Broken Hearted: How To Attack ECG Biometrics
Simon Eberz, Nicola Paoletti, Marc Roeschlin, Andrea Patané, Marta Kwiatkowska, Ivan Martinovic
摘要
In this work we present a systematic presentation attack against ECG biometrics. We demonstrate the attack's effectiveness using the Nymi Band, a wrist band that uses electrocardiography (ECG) as a biometric to authenticate the wearer. We instantiate the attack using a hardware-based Arbitrary Waveform Generator (AWG), an AWG software using a computer sound card, and the playback of ECG signals encoded as .wav files using an off-the-shelf audio player. In two sets of experiments we collect data from a total of 41 participants using a variety of ECG monitors, including a medical monitor, a smartphone-based mobile monitor and the Nymi Band itself. We use the first dataset to understand the statistical differences in biometric features that arise from using different measurement devices and modes. Such differences are addressed through the automated derivation of so-called mapping functions, whose purpose is to transform ECG signals from any device in order to resemble the morphology of the signals recorded with the Nymi Band. As part of our second dataset, we enroll users into the Nymi Band and test whether data from any of our sources can be used for a signal injection attack. Using data collected directly on the Nymi Band we achieve a success rate of 81%. When only using data gathered on other devices, this rate decreases to 43% when using raw data, and 62% after applying the mapping function. While we demonstrate the attack on the Nymi Band, we expect other ECG-based authentication systems to most likely suffer from the same, fundamental weaknesses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- 28 Blinks Later: Tackling Practical Challenges of Eye Movement BiometricsSimon Eberz, Giulio Lovisotto, Kasper Bonne Rasmussen, Vincent Lenders 等CCS 2019 · 被引用 39 次
- User Authentication via Electrical Muscle StimulationYuxin Chen, Zhuolin Yang, Ruben Abbou, Pedro Lopes 等CHI 2021 · 被引用 35 次
- When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across ContextsSimon Eberz, Giulio Lovisotto, Andrea Patane, Marta Kwiatkowska 等S&P 2018 · 被引用 29 次
- Heartbeats in the Wild: A Field Study Exploring ECG Biometrics in Everyday LifeFlorian Lehmann, Daniel BuschekCHI 2020 · 被引用 15 次
- Biosignal Authentication Considered Harmful TodayVeena Krish, Nicola Paoletti, Milad Kazemi, Scott A. Smolka 等USENIX Security 2024 · 被引用 2 次
它引用的顶会 Paper1
相关 Paper
- Know Me by My Pulse: Toward Practical Continuous Authentication on Wearable Devices via Wrist-Worn PPGWei Shao, Zequan Liang, Ruoyu Zhang, Ruijie Fang 等NDSS 2026 · 被引用 7 次
- TrueHeart: Continuous Authentication on Wrist-worn Wearables Using PPG-based BiometricsTianming Zhao, Yan Wang, Jian Liu, Yingying Chen 等INFOCOM 2020 · 被引用 91 次
- NF-Heart: A Near-field Non-contact Continuous User Authentication System via BallistocardiogramYandao Huang, Minghui Qiu, Lin Chen, Zhencan Peng 等UbiComp 2023 · 被引用 11 次
- My(o) Armband Leaks Passwords: An EMG and IMU Based Keylogging Side-Channel AttackMatthias Gazzari, Annemarie Mattmann, Max Maass, Matthias HollickUbiComp 2022 · 被引用 12 次
- SwipePass: Acoustic-based Second-factor User Authentication for SmartphonesYongliang Chen, Tao Ni, Weitao Xu, Tao GuUbiComp 2022 · 被引用 26 次
