VLDB 2026 Research / reviewers in the wild / expert
Nico Ebert
dblp:38/3058
· DBLP profile ↗
6ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0002-9683-4792ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Chatbot Confessions:~Large-Scale Analysis of Private Data Disclosure in Shared AI Chatbot ConversationsabstractThe proliferation of AI conversation platforms has introduced unprecedented privacy risks through user-shared conversations. This paper presents a comprehensive analysis of privacy vulnerabilities in shared conversations across three major LLM platforms: ChatGPT, Microsoft Copilot, and Google Gemini. We collected and analyzed 100 342 conversations using an automated LLM-based privacy detection pipeline enhanced with a defined risk scoring system and the LINDDUN threat modeling framework. Our analysis identifies 8 131 conversations (8%) to incur privacy risks deriving from the disclosure of private and sensitive data including user identifiers (49%) and user location data (40%), yet in some cases also financial (4%), health (3%) and authentication data such as access tokens (3%). Through systematic analysis of conversation length and temporal disclosure patterns, we demonstrate that extended conversations exhibit higher privacy risk rates compared to brief interactions. Notably, 60% of private data disclosures in longer con- versation occur in the final quartile of these conversations, which may indicate that users progressively lose privacy awareness as interactions deepen. Our findings have immediate implications for platform designers and policymakers, highlighting the need for proactive interventions including real-time privacy warnings, pre- share scanning, and clearer education about the permanence and discoverability of shared conversation links. Majid Mollaeefar, Dimitri Van Landuyt, Gertjan Franken, Nico Ebert, Silvio Ranise |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | QButterfly: Lightweight Survey Extension for Online User Interaction Studies for Non-Tech-Savvy ResearchersabstractWe provide a user-friendly, flexible, and lightweight open-source HCI toolkit (github.com/QButterfly) that allows non-tech-savvy researchers to conduct online user interaction studies using the widespread Qualtrics and LimeSurvey platforms. These platforms already provide rich functionality (e.g., for experiments or usability tests) and therefore lend themselves to an extension to display stimulus web pages and record clickstreams. The toolkit consists of a survey template with embedded JavaScript, a JavaScript library embedded in the HTML web pages, and scripts to analyze the collected data. No special programming skills are required to set up a study or match survey data and user interaction data after data collection. We empirically validated the software in a laboratory and a field study. We conclude that this extension, even in its preliminary version, has the potential to make online user interaction studies (e.g., with crowdsourced participants) accessible to a broader range of researchers. Nico Ebert, Björn Scheppler, Kurt Alexander Ackermann, Tim Geppert |
CHI | 1 |
| 2023 | Learning from safety science: A way forward for studying cybersecurity incidents in organizationsabstractIn the aftermath of cybersecurity incidents within organizations, explanations of their causes often revolve around isolated technical or human events such as an Advanced Persistent Threat or a “bad click by an employee.” These explanations serve to identify the responsible parties and inform efforts to improve security measures. However, safety science researchers have long been aware that explaining incidents in socio-technical systems and determining the role of humans and technology in incidents is not an objective procedure but rather an act of social constructivism: what you look for is what you find, and what you find is what you fix. For example, the search for a technical “root cause” of an incident might likely result in a technical fix, while from a sociological perspective, cultural issues might be blamed for the same incident and subsequently lead to the improvement of the security culture. Starting from the insights of safety science, this paper aims to extract lessons on what general explanations for cybersecurity incidents can be identified and what methods can be used to study causes of cybersecurity incidents in organizations. We provide a framework that allows researchers and practitioners to proactively select models and methods for the investigation of cybersecurity incidents. Nico Ebert, Thierry Schaltegger, Benjamin Ambuehl, Lorin Schöni, Verena Zimmermann, Melanie Knieps |
Comput. Secur. | 1 |
| 2023 | Creative beyond TikToks: Investigating Adolescents' Social Privacy Management on TikTokabstractTikTok has been criticized for its low privacy standards, but little is known about how its adolescent users protect their privacy. Based on interviews with 54 adolescents in Switzerland, this study provides a comprehensive understanding of young TikTok users' privacy management practices related to the creation of videos. The data were explored using the COM-B model, an established behavioral analysis framework adapted for sociotechnical privacy research. Our overall findings are in line with previous research on other social networks: adolescents are aware of privacy related to their online social connections (social privacy) and perform conscious privacy management. However, we also identified new patterns related to the central role of algorithmic recommendations potentially relevant for other social networks. Adolescents are aware that TikTok's special algorithm, combined with the app's high prevalence among their peers, could easily put them in the spotlight. Some adolescents also reduce TikTok, which was originally conceived as a social network, to its extensive audio-visual capabilities and share TikToks via more private channels (e.g., Snapchat) to manage audiences and avoid identification by peers. Young users also find other creative ways to protect their privacy such as identifying stalkers or maintaining multiple user accounts with different privacy settings to establish granular audience management. Based on our findings, we propose various concrete measures to develop interventions that protect the privacy of adolescents on TikTok. Nico Ebert, Tim Geppert, Joanna Strycharz, Melanie Knieps, Michael Hönig, Elke Brucker-Kley |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Bolder is Better: Raising User Awareness through Salient and Concise Privacy NoticesabstractThis paper addresses the question whether the recently proposed approach of concise privacy notices in apps and on websites is effective in raising user awareness. To assess the effectiveness in a realistic setting, we included concise notices in a fictitious but realistic fitness tracking app and asked participants recruited from an online panel to provide their feedback on the usability of the app as a cover story. Importantly, after giving feedback, users were also asked to recall the data practices described in the notices. The experimental setup included the variation of different levels of saliency and riskiness of the privacy notices. Based on a total sample of 2,274 participants, our findings indicate that concise privacy notices are indeed a promising approach to raise user awareness for privacy information when displayed in a salient way, especially in case the notices describe risky data practices. Our results may be helpful for regulators, user advocates and transparency-oriented companies in creating or enforcing better privacy transparency towards average users that do not read traditional privacy policies. Nico Ebert, Kurt Alexander Ackermann, Björn Scheppler |
CHI | 1 |
| 2020 | Does Context in Privacy Communication Really Matter? - A Survey on Consumer Concerns and PreferencesabstractPrivacy policies as a means of communicating with customers still prove ineffective. Researchers have recently suggested that a specific usage context should be considered to make privacy notices more relevant to users. To explore this approach further, we conducted an explorative online survey of privacy concerns and privacy information preferences with 642 participants for two different contexts (loyalty cards and fitness tracking). Our data shows some support for the suggestion that context may be a significant moderator of concerns and preferences. However, the corresponding effects are rather small and limited to specific concerns and information categories. In line with other research, the data supports the known hierarchy of concerns regarding unauthorized secondary use and improper data access, which seem to exceed concerns about erroneous data processing or excessive data collection in both contexts. Furthermore, participants considered information on personal rights and processing purposes more relevant than information on contact persons. Nico Ebert, Kurt Alexander Ackermann, Peter Heinrich |
CHI | 1 |