Skip to main content
QUICK REVIEW

[Paper Review] Alexa, Who Am I Speaking To? Understanding Users' Ability to Identify Third-Party Apps on Amazon Alexa

D. J. Major, Danny Yuxing Huang|arXiv (Cornell University)|Oct 30, 2019
Advanced Malware Detection Techniques4 citations
TL;DR

This study investigates users' ability to distinguish between native Alexa skills and third-party applications, revealing that even experienced users frequently confuse third-party skills with native functionality. Despite awareness of third-party development, 70% of participants failed to identify malicious or third-party skills correctly, highlighting critical privacy and security risks due to ambiguous voice interface design.

ABSTRACT

Many Internet of Things (IoT) devices have voice user interfaces (VUIs). One of the most popular VUIs is Amazon's Alexa, which supports more than 47,000 third-party applications ("skills"). We study how Alexa's integration of these skills may confuse users. Our survey of 237 participants found that users do not understand that skills are often operated by third parties, that they often confuse third-party skills with native Alexa functions, and that they are unaware of the functions that the native Alexa system supports. Surprisingly, users who interact with Alexa more frequently are more likely to conclude that a third-party skill is native Alexa functionality. The potential for misunderstanding creates new security and privacy risks: attackers can develop third-party skills that operate without users' knowledge or masquerade as native Alexa functions. To mitigate this threat, we make design recommendations to help users distinguish native and third-party skills.

Motivation & Objective

  • To investigate users' understanding of whether Alexa skills are developed by Amazon or third parties.
  • To assess users' ability to differentiate between native Alexa functions, third-party skills, and malicious skills.
  • To identify design flaws in Alexa's voice user interface that contribute to user confusion.
  • To explore the privacy and security implications of users mistakenly interacting with third-party skills.
  • To provide design recommendations that improve transparency and user awareness of skill origins.

Proposed method

  • Conducted a survey with 237 Alexa users, including undergraduates and Mechanical Turk workers, to assess their understanding of skill origins.
  • Presented participants with audio and video clips of interactions with three types of skills: native Alexa, publicly available third-party, and custom-developed malicious skills.
  • Used anonymized clips without revealing the type of skill being demonstrated to avoid bias in user responses.
  • Analyzed user responses to determine confusion levels between native and third-party skills, including misidentification of malicious skills as native.
  • Evaluated design principles such as discoverability and consistency in voice command structure to identify root causes of user misunderstanding.
  • Proposed design recommendations based on Norman’s design principles, focusing on audio/visual cues and standardized invocation phrases.

Experimental results

Research questions

  • RQ1To what extent can users correctly identify whether a skill is native to Alexa or developed by a third party?
  • RQ2How does user experience level affect the likelihood of confusing third-party skills with native Alexa functionality?
  • RQ3What design characteristics of Alexa’s voice interface contribute to user confusion about skill origins?
  • RQ4How do users perceive the functionality and availability of voice commands on Alexa, particularly in relation to third-party skills?
  • RQ5What are the privacy and security implications of users mistakenly interacting with third-party or malicious skills?

Key findings

  • 70% of participants failed to correctly identify third-party skills, even after being informed that skills could be developed by third parties.
  • Users with more experience using Alexa were significantly more likely to misidentify third-party skills as native Alexa functionality.
  • Participants often confused malicious third-party skills with native Alexa functions, indicating a high risk of privacy exposure.
  • Many users were unaware that Alexa supports only a limited set of native functions and that third-party skills can mimic these functions.
  • The lack of consistent audio or visual cues to distinguish skill origins contributed heavily to user confusion.
  • The absence of standardized invocation phrases allowed malicious skills to exploit ambiguous commands, such as 'Please go away,' to gain unintended access.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.