| 2015 | Peace vs. Privacy: Leveraging Conflicting Jurisdictions for Email Security. | Mohammad Mannan, Arash Shahkar, Atieh Saberi Pirouz, Vladimir Rabotka |
| 2015 | Bridging the Trust Gap: Integrating Models of Behavior and Perception. | Raquel Hill, Devan Ray Donaldson |
| 2015 | Milware: Identification and Implications of State Authored Malicious Software. | Trey Herr, Eric Armbrust |
| 2015 | "If you were attacked, you'd be sorry": Counterfactuals as security arguments. | Cormac Herley, Wolter Pieters |
| 2015 | Examining the Contribution of Critical Visualisation to Information Security. | Peter Hall, Claude Heath, Lizzie Coles-Kemp, Axel Tanner |
| 2015 | Choose Your Own Authentication. | Alain Forget, Sonia Chiasson, Robert Biddle |
| 2015 | Towards Managed Role Explosion. | Aaron Elliott, Scott Knight |
| 2015 | The Myth of the Average User: Improving Privacy and Security Systems through Individualization. | Serge Egelman, Eyal Per |
| 2015 | Employee Rule Breakers, Excuse Makers and Security Champions: : Mapping the risk perceptions and emotions that drive security behaviors. | Odette Beris, Adam Beautement, M. Angela Sasse |
| 2015 | Maybe Poor Johnny Really Cannot Encrypt: The Case for a Complexity Theory for Usable Security. | Zinaida Benenson, Gabriele Lenzini, Daniela Oliveira, Simon Parkin, Sven Uebelacker |
| 2014 | A Password Manager that Doesn't Remember Passwords. | Elizabeth Stobert, Robert Biddle |
| 2014 | An Asset to Security Modeling?: Analyzing Stakeholder Collaborations Instead of Threats to Assets. | Andreas Poller, Sven Trpe, Katharina Kinder-Kurlanda |
| 2014 | Cyber Security as Social Experiment. | Wolter Pieters, Dina Hadziosmanovic, Francien Dechesne |
| 2014 | I'm OK, You're OK, the System's OK: Normative Security for Systems. | Olgierd Pieczul, Simon N. Foley, Vivien M. Rooney |
| 2014 | Shifts in the Cybersecurity Paradigm: Zero-Day Exploits, Discourse, and Emerging Institutions. | Andreas Kuehn, Milton Mueller |
| 2014 | Emergent Properties & Security: The Complexity ofSecurity as a Science. | Nathaniel Husted, Steven A. Myers |
| 2014 | Data Is the New Currency. | Carrie Gates, Peter Matthews |
| 2014 | Panel Summary: The Future of Software Regulation. | Benjamin Edwards, Michael E. Locasto, Jeremy Epstein |
| 2014 | Understanding the Experience-Centeredness of Privacy and Security Technologies. | Paul Dunphy, John Vines, Lizzie Coles-Kemp, Rachel Clarke, Vasillis Vlachokyriakos, Peter C. Wright, John C. McCarthy, Patrick Olivier |
| 2014 | Vulnerabilities as Blind Spots in Developer's Heuristic-Based Decision-Making Processes. | Justin Cappos, Yanyan Zhuang, Daniela Oliveira, Marissa Rosenthal, Kuo-Chuan (Martin) Yeh |
| 2014 | Planning and Integrating Deception into Computer Security Defenses. | Mohammed H. Almeshekah, Eugene H. Spafford |
| 2014 | Isn't that Fantabulous: Security, Linguistic and Usability Challenges of Pronounceable Tokens. | Andrew M. White, Katherine Shaw, Fabian Monrose, Elliott Moreton |
| 2013 | Explicit authentication response considered harmful. | Lianying Zhao, Mohammad Mannan |
| 2013 | Designing forensic analysis techniques through anthropology. | Sathya Chandran Sundaramurthy |
| 2013 | Towards narrative authentication: or, against boring authentication. | Anil Somayaji, David Mould, Carson Brown |