EDBT 2026 Demo / reviewers in the wild / expert
Ruba Abu-Salma
dblp:163/8698
· DBLP profile ↗
19ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0002-5316-9956ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 10 · 2 first-author · 9 since 2021Security and privacy · 9 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "Create an environment that protects women, rather than selling anxiety!": Participatory Threat Modelling with Chinese Young Women Living AloneabstractAs more young women in China live alone, they navigate entangled privacy, security, and safety (PSS) risks across smart homes, online platforms, and public infrastructures. Drawing on six participatory threat modeling (PTM) workshops (n = 33), we present a human-centered threat model that illustrates how digitally facilitated physical violence, digital harassment and scams, and pervasive surveillance by individuals, companies, and the state are interconnected and mutually reinforcing. We also document four mitigation strategies employed by participants: smart home device configurations, boundary management, sociocultural practices, and social media tactics–each of which can introduce new vulnerabilities and emotional burdens. Based on these insights, we developed a digital PSS guidebook for young women living alone (YWLA) in China. We further propose actionable design implications for smart home devices and social media platforms, along with policy and legal recommendations and directions for educational interventions. Shijing He, Chenkai Ma, Chi Zhang 0084, Adam D. G. Jenkins, Ruba Abu-Salma, Jose M. Such |
CHI | 5 |
| 2026 | Investigating Bystander Privacy in Chinese Smart Home AppsabstractBystander privacy in smart homes has been widely studied in Western contexts, yet it remains underexplored in non-Western countries such as China. In this study, we analyze 49 Chinese smart home apps using a mixed-methods approach, including privacy policy review, UX/UI evaluation, and assessment of Apple App Store privacy labels. While most apps nominally comply with national regulations, we identify significant gaps between written policies and actual implementation. Our traceability analysis highlights inconsistencies in data controls and a lack of transparency in data-sharing practices. Crucially, bystander privacy—particularly for visitors and non-user individuals—is largely absent from both policy documents and interface design. Additionally, discrepancies between privacy labels and actual data practices threaten user trust and undermine informed consent. We provide design recommendations to strengthen bystander protections, improve privacy-oriented UI transparency, and enhance the credibility of privacy labels, supporting the development of inclusive smart home ecosystems in non-Western contexts. Shijing He, Yaxiong Lei, Chi Zhang 0084, Ruba Abu-Salma, Jose M. Such |
CHI | 5 |
| 2026 | Privacy and Safety Experiences and Concerns of US Women Using Generative AI for Seeking Sexual and Reproductive Health InformationabstractThe rapid adoption of generative AI (GenAI) chatbots has reshaped access to sexual and reproductive health (SRH) information, particularly following the overturning of Roe v. Wade, as individuals assigned female at birth increasingly turn to online sources. However, existing research remains largely model-centered, paying limited attention to user privacy and safety. We conducted semi-structured interviews with 18 U.S.-based participants from both restrictive and non-restrictive states who had used GenAI chatbots to seek SRH information. Adoption was influenced by perceived utility, usability, credibility, accessibility, and anthropomorphism, and many participants disclosed sensitive personal SRH details. Participants identified multiple privacy risks, including excessive data collection, government surveillance, profiling, model training, and data commodification. While most participants accepted these risks in exchange for perceived utility, abortion-related queries elicited heightened safety concerns. Few participants employed protective strategies beyond minimizing disclosures or deleting data. Based on these findings, we offer design and policy recommendations—such as health-specific features and stronger moderation practices—to enhance privacy and safety in GenAI-supported SRH information seeking. Ina Kaleva, Xiao Zhan, Ruba Abu-Salma, Jose M. Such |
CHI | 3 |
| 2026 | Privacy Perspectives and Practices of Chinese Smart Home Product TeamsabstractPrevious research has explored the privacy needs and concerns of device owners, primary users, and different bystander groups with regard to smart home devices like security cameras, smart speakers, and hubs, but little is known about the privacy views and practices of smart home product teams, particularly those in non-Western contexts. This paper presents findings from 27 semi-structured interviews with Chinese smart home product team members, including product/project managers, software/hardware engineers, user experience (UX) designers, legal/privacy experts, and marketers/operation specialists. We examine their privacy perspectives, practices, and risk mitigation strategies. Our results show that participants emphasized compliance with Chinese data privacy laws, which typically prioritized national security over individual privacy rights. China-specific cultural, social, and legal factors also influenced participants' ethical considerations and attitudes toward balancing user privacy and security with convenience. Drawing on our findings, we propose a set of recommendations for smart home product teams, along with socio-technical and legal interventions to address smart home privacy issues-especially those belonging to at-risk groups-in Chinese multi-user smart homes. Shijing He, Yaxiong Lei, Xiao Zhan, Chi Zhang 0084, Juan Ye, Ruba Abu-Salma, Jose M. Such |
SP | 6 |
| 2026 | "I don't think it needs to be political": Privacy Experiences and Concerns of FemHealth App Users in the United StatesabstractFemHealth apps have rapidly developed, offering innovative opportunities to track users’ menstrual cycles, fertility, pregnancy, and other aspects of sexual and reproductive health. However, such apps collect a significant amount of sensitive user health data, posing privacy risks to users. In this paper, we conducted 14 in-depth semistructured interviews with current and past users of FemHealth apps in the US to examine their privacy experiences and concerns. We found that participants were concerned about a wider range of risks than was found in prior user research about FemTech, including criminalization related to abortion or contraceptive access; emotional distress related to social stigma; third-party data sharing; and targeted advertising based on processing sensitive health data. Some participants acknowledged that FemHealth apps posed privacy risks and potential harms to users in general but were not necessarily concerned about their own privacy due to privilege (e.g., living in a state with strong reproductive health rights). However, all participants agreed that user privacy and data protection in FemHealth apps should be considered a fundamental right, not subject to legal discourse in specific locales. Most participants felt unsure about the effectiveness of existing data protection regulations and their interplay with anti-abortion laws. Participants suggested several ways to mitigate privacy risks, including disclosures and controls, back-end technical protections, behavioral strategies, and policy improvements. We provide recommendations for extending practical and policy-based privacy protections of sexual and reproductive health data collected by FemHealth apps. Ina Kaleva, Alisa Frik, Lisa Mekioussa Malki, Mark Warner, Ruba Abu-Salma |
Proc. Priv. Enhancing Technol. | 5 |
| 2026 | "Users are worried, but we are confused": Exploring the Privacy, Security, and Safety Perspectives and Practices of FemHealth App Product Team MembersabstractFemHealth apps (e.g., period, fertility, and pregnancy trackers) collect highly sensitive sexual and reproductive health data and have become a focal point for privacy, security, and safety (PSS) concerns, particularly amid changes in reproductive health regulations in the US and growing public scrutiny. While prior work has identified shortcomings in the PSS protections implemented by FemHealth apps, far less is known about how the product teams developing these apps conceptualize and operationalize PSS in practice. We conducted semi-structured interviews with 14 FemHealth app product team members who represented 11 unique apps and held diverse roles, including software engineering and architecture, security and privacy, product management, policy and legal compliance, and UX/UI research and design. We found that data collection decisions are often driven by feature-specific objectives, such as improving prediction accuracy and enabling reliable backups, rather than by explicitly articulated PSS requirements. Teams also frequently rely on legal compliance frameworks and PSS practices designed for general-purpose apps, while expressing confidence that these measures provide adequate protection. In addition, we identified four persistent challenges faced by FemHealth app product teams: disagreement over whether FemHealth apps require distinct PSS protections compared to non-FemHealth apps; difficulty establishing and maintaining user trust; uncertainty arising from cross-border enforcement related to abortion; and technical limitations associated with backups, end-to-end encryption, and coercive local access to data. Based on these findings, we derive a set of requirements and provide actionable technical and policy recommendations to inform the design, engineering, and governance of PSS in FemHealth apps. Chenkai Ma, Shijing He, Ina Kaleva, Alisa Frik, Jose M. Such, Ruba Abu-Salma |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | Exploring the Privacy and Security Challenges Faced by Migrant Domestic Workers in Chinese Smart HomesabstractFunding: Shijing He is supported by a King’s-China Scholarship Council (K-CSC) PhD Scholarship, and Yaxiong Lei is supported by a Joint Scholarship from the University of St Andrews and China Scholarship Council. Shijing He, Xiao Zhan, Yaxiong Lei, Yueyan Liu, Ruba Abu-Salma, Jose M. Such |
CHI | 5 |
| 2025 | "They Didn't Buy Their Smart TV to Watch Me with the Kids": Comparing Nannies' and Parents' Privacy Threat Models for Smart Home DevicesabstractSmart home devices raise privacy concerns among not only primary users but also bystanders like domestic workers. We conducted 25 qualitative interviews with nannies and 16 with parents who employed nannies, in the U.S., to explore and compare their views on and privacy threat models for smart home devices. We found device-specific purposes of use inspired different perspectives among nanny participants. Most were comfortable with employers’ smart speakers and smart TVs, whose purpose had nothing to do with them. However, with indoor smart cameras, nanny participants were often not just bystanders but targets of monitoring; in such situations, they had a wider range of attitudes. In contrast, parent participants tended to have more similar views across devices. We found notable disconnects regarding disclosure, where nanny participants often hesitated to ask about cameras, but parent participants assumed nannies just didn’t care. We recommend prioritizing interventions supporting disclosure, discussion, and sharing control. Ruba Abu-Salma, Junghyun Choy, Alisa Frik, Julia Bernd |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2025 | Bystander Privacy in Smart Homes: A Systematic Review of Concerns and SolutionsabstractSmart home devices, such as security cameras and voice assistants, have seen widespread adoption due to the utility and convenience they offer to users. The deployment of these devices in homes, however, raises privacy concerns for bystanders—people who may not necessarily have a say in the deployment and configuration of these devices, and yet are exposed to or affected by their data collection. Examples of bystanders include guests, short-term tenants, and domestic workers. Prior work has studied the privacy concerns of different bystander groups and proposed design solutions for addressing these concerns. In this article, we present a systematic review of previous studies, describing how smart home bystanders are defined and classified, and illuminating the range of concerns and solutions proposed in the existing academic literature. We also discuss limitations in prior work, barriers to the uptake of research-based solutions by industry, and identify avenues for future research. Eimaan Saqib, Shijing He, Junghyun Choy, Ruba Abu-Salma, Jose M. Such, Julia Bernd, Mobin Javed |
ACM Trans. Comput. Hum. Interact. | 4 |
| 2024 | Surveys Considered Harmful? Reflecting on the Use of Surveys in AI Research, Development, and GovernanceabstractCalls for engagement with the public in Artificial Intelligence (AI) research, development, and governance are increasing, leading to the use of surveys to capture people's values, perceptions, and experiences related to AI. In this paper, we critically examine the state of human participant surveys associated with these topics. Through both a reflexive analysis of a survey pilot spanning six countries and a systematic literature review of 44 papers featuring public surveys related to AI, we explore prominent perspectives and methodological nuances associated with surveys to date. We find that public surveys on AI topics are vulnerable to specific Western knowledge, values, and assumptions in their design, including in their positioning of ethical concepts and societal values, lack sufficient critical discourse surrounding deployment strategies, and demonstrate inconsistent forms of transparency in their reporting. Based on our findings, we distill provocations and heuristic questions for our community, to recognize the limitations of surveys for meeting the goals of engagement, and to cultivate shared principles to design, deploy, and interpret surveys cautiously and responsibly. Mohammad Tahaei, Daricia Wilkinson, Alisa Frik, Ruba Abu-Salma, Lauren Wilcox |
AIES (1) | 5 |
| 2024 | Exploring Privacy Practices of Female mHealth Apps in a Post-Roe WorldabstractMobile apps which support women’s health have developed rapidly alongside the increasing de-stigmatisation of female reproductive wellbeing. However, the ubiquity of these apps has advanced the practice of intimate surveillance and the commodification of sensitive user data. While the overturning of Roe v. Wade has prompted reflection on the privacy and safety implications of female mobile health (mHealth) apps, the privacy practices of these apps have yet to be thoroughly examined in a post-Roe world. We investigated the privacy practices of 20 popular female mHealth apps, combining a thematic analysis of Data safety sections and privacy policies with a privacy-focused usability inspection. Our findings revealed problematic practices, including inconsistencies across privacy policy content and privacy-related app features, flawed consent and data deletion mechanisms, and covert gathering of sensitive data. We present recommendations for improving privacy practices, and call for a dedicated focus not only on user privacy, but also safety. Lisa Mekioussa Malki, Ina Kaleva, Dilisha Patel, Mark Warner, Ruba Abu-Salma |
CHI | 5 |
| 2024 | "My Best Friend's Husband Sees and Knows Everything": A Cross-Contextual and Cross-Country Approach to Understanding Smart Home PrivacyabstractAs smart home devices proliferate, protecting the privacy of those who encounter the devices is of the utmost importance both within their own home and in other people's homes. In this study, we conducted a large-scale survey (N=1459) with primary users of and bystanders to smart home devices. While previous work has studied people's privacy experiences and preferences either as smart home primary users or as bystanders, there is a need for a deeper understanding of privacy experiences and preferences in different contexts and across different countries. Instead of classifying people as either primary users or bystanders, we surveyed the same participants across different contexts. We deployed our survey in four countries (Germany, Mexico, the United Kingdom, and the United States) and in two languages (English and Spanish). We found that participants were generally more concerned about devices in their own homes, but perceived video cameras—especially unknown ones—and usability as more concerning in other people's homes. Compared to male participants, female and non-binary participants had less control over configuration of devices and privacy settings—regardless of whether they were the most frequent user. Comparing countries, participants in Mexico were more likely to be comfortable with devices, but also more likely to take privacy precautions around them. We also make cross-contextual recommendations for device designers and policymakers, such as nudges to facilitate social interactions. Tess Despres, Marcelino Ayala Constantino, Naomi Zacarias Lizola, Gerardo Sánchez Romero, Shijing He, Xiao Zhan, Noura Abdi, Ruba Abu-Salma, Jose M. Such, Julia Bernd |
Proc. Priv. Enhancing Technol. | 8 |
| 2024 | Cross-Contextual Examination of Older Adults' Privacy Concerns, Behaviors, and VulnerabilitiesabstractA growing body of research has examined the privacy concerns and behaviors of older adults, often within specific contexts. It remains unclear to what extent older adults' privacy concerns and behaviors vary across contexts and whether old age is the primary factor influencing privacy vulnerabilities. To address this gap, we conducted semi-structured interviews with 43 older adults (aged 65 to 89) in the United States. Our interviews were grounded in five scenarios: account and device sharing, healthcare, online advertising, social networking, and cybercrime. Our cross-contextual analysis showed that cybercrime was a recurring and pressing concern across scenarios; privacy concerns and protective behaviors were rarely mentioned in the healthcare scenario. Across all scenarios, participants' threat models and strategies revolved around data collection rather than other stages in which privacy harms may occur; they employed various active strategies to safeguard their privacy while trusting service providers to protect their information. Our findings underscore the need to revisit the discussion around privacy vulnerability and aging. Vulnerability levels among our participants varied widely and were often influenced by factors beyond age, such as tech savviness and income. We discuss opportunities for privacy interventions, technologies, and education that promote positive aging and recognize diversity among older adults. Yixin Zou, Kaiwen Sun 0001, Tanisha Afnan, Ruba Abu-Salma, Robin Brewer, Florian Schaub |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsabstractWhile the literature on permissions from the end-user perspective is rich, there is a lack of empirical research on why developers request permissions, their conceptualization of permissions, and how their perspectives compare with end-users’ perspectives. Our study aims to address these gaps using a mixed-methods approach. Mohammad Tahaei, Ruba Abu-Salma, Awais Rashid |
CHI | 2 |
| 2022 | "They Look at Vulnerability and Use That to Abuse You": Participatory Threat Modelling with Migrant Domestic Workers
Julia Slupska, Selina Y. Cho, Marissa Begonia, Ruba Abu-Salma, Nayanatara Prakash, Mallika Balakrishnan |
USENIX Security Symposium | 4 |
| 2020 | Understanding User Perceptions of Security and Privacy for Group Chat: A Survey of Users in the US and UKabstractSecure messaging tools are an integral part of modern society. While there is a significant body of secure messaging research generally, there is a lack of information regarding users’ security and privacy perceptions and requirements for secure group chat. To address this gap, we conducted a survey of 996 respondents in the US and UK. The results of our study show that group chat presents important security and privacy challenges, some of which are not present in one-to-one chat. For example, users need to be able to manage and monitor group membership, establish trust for new group members, and filter content that they share in different chat contexts. Similarly, we find that the sheer volume of notifications that occur in group chat makes it extremely likely that users ignore important security or privacy notifications. We also find that respondents lack mechanisms for determining which tools are secure and instead rely on non-technical strategies for protecting their privacy—for example, self-filtering what they post and carefully tracking group membership. Based on these findings, we provide recommendations on how to improve the security and usability of secure group chat. Sean Oesch, Ruba Abu-Salma, Oumar Diallo, Juliane Krämer, James Simmons, Justin Wu, Scott Ruoti |
ACSAC | 2 |
| 2020 | Evaluating the End-User Experience of Private Browsing ModeabstractIn this paper, we investigate why users of private browsing mode misunderstand the benefits and limitations of private browsing. We design and conduct a three-part study: (1) an analytic evaluation of the user interface of private mode in different browsers; (2) a qualitative user study to explore user mental models of private browsing; (3) a participatory design study to investigate why existing browser disclosures, the in-browser explanations of private mode, do not communicate the actual protection of private mode. We find the user interface of private mode in different browsers violated well-established design guidelines and heuristics. Further, most participants had incorrect mental models of private browsing, influencing their understanding and usage of private mode. We also find existing browser disclosures did not explain the primary security goal of private mode. Drawing from the results of our study, we extract a set of recommendations to improve the design of disclosures. Ruba Abu-Salma, Benjamin Livshits |
CHI | 1 |
| 2017 | Obstacles to the Adoption of Secure Communication ToolsabstractThe computer security community has advocated widespread adoption of secure communication tools to counter mass surveillance. Several popular personal communication tools (e.g., WhatsApp, iMessage) have adopted end-to-end encryption, and many new tools (e.g., Signal, Telegram) have been launched with security as a key selling point. However it remains unclear if users understand what protection these tools offer, and if they value that protection. In this study, we interviewed 60 participants about their experience with different communication tools and their perceptions of the tools' security properties. We found that the adoption of secure communication tools is hindered by fragmented user bases and incompatible tools. Furthermore, the vast majority of participants did not understand the essential concept of end-to-end encryption, limiting their motivation to adopt secure tools. We identified a number of incorrect mental models that underpinned participants' beliefs. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova, Alena Naiakshina, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 1 |
| 2015 | POSTER: Secure Chat for the Masses? User-centered Security to the RescueabstractIn light of recent revelations of mass state surveillance of phone and Internet communications, many solutions now claim to provide secure messaging. This includes both a broad range of new projects and several widely adopted applications that have added security features. However, despite the demand for better solutions, there is no clear winner in the race for widespread development and deployment of messaging products. Recently, the Electronic Frontier Foundation evaluated dozens of messaging tools based on security best practices, and publicized the results via the Secure Messaging Scorecard. Our goal is to expand the scorecard by evaluating messaging tools on a range of usefulness (utility and usability) attributes. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Matthew Smith 0001 |
CCS | 1 |