VLDB 2026 Research / reviewers in the wild / expert
Benjamin Berens
dblp:305/7426 · also Benjamin Maximilian Berens
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-9284-7924ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingabstractEnd-to-end verifiable Internet voting promises that voters can remotely check whether their ballot was recorded correctly and that all ballots were tallied as cast. However, in order to achieve an adequate level of security, voters actually need to perform the first check. Our research focuses on the cast-then-audit approach for this check. We use related work to improve this approach in particular by providing a step-by-step guide. We conducted a deceptive online user study (N = 437) to compare our improved system with a baseline version from an actual election. We also measured the usability and participants confidence in using such systems. Our findings show that participants from the improved system perform significantly better than the baseline w.r.t. manipulation detecting and reporting capabilities. Furthermore, we show that it is important to distinguish between detection and reporting to understand how to further increase the overall security. Tobias Hilt, Christian Mack, Benjamin Berens, Melanie Volkamer |
CHI | 3 |
| 2026 | Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerabstractQR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR’s design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n = 556), where SEQR achieved 93.35% correct answers, compared to 75.24% for the Apple iOS QR code scanner and 65.11% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub. Mattia Mossano, Maxime Veit, Tobias Länge, Benjamin Berens, Filipo Sharevski, Melanie Volkamer |
CHI | 4 |
| 2026 | Implementing and Evaluating the Usability of Reliable Voter Complaints in E2E Verifiable Remote Electronic Voting
Tobias Hilt, Christian Mack, Philipp Matheis, Benjamin Berens, Tobias Länge, Rolf Haenni, Reto E. Koenig, Philipp Locher, Melanie Volkamer |
EuroS&P | 4 |
| 2025 | Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessabstractPhishing warning researchers have proposed two forms of hyperlink restrictions for reducing phishing click-through rates: focused attention, which prevents users from proceeding to a suspicious URL until they click the uncovered link inside the warning; and time delay, which disables link clicking for a short period of time. Both measures aim to draw user attention to the warning and nudge them to carefully evaluate the respective link's URL. However, the effectiveness of these measures has so far not been comparatively evaluated. We conducted a mixed-methods online experiment (n=1,320) to understand differences in the effectiveness of focused attention and time delay both independently and together. Our study used an instrumented email inbox environment, in which participants were asked to assess emails and email hyper-links. We found that, while both focused attention and time delay reduced click-through rates independently, the strength of these effects were significantly different from each other with focused attention being more effective than time delay. Combining both measures reduced CTR even further. We also found that participants who saw a warning with a time delay were more likely to hover over hyperlinks for longer than those who saw a focused attention warning. We discuss the implications of our findings for the design of anti-phishing warnings. Justin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer, Florian Schaub |
SP | 2 |
| 2024 | Better Together: The Interplay Between a Phishing Awareness Video and a Link-centric Phishing Support ToolabstractTwo popular approaches for helping consumers avoid phishing threats are phishing awareness videos and tools supporting users in identifying phishing emails. Awareness videos and tools have each been shown on their own to increase people’s phishing detection rate. Videos have been shown to be a particularly effective awareness measure; link-centric warnings have been shown to provide effective tool support. However, it is unclear how these two approaches compare to each other. We conducted a between-subjects online experiment (n=409) in which we compared the effectiveness of the NoPhish video and the TORPEDO tool and their combination. Our main findings suggest that the TORPEDO tool outperformed the NoPhish video and that the combination of both performs significantly better than just the tool. We discuss the implications of our findings for the design and deployment of phishing awareness measures and support tools. Benjamin Berens, Florian Schaub, Mattia Mossano, Melanie Volkamer |
CHI | 1 |
| 2024 | Cookie disclaimers: Dark patterns and lack of transparencyabstractWhile cookie disclaimers on websites have been proposed to ensure that users make informed decisions regarding consenting to data collection via cookies, such informed consent is hindered by several factors. One of them is the presence of so-called dark patterns, that is, design elements that are used to lead users to accept more cookies than needed and more than they are aware of. The second factor is lack of transparency on behalf of the service providers with regards to what happens if the user does not consent to cookie usage even despite dark patterns nudging them to do so. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behaviour; (2) identifying users' attitude towards cookie disclaimers including how they decide which cookies to accept or reject; (3) assessing the behaviour of websites regarding storing non-necessary cookies despite user's consent. We show that different visual representation of the reject/accept option have a significant impact on users' decision. We also found that the labelling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users' decision). Our results on users' attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We furthermore show that even without user's explicit consent, the majority of websites we investigated still uses non-necessary cookies. We provide recommendations on how to improve the situation for different stakeholders, namely, for developers and policy makers. Benjamin Berens, Mark Bohlender, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
Comput. Secur. | 1 |
| 2024 | Taking 5 minutes protects you for 5 months: Evaluating an anti-phishing awareness videoabstractPhishing is one of the biggest security threats to organizations. Anti-phishing awareness measures can improve phishing email detection rates. These measures need to be efficient, effective, and have an enduring impact over months, rather than days. Related research provides evidence of their effectiveness in the short term. However, questions remain as to how long this impact endures. We conducted a retention user study in two phases, with almost 200 participants in the first phase and almost 80 in the second phase, to determine whether a five-minute video retains its effectiveness five months after the intervention (similar to related work on more time-intensive measures). Our results suggest that short videos can indeed still exert a positive influence five months later. We also report on the video's influence on phishing detection strategies, as well as on viewers' confidence in this respect. Based on our results, we propose recommendations to inform the content of future awareness refreshment measures. Benjamin Berens, Mattia Mossano, Melanie Volkamer |
Comput. Secur. | 1 |
| 2022 | Cookie Disclaimers: Impact of Design and Users' AttitudeabstractDark patterns in cookie disclaimers are factors that are used to lead users to accept more cookies than needed and more than they are aware of. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behavior; (2) identifying users’ attitude towards cookie disclaimers including how they decide which cookies to accept or reject. We show that different visual representation of the reject/accept option have a significant impact on users’ decision. We also found that the labeling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users’ decision). Our results on users’ attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We provide recommendations on how to improve the situation for the different user groups. Benjamin Berens, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
ARES | 1 |
| 2021 | How to Increase Smart Home Security and Privacy Risk PerceptionabstractWith continuous technological advancements, our homes become smarter by interconnecting more and more devices. Smart homes provide many advantages. However, they also introduce new privacy and security risks. Recent studies show that only a few people are aware of abstract risks, and most people are not aware of specific negative consequences. We developed a privacy and security awareness intervention for people who want to inform themselves about risks in the smart home context. Our intervention is based on research literature on risk perception and feedback from both lay users and security and privacy experts. We evaluated our intervention regarding its influence on participants' perceived threat, privacy attitude, motivation to avoid threats, willingness to pay, and time commitment to configure protective measures. The results of this evaluation show a significant increase for all these aspects. We also compared our intervention to information that users could obtain during an Internet search on the topic. In this comparison, our intervention evokes a significantly higher perceived threat and privacy attitude. It showed no significant difference for the other three scales. We discuss our findings in light of related work. Reyhan Duezguen, Peter Mayer 0001, Benjamin Berens, Christopher Beckmann, Lukas Aldag, Mattia Mossano, Melanie Volkamer, Thorsten Strufe |
TrustCom | 3 |