Traffic Manipulation via Beamforming Feedback Forgery in Practical Wi-Fi Systems
Yinghui He, Mingming Xu, Xin Yan Li, Jingzhi Hu, Zhe Chen, Fu Xiao, Jun Luo · IEEE Transactions on Mobile Computing · 2025
New Wi-Fi systems have leveraged beamforming to manage a significant portion of traffic for achieving high throughput and reliability. Unfortunately, this has amplified certain security risks since beamforming critically relies on theclear-textbeamforming feedback information (BFI): though similar risks have been exposed using emulation platforms (e.g., USRP), they have never proven realistic till this day. In this paper, we propose BeamCraft, thefirstattack to manipulate traffic incommodityWi-Fi systems; it differs significantly from existing attacks either staying only on emulation platforms with limited real-world applicability or jamming communications by brute force. The core idea of BeamCraft involves corrupting beamforming decisions by injecting crafted BFIs that feed an access point (AP) with erroneous information on channel states. To mount a covert yet purposeful attack, we develop i) a joint location and transmit power selection strategy to evade detection by victims and ii) a novel BFI forgery method to effectively manipulate AP's beamforming decisions. We implement BeamCraft using commodity Wi-Fi devices and perform extensive evaluations with it; the results reveal that BeamCraft effectively manipulates Wi- Fi traffic while maintaining a low exposure rate. Furthermore, we also introduce a defense strategy, namely BeamCrypt, that jointly leverages reciprocity and similarity of the channel within the coherence time to authenticate the legitimate user with low overhead. We implement it using WARP and evaluation results verify the effectiveness.