PhantomMotion: Laser-Based Motion Injection Attacks on Wireless Security Surveillance Systems
Yan He (University of Oklahoma)
Network and Distributed System Security (NDSS) Symposium 2026 · Day 2 · Wireless Security
Overview
Yan He from the University of Oklahoma presents PhantomMotion, a novel attack that uses lasers to inject fake motion events into wireless security cameras, exploiting the passive infrared (PIR) motion sensors that trigger recording in battery-powered cameras. By heating a surface within the camera's detection zone to approximately 37 degrees Celsius (simulating human body temperature), a laser can trick the camera into recording empty footage. When repeated rapidly, the attack serves as both a denial-of-service (draining battery-powered cameras from 60 days to under 3 hours of battery life) and a cry-wolf attack (flooding the user with hundreds of false alarms, causing them to ignore real intrusions). The researchers tested 15 cameras and 3 security systems with a 100% success rate and demonstrated a remote attack at 120 meters distance. The attack can also be used defensively to detect and disable hidden cameras in spaces like hotel rooms and Airbnbs.

Key moments
- 0:30 Motivation: $43.65 billion wireless camera market and property crime stats
- 2:00 How PIR motion sensors work: detecting heat signatures
- 4:00 Laser can simulate human body temperature heat signature
- 6:00 Threat model: cry-wolf attack and battery drain to 3 hours
- 8:00 Target camera identification via WiFi MAC address OUI table
- 12:00 Scanning method and trigger detection via WiFi traffic spikes
- 14:00 Stealthy attack: laser embedded in delivery box as a gift
- 16:00 Q&A: 80% of wireless cameras use this vulnerable mechanism
PhantomMotion: Laser-Based Motion Injection Attacks on Wireless Security Surveillance Systems
Speakers: Yan He
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=LKNHAe_eyBY
Overview
Yan He from the University of Oklahoma presents PhantomMotion, a novel attack that uses lasers to inject fake motion events into wireless security cameras, exploiting the passive infrared (PIR) motion sensors that trigger recording in battery-powered cameras. By heating a surface within the camera's detection zone to approximately 37 degrees Celsius (simulating human body temperature), a laser can trick the camera into recording empty footage. When repeated rapidly, the attack serves as both a denial-of-service (draining battery-powered cameras from 60 days to under 3 hours of battery life) and a cry-wolf attack (flooding the user with hundreds of false alarms, causing them to ignore real intrusions). The researchers tested 15 cameras and 3 security systems with a 100% success rate and demonstrated a remote attack at 120 meters distance. The attack can also be used defensively to detect and disable hidden cameras in spaces like hotel rooms and Airbnbs.
Background
▶ Watch: Motivation: $43.65 billion wireless camera market and property crime stats (0:30)
Property offenses in the US account for approximately 40 million cases annually, with 1.2 million violence offenses, driving massive growth in the wireless security camera market -- projected to reach $80 billion by 2030 with an annual growth rate of 11.2%. Wireless cameras dominate consumer security because they can be freely installed anywhere without wiring. However, always-on recording would drain a camera's battery in approximately 4 hours, so manufacturers rely on PIR (Passive Infrared) motion sensors to trigger recording only when motion is detected, extending battery life to over 60 days.
PIR sensors detect heat signatures rather than visual motion. They identify objects by measuring temperature differentials against the ambient environment. A human body at approximately 37 degrees Celsius in a 20-degree environment produces a distinctive heat signature of roughly 70 degrees that triggers the sensor. These sensors cost approximately $1 each, have near-instant response times, and are compact enough to embed in any camera housing. An estimated 80% of wireless cameras on the market use this mechanism.
Key Findings
▶ Watch: Laser can simulate human body temperature heat signature (4:00)
100% success rate across all tested devices: Every camera and security system tested was successfully triggered by the laser-based fake motion injection. Zero false positives were observed -- all triggers were caused by the laser.
Battery depletion in under 3 hours: By repeatedly triggering recording cycles, the attack reduced camera battery life from the advertised 60+ days to less than 3 hours for battery-powered cameras, effectively disabling the security system.
Operation time under 15 seconds: From initiating the laser to successfully triggering the camera, the entire operation consistently completed in under 15 seconds across all tested devices.
120-meter attack range demonstrated: Using a laser with a focusing lens, the researchers achieved successful camera triggering at 120 meters. The limiting factor was WiFi sniffing range, not laser range, as lasers can travel much farther.
Invisible laser variant: Using IR (infrared) lasers, the attack becomes completely invisible to the human eye, leaving no visual evidence of the attack on recorded footage.
Stealthy delivery method: The researchers demonstrated embedding the laser in a small box that could be delivered as a gift to the victim's home, enabling autonomous and covert operation.
Technical Deep Dive
▶ Watch: Target camera identification via WiFi MAC address OUI table (8:00)
The attack addresses three technical challenges. First, target identification: the researchers use WiFi sniffing to identify cameras by their MAC address OUI (Organizationally Unique Identifier) prefix -- the first three bytes of a MAC address identify the manufacturer. Using a WiFi sniffer (or a rooted Android phone in monitor mode), the attacker identifies all devices communicating on the network and filters for known camera manufacturers using an OUI lookup table.
Second, laser heating control: the laser must heat the target surface to approximately 37 degrees Celsius (simulating human body temperature) without causing damage or fire. The researchers use a DHT11 temperature sensor to measure ambient temperature, then calculate the required heating time based on the temperature differential. Different building materials (wood, stone, brick) require different heating times due to varying thermal properties, which the researchers characterized through material sampling. The minimum laser power required is 150 mW, compared to a typical laser pointer's 5-10 mW.
Third, camera trigger detection: the researchers monitor WiFi traffic to confirm successful triggering. In standby mode, cameras generate zero network traffic. When triggered, cameras begin recording and transmitting data, producing a distinctive spike in network activity that confirms the fake motion was detected.
The scanning method handles the challenge of locating the camera's detection zone. The attacker selects a starting point and moves the laser in increments across the surface, heating each point for the minimum required time, until the laser falls within the camera's PIR sensor detection range. The overall scan distance is consistently less than 1.4 meters.
Demo / Proof of Concept
▶ Watch: Scanning method and trigger detection via WiFi traffic spikes (12:00)
The researchers tested 15 different wireless cameras including Arlo Pro 3, Blink XT2, and Ring Stick Up Camera, plus 3 security systems (door-open detection systems using the same PIR sensor technology). They developed a user-friendly application that enables even users with no laser experience to operate the attack. The evaluation covered success rate, false positive rate, operation time, and scanning distance. A remote attack demonstration achieved triggering at 120 meters using a laser with a focusing lens. The stealthy attack variant embedded the laser in a small delivery box, demonstrating a gift-based covert deployment model.
Defensive Implications
▶ Watch: Q&A: 80% of wireless cameras use this vulnerable mechanism (16:00)
The dual-use nature of this attack is notable -- it can be used both offensively (to disable security cameras before a physical intrusion) and defensively (to detect and disable hidden cameras in hotel rooms, Airbnbs, and other spaces). For mitigation, computer vision and AI-based detection could potentially identify that no actual human or animal is present despite the motion trigger, but this fails against invisible IR lasers that produce no visual signature. Subscription-based camera services that label detected objects (person, animal, vehicle) could partially mitigate the cry-wolf attack but cannot prevent the battery depletion denial-of-service. Ultimately, the PIR sensor technology itself is the vulnerability, and meaningful mitigation may require supplementary sensor types or fundamental redesign of the motion detection approach.
Key Takeaways
- Approximately 80% of wireless security cameras use PIR motion sensors vulnerable to laser-based fake motion injection
- A 150 mW laser (significantly more powerful than a pointer but not dangerous) achieves 100% success rate across 15 tested cameras and 3 security systems
- Battery-powered cameras can be drained from 60 days to under 3 hours of battery life through repeated triggering
- IR lasers make the attack completely invisible, with no visual evidence on camera footage
- The attack can be used defensively to detect and disable hidden cameras in hotels and Airbnbs
- WiFi range (not laser range) is the limiting factor at 120 meters demonstrated distance
About the Speaker(s)
Yan He is a researcher at the University of Oklahoma working with advisor Dr. Fang and colleague Guanchong on physical-layer attacks against IoT security systems. The research focuses on the intersection of physical sensor exploitation and wireless security infrastructure.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A practical physical-layer attack that reliably disables wireless security cameras by exploiting PIR motion sensor physics. The 100% success rate across 15 cameras, battery drain from 60 days to 3 hours, and 120-meter range make this operationally useful. Clean engineering but the underlying insight (lasers produce heat, PIR sensors detect heat) is not deeply novel.
Heather Calloway (CISO) — STRONG
A high-impact physical security finding that every organization relying on battery-powered wireless cameras needs to know about. The ability to drain a security camera's battery from 60 days to 3 hours using a $50 laser -- with 100% success rate across 15 tested camera models -- represents a fundamental gap in physical security infrastructure that warrants immediate risk reassessment.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2026
All talks from Network and Distributed System Security (NDSS) Symposium 2026