C9.06.7Trust erosion as false-positive costdesignresearch

Evaluating false-positive cost must include long-term trust loss, not only the harm of a single error

Aliases: cry-wolf · trust erosion · long-run false-positive cost

What it is

The immediate cost of one false positive is an interruption, a scare, or an extra cancel tap. Summing those still undercounts: people stop believing the next alarm, revoke permission, and the channel is gone when it is needed. Trust erosion is the delayed cost of false alarms. It shows up after repetition, not in a single confusion matrix.

Why it happens

The cry-wolf effect in alarm research is that repeated false reports slow and thin later responses. Physiological channels add a layer: the body being mis-described becomes interference with self-judgment (“the watch says I’m stressed, maybe I should rest”) or hostility toward the device. Trust is a subjective estimate of the next alarm’s likelihood; false positives pull it down. Past a point, the rational policy is to ignore or uninstall. A single medical or operational miss can be huge, but consumer settings more often push people over this ignore threshold. Long-run cost also includes what teams spend to keep users (gifts, support), which rarely enters model evaluation.

Studying it

Use a longitudinal design: control false-alarm rate over days to weeks, and measure response time, response rate, permission loss, and “would you still attend to it next time.” Factors: false-alarm density, presence of an after-the-fact explanation. Outcomes: time-to-channel-death in a survival analysis, missed responses on real events. A one-shot laboratory task has no time for trust to decay and writes false alarms as negligible friction. Count “uninstall” and “notifications off but still worn” separately; the latter is silent trust death.

Where it stops holding

Where users have no exit (wards, shop floors), trust erosion shows up as falling compliance and tape over speakers, not as store ratings. One severe false positive (a mistaken emergency call) can destroy trust without repetition. The opposite direction exists too: long stretches with zero false alarms and an occasional miss make people doubt the channel is still alive. Trust curves differ across people; a mean hides the cohort that uninstalls first.

Applying it

  • Put “permission still on at 7 and 30 days” and “response rate on true events” into false-alarm acceptance, not only that day’s confusion matrix.
  • Cool down and merge repeated same-class false alarms so frequency does not shove people over the ignore threshold.
  • After each false alarm, give one checkable reason, slowing attribution to “the device talks nonsense.”
  • Verify by raising false-alarm density for a week in a staged rollout and watching whether response to true events falls in week two; that drop is trust cost, not that week’s single-error harm.

Related

  • Same group: C9.06.1 False-positive and false-negative costs are asymmetric · C9.06.2 Threshold choice is a product decision, not an algorithm decision · C9.06.3 High-consequence actions must not be decided by a single sensor · C9.06.4 Medical alarms usually prefer false positives over false negatives; consumer settings often reverse that · C9.06.5 Cost asymmetry should appear as a concrete classification threshold, not only as a stated principle · C9.06.6 Reusing one sensor across functions may require different false-positive tolerances
  • Adjacent: C9.13 Informed Consent and Correction of Implicit Inferences · C7.08 False Wakes
  • Search: cry-wolf effect · trust erosion · alarm disablement

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/C9.06.7