian Alt
MUM1
2018 Design Considerations for Secure and Usable Authentication on Situated Displays
abstract
Users often need to authenticate at situated displays in order to, for example, make purchases, access sensitive information, or confirm an identity. However, the exposure of interactions in public spaces introduces a large attack surface (e.g., observation, smudge or thermal attacks). A plethora of authentication models and input modalities that aim at disguising users' input has been presented in the past. However, a comprehensive analysis on the requirements for secure and usable authentication on public displays is still missing. This work presents 13 design considerations suitable to inform practitioners and researchers during the development process of authentication systems for situated displays in public spaces. It draws on a comprehensive analysis of prior literature and subsequent discussion with five experts in the fields of pervasive displays, human-computer-interaction and usable security.
Ludwig Trotter, Sarah Prange, Mohamed Khamis, Nigel Davies 0001, Florian Alt
MUM2
2017 Quakequiz: a case study on deploying a playful display application in a museum context
abstract
In this paper, we present a case study in which we designed and implemented an interactive museum exhibit. In particular, we extended a section of the museum with an interactive quiz game. The project is an example of an opportunistic deployment where the needs of different stakeholders (museum administration, visitors, researchers) and the properties of the space needed to be considered. It is also an example of how we can apply knowledge on methodology and audience behavior collected over the past years by the research community. At the focus of this paper is (1) the design and concept phase that led to the initial idea for the exhibit, (2) the implementation phase, (3) a roll-out and early insights phase where we tested and refined the application in an iterative design process on-site, and (4) the final deployment as a permanent exhibit of the museum. We hope our report to be useful for researchers and practitioners designing systems for similar contexts.
Sarah Prange, Victoria Müller, Daniel Buschek, Florian Alt
MUM1