Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and Devices

3Citations
Citations of this article
35Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Along with the benefits of Internet of Things (IoT) come potential privacy risks, since billions of the connected devices are granted permission to track information about their users and communicate it to other parties over the Internet. Of particular interest to the adversary is the user identity which constantly plays an important role in launching attacks. While the exposure of a certain type of physical biometrics or device identity is extensively studied, the compound effect of leakage from both sides remains unknown in multi-modal sensing environments. In this work, we explore the feasibility of the compound identity leakage across cyber-physical spaces and unveil that co-located smart device IDs (e.g., smartphone MAC addresses) and physical biometrics (e.g., facial/vocal samples) are side channels to each other. It is demonstrated that our method is robust to various observation noise in the wild and an attacker can comprehensively profile victims in multi-dimension with nearly zero analysis effort. Two real-world experiments on different biometrics and device IDs show that the presented approach can compromise more than 70% of device IDs and harvests multiple biometric clusters with purity at the same time.

Cite

CITATION STYLE

APA

Lu, C. X., Li, Y., Xiangli, Y., & Li, Z. (2020). Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and Devices. In The Web Conference 2020 - Proceedings of the World Wide Web Conference, WWW 2020 (pp. 212–223). Association for Computing Machinery, Inc. https://doi.org/10.1145/3366423.3380108

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free