EDBT 2026 Demo / reviewers in the wild / expert
Partha Das Chowdhury
dblp:59/4305
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-5367-6659ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Maybe... I Don't Really Wanna Clone: Attitudes and Anticipated Harms of (Consensual) After-Death Cloning of One's Own and Voices of Entrusted Others
Jennifer Vander Loop, Filipo Sharevski, Lucy Davies, Partha Das Chowdhury |
SOUPS | 4 |
| 2025 | Would 'Secure' Users Lead to Secure Commons? Surprisingly Not! A framework to evaluate effective power and collective outcomes in cybersecurityabstractIndividuals are often held responsible when adverse cyber incidents occur. The ensuing narrative, explaining the occurrence, points to confounding factuals e.g., inability to act securely, a convincingly deceptive attack, or selfishness/laziness. The underlying assumption is that: if only humans were different (acted securely), such adverse events would not occur. In this paper, we use a game theoretic approach to investigate the counterfactual in cyber: what would happen if individuals were indeed different? To that end, we propose a generic framework drawing upon two games. Our proposed framework can help move the field towards judicious responsibilization of individuals and eliminate knee-jerk scapegoating. We use this framework to examine a specific social harm — data pollution. Our explorations show that even if individuals always behaved securely, this would not necessarily improve collective outcomes. We show that individuals are sometimes not in a position to change security outcomes, however secure their behaviours. The proposed framework can be applied to highlight those entities that are indeed in a position to influence security outcomes in the wider aggregate harm landscape. Future research should build on our work to assign responsibilities in the cyber domain, explore ways to operationalise the games to carry out empirical research, and contribute to novel paradigms such as ethical responsibilization in the context of data breaches. Partha Das Chowdhury, Karen Renaud, Ingrid Ott |
NSPW | 1 |
| 2024 | "When Data Breaches Happen, Where Does the Buck Stop?... and where should it stop?"abstractA digital-first society requires its citizens to carry out essential activities online e.g., applying for a passport, managing pension funds or scheduling medical appointments. Sensitive and personal information is requested and provided in the hope that the confidentiality, integrity and availability thereof will be preserved. In reality, data breaches occur with distressing regularity. When this occurs, ‘second’ victims are created: the customers whose data has been leaked. In many cases, service providers demonstrate very little care or concern for these victims, responsibilizing instead of supporting them. We surveyed 175 respondents, including second victims, non-victims and managers. It becomes clear that a ‘feudal security’ paradigm informs organisations’ responses to data breaches. Indeed, the buck seems to stop with second victims, instead of with the breached service provider. We propose an ‘Ethical Responsibilization’ paradigm which would see second victims treated more equitably and fairly. Partha Das Chowdhury, Karen Renaud, Awais Rashid |
NSPW | 1 |
| 2024 | Threat models over space and time: A case study of end-to-end-encrypted messaging applicationsabstractAbstract Threat modeling is one of the foundations of secure systems engineering and must take heed of the context within which systems operate. In this work, we explore the extent to which real‐world systems engineering reflects a changing threat context. We examine the desktop clients of six widely used end‐to‐end‐encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short‐lived adversarial access against these desktop clients and analyzed the results using two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to track threats in the evolving context within which systems operate and, more importantly, mitigate them by rescoping trust boundaries so that they remain consistent with administrative boundaries. A nuanced understanding of the relationship between trust and administration is vital for robust security, including the provision of safe defaults. Partha Das Chowdhury, Maria Sameen, Jenny Blessing, Nicholas Boucher, Joseph Gardiner, Tom Burrows, Ross J. Anderson, Awais Rashid |
Softw. Pract. Exp. | 1 |
| 2023 | 'Ought' should not assume 'Can'? Basic Capabilities in Cybersecurity to Ground Sen's Capability ApproachabstractWe inhabit a ‘digital first’ society, which is only viable if everyone, regardless of ability and capacity, is able to benefit from online offerings in a safe and secure way. However, disabled individuals, people living under oppressive regimes, elderly citizens and individuals fleeing conflict can be excluded, because they might not have the opportunity to implement cybersecurity hygiene measures. To reduce this potential exclusion, it is crucial to make all users’ situated realities focal variables in policy debates and provisioning efforts. This requires a validated set of basic minimum capabilities which reflect individuals’ diverse personal and social realities. In this paper, we report on a scoping literature review intended to reveal the state of play with respect to capabilities-related research in the cyber domain. We motivate our initial focus on the over 65s for this investigation. We used advice from online government cybersecurity advisories to arrive at a set of five recommended cybersecurity hygiene tasks. These fed into a survey with sixty senior citizens to elicit the barriers they could envisage someone of their age encountering, in acting upon cybersecurity hygiene advice. The final deliverable is a candidate list of basic capabilities (cybersecurity) for seniors. This enables us to start measuring security and privacy poverty, an essential step in recognising and mitigating exclusion, as well as informing threat modelling efforts. Partha Das Chowdhury, Karen Renaud |
NSPW | 1 |
| 2023 | Co-creating a Transdisciplinary Map of Technology-mediated Harms, Risks and Vulnerabilities: Challenges, Ambivalences and OpportunitiesabstractThe phrase "online harms'' has emerged in recent years out of a growing political willingness to address the ethical and social issues associated with the use of the Internet and digital technology at large. The broad landscape that surrounds online harms gathers a multitude of disciplinary, sectoral and organizational efforts while raising myriad challenges and opportunities for the crossing entrenched boundaries. In this paper we draw lessons from a journey of co-creating a transdisciplinary knowledge infrastructure within a large research initiative animated by the online harms agenda. We begin with a reflection of the implications of mapping, taxonomizing and constructing knowledge infrastructures and a brief review of how online harm and adjacent themes have been theorized and classified in the literature to date. Grounded on our own experience of co-creating a map of online harms, we then argue that the map---and the process of mapping---perform three mutually constitutive functions, acting simultaneously as method, medium and provocation. We draw lessons from how an open-ended approach to mapping, despite not guaranteeing consensus, can foster productive debate and collaboration in ethically and politically fraught areas of research. We end with a call for CSCW research to surface and engage with the multiple temporalities, social lives and political sensibilities of knowledge infrastructures. Andrés Domínguez Hernández, Kopo M. Ramokapane, Partha Das Chowdhury, Ola Aleksandra Michalec, Emily Johnstone, Emily Godwin, Alicia G. Cork, Awais Rashid |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | From Utility to Capability: A New Paradigm to Conceptualize and Develop Inclusive PETsabstractThe wider adoption of Privacy Enhancing Technologies (PETs) has relied on usability studies – which focus mainly on an assessment of how a specified group of users interface, in particular contexts, with the technical properties of a system. While human-centred efforts in usability aim to achieve important technical improvements and drive technology adoption, a focus on the usability of PETs alone is not enough. PETs development and adoption requires a broadening of focus to adequately capture the specific needs of individuals, particularly of vulnerable individuals and/or individuals in marginalized populations. We argue for a departure, from the utilitarian evaluation of surface features aimed at maximizing adoption, towards a bottom-up evaluation of what real opportunities humans have to use a particular system. We delineate a new paradigm for the way PETs are conceived and developed. To that end, we propose that Amartya Sen’s capability approach offers a foundation for the comprehensive evaluation of the opportunities individuals have based on their personal and environmental circumstances which can, in turn, inform the evolution of PETs. This includes considerations of vulnerability, age, education, physical and mental ability, language barriers, gender, access to technology, freedom from oppression among many important contextual factors. Partha Das Chowdhury, Andrés Domínguez Hernández, Kopo M. Ramokapane, Awais Rashid |
NSPW | 1 |