For additional references, please see my Google Scholar or DBLP. Additional activities (such as poster, talks, etc.) can be found on my CV.

View pubs as a bibtex file.

2026

[104]
Shiza Ali, Wellington Esposito Barbosa, Matthias Fassl, Aditi Ganapathi, Jaron Mink and Adam J. Aviv. SoK: Mapping Threats to Defenses in Online Survey Fraud. Twenty-Second Symposium on Usable Privacy and Security (SOUPS'26). August 2026. ()
@inproceedings{ali2026sok,
  author = {Shiza Ali and Wellington Esposito Barbosa and Matthias Fassl and Aditi Ganapathi and Jaron Mink and Adam J. Aviv},
  booktitle = {Twenty-Second Symposium on Usable Privacy and Security},
  series = {SOUPS'26},
  title = {SoK: Mapping Threats to Defenses in Online Survey Fraud},
  year = {2026},
  month = aug,
  url ={https://n0g.at/publications/SoK_Survey_Fraud_SOUPS_2026.pdf}
}
[103]
Arwa Alsahdi, Jialiang Yan, Monica Kodwani, Matthias Fassl, Chris Kanich and Adam J. Aviv. "Because I didn't touch these and even don't know why I should to change these": Why App Developers Do (Not) Update Apple's Privacy Labels. Proceedings on Privacy Enhancing Technologies. Vol. 2026 (4) (PoPETS'26). July 2026. ()
@article{alsahdi2026privacy,
  title   = {"Because I didn't touch these and even don't know why I should to change these": Why App Developers Do (Not) Update Apple's Privacy Labels},
  author  = {Arwa Alsahdi and Jialiang Yan and Monica Kodwani and Matthias Fassl and Chris Kanich and Adam J. Aviv},
  year    = {2026},
  month   = {jul},
  number  = {4},
  volume  = {2026},
  series = {PoPETS'26},
  journal = {Proceedings on Privacy Enhancing Technologies},
  url = {https://petsymposium.org/popets/2026/popets-2026-0151.pdf}
}
[102]
Jan Tolsdorf, Alan F. Luo, Monica Kodwani, Junho Eum, Mahmood Sharif, Michelle L. Mazurek and Adam J. Aviv. How Probing for Problems and Bias Affects Perceptions of AI Chatbot Trustworthiness. Proceedings of the 2026 ACM Conference on Fairness, Accountability, and Transparency (FAccT '26). Pgs. 4342–4374. May 2026. (doi) ()
@inproceedings{tolsdorf2026probing,
 author = {Tolsdorf, Jan and Luo, Alan F. and Kodwani, Monica and Eum, Junho and Sharif, Mahmood and Mazurek, Michelle L. and Aviv, Adam J.},
title = {How Probing for Problems and Bias Affects Perceptions of AI Chatbot Trustworthiness},
year = {2026},
isbn = {9798400725968},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3805689.3806751},
doi = {10.1145/3805689.3806751},
abstract = {The rapid adoption of generative AI chatbots has intensified discussions around “trustworthy AI.” Understanding how lay users perceive and evaluate chatbot trustworthiness is essential to keeping these discussions inclusive, making formal assessments user-centered, and revealing instances of misplaced user trust. To this end, we conducted an interactive online study with 254 U.S.-based participants who were asked to investigate whether a generative AI chatbot produced problematic, questionable, or unfair responses. Using a researcher-supplied probing tool, participants could freely interact with the chatbot and flag any issues. Participants engaged in 551 open-ended conversations and primarily sought to probe for issues and topics related to their everyday use. However, participants frequently failed to uncover the issues they expected to find. Overall, trustworthiness perceptions increased after the probing intervention, regardless of whether issues were detected, and participants with higher initial trustworthiness were less likely to flag problems in general. Our findings suggest that lay users may have the right instincts about concerns with generative AI, but are not well equipped to surface these issues on their own. We also find that trustworthiness perceptions can increase rapidly, even among initially skeptical users, likely driven by users' tendency to treat outputs as deliberate and reasoned rather than probabilistic, and by their reliance on surface cues—particularly performance and utility—when judging trustworthiness. Our work complements prior work by illuminating how everyday users assess trustworthiness in generative AI, broadening debates on trustworthy AI, and highlighting the need for stronger guidance to help lay users accurately assess and calibrate trustworthiness.},
booktitle = {Proceedings of the 2026 ACM Conference on Fairness, Accountability, and Transparency},
pages = {4342–4374},
numpages = {33},
keywords = {Generative AI, Chatbots, Trustworthiness, Mixed-Methods, User Study},
location = {
},
series = {FAccT '26},
month = may
}
[101]
Alan F. Luo, Miuyin Yong Wong, Adam J. Aviv and Michelle L. Mazurek. Small Business Adoption of Gen-AI Services. 10th Workshop on Technology and Consumer Protection (ConPro'26). May 2026. ()
@inproceedings{luo2026smallbusiness,
  author = {Alan F. Luo and Miuyin Yong Wong and Adam J. Aviv and Michelle L. Mazurek},
  title = {Small Business Adoption of Gen-AI Services},
  booktitle = { 10th Workshop on Technology and Consumer Protection},
  series= {ConPro'26},
  year = {2026},
  month = may,
  url = {https://conpro26.ieee-security.org/papers/luo-conpro26.pdf}
}
[100]
Adryana Hutchinson, Elaine Ly, Collins W. Munyendo and Adam J Aviv. Re-Examining the Examiners: Changes in Privacy and Security Perceptions of Exam Proctoring. Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems (CHI '26). April 2026. (doi) ()
@inproceedings{hutchinson2026reexamining,
author = {Hutchinson, Adryana and Ly, Elaine and Munyendo, Collins W. and Aviv, Adam J},
title = {Re-Examining the Examiners: Changes in Privacy and Security Perceptions of Exam Proctoring},
year = {2026},
isbn = {9798400722783},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3772318.3790794},
doi = {10.1145/3772318.3790794},
abstract = {With the shift to remote learning during the COVID-19 pandemic, educators turned to remote exam proctoring software to support integrity for online tests. However, due to the mechanisms used to surveil test-takers, these systems come with significant privacy and security tradeoffs. At the height of the pandemic, Balash et al. (SOUPS ’21) found that test-takers had privacy concerns with remote proctoring but acquiesced due to a number of factors. We investigate how perceptions have changed four years later. To gain a fuller perspective on how users experience these tools now, we replicate Balash et al.’s study with 127 participants who have experienced exam proctoring. We found a significant shift in favor of proctoring software, with greater acceptance of all monitoring methods compared to 2020. This is likely due to the convenience of remote exams and a growing resignation to privacy trade-offs. We discuss these implications and suggest future directions.},
booktitle = {Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems},
articleno = {1211},
numpages = {19},
location = {
},
series = {CHI '26},
month = apr
}
[99]
Mindy Tran, Xinru Tang, Adryana Hutchinson, Adam J. Aviv and Yixin Zou. Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview Study. IEEE Symposium on Security and Privacy (SP'26). may doi=10.1109/SP63933.2026.00027 2026. ()
@inproceedings{Tran2026toward,
  author = { Mindy Tran and Xinru Tang and Adryana Hutchinson and Adam J. Aviv and Yixin Zou},
  booktitle = {IEEE Symposium on Security and Privacy},
  series= {SP'26},
  title = {Toward Inclusive Security and Privacy for Deaf and Hard-of-Hearing People: A Community-Based Interview Study},
  year = {2026},
  url   = {https://yixinzou.github.io/publications/pdf/sp2026-tran-preprint.pdf},
  month = may
  doi={10.1109/SP63933.2026.00027}}

2025

[98]
Jan Tolsdorfand Alan F. Luo, Monica Kodwani, Junho Eum, Mahmood Sharif, Michelle L. Mazurek and Adam J. Aviv. Safety Perceptions of Generative AI Conversational Agents: Uncovering Perceptual Differences in Trust, Risk, and Fairness. Twenty-First Symposium on Usable Privacy and Security (SOUPS'25). August 2025. ()
@inproceedings{tolsdorf2025safety,
  author = {Jan Tolsdorfand Alan F. Luo and Monica Kodwani and Junho Eum and Mahmood Sharif and Michelle L. Mazurek and Adam J. Aviv},
  booktitle = {Twenty-First Symposium on Usable Privacy and Security},
  series= {SOUPS'25},
  title = {Safety Perceptions of Generative AI Conversational Agents: Uncovering Perceptual Differences in Trust, Risk, and Fairness},
  year = {2025},
  url={https://www.usenix.org/conference/soups2025/presentation/tolsdorf},
  month = aug
}
[97]
Kavous Salehzadeh Niksirat, Collins W. Munyendo, Onicio Batista Leal Neto, Ms Muswagha Katya, Cyrille Kouassi, Kevin Ochieng, Angoa Georgina, Bernard Olayo, Jean-Philippe Barra, Ciro Cattuto, Adam J. Aviv and Carmela Troncoso. Reimagining Wearable-Based Digital Contact Tracing: Insights from Kenya and Côte d’Ivoire. ACM Conference on Human Factors in Computing Systems. (CHI'25). May 2025. (doi) ()
@inproceedings{nisrat2025reimagining,
  author = {Kavous Salehzadeh Niksirat and Collins W. Munyendo and Onicio Batista Leal Neto and Ms Muswagha Katya and Cyrille Kouassi and Kevin Ochieng and Angoa Georgina and Bernard Olayo and Jean-Philippe Barra and Ciro Cattuto and Adam J. Aviv and Carmela Troncoso},
  booktitle = {ACM Conference on Human Factors in Computing Systems.},
  series = {CHI'25},
  title = {Reimagining Wearable-Based Digital Contact Tracing: Insights from Kenya and Côte d’Ivoire},
  year = {2025},
  month = may,
  doi={10.1145/3706598.3713817}
}
[96]
Elisa Shioji, Ani Meliksetyan, Lucy Simko, Ryan Watkins, Adam J. Aviv and Shaanan Cohney. It's been lovely watching you": Institutional Decision-Making on Online Proctoring Software. IEEE Symposium on Security and Privacy (SP'25). May 2025. (doi) ()
@inproceedings{shioji2025itsbeenlovely,
  author = {Elisa Shioji and Ani Meliksetyan and Lucy Simko and Ryan Watkins and  Adam J. Aviv and Shaanan Cohney},
  title = {It's been lovely watching you'': Institutional Decision-Making on Online Proctoring Software},
  booktitle = {IEEE Symposium on Security and Privacy},
  series = {SP'25},
  year = {2025},
  month = may,
  url={https://www.computer.org/csdl/proceedings-article/sp/2025/223600a018/21B7Q9z8UV2},
  doi={10.1109/SP61157.2025.00018}
}
[95]
Collins W. Munyendo, Kentrell Owens, Faith Strong, Shaoqi Wang, Adam J. Aviv, Tadayoshi Kohno and Franziska Roesner. "You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp Mods. IEEE Symposium on Security and Privacy (SP'25). May 2025. (doi) ()
@inproceedings{munyendo2025youhaveto,
author = {Collins W. Munyendo and Kentrell Owens and Faith Strong and Shaoqi Wang and Adam J. Aviv and  Tadayoshi Kohno and Franziska Roesner},
title = {"You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp Mods},
booktitle = {IEEE Symposium on Security and Privacy},
series = {SP'25},
year = {2025},
month = may,
url={https://www.computer.org/csdl/proceedings-article/sp/2025/223600a087/21Tfery3gcM},
doi={10.1109/SP61157.2025.00087}
}
[94]
Jan Tolsdorf, Alan F. Luo, Monica Kodwani, Junho Eum, Mahmood Sharif, Michelle L. Mazurek and Adam J. Aviv. On a Scale of 1 to 5, How Reliable Are AI User Studies? A Call for Developing Validated, Meaningful Scales and Metrics about User Perceptions of AI Systems. 9th Workshop on Technology and Consumer Protection (ConPro'25). May 2025. ()
@inproceedings{tolsdorf2025onascale,
  author = {Jan Tolsdorf and Alan F. Luo and Monica Kodwani and Junho Eum and Mahmood Sharif and Michelle L. Mazurek and Adam J. Aviv},
  title = {On a Scale of 1 to 5, How Reliable Are AI User Studies? A Call for Developing Validated, Meaningful Scales and Metrics about User Perceptions of AI Systems},
  booktitle = { 9th Workshop on Technology and Consumer Protection},
  series= {ConPro'25},
  year = {2025},
  url= {https://conpro25.ieee-security.org/papers/tolsdorf-conpro25.pdf},
  month = may,
}
[93]
Neal Keating, Wellington Esposito Barbosa, Leo Phan, Viraj Prakash, Gianluca Stringhini and Adam J. Aviv. Mirror Mirror on the Wall, which APK Mirror Site is the Largest of Them All?. Proceedings of the 2025 ACM Internet Measurement Conference (IMC '25). Pgs. 963–969. 2025. (doi) ()
@inproceedings{keating2025mirror,
author = {Keating, Neal and Barbosa, Wellington Esposito and Phan, Leo and Prakash, Viraj and Stringhini, Gianluca and Aviv, Adam J.},
title = {Mirror Mirror on the Wall, which APK Mirror Site is the Largest of Them All?},
year = {2025},
isbn = {9798400718601},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3730567.3764499},
doi = {10.1145/3730567.3764499},
abstract = {Android apps or Android Application Packages (APKs) are commonly distributed through official app stores, but a significant parallel ecosystem of APK mirror sites has emerged, providing users with alternative access to APK packages. These mirror sites host APKs for direct download and sideloading, bypassing security checks typical of official stores and offering access to packages otherwise unavailable to some users. Despite their growing prominence, academic researchers have underexplored the APK mirror ecosystem. In this paper, we analyzed metadata from over 34M versions of approximately 27M unique Android packages collected from seven prominent APK mirror sites, alongside data from the Google Play Store and Amazon Appstore for comparison. Our findings reveal substantial variation in catalog size and package versioning across mirror sites. The smallest, APK Mirror, has only 17K packages while the largest, APK Combo, hosts over 12M packages, compared to Google Play Store's 3.1M packages, at the time of measurement. Mirror sites differ markedly from official stores in both breadth - hosting more unique packages - and depth - retaining multiple package versions, often serving as semi-historical archives. This offers a potentially rich record for researchers to access.},
booktitle = {Proceedings of the 2025 ACM Internet Measurement Conference},
pages = {963–969},
numpages = {7},
keywords = {mirror sites, apk repositories, android, metadata},
location = {USA},
series = {IMC '25}
}
[92]
Wentao Guo, Paige Pepito, Adam J. Aviv and Michelle L. Mazurek. How Researchers De-identify Data in Practice. The 34th USENIX Security Symposium (Sec'25). 2025. ()
@inproceedings{guo2025howresearchers,
  author = {Wentao Guo and Paige Pepito and Adam J. Aviv and Michelle L. Mazurek},
  booktitle = {The 34th USENIX Security Symposium},
  series = {Sec'25},
  title = {How Researchers De-identify Data in Practice},
  year = {2025},
  url={https://www.usenix.org/conference/usenixsecurity25/presentation/guo-wentao}
  month = aug
}

2024

[91]
Elena Korkes, Collins W. Munyendo, Alvin Isaac, Victoria Hennemann and Adam J. Aviv. "I'm going to try her birthday": Investigating How Friends Guess Each Other's Smartphone Unlock PINs in the Lab. 2024 European Symposium on Usable Security (EuroUSEC'24). October 2024. ()
@inproceedings{korkes2024birthday,
  author = {Elena Korkes and Collins W. Munyendo and Alvin Isaac and Victoria Hennemann and Adam J. Aviv },
  booktitle = {2024 European Symposium on Usable Security},
  series = {EuroUSEC'24},
  title = {"I'm going to try her birthday": Investigating How Friends Guess Each Other's Smartphone Unlock PINs in the Lab},
  year = {2024},
  month = oct,
  url = {https://eurousec24.kau.se/pre-proceedings/15.pdf}
}
[90]
Wentao Guo, Aditya Kishore, Adam J. Aviv and Michelle L. Mazurek. A Qualitative Analysis of Practical De-identification Guides. The ACM Conference on Computer and Communication Security (CCS'24). October 2024. ()
@inproceedings{guo2024qualitative,
  author    = {Wentao Guo and Aditya Kishore and Adam J. Aviv and Michelle L. Mazurek},
  title     = {A Qualitative Analysis of Practical De-identification Guides},
  booktitle = {The ACM Conference on Computer and Communication Security},
  series    = {CCS'24},
  year      = {2024},
  url      = {https://dl.acm.org/doi/10.1145/3658644.3690270},
  month     = oct
}
[89]
Lucy Simko, Adryana Hutchinson, Alvin Isaac, Evan Fries, Micah Sherr and Adam J. Aviv. "Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring Evasion. The ACM Conference on Computer and Communication Security (CCS'24). October 2024. ()
@inproceedings{simko2024modern,
  author    = {Lucy Simko and Adryana Hutchinson and Alvin Isaac and Evan Fries and Micah Sherr and Adam J. Aviv},
  title     = {"Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring Evasion},
  booktitle = {The ACM Conference on Computer and Communication Security},
  series    = {CCS'24},
  year      = {2024},
  url      = {https://dl.acm.org/doi/10.1145/3658644.3691638},
  month     = oct
}
[88]
Yixin Zou, Khue Le, Peter Mayer, Alessandro Acquisti, Adam J. Aviv and Florian Schaub. Encouraging Users to Change Breached Passwords Using the Protection Motivation Theory. ACM Trans. Comput.-Hum. Interact. Association for Computing Machinery. August 2024. (doi) ()
@article{zou2024Encourgin,
  author    = {Zou, Yixin and Le, Khue and Mayer, Peter and Acquisti, Alessandro and Aviv, Adam J. and Schaub, Florian},
  title     = {Encouraging Users to Change Breached Passwords Using the Protection Motivation Theory},
  year      = {2024},
  publisher = {Association for Computing Machinery},
  address   = {New York, NY, USA},
  issn      = {1073-0516},
  url       = {https://doi.org/10.1145/3689432},
  doi       = {10.1145/3689432},
  note      = {Just Accepted},
  journal   = {ACM Trans. Comput.-Hum. Interact.},
  month     = {aug},  
}
[87]
David G. Balash, Mir Masood Ali, Chris Kanich and Adam J. Aviv. "I would not install an app with this label": Privacy Label Impact on Risk Perception and Willingness to Install iOS Apps. Twentieth Symposium on Usable Privacy and Security (SOUPS 2024). Pgs. 413–432. August 2024. ()
@inproceedings{balash2024wouldnotinstall,
  author    = {David G. Balash and Mir Masood Ali and Chris Kanich and Adam J. Aviv},
  title     = {"I would not install an app with this label": Privacy Label Impact on Risk Perception and Willingness to Install {iOS} Apps},
  booktitle = {Twentieth Symposium on Usable Privacy and Security (SOUPS 2024)},
  year      = {2024},
  isbn      = {978-1-939133-42-7},
  address   = {Philadelphia, PA},
  pages     = {413--432},
  url       = {https://www.usenix.org/conference/soups2024/presentation/balash},
  publisher = {USENIX Association},
  month     = aug
}
[86]
Mir Masood Ali, David G. Balash, Monica Kodwani, Chris Kanich and Adam J. Aviv. Honesty is the Best Policy: On the Accuracy of Apple Privacy Labels Compared to Apps' Privacy Policies. Proceedings of Privacy Enhancing Technologies. Vol. 2024 (4). Pgs. 142-166 (PoPETS'24). July 2024. (arxiv) (pdf) (doi) ()
@article{ali2023honesty,
  title   = {Honesty is the Best Policy: On the Accuracy of Apple Privacy Labels Compared to Apps' Privacy Policies},
  author  = {Mir Masood Ali and David G. Balash and Monica Kodwani and Chris Kanich and Adam J. Aviv},
  year    = {2024},
  month   = {jul},
  number  = {4},
  volume  = {2024},
  pages   = {142-166},
  journal = {Proceedings of Privacy Enhancing Technologies},
  arxiv   = {https://arxiv.org/abs/2306.17063},
  series  = {PoPETS'24},
  url     = {https://petsymposium.org/popets/2024/popets-2024-0111.php},
  doi     = {https://doi.org/10.56553/popets-2024-0111},
  pdf     = {https://petsymposium.org/popets/2024/popets-2024-0111.pdf}
}
[85]
Florian M. Farke, David G. Balash, Maximilian Golla and Adam J. Aviv. How Does Connecting Online Activities to Advertising Inferences Impact Privacy Perceptions?. Proceedings of Privacy Enhancing Technologies. Vol. 2024 (2). Pgs. 372-390 (PoPETS'24). July 2024. (arxiv) (pdf) (doi) ()
@article{farke2023does,
  title   = {How Does Connecting Online Activities to Advertising Inferences Impact Privacy Perceptions?},
  author  = {Florian M. Farke and David G. Balash and Maximilian Golla and Adam J. Aviv},
  year    = {2024},
  month   = jul,
  number  = {2},
  volume  = {2024},
  pages   = {372-390},
  journal = {Proceedings of Privacy Enhancing Technologies},
  arxiv   = {https://arxiv.org/abs/2312.13813},
  series  = {PoPETS'24},
  url     = {https://petsymposium.org/popets/2024/popets-2024-0055.php},
  doi     = {https://doi.org/10.56553/popets-2024-0055},
  pdf     = {https://petsymposium.org/popets/2024/popets-2024-0055.pdf}
}
[84]
Mindy Tran, Xinru Tang And Adryana Hutchinson, Adam J. Aviv and Yixin Zou. Position Paper: Exploring Security and Privacy Needs of d/Deaf Individuals. First Workshop on Accessible Security Privacy (WASP). July 2024. ()
@inproceedings{tran2024exploring,
  author    = {Mindy Tran and Xinru Tang And Adryana Hutchinson and Adam J. Aviv and Yixin Zou},
  booktitle = {First Workshop on Accessible Security & Privacy},
  series    = {WASP},
  title     = {Position Paper: Exploring Security and Privacy Needs of d/Deaf Individuals},
  year      = {2024},
  month     = {jul}
}
[83]
Adryana Hutchinson, Collins W. Munyendo, Peter Mayer and Adam J. Aviv. An Analysis of Password Managers' Password Checkup Tools. Extended Abstracts of the 2024 CHI Conference on Human Factors in Computing Systems (CHI EA '24). May 2024. ()
@inproceedings{hutchinson2024analysis,
  author    = {Adryana Hutchinson and Collins W. Munyendo and Peter Mayer and Adam J. Aviv},
  title     = {An Analysis of Password Managers' Password Checkup Tools},
  booktitle = {Extended Abstracts of the 2024 CHI Conference on Human Factors in Computing Systems},
  series    = {CHI EA '24},
  year      = {2024},
  month     = may,
  url       = {https://dl.acm.org/doi/10.1145/3613905.3650741},
  publisher = {ACM}
}
[82]
Adryana Hutchinson, Jinwei Tang, Adam J. Aviv and and Peter Story. Measuring the Prevalence of Password Manager Issues Using In-Situ Experiments. Symposium on Usable Security and Privacy (USEC'24). February 2024. (doi) ()
@inproceedings{hutchinson2024measuring,
  author    = {Adryana Hutchinson and Jinwei Tang and Adam J. Aviv and and Peter Story},
  title     = {Measuring the Prevalence of Password Manager Issues Using In-Situ Experiments},
  booktitle = {Symposium on Usable Security and Privacy},
  series    = {USEC'24},
  year      = {2024},
  url       = {https://www.ndss-symposium.org/wp-content/uploads/usec2024-94-paper.pdf},
  doi       = {10.14722/usec.2024.23094},
  month     = {feb}
}

2023

[81]
Collins W. Munyendo, Peter Mayer and Adam J. Aviv. "I Just Stopped Using One and Started Using the Other": Motivations, Techniques, and Challenges When Switching Password Managers. Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS'23). Pgs. 3123–3137. November 2023. (doi) ()
@inproceedings{munyendo2023pmswitching,
  author    = {Munyendo, Collins W. and Mayer, Peter and Aviv, Adam J.},
  title     = {"I Just Stopped Using One and Started Using the Other": Motivations, Techniques, and Challenges When Switching Password Managers},
  year      = {2023},
  month     = nov,
  publisher = {Association for Computing Machinery},
  address   = {New York, NY, USA},
  url       = {https://doi.org/10.1145/3576915.3623150},
  doi       = {10.1145/3576915.3623150},
  booktitle = {Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security},
  pages     = {3123–3137},
  numpages  = {15},
  series    = {CCS'23}
}
[80]
Peter Mayer, Yixin Zou, Byron M. Lowens, Hunter A. Dyer, Khue Le, Florian Schaub and Adam J. Aviv. Awareness, Intention, (In)Action: Individuals’ Reactions to Data Breaches. ACM Trans. Comput.-Hum. Interact. Vol. 30 (5). Association for Computing Machinery. September 2023. (doi) ()
@article{mayer2023awareness,
  author     = {Mayer, Peter and Zou, Yixin and Lowens, Byron M. and Dyer, Hunter A. and Le, Khue and Schaub, Florian and Aviv, Adam J.},
  title      = {Awareness, Intention, (In)Action: Individuals’ Reactions to Data Breaches},
  year       = {2023},
  issue_date = {October 2023},
  publisher  = {Association for Computing Machinery},
  address    = {New York, NY, USA},
  volume     = {30},
  number     = {5},
  issn       = {1073-0516},
  url        = {https://doi.org/10.1145/3589958},
  doi        = {10.1145/3589958},
  journal    = {ACM Trans. Comput.-Hum. Interact.},
  month      = {sep},
  articleno  = {77},
  numpages   = {53}
}
[79]
David G. Balash, Rahel A. Fainchtein, Elena Korkes, Miles Grant, Micah Sherr and Adam J. Aviv. Educators’ Perspectives of Using (or Not Using) Online Exam Proctoring. Proceedings of the 32nd USENIX Security Symposium (Sec'23). August 2023. (arxiv) (artifact) ()
@inproceedings{balash2023educators,
  author    = {David G. Balash and Rahel A. Fainchtein and Elena Korkes and Miles Grant and Micah Sherr and Adam J. Aviv},
  booktitle = {Proceedings of the 32nd USENIX Security Symposium},
  title     = {Educators’ Perspectives of Using (or Not Using) Online Exam Proctoring},
  series    = {Sec'23},
  month     = aug,
  year      = {2023},
  publisher = {USENIX},
  url       = {https://www.usenix.org/conference/usenixsecurity23/presentation/balash},
  arxiv     = {https://arxiv.org/abs/2302.12936},
  artifact  = {https://github.com/gwusec/2023-USENIX-Educator-Perspectives-of-Exam-Proctoring}
}
[78]
Collins W. Munyendo, Yasemin Acar and Adam J. Aviv. "In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in Kenya. 2023 IEEE Symposium on Security and Privacy (SP). Pgs. 570-587. 2023. (pdf) (doi) ()
@inproceedings{munyendo2023cybercafes,
  author      = {Munyendo, Collins W. and Acar, Yasemin and Aviv, Adam J.},
  booktitle   = {2023 IEEE Symposium on Security and Privacy (SP)},
  title       = {"In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in Kenya},
  year        = {2023},
  volume      = {},
  number      = {},
  pages       = {570-587},
  keywords    = {Training;Printing;Privacy;Government;Sociology;Passwords;Microcomputers;Cybercafes;Kenya;Security;Privacy},
  doi         = {10.1109/SP46215.2023.10179410},
  documenturl = {papers/munyendo-sp23.pdf}
}
[77]
Daniel V. Bailey, Collins W. Munyendo, Hunter A. Dyer, Miles Grant, Philipp Markert and Adam J. Aviv. "Someone Definitely Used 0000": Strategies, Performance, and User Perception of Novice Smartphone-Unlock PIN-Guessers. Proceedings of the 2023 European Symposium on Usable Security (EuroUSEC '23). Pgs. 158–174. 2023. (doi) ()
@inproceedings{baily2023pinguessing,
  author    = {Bailey, Daniel V. and Munyendo, Collins W. and Dyer, Hunter A. and Grant, Miles and Markert, Philipp and Aviv, Adam J.},
  title     = {"Someone Definitely Used 0000":  Strategies, Performance, and User Perception of Novice Smartphone-Unlock PIN-Guessers},
  year      = {2023},
  isbn      = {9798400708145},
  url       = {https://doi.org/10.1145/3617072.3617113},
  doi       = {10.1145/3617072.3617113},
  booktitle = {Proceedings of the 2023 European Symposium on Usable Security},
  pages     = {158–174},
  numpages  = {17},
  location  = {Copenhagen, Denmark},
  series    = {EuroUSEC '23}
}
[76]
Harel Berger, Micah Sherr and Adam Aviv. Cadence: A Simulator for Human Movement-Based Communication Protocols. Proceedings of the 16th Cyber Security Experimentation and Test Workshop (CSET '23). Pgs. 26–31. 2023. (doi) ()
@inproceedings{berger2023cadance,
  author    = {Berger, Harel and Sherr, Micah and Aviv, Adam},
  title     = {Cadence: A Simulator for Human Movement-Based Communication Protocols},
  year      = {2023},
  isbn      = {9798400707889},
  publisher = {Association for Computing Machinery},
  address   = {New York, NY, USA},
  url       = {https://doi.org/10.1145/3607505.3607507},
  doi       = {10.1145/3607505.3607507},
  booktitle = {Proceedings of the 16th Cyber Security Experimentation and Test Workshop},
  pages     = {26–31},
  numpages  = {6},
  location  = {Marina del Rey, CA, USA},
  series    = {CSET '23}
}

2022

[75]
Rahel A. Fainchtein, Adam J. Aviv and Micah Sherr. User Perceptions of the Privacy and Usability of Smart DNS. Annual Computer Security Applications Conference (ACSAC'22). December 2022. ()
@inproceedings{fainchein2022smartDNS,
  title     = {User Perceptions of the Privacy and Usability of Smart DNS},
  booktitle = {Annual Computer Security Applications Conference},
  author    = {Rahel A. Fainchtein and Adam J. Aviv and Micah Sherr},
  url       = {https://dl.acm.org/doi/abs/10.1145/3564625.3567978},
  series    = {ACSAC'22},
  month     = dec,
  year      = {2022}
}
[74]
Xiaoyuan Wu, Collins W. Munyendo, Eddie Cosic, Genevieve A. Flynn, Olivia Legault and Adam J. Aviv. User Perceptions of Five-Word Passwords. Annual Computer Security Applications Conference (ACSAC'22). December 2022. ()
@inproceedings{wu2022fivewords,
  title     = {User Perceptions of Five-Word Passwords},
  booktitle = {Annual Computer Security Applications Conference},
  author    = {Xiaoyuan Wu and Collins W. Munyendo and Eddie Cosic and Genevieve A. Flynn and Olivia Legault and Adam J. Aviv},
  url       = {https://dl.acm.org/doi/abs/10.1145/3564625.3567981},
  series    = {ACSAC'22},
  month     = dec,
  year      = {2022}
}
[73]
Peter Mayer, Collins W. Munyendo, Michelle L. Mazurek and Adam J. Aviv. Why Users (Don't) Use Password Managers at a Large Educational Institution. 31st USENIX Security Symposium (USENIX Security 22) (Sec'22). August 2022. (artifact) ()
@inproceedings{mayer2022pms,
  title     = {Why Users (Don't) Use Password Managers at a Large Educational Institution},
  booktitle = {31st {USENIX} Security Symposium ({USENIX} Security 22)},
  author    = {Peter Mayer and Collins W. Munyendo and Michelle L. Mazurek and Adam J. Aviv},
  year      = {2022},
  publisher = {{USENIX} Association},
  series    = {Sec'22},
  url       = {https://www.usenix.org/conference/usenixsecurity22/presentation/mayer},
  month     = aug,
  artifact  = {https://github.com/gwusec/2022-USENIX-Password-Managers}
}
[72]
Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur and Adam J. Aviv. "The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits. 31st USENIX Security Symposium (USENIX Security 22) (Sec'22). August 2022. ()
@inproceedings{munyendo2022pins4to6,
  title     = {"The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits},
  booktitle = {31st {USENIX} Security Symposium ({USENIX} Security 22)},
  author    = {Collins W. Munyendo and Philipp Markert and Alexandra Nisenoff and Miles Grant and Elena Korkes and Blase Ur and Adam J. Aviv},
  year      = {2022},
  publisher = {{USENIX} Association},
  series    = {Sec'22},
  url       = {https://www.usenix.org/conference/usenixsecurity22/presentation/munyendo},
  month     = aug
}
[71]
David G. Balash, Xiaoyuan Wu, Miles Grant, Irwin Reyes and Adam J. Aviv. Security and Privacy Perceptions of Third-Party Application Access for Google Accounts. 31st USENIX Security Symposium (USENIX Security 22) (Sec'22). August 2022. ()
@inproceedings{balash2022apipriv,
  title     = {Security and Privacy Perceptions of Third-Party Application Access for Google Accounts},
  booktitle = {31st {USENIX} Security Symposium ({USENIX} Security 22)},
  author    = {David G. Balash and Xiaoyuan Wu and Miles Grant and Irwin Reyes and Adam J. Aviv},
  year      = {2022},
  publisher = {{USENIX} Association},
  series    = {Sec'22},
  month     = aug,
  url       = {https://www.usenix.org/conference/usenixsecurity22/presentation/balash}
}
[70]
Collins Munyendo, Yasemin Acar and and Adam J. Aviv. "Desperate Times Call for Desperate Measures:" User Concerns with Mobile Loan Apps in Kenya.. 43rd IEEE Symposium on Security and Privacy (SP'22). May 2022. ()
@inproceedings{munyendo2022loanapps,
  title     = {``Desperate Times Call for Desperate Measures:'' User Concerns with Mobile Loan Apps in Kenya.},
  booktitle = {43rd IEEE Symposium on Security and Privacy},
  author    = {Collins Munyendo and Yasemin Acar and and Adam J. Aviv},
  year      = 2022,
  month     = may,
  publisher = {IEEE},
  series    = {SP'22},
  url       = {https://ieeexplore.ieee.org/document/9833779}
}
[69]
Jaron Mink, Amanda Rose Yuile, Uma Pal, Adam J. Aviv and Adam Bates. Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking Apps. ACM CHI Conference on Human Factors in Computing Systems. May 2022. ()
@inproceedings{mink2022epz,
  title     = {Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking Apps},
  booktitle = {ACM CHI Conference on Human Factors in Computing Systems},
  author    = {Jaron Mink and Amanda Rose Yuile and Uma Pal and Adam J. Aviv and Adam Bates},
  year      = {2022},
  publisher = {ACM},
  month     = may,
  url       = {https://dl.acm.org/doi/10.1145/3491102.3502136}
}
[68]
Hirak Ray, Ravi Kuber and Adam J. Aviv. Investigating Older Adults’ Adoption and Usage of Online Conferencing Tools During COVID-19. 19th International Web for All Conference (W4A '22). April 2022. ()
@inproceedings{ray2022investigating,
  title     = {Investigating Older Adults’ Adoption and Usage of Online Conferencing Tools During COVID-19},
  booktitle = {19th International Web for All Conference (W4A '22)},
  author    = {Hirak Ray and Ravi Kuber and Adam J. Aviv},
  publisher = {ACM},
  month     = apr,
  year      = {2022},
  url       = {https://dl.acm.org/doi/10.1145/3493612.3520447}
}

2021

[67]
Philipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth and Adam J. Aviv. On the Security of Smartphone Unlock PINs. ACM Trans. Priv. Secur. Vol. 24 (4). Association for Computing Machinery. September 2021. (doi) ()
@article{markert2021unlockpins,
  author     = {Markert, Philipp and Bailey, Daniel V. and Golla, Maximilian and D\"{u}rmuth, Markus and Aviv, Adam J.},
  title      = {On the Security of Smartphone Unlock PINs},
  year       = {2021},
  issue_date = {November 2021},
  publisher  = {Association for Computing Machinery},
  address    = {New York, NY, USA},
  volume     = {24},
  number     = {4},
  issn       = {2471-2566},
  url        = {https://doi.org/10.1145/3473040},
  doi        = {10.1145/3473040},
  journal    = {ACM Trans. Priv. Secur.},
  month      = sep,
  articleno  = {30},
  numpages   = {36},
  keywords   = {usability, smartphone, authentication, blocklist, PIN, mobile, Security}
}
[66]
Collins Munyendo, Miles Grant, Philipp Markert, Timothy J. Forman and Adam J. Aviv. Using a Blocklist to Improve the Security of User Selection of Android Patterns. 17th Symposium on Usable Security and Privacy (SOUPS'21). August 2021. (pdf) ()
@inproceedings{munyendo2021blocklists,
  title     = {Using a Blocklist to Improve the Security of User Selection of Android Patterns},
  booktitle = {17th Symposium on Usable Security and Privacy},
  author    = {Collins Munyendo and Miles Grant and Philipp Markert and Timothy J. Forman and Adam J. Aviv},
  year      = {2021},
  series    = {SOUPS'21},
  month     = aug,
  url       = {https://www.usenix.org/conference/soups2021/presentation/munyendo},
  pdf       = {https://www.usenix.org/system/files/soups2021-munyendo.pdf}
}
[65]
David G. Balash, Dongkun Kim, Darika Shaibekova, Rahel A. Fainchtein, Micah Sherr and Adam J. Aviv. Examining the Examiners: Students' Privacy and Security Perceptions of Online Proctoring Services. 17th Symposium on Usable Security and Privacy (SOUPS'21). August 2021. (arxiv) (pdf) ()
@inproceedings{balash2021examining,
  title     = {Examining the Examiners: Students' Privacy and Security Perceptions of Online Proctoring Services},
  booktitle = {17th Symposium on Usable Security and Privacy},
  author    = {David G. Balash and Dongkun Kim and Darika Shaibekova and Rahel A. Fainchtein and Micah Sherr and Adam J. Aviv},
  year      = {2021},
  series    = {SOUPS'21},
  month     = aug,
  arxiv     = {https://arxiv.org/abs/2106.05917},
  url       = {https://www.usenix.org/conference/soups2021/presentation/balash},
  pdf       = {https://www.usenix.org/system/files/soups2021-balash.pdf}
}
[64]
Daniel V. Baily, Philipp Markert and Adam J. Aviv. "I have no idea what they're trying to accomplish:" Enthusiastic and Casual Signal Users' Understanding of Signal PINs. 17th Symposium on Usable Security and Privacy (SOUPS'21). August 2021. (pdf) ()
@inproceedings{baily2021signal,
  title     = {``I have no idea what they're trying to accomplish:'' Enthusiastic and Casual Signal Users' Understanding of Signal PINs},
  booktitle = {17th Symposium on Usable Security and Privacy},
  author    = {Daniel V. Baily and Philipp Markert and Adam J. Aviv},
  year      = {2021},
  series    = {SOUPS'21},
  month     = aug,
  url       = {https://www.usenix.org/conference/soups2021/presentation/baily},
  pdf       = {https://www.usenix.org/system/files/soups2021-bailey.pdf}
}
[63]
Flynn Wolf, Adam J. Aviv and Ravi Kuber. Security Obstacles and Motivationsfor Small Businesses from a CISO’s Perspective. 30th USENIX Security Symposium (USENIX Security 21) (Sec'21). August 2021. (pdf) ()
@inproceedings{wolf2021ciso,
  title     = {Security Obstacles and Motivationsfor Small Businesses from a CISO’s Perspective},
  booktitle = {30th {USENIX} Security Symposium ({USENIX} Security 21)},
  author    = {Flynn Wolf and Adam J. Aviv and Ravi Kuber},
  year      = {2021},
  publisher = {{USENIX} Association},
  series    = {Sec'21},
  month     = aug,
  url       = {https://www.usenix.org/conference/usenixsecurity21/presentation/wolf},
  pdf       = {https://www.usenix.org/system/files/sec21-wolf.pdf}
}
[62]
Florian Farke, David G. Balash, Maximilian Golla, Markus Dürmuth and Adam J. Aviv. Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My Activity. 30th USENIX Security Symposium (USENIX Security 21) (Sec'21). August 2021. (arxiv) (pdf) ()
@inproceedings{farke2021dashboards,
  title     = {Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My Activity},
  booktitle = {30th {USENIX} Security Symposium ({USENIX} Security 21)},
  author    = {Florian Farke and David G. Balash and Maximilian Golla and Markus Dürmuth and Adam J. Aviv},
  year      = {2021},
  publisher = {{USENIX} Association},
  series    = {Sec'21},
  arxiv     = {https://arxiv.org/abs/2105.14066},
  url       = {https://www.usenix.org/conference/usenixsecurity21/presentation/farke},
  pdf       = {https://www.usenix.org/system/files/sec21-farke.pdf},
  month     = aug
}
[61]
Noel Warford, Collins W. Munyendo, Ashna Mediratta, Adam J. Aviv and Michelle L. Mazurek. Strategies and Perceived Risks of Sending Sensitive Documents. 30th USENIX Security Symposium (USENIX Security 21) (Sec'21). August 2021. (arxiv) (pdf) ()
@inproceedings{warford2021strategies,
  title     = {Strategies and Perceived Risks of Sending Sensitive Documents},
  booktitle = {30th {USENIX} Security Symposium ({USENIX} Security 21)},
  author    = {Noel Warford and Collins W. Munyendo and Ashna Mediratta and Adam J. Aviv and Michelle L. Mazurek},
  year      = {2021},
  publisher = {{USENIX} Association},
  series    = {Sec'21},
  arxiv     = {https://arxiv.org/abs/2105.14619},
  url       = {https://www.usenix.org/conference/usenixsecurity21/presentation/warford},
  pdf       = {https://www.usenix.org/system/files/sec21-warford.pdf},
  month     = aug
}
[60]
Peter Mayer, Yixin Zou, Florian Schaub and Adam J. Aviv. "Now I'm a bit angry:" Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them. 30th USENIX Security Symposium (USENIX Security 21) (Sec'21). August 2021. (pdf) ()
@inproceedings{mayer2021nowimangry,
  title     = {"Now I'm a bit angry:" Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them},
  booktitle = {30th {USENIX} Security Symposium ({USENIX} Security 21)},
  author    = {Peter Mayer and Yixin Zou and Florian Schaub and Adam J. Aviv},
  year      = {2021},
  url       = {https://www.usenix.org/conference/usenixsecurity21/presentation/mayer},
  publisher = {{USENIX} Association},
  series    = {Sec'21},
  pdf       = {https://www.usenix.org/system/files/sec21-mayer.pdf},
  month     = aug
}
[59]
Hirak Ray, Flynn Wolf, Ravi Kuber and Adam J. Aviv. Why Older Adults (Don't) Use Password Managers. 30th USENIX Security Symposium (USENIX Security 21) (Sec'21). August 2021. (arxiv) ()
@inproceedings{ray2021olderadults,
  title     = {Why Older Adults (Don't) Use Password Managers},
  author    = {Hirak Ray and Flynn Wolf and Ravi Kuber and Adam J. Aviv},
  year      = {2021},
  month     = aug,
  booktitle = {30th {USENIX} Security Symposium ({USENIX} Security 21)},
  series    = {Sec'21},
  arxiv     = {https://arxiv.org/abs/2010.01973},
  url       = {https://www.usenix.org/system/files/sec21-ray.pdf},
}
[58]
Hirak Ray, Flynn Wolf, Ravi Kuber and Adam J. Aviv. "Warn Them" or "Just Block Them"?: Comparing Privacy Concerns of Older and Working Age Adults. Proceedings on Privacy Enhancing Technologies (PoPETS). July 2021. (video) ()
@article{ray2021warnthem,
  author  = {Hirak Ray and Flynn Wolf and Ravi Kuber and Adam J. Aviv},
  journal = {Proceedings on Privacy Enhancing Technologies (PoPETS)},
  month   = jul,
  title   = {{``Warn Them'' or ``Just Block Them''?: Comparing Privacy Concerns of Older and Working Age Adults}},
  year    = {2021},
  url     = {https://petsymposium.org/2021/files/papers/issue2/popets-2021-0016.pdf},
  video   = {https://www.youtube.com/watch?v=RjsVYGbOg3U}
}
[57]
Rahel A. Fainchtein, Adam J. Aviv, Micah Sherr, Stephen Ribaudo and Armaan Khullar. Holes in the Geofence: Privacy Vulnerabilities in "Smart" DNS Services. Proceedings on Privacy Enhancing Technologies (PoPETS). July 2021. (arxiv) (video) (pdf) ()
@article{fainchtein2021sdns,
  author  = {Rahel A. Fainchtein and Adam J. Aviv and Micah Sherr and Stephen Ribaudo and Armaan Khullar},
  journal = {Proceedings on Privacy Enhancing Technologies (PoPETS)},
  month   = {July},
  title   = {{Holes in the Geofence: Privacy Vulnerabilities in ``Smart'' DNS Services}},
  year    = {2021},
  arxiv   = {https://arxiv.org/abs/2012.07944},
  pdf     = {https://petsymposium.org/2021/files/papers/issue2/popets-2021-0022.pdf},
  video   = {https://www.youtube.com/watch?v=RjsVYGbOg3U}
}
[56]
Ian Martiny, Gabriel Kaptchuk, Adam J. Aviv, Daniel S. Roche and Eric Wustrow. Improving Signal’s Sealed Sender. Network and Distributed Systems Security Symposium (NDSS'21). Feb 2021. (pdf) ()
@inproceedings{martiny2021signal,
  title       = {Improving Signal’s Sealed Sender},
  author      = {Ian Martiny and Gabriel Kaptchuk and Adam J. Aviv and Daniel S. Roche and Eric Wustrow},
  booktitle   = {Network and Distributed Systems Security Symposium},
  series      = {NDSS'21},
  month       = {Feb},
  year        = {2021},
  url         = {https://www.ndss-symposium.org/ndss-paper/improving-signals-sealed-sender/},
  documenturl = {papers/martiny2021signal.pdf}
}

2020

[55]
Timothy J. Forman and Adam J. Aviv. Double Patterns: A Usable Solution to Increase the Security of Android Unlock Patterns. 2020 Annual Computer Security Conference (ACSAC'20). December 2020. (arxiv) ()
@inproceedings{forman2020doublepatterns,
  title     = {Double Patterns: A Usable Solution to Increase the Security of Android Unlock Patterns},
  author    = {Timothy J. Forman and Adam J. Aviv},
  year      = {2020},
  month     = dec,
  booktitle = {2020 Annual Computer Security Conference},
  series    = {ACSAC'20},
  arxiv     = {https://arxiv.org/abs/2008.10681},
  url       = {https://dl.acm.org/doi/10.1145/3427228.3427252}
}
[54]
Hassan Khan, Jason Ceci, Jonah Stegman, Adam J. Aviv, Rozita Dara and Ravi Kuber. Widely Reused and Shared, Infrequently Updated, and Sometimes Inherited: A Holistic View of PIN Authentication in Digital Lives and Beyond. 2020 Annual Computer Security Conference (ACSAC'20). December 2020. (arxiv) ()
@inproceedings{kahn2020widely,
  title     = {Widely Reused and Shared, Infrequently Updated, and Sometimes Inherited: A Holistic View of PIN Authentication in Digital Lives and Beyond},
  author    = {Hassan Khan and Jason Ceci and Jonah Stegman and Adam J. Aviv and Rozita Dara and Ravi Kuber},
  year      = {2020},
  month     = dec,
  booktitle = {2020 Annual Computer Security Conference},
  series    = {ACSAC'20},
  arxiv     = {https://arxiv.org/abs/2008.10697},
  url       = {https://dl.acm.org/doi/10.1145/3427228.3427240}
}
[53]
Raina Samuel, Philipp Markert, Adam J. Aviv and Iulian Neamtiu. Knock, Knock. Who's There? On the Security of LG's Knock Codes. 2020 Symposium on Usable Security and Privacy (SOUPS'20). Pgs. 1-24. August 2020. (arxiv) (video) (slides) (pdf) ()
@inproceedings{samuel2020knock,
  title       = {Knock, Knock. Who's There? On the Security of LG's Knock Codes},
  author      = {Raina Samuel and Philipp Markert and Adam J. Aviv and Iulian Neamtiu},
  year        = {2020},
  month       = aug,
  pages       = {1-24},
  publisher   = {USENIX},
  booktitle   = {2020 Symposium on Usable Security and Privacy},
  series      = {SOUPS'20},
  url         = {https://www.usenix.org/conference/soups2020/presentation/samuel},
  video       = {https://2459d6dc103cb5933875-c0245c5c937c5dedcca3f1764ecc9b2f.ssl.cf2.rackcdn.com/soups2020/1_authentication_long_optional/3_soups2020-paper79-optional-presentation-video-final.mp4},
  slides      = {https://www.usenix.org/system/files/soups2020-paper79-slides-samuel.pdf},
  arxiv       = {https://arxiv.org/abs/2006.03556},
  documenturl = {https://www.usenix.org/system/files/soups2020-samuel.pdf}
}
[52]
Philipp Markert, Daniel V. Bailey, Maximillian Golla, Markus Duermuth and Adam J. Aviv. This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINs. 2020 IEEE Symposium on Security and Privacy (SP). Pgs. 1525-1542. May 2020. (doi) ()
@inproceedings{markert2020thispin,
  author    = {Philipp Markert and Daniel V. Bailey and Maximillian Golla and Markus Duermuth and Adam J. Aviv},
  booktitle = {2020 IEEE Symposium on Security and Privacy (SP)},
  title     = {This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINs},
  year      = {2020},
  volume    = {},
  issn      = {2375-1207},
  pages     = {1525-1542},
  keywords  = {authentication;pin;blacklist;mobile;smartphone;security;usability},
  doi       = {10.1109/SP40000.2020.00100},
  url       = {https://doi.ieeecomputersociety.org/10.1109/SP40000.2020.00100},
  publisher = {IEEE Computer Society},
  address   = {Los Alamitos, CA, USA},
  month     = may
}
[51]
Timothy J. Forman, Daniel S. Roche and Adam J. Aviv. Twice as Nice? A Preliminary Evaluation of Double Android Unlock Patterns. Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems (CHI EA ’20). Pgs. 1–7. 2020. (doi) ()
@inproceedings{forman2020double,
  author    = {Forman, Timothy J. and Roche, Daniel S. and Aviv, Adam J.},
  title     = {Twice as Nice? A Preliminary Evaluation of Double Android Unlock Patterns},
  year      = {2020},
  isbn      = {9781450368193},
  publisher = {Association for Computing Machinery},
  address   = {New York, NY, USA},
  url       = {https://doi.org/10.1145/3334480.3382922},
  doi       = {10.1145/3334480.3382922},
  booktitle = {Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems},
  pages     = {1–7},
  numpages  = {7},
  keywords  = {android patterns, usability, security, mobile authentication},
  location  = {Honolulu, HI, USA},
  series    = {CHI EA ’20}
}

2019

[50]
Hirak Ray, Flynn Wolf, Ravi Kuber and Adam J. Aviv. "Woe is me:" Examining Older Adults' Perceptions of Privacy. Extended Abstracts of the 2019 CHI Conference on Human Factors in Computing Systems (CHI EA '19). Pgs. LBW2611:1–LBW2611:6. 2019. (pdf) (doi) ()
@inproceedings{ray2019woe,
  author      = {Hirak Ray and Flynn Wolf and Ravi Kuber and Adam J. Aviv},
  title       = {"Woe is me:" Examining Older Adults' Perceptions of Privacy},
  booktitle   = {Extended Abstracts of the 2019 CHI Conference on Human Factors in Computing Systems},
  series      = {CHI EA '19},
  year        = {2019},
  pages       = {LBW2611:1--LBW2611:6},
  publisher   = {ACM},
  doi         = {10.1145/3290607.3312770},
  url         = {https://doi.org/10.1145/3290607.3312770},
  documenturl = {papers/ray2019woe.pdf}
}
[49]
Flynn Wolf, Ravi Kuber and Adam J. Aviv. "Pretty Close to a Must-Have": Balancing Usability Desire and Security Concern in Biometric Adoption. Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems (CHI '19). Pgs. 151:1–151:12. 2019. (doi) ()
@inproceedings{wolf2019musthave,
  author    = {Wolf, Flynn and Kuber, Ravi and Aviv, Adam J.},
  title     = {"Pretty Close to a Must-Have": Balancing Usability Desire and Security Concern in Biometric Adoption},
  booktitle = {Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems},
  series    = {CHI '19},
  year      = {2019},
  isbn      = {978-1-4503-5970-2},
  location  = {Glasgow, Scotland Uk},
  pages     = {151:1--151:12},
  articleno = {151},
  url       = {http://doi.acm.org/10.1145/3290605.3300381},
  doi       = {10.1145/3290605.3300381},
  acmid     = {3300381},
  publisher = {ACM}
}
[48]
Anrin Chakraborti, Adam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. Roche and Radu Sion. rORAM: Efficient Range ORAM with O(log^2 N) Locality. Symposium on the Network and Distributed Systems Security (NDSS'19). 2019. (doi) ()
@inproceedings{chakraborti2019rOram,
  author    = {Anrin Chakraborti and Adam J. Aviv and Seung Geol Choi and Travis Mayberry and Daniel S. Roche and Radu Sion},
  title     = { rORAM: Efficient Range ORAM with O(log^2 N) Locality},
  booktitle = {Symposium on the Network and Distributed Systems Security},
  series    = {NDSS'19},
  publisher = {ISOC},
  year      = {2019},
  location  = {San Diego, CA},
  url       = {https://dx.doi.org/10.14722/ndss.2019.23320},
  doi       = {10.14722/ndss.2019.23320}
}
[47]
Maximilian Golla, Jan Rimkus, Adam J. Aviv and Markus Duermuth. Work in Progress: On the In-Accuracy and Influence of Android Pattern Strength Meters. Workshop on Usable Security (USEC'19). 2019. (pdf) (doi) ()
@inproceedings{golla2019inaccuracy,
  title       = {Work in Progress: On the In-Accuracy and Influence of Android Pattern Strength Meters},
  booktitle   = {Workshop on Usable Security},
  series      = {USEC'19},
  author      = {Maximilian Golla and Jan Rimkus and Adam J. Aviv and Markus Duermuth},
  year        = {2019},
  url         = {https://dx.doi.org/10.14722/usec.2019.23025},
  doi         = {10.14722/usec.2019.23025},
  documenturl = {papers/golla-usec19.pdf}
}

2018

[46]
Guixin Ye, Zhanyong Tang, Dingyi Fang, Xiaojiang Chen, Willy Wolff, Adam J. Aviv and Zheng Wang. A Video-based Attack for Android Pattern Lock. ACM Transactions on Privacy and Security (TOPS). Vol. 21 (4). Pgs. 19:1–19:31. ACM. July 2018. (doi) ()
@article{guixin2018video,
  author     = {Ye, Guixin and Tang, Zhanyong and Fang, Dingyi and Chen, Xiaojiang and Wolff, Willy and Aviv, Adam J. and Wang, Zheng},
  title      = {A Video-based Attack for Android Pattern Lock},
  journal    = {ACM Transactions on Privacy and Security (TOPS)},
  issue_date = {October 2018},
  volume     = {21},
  number     = {4},
  month      = jul,
  year       = {2018},
  issn       = {2471-2566},
  pages      = {19:1--19:31},
  articleno  = {19},
  numpages   = {31},
  url        = {http://doi.acm.org/10.1145/3230740},
  doi        = {10.1145/3230740},
  publisher  = {ACM}
}
[45]
Flynn Wolf, Adam J. Aviv and Ravi Kuber. "It’s all about the start" classifying eyes-free mobile authentication techniques. Journal of Information Security and Applications. Vol. 41. Pgs. 28 - 40. 2018. (doi) ()
@article{wolf2018start,
  author  = {Flynn Wolf and Adam J. Aviv and Ravi Kuber},
  title   = {"{I}t’s all about the start" classifying eyes-free mobile authentication techniques},
  journal = {Journal of Information Security and Applications},
  volume  = {41},
  pages   = {28 - 40},
  year    = {2018},
  issn    = {2214-2126},
  doi     = {https://doi.org/10.1016/j.jisa.2018.05.004},
  url     = {https://www.sciencedirect.com/science/article/pii/S2214212618301315}
}
[44]
Flynn Wolf, Ravi Kuber and Adam J Aviv. An empirical study examining the perceptions and behaviours of security-conscious users of mobile authentication. Behaviour & Information Technology. Vol. 37 (4). Pgs. 320–334. Taylor & Francis. 2018. ()
@article{wolf2018empirical,
  title     = {An empirical study examining the perceptions and behaviours of security-conscious users of mobile authentication},
  author    = {Wolf, Flynn and Kuber, Ravi and Aviv, Adam J},
  journal   = {Behaviour \& Information Technology},
  volume    = {37},
  number    = {4},
  pages     = {320--334},
  year      = {2018},
  publisher = {Taylor \& Francis}
}
[43]
Adam J. Aviv, Flynn Wolf and Ravi Kuber. Comparing Video Based Shoulder Surfing with Live Simulation. Annual Computer Security Applications Conference (ACSAC'18). 2018. (arxiv) (doi) ()
@inproceedings{aviv2018comparing,
  author    = {Adam J. Aviv and Flynn Wolf and Ravi Kuber},
  title     = {Comparing Video Based Shoulder Surfing with Live Simulation},
  booktitle = {Annual Computer Security Applications Conference},
  year      = {2018},
  series    = {ACSAC'18},
  url       = {https://dl.acm.org/citation.cfm?id=3274702},
  doi       = {10.1145/3274694.3274702},
  arxiv     = {https://arxiv.org/abs/1809.08640}
}
[42]
John Sonchack, Oliver Michel, Adam J. Aviv, Eric Keller and Jonathan M. Smith. Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow. 2018 USENIX Annual Technical Conference (ATC'18). 2018. ()
@inproceedings{sonchack2018scaling,
  author    = {John Sonchack and Oliver Michel and Adam J. Aviv and Eric Keller and Jonathan M. Smith},
  title     = {Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow},
  booktitle = {2018 {USENIX} Annual Technical Conference ({ATC}'18)},
  year      = {2018},
  address   = {Boston, MA},
  url       = {https://www.usenix.org/conference/atc18/presentation/sonchack},
  publisher = {{USENIX} Association}
}
[41]
Flynn Wolf, Ravi Kuber and Adam J. Aviv. How Do We Talk Ourselves Into These Things?. Extended Abstracts of the 2018 CHI Conference on Human Factors in Computing Systems (CHI EA '18). Pgs. LBW502:1–LBW502:6. 2018. (doi) ()
@inproceedings{wolf2018how,
  author    = {Wolf, Flynn and Kuber, Ravi and Aviv, Adam J.},
  title     = {How Do We Talk Ourselves Into These Things?},
  booktitle = {Extended Abstracts of the 2018 CHI Conference on Human Factors in Computing Systems},
  series    = {CHI EA '18},
  year      = {2018},
  isbn      = {978-1-4503-5621-3},
  location  = {Montreal QC, Canada},
  pages     = {LBW502:1--LBW502:6},
  articleno = {LBW502},
  numpages  = {6},
  url       = {http://doi.acm.org/10.1145/3170427.3188578},
  doi       = {10.1145/3170427.3188578},
  acmid     = {3188578},
  publisher = {ACM},
  address   = {New York, NY, USA}
}
[40]
John Sonchack, Adam J. Aviv, Eric Keller and Jonathan M. Smith. Turboflow: Information Rich Flow Record Generation on Commodity Switches. Proceedings of the Thirteenth EuroSys Conference (EuroSys '18). Pgs. 11:1–11:16. 2018. (doi) ()
@inproceedings{sonchack2018turboflow,
  author    = {Sonchack, John and Aviv, Adam J. and Keller, Eric and Smith, Jonathan M.},
  title     = {Turboflow: Information Rich Flow Record Generation on Commodity Switches},
  booktitle = {Proceedings of the Thirteenth EuroSys Conference},
  series    = {EuroSys '18},
  year      = {2018},
  isbn      = {978-1-4503-5584-1},
  location  = {Porto, Portugal},
  pages     = {11:1--11:16},
  articleno = {11},
  numpages  = {16},
  url       = {http://doi.acm.org/10.1145/3190508.3190558},
  doi       = {10.1145/3190508.3190558},
  acmid     = {3190558},
  publisher = {ACM},
  address   = {New York, NY, USA}
}
[39]
Adam J Aviv and Ravi Kuber. Towards Understanding Connections between Security/Privacy Attitudes and Unlock Authentication. Workshop on Usable Security (USEC'18). 2018. (arxiv) (doi) ()
@inproceedings{aviv2018towards,
  title     = {Towards Understanding Connections between Security/Privacy Attitudes and Unlock Authentication},
  booktitle = {Workshop on Usable Security},
  series    = {USEC'18},
  author    = {Aviv, Adam J and Kuber, Ravi},
  url       = {https://dx.doi.org/10.14722/usec.2018.23011},
  doi       = {10.14722/usec.2018.23011},
  arxiv     = {http://arxiv.org/abs/1801.07518a},
  year      = {2018}
}
[38]
Flynn Wolf, Adam J. Aviv and Ravi Kuber. Work-In-Progress: Performance of Eyes-Free Mobile Authentication. Workshop on Usable Security (USEC'18). 2018. (doi) ()
@inproceedings{wolf2018eyes,
  title     = {Work-In-Progress: Performance of Eyes-Free Mobile Authentication},
  author    = {Flynn Wolf and Adam J. Aviv and Ravi Kuber},
  booktitle = {Workshop on Usable Security},
  url       = {https://dx.doi.org/10.14722/usec.2018.23013},
  doi       = {10.14722/usec.2018.23013},
  series    = {USEC'18},
  year      = {2018}
}

2017

[37]
Adam J Aviv, Ravi Kuber and Devon Budzitowski. Is Bigger Better When It Comes to Android Graphical Pattern Unlock?. IEEE Internet Computing. Vol. 21 (6). Pgs. 46–51. IEEE. 2017. (doi) ()
@article{aviv2017bigger,
  title     = {Is Bigger Better When It Comes to Android Graphical Pattern Unlock?},
  author    = {Aviv, Adam J and Kuber, Ravi and Budzitowski, Devon},
  journal   = {IEEE Internet Computing},
  volume    = {21},
  number    = {6},
  pages     = {46--51},
  year      = {2017},
  publisher = {IEEE},
  url       = {https://ieeexplore.ieee.org/document/8114690},
  doi       = {10.1109/MIC.2017.4180833}
}
[36]
Adam J. Aviv, John T. Davin, Flynn Wolf and Ravi Kuber. Towards Baselines for Shoulder Surfing on Mobile Authentication. Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC 2017). Pgs. 486–498. 2017. (pdf) (doi) ()
@inproceedings{aviv2017towards,
  author      = {Aviv, Adam J. and Davin, John T. and Wolf, Flynn and Kuber, Ravi},
  title       = {Towards Baselines for Shoulder Surfing on Mobile Authentication},
  booktitle   = {Proceedings of the 33rd Annual Computer Security Applications Conference},
  series      = {ACSAC 2017},
  year        = {2017},
  isbn        = {978-1-4503-5345-8},
  location    = {Orlando, FL, USA},
  pages       = {486--498},
  numpages    = {13},
  url         = {http://doi.acm.org/10.1145/3134600.3134609},
  doi         = {10.1145/3134600.3134609},
  acmid       = {3134609},
  publisher   = {ACM},
  address     = {New York, NY, USA},
  documenturl = {papers/aviv-acsac17.pdf}
}
[35]
Daniel S. Roche, Adam Aviv, Seung Geol Choi and Travis Mayberry. Deterministic, Stash-Free Write-Only ORAM. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS '17). Pgs. 507–521. 2017. (pdf) (doi) ()
@inproceedings{roche2017deterministic,
  author      = {Roche, Daniel S. and Aviv, Adam and Choi, Seung Geol and Mayberry, Travis},
  title       = {Deterministic, Stash-Free Write-Only ORAM},
  booktitle   = {Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security},
  series      = {CCS '17},
  year        = {2017},
  isbn        = {978-1-4503-4946-8},
  location    = {Dallas, Texas, USA},
  pages       = {507--521},
  numpages    = {15},
  url         = {http://doi.acm.org/10.1145/3133956.3134051},
  doi         = {10.1145/3133956.3134051},
  acmid       = {3134051},
  publisher   = {ACM},
  address     = {New York, NY, USA},
  documenturl = {papers/roche-ccs17-deterministic.pdf}
}
[34]
Adam J. Aviv and Seung Geol Choi and Travis Mayberry and Daniel S. Roche. ObliviSync: Practical Oblivious File Backup and Synchronization. 24th Annual Network and Distributed System Security Symposium, NDSS 2017, San Diego, California, USA, February 26 - March 1, 2017. 2017. (pdf) ()
@inproceedings{aviv2017oblivisync,
  author      = {Adam J. Aviv and
                 Seung Geol Choi and
                 Travis Mayberry and
                 Daniel S. Roche},
  title       = {ObliviSync: Practical Oblivious File Backup and Synchronization},
  booktitle   = {24th Annual Network and Distributed System Security Symposium, {NDSS}
                 2017, San Diego, California, USA, February 26 - March 1, 2017},
  year        = {2017},
  url         = {https://www.ndss-symposium.org/ndss2017/ndss-2017-programme/oblivisync-practical-oblivious-file-backup-and-synchronization/},
  timestamp   = {Tue, 16 Jan 2018 15:44:17 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/ndss/AvivCMR17},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/ndss2017_01-2_Aviv_paper.pdf}
}

2016

[33]
John Sonchack and Adam J Aviv. Exploring large scale security system reproducibility with the LESS simulator. Journal of Computer Security. Vol. 24 (5). Pgs. 645–665. IOS Press. 2016. ()
@article{sonchack2016exploring,
  title     = {Exploring large scale security system reproducibility with the LESS simulator},
  author    = {Sonchack, John and Aviv, Adam J},
  journal   = {Journal of Computer Security},
  volume    = {24},
  number    = {5},
  pages     = {645--665},
  year      = {2016},
  publisher = {IOS Press}
}
[32]
John Sonchack and Anurag Dubey and Adam J. Aviv and Jonathan M. Smith and Eric Keller. Timing-based reconnaissance and defense in software-defined networks. Proceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC 2016, Los Angeles, CA, USA, December 5-9, 2016. Pgs. 89–100. 2016. (pdf) ()
@inproceedings{sonchack2016timing,
  author      = {John Sonchack and
                 Anurag Dubey and
                 Adam J. Aviv and
                 Jonathan M. Smith and
                 Eric Keller},
  title       = {Timing-based reconnaissance and defense in software-defined networks},
  booktitle   = {Proceedings of the 32nd Annual Conference on Computer Security Applications,
                 {ACSAC} 2016, Los Angeles, CA, USA, December 5-9, 2016},
  pages       = {89--100},
  year        = {2016},
  url         = {http://dl.acm.org/citation.cfm?id=2991081},
  timestamp   = {Wed, 07 Dec 2016 11:05:29 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/SonchackDASK16},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/sonchack-ACASC-16.pdf}
}
[31]
Vaishali Narkhede and Karuna P. Joshi and Adam J. Aviv and Seung Geol Choi and Daniel S. Roche and Tim Finin. Managing Cloud Storage Obliviously. 9th IEEE International Conference on Cloud Computing, CLOUD 2016, San Francisco, CA, USA, June 27 - July 2, 2016. Pgs. 990–993. 2016. (doi) ()
@inproceedings{narkhede2016managing,
  author    = {Vaishali Narkhede and
               Karuna P. Joshi and
               Adam J. Aviv and
               Seung Geol Choi and
               Daniel S. Roche and
               Tim Finin},
  title     = {Managing Cloud Storage Obliviously},
  booktitle = {9th {IEEE} International Conference on Cloud Computing, {CLOUD} 2016,
               San Francisco, CA, USA, June 27 - July 2, 2016},
  pages     = {990--993},
  year      = {2016},
  url       = {https://doi.org/10.1109/CLOUD.2016.0151},
  doi       = {10.1109/CLOUD.2016.0151},
  timestamp = {Wed, 17 May 2017 14:24:56 +0200},
  biburl    = {https://dblp.org/rec/bib/conf/IEEEcloud/NarkhedeJACRF16},
  bibsource = {dblp computer science bibliography, https://dblp.org}
}
[30]
Daniel S. Roche and Adam J. Aviv and Seung Geol Choi. A Practical Oblivious Map Data Structure with Secure Deletion and History Independence. IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, May 22-26, 2016. Pgs. 178–197. 2016. (doi) ()
@inproceedings{roche2016practical,
  author    = {Daniel S. Roche and
               Adam J. Aviv and
               Seung Geol Choi},
  title     = {A Practical Oblivious Map Data Structure with Secure Deletion and
               History Independence},
  booktitle = {{IEEE} Symposium on Security and Privacy, {SP} 2016, San Jose, CA,
               USA, May 22-26, 2016},
  pages     = {178--197},
  year      = {2016},
  url       = {https://doi.org/10.1109/SP.2016.19},
  doi       = {10.1109/SP.2016.19},
  timestamp = {Sat, 16 Sep 2017 12:10:30 +0200},
  biburl    = {https://dblp.org/rec/bib/conf/sp/RocheAC16},
  bibsource = {dblp computer science bibliography, https://dblp.org}
}
[29]
Abdullah Ali, Adam J Aviv and Ravi Kuber. Developing and evaluating a gestural and tactile mobile interface to support user authentication. IConference 2016 Proceedings. 2016. (pdf) ()
@inproceedings{ali2016developing,
  title       = {Developing and evaluating a gestural and tactile mobile interface to support user authentication},
  author      = {Ali, Abdullah and Aviv, Adam J and Kuber, Ravi},
  booktitle   = {IConference 2016 Proceedings},
  year        = {2016},
  publisher   = {iSchools},
  documenturl = {papers/ali-iconference16.pdf}
}
[28]
John Sonchack and Jonathan M. Smith and Adam J. Aviv and Eric Keller. Enabling Practical Software-defined Networking Security Applications with OFX. 23rd Annual Network and Distributed System Security Symposium, NDSS 2016, San Diego, California, USA, February 21-24, 2016. 2016. (pdf) ()
@inproceedings{sonchack2016enabling,
  author      = {John Sonchack and
                 Jonathan M. Smith and
                 Adam J. Aviv and
                 Eric Keller},
  title       = {Enabling Practical Software-defined Networking Security Applications
                 with {OFX}},
  booktitle   = {23rd Annual Network and Distributed System Security Symposium, {NDSS}
                 2016, San Diego, California, USA, February 21-24, 2016},
  year        = {2016},
  url         = {http://wp.internetsociety.org/ndss/wp-content/uploads/sites/25/2017/09/enabling-practical-software-defined-networking-security-applications-ofx.pdf},
  timestamp   = {Tue, 16 Jan 2018 13:23:48 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/ndss/SonchackSAK16},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/sonchack-ndss16.pdf}
}
[27]
Adam J. Aviv, Markus Duermuth and Payas Gupta. Position Paper: Measuring the Impact of Al- phabet and Culture on Graphical Passwords. Who Are You?! Adventures in Authentication Workshop (WAY'16). 2016. ()
@inproceedings{aviv2016position,
  title     = {Position Paper: Measuring the Impact of Al- phabet and Culture on Graphical Passwords},
  author    = {Adam J. Aviv and Markus Duermuth and Payas Gupta},
  booktitle = {Who Are You?! Adventures in Authentication Workshop},
  series    = {WAY'16},
  year      = {2016}
}
[26]
Flynn Wolf, Ravi Kuber and Adam J. Aviv. Preliminary Findings from an Exploratory Qualitative Study of Security-Conscious Users of Mobile Authentication. 2nd Workshop on Security Information Workers (WSIW'16). 2016. ()
@inproceedings{wolf2016preliminary,
  title     = {Preliminary Findings from an Exploratory Qualitative Study of Security-Conscious Users of Mobile Authentication},
  author    = {Flynn Wolf and Ravi Kuber and Adam J. Aviv},
  booktitle = {2nd Workshop on Security Information Workers},
  series    = {WSIW'16},
  year      = {2016}
}
[25]
John Sonchack and Adam J. Aviv and Eric Keller. Timing SDN Control Planes to Infer Network Configurations. Proceedings of the 2016 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization, SDN-NFV@CODASPY 2016, New Orleans, LA, USA, March 11, 2016. Pgs. 19–22. 2016. (pdf) (doi) ()
@inproceedings{sonchack2016timing2,
  author      = {John Sonchack and
                 Adam J. Aviv and
                 Eric Keller},
  title       = {Timing {SDN} Control Planes to Infer Network Configurations},
  booktitle   = {Proceedings of the 2016 {ACM} International Workshop on Security in
                 Software Defined Networks {\&} Network Function Virtualization,
                 SDN-NFV@CODASPY 2016, New Orleans, LA, USA, March 11, 2016},
  pages       = {19--22},
  year        = {2016},
  url         = {http://doi.acm.org/10.1145/2876019.2876030},
  doi         = {10.1145/2876019.2876030},
  timestamp   = {Tue, 15 Mar 2016 10:03:36 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/codaspy/SonchackAK16},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/sonchack-SDN-NFV16.pdf}
}
[24]
Adam J Aviv, Justin Maguire and Jeanne Luning Prak. Analyzing the impact of collection methods and demographics for android’s pattern unlock. Workshop on Usable Security (USEC'16). 2016. (pdf) ()
@inproceedings{aviv2016analyzing,
  title       = {Analyzing the impact of collection methods and demographics for android’s pattern unlock},
  author      = {Aviv, Adam J and Maguire, Justin and Prak, Jeanne Luning},
  booktitle   = {Workshop on Usable Security},
  series      = {USEC'16},
  year        = {2016},
  documenturl = {papers/aviv-usec16.pdf}
}
[23]
Andrew West and Adam J. Aviv. On the Privacy Concerns of URL Query Strings. Workshop on Web 2.0 Security and Privacy. 2016. (pdf) ()
@inproceedings{west2014urlquery,
  title       = {On the Privacy Concerns of URL Query Strings},
  author      = {Andrew West and Adam J. Aviv},
  booktitle   = {Workshop on Web 2.0 Security and Privacy},
  year        = {2016},
  documenturl = {papers/west_w2sp.pdf}
}

2015

[22]
John Sonchack, Adam J Aviv and Jonathan M Smith. Cross-domain collaboration for improved IDS rule set selection. Journal of Information Security and Applications. Vol. 24. Pgs. 25–40. Elsevier. 2015. ()
@article{sonchack2015cross,
  title     = {Cross-domain collaboration for improved IDS rule set selection},
  author    = {Sonchack, John and Aviv, Adam J and Smith, Jonathan M},
  journal   = {Journal of Information Security and Applications},
  volume    = {24},
  pages     = {25--40},
  year      = {2015},
  publisher = {Elsevier}
}
[21]
Adam J. Aviv and Devon Budzitowski and Ravi Kuber. Is Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4 Grid Sizes for Android's Pattern Unlock. Proceedings of the 31st Annual Computer Security Applications Conference, Los Angeles, CA, USA, December 7-11, 2015. Pgs. 301–310. 2015. (pdf) (doi) ()
@inproceedings{aviv2015bigger,
  author      = {Adam J. Aviv and
                 Devon Budzitowski and
                 Ravi Kuber},
  title       = {Is Bigger Better? Comparing User-Generated Passwords on 3x3 vs. 4x4
                 Grid Sizes for Android's Pattern Unlock},
  booktitle   = {Proceedings of the 31st Annual Computer Security Applications Conference,
                 Los Angeles, CA, USA, December 7-11, 2015},
  pages       = {301--310},
  year        = {2015},
  url         = {http://doi.acm.org/10.1145/2818000.2818014},
  doi         = {10.1145/2818000.2818014},
  timestamp   = {Tue, 15 Dec 2015 16:46:09 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/AvivBK15},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/aviv-acsac15.pdf}
}

2014

[20]
Adam J Aviv, Matt Blaze, Micah Sherr and Jonathan M Smith. Privacy-aware message exchanges for HumaNets. Computer Communications. Vol. 48. Pgs. 30–43. Elsevier. 2014. (pdf) ()
@article{aviv2014privacy,
  title       = {Privacy-aware message exchanges for HumaNets},
  author      = {Aviv, Adam J and Blaze, Matt and Sherr, Micah and Smith, Jonathan M},
  journal     = {Computer Communications},
  volume      = {48},
  pages       = {30--43},
  year        = {2014},
  publisher   = {Elsevier},
  documenturl = {papers/aviv-esorics12-privacy.pdf}
}
[19]
Andrew G West and Adam J Aviv. Measuring Privacy Disclosures in URL Query Strings. IEEE Internet Computing. Vol. 18 (6). Pgs. 52–59. IEEE. 2014. (pdf) ()
@article{west2014measuring,
  title       = {Measuring Privacy Disclosures in URL Query Strings},
  author      = {West, Andrew G and Aviv, Adam J},
  journal     = {IEEE Internet Computing},
  volume      = {18},
  number      = {6},
  pages       = {52--59},
  year        = {2014},
  publisher   = {IEEE},
  documenturl = {papers/ieee-aviv-west.pdf}
}
[18]
Adam J. Aviv and Dane Fichter. Understanding visual perceptions of usability and security of Android's graphical password pattern. Proceedings of the 30th Annual Computer Security Applications Conference, ACSAC 2014, New Orleans, LA, USA, December 8-12, 2014. Pgs. 286–295. 2014. (pdf) (doi) ()
@inproceedings{aviv2014understanding,
  author      = {Adam J. Aviv and
                 Dane Fichter},
  title       = {Understanding visual perceptions of usability and security of Android's
                 graphical password pattern},
  booktitle   = {Proceedings of the 30th Annual Computer Security Applications Conference,
                 {ACSAC} 2014, New Orleans, LA, USA, December 8-12, 2014},
  pages       = {286--295},
  year        = {2014},
  url         = {http://doi.acm.org/10.1145/2664243.2664253},
  doi         = {10.1145/2664243.2664253},
  timestamp   = {Sat, 06 Dec 2014 14:20:32 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/AvivF14},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/p286-aviv.pdf}
}
[17]
John Sonchack and Adam J. Aviv. LESS Is More: Host-Agent Based Simulator for Large-Scale Evaluation of Security Systems. Computer Security - ESORICS 2014 - 19th European Symposium on Research in Computer Security, Wroclaw, Poland, September 7-11, 2014. Proceedings, Part II. Pgs. 365–382. 2014. (doi) ()
@inproceedings{sonchack2014less,
  author    = {John Sonchack and
               Adam J. Aviv},
  title     = {{LESS} Is More: Host-Agent Based Simulator for Large-Scale Evaluation
               of Security Systems},
  booktitle = {Computer Security - {ESORICS} 2014 - 19th European Symposium on Research
               in Computer Security, Wroclaw, Poland, September 7-11, 2014. Proceedings,
               Part {II}},
  pages     = {365--382},
  year      = {2014},
  url       = {https://doi.org/10.1007/978-3-319-11212-1_21},
  doi       = {10.1007/978-3-319-11212-1_21},
  timestamp = {Tue, 23 May 2017 01:07:16 +0200},
  biburl    = {https://dblp.org/rec/bib/conf/esorics/SonchackA14},
  bibsource = {dblp computer science bibliography, https://dblp.org}
}

2013

[16]
John Sonchack, Adam J Aviv and Jonathan M Smith. Bridging the Data Gap: Data Related Challenges in Evaluating Large Scale Collaborative Security Systems.. 6th Workshop on Cybersecurity Evaluatoin and Testing (CSET'13). 2013. (pdf) ()
@inproceedings{sonchack2013bridging,
  title       = {Bridging the Data Gap: Data Related Challenges in Evaluating Large Scale Collaborative Security Systems.},
  author      = {Sonchack, John and Aviv, Adam J and Smith, Jonathan M},
  booktitle   = {6th Workshop on Cybersecurity Evaluatoin and Testing},
  series      = {CSET'13},
  year        = {2013},
  documenturl = {papers/jsonch_cset.pdf}
}

2012

[15]
Adam J Aviv, Vin Mannino, Thanat Owlarn, Seth Shannin, Kevin Xu and Boon Thau Loo. Experiences in teaching an educational user-level operating systems implementation project. ACM SIGOPS Operating Systems Review. Vol. 46 (2). Pgs. 80–86. ACM. 2012. (pdf) ()
@article{aviv2012experiences,
  title       = {Experiences in teaching an educational user-level operating systems implementation project},
  author      = {Aviv, Adam J and Mannino, Vin and Owlarn, Thanat and Shannin, Seth and Xu, Kevin and Loo, Boon Thau},
  journal     = {ACM SIGOPS Operating Systems Review},
  volume      = {46},
  number      = {2},
  pages       = {80--86},
  year        = {2012},
  publisher   = {ACM},
  documenturl = {papers/pennos.pdf}
}
[14]
Adam J. Aviv and Benjamin Sapp and Matt Blaze and Jonathan M. Smith. Practicality of accelerometer side channels on smartphones. 28th Annual Computer Security Applications Conference, ACSAC 2012, Orlando, FL, USA, 3-7 December 2012. Pgs. 41–50. 2012. (pdf) (doi) ()
@inproceedings{aviv2012practicality,
  author      = {Adam J. Aviv and
                 Benjamin Sapp and
                 Matt Blaze and
                 Jonathan M. Smith},
  title       = {Practicality of accelerometer side channels on smartphones},
  booktitle   = {28th Annual Computer Security Applications Conference, {ACSAC} 2012,
                 Orlando, FL, USA, 3-7 December 2012},
  pages       = {41--50},
  year        = {2012},
  url         = {http://doi.acm.org/10.1145/2420950.2420957},
  doi         = {10.1145/2420950.2420957},
  timestamp   = {Thu, 20 Dec 2012 09:09:21 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/AvivSBS12},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/aviv-acsac12-accel.pdf}
}
[13]
Adam J. Aviv and Micah Sherr and Matt Blaze and Jonathan M. Smith. Privacy-Aware Message Exchanges for Geographically Routed Human Movement Networks. Computer Security - ESORICS 2012 - 17th European Symposium on Research in Computer Security, Pisa, Italy, September 10-12, 2012. Proceedings. Pgs. 181–198. 2012. (doi) ()
@inproceedings{aviv2012privacyaware,
  author    = {Adam J. Aviv and
               Micah Sherr and
               Matt Blaze and
               Jonathan M. Smith},
  title     = {Privacy-Aware Message Exchanges for Geographically Routed Human Movement
               Networks},
  booktitle = {Computer Security - {ESORICS} 2012 - 17th European Symposium on Research
               in Computer Security, Pisa, Italy, September 10-12, 2012. Proceedings},
  pages     = {181--198},
  year      = {2012},
  url       = {https://doi.org/10.1007/978-3-642-33167-1_11},
  doi       = {10.1007/978-3-642-33167-1_11},
  timestamp = {Fri, 02 Jun 2017 20:48:01 +0200},
  biburl    = {https://dblp.org/rec/bib/conf/esorics/AvivSBS12},
  bibsource = {dblp computer science bibliography, https://dblp.org}
}
[12]
Adam J. Aviv. Side Channels Enabled by Smartphone Interaction. Ph.D. Thesis, University of Pennsylvania. 2012. (pdf) ()
@phdthesis{phdthesis,
  author      = {Adam J. Aviv},
  title       = {Side Channels Enabled by Smartphone Interaction},
  school      = {University of Pennsylvania},
  year        = {2012},
  documenturl = {papers/aviv-thesis.pdf}
}

2011

[11]
Adam J. Aviv, Gaurav Shah and Matt Blaze. Steganographic Timing Channels. Technical Report MS-CIS-11-18. University of Pennsylvania. December 2011. (pdf) ()
@techreport{aviv2011stego,
  author      = {Adam J. Aviv and Gaurav Shah and Matt Blaze},
  title       = {Steganographic Timing Channels},
  institution = {University of Pennsylvania},
  number      = {MS-CIS-11-18},
  year        = {2011},
  month       = dec,
  documenturl = {papers/stego-MS-CIS-11-18.pdf}
}
[10]
Adam J Aviv and Andreas Haeberlen. Challenges in experimenting with botnet detection systems. 4th Workshop on Cybersecurity Evaluatoin and Testing (CSET'11). 2011. (pdf) ()
@inproceedings{aviv2011challenges,
  title       = {Challenges in experimenting with botnet detection systems},
  author      = {Aviv, Adam J and Haeberlen, Andreas},
  booktitle   = {4th Workshop on Cybersecurity Evaluatoin and Testing},
  series      = {CSET'11},
  year        = {2011},
  documenturl = {aviv_cset.pdf}
}

2010

[9]
Andrew G. West and Adam J. Aviv and Jian Chang and Insup Lee. Spam mitigation using spatio-temporal reputations from blacklist history. Twenty-Sixth Annual Computer Security Applications Conference, ACSAC 2010, Austin, Texas, USA, 6-10 December 2010. Pgs. 161–170. 2010. (pdf) (doi) ()
@inproceedings{west2010spam,
  author      = {Andrew G. West and
                 Adam J. Aviv and
                 Jian Chang and
                 Insup Lee},
  title       = {Spam mitigation using spatio-temporal reputations from blacklist history},
  booktitle   = {Twenty-Sixth Annual Computer Security Applications Conference, {ACSAC}
                 2010, Austin, Texas, USA, 6-10 December 2010},
  pages       = {161--170},
  year        = {2010},
  url         = {http://doi.acm.org/10.1145/1920261.1920287},
  doi         = {10.1145/1920261.1920287},
  timestamp   = {Tue, 12 Aug 2014 16:59:10 +0200},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/WestACL10},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/acsac_10_final.pdf}
}
[8]
Adam J Aviv, Micah Sherr, Matt Blaze and Jonathan M Smith. Evading cellular data monitoring with human movement networks. 5th USENIX Workhsop on Hot Topics in Security (HotSec'10). Pgs. 1–9. 2010. ()
@inproceedings{aviv2010evading,
  title     = {Evading cellular data monitoring with human movement networks},
  author    = {Aviv, Adam J and Sherr, Micah and Blaze, Matt and Smith, Jonathan M},
  booktitle = {5th {USENIX} Workhsop on Hot Topics in Security},
  series    = {HotSec'10},
  pages     = {1--9},
  year      = {2010}
}
[7]
Adam J Aviv, Katherine L Gibson, Evan Mossop, Matt Blaze and Jonathan M Smith. Smudge Attacks on Smartphone Touch Screens.. 4th USENIX Workshop on on Offensive Security (WOOT'10). 2010. (pdf) ()
@inproceedings{aviv2010smudge,
  title       = {Smudge Attacks on Smartphone Touch Screens.},
  author      = {Aviv, Adam J and Gibson, Katherine L and Mossop, Evan and Blaze, Matt and Smith, Jonathan M},
  booktitle   = {4th {USENIX} Workshop on  on Offensive Security},
  series      = {WOOT'10},
  year        = {2010},
  documenturl = {papers/aviv-woot10.pdf}
}
[6]
Jason Reed, Adam J. Aviv, Daniel Wagner, Andreas Haeberlen, Benjamin C. Pierce and Jonathan M. Smith. Differential Privacy for Collaborative Security. Proceedings of the Third European Workshop on System Security (EUROSEC '10). Pgs. 1–7. 2010. (doi) ()
@inproceedings{reed2010differential,
  author    = {Reed, Jason and Aviv, Adam J. and Wagner, Daniel and Haeberlen, Andreas and Pierce, Benjamin C. and Smith, Jonathan M.},
  title     = {Differential Privacy for Collaborative Security},
  booktitle = {Proceedings of the Third European Workshop on System Security},
  series    = {EUROSEC '10},
  year      = {2010},
  isbn      = {978-1-4503-0059-9},
  location  = {Paris, France},
  pages     = {1--7},
  numpages  = {7},
  url       = {http://doi.acm.org/10.1145/1752046.1752047},
  doi       = {10.1145/1752046.1752047},
  acmid     = {1752047},
  publisher = {ACM},
  address   = {New York, NY, USA}
}

2009

[5]
Andrew G. West, Adam J. Aviv, Jian Chang, Vinayak S. Prabhu, Matt Blaze, Sampath Kannan, Insup Lee, Jonathan M. Smith and Oleg Sokolsky. QuanTM: A Quantitative Trust Management System. Proceedings of the Second European Workshop on System Security (EUROSEC '09). Pgs. 28–35. 2009. (doi) ()
@inproceedings{west2009quantm,
  author    = {West, Andrew G. and Aviv, Adam J. and Chang, Jian and Prabhu, Vinayak S. and Blaze, Matt and Kannan, Sampath and Lee, Insup and Smith, Jonathan M. and Sokolsky, Oleg},
  title     = {QuanTM: A Quantitative Trust Management System},
  booktitle = {Proceedings of the Second European Workshop on System Security},
  series    = {EUROSEC '09},
  year      = {2009},
  isbn      = {978-1-60558-472-0},
  location  = {Nuremburg, Germany},
  pages     = {28--35},
  numpages  = {8},
  url       = {http://doi.acm.org/10.1145/1519144.1519149},
  doi       = {10.1145/1519144.1519149},
  acmid     = {1519149},
  publisher = {ACM},
  address   = {New York, NY, USA}
}

2008

[4]
Maritza L Johnson, Chaitanya Atreya, Adam J Aviv, Steven M Bellovin and Gail E Kaiser. RUST: A Retargetable Usability Testbed for Web Site Authentication Technologies.. USENIX Workshop on Usability, Psychology and Security (UPSEC'08). 2008. (pdf) ()
@inproceedings{johnson2008rust,
  title       = {RUST: A Retargetable Usability Testbed for Web Site Authentication Technologies.},
  author      = {Johnson, Maritza L and Atreya, Chaitanya and Aviv, Adam J and Bellovin, Steven M and Kaiser, Gail E},
  booktitle   = {{USENIX} Workshop on Usability, Psychology and Security},
  series      = {UPSEC'08},
  year        = {2008},
  documenturl = {papers/johnson.pdf}
}
[3]
Adam Aviv, Pavol Cerny, Sandy Clark, Eric Cronin, Gaurav Shah, Micah Sherr and Matt Blaze. Security evaluation of ES&S voting machines and election management system. Conference on Electronic voting technology. Pgs. 11. 2008. (pdf) ()
@inproceedings{aviv2008security,
  title        = {Security evaluation of ES\&S voting machines and election management system},
  author       = {Aviv, Adam and Cerny, Pavol and Clark, Sandy and Cronin, Eric and Shah, Gaurav and Sherr, Micah and Blaze, Matt},
  booktitle    = {Conference on Electronic voting technology},
  pages        = {11},
  year         = {2008},
  organization = {USENIX Association},
  documenturl  = {papers/ess-evt08.pdf}
}

2007

[2]
Patrick McDaniel, Matt Blaze, Giovanni Vigna, et al. EVEREST: Evaluation and Validation of Election-Related Equipment, Standards and Testing. Technical Report. Ohio Secretary of State. December 2007. (pdf) ()
@techreport{mcdaniel2007everest,
  author      = {Patrick McDaniel and Matt Blaze and Giovanni Vigna and others},
  title       = {EVEREST: Evaluation and Validation of Election-Related Equipment, Standards and Testing},
  institution = {Ohio Secretary of State},
  year        = {2007},
  month       = dec,
  documenturl = {papers/everest-ohio.pdf}
}
[1]
Adam J. Aviv and Michael E. Locasto and Shaya Potter and Angelos D. Keromytis. SSARES: Secure Searchable Automated Remote Email Storage. 23rd Annual Computer Security Applications Conference (ACSAC 2007), December 10-14, 2007, Miami Beach, Florida, USA. Pgs. 129–139. 2007. (pdf) (doi) ()
@inproceedings{aviv2007ssares,
  author      = {Adam J. Aviv and
                 Michael E. Locasto and
                 Shaya Potter and
                 Angelos D. Keromytis},
  title       = {{SSARES:} Secure Searchable Automated Remote Email Storage},
  booktitle   = {23rd Annual Computer Security Applications Conference {(ACSAC} 2007),
                 December 10-14, 2007, Miami Beach, Florida, {USA}},
  pages       = {129--139},
  year        = {2007},
  url         = {https://doi.org/10.1109/ACSAC.2007.30},
  doi         = {10.1109/ACSAC.2007.30},
  timestamp   = {Wed, 10 Jan 2018 13:55:52 +0100},
  biburl      = {https://dblp.org/rec/bib/conf/acsac/AvivLPK07},
  bibsource   = {dblp computer science bibliography, https://dblp.org},
  documenturl = {papers/aviv-SSARES.pdf}
}