Rizu Paudel

dblp:339/2178 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
9since 2021 · last 2026
0000-0003-3840-9015ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 8 · 6 first-author · 8 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 "We listen, we don't judge": Exploring Design Opportunities for Emotional Literacy and Normalization in Parent-Child Interactions
abstract
We focus on emotional literacy and normalization to foster safe space in parent-child communication. To this end, we conceptualized our designs through two focus group sessions; first with three child experts, followed by a session with four UX experts. We then created storyboards accommodating our designs, which we used as interview stimuli in a study with 16 parent-child dyads in the USA, aimed at understanding the usefulness and applicability of our designs. Our findings show promise in creating safe space in parent-child interaction through offering ease and flexibility in expression, allowing opportunities for situational appraisal, cultivating reassurance of judgment-free space, and fostering accountability towards collaborative activity.
Rizu Paudel, Mahdi N. Al-Ameen
IDC1
2025 Understanding Teen's Expectations and Challenges to Seek Help in Social Media
Rizu Paudel, Mahdi N. Al-Ameen
IDC1
2025 Mental Model-Based Designs: The Study in Privacy Policy Landscape
abstract
Users’ mental models influence secure and privacy-preserving behavior in a computing environment. Prior studies on users’ mental models of Internet, security tools, and digital privacy show that there is no one-size-fits-all solution when it comes to security and privacy design. However, little study to date has explored the ways to translate users’ mental models into interactive security and privacy designs. As we begin to address this gap, we focus on privacy policy in this paper. The typical text-based privacy policy suffers from poor readability and usability. A recent study proposed a Visual Interactive Privacy Policy (VIPP), showing promise to offer a better user experience as compared to prior designs – we used VIPP as a control condition and compared that with our mental model (MM)-based designs, inspired by users’ privacy mental models explored in the existing literature. We iteratively improved our MM-based designs through a series of user studies in the lab setting. We evaluated our updated designs in an online study with 182 participants over Amazon Mechanical Turk. The participants rated MM-based designs significantly better than the control in most of our evaluation parameters. Furthermore, we found that when a design is centered around the mental model of participants, study participants rated it higher in terms of personal connection to the design, perspicuity, attractiveness, being stimulated towards privacy protection, as well as the propensity for real-life adoption. Based on our findings, we discussed the successes and challenges of MM-based designs and provided guidelines on the scope of leveraging mental models in the broader area of privacy and security designs.
Hanieh Atashpanjeh, Rizu Paudel, Mahdi N. Al-Ameen
Int. J. Hum. Comput. Interact.2
2025 "It's Definitely New and Different...It's Really Engaging": Understanding the Power of Storytelling Towards Secure Password Creation
abstract
There is a dearth in existing literature to attain systematic understanding of leveraging digital storytelling in security designs. As we begin to address this gap, we focused on user authentication where the existing password composition policies and password meters often fail to help users around creating a strong and memorable password. To this end, we conducted a lab study with 19 participants, where we updated our initial designs in an iterative manner based on their feedback. We then conducted a between-subject online study with 104 participants over Amazon Mechanical Turk to evaluate our designs. We found that all of our designs received positive ratings from participants in terms of how they felt confident, and capable in password creation upon interacting with our design. Taken together, the findings from our studies unpacked users’ perceptions and preferences in using storytelling around password creation, where we provide guideline for future research in these directions.
Rizu Paudel, Mahdi N. Al-Ameen
Int. J. Hum. Comput. Interact.1
2024 "...I have my dad, sister, brother, and mom's password": unveiling users' mental models of security and privacy-preserving tools
abstract
Purpose The purpose of this study is to understand user perceptions and misconceptions regarding security tools. Security and privacy-preserving tools (for brevity, the authors term them as “security tools” in this paper, unless otherwise specified) are designed to protect the security and privacy of people in the digital environment. However, inappropriate use of these tools can lead to unexpected consequences that are preventable. Hence, it is significant to examine why users do not understand the security tools. Design/methodology/approach The authors conducted a qualitative study with 40 participants in the USA to investigate the prevalent misconceptions of people regarding security tools, their perceptions of data access and the corresponding impact on their usage behavior and data protection strategies. Findings While security vulnerabilities are often rooted in people’s internet usage behavior, this study examined user’s mental models of the internet and unpacked how the misconceptions about security tools relate to those mental models. Originality/value Based on the findings, this study offers recommendations highlighting the design aspects of security tools that need careful attention from researchers and industry practitioners, to alleviate users’ misconceptions and provide them with accurate conceptual models toward the desired use of security tools.
Prakriti Dumaru, Ankit Shrestha, Rizu Paudel, Cassity Haverkamp, Maryellen Brunson McClain, Mahdi N. Al-Ameen
Inf. Comput. Secur.3
2024 Priming through Persuasion: Towards Secure Password Behavior
abstract
Users tend to create weak passwords even for the important accounts. The prior research shed light on user's insecure password behavior, and why the interventions, including requirement specification (e.g., password composition policies) and feedback systems (e.g., password meters) fail in practice. To this end, we propose and evaluate the concept: priming-through-persuasion in the realm of secure password creation. In particular, we created visual designs, aimed at priming users about the repercussions of weak passwords before their password creation. We base our designs on two forms of persuasion methods: pathos and logos. Pathos appeals to people's emotion in order to persuade them towards an expected behavior, where logos-based rhetoric appeals to a person's sense of reason. We conducted a lab study including participatory design and semi-structured interview with 20 participants. We updated our designs in an iterative manner based on the feedback from our participants in the lab study. To evaluate our updated designs, we conducted a between-subject online study with 131 participants over Amazon Mechanical Turk. Our study provides insight into how the use of persuasion techniques contributed to user attachment and engagement with the design, as well as the comprehension of the conveyed message about password vulnerabilities. Our findings lead to the guideline for future research on leveraging the priming-through-persuasion to complement the existing techniques in encouraging users towards secure behavior.
Rizu Paudel, Mahdi N. Al-Ameen
Proc. ACM Hum. Comput. Interact.1
2024 Leveraging the Power of Storytelling to Encourage and Empower Children towards Strong Passwords
abstract
With the increasing use of computer and smartphones by children, their online safety has been of major concern due to their limited security knowledge and skills. User authentication is pivotal for their security protection, where a body of work focused on children's password practices. The insights from these studies highlight children's lack of awareness and skills in creating a strong password. However, there is a dearth in existing literature to understand the scopes of designs for encouraging and empowering children towards strong passwords. As we begin to address this gap, we leveraged the power of storytelling to foster user attachment, encouragement, and empowerment. To this end, we adopted a systematic approach through a series of studies. First, a focus group session with three experts whose research primarily focuses on children contributed to build the narrative of a story, followed by a participatory design study with 20 children (aged between 8 and 12) to understand their preferences and perceptions of design components for the visual depiction of that narrative. The insights from focus group and participatory design led to the design of 'Story', a digital storytelling based design representing password advice for children. We also created the baseline designs and compared them with Story in a within-subject survey with 44 children aged between 8 and 12. The findings from our study unpack the efficacy of storytelling, leading us to offer guidelines for future research in these directions.
Rizu Paudel, Mahdi N. Al-Ameen
Proc. ACM Hum. Comput. Interact.1
2023 A Deep Dive into User's Preferences and Behavior around Mobile Phone Sharing
abstract
Users share their personal devices with different entities in various circumstances. While prior research shed light on the broad reasons behind the sharing of mobile phones, there is a dearth of systematic study to understand the user's decision-making process and the underlying preferences and concerns in the context of phone sharing. To address these gaps, we designed a prototype that we leveraged to investigate the interplay between a user's relationship with sharees, preferences of sharing a subset of apps with a certain entity, perceived sensitivity of the apps being shared, and how these factors relate to their authentication behavior. We conducted a multi-session study with 50 participants from three countries (USA, Turkey, and Nepal), where the participants interacted with our prototype and took part in semi-structured interviews. The findings from our study revealed the need for phone sharing at a granular level, where we identified the factors that could influence a user's decision-making process in sharing. Our analysis unpacked the relation between a user's perceived sensitivity of apps being shared, and authentication behavior to protect information from unauthorized access. Overall, our findings advance the CSCW community's understanding of how the user attains a balance between privacy protection and the need for phone sharing.
Rizu Paudel, Prakriti Dumaru, Ankit Shrestha, Huzeyfe Kocabas, Mahdi N. Al-Ameen
Proc. ACM Hum. Comput. Interact.1
2022 Understanding the Behavior, Challenges, and Privacy Risks in Digital Technology Use by Nursing Professionals
abstract
With the growing adoption of digital technology in healthcare organizations, it is important to understand nursing professionals' behavior and challenges, and the corresponding privacy implications around digital technology use. To this end, we conducted semi-structured interviews with 21 participants (16 nursing professionals, and five nursing faculties) in the USA. In our study with nursing professionals, we explored how they used digital technology and protected sensitive health data at their workplace. We investigated their understanding of privacy breaches and possible consequences, the challenges they encountered to maintaining privacy, and their workarounds to deal with such issues. We looked into the support that professional nurses receive in the form of organizational training, and how they collaborate with the IT department at their institution to address technical issues. In addition, we shed light on the gap between their academic preparation and professional needs in the context of digital technology use and privacy protection, where we also interviewed five nursing faculties to get more in-depth understanding of this issue from the point of view of academia. Overall, our findings provide valuable insights for the CSCW community to better understand the challenges and privacy risks in digital technology use by nursing professionals, and lead to our recommendations to address these issues.
Ankit Shrestha, Danielle M. Graham, Prakriti Dumaru, Rizu Paudel, Kristin A. Searle, Mahdi N. Al-Ameen
Proc. ACM Hum. Comput. Interact.4