Efficiency and Equity in Screening for Participants in Representative Cybersecurity Studies

dc.contributor.authorChen, Po-Yuen
dc.contributor.authorOh, Jinwooen
dc.contributor.authorHsing, Hsiang-Wenen
dc.contributor.authorLau, Nathanen
dc.contributor.authorBeltz, Brandonen
dc.contributor.authorWu, Peggyen
dc.contributor.authorZhu, Quanyanen
dc.date.accessioned2026-07-24T14:20:00Zen
dc.date.available2026-07-24T14:20:00Zen
dc.date.issued2026-07-31en
dc.description.abstractHuman factors research in cybersecurity confronts the practical challenge of how to recruit and screen participants with the skills necessary to perform demanding, ecologically valid tasks. Credible results from hacking studies rely on participants possessing sufficient technical skills to maneuver inside a representative network in a cyber range. Screening via self-reports can be unreliable, while rigorous skills testing is resource intensive. This paper presents empirical research investigating the effectiveness of cybersecurity certifications and cyber range skills tests for screening domain-specific competence. The Guarding Against Malicious Biased Threats (GAMBiT) project recruited participants with a two-stage screening process. The project screened 269 candidates for a final sample of 61 qualified participants. We compared the capability between the Offensive Security Certified Professional (OSCP) certification and a custom Capture-the-Flag (CTF) assessment (“Cedar Bunny”) at predicting actual performance in a two-day cyber range experiment. Results indicate that OSCP holders scored significantly higher on the skills test (p < 0.001) and progressed further in the hacking experiment (p = 0.002) than non-holders. Skills test scores correlated moderately and positively with hacking progress (ρ = 0.344). Furthermore, hierarchical regression analysis demonstrated that the skills test provided incremental predictive validity (ΔR2 = 5.2%) beyond certification alone. These findings suggest that while certifications are efficient proxies and skills tests can be effective supplements for identifying viable, albeit non-certified, participants. We propose a mixed screening approach to balance recruitment efficiency and participant diversity.en
dc.description.notesYes, full paper (Peer reviewed?)en
dc.description.versionAccepted versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.doihttps://doi.org/10.1007/978-3-032-29723-5_24en
dc.identifier.orcidChen, Po-Yu [0009-0002-6727-2708]en
dc.identifier.urihttps://hdl.handle.net/10919/143682en
dc.identifier.volume38en
dc.language.isoenen
dc.publisherSpringeren
dc.relation.ispartofEfficiency and Equity in Cybersecurity Screeningen
dc.rightsIn Copyrighten
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/en
dc.subjectCybersecurityen
dc.subjectHuman Factorsen
dc.subjectParticipant Screeningen
dc.subjectOSCPen
dc.subjectSkills Assessmenten
dc.titleEfficiency and Equity in Screening for Participants in Representative Cybersecurity Studiesen
dc.title.serialHCI International 2026 Proceedings - HCI for Cybersecurity, Privacy and Trusten
dc.typeConference proceedingen
dc.type.dcmitypeTexten
pubs.finish-date2026-07-31en
pubs.organisational-groupVirginia Techen
pubs.organisational-groupVirginia Tech/Engineeringen
pubs.organisational-groupVirginia Tech/Engineering/Industrial and Systems Engineeringen
pubs.organisational-groupVirginia Tech/Graduate studentsen
pubs.organisational-groupVirginia Tech/Graduate students/Doctoral studentsen
pubs.start-date2026-07-26en

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
EfficiencyAndEquity.pdf
Size:
1.22 MB
Format:
Adobe Portable Document Format
Description:
Accepted version
License bundle
Now showing 1 - 1 of 1
Name:
license.txt
Size:
1.5 KB
Format:
Plain Text
Description: