User Tools

Site Tools


privacy:darkpatterns

Dark Patterns in Interfaces You Measure

A dark pattern (the term the field is drifting towards is deceptive pattern) is an interface built so that the choice the operator wants is easier to make than the choice the user wants. For a web measurement study that matters in two distinct ways, and this page is about both:

  • As the thing you measure. If you are auditing consent notices, cancellation flows or data-rights portals, the asymmetry is the result. Counting it means committing to a taxonomy, an operationalisation per category, and a denominator — and the field's operationalisations differ enough that two papers reporting “interface interference” are often not measuring the same thing.
  • As a confounder in every other crawl. A banner engineered to make refusal expensive is also, incidentally, engineered against your crawler — and two 2026 papers show LLM-driven agents are measurably susceptible to the same designs. If your pipeline clicks “Accept” because the accept button was the only one it could find, the pattern has become part of your instrument.

This page is deliberately short, and it is short for a reason you need to know about. The measurement literature on dark patterns lives overwhelmingly at CHI, CSCW and SOUPS, and none of those venues is in the publication corpus behind this wiki (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P, 2010–2026). Every count on this page is therefore a count over the security and privacy slice of the topic, which is the smaller slice. The taxonomy section below rests on out-of-corpus work that was checked by hand rather than by query. Treat this page as a pointer into the HCI literature plus a survey of what S&P venues have actually measured, not as a survey of the field.

Pick a taxonomy, and say which one

There is no single legal or academic definition, and this is the central methodological problem: a prevalence figure is uninterpretable without the taxonomy that produced it.

The current answer to “which taxonomy” is Gray et al.'s ontology [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)], which harmonises ten prior regulatory and academic taxonomies into 65 pattern types across three levels of abstraction — high-level strategies, meso-level angles of attack, low-level concrete patterns. It is the right starting point in 2026 for two reasons. First, it is a mapping rather than a competitor: if your data was labelled with Mathur et al.'s categories [2Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)] or with the taxonomy embedded in a regulator's guidance, the ontology tells you where those labels sit. Second, its low/meso/high split is exactly the axis on which measurement papers talk past each other — an automated crawl detects low-level patterns (a pre-ticked box, a greyed-out button), while a user study measures high-level effects (did the design change the decision), and reporting one as the other is a common overclaim in this area.

Older taxonomies still worth knowing, and their status:

Taxonomy Year Status for a new study
Bösch et al., privacy dark strategies and dark patterns [3Bösch, Christoph; Erb, Benjamin; Kargl, Frank; Kopp, Henning; Pfattheicher, Stefan (2016): "Tales from the Dark Side: Privacy Dark Strategies and Privacy Dark Patterns", Proceedings on Privacy Enhancing Technologies 2016(4):237-254. (DOI)] 2016 Historical. The first S&P-venue treatment (in corpus, PETS); seven patterns, derived by manual survey, not designed for automated detection. Read for the psychological framing, do not use as your label set.
Mathur et al., dark patterns at scale [2Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)] 2019 Still widely used, especially in e-commerce work. Superseded as a classification system by the ontology, which subsumes it.
Gray et al., ontology of dark patterns knowledge [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)] 2024 Current default. Use it, or state your mapping onto it.

Legally, the position as of August 2026 is still fragmentation, and your paper should not claim otherwise. The DSA prohibits dark patterns on online platforms in Article 25 and describes them in recital 67, but Article 25 explicitly steps aside where the UCPD or GDPR applies; the UCPD prohibits “misleading” and “aggressive” practices without using the term and without addressing digital interfaces in its Annex I; the GDPR does not name them at all, though consent-obtaining techniques can be assessed under it.1) A Digital Fairness Act intended to consolidate this was announced in the Commission's 2026 work programme for Q4 2026 and, as of this writing, has not been tabled — so do not cite it as law.2)

What the S&P corpus has actually measured

Of the 5,855 papers whose paper.cols.txt the probe could read (4 of the 5,859 extracted papers have no readable full text and are silently counted as negatives here), 48 discuss dark patterns substantively (at least five occurrences of dark pattern / deceptive design / deceptive pattern / manipulative design in the full text, whitespace-collapsed); a further 83 mention the term only in passing or in related work. That 48 is the honest denominator for anything on this page. Its year distribution — 2 papers before 2020, 10 in 2020–2022, 18 in 2023–2024, 18 in 2025–2026 (both provisional venue-years) — says the topic arrived in security venues late and is growing.

Almost all of it is about consent notices. The measured figures below are quoted with each paper's own denominator; note how different the denominators are, which is why the percentages should never be averaged.

Finding Figure Denominator Paper
Nudging present in the notice design 57.4% consent notices audited by hand from screenshots [4Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]
Pre-selected choices 46.5% (236 of 508) websites where refusal was possible at all [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]
No way to opt out 6.8% (38 of 560) semi-automatically crawled websites [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]
Accept and reject controls visually unequal six of ten consent pop-ups studied by hand, CMP default configurations [6Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)]
Interface interference (colour/text-style asymmetry between accept and reject) 67.8% 16,122 websites offering both a positive and a negative option [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)]
Forced action (non-notice links unreachable before interacting) 46.4% 48,843 websites with a cookie notice [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)]
Mobile consent dialogs violating at least one design requirement 98.8% (429) apps showing a proper consent dialog — itself only 11.9% of apps analysed [8Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)]
Websites with at least one deceptive pattern detected (vision-model pipeline) 49.02% (375 of 765) accessible websites reached by the crawl [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)]
Apps with at least one deceptive pattern detected (same pipeline) 25.68% (246 of 958) apps from which screenshots could be collected [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)]

Two things to take from that table rather than from any single row. The first is that the denominator does most of the work: “67.8% show interface interference” is a statement about sites that offered a reject option, and the sites that offered none are excluded from it, so the figure understates the population-level asymmetry rather than overstating it. The second is that the effect-side evidence is thinner and comes from experiments, not crawls: a randomised banner study found refusal rates moving from 17% on a control banner to 34% with a highlighted decline button and 47% when consequences were spelled out [10Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)], and the effect partly persisted when participants later saw a neutral banner. Prevalence and effect are different claims; the corpus supports the first much better than the second.

Detection methods, and which are current

Dating these matters, because the cheap method and the current method are not the same one.

Method Years it is used in the corpus Status
Manual audit of screenshots against a coded variable list 2016–2022, and still used for validation after Still the ground truth. [4Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], [6Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)]. Does not scale, and remains what everything else is validated against.
DOM and CSS heuristics: pre-ticked checked attributes, computed colour/contrast of button pairs, text-style comparison, reachability of links behind the overlay 2022–2024 Current practice for low-level patterns at scale, and the highest-precision option for the narrow set of patterns it covers — [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)] report a 0.0% false-positive rate for dark patterns against 500 hand-annotated sites, versus 9.4% for the harder privacy-violation judgements in the same pipeline. Cannot see anything requiring semantics.
Regular expressions / keyword matching over dialog text 2023 (one paper at scale) Superseded for anything but a first filter. Used at scale for mobile dialogs [8Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)]; brittle across languages, and the language question is on Multilingual support.
Vision models over screenshots: object detection to localise UI elements, then a multimodal model to classify 2025–2026 Current for the categories heuristics cannot reach. [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)] (YOLO-family detector plus a multimodal classifier, 65-type taxonomy); [11Nayak, Asmit; Wani, Yash; Zhang, Shirley; Khandelwal, Rishabh; Fawaz, Kassem (2025): "Automatically Detecting Online Deceptive Patterns", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] report F1 0.93 for deceptive-pattern detection and F1 0.91 for UI-element localisation on 5,879 elements, then deploy the pipeline over a separate corpus of 11,118 websites (6,626 Tranco domains plus 4,492 Shopify stores) — note that the 11,118 is the deployment corpus, not the set the F1 was computed on. This is where the field is moving, and it is also the least externally validated: both are 2025 results in the provisional slice of the corpus.
LLM-driven agents that traverse a workflow and classify what they encounter 2026 Emerging, and not yet a measurement instrument you should trust unsupervised. [12Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)] audited CCPA data-rights workflows across 456 data brokers, verifying agent completion at 87% and 79% in two phases, and got category prevalence estimates spanning 15.2%–48.6% across eight categories — wide intervals that are the point of the paper, not a footnote to it.

The honest summary: manual coding for validation, DOM heuristics for the low-level patterns you can define mechanically, vision models for the rest, and agent-driven auditing as a research direction rather than a method to adopt. If you build a detector, report per-category precision and recall against a hand-annotated sample, not an aggregate F1 — the aggregate hides that most pipelines are good at pre-ticked boxes and poor at, say, confirmshaming.

Dark patterns as an attack on your instrument

This is the part a fresh PhD student is least likely to expect, and it is the newest material in the corpus.

If your crawler interacts with consent notices — see Granting consent to websites and Interaction with websites — then interface asymmetry is a systematic bias in your treatment assignment, not background noise. A pipeline that clicks the visually dominant button reproduces the operator's intended outcome and will report a consent rate that is a property of your heuristic. Two 2026 papers make this concrete for agentic crawlers. LLM-based web agents followed the dark pattern rather than the task an average of 41% of the time when a single pattern was present, with susceptibility varying strongly by category and by agent — per-agent rates reach 72.3% — and prompt-level countermeasures recovering only part of it [13Ersoy, Devin; Lee, Brandon; Shreekumar, Ananth; Arunasalam, Arjun; Ibrahim, Muhammad; Bianchi, Antonio; Celik, Z. Berkay (2026): "Investigating the Impact of Dark Patterns on LLM-Based Web Agents", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. And when an agent is the auditing instrument rather than the subject, its category estimates spread across 15.2%–48.6% depending on configuration [12Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)], which is the same problem seen from the measurement side.

Practical consequences for a crawl:

  • Log what your interaction code saw and chose, per site, not just the outcome. Without the element it clicked and why, you cannot separate “the site refused” from “the crawler missed the reject button”.
  • Report the sites where your interaction failed as a category, not as missing data. In this literature the sites that defeat automation are disproportionately the ones with the patterns you are counting, so dropping them biases the estimate downward.
  • If your interaction is an LLM agent, treat its susceptibility as a measured property of your instrument and validate it on seeded cases before trusting a prevalence number.

What to report

  • The taxonomy and its version, and the mapping onto Gray et al.'s ontology [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)] if you used something else.
  • The operationalisation of each category — the concrete DOM, colour or text test — because “interface interference” is not a measurement until you say what it is.
  • A denominator per category, and it will not be the same one for every category: a reject-button asymmetry can only be measured where a reject button exists.
  • Per-category precision and recall against a hand-annotated sample, with the sample size and the annotation procedure (inter-rater agreement).
  • Vantage and language, since notices differ by both (Crawling location).
  • What your automation could not reach, counted.

Methodology and limitations of these figures

Counts come from a keyword-and-full-text probe over the 5,859-paper extraction of the seven-venue corpus described on corpus; the report script, every query with its denominator, the quotes checked against source PDFs, and the probe's residue are on darkpatterns.

Three limitations that bound what this page can say:

  • CHI, CSCW and SOUPS are not in the corpus, and that is where most dark-pattern measurement is published. The 48-paper figure is a count of security-venue papers, and nothing more. The taxonomy section is built from hand-checked external sources.
  • 2025 and 2026 are provisional venue-years — some venue-years in them had not been held or were not fully indexed at corpus build time. The vision-model and agent-auditing rows above therefore rest on the thinnest years available, which is a reason to date them rather than to omit them.
  • A keyword probe under-recalls. 32 of the 48 substantive papers never mention a dark-pattern term in their structured extraction record, so any query against the schema alone would have missed two thirds of them. Papers that measure interface asymmetry without using the vocabulary at all are not counted here at all.
[1]
Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)
[2]
Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)
[3]
Bösch, Christoph; Erb, Benjamin; Kargl, Frank; Kopp, Henning; Pfattheicher, Stefan (2016): "Tales from the Dark Side: Privacy Dark Strategies and Privacy Dark Patterns", Proceedings on Privacy Enhancing Technologies 2016(4):237-254. (DOI)
[4]
Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[5]
Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[6]
Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)
[7]
Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)
[8]
Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)
[9]
Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)
[10]
Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)
[11]
Nayak, Asmit; Wani, Yash; Zhang, Shirley; Khandelwal, Rishabh; Fawaz, Kassem (2025): "Automatically Detecting Online Deceptive Patterns", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[12]
Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)
[13]
Ersoy, Devin; Lee, Brandon; Shreekumar, Ananth; Arunasalam, Arjun; Ibrahim, Muhammad; Bianchi, Antonio; Celik, Z. Berkay (2026): "Investigating the Impact of Dark Patterns on LLM-Based Web Agents", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
1)
European Parliamentary Research Service, Regulating dark patterns in the EU: Towards digital fairness, PE 767.191, January 2025.
2)
European Parliament Legislative Train Schedule, Digital Fairness Act, status “Announced”, CWP indicative date Q4 2026; checked 2026-08-21.
You could leave a comment if you were logged in.
privacy/darkpatterns.txt · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki