Toggle Main Menu Toggle Search

Open Access padlockePrints

Entropy collapse in mobile sensors: The hidden risks of sensor-based security

Lookup NU author(s): Dr Carlton Shepherd

Downloads


Licence

This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0).


Abstract

© 2025 The Author(s).Mobile sensor data has been proposed for security-critical applications such as device pairing, proximity detection, and continuous authentication. However, the foundational premise that these signals provide sufficient entropy remains under-explored. In this work, we systematically analyse the entropy of mobile sensor data using four datasets from multiple application contexts (UCI-HAR, SHL, Relay, and PerilZIS). Using direct computation and estimation, we report entropy values – max, Shannon, collision, and min-entropy – for an exhaustive range of sensor combinations. We demonstrate that the entropy of mobile sensors remains far below what is considered secure by modern standards for security applications, even when many sensors are combined. In particular, we observe an alarming divergence between average-case Shannon entropy and worst-case min-entropy. Single-sensor min-entropy varies between 3.408–4.483 bits despite Shannon entropy being several multiples higher. We also show that redundancies between sensor modalities contribute to a ≈ 75% reduction between Shannon and min-entropy. Indeed, min-entropy plateaus between 8.1–23.9 bits when combining up to 22 modalities, while Shannon entropy can exceed 80 bits. Adding sensors typically increases Shannon entropy but moves min-entropy by only ≈ 1–2 bits per added modality, evidencing entropy collapse under redundancy. Our results reveal that adversaries may feasibly predict sensor signals through an exhaustive exploration of the measurement space. Our work also calls into question the widely held assumption that adding more sensors inherently yields higher security. Ultimately, we strongly urge caution when relying on mobile sensor data for security applications.


Publication metadata

Author(s): Shepherd C, Hurley EAJ

Publication type: Article

Publication status: Published

Journal: Journal of Information Security and Applications

Year: 2025

Volume: 95

Print publication date: 01/12/2025

Online publication date: 24/10/2025

Acceptance date: 02/04/2018

Date deposited: 26/11/2025

ISSN (print): 2214-2134

ISSN (electronic): 2214-2126

Publisher: Elsevier Ltd

URL: https://doi.org/10.1016/j.jisa.2025.104272

DOI: 10.1016/j.jisa.2025.104272

Data Access Statement: A link to an open-source repository is given in the paper.


Altmetrics

Altmetrics provided by Altmetric


Funding

Funder referenceFunder name
EP/Y030168/1
EPSRC

Share