VLDB 2026 Research / reviewers in the wild / expert
Verena Winterhalter
dblp:260/6458
· DBLP profile ↗
6ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0003-0752-3480ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 5 · 1 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | I don't know what I've all granted. Does it really matter? - Understanding Users' Awareness of Different Permission Types on Android
Verena Winterhalter, Sarah Prange, Anouk Moreno, Harel Israel Berger, Florian Alt |
SOUPS | 1 |
| 2025 | BlueTOTP: Designing Phishing-Resistant and User-Friendly Two-Factor AuthenticationabstractAbstract Two-factor authentication (2FA) is an effective measure to safeguard against password attacks (e.g., guessing, credential stuffing). However, many existing 2FA methods are neither user-friendly nor protect adequately against phishing, particularly real-time (person-in-the-middle) attacks. We introduce BlueTOTP , a novel approach that leverages Bluetooth to automatically transmit time-based one-time passwords (TOTP) and verify the requesting domain before issuing the second factor. By reducing manual interactions and ensuring domain legitimacy, BlueTOTP streamlines the authentication process and mitigates phishing risks. We present the design and implementation of BlueTOTP, followed by an evaluation of its usability and performance. BlueTOTP not only improves the user experience during authentication but also significantly reduces the overall time required to complete 2FA authentication. Marian Käsemodel, Verena Winterhalter, Felix Heisel, Florian Alt, Bastian Pfleging |
INTERACT (3) | 2 |
| 2025 | A Multi-Layered Privacy Permission Framework for Extended RealityabstractExtended Reality (XR) systems bring arrays of sensors closer to the user’s body, enabling the collection of extensive user and contextual data, from motion and biometrics to behavioral analytics, that users might not be aware they are sharing. This poses significant risks to users’ privacy. Yet, despite the immersive and dynamic nature of XR, most platforms still rely on static, text-based privacy mechanisms inherited from traditional 2D interfaces. We propose a new paradigm of continuous consent in XR, where privacy decisions unfold as a relational, context-aware, and renegotiable process embedded in the experience – not a single consent event. To this end, we propose a Multi-Layered Privacy Framework spanning five interdependent layers: regulatory compliance, technical implementation, permission models, user experience, and user perception and cognition. We then introduce the User Privacy Journey Model, which operationalizes the framework as a sequential user pathway: from onboarding and contextual prompts to in-experience control and post-session review, along with the XR Privacy Checklist to support practical adoption. By rethinking consent as a continuous journey, we present a new paradigm for XR privacy, one that opens a new research perspective on what "informed" consent means in immersive environments where the boundaries between self, system, and space are increasingly blurred. Shady Mansour, Verena Winterhalter, Florian Alt, Viktorija Paneva |
NSPW | 2 |
| 2025 | User Understanding of Privacy Permissions in Mobile Augmented Reality: Perceptions and Misconceptions MHCI037abstractMobile Augmented Reality (AR) applications leverage various sensors to provide immersive user experiences. However, their reliance on diverse data sources introduces significant privacy challenges. This paper investigates user perceptions and understanding of privacy permissions in mobile AR apps through an analysis of existing applications and an online survey of 120 participants. Findings reveal common misconceptions, including confusion about how permissions relate to specific AR functionalities (e.g., location and measurement of physical distances), and misinterpretations of permission labels (e.g., conflating camera and gallery access). We identify a set of actionable implications for designing more usable and transparent privacy mechanisms tailored to mobile AR technologies, including contextual explanations, modular permission requests, and clearer permission labels. These findings offer actionable guidance for developers, researchers, and policymakers working to enhance privacy frameworks in mobile AR. Viktorija Paneva, Verena Winterhalter, Franziska Augustinowski, Florian Alt |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2023 | Understanding and Mitigating Technology-Facilitated Privacy Violations in the Physical WorldabstractWe are constantly surrounded by technology that collects and processes sensitive data, paving the way for privacy violations. Yet, current research investigating technology-facilitated privacy violations in the physical world is scattered and focused on specific scenarios or investigates such violations purely from an expert’s perspective. Informed through a large-scale online survey, we first construct a scenario taxonomy based on user-experienced privacy violations in the physical world through technology. We then validate our taxonomy and establish mitigation strategies using interviews and co-design sessions with privacy and security experts. In summary, this work contributes (1) a refined scenario taxonomy for technology-facilitated privacy violations in the physical world, (2) an understanding of how privacy violations manifest in the physical world, (3) a decision tree on how to inform users, and (4) a design space to create notices whenever adequate. With this, we contribute a conceptual framework to enable a privacy-preserving technology-connected world. Maximiliane Windl, Verena Winterhalter, Albrecht Schmidt 0001, Sven Mayer |
CHI | 2 |
| 2020 | Developing a Personality Model for Speech-based Conversational Agents Using the Psycholexical ApproachabstractWe present the first systematic analysis of personality dimensions developed specifically to describe the personality of speech-based conversational agents. Following the psycholexical approach from psychology, we first report on a new multi-method approach to collect potentially descriptive adjectives from 1) a free description task in an online survey (228 unique descriptors), 2) an interaction task in the lab (176 unique descriptors), and 3) a text analysis of 30,000 online reviews of conversational agents (Alexa, Google Assistant, Cortana) (383 unique descriptors). We aggregate the results into a set of 349 adjectives, which are then rated by 744 people in an online survey. A factor analysis reveals that the commonly used Big Five model for human personality does not adequately describe agent personality. As an initial step to developing a personality model, we propose alternative dimensions and discuss implications for the design of agent personalities, personality-aware personalisation, and future research. Sarah Theres Völkel, Ramona Schödel, Daniel Buschek, Clemens Stachl, Verena Winterhalter, Markus Bühner, Heinrich Hußmann |
CHI | 5 |