No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your Typing
Song Fang, Ian D. Markwood, Yao Liu, Shangqing Zhao, Zhuo Lu, Haojin Zhu
Abstract
Traditional methods to eavesdrop keystrokes leverage some malware installed in a target computer to record the keystrokes for an adversary. Existing research work has identified a new class of attacks that can eavesdrop the keystrokes in a non-invasive way without infecting the target computer to install a malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks.
In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from wireless signal. To eavesdrop keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. We implement this attack on software-defined radio platforms and conduct a suite of experiments to validate the impact of this attack. We point out that this paper does not propose to use wireless signal for inferring keystrokes, since such work already exists. Instead, the main goal of this paper is to propose new techniques to remove the training process, which can make existing work unpractical.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2e1a3419-00b4-4eca-a9a8-72b6557630c8Cited by top-tier papers12
- WaveSpy: Remote and Through-wall Screen Attack via mmWave SensingZhengxiong Li, Fenglong Ma, Aditya Singh Rathore, Zhuolin Yang et al.S&P 2020 · 40 citations
- Password-Stealing without Hacking: Wi-Fi Enabled Practical Keystroke EavesdroppingJingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu et al.CCS 2023 · 34 citations
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 34 citations
- MIMOCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO EncryptionJun Luo, Hangcheng Cao, Hongbo Jiang, Yanbing Yang et al.S&P 2024 · 28 citations
- RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, Huacheng ZengS&P 2026 · 2 citations
Builds on2
- When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi SignalsMengyuan Li, Yan Meng, Junyi Liu, Haojin Zhu et al.CCS 2016 · 213 citations
- VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside MotionJingchao Sun, Xiaocong Jin, Yimin Chen, Jinxue Zhang et al.NDSS 2016 · 72 citations
Related papers
- WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisEdwin Yang, Qiuye He, Song FangCCS 2022 · 14 citations
- Silent Thief: Password Eavesdropping Leveraging Wi-Fi Beamforming Feedback from POS TerminalSiyu Chen, Hongbo Jiang, Jingyang Hu, Zhu Xiao et al.INFOCOM 2024 · 10 citations
- TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath KeyboardsJiawei Li, Yan Zhang, Dianqi Han, Ang Li et al.INFOCOM 2026
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
