Pith. sign in

REVIEW 3 cited by

Spying on the Smart Home: Privacy Attacks and Defenses on Encrypted IoT Traffic

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1708.05044 v1 pith:HKLX4OZW submitted 2017-08-16 cs.CR

classification cs.CR
keywords smarthomedevicesprivacyactivitiestrafficinternetmany
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The growing market for smart home IoT devices promises new conveniences for consumers while presenting new challenges for preserving privacy within the home. Many smart home devices have always-on sensors that capture users' offline activities in their living spaces and transmit information about these activities on the Internet. In this paper, we demonstrate that an ISP or other network observer can infer privacy sensitive in-home activities by analyzing Internet traffic from smart homes containing commercially-available IoT devices even when the devices use encryption. We evaluate several strategies for mitigating the privacy risks associated with smart home device traffic, including blocking, tunneling, and rate-shaping. Our experiments show that traffic shaping can effectively and practically mitigate many privacy risks associated with smart home IoT devices. We find that 40KB/s extra bandwidth usage is enough to protect user activities from a passive network adversary. This bandwidth cost is well within the Internet speed limits and data caps for many smart homes.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT Traffic with Neural Networks

    cs.CR 2019-08 conditional novelty 6.0 of 10

    LSTM models can identify IoT device types from packet sizes and timing with 81-99% accuracy even when traffic is merged by NAT or VPN.

  2. The House That Knows You: User Authentication Based on IoT Data

    cs.CR 2019-08 conditional novelty 5.0 of 10

    A gradient-boosting ensemble using aggregated HTTPS header features from 15 IoT devices classifies five lab users with 0.97 F1 when both models agree.

  3. Hiding in Plain Sight: An IoT Traffic Camouflage Framework for Enhanced Privacy

    cs.CR 2025-01 reject novelty 3.0 of 10

    A Raspberry Pi-based framework applies six known packet obfuscation techniques to IoT traffic and reports large drops in classifier accuracy, but the multi-technique combination and adaptive robustness claims are not ...

Pith tools