Site navigation

Eavesdropping AI: Model Can Detect Keystrokes Through Sounds

Elizabeth Greenberg

,

eavesdropping AI
“Over enthusiastic executives should take note that AI may look like Barbie, but it could turn out to be Oppenheimer if the necessary cyber protections and regulatory procedures aren’t in place,” said Suid Adeyanju, a cyber expert and CEO of RiverSafe.

An AI model can now work out which keys are being pressed purely by sound recognition with high accuracy, according to a group researchers from three UK universities.

Typing a computer password while chatting over a video call like Zoom could therefore open the door to a cyber-attack, the research suggests, after the study underscored AI‘s eavesdropping capabilities.

Industry experts say that as video conferencing tools such as Zoom have grown in use, and devices with built-in microphones have become ubiquitous, the threat of cyber-attacks based on sounds has also risen.

The researchers say they have created a system which can work out which keys are being pressed on a laptop keyboard with more than 90% accuracy, just based on sound recordings.

“I can only see the accuracy of such models, and such attacks, increasing,” said Dr Ehsan Toreini at the University of Surrey and co-author of the study, adding that with smart devices bearing microphones becoming ever more common within households, such attacks highlight the need for public debates on AI governance.

The research, published as part of the IEEE European Symposium on Security and Privacy Workshops, reveals how Toreini and colleagues used machine learning algorithms to create a system able to identify which keys were being pressed on a laptop based on sound – an approach that researchers deployed on the Enigma cipher device in recent years.

The study reports how the researchers pressed each of 36 keys on a MacBook Pro, including all of the letters and numbers, 25 times in a row, using different fingers and with varying pressure. The sounds were recorded both over a Zoom call and on a smartphone places a short distance from the keyboard.

The team then fed part of the data into a machine learning system which, over time, learned to recognise features of the acoustic signals associated with each key. While it is not clear which clues the system used, Joshua Harrison, first author of the study, from Durham University, said it was possible that an important influence was how close the keys were to the edge of the keyboard.

“This positional information could be the main driver behind the different sounds,” he said.

The results revealed that the system could accurately assign the correct key to a sound 95% of the time when the recording was made over a phone call, and 93% of the time when the recording was made over a Zoom call.

The study, which is also authored by Dr Maryam Mehrnezhad from the Royal Holloway, University of London, is not the first to show that keystrokes can be identified by sound. However, the team say their study uses the most up-to-date methods and has achieved the highest accuracy so far.


Recommended reading


While the researchers say the work is a proof-of-principle study, and has not been used to crack passwords – which would involve correctly guessing strings of keystrokes – or in real world settings like coffee shops, they say the work highlights the need for vigilance, noting that while laptops – with their similar keyboards and common use in public places – are at high risk, similar eavesdropping methods could be applied to any keyboard.

The researchers add there are a number of ways the risk of such acoustic “side channel attacks” can be mitigated, interluding opting for biometric passwords where possible or activating two-step verification systems.

Commenting on the findings, cyber expert Suid Adeyanju, CEO of RiverSafe said: “This study should serve as a wake-up call about the true risks posed by artificial intelligence when the technology is hijacked by cyber criminals. Far too many organisations are rushing to adopt the technology without conducting even the most basic due diligence tests and in total disregard for standard security protocols.

“Over enthusiastic executives should take note that AI may look like Barbie, but it could turn out to be Oppenheimer if the necessary cyber protections and regulatory procedures aren’t in place,” said Adeyanju.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data