mimoCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption
Jun Luo, Hangcheng Cao, Hongbo Jiang, Yanbing Yang, Zhe Chen
IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 4
Overview
The talk "mimoCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption" by Jun Luo and co-authors introduces a groundbreaking defensive mechanism against privacy threats posed by advanced Wi-Fi sensing technologies. Presented at IEEE S&P, this research addresses the critical security and privacy implications arising from the recent advancements in multi-person Wi-Fi sensing. As Wi-Fi networks become increasingly sophisticated in their ability to monitor human activities without requiring subjects to wear any devices, the potential for unauthorized surveillance and data exploitation escalates dramatically.

Key moments
- 0:00 Introducing mimoCrypt and Wi-Fi sensing privacy problem
- 4:00 Critiquing existing Wi-Fi sensing privacy countermeasures
- 6:00 The challenge: encrypting physical human behaviors
- 7:40 mimoCrypt's physical encryption mechanism using MIMO antennas
- 9:00 Visual demonstration of encryption scrambling sensing data
mimoCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption
Speakers: Jun Luo, Hangcheng Cao, Hongbo Jiang, Yanbing Yang, Zhe Chen
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=TokDOhHvwQ8
Overview
The talk "mimoCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption" by Jun Luo and co-authors introduces a groundbreaking defensive mechanism against privacy threats posed by advanced Wi-Fi sensing technologies. Presented at IEEE S&P, this research addresses the critical security and privacy implications arising from the recent advancements in multi-person Wi-Fi sensing. As Wi-Fi networks become increasingly sophisticated in their ability to monitor human activities without requiring subjects to wear any devices, the potential for unauthorized surveillance and data exploitation escalates dramatically.
The core of the problem lies in the fact that while multi-person Wi-Fi sensing offers significant benefits in areas like smart homes, elder care, and security monitoring, it simultaneously exposes individuals to unprecedented privacy risks. Traditional digital encryption methods are insufficient to protect physical behaviors, such as typing a password or monitoring vital signs, which are inferred directly from physical layer channel characteristics. mimoCrypt steps in to fill this crucial gap, proposing the first comprehensive solution that not only thwarts attackers but also preserves the performance for legitimate communication and sensing users in complex multi-user environments.
Background
▶ Watch: Introducing mimoCrypt and Wi-Fi sensing privacy problem (0:00)
Wi-Fi sensing operates on the principle that human movement and other environmental changes perturb Wi-Fi signals, creating measurable alterations in the Channel State Information (CSI). When a transmitter sends a known signal S through a channel H, the receiver observes Y. The CSI, H, can then be derived from Y and S. Any activity within the channel, such as a hand wave, causes H to change, providing a rich source of information about amplitude, time, and phase variations. This capability underpins a wide array of applications, from tracking and activity detection to even vital sign monitoring.
Historically, Wi-Fi sensing has largely been confined to two modes: device-based sensing, primarily used for device localization, and device-free sensing, which monitors subjects without requiring them to carry any devices. A significant limitation of device-free sensing, persisting for over a decade, was its inability to effectively distinguish and monitor multiple subjects simultaneously. The behaviors of different individuals would mix, rendering the data indecipherable. This bottleneck was only recently overcome, with breakthrough publications in conferences like MobiCom and MobiSys, extending device-based sensing to general human sensing and relaxing the single-person limitation on device-free sensing.
While these advancements unlock powerful new applications, they concurrently introduce profound privacy and security vulnerabilities. The speakers highlight a prior demonstration from CCS, where they showed that an attacker could easily eavesdrop on passwords being typed on a mobile phone using Wi-Fi sensing, without any hacking or device modification. This capability, now extended to multiple individuals, means that physical behaviors in public or even private spaces are potentially exposed, raising serious concerns about personal safety and data privacy.
Awareness of these issues predates the multi-person sensing breakthrough. Earlier proposals aimed at mitigating these risks, though with significant limitations. An approach presented at NSDI '16 suggested that a legitimate sensing user could inject jamming into the channel after receiving CSI, preventing others from sensing. However, this method only works for a single legitimate user. A more recent proposal from S&P; two years prior involved using intelligent reflection surfaces to generate jamming that indiscriminately affected all users, including legitimate communication and sensing users. These brute-force methods are undesirable as they compromise the very utility of Wi-Fi. The clear demand was for a sophisticated defensive mechanism that could selectively deter attackers while maintaining high performance for authorized users in complex multi-user scenarios.
Key Findings
▶ Watch: Critiquing existing Wi-Fi sensing privacy countermeasures (4:00)
The central contribution of this research is mimoCrypt, presented as the first full-fledged defensive mechanism designed for multi-user, privacy-preserving Wi-Fi sensing. mimoCrypt addresses the unique challenge of protecting physical behaviors from Wi-Fi sensing eavesdropping, which cannot be adequately secured by conventional digital encryption techniques.
The key findings and contributions include:
- Physical Layer Encryption: mimoCrypt introduces a novel concept of physical encryption or analog encryption directly applied to the Wi-Fi channel itself, rather than digitally encrypting data. This involves manipulating the Wi-Fi signal at the subcarrier and antenna level within the Wi-Fi card to scramble the CSI observed by unauthorized entities.
- Integrated Sensing and Communication (ISAC) Optimization: Recognizing that Wi-Fi networks serve both communication and sensing purposes, mimoCrypt incorporates an optimization framework. This framework intelligently selects encryption keys that achieve a delicate balance: minimizing the signal-to-distortion ratio (SDR) for eavesdroppers (making their observed CSI unusable) while maximizing the signal-to-noise ratio (SNR) for legitimate communication and sensing users, thereby preserving their performance.
- Lightweight Key Conveyance for Sensing Users: To overcome the overhead associated with complex, large-volume analog encryption keys, mimoCrypt proposes an innovative method for key distribution to legitimate sensing users. Instead of transmitting the entire complex key, a hash of the key is used as a selector for a pre-trained dynamic network of encoders, significantly reducing the key management burden without compromising security.
- Robust Security Against Antenna Diversity: A crucial finding is mimoCrypt's resilience against attackers employing multiple antennas or virtual antennas to enhance their sensing capabilities. The security analysis demonstrates that increasing an attacker's antenna diversity paradoxically backfires, as each additional antenna introduces new unknown parameters (key + channel), making the decryption task even harder rather than easier. This fundamentally differentiates mimoCrypt from systems where more observations lead to better estimates of a single unknown.
Technical Deep Dive
▶ Watch: The challenge: encrypting physical human behaviors (6:00)
At its heart, Wi-Fi sensing relies on the precise estimation of the Channel State Information (CSI). In a simplified model, a known signal S is transmitted, passes through the channel H, and is received as Y. From Y and S, the receiver can deduce H. When a human or object interacts with the environment, H changes, and these changes are what Wi-Fi sensing algorithms interpret.
The fundamental challenge mimoCrypt tackles is that the "plaintext" here is not digital data but physical behavior, manifested as changes in the physical channel H. Therefore, conventional digital encryption, which operates on bits and bytes, is inadequate. Encrypting S (the known training sequence) also proves to be weak, as S is typically a short, fixed sequence, making its encryption easily guessable. The innovation lies in physically encrypting the channel itself.
The key insight is that while the "air channel" is uncontrollable, the signal processing within the Wi-Fi card offers opportunities for manipulation. Modern Wi-Fi systems leverage Orthogonal Frequency-Division Multiplexing (OFDM), which divides the signal across multiple subcarriers, and Multiple-Input Multiple-Output (MIMO) technology, utilizing multiple antennas. mimoCrypt exploits these features by injecting encryption keys directly onto individual subcarriers and, more prominently, onto individual antennas. These key-modulated signals are then transmitted simultaneously and allowed to mix in the air. The result is a scrambled CSI at an unauthorized receiver, as demonstrated by the speaker's visual example: a clear hand-waving pattern in unencrypted CSI becomes an indistinguishable, scrambled mess post-encryption.
However, the use of physical (analog) encryption introduces a unique set of challenges, particularly in the context of Integrated Sensing and Communication (ISAC). Unlike digital encryption, which guarantees perfect fidelity upon decryption (1 minus 1 equals exactly 0, then plus 1 equals exactly 1), analog processes are inherently subject to noise and distortion. A physically encrypted and then decrypted signal will not be an exact replica of the original due to accumulated physical or analog imperfections. This necessitates a careful balance.
mimoCrypt formulates this as an optimization problem. The goal is to select encryption keys that simultaneously:
- Minimize the Signal-to-Distortion Ratio (SDR) for an eavesdropper, effectively making the attacker's observed CSI too noisy or distorted to extract meaningful information.
- Maximize the Signal-to-Noise Ratio (SNR) for legitimate communication and sensing users, ensuring their intended functions remain robust and accurate.
Solving this non-convex optimization problem to find a globally unique optimal solution is difficult. Instead, mimoCrypt aims to identify a "good set of encryption keys" that maintain an adequate balance between these conflicting objectives. The system is designed to allow for dynamic key switching as needed, adapting to changing environmental conditions or security requirements.
A significant practical consideration is the encryption overhead. The encryption keys are complex numbers, not simple bits. For instance, a key of length 64 might involve 64 components, each being two 64-bit real numbers. Transmitting such large volumes of complex key data to every legitimate sensing user poses a substantial overhead. mimoCrypt addresses this with an ingenious lightweight key conveyance process specifically tailored for sensing users. Recognizing that sensing often requires lower information granularity compared to communication, the system does not transmit the full, complex key. Instead, legitimate sensing users are equipped with a dynamic network—a convolutional combination of different encoders, each capable of handling various encryption keys. After training this model, only a hash of the encryption key is provided to the sensing user. This hash acts as a "selector," dynamically choosing which encoder within the pre-trained network to use for decryption. For example, a system with eight encoders could offer up to 256 different choices, significantly reducing the data volume transmitted for key management while enabling the local inference network to adapt to different encrypted channels.
Demo / Proof of Concept
▶ Watch: mimoCrypt's physical encryption mechanism using MIMO antennas (7:40)
While the talk doesn't detail a live, interactive demo, it presents compelling performance evaluations that serve as a robust proof of concept for mimoCrypt's effectiveness. The results are presented compactly, illustrating the mechanism's dual impact on attackers and legitimate users.
For attackers, the efficacy of various prominent Wi-Fi sensing algorithms published over the past decade was tested under mimoCrypt's encryption. The findings were stark: regardless of the specific sensing algorithm used, when mimoCrypt was applied, the accuracy of the attacker's sensing capabilities plummeted to below 20%, typically hovering around 16%. In stark contrast, without mimoCrypt, these same algorithms achieved accuracies exceeding 90-95%, validating their utility in unencrypted environments. This clearly demonstrates that mimoCrypt effectively renders Wi-Fi sensing data unusable for unauthorized parties.
For legitimate users, the impact on communication performance was assessed by measuring the Bit Error Rate (BER). The results showed only a "very minor" increase in BER when mimoCrypt encryption was applied, on the scale of "only a few percent." This indicates that mimoCrypt successfully preserves the integrity and performance of legitimate Wi-Fi communication, fulfilling the critical requirement of not being a brute-force jamming solution.
A particularly insightful aspect of the proof of concept is the security analysis against advanced attackers employing multiple antennas. A common assumption in signal processing is that increasing the number of observation points (e.g., antennas) allows for better estimation of unknown parameters. However, mimoCrypt fundamentally changes this dynamic. The speaker explains that because the channel H is already unknown and being estimated, and mimoCrypt then encrypts onto this unknown channel, the attacker is faced with at least two unknown parameters: the channel and the encryption key. When an attacker adds another antenna, they don't just gain more observations of the same unknown parameters; rather, they introduce a new pair of unknown parameters (a new channel for that antenna, combined with the unknown key). This phenomenon, termed "diversity backfires," means that increasing antenna diversity actually increases the number of unknowns at the same rate, preventing the attacker from gaining a significant advantage. The evaluation supported this, showing that even when an attacker increased their antennas from one to 80, their sensing accuracy did not improve. Conversely, for legitimate sensing users, whose keys are known, increasing antenna quality does enhance their accuracy, which is a standard and understandable outcome in MIMO systems.
Defensive Implications
▶ Watch: Visual demonstration of encryption scrambling sensing data (9:00)
The advent of highly accurate multi-user Wi-Fi sensing, while offering significant societal benefits, also ushers in an era of unprecedented privacy risks. The mimoCrypt research provides crucial guidance for defenders, ranging from network administrators and hardware manufacturers to individual users.
Firstly, the most direct implication is the urgent need for physical layer security mechanisms in Wi-Fi infrastructure. Traditional network security focuses on digital data; however, the ability to infer sensitive physical behaviors (like password typing or vital signs) from raw CSI necessitates a shift in defensive strategy. Network architects and equipment vendors should explore integrating technologies like mimoCrypt directly into Wi-Fi chipsets and access points. This would provide a foundational layer of protection against device-free sensing attacks at the source.
Secondly, any future deployments of Wi-Fi sensing for legitimate applications, such as elder care or smart home monitoring, must explicitly incorporate privacy-preserving designs. Solutions should prioritize balancing the utility of sensing with robust mechanisms to prevent unauthorized access to the raw CSI data. mimoCrypt's approach of minimizing attacker SDR while maximizing legitimate user SNR serves as a blueprint for such balanced designs.
Thirdly, the concept of lightweight, dynamic key management for physical layer encryption, as demonstrated by mimoCrypt's use of dynamic networks and key hashes, is a critical takeaway for implementing practical security. The overhead of complex analog keys must be managed efficiently to ensure widespread adoption and usability without compromising performance. Developers of sensing applications should consider how to securely distribute and manage these physical layer keys to authorized users.
Fourthly, the "diversity backfires" finding is a powerful deterrent against sophisticated attackers. This implies that simply investing in more advanced receiving hardware with multiple antennas will not grant an attacker an advantage against mimoCrypt-protected networks. Defenders can leverage this understanding to design more resilient systems and to educate stakeholders about the inherent security strengths of such physical layer encryption.
Finally, for end-users, while direct action might be limited without hardware-level changes, awareness is key. Users should understand that their physical behaviors can be passively monitored through Wi-Fi signals. This awareness can drive demand for privacy-enhanced Wi-Fi technologies and encourage manufacturers to adopt robust defensive mechanisms like mimoCrypt as standard features, making public and shared spaces safer for sensitive activities.
Key Takeaways
- The rise of multi-user device-free Wi-Fi sensing introduces significant privacy risks, enabling passive monitoring of physical behaviors like password typing.
- Traditional digital encryption is inadequate for protecting physical behaviors inferred from Wi-Fi Channel State Information (CSI).
- mimoCrypt introduces physical (analog) encryption directly into the Wi-Fi card, manipulating subcarriers and MIMO antennas to scramble CSI for unauthorized observers.
- The system employs an optimization strategy to balance performance, minimizing attacker signal distortion while maintaining high communication and sensing quality for legitimate users.
- Lightweight key management for legitimate sensing users is achieved through a dynamic network approach, using a hash of the complex key as an encoder selector rather than transmitting the full key.
- mimoCrypt is robust against attackers with high antenna diversity; paradoxically, increased attacker antennas lead to more unknown parameters, a phenomenon termed "diversity backfires," which hinders rather than helps decryption.
About the Speaker(s)
The talk "mimoCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption" was presented by Jun Luo, with co-authors Hangcheng Cao, Hongbo Jiang, Yanbing Yang, and Zhe Chen. The speakers are researchers whose work focuses on the intersection of Wi-Fi technology, sensing, and security. Their previous work includes significant contributions to the field of multi-person Wi-Fi sensing and demonstrations of its privacy implications, such as password eavesdropping. This presentation at IEEE S&P highlights their continued commitment to advancing both the capabilities and the security of wireless sensing technologies.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk introduces mimoCrypt, a groundbreaking physical layer encryption scheme designed to protect against multi-user Wi-Fi sensing surveillance. It uniquely scrambles Channel State Information for eavesdroppers while preserving legitimate communication and sensing, leveraging clever ISAC optimization and lightweight key management. The research is technically profound and offers a critical, novel defense against emerging privacy threats.
Heather Calloway (CISO) — STRONG ACCEPT
This research identifies a critical, often overlooked privacy threat: the inference of physical behaviors from Wi-Fi signals. mimoCrypt offers a groundbreaking physical layer encryption solution that balances robust attacker deterrence with legitimate user performance, fundamentally changing how we must approach Wi-Fi privacy.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024