Is WiFi watching you?

18 July, 2026

Imagine this.

You’re inside your home, a WiFi operating in your home or close by. Outside your home, someone is using electronic equipment they’ve easily purchased to tell what you’re doing and record it. No cameras needed.

No, it’s not science fiction. It can be done – possibly is being done – right now and researchers from Germany have shown how as well as expressing concerns about what this means for our privacy.

The team, from the Karlsruhe Institute of Technology (KIT), showed that the signals transferring between WiFi devices can be used to identify people. They made recordings of 197 volunteers as they walked through a WiFi field and were able to identify the participants, based on their body profile and movement patterns, with up to 99.5% accuracy. They were even able to identify people using different walking styles, such as carrying a backpack or crate or walking quickly.

How is this possible?

The system works by exploiting the communication of legitimate users of the WLAN, whose devices are connected to the WiFi network. These regularly send feedback signals within the network, also called beamforming feedback information (BFI), to the router – in unencrypted form so that it is readable by anybody in range. This gives information from different perspectives that can serve to identify individuals.  

The KIT study showed that this beamforming information used by newer WiFi technologies was even more effective for surveillance than the Channel State Information (CSI), a different representation of WiFi channels, that has been previously used to identify people.

Professor Thorsten Strufe, from KASTEL, KIT’s Institute of Information Security and Dependability and coauthor of the study, explains more. ‘By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present. This works similar to a normal camera, the difference being that in our case, radio waves instead of light waves are used for the recognition.’

The authors were concerned about how this technology could affect people’s privacy and wanted to let the public know. ‘While there may be legitimate use-cases, we explicitly consider identity inference via WiFi sensing a privacy attack. This view reflects the serious risks associated with the ubiquity of WiFi networks, their ability to sense through walls and in non-line-of-sight scenarios, and the fact that this would likely happen without explicit consent,’ they wrote.

They also expressed concern about the ability of malicious agents to use this technology in a way that could be harmful to people. Their paper says, ‘This makes this threat especially problematic in low-regulation and high-surveillance contexts, such as authoritarian regimes, as government actors may use this technique to track dissidents or suppress protests.’

Further, the authors point out that there are two advantages of using WiFi surveillance over using cameras. The first is that WiFi networks are virtually ubiquitous, whereas cameras are not. The second is that people don’t know they’re being observed.

‘WiFi sensing allows an adversary to employ surveillance without raising suspicion, effectively creating an “inverse panopticon”, where individuals behave as though they are unobserved, while being silently tracked. Thus, an adversary might choose WiFi-based attacks to give individuals a false sense of security. In the protester example, individuals might purposely avoid an area with video cameras, but will ignore seemingly harmless WiFi APs.’

Previous research has shown that WiFi sensing can be used to recognise gestures, objects, location, tracking, respiratory rate and numbers of people.

The authors point out that there are no mitigation strategies available at present. ‘Without possible mitigation strategies, with standardization of WiFi sensing in work and the integration of similar joint-communication-and-sensing (JCAS) approaches planned for 6G and beyond, we feel it necessary to communicate the associated privacy threats to the public,’ they say. ‘Particularly, the planned standardization of WiFi sensing in 802.11bf [a WiFi standard] should strongly consider adding effective privacy protection, or abandon beamforming entirely.’

Todt, Julian & Morsbach, Felix & Strufe, Thorsten. (2025). BFId: Identity Inference Attacks Utilizing Beamforming Feedback Information. 2399-2413. 10.1145/3719027.3765062, https://publikationen.bibliothek.kit.edu/1000185756