EDBT 2026 Demo / reviewers in the wild / expert
Verena Distler
dblp:217/9240
· DBLP profile ↗
17ranked-venue papers
5as first author
14since 2021 · last 2026
0000-0002-4461-0551ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 10 · 4 first-author · 8 since 2021Security and privacy · 7 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Too Many Zombies: Exploring Challenges and Motivations for (Not) Deleting Unused Online AccountsabstractUnused online accounts (“zombie accounts”) pose avoidable privacy and security risks by retaining personal data that may be exposed in breaches. Yet, little is known about when and how to effectively prompt users to delete them. This work investigates the challenges users encounter when attempting to delete zombie accounts. We conducted two online studies with U.S. participants via Prolific: the accounts study (N = 120) to identify common zombie account categories, and the challenges study (N = 100) to examine users’ motivations, perceived abilities, and preferred moments for deletion. Participants reported high self-efficacy but underestimated the number of zombie accounts they had. We identify promising opportune moments — such as when updating account information or setting up a new device — and evaluate potential triggers, including breach notifications and data sensitivity. This work contributes an empirical characterization of end-users’ diverse challenges related to zombie accounts and design recommendations for future deletion-support tools. Franziska Bumiller, Sarah Delgado Rodriguez, Lukas Mecke, Verena Distler, Florian Alt |
CHI | 4 |
| 2026 | "I didn't know I would be this excited not to be scammed." Exploring Emotional and Behavioral Responses During Phishing Attacks
Raphael Weidhaas, Alexandra von Preuschen, Verena Distler |
SOUPS | 3 |
| 2026 | Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experimentabstractBackground : Humans remain a critical vulnerability in the cybersecurity chain. While research has explored various behavioral factors influencing phishing susceptibility, the role of national culture and individual cultural orientations remains under-researched, representing a significant gap in the literature. Aims : This study investigates the impact of individual cultural orientations on phishing victimization, while taking into account other relevant factors, such as self-control, risk-taking, technical training, email management practices, demographics (age and gender), and country-level economic and ICT development. Methods : Data were collected via an online survey of university students (N = 2,143) across 12 countries in Asia, Africa, North America, and Europe. Outcomes measures included phishing victimization, phishing recognition, and legitimate email recognition; the last two measures were assessed via scenarios. Data were analyzed using Signal Detection Theory and mixed modelling. Results : Phishing victimization was significantly associated with low self-control, high risk-taking, high exposure, and poorer recognition of legitimate emails. Conversely, cultural orientations, religiosity, and country of origin had minimal effects. While phishing recognition was unrelated to victimization, the ability to recognize legitimate emails reduced victimization risk. For culturally diverse organizations, these findings suggest that cultural factors may be less critical to phishing victimization than has been previously assumed. Training users and improved self-control techniques may help protect against phishing victimization. Marianne Junger, Pawel Olber, Rafal Plocki, J. W. (Hans) Luyten, Luka Koning, Caitlyn N. Muniz, Jan-Willem Bullee, Victoria Wang, Reinhardt A. Botha, C. Jordan Howell, Verena Distler, Xiaowei Chen 0013, Cong Hiep Pham 0001, Mohammed Aljohani, Newman U. Richards, Fabian Muhly, Abhishta, Steven Furnell |
Comput. Secur. | 11 |
| 2025 | Empowering Parents to Support Children's Online Security and Privacy: Findings from a Randomized Controlled TrialabstractIn the ubiquitous computing society, parenting ''digital natives'' presents unprecedented challenges. Parents often rely on online resources to support and guide their children in security and privacy (S&P) related topics. However, the abundance of online resources makes it challenging for parents to find high-quality and relevant resources that align with their S&P needs. Further, the longitudinal development of parental competence and coping strategies in S&P topics remains largely unexplored. Xiaowei Chen 0013, Verena Distler, Chloe Gordon, Yaxing Yao, Ziwen Teuber |
CCS | 2 |
| 2025 | Beyond Deterrence: A Systematic Review of the Role of Autonomous Motivation in Organizational Security Behavior StudiesabstractWhat drives employees to ensure security when handling information assets in organizations? There is growing interest from the security behavior community in how autonomous motivators shape employees’ security-related behaviors. To reconcile the scattered viewpoints on autonomous motivation and synthesize findings from studies utilizing various theoretical frameworks, we systematically reviewed relevant publications. We present a preregistered literature review that investigated (a) what forms of autonomous motivation have been examined in organizational security contexts, (b) which behaviors/behavioral intentions are related to autonomous motivators, and (c) how autonomous motivation affects employees’ security behaviors. Based on an initial set of 432 papers, filtered down to 45 studies, we identified 17 unique autonomous motivators and three types of related security behaviors. This review not only develops a refined taxonomy of autonomous motivation related to security behaviors but also charts a path forward for future research on autonomous motivation in human-centered security. Xiaowei Chen 0013, Lorin Schöni, Verena Distler, Verena Zimmermann |
CHI | 3 |
| 2025 | "Helps me Take the Post With a Grain of Salt: " Soft Moderation Effects on Accuracy Perceptions and Sharing Intentions of Inauthentic Political Content on X
Filipo Sharevski, Verena Distler, Florian Alt |
USENIX Security Symposium | 2 |
| 2025 | Vishing: Detecting social engineering in spoken communication - A first survey & urgent roadmap to address an emerging societal challengeabstractVishing – the use of voice calls for phishing – is a form of Social Engineering (SE) attacks. The latter have become a pervasive challenge in modern societies, with over 300,000 yearly victims in the US alone. An increasing number of those attacks is conducted via voice communication, be it through machine-generated ‘robocalls’ or human actors. The goals of ‘social engineers’ can be manifold, from outright fraud to more subtle forms of persuasion. Accordingly, social engineers adopt multi-faceted strategies for voice-based attacks, utilising a variety of ‘tricks’ to exert influence and achieve their goals. Importantly, while organisations have set in place a series of guardrails against other types of SE attacks, voice calls still remain ‘open ground’ for potential bad actors. In the present contribution, we provide an overview of the existing speech technology subfields that need to coalesce into a protective net against one of the major challenges to societies worldwide. Given the dearth of speech science and technology works targeting this issue, we have opted for a narrative review that bridges the gap between the existing psychological literature on the topic and research that has been pursued in parallel by the speech community on some of the constituent constructs. Our review reveals that very little literature exists on addressing this very important topic from a speech technology perspective, an omission further exacerbated by the lack of available data. Thus, our main goal is to highlight this gap and sketch out a roadmap to mitigate it, beginning with the psychological underpinnings of vishing, which primarily include deception and persuasion strategies, continuing with the speech-based approaches that can be used to detect those, as well as the generation and detection of AI-based vishing attempts, and close with a discussion of ethical and legal considerations. • Vishing is an emerging security problem. • Generative artificial intelligence will exacerbate the issue. • Speech-based detection is urgently needed. • Beyond detection performance, effective interventions are warranted. Andreas Triantafyllopoulos, Anika A. Spiesberger, Iosif Tsangko, Xin Jing 0001, Verena Distler, Felix Dietz, Florian Alt, Björn W. Schuller |
Comput. Speech Lang. | 5 |
| 2024 | The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentabstractOrganizations rely on phishing interventions to enhance employees’ vigilance and safe responses to phishing emails that bypass technical solutions. While various resources are available to counteract phishing, studies emphasize the need for interactive and practical training approaches. To investigate the effectiveness of such an approach, we developed and delivered two anti-phishing trainings, group discussion and role-playing, at a European university. We conducted a pre-registered1 experiment (N = 105), incorporating repeated measures at three time points, a control group, and three in-situ phishing tests. Both trainings enhanced employees’ anti-phishing self-efficacy and support-seeking intention in within-group analyses. Only the role-playing training significantly improved support-seeking intention when compared to the control group. Participants in both trainings reported more phishing tests and demonstrated heightened vigilance to phishing attacks compared to the control group. We discuss practical implications for evaluating and improving phishing interventions and promoting safe responses to phishing threats within organizations. Xiaowei Chen 0013, Margault Sacré, Gabriele Lenzini, Samuel Greiff, Verena Distler, Anastasia Sergeeva |
CHI | 5 |
| 2024 | Public Security User Interfaces: Supporting Spontaneous Engagement with IT SecurityabstractPublisher Copyright: Copyright © 2024 held by the owner/author(s). Doruntina Murtezaj, Viktorija Paneva, Verena Distler, Florian Alt |
NSPW | 3 |
| 2024 | Running out of time(rs): effects of scarcity cues on perceived task load, perceived benevolence and user experience on e-commerce sitesabstractOnline vendors often deploy limited-time and limited-quantity cues on their e-commerce sites to influence consumers purchase decisions. Although these scarcity cues can reflect genuine restrictions in the availability of goods, they are increasingly considered as ill-intentioned nudges or ‘dark patterns’ due to their omnipresence and success in persuading consumers. In an online experiment (N = 202), we examined the effects of limited-time and limited-quantity cues on perceived task load, perceived benevolence, and user experience. Results suggest that participants associated scarcity cues with a lack of benevolence from online vendors. E-commerce site design without scarcity cues provided participants with a superior hedonic and pragmatic user experience. In the case of limited-time scarcity cues, participants reported frustration-related negative emotions. We discuss the implications of these findings from the perspectives of dark pattern researchers, designers, and online vendors. Reha Tuncer, Anastasia Sergeeva, Kerstin Bongard-Blanchy, Verena Distler, Sophie Doublet, Vincent Koenig |
Behav. Inf. Technol. | 4 |
| 2023 | The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception StudyabstractIn today’s digitized societies, phishing attacks are a security threat with damaging consequences. Organizations remain vulnerable to phishing attacks, and it is not clear how the work context influences people’s perceptions and behaviors related to phishing attempts. I investigate (1) how contextual factors influence reactions to a spear-phishing attempt, (2) why people report or do not report phishing attempts, (3) which opportunities for security-enhancing interventions people identify. I use an in-situ deception methodology to observe participants (N=14) in their realistic work environment. I triangulate observational and self-reported data to obtain rich qualitative insights into participants’ emotions, thoughts, and actions when receiving a targeted phishing email. I find that task, IT, internal and social context play an important role. The email’s request being aligned with expectations and perceived time pressure when responding to emails were associated with insecure behavior. The social context positively influenced phishing detection, but “phished” participants did not tell anyone. Verena Distler |
CHI | 1 |
| 2023 | "We Need a Big Revolution in Email Advertising": Users' Perception of Persuasion in Permission-based Advertising EmailsabstractPersuasive tactics intend to encourage users to open advertising emails. However, these tactics can overwhelm users, which makes them frustrated and leads to lower open rates. This paper intends to understand which persuasive tactics are used and how they are perceived by users. We first developed a categorization of inbox-level persuasive tactics in permission-based advertising emails. We then asked participants to interact with an email inbox prototype, combined with interviews (N=32), to investigate their opinions towards advertising emails and underlying persuasive tactics. Our qualitative findings reveal poor user experience with advertising emails, which was related to feeling surveilled by companies, forced subscription, high prior knowledge about persuasive tactics, and a desire for more agency. We also found that using certain persuasive tactics on the inbox level is perceived as ethically inappropriate. Based on these insights, we provide design recommendations to improve advertising communication and make such emails more valuable to users. Anastasia Sergeeva, Björn Rohles, Verena Distler, Vincent Koenig |
CHI | 3 |
| 2023 | Human-centered Behavioral and Physiological SecurityabstractWe propose a paradigm shift in human-centered security research in which users’ objective behavior and physiological states move into focus. This proposal is motivated by the fact that many personal and wearable devices today come with capabilities that allow researchers to assess users’ behavior and physiology in real-time. We expect substantial advances due to the ability to develop more targeted approaches to human-centered security in which solutions are targeted at individuals’ literacy, skills, and context. To this end, the main contribution of this work is a research space: we first provide an overview of common human-centered attacks that could be better understood and addressed through our approach. Based on this overview, we then showcase how specific security habits can benefit from the knowledge of users’ current state. Our work is complemented by a discussion of the implications and research directions enabled through this novel paradigm. Florian Alt, Mariam Hassib, Verena Distler |
NSPW | 3 |
| 2021 | A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security ResearchabstractUsable privacy and security researchers have developed a variety of approaches to represent risk to research participants. To understand how these approaches are used and when each might be most appropriate, we conducted a systematic literature review of methods used in security and privacy studies with human participants. From a sample of 633 papers published at five top conferences between 2014 and 2018 that included keywords related to both security/privacy and usability, we systematically selected and analyzed 284 full-length papers that included human subjects studies. Our analysis focused on study methods; risk representation; the use of prototypes, scenarios, and educational intervention; the use of deception to simulate risk; and types of participants. We discuss benefits and shortcomings of the methods, and identify key methodological, ethical, and research challenges when representing and assessing security and privacy risk. We also provide guidelines for the reporting of user studies in security and privacy. Verena Distler, Matthias Fassl, Hana Habib, Katharina Krombholz, Gabriele Lenzini, Carine Lallemand, Lorrie Faith Cranor, Vincent Koenig |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2020 | The Framework of Security-Enhancing Friction: How UX Can Help Users Behave More SecurelyabstractA growing body of research in the usable privacy and security community addresses the question of how to best influence user behavior to reduce risk-taking. We propose to address this challenge by integrating the concept of user experience (UX) into empirical usable privacy and security studies that attempt to change risk-taking behavior. UX enables us to study the complex interplay between user-related, system-related and contextual factors and provides insights into the experiential aspects underlying behavior change, including negative experiences. Verena Distler, Gabriele Lenzini, Carine Lallemand, Vincent Koenig |
NSPW | 1 |
| 2019 | Security - Visible, Yet Unseen?abstractAn unsolved debate in the field of usable security concerns whether security mechanisms should be visible, or black-boxed away from the user for the sake of usability. However, tying this question to pragmatic usability factors only might be simplistic. This study aims at researching the impact of displaying security mechanisms on User Experience (UX) in the context of e-voting. Two versions of an e-voting application were designed and tested using a between-group experimental protocol (N=38). Version D displayed security mechanisms, while version ND did not reveal any security-related information. We collected data on UX using stan-dardised evaluation scales and semi-structured interviews. Version D performed better overall in terms of UX and need fulfilment. Qualitative analysis of the interviews gives further insights into factors impacting perceived security. Our study adds to existing research suggesting a conceptual shift from usability to UX and discusses implications for designing and evaluating secure systems. Verena Distler, Marie-Laure Zollinger, Carine Lallemand, Peter B. Rønne, Peter Y. A. Ryan, Vincent Koenig |
CHI | 1 |
| 2018 | Acceptability and Acceptance of Autonomous Mobility on Demand: The Impact of an Immersive ExperienceabstractAutonomous vehicles have the potential to fundamentally change existing transportation systems. Beyond legal concerns, these societal evolutions will critically depend on user acceptance. As an emerging mode of public transportation [7], Autonomous mobility on demand (AMoD) is of particular interest in this context. The aim of the present study is to identify the main components of acceptability (before first use) and acceptance (after first use) of AMoD, following a user experience (UX) framework. To address this goal, we conducted three workshops (N=14) involving open discussions and a ride in an experimental autonomous shuttle. Using a mixed-methods approach, we measured pre-immersion acceptability before immersing the participants in an on-demand transport scenario, and eventually measured post-immersion acceptance of AMoD. Results show that participants were reassured about safety concerns, however they perceived the AMoD experience as ineffective. Our findings highlight key factors to be taken into account when designing AMoD experiences. Verena Distler, Carine Lallemand, Thierry Bellet |
CHI | 1 |