← Back to Blogs

rethinking novelty in usable security research

I consider usable security research as advocacy, and advocacy does not stop simply because the cause is no longer considered new.

This is what I find myself returning to every time a reviewer asks me to prove the novelty of my work, which in my experience as a usable security researcher working with the non-WEIRD (Western, Educated, Industrialized, Rich, and Democratic) contexts is in nearly every submission.

I wonder what novelty even means. In my view, novelty is a unique method or result that has not been implemented or reported in prior literature. If we imagine the solution to a problem as a box kept on the roof, novelty is one step on the ladder that helps the community reach it.

But I often wonder whether novelty is even required when the very first novel steps of the ladder end up not changing the world. Whatever we produce on top of that novelty is essentially additional information, with the hope that it will be noticed and implemented one day. Consider digital safety. Activists, policymakers, and researchers have long argued for its importance and published clear guidelines on how to make the internet safer. Unfortunately, the primary benefactors of the internet, social media companies for instance, do not adopt those guidelines because doing so does not profit them.

Facebook never developed a cohesive vocabulary of digital abuse terms suited to individual contexts around the world. Women are still harassed on the platform. Snapchat never implemented sufficient guardrails for child safety. In 2024, two teenager boys contacted a 15-year-old girl through Snapchat, raped her repeatedly while filming and laughing, and shared the video on the platform. Seven weeks later they enlisted a third boy to target a 14-year-old. All three were convicted but walked free without custodial sentences in May 2026.1 App stores on mobile devices still host deepfake applications that men use to undress women and circulate the images.2

Researchers have repeatedly warned internet companies about the harms emerging from their platforms, but to no avail. This is why I feel research should be allowed to produce findings that are not particularly novel, so that these issues remain relevant at every conference until problems are fixed.

When I say research is advocacy, I do not mean that every paper changes the world the week it is published. I mean something more patient than that. Researchers have to resist. They have to keep showing up. And sometimes that persistence does lead somewhere.

Yixin Zou published work on how to effectively convey privacy choices to users through icons, and their recommendation was eventually adopted into the official CCPA regulations in California.3 Patrick Gage Kelley's work on privacy nutrition labels, first published in 2009, took over a decade to become a mandated feature on both the Apple App Store and Google Play Store.4 Zakir Durumeric's research characterizing the MrDeepFakes marketplace contributed to the public and legal scrutiny that ultimately led to the site's shutdown in 2025.5

None of these changes happened the moment those papers were published. The change happened because the community kept talking. Each paper was one more voice saying the problem still existed, still mattered, and still needed a response.

This raises something the novelty requirement tends to obscure. Many understudied communities have no literature at all, and building that literature from scratch looks, on the surface, like producing findings that already exist elsewhere. The usable security field has largely built its findings on WEIRD populations and often assumed those findings travel broadly. They frequently do not. When researchers study other populations, like our work on Pakistani immigrants to the US which found that first-generation immigrants perceive heightened risks of discrimination, surveillance, and self-censorship as Muslim immigrants,6 reviewers asked us to justify why we chose that population and how well the findings generalize. I am not sure that is a fair question to ask. We cannot expect generalizability from studies on populations we have barely examined at all. The point of such work is to start building a literature that does not yet exist.

It is also worth noting that the structural conditions reviewers work under are getting harder. Academic peer review runs on voluntary labor, and that labor is now under real strain. CHI 2025 received over 5,000 completed submissions, a 58% increase from just two years earlier, and projections suggest the numbers could keep climbing as AI-assisted writing accelerates paper production.7 In that kind of environment, novelty becomes less of a principled criterion and more of a quick filter for someone trying to get through an overwhelming stack of papers.

On top of this, funding for the kinds of research that most need sustained attention is shrinking. In April 2025, NSF terminated hundreds of grants under the directive that they were no longer aligned with agency priorities. Misinformation and disinformation research was explicitly named as a category that would no longer be supported.8 Over 1,300 NSF grants representing around $700 million in unspent funds were cut or frozen by November 2025.9 When funding disappears for research on online harms and platform accountability, publication becomes one of the few remaining ways to keep those conversations alive in the scientific community at all.

So what I am observing is something like a narrowing from both ends. The novelty requirement makes it harder to publish work that is persistent and community-centered. Funding cuts make it harder to support such work in the first place. And the communities that research in this space tends to serve are not going anywhere. The harms are not going anywhere either. I am not sure the research community has fully reckoned with what it means to keep demanding novelty in this environment, but it seems like a question worth sitting with.