{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T12:04:28Z","timestamp":1769515468625,"version":"3.49.0"},"reference-count":68,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"name":"NSF","award":["2112471"],"award-info":[{"award-number":["2112471"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>\n            Bluetooth Low Energy (BLE) is ubiquitous today. To prevent a BLE device (e.g., a smartphone) from being connected by unknown devices, it uses allowlisting to allow the connectivity from only recognized devices. Unfortunately, we show that this allowlist feature actually introduces a side channel for device tracking, since a device with the allowed list behaves differently even though it has used randomized MAC addresses. Even worse, we also find that the current MAC address randomization scheme specified in Bluetooth protocol is flawed, suffering from a replay attack with which an attacker can replay a sniffed MAC address to probe whether a targeted device will respond or not based on its allowlist. We have validated our allowlist-based side channel attacks with 43 BLE peripheral devices, 11 centrals, and 4 development boards, and found none of them once configured with allowlisting is immune to the proposed attacks. We advocate the use of an interval unpredictable, central and peripheral synchronized random MAC address randomization scheme to defeat passive device tracking (introducing 1% power consumption overhead for centrals and 6.75% for peripherals, and 88.49 \u03bcs performance overhead for centrals and 94.46 \u03bcs for peripherals), and the use of timestamps to derive randomized MAC addresses such that attackers can no longer be able to replay them to defeat active device tracking (introducing 3.04% overhead for peripherals, and 63.58 \u03bcs and 20.54 \u03bcs performance overhead for centrals and peripherals). Our field testing with a long range Bluetooth sniffer shows that 16,422 of 100,101 sniffed devices are subject to our\n            <jats:sans-serif>BAT<\/jats:sans-serif>\n            attacks. We have disclosed our findings to Bluetooth SIG and many other stakeholders in October 2020. Bluetooth SIG assigned CVE-2020-35473 to track this logical-level protocol flaw. Google assigned our findings as a high severity design flaw and awarded us with a bug bounty.\n          <\/jats:p>","DOI":"10.1145\/3744559","type":"journal-article","created":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T07:39:29Z","timestamp":1750837169000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Breaking BLE MAC Address Randomization with Allowlist-Based Side Channels and its Countermeasure"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7786-0231","authenticated-orcid":false,"given":"Yue","family":"Zhang","sequence":"first","affiliation":[{"name":"Department of Computer Science, The Ohio State University","place":["Columbus, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6527-5994","authenticated-orcid":false,"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering Dept, Ohio State University","place":["Columbus, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,9,27]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"176","volume-title":"Proceedings of the Cryptographers\u2019 Track at the RSA Conference","author":"Jakobsson Markus","year":"2001","unstructured":"Markus Jakobsson and Susanne Wetzel. 2001. Security weaknesses in Bluetooth. In Proceedings of the Cryptographers\u2019 Track at the RSA Conference. Springer, 176\u2013191."},{"key":"e_1_3_2_3_2","first-page":"1205","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security 16)","author":"Fawaz Kassem","year":"2016","unstructured":"Kassem Fawaz, Kyu-Han Kim, and Kang G. Shin. 2016. Protecting privacy of BLE device users. In Proceedings of the 25th USENIX Security Symposium (USENIX Security 16). 1205\u20131221."},{"issue":"3","key":"e_1_3_2_4_2","doi-asserted-by":"crossref","first-page":"50","DOI":"10.2478\/popets-2019-0036","article-title":"Tracking anonymized Bluetooth devices","volume":"2019","author":"Becker Johannes K.","year":"2019","unstructured":"Johannes K. Becker, David Li, and David Starobinski. 2019. Tracking anonymized Bluetooth devices. Proceedings on Privacy Enhancing Technologies (PETS) 2019, 3 (2019), 50\u201365.","journal-title":"Proceedings on Privacy Enhancing Technologies (PETS)"},{"key":"e_1_3_2_5_2","first-page":"444","volume-title":"Proceedings of the 16th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services","author":"Celosia Guillaume","year":"2019","unstructured":"Guillaume Celosia and Mathieu Cunche. 2019. Saving private addresses: An analysis of privacy issues in the Bluetooth-low-energy advertising mechanism. In Proceedings of the 16th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services. 444\u2013453."},{"key":"e_1_3_2_6_2","first-page":"43","volume-title":"Proceedings of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY)","author":"Korolova Aleksandra","year":"2018","unstructured":"Aleksandra Korolova and Vinod Sharma. 2018. Cross-app tracking via nearby Bluetooth low energy devices. In Proceedings of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY). 43\u201352."},{"key":"e_1_3_2_7_2","article-title":"Bluetooth core specification version 4.2","author":"Bluetooth SIG","year":"2014","unstructured":"SIG Bluetooth. 2014. Bluetooth core specification version 4.2. Specification of the Bluetooth System (2014).","journal-title":"Specification of the Bluetooth System"},{"key":"e_1_3_2_8_2","unstructured":"Apple Inc.2019. Accessory Design Guidelines for Apple Devices). Retrieved July 5 2025 from https:\/\/developer.apple.com\/accessories\/Accessory-Design-Guidelines.pdf. (2019)."},{"key":"e_1_3_2_9_2","unstructured":"SIG Bluetooth. 2024. Bluetooth Core Specification Version 6.0: Specification of the Bluetooth System (2024)."},{"key":"e_1_3_2_10_2","unstructured":"SIG Bluetooth. 2024. Bluetooth Core Specification Version 6.0: Specification of the Bluetooth System (2024)."},{"key":"e_1_3_2_11_2","unstructured":"Google. 2025. Android Open Source Project. Retrieved from https:\/\/source.android.com\/. ([n. d.])."},{"key":"e_1_3_2_12_2","unstructured":"SIG Bluetooth. 2024. Bluetooth Core Specification Version 6.0: Specification of the Bluetooth System (2024)."},{"key":"e_1_3_2_13_2","volume-title":"Ubicomp Poster Proceedings","volume":"2","author":"Haase Marc","year":"2004","unstructured":"Marc Haase, Matthias Handy, et\u00a0al. 2004. BlueTrack\u2013imperceptible tracking of Bluetooth devices. In Ubicomp Poster Proceedings, Vol. 2."},{"key":"e_1_3_2_14_2","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1109\/NEXTCOMP.2017.8016185","volume-title":"Proceedings of the 2017 1st International Conference on Next Generation Computing Applications (NextComp)","author":"Issoufaly Taher","year":"2017","unstructured":"Taher Issoufaly and Pierre Ugo Tournoux. 2017. BLEB: Bluetooth low energy botnet for large scale individual tracking. In Proceedings of the 2017 1st International Conference on Next Generation Computing Applications (NextComp). IEEE, 115\u2013120."},{"key":"e_1_3_2_15_2","unstructured":"Google. 2016. Android 6.0 Changes. Retrieved July 5 2025 from https:\/\/developer.android.com\/about\/versions\/marshmallow\/android-6.0-changes#behavior-hardware-id. (2016)."},{"issue":"4","key":"e_1_3_2_16_2","article-title":"Replay (far) away: Exploiting and fixing Google\/Apple exposure notification contact tracing","volume":"2022","author":"Ellis Christopher","year":"2022","unstructured":"Christopher Ellis, Haohuang Wen, Zhiqiang Lin, and Anish Arora. 2022. Replay (far) away: Exploiting and fixing Google\/Apple exposure notification contact tracing. Proceedings on Privacy Enhancing Technologies (PETS) 2022, 4 (2022), 727\u2013745.","journal-title":"Proceedings on Privacy Enhancing Technologies (PETS)"},{"key":"e_1_3_2_17_2","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/2939918.2939930","volume-title":"Proceedings of the 9th ACM Conference on Security & Privacy in Wireless and Mobile Networks","author":"Matte C\u00e9lestin","year":"2016","unstructured":"C\u00e9lestin Matte, Mathieu Cunche, Franck Rousseau, and Mathy Vanhoef. 2016. Defeating MAC address randomization through timing attacks. In Proceedings of the 9th ACM Conference on Security & Privacy in Wireless and Mobile Networks. 15\u201320."},{"key":"e_1_3_2_18_2","first-page":"1469","volume-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"Zuo Chaoshun","year":"2019","unstructured":"Chaoshun Zuo, Haohuang Wen, Zhiqiang Lin, and Yinqian Zhang. 2019. Automatic fingerprinting of vulnerable BLE IoT devices with static UUIDs from mobile apps. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. 1469\u20131483."},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS\u201919)","author":"Xu Fenghao","year":"2019","unstructured":"Fenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen, and Kehuan Zhang. 2019. BadBluetooth: Breaking android security mechanisms via malicious Bluetooth peripherals. In Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS\u201919)."},{"key":"e_1_3_2_20_2","volume-title":"Proceedings of the 21st Annual Network and Distributed System Security Symposium, NDSS 2014","author":"Naveed Muhammad","year":"2014","unstructured":"Muhammad Naveed, Xiao-yong Zhou, Soteris Demetriou, XiaoFeng Wang, and Carl A. Gunter. 2014. Inside job: Understanding and mitigating the threat of external device mis-binding on android. In Proceedings of the 21st Annual Network and Distributed System Security Symposium, NDSS 2014."},{"key":"e_1_3_2_21_2","unstructured":"Lily Hay Newman. 2020. Sneaky Zero-Click Attacks Are a Hidden Menace. Retrieved December 24 2021 from https:\/\/www.wired.com\/story\/sneaky-zero-click-attacks-hidden-menace\/. (April2020)."},{"key":"e_1_3_2_22_2","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P)","author":"Antonioli Daniele","year":"2020","unstructured":"Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. 2020. BIAS: Bluetooth impersonation attacks. In Proceedings of the IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_23_2","first-page":"1047","volume-title":"Proceedings of the 28th  \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security 19)","author":"Antonioli Daniele","year":"2019","unstructured":"Daniele Antonioli, Nils Ole Tippenhauer, and Kasper B. Rasmussen. 2019. The \\(\\lbrace\\) KNOB \\(\\rbrace\\) is broken: Exploiting low entropy in the encryption key negotiation of Bluetooth BR\/EDR. In Proceedings of the 28th \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security 19). 1047\u20131061."},{"key":"e_1_3_2_24_2","first-page":"37","volume-title":"Proceedings of the 29th  \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security 20)","author":"Zhang Yue","year":"2020","unstructured":"Yue Zhang, Jian Weng, Rajib Dey, Yier Jin, Zhiqiang Lin, and Xinwen Fu. 2020. Breaking secure pairing of Bluetooth low energy using downgrade attacks. In Proceedings of the 29th \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security 20). 37\u201354."},{"key":"e_1_3_2_25_2","volume-title":"Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP)","author":"Ludant Norbert","year":"2021","unstructured":"Norbert Ludant, Tien D. Vo-Huu, Sashank Narain, and Guevara Noubir. 2021. Linking Bluetooth LE & classic and implications for privacy-preserving Bluetooth-based protocols. In Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_26_2","doi-asserted-by":"crossref","first-page":"534","DOI":"10.1109\/SP40000.2020.00091","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP)","author":"Cominelli Marco","year":"2020","unstructured":"Marco Cominelli, Francesco Gringoli, Paul Patras, Margus Lind, and Guevara Noubir. 2020. Even black cats cannot stay hidden in the dark: Full-band de-anonymization of Bluetooth classic devices. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 534\u2013548."},{"key":"e_1_3_2_27_2","unstructured":"SENA. 2025. Patch Antenna - RP-SMA-R\/A Right-Hand Thread 9dBi. 636\u2013645. Retrieved February 2025 from http:\/\/www.senanetworks.com\/pat-g01r.html. (2025)."},{"issue":"2","key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"370","DOI":"10.1109\/JSAC.2005.861394","article-title":"Wormhole attacks in wireless networks","volume":"24","author":"Hu Yih-Chun","year":"2006","unstructured":"Yih-Chun Hu, Adrian Perrig, and David B. Johnson. 2006. Wormhole attacks in wireless networks. IEEE Journal on Selected Areas in Communications 24, 2 (2006), 370\u2013380.","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"e_1_3_2_29_2","first-page":"179","volume-title":"Concurrency: The Works of Leslie Lamport","author":"Lamport Leslie","year":"2019","unstructured":"Leslie Lamport. 2019. Time, clocks, and the ordering of events in a distributed system. In Concurrency: The Works of Leslie Lamport. Association for Computing Machinery (ACM). 179\u2013196."},{"key":"e_1_3_2_30_2","unstructured":"Statistics. 2020. Bluetooth device shipments worldwide from 2015 to 2026. Retrieved November 19 2014 from https:\/\/www.statista.com\/statistics\/1220933\/global-bluetooth-device-shipment-forecast\/. (April2020)."},{"key":"e_1_3_2_31_2","unstructured":"Adafruit. Adafruit Sniffer. Retrieved from https:\/\/learn.adafruit.com\/introducing-the-adafruit-bluefruit-le-sniffer\/introduction. ([n. d.])."},{"issue":"7","key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"1625","DOI":"10.1109\/TIFS.2017.2678463","article-title":"Revisiting urban war nibbling: Mobile passive discovery of classic Bluetooth devices using Ubertooth one","volume":"12","author":"Chernyshev Maxim","year":"2017","unstructured":"Maxim Chernyshev, Craig Valli, and Michael Johnstone. 2017. Revisiting urban war nibbling: Mobile passive discovery of classic Bluetooth devices using Ubertooth one. IEEE Transactions on Information Forensics and Security 12, 7 (2017), 1625\u20131636.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_2_33_2","unstructured":"Ganesh. 2020. The current PSoC EZ-Serial FW does not support RPA for whitelist. Retrieved July 5 2025 from https:\/\/community.cypress.com\/thread\/51728?start=0&tstart=0. (2020)."},{"key":"e_1_3_2_34_2","unstructured":"Silcon Labs. 2020. TWhitelisting (Silcon Labs Official Document). Retrieved July 5 2025 from https:\/\/docs.silabs.com\/bluetooth\/3.0\/general\/adv-and-scanning\/whitelisting. (2020)."},{"issue":"12","key":"e_1_3_2_35_2","doi-asserted-by":"crossref","first-page":"386","DOI":"10.3390\/electronics7120386","article-title":"Power consumption analysis of Bluetooth low energy commercial products and their implications for IoT applications","volume":"7","author":"Garcia-Espinosa Eduardo","year":"2018","unstructured":"Eduardo Garcia-Espinosa, Omar Longoria-Gandara, Ioseth Pegueros-Lepe, and Arturo Veloz-Guerrero. 2018. Power consumption analysis of Bluetooth low energy commercial products and their implications for IoT applications. Electronics 7, 12 (2018), 386.","journal-title":"Electronics"},{"key":"e_1_3_2_36_2","doi-asserted-by":"crossref","first-page":"1231","DOI":"10.1109\/MILCOM.2016.7795499","volume-title":"MILCOM 2016-Proceedings of the 2016 IEEE Military Communications Conference","author":"Uher Jason","year":"2016","unstructured":"Jason Uher, Ryan G. Mennecke, and Bassam S. Farroha. 2016. Denial of sleep attacks in Bluetooth low energy wireless sensor networks. In MILCOM 2016-Proceedings of the 2016 IEEE Military Communications Conference. IEEE, 1231\u20131236."},{"key":"e_1_3_2_37_2","first-page":"1","volume-title":"Proceedings of the 2007 3rd IEEE\/IFIP International Conference in Central Asia on Internet","author":"Hypponen Konstantin","year":"2007","unstructured":"Konstantin Hypponen and Keijo M. J. Haataja. 2007. \u201cNino\u201d man-in-the-middle attack on Bluetooth secure simple pairing. In Proceedings of the 2007 3rd IEEE\/IFIP International Conference in Central Asia on Internet. IEEE, 1\u20135."},{"key":"e_1_3_2_38_2","unstructured":"Josh Howarth. 2025. How Many People Own Smartphones? (2024-2029). Retrieved June 18 2025 from https:\/\/explodingtopics.com\/blog\/smartphone-stats. (2025)."},{"key":"e_1_3_2_39_2","first-page":"539","volume-title":"Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP)","author":"Li Xiao","year":"2025","unstructured":"Xiao Li, Yue Li, Hao Wu, Yue Zhang, Kaidi Xu, Xiuzhen Cheng, Sheng Zhong, and Fengyuan Xu. 2025. Make a feint to the east while attacking in the west: Blinding LLM-based code auditors with flashboom attacks. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 539\u2013557."},{"key":"e_1_3_2_40_2","volume-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"Wen Hanghuang","year":"2020","unstructured":"Hanghuang Wen, Zhiqiang Lin, and Yinqian Zhang. 2020. FirmXRay: Detecting Bluetooth link layer vulnerabilities from bare-metal firmware. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security."},{"issue":"1","key":"e_1_3_2_41_2","doi-asserted-by":"crossref","first-page":"26","DOI":"10.2478\/popets-2020-0003","article-title":"Discontinued privacy: Personal data leaks in Apple Bluetooth-low-energy continuity protocols","volume":"2020","author":"Celosia Guillaume","year":"2020","unstructured":"Guillaume Celosia and Mathieu Cunche. 2020. Discontinued privacy: Personal data leaks in Apple Bluetooth-low-energy continuity protocols. Proceedings on Privacy Enhancing Technologies 2020, 1 (2020), 26\u201346.","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"issue":"4","key":"e_1_3_2_42_2","doi-asserted-by":"crossref","first-page":"34","DOI":"10.2478\/popets-2019-0057","article-title":"Handoff all your privacy\u2013A review of Apple\u2019s Bluetooth low energy continuity protocol","volume":"2019","author":"Martin Jeremy","year":"2019","unstructured":"Jeremy Martin, Douglas Alpuche, Kristina Bodeman, Lamont Brown, Ellis Fenske, Lucas Foppe, Travis Mayberry, Erik Rye, Brandon Sipes, and Sam Teplov. 2019. Handoff all your privacy\u2013A review of Apple\u2019s Bluetooth low energy continuity protocol. Proceedings on Privacy Enhancing Technologies 2019, 4 (2019), 34\u201353.","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"e_1_3_2_43_2","first-page":"37","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security 19)","author":"Stute Milan","year":"2019","unstructured":"Milan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich, David Kreitschmann, Guevara Noubir, and Matthias Hollick. 2019. A billion open interfaces for eve and mallory: \\(\\lbrace\\) MitM \\(\\rbrace ,\\lbrace\\) DoS \\(\\rbrace\\) , and tracking attacks on \\(\\lbrace\\) iOS \\(\\rbrace\\) and \\(\\lbrace\\) macOS \\(\\rbrace\\) through Apple wireless direct link. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19). 37\u201354."},{"key":"e_1_3_2_44_2","first-page":"3917","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security 21)","author":"Stute Milan","year":"2021","unstructured":"Milan Stute, Alexander Heinrich, Jannik Lorenz, and Matthias Hollick. 2021. Disrupting continuity of Apple\u2019s wireless ecosystem security: New tracking, \\(\\lbrace\\) DoS \\(\\rbrace\\) , and \\(\\lbrace\\) MitM \\(\\rbrace\\) attacks on \\(\\lbrace\\) iOS \\(\\rbrace\\) and \\(\\lbrace\\) macOS \\(\\rbrace\\) through Bluetooth low energy, \\(\\lbrace\\) AWDL \\(\\rbrace\\) , and \\(\\lbrace\\) Wi-Fi \\(\\rbrace\\) . In Proceedings of the 30th USENIX Security Symposium (USENIX Security 21). 3917\u20133934."},{"issue":"3","key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"227","DOI":"10.2478\/popets-2021-0045","article-title":"Who can devices? Security and privacy of Apple\u2019s crowd-sourced Bluetooth location tracking system","volume":"2021","author":"Heinrich Alexander","year":"2021","unstructured":"Alexander Heinrich, Milan Stute, Tim Kornhuber, and Matthias Hollick. 2021. Who can devices? Security and privacy of Apple\u2019s crowd-sourced Bluetooth location tracking system. Proceedings on Privacy Enhancing Technologies 2021, 3 (2021), 227\u2013245.","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"e_1_3_2_46_2","first-page":"99","volume-title":"Proceedings of the 17th International Workshop on Mobile Computing Systems and Applications","author":"Das Aveek K.","year":"2016","unstructured":"Aveek K. Das, Parth H. Pathak, Chen-Nee Chuah, and Prasant Mohapatra. 2016. Uncovering privacy leakage in BLE network traffic of wearable fitness trackers. In Proceedings of the 17th International Workshop on Mobile Computing Systems and Applications. ACM, 99\u2013104."},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1145\/2897845.2897883","volume-title":"Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security","author":"Vanhoef Mathy","year":"2016","unstructured":"Mathy Vanhoef, C\u00e9lestin Matte, Mathieu Cunche, Leonardo S. Cardoso, and Frank Piessens. 2016. Why MAC address randomization is not enough: An analysis of Wi-Fi network discovery mechanisms. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security. 413\u2013424."},{"key":"e_1_3_2_48_2","volume-title":"Proceedings of the International Conference on Security and Privacy in Communication Networks","author":"Wen Haohuang","year":"2020","unstructured":"Haohuang Wen, Qingchuan Zhao, Zhiqiang Lin, Dong Xuan, and Ness Shroff. 2020. A study of the privacy of COVID-19 contact tracing apps. In Proceedings of the International Conference on Security and Privacy in Communication Networks."},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1145\/3338507.3358617","volume-title":"Proceedings of the 2nd International ACM Workshop on Security and Privacy for the Internet-of-Things","author":"Celosia Guillaume","year":"2019","unstructured":"Guillaume Celosia and Mathieu Cunche. 2019. Fingerprinting Bluetooth-low-energy devices based on the generic attribute profile. In Proceedings of the 2nd International ACM Workshop on Security and Privacy for the Internet-of-Things. 24\u201331."},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","first-page":"374","DOI":"10.1145\/3448300.3468251","volume-title":"Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks","author":"Heinrich Alexander","year":"2021","unstructured":"Alexander Heinrich, Milan Stute, and Matthias Hollick. 2021. OpenHaystack: A framework for tracking personal Bluetooth devices via Apple\u2019s massive find my network. In Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks. 374\u2013376."},{"key":"e_1_3_2_51_2","article-title":"Bluetooth Security & Hacks","author":"Becker Andreas","year":"2007","unstructured":"Andreas Becker and Ing Christof Paar. 2007. Bluetooth Security & Hacks. Ruhr-Universit\u00e4t Bochum.","journal-title":"Ruhr-Universit\u00e4t Bochum"},{"key":"e_1_3_2_52_2","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/1067170.1067176","volume-title":"Proceedings of the 3rd International Conference on Mobile Systems, Applications, and Services","author":"Shaked Yaniv","year":"2005","unstructured":"Yaniv Shaked and Avishai Wool. 2005. Cracking the Bluetooth pin. In Proceedings of the 3rd International Conference on Mobile Systems, Applications, and Services. ACM, 39\u201350."},{"key":"e_1_3_2_53_2","first-page":"1","article-title":"BlueSniff: Eve meets alice and Bluetooth.","volume":"7","author":"Spill Dominic","year":"2007","unstructured":"Dominic Spill and Andrea Bittau. 2007. BlueSniff: Eve meets alice and Bluetooth. WOOT 7 (2007), 1\u201310.","journal-title":"WOOT"},{"key":"e_1_3_2_54_2","first-page":"4","volume-title":"Proceedings of the 7th USENIX Conference on Offensive Technologies (WOOT\u201913)","author":"Ryan Mike","year":"2013","unstructured":"Mike Ryan. 2013. Bluetooth: With low energy comes low security. In Proceedings of the 7th USENIX Conference on Offensive Technologies (WOOT\u201913). USENIX Association, Berkeley, CA, USA, 4\u20134. Retrieved from http:\/\/dl.acm.org\/citation.cfm?id=2534748.2534754"},{"key":"e_1_3_2_55_2","unstructured":"SIG Bluetooth. 2024. Bluetooth Core Specification Version 6.0: Specification of the Bluetooth System (2024)."},{"key":"e_1_3_2_56_2","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1007\/978-3-540-45126-6_11","volume-title":"Proceedings of the International Conference on Financial Cryptography","author":"K\u00fcgler Dennis","year":"2003","unstructured":"Dennis K\u00fcgler. 2003. \u201cMan in the Middle\u201d attacks on Bluetooth. In Proceedings of the International Conference on Financial Cryptography. Springer, 149\u2013161."},{"issue":"1","key":"e_1_3_2_57_2","article-title":"Two practical man-in-the-middle attacks on Bluetooth secure simple pairing and countermeasures","volume":"9","author":"Haataja Keijo","year":"2010","unstructured":"Keijo Haataja and Pekka Toivanen. 2010. Two practical man-in-the-middle attacks on Bluetooth secure simple pairing and countermeasures. IEEE Transactions on Wireless Communications 9, 1 (2010).","journal-title":"IEEE Transactions on Wireless Communications"},{"key":"e_1_3_2_58_2","first-page":"636","volume-title":"IEEE INFOCOM 2020-Proceedings of the IEEE Conference on Computer Communications","author":"Zhang Yue","year":"2020","unstructured":"Yue Zhang, Jian Weng, Zhen Ling, Bryan Pearson, and Xinwen Fu. 2020. BLESS: A BLE application security scanning framework. In IEEE INFOCOM 2020-Proceedings of the IEEE Conference on Computer Communications. IEEE, 636\u2013645."},{"key":"e_1_3_2_59_2","unstructured":"SIG Bluetooth. 2024. Bluetooth Core Specification Version 6.0: Specification of the Bluetooth System (2024)."},{"issue":"3","key":"e_1_3_2_60_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3394497","article-title":"Key negotiation downgrade attacks on Bluetooth and Bluetooth low energy","volume":"23","author":"Antonioli Daniele","year":"2020","unstructured":"Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen. 2020. Key negotiation downgrade attacks on Bluetooth and Bluetooth low energy. ACM Transactions on Privacy and Security (TOPS) 23, 3 (2020), 1\u201328.","journal-title":"ACM Transactions on Privacy and Security (TOPS)"},{"key":"e_1_3_2_61_2","first-page":"7085","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24)","author":"Lei Chongqing","year":"2024","unstructured":"Chongqing Lei, Zhen Ling, Yue Zhang, Yan Yang, Junzhou Luo, and Xinwen Fu. 2024. A friend\u2019s eye is a good mirror: Synthesizing \\(\\lbrace\\) MCU \\(\\rbrace\\) peripheral models from peripheral drivers. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24). 7085\u20137102."},{"key":"e_1_3_2_62_2","first-page":"2341","volume-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","author":"Liu Kaizheng","year":"2024","unstructured":"Kaizheng Liu, Ming Yang, Zhen Ling, Yue Zhang, Chongqing Lei, Junzhou Luo, and Xinwen Fu. 2024. RIoTFuzzer: Companion app assisted remote fuzzing for detecting vulnerabilities in IoT devices. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 2341\u20132354."},{"key":"e_1_3_2_63_2","doi-asserted-by":"crossref","first-page":"1761","DOI":"10.1145\/3658644.3690216","volume-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","author":"Zhang Yue","year":"2024","unstructured":"Yue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang, Christopher Morales-Gonzalez, Qun Zhou Sun, and Xinwen Fu. 2024. Collapse like a house of cards: Hacking building automation system through fuzzing. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 1761\u20131775."},{"key":"e_1_3_2_64_2","article-title":"AutoIoT: Automated IoT platform using large language models","author":"Cheng Ye","year":"2025","unstructured":"Ye Cheng, Minghui Xu, Yue Zhang, Kun Li, Ruoxi Wang, and Lian Yang. 2025. AutoIoT: Automated IoT platform using large language models. IEEE Internet of Things Journal 12, 10 (2025).","journal-title":"IEEE Internet of Things Journal"},{"key":"e_1_3_2_65_2","volume-title":"2025 Proceedings of the Annual Network and Distributed System Security Symposium","author":"Ellis Christopher","year":"2025","unstructured":"Christopher Ellis, Yue Zhang, Mohit Kumar Jangid, Shixuan Zhao, and Zhiqiang Lin. 2025. Deanonymizing device identities via side-channel attacks in exclusive-use IoTs & mitigation. In 2025 Proceedings of the Annual Network and Distributed System Security Symposium."},{"key":"e_1_3_2_66_2","doi-asserted-by":"crossref","first-page":"506","DOI":"10.1145\/3019612.3019878","volume-title":"Proceedings of the Symposium on Applied Computing","author":"Meidan Yair","year":"2017","unstructured":"Yair Meidan, Michael Bohadana, Asaf Shabtai, Juan David Guarnizo, Mart\u00edn Ochoa, Nils Ole Tippenhauer, and Yuval Elovici. 2017. ProfilIoT: A machine learning approach for IoT device identification based on network traffic analysis. In Proceedings of the Symposium on Applied Computing. 506\u2013509."},{"key":"e_1_3_2_67_2","doi-asserted-by":"crossref","first-page":"474","DOI":"10.1109\/EuroSP48549.2020.00037","volume-title":"Proceedings of the 2020 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"Perdisci Roberto","year":"2020","unstructured":"Roberto Perdisci, Thomas Papastergiou, Omar Alrawi, and Manos Antonakakis. 2020. IoTFinder: Efficient large-scale identification of IoT devices via passive DNS traffic analysis. In Proceedings of the 2020 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 474\u2013489."},{"key":"e_1_3_2_68_2","first-page":"55","volume-title":"Proceedings of the 29th  \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security 20)","author":"Yu Lingjing","year":"2020","unstructured":"Lingjing Yu, Bo Luo, Jun Ma, Zhaoyu Zhou, and Qingyun Liu. 2020. You are what you broadcast: Identification of mobile and IoT devices from (public) wifi. In Proceedings of the 29th \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security 20). 55\u201372."},{"issue":"2","key":"e_1_3_2_69_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3397333","article-title":"IoT inspector: Crowdsourcing labeled network traffic from smart home devices at scale","volume":"4","author":"Huang Danny Yuxing","year":"2020","unstructured":"Danny Yuxing Huang, Noah Apthorpe, Frank Li, Gunes Acar, and Nick Feamster. 2020. IoT inspector: Crowdsourcing labeled network traffic from smart home devices at scale. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 4, 2 (2020), 1\u201321.","journal-title":"Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3744559","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,27]],"date-time":"2025-09-27T12:12:21Z","timestamp":1758975141000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3744559"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,27]]},"references-count":68,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3744559"],"URL":"https:\/\/doi.org\/10.1145\/3744559","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,27]]},"assertion":[{"value":"2022-12-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-21","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}