A team at Germany’s Karlsruhe Institute of Technology put 197 people in front of an ordinary WiFi setup and identified them with almost 100% accuracy. No camera. No phone in anyone’s pocket. Just the radio traffic your router is already spraying across the room.
That last part is what makes this different from every other “WiFi can see you” study of the past decade. Those needed special gear. This one doesn’t.
It works like a camera, minus the lens
“By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present,” said Thorsten Strufe, a professor at KASTEL, KIT’s Institute of Information Security and Dependability.
“This works similar to a normal camera, the difference being that in our case, radio waves instead of light waves are used for the recognition,” Strufe said.
Because the system reads waves moving through a space rather than pinging a gadget, you don’t need to be carrying anything. “Thus, it does not matter whether you carry a WiFi device on you or not.”
And switching off your own phone doesn’t get you out of it either. “It’s sufficient that other WiFi devices in your surroundings are active.”
Read that twice. Your privacy here depends on the behavior of strangers’ devices, not your own.
The unencrypted data that makes it possible
Previous attempts at seeing people through walls leaned on LIDAR sensors, which measure distance by firing light and reading the reflection, or on channel state information, the detailed measurements of how a radio signal warps as it bounces off walls, furniture and bodies. Both mean specialized equipment or heavier measurement work.
The KIT method skips all of it. A standard WiFi device is enough, according to the researchers.
The trick is beamforming feedback information, or BFI. Devices connected to a WLAN routinely report back to the router to help tune the wireless link. Those reports go out unencrypted, which means anyone in range can read them.
Feed enough of that into the system and you get images of a person from multiple viewpoints, which is what makes an identity match possible. Once the machine learning model has been trained on someone, recognizing them again takes a few seconds.
In the 197-person study, the system inferred identities with almost 100% accuracy regardless of the viewing perspective or the way a person walked. Gait tricks won’t save you.
Every router is now a potential camera you can’t see
“This technology turns every router into a potential means for surveillance,” said Julian Todt of KASTEL. “If you regularly pass by a cafe that operates a WiFi network, you could be identified there without noticing it and be recognized later — for example by public authorities or companies.”
The researchers are refreshingly unwilling to oversell the immediate threat. Felix Morsbach notes there are easier routes today for intelligence agencies or criminals who want to watch you, like breaking into existing CCTV systems or connected video doorbells.
The concern is what comes next. “However, the omnipresent wireless networks might become a nearly comprehensive surveillance infrastructure with one concerning property: they are invisible and raise no suspicion.”
That’s the actual story. A security camera is a physical object you can spot, photograph and complain about. A router sitting behind a espresso machine tells you nothing about what its signals are being used for.
Why the fix has to happen in the standard
“The technology is powerful, but at the same time entails risks to our fundamental rights, especially to privacy,” Strufe said.
The team is most worried about authoritarian states, where WiFi based identification could be turned on protesters or other groups without any of the visible hardware that normally signals surveillance is happening. No cameras to smash, no lenses to cover.
Their argument is that because wireless networks are already everywhere, in homes, offices, restaurants and public spaces, protections need to be designed in before this gets cheap and easy to run at scale. They’re calling for safeguards to be written into the forthcoming IEEE 802.11bf WiFi standard.
The work was funded under the Helmholtz “Engineering Secure Systems” topic, and the results were presented at the ACM Conference on Computer and Communications Security in Taipei.
If you want something concrete to take away: the vulnerable piece here is BFI, and it’s unencrypted by design in current WiFi. Not by accident, not by an implementation bug you can patch on your own router. Fixing that is a standards-body decision, and 802.11bf is where it gets made or missed.