Practical Adversarial Attack on WiFi Sensing Through Unnoticeable Communication Packet Perturbation
Changming Li, Mingjing Xu, Yicong Du, Limin Liu, Cong Shi, Yan Wang, Hongbo Liu, Yingying Chen
Abstract
The pervasive use of WiFi has driven the recent research in WiFi sensing, converting communication tech into sensing for applications such as activity recognition, user authentication, and vital sign monitoring. Despite the integration of deep learning into WiFi sensing systems, potential security vulnerabilities to adversarial attacks remain unexplored. This paper introduces the first physical attack focusing on deep learning-based WiFi sensing systems, demonstrating how adversaries can subtly manipulate WiFi packet preambles to affect channel state information (CSI), a critical feature in such systems, and thereby influence underlying deep learning models without disrupting regular communication. To realize the proposed attack in practical scenarios, we rigorously analyze and derive the intricate relationship between the pilot symbol and CSI. A novel mechanism is proposed to facilitate quantitive control of receiver-side CSI through minimal modifications to the pilot symbols of WiFi packets at the transmitter. We further develop a perturbation optimization method based on the Carlini & Wagner (CW) attack and a penalty-based training process to ensure the attack's universal efficacy across various CSI responses and noise. The physical attack is implemented and evaluated in two representative WiFi sensing systems (i.e., activity recognition and user authentication) with 35 participants over 3 months. Extensive experiments demonstrate the remarkable attack success rates of 90.47% and 83.83% for activity recognition and user authentication, respectively.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b78cd863-47a4-49d4-a7fc-4b41430d80a1Cited by top-tier papers3
- Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFiRui Xiao, Xiankai Chen, Yinghui He, Jun Han et al.NDSS 2025
- DiffLoc: WiFi Hidden Camera Localization Based on Electromagnetic DiffractionXiang Zhang, Jie Zhang, Huan Yan, Jinyang Huang et al.USENIX Security 2025
- Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication SystemsJung-Woo Chang, Ke Sun, Nasimeh Heydaribeni, Seira Hidano et al.NDSS 2025
Related papers
- Physical-World Attack towards WiFi-based Behavior RecognitionJianwei Liu, Yinghui He, Chaowei Xiao, Jinsong Han et al.INFOCOM 2022 · 25 citations
- WiAdv: Practical and Robust Adversarial Attack against WiFi-based Gesture Recognition SystemYuxuan Zhou, Huangxun Chen, Chenyu Huang, Qian ZhangUbiComp 2022 · 31 citations
- Poisoning Attacks on Deep Learning based Wireless Traffic PredictionTianhang Zheng, Baochun LiINFOCOM 2022 · 32 citations
- Attacking mmWave-enabled Chest Vibration Sensing via Actuator-induced MimicryXiaonan Guo, Yi Wei, Yuan Ge, Yucheng Xie et al.INFOCOM 2026
- UniFi: A Unified Framework for Generalizable Gesture Recognition with Wi-Fi Signals Using Consistency-guided Multi-View NetworksYan Liu, Anlan Yu, Leye Wang, Bin Guo et al.UbiComp 2024 · 57 citations
