{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:03:10Z","timestamp":1784131390020,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,19]],"date-time":"2023-04-19T00:00:00Z","timestamp":1681862400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,19]]},"DOI":"10.1145\/3544548.3581484","type":"proceedings-article","created":{"date-parts":[[2023,4,20]],"date-time":"2023-04-20T04:28:44Z","timestamp":1681964924000},"page":"1-15","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Models of Applied Privacy (MAP): A Persona Based Approach to Threat Modeling"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2673-5964","authenticated-orcid":false,"given":"Jayati","family":"Dev","sequence":"first","affiliation":[{"name":"Comcast, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8817-0757","authenticated-orcid":false,"given":"Bahman","family":"Rashidi","sequence":"additional","affiliation":[{"name":"Comcast, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1796-0177","authenticated-orcid":false,"given":"Vaibhav","family":"Garg","sequence":"additional","affiliation":[{"name":"Comcast, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,19]]},"reference":[{"key":"e_1_3_3_2_1_1","unstructured":"[1] 2022. http:\/\/veriscommunity.net\/"},{"key":"e_1_3_3_2_2_1","volume-title":"Design and Philosophy","author":"Alexander Otis","year":"2020","unstructured":"Otis Alexander, Misha Belisle, and Jacob Steele. 2020. MITRE ATT&CK for Industrial Control Systems: Design and Philosophy. The MITRE Corporation: Bedford, MA, USA(2020)."},{"key":"e_1_3_3_2_3_1","volume-title":"HIPAA Regulations: A New Era of Medical-Record Privacy?New England Journal of Medicine 348","author":"Annas J","year":"2003","unstructured":"George\u00a0J Annas. 2003. HIPAA Regulations: A New Era of Medical-Record Privacy?New England Journal of Medicine 348 (2003), 1486."},{"key":"e_1_3_3_2_4_1","volume-title":"NIST Special Publication 800-30 Revision 1 Guide for Conducting Risk Assessments","author":"Blank R","year":"2012","unstructured":"R Blank and P Gallagher. 2012. NIST Special Publication 800-30 Revision 1 Guide for Conducting Risk Assessments. National Institute of Standards and Technology (2012)."},{"key":"e_1_3_3_2_5_1","volume-title":"Privacy Threat Modeling","author":"Bloom Cara","unstructured":"Cara Bloom. 2022. Privacy Threat Modeling. USENIX Association, Santa Clara, CA."},{"key":"e_1_3_3_2_6_1","volume-title":"Threat Modeling Manifesto","author":"Braiterman Zoe","year":"2020","unstructured":"Zoe Braiterman, Adam Shostack, Jonathan Marcil, Stephen de Vries, Irene Michlin, Kim Wuyts, Robert Hurlbut, BS Schoenfield, F Scott, M Coles, 2020. Threat Modeling Manifesto. Threat Modeling Manifesto Working Group(2020)."},{"key":"e_1_3_3_2_7_1","unstructured":"Thomas Brewster. 2022. Why Strava\u2019s Fitness Tracking Should Really Worry You. https:\/\/www.forbes.com\/sites\/thomasbrewster\/2018\/01\/29\/strava-fitness-data-location-privacy-scare\/?sh=7d324e6355c3"},{"key":"e_1_3_3_2_8_1","unstructured":"M\u00a0de Bruijne M\u00a0van Eeten C\u00a0Hern\u00e1ndez Ga\u00f1\u00e1n and Wolter Pieters. 2017. Towards a New Cyber Threat Actor Typology. (2017)."},{"key":"e_1_3_3_2_9_1","first-page":"361","article-title":"Privacy Harm Exceptionalism. Colo","volume":"12","author":"Calo Ryan","year":"2014","unstructured":"Ryan Calo. 2014. Privacy Harm Exceptionalism. Colo. Tech. LJ 12(2014), 361.","journal-title":"Tech. LJ"},{"key":"e_1_3_3_2_10_1","first-page":"2009","article-title":"Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario","volume":"5","author":"Cavoukian Ann","year":"2009","unstructured":"Ann Cavoukian 2009. Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario, Canada 5 (2009), 2009.","journal-title":"Canada"},{"key":"e_1_3_3_2_11_1","volume-title":"Proceedings of the 5th Nordic Conference on Human-Computer Interaction: Building Bridges. 439\u2013442","author":"Stolterman Erik","year":"2008","unstructured":"Yen-ning Chang, Youn-kyung Lim, and Erik Stolterman. 2008. Personas: From Theory to Practices. In Proceedings of the 5th Nordic Conference on Human-Computer Interaction: Building Bridges. 439\u2013442."},{"key":"e_1_3_3_2_12_1","volume-title":"Popular Method. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting, Vol.\u00a050","author":"Chapman N","year":"2006","unstructured":"Christopher\u00a0N Chapman and Russell\u00a0P Milham. 2006. The Personas\u2019 New Clothes: Methodological and Practical Arguments against a Popular Method. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting, Vol.\u00a050. SAGE Publications Sage CA: Los Angeles, CA, 634\u2013636."},{"key":"e_1_3_3_2_13_1","first-page":"793","article-title":"Privacy Harms","volume":"102","author":"Citron Danielle\u00a0Keats","year":"2022","unstructured":"Danielle\u00a0Keats Citron and Daniel\u00a0J Solove. 2022. Privacy Harms. BUL Rev. 102(2022), 793.","journal-title":"BUL Rev."},{"key":"e_1_3_3_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702535"},{"key":"e_1_3_3_2_15_1","volume-title":"The Inmates Are Running the Asylum: Why High Tech Products Drive Us Crazy and How to Restore the Sanity","author":"Cooper Alan","unstructured":"Alan Cooper. 2004. The Inmates Are Running the Asylum: Why High Tech Products Drive Us Crazy and How to Restore the Sanity (2nd Edition). Pearson Higher Education.","edition":"2"},{"key":"e_1_3_3_2_16_1","unstructured":"Rikke\u00a0Friis Dam and Teo\u00a0Yu Siang. 2022. Personas \u2013 A Simple Introduction. https:\/\/www.interaction-design.org\/literature\/article\/personas-why-and-how-you-should-use-them"},{"key":"e_1_3_3_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516753"},{"key":"e_1_3_3_2_18_1","unstructured":"Victoria Drake. 2021. Threat Modeling. https:\/\/owasp.org\/www-community\/Threat_Modeling"},{"key":"e_1_3_3_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979274"},{"key":"e_1_3_3_2_20_1","doi-asserted-by":"crossref","unstructured":"Shamal Faily Claudia Iacob Raian Ali and Duncan Ki-Aries. 2021. Visualising Personas as Goal Models to Find Security Tensions. Information & Computer Security(2021).","DOI":"10.1108\/ICS-03-2021-0035"},{"key":"e_1_3_3_2_21_1","volume-title":"Co-creating Persona Scenarios with Diverse Users Enriching Inclusive Design. In International Conference on Human-Computer Interaction. Springer, 48\u201359","author":"Fuglerud Kristin\u00a0Skeide","year":"2020","unstructured":"Kristin\u00a0Skeide Fuglerud, Trenton Schulz, Astri\u00a0Letnes Janson, and Anne Moen. 2020. Co-creating Persona Scenarios with Diverse Users Enriching Inclusive Design. In International Conference on Human-Computer Interaction. Springer, 48\u201359."},{"key":"e_1_3_3_2_23_1","unstructured":"Kashmir Hill. 2022. How Target Figured Out a Teen Girl was Pregnant Before Her Father Did. https:\/\/www.forbes.com\/sites\/kashmirhill\/2012\/02\/16\/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did\/"},{"key":"e_1_3_3_2_24_1","volume-title":"Comparing Expert and Non-Expert Security Practices. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015","author":"Ion Iulia","year":"2015","unstructured":"Iulia Ion, Rob Reeder, and Sunny Consolvo. 2015. \u201c...No one Can Hack My Mind\u201d: Comparing Expert and Non-Expert Security Practices. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015). USENIX Association, Ottawa, 327\u2013346. https:\/\/www.usenix.org\/conference\/soups2015\/proceedings\/presentation\/ion"},{"key":"e_1_3_3_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3025453.3026003"},{"key":"e_1_3_3_2_26_1","unstructured":"Lee Kaelin. 2011. Anonymous Publishes Details of 16 000 Finnish Residents. https:\/\/www.techspot.com\/news\/46187-anonymous-publishes-details-of-16000-finnish-residents.html"},{"key":"e_1_3_3_2_27_1","volume-title":"STRIDE-based Threat Modeling for Cyber-physical Systems. In 2017 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe). IEEE, 1\u20136.","author":"Khan Rafiullah","year":"2017","unstructured":"Rafiullah Khan, Kieran McLaughlin, David Laverty, and Sakir Sezer. 2017. STRIDE-based Threat Modeling for Cyber-physical Systems. In 2017 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe). IEEE, 1\u20136."},{"key":"e_1_3_3_2_28_1","first-page":"549","article-title":"A Survey on Threat-Modeling Techniques","volume":"14","author":"Konev Anton","year":"2022","unstructured":"Anton Konev, Alexander Shelupanov, Mikhail Kataev, Valeriya Ageeva, and Alina Nabieva. 2022. A Survey on Threat-Modeling Techniques: Protected Objects and Classification of Threats. Symmetry 14, 3 (2022), 549.","journal-title":"Protected Objects and Classification of Threats. Symmetry"},{"key":"e_1_3_3_2_29_1","unstructured":"D Leblanc. 2007. DREADful [blog post]. David LeBlanc\u2019s Web Log(2007)."},{"key":"e_1_3_3_2_30_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Liu Yang","year":"2015","unstructured":"Yang Liu, Armin Sarabi, Jing Zhang, Parinaz Naghizadeh, Manish Karir, Michael Bailey, and Mingyan Liu. 2015. Cloudy with a Chance of Breach: Forecasting Cyber Security Incidents. In 24th USENIX Security Symposium (USENIX Security 15). 1009\u20131024."},{"key":"e_1_3_3_2_31_1","doi-asserted-by":"publisher","DOI":"10.2760\/094023(2017)"},{"key":"e_1_3_3_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2207676.2208573"},{"key":"e_1_3_3_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2017.63"},{"key":"e_1_3_3_2_34_1","unstructured":"Peter Mell Karen Scarfone Sasha Romanosky 2007. A Complete Guide to the Common Vulnerability Scoring System Version 2.0. In Published by FIRST-Forum of Incident Response and Security Teams Vol.\u00a01. 23."},{"key":"e_1_3_3_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2212776.2212822"},{"key":"e_1_3_3_2_36_1","first-page":"119","article-title":"Privacy as Contextual Integrity","volume":"79","author":"Nissenbaum Helen","year":"2004","unstructured":"Helen Nissenbaum. 2004. Privacy as Contextual Integrity. Wash. L. Rev. 79(2004), 119.","journal-title":"Wash. L. Rev."},{"key":"e_1_3_3_2_37_1","volume-title":"Challenges for Designing Serious Games on Security and Privacy Awareness","author":"Pape Sebastian","unstructured":"Sebastian Pape. 2022. Challenges for Designing Serious Games on Security and Privacy Awareness. In Privacy and Identity Management. Between Data Protection and Security, Michael Friedewald, Stephan Krenn, Ina Schiering, and Stefan Schiffner (Eds.). Springer International Publishing, Cham, 3\u201316."},{"key":"e_1_3_3_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/Metrisec.2011.20"},{"key":"e_1_3_3_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/997078.997089"},{"key":"e_1_3_3_2_40_1","volume-title":"Buyer Personas: How to Gain Insight into your Customer\u2019s Expectations, Align your Marketing Strategies, and Win More Business","author":"Revella Adele","year":"2015","unstructured":"Adele Revella. 2015. Buyer Personas: How to Gain Insight into your Customer\u2019s Expectations, Align your Marketing Strategies, and Win More Business. John Wiley & Sons."},{"key":"e_1_3_3_2_41_1","unstructured":"Armin Sarabi Parinaz Naghizadeh Yang Liu and Mingyan Liu. 2015. Prioritizing Security Spending: A Quantitative Analysis of Risk Distributions for Different Business Profiles.. In WEIS."},{"key":"e_1_3_3_2_42_1","volume-title":"Dobb\u2019s journal 24, 12","author":"Schneier Bruce","year":"1999","unstructured":"Bruce Schneier. 1999. Attack Trees. Dr. Dobb\u2019s journal 24, 12 (1999), 21\u201329."},{"key":"e_1_3_3_2_43_1","volume-title":"Threat Modeling: A Summary of Available Methods. Technical Report","author":"Shevchenko Nataliya","year":"2018","unstructured":"Nataliya Shevchenko, Timothy\u00a0A Chick, Paige O\u2019Riordan, Thomas\u00a0P Scanlon, and Carol Woody. 2018. Threat Modeling: A Summary of Available Methods. Technical Report. Carnegie Mellon University Software Engineering Institute, Pittsburgh, United States."},{"key":"e_1_3_3_2_44_1","unstructured":"Adam Shostack. 2014. Elevation of Privilege: Drawing Developers into Threat Modeling. In 2014 USENIX Summit on Gaming Games and Gamification in Security Education (3GSE 14)."},{"key":"e_1_3_3_2_45_1","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014","unstructured":"Adam Shostack. 2014. Threat Modeling: Designing for Security. John Wiley & Sons."},{"key":"e_1_3_3_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3167132.3167285"},{"key":"e_1_3_3_2_47_1","volume-title":"Privacy at the Margins","author":"Skinner-Thompson Scott","unstructured":"Scott Skinner-Thompson. 2020. Privacy at the Margins. Cambridge University Press."},{"key":"e_1_3_3_2_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411763.3451731"},{"key":"e_1_3_3_2_49_1","volume-title":"Assessing the Usability of Incident Response Playbook Frameworks. In CHI Conference on Human Factors in Computing Systems. 1\u201318","author":"Stevens Rock","year":"2022","unstructured":"Rock Stevens, Daniel Votipka, Josiah Dykstra, Fernando Tomlinson, Erin Quartararo, Colin Ahern, and Michelle\u00a0L Mazurek. 2022. How Ready is Your Ready? Assessing the Usability of Incident Response Playbook Frameworks. In CHI Conference on Human Factors in Computing Systems. 1\u201318."},{"key":"e_1_3_3_2_50_1","volume-title":"Privacy Shift Left: A Machine-Assisted Threat Modeling Approach","author":"Tan Kristen","unstructured":"Kristen Tan. 2022. Privacy Shift Left: A Machine-Assisted Threat Modeling Approach. USENIX Association, Santa Clara, CA."},{"key":"e_1_3_3_2_51_1","volume-title":"PASTA: Portable Automotive Security Testbed with Adaptability.","author":"Toyama Tsuyoshi","year":"2018","unstructured":"Tsuyoshi Toyama, Takuya Yoshida, Hisashi Oguma, and Tsutomu Matsumoto. 2018. PASTA: Portable Automotive Security Testbed with Adaptability. London, BlackHat Europe(2018)."},{"key":"e_1_3_3_2_52_1","volume-title":"Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis","author":"UcedaVelez Tony","unstructured":"Tony UcedaVelez and Marco\u00a0M Morana. 2015. Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis. John Wiley & Sons."},{"key":"e_1_3_3_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341105.3375762"},{"key":"e_1_3_3_2_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-019-03028-9"},{"key":"e_1_3_3_2_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3415231"},{"key":"e_1_3_3_2_56_1","volume-title":"Privacy Impact Assessment","author":"Wright David","unstructured":"David Wright and Paul\u00a0De Hert. 2012. Introduction to Privacy Impact Assessment. In Privacy Impact Assessment. Springer, 3\u201332."},{"key":"e_1_3_3_2_57_1","volume-title":"Design and Research on Vulnerability Database. In 2010 Third International Conference on Information and Computing, Vol.\u00a02. IEEE, 209\u2013212","author":"Li Pei Gu","year":"2010","unstructured":"Gu Yun-hua and Li Pei. 2010. Design and Research on Vulnerability Database. In 2010 Third International Conference on Information and Computing, Vol.\u00a02. IEEE, 209\u2013212."}],"event":{"name":"CHI '23: CHI Conference on Human Factors in Computing Systems","location":"Hamburg Germany","acronym":"CHI '23","sponsor":["SIGCHI ACM Special Interest Group on Computer-Human Interaction"]},"container-title":["Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3544548.3581484","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3544548.3581484","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:56Z","timestamp":1750178816000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3544548.3581484"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,19]]},"references-count":56,"alternative-id":["10.1145\/3544548.3581484","10.1145\/3544548"],"URL":"https:\/\/doi.org\/10.1145\/3544548.3581484","relation":{},"subject":[],"published":{"date-parts":[[2023,4,19]]},"assertion":[{"value":"2023-04-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}