Short CV

Sebastian Pape is a security and privacy manager working at AUMOVIO (formerly known as Continental Automotive Technologies GmbH). He is also a Privatdozent at Goethe University Frankfurt and (co-)founder and managing director of the Social Engineering Academy (SEA) GmbH.
Sebastian successfully completed diplomas in mathematics (Dipl.-Math.) and computer science (Dipl.-Inform.) at Darmstadt University of Technology and holds a doctoral degree (Dr. rer. nat.) from the University of Kassel and a venia legendi for computer science from his habilitation at Goethe University Frankfurt. From 2005 to 2011, he worked as research and teaching assistant at the Database Group (lead by Prof. Dr. Lutz Wegner) of the Department of Electrical Engineering and Computer Science of the University of Kassel. From 2011 to 2015, he was a senior researcher and teaching assistant at the Software Engineering for Critical Systems Group (lead by Prof. Dr. Jan Jürjens) of the Department of Computer Science Department of TU Dortmund University. From October 2014 to January 2015, he also was a visiting researcher (of Prof. Dr. Fabio Massacci) at the security group of the Department of Information Engineering and Computer Science of University of Trento. From October 2018 to August 2019 he was standing in as a professor for business informatics at Regensburg University. From 2015 to 2022 Sebastian was working as senior researcher at the Chair of Mobile Business & Multilateral Security at Goethe University Frankfurt. Outlets of his research include the following journals and conferences:
Lists of publications, given talks, projects I've been involved in, teaching activities and further scientific activities can be found on dedicated pages.

News

Research Interests

Research areas diagram Research topics word cloud
Research Topics Human Factors Serious Games & Gamification Privacy Enhancing Technologies Modeling & Measuring Security Management Applied Cryptography Application Domains Cloud / Edge / Fog Computing Internet of Things (IoT) Augmented Reality Critical Infrastructures E-Commerce Interdisciplinary Work Psychology Economy Law Digital Humanities Scientific Methodology My research sits at the intersection of security, privacy, artificial intelligence, and human behaviour, combining technical contributions with empirical studies and inter-disciplinary perspectives. The work spans several interconnected threads across research topics, application domains, and inter- and transdisciplinary approaches.

Research Topics

The central thread is human factors: understanding how people perceive, adopt, and interact with security and privacy technologies — spanning privacy tool adoption, security training design, practitioner capability assessment, and the psychological mechanisms underlying security and privacy decisions. A significant subtopic is social engineering, where I study both the attacker side (intelligence-gathering tools, psychological exploitation mechanisms) and defences, leading to a family of serious games and gamification approaches — including HATCH, PERSUADED, and PROTECT — designed to train employees and raise security awareness in an engaging and lasting way. On the technical side, my work on Privacy-Enhancing Technologies (PETs) spans the full spectrum from anonymisation infrastructure (Tor, JonDonym, AN.ON-Next) to user-facing privacy tools and GDPR-aligned frameworks for selecting PETs based on an organisation's trust model. Modelling and measuring security and privacy is another core thread, encompassing attack tree analysis with asset-level annotations, graph-based risk visualisation, and the LiSRA lightweight risk assessment framework that translates expert-configured models into actionable recommendations for organisations without dedicated security expertise. In security management, I investigate how organisations assess and implement information security controls — with empirical findings on practitioner overconfidence in maturity assessments and structured methods for improving reliability. Applied cryptography contributions address visual cryptography for online banking authentication, identity-based cryptography with portrait images as public keys for privacy-preserving mobile ticket validation, and the policy implications of surveillance backdoors and key escrow legislation.

Application Domains

These research topics are pursued across a broad range of application domains. In cloud, edge, and fog computing, the work covers combined system and attacker modelling, empirical cloud provider selection studies, and data-protection-by-design mechanisms for connected ecosystems. The Internet of Things strand applies privacy patterns to layered IoT/fog/cloud architectures and empirically evaluates the GDPR compliance of real-world IoT privacy policies across 110 devices. The automotive domain has been a sustained focus: a series of complementary artefacts — system models, attribute-based encryption for purpose limitation, a runtime privacy manager, and a PET selection framework — address the specific privacy engineering challenges of connected and autonomous vehicles, validated in the AUTOPSY project. Research in machine learning addresses explainable ML for default privacy setting prediction, a user-acceptance-based framework for selecting Privacy-Preserving ML techniques (differential privacy, federated learning, secure multiparty computation), and the transparency–trustworthiness trade-off in AI model card design. Augmented reality serves as a living laboratory for studying technology acceptance and privacy concerns in mobile AR, using Pokémon Go as a large-scale real-world case and a vignette experiment (n ≈ 1,100) to quantify the role of permission sensitivity and prior download count. Work on critical infrastructures — primarily with German energy providers responding to KRITIS legislation — spans inter-organisational platform requirements, two longitudinal ISMS adoption surveys, and attack tree tooling for complex infrastructure risk assessment. In e-commerce, the focus is on pseudonymous platform architectures evaluated against LINDDUN privacy threat analysis, demonstrating that meaningful privacy by design is achievable without abandoning existing commercial structures.

Inter- and Transdisciplinary Approaches

The research is enriched by several cross-disciplinary perspectives. From psychology, established social-psychological models (IUIPC, CFIP, TAM, UTAUT2) are applied and extended to understand security and privacy behaviour, including a cross-cultural replication study with over 9,000 Japanese respondents revealing significant differences in the trust–risk pathway across cultures. The economic dimension examines organisational incentive structures for PET adoption and users' willingness to pay for privacy tools such as Tor and JonDonym, addressing the fundamental sustainability problem of privacy-protection markets. Legal perspectives run through the work as a constraint, a driver, and an object of study — from GDPR compliance assessments of IoT policies and longitudinal evaluation of the KRITIS legislation, to analysis of the technical conditions under which encryption can remain effective against legislative surveillance mandates. A digital humanities contribution — the TEICHI framework — brings software engineering methodology to bear on the challenge of publishing TEI-encoded scholarly text editions on the web. Finally, the scientific methodology thread promotes reproducibility and rigour in empirical security and privacy research, through systematic analysis of user study practices across leading security conferences and the open publication of professionally validated German translations of the CFIP and UTAUT2 instruments.