← All research

Privacy & Security

As connected devices and apps collect ever more data about people, we study how to make these technologies trustworthy, transparent, and controllable by the people they affect. Our work spans both systems and human factors. On the consumer side, we led the design of the IoT Security and Privacy Label, studied how label complexity, the U.S. Cyber Trust Mark, and QR codes affect consumer comprehension and purchase decisions, and helped inform national IoT labeling efforts; this line of work was recognized with the Norm Hardy Prize from the Foresight Institute. For shared and always-on sensing, we explore mechanisms for transparency and control in smart homes, and ThingPoll, which lets the people sharing a space negotiate privacy settings together. For developers, we build tools such as Matcha and Honeysuckle that help create accurate privacy nutrition labels and in-app privacy notices. We also study the security of the broader device ecosystem, such as granular data ownership for IoT devices.

Projects

Survey responses on whether participants would use, find reliable, and trust devices with software, hardware, and jamming privacy features.
Ubicomp 2025
"I would still use it but I wouldn't trust it": Evaluating Mechanisms for Transparency and Control for Smart-Home Sensors

A 489-person survey of which smart-home privacy features, from mute buttons to microphone jammers, people actually trust and would use.

The Matcha plugin in Android Studio: detected data-access API calls, annotation quick-fixes, generated XML label specification, and a preview of the Google Play data safety label.
UbiComp 2024
Matcha: An IDE Plugin for Creating Accurate Privacy Nutrition Labels

An Android Studio plugin that uses code analysis to help developers create accurate Google Play data safety labels.

ThingPoll's negotiation workflow, from profile assignment through privacy queries and configuration suggestions, alongside screenshots of each step in the app.
CHI 2024
Bring Privacy To The Table: Interactive Negotiation for Privacy Settings of Shared Sensing Devices

A negotiation system that helps co-located people agree on privacy settings for shared IoT sensors, reaching agreement in 97.5% of scenarios.

The high-complexity Security & Privacy Facts label for a fictional smart thermostat, with the U.S. Cyber Trust Mark, sensor data practices, and a QR code.
CHI 2024
Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and Behavior

A 518-person survey comparing IoT labels of three complexity levels, finding most buyers ignore QR codes and prefer details on the package.

Frames from a video: smart thermostat boxes with security and privacy labels on a store shelf, a shopper scanning the QR code, and the detailed label on a phone.
CACM 2024
Internet of Things Security and Privacy Labels Should Empower Consumers

An argument, backed by a 518-person study, that IoT labels should print key security and privacy facts next to the QR code.

A multiple price list table asking participants to choose between discount coupons for a smart device with no security updates versus automatic security updates.
USENIX Security 2023
Are Consumers Willing to Pay for Security and Privacy of IoT Devices?

An incentive-compatible study of 180 people measuring how much more they will pay for IoT devices with better security and privacy.

An example website depending on DynDNS and Cloudflare for DNS and KeyCDN for content delivery.
PAM 2023
A First Look at Third-Party Service Dependencies of Web Services in Africa

A measurement study from four African vantage points finding that 93% of popular Africa-visited websites critically depend on a third-party DNS, CDN, or CA.

TEO workflow: an admin initializes a device, users claim ephemeral co-ownership, the device uploads encrypted data, and requesters must get every co-owner's approval.
MobiSys 2022
TEO: Ephemeral Ownership for IoT Devices to Provide Granular Data Control

Lets people near an IoT device temporarily claim co-ownership of its encrypted data, so no one can access it without their permission.

A HelloVisitor app manifest chains push, detect, select, and post operators so an in-home hub extracts faces from camera video and sends only cropped faces to the cloud.
Oakland S&P 2022
Peekaboo: A Hub-Based Approach to Enable Transparency in Data Processing within Smart Homes

An in-home hub that runs developer-declared chains of fixed operators to minimize smart home data before it leaves for the cloud.

PSA pipeline: smart apps are parsed into models, combined with device, environment, interaction, and intent models, and checked to produce counterexamples and safe configurations.
ICCPS 2022
Protecting Smart Homes from Unintended Application Actions

Models SmartThings apps as parameterized timed automata to find unsafe app interactions, uncovering 19 new violations across 86 apps.

Line chart of the cumulative share of U.S. App Store apps with a privacy label, rising from about 28% in April 2021 to 48% in November 2021.
CHI 2022
Understanding iOS Privacy Nutrition Labels: An Exploratory Large-Scale Analysis of App Store Data

Weekly snapshots of 1.4 million U.S. App Store apps show over half still lacked a privacy label months after Apple required one.

Example privacy nutrition labels: Apple's iOS App Privacy label on the left and Android's tentative Data privacy and security section on the right.
CHI 2022
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels

An observation and interview study of 12 iOS developers revealing common challenges in creating accurate Apple privacy nutrition labels.

Five-panel storyboard of the preferred Privacy Diagnostics concept, where an app scores a user's smart home privacy settings and guides fixes.
CHI 2022
Exploring the Needs of Users for Supporting Privacy-protective Behavior in Smart Homes

Two surveys of 386 people on how they protect privacy in smart homes, finding a privacy diagnostics app the most wanted tool.

The primary layer of the IoT security and privacy label for a smart video doorbell, listing security mechanisms, sensor data practices, and a QR code.
IEEE S&P 2022
An Informative Security and Privacy "Nutrition" Label for Internet of Things Devices

A two-layer IoT security and privacy label, designed with consumers and experts, that shows device data practices and protections before purchase.

Code annotations and XML configuration (top) that Honeysuckle turns into in-app privacy notices, from permission explanations to data use history and per-purpose settings.
Ubicomp 2021
Honeysuckle: Annotation-Guided Code Generation of In-App Privacy Notices

An Android IDE plugin, build plugin, and library that generate in-app privacy notices from code annotations, tested with 12 developers.

Capture architecture: each device's firmware and its hub-side driver use Capture libraries, sharing centrally updated security libraries such as OpenSSL under a hub monitor that enforces isolation.
USENIX Security 2021
Capture: Centralized Library Management for Heterogeneous IoT Devices

A local hub that hosts and updates third-party libraries like OpenSSL for many IoT devices, instead of baking them into vendor firmware.

Stacked bars showing how each IoT label attribute's most and least protective values shift participants' risk perception (a) and willingness to purchase (b).
Oakland S&P 2021
Which Privacy and Security Attributes Most Impact Consumers’ Risk Perception and Willingness to Purchase IoT Devices?

A 1,371-person survey measuring how each attribute on a proposed IoT privacy and security label shifts perceived risk and willingness to buy.

The three-step survey experiment: an app description with quiz questions, questions about install intention and perceptions of the app, then validated scales and demographics.
PMC 2021
What Makes People Install a COVID-19 Contact-Tracing App? Understanding the Influence of App Design and Individual Difference on Contact-Tracing App Adoption Intention

A 1,963-person U.S. survey experiment finding that individual differences matter more than app design for contact-tracing app adoption intention.

Three Android settings screens showing purpose-based policy cards for approximate location, with per-purpose Off/Ask/On sliders and per-app overrides.
arXiv 2021
The Design of the User Interfaces for Privacy Enhancements for Android

User interface designs for Android privacy settings built on developer-declared purposes, split between first-party and third-party data use.

Netter workflow: a Netter program and performance metrics are compiled to a Markov chain, which the Storm model checker analyzes against user-specified properties.
VMCAI 2021
Netter: Probabilistic, Stateful Network Models

A language for probabilistic, stateful network models that compiles to Markov chains to verify quantitative properties like latency and failure rates.

Life cycle of a web request: DNS lookup, TCP and SSL handshakes, OCSP certificate validation, and content fetched from the site's server, a CDN, and other content providers.
IMC 2020
Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident?

A measurement of Alexa top-100K websites showing 89% critically depend on third-party DNS, CDN, or certificate authority providers.

Primary layer of the prototype IoT privacy and security label for a smart security camera, listing security mechanisms, data practices, and a QR code to the detailed label.
Oakland S&P 2020
Ask The Experts: What Should Be On An IoT Privacy And Security Label?

A Delphi study with 22 experts and interviews with 15 consumers that produced a two-layer privacy and security label for IoT devices.

Coconut in Android Studio: a location annotation in code, a quick-fix suggesting coarse location, and a panel summarizing the app's personal data access.
Ubicomp 2019
Coconut: An IDE Plugin for Developing Privacy-friendly Apps

An Android Studio plugin that prompts developers to annotate personal data use and flags privacy issues with quick fixes as they code.

MobiPurpose workflow: an app's traffic request is parsed into key-value pairs, classified by data type, and combined with app, text, and domain features to rank likely purposes.
Ubicomp 2019
MobiPurpose: Inferring the Purposes of Network Traffic in Mobile Apps

A classifier that infers why an Android app sends data in each network request, reaching 84% average precision across 19 purposes.

Prototype Privacy & Security Facts label for a hypothetical security camera, listing collected data, retention, sharing, update policy, and privacy and security ratings.
CHI 2019
Exploring How Privacy and Security Factor into IoT Device Purchase Behavior

Interviews with 24 IoT device owners on whether privacy and security shaped their purchases, plus their reactions to a prototype privacy label.

Pipeline that learns notification templates and semantic rules offline, then turns on-device push notifications into knowledge triples such as <user, purchases, iPhone X>.
BigData 2018
Automated Extraction of Personal Knowledge from Smartphone Push Notifications

Mining templates from 120 million push notifications to automatically extract personal facts, such as names and purchases, without uploading personal data.

The life cycle of a web request, touching the DNS provider, the website's server, an OCSP certificate server, and possibly a CDN.
Computing Research Repository, June 2018
Oh, What a Fragile Web We Weave: Third-party Service Dependencies In Modern Webservices and Implications

A measurement of the top 100K websites showing how many critically depend on a few third-party DNS, CDN, and certificate providers.

PrivacyStreams architecture: providers convert raw sensor and system data into streams that transformations process and actions output to the app.
Ubicomp 2017
PrivacyStreams: Enabling Transparency in Personal Data Processing for Mobile Apps

An Android programming framework that processes personal data as streams, making the granularity of data an app actually uses easy to analyze.

Architecture of ProtectMyPrivacy for Android: an on-device service, firewall, and anonymizer built on Xposed that intercept app data accesses and sync decisions with a server.
Ubicomp 2017
Does This App Really Need My Location?: Context-Aware Privacy Management for Smartphones

ProtectMyPrivacy for Android controls private data access per third-party library, since 30 libraries cause over half of accesses; deployed to 1,321 users.

Users' phones upload private signatures of app traffic key-value pairs to the PrivacyProxy backend, which merges them and serves public signatures back to users.
Computing Research Repository, August 2017
PrivacyProxy: Leveraging Crowdsourcing and In Situ Traffic Analysis to Detect and Mitigate Information Leakage

Detects personal information leaked by smartphone apps by combining hashed traffic signatures crowdsourced from many users of the same app.

Static analysis pipeline: apps are decompiled, permission-related custom code is identified, features are extracted, and a classifier assigns one of ten location or ten contacts purposes.
ACM Trans. Inf. Syst. · 2017
Understanding the Purpose of Permission Use in Mobile Apps

Static and dynamic analysis of decompiled Android code that infers why apps use location and contacts permissions, for over 90% of uses.

Privacy assistant screens: a question asking whether travel apps may access location, then personalized recommendations to deny specific apps' location and calendar permissions.
Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)
Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions

A personalized privacy assistant that recommends Android permission settings from a few questions; 72 field-study users adopted 78.7% of its recommendations.

Four Fitbit privacy notice designs tested in the study: a table, a bulleted list with icons, a plain bulleted list, and an icon grid.
Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)
How Short Is Too Short? Implications of Length and Framing on the Effectiveness of Privacy Notices

Three online studies of fitness-wearable privacy notices finding that short notices inform users, but cutting expected practices can reduce awareness.

The GIoTTO open-source stack, layered from sensors and actuators through data integration, edge analytics, datastore, and analytics up to IoT apps and development environments.
IEEE Computer 2016: IEEE Computer Society.
Toward Building a Safe, Secure, and Easy-to-Use Internet of Things Infrastructure

An overview of GIoTTO, an open-source IoT infrastructure stack led by CMU, and the security, privacy, and usability challenges it targets.

IoTSec vision: a central control platform launches customized micro-boxes that tunnel and filter traffic for each IoT device, annotated with three challenges: policy, learning, and enforcement.
HotNets 2015: Fourteenth ACM Workshop on Hot Topics in Networks.
Handling a trillion (unfixable) flaws on a billion devices: Rethinking network security for the Internet-of-Things

A position paper arguing the network must secure unpatchable IoT devices, using per-device micro-middleboxes driven by context-aware, cross-device policies.

A privacy nudge telling the user their location was shared 5,398 times in 14 days, and a detail screen listing how often each app accessed it.
Conference on Human Factors in Computing Systems - Proceedings · 2015
Your location has been shared 5,398 times! A field study on mobile app privacy nudging

A field study showing that nudges reporting how often apps accessed personal data led 95% of participants to reassess their app permissions.

ProtectMyPrivacy architecture: iOS apps report private data accesses and user protection decisions to a server whose recommendation engine suggests settings to others.
MobiSys 2013 - Proceedings of the 11th Annual International Conference on Mobile Systems, Applications, and Services
ProtectMyPrivacy: Detecting and mitigating privacy leaks on iOS devices using crowdsourcing

An iOS tool that detects app access to private data and crowdsources protection decisions from 90,000+ users into per-app recommendations.

Long-running Projects

ProtectMyPrivacy
The ProtectMyPrivacy app tells users what information other apps are trying to access on iOS devices. It also makes recommendations about whether to allow or deny access.