| 2009 | A "nutrition label" for privacy. | Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, Robert W. Reeder |
| 2009 | Textured agreements: re-envisioning electronic consent. | Matthew Kay, Michael A. Terry |
| 2009 | How does the emergence of reputation mechanisms affect the overall trust formation mechanisms, implicit and explicit, in the online environment? | Kristiina Karvonen |
| 2009 | Not one click for security? | Alan H. Karp, Marc Stiegler, Tyler Close |
| 2009 | Conditioned-safe ceremonies and a user study of an application to web authentication. | Chris Karlof, J. D. Tygar, David A. Wagner |
| 2009 | Usability and security of out-of-band channels in secure device pairing protocols. | Ronald Kainda, Ivan Flechais, A. W. Roscoe |
| 2009 | Personal choice and challenge questions: a security and usability assessment. | Mike Just, David Aspinall |
| 2009 | A multi-method approach for user-centered design of identity management systems. | Pooya Jaferian, David Botta, Kirstie Hawkey, Konstantin Beznosov |
| 2009 | Educated guess on graphical authentication schemes: vulnerabilities and countermeasures. | Eiji Hayashi, Jason I. Hong, Nicolas Christin |
| 2009 | New directions in multisensory authentication. | Madoka Hasegawa, Nicolas Christin, Eiji Hayashi |
| 2009 | Games for extracting randomness. | Ran Halprin, Moni Naor |
| 2009 | Machine learning attacks against the Asirra CAPTCHA. | Philippe Golle |
| 2009 | Challenges in supporting end-user privacy and security management with social navigation. | Jeremy Goecks, W. Keith Edwards, Elizabeth D. Mynatt |
| 2009 | Short and long term research suggestions for NSF and NIST. | Nancy Gillis |
| 2009 | Invisible HCI-SEC: ways of re-architecting the operating system to increase usability and security. | Simson L. Garfinkel |
| 2009 | A new graphical password scheme against spyware by using CAPTCHA. | Haichang Gao, Xiyang Liu |
| 2009 | Escape from the matrix: lessons from a case-study in access-control requirements. | Kathi Fisler, Shriram Krishnamurthi |
| 2009 | Privacy stories: confidence in privacy behaviors through end user programming. | Luke Church, Jonathan Anderson, Joseph Bonneau, Frank Stajano |
| 2009 | Sanitization's slippery slope: the design and study of a text revision assistant. | Richard Chow, Ian Oberst, Jessica Staddon |
| 2009 | Privacy suites: shared privacy for social networks. | Joseph Bonneau, Jonathan Anderson, Luke Church |
| 2009 | Graphical passwords as browser extension: implementation and usability study. | Kemal Bicakci, Mustafa Yuceel, Burak Erdeniz, Hakan Gurbaslar, Nart Bedin Atalay |
| 2009 | Social applications: exploring a more secure framework. | Andrew Besmer, Heather Richter Lipford, Mohamed Shehab, Gorrell P. Cheek |
| 2009 | The impact of expressiveness on the effectiveness of privacy mechanisms for location-sharing. | Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh, Tuomas Sandholm, Janice Y. Tsai, Lorrie Faith Cranor, Paul Hankes Drielsma |
| 2008 | Usability of CAPTCHAs or usability issues in CAPTCHA design. | Jeff Yan, Ahmad Salah El Ahmad |
| 2008 | The challenges of using an intrusion detection system: is it worth the effort? | Rodrigo Werlinger, Kirstie Hawkey, Kasia Muldner, Pooya Jaferian, Konstantin Beznosov |