Sign in

Sauvik Das

@sauvik.me
483 followers 117 following 179 posts

I work on human-centered {security|privacy|computing}. Associate Professor (w/o tenure) at @hcii.cmu.edu. Director of the SPUD (Security, Privacy, Usability, and Design) Lab. Non-Resident Fellow @cendemtech.bsky.social

PostsRepliesMedia
Sauvik Das @sauvik.me · 27/09/2026
New #UIST2026 paper led by @yuxuanli1225.bsky.social WhatIf lets policymakers steer, inspect, and compare large-scale LLM-powered social simulations in real time. It helped emergency professionals recognize previously unrecognized planning vulnerabilities. Paper: sauvikdas.com/papers/74/se...
000
Sauvik Das @sauvik.me · 26/09/2026
New #AIES2026 paper led by @hankhplee: Agentic AI devs focus on product and business risks over downstream risks like job displacement and privacy. Lacking mature controls, they contain risk by constraining the same capabilities that make agents useful. sauvikdas.com/papers/73/s...
020
Sauvik Das @sauvik.me · 06/07/2026
I stopped using Google Analytics on my site almost 10 years ago because I didn't want to contribute to even more cookie-based tracking. Over the weekend, I used a Claude loop to set up self-hosted, cookieless analytics and I'm...pleasantly surprised that it worked so well.
010
Sauvik Das @sauvik.me · 31/03/2026
The overleaf git project for one of my #uist2026 submissions was assigned a uuid starting with "67". I believe this lets me mine the latest block on the gen alpha blockchain using the "Proof of Relevance" protocol. Who should I speak with about this
030
Sauvik Das @sauvik.me · 13/03/2026
I am working on a UX audit agent for my company (fuguux.com/). I passed in the output of our audit agent into Claude code for my personal website and...voila, a refreshed and much better site. Surprised it worked! Before -> after sauvik.me
110
Sauvik Das @sauvik.me · 10/02/2026
(1) Pair risk flags with actionable guidance (how to preserve intent, reduce risk) (2) Explain plausible attacker exploits (not just “risk: high”) (3) Communicate risk without pushing unnecessary self-censorship (4) Use intuitive language/visuals; avoid jargon
100
Sauvik Das @sauvik.me · 10/02/2026
Interestingly, no single UI for presenting PREs to users “won”. Participants didn’t show a strong overall preference across the five designs (though “risk by disclosure” tended to be liked more; the meter less). So what *should* PRE designs do? 4 design recommendations:
100
Sauvik Das @sauvik.me · 10/02/2026
The 5 concepts ranged from: (1) raw k-anonymity score (2) a re-identifiability “meter” (3) low/med/high simplified risk (4) threat-specific risk (5) “risk by disclosure” (which details contribute most)
100
Sauvik Das @sauvik.me · 10/02/2026
Method: speculative design + design fictions. We storyboarded 5 PRE UI concepts using comic-boards (different ways to show risk + what’s driving it).
100
Sauvik Das @sauvik.me · 10/02/2026
This paper explores how to present “population risk estimates” (PREs): an AI-driven estimate of how uniquely identifiable you are based on your disclosures. Smaller “k” means you're more identifiable (e.g., k=1 means only 1 person matches everything you have disclosed)
100
Sauvik Das @sauvik.me · 10/02/2026
📣 New at #CHI2026 People share sensitive things “anonymously”… but anonymity is hard to reason about. What if we could quantify re-identification risk with AI? How should we present those AI-estimated risks to users? Led by my student Isadora Krsek Paper: www.sauvik.me/papers/70/s...
111
Sauvik Das @sauvik.me · 09/02/2026
Check out the paper! It's one of the coolest papers from my lab in that includes both a fully working system *and* a very comprehensive mixed-methods evaluation. Still had a reviewer that wanted even more, but c'est la vie 😂 www.sauvik.me/papers/69/s... Thank for the support @NSF!
000
Sauvik Das @sauvik.me · 09/02/2026
A surprising aside: we added a number of design frictions to Privy-LLM to encourage critical thinking. As a result, some practitioners rated Privy-LLM as being *less helpful* than those who used just the static template (where they had to do much more of the work manually).
100
Sauvik Das @sauvik.me · 09/02/2026
But outputs from the LLM-supported version was rated higher quality overall: clearer, more correct, more relevant/severe risks; and mitigation plans that experts saw as more effective and more product-specific.
100
Sauvik Das @sauvik.me · 09/02/2026
Both versions enabled practitioners to produce strong privacy impact assessments (as judged by experts). So the scaffolding itself mattered irrespective of the AI-support provided.
100
Sauvik Das @sauvik.me · 09/02/2026
Privy then helps folks: • articulate how each risk could show up in this specific product • prioritize what is most relevant and severe • draft mitigations that protect people without flattening the feature’s utility.
100
Sauvik Das @sauvik.me · 09/02/2026
In a vacuum, it's hard to answer how a product will lead to privacy risks. Privy guides folks through a workflow to articulate: • who uses the product + who’s affected • what the AI can do • what data it needs / produces → then maps that to the AI privacy taxonomy.
110
Sauvik Das @sauvik.me · 09/02/2026
📣 New at #CHI2026 Developing a new AI product? How would you figure out what are the privacy risks? Privy help non-privacy expert practitioners create high quality privacy impact assessments for early-stage AI products. Led by @hankhplee.bsky.social Paper: www.sauvik.me/papers/69/s...
151
Sauvik Das @sauvik.me · 19/11/2025
I'm fortunate to be able to teach my new class on "Building Technologies for the Resistance" next semester. If you're a CMU student, consider enrolling! This will be a collaborative, project-based class where you'll get to prototype resistance technologies.
292
Sauvik Das @sauvik.me · 20/10/2025
Two spuddies will be at #CSCW2025: @yuxiwu.com will present our work on designing citizen harm reporting interfaces for privacy (and is on the job market!). Isadora Krsek will present our work on user reactions to AI-identified self-disclosure risks online.
172
Sauvik Das @sauvik.me · 13/10/2025
The 1st Human-Centered AI, Privacy, and Security (#HAIPS2025) workshop at CCS will happen on Oct 17th! We have two amazing keynote speakers (@pgk.bsky.social and @jas0nh0ng.bsky.social), and a slate of insightful and provocative papers. Agenda here: haips.com/#dates #CCS2025 #AcademicSky
010
Sauvik Das @sauvik.me · 27/09/2025
📣 Accepted to #AIES2025: What do the audio datasets powering generative audio models actually contain? (led by @willie-agnew.bsky.social) Answer: Lots of old audio content that is mostly English, often biased, and of dubious copyright / permissioning status. Paper: www.sauvik.me/papers/65/s...
131
Sauvik Das @sauvik.me · 26/09/2025
Importantly, we found that Imago Obscura helps *address* privacy risks without impacting sharing intent. People believed it *greatly* reduced privacy risks for images they previously wanted to share but did not share for privacy reasons, with no difference in sharing intent.
110
Sauvik Das @sauvik.me · 26/09/2025
In a summative evaluation, we found that Imago Obscura effectively improved users' awareness of / motivation to address / ability to address key privacy risks in images they wanted to share online.
110
Sauvik Das @sauvik.me · 26/09/2025
It can identify when the background of an image might uniquely identify a user's location and replace it to mitigate that risk. It can recognize when bystanders may be in the background of a photo and provides simple mechanisms to replace those bystanders.
110
Sauvik Das @sauvik.me · 26/09/2025
Examples: Imago Obscura flags content that could uniquely identify an individual, like an obvious tattoo, and can generate realistic and less identifiable replacements. It also identifies information that a user might consider confidential, and can obfuscate it via, e.g., blurring.
110
Sauvik Das @sauvik.me · 26/09/2025
A longstanding usable privacy challenge is helping users understand and address privacy risks in personal images they share online, from location risks to bystander risks. Imago Obscura lets users bring-their-own-threat model, and then helps identify and address specific risks.
110
Sauvik Das @sauvik.me · 26/09/2025
🔐 New #UIST2025 paper by @kyzyl.me Imago Obscura uses #vision #language #models to understand user #privacy concerns, improve their awareness of image privacy risks, and their ability to address these risks. 📜: sauvik.me/papers/66/se... 🔗: cmu-spuds.github.io/imago-obscura/ #PrivacySky
141
Sauvik Das @sauvik.me · 18/09/2025
Honestly, now I want to write a piper titled: "[mention a specific relevant paper by them]"
030
Sauvik Das @sauvik.me · 21/07/2025
Who are all you people searching for my thumbprint?!
000
Sauvik Das @sauvik.me · 14/07/2025
Maybe he was going for a Dreyfussian Man?
120
Sauvik Das @sauvik.me · 01/07/2025
As of today, I am officially Associate Professor* at @hcii.cmu.edu. Surreal — I was out of my depth when I started. Couldn't have done it without my incredible students — the true brains of the operation — and the support of my mentors. Thank you all! * not yet tenured, because CMU
2180
Sauvik Das @sauvik.me · 18/06/2025
Quite a notification from LinkedIn...@mmazurek.bsky.social
010
Sauvik Das @sauvik.me · 27/05/2025
📢 We now have two amazing keynote speakers lined up for #HAIPS2025 (the 1st Workshop on Human-Centered AI, Privacy, and Security)! @jas0nh0ng.bsky.social and @pgk.bsky.social Submit your: - Original papers - Encore papers - SoK papers - Vision papers by June 20th! 💻http://haips.com
010
Sauvik Das @sauvik.me · 13/05/2025
😬In sims, 1/100 Asian-coded agents will join a protest if told they shouldn't. All 100 Black-coded agents will join anyway. New #Facct2025 paper led by @yuxuanli1225.bsky.social Actions Speak Louder than Words: Agent Decisions Reveal Implicit Biases in Language Models sauvikdas.com/papers/64/se...
034
Sauvik Das @sauvik.me · 25/04/2025
En route to #chi2025! 1) Sunday: I will present a keynote talk at the computational UI workshop — the first public discussion of what we're doing at fuguUX, the company I'm co-founding with @jas0nh0ng.bsky.social . "Towards Smart, Automated UI Assessments at Scale" 1/3
181
Sauvik Das @sauvik.me · 12/04/2025
My third Ph.D. student, Jacob Logas, successfully defended his dissertation yesterday! Jacob developed a framework for creating computationally aesthetic anti-facial recognition perturbations on images. Details to come! He will be joining Franklin & Marshall as an assistant professor. Congrats!
0101
Sauvik Das @sauvik.me · 08/03/2025
Hey look at that my 5yo already knows that 0-indexing is superior. This bodes well
050
Sauvik Das @sauvik.me · 03/03/2025
The scale of the problem is massive: An estimated 900 million* people worldwide own cryptocurrency, up from just 5M in 2016. Yet only 43% of crypto users in our survey with 643 participants could correctly identify a seed phrase from an image! * www.statista.com/statistics/1...
100
Sauvik Das @sauvik.me · 03/03/2025
First, what's a seed phrase? It's a list of words (typically 24) that gives COMPLETE access to a “self-custodied” crypto wallet. This list of words can be used to derive the public/private keypair used to access one's crypto assets. Many crypto users are utterly confused about what they are.
100
Sauvik Das @sauvik.me · 03/03/2025
📣 New research: Only 43% of 643 crypto users surveyed in our #CHI2025 study correctly identified a seed phrase from an image; 58% of those thought they choose their own, like a password. These, and other, misconceptions put these users at high risk. Read the paper: sauvikdas.com/papers/63/se... 🧵👇
120
Sauvik Das @sauvik.me · 26/02/2025
Key findings: Users felt MORE concerned when: - In public vs. private locations - Permissions didn't match context expectations - Apps requested sensitive permissions (camera, mic, calls)
100
Sauvik Das @sauvik.me · 26/02/2025
What does “concern” mean? We had participants rate both “concern” level and pick from a range of affective words that described their state. High concern was correlated with feeling “hostile” or “distressed”; low concern was correlated with feeling “indifferent” or “curious”.
100
Sauvik Das @sauvik.me · 26/02/2025
🔒 Our new #USEC2025 paper shows that by automating permission decisions based on prior decisions, we risk NORMALIZING privacy discomfort rather than reducing it. "Modeling End-User Affective Discomfort With Mobile App Permissions" Paper: sauvikdas.com/papers/60/se...
192
Sauvik Das @sauvik.me · 24/02/2025
One of the cooler findings of the paper: through a within-subjects experiment, we show that users trust On-demand RFID to activate only in-line with their intentions even more so than using a standard RFID tag with a RFID-blocking sleeve.
100
Sauvik Das @sauvik.me · 24/02/2025
🚨 In our new #USEC2025 paper, we introduce a secure, physically-intuitive RFID tag that users actually trust. On-demand RFID: Improving Privacy, Security, and User Trust in RFID Activation through Physically-Intuitive Design 👉 Paper: sauvikdas.com/papers/62/se... #Privacy #AcademicSky #Security
1113
Sauvik Das @sauvik.me · 21/12/2024
This is not necessarily a bad thing! Sometimes, self-disclosure is necessary when seeking specific informational and/or emotional support. Other times the risk may be one that participants recognize but don't find salient.
100
Sauvik Das @sauvik.me · 21/12/2024
We had _lots_ of findings, so I'll just highlight a few. Users accepted many more of the models flagged self-disclosure risks in the categorical setting than the binary setting. A key reason for this is that the categorical model provided a coarse-explanation for *why* a disclosure was risky.
100
Sauvik Das @sauvik.me · 21/12/2024
And then we asked them questions related to their perception of the models' outputs on their specific posts, and what additional information they may need to make sense of the outputs to make informed decisions.
100
Sauvik Das @sauvik.me · 21/12/2024
We showed them both binary outputs (that a span contained self-disclosure risk), and more granular categorical outputs.
100