Broken Hearted: How To Attack ECG Biometrics
Simon Eberz, Nicola Paoletti, Marc Roeschlin, Andrea Patané, Marta Kwiatkowska, Ivan Martinovic
Abstract
In this work we present a systematic presentation attack against ECG biometrics. We demonstrate the attack's effectiveness using the Nymi Band, a wrist band that uses electrocardiography (ECG) as a biometric to authenticate the wearer. We instantiate the attack using a hardware-based Arbitrary Waveform Generator (AWG), an AWG software using a computer sound card, and the playback of ECG signals encoded as .wav files using an off-the-shelf audio player. In two sets of experiments we collect data from a total of 41 participants using a variety of ECG monitors, including a medical monitor, a smartphone-based mobile monitor and the Nymi Band itself. We use the first dataset to understand the statistical differences in biometric features that arise from using different measurement devices and modes. Such differences are addressed through the automated derivation of so-called mapping functions, whose purpose is to transform ECG signals from any device in order to resemble the morphology of the signals recorded with the Nymi Band. As part of our second dataset, we enroll users into the Nymi Band and test whether data from any of our sources can be used for a signal injection attack. Using data collected directly on the Nymi Band we achieve a success rate of 81%. When only using data gathered on other devices, this rate decreases to 43% when using raw data, and 62% after applying the mapping function. While we demonstrate the attack on the Nymi Band, we expect other ECG-based authentication systems to most likely suffer from the same, fundamental weaknesses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ba3f5155-9995-4198-b3fb-8516adcb882fCited by top-tier papers6
- 28 Blinks Later: Tackling Practical Challenges of Eye Movement BiometricsSimon Eberz, Giulio Lovisotto, Kasper Bonne Rasmussen, Vincent Lenders et al.CCS 2019 · 39 citations
- User Authentication via Electrical Muscle StimulationYuxin Chen, Zhuolin Yang, Ruben Abbou, Pedro Lopes et al.CHI 2021 · 35 citations
- When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across ContextsSimon Eberz, Giulio Lovisotto, Andrea Patane, Marta Kwiatkowska et al.S&P 2018 · 29 citations
- Heartbeats in the Wild: A Field Study Exploring ECG Biometrics in Everyday LifeFlorian Lehmann, Daniel BuschekCHI 2020 · 15 citations
- Biosignal Authentication Considered Harmful TodayVeena Krish, Nicola Paoletti, Milad Kazemi, Scott A. Smolka et al.USENIX Security 2024 · 2 citations
Builds on1
Related papers
- Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPGWei Shao, Zequan Liang, Ruoyu Zhang, Ruijie Fang et al.NDSS 2026 · 7 citations
- TrueHeart: Continuous Authentication on Wrist-worn Wearables Using PPG-based BiometricsTianming Zhao, Yan Wang, Jian Liu, Yingying Chen et al.INFOCOM 2020 · 91 citations
- NF-Heart: A Near-field Non-contact Continuous User Authentication System via BallistocardiogramYandao Huang, Minghui Qiu, Lin Chen, Zhencan Peng et al.UbiComp 2023 · 11 citations
- My(o) Armband Leaks Passwords: An EMG and IMU Based Keylogging Side-Channel AttackMatthias Gazzari, Annemarie Mattmann, Max Maass, Matthias HollickUbiComp 2022 · 12 citations
- SwipePass: Acoustic-based Second-factor User Authentication for SmartphonesYongliang Chen, Tao Ni, Weitao Xu, Tao GuUbiComp 2022 · 26 citations
