Turning Everyday Earphones into a Full-Duplex Speech Eavesdropping Platform via Zero-permission IMU
Ming Gao, Ayijiaken Amantai, Yichen Dai, Jia Lv, Kaiyan Cui, Jinsong Han, Minhao Cui, Fu Xiao
Abstract
With the rapid development of wearable electronics, commercial off-the-shelf earphones have been widely adopted in daily life. Inertial Measurement Units (IMUs) are standard hardware on modern earphones, which are originally designed for motion detection and user interaction. When sound propagates through the earphone structure, it will induce tiny physical vibrations, which can be recorded by built-in IMUs. Such physical responses can be exploited as a side channel to recover speech content, leading to serious privacy threats. Different from traditional audio eavesdropping methods, this work focuses on zero-permission IMU side-channel attacks, which requires no audio access or privileged permissions from the operating system. Considering the practical constraints including ultra-low sampling rate (25 Hz) and strong motion noise in real-world deployment, we propose an integrated solution combining multi-axial sensor data fusion, dual-stream attention networks, feature pyramid structures and conditional generative adversarial networks (CGAN). The system supports full-duplex and open-vocabulary speech recognition, and is capable of separating and recognizing mixed signals from human speech and on-device audio playback. This repository releases the complete implementation of the proposed framework, including raw data processing pipelines, feature extraction modules, inference engines, image denoising and cross-sensor conversion tools. We also release near-end and far-end IMU samples, category label files and well-trained model weights for validation. Due to privacy protection regulations, full datasets are not publicly available. The released codes and resources can be used for algorithm verification, performance evaluation and security research on wearable device side-channel vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c29e55ec-b05b-4d5e-8c22-bfc20565bdf8Builds on24
- Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial SensorsYazhou Tu, Zhiqiang Lin, Insup Lee, Xiali HeiUSENIX Security 2018 · 132 citations
- Speechless: Analyzing the Threat to Speech Privacy from Smartphone Motion SensorsS. Abhishek Anand, Nitesh SaxenaS&P 2018 · 110 citations
- IMUPoser: Full-Body Pose Estimation using IMUs in Phones, Watches, and EarbudsVimal Mollyn, Riku Arakawa, Mayank Goel, Chris Harrison et al.CHI 2023 · 103 citations
- Face-Mic: inferring live speech and speaker identity via subtle facial dynamics captured by AR/VR motion sensorsCong Shi, Xiangyu Xu, Tianfang Zhang, Payton Walker et al.MobiCom 2021 · 89 citations
- UltraSE: single-channel speech enhancement using ultrasoundKe Sun, Xinyu ZhangMobiCom 2021 · 69 citations
Related papers
- InertiEAR: Automatic and Device-independent IMU-based Eavesdropping on SmartphonesMing Gao, Yajie Liu, Yike Chen, Yimin Li et al.INFOCOM 2022 · 18 citations
- VibSpeech: Exploring Practical Wideband Eavesdropping via Bandlimited Signal of Vibration-based Side ChannelChao Wang, Feng Lin, Hao Yan, Tong Wu et al.USENIX Security 2024 · 16 citations
- Learning-based Practical Smartphone Eavesdropping with Built-in AccelerometerZhongjie Ba, Tianhang Zheng, Xinyu Zhang, Zhan Qin et al.NDSS 2020
- EveGuard: Defeating Vibration-based Side-Channel Eavesdropping with Audio Adversarial PerturbationsJung-Woo Chang, Ke Sun, David Xia, Xinyu Zhang et al.S&P 2025
- I Can Hear You Without a Microphone: Live Speech Eavesdropping From Earphone Motion SensorsYetong Cao, Fan Li, Huijie Chen, Xiaochen Liu et al.INFOCOM 2023 · 16 citations
