Researchers at Cornell University have discovered a new AI-driven attack capable of stealing passwords with remarkable accuracy. The attack involves training an AI model on audio recordings of people typing, enabling it to recognize distinct sounds produced by each key press. Testing was performed using a nearby phone’s microphone to capture keystrokes on a MacBook Pro. The AI achieved an accuracy rate of 95% in identifying pressed keys.
The experiment was further extended to crack passwords during Zoom and Skype calls. The AI model reproduced keystrokes with 93% accuracy during Zoom calls and 91.7% accuracy during Skype calls.
Contrary to popular belief, the attack is not based on the volume of typing but on identifying waveform, intensity, and timing of keystrokes. The AI can discern unique typing patterns, such as the slight delay in pressing a specific key, which contributes to its high accuracy.
The attack raises concerns as it can be executed using readily available equipment. An attacker could place a smartphone with a microphone near a target’s keyboard and utilize the AI model to steal passwords and sensitive information.
To safeguard against this type of attack, experts recommend avoiding manual password entry by utilizing features like Windows Hello and Touch ID. Employing a password manager to generate and store strong passwords is also advised, eliminating the need for individuals to remember multiple passwords themselves.

