Invisible eyes: Real-time activity detection through encrypted Wi-Fi traffic without machine learning
Muhammad Bilal Rasool, Uzair Muzamil Shah, Mohammad Imran, Daud Mustafa Minhas, Georg Frey · Internet of Things · 2025
Wi-Fi camera-based home monitoring systems are increasingly popular for improving security and real-time observation. However, reliance on Wi-Fi introduces privacy vulnerabilities, as sensitive activities within monitored areas can be inferred from encrypted traffic. This paper presents a lightweight, non-ML attack model that analyzes Wi-Fi traffic metadata—such as packet size variations, serial number sequences, and transmission timings—to detect live streaming, motion detection, and person detection. Unlike machine learning-based approaches, our method requires no training data or feature extraction, making it computationally efficient and easily scalable. Empirical testing at varying distances (10 m, 20 m, and 30 m) and under different environmental conditions shows accuracy rates of up to 90% at close range and 72% at greater distances, demonstrating its robustness. Compared to existing ML-based techniques, which require extensive retraining for different camera manufacturers, our approach provides a universal and adaptable attack model. This research underscores significant privacy risks in Wi-Fi surveillance systems and emphasizes the urgent need for stronger encryption mechanisms and obfuscation techniques to mitigate unauthorized activity inference. • Wi-Fi cameras enhance security but risk privacy via encrypted traffic analysis. • Detects streaming, motion, person using Wi-Fi patterns, no ML or big data. • Scalable method avoids ML, achieves 90% accuracy in real-time detection. • Notification timing, packet size expose info, highlighting privacy risks. • Urges stronger privacy in Wi-Fi surveillance, offers actionable insights.