The rapid growth of Internet of Things (IoT) devices in smart homes presents significant opportunities for enhanced convenience and automation but also introduces notable challenges, particularly in terms of security, privacy, and understandability for non-expert users. This paper presents SecureTAP, a conversational agent designed to assist users in creating and modifying trigger-action programming (TAP) automations in smart home environments. The system leverages GPT-4o's capabilities to identify potential security vulnerabilities and privacy concerns in automation rules, offering users proactive mitigation strategies. Through an iterative process of prompt engineering, we developed a system that analyses automations, identifies risks, and suggests safer configurations to safeguard user privacy and security in IoT smart spaces. A user study with 15 participants evaluated the effectiveness of SecureTAP in addressing security and privacy issues, as well as user trust in the assistant's recommendations. Results indicated that SecureTAP effectively simplified the automation process while raising users' awareness of potential security and privacy concerns.

SecureTAP: a conversational agent for secure and privacy-aware smart home automations

Di Serio A.
;
Gallo S.;Paterno' F.
2025

Abstract

The rapid growth of Internet of Things (IoT) devices in smart homes presents significant opportunities for enhanced convenience and automation but also introduces notable challenges, particularly in terms of security, privacy, and understandability for non-expert users. This paper presents SecureTAP, a conversational agent designed to assist users in creating and modifying trigger-action programming (TAP) automations in smart home environments. The system leverages GPT-4o's capabilities to identify potential security vulnerabilities and privacy concerns in automation rules, offering users proactive mitigation strategies. Through an iterative process of prompt engineering, we developed a system that analyses automations, identifies risks, and suggests safer configurations to safeguard user privacy and security in IoT smart spaces. A user study with 15 participants evaluated the effectiveness of SecureTAP in addressing security and privacy issues, as well as user trust in the assistant's recommendations. Results indicated that SecureTAP effectively simplified the automation process while raising users' awareness of potential security and privacy concerns.
2025
Istituto di Scienza e Tecnologie dell'Informazione "Alessandro Faedo" - ISTI
979-8-4007-2102-1
Internet of Things, Conversational Interfaces, Trigger-Action Automations, Security and Privacy
File in questo prodotto:
File Dimensione Formato  
Di Serio-Gallo-Paternò_CHI 2025.pdf

accesso aperto

Descrizione: SecureTAP: A Conversational Agent for Secure and Privacy-Aware Smart Home Automations
Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 469.02 kB
Formato Adobe PDF
469.02 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/555190
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact