Research Topics
Human Factors
My research on human factors examines how people perceive, adopt, and interact with security and privacy technologies. The work spans privacy tool adoption (contact tracing apps, cryptocurrency, PETs), security training design (serious games, awareness posters), practitioner capability (maturity assessments), ethical design of digital services, and the psychological mechanisms - privacy calculus, health belief, social influence, affect - that underlie security and privacy behaviour.
Social Engineering
A subtopic of human factors is social engineering (SE) where my research begins with foundational theory: gaps in SE defences from a social-psychology lens, and a survey of attacker intelligence tools. It then moves through the design and evaluation of a family of serious games (HATCH, PERSUADED, PROTECT, CyberSecurity Awareness Quiz), and then addresses practical deployment concerns including legal compliance, scenario customisation for specific industries, and inclusive design for diverse players. Especially the serious games and the practical deployment topics were supported by the European projects
THREAT-ARREST,
PHOENI2X, and
CyberSec4Europe.
Serious Games & Gamification
This line of work centres on designing, evaluating, and deploying serious games that train players to recognise and defend against cybersecurity threats, with a particular emphasis on social engineering. The game family includes HATCH (a card game for collaborative threat elicitation and security requirements engineering), PERSUADED (inoculation-based resistance training grounded in social psychology), PROTECT (a highly configurable online successor), and a CyberSecurity Awareness Quiz developed within the THREAT-ARREST project. Beyond game design, the research addresses the full deployment lifecycle: systematic scenario creation for specific industries, legal compliance under German labour law, and inclusive design for diverse player populations — since attackers disproportionately target those who are least trained. Several of these contributions were supported by the European projects
THREAT-ARREST,
PHOENI2X, and
CyberSec4Europe.
Privacy Enhancing Technologies
My PETs research spans the full spectrum from infrastructure-level anonymisation to user-facing privacy tools and the decision support needed to choose between them. On the technical side, the work covers anonymisation services (Tor, JonDonym, AN.ON-Next), de-identification techniques for vehicular and mobility data sharing, privacy-preserving machine learning approaches (differential privacy, homomorphic encryption, secure multiparty computation), and a GDPR-aligned framework for selecting PETs based on an organisation's trust model — validated in the automotive domain. Complementing the technical contributions, a series of empirical studies investigates why users do or do not adopt PETs, examining the roles of trust, privacy concerns, perceived anonymity, and willingness to pay, and a separate thread explores what users understand — and fail to understand — about personal information inference from voice recordings and its legal and design implications.
Modeling & Measuring
This research thread develops formal and semi-formal representations of security properties and risks to support engineering and operational decisions. An early contribution surveyed security properties in software engineering and their relationship to modelling notations. More recently the focus has shifted to attack tree analysis extended with asset-level annotations and graph metrics — enabling quantitative risk visualisation for complex infrastructures — and to lightweight risk assessment frameworks (LiSRA) that translate expert-configured attack trees and security controls into transparent, actionable recommendations suitable for organisations without dedicated security expertise.
Security Management
My security management research addresses the organisational and decision-making challenges that arise when implementing and auditing information security. Key contributions include an empirical study revealing that security practitioners struggle to reliably assign ISO/IEC 27002 maturity levels and tend to overestimate their own competence, and a follow-up showing that structured group discussion substantially improves the reliability of control-weight assessments. Further work examines cloud provider selection via CAIQ-based multi-criteria analysis, risk communication through attack tree visualisation, and inter-organisational platforms for critical infrastructure security management, with several contributions shaped by collaborations with German energy providers responding to new regulatory requirements for critical infrastructure certification.
Applied Cryptography
The applied cryptography work focuses on scenarios where standard security models are too strong or too restrictive for practical deployment. A central contribution introduces Sample-or-Random security under Ciphertext-Only attacks (SOR-CO) — a weaker but practically motivated security notion for segment-based visual cryptography used in online banking authentication — and formally establishes its relationship to standard notions. Further work proposes identity-based cryptography with portrait images as public keys for privacy-preserving mobile ticket validation, eliminating the need for a PKI while avoiding unnecessary identity disclosure. More recent contributions address the policy dimension of cryptography, analysing the technical conditions under which encryption remains effective against surveillance measures such as key escrow, backdoors, and source telecommunications interception.