<p>In this systematic literature review, we explore the concept of personas in the context of security and privacy literature. Personas are archetypes of users commonly employed in user-centered design processes to aid in understanding user needs, behaviors, and goals. This study examines how personas are used to study user behavior in security and privacy research. Through a systematic inquiry, this study reviewed 35 articles. The study found diverse methods for creating personas in this domain, with varied levels of evidence. Some personas, such as heuristic personas, relied less on empirical evidence, while others were developed through surveys and interviews. Q methodology from social science emerged as a novel and resource-efficient way of creating personas. The personas were not just representative of ideal users but were also used to model threat actors whose interactions the system architects tried to mitigate. This complexity was reflected in the attributes that define the personas. The findings provide practical directions for system designers to develop secure systems considering both user privacy and security threats. The main contribution is a comprehensive set of personas that system architects should consider when designing new systems. Additionally, the research offers insights into employing AI for double screening in systematic literature reviews.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

What do personas say about privacy & security: a systematic literature review through human-AI collaboration

  • Amir Reza Asadi,
  • Yuchong Zhang,
  • Hazem Said

摘要

In this systematic literature review, we explore the concept of personas in the context of security and privacy literature. Personas are archetypes of users commonly employed in user-centered design processes to aid in understanding user needs, behaviors, and goals. This study examines how personas are used to study user behavior in security and privacy research. Through a systematic inquiry, this study reviewed 35 articles. The study found diverse methods for creating personas in this domain, with varied levels of evidence. Some personas, such as heuristic personas, relied less on empirical evidence, while others were developed through surveys and interviews. Q methodology from social science emerged as a novel and resource-efficient way of creating personas. The personas were not just representative of ideal users but were also used to model threat actors whose interactions the system architects tried to mitigate. This complexity was reflected in the attributes that define the personas. The findings provide practical directions for system designers to develop secure systems considering both user privacy and security threats. The main contribution is a comprehensive set of personas that system architects should consider when designing new systems. Additionally, the research offers insights into employing AI for double screening in systematic literature reviews.