EDBT 2026 Demo / reviewers in the wild / expert
Yixin Zou
dblp:218/0356
· DBLP profile ↗
42ranked-venue papers
6as first author
37since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 24 · 3 first-author · 20 since 2021Security and privacy · 16 · 2 first-author · 15 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revealed or Reinforced: How Assistive Technologies Shape the Experience with Dark Patterns for Blind and Low-Vision UsersabstractDark patterns have gained increasing attention among the HCI and design communities, but little is known about how they intersect with assistive technologies (ATs) and impact people with accessibility needs, such as blind and low-vision (BLV) individuals. To address this gap, we conducted an in-lab user study with 18 BLV participants using a custom-built social media application that embeds six common dark patterns. Through observing participant experiences with assigned tasks and semi-structured post-study interviews, we explored how screen readers and magnification tools influence the perception and amplification of deceptive design elements. In contrast to prior work that identified accessibility-induced deception, our findings demonstrate a dual role of ATs where dark patterns are either revealed or intensified. Screen readers exposed hidden manipulations like bad defaults but amplified other dark patterns through sequential reading. Similarly, magnifiers intensified deceptive effects through viewport reduction by restricting the visible area. We conceptualize this mechanism as assistive amplification and show how dark patterns manifest differently for BLV users, informing the design of more inclusive and manipulation-resistant interfaces. Agata Stanczyk, Mindy Tran, Tarini Saka, Yixin Zou, Veelasha Moonsamy |
DIS | 4 |
| 2026 | It Shouldn't Be This Difficult: Researcher Perspectives on Diversity and Inclusion in Usable Privacy and Security ResearchabstractWhile recent usable privacy and security (UPS) research has made progress in moving beyond “the average user,” a systematic account of how UPS researchers navigate diversity and inclusion in their work remains lacking. Through 20 in-depth semi-structured interviews with experienced researchers, we examine how and why they recruit diverse, underserved populations in their work, as well as the challenges they face in doing so, including conceptual difficulties in defining who is underserved, limited access to target populations, and inflexible peer review and publishing norms. Participants also reflected on their own positionality when planning and conducting studies, often expressing uncertainty about how to account for and articulate their positionality. We identify strategies researchers use to overcome challenges and highlight areas where collective action from the research community and institutions is needed to foster greater inclusion in UPS research practices. Priyasha Chatterjee, Smirity Kaushik, Karola Marky, Yixin Zou |
CHI | 4 |
| 2026 | From Harm to Healing: Understanding Individual Resilience after CybercrimesabstractHow do individuals recover from cybercrimes? Victims experience various types of harm after cybercrimes, including monetary loss, data breaches, negative emotions, and even psychological trauma. The aspects that support their recovery process and contribute to individual cyber resilience remain underinvestigated. To address this gap, we interviewed 18 cybercrime victims from Western Europe using a trauma-informed approach. We identified four common stages following victimization: recognition, coping, processing, and recovery. Participants adopted various strategies to mitigate the impact of cybercrime and used different indicators to describe recovery. While they mostly relied on social support and self-regulation for emotional coping, service providers largely determined whether victims were able to recover their money. Internal factors, external support, and context sensitivity collectively contribute to individuals’ cyber resilience. We recommend trauma-informed support for cybercrime victims. Extending our conceptualization of individual cyber resilience, we propose collaborative and context-sensitive strategies to address the harmful impacts of cybercrime. Xiaowei Chen 0013, Mindy Tran, Yue Deng 0003, Bhupendra Acharya, Yixin Zou |
CHI | 5 |
| 2026 | What is Safety? Corporate Discourse, Power, and the Politics of Generative AI SafetyabstractThis work examines how leading generative artificial intelligence companies construct and communicate the concept of "safety" through public-facing documents. Drawing on critical discourse analysis, we analyze a corpus of corporate safety-related statements to explicate how authority, responsibility, and legitimacy are discursively established. These discursive strategies consolidate legitimacy for corporate actors, normalize safety as an experimental and anticipatory practice, and push a perceived participatory agenda toward safe technologies. We argue that uncritical uptake of these discourses risks reproducing corporate priorities and constraining alternative approaches to governance and design. The contribution of this work is twofold: first, to situate safety as a sociotechnical discourse that warrants critical examination; second, to caution human-computer interaction scholars against legitimizing corporate framings, instead foregrounding accountability, equity, and justice. By interrogating safety discourses as artifacts of power, this paper advances a critical agenda for human-computer interaction scholarship on artificial intelligence. Ankolika De, Gabriel Lima, Yixin Zou |
CHI | 3 |
| 2026 | Experiencer, Helper, or Observer: Online Fraud Intervention for Older Adults Through a Role-based Simulation ApproachabstractOnline fraud is a critical global threat that disproportionately targets older adults. Prior anti-fraud education for older adults has largely relied on static, traditional instruction that limits engagement and real-world transfer, whereas role-based simulation offers realistic yet low-risk opportunities for practice. Moreover, most interventions situate learners as victims, overlooking that fraud encounters often involve multiple roles, such as bystanders who witness scams and helpers who support victims. To address this gap, we developed ROLESafe, an anti-fraud educational intervention in which older adults learn through different learning roles, including Experiencer (experiencing fraud), Helper (assisting a victim), and Observer (witnessing fraud). In a between-subjects study with 144 older adults in China, we found that the Experiencer and Helper roles significantly improved participants’ ability to identify online fraud. These findings highlight the promise of role-based, multi-perspective simulations for enhancing fraud awareness among older adults and provide design implications for future anti-fraud education. Yue Deng 0003, Xiaowei Chen 0013, Junxiang Liao, Bo Li 0001, Yixin Zou |
CHI | 5 |
| 2026 | "What If My Face Gets Scanned Without Consent": Older Adults' Experiences with Biometric PaymentabstractBiometric payment, i.e., biometric authentication implemented in digital payment systems, can reduce memory demands and streamline payment for older adults. However, older adults’ perceptions and practices regarding biometric payment remain underexplored. We conducted semi-structured interviews with 22 Chinese older adults, including both users and non-users. Participants were motivated to use biometric payment due to convenience and perceived security. However, they also worried about loss of control due to its password-free nature and expressed concerns about biometric data security. Participants also identified desired features for biometric payment, such as lightweight and context-aware cognitive confirmation mechanisms to enhance user control. We outline recommendations for more accessible and informative digital financial services that better support older adults. Yue Deng 0003, Changyang He, Bo Li 0001, Yixin Zou |
CHI | 4 |
| 2026 | Do Citizens Agree with the EU AI Act? Public Perspectives on Risk and Regulation of AI SystemsabstractThe European Union (EU) has spearheaded the regulation of artificial intelligence (AI) with the AI Act, which regulates AI systems based on the risks they pose to fundamental rights and other protected values. AI systems that pose unacceptable risks are prohibited, high-risk AI systems must comply with mandatory requirements, and minimal risk AI systems are encouraged—but not required—to adopt voluntary standards. Motivated by concerns that the AI Act may not reflect the public’s opinions, we investigate how laypeople (N = 1,421) assess 48 different AI systems concerning their risk and regulation. We find that people believe all 48 AI systems pose moderate levels of risk and should be regulated (albeit without outright prohibitions). Our findings challenge the AI Act’s tiered approach, showing that people might support horizontal regulation requiring minimal standards for AI systems, and provide implications for developers seeking to develop AI aligned with public expectations. Gabriel Lima, Gustavo Gil Gasiola, Frederike Zufall, Yixin Zou |
CHI | 4 |
| 2026 | Characterizing Scam-Driven Human Trafficking Across Chinese Borders and Online Community Responses on RedNoteabstractA new form of human trafficking has emerged across Chinese borders, where individuals are lured to Southeast Asia with fraudulent job offers and then coerced into operating online scams. Despite its massive economic and human toll, this scam-driven trafficking remains underexplored in academic research. Through qualitative analysis of 158 RedNote posts, we examined how Chinese online communities respond to this threat. Our findings reveal that perpetrators exploit cultural ties to recruit victims for cybercriminal roles within self-sustaining compounds, using sophisticated manipulation tactics. Survivors face serious reintegration barriers, including family rejection, as the cultural values that enable trafficking also hinder their recovery. While communities present protective strategies, efforts are complicated by doubts about the reliability of support and cross-border coordination. We discuss key implications for prevention, platform governance, and international cooperation against scam-driven trafficking. Warning: This paper contains descriptions of physical, psychological, and sexual abuse. Yue Deng 0003, Jessica Chen, Shujun Li 0001, Yixin Zou |
CHI | 5 |
| 2026 | "You Have Been Selected as the Winner": Characterizing User-Reported Scams on TikTok
Smirity Kaushik, Kyle Beadle, Gauri Nayak, Madelyn Sanfilippo, Mainack Mondal, Yang Wang 0005, Sai Teja Peddinti, Yixin Zou |
SOUPS | 9 |
| 2026 | "I Wonder if These Warnings are Accurate": Security and Privacy Advice in Nine Majority World CountriesabstractSecurity and privacy (S&P) advice plays a crucial role in how people stay safe online. While prior work shows that the plethora of advice from varied sources makes it difficult for users to prioritize advice, the insights are primarily based on studies conducted in Western contexts. Other work shows that users outside the West have different S&P needs and thus, we cannot simply rely on advice curated in the West to generalize to the majority world - regions of Africa, Asia, Latin America, and the Middle East, where most of the world's population lives. We fill this gap by investigating S&P advice across nine majority world countries via 70 semi-structured interviews with local experts: cybercafe operators, tech repair specialists, and other community figures that people commonly rely on for tech support and S&P advice. We find that the advice provided by local experts in the majority world largely matches the advice they provide to their constituents and the advice from the West. However, we surface various significant barriers that hinder majority world users from implementing advice, including economic constraints, language barriers, and social friction from taking protective measures. Our findings further show how factors such as social norms and gender shape advice practices, e.g., by driving gendered advice-seeking. We discuss how S&P advice in the majority world can be improved and reflect on how the S&P community can better engage with local communities in conducting similar research. Collins W. Munyendo, Veronica A. Rivera, Jackie Hu, Emmanuel Tweneboah, Amna Shahnawaz, Karen Sowon, Dilara Keküllüoglu, Marcos Silva, Mercy Omeiza, Gayatri Priyadarsini Kancherla, Marianne Batista Diniz Da Silva, Abhishek Bichhawat, Maryam Mustafa, Francisco J. Marmolejo Cossío, Elissa M. Redmiles, Yixin Zou |
SP | 17 |
| 2026 | Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview Study
Mindy Tran, Xinru Tang, Adryana Hutchinson, Adam J. Aviv, Yixin Zou |
SP | 5 |
| 2026 | Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths Forward
Warda Usman, Yixin Zou, Daniel Zappala |
SP | 2 |
| 2025 | "Auntie, Please Don't Fall for Those Smooth Talkers": How Chinese Younger Family Members Safeguard Seniors from Online FraudabstractOnline fraud substantially harms individuals and seniors are disproportionately targeted. While family is crucial for seniors, little research has empirically examined how they protect seniors against fraud. To address this gap, we employed an inductive thematic analysis of 124 posts and 16,872 comments on RedNote (Xiaohongshu), exploring the family support ecosystem for senior-targeted online fraud in China. We develop a taxonomy of senior-targeted online fraud from a familial perspective, revealing younger members often spot frauds hard for seniors to detect, such as unusual charges. Younger family members fulfill multiple safeguarding roles, including preventative measures, fraud identification, fraud persuasion, loss recovery, and education. They also encounter numerous challenges, such as seniors' refusal of help and considerable mental and financial stress. Drawing on these, we develop a conceptual framework to characterize family support in senior-targeted fraud, and outline implications for researchers and practitioners to consider the broader stakeholder ecosystem and cultural aspects. Yue Deng 0003, Changyang He, Yixin Zou, Bo Li 0001 |
CHI | 3 |
| 2025 | Lay Perceptions of Algorithmic Discrimination in the Context of Systemic InjusticeabstractAlgorithmic fairness research often disregards concerns related to systemic injustice.We study how contextualizing algorithms within systemic injustice impacts lay perceptions of algorithmic discrimination.Using the hiring domain as a case-study, we conduct a 2x3 between-participants experiment (𝑁 =716), studying how people's views of algorithmic fairness are influenced by information about (i) systemic injustice in historical hiring decisions and (ii) algorithms' propensity to perpetuate biases learned from past human decisions.We find that shedding light on systemic injustice has heterogeneous effects: participants from historically advantaged groups became more negative about discriminatory algorithms, while those from disadvantaged groups reported more positive attitudes.Explaining that algorithms learn from past human decisions had null effects on people's views, adding nuances to calls for improving public understanding of algorithms.Our findings reveal that contextualizing algorithms in systemic injustice can have unintended consequences and show how different ways of framing existing inequalities influence perceptions of injustice. Gabriel Lima, Nina Grgic-Hlaca, Markus Langer, Yixin Zou |
CHI | 4 |
| 2025 | More than Usability: Differential Access to Digital Security and Privacy
Annalina Buckmann, Jan Magnus Nold, Yasemin Acar, Yixin Zou |
SOUPS | 4 |
| 2025 | SoK: A Privacy Framework for Security Research Using Social Media DataabstractThe use of social media data in research is common, spanning fields from computer science to social science, from human-computer interaction to law and criminology. However, social media data often contains personal and sensitive information. While prior work discusses the ethics of research using social media data, focusing on ethics broadly can be insufficient to unravel granular privacy risks and possible mitigations. Focusing on research papers that use social media data to study security-related topics, we systematically analyze 601 papers across 16 years, covering a wide array of academic disciplines. Our findings highlight a lack of transparency in reporting - only 35% of papers mention any considerations of data anonymization, availability, and storage. Applying Solove's taxonomy to classify the identified privacy risks in the social media setting, we observe that Solove's taxonomy was prescient in capturing aggregation risk, but the volume, timeliness, and micro details of data, combined with modern data science, yield risks beyond what was considered 20 years ago. We present the implications of our findings for various stakeholders: researchers, ethics boards, and publishing venues. While there are already signs of improvement, we posit that some small behavioral changes from the academic community may make a big difference in user privacy. Kyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran, Marilyne Ordekian, Enrico Mariconti, Yixin Zou, Marie Vasek |
SP | 7 |
| 2025 | Digital Security Perceptions and Practices Around the World: A WEIRD versus Non-WEIRD Comparison
Franziska Herbert, Collins W. Munyendo, Jonas Hielscher, Steffen Becker 0003, Yixin Zou |
USENIX Security Symposium | 5 |
| 2025 | "No, I Can't Be a Security Personnel on Your Phone": Security and Privacy Threats From Sharing Infrastructure in Rural Ghana
Emmanuel Tweneboah, Collins W. Munyendo, Yixin Zou |
USENIX Security Symposium | 3 |
| 2025 | Dynamic Layered Clustering Routing Protocol Based on Hybrid-Optimized Neural Networks for UWSNsabstractTo address the limitations of traditional flat routing in large-scale underwater wireless sensor networks (UWSNs), and to tackle challenges, such as long delays, low bandwidth, and high error rates encountered by sensor nodes in underwater environments, this article proposes a dynamic layered clustering routing protocol based on a hybrid optimized backpropagation neural network (PSB-NN), referred to as PSBDR. The protocol introduces nonuniform vertical layering of the network based on water depth and assigns different communication and sensing radii to nodes according to their initial layer. A trained hierarchical prediction model dynamically adjusts the virtual layer assignments of nodes throughout the network’s operation. Additionally, a method is implemented for isolated nodes to join clusters via relay nodes, and a priority mechanism, along with a dynamic weight update strategy, is employed to select the optimal next hop during routing. This protocol effectively balances the workload across nodes at varying depths and maximizes the utilization of residual energy in the nodes, contributing to an extending network lifetime. Simulation results demonstrate that PSBDR enhances network performance by improving load balancing, prolonging network longevity, reducing end-to-end delay, and increasing data collection reliability. Xinmiao Lu, Longyue Yang, Qiong Wu 0004, Yuna Zhu, Yixin Zou, Yunbo Shi |
IEEE Internet Things J. | 5 |
| 2025 | Beyond "Vulnerable Populations": A Unified Understanding of Vulnerability From A Socio-Ecological PerspectiveabstractHCI and CSCW research has witnessed increasing efforts to address diversity and inclusion in research and design practice, as evidenced by the growing body of research with populations deemed as vulnerable, marginalized, or underserved. However, this work has been largely limited to a population-specific approach, i.e., identifying certain populations as vulnerable and gathering their individual experiences. Drawing primarily from human-centered security and privacy research, we identify three key challenges faced by this population-specific approach: (1) It is limited in addressing user diversity within the target population; (2) It may fail to capture the complex social reality of vulnerability; and (3) It runs the risk of perpetuating othering and stereotypes. To address these limitations, we propose a socio-ecological perspective on vulnerability adapted from the Ecological System Theory (EST). We argue that a socio-ecological perspective of vulnerability can guide researchers to look beyond static and stigmatizing definitions of vulnerability --- instead, focus on the situations, relations, and structures that lead to vulnerability, eventually enabling transferable knowledge of vulnerability across populations. We demonstrate how the socio-ecological lens maps onto existing work and generates new insights in the case of older adults' security and privacy, as well as its potential for being applied to other contexts such as reproductive privacy and responsible artificial intelligence. We end by providing concrete recommendations on how HCI and CSCW research can better operationalize vulnerability in scholarship and design practice. Xinru Tang, Gabriel Lima, Li Jiang 0013, Lucy Simko, Yixin Zou |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2025 | "What are they gonna do with my data?": Privacy Expectations, Concerns, and Behaviors in Virtual RealityabstractThe immersive nature of Virtual Reality (VR) and its reliance on sensory devices like head-mounted displays introduce privacy risks to users. While earlier research has explored users' privacy concerns within VR environments, less is known about users' comprehension of VR data practices and protective behaviors; the expanding VR market and technological progress also necessitate a fresh evaluation. We conducted semi-structured interviews with 20 VR users, showing their diverse perceptions regarding the types of data collected and their intended purposes. We observed privacy concerns in three dimensions: institutional, social, and device-specific. Our participants sought to protect their privacy through considerations when selecting the device, scrutinizing VR apps, and selective engagement in different VR interactions. We contrast our findings with observations from other technologies and ecosystems, shedding light on how VR has altered the privacy landscape for end-users. We further offer recommendations to alleviate users' privacy concerns, rectify misunderstandings, and encourage the adoption of privacy-conscious behaviors. Abhinaya S. B., Abhishri Agrawal, Yaxing Yao, Yixin Zou, Anupam Das 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Privacy Perceptions and Behaviors Towards Targeted Advertising on Social Media: A Cross-Country Study on the Effect of Culture and ReligionabstractSocial media platforms are an effective channel for businesses to reach potential audiences through targeted advertising. As the user base of these platforms expands and diversifies, research on targeted advertising and social media needs to go beyond well-studied Western contexts. In an online survey (n=412), we compared users' privacy-related perceptions and behaviors regarding targeted ads on social media in the United States (as a baseline representing Western contexts) and three South Asian countries: Bangladesh, India, and Pakistan. We found that participants in the US perceived significantly fewer benefits and more concerns related to security and privacy about targeted ads than those in the three South Asian countries. We also identified that individual's cultural values and religious affiliations influenced the observed cross-country variances. For instance, US participants identified less with vertical collectivism and vertical individualism than South Asian participants; these two cultural dimensions were, in turn, positively associated with perceived benefits. Our findings highlight the limitation of using one's country as a proxy for culture, as our findings show users' privacy perceptions regarding targeted advertising on social media are more fundamentally associated with their cultural values and religion. We discuss the corresponding design, education, and regulatory implications for targeted advertising on social media. Smirity Kaushik, Tanusree Sharma, Yaman Yu, Amna F. Ali, Bart P. Knijnenburg, Yang Wang 0005, Yixin Zou |
Proc. Priv. Enhancing Technol. | 7 |
| 2025 | Misalignments and Demographic Differences in Expected and Actual Privacy Settings on FacebookabstractSocial media platforms pose privacy risks when data is used in unexpected ways (e.g., for advertising or data sharing with partners). Using a custom browser extension and an online survey with 195 Facebook users, we investigated (1) whether participants’ expected values of their Facebook privacy settings were (mis)aligned with their actual settings; (2) demographic differences in privacy expectation-setting mismatches; and (3) participants' privacy concerns and trust towards Facebook.Our study presents a current and comprehensive analysis of Facebook users' privacy settings. We find that expectation-setting mismatches are prevalent: all participants had at least one mismatch; many had multiple, often expecting their settings to be more restrictive than they were. We also found that Facebook's default values are not aligned with people's expectations and/or actual settings, which suggests that those defaults are ineffective. Furthermore, mismatches differed along certain demographic variables.Participants' trust in Facebook decreased after they became aware of mismatches and their actual settings. Our empirical findings indicate that, despite increased public awareness, media scrutiny, and regulatory attention regarding privacy issues, there is still a substantial and concerning disconnect between how private people perceive their social media data to be and how exposed their data actually is, opening them up to both interpersonal and institutional privacy risks. We discuss design and public policy implications of our findings. Byron Lowens, Sean Scarnecchia, Jane Im, Tanisha Afnan, Annie Chen, Yixin Zou, Florian Schaub |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | Robust Distributed Localization Based on Barycentric Coordinates Under Random Data LossabstractDistributed localization systems enable nodes to determine their locations by exchanging information with neighboring nodes, without relying on centralized infrastructure. While it enhances scalability and robustness, random data loss during in formation transmission can significantly degrade the localization performance. In this paper, to mitigate the impact of random data loss, we propose a Loss-Robust distributed localization method based on the Distributed Iterative Localization algorithm (LR DILOC). In LR-DILOC, each node updates its location estimate by leveraging the most recent available location information from its neighboring nodes, thereby improving the utilization of available data. We theoretically analyze the convergence of LR-DILOC, demonstrating that LR-DILOC maintains accurate localization even in the presence of random data loss. Numerical results further validate the theoretical analysis, demonstrating that LR-DILOC achieves higher localization accuracy and exhibits stronger robustness under random data loss. Yixin Zou, Xiufang Shi, Mincheng Wu, Wen-An Zhang 0001 |
IEEE Signal Process. Lett. | 1 |
| 2024 | Explainability as a Requirement for Hardware: Introducing Explainable Hardware (XHW)abstractIn today's age of digital technology, ethical concerns regarding computing systems are increasing. While the focus of such concerns currently is on requirements for software, this article spotlights the hardware domain, specifically microchips. For example, the opaqueness of modern microchips raises security issues, as malicious actors can manipulate them, jeopardizing system integrity. As a consequence, governments invest substantially to facilitate a secure microchip supply chain. To combat the opaqueness of hardware, this article introduces the concept of Explainable Hardware (XHW). Inspired by and building on previous work on Explainable AI (XAI) and explainable software systems, we develop a framework for achieving XHW comprising relevant stakeholders, requirements they might have concerning hardware, and possible explainability approaches to meet these requirements. Through an exploratory survey among 18 hardware experts, we showcase applications of the framework and discover potential research gaps. Our work lays the foundation for future work and structured debates on XHW. Timo Speith, Julian Speith, Steffen Becker 0003, Yixin Zou, Asia J. Biega, Christof Paar |
RE | 4 |
| 2024 | Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User GroupsabstractThis paper investigates the digital security experiences of four at-risk user groups in Germany, including older adults (70+), teenagers (14-17), people with migration backgrounds, and people with low formal education. Using computer-assisted telephone interviews, we sampled 250 participants per group, representative of region, gender, and partly age distributions. We examine their device usage, concerns, prior negative incidents, perceptions of potential attackers, and information sources. Our study provides the first quantitative and nationally representative insights into the digital security experiences of these four at-risk groups in Germany. Our findings show that participants with migration backgrounds used the most devices, sought more security information, and reported more experiences with cybercrime incidents than other groups. Older adults used the fewest devices and were least affected by cybercrimes. All groups relied on friends and family and online news as their primary sources of security information, with little concern about their social circles being potential attackers. We highlight the nuanced differences between the four at-risk groups and compare them to the broader German population when possible. We conclude by presenting recommendations for education, policy, and future research aimed at addressing the digital security needs of these at-risk user groups. Franziska Herbert, Steffen Becker 0003, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Dürmuth, Yixin Zou, M. Angela Sasse |
SP | 8 |
| 2024 | Unfulfilled Promises of Child Safety and Privacy: Portrayals and Use of Children in Smart Home MarketingabstractSmart home technologies are making their way into families. Parents' and children's shared use of smart home technologies has received growing attention in CSCW and related research communities. Families and children are also frequently featured as target audiences in smart home product marketing. However, there is limited knowledge of how exactly children and family interactions are portrayed in smart home product marketing, and to what extent those portrayals align with the actual consideration of children and families in product features and resources for child safety and privacy. We conducted a content analysis of product websites and online resources of 102 smart home products, as these materials constitute a main marketing channel and information source about products for consumers. We found that despite featuring children in smart home marketing, most analyzed product websites did not mention child safety features and lacked sufficient information on how children's data is collected and used. Specifically, our findings highlight misalignments in three aspects: (1) children are depicted as users of smart home products but there are insufficient child-friendly product features; (2) harmonious child-product co-presence is portrayed but potential child safety issues are neglected; and (3) children are shown as the subject of monitoring and datafication but there is limited information on child data collection and use. We discuss how parent-child relationships and parenting may be negatively impacted by such marketing depictions, and we provide design and policy recommendations for better incorporating child safety and privacy considerations into smart home products. Kaiwen Sun 0001, Yixin Zou, Jenny S. Radesky, Christopher Brooks 0001, Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | Cross-Contextual Examination of Older Adults' Privacy Concerns, Behaviors, and VulnerabilitiesabstractA growing body of research has examined the privacy concerns and behaviors of older adults, often within specific contexts. It remains unclear to what extent older adults' privacy concerns and behaviors vary across contexts and whether old age is the primary factor influencing privacy vulnerabilities. To address this gap, we conducted semi-structured interviews with 43 older adults (aged 65 to 89) in the United States. Our interviews were grounded in five scenarios: account and device sharing, healthcare, online advertising, social networking, and cybercrime. Our cross-contextual analysis showed that cybercrime was a recurring and pressing concern across scenarios; privacy concerns and protective behaviors were rarely mentioned in the healthcare scenario. Across all scenarios, participants' threat models and strategies revolved around data collection rather than other stages in which privacy harms may occur; they employed various active strategies to safeguard their privacy while trusting service providers to protect their information. Our findings underscore the need to revisit the discussion around privacy vulnerability and aging. Vulnerability levels among our participants varied widely and were often influenced by factors beyond age, such as tech savviness and income. We discuss opportunities for privacy interventions, technologies, and education that promote positive aging and recognize diversity among older adults. Yixin Zou, Kaiwen Sun 0001, Tanisha Afnan, Ruba Abu-Salma, Robin Brewer, Florian Schaub |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Encouraging Users to Change Breached Passwords Using the Protection Motivation TheoryabstractWe draw on the Protection Motivation Theory (PMT) to design interventions that encourage users to change breached passwords. Our online experiment ( \(n=1{,}386\) ) compared the effectiveness of a threat appeal (highlighting the negative consequences after passwords were breached) and a coping appeal (providing instructions on changing the breached password) in a 2 \(\times\) 2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords. Participants’ password change behaviors are further associated with other factors, such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based interventions are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT’s application in security research and provides concrete design implications for improving compromised credential notifications. Yixin Zou, Khue Le, Peter Mayer 0001, Alessandro Acquisti, Adam J. Aviv, Florian Schaub |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2023 | Bridging the Gap: Towards Advancing Privacy and AccessibilityabstractThe privacy dimensions of accessibility technologies are often understudied and overlooked. Very little prior research has investigated the privacy concerns of disabled people, and much less has studied the barriers of privacy-preserving techniques. In order to address this gap and bridge between two separate communities (accessibility and privacy), our one-day workshop explores how researchers might design and build technologies that are both accessible and privacy-preserving. Rahaf Alharbi, Robin Brewer, Gesu India, Lotus Hanzi Zhang, Leah Findlater, Yixin Zou, Abigale Stangl |
ASSETS | 6 |
| 2023 | A New Pareto Discrete NSGAII Algorithm for Disassembly Line Balance ProblemabstractWith the increasing variety and quantity of end‐of‐life (EOL) products, the traditional disassembly process has become inefficient. In response to this phenomenon, this article proposes a random multiproduct U‐shaped mixed‐flow incomplete disassembly line balancing problem (MUPDLBP). MUPDLBP introduces a mixed disassembly method for multiple products and incomplete disassembly method into the traditional DLBP, while considering the characteristics of U‐shaped disassembly lines and the uncertainty of the disassembly process. First, mixed‐flow disassembly can improve the efficiency of disassembly lines, reducing factory construction and maintenance costs. Second, by utilizing the characteristics of incomplete disassembly to reduce the number of dismantled components and the flexibility and efficiency of U‐shaped disassembly lines in allocating disassembly tasks, further improvement in disassembly efficiency can be achieved. In addition, this paper also addresses the characteristics of EOL products with heavy weight and high rigidity. While retaining the basic settings of MUPDLBP, the stability of the assembly during the disassembly process is considered, and a new problem called MUPDLBP_S, which takes into account the disassembly stability, is further proposed. The corresponding mathematical model is provided. To obtain high‐quality disassembly plans, a new and improved algorithm called INSGAII is proposed. The INSGAII algorithm uses the initialization method based on Monte Carlo tree simulation (MCTI) and the Group Global Crowd Degree Comparison (GCDC) operator to replace the initialization method and crowding distance comparison operator in the NSGAII algorithm, effectively improving the coverage of the initial population individuals in the entire solution space and the evenness and spread of the Pareto front. Finally, INSGAII’s effectiveness has been affirmed by tackling both current disassembly line balancing problems and the proposed MUPDLBP and MUPDLBP_S. Importantly, INSGAII outshines six comparison algorithms with a top rank of 1 in the Friedman test, highlighting its superior performance. Zhenxin Li, Yixin Zou |
Int. J. Intell. Syst. | 4 |
| 2023 | Awareness, Intention, (In)Action: Individuals' Reactions to Data BreachesabstractData breaches are prevalent. We provide novel insights into individuals’ awareness, perception, and responses to breaches that affect them through two online surveys: a main survey (n= 413) in which we presented participants with up to three breaches that affected them, and a follow-up survey (n= 108) in which we investigated whether the main study participants followed through with their intentions to act. Overall, 73% of participants were affected by at least one breach, but participants were unaware of 74% of breaches affecting them. Although some reported intention to take action, most participants believed the breach would not impact them. We also found a sizable intention-behavior gap. Participants did not follow through with their intention when they were apathetic about breaches, considered potential costs, forgot, or felt resigned about taking action. Our findings suggest that breached organizations should be held accountable for more proactively informing and protecting affected consumers. Peter Mayer 0001, Yixin Zou, Byron Lowens, Hunter A. Dyer, Khue Le, Florian Schaub, Adam J. Aviv |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2022 | Trauma-Informed Computing: Towards Safer Technology Experiences for AllabstractTrauma is the physical, emotional, or psychological harm caused by deeply distressing experiences. Research with communities that may experience high rates of trauma has shown that digital technologies can create or exacerbate traumatic experiences. Via three vignettes, we discuss how considering the possible effects of trauma and traumatic stress reactions provides an explanatory lens with new insights into people’s technology experiences. Then, we present a framework—trauma-informed computing—in which we adapt and show how to apply six key principles of trauma-informed approaches to computing: safety, trust, peer support, collaboration, enablement, and intersectionality. Through specific examples, we describe how to apply trauma-informed computing in four areas of computing research and practice: user experience research & design, security & privacy, artificial intelligence & machine learning, and organizational culture in tech companies. We conclude by discussing how adopting trauma-informed computing will lead to benefits for all users, not only those experiencing trauma. Janet X. Chen, Allison McDonald, Yixin Zou, Emily Tseng, Kevin A. Roundy, Acar Tamersoy, Florian Schaub, Thomas Ristenpart, Nicola Dell |
CHI | 3 |
| 2021 | Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link TextsabstractIncreasingly, icons are being proposed to concisely convey privacy-related information and choices to users. However, complex privacy concepts can be difficult to communicate. We investigate which icons effectively signal the presence of privacy choices. In a series of user studies, we designed and evaluated icons and accompanying textual descriptions (link texts) conveying choice, opting-out, and sale of personal information — the latter an opt-out mandated by the California Consumer Privacy Act (CCPA). We identified icon-link text pairings that conveyed the presence of privacy choices without creating misconceptions, with a blue stylized toggle icon paired with “Privacy Options” performing best. The two CCPA-mandated link texts (“Do Not Sell My Personal Information” and “Do Not Sell My Info”) accurately communicated the presence of do-not-sell opt-outs with most icons. Our results provide insights for the design of privacy choice indicators and highlight the necessity of incorporating user testing into policy making. Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Joel R. Reidenberg, Norman M. Sadeh, Florian Schaub |
CHI | 2 |
| 2021 | "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them
Peter Mayer 0001, Yixin Zou, Florian Schaub, Adam J. Aviv |
USENIX Security Symposium | 2 |
| 2021 | The Role of Computer Security Customer Support in Helping Survivors of Intimate Partner Violence
Yixin Zou, Allison McDonald, Julia Narakornpichit, Nicola Dell, Thomas Ristenpart, Kevin A. Roundy, Florian Schaub, Acar Tamersoy |
USENIX Security Symposium | 1 |
| 2021 | Child Safety in the Smart Home: Parents' Perceptions, Needs, and Mitigation StrategiesabstractConcerns about child physical and digital safety are emerging with families' adoption of smart home technologies such as robot vacuums and smart speakers. To better understand parents' definitions and perceptions of child safety regarding smart home technologies, we interviewed 23 parents who are smart home adopters. We contribute insights into parents' perceptions of the physical and digital safety risks smart home technologies pose to children, and how such perceptions formed and changed across three phases. In acquiring smart home devices, parents already considered whether the device could cause physical harm to their children or pose privacy and security risks. Once children become active users of smart home technologies, parents however reported encountering unanticipated physical safety risks and digital safety issues (e.g., exposure to unsuitable content) that required their mitigation strategies. As their children grow up, parents further expressed the need to shift attention from physical safety to digital safety. Parents' safety perceptions influence how they involve children in smart home interactions and implement mitigation strategies, such as restricting access to certain devices and using parental controls. We identify six factors that shape parents' perception and evaluation of smart home safety risks to children, including parenting style, parents' tech-savviness, parents' trust in tech companies, children's age and developmental differences, news media, and device characteristics. We provide design and policy recommendations to better protect children's safety in the smart home environment. Kaiwen Sun 0001, Yixin Zou, Jenny S. Radesky, Christopher Brooks 0001, Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2020 | "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesabstractWe conducted an in-lab user study with 24 participants to explore the usefulness and usability of privacy choices offered by websites. Participants were asked to find and use choices related to email marketing, targeted advertising, or data deletion on a set of nine websites that differed in terms of where and how these choices were presented. They struggled with several aspects of the interaction, such as selecting the correct page from a site's navigation menu and understanding what information to include in written opt-out requests. Participants found mechanisms located in account settings pages easier to use than options contained in privacy policies, but many still consulted help pages or sent email to request assistance. Our findings indicate that, despite their prevalence, privacy choices like those examined in this study are difficult for consumers to exercise in practice. We provide design and policy recommendations for making these website opt-out and deletion choices more useful and usable for consumers. Hana Habib, Sarah Pearman, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
CHI | 4 |
| 2020 | Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection PracticesabstractUsers struggle to adhere to expert-recommended security and privacy practices. While prior work has studied initial adoption of such practices, little is known about the subsequent implementation and abandonment. We conducted an online survey (n=902) examining the adoption and abandonment of 30 commonly recommended practices. Security practices were more widely adopted than privacy and identity theft protection practices. Manual and fully automatic practices were more widely adopted than practices requiring recurring user interaction. Participants' gender, education, technical background, and prior negative experience are correlated with their levels of adoption. Furthermore, practices were abandoned when they were perceived as low-value, inconvenient, or when users overrode them with subjective judgment. We discuss how security, privacy, and identity theft protection recommendations and tools can be better aligned with user needs. Yixin Zou, Kevin A. Roundy, Acar Tamersoy, Saurabh Shintre, Johann Roturier, Florian Schaub |
CHI | 1 |
| 2020 | Listen Only When Spoken To: Interpersonal Communication Cues as Smart Speaker Privacy ControlsabstractAbstract Internet of Things and smart home technologies pose challenges for providing effective privacy controls to users, as smart devices lack both traditional screens and input interfaces. We investigate the potential for leveraging interpersonal communication cues as privacy controls in the IoT context, in particular for smart speakers. We propose privacy controls based on two kinds of interpersonal communication cues – gaze direction and voice volume level – that only selectively activate a smart speaker’s microphone or voice recognition when the device is being addressed, in order to avoid constant listening and speech recognition by the smart speaker microphones and reduce false device activation. We implement these privacy controls in a smart speaker prototype and assess their feasibility, usability and user perception in two lab studies. We find that privacy controls based on interpersonal communication cues are practical, do not impair the smart speaker’s functionality, and can be easily used by users to selectively mute the microphone. Based on our findings, we discuss insights regarding the use of interpersonal cues as privacy controls for smart speakers and other IoT devices. Abraham H. Mhaidli, Manikandan Kandadai Venkatesh, Yixin Zou, Florian Schaub |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | Put Your Warning Where Your Link Is: Improving and Evaluating Email Phishing WarningsabstractPhishing emails often disguise a link's actual URL. Thus, common anti-phishing advice is to check a link's URL before clicking, but email clients do not support this well. Automated phishing detection enables email clients to warn users that an email is suspicious, but current warnings are often not specific. We evaluated the effects on phishing susceptibility of (1) moving phishing warnings close to the suspicious link in the email, (2) displaying the warning on hover interactions with the link, and (3) forcing attention to the warning by deactivating the original link, forcing users to click the URL in the warning. We assessed the effectiveness of such link-focused phishing warning designs in a between-subjects online experiment (n=701). We found that link-focused phishing warnings reduced phishing click-through rates compared to email banner warnings; forced attention warnings were most effective. We discuss the implications of our findings for phishing warning design. Justin Petelka, Yixin Zou, Florian Schaub |
CHI | 2 |
| 2019 | You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach NotificationsabstractData breaches place affected individuals at significant risk of identity theft. Yet, prior studies have shown that many consumers do not take protective actions after receiving a data breach notification from a company. We analyzed 161 data breach notifications sent to consumers with respect to their readability, structure, risk communication, and presentation of potential actions. We find that notifications are long and require advanced reading skills. Many companies downplay or obscure the likelihood of the receiver being affected by the breach and associated risks. Moreover, potential actions and offered compensations are frequently described in lengthy paragraphs instead of clearly listed. Little information is provided regarding an action's urgency and effectiveness; little guidance is provided on which actions to prioritize. Based on our findings, we provide recommendations for designing more usable and informative data breach notifications that could help consumers better mitigate the consequences of being affected by a data breach. Yixin Zou, Shawn Danino, Kaiwen Sun 0001, Florian Schaub |
CHI | 1 |