{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T23:38:19Z","timestamp":1769729899562,"version":"3.49.0"},"reference-count":39,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T00:00:00Z","timestamp":1769644800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CNS-2238701"],"award-info":[{"award-number":["CNS-2238701"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Things"],"published-print":{"date-parts":[[2026,2,28]]},"abstract":"<jats:p>The network traffic data produced by the Internet of Things (IoT) devices are collected by Internet Service Providers (ISPs) and IoT manufacturers, and often also shared with their third parties to maintain and enhance user experiences. Unfortunately, on-path adversaries could fingerprint users\u2019 sensitive and private information by analyzing these network traffic traces. While there\u2019s a growing body of literature on defending against this side-channel attack\u2014malicious IoT traffic analytics (TA), there\u2019s currently no systematic method to compare and evaluate the comprehensiveness of these existing studies. To address this problem, we design a new low-cost, open-source system framework\u2014IoT Traffic Exposure Monitoring Toolkit (ITEMTK) that enables people to comprehensively examine and validate prior attack models and their defending approaches. During the design of ITEMTK, we also identified a novel image-based attack capable of inferring sensitive user information, even when users implement the most robust preventative measures in their smart homes. We then present a new, initial, prototype-level defense mechanism\u2014PrivacyProtector, which could effectively defend against a wide range of state-of-the-art machine learning-based TA attacks, including our newly proposed image-based TA attacks. ITEMTK\u2019s flexibility allows users\u2019 easy expansion by integrating new TA attack models and defenses to benchmark their future work.<\/jats:p>","DOI":"10.1145\/3772091","type":"journal-article","created":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T11:34:44Z","timestamp":1761046484000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["ITEMTK: IoT Traffic Exposure Monitoring Toolkit"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9865-0936","authenticated-orcid":false,"given":"Su","family":"Wang","sequence":"first","affiliation":[{"name":"Computer Science, Colorado School of Mines","place":["Golden, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5224-1410","authenticated-orcid":false,"given":"Keyang","family":"Yu","sequence":"additional","affiliation":[{"name":"Computer Science, Marquette University","place":["Milwaukee, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6418-7474","authenticated-orcid":false,"given":"Qi","family":"Li","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering, University of Oklahoma","place":["Norman, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1052-5658","authenticated-orcid":false,"given":"Dong","family":"Chen","sequence":"additional","affiliation":[{"name":"Computer Science, Colorado School of Mines","place":["Golden, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,1,29]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"2023. PAROS. Retrieved 3 November 2025 from https:\/\/github.com\/cyber-physical-systems\/paros"},{"key":"e_1_3_1_3_2","unstructured":"2024. ITEMTK. Retrieved 3 November 2025 from https:\/\/github.com\/cyber-physical-systems\/itemtk"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0040"},{"key":"e_1_3_1_5_2","unstructured":"Silvio Barra Salvatore Mario Carta Andrea Corriga Alessandro Sebastian Podda and Diego Reforgiato Recupero. 2020. Deep learning and time series-to-image encoding for financial forecasting. IEEE Transactions on Computational Social Systems 1 1 (2020) 89\u2013107."},{"key":"e_1_3_1_6_2","volume-title":"Proceedings of the 2020 IEEE\/ACM Fifth International Conference on Internet-of-Things Design and Implementation","author":"Bovornkeeratiroj Phuthipong","unstructured":"Phuthipong Bovornkeeratiroj, Srinivasan Iyengar, Stephen Lee, David Irwin, and Prashant Shenoy. [n.d.]. RepEL: A utility-preserving privacy system for iot-based energy meters. In Proceedings of the 2020 IEEE\/ACM Fifth International Conference on Internet-of-Things Design and Implementation."},{"key":"e_1_3_1_7_2","article-title":"Now Those, Privacy Rules Are Gone, This Is How ISPs Will Actually Sell Your Personal Data","author":"Brewster T.","year":"2017","unstructured":"T. Brewster. 2017. Now Those, Privacy Rules Are Gone, This Is How ISPs Will Actually Sell Your Personal Data. Retrieved 3 November 2025 from https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/03\/30\/fcc-privacy-rules-how-isps-will-actually-sell-your-data\/","journal-title":"Retrieved 3 November 2025 from https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/03\/30\/fcc-privacy-rules-how-isps-will-actually-sell-your-data\/"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.5555\/184656.180369"},{"key":"e_1_3_1_9_2","first-page":"227","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Cai Xiang","year":"2014","unstructured":"Xiang Cai, Rishab Nithyanand, Tao Wang, Rob Johnson, and Ian Goldberg. 2014. A systematic approach to developing and evaluating website fingerprinting defenses. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 227\u2013238."},{"key":"e_1_3_1_10_2","first-page":"208","volume-title":"Proceedings of the IEEE International Conference on Pervasive Computing and Communications","author":"Chen Dong","year":"2014","unstructured":"Dong Chen, David Irwin, Prashant Shenoy, and Jeannie Albrecht. 2014. Combined heat and privacy: Preventing occupancy detection from smart meters. In Proceedings of the IEEE International Conference on Pervasive Computing and Communications. 208\u2013215."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1967.1053964"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243865"},{"key":"e_1_3_1_13_2","first-page":"303","volume-title":"Proceedings of the USENIX Security Symposium","year":"2004","unstructured":"Roger Dingledine, Nick Mathewson, and Paul Syverson. 2004. Tor: The second-generation onion router. In Proceedings of the USENIX Security Symposium. 303\u2013320."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.28"},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","first-page":"843","DOI":"10.1109\/ICACT.2008.4493886","volume-title":"Proceedings of the 2008 10th International Conference on Advanced Communication Technology","author":"Hasan Md Kamrul","year":"2008","unstructured":"Md Kamrul Hasan, Husne Ara Rubaiyeat, Yong-Koo Lee, and Sungyoung Lee. 2008. A reconfigurable HMM for activity recognition. In Proceedings of the 2008 10th International Conference on Advanced Communication Technology. IEEE, 843\u2013846."},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.5555\/2876386.2876401"},{"key":"e_1_3_1_17_2","volume-title":"Proceedings of the European Symposium on Research in Computer Security","author":"Juarez Marc","year":"2016","unstructured":"Marc Juarez, Mohsen Imani, Mike Perry, Claudia Diaz, and Matthew Wright. 2016. Toward an efficient website fingerprinting defense. In Proceedings of the European Symposium on Research in Computer Security. Springer."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.parco.2011.09.001"},{"key":"e_1_3_1_19_2","article-title":"Smart Devices Leaking Data to Tech Giants Raises New IoT Privacy Issues","author":"Lindsey Nicole","year":"2019","unstructured":"Nicole Lindsey. 2019. Smart Devices Leaking Data to Tech Giants Raises New IoT Privacy Issues. Retrieved 3 November 2025 from https:\/\/www.cpomagazine.com\/data-privacy\/smart-devices-leaking-data-to-tech-giants-raises-new-iot-privacy-issues\/","journal-title":"Retrieved 3 November 2025 from https:\/\/www.cpomagazine.com\/data-privacy\/smart-devices-leaking-data-to-tech-giants-raises-new-iot-privacy-issues\/"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2799820"},{"key":"e_1_3_1_21_2","unstructured":"mcc 2022. Matthews Correlation Coefficient. Retrieved 3 November 2025 from https:\/\/en.wikipedia.org\/wiki\/Matthews%_correlation%_coefficient."},{"issue":"9","key":"e_1_3_1_22_2","article-title":"pandas: A foundational Python library for data analysis and statistics","volume":"14","author":"McKinney Wes","year":"2011","unstructured":"Wes McKinney. 2011. pandas: A foundational Python library for data analysis and statistics. Python for High Performance and Scientific Computing 14, 9 (2011), 1\u20139.","journal-title":"Python for High Performance and Scientific Computing"},{"key":"e_1_3_1_23_2","unstructured":"mozilla [n.d.]. ISPs Lied to Congress to Spread Confusion about Encrypted DNS Mozilla says. Retrieved 3 November 2025 from https:\/\/arstechnica.com\/tech-policy\/2019\/11\/isps-lied-to-congress-to-spread-confusion-about-encrypted-dns-mozilla-says\/"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.3390\/s140916235"},{"key":"e_1_3_1_25_2","unstructured":"Adam Paszke Sam Gross Francisco Massa Adam Lerer James Bradbury Gregory Chanan Trevor Killeen Zeming Lin Natalia Gimelshein Luca Antiga Alban Desmaison Andreas K\u00f6pf Edward Yang Zach DeVito Martin Raison Alykhan Tejani Sasank Chilamkurthy Benoit Steiner Lu Fang Junjie Bai and Soumith Chintala. 2019. PyTorch: An imperative style high-performance deep learning library. In Proceedings of the 33rd International Conference on Neural Information Processing Systems. Curran Associates Inc. Red Hook NY USA Article 721 8026\u20138037."},{"key":"e_1_3_1_26_2","unstructured":"Fabian Pedregosa Ga\u00ebl Varoquaux Alexandre Gramfort Vincent Michel Bertrand Thirion Olivier Grisel Mathieu Blondel Peter Prettenhofer Ron Weiss Vincent Dubourg Jake Vanderplas Alexandre Passos David Cournapeau Matthieu Brucher Matthieu Perrot and \u00c9douard Duchesnay. 2011. Scikit-learn: Machine learning in python. J. Mach. Learn. Res. 12 null (2011) 2825\u20132830."},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/MASSP.1986.1165342"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMEW.2013.6618397"},{"key":"e_1_3_1_29_2","doi-asserted-by":"crossref","DOI":"10.1109\/TCSS.2014.2307453","article-title":"Modeling temporal activity patterns in dynamic social networks","author":"Raghavan Vasanthan","year":"2014","unstructured":"Vasanthan Raghavan, Greg Ver Steeg, Aram Galstyan, and Alexander G. Tartakovsky. 2014. Modeling temporal activity patterns in dynamic social networks. IEEE Transactions on Computational Social Systems 1, 1 (2014), 89\u2013107.","journal-title":"IEEE Transactions on Computational Social Systems"},{"key":"e_1_3_1_30_2","article-title":"Prediction of player churn and disengagement based on user activity data of a freemium online strategy game","author":"Rothmeier Karsten","year":"2020","unstructured":"Karsten Rothmeier, Nicolas Pflanzl, Joschka H\u00fcllmann, and Mike Preuss. 2020. Prediction of player churn and disengagement based on user activity data of a freemium online strategy game. IEEE Transactions on Games 13, 1 (2020), 78\u201388.","journal-title":"IEEE Transactions on Games"},{"key":"e_1_3_1_31_2","unstructured":"Sam Roweis. 1997. EM algorithms for PCA and SPCA. In Proceedings of the 11th International Conference on Neural Information Processing Systems (NIPS\u201997). MIT Press Cambridge MA USA 626\u2013632."},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_2"},{"key":"e_1_3_1_33_2","article-title":"Classifying IoT devices in smart environments using network traffic characteristics","author":"Sivanathan Arunan","year":"2018","unstructured":"Arunan Sivanathan, Hassan Habibi Gharakheili, Franco Loi, Adam Radford, Chamith Wijenayake, Arun Vishwanath, and Vijay Sivaraman. 2018. Classifying IoT devices in smart environments using network traffic characteristics. IEEE Transactions on Mobile Computing 18, 8 (2018), 1745\u20131759.","journal-title":"IEEE Transactions on Mobile Computing"},{"key":"e_1_3_1_34_2","article-title":"Internet of Things Connected Devices Installed base Worldwide from 2015 to 2025 (in billions)","year":"2022","unstructured":"Statista. 2022. Internet of Things Connected Devices Installed base Worldwide from 2015 to 2025 (in billions). Retrieved 3 November 2025 from https:\/\/www.statista.com\/statistics\/1183457\/iot-connected-devices-worldwide\/","journal-title":"Retrieved 3 November 2025 from https:\/\/www.statista.com\/statistics\/1183457\/iot-connected-devices-worldwide\/"},{"key":"e_1_3_1_35_2","unstructured":"vgg 2012. Very Deep Convolutional Networks for Large-Scale Visual Recognition. Retrieved 3 November 2025 from https:\/\/www.robots.ox.ac.uk\/% vgg\/research\/very_deep\/"},{"key":"e_1_3_1_36_2","volume-title":"Proceedings of the 26th USENIX Security Symposium","author":"Wang Tao","year":"2017","unstructured":"Tao Wang and Ian Goldberg. 2017. Walkie-talkie: An efficient defense against passive website fingerprinting attacks. In Proceedings of the 26th USENIX Security Symposium."},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455812"},{"key":"e_1_3_1_38_2","first-page":"1","volume-title":"Proceedings of the 2023 32nd International Conference on Computer Communications and Networks","author":"Yu Keyang","year":"2023","unstructured":"Keyang Yu and Dong Chen. 2023. PAROS: The Missing \u201cPuzzle\u201d in Smart Home Router Operating Systems. In Proceedings of the 2023 32nd International Conference on Computer Communications and Networks. 1\u201310."},{"key":"e_1_3_1_39_2","first-page":"62","volume-title":"Proceedings of the 20th International Conference on Information Processing in Sensor Networks.","author":"Yu Keyang","year":"2021","unstructured":"Keyang Yu, Qi Li, Dong Chen, Mohammad Rahman, and Shiqiang Wang. 2021. PrivacyGuard: Enhancing smart home user privacy. In Proceedings of the 20th International Conference on Information Processing in Sensor Networks. (Nashville, TN, USA). 62\u201376."},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00312"}],"container-title":["ACM Transactions on Internet of Things"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3772091","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3772091","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T12:33:36Z","timestamp":1769690016000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3772091"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,29]]},"references-count":39,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,2,28]]}},"alternative-id":["10.1145\/3772091"],"URL":"https:\/\/doi.org\/10.1145\/3772091","relation":{},"ISSN":["2691-1914","2577-6207"],"issn-type":[{"value":"2691-1914","type":"print"},{"value":"2577-6207","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,29]]},"assertion":[{"value":"2025-05-23","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-03","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}