| 2017 | Weighing Context and Trade-offs: How Suburban Adults Selected Their Online Security Posture. | Scott Ruoti, Tyler Monson, Justin Wu, Daniel Zappala, Kent E. Seamons |
| 2017 | You Want Me To Do What? A Design Study of Two-Factor Authentication Messages. | Elissa M. Redmiles, Everest Liu, Michelle L. Mazurek |
| 2017 | "I feel stupid I can't delete...": A Study of Users' Cloud Deletion Practices and Coping Strategies. | Kopo M. Ramokapane, Awais Rashid, Jose M. Such |
| 2017 | The importance of visibility for folk theories of sensor data. | Emilee J. Rader, Janine Slaker |
| 2017 | Valuating Friends' Privacy: Does Anonymity of Sharing Personal Data Matter? | Yu Pu, Jens Grossklags |
| 2017 | Modeling Aggregate Security with User Agents that Employ Password Memorization Techniques. | Christopher Novak, Jim Blythe, Ross Koppel, Vijay H. Kothari, Sean W. Smith |
| 2017 | Can we fight social engineering attacks by social means? Assessing social salience as a means to improve phish detection. | James Nicholson, Lynne M. Coventry, Pam Briggs |
| 2017 | Touchscreen Biometrics Across Multiple Devices. | Tuan Ngyuen, Jonathan Voris |
| 2017 | Smartwatches Locking Methods: A Comparative Study. | Toan Nguyen, Nasir D. Memon |
| 2017 | Privacy Expectations and Preferences in an IoT World. | Pardis Emami Naeini, Sruti Bhagavatula, Hana Habib, Martin Degeling, Lujo Bauer, Lorrie Faith Cranor, Norman M. Sadeh |
| 2017 | Folk Risk Analysis: Factors Influencing Security Analysts' Interpretation of Risk. | Andrew M'manga, Shamal Faily, John McAlaney, Christopher Williams |
| 2017 | A Gamified Approach to Improve Users' Memorability of Fall-back Authentication. | Nicholas Micallef, Nalin Asanka Gamagedara Arachchilage |
| 2017 | A Second Look at Password Composition Policies in the Wild: Comparing Samples from 2010 and 2016. | Peter Mayer, Jan Kirchner, Melanie Volkamer |
| 2017 | Impact of User Characteristics on Attitudes Towards Automatic Mobile Application Updates. | Arunesh Mathur, Marshini Chetty |
| 2017 | Learning System-assigned Passwords: A Preliminary Study on the People with Learning Disabilities. | Sonali Tukaram Marne, Mahdi Nasrullah Al-Ameen, Matthew K. Wright |
| 2017 | Security and privacy design considerations for low-literate users in developing regions. | Shrirang Mare, Aditya Vashistha, Richard Anderson |
| 2017 | How Effective is Anti-Phishing Training for Children? | Elmer Lastdrager, Ins Carvajal Gallardo, Pieter H. Hartel, Marianne Junger |
| 2017 | Inclusive persuasion for security software adoption. | Eunjin Jung, Evelyn Y. Ho |
| 2017 | Formal Mental Models for Inclusive Privacy and Security. | Adam Houser, Matthew L. Bolton |
| 2017 | Key-bored to Tears: The Usability Cost of Character Authentication on Mobile Devices. | Ann-Marie Horcher |
| 2017 | Skills and Characteristics of Successful Cybersecurity Advocates. | Julie M. Haney, Wayne G. Lutters |
| 2017 | "I want my money back!" Limiting Online Password-Guessing Financially. | Maximilian Golla, Daniel V. Bailey, Markus Drmuth |
| 2017 | New Me: Understanding Expert and Non-Expert Perceptions and Usage of the Tor Anonymity Network. | Kevin Gallagher, Sameer Patil, Nasir D. Memon |
| 2017 | Ask Me Anything: A Conversational Interface to Augment Information Security Workers. | Bobby Filar, Richard Seymour, Matthew Park |
| 2017 | Authentication on the Go: Assessing the Effect of Movement on Mobile Device Keystroke Dynamics. | Heather Crawford, Ebad Ahmadzadeh |