6.2CRMay 4
Towards a Risk-Cost Model for Financial Adaptive AuthenticationSupriya Khadka, Sanchari Das
Authentication in financial systems remains a uniquely high-stakes security challenge, where even marginal increases in false acceptance can result in catastrophic monetary loss. Existing deployments of adaptive authentication, which combine biometrics, behavioral signals, and contextual risk scoring, remain conceptually fragmented and often prioritize regulatory compliance over explicit economic and adversarial risk modeling. To address this structural imbalance, in this paper we introduce a formal Risk-Cost Model (RCM) for adaptive authentication in financial systems. The RCM provides a principled mathematical foundation that integrates three essential components: (i) cost-sensitive risk functions that explicitly capture fraud loss, opportunity cost, and tail risk through Conditional Value-at-Risk (CVaR); (ii) sequential decision-making mechanisms that adapt to adversarial probing and distributional drift; and (iii) quantifiable privacy and regulatory constraints embedded directly within the optimization objective. By reframing authentication as a constrained dynamic risk-cost optimization problem, the RCM moves beyond static classification and compliance-driven design toward systems that are economically grounded, tail-risk aware, and resilient under adversarial uncertainty.
4.1LGMay 23, 2025
POSTER: A Multi-Signal Model for Detecting Evasive SmishingShaghayegh Hosseinpour, Sanchari Das
Smishing, or SMS-based phishing, poses an increasing threat to mobile users by mimicking legitimate communications through culturally adapted, concise, and deceptive messages, which can result in the loss of sensitive data or financial resources. In such, we present a multi-channel smishing detection model that combines country-specific semantic tagging, structural pattern tagging, character-level stylistic cues, and contextual phrase embeddings. We curated and relabeled over 84,000 messages across five datasets, including 24,086 smishing samples. Our unified architecture achieves 97.89% accuracy, an F1 score of 0.963, and an AUC of 99.73%, outperforming single-stream models by capturing diverse linguistic and structural cues. This work demonstrates the effectiveness of multi-signal learning in robust and region-aware phishing.
3.8CRMar 25, 2021
Location Data and COVID-19 Contact Tracing: How Data Privacy Regulations and Cell Service Providers Work In TandemCallie Monroe, Faiza Tazi, Sanchari Das
Governments, Healthcare, and Private Organizations in the global scale have been using digital tracking to keep COVID-19 outbreaks under control. Although this method could limit pandemic contagion, it raises significant concerns about user privacy. Known as ~"Contact Tracing Apps", these mobile applications are facilitated by Cellphone Service Providers (CSPs), who enable the spatial and temporal real-time user tracking. Accordingly, it might be speculated that CSPs collect information violating the privacy policies such as GDPR, CCPA, and others. To further clarify, we conducted an in-depth analysis comparing privacy legislations with the real-world practices adapted by CSPs. We found that three of the regulations (GDPR, COPPA, and CCPA) analyzed defined mobile location data as private information, and two (T-Mobile US, Boost Mobile) of the five CSPs that were analyzed did not comply with the COPPA regulation. Our results are crucial in view of the threat these violations represent, especially when it comes to children's data. As such proper security and privacy auditing is necessary to curtail such violations. We conclude by providing actionable recommendations to address concerns and provide privacy-preserving monitoring of the COVID-19 spread through the contact tracing applications.
8.8CRJan 18, 2021
Panel: Humans and Technology for Inclusive Privacy and SecuritySanchari Das, Robert S. Gutzwiller, Rod D. Roscoe et al.
Computer security and user privacy are critical issues and concerns in the digital era due to both increasing users and threats to their data. Separate issues arise between generic cybersecurity guidance (i.e., protect all user data from malicious threats) and the individualistic approach of privacy (i.e., specific to users and dependent on user needs and risk perceptions). Research has shown that several security- and privacy-focused vulnerabilities are technological (e.g., software bugs (Streiff, Kenny, Das, Leeth, & Camp, 2018), insecure authentication (Das, Wang, Tingle, & Camp, 2019)), or behavioral (e.g., sharing passwords (Das, Dingman, & Camp, 2018); and compliance (Das, Dev, & Srinivasan, 2018) (Dev, Das, Rashidi, & Camp, 2019)). This panel proposal addresses a third category of sociotechnical vulnerabilities that can and sometimes do arise from non-inclusive design of security and privacy. In this panel, we will address users' needs and desires for privacy. The panel will engage in in-depth discussions about value-sensitive design while focusing on potentially vulnerable populations, such as older adults, teens, persons with disabilities, and others who are not typically emphasized in general security and privacy concerns. Human factors have a stake in and ability to facilitate improvements in these areas.
3.3SIAug 7, 2020
Change-Point Analysis of Cyberbullying-Related Twitter Discussions During COVID-19Sanchari Das, Andrew Kim, Sayar Karmakar
Due to the outbreak of COVID-19, users are increasingly turning to online services. An increase in social media usage has also been observed, leading to the suspicion that this has also raised cyberbullying. In this initial work, we explore the possibility of an increase in cyberbullying incidents due to the pandemic and high social media usage. To evaluate this trend, we collected 454,046 cyberbullying-related public tweets posted between January 1st, 2020 -- June 7th, 2020. We summarize the tweets containing multiple keywords into their daily counts. Our analysis showed the existence of at most one statistically significant changepoint for most of these keywords, which were primarily located around the end of March. Almost all these changepoint time-locations can be attributed to COVID-19, which substantiates our initial hypothesis of an increase in cyberbullying through analysis of discussions over Twitter.
1.2CYJul 26, 2020
Substituting Restorative Benefits of Being Outdoors through Interactive Augmented Spatial SoundscapesSwapna Joshi, Kostas Stavrianakis, Sanchari Das
Geriatric depression is a common mental health condition affecting majority of older adults in the US. As per Attention Restoration Theory (ART), participation in outdoor activities is known to reduce depression and provide restorative benefits. However, many older adults, who suffer from depression, especially those who receive care in organizational settings, have less access to sensory experiences of the outdoor natural environment. This is often due to their physical or cognitive limitations and from lack of organizational resources to support outdoor activities. To address this, we plan to study how technology can bring the restorative benefits of outdoors to the indoor environments through augmented spatial natural soundscapes. Thus, we propose an interview and observation-based study at an assisted living facility to evaluate how augmented soundscapes substitute for outdoor restorative, social, and experiential benefits. We aim to integrate these findings into a minimally intrusive and intuitive design of an interactive augmented soundscape, for indoor organizational care settings.
13.6CRJul 22, 2020
Towards Secure and Usable Authentication for Augmented and Virtual Reality Head-Mounted DisplaysReyhan Duezguen, Peter Mayer, Sanchari Das et al.
Immersive technologies, including augmented and virtual reality (AR & VR) devices, have enhanced digital communication along with a considerable increase in digital threats. Thus, authentication becomes critical in AR & VR technology, particularly in shared spaces. In this paper, we propose applying the ZeTA protocol that allows secure authentication even in shared spaces for the AR & VR context. We explain how it can be used with the available interaction methods provided by Head-Mounted Displays. In future work, our research goal is to evaluate different designs of ZeTA (e.g., interaction modes) concerning their usability and users' risk perception regarding their security - while using a cross-cultural approach.
2.9CRJun 29, 2020
Quantifying Susceptibility to Spear Phishing in a High School Environment Using Signal Detection TheoryPloy Unchit, Sanchari Das, Andrew Kim et al.
Spear phishing is a deceptive attack that uses social engineering to obtain confidential information through targeted victimization. It is distinguished by its use of social cues and personalized information to target specific victims. Previous work on resilience to spear phishing has focused on convenience samples, with a disproportionate focus on students. In contrast, here, we report on an evaluation of a high school community. We engaged 57 high school students and faculty members (12 high school students, 45 staff members) as participants in research utilizing signal detection theory (SDT). Through scenario-based analysis, participants tasked with distinguishing phishing emails from authentic emails. The results revealed an overconfidence bias in self-detection from the participants, regardless of their technical background. These findings are critical for evaluating the decision-making of underrepresented populations and protecting people from potential spear phishing attacks by examining human susceptibility.
2.9CRJun 16, 2020
Bayesian Evaluation of User App Choices in the Presence of Risk Communication on Android DevicesBehnood Momenzadeh, Shakthidhar Gopavaram, Sanchari Das et al.
In the age of ubiquitous technologies, security- and privacy-focused choices have turned out to be a significant concern for individuals and organizations. Risks of such pervasive technologies are extensive and often misaligned with user risk perception, thus failing to help users in taking privacy-aware decisions. Researchers usually try to find solutions for coherently extending trust into our often inscrutable electronic networked environment. To enable security- and privacy-focused decision-making, we mainly focused on the realm of the mobile marketplace, examining how risk indicators can help people choose more secure and privacy-preserving apps. We performed a naturalistic experiment with N=60 participants, where we asked them to select applications on Android tablets with accurate real-time marketplace data. We found that, in aggregate, app selections changed to be more risk-averse in the presence of user risk-perception-aligned visual indicators. Our study design and research propose practical and usable interactions that enable more informed, risk-aware comparisons for individuals during app selections. We include an explicit argument for the role of human decision-making during app selection, beyond the current trend of using machine learning to automate privacy preferences after selection during run-time.
8.3CRAug 16, 2019
MFA is a Waste of Time! Understanding Negative Connotation Towards MFA Applications via User Generated ContentSanchari Das, Bingxing Wang, L. Jean Camp
Traditional single-factor authentication possesses several critical security vulnerabilities due to single-point failure feature. Multi-factor authentication (MFA), intends to enhance security by providing additional verification steps. However, in practical deployment, users often experience dissatisfaction while using MFA, which leads to non-adoption. In order to understand the current design and usability issues with MFA, we analyze aggregated user generated comments (N = 12,500) about application-based MFA tools from major distributors, such as, Amazon, Google Play, Apple App Store, and others. While some users acknowledge the security benefits of MFA, majority of them still faced problems with initial configuration, system design understanding, limited device compatibility, and risk trade-offs leading to non-adoption of MFA. Based on these results, we provide actionable recommendations in technological design, initial training, and risk communication to improve the adoption and user experience of MFA.
9.7CRAug 16, 2019
Evaluating User Perception of Multi-Factor Authentication: A Systematic ReviewSanchari Das, Bingxing Wang, Zachary Tingle et al.
Security vulnerabilities of traditional single factor authentication has become a major concern for security practitioners and researchers. To mitigate single point failures, new and technologically advanced Multi-Factor Authentication (MFA) tools have been developed as security solutions. However, the usability and adoption of such tools have raised concerns. An obvious solution can be viewed as conducting user studies to create more user-friendly MFA tools. To learn more, we performed a systematic literature review of recently published academic papers (N = 623) that primarily focused on MFA technologies. While majority of these papers (m = 300) proposed new MFA tools, only 9.1% of papers performed any user evaluation research. Our meta-analysis of user focused studies (n = 57) showed that researchers found lower adoption rate to be inevitable for MFAs, while avoidance was pervasive among mandatory use. Furthermore, we noted several reporting and methodological discrepancies in the user focused studies. We identified trends in participant recruitment that is indicative of demographic biases.
13.0CRAug 16, 2019
All About Phishing: Exploring User Research through a Systematic Literature ReviewSanchari Das, Andrew Kim, Zachary Tingle et al.
Phishing is a well-known cybersecurity attack that has rapidly increased in recent years. It poses legitimate risks to businesses, government agencies, and all users due to sensitive data breaches, subsequent financial and productivity losses, and social and personal inconvenience. Often, these attacks use social engineering techniques to deceive end-users, indicating the importance of user-focused studies to help prevent future attacks. We provide a detailed overview of phishing research that has focused on users by conducting a systematic literature review of peer-reviewed academic papers published in ACM Digital Library. Although published work on phishing appears in this data set as early as 2004, we found that of the total number of papers on phishing (N = 367) only 13.9% (n = 51) focus on users by employing user study methodologies such as interviews, surveys, and in-lab studies. Even within this small subset of papers, we note a striking lack of attention to reporting important information about methods and participants (e.g., the number and nature of participants), along with crucial recruitment biases in some of the research.