Michelle Mazurek Builds People-Centered Security Tools
University of Maryland Professor of Computer Science Michelle Mazurek studies how people navigate security and privacy decisions in everyday digital systems. Affiliated with the University of Maryland Institute for Advanced Computer Studies (UMIACS) and the Maryland Cybersecurity Center (MC2), her research connects technical questions with the human choices behind them, from how software developers handle secure coding to how researchers protect sensitive data before sharing it.
In this Q&A, Mazurek discusses the early experiences that drew her to computing, her work on data de-identification and why communication is central to human-centered security research.
Was there a defining moment that shaped your path into computer science?
There was more than one. Growing up, my dad was an electrical engineer, and he taught my sister and me that engineering was a way to solve problems, whether something broke in the house or needed to be fixed on a computer.
I first tried programming in second or third grade with Logo, where you could move a pointer on a screen by writing commands. Later, we used Lego Logo, an early version of Lego robotics systems. We built things with Legos and programmed motors to make them move. That was probably how I became interested in programming and computer science.
Can you describe your research focus?
My work is at the intersection of security and privacy with human-computer interaction. We study how people make decisions related to privacy and security and how to help those decisions go better.
That includes end users trying to protect themselves, software developers whose code affects others and professionals such as librarians who manage privacy issues for the people they serve.
What is one current project you are working on?
One project I am working on with my student Wentao Guo focuses on disclosure avoidance and de-identification for research data.
Social science and health researchers often collect human subjects data about topics such as health outcomes, poverty, income or personal background. There is interest in releasing that data after a study so other researchers can replicate findings or conduct new analyses.
At the same time, there are risks. If data can be re-identified, someone could learn sensitive information about the people who participated. Researchers have a responsibility to protect participants, especially when they have promised that study data will not be tied back to a person’s identity.
The challenge is that many things besides a name can identify someone. A combination of details, such as job title, gender, department or years at an institution, can quickly narrow the group of possible people.
How is your group approaching that problem?
There are technical approaches to making data less identifiable, but they involve trade-offs. If you replace all the data with random numbers, it may be private, but it will not be useful for research.
Many social science and medical researchers are expected to de-identify and release data, but they often do not receive detailed training on how to do it. We have talked to researchers and reviewed existing documentation to understand their goals and constraints.
More recently, we studied how people use tools designed to support de-identification. We are interested in tools that help researchers understand the choices they are making and select an approach that fits their data and research goals.
Can you describe your lab?
My group works closely with the Maryland Cybersecurity Center (MC2), where I am affiliated. At the moment, the lab includes a postdoc, five doctoral students, and a couple of undergraduate students.
That size allows us to work on several projects while still giving each student the attention they need.
What role does MC2 play on campus?
The Maryland Cybersecurity Center brings together faculty and students working on security and privacy research across campus. It includes about 10 to 15 faculty members, mostly from computer science and electrical and computer engineering, with some participation from other departments.
The center gives researchers a way to communicate, share resources and connect students with a broader community working on related problems.
How does your work connect to broader issues in computer science?
Security is a technical problem, but it is also a human and organizational problem. Secure software matters, and the challenge is growing as software systems become larger and more complex.
In many cases, the issue is not that no solution exists. It may be that a vulnerability was not noticed soon enough, a patch was not applied in time or the process did not work at scale. Technical solutions are important, but we also need to understand the barriers that prevent those solutions from being used effectively.
What inspired you to join the University of Maryland?
I was an undergraduate at Maryland, where I studied electrical and computer engineering. My husband is also an alum, and many of our friends and family connections are in the area, so returning to Maryland felt like coming back home in some ways.
It was also a chance to see the university from a different perspective, as a professor rather than a student. The computer science department spans many areas, including human-computer interaction and security.
What advice would you give students interested in your research area?
Students should think carefully about communication skills. Technical skills and programming are important, but this kind of work also requires understanding people, asking questions and explaining findings clearly.
You need to be able to talk to people about the challenges they face, write about what you find and communicate ideas to people who may build new systems. Those skills are important in human-centered security and privacy research.
—Story by Samuel Malede Zewdu, CS Communications
The Department welcomes comments, suggestions and corrections. Send email to editor [-at-] cs [dot] umd [dot] edu.
