"Privacy across the boundary": Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal Assistants
Authors
Paper Title
'Privacy across the boundary': Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal Assistants
Publication Info
- Topic area: Privacy risk perceptions in Smart Home Personal Assistants (SPAs) using Privacy Boundary Theory (PBT).
- Keywords: Privacy Boundary Theory, Smart Home Personal Assistants, data transmission, data sharing, privacy risk, user perception, anonymization, encryption, boundary regulation, privacy design.
Background and Problem
- Problem / challenge: Existing privacy models for SPAs are insufficient to address the nuanced, dynamic privacy management required as SPAs evolve into social agents. Prior work has focused on technical vulnerabilities or individual data flows but lacks a comprehensive framework for understanding user privacy perceptions in SPA ecosystems.
- Significance: SPAs are deeply integrated into users' daily lives, collecting sensitive data and interacting with third-party services. Understanding and addressing privacy risks is critical to fostering trust and ensuring user adoption.
- Motivation and related work: Previous research has explored technical vulnerabilities, privacy norms, and user concerns but has not adequately addressed the impact of boundary-related factors (e.g., data transmission and sharing ranges) on privacy perceptions. This paper builds on Privacy Boundary Theory to fill this gap.
Solution
- Proposed approach: The study applies Privacy Boundary Theory (PBT) to investigate how users perceive privacy risks in SPAs, focusing on two key boundary-related factors: transmission ranges (spatial boundaries) and sharing ranges (relational boundaries).
- Novelty:
- Extends PBT to the SPA context by empirically validating the "Home Network" and "Service Provider" as critical privacy boundaries.
- Quantitatively measures the effects of boundary crossings on perceived privacy risks across data types and demographics.
- Reveals the limited effectiveness of technical safeguards like encryption and anonymization in mitigating boundary-related risks.
- Proposes boundary-aware design implications for SPAs.
- Procedure and key techniques:
- Conducted a three-phase preliminary study to identify boundary-related factors, categorize SPA functions, and analyze commercial practices.
- Performed a mixed-methods study (N=412 survey, N=40 interviews) to assess perceived privacy risks across transmission and sharing ranges.
- Analyzed the influence of data attributes, user demographics, and technical safeguards on privacy risk perceptions.
Results
- Concrete findings:
- Perceived privacy risks escalate significantly when data crosses the "home network" boundary (transmission) or the "provider to third-party" boundary (sharing).
- Users view the home as a private sanctuary and third-party sharing as a breach of relational trust.
- Risk perception is modulated by data sensitivity, functional necessity, and user awareness.
- Technical safeguards like encryption and anonymization show limited effectiveness, particularly for third-party sharing.
- Advantage over baselines:
- Provides a structured, empirical framework for understanding privacy boundaries in SPAs, surpassing prior qualitative or narrowly scoped studies.
- Demonstrates consistent boundary effects across diverse data types and demographics.
- Experiments / evaluation:
- Surveyed 412 participants and conducted 40 follow-up interviews in China.
- Used statistical methods (Friedman tests, Kruskal-Wallis tests) and thematic analysis to evaluate privacy risk perceptions across transmission and sharing ranges.
- Examined the effectiveness of encryption and anonymization as mitigating factors.
- Limitations and future work:
- Cultural and regional focus on China may limit generalizability; future research should include cross-cultural studies.
- Relied on self-reported data, which may not fully capture actual behaviors (privacy paradox).
- Did not address multi-user dynamics or temporal shifts in privacy boundaries; future work should explore these dimensions.
Summary
This paper applies Privacy Boundary Theory to investigate how users perceive privacy risks in Smart Home Personal Assistants (SPAs). It identifies two critical boundaries—home network (spatial) and provider to third-party (relational)—where privacy risks escalate significantly. The study reveals that technical safeguards like encryption and anonymization are insufficient to mitigate these risks due to user distrust and boundary coordination failures. By empirically validating boundary effects across data types and demographics, the findings inform boundary-aware privacy design, including hierarchical visualizations and dynamic access controls. These insights are crucial for designing SPAs that respect user privacy expectations and foster trust.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 83%
Investigating Bystander Privacy in Chinese Smart Home Apps
CHI '26· Smart Home Privacy & Security +2
- 71%
VisGuardian: A Lightweight Group-based Visual Privacy Control Technique For Smart Glasses in Home Environments
CHI '26· Smart Home Privacy & Security +3
- 60%
Informing the Design of Privacy-Empowering Tools for the Connected Home
CHI '20· Privacy by Design & User Control +1
- 60%
Investigating Tangible Privacy-Preserving Mechanisms for Future Smart Homes
CHI '23· Privacy by Design & User Control +1
- 60%
Home Is Where the Smart Is: Development and Validation of the Cybersecurity Self-Efficacy in Smart Homes (CySESH) Scale
CHI '23· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)