Inter- and Transdisciplinary Work
Psychology
The psychology strand applies and extends established social-psychological models to understand security and privacy behaviour. Several studies use privacy constructs (IUIPC, CFIP) and technology acceptance models (TAM, UTAUT2) to investigate adoption of PETs and mobile AR apps, finding that perceived anonymity, trust, hedonic motivation, and — most strikingly — childhood brand nostalgia all significantly shape privacy-related decisions and risk perception. A cross-cultural replication of the IUIPC model with more than 9,000 Japanese respondents reveals that the trust–risk pathway differs significantly across cultures, cautioning against uncritical transfer of Western privacy models. On the security side, a dual literature review combining IT security and social psychology perspectives identifies the psychological mechanisms underlying social engineering attacks — authority, social proof, scarcity — and proposes training strategies grounded in those same principles.
Economy
The economic dimension of security and privacy research centres on two questions: what drives organisations to invest in PETs, and what determines users' willingness to pay for them. Qualitative interviews with privacy experts identified a layered incentive structure for corporate PET adoption spanning regulatory pressure, competitive advantage, and product-level considerations. On the user side, empirical work on Tor and JonDonym users traces the antecedents of willingness to pay and informs tariff-scheme design, addressing a fundamental sustainability problem for privacy-protection markets. A related thread examines how architects can design pseudonymous e-commerce platforms that remain commercially viable while substantially reducing personal data exposure.
Law
Legal and regulatory considerations run through much of the research as a constraint, a driver, or an object of study. Work on IoT privacy policies assesses whether industry practices comply with GDPR, consistently finding large gaps between policy content and regulatory requirements. The KRITIS legislation for German energy providers is studied longitudinally as a natural experiment in regulatory effectiveness, finding that mandated ISMS certification measurably improved both adoption and perceived security. A dedicated legal analysis of the serious game HATCH investigates which scenario types are admissible under German labour law, and a broader policy contribution analyses the technical conditions under which encryption can remain effective against legislative surveillance mandates such as key escrow and backdoors.
Digital Humanities
My digital humanities work addresses the challenge of publishing TEI-encoded scholarly text editions on the web. The TEICHI framework — developed in collaboration with literary scholars — provides a lightweight, standards-compliant publication pipeline that fills the gap between encoding a document in TEI and making it publicly accessible, without requiring the full infrastructure of specialist repository systems. This work brought software engineering methodology to bear on the practical needs of textual scholarship, and is one of the earlier examples of my interest in designing tools that lower barriers for non-technical domain experts.
Scientific Methodology
The methodology thread addresses the reproducibility and rigour of empirical security and privacy research. A systematic analysis of user studies across three leading security conferences found that while surveys are increasingly common, openly shared data remains entirely absent — motivating a push for more transparent research practice. In support of this, professionally validated German translations of two widely used instruments — the Concerns for Information Privacy (CFIP) scale and the UTAUT2 questionnaire — were developed and made openly available, lowering the barrier for German-language privacy research. Several publications in the corpus are additionally accompanied by open datasets of survey responses from the Tor and JonDonym user studies.