Hiding an Ear in Plain Sight: On the Practicality and Implications of Acoustic Eavesdropping with Telecom Fiber Optic Cables

Youqian Zhang

Network and Distributed System Security (NDSS) Symposium 2026 · Day 3 · Covert Sensing

Overview

This research demonstrates that standard telecom fiber optic cables -- deployed in homes and offices as part of fiber-to-the-home (FTTH) infrastructure -- can be exploited as acoustic eavesdropping sensors. While optical fibers are traditionally considered secure against eavesdropping (immune to electromagnetic interference, no RF emissions), they are inherently sensitive to mechanical vibrations, including sound pressure waves. By winding telecom fiber around a hollow cylinder "sensory receptor" that can be camouflaged inside standard optical fiber junction boxes, an attacker connected to the fiber's other end can recover speech with over 80% word accuracy at distances up to 2 meters.

Watch on YouTube · Slides

Visual summary for Hiding an Ear in Plain Sight: On the Practicality and Implications of Acoustic Eavesdropping with Telecom Fiber Optic Cables by Youqian Zhang
Visual summary for Hiding an Ear in Plain Sight: On the Practicality and Implications of Acoustic Eavesdropping with Telecom Fiber Optic Cables by Youqian Zhang

Key moments

  1. 0:00 Optical fibers as sensors: distributed acoustic sensing principles
  2. 2:00 FTTH deployment and dark fiber attack opportunity
  3. 6:00 Threat model: attacker access to ODN and optical fiber boxes
  4. 8:00 Sensory receptor design: fiber wound around hollow cylinder
  5. 10:00 Parameter optimization: diameter, fiber length, frequency response
  6. 12:00 Results: sound classification, localization, and speech recovery
  7. 16:00 Resistant to ultrasonic jammers that defeat all microphones
  8. 18:00 Q&A: multi-room monitoring and DAS equipment capabilities

Hiding an Ear in Plain Sight: On the Practicality and Implications of Acoustic Eavesdropping with Telecom Fiber Optic Cables

Speakers: Youqian Zhang

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=0yBv4cXiS4w

Overview

This research demonstrates that standard telecom fiber optic cables -- deployed in homes and offices as part of fiber-to-the-home (FTTH) infrastructure -- can be exploited as acoustic eavesdropping sensors. While optical fibers are traditionally considered secure against eavesdropping (immune to electromagnetic interference, no RF emissions), they are inherently sensitive to mechanical vibrations, including sound pressure waves. By winding telecom fiber around a hollow cylinder "sensory receptor" that can be camouflaged inside standard optical fiber junction boxes, an attacker connected to the fiber's other end can recover speech with over 80% word accuracy at distances up to 2 meters.

Critically, the fiber-based eavesdropping method is resistant to ultrasonic jammers -- commercial anti-eavesdropping devices that render conventional microphones and voice recorders useless. This makes fiber eavesdropping a threat in high-security environments (boardrooms, trading floors) that have been swept for microphones but overlook the fiber infrastructure running through their walls.

Background

▶ Watch: Optical fibers as sensors: distributed acoustic sensing principles (0:00)

Distributed Acoustic Sensing (DAS) is an established technology that uses the back-scattered light in optical fibers to detect mechanical vibrations along the fiber's length. Commercial DAS systems are used for traffic monitoring, pipeline surveillance, and submarine activity detection. The underlying physics: when sound pressure causes minor deformation of the optical fiber, it creates phase changes in the back-scattered light that can be measured and converted back to acoustic signals.

Previous work explored this concept: Russian researchers discussed theoretical possibilities in 2012, and Chinese researchers demonstrated sound capture in 2022 -- but only through structure-borne vibrations (sound coupled through a shared metal plate), not airborne sound propagation through air.

Fiber-to-the-home (FTTH) deployment has penetration rates of 80-90% in many countries. Importantly, multiple fibers are typically installed during FTTH deployment, but users only connect to one ISP's fiber. The unused "dark fibers" create an opportunity: an attacker can connect sensing equipment to one end of an unused fiber while the other end passes through the target's living or working space.

Key Findings

▶ Watch: Threat model: attacker access to ODN and optical fiber boxes (6:00)

Linear fiber alone cannot capture airborne speech but can detect footsteps. Plain fiber along a baseboard captures structure-borne vibrations (footsteps through the floor) but not airborne sound at 80 dB from 1 meter. This is because the coupling between airborne sound and the stiff fiber is insufficient.

Sensory receptor enables airborne speech capture. Winding telecom fiber around a PET hollow cylinder (85mm optimal diameter) amplifies the acoustic coupling. Sound pressure causes radial deformation of the cylinder, which is converted to longitudinal strain on the fiber and ultimately to measurable phase changes in back-scattered light.

Over 80% word accuracy at 2 meters. Word error rate (WER) below 0.2 at 2 meters means more than 80% of speech information is retained. Performance degrades with distance but remains above random guess levels even at greater distances.

Sound event classification reaches 83% accuracy at 0.1 meters. Across 14 sound event types (clock alarm, coughing, keyboard typing, etc.), fine-tuned models achieve 83% accuracy at 0.1m, degrading to 50% at 1m and 43% at 2m (vs. 7% random baseline).

Indoor localization with 0.77m average error. Using three sensory receptors and time-difference-of-arrival calculations, the system locates sound sources with sub-meter accuracy in a 27-square-meter room.

Resistant to ultrasonic jammers. When commercial ultrasonic jammers are activated, conventional voice recorders (iPhone, Huawei, Xiaomi, mini recorders) show dramatically increased WER, while the fiber-based system shows minimal performance change. This is because ultrasonic frequencies affect MEMS microphones but not the fiber's acoustic sensing mechanism.

Multi-room monitoring is possible. Every point on the optical fiber acts as a sensing point, so fiber routed through multiple rooms can monitor all of them simultaneously -- a feature inherited from DAS technology.

Technical Deep Dive

▶ Watch: Parameter optimization: diameter, fiber length, frequency response (10:00)

Sensory receptor design: Standard telecom fiber is wound around a hollow cylinder made of PET material (optimal among tested materials). The physics: airborne sound pressure causes radial deformation of the hollow cylinder, which creates longitudinal strain on the wrapped fiber, changing its effective length and refractive index. These changes produce measurable phase shifts in the Rayleigh back-scattered light captured by the DAS interrogator.

Key parameters optimized: Outer diameter (85mm optimal, though 65mm fits inside standard junction boxes), wrapping fiber length (longer = better, consistent with theory), and the system maintains strong performance across the 100-4000 Hz frequency range relevant to speech.

Signal processing pipeline: Raw back-scattered light phase data is reconstructed into acoustic waveforms, then processed through filtering and transformer-based denoising to remove noise. Machine learning models (fine-tuned on recovered audio characteristics) perform classification, localization, and speech recognition tasks.

Commercial DAS equipment is used for the interrogation, with an equivalent sampling rate of approximately 8,000 Hz (enabling recovery of signals up to ~4,000 Hz via Nyquist).

Camouflage: The sensory receptor is designed to fit inside standard optical fiber junction boxes, making it visually indistinguishable from normal fiber routing during routine inspections. An attacker posing as a technician during installation or maintenance can install the device without raising suspicion.

Demo / Proof of Concept

▶ Watch: Results: sound classification, localization, and speech recovery (12:00)

The researchers conducted experiments in a room with three sensory receptors installed in optical fiber junction boxes along a single fiber. Twenty-five sound source positions were tested. Results across three tasks:

  • Sound event classification: 83% accuracy at 0.1m (14 event types)
  • Indoor localization: 0.77m average positioning error (27 sq meter room)
  • Speech eavesdropping: WER below 0.2 at 2m (80%+ word accuracy)

Sound samples from the recovered audio are available via QR code provided in the presentation, demonstrating the quality of recovered speech.

Defensive Implications

▶ Watch: Q&A: multi-room monitoring and DAS equipment capabilities (18:00)

High-security environments must consider fiber infrastructure as an eavesdropping channel. Boardrooms, trading floors, government facilities, and any environment where ultrasonic jammers are deployed for anti-eavesdropping protection should evaluate the fiber optic cables running through their spaces.

Ultrasonic jammers provide false security against fiber eavesdropping. Organizations that rely on commercial ultrasonic jammers to protect sensitive conversations are not protected against fiber-based eavesdropping, creating a dangerous false sense of security.

Dark fibers are the primary attack vector. The unused fibers in FTTH deployments provide the infrastructure for the attack. Organizations should audit how many fibers enter their spaces and whether unused fibers are properly terminated and monitored.

Physical inspection of junction boxes should check for coiled fiber. Security sweeps should include examination of fiber optic junction boxes for unusual fiber winding that could indicate sensory receptors.

This side channel cannot be mitigated with traditional TSCM (Technical Surveillance Countermeasures). Standard bug sweeping equipment detects RF emissions and electronic devices, not passive optical fiber modifications.

Key Takeaways

  • Standard telecom fiber optic cables can be exploited for acoustic eavesdropping by winding fiber around a hollow cylinder sensory receptor
  • Speech recovery achieves over 80% word accuracy at 2 meters using commercial DAS equipment
  • The method is resistant to ultrasonic jammers that defeat all conventional microphones and voice recorders
  • Sensory receptors can be camouflaged inside standard fiber junction boxes, undetectable during routine inspections
  • FTTH deployment creates attack opportunities through unused dark fibers that attackers can connect to sensing equipment
  • Multi-room simultaneous monitoring is possible since every point on the fiber is a sensing point
  • High-security environments relying on TSCM sweeps and ultrasonic jammers should reassess their fiber infrastructure

About the Speaker(s)

Youqian Zhang is a researcher at the Hong Kong Polytechnic University. Collaborators include Junfang Chau and Xiaolu from Hong Kong Polytechnic, Seio Chao from the Chinese University of Hong Kong, and Juan from the Technological and Higher Education Institute of Hong Kong. The research bridges optical fiber sensing technology with security and privacy research.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Turning telecom fiber optic cables into eavesdropping microphones that defeat ultrasonic jammers -- this is intelligence-agency-grade tradecraft published as academic research. The sensory receptor design (fiber wound around a hollow cylinder, hidden in junction boxes) is simple, cheap, and undetectable by standard TSCM sweeps. The ultrasonic jammer resistance is the killer feature: it works precisely where conventional bugs fail.

Heather Calloway (CISO) — MUST SEE

A paradigm-shifting finding that fiber optic cables -- assumed inherently secure -- can be turned into acoustic eavesdropping devices that defeat the ultrasonic jammers used in high-security environments. Any organization with sensitive discussions in spaces with fiber infrastructure needs to reassess their TSCM (Technical Surveillance Countermeasures) program. The dark fiber attack vector in FTTH deployments is particularly concerning.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2026

All talks from Network and Distributed System Security (NDSS) Symposium 2026