New Mic-E-Mouse Attack Let Hackers Exfiltrate Sensitive Data by Exploiting Mouse Sensors
Researchers have identified a new cybersecurity vulnerability termed the "Mic-E-Mouse" attack. This technique involves transforming a standard computer mouse into a device capable of eavesdropping, exploiting the high-performance optical sensors found in…
Researchers have identified a new cybersecurity vulnerability termed the "Mic-E-Mouse" attack. This technique involves transforming a standard computer mouse into a device capable of eavesdropping, exploiting the high-performance optical sensors found in many modern mice.
The attack allows the capture and reconstruction of user speech through the detection of vibrations caused by speech on a desk or work surface. This vulnerability is particularly linked to the sensitivity and polling rates of optical sensors in consumer-grade mice, common in gaming and high-performance models.
The Mic-E-Mouse attack utilizes the mouse's sensor to detect microscopic vibrations emanating from the acoustic environment. However, the raw signal from these vibrations is distorted due to high noise levels, non-uniform sampling, and extreme quantization.
To address these challenges, a sophisticated pipeline of signal processing and machine learning techniques has been developed. This pipeline is capable of filtering noise and correcting distortions to reconstruct an intelligible audio waveform.
Researchers have identified a new cybersecurity vulnerability termed the "Mic-E-Mouse" attack.
Tests conducted with the VCTK and AudioMNIST speech datasets demonstrated a Signal-to-Interference-plus-Noise Ratio (SI-SNR) increase of +19dB. Additionally, automated tests showed an 80% accuracy in speaker recognition, while a human study reported a Word Error Rate (WER) of 16.79%.
The attack's threat model suggests using open-source software as a delivery vehicle. Applications that naturally collect high-frequency mouse data, such as video games and creative software, are particularly vulnerable.
Once an application is compromised, it can begin collecting mouse sensor data. This data can be exfiltrated using existing networking code in the application, remaining undetected by security software.
The affordability of high-fidelity mice, often priced under $50, increases the potential attack surface. As technology advances, more consumers and organizations are expected to use these vulnerable devices.
The research highlights that most human speech falls within the 200Hz to 2000Hz frequency range, which the pipeline can effectively detect and reconstruct. The study demonstrates that auditory surveillance through high-performance optical sensors is a practical threat.
Based on reporting by Cyber Security News.
