Device Fingerprinting from Passive WiFi Traffic: Can Devices Be Uniquely Identified?

dc.contributor.authorBergström, Miranda
dc.contributor.authorDahl, Ludvig
dc.contributor.authorDetterfelt, Måns
dc.contributor.authorJiang Safady, Rima
dc.contributor.authorStatelova, Monika
dc.contributor.authorOsman Uzel, Seyyid
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerLinde, Arne
dc.contributor.supervisorHashim Changrampadi, Mohamed
dc.date.accessioned2026-08-07T07:51:04Z
dc.date.issued2026
dc.date.submitted
dc.description.abstractWireless devices are widely used in homes, workplaces, and public spaces, making WiFi communication a pervasive part of everyday digital infrastructure. Even when payload encryption and Media-Access Control (MAC) address randomization are enabled, wireless devices can still expose metadata that may support device identification. Such identification could enable social engineering attacks, surveillance, and compromises of personal privacy. To examine this risk, this study investigated whether WiFi devices can be fingerprinted using only passively observed traffic, without decrypting payload content or actively interacting with the network. Data was collected through passive monitoring in a controlled home environment and analyzed using statistical methods, DBSCAN clustering, Uniform Manifold Approximation and Projection (UMAP) dimensionality reduction, and a cluster-based prediction model. The extracted features included probe request structure, vendor specific metadata, timing behavior, RSSI, and power-management indicators. The results show that combinations of passively observable metadata can reveal distinguishable patterns, particularly at the vendor and device-type level. Probe request metadata was the most informative feature category, while RSSI and sleep/wake behavior mainly provided contextual information. However, reliable identification of individual devices remained limited because similar devices often produced overlapping metadata patterns. The findings show that MAC address randomization and encryption reduce direct tracking, but do not fully prevent metadata-based classification or partial device re-identification
dc.identifier.coursecodeDATX11
dc.identifier.urihttps://hdl.handle.net/20.500.12380/312086
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectWiFi, device fingerprinting, security, metadata, passive monitoring, privacy.
dc.titleDevice Fingerprinting from Passive WiFi Traffic: Can Devices Be Uniquely Identified?
dc.type.degreeExamensarbete på kandidatnivåsv
dc.type.degreeBachelor Thesisen
dc.type.uppsokM2
local.programmeInformationsteknik 300 hp (civilingenjör)
local.programmeDatateknik 300 hp (civilingenjör)
local.programmeAutomation och mekatronik 300 hp (civilingenjör)

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 26-12C.pdf
Size:
3.34 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Size:
2.35 KB
Format:
Item-specific license agreed upon to submission
Description: