Christena Nippert-Eng

dblp:224/9225 · DBLP profile ↗
← Back
7ranked-venue papers
0as first author
6since 2021 · last 2024
0000-0002-1212-3628ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 6 · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Snitches Get Unplugged: Adolescents' Privacy Concerns about Robots in the Home are Relationally Situated
abstract
Though teens are a population with growing agency and use of smart technologies, their concerns surrounding privacy with AI and robots are under-represented in research. Using focus group discussions and a mixed methods analysis, we present teens' comfort levels with robotic information collection and sharing during three hypothetical scenarios involving a child interacting with the Haru social robot in the home. We find participant concerns align with an access-based definition of privacy which prioritizes being in control of their information and of when the robot behaves autonomously. Responses also indicate that teens conceptualize Haru not just as an intelligent device, but also as a social entity. Their shifts in comfort and discussions reflect an engagement in social relationship management with robots in the home in cases where the robot mediates a user's responsibilities and relationships with others.
Leigh Levinson, Christena Nippert-Eng, Randy Gomez, Selma Sabanovic
HRI2
2024 Enhancing Epilepsy Awareness and Cooperative Care in Elementary and Middle Schools
abstract
Epilepsy, a prevalent chronic neurological disorder, presents numerous challenges for people with epilepsy (PWEs) and their caregivers. They experience difficulties in receiving proper care and support due to stigma and misconceptions. Promoting public awareness in early education would be critical to reduce the stigma and to properly support them. We conducted 145 surveys and 21 interviews with teachers, school nurses, and parents of elementary and middle school students. While the participants exhibited slightly positive attitudes towards PWEs, we identified obstacles that hinder learning about epilepsy and seizure first aid: inadequate education and limited information sharing among school stakeholders. Moreover, there is a pressing need for age-appropriate education that considers the students' ages and perceptual levels. Considering the current limitations and needs, we propose potential implications for future information and communication technologies (ICTs) designs, including knowledge-sharing systems and an educational game aimed at enhancing epilepsy awareness and fostering collaborative care in elementary and middle school environments.
Aehong Min, Wendy Miller, Kay Connelly, Christena Nippert-Eng, Hsien-Chang Lin, Patrick C. Shih
Proc. ACM Hum. Comput. Interact.4
2023 Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
abstract
Preventing workplace phishing depends on the actions of every employee, regardless of cybersecurity expertise. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old) at two U.S. universities, we found that less than 21% of our participants had any formal anti-phishing training. Much of what our participants know about phishing comes from informal sources that emphasize “tips” and "tricks" like those found in conversations with friends, news stories, newsletters, social media, and podcasts. These informal channels provide opportunities for IT professionals wishing to enhance employees’ anti-phishing awareness by better aligning the delivery of expert advice with employees’ current practices and desires. We provide four recommendations designed to embrace "guerrilla learning" by distributing anti-phishing educational resources across the workplace and workday in part to encourage the delivery of more accurate information in more informal and incidental ways, and greater dialogue between anti-phishing training instructors and learners.
Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng
CHI5
2023 What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing Decisions
abstract
Phishing attacks, in which deceptive messages purporting to be from a legitimate contact are used to trick recipients and acquire sensitive information for the purposes of committing fraud, are a substantial and growing problem for organizations. IT departments and professionals may put in place a variety of institutional responses to thwart such attacks, but an organization's susceptibility to phishing also depends on the decisions and actions of individual employees. These employees may have little phishing expertise but still need to react to such attempts on a daily basis. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old, with a bachelor's degree or more) at two universities in the midwestern United States, we find that employees self-describe a wide range of levels of awareness of, and confidence, competency and investment in, the organization's proscribed anti-phishing policies and practices. These employees also describe variation in the ways they would prefer to increase their perceived performance levels in all of these areas. In this paper, we argue that in order to empower employees to be better collaborators in an organization's anti-phishing efforts, organizations should embrace a range of efforts akin to the range of expertise among the users themselves. We make four such empowering recommendations for organizations to consider incorporating into their existing anti-phishing policies and practices, including suggestions to 1) embrace educating non-expert users more fully on organizational processes and consequences, 2) provide employees with a standing one-to-one communication channel between them and an IT phishing point-of-contact, 3) keep employees in the loop once phishing reports are made, and 4) avoid testing employees with "gotcha" assessments.
Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng
Proc. ACM Hum. Comput. Interact.5
2022 Evaluating user susceptibility to phishing attacks
abstract
Purpose Phishing is a well-known cybersecurity attack that has rapidly increased in recent years. It poses risks to businesses, government agencies and all users due to sensitive data breaches and subsequent financial losses. To study the user side, this paper aims to conduct a literature review and user study. Design/methodology/approach To investigate phishing attacks, the authors provide a detailed overview of previous research on phishing techniques by conducting a systematic literature review of n = 367 peer-reviewed academic papers published in ACM Digital Library. Also, the authors report on an evaluation of a high school community. The authors engaged 57 high school students and faculty members (12 high school students, 45 staff members) as participants in research using signal detection theory (SDT). Findings Through the literature review which goes back to as early as 2004, the authors found that only 13.9% of papers focused on user studies. In the user study, through scenario-based analysis, participants were tasked with distinguishing phishing e-mails from authentic e-mails. The results revealed an overconfidence bias in self-detection from the participants, regardless of their technical background. Originality/value The authors conducted a literature review with a focus on user study which is a first in this field as far the authors know. Additionally, the authors conducted a detailed user study with high school students and faculty using SDT which is also an understudied area and population.
Sanchari Das 0001, Christena Nippert-Eng, L. Jean Camp
Inf. Comput. Secur.2
2021 Protect and Project: Names, Privacy, and the Boundary Negotiations of Online Video Game Players
abstract
Video game players face a fundamental challenge in managing their competing desires for both privacy and publicity, for being both apart from, and a part of, the communities in which they play. In this paper, we argue that "gamertags" are important tools for protecting gamers' privacy as well as creative outlets for expressing meaningful aspects of identity. Based on 30 semi-structured interviews focused on players' usernames, we find through the pseudonyms under which they play, gamers both hide identifying information such as their offline names and addresses while bringing attention to information that is deeply meaningful to them, such as their family nickname or favorite music. By deemphasizing some parts of their identity and by emphasizing others, players not only shape how they are perceived by other gamers, but they also attempt to preclude accidental disclosure of more identifying information. We argue that gamertag practices thus constitute an important form of boundary work through which gamers actively seek to draw lines between their offline and multiple online worlds in the ways that they wish. We argue that gamers use these names to both protect and project aspects of their identities--at times even seeking protection through projection--as a way of addressing their competing desires to both conceal and reveal different aspects of their identities. As boundary work, players' efforts to carefully protect personally-identifying information and intentionally project personally meaningful information to their communities help them better manage their online identities, relationships with others, and overall data privacy.
Anne Clara Tally, Yu Ra Kim, Katreen Boustani, Christena Nippert-Eng
Proc. ACM Hum. Comput. Interact.4
2020 "It's easier than causing confrontation": Sanctioning Strategies to Maintain Social Norms and Privacy on Social Media
abstract
Sanctions play an essential role in enforcing and sustaining social norms. On social networking sites (SNS), sanctions allow individuals to shape community norms on appropriate privacy respecting behaviors. Existing theories of privacy assume the use of such sanctions but do not examine the extent and effectiveness of sanctioning behaviors. We conducted a qualitative interview study of young adults (N=23), and extend research on collective boundary regulation by studying sanctions in the context of popular SNS. Through a systematization of sanctioning strategies, we find that young adults prefer to use indirect and invisible sanctions to preserve strong-tie relationships. Such sanctions are not always effective in helping the violator understand the nature of their normative violation. We offer suggestions on supporting online sanctioning that make norms more visible and signal violations in ways that avoid direct confrontation to reduce the risk of harming on-going social relationships.
Yasmeen Rashidi, Apu Kapadia, Christena Nippert-Eng, Norman Makoto Su
Proc. ACM Hum. Comput. Interact.3