EDBT 2026 Demo / reviewers in the wild / expert
Patricia Arias Cabarcos
dblp:13/8970 · also Patricia Arias
· DBLP profile ↗
20ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0001-7401-6185ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 5 first-author · 12 since 2021Human-computer interaction and ubiquitous computing · 6 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | IdentitySign: Design and User Study of a Prototype Application for Digitally Signing Documents Using an Identity Wallet
Yorick Last, Hanna Schraffenberger, Daniel Ostkamp, Jorrit Geels, Patricia Arias Cabarcos |
SOUPS | 5 |
| 2026 | "The city isn't uploading me to TikTok": Exploring Privacy Attitudes towards Data Collection in Urban Public SpacesabstractSmart cities promise safer streets, smoother traffic, and more efficient services, enabled by dense networks of urban sensors. Yet this infrastructure, often unnoticed by citizens, introduces pervasive privacy risks, from tracking, profiling, and sensitive inferences to subtle forms of self-censorship. Despite widespread deployment, little is known about how the public understands and perceives these sensing systems. To address this gap, we present an intervention based user study (n = 172) in which participants are exposed to data collection by six urban sensors, including cameras and alternative technologies commonly framed as privacy-preserving. Participants encounter either the sensors alone or sensors accompanied by real-time data visualizations. Our results reveal widespread misunderstanding of some sensors (radar, LiDAR, Wi-Fi, depth, and thermal imaging sensors), particularly their capacity for identification and for attribute inferences such as gender or age. We also identify persistent misconceptions, including the belief that Wi-Fi poses privacy risks only when users connect to public networks. While making sensors visible and visualizing collected data improves privacy awareness, these measures alone are not enough for citizens to understand the actual risks of urban sensing. We derive recommendations for privacy-respecting smart city environments grounded in citizens’ informational needs and expectations. Julian Todt, Emiram Kablo, Felix Morsbach, Patricia Arias Cabarcos, Thorsten Strufe |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | A Comprehensive Re-Evaluation of Biometric Modality Properties in the Modern EraabstractThe rapid advancement of authentication systems and their increasing reliance on biometrics for faster and more accurate user verification experience, highlight the critical need for a reliable framework to evaluate the suitability of biometric modalities for specific applications. Currently, the most widely known evaluation framework is a comparative table from 1998, which no longer adequately captures recent technological developments or emerging vulnerabilities in biometric systems. To address these challenges, this work revisits the evaluation of biometric modalities through an expert survey involving 24 biometric specialists. The findings indicate substantial shifts in property ratings across modalities. For example, face recognition, shows improved ratings due to technological progress, while fingerprint, shows decreased reliability because of emerging vulnerabilities and attacks. Further analysis of expert agreement levels across rated properties highlighted the consistency of the provided evaluations and ensured the reliability of the ratings. Finally, expert assessments are compared with dataset-level uncertainty across 55 biometric datasets, revealing strong alignment in most modalities and underscoring the importance of integrating empirical evidence with expert insight. Moreover, the identified expert disagreements reveal key open challenges and help guide future research toward resolving them. Rouqaiah Al-Refai, Pankaja Priya Ramasamy, Ragini Ramesh, Patricia Arias Cabarcos, Philipp Terhörst |
IJCB | 4 |
| 2025 | The more accounts I use, the less I have to think': A Longitudinal Study on the Usability of Password Managers for Novice Users
Patricia Arias Cabarcos, Peter Mayer 0001 |
SOUPS | 1 |
| 2025 | PrivaCI in VR: Exploring Perceptions and Acceptability of Data Sharing in Virtual Reality Through Contextual Integrity
Emiram Kablo, Melina Kleber, Patricia Arias Cabarcos |
USENIX Security Symposium | 3 |
| 2024 | NeuroIDBench: An open-source benchmark framework for the standardization of methodology in brainwave-based authentication researchabstractBiometric systems based on brain activity have been proposed as an alternative to passwords or to complement current authentication techniques. By leveraging the unique brainwave patterns of individuals, these systems offer the possibility of creating authentication solutions that are resistant to theft, hands-free, accessible, and potentially even revocable. However, despite the growing stream of research in this area, faster advance is hindered by reproducibility problems. Issues such as the lack of standard reporting schemes for performance results and system configuration, or the absence of common evaluation benchmarks, make comparability and proper assessment of different biometric solutions challenging. Further, barriers are erected to future work when, as so often, source code is not published open access. To bridge this gap, we introduce NeuroIDBench, a flexible open source tool to benchmark brainwave-based authentication models. It incorporates nine diverse datasets, implements a comprehensive set of pre-processing parameters and machine learning algorithms, enables testing under two common adversary models (known vs unknown attacker), and allows researchers to generate full performance reports and visualizations. We use NeuroIDBench to investigate the shallow classifiers and deep learning-based approaches proposed in the literature, and to test robustness across multiple sessions. We observe a 37.6% reduction in Equal Error Rate (EER) for unknown attacker scenarios (typically not tested in the literature), and we highlight the importance of session variability to brainwave authentication. All in all, our results demonstrate the viability and relevance of NeuroIDBench in streamlining fair comparisons of algorithms, thereby furthering the advancement of brainwave-based authentication through robust methodological practices. Avinash Kumar Chaurasia, Matin Fallahi, Thorsten Strufe, Philipp Terhörst, Patricia Arias Cabarcos |
J. Inf. Secur. Appl. | 5 |
| 2023 | Poster: Towards Practical Brainwave-based User AuthenticationabstractBrainwave measuring devices have transitioned from specialized medical tools to user-friendly and economically accessible consumer products. This shift has opened new avenues for pervasive services, with applications spanning brain-computer interfaces (BCIs), disease detection, criminal trials, and, notably, authentication in computer security. Electroencephalography (EEG) signals, being difficult to steal and revocable, present an attractive biometric option. However, the practical deployment of these signals is hindered by security threats, usability issues, and privacy concerns. To this end, we expect to improve the overall performance of authentication systems using consumer-grade devices, gain a better understanding of user attitudes toward this type of authentication, and protect the user's privacy against unauthorized use of samples collected during enrollment and verification. Matin Fallahi, Patricia Arias Cabarcos, Thorsten Strufe |
CCS | 2 |
| 2023 | Privacy in the Age of Neurotechnology: Investigating Public Attitudes towards Brain Data Collection and UseabstractBrain Computer Interfaces (BCIs) are expanding beyond the medical realm into entertainment, wellness, and marketing. However, as consumer neurotechnology becomes more popular, privacy concerns arise due to the sensitive nature of brainwave data and its potential commodification. Attacks on privacy have been demonstrated and AI advancements in brain-to-speech and brain-to-image decoding pose a new unique set of risks. In this space, we contribute with the first user study (n=287) to understand people's neuroprivacy expectations and awareness of neurotechnology implications. Our analysis shows that, while users are interested in the technology, privacy is a critical issue for acceptability. The results underscore the importance of consent and the need for implementing effective transparency about neurodata sharing. Our insights provide a ground to analyse the gap in current privacy protection mechanisms, adding to the debate on how to design privacy-respecting neurotechnology. Emiram Kablo, Patricia Arias Cabarcos |
CCS | 2 |
| 2023 | BrainNet: Improving Brainwave-based Biometric Recognition with Siamese NetworksabstractWith the advent of consumer wearables that capture brain activity, the use of brainwaves to verify a user's identity has been proposed as a convenient alternative to passwords. While recent work on brain biometrics shows feasible performance, it falls short in considering practical applicability. We propose a new solution, BrainNet, which trains a Siamese Network to measure the similarity of two electroencephalogram (EEG) inputs, and uses time-locked brain reactions instead of continuous mental activity to improve accuracy. This approach removes the need for retraining the brainwave recognition system, a common pitfall in current solutions, facilitating practical deployment. Furthermore, BrainNet achieves Equal Error Rates (EERs) of 0.14% in verification mode and 0.34% in identification mode, outperforming the state of the art even when evaluated under unseen attacker scenarios. Matin Fallahi, Thorsten Strufe, Patricia Arias Cabarcos |
PERCOM | 3 |
| 2023 | Privacy-centered authentication: A new framework and analysisabstractThe usage of authentication schemes is increasing in our daily life with the ubiquitous spreading Internet services. The verification of user's identity is still predominantly password-based, despite being susceptible to various attacks and openly disliked by users. Bonneau et al. presented a framework, based on Usability, Deployability, and Security criteria (UDS), to evaluate authentication schemes and find a replacement for passwords. Although the UDS framework is a mature and comprehensive evaluation framework and has been extended by other authors, it does not analyse privacy aspects in the usage of authentication schemes. In the present work, we extend the UDS framework with a privacy category to allow a more comprehensive evaluation, becoming the UDSP framework. We provide a thorough, rigorous assessment of sample authentication schemes, including the analysis of novel behavioural biometrics. Our work also discusses implementation aspects regarding the new privacy dimension and current gaps to be addressed in the future research. Antonio Robles-González, Patricia Arias Cabarcos, Javier Parra-Arnau |
Comput. Secur. | 2 |
| 2023 | 'Surprised, Shocked, Worried'}: User Reactions to Facebook Data Collection from Third PartiesabstractData collection and aggregation by online services happens to an extent that is often beyond awareness and comprehension of its users. Transparency tools become crucial to inform people, though it is unclear how well they work. To investigate this matter, we conducted a user study focusing on Facebook, which has recently released the 'Off-Facebook Activity' transparency dashboard that informs about personal data collection from third parties. We exposed a group of n = 100 participants to the dashboard and surveyed their level of awareness and reactions to understand how transparency impacts users' privacy attitudes and intended behavior. Our participants were surprised about the massive amount of collected data, became significantly less comfortable with data collection, and more likely to take protective measures. Collaterally, we observed that current consent schemes are inadequate. Based on the survey findings, we make recommendations for more usable transparency and highlight the need to raise awareness about transparency tools and to provide easily actionable privacy controls. Patricia Arias Cabarcos, Saina Khalili, Thorsten Strufe |
Proc. Priv. Enhancing Technol. | 1 |
| 2023 | Performance and Usability Evaluation of Brainwave Authentication Techniques with Consumer DevicesabstractBrainwaves have demonstrated to be unique enough across individuals to be useful as biometrics. They also provide promising advantages over traditional means of authentication, such as resistance to external observability, revocability, and intrinsic liveness detection. However, most of the research so far has been conducted with expensive, bulky, medical-grade helmets, which offer limited applicability for everyday usage. With the aim to bring brainwave authentication and its benefits closer to real world deployment, we investigate brain biometrics with consumer devices. We conduct a comprehensive measurement experiment and user study that compare five authentication tasks on a user sample up to 10 times larger than those from previous studies, introducing three novel techniques based on cognitive semantic processing. Furthermore, we apply our analysis on high-quality open brainwave data obtained with a medical-grade headset, to assess the differences. We investigate both the performance, security, and usability of the different options and use this evidence to elicit design and research recommendations. Our results show that it is possible to achieve Equal Error Rates as low as 7.2% (a reduction between 68–72% with respect to existing approaches) based on brain responses to images with current inexpensive technology. We show that the common practice of testing authentication systems only with known attacker data is unrealistic and may lead to overly optimistic evaluations. With regard to adoption, users call for simpler devices, faster authentication, and better privacy. Patricia Arias Cabarcos, Matin Fallahi, Thilo Habrich, Karen Schulze, Christian Becker 0001, Thorsten Strufe |
ACM Trans. Priv. Secur. | 1 |
| 2021 | Inexpensive Brainwave Authentication: New Techniques and Insights on User Acceptance
Patricia Arias Cabarcos, Thilo Habrich, Karen Becker, Christian Becker 0001, Thorsten Strufe |
USENIX Security Symposium | 1 |
| 2019 | Poster: Towards a Framework for Assessing Vulnerabilities of Brainwave Authentication SystemsabstractIn the quest to devise new alternatives to password-based authentication, behavioral biometrics have become more and more appealing due to the improved usability that comes with their unobtrusiveness. One such type of biometric are brainwaves, which can be nowadays easily measured and used to prove a person's identity. Given the potential for this technology to be adopted in the near future, it is paramount to analyze its security implications. Furthermore, recent advances in brain computer interfaces make feasible the usage of brainwaves to prove users' identity. This work presents a comprehensive framework for assessing the vulnerabilities of brainwave authentication systems, incorporating new attack vectors that target specific features of brain biometrics. Resting on this theoretical groundwork, we analyze the existing literature on attacks and countermeasures, identifying gaps and providing a foundation for future research. Furthermore, we evaluated a subset of attacks identified through the framework and report our preliminary results. Karen Becker, Patricia Arias Cabarcos, Thilo Habrich, Christian Becker 0001 |
CCS | 2 |
| 2019 | "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersabstractPasswords are an often unavoidable authentication mechanism, despite the availability of additional alternative means. In the case of smartphones, usability problems are aggravated because interaction happens through small screens and multilayer keyboards. While password managers (PMs) can improve this situation and contribute to hardening security, their adoption is far from widespread. To understand the underlying reasons, we conducted the first empirical usability study of mobile PMs, covering both quantitative and qualitative evaluations. Our findings show that popular PMs are barely acceptable according to the standard System Usability Scale, and that there are three key areas for improvement: integration with external applications, security, and user guidance and interaction. We build on the collected evidence to suggest recommendations that can fill this gap. Sunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín López, Florina Almenárez, Daniel Díaz Sánchez, Christian Becker 0001 |
CCS | 2 |
| 2018 | RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based SecurityabstractDigital certificates, based on X.509 PKI standard, are located at the core of many security mechanisms implemented in services and applications. However, the usage of certificates has revealed flaws in the certificate validation process (e.g., possibility of unavailable or non-updated data). This fact implies security risks that are not assessed. In order to address these issues that such flaws entail, we propose a novel probabilistic approach for quantitative risk assessment in X.509 PKI, together with trust management when there is uncertainty. We have evaluated our risk assessment approach and demonstrated its usage, considering as a use case the secure installation of mobile applications. The results show that our approach provides more granularity, appropriate values according to the impact, and relevant information in the risk calculation than other approaches. M. Francisca Hinarejos, Florina Almenárez, Patricia Arias Cabarcos, Josep-Lluís Ferrer-Gomila, Andrés Marín López |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | On the Design of Distributed Adaptive Authentication Systems
Patricia Arias Cabarcos, Christian Krupitzer |
SOUPS | 1 |
| 2017 | Collaborative eHealth Meets Security: Privacy-Enhancing Patient Profile ManagementabstractCollaborative healthcare environments offer potential benefits, including enhancing the healthcare quality delivered to patients and reducing costs. As a direct consequence, sharing of electronic health records (EHRs) among healthcare providers has experienced a noteworthy growth in the last years, since it enables physicians to remotely monitor patients' health and enables individuals to manage their own health data more easily. However, these scenarios face significant challenges regarding security and privacy of the extremely sensitive information contained in EHRs. Thus, a flexible, efficient, and standards-based solution is indispensable to guarantee selective identity information disclosure and preserve patient's privacy. We propose a privacy-aware profile management approach that empowers the patient role, enabling him to bring together various healthcare providers as well as user-generated claims into an unique credential. User profiles are represented through an adaptive Merkle Tree, for which we formalize the underlying mathematical model. Furthermore, performance of the proposed solution is empirically validated through simulation experiments. Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Patricia Arias Cabarcos, Andrés Marín López |
IEEE J. Biomed. Health Informatics | 4 |
| 2010 | Introducing Infocards in NGN to Enable User-Centric Identity ManagementabstractWith the rapid evolution of networks and the widespread penetration of mobile devices with increasing capabilities, that have already become a commodity, we are getting a step closer to ubiquity. Thus, we are moving a great part of our lives from the physical world to the online world, i.e. social interactions, business transactions, relations with government administrations, etc. However, while identity verification is easy to handle in the real world, there are many unsolved challenges when dealing with digital identity management, especially due to the lack of user awareness when it comes to privacy. Thus, with the aim to enhance the navigation experience and security in multiservice and multiprovider environments the user must be empowered to control how her attributes are shared and disclosed between different domains.With these goals on mind, we leverage the benefits of the Infocard technology and introduce this usercentric paradigm into the emerging NGN architectures. This paper proposes a way to combine the gains of a SAML federation between service and identity providers with the easiness for the final user of the Inforcard System using the well known architectural schema of IP Multimedia Subsystem. Davide Proserpio, Fabio Sanvido, Patricia Arias Cabarcos, Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Andrés Marín López |
GLOBECOM | 3 |
| 2009 | Towards dynamic trust establishment for identity federationabstractFederation has emerged as a key concept for identity management, as it is the basis to reduce complexity in the companies and improve user experience. However, the problem of establishing identity federations in dynamic open environments, where it is desirable to speed up the processes of service provisioning and deprovisioning, has not been fully addressed. This paper reviews the existing frameworks for identity federation, analyzing the underlying trust mechanisms and its suitability to be applied in the mentioned environments. Finally, we propose a generic extension for the Security Assertion Markup Language (SAML) standard in order to facilitate the creation of federation relationships in a secure dynamic way between prior unknown parties. Florina Almenárez, Patricia Arias Cabarcos, Andrés Marín López, Daniel Díaz Sánchez |
EATIS | 2 |