Skip to content

Allen School Blog

Allen School professor Franziska Roesner receives SOUPS Impact Award for illuminating smart home users’ security and privacy concerns 


Man holding home model and software icons (temperature, sound, padlock, water, CCTV) controlling appliances smart home technology applications on smartphone screen.
Photo by Sompoch Sivakosit/Vecteezy

Today, more and more consumers are transforming their homes into smart homes decked out with Internet of Things (IoT) devices such as thermostats, lights and locks that can be activated with voice commands or maybe a quick hand clap. While security experts have since raised privacy risks and other vulnerabilities with IoT and smart homes, back in 2017, little research had gone into the security and privacy concerns of the end users who actually set up and interact with smart homes.

Through a series of interviews with smart home users, a team of researchers in the Allen School’s Security and Privacy Research Lab identified gaps in threat models stemming from issues such as a limited technical understanding of IoT devices. 

Portrait of Franziska Roesner
Franziska Roesner

In August, the team’s 2017 paper titled “End User Security & Privacy Concerns with Smart Homes” was recognized with the 2026 Symposium on Usable Privacy and Security (SOUPS) Impact Award at the SOUPS conference in Hanover, Germany. Presented every three years, the award highlights a highly-cited previous SOUPS paper “that has had a significant impact on usable security and privacy research and practice.”

“This paper was one of the first looks at end-user security and privacy perspectives on then-emerging smart home technologies, and it has been gratifying to see the amount of impact it has had within the human-centered computer security and privacy literature,” said Allen School professor and alum Franziska Roesner (Ph.D., ‘14), senior author of the paper and co-director of the Security and Privacy Research Lab. 

The team found that participants’ threat models often depended on the sophistication of their technical mental models. For example, participants with less sophisticated mental models could not identify smart-home specific vulnerabilities and tended to base their mitigation strategies on best practices from other technologies such as using strong passwords. Participants generally did not share the same concerns over smart home technologies as security experts, which included risks associated with malicious devices or company data collection. Participants indicated they were not concerned about those potential risks because they did not feel personally targeted and believed their existing mitigation strategies were sufficient.

Since the paper was published, smart homes have become even more prevalent. We hope our recommendations have helped designers build safer and more secure technologies that both technical and not as tech-savvy users can feel confident navigating.

Franziska RoesnerAllen School professor

Based on these findings, Roesner and her collaborators developed recommendations for designers to help users make more informed security decisions. Surfacing more information to users about what their devices are doing — by providing usable auditing features in the associated phone apps or physical indicators, for example — can help users improve their technology mental models. They also suggested that designers consider potential risks among users in the same home and ensure smart home platforms support multiple distinct user accounts. 

“Since the paper was published, smart homes have become even more prevalent. We hope our recommendations have helped designers build safer and more secure technologies that both technical and not as tech-savvy users can feel confident navigating,” added Roesner.

Additional authors include Allen School alum Eric Zeng (Ph.D., ‘22), now a postdoctoral fellow at Georgetown University, and former Allen School postdoc Shrirang Mare, now a faculty member at Western Washington University.

Read the full award-winning paper here.