Sign in

SPUR Lab

@spur.science
35 followers 82 following 26 posts

Nathan Malkin's research group — studying Security, Privacy, Usability, Respect at New Jersey Institute of Technology (NJIT) – spur.science

PostsRepliesMedia
SPUR Lab @spur.science · 08/07/2026
One more thing we observed was that, on Mechanical Turk, the incidence of AI usage is upwards of 80%, which might provide some context for their recent announcement: techcrunch.com/2026/07/05/a...
techcrunch.com
Amazon will stop accepting new customers for Mechanical Turk | TechCrunch
These may be the last days of Amazon’s Mechanical Turk.
000
SPUR Lab @spur.science · 08/07/2026
A lot more details are in our paper, which we'll be presenting at SOUPS 2026: arxiv.org/abs/2607.00403
arxiv.org
A Penny for Your Prompts: Experiments Detecting and Mitigating LLM Usage by Survey Respondents
Large language models are increasingly used by participants on crowdsourcing platforms when responding to surveys, potentially undermining the validity of collected data. Our study aims to quantify th...
100
SPUR Lab @spur.science · 08/07/2026
Accordingly, disabling copy/paste seems like a reasonable solution, but we found that asking participants not to use AI was surprisingly effective. Another surprising effect of doing this: browser automation agents see these messages and will often refuse to proceed.
110
SPUR Lab @spur.science · 08/07/2026
The most effective one is having the survey software keep track of the frequency and contents of copy/pasting. When it happens for most open-ended responses, that's a good clue respondents might not be using their own words.
100
SPUR Lab @spur.science · 08/07/2026
Running several experiments, @zanexuprivacy.bsky.social discovered better approaches for detecting when participants use AI.
100
SPUR Lab @spur.science · 08/07/2026
But how do we tell if a participant is using AI? So far, we've just read answers and guessed if they looked suspicious based on cues we've all come to recognize — certain words, phrases, or punctuation. But none of that is very reliable.
100
SPUR Lab @spur.science · 08/07/2026
We at the SPUR lab run lots of surveys and have noticed (like many others) that some participants use AI when filling them out. This makes it hard to trust our own results: what if they just asked an LLM like ChatGPT to write a response? Then we're getting its opinions and not those of real people.
111
SPUR Lab @spur.science · 14/04/2026
We actually asked our participants about that as well. Rejection reasons are often confusing, so developers go back to LLMs to understand what happened and figure out how to fix it.
000
SPUR Lab @spur.science · 14/04/2026
That's also not super transparent, but it's alluded to in the documentation (support.google.com/googleplay/a...) and there are discussions in forums from developers whose updates were rejected on their basis.
support.google.com
Provide information for Google Play's Data safety section - Play Console Help
Google Play's Data safety section provides developers with a transparent way to show users if and how they collect, share, and protect user data, before users install an app. Developers are required t
100
SPUR Lab @spur.science · 14/04/2026
However, it's worth noting that, while app stores don't validate privacy policies, they *do* have some checks for data safety ("privacy nutrition") labels.
110
SPUR Lab @spur.science · 14/04/2026
As far as I know, our participants weren't doing their own static analysis — they were all comparatively low-resourced teams.
100
SPUR Lab @spur.science · 13/04/2026
To find out more, check out our paper: doi.org/10.1145/3772... And if you're at #CHI2026, you can hear the talk on Tuesday, at 10:12, in Room 133.
doi.org
Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AI | Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems
010
SPUR Lab @spur.science · 13/04/2026
All of this suggests that, until a privacy policy has been verified, we need to treat it like any other (potentially) vibe-coded artifact: with suspicion.
100
SPUR Lab @spur.science · 13/04/2026
When we asked how they'd validate their policy, the most common answer was: submit it to the app store and see if it gets rejected. The problem is that, as far we know, neither Google Play nor the App Store actually check the content of privacy policies.
210
SPUR Lab @spur.science · 13/04/2026
We interviewed 20 developers across 5 regions and then watched them build a privacy policy live using an LLM. Most made fewer than 4 follow-up prompts, half rated their comfort with the output at 8/10 or higher, and the majority said they'd submit it to the app store as-is.
100
SPUR Lab @spur.science · 13/04/2026
New research from our lab, appearing at #CHI2026: We studied how mobile app developers create privacy policies, with and without AI. The strategies varied, but plenty do just open an LLM and ask it to write a privacy policy for them.
doi.org
Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AI | Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems
161
SPUR Lab @spur.science · 18/11/2025
Learn more at spur.science/join/phd and apply by December 15!
spur.science
PhD positions in human-centered privacy and security in New York City area
PhD student positions in security, privacy, and human-computer interaction at New Jersey Institute of Technology (NJIT)
000
SPUR Lab @spur.science · 18/11/2025
This year, I'm again recruiting students who want to pursue a PhD in computer science with a focus on human-centered privacy & security. Located at NJIT, near New York City, this fully-funded position will help make systems more secure, private, usable, and respectful.
spur.science
PhD positions in human-centered privacy and security in New York City area
PhD student positions in security, privacy, and human-computer interaction at New Jersey Institute of Technology (NJIT)
111
SPUR Lab @spur.science · 22/04/2025
Wondering where to submit your next human-centered security/privacy research paper? See the deadlines and decision dates for major usable security & privacy conferences at deadlines.spur.science
deadlines.spur.science
Usable Security Conference Timeline
Deadlines and other important dates for conferences in human-centered security and privacy
000
SPUR Lab @spur.science · 02/12/2024
I'm recruiting again this year!
012
SPUR Lab @spur.science · 02/12/2024
This year's application deadline is December 15, 2024. If you're interested in this research area, please consider applying, I would love to talk to you!
000
SPUR Lab @spur.science · 02/12/2024
What's new this year? You'll be joining an active lab with four other students, working on new projects at the intersection of human-centered privacy with AI, healthcare, and autonomous vehicles.
100
SPUR Lab @spur.science · 02/12/2024
Looking to get a PhD in computer science or social sciences? Now hiring at NJIT, near New York City, for a fully funded position in human-centered privacy & security. We're working to make systems more secure, private, usable, and respectful. Learn more at spur.science/join/phd
spur.science
PhD positions in human-centered privacy and security in New York City area
PhD student positions in security, privacy, and human-computer interaction at New Jersey Institute of Technology (NJIT)
120
SPUR Lab @spur.science · 11/12/2023
Many PhD applications are due soon (including ours!). Here's some advice about how to write your Statement of Purpose: www.spur.science/advice/phd/sop
000
SPUR Lab @spur.science · 09/11/2023
Now recruiting for PhD positions near New York City in human-centered and usable security & privacy. How do we make systems more secure, private, usable, and respectful? Computer science and social science backgrounds welcome! Learn more at spur.science/join/phd
spur.science
PhD positions in human-centered privacy and security in NYC area
PhD student positions in security, privacy, and human-computer interaction at New Jersey Institute of Technology (NJIT)
123
SPUR Lab @spur.science · 09/11/2023
Hello, world! As a privacy researcher, I'm a reluctant user of social media, but I want to be able to share the accomplishments of the awesome students I work with, as well as meet future colleagues. So here I am (and on other platforms too)! 👋🙂
030