Sign in

Sauvik Das

@sauvik.me
483 followers 117 following 179 posts

I work on human-centered {security|privacy|computing}. Associate Professor (w/o tenure) at @hcii.cmu.edu. Director of the SPUD (Security, Privacy, Usability, and Design) Lab. Non-Resident Fellow @cendemtech.bsky.social

PostsRepliesMedia
Sauvik Das @sauvik.me · 27/09/2026
New #UIST2026 paper led by @yuxuanli1225.bsky.social WhatIf lets policymakers steer, inspect, and compare large-scale LLM-powered social simulations in real time. It helped emergency professionals recognize previously unrecognized planning vulnerabilities. Paper: sauvikdas.com/papers/74/se...
000
Sauvik Das @sauvik.me · 26/09/2026
New #AIES2026 paper led by @hankhplee: Agentic AI devs focus on product and business risks over downstream risks like job displacement and privacy. Lacking mature controls, they contain risk by constraining the same capabilities that make agents useful. sauvikdas.com/papers/73/s...
020
Sauvik Das @sauvik.me · 23/09/2026
yikes... this is supposed to be an advertisement for his product?
000
Sauvik Das @sauvik.me · 28/08/2026
wait, that's not what it stands for?
120
Reposted by Sauvik Das
Hao-Ping (Hank) Lee @hankhplee.bsky.social · 13/08/2026
📣 New paper alert 📣 What if AI agents' biggest strength is also their biggest risk? "The Perils of Agency: How Developers Perceive, Prioritize, and Address Risks in Agentic AI Products" (#AIES2026) 📑 hankhplee.com/papers/aies2... 🧵1/9
111
Sauvik Das @sauvik.me · 06/08/2026
but how else can i FUD?
000
Sauvik Das @sauvik.me · 23/07/2026
I still have one pending from Sep 2025, but I think the fiscal year is coming to a close so a lot of decisions are probably going out haha
120
Sauvik Das @sauvik.me · 10/07/2026
Spoke to Aditi Bharade from Business Insider about how to identify AI slop apps: www.businessinsider.com/ai-coded-ap...
businessinsider.com
There are 3 telltale signs that you used AI to make your app — and they aren't pretty
In a sea of cookie-cutter vibe-coded apps, it's getting harder to stand out. Here's what you can change in yours to set yourself apart.
000
Sauvik Das @sauvik.me · 06/07/2026
I stopped using Google Analytics on my site almost 10 years ago because I didn't want to contribute to even more cookie-based tracking. Over the weekend, I used a Claude loop to set up self-hosted, cookieless analytics and I'm...pleasantly surprised that it worked so well.
010
Reposted by Sauvik Das
Sean Munson @smunson.com · 03/07/2026
We are hiring an assistant professor to join @hcde.uw.edu in Autumn 2027. We welcome applications in all areas, with a focus on: (1) Environment and sustainability; (2) Civic infrastructure and society; (3) Labor and the future of work. Learn more & apply: apply.interfolio.com/188238
apply.interfolio.com
Apply - Interfolio {{$ctrl.$state.data.pageTitle}} - Apply - Interfolio
077
Reposted by Sauvik Das
sorelle @friedler.net · 26/06/2026
Are you curious about the environmental impact of AI? Install the AI Impact Tracker to estimate the environmental footprint of your ChatGPT usage, including energy, water, and CO2. chromewebstore.google.com/detail/ai-im... #FAccT2026
chromewebstore.google.com
2199
Reposted by Sauvik Das
Serge Egelman @v0max.bsky.social · 22/06/2026
Now available on SSRN: papers.ssrn.com/sol3/papers....
papers.ssrn.com
Anonymity, Consent, And Other Noble Lies: An Empirical Study of The Data Economy
While legal scholars have cited decades of computer science research that demonstrates why anonymity is hard (and that datasets should not be labelled as "
033
Sauvik Das @sauvik.me · 10/06/2026
make sure you don't accidentally break all of cybersecurity doing that
020
Reposted by Sauvik Das
Mark Riedl @markriedl.bsky.social · 09/06/2026
In 2019 it took 6 months for GPT-2 to go from too-dangerous to release. Claude Mythos/Fable ran that cycle in 2 months. The AI PR singularity is amongst us. In 2029, there will be zero latency between a company saying a model is too dangerous and it being released.
1313
Sauvik Das @sauvik.me · 18/05/2026
You could sell this to schools all over the country for billions
120
Sauvik Das @sauvik.me · 15/05/2026
Stop! And run around in a circle
010
Reposted by Sauvik Das
Willie Agnew @willie-agnew.bsky.social · 12/05/2026
Our work on how gen ai is impacting the labor conditions and power of professional visual artists got a great writeup from Brian Merchant! www.bloodinthemachine.com/p/the-ai-inf...
bloodinthemachine.com
The AI-inflected crisis artists are facing, in 4 charts
An alarming new study reveals the dire impact AI is having on artists' livelihoods. It does offer some hope, too.
04221
Sauvik Das @sauvik.me · 10/05/2026
as a matter of fact... www.11alive.com/article/news...
11alive.com
Woman convicted of racially motivated confrontation at child's birthday party released from prison
A victim of that disturbing day said she didn't know until she saw Kayla Rae Norton walking free. That's when she called the district attorney.
010
Reposted by Sauvik Das
Yuxuan Li @yuxuanli1225.bsky.social · 30/04/2026
Excited to share that our paper has been accepted to 𝗜𝗖𝗠𝗟 𝟮𝟬𝟮𝟲! 🎉 Multi-agent is everywhere today. But put frontier LLMs in a room where each holds a different piece of the puzzle, and they fail 70% of the time. Here's why: 📄 Paper: arxiv.org/abs/2505.11556
arxiv.org
Systematic Failures in Collective Reasoning under Distributed Information in Multi-Agent LLMs
Multi-agent systems built on large language models (LLMs) are expected to enhance decision-making by pooling distributed information, yet systematically evaluating this capability has remained challen...
131
Sauvik Das @sauvik.me · 24/04/2026
When was the last time you read a paper end-to-end for non-reviewing purposes? Seems like we write more than ever and read less than ever. (I'm guilty too) GenAI tools are kind of like a ddos attack on our attention. Far too much being produced to handle and justify consuming.
010
Sauvik Das @sauvik.me · 22/04/2026
pretty much every new lecture prep for me -.- I start out wondering how I'm supposed to fill up 80 minutes, and always end only half way through my slide deck
010
Reposted by Sauvik Das
Christos Argyropoulos MD, PhD, FASN 🇺🇸 0kale/acc @christosargyrop.bsky.social · 20/04/2026
#oopsie Anthropic secretly installs spyware when you install Claude Desktop www.thatprivacyguy.com/blog/anthrop...
thatprivacyguy.com
Anthropic secretly installs spyware when you install Claude Desktop — That Privacy Guy!
Anthropic's Claude Desktop silently installs a Native Messaging bridge into seven Chromium browsers, including browsers Anthropic's own documentation says it does not support, and browsers the user ha...
721666867
Reposted by Sauvik Das
CMU Human-Computer Interaction Institute @hcii.cmu.edu · 15/04/2026
Carnegie Mellon University authors from 12 different @cmu.edu depts contributed to 76 #CHI2026 papers: 🛠️ New tools & systems 🧠 New frameworks & taxonomies ☑️ New ways to audit tech 🆕 New advancements in Accessibility, Health, Design & so much more... Details here: hcii.cmu.edu/news/cmu-chi...
CHI '26 logo letters filled with brightly colored mosaic tiles
132
Reposted by Sauvik Das
Yuxuan Li @yuxuanli1225.bsky.social · 11/04/2026
Excited to be heading to Barcelona for #CHI2026 to host our workshop PoliSim: LLM Agent Simulation for Policy! This year, we’ve seen incredible interest from researchers across HCI, NLP, CSS, and Policy. We accepted 25 outstanding papers, with 5 selected as Best Paper nominees.
282
Sauvik Das @sauvik.me · 31/03/2026
The overleaf git project for one of my #uist2026 submissions was assigned a uuid starting with "67". I believe this lets me mine the latest block on the gen alpha blockchain using the "Proof of Relevance" protocol. Who should I speak with about this
030
Reposted by Sauvik Das
Jay Van Bavel, PhD @jayvanbavel.bsky.social · 17/03/2026
Will AI become a confirmation bias machine? AI can be a powerful tool for truth-seeking. Yet, people might prefer to use AI to confirm their pre-existing beliefs, and features of AI systems (eg sycophancy) may make AI effective at justifying what people want to believe. osf.io/preprints/ps...
23313
Reposted by Sauvik Das
Hao-Ping (Hank) Lee @hankhplee.bsky.social · 14/03/2026
Really excited that “Privy” received a CHI ’26 Honorable Mention Award 🏅 Privy is part of my PhD work on AI privacy: understanding AI privacy risks, studying why they’re hard to address in practice, and building tools that help product teams act on them.
222
Sauvik Das @sauvik.me · 13/03/2026
I am working on a UX audit agent for my company (fuguux.com/). I passed in the output of our audit agent into Claude code for my personal website and...voila, a refreshed and much better site. Surprised it worked! Before -> after sauvik.me
110
Sauvik Das @sauvik.me · 09/03/2026
An exciting development: Privy was recognized with a best paper honorable mention at #chi2026! Congrats to the whole team, including: @hankhplee.bsky.social @kyzyl.me @jodiforlizzi.bsky.social
031
Reposted by Sauvik Das
404 Media @404media.co · 03/03/2026
SCOOP: An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. This surveillance can happen through all sorts of apps, such as video games, news apps, weather trackers, and dating apps.
404media.co
CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements
An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar t...
5821291402
Sauvik Das @sauvik.me · 02/03/2026
This is functionally an end-run around judicial oversight and due process, transforming consumer data into a tool for tracking and enforcement while inevitably sweeping in non-targets, including U.S. citizens and lawful residents.
000
Sauvik Das @sauvik.me · 02/03/2026
Data collected for advertising should not be repurposed for government surveillance or tracking. This secondary use of personal data violates contextual integrity and breaches basic data minimization by turning commercially gathered information into a general investigate resource
100
Sauvik Das @sauvik.me · 02/03/2026
In January, ICE/DHS put out an RFI on how companies with “commercial Big Data and Ad Tech” products can “directly support investigations activities.” This effort would go against the best practice of minimizing data collection as a safeguard against misuse.
100
Sauvik Das @sauvik.me · 02/03/2026
Honored to be named Privacy co-chair of ACM's U.S. Technology Policy Committee with @benwinters.bsky.social On that note: please read USTPC's statement discouraging adtech vendors from sharing personal data with DHS/ICE.
140
Reposted by Sauvik Das
Yuxuan Li @yuxuanli1225.bsky.social · 25/02/2026
Can LLMs really serve as "crash dummies" for security & privacy testing? We put this assumption to the test. 🚨New preprint 🚨: "How Well Can LLM Agents Simulate End-User Security and Privacy Attitudes and Behaviors?" 👇 THREAD 👇 [Link to paper: arxiv.org/abs/2602.184... [1/n]
arxiv.org
142
Reposted by Sauvik Das
ACM Policy Committees @acmpolicy.bsky.social · 24/02/2026
New statement from the ACM U.S. Technology Policy Committee on AdTech & DHS privacy/security: computing experts urge stronger safeguards around government use of advertising-tech data collection. #Privacy #Security #TechPolicy acm.org/binaries/con...
acm.org
033
Reposted by Sauvik Das
Yuxuan Li @yuxuanli1225.bsky.social · 13/02/2026
🚨New paper🚨 We spent a year working with emergency preparedness policymakers to answer a simple question: can LLM agent simulations actually help real institutions make better decisions? The answer is yes—but perhaps not how you'd expect. 👇 THREAD 👇 [Link to paper: arxiv.org/abs/2509.218... [1/n]
112
Sauvik Das @sauvik.me · 10/02/2026
In short: Quantifying privacy risks can help users make more informed decisions—but the UX needs to present risks in a manner that is interpretable and actionable to truly *empower* users, rather than scare them. Thanks @NSF for supporting this work!
000
Sauvik Das @sauvik.me · 10/02/2026
(1) Pair risk flags with actionable guidance (how to preserve intent, reduce risk) (2) Explain plausible attacker exploits (not just “risk: high”) (3) Communicate risk without pushing unnecessary self-censorship (4) Use intuitive language/visuals; avoid jargon
100
Sauvik Das @sauvik.me · 10/02/2026
Interestingly, no single UI for presenting PREs to users “won”. Participants didn’t show a strong overall preference across the five designs (though “risk by disclosure” tended to be liked more; the meter less). So what *should* PRE designs do? 4 design recommendations:
100
Sauvik Das @sauvik.me · 10/02/2026
…but sometimes PREs encouraged self-censorship. A meaningful chunk of reflections ended with deleting the post, not posting at all, or even leaving the platform.
100
Sauvik Das @sauvik.me · 10/02/2026
Finding #2: PREs drove action (often good!). In 66% of reflections, participants envisioned the user editing the post. Most commonly: “evasive but still expressive” edits (change details, generalize, remove a pinpoint).
100
Sauvik Das @sauvik.me · 10/02/2026
Finding #1: PREs often *shifted perspective*. In ~74% of reflections, participants expected higher privacy awareness / risk concern. …but awareness came with emotional costs. Many participants anticipated anxiety, frustration, or feeling stuck about trade-offs.
100
Sauvik Das @sauvik.me · 10/02/2026
The 5 concepts ranged from: (1) raw k-anonymity score (2) a re-identifiability “meter” (3) low/med/high simplified risk (4) threat-specific risk (5) “risk by disclosure” (which details contribute most)
100
Sauvik Das @sauvik.me · 10/02/2026
Method: speculative design + design fictions. We storyboarded 5 PRE UI concepts using comic-boards (different ways to show risk + what’s driving it).
100
Sauvik Das @sauvik.me · 10/02/2026
The core design question: How should PREs be presented so they help people make better disclosure decisions… *without* nudging them into unnecessary self-censorship? We don't want people to stop posting — we want them to make informed disclosure decisions accounting for risks.
100
Sauvik Das @sauvik.me · 10/02/2026
This paper explores how to present “population risk estimates” (PREs): an AI-driven estimate of how uniquely identifiable you are based on your disclosures. Smaller “k” means you're more identifiable (e.g., k=1 means only 1 person matches everything you have disclosed)
100
Sauvik Das @sauvik.me · 10/02/2026
This paper is the latest of a productive collaboration between my lab, @cocoweixu, and @alan_ritter. ACL'24 -> a SOTA self-disclosure detection model CSCW'25 -> a human-AI collaboration study of disclosure risk mitigation NeurIPS'25 -> a method to quantify self-disclosure risk
100
Sauvik Das @sauvik.me · 10/02/2026
📣 New at #CHI2026 People share sensitive things “anonymously”… but anonymity is hard to reason about. What if we could quantify re-identification risk with AI? How should we present those AI-estimated risks to users? Led by my student Isadora Krsek Paper: www.sauvik.me/papers/70/s...
111
Sauvik Das @sauvik.me · 09/02/2026
Check out the paper! It's one of the coolest papers from my lab in that includes both a fully working system *and* a very comprehensive mixed-methods evaluation. Still had a reviewer that wanted even more, but c'est la vie 😂 www.sauvik.me/papers/69/s... Thank for the support @NSF!
000