<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>The Italian Conference on CyberSecurity, May</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>User Perception of Risks Associated with IFT T T Applets: A Preliminary User Study</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Bernardo Breve</string-name>
          <email>bbreve@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gaetano Cimino</string-name>
          <email>gcimino@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vincenzo Deufemia</string-name>
          <email>deufemia@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Annunziata Elefante</string-name>
          <email>anelefante@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science, University of Salerno</institution>
          ,
          <addr-line>Fisciano</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <volume>0</volume>
      <fpage>3</fpage>
      <lpage>05</lpage>
      <abstract>
        <p>Trigger-Action Platforms (TAPs) enable users to define rules that trigger device operations automatically. However, the execution of these rules can potentially create security risks for users. This paper presents a user study conducted to assess the validity of a classification model, which used Natural Language Processing (NLP) techniques to automatically classify Event-Condition-Action (ECA) rules according to security and privacy risks in TAPs, e.g., IFTTT. The study asked each user to evaluate 50 diferent IFTTT rules, named applets, classified as risky by the proposed model and provide answers to two specific questions designed to assess risk perception. The results confirmed that the proposed classification model ofers an assessment of the risk associated with a rule in line with user opinion. Furthermore, highlighting the presence of security or privacy-related risk positively impacted users' willingness to avoid using risky applets.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Usable Security and Privacy</kwd>
        <kwd>Trigger-Action Platforms</kwd>
        <kwd>Internet of Things</kwd>
        <kwd>User Perception</kwd>
        <kwd>Human issues and awareness</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The vast spread of the Internet of Things (IoT) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] has revolutionized the way we live our daily
lives, turning home appliances, speakers, thermostats, and other devices into their smart variants,
equipped with an Internet connection that enables them to collect and share information with
other devices, leading the creation of factual ecosystems [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. In an efort to enable all categories
of users, including those with no technical knowledge, to take full advantage of the use of
IoT devices, a number of platforms have emerged in recent years that make it easy for users
to configure smart devices and define automation [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]. The use of these platforms, named
Trigger-Action Platforms (TAPs), allows the definition of interoperability behaviors between
IoT devices through the creation of simple rules based on the Event-Condition Action (ECA)
paradigm [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], i.e., specifying the event that triggers the automatism when a certain condition
is met and the subsequent action that will be taken. Among TAPs, If-This-Then-That (IFTTT)
afirmed itself in the last years as one of the most used ones, mainly thanks to the vast catalog
of rules (a.k.a. applets) that are available to the users and also for the considerable amount of
services and devices that IFTTT supports.
      </p>
      <p>
        Unfortunately, the IoT domain as well as technology in general can be characterized by several
vulnerabilities which, if exploited by malicious individuals, can cause serious risks to the security
of the IoT ecosystem and the privacy of users interacting with it [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]. Sometimes, it may be
the user who, inexperienced on security and privacy topics, introduces vulnerabilities himself
through ECA rules [
        <xref ref-type="bibr" rid="ref8 ref9">8, 9</xref>
        ]. For instance, the rule in Figure 1 allows the user to automatically
tweets anytime s/he enters a certain area. The user can decide to use this rule to notify his/her
followers that s/he just arrived at the gym. However, this rule could pose an important security
risk, as thieves can gain awareness concerning the users’ absence by monitoring his/her routine
through the tweets, helping them plan a break-in.
      </p>
      <sec id="sec-1-1">
        <title>Trigger</title>
        <sec id="sec-1-1-1">
          <title>You enter an area</title>
        </sec>
      </sec>
      <sec id="sec-1-2">
        <title>Action</title>
        <sec id="sec-1-2-1">
          <title>Post a new tweet</title>
          <p>
            In a previous publication, we addressed the problem of identifying security and privacy risks
underlying the definition of ECA rules [
            <xref ref-type="bibr" rid="ref10">10</xref>
            ]. In particular, we proposed the application of Natural
Language Processing (NLP) techniques to automatically classify ECA rules according to security
and privacy risks. The application of NLP techniques allowed us to semantically analyze the
triggers, actions, and natural language textual descriptions provided by the rule. The best model
we considered, based on the Bidirectional Encoder Representations from Transformers (BERT)
by Google achieved very high accuracy scores, with an average of 88%.
          </p>
          <p>
            In addition to the empirical evaluations we have already conducted, we sought to ascertain
whether the risks we identified could also be recognized and confirmed by the end-users who
are the primary audience for our initial proposal. Thus, in this paper, we present a user study
involving a group of 30 individuals. Specifically, we asked each user to evaluate 50 diferent
IFTTT applets classified by our model proposed in [
            <xref ref-type="bibr" rid="ref10">10</xref>
            ]. For each applet, the user was asked to
provide the answer to two specific questions designed to assess risk perception in view of the
classification performed. The collected responses served a dual purpose of evaluating users’
perception of the identified risk type as plausible and examining if reporting the risk could
influence their decision to use or avoid the risky applets. The study findings were consistent
with the empirical evaluations, indicating that our classification model accurately assesses
applet-associated risks according to user perspectives. Moreover, bringing attention to potential
security or privacy risks had a positive efect on users’ willingness to avoid using unsafe applets.
          </p>
          <p>The rest of the paper is organized as follows: Section 2 presents the main studies published in
the literature assessing users’ perceptions regarding security and privacy risks in IoT
environments. Section 3 briefly summarizes the contribution related to the definition of the BERT-based
classification model for identifying risks related to ECA rules. Section 4 presents the user study,
discussing the evaluation setup and the obtained results. Finally, in Section 5, conclusions and
planned future developments are drawn.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>
        The interaction with TAPs can sometimes pose serious risks both for the privacy of the user
and/or the security of the smart environment [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. In fact, rules created through such platforms
define automatisms hiding unexpected behaviors that may go unnoticed by users. This becomes
particularly evident if we consider the lack of technical knowledge the end-users have [
        <xref ref-type="bibr" rid="ref11 ref7">7, 11</xref>
        ].
      </p>
      <p>
        The perception of users with respect to the privacy and security risks arising from rules
defined through TAPs is a crucial aspect that needs to be considered. Various studies have
been conducted to investigate this topic, aiming to understand how users perceive the potential
risks of granting third-party access to their personal data and devices, as well as the measures
they take to protect their privacy and security. Saeidi et al. conducted a study to investigate
the implicit risks of using trigger-action platforms such as IFTTT in connecting smart-home
devices and services [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. They surveyed 386 participants on 49 smart-home IFTTT applets
using a Mechanical Turk survey and found that users were generally not very concerned about
using the rules, with the lowest level of concern being the most frequently selected answer.
The study also identified the types of rules that elicited more concerns from users, which were
those that involved acquiring, processing, or sharing location data. The authors suggest that
nudging participants to think about diferent usage contexts led them to raise their concern
scores. The study presented in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] aimed to investigate the rationales behind smart home device
purchases, homeowners’ perceptions of privacy risks, and the measures taken to protect privacy
from external entities such as device manufacturers, governments, Internet Service Providers,
and advertisers. The study involved 11 semi-structured interviews with smart homeowners,
and the analysis identified recurring themes. First, users’ preferences for convenience and
connectedness influenced their privacy-related behaviors in dealing with external entities.
Second, users’ opinions about external entities collecting smart home data were based on the
perceived benefits of these entities. Third, users trusted IoT device manufacturers to protect
their privacy but did not verify the implementation of such safeguards. Finally, users were
unaware of the privacy risks from inference algorithms operating on data from non-audio/visual
devices. The study’s results suggest recommendations for device designers, researchers, and
industry standards to match device privacy features with the expectations and preferences of
smart homeowners. In [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], the authors analyzed 732 applets installed by 28 participants and
their responses to survey questions to study the risks of real-world use of IFTTT. The study
found that although public applets on IFTTT present a potential attack vector, most participants
preferred creating their own applets. While participants did not express significant concerns
about security and privacy risks from their use of IFTTT, they were aware of the possibility of
such risks. Additionally, four participants reported experiencing applet-related harms or applets
that did not function as expected. Overall, participants stressed the importance of security
and privacy for their applets, and expressed concerns about applets triggering unintentionally,
posting private information, spreading malware, or damaging smart-home devices.
      </p>
      <p>
        The results suggest that TAPs should ofer support to end-users in efectively managing and
comprehending the security and privacy risks associated with creating trigger-action rules. To
address this issue, specific eforts have been dedicated to developing ad-hoc solutions that enable
end-users to identify and mitigate these risks [
        <xref ref-type="bibr" rid="ref10 ref13">10, 13</xref>
        ]. Moreover, it is crucial to ensure that users
can fully comprehend the identified risks in order to make informed decisions. Consequently,
various studies have proposed approaches for generating explanations that describe the causes
of system instability [
        <xref ref-type="bibr" rid="ref14 ref15">14, 15</xref>
        ]. Such explanations aim to provide a clear and understandable
account of the underlying technical concepts, as well as the potential consequences of certain
trigger-action rules. These explanations may also help users to understand the trade-ofs
between privacy and functionality, and to make more informed decisions about whether or
not to grant access to their personal data and devices. However, further research is needed to
evaluate the efectiveness of these approaches, and to determine how they can be integrated
into existing trigger-action programming tools.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology</title>
      <p>This section presents a comprehensive description of the sequential steps undertaken to produce
a fully labeled dataset that encompasses ECA rules, followed by the process of training and
evaluating a classification model that targets the identification of harmful rules. The proposed
methodology was applied to a case study concerning the IFTTT platform.
3.1. System Overview
There are three fundamental phases involved in the process of constructing a classifier to
identify harmful ECA rules:
• The first phase, named “ Data Labeling”, is designed to create labeled datasets for
classification models. This is accomplished by defining the possible classes of risk for ECA rules,
and their corresponding labels. Each ECA rule in the input dataset is then annotated with
a suitable label using a semi-automatic labeling strategy that partitions the dataset into
a small manually labeled subset and a larger subset that is automatically labeled using
semi-supervised classification models.
• The second phase, named “Model Training”, focuses on training the classification models
using the labeled ECA rules dataset. NLP techniques are used to extract semantic
information from the textual components of the ECA rules, and a weighted loss function is
applied to deal with the imbalanced nature of the training set.
• The last phase, named “Model testing”, involves evaluating the performance of the
classiifcation models by inputting a set of manually labeled ECA rules and measuring their
precision, recall, F1-score, and accuracy.
3.2. Data Labeling
This section introduces the dataset employed in training the classifier for identifying harmful
applets and the process by which the applets were labeled. The applet labeling process comprised
a dual approach of manual and automatic labeling, involving semi-supervised models and an
ensemble strategy.</p>
      <p>
        IFTTT Applet Dataset. The study was based on the dataset proposed by Mi et al. [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. It was
generated by researchers from Indiana University Bloomington, who conducted a web crawl of
the IFTTT.com site over a period of six months, from November 2016 to May 2017. During this
time, they collected a “snapshot” of the available applets each week, resulting in a dataset of
over 300,000 unique applets, which totaled approximately 200 GB of data. The dataset contains
essential information, including the applet name, description, trigger, trigger channel, action,
action channel, and the number of users who have installed each applet.
      </p>
      <p>
        The dataset underwent a data cleaning process to obtain a uniform dataset in language, and
the langdetect Python library was used to filter out applets not written in English. Applets
without a name or description, or containing only numbers for these features, were discarded.
After the data cleaning process, the resulting dataset contained 116,825 applets.
Categorization of IFTTT Applets According to Security and Privacy Risks. To
categorize the potential damages that could be inflicted by an applet on the user, we referred to the
work presented in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], where potential damages were classified into four macro-categories.
The first category, referred to as Innocuous, comprises applets that do not pose any harm or
risks. The second category, labeled as Personal, includes applets that may result in the loss or
compromise of sensitive data, which is solely due to the user’s behavior. The third category,
named Physical, involves applets that may cause physical harm or damage to goods, and the
harm is external, i.e., inflicted by third parties. The fourth category, denoted as Cybersecurity,
encompasses applets that may disrupt online services or distribute malware, and the harm is
external as well.
      </p>
      <p>We used the following classes for applet labeling, based on the considered macro-categories
of risk: class 0 corresponds to Innocuous applets, class 1 to Personal damages, class 2 to Physical
damages, and class 3 to Cybersecurity damages.</p>
      <p>Manual Applet Labeling. The process of manually labeling the IFTTT dataset involved
applying the majority method, whereby the first and second authors were responsible for the
labeling process, and the third author mediated in cases of disagreement. This approach resulted
in the labeling of 1,000 applets.</p>
      <p>To increase the number of labeled applets, we developed a process for selecting additional
applets to be manually labeled. This process involved creating a spreadsheet for each labeled
applet, and sorting all unlabeled applets by their similarity to the labeled applet, using a
combination of vector semantics and similarity functions. Specifically, we used SentenceBERT
[18] to compute sentence embeddings for each applet and cosine similarity to compare the
embeddings. We then manually reviewed each spreadsheet to identify and label applets that
exhibited similar characteristics to those previously labeled, but difered in the triggers, actions,
and/or channels involved. This process resulted in an augmented dataset consisting of 2,473
labeled applets.</p>
      <p>Automatic Applet Labeling. After the manual labeling process, we developed a methodology
that combines various semi-supervised learning models with an ensemble strategy. We utilized
three distinct semi-supervised learning techniques, namely Self Learning [19], Label Propagation
[20], and Generative Adversarial Learning [21]. Self Learning is a semi-supervised learning
technique that uses a combination of labeled and unlabeled applets to train a model. This
technique involves making predictions on unlabeled applets and treating those predictions as
additional labeled applets to augment the existing labeled set. In contrast, Label Propagation
propagates labels from a small set of labeled applets to a larger set of unlabeled applets. This is
achieved by constructing a graph where the applets represent the nodes and the edges represent
their similarity. Finally, Generative Adversarial Learning uses a generative model to generate
synthetic applets similar to real ones and a discriminative model that learns to distinguish
between them.</p>
      <p>To obtain a single dataset from the three labeled applet datasets generated by the
semisupervised learning models, we employed an ensemble strategy. It consisted of a majority-vote
scheme among the three semi-supervised models, in which applets were considered for inclusion
in the final dataset with their respective class labels only if at least two models produced the
same prediction. This approach provided us with more consistent labels for the evaluated
applets.
3.3. Model Training
The dataset we constructed was characterized by an imbalance in the number of applets across
classes, which poses a challenge in supervised classification [ 22]. In such scenarios, models
trained on imbalanced data tend to classify input samples based on the majority class. To
overcome this issue, we employed a weighted loss function that assigns diferent weights to
each class based on the number of applets in the class. Notably, we assigned the minimum
weight to class 0, which had the highest number of applets in the dataset.</p>
      <p>We developed a BERT-based classifier to identify harmful applets by using applet information
as textual features. The BertForSequenceClassification class of the transformers
Python library was employed for training the classifier. This class corresponds to the BERT
model with a single linear layer added for classification. We used the “ bert-base-uncased” model,
which is the base version of BERT with 12 transformer blocks, 768 hidden units, 12 self-attention
heads, and lowercase letters.
3.4. Model testing
We conducted a series of experiments aimed at evaluating the efectiveness of the BERT-based
model in classifying the diferent types of applet damage. To this end, a training dataset of 76,741
applets was assembled by employing the ensemble strategy combining the three sets of labeled
applets generated with the semi-supervised learning models. The eficacy of the proposed
approach and the quality of the labels produced by the ensemble strategy were validated by
evaluating the model’s performance on a test set comprising 2,473 manually labeled applets.</p>
      <p>Table 1 reports the values of accuracy, precision, recall, and F1-score achieved by the BERT
model. Notably, the model attained a weighted average score of 88% across all metrics. Analysis
of the results by class reveals that identifying class 1 applets is the most challenging task for the
model. This dificulty arises from the slight diferences in the context of rule execution that can
cause errors by classifying class 1 applets as class 2 or 3. To illustrate, consider the applet “Any
new photo by me uploaded in a specific Google Drive folder, publish it
on Twitter”. This applet falls under class 1 since it can lead to the unintentional sharing of
sensitive or embarrassing photos. On the other hand, the applet “Any new photo uploaded
by anyone in a specific Google Drive folder, publish it on Twitter” should
be classified as class 3 due to the potential privacy risk of publishing a photo on the user’s
Twitter profile without their knowledge of who uploaded it. Similarly, the applet “ New tweet
by me with a specific hashtag, turn off lights” may be employed by a user to
turn of lights with a goodnight tweet, but it can also trigger unintentionally in inappropriate
situations, making it a class 1 applet. On the other hand, the applet “New tweet by anyone
in the area with a specific tag, turn on lights” enables a user to determine if
there are people who published a tweet in the zone, but its behavior may be jeopardized by
third parties causing damage to the lights, making it a class 2 applet. These applets have subtle
diferences that make it challenging to classify class 1 applets compared to the other classes,
which explains the lower performance of the model in this regard.</p>
    </sec>
    <sec id="sec-4">
      <title>4. User study</title>
      <p>
        This section describes the study we conducted to evaluate the user’s perception of security
and privacy issues related to IFTTT applets. In particular, we examined whether users are
able to perceive the potential risks identified by the proposed BERT model as actual risks, and
then evaluated whether such perception could potentially influence their decision to enable the
corresponding applets. The research aimed to answer two questions, which were investigated
through our experimental evaluation:
• RQ1. “Do users acknowledge the classification made by our model as an actual risk?”
• RQ2. “Can the identified risks impact on users’ decision to activate the applet?”
To answer the two research questions, we recruited 30 volunteers (12 females) and designed
a dedicated platform in charge of randomly selecting 50 IFTTT applets, contained within the
dataset we released in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Out of the applets selected for each test, 40 were belonging to
one of three risk classes, Personal, Physical, or Cybersecurity, while the remaining 10 applets
had been classified as Harmless. This distribution of applets had two advantages: firstly, it
served as a control to prevent any pattern in user responses by randomly presenting 50 applets,
some harmless and some harmful. Secondly, for harmless applets, open-ended responses were
recorded on whether there was a discrepancy between the user’s evaluation and the model’s
one, i.e., when the user interprets an applet as harmful but the model did not. The participants
were selected from a mixed pool of users, consisting of individuals pursuing bachelor’s and
master’s degrees in computer science as well as those from other academic disciplines, with a
mean age of 28 years. Figure 2 shows an example of how applets are presented to the users and
the related questions asked to them. Each applet was presented to the participants in terms of
its title, description, trigger, and action components. Initially, the box describing the identified
risk (b) for a certain applet is hidden from the user, as well as the second question (c), while the
only operation a participant could perform is answering the first question (a). Once the users
answer the first question, blocks (b) and (c) appear, and users are asked to confirm whether
they would activate the applet in view of the identified risk. The evaluation process lasted on
average 20 minutes per user.
      </p>
      <p>34
26
14
6
12
28
16
24</p>
      <p>To avoid answers that were biased over personal considerations outside the scope of our
evaluation, we made it clear to the users to provide their answers only according to the risk and
not to their personal needs. This is to avoid, for example, that the applet having the description
“Turn off my Philips Hue light anytime I leave the apartment” would not be
activated by a user, not because of the risk it implies, but because such a user did not have a
Philips Hue light.</p>
      <p>Figure 3 shows the results obtained from the user study, considering only the 40 risky
applets presented to each user. Arranged on the x-axis are the 30 users who were involved in
the experiment, while the y-axis collects the number of responses received for both the first
question, the one about risk perception, and the second question, the one that asked about the
user’s confirmation to activate the applets.</p>
      <p>In detail, the top part of the plot compares the responses obtained from the first question.
While the left bar (the one in the light purple) shows the number of negative responses, i.e., the
number of times in the user’s opinion the applet presented did not pose a security or privacy
risk. On the other hand, the bar on the right of each user shows the number of times a given
user considered the type of risk identified by the model to be likely.</p>
      <p>As for the lower part of the plot, the number of responses regarding the second question is
reported. In this case, the left bar (the one in the dark purple) reports the number of times that,
at the expense of the highlighted risk, the user would still decide to activate such an applet in
their smart environment. Accordingly, the right bar highlights the number of times when the
presence of an identified security or privacy risk leads the user to decide to avoid activating
such an applet.</p>
      <p>The results obtained are very promising and indicative. In fact, even at first glance, it can be
seen that the number of times the risk identified by our model was deemed likely is very high,
with an average of 34.7 out of 40. For many users (U3, U4, U5, U17, U21, U25), the totality of the
applets they were asked to evaluate had security and privacy risks that conformed with what the
model highlighted. In a few cases (U2, U13, U18, U28) it happened that the risk was highly not
recognized by the participants, resulting in more than 10 negative responses. When questioned
about the reason for such a high number of unrecognized risks, all of the above-mentioned
users gave the same answer, namely that in their opinion the highlighted risk was related to
scenarios so remote as to be almost unrealistic, reasoning that such applets would never come
to pose any security or privacy risk.</p>
      <p>Regarding the users’ responses on whether they planned to activate the applets, this study
revealed some variability in the responses, in fact it was observed that none of the users chose
to refrain from activating all 40 applets that were presented for evaluation. It is worth noting,
however, that even for this type of evaluation, users almost always opted not to activate the
applets highlighted as risky. The only exception is user U21, for whom the number of applets
he would not activate (15), turns out to be lower than the number of applets he would activate
anyway (25). This result is even more surprising in light of the fact that U21 belongs to that
group of users who instead indicated that all the applets that were submitted to him were likely
to be risky. When questioned about this ambivalence in the answers, the participant responded
as follows: “I agree that all applets are in some way risky, however, in my opinion, having them
available would still be convenient. But now, knowing that they are risky, I would perhaps be
more careful to avoid falling into problems (of security or privacy)”.</p>
      <p>On the other hand, with regard to users U2, U13, U18, and U28, who had been the ones
who had most indicated the identified risk as “unlikely”, the responses collected to this second
question confirm their thinking. These users, in fact, are among those who would activate most
of the applets presented to them. This result should not be surprising since in view of the fact
that they do not consider many applets as risky, it is reasonable to assume that such applets can
(and should) be activated either way.</p>
      <p>As for the results concerning the 300 harmless applets we submitted to the users as a control,
our results highlighted that 39 (13%) of them were instead judged as harmful by the participants.
As mentioned above, for such applets we asked the participants to provide us with an open-ended
answer, explaining why, in their own view, such an applet would be capable of causing a danger
to the user. Table 2 shows some of the most relevant answers we received from participants
and a short summary of the considered applet. In particular, some users e.g. U3, highlighted
that the overuse of certain automation could lead to concerns since some services might not be
capable of keep functioning as intended when involved in applets, such as the Evernote cloud
space that could be filled up if provided with multiple notes. On the other hand, users such as
U12 and U34 suggested that certain applets should be considered as harmful whether certain
conditions apply, like when minors are involved or when there is a risk of fueling the spread of
malicious software.</p>
      <p>
        In conclusion, the experimental evaluations provided interesting insights concerning the 2 RQs
posed upstream of this study. In fact, with respect to RQ1, the BERT-based harm classification
model we presented in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] provided risk classifications of IFTTT applets that were highly
compatible with the thought of the users involved in the experiment, further demonstrating
its reliability, already highlighted by empirical evaluations. Regarding RQ2, on the other hand,
the results show that highlighting the presence of security and privacy risks related to IFTTT
applets positively influenced users not to activate the applets, or at least to weigh their use
to avoid the occurrence of those risk scenarios. Finally, some harmless applets were instead
identified as harmful by some participants, and some of their suggestions stressed the need to
take a broader view with respect to how to assess risk.
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>
        In this study, we investigated the privacy and security concerns associated with applets activated
through the IFTTT platform. We recruited 30 users to evaluate applets classified as risky
by our previously proposed BERT-based classification model [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. The results demonstrate
the efectiveness of the model in ranking risky applets in accordance with user opinions.
Furthermore, our analysis reveals that users can perform accurate risk assessments when
provided with appropriate warnings. Specifically, we found that participants demonstrated
a greater level of consideration towards specific applets, often opting to use the applet more
consciously or not activate it to prevent potential risks. These findings suggest that risk
assessment and management should be incorporated into the design and implementation of
TAPs, with adequate warning mechanisms being provided to users. Future research could
also investigate the efectiveness of additional strategies for enhancing user awareness and
understanding of privacy and security risks associated with automated platforms.
      </p>
    </sec>
    <sec id="sec-6">
      <title>6. Acknowledgments</title>
      <p>This work has been supported by the Italian Ministry of University and Research (MUR) under
grant PRIN 2017 “EMPATHY: Empowering People in deAling with internet of THings ecosYstems”
(Progetti di Rilevante Interesse Nazionale − Bando 2017, Grant 2017MX9T7H).
[18] N. Reimers, I. Gurevych, Sentence-BERT: Sentence embeddings using Siamese
BERTnetworks, in: Proceedings International Conference on Empirical Methods in Natural
Language Processing and the 9th International Joint Conference on Natural Language
Processing, ACL, 2019, pp. 3982–3992.
[19] D. Yarowsky, Unsupervised word sense disambiguation rivaling supervised methods, in:
Proceedings 33rd Annual Meeting of the Association for Computational Linguistics, ACM,
1995, pp. 189–196.
[20] X. Zhu, Z. Ghahramani, Learning from labeled and unlabeled data with label propagation,</p>
      <p>Technical Report CMU-CALD-02-107, Carnegie Mellon University, 2002.
[21] D. Croce, G. Castellucci, R. Basili, GAN-BERT: Generative adversarial learning for robust
text classification with a bunch of labeled examples, in: Proceedings of 58th Annual
Meeting of the Association for Computation Linguistics, ACL, 2020, pp. 2114–2119.
[22] L. Wang, M. Han, X. Li, N. Zhang, H. Cheng, Review of classification methods on
unbalanced data sets, IEEE Access 9 (2021) 64606–64628.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>L.</given-names>
            <surname>Atzori</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Iera</surname>
          </string-name>
          ,
          <string-name>
            <surname>G. Morabito,</surname>
          </string-name>
          <article-title>The internet of things: A survey</article-title>
          ,
          <source>Computer networks 54</source>
          (
          <year>2010</year>
          )
          <fpage>2787</fpage>
          -
          <lpage>2805</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>B. L. R.</given-names>
            <surname>Stojkoska</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K. V.</given-names>
            <surname>Trivodaliev</surname>
          </string-name>
          ,
          <article-title>A review of internet of things for smart home: Challenges and solutions</article-title>
          ,
          <source>Journal of cleaner production 140</source>
          (
          <year>2017</year>
          )
          <fpage>1454</fpage>
          -
          <lpage>1464</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>C.</given-names>
            <surname>Ardito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Buono</surname>
          </string-name>
          , G. Desolda,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>From smart objects to smart experiences: An end-user development approach</article-title>
          ,
          <source>International Journal of Human-Computer Studies</source>
          <volume>114</volume>
          (
          <year>2018</year>
          )
          <fpage>51</fpage>
          -
          <lpage>68</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>G.</given-names>
            <surname>Ghiani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Manca</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Paternò</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Santoro</surname>
          </string-name>
          ,
          <article-title>Personalization of context-dependent applications through trigger-action rules, ACM Transactions on Computer-Human Interaction (TOCHI) 24 (</article-title>
          <year>2017</year>
          )
          <fpage>1</fpage>
          -
          <lpage>33</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ardito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>Empowering end users to customize their smart environments: model, composition paradigms, and domain-specific tools, ACM Transactions on Computer-Human Interaction (TOCHI) 24 (</article-title>
          <year>2017</year>
          )
          <fpage>1</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>B.</given-names>
            <surname>Breve</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Deufemia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Greco</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>An end-user development approach to secure smart environments, in: End-User Development: 8th International Symposium</article-title>
          , IS-EUD
          <year>2021</year>
          ,
          <string-name>
            <given-names>Virtual</given-names>
            <surname>Event</surname>
          </string-name>
          ,
          <source>July 6-8</source>
          ,
          <year>2021</year>
          , Proceedings, Springer,
          <year>2021</year>
          , pp.
          <fpage>36</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Zheng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Apthorpe</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Chetty</surname>
          </string-name>
          ,
          <string-name>
            <surname>N. Feamster,</surname>
          </string-name>
          <article-title>User perceptions of smart home IoT privacy</article-title>
          ,
          <source>Proceedings of the ACM on human-computer interaction 2</source>
          (
          <year>2018</year>
          )
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>M.</given-names>
            <surname>Surbatovich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Aljuraidan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. Das</surname>
            ,
            <given-names>L. Jia,</given-names>
          </string-name>
          <article-title>Some recipes can do more than spoil your appetite: Analyzing the security and privacy risks of IFTTT recipes</article-title>
          ,
          <source>in: Proceedings of the 26th International Conference on World Wide Web</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>1501</fpage>
          -
          <lpage>1510</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>C.</given-names>
            <surname>Cobb</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Surbatovich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kawakami</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Sharif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. Das</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Jia</surname>
          </string-name>
          ,
          <article-title>How risky are real users' IFTTT applets?</article-title>
          ,
          <source>in: Proceedings of the Sixteenth USENIX Conference on Usable Privacy and Security</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>505</fpage>
          -
          <lpage>529</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>B.</given-names>
            <surname>Breve</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Cimino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Deufemia</surname>
          </string-name>
          ,
          <article-title>Identifying security and privacy violation rules in trigger-action IoT platforms with NLP models</article-title>
          ,
          <source>IEEE Internet of Things Journal</source>
          (
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Q.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Datta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Bates</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. A.</given-names>
            <surname>Gunter</surname>
          </string-name>
          ,
          <article-title>Charting the attack surface of trigger-action IoT platforms</article-title>
          ,
          <source>in: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>1439</fpage>
          -
          <lpage>1453</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
            <surname>Saeidi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Calvert</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. W.</given-names>
            <surname>Au</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sarma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. B.</given-names>
            <surname>Bobba</surname>
          </string-name>
          ,
          <article-title>If this context then that concern: Exploring users' concerns with IFTTT applets</article-title>
          ,
          <source>Proceedings on Privacy Enhancing Technologies</source>
          <year>2022</year>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>F.</given-names>
            <surname>Paci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Bianchin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Quintarelli</surname>
          </string-name>
          ,
          <string-name>
            <surname>N.</surname>
          </string-name>
          <article-title>Zannone, IFTTT privacy checker, in: Emerging Technologies for Authorization</article-title>
          and Authentication: Third International Workshop, ETAA 2020,
          <article-title>Guildford</article-title>
          , UK,
          <year>September 18</year>
          ,
          <year>2020</year>
          , Proceedings 3, Springer,
          <year>2020</year>
          , pp.
          <fpage>90</fpage>
          -
          <lpage>107</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>B.</given-names>
            <surname>Breve</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Cimino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Deufemia</surname>
          </string-name>
          ,
          <article-title>Towards explainable security for ECA rules</article-title>
          ,
          <source>in: Proceedings of the 3rd International Workshop on Empowering People in Dealing with Internet of Things Ecosystems (EMPATHY '22)</source>
          , volume
          <volume>3172</volume>
          <source>of CEUR Workshop Proceedings, CEUR-WS.org</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>26</fpage>
          -
          <lpage>30</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>D.</given-names>
            <surname>Xiao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Cai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <surname>A3ID:</surname>
          </string-name>
          <article-title>An automatic and interpretable implicit interference detection method for smart home via knowledge graph</article-title>
          ,
          <source>IEEE IoT J</source>
          <volume>7</volume>
          (
          <year>2019</year>
          )
          <fpage>2197</fpage>
          -
          <lpage>2211</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>X.</given-names>
            <surname>Mi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Qian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>An empirical characterization of IFTTT: ecosystem, usage, and performance</article-title>
          ,
          <source>in: Proceedings of the 2017 Internet Measurement Conference</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>398</fpage>
          -
          <lpage>404</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>M.</given-names>
            <surname>Surbatovich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Aljuraidan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. Das</surname>
            ,
            <given-names>L. Jia,</given-names>
          </string-name>
          <article-title>Some recipes can do more than spoil your appetite: Analyzing the security and privacy risks of IFTTT recipes</article-title>
          ,
          <source>in: Proceedings 26th International Conference on World Wide Web, ACM</source>
          ,
          <year>2017</year>
          , p.
          <fpage>1501</fpage>
          -
          <lpage>1510</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>