Skip to main navigation Skip to search Skip to main content

The Illusion of Control in Smart Homes: How IoT App Privacy Statement and Device Interaction Complexity Impact User Security Practices

  • Leena Marghalani*
  • , Walid Aljoby
  • , Ahmad Asadullah
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

While security experts have extensively identified risks in smart homes with interconnected Internet of Things (IoT) devices, little work has examined user-perceived control over security practices. Particularly, how the interaction complexity of IoT devices and privacy statements influence user security practices. To address this problem, we developed a threat and mental model grounded in the Illusion of Control (IoC) theory and empirically evaluated how IoT privacy statements and interaction complexity alter users' security practices. We surveyed 102 participants to measure how security knowledge, security attitude, perceived controllability, understanding of privacy statement, and perceived IoT interaction complexity impact security practices. Our findings allude to three key insights. First, overconfidence in security management weakens the adoption of secure practices. Second, users who understand and trust the privacy statement of IoT applications are more likely to engage in secure practices. Third, the results indicate that users who perceive IoT interoperability as too complex are less likely to adopt protective measures. Based on our findings, we provide recommendations to IoT security experts to develop more effective IoT security and privacy measures.

Original languageEnglish
Title of host publicationProceedings - 2025 European Symposium on Usable Security, EuroUSEC 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages191-203
Number of pages13
ISBN (Electronic)9798331559236
DOIs
StatePublished - 2025
Event2025 European Symposium on Usable Security, EuroUSEC 2025 - Manchester, United Kingdom
Duration: 10 Sep 202511 Sep 2025

Publication series

NameProceedings - 2025 European Symposium on Usable Security, EuroUSEC 2025

Conference

Conference2025 European Symposium on Usable Security, EuroUSEC 2025
Country/TerritoryUnited Kingdom
CityManchester
Period10/09/2511/09/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • Interaction Complexity
  • IoT Security
  • Privacy Statements
  • Smart Homes
  • User Behavior

ASJC Scopus subject areas

  • Computer Graphics and Computer-Aided Design
  • Hardware and Architecture

Fingerprint

Dive into the research topics of 'The Illusion of Control in Smart Homes: How IoT App Privacy Statement and Device Interaction Complexity Impact User Security Practices'. Together they form a unique fingerprint.

Cite this