Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths Forward
Warda Usman, Yixin Zou, Daniel Zappala
Abstract
Human-centered threat modeling (HCTM) is an emerging area within security and privacy research that focuses on how people define and navigate threats in various social, cultural, and technological contexts. While researchers increasingly approach threat modeling from a human-centered perspective, little is known about how they prepare for and engage with HCTM in practice. In this work, we conduct 23 semistructured interviews with researchers to examine the state of HCTM, including how researchers design studies, elicit threats, and navigate values, constraints, and long-term goals. We find that HCTM is not a prescriptive process but a set of evolving practices shaped by relationships with participants, disciplinary backgrounds, and institutional structures. Researchers approach threat modeling through sustained groundwork and participant-centered inquiry, guided by values such as care, justice, and autonomy. They also face challenges including emotional strain, ethical dilemmas, and structural barriers that complicate efforts to translate findings into real-world impact. We conclude by identifying opportunities to advance HCTM through shared infrastructure, broader recognition of diverse contributions, and stronger mechanisms for translating findings into policy, design, and societal change.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6460e2ee-a50f-41fa-a1dc-ea4b324a350bBuilds on29
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh et al.S&P 2021 · 175 citations
- IoT Inspector: Crowdsourcing Labeled Network Traffic from Smart Home Devices at ScaleDanny Yuxing Huang, Noah J. Apthorpe, Frank Li, Gunes Acar et al.UbiComp 2020 · 171 citations
- A Framework of Severity for Harmful Content OnlineMorgan Klaus Scheuerman, Jialun Aaron Jiang, Casey Fiesler, Jed R. BrubakerCSCW 2021 · 113 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 95 citations
Related papers
- SoK: A Framework and Guide for Human-Centered Threat Modeling in Security and Privacy ResearchWarda Usman, Daniel ZappalaS&P 2025
- Using HCI in Cross-Disciplinary Teams: A Case Study of Academic Collaboration in HCI-Health Teams in the US Using a Team Science PerspectiveElena Agapie, Shefali Haldar, Sharmaine Galvez PobleteCSCW 2022 · 22 citations
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
- Understanding Gendered Experiences of Harassment Among Pakistani Young Adults Using Human-Centered Threat ModelingWarda Usman, Taha, Saba Iqbal, Amna Batool et al.CHI 2026 · 3 citations
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 14 citations
