Mitigating shoulder spoofing vulnerabilities in mobile payment systems: a security framework

缓解移动支付系统中的肩部欺骗漏洞:一个安全框架

阅读:1

Abstract

The rapid growth of mobile payment platforms has enhanced transactional convenience but also introduced critical security challenges, notably shoulder spoofing. This attack occurs when unauthorized individuals or surveillance devices visually intercept sensitive information, such as Mobile Personal Identification Numbers (MPINs), during payment processes. Existing security mechanisms-including PIN masking and screen dimming-fail to detect environmental threats or provide adaptive responses, leaving users vulnerable in public spaces. To address this gap, propose a novel solution titled Gaze-Aware Threat Detection with Contextual Scene Analysis (GATCSA). GATCSA leverages the front-facing camera and on-device computer vision algorithms to monitor the surroundings during mobile transactions. The system identifies suspicious behavior such as gaze fixation by nearby individuals or the presence of surveillance equipment targeting the mobile screen. A risk evaluation module considers proximity, gaze direction, and focus duration to classify threat levels in real time. Upon detection, the system provides users with contextual alerts and actionable suggestions-such as changing the device angle, enabling a privacy screen, or halting the transaction-to safeguard against unauthorized visual access. Unlike traditional methods, GATCSA processes all data locally to ensure user privacy and operates efficiently on resource-constrained mobile devices. Preliminary testing in varied real-world conditions-differing in lighting, crowd density, and device orientation-demonstrates high accuracy in threat identification and user responsiveness. By integrating gaze tracking with environmental awareness, GATCSA represents a significant advancement in mobile payment security, enhancing user trust and privacy during digital transactions.

特别声明

1、本页面内容包含部分的内容是基于公开信息的合理引用;引用内容仅为补充信息,不代表本站立场。

2、若认为本页面引用内容涉及侵权,请及时与本站联系,我们将第一时间处理。

3、其他媒体/个人如需使用本页面原创内容,需注明“来源:[生知库]”并获得授权;使用引用内容的,需自行联系原作者获得许可。

4、投稿及合作请联系:info@biocloudy.com。