activity
20192026
most citedContent, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training

15 citations · 22 across the 8 of their papers we have counts for

collaborators
Showing cs.CRShow all

9 papers · 1 filter

cs.CR2026

Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations

Sheila Zingg, Daniele Lain, Yoshimichi Nakatsuka +3

The European Union will introduce the EUDI Wallet by late 2026, which allows users to hold digital credentials (i.e., representations of physical official identity documents) on th…

cs.CR2025

Can LLMs Make (Personalized) Access Control Decisions?

Friederike Groschupp, Daniele Lain, Aritra Dhar +2

Precise access control decisions are crucial for the security of both traditional applications and emerging agent-based systems. Typically, these decisions are made by users during…

cs.CR2025

URL Inspection Tasks: Helping Users Detect Phishing Links in Emails

Daniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen +2

The most widespread type of phishing attack involves email messages with links pointing to malicious content. Despite user training and the use of detection techniques, these attac…

cs.CR20244 cited

Breaking Bad: How Compilers Break Constant-Time Implementations

Moritz Schneider, Daniele Lain, Ivan Puddu +2

The implementations of most hardened cryptographic libraries use defensive programming techniques for side-channel resistance. These techniques are usually specified as guidelines…

cs.CR202415 cited

Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training

Daniele Lain, Tarek Jost, Sinisa Matetic +2

A common form of phishing training in organizations is the use of simulated phishing emails to test employees' susceptibility to phishing attacks, and the immediate delivery of tra…

cs.CR20202 cited

IntegriScreen: Visually Supervising Remote User Interactions on Compromised Clients

Ivo Sluganovic, Enis Ulqinaku, Aritra Dhar +3

Remote services and applications that users access via their local clients (laptops or desktops) usually assume that, following a successful user authentication at the beginning of…