{"id":"https://openalex.org/W4408216059","doi":"https://doi.org/10.56553/popets-2025-0084","title":"Why Am I Seeing Double? An Investigation of Device Management Flaws in Voice Assistant Platforms","display_name":"Why Am I Seeing Double? An Investigation of Device Management Flaws in Voice Assistant Platforms","publication_year":2025,"publication_date":"2025-03-07","ids":{"openalex":"https://openalex.org/W4408216059","doi":"https://doi.org/10.56553/popets-2025-0084"},"language":"en","primary_location":{"id":"doi:10.56553/popets-2025-0084","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2025-0084","pdf_url":"https://petsymposium.org/popets/2025/popets-2025-0084.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://petsymposium.org/popets/2025/popets-2025-0084.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5006395041","display_name":"Muslum Ozgur Ozmen","orcid":"https://orcid.org/0000-0002-5696-8964"},"institutions":[{"id":"https://openalex.org/I55732556","display_name":"Arizona State University","ror":"https://ror.org/03efmqc40","country_code":"US","type":"education","lineage":["https://openalex.org/I55732556"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muslum Ozgur Ozmen","raw_affiliation_strings":["Arizona State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Arizona State University","institution_ids":["https://openalex.org/I55732556"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116549188","display_name":"Mehmet Oguz Sakaoglu","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mehmet Oguz Sakaoglu","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116549189","display_name":"Jackson Bizjak","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jackson Bizjak","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101102768","display_name":"Jianliang Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I18014758","display_name":"Simon Fraser University","ror":"https://ror.org/0213rcc28","country_code":"CA","type":"education","lineage":["https://openalex.org/I18014758"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Jianliang Wu","raw_affiliation_strings":["Simon Fraser University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Simon Fraser University","institution_ids":["https://openalex.org/I18014758"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028194244","display_name":"Antonio Bianchi","orcid":"https://orcid.org/0000-0002-2862-5286"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Antonio Bianchi","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015662045","display_name":"Dave Tian","orcid":"https://orcid.org/0000-0002-7506-9593"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dave (Jing) Tian","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":null,"display_name":"Z. Berkay Celik","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Z. Berkay Celik","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.01517525,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"2025","issue":"2","first_page":"719","last_page":"733"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12128","display_name":"AI in Service Interactions","score":0.9397000074386597,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12128","display_name":"AI in Service Interactions","score":0.9397000074386597,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12501","display_name":"Digital Economy and Work Transformation","score":0.9193000197410583,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.38436296582221985},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.322539746761322}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.38436296582221985},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.322539746761322}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.56553/popets-2025-0084","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2025-0084","pdf_url":"https://petsymposium.org/popets/2025/popets-2025-0084.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.56553/popets-2025-0084","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2025-0084","pdf_url":"https://petsymposium.org/popets/2025/popets-2025-0084.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1194779482","display_name":"CAREER: A Model-Guided and Holistic Approach for Peripheral Security","funder_award_id":"2145744","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5925140207","display_name":null,"funder_award_id":"CNS-2145744","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8411576471","display_name":"CAREER: Compositional IoT Safety and Security in Physical Spaces","funder_award_id":"2144645","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4408216059.pdf","grobid_xml":"https://content.openalex.org/works/W4408216059.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"In":[0,85],"Voice":[1],"Assistant":[2],"(VA)":[3],"platforms,":[4,40],"when":[5],"users":[6,235],"add":[7],"devices":[8],"to":[9,114,153,192,216],"their":[10,238],"accounts":[11],"and":[12,25,47,67,74,122,136,142,159,204,207,240],"give":[13],"voice":[14,65,151],"commands,":[15],"complex":[16],"interactions":[17,29],"occur":[18],"between":[19],"the":[20,33,51,72,95,154,165,174,183,242,245],"devices,":[21,239],"skills,":[22],"VA":[23,39,60,99,106,116,121,129,144,178,194,246],"clouds,":[24],"vendor":[26],"clouds.":[27],"These":[28],"are":[30],"governed":[31],"by":[32],"device":[34,44,78,100,195,232],"management":[35,79,101,196],"capabilities":[36],"(DMC)":[37],"of":[38,77,98,177,186],"which":[41],"rely":[42],"on":[43,201,230,244],"names,":[45,132],"types,":[46,133],"associated":[48],"skills":[49,224],"in":[50,58,138],"user":[52],"account.":[53],"Prior":[54],"work":[55],"studied":[56],"vulnerabilities":[57],"specific":[59],"components,":[61],"such":[62],"as":[63],"hidden":[64],"commands":[66,152],"bypassing":[68],"skill":[69,123],"vetting.":[70],"However,":[71],"security":[73,170],"privacy":[75],"implications":[76],"flaws":[80,211],"have":[81],"largely":[82],"been":[83],"unexplored.":[84],"this":[86],"paper,":[87],"we":[88],"introduce":[89,105],"DMC-Xplorer,":[90],"a":[91,110,139],"testing":[92],"framework":[93],"for":[94,118],"automated":[96],"discovery":[97],"flaws.":[102,197],"We":[103,198,220],"first":[104],"description":[107],"language":[108,113],"(VDL),":[109],"new":[111],"domain-specific":[112],"create":[115],"environments":[117,145],"testing,":[119],"using":[120],"developer":[124,157],"APIs.":[125],"DMC-Xplorer":[126,181,200],"then":[127],"selects":[128],"parameters":[130],"(device":[131],"vendors,":[134],"actions,":[135],"skills)":[137],"combinatorial":[140],"approach":[141],"creates":[143],"with":[146,225],"VDL.":[147],"It":[148,163],"issues":[149],"real":[150],"environment":[155],"via":[156],"APIs":[158],"logs":[160],"event":[161],"traces.":[162],"validates":[164],"traces":[166],"against":[167],"three":[168],"formal":[169],"properties":[171],"that":[172,212,222],"define":[173],"secure":[175],"operation":[176],"platforms.":[179],"Lastly,":[180],"identifies":[182],"root":[184],"cause":[185],"property":[187],"violations":[188],"through":[189],"intervention":[190],"analysis":[191],"identify":[193],"exercised":[199],"Amazon":[202],"Alexa":[203],"Google":[205],"Home":[206],"discovered":[208],"two":[209],"design":[210],"can":[213,228],"be":[214],"exploited":[215],"launch":[217],"four":[218],"attacks.":[219],"show":[221],"malicious":[223],"default":[226],"permissions":[227],"eavesdrop":[229],"privacy-sensitive":[231],"states,":[233],"prevent":[234],"from":[236],"controlling":[237],"disrupt":[241],"services":[243],"cloud.":[247]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
