USEC 2022 Symposium on Usable Security and Privacy
The Symposium on Usable Security and Privacy (USEC) serves as an international forum for research and discussion in the area of human factors in security and privacy. USEC is a Symposium with proceedings.
USEC 2022 will be held on April 28, 2022 in conjunction with NDSS at the Catamaran Resort Hotel & Spa in San Diego, California.
It is the aim of USEC to contribute to an increase of the scientific quality of research in human factors in security and privacy. To this end, we encourage replication studies to validate previous research findings. Papers in these categories should be clearly marked as such and will not be judged against regular submissions on novelty. Rather, they will be judged based on scientific quality and value to the community. We also encourage reports of faded experiments. They must highlight the lessons learned and provide recommendations on how to avoid falling into the same traps.
Schedule | Details |
---|---|
9:00-9:15 | Opening Remarks |
9:15-10:15 | Keynote by Ross Anderson |
10:15-10:50 | Coffee Break |
10:50-12:10 |
Security Awarness: Session Chair: Aiping Xiong PickMail: A Serious Game for Email Phishing Awareness Training
|
1:40-3:00 |
Emerging Themes: Session Chair: Lea Gröber Explainable AI in Cybersecurity Operations: Lessons Learned from xAI Tool Deployment
|
3:00-3:30 | Coffee Break |
3:30-5:00 |
Privacy: Session Chair: Alena Naiakshina Trust & Privacy Expectations during Perilous Times of Contact Tracing “So I Sold My Soul'': Effects of Dark Patterns in Cookie Notices on End-User Behavior and Perceptions
|
Ross Anderson: "Adversarial Usability: The New Frontier?"
"When we started work on usable security at the turn of the century, we tackled problems for which we thought there might be simple and durable answers. Can people actually use your encryption program safely? What sort of password advice can you give people, and with what results? Could experiments lead us to sound engineering design? But as time passed, we realised that the hackers were not our only adversaries. Banks designed systems so their customers had to write their passwords down, and used that to hold them liable for fraud. Governments produced stupid advice, such as monthly password changes, which audit firms imposed worldwide. Big service firms changed their privacy mechanisms whenever enough of their users figured out how to opt out of surveillance. Usability for developers is another issue, and recent experience with attacks based on coding has some interesting lessons to teach. And as dark patterns proliferate from scammers to regular businesses, the FTC started last year to run workshops on the problem. Research on usable security is lagging research on consumer protection! Yet security economics warns us to analyse not just the perspectives of users, but those of companies and regulators too. The implications are broad. To take just one example, the likely future benefits and harms from machine learning will depend on who controls it, what it's used for, and how easy it is to fix problems. A world where nudge becomes sludge and evolves into smart sludge could be tiresome; and the history of cookie banners suggests that pushing back on adversarial usability by direct regulation may be hard."
Katharina Krombholz, CISPA Helmholtz Center for Information Security
Prashanth Rajivan, University of Washington
Aiping Xiong |
Penn State University |
Alena Naiakshina |
Ruhr-University Bochum |
Diane Staheli |
MIT Lincoln Lab |
Fariza Sabrina |
Central Queensland University |
Hyoungshick Kim |
Sungkyunkwan University |
Imani N. S. Munyaka |
University of California, San Diego |
Josiah Dykstra |
National Security Agency |
Karima Boudaoud |
University of Nice Sophia Antipolis |
Katharina Krombholz |
CISPA Helmholtz Center for Information Security |
Kuldeep Singh |
University of Texas El Paso |
Lea Gröber |
CISPA Helmholtz Center for Information Security |
Leah Zhang-Kennedy |
University of Waterloo |
Matthias Fassl |
CISPA Helmholtz Center for Information Security |
Megan Nyre-Yu |
Sandia National Labs |
David Schuster |
San Jose State University. |
Palvi Aggarwal |
University of Texas El Paso |
Pardis Emami-Naeini |
University of Washington |
Prashanth Rajivan |
University of Washington |
Sanchari Das |
University of Denver |
Simson Garfinkel |
George Washington University |
Varun Dutt |
Applied Cognitive Science Lab, Indian Institute of Technology Mandi, Kamand, Himachal Pradesh, India – 175005 |
Verena Distler |
University of Luxembourg |
|
All submissions must be original work; authors must clearly document any overlap with previously published or simultaneously submitted papers from any of the authors. All papers should be written in English.
Format: The text must be in Times font, 10-point or larger, with 11-point or larger line spacing. Use the NDSS USEC format found at: https://www.ndss-symposium.org/ndss2021/templates/
Paper length: We are looking for submissions of 5 to 10 pages, excluding references and supplementary materials. We encourage authors to submit papers of appropriate length for the research contribution. If your research contribution only requires 5-7 pages, please only submit 5-7 pages (plus references). Shorter papers with be reviewed like any other paper and not penalized. Papers shorter than 5 pages or longer than 10 pages (excluding references) will not be considered.
Submitting supplementary material that adds depth to the contribution and/or contributes to the submission’s replicability is strongly encouraged. Supplemental material must be linked to in the paper in an anonymous way as we cannot support direct upload to the submission system.
Anonymous Submission: Reviewing will be double blind. Author names and affiliations should not appear in the paper. The authors should make a reasonable effort not to reveal their identities or institutional affiliation in the text, figures, photos, links, or other data that is contained in the paper. Authors’ prior work should be preferably referred to in the third person; if this is not feasible, the references should be blinded. Submissions that violate these requirements will be rejected without review. The list of authors cannot be changed after the acceptance decision is made unless approved by the Program Chairs.
Conflict of Interest: Authors and Program Committee members are required to indicate any conflict of interest and its nature. Advisors and those that they are advising, as well as authors and PC members with an institutional relationship are considered to share a conflict of interest. Professional collaborations (irrespective of whether they resulted in publication or funding) that occurred in the past 2 years and close personal relationships equally constitute a conflict of interest. PC members, including chairs, that have a conflict of interest with a paper, will be entirely excluded from the evaluation of that paper.
The submission site is https://usec22.hotcrp.com/