Ordinary Wi-Fi Routers Identified People With 99.5% Accuracy. Is 6G Next?

Ordinary Wi-Fi Routers Identified People With 99.5% Accuracy. Is 6G Next?

Wi-Fi router emitting radio waves toward a walking man, with a blue wireframe body scan and gait analysis overlay
Share This:

A German research team has shown that a passive listener sitting within range of an ordinary Wi-Fi network can recognize individual people walking through that network’s signal field, without a camera, without the target carrying a phone, and without ever joining the network.

The finding is real, it is peer-reviewed, and it was presented at one of the most competitive security conferences in the field. It is also narrower than the headlines that have carried it for the past ten months, and the gap between the two is worth understanding, because the details are what determine whether this is a laboratory result or an operational surveillance capability.

The more consequential question is not what the attack can do to your router. It is what it implies about the wireless standards being written right now  because the industry is currently designing the next generation of cellular networks to sense the physical world on purpose.

Background

The paper is titled “BFId: Identity Inference Attacks Utilizing Beamforming Feedback Information.” Its authors are Julian Todt, Felix Morsbach and Professor Thorsten Strufe of the KASTEL Security Research Labs at the Karlsruhe Institute of Technology. It was presented at the 32nd ACM Conference on Computer and Communications Security in Taipei in October 2025 and published in the conference proceedings the following month.

The work is not new. KIT issued its press release on October 13, 2025. The story then recirculated through aggregators and general-interest outlets across May and August 2026, which is why it may be reaching readers now as though it broke this month.

The underlying mechanism has been understood for years. Radio waves reflect, scatter and get absorbed as they move through a room. A human body in the signal path changes them in measurable ways. Researchers have used those distortions to count people, detect falls, estimate breathing rates and recognize gestures.

What the KIT team did was change the input. Most prior work in this area used channel state information, or CSI, a low-level measurement buried in the Wi-Fi physical layer. CSI is powerful but hard to reach: extracting it requires modified firmware that exists for only a handful of network cards, several of them well over a decade old. That practical barrier has functioned as an accidental privacy protection.

Beamforming feedback information, or BFI, does not have that barrier. In simple terms: when your laptop or phone connects to a modern router, it periodically tells the router how the radio channel between them looks so the router can aim its transmissions more precisely. That report is broadcast over the air unencrypted. Any Wi-Fi adapter set to monitor mode can read it.

That is the vulnerability. The attacker does not need the network password. The attacker does not need to be on the network at all.

What the Researchers Built and Measured

The team recruited 197 volunteers from a student panel and recorded them walking through a controlled Wi-Fi field in November 2024. Participants were paid €15, walked in five styles  normal, with a backpack, carrying a bottle crate, through a turnstile, and quickly  and were recorded from four antenna positions simultaneously, capturing BFI and CSI at the same time.

The setup used two consumer TP-Link Archer BE800 routers on 6 GHz channels with 160 MHz of bandwidth, and Intel AX210 network cards at each listening position.

The headline result: a standard LSTM neural network, with no signal pre-processing and no domain expertise assumed, identified individuals from BFI at 99.5% accuracy, plus or minus 0.38. The same model on CSI data from the same participants reached 82.4%.

That comparison surprised the authors. They had hypothesized CSI would win, since BFI is a compressed, lower-resolution derivative of it. It lost. Their explanation is that the compression acts as a form of noise filtering, and that BFI’s higher feature count  740 values per time step versus 212 for CSI  may capture more spatial detail.

Four qualifications that the coverage has largely dropped:

The 197 figure and the 99.5% figure describe different populations. The study recruited 197 people. Equipment failures meant not all recordings were usable. The paper states plainly that the working sets were 170 participants for CSI and 161 for BFI. The 99.5% accuracy was measured on 161 people, not 197. Both numbers appear in the paper’s own data table; the press release led with 197 and nearly every downstream story followed.

The system re-identifies, it does not identify. The model uses a softmax classifier, which means it assigns every input to one of the identities it was trained on. The authors state directly that because of this design they cannot test how the model generalizes to individuals outside the training data. In practice, this recognizes someone the operator has already recorded and labeled. It cannot pick a stranger out of a crowd.

Change the antenna position and it collapses. When the researchers trained on one recording perspective and tested on another, accuracy fell below 5% in most pairings. The identifying signature is not a portable fingerprint of a person. It is a fingerprint of that person in that geometry, relative to that router and that listening position.

The conditions were controlled to favor the result. Participants were instructed not to wear baggy clothing, skirts, dresses or heeled shoes, so their gait would register cleanly. The average participant was 23.2 years old. Network traffic was artificially saturated at 200 Mb/s to trigger channel-sounding as often as possible. The authors acknowledge all of this and say it may overstate real-world performance, while noting the constraints cut the other way too, since uniform clothing makes people harder to tell apart.

To the team’s credit, they ran a control that much of this literature skips. They fed their trained model 45-second recordings of the empty room taken between participants. If the model were latching onto session artifacts rather than human gait, it would have matched those empty recordings to whoever walked through immediately before or after. Top-two accuracy was 2.34%. The model was reading bodies, not sessions.

Why the Researchers Framed It as an Attack

The most consequential part of the paper is not the accuracy number. It is a definitional argument.

A long list of prior Wi-Fi-sensing papers described their own identification systems as privacy-preserving, on the theory that a system with no camera cannot violate privacy. The KIT authors reject that framing outright, writing that “we explicitly consider identity inference via WiFi sensing a privacy attack.”

Their threat model does not require linking a signal signature to a legal name. It requires only linking two recordings of the same body across time  once in a situation the operator can label, once in a situation the person believed was unobserved. The paper’s worked example involves a state recording people passing a café on the way to a protest, using their phones’ MAC addresses as labels on ordinary days, then recognizing them later on days they deliberately left their phones at home.

That last detail matters, because leaving the phone behind is standard advice from civil-liberties organizations. This technique is specifically designed to defeat it.

Todt put the ambient risk more plainly in the university’s release: “This technology turns every router into a potential means for surveillance.”

The Standards Timing Problem

The KIT release urged the IEEE to build privacy protections into the “forthcoming” 802.11bf Wi-Fi sensing standard.

IEEE Std 802.11bf-2025 was published on September 26, 2025, seventeen days before that release went out.

The amendment formalizes Wi-Fi sensing across the 2.4, 5 and 6 GHz bands, giving vendors a common specification for presence detection, fall detection and similar features. Those are legitimate applications with real value, particularly in elder care. But standardization also means sensing capability arrives in consumer hardware by default rather than as a research curiosity, and the window for the design-stage privacy debate the KIT team was calling for had already closed when they called for it.

Does This Work on 5G?

The obvious next question is whether the same technique reaches the cellular network, where the coverage footprint is vastly larger and the operator is a licensed, regulated entity.

The structural analogue exists. A 5G handset sends channel state reports back to the base station  channel quality indicator, precoding matrix indicator, rank indicator, beam indices  as Uplink Control Information on the physical uplink control channel. The concept is the same as Wi-Fi beamforming feedback: the device tells the network what the radio path looks like so the network can aim more precisely.

Those reports are not encrypted either. Ciphering in 5G is applied at the packet data convergence protocol layer and covers signaling and user traffic; physical-layer control information sits beneath it. Researchers examining unprotected low-layer control procedures in 4G and 5G have found that these channel state reports can be used by a passive attacker to track a user’s movement within a cell.

Three things make cellular a much harder target than Wi-Fi, at least today.

The control information is scrambled using an identifier the network assigns to each device during the initial access exchange, so an eavesdropper has to capture that exchange and then follow the scheduling to decode anything. That requires a software-defined radio and sustained effort, rather than a consumer Wi-Fi adapter switched into monitor mode.

The geometry is unfavorable. The Wi-Fi attack works partly because a person walking through a room dominates the signal paths between two devices a few meters apart. A macro cell spans hundreds of meters, and a single body is a much smaller perturbation in that channel. Millimeter-wave small cells would be the place to look, not conventional wide-area coverage.

And cellular runs in licensed spectrum, which puts interception on different legal footing in the United States than unlicensed Wi-Fi.

The published cellular work covers movement tracking, localization and application fingerprinting. NexfinityNews found no published equivalent of the KIT attack  gait-based identification of individuals  using 5G signals. That may mean the geometry genuinely does not support it. It may also mean no one has tried.

6G Is Being Designed to Do This on Purpose

That is where the framing shifts, and where the KIT paper’s significance grows rather than shrinks.

The International Telecommunication Union has named integrated sensing and communication, generally abbreviated ISAC, as one of the defining usage scenarios for the generation of networks it calls IMT-2030  in plain terms, 6G. The premise is that the same radio infrastructure carrying your data should also perceive the physical environment around it.

Standardization is already underway. 3GPP completed the Release 19 study work on ISAC channel modeling in May 2025, cataloguing dozens of candidate sensing use cases. Release 20 splits into two tracks: normative work on base-station sensing within 5G-Advanced, currently scoped to detecting uncrewed aircraft, running in parallel with 6G study items on broader sensing architectures. The first normative 6G specifications, expected in Release 21, are anticipated to include ISAC.

The industry literature describes the goal as device-free sensing: detecting and tracking objects and people that carry no radio transmitter at all. That is the stated feature, not an unintended side effect. The network becomes, in the words of one recent review, a perceptive system rather than a transport system.

This changes the threat model completely. BFId describes an attacker exploiting a leak. ISAC describes a licensed carrier sensing deliberately, with the core network processing the results and exposing them to third-party applications as a commercial service.

To the standards bodies’ credit, the privacy work here is further along than it was for 802.11bf. ETSI published a technical report in February 2026 identifying nineteen key issues for 6G sensing, fifteen of them security and privacy, including consent and transparency for sensing people who are not network subscribers, and protection against unauthorized parties using the network’s own sensing optimizations. 3GPP’s requirements study raises encryption, integrity protection, GDPR compliance and authorization.

The criticism in the academic literature is that these documents treat European data protection law and the EU AI Act as policy gaps to be acknowledged rather than engineering requirements to be built. One 2026 paper on ISAC governance frames the core problem directly: unlike a wearable sensor or a camera, the subject of radio sensing is passive and typically non-consenting. A person walking through a monitored radio field never opts in, yet their spatial and physiological state is continuously inferred.

Here is why the KIT result matters for that debate. ISAC is being justified on detection and counting  is someone present, did they fall, how many people are in this space  and identification is treated as a downstream risk to be managed later. BFId is evidence that the physics already supports identification at high accuracy from a compressed, low-rate byproduct of beamforming, using a simple model and no specialist knowledge. A system engineered from the ground up for sensing, with dedicated waveforms and licensed spectrum, is unlikely to do worse.

The U.S. Legal Position

American biometric privacy law was not written for this.

Illinois has the strongest statute in the country. The Biometric Information Privacy Act creates a private right of action with statutory damages of $1,000 for negligent violations and $5,000 for intentional or reckless ones, and it has generated verdicts including a $228 million judgment against BNSF Railway in 2023.

But BIPA defines “biometric identifier” as a closed list of four things: a retina or iris scan, a fingerprint, a voiceprint, and a scan of hand or face geometry. Gait is not among them. Neither is a radio-frequency signature derived from how a body distorts a wireless channel. On the statute’s plain text, a BFI-based gait classifier appears to fall outside the law entirely  and no court has ruled on the question, because no such case has been brought.

Texas and Washington have biometric statutes with similar enumerated structures. Roughly twenty additional states fold biometrics into general consumer privacy laws as a sensitive-data category. There is no federal biometric privacy statute.

The result is a technology that identifies people by body mechanics, sitting outside a legal framework built around eyes, fingers, hands, faces and voices.

The gap widens as the capability moves from Wi-Fi to cellular. European deployments of 6G sensing will land inside the General Data Protection Regulation, which treats biometric data used for identification as a special category and does not depend on an enumerated list of body parts. American deployments will land in a regime where gait is not a protected identifier in any state statute, and where the ISAC architecture explicitly contemplates selling sensing results to third parties through the carrier’s core network.

Analysis

Two readings of this study are both defensible, and they lead to different places.

The narrow reading: this is a controlled laboratory demonstration with a closed identity set, a fixed antenna geometry, dress-code restrictions, artificially saturated network traffic and a population of 161 young adults. Move the listening device and performance collapses. It is a proof of concept, not a deployed capability.

The broad reading: every constraint above is an engineering problem, and engineering problems get solved. The barrier that kept CSI-based sensing academic  specialized hardware and custom firmware  does not exist for BFI. One prior study cited in the paper found that while under 6% of deployed Wi-Fi devices supported CSI extraction, more than half already supported BFI as of 2023, and that share grows with every hardware refresh. Meanwhile, the identity set is only closed because the researchers chose a closed-set classifier for comparability with prior work, not because open-set matching is impossible.

The honest position is that the narrow reading is correct today and the broad reading describes the trajectory.

What makes the finding hard to dismiss is the mitigation picture. The researchers tested the obvious defense  reducing how often routers request beamforming feedback  and found identification stayed robust even at sharply reduced sample rates. Adding noise to the signal degrades network performance. Encrypting beamforming reports would require amending the Wi-Fi standard and would break compatibility with existing devices. The paper’s conclusion is that no straightforward mitigation currently exists, which is an unusual thing for a security paper to concede.

There is a third reading, and it may be the most useful one. Treat BFId less as a finding about routers and more as a physics result about what radio feedback contains. Read that way, the relevant deadline is not whether someone patches Wi-Fi. It is whether the 6G specifications now being drafted treat identification as a capability requiring authorization and consent, or as a risk to be noted in an annex.

Conclusion

The claim that a Wi-Fi router can function as a camera is a metaphor from a press release, not a description of what the system does. It does not produce images. It classifies gait signatures against a reference set the operator built in advance.

That is a meaningfully smaller claim. It is also, for anyone thinking about surveillance infrastructure, still a significant one  because the recording is passive, the hardware is already installed nearly everywhere, no consent is obtainable, no indicator light exists, and in the United States no statute clearly applies.

And the Wi-Fi case may prove to be the smaller half of the story. For 802.11bf the argument was already over before it started, because the standard published before the researchers finished raising the alarm. For 6G it has not started yet. Release 21 has not been written. That is a genuinely open window, and it is the only one currently open.

Key Takeaways

·       KIT researchers identified individuals from unencrypted Wi-Fi beamforming feedback at 99.5% accuracy, using no specialized hardware and without joining the network.

·       The study recruited 197 people, but the 99.5% figure was measured on the 161 whose recordings were usable for BFI. Press coverage has generally merged the two numbers.

·       The system re-identifies people already in its training set. It cannot identify strangers, and the authors state they did not test generalization to unseen individuals.

·       Accuracy falls below 5% when the listening antenna moves, meaning the signature is tied to a specific recording geometry rather than to the person.

·       Conditions were controlled: restricted clothing, a student cohort averaging 23 years old, and artificially saturated network traffic.

·       IEEE Std 802.11bf-2025, which standardizes Wi-Fi sensing, was published on September 26, 2025, before the researchers’ public call for privacy safeguards in it.

·       Illinois BIPA’s four enumerated biometric identifiers do not include gait, leaving this class of identification outside the strongest U.S. biometric statute.

·       The researchers found no workable mitigation. Reducing feedback frequency barely degrades the attack, and encrypting the reports would require changing the Wi-Fi standard.

·       5G carries a structurally similar unencrypted feedback report, and researchers have used it to track movement within a cell, but no published work has demonstrated gait identification over 5G.

·       6G is a different case. The ITU has named integrated sensing and communication a defining usage scenario for IMT-2030, and 3GPP is drafting sensing into the standard as a deliberate feature that detects people carrying no device at all.

·       The privacy work for 6G sensing is further along than it was for Wi-Fi. ETSI’s February 2026 report lists nineteen key issues, fifteen of them security and privacy. Critics argue the standards treat data-protection law as policy commentary rather than engineering requirements.

Share This: