EDBT 2026 Demo / reviewers in the wild / expert
Yaxing Yao
dblp:142/7931
· DBLP profile ↗
50ranked-venue papers
5as first author
42since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 33 · 5 first-author · 27 since 2021Security and privacy · 17 · 15 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PrivacyMotiv: Vulnerability-Centered Persona Journeys for Empathic Privacy Reviews in UX DesignabstractUX professionals routinely conduct design reviews, yet privacy concerns are often overlooked, not only due to limited tools, but more fundamentally from low intrinsic motivation, driven by limited privacy knowledge, weak empathy for unexpectedly affected users, and low autonomy in identifying harms. We present PrivacyMotiv, an LLM-powered system that generates vulnerability-centered personas, persona journey stories, and traceable design diagnoses grounded in lo-fi user flows to support privacy-oriented UX design review. In a within-subjects study with professional UX practitioners (N=16), PrivacyMotiv significantly improved empathy, intrinsic motivation, and perceived usefulness, with participants identifying 59% more privacy issues and proposing 70% more redesign solutions compared to self-proposed methods. This work contributes empirical insight into motivational barriers in privacy-aware UX and a structured, narrative-driven approach for integrating privacy review into early-stage UX practice. Zeya Chen, Jianing Wen, Yaxing Yao, Toby Jia-Jun Li, Tianshi Li 0001 |
DIS | 3 |
| 2026 | Understanding Parents' Desires in Moderating Children's Interactions with GenAI Chatbots through LLM-Generated Probes
John Driscoll, Viki Shi, Izak Vucharatavintara, Yaxing Yao, Haojian Jin |
CHI | 5 |
| 2026 | User Perceptions of Responsible Gambling Messages as Nudges for Gambling SafetyabstractNudges are subtle interventions designed to influence user behavior without restricting choice. Responsible gambling messages (RGMs) exemplify such nudges by encouraging safer decision-making in gambling environments. Prior research has examined how pop-up messages influence gambling behavior in experimental settings and has explored the design of effective slogan messages. However, little is known about how different types of RGMs shape users’ real-world gambling behavior and safety. To address this gap, we apply a nudging perspective to examine how RGMs support gambling safety throughout gamblers’ decision-making journey. We conducted semi-structured interviews with 22 gamblers and found that participants were generally aware of RGMs, yet some misunderstood their intended purpose. Participants perceived the safety impact of RGMs as reflected in both attitudinal and behavioral dimensions. We further discuss users’ message reception practices and the effectiveness of RGMs as nudges, and conclude with design implications for promoting gambling safety. Maggie Yongqi Guan, Yaxing Yao, Sio Hong Teng, Xiaobo Zhou 0002, Kanye Ye Wang |
CHI | 2 |
| 2026 | Designing Privacy Choice in Generative AI Chatbot EcosystemsabstractGenerative AI (GenAI) is evolving from standalone tools to interconnected ecosystems that integrate chatbots, cloud platforms, and third-party services. While this ecosystem model enables personalization and extended services, it also introduces complex information flows and amplifies privacy risks. Existing solutions focus on system-level protections, offering little support for users to make meaningful privacy choices. To address this gap, we conducted two vignette-based survey studies with 486 participants and a follow-up interview study with 16 participants. We also explored users’ needs and preferences for privacy choice design across both GenAI personalization and data-sharing. Our results reveal paradoxical patterns: participants sometimes trusted third-party ecosystems more for personalization but perceived greater control in first-party ecosystems when data was shared externally. We discuss design implications for privacy choice interfaces that enhance transparency, control, and trust in GenAI ecosystems. Lanjing Liu, Xinran Adeline Li, Allen Yilun Lin, Yaxing Yao |
CHI | 4 |
| 2026 | Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human OversightabstractThe dark patterns, deceptive interface designs manipulating user behaviors, have been extensively studied for their effects on human decision-making and autonomy. Yet, with the rising prominence of LLM-powered GUI agents that automate tasks from high-level intents, understanding how dark patterns affect agents is increasingly important. We present a two-phase empirical study examining how agents, human participants, and human-AI teams respond to 16 types of dark patterns across diverse scenarios. Phase 1 highlights that agents often fail to recognize dark patterns, and even when aware, prioritize task completion over protective action. Phase 2 revealed divergent failure modes: humans succumb due to cognitive shortcuts and habitual compliance, while agents falter from procedural blind spots. Human oversight improved avoidance but introduced costs such as attentional tunneling and cognitive load. Our findings show neither humans nor agents are uniformly resilient, and collaboration introduces new vulnerabilities, suggesting design needs for transparency, adjustable autonomy, and oversight. Bingcan Guo, Ibrahim Khalilov, Simret Araya Gebreegziabher, Bingsheng Yao, Dakuo Wang, Yanfang Ye 0001, Tianshi Li 0001, Ziang Xiao, Yaxing Yao, Toby Jia-Jun Li |
CHI | 13 |
| 2025 | HAIPS '25: First ACM CCS Workshop on Human-Centered AI Privacy and SecurityabstractRecent advances in AI/ML create novel and pressing privacy and security challenges—ranging from using generative AI to create harmful content, to the generation of insecure code by AI coding assistants; from oversharing information with ChatGPT to unexpected privacy leaks by LLM agents. At the same time, AI offers new opportunities to address long-standing end-user privacy and security concerns and empower practitioners to adopt better security and privacy practices. In the inaugural workshop of HAIPS'25, we aim to help build and strengthen a community of people enthusiastic about privacy and security issues related to AI from a human-centered perspective, and foster cross-disciplinary research agendas that effectively engage with the human element when addressing these issues. Tianshi Li 0001, Toby Jia-Jun Li, Yaxing Yao, Sauvik Das |
CCS | 3 |
| 2025 | Empowering Parents to Support Children's Online Security and Privacy: Findings from a Randomized Controlled TrialabstractIn the ubiquitous computing society, parenting ''digital natives'' presents unprecedented challenges. Parents often rely on online resources to support and guide their children in security and privacy (S&P) related topics. However, the abundance of online resources makes it challenging for parents to find high-quality and relevant resources that align with their S&P needs. Further, the longitudinal development of parental competence and coping strategies in S&P topics remains largely unexplored. Xiaowei Chen 0013, Verena Distler, Chloe Gordon, Yaxing Yao, Ziwen Teuber |
CCS | 4 |
| 2025 | From Knowledge to Practice: Co-Designing Privacy Controls with ChildrenabstractChildren born in the digital era are facing increasing privacy risks and the need to control privacy in various contexts, suggesting an urgent need to enhance their privacy literacy. While previous research focuses on developing children’s privacy literacy by delivering privacy knowledge, it remains unclear how children process the knowledge and apply it in various privacy situations. Furthermore, children’s desire for privacy controls remains understudied. To fill the gap, we conducted two five-day co-design workshops with 11 children (ages 6-11). We uncovered children’s sophisticated expectations of everyday privacy management, such as staying aware of their privacy situations, strong authentication methods, and minimal privacy exposure. We further discovered that children translated their privacy knowledge to privacy practices through an iterative reflection and action process. We discussed key considerations to support children’s privacy literacy development by leveraging this process and offered implications for children-friendly privacy design. Lanjing Liu, Yaxing Yao |
CHI | 2 |
| 2025 | Inclusive Avatar Guidelines for People with Disabilities: Supporting Disability Representation in Social Virtual RealityabstractAvatar is a critical medium for identity representation in social virtual reality (VR). However, options for disability expression are highly limited on current avatar interfaces. Improperly designed disability features may even perpetuate misconceptions about people with disabilities (PWD). As more PWD use social VR, there is an emerging need for comprehensive design standards that guide developers and designers to create inclusive avatars. Our work aim to advance the avatar design practices by delivering a set of centralized, comprehensive, and validated design guidelines that are easy to adopt, disseminate, and update. Through a systematic literature review and interview with 60 participants with various disabilities, we derived 20 initial design guidelines that cover diverse disability expression methods through five aspects, including avatar appearance, body dynamics, assistive technology design, peripherals around avatars, and customization control. We further evaluated the guidelines via a heuristic evaluation study with 10 VR practitioners, validating the guideline coverage, applicability, and actionability. Our evaluation resulted in a final set of 17 design guidelines with recommendation levels. Kexin Zhang 0002, Edward Glenn Scott Spencer, Abijith Manikandan, Andric Li, Ang Li 0018, Yaxing Yao, Yuhang Zhao 0001 |
CHI | 6 |
| 2025 | CLEAR: Towards Contextual LLM-Empowered Privacy Policy Analysis and Risk Generation for Large Language Model ApplicationsabstractThe rise of end-user applications powered by large language models (LLMs), including both conversational interfaces and add-ons to existing graphical user interfaces (GUIs), introduces new privacy challenges. However, many users remain unaware of the risks. This paper explores methods to increase user awareness of privacy risks associated with LLMs in end-user applications. We conducted five co-design workshops to uncover user privacy concerns and their demand for contextual privacy information within LLMs. Based on these insights, we developed CLEAR (Contextual LLM-Empowered Privacy Policy Analysis and Risk Generation), a just-in-time contextual assistant designed to help users identify sensitive information, summarize relevant privacy policies, and highlight potential risks when sharing information with LLMs. We evaluated the usability and usefulness of CLEAR across two example domains: ChatGPT and the Gemini plugin in Gmail. Our findings demonstrated that CLEAR is easy to use and improves users’ understanding of data practices and privacy risks. We also discussed LLM’s duality in posing and mitigating privacy risks, offering design and policy implications. Daodao Zhou, Yanfang Ye 0001, Toby Jia-Jun Li, Yaxing Yao |
IUI | 5 |
| 2025 | Mental Models of Generative AI Chatbot EcosystemsabstractThe capability of GenAI-based chatbots, such as ChatGPT and Gemini, has expanded quickly in recent years, turning them into GenAI Chatbot Ecosystems. Yet, users’ understanding of how such ecosystems work remains unknown. In this paper, we investigate users’ mental models of how GenAI Chatbot Ecosystems work. This is an important question because users’ mental models guide their behaviors, including making decisions that impact their privacy. Through 21 semi-structured interviews, we uncovered users’ four mental models towards first-party (e.g., Google Gemini) and third-party (e.g., ChatGPT) GenAI Chatbot Ecosystems. These mental models centered around the role of the chatbot in the entire ecosystem.We further found that participants held a more consistent and simpler mental model towards third-party ecosystems than the first-party ones, resulting in higher trust and fewer concerns towards the thirdparty ecosystems. We discuss the design and policy implications based on our results. Xingyi Wang, Sunyup Park, Yaxing Yao |
IUI | 4 |
| 2025 | Supporting Family Discussions About Digital Privacy Through Perspective-Taking: An Empirical InvestigationabstractWhile 96% of U.S. teens use the internet daily, most families face challenges in discussing privacy concerns, with parents feeling unprepared and teens being hesitant to communicate. This study explored how guided family discussions, grounded in perspective-taking theory, promoted mutual understanding and enhanced digital privacy literacy. Through a qualitative study involving 13 parent-child pairs, we identified three key communication challenges: abstract discussions about privacy, reliance on absolute statements, and a decline in teen engagement. These challenges stemmed from limited privacy literacy and a lack of adaptive communication. Our perspective-taking facilitation approach addressed these issues by transforming traditional parent-led conversations into collaborative exchanges through reflective practices and helping families view privacy as a context-dependent concept. We propose design implications for educational technology to scale the support of family privacy discussions, including tools that support perspective-taking and interfaces that highlight non-binary privacy choices. Zikai Wen, Lanjing Liu, Yaxing Yao |
SP | 3 |
| 2025 | Teaching Data Science Students to Sketch Privacy Designs Through HeuristicsabstractRecent studies reveal that experienced data practitioners often draw sketches to facilitate communication around privacy design concepts. However, there is limited understanding of how we can help novice students develop such communication skills. This paper studies methods for lowering novice data science students' barriers to creating high-quality privacy sketches. We first conducted a need-finding study (N=12) to identify barriers students face when sketching privacy designs. We then used a human-centered design approach to guide the method development, culminating in three simple, text-based heuristics. Our user studies with 24 data science students revealed that simply presenting three heuristics to the participants at the beginning of the study can enhance the coverage of privacy-related design decisions in sketches, reduce the mental effort required for creating sketches, and improve the readability of the final sketches. Jinhe Wen, Yingxi Zhao, Yaxing Yao, Haojian Jin |
SP | 4 |
| 2025 | Why am I seeing this: Democratizing End User Auditing for Online Content Recommendations
Leyang Li, Luke Cao, Yanfang Ye 0001, Tianshi Li 0001, Yaxing Yao, Toby Jia-Jun Li |
UIST | 6 |
| 2025 | Behind the Same Mask: Understanding the Practice of Spontaneous Collective Anonymity on Chinese Social PlatformsabstractAnonymity plays a crucial role in social interactions online. Recently, a new phenomenon has emerged on Chinese social platforms where users collectively adopt a uniform avatar and nickname ''momo'', thereby achieving anonymity. However, understanding such spontaneous collective anonymity within Chinese cultural and contextual factors remains limited since much of the anonymity research focuses on Western users. Yet, it is unclear how users perceive the usage of ''momo'', their motivations, and how using this collective anonymity impacts their social interaction. To answer these questions, we conducted interviews with 20 ''momo'' users. We found that the shared identity ''momo'' provides an additional layer of anonymity on identity-constrained Chinese social platforms. Users adopted ''momo'' to engage in more inclusive discussions and to balance anonymity and self-presentation. Moreover, this collective anonymity fosters connections and forms a meaningful group identity in a loosely organized community. We also identified the benefits and risks associated with this unique collective anonymity. This work makes significant contributions to CSCW and HCI research by (1) extending the knowledge of anonymity practices and privacy concerns within non-Western and mainly Chinese contexts. (2) advancing the work on anonymity models by revealing the dual role of the Momo identity in facilitating collective anonymity and community bonds. (3) providing design implications to support future social technologies in identity design and anonymous communities. Suqi Lou, Chao Zhang 0082, Shi Chen 0005, Zhicong Lu, Yaxing Yao |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2025 | "If We Had the Option": Infrastructuring for Access to Online Subscription-Based Services in BangladeshabstractAs online access to entertainment, education, news, and information increasingly becomes mitigated through subscription-based services, it is important to study how inequities in access impact users in low and middle-income countries (LMICS), and what infrastructuring strategies they employ to overcome obstacles. In this paper, we present findings from an interview study with 22 participants from Bangladesh who use and share online subscription-based services. Due to the lack of availability and limitations using formal international payment methods, procedural difficulties, and infrastructural challenges in Bangladesh, we found an emergence of a distinct informal ecosystem of accessing, sharing, and using subscription-based services. We report a detailed analysis of the adoption, sharing practices, and dynamics of sharing online subscription-based services in Bangladesh, that builds on and extends previous HCI literature on informality, informal marketplace, intermediaries, and media sharing in the Global South. Our findings show how a vibrant and growing user base of subscription-based online services is using creative and sometimes risky ways to gain access to media and information through informal intermediaries and administrators. Finally, we discuss potential directions for practice and policy innovations that include facilitating international payments for online services and platforms and reconsidering their policies and service delivery mechanisms to better support users in the Global South context. Hasan Mahmud Prottoy, Yaxing Yao, Foad Hamidi |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2025 | Families' Vision of Generative AI Agents for Household Safety Against Digital and Physical ThreatsabstractAs families face increasingly complex safety challenges in digital and physical environments, generative AI (GenAI) presents new opportunities to support household safety through multiple specialized AI agents. Through a two-phase qualitative study consisting of individual interviews and collaborative sessions with 13 parent-child dyads, we explored families' conceptualizations of GenAI and their envisioned use of AI agents in daily family life. Our findings reveal that families preferred to distribute safety-related support across multiple AI agents, each embodying a familiar caregiving role: a household manager coordinating routine tasks and mitigating risks such as digital fraud and home accidents; a private tutor providing personalized educational support, including safety education; and a family therapist offering emotional support to address sensitive safety issues such as cyberbullying and digital harassment. Families emphasized the need for agent-specific privacy boundaries, recognized generational differences in trust toward AI agents, and stressed the importance of maintaining open family communication alongside the assistance of AI agents. Based on these findings, we propose a multi-agent system design featuring four privacy-preserving principles: memory segregation, conversational consent, selective data sharing, and progressive memory management to help balance safety, privacy, and autonomy within family contexts. Zikai Wen, Lanjing Liu, Yaxing Yao |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2025 | How Social Media Plays A Role in Stay-At-Home-Moms' Transition: A Case Study in ChinaabstractIn China, stay-at-home moms (SAHMs) often experience a hard time during their transitions, such as returning to school or restarting their careers. Yet, their experiences throughout this transition and their strategies to overcome potential challenges are rarely studied in the CSCW literature. In this study, we examined how Chinese SAHMs leveraged social media platforms to assist their transition and help them navigate the potential challenges. Through interviewing 15 SAHMs who have successfully completed their transitions, we identified the key role that social media platforms (e.g., RedNote, Douyin) play in helping SAHMS build resilience as they re-engage with society. For example, many SAHMs found peer support during their transition from mom-centric social groups where they could receive advice that was specific to their situations and constraints. When they achieved their goals, they turned into contributors in such groups and altruistically shared their experiences to help other moms. Based on the findings, we discussed the opportunities to support SAHMs' transitions. Xinyi Zhang 0007, Minzhu Zhao, Yaxing Yao, Zhicong Lu |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2025 | "What are they gonna do with my data?": Privacy Expectations, Concerns, and Behaviors in Virtual RealityabstractThe immersive nature of Virtual Reality (VR) and its reliance on sensory devices like head-mounted displays introduce privacy risks to users. While earlier research has explored users' privacy concerns within VR environments, less is known about users' comprehension of VR data practices and protective behaviors; the expanding VR market and technological progress also necessitate a fresh evaluation. We conducted semi-structured interviews with 20 VR users, showing their diverse perceptions regarding the types of data collected and their intended purposes. We observed privacy concerns in three dimensions: institutional, social, and device-specific. Our participants sought to protect their privacy through considerations when selecting the device, scrutinizing VR apps, and selective engagement in different VR interactions. We contrast our findings with observations from other technologies and ecosystems, shedding light on how VR has altered the privacy landscape for end-users. We further offer recommendations to alleviate users' privacy concerns, rectify misunderstandings, and encourage the adoption of privacy-conscious behaviors. Abhinaya S. B., Abhishri Agrawal, Yaxing Yao, Yixin Zou, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Towards Understanding Family Privacy and Security Literacy Conversations at Home: Design Implications for Privacy Literacy InterfacesabstractPolicymakers and researchers have emphasized the crucial role of parent-child conversations in shaping children’s digital privacy and security literacy. Despite this emphasis, little is known about the current nature of these parent-child conversations, including their content, structure, and children’s engagement during these conversations. This paper presents the findings of an interview study involving 13 parents of children ages under 13 reflecting on their privacy literacy practices at home. Through qualitative thematic analysis, we identify five categories of parent-child privacy and security conversations and examine parents’ perceptions of their children’s engagement during these discussions. Our findings show that although parents used different conversation approaches, rule-based conversations were one of the most common approaches taken by our participants, with example-based conversations perceived to be effective by parents. We propose important design implications for developing effective privacy educational technologies for families to support parent-child conversations. Kenan Kamel A Alghythee, Adel Hrncic, Karthik Singh, Sumanth Kunisetty, Yaxing Yao, Nikita Soni 0001 |
CHI | 5 |
| 2024 | An Empathy-Based Sandbox Approach to Bridge the Privacy Gap among Attitudes, Goals, Knowledge, and BehaviorsabstractManaging privacy to reach privacy goals is challenging, as evidenced by the privacy attitude-behavior gap. Mitigating this discrepancy requires solutions that account for both system opaqueness and users’ hesitations in testing different privacy settings due to fears of unintended data exposure. We introduce an empathy-based approach that allows users to experience how privacy attributes may alter system outcomes in a risk-free sandbox environment from the perspective of artificially generated personas. To generate realistic personas, we introduce a novel pipeline that augments the outputs of large language models (e.g., GPT-4) using few-shot learning, contextualization, and chain of thoughts. Our empirical studies demonstrated the adequate quality of generated personas and highlighted the changes in privacy-related applications (e.g., online advertising) caused by different personas. Furthermore, users demonstrated cognitive and emotional empathy towards the personas when interacting with our sandbox. We offered design implications for downstream applications in improving user privacy literacy. Wenxin Song, Yanfang Ye 0001, Yaxing Yao, Toby Jia-Jun Li |
CHI | 5 |
| 2024 | Understanding How to Inform Blind and Low-Vision Users about Data Privacy through Privacy Question Answering Assistants
Yuanyuan Feng, Abhilasha Ravichander, Yaxing Yao, Shikun Zhang, Rex Chen, Shomir Wilson, Norman M. Sadeh |
USENIX Security Symposium | 3 |
| 2024 | Users' Perceptions of Online Child Abuse Detection MechanismsabstractChild sexual exploitation and abuse (CSEA) online has become a major safety issue for children to access the Internet. To combat CSEA, electronics services providers (ESP) have implemented various mechanisms to detect child sexual abuse materials (CSAM). However, these mechanisms, despite their capability to prevent the mass distribution of CSAM online, may raise significant privacy concerns among general users. In this paper, we conducted a semi-structured interview study with 23 participants to understand their privacy perceptions of two types of online CSAM detection mechanisms. Our results suggested that users were concerned about the transparency of the detection process, inappropriate access to users' data, and unclear boundaries of such mechanisms. Our results also highlight that, even though the majority of participants choose to sacrifice their privacy for societal benefits, they still have privacy concerns that need to be addressed. We discuss the design and policy implications for ESP to improve users' awareness of the data practices of these mechanisms, alleviate users' privacy concerns, and increase societal benefits. Elmira Deldari, Parth Kirankumar Thakkar, Yaxing Yao |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | From Awareness to Action: Exploring End-User Empowerment Interventions for Dark Patterns in UXabstractThe study of UX dark patterns, i.e., UI designs that seek to manipulate user behaviors, often for the benefit of online services, has drawn significant attention in the CHI and CSCW communities in recent years. To complement previous studies in addressing dark patterns from (1) the designer's perspective on education and advocacy for ethical designs; and (2) the policymaker's perspective on new regulations, we propose an end-user-empowerment intervention approach that helps users (1) raise the awareness of dark patterns and understand their underlying design intents; (2) take actions to counter the effects of dark patterns using a web augmentation approach. Through a two-phase co-design study, including 5 co-design workshops (N=12) and a 2-week technology probe study (N=15), we reported findings on the understanding of users' needs, preferences, and challenges in handling dark patterns and investigated the feedback and reactions to users' awareness of and action on dark patterns being empowered in a realistic in-situ setting. Yuwen Lu, Chao Zhang 0082, Yuewen Yang, Yaxing Yao, Toby Jia-Jun Li |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2024 | Understanding Chinese Internet Users' Perceptions of, and Online Platforms' Compliance with, the Personal Information Protection Law (PIPL)abstractThe Personal Information Protection Law (PIPL) was implemented in November 2021 to safeguard the personal information rights and interests of Internet users in China. However, the impact and existing shortcomings of the PIPL remain unclear, carrying significant implications for policymakers. This study examined privacy policies on 13 online platforms before and after the PIPL. Concurrently, it conducted semi-structured interviews with 30 Chinese Internet users to assess their perceptions of the PIPL. Users were also given tasks to identify non-compliance within the platforms, assessing their ability to address related privacy concerns effectively. The research revealed various instances of non-compliance in post-PIPL privacy policies, especially concerning inadequate risk assessments for sensitive data. Although users identified some non-compliant activities like app eavesdropping, issues related to individual consent proved challenging. Surprisingly, over half of the interviewees believed that the government could access their personal data without explicit consent. Our findings and implications can be valuable for lawmakers, online platforms, users, and future researchers seeking to enhance personal privacy practices both in China and globally. Morgana Mo Zhou, Zhiyan Qu, Jinhan Wan, Yaxing Yao, Zhicong Lu |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2024 | Exploring Design Opportunities for Family-Based Privacy Education in Informal Learning SpacesabstractChildren face increasing privacy risks and the need to navigate complex choices, while privacy education is not sufficient due to limited education scope and family involvement. We advocate for informal learning spaces (ILS) as a pioneering channel for family-based privacy education, given their established role in holistic technology and digital literacy education, which specifically targets family groups. In this paper, we conducted an interview study with eight families to understand revealing current approaches to privacy education and engagement with ILS for family-based learning. Our findings highlight ILS’s transformative potential in family privacy education, considering existing practices and challenges. We discuss the design opportunities for family-based privacy education in ILS, covering goals, content, engagement, and experience design. These insights contribute to future research on family-based privacy education in ILS. Lanjing Liu, Lan Gao 0001, Nikita Soni 0001, Yaxing Yao |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | A Diary Study in Social Virtual Reality: Impact of Avatars with Disability Signifiers on the Social Experiences of People with DisabilitiesabstractPeople with disabilities (PWD) have shown a growing presence in the emerging social virtual reality (VR). To support disability representation, some social VR platforms start to involve disability features in avatar design. However, it is unclear how disability disclosure via avatars (and the way to present it) would affect PWD’s social experiences and interaction dynamics with others. To fill this gap, we conducted a diary study with 10 PWD who freely explored VRChat—a popular commercial social VR platform—for two weeks, comparing their experiences between using regular avatars and avatars with disability signifiers (i.e., avatar features that indicate the user’s disability in real life). We found that PWD preferred using avatars with disability signifiers and wanted to further enhance their aesthetics and interactivity. However, such avatars also caused embodied, explicit harassment targeting PWD. We revealed the unique factors that led to such harassment and derived design implications and protection mechanisms to inspire more safe and inclusive social VR. Kexin Zhang 0002, Elmira Deldari, Yaxing Yao, Yuhang Zhao 0001 |
ASSETS | 3 |
| 2023 | Exploring Smart Commercial Building Occupants' Perceptions and Notification Preferences of Internet of Things Data Collection in the United StatesabstractData collection through the Internet of Things (IoT) devices, or smart devices, in commercial buildings enables possibilities for increased convenience and energy efficiency. However, such benefits face a large perceptual challenge when being implemented in practice, due to the different ways occupants working in the buildings understand and trust in the data collection. The semi-public, pervasive, and multi-modal nature of data collection in smart buildings points to the need to study occupants’ understanding of data collection and notification preferences. We conduct an online study with 492 participants in the US who report working in smart commercial buildings regarding: 1) awareness and perception of data collection in smart commercial buildings, 2) privacy notification preferences, and 3) potential factors for privacy notification preferences. We find that around half of the participants are not fully aware of the data collection and use practices of IoT even though they notice the presence of IoT devices and sensors. We also discover many misunderstandings around different data practices. The majority of participants want to be notified of data practices in smart buildings, and they prefer push notifications to passive ones such as websites or physical signs. Surprisingly, mobile app notification, despite being a popular channel for smart homes, is the least preferred method for smart commercial buildings. Tu Le, Alan Wang 0002, Yaxing Yao, Yuanyuan Feng, Arsalan Heydarian, Norman M. Sadeh, Yuan Tian 0001 |
EuroS&P | 3 |
| 2023 | An Investigation of Teenager Experiences in Social Virtual Reality from Teenagers', Parents', and Bystanders' Perspectives
Elmira Deldari, Diana Freed, Julio Poveda, Yaxing Yao |
SOUPS | 4 |
| 2023 | "If sighted people know, I should be able to know: " Privacy Perceptions of Bystanders with Visual Impairments around Camera-based Technology
Yuhang Zhao 0001, Yaxing Yao, Jiaru Fu, Nihan Zhou |
USENIX Security Symposium | 2 |
| 2023 | Exploring Tenants' Preferences of Privacy Negotiation in Airbnb
Danny Yuxing Huang, Yaxing Yao |
USENIX Security Symposium | 3 |
| 2023 | The influence of explanation designs on user understanding differential privacy and making data-sharing decision
Zikai Wen, Jingyu Jia, Hongyang Yan, Yaxing Yao, Zheli Liu, Changyu Dong |
Inf. Sci. | 4 |
| 2022 | "It's Just Part of Me: " Understanding Avatar Diversity and Self-presentation of People with Disabilities in Social Virtual RealityabstractIn social Virtual Reality (VR), users are embodied in avatars and interact with other users in a face-to-face manner using avatars as the medium. With the advent of social VR, people with disabilities (PWD) have shown an increasing presence on this new social media. With their unique disability identity, it is not clear how PWD perceive their avatars and whether and how they prefer to disclose their disability when presenting themselves in social VR. We fill this gap by exploring PWD’s avatar perception and disability disclosure preferences in social VR. Our study involved two steps. We first conducted a systematic review of fifteen popular social VR applications to evaluate their avatar diversity and accessibility support. We then conducted an in-depth interview study with 19 participants who had different disabilities to understand their avatar experiences. Our research revealed a number of disability disclosure preferences and strategies adopted by PWD (e.g., reflect selective disabilities, present a capable self). We also identified several challenges faced by PWD during their avatar customization process. We discuss the design implications to promote avatar accessibility and diversity for future social VR platforms. Kexin Zhang 0002, Elmira Deldari, Zhicong Lu, Yaxing Yao, Yuhang Zhao 0001 |
ASSETS | 4 |
| 2022 | Exploring the Needs of Users for Supporting Privacy-Protective Behaviors in Smart HomesabstractIn this paper, we studied people’s smart home privacy-protective behaviors (SH-PPBs), to gain a better understanding of their privacy management do’s and don’ts in this context. We first surveyed 159 participants and elicited 33 unique SH-PPB practices, revealing that users heavily rely on ad hoc approaches at the physical layer (e.g., physical blocking, manual powering off). We also characterized the types of privacy concerns users wanted to address through SH-PPBs, the reasons preventing users from doing SH-PPBs, and privacy features they wished they had to support SH-PPBs. We then storyboarded 11 privacy protection concepts to explore opportunities to better support users’ needs, and asked another 227 participants to criticize and rank these design concepts. Among the 11 concepts, Privacy Diagnostics, which is similar to security diagnostics in anti-virus software, was far preferred over the rest. We also witnessed rich evidence of four important factors in designing SH-PPB tools, as users prefer (1) simple, (2) proactive, (3) preventative solutions that can (4) offer more control. Haojian Jin, Boyuan Guo, Rituparna Roychoudhury, Yaxing Yao, Swarun Kumar, Yuvraj Agarwal, Jason I. Hong |
CHI | 4 |
| 2022 | "It would probably turn into a social faux-pas": Users' and Bystanders' Preferences of Privacy Awareness Mechanisms in Smart HomesabstractThe opaque data practices in smart home devices have raised significant privacy concerns for smart home users and bystanders. One way to learn about the data practices is through privacy-related notifications. However, how to deliver these notifications to users and bystanders and increase their awareness of data practices is not clear. We surveyed 136 users and 123 bystanders to understand their preferences of receiving privacy-related notifications in smart homes. We further collected their responses to four mechanisms that improve privacy awareness (e.g., Data Dashboard) as well as their selections of mechanisms in four different scenarios (e.g., friend visiting). Our results showed the pros and cons of each privacy awareness mechanism, e.g., Data Dashboard can help reduce bystanders’ dependence on users. We also found some unique benefits of each mechanism (e.g., Ambient Light could provide unobtrusive privacy awareness). We summarized four key design dimensions for future privacy awareness mechanisms design. Parth Kirankumar Thakkar, Shijing He, Danny Yuxing Huang, Yaxing Yao |
CHI | 5 |
| 2022 | Impact and User Perception of Sandwich Attacks in the DeFi EcosystemabstractDecentralized finance (DeFi) enables crypto-asset holders to conduct complex financial transactions, while maintaining control over their assets in the blockchain ecosystem. However, the transparency of blockchain networks and the open mechanism of DeFi applications also cause new security issues. In this paper, we focus on sandwich attacks, where attackers take advantage of the transaction confirmation delay and cause financial losses for victims. We evaluate the impact and investigate users’ perceptions of sandwich attacks through a mix-method study. We find that due to users’ lack of technical background and insufficient notifications from the markets, many users were not aware of the existence and the impact of sandwich attacks. They also had a limited understanding of how to resolve the security issue. Interestingly, users showed high tolerance for the impact of sandwich attacks on individuals and the ecosystem, despite potential financial losses. We discuss general implications for users, DeFi applications, and the community. Kanye Ye Wang, Patrick Zuest, Yaxing Yao, Zhicong Lu, Roger Wattenhofer |
CHI | 3 |
| 2022 | Increasing Adoption of Tor Browser Using Informational and Planning NudgesabstractAbstract Browsing privacy tools can help people protect their digital privacy. However, tools which provide the strongest protections—such as Tor Browser—have struggled to achieve widespread adoption. This may be due to usability challenges, misconceptions, behavioral biases, or mere lack of awareness. In this study, we test the effectiveness of nudging interventions that encourage the adoption of Tor Browser. First, we test an informational nudge based on protection motivation theory (PMT), designed to raise awareness of Tor Browser and help participants form accurate perceptions of it. Next, we add an action planning implementation intention, designed to help participants identify opportunities for using Tor Browser. Finally, we add a coping planning implementation intention, designed to help participants overcome challenges to using Tor Browser, such as extreme website slowness. We test these nudges in a longitudinal field experiment with 537 participants. We find that our PMT-based intervention increased use of Tor Browser in both the short- and long-term. Our coping planning nudge also increased use of Tor Browser, but only in the week following our intervention. We did not find statistically significant evidence of our action planning nudge increasing use of Tor Browser. Our study contributes to a greater understanding of factors influencing the adoption of Tor Browser, and how nudges might be used to encourage the adoption of Tor Browser and similar privacy enhancing technologies. Peter Story, Daniel Smullen, Rex Chen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | How Usable Are iOS App Privacy Labels?abstractStandardized privacy labels that succinctly summarize those data practices that people are most commonly concerned about offer the promise of providing users with more effective privacy notices than full-length privacy policies. With their introduction by Apple in iOS 14 and Google’s recent adoption in its Play Store, mobile app privacy labels are for the first time available at scale to users. We report the first indepth interview study with 24 lay iPhone users to investigate their experiences, understanding, and perceptions of Apple’s privacy labels. We uncovered misunderstandings of and dissatisfaction with the iOS privacy labels that hinder their effectiveness, including confusing structure, unfamiliar terms, and disconnection from permission settings and controls. We identify areas where app privacy labels might be improved and propose suggestions to address shortcomings to make them more understandable, usable, and useful. Shikun Zhang, Yuanyuan Feng, Yaxing Yao, Lorrie Faith Cranor, Norman M. Sadeh |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | A Design Space for Privacy Choices: Towards Meaningful Privacy Control in the Internet of Thingsabstract“Notice and choice” is the predominant approach for data privacy protection today. There is considerable user-centered research on providing effective privacy notices but not enough guidance on designing privacy choices. Recent data privacy regulations worldwide established new requirements for privacy choices, but system practitioners struggle to implement legally compliant privacy choices that also provide users meaningful privacy control. We construct a design space for privacy choices based on a user-centered analysis of how people exercise privacy choices in real-world systems. This work contributes a conceptual framework that considers privacy choice as a user-centered process as well as a taxonomy for practitioners to design meaningful privacy choices in their systems. We also present a use case of how we leverage the design space to finalize the design decisions for a real-world privacy choice platform, the Internet of Things (IoT) Assistant, to provide meaningful privacy control in the IoT. Yuanyuan Feng, Yaxing Yao, Norman M. Sadeh |
CHI | 2 |
| 2021 | Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link TextsabstractIncreasingly, icons are being proposed to concisely convey privacy-related information and choices to users. However, complex privacy concepts can be difficult to communicate. We investigate which icons effectively signal the presence of privacy choices. In a series of user studies, we designed and evaluated icons and accompanying textual descriptions (link texts) conveying choice, opting-out, and sale of personal information — the latter an opt-out mandated by the California Consumer Privacy Act (CCPA). We identified icon-link text pairings that conveyed the presence of privacy choices without creating misconceptions, with a blue stylized toggle icon paired with “Privacy Options” performing best. The two CCPA-mandated link texts (“Do Not Sell My Personal Information” and “Do Not Sell My Info”) accurately communicated the presence of do-not-sell opt-outs with most icons. Our results provide insights for the design of privacy choice indicators and highlight the necessity of incorporating user testing into policy making. Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Joel R. Reidenberg, Norman M. Sadeh, Florian Schaub |
CHI | 3 |
| 2021 | Managing Potentially Intrusive Practices in the Browser: A User-Centered PerspectiveabstractAbstract Browser users encounter a broad array of potentially intrusive practices: from behavioral profiling, to crypto-mining, fingerprinting, and more. We study people’s perception, awareness, understanding, and preferences to opt out of those practices. We conducted a mixed-methods study that included qualitative (n=186) and quantitative (n=888) surveys covering 8 neutrally presented practices, equally highlighting both their benefits and risks. Consistent with prior research focusing on specific practices and mitigation techniques, we observe that most people are unaware of how to effectively identify or control the practices we surveyed. However, our user-centered approach reveals diverse views about the perceived risks and benefits, and that the majority of our participants wished to both restrict and be explicitly notified about the surveyed practices. Though prior research shows that meaningful controls are rarely available, we found that many participants mistakenly assume opt-out settings are common but just too difficult to find. However, even if they were hypothetically available on every website, our findings suggest that settings which allow practices by default are more burdensome to users than alternatives which are contextualized to website categories instead. Our results argue for settings which can distinguish among website categories where certain practices are seen as permissible, proactively notify users about their presence, and otherwise deny intrusive practices by default. Standardizing these settings in the browser rather than being left to individual websites would have the advantage of providing a uniform interface to support notification, control, and could help mitigate dark patterns. We also discuss the regulatory implications of the findings. Daniel Smullen, Yaxing Yao, Yuanyuan Feng, Norman M. Sadeh, Arthur Edelstein, Rebecca Weiss |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Awareness, Adoption, and Misconceptions of Web Privacy ToolsabstractAbstract Privacy and security tools can help users protect themselves online. Unfortunately, people are often unaware of such tools, and have potentially harmful misconceptions about the protections provided by the tools they know about. Effectively encouraging the adoption of privacy tools requires insights into people’s tool awareness and understanding. Towards that end, we conducted a demographically-stratified survey of 500 US participants to measure their use of and perceptions about five web browsing-related tools: private browsing, VPNs, Tor Browser, ad blockers, and antivirus software. We asked about participants’ perceptions of the protections provided by these tools across twelve realistic scenarios. Our thematic analysis of participants’ responses revealed diverse forms of misconceptions. Some types of misconceptions were common across tools and scenarios, while others were associated with particular combinations of tools and scenarios. For example, some participants suggested that the privacy protections offered by private browsing, VPNs, and Tor Browser would also protect them from security threats – a misconception that might expose them to preventable risks. We anticipate that our findings will help researchers, tool designers, and privacy advocates educate the public about privacy- and security-enhancing technologies. Peter Story, Daniel Smullen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | Defending My Castle: A Co-Design Study of Privacy Mechanisms for Smart HomesabstractHome is a person's castle, a private and protected space. Internet-connected devices such as locks, cameras, and speakers might make a home "smarter" but also raise privacy issues because these devices may constantly and inconspicuously collect, infer or even share information about people in the home. To explore user-centered privacy designs for smart homes, we conducted a co-design study in which we worked closely with diverse groups of participants in creating new designs. This study helps fill the gap in the literature between studying users' privacy concerns and designing privacy tools only by experts. Our participants' privacy designs often relied on simple strategies, such as data localization, disconnection from the Internet, and a private mode. From these designs, we identified six key design factors: data transparency and control, security, safety, usability and user experience, system intelligence, and system modality. We discuss how these factors can guide design for smart home privacy. Yaxing Yao, Justin Reed Basdeo, Smirity Kaushik, Yang Wang 0005 |
CHI | 1 |
| 2019 | Higher Education Check-Ins: Exploring the User Experience of Hybrid Location SensingabstractA large body of literature is dedicated to understanding people's check-in behavior when they use location sharing services to pair their location with a venue, e.g., a restaurant, a park, etc. Check-in behavior in higher education settings, e.g., where students and instructors have academic purposes for check-ins, is under-studied. In this work, we explore how university students apply two different mechanisms, i.e., automatic and manual location-sharing services, to conduct check-ins for an academic purpose (i.e., students sharing their class attendance with their instructor). More specifically, a Bluetooth Low Energy beacon-based technology is applied to enable automatic class check-ins. We conducted two field trials with a total of 141 university students. Our findings showed that several social, technological, and psychological factors impacted the use of auto and manual check-ins. Feedback from the student participants suggested that future higher education check-in systems may need to consider the integration of check-ins for a variety of purposes. Yun Huang 0003, Yisi Sang, Qunfang Wu, Yaxing Yao |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2019 | Privacy Perceptions and Designs of Bystanders in Smart HomesabstractAs the Internet of Things (IoT) devices make their ways into people's homes, traditional dwellings are turning into smart homes. While prior empirical studies have examined people's privacy concerns of smart homes and their desired ways of mitigating these concerns, the focus was primarily on the end users or device owners. Our research investigated the privacy perceptions and design ideas of smart home bystanders, i.e., people who are not the owners nor the primary users of smart home devices but can potentially be involved in the device usage, such as other family members or guests. We conducted focus groups and co-design activities with eighteen participants. We identified three impacting factors of bystanders' privacy perceptions (e.g., perceived norms) and a number of design factors to mitigate their privacy concerns (e.g., asking for device control). We highlighted bystanders' needs for privacy and controls, as well as the tension of privacy expectations between the owners/users and the bystanders in smart homes. We discussed how future designs can better support and balance the privacy needs of different stakeholders in smart homes. Yaxing Yao, Justin Reed Basdeo, Oriana Rosata Mcdonough, Yang Wang 0005 |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2019 | "What if?" Predicting Individual Users' Smart Home Privacy Preferences and Their ChangesabstractAbstract Smart home devices challenge a long-held notion that the home is a private and protected place. With this in mind, many developers market their products with a focus on privacy in order to gain user trust, yet privacy tensions arise with the growing adoption of these devices and the risk of inappropriate data practices in the smart home (e.g., secondary use of collected data). Therefore, it is important for developers to consider individual user preferences and how they would change under varying circumstances, in order to identify actionable steps towards developing user trust and exercising privacy-preserving data practices. To help achieve this, we present the design and evaluation of machine learning models that predict (1) personalized allow/deny decisions for different information flows involving various attributes, purposes, and devices (AUC .868), (2) what circumstances may change original decisions (AUC .899), and (3) how much (US dollars) one may be willing to pay or receive in exchange for smart home privacy (RMSE 12.459). We show how developers can use our models to derive actionable steps toward privacy-preserving data practices in the smart home. Natã M. Barbosa, Joon S. Park, Yaxing Yao, Yang Wang 0005 |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Privacy Mechanisms for Drones: Perceptions of Drone Controllers and BystandersabstractDrones pose privacy concerns such as surveillance and stalking. Many technology-based or policy-based mechanisms have been proposed to mitigate these concerns. However, it is unclear how drone controllers and bystanders perceive these mechanisms and whether people intend to adopt them. In this paper, we report results from two rounds of online survey with 169 drone controllers and 717 bystanders in the U.S. We identified respondents' perceived pros and cons of eight privacy mechanisms. We found that owner registration and automatic face blurring individually received most support from both controllers and bystanders. Our respondents also suggested using varied combinations of mechanisms under different drone usage scenarios, highlighting their context-dependent preferences. We outline a set of important questions for future privacy designs and public policies of drones. Yaxing Yao, Huichuan Xia, Yun Huang 0003, Yang Wang 0005 |
CHI | 1 |
| 2017 | Free to Fly in Public Spaces: Drone Controllers' Privacy Perceptions and PracticesabstractPrior research has discovered various privacy concerns that bystanders have about drones. However, little is known about drone controllers' privacy perceptions and practices of drones. Understanding controllers' perspective is important because it will inform whether controllers' current practices protect or infringe on bystanders' privacy and what mechanisms could be designed to better address the potential privacy issues of drones. In this paper, we report results from interviews of 12 drone controllers in the US. Our interviewees treated safety as their top priority but considered privacy issues of drones exaggerated. Our results also highlight many significant differences in how controllers and bystanders think about drone privacy, for instance, how they determine public vs. private spaces and whether notice and consent of bystanders are needed. Yaxing Yao, Huichuan Xia, Yun Huang 0003, Yang Wang 0005 |
CHI | 1 |
| 2017 | Folk Models of Online Behavioral AdvertisingabstractOnline Behavioral Advertising (OBA) is pervasive on the Internet. While there is a line of empirical research that studies Internet users' attitudes and privacy preferences of OBA, little is known about their actual understandings of how OBA works. This is an important question to answer because people often draw on their understanding to make decisions. Through a qualitative study conducted in an iterative manner, we identify four "folk models" held by our participants about how OBA works and show how these models are either incomplete or inaccurate in representing common OBA practices. We discuss how privacy tools can be designed to consider these folk models. In addition, most of our participants felt that the information being tracked is more important than who the web trackers are. This suggests the potential for an information-based blocking scheme rather than a tracker-based blocking scheme used by most existing ad-blocking tools. Yaxing Yao, Davide Lo Re, Yang Wang 0005 |
CSCW | 1 |
| 2016 | Flying Eyes and Hidden Controllers: A Qualitative Study of People's Privacy Perceptions of Civilian Drones in The USabstractAbstract Drones are unmanned aircraft controlled remotely or operated autonomously. While the extant literature suggests that drones can in principle invade people’s privacy, little is known about how people actually think about drones. Drawing from a series of in-depth interviews conducted in the United States, we provide a novel and rich account of people’s privacy perceptions of drones for civilian uses both in general and under specific usage scenarios. Our informants raised both physical and information privacy issues against government, organization and individual use of drones. Informants’ reasoning about the acceptance of drone use was in part based on whether the drone is operating in a public or private space. However, our informants differed significantly in their definitions of public and private spaces. While our informants’ privacy concerns such as surveillance, data collection and sharing have been raised for other tracking technologies such as camera phones and closed-circuit television (CCTV), our interviews highlight two heightened issues of drones: (1) powerful yet inconspicuous data collection, (2) hidden and inaccessible drone controllers. These two aspects of drones render some of people’s existing privacy practices futile (e.g., notice recording and ask controllers to stop or delete the recording). Some informants demanded notifications of drones near them and expected drone controllers asking for their explicit permissions before recording. We discuss implications for future privacy-enhancing drone designs. Yang Wang 0005, Huichuan Xia, Yaxing Yao, Yun Huang 0003 |
Proc. Priv. Enhancing Technol. | 3 |