XR Devices Send WiFi Packets When They Should Not: Cross-Building Keylogging Attacks via Non-Cooperative Wireless Sensing
Christopher Vattheuer, Justin Feng, Hossein Khalili, Nader Sehatbakhsh, Omid Abari
摘要
Angeles (UCLA) (1) Fake WiFi Packet (2) Ack Packet (4)"password" (3) Signal Processing 10s of meters Abstract-As Extended Reality (XR) technology continues to integrate into diverse fields, various security vulnerabilities-such as keystroke inference (keylogging)-have become a growing concern. Several keylogging attacks demonstrate the feasibility of exploiting this vulnerability using different modalities, including voice and vision. However, these attacks are often constrained by the need for line of sight (LoS) and/or close proximity (<10 meters). We propose a novel keylogging attack on XR devices leveraging WiFi wireless sensing. Unlike prior methods, our attack does not require LoS and is effective across various scenarios, including long-distance, cross-building settings (up to 30 meters). Our attack requires only a single, cheap, pocket-sized receiving setup to collect the victim's WiFi packets. Compared to previous keylogging attacks leveraging WiFi, our approach is the first to eliminate the need for a separate transmitter and receiver or a fake hotspot. As a result, unlike prior methods, our attack is effective even at large distances. The core idea hinges on exploiting a security vulnerability in WiFi chipsets. This vulnerability allows an attacker to send a fake, unencrypted packet to the victim's device, where, in response, the victim's device involuntarily and automatically transmits an acknowledgment ("ACK") packet. By leveraging this mechanism, we can continuously force the headset's WiFi chipset to transmit packets and therefore harvest large volumes of Channel State Information (CSI) data from the victim's headset. We then develop a novel unsupervised signal processing algorithm to exploit CSI data to perform pose estimation and locate the victim's hands and fingers, ultimately enabling keystroke inference. We evaluate our attack on Meta Quest 2 and Meta Quest 3 [1], [2] headsets under diverse conditions, including distances ranging from 1 meter to 30 meters, angles spanning from -90° to +90°, multiple users, and through-wall scenarios, demonstrating its robustness and effectiveness across a wide range of environments. Our attack achieves 78.6% top-25 accuracy across a building on passwords up to 15 characters long. I. INTRODUCTION Virtual and Augmented Reality, collectively known as Mixed/Extended Reality (XR), are transformative technologies that immerse users in customizable, interactive, and simulated environments. These advancements have revolutionized numerous sectors, making XR devices increasingly prevalent in many personal and public spaces [3], [4], [5], [6], [7], [8], [9].
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper19
- When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi SignalsMengyuan Li, Yan Meng, Junyi Liu, Haojin Zhu 等CCS 2016 · 被引用 213 次
- MUSE-Fi: Contactless MUti-person SEnsing Exploiting Near-field Wi-Fi Channel VariationJingzhi Hu, Tianyue Zheng, Zhe Chen, Hongbo Wang 等MobiCom 2023 · 被引用 72 次
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 被引用 70 次
- EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsYimin Chen, Tao Li, Rui Zhang, Yanchao Zhang 等S&P 2018 · 被引用 60 次
- No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your TypingSong Fang, Ian D. Markwood, Yao Liu, Shangqing Zhao 等CCS 2018 · 被引用 46 次
相关 Paper
- Eavesdropping on Controller Acoustic Emanation for Keystroke Inference Attack in Virtual RealityShiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun 等NDSS 2024
- mmSpyVR: Exploiting mmWave Radar for Penetrating Obstacles to Uncover Privacy Vulnerability of Virtual RealityLuoyu Mei, Ruofeng Liu, Zhimeng Yin, Qingchuan Zhao 等UbiComp 2025 · 被引用 13 次
- Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side ChannelTao Ni, Yuefeng Du, Qingchuan Zhao, Cong WangNDSS 2025
- GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR DevicesHanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai 等CCS 2024 · 被引用 16 次
- HoloLogger: Keystroke Inference on Mixed Reality Head Mounted DisplaysShiqing Luo, Xinyu Hu, Zhisheng YanIEEE VR 2022 · 被引用 30 次
