Efficiency and Equity in Screening for Participants in Representative Cybersecurity Studies
| dc.contributor.author | Chen, Po-Yu | en |
| dc.contributor.author | Oh, Jinwoo | en |
| dc.contributor.author | Hsing, Hsiang-Wen | en |
| dc.contributor.author | Lau, Nathan | en |
| dc.contributor.author | Beltz, Brandon | en |
| dc.contributor.author | Wu, Peggy | en |
| dc.contributor.author | Zhu, Quanyan | en |
| dc.date.accessioned | 2026-07-24T14:20:00Z | en |
| dc.date.available | 2026-07-24T14:20:00Z | en |
| dc.date.issued | 2026-07-31 | en |
| dc.description.abstract | Human factors research in cybersecurity confronts the practical challenge of how to recruit and screen participants with the skills necessary to perform demanding, ecologically valid tasks. Credible results from hacking studies rely on participants possessing sufficient technical skills to maneuver inside a representative network in a cyber range. Screening via self-reports can be unreliable, while rigorous skills testing is resource intensive. This paper presents empirical research investigating the effectiveness of cybersecurity certifications and cyber range skills tests for screening domain-specific competence. The Guarding Against Malicious Biased Threats (GAMBiT) project recruited participants with a two-stage screening process. The project screened 269 candidates for a final sample of 61 qualified participants. We compared the capability between the Offensive Security Certified Professional (OSCP) certification and a custom Capture-the-Flag (CTF) assessment (“Cedar Bunny”) at predicting actual performance in a two-day cyber range experiment. Results indicate that OSCP holders scored significantly higher on the skills test (p < 0.001) and progressed further in the hacking experiment (p = 0.002) than non-holders. Skills test scores correlated moderately and positively with hacking progress (ρ = 0.344). Furthermore, hierarchical regression analysis demonstrated that the skills test provided incremental predictive validity (ΔR2 = 5.2%) beyond certification alone. These findings suggest that while certifications are efficient proxies and skills tests can be effective supplements for identifying viable, albeit non-certified, participants. We propose a mixed screening approach to balance recruitment efficiency and participant diversity. | en |
| dc.description.notes | Yes, full paper (Peer reviewed?) | en |
| dc.description.version | Accepted version | en |
| dc.format.mimetype | application/pdf | en |
| dc.identifier.doi | https://doi.org/10.1007/978-3-032-29723-5_24 | en |
| dc.identifier.orcid | Chen, Po-Yu [0009-0002-6727-2708] | en |
| dc.identifier.uri | https://hdl.handle.net/10919/143682 | en |
| dc.identifier.volume | 38 | en |
| dc.language.iso | en | en |
| dc.publisher | Springer | en |
| dc.relation.ispartof | Efficiency and Equity in Cybersecurity Screening | en |
| dc.rights | In Copyright | en |
| dc.rights.uri | http://rightsstatements.org/vocab/InC/1.0/ | en |
| dc.subject | Cybersecurity | en |
| dc.subject | Human Factors | en |
| dc.subject | Participant Screening | en |
| dc.subject | OSCP | en |
| dc.subject | Skills Assessment | en |
| dc.title | Efficiency and Equity in Screening for Participants in Representative Cybersecurity Studies | en |
| dc.title.serial | HCI International 2026 Proceedings - HCI for Cybersecurity, Privacy and Trust | en |
| dc.type | Conference proceeding | en |
| dc.type.dcmitype | Text | en |
| pubs.finish-date | 2026-07-31 | en |
| pubs.organisational-group | Virginia Tech | en |
| pubs.organisational-group | Virginia Tech/Engineering | en |
| pubs.organisational-group | Virginia Tech/Engineering/Industrial and Systems Engineering | en |
| pubs.organisational-group | Virginia Tech/Graduate students | en |
| pubs.organisational-group | Virginia Tech/Graduate students/Doctoral students | en |
| pubs.start-date | 2026-07-26 | en |