Application Domains
Cloud / Edge / Fog Computing
My cloud computing research combines security modelling with empirical investigation of the organisational challenges cloud adoption presents. An early contribution developed a combined system and attacker model for infrastructure clouds that enables customers to construct and reason about attack scenarios across the blurred boundary between insiders and outsiders. Subsequent work examined empirically how German organisations actually choose cloud providers — finding compliance rather than security to be the dominant driver — and proposed a CAIQ-based multi-criteria approach to make provider comparisons tractable. A more recent contribution addresses data protection by design in connected vehicle cloud ecosystems, using attribute-based encryption to technically enforce GDPR purpose limitation.
Internet of Things (IoT)
My IoT research addresses privacy engineering at the architectural level and the adequacy of privacy governance across connected devices. A foundational contribution maps established software privacy patterns onto the layered IoT / fog / cloud architecture, showing how the edge layer can host meaningful privacy controls close to the data source, illustrated with a smart vehicles scenario. Empirically, an assessment of 110 IoT devices against a GDPR-derived framework showed that most privacy policies are inadequate to satisfy regulatory requirements. Further work investigates social factors shaping adoption of privacy-sensitive IoT services — including contact tracing apps — and analyses the specific privacy threats and pattern gaps that arise in next-generation use cases such as robotaxis.
Automotive
The automotive strand is a sustained line of work on privacy engineering for connected and autonomous vehicles. The work produced a series of complementary artefacts: a system model for the automotive domain identifying suitable locations for PETs, a purpose-limitation enforcement mechanism using attribute-based encryption, a privacy manager component for runtime control of in-vehicle data flows, and a GDPR-grounded PET selection framework — all integrated into the AUTOPSY project framework and validated on a location-based services demonstrator. A parallel thread critically evaluates existing PET selection methods against a realistic robotaxi use case, exposing significant shortcomings and providing concrete recommendations for methodology development.
Machine Learning
My machine learning research focuses on the intersection of privacy and user-centred AI design. Contributions include an explainable ML model for predicting appropriate default privacy settings in line with GDPR interpretability requirements, and a framework — grounded in expert input — that maps Privacy-Preserving Machine Learning (PPML) techniques (differential privacy, federated learning, secure multiparty computation) to user acceptance criteria, enabling privacy-by-design choices that reflect what users actually value. A separate thread examines the user perspective on AI transparency: an experiment on AI model cards reveals a usability–trustworthiness trade-off in disclosure design, while a large-scale analysis of generative AI app reviews finds that real users' concerns centre on validity and safety rather than privacy, pointing to a significant awareness gap.
Augmented Reality
My AR research uses Pokémon Go — a rare example of a mainstream AR app with millions of real-world users — as a living laboratory to investigate both technology acceptance and privacy concerns in mobile augmented reality. Studies employing the UTAUT2 model identify hedonic motivation as the dominant adoption driver, while an extension incorporating childhood brand nostalgia reveals that brand-induced positivity can substantially bias privacy risk calculus. A complementary large-scale vignette experiment (n=1,100) on mobile AR privacy finds that permission sensitivity and prior download count drive user concern, with AR-specific contextual factors playing a smaller role than expected — providing practical guidance for developers and regulators.
Critical Infrastructures
Much of my critical infrastructure work was conducted within the SIDATE project, a collaboration with small and medium-sized German energy providers responding to new KRITIS legislation that mandated IT security certification. The research spans the full practical lifecycle: eliciting requirements for an inter-organisational IT security management platform, tracking ISMS adoption through two longitudinal surveys — finding that regulatory pressure successfully increased both adoption rates and perceived security — and contributing attack tree modelling tools and lightweight risk assessment frameworks to support security assessments in complex infrastructure environments.
E-Commerce
In the e-commerce domain, the work examines how online shopping platforms can be redesigned to minimise unnecessary data disclosure. The key contribution proposes and compares several architectural designs for a pseudonymous e-commerce platform, evaluating each against privacy threat analysis (LINDDUN), transparency, usability, and business model compatibility — demonstrating that meaningful privacy by design is achievable without abandoning existing commercial structures.