Searcharxiv⌕ Search

arXiv subjects

Johannes Kortz

Publications and source records attributed to Johannes Kortz.

2 recordsLinked to original sources

PINsight: Systematic Threat Assessment of Cross-Domain Wi-Fi-based PIN Inference

Wi-Fi signals can be repurposed as radar-like sensors, exposing a side channel for inferring sensitive information. A particularly concerning example is PIN inference, where an attacker recovers typed digits by mapping Wi-Fi channel estimations back to individual keystrokes. While effective in a fixed setting, such attacks typically fail once physical conditions change, e.g., a new room, a different person, or a repositioned device. The state-of-the-art attack WiKI-Eve tackles this domain generalization problem with deep learning, reporting high PIN inference accuracy regardless of physical conditions - suggesting a significant real-world threat. However, the actual threat potential remains unclear: isolated success cases cannot substantiate general performance, and no systematic method exists to evaluate attacks under unseen conditions. We close this gap with PINsight, a methodology that separates the effects of changing physical conditions from those of PIN typing itself, enabling a rigorous threat assessment that attributes performance degradation to specific condition changes. PINsight leverages a robotic typing platform that produces highly repeatable keystrokes under systematically varied conditions, such as room and device placement. Using this setup, we record over one million typed digits across over one thousand controlled combinations of physical conditions, yielding the first benchmark for cross-domain generalization in Wi-Fi PIN inference, which we release publicly. On this benchmark, we revisit WiKI-Eve, address several reproducibility gaps in its evaluation, and construct a stronger variant as an attack baseline. We find that attacks generalize reliably across background changes but degrade substantially once devices are repositioned. We conclude that domain generalization is partially feasible, but prior results overstate the real-world threat.

cs.CR↗

Anti-Tamper Radio meets Reconfigurable Intelligent Surface for System-Level Tamper Detection

Many computing systems need to be protected against physical attacks using active tamper detection based on sensors. One technical solution is to employ an ATR (Anti-Tamper Radio) approach, analyzing the radio wave propagation effects within a protected device to detect unauthorized physical alterations. However, ATR systems face key challenges in terms of susceptibility to signal manipulation attacks, limited reliability due to environmental noise, and regulatory constraints from wide bandwidth usage. In this work, we propose and experimentally evaluate an ATR system complemented by an RIS to dynamically reconfigure the wireless propagation environment. We show that this approach can enhance resistance against signal manipulation attacks, reduce bandwidth requirements from several~GHz down to as low as 20 MHz, and improve robustness to environmental disturbances such as internal fan movements. Our work demonstrates that RIS integration can strengthen the ATR performance to enhance security, sensitivity, and robustness, recognizing the potential of smart radio environments for ATR-based tamper detection

cs.CR↗