S3: Side-Channel Attack on Stylus Pencil through Sensors
Habiba Farrukh, Tinghan Yang, Hanwen Xu, Yuxuan Yin, He Wang, Z. Berkay Celik
Abstract
With smart devices being an essential part of our everyday lives, unsupervised access to the mobile sensors' data can result in a multitude of side-channel attacks. In this paper, we study potential data leaks from Apple Pencil (2 nd generation) supported by the Apple iPad Pro, the latest stylus pen which attaches to the iPad body magnetically for charging. We observe that the Pencil's body affects the magnetic readings sensed by the iPad's magnetometer when a user is using the Pencil. Therefore, we ask: Can we infer what a user is writing on the iPad screen with the Apple Pencil, given access to only the iPad's motion sensors' data? To answer this question, we present Side-channel attack on Stylus pencil through Sensors (𝑆 3 ), a system that identifies what a user is writing from motion sensor readings. We first use the sharp fluctuations in the motion sensors' data to determine when a user is writing on the iPad. We then introduce a high-dimensional particle filter to track the location and orientation of the Pencil during usage. Lastly, to guide particles, we build the Pencil's magnetic map serving as a bridge between the measured magnetic data and the Pencil location and orientation. We evaluate 𝑆 3 with 10 subjects and demonstrate that we correctly identify 93.9%, 96%, 97.9%, and 93.33% of the letters, numbers, shapes, and words by only having access to the motion sensors' data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6bc862f4-7f3f-4c72-b05f-f95eb1ebbfa2Cited by top-tier papers2
- Shadowed Realities: An Investigation of UI Attacks in WebXRChandrika Mukherjee, Reham Mohamed, Arjun Arunasalam, Habiba Farrukh et al.USENIX Security 2025
- One Key to Rule Them All: Secure Group Pairing for Heterogeneous IoT DevicesHabiba Farrukh, Muslum Ozgur Ozmen, Faik Kerem Örs, Z. Berkay CelikS&P 2023
Builds on2
Related papers
- My Smartphone Knows What You Print: Exploring Smartphone-based Side-channel Attacks Against 3D PrintersChen Song, Feng Lin, Zhongjie Ba, Kui Ren et al.CCS 2016 · 122 citations
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 34 citations
- OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOSXiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang et al.NDSS 2018 · 34 citations
- Leave Your Phone at the Door: Side Channels that Reveal Factory Floor SecretsAvesta Hojjati, Anku Adhikari, Katarina Struckmann, Edward Chou et al.CCS 2016 · 78 citations
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 62 citations
