Who am I Talking to? A Large-Scale Measurement of Surface Attribution Across Real-World Security and Privacy Interfaces

Privacy by Design & User ControlPrivacy Perception & Decision-MakingExplainable AI (XAI)UI/UX DesignersCybersecurity EngineersPrivacy Policy Makers

Paper Title

Who am I Talking to? A Large-Scale Measurement of Surface Attribution Across Real-World Security and Privacy Interfaces

Publication Info

  • Topic area: Usable security and privacy, focusing on user interface (UI) attribution.
  • Keywords: Surface attribution, user interfaces, trusted UI, mental models, security, privacy, Android, Chrome, permission prompts, branding.

Background and Problem

  • Problem / challenge: Users struggle to correctly attribute the source of UI elements (e.g., OS, browser, app, website), which can undermine security and privacy mechanisms reliant on trusted UI.
  • Significance: Misattribution can lead to phishing, scams, or incorrect privacy decisions, as users fail to recognize trusted UI or understand where to manage settings.
  • Motivation and related work: Prior research has explored mental models, trusted UI, and phishing but has not directly measured users’ ability to attribute UI elements to their sources. This paper addresses this gap by empirically measuring surface attribution and identifying influencing factors.

Solution

  • Proposed approach: Large-scale vignette-based surveys to measure users' ability to attribute UI elements to their correct source and evaluate factors influencing attribution.
  • Novelty:
    1. First empirical measurement of surface attribution across desktop and mobile platforms.
    2. Analysis of factors affecting attribution, including familiarity, branding, positioning, and user data presence.
    3. Evaluation of the impact of added branding cues on Android permission prompts.
  • Procedure and key techniques:
    • Conducted two large-scale surveys (N = 4,400 and N = 3,057) targeting Chrome users on Windows and Android.
    • Tested attribution across 61 UI surfaces varying in branding, familiarity, positioning, and data content.
    • Investigated the effect of adding "Security & Privacy" branding and explanatory text to Android permission prompts.

Results

  • Concrete findings:
    • Correct attribution rates were low: 55% on desktop and 53% on mobile.
    • Familiarity and brand cues (e.g., logos, styling) improved attribution by up to 34 percentage points.
    • UI positioning (e.g., "line of death") had minimal impact on attribution.
    • Adding "Security & Privacy" branding to Android permission prompts did not significantly improve attribution, though explanatory text improved action-based understanding for some users.
  • Advantage over baselines:
    • Identified specific factors (familiarity, branding) that improve attribution, while challenging assumptions about the effectiveness of spatial positioning.
    • Demonstrated that branding alone is insufficient to address attribution challenges.
  • Experiments / evaluation:
    • Study 1 focused on Chrome UI attribution across desktop and mobile platforms.
    • Study 2 examined Android permission prompts with and without branding cues across three mobile ecosystems (stock Android, Samsung, Apple).
    • Metrics included correct attribution rates, perceived responsibility, and action-based understanding.
  • Limitations and future work:
    • Synthetic survey setup may not fully replicate real-world contexts.
    • Limited to honest UIs; future work should explore spoofing scenarios.
    • Focused on U.S. participants; cross-cultural studies are needed.
    • Further research is required to link attribution errors to security and privacy behaviors.

Summary

This paper provides the first large-scale empirical measurement of users' ability to attribute UI elements to their correct source, revealing a low overall accuracy of 53–55%. Factors such as familiarity and brand cues significantly improved attribution, while UI positioning had minimal impact. Adding branding to Android permission prompts showed limited success, with explanatory text improving action-based understanding but not perceived responsibility. These findings highlight the fragility of relying on trusted UI for security and privacy decisions and suggest the need for system-level safeguards and user education. Future work should explore the behavioral consequences of misattribution and test interventions across diverse contexts and populations.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/222921/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3791287
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
2 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Explainable AI (XAI)
work
Professions
UI/UX Designers, Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers