4.7 Article

Analysis of security and data control in smart personal assistants from the user's perspective

出版社

ELSEVIER
DOI: 10.1016/j.future.2023.02.009

关键词

Cybersecurity; Data control; Internet of things; Minors; Smart personal assistants; Testing methodology

向作者/读者索取更多资源

Advances in IoT, Speech Recognition and AI have led to the development of Smart Personal Assistants, but their popularity and technological complexity also make them a target for security concerns. This study proposes a methodology to systematically analyze the security of Smart Personal Assistants and applies it to analyze major commercial ones. The findings reveal vulnerabilities in voice replay attacks, unreliable skills activation in multi-user households, insufficient control over Personally Identifiable Information, and lack of configurations for minors. Voice authentication and authorization are identified as interesting research topics to enhance both usability and security of Smart Personal Assistants.
Advances in the fields of the Internet of Things, Speech Recognition and Artificial Intelligence have facilitated the development of Smart Personal Assistants. As a result, Smart Personal Assistants currently allow requesting a wide range of tasks naturally and intuitively through voice interaction. Their wide popularity, together with the high technological complexity of their environments, have made them an attractive target from a security point of view. Recent works have shown some of the security and privacy issues they stand upon. In this work, we propose a methodology to carry out a systematic security analysis of Smart Personal Assistants using a comprehensive set of tests designed to measure issues around the installation, the interaction, key functionality, and overall Security and Privacy controls. We apply this methodology to analyse security and data control in predominant commercial Smart Personal Assistants (SPA), including Apple HomePod, Google Home and Nest, Amazon Echo (Show and Dot), and Facebook Portal. The main findings of our research are: (i) SPA are not resilient to voice replay attacks; (ii) their skills activation mechanisms can be significantly improved to be more reliable in multi-user households; (iii) the users' control to restrict the collection and access of Personally Identifiable Information can be also improved; (iv) they lack configurations adapted to minors, which should be included to make them more appropriate for a segment of users who interact more and more with them and have especially high regulatory requirements regarding security and data protection. Among the many hot research topics within this area, we find voice authentication and authorization especially interesting since they may push the usability of Smart Personal Assistants further, as long as they are robust enough from the security perspective.(c) 2023 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据