Affiliation:
1. University of Electronic Science and Technology of China, Chengdu, Sichuan, China
2. Temple University, Philadelphia, Pennsylvania, USA
3. Rutgers University, New Brunswick, USA
Abstract
Photoplethysmography (PPG) sensors have become integral components of wearable and portable health devices in the current technological landscape. These sensors offer easy access to heart rate and blood oxygenation, facilitating continuous long-term health monitoring in clinic and non-clinic environments. While people understand that health-related information provided by PPG is private, no existing research has demonstrated that PPG sensors are dangerous devices capable of obtaining sensitive information other than health-related data. This work introduces PPG-Hear, a novel side-channel attack that exploits PPG sensors to intercept nearby audio information covertly. Specifically, PPG-Hear exploits low-frequency PPG measurements to discern and reconstruct human speech emitted from proximate speakers. This technology allows attackers to eavesdrop on sensitive conversations (e.g., audio passwords, business decisions, or intellectual properties) without being noticed. To achieve this non-trivial attack on commodity PPG-enabled devices, we employ differentiation and filtering techniques to mitigate the impact of temperature drift and user-specific gestures. We develop the first PPG-based speech reconstructor, which can identify speech patterns in the PPG spectrogram and establish the correlation between PPG and speech spectrograms. By integrating a MiniRocket-based classifier with a PixelGAN model, PPG-Hear can reconstruct human speech using low-sampling-rate PPG measurements. Through an array of real-world experiments, encompassing common eavesdropping scenarios such as surrounding speakers and the device's own speakers, we show that PPG-Hear can achieve remarkable accuracy of 90% for recognizing human speech, surpassing the current state-of-the-art side-channel eavesdropping attacks using motion sensors operating at equivalent sampling rates (i.e., 50Hz to 500Hz).
Funder
Natural Science Foundation of Sichuan Province
National Natural Science Foundation of China
National Key Research and Development Program of China
Publisher
Association for Computing Machinery (ACM)
Reference40 articles.
1. 2017. Android Wear: How to get raw PPG data? https://stackoverflow.com/questions/47444302/android-wear-how-to-get-raw-ppg-data (Accessed on 2/2/2024).
2. 2021. Wearable Device Data Breach. https://healthitsecurity.com/news/61m-fitbit-apple-users-had-data-exposed-in-wearable-device-data-breach (Accessed on 8/1/2023).
3. 2023. AudioMNIST Dataset. https://github.com/soerenab/AudioMNIST (Accessed on 8/1/2023).
4. 2023. Samsung Privilege Health SDK. https://developer.samsung.com/health/privileged-partner/guide/data-specifications.html#Setting-Events-for-Multiple-Tracker-Types (Accessed on 7/10/2023).
5. 2024. HarmonyOS Developer. https://developer.huawei.com/consumer/cn/doc/ecosystem-Guides/03_03_03_02_03_data-0000001180474833 (Accessed on 2/2/2024).
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Pushing the Limits of Acoustic Spatial Perception via Incident Angle Encoding;Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies;2024-05-13