Pith. sign in

REVIEW 3 major objections 4 minor 80 references

Users' Mental Models of Generative AI Chatbot Ecosystems

T0 review · 3 major / 4 minor · reviewed 2026-08-09 · deepseek-v4-flash

Pith's one-line read Users hold four distinct mental models of AI chatbot ecosystems, and trust third-party plugins more than first-party ones.

desk verdict Solid taxonomy, but the headline comparative claim is confounded by unequal task conditions and inconsistent numbers. read the letter →

arxiv 2501.19211 v1 pith:TATXQOI6 submitted 2025-01-31 cs.HC

classification cs.HC
keywords mentalmodelsgenerativeAIchatbotsprivacyandsecurityhuman-computerinteractionchatbotecosystemstrustpluginsfirst-partyvsthird-party
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Through 21 interviews in which people drew the data-flow diagrams of two real chatbot tasks, this paper tries to establish that users do not have a single picture of how generative-AI chatbot ecosystems work: they hold four distinct mental models, each defined by the role they assign to the chatbot (key player, medium, representation of its parent company, or independent agent). The paper further claims that the mental model is not stable across ecosystems: for Google's Gemini, a first-party ecosystem, participants split across all four models, while for ChatGPT with an Expedia plugin, a third-party ecosystem, all 21 participants used the same simple Agent model. That consistency is associated with higher trust and fewer privacy concerns toward the third-party system, opposite to the usual assumption that users trust first-party services more. The paper argues this happens because the third-party interface makes the data flow visible and familiar, whereas the integrated first-party ecosystem is opaque. If correct, the finding means users' privacy decisions about AI assistants are shaped by how clearly they can see who touches their data, not by brand familiarity alone.

What carries the argument

The central object is the mental model, defined as the user's internal picture of which entities exist in the chatbot ecosystem and how personal data flows between them. The paper elicits these models with a drawing exercise: after a scripted hotel-booking interaction with each chatbot, participants drew diagrams of the entities and data flows, and the researchers coded the diagrams together with the interview transcripts. The distinguishing mechanism is the 'role of the chatbot' as the axis of classification, producing four named models (Key Player, Medium, Representation, Agent). That role variable is what carries the argument: the paper ties differences in trust and privacy concern to which role the participant assigned, and ties the assignment itself to whether the ecosystem is first-party or third-party.

What would settle it

Run the identical hotel-booking task with the ChatGPT interface modified so that the Expedia branding and any third-party plugin icon are removed while the functionality stays the same; if participants then no longer converge on the Agent model and no longer show higher trust and fewer concerns than with Gemini, the paper's link between visible third-party entities, mental-model consistency, and trust is not supported. A complementary falsifier is a field study where users describe how they believe their own everyday chatbot conversations move data, outside any scripted booking task; if the four-model taxonomy and the first-party/third-party asymmetry do not appear there, the results are task-specific rather than general mental models.

Watch

Extended reading notes

Core claim

On its own terms, the paper offers a taxonomy and an association. The taxonomy: four mental models, centered on the chatbot's role in the ecosystem—Key Player (the chatbot collects personal information and passes it to the parent company to complete the task), Medium (the chatbot is a passive conduit to the parent company, which then works with plugins), Representation (the chatbot and the parent company are the same entity, so trust in the company transfers directly), and Agent (the chatbot forwards data directly to the plugin, with no parent company in the data flow). The association: of the 21 participants, those who interacted with Gemini as the first-party ecosystem showed all four models and all but one reported privacy concerns; when the same participants interacted with ChatGPT as the third-party ecosystem, all of them used the Agent model and 16 of 21 reported no concerns. The paper explicitly reads this as evidence that a simpler, more consistent mental model accompanies higher trust and lower concern, and that the third-party ecosystem's visible, familiar plugin (Expedia) gives users a clearer sense of where their data goes than the highly integrated first-party ecosystem (Gemini and Google Hotels).

Load-bearing premise

The load-bearing premise is that a mental model measured in one scripted hotel-booking task, using a shared lab account, fake personal information, fixed prompts, and a screenshot of a successful booking, reflects the mental models people actually apply in their own daily chatbot use, rather than describing only the interface they were just shown.

Editorial extensions

If this is right

  • If users' mental models guide their privacy behavior, then a first-party ecosystem like Gemini that leaves users confused about data flow will need transparency features—such as visible entity badges or data-flow diagrams—to reach the same level of trust as a clearly intermediated third-party ecosystem.
  • For policy, the paper suggests regulators should require disclosure of the entities involved in a chatbot ecosystem, not just the types of data collected, because perceived entity boundaries directly affect users' concern.
  • For design, visible third-party branding (like the Expedia icon in ChatGPT) can act as a mental-model cue that simplifies the perceived data flow; designers of first-party ecosystems may need to create equivalent transparency cues deliberately.
  • For researchers, the four-model taxonomy gives a shared vocabulary for studying user understanding of AI ecosystems, analogous to prior folk-model taxonomies in security and privacy, and could be extended to other GenAI products.
  • The paper notes these mental models are incomplete or inaccurate relative to the true data flow, so a consequence is that users are making trust and disclosure decisions on the basis of simplified, sometimes wrong, pictures of the system.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A testable extension, not run by the paper, is to replace the Expedia plugin with an unfamiliar brand: if the trust advantage disappears, then the effect is driven by plugin reputation, not by third-party ownership per se.
  • An implicit consequence is that users may be disclosing more to third-party plugin ecosystems than their own understanding would support if the parent company were more visible, an asymmetry the paper does not discuss.
  • Because the drawing task immediately followed the booking interaction, an unstated possibility is that the 'Agent' model for ChatGPT reflects the momentary salience of the Expedia icon rather than a stable mental model users would carry into other tasks.
  • The taxonomy could be extended to other emerging GenAI ecosystems, such as AI assistants embedded in operating systems, where the first-party/third-party boundary is again likely to shape perceived data flow.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper reports a semi-structured interview study with 21 participants who completed hotel-booking tasks with Google Gemini and ChatGPT, drew diagrams of the data flow, and answered follow-up questions. The authors identify four mental models of GenAI chatbot ecosystems (Key Player, Medium, Representation, Agent) centered on the chatbot's perceived role. They further claim that participants held a more consistent and simpler mental model toward the third-party ecosystem (ChatGPT/Expedia) than toward the first-party ecosystem (Gemini/Google), and that this resulted in higher trust and fewer privacy concerns toward the third-party ecosystem. The paper closes with design and policy implications for transparency and entity disclosure in GenAI ecosystems.

Significance. The qualitative taxonomy of four mental models is a useful contribution to HCI and privacy research on GenAI, and the drawing-based elicitation with participant quotes and diagrams provides rich, interpretable data. The full-agreement coding process and the explicit attention to data-flow perceptions are strengths. If the comparative result were robust, it would challenge common assumptions that users trust first-party services more than third-party ones. However, the central first-party/third-party comparison is currently not identifiable from the design, because the two conditions differ not only in ecosystem type but also in visible task flow: ChatGPT redirected participants to Expedia, while Gemini completed the booking in-chat. The paper is therefore best viewed as an exploratory taxonomy with a plausible but unproven association between perceived data-flow complexity and trust; the causal wording in the abstract and conclusion needs substantial revision.

major comments (3)
  1. [§3.5, §4.2.4, §4.3] The central first-party vs third-party comparison is confounded with task flow. Section 3.5 states that ChatGPT did not support booking hotels directly from its interface even with the Expedia plugin, while Gemini could complete the booking in-chat; participants were stopped before submission and shown a confirmation screenshot from Gemini (Figure 1). P15's quote in §4.2.4 explicitly describes the user finishing the last step on Expedia, so the 'Agent' model for ChatGPT accurately reflects the visible interaction with an external site rather than a mental model of a third-party ecosystem. The abstract's causal claim that third-party ecosystems 'resulted in' higher trust thus cannot be identified from this design. I recommend reframing the result as a comparison of the two specific configurations (integrated first-party booking vs off-platform redirect to Expedia) or adding an analysis that separates perceived data-flow transparency from ecosystem type.
  2. [§4.4, Table 3] The privacy-concern counts are internally inconsistent and the discrepancy is load-bearing. Table 3 lists concerns for 20 of 21 participants in the Bard/Gemini condition (only P15 has 'No'), but §4.4 says '14 of 15 participants consistently expressed concerns'; in contrast, §4.3's '16 out of 21' for ChatGPT matches Table 3 (5 with concerns). The text should report the exact counts from Table 3 and, if a subset was analyzed (e.g., only 15 codable transcripts), state that subset explicitly. As written, the reader cannot verify the 'fewer concerns' claim.
  3. [§3.3, §3.5] The measurement procedure may elicit interface descriptions rather than stable mental models. The drawing task immediately followed a single scripted booking attempt using a shared lab account with fake personal information, and the final booking step was never completed; instead a pre-made Gemini confirmation screenshot was shown. Section 3.5 acknowledges that company-brand reputation influenced the models and that participants were intentionally exposed to all entities. Because participants relied on the visible Expedia icon in the ChatGPT interface (as noted in §4.3), the claimed mental models may be artifacts of the immediately preceding visual and task experience. The paper should provide evidence that the models predate the task (e.g., pre-task elicitation or questions about prior use) or temper the claim that these are users' stable mental models of chatbot ecosystems.
minor comments (4)
  1. [Table 1] Table 1 lists P2's education as 'Mater'; this appears to be a typo for 'Master'.
  2. [§4.2] The introduction to the mental models uses 'Representations' (plural) as the model name, whereas the model is elsewhere called 'Representation'; please standardize the terminology.
  3. [§5.1] The phrase 'carry out more precious user education' should likely be 'more precise user education'.
  4. [Figure 1 and §3.3] Please clarify in the text whether the Gemini confirmation screenshot was shown in both the Gemini and ChatGPT conditions; the current description suggests it was taken from a Gemini pre-study test, which may have influenced the ChatGPT-condition drawings.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: qualitative taxonomy is derived from interview and drawing data, not from an assumed input.

full rationale

This paper is a qualitative interview study with no formal derivation, predictive model, or fitted parameter. The four mental models are induced from participants' drawings and transcripts via thematic analysis, so there is no claimed result that is equivalent to its inputs by construction. The comparative claim that Gemini elicited four mental models while ChatGPT elicited a single Agent model is an empirical summary of coded interviews, not a quantity derived from an assumed equation. The acknowledged asymmetry in the study design, where ChatGPT redirected users to Expedia while Gemini completed booking in-chat, is a potential confound that threatens the validity of the comparative claim, but it is not circularity: the mental-model categories are not defined in terms of the outcome measure, and the authors do not rename a fitted parameter as a prediction. Self-citations (e.g., Yao et al. 2017, used as a drawing-exercise method precedent) support methodological continuity only and are not load-bearing for the paper's central findings. No circular step was identified.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

No free parameters or invented entities apply: this is an interview study with no mathematical model. The load-bearing assumptions are all methodological: that the drawing task measures stable mental models, that the concern coding is reliable, that the two chatbot conditions are comparable, and that 21 US participants can ground claims about 'users' generally. The paper explicitly acknowledges the instability of the AI systems and the US-only sample in Section 3.5.

assumptions (4)
  • domain assumption Participants' self-reported concerns in a scripted interview task are a valid operationalization of privacy concern and trust.
    The binary 'Concerns?' column in Table 3 is derived from interview coding, but the paper does not define the coding rule for concern vs. no concern (Section 3.4, Section 4.3).
  • domain assumption A single drawing exercise immediately after one scripted interaction elicits the participant's stable mental model of the ecosystem.
    The drawing task is the core measurement instrument (Section 3.3), and the paper assumes it reflects participants' actual understanding rather than a description of the specific interface just seen.
  • domain assumption GPT Actions/plugins and Gemini extensions are functionally comparable enough to compare across the two ecosystems.
    Section 3.3 states plugins and extensions 'provide similar functionalities,' but Section 3.5 acknowledges ChatGPT's Expedia plugin did not support completing hotel bookings directly, which made the two conditions non-equivalent.
  • domain assumption A sample of 21 US participants with prior chatbot experience can support generalizations about 'users'' mental models.
    Section 3.1 describes the recruitment; Section 3.5 acknowledges the US-only context, but the abstract and discussion phrase findings in general terms without hedging.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Users' Mental Models of Generative AI Chatbot Ecosystems." pith.science (2026). https://pith.science/paper/TATXQOI6

@misc{pith2026250119211,
  author       = {Pith},
  title        = {Pith review of: Users' Mental Models of Generative AI Chatbot Ecosystems},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/TATXQOI6}},
  note         = {Machine review of arXiv:2501.19211}
}
read the original abstract

The capability of GenAI-based chatbots, such as ChatGPT and Gemini, has expanded quickly in recent years, turning them into GenAI Chatbot Ecosystems. Yet, users' understanding of how such ecosystems work remains unknown. In this paper, we investigate users' mental models of how GenAI Chatbot Ecosystems work. This is an important question because users' mental models guide their behaviors, including making decisions that impact their privacy. Through 21 semi-structured interviews, we uncovered users' four mental models towards first-party (e.g., Google Gemini) and third-party (e.g., ChatGPT) GenAI Chatbot Ecosystems. These mental models centered around the role of the chatbot in the entire ecosystem. We further found that participants held a more consistent and simpler mental model towards third-party ecosystems than the first-party ones, resulting in higher trust and fewer concerns towards the third-party ecosystems. We discuss the design and policy implications based on our results.

Figures

Figures reproduced from arXiv: 2501.19211 by the authors.

Figure 1
Figure 1. Successful booking confirmation from Gemini [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. Chatbot as a Key Player Drawing from P2. The [PITH_FULL_IMAGE:figures/full_fig_p006_2.png] view at source ↗
Figure 4
Figure 4. GenAI as a Medium Drawing from P1. P1 believed [PITH_FULL_IMAGE:figures/full_fig_p007_4.png] view at source ↗
Figures from the paper (5 more)
Figure 3
Figure 3. Figure 3: Chatbot as a Key Player Drawing from P20. In P20’s [PITH_FULL_IMAGE:figures/full_fig_p007_3.png]
Figure 5
Figure 5. Figure 5: GenAI as a Representation Drawing from P19 (In the [PITH_FULL_IMAGE:figures/full_fig_p009_5.png]
Figure 6
Figure 6. Figure 6: P21’s drawing demonstrates how the Agent mental [PITH_FULL_IMAGE:figures/full_fig_p009_6.png]
Figure 7
Figure 7. Figure 7: P15’s drawing demonstrates how the Agent mental [PITH_FULL_IMAGE:figures/full_fig_p010_7.png]
Figure 8
Figure 8. Figure 8: P1’s drawing demonstrates how Agent MM Oper [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

80 extracted references · 64 canonical work pages

  1. [1]

    Alessandro Acquisti and Jens Grossklags. 2005. Privacy and rationality in indi- vidual decision making. IEEE security & privacy 3, 1 (2005), 26–33

  2. [2]

    Eleni Adamopoulou and Lefteris Moussiades. 2020. Chatbots: History, technology, and applications. Machine Learning with Applications 2 (2020), 100006

  3. [3]

    Farzaneh Asgharpour, Debin Liu, and L Jean Camp. 2007. Mental models of security risks. In Financial Cryptography and Data Security: 11th International Conference, FC 2007, and 1st International Workshop on Usable Security, USEC 2007, Scarborough, Trinidad and Tobago, February 12-16, 2007. Revised Selected Papers

  4. [4]

    David Baidoo-Anu and Leticia Owusu Ansah. 2023. Education in the era of generative artificial intelligence (AI): Understanding the potential benefits of ChatGPT in promoting teaching and learning. Journal of AI 7, 1 (2023), 52–62

  5. [5]

    Rahul C Basole and AI Accenture. 2021. Visualizing the Evolution of the AI Ecosystem.. In HICSS. 1–10

  6. [6]

    Richard E Boyatzis. 1998. Transforming qualitative information: Thematic analysis and code development. sage

  7. [7]

    danah boyd and Eszter Hargittai. 2010. Facebook Privacy Settings: Who Cares? First Monday 15 (07 2010). https://doi.org/10.5210/fm.v15i8.3086

  8. [8]

    Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie Downs, and Saranga Komanduri

Show all 80 references
  1. [9]

    L Jean Camp. 2009. Mental models of privacy and security. IEEE Technology and society magazine 28, 3 (2009), 37–46

  2. [10]

    Jean Camp

    L. Jean Camp. 2009. Mental models of privacy and security. IEEE Technology and Society Magazine 28, 3 (2009), 37–46. https://doi.org/10.1109/MTS.2009.934142

  3. [11]

    Fred H. Cate. 2010. The Limits of Notice and Choice. IEEE Security and Privacy 8, 2 (2010), 59–62. https://doi.org/10.1109/MSP.2010.84

  4. [12]

    Benjamin Cheatham, Kia Javanmardian, and Hamid Samandari. 2019. Con- fronting the risks of artificial intelligence. McKinsey Quarterly 2, 38 (2019), 1–9

  5. [13]

    Chaoran Chen, Daodao Zhou, Yanfang Ye, Toby Jia-jun Li, and Yaxing Yao. 2025. CLEAR: Towards Contextual LLM-Empowered Privacy Policy Analysis and Risk Generation for Large Language Model Applications.30th International Conference on Intelligent User Interfaces (2025)

  6. [14]

    Yang Cheng and Hua Jiang. 2020. How do AI-driven chatbots impact user experience? Examining gratifications, perceived privacy risk, satisfaction, loyalty, and continued use. Journal of Broadcasting & Electronic Media 64, 4 (2020), 592–614

  7. [15]

    Lorrie Faith Cranor. 2012. Necessary but not sufficient: Standardized mechanisms for privacy notice and choice. J. on Telecomm. & High Tech. L. 10 (2012), 273

  8. [16]

    Robert Dale. 2016. The return of the chatbots. Natural Language Engineering 22, 5 (2016), 811–817

  9. [17]

    Yuanyuan Feng, Yaxing Yao, and Norman Sadeh. 2021. A design space for privacy choices: Towards meaningful privacy control in the internet of things. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems . 1–16

  10. [18]

    Fiona Fui-Hoon Nah, Ruilin Zheng, Jingyuan Cai, Keng Siau, and Langtao Chen

  11. [19]

    Artur d’Avila Garcez, Sebastian Bader, Howard Bowman, Luis C Lamb, Leo de Penning, BV Illuminoo, Hoifung Poon, and COPPE Gerson Zaverucha. 2022. Neural-symbolic learning and reasoning: A survey and interpretation. Neuro- Symbolic Artificial Intelligence: The State of the Art 3...

  12. [20]

    Ella Glikson and Anita Williams Woolley. 2020. Human trust in artificial intel- ligence: Review of empirical research. Academy of Management Annals 14, 2 (2020), 627–660

  13. [21]

    Google. 2023. Bard Extention. (2023). https://support.google.com/gemini

  14. [22]

    Okay, whatever

    Hana Habib, Megan Li, Ellie Young, and Lorrie Cranor. 2022. “Okay, whatever”: An Evaluation of Cookie Consent Interfaces. In Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems . 1–27

  15. [23]

    Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Cranor, Joel Reidenberg, Norman Sadeh, and Florian Schaub. 2021. Toggles, dollar signs, and triangles: How to (in) effectively convey privacy choices with icons and link texts. In Proceedings of the 2021 CHI Confer...

  16. [24]

    Philipp Hacker, Andreas Engel, and Marco Mauer. 2023. Regulating ChatGPT and Other Large Generative AI Models. Association for Computing Machinery, New York, NY, USA. https://doi.org/10.1145/3593013.3594067

  17. [25]

    Marian Harbach, Markus Hettig, Susanne Weber, and Matthew Smith. 2014. Using personal examples to improve risk communication for security & privacy decisions. In Proceedings of the SIGCHI conference on human factors in computing systems. 2647–2656

  18. [26]

    Carolin Ischen, Theo Araujo, Hilde Voorveld, Guda van Noort, and Edith Smit

  19. [27]

    Philip N Johnson-Laird, Vittorio Girotto, and Paolo Legrenzi. 1998. Mental models: a gentle guide for outsiders. Sistemi Intelligenti 9, 68 (1998), 33

  20. [28]

    My Data Just Goes Everywhere:

    Ruogu Kang, Laura Dabbish, Nathaniel Fruchter, and Sara Kiesler. 2015. “My Data Just Goes Everywhere:” User Mental Models of the Internet and Implications for Privacy and Security. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015). USENIX Association, Ottawa, 3...

  21. [29]

    My} data just goes {Everywhere:

    Ruogu Kang, Laura Dabbish, Nathaniel Fruchter, and Sara Kiesler. 2015. {“My} data just goes {Everywhere:”} user mental models of the internet and impli- cations for privacy and security. In Eleventh symposium on usable privacy and security (SOUPS 2015). 39–52

  22. [30]

    Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder

  23. [31]

    Ku Chhaya A Khanzode and Ravindra D Sarode. 2020. Advantages and dis- advantages of artificial intelligence and machine learning: A literature review. International Journal of Library & Information Science (IJLIS) 9, 1 (2020), 3

  24. [32]

    Anjali Khurana, Parsa Alamzadeh, and Parmit K Chilana. 2021. ChatrEx: Design- ing explainable chatbot interfaces for enhancing usefulness, transparency, and trust. In 2021 IEEE Symposium on Visual Languages and Human-Centric Computing (VL/HCC). IEEE, 1–11

  25. [33]

    Martucci

    Agnieszka Kitkowska, Mark Warner, Yefim Shulman, Erik Wästlund, and Leonardo A. Martucci. 2020. Enhancing Privacy through the Visual Design of Privacy Notices: Exploring the Interplay of Curiosity, Control and Affect. In Sixteenth Symposium on Usable Privacy and Security (SOUP...

  26. [34]

    When I am on Wi-Fi, I am fearless

    Predrag Klasnja, Sunny Consolvo, Jaeyeon Jung, Benjamin M Greenstein, Louis LeGrand, Pauline Powledge, and David Wetherall. 2009. " When I am on Wi-Fi, I am fearless" privacy concerns & practices in everyday Wi-Fi use. In Proceedings of the SIGCHI Conference on Human Factors i...

  27. [35]

    Bart Knijnenburg and David Cherry. 2016. Comics as a medium for privacy notices. In Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)

  28. [36]

    Tu Le, Zixin Wang, Danny Huang, Yaxing Yao, and Yuan Tian. 2024. Towards Real- time Voice Interaction Data Collection Monitoring and Ambient Light Privacy Notification for Voice-controlled Services. Symposium on Usable Security and Privacy (USEC) 2024. Users’ Mental Models of ...

  29. [37]

    Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, and Sauvik Das. 2024. Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks. InProceedings of the CHI Conference on Human Factors in Computing Systems. 1–19

  30. [38]

    Alexandra Mai, Leonard Guelmino, Katharina Pfeffer, Edgar Weippl, and Katha- rina Krombholz. 2022. Mental Models Of the Internet And Its Online Risks: Children And Their Parent(s). Springer-Verlag, Berlin, Heidelberg. https: //doi.org/10.1007/978-3-031-05563-8_4

  31. [39]

    Nora McDonald, Sarita Schoenebeck, and Andrea Forte. 2019. Reliability and inter-rater reliability in qualitative research: Norms and guidelines for CSCW and HCI practice. Proceedings of the ACM on human-computer interaction 3, CSCW (2019), 1–23

  32. [40]

    Siddhant Meshram, Namit Naik, Megha VR, Tanmay More, and Shubhangi Kharche. 2021. Conversational AI: Chatbots. In 2021 International Conference on Intelligent Technologies (CONIT). 1–6. https://doi.org/10.1109/CONIT51480.2021. 9498508

  33. [41]

    Meta. 2024. Meet Your New Assistant: Meta AI, Built With Llama

  34. [42]

    Microsoft. 2023. Announcing Microsoft Copilot: Your Everyday AI Compan- ion. https://blogs.microsoft.com/blog/2023/09/21/announcing-microsoft-copilot- your-everyday-ai-companion/. Accessed: 2024-06-01

  35. [43]

    Microsoft. 2024. Bringing the Full Power of Copilot to More People and Busi- nesses. https://blogs.microsoft.com/blog/2024/01/01/bringing-the-full-power-of- copilot-to-more-people-and-businesses/. Accessed: 2024-06-01

  36. [44]

    Microsoft. 2024. Introducing Copilot for Microsoft 365. https: //www.microsoft.com/en-us/microsoft-365/blog/2024/01/01/introducing- copilot-for-microsoft-365/. Accessed: 2024-06-01

  37. [45]

    Neville Moray. 1998. Identifying mental models of complex human–machine systems. International Journal of Industrial Ergonomics 22, 4 (1998), 293–297. https://doi.org/10.1016/S0169-8141(97)00080-2

  38. [46]

    Accessed: 2024-06-01

    https://about.fb.com/news/2024/04/meet-your-new-assistant-meta-ai-built- with-llama-3/. Accessed: 2024-06-01

  39. [47]

    Meenakshi Nadimpalli. 2017. Artificial intelligence risks and benefits. Interna- tional Journal of Innovative Research in Science, Engineering and Technology 6, 6 (2017)

  40. [48]

    Alena Naiakshina, Anastasia Danilova, Sergej Dechand, Kat Krol, M Angela Sasse, and Matthew Smith. 2016. Poster: Mental models–User understanding of messaging and encryption. In Proc. of the 1st IEEE European Symposium on Security and Privacy

  41. [49]

    Luminit,a Nicolescu and Monica Teodora Tudorache. 2022. Human-computer interaction in customer service: the experience with AI chatbots—a systematic literature review. Electronics 11, 10 (2022), 1579

  42. [50]

    Amin Heyrani Nobari, Muhammad Fathy Rashad, and Faez Ahmed. 2021. Cre- ativegan: Editing generative adversarial networks for creative design synthesis. arXiv preprint arXiv:2103.06242 (2021)

  43. [51]

    Michael Muller, Lydia B Chilton, Anna Kantosalo, Charles Patrick Martin, and Greg Walsh. 2022. GenAICHI: generative AI and HCI. InCHI conference on human factors in computing systems extended abstracts . 1–7

  44. [52]

    Erika Shehan Poole, Christopher A Le Dantec, James R Eagan, and W Keith Edwards. 2008. Reflecting on the invisible: understanding end-user perceptions of ubiquitous computing. In Proceedings of the 10th international Conference on Ubiquitous Computing. 192–201

  45. [53]

    Joel R Reidenberg, Travis Breaux, Lorrie Faith Cranor, Brian French, Amanda Grannis, James T Graves, Fei Liu, Aleecia McDonald, Thomas B Norton, Ro- han Ramanath, et al. 2015. Disagreeable privacy policies: Mismatches between meaning and users’ understanding. Berkeley Tech. LJ...

  46. [54]

    Wiebke Reim, Josef Åström, and Oliver Eriksson. 2020. Implementation of artificial intelligence (AI): a roadmap for business model innovation. AI 1, 2 (2020), 11

  47. [55]

    Othman Sbai, Mohamed Elhoseiny, Antoine Bordes, Yann LeCun, and Camille Couprie. 2018. Design: Design inspiration from generative networks. In Proceed- ings of the European Conference on Computer Vision (ECCV) Workshops . 0–0

  48. [56]

    OpenAI. 2023. ChatGPT Plugins. (2023). https://openai.com/index/chatgpt- plugins

  49. [57]

    Florian Schaub, Rebecca Balebako, Adam L Durity, and Lorrie Faith Cranor. 2015. A design space for effective privacy notices. In Eleventh symposium on usable privacy and security (SOUPS 2015) . 1–17

  50. [58]

    Harsh Shivam. 2024. Meta goes after OpenAI, Microsoft, Google with Llama 3 AI model: Details. Business Standard (2024). https://www.business- standard.com/technology/tech-news/meta-goes-after-openai-microsoft- google-with-llama-3-ai-model-details-124041900368_1.html Accessed: ...

  51. [59]

    It would probably turn into a social faux-pas

    Parth Kirankumar Thakkar, Shijing He, Shiyu Xu, Danny Yuxing Huang, and Yaxing Yao. 2022. “It would probably turn into a social faux-pas”: Users’ and Bystanders’ Preferences of Privacy Awareness Mechanisms in Smart Homes. In Proceedings of the 2022 CHI Conference on Human Fact...

  52. [60]

    Andrew Thatcher and Mike Greyling. 1998. Mental models of the Internet. International Journal of Industrial Ergonomics 22, 4 (1998), 299–305. https://doi. org/10.1016/S0169-8141(97)00081-4

  53. [61]

    Florian Schaub, Rebecca Balebako, and Lorrie Faith Cranor. 2017. Designing Effective Privacy Notices and Controls. IEEE Internet Computing 21, 3 (2017), 70–77. https://doi.org/10.1109/MIC.2017.75

  54. [62]

    Quentin Vanhaelen, Yen-Chu Lin, and Alex Zhavoronkov. 2020. The advent of generative chemistry. ACS Medicinal Chemistry Letters 11, 8 (2020), 1496–1505

  55. [63]

    Rick Wash. 2010. Folk models of home computer security. In Proceedings of the Sixth Symposium on Usable Privacy and Security . 1–16

  56. [64]

    Kuang-Wen Wu, Shaio Yan Huang, David C Yen, and Irina Popova. 2012. The effect of online privacy policy on consumer privacy concern and trust.Computers in human behavior 28, 3 (2012), 889–897

  57. [65]

    Yaxing Yao, Justin Reed Basdeo, Smirity Kaushik, and Yang Wang. 2019. De- fending my castle: A co-design study of privacy mechanisms for smart homes. In Proceedings of the 2019 chi conference on human factors in computing systems . 1–12

  58. [66]

    Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, and Thorsten Holz

  59. [67]

    Yaxing Yao, Yun Huang, and Yang Wang. 2019. Unpacking People’s Understand- ings of Bluetooth Beacon Systems-A Location-Based IoT Technology. (2019)

  60. [68]

    Yaxing Yao, Davide Lo Re, and Yang Wang. 2017. Folk models of online behavioral advertising. In Proceedings of the 2017 ACM Conference on Computer Supported Cooperative Work and Social Computing . 1957–1969

  61. [69]

    Yaxing Yao, Huichuan Xia, Yun Huang, and Yang Wang. 2017. Privacy mecha- nisms for drones: Perceptions of drone controllers and bystanders. In Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems . 6777–6788

  62. [70]

    Shikun Zhang, Yuanyuan Feng, Yaxing Yao, Lorrie Faith Cranor, and Norman Sadeh. 2022. How usable are ios app privacy labels? Proceedings on Privacy Enhancing Technologies (2022)

  63. [71]

    It’s a Fair Game

    Zhiping Zhang, Michelle Jia, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, Tianshi Li, et al. 2023. " It’s a Fair Game”, or Is It? Examining How Users Navigate Disclosure Risks and Benefits When Using LLM-Based Conversational Agents. arXiv preprint arXiv:2309.11653 (2023)

  64. [72]

    Yaxing Yao, Justin Reed Basdeo, Oriana Rosata Mcdonough, and Yang Wang

  65. [73]

    Proceedings of the ACM on Human-Computer Interaction 3, CSCW (2019), 1–24

    Privacy perceptions and designs of bystanders in smart homes. Proceedings of the ACM on Human-Computer Interaction 3, CSCW (2019), 1–24

  66. [79]

    Jianlong Zhou, Heimo Müller, Andreas Holzinger, and Fang Chen. 2023. Eth- ical ChatGPT: Concerns, challenges, and commandments. arXiv preprint arXiv:2305.10646 (2023)

  67. [80]

    GenAI Chatbots

    Jakub Złotowski, Diane Proudfoot, Kumar Yogeeswaran, and Christoph Bart- neck. 2015. Anthropomorphism: opportunities and challenges in human–robot interaction. International journal of social robotics 7 (2015), 347–360. 8 Appendix Interview Protocol General Questions Here, we ...

  68. [2009]

    nutrition label

    A" nutrition label" for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security . 1–12

  69. [2011]

    IEEE Security and Privacy 9, 2 (2011), 18–26

    Bridging the Gap in Computer Security Warnings: A Mental Model Ap- proach. IEEE Security and Privacy 9, 2 (2011), 18–26. https://doi.org/10.1109/ MSP.2010.198

  70. [2019]

    In Proceedings of the 2019 acm sigsac conference on computer and communications security

    (Un) informed consent: Studying GDPR consent notices in the field. In Proceedings of the 2019 acm sigsac conference on computer and communications security. 973–990

  71. [2020]

    In Chatbot Research and Design: Third International Workshop, CONVERSATIONS 2019, Amsterdam, The Nether- lands, November 19–20, 2019, Revised Selected Papers 3

    Privacy concerns in chatbot interactions. In Chatbot Research and Design: Third International Workshop, CONVERSATIONS 2019, Amsterdam, The Nether- lands, November 19–20, 2019, Revised Selected Papers 3 . Springer, 34–48

  72. [2023]

    , 277–304 pages

    Generative AI and ChatGPT: Applications, challenges, and AI-human collaboration. , 277–304 pages

Pith tools

Reviewed August 9, 2026 · model on record in the stance chip above.