Don’t Interrupt Me While I Type: Inferring Text Entered Through Gesture Typing on Android Keyboards

We present a new side-channel attack against soft keyboards that support gesture typing on Android smartphones. An application without any special permissions can observe the number and timing of the screen hardware interrupts and system-wide software interrupts generated during user input, and anal...

Full description

Bibliographic Details
Main Authors: Simon Laurent, Xu Wenduan, Anderson Ross
Format: Article
Language:English
Published: Sciendo 2016-07-01
Series:Proceedings on Privacy Enhancing Technologies
Subjects:
rnn
ml
Online Access:https://doi.org/10.1515/popets-2016-0020
Description
Summary:We present a new side-channel attack against soft keyboards that support gesture typing on Android smartphones. An application without any special permissions can observe the number and timing of the screen hardware interrupts and system-wide software interrupts generated during user input, and analyze this information to make inferences about the text being entered by the user. System-wide information is usually considered less sensitive than app-specific information, but we provide concrete evidence that this may be mistaken. Our attack applies to all Android versions, including Android M where the SELinux policy is tightened.
ISSN:2299-0984