Inter- and Transdisciplinary Work

psychologyPsychology

The psychology strand applies and extends established social-psychological models to understand security and privacy behaviour. Several studies use privacy constructs (IUIPC, CFIP) and technology acceptance models (TAM, UTAUT2) to investigate adoption of PETs and mobile AR apps, finding that perceived anonymity, trust, hedonic motivation, and — most strikingly — childhood brand nostalgia all significantly shape privacy-related decisions and risk perception. A cross-cultural replication of the IUIPC model with more than 9,000 Japanese respondents reveals that the trust–risk pathway differs significantly across cultures, cautioning against uncritical transfer of Western privacy models. On the security side, a dual literature review combining IT security and social psychology perspectives identifies the psychological mechanisms underlying social engineering attacks — authority, social proof, scarcity — and proposes training strategies grounded in those same principles.
Show related bibliography:
  1. Harborth, D. and Pape, S.: Investigating Privacy Concerns Related to Mobile Augmented Reality Apps - A Vignette Based Online Experiment. In Computers in Human Behavior, 122, 2021.
    PDFDOILinkLinkLinkLink Abstract HP21chbBibtexprivacyhuman factorsarpsychologycs4e

  2. Harborth, D. and Pape, S.: Empirically Investigating Extraneous Influences on the ``APCO'' Model - Childhood Brand Nostalgia and the Positivity Bias. In Future Internet, 12(12) (220), 2020.
    PDFDOILinkLinkLinkLink Abstract HP20futureinternetBibtexprivacyhuman factorspsychologyanon

  3. Pape, S.; Ivan, A.; Harborth, D.; Nakamura, T.; Kiyomoto, S.; Takasaki, H. and Rannenberg, K.: Re-evaluating Internet Users' Information Privacy Concerns: The Case in Japan. In AIS Transactions on Replication Research, 6 (18): 1-18, 2020.
    PDFDOILinkLinkLinkno Link Abstract PIHNKTR20trrBibtexprivacyhuman factorsmethodologypsychology

  4. Pape, S.; Ivan, A.; Harborth, D.; Nakamura, T.; Kiyomoto, S.; Takasaki, H. and Rannenberg, K.: Open Materials Discourse: Re-evaluating Internet Users' Information Privacy Concerns: The Case in Japan. In AIS Transactions on Replication Research, 6 (22): 1-7, 2020.
    PDFDOILinkLinkLinkno Link Abstract PIHNKTR20trromdBibtexprivacymethodologypsychology

  5. Pape, S.: Requirements Engineering and Tool-Support for Security and Privacy.
    PDFDOILinkLinkLink Abstract Pape20habilBibtexprivacysecurityhuman factorspetssecurity managementserious gamesocial engineeringcloud computingioteconomylawpsychology

  6. Harborth, D. and Pape, S.: How Nostalgic Feelings Impact Pokémon Go Players - Integrating Childhood Brand Nostalgia into the Technology Acceptance Theory. In Behaviour & Information Technology, 39 (12): 1276-1296, 2019.
    PDFDOILinkLinkLinkLink Abstract HP19bitBibtexinformation systemshuman factorsarpsychologyanon

  7. Harborth, D. and Pape, S.: JonDonym Users' Information Privacy Concerns. In ICT Systems Security and Privacy Protection - 33rd IFIP TC 11 International Conference, SEC 2018, Held at the 24th IFIP World Computer Congress, WCC 2018, Poznan, Poland, September 18-20, 2018, Proceedings, pages 170-184, 2018, Acceptance rate: 27 / 89 = 30.3%.
    PDFPresentation slidesDOILinkLinkLinkLink Dataset Dataset Abstract HP18ifipsecBibtexinformation systemsprivacyhuman factorspetspsychologyanon

  8. Harborth, D. and Pape, S.: Examining Technology Use Factors of Privacy-Enhancing Technologies: The Role of Perceived Anonymity and Trust. In 24th Americas Conference on Information Systems, AMCIS 2018, New Orleans, LA, USA, August 16-18, 2018, Association for Information Systems, 2018.
    PDFDOILinkLinkLinkLink Abstract HP18amcisBibtexinformation systemsprivacyhuman factorspetspsychologyanon

  9. Harborth, D. and Pape, S.: Privacy Concerns and Behavior of Pokémon Go Players in Germany. In Privacy and Identity Management. The Smart Revolution - 12th IFIP WG 9.2, 9.5, 9.6/11.7, 11.6/SIG 9.2.2 International Summer School, Ispra, Italy, September 4-8, 2017, Revised Selected Papers, pages 314-329, Springer International Publishing, IFIP Advances in Information and Communication Technology 526, 2017.
    PDFDOILinkLinkLinkLink Abstract HP17ifipscBibtexinformation systemsprivacyhuman factorspetsarpsychologyanon

  10. Harborth, D. and Pape, S.: Age Matters - Privacy Concerns of Pokémon Go Players in Germany (Extended Abstract)., 2017.
    PDFDOILinkno Link Abstract HP17ifipsc_eaBibtexinformation systemsprivacyhuman factorsarpsychology

  11. Harborth, D. and Pape, S.: Exploring the Hype: Investigating Technology Acceptance Factors of Pokémon Go. In 2017 IEEE International Symposium on Mixed and Augmented Reality, ISMAR 2017, Nantes, France, October 9-13, 2017, pages 155-168, 2017, Acceptance rate: (17)/99 = 17.2 %.
    PDFDOILinkLinkLinkLink Abstract HP17ismarBibtexinformation systemshuman factorsarpsychology

  12. Schaab, P.; Beckers, K. and Pape, S.: Social engineering defence mechanisms and counteracting training strategies. In Information and Computer Security, 25 (2): 206-222, 2017.
    PDFDOILinkLinkLinkLink Abstract SBP17icsBibtexsecuritysocial engineeringpsychology

  13. Schaab, P.; Beckers, K. and Pape, S.: A systematic Gap Analysis of Social Engineering Defence Mechanisms considering Social Psychology. In 10th International Symposium on Human Aspects of Information Security & Assurance, HAISA 2016, Frankfurt, Germany, July 19-21, 2016, Proceedings., 2016.
    PDFDOILinkLinkLinkLink Abstract SBP16haisaBibtexsecuritysocial engineeringpsychology

economyEconomy

The economic dimension of security and privacy research centres on two questions: what drives organisations to invest in PETs, and what determines users' willingness to pay for them. Qualitative interviews with privacy experts identified a layered incentive structure for corporate PET adoption spanning regulatory pressure, competitive advantage, and product-level considerations. On the user side, empirical work on Tor and JonDonym users traces the antecedents of willingness to pay and informs tariff-scheme design, addressing a fundamental sustainability problem for privacy-protection markets. A related thread examines how architects can design pseudonymous e-commerce platforms that remain commercially viable while substantially reducing personal data exposure.
Show related bibliography:
  1. Pape, S.: Requirements Engineering and Tool-Support for Security and Privacy.
    PDFDOILinkLinkLink Abstract Pape20habilBibtexprivacysecurityhuman factorspetssecurity managementserious gamesocial engineeringcloud computingioteconomylawpsychology

  2. Harborth, D.; Cai, X. and Pape, S.: Why Do People Pay for Privacy-Enhancing Technologies? The Case of Tor and JonDonym?. In ICT Systems Security and Privacy Protection - 34th IFIP TC 11 International Conference, SEC 2019, Lisbon, Portugal, June 25-27, 2019, Proceedings, pages 253-267, 2019, Acceptance rate: 26 / 142 = 18.3%.
    PDFDOILinkLinkLinkLink Dataset Dataset Abstract HCP19ifipsecBibtexinformation systemsprivacypetseconomyanon

  3. Harborth, D.; Braun, M.; Grosz, A.; Pape, S. and Rannenberg, K.: Anreize und Hemmnisse für die Implementierung von Privacy-Enhancing Technologies im Unternehmenskontext. In Sicherheit 2018: Sicherheit, Schutz und Zuverlässigkeit, Beiträge der 9. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft für Informatik e.V. (GI), 25.-27. April 2018, Konstanz, pages 29-41, 2018.
    PDFPresentation slidesDOILinkLinkLinkLink Abstract HBGPR18sicherheitBibtexinformation systemsprivacypetseconomyanonsioc

  4. Pape, S.; Tasche, D.; Bastys, I.; Grosz, A.; Laessig, J. and Rannenberg, K.: Towards an Architecture for Pseudonymous E-Commerce -- Applying Privacy by Design to Online Shopping. In Sicherheit 2018: Sicherheit, Schutz und Zuverlässigkeit, Beiträge der 9. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft für Informatik e.V. (GI), 25.-27. April 2018, Konstanz, pages 17-28, 2018.
    PDFPresentation slidesDOILinkLinkLinkLink Abstract PTBGLR18sicherheitBibtexprivacypetse-commerceeconomysioc

lawLaw

Legal and regulatory considerations run through much of the research as a constraint, a driver, or an object of study. Work on IoT privacy policies assesses whether industry practices comply with GDPR, consistently finding large gaps between policy content and regulatory requirements. The KRITIS legislation for German energy providers is studied longitudinally as a natural experiment in regulatory effectiveness, finding that mandated ISMS certification measurably improved both adoption and perceived security. A dedicated legal analysis of the serious game HATCH investigates which scenario types are admissible under German labour law, and a broader policy contribution analyses the technical conditions under which encryption can remain effective against legislative surveillance mandates such as key escrow and backdoors.
Show related bibliography:
  1. Pape, S. and Kipker, D-K.: Case Study: Checking a Serious Security-Awareness Game for its Legal Adequacy. In Datenschutz und Datensicherheit, 45 (5): 310-314, 2021.
    PDFDOILinkLinkLinkLink Abstract PK21dudBibtexsecuritysocial engineeringlawcs4ehatchthreat-arrest

  2. Pape, S.: Requirements Engineering and Tool-Support for Security and Privacy.
    PDFDOILinkLinkLink Abstract Pape20habilBibtexprivacysecurityhuman factorspetssecurity managementserious gamesocial engineeringcloud computingioteconomylawpsychology

  3. Pape, S.; Schmitz, C.; Kipker, D-K. and Sekula, A.: On the use of Information Security Management Systems by German Energy Providers. In Presented at the Fourteenth IFIP Working Group 11.10 International Conference on Critical Infrastructure Protection, 2020.
    PDFPresentation slidesDOIno Link Abstract PSKS20iccipBibtexinformation systemssecuritysecurity managementcritical infrastructureslawcs4esidate

  4. Paul, N.; Tesfay, W. B.; Kipker, D-K.; Stelter, M. and Pape, S.: Assessing Privacy Policies of Internet of Things Services. In ICT Systems Security and Privacy Protection - 33rd IFIP TC 11 International Conference, SEC 2018, Held at the 24th IFIP World Computer Congress, WCC 2018, Poznan, Poland, September 18-20, 2018, Proceedings, pages 156-169, 2018, Acceptance rate: 27 / 89 = 30.3%.
    PDFPresentation slidesDOILinkLinkLinkLink Abstract PTKSP18ifipsecBibtexprivacyiotlawanon

  5. Kipker, D-K.; Pape, S.; Wojak, S. and Beckers, K.: Juristische Bewertung eines Social-Engineering-Abwehr Trainings. In State of the Art: IT-Sicherheit für Kritische Infrastrukturen, pages 112-115, Universität der Bundeswehr, Neubiberg, 2018.
    PDFDOILinkno LinkBibtexsecurityserious gamesocial engineeringlawhatchsidate

digital humanitiesDigital Humanities

My digital humanities work addresses the challenge of publishing TEI-encoded scholarly text editions on the web. The TEICHI framework — developed in collaboration with literary scholars — provides a lightweight, standards-compliant publication pipeline that fills the gap between encoding a document in TEI and making it publicly accessible, without requiring the full infrastructure of specialist repository systems. This work brought software engineering methodology to bear on the practical needs of textual scholarship, and is one of the earlier examples of my interest in designing tools that lower barriers for non-technical domain experts.
Show related bibliography:
  1. Pape, S.; Schöch, C. and Wegner, L.: TEICHI and the Tools Paradox. Developing a Publishing Framework for Digital Editions. In Journal of the Text Encoding Initiative, 2: 1-16, 2012.
    PDFDOILinkLinkLinkno Link Abstract PSW12jteiBibtexsoftware engineeringdigital humanitiesteichi

  2. Pape, S.; Schöch, C. and Wegner, L.: Bringing Bérardier de Bataut's Essai sur le récit to the Web: Editorial Requirements and Publishing Framework (Poster). In Poster at: TEI 2010, The 2010 Conference of the Text Encoding Initiative Consortium, 2010.
    PosterDOIno LinkBibtexsoftware engineeringdigital humanitiesteichi

  3. Pape, S.; Schöch, C. and Wegner, L.: A Framework for TEI-Based Scholarly Text Editions. Technical Report, Universität Kassel, 2010.
    PDFDOILinkno Link Abstract PSW10trBibtexsoftware engineeringdigital humanitiesteichi

methodologyScientific Methodology

The methodology thread addresses the reproducibility and rigour of empirical security and privacy research. A systematic analysis of user studies across three leading security conferences found that while surveys are increasingly common, openly shared data remains entirely absent — motivating a push for more transparent research practice. In support of this, professionally validated German translations of two widely used instruments — the Concerns for Information Privacy (CFIP) scale and the UTAUT2 questionnaire — were developed and made openly available, lowering the barrier for German-language privacy research. Several publications in the corpus are additionally accompanied by open datasets of survey responses from the Tor and JonDonym user studies.
Show related bibliography:
  1. Kröger, J. L.; Gellrich, L.; Pape, S.; Brause, S. R. and Ullrich, S.: Response data - Survey on privacy impacts of voice & speech analysis. DepositOnce, 2021.
    DOILinkno Link Abstract KGPBU21dataBibtexprivacymethodology

  2. Pape, S.; Ivan, A.; Harborth, D.; Nakamura, T.; Kiyomoto, S.; Takasaki, H. and Rannenberg, K.: Re-evaluating Internet Users' Information Privacy Concerns: The Case in Japan. In AIS Transactions on Replication Research, 6 (18): 1-18, 2020.
    PDFDOILinkLinkLinkno Link Abstract PIHNKTR20trrBibtexprivacyhuman factorsmethodologypsychology

  3. Pape, S.; Ivan, A.; Harborth, D.; Nakamura, T.; Kiyomoto, S.; Takasaki, H. and Rannenberg, K.: Open Materials Discourse: Re-evaluating Internet Users' Information Privacy Concerns: The Case in Japan. In AIS Transactions on Replication Research, 6 (22): 1-7, 2020.
    PDFDOILinkLinkLinkno Link Abstract PIHNKTR20trromdBibtexprivacymethodologypsychology

  4. Harborth, D. and Pape, S.: Dataset on Actual Users of the Privacy-Enhancing Technology Jondonym. IEEE Dataport, 2020.
    PDFDOILinkLinkLinkno Link Dataset Dataset Abstract HP20dataportJDBibtexprivacypetsmethodologyanon

  5. Harborth, D. and Pape, S.: Dataset on Actual Users of the Privacy-Enhancing Technology Tor. IEEE Dataport, 2020.
    PDFDOILinkLinkLinkno Link Dataset Dataset Abstract HP20dataportTorBibtexprivacypetsmethodologyanon

  6. Hamm, P.; Harborth, D. and Pape, S.: A Systematic Analysis of User Evaluations in Security Research. In Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES 2019, Canterbury, UK, August 26-29, 2019, ACM, 2019.
    PDFDOILinkLinkLinkLink Abstract HHP19iwsmrBibtexsecuritymethodologycs4e

  7. Harborth, D. and Pape, S.: German Translation of the Unified Theory of Acceptance and Use of Technology 2 (UTAUT2) Questionnaire. Technical Report, SSRN, 2018.
    PDFDOILinkLinkno Link Abstract HP18ssrn_utautBibtexinformation systemsmethodologyanon

  8. Harborth, D. and Pape, S.: German Translation of the Concerns for Information Privacy (CFIP) Construct. Technical Report, SSRN, 2018.
    PDFDOILinkLinkno Link Abstract HP18ssrn_cfipBibtexprivacymethodologyanon