VLDB 2026 Research / reviewers in the wild / expert
Thea Riebe
dblp:233/3716
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0003-3210-6734ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Harnessing Inter-Organizational Collaboration and Automation to Combat Online Hate Speech: A Qualitative Study with German Reporting CentersabstractIn Germany and other countries, specialized non-profit reporting centers combat online hate speech by submitting criminal content to law enforcement agencies, forwarding deletion requests to social media platforms, and providing counseling to victims, thus contributing to the governance mechanism of content moderation as intermediaries between victims and various organizations. Whereas research in computer-supported cooperative work has extensively explored collaboration of and automation for content moderators, there are no works that focus on reporting centers. Based on expert interviews with their staff (N=15), this study finds that most German centers share a collaborative workflow, of which multiple tasks are heavily dependent on inter-organizational exchange. However, there are differences in their implementation of monitoring, content assessment, automation technology adoption, and external collaborators. As the centers are faced with diverse challenges, such as borderline case assessment, psychological burdens, limited visibility, conflicting goals with other actors, and manual repetitive work, our study contributes with nine implications for designing and researching supportive technologies. They provide suggestions for improving hate speech gathering and reporting, researching hate speech prioritization and assessment algorithms, and designing case processing systems. Beyond that, we outline directions for research on inter-organizational collaboration. Julian Bäumler, Thea Riebe, Marc-André Kaufhold, Christian Reuter 0001 |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2024 | 'We Do Not Have the Capacity to Monitor All Media': A Design Case Study on Cyber Situational Awareness in Computer Emergency Response TeamsabstractComputer Emergency Response Teams (CERTs) provide advisory, preventive and reactive cybersecurity services for authorities, citizens, and businesses. However, their responsibility of monitoring, analyzing, and communicating cyber threats have become challenging due to the growing volume and varying quality of information disseminated through public channels. Based on a design case study conducted from 2021 to 2023, this paper combines three iterations of expert interviews, design workshops and cognitive walkthroughs to design an automated, cross-platform and real-time cybersecurity dashboard. By adopting the notion of cyber situational awareness, the study extracts user requirements and design heuristics for enhanced threat awareness and mission awareness in CERTs, discussing the aspects of source integration, data management, customizable visualization, relationship awareness, information assessment, software integration, (inter-)organizational collaboration, and communication of stakeholder warnings. Marc-André Kaufhold, Thea Riebe, Markus Bayer, Christian Reuter 0001 |
CHI | 2 |
| 2024 | Values and Value Conflicts in the Context of OSINT Technologies for Cybersecurity Incident Response: A Value Sensitive Design PerspectiveabstractAbstract The negotiation of stakeholder values as a collaborative process throughout technology development has been studied extensively within the fields of Computer Supported Cooperative Work and Human-Computer Interaction. Despite their increasing significance for cybersecurity incident response, there is a gap in research on values of importance to the design of open-source intelligence (OSINT) technologies for this purpose. In this paper, we investigate which values and value conflicts emerge due to the application and development of machine learning (ML) based OSINT technologies to assist cyber security incident response operators. For this purpose, we employ a triangulation of methods, consisting of a systematic survey of the technical literature on the development of OSINT artefacts for cybersecurity (N = 73) and an empirical value sensitive design case study, comprising semi-structured interviews with stakeholders (N = 9) as well as a focus group (N = 7) with developers. Based on our results, we identify implications relevant to the research on and design of OSINT artefacts for cybersecurity incident response. Thea Riebe, Julian Bäumler, Marc-André Kaufhold, Christian Reuter 0001 |
Comput. Support. Cooperative Work. | 1 |
| 2023 | Privacy Concerns and Acceptance Factors of OSINT for Cybersecurity: A Representative SurveyabstractThe use of Open Source Intelligence (OSINT) to monitor and detect cybersecurity threats is gaining popularity among Cybersecurity Emergency or Incident Response Teams (CERTs/CSIRTs). They increasingly use semi-automated OSINT approaches when monitoring cyber threats for public infrastructure services and incident response. Most of the systems use publicly available data, often focusing on social media due to timely data for situational assessment. As indirect and affected stakeholders, the acceptance of OSINT systems by users, as well as the conditions which influence the acceptance, are relevant for the development of OSINT systems for cybersecurity. Therefore, as part of the ethical and social technology assessment, we conducted a survey (N=1,093), in which we asked participants about their acceptance of OSINT systems, their perceived need for open source surveillance, as well as their privacy behavior and concerns. Further, we tested if the awareness of OSINT is an interactive factor that affects other factors. Our results indicate that cyber threat perception and the perceived need for OSINT are positively related to acceptance, while privacy concerns are negatively related. The awareness of OSINT, however, has only shown effects on people with higher privacy concerns. Here, particularly high OSINT awareness and limited privacy concerns were associated with higher OSINT acceptance. Lastly, we provide implications for further research and the use of OSINT systems for cybersecurity by authorities. As OSINT is a framework rather than a single technology, approaches can be selected and combined to adhere to data minimization and anonymization as well as to leverage improvements in privacy-preserving computation and machine learning innovations. Regarding the use of OSINT, the results suggest to favor approaches that provide transparency to users regarding the use of the systems and the data they gather. Thea Riebe, Tom Biselli, Marc-André Kaufhold, Christian Reuter 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | CySecAlert: An Alert Generation System for Cyber Security Events Using Open Source Intelligence Data
Thea Riebe, Tristan Wirth, Markus Bayer, Philipp Kuehn 0001, Marc-André Kaufhold, Volker Knauthe, Stefan Guthe, Christian Reuter 0001 |
ICICS (1) | 1 |
| 2021 | The Impact of Organizational Structure and Technology Use on Collaborative Practices in Computer Emergency Response Teams: An Empirical StudyabstractBesides the merits of increasing digitization and interconnectedness in private and professional spaces, critical infrastructures and societies are more and more exposed to cyberattacks. In order to enhance the preventative and reactive capabilities against cyberattacks, Computer Emergency Response Teams (CERTs) are deployed in many countries and organizations. In Germany, CERTs in the public sector operate on federal and state level to provide information security services for authorities, citizens, and enterprises. Their tasks of monitoring, analyzing, and communicating threats and incidents is getting more complex due to the increasing amount of information disseminated into public channels. By adopting the perspectives of Computer-Supported Cooperative Work (CSCW) and Crisis Informatics, we contribute to the study of organizational structures, technology use, and the impact on collaborative practices in and between state CERTs with empirical research based on expert interviews with representatives of German state CERTs (N=15) and supplementary document analyses (N=25). We derive design and policy implications from our findings, including the need for interoperable and modular architecture, a shift towards service level agreements, cross-platform monitoring and analysis of incident data, use of deduplication techniques and standardized threat exchange formats, a reduction of resource costs through process automation, and transparent reporting and tool structures for information exchange. Thea Riebe, Marc-André Kaufhold, Christian Reuter 0001 |
Proc. ACM Hum. Comput. Interact. | 1 |