
Machine learning technology can be used to turn regular Wi-Fi traffic into a kind of surveillance system able to identify individuals, researchers have discovered. The study was published as BFId: Identity Inference Attacks Utilizing Beamforming Feedback Information.
Unlike attacks with LIDAR sensors or previous Wi-Fi-based methods, which use channel state information (CSI) – i.e. measured data that indicate how a radio signal changes when it reflects off of walls, furniture, or persons – a team of researchers at Germany’s Karlsruhe Institute of Technology (KIT) created a system that doesn’t require any special hardware.
This method requires nothing but a standard Wi-Fi device. It works by exploiting the communication of legitimate users of the WLAN, whose devices are connected to the Wi-Fi network. These regularly send feedback signals within the network, also called beamforming feedback information (BFI), to the router – in unencrypted form so that it is readable by anybody in range. This creates images from different perspectives that can serve to identify the respective persons. Once the underlying machine-learning model has been trained, the identification only takes a few seconds.
“By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present,” says Professor Thorsten Strufe from KASTEL – KIT’s Institute of Information Security and Dependability. “This works similar to a normal camera, the difference being that in our case, radio waves instead of light waves are used for the recognition,” explains the cybersecurity expert. “Thus, it does not matter whether you carry a Wi-Fi device on you or not.” Switching your device off does not help: “It’s sufficient that other Wi-Fi devices in your surroundings are active.”
In a study with 197 participants, the team could infer the identity of persons with almost 100% accuracy – independently of the perspective or their gait. “The technology is powerful, but at the same time entails risks to our fundamental rights, especially to privacy,” emphasizes Strufe. The researchers warn that this is particularly critical in authoritarian states where the technology might be used for the observation of protesters. Therefore, they urgently call for protective measures and privacy safeguards in the forthcoming IEEE 802.11bf Wi-Fi standard.