Tailoring a Persuasive Game to Promote Secure Smartphone Behaviour
Honorable MentionAuthors
Serious & Functional GamesGamification DesignPrivacy by Design & User ControlCybersecurity EngineersAthletes & Fitness EnthusiastsPersonal Trainers & Fitness Coaches
Title of the Paper
Tailoring a Persuasive Game to Promote Secure Smartphone Behaviour
Paper Information
- Research Area: Human-Computer Interaction (HCI), Persuasive Technology, and Cybersecurity
- Keywords: Tailored persuasive games, smartphone security behavior, Protection Motivation Theory, Regulatory Focus Theory, game design
Research Background and Problem Statement
- Identified Problems or Challenges: Although smartphones have become an indispensable part of daily life, users have low awareness of secure behaviors and are unable to effectively prevent security and privacy threats. Previous interventions (e.g., videos, documents, events) have shown limited effectiveness in raising users' cybersecurity awareness.
- Why the Problem is Important:
- The Android operating system, due to its open design for user control, is at higher risk of social engineering attacks.
- Users' insufficient understanding of smartphone permission management and data privacy protection increases the risk of data breaches and attacks.
- Raising awareness of cybersecurity behaviors is crucial for reducing potential threats and enhancing data protection capabilities.
- Research Motivation and Related Work:
- Persuasive games have been proven to change user behavior in other domains (e.g., health, physical activity).
- Previous game attempts focused on security issues like phishing attacks and password management, but their "one-size-fits-all" design failed to cater to diverse user needs.
- Regulatory Focus Theory (RFT) provides a logical framework for personalized user experiences by distinguishing between "promotion-focused" and "prevention-focused" behavioral tendencies, enabling the development of more targeted interventions.
Solution
- Core Method and Solution:
- Designed a 2D retro-themed persuasive game based on Regulatory Focus Theory to encourage users to adopt safer smartphone usage behaviors.
- Customized two game versions:
- Promotion-Focused Version: Motivates users to achieve goals through accomplishments/positive rewards.
- Prevention-Focused Version: Motivates users to achieve goals by avoiding negative consequences.
- The game design integrates Protection Motivation Theory (PMT) and Persuasive Systems Design (PSD) strategies.
- Innovative Aspects:
- First application of Regulatory Focus Theory in persuasive game design for smartphone security behavior.
- Game content covers a wide range of smartphone security and privacy scenarios, with feedback mechanisms to enhance user learning.
- Integrated interactivity and real-world security contexts into the gaming experience.
- Implementation Steps and Techniques:
- Game Development: Developed using the Unity engine with a 2D retro style for easy accessibility.
- Game Mechanics:
- Permission collection tasks, interactive scenarios based on multiple-choice questions, hidden area settings, etc.
- Provides instant feedback and rewards (e.g., health points).
- User Customization:
- Players are assigned different versions based on their motivational tendencies assessed via the Regulatory Focus Questionnaire (RFQ) before participation.
- Evaluation Metrics and Mechanisms:
- PMT scales are used to assess changes in users' behavioral intentions.
- The Intrinsic Motivation Inventory (IMI) evaluates user satisfaction and intrinsic motivation during gameplay.
Research Outcomes
- Specific Results:
- User Behavior: After completing the game, players showed a significant increase in their intention to adopt secure smartphone behaviors, especially technical actions (e.g., using VPNs, managing permissions).
- Effectiveness of Customization: Compared to non-customized versions, players preferred game versions aligned with their motivational type, which helped improve overall engagement and secure behaviors.
- User Experience:
- Game design elements (e.g., retro style, hidden areas) enhanced players' enjoyment and satisfaction.
- Players reported the game as educational, learning new security concepts through interactive quizzes.
- Experiments and Evaluation:
- A 10-day mixed-method study (102 users, 25 interviews) validated the effectiveness of the game design.
- Customized game versions significantly improved players' in-game behaviors and learning experiences.
- Limitations and Future Directions:
- Limitations:
- The study focused on the Android platform and did not cover iOS systems or other device types.
- Data collection relied mainly on self-reports, which may introduce bias.
- Future Directions:
- Expand to other operating systems and develop PC or console versions of the game.
- Conduct long-term longitudinal studies to observe sustained changes in user behavior.
- Explore the integration of games into mental health domains, enabling users to improve both security behaviors and psychological well-being.
- Limitations:
This paper demonstrates the strong potential of tailored persuasive games in enhancing users' cybersecurity behaviors. Future research can further optimize personalized designs to provide more effective and engaging learning methods for diverse user groups.
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- How do regulatory focus theory-based customized persuasive games affect users' smartphone security behavior?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- Do users' motivation types (e.g., promotion-focused, prevention-focused) affect their engagement and learning outcomes with personalized persuasive games?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- How can gamified interaction improve users' permission management and data protection behavior in smartphone privacy and security scenarios?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
lightbulb
Practical Problems
1- Users have low smartphone security awareness and cannot effectively respond to privacy and data breach risks.Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
No related papers with ≥60% similarity
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3581038
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
Honorable Mention
group
Authors
3 authors
sell
Subtopics
Serious & Functional Games, Gamification Design, Privacy by Design & User Control
work
Professions
Cybersecurity Engineers, Athletes & Fitness Enthusiasts, Personal Trainers & Fitness Coaches
article
Content Status
Full text indexed
hub
Related Papers
0 related papers