* indicates equal contribution.
Operationalizing Welcoming in Cybersecurity Communities: How Organizers Try to Shape Culture
, , , ,
48th IEEE Symposium on Security and Privacy (IEEE S&P), 2027
In Preparation
Do Newer Models Make Better Tutors?: Characterizing Real-World Failures of AI Tutors in Higher Education Across Two Years, Two Prompts, and Five Models
, , , , , ,
58th ACM Technical Symposium on Computer Science Education (SIGCSE TS), 2027
In Preparation
Do Hackers Dream of Electric Teachers?: A Large-Scale, In-Situ Measurement of Cybersecurity Student Behaviors and Educational Performance with AI Tutors
, , , , , , , , , ,
33rd ACM Conference on Computer and Communications Security (CCS), 2026
PDF
"I Thought You Were The Uncensored Place": Norms, Rules, and Moderation in AI-Generated Sexual Content Communities
, ,
9th AAAI/ACM Conference on AI, Ethics, and Society (AIES), 2026
PDF
Website
Is This AI? Longitudinal Analysis of Strategies Used for AI Detection on Two Subreddits
, , ,
9th AAAI/ACM Conference on AI, Ethics, and Society (AIES), 2026
PDF
Website
Press:
The Atlantic
Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit
, , , , ,
22nd Symposium on Usable Privacy and Security (SOUPS), 2026
PDF
SoK: Mapping Threats to Defenses in Online Survey Fraud
, , , , ,
22nd Symposium on Usable Privacy and Security (SOUPS), 2026
PDF
"Unlimited Realm of Exploration and Experimentation": Methods and Motivations of AI-Generated Sexual Content Creators
, ,
9th ACM Conference on Fairness, Accountability, and Transparency (FAccT), 2026
PDF
Website
Poster
Press:
Harvard Berkman Klein Center Whitepaper on Survivor-Centered NCII Reporting,
Lawfare Daily: Consent in the Age of AI
I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery
, , , , , , , ,
44th ACM CHI Conference on Human Factors in Computing Systems (CHI), 2026
PDF
Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
, , , , , , , , , , , , , , , , , , , , , , ,
arXiv, 2025
PDF
Press:
OWASP Agentic AI Security Risk Scoring (AIVSS),
Schmidt Sciences,
Cloud Security Alliance,
Infosecurity Magazine,
Institute for AI Policy and Strategy
SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security Behaviors
, , , , ,
33rd USENIX Security Symposium (USENIX Security), 2024
PDF
Press:
Japan Science and Technology Agency: Center for Research and Development Strategy Report
It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based Bias
, , , , , ,
42nd ACM CHI Conference on Human Factors in Computing Systems (CHI), 2024
PDF
Talk
Press:
Response to NIST RFI on AI Safety, Security, and Synthetic Content
"Security is not my field, I'm a stats guy": A Qualitative Root Cause Analysis of Barriers to Adversarial Machine Learning Defenses in Industry
, , , ,
32nd USENIX Security Symposium (USENIX Security), 2023
PDF
Talk
Poster
Press:
Human-Centered Security Podcast,
Response to NIST RFI on AI Safety, Security, and Synthetic Content
SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions
, , , , , , , ,
44th IEEE Symposium on Security and Privacy (IEEE S&P), 2023
PDF
Everybody's Got ML, Tell Me What Else You Have: Practitioners' Perception of ML-Based Security Tools and Explanations
, , , , , ,
44th IEEE Symposium on Security and Privacy (IEEE S&P), 2023
PDF
Talk
Teaser
Press:
Human-Centered Security Podcast,
Response to NIST RFI on AI Safety, Security, and Synthetic Content
FAuST: Striking a Bargain between Forensic Auditing's Security and Throughput
, , , , , , ,
38th Annual Computer Security Applications Conference (ACSAC), 2022
PDF
DeepPhish: Understanding User Trust Towards Artificially Generated Profiles in Online Social Networks
, , , , ,
31st USENIX Security Symposium (USENIX Security), 2022
PDF
Supplemental Materials
Website
Talk
Press:
Harvard Kennedy School Misinformation Review,
Futurum,
New Scientist,
Response to NIST RFI on AI Safety, Security, and Synthetic Content
Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking Apps
, , , ,
40th ACM CHI Conference on Human Factors in Computing Systems (CHI), 2022
PDF
Supplemental Materials
Talk
Press:
Raidió Teilifís Éireann (RTÉ),
The 21st Show
Beyond Bot Detection: Combating Fraudulent Online Survey Takers
, , , , ,
31st ACM Web Conference (WWW), 2022
PDF
Press:
Prolific Guidance to Prevent AI-Generated Responses,
The Transmitter