Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic Emanations
Wenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming Li
摘要
This study presents Periscope, a novel side-channel attack that exploits human-coupled electromagnetic (EM) emanations from touchscreens to infer sensitive inputs on a mobile device. Periscope is motivated by the observation that finger movement over the touchscreen leads to time-varying coupling between these two. Consequently, it impacts the screen's EM emanations that can be picked up by a remote sensory device. We intend to map between EM measurements and finger movements to recover the inputs. As the significant technical contribution of this work, we build an analytic model that outputs finger movement trajectories based on given EM readings. Our approach does not need a large amount of labeled dataset for offline model training, but instead a couple of samples to parameterize the user-specific analytic model. We implement Periscope with simple electronic components and conduct a suite of experiments to validate this attack's impact. Experimental results show that Periscope achieves a recovery rate over 6-digit PINs of 56.2% from a distance of 90 cm. Periscope is robust against environment dynamics and can well adapt to different device models and setting contexts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelTao Ni, Xiaokuan Zhang, Qingchuan ZhaoCCS 2023 · 被引用 34 次
- Password-Stealing without Hacking: Wi-Fi Enabled Practical Keystroke EavesdroppingJingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu 等CCS 2023 · 被引用 34 次
- Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot LearningTao Ni, Jianfeng Li, Xiaokuan Zhang, Chaoshun Zuo 等MobiCom 2023 · 被引用 27 次
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar 等USENIX Security 2024 · 被引用 26 次
- MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage SignalsRui Xiao, Tianyu Li, Soundarya Ramesh, Jun Han 等MobiCom 2023 · 被引用 20 次
它引用的顶会 Paper7
- When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi SignalsMengyuan Li, Yan Meng, Junyi Liu, Haojin Zhu 等CCS 2016 · 被引用 213 次
- VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside MotionJingchao Sun, Xiaocong Jin, Yimin Chen, Jinxue Zhang 等NDSS 2016 · 被引用 72 次
- EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsYimin Chen, Tao Li, Rui Zhang, Yanchao Zhang 等S&P 2018 · 被引用 60 次
- No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your TypingSong Fang, Ian D. Markwood, Yao Liu, Shangqing Zhao 等CCS 2018 · 被引用 46 次
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 被引用 39 次
相关 Paper
- Eavesdropping on Black-box Mobile Devices via Audio Amplifier's EMRHuiling Chen, Wenqiang Jin, Yupeng Hu, Zhenyu Ning 等NDSS 2024
- Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic DevicesHaoqi Shan, Boyi Zhang, Zihao Zhan, Dean Sullivan 等S&P 2022 · 被引用 17 次
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 被引用 24 次
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 被引用 62 次
- GhostTouch: Targeted Attacks on Touchscreens without Physical TouchKai Wang, Richard Mitev, Chen Yan, Xiaoyu Ji 等USENIX Security 2022
