AcouListener: An Inaudible Acoustic Side-Channel Attack on AR/VR Systems

  • Fengliang He
  • , Hong-Ning Dai*
  • , Hanyang Guo
  • , Xiapu Luo
  • , Jiadi Yu
  • *Corresponding author for this work

Research output: Chapter in book/report/conference proceedingConference proceedingpeer-review

Abstract

Although augmented reality (AR) and virtual reality (VR) systems have garnered extensive attention from both industry and academia, their built-in sensors continuously collect sensitive user data, making them potential targets for malicious attacks. To assess the threat of inaudible acoustic channels in AR/VR, we propose AcouListener, a novel side-channel attack that uses inaudible acoustic signals emitted and received by off-the-shelf VR headsets or mobile phones. Variations in the acoustic channel caused by hand movements allow attackers to reconstruct user input (e.g., passwords). AcouListener is implemented as a camouflaged mobile app that runs on AR/VR or mobile platforms. We evaluate it across three common VR attack scenarios: (1) inferring victims’ unlocking patterns, (2) handwriting patterns and (3) typing words and passwords on virtual keyboards. AcouListener achieves an average F1-score of 84%, 95% and 80%, respectively. Furthermore, we present countermeasures against this inaudible acoustic attack.
Original languageEnglish
Title of host publicationComputer Security – ESORICS 2025
Subtitle of host publication30th European Symposium on Research in Computer Security, Toulouse, France, September 22–24, 2025, Proceedings, Part III
EditorsVincent Nicomette, Abdelmalek Benzekri, Nora Boulahia-Cuppens, Jaideep Vaidya
Place of PublicationCham
PublisherSpringer Cham
Pages164-183
Number of pages20
Volume3
Edition1st
ISBN (Electronic)9783032078940
ISBN (Print)9783032078933
DOIs
Publication statusPublished - 17 Oct 2025
Event30th European Symposium on Research in Computer Security - Toulouse University, Toulouse, France
Duration: 22 Sept 202524 Sept 2025
https://link.springer.com/book/10.1007/978-3-032-07884-1 (Conference proceeding)
https://esorics2025.sciencesconf.org/ (Conference website)
https://esorics2025.sciencesconf.org/data/detailed_program.pdf (Conference program)

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume16055
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349
NameEuropean Symposium on Research in Computer Security
PublisherSpringer

Conference

Conference30th European Symposium on Research in Computer Security
Abbreviated titleESORICS 2025
Country/TerritoryFrance
CityToulouse
Period22/09/2524/09/25
Internet address

User-Defined Keywords

  • Augmented Reality
  • Side-channel Attacks
  • Virtual Reality

Fingerprint

Dive into the research topics of 'AcouListener: An Inaudible Acoustic Side-Channel Attack on AR/VR Systems'. Together they form a unique fingerprint.

Cite this