Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible Future
Harshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez, Tadayoshi Kohno, Yasemin Acar
Abstract
Ethical questions are discussed regularly in computer security. Still, researchers in computer security lack clear guidance on how to make, document, and assess ethical decisions in research when what is morally right or acceptable is not clear-cut. In this work, we give an overview of the discussion of ethical implications in current published work in computer security by reviewing all 1154 publications at top 4 security conferences published in 2024, finding inconsistent levels of ethics reporting with a strong focus of reporting institutional or ethics board approval, human subjects protection, and responsible disclosure, and a lack of discussion of balancing harms and benefits. We further report on the results of a semi-structured interview study with 24 computer security and privacy researchers (among whom were also: reviewers, ethics committee members, and/or program chairs) and their ethical decision-making both as authors and during peer review, finding a strong desire for ethical research, but a lack of consistency in considered values, ethical frameworks (if articulated), decision-making, and outcomes. We present an overview of the current state of the discussion of ethics and current de-facto standards in computer security research, contributing suggestions to improve the state of ethics in computer security research.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3c6c4c3f-79b2-4594-9aec-68516a0d45aaCited by top-tier papers1
Ask how each one uses itBuilds on15
- Co-Designing Checklists to Understand Organizational Challenges and Opportunities around Fairness in AIMichael A. Madaio, Luke Stark, Jennifer Wortman Vaughan, Hanna M. WallachCHI 2020 · 428 citations
- Computer Security and Privacy for Refugees in the United StatesLucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner et al.S&P 2018 · 77 citations
- "That's important, but...": How Computer Science Researchers Anticipate Unintended Consequences of Their Research InnovationsKimberly Do, Rock Yuren Pang, Jiachen Jiang, Katharina ReineckeCHI 2023 · 40 citations
- Understanding Help-Seeking and Help-Giving on Social Media for Image-Based Sexual AbuseMiranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno et al.USENIX Security 2024 · 27 citations
- It's the Wild, Wild West: Lessons Learned From IRB Members' Risk Perceptions Toward Digital Research DataJina Huh-Yoo, Emilee RaderCSCW 2020 · 26 citations
Related papers
- "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security PapersAnanta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao et al.S&P 2022 · 17 citations
- Ethical Frameworks and Computer Security Trolley Problems: Foundations for ConversationsTadayoshi Kohno, Yasemin Acar, Wulf LohUSENIX Security 2023
- Reflection, Education, Consistency: Towards Best Ethics Practices At Security And Privacy ConferencesFlorian Hantke, Rafael Mrowczynski, Til Dralle, Ben StockCCS 2026
- Data to Infinity and Beyond: Examining Data Sharing and Reuse Practices in the Computer Security CommunityAnna Crowder, Allison Lu, Kevin Childs, Carson Stillman et al.S&P 2025
- Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesFlorin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam et al.CHI 2025 · 7 citations
