Symposium on Usable Privacy and Security (SOUPS 2026) - Day 2

Welcome to the Symposium on Usable Security and Privacy happening in Hannover, Germany and being hosted by CISPA.

Blog posts:

Session 1: Privacy Notices, Permissions & Labels

How Effective are Privacy Labels at Informing Users About App Data Handling Practices?

Presenter: Sophia Walsh, University of Bristol

Do the short data notices on app stores properly inform users?

The study looks at users ability to understand the labels in app store notices. They used a card matching approach where they gave users popular apps on one set of cards and a print-out of the short privacy notice icons on another. They then asked the participants to try and match the two sets while doing a think aloud.

Unsupprisingly, they find that users do not know how to map the permissions information to the features that exist in apps. They also find that the information can be overwhelming and causes users to give up.

I don’t know what I’ve all granted. Does it really matter? – Understanding Users’ Awareness of Different Permission Types on Android

Presenter: Verena Winterhalter, LMU Munich

More than 372 apps installed on a given phone.

Each of these apps has permissions that control how it can collect and use user data. Users’ awareness of these permissions is poor to start with and can get worse with time since permissions can change over time.

Studied users understandings of what permissions that the user has installed and uses.

Recommends:

  • Focus on permissions where user has agency
  • Improve visabiliity & reviwability of installtime permissions
  • App usage recency as indicator for suggesting app deletion
  • Different intervention approach per type of misconception

Nudging Developers Toward Privacy: Evaluating the Impact of Personalized App Review Reports

Presenter: Nina Taft, Google

It can be challenging for developers who are building an app to get privacy right. They use libraries, but may not know what those libraries do. But users sometimes have allot to say about the topic in reviews.

This project attempts to give developers personalized reports about their app.

Study is multi-stage. Stage-1: survey of developers about their concerns, privacy perceptions, and odds of taking action. Stage-2: showed them a personalized privacy report. Stage-3: measured their understanding.

The report:

  • Top 3 privacy concerns from their users’ reviews
  • Focused on one of those concerns, showed them Volume and Trends
  • Peer benchmark - compared their app to their peers
  • Emotions - emotion words

Studied people who work in the privacy field, or at least someone who can make decisions involving the privacy design of the app.

Asked developers about the approaches they have for lookimg at their own reviews, particularly privacy-related. Some read the 1 star reviews. Some have software that reads and summarizes reviews, though not specifically for privacy.

76% of respondants found it useful. The remaining 24% had a “I already knew that” response. 69% say that they are likely to do something about the user concerns after seeing the report.

Session 2: Security Operations & Practitioners

Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit

Presenter: Souradip Nath

Looking at how security operations are using LLMs. The reasearch used Reddit to understand usagage. Used mix of Qualtiative and Quantitative.

The AI vender landscape is wide and growing. But awareness of them are fragmented.

Security focused LLMs integrated with Triage and Response while general purpose were more for code writing.

There was a large amount of range in autonomy granted to the agents.

Developers are finding LLMs to be very helpful in doing things like digging through logs and alerts. Agentic AI, in particular, was seen as valuable to find information and quickly answer questions like “does this log line happen every time a user logs in, or is this a new alert?” That said, they were concerned about the accuracy of the tools.

Lots of concerns about how much agency should be given to the tools. The costs of the tools also came up as a serious issue, equating the costs to things like a full time employee salary.

The Impact of Emerging AI Practices on the Cybersecurity Workforce

Presenter: Miuyin Yong Wong, University of Maryland

Are LLMs making people more efficient? Are they benefiting productivity of cybersecurity professionals? This field particuarly susceptible to burnout.

RQs (terse version):

  • What policies and guidance for LLMs are organizations providing
  • What challenges and risks when using LLMs
  • How do peer perceptions impact views

Conducted interviews 28 participants from 26 organizations spanning 16 job roles.

The current landscape

Quite a range of policies avaiable. Many did not have a policy or had a relaxed or generic policy. A few had very restricted policy, such as not allowing training on local company data. Participants mostly relied on exsisting data loss measures. Most of the burdon for being safe falls on the individual to not do the wrong thing.

Barriers to adoption and mitigations

Issues like data leakage, hallucinations, lack of confidence in promoting skills, and wasting time.

People were also afraid of other people using the AI. Concerns that less experienced people would use the AI poorly, or loose the ability to learn.

“What will others think of me if I use AI?” The cybersecurity community is an open community that shares knowledge, but AI may be changing that. People are worried about what others will think about their AI use which is causing a lack of communication about it.

From Preventive to Reactive: How AI Coding Assistants Transform Developers’ Security Awareness

Presenter: Faisal Haque Bappy, University of Maryland Baltimore County

Did a coding session using thinking aloud. Divided participants based on the date they were trained, before AI, during the AI boom, or were native to AI use. They also did an interview and a post-task reflection.

the good news is that AI ouptputs are treated as reference rather than a final code state. People talked about the AI like a junior collegue, but they also didn’t explicitly make security requirements to the AI.

I See DNS People: DNS Resolver Security, Through Operator Perspectives and Practices

Presenter: Katharina Barlage, LMU Munich

DNS converts human-friendly URLs like “vaniea.com” to an IP address (205.196.221.231) which is where the computer establishes a connection. A successful DNS attack can route traffic to somewhere else. Or it could stop users from visiting the site. Having security on DNS servers is vital, but not universally deployed.

DNS “just works” so no one cares untill there is a problem. So upper management does not give resources. Security is often assumed but not assessed. Uptime is a seroius concern and can outrank security.

Some DNS opperators are buying software to run, and assuming that security is there because it should be. They do not assess. Because everything looks fine there is no percieved need to go adjust things. The danger is also abstract and not seem real because there have not been any DNS incidents that they know of. But if they adjust DNS wrong, everything will break, so the short term risk seems more risky. Turning on security is similar, turning on security seems risky and not worth that risk.

Session: Phishing & Social Engineering

“I didn’t know I would be this excited not to be scammed.” Exploring Emotional and Behavioral Responses During Phishing Attacks

Presenter: Raphael Weidhaas, Aalto University

People are still clicking on phising despite lots of training. There is limited research on how phishing impacts the emotion state of the person who gets the phishing.

Lab study where users were put in an office setting. They were given a set of tasks. After about 45 minutes they were sent a simulated phishing email. It was mildly associated with a task, but had some clear indicators like three ‘o’ on zooom. Followed by an interview.

22 participants identified the phishing, 7 clicked, 8 avoided but didn’t realize it was a phishing. 4 fell for the phishing and entered data. The clickers tended to think they had made an error and were trying to correct it, but did realize that it was a problem. Phished people felt that they had solved the problem and felt positive afterwards.

People who fell for phishing had the most positive emotions. Detectors were the most annoyed.

Anxious and Aware: Examining the Effects of Social Anxiety on Social Engineering Resilience and Vulnerability

Presenter: Martin Dechant, University College London

How does having Social Anxiety impact how people process and think about phishing.

People with social anxiety are worried about situations were they are around large groups of others where they might stand out or be criticised by those peers. 4.7% of children, and 8.3% of adolescents have social anxiety globally.

Asked a group of people about a recent social engineering attack that they had experienced. Scammers exploit trust and desires by creating a sense of familiarity, then manipulating with the promises of materialistic or financial gains. Perpetrators weaponized any shared material. Perpetrators fabricate a crisese or urgent situation.

Studied three scams where participants experienced a scenario as a role play.

  • Job Scam (Trust and Desires)
  • Extortion (Compromising material)
  • Romance Scam (Empathy and Urgency)

Participants did not want to reach out for help due to structural barriers. Social Anxiety people didn’t want to talk about it, they were worried about judgement, assumed that others would laugh.

Scammers used language to give affirmation that the social anxious person craved like “you are great” and “you are amazing”.

Quantifying Risk Perception and Scam Response Among International and Domestic US University Students

Presenter: Elijah Bouma-Sims, Carnegie Mellon University;

International students may be more vulnerable to scams for reasons like: unfamiliarity with US legal, lingustic, and cultural norms, pressures for post-graduation employment.

Surveyed about 1000 international and domestic students from 5 universities. Each person saw a scenario describing a scam from a set of sources like phone call, sms, email. They were also asked about prior scam experience.

Experiences with Digital Scams Post-Incarceration in the U.S.

Presenter: Yael Eiger, University of Washington

Incarcerated people are more commmen than you might realize. It is in the millions. 7.6 millions times a year people are sent to jail because they cannot make bail and must stay there till their case is resolved. More people are Incarcerated than are convited of any crime.

Research looks at how previously Incarcerated people experience scams. The research is interesting in pointing out what it is like to experience all of technology all at once, including setting up accounts. This population is also at great risk from things like parking tickets, which makes scams more scary.

This group also have to register their existance, so they are in public databases which scammers then use.

Session: At risk and vulnerable users

Usability Determines Safety for At-Risk Users: Evaluating Hidden Device Detectors for Intimate Partner Surveillance

Presenter: Akhil Polamarasetty, University College London (UCL)

Trackers are now cheap to obtain, and easy to buy. There are also lots of detectors. Physical dtectors use things like RF Signal Detection, Magnetometer, Lens Detection. There are also mobile apps that do things like scanning wifi and bluetooth.

The researchers did several rounds of testing of various devices, such as testing in an anechoic chapber and dark room to see what the detectors could do in opitmal conditions. Then had users try them in a fake living room.

Users searched the room in two ways:

  • Intuitive: looked for sply-looking objects like clocks
  • Systematic: Divide a room into a grid and looked at most objects. This tactic was more common for people with law enforcement background

Having a physical detector tended to make people feel more vulnerable, even though they were in a safe lab space.

Goals, Risks, and Safety Practices in Online Labor Abuse Disclosures

Presenter: Tarini Saka

Recovery from serious security issues is challenges. Many people turn to online support. But the online communities themselves have minimal security.

This work looks at the context of labor abuse. For this group Human Resource departments, which are the reporting destination, may not help and re-traumitize instead. Instead people try to find groups to communicate with safely about what they can do.

Labor abuse survivers form networks across platforms where they are forming an audience. Compare them to activists who have nation-state abilities. Labor abuse victim face locally powerful adversaries that have financial and direct ability to impact the victim, but they have less ability to impact the technology world.

This is an interview and thematic analysis study.

Many people reached out to understand if their situation was indeedproblematic or if they were just “crazy”. The researchres group into four types of communication groups: feed-based groups, publicly visible threads, Messaging groups, ???

[]“I feel as though my privacy is being violated”: Privacy Risks and Barriers in Instant Messaging for Blind and Low-Vision Users](https://www.usenix.org/conference/soups2026/presentation/akter)

Presenter: Sohana Akter, University of Texas at San Antonio

Instant messsaging is used for a large parts of personal and professional life. The same is true for the Blind and Partially Sighted users.

Blind and low vision people may have further issues like tryingn to understand an image, others might hear a screen reader, and then there are privacy controls….

Just moving a mouse into some spaces can activate things, but a blind user has no way to know that will or has happened. Tags like “last seen” are intended to be seen at a glance, but that is more challenging for partially sighted.

Some information entry is irreversible, which is more challenging when using a screen reader which may not properly explain what information is entered or why.

[]“Don’t Let Them Get To You”: Understanding the Role of TikTok as a Source of Support for Cyberbullying Victims](https://www.usenix.org/conference/soups2026/presentation/iqbal)

Presenter: Daniel Zappala, Brigham Young University, on behalf of Saba Iqbal

Cyberbulling is increasing as a problem in the US.

Prior work shows that sorting through security and privacy advice is challenging and users strugggle to prioritize it.

This work looks at the cyberbulling advice that exists on TicTok and how accurate that advice is.

Looked through lots of TicTok videos and found, that there were roughly 5 categories of advice:

  • Coping strategies
    • Things like: don’t respond, block and report, take a break, comfort the bully
  • Emotional Support
    • Reassuring that bulling is not acceptable, not true, projection of bully insecurities, empower yourself.
  • Mental Health Advice
    • Set boundaries, don’t take it personal, exercise, journaling, get sleep,
  • Spiritual Support
    • Support based on faith things like: Turn the other cheek, god is watching over you,
  • Seeking support
    • Guidance on where to turn to. Like get evidence, contact law enforcement

Survey was then run where asked about experiences, and asked them the rate the content of the videos (text transcription). Rated baed on: comprhensibility, efficacy, actionability.

Most advice was rated as comprehensible. Most advice was considered effective. The spiritual category was rated lower for being helpful. About 1/3 of advice was considered actionable. Confrunting the bully, for example, were not seen as actionable.

Reproductive Security & Privacy Advice on TikTok after the Overturn of Roe

Presenters: Harshini Sri Ramulu and Rachel Gonzalez Rodriguez, Paderborn University

The overturning of Roe vs Wade in the US lead to many women suddenly loosing reproductive care and requests for information about how to protect themselves.

Study looked at TikToc videos that gave advice on protect yourself as a woman in the US. The covered issues like how to not track mentration (delete period tracking apps). There were lots of contradictory advice, such as using apps in Europe or not using apps because they were in Europe. Some advice also suggested creating a fake data.

Kami Vaniea
Kami Vaniea
Associate Professor of Usable Privacy and Security

I research how people interact with cyber security and privacy technology.