剖析Wi-Fi CSI生物识别的安全漏洞与评估缺陷,揭示隐藏风险。
SoK: Security Evaluation of Wi-Fi CSI Biometrics: Attacks, Metrics, and Open Challenges
- 从安全角度系统梳理现有方法的差异与漏洞
- 发现传统指标掩盖了高风险集中问题
- 提出新评估框架,适合安全研究者参考
Wi-Fi信道状态信息(CSI)被多次提出作为生物识别模态,常宣称具备高准确率和可行性。然而,该领域缺乏对安全特性、抗攻击能力及方法一致性全面理解。本文以知识体系化(SoK)视角,分析现有工作在感知设备、信号表示、特征处理、学习模型和评估方法上的分歧。综合发现系统性问题:依赖聚合准确率、有限报告误报率(FAR)、拒识率(FRR)与等错误率(EER)、缺少用户级风险分析,且忽视威胁模型与攻击可行性。为此,构建统一评估框架,实证揭示传统报告方式掩盖的风险集中现象。通过每类错误率(per-class EER)、得分频率统计(FCS)和吉尼系数,暴露攻击面——包括重放攻击、几何模拟与环境扰动。结果表明方法选择显著影响脆弱性分布。据此界定当前CSI生物识别的安全边界,提出严谨评估、可复现实验及未来研究建议。本研究为安全社区提供基于证据的重新审视,评估其作为认证原语的适用性。
原文摘要 · Abstract (English)
Wi-Fi Channel State Information (CSI) has been repeatedly proposed as a biometric modality, often with reports of high accuracy and operational feasibility. However, the field lacks a consolidated understanding of its security properties, adversarial resilience, and methodological consistency. This Systematization of Knowledge (SoK) examines CSI-based biometric authentication through a security lens, analyzing how existing works diverge in sensing infrastructure, signal representations, feature pipelines, learning models, and evaluation methodologies. Our synthesis reveals systemic inconsistencies: reliance on aggregate accuracy metrics, limited reporting of FAR/FRR/EER, absence of per-user risk analysis, and scarce consideration of threat models or adversarial feasibility. To this end, we construct a unified evaluation framework to expose these issues empirically and demonstrate how security-relevant metrics such as per-class EER, Frequency Count of Scores (FCS), and the Gini Coefficient uncover risk concentration that remains hidden under traditional reporting practices. The resulting analysis highlights concrete attack surfaces--including replay, geometric mimicry, and environmental perturbation--and shows how methodological choices materially influence vulnerability profiles. Based on these findings, we articulate the security boundaries of current CSI biometrics and provide guidelines for rigorous evaluation, reproducible experimentation, and future research directions. This SoK offers the security community a structured, evidence-driven reassessment of Wi-Fi CSI biometrics and their suitability as an authentication primitive.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。