USENIX Security2023Top-tier venue
Hey Kimya, Is My Smart Speaker Spying on Me? Taking Control of Sensor Privacy Through Isolation and Amnesia
Piet De Vaere, Adrian Perrig
Abstract
Although smart speakers and other voice assistants are becoming increasingly ubiquitous, their always-standby nature continues to prompt significant privacy concerns. To address these, we propose KIMYA, a hardening framework that allows device vendors to provide strong data-privacy guarantees. Concretely, KIMYA guarantees that microphone data can only be used for local processing, and is immediately discarded unless a user-auditable notification is generated. KIMYA thus makes devices accountable for their data-retention behavior. Moreover, KIMYA is not limited to voice assistants, but is applicable to all devices with always-standby, event-triggered sensors. We implement KIMYA for ARM Cortex-M, and apply it to a wake-word detection engine. Our evaluation shows that KIMYA introduces low overhead, can be used in constrained environments, and does not require hardware modifications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 25b6c576-767f-40be-9bcb-99225462a124Cited by top-tier papers1
Ask how each one uses itBuilds on9
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato et al.USENIX Security 2016 · 296 citations
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- Owning and Sharing: Privacy Perceptions of Smart Speaker UsersNicole Meng, Dilara Keküllüoglu, Kami VanieaCSCW 2021 · 50 citations
- AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation BindingsGiuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags et al.USENIX Security 2017 · 35 citations
Related papers
- SafeSpeaker: Voice Obfuscation for Resource-Constrained IoT DevicesCameron Haire, Yasha Iravantchi, Kang G. Shin, Alanson P. SampleUbiComp 2026 · 1 citation
- Powering for Privacy: Improving User Trust in Smart Speaker Microphones with Intentional Powering and Perceptible AssuranceYoungwook Do, Nivedita Arora, Ali Mirzazadeh, Injoo Moon et al.USENIX Security 2023
- FakeWake: Understanding and Mitigating Fake Wake-up Words of Voice AssistantsYanjiao Chen, Yijie Bai, Richard Mitev, Kaibo Wang et al.CCS 2021 · 24 citations
- Investigating Users' Preferences and Expectations for Always-Listening Voice AssistantsMadiha Tabassum, Tomasz Kosinski, Alisa Frik, Nathan Malkin et al.UbiComp 2020 · 74 citations
- SILENCE: Protecting privacy in offloaded speech understanding on resource-constrained devicesDongqi Cai, Shangguang Wang, Zeling Zhang, Felix Xiaozhu Lin et al.NeurIPS 2024 · 2 citations
