Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and Devices
Chris Xiaoxuan Lu, Yang Li, Yuanbo Xiangli, Zhengxiong Li
Abstract
Along with the benefits of Internet of Things (IoT) come potential privacy risks, since billions of the connected devices are granted permission to track information about their users and communicate it to other parties over the Internet. Of particular interest to the adversary is the user identity which constantly plays an important role in launching attacks. While the exposure of a certain type of physical biometrics or device identity is extensively studied, the compound effect of leakage from both sides remains unknown in multi-modal sensing environments. In this work, we explore the feasibility of the compound identity leakage across cyber-physical spaces and unveil that co-located smart device IDs (e.g., smartphone MAC addresses) and physical biometrics (e.g., facial/vocal samples) are side channels to each other. It is demonstrated that our method is robust to various observation noise in the wild and an attacker can comprehensively profile victims in multi-dimension with nearly zero analysis effort. Two real-world experiments on different biometrics and device IDs show that the presented approach can compromise more than 70% of device IDs and harvests multiple biometric clusters with ∼ 94% purity at the same time. CCS CONCEPTS • Security and privacy → Pseudonymity, anonymity and untraceability; • Human-centered computing → Ubiquitous and mobile computing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on1
Related papers
- IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi TrafficQingsong Zou, Qing Li, Ruoyu Li, Yucheng Huang et al.UbiComp 2023 · 24 citations
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
- Deanonymizing Device Identities via Side-channel Attacks in Exclusive-use IoTs & MitigationChristopher Ellis, Yue Zhang, Mohit Kumar Jangid, Shixuan Zhao et al.NDSS 2025
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- Mind the Portability: A Warriors Guide through Realistic Profiled Side-channel AnalysisShivam Bhasin, Anupam Chattopadhyay, Annelie Heuser, Dirmanto Jap et al.NDSS 2020
