WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data Injection
Changjia Zhu, Xiao Han, Parush Gera, Zhuo Lu, Tempestt Neal, Yao Liu
摘要
Traditional Wi-Fi Positioning System (WPS) spoofing attacks, while seemingly effective, have failed to raise major WPS security concerns due to their lack of stealth and persistence. This paper introduces a novel WILD Attack that undermines WPS security by subverting its core infrastructure–the Location Lookup Table (LLT). In this attack, an adversary remotely submits falsified crowd-sourced reports for target Wi-Fi access points, inducing WPS providers to update LLT based on falsified rather than legitimate data. We examine four widely deployed WPS providers–Google, Apple, A-Map, and WiGLE–and observe that they all accept falsified reports and apply distinct policies to resolve conflicts between legitimate and falsified data. Exploiting these policies, the attacker can induce two forms of LLT subversion: LLT Entry Tampering and LLT Entry Removal , both persisting for weeks even after the attacker ceases activity. We further present three case studies that show the real-world impact of the WILD Attack and propose countermeasures to mitigate such threats.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders 等S&P 2018 · 被引用 135 次
- Location Heartbleeding: The Rise of Wi-Fi Spoofing Attack Via Geolocation APIXiao Han, Junjie Xiong, Wenbo Shen, Zhuo Lu 等CCS 2022 · 被引用 7 次
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 被引用 5 次
- GNSS-WASP: GNSS Wide Area SPoofingChristopher Tibaldo, Harshad Sathaye, Giovanni Camurati, Srdjan CapkunUSENIX Security 2025
- IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level GeolocationErik C. Rye, Robert BeverlyS&P 2023
相关 Paper
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsXuewei Feng, Qi Li, Kun Sun, Yuxiang Yang 等S&P 2023
- A nationwide census on wifi security threats: prevalence, riskiness, and the economicsDi Gao, Hao Lin, Zhenhua Li, Feng Qian 等MobiCom 2021 · 被引用 14 次
- Security and Privacy Analysis of Tile's Location Tracking ProtocolAkshaya Kumar, Anna Raymaker, Michael A. SpecterUSENIX Security 2026 · 被引用 1 次
- A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination SystemsYilu Dong, Tianchang Yang, Arupjyoti Bhuyan, Syed Rafiul HussainNSDI 2026
- Graph-based Fingerprint Update Using Unlabelled WiFi SignalsKa Ho Chiu, Handi Yin, Weipeng Zhuo, Chul-Ho Lee 等UbiComp 2025 · 被引用 3 次
