Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi

Rui Xiao

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · WiFi and Bluetooth Security

Overview

In an era where Wi-Fi devices are ubiquitous, forming the backbone of our connected lives in homes, offices, and factories, a new class of privacy-invasive attacks is emerging. This talk, "Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi," presented by Rui Xiao from Jun University, unveils a novel attack dubbed Zikib Beam. This sophisticated yet practical attack transforms everyday Wi-Fi infrastructure into an adversarial motion sensor, capable of silently detecting human occupancy within a residence. Unlike traditional attacks that target data exfiltration or network traffic patterns, Zikib Beam operates entirely passively, requiring only a small sniffer device positioned outside a target location.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: Wi-Fi as an adversarial motion sensor
  2. 1:56 BFI packet ubiquity and severe real-world consequences
  3. 2:20 Understanding Beamforming and BFI packet purpose
  4. 3:10 Mechanism: How BFI reveals human activity
  5. 4:05 Zikib Beam: Silent occupancy detection attack features
  6. 5:30 Overcoming BFI phase offset for accurate detection
  7. 7:00 Evaluation results: High accuracy across devices, distances
  8. 9:00 Defense strategies: Encrypting or obfuscating BFI content

Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi

Speakers: Rui Xiao, Jun University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=0dOP8zpyVzA

Overview

In an era where Wi-Fi devices are ubiquitous, forming the backbone of our connected lives in homes, offices, and factories, a new class of privacy-invasive attacks is emerging. This talk, "Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi," presented by Rui Xiao from Jun University, unveils a novel attack dubbed Zikib Beam. This sophisticated yet practical attack transforms everyday Wi-Fi infrastructure into an adversarial motion sensor, capable of silently detecting human occupancy within a residence. Unlike traditional attacks that target data exfiltration or network traffic patterns, Zikib Beam operates entirely passively, requiring only a small sniffer device positioned outside a target location.

The core of this vulnerability lies in the Beamforming Feedback Information (BFI) packets, regular control frames transmitted in plaintext from Wi-Fi client devices to access points (APs). While BFI is fundamental to enhancing Wi-Fi signal directionality and strength, it inadvertently carries sensitive spatial information that changes with human presence and movement. The Zikib Beam attack capitalizes on this side channel, allowing an attacker to deduce whether a home is occupied, whether individuals are moving, or even if they are stationary, simply by eavesdropping on these unencrypted packets. The widespread deployment of BFI—present in 86% of Wi-Fi 5 and 6 devices—coupled with its plaintext transmission and long-range detectability (up to 20 meters), underscores the severe privacy and security implications, from continuous surveillance to aiding burglaries.

Background

▶ Watch: Introduction: Wi-Fi as an adversarial motion sensor (0:00)

To understand the Zikib Beam attack, it's essential to first grasp the concept of beamforming in Wi-Fi networks. Beamforming is a crucial technique designed to improve wireless communication efficiency and range. Instead of broadcasting Wi-Fi signals indiscriminately, beamforming allows an AP to directionally focus its signal toward a specific client device. This targeted transmission enhances signal quality, reduces interference, and optimizes data rates.

The mechanism relies on the AP possessing spatial information, often referred to as a steering matrix, which dictates the precise direction for signal transmission. This steering matrix is not static; it needs to be continuously updated to account for environmental changes and client mobility. The process begins with a sounding process, where the AP and the client exchange preliminary information. Following this, the client measures the channel characteristics and computes the necessary spatial information. This computed information, the steering matrix, is then reported back to the AP in the form of Beamforming Feedback Information (BFI) packets. These BFI packets are transmitted frequently, typically at a rate of around 10 Hz, ensuring that the AP has up-to-date spatial data for effective beamforming.

The critical vulnerability exploited by Zikib Beam stems from the nature of this spatial information. While intended purely for optimizing wireless links, the physical environment between the AP and the client, including the presence and movement of occupants, directly influences the radio signal paths. Consider a room with two primary signal paths between an AP and a client. When no one is present, the BFI values tend to be relatively stable. However, when an occupant enters the room, they can obstruct one or more of these signal paths. This obstruction causes a measurable drop in the BFI value. Furthermore, as the occupant moves, they don't just block signals; they create new, dynamic signal reflections and refractions, leading to significant fluctuations and variations in the BFI values. It is these subtle yet consistent changes in BFI that Zikib Beam leverages to infer human activity and occupancy. The problem isn't that BFI exists, but that it's transmitted in plaintext, making it accessible to any passive sniffer within range, and that its contents are inherently linked to the physical environment and, by extension, human presence.

Key Findings

▶ Watch: Understanding Beamforming and BFI packet purpose (2:20)

The central contribution of this research is the introduction of Zikib Beam, a novel silent occupancy detection attack that re-purposes standard Wi-Fi infrastructure into an adversarial motion sensor. The key findings highlight the attack's capabilities, its underlying mechanisms, and its practical implications.

Zikib Beam is characterized by four primary features:

  1. High Accuracy: The attack is not limited to detecting gross movements. It can accurately identify both moving occupants and even stationary individuals engaged in daily activities, such as breathing.
  2. Stealthiness: Zikib Beam operates purely through passive sniffing. The attacker's device does not transmit any signals, making it undetectable by conventional network intrusion detection systems. This stealth significantly lowers the risk of detection for the attacker.
  3. Accessibility: The attack leverages the plaintext nature of BFI packets. This means that any off-the-shelf Wi-Fi sniffer, such as a laptop running Wireshark, can capture and analyze these packets without requiring special hardware or cryptographic keys.
  4. Long Range: Zikib Beam demonstrates impressive range capabilities, effectively detecting occupancy at distances of up to 20 meters. This range allows an attacker to operate from a safe and discreet distance outside a target residence.

The detection methodology employed by Zikib Beam is multi-faceted, adapting to different states of occupancy:

  • Detecting Moving Occupants: The initial phase of detection focuses on identifying human motion by observing the variance of amplitude within the BFI signals. As an occupant moves, the signal paths are dynamically altered, leading to easily discernible fluctuations in amplitude. This method effectively captures active movement.
  • Detecting Stationary Occupants: A significant challenge in occupancy detection is identifying stationary individuals. Simple amplitude variance is insufficient here, as a stationary person causes minimal amplitude changes. Zikib Beam refines its detection by incorporating phase information. By analyzing the spectrogram of the phase components of the BFI, the system can capture subtle, periodic patterns, such as an occupant's breathing pattern. This advanced technique allows Zikib Beam to detect even motionless individuals, significantly enhancing its overall accuracy and intrusiveness.

The effectiveness of Zikib Beam was rigorously evaluated across various real-world scenarios:

  • Improved True Positive Rate: Initial attempts using only amplitude information yielded a true positive rate of approximately 50%, meaning roughly half of the occupants went undetected. However, by integrating both amplitude and crucial phase information, the true positive rate dramatically increased to around 80%, making Zikib Beam highly effective for practical occupancy detection.
  • Device Agnostic: The attack proved effective across a wide array of victim devices. BFI packets transmitted from diverse Wi-Fi clients, including smart speakers, cameras, tablets, and smart TVs, were all susceptible to the attack. This broad compatibility underscores the pervasive nature of the vulnerability.
  • Traffic Pattern Resilience: Zikib Beam performed consistently well regardless of the background network traffic patterns. It maintained its accuracy even when client devices were actively transmitting different types of data or were entirely idle, indicating its robustness against varying network conditions.
  • High Accuracy at Range: The attack achieved an impressive overall accuracy of 88% at distances up to 20 meters, confirming its practical viability for remote surveillance.

These findings collectively demonstrate that Zikib Beam is a highly effective, stealthy, and practical attack vector, leveraging an overlooked side channel in standard Wi-Fi protocols to infer sensitive occupancy information.

Technical Deep Dive

▶ Watch: Zikib Beam: Silent occupancy detection attack features (4:05)

The technical foundation of Zikib Beam lies in the intricate relationship between Channel State Information (CSI) and Beamforming Feedback Information (BFI), and the clever manipulation of these signals to overcome inherent Wi-Fi system complexities.

At its core, BFI is derived from the CSI, which represents the channel properties of a communication link. For instance, consider an AP with two antennas and a client device with a single antenna. In this configuration, the CSI can be represented as a row vector containing two complex values. These complex values encapsulate both the amplitude and phase information of the signals received across the different paths between the antennas.

A significant technical challenge arises from the unsynchronization between the AP and the client devices. This lack of perfect synchronization introduces a phase offset into the CSI values. Since BFI is essentially the right singular matrix of CSI, it inherently inherits this problematic phase offset. The critical issue is that the exact transformation used to derive BFI from CSI, and thus the nature of this phase offset, is unknown to an external attacker. This makes it exceedingly difficult for an attacker to directly recover the original, true phase information that would reveal subtle patterns like breathing. Without addressing this, the detection of stationary occupants through their breathing patterns would be severely hampered.

To circumvent this challenge, the researchers proposed an intuitive yet powerful solution: deriving a new feature, denoted as R, which is entirely phase offset-free. The derivation of R is mathematically elegant and relies on the properties of complex numbers. If the CSI values are represented as H1 and H2 (complex numbers), and they share a common phase offset, then their conjugated multiplication (e.g., H1 conjugate(H2)) effectively cancels out this common phase offset. The proof for this is straightforward: if H1 = |H1| e^(jθ + jφ) and H2 = |H2| e^(jθ), where θ is the common phase offset and φ is the relative phase difference between the paths, then H1 conjugate(H2) = (|H1| e^(jθ + jφ)) (|H2| e^(-jθ)) = |H1||H2| e^(jφ). The common phase offset (θ) is eliminated, leaving only the relative phase difference (φ), which is directly relevant to environmental changes. This new feature R thus provides a stable and reliable signal for detecting subtle variations, such as the breathing patterns of stationary occupants, that would otherwise be obscured by the unknown phase offset.

The practical implementation of Zikib Beam highlights its low barrier to entry for attackers. The system was implemented using an ordinary laptop with no external antenna, relying solely on its integrated Wi-Fi capabilities. Packet sniffing was performed using Wireshark, a widely available and standard network protocol analyzer. This minimalist setup demonstrates that an attacker does not require specialized, expensive hardware, making the attack highly accessible.

For evaluation, the researchers conducted extensive experiments across diverse environments. They utilized eight different Wi-Fi APs and tested in three distinct physical environments. To ensure robustness and generalize the findings, the layout within each environment was systematically altered three times, simulating varying real-world conditions. The assessment of occupancy detection, being a two-class classification problem (occupied vs. unoccupied), relied on two standard metrics: True Positive Rate (TPR) and True Negative Rate (TNR). The success of Zikib Beam, particularly its ability to achieve an 80% TPR when incorporating both amplitude and the phase-offset-free feature R, underscores the effectiveness of this technical approach in overcoming inherent Wi-Fi signal complexities for covert surveillance.

Demo / Proof of Concept

▶ Watch: Overcoming BFI phase offset for accurate detection (5:30)

While the talk did not feature a live, interactive demonstration of Zikib Beam in action, the researchers presented a comprehensive proof of concept through their rigorous implementation and evaluation methodology. This section details how the attack was practically realized and its performance validated, effectively serving as a demonstration of its feasibility and efficacy.

The proof of concept for Zikib Beam was established through a series of experiments designed to simulate real-world attack scenarios and measure the system's performance. The setup was deliberately kept simple to underscore the accessibility of the attack:

  • Attacker Hardware: An ordinary laptop was used as the attacker's device. Crucially, this laptop did not require any specialized or external antennas, relying solely on its built-in Wi-Fi adapter. This choice emphasizes that the attack can be mounted with readily available consumer-grade equipment.
  • Sniffing Software: Wireshark, a common and free network protocol analyzer, was employed for packet sniffing. This demonstrates that no proprietary or complex software is needed, further lowering the barrier for potential attackers.
  • Target Environments: The experiments were conducted across eight different Wi-Fi Access Points (APs) and in three distinct environmental layouts. To ensure the generalizability and robustness of the findings, the researchers varied the internal layout of each environment three times, simulating changes in furniture, obstacles, and general room configurations. This rigorous testing across diverse settings validates the attack's adaptability.

The evaluation served as a concrete demonstration of Zikib Beam's capabilities:

  • Detection of Moving Occupants: The system successfully demonstrated its ability to detect moving occupants by analyzing the variance of amplitude in the BFI signals. Visual representations presented during the talk showed clear spikes in amplitude variance corresponding to human movement, effectively proving this foundational detection capability.
  • Detection of Stationary Occupants: The more challenging aspect, detecting stationary occupants, was demonstrated through the successful application of the phase-offset-free feature R. The spectrograms generated from this feature clearly captured breathing patterns, illustrating the system's ability to infer presence even without overt movement. This specific finding is a strong proof of concept for the advanced capabilities of Zikib Beam.
  • Performance Metrics: The quantitative results served as the ultimate demonstration of the attack's effectiveness. The system achieved a true positive rate of approximately 80% for occupancy detection when both amplitude and phase information were utilized. Furthermore, it demonstrated an overall accuracy of 88% at distances up to 20 meters. These figures unequivocally prove that Zikib Beam is not merely a theoretical concept but a practically viable and highly effective surveillance tool.
  • Device and Traffic Agnostic Performance: The ability of Zikib Beam to function consistently across various client devices (e.g., smart speakers, tablets, smart TVs) and under different network traffic conditions (from idle to active data transmission) further solidified its robustness as a proof of concept. It showcased that the vulnerability is inherent to the BFI mechanism itself, rather than being dependent on specific device types or usage patterns.

In essence, the detailed description of the implementation, the experimental setup, and the compelling performance metrics presented in the talk collectively served as a robust proof of concept, clearly demonstrating the practical feasibility and significant privacy implications of the Zikib Beam attack.

Defensive Implications

▶ Watch: Defense strategies: Encrypting or obfuscating BFI content (9:00)

The Zikib Beam attack exposes a critical privacy vulnerability stemming directly from the plaintext transmission of Beamforming Feedback Information (BFI) packets. Addressing this vulnerability requires a careful balance between security enhancements and maintaining the functionality and ubiquity of Wi-Fi.

A straightforward solution to prevent such passive sniffing attacks would be to encrypt the transmission of BFI packets. However, the speaker acknowledges that this approach, while ideal from a security standpoint, is difficult and unrealistic in practice. The global installed base of Wi-Fi client devices is enormous and diverse, ranging from legacy Wi-Fi 4 devices to the latest Wi-Fi 6/6E hardware. Updating all these devices to support a new encryption standard for control frames like BFI would be a monumental and likely impossible task, incurring significant costs and compatibility issues.

Given these constraints, the researchers propose an effective defense mechanism that aims to obfuscate the content of BFI packets while deliberately retaining their plaintext transmission. This approach seeks to make the BFI data unintelligible to an attacker, thereby preventing the inference of sensitive user data, without disrupting the core beamforming functionality or requiring widespread device upgrades.

The proposed defense mechanism works as follows:

  1. Random Mapping at the AP: In the original BFI measurement process, the AP transmits a standard long training symbol (X) to the client. In the proposed defense, the AP instead transmits a randomly mapped version of this training symbol. This random mapping acts as a transformation on the transmitted signal.
  2. Client-Side Process Unaffected: The client device receives this randomly mapped training symbol. Crucially, the client's internal processes remain unaffected; it measures the Channel State Information (CSI) and computes the steering matrix as it normally would, based on the received signal.
  3. Obfuscated BFI Return: When the client returns the computed steering matrix (BFI) to the AP, this BFI is now inherently obfuscated due to the initial random mapping of the training symbol. To an eavesdropping attacker, this obfuscated BFI appears as random noise, preventing them from inferring any meaningful spatial information or occupancy data.
  4. AP Recovery: The AP, which initiated the random mapping, possesses the necessary information to recover the original steering matrix. This is achieved through a simple matrix multiplication, leveraging known mathematical properties of the transformation. This ensures that the beamforming functionality remains fully effective, as the AP can still accurately direct its signals.

The features of this defense mechanism highlight its practicality and minimal impact:

  • Minimal Impact on Communication: Beamforming, the primary purpose of BFI, remains fully effective. The AP can still accurately calculate and apply the steering matrix, ensuring optimal signal direction and communication performance.
  • Minimal Hardware Modification: This defense strategy requires no modification to client devices. They continue to operate as usual, measuring channels and reporting BFI. For the AP, the modification involves reusing existing spatial mapping mechanisms to implement the random transformation, minimizing the need for new hardware or complex firmware changes.
  • One-Time Pad Principle: During the Q&A session, the speaker clarified that the random mapping matrix is not static but behaves like a one-time pad, constantly changing. This dynamic nature prevents an attacker from inferring the mapping pattern over time, making it statistically impossible to reverse-engineer the obfuscation. A formal proof for this security guarantee is provided in the paper's appendix.

The proposed defense offers a pragmatic and effective countermeasure to the Zikib Beam attack, providing a path to secure Wi-Fi networks against passive occupancy detection without demanding an impractical overhaul of existing infrastructure.

Key Takeaways

  • Ubiquitous Wi-Fi BFI Exposes Privacy: Standard Beamforming Feedback Information (BFI) packets, transmitted in plaintext by 86% of Wi-Fi 5 and 6 devices, inadvertently leak sensitive spatial information that can be exploited for privacy-invasive surveillance.
  • Zikib Beam: A Stealthy, Long-Range Attack: The Zikib Beam attack passively sniffs plaintext BFI to silently detect human occupancy, operating stealthily without transmitting any signals and effective at distances up to 20 meters.
  • Human Activity Alters BFI: Occupants block signal paths (reducing BFI amplitude) or create dynamic reflections (causing BFI fluctuations), providing a detectable side channel for presence and movement.
  • Advanced Detection for Stationary Occupants: Zikib Beam detects moving occupants via amplitude variance, but innovatively identifies stationary individuals by extracting their subtle breathing patterns from phase information, enabled by a novel phase-offset-free feature 'R'.
  • High Accuracy and Broad Compatibility: The attack achieves an 80% true positive rate (88% overall accuracy) and works across various client devices (smart speakers, cameras, tablets) and network traffic conditions, demonstrating its robustness.
  • Practical Defense Through Obfuscation: A proposed defense mechanism involves the AP randomly mapping training symbols, causing clients to return obfuscated BFI. The AP can still recover the original steering matrix, while attackers are blocked, providing a practical solution with minimal hardware impact and maintaining beamforming effectiveness.

About the Speaker(s)

Rui Xiao is a researcher affiliated with Jun University. The speaker presented this work at the prestigious NDSS Symposium, highlighting expertise in wireless security. While specific titles or detailed biographical information were not provided in the transcript, the depth and technical rigor of the "Lend Me Your Beam" talk demonstrate a strong background in analyzing and mitigating vulnerabilities in modern wireless communication systems. The Q&A session also indicated that other researchers from "Jan University" (likely the same institution as Jun University) were present, suggesting a collaborative research environment.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original wireless security research that identifies a genuinely overlooked side channel in a protocol component nobody was looking at. The attack is passive, practical, and the defensive proposal is technically coherent rather than the usual hand-wavy 'encrypt everything' non-answer.

Heather Calloway (CISO) — WEAK

Technically credible research that exposes a real privacy side channel in widely deployed Wi-Fi infrastructure, but it stops at the protocol layer and never climbs to where decisions get made. The defensive proposal is interesting but narrowly scoped, and the talk offers nothing to the people who actually govern the risk.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025