EDBT 2026 Demo / reviewers in the wild / expert
Anna-Marie Ortloff
dblp:248/7206
· DBLP profile ↗
11ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-5735-178XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 11 · 7 first-author · 10 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "The AI tool can't make it any worse." Investigating Developers' Security Behavior with AI Assistants in a Password Storage StudyabstractPast research showed that software developers often require explicit instructions to implement security measures. With the rapid rise of AI assistant tools such as ChatGPT, it remains unclear whether AI assistance supports or undermines secure practices, whether explicit security instructions are still essential, and how developers behave without guidance. To investigate these research questions, we conducted a qualitative lab study with 21 computer science students and a quantitative online study with 80 freelance developers. We focused on secure password storage and asked participants to implement registration logic under four conditions: without instructions, with AI assistance, with security instructions, or with both AI assistance and security instructions. Our study reveals a clear behavioral shift: In our task, many participants relied on AI-assisted code generation for security-related tasks, often prioritizing convenience over security. However, explicit security-focused instructions can redirect this behavior toward secure outcomes, demonstrating that AI tools alone are insufficient without targeted guidance. Asli Yardim, Raphael Serafini, Nadine Jost, Anna-Marie Ortloff, Joshua Gabriel Speckels, Alena Naiakshina |
CHI | 4 |
| 2025 | Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesabstractAdherence to data protection measures such as pseudonymization or anonymization is critical in human subjects research because it has a direct impact on the confidentiality of participants' sensitive information, trust in research practices, and compliance with ethical and legal standards. Regulations such as the General Data Protection Regulation (GDPR) and guarantees made by researchers in informed consent forms mandate strict protocols for data security. However, compliance with these is not always straightforward. To gain qualitative insights into data protection practices in the field of Usable Security and Privacy (USP), we conducted interviews with 22 practitioners (five professors, eight researchers, nine data protection officers) and one focus group with five researchers. Overall, our results show a high awareness of ethical and legal responsibilities but highlight many practical and procedural issues. Based on these, we make concrete recommendations on how to improve the protection of personal data in research. Florin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam, Lisa Geierhaas, Anna-Marie Ortloff, Matthew Smith 0001, Christian Tiefenau |
CHI | 6 |
| 2025 | A Qualitative Study on How Usable Security and HCI Researchers Judge the Size and Importance of Odds Ratio and Cohen's d Effect SizesabstractResearchers often place a strong focus on statistical significance when reporting the results of statistical tests. However, effect sizes are reported less frequently, and interpretation in the context of the study and the research field is even rarer. These interpretations of effect sizes are, however, necessary to understand the practical importance of a result for the community. To explore how Usable Security & Privacy (USP) and HCI researchers interpret effect sizes and make judgments on practical importance, we conducted survey and interview studies with a total of 63 researchers at CHI and SOUPS 2023. Our studies focused on Cohen's d and odds ratios in two USP and one HCI scenario. We analyzed which artifacts researchers consider when judging effect size, and found misconceptions and variation between the participants, highlighting how difficult judging statistics can be. Based on our findings, we make concrete recommendations for improved reporting practices around effect sizes. Anna-Marie Ortloff, Julia Angelika Grohs, Simon Lenau, Matthew Smith 0001 |
CHI | 1 |
| 2025 | Small, Medium, Large? A Meta-Study of Effect Sizes at CHI to Aid Interpretation of Effect Sizes and Power CalculationabstractStatistical reporting, especially of effect sizes, is at the root of many methodological issues in quantitative research at CHI. Effect sizes are necessary for assessing practical relevance of results, a-priori power analysis, and meta-analyses, but currently, they are often not reported. Interpretations in the context of the study and the research field are also rare. To aid to researchers in reporting and contextualizing their effect sizes within their research field as well as choosing effect sizes for power analysis, we conducted a meta-study of quantitative CHI papers. We extracted statistics from all quantitative CHI papers published between 2019-2023 (N=1692). Based on effect sizes and the papers' CCS categories, we present effect size distributions in 12 CHI research fields. Through an additional qualitative analysis of 67 quantitative CHI'23 publications, we identify five categories of approaches that researchers take when interpreting effect size: Comparing test-specific values, assigning size labels, using a statistical or methodological reference frame, comparing different observations and interpreting for the big picture. Anna-Marie Ortloff, Florin Martius, Mischa Meier, Theo Sans-Raimbault, Lisa Geierhaas, Matthew Smith 0001 |
CHI | 1 |
| 2025 | I never reuse passwords! Development and Validation of a Security and Privacy Social Desirability Scale (SP-SDS) for end users without a background in computer science
Laura Marie Abels, Matthew Smith 0001, Anna-Marie Ortloff |
SOUPS | 3 |
| 2025 | Replication: "No one can hack my mind" - 10 years later: An update and outlook on experts' and non-experts' security practices and advice
Anna-Marie Ortloff, Jenny Tang, Arthi Arumugam, Daniel Huschina, Lisa Geierhaas, Florin Martius, Luisa Jansen, Kolja von der Twer, Lilly Jungbluth, Matthew Smith 0001 |
SOUPS | 1 |
| 2023 | Different Researchers, Different Results? Analyzing the Influence of Researcher Experience and Data Type During Qualitative Analysis of an Interview and Survey Study on Security AdviceabstractWhen conducting qualitative research it is necessary to decide how many researchers should be involved in coding the data: Is one enough or are more coders beneficial? To offer empirical evidence for this question, we designed a series of studies investigating qualitative coding. We replicated and extended a usable security and privacy study by Ion et al. to gather both simple survey data and complex interview data. We had a total of 65 students and seven researchers analyze different parts of this data. We analyzed the codebook creation process, similarity of outcomes, inter-rater reliability, and compared the student to the researcher outcomes. We also surveyed five years of SOUPS-PC members about their views on coding. The reviewers view on coding practices for complex and simple data are almost identical. However, our results suggest that the coding process can be different for the two types of data, with complex data benefiting more from interaction between coders. Anna-Marie Ortloff, Matthias Fassl, Alexander Ponticello, Florin Martius, Anne Mertens, Katharina Krombholz, Matthew Smith 0001 |
CHI | 1 |
| 2023 | SoK: I Have the (Developer) Power! Sample Size Estimation for Fisher's Exact, Chi-Squared, McNemar's, Wilcoxon Rank-Sum, Wilcoxon Signed-Rank and t-tests in Developer-Centered Usable Security
Anna-Marie Ortloff, Christian Tiefenau, Matthew Smith 0001 |
SOUPS | 1 |
| 2022 | Privacy at a Glance: A Process to Learn Modular Privacy Icons During Web BrowsingabstractPrivacy policies (PPs) are currently the only way to inform users about their rights and choices during web browsing and searching. However, users avoid engaging with them, because of their length and abstract legal language, which makes them hard to read and understand. We propose to support the understanding of PPs by using modular icons. Icons have already proven to be helpful in visualizing concepts with high information density. However, the value of using icons to supplement PPs lacks a scientific foundation. Thus, we conducted two studies to evaluate existing icon sets for their understandability and to teach participants their meaning in situ. We show that modular privacy icons can be taught using our process, which has the potential to aid quicker and easier comprehension of PPs. We contribute a set of tested modular privacy icons and a verified process on how to teach them to users incidentally during web browsing. Maximiliane Windl, Anna-Marie Ortloff, Niels Henze, Valentin Schwind |
CHIIR | 2 |
| 2021 | The Effect of Nudges and Boosts on Browsing Privacy in a Naturalistic EnvironmentabstractDuring everyday web browsing and search users reveal many pieces of private information to third parties. Even though people report being concerned about their privacy online, they often do not take steps to protect it. This is known as the 'privacy paradox' in the literature. In this work we study two well-known strategies based on theories from the behavioral sciences, nudging and boosting, which encourage users to browse in a way that their private data are less exposed. First, an online survey (N=127) tested the comprehensibility and efficacy of various facts (boosts), before the most effective of these were evaluated against 'nudge' interventions previously shown to be efficacious in lab-studies. A three week naturalistic study (N=68) using a browser extension revealed that both nudges and boosts improve browsing privacy, as approximated by different measures. Boosts are also shown to improve user knowledge about privacy in the short term, but the benefit weakens over time. Anna-Marie Ortloff, Steven Zimmerman, David Elsweiler, Niels Henze |
CHIIR | 1 |
| 2020 | Implementation and In Situ Assessment of Contextual Privacy PoliciesabstractOnline services collect an increasing amount of data about their users. Privacy policies are currently the only common way to inform users about the kinds of data collected, stored and processed by online services. Previous work showed that users do not read and understand privacy policies, due to their length, difficult language, and often non-prominent location. Embedding privacy-relevant information directly in the context of use could help users understand the privacy implications of using online services. We implemented Contextual Privacy Policies (CPPs) as a browser extension and provide it to the community to make privacy information accessible for end-users. We evaluated CPPs through a one-week deployment and in situ questionnaires as well as pre- and post-study interviews. We found that CPPs were well received by participants. The analysis revealed that provided information should be as compact as possible, be adjusted to user groups and enable users to take action. Anna-Marie Ortloff, Maximiliane Windl, Valentin Schwind, Niels Henze |
Conference on Designing Interactive Systems | 1 |