EDBT 2026 Demo / reviewers in the wild / expert
Carrie Gates
dblp:21/1838
· DBLP profile ↗
23ranked-venue papers
11as first author
2since 2021 · last 2025
0009-0000-5629-4755ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 7 first-author · 2 since 2021Systems, architecture and hardware · 3 · 2 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 first-authorComputer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A First Look at Governments' Enterprise Security Guidance
Kimberly Ruth, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li, Carrie Gates, Grant Ho, Zakir Durumeric |
USENIX Security Symposium | 5 |
| 2024 | "Better Be Computer or I'm Dumb": A Large-Scale Evaluation of Humans as Audio Deepfake DetectorsabstractAudio deepfakes represent a rising threat to trust in our daily communications. In response to this, the research community has developed a wide array of detection techniques aimed at preventing such attacks from deceiving users. Unfortunately, the creation of these defenses has generally overlooked the most important element of the system - the user themselves. As such, it is not clear whether current mechanisms augment, hinder, or simply contradict human classification of deepfakes. In this paper, we perform the first large-scale user study on deepfake detection. We recruit over 1,200 users and present them with samples from the three most widely-cited deepfake datasets. We then quantitatively compare performance and qualitatively conduct thematic analysis to motivate and understand the reasoning behind user decisions and differences from machine classifications. Our results show that users correctly classify human audio at significantly higher rates than machine learning models, and rely on linguistic features and intuition when performing classification. However, users are also regularly misled by pre-conceptions about the capabilities of generated audio (e.g., that accents and background sounds are indicative of humans). Finally, machine learning models suffer from significantly higher false positive rates, and experience false negatives that humans correctly classify when issues of quality or robotic characteristics are reported. By analyzing user behavior across multiple deepfake datasets, our study demonstrates the need to more tightly compare user and machine learning performance, and to target the latter towards areas where humans are less likely to successfully identify threats. Kevin Warren, Tyler Tucker, Anna Crowder, Daniel Olszewski, Allison Lu, Caroline Fedele, Magdalena Pasternak, Seth Layton, Kevin R. B. Butler, Carrie Gates, Patrick Traynor |
CCS | 10 |
| 2018 | Augmenting Machine Learning with ArgumentationabstractThe information security community is haunted by the failure of an appropriate break-the-glass access control at the United States Center for Disease Control that led to an estimated additional 1.2 million deaths in North America in 2036. In this paper we review what caused the security failures in this system and argue that, by combining human intelligence with multiple technological approaches to create a system that emphasizes human approaches to guide analysis, the failures that occurred will not recur. We also leverage people and technologies to identify and fill gaps in the training data to minimize the threat of unexpected events. While we use this scenario as our running example, we note that our approach is generalizable to a broader problem space where machine learning approaches have been deployed to make decisions. Matt Bishop, Carrie Gates, Karl N. Levitt |
NSPW | 2 |
| 2014 | Data Is the New CurrencyabstractData is growing. We are all aware of this in the IT industry, it is a common mantra. The elephant in the room is the ownership of that data and the use of that data. As with many new technologies, its legal and personal implications are not well understood until the technology has matured. Data ownership has by default resided with organisations that hold the data; utility companies, websites, retailers and data aggregators and brokers. If data could be owned by the people it identifies, the data handlers would have to pay to use that data for sales and marketing purposes. We are not suggesting payment would be the mostly illusory free services and hidden discounts that are the current answer but real money or an asset that can be bartered or purchased. If even the poorest people can gain an income this would revolutionise personal finance for those who register on the web either for purchases or to make their name available for use. We propose such a revolution in data ownership and urge all data generators to establish their rights to a business asset that they frequently gift to already wealthy organisations. Don't be a mere generator of data, become a personal data aggregator, collecting and controlling all your data. Time to man the barricades against entities who are using your data for their profit and pleasure, not yours. Carrie Gates, Peter Matthews |
NSPW | 1 |
| 2013 | Reflecting on visualization for cyber securityabstractIn this short position paper, we explore three questions regarding cyber security visualization: (1) why cyber security visualization has not been more effective in the past, (2) how visualization can be utilized in cyber security, and (3) how to evaluate cyber security visualization. Carrie Gates, Sophie Engle |
ISI | 1 |
| 2013 | Information behaving badlyabstractTraditionally, insider threat detection has focused on observing human actors -- or, more precisely, computer accounts and processes acting on behalf of those actors -- to model their "normal" behavior, then determine if they have performed some anomalous action and, further, if that action is malicious. In this paper, we shift the paradigm from observing human behavior to observing information behavior by modeling how documents flow through an organization. We hypothesize that similar types of documents will exhibit similar workflows, and that a document deviating from its expected workflow indicates potential data leakage. Julie Boxwell Ard, Matt Bishop, Carrie Gates, Michael Xin Sun |
NSPW | 3 |
| 2013 | Forgive and forget: return to obscurityabstractTraditionally, if someone did some act that required forgiveness, there were social norms in place for such forgiveness to happen. Over time, the act is also typically forgotten. And, should the person not be forgiven and the social pressure become too great, he had the option of moving to a new location for a fresh start. Yet with the Internet, these options are no longer available. Worse, activities which traditionally did not even require forgiveness are now impacting lives in unexpected ways, and are never forgotten. There are, however, technical approaches that could be applied to the problem, such as (1) controlling dissemination through new access control models or cryptographic approaches, (2) flooding the web with contrary information, (3) leading users to believe the information applies to someone else, (4) changing the semantics of what was written, and (5) finding a way to take advantage of the inconvenient information. In this paper we discuss the social act of forgiveness, and go into detail on the possible technical approaches to "forgetting" without deleting. Matt Bishop, Emily Rine Butler, Kevin R. B. Butler, Carrie Gates, Steven Greenspan |
NSPW | 4 |
| 2011 | Do you know dis?: a user study of a knowledge discovery tool for organizationsabstractOrganisations today have no reliable way of ensuring that all employees are aware of information that may be relevant to their work. In this paper we report on a 2-year project in which we have iteratively designed, developed and tested a knowledge discovery system (KnowDis) for organizations. Early stages of our study revealed that, employees do not know what is available on the corporate intranet, or files and messages they have stored. KnowDis proactively fetches relevant information and displays it in an unobtrusive form; this increases employee awareness without disrupting their tasks. We discuss and characterize knowledge workers' email usage behavior. Our main study with 28 users of KnowDis-enhanced email showed it can improve the user experience and performance on information retrieval tasks for knowledge workers. Sven Laqua, M. Angela Sasse, Steven Greenspan, Carrie Gates |
CHI | 4 |
| 2010 | Watching the watchers: "voluntary monitoring" of infosec employeesabstractPurpose While many papers discuss the privacy implications of workplace monitoring, the purpose of this paper is to describe the positive aspects to voluntary monitoring in the workplace. Design/methodology/approach These aspects were identified through in‐depth qualitative interviews with employees of various organizations chosen for the invasiveness of their monitoring procedures. Specifically, the authors worked with individuals who had high‐level government clearances, working in information security (infosec), who were subjected to comprehensive monitoring both before being employed and during the term of their employment. Findings Through these interviews, the paper identifies four positive results of employee monitoring, four procedural issues that affected employee perception of the monitoring, and two secondary aspects that are specific benefits of holding a clearance, as opposed to benefits from the monitoring itself. Research limitations/implications The research reported here is gathered from a specific sample: eight participants working at American infosec organizations. Thus, the results may not be widely generalizable to work environments, particularly for employees working in other countries where different monitoring requirements exist. Originality/value The contribution of this paper is the identification of positive aspects to voluntary monitoring as a condition of employment, the implication of which is that workplace monitoring can be deployed with positive results. The paper also identifies procedural aspects that organizations can address in order to improve employees' experience of being monitored. While preliminary, these results can be used to guide future research directions. Additionally, organizations that require employee monitoring can use these results to strengthen benefits to employees in compensation for their voluntary cooperation. Tara Whalen, Carrie Gates |
Inf. Manag. Comput. Secur. | 2 |
| 2009 | Coordinated Scan Detection
Carrie Gates |
NDSS | 1 |
| 2009 | The sisterhood of the traveling packetsabstractFrom a cyber-security perspective, attribution is considered to be the ability to determine the originating location for an attack. However, should such an attribution system be developed and deployed, it would provide attribution for all traffic, not just attack traffic. This has several implications for both the senders and receivers of traffic, as well as the intervening organizations, Internet service providers and nation-states. In this paper we examine the requirements for an attribution system, identifying all of the actors, their potential interests, and the resulting policies they might therefore have. We provide a general framework that represents the attribution problem, and outline the technical and policy requirements for a solution. We discuss the inevitable policy conflicts due to the social, legal and cultural issues that would surround such a system. Categories and Subject Descriptors K.4.1 [Computers and Society]: Public Policy Issues – abuse and crime involving computers, ethics, privacy, regulation, Matt Bishop, Carrie Gates, Jeffrey Hunker |
NSPW | 2 |
| 2009 | Over flow: An overview visualization for network analysisabstractMany network visualizations make the assumption that an administrator has previously determined the subset of data that should be visualized. Yet the problem remains that if the visualization provides no insight into the network events that warrant further consideration, then the administrator must go back to the data to determine what should be visualized next. This is a critical issue given the amount of network data under consideration, only a small portion of which can be examined at any one time. In this paper we present a visualization that provides context for network visualizations by providing a high-level view of network events. Our visualization not only provides a starting point for network visualization, but also reduces the cognitive burden of the analyst by providing a visual paradigm for both the filtering of network data and the selection of network data to drill into and visualize with alternative representations. We demonstrate, through the use of a case study, that our visualization can provide motivation for further investigation into anomalous network activity. Joel Glanfield, Stephen Brooks, Teryl Taylor, Diana Paterson, Carrie Gates, John McHugh |
VizSEC | 6 |
| 2008 | The Contact Surface: A Technique for Exploring Internet Scale Emergent Behaviors
Carrie Gates, John McHugh |
DIMVA | 1 |
| 2008 | We have met the enemy and he is usabstractThe insider threat has long been considered one of the most serious threats in computer security, and one of the most difficult to combat. But the problem has never been defined precisely, and that lack of precise definition inhibits solutions. This paper presents a precise definition of insider threat, and shows how the definition enables an analysis of the set of problems traditionally lumped into \the insider threat". It introduces a hierarchy of policy abstractions, and argues that the discrepancies between the different layers of abstraction expose the potential for insider threat. It also presents a methodology for analyzing the threat based upon our definitions. In the process, we introduce Attribute-Based Group Access Control, a generalization of the Role-Based Access Control model that allows any attributes to define a group. We apply this to the insider threat by defining groups based on access capabilities, and using that to identify users with a high level of threat with respect to high-risk resources. Matt Bishop, Sophie Engle, Sean Peisert, Sean Whalen, Carrie Gates |
NSPW | 5 |
| 2006 | DJs' perspectives on interaction and awareness in nightclubsabstractSeveral researchers have recently proposed technology for crowd-and-DJ interactions in nightclub environments. However, these attempts have not always met with success. In order to design better technologies and systems in this area, it is important to start with an understanding of how nightclub interaction currently happens. To build this understanding, we carried out an interview study focusing on DJ-audience interactions. We interviewed eleven DJs from several different cities, and asked them to discuss the ways that they interact with the audience, and the ways that they maintain and use awareness of the audience. We found that DJs gather a wide variety of information about their audiences, and that this information is important to them as they plan and shape the evening's musical experience. DJs are adept at gathering visual information about the audience, despite poor lighting conditions and a heavy workload of selecting and mixing music. Despite the difficulties, DJs took a dim view of technology designed to let crowds exert more control over the music. This study is one of the first to look closely at the interactive relationship between the DJ and the nightclub audience through the lens of HCI, and our findings provide a number of guidelines for the design of new DJ-focused nightclub technologies. Carrie Gates, Sriram Subramanian, Carl Gutwin |
Conference on Designing Interactive Systems | 1 |
| 2006 | Scan Detection on Very Large Networks Using Logistic Regression ModelingabstractScanning activity is a common activity on the Internet today, representing malicious activity such as information gathering by a motivated adversary or automated tools searching for vulnerable hosts (e.g., worms). Many scan detection techniques have been developed; however, their focus has been on smaller networks where packet-level information is available, or where internal characteristics of the network are known. For large networks, such as those of ISPs, large corporations or government organizations, this information might not be available. This paper presents a model of scans that can be used given only unidirectional flow data. The model uses a Bayesian logistic regression, which was developed using a combination of expert opinion and manually-classified training data. It is shown to have a detection rate of 95.5% with a false positive rate of 0.4% overall when tested against a set of 300 TCP events. Carrie Gates, Joshua J. McNutt, Joseph B. Kadane, Marc I. Kellner |
ISCC | 1 |
| 2006 | NAF: The NetSA Aggregated Flow Tool Suite
Brian Trammell, Carrie Gates |
LISA | 2 |
| 2006 | Challenging the anomaly detection paradigm: a provocative discussion
Carrie Gates, Carol Taylor |
NSPW | 1 |
| 2004 | More Netflow Tools for Performance and Security
Carrie Gates, Michael P. Collins, Michael Duggan, Andrew Kompanek |
LISA | 1 |
| 2004 | Profiling the defendersabstractPsychological research in the security arena has focused on understanding the attacker, with little work done on understanding the defender. This paper presents a pilot study undertaken to determine if there are trends within the defender community, or if we represent a more diverse group with varying approaches to the problem. We surveyed 76 security professionals, using the Myers-Briggs Type Indicator as a tool to indicate similarities and differences in problem approaches. We find that the security community consists disproportionately of INTJs, and is especially disproportionate in the intuitive end of the intuitive-sensing dichotomy. This is not only in contrast to the general population of the United States, but also to engineers, software engineers and computer scientists (who are predominately ISTJ). We conclude that homogeneity amongst the defenders may not be a good strategy, and that further study be undertaken to determine the extent and effect of this homogeneity. Carrie Gates, Tara Whalen |
NSPW | 1 |
| 2003 | The Yearly Review, or How to Evaluate Your Sys Admin
Carrie Gates, Jason Rouse |
LISA | 1 |
| 2003 | Owner-controlled informationabstractInformation about individuals is currently maintained in many thousands of databases, with much of that information, such as name and address, replicated across multiple databases. However, this proliferation of personal information raises issues of privacy for the individual, as well as maintenance issues in terms of the accuracy of the information. Ideally, each individual would own, maintain and control his personal information, allowing access to those who needed at the time it was needed. Organizations would contact the individual directly to obtain information, therefore being assured of using current and correct information.While research has been performed on users owning and controlling access to their personal information in an electronic commerce environment, we argue that this concept should be extended to all user information including, for example, medical and financial information. The end goal is not for users to simply maintain copies of this information, but to be the source of this information.This paper presents the concept of users owning their personal information and introduces some of the issues involved in users being able to control access to this information. The security requirements, including authentication, access control and audit, as well as user interfaces and trust, for this new paradigm are given particular emphasis. Carrie Gates, Jacob Slonim |
NSPW | 1 |
| 2003 | Locality: a new paradigm for thinking about normal behavior and outsider threatabstractLocality as a unifying concept for understanding the normal behavior of benign users of computer systems is suggested as a unifying paradigm that will support the detection of malicious anomalous behaviors. The paper notes that locality appears in many dimensions and applies to such diverse mechanisms as the working set of IP addresses contacted during a web browsing session, the set of email addresses with which one customarily corresponds, the way in which pages are fetched from a web site. In every case intrusive behaviors that violate locality are known to exist and in some cases, the violation is necessary for the intrusive behavior to achieve its goal. If this observation holds up under further investigation, we will have a powerful way of thinking about security and intrusive activity. John McHugh, Carrie Gates |
NSPW | 2 |