Hand Me Your PIN! Inferring ATM PINs of Users Typing with a Covered Hand
Matteo Cardaioli, Stefano Cecconello, Mauro Conti, Simone Milani, Stjepan Picek, Eugen Saraci
摘要
Automated Teller Machines (ATMs) represent the most used system for withdrawing cash. The European Central Bank reported more than 11 billion cash withdrawals and loading/unloading transactions on the European ATMs in 2019. Although ATMs have undergone various technological evolutions, Personal Identification Numbers (PINs) are still the most common authentication method for these devices. Unfortunately, the PIN mechanism is vulnerable to shoulder-surfing attacks performed via hidden cameras installed near the ATM to catch the PIN pad. To overcome this problem, people get used to covering the typing hand with the other hand. While such users probably believe this behavior is safe enough to protect against mentioned attacks, there is no clear assessment of this countermeasure in the scientific literature. This paper proposes a novel attack to reconstruct PINs entered by victims covering the typing hand with the other hand. We consider the setting where the attacker can access an ATM PIN pad of the same brand/model as the target one. Afterward, the attacker uses that model to infer the digits pressed by the victim while entering the PIN. Our attack owes its success to a carefully selected deep learning architecture that can infer the PIN from the typing hand position and movements. We run a detailed experimental analysis including 58 users. With our approach, we can guess 30% of the 5-digit PINs within three attempts -- the ones usually allowed by ATM before blocking the card. We also conducted a survey with 78 users that managed to reach an accuracy of only 7.92% on average for the same setting. Finally, we evaluate a shielding countermeasure that proved to be rather inefficient unless the whole keypad is shielded.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Password-Stealing without Hacking: Wi-Fi Enabled Practical Keystroke EavesdroppingJingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu 等CCS 2023 · 被引用 34 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side ChannelsTao Ni, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 等S&P 2023
它引用的顶会 Paper4
- Cracking Android Pattern Lock in Five AttemptsGuixin Ye, Zhanyong Tang, Dingyi Fang, Xiaojiang Chen 等NDSS 2017 · 被引用 123 次
- VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside MotionJingchao Sun, Xiaocong Jin, Yimin Chen, Jinxue Zhang 等NDSS 2016 · 被引用 72 次
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 被引用 34 次
- Mind the Portability: A Warriors Guide through Realistic Profiled Side-channel AnalysisShivam Bhasin, Anupam Chattopadhyay, Annelie Heuser, Dirmanto Jap 等NDSS 2020
相关 Paper
- ArmSpy: Video-assisted PIN Inference Leveraging Keystroke-induced Arm Posture ChangesYuefeng Chen, Yicong Du, Chunlong Xu, Yanghai Yu 等INFOCOM 2022 · 被引用 4 次
- Towards a General Video-based Keystroke Inference AttackZhuolin Yang, Yuxin Chen, Zain Sarwar, Hadleigh Schwartz 等USENIX Security 2023
- Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics LibrariesDaimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh 等NDSS 2019 · 被引用 47 次
- Modeling Deep Learning Based Privacy Attacks on Physical MailBingyao Huang, Ruyi Lian, Dimitris Samaras, Haibin LingAAAI 2021
- Hidden Reality: Caution, Your Hand Gesture Inputs in the Immersive Virtual World are Visible to All!Sindhu Reddy Kalathur Gopal, Diksha Shukla, James David Wheelock, Nitesh SaxenaUSENIX Security 2023
