IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi Traffic
Qingsong Zou, Qing Li, Ruoyu Li, Yucheng Huang, Gareth Tyson, Jingyu Xiao, Yong Jiang
Abstract
With the deployment of a growing number of smart home IoT devices, privacy leakage has become a growing concern. Prior work on privacy-invasive device localization, classification, and activity identification have proven the existence of various privacy leakage risks in smart home environments. However, they only demonstrate limited threats in real world due to many impractical assumptions, such as having privileged access to the user's home network. In this paper, we identify a new end-to-end attack surface using IoTBeholder, a system that performs device localization, classification, and user activity identification. IoTBeholder can be easily run and replicated on commercial off-the-shelf (COTS) devices such as mobile phones or personal computers, enabling attackers to infer user's habitual behaviors from smart home Wi-Fi traffic alone. We set up a testbed with 23 IoT devices for evaluation in the real world. The result shows that IoTBeholder has good device classification and device activity identification performance. In addition, IoTBeholder can infer the users' habitual behaviors and automation rules with high accuracy and interpretability. It can even accurately predict the users' future actions, highlighting a significant threat to user privacy that IoT vendors and users should highly concern.
CCS Concepts: • Security and privacy → Human and societal aspects of security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 789a7a66-b100-419e-ab3d-a5005966d7fbCited by top-tier papers3
- Make Your Home Safe: Time-aware Unsupervised User Behavior Anomaly Detection in Smart Homes via Loss-guided MaskJingyu Xiao, Zhiyao Xu, Qingsong Zou, Qing Li et al.KDD 2024 · 12 citations
- Dissect Black Box: Interpreting for Rule-Based Explanations in Unsupervised Anomaly DetectionYu Zhang, Ruoyu Li, Nengwu Wu, Qing Li et al.NeurIPS 2024 · 7 citations
- WiFinger: Fingerprinting Noisy IoT Event Traffic Using Packet-level Sequence MatchingRonghua Li, Shinan Liu, Haibo Hu, Qingqing Ye et al.NDSS 2026 · 6 citations
Builds on12
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
- IoT Inspector: Crowdsourcing Labeled Network Traffic from Smart Home Devices at ScaleDanny Yuxing Huang, Noah J. Apthorpe, Frank Li, Gunes Acar et al.UbiComp 2020 · 171 citations
- HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart HomesChenglong Fu, Qiang Zeng, Xiaojiang DuUSENIX Security 2021 · 109 citations
Related papers
- IoTMosaic: Inferring User Activities from IoT Network Traffic in Smart HomesYinxin Wan, Kuai Xu, Feng Wang, Guoliang XueINFOCOM 2022 · 18 citations
- Discovering and Exploiting IoT Device Hidden Attributes: A New Vulnerability in Smart HomesXuening Xu, Chenglong Fu, Xiaojiang Du, Bo LuoCCS 2025
- Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and DevicesChris Xiaoxuan Lu, Yang Li, Yuanbo Xiangli, Zhengxiong LiWWW 2020 · 3 citations
- Extracting Spatial Information of IoT Device Events for Smart Home Safety MonitoringYinxin Wan, Xuanli Lin, Kuai Xu, Feng Wang et al.INFOCOM 2023 · 5 citations
- HoMonit: Monitoring Smart Home Apps from Encrypted TrafficWei Zhang, Yan Meng, Yugeng Liu, Xiaokuan Zhang et al.CCS 2018 · 201 citations
