Deceptive/Manipulative Patterns (DMP) are interface designs, also known as “dark patterns,” that manipulate user behavior. While considerable attention has been paid to their ethical and legal implications, empirical evidence about their real-world effects remains diffuse. This review synthesizes up-to-date experimental studies, focusing on works that quantify how (or whether) DMPs influence users. We also aggregate findings on interventions aimed at reducing DMP effects. Our synthesis highlights the experimental agreement that DMPs do significantly alter user behavior (with large variance in effect size) and that external interventions have been mostly unsuccessful in mitigating their effects. Lastly, we show that significant correlations between DMP effects and personal characteristics (e.g., age or political affiliation) are uncommon, indicating DMPs similarly affected nearly all populations tested. By summarizing the experimental evidence, we clarify the effects of DMPs, highlight gaps and tensions in the existing experimental literature, and help inform ongoing research and policy directions.
Generative AI (GenAI) systems such as ChatGPT, Gemini, Character.AI, and LLaMA are becoming tightly woven into youths’ everyday lives. Young people now turn to these tools not only for homework help and creative projects, but also for companionship, identity exploration, and emotionally charged conversations. These always-available, highly responsive systems can support learning and self-expression, yet they also introduce new and poorly understood risks for cognitive, emotional, social, moral, and identity development. At the same time, caregivers, educators, designers, and policymakers often have limited visibility into how youth actually use GenAI and few shared frameworks for supporting developmentally appropriate, safe, and empowering engagement. This workshop aims to critically explore the holistic impact of GenAI on youth and to build a shared, developmentally grounded agenda for research and design. Our goals are to: (1) identify promising research approaches and ethical, participatory methods for studying youth–GenAI interactions in situ; (2) surface open challenges, hidden risks, and unintended impacts of GenAI use across diverse cultures and contexts; (3) explore community-based and longitudinal research models that connect youth, caregivers, educators, designers, and policymakers; (4) co-develop shared infrastructures and evaluation metrics to guide design, education, and policy, such as datasets, toolkits, forums, and indicators of developmental safety and well-being. We will bring together researchers and practitioners from HCI, education, child development, security and privacy, and policy to collaboratively sketch actionable strategies for developmentally safe GenAI environments that balance risk mitigation with youth agency, autonomy, and space for exploration and growth.
Online platforms are seeing increasing amounts of AI-generated content—text and other forms of media that are made or co-created with generative AI. This trend suggests platforms may need to establish governance frameworks, including policies and enforcement strategies for how users create, post, share, and engage with such content to encourage responsible use. We investigate the governance of AI-generated content across 40 popular social media platforms. Just over two-thirds explicitly describe governance of AI-generated content spanning six themes. Most platforms focus on moderating AI-generated content that violates established content rules and discloses AI-generated content. Fewer platforms—those that are focused on creativity and knowledge-sharing—address other issues such as ownership and monetization. Based on these findings, we suggest stakeholders and policymakers develop more direct, comprehensive, and forward-looking AI-generated content governance, as well as tools and education for users about the use of such content.
Creating accurate hyper-local climate Artificial Intelligence (AI) models requires neighborhood-level weather measurements and community partnerships. In this paper, we describe a three year case study of using a participatory approach to support the creation of hyper-local climate AI models, or what we term “precision weather.” Using participatory design to involve stakeholders in the climate AI pipeline design process i.e., “participatory AI,” we collaborated with a national laboratory and a community organization in a major metropolitan area in the United States, working with community members and scientists. We held interviews, co-design workshops (“Community Cafes”), and created an app for the community to collect flood reports in their neighborhood for advocacy and to contribute data to the AI model pipeline. We discuss our findings, lessons learned, and implications for future participatory projects to support hyper-local climate AI.
Prior work on dark patterns, or manipulative online interfaces, suggests they have potentially detrimental effects on user autonomy. Dark pattern features, like those designed for attention capture, can potentially extend platform sessions beyond what users would have otherwise intended. Existing research, however, has not formally measured the quantitative effects of these features on user engagement in subscription video-on-demand platforms (SVODs). In this work, we conducted an experimental study with 76 Netflix users in the US to analyze the impact of a specific attention capture feature, autoplay, on key viewing metrics. We found that disabling autoplay on Netflix significantly reduced key content consumption aggregates, including average daily watching and average session length, partly filling the evidentiary gap regarding the empirical effects of dark pattern interfaces. We paired the experimental analysis with users' perceptions of autoplay and their viewing behaviors, finding that participants were split on whether the effects of autoplay outweigh its benefits, albeit without knowledge of the study findings. Our findings strengthen the broader argument that manipulative interface designs can and do affect users in potentially damaging ways, highlighting the continued need for considering user well-being and varied preferences in interface design.
To protect consumer privacy, the California Consumer Privacy Act (CCPA) requires businesses to provide consumers with a straightforward way to opt out of the sale and sharing of their personal information. However, the control that businesses enjoy over the opt-out process allows them to impose hurdles on consumers aiming to opt out, including by employing dark patterns. Motivated by the enactment of the California Privacy Rights Act (CPRA), which strengthens the CCPA and explicitly forbids certain dark patterns in the opt-out process, we investigate how dark patterns are used in opt-out processes and assess their compliance with CCPA regulations. Our research on 330 CCPA-subject websites reveals that these websites employ a variety of dark patterns. Some of these patterns are explicitly prohibited under the CCPA; others seem to take advantage of legal loopholes.
Generative AI could enhance scientific discovery by supporting knowledge workers in science organizations. However, the real-world applications and perceived concerns of generative AI use in these organizations are uncertain. In this paper, we report on a collaborative study with a US national laboratory with employees spanning Science and Operations about their use of generative AI tools. We surveyed 66 employees, interviewed a subset (N=22), and measured early adoption of an internal generative AI interface called Argo lab-wide. We have four findings: (1) Argo usage data shows small but increasing use by Science and Operations employees; Common current and envisioned use cases for generative AI in this context conceptually fall into either a (2) copilot or (3) workflow agent modality; and (4) Concerns include sensitive data security, academic publishing, and job impacts. Based on our findings, we make recommendations for generative AI use in science and other organizations.
While recent research has focused on developing safeguards for generative AI (GAI) model-level content safety, little is known about how content moderation to prevent malicious content performs for end-users in real-world GAI products. To bridge this gap, we investigated content moderation policies and their enforcement in GAI online tools — consumer-facing web-based GAI applications. We first analyzed content moderation policies of 14 GAI online tools. While these policies are comprehensive in outlining moderation practices, they usually lack details on practical implementations and are not specific about how users can aid in moderation or appeal moderation decisions. Next, we examined user-experienced content moderation successes and failures through Reddit discussions on GAI online tools. We found that although moderation systems succeeded in blocking malicious generations pervasively, users frequently experienced frustration in failures of both moderation systems and user support after moderation. Based on these findings, we suggest improvements for content moderation policy and user experiences in real-world GAI products.
The growing use of technology in K--8 classrooms highlights a parallel need for formal learning opportunities aimed at helping children use technology safely and protect their personal information. Even the youngest students are now using tablets, laptops, and apps to support their learning; however, there are limited curricular materials available for elementary and middle school children on digital privacy and security topics. To bridge this gap, we developed a series of micro-lessons to help K--8 children learn about digital privacy and security at school. We first conducted a formative study by interviewing elementary school teachers to identify the design needs for digital privacy and security lessons. We then developed micro-lessons -- multiple 15-20 minute activities designed to be easily inserted into the existing curriculum -- using a co-design approach with multiple rounds of developing and revising the micro-lessons in collaboration with teachers. Throughout the process, we conducted evaluation sessions where teachers implemented or reviewed the micro-lessons. Our study identifies strengths, challenges, and teachers' tailoring strategies when incorporating micro-lessons for K--8 digital privacy and security topics, providing design implications for facilitating learning about these topics in school classrooms.
As smart TVs gain popularity, they introduce significant privacy and security concerns due to their extensive data collection and multi-user contexts. This paper investigates user perceptions of privacy concerns regarding both service providers and the multi-user use case in the context of smart TVs. Through in-depth interviews with 22 smart TV users, we found that participants expressed uncertainty about the data collection practices of smart TVs and a desire for clearer communication of such practices. Participants reported discomfort with how their personal information is handled through their smart TVs but felt forced to accept it due to the lack of ability to opt out. Our study also highlights varied privacy concerns when smart TVs are shared in public versus private settings. While participants expressed significantly less concern when sharing smart TVs with acquaintances in private settings, concerns were more prevalent in public settings like hotels and Airbnbs. Based on the findings, we provide recommendations for designers, policymakers, and researchers to improve privacy protection and user experience around smart TVs.
It is common practice for researchers to join public WhatsApp chats and scrape their contents for analysis. However, research shows collecting data this way contradicts user expectations and preferences, even if the data is effectively public. To overcome these issues, we outline design considerations for collecting WhatsApp chat data with improved user privacy by heightening user control and oversight of data collection and taking care to minimize the data researchers collect and process off a user's device. We refer to these design principles as User-Centered Data Sharing (UCDS). To evaluate our UCDS principles, we implemented a mobile application representing one possible instance of these improved data collection techniques and evaluated the viability of using the app to collect WhatsApp chat data. Second, we surveyed WhatsApp users to gather user perceptions on common existing WhatsApp data collection methods as well as UCDS methods. Our results show that we were able to glean similar informative insights into WhatsApp chats using UCDS principles in our prototype app to common, less privacy-preserving methods. Our survey showed that methods following the UCDS principles are preferred by users because they offered users more control over the data collection process. Future user studies could further expand upon UCDS principles to overcome complications of researcher-to-group communication in research on WhatsApp chats and evaluate these principles in other data sharing contexts.
The widespread sharing of consumers personal information with third parties raises significant privacy concerns. The California Consumer Privacy Act (CCPA) mandates that online businesses offer consumers the option to opt out of the sale and sharing of personal information. Our study automatically tracks the presence of the opt-out link longitudinally across multiple states after the California Privacy Rights Act (CPRA) went into effect. We categorize websites based on whether they are subject to CCPA and investigate cases of potential non-compliance. We find a number of websites that implement the opt-out link early and across all examined states but also find a significant number of CCPA-subject websites that fail to offer any opt-out methods even when CCPA is in effect. Our findings can shed light on how websites are reacting to the CCPA and identify potential gaps in compliance and opt-out method designs that hinder consumers from exercising CCPA opt-out rights.
The cybersecurity workforce lacks diversity; the field is predominately men and White or Asian, with only 10% identifying as women, Latine, or Black. Previous studies identified access to supportive communities as a possible disparity between marginalized and non-marginalized cybersecurity professional populations and highlighted this support as a key to career success. We focus on these community experiences by conducting a survey of 342 cybersecurity professionals to identify differences in perceptions and experiences of belonging across demographic groups. Our results show a discrepancy between experiences for different gender identities, with women being more likely than men to report instances of harassment and encountering unsupportive environments because of their gender. Psychological safety was low across all demographic groups, meaning participants did not feel comfortable engaging with or speaking up in the community. Based on these result we provide recommendations to community leaders.
Moderating user-generated content on online platforms is crucial for balancing user safety and freedom of speech. Particularly in the United States, platforms are not subject to legal constraints prescribing permissible content. Each platform has thus developed bespoke content moderation policies, but there is little work towards a comparative understanding of these policies across platforms and topics. This paper presents the first systematic study of these policies from the 43 largest online platforms hosting user-generated content, focusing on policies around copyright infringement, harmful speech, and misleading content. We build a custom web-scraper to obtain policy text and develop a unified annotation scheme to analyze the text for the presence of critical components. We find significant structural and compositional variation in policies across topics and platforms, with some variation attributable to disparate legal groundings. We lay the groundwork for future studies of ever-evolving content moderation policies and their impact on users.
Children are exposed to technology at home and school at very young ages, often using family mobile devices and educational apps. It is therefore critical that they begin learning about privacy and security concepts during their elementary school years, rather than waiting until they are older. Such skills will help children navigate an increasingly connected world and develop agency over their personal data, online interactions, and online security. In this paper, we explore how a simple technique---a ''Would Your Rather'' (WYR) game involving hypothetical privacy and security scenarios---can support children in working through the nuances of these types of situations and how educators can leverage this approach to support children's privacy and security learning. We conducted three focus groups with 21 children aged 7-12 using the WYR activity and interviewed 13 elementary school teachers about the use of WYR for facilitating privacy and security learning. We found that WYR provided a meaningful opportunity for children to assess privacy and security risks, consider some of the social and emotional aspects of privacy and security dilemmas, and assert their agency in a manner typically unavailable to children in an adult-centric society. Teachers highlighted connections between privacy and security dilemmas and children's social and emotional learning and offered additional insights about using this WYR technique in and beyond their classrooms. Based on these findings, we highlight four opportunities for using WYR to support children in engaging with privacy and security concepts from an early age.
Increased use of technology in schools raises new privacy and security challenges for K-12 students-and harms such as commercialization of student data, exposure of student data in security breaches, and expanded tracking of students-but the extent of these challenges is unclear. In this paper, first, we interviewed 18 school officials and IT personnel to understand what educational technologies districts use and how they manage student privacy and security around these technologies. Second, to determine if these educational technologies are frequently endorsed across United States (US) public schools, we compiled a list of linked educational technology websites scraped from 15,573 K-12 public school/district domains and analyzed them for privacy risks. Our findings suggest that administrators lack resources to properly assess privacy and security issues around educational technologies even though they do pose potential privacy issues. Based on these findings, we make recommendations for policymakers, educators, and the CHI research community.
Users often turn to subscription video on demand (SVOD) platforms for entertainment. However, these platforms sometimes employ manipulative tactics that undermine a user's sense of agency over time and content choice to increase their share of a user's attention. Prior research has investigated how interface designs affect a user's sense of agency on social media and YouTube. For example, YouTube's autoplay left users feeling like they had less control over their time. We extend this work by investigating the design elements of Netflix, the most used SVOD, for the impact they have on users' senses of agency. We conducted interviews with 20 participants that used Netflix regularly, asking about their experiences and perceptions of features in the Netflix platform design that may affect their sense of agency. We found that a user's sense of agency was at odds with the platform's design. Users, who were often seeking entertainment for mood management, were met with features that encouraged watching more than they originally planned to and watching content they may not otherwise watch. We discuss design recommendations that Netflix could employ to reaffirm their users' agency.
With the rapid shift to remote learning in the early days of the COVID-19 pandemic, parents, teachers, and students had to quickly adapt to what scholars have called "emergency remote learning" (ERL). This transition required increased reliance on digital tools, exacerbating privacy and security threats associated with expanded data collection and new vulnerabilities. In this study, we adopt a sociotechnical and infrastructural perspective to understand how these threats emerged through breakdowns and tensions in elementary school ERL. Through interviews with 29 US-based teachers and parents of elementary school students (grades PreK-6), we identify two core findings related to privacy and security. First, we detail three breakdowns in the ERL sociotechnical infrastructure: (1) reduced attention to privacy and security issues as parents and teachers cobbled together a patchwork of tools needed to make ERL work; (2) privacy and security risks that emerged from ambiguous and shifting school policies; and (3) the failure to adapt standard authentication mechanisms (e.g., passwords) to be usable by young children. Second, we identify tensions between parents' and teachers' desire to help children advance in their education and their desire for children's privacy and security in ERL, as well as tensions resulting from the collapse of home and school contexts. These findings collectively suggest that ERL exacerbated existing--and created new--privacy and security challenges for young students, and we argue these challenges will carry beyond the pandemic due to the increasing use of technology to supplement traditional education. In light of these findings, we recommend researchers and educators use a framework of care to develop social and technical approaches to improving remote learning in order to protect children's privacy and security.