Publications (38)
From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)
Kunlin Cai, Jinghuai Zhang, Ying Li +4
The immersive nature of XR introduces a fundamentally different set of security and privacy (S&P) challenges due to the unprecedented user interactions and data collection that tra…
Toward a Human-Centered Evaluation Framework for Trustworthy LLM-Powered GUI Agents
Chaoran Chen, Zhiping Zhang, Ibrahim Khalilov +7
The rise of Large Language Models (LLMs) has revolutionized Graphical User Interface (GUI) automation through LLM-powered GUI agents, yet their ability to process sensitive data wi…
The Obvious Invisible Threat: LLM-Powered GUI Agents' Vulnerability to Fine-Print Injections
Chaoran Chen, Zhiping Zhang, Bingcan Guo +8
A Large Language Model (LLM) powered GUI agent is a specialized autonomous system that performs tasks on the user's behalf according to high-level instructions. It does so by perce…
Position: Privacy Is Not Just Memorization!
Niloofar Mireshghallah, Tianshi Li
The discourse on privacy risks in Large Language Models (LLMs) has disproportionately focused on verbatim memorization of training data, while a constellation of more immediate and…
Privacy Leakage Overshadowed by Views of AI: A Study on Human Oversight of Privacy in Language Model Agent
Zhiping Zhang, Bingcan Guo, Tianshi Li
Language model (LM) agents that act on users' behalf for personal tasks (e.g., replying emails) can boost productivity, but are also susceptible to unintended privacy leakage risks…
Human-Centered Privacy Research in the Age of Large Language Models
Tianshi Li, Sauvik Das, Hao-Ping Lee +3
The emergence of large language models (LLMs), and their increased use in user-facing systems, has led to substantial privacy concerns. To date, research on these privacy concerns…
Understanding the Interactions of Workloads and DRAM Types: A Comprehensive Experimental Study
Saugata Ghose, Tianshi Li, Nastaran Hajinazar +2
It has become increasingly difficult to understand the complex interaction between modern applications and main memory, composed of DRAM chips. Manufacturers are now selling and pr…
PrivacyMotiv: Vulnerability-Centered Persona Journeys for Empathic Privacy Reviews in UX Design
Zeya Chen, Jianing Wen, Yaxing Yao +2
UX professionals routinely conduct design reviews, yet privacy concerns are often overlooked, not only due to limited tools, but more fundamentally from low intrinsic motivation, d…
Rescriber: Smaller-LLM-Powered User-Led Data Minimization for LLM-Based Chatbots
Jijie Zhou, Eryue Xu, Yaoyao Wu +1
The proliferation of LLM-based conversational agents has resulted in excessive disclosure of identifiable or sensitive information. However, existing technologies fail to offer per…
What Makes People Install a COVID-19 Contact-Tracing App? Understanding the Influence of App Design and Individual Difference on Contact-Tracing App Adoption Intention
Tianshi Li, Camille Cobb, Jackie +6
Smartphone-based contact-tracing apps are a promising solution to help scale up the conventional contact-tracing process. However, low adoption rates have become a major issue that…
Agentic LLMs as Powerful Deanonymizers: Re-identification of Participants in the Anthropic Interviewer Dataset
Tianshi Li
On December 4, 2025, Anthropic released Anthropic Interviewer, an AI tool for running qualitative interviews at scale, along with a public dataset of 1,250 interviews with professi…
Matcha: An IDE Plugin for Creating Accurate Privacy Nutrition Labels
Tianshi Li, Lorrie Faith Cranor, Yuvraj Agarwal +1
Apple and Google introduced their versions of privacy nutrition labels to the mobile app stores to better inform users of the apps' data practices. However, these labels are self-r…
"Should I Give Up Now?" Investigating LLM Pitfalls in Software Engineering
Jiessie Tie, Bingsheng Yao, Tianshi Li +4
Software engineers are increasingly incorporating AI assistants into their workflows to enhance productivity and alleviate cognitive load. However, experiences with large language…
Beyond Permissions: Investigating Mobile Personalization with Simulated Personas
Ibrahim Khalilov, Chaoran Chen, Ziang Xiao +3
Mobile applications increasingly rely on sensor data to infer user context and deliver personalized experiences. Yet the mechanisms behind this personalization remain opaque to use…
LLM Anonymization Against Agentic Re-Identification
Ziwen Li, Jianing Wen, Tianshi Li
Agentic LLMs with web search change the threat model for text anonymization: weak contextual cues can become cross-referenceable evidence for re-identification, yet those same deta…
PrivacyLens: Evaluating Privacy Norm Awareness of Language Models in Action
Yijia Shao, Tianshi Li, Weiyan Shi +2
As language models (LMs) are widely utilized in personalized communication scenarios (e.g., sending emails, writing social media posts) and endowed with a certain level of agency,…
Operationalizing Data Minimization for Privacy-Preserving LLM Prompting
Jijie Zhou, Niloofar Mireshghallah, Tianshi Li
The rapid deployment of large language models (LLMs) in consumer applications has led to frequent exchanges of personal information. To obtain useful responses, users often share m…
ReactGenie: A Development Framework for Complex Multimodal Interactions Using Large Language Models
Jackie Junrui Yang, Yingtian Shi, Yuhan Zhang +7
By combining voice and touch interactions, multimodal interfaces can surpass the efficiency of either modality alone. Traditional multimodal frameworks require laborious developer…
Comparing Human Oversight Strategies for Computer-Use Agents
Chaoran Chen, Zhiping Zhang, Zeya Chen +9
LLM-powered computer-use agents (CUAs) are shifting users from direct manipulation to supervisory coordination. Existing oversight mechanisms, however, have largely been studied as…
Why am I seeing this: Democratizing End User Auditing for Online Content Recommendations
Chaoran Chen, Leyang Li, Luke Cao +4
Personalized recommendation systems tailor content based on user attributes, which are either provided or inferred from private data. Research suggests that users often hypothesize…
Disclose with Care: Designing Privacy Controls in Interview Chatbots
Ziwen Li, Ziang Xiao, Tianshi Li
Collecting data on sensitive topics remains challenging in HCI, as participants often withhold information due to privacy concerns and social desirability bias. While chatbots' per…
The Design of the User Interfaces for Privacy Enhancements for Android
Jason I. Hong, Yuvraj Agarwal, Matt Fredrikson +22
We present the design and design rationale for the user interfaces for Privacy Enhancements for Android (PE for Android). These UIs are built around two core ideas, namely that dev…
CIDER: A Dataset of Contextual Disclosure Boundaries for Privacy Preference Alignment
Bingcan Guo, Eryue Xu, Jijie Zhou +2
Aligning large language models (LLMs) with human privacy preferences requires capturing individuals' disclosure boundaries beyond general privacy norms. However, a gap remains in e…
"It's a Fair Game", or Is It? Examining How Users Navigate Disclosure Risks and Benefits When Using LLM-Based Conversational Agents
Zhiping Zhang, Michelle Jia, Hao-Ping Lee +5
The widespread use of Large Language Model (LLM)-based conversational agents (CAs), especially in high-stakes domains, raises many privacy concerns. Building ethical LLM-based CAs…
Secret Use of Large Language Model (LLM)
Zhiping Zhang, Chenxinran Shen, Bingsheng Yao +2
The advancements of Large Language Models (LLMs) have decentralized the responsibility for the transparency of AI usage. Specifically, LLM users are now encouraged or required to d…
Shaping the Emerging Norms of Using Large Language Models in Social Computing Research
Hong Shen, Tianshi Li, Toby Jia-Jun Li +2
The emergence of Large Language Models (LLMs) has brought both excitement and concerns to social computing research. On the one hand, LLMs offer unprecedented capabilities in analy…
{A New Hope}: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated Generation
Shidong Pan, Zhen Tao, Thong Hoang +7
Privacy policies have emerged as the predominant approach to conveying privacy notices to mobile application users. In an effort to enhance both readability and user engagement, th…
Decentralized is not risk-free: Understanding public perceptions of privacy-utility trade-offs in COVID-19 contact-tracing apps
Tianshi Li, Jackie, Yang +5
Contact-tracing apps have potential benefits in helping health authorities to act swiftly to halt the spread of COVID-19. However, their effectiveness is heavily dependent on their…
Not My Agent, Not My Boundary? Elicitation of Personal Privacy Boundaries in AI-Delegated Information Sharing
Bingcan Guo, Eryue Xu, Zhiping Zhang +1
Aligning AI systems with human privacy preferences requires understanding individuals' nuanced disclosure behaviors beyond general norms. Yet eliciting such boundaries remains chal…
Autonomy Reshapes How Personalization Affects Privacy Concerns and Trust in LLM Agents
Zhiping Zhang, Yi Evie Zhang, Freda Shi +1
LLM agents require personal information for personalization in order to effectively act on users' behalf, but this raises privacy concerns that can discourage data sharing, limitin…
"I'm categorizing LLM as a productivity tool": Examining ethics of LLM use in HCI research practices
Shivani Kapania, Ruiyi Wang, Toby Jia-Jun Li +2
Large language models are increasingly applied in real-world scenarios, including research and education. These models, however, come with well-known ethical issues, which may mani…
Exploring Collaboration Breakdowns Between Provider Teams and Patients in Post-Surgery Care
Bingsheng Yao, Menglin Zhao, Zhan Zhang +11
Post-surgery care involves ongoing collaboration between provider teams and patients, which starts from post-surgery hospitalization through home recovery after discharge. While pr…
Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human Oversight
Jingyu Tang, Chaoran Chen, Jiawen Li +11
The dark patterns, deceptive interface designs manipulating user behaviors, have been extensively studied for their effects on human decision-making and autonomy. Yet, with the ris…
Using ECC DRAM to Adaptively Increase Memory Capacity
Yixin Luo, Saugata Ghose, Tianshi Li +5
Modern DRAM modules are often equipped with hardware error correction capabilities, especially for DRAM deployed in large-scale data centers, as process technology scaling has incr…
Flexible-Latency DRAM: Understanding and Exploiting Latency Variation in Modern DRAM Chips
Kevin K. Chang, Abhijith Kashyap, Hasan Hassan +7
This article summarizes key results of our work on experimental characterization and analysis of latency variation and latency-reliability trade-offs in modern DRAM chips, which wa…
Learning Word Sense Embeddings from Word Sense Definitions
Qi Li, Tianshi Li, Baobao Chang
Word embeddings play a significant role in many modern NLP systems. Since learning one representation per word is problematic for polysemous words and homonymous words, researchers…
From Fragmentation to Integration: Exploring the Design Space of AI Agents for Human-as-the-Unit Privacy Management
Eryue Xu, Tianshi Li
Managing one's digital footprint is overwhelming, as it spans multiple platforms and involves countless context-dependent decisions. Recent advances in agentic AI offer ways forwar…
PriviSense: A Frida-Based Framework for Multi-Sensor Spoofing on Android
Ibrahim Khalilov, Chaoran Chen, Ziang Xiao +3
Mobile apps increasingly rely on real-time sensor and system data to adapt their behavior to user context. While emulators and instrumented builds offer partial solutions, they oft…