{"id":"3258bc7f-ce28-4e8d-bf47-bcddd6288794","arxiv_id":"2506.08866","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A Wear OS smartwatch running an FFT-based decoder can receive covert 18-22 kHz B-FSK transmissions from nearby computers at short range, but the paper's reported SNR/BER tables contain internal inconsistencies and omit the watch model and sampling rate.","lead":"This paper tests whether a smartwatch's microphone can secretly receive data sent as inaudible 18-22 kHz sound from an infected computer, and reports bit-error rates and signal quality across distances of 1-9 meters and different speaker types. The result matters because smartwatches are worn into high-security, air-gapped rooms, giving an attacker a receiver that looks like an ordinary watch.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Quantitative support is inconsistent and the hardware precondition is undisclosed: the BER/SNR tables contradict the paper's own model, so the >6 m / 50 bps claim is not established without hardware disclosure and consistent measurements.","rationale":"Reading the paper in good faith, the attack idea is plausible and prior art supports near-ultrasonic reception by consumer microphones; the spectrograms and short-range decoding narrative provide a qualitative existence argument. The reader's hardware concern is genuine: Section IV.C never names the watch or sampling rate, and Algorithm 1's 'set sampling rate' is a non-answer. That concern alone would be enough to make the quantitative claim conditional. However, I see a second, sharper problem that is visible directly in the tables and does not depend on outside hardware knowledge. The paper states BER(d) = Q(sqrt(SNR(d))) in Section V.C, yet Table IV contains pairs like SNR=10 dB/BER=0% at 8 m and SNR=8 dB/BER=100% at 9 m, and SNR=23 dB/BER=100% at 8 m alongside SNR=35 dB/BER=0% at 9 m for the same 50 bps modulation. Table VI shows SNR=28 dB with BER=12.5% at 6 m. These are not measurement noise; they violate the monotonic relationship the paper itself relies on, so the tables cannot all be trusted as genuine measurements of a single system. Since Section VII's 'over 6 m / 50 bps' claim is justified only by these tables, the central quantitative claim is not currently supported. This does not make the paper hopeless: the qualitative idea remains plausible, and the concern is testable. I would keep the reader's CONDITIONAL verdict and require hardware disclosure plus re-measured, internally consistent BER/SNR tables before the quantitative claims are accepted.","tokens_in":13638,"tokens_out":4719,"duration_ms":52227,"concrete_test":"Ask the authors to disclose the exact watch model, microphone part, and the sample rate configured in Algorithm 1, then repeat the full active-, passive-, and laptop-speaker experiments at 44.1 kHz with end-to-end decoded BER (not just SNR) reported for every distance, including 9 m. An independent check with a known 18.5/19.5 kHz tone recorded by the same watch and inspected with an FFT will settle whether the ultrasonic band is captured at all; if the tones are absent or attenuated by more than 20 dB, the hardware precondition fails. Separately, recompute the expected BER from each reported SNR using BER = Q(sqrt(SNR)) and require the measured BERs to be monotonically consistent with distance; the Table IV/VI pairs that violate this condition must be re-measured or flagged as invalid.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central quantitative claim (Section VII, 'distances exceeding 6 meters, data rates up to 50 bps') is load-bearing on two unverified conditions. First, the receiver is described only as 'a Wear OS smartwatch' (Section IV.C), and Algorithm 1 says 'set sampling rate' without giving a value; if the watch's codec samples below 44.1 kHz or the microphone's anti-alias filter rolls off at 18-22 kHz, the B-FSK tones are aliased or attenuated and no decoding is possible at any claimed distance. This is explicitly a missing support in the manuscript, not an external assumption. Second, the evaluation tables contradict the paper's own BER = Q(sqrt(SNR(d))) relation: Table IV passive 5 bps shows BER 0% at 8 m with SNR 10 dB but BER 100% at 9 m with SNR 8 dB; 50 bps shows BER 100% at 8 m with SNR 23 dB but BER 0% at 9 m with SNR 35 dB; Table VI laptop 50 bps reports BER 12.5% at 6 m with SNR 28 dB, which is inconsistent with any Q-function mapping. These cannot all be genuine measurements of one system, so the distance/rate envelope in the conclusion is not supported by the data as reported.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents SmartAttack, a proposed ultrasonic covert channel in which a compromised computer modulates data with B-FSK at 18.5/19.5 kHz and transmits it through its speakers, while a Wear OS smartwatch worn on the wrist acts as the receiver, capturing the signal through its built-in microphone and decoding it with an FFT-based pipeline. The authors report experiments across three transmitter types (active speaker, passive speaker, laptop), eight wrist orientations, varying distances up to 9 m, and bit rates of 5, 20, and 50 bps, and conclude that the attack can transmit data over distances exceeding 6 m at rates up to 50 bps. The paper also discusses smartwatch-specific factors such as wrist movement, body attenuation, directional microphone response, and mitigation strategies.","tokens_in":1622,"tokens_out":1716,"duration_ms":61834,"significance":"If the central feasibility claim is correct, the paper identifies a plausible and under-explored attack vector: a smartwatch, which may be worn continuously in a sensitive facility, can serve as a covert receiver for ultrasonic exfiltration from an air-gapped computer. The paper contributes a clear attack model, a pseudocode decoder, qualitative orientation and attenuation analyses, and a comparison across transmitter types. However, the empirical support is currently not trustworthy: the receiver hardware is never identified, and the SNR/BER tables are internally inconsistent with the paper's own channel model. Because the conclusion depends on these measurements, the result is not yet established. The work is sufficiently important that the evaluation should be fixed and re-reviewed rather than dismissed.","major_comments":[{"comment":"The receiver hardware is not disclosed: the watch is described only as a Wear OS smartwatch, Algorithm 1 says Initialize microphone and set sampling rate without giving a value, and no microphone part number, model name, or recording API configuration is provided. Since the claimed channel is 18-22 kHz, the microphone's frequency response, anti-alias filter, and ADC sampling rate determine whether those tones are captured at all. If the sampling rate is below 44.1 kHz, or if the analog path rolls off before 18 kHz, the spectrograms in Figures 3, 4, and 7 could reflect aliased or attenuated energy rather than genuine ultrasonic reception. The paper must name the watch model, sampling rate, and recording settings, and ideally include a frequency-response measurement, before the feasibility claim can be evaluated.","section":"Section IV.C and V"},{"comment":"The passive-speaker BER/SNR values contradict the model BER(d) = Q(sqrt(SNR(d))) stated in the same section. For 5 bps, the table reports 0% BER at 8 m with SNR 10 dB but 100% BER at 9 m with SNR 8 dB; for 50 bps, it reports 100% BER at 8 m with SNR 23 dB but 0% BER at 9 m with SNR 35 dB. These entries cannot all come from one monotone system with the stated Q-function relationship. The inconsistency is load-bearing because Table IV is the primary quantitative support for the claim of distances exceeding 6 meters in Section VII. The authors need to reproduce or correct these measurements and ensure that SNR and BER are coherent with the stated model.","section":"Section V.C, Table IV"},{"comment":"The laptop-speaker 50 bps rows are self-contradictory: the table reports 12.5% BER at 6 m (SNR 28 dB), 0% at 7 m (SNR 22 dB), 100% at 8 m (SNR 30 dB), and 0% at 9 m (SNR 25 dB). The accompanying text says BER increasing to 12.5% at 6 meters and reaching 100% at 8 meters, indicating a complete loss of data integrity, which the table itself contradicts at 9 m. This undermines the conclusion that data rates of up to 50 bps are achievable, and the data set must be reconciled or removed.","section":"Section V.D, Table VI"},{"comment":"The evaluation reports no experimental protocol: the number of transmitted messages per configuration, the method for computing BER (per bit or per packet), the duration of each trial, the environmental conditions, and the criterion for success are all unspecified. Without such details, the tables cannot be independently checked, and the concluding claim of distances exceeding 6 meters at data rates up to 50 bps is not reproducible. The authors should add a standard experimental methodology subsection describing trial counts, confidence measures, and the definition of a successful decoded message.","section":"Section V and VII"}],"minor_comments":[{"comment":"The paragraph beginning To efficiently decode ultrasonic transmissions, the smartwatch employs an optimized signal processing pipeline is duplicated verbatim; one copy should be removed.","section":"Section IV.D"},{"comment":"The 20 bps row at 9 m reports SNR as ?; this missing value should be measured or the entry should explicitly state not available with an explanation.","section":"Table IV"},{"comment":"The SNR values in these tables are presented without units in the table headers; the headers should include (dB) to match the text.","section":"Tables V and VII"},{"comment":"The numerical example (initial power 60 dB, attenuation coefficient 5 dB/m) appears to be an illustrative calculation rather than a measured result; the text should clarify that these numbers are an example, not experimental data.","section":"Section V.F"},{"comment":"The text in Section V.E refers to Figure 5 and Figure 6, but the figures are not present in the supplied manuscript; please ensure they are included in the final submission.","section":"Figures 5 and 6"},{"comment":"The expression d_max approximately equals (P_t/P_min)^(1/beta) is dimensionally unclear; the text should define whether P_t and P_min are power ratios or dB values, or explain that this is a heuristic relationship.","section":"Section IV.B"}],"recommendation":"major_revision","confidential_remarks":"This is a single-author paper in a well-established line of air-gap covert-channel research, and the manuscript builds heavily on the author's prior work. The heavy self-citation is not by itself a problem because the central feasibility claim is empirical. The main obstacle is the quality of the evaluation: the hardware must be disclosed and the SNR/BER inconsistencies must be resolved. If the authors can provide consistent measurements and a reproducible protocol, the paper could be acceptable; in its current form it is not."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Mordechai Guri's SmartAttack is the first paper I know of that puts a smartwatch on the receiving end of an ultrasonic covert channel. Table I confirms that the Workstation/Laptop-to-Smartwatch cell was empty before this. That is a real increment: a wrist-worn receiver is operationally more plausible than a phone in an air-gapped office, and the orientation and body-occlusion measurements are genuinely new. The qualitative evidence—the spectrograms in Figures 3, 4, and 7—shows that the watch does pick up the 18.5/19.5 kHz B-FSK tones at close range. The basic physics is textbook: passive speakers, laptop speakers, a bandpass filter, FFT peak detection. I believe the channel exists.\n\nWhat I do not believe is the quantitative envelope. The SNR tables are not monotonic in distance and repeatedly contradict the paper's own BER = Q(sqrt(SNR)) relation. Table IV shows 100% BER at 9 m with 8 dB SNR but 0% BER at 8 m with 10 dB SNR for 5 bps, and the 50 bps column has 100% BER at 8 m with 23 dB but 0% at 9 m with 35 dB. Table VI has a similar inversion. These cannot all be genuine measurements of one system. The conclusion's headline claim—\"distances exceeding 6 meters, data rates up to 50 bps\"—is not supported by the data as reported.\n\nThe bigger problem is that the receiver is never specified. The paper says only \"a Wear OS smartwatch\" and Algorithm 1 says \"set sampling rate\" without giving a value. If the audio pipeline samples below 44.1 kHz or the microphone rolls off before 18 kHz, the tones alias or vanish and the whole feasibility result collapses. This is a missing precondition, not a quibble. The stress-test note is right about both the hardware gap and the table inconsistencies; I checked the tables myself and they are as bad as stated.\n\nWhere the paper is still salvageable: the self-citation density in Section II is high but does not load-bear on the empirical claim, and the theoretical model (path loss, Q-function) is standard. The orientation analysis is internally contradictory—it says strongest reception at 180–225 degrees in one paragraph and then recommends 90 degrees in the next—but that is a presentation error, not a fatal flaw.\n\nThis deserves a serious referee, but only with the understanding that the quantitative claims need to be re-measured with full hardware disclosure, error bars, and a corrected conclusion. The idea is credible and novel; the evidence presentation is not. I would not cite the specific numbers until they are fixed, but I would cite the existence of the smartwatch receiver vector.","headline":"Plausible new receiver vector for ultrasonic air-gap exfiltration, but the quantitative evaluation is internally inconsistent and the watch hardware is undisclosed; the qualitative core is credible, the numbers are not.","tokens_in":14476,"tokens_out":942,"would_cite":true,"duration_ms":12452,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A smartwatch on the wrist can receive covert data from an air-gapped computer.","keywords":["smartwatch","air-gap attack","ultrasonic covert channel","data exfiltration","acoustic communication","wearable security","B-FSK modulation","Wear OS"],"falsifier":"Take a common Wear OS smartwatch, measure its microphone frequency response with a calibrated ultrasonic source at 18.5 and 19.5 kHz, and attempt the SmartAttack decode; if sensitivity at those frequencies is below the measured noise floor or the ADC aliases the tones into the audible band, the claimed distances and bit rates cannot be reproduced.","tokens_in":13243,"feed_emoji":"⌚","tokens_out":4692,"duration_ms":50485,"temperature":0.7,"pith_summary":"This paper tries to establish that a smartwatch worn on the wrist can act as a covert receiver for ultrasonic data exfiltration from an air-gapped computer. The proposed attack, SmartAttack, uses a compromised computer's speakers to emit binary frequency-shift keyed tones at 18.5 and 19.5 kHz, which are captured by the smartwatch's built-in microphone and decoded into a bitstream. The reported experiments show successful delivery over distances beyond 6 meters at rates up to 50 bits per second, with lower rates working at longer range. The point of caring is that air-gapped networks are supposed to be sealed, but a device people wear every day can bridge that seal without being noticed.","feed_headline":"A smartwatch on the wrist can pick up covert data at 50 bits per second","feed_subtitle":"Air-gapped computers leak secrets through inaudible 18.5 and 19.5 kHz tones decoded by a nearby wearable.","key_machinery":"The machinery is binary frequency-shift keying (B-FSK) at 18.5/19.5 kHz combined with a real-time decoding pipeline on the watch: a Butterworth bandpass filter for the 18–22 kHz band, spectral subtraction, overlapping Hamming-windowed FFTs, peak-frequency classification, preamble-based frame synchronization, CRC check, and Kalman filtering to smooth Doppler shifts from wrist movement. On the channel side, path loss models SNR(d) ∝ $d^{{-γ}}$ and attenuation A(f,d)=A0 $e^{{-α(f)d}}$ describe how distance and body tissue degrade the signal, and the experiments map which orientations and frequency ranges keep the link usable. This pipeline is what carries the argument from raw microphone samples to recovered bits.","core_discovery":"SmartAttack is a three-stage exfiltration: malware on an air-gapped machine gathers data and modulates it with B-FSK onto two ultrasonic tones (18.5 kHz for binary 0, 19.5 kHz for binary 1); a Wear OS smartwatch compromised beforehand samples the room with its microphone, filters the 18–22 kHz band, runs an FFT and peak detector to classify each symbol, and uses the preamble and checksum to reassemble the payload; the watch then forwards the data over Wi-Fi, Bluetooth, or cellular. The paper's experiments report SNR and BER across active speakers, passive speakers, and laptop speakers at distances from 1 to 9 meters, and show that reception is orientation-dependent (strongest around 180–225 degrees, weakest at 0 and 270 degrees), that body occlusion adds 10–30+ dB of loss, that frequencies above 20 kHz degrade quickly, and that keyboard typing noise does not mask the ultrasonic band. The conclusion states that the attack successfully transmits data over distances exceeding 6 meters at up to 50 bits per second.","pith_inferences":["Because the paper never identifies the watch model or sample rate, the practical reach of SmartAttack is probably hardware-dependent; an obvious next step is to survey microphone frequency response across Wear OS and other smartwatch lines.","The same ultrasonic link could likely be reversed (smartwatch as transmitter to a compromised computer) or combined with another covert channel to relay data out of the room, though the paper does not test this.","If keyboard typing noise is spectrally separated from 18.5–19.5 kHz, then other human-generated sounds such as speech may also fail to jam the channel, making detection harder; this is an inference from the spectral-separation argument rather than a measured result."],"forward_implications":["An attacker can exfiltrate data from an air-gapped computer without needing a phone: a watch already on the user's wrist receives the signal.","Lower bit rates (5 bps) remain reliable over longer distances, so the channel favors small payloads like keystrokes or keys over bulk file transfer.","Frequencies above 20 kHz are largely wasted on smartwatch microphones; the usable covert band sits at 18–19.5 kHz.","Defenders can exploit orientation and body occlusion: certain wrist angles cut the signal by 10 dB or more, and banning or disabling wearable audio hardware removes the channel."],"supporting_citations":[{"why":"Establishes the feasibility of acoustic covert channels between air-gapped systems using ultrasonic frequencies, the foundation SmartAttack extends.","marker":"[5]"},{"why":"Demonstrates an ultrasonic covert channel from a workstation to a smartphone, the receiver-side baseline that smartwatches are compared against.","marker":"[16]"},{"why":"Shows speaker-to-speaker ultrasonic transmission, providing the transmitter-side modulation and propagation techniques reused here.","marker":"[20]"},{"why":"Highlights vulnerabilities of smart wearable devices, supporting the premise that smartwatches are a plausible attack vector.","marker":"[6]"},{"why":"Claims that high-sensitivity microphones can capture frequencies beyond human hearing, the hardware assumption behind using a smartwatch microphone for 18–22 kHz reception.","marker":"[30]"}],"fun_headline_variants":["Smartwatch mics turn air-gapped PCs into leaky speakers","Ultrasonic tones let a smartwatch steal data from air-gapped PCs","Wearables become covert listeners for air-gap exfiltration","SmartAttack: watch mic captures secret tones at 50 bps","Air-gap secrets leak via smartwatch at up to 50 bits per second"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The result assumes, without the paper stating it, that the smartwatch's microphone and audio digitizer truly capture the 18–22 kHz band; if the hardware samples below 44.1 kHz or rolls off before 18 kHz, the reported reception would not occur.","fun_headline_variants_meta":{"raw":{"variants":["Smartwatch mics turn air-gapped PCs into leaky speakers","Ultrasonic tones let a smartwatch steal data from air-gapped PCs","Wearables become covert listeners for air-gap exfiltration","SmartAttack: watch mic captures secret tones at 50 bps","Air-gap secrets leak via smartwatch at up to 50 bits per second"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000824,"raw_usage":{"total_tokens":3616,"prompt_tokens":972,"completion_tokens":2644,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":588,"completion_tokens_details":{"reasoning_tokens":2562}},"tokens_in":588,"tokens_out":2644,"duration_ms":18809,"temperature":1.0,"reasoning_tokens":2562,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T05:01:00.069682+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a common Wear OS smartwatch, measure its microphone frequency response with a calibrated ultrasonic source at 18.5 and 19.5 kHz, and attempt the SmartAttack decode; if sensitivity at those frequencies is below the measured noise floor or the ADC aliases the tones into the audible band, the claimed distances and bit rates cannot be reproduced.","supporting_citations":[{"cited_title":"On acoustic covert channels between air- gapped systems,","cited_arxiv_id":null,"evidence_quote":"Establishes the feasibility of acoustic covert channels between air-gapped systems using ultrasonic frequencies, the foundation SmartAttack extends."},{"cited_title":"Crossing the air gap—an ultrasonic covert channel,","cited_arxiv_id":null,"evidence_quote":"Demonstrates an ultrasonic covert channel from a workstation to a smartphone, the receiver-side baseline that smartwatches are compared against."},{"cited_title":"Mosquito: Covert ultrasonic trans- missions between two air-gapped computers using speaker-to-speaker communication,","cited_arxiv_id":null,"evidence_quote":"Shows speaker-to-speaker ultrasonic transmission, providing the transmitter-side modulation and propagation techniques reused here."},{"cited_title":"Vulner- ability analysis and exploitation attacks on smart wearable devices,","cited_arxiv_id":null,"evidence_quote":"Highlights vulnerabilities of smart wearable devices, supporting the premise that smartwatches are a plausible attack vector."},{"cited_title":"Microphone frequency range guide,","cited_arxiv_id":null,"evidence_quote":"Claims that high-sensitivity microphones can capture frequencies beyond human hearing, the hardware assumption behind using a smartwatch microphone for 18–22 kHz reception."}],"review_version":1}