Towards Robust Experimental Design for User Studies in Security and Privacy

Authors: 

Kat Krol, Jonathan M. Spring, Simon Parkin and M. Angela Sasse, University College London

Abstract: 

Background: Human beings are an integral part of computer security, whether we actively participate or simply build the systems. Despite this importance, understanding users and their interaction with security is a blind spot for most security practitioners and designers.

Aim: Define principles for conducting experiments into usable security and privacy, to improve study robustness and usefulness.

Data: The authors’ experiences conducting several research projects complemented with a literature survey.

Method: We extract principles based on relevance to the advancement of the state of the art. We then justify our choices by providing published experiments as cases of where the principles are and are not followed in practice to demonstrate the impact. Each principle is a discipline-specific instantiation of desirable experiment-design elements as previously established in the domain of philosophy of science.

Results: Five high-priority principles – (i) give participants a primary task; (ii) incorporate realistic risk; (iii) avoid priming the participants; (iv) perform double-blind experiments whenever possible and (v) think carefully about how meaning is assigned to the terms threat model, security, privacy, and usability.

Conclusion: The principles do not replace researcher acumen or experience, however they can provide a valuable service for facilitating evaluation, guiding younger researchers and students, and marking a baseline common language for discussing further improvements.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {201478,
author = {Kat Krol and Jonathan M. Spring and Simon Parkin and M. Angela Sasse},
title = {Towards Robust Experimental Design for User Studies in Security and Privacy},
booktitle = {The LASER Workshop: Learning from Authoritative Security Experiment Results (LASER 2016)},
year = {2016},
isbn = {978-1-931971-35-5},
address = {San Jose, CA},
pages = {21--31},
url = {https://www.usenix.org/conference/laser2016/program/presentation/krol},
publisher = {USENIX Association},
month = may
}