Hilda Hadan

dblp:271/9036 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-5911-1405ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 7 · 6 first-author · 7 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Rushed by Discomfort, Trapped by Immersion: Users' Experiences and Responses to Privacy Deceptive Design in Commercial VR Applications
abstract
Commercial Virtual Reality (VR) transforms people’s virtual experiences but introduces deceptive design opportunities that threaten user privacy. Although privacy deceptive patterns on 2D platforms are well-documented, their impacts in VR remain understudied. We surveyed 481 users’ experiences and responses to privacy deceptive patterns across eight commercial VR scenarios. We found that VR deceptive design can exploit both cognitive vulnerabilities and bodily strain, a phenomenon we define as Ergonomic Susceptibility, and that VR’s sensory-rich experiences can make users more likely to accept invasive data disclosure framed as immersion-preserving. Users recognized manipulation but their prior non-VR exposure can foster privacy resignation. Our study shows ergonomics is a critical factor in future privacy-preserving VR design, and urges VR researchers, designers, and policymakers to develop ethical design and privacy management solutions that account for VR’s unique multimodal, immersive, and ergonomic properties, building immersive experiences that respect user privacy and mitigate manipulative data practices.
Hilda Hadan, Michaela Valiquette, Lennart E. Nacke, Leah Zhang-Kennedy
DIS1
2026 Who is Responsible When AI Fails? Mapping Causes, Entities, and Consequences of AI Privacy and Ethical Incidents
abstract
The rapid growth of artificial intelligence (AI) technologies has raised major privacy and ethical concerns. However, existing AI incident taxonomies and guidelines lack grounding in real-world cases, limiting their effectiveness for prevention and mitigation. We analyzed 202 real-world AI privacy and ethical incidents to develop a taxonomy that classifies them across AI lifecycle stages and captures contributing factors, including causes, responsible entities, sources of disclosure, and impacts. Our findings reveal widespread harms from poor organizational decisions and legal non-compliance, limited corrective interventions, and rare reporting from AI developers and adopting entities. Our taxonomy offers a structured approach for systematic incident reporting and emphasizes the weaknesses of current AI governance frameworks. Our findings provide actionable guidance for policymakers and practitioners to strengthen user protections, develop targeted AI policies, enhance reporting practices, and foster responsible AI governance and innovation, especially in contexts such as social media and child protection.
Hilda Hadan, Reza Hadi Mogavi, Leah Zhang-Kennedy, Lennart E. Nacke
Int. J. Hum. Comput. Interact.1
2025 Folk Tales of IoT: Understanding the Impact of Stories on Users' Positive and Negative Perceptions of Smart Home IoT Devices
abstract
This study examines how anecdotal stories from friends, peers, and online sources influence non-experts' perceptions and behaviors toward smart home IoT devices.We surveyed 263 participants, collecting narratives that either positively or negatively influenced their perception of IoT devices, which they retold in text and comic formats to encourage deeper reflection.Thematic analysis of the narratives, combined with quantitative survey data, reveals that stories significantly impact trust and willingness to use and adopt IoT devices.Negative stories, particularly those concerning security, privacy, and device unreliability, reduced trust and usage, while positive stories about home safety through monitoring and improved quality of life increased interest in IoT devices.Perceptions of different IoT devices varied based on the themes associated with the stories.The findings highlight the powerful role of storytelling in driving consumer acceptance of technology. CCS Concepts• Human-centered computing → Empirical studies in HCI; • Security and privacy → Social aspects of security and privacy.
Leah Zhang-Kennedy, Michaela Valiquette, An Bella Chen, Hilda Hadan, Sangho Suh
CHI4
2025 Immersive Invaders: Privacy Threats from Deceptive Design in Virtual Reality Games and Applications
abstract
Virtual Reality (VR) technologies offer immersive experiences but collect substantial user data. While deceptive design is well-studied in 2D platforms, little is known about its manifestation in VR environments and its impact on user privacy. This research investigates deceptive designs in privacy communication and interaction mechanisms of 12 top-rated VR games and applications through autoethnographic evaluation of the applications and thematic analysis of privacy policies. We found that while many deceptive designs rely on 2D interfaces, some VR-unique features, while not directly enabling deception, amplified data disclosure behaviors, and obscured actual data practices. Convoluted privacy policies and manipulative consent practices further hinder comprehension and increase privacy risks. We also observed privacy-preserving design strategies and protective considerations in VR privacy policies. We offer recommendations for ethical VR design that balance immersive experiences with strong privacy protections, guiding researchers, designers, and policymakers to improve privacy in VR environments.
Hilda Hadan, Michaela Valiquette, Lennart E. Nacke, Leah Zhang-Kennedy
Proc. ACM Hum. Comput. Interact.1
2024 Privacy in Immersive Extended Reality: Exploring User Perceptions, Concerns, and Coping Strategies
abstract
Extended Reality (XR) technology is changing online interactions, but its granular data collection sensors may be more invasive to user privacy than web, mobile, and the Internet of Things technologies. Despite an increased interest in studying developers’ concerns about XR device privacy, user perceptions have rarely been addressed. We surveyed 464 XR users to assess their awareness, concerns, and coping strategies around XR data in 18 scenarios. Our findings demonstrate that many factors, such as data types and sensitivity, affect users’ perceptions of privacy in XR. However, users’ limited awareness of XR sensors’ granular data collection capabilities, such as involuntary body signals of emotional responses, restricted the range of privacy-protective strategies they used. Our results highlight a need to enhance users’ awareness of data privacy threats in XR, design privacy-choice interfaces tailored to XR environments, and develop transparent XR data practices.
Hilda Hadan, Derrick M. Wang, Lennart E. Nacke, Leah Zhang-Kennedy
CHI1
2024 Comprehending the Crypto-Curious: How Investors and Inexperienced Potential Investors Perceive and Practice Cryptocurrency Trading
abstract
With the increasing popularity of cryptocurrency, many people are interested in cryptocurrency investments, but have so far hesitated. Many others have made investments without adequate preparation. To help interested investors improve their understanding of cryptocurrency and make rational investment decisions, it is important to study their concerns and motivations and to draw upon experienced investors’ experiences and practices. Therefore, we surveyed crypto investors and inexperienced potential investors interested in trading cryptocurrency (n = 395). Our results showed that extreme price volatility is the primary incentive and a substantial obstacle to market participation. Fraud risks, lack of personal funds, insufficient knowledge, and difficulty identifying credible information sources are also common barriers. Our findings highlight the need to build trustworthy exchange platforms and integrate educational features. Based on the reported concerns and experiences, we (1) identify learning components for new investors, and (2) formulate design recommendations for beginner-friendly exchange platforms.
Hilda Hadan, Leah Zhang-Kennedy, Lennart E. Nacke, Ville Mäkelä
Int. J. Hum. Comput. Interact.1
2024 From Motivating to Manipulative: The Use of Deceptive Design in a Game's Free-to-Play Transition
abstract
Over the last decade, the free-to-play (F2P) game business model has gained popularity in the games industry. We examine the role of deceptive design during a game's transition to F2P and its impacts on players. Our analysis focuses on game mechanics and a Reddit analysis of the Overwatch (OW) series after it transitioned to an F2P model. Our study identifies nine game mechanics that use deceptive design patterns. We also identify factors contributing to a negative gameplay experience. Business model transitions in games present possibilities for problematic practices. Our findings identify the need for game developers and publishers to balance player investments and fairness of rewards. A game's successful transition depends on maintaining fundamental components of player motivation and ensuring transparent communication. Compared to existing taxonomies in other media, games need a comprehensive classification of deceptive design. We emphasize the importance of understanding player perceptions and the impact of deceptive practices in future research.
Hilda Hadan, Sabrina A. Sgandurra, Leah Zhang-Kennedy, Lennart E. Nacke
Proc. ACM Hum. Comput. Interact.1
2021 Human and Organizational Factors in Public Key Certificate Authority Failures
abstract
Public Key Infrastructure (PKI) is the foundation of secure and trusted transactions across the Internet. Public key certificates are issued and validated by Certificate Authorities (CAs), which have their trust-of-anchor certificates in Root Program Operators' stores. These CAs provide certificates that attest to the integrity of the ownership of domain names on the web and enable secure communications. Each year hundreds of certificates are by these verified and trusted Certificate Authorities issued in error. In this research, we complied and classified certificate incident reports documented on Bugzilla, a web-based bug tracking system where such instances are reported. We focus on the 210 incident reports from the last year; we compare this pandemic period to trends from previous years. Our data show that the frequency of Certificate Authority non-compliance is a consistence source of vulnerability in the PKI ecosystem. The evaluation of reasons for the misissuance illustrate the role of one-off human failures, systematic interaction flaws leading to repeated incidents, and evidence of perverse incentives leading to misissuance.
Skyler Johnson, Katherine Ferro, L. Jean Camp, Hilda Hadan
CCS4