@article{Wei2026, 
author = {Ruyi Wei and Junhua Wu and Huigui Rong and Daibo Liu},
title = {Cross-App Keystroke Inference Through Malicious In-App Training on Keystroke-Induced Vibrations},
year = {2026},
journal = {Tsinghua Science and Technology},
keywords = {smartphone, keystroke inference, cross-App attack, vibrations, side-channel},
url = {https://www.sciopen.com/article/10.26599/TST.2026.9010051},
doi = {10.26599/TST.2026.9010051},
abstract = {Keystroke privacy is critical on mobile devices, as typed content often includes passwords and sensitive personal data. This paper revisits cross-Application (App) keystroke inference and shows that software sandboxing cannot prevent keystroke leakage at the physical layer because co-resident Apps inevitably share the same hardware. Our insight is twofold. (1) Keystroke-induced vibrations propagate through the touchscreen and internal components and are captured by zero-permission motion sensors, preserving spatial traits tied to key positions. (2) Typing habits enable cross-App generalization, as users typically rely on the same Virtual Keyboard (VK) layout across Apps, causing identical letters to yield similar vibration patterns. Based on these properties, we propose Cross-Apps Mirror Inference (CaMi), a practical cross-App keystroke inference attack. CaMi learns letter-level vibration signatures using labeled samples in any commonly used App and then covertly collects motion sensor data to infer keystrokes typed in a target App. We implemented CaMi on smartphones and tablets, and extensive experiments demonstrate high inference accuracy across devices. We also discuss potential software-level defenses.}
}