Towards Label-Only Membership Inference Attack against Pre-trained Large Language Models
Yu He
34th USENIX Security Symposium (USENIX Security '25) · Day 1 · LLM Privacy
Overview
The proliferation of Internet of Things (IoT) devices in homes has introduced a significant security challenge: users are often ill-equipped to secure these devices, lacking both the information and the technical expertise to do so effectively. This paper, "Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service," presents a comprehensive study of a novel web service designed to address this gap. Launched in February 2022 by researchers from Yokohama National University and Delft University of Technology, the service, aptly named "am I infected?", offers Japanese users a free, accessible platform to diagnose vulnerabilities and malware infections in their home IoT devices.
Read the paper · Download the PDF (PDF) · Slides
Paper abstract
There is an expectation that users of home IoT devices will be able to secure those devices, but they may lack information about what they need to do. In February 2022, we launched a web service that scans users' IoT devices to determine how secure they are. The service aims to diagnose and remediate vulnerabilities and malware infections of IoT devices of Japanese users. This paper reports on findings from operating this service drawn from three studies: (1) the engagement of 114,747 users between February, 2022 - May, 2024; (2) a large-scale evaluation survey among service users (n=4,103), and; (3) an investigation and targeted survey (n=90) around the remediation actions of users of non-secure devices. During the operation, we notified 417 (0.36%) users that one or more of their devices were detected as vulnerable, and 171 (0.15%) users that one of their devices was infected with malware. The service found no issues for 99% of users. Still, 96% of all users evaluated the service positively, most often for it providing reassurance, being free of charge, and short diagnosis time. Of the 171 users with malware infections, 67 returned to the service later for a new check, with 59 showing improvement. Of the 417 users with vulnerable devices, 151 users revisited and re-diagnosed, where 75 showed improvement. We report on lessons learned, including a consideration of the capabilities that non-expert users will assume of a security scan.

Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service
Speakers: Takayuki Sasaki (Yokohama National University); Tomoya Inazawa (Yokohama National University); Youhei Yamaguchi (Yokohama National University); Simon Parkin (Delft University of Technology/Yokohama National University); Michel van Eeten (Delft University of Technology/Yokohama National University); Katsunari Yoshioka (Yokohama National University); Tsutomu Matsumoto (Yokohama National University)
Conference: USENIX Security
YouTube: No video available, this article is based on the peer-reviewed conference paper.
Overview
The proliferation of Internet of Things (IoT) devices in homes has introduced a significant security challenge: users are often ill-equipped to secure these devices, lacking both the information and the technical expertise to do so effectively. This paper, "Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service," presents a comprehensive study of a novel web service designed to address this gap. Launched in February 2022 by researchers from Yokohama National University and Delft University of Technology, the service, aptly named "am I infected?", offers Japanese users a free, accessible platform to diagnose vulnerabilities and malware infections in their home IoT devices.
The significance of this work lies in its real-world deployment and extensive user engagement data, spanning 27 months and involving over 114,000 users. Unlike traditional security notification campaigns that rely on third parties like ISPs or governments to inform users, "am I infected?" empowers users to proactively seek out security information tailored to their specific devices. The research investigates user engagement, the effectiveness of remediation, and the obstacles users face, providing crucial insights into the usability and impact of user-initiated security diagnostic services for the general public.
The study leverages a multi-faceted approach, combining operational data from the service, a large-scale evaluation survey (n=4,103), and a targeted investigation into the remediation actions of users with identified security issues (n=90). The findings illuminate not only the technical efficacy of such a service but also the psychological and practical factors influencing user behavior, such as the value of reassurance, the importance of ease of use, and the persistent challenges of technical ability and financial constraints in addressing security risks.
Background
The landscape of cybersecurity advice for general consumers is often characterized by an overwhelming volume of generic recommendations, leading to a "crisis of advice prioritization" [47]. Users struggle to discern which security actions are most relevant or urgent for their specific circumstances. This problem is exacerbated in the context of IoT devices, which are frequently exposed to the internet [1,6,22] and are common targets for malware like Mirai [11,13]. While notification campaigns by ISPs [18] or governments [17] have shown some effectiveness in prompting remediation, they are reactive and do not allow users to proactively seek out information about their own devices.
Existing web services offer some analogous capabilities, such as checking for personal credential breaches (e.g., haveibeenpwned.com [4]), IP reputation services [19,35], or open port scanners [32,45,53]. However, these are often designed for more technically proficient users or address only single security issues. Browser extensions or dedicated applications [54,7] offer an alternative but introduce adoption barriers by requiring software installation and a higher level of trust. The "am I infected?" service distinguishes itself by being a web-based service accessible via a browser, requiring no software installation, and offering a comprehensive diagnosis for various IoT security risks.
The motivation behind "am I infected?" stems from the recognition that users need tailored, actionable advice that they can seek on demand. The service aims to fill a critical gap by providing a user-centric approach to IoT security, moving beyond generic advice or third-party notifications. It also seeks to contribute to the limited academic research on user engagement and experience with security diagnosis web services, particularly for IoT devices. The authors acknowledge the inherent self-selection bias in studying users who voluntarily engage with such a service, but argue that evaluating these real-world solutions is crucial for improving user support, even if the user base is not universally representative. This research provides a valuable counterpoint to studies focusing on unsolicited notifications, exploring the dynamics of user-initiated security management.
Key Findings
The operation of the "am I infected?" service over 27 months, from February 2022 to May 2024, yielded several critical insights into user engagement and IoT security remediation. The service attracted a substantial user base, conducting 195,598 diagnoses for 114,747 unique users. A large-scale evaluation survey (n=4,103) revealed overwhelmingly positive user sentiment, with 96% of users rating the service as helpful and expressing a willingness to continue using it. The most frequently cited positive aspects were the ease of diagnosis, short diagnosis time, and the reassurance provided, even when no issues were found, underscoring the psychological value of security validation. Being free of charge was also a significant factor in user satisfaction.
Despite the high satisfaction, security issues were detected for a small but significant fraction of users. Specifically, 417 users (0.36%) were notified of one or more vulnerabilities, and 171 users (0.15%) were informed of malware infections. Three users exhibited both types of issues. The most common issues identified included malware infection (171 cases), known default IDs/credentials (154 cases), risky protocols like Telnet (121 cases), and old firmware (113 cases). The affected device categories primarily included routers, webcams, NAS (Network-Attached Storage), and firewalls.
Crucially, the service demonstrated a tangible impact on remediation rates. Of the 171 users with malware infections, 67 revisited for a re-check (at least 24 hours after initial diagnosis, due to detection methodology), and 59 (88%) showed confirmed remediation. For vulnerabilities, 151 of 417 users re-diagnosed, and 75 (50%) demonstrated improvement. This indicates that user-initiated web services can effectively support remediation, offering a viable alternative to third-party notification mechanisms.
However, the study also identified significant obstacles to remediation. A follow-up survey (n=90) of users with unconfirmed remediation revealed that while most users understood the need for action, a substantial portion faced technical difficulties in identifying or operating the affected devices (17% of those who attempted but didn't complete). Furthermore, 30% of users who did not attempt measures cited not knowing how to take action. Financial burden, particularly for replacing end-of-life devices, was also a notable deterrent (30% of users with vulnerabilities who didn't take measures). The research also highlighted concerns about false reassurance when no problems were found, and user skepticism regarding the trustworthiness of email communications (325 users) and the website itself (138 users), mirroring broader phishing concerns.
Technical Deep Dive
The "am I infected?" service is designed as a web-based platform to offer maximum accessibility and minimize barriers for non-expert users. It provides a comprehensive diagnosis of various security risks for IoT devices, without requiring any software installation or dependence on specific browsers or operating systems. The service's architecture focuses on external scanning capabilities, meaning it diagnoses risks that can be detected from the Internet, rather than requiring an internal agent on the user's network.
The core of the service's diagnostic capabilities revolves around two primary detection methods: malware infection detection and vulnerability detection.
For malware infection detection, the service leverages honeypots and darknet observation data. It operates a Telnet honeypot using real IoT devices and an HTTP honeypot capable of imitating various IoT devices by collecting their responses from the Internet. The darknet system observes unused IP address ranges for malicious activity. When a user requests a diagnosis, the service checks if the user's public IP address has accessed these honeypots or the darknet within the past 24 hours. A match indicates a potential malware infection. The 24-hour window is crucial to mitigate false positives due to dynamic IP address assignments. This method, however, may result in false negatives if malware activity is not continuous or does not reach the honeypots/darknet.
Vulnerability detection is powered by the Karma scan engine [9], developed by 00One, Inc., deployed on the university's network. Karma employs non-harmful methods such as collecting banner information and HTML responses from target devices, avoiding active penetration testing. It probes typical TCP ports (e.g., TCP 80, 8080) used for WebUI. Karma maintains a database of device signatures [10] to identify specific IoT device models based on these responses. Once a device model is identified, Karma consults its vulnerability database to determine known vulnerabilities associated with that model. The service also detects the presence of the Telnet service (port 23/TCP) regardless of device identification, as Telnet is considered a risky protocol. The scope of devices covered includes routers, NAS, web cameras, firewalls, WiFi access points, video recorders, industrial devices, home energy management, home network management, and printers, though in practice, issues were primarily found in routers, webcams, NAS, and firewalls for general consumers. False positives can arise from device fingerprinting errors, while false negatives occur if a device model cannot be identified.
The service diagnoses a wide range of risks as listed in Table 1:
- Malware infection: Recommends firmware update and device reboot.
- Risky protocol (Telnet): Recommends disabling Telnet or device replacement.
- End of support: Recommends device replacement.
- Admin password not set: Recommends password change.
- Known vulnerability: Recommends firmware update.
- Old firmware: Recommends firmware update.
- Known ID/credential: Recommends ID/password update.
- Vulnerable default Wi-Fi password: Recommends Wi-Fi password change.
- No authentication: Recommends device replacement if used in critical infrastructure.
To ensure the security of the service itself, Google re-CAPTCHA [3] is deployed to prevent automated diagnosis requests from bots. Access to diagnosis results pages is controlled via Cookies, ensuring that only the requesting user can view their specific results. The service also features a re-diagnosis option, allowing users to verify if their remediation efforts were successful. Reminder emails are sent to users who have not re-diagnosed within a certain period (initially one week, later reduced to three days) to encourage follow-through.
Demo / Proof of Concept
The "am I infected?" service itself serves as the proof of concept for a user-initiated, web-based IoT security diagnostic tool. Rather than a traditional conference demonstration of a prototype, the researchers operated a live, public-facing service in Japan for over two years, gathering extensive real-world data on its efficacy and user experience.
The user journey through the service is designed for simplicity and accessibility, as detailed in Section 2:
- Request diagnosis: Users navigate to the service's top page, where they enter their email address and indicate their location (e.g., home, workplace). They also provide information on how they learned about the service. After agreeing to the terms of use, they click the "Start Infection Diagnosis" button.
- Receive diagnosis result: Within a few minutes, users receive an email notification that the inspection is complete. This email contains a URL linking to a dedicated web page displaying their diagnosis results. As shown in Figure 1 of the paper, the results page clearly indicates whether any risks were detected. If no issues are found, a "No issue was found" message is displayed. If risks like malware infection or vulnerabilities are detected, the page provides the type of risk, information about the affected device (manufacturer and model, if identified by Karma), and specific recommended measures (e.g., "Update firmware and reboot"). Detailed notification messages are provided in Appendix A of the paper. A "request support" button was also implemented 14 months into the service's operation, allowing users to seek direct assistance via email.
- Take measures and re-diagnose: Users who are notified of security risks are encouraged to implement the recommended countermeasures. After taking action, they can request a re-diagnosis by clicking a button on their results page. This step is crucial for verifying the effectiveness of their remediation efforts. Reminder emails are sent to prompt users who have not re-diagnosed within a specified timeframe.
This operational model, with its clear step-by-step process and focus on user-friendly communication, demonstrates a practical and scalable approach to empowering non-expert users in managing the security of their IoT devices. The continuous operation and data collection from tens of thousands of users validate the service's design and its ability to engage and facilitate remediation among a broad consumer audience.
Defensive Implications
The findings from the "am I infected?" service offer several critical implications for cybersecurity defenders, including individuals, organizations, and policymakers.
First, the high user satisfaction and the value placed on "reassurance" highlight a significant unmet need among general consumers for accessible, trustworthy security diagnostic tools. Defenders should recognize that even a "clean" scan provides substantial value to users by alleviating anxiety and validating their security posture. This suggests that public-facing, free, and easy-to-use diagnostic services can be a powerful tool for public engagement and awareness, complementing traditional threat intelligence and incident response.
Second, the study demonstrates the effectiveness of user-initiated services in driving remediation. The high remediation rates for malware (88%) and vulnerabilities (50%) among users who re-diagnosed indicate that when users are empowered to seek information and receive tailored advice, they are often motivated to act. This supports a shift towards more proactive, user-centric security models, rather than solely relying on reactive notifications from third parties. Organizations and governments should consider investing in or promoting similar services that allow individuals to "pull" security information rather than just "push" it.
However, significant obstacles to remediation persist, primarily related to user ability and financial constraints. Many users struggle with the technical complexity of identifying affected devices, understanding how to apply firmware updates, or changing complex settings. Defenders developing or promoting security advice must prioritize actionable, step-by-step guidance that minimizes technical jargon and addresses the practicalities of device operation. Providing direct support channels, even if only a small fraction of users utilize them, can be crucial for those who are motivated but lack the ability. Furthermore, the financial burden of replacing end-of-life or inherently insecure devices is a major barrier; policies or programs that subsidize secure device upgrades or offer trade-in incentives could significantly improve overall IoT security.
The study also underscores the importance of trustworthiness and communication clarity. Users expressed concerns about the authenticity of reminder emails and the service website itself, reflecting the pervasive threat of phishing. Defenders must employ robust email authentication (e.g., DMARC) and clearly communicate the legitimacy of their services. Operating under the umbrella of a respected, non-profit entity (like a university, as in this case) and avoiding advertisements can enhance user trust. Regular, non-intrusive prompts for re-diagnosis are beneficial, as users tend to forget, but these must be carefully designed to avoid appearing suspicious.
Finally, the phenomenon of false reassurance must be actively mitigated. While simplicity aids adoption, oversimplification can lead users to overestimate a service's capabilities. Diagnostic services should clearly communicate their scope and limitations, acknowledging potential false negatives. Providing options for more detailed technical information for expert users, while maintaining a simple interface for non-experts, can strike a balance between comprehensibility and accurate expectation-setting. This dual approach, offering "shortcuts" to advanced features, can cater to a broader spectrum of user expertise.
Key Takeaways
- User-initiated diagnostic services are highly valued: The "am I infected?" service demonstrated that users are eager for free, easy-to-use, and trustworthy web services that offer tailored security diagnoses for their IoT devices, with 96% of users rating it positively.
- Reassurance is a key benefit: Even when no issues are found, the service provides significant reassurance to users, highlighting the psychological value of security validation and the importance of addressing user anxiety about cyber threats.
- Effective remediation is achievable: The service successfully prompted remediation for a significant portion of affected users, with 88% of malware infections and 50% of vulnerabilities being addressed, proving that user-centric approaches can drive tangible security improvements.
- Ability and cost are major obstacles: Users often struggle with the technical complexity of identifying and operating devices for remediation, or face financial burdens when device replacement is necessary, indicating a need for more practical, actionable advice and potentially financial support mechanisms.
- Trust and consistent communication are crucial: Concerns about phishing and website authenticity underscore the importance of clear, trustworthy communication channels and operator credibility. Regular, non-suspicious reminders are necessary to encourage sustained security practices like re-diagnosis.
- Balance simplicity with detail: While ease of use is paramount for non-experts, the service should also consider providing more detailed diagnostic information for technically inclined users to fully satisfy their expectations and prevent false reassurance.
About the Speaker(s)
The "Am I Infected?" paper was authored by a collaborative team of researchers from Yokohama National University in Japan and Delft University of Technology in the Netherlands. The primary authors, Takayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Katsunari Yoshioka, and Tsutomu Matsumoto, are affiliated with Yokohama National University. Simon Parkin and Michel van Eeten hold affiliations with both Delft University of Technology and Yokohama National University. This interdisciplinary team brings expertise in areas such as network security, usable security, and the operation of large-scale systems, contributing to the comprehensive design, deployment, and evaluation of the "am I infected?" IoT security diagnostic service. Their work focuses on understanding user behavior in response to security threats and developing practical solutions to enhance consumer cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Solid empirical work with real operational data from 114k users over 27 months. The remediation rates (88% malware, 50% vulns) are the money shot—actual evidence that user-initiated diagnostics can work. Not groundbreaking technically, but the scale and longitudinal nature make it genuinely useful for anyone building consumer security tooling.
Heather Calloway (CISO) — SOLID
Solid operational research that answers a question most security programs ignore: what happens when you give consumers a free, low-friction way to diagnose their own IoT exposure? The remediation rates are credible, and the obstacles they surfaced — technical ability and replacement cost — are the same ones enterprise security teams hit when dealing with unmanaged devices.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)