publications

papers

BREAK-IT: Understanding Novice Approaches to an Attack-Challenge Task

Michelle Jensen, Matthew Berland, Rahul Chatterjee

ACM Innovation and Technology in Computer Science Education (ITiCSE '26)

pdf | doi


Do CS Undergraduates Show Evidence of a Security Mindset without Formal Coursework?
An Exploratory Qualitative Study

Michelle Jensen, Matthew Berland, Rahul Chatterjee

ACM International Computing Education Research (ICER '25)

pdf | doi

posters

A Dichotomy of Demonstrated vs. Perceived Knowledge in Computer Security

Michelle Jensen

ISLS International Conference of the Learning Sciences (ICLS '24)

pdf | doi


current projects

building security mindsets

Examining how undergraduate CS students without formal security experience reason about security and engage with seucrity tasks.

We found that with minimal prompting, most students demonstrated explicit examples of secure design and threat perception. Students also drew from knowledge including formal non-security coursework, personal and informal experiences, and prior defense task. When searching for vulnerabilities, students utilized strategic testing approaches rather than blind exploration. These findings suggest potential avenues for scaffolding security learning within existing coursework.

publications
BREAK-IT: Understanding Novice Approaches to an Attack-Challenge Task (ITiCSE '26)
Do CS Undergraduates Show Evidence of a Security Mindset without Formal Coursework? (ICER '25)

classroom bibifi

Adapting Ruef et al.'s Build-It, Break-It, Fix-It (BIBIFI) competitions into non-security CS classrooms develop security thinking by making the attacker tangible and removing the competitive aspect. An activity has been implemented in UW—Madison's CS400: Programming III course and is undergoing refinement.

In addition, I am building a set of prompts/activities for instructors to use or adapt for their own classrooms. Some of these prompts have appeared in my published work, but complete materials and guidance for classroom use are still in development.

publications
Data collected, analysis in progress

meander graphs

Developed a linear-time, non-destructive algorithm for determining the structure of a meander graph by indentifying the hierarchical arrangement of paths and cycles. This also yields a linear-time path and cycle detection algorithm as a preprocessing step. Meander graphs have many applications including but not limited to seaweed sub-algebras (Lie Theory) and secondary RNA structures.

(Collaboration with Professors Amber Russell and Ankur Gupta)

publications
Manuscript in Progress

emerging ideas

My notebook is always filled with research ideas, but these are a few that I am currently thinking about.

  • Alternative approaches to computer security learning and teaching
  • Informal contexts for learning computer security
  • How peer collaboration shapes computer security learning
While these ideas are still in the early stages, if you'd like to chat or work together on them, please reach out!