"Privacy across the boundary": Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal Assistants

Privacy by Design & User ControlSmart Home Privacy & SecurityUI/UX DesignersAI/ML Researchers & EngineersPrivacy Policy Makers

Paper Title

'Privacy across the boundary': Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal Assistants

Publication Info

  • Topic area: Privacy risk perceptions in Smart Home Personal Assistants (SPAs) using Privacy Boundary Theory (PBT).
  • Keywords: Privacy Boundary Theory, Smart Home Personal Assistants, data transmission, data sharing, privacy risk, user perception, anonymization, encryption, boundary regulation, privacy design.

Background and Problem

  • Problem / challenge: Existing privacy models for SPAs are insufficient to address the nuanced, dynamic privacy management required as SPAs evolve into social agents. Prior work has focused on technical vulnerabilities or individual data flows but lacks a comprehensive framework for understanding user privacy perceptions in SPA ecosystems.
  • Significance: SPAs are deeply integrated into users' daily lives, collecting sensitive data and interacting with third-party services. Understanding and addressing privacy risks is critical to fostering trust and ensuring user adoption.
  • Motivation and related work: Previous research has explored technical vulnerabilities, privacy norms, and user concerns but has not adequately addressed the impact of boundary-related factors (e.g., data transmission and sharing ranges) on privacy perceptions. This paper builds on Privacy Boundary Theory to fill this gap.

Solution

  • Proposed approach: The study applies Privacy Boundary Theory (PBT) to investigate how users perceive privacy risks in SPAs, focusing on two key boundary-related factors: transmission ranges (spatial boundaries) and sharing ranges (relational boundaries).
  • Novelty:
    1. Extends PBT to the SPA context by empirically validating the "Home Network" and "Service Provider" as critical privacy boundaries.
    2. Quantitatively measures the effects of boundary crossings on perceived privacy risks across data types and demographics.
    3. Reveals the limited effectiveness of technical safeguards like encryption and anonymization in mitigating boundary-related risks.
    4. Proposes boundary-aware design implications for SPAs.
  • Procedure and key techniques:
    1. Conducted a three-phase preliminary study to identify boundary-related factors, categorize SPA functions, and analyze commercial practices.
    2. Performed a mixed-methods study (N=412 survey, N=40 interviews) to assess perceived privacy risks across transmission and sharing ranges.
    3. Analyzed the influence of data attributes, user demographics, and technical safeguards on privacy risk perceptions.

Results

  • Concrete findings:
    • Perceived privacy risks escalate significantly when data crosses the "home network" boundary (transmission) or the "provider to third-party" boundary (sharing).
    • Users view the home as a private sanctuary and third-party sharing as a breach of relational trust.
    • Risk perception is modulated by data sensitivity, functional necessity, and user awareness.
    • Technical safeguards like encryption and anonymization show limited effectiveness, particularly for third-party sharing.
  • Advantage over baselines:
    • Provides a structured, empirical framework for understanding privacy boundaries in SPAs, surpassing prior qualitative or narrowly scoped studies.
    • Demonstrates consistent boundary effects across diverse data types and demographics.
  • Experiments / evaluation:
    • Surveyed 412 participants and conducted 40 follow-up interviews in China.
    • Used statistical methods (Friedman tests, Kruskal-Wallis tests) and thematic analysis to evaluate privacy risk perceptions across transmission and sharing ranges.
    • Examined the effectiveness of encryption and anonymization as mitigating factors.
  • Limitations and future work:
    • Cultural and regional focus on China may limit generalizability; future research should include cross-cultural studies.
    • Relied on self-reported data, which may not fully capture actual behaviors (privacy paradox).
    • Did not address multi-user dynamics or temporal shifts in privacy boundaries; future work should explore these dimensions.

Summary

This paper applies Privacy Boundary Theory to investigate how users perceive privacy risks in Smart Home Personal Assistants (SPAs). It identifies two critical boundaries—home network (spatial) and provider to third-party (relational)—where privacy risks escalate significantly. The study reveals that technical safeguards like encryption and anonymization are insufficient to mitigate these risks due to user distrust and boundary coordination failures. By empirically validating boundary effects across data types and demographics, the findings inform boundary-aware privacy design, including hierarchical visualizations and dynamic access controls. These insights are crucial for designing SPAs that respect user privacy expectations and foster trust.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/222582/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3790455
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
8 authors
sell
Subtopics
Privacy by Design & User Control, Smart Home Privacy & Security
work
Professions
UI/UX Designers, AI/ML Researchers & Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
5 related papers