This is an old revision of the document!
Table of Contents
Dark Patterns in Interfaces You Measure
A dark pattern (the term the field is drifting towards is deceptive pattern) is an interface built so that the choice the operator wants is easier to make than the choice the user wants. For a web measurement study that matters in two distinct ways, and this page is about both:
- As the thing you measure. If you are auditing consent notices, cancellation flows or data-rights portals, the asymmetry is the result. Counting it means committing to a taxonomy, an operationalisation per category, and a denominator — and the field's operationalisations differ enough that two papers reporting “interface interference” are often not measuring the same thing.
- As a confounder in every other crawl. A banner engineered to make refusal expensive is also engineered against your crawler, and since 2025 explicitly against LLM-driven agents. If your pipeline clicks “Accept” because the accept button was the only one it could find, the pattern has become part of your instrument.
This page is deliberately short, and it is short for a reason you need to know about. The measurement literature on dark patterns lives overwhelmingly at CHI, CSCW and SOUPS, and none of those venues is in the publication corpus behind this wiki (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P, 2010–2026). Every count on this page is therefore a count over the security and privacy slice of the topic, which is the smaller slice. The taxonomy section below rests on out-of-corpus work that was checked by hand rather than by query. Treat this page as a pointer into the HCI literature plus a survey of what S&P venues have actually measured, not as a survey of the field.
Pick a taxonomy, and say which one
There is no single legal or academic definition, and this is the central methodological problem: a prevalence figure is uninterpretable without the taxonomy that produced it.
The current answer to “which taxonomy” is Gray et al.'s ontology [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)], which harmonises ten prior regulatory and academic taxonomies into 65 pattern types across three levels of abstraction — high-level strategies, meso-level angles of attack, low-level concrete patterns. It is the right starting point in 2026 for two reasons. First, it is a mapping rather than a competitor: if your data was labelled with Mathur et al.'s categories [2Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)] or with the taxonomy embedded in a regulator's guidance, the ontology tells you where those labels sit. Second, its low/meso/high split is exactly the axis on which measurement papers talk past each other — an automated crawl detects low-level patterns (a pre-ticked box, a greyed-out button), while a user study measures high-level effects (did the design change the decision), and reporting one as the other is the commonest overclaim in this area.
Older taxonomies still worth knowing, and their status:
| Taxonomy | Year | Status for a new study |
|---|---|---|
| Bösch et al., privacy dark strategies and dark patterns [3Bösch, Christoph; Erb, Benjamin; Kargl, Frank; Kopp, Henning; Pfattheicher, Stefan (2016): "Tales from the Dark Side: Privacy Dark Strategies and Privacy Dark Patterns", Proceedings on Privacy Enhancing Technologies 2016(4):237-254. (DOI)] | 2016 | Historical. The first S&P-venue treatment (in corpus, PETS); seven patterns, derived by manual survey, not designed for automated detection. Read for the psychological framing, do not use as your label set. |
| Mathur et al., dark patterns at scale [2Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)] | 2019 | Still widely used, especially in e-commerce work. Superseded as a classification system by the ontology, which subsumes it. |
| Gray et al., ontology of dark patterns knowledge [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)] | 2024 | Current default. Use it, or state your mapping onto it. |
Legally, the position as of August 2026 is still fragmentation, and the page you are writing should not claim otherwise. The DSA prohibits dark patterns on online platforms in Article 25 and describes them in recital 67, but Article 25 explicitly steps aside where the UCPD or GDPR applies; the UCPD prohibits “misleading” and “aggressive” practices without using the term and without addressing digital interfaces in its Annex I; the GDPR does not name them at all, though consent-obtaining techniques can be assessed under it.1) A Digital Fairness Act intended to consolidate this was announced in the Commission's 2026 work programme for Q4 2026 and, as of this writing, has not been tabled — so do not cite it as law.2)
What the S&P corpus has actually measured
Of the 5,859 papers with extracted full text, 48 discuss dark patterns substantively (at least five occurrences of dark pattern / deceptive design / deceptive pattern / manipulative design in the full text, whitespace-collapsed); a further 83 mention the term only in passing or in related work. That 48 is the honest denominator for anything on this page. Its year distribution — 2 papers before 2020, 10 in 2020–2022, 18 in 2023–2024, 18 in 2025–2026 (both provisional venue-years) — says the topic arrived in security venues late and is growing.
Almost all of it is about consent notices. The measured figures below are quoted with each paper's own denominator; note how different the denominators are, which is why the percentages should never be averaged.
| Finding | Figure | Denominator | Paper |
|---|---|---|---|
| Nudging present in the notice design | 57.4% | consent notices audited by hand from screenshots | [4Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] |
| Pre-selected choices | 46.5% (236 of 508) | websites where refusal was possible at all | [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] |
| No way to opt out | 6.8% (38 of 560) | semi-automatically crawled websites | [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] |
| Accept and reject controls visually unequal | six of ten | consent pop-ups studied by hand, CMP default configurations | [6Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)] |
| Interface interference (colour/text-style asymmetry between accept and reject) | 67.8% | 16,122 websites offering both a positive and a negative option | [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Forced action (non-notice links unreachable before interacting) | 46.4% | 48,843 websites with a cookie notice | [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Mobile consent dialogs violating at least one design requirement | 98.8% (429) | apps showing a proper consent dialog — itself only 11.9% of apps analysed | [8Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)] |
| Deceptive patterns detected per site (VLM-based) | 49.02% (375 of 765) | accessible websites reached by the crawl | [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)] |
| Deceptive patterns in mobile apps (same pipeline) | 25.68% (246 of 958) | apps from which screenshots could be collected | [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)] |
Two things to take from that table rather than from any single row. The first is that the denominator does most of the work: “67.8% show interface interference” is a statement about sites that offered a reject option, and the sites that offered none are excluded from it, so the figure understates the population-level asymmetry rather than overstating it. The second is that the effect-side evidence is thinner and comes from experiments, not crawls: a randomised banner study found refusal rates moving from 17% on a control banner to 34% with a highlighted decline button and 47% when consequences were spelled out [10Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)], and the effect partly persisted when participants later saw a neutral banner. Prevalence and effect are different claims; the corpus supports the first much better than the second.
Detection methods, and which are current
Dating these matters, because the cheap method and the current method are not the same one.
| Method | Period | Status |
|---|---|---|
| Manual audit of screenshots against a coded variable list | 2016–2020 | Still the ground truth. [4Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], [5Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], [6Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)]. Does not scale, and remains what everything else is validated against. |
DOM and CSS heuristics: pre-ticked checked attributes, computed colour/contrast of button pairs, text-style comparison, reachability of links behind the overlay | 2022–2024 | Current practice for low-level patterns at scale, and the highest-precision option for the narrow set of patterns it covers — [7Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)] report a 0.0% false-positive rate for dark patterns against 500 hand-annotated sites, versus 9.4% for the harder privacy-violation judgements in the same pipeline. Cannot see anything requiring semantics. |
| Regular expressions / keyword matching over dialog text | 2023 | Superseded for anything but a first filter. Used at scale for mobile dialogs [8Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)]; brittle across languages, and the language question is on Multilingual support. |
| Vision models over screenshots: object detection to localise UI elements, then a multimodal model to classify | 2025–2026 | Current for the categories heuristics cannot reach. [9Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)] (YOLO-family detector plus a multimodal classifier, 65-type taxonomy); [11Nayak, Asmit; Wani, Yash; Zhang, Shirley; Khandelwal, Rishabh; Fawaz, Kassem (2025): "Automatically Detecting Online Deceptive Patterns", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] report F1 0.93 for detection-and-localisation over 11,118 websites, with element localisation F1 0.91 on 5,879 elements. This is where the field is moving, and it is also the least externally validated: both are 2025 results in the provisional slice of the corpus. |
| LLM-driven agents that traverse a workflow and classify what they encounter | 2026 | Emerging, and not yet a measurement instrument you should trust unsupervised. [12Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)] audited CCPA data-rights workflows across 456 data brokers, verifying agent completion at 87% and 79% in two phases, and got category prevalence estimates spanning 15.2%–48.6% across eight categories — wide intervals that are the point of the paper, not a footnote to it. |
The honest summary: manual coding for validation, DOM heuristics for the low-level patterns you can define mechanically, vision models for the rest, and agent-driven auditing as a research direction rather than a method to adopt. If you build a detector, report per-category precision and recall against a hand-annotated sample, not an aggregate F1 — the aggregate hides that most pipelines are good at pre-ticked boxes and poor at, say, confirmshaming.
Dark patterns as an attack on your instrument
This is the part a fresh PhD student is least likely to expect, and it is the newest material in the corpus.
If your crawler interacts with consent notices — see Granting consent to websites and Interaction with websites — then interface asymmetry is a systematic bias in your treatment assignment, not background noise. A pipeline that clicks the visually dominant button reproduces the operator's intended outcome and will report a consent rate that is a property of your heuristic. Two 2026 papers make this concrete for agentic crawlers: LLM-based web agents followed the dark pattern rather than the task an average of 41% of the time when a single pattern was present, with susceptibility varying strongly by category and by agent, and prompt-level countermeasures recovering only part of it [13Ersoy, Devin; Lee, Brandon; Shreekumar, Ananth; Arunasalam, Arjun; Ibrahim, Muhammad; Bianchi, Antonio; Celik, Z. Berkay (2026): "Investigating the Impact of Dark Patterns on LLM-Based Web Agents", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)].
Practical consequences for a crawl:
- Log what your interaction code saw and chose, per site, not just the outcome. Without the element it clicked and why, you cannot separate “the site refused” from “the crawler missed the reject button”.
- Report the sites where your interaction failed as a category, not as missing data. In this literature the sites that defeat automation are disproportionately the ones with the patterns you are counting, so dropping them biases the estimate downward.
- If your interaction is an LLM agent, treat its susceptibility as a measured property of your instrument and validate it on seeded cases before trusting a prevalence number.
What to report
- The taxonomy and its version, and the mapping onto Gray et al.'s ontology [1Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)] if you used something else.
- The operationalisation of each category — the concrete DOM, colour or text test — because “interface interference” is not a measurement until you say what it is.
- A denominator per category, and it will not be the same one for every category: a reject-button asymmetry can only be measured where a reject button exists.
- Per-category precision and recall against a hand-annotated sample, with the sample size and the annotation procedure (inter-rater agreement).
- Vantage and language, since notices differ by both (Crawling location).
- What your automation could not reach, counted.
Methodology and limitations of these figures
Counts come from a keyword-and-full-text probe over the 5,859-paper extraction of the seven-venue corpus described on corpus; the report script, every query with its denominator, the quotes checked against source PDFs, and the probe's residue are on darkpatterns.
Three limitations that bound what this page can say:
- CHI, CSCW and SOUPS are not in the corpus, and that is where most dark-pattern measurement is published. The 48-paper figure is a count of security-venue papers, and nothing more. The taxonomy section is built from hand-checked external sources.
- 2025 and 2026 are provisional venue-years — some venue-years in them had not been held or were not fully indexed at corpus build time. The vision-model and agent-auditing rows above therefore rest on the thinnest years available, which is a reason to date them rather than to omit them.
- A keyword probe under-recalls. 32 of the 48 substantive papers never mention a dark-pattern term in their structured extraction record, so any query against the schema alone would have missed two thirds of them. Papers that measure interface asymmetry without using the vocabulary at all are not counted here at all.
- [1]
- Gray, Colin M.; Santos, Cristiana Teixeira; Bielova, Nataliia; Mildner, Thomas (2024): "An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-Building", in: Proceedings of the CHI Conference on Human Factors in Computing Systems. (DOI)
- [2]
- Mathur, Arunesh; Acar, Gunes; Friedman, Michael J.; Lucherini, Elena; Mayer, Jonathan; Chetty, Marshini; Narayanan, Arvind (2019): "Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites", Proceedings of the ACM on Human-Computer Interaction 3(CSCW). (DOI)
- [3]
- Bösch, Christoph; Erb, Benjamin; Kargl, Frank; Kopp, Henning; Pfattheicher, Stefan (2016): "Tales from the Dark Side: Privacy Dark Strategies and Privacy Dark Patterns", Proceedings on Privacy Enhancing Technologies 2016(4):237-254. (DOI)
- [4]
- Utz, Christine; Degeling, Martin; Fahl, Sascha; Schaub, Florian; Holz, Thorsten (2019): "(Un)informed Consent: Studying GDPR Consent Notices in the Field", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [5]
- Matte, Célestin; Bielova, Nataliia; Santos, Cristiana Teixeira (2020): "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
- [6]
- Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)
- [7]
- Bouhoula, Ahmed; Kubicek, Karel; Zac, Amit; Cotrini, Carlos; Basin, David (2024): "Automated Large-Scale Analysis of Cookie Notice Compliance", in: Proceedings of the USENIX Security Symposium. (Link)
- [8]
- Koch, Simon; Altpeter, Benjamin; Johns, Martin (2023): "The OK Is Not Enough: A Large Scale Study of Consent Dialogs in Smartphone Applications", in: Proceedings of the USENIX Security Symposium. (Link)
- [9]
- Shi, Zewei; Sun, Ruoxi; Chen, Jieshan; Sun, Jiamou; Xue, Minhui; Gao, Yansong; Liu, Feng; Yuan, Xingliang (2025): "50 Shades of Deceptive Patterns: A Unified Taxonomy, Multimodal Detection, and Security Implications", in: Proceedings of the ACM Web Conference. (DOI)
- [10]
- Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)
- [11]
- Nayak, Asmit; Wani, Yash; Zhang, Shirley; Khandelwal, Rishabh; Fawaz, Kassem (2025): "Automatically Detecting Online Deceptive Patterns", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
- [12]
- Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)
- [13]
- Ersoy, Devin; Lee, Brandon; Shreekumar, Ananth; Arunasalam, Arjun; Ibrahim, Muhammad; Bianchi, Antonio; Celik, Z. Berkay (2026): "Investigating the Impact of Dark Patterns on LLM-Based Web Agents", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
