How to BREAK MU-MIMO Precoding in IEEE 802.11 Wi-Fi Networks
Francesca Meneghello, Francesco Gringoli, Marco Cominelli, Michele Rossi, Francesco Restuccia
Abstract
This work reveals a critical vulnerability of the Wi-Fi standard that if unaddressed, might lead to serious security issues and compromise the performance of several billions of Wi-Fi devices. Specifically, this paper introduces and validates with commercial off-the-shelf Wi-Fi devices a new Beamforming Report Eavesdropping Attack (BREAK), which leverages the MU-MIMO channel estimation procedure used by Wi-Fi to decrease the throughput of the entire network without being detected. Through rigorous mathematical optimization, we compute the poisoned feedback that a BREAK adversary needs to send to the access point to reduce the throughput of legitimate users. Through extensive experimental evaluation with commercial Wi-Fi routers and smartphones in multiple network configurations, we show that through BREAK, an adversary may decrease the throughput at legitimate stations by 65 % modifying only about 17 % of its feedback without being detected. For replicability, we shared the code implementing the attack together with the modified firmware to be used at the adversary node. A video demonstration of BREAK is also available11https://youtu.be/SeVt0PWZZ8o.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d5ee7fa7-911d-428d-a6d5-a30df44654fcRelated papers
- Beamforming made Malicious: Manipulating Wi-Fi Traffic via Beamforming Feedback ForgeryMingming Xu, Yinghui He, Xin Li, Jingzhi Hu et al.MobiCom 2024 · 10 citations
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 48 citations
- Password-Stealing without Hacking: Wi-Fi Enabled Practical Keystroke EavesdroppingJingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu et al.CCS 2023 · 34 citations
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsXuewei Feng, Qi Li, Kun Sun, Yuxiang Yang et al.S&P 2023
- Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFiRui Xiao, Xiankai Chen, Yinghui He, Jun Han et al.NDSS 2025
