EDBT 2026 Demo / reviewers in the wild / expert
Collins W. Munyendo
dblp:293/9864
· DBLP profile ↗
16ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0003-1987-1685ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 6 first-author · 13 since 2021Human-computer interaction and ubiquitous computing · 4 · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Re-Examining the Examiners: Changes in Privacy and Security Perceptions of Exam ProctoringabstractWith the shift to remote learning during the COVID-19 pandemic, educators turned to remote exam proctoring software to support integrity for online tests. However, due to the mechanisms used to surveil test-takers, these systems come with significant privacy and security tradeoffs. At the height of the pandemic, Balash et al. (SOUPS ’21) found that test-takers had privacy concerns with remote proctoring but acquiesced due to a number of factors. We investigate how perceptions have changed four years later. To gain a fuller perspective on how users experience these tools now, we replicate Balash et al.’s study with 127 participants who have experienced exam proctoring. We found a significant shift in favor of proctoring software, with greater acceptance of all monitoring methods compared to 2020. This is likely due to the convenience of remote exams and a growing resignation to privacy trade-offs. We discuss these implications and suggest future directions. Adryana Hutchinson, Elaine Ly, Collins W. Munyendo, Adam J. Aviv |
CHI | 3 |
| 2026 | "I Wonder if These Warnings are Accurate": Security and Privacy Advice in Nine Majority World CountriesabstractSecurity and privacy (S&P) advice plays a crucial role in how people stay safe online. While prior work shows that the plethora of advice from varied sources makes it difficult for users to prioritize advice, the insights are primarily based on studies conducted in Western contexts. Other work shows that users outside the West have different S&P needs and thus, we cannot simply rely on advice curated in the West to generalize to the majority world - regions of Africa, Asia, Latin America, and the Middle East, where most of the world's population lives. We fill this gap by investigating S&P advice across nine majority world countries via 70 semi-structured interviews with local experts: cybercafe operators, tech repair specialists, and other community figures that people commonly rely on for tech support and S&P advice. We find that the advice provided by local experts in the majority world largely matches the advice they provide to their constituents and the advice from the West. However, we surface various significant barriers that hinder majority world users from implementing advice, including economic constraints, language barriers, and social friction from taking protective measures. Our findings further show how factors such as social norms and gender shape advice practices, e.g., by driving gendered advice-seeking. We discuss how S&P advice in the majority world can be improved and reflect on how the S&P community can better engage with local communities in conducting similar research. Collins W. Munyendo, Veronica A. Rivera, Jackie Hu, Emmanuel Tweneboah, Amna Shahnawaz, Karen Sowon, Dilara Keküllüoglu, Marcos Silva, Mercy Omeiza, Gayatri Priyadarsini Kancherla, Marianne Batista Diniz Da Silva, Abhishek Bichhawat, Maryam Mustafa, Francisco J. Marmolejo Cossío, Elissa M. Redmiles, Yixin Zou |
SP | 1 |
| 2025 | Reimagining Wearable-Based Digital Contact Tracing: Insights from Kenya and Côte d'Ivoire
Kavous Salehzadeh Niksirat, Collins W. Munyendo, Onicio Batista Leal Neto, Muswagha Katya, Cyrille Kouassi, Kevin Ochieng, Angoa Georgina, Bernard Olayo, Jean-Philippe Barras, Ciro Cattuto, Adam J. Aviv, Carmela Troncoso |
CHI | 2 |
| 2025 | Design and Evaluation of Privacy-Preserving Protocols for Agent-Facilitated Mobile Money Services in Kenya
Karen Sowon, Collins W. Munyendo, Lily Klucinec, Eunice Maingi, Gerald Suleh, Lorrie Faith Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye |
SOUPS | 2 |
| 2025 | "You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp ModsabstractWhatsApp is the most popular social messaging platform, and modified versions (or “mods”) of the official WhatsApp are increasingly popular. Mods advertise additional features and customization. However, some of these features, e.g., retaining deleted messages and statuses, enable mod users to subvert the privacy of others, and have the potential for seri-ous security and privacy implications. In this study, we explore user perspectives of WhatsApp mods through an interview study$(n=20)$of mod users in Kenya, one of the countries with the highest WhatsApp mod usage. Many turned to WhatsApp mods for their “advanced” features to protect themselves (e.g., “anti-delete” for legal liability), while others admitted to using mod features to hide their behavior or to stalk others. To understand how users' expectations of WhatsApp mods align with the apps' behavior, we identify and analyze 13 instances of the most common mod (GB WhatsApp). While WhatsApp mods contained the features they claimed to offer, some participants incorrectly believed that features currently available in the official app only existed in mods. Additionally, several mods were significantly over-permissioned compared to the official WhatsApp, despite participants believing that they requested the same permissions as the official app. While almost half of participants indicated they trust mods more than the official WhatsApp, we found two mods contained malware. The use of WhatsApp mods poses risks to mod users and those they communicate with, but also empowers users in ways that the official app does not. We caution developers and mod users to do their due diligence before using or distributing mods. Collins W. Munyendo, Kentrell Owens, Faith Strong, Adam J. Aviv, Tadayoshi Kohno, Franziska Roesner |
SP | 1 |
| 2025 | Digital Security Perceptions and Practices Around the World: A WEIRD versus Non-WEIRD Comparison
Franziska Herbert, Collins W. Munyendo, Jonas Hielscher, Steffen Becker 0003, Yixin Zou |
USENIX Security Symposium | 2 |
| 2025 | "No, I Can't Be a Security Personnel on Your Phone": Security and Privacy Threats From Sharing Infrastructure in Rural Ghana
Emmanuel Tweneboah, Collins W. Munyendo, Yixin Zou |
USENIX Security Symposium | 2 |
| 2024 | It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based BiasabstractOnline platforms employ manual human moderation to distinguish human-created social media profiles from deepfake-generated ones. Biased misclassification of real profiles as artificial can harm general users as well as specific identity groups; however, no work has yet systematically investigated such mistakes and biases. We conducted a user study (n=695) that investigates how 1) the identity of the profile, 2) whether the moderator shares that identity, and 3) components of a profile shown affect the perceived artificiality of the profile. We find statistically significant biases in people’s moderation of LinkedIn profiles based on all three factors. Further, upon examining how moderators make decisions, we find they rely on mental models of AI and attackers, as well as typicality expectations (how they think the world works). The latter includes reliance on race/gender stereotypes. Based on our findings, we synthesize recommendations for the design of moderation interfaces, moderation teams, and security training. Jaron Mink, Miranda Wei, Collins W. Munyendo, Kurt Hugenberg, Tadayoshi Kohno, Elissa M. Redmiles, Gang Wang 0011 |
CHI | 3 |
| 2024 | Security, Privacy, and Data-sharing Trade-offs When Moving to the United States: Insights from a Qualitative StudyabstractMoving to a new country often means that people leave their "known environment" and interact with new entities, often sharing sensitive and personal information. This exposes them to various risks. In this study, we investigate the challenges and concerns related to security, privacy, and data-sharing for people who have recently moved to the United States. Through semi-structured interviews (n=25), we find that most participants feel uncomfortable sharing documents containing their personal and sensitive information for the visa process e.g., their financial information and proof of relationship. Sharing this information makes participants concerned about their safety and privacy and sometimes violates their cultural information-sharing norms. Moving to a new environment, particularly to the US, also makes people vulnerable to fraud, specifically fraudulent online renting posts and scam calls. Those who move also navigate bureaucratic, administrative, and technical challenges that exacerbate their perceived security and privacy concerns. We further find a power imbalance that compels visa applicants to share all required information—to avoid getting their visa rejected—without feeling fully informed about the requirements and safeguards in place. Our study highlights the need for more guidance, transparency, and respect for individuals’ privacy from embassies and for technology designers to better support and protect those moving countries. Mindy Tran, Collins W. Munyendo, Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Luisa Ball Schnell, Cora Sula, Lucy Simko, Yasemin Acar |
SP | 2 |
| 2023 | "I just stopped using one and started using the other": Motivations, Techniques, and Challenges When Switching Password ManagersabstractThis paper explores what motivates password manager (PM) users in the US to switch from one PM to another, the techniques they employ when switching, and challenges they encounter throughout. Through a screener (n = 412) followed by a main survey (n = 54), we find that browser-based PMs are the most widely used, with most of these users motivated to use the PM due to convenience. Unfortunately, password reuse remains high. Most participants that switch PMs do so for usability reasons, but are also motivated by cost, as third-party PMs' full suite of features often require a subscription fee. Some PM-switchers are also motivated by recent security breaches, such as what was reported at LastPass in the Fall of 2022, with some participants losing trust in LastPass and PMs generally as a result. Those that switch mostly employ manual techniques of moving their passwords, e.g., copying and pasting their credentials from their previous to their new PM, despite most PMs offering ways to automatically transfer credentials in bulk across PMs. Assistance during the switching process is limited, with less than half of participants that switched receiving guidance during the switching process. From these findings, we make recommendations to PMs that can improve their overall user experience and use, including eliciting and acting on regular feedback from users as well as making PM settings more easily reachable and customizable by end-users. Collins W. Munyendo, Peter Mayer 0001, Adam J. Aviv |
CCS | 1 |
| 2023 | "In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in KenyaabstractCybercafes remain a popular way to access the Internet in the developing world as many users still lack access to personal computers. Coupled with the recent digitization of government services, e.g. in Kenya, many users have turned to cybercafes to access essential services. Many of these users may have never used a computer, and face significant security and privacy issues at cybercafes. Yet, these challenges as well as the advice offered remain largely unexplored. We investigate these challenges along with the security advice and support provided by the operators at cybercafes in Kenya through n = 36 semi-structured interviews (n = 14 with cybercafe managers and n = 22 with customers). We find that cybercafes serve a crucial role in Kenya by enabling access to printing and government services. However, most customers face challenges with computer usage as well as security and usability challenges with account creation and password management. As a workaround, customers often rely on the support and advice of cybercafe managers who mostly direct them to use passwords that are memorable, e.g. simply using their national ID numbers or names. Some managers directly manage passwords for their customers, with one even using the same password for all their customers. These results suggest the need for more awareness about phone-based password managers, as well as a need for computer training and security awareness among these users. There is also a need to explore security and privacy advice beyond Western peripheries to support broader populations. Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
SP | 1 |
| 2022 | User Perceptions of Five-Word PasswordsabstractHuman-chosen passwords are often short, selected non-uniformly, and thus, susceptible to automated guessing attacks. To help users to select more secure but memorable passwords, experts have recommended the use of passphrases of multiple words or phrases. In this paper, we explore a strategy for passphrase selection, so-called five-word passwords, where users are assigned five random words for a passphrase. Such a password composition policy was recently adopted at Georgetown University in December 2020. Through a two-part online survey (n = 150 and n = 116), participants selected a five-word password under different conditions. We find that computer-generated five-word passwords are more diverse and likely more secure than five-word passwords users select themselves. While all cases of five-word passwords are likely more secure than a human-generated, traditional password, participants expressed misconceptions regarding the security of five-word passwords (and passwords generally). Five-word passwords also appear to negatively impact usability, only 39.7 % of participants successfully recalled their password after two weeks. While five-word passwords offer improvements for security, more outreach is needed to explain their security benefits and reduce usability burdens. Xiaoyuan Wu, Collins W. Munyendo, Eddie Cosic, Genevieve A. Flynn, Olivia Legault, Adam J. Aviv |
ACSAC | 2 |
| 2022 | "Desperate Times Call for Desperate Measures": User Concerns with Mobile Loan Apps in KenyaabstractThe usage of mobile loan applications has proliferated in developing countries. This is due to the ease and speed in which they disburse small loans to users, compared to traditional financial institutions, such as banks, that only offer similar loans based on existing customer relationship or collateral. As mobile loan apps are a relatively new industry, these apps are mostly unregulated and therefore tend to charge extremely high interest rates. Further, they collect and sometimes misuse sensitive user data through the course of verifying customers and ensuring loan repayment, such as users’ contacts and SMS communications through the mobile device permission system. Yet, the reasons for usage as well as privacy concerns with these mobile loan apps in the developing world, and specifically in Kenya, remain largely unexplored. To investigate mobile loan apps, we conducted semi-structured interviews (n = 20) with loan app users in Kenya, and we find that most users generally have privacy concerns, particularly regarding access to their phones’ contacts. However, they often overlook these concerns as this outweighs their need to procure loans. At the same time, we find that users struggle to understand the use of permissions by these mobile loan apps (and mobile apps generally), confirming prior research on comprehension of Android permissions. Our results highlight privacy risks, concerns and behavior with the emerging mobile loan app marketplace in the developing world, and we offer recommendations that can help protect their users’ security and privacy, including the need for transparent communication by these apps on how they collect, use and secure their users’ data. Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
SP | 1 |
| 2022 | Why Users (Don't) Use Password Managers at a Large Educational Institution
Peter Mayer 0001, Collins W. Munyendo, Michelle L. Mazurek, Adam J. Aviv |
USENIX Security Symposium | 2 |
| 2022 | "The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits
Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur, Adam J. Aviv |
USENIX Security Symposium | 1 |
| 2021 | Strategies and Perceived Risks of Sending Sensitive Documents
Noel Warford, Collins W. Munyendo, Ashna Mediratta, Adam J. Aviv, Michelle L. Mazurek |
USENIX Security Symposium | 2 |