Earth Science News
INTERNET SPACE
Smart devices' ambient light sensors pose imaging privacy risk
A computational imaging algorithm from MIT demonstrates how ambient light sensors can expose touch interactions with our phones to hackers, who could process the sensor data from another device. Credits:Image: Alex Shipps/MIT CSAIL
Smart devices' ambient light sensors pose imaging privacy risk
by Alex Shipps | MIT CSAIL
Boston MA (SPX) Feb 05, 2024

In George Orwell's novel "1984," Big Brother watches citizens through two-way, TV-like telescreens to surveil citizens without any cameras. In a similar fashion, our current smart devices contain ambient light sensors, which open the door to a different threat: hackers.

These passive, seemingly innocuous smartphone components receive light from the environment and adjust the screen's brightness accordingly, like when your phone automatically dims in a bright room. Unlike cameras, though, apps are not required to ask for permission to use these sensors. In a surprising discovery, researchers from MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) uncovered that ambient light sensors are vulnerable to privacy threats when embedded on a smart device's screen.

The team proposed a computational imaging algorithm to recover an image of the environment from the perspective of the display screen using subtle single-point light intensity changes of these sensors to demonstrate how hackers could use them in tandem with monitors. An open-access paper on this work was published in Science Advances on Jan. 10.

"This work turns your device's ambient light sensor and screen into a camera! Ambient light sensors are tiny devices deployed in almost all portable devices and screens that surround us in our daily lives," says Princeton University professor Felix Heide, who was not involved with the paper. "As such, the authors highlight a privacy threat that affects a comprehensive class of devices and has been overlooked so far."

While phone cameras have previously been exposed as security threats for recording user activity, the MIT group found that ambient light sensors can capture images of users' touch interactions without a camera. According to their new study, these sensors can eavesdrop on regular gestures, like scrolling, swiping, or sliding, and capture how users interact with their phones while watching videos. For example, apps with native access to your screen, including video players and web browsers, could spy on you to gather this permission-free data.

According to the researchers, a commonly held belief is that ambient light sensors don't reveal meaningful private information to hackers, so programming apps to request access to them is unnecessary. "Many believe that these sensors should always be turned on," says lead author Yang Liu, a PhD student in MIT's Department of Electrical Engineering and Computer Science and a CSAIL affiliate.

"But much like the telescreen, ambient light sensors can passively capture what we're doing without our permission, while apps are required to request access to our cameras. Our demonstrations show that when combined with a display screen, these sensors could pose some sort of imaging privacy threat by providing that information to hackers monitoring your smart devices."

Collecting these images requires a dedicated inversion process where the ambient light sensor first collects low-bitrate variations in light intensity, partially blocked by the hand making contact with the screen. Next, the outputs are mapped into a two-dimensional space by forming an inverse problem with the knowledge of the screen content. An algorithm then reconstructs the picture from the screen's perspective, which is iteratively optimized and denoised via deep learning to reveal a pixelated image of hand activity.

The study introduces a novel combination of passive sensors and active monitors to reveal a previously unexplored imaging threat that could expose the environment in front of the screen to hackers processing the sensor data from another device. "This imaging privacy threat has never been demonstrated before," says Liu, who worked alongside Fredo Durand on the paper, who is an MIT EECS professor, CSAIL member, and senior author of the paper.

The team suggested two software mitigation measures for operating system providers: tightening up permissions and reducing the precision and speed of the sensors. First, they recommend restricting access to the ambient light sensor by allowing users to approve or deny those requests from apps.

To further prevent any privacy threats, the team also proposed limiting the capabilities of the sensors. By reducing the precision and speed of these components, the sensors would reveal less private information. From the hardware side, the ambient light sensor should not be directly facing the user on any smart device, they argued, but instead placed on the side, where it won't capture any significant touch interactions.

Getting the picture
The inversion process was applied to three demonstrations using an Android tablet. In the first test, the researchers seated a mannequin in front of the device, while different hands made contact with the screen. A human hand pointed to the screen, and later, a cardboard cutout resembling an open-hand gesture touched the monitor, with the pixelated imprints gathered by the MIT team revealing the physical interactions with the screen.

A subsequent demo with human hands revealed that the way users slide, scroll, pinch, swipe, and rotate could be gradually captured by hackers through the same imaging method, although only at a speed of one frame every 3.3 minutes. With a faster ambient light sensor, malicious actors could potentially eavesdrop on user interactions with their devices in real time.

In a third demo, the group found that users are also at risk when watching videos like films and short clips. A human hand hovered in front of the sensor while scenes from Tom and Jerry cartoons played on screen, with a white board behind the user reflecting light to the device. The ambient light sensor captured the subtle intensity changes for each video frame, with the resulting images exposing touch gestures.

While the vulnerabilities in ambient light sensors pose a threat, such a hack is still restricted. The speed of this privacy issue is low, with the current image retrieval rate being 3.3 minutes per frame, which overwhelms the dwell of user interactions.

Additionally, these pictures are still a bit blurry if retrieved from a natural video, potentially leading to future research. While telescreens can capture objects away from the screen, this imaging privacy issue is only confirmed for objects that make contact with a mobile device's screen, much like how selfie cameras cannot capture objects out of frame.

Two other EECS professors are also authors on the paper: CSAIL member William T. Freeman and MIT-IBM Watson AI Lab member Gregory Wornell, who leads the Signals, Information, and Algorithms Laboratory in the Research Laboratory of Electronics. Their work was supported, in part, by the DARPA REVEAL program and an MIT Stata Family Presidential Fellowship.

Research Report:"Imaging privacy threats from an ambient light sensor"

Related Links
Computer Science and Artificial Intelligence Laboratory (CSAIL)
Satellite-based Internet technologies

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
INTERNET SPACE
EU law prompts Apple to make major changes to App Store in Europe
Paris (AFP) Jan 26, 2024
Apple has announced major changes to its services in Europe that will allow iPhone users to download alternative app stores for the first time, as the US tech giant yields to new EU antitrust regulations. The overhaul, which will take place in March when the European Union's sweeping Digital Markets Act comes into force, will curtail the dominance of the App Store, which has been a mainstay of the iPhone since 2008. Users will for the first time be able to download software from outside the App ... read more

INTERNET SPACE
Fukushima operator reports leak, says no contamination detected

Ancient Antioch turns into container city year after quake

Global turbulence the 'new normal': EU's von der Leyen

Libya needs $1.8 bn to rebuild flood-devastated areas: report

INTERNET SPACE
New Data Prep Tool from Spatial to Streamline CAD Workflows

Six recycling innovations that could change fashion

Corning uses neutrons to reveal 'atomic rings' help predict glass performance

Ghana struggling with tsunami of secondhand clothes

INTERNET SPACE
Nestle admits treating some mineral waters

One third of French mineral waters receive banned treatments: report

Possible 'first' sighting of newborn great white shark

China's FY-3G commences space-based atmospheric precipitation measurements

INTERNET SPACE
Permafrost alone holds back Arctic rivers - and a lot of carbon

Greenland absorbs more methane than it emits: study

Scientists warn missing Russian data causing Arctic climate blind spots

Colombian mission to Antarctica analyzes climate change footprints

INTERNET SPACE
EU walks farming minefield with new climate goals

Caterpillar profits jump despite weakness in China

Tajikistan wants to stockpile food over climate change

Fixing food could produce trillions in annual benefits: report

INTERNET SPACE
Turkey quake survivors seek justice one year on

Cyclone hits northeast Australia leaving thousands without power

Japan says New Year quake damage could cost $17 billion

Nearly 60,000 killed in 2023 Turkey, Syria quake: new toll

INTERNET SPACE
EU 'regrets' Mali scrapping peace deal with separatists

Blinken nudges Nigeria on capital flows for US businesses

African Union troops complete new phase of Somalia pullout plan

UN 'appalled' by killing of 50 people in Mali attacks

INTERNET SPACE
US patient 'happy again' after brain implant treats epilepsy and OCD

App lets Indigenous Brazilians connect in own languages

Activists decry Tibet 'cultural genocide' ahead of China rights review

Woolly mammoth movements tied to earliest Alaska hunting camps

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.