24/7 Space News
INTERNET SPACE
Smart devices' ambient light sensors pose imaging privacy risk
A computational imaging algorithm from MIT demonstrates how ambient light sensors can expose touch interactions with our phones to hackers, who could process the sensor data from another device. Credits:Image: Alex Shipps/MIT CSAIL
Smart devices' ambient light sensors pose imaging privacy risk
by Alex Shipps | MIT CSAIL
Boston MA (SPX) Feb 05, 2024

In George Orwell's novel "1984," Big Brother watches citizens through two-way, TV-like telescreens to surveil citizens without any cameras. In a similar fashion, our current smart devices contain ambient light sensors, which open the door to a different threat: hackers.

These passive, seemingly innocuous smartphone components receive light from the environment and adjust the screen's brightness accordingly, like when your phone automatically dims in a bright room. Unlike cameras, though, apps are not required to ask for permission to use these sensors. In a surprising discovery, researchers from MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) uncovered that ambient light sensors are vulnerable to privacy threats when embedded on a smart device's screen.

The team proposed a computational imaging algorithm to recover an image of the environment from the perspective of the display screen using subtle single-point light intensity changes of these sensors to demonstrate how hackers could use them in tandem with monitors. An open-access paper on this work was published in Science Advances on Jan. 10.

"This work turns your device's ambient light sensor and screen into a camera! Ambient light sensors are tiny devices deployed in almost all portable devices and screens that surround us in our daily lives," says Princeton University professor Felix Heide, who was not involved with the paper. "As such, the authors highlight a privacy threat that affects a comprehensive class of devices and has been overlooked so far."

While phone cameras have previously been exposed as security threats for recording user activity, the MIT group found that ambient light sensors can capture images of users' touch interactions without a camera. According to their new study, these sensors can eavesdrop on regular gestures, like scrolling, swiping, or sliding, and capture how users interact with their phones while watching videos. For example, apps with native access to your screen, including video players and web browsers, could spy on you to gather this permission-free data.

According to the researchers, a commonly held belief is that ambient light sensors don't reveal meaningful private information to hackers, so programming apps to request access to them is unnecessary. "Many believe that these sensors should always be turned on," says lead author Yang Liu, a PhD student in MIT's Department of Electrical Engineering and Computer Science and a CSAIL affiliate.

"But much like the telescreen, ambient light sensors can passively capture what we're doing without our permission, while apps are required to request access to our cameras. Our demonstrations show that when combined with a display screen, these sensors could pose some sort of imaging privacy threat by providing that information to hackers monitoring your smart devices."

Collecting these images requires a dedicated inversion process where the ambient light sensor first collects low-bitrate variations in light intensity, partially blocked by the hand making contact with the screen. Next, the outputs are mapped into a two-dimensional space by forming an inverse problem with the knowledge of the screen content. An algorithm then reconstructs the picture from the screen's perspective, which is iteratively optimized and denoised via deep learning to reveal a pixelated image of hand activity.

The study introduces a novel combination of passive sensors and active monitors to reveal a previously unexplored imaging threat that could expose the environment in front of the screen to hackers processing the sensor data from another device. "This imaging privacy threat has never been demonstrated before," says Liu, who worked alongside Fredo Durand on the paper, who is an MIT EECS professor, CSAIL member, and senior author of the paper.

The team suggested two software mitigation measures for operating system providers: tightening up permissions and reducing the precision and speed of the sensors. First, they recommend restricting access to the ambient light sensor by allowing users to approve or deny those requests from apps.

To further prevent any privacy threats, the team also proposed limiting the capabilities of the sensors. By reducing the precision and speed of these components, the sensors would reveal less private information. From the hardware side, the ambient light sensor should not be directly facing the user on any smart device, they argued, but instead placed on the side, where it won't capture any significant touch interactions.

Getting the picture
The inversion process was applied to three demonstrations using an Android tablet. In the first test, the researchers seated a mannequin in front of the device, while different hands made contact with the screen. A human hand pointed to the screen, and later, a cardboard cutout resembling an open-hand gesture touched the monitor, with the pixelated imprints gathered by the MIT team revealing the physical interactions with the screen.

A subsequent demo with human hands revealed that the way users slide, scroll, pinch, swipe, and rotate could be gradually captured by hackers through the same imaging method, although only at a speed of one frame every 3.3 minutes. With a faster ambient light sensor, malicious actors could potentially eavesdrop on user interactions with their devices in real time.

In a third demo, the group found that users are also at risk when watching videos like films and short clips. A human hand hovered in front of the sensor while scenes from Tom and Jerry cartoons played on screen, with a white board behind the user reflecting light to the device. The ambient light sensor captured the subtle intensity changes for each video frame, with the resulting images exposing touch gestures.

While the vulnerabilities in ambient light sensors pose a threat, such a hack is still restricted. The speed of this privacy issue is low, with the current image retrieval rate being 3.3 minutes per frame, which overwhelms the dwell of user interactions.

Additionally, these pictures are still a bit blurry if retrieved from a natural video, potentially leading to future research. While telescreens can capture objects away from the screen, this imaging privacy issue is only confirmed for objects that make contact with a mobile device's screen, much like how selfie cameras cannot capture objects out of frame.

Two other EECS professors are also authors on the paper: CSAIL member William T. Freeman and MIT-IBM Watson AI Lab member Gregory Wornell, who leads the Signals, Information, and Algorithms Laboratory in the Research Laboratory of Electronics. Their work was supported, in part, by the DARPA REVEAL program and an MIT Stata Family Presidential Fellowship.

Research Report:"Imaging privacy threats from an ambient light sensor"

Related Links
Computer Science and Artificial Intelligence Laboratory (CSAIL)
Satellite-based Internet technologies

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
INTERNET SPACE
EU law prompts Apple to make major changes to App Store in Europe
Paris (AFP) Jan 26, 2024
Apple has announced major changes to its services in Europe that will allow iPhone users to download alternative app stores for the first time, as the US tech giant yields to new EU antitrust regulations. The overhaul, which will take place in March when the European Union's sweeping Digital Markets Act comes into force, will curtail the dominance of the App Store, which has been a mainstay of the iPhone since 2008. Users will for the first time be able to download software from outside the App ... read more

INTERNET SPACE
Virgin Galactic Marks 11th Spaceflight with Full Passenger Manifest

Cygnus spacecraft arrives at space station with 8,200 pounds of cargo

NASA's latest experiments aboard ISS aim to boost life in space

China warns US tech curbs will 'come back to bite them'

INTERNET SPACE
Ex-staff accuse SpaceX of sexual harassment, discrimination

MITRE and MDC team up to advance at Midland Spaceport

Starlab Partners with SpaceX to Launch Private Space Laboratory into Orbit

Sidus Space's 3D Hybrid satellite 'LizzieSat' ready for launch

INTERNET SPACE
Confirmation of ancient lake on Mars builds excitement for Perseverance rover's samples

NASA helicopter's mission ends after three years on Mars

New Year, New images from Perseverance on Mars

Polka Dots and Sunbeams: Sol 4078

INTERNET SPACE
BIT advances microbiological research on Chinese Space Station

Shenzhou 18 and 19 crews undertake intensive training for next missions

Tianzhou 6 burns up safely reentering Earth

Yan Hongsen's future dreams as 'Rocket Boy'

INTERNET SPACE
Intelsat Launches Inflight Internet Above the Arctic

Into the Starfield

Sidus ships LizzieSat to Vandenberg for upcoming SpaceX launch

Rocket Lab Launches $275 Million Convertible Note Offering for 2029 Maturity

INTERNET SPACE
New Data Prep Tool from Spatial to Streamline CAD Workflows

Six recycling innovations that could change fashion

Corning uses neutrons to reveal 'atomic rings' help predict glass performance

Ghana struggling with tsunami of secondhand clothes

INTERNET SPACE
UC Irvine-led team unravels mysteries of planet formation and evolution in distant solar system

NASA's Hubble Finds Water Vapor in Small Exoplanet's Atmosphere

TESS finds Super-Earth in habitable zone around nearby red dwarf

NASA Puts Next-Gen Exoplanet-Imaging Technology to the Test

INTERNET SPACE
New images reveal what Neptune and Uranus really look like

Researchers reveal true colors of Neptune, Uranus

The PI's Perspective: The Long Game

Webb rings in the holidays with the ringed planet Uranus

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.