Download presentation
Presentation is loading. Please wait.
Published byMiodrag MiljkoviΔ Modified over 6 years ago
1
Acoustic Eavesdropping through Wireless Vibrometry
Teng Wei, Shu Wang, Anfu Zhou and Xinyu Zhang University of Wisconsin β Madison Chinese Academy of Sciences Institute of Computing Technology Chinese Academy of Sciences
2
Image wireless can pick up the sound and leak private information
Acoustic Eavesdropping through Wireless Loudspeaker and Wi-Fi are widely used in the conference and home environment Image wireless can pick up the sound and leak private information
3
Threat Models Reflective Emissive Attacker Victim Wall Attacker Victim
Tx Rx Victim Wall Attacker Victim Wall Rx AP
4
Acoustic-Radio Transformation (ART)
How Possible? Translate acoustic vibration into radio signal fluctuation Acoustic-Radio Transformation (ART)
5
Pros and Cons: Technique Review
Widely used in espionage and newsgathering Highly directional and sensitive Laser-based Microphone Directional Microphones Fail in the sound-proof environment Require unobstructed line-of-sight between the subject and laser Penetrate sound-proof material and unblocked by obstacles Microwave-based Microphone
6
Understand Basic ART Physical Model RSS-based ART Phase-based ART
Taylor expansion Audio signal component High-order harmonics DC component π
ππ= π π΄ 2 π 0 + π =π[ π΄ 2 π 0 +2π΄ π 0 π΄ β² π 0 π +β¦] Radio pathloss πβππ π= 2π( π 0 +2 π ) π 0 Micro Doppler Audio signal component DC component Audio Decoding of ART Frequency domain analysis Estimate Channel RSS/Phase Assemble audio signals Modulate a known sequence Passband filter Radio sampling frequency >> Audio sampling frequency
7
Validating Feasibility
Setup Rx Tx 2m 0.5m Channel GHz CW 5MHz Result Piano sound 440Hz, Hz, Hz High-order harmonics Diversity
8
> Influence of Multipath Wireless signal is broadcasting in natural
Background Reflection Path Loudspeaker Wireless signal is broadcasting in natural Tx Rx I Q Sl S Sc Multipath affects eavesdropping quality Received signal Loudspeaker reflection Background reflection I Q Sl S Sc Qualityβ > Good multipath profile = π π β₯ π π β₯ 2 Quality
9
Role-switching Beamform
Enhanced 1: Spatial Diversity I Q Sl S Sc Γ π π + Γ π π = Antenna 1 Antenna 2 Beamform Improved eavesdropping quality Basic Idea Problem: no channel training Weight Searching Solution: blind beamforming algorithm Rx Tx Radio 1 Radio 2 Role-switch Rx weight search 2 Role-switching Beamform Rx weight search 1 Problem: how to find Tx beamforming weights?
10
Enhanced 2: Frequency Diversity
Sl S Sc Channel 1 Channel 7 Basic Idea Alter angles of multipath profile Avoid interference Validation Interference Diversity gain
11
Enhanced Emissive ART AP Audio Recovery (WiFi decoding)
Attacker Rx AP STF LTF Header Payload Audio Recovery (WiFi decoding) Packet detection CSI estimation Audio assembling β β‘ β’ Problem 1: Non-uniform packet arrival time Problem 2: Inaccurate signal amplitude estimation LTF Payload 2 OFDM symbols 100+ OFDM symbols Solution: audio sample re-interpolation Solution: RSS estimation and amplification
12
Interfering Mechanical Vibrations
Counter Measure: Reflective ART Drywall 2.4 GHz Safety Distance Free space model 12dB antenna gain Typical WiFi Hardware Interfering Mechanical Vibrations Human movement Rotating fan β¦
13
Transmission Power Randomization
Counter Measure: Emissive ART Uplink WiFi packets time Original power of packets Power Randomized power of packets Transmission Power Randomization
14
Implementation and Testbed
Software Implementation 802.11g/n-compliant communication library Reflective ART decoder WARP FPGA modification WARP and WURC SDR testbed Altec Lansing Multimedia Computer Speakers Testing Loudspeakers
15
Distance to antenna: 1 ~ 5m
Experiment Setup Conference Room Diversity gain Distance to antenna: 1 ~ 5m Sound-proof Room
16
Penetrate wall and conventional sound isolator
Reflective Eavesdropping Beamforming Human Impact Environment Penetrate wall and conventional sound isolator
17
Emissive Eavesdropping
Victim: Moto X XT1053 AP: Belkin N150 Protocol: IEEE g Running application: Iperf, TCP transferring at 10Mbps Experiment Setup Human Perception Accuracy Good eavesdropping despite low sound volume
18
Effectiveness of Counter Measures
Validating Transmission Power Randomization (TPR) Trace-driven simulation Collect WiFi packet trace (1900pkt/s) Enforce TPR on each of the collected packet 21dB more than 2 orders of magnitude reduction
19
Conclusion First to thoroughly investigate vibrometry on wireless devices and practical attack models Distill key factors that enable highly sensitive WiFi vibrometry Basic ART Enhanced reflective ART Enhanced emissive ART Extensive experiments using COTS smartphone, WiFi access point, and software-radio eavesdropper Pose alarming challenges to securing acoustic in formation
20
Questions? Thank you
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.