EDBT 2026 Demo / reviewers in the wild / expert
Verena Zimmermann
dblp:198/5724
· DBLP profile ↗
23ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0002-6873-8146ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 17 · 5 first-author · 12 since 2021Security and privacy · 7 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Personalization over Privacy? Implications of the Privacy-Personalization Trade-Off on Future Use of Intelligent Tutoring Systems
Adrienn Toth, Linda Fanconi, Noé Zufferey, Verena Zimmermann |
AIED (6) | 4 |
| 2025 | "I Would Share It, But..." Exploring Ways to Optimize the Privacy-Personalization Trade-Off in Intelligent Tutoring Systems
Adrienn Toth, Neele Roch, Noé Zufferey, Verena Zimmermann |
AIED (5) | 4 |
| 2025 | Beyond Deterrence: A Systematic Review of the Role of Autonomous Motivation in Organizational Security Behavior StudiesabstractWhat drives employees to ensure security when handling information assets in organizations? There is growing interest from the security behavior community in how autonomous motivators shape employees’ security-related behaviors. To reconcile the scattered viewpoints on autonomous motivation and synthesize findings from studies utilizing various theoretical frameworks, we systematically reviewed relevant publications. We present a preregistered literature review that investigated (a) what forms of autonomous motivation have been examined in organizational security contexts, (b) which behaviors/behavioral intentions are related to autonomous motivators, and (c) how autonomous motivation affects employees’ security behaviors. Based on an initial set of 432 papers, filtered down to 45 studies, we identified 17 unique autonomous motivators and three types of related security behaviors. This review not only develops a refined taxonomy of autonomous motivation related to security behaviors but also charts a path forward for future research on autonomous motivation in human-centered security. Xiaowei Chen 0013, Lorin Schöni, Verena Distler, Verena Zimmermann |
CHI | 4 |
| 2025 | Fear, Fun or None: A Qualitative Quest Towards Unlocking Cybersecurity Attitudes
Alexandra von Preuschen, Carolin Benda, Monika C. Schuhmacher, Verena Zimmermann |
CHI | 4 |
| 2025 | It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationabstractEffective training is essential for enhancing users’ ability to detect phishing attempts. Personalised training offers huge potential to more closely align training content with individuals’ needs and skill levels. In an online study, we assigned N=342 participants to personalised training or a random training variant to compare their effectiveness. The personalisation was based on a phishing proficiency score calculated from factors such as detection ability, knowledge, and security attitude. After training, the participants demonstrated greater proficiency, with an increased ability to detect phishing emails and higher security attitudes. These effects were most pronounced in the personalised condition, demonstrating the potential of personalisation to improve training outcomes. Overall, personalised training levelled the playing field, efficiently bringing all groups, regardless of their initial proficiency, to a comparable and desired post-training phishing proficiency level. Finally, we derived recommendations for designing personalised phishing training content and assigning users to suitable training programmes. Lorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier, Peter Mayer 0001, Verena Zimmermann |
CHI | 6 |
| 2025 | Stop the Clock - Counteracting Bias Exploited by Attackers through an Interactive Augmented Reality Phishing Training
Lorin Schöni, Martin Strohmeier, Ivo Sluganovic, Verena Zimmermann |
CHI | 4 |
| 2025 | Unpacking the Social and Emotional Dimensions of Security and Privacy User Engagement
Nina Gerber, Verena Zimmermann, Alexandra von Preuschen, Karen Renaud |
SOUPS | 2 |
| 2025 | Let's Get Visual - Testing Visual Analogies and Metaphors for Conveying Privacy Policies and Data Handling InformationabstractWith EU-GDPR and related regulations, the respon-sibility to make privacy-related decisions such as to provide informed consent to data handling practices mainly rests with the user. However, current lengthy privacy policies and often deceptive cookie notices rarely facilitate truly informed consent. Related work on privacy icons or structuring privacy policies aims to enhance users' understanding but achieve mixed results. In a between-subjects study with N=379 participants we thus explored the potential of embedding privacy information in visual metaphors and analogies to support informed decision-making. Additionally, we explored whether dynamic feedback helped users understand the implications of their decisions. While both visual and textual information and feedback appeared to support users' understanding of data handling practices and alignment with personal preferences, with no significant differences between conditions, users per-ceived visualizations as more suitable and aesthetically pleasing than text. This indicates potential for using visual contexts to enhance informed consent not only within existing cookie notices but also in emerging tools such as privacy assistants or related privacy-enhancing technologies. Future work should investigate differences to currently deployed solutions and the effect of perceived pleasantness of design variants on users' understanding and decisions. Verena Zimmermann, Adrienn Toth, Hannah Sievers, Linda Fanconi, Yanis Isenring, Mona Henz, Alina Stöver, Nina Gerber |
SP | 1 |
| 2025 | 'AI is from the devil.' Behaviors and Concerns Toward Personal Data Sharing with LLM-based Conversational AgentsabstractWith the increased performance of large language models (LLMs), conversational agents (CA), such as ChatGPT, are nowadays available to any individual requiring little technical knowledge and skills. Initial studies that have investigated related privacy risks primarily focused on either technical aspects and misuse of these tools, or captured overall perceptions of CA users in small-scale qualitative evaluations. Complementing and extending previous work, we used a quantitative user-centered approach to analyze and compare the behaviors and concerns of users and non-users. We conducted a survey study (N=422) with (1) service users, i.e., users of CA services, (2) local users, i.e., users of a local instance of CA (partially local users, or fully local users), and (3) non-users. We collected self-reported usage patterns and personal data-sharing behavior as well as privacy concerns related to different types of personal data (e.g., health data, demographics, or opinions). Furthermore, we analyze individuals' intention to use CA services in multiple scenarios. Our findings show that users of CA services generally have fewer privacy concerns than non-users. While users rarely share data related to personal identifiers and account credentials, they tend to often share data related to lifestyle, health, standard of living, and opinions. Surprisingly, partially local users tend to share more data with CA services as they also generally use CA services more often and for more diverse purposes. Also, while the majority of CA services users declared not being willing to prioritize CA services as an information source in the described scenarios such as seeking legal advice, between about one-quarter and one-third of partially local users would use CA services for all scenarios. Furthermore, half of the users were willing to stop using CA for privacy reasons (e.g., in case of data leaks), whereas a large majority of non-users reported not using CAs simply because they do not have the need or the opportunity. Our work highlights the high privacy risks for CA services users as CA services largely expand the amount of any type of personal information that can be collected by companies. Noé Zufferey, Sarah Abdelwahab Gaballah, Karola Marky, Verena Zimmermann |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Authenticate as You Go: From Exploring Smart Home Authentication with Daily Objects to Authenticating with Primary TasksabstractSmart home applications aim to increase convenience, yet often require authentication to protect sensitive data. This is non-trivial: effortful authentication contradicts intended convenience, the multitude of devices raises scalability issues, many devices lack suitable interfaces, and the presence of other inhabitants requires intentional and acceptable interactions. To address these issues, we explored new and creative authentication interactions with an interaction relabeling approach using everyday objects. We conducted six focus group workshops with 20 participants in a living room and a kitchen setting that resulted in a variety of creative authentication interactions with analogue and digital objects. Furthermore, participants created authentication interactions based on tasks that they have to or wish to perform anyway such as cleaning the kitchen—thus primary tasks. This led us to explore the option to transform authentication from being an additional, secondary task toward using primary tasks further in an online study with 194 participants. Relevant implications in terms of acceptable authentication task characteristics, user perceptions, arising security challenges, and psychological habit research are discussed. Verena Zimmermann, Stina Schäfer, Markus Dürmuth, Karola Marky |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2024 | Decide Yourself or Delegate - User Preferences Regarding the Autonomy of Personal Privacy Assistants in Private IoT-Equipped EnvironmentsabstractPersonalized privacy assistants (PPAs) communicate privacy-related decisions of their users to Internet of Things (IoT) devices. There are different ways to implement PPAs by varying the degree of autonomy or decision model. This paper investigates user perceptions of PPA autonomy models and privacy profiles – archetypes of individual privacy needs – as a basis for PPA decisions in private environments (e.g., a friend’s home). We first explore how privacy profiles can be assigned to users and propose an assignment method. Next, we investigate user perceptions in 18 usage scenarios with varying contexts, data types and number of decisions in a study with 1126 participants. We found considerable differences between the profiles in settings with few decisions. If the number of decisions gets high (> 1/h), participants exclusively preferred fully autonomous PPAs. Finally, we discuss implications and recommendations for designing scalable PPAs that serve as privacy interfaces for future IoT devices. Karola Marky, Alina Stöver, Sarah Prange, Kira Bleck, Paul Gerber, Verena Zimmermann, Florian Müller 0003, Florian Alt, Max Mühlhäuser |
CHI | 6 |
| 2024 | Block Cookies, Not Websites: Analysing Mental Models and Usability of the Privacy-Preserving Browser Extension CookieBlockabstractIn the modern web, users are confronted with a plethora of complex privacy-related decisions about cookies and consent, often com- pounded by misleading policies and deceptive patterns. Past efforts to enhance online privacy have failed due to their dependence on website compliance. A solution to this lies in privacy-enhancing tools that are directly controlled by the user. However, challenges related to the usability and flawed understanding of the tools’ func- tionality hinder their widespread adoption. To address this problem, we evaluated the browser extension CookieBlock as an example of a current tool, which supports users by blocking tracking cookies independent of website compliance. We used a complementary approach consisting of an expert eval- uation of CookieBlock and the related tools NoScript and Ghostery, and a laboratory user study focusing on the unique details of how users interact with CookieBlock specifically. The laboratory study with 42 participants investigated usage, mental models, and us- ability of CookieBlock based on eye tracking, interaction, and self- report data. While CookieBlock received good usability ratings, 18 participants were unable to solve a website breakage caused by cookie misclassification on their own. Overall, the results revealed flawed mental models of CookieBlock’s functionality and resulting challenges in making the connection between website breakage and cookie misclassification. Implications for CookieBlock and related applications include interface design recommendations supporting accurate mental models and the proposal of improved heuristics to better guide users and warn them about potential identified website breakage. Lorin Schöni, Karel Kubicek 0001, Verena Zimmermann |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Don't Accept All and Continue: Exploring Nudges for More Deliberate Interaction with Tracking Consent NoticesabstractLegal frameworks rely on users to make an informed decision about data collection, e.g., by accepting or declining the use of tracking technologies. In practice, however, users hardly interact with tracking consent notices on a deliberate website per website level, but usually accept or decline optional tracking technologies altogether in a habituated behavior. We explored the potential of three different nudge types (color highlighting, social cue, timer) and default settings to interrupt this auto-response in an experimental between-subject design with 167 participants. We did not find statistically significant differences regarding the buttons clicked. Our results showed that opt-in default settings significantly decrease tracking technology use acceptance rates. These results are a first step towards understanding the effects of different nudging concepts on users’ interaction with tracking consent notices. Nina Gerber, Alina Stöver, Justin Peschke, Verena Zimmermann |
ACM Trans. Comput. Hum. Interact. | 4 |
| 2023 | Hybrid password meters for more secure passwords - a comprehensive study of password meters including nudges and password informationabstractSupporting users with secure password creation is a well-explored yet unresolved research topic. A promising intervention is the password meter, i.e. providing feedback on the user's password strength as and when it is created. However, findings related to the password meter's effectiveness are varied. An extensive literature review revealed that, besides password feedback, effective password meters often include: (a) feedback nudges to encourage stronger passwords choices and (b) additional guidance. A between-subjects study was carried out with 645 participants to test nine variations of password meters with different types of feedback nudges exploiting various heuristics and norms. This study explored differences in resulting passwords: (1) actual strength, (2) memorability, and (3) user perceptions. The study revealed that password feedback, in combination with a feedback nudge and additional guidance, labelled a hybrid password meter, was generally more efficacious than either intervention on its own, on all three metrics. Yet, the type of feedback nudge targeting either the person, the password creation task, or the social context, did not seem to matter much. The meters were nearly equally efficacious. Future work should explore the long-term effects of hybrid password meters in real-life settings to confirm the external validity of these findings. Verena Zimmermann, Karola Marky, Karen Renaud |
Behav. Inf. Technol. | 1 |
| 2023 | Learning from safety science: A way forward for studying cybersecurity incidents in organizationsabstractIn the aftermath of cybersecurity incidents within organizations, explanations of their causes often revolve around isolated technical or human events such as an Advanced Persistent Threat or a “bad click by an employee.” These explanations serve to identify the responsible parties and inform efforts to improve security measures. However, safety science researchers have long been aware that explaining incidents in socio-technical systems and determining the role of humans and technology in incidents is not an objective procedure but rather an act of social constructivism: what you look for is what you find, and what you find is what you fix. For example, the search for a technical “root cause” of an incident might likely result in a technical fix, while from a sociological perspective, cultural issues might be blamed for the same incident and subsequently lead to the improvement of the security culture. Starting from the insights of safety science, this paper aims to extract lessons on what general explanations for cybersecurity incidents can be identified and what methods can be used to study causes of cybersecurity incidents in organizations. We provide a framework that allows researchers and practitioners to proactively select models and methods for the investigation of cybersecurity incidents. Nico Ebert, Thierry Schaltegger, Benjamin Ambuehl, Lorin Schöni, Verena Zimmermann, Melanie Knieps |
Comput. Secur. | 5 |
| 2021 | The Nudge Puzzle: Matching Nudge Interventions to Cybersecurity DecisionsabstractNudging is a promising approach, in terms of influencing people to make advisable choices in a range of domains, including cybersecurity. However, the processes underlying the concept and the nudge’s effectiveness in different contexts, and in the long term, are still poorly understood. Our research thus first reviewed the nudge concept and differentiated it from other interventions before applying it to the cybersecurity area. We then carried out an empirical study to assess the effectiveness of three different nudge-related interventions on four types of cybersecurity-specific decisions. Our study demonstrated that the combination of a simple nudge and information provision, termed a “hybrid nudge,” was at least as, and in some decision contexts even more effective in encouraging secure choices as the simple nudge on its own. This indicates that the inclusion of information when deploying a nudge, thereby increasing the intervention’s transparency, does not necessarily diminish its effectiveness. A follow-up study explored the educational and long-term impact of our tested nudge interventions to encourage secure choices. The results indicate that the impact of the initial nudges, of all kinds, did not endure. We conclude by discussing our findings and their implications for research and practice. Verena Zimmermann, Karen Renaud |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2020 | 3D-Auth: Two-Factor Authentication with Personalized 3D-Printed ItemsabstractTwo-factor authentication is a widely recommended security mechanism and already offered for different services. However, known methods and physical realizations exhibit considerable usability and customization issues. In this paper, we propose 3D-Auth, a new concept of two-factor authentication. 3D-Auth is based on customizable 3D-printed items that combine two authentication factors in one object. The object bottom contains a uniform grid of conductive dots that are connected to a unique embedded structure inside the item. Based on the interaction with the item, different dots turn into touch-points and form an authentication pattern. This pattern can be recognized by a capacitive touchscreen. Based on an expert design study, we present an interaction space with six categories of possible authentication interactions. In a user study, we demonstrate the feasibility of 3D-Auth items and show that the items are easy to use and the interactions are easy to remember. Karola Marky, Martin Schmitz 0001, Verena Zimmermann, Martin Herbers, Kai Kunze, Max Mühlhäuser |
CHI | 3 |
| 2020 | Improving the Usability and UX of the Swiss Internet Voting InterfaceabstractUp to 20% of residential votes and up to 70% of absentee votes in Switzerland are cast online. The Swiss system aims to provide individual verifiability by different verification codes. The voters have to carry out verification on their own, making the usability and UX of the interface of great importance. To improve the usability, we first performed an evaluation with 12 human-computer interaction experts to uncover usability weaknesses of the Swiss Internet voting interface. Based on the experts' findings, related work, and an exploratory user study with 36 participants, we propose a redesign that we evaluated in a user study with 49 participants. Our study confirmed that the redesign indeed improves the detection of incorrect votes by 33% and increases the trust and understanding of the voters. Our studies furthermore contribute important lessons for designing verifiable e-voting systems in general. Karola Marky, Verena Zimmermann, Markus Funk, Jörg Daubert, Kira Bleck, Max Mühlhäuser |
CHI | 2 |
| 2020 | The password is dead, long live the password - A laboratory study on user perceptions of authentication schemes
Verena Zimmermann, Nina Gerber |
Int. J. Hum. Comput. Stud. | 1 |
| 2019 | Moving from a 'human-as-problem" to a 'human-as-solution" cybersecurity mindset
Verena Zimmermann, Karen Renaud |
Int. J. Hum. Comput. Stud. | 1 |
| 2019 | Keep on rating - on the systematic rating and comparison of authentication schemesabstractPurpose Six years ago, Bonneau et al. (2012) proposed a framework to compare authentication schemes to the ubiquitous text password. Even though their work did not reveal an alternative outperforming the text password on every criterion, the framework can support decision makers in finding suitable solutions for specific authentication contexts. The purpose of this paper is to extend and update the database, thereby discussing benefits, limitations and suggestions for continuing the development of the framework. Design/methodology/approach This paper revisits the rating process and describes the application of an extended version of the original framework to an additional 40 authentication schemes identified in a literature review. All schemes were rated in terms of 25 objective features assigned to the three main criteria: usability, deployability and security. Findings The rating process and results are presented along with a discussion of the benefits and pitfalls of the rating process. Research limitations/implications While the extended framework, in general, proves suitable for rating and comparing authentication schemes, ambiguities in the rating could be solved by providing clearer definitions and cut-off values. Further, the extension of the framework with subjective user perceptions that sometimes differ from objective ratings could be beneficial. Originality/value The results of the rating are made publicly available in an authentication choice support system named ACCESS to support decision makers and researchers and to foster the further extension of the knowledge base and future development of the extended rating framework. Verena Zimmermann, Nina Gerber, Peter Mayer 0001, Marius Kleboth, Alexandra von Preuschen, Konstantin Schmidt |
Inf. Comput. Secur. | 1 |
| 2018 | Finally Johnny Can Encrypt: But Does This Make Him Feel More Secure?abstractEnd-to-end (E2E) encryption is an effective measure against privacy infringement. In 2016, it was introduced by WhatsApp for all users (of the latest app version) quasi overnight. However, it is unclear how non-expert users perceived this change, whether they trust WhatsApp as a provider of E2E encryption, and how their communication behavior changed. We conducted semi-structured interviews with twenty WhatsApp users to answer these questions. We found that about half of the participants perceived that even with E2E encryption, their messages could still be eavesdropped, for example by hackers and other criminals, governmental institutions, or WhatsApp's employees and cooperation partners. Many participants correctly identified sender and recipient as weakest points after the introduction of E2E encryption, but misconceptions were still present. For instance, users thought that messages were transmitted directly between two devices without being forwarded or stored on a server, or interpreted 'end-to-end' as a temporally end of communication. The majority of users stated to mistrust WhatsApp and its E2E encryption and presumed image-related reasons for the cost-free implementation. While most participants did not change their communication behavior, they reported to use protection strategies such as sending sensitive content via alternative channels even after the introduction of E2E encryption. Nina Gerber, Verena Zimmermann, Birgit Henhapl, Sinem Emeröz, Melanie Volkamer |
ARES | 2 |
| 2018 | Ethical guidelines for nudging in information security & privacy
Karen Renaud, Verena Zimmermann |
Int. J. Hum. Comput. Stud. | 2 |