arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

MacBookの内蔵慣性センサーから入力情報が漏れる可能性

Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel

Jiaji He, Yi Shi, Junfeng Cai, Chang Liu, Yongqiang Lyu

この論文をやさしく読む

ひとことで言うと

ノートパソコン内部の振動センサーが、打鍵や使用環境の手掛かりまで捉える情報漏洩を報告しています。

何に役立つ?

センサーのアクセス権限や、入力内容を直接含まないメタデータのプライバシー影響を見直す材料になります。

この研究の面白いところ

キーボードの文字だけでなく、机の種類や入力者に関する特徴も同じセンサーから得られる点を扱っています。

どこまで分かった?

精度は著者らの評価条件での報告です。100%復元は一部の文に限られ、要旨には対象機種、OSの範囲や修正状況の詳細はありません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

近年のApple MacBookには、装置の向きや動きを検知するため、ユニボディ筐体の中に慣性計測装置(IMU)が組み込まれている。しかしこのIMUは、意図された装置レベルの情報だけでなく、ユーザー操作や周囲の環境から生じる微細な物理振動も意図せず捉える。これらの信号は、これまで調べられていなかった新たなサイドチャネルを形成する。本研究では、IOKitドライバを通じてroot権限なしでIMUデータへアクセスできる脆弱性を発見する。また、内容そのものを含まない二つのシステムメタデータ・インターフェース、HIDIdleTimeとCGEventSourceが、このサイドチャネルの漏洩をさらに強めることを示す。 IMUデータを厳密に特徴付けることで、漏洩が三つの主要な側面に及ぶことを明らかにする。(1)打鍵されたキーの識別、(2)ノートパソコンが置かれた机の表面、(3)誰が入力しているかというユーザーの行動である。これらの知見を用い、Apple MacBookの内蔵IMUを対象とする初の包括的な非特権サイドチャネル攻撃BRUTUSを導入する。BRUTUSはキー復元で文字単位89.1〜97.5%の精度を達成する。さらに言語モデルの支援により、一部の文を100%の精度で復元できる。ユーザー識別と環境のプロファイリングでは、ラベルなしでユーザーと環境のプロファイルを正しく発見し、後続の区間を対応するプロファイルへ正しく割り当てる。最終的に本研究は、内蔵IMUセンサーへのアクセスを厳格に規制する緊急の必要性を強調する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-18(UTC)
最新改訂
2026-09-18 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Recent generations of Apple MacBooks embed an inertial measurement unit (IMU) within their unibody chassis for device orientation and motion sensing. However, this IMU inadvertently captures not only intended device-level information but also subtle physical vibrations from user interactions and the surrounding environment. These signals establish a novel, previously unexplored side channel. We uncover a vulnerability allowing non-root access to IMU data via an IOKit driver, alongside two content-free system metadata interfaces (HIDIdleTime and CGEventSource) that further enrich the side-channel leakage. Through rigorous characterization of the IMU data, we reveal that the leakage spans three core dimensions: (1) keystroke identity (which key is typed), (2) desk surface (where the laptop is placed), and (3) user behavior (who is typing). Leveraging these findings, we introduce BRUTUS, the first comprehensive unprivileged side-channel attack targeting built-in IMU sensors on Apple MacBooks. BRUTUS achieves a character-level accuracy of 89.1% to 97.5% in key recovery. Furthermore, aided by language models, it can successfully reconstruct certain sentences with 100% accuracy. For user identification and environment profiling, BRUTUS correctly discovers user and environment profiles without labels and correctly assigns subsequent segments to their corresponding profiles. Ultimately, this work highlights the urgent necessity of strictly regulating access to built-in IMU sensors.

arXiv ID: 2609.21569 / 要約の誤りについて