Alexa, Who Am I Speaking To?: Understanding Users’ Ability to Identify Third-Party Apps on Amazon Alexa

Alexa, Who Am I Speaking To?: Understanding Users’ Ability to Identify Third-Party Apps on Amazon Alexa
复制标题

DOI:
10.1145/3446389
复制
发表时间:
2019-10
期刊:
ACM Transactions on Internet Technology (TOIT)
影响因子:
--
通讯作者:
David J. Major;D. Huang;M. Chetty;N. Feamster
David J. Major;D. Huang;M. Chetty;N. Feamster
中科院分区:
其他
文献类型:
--
作者:
David J. Major;D. Huang;M. Chetty;N. Feamster

文献摘要

相似文献

许多事物设备具有最受欢迎的语音用户界面之一,是亚马逊的Alexa,它支持50,000多个第三方应用程序(“技能”)对237名参与者的调查发现,用户不了解技能通常是由第三方运营的,他们经常将第三方技能与本地人混淆Alexa的功能,他们不知道本机Alexa系统支持的功能,更频繁地与Alexa交互的用户更有可能包括第三方技能是本机的Alexa功能。安全性和隐私风险:攻击者可以开发第三方技能,而无需用户的知识或化妆作为本地Alexa功能,以减轻这种威胁。我们提出设计建议,以帮助用户更好地区分本地功能和第三方技能,包括本地和第三方环境的音频和视觉指标,以及一致的设计标准,以帮助用户了解Alexa上的功能是和不可能的。 。
Many Internet of Things devices have voice user interfaces. One of the most popular voice user interfaces is Amazon’s Alexa, which supports more than 50,000 third-party applications (“skills”). We study how Alexa’s integration of these skills may confuse users. Our survey of 237 participants found that users do not understand that skills are often operated by third parties, that they often confuse third-party skills with native Alexa functions, and that they are unaware of the functions that the native Alexa system supports. Surprisingly, users who interact with Alexa more frequently are more likely to conclude that a third-party skill is a native Alexa function. The potential for misunderstanding creates new security and privacy risks: attackers can develop third-party skills that operate without users’ knowledge or masquerade as native Alexa functions. To mitigate this threat, we make design recommendations to help users better distinguish native functionality and third-party skills, including audio and visual indicators of native and third-party contexts, as well as a consistent design standard to help users learn what functions are and are not possible on Alexa.