WiFi Technology May Enable Unseen Surveillance Using Radio Waves
Research from KASTEL, the Institute of Information Security and Dependability at the Karlsruhe Institute of Technology (KIT), indicates that ordinary WiFi signals could potentially be utilized to identify individuals and map their environments without the need for cameras or personal devices. Professor Thorsten Strufe explained, “By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present.” Unlike traditional cameras that rely on light waves, this method harnesses radio waves for recognition.
A significant aspect of this technique is that individuals do not need to possess a WiFi-enabled device, such as a phone or smartwatch, for the system to work. Strufe noted, “Thus, it does not matter whether you carry a WiFi device on you or not.” The technology can function even if a person’s device is turned off, as long as other active WiFi devices are in the vicinity.
Concerns Over Privacy Risks
The researchers highlight serious privacy concerns due to the widespread presence of WiFi networks in homes, offices, and public spaces. Julian Todt, another researcher at KASTEL, warned, “This technology turns every router into a potential means for surveillance.” He pointed out that people could be unknowingly identified in locations like cafés, with their data potentially accessible to public authorities or companies.
While there are established methods for surveillance, such as CCTV systems, these require visible infrastructure. In contrast, “the omnipresent wireless networks might become a nearly comprehensive surveillance infrastructure with one concerning property: they are invisible and raise no suspicion,” explained Felix Morsbach.
No Specialized Hardware Required
This new methodology does not depend on advanced equipment. Traditionally, detecting individuals via wireless signals has necessitated specialized tools. However, the researchers state that a standard WiFi device suffices. The system capitalizes on the routine communications sent by legitimate users connected to a wireless local area network (WLAN).
Connected devices transmit beamforming feedback information (BFI) to optimize connection, which is sent without encryption, making it potentially accessible to anyone within range. By analyzing this data, the system can construct images of people from diverse perspectives, enabling the identification of individuals. Once the machine learning model is trained, identification can occur in mere seconds.
High Identification Accuracy Demonstrated
In a study comprising 197 participants, the system achieved nearly 100% accuracy in identifying individuals, regardless of perspective or movement style. Strufe remarked, “The technology is powerful, but at the same time entails risks to our fundamental rights, especially to privacy.” The potential misuse of this technology in authoritarian regimes is particularly alarming, as it could be employed to monitor dissenters discreetly.
The researchers advocate for integrated privacy protections within future WiFi standards to prevent large-scale exploitation of such technology. They are calling for protective measures to be included in the upcoming IEEE 802.11bf WiFi standard. The project was funded under Helmholtz’s “Engineering Secure Systems” initiative and was presented at the ACM Conference on Computer and Communications Security (CCS) held in Taipei.


