EDBT 2026 Demo / reviewers in the wild / expert
Sebastian Pape 0001
dblp:09/7922
· DBLP profile ↗
31ranked-venue papers
3as first author
14since 2021 · last 2025
0000-0002-0893-7856ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 2 first-author · 13 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Framework for Supporting PET Selection Based on GDPR Principles
Sebastian Pape 0001, Anis Bkakria, Badreddine Chah, Maurice Heymann, Sarah Syed-Winkler |
ARES (1) | 1 |
| 2024 | User Issues and Concerns in Generative AI: A Mixed-Methods Analysis of App Reviews
Vanessa Bracamonte, Sascha Löbner, Frédéric Tronnier, Ann-Kristin Lieberknecht, Sebastian Pape 0001 |
CHIRA (1) | 5 |
| 2023 | User Acceptance Criteria for Privacy Preserving Machine Learning TechniquesabstractUsers are confronted with a variety of different machine learning applications in many domains. To make this possible especially for applications relying on sensitive data, companies and developers are implementing Privacy Preserving Machine Learning (PPML) techniques what is already a challenge in itself. This study provides the first step for answering the question how to include the user’s preferences for a PPML technique into the privacy by design process, when developing a new application. The goal is to support developers and AI service providers when choosing a PPML technique that best reflects the users’ preferences. Based on discussions with privacy and PPML experts, we derived a framework that maps the characteristics of PPML to user acceptance criteria. Sascha Löbner, Sebastian Pape 0001, Vanessa Bracamonte |
ARES | 2 |
| 2023 | Comparing the Effect of Privacy and Non-Privacy Social Media Photo Tools on Factors of Privacy Concern
Vanessa Bracamonte, Sebastian Pape 0001, Sascha Löbner |
ICISSP | 2 |
| 2023 | Effectiveness and Information Quality Perception of an AI Model Card: A Study Among Non-ExpertsabstractWith the rising popularity of artificial intelligence (AI) applications, the use of the underlying models has spread to the general public. These AI models have limitations and biases, and knowing about their characteristics could promote their safe use. Although there is some information about AI models available, in the form of AI Model Cards, there is little research on how useful this information is for non-expert users. In this paper, we conduct an experiment to evaluate the effectiveness and perception of information quality of the Model Card of a currently available AI and compare it with shorter versions. The results show that participants can use the Model Card to answer questions about the AI, but they are less confident about their answers compared to shorter versions. In addition, the full Model Card is considered less understandable and interpretable compared with a short version. On the other hand, a short version had a negative effect on perceived trustworthiness of the AI, but in all cases the participants had a positive attitude towards seeking information about the AI. Vanessa Bracamonte, Sebastian Pape 0001, Sascha Löbner, Frédéric Tronnier |
PST | 2 |
| 2023 | Factors of Intention to Use a Photo Tool: Comparison Between Privacy-Enhancing and Non-privacy-enhancing Tools
Vanessa Bracamonte, Sebastian Pape 0001, Sascha Löbner |
SEC | 2 |
| 2023 | The Influence of Privacy Concerns on Cryptocurrency Acceptance
Peter Hamm, Sebastian Pape 0001, Kai Rannenberg |
SEC | 2 |
| 2023 | A privacy calculus model for contact tracing apps: Analyzing the use behavior of the German Corona-Warn-App with a longitudinal user study
David Harborth, Sebastian Pape 0001 |
Comput. Secur. | 2 |
| 2022 | Properties for Cybersecurity Awareness Posters' Design and Quality AssessmentabstractPosters are widely in practice to communicate cybersecurity awareness (CSA) messages. This popularity could be because it is one of the simplest mechanisms, and most people are accustomed to poster usage. Despite this, very little effort has been made to make the CSA poster design and assessment more systematic. Due to this, there exists a wide variation in CSA poster design. Alarmingly, many of them do not align with the needs and objectives of CSA. This study, therefore, intends to collect and analyze the properties that can guide the production of more uniform and effective posters for CSA purposes. At the same time, the study contributes to making the poster design and quality assessment approach more systematic. In order to do so, this study used a literature review for the elicitation of properties and an online assessment to analyze the relevancy of the elicited properties. As a final result, the study provides six main properties (i.e., topic, information quality, message framing, suggestions quality, content presentation, localization, and style and formatting) and their respective twenty-one sub-properties that can facilitate CSA poster design and its quality assessment. Sunil Chaudhary, Marko Kompara, Sebastian Pape 0001, Vasileios Gkioulos |
ARES | 3 |
| 2022 | A Privacy Calculus Model for Contact Tracing Apps: Analyzing the German Corona-Warn-App
David Harborth, Sebastian Pape 0001 |
SEC | 2 |
| 2022 | "All apps do this": Comparing Privacy Concerns Towards Privacy Tools and Non-Privacy Tools for Social Media ContentabstractUsers report that they have regretted accidentally sharing personal information on social media. There have been proposals to help protect the privacy of these users, by providing tools which analyze text or images and detect personal information or privacy disclosure with the objective to alert the user of a privacy risk and transform the content. However, these proposals rely on having access to users’ data and users have reported that they have privacy concerns about the tools themselves. In this study, we investigate whether these privacy concerns are unique to privacy tools or whether they are comparable to privacy concerns about non-privacy tools that also process personal information. We conduct a user experiment to compare the level of privacy concern towards privacy tools and nonprivacy tools for text and image content, qualitatively analyze the reason for those privacy concerns, and evaluate which assurances are perceived to reduce that concern. The results show privacy tools are at a disadvantage: participants have a higher level of privacy concern about being surveilled by the privacy tools, and the same level concern about intrusion and secondary use of their personal information compared to non-privacy tools. In addition, the reasons for these concerns and assurances that are perceived to reduce privacy concern are also similar. We discuss what these results mean for the development of privacy tools that process user content. Vanessa Bracamonte, Sebastian Pape 0001, Sascha Löbner |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Personal information inference from voice recordings: User awareness and privacy concernsabstractAbstract Through voice characteristics and manner of expression, even seemingly benign voice recordings can reveal sensitive attributes about a recorded speaker (e. g., geographical origin, health status, personality). We conducted a nationally representative survey in the UK (n = 683, 18–69 years) to investigate people’s awareness about the inferential power of voice and speech analysis. Our results show that – while awareness levels vary between different categories of inferred information – there is generally low awareness across all participant demographics, even among participants with professional experience in computer science, data mining, and IT security. For instance, only 18.7% of participants are at least somewhat aware that physical and mental health information can be inferred from voice recordings. Many participants have rarely (28.4%) or never (42.5%) even thought about the possibility of personal information being inferred from speech data. After a short educational video on the topic, participants express only moderate privacy concern. However, based on an analysis of open text responses, unconcerned reactions seem to be largely explained by knowledge gaps about possible data misuses. Watching the educational video lowered participants’ intention to use voice-enabled devices. In discussing the regulatory implications of our findings, we challenge the notion of “informed consent” to data processing. We also argue that inferences about individuals need to be legally recognized as personal data and protected accordingly. Jacob Leon Kröger, Leon Gellrich, Sebastian Pape 0001, Saba Rebecca Brause, Stefan Ullrich 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Privacy Concerns Go Hand in Hand with Lack of Knowledge: The Case of the German Corona-Warn-App
Sebastian Pape 0001, David Harborth, Jacob Leon Kröger |
SEC | 1 |
| 2021 | Maturity level assessments of information security controls: An empirical analysis of practitioners assessment capabilities
Christopher Schmitz, David Harborth, Sebastian Pape 0001 |
Comput. Secur. | 4 |
| 2020 | How nostalgic feelings impact Pokémon Go players - integrating childhood brand nostalgia into the technology acceptance theoryabstractThe augmented reality smartphone game Pokémon Go is one of the biggest commercial successes in the last years, posing the question concerning the factors contributing to the game’s success. An apparent distinction to other games is the strong brand Pokémon. We derive a research model based on the established theory of technology acceptance, which includes an established construct for nostalgic feelings – childhood brand nostalgia – and theorise on how it is related to beliefs about technology characteristics and the intention to play the game. For this purpose, we adapt one of the most prominent technology acceptance models for the consumer context and for hedonic information systems, the UTAUT2 model. Based on our model, we conduct a study with 418 active German players aged between 18 and 35. Our results indicate that the effect of childhood brand nostalgia on behavioural intention is fully mediated by the belief constructs. Thus, nostalgic feelings about Pokémon influence the intention of users through altering beliefs concerning Pokémon. We include nostalgic feelings in a technology acceptance model for the first time, therefore contributing to the theoretical advance in the IS domain. The results can be used to enhance the technology acceptance of newly designed products. David Harborth, Sebastian Pape 0001 |
Behav. Inf. Technol. | 2 |
| 2020 | LiSRA: Lightweight Security Risk Assessment for decision support in information security
Christopher Schmitz, Sebastian Pape 0001 |
Comput. Secur. | 2 |
| 2020 | Explaining the Technology Use Behavior of Privacy-Enhancing Technologies: The Case of Tor and JonDonymabstractAbstract Today’s environment of data-driven business models relies heavily on collecting as much personal data as possible. Besides being protected by governmental regulation, internet users can also try to protect their privacy on an individual basis. One of the most famous ways to accomplish this, is to use privacy-enhancing technologies (PETs). However, the number of users is particularly important for the anonymity set of the service. The more users use the service, the more difficult it will be to trace an individual user. There is a lot of research determining the technical properties of PETs like Tor or JonDonym, but the use behavior of the users is rarely considered, although it is a decisive factor for the acceptance of a PET. Therefore, it is an important driver for increasing the user base. We undertake a first step towards understanding the use behavior of PETs employing a mixed-method approach. We conducted an online survey with 265 users of the anonymity services Tor and JonDonym (124 users of Tor and 141 users of JonDonym). We use the technology acceptance model as a theoretical starting point and extend it with the constructs perceived anonymity and trust in the service in order to take account for the specific nature of PETs. Our model explains almost half of the variance of the behavioral intention to use the two PETs. The results indicate that both newly added variables are highly relevant factors in the path model. We augment these insights with a qualitative analysis of answers to open questions about the users’ concerns, the circumstances under which they would pay money and choose a paid premium tariff (only for JonDonym), features they would like to have and why they would or would not recommend Tor/JonDonym. Thereby, we provide additional insights about the users’ attitudes and perceptions of the services and propose new use factors not covered by our model for future research. David Harborth, Sebastian Pape 0001, Kai Rannenberg |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | A Systematic Analysis of User Evaluations in Security ResearchabstractWe conducted a literature survey on reproducibility and replicability of user surveys in security research. For that purpose, we examined all papers published over the last five years at three leading security research conferences and recorded the type of study and whether the authors made the underlying responses available as open data, as well as if they published the used questionnaire respectively interview guide. We uncovered how user surveys become more widespread in security research and how authors and conferences are increasingly publishing their methodologies, while we had no examples of data being made available. Based on these findings, we recommend that future researchers publish their data in addition to their results to facilitate replication and ensure a firm basis for user studies in security research. Peter Hamm, David Harborth, Sebastian Pape 0001 |
ARES | 3 |
| 2019 | Why Do People Pay for Privacy-Enhancing Technologies? The Case of Tor and JonDonym
David Harborth, Xinyuan Cai, Sebastian Pape 0001 |
SEC | 3 |
| 2019 | ESARA: A Framework for Enterprise Smartphone Apps Risk Assessment
Majid Hatamian, Sebastian Pape 0001, Kai Rannenberg |
SEC | 2 |
| 2019 | A Structured Comparison of the Corporate Information Security Maturity Level
Michael Schmid 0004, Sebastian Pape 0001 |
SEC | 2 |
| 2019 | Applying Privacy Patterns to the Internet of Things' (IoT) Architecture
Sebastian Pape 0001, Kai Rannenberg |
Mob. Networks Appl. | 1 |
| 2018 | JonDonym Users' Information Privacy Concerns
David Harborth, Sebastian Pape 0001 |
SEC | 2 |
| 2018 | Assessing Privacy Policies of Internet of Things Services
Niklas Paul, Welderufael B. Tesfay, Dennis-Kenji Kipker, Mattea Stelter, Sebastian Pape 0001 |
SEC | 5 |
| 2018 | PERSUADED: Fighting Social Engineering Attacks with a Serious Game
Dina Aladawy, Kristian Beckers, Sebastian Pape 0001 |
TrustBus | 3 |
| 2017 | Exploring the Hype: Investigating Technology Acceptance Factors of Pokémon GoabstractWe investigate the technology acceptance factors of the AR smart-phone game Pokémon Go with a PLS-SEM approach based on the UTAUT2 model by Venkatesh et al. [1]. Therefore, we conducted an online study in Germany with 683 users of the game. Many other studies rely on the users' imagination of the application's functionality or laboratory environments. In contrast, we asked a relatively large user base already interacting in the natural environment with the application. Not surprisingly, the strongest predictor of behavioral intention to play Pokémon Go is hedonic motivation, i.e. fun and pleasure due to playing the game. Additionally, we find medium-sized effects of effort expectancy on behavioral intention, and of habit on behavioral intention and use behavior. These results imply that AR applications - besides needing to be easily integrable in the users' daily life - should be designed in an intuitive and easily understandable way. We contribute to the understanding of the phenomenon of Pokémon Go by investigating established acceptance factors that potentially fostered the massive adoption of the game. David Harborth, Sebastian Pape 0001 |
ISMAR | 2 |
| 2017 | A Structured Comparison of Social Engineering Intelligence Gathering Tools
Kristian Beckers, Daniel Schosser, Sebastian Pape 0001, Peter Schaab |
TrustBus | 3 |
| 2017 | Social engineering defence mechanisms and counteracting training strategiesabstractPurpose This paper aims to outline strategies for defence against social engineering that are missing in the current best practices of information technology (IT) security. Reason for the incomplete training techniques in IT security is the interdisciplinary of the field. Social engineering is focusing on exploiting human behaviour, and this is not sufficiently addressed in IT security. Instead, most defence strategies are devised by IT security experts with a background in information systems rather than human behaviour. The authors aim to outline this gap and point out strategies to fill the gaps. Design/methodology/approach The authors conducted a literature review from viewpoint IT security and viewpoint of social psychology. In addition, they mapped the results to outline gaps and analysed how these gaps could be filled using established methods from social psychology and discussed the findings. Findings The authors analysed gaps in social engineering defences and mapped them to underlying psychological principles of social engineering attacks, for example, social proof. Furthermore, the authors discuss which type of countermeasure proposed in social psychology should be applied to counteract which principle. The authors derived two training strategies from these results that go beyond the state-of-the-art trainings in IT security and allow security professionals to raise companies’ bars against social engineering attacks. Originality/value The training strategies outline how interdisciplinary research between computer science and social psychology can lead to a more complete defence against social engineering by providing reference points for researchers and IT security professionals with advice on how to improve training. Peter Schaab, Kristian Beckers, Sebastian Pape 0001 |
Inf. Comput. Secur. | 3 |
| 2016 | A Serious Game for Eliciting Social Engineering Security RequirementsabstractSocial engineering is the acquisition of information about computer systems by methods that deeply include nontechnical means. While technical security of most critical systems is high, the systems remain vulnerable to attacks from social engineers. Social engineering is a technique that: (i) does not require any (advanced) technical tools, (ii) can be used by anyone, (iii) is cheap. Traditional security requirements elicitation approaches often focus on vulnerabilities in network or software systems. Few approaches even consider the exploitation of humans via social engineering and none of them elicits personal behaviours of individual employees. While the amount of social engineering attacks and the damage they cause rise every year, the security awareness of these attacks and their consideration during requirements elicitation remains negligible. We propose to use a card game to elicit these requirements, which all employees of a company can play to understand the threat and document security requirements. The game considers the individual context of a company and presents underlying principles of human behaviour that social engineers exploit, as well as concrete attack patterns. We evaluated our approach with several groups of researchers, IT administrators, and professionals from industry. Kristian Beckers, Sebastian Pape 0001 |
RE | 2 |
| 2016 | On Gender Specific Perception of Data Sharing in Japan
Markus Tschersich, Shinsaku Kiyomoto, Sebastian Pape 0001, Toru Nakamura, Gökhan Bal, Haruo Takasaki, Kai Rannenberg |
SEC | 3 |
| 2013 | Defining the Cloud Battlefield - Supporting Security Assessments by Cloud CustomersabstractCloud computing is becoming more and more popular, but security concerns overshadow its technical and economic benefits. In particular, insider attacks and malicious insiders are considered as one of the major threats and risks in cloud computing. As physical boundaries disappear and a variety of parties are involved in cloud services, it is becoming harder to define a security perimeter that divides insiders from outsiders, therefore making security assessments by cloud customers more difficult. In this paper, we propose a model that combines a comprehensive system model of infrastructure clouds with a security model that captures security requirements of cloud customers as well as characteristics of attackers. This combination provides a powerful tool for systematically analyzing attacks in cloud environments, supporting cloud customers in their security assessment by providing a better understanding of existing attacks and threats. Furthermore, we use the model to construct "what-if" scenarios that could possible lead to new attacks and to raise concerns about unknown threats among cloud customers. Sören Bleikertz, Toni Mastelic, Sebastian Pape 0001, Wolter Pieters, Trajce Dimkov |
IC2E | 3 |