KeyPrint: Practical Black-box Keystroke Inference Attacks to Mobile Devices
Yunpeng Feng, Daibo Liu, Wenqiang Jin, Liangyi Gong
Abstract
Recent years have shown substantial interest in revealing vulnerability issues of keystroke privacy on smartphones and tablets. While significant prior works have leveraged different techniques to compromise the keystroke security of these mobile devices, existing methods are typically executed on the basic assumption of white-box scenarios where the adversary possesses prior knowledge of the victim's device and usage behavior, or they are conducted within a pre-set trap attack environment. These limitations undermine the practicality and real-world applicability of the proposed methods. In this paper, we present KeyPrint, a practical black-box keystroke inference attack system for mobile devices, without requiring any prior knowledge of the victims and attack scenarios. The primary innovation of KeyPrint is the ability to leverage both on-device acoustic source and attenuation path disparities in device medium to create the fingerprint of keystroke position. To enable their differentiation, we design a theoretical model to represent the keystroke position with the keystroke-induced sonic effect (KiSe) captured by built-in microphones. We also propose a novel approach to mitigate the impact of ambient noise and detect keystroke events, which improves KeyPrint's wide-adaptability. Finally, we propose using machine learning to cluster KiSe samples and infer keystroke content from unlabelled clustering results. We implemented KeyPrint on commercial smartphones/tablets and evaluate the prototypes in typical indoor and outdoor scenarios using different mobile devices. Experiments results demonstrate that KeyPrint can achieve an average accuracy of 55% and 70% for inference on keystroke content when the number of inputted words only reaches 30 and 40, respectively. Leveraging the spatial correlation between numeric and letter keys within the virtual keyboard, KeyPrint effectively reduces the search space for PINs from 10 digits to 10 candidates, with a probability of 63.9%.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6b507030-61eb-4167-b356-14db5bef9abdCited by top-tier papers1
Ask how each one uses itRelated papers
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
- Listen to Your Fingers: User Authentication Based on Geometry Biometrics of Touch GestureHuijie Chen, Fan Li, Wan Du, Song Yang et al.UbiComp 2020 · 49 citations
- Towards a General Video-based Keystroke Inference AttackZhuolin Yang, Yuxin Chen, Zain Sarwar, Hadleigh Schwartz et al.USENIX Security 2023
- TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath KeyboardsJiawei Li, Yan Zhang, Dianqi Han, Ang Li et al.INFOCOM 2026
- Eavesdropping on Controller Acoustic Emanation for Keystroke Inference Attack in Virtual RealityShiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun et al.NDSS 2024
