”Who is Trying to Access My Account?” Exploring User Perceptions and Reactions to Risk-based Authentication Notifications

Tongxin Wei (PhD student · Nanka University)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Privacy & Usability 2 · Privacy & Usability 2

Overview

In an era where account security is paramount, but user fatigue with complex authentication methods is common, Risk-Based Authentication Notifications (RBANs) offer a crucial middle ground. This talk, presented by Tongxin Wei, a PhD student at Nanka University, delves into the intricate world of user perceptions and reactions to these notifications. RBANs are designed to bolster account security on websites by intelligently detecting suspicious activity—such as logins from unfamiliar devices or IP addresses—and alerting the user, without demanding the constant overhead of two-factor authentication (2FA) for every login.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to Risk-Based Authentication and research goals
  2. 2:00 Study methodology: Website testing and participant interviews
  3. 6:00 User emotional reactions: suspense, anxiety, and nervousness
  4. 6:45 User actions: verifying activity, enabling 2FA
  5. 8:00 Notification design preferences: detailed info, professional layout
  6. 8:45 User indifference, confusion, and phishing concerns
  7. 10:00 Key takeaways and Q&A: device preferences for notifications

”Who is Trying to Access My Account?” Exploring User Perceptions and Reactions to Risk-based Authentication Notifications

Speakers: Tongxin Wei, PhD student, Nanka University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=4pgLGJcFxg

Overview

In an era where account security is paramount, but user fatigue with complex authentication methods is common, Risk-Based Authentication Notifications (RBANs) offer a crucial middle ground. This talk, presented by Tongxin Wei, a PhD student at Nanka University, delves into the intricate world of user perceptions and reactions to these notifications. RBANs are designed to bolster account security on websites by intelligently detecting suspicious activity—such as logins from unfamiliar devices or IP addresses—and alerting the user, without demanding the constant overhead of two-factor authentication (2FA) for every login.

The significance of this research lies in its exploration of the human element in security. While RBANs promise a superior balance of security and usability compared to password-only systems, their effectiveness hinges entirely on how users perceive, understand, and act upon these alerts. With the pervasive threat of phishing attacks, users are increasingly wary of unsolicited security notifications. Wei's work sheds light on the emotional responses, behavioral patterns, and design preferences of users when confronted with potential account compromises, providing invaluable insights for improving the efficacy of these critical security mechanisms.

Background

▶ Watch: Introduction to Risk-Based Authentication and research goals (0:00)

The landscape of online account security is a constant tug-of-war between robust protection and seamless user experience. On one end of the spectrum lies password-only authentication, which is simple for users but notoriously vulnerable to breaches, brute-force attacks, and credential stuffing. On the other end, two-factor authentication (2FA) provides a significantly higher level of security by requiring a second verification factor, but often introduces friction, leading to user frustration and lower adoption rates.

Risk-Based Authentication (RBA) emerges as an intelligent compromise. Instead of universally enforcing a second factor, RBA systems dynamically assess the risk associated with a login attempt. Factors like unusual geographic locations, new devices, atypical login times, or rapid successive failed attempts trigger an elevated risk score. When this threshold is crossed, the system may initiate an RBAN, sending an alert to the user via email or SMS, or prompting for an additional verification step. This approach aims to provide "more security than password-only, but more usability than 2FA," as highlighted in previous research.

Prior work, including "markers research" from 2024, has underscored the importance of user attention to suspicious successful logins. However, a significant gap remained in understanding how users specifically react to the notifications themselves when targeted by others attempting to access their accounts. This research sought to bridge that gap by exploring user feelings, understandings, perceptions, and expectations regarding RBAN designs and their subsequent actions. The problem is compounded by the prevalence of phishing attacks, where malicious actors mimic legitimate security alerts, leading to user skepticism and a tendency to ignore genuine warnings. Understanding user psychology in this context is crucial for designing RBANs that are both effective in prompting protective action and resilient against user distrust.

Key Findings

▶ Watch: User emotional reactions: suspense, anxiety, and nervousness (6:00)

The research uncovered several critical insights into user reactions to RBANs, highlighting both the potential and the pitfalls of these security mechanisms.

Firstly, a dominant emotional response was observed: most participants experienced suspense, anxiety, and nervousness upon receiving an RBAN. This indicates that these notifications successfully convey a sense of urgency and potential threat, prompting users to pay attention.

Regarding notification channels, participants showed a clear preference for receiving RBANs via email and their smartphones. This suggests that security notifications should leverage these ubiquitous communication methods for maximum reach and user comfort. However, the study also revealed that the time, location, and device used to receive the notification significantly affect how users respond, indicating the need for contextual awareness in notification delivery and content.

A crucial finding concerned the actions users take after receiving an RBAN. A substantial 65% of participants attempted to log into their account to verify the reported activity. If they confirmed suspicious activity, they typically changed their password. If no suspicious activity was found (e.g., it was a false positive or they had forgotten a previous login), they often took no further action. Furthermore, 63% of participants indicated they would check for any abnormal activity within their account, demonstrating a proactive security posture. Perhaps most encouragingly, 56% of participants mentioned that they would enable two-factor authentication (2FA) after receiving such a notification. This suggests that RBANs can act as a powerful catalyst for users to adopt stronger security measures.

The study also detailed user preferences for notification content and layout. Participants expressed a strong desire for detailed login information (e.g., specific time, location, device, and IP address of the suspicious activity) and a professional layout. This preference is critical for two main reasons: it helps users quickly assess the legitimacy of the alert and distinguish it from phishing attempts, and it provides the necessary context to make informed decisions.

However, the research also identified significant challenges. Four participants showed indifference towards RBANs, explaining that their past experiences with phishing or spam had desensitized them. This "alert fatigue" or distrust is a major hurdle. Additionally, three participants felt nervous because an incorrect password attempt might lock their account, indicating a need to clarify the system's behavior (e.g., emphasizing that the IP address, not the account, is the focus of the lockout). More than one-third of participants emphasized the importance of the email clearly establishing its identity, reinforcing the need for trusted sender verification to combat phishing concerns. These findings collectively underscore the complex interplay between user psychology, notification design, and the effectiveness of risk-based security measures.

Technical Deep Dive

▶ Watch: User actions: verifying activity, enabling 2FA (6:45)

The research employed a robust mixed-method approach, combining both quantitative and qualitative techniques to gather comprehensive data on user perceptions and behaviors. This methodology allowed for a broad statistical understanding complemented by deeper, nuanced insights.

The initial phase involved a website analysis to understand the current state of RBAN implementation. Researchers attempted to trigger RBANs on 251 websites selected from the top 5,000 domains ranked by Tranco as of December 2023. This selection ensured a focus on widely used and impactful online services. The team simulated three types of suspicious activities across various devices and IP addresses:

  1. Correct password login from an unfamiliar device/IP address: This scenario triggers notifications for legitimate but unusual access.
  2. Repeated incorrect password attempts: Simulating a brute-force or guessing attack.
  3. "Forgot password" operations: Observing notifications related to account recovery attempts by a third party.

This phase allowed the researchers to collect and categorize the content of existing RBANs, providing a realistic foundation for their subsequent user study materials.

For the user study, a diverse participant pool was recruited:

  • 258 US participants were recruited through the online platform Prolific. A key screening criterion was that participants must have a Google account, as the study used simulated Google RBANs to maintain consistency and familiarity.
  • 15 offline Chinese participants engaged in semi-structured interviews. These interviews provided qualitative data, allowing for deeper exploration of their perceptions, expectations, and reasoning behind their responses.

The core of the user study involved sending fake RBAN notifications to participants over a period, specifically on the seventh day, third day, and on the day of the interview. To simulate real-world conditions and observe variations in response, these emails were sent at different times: process late (unspecified but implies late at night), around 12:00 PM (noon), and around 8:00 PM (evening). Participants were then asked to evaluate the design and content of these RBANs using a five-point rating scale, capturing quantitative data on their preferences and usability.

The study also specifically investigated the impact of the device used to receive the notification. While the initial Q&A suggested a preference for PC, the speaker clarified that users preferred to receive notifications via smartphone and email. This distinction is critical: users might act on a PC, but they want the initial alert on their most immediate device. The researchers explored this by targeting RBANs to unfamiliar smartphones or IP addresses, with five researchers actively conducting these tests. This comprehensive approach allowed for the collection of both broad quantitative trends and specific qualitative insights into the complex interactions between RBAN design, user context, and behavioral outcomes.

Demo / Proof of Concept

▶ Watch: User indifference, confusion, and phishing concerns (8:45)

The talk focused on presenting the findings from an extensive empirical research study rather than demonstrating a live technical exploit or a proof-of-concept for a new security tool. While there wasn't a "demo" in the traditional sense of a live hack or software showcase, the methodology involved a crucial simulation component. The research team simulated the receipt of RBANs by sending carefully crafted, fake notifications to their study participants. These simulated alerts were designed based on the analysis of real-world RBANs observed on top websites, ensuring their authenticity and relevance to user experience. This simulation served as the "demonstration" of the research's premise, allowing participants to react to and evaluate these notifications in a controlled environment, which was essential for gathering the qualitative and quantitative data presented.

Defensive Implications

▶ Watch: Key takeaways and Q&A: device preferences for notifications (10:00)

The findings from this research offer critical insights for security practitioners and platform developers aiming to enhance the effectiveness of RBANs and, by extension, overall account security.

  1. Prioritize Clear and Detailed Notification Design: The strong user preference for detailed login information (time, location, device, IP address) and professional layouts is a direct call to action. RBANs must move beyond generic alerts. Implementing specific, verifiable details helps users quickly ascertain the legitimacy of the notification and determine if the activity is truly suspicious. This also builds trust and mitigates the risk of users dismissing alerts as phishing attempts.
  2. Reinforce Sender Identity and Trust: Given that more than one-third of participants emphasized the importance of the email clearly establishing its identity, organizations must employ robust email authentication mechanisms (like DMARC, SPF, DKIM) and visually consistent branding. Clearly displaying the sender's identity in a way that is difficult to spoof is paramount to combat user skepticism driven by phishing experiences.
  3. Leverage Preferred Channels and Contextual Delivery: Users prefer receiving RBANs via email and smartphone. Security teams should ensure notifications are optimized for mobile viewing and are delivered promptly through these channels. Furthermore, considering the impact of time, location, and device on user response, future RBAN systems could become more sophisticated, perhaps adjusting notification urgency or content based on these contextual factors. For instance, a notification received at an unusual time for the user might be designed to be more attention-grabbing.
  4. Educate Users on RBAN Purpose and Actions: The observed indifference and confusion among some participants highlight a significant education gap. Platforms should proactively educate users on what RBANs are, why they receive them, and, crucially, what specific actions they should take (e.g., "If this wasn't you, click here to secure your account," or "If this was you, you can safely ignore this"). Addressing concerns about account lockouts due to incorrect password attempts (as seen with three participants) is also vital, clarifying that the system often flags the IP, not necessarily locks the user out.
  5. Utilize RBANs as a Catalyst for 2FA Adoption: The finding that 56% of participants enabled 2FA after receiving an RBAN presents a powerful opportunity. RBANs can serve as a "teachable moment" for users, demonstrating the real-world risk and the immediate benefit of stronger security. Platforms should integrate clear, easy-to-follow prompts within or immediately after an RBAN to encourage and facilitate 2FA enrollment.
  6. Empower Direct Verification and Action: Since 65% of participants attempt to log in to verify activity, RBANs should provide direct, secure links or in-app pathways for users to review suspicious activity and take immediate action (e.g., "Was this you? Yes / No"). This streamlined process reduces friction and ensures users don't navigate potentially insecure routes to verify.

By implementing these defensive strategies, organizations can transform RBANs from mere alerts into powerful, user-centric security tools that effectively protect accounts and foster a more security-conscious user base.

Key Takeaways

  • Emotional Impact: RBANs evoke strong emotional responses in users, including suspense, anxiety, and nervousness, indicating their potential to grab attention.
  • Channel and Context Preferences: Users prefer receiving RBANs via email and their smartphones, but their response is significantly influenced by the time, location, and device where the notification is received.
  • Catalyst for Stronger Security: A substantial 56% of users are prompted to enable two-factor authentication (2FA) after receiving an RBAN, highlighting their effectiveness as a trigger for adopting better security practices.
  • Importance of Design Clarity: Detailed login information and professional notification layouts are crucial for users to distinguish legitimate alerts from phishing attempts and to make informed decisions.
  • Addressing User Confusion and Distrust: A notable portion of users demonstrate indifference or confusion due to past phishing experiences or concerns about account lockouts, underscoring the need for clearer communication and trust-building measures in RBAN design.
  • Proactive Verification: A majority of users (65%) will attempt to log in and verify suspicious activity, indicating a strong inclination to take action when alerted.

About the Speaker(s)

Tongxin Wei is a PhD student at Nanka University. Their research focuses on critical aspects of user perception and interaction with security mechanisms, particularly in the realm of authentication notifications. This work at the NDSS Symposium highlights their contribution to understanding the human factors that influence the effectiveness of modern cybersecurity defenses.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent HCI security research with a clear methodology and actionable design recommendations for RBAN practitioners. Nothing here will surprise security engineers who've read the adjacent usable-security literature, but the empirical grounding — 258 Prolific participants plus qualitative interviews, triggered against real top-5000 sites — gives it enough meat to be worth the slot at NDSS.

Heather Calloway (CISO) — SOLID

Competent usable-security research that surfaces real design implications for RBANs — particularly the 2FA catalyst finding and the detailed-content preference. But it's scoped as HCI/academic work, and it stops well short of the institutional and governance questions a security leader actually needs answered.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025