VLDB 2026 Research / reviewers in the wild / expert
Florian Dehling
dblp:252/7722
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0002-8824-2500ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SoK: Continuous Authentication Beyond Error Rates: Reviewing General System Properties
Florian Dehling, Sebastian Kawelke, Luigi Lo Iacono |
ACNS (3) | 1 |
| 2024 | You Are as You Type: Investigating the Influence of Timestamp Accuracy on the Robustness of Keystroke BiometricsabstractKeystroke dynamics are behavioral biometric traits that are frequently proposed to be used in novel authentication systems. Keystroke dynamics are based on the analysis of intervals between keystroke events originating from user input and thus directly depend on available timing information. However, modern web browsers limit the accuracy of timestamps to improve security and privacy. This study systematically investigates the impact of limited timestamp accuracies on the performance of keystroke dynamic analysis. By conducting multiple experiments with popular web browsers, we demonstrate that the minor timestamp modifications that mitigate timing side-channel attacks do not interfere with the effectiveness of keystroke dynamics analysis algorithms. Furthermore, they are surprisingly resilient to larger timestamp modifications, which results in a serious threat to users’ privacy. This research provides fundamental knowledge enabling researchers, privacy engineers, and browser vendors to study risks in keystroke dynamics-related systems and to develop mitigations against tracking methods that fingerprint users instead of devices or browsers. Florian Dehling, Luigi Lo Iacono, Hannes Federrath |
TrustCom | 1 |
| 2024 | Internet Users' Willingness to Disclose Biometric Data for Continuous Online Account Protection: An Empirical InvestigationabstractContinuous authentication has emerged as a promising approach to increase user account security for online services. Unlike traditional authentication methods, continuous authentication provides ongoing security throughout the session, protecting against session takeover attacks due to illegitimate access. The effectiveness of continuous authentication systems relies on the continuous processing of users' sensitive biometric data. To balance security and privacy trade-offs, it's crucial to understand when users are willing to disclose biometric data for enhanced account security, addressing inevitable privacy concerns and user acceptance. To address this knowledge gap, we conducted an online study with 830 participants from the U.S., aiming to investigate user perceptions towards continuous authentication across different classes of online services. Our analysis identified four groups of biometric traits that directly reflect users' willingness to disclose them. Our findings demonstrate that willingness to disclose is influenced by both the specific biometric traits and the type of online service involved. User perceptions are strongly shaped by factors such as response efficacy, perceived privacy risks associated with the biometric traits, and concerns about the service providers' handling of such data. Our results emphasize the inadequacy of one-size-fits-all solutions and provide valuable insights for the design and implementation of continuous authentication systems. Florian Dehling, Jan Tolsdorf, Hannes Federrath, Luigi Lo Iacono |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | Data cart - designing a tool for the GDPR-compliant handling of personal data by employeesabstractEmployees who process personal data as part of their job play a critical role in protecting privacy. They are expected to follow strict data protection guidelines and protect personal data adequately. However, few studies have addressed the needs of these employees in terms of appropriate tools to assist them in complying with privacy laws. To develop a suitable tool, we used a human-centred design approach and held a series of eight workshops with 19 employees from two German public institutions. Based on the metaphor of a data cart, we developed a concept for a tool that supports employees in data management and data protection compliance. Qualitative usability testing revealed that participants expected the tool to raise their data protection awareness, reduce errors, and increase work efficiency. Our findings also suggest that if Privacy by Design becomes an integral part of digitalisation, employee perceptions of data protection may be positively altered. Employers, IT engineers, and researchers benefit from gaining insights into ways to improve the usability of data protection compliant personal data management tools. Simultaneously, we highlight how they can improve and promote compliance. Jan Tolsdorf, Florian Dehling, Luigi Lo Iacono |
Behav. Inf. Technol. | 2 |
| 2021 | Components and Architecture for the Implementation of Technology-Driven Employee Data Protection
Florian Dehling, Denis Feth, Svenja Polst, Bianca Steffes, Jan Tolsdorf |
TrustBus | 1 |
| 2021 | Exploring mental models of the right to informational self-determination of office workers in GermanyabstractAbstract Applied privacy research has so far focused mainly on consumer relations in private life. Privacy in the context of employment relationships is less well studied, although it is subject to the same legal privacy framework in Europe. The European General Data Protection Regulation (GDPR) has strengthened employees’ right to privacy by obliging that employers provide transparency and intervention mechanisms. For such mechanisms to be effective, employees must have a sound understanding of their functions and value. We explored possible boundaries by conducting a semi-structured interview study with 27 office workers in Germany and elicited mental models of the right to informational self-determination, which is the European proxy for the right to privacy. We provide insights into (1) perceptions of different categories of data, (2) familiarity with the legal framework regarding expectations for privacy controls, and (3) awareness of data processing, data flow, safeguards, and threat models. We found that legal terms often used in privacy policies used to describe categories of data are misleading. We further identified three groups of mental models that differ in their privacy control requirements and willingness to accept restrictions on their privacy rights. We also found ignorance about actual data flow, processing, and safeguard implementation. Participants’ mindsets were shaped by their faith in organizational and technical measures to protect privacy. Employers and developers may benefit from our contributions by understanding the types of privacy controls desired by office workers and the challenges to be considered when conceptualizing and designing usable privacy protections in the workplace. Jan Tolsdorf, Florian Dehling, Delphine Reinhardt, Luigi Lo Iacono |
Proc. Priv. Enhancing Technol. | 2 |