VLDB 2026 Research / reviewers in the wild / expert
Sauvik Das
dblp:83/8570
· DBLP profile ↗
49ranked-venue papers
10as first author
31since 2021 · last 2026
0000-0002-9073-8054ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 37 · 9 first-author · 21 since 2021Security and privacy · 14 · 2 first-author · 10 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Supporting Informed Self-Disclosure: Design Recommendations for Presenting AI-Estimates of Privacy Risks to UsersabstractPeople candidly discuss sensitive topics online under the perceived safety of anonymity; yet, for many, this perceived safety is tenuous, as miscalibrated risk perceptions can lead to over-disclosure. Recent advances in Natural Language Processing (NLP) afford an unprecedented opportunity to present users with quantified disclosure-based re-identification risk — i.e., “population risk estimates” (PREs). How can PREs be presented to users in a way that promotes informed decision-making, mitigating risk without encouraging unnecessary self-censorship? Using design fictions and comic-boarding, we story-boarded five design concepts for presenting PREs to users and evaluated them through an online survey with N = 44 Reddit users. We found participants had detailed conceptions of how PREs may impact risk awareness and motivation, but envisioned needing additional context and support to effectively interpret and act on risks. We distill our findings into four key design recommendations for how best to present users with quantified privacy risks to support informed disclosure decision-making. Isadora Krsek, Meryl Ye, Wei Xu 0004, Alan Ritter, Laura A. Dabbish, Sauvik Das |
CHI | 6 |
| 2026 | Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product ConceptsabstractAI creates and exacerbates privacy risks, yet practitioners lack effective resources to identify and mitigate these risks. We present Privy, a tool that guides practitioners without privacy expertise through structured privacy impact assessments to: (i) identify relevant risks in novel AI product concepts, and (ii) propose appropriate mitigations. Privy was shaped by a formative study with 11 practitioners, which informed two versions — one LLM-powered, the other template-based. We evaluated these two versions of Privy through a between-subjects, controlled study with 24 separate practitioners, whose assessments were reviewed by 13 independent privacy experts. Results show that Privy helps practitioners produce privacy assessments that experts deemed high quality: practitioners identified relevant risks and proposed appropriate mitigation strategies. These effects were augmented in the LLM-powered version. Practitioners themselves rated Privy as being useful and usable, and their feedback illustrates how it helps overcome long-standing awareness, motivation, and ability barriers in privacy work. Hao-Ping Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek, Thomas Serban Von Davier, Kyzyl Monteiro, Shivani Agarwal 0008, Jodi Forlizzi, Sauvik Das |
CHI | 10 |
| 2025 | HAIPS '25: First ACM CCS Workshop on Human-Centered AI Privacy and SecurityabstractRecent advances in AI/ML create novel and pressing privacy and security challenges—ranging from using generative AI to create harmful content, to the generation of insecure code by AI coding assistants; from oversharing information with ChatGPT to unexpected privacy leaks by LLM agents. At the same time, AI offers new opportunities to address long-standing end-user privacy and security concerns and empower practitioners to adopt better security and privacy practices. In the inaugural workshop of HAIPS'25, we aim to help build and strengthen a community of people enthusiastic about privacy and security issues related to AI from a human-centered perspective, and foster cross-disciplinary research agendas that effectively engage with the human element when addressing these issues. Tianshi Li 0001, Toby Jia-Jun Li, Yaxing Yao, Sauvik Das |
CCS | 4 |
| 2025 | Of Secrets and Seedphrases: Conceptual Misunderstandings and Security Challenges for Seed Phrase Management among Cryptocurrency Users
Farida Eleshin, Mengzhe Ye, Sauvik Das, Jason I. Hong |
CHI | 4 |
| 2025 | Probabilistic Reasoning with LLMs for Privacy Risk EstimationabstractProbabilistic reasoning is a key aspect of both human and artificial intelligence that allows for handling uncertainty and ambiguity in decision-making. In this paper, we introduce a new numerical reasoning task under uncertainty for large language models, focusing on estimating the privacy risk of user-generated documents containing privacy-sensitive information. We propose BRANCH, a new LLM methodology that estimates the $k$-privacy value of a text—the size of the population matching the given information. BRANCH factorizes a joint probability distribution of personal information as random variables. The probability of each factor in a population is estimated separately using a Bayesian network and combined to compute the final $k$-value. Our experiments show that this method successfully estimates the $k$-value 73% of the time, a 13% increase compared to o3-mini with chain-of-thought reasoning. We also find that LLM uncertainty is a good indicator for accuracy, as high variance predictions are 37.47% less accurate on average. Jonathan Zheng, Alan Ritter, Sauvik Das, Wei (Coco) Xu |
NeurIPS | 3 |
| 2025 | Transformational Provocations for Usable Privacy and Security: Designing Beyond Compliance and Expert NormsabstractA long standing goal of usable privacy and security (UPS) research is to align end-user behaviors with expert suggestions, such as through developing tools to increase user control and awareness of security and privacy (S&P) threats. These approaches, while necessary, are not sufficient to combat the ubiquitous slow violence of S&P harms that impede on people’s motivation to change and erode their trust in the institutions in which experts are often entrenched. We propose that we can only effect true change and rebuild trust with users if we first deconstruct our norms of telling users what’s best and expecting them to comply. We draw from concepts in critical computing, design, and games research, to propose a research agenda—“Transformational Provocation”—that involves provoking transformation in not just users’ S&P knowledge, skills, or behaviors, but also their senses of truth, self, relationships, and society. Moreover, we demonstrate the value and application of our framework through illustrative case studies. With this framework, we call upon the UPS community to pursue new design opportunities for engendering organic and enduring intrinsic motivation for people to act on their S&P, both on their own and together. Alexandra To, Emilee Rader, W. Keith Edwards, Sauvik Das |
NSPW | 5 |
| 2025 | Imago Obscura: An Image Privacy AI Co-pilot to Enable Identification and Mitigation of Risks
Kyzyl Monteiro, Sauvik Das |
UIST | 3 |
| 2025 | Measuring, Modeling, and Helping People Account for Privacy Risks in Online Self-Disclosures with AIabstractIn pseudonymous online fora like Reddit, the benefits of self-disclosure are often apparent to users (e.g., I can vent about my in-laws to understanding strangers), but the privacy risks are more abstract (e.g., will my partner be able to tell that this is me?). Prior work has sought to develop natural language processing (NLP) tools that help users identify potentially risky self-disclosures in their text, but none have been designed for or evaluated with the users they hope to protect. Absent this assessment, these tools will be limited by the social-technical gap: users need assistive tools that help them make informed decisions, not paternalistic tools that tell them to avoid self-disclosure altogether. To bridge this gap, we conducted a study with N =21 Reddit users; we had them use a state-of-the-art NLP disclosure detection model on two of their authored posts and asked them questions to understand if and how the model helped, where it fell short, and how it could be improved to help them make more informed decisions. Despite its imperfections, users responded positively to the model and highlighted its use as a tool that can help them catch mistakes, inform them of risks they were unaware of, and encourage self-reflection. However, our work also shows how, to be useful and usable, AI for supporting privacy decision-making must account for posting context, disclosure norms, and users' lived threat models, and provide explanations that help contextualize detected risks. Isadora Krsek, Anubha Kabra, Yao Dou, Tarek Naous, Laura A. Dabbish, Alan Ritter, Wei Xu 0004, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 8 |
| 2025 | Design(ing) Fictions for Collective Civic Reporting of Privacy HarmsabstractIndividually-experienced privacy harms are often difficult to demonstrate and quantify, which impedes efforts for their redress. Their effects often appear small and are inconsistently documented, and they only become more obvious when aggregated over time and across populations. Taking a design fiction approach, we explore the design requirements and cultural ideals of a government-run system that empowers people to collectively report on and make sense of experiences of privacy harm from online behavioral advertising. Through the use of fictional inquiry, story completion, and comicboarding methods, delivered in an online survey with 50 participants, we found that participants had detailed conceptions of the user experience of such a tool, but wanted assurance that their labor and personal data would not be exploited further by the government if they contributed evidence of harm. We extrapolate these design insights to government-supported complaint-reporting platforms in other domains, finding multiple common design gaps that might disincentivize people to report experiences of harm, be they privacy-related or otherwise. William Agnew, W. Keith Edwards, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2025 | Purpose Mode: Reducing Distraction through Toggling Attention Capture Damaging Patterns on Social Media Web SitesabstractSocial media websites thrive on user engagement by employing Attention Capture Damaging Patterns (ACDPs), e.g., infinite scroll, that prey on cognitive vulnerabilities to distract users. Prior work has taxonomized these ACDPs, but we have yet to measure how the presence of ACDPs impacts perceived distraction nor how mechanisms that suppress ACDPs reduce distraction. We conducted a two-week, mixed-methods field study with 29 participants to model how people get distracted when browsing social media websites, and how ACDPs might play a role. In the first week of the study, we sample participants’ in-situ perceptions of distraction, subjective perceptions of the browsing session (e.g., satisfaction), and the presence/absence of ACDPs. Participants reported feeling distracted 28% of the time, and that subjective perceptions and some ACDPs (e.g., notifications) highly correlated with when they felt distracted. In the second week of the study, participants were given access to Purpose Mode — a browser extension that allows users to “toggle off” ACDPs. Participants reported feeling distracted only 7% of the time and spent 21 fewer daily minutes browsing these websites. We discovered that Purpose Mode empowered users to feel more in control over their social media browsing and made participants feel less irritated and frustrated. Hao-Ping Lee, Yi-Shyuan Chiang, Lan Gao 0001, Stephanie S. Yang, Philipp Winter, Sauvik Das |
ACM Trans. Comput. Hum. Interact. | 6 |
| 2024 | Reducing Privacy Risks in Online Self-Disclosures with Language ModelsabstractYao Dou, Isadora Krsek, Tarek Naous, Anubha Kabra, Sauvik Das, Alan Ritter, Wei Xu. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Yao Dou, Isadora Krsek, Tarek Naous, Anubha Kabra, Sauvik Das, Alan Ritter, Wei Xu 0004 |
ACL (1) | 5 |
| 2024 | Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy RisksabstractPrivacy is a key principle for developing ethical AI technologies, but how does including AI technologies in products and services change privacy risks? We constructed a taxonomy of AI privacy risks by analyzing 321 documented AI privacy incidents. We codified how the unique capabilities and requirements of AI technologies described in those incidents generated new privacy risks, exacerbated known ones, or otherwise did not meaningfully alter the risk. We present 12 high-level privacy risks that AI technologies either newly created (e.g., exposure risks from deepfake pornography) or exacerbated (e.g., surveillance risks from collecting training data). One upshot of our work is that incorporating AI technologies into a product can alter the privacy risks it entails. Yet, current approaches to privacy-preserving AI/ML (e.g., federated learning, differential privacy, checklists) only address a subset of the privacy risks arising from the capabilities and data requirements of AI. Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, Sauvik Das |
CHI | 5 |
| 2024 | "Don't put all your eggs in one basket": How Cryptocurrency Users Choose and Secure Their WalletsabstractCryptocurrency wallets come in various forms, each with unique usability and security features. Through interviews with 24 users, we explore reasons for selecting wallets in different contexts. Participants opt for smart contract wallets to simplify key management, leveraging social interactions. However, they prefer personal devices over individuals as guardians to avoid social cybersecurity concerns in managing guardian relationships. When engaging in high-stakes or complex transactions, they often choose browser-based wallets, leveraging third-party security extensions. For simpler transactions, they prefer the convenience of mobile wallets. Many participants avoid hardware wallets due to usability issues and security concerns with respect to key recovery service provided by manufacturer and phishing attacks. Social networks play a dual role: participants seek security advice from friends, but also express security concerns in soliciting this help. We offer novel insights into how and why users adopt specific wallets. We also discuss design recommendations for future wallet technologies based on our findings. Yaman Yu, Tanusree Sharma, Sauvik Das, Yang Wang 0005 |
CHI | 3 |
| 2024 | "It's a Fair Game", or Is It? Examining How Users Navigate Disclosure Risks and Benefits When Using LLM-Based Conversational AgentsabstractThe widespread use of Large Language Model (LLM)-based conversational agents (CAs), especially in high-stakes domains, raises many privacy concerns. Building ethical LLM-based CAs that respect user privacy requires an in-depth understanding of the privacy risks that concern users the most. However, existing research, primarily model-centered, does not provide insight into users’ perspectives. To bridge this gap, we analyzed sensitive disclosures in real-world ChatGPT conversations and conducted semi-structured interviews with 19 LLM-based CA users. We found that users are constantly faced with trade-offs between privacy, utility, and convenience when using LLM-based CAs. However, users’ erroneous mental models and the dark patterns in system design limited their awareness and comprehension of the privacy risks. Additionally, the human-like interactions encouraged more sensitive disclosures, which complicated users’ ability to navigate the trade-offs. We discuss practical design guidelines and the needs for paradigm shifts to protect the privacy of LLM-based CA users. Michelle Jia, Hao-Ping Lee, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, Tianshi Li 0001 |
CHI | 5 |
| 2024 | Granular Privacy Control for Geolocation with Vision Language ModelsabstractVision Language Models (VLMs) are rapidly advancing in their capability to answer information-seeking questions. As these models are widely deployed in consumer applications, they could lead to new privacy risks due to emergent abilities to identify people in photos, geolocate images, etc. As we demonstrate, somewhat surprisingly, current open-source and proprietary VLMs are very capable image geolocators, making widespread geolocation with VLMs an immediate privacy risk, rather than merely a theoretical future concern. As a first step to address this challenge, we develop a new benchmark, GPTGeoChat, to test the capability of VLMs to moderate geolocation dialogues with users. We collect a set of 1,000 image geolocation conversations between in-house annotators and GPT-4v, which are annotated with the granularity of location information revealed at each turn. Using this new dataset we evaluate the ability of various VLMs to moderate GPT-4v geolocation conversations by determining when too much location information has been revealed. We find that custom fine-tuned models perform on par with prompted API-based models when identifying leaked location information at the country or city level, however fine-tuning on supervised data appears to be needed to accurately moderate finer granularities, such as the name of a restaurant or building. Ethan Mendes, Yang Chen 0065, James Hays, Sauvik Das, Wei Xu 0004, Alan Ritter |
EMNLP | 4 |
| 2024 | "I Don't Know If We're Doing Good. I Don't Know If We're Doing Bad": Investigating How Practitioners Scope, Motivate, and Conduct Privacy Work When Developing AI Products
Hao-Ping Lee, Lan Gao 0001, Stephanie S. Yang, Jodi Forlizzi, Sauvik Das |
USENIX Security Symposium | 5 |
| 2024 | The Subversive AI Acceptance Scale (SAIA-8): A Scale to Measure User Acceptance of AI-Generated, Privacy-Enhancing Image ModificationsabstractTo resist government and corporate use of facial recognition to surveil users through their personal images, researchers have created privacy-enhancing image filters that use adversarial machine learning. These "subversive AI'' (SAI) image filters aim to defend users from facial recognition by distorting personal images in ways that are barely noticeable to humans but confusing to computer vision algorithms. SAI filters are limited, however, by the lack of rigorous user evaluation that assess their acceptability. We addressed this limitation by creating and validating a scale to measure user acceptance --- the SAIA-8. In a three-step process, we apply a mixed-methods approach that closely adhered to best practices for scale creation and validation in measurement theory. Initially, to understand the factors that influence user acceptance of SAI filter outputs, we interviewed 15 participants. Interviewees disliked extant SAI filter outputs because of a perceived lack of usefulness and conflicts with their desired self-presentation. Using insights and statements from the interviews, we generated 106 potential items for the scale. Employing an iterative refinement and validation process with 245 participants from Prolific, we arrived at the SAIA-8 scale: a set of eight items that capture user acceptability of privacy-enhancing perturbations to personal images, and that can aid in benchmarking and prioritizing user acceptability when developing and evaluating new SAI filters. Jacob Logas, Poojita Garg, Rosa I. Arriaga, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2023 | GuardLens: Supporting Safer Online Browsing for People with Visual Impairments
Smirity Kaushik, Natã M. Barbosa, Yaman Yu, Tanusree Sharma, Zachary Kilhoffer, Jooyoung Seo, Sauvik Das, Yang Wang 0005 |
SOUPS | 7 |
| 2023 | ImageAlly: A Human-AI Hybrid Approach to Support Blind People in Detecting and Redacting Private Image Content
Zhuohao (Jerry) Zhang, Smirity Kaushik, Jooyoung Seo, Haolin Yuan, Sauvik Das, Leah Findlater, Danna Gurari, Abigale Stangl, Yang Wang 0005 |
SOUPS | 5 |
| 2023 | Iterative Design of An Accessible Crypto Wallet for Blind Users
Kyrie Zhixuan Zhou, Tanusree Sharma, Luke Emano, Sauvik Das, Yang Wang 0005 |
SOUPS | 4 |
| 2023 | When and Why Do People Want Ad Targeting Explanations? Evidence from a Four-Week, Mixed-Methods Field StudyabstractMany people are concerned about how their personal data is used for online behavioral advertising (OBA). Ad targeting explanations have been proposed as a way to reduce this concern by improving transparency. However, it is unclear when and why people might want ad targeting explanations. Without this insight, we run the risk of designing explanations that do not address real concerns. To bridge this gap, we conducted a four-week, mixed-methods field study with 60 participants to understand when and why people want targeting explanations for the ads they actually encountered while browsing the web. We found that users wanted explanations for around 30% of the 4,251 ads we asked them about during the study, and that subjective perceptions of how their personal data was collected and shared were highly correlated with when users wanted ad explanations. Often, users wanted these explanations to confirm or deny their own preconceptions about how their data was collected or the motives of advertisers. A key upshot of our work is that one-size-fits-all approaches to ad explanations are likely to fail at addressing people’s lived concerns about ad targeting; instead, more personalized explanations are needed. Hao-Ping Lee, Jacob Logas, Stephanie S. Yang, Zhouyu Li, Natã M. Barbosa, Yang Wang 0005, Sauvik Das |
SP | 7 |
| 2023 | Powering for Privacy: Improving User Trust in Smart Speaker Microphones with Intentional Powering and Perceptible Assurance
Youngwook Do, Nivedita Arora, Ali Mirzazadeh, Injoo Moon, Eryue Xu, Zhihan Zhang 0002, Gregory D. Abowd, Sauvik Das |
USENIX Security Symposium | 8 |
| 2022 | To Self-Persuade or be Persuaded: Examining Interventions for Users' Privacy Setting SelectionabstractUser adoption of security and privacy (S&P) best practices remains low, despite sustained efforts by researchers and practitioners. Social influence is a proven method for guiding user S&P behavior, though most work has focused on studying peer influence, which is only possible with a known social graph. In a study of 104 Facebook users, we instead demonstrate that crowdsourced S&P suggestions are significantly influential. We also tested how reflective writing affected participants’ S&P decisions, with and without suggestions. With reflective writing, participants were less likely to accept suggestions — both social and Facebook default suggestions. Of particular note, when reflective writing participants were shown the Facebook default suggestion, they not only rejected it but also (unknowingly) configured their settings in accordance with expert recommendations. Our work suggests that both non-personal social influence and reflective writing can positively influence users’ S&P decisions, but have negative interactions. Isadora Krsek, Kimi Wenzel, Sauvik Das, Jason I. Hong, Laura A. Dabbish |
CHI | 3 |
| 2022 | "A Reasonable Thing to Ask For": Towards a Unified Voice in Privacy Collective ActionabstractPeople feel concerned, angry, and powerless when subjected to surveillance, data breaches and other privacy-violating experiences with institutions (PVEIs). Collective action may empower groups of people affected by a PVEI to jointly demand redress, but a necessary first step is for the collective to agree on demands. We designed a sensitizing prototype to explore how to shepherd a collective to generate a unified set of demands for redress in response to a triggering PVEI. We found that collectives can converge on high-priority concerns and demands for redress, and that many of their demands indicated preferences for broad reform. We then gathered a panel of security and privacy experts to react to the collective’s demands. Experts were dismissive, preferring incremental measures that cleanly mapped onto existing legal structures. We argue this misalignment may help uphold the power chasm between data-harvesting institutions and the individuals whose personal data they monetize. W. Keith Edwards, Sauvik Das |
CHI | 3 |
| 2022 | SoK: Social CybersecurityabstractWe analyze prior work in social cybersecurity and present a structuring of this literature based on its pertinence to four S&P-relevant social behaviors: (1) negotiating access to shared resources, (2) shared and social authentication, (3) managing self-presentation, and (4) influencing others’ S&P behaviors. We further break down these domains into four scales of social distance—intimate, personal, social, and public— showing that desired access control policies, authentication methods, and privacy and sharing preferences vary across these social scales. We evaluate the current landscape of work through the lens of Ackerman’s social-technical gap in social computing systems, finding that while social behaviors clearly impact S&P preferences and needs, existing S&P systems are designed with little understanding of these behaviors. This mismatch forces users to choose between implementing their ideal S&P policies or reducing social friction. To address this mismatch, we outline a research agenda for social cybersecurity work that better aligns S&P goals with social needs, preferences and behaviors. W. Keith Edwards, Sauvik Das |
SP | 3 |
| 2022 | "How Do You Not Lose Friends?": Synthesizing a Design Space of Social Controls for Securing Shared Digital Resources Via Participatory Design Jams
Eyitemi Moju-Igbene, Hanan Abdi, Alan Lu, Sauvik Das |
USENIX Security Symposium | 4 |
| 2022 | Image DePO: Towards Gradual Decentralization of Online Social Networks using Decentralized Privacy OverlaysabstractCentralized online social networks --- e.g., Facebook, Twitter and TikTok --- help drive social connection on the Internet, but have nigh unfettered access to monitor and monetize the personal data of their users. This centralization can especially undermine the use of the social internet by minority populations, who disproportionately bear the costs of institutional surveillance. We introduce a new class of privacy-enhancing technology --- decentralized privacy overlays (DePOs) --- that helps cOSN users regain some control over their personal data by allowing them to selectively share secret content on cOSNs through decentralized content distribution networks. As a first step, we present an implementation and user evaluation of Image DePO, a proof-of-concept design probe that allows users to upload and share secret photos on Facebook through the Interplanetary File System peer-to-peer protocol. We qualitatively evaluated Image DePO in a controlled, test environment with 19 queer and Black, Indigenous, (and) Person of Color (BIPOC) participants. We found that while Image DePO could help address the institutional threats with which our participants expressed concern, interpersonal threats were the more salient concern in their decisions to share content. Accordingly, we argue that in order to see widespread use, DePOs must align protection against abstract institutional threats with protection against the more salient interpersonal threats users consider when making specific sharing decisions. Jacob Logas, Ari Schlesinger, Zhouyu Li, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Spidey Sense: Designing Wrist-Mounted Affective Haptics for Communicating Cybersecurity WarningsabstractImproving end-users’ awareness of cybersecurity warnings (e.g., phishing and malware alerts) remains a longstanding problem in usable security. Prior work suggests two key weaknesses with existing warnings: they are primarily communicated via saturated communication channels (e.g., visual, auditory, and vibrotactile); and, they are communicated rationally, not viscerally. We hypothesized that wrist-based affective haptics should address both of these weaknesses in a form-factor that is practically deployable: i.e., as a replaceable wristband compatible with modern smartwatches like the Apple Watch. To that end, we designed and implemented Spidey Sense, a wristband that produces customizable squeezing sensations to alert users to urgent cybersecurity warnings. To evaluate Spidey Sense, we applied a three-phased ‘Gen-Rank-Verify’ study methodology with 48 participants. We found evidence that, relative to vibrotactile alerts, Spidey Sense was considered more appropriate for the task of alerting people to cybersecurity warnings. Youngwook Do, Linh Thai Hoang, Jung Wook Park, Gregory D. Abowd, Sauvik Das |
Conference on Designing Interactive Systems | 5 |
| 2021 | Bit Whisperer: Enabling Ad-hoc, Short-range, Walk-Up-and-Share Data Transmissions via Surface-restricted AcousticsabstractBluetooth requires device pairing to ensure security in data transmission, encumbering a number of ad-hoc, transactional interactions that require both ease-of-use and “good enough” security: e.g., sharing contact information or secure links to people nearby. We introduce Bit Whisperer, an ad-hoc short-range wireless communication system that enables “walk up and share” data transmissions with “good enough” security. Bit Whisperer transmits data to proximate devices co-located on a solid surface through high frequency, inaudible acoustic signals. The physical surface has two benefits: it enhances acoustic signal transmission by reflecting sound waves as they propagate; and, it makes the domain of communication visible, helping users identify exactly with whom they are sharing data without prior pairing. Through a series of technical evaluations, we demonstrate that Bit Whisperer is robust for common use-cases and secure against likely threats. We also implement three example applications to demonstrate the utility of Whisperer: 1-to-1 local contact sharing, 1-to-N private link sharing to open a secure group chat, and 1-to-N local device authentication. Youngwook Do, Siddhant Singh, Zhouyu Li, Steven R. Craig, Phoebe J. Welch, Chengzhi Shi, Thad Starner, Gregory D. Abowd, Sauvik Das |
UIST | 9 |
| 2021 | Exploring the Utility Versus Intrusiveness of Dynamic Audience Selection on FacebookabstractIn contrast to existing, static audience controls that map poorly onto users' ideal audiences on social networking sites, dynamic audience selection (DAS) controls can make intelligent inferences to help users select their ideal audience given context and content. But does this potential utility outweigh its potential intrusiveness? We surveyed 250 participants to model users' ideal versus their chosen audiences with static controls and found a significant misalignment, suggesting that DAS might provide utility. We then designed a sensitizing prototype that allowed users to select audiences based on personal attributes, content, or context constraints. We evaluated DAS vis-a-vis Facebook's existing audience selection controls through a counterbalanced summative evaluation. We found that DAS's expressiveness, customizability, and scalability made participants feel more confident about the content they shared on Facebook. However, low transparency, distrust in algorithmic inferences, and the emergence of privacy-violating side channels made participants find the prototype unreliable or intrusive. We discuss factors that affected this trade-off between DAS's utility and intrusiveness and synthesize design implications for future audience selection tools. Sindhu Kiranmai Ernala, Stephanie S. Yang, Kristen Wells, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2021 | Individually Vulnerable, Collectively Safe: The Security and Privacy Practices of Households with Older AdultsabstractOlder adults are especially vulnerable to online cybersecurity and privacy (SP) threats, such as phishing, ransomware, and targeted misinformation campaigns. Prior work has suggested that this vulnerability may be addressed with the design of social SP interfaces, such that groups of individuals might work together on behalf of one another to manage SP threats collectively. To this end, we present findings from a qualitative inquiry conducted with older adults and members of technology-rich middle-income households in urban India, where technology users have been shown to engage in relatively more social SP practices. Our research examines the collaborative behaviors enacted by different members of the household for protection from SP threats. In particular, we show how self-appointed family technology managers straddle the line between stewardship and paternalism in their efforts to protect older adults from perceived digital threats. We also offer design implications for supporting collaborative cybersecurity within households based on the insights derived from our analysis. Savanthi Murthy, Karthik S. Bhat, Sauvik Das, Neha Kumar 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2020 | "We Hold Each Other Accountable": Unpacking How Social Groups Approach Cybersecurity and Privacy TogetherabstractDigital resources are often collectively owned and shared by small social groups (e.g., friends sharing Netflix accounts, roommates sharing game consoles, families sharing WhatsApp groups). Yet, little is known about (i) how these groups jointly navigate cybersecurity and privacy (S&P) decisions for shared resources, (ii) how shared experiences influence individual S&P attitudes and behaviors, and (iii) how well existing S&P controls map onto group needs. We conducted group interviews and a supplemental diary study with nine social groups (n=34) of varying relationship types. We identified why, how and what resources groups shared, their jointly construed threat models, and how these factors influenced group strategies for securing shared resources. We also identified missed opportunities for cooperation and stewardship among group members that could have led to improved S&P behaviors, and found that existing S&P controls often fail to meet the needs of these small social groups. Hue Watson, Eyitemi Moju-Igbene, Akanksha Kumari, Sauvik Das |
CHI | 4 |
| 2020 | Tensions between Access and Control in MakerspacesabstractMakerspaces have complex access control requirements and are increasingly protected through digital access control mechanisms (e.g., keycards, transponders). However, it remains unclear how space administrators craft access control policies, how existing technical infrastructures support and fall short of access needs, and how these access control policies impact end-users in a makerspace. We bridge this gap through a mixed-methods, multi-stakeholder study. Specifically, we conducted 16 semi-structured interviews with makerspace administrators across the U.S. along with a survey of 48 makerspace end-users. We found four factors influenced administrators' construction of access control policies: balancing safety versus access; logistics; prior experience; and, the politics of funding. Moreover, administrators often made situational exceptions to their policies: e.g., during demand spikes, to maintain a good relationship with their staff, and if they trusted the user(s) requesting an exception. Conversely, users expressed frustration with the static nature of access control policies, wishing for negotiability and for social nuance to be factored into access decisions. The upshot is that existing mechanisms for access control in makerspaces are often inappropriately static and socially unaware. Jacob Logas, Ruican Zhong, Stephanie Almeida, Sauvik Das |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2019 | The Memory Palace: Exploring Visual-Spatial Paths for Strong, Memorable, Infrequent AuthenticationabstractMany accounts and devices require only infrequent authentication by an individual, and thus authentication secrets should be both secure and memorable without much reinforcement. Inspired by people's strong visual-spatial memory, we introduce a novel system to help address this problem: the Memory Palace. The Memory Palace encodes authentication secrets as paths through a 3D virtual labyrinth navigated in the first-person perspective. We ran two experiments to iteratively design and evaluate the Memory Palace. In the first, we found that visual-spatial secrets are most memorable if navigated in a 3D first-person perspective. In the second, we comparatively evaluated the Memory Palace against Android's 9-dot pattern lock along three dimensions: memorability after one week, resilience to shoulder surfing, and speed. We found that relative to 9-dot, complexity-controlled secrets in the Memory Palace were significantly more memorable after one week, were much harder to break through shoulder surfing, and were not significantly slower to enter. Sauvik Das, David Lu, Joanne Lo, Jason I. Hong |
UIST | 1 |
| 2018 | Breaking! A Typology of Security and Privacy News and How It's SharedabstractNews coverage of security and privacy (S&P) events is pervasive and may affect the salience of S&P threats to the public. To better understand this coverage and its effects, we asked: What types of S&P news come into people's awareness? How do people hear about and share this news? Over two years, we recruited 1999 participants to fill out a survey on emergent S&P news events. We identified four types of S&P news: financial data breaches, corporate personal data breaches, high sensitivity systems breaches, and politicized / activist cybersecurity. These event types strongly correlated with how people shared S&P news-e.g., financial data breaches were shared most (42%), while politicized / activist cybersecurity events were shared least (21%). Furthermore, participants' age, gender and security behavioral intention strongly correlated with how they heard about and shared S&P news-e.g., males more often felt a personal responsibility to share, and older people were less likely to hear about S&P news through conversation. Sauvik Das, Joanne Lo, Laura A. Dabbish, Jason I. Hong |
CHI | 1 |
| 2017 | Thumprint: Socially-Inclusive Local Group Authentication Through Shared Secret KnocksabstractSmall, local groups who share protected resources (e.g., families, work teams, student organizations) have unmet authentication needs. For these groups, existing authentication strategies either create unnecessary social divisions (e.g., biometrics), do not identify individuals (e.g., shared passwords), do not equitably distribute security responsibility (e.g., individual passwords), or make it difficult to share or revoke access (e.g., physical keys). To explore an alternative, we designed Thumprint: inclusive group authentication with a shared secret knock. All group members share one secret knock, but individual expressions of the secret are discernible. We evaluated the usability and security of our concept through two user studies with 30 participants. Our results suggest that (1) individuals who enter the same shared thumprint are distinguishable from one another, (2) that people can enter thumprints consistently over time, and (3) that thumprints are resilient to casual adversaries. Sauvik Das, Gierad Laput, Chris Harrison 0001, Jason I. Hong |
CHI | 1 |
| 2017 | Evolving the Ecosystem of Personal Behavioral DataabstractEveryday, people generate lots of personal data. Driven by the increasing use of online services and widespread adoption of smartphones (owned by 68% of U.S. residents; Anderson, 2015), personal data take many forms, including communications (e.g., e-mail, SMS, Facebook), plans and coordination (e.g., calendars, TripIt, to-do lists), entertainment consumption (e.g., YouTube, Spotify, Netflix), finances (e.g., banking, Amazon, eBay), activities (e.g., steps, runs, check-ins), and even health care (e.g., doctor visits, medications, heart rate). Collectively, these data provide a highly detailed description of an individual. Personal data afford the opportunity for many new kinds of applications that might improve people’s lives through deep personalization, tools to manage personal well-being, and services that support identity construction. However, developers currently encounter challenges working with personal data due to its fragmentation across services. This article evaluates the landscape of personal data, including the systemic forces that created current fragmented collections of data and the process required for integrating data from across services into an application. It details challenges the fragmented ecosystem imposes. Finally, it contributes Phenom, an experimental system that addresses these challenges, making it easier to develop applications that access personal data and providing users with greater control over how their data are used. Jason Wiese, Sauvik Das, Jason I. Hong, John Zimmerman |
Hum. Comput. Interact. | 2 |
| 2016 | A Market in Your Social Network: The Effects of Extrinsic Rewards on Friendsourcing and RelationshipsabstractFriendsourcing consists of broadcasting questions and help requests to friends on social networking sites. Despite its potential value, friendsourcing requests often fall on deaf ears. One way to improve response rates and motivate friends to undertake more effortful tasks may be to offer extrinsic rewards, such as money or a gift, for responding to friendsourcing requests. However, past research suggests that these extrinsic rewards can have unintended consequences, including undermining intrinsic motivations and undercutting the relationship between people. To explore the effects of extrinsic reward on friends' response rate and perceived relationship, we conducted an experiment on a new friendsourcing platform - Mobilyzr. Results indicate that large extrinsic rewards increase friends' response rates without reducing the relationship strength between friends. Additionally, the extrinsic rewards allow requesters to explain away the failure of friendsourcing requests and thus preserve their perceptions of relationship ties with friends. Haiyi Zhu, Sauvik Das, Yiqun Cao, Aniket Kittur, Robert E. Kraut |
CHI | 2 |
| 2016 | Epistenet: facilitating programmatic access & processing of semantically related mobile personal dataabstractEffective use of personal data is a core utility of modern smartphones. On Android, several challenges make developing compelling personal data applications difficult. First, personal data is stored in isolated silos. Thus, relationships between data from different providers are missing, data must be queried by source of origin rather than meaning and the persistence of different types of data differ greatly. Second, interfaces to these data are inconsistent and complex. In turn, developers are forced to interleave SQL with Java boilerplate, resulting in error-prone code that does not generalize. Our solution is Epistenet: a toolkit that (1) unifies the storage and treatment of mobile personal data; (2) preserves relationships between disparate data; (3) allows for expressive queries based on the meaning of data rather than its source of origin (e.g., one can query for all communications with John while at the park); and, (4) provides a simple, native query interface to facilitate development. Sauvik Das, Jason Wiese, Jason I. Hong |
MobileHCI | 1 |
| 2016 | Expert and Non-Expert Attitudes towards (Secure) Instant Messaging
Alexander De Luca, Sauvik Das, Martin Ortlieb, Iulia Ion, Ben Laurie |
SOUPS | 2 |
| 2015 | Examining Game World Topology PersonalizationabstractWe present an exploratory analysis of the effects of game world topologies on self-reported player experience in Computer Role Playing Games (CRPGs). We find that (a) players are more engaged in game worlds that better match their self-reported preferences; and (b) player preferences for game topology can be predicted based on their in-game behavior. We further describe how in-game behavioral features that correlate to preferences can be used to control procedural content generation algorithms. Sauvik Das, Alexander Zook, Mark O. Riedl |
CHI | 1 |
| 2015 | The Role of Social Influence in Security Feature AdoptionabstractSocial influence is key in technology adoption, but its role in security-feature adoption is unique and remains unclear. Here, we analyzed how three Facebook security features' Login Approvals, Login Notifications, and Trusted Contacts-diffused through the social networks of 1.5 million people. Our results suggest that social influence affects one's likelihood to adopt a security feature, but its effect varies based on the observability of the feature, the current feature adoption rate among a potential adopter's friends, and the number of distinct social circles from which those feature-adopting friends originate. Curiously, there may be a threshold higher than which having more security feature adopting friends predicts for higher adoption likelihood, but below which having more feature-adopting friends predicts for lower adoption likelihood. Furthermore, the magnitude of this threshold is modulated by the attributes of a feature-features that are more noticeable (Login Approvals, Trusted Contacts) have lower thresholds. Sauvik Das, Adam D. I. Kramer, Laura A. Dabbish, Jason I. Hong |
CSCW | 1 |
| 2014 | Increasing Security Sensitivity With Social Proof: A Large-Scale Experimental ConfirmationabstractOne of the largest outstanding problems in computer security is the need for higher awareness and use of available security tools. One promising but largely unexplored approach is to use social proof: by showing people that their friends use security features, they may be more inclined to explore those features, too. To explore the efficacy of this approach, we showed 50,000 people who use Facebook one of 8 security announcements'7 variations of social proof and 1 non-social control-to increase the exploration and adoption of three security features: Login Notifications, Login Approvals, and Trusted Contacts. Our results indicated that simply showing people the number of their friends that used security features was most effective, and drove 37% more viewers to explore the promoted security features compared to the non-social announcement (thus, raising awareness). In turn, as social announcements drove more people to explore security features, more people who saw social announcements adopted those features, too. However, among those who explored the promoted features, there was no difference in the adoption rate of those who viewed a social versus a non-social announcement. In a follow up survey, we confirmed that the social announcements raised viewer's awareness of available security features. Sauvik Das, Adam D. I. Kramer, Laura A. Dabbish, Jason I. Hong |
CCS | 1 |
| 2014 | The Effect of Social Influence on Security Sensitivity
Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, Jason I. Hong |
SOUPS | 1 |
| 2013 | The post that wasn't: exploring self-censorship on facebookabstractSocial networking site users must decide what content to share and with whom. Many social networks, including Facebook, provide tools that allow users to selectively share content or block people from viewing content. However, sometimes instead of targeting a particular audience, users will self-censor, or choose not to share. We report the results from an 18-participant user study designed to explore self-censorship behavior as well as the subset of unshared content participants would have potentially shared if they could have specifically targeted desired audiences. We asked participants to report all content they thought about sharing but decided not to share on Facebook and interviewed participants about why they made sharing decisions and with whom they would have liked to have shared or not shared. Participants reported that they would have shared approximately half the unshared content if they had been able to exactly target their desired audiences. Manya Sleeper, Rebecca Balebako, Sauvik Das, Amber Lynn McConahy, Jason Wiese, Lorrie Faith Cranor |
CSCW | 3 |
| 2013 | Exploring capturable everyday memory for autobiographical authenticationabstractWe explore how well the intersection between our own everyday memories and those captured by our smartphones can be used for what we call autobiographical authentication-a challenge-response authentication system that queries users about day-to-day experiences. Through three studies-two on MTurk and one field study-we found that users are good, but make systematic errors at answering autobiographical questions. Using Bayesian modeling to account for these systematic response errors, we derived a formula for computing a confidence rating that the attempting authenticator is the user from a sequence of question-answer responses. We tested our formula against five simulated adversaries based on plausible real-life counterparts. Our simulations indicate that our model of autobiographical authentication generally performs well in assigning high confidence estimates to the user and low confidence estimates to impersonating adversaries. Sauvik Das, Eiji Hayashi, Jason I. Hong |
UbiComp | 1 |
| 2013 | Self-Censorship on Facebook
Sauvik Das, Adam D. I. Kramer |
ICWSM | 1 |
| 2013 | CASA: context-aware scalable authenticationabstractWe introduce context-aware scalable authentication (CASA) as a way of balancing security and usability for authentication. Our core idea is to choose an appropriate form of active authentication (e.g., typing a PIN) based on the combination of multiple passive factors (e.g., a user's current location) for authentication. We provide a probabilistic framework for dynamically selecting an active authentication scheme that satisfies a specified security requirement given passive factors. We also present the results of three user studies evaluating the feasibility and users' receptiveness of our concept. Our results suggest that location data has good potential as a passive factor, and that users can reduce up to 68% of active authentications when using an implementation of CASA, compared to always using fixed active authentication. Furthermore, our participants, including those who do not using any security mechanisms on their phones, were very positive about CASA and amenable to using it on their phones. Eiji Hayashi, Sauvik Das, Shahriyar Amini, Jason I. Hong, Ian Oakley |
SOUPS | 2 |
| 2010 | A new differential evolution with improved mutation strategyabstractThe paper employs Lagrange's mean value theorem of differential Calculus to design a new strategy for the selection of parameter vectors in the Differential Evolution (DE) algorithm. Classical differential evolution selects parameter vectors randomly to obtain the donor vectors. These donor vectors thus cannot be directly used as trial solution to the optimization problem. The recombination step indeed is very useful to generate potential trial solutions. The proposed algorithm eliminates the recombination step as the trial solutions can be directly generated by the extended mutation step only. Performance analysis of the proposed algorithm with respect to standard benchmark functions reveals that both in expected convergence time and accuracy in solutions, the proposed algorithm outperforms classical DE/rand/1. Besides extension in mutation strategy, an adaptive selection strategy in the scaling factor F also improves the performance of the proposed algorithm. In addition, the proposed algorithm outperforms classical DE in noisy optimization problem. Further, the number of function evaluation with scaled up dimensions of the optimization problem adds insignificantly small complexity in comparison to that in classical differential evolution to meet up a prescribed level of accuracy in solution quality. Pavel Bhowmik, Sauvik Das, Amit Konar, Swagatam Das, Atulya K. Nagar |
IEEE Congress on Evolutionary Computation | 2 |