DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity Keyboards
Xiaomeng Chen, Jike Wang, Zhenyu Chen, Qi Alfred Chen, Xinbing Wang, Dongyao Chen
Abstract
We discover that enabling both eavesdropping and non-invasive, per-key injection is viable on keyboards, in particular, the fast-emerging commodity Hall-effect keyboards. This paper introduces DualStrike, a new attack system that allows attackers to remotely listen to victim input and control any key on a Hall-effect keyboard. This capability opens doors to severe attacks (e.g., file deletion, private key theft, and tampering) based on the victim's input and context, all without requiring hardware or software modifications to the victim's computer. We present several key innovations in DualStrike, including a novel, compact electromagnet-based hardware design for high-frequency magnetic spoofing, a synchronization-free attack scheme, and a magnetometer-based listening mechanism using commercial off-the-shelf components. Our real-world experiments demonstrate that DualStrike can reliably compromise arbitrary keys across six recent Hall-effect keyboard models. Specifically, DualStrike achieves over 98.9% keystroke injection accuracy across all tested models. In an end-to-end test, the eavesdropping module achieves a high listening accuracy (i.e., above 99%). To improve the robustness of DualStrike, we implement a calibration algorithm to account for keyboard displacement, allowing it to maintain 98.5% injection accuracy even with offsets up to 4 cm. We also identified DualStrike's immunity to existing magnetic shielding mechanisms and proposed a novel shielding approach for Hall-effect keyboards. The demo video of DualStrike can be found in [30] .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fd367ee1-7fbb-4735-9b17-121b8ae9ca64Builds on9
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 34 citations
- Time-Print: Authenticating USB Flash Drives with Novel Timing FingerprintsPatrick Cronin, Xing Gao, Haining Wang, Chase CottonS&P 2022 · 16 citations
- VoltSchemer: Use Voltage Noise to Manipulate Your Wireless ChargerZihao Zhan, Yirui Yang, Haoqi Shan, Hanqiu Wang et al.USENIX Security 2024 · 10 citations
- Hall Spoofing: A Non-Invasive DoS Attack on Grid-Tied Solar InverterAnomadarshi Barua, Mohammad Abdullah Al FaruqueUSENIX Security 2020
- Every Signature is Broken: On the Insecurity of Microsoft Office's OOXML SignaturesSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger et al.USENIX Security 2023
Related papers
- GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of KeyboardsQinhong Jiang, Yanze Ren, Yan Long, Chen Yan et al.NDSS 2024
- RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, Huacheng ZengS&P 2026 · 2 citations
- Eavesdropping on Controller Acoustic Emanation for Keystroke Inference Attack in Virtual RealityShiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun et al.NDSS 2024
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
- TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath KeyboardsJiawei Li, Yan Zhang, Dianqi Han, Ang Li et al.INFOCOM 2026
