EDBT 2026 Demo / reviewers in the wild / expert
Weijia He
dblp:198/7178
· DBLP profile ↗
11ranked-venue papers
5as first author
8since 2021 · last 2026
0009-0002-1189-7063ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DataMorph: Designing a Metaphorical Data Factory Provotype to Physicalise Invisible DataabstractData has emerged as one of the most powerful resources of the 21st century, yet the processes through which it is collected, transformed, and exploited remain opaque to the general public. While individuals continuously generate data through everyday interactions, they often lack understanding of how data is collected, by whom, and for what purposes. In this poster paper, we present the development process of DataMorph, an artistic provotype inspired by the metaphor of a data factory. It employs data physicalisation to render invisible processes and abstract data flows visible through a physical shape-changing form. Through this design provocation, we aim to foster critical reflection, public dialogue, and engagement with data practices, agency, and power. Lastly, we discuss various contexts in which DataMorph could be deployed. Xixiang Nie, Eike Schneiders, Weijia He |
Creativity & Cognition | 3 |
| 2025 | How Humans Communicate Programming Tasks in Natural Language and Implications For End-User Programming with LLMsabstractLarge language models (LLMs) like GPT-4 can convert natural-language descriptions of a task into computer code, making them a promising interface for end-user programming. We undertake a systematic analysis of how people with and without programming experience describe information-processing tasks (IPTs) in natural language, focusing on the characteristics of successful communication. Across two online between-subjects studies, we paired crowdworkers either with one another or with an LLM, asking senders (always humans) to communicate IPTs in natural language to their receiver (either a human or LLM). Both senders and receivers tried to answer test cases, the latter based on their sender’s description. While participants with programming experience tended to communicate IPTs more successfully than non-programmers, this advantage was not overwhelming. Furthermore, a user interface that solicited example test cases from senders often, but not always, improved IPT communication. Allowing receivers to request clarification, though, was less successful at improving communication. Madison Pickering, Helena Williams, Alison Gan, Weijia He, Hyojae Park, Francisco Piedrahita Velez, Michael L. Littman, Blase Ur |
CHI | 4 |
| 2025 | Help Me Help You: Privacy Considerations for Third Party IoT Device RepairabstractSmart home devices are becoming increasingly complex and data-rich. The inevitable repair of these devices will be both difficult and privacy-sensitive. A "HandyTech"—a technician for home Internet of Things (IoT) system repair—has the potential to lower barriers to repair, but privacy questions remain: Are people willing to use a HandyTech to fix a broken home IoT device despite the inherent privacy risk (i.e., allowing a third party to access potentially sensitive IoT data)? We explore this question through a vignette-based, multi-factorial survey with a nationally representative sample of adults in the United States. We further ask whether types of devices (i.e., smart speakers, refrigerators, and CPAP machines) and factors adjacent to privacy and associated with the HandyTech's work (i.e., scope of access, state-based licensing requirements, and transparency provisions) affect decisions to use or not use a HandyTech. We find that some demographic groups are more willing than others to use a HandyTech (e.g., younger age groups, those with children in the home). Current ownership of more types of smart devices increases willingness to use a HandyTech, while greater concerns over general IoT privacy decreases willingness to use a HandyTech. Device-specific perceptions also mattered, such that perceived urgency to fix is strongly associated with willingness to use a HandyTech, but concern over that device's privacy is not. In addition, reduced scope of access and increased transparency by the HandyTech statistically increased willingness to use a HandyTech. In closing, we recommend takeaways that developers and policymakers can engage with to decrease privacy concerns and increase the adoption of third-party IoT repair. Nathan Reitinger, Weijia He, Chelsea Bruno, Susan Landau 0001, Carl A. Gunter, Mounib Khanafer, Ravindra Mangar, Denise L. Anthony |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Can Allowlists Capture the Variability of Home IoT Device Network Behavior?abstractHome Internet of Things (IoT) devices can be difficult for users to secure. Prior work has suggested measuring these devices' network behaviors and using these characterizations to create allowlists of permitted endpoints. Unfortunately, previous studies have typically been conducted in controlled lab settings, with one or two devices per product. In this paper, we examine whether popular home IoT products' network behaviors generalize via both in-lab experiments of 24 devices and a large, crowdsourced dataset of IoT devices in the wild. We find that observing traffic from one device in one lab is often insufficient to fully characterize an IoT product's network behaviors. For example, specifying which endpoints a device may contact based on initial measurements in our lab led 25% of products to stop functioning later, and even more when using a VPN. We then used the crowdsourced dataset to better understand this traffic's heterogeneity and pinpoint how to create more generalizable allowlists. We identified causes of failure, such as regionalization, CDN usage, third-party integrations, and API changes. Finally, we used the crowdsourced data in numerous configurations to specify which endpoints each product in our lab could contact. We found that domain-level allowlists enabled the majority of devices to function in our lab using data collected years in the past. For the remaining devices, we characterize how to mitigate the failures observed and pave the way to creating more generalizable allowlists. Weijia He, Kevin Bryson 0002, Ricardo Calderon, Nick Feamster, Danny Yuxing Huang, Blase Ur |
EuroS&P | 1 |
| 2024 | Contextualizing Interpersonal Data Sharing in Smart HomesabstractA key feature of smart home devices is monitoring the environment and recording data. These devices provide security via motion-detection video alerts, cost-savings via thermostat usage history, and peace of mind via functions like auto-locking doors or water leak detectors. At the same time, the sharing of this information in interpersonal relationships---though necessary---is currently accomplished on an all-or-nothing basis. This can easily lead to oversharing in a multi-user environment. Although prior work has studied people's perceptions of information sharing with vendors or ISPs, the sharing of household data among users who interact personally is less well understood. Interpersonal situations make data sharing much more context-based and, thus, more complicated. In this paper, we use themes from the theory of contextual integrity in an online survey (n=1,992) to study how people perceive data sharing with others in smart homes and inform future designs and research. Our results show that data recipients in a smart home can be reduced to three major groups, and data types matter more than device types. We also found that the types of access control desired by users can vary from scenario to scenario. Depending on whom they are sharing data with and about what data, participants expressed varying levels of comfort when presented with different types of access control (e.g., explicit approval versus time-limited access). Taken together, this provides strong evidence that a more dynamic access control system is needed, and we can design it in a more usable way. Weijia He, Nathan Reitinger, Atheer Almogbil, Yi-Shyuan Chiang, Timothy J. Pierson, David Kotz |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Massive parallelization of multilevel fast multipole algorithm for 3-D electromagnetic scattering problems on SW26010 many-core cluster
Xin-Duo Liu, Weijia He, Ming-Lin Yang, Xin-Qing Sheng |
J. Supercomput. | 2 |
| 2021 | SoK: Context Sensing for Access Control in the Adversarial Home IoTabstractIn smart homes, access-control policies increasingly depend on contexts, such as who is taking an action, whether there is an emergency, or whether an adult is nearby. The vast literature on context sensing could potentially be leveraged to support contextual access control, yet this literature mostly ignores attacks, adversaries, and privacy. In this paper, we reevaluate the literature on home context sensing through a security and privacy mindset. We first describe a novel threat model in smart homes focusing on the capabilities of non-technical adversaries. Replay, imitation, and shoulder-surfing attacks are much more likely in this model. We summarize contexts relevant to access control in homes, mapping them to existing sensors. We then systematize the sensing literature to construct a decision framework for home context sensing that considers security, privacy, and usability. Applying our framework, we find that current sensors do not fully mitigate likely threats in homes. Some sensors are susceptible to simple threats like physical denial-of-service attacks, making it easy to bypass policies relying on the absence of a characteristic. Many sensors collect more data than needed and are not effective for all groups of users or under all situations. Weijia He, Valerie Zhao, Olivia Morkved, Sabeeka Siddiqui, Earlence Fernandes, Josiah D. Hester, Blase Ur |
EuroS&P | 1 |
| 2021 | Efficient parallelization of multilevel fast multipole algorithm for electromagnetic simulation on many-core SW26010 processor
Weijia He, Ming-Lin Yang, Xin-Qing Sheng |
J. Supercomput. | 1 |
| 2019 | How Users Interpret Bugs in Trigger-Action ProgrammingabstractTrigger-action programming (TAP) is a programming model enabling users to connect services and devices by writing if-then rules. As such systems are deployed in increasingly complex scenarios, users must be able to identify programming bugs and reason about how to fix them. We first systematize the temporal paradigms through which TAP systems could express rules. We then identify ten classes of TAP programming bugs related to control flow, timing, and inaccurate user expectations. We report on a 153-participant online study where participants were assigned to a temporal paradigm and shown a series of pre-written TAP rules. Half of the rules exhibited bugs from our ten bug classes. For most of the bug classes, we found that the presence of a bug made it harder for participants to correctly predict the behavior of the rule. Our findings suggest directions for better supporting end-user programmers. Will Brackenbury, Abhimanyu Deora, Jillian Ritchey, Jason Vallee, Weijia He, Michael L. Littman, Blase Ur |
CHI | 5 |
| 2019 | AutoTap: synthesizing and repairing trigger-action programs using LTL propertiesabstractEnd-user programming, particularly trigger-action programming (TAP), is a popular method of letting users express their intent for how smart devices and cloud services interact. Unfortunately, sometimes it can be challenging for users to correctly express their desires through TAP. This paper presents AutoTap, a system that lets novice users easily specify desired properties for devices and services. AutoTap translates these properties to linear temporal logic (LTL) and both automatically synthesizes property-satisfying TAP rules from scratch and repairs existing TAP rules. We designed AutoTap based on a user study about properties users wish to express. Through a second user study, we show that novice users made significantly fewer mistakes when expressing desired behaviors using AutoTap than using TAP rules. Our experiments show that AutoTap is a simple and effective option for expressive end-user programming. Lefan Zhang, Weijia He, Jesse J. Martinez, Noah Brackenbury, Shan Lu 0001, Blase Ur |
ICSE | 2 |
| 2018 | Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek, Markus Dürmuth, Earlence Fernandes, Blase Ur |
USENIX Security Symposium | 1 |