EDBT 2026 Demo / reviewers in the wild / expert
Mindy Tran
dblp:353/2032
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0000-1601-8588ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revealed or Reinforced: How Assistive Technologies Shape the Experience with Dark Patterns for Blind and Low-Vision UsersabstractDark patterns have gained increasing attention among the HCI and design communities, but little is known about how they intersect with assistive technologies (ATs) and impact people with accessibility needs, such as blind and low-vision (BLV) individuals. To address this gap, we conducted an in-lab user study with 18 BLV participants using a custom-built social media application that embeds six common dark patterns. Through observing participant experiences with assigned tasks and semi-structured post-study interviews, we explored how screen readers and magnification tools influence the perception and amplification of deceptive design elements. In contrast to prior work that identified accessibility-induced deception, our findings demonstrate a dual role of ATs where dark patterns are either revealed or intensified. Screen readers exposed hidden manipulations like bad defaults but amplified other dark patterns through sequential reading. Similarly, magnifiers intensified deceptive effects through viewport reduction by restricting the visible area. We conceptualize this mechanism as assistive amplification and show how dark patterns manifest differently for BLV users, informing the design of more inclusive and manipulation-resistant interfaces. Agata Stanczyk, Mindy Tran, Tarini Saka, Yixin Zou, Veelasha Moonsamy |
DIS | 2 |
| 2026 | From Harm to Healing: Understanding Individual Resilience after CybercrimesabstractHow do individuals recover from cybercrimes? Victims experience various types of harm after cybercrimes, including monetary loss, data breaches, negative emotions, and even psychological trauma. The aspects that support their recovery process and contribute to individual cyber resilience remain underinvestigated. To address this gap, we interviewed 18 cybercrime victims from Western Europe using a trauma-informed approach. We identified four common stages following victimization: recognition, coping, processing, and recovery. Participants adopted various strategies to mitigate the impact of cybercrime and used different indicators to describe recovery. While they mostly relied on social support and self-regulation for emotional coping, service providers largely determined whether victims were able to recover their money. Internal factors, external support, and context sensitivity collectively contribute to individuals’ cyber resilience. We recommend trauma-informed support for cybercrime victims. Extending our conceptualization of individual cyber resilience, we propose collaborative and context-sensitive strategies to address the harmful impacts of cybercrime. Xiaowei Chen 0013, Mindy Tran, Yue Deng 0003, Bhupendra Acharya, Yixin Zou |
CHI | 2 |
| 2026 | Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview Study
Mindy Tran, Xinru Tang, Adryana Hutchinson, Adam J. Aviv, Yixin Zou |
SP | 1 |
| 2025 | SoK: A Privacy Framework for Security Research Using Social Media DataabstractThe use of social media data in research is common, spanning fields from computer science to social science, from human-computer interaction to law and criminology. However, social media data often contains personal and sensitive information. While prior work discusses the ethics of research using social media data, focusing on ethics broadly can be insufficient to unravel granular privacy risks and possible mitigations. Focusing on research papers that use social media data to study security-related topics, we systematically analyze 601 papers across 16 years, covering a wide array of academic disciplines. Our findings highlight a lack of transparency in reporting - only 35% of papers mention any considerations of data anonymization, availability, and storage. Applying Solove's taxonomy to classify the identified privacy risks in the social media setting, we observe that Solove's taxonomy was prescient in capturing aggregation risk, but the volume, timeliness, and micro details of data, combined with modern data science, yield risks beyond what was considered 20 years ago. We present the implications of our findings for various stakeholders: researchers, ethics boards, and publishing venues. While there are already signs of improvement, we posit that some small behavioral changes from the academic community may make a big difference in user privacy. Kyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran, Marilyne Ordekian, Enrico Mariconti, Yixin Zou, Marie Vasek |
SP | 4 |
| 2024 | Security, Privacy, and Data-sharing Trade-offs When Moving to the United States: Insights from a Qualitative StudyabstractMoving to a new country often means that people leave their "known environment" and interact with new entities, often sharing sensitive and personal information. This exposes them to various risks. In this study, we investigate the challenges and concerns related to security, privacy, and data-sharing for people who have recently moved to the United States. Through semi-structured interviews (n=25), we find that most participants feel uncomfortable sharing documents containing their personal and sensitive information for the visa process e.g., their financial information and proof of relationship. Sharing this information makes participants concerned about their safety and privacy and sometimes violates their cultural information-sharing norms. Moving to a new environment, particularly to the US, also makes people vulnerable to fraud, specifically fraudulent online renting posts and scam calls. Those who move also navigate bureaucratic, administrative, and technical challenges that exacerbate their perceived security and privacy concerns. We further find a power imbalance that compels visa applicants to share all required information—to avoid getting their visa rejected—without feeling fully informed about the requirements and safeguards in place. Our study highlights the need for more guidance, transparency, and respect for individuals’ privacy from embassies and for technology designers to better support and protect those moving countries. Mindy Tran, Collins W. Munyendo, Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Luisa Ball Schnell, Cora Sula, Lucy Simko, Yasemin Acar |
SP | 1 |
| 2024 | "Those things are written by lawyers, and programmers are reading that." Mapping the Communication Gap Between Software Developers and Privacy ExpertsabstractTo ensure data-privacy compliance, it is common for companies to consult privacy experts for the identification and communication of privacy requirements to software developers. However, developers often fail to fulfill those requirements resulting in companies regularly being fined for violations due to non-compliance with privacy data regulations. To investigate why software developers struggle with the implementation of privacy requirements and explore their communication modality, we conducted a qualitative semi-structured interview study with 30 participants involving 10 software developers, 10 privacy experts, and 10 team coordinators with an average experience of nine years in the privacy communication and implementation process within a company context. We found a communication gap between software developers and privacy experts, suggesting a lack of proper procedural steps during the software development process to guarantee that the privacy requirements have been adequately addressed. We also uncovered that since privacy requirements were mostly communicated in a uni-directional manner, they were often perceived as a hindrance during software development, thus fostering an adversarial relationship between privacy experts and developers. Therefore, in order to fulfill the experts' requirements, software developers requested concrete steps to take during the software development process, as observed in the security field. However, privacy experts often lacked the technical knowledge to provide such instructions. This work contributes an explanatory theory on the communication gap between software developers and privacy experts. We discuss common obstacles in the communication of privacy experts and software developers and provide guidance on how to address them. Stefan Horstmann, Samuel Domiks, Marco Gutfleisch, Mindy Tran, Yasemin Acar, Veelasha Moonsamy, Alena Naiakshina |
Proc. Priv. Enhancing Technol. | 4 |