Wearing Privacy at Risk: Privacy Leakages and Defense Strategies in Encrypted Traffic for Wearable Devices

Ransika Gunasekara · 2025

Wearable IoT devices, such as fitness trackers and smartwatches, transmit sensitive user data over Bluetooth protocols, making them vulnerable to traffic analysis attacks even when encryption is employed. However, existing research in encrypted traffic analysis has predominantly focused on Ethernet-based traffic, leaving a significant gap in understanding privacy leakages from wearable IoT devices. To address this gap, we first investigate the privacy threats posed by encrypted Bluetooth traffic analysis in wearable IoT devices, highlighting how adversaries can infer important data from encrypted communications. For this, we propose leveraging advanced time-series analysis techniques and few-shot learning models to tackle challenges such as limited training data and the heterogeneous nature of wearable IoT traffic. Next, we explore privacy-preserving defenses against encrypted traffic analysis designed specifically for wearable devices, considering their limited computational resources. We examine lightweight traffic-shaping mechanisms that enhance privacy while maintaining acceptable performance levels.

Read the paper · More papers on PaperTik