Source-linked AI summary
Discovering Smart Home Internet of Things Privacy Norms Using Contextual Integrity
Noah Apthorpe, Yan Shvartzshnaider, Arunesh Mathur, Dillon Reisman, Nick Feamster
TL;DR
Smart home IoT devices create privacy concerns, while existing approaches lacked scalable, formally grounded ways to discover privacy norms. The paper develops a Contextual Integrity survey method and applies it to thousands of smart home information flows, yielding actionable recommendations for IoT stakeholders.
Problem
Smart home IoT devices can observe sensitive in-home details, but prior studies did not discover IoT privacy norms at scale using a formal privacy theory.
Method
The paper integrates Contextual Integrity with combinatorial survey testing to measure the acceptability of contextual smart home information flows.
Results
The survey produced actionable recommendations for device manufacturers, regulators, and consumer advocates regarding smart home privacy norms.
Takeaways & Limitations
The CI survey method is adaptable to arbitrary contexts and can support privacy-norm discovery in rapidly changing technological domains.
Takeaways & Limitations
Because participants were recruited through Amazon Mechanical Turk, the results may be less generalizable to the broader U.S. population.
Abstract
from arXiv · showhide
The proliferation of Internet of Things (IoT) devices for consumer "smart" homes raises concerns about user privacy. We present a survey method based on the Contextual Integrity (CI) privacy framework that can quickly and efficiently discover privacy norms at scale. We apply the method to discover privacy norms in the smart home context, surveying 1,731 American adults on Amazon Mechanical Turk. For $2,800 and in less than six hours, we measured the acceptability of 3,840 information flows representing a combinatorial space of smart home devices sending consumer information to first and third-party recipients under various conditions. Our results provide actionable recommendations for IoT device manufacturers, including design best practices and instructions for adopting our method for further research.
1 INTRODUCTION
The paper introduces a scalable Contextual Integrity survey method for discovering smart home privacy norms and applies it to produce actionable recommendations for stakeholders.
- IoT devices can observe sensitive in-home details, creating a need for scalable methods grounded in formal privacy theory.
- The method represents information flows through five contextual parameters, enabling repeatable investigation of combinatorial privacy norms.
- 1,731 U.S. adults evaluated 3,840 smart home information flows for $2,800 in less than six hours.
- Information flows unrelated to core device features, involving ISPs, advertising, or indefinite storage, were especially unacceptable.
- Information flows outside the home were generally unacceptable unless the device owner specifically granted consent.
- The authors provide recommendations for manufacturers, regulators, and advocates, plus instructions for adapting the method and conducting longitudinal studies.
2 CONTEXTUAL INTEGRITY BACKGROUND
Contextual Integrity defines privacy through the appropriateness of information exchanges within contexts, using structured parameters to evaluate changing norms.
- Contextual Integrity defines privacy as whether an informational exchange conforms to norms established within a specific context.
- CI represents information flows with sender, recipient, attribute, subject, and transmission principle parameters.
- Changing any information-flow parameter may produce a privacy-norm violation.
- CI supports reassessing norms as new technologies create unfamiliar information exchanges and contexts.
- The survey’s parameter table fixes the subject as the device owner and includes a null transmission principle for unconditional flows.
3 SURVEY METHOD
The survey constructs smart home information flows from Contextual Integrity parameters, measures their acceptability, and examines how recipients, attributes, subjects, and transmission conditions shape privacy norms.
- The method selects context-relevant senders, recipients, attributes, subjects, and transmission principles before surveying flow acceptability.
- Sender: The sender list spans commercially available devices representing physical presence, behavior, and energy usage.
- Sender: Device names were generally omitted to reduce company-specific opinions, except when examples were needed to clarify a device category.
- Recipient: Recipients included manufacturers, police, intelligence agencies, ISPs, other home devices, family members, and social media accounts.
- Attribute and subject: Attributes covered raw sensor recordings and inferred behaviors, while the device owner was the survey’s sole subject to limit questions and fatigue.
- Transmission Principle: Transmission principles varied information use, storage, and circumstances, and response differences showed that privacy norms depend on these conditions.
3.2 Survey Design
The survey operationalized Contextual Integrity questions as matrix-based acceptability ratings over selected smart-home information flows. Grouping and ordering reduced participant burden while preserving comparisons across recipients and transmission principles.
- Survey design: The survey queried acceptability for selected combinations of five Contextual Integrity parameters, excluding flows that were implausible for current IoT devices.For example, refrigerator heart-rate flows were excluded.
- Survey design: 3,840 information flows were divided into 48 sets sharing the same sender and attribute, with each participant assigned one set.This design limited the number of flows each participant rated while covering all tested recipients and transmission principles across participants.
- Survey design: Each participant rated 82 flows using matrix questions with a five-point acceptability scale.Matrix columns ranged from “Completely Unacceptable” to “Completely Acceptable,” while rows represented varying parameter values.
- Contextual Integrity Questions: The first matrix varied recipients under the null transmission principle, followed by matrices varying transmission principles for fixed recipients.The initial ordering was intended to prevent priming by other transmission principles, while later matrix order was randomized.
- Survey design: The survey concluded with demographic and technical-background questions, and participants were split equally between males and females.Many participants had at least a Bachelor’s degree and were younger than the general US population.
3.3 Survey Deployment
The researchers refined the survey through usability testing and then deployed it on MTurk using controlled recruitment criteria. The final deployment cost $2,800 and took less than six hours.
- Survey deployment: The survey was hosted in Qualtrics, approved by an Institutional Review Board, and refined after five cognitive interviews with MTurk workers.The UserBob testers completed the survey within 15 minutes, and their responses were excluded from final results.
- Survey deployment: 2,000 participants were recruited through TurkPrime and paid $1.00 each for completing the survey.Recruitment was limited to US workers with 90–100% HIT approval ratings.
- Survey deployment: $2,800 and less than six hours were required to run the entire survey.The reported cost and duration demonstrate the method’s operational efficiency at scale.
3.4 Response Analysis
The analysis aggregated Likert responses by Contextual Integrity parameter pairs and used non-parametric tests to assess recipient and transmission-principle effects. Attention checks and multiple-comparison correction supported the statistical analysis.
- Response processing: 269 participants were removed after failing the attention check, leaving 1,731 responses averaging 37 responses per matrix question.Responses used a Likert scale from −2 for Completely Unacceptable to 2 for Completely Acceptable.
- Aggregation: Average Likert acceptability scores were computed for sender/attribute pairs and recipient/transmission-principle pairs.These averages enabled comparisons of individual parameter effects and parameter-pair effects on information-flow acceptability.
- Statistical testing: Independence across sender and attribute pairs enabled non-parametric Wilcoxon signed-rank tests for recipients and transmission principles.The tests compared matched information flows while varying the parameter under study.
- Statistical testing: The transmission-principle and recipient tests used Bonferroni-adjusted thresholds of 0.00008 and 0.0001, respectively.These thresholds came from dividing the standard 0.05 cutoff by the number of tests.
4 RESULTS
Smart-home information-flow acceptability varied most across recipients and transmission principles, with consent, emergencies, and notification generally improving acceptability while advertising, indefinite storage, and several recipients reduced it. Parameter interactions also mattered, and device ownership produced only small shifts.
- 4.1 Average Acceptability Scores: Consent, emergencies, and owner notification were the only transmission principles with positive average acceptability scores in any pair.Their score ranges were 0.58 to 1.38, −0.33 to 0.86, and −0.82 to 0.40, respectively.
- 4.1 Average Acceptability Scores: Advertising and indefinite storage had the lowest transmission-principle scores, while government intelligence agencies, social media accounts, and ISPs had the lowest recipient scores.Advertising ranged from −1.51 to −1.24, and indefinite storage from −1.53 to −0.87.
- 4.1 Average Acceptability Scores: Sender/attribute pairs varied less than recipient/transmission-principle pairs, with score ranges of −0.23 to −0.87 and −1.53 to 1.38, respectively.Power meters and fitness trackers were the most acceptable senders, whereas security cameras and refrigerators were the least acceptable.
- 4.1 Average Acceptability Scores: Contextual Integrity parameters interacted: other devices in the home were positive with six transmission principles but negative with five others.Eating-habit information from refrigerators scored −0.35, compared with −0.73 to −0.53 for other senders.
- 4.2 Effect of Transmission Principle and Recipient: Consent, emergencies, and notification changed scores significantly in ≥85% of instances, whereas non-storage, price discounts, and anonymity did so in <10%.Government intelligence agencies, ISPs, and social media accounts differed from the family-recipient baseline in ≥98% of instances.
- 4.3 Effect of Smart Home Device Ownership: Owning a smart-home device generally increased acceptability slightly, with ∆0.17 for feature development and maintenance flows.Indefinite-storage flows were the strongest exception, receiving ∆0.14 higher scores from non-owners; no principle crossed from negative to positive or vice versa.
5 OBSERVATIONS AND RECOMMENDATIONS
The paper uses a scalable Contextual Integrity survey to identify smart-home privacy norms and translate broad findings into recommendations for manufacturers, regulators, and advocates. Results emphasize minimizing nonessential communications, treating consent and context carefully, and scrutinizing recipients, attributes, and storage or advertising practices.
- 5.1 Device Manufacturers Should Survey Contextual Privacy Norms: Manufacturers can customize the method with product-specific five-parameter flows to identify communications that may disrupt established contextual norms.The method is intended to support research on products and contexts not studied in this paper.
- 5.2 Device Communications Should Be Necessary for Core Functionality: Most information flows received negative acceptability scores, supporting restrictive rather than permissive device communications and careful review of third-party services and libraries.Third-party components may invoke information flows to potentially unknown recipients.
- 5.4 User Consent is Broadly Important for Information Flow Acceptability: Consent produced the highest average acceptability across recipients, but emergency-conditioned flows could also be acceptable without specified consent, showing that contextual factors extend beyond consent alone.Consent was the only information-flow parameter with positive average acceptability across all conditions, while emergency flows were positive with five of six recipients.
- 5.5 Local Data Sharing Should Consider Secondary Information Flows: Sharing with other devices in the home was comparatively acceptable, whereas ISPs, advertising, and indefinite storage were among the least acceptable conditions.The home-device recipient was the only recipient with positive average acceptability under the null transmission principle; ISP flows had median scores of −2 versus 0 for the family baseline.
- 5.6 Information Flows Should Be Closely Related to Core Device Function: Acceptability generally increased when information was closely related to a device’s core function, while device type and respondent ownership produced smaller or differing effects.Fitness-related data from a fitness tracker was more acceptable than less fitness-relevant recorded audio, and owners rated flows higher across transmission principles but with small differences.
6 LIMITATIONS AND FUTURE WORK
The authors identify limitations involving ambiguous participant interpretations, limited rationale in open-ended responses, additional unmodeled factors, and MTurk generalizability. They propose clearer parameters, follow-up studies, richer models, broader samples, and an online survey tool as future work.
- 6.1 Parameter Ambiguity: Participant interpretations may have introduced uncontrolled variation in information-flow acceptability scores.Examples include differing interpretations of family groups and generic device types.
- Future Work: Future studies can use more clearly defined information-flow parameters and apply the customizable CI method to product-specific scenarios.The authors also propose an online tool for creating, deploying, and analyzing CI surveys.
- Future Work: The CI survey method discovers privacy norms but does not by itself reveal the values and tradeoffs that produce them.The authors identify trust, national security, safety, security, efficiency, and productivity as examples for deeper study.
- 6.2 Participant Rationale: 30 participants provided IoT-related comments, but their limited number and length restricted explanations of nuanced acceptability differences.Follow-up studies could examine the values underlying especially interesting or surprising norms.
- 6.3 Complex Modeling: Privacy expectations may depend on factors beyond the five CI parameters, although adding factors substantially increases model complexity.The authors suggest that sufficient data and mixed-effect models could examine these influences.
- 6.4 Limitations of the Platform: MTurk-based results may be less generalizable to the broader U.S. population.Future research could validate and extend the findings using more diverse participants.
7 RELATED WORK
Prior IoT privacy studies used vignettes, smaller CI studies, or focused scenarios to examine expectations and norms. This work extends that literature with broader coverage of actors, attributes, transmission principles, settings, devices, and information types.
- Contextual Integrity: Contextual Integrity was proposed as a way to capture contextually grounded reasons for privacy concerns or their absence.This observation motivates the present work.
- Contextual Integrity: A prior small CI-based IoT study identified practices that could be perceived as privacy violations.The present study examines more actors, attributes, and transmission principles and provides more extensive statistical analysis.
- Prior IoT Privacy Studies: Pew research found that Americans may exchange personal information or permit surveillance for something perceived as valuable, including in smart-home settings.The present work instead provides a broader analysis of IoT information-flow scenarios.
- Contextual Integrity: Prior CI vignette research found that contextual information affects sensitivity judgments and that use is more important to privacy expectations than information type alone.This finding supports examining information flows together with their contextual parameters.
- This Work: The present work integrates formal privacy theory with combinatorial testing at scale to analyze a more comprehensive range of IoT information flows.It builds on earlier crowdsourced CI norm discovery while expanding coverage and statistical analysis.
- Prior IoT Privacy Studies: Earlier IoT studies examined privacy expectations through vignette scenarios involving data types, purposes, retention, sharing, collection frequency, and granularity.These studies included a 1,007-participant study of 380 use-case scenarios and experiments on smart power meters.
8 CONCLUSION
The paper presents a scalable Contextual Integrity survey method for discovering smart-home IoT privacy norms. A survey of 1,731 U.S. adults covering 3,840 information flows produced actionable recommendations for relevant stakeholders.
- 8 CONCLUSION: The method combines a formal privacy theory with combinatorial testing at scale to discover smart-home IoT privacy norms.The authors present it as applicable to rapidly changing technology contexts.
- 8 CONCLUSION: 1,731 U.S. adults evaluated 3,840 information flows, producing actionable recommendations for device manufacturers, regulators, and consumer advocates.
APPENDIX
The appendix presents self-reported demographic and technical-background information for the survey participants.
- APPENDIX: Table 3 reports participants’ self-reported demographics and technical background.