People, Agents, and Security
We study security at the intersection of people, software, and AI agents. Our work examines how people interact with security mechanisms, including phishing prevention, authentication, user interfaces, and secure decision-making. We also investigate risks introduced when agents use programs on people’s behalf, including computer-use, browser, and coding agents. We design and evaluate safer agentic systems and sandboxes, and explore how LLMs can help users make security decisions.
Active Members
Prof. Srdjan Čapkun
Group Leader
Dr. Kari Kostiainen
Senior Scientist
Dr. Daniele Lain
Post-doc
Friederike Groschupp
Doctoral Student
Claudio Anliker
Doctoral Student
Nicolas Dutly
Doctoral Student
Talks
Phishing in Organizations: Findings from a Large-Scale and Long-Term Study
Selected Publications
arXiv
USENIX Security Symposium
(USENIX '25)
USENIX Security Symposium
(USENIX '25)
ACM Conference on Computer and Communications Security
(CCS '24)
IEEE Symposium on Security & Privacy
(S&P '22)





