VLDB 2026 Research / reviewers in the wild / expert
Yukiko Sawaya
dblp:43/10041
· DBLP profile ↗
11ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-0432-2256ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploring Factors of Organizational Culture that Promote Adherence to Security Rules
Yukiko Sawaya, Takamasa Isohara, Ayumu Kubota, Ayako Komatsu |
ICISSP (1) | 1 |
| 2026 | Accurate, Generalizable, and Practical Behavioral Models to Identify Impending User Exposure to Malicious WebsitesabstractTo keep users safe online, current protections frequently employ blocklists of known malware and phishing websites. However, such defenses suffer from an inherent gap between malicious content creation and its detection, leaving a window where users are left vulnerable. To address this limitation, earlier research has shown that one could use individual user web browsing behavior to identify imminent exposure to malicious content. While existing methods frequently rely on temporal proximity (e.g., aggregating browsing patterns over the recent past), they do not leverage temporal ordering in user browsing, which results in suboptimal performance and is, in practice, inadequate given the low base rates of malware incidence. We introduce network and browser-level features (e.g., page rank, tab browsing time) and a temporal model that captures user behavior through a time-series representation. This not only improves classification performance by a significant margin (between 93% and 145% F1-score improvements) over previous models, but also maintains strong robustness across completely disparate sets of users. More importantly, our method shows strong resilience to concept drift, as performance holds steady over multiple years of testing. We discuss how this method is capable of anticipating future exposure. We also assess the relative importance of each feature to the performance, as well as their impact on false positive rates—whose minimization is critical to foster adoption. Finally, we discuss use cases for such behavior-based models. Jin-Dong Dong, Kyle Crichton, Akira Yamada 0001, Yukiko Sawaya, Lorrie Faith Cranor, Nicolas Christin |
ACM Trans. Web | 4 |
| 2025 | Do Regularly Personalized Security Messages Cause Habituation?
Ayane Sano, Yukiko Sawaya, Takamasa Isohara, Vanessa Bracamonte, Masakatsu Nishigaki |
AINA (4) | 2 |
| 2024 | Messages and Incentives to Promote Updating of Software on Smartphones
Ayane Sano, Yukiko Sawaya, Takamasa Isohara, Masakatsu Nishigaki |
AINA (4) | 2 |
| 2024 | A High Coverage Cybersecurity Scale Predictive of User Behavior
Yukiko Sawaya, Sarah Lu, Takamasa Isohara, Mahmood Sharif |
USENIX Security Symposium | 1 |
| 2023 | Survey on Recognition of Privacy Risk from Responding on TwitterabstractSocial networking services (SNS) are often the subject of privacy concerns. Hence users should be careful not to post content with unacceptable privacy risks. In order to correctly determine whether a privacy risk is acceptable, the perceived privacy risk must match the actual privacy risk. One of the objectives of this study is to investigate whether the recognition of privacy risk is consistent with the actual privacy risk. This study investigates the posters ’recognition of privacy risk from postings that infer their attributes and regrets about their actions. On the other hand, privacy information can also be leaked from other people’s posts, to which people respond with "Liking" or "Retweeting." Existing methods for analyzing their posts to suppress their posts may not be effective if personal information is leaked from the responses to the contents of others’ posts. In addition, users may be less likely to perceive the risk of privacy information leakage from responses to the contents of others ’ posts than from their posts. Therefore, this study tests the hypothesis that there is a difference between the users’ recognition of privacy risk in posting by themselves and that caused by responding to contents of others’ posts and evaluates the difficulty of recognizing privacy risk caused by responding compared with that by posting. Toru Nakamura, Yukiko Sawaya, Takamasa Isohara |
TrustCom | 2 |
| 2021 | SeBeST: Security Behavior Stage Model and Its Application to OS Update
Ayane Sano, Yukiko Sawaya, Akira Yamada 0001, Ayumu Kubota |
AINA (2) | 2 |
| 2021 | Designing Personalized OS Update Message based on Security Behavior Stage ModelabstractAs one of the scales which assess the end-user’s security behavior, the security behavior stage model (SeBeST) [1] is a practical approach to characterize similar groups of users (precontemplation, contemplation, preparation, action and maintenance stages) and provide customized remedies to improve their security behavior. For example, in OS update message customization, a group that does not update OS continuously may require a message indicating the ease of OS update; on the other hand, updating users need a message indicating the importance of OS update. In this paper, we propose a personalized OS update message interface based on SeBeST. We conduct two online surveys to evaluate effective appearance and message as the personalized user interface (UI). First, we assess the interface’s appearance individually for the three behavior stages (preparation, action, and maintenance) and then combine the customized messages and the selected impressions for these stages. We confirmed that appropriate appearances are different for each stage. For example, a highlighted red button is efficient for users in the preparation stage. On the other hand, the red background is suitable for users of the action and maintenance stages. We discovered that the combination of the message indicating the disadvantage of the OS update and the UI which is the highlighted red button is suitable for the preparation and action stages. In addition, we confirmed the best combination for users of the maintenance stage is a message indicating the ease of OS update and the UI which is mouse over pop-up representation. Therefore, it is necessary for each user to show the appropriate message and UI. Ayane Sano, Yukiko Sawaya, Akira Yamada 0001, Ayumu Kubota, Takamasa Isohara |
PST | 2 |
| 2020 | Human Factors in Homograph Attack Recognition
Tran Thao Phuong, Yukiko Sawaya, Hoang-Quoc Nguyen-Son, Akira Yamada 0001, Ayumu Kubota, Tran Van Sang, Rie Shigetomi Yamaguchi |
ACNS (2) | 2 |
| 2019 | Hunting Brand Domain Forgery: A Scalable Classification for Homograph Attack
Tran Thao Phuong, Yukiko Sawaya, Hoang-Quoc Nguyen-Son, Akira Yamada 0001, Kazumasa Omote, Ayumu Kubota |
SEC | 2 |
| 2017 | Self-Confidence Trumps Knowledge: A Cross-Cultural Study of Security BehaviorabstractComputer security tools usually provide universal solutions without taking user characteristics (origin, income level, ...) into account. In this paper, we test the validity of using such universal security defenses, with a particular focus on culture. We apply the previously proposed Security Behavior Intentions Scale (SeBIS) to 3,500 participants from seven countries. We first translate the scale into seven languages while preserving its reliability and structure validity. We then build a regression model to study which factors affect participants' security behavior. We find that participants from different countries exhibit different behavior. For instance, participants from Asian countries, and especially Japan, tend to exhibit less secure behavior. Surprisingly to us, we also find that actual knowledge influences user behavior much less than user self-confidence in their computer security knowledge. Stated differently, what people think they know affects their security behavior more than what they do know. Yukiko Sawaya, Mahmood Sharif, Nicolas Christin, Ayumu Kubota, Akihiro Nakarai, Akira Yamada 0001 |
CHI | 1 |