[论文解读] The digital harms of smart home devices: A systematic literature review
本篇系统性文献回顾采用PRISMA方法论,分析智能家庭设备中的数字危害,共审查63项研究(2011–2021年),识别出隐私侵犯、未授权访问及系统操控等问题。主要发现显示,隐私泄露是最普遍的危害,技术缓解策略在研究中占主导地位,而社会与系统性解决方案仍研究不足,凸显未来跨学科研究的关键缺口。
The connection of home electronic devices to the internet allows remote control of physical devices and involves the collection of large volumes of data. With the increase in the uptake of Internet-of-Things home devices, it becomes critical to understand the digital harms of smart homes. We present a systematic literature review on the security and privacy harms of smart homes. PRISMA methodology is used to systematically review 63 studies published between January 2011 and October 2021; and a review of known cases is undertaken to illustrate the literature review findings with real-world scenarios. Published literature identifies that smart homes may pose threats to confidentiality (unwanted release of information), authentication (sensing information being falsified) and unauthorised access to system controls. Most existing studies focus on privacy intrusions as a prevalent form of harm against smart homes. Other types of harms that are less common in the literature include hacking, malware and DoS attacks. Digital harms, and data associated with these harms, may vary extensively across smart devices. Most studies propose technical measures to mitigate digital harms, while fewer consider social prevention mechanisms. We also identify salient gaps in research, and argue that these should be addressed in future cross-disciplinary research initiatives.
研究动机与目标
- 识别并分类与智能家庭设备相关的首要数字危害,特别是与安全和隐私相关的问题。
- 考察未授权访问、数据泄露及系统操控等威胁在物联网家庭中的普遍性与性质。
- 评估学术文献中提出的现有技术与社会缓解策略的有效性。
- 突出当前研究中的关键缺口,尤其是对社会技术与系统性预防机制关注不足的问题。
- 通过整合63篇同行评审研究及真实案例,为未来跨学科研究提供证据支持。
提出的方法
- 应用PRISMA(系统性综述与Meta分析首选报告项目)框架,确保文献筛选与分析的方法严谨性。
- 对2011年1月至2021年10月间发表的63篇聚焦智能家庭安全与隐私的同行评审研究进行系统性检索与筛选。
- 对识别出的危害进行主题分析,包括机密性泄露、认证失败及未授权控制访问等。
- 结合真实世界案例,以情境化并验证学术文献中的发现。
- 将提出的缓解策略分类为技术控制(如加密、访问控制)与社会机制(如用户教育、政策框架)。
- 通过对比研究重点、方法论与所提解决方案,识别研究缺口。
实验结果
研究问题
- RQ1学术文献中识别出的智能家庭设备中最普遍的数字危害类型是什么?
- RQ2技术与社会缓解策略在应对智能家庭中隐私与安全风险方面如何比较?
- RQ3现有研究在多大程度上关注了超越单个设备层面威胁的系统性或结构性漏洞?
- RQ4现实世界事件与学术研究中报告的智能家庭危害发现是否一致或存在差异?
- RQ5在理解与缓解物联网家庭环境中的数字危害方面,仍存在哪些关键研究缺口?
主要发现
- 隐私侵犯,包括未经授权的数据收集与暴露,是智能家庭系统中最常报告的数字危害形式。
- 对设备控制的未授权访问以及传感器数据的欺骗,对系统完整性与用户安全构成重大威胁。
- 多数研究提出的技术解决方案包括加密、访问控制机制及安全认证协议。
- 较少研究考虑社会或组织干预措施,如用户意识计划或监管框架,尽管其具有更广泛的影响潜力。
- 文献中明显缺乏对跨设备或生态系统层面威胁的研究,特别是关于数据聚合与长期追踪的问题。
- 真实世界案例表明,研究中识别出的许多危害——如设备劫持与数据外泄——已在实践中发生,验证了缓解策略的紧迫性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。