Abstract
The rapid growth of augmented reality (AR) and virtual reality (VR) technologies has introduced immersive digital experiences for consumers across numerous fields, including banking, education, and professional spheres. In these environments, head-mounted displays (HMDs) enable users to interact with virtual objects through head and hand tracking. In particular, virtual keyboards are emerging as a primary input method, allowing users to type directly with their hands-eliminating the need for additional devices and adding convenience for portable HMD use. However, this direct hand-based typing introduces new security concerns, namely subtle head movements that occur during direct hand-based typing can unintentionally reveal private information. In this paper, we propose SNOOPFINGER, a novel side-channel attack that leverages head movement data, which is accessible without additional user permissions, to estimate typed inputs on a virtual keyboard. Unlike previous methods, SNOOPFINGER uniquely employs a cross-modality approach, relying solely on head movement data to infer hand-typed inputs without the use of controllers. Additionally, our approach is designed to identify a victim's typed inputs without requiring prior access to extensive head movement data from the victim or other users. In an experiment involving 24 participants, SNOOPFING ER achieved high inference accuracy rates, with an average Top-1 accuracy of 55.2% for word inference and 68.8% for sentence reconstruction. Finally, we discuss potential mitigation strategies to counteract such attacks. Our findings reveal critical privacy risks associated with direct hand-based typing in AR/VR environments, demonstrating how zero-permission sensor data can be exploited to obtain private information.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 46th IEEE Symposium on Security and Privacy, SP 2025 |
| Editors | Marina Blanton, William Enck, Cristina Nita-Rotaru |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 4340-4355 |
| Number of pages | 16 |
| ISBN (Electronic) | 9798331522360 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | 46th IEEE Symposium on Security and Privacy, SP 2025 - San Francisco, United States Duration: 2025 May 12 → 2025 May 15 |
Publication series
| Name | Proceedings - IEEE Symposium on Security and Privacy |
|---|---|
| ISSN (Print) | 1081-6011 |
Conference
| Conference | 46th IEEE Symposium on Security and Privacy, SP 2025 |
|---|---|
| Country/Territory | United States |
| City | San Francisco |
| Period | 25/5/12 → 25/5/15 |
Bibliographical note
Publisher Copyright:© 2025 IEEE.
ASJC Scopus subject areas
- Software
- Safety, Risk, Reliability and Quality
- Computer Networks and Communications
Fingerprint
Dive into the research topics of 'Eyes on your Typing: Snooping Finger Motions on Virtual Keyboards'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS