Privacy Assessment and Threat Modeling in Internet of Things Systems
Emmanuel Dare Alalade · 2026
Privacy in IoT involves protecting and regulating who can access the data, when, and what can be done to the data, which is crucial for protecting data both in transit and at rest. Based on the importance of privacy in IoT, we conducted a scoping review of privacy preservation techniques (PPTs) in IoT systems and the privacy-enhancing Technologies (PETs) used by these PPTs to achieve various privacy goals in IoT systems. Our study was conducted under four categories: the goals of PPTs and PETs, the types of privacy focus in IoT, and the computing layers of PPT deployment in the IoT architecture. From our study, we observed some gaps not covered in previous works which are 1) limited works focusing on the preserving IoT device data (IoT device identity data), 2) the importance of continuous privacy preservation process beyond design in IoT system, 3) the need for privacy-centered threat analysis framework and 4) the need for deep understanding of threat actors’ activities during privacy threats in IoT system. In this dissertation, we first propose privacy engineering (PE) that provides continuous privacy preservation for both IoT devices and users in the IoT system. The PE, which involves privacy threat analysis (PTA) and privacy impact assessment (PIA), should be continuously carried out throughout the design, planning, implementation, and whenever a new change is made to the IoT system. Secondly, we proposed a Privacy Threat Modeling Framework (PTMF) that can be used across various privacy approaches, including risk assessment and privacy threat analysis. Thirdly, using the proposed PTMF, we conducted an expert-driven analysis of threat actor activities by seeking the opinions of security and privacy experts on tactics and techniques threat actors could use to target privacy in IoT systems. In our study, we analyzed 12 privacy threats associated with IoT systems gathered from the literature. This comprehensive privacy preservation process is envisioned to benefit all stakeholders involved in IoT systems. Implementing this process correctly is expected to limit threat actors’ activities and mitigate privacy threats in IoT systems.