Prianka Mandal

dblp:354/8813 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
7since 2021 · last 2025
0009-0009-1329-9818ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Testing Practices, Challenges, and Developer Perspectives in Open-Source IoT Platforms
abstract
As the popularity of Internet of Things (IoT) platforms grows, users gain unprecedented control over their homes, health monitoring, and daily task automation. However, the testing of software for these platforms poses significant challenges due to their diverse composition, e.g., common smart home platforms are often composed of varied types of devices that use a diverse array of communication protocols, connections to mobile apps, cloud services, as well as integration among various platforms. This paper is the first to uncover both the practices and perceptions behind testing in IoT platforms, particularly open-source smart home platforms. Our study is composed of two key components. First, we mine and empirically analyze the code and integrations of two highly popular and well maintained open-source IoT platforms, OpenHAB and HomeAssistant. Our analysis involves the identification of functional and related test methods based on the focal method approach. We find that OpenHAB has only 0.04 test ratio (~ 4K focal test methods from ~ 76K functional methods) in Java files, while HomeAssistant exhibits higher test ratio of 0.42, which reveals a significant dearth of testing. Second, to understand the developers' perspective on testing in IoT, and to explain our empirical observations, we survey 80 open-source developers actively engaged in IoT platform development. Our analysis of survey responses reveals a significant focus on automated (unit) testing, and a lack of manual testing, which supports our empirical observations, as well as testing challenges specific to IoT. Together, our empirical analysis and survey yield 10 key findings that uncover the current state of testing in IoT platforms, and reveal key perceptions and challenges. These findings provide valuable guidance to the research community in navigating the complexities of effectively testing IoT platforms.
Daniel Rodríguez-Cárdenas, Safwat Ali Khan, Prianka Mandal, Adwait Nadkarni, Kevin Moran, Denys Poshyvanyk
ICST3
2025 "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product Security
abstract
As the regulatory landscape for the Internet of Things (IoT) evolves, vendors are moving towards certifying their products for security. Thus, we need to understand who is liable when certification failures result in harm, i.e., when certified products have vulnerabilities that are exploited to cause harm to users. This paper addresses the fundamental and timely question that has significant implications for vulnerability detection in certified products: who is liable for harm resulting from vulnerabilities in certified products, and who should be so liable? Through a qualitative analysis of contractual documents from 20 IoT vendors, this paper investigates how liability is currently defined in vendor-user contractual terms. This analysis then incorporates an expert survey of 18 legal professionals to examine their perspectives on liability within this context. Our analysis leads to 14 key findings (F1- F14) that show how vendors exclude liability to the maximum extent with (sometimes unlawful) exclusions, and how the perspectives of legal experts lie in stark contrast to what we observe in contracts (which are drafted by lawyers). We distill our findings into three key themes that call for a robust and clear liability framework, creating an incentive for IoT vendors to ensure that their IoT products meet proper security and privacy standards.
Prianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin, Ella Sullivan, Adwait Nadkarni
SP1
2025 "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and Certification
abstract
Regulators and standards bodies have recently proposed several security compliance initiatives for IoT products. These emerging standards and regulations seek to bring security assurance to IoT products by way of compliance certification. However, even certified IoT products exhibit common vulnerabilities, which suggests the presence of latent challenges in the certification ecosystem. This paper performs the first qualitative, interview-based study (n=17) with IoT practitioners to understand industry perspectives and experiences of IoT product security certification, in order to uncover the latent factors and challenges obstructing effective IoT product certification. Our reflexive thematic analysis of the interview transcripts leads to 16 key findings that uncover critical factors affecting compliance enforcement in practice. We distill these findings and our observations into 4 major themes which represent critical gaps that must be addressed for product certification to be viable for IoT.
Prianka Mandal, Adwait Nadkarni
SP1
2025 "Free WiFi is not ultimately free": Privacy Perceptions of Users in the US regarding City-wide WiFi Services
abstract
City-wide free WiFi is one of the most common initiatives of smart city infrastructures. While city-wide free WiFi services are not subject to privacy-focused regulations and appeal to a broader demographic, how users perceive privacy in such services is unknown. This study explores perspectives of users in the United States regarding the privacy practices of such services as well as their expectations. We conducted surveys with 199 participants of US, consisting of those who had used such services (i.e., experienced users, n=99) and those who had not (i.e., potential users, n=100), assessing their satisfaction with the services, perceptions regarding data privacy practices of city-wide free WiFi services, and general expectations of privacy. We identify 14 key findings by analyzing the responses from participants. We found that participants are aware of the data collection and data sharing by the WiFi services and are uncomfortable with both but are still inclined to use the services as the need for WiFi outweighs privacy, as well as because of the significant trust they place in the services due to their non-profit and government-run nature. Our analysis provides actionable takeaways for researchers and practitioners, arguing for long-term privacy gains through a regulatory approach that treats city-wide WiFi as a utility, given the trust consumers place in it, and the overall tendency of consumers to trade-off privacy for WiFi access in this context.
Prianka Mandal, Tu Le, Amit Seal Ami, Adwait Nadkarni
Proc. Priv. Enhancing Technol.1
2024 Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites
abstract
Political campaigns are known to collect private user data, whether for building voter profiles, engaging with volunteers, or for soliciting donations. However, as such campaigns are classified as nonprofit in the United States (U.S.), their privacy practices have not received the same level of scrutiny as those of for-profit enterprises. This paper presents the Polityzer framework to evaluate the privacy posture of political campaign websites, and uses it to analyze 2060 campaign websites active during the U.S. election of November 2020. Our analysis leads to 20 key findings that demonstrate gaps in the privacy postures of political campaigns. For instance, we find that campaigns collect extensive private data they are not required to by the Federal Election Commission (FEC), and a vast majority do not provide any form of privacy disclosure. When disclosures are provided, they are often incomplete. We also found that campaigns may be inadvertently sharing data with other campaigns through common fundraising platforms, without disclosing such sharing. Reporting the lack of privacy disclosure to the respective campaigns yields further insights into the rationale behind their security posture. Finally, we discuss ways in which our results could enable future research, inform emerging privacy regulations, and transform user behavior regarding data privacy in this critical context.
Kaushal Kafle, Prianka Mandal, Kapil Singh, Benjamin Andow, Adwait Nadkarni
SP2
2024 "Belt and suspenders" or "just red tape"?: Investigating Early Artifacts and User Perceptions of IoT App Security Certification
Prianka Mandal, Amit Seal Ami, Victor Olaiya, Sayyed Hadi Razmjo, Adwait Nadkarni
USENIX Security Symposium1
2023 Helion: Enabling Natural Testing of Smart Homes
abstract
Prior work has developed numerous systems that test the security and safety of smart homes. For these systems to be applicable in practice, it is necessary to test them with realistic scenarios that represent the use of the smart home, i.e., home automation, in the wild. This demo paper presents the technical details and usage of Helion, a system that uses n-gram language modeling to learn the regularities in user-driven programs, i.e., routines developed for the smart home, and predicts natural scenarios of home automation, i.e., event sequences that reflect realistic home automation usage. We demonstrate the HelionHA platform, developed by integrating Helion with the popular Home Assistant smart home platform. HelionHA allows an end-to-end exploration of Helion’s scenarios by executing them as test cases with real and virtual smart home devices.
Prianka Mandal, Sunil Manandhar, Kaushal Kafle, Kevin Moran, Denys Poshyvanyk, Adwait Nadkarni
ESEC/SIGSOFT FSE1