Research Ethics Wiki#

This wiki is maintained by the community. The information provided is for educational purposes and should not be considered legal advice. Researchers should always consult with their institution's ethics review board and legal counsel when necessary.

Overview#

This wiki is a collection of information regarding research ethics in computer security and privacy (S&P) research. It aims to provide researchers, reviewers, and students with a resource for understanding and navigating the ethical considerations inherent in conducting and reviewing S&P research.

What Is Research Ethics?#

Research is guided by moral principles, which we call research ethics. In the context of computer security and privacy research, research ethics is driven by four goal sets – impact on the outside world; impact on the S&P community; impact on individual community members; and the external perception. Ethical considerations in the S&P domain are particularly important due to:

  1. The potential impact on human subjects and their privacy in active and passive forms
  2. The dual-use nature of security research findings
  3. The legal and regulatory landscape surrounding security and privacy research

Why We Have This Wiki?#

A number of studies found that S&P researchers ask for more guidance when it comes to research ethics. The topic is complex and constantly evolving. This wiki therefore serves to:

  • Provide an overview of current ethical norms in the S&P community and its conferences
  • Offer resources on institutional review processes (e.g, RECs)
  • Document best practices for conducting ethical research
  • Share case studies and lessons learned from the research community

We would recommending to start by reading about the ethics procedure and ethical considerations sections.

Contributing#

This wiki is a community effort and we welcome contributions from researchers and practitioners. Whether you want to add new content and references, improve existing pages, or share case studies, your input is valuable. See Contributions for more details.

About#

This wiki started as an actionable result from the REC study and aims to provide a similar comprehensive resource for research ethics in computer security and privacy.

If you found this wiki helpful and used it as inspiration for your ethics section, please consider citing or mentioning it there so that others can discover and benefit from it as well.

@inproceedings{hantke2026reflection,
  title={Reflection, Education, Consistency: Towards Best Ethics Practices At Security And Privacy Conferences},
  author={Hantke, Florian and Mrowczynski, Rafael and Dralle, Til and Stock, Ben},
  booktitle={Proceedings of the 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS)},
  year={2026}
}