VITAS : Guided Model-based VUI Testing of VPA Apps
Suwan Li, Lei Bu, Guangdong Bai, Zhixiu Guo, Kai Chen, Hanlin Wei
Abstract
Virtual personal assistant (VPA) services, e.g. Amazon Alexa and Google Assistant, are becoming increasingly popular recently. Users interact with them through voice-based apps, e.g. Amazon Alexa skills and Google Assistant actions. Unlike the desktop and mobile apps which have visible and intuitive graphical user interface (GUI) to facilitate interaction, VPA apps convey information purely verbally through the voice user interface (VUI), which is known to be limited in its invisibility, single mode and high demand of user attention. This may lead to various problems on the usability and correctness of VPA apps.
In this work, we propose a model-based framework named Vitas to handle VUI testing of VPA apps. Vitas interacts with the app VUI, and during the testing process, it retrieves semantic information from voice feedbacks by natural language processing. It incrementally constructs the finite state machine (FSM) model of the app with a weighted exploration strategy guided by key factors such as the coverage of app functionality. We conduct a large-scale testing on 41,581 VPA apps (i.e., skills) of Amazon Alexa, the most popular VPA service, and find that 51.29% of them have weaknesses. They largely suffer from problems such as unexpected exit/start, privacy violation and so on. Our work reveals the immaturity of the VUI designs and implementations in VPA apps, and sheds light on the improvement of several crucial aspects of VPA apps.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9c3e043d-ab42-4522-bf32-fe4faf087e0dCited by top-tier papers5
- Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesSong Liao, Mohammed Aldeen, Jingwen Yan, Long Cheng et al.WWW 2024 · 9 citations
- SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseSong Liao, Long Cheng, Haipeng Cai, Linke Guo et al.CCS 2023 · 7 citations
- End-Users Know Best: Identifying Undesired Behavior of Alexa Skills Through User Review AnalysisMohammed Aldeen, Jeffrey Young, Song Liao, Tsu-Yao Chang et al.UbiComp 2024 · 4 citations
- Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA AppFuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng et al.ICSE 2024 · 4 citations
- SKILLPoV: Towards Accessible and Effective Privacy Notice for Amazon Alexa SkillsJingwen Yan, Song Liao, Mohammed Aldeen, Luyi Xing et al.NDSS 2025
Builds on6
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant ApplicationsYangyong Zhang, Lei Xu, Abner Mendoza, Guangliang Yang et al.NDSS 2019 · 60 citations
- Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsLong Cheng, Christin Wilson, Song Liao, Jeffrey Young et al.CCS 2020 · 58 citations
- Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsFuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li et al.ASE 2022 · 31 citations
Related papers
- SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the WildJeffrey Young, Song Liao, Long Cheng, Hongxin Hu et al.USENIX Security 2022
- Sorry, I don't Understand: Improving Voice User Interface TestingEmanuela Guglielmi, Giovanni Rosa, Simone Scalabrino, Gabriele Bavota et al.ASE 2022 · 8 citations
- SkillExplorer: Understanding the Behavior of Skills in Large ScaleZhixiu Guo, Zijin Lin, Pan Li, Kai ChenUSENIX Security 2020
- Read Between the Lines: An Empirical Measurement of Sensitive Applications of Voice Personal Assistant SystemsFaysal Hossain Shezan, Hang Hu, Jiamin Wang, Gang Wang et al.WWW 2020 · 27 citations
- Voice App Developer Experiences with Alexa and Google Assistant: Juggling Risks, Liability, and SecurityWilliam Seymour, Noura Abdi, Kopo M. Ramokapane, Jide S. Edu et al.USENIX Security 2024 · 9 citations
