| 2026 | SP | What's in the Mandatory USENIX Security 2025 Ethics Sections? Results from a Meta-Analysis. | Rachel Gonzalez Rodriguez, Harshini Sri Ramulu, Yasemin Acar |
| 2026 | SOUPS | Reproductive Security & Privacy Advice on TikTok after the Overturn of Roe. | Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Yasemin Acar, Lucy Simko |
| 2026 | SOUPS | From Thrift Stores to Digital Storefronts: Users' Perspectives on Privacy and Security of Online Second-Hand Shopping in Germany. | Darya Zarkalam, Anna Lena Rotthaler, Lucy Simko, Yasemin Acar |
| 2025 | CCS | Security and Privacy Perceptions of Pakistani Facebook Matrimony Group Users. | Mah Jan Dorazahi, Deepthi Mungara, Yasemin Acar, Harshini Sri Ramulu |
| 2025 | CCS | It Should Be Easy but... New Users' Experiences and Challenges with Secret Management Tools. | Lorenzo Neil, Deepthi Mungara, Laurie A. Williams, Yasemin Acar, Bradley Reaves |
| 2025 | CCS | Poster: Computer Security Researchers' Experiences with Vulnerability Disclosures. | Harshini Sri Ramulu, Anna Lena Rotthaler, Jost Rossel, Rachel Gonzalez Rodriguez, Dominik Wermke, Sascha Fahl, Tadayoshi Kohno, Juraj Somorovsky, Yasemin Acar |
| 2025 | CCS | Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible Future. | Harshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez, Tadayoshi Kohno, Yasemin Acar |
| 2025 | HCI | Smart Home Users' Security and Privacy Perceptions and Actions Differ By Device Category: Results from a U.S. Survey. | Julie M. Haney, Yasemin Acar, Anna Li, Faith Haney |
| 2025 | SP | "It's Time. Time for Digital Security.": An End User Study on Actionable Security and Privacy Advice. | Anna Lena Rotthaler, Harshini Sri Ramulu, Lucy Simko, Sascha Fahl, Yasemin Acar |
| 2025 | SOUPS | More than Usability: Differential Access to Digital Security and Privacy. | Annalina Buckmann, Jan Magnus Nold, Yasemin Acar, Yixin Zou |
| 2024 | CHI | Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter. | Juliane Schmser, Harshini Sri Ramulu, Noah Whler, Christian Stransky, Felix Bensmann, Dimitar Dimitrov, Sebastian Schellhammer, Dominik Wermke, Stefan Dietze, Yasemin Acar, Sascha Fahl |
| 2024 | ICSE | Decomposing and Measuring Trust in Open-Source Software Supply Chains. | Lina Boughton, Courtney Miller, Yasemin Acar, Dominik Wermke, Christian Kstner |
| 2024 | SP | Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User Groups. | Franziska Herbert, Steffen Becker, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Drmuth, Yixin Zou, M. Angela Sasse |
| 2024 | SP | Security, Privacy, and Data-sharing Trade-offs When Moving to the United States: Insights from a Qualitative Study. | Mindy Tran, Collins W. Munyendo, Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Luisa Ball Schnell, Cora Sula, Lucy Simko, Yasemin Acar |
| 2023 | CCS | "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments. | Sabrina Amft, Sandra Hltervennhoff, Nicolas Huaman, Alexander Krause, Lucy Simko, Yasemin Acar, Sascha Fahl |
| 2023 | CCS | "Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure Authentication. | Jan H. Klemmer, Marco Gutfleisch, Christian Stransky, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
| 2023 | CHI | A World Full of Privacy and Security (Mis)conceptions? Findings of a Representative Survey in 12 Countries. | Franziska Herbert, Steffen Becker, Leonie Schaewitz, Jonas Hielscher, Marvin Kowalewski, M. Angela Sasse, Yasemin Acar, Markus Drmuth |
| 2023 | SP | It's like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security. | Marcel Fourn, Dominik Wermke, William Enck, Sascha Fahl, Yasemin Acar |
| 2023 | SP | "We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups. | Dilara Keklloglu, Yasemin Acar |
| 2023 | SP | "In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in Kenya. | Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
| 2023 | SP | "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain. | Dominik Wermke, Jan H. Klemmer, Noah Whler, Juliane Schmser, Harshini Sri Ramulu, Yasemin Acar, Sascha Fahl |
| 2023 | SOUPS | "Would You Give the Same Priority to the Bank and a Game? I Do Not!" Exploring Credential Management Strategies and Obstacles during Password Manager Setup. | Sabrina Amft, Sandra Hltervennhoff, Nicolas Huaman, Yasemin Acar, Sascha Fahl |
| 2023 | SOUPS | Who Comes Up with this Stuff? Interviewing Authors to Understand How They Produce Security Advice. | Lorenzo Neil, Harshini Sri Ramulu, Yasemin Acar, Bradley Reaves |
| 2022 | SP | How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview Study. | Marco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
| 2022 | SP | "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing Attacks. | Jan Jancar, Marcel Fourn, Daniel De Almeida Braga, Mohamed Sabt, Peter Schwabe, Gilles Barthe, Pierre-Alain Fouque, Yasemin Acar |
| 2022 | SP | "Desperate Times Call for Desperate Measures": User Concerns with Mobile Loan Apps in Kenya. | Collins W. Munyendo, Yasemin Acar, Adam J. Aviv |
| 2022 | SP | 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire University. | Christian Stransky, Oliver Wiese, Volker Roth, Yasemin Acar, Sascha Fahl |
| 2022 | SP | Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects. | Dominik Wermke, Noah Whler, Jan H. Klemmer, Marcel Fourn, Yasemin Acar, Sascha Fahl |
| 2022 | SOUPS | If You Can't Get Them to the Lab: Evaluating a Virtual Study Environment with Security Information Workers. | Nicolas Huaman, Alexander Krause, Dominik Wermke, Jan H. Klemmer, Christian Stransky, Yasemin Acar, Sascha Fahl |
| 2021 | SP | They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and Websites. | Nicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar, Sascha Fahl |
| 2021 | SOUPS | Never ever or no matter what: Investigating Adoption Intentions and Misconceptions about the Corona-Warn-App in Germany. | Maximilian Hring, Eva Gerlitz, Christian Tiefenau, Matthew Smith, Dominik Wermke, Sascha Fahl, Yasemin Acar |
| 2021 | SOUPS | Investigating Web Service Account Remediation Advice. | Lorenzo Neil, Elijah Robert Bouma-Sims, Evan Lafontaine, Yasemin Acar, Bradley Reaves |
| 2021 | SOUPS | On the Limited Impact of Visualizing Encryption: Perceptions of E2E Messaging Security. | Christian Stransky, Dominik Wermke, Johanna Schrader, Nicolas Huaman, Yasemin Acar, Anna Lena Fehlhaber, Miranda Wei, Blase Ur, Sascha Fahl |
| 2020 | CHI | Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs. | Peter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha Fahl |
| 2020 | HCI | Smart Home Security and Privacy Mitigations: Consumer Perceptions, Practices, and Challenges. | Julie M. Haney, Susanne M. Furman, Yasemin Acar |
| 2020 | SOUPS | Cloudy with a Chance of Misconceptions: Exploring Users' Perceptions and Expectations of Security and Privacy in Cloud Office Suites. | Dominik Wermke, Nicolas Huaman, Christian Stransky, Niklas Busch, Yasemin Acar, Sascha Fahl |
| 2018 | ACSAC | A Large Scale Investigation of Obfuscation Use in Google Play. | Dominik Wermke, Nicolas Huaman, Yasemin Acar, Bradley Reaves, Patrick Traynor, Sascha Fahl |
| 2018 | WWW | Your Secrets Are Safe: How Browsers' Explanations Impact Misconceptions About Private Browsing Mode. | Yuxi Wu, Panya Gupta, Miranda Wei, Yasemin Acar, Sascha Fahl, Blase Ur |
| 2018 | SP | The Rise of the Citizen Developer: Assessing the Security Impact of Online App Generators. | Marten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar, Sascha Fahl, Christian Rossow, Giancarlo Pellegrino, Sven Bugiel, Michael Backes |
| 2018 | SOUPS | Developers Deserve Security Warnings, Too: On the Effect of Integrated Security Advice on Cryptographic API Misuse. | Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian Mller, Yasemin Acar, Sascha Fahl |
| 2018 | SOUPS | "We make it a big deal in the company": Security Mindsets in Organizations that Develop Cryptographic Products. | Julie M. Haney, Mary Theofanos, Yasemin Acar, Sandra Spickard Prettyman |
| 2017 | CCS | Keep me Updated: An Empirical Study of Third-Party Library Updatability on Android. | Erik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar, Michael Backes |
| 2017 | CCS | A Stitch in Time: Supporting Android Developers in WritingSecure Code. | Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, Sascha Fahl |
| 2017 | SP | Comparing the Usability of Cryptographic APIs. | Yasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel, Doowon Kim, Michelle L. Mazurek, Christian Stransky |
| 2017 | SP | Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security. | Felix Fischer, Konstantin Bttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, Sascha Fahl |
| 2017 | SOUPS | Security Developer Studies with GitHub Users: Exploring a Convenience Sample. | Yasemin Acar, Christian Stransky, Dominik Wermke, Michelle L. Mazurek, Sascha Fahl |
| 2016 | SP | SoK: Lessons Learned from Android Security Research for Appified Software Platforms. | Yasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl, Patrick D. McDaniel, Matthew Smith |
| 2016 | SP | You Get Where You're Looking for: The Impact of Information Sources on Code Security. | Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle L. Mazurek, Christian Stransky |
| 2015 | CCS | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits. | Henning Perl, Sergej Dechand, Matthew Smith, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, Yasemin Acar |
| 2014 | CCS | Why eve and mallory (also) love webmasters: a study on the root causes of SSL misconfigurations. | Sascha Fahl, Yasemin Acar, Henning Perl, Matthew Smith |
| 2013 | SOUPS | On the ecological validity of a password study. | Sascha Fahl, Marian Harbach, Yasemin Acar, Matthew Smith |