paper-with-me

Papers

GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR Devices

2024-09-12 · Hanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai, Max Panoff, Shuo Wang

The advent and growing popularity of Virtual Reality (VR) and Mixed Reality (MR) solutions have revolutionized the way we interact with digital platforms. The cutting-edge gaze-controlled typing methods, now prevalent in high-end models of these devices, e.g., Apple Vision Pro, have not only improved user experience but also mitigated traditional keystroke inference attacks that relied on hand gestures, head movements and acoustic side-channels. However, this advancement has paradoxically given birth to a new, potentially more insidious cyber threat, GAZEploit. In this paper, we unveil GAZEploit, a novel eye-tracking based attack specifically designed to exploit these eye-tracking information by leveraging the common use of virtual appearances in VR applications. This widespread usage significantly enhances the practicality and feasibility of our attack compared to existing methods. GAZEploit takes advantage of this vulnerability to remotely extract gaze estimations and steal sensitive keystroke information across various typing scenarios-including messages, passwords, URLs, emails, and passcodes. Our research, involving 30 participants, achieved over 80% accuracy in keystroke inference. Alarmingly, our study also identified over 15 top-rated apps in the Apple Store as vulnerable to the GAZEploit attack, emphasizing the urgent need for bolstered security measures for this state-of-the-art VR/MR text entry method.

📄 PDF Abstract BibTeX arXiv:2409.08122

Code (0)

등록된 구현이 없습니다.

Tasks

Gaze EstimationInference AttackMixed Reality

Similar Papers 제목 키워드 기반

Zoom on the Keystrokes: Exploiting Video Calls for Keystroke Inference Attacks

2020-10-22 · Mohd Sabra, Anindya Maiti, Murtuza Jadliwala

Due to recent world events, video calls have become the new norm for both personal and professional remote communication. However, if a participant in a video call is not careful, he/she can reveal his/her private inform…

Revisiting the Threat Space for Vision-based Keystroke Inference Attacks

2020-09-12 · John Lim, True Price, Fabian Monrose, Jan-Michael Frahm

A vision-based keystroke inference attack is a side-channel attack in which an attacker uses an optical device to record users on their mobile devices and infer their keystrokes. The threat space for these attacks has be…

Domain AdaptationInference AttackTransfer Learning

Leveraging Disentangled Representations to Improve Vision-Based Keystroke Inference Attacks Under Low Data

2022-04-05 · John Lim, Jan-Michael Frahm, Fabian Monrose

Keystroke inference attacks are a form of side-channel attacks in which an attacker leverages various techniques to recover a user's keystrokes as she inputs information into some display (e.g., while sending a text mess…

Data AugmentationDomain Adaptation

Disentangling style and content for low resource video domain adaptation: a case study on keystroke inference attacks

2021-01-01 · John Lim, Fabian Monrose, Jan-Michael Frahm

Keystroke inference attacks are a form of side-channels attacks in which an attacker leverages various techniques to recover a user’s keystrokes as she inputs information into some display (for example, while sending a t…

BIG-bench Machine LearningData AugmentationDomain Adaptation

Conditional Generative Adversarial Network for keystroke presentation attack

2022-12-16 · Idoia Eizaguirre-Peral, Lander Segurola-Gil, Francesco Zola

Cybersecurity is a crucial step in data protection to ensure user security and personal data privacy. In this sense, many companies have started to control and restrict access to their data using authentication systems. …

Generative Adversarial Network