Franziska Roesner

dblp:23/2758 · DBLP profile ↗
← Back
73ranked-venue papers
6as first author
39since 2021 · last 2026
0000-0001-8735-4810ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 3 first-author · 14 since 2021Human-computer interaction and ubiquitous computing · 26 · 1 first-author · 20 since 2021Computer networks · 6 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Toys that listen, talk, and play: Understanding Children's Sensemaking and Interactions with AI Toys
abstract
Generative AI (genAI) is increasingly being integrated into children’s everyday lives, not only through screens but also through so-called “screen-free” AI toys. These toys can simulate emotions, personalize responses, and recall prior interactions, creating the illusion of an ongoing social connection. Such capabilities raise important questions about how children understand boundaries, agency, and relationships when interacting with AI toys. To investigate this, we conducted two participatory design sessions with eight children ages 6 - 11 where they engaged with three different AI toys, shifting between play, experimentation, and reflection. Our findings reveal that children approached AI toys with genuine curiosity, profiling them as social beings. However, frequent interaction breakdowns and mismatches between apparent intelligence and toy-like form disrupted expectations around play and led to adversarial play. We conclude with implications and design provocations to navigate children’s encounters with AI toys in more transparent, developmentally appropriate, and responsible ways.
Aayushi Dangol, Meghna Gupta, Daeun Yoo, Robert Wolfe, Jason C. Yip 0001, Franziska Roesner, Julie A. Kientz
IDC6
2026 Exploring AI Companions Together: A Structured Family Co-Investigation of Character.AI
abstract
Teens today are increasingly drawn to emotionally responsive AI systems, often called AI companions. As these technologies grow in popularity, families face new questions about mediating teens’ interactions with them. Traditional mediation strategies, such as monitoring or restriction, often fall short when interactions are private, emotionally persuasive, and relational. In this study, we examine how families, parents and teens, can jointly explore, interpret, and negotiate the use of AI companions together. We conducted a four-week study with 11 families with teens aged 13–15, centered on Character.AI and structured around activities that progressed from joint exploration to teen independent use. Our findings show that co-exploration fostered family connection, supported joint calibration of AI behaviors and limits, gave parents real-time insight into teens’ decision-making, and prompted families to reassess their assumptions about AI companions. We conclude with implications and recommendations for designing parental-mediation tools that help scaffold healthy teen-AI companion use.
Meghna Gupta, Mitsuka Kiyohara, Ranjitha Naruganahalli Rangaswamy, Franziska Roesner, Julie A. Kientz
IDC4
2026 Consent under Constraints: Negotiating Photography and Media Sharing in Institutionalized Childcare
abstract
Taking and sharing photos is a routine practice in childcare institutions, used to document children’s learning, communicate with families, and support marketing. These practices are typically regulated through consent forms, the institutional mechanism for authorizing photography and media use. While prior research has examined parents’ photo-taking and sharing, little is known about consent in institutional childcare, where formal policies and non-parental figures (e.g., staff and administrators) shape children’s privacy in distinct ways. To investigate this, we analyzed 42 consent forms and conducted 21 semi-structured interviews with parents, educators, and administrators in U.S.-based childcare institutions. Our findings reveal that consent forms serve as procedural, one-time agreements rather than meaningful safeguards. Parents navigate consent pragmatically amidst structural precarity and power asymmetries, while staff performs the unseen labor of consent enforcement. We conclude with implications for reimagining consent and designing usable institutional mechanisms that support children’s privacy and safety in practice.
Meghna Gupta, Sophie Stephenson, Franziska Roesner, Julie A. Kientz
CHI4
2026 Experiences with Digital Scams Post-Incarceration in the U.S
Yael Eiger, Candice Baughman, Rory Andes, Bryan Glant, Franziska Roesner
SOUPS5
2026 "They are not my children to post": Examining Non-Parental Sharenting Practices in In-home Childcare
Meghna Gupta, Sophie Stephenson, Apu Kapadia, Julie A. Kientz, Franziska Roesner
SOUPS5
2026 Towards Automating Data Access Permissions in AI Agents
abstract
As AI agents attempt to autonomously act on users' behalf, they raise transparency and control issues. We argue that permission-based access control is indispensable in providing meaningful control to the users, but conventional permission models are inadequate for the automated agentic execution paradigm. We therefore propose automated permission management for AI agents. Our key idea is to conduct a user study to identify the factors influencing users' permission decisions and to encode these factors into an ML-based permission management assistant capable of predicting users' future decisions. We find that participants' permission decisions are influenced by communication context but importantly individual preferences tend to remain consistent within contexts, and align with those of other participants. Leveraging these insights, we develop a permission prediction model achieving 85.1% accuracy overall and 94.4% for high-confidence predictions. We find that even without using permission history, our model achieves an accuracy of 66.9%, and a slight increase of training samples (i.e., 1-4) can substantially increase the accuracy by 10.8%.
Yuhao Wu 0006, Franziska Roesner, Tadayoshi Kohno, Ning Zhang 0017, Umar Iqbal 0002
SP3
2025 "We're utterly ill-prepared to deal with something like this": Teachers' Perspectives on Student Generation of Synthetic Nonconsensual Explicit Imagery
Miranda Wei, Christina Yeung, Franziska Roesner, Tadayoshi Kohno
CHI3
2025 IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
Yuhao Wu 0006, Franziska Roesner, Tadayoshi Kohno, Ning Zhang 0017, Umar Iqbal 0002
NDSS2
2025 "You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp Mods
abstract
WhatsApp is the most popular social messaging platform, and modified versions (or “mods”) of the official WhatsApp are increasingly popular. Mods advertise additional features and customization. However, some of these features, e.g., retaining deleted messages and statuses, enable mod users to subvert the privacy of others, and have the potential for seri-ous security and privacy implications. In this study, we explore user perspectives of WhatsApp mods through an interview study$(n=20)$of mod users in Kenya, one of the countries with the highest WhatsApp mod usage. Many turned to WhatsApp mods for their “advanced” features to protect themselves (e.g., “anti-delete” for legal liability), while others admitted to using mod features to hide their behavior or to stalk others. To understand how users' expectations of WhatsApp mods align with the apps' behavior, we identify and analyze 13 instances of the most common mod (GB WhatsApp). While WhatsApp mods contained the features they claimed to offer, some participants incorrectly believed that features currently available in the official app only existed in mods. Additionally, several mods were significantly over-permissioned compared to the official WhatsApp, despite participants believing that they requested the same permissions as the official app. While almost half of participants indicated they trust mods more than the official WhatsApp, we found two mods contained malware. The use of WhatsApp mods poses risks to mod users and those they communicate with, but also empowers users in ways that the official app does not. We caution developers and mod users to do their due diligence before using or distributing mods.
Collins W. Munyendo, Kentrell Owens, Faith Strong, Adam J. Aviv, Tadayoshi Kohno, Franziska Roesner
SP7
2025 The Collaborative Practices and Motivations of Online Communities Dedicated to Voluntary Misinformation Response
abstract
Responding to misinformation online can be an exhausting and thankless task. It takes time and energy to write effective content, puts users at risk of online harassment, and strains personal relationships. Despite these challenges, there are people who voluntarily respond to misinformation online, and some have established communities on platforms such as Reddit, Discord, and X (formerly Twitter) dedicated to these efforts. In this work, we interviewed 8 people who participate in such communities to understand the type of support they receive from each other in these discussion spaces. Interviewees described that their communities helped them sustain motivation, save time, and improve their communication skills. Common practices included sharing sources and citations, providing emotional support, giving others advice, and signaling positive feedback. We present our findings as three case studies and discuss opportunities for future work to support collaborative practices in online communities dedicated to misinformation response. Our work surfaces how resource sharing, social motivation, and decentralization can make misinformation correction more sustainable, rewarding, and effective for online citizens.
Jina Yoon, Shreya Sathyanarayanan, Franziska Roesner, Amy X. Zhang
Proc. ACM Hum. Comput. Interact.3
2025 To Reveal or Conceal: Privacy and Marginalization in Avatars
abstract
The present and future transition of lives and activities into virtual worlds --- worlds in which people interact using avatars --- creates novel privacy challenges and opportunities. Avatars present an opportunity for people to control the way they are represented to other users and the information shared or implied by that representation. Importantly, users with marginalized identities may have a unique set of concerns when choosing what information about themselves (and their identities) to conceal or expose in an avatar. We present a theoretical basis, supported by two empirical studies, to understand how marginalization impacts the ways in which people create avatars and perceive others' avatars: what information do people choose to reveal or conceal, and how do others react to these choices? In Study 1, participants from historically marginalized backgrounds felt more concerned about being devalued based on their identities in virtual worlds, which related to a lower desire to reveal their identities in an avatar, compared to non-marginalized participants. However, in Study 2 participants were often uncomfortable with others changing visible characteristics in an avatar, weighing concerns about others' anonymity with possible threats to their own safety and security online. Our findings demonstrate asymmetries in what information people prefer the self vs. others to reveal in their online representations: participants want privacy for themselves but to feel informed about others. Although avatars allow people to choose what information to reveal about themselves, people from marginalized backgrounds may still face backlash for concealing components of their identities to avoid harm.
Mattea Sim, Basia Radka, Emi Yoshikawa, Franziska Roesner, Kurt Hugenberg, Tadayoshi Kohno
Proc. Priv. Enhancing Technol.4
2024 LLM Platform Security: Applying a Systematic Evaluation Framework to OpenAI's ChatGPT Plugins
abstract
Large language model (LLM) platforms, such as ChatGPT, have recently begun offering an app ecosystem to interface with third-party services on the internet. While these apps extend the capabilities of LLM platforms, they are developed by arbitrary third parties and thus cannot be implicitly trusted. Apps also interface with LLM platforms and users using natural language, which can have imprecise interpretations. In this paper, we propose a framework that lays a foundation for LLM platform designers to analyze and improve the security, privacy, and safety of current and future third-party integrated LLM platforms. Our framework is a formulation of an attack taxonomy that is developed by iteratively exploring how LLM platform stakeholders could leverage their capabilities and responsibilities to mount attacks against each other. As part of our iterative process, we apply our framework in the context of OpenAI's plugin (apps) ecosystem. We uncover plugins that concretely demonstrate the potential for the types of issues that we outline in our attack taxonomy. We conclude by discussing novel challenges and by providing recommendations to improve the security, privacy, and safety of present and future LLM-based computing platforms. The full version of this paper is available online at https://arxiv.org/abs/2309.10254
Umar Iqbal 0002, Tadayoshi Kohno, Franziska Roesner
AIES (1)3
2024 Face the Facts: Using Face Averaging to Visualize Gender-by-Race Bias in Facial Analysis Algorithms
abstract
We applied techniques from psychology --- typically used to visualize human bias --- to facial analysis systems, providing novel approaches for diagnosing and communicating algorithmic bias. First, we aggregated a diverse corpus of human facial images (N=1492) with self-identified gender and race. We tested four automated gender recognition (AGR) systems and found that some exhibited intersectional gender-by-race biases. Employing a technique developed by psychologists --- face averaging --- we created composite images to visualize these systems' outputs. For example, we visualized what an "average woman" looks like, according to a system's output. Second, we conducted two online experiments wherein participants judged the bias of hypothetical AGR systems. The first experiment involved participants (N=228) from a convenience sample. When depicting the same results in different formats, facial visualizations communicated bias to the same magnitude as statistics. In the second experiment with only Black participants (N=223), facial visualizations communicated bias significantly more than statistics, suggesting that face averages are meaningful for communicating algorithmic bias.
Kentrell Owens, Erin Freiburger, Ryan Hutchings, Mattea Sim, Kurt Hugenberg, Franziska Roesner, Tadayoshi Kohno
AIES (1)6
2024 "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection Purposes
abstract
Data collection purposes and their descriptions are presented on almost all privacy notices under the GDPR, yet there is a lack of research focusing on how effective they are at informing users about data practices. We fill this gap by investigating users’ perceptions of data collection purposes and their descriptions, a crucial aspect of informed consent. We conducted 23 semi-structured interviews with European users to investigate user perceptions of six common purposes (Strictly Necessary, Statistics and Analytics, Performance and Functionality, Marketing and Advertising, Personalized Advertising, and Personalized Content) and identified elements of an effective purpose name and description.
Lin Kyi, Abraham H. Mhaidli, Cristiana Teixeira Santos, Franziska Roesner, Asia J. Biega
CHI4
2024 Sharenting on TikTok: Exploring Parental Sharing Behaviors and the Discourse Around Children's Online Privacy
abstract
Since the inception of social media, parents have been sharing information about their children online. Unfortunately, this “sharenting” can expose children to several online and offline risks. Although researchers have studied sharenting on multiple platforms, sharenting on short-form video platforms like TikTok—where posts can contain detailed information, spread quickly, and spark considerable engagement—is understudied. Thus, we provide a targeted exploration of sharenting on TikTok. We analyzed 328 TikTok videos that demonstrate sharenting and 438 videos where TikTok creators discuss sharenting norms. Our results indicate that sharenting on TikTok indeed creates several risks for children, not only within individual posts but also in broader patterns of sharenting that arise when parents repeatedly use children to generate viral content. At the same time, creators voiced sharenting concerns and boundaries that reflect what has been observed on other platforms, indicating the presence of cross-platform norms. Promisingly, we observed that TikTok users are engaging in thoughtful conversations around sharenting and beginning to shift norms toward safer sharenting. We offer concrete suggestions for designers and platforms based on our findings.
Sophie Stephenson, Christopher Nathaniel Page, Miranda Wei, Apu Kapadia, Franziska Roesner
CHI5
2024 Analyzing User Engagement with TikTok's Short Format Video Recommendations using Data Donations
abstract
Short-format videos have exploded on platforms like TikTok, Instagram, and YouTube. Despite this, the research community lacks large-scale empirical studies into how people engage with short-format videos and the role of recommendation systems that offer endless streams of such content. In this work, we analyze user engagement on TikTok using data we collect via a data donation system that allows TikTok users to donate their data. We recruited 347 TikTok users and collected 9.2M TikTok video recommendations they received. By analyzing user engagement, we find that the average daily usage time increases over the users’ lifetime while the user attention remains stable at around 45%. We also find that users like more videos uploaded by people they follow than those recommended by people they do not follow. Our study offers valuable insights into how users engage with short-format videos on TikTok and lessons learned from designing a data donation system.
Savvas Zannettou, Olivia Nemes Nemeth, Oshrat Ayalon, Angelica Goetzen, Krishna P. Gummadi, Elissa M. Redmiles, Franziska Roesner
CHI7
2024 Analyzing the (In)Accessibility of Online Advertisements
abstract
Ads are often designed visually, with images and videos conveying information. In this work, we study the accessibility of ads on the web to users of screen readers. We approach this in two ways: first, we conducted a measurement and analysis of 90 websites over a month, collecting ads and auditing their behavior against a subset of best practices established by the Web Content Accessibility Guidelines (WCAG). Then, to put our measurement findings in context, we interviewed 13 blind participants who navigate the web with a screen reader to understand their experiences with (in)accessible ads. We find that the overall web ad ecosystem is fairly inaccessible in multiple ways: many images are missing alt-text, unlabeled links make it confusing for folks to navigate, and closing ads can be tricky. But, there are straightforward ways to improve: because only a few large companies dominate the ad ecosystem, making small changes to the way they enforce accessibility standards can make a large difference.
Christina Yeung, Tadayoshi Kohno, Franziska Roesner
IMC3
2024 When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented Reality
Kaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 0005, Aroosh Kumar, Jeffery F. Tian, Tadayoshi Kohno, Franziska Roesner
USENIX Security Symposium8
2024 Understanding Help-Seeking and Help-Giving on Social Media for Image-Based Sexual Abuse
Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Tara Matthews, Sarah Meiklejohn, Franziska Roesner, Renee Shelby, Kurt Thomas, Rebecca Umbach
USENIX Security Symposium7
2024 SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security Behaviors
Miranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno, Elissa M. Redmiles, Franziska Roesner
USENIX Security Symposium6
2024 TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds
abstract
Recommendation algorithms for social media feeds often function as black boxes from the perspective of users. We aim to detect whether social media feed recommendations are personalized to users, and to characterize the factors contributing to personalization in these feeds. We introduce a general framework to examine a set of social media feed recommendations for a user as a timeline. We label items in the timeline as the result of exploration vs. exploitation of the user's interests on the part of the recommendation algorithm and introduce a set of metrics to capture the extent of personalization across user timelines. We apply our framework to a real TikTok dataset and validate our results using a baseline generated from automated TikTok bots, as well as a randomized baseline. We also investigate the extent to which factors such as video viewing duration, liking, and following drive the personalization of content on TikTok. Our results demonstrate that our framework produces intuitive and explainable results, and can be used to audit and understand personalization in social media feeds.
Karan Vombatkere, Sepehr Mousavi, Savvas Zannettou, Franziska Roesner, Krishna P. Gummadi
WWW4
2023 Investigating Deceptive Design in GDPR's Legitimate Interest
abstract
Legitimate interest is one of the six grounds for processing data under the European Union’s General Data Protection Regulation (GDPR). The flexibility and ambiguity of the term "legitimate interests" can be problematic; coupled with the lack of enforcement from legal authorities and different interpretations from the various data protection authorities, legitimate interests can be taken advantage of as a loophole to collect more user data.
Lin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner, Frederike Zufall, Asia J. Biega
CHI4
2023 Understanding People's Concerns and Attitudes Toward Smart Cities
abstract
Designing privacy-respecting and human-centric smart cities requires a careful investigation of people’s attitudes and concerns toward city-wide data collection scenarios. To capture a holistic view, we carried out this investigation in two phases. We first surfaced people’s understanding, concerns, and expectations toward smart city scenarios by conducting 21 semi-structured interviews with people in underserved communities. We complemented this in-depth qualitative study with a 348-participant online survey of the general population to quantify the significance of smart city factors (e.g., type of collected data) on attitudes and concerns. Depending on demographics, privacy and ethics were the two most common types of concerns among participants. We found the type of collected data to have the most and the retention time to have the least impact on participants’ perceptions and concerns about smart cities. We highlight key takeaways and recommendations for city stakeholders to consider when designing inclusive and protective smart cities.
Pardis Emami Naeini, Joseph Breda, Wei Dai 0007, Tadayoshi Kohno, Kim Laine, Shwetak N. Patel, Franziska Roesner
CHI7
2023 Eliciting Security & Privacy-Informed Sharing Techniques for Multi-User Augmented Reality
abstract
The HCI community has explored new interaction designs for collaborative AR interfaces in terms of usability and feasibility; however, security & privacy (S&P) are often not considered in the design process and left to S&P professionals. To produce interaction proposals with S&P in mind, we extend the user-driven elicitation method with a scenario-based approach that incorporates a threat model involving access control in multi-user AR. We conducted an elicitation study in two conditions, pairing AR/AR experts in one condition and AR/S&P experts in the other, to investigate the impact of each pairing. We contribute a set of expert-elicited interactions for sharing AR content enhanced with access control provisions, analyze the benefits and tradeoffs of pairing AR and S&P experts, and present recommendations for designing future multi-user AR interactions that better balance competing design goals of usability, feasibility, and S&P in collaborative AR.
Shwetha Rajaram, Chen Chen 0108, Franziska Roesner, Michael Nebeling
CHI3
2023 How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
abstract
Strong end-user security practices benefit both the user and hosting platform, but it is not well understood how companies communicate with their users to encourage these practices. This paper explores whether web companies and their platforms use different levels of language formality in these communications and tests the hypothesis that higher language formality leads to users’ increased intention to comply. We contribute a dataset and systematic analysis of 1,817 English language strings in web security and privacy interfaces across 13 web platforms, showing strong variations in language. An online study with 512 participants further demonstrated that people perceive differences in the language formality across platforms and that a higher language formality is associated with higher self-reported intention to comply. Our findings suggest that formality can be an important factor in designing effective security and privacy prompts. We discuss implications of these results, including how to balance formality with platform language style. In addition to being the first piece of work to analyze language formality in user security, these findings provide valuable insights into how platforms can best communicate with users about account security.
Jackson Stokes, Tal August, Robert A Marver, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno, Katharina Reinecke
CHI5
2023 "There's so much responsibility on users right now: " Expert Advice for Staying Safer From Hate and Harassment
abstract
Online hate and harassment poses a threat to the digital safety of people globally. In light of this risk, there is a need to equip as many people as possible with advice to stay safer online. We interviewed 24 experts to understand what threats and advice internet users should prioritize to prevent or mitigate harm. As part of this, we asked experts to evaluate 45 pieces of existing hate-and-harassment-specific digital-safety advice to understand why they felt advice was viable or not. We find that experts frequently had competing perspectives for which threats and advice they would prioritize. We synthesize sources of disagreement, while also highlighting the primary threats and advice where experts concurred. Our results inform immediate efforts to protect users from online hate and harassment, as well as more expansive socio-technical efforts to establish enduring safety.
Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Franziska Roesner, Kurt Thomas
CHI5
2023 Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem
abstract
Smart speakers collect voice commands, which can be used to infer sensitive information about users. Given the potential for privacy harms, there is a need for greater transparency and control over the data collected, used, and shared by smart speaker platforms as well as third party skills supported on them. To bridge this gap, we build a framework to measure data collection, usage, and sharing by the smart speaker platforms. We apply our framework to the Amazon smart speaker ecosystem. Our results show that Amazon and third parties, including advertising and tracking services that are unique to the smart speaker ecosystem, collect smart speaker interaction data. We also find that Amazon processes smart speaker interaction data to infer user interests and uses those inferences to serve targeted ads to users. Smart speaker interaction also leads to ad targeting and as much as 30X higher bids in ad auctions, from third party advertisers. Finally, we find that Amazon's and third party skills' data practices are often not clearly disclosed in their policy documents.
Umar Iqbal 0002, Pouneh Nikkhah Bahrami, Rahmadi Trimananda, Hao Cui 0004, Alexander Gamero-Garrido, Daniel J. Dubois, David R. Choffnes, Athina Markopoulou, Franziska Roesner, Zubair Shafiq
IMC9
2023 A Scalable Inclusive Security Intervention to Center Marginalized & Vulnerable Populations in Security & Privacy Design
abstract
Research in computer security has increasingly considered the needs of marginalized and vulnerable groups in technology. Through this work, we hope to translate this research movement into practice and, ultimately, cause designers-in-training (and, eventually, designers) to consider a more inclusive range of stakeholders. Thus, we created an educational intervention to center marginalized and vulnerable populations in the context of threat modeling. We find that computer security students are more likely to consider unique threats and vulnerabilities facing marginalized and vulnerable populations after being exposed to an intervention prompting them to think about populations that might often be overlooked. We suggest practical methods to teach designers-in-training inclusive methods in computer security and discuss other possible adoptions of this practice across the field. This work is part of an important shift toward inclusive security that centers marginalized and vulnerable populations both in research and in practice.
Mattea Sim, Kurt Hugenberg, Tadayoshi Kohno, Franziska Roesner
NSPW4
2023 Skilled or Gullibleƒ Gender Stereotypes Related to Computer Security and Privacy
abstract
Gender stereotypes remain common in U.S. society and harm people of all genders. Focusing on binary genders (women and men) as a first investigation, we empirically study gender stereotypes related to computer security and privacy. We used Prolific to conduct two surveys with U.S. participants that aimed to: (1) surface potential gender stereotypes related to security and privacy (N = 202), and (2) assess belief in gender stereotypes about security and privacy engagement, personal characteristics, and behaviors (N = 190). We find that stereotype beliefs are significantly correlated with participants’ gender as well as level of sexism, and we delve into the justifications our participants offered for their beliefs. Beyond scientifically studying the existence and prevalence of such stereotypes, we describe potential implications, including biasing crowdworker-faciliated user research. Further, our work lays a foundation for deeper investigations of the impacts of stereotypes in computer security and privacy, as well as stereotypes across the whole gender and identity spectrum.
Miranda Wei, Pardis Emami Naeini, Franziska Roesner, Tadayoshi Kohno
SP3
2023 Reframe: An Augmented Reality Storyboarding Tool for Character-Driven Analysis of Security & Privacy Concerns
abstract
While current augmented reality (AR) authoring tools lower the technical barrier for novice AR designers, they lack explicit guidance to consider potentially harmful aspects of AR with respect to security & privacy (S&P). To address potential threats in the earliest stages of AR design, we developed Reframe, a digital storyboarding tool for designers with no formal training to analyze S&P threats. We accomplish this through a frame-based authoring approach, which captures and enhances storyboard elements that are relevant for threat modeling, and character-driven analysis tools, which personify S&P threats from an underlying threat model to provide simple abstractions for novice AR designers. Based on evaluations with novice AR designers and S&P experts, we find that Reframe enables designers to analyze threats and propose mitigation techniques that experts consider good quality. We discuss how Reframe can facilitate collaboration between designers and S&P professionals and propose extensions to Reframe to incorporate additional threat models.
Shwetha Rajaram, Franziska Roesner, Michael Nebeling
UIST2
2023 Exploring User Reactions and Mental Models Towards Perceptual Manipulation Attacks in Mixed Reality
Kaiming Cheng, Jeffery F. Tian, Tadayoshi Kohno, Franziska Roesner
USENIX Security Symposium4
2023 Online Advertising in Ukraine and Russia During the 2022 Russian Invasion
abstract
Online ads are a major source of information on the web. The mass reach of online advertising is often leveraged for information dissemination, at times with an objective to influence public opinion (e.g., election misinformation). We hypothesized that online advertising, due to its reach and potential, might have been used to spread information around the 2022 Russian invasion of Ukraine. Thus, to understand the online ad ecosystem during this conflict, we conducted a five-month long large-scale measurement study of online advertising in Ukraine, Russia, and the US. We studied advertising trends of ad platforms that delivered ads in Ukraine, Russia, and the US and conducted an in-depth qualitative analysis of the conflict-related ad content. We found that prominent US-based advertisers continued to support Russian websites, and a portion of online ads were used to spread conflict-related information, including protesting the invasion, and spreading awareness, which might have otherwise potentially been censored in Russia.
Christina Yeung, Umar Iqbal 0002, Yekaterina Tsipenyuk O'Neil, Tadayoshi Kohno, Franziska Roesner
WWW5
2022 Misinfo Reaction Frames: Reasoning about Readers' Reactions to News Headlines
abstract
Saadia Gabriel, Skyler Hallinan, Maarten Sap, Pemi Nguyen, Franziska Roesner, Eunsol Choi, Yejin Choi. Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2022.
Saadia Gabriel, Skyler Hallinan, Maarten Sap, Pemi Nguyen, Franziska Roesner, Eunsol Choi, Yejin Choi 0001
ACL (1)5
2022 What factors affect targeting and bids in online advertising?: a field measurement study
abstract
Targeted online advertising is a well-known but extremely opaque phenomenon. Though the targeting capabilities of the ad tech ecosystem are public knowledge, from an outside perspective, it is difficult to measure and quantify ad targeting at scale. To shed light on the extent of targeted advertising on the web today, we conducted a controlled field measurement study of the ads shown to a representative sample of 286 participants in the U.S. Using a browser extension, we collected data on ads seen by users on 10 popular websites, including the topic of the ad, the value of the bid placed by the advertiser (via header bidding), and participants' perceptions of targeting. We analyzed how ads were targeted across individuals, websites, and demographic groups, how those factors affected the amount advertisers bid, and how those results correlated with participants' perceptions of targeting. Among our findings, we observed that the primary factors that affected targeting and bid values were the website the ad appeared on and individual user profiles. Surprisingly, we found few differences in how advertisers target and bid across demographic groups. We also found that high outliers in bid values (10x higher than baseline) may be indicative of retargeting. Our measurements provide a rare in situ view of targeting and bidding across a diversity of users.
Eric Zeng 0001, Rachel McAmis, Tadayoshi Kohno, Franziska Roesner
IMC4
2022 Principles Matter: Integrating an Ethics Intervention into a Computer Security Course
abstract
There is increasing agreement that teaching students ethics in computer science (CS) is important, but there is little agreement about how to teach ethics, when to teach ethics, or even what ethics curricula should include. CS programs are experimenting with both stand-alone courses and approaches that integrate ethics throughout the computer science curriculum. Drawing from work in CS education and Science & Technology Studies, we designed an integrated and interdisciplinary ethics intervention to help computer security students identify where ethics and politics intersect with their technical field and encourage students to see themselves as practitioners of politics and ethics. Through analysis of student assignments, post-course surveys, and instructor reflections, we found that, while our intervention had benefits for students and instructors, it only weakly encouraged students to think of themselves as practitioners of ethics and politics. Students also struggled to confidently adjudicate ethical dilemmas given only a set of ethical principles. Finally, the ethical principles we gave students strongly shaped their analysis -- for example, students were more likely to consider disparate impacts of technology on marginalized groups when directly prompted to do so. Our results suggest that integrated and inter-disciplinary approaches have many benefits, but they require additional resources beyond a single course to effectively support students in adjudicating ethical dilemmas.
Justin Petelka, Megan Finn, Franziska Roesner, Katie Shilton
SIGCSE (1)3
2022 "Like Lesbians Walking the Perimeter": Experiences of U.S. LGBTQ+ Folks With Online Security, Safety, and Privacy Advice
Christine Geeng, Mike Harris, Elissa M. Redmiles, Franziska Roesner
USENIX Security Symposium4
2022 Electronic Monitoring Smartphone Apps: An Analysis of Risks from Technical, Human-Centered, and Legal Perspectives
Kentrell Owens, Anita Alem, Franziska Roesner, Tadayoshi Kohno
USENIX Security Symposium3
2021 What Makes a "Bad" Ad? User Perceptions of Problematic Online Advertising
abstract
Online display advertising on websites is widely disliked by users, with many turning to ad blockers to avoid “bad” ads. Recent evidence suggests that today’s ads contain potentially problematic content, in addition to well-studied concerns about the privacy and intrusiveness of ads. However, we lack knowledge of which types of ad content users consider problematic and detrimental to their browsing experience. Our work bridges this gap: first, we create a taxonomy of 15 positive and negative user reactions to online advertising from a survey of 60 participants. Second, we characterize classes of online ad content that users dislike or find problematic, using a dataset of 500 ads crawled from popular websites, labeled by 1000 participants using our taxonomy. Among our findings, we report that users consider a substantial amount of ads on the web today to be clickbait, untrustworthy, or distasteful, including ads for software downloads, listicles, and health & supplements.
Eric Zeng 0001, Tadayoshi Kohno, Franziska Roesner
CHI3
2021 Polls, clickbait, and commemorative $2 bills: problematic political advertising on news and media websites around the 2020 U.S. elections
abstract
Online advertising can be used to mislead, deceive, and manipulate Internet users, and political advertising is no exception. In this paper, we present a measurement study of online advertising around the 2020 United States elections, with a focus on identifying dark patterns and other potentially problematic content in political advertising. We scraped ad content on 745 news and media websites from six geographic locations in the U.S. from September 2020 to January 2021, collecting 1.4 million ads. We perform a systematic qualitative analysis of political content in these ads, as well as a quantitative analysis of the distribution of political ads on different types of websites. Our findings reveal the widespread use of problematic tactics in political ads, such as bait-and-switch ads formatted as opinion polls to entice users to click, the use of political controversy by content farms for clickbait, and the more frequent occurrence of political ads on highly partisan news websites. We make policy recommendations for online political advertising, including greater scrutiny of non-official political ads and comprehensive standards across advertising platforms.
Eric Zeng 0001, Miranda Wei, Theo Gregersen, Tadayoshi Kohno, Franziska Roesner
Internet Measurement Conference5
2020 Fake News on Facebook and Twitter: Investigating How People (Don't) Investigate
abstract
With misinformation proliferating online and more people getting news from social media, it is crucial to understand how people assess and interact with low-credibility posts. This study explores how users react to fake news posts on their Facebook or Twitter feeds, as if posted by someone they follow. We conducted semi-structured interviews with 25 participants who use social media regularly for news, temporarily caused fake news to appear in their feeds with a browser extension unbeknownst to them, and observed as they walked us through their feeds. We found various reasons why people do not investigate low-credibility posts, including taking trusted posters' content at face value, as well as not wanting to spend the extra time. We also document people's investigative methods for determining credibility using both platform affordances and their own ad-hoc strategies. Based on our findings, we present design recommendations for supporting users when investigating low-credibility posts.
Christine Geeng, Savanna Yee, Franziska Roesner
CHI3
2020 Smart Devices in Airbnbs: Considering Privacy and Security for both Guests and Hosts
abstract
Abstract Consumer smart home devices are becoming increasingly pervasive. As Airbnb hosts deploy smart devices in spaces shared with guests, we seek to understand the security and privacy implications of these devices for both hosts and guests. We conducted a large-scale survey of 82 hosts and 554 guests to explore their current technology practices, their preferences for smart devices and data collection/sharing, and their privacy and security concerns in the context of Airbnbs. We found that guests preferred smart devices, even viewed them as a luxury, but some guests were concerned that smart devices enable excessive monitoring and control, which could lead to repercussions from hosts (e.g., locked thermostat). On average, the views of guests and hosts on data collection in Airbnb were aligned, but for the data types where differences occur, serious privacy violations might happen. For example, 90% of our guest participants did not want to share their Internet history with hosts, but one in five hosts wanted access to that information. Overall, our findings surface tensions between hosts and guests around the use of smart devices and in-home data collection. We synthesize recommendations to address the surfaced tensions and identify broader research challenges.
Shrirang Mare, Franziska Roesner, Tadayoshi Kohno
Proc. Priv. Enhancing Technol.2
2019 Who's In Control?: Interactions In Multi-User Smart Homes
abstract
Adoption of commercial smart home devices is rapidly increasing, allowing in-situ research in people's homes. As these technologies are deployed in shared spaces, we seek to understand interactions among multiple people and devices in a smart home. We conducted a mixed-methods study with 18 participants (primarily people who drive smart device adoption in their homes) living in multi-user smart homes, combining semi-structured interviews and experience sampling. Our findings surface tensions and cooperation among users in several phases of smart device use: device selection and installation, ordinary use, when the smart home does not work as expected, and over longer term use. We observe an outsized role of the person who installs devices in terms of selecting, controlling, and fixing them; negotiations between parents and children; and minimally voiced privacy concerns among co-occupants, possibly due to participant sampling. We make design recommendations for supporting long-term smart homes and non-expert household members.
Christine Geeng, Franziska Roesner
CHI2
2019 Defending Against Neural Fake News
abstract
Recent progress in natural language generation has raised dual-use concerns. While applications like summarization and translation are positive, the underlying technology also might enable adversaries to generate neural fake news: targeted propaganda that closely mimics the style of real news. Modern computer security relies on careful threat modeling: identifying potential threats and vulnerabilities from an adversary's point of view, and exploring potential mitigations to these threats. Likewise, developing robust defenses against neural fake news requires us first to carefully investigate and characterize the risks of these models. We thus present a model for controllable text generation called Grover. Given a headline like 'Link Found Between Vaccines and Autism,' Grover can generate the rest of the article; humans find these generations to be more trustworthy than human-written disinformation. Developing robust verification techniques against generators like Grover is critical. We find that best current discriminators can classify neural fake news from real, human-written, news with 73% accuracy, assuming access to a moderate level of training data. Counterintuitively, the best defense against Grover turns out to be Grover itself, with 92% accuracy, demonstrating the importance of public release of strong generators. We investigate these results further, showing that exposure bias -- and sampling strategies that alleviate its effects -- both leave artifacts that similar discriminators can pick up on. We conclude by discussing ethical issues regarding the technology, and plan to release Grover publicly, helping pave the way for better detection of neural fake news.
Rowan Zellers, Ari Holtzman, Hannah Rashkin, Yonatan Bisk, Ali Farhadi, Franziska Roesner, Yejin Choi 0001
NeurIPS6
2019 Computer Security and Privacy in the Interactions Between Victim Service Providers and Human Trafficking Survivors
Christine Chen, Nicola Dell, Franziska Roesner
USENIX Security Symposium3
2019 Secure Multi-User Content Sharing for Augmented Reality Applications
Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner
USENIX Security Symposium3
2019 Understanding and Improving Security and Privacy in Multi-User Smart Homes: A Design Exploration and In-Home User Study
Eric Zeng 0001, Franziska Roesner
USENIX Security Symposium2
2018 Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End Users
abstract
Immersive augmented reality (AR) technologies are becoming a reality. Prior works have identified security and privacy risks raised by these technologies, primarily considering individual users or AR devices. However, we make two key observations: (1) users will not always use AR in isolation, but also in ecosystems of other users, and (2) since immersive AR devices have only recently become available, the risks of AR have been largely hypothetical to date. To provide a foundation for understanding and addressing the security and privacy challenges of emerging AR technologies, grounded in the experiences of real users, we conduct a qualitative lab study with an immersive AR headset, the Microsoft HoloLens. We conduct our study in pairs - 22 participants across 11 pairs - wherein participants engage in paired and individual (but physically co-located) HoloLens activities. Through semi-structured interviews, we explore participants' security, privacy, and other concerns, raising key findings. For example, we find that despite the HoloLens's limitations, participants were easily immersed, treating virtual objects as real (e.g., stepping around them for fear of tripping). We also uncover numerous security, privacy, and safety concerns unique to AR (e.g., deceptive virtual objects misleading users about the real world), and a need for access control among users to manage shared physical spaces and virtual content embedded in those spaces. Our findings give us the opportunity to identify broader lessons and key challenges to inform the design of emerging single-and multi-user AR technologies.
Kiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner
IEEE Symposium on Security and Privacy4
2018 Computer Security and Privacy for Refugees in the United States
abstract
In this work, we consider the computer security and privacy practices and needs of recently resettled refugees in the United States. We ask: How do refugees use and rely on technology as they settle in the US? What computer security and privacy practices do they have, and what barriers do they face that may put them at risk? And how are their computer security mental models and practices shaped by the advice they receive? We study these questions through in-depth qualitative interviews with case managers and teachers who work with refugees at a local NGO, as well as through focus groups with refugees themselves. We find that refugees must rely heavily on technology (e.g., email) as they attempt to establish their lives and find jobs; that they also rely heavily on their case managers and teachers for help with those technologies; and that these pressures can push security practices into the background or make common security "best practices" infeasible. At the same time, we identify fundamental challenges to computer security and privacy for refugees, including barriers due to limited technical expertise, language skills, and cultural knowledge-for example, we find that scams as a threat are a new concept for many of the refugees we studied, and that many common security practices (e.g., password creation techniques and security questions) rely on US cultural knowledge. From these and other findings, we distill recommendations for the computer security community to better serve the computer security and privacy needs and constraints of refugees, a potentially vulnerable population that has not been previously studied in this context.
Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, Tadayoshi Kohno
IEEE Symposium on Security and Privacy4
2017 Rewriting History: Changing the Archived Web from the Present
abstract
The Internet Archive's Wayback Machine is the largest modern web archive, preserving web content since 1996. We discover and analyze several vulnerabilities in how the Wayback Machine archives data, and then leverage these vulnerabilities to create what are to our knowledge the first attacks against a user's view of the archived web. Our vulnerabilities are enabled by the unique interaction between the Wayback Machine's archives, other websites, and a user's browser, and attackers do not need to compromise the archives in order to compromise users' views of a stored page. We demonstrate the effectiveness of our attacks through proof-of-concept implementations. Then, we conduct a measurement study to quantify the prevalence of vulnerabilities in the archive. Finally, we explore defenses which might be deployed by archives, website publishers, and the users of archives, and present the prototype of a defense for clients of the Wayback Machine, ArchiveWatcher.
Ada Lerner, Tadayoshi Kohno, Franziska Roesner
CCS3
2017 Toys that Listen: A Study of Parents, Children, and Internet-Connected Toys
abstract
Hello Barbie, CogniToys Dino, and Amazon Echo are part of a new wave of connected toys and gadgets for the home that listen. Unlike the smartphone, these devices are always on, blending into the background until needed. We conducted interviews with parent-child pairs in which they interacted with Hello Barbie and CogniToys Dino, shedding light on children's expectations of the toys' "intelligence'" and parents' privacy concerns and expectations for parental controls. We find that children were often unaware that others might be able to hear what was said to the toy, and that some parents draw connections between the toys and similar tools not intended as toys (e.g., Siri, Alexa) with which their children already interact. Our findings illuminate people's mental models and experiences with these emerging technologies and will help inform the future designs of interactive, connected toys and gadgets. We conclude with recommendations for parents, designers, and policy makers.
Emily McReynolds, Sarah Hubbard, Timothy Lau, Aditya Saraf, Maya Cakmak, Franziska Roesner
CHI6
2017 Confidante: Usable Encrypted Email: A Case Study with Lawyers and Journalists
abstract
Email encryption tools remain underused, even by people who frequently conduct sensitive business over email, such as lawyers and journalists. Usable encrypted email has remained out of reach largely because key management and verification remain difficult. However, key management has evolved in the age of social media: Keybase is a service that allows users to cryptographically link public keys to their social media accounts (e.g., Twitter), enabling key trust without out-of-band communication. We design and prototype Confidante, an encrypted email client that uses Keybase for automatic key management. We conduct a user study with 15 people (8 U. S. lawyers and 7 U. S. journalists) to evaluate Confidante's design decisions. We find that users complete an encrypted email task more quickly and with fewer errors using Confidante than with an existing email encryption tool, and that many users report finding Confidante comparable to using ordinary email. However, we also find that lawyers and journalists have diverse operational constraints and threat models, and thus that there may not be a one-size-fits-all solution to usable encrypted email. We reflect on our findings — both specifically about Confidante and more generally about the needs and constraints of lawyers and journalists—to identify lessons and remaining security and usability challenges for encrypted email.
Ada Lerner, Eric Zeng 0001, Franziska Roesner
EuroS&P3
2017 End User Security and Privacy Concerns with Smart Homes
Eric Zeng 0001, Shrirang Mare, Franziska Roesner
SOUPS3
2017 Securing Augmented Reality Output
abstract
Augmented reality (AR) technologies, such as Microsoft's HoloLens head-mounted display and AR-enabled car windshields, are rapidly emerging. AR applications provide users with immersive virtual experiences by capturing input from a user's surroundings and overlaying virtual output on the user's perception of the real world. These applications enable users to interact with and perceive virtual content in fundamentally new ways. However, the immersive nature of AR applications raises serious security and privacy concerns. Prior work has focused primarily on input privacy risks stemming from applications with unrestricted access to sensor data. However, the risks associated with malicious or buggy AR output remain largely unexplored. For example, an AR windshield application could intentionally or accidentally obscure oncoming vehicles or safety-critical output of other AR applications. In this work, we address the fundamental challenge of securing AR output in the face of malicious or buggy applications. We design, prototype, and evaluate Arya, an AR platform that controls application output according to policies specified in a constrained yet expressive policy framework. In doing so, we identify and overcome numerous challenges in securing AR output.
Kiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner
IEEE Symposium on Security and Privacy4
2017 When the Weakest Link is Strong: Secure Collaboration in the Case of the Panama Papers
Susan E. McGregor, Elizabeth Anne Watkins, Mahdi N. Al-Ameen, Kelly Caine, Franziska Roesner
USENIX Security Symposium5
2016 AUDACIOUS: User-Driven Access Control with Unmodified Operating Systems
abstract
User-driven access control improves the coarse-grained access control of current operating systems (particularly in the mobile space) that provide only all-or-nothing access to a resource such as the camera or the current location. By granting appropriate permissions only in response to explicit user actions (for example, pressing a camera button), user-driven access control better aligns application actions with user expectations. Prior work on user-driven access control has relied in essential ways on operating system (OS) modifications to provide applications with uncompromisable access control gadgets, distinguished user interface (UI) elements that can grant access permissions. This work presents a design, implementation, and evaluation of user-driven access control that works with no OS modifications, thus making deployability and incremental adoption of the model more feasible. We develop (1) a user-level trusted library for access control gadgets, (2) static analyses to prevent malicious creation of UI events, illegal flows of sensitive information, and circumvention of our library, and (3) dynamic analyses to ensure users are not tricked into granting permissions. In addition to providing the original user-driven access control guarantees, we use static information flow to limit where results derived from sensitive sources may flow in an application.
Talia Ringer, Dan Grossman, Franziska Roesner
CCS3
2016 Radiatus: a Shared-Nothing Server-Side Web Architecture
abstract
Web applications are a frequent target of successful attacks. In most web frameworks, the damage is amplified by the fact that application code is responsible for security enforcement. In this paper, we design and evaluate Radiatus, a shared-nothing web framework where application-specific computation and storage on the server is contained within a sandbox with the privileges of the end-user. By strongly isolating users, user data and service availability can be protected from application vulnerabilities.
Raymond Cheng 0001, William Scott 0002, Paul M. Ellenbogen, Jon Howell, Franziska Roesner, Arvind Krishnamurthy, Thomas E. Anderson
SoCC5
2016 Computer Security for Data Collection Technologies
abstract
Many organizations in the developing world (e.g., NGOs), include digital data collection in their workflow. Data collected can include information that may be considered sensitive, such as medical or socioeconomic data, and which could be affected by computer security attacks or unintentional mishandling. The attitudes and practices of organizations collecting data have implications for confidentiality, availability, and integrity of data. This work, a collaboration between computer security and ICTD researchers, explores security and privacy attitudes, practices, and needs within organizations that use Open Data Kit (ODK), a prominent digital data collection platform. We conduct a detailed threat modeling exercise to inform our view on potential security threats, and then conduct and analyze a survey and interviews with technology experts in these organizations to ground this analysis in real deployment experiences. We then reflect upon our results, drawing lessons for both organizations collecting data and for tool developers.
Camille Cobb, Samuel Sudar, Nicholas Reiter, Richard J. Anderson 0001, Franziska Roesner, Tadayoshi Kohno
ICTD5
2016 Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016
Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska Roesner
USENIX Security Symposium4
2016 Individual versus Organizational Computer Security and Privacy Concerns in Journalism
abstract
Abstract A free and open press is a critical piece of the civil-society infrastructure that supports both established and emerging democracies. However, as the professional activities of reporting and publishing are increasingly conducted by digital means, computer security and privacy risks threaten free and independent journalism around the globe. Through interviews with 15 practicing journalists and 14 organizational stakeholders (supervising editors and technologists), we reveal the distinct - and sometimes conflicting-computer security concerns and priorities of different stakeholder groups within journalistic institutions, as well as unique issues in journalism compared to other types of organizations. As these concerns have not been deeply studied by those designing computer security practices or technologies that may benefit journalism, this research offers insight into some of the practical and cultural constraints that can limit the computer security and privacy practices of the journalism community as a whole. Based on these findings, we suggest paths for future research and development that can bridge these gaps through new tools and practices.
Susan E. McGregor, Franziska Roesner, Kelly Caine
Proc. Priv. Enhancing Technol.2
2015 The Privacy-Utility Tradeoff for Remotely Teleoperated Robots
abstract
Though teleoperated robots have become common for more extreme tasks such as bomb diffusion, search-and-rescue, and space exploration, they are not commonly used in human-populated environments for more ordinary tasks such as house cleaning or cooking. This presents near-term opportunities for teleoperated robots in the home. However, a teleoperator's remote presence in a consumer's home presents serious security and privacy risks, and the concerns of end-users about these risks may hinder the adoption of such in-home robots. In this paper, we define and explore the privacy-utility tradeoff for remotely teleoperated robots: as we reduce the quantity or fidelity of visual information received by the teleoperator to preserve the end-user's privacy, we must balance this against the teleoperator's need for sufficient information to successfully carry out tasks. We explore this tradeoff with two surveys that provide a framework for understanding the privacy attitudes of end-users, and with a user study that empirically examines the effect of different filters of visual information on the ability of a teleoperator to carry out a task. Our findings include that respondents do desire privacy protective measures from teleoperators, that respondents prefer certain visual filters from a privacy perspective, and that, for the studied task, we can identify a filter that balances privacy with utility. We make recommendations for in-home teleoperation based on these findings.
Daniel J. Butler, Justin Huang, Franziska Roesner, Maya Cakmak
HRI3
2015 Analyzing the Use of Quick Response Codes in the Wild
abstract
One- and two-dimensional barcodes, including Quick Response (QR) codes, have become a convenient way to communicate small amounts of information from physical objects to mobile devices. While there is much discussion, awareness, and proposed use of such barcodes, both in aca-demia and in industry, to our knowledge there has not been a systematic and in-depth analysis of the actual ecosystem surrounding these codes. To fill this gap, we analyze a log of all scans performed by users of a popular QR and barcode scanning app available for Android, iPhone, and Windows Phone. Our dataset includes over 87 million scans performed over a 10-month period from May 2013 to March 2014. We examine general use patterns of QR and barcodes in the wild and identify common and uncommon uses and misuses. We see the presence of both conventional (e.g., web) and emerging (e.g., Bitcoin) uses of QR codes, and develop an informed understanding of the types of QR codes being created and how users interact with QR and barcodes in the wild.
Ada Lerner, Alisha Saxena, Kirk Ouimet, Ben Turley, Anthony Vance, Tadayoshi Kohno, Franziska Roesner
MobiSys7
2015 Investigating the Computer Security Practices and Needs of Journalists
Susan E. McGregor, Polina Charters, Tobin Holliday, Franziska Roesner
USENIX Security Symposium4
2014 Collaborative Verification of Information Flow for a High-Assurance App Store
abstract
Current app stores distribute some malware to unsuspecting users, even though the app approval process may be costly and time-consuming. High-integrity app stores must provide stronger guarantees that their apps are not malicious. We propose a verification model for use in such app stores to guarantee that the apps are free of malicious information flows. In our model, the software vendor and the app store auditor collaborate -- each does tasks that are easy for her/him, reducing overall verification cost. The software vendor provides a behavioral specification of information flow (at a finer granularity than used by current app stores) and source code annotated with information-flow type qualifiers. A flow-sensitive, context-sensitive information-flow type system checks the information flow type qualifiers in the source code and proves that only information flows in the specification can occur at run time. The app store auditor uses the vendor-provided source code to manually verify declassifications.
Michael D. Ernst, René Just, Suzanne Millstein, Werner Dietl, Stuart Pernsteiner, Franziska Roesner, Karl Koscher, Paulo Barros, Ravi Bhoraskar, Seungyeop Han, Paul Vines, Edward XueJun Wu
CCS6
2014 World-Driven Access Control for Continuous Sensing
abstract
Modern applications increasingly rely on continuous monitoring of video, audio, or other sensor data to provide their functionality, particularly in platforms such as the Microsoft Kinect and Google Glass. Continuous sensing by untrusted applications poses significant privacy challenges for both device users and bystanders. Even honest users will struggle to manage application permissions using existing approaches.
Franziska Roesner, David Molnar, Alexander Moshchuk, Tadayoshi Kohno, Helen J. Wang
CCS1
2013 Operating System Support for Augmented Reality Applications
Loris D'Antoni, Alan M. Dunn, Suman Jana, Tadayoshi Kohno, Benjamin Livshits, David Molnar, Alexander Moshchuk, Eyal Ofek, Franziska Roesner, T. Scott Saponas, Margus Veanes, Helen J. Wang
HotOS9
2013 Securing Embedded User Interfaces: Android and Beyond
Franziska Roesner, Tadayoshi Kohno
USENIX Security Symposium1
2012 Detecting and Defending Against Third-Party Tracking on the Web
Franziska Roesner, Tadayoshi Kohno, David Wetherall
NSDI1
2012 User-Driven Access Control: Rethinking Permission Granting in Modern Operating Systems
abstract
Modern client platforms, such as iOS, Android, Windows Phone, Windows 8, and web browsers, run each application in an isolated environment with limited privileges. A pressing open problem in such systems is how to allow users to grant applications access to user-owned resources, e.g., to privacy- and cost-sensitive devices like the camera or to user data residing in other applications. A key challenge is to enable such access in a way that is non-disruptive to users while still maintaining least-privilege restrictions on applications. In this paper, we take the approach of user-driven access control, whereby permission granting is built into existing user actions in the context of an application, rather than added as an afterthought via manifests or system prompts. To allow the system to precisely capture permission-granting intent in an application's context, we introduce access control gadgets (ACGs). Each user-owned resource exposes ACGs for applications to embed. The user's authentic UI interactions with an ACG grant the application permission to access the corresponding resource. Our prototyping and evaluation experience indicates that user-driven access control is a promising direction for enabling in-context, non-disruptive, and least-privilege permission granting on modern client platforms.
Franziska Roesner, Tadayoshi Kohno, Alexander Moshchuk, Bryan Parno, Helen J. Wang, Crispin Cowan
IEEE Symposium on Security and Privacy1
2012 User interface toolkit mechanisms for securing interface elements
abstract
User interface toolkit research has traditionally assumed that developers have full control of an interface. This assumption is challenged by the mashup nature of many modern interfaces, in which different portions of a single interface are implemented by multiple, potentially mutually distrusting developers (e.g., an Android application embedding a third-party advertisement). We propose considering security as a primary goal for user interface toolkits. We motivate the need for security at this level by examining today's mashup scenarios, in which security and interface flexibility are not simultaneously achieved. We describe a security-aware user interface toolkit architecture that secures interface elements while providing developers with the flexibility and expressivity traditionally desired in a user interface toolkit. By challenging trust assumptions inherent in existing approaches, this architecture effectively addresses important interface-level security concerns.
Franziska Roesner, James Fogarty, Tadayoshi Kohno
UIST1
2011 Comprehensive Experimental Analyses of Automotive Attack Surfaces
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno
USENIX Security Symposium9
2010 Experimental Security Analysis of a Modern Automobile
abstract
Modern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks. In this paper we experimentally evaluate these issues on a modern automobile and demonstrate the fragility of the underlying system structure. We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input\dash including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car's two internal subnets. We also present composite attacks that leverage individual weaknesses, including an attack that embeds malicious code in a car's telematics unit and that will completely erase any evidence of its presence after a crash. Looking forward, we discuss the complex challenges in addressing these vulnerabilities while considering the existing automotive ecosystem.
Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage
IEEE Symposium on Security and Privacy3
2008 Counting Dependence Predictors
abstract
Modern processors rely on memory dependence prediction to execute load instructions as early as possible, speculating that they are not dependent on an earlier, unissued store. To date, the most sophisticated dependence predictors, such as Store Sets, have been tightly coupled to the fetch and execution streams, requiring global knowledge of the in-flight stream of stores to synchronize loads with specific stores. This paper proposes a new dependence predictor design, called a Counting Dependence Predictor (CDP). The key feature of CDPs is that the prediction mechanism predicts some set of events for which a particular dynamic load should wait, which may include some number of matching stores. By waiting for local events only, this dependence predictor can work effectively in a distributed microarchitecture where centralized fetch and execution streams are infeasible or undesirable. We describe and evaluate a distributed Counting Dependence Predictor and protocol that achieves 92% of the performance of perfect memory disambiguation. It outperforms a load-wait table, similar to the Alpha 21264, by 11%. Idealized, centralized implementations of Store Sets and the Exclusive Collision Predictor, both of which would be difficult to implement in a distributed microarchitecture, achieve 97% and 94% of oracular performance, respectively.
Franziska Roesner, Doug Burger, Stephen W. Keckler
ISCA1
2007 Late-binding: enabling unordered load-store queues
abstract
Conventional load/store queues (LSQs) are an impediment to both power-efficient execution in superscalar processors and scaling tolarge-window designs. In this paper, we propose techniques to improve the area and power efficiency of LSQs by allocating entries when instructions issue ("late binding"), rather than when they are dispatched. This approach enables lower occupancy and thus smaller LSQs. Efficient implementations of late-binding LSQs, however, require the entries in the LSQ to be unordered with respect to age. In this paper, we show how to provide full LSQ functionality in an unordered design with only small additional complexity and negligible performance losses. We show that late-binding, unordered LSQs work well for small-window superscalar processors, but can also be scaled effectively to large, kilo-window processors by breaking the LSQs into address-interleaved banks. To handle the increased overflows, we apply classic network flow control techniques to the processor micronetworks, enabling low-overhead recovery mechanisms from bank overflows. We evaluate three such mechanisms: instruction replay, skid buffers, an dvirtual-channel buffering in the on-chip memory network. We show that for an 80-instruction window, the LSQ can be reduced to 32 entries. For a 1024-instruction window, the unordered, late-binding LSQ works well with four banks of 48 entries each. By applying a Bloom filter as well, this design achieves full hardware memory disambiguation for a 1,024 instruction window while requiring low average power per load and store access of 8 and 12 CAM entries, respectively.
Simha Sethumadhavan, Franziska Roesner, Joel S. Emer, Doug Burger, Stephen W. Keckler
ISCA2