Ayako Akiyama Hasegawa

dblp:249/1158 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-5527-5306ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Influence or Deception? Evaluating Social Suggestions with Persuasive Statements for Security and Privacy Settings
abstract
Configuring security and privacy (S&P) settings can be challenging for non-expert users, resulting in excessive dependence on persuasive cues, such as social proofs or expert suggestions. Although such suggestions can promote protective user choices, they can be misused as deceptive patterns that steer users toward less-protective settings. This study examines (1) how source-based suggestions (public vs. experts), when combined with logical persuasive statements, influence decision-making in S&P settings under honest or deceptive conditions and (2) how users evaluate these approaches once deception is revealed. An online experiment with 1,433 U.S. participants utilizing a 2 × 2 × 2 factorial design revealed that persuasive statements amplified the effect of social proof- and authority-based cues, which persisted even when promoting less-protective settings. These findings demonstrate the importance of persuasive S&P interfaces that follow transparent and rational design, as well as complementary interventions that foster users’ critical assessment and resilience against manipulation.
Ayako Akiyama Hasegawa, Takahiro Kasama, Mitsuaki Akiyama
CHI1
2025 Collaborative Work in Malware Analysis: Understanding the Roles and Challenges of Malware Analysts
Rei Yamagishi, Shota Fujii, Shingo Yasuda, Takayuki Sato, Ayako Akiyama Hasegawa
CHI5
2024 How WEIRD is Usable Privacy and Security Research?
Ayako Akiyama Hasegawa, Mitsuaki Akiyama
USENIX Security Symposium1
2023 Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries
abstract
Secure development guidelines contribute to improving software security from the development stage by making developers aware of the risks to be assumed, the necessary security countermeasures, and how to implement them. In this study, we investigated the actual utilization of guidelines and their usability in the industry through a survey of software development professionals in the U.S. and Japan (N=396 in the U.S. and N=474 in Japan). Our quantitative analysis revealed that “in-house” guidelines not examined in most existing studies are in fact widely utilized in the industry and also clarified how they are related to the use of public guidelines. In addition, we found that the practices for implementing guidelines recommended by existing studies are difficult for software development professionals with certain attributes, e.g., those who are working on small projects. The findings demonstrate the need for lightweight recommended practices taking into account organizational issues at industrial development sites that are easy for developers to implement.
Fumihiro Kanei, Ayako Akiyama Hasegawa, Eitaro Shioji, Mitsuaki Akiyama
CHI2
2021 A Cross-role and Bi-national Analysis on Security Efforts and Constraints of Software Development Projects
abstract
Software security, which is often regarded as a non-functional requirement, tends to be less prioritized than other explicit requirements in development projects. For designing security measures that can be used in software development, we must understand the obstacles that prevent the adoption of secure software development practices. In this study, we quantitatively analyzed security efforts and constraints of software development projects through an online survey of software development professionals in the US and Japan (N=664). We revealed how certain characteristics of a development project, such as the project’s contractual relationships or the software’s target users, influence security efforts and constraints. In addition, by comparing the survey results of two groups (developers and managers), we revealed how the gap in their security efforts and constraints influences software security. We believe the results provide insights toward designing usable measures to assist security-related decision-making in software development and conducting appropriate surveys targeting software development professionals.
Fumihiro Kanei, Ayako Akiyama Hasegawa, Eitaro Shioji, Mitsuaki Akiyama
ACSAC2
2019 I know what you did last login: inconsistent messages tell existence of a target's account to insiders
abstract
Account security to protect user accounts against sensitive data breaches is a major mission for online service providers. Therefore, they exert tremendous effort in securing account authentication. Although threats from complete outsiders, such as account hijacking for monetization, still occur, recent studies have shed light on threats to privacy from insiders. This paper sheds light on the latter threats. Specifically, we present the first comprehensive study of an attack from insiders that identifies the existence of a target's account by using the target's email address and insecure login-related messages displayed. Such a threat may violate intimates' or acquaintances' privacy because the kinds of service accounts a user has implies his/her personal preferences or situation. We conducted surveys regarding user expectations and behaviors on online services and a measurement study of the login-related messages on online services that are considered sensitive. We found that over 80% of participants answered that there are sensitive services and that almost all services were vulnerable to our attack. Moreover, about half the participants who have sensitive services are insecurely registered on them and thus could be potential victims. Finally, we make recommendations on the basis of our findings for online service providers to improve login-related messages and for users to take appropriate defensive actions.
Ayako Akiyama Hasegawa, Takuya Watanabe 0001, Eitaro Shioji, Mitsuaki Akiyama
ACSAC1
2019 DomainScouter: Understanding the Risks of Deceptive IDNs
Daiki Chiba 0001, Ayako Akiyama Hasegawa, Takashi Koide, Yuta Sawabe, Shigeki Goto, Mitsuaki Akiyama
RAID2