Alisa Frik

dblp:239/8147 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-8477-7276ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 6 since 2021Security and privacy · 6 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Are Bite-Size Data Safety Details a Healthy Diet for Android Telehealth App Users? Impacts of Privacy Nutrition Labels on Users' Privacy Perceptions
abstract
Mobile telehealth apps can provide valuable services, but they raise significant privacy and security concerns, as they collect health-related and other sensitive personal information. We conducted two surveys (𝑁 = 1, 256 total) to examine US users’ privacy expectations about Android telehealth and teletherapy apps’ data practices and legal privacy protections for the data they collect, gaps between those expectations and actual practices and protections, and how privacy perceptions and behavioral intentions are affected by privacy disclosures. In Survey 1, we explored participants’ privacy perceptions and intentions about 10 telehealth apps, first after reading just the general description from the Google Play Store, then after reading the Data Safety section (DSS). Survey 2 explored broader privacy expectations regarding telehealth apps, regulatory awareness, and preferred legal protections. Findings indicate that participants perceived apps provided by independent developers as less likely to protect privacy than apps offered by healthcare providers. However, participants often had inaccurate privacy expectations and overestimated legal safeguards, potentially leading to uninformed privacy decisions. DSSs significantly affected participants’ expectations about data practices and legal protections and their likelihood of using the app—but while DSSs often increased participants’ confidence in their privacy expectations, they did not necessarily improve their accuracy.
Alisa Frik, Subham Mitra, Priyasha Chatterjee, Julia Bernd
Proc. Priv. Enhancing Technol.1
2026 "I don't think it needs to be political": Privacy Experiences and Concerns of FemHealth App Users in the United States
abstract
FemHealth apps have rapidly developed, offering innovative opportunities to track users’ menstrual cycles, fertility, pregnancy, and other aspects of sexual and reproductive health. However, such apps collect a significant amount of sensitive user health data, posing privacy risks to users. In this paper, we conducted 14 in-depth semistructured interviews with current and past users of FemHealth apps in the US to examine their privacy experiences and concerns. We found that participants were concerned about a wider range of risks than was found in prior user research about FemTech, including criminalization related to abortion or contraceptive access; emotional distress related to social stigma; third-party data sharing; and targeted advertising based on processing sensitive health data. Some participants acknowledged that FemHealth apps posed privacy risks and potential harms to users in general but were not necessarily concerned about their own privacy due to privilege (e.g., living in a state with strong reproductive health rights). However, all participants agreed that user privacy and data protection in FemHealth apps should be considered a fundamental right, not subject to legal discourse in specific locales. Most participants felt unsure about the effectiveness of existing data protection regulations and their interplay with anti-abortion laws. Participants suggested several ways to mitigate privacy risks, including disclosures and controls, back-end technical protections, behavioral strategies, and policy improvements. We provide recommendations for extending practical and policy-based privacy protections of sexual and reproductive health data collected by FemHealth apps.
Ina Kaleva, Alisa Frik, Lisa Mekioussa Malki, Mark Warner, Ruba Abu-Salma
Proc. Priv. Enhancing Technol.2
2026 "Users are worried, but we are confused": Exploring the Privacy, Security, and Safety Perspectives and Practices of FemHealth App Product Team Members
abstract
FemHealth apps (e.g., period, fertility, and pregnancy trackers) collect highly sensitive sexual and reproductive health data and have become a focal point for privacy, security, and safety (PSS) concerns, particularly amid changes in reproductive health regulations in the US and growing public scrutiny. While prior work has identified shortcomings in the PSS protections implemented by FemHealth apps, far less is known about how the product teams developing these apps conceptualize and operationalize PSS in practice. We conducted semi-structured interviews with 14 FemHealth app product team members who represented 11 unique apps and held diverse roles, including software engineering and architecture, security and privacy, product management, policy and legal compliance, and UX/UI research and design. We found that data collection decisions are often driven by feature-specific objectives, such as improving prediction accuracy and enabling reliable backups, rather than by explicitly articulated PSS requirements. Teams also frequently rely on legal compliance frameworks and PSS practices designed for general-purpose apps, while expressing confidence that these measures provide adequate protection. In addition, we identified four persistent challenges faced by FemHealth app product teams: disagreement over whether FemHealth apps require distinct PSS protections compared to non-FemHealth apps; difficulty establishing and maintaining user trust; uncertainty arising from cross-border enforcement related to abortion; and technical limitations associated with backups, end-to-end encryption, and coercive local access to data. Based on these findings, we derive a set of requirements and provide actionable technical and policy recommendations to inform the design, engineering, and governance of PSS in FemHealth apps.
Chenkai Ma, Shijing He, Ina Kaleva, Alisa Frik, Jose M. Such, Ruba Abu-Salma
Proc. Priv. Enhancing Technol.4
2025 Who Cares? Contextual Privacy Judgments from Owner and Bystander Perspectives in Different Smart Home Situations
abstract
Current privacy protections for smart home devices rarely consider bystanders' privacy, whose preferences are varied and may differ from primary users. We use Contextual Integrity theory to explore context-dependent variation in privacy norms regarding smart home bystanders’ data. We conducted a vignette-based survey with 761 participants in the US, varying parameter values to capture acceptability judgments regarding bystander information flows in certain situations: domestic work, shared housing, visiting a friend overnight, and Airbnb. We found that recipients and purposes of sharing impact acceptance the most. Sharing interaction logs was more acceptable than audio or video. Sharing smart speaker data was less acceptable than smart camera or smart door lock data. We found nuanced interaction effects between factors in different smart home situations, and differences between protections most favored by participants playing bystander vs. owner roles. We provide design and policy recommendations for smart home privacy protections that consider bystanders' needs.
Alisa Frik, Xiao Zhan, Noura Abdi, Julia Bernd
Proc. Priv. Enhancing Technol.1
2025 "They Didn't Buy Their Smart TV to Watch Me with the Kids": Comparing Nannies' and Parents' Privacy Threat Models for Smart Home Devices
abstract
Smart home devices raise privacy concerns among not only primary users but also bystanders like domestic workers. We conducted 25 qualitative interviews with nannies and 16 with parents who employed nannies, in the U.S., to explore and compare their views on and privacy threat models for smart home devices. We found device-specific purposes of use inspired different perspectives among nanny participants. Most were comfortable with employers’ smart speakers and smart TVs, whose purpose had nothing to do with them. However, with indoor smart cameras, nanny participants were often not just bystanders but targets of monitoring; in such situations, they had a wider range of attitudes. In contrast, parent participants tended to have more similar views across devices. We found notable disconnects regarding disclosure, where nanny participants often hesitated to ask about cameras, but parent participants assumed nannies just didn’t care. We recommend prioritizing interventions supporting disclosure, discussion, and sharing control.
Ruba Abu-Salma, Junghyun Choy, Alisa Frik, Julia Bernd
ACM Trans. Comput. Hum. Interact.3
2024 Surveys Considered Harmful? Reflecting on the Use of Surveys in AI Research, Development, and Governance
abstract
Calls for engagement with the public in Artificial Intelligence (AI) research, development, and governance are increasing, leading to the use of surveys to capture people's values, perceptions, and experiences related to AI. In this paper, we critically examine the state of human participant surveys associated with these topics. Through both a reflexive analysis of a survey pilot spanning six countries and a systematic literature review of 44 papers featuring public surveys related to AI, we explore prominent perspectives and methodological nuances associated with surveys to date. We find that public surveys on AI topics are vulnerable to specific Western knowledge, values, and assumptions in their design, including in their positioning of ethical concepts and societal values, lack sufficient critical discourse surrounding deployment strategies, and demonstrate inconsistent forms of transparency in their reporting. Based on our findings, we distill provocations and heuristic questions for our community, to recognize the limitations of surveys for meeting the goals of engagement, and to cultivate shared principles to design, deploy, and interpret surveys cautiously and responsibly.
Mohammad Tahaei, Daricia Wilkinson, Alisa Frik, Ruba Abu-Salma, Lauren Wilcox
AIES (1)3
2024 "Protect Me Tomorrow": Commitment Nudges to Remedy Compromised Passwords
abstract
Internet users often neglect important security actions (e.g., installing security updates or changing passwords) because they interrupt users’ main task at inopportune times. Commitment devices, such as reminders and promises, have been found to be effective at reducing procrastination in other domains. In a series of online experiments ( \(n{\gt}3{,}000\) ), we explored the effects of reminders and promises on users’ willingness to change a compromised password. We find that adding an option to delay the task increases the share of people willing to eventually change their password considerably. Critically, the option to delay yields this overall increase without reducing the share of people choosing to change their password immediately. Additionally, most participants who promised to change their password later, or asked to be reminded to do so, indeed followed through on their commitment, leading to a net positive effect. Reminding participants of their previous commitment further increased this effect.
Eyal Péer, Alisa Frik, Conor Gilsenan, Serge Egelman
ACM Trans. Comput. Hum. Interact.2
2023 A Model of Contextual Factors Affecting Older Adults' Information-Sharing Decisions in the U.S
abstract
The sharing of information between older adults and their friends, families, caregivers, and doctors promotes a collaborative approach to managing their emotional, mental, and physical well-being and health, prolonging independent living, and improving care quality and quality of life in general. However, information flow in collaborative systems is complex, not always transparent to elderly users, and may raise privacy and security concerns. Because older adults’ decisions about whether to engage in information exchange affect interpersonal communications and delivery of care, it is important to understand the factors and context that influence those decisions. Our work contributes empirical evidence and suggests a systematic approach. In this article, we present the results of semi-structured interviews with 46 older adults aged 65+ about their views on information collection, transmission, and sharing. We develop a detailed model of the contextual factors that combine in complex ways to affect older adults’ decision making about information sharing. We discuss how our comprehensive model compares to existing frameworks for analyzing information-sharing expectations and preferences. Finally, we suggest directions for future research and describe the practical implications of our model for the design and evaluation of collaborative information-sharing systems, as well as for policy and consumer protection.
Alisa Frik, Julia Bernd, Serge Egelman
ACM Trans. Comput. Hum. Interact.1
2022 Users' Expectations About and Use of Smartphone Privacy and Security Settings
abstract
With the growing smartphone penetration rate, smartphone settings remain one of the main models for information privacy and security controls. Yet, their usability is largely understudied, especially with respect to the usability impact on underrepresented socio-economic and low-tech groups. In an online survey with 178 users, we find that many people are not aware of smartphone privacy and security settings, their defaults, and have not configured them in the past, but are willing to do it in the future. Some participants perceive low self-efficacy and expect difficulties and usability issues with configuring those settings. Finally, we find that certain socio-demographic groups are more vulnerable to risks and feel less prepared to use smartphone settings to protect their online privacy and security.
Alisa Frik, Juliann Kim, Joshua Rafael Sanchez, Joanne Ma
CHI1
2022 Deployment of Source Address Validation by Network Operators: A Randomized Control Trial
abstract
IP spoofing, sending IP packets with a false source IP address, continues to be a primary attack vector for large-scale Denial of Service attacks. To combat spoofing, various interventions have been tried to increase the adoption of source address validation (SAV) among network operators. How can SAV deployment be increased? In this work, we conduct the first randomized control trial to measure the effectiveness of various notification mechanisms on SAV deployment. We include new treatments using nudges and channels, previously untested in notification experiments. Our design reveals a painful reality that contrasts with earlier observational studies: none of the notification treatments significantly improved SAV deployment compared to the control group. We explore the reasons for these findings and report on a survey among operators to identify ways forward. A portion of the operators indicate that they do plan to deploy SAV and ask for better notification mechanisms, training, and support materials for SAV implementation.
Qasim Lone, Alisa Frik, Matthew J. Luckie, Maciej Korczynski, Michel van Eeten, Carlos Gañán
SP2
2021 Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges
abstract
Software development teams are responsible for making and implementing software design decisions that directly impact end-user privacy, a challenging task to do well. Privacy Champions—people who strongly care about advocating privacy—play a useful role in supporting privacy-respecting development cultures. To understand their motivations, challenges, and strategies for protecting end-user privacy, we conducted 12 interviews with Privacy Champions in software development teams. We find that common barriers to implementing privacy in software design include: negative privacy culture, internal prioritisation tensions, limited tool support, unclear evaluation metrics, and technical complexity. To promote privacy, Privacy Champions regularly use informal discussions, management support, communication among stakeholders, and documentation and guidelines. They perceive code reviews and practical training as more instructive than general privacy awareness and on-boarding training. Our study is a first step towards understanding how Privacy Champions work to improve their organisation’s privacy approaches and improve the privacy of end-user products.
Mohammad Tahaei, Alisa Frik, Kami Vaniea
CHI2
2020 The Impact of Ad-Blockers on Product Search and Purchase Behavior: A Lab Experiment
Alisa Frik, Amelia Haviland, Alessandro Acquisti
USENIX Security Symposium1
2019 A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
abstract
Commitment devices are a technique from behavioral economics that have been shown to mitigate the effects of present bias---the tendency to discount future risks and gains in favor of immediate gratifications. In this paper, we explore the feasibility of using commitment devices to nudge users towards complying with varying online security mitigations. Using two online experiments, with over 1,000 participants total, we offered participants the option to be reminded or to schedule security tasks in the future. We find that both reminders and commitment nudges can increase users' intentions to install security updates and enable two-factor authentication, but not to configure automatic backups. Using qualitative data, we gain insights into the reasons for postponement and how to improve future nudges. We posit that current nudges may not live up to their full potential, as the timing options offered to users may be too rigid.
Alisa Frik, Nathan Malkin, Marian Harbach, Eyal Péer, Serge Egelman
CHI1