"Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security Papers
Ananta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doupé
Abstract
The academic computer security community has traditionally adopted peer review as an integral part of scientific publishing and dissemination, in a process that grows organically and nourishes itself by internal communications and intuitions, rather than repeatable experiments and investigations. Recently, key community members have shared a series of concerns regarding this process in public. To support or disprove some of these concerns, this paper presents the first qualitative study to examine the peer review process in the computer security field. Through semi-structured interviews (n=21) with Program Committee members, we systematically collect the reviewers’ insights on how papers are evaluated in top-tier security conferences and investigate their concerns regarding the current security peer review system. Based on the collected data, we identify several issues in the security review system: whereas some have been previously observed by the community (e.g., the randomness in reviewers’ decisions), others (e.g., reviewers have much more diverse and concrete opinions on the metrics of rejecting papers) have been observed for the first time in our study. Finally, through a series of recommendations, we aim to encourage the collaborative establishment of community norms that will significantly improve the security peer review process.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers7
- How WEIRD is Usable Privacy and Security Research?Ayako Akiyama Hasegawa, Daisuke Inoue, Mitsuaki AkiyamaUSENIX Security 2024 · 26 citations
- How Transparent is Usable Privacy and Security Research? A Meta-Study on Current Research Transparency PracticesJan H. Klemmer, Juliane Schmüser, Fabian Fischer, Jacques Suray et al.USENIX Security 2025
- Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible FutureHarshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez et al.CCS 2025
- No more Reviewer #2: Subverting Automatic Paper-Reviewer Assignment using Adversarial LearningThorsten Eisenhofer, Erwin Quiring, Jonas Möller, Doreen Riepel et al.USENIX Security 2023
- "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing InfrastructuresSouradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao et al.S&P 2025
Related papers
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- A One-Size-Fits-All Approach to Improving Randomness in Paper AssignmentYixuan Even Xu, Steven Jecmen, Zimeng Song, Fei FangNeurIPS 2023 · 11 citations
- Community expectations for research artifacts and evaluation processesBen Hermann, Stefan Winter, Janet SiegmundFSE 2020 · 40 citations
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 95 citations
- Data to Infinity and Beyond: Examining Data Sharing and Reuse Practices in the Computer Security CommunityAnna Crowder, Allison Lu, Kevin Childs, Carson Stillman et al.S&P 2025
