Sanchari Das 0001

dblp:217/7358-1 · DBLP profile ↗
← Back
37ranked-venue papers
2as first author
35since 2021 · last 2026
0000-0003-1299-7867ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 1 first-author · 17 since 2021Human-computer interaction and ubiquitous computing · 15 · 1 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SoK: Analysis of Privacy Risks and Mitigation in Online Propaganda Detection through the PROMPT Framework
Dhiman Goswami, Al Nahian Bin Emran, Md Hasan Ullah Sadi, Sanchari Das 0001
AsiaCCS4
2026 SoK: Reviewing Two Decades of Security, Privacy, Accessibility, and Usability Studies on Internet of Things for Older Adults
abstract
The Internet of Things (IoT) has the potential to enhance older adults' independence and quality of life, but it also exposes them to security, privacy, accessibility, and usability (SPAU) risks. We conducted a systematic review of 44 peer-reviewed studies published between 2004 and 2024 using a five-phase screening pipeline. From each study, we extracted data on study design, IoT type, SPAU measures, and identified research gaps. We introduce the SPAU-IoT Framework, which comprises 27 criteria across four dimensions: security (e.g., resilience to cyber threats, secure authentication, encrypted communication, secure-by-default settings, and guardianship features), privacy (e.g., data minimization, explicit consent, and privacy-preserving analytics), accessibility (e.g., compliance with ADA/WCAG standards and assistive-technology compatibility), and usability (e.g., guided interaction, integrated assistance, and progressive learning). Applying this framework revealed that more than 70% of studies implemented authentication and encryption mechanisms, whereas fewer than 50% addressed accessibility or usability concerns. We further developed a threat model that maps IoT assets, networks, and backend servers to exploit vectors such as phishing, caregiver exploitation, and weak-password attacks, explicitly accounting for age-related vulnerabilities including cognitive decline and sensory impairment. Our results expose a systemic lack of integrated SPAU approaches in existing IoT research and translate these gaps into actionable, standards-aligned design guidelines for IoT systems designed for older adults.
Suleiman Saka, Sanchari Das 0001
AsiaCCS2
2026 Expert-led Debunking of Health Misinformation on TikTok
abstract
In this work, we empirically evaluated expert-led debunking of health misinformation on TikTok with n=420 survey and n=20 interview participants. Unlike fact-checkers, health professionals debunk misinformation non-anonymously through video-against-video formats (stitching/”duetting”), rather than using labels. We analyzed 5,161 such posts to select six misinformation and six debunking videos across three common topics – two general health, two mental health, and two nutrition – for statistical comparison. Participants exposed to debunking videos believed misinformation claims significantly less than those exposed to misinformation videos in all six conditions. Experts were seen as more credible than misinformation creators, except in one instance involving mental health. Thematic analysis showed that expert-led debunking succeeded because experts’ videos aligned with the Debunking Handbook method for effective refutation. Experts’ credibility is derived mainly from being perceived as non-typical influencers who maintain reputable TikTok personas by providing qualified medical evidence and advice.
Filipo Sharevski, Jennifer Vander Loop, Amy Devine, Peter Jachim, Sanchari Das 0001
CHI5
2026 Co-designing MESA-Bot: Enhancing Accessibility, Privacy, Security, and Trust in a Mental Health Chatbot for Older Adults
abstract
Older adults are increasingly turning to chatbot-based mental health support, yet adoption remains limited by barriers in accessibility, privacy, security, and trust. We present a two-phase study on the co-design of MESA-Bot (Mental and Emotional Support Assistant for Older Adults), a non-diagnostic chatbot tailored to later-life needs. In Phase I, we analyzed ten leading mental health chatbots and conducted co-design sessions with N1 = 10 older adults to identify challenges and inform an accessible, privacy-aware prototype. In Phase II, we evaluated MESA-Bot with N2 = 28 older adults using semi-structured interviews and structured technical assessments. Participants emphasized transparent consent, supportive tone, and fine-grained data control. Features such as revocable consent, role-based access control, customizable data visibility, and simplified dialogue flows increased trust and usability; 86% found MESA-Bot easy to use. We offer design insights for inclusive, trustworthy mental health technologies that integrate accessibility with verifiable privacy and security protections.
Aishwarya Umeshkumar Surani, Sanchari Das 0001
CHI2
2026 Privacy Discourse and Emotional Dynamics in Mental Health Information Interaction on Reddit
abstract
Reddit is a major venue for mental-health information interaction and peer support, where privacy concerns increasingly surface in user discourse. Thus, we analyze privacy-related discussions across 14 mental-health and regulatory subreddits, comprising 10, 119 posts and 65, 385 comments collected with a custom web scraper. Using lexicon-based sentiment analysis, we quantify emotional alignment between communities via cosine similarity of sentiment distributions, observing high similarity for Bipolar and ADHD (0.877), Anxiety and Depression (0.849), and MentalHealthSupport and MentalIllness (0.989) subreddits. We also construct keyword dictionaries to tag privacy-related themes (e.g., HIPAA, GDPR) and perform temporal analysis from 2020 to 2025, finding a \(50\%\) increase in privacy discourse with intermittent regulatory spikes. A chi-square test of independence across subreddit domains indicates significant distributional differences (χ2 = 5596.67, p = 0.03, df = 50). The results characterize how privacy-oriented discussion co-varies with user sentiment in online mental-health communities.
Jai Kruthunz Naveen Kumar, Aishwarya Umeshkumar Surani, Harkirat Singh, Sanchari Das 0001
CHIIR4
2026 Privacy-Preserving Compliance on Public Ledgers via Selective Disclosure Authorization Schemes
Supriya Khadka, Sanchari Das 0001
SECRYPT (1)2
2026 Starting with DEI and Ethics - A New First-Year College Computer Science Introduction
abstract
Early exposure to ethical reasoning and diversity, equity, and inclusion (DEI) concepts is critical for preparing socially responsible computer scientists. To support this goal, we designed and implemented a required non-programming first-year undergraduate computer science course that is taken concurrently with an introductory programming course. This discussion-based course integrates DEI and ethics as foundational themes. The new course adopts a breadth-first structure delivered over a 10-week quarter, with 5 of the 18 sessions focused on DEI and ethics. Over three consecutive academic years, we collected pre- and post-course survey data from 451 students enrolled in the new course. Results show an %statistically significant increase in student's recognition of the importance of DEI and ethics and a substantial increase in understanding how these dimensions intersect with technical practice. In this experience report, we describe the course design, instructional methods, and survey instruments; present key findings; and reflect on lessons learned. This work contributes a model for embedding DEI and ethics into the early undergraduate computing curriculum.
Scott T. Leutenegger, Stephen Hutt, Andrew Hannum, Sanchari Das 0001, Alannah Oleson, Alexandria Leto, Sunny Shrestha
SIGCSE (1)4
2025 Systemization of Knowledge (SoK): Goals, Coverage, and Evaluation in Cybersecurity and Privacy Games
abstract
This paper systematized existing knowledge on cybersecurity and privacy game-based approaches, exploring their goals, scope, and evaluation methods. Our review of 93 academic papers revealed that these approaches serve multiple purposes and target diverse player types. We identified 11 key aspects of cybersecurity and privacy that these approaches addressed, such as threats, defensive strategies, and data privacy. Additionally, we analyzed the effectiveness evaluation methods of these approaches, emphasizing the connections between evaluation techniques, types of data used, and their alignment with the approaches' goals. We also summarized the aspects of user experience evaluated in the literature and the types of questions used to capture these experiences. Reflecting on these methods, we provide guidance for future research and practice in designing and evaluating game-based approaches. Finally, we identify key gaps and propose opportunities to enhance user understanding, foster adaptability, and address emerging cybersecurity and privacy challenges.
Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das 0001, Jing Wei 0002, Helge Janicke
CHI5
2025 "Watch My Health, Not My Data": Understanding Perceptions, Barriers, Emotional Impact, & Coping Strategies Pertaining to IoT Privacy and Security in Health Monitoring for Older Adults
abstract
The proliferation of "Internet of Things (IoT)" provides older adults with critical support for "health monitoring" and independent living, yet significant concerns about security and privacy persist. In this paper, we report on these issues through a two-phase user study, including a survey (N = 22) and semi-structured interviews (n = 9) with adults aged 65+. We found that while 81.82% of our participants are aware of security features like "two-factor authentication (2FA)" and encryption, 63.64% express serious concerns about unauthorized access to sensitive health data. Only 13.64% feel confident in existing protections, citing confusion over "data sharing policies" and frustration with "complex security settings" which lead to distrust and anxiety. To cope, our participants adopt various strategies, such as relying on family or professional support and limiting feature usage leading to disengagement. Thus, we recommend "adaptive security mechanisms," simplified interfaces, and real-time transparency notifications to foster trust and ensure "privacy and security by design" in IoT health systems for older adults.
Suleiman Saka, Sanchari Das 0001
CHI2
2025 PolicyPulse: Precision Semantic Role Extraction for Enhanced Privacy Policy Comprehension
Andrick Adhikari, Sanchari Das 0001, Rinku Dewri
NDSS2
2025 "It's Like Not Being Able to Read and Write": Narrowing the Digital Divide for Older Adults and Leveraging the Role of Digital Educators in Ireland
abstract
As digital services increasingly replace traditional analogue systems, ensuring that older adults are not left behind is critical to fostering inclusive access. This study explores how digital educators support older adults in developing essential digital skills, drawing insights from interviews with $34$ educators in Ireland. These educators, both professional and volunteer, offer instruction through a range of formats, including workshops, remote calls, and in-person sessions. Our findings highlight the importance of personalized, step-by-step guidance tailored to older adults' learning needs, as well as fostering confidence through hands-on engagement with technology. Key challenges identified include limited transportation options, poor internet connectivity, outdated devices, and a lack of familial support for learning. To address these barriers, we propose enhanced public funding, expanded access to resources, and sustainable strategies such as providing relevant and practical course materials. Additionally, innovative tools like simulated online platforms for practicing digital transactions can help reduce anxiety and enhance digital literacy among older adults. This study underscores the vital role that digital educators play in bridging the digital divide, creating a more inclusive, human-centered approach to digital learning for older adults.
Melanie Gruben, Ashley Sheil, Sanchari Das 0001, Michelle O'Keeffe, Jacob Camilleri, Moya Cronin, Hazel Murray
TEI3
2025 POSTER: TRIDENT - A Three-Tier Privacy-Preserving Propaganda Detection Model in Mobile Networks using Transformers, Adversarial Learning, and Differential Privacy
abstract
The proliferation of propaganda on mobile platforms raises critical concerns around detection accuracy and user privacy. To address this, we propose TRIDENT -a three-tier propaganda detection model implementing transformers, adversarial learning, and differential privacy which integrates syntactic obfuscation and label perturbation to mitigate privacy leakage while maintaining propaganda detection accuracy. TRIDENT leverages multilingual back-translation to introduce semantic variance, character-level noise, and entity obfuscation for differential privacy enforcement, and combines these techniques into a unified defense mechanism. Using a binary propaganda classification dataset, baseline transformer models (BERT, GPT-2) we achieved F1 scores of 0.89 and 0.90. Applying TRIDENT's third-tier defense yields a reduced but effective cumulative F1 of 0.83, demonstrating strong privacy protection across mobile ML deployments with minimal degradation.
Al Nahian Bin Emran, Dhiman Goswami, Md Hasan Ullah Sadi, Sanchari Das 0001
WISEC4
2025 POSTER: VeilPIR: A Lightweight Private Information Retrieval Protocol for Enhancing Data Privacy in IoT Ecosystems
Saurav Ghosh, Sanchari Das 0001
WISEC2
2025 POSTER: A Multi-Signal Model for Detecting Evasive Smishing
abstract
Smishing, or SMS-based phishing, poses an increasing threat to mobile users by mimicking legitimate communications through culturally adapted, concise, and deceptive messages, which can result in the loss of sensitive data or financial resources. In such, we present a multi-channel smishing detection model that combines country-specific semantic tagging, structural pattern tagging, character-level stylistic cues, and contextual phrase embeddings. We curated and relabeled over 84,000 messages across five datasets, including 24,086 smishing samples. Our unified architecture achieves 97.89% accuracy, an F1 score of 0.963, and an AUC of 99.73%, outperforming single-stream models by capturing diverse linguistic and structural cues. This work demonstrates the effectiveness of multi-signal learning in robust and region-aware phishing.
Shaghayegh Hosseinpour, Sanchari Das 0001
WISEC2
2025 Social Media Misinformation and Voting Intentions: Older Adults' Experiences with Manipulative Narratives
abstract
Older adults habitually encounter misinformation, yet little is known about their experiences with it. In this study, we employed a mixed-methods approach, combining a survey (n=119) with semi-structured interviews ( n =21), to investigate how older adults in America conceptualize, discern, and contextualize social media misinformation. Given the historical context of misinformation being used to influence voting outcomes, our study specifically examined this phenomenon from a voting intention perspective. Our findings reveal that 62% of participants intending to vote Democrat perceived a manipulative political purpose behind the spread of misinformation, whereas only 5% of those intending to vote Republican believed that misinformation serves a political dissent purpose. Regardless of voting intentions, most participants relied on source heuristics and fact-checking to discern truth from misinformation on social media. A major concern among participants was the biased reasoning influenced by personal values and emotions affected by misinformation. Notably, 74% of participants intending to vote Democrat were concerned that misinformation would escalate extremism in the future. In contrast, those intending to vote Republican, those undecided, or those planning to abstain expressed concerns that misinformation would further erode trust in democratic institutions, particularly in public health and free and fair elections. During our interviews, we discovered that 63% of participants intending to vote Republican mentioned that Republican or conservative voices often disseminate misinformation, even though these participants were closely aligned with this political ideology.
Filipo Sharevski, Jennifer Vander Loop, Sanchari Das 0001
Proc. ACM Hum. Comput. Interact.3
2025 A Multi-Dimensional Analysis of IoT Companion Apps: A Look at Privacy, Security and Accessibility
abstract
Internet of Things (IoT) devices provide convenience to users by simplifying household tasks. Most IoTs can be remotely controlled via mobile companion apps, which constitute the main interface between devices themselves and their users. Such apps are used to configure, update, and control the device(s) and thus constitute a critical component in the IoT ecosystem. However, they have historically been understudied which prompts us to look into them. In this paper, we report on a study where we evaluated a sample of 455 IoT companion apps and analyze their privacy, security, and accessibility aspects. Our research aim is to understand these metrics, gauge their state and evaluate whether there is a correlation between them. Our primary findings from the analysis are: (i) most apps have reasonable security and accessibility posture, but in several dimensions there exists a long tail of apps with significant problems and (ii) apps tend to over-request permissions which are not related to their main goal. Moreover, the quality of an app along one aspect is uncorrelated to the same along other aspects. We conclude with actionable recommendations for companion app developers.
Faiza Tazi, Suleiman Saka, Shradha Neupane, Ethan Myers, Sanchari Das 0001, Lorenzo De Carli, Indrakshi Ray
IEEE Trans. Serv. Comput.5
2025 From PINs to Gestures: Analyzing Knowledge-Based Authentication Schemes for Augmented and Virtual Reality
abstract
As Augmented and Virtual Reality (AR/VR) advances, secure and user-friendly authentication becomes vital. We evaluated 17 authentication schemes across gaze, gesture, PIN, spatial, and recognition-based categories using a systematic framework focused on effectiveness, security, and usability. Our analysis revealed varied performance and significant gaps requiring standardized methods. For example, Beat-PIN demonstrated strong security with 140-bit entropy, while RubikAuth achieved high usability with authentication times of 1.69 seconds. Gaze-based methods, though innovative, faced accuracy issues. We also observed a preference for schemes like In-Air Handwriting and Things, which balanced security and ease of use. By extending Bonneau et al.'s framework [5] to develop an AR/VR-specific evaluation model, we identified schemes like RubikAuth and Things as particularly promising for AR/VR. This study highlights the strengths and limitations of current methods and emphasizes the need for cross-modal and context-aware techniques to advance AR/VR authentication.
Naheem Noah, Sanchari Das 0001
IEEE Trans. Vis. Comput. Graph.2
2024 "We Have No Security Concerns": Understanding the Privacy-Security Nexus in Telehealth for Audiologists and Speech-Language Pathologists: Understanding the Privacy-Security Nexus in Telehealth
abstract
The advent of telehealth revolutionizes healthcare by enabling remote consultations, yet poses complex security and privacy challenges. These are often acutely felt by lower-resourced, allied-healthcare practices. To address this, our study focuses on audiologists and speech-language pathologists (SLPs) in private practice settings, often characterized by limited information technology resources. Over the course of six months, we conducted semi-structured interviews with ten audiologists and ten SLPs to understand their telehealth experiences and concerns. Key findings reveal a diversity of opinions on technology trustworthiness, data security concerns, implemented security protocols, and patient behaviors. Given the nature of the medical practitioners’ primary work, participants expressed varied concerns about data breaches and platform vulnerabilities, yet trusted third-party services like Zoom due to inadequate expertise and time to evaluate security protocols. This work underscores the imperative of bridging the technology-healthcare gap to foster secure, patient/provider-centered telehealth as the prevailing practice. It also emphasizes the need to synergize security, privacy, and usability to securely deliver care through telehealth.
Faiza Tazi, Josiah Dykstra, Prashanth Rajivan, Sanchari Das 0001
CHI4
2024 Evaluating the Security and Privacy Risk Postures of Virtual Assistants
Borna Kalhor, Sanchari Das 0001
ICISSP2
2024 'Debunk-It-Yourself': Health Professionals Strategies for Responding to Misinformation on TikTok
Filipo Sharevski, Jennifer Vander Loop, Peter Jachim, Amy Devine, Sanchari Das 0001
NSPW5
2024 "I really just leaned on my community for support": Barriers, Challenges and Coping Mechanisms Used by Survivors of Technology-Facilitated Abuse to Seek Social Support
Kate Walsh, Sanchari Das 0001, Rahul Chatterjee 0001
USENIX Security Symposium3
2024 SoK: Analyzing Privacy and Security of Healthcare Data from the User Perspective
abstract
Interactions in healthcare, by necessity, involve sharing sensitive information to achieve high-quality patient outcomes. Therefore, sensitive data must be carefully protected. This article explores existing privacy and security research conducted in the context of healthcare organizations. We conducted a systematic literature review of N =1,553 articles that examine the security and privacy of healthcare data and focus on 80 articles addressing human factors. Key findings show that much of the healthcare security and privacy research is focused on technology (44.11%, 712 articles), with a lack of emphasis on the human element (4.96%, 80 articles). In the subset of user studies, we find that patients and the general public express concerns about privacy and security with technologies like electronic health records (EHRs). Furthermore, our analysis shows that healthcare professionals often have low awareness of risks related to data security. Additionally, our analysis revealed that most research focuses narrowly on large hospitals, neglecting private practices and the unique challenges they face. We conclude by identifying research gaps and providing potential solutions to enable robust data security for sensitive patient data.
Faiza Tazi, Archana Nandakumar, Josiah Dykstra, Prashanth Rajivan, Sanchari Das 0001
ACM Trans. Comput. Heal.5
2023 Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
abstract
Preventing workplace phishing depends on the actions of every employee, regardless of cybersecurity expertise. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old) at two U.S. universities, we found that less than 21% of our participants had any formal anti-phishing training. Much of what our participants know about phishing comes from informal sources that emphasize “tips” and "tricks" like those found in conversations with friends, news stories, newsletters, social media, and podcasts. These informal channels provide opportunities for IT professionals wishing to enhance employees’ anti-phishing awareness by better aligning the delivery of expert advice with employees’ current practices and desires. We provide four recommendations designed to embrace "guerrilla learning" by distributing anti-phishing educational resources across the workplace and workday in part to encourage the delivery of more accurate information in more informal and incidental ways, and greater dialogue between anti-phishing training instructors and learners.
Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng
CHI4
2023 Security and Privacy of Digital Mental Health: An Analysis of Web Services and Mobile Applications
Aishwarya Surani, Amani Bawaked, Matthew Wheeler, Braden Kelsey, Nikki Roberts, David Vincent, Sanchari Das 0001
DBSec7
2023 The Right To Be Forgotten and Educational Data Mining: Challenges and Paths Forward
Stephen Hutt, Sanchari Das 0001, Ryan Baker 0001
EDM2
2023 What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing Decisions
abstract
Phishing attacks, in which deceptive messages purporting to be from a legitimate contact are used to trick recipients and acquire sensitive information for the purposes of committing fraud, are a substantial and growing problem for organizations. IT departments and professionals may put in place a variety of institutional responses to thwart such attacks, but an organization's susceptibility to phishing also depends on the decisions and actions of individual employees. These employees may have little phishing expertise but still need to react to such attempts on a daily basis. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old, with a bachelor's degree or more) at two universities in the midwestern United States, we find that employees self-describe a wide range of levels of awareness of, and confidence, competency and investment in, the organization's proscribed anti-phishing policies and practices. These employees also describe variation in the ways they would prefer to increase their perceived performance levels in all of these areas. In this paper, we argue that in order to empower employees to be better collaborators in an organization's anti-phishing efforts, organizations should embrace a range of efforts akin to the range of expertise among the users themselves. We make four such empowering recommendations for organizations to consider incorporating into their existing anti-phishing policies and practices, including suggestions to 1) embrace educating non-expert users more fully on organizational processes and consequences, 2) provide employees with a standing one-to-one communication channel between them and an IT phishing point-of-contact, 3) keep employees in the loop once phishing reports are made, and 4) avoid testing employees with "gotcha" assessments.
Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng
Proc. ACM Hum. Comput. Interact.4
2023 Cybersecurity, Safety, & Privacy Concerns of Student Support Structure for Information and Communication Technologies in Online Education
abstract
COVID-19 has created a dramatic paradigm shift in education methods, which forced schools and universities to abandon the usual in-person education in favor of online education modules. Such a shift has extended the time and use of internet communication technologies (ICTs) by most, making online education platforms primary cyberattack targets. In this context, this study aims to explore parents, educators, and other caregivers' concerns about online education and the cybersecurity of their children and students. Thus, we conducted a survey-based study with 983 participants recruited through popular crowdsourcing platforms: MTurk and Prolific. Our results indicate a lack of technical support following cyber safety that the students received with the sudden transition to online education. Over 31% of our participants claimed that they never or rarely receive any communication related to cyber safety from the students' educational institutions. Additionally, our analysis shows that the student support structure needs to be trained and informed on the threats faced by children online and on the ways to mitigate these threats. Finally, we find a statistically significant difference between parents, educators, and other caregivers regarding their perceptions of children's online privacy and cyber safety. We conclude this work by providing actionable recommendations to promote privacy-preserving and digitally secure online education.
Faiza Tazi, Sunny Shrestha, Sanchari Das 0001
Proc. ACM Hum. Comput. Interact.3
2023 Evolution of Composition, Readability, and Structure of Privacy Policies over Two Decades
abstract
Privacy policies outline data collection and sharing practices followed by an organization, together with choice and control measures available to users to manage the process. However, users have often needed help reading and understanding such documents, regardless of their being written in a natural language. The fundamental problems with privacy policies persist despite advancements in privacy design, frameworks, and regulations. To identify the causes of privacy policies being persistently challenging to comprehend, it is vital to investigate historical policy patterns and understand the evolution of privacy policies concerning information packaging and presentation. To this aid, we create a sentence-level classifier to conduct a large-scale longitudinal analysis on different privacy policies from 130,604 organizations, totaling approximately one million policies from 1997 to 2019. We annotate 10,717 sentences from 115 policies in the OPP-115 corpus to implement the classifier and then use those annotations to train the XLNet and BERT classifiers. Results from our analysis reveal that specific data practice categories experience more frequent policy changes than others, making it challenging to track relevant information over time. In addition, we discover that every category has distinct composition, readability, and structural issues, which exacerbate when categories frequently co-occur in a document. Based on our observations, we provide recommendations for policy articulation and revision to make privacy policy documents conform to better coherence and structure.
Andrick Adhikari, Sanchari Das 0001, Rinku Dewri
Proc. Priv. Enhancing Technol.2
2022 SoK: A Systematic Literature Review of Knowledge-Based Authentication on Augmented Reality Head-Mounted Displays
abstract
The adoption of Augmented Reality (AR) technology has increased over the years. AR enhances various activities for consumers and businesses, particularly in industrial contexts. The three-dimensional virtual experience is realized by the usage of Head-Mounted Displays (HMD). These devices provide access to sensitive data and services. Thus, secure and usable authentication schemes are essential to control access to the HMD and the stored data as well as schemes to authenticate to the services one wants to use with the AR device. We conducted a systematic literature review on knowledge-based authentication schemes for AR HMD. 31 different schemes were identified. These schemes were assessed regarding various aspects including the type of AR HMD, the type of secret, how users input their secret, as well as usability and security aspects. We discuss gaps for future work.
Reyhan Duezguen, Naheem Noah, Peter Mayer 0001, Sanchari Das 0001, Melanie Volkamer
ARES4
2022 On the Data Privacy, Security, and Risk Postures of IoT Mobile Companion Apps
Shradha Neupane, Faiza Tazi, Upakar Paudel, Freddy Veloz Baez, Merzia Adamjee, Lorenzo De Carli, Sanchari Das 0001, Indrakshi Ray
DBSec7
2022 Privacy Policy Analysis with Sentence Classification
abstract
Privacy policies inform users of the data practices and access protocols employed by organizations and their digital counterparts. Research has shown that users often feel that these privacy policies are lengthy and complex to read and comprehend. However, it is critical for people to be aware of the data access practices employed by the organizations. Hence, much research has focused on automatically extracting privacy-specific artifacts from the policies, predominantly by using natural language classification tools. However, these classification tools are designed primarily for the classification of paragraphs or segments of the policies. In this paper, we report on our research where we identify the gap in classifying policies at a segment level, and provide an alternate definition of segment classification using sentence classification. To this aid, we train and evaluate sentence classifiers for privacy policies using BERT and XLNet. Our approach demonstrates improvements in prediction quality of existing models and hence, surpasses the current baselines for classification models, without requiring additional parameter and model tuning. Using our sentence classifiers, we also study topical structures in Alexa top 5000 website policies, in order to identify and quantify the diffusion of information pertaining to privacy-specific topics in a policy.
Andrick Adhikari, Sanchari Das 0001, Rinku Dewri
PST2
2022 Evaluating user susceptibility to phishing attacks
abstract
Purpose Phishing is a well-known cybersecurity attack that has rapidly increased in recent years. It poses risks to businesses, government agencies and all users due to sensitive data breaches and subsequent financial losses. To study the user side, this paper aims to conduct a literature review and user study. Design/methodology/approach To investigate phishing attacks, the authors provide a detailed overview of previous research on phishing techniques by conducting a systematic literature review of n = 367 peer-reviewed academic papers published in ACM Digital Library. Also, the authors report on an evaluation of a high school community. The authors engaged 57 high school students and faculty members (12 high school students, 45 staff members) as participants in research using signal detection theory (SDT). Findings Through the literature review which goes back to as early as 2004, the authors found that only 13.9% of papers focused on user studies. In the user study, through scenario-based analysis, participants were tasked with distinguishing phishing e-mails from authentic e-mails. The results revealed an overconfidence bias in self-detection from the participants, regardless of their technical background. Originality/value The authors conducted a literature review with a focus on user study which is a first in this field as far the authors know. Additionally, the authors conducted a detailed user study with high school students and faculty using SDT which is also an understudied area and population.
Sanchari Das 0001, Christena Nippert-Eng, L. Jean Camp
Inf. Comput. Secur.1
2021 Bayesian evaluation of privacy-preserving risk communication for user android app preferences
abstract
Purpose The purpose of this paper is to propose practical and usable interactions that will allow more informed, risk-aware comparisons for individuals during app selections. The authors include an explicit argument for the role of human decision-making during app selection and close with a discussion of the strengths of a Bayesian approach to evaluating privacy and security interventions. Design/methodology/approach The authors focused on the risk communication in mobile marketplace’s realm, examining how risk indicators can help people choose more secure and privacy-preserving apps. Combining canonical findings in risk perception with previous work in usable security, the authors designed indicators for each app to enable decisions that prioritize risk avoidance. Specifically, the authors performed a natural experiment with N = 60 participants, where they asked them to select applications on Android tablets with accurate real-time marketplace data. Findings In the aggregate, the authors found that app selections changed to be more risk-averse in the presence of a user-centered multi-level warning system using visual indicators that enabled a click-thru to the more detailed risk and permissions information. Originality/value Privacy research in the laboratory is often in conflict with privacy decision-making in the marketplace, resulting in a privacy paradox. To better understand this, the authors implemented a research design based on clinical experimental approaches, testing the interaction in a noisy, confounded field environment.
Behnood Momenzadeh, Shakthidhar Gopavaram, Sanchari Das 0001, L. Jean Camp
Inf. Comput. Secur.3
2021 Exploring evolution of augmented and virtual reality education space in 2020 through systematic literature review
abstract
Abstract Research is increasingly being conducted to identify the benefits provided by the latest developments in the AR/VR domain, which has seen an increase in interest as a result of the stay‐at‐home phenomena in 2020. Of particular interest is the application of AR/VR to education, a discipline that has seen a rapid shift to online modules in 2020. To better understand the advancements in AR/VR enabled education, we conducted a systematic literature review consisting of papers published in the year 2020 that focused on AR/VR in the education sector. We particularly focused on papers where studies have evaluated user perceptions in different countries, academic fields, and at varied educational levels. We found that while most papers conducted user studies and evaluated the technical applications of AR/VR, user perceptions, impact, and awareness were not explored in detail. Our findings highlight trends that can drive critically needed innovations through AR/VR especially to help a globalized digital evolution in the education sector.
Naheem Noah, Sanchari Das 0001
Comput. Animat. Virtual Worlds2
2021 Does This Photo Make Me Look Good?: How Social Media Feedback on Photos Impacts Posters, Outsiders, and Friends
abstract
In recent years, the use and importance of visual communication through photos have grown considerably. However, we have little understanding of the alignment between the intentions of the photo posters and the reactions of viewers. To address this gap, we replicated previous work that studied the alignment of poster and outsider judgments of text posts by extending it to photo posts. In our study of 573 users across four social media platforms, we found that outsiders generally judge photo posts more positively than anticipated by posters. Examining viewer engagement on social media revealed that photos depicting family and friends receive fewer reactions. We apply our insight to propose novel solutions that can help users create a more positive digital presence by aligning their photo posts with the expectations of their audiences.
Sanchari Das 0001, Tousif Ahmed, Apu Kapadia, Sameer Patil 0001
Proc. ACM Hum. Comput. Interact.1
2020 Substituting Restorative Benefits of Being Outdoors through Interactive Augmented Spatial Soundscapes
abstract
Geriatric depression is a common mental health condition affecting majority of older adults in the US. As per Attention Restoration Theory (ART), participation in outdoor activities is known to reduce depression and provide restorative benefits. However, many older adults, who suffer from depression, especially those who receive care in organizational settings, have less access to sensory experiences of the outdoor natural environment. This is often due to their physical or cognitive limitations and from lack of organizational resources to support outdoor activities. To address this, we plan to study how technology can bring the restorative benefits of outdoors to the indoor environments through augmented spatial natural soundscapes. Thus, we propose an interview and observation-based study at an assisted living facility to evaluate how augmented soundscapes substitute for outdoor restorative, social, and experiential benefits. We aim to integrate these findings into a minimally intrusive and intuitive design of an interactive augmented soundscape, for indoor organizational care settings.
Swapna Joshi, Kostas Stavrianakis, Sanchari Das 0001
ASSETS3
2019 Techies Against Facebook: Understanding Negative Sentiment Toward Facebook via User Generated Content
abstract
Researchers have recognized the need to pay attention to negative aspects and non-use of social media services to uncover usage barriers and surface shortcomings of these systems. We contribute to these efforts by analyzing comments on posts related to Facebook on two blogs with a technically savvy readership: Slashdot and Schneier on Security. Our analysis indicates that technically savvy individuals exhibit notably large negative sentiment toward Facebook with nearly 45% of the 3,000 reader comments we coded expressing such views. Qualitative coding revealed Privacy and Security, User Experience, and Personal Disposition as key factors underlying the negative views. Our findings suggest that negative sentiment is an explicit higher level factor driving non-use practices. Further, we confirm several non-use practices reported in the literature and identify additional aspects connected to recent technological and societal developments. Our results demonstrate that analysis of user generated content can be useful for surfacing usage practices on a large scale.
Abu Saleh Md Noman, Sanchari Das 0001, Sameer Patil 0001
CHI2