Acoustic Eavesdropping through Wireless Vibrometry

Slides:



Advertisements
Similar presentations
OFDM Transmission over Wideband Channel
Advertisements

We Can Hear You with Wi-Fi !
Data Communication lecture10
Dirty RF Impact on Interference Alignment
Introduction to Ultra WideBand Systems
Analog Network Coding Sachin Katti Shyamnath Gollakota and Dina Katabi.
Whole-Home Gesture Recognition Using Wireless Signals —— MobiCom’13 Author: Qifan Pu et al. University of Washington Presenter: Yanyuan Qin & Zhitong Fei.
Software Defined Radio Testbed Team may11-18 Members: Alex Dolan, Mohammad Khan, Ahmet Unsal Adviser: Dr. Aditya Ramamoorthy.
1 Dhwani : Peer–Peer Secure Acoustic NFC Rajalakshmi Nandakumar Krishna Chintalapudi Venkata Padmanabhan Ramarathnam Venkatesan Microsoft Research India.
1 Mobile Communication Systems 1 Prof. Carlo Regazzoni Prof. Fabio Lavagetto.
Can we get Wi-Fi connectivity for 15 µW? Bryce Kellogg.
Harbin Institute of Technology (Weihai) 1 Chapter 2 Channel Measurement and simulation  2.1 Introduction  Experimental and simulation techniques  The.
MIMO and TCP: A CASE for CROSS LAYER DESIGN Soon Y. Oh, Mario Gerla Computer Science Dept. University of California, Los Angeles {soonoh,
Wireless communication channel
SourceSync: A Distributed Architecture for Sender Diversity Hariharan Rahul Haitham Hassanieh Dina Katabi.
Combating Cross-Technology Interference Shyamnath Gollakota Fadel Adib Dina Katabi Srinivasan Seshan.
Doc.: IEEE /1399r0 Submission November 2014 Multi-Carrier Training Field for OFDM Transmission in aj (45GHz) Authors/contributors: Date:
work including Performance of DSP-based TX-RX emulator Contribution to WP2 and WP3 Daniele Borio, Laura Camoriano, Letizia Lo Presti.
Technical Seminar Presented by :- Debabandana Apta (EC ) National Institute of Science and Technology [1] “ECHO CANCELLATION” Presented.
mTrack: High-Precision Passive Tracking Using Millimeter Wave Radios
Doc.: IEEE /0364r1 SubmissionEldad Perahia, Intel CorporationSlide 1 Date: Authors: Antenna Array Gain from Measured Data for n/ac.
Support WiFi and LTE Co-existence
EELE 5490, Fall, 2009 Wireless Communications Ali S. Afana Department of Electrical Engineering Class 5 Dec. 4 th, 2009.
SMACK: Smart ACKnowledgment Scheme for Broadcast Messages in Wireless Networks Aveek Dutta, Dola Saha, Dirk Grunwald, Douglas Sicker, University of Colorado.
Keystroke Recognition using WiFi Signals
Doc.: IEEE d_Intra-Device_Propagation_Measuremets Submission March 2015 Slide 1 Project: IEEE P Working Group for Wireless Personal.
Harnessing Frequency Diversity in Wi-Fi Networks Apurv Bhartia Yi-Chao Chen Swati Rallapalli Lili Qiu MobiCom 2011, Las Vegas, NV The University of Texas.
Statistical Description of Multipath Fading
A Simple Transmit Diversity Technique for Wireless Communications -M
Doc.: IEEE /1398r0 Submission November 2014 Slide 1 Shiwen He, Haiming Wang Preamble Sequence for IEEE aj (45GHz) Authors/contributors:
Turning a Mobile Device into a Mouse in the Air
Acoustic Eavesdropping through Wireless Vibrometry University of Wisconsin – Madison, Chinese Academy of Sciences School of Electronic Information and.
1 Yue Qiao, Ouyang Zhang, Wenjie Zhou, Kannan Srinivasan and Anish Arora Department of Computer Science and Engineering PhyCloak: Obfuscating Sensing from.
Technology training (Session 6)
Teng Wei and Xinyu Zhang
When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi Signals Adekemi Adedokun May 2, 2017.
B2W2 N-Way Concurrent Communication for IoT Devices
1.) Acquisition Phase Task:
MobiCom’13 Jie Xiong and Kyle Jamieson University College London
Jaime Johnson Yuhang Lin Nathan Daniel Anil Koneri Vineeth Chander
Dhwani : Peer–Peer Secure Acoustic NFC
White Space Networking with Wi-Fi like Connectivity
Teng Wei and Xinyu Zhang
Co-BCast: High-Rate WiFi Broadcasting in Crowded Scenarios via Lightweight Coordination of Multiple Access Points Hang Qiu, Konstantinos Psounis, Giuseppe.
GI Overhead/Performance Impact on Open-Loop SU-MIMO
One Problem of Reliability In Collaborative Communication System
Stateful Inter-Packet Signal Processing for Wireless Networking
Konstantinos Nikitopoulos
WiFinger: Talk to Your Smart Devices with Finger-grained Gesture
WiDeo: Fine-grained Device-free Motion Tracing using RF Backscatter
Communication Systems.
Joe Morrissey Motorola
Match 2015 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: The THz Channel Model in Wireless Data Center.
Blind Known Interference Cancellation
Wireless Channels Y. Richard Yang 01/12/2011.
Preamble Sequence for aj(45GHz)
Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [The Usage of Polarized Antenna System] Date.
UWB Receiver Algorithm
Performance Simulations
Keystroke Recognition using Wi-Fi Signals
doc.: n Jeff Gilbert Atheros Communications
Packet Design for Wake-up Receiver (WUR)
Conducted and Wireless Media (Part II)
STBC in Single Carrier(SC) for IEEE aj (45GHz)
AoD in Passive Ranging Date: Authors: Name Affiliations
3D Localization for Sub-Centimeter Sized Devices
AoD in Passive Ranging Date: Authors: Name Affiliations
Ghostbuster: Detecting the Presence of Hidden Eavesdroppers
Now that we can store audio with high resolution, what will it take to reproduce it with high accuracy? 10/29/2019
Combating Replay Attacks Against Voice Assistants
Presentation transcript:

Acoustic Eavesdropping through Wireless Vibrometry Teng Wei, Shu Wang, Anfu Zhou and Xinyu Zhang University of Wisconsin – Madison Chinese Academy of Sciences Institute of Computing Technology Chinese Academy of Sciences

Image wireless can pick up the sound and leak private information Acoustic Eavesdropping through Wireless Loudspeaker and Wi-Fi are widely used in the conference and home environment Image wireless can pick up the sound and leak private information

Threat Models Reflective Emissive Attacker Victim Wall Attacker Victim Tx Rx Victim Wall Attacker Victim Wall Rx AP

Acoustic-Radio Transformation (ART) How Possible? Translate acoustic vibration into radio signal fluctuation Acoustic-Radio Transformation (ART)

Pros and Cons: Technique Review Widely used in espionage and newsgathering Highly directional and sensitive Laser-based Microphone Directional Microphones Fail in the sound-proof environment Require unobstructed line-of-sight between the subject and laser Penetrate sound-proof material and unblocked by obstacles Microwave-based Microphone

Understand Basic ART Physical Model RSS-based ART Phase-based ART Taylor expansion Audio signal component High-order harmonics DC component 𝑅𝑆𝑆= 𝜎 𝐴 2 𝑑 0 + 𝑑 =𝜎[ 𝐴 2 𝑑 0 +2𝐴 𝑑 0 𝐴 ′ 𝑑 0 𝑑 +…] Radio pathloss 𝑃ℎ𝑎𝑠𝑒= 2𝜋( 𝑑 0 +2 𝑑 ) 𝜆 0 Micro Doppler Audio signal component DC component Audio Decoding of ART Frequency domain analysis Estimate Channel RSS/Phase Assemble audio signals Modulate a known sequence Passband filter Radio sampling frequency >> Audio sampling frequency

Validating Feasibility Setup Rx Tx 2m 0.5m Channel 14 2.485GHz CW 5MHz Result Piano sound 440Hz, 493.88Hz, 554.37Hz High-order harmonics Diversity

> Influence of Multipath Wireless signal is broadcasting in natural Background Reflection Path Loudspeaker Wireless signal is broadcasting in natural Tx Rx I Q Sl S Sc Multipath affects eavesdropping quality Received signal Loudspeaker reflection Background reflection I Q Sl S Sc Quality’ > Good multipath profile = 𝑆 𝑙 ⊥ 2 𝑆 𝑐 ⊥ 2 Quality

Role-switching Beamform Enhanced 1: Spatial Diversity I Q Sl S Sc × 𝒘 𝟏 + × 𝒘 𝟐 = Antenna 1 Antenna 2 Beamform Improved eavesdropping quality Basic Idea Problem: no channel training Weight Searching Solution: blind beamforming algorithm Rx Tx Radio 1 Radio 2 Role-switch Rx weight search 2 Role-switching Beamform Rx weight search 1 Problem: how to find Tx beamforming weights?

Enhanced 2: Frequency Diversity Sl S Sc Channel 1 Channel 7 Basic Idea Alter angles of multipath profile Avoid interference Validation Interference Diversity gain

Enhanced Emissive ART AP Audio Recovery (WiFi decoding) Attacker Rx AP STF LTF Header Payload Audio Recovery (WiFi decoding) Packet detection CSI estimation Audio assembling ① ② ③ Problem 1: Non-uniform packet arrival time Problem 2: Inaccurate signal amplitude estimation LTF Payload 2 OFDM symbols 100+ OFDM symbols Solution: audio sample re-interpolation Solution: RSS estimation and amplification

Interfering Mechanical Vibrations Counter Measure: Reflective ART Drywall 2.4 GHz Safety Distance Free space model 12dB antenna gain Typical WiFi Hardware Interfering Mechanical Vibrations Human movement Rotating fan …

Transmission Power Randomization Counter Measure: Emissive ART Uplink WiFi packets time Original power of packets Power Randomized power of packets Transmission Power Randomization

Implementation and Testbed Software Implementation 802.11g/n-compliant communication library Reflective ART decoder WARP FPGA modification WARP and WURC SDR testbed Altec Lansing Multimedia Computer Speakers Testing Loudspeakers

Distance to antenna: 1 ~ 5m Experiment Setup Conference Room Diversity gain Distance to antenna: 1 ~ 5m Sound-proof Room

Penetrate wall and conventional sound isolator Reflective Eavesdropping Beamforming Human Impact Environment Penetrate wall and conventional sound isolator

Emissive Eavesdropping Victim: Moto X XT1053 AP: Belkin N150 Protocol: IEEE 802.11g Running application: Iperf, TCP transferring at 10Mbps Experiment Setup Human Perception Accuracy Good eavesdropping despite low sound volume

Effectiveness of Counter Measures Validating Transmission Power Randomization (TPR) Trace-driven simulation Collect WiFi packet trace (1900pkt/s) Enforce TPR on each of the collected packet 21dB more than 2 orders of magnitude reduction

Conclusion First to thoroughly investigate vibrometry on wireless devices and practical attack models Distill key factors that enable highly sensitive WiFi vibrometry Basic ART Enhanced reflective ART Enhanced emissive ART Extensive experiments using COTS smartphone, WiFi access point, and software-radio eavesdropper Pose alarming challenges to securing acoustic in formation

Questions? Thank you