Physical Noninvasive Attacks on Photoplethysmogram by Computer Controlled Blood Pressure Cuff

Sensors (Basel). 2023 Dec 11;23(24):9764. doi: 10.3390/s23249764.

Abstract

Sensor data has been used in social security and welfare infrastructures such as insurance and medical care to provide personalized products and services; there is a risk that attackers can alter sensor data to obtain unfair benefits. We consider that one of the attack methods to modify sensor data is to attack the wearer's body to modify biometric information. In this study, we propose a noninvasive attack method to modify the sensor value of a photoplethysmogram. The proposed method can disappear pulse wave peaks by pressurizing the upper arm with air pressure to control blood volume. Seven subjects experiencing a rest environment and five subjects experiencing an after-exercise environment wore five different models of smartwatches, and three pressure patterns were performed. It was confirmed in both situations that the displayed heart rate decreased from the true heart rate.

Keywords: attack; control; heart rate; manipulation; peak disappearance; pulse wave; smartwatch; upper arm pressure; wearable.

MeSH terms

  • Blood Pressure / physiology
  • Blood Pressure Determination* / methods
  • Computers
  • Heart Rate / physiology
  • Humans
  • Photoplethysmography* / methods