Discover the SciOpen Platform and Achieve Your Research Goals with Ease.
Search articles, authors, keywords, DOl and etc.
Keystroke privacy is critical on mobile devices, as typed content often includes passwords and sensitive personal data. This paper revisits cross-Application (App) keystroke inference and shows that software sandboxing cannot prevent keystroke leakage at the physical layer because co-resident Apps inevitably share the same hardware. Our insight is twofold. (1) Keystroke-induced vibrations propagate through the touchscreen and internal components and are captured by zero-permission motion sensors, preserving spatial traits tied to key positions. (2) Typing habits enable cross-App generalization, as users typically rely on the same Virtual Keyboard (VK) layout across Apps, causing identical letters to yield similar vibration patterns. Based on these properties, we propose Cross-Apps Mirror Inference (CaMi), a practical cross-App keystroke inference attack. CaMi learns letter-level vibration signatures using labeled samples in any commonly used App and then covertly collects motion sensor data to infer keystrokes typed in a target App. We implemented CaMi on smartphones and tablets, and extensive experiments demonstrate high inference accuracy across devices. We also discuss potential software-level defenses.
The articles published in this open access journal are distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/).
Comments on this article