Pith. sign in

REVIEW 2 major objections 3 minor 99 references

Ethics reporting in top security research is inconsistent and compliance-focused, with deep ethical reasoning rarely making it into the written record.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-04 19:12 UTC pith:YDUO22TF

load-bearing objection The first full-year census of ethics reporting in top-4 security venues, with a strong interview study—but the abstract overstates a 'lack' of risk–benefit discussion that its own tables contradict. the 2 major comments →

arxiv 2509.09351 v1 pith:YDUO22TF submitted 2025-09-11 cs.CR

[Extended] Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible Future

classification cs.CR
keywords security ethicsresearch ethicsmeta-analysisethics reportingMenlo ReportIRBpeer reviewusable security and privacy
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This paper claims that ethics reporting in top-tier computer security research is inconsistent and tilted toward formal compliance, with an emphasis on institutional approval, human subjects protection, and responsible disclosure, while the harder question of balancing harms and benefits is rarely discussed. The claim rests on a manual review of all 1,154 papers published in 2024 at the four main security conferences, plus interviews with 24 security researchers. The interviews show that authors do engage in substantive ethical reasoning, but that reasoning is mostly invisible in the published papers. A sympathetic reader would care because the paper reframes ethics in security research from a matter of individual conscience to a measurable, systemic feature of the publication pipeline, one that could be improved with clearer community standards and earlier, proactive guidance.

Core claim

By coding every paper published in 2024 at the big four security venues against the Menlo Report's four ethical principles—respect for persons, beneficence, justice, and respect for law and public interest—the authors find that 839 of 1,154 papers (about 73%) contain no discussion of ethics at all. Among the 315 papers that do engage with ethics, the dominant themes are institutional approval (121 board-approved, 19 exempt), confidentiality (110 papers), informed consent (89), and vulnerability disclosure (257 papers); the explicit balancing of risks and benefits appears in only 159 papers. Interviews with 24 authors, reviewers, ethics committee members, and program chairs reveal a community

What carries the argument

The central analytical instrument is the Menlo Report's four principles—respect for persons, beneficence, justice, and respect for law and public interest—used as a codebook to classify every paper in the corpus. Each paper was skimmed and keyword-checked for indicators of each principle, for IRB/ERB status, consent, deception, and vulnerability disclosure. The second mechanism is a two-stage qualitative study: a semi-structured interview guide covering decision-making, peer review, and hopes for the future, analyzed with open coding and affinity diagramming. Together these let the paper measure both the written record (what gets reported) and the lived process (what authors and reviewers ac

Load-bearing premise

The headline numbers depend on the reliability of three coders' manual classification of 1,154 papers; the paper reports only a 10% spot-check by the lead author and no formal inter-rater reliability statistic, and the authors themselves note they may have missed ethics discussions written in language they did not associate with ethics.

What would settle it

Recode a random sample of 200 papers from the corpus with two independent coders using the paper's own codebook; if inter-rater agreement (e.g., Cohen's kappa) falls below about 0.7, or if the recoded share of papers with no ethics discussion moves more than a few percentage points away from the reported 839/1154, the quantitative core of the claim is not stable. A complementary check is to run the paper's own keyword list over the full text of the 839 'no ethics' papers; if a substantial share contain terms like 'consent' or 'harm,' the manual screen may have missed discussions.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

If this is right

  • If the findings are right, the de facto ethics standard in top security venues is compliance-oriented: getting the board approval and writing the disclosure paragraph matters more than demonstrating that harms were weighed against benefits.
  • The written literature systematically underrepresents the ethical reasoning of authors, so readers—especially junior researchers—cannot learn the field's actual ethical practice from published papers alone.
  • Wide variation in calls for papers across venues means authors and reviewers face different and sometimes conflicting ethics expectations for essentially similar work.
  • Research ethics committees and peer reviewers operate without a shared framework, making ethics review subjective, reactive, and inconsistent across subdisciplines and geographies.
  • Because ethics is largely learned informally from advisors and colleagues, researchers without access to experienced mentors are at a structural disadvantage.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If the gap between interview reasoning and written reporting is real and caused partly by space and incentive constraints, then venue policies that allocate dedicated space for ethics reasoning (a change the paper notes one major conference has recently introduced) could measurably increase the depth of published ethics sections; this is a testable prediction.
  • The paper's focus on the Menlo Report may itself shape what is counted as 'ethics'; a complementary analysis coding for consequentialist vs. deontological reasoning, or for dual-use and environmental harms, could reveal whether risk-benefit balancing is genuinely rare or simply phrased in language the codebook missed.
  • The authors' deliberate choice not to release the full paper-level coding means the quantitative results cannot be independently audited; a privacy-preserving release of aggregated codes by venue and paper type would let the community verify the headline rates without identifying individual authors.
  • If the 'hidden curriculum' finding generalizes, formalizing ethics mentorship—for example, pairing junior researchers with ethics-experienced reviewers before submission—could reduce the inconsistency the paper documents.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 3 minor

Summary. This paper presents a data-driven assessment of ethics reporting and decision-making in computer security research. The authors manually coded all 1,154 papers published at the four top security conferences (CCS, IEEE S&P, NDSS, USENIX Security) in 2024 for the presence and type of ethics discussions, using a Menlo Report-derived codebook. They supplement this meta-analysis with 24 semi-structured interviews with security and privacy researchers, including authors, reviewers, ethics-committee members, and program chairs. The paper's central claims are that ethics reporting in published papers is inconsistent and compliance-oriented (e.g., review-board approval, human-subjects protection, responsible disclosure), that deeper ethical reasoning reported by authors is often absent from papers, and that the community lacks shared standards and guidance. The paper also proposes recommendations for conferences, review boards, and ethics education.

Significance. If the headline findings are accurate, this is a valuable empirical contribution to the ongoing discussion of research ethics in computer security. The manuscript makes its codebook, interview guide, and extended appendix available, and it provides a rare corpus-level snapshot of ethics reporting across a full publication year. The interview data add a useful qualitative layer, and the authors are transparent about many limitations, including sample bias and the non-generalizability of the interview findings. The main quantitative claim in the abstract, however, is not supported by the paper's own frequency data, which is a load-bearing inconsistency that must be addressed before the paper can be accepted.

major comments (2)
  1. [Abstract; Section 4.1, Table 3] The abstract states the meta-analysis found 'a lack of discussion of balancing harms and benefits,' but Table 3 reports that 'balancing/mitigating risks and benefits' is the most commonly coded Menlo principle, appearing in 159 papers—more than IRB/ERB approval (121) or human-subjects protection (116). Section 4.1 also explicitly says this was 'the most common discussion of ethics.' If 'lack' is meant to refer to depth or quality rather than presence, that dimension was not coded in the meta-analysis; the paper only records presence/absence. The abstract should be revised to match the data, or the authors should add a depth-based analysis to justify the current wording.
  2. [Section 3.1.2] The quantitative claims (e.g., 839 papers with no ethics discussion, 159 with risk-benefit discussion) rest entirely on manual coding by three researchers, yet no inter-rater reliability statistic is reported for the meta-analysis. The paper reports only a 10% spot-check by the lead author and team discussions for ambiguous cases. For the interview coding, Krippendorff's alpha > 0.80 is reported; an analogous reliability measure (or a detailed justification of the consensus process) should be provided for the paper coding, or at least for a reliability subsample, so readers can assess the stability of the headline numbers.
minor comments (3)
  1. [Abstract; Section 3.1] The phrase 'all 1154 top-tier security papers published in 2024' is imprecise: the dataset covers papers from four selected venues, not all top-tier security venues. The Limitations section correctly notes this, but the abstract should say 'all papers at the top four security conferences' to avoid overstatement.
  2. [Section 4.1] The claim that 'published research seems to view the Menlo Report principles as a useful framework' is an inference from the coders' mapping, not from authors' explicit use: only 36 papers explicitly referenced the Menlo Report. This sentence should be softened or clarified.
  3. [Appendix F, Table 3] The table is dense and the row/column totals are not always immediately checkable. Adding a 'Total' column or explicit totals in the table header would improve readability.

Circularity Check

0 steps flagged

No load-bearing circularity: the meta-analysis and interview findings rest on original coding and transcripts; self-citations are background only. One internal inconsistency in the abstract is not a circularity.

full rationale

The paper's central claims are empirical: a manual meta-analysis of 1,154 papers and a semi-structured interview study of 24 researchers. The quantitative results come from original coding using a codebook and keyword lists (Section 3.1), and the qualitative results come from original interview transcripts (Section 3.2). There is no fitted parameter later renamed as a prediction, no derived equation whose output equals its input, and no uniqueness theorem imported from the authors' prior work to force a choice. The paper does cite prior work by the same authors (e.g., Kohno et al. 2023 [47], Ramulu et al. 2024 [61], Schmüser et al. 2024 [68], Wei et al. 2024 [81]), but these citations appear in background, motivation, and example contexts, not as evidence for the paper's headline findings. The recommendation sections occasionally reference the authors' own prior ethical-frameworks paper, but those references are advisory and do not carry the empirical argument. The most notable issue is an internal inconsistency rather than circularity: the abstract claims 'a lack of discussion of balancing harms and benefits,' while Section 4.1 and Table 3 report that 'the most common discussion of ethics was on the principle of beneficence through balancing/mitigating risks and benefits (159),' a count higher than the IRB-approval (121) and human-subjects (116) categories the abstract calls a 'strong focus.' This is a correctness or presentation flaw in the paper's own evidence, not a case where a conclusion is equivalent to an input by construction. Similarly, the lack of a reported inter-rater reliability statistic for the paper meta-analysis is a methodological limitation, but it does not make the analysis circular. Overall, the derivation chain from data to conclusions is self-contained and does not reduce to the paper's inputs.

Axiom & Free-Parameter Ledger

0 free parameters · 3 axioms · 0 invented entities

No numeric free parameters or invented entities. The study relies on domain assumptions about representativeness of venues, reliability of manual coding, and honesty of self-reports.

axioms (3)
  • domain assumption The top-4 security conferences (CCS, IEEE S&P, NDSS, USENIX Security) are representative of computer security research for 2024.
    Section 3.1 states the choice of venues and discusses in limitations that specialized sub-discipline venues and workshops are excluded, so the census is not the whole field.
  • domain assumption Manual coding with the provided codebook and keyword list reliably identifies ethics discussions and Menlo-related content in papers.
    Section 3.1.2 describes the coding process; no inter-rater reliability is reported for the paper meta-analysis, so consistency is assumed.
  • domain assumption Interview participants' self-reports accurately reflect their ethical reasoning and practices.
    Section 3.2.3 and 3.4: qualitative analysis relies on self-report; participants may present themselves favorably, though authors felt they spoke openly.

pith-pipeline@v1.3.0-alltime-deepseek · 29159 in / 10517 out tokens · 103079 ms · 2026-08-04T19:12:31.244831+00:00 · methodology

0 comments
read the original abstract

Ethical questions are discussed regularly in computer security. Still, researchers in computer security lack clear guidance on how to make, document, and assess ethical decisions in research when what is morally right or acceptable is not clear-cut. In this work, we give an overview of the discussion of ethical implications in current published work in computer security by reviewing all 1154 top-tier security papers published in 2024, finding inconsistent levels of ethics reporting with a strong focus of reporting institutional or ethics board approval, human subjects protection, and responsible disclosure, and a lack of discussion of balancing harms and benefits. We further report on the results of a semi-structured interview study with 24 computer security and privacy researchers (among whom were also: reviewers, ethics committee members, and/or program chairs) and their ethical decision-making both as authors and during peer review, finding a strong desire for ethical research, but a lack of consistency in considered values, ethical frameworks (if articulated), decision-making, and outcomes. We present an overview of the current state of the discussion of ethics and current de-facto standards in computer security research, and contribute suggestions to improve the state of ethics in computer security research.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

99 extracted references · 7 canonical work pages

  1. [1]

    ACM Ethics - The Official Site of the Association for Computing Machinery’s Committee on Professional Ethics. 2016. Code of Ethics - ACM Ethics. https: //ethics.acm.org/code-of-ethics/. Accessed: 2022-01-01

  2. [2]

    Mamia Agbese, Rahul Mohanani, Arif Khan, and Pekka Abrahamsson. 2023. Im- plementing AI ethics: Making sense of the ethical requirements.ACM Proceedings of the Evaluation and Assessment in Software Engineering Conference1, 1 (2023)

  3. [3]

    Ross Anderson. 2012. Ethics Committees and IRBs: Boon, or Bane, or More Research Needed?Financial Cryptography and Data Security(2012), 133–135

  4. [4]

    Association for Computing Machinery. 2022. ACM Code of Ethics and Profes- sional Conduct. https://www.acm.org/code-of-ethics

  5. [5]

    Michael Bailey, David Dittrich, Erin Kenneally, and Doug Maughan. 2012. The Menlo Report.IEEE Security & Privacy Magazine10, 2 (2012), 71–75. doi:10.1109/ MSP.2012.52

  6. [6]

    Virginia Braun and Victoria Clarke. 2021. Can I use TA? Should I use TA? Should I not use TA? Comparing reflexive thematic analysis and other pattern-based qualitative analytic approaches.Counselling and psychotherapy research21, 1 (2021), 37–47

  7. [7]

    Philip AE Brey. 2012. Anticipatory Ethics for Emerging Technologies.NanoEthics 6, 1 (2012), 1–13

  8. [8]

    Barry Brown, Alexandra Weilenmann, Donald McMillan, and Airi Lampinen

  9. [9]

    Noelle Brown, Benjamin Xie, Ella Sarder, Casey Fiesler, and Eliane S Wiese. 2024. Teaching ethics in computing: a systematic literature review of ACM computer science education publications.ACM Transactions on Computing Education24, 1 (2024), 1–36

  10. [10]

    Amy Bruckman. 2020. ’Have you thought about . . .’.Commun. ACM63, 9 (2020), 38–40. doi:10.1145/3377405

  11. [11]

    Elizabeth Buchanan, John Aycock, Scott Dexter, David Dittrich, and Erin Hviz- dak. 2011. Computer science security research and human subjects: emerging considerations for research ethics boards.Journal of empirical research on human research ethics : JERHRE6, 2 (2011), 71–83. doi:10.1525/jer.2011.6.2.71

  12. [12]

    Sam Burnett and Nick Feamster. 2015. Encore: Lightweight measurement of web censorship with cross-origin requests. InProceedings of the 2015 ACM conference on special interest group on data communication. 653–667

  13. [13]

    Kevin Butler and Kurt Thomas. 2022. Message from the USENIX Security ’22 Program Co-Chairs. (2022). https://www.usenix.org/sites/default/files/sec22_ [Extended] Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible Future CCS ’25, October 13–17, 2025, Taipei, Taiwan message.pdf

  14. [14]

    Monica Chin. 2021. How a university got itself banned from the Linux ker- nel. https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of- minnesota-banned-open-source. Accessed: 2024-04-09

  15. [15]

    Shruthi Sai Chivukula, Colin Gray, Ziqing Li, Anne C Pivonka, and Jingning Chen. 2021. Surveying a Landscape of Ethics-Focused Design Methods.ACM Journal on Responsible Computing(2021)

  16. [16]

    2020.The ethics of cybersecurity

    Markus Christen, Bert Gordijn, and Michele Loi. 2020.The ethics of cybersecurity. Springer Nature

  17. [17]

    David B. Resnik. 2022. What Is Ethics in Research & Why Is It Important? https: //www.niehs.nih.gov/research/resources/bioethics/whatis/index.cfm. Accessed: 2024-09-04

  18. [18]

    Alexandra Dirksen, Sebastian Giessler, Hendrik Erz, Martin Johns, and Tobias Fiebig. 2024. Don’t Patch the Researcher, Patch the Game: A Systematic Approach for Responsible Research via Federated Ethics Boards. InProceedings of the New Security Paradigms Workshop. 126–141

  19. [19]

    David Dittrich, Erin Kenneally, and Michael Bailey. 2013. Applying Ethical Prin- ciples to Information and Communication Technology Research: A Companion to the Menlo Report.SSRN Electronic Journal(2013). doi:10.2139/ssrn.2342036

  20. [20]

    That’s important, but

    Kimberly Do, Rock Yuren Pang, Jiachen Jiang, and Katharina Reinecke. 2023. “That’s important, but... ”: How Computer Science Researchers Anticipate Un- intended Consequences of Their Research Innovations. InProceedings of the 2023 CHI Conference on Human Factors in Computing Systems (CHI ’23). ACM. doi:10.1145/3544548.3581347

  21. [21]

    Serge Egelman, Joseph Bonneau, Sonia Chiasson, David Dittrich, and Stuart Schechter. 2012. It’s not stealing if you need it: A panel on the ethics of performing research using public data of illicit origin. InFinancial Cryptography and Data Security: FC 2012 Workshops, USEC and WECSR 2012, Kralendijk, Bonaire, March 2, 2012, Revised Selected Papers 16. Sp...

  22. [22]

    Felix Anand Epp, Tim Moesgen, Antti Salovaara, Emmi Pouta, and İdil Gaziulusoy

  23. [23]

    Shencha Fan, Jackson Sippe, Sakamoto San, Jade Sheffey, David Fifield, Amir Houmansadr, Elson Wedwards, and Eric Wustrow. 2025. Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China. In 32nd Annual Network and Distributed System Security Symposium, NDSS 2025, San Diego, California, USA, February 24-28, 2025. The Internet So- ciety. h...

  24. [24]

    Jennifer Fereday and Eimear Muir-Cochrane. 2006. Demonstrating rigor using thematic analysis: A hybrid approach of inductive and deductive coding and theme development.International journal of qualitative methods5, 1 (2006)

  25. [25]

    Casey Fiesler, Natalie Garrett, and Nathan Beard. 2020. What Do We Teach When We Teach Tech Ethics? A Syllabi Analysis. InProceedings of the 51st ACM Technical Symposium on Computer Science Education. Association for Computing Machinery. doi:10.1145/3328778.3366825

  26. [26]

    Megan Finn and Katie Shilton. 2023. Ethics governance development: The case of the Menlo Report.Social Studies of Science53, 3 (2023), 315–340

  27. [27]

    Ivan Flechais and George Chalhoub. 2023. Practical Cybersecurity Ethics: Mapping CyBOK to Ethical Concerns. InProceedings of the 2023 New Security Paradigms Workshop. 62–75

  28. [28]

    Paul Formosa, Michael Wilson, and Deborah Richards. 2021. A principlist framework for cybersecurity ethics.Computers & Security109 (2021), 102382. doi:10.1016/j.cose.2021.102382

  29. [29]

    Batya Friedman, Peter H Kahn, Alan Borning, and Alina Huldtgren. 2013. Value sensitive design and information systems.Early engagement and new technologies: Opening up the laboratory(2013), 55–95

  30. [30]

    Simson L Garfinkel. 2008. IRBs and Security Research: Myths, Facts and Mission Creep.UPSEC8 (2008), 1–5

  31. [31]

    Martyna Gliniecka. 2023. The ethics of publicly available data research: A situated ethics framework for Reddit.Social Media+ Society9, 3 (2023)

  32. [32]

    Colin M Gray and Shruthi Sai Chivukula. 2019. Ethical mediation in UX practice. InProceedings of the 2019 CHI conference on human factors in computing systems

  33. [33]

    Florian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz, and Ben Stock. 2024. Where are the red lines? Towards Ethical Server-side Scans in Security and Privacy Research. In2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 103–103

  34. [34]

    Bigham, Johannes Schöning, Ehsan Hoque, Jason Ernst, Yonatan Bisk, Luigi de Russis, Lana Yarosh, Bushra Anjum, Danish Contractor, and Cathy Wu

    Brent Hecht, Lauren Wilcox, Jeffrey P. Bigham, Johannes Schöning, Ehsan Hoque, Jason Ernst, Yonatan Bisk, Luigi de Russis, Lana Yarosh, Bushra Anjum, Danish Contractor, and Cathy Wu. 2021. It’s Time to Do Something: Mitigating the Negative Impacts of Computing Through a Change to the Peer Review Process. https://arxiv.org/pdf/2112.09544

  35. [35]

    Monique M Hennink, Bonnie N Kaiser, and Vincent C Marconi. 2017. Code Saturation Versus Meaning Saturation: How Many Interviews Are Enough? Qualitative health research27, 4 (2017), 591–608

  36. [36]

    2021.Princeton privacy study halts GDPR/CCPA research over ethics concerns and industry blowback

    Jon Henshaw. 2021.Princeton privacy study halts GDPR/CCPA research over ethics concerns and industry blowback. https://coywolf.com/news/web- development/princeton-radboud-researchers-halt-gdpr-ccpa-study-over- ethics-concerns-and-industry-blowback/ Last updated December 27, 2021

  37. [37]

    Sarah Beth Hopton. 2021. The Tarot of Tech.Equipping Technical Communicators for Social Justice Work: Theories, Methodologies, and Pedagogies(2021), 158

  38. [38]

    Hsiu-Fang Hsieh and Sarah E Shannon. 2005. Three Approaches to Qualitative Content Analysis.Qualitative health research15, 9 (2005), 1277–1288

  39. [39]

    Jina Huh-Yoo and Emilee Rader. 2020. It’s the Wild, Wild West: Lessons Learned From IRB Members’ Risk Perceptions Toward Digital Research Data.Proceedings of the ACM on Human-Computer Interaction4, CSCW1 (2020), 1–22

  40. [40]

    IEEE Security and Privacy. 2022. REC Annual Summary. https://docs.google.com/ document/d/15x5Qd1UTaoMSRZgRRvurPbgRg4SWWLQKhG41ouYV0TY/edit. Accessed: 2024-06-06

  41. [41]

    IEEE Security and Privacy Symposium. 2022. Call for Papers. https://www.ieee- security.org/TC/SP2022/cfpapers.html. Accessed: 2024-09-04

  42. [42]

    IEEE Security and Privacy Symposium 2024. 2024. Call for Papers. https://sp2024. ieee-security.org/changes-cfp.html. Accessed: 05-06-2024

  43. [43]

    IEEE Symposium on Security and Privacy. 2021. 2021 Program Committee State- ment. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_Statement. pdf. Accessed: 05-06-2024

  44. [44]

    IEEE Symposium on Security and Privacy. 2021. Call for Papers. https://www.ieee- security.org/TC/SP2022/cfpapers.html

  45. [45]

    Institute of Electrical & Electronics Engineers. 2023. IEEE Code of Ethics. https: //www.ieee.org/about/corporate/governance/p7-8.html. Accessed: 2023-06-03

  46. [46]

    Kai-Kristian Kemell, Ville Vakkuri, and Erika Halme. 2022. Utilizing user stories to bring AI ethics into practice in software engineering. InInternational Conference on Product-Focused Software Process Improvement. Springer, 553–558

  47. [47]

    Tadayoshi Kohno, Yasemin Acar, and Wulf Loh. 2023. Ethical Frameworks and Computer Security Trolley Problems: Foundations for Conversations. In32nd USENIX Security Symposium (USENIX Security 23). 5145–5162

  48. [48]

    Daria Korobenko, Anastasija Nikiforova, and Rajesh Sharma. 2024. Towards a Privacy and Security-Aware Framework for Ethical AI: Guiding the Development and Assessment of AI Systems. InProceedings of the 25th Annual International Conference on Digital Government Research. 740–753

  49. [49]

    2001.Crypto: How the Code Rebels Beat the Government–Saving Privacy in the Digital Age

    Steven Levy. 2001.Crypto: How the Code Rebels Beat the Government–Saving Privacy in the Digital Age. Penguin

  50. [50]

    Kevin Macnish and Jeroen van der Ham. 2020. Ethics in cybersecurity research and practice.Technology in Society63 (2020), 101382. doi:10.1016/j.techsoc.2020. 101382

  51. [51]

    Michael A Madaio, Luke Stark, Jennifer Wortman Vaughan, and Hanna Wallach

  52. [52]

    Tina Marjanov and Alice Hutchings. 2025. SoK: Digging into the Digital Under- world of Stolen Data Markets. In2025 IEEE Symposium on Security and Privacy (SP). 1–18. doi:10.1109/SP61157.2025.00037

  53. [53]

    Nora McDonald, Adegboyega Akinsiku, Jonathan Hunter-Cevera, Maria Sanchez, Kerrie Kephart, Mark Berczynski, and Helena M Mentis. 2022. Responsible computing: A Longitudinal Study of a Peer-led Ethics Learning Framework.ACM Transactions on Computing Education (TOCE)22, 4 (2022), 1–21

  54. [54]

    Andrew McNamara, Justin Smith, and Emerson Murphy-Hill. 2018. Does ACM’s Code of ethics change ethical decision making in software development?. In Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering(Lake Buena Vista, FL, USA)(ESEC/FSE 2018). Association for Co...

  55. [55]

    Brent Mittelstadt. 2019. Principles alone cannot guarantee ethical AI.Nature machine intelligence1, 11 (2019), 501–507

  56. [56]

    Giovane Moura and John Heidemann. 2023. Vulnerability Disclosure Considered Stressful.ACM SIGCOMM Computer Communication Review53 (07 2023), 2–10. doi:10.1145/3610381.3610383

  57. [57]

    2025.‘Unethical’ AI Research on Reddit Under Fire

    Kathleen O’Grady. 2025.‘Unethical’ AI Research on Reddit Under Fire. https: //www.science.org/content/article/unethical-ai-research-reddit-under-fire Ac- cessed: 2025-07-22

  58. [58]

    Rock Yuren Pang, Sebastin Santy, René Just, and Katharina Reinecke. 2024. BLIP: Facilitating the Exploration of Undesirable Consequences of Digital Technologies. InProceedings of the CHI Conference on Human Factors in Computing Systems

  59. [59]

    Emerson W. Pugh. 2009. Creating the IEEE Code of Ethics. In2009 IEEE Conference on the History of Technical Societies. doi:10.1109/HTS.2009.5337855

  60. [60]

    Robert Ramirez, Shun Inagaki, Masaki Shimaoka, and Kenichi Magata. 2020. A cybersecurity research ethics decision support UI.USENIX Association(2020)

  61. [61]

    Harshini Sri Ramulu, Helen Schmitt, Dominik Wermke, and Yasemin Acar. 2024. Security and Privacy Software Creators’ Perspectives on Unintended Conse- quences. In2024 33rd USENIX Security Symposium. https://www.usenix.org/ system/files/sec24fall-prepub-1692-ramulu.pdf

  62. [62]

    Paul Rehren and Hanno Sauer. 2024. Another brick in the wall? moral education, social learning, and moral progress.Ethical Theory and Moral Practice(2024). CCS ’25, October 13–17, 2025, Taipei, Taiwan Harshini Sri Ramulu et al

  63. [63]

    Dennis Reidsma, Jeroen van der Ham, and Andrea Continella. 2023. Operational- izing Cybersecurity Research Ethics Review: From principles and guidelines to practice.Proceedings of the 2nd International Workshop on Binary Analysis Research(2023). doi:10.14722/ethics.2023.237352

  64. [64]

    Wessel Reijers, David Wright, Philip Brey, Karsten Weber, Rowena Rodrigues, Declan O’Sullivan, and Bert Gordijn. 2017. Methods for practising ethics in Research and Innovation: A Literature Review, critical analysis and rec- ommendations.Science and Engineering Ethics24, 5 (09 2017), 1437–1481. doi:10.1007/s11948-017-9961-8

  65. [65]

    Todd W. Rice. 2008. The historical, ethical, and legal background of human- subjects research.Respiratory care53, 10 (2008), 1325–1329

  66. [66]

    Phillip Rogaway. 2015. The moral character of cryptographic work.Cryptology ePrint Archive(2015)

  67. [67]

    Benjamin Saunders, Julius Sim, Tom Kingstone, Shula Baker, Jackie Waterfield, Bernadette Bartlam, Heather Burroughs, and Clare Jinks. 2018. Saturation in qual- itative research: exploring its conceptualization and operationalization.Quality & quantity52 (2018), 1893–1907

  68. [68]

    Juliane Schmüser, Harshini Sri Ramulu, Noah Wöhler, Christian Stransky, Felix Bensmann, Dimitar Dimitrov, Sebastian Schellhammer, Dominik Wermke, Stefan Dietze, Yasemin Acar, et al. 2024. Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter. InProceedings of the 2024 CHI Conference on Human Factors in Computing Syst...

  69. [69]

    Schwenzer

    Karen J. Schwenzer. 2011. Best practice & research in anaesthesiology issue on new approaches in clinical research ethics in clinical research.Best practice & research. Clinical anaesthesiology(2011). doi:10.1016/j.bpa.2011.08.003

  70. [70]

    Hong Shen, Wesley H Deng, Aditi Chattopadhyay, Zhiwei Steven Wu, Xu Wang, and Haiyi Zhu. 2021. Value cards: An educational toolkit for teaching social impacts of machine learning through deliberation. InProceedings of the 2021 ACM conference on fairness, accountability, and transparency. 850–861

  71. [71]

    Katie Shilton, Megan Finn, and Quinn DuPont. 2021. Shaping ethical computing cultures.Commun. ACM64, 11 (2021), 26–29. doi:10.1145/3486639

  72. [72]

    Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, and Tadayoshi Kohno

  73. [73]

    Konstantinos Solomos, John Kristoff, Chris Kanich, and Jason Polakis. 2021. Tales of favicons and caches: Persistent tracking in modern browsers. InNetwork and Distributed System Security Symposium

  74. [74]

    Flawed, but like democracy we don’t have a better system

    Ananta Soneji, Faris Bugra Kokulu, Carlos Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, and Adam Doupé. 2022. “Flawed, but like democracy we don’t have a better system”: The Experts’ Insights on the Peer Review Process of Evaluating Security Papers. In2022 IEEE Symposium on Security and Privacy (SP). IEEE, 1845–1862

  75. [75]

    Shun Takai and Kosuke Ishii. 2010. A use of subjective clustering to support affinity diagram results in customer needs analysis.Concurrent Engineering (2010)

  76. [76]

    Thomas, Sergio Pastrana, Alice Hutchings, Richard Clayton, and Alas- tair R

    Daniel R. Thomas, Sergio Pastrana, Alice Hutchings, Richard Clayton, and Alas- tair R. Beresford. 2017. Ethical issues in research using datasets of illicit origin. InProceedings of the 2017 Internet Measurement Conference(London, United King- dom)(IMC ’17). Association for Computing Machinery, New York, NY, USA, 445–462. doi:10.1145/3131365.3131389

  77. [77]

    It’s Not Exactly Meant to Be Realistic

    Michelle Tran and Casey Fiesler. 2024. " It’s Not Exactly Meant to Be Realistic": Student Perspectives on the Role of Ethics In Computing Group Projects. In Proceedings of the 2024 ACM Conference on International Computing Education Research-Volume 1. 517–526

  78. [78]

    Department of Homeland Security

    U.S. Department of Homeland Security. 2012. The Menlo Report: Eth- ical Principles Guiding Information and Communication Technology Research. https://www.dhs.gov/sites/default/files/publications/CSD- MenloPrinciplesCORE-20120803_1.pdf DHS, Science and Technology

  79. [79]

    USENIX Security. 2024. USENIX Security Ethics Guidelines. https://www.usenix. org/conference/usenixsecurity25/ethics-guidelines. Accessed: 2024-09-04

  80. [80]

    Jessica Vitak, Nicholas Proferes, Katie Shilton, and Zahra Ashktorab. 2017. Ethics regulation in social computing research: Examining the role of institutional review boards.Journal of Empirical Research on Human Research Ethics(2017)

Showing first 80 references.