Sort:
Open Access Research Article Online First
Cross-App Keystroke Inference Through Malicious In-App Training on Keystroke-Induced Vibrations
Tsinghua Science and Technology
Published: 21 September 2026
Abstract PDF (5.8 MB) Collect
Downloads:37

Keystroke privacy is critical on mobile devices, as typed content often includes passwords and sensitive personal data. This paper revisits cross-Application (App) keystroke inference and shows that software sandboxing cannot prevent keystroke leakage at the physical layer because co-resident Apps inevitably share the same hardware. Our insight is twofold. (1) Keystroke-induced vibrations propagate through the touchscreen and internal components and are captured by zero-permission motion sensors, preserving spatial traits tied to key positions. (2) Typing habits enable cross-App generalization, as users typically rely on the same Virtual Keyboard (VK) layout across Apps, causing identical letters to yield similar vibration patterns. Based on these properties, we propose Cross-Apps Mirror Inference (CaMi), a practical cross-App keystroke inference attack. CaMi learns letter-level vibration signatures using labeled samples in any commonly used App and then covertly collects motion sensor data to infer keystrokes typed in a target App. We implemented CaMi on smartphones and tablets, and extensive experiments demonstrate high inference accuracy across devices. We also discuss potential software-level defenses.

Total 1