Smart-home hubs sit between low-power devices (door locks, motion sensors, smart bulbs) and the cloud. Their traffic is encrypted, which is often assumed to keep a household’s activity private. ChatterHub shows that this blind spot persists even behind encryption: an adversary who can only observe the hub’s encrypted traffic can still learn which devices are in the home and what they are doing.
How it works
- Offline training. Packet traces from a hub are labeled with ground-truth device events.
- Segmentation. A packet filter and dynamic change-point detection isolate the bursts of traffic caused by individual device events.
- Classification. Models (sequence-to-sequence, LSTM, and random forest) learn to map each burst to a device and an action.
- Attack. The trained model is applied to a target home’s encrypted traffic, observed by a nearby sniffer, a compromised router, or an Internet service provider.
Key findings
- Device identity and user actions can be inferred from encrypted hub traffic without decryption.
- The attack needs no prior knowledge of which devices are installed in the home.
- The results highlight the need for traffic-shaping defenses in smart-home ecosystems.