Skip to main navigation Skip to search Skip to main content

Characterizing Security and Privacy Risks in Smart Home IoT Device Access Sharing

  • Yinxin Wan
  • , Ting Xu
  • , Tran Ngoc Bao Huynh
  • , Jun Dai
  • , Xiaoyan Sun
  • , Kuai Xu
  • , Guoliang Xue
  • University of Massachusetts Boston
  • Worcester Polytechnic Institute
  • Arizona State University

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Smart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats.

Original languageEnglish
Title of host publicationSenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026
PublisherAssociation for Computing Machinery, Inc
Pages1129-1136
Number of pages8
ISBN (Electronic)9798400723094
DOIs
StatePublished - May 10 2026
EventInternational Conference on Embedded Artificial Intelligence and Sensing Systems, SenSys 2026 - Saint Malo, France
Duration: May 11 2026May 14 2026

Publication series

NameSenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026

Conference

ConferenceInternational Conference on Embedded Artificial Intelligence and Sensing Systems, SenSys 2026
Country/TerritoryFrance
CitySaint Malo
Period5/11/265/14/26

ASJC Scopus Subject Areas

  • Artificial Intelligence
  • Software
  • Computer Networks and Communications
  • Signal Processing

Keywords

  • device access sharing
  • IoT security and privacy
  • sharing workflows
  • Smart home IoT
  • smart home security

Cite this