Lab members are underlined. * indicates equal contribution.
Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit
, , , , ,
Symposium on Usable Privacy and Security (SOUPS), 2026
PDF
SoK: Mapping Threats to Defenses in Online Survey Fraud
, , , , ,
Symposium on Usable Privacy and Security (SOUPS), 2026
In Preparation
"Unlimited Realm of Exploration and Experimentation": Methods and Motivations of AI-Generated Sexual Content Creators
, ,
ACM Conference on Fairness, Accountability, and Transparency (FAccT), 2026
PDF
Website
Poster
News:
Harvard Berkman Klein Center Whitepaper on Survivor-Centered NCII Reporting
Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
, , , , , , , , , , , , , , , , , , , , , , ,
Pre-Print, 2026
PDF
I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery
, , , , , , , ,
ACM CHI Conference on Human Factors in Computing Systems, 2026
PDF
Do Hackers Dream of Electric Teachers?: A Large-Scale, In-Situ Evaluation of Cybersecurity Student Behaviors and Performance with AI Tutors
, , , , , , , , , ,
Pre-Print, 2026
PDF
SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security Behaviors
, , , , ,
33rd USENIX Security Symposium, 2024
PDF
It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based Bias
, , , , , ,
ACM CHI Conference on Human Factors in Computing Systems, 2024
PDF
Talk
News:
NIST AI Executive Order RFI
"Security is not my field, I'm a stats guy": A Qualitative Root Cause Analysis of Barriers to Adversarial Machine Learning Defenses in Industry
, , , ,
32nd USENIX Security Symposium, 2023
PDF
Talk
Poster
Slides
News:
Human-Centered Security Podcast,
NIST AI Executive Order RFI
SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions
, , , , , , , ,
44th IEEE Symposium on Security and Privacy, 2023
PDF
Everybody's Got ML, Tell Me What Else You Have: Practitioners' Perception of ML-Based Security Tools and Explanations
, , , , , ,
44th IEEE Symposium on Security and Privacy, 2023
PDF
Talk
Slides
Teaser
News:
Human-Centered Security Podcast,
NIST AI Executive Order RFI
FAuST: Striking a Bargain between Forensic Auditing's Security and Throughput
, , , , , , ,
38th Annual Computer Security Applications Conference, 2022
PDF
DeepPhish: Understanding User Trust Towards Artificially Generated Profiles in Online Social Networks
, , , , ,
31st USENIX Security Symposium, 2022
PDF
Supplemental Materials
Website
Talk
Slides
News:
Futurum,
New Scientist,
NIST AI Executive Order RFI
Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking Apps
, , , ,
ACM CHI Conference on Human Factors in Computing Systems, 2022
PDF
Supplemental Materials
Talk
Slides
News:
The 21st Show
Beyond Bot Detection: Combating Fraudulent Online Survey Takers
, , , , ,
The ACM Web Conference, 2022
PDF
News:
The Transmitter
On the Forensic Validity of Approximated Audit Logs
, , , , ,
36th Annual Computer Security Applications Conference, 2020
PDF
Talk
Slides
The documents listed here are available for downloading and have been provided as a means to ensure timely dissemination of scholarly and technical work on a noncommercial basis. Copyright and all rights therein are maintained by the authors or by other copyright holders, notwithstanding that they have offered their works here electronically. It is understood that all persons copying this information will adhere to the terms and constraints invoked by each author’s copyright. These works may not be re-posted without the explicit permission of the copyright holder.