
For a decade the privacy-conscious move was simple: leave your phone at home. No device, no beacon, no trail. A study out of Germany’s Karlsruhe Institute of Technology, reported this month, quietly retires that assumption. KIT’s security researchers showed that ordinary WiFi can identify a specific person, with near-100% accuracy, when they carry no device at all and their phone is switched off. The router does not need your phone. It needs your body. And you cannot leave that at home.
How a router learns to recognize you
The physics has been understood for years; what changed is the practicality. A human body is a bag of water that reflects, absorbs and scatters 2.4 and 5 GHz radio waves in a way that is specific to your size, shape, posture and gait. As WiFi signals fill a room, your presence perturbs them, and those perturbations encode a radio biometric signature — a body-shaped fingerprint drawn purely from how you bend the ambient field. Feed enough of those perturbations to a neural network and it learns to tell people apart.
This is not new in the lab. The 2025 WhoFi work from Sapienza University of Rome hit 95.5% person re-identification using a Transformer trained on channel state information (CSI). What makes the KIT result the escalation worth noting is what it needs. Earlier systems required specialized hardware and complex CSI measurements — a research setup, not a threat. KIT used the routine feedback data that WiFi devices and routers already exchange during normal communication, and still hit near-100% across 197 participants, from different angles, regardless of how they walked. The barrier dropped from "needs a lab" to "needs a router and the traffic that is already flowing." That is the difference between a curiosity and a capability.
Why this is a genuinely new class of privacy attack
I have written a lot this month about surveillance and identity — Facebook demanding a face scan, ChatGPT estimating your age. WiFi sensing belongs in that conversation but is categorically worse along three axes, and it is worth being precise about why:
- It is passive and consentless. Face verification and age estimation at least require you to do something — upload a selfie, use a service. WiFi sensing requires nothing from you. You walk into a room; the infrastructure already there identifies you. There is no button you failed to uncheck.
- There is no device to leave behind. Every prior location-tracking privacy control assumed the tracker was your phone, your car, your card — something you carry and could, in principle, not carry. Your body’s radio signature is not detachable. The one defense the paranoid always had is gone.
- It is infrastructure-native and invisible. This does not require deploying cameras someone might notice and object to. It runs on the WiFi that is already in every office, shop, airport and home. The surveillance layer is the connectivity layer. You cannot see it, and it was installed for another purpose.
The researchers themselves now argue that identity inference via WiFi sensing should be classified as a privacy attack, and they are right. It is the first identification technology that is simultaneously passive, device-independent, and built into infrastructure you cannot avoid without leaving society.
The dual-use fork, and why it makes this hard to stop
Here is what keeps WiFi sensing from being simply banned: the exact same capability is genuinely, valuably good. Camera-free fall detection for an elderly person living alone — dignity-preserving, no lens in the bathroom, just the router noticing they went down and did not get up. Occupancy sensing for HVAC efficiency. Intrusion detection without cameras. Presence-aware smart homes. These are real benefits, and they are why the industry is not fighting the technology — it is standardizing it. IEEE 802.11bf, the "WiFi Sensing" amendment, is deliberately turning your access point into a sensor as a first-class feature. The capability that identifies you and the capability that catches your grandmother when she falls are the same capability. That is the whole problem: you cannot ban the sensing without losing the care, and you cannot allow the care without enabling the surveillance.
What I would take from this
- Update your model of what a network is. A WiFi access point is no longer just a data pipe; it is a sensor with a growing view of the physical bodies around it. For anyone doing threat modeling, the RF environment is now part of the attack surface, and "we have no cameras here" is no longer equivalent to "this space is not under identification."
- Assume physical-presence privacy is eroding faster than data privacy. We spent a decade building consent frameworks for data you knowingly hand over. WiFi sensing takes something you never hand over — your physical presence and identity — from infrastructure you do not control. Regulation is nowhere near this, and the technology is standardizing now.
- Watch 802.11bf and demand the controls be built in, not bolted on. The time to decide who may enable sensing, whether identification (as opposed to mere presence) is permitted, and what consent looks like is during standardization, not after every router ships with it on. Sensing-as-presence is defensible; sensing-as-identification is a different product and should be gated as one.
- The beneficial framing is doing heavy lifting — scrutinize it. "Privacy-preserving alternative to cameras" is how WiFi sensing is being sold, and against cameras it is genuinely better in some ways. But "better than a camera" is not the same as "private," and a technology you cannot see, cannot opt out of, and cannot evade by leaving your devices at home is not obviously the lesser evil.
The reassuring caveat is real: this is research demonstrated in controlled conditions, not proof your café router is fingerprinting you today. But the trajectory is the story. Every barrier that kept WiFi identification in the lab — special hardware, complex measurements, device dependency — has now fallen, and the industry is baking the sensing substrate into the standard. The question is no longer whether the walls can see you. It is who gets to look, and whether we decide that before the capability is in every ceiling. Right now, we are not deciding. We are shipping.