A password can be exposed without anyone seeing your screen, watching your fingers or installing a conventional keylogger. Researchers demonstrated that AI keyboard eavesdropping could identify individual laptop keystrokes from audio recordings, reaching 95% accuracy when a nearby smartphone captured the sound and 93% when the keystrokes were recorded through Zoom.
Those figures come from controlled research conditions, not evidence that criminals can effortlessly extract every password from an ordinary video call. Nevertheless, the study shows that the familiar clicking of a keyboard can reveal more information than most people realise, particularly when an attacker can obtain suitable recordings and train a model on the relevant device.
How AI Keyboard Eavesdropping Works
The research, by Joshua Harrison, Ehsan Toreini and Maryam Mehrnezhad, was published in connection with the 2023 IEEE European Symposium on Security and Privacy Workshops. It investigated an acoustic side-channel attack, meaning a technique that extracts information from an unintended signal produced during normal computer use.
When a key is pressed, the sound it creates is influenced by its position, the mechanics of the keyboard and the surrounding device. Individual clicks can appear interchangeable to a listener, but their acoustic properties are not perfectly identical. A machine-learning model can be trained to recognise those differences.
The researchers recorded 36 keys comprising the letters A to Z and digits zero to nine. Each key was pressed 25 times, giving the model labelled examples from which to learn. Recordings were then converted into visual representations of sound called mel-spectrograms, allowing an AI system to distinguish patterns associated with particular keys.
This is an important qualification: the system did not magically identify any password typed on any computer. It classified individual, previously characterised keystrokes under a defined experimental setup. Turning that capability into a real attack would involve additional obstacles, including recording quality, training data and reconstructing the correct sequence.
The Phone Was Only 17 Centimetres Away
The headline 95% result came from a specific arrangement. The researchers used a 2021 16-inch MacBook Pro and placed an iPhone 13 mini approximately 17 centimetres from the laptop. The phone rested on folded microfibre cloth to reduce vibrations travelling through the desk.
Under those conditions, the model correctly classified 95% of individual keystrokes in a 180-sample test set. That is not the same as recovering 95% of complete passwords, and the research did not demonstrate attacks across every laptop, every typing style or every noisy working environment.
Distance matters because a weak or distorted recording makes individual key sounds harder to isolate. Background conversation, room acoustics, the position of a microphone and differences between keyboards can all change what a model receives. A research result obtained with a phone close to a particular laptop should not be presented as a universal real-world success rate.
Even so, the arrangement is not exotic. Phones, laptops and other microphone-equipped devices regularly share the same desk. As LiveAIWire’s reporting on identification using ordinary Wi-Fi signals demonstrates, everyday equipment can sometimes reveal information that users never deliberately intended to transmit.
What This Means for Your Passwords and Video Calls
The second experiment captured typing through a Zoom meeting using the MacBook’s built-in microphones. The researchers set Zoom’s noise suppression to its lowest available setting, recorded the audio and trained a model that identified 93% of individual keystrokes in another 180-sample test set.
This should not be confused with proof that every person attending a meeting can instantly reconstruct your login details. The study involved one participant, a known laptop and carefully prepared training recordings. A malicious listener would still need access to usable audio and enough relevant information to build or apply an appropriate classifier.
However, the practical lesson is straightforward. Typing sensitive information while your microphone is active can expose an acoustic signal. Muting before entering passwords, banking details or confidential information removes that particular transmission route when muting is possible.
The broader issue is familiar from LiveAIWire’s coverage of AI inferring private information from anonymous writing. Information does not have to be explicitly disclosed to become detectable. Sometimes it can be reconstructed from traces that appeared harmless when viewed separately.
Why Noise Suppression Is Helpful but Not a Guarantee
Zoom already provides audio settings designed to reduce background noise. Its official audio configuration guidance identifies noise removal as the standard setting and explains that users can switch between different microphone modes.
The research itself found that Zoom’s noise suppression complicated the separation of individual keystrokes because the volume varied considerably. The researchers nevertheless developed a method to isolate enough sounds for their controlled test, even though suppression could not be completely disabled.
That creates a more nuanced conclusion than either panic or complacency. Noise filtering can make an acoustic attack harder, but it should not be treated as a verified guarantee that no keyboard information can pass through a call.
Audio settings also matter. Modes intended to preserve higher-quality sound for music or professional recording may handle background audio differently from standard speech settings. Anyone working with sensitive material should understand which microphone mode is active rather than assuming every configuration offers the same protection.
This concern sits alongside better-known digital threats such as AI-assisted phishing attacks. The common thread is that security depends not only on whether a password is strong, but also on how the information reaches an attacker.
The Strongest Defence May Be Not Typing a Password
For many accounts, the simplest way to reduce exposure is to avoid manually typing a reusable password whenever possible. The UK’s National Cyber Security Centre now recommends using passkeys instead of passwords where they are available.
Passkeys use device-based authentication, typically involving an existing fingerprint check, facial recognition or device PIN. Because a conventional website password is not typed into the account login form, there is no corresponding password keystroke sequence for an acoustic classifier to reconstruct during that sign-in.
That does not mean every possible sound-based risk disappears. A device PIN may still be entered, and confidential information other than a password can still be typed. The point is narrower: reducing the use of manually entered, reusable passwords removes one particularly valuable target.
Where passkeys are unavailable, the NCSC recommends password managers that create, store and autofill unique credentials. Autofill reduces the need to type a complete password while also helping prevent the reuse of identical credentials across multiple services.
The agency also recommends two-step verification. An extra authentication requirement can reduce the consequences if a password is exposed, although different authentication methods offer different levels of protection and no single measure removes every account-security risk.
What the Study Did Not Prove
The paper did not document a live criminal campaign, a compromised Zoom account or attackers secretly harvesting passwords from routine meetings. It presented a controlled demonstration using a particular MacBook keyboard, known training examples and recordings made under specific conditions.
Its 95% and 93% results describe classification accuracy for individual keys, not the proportion of complete passwords successfully recovered. The experiments also focused on 36 alphanumeric keys rather than every possible character, modifier, correction or typing habit involved in a real login.
That difference becomes more important as a password gets longer. Even a model that recognises most individual keystrokes can make mistakes, and a single error may prevent a complete password from being reconstructed correctly. Additional uncertainty comes from shift keys, symbols, repeated attempts and the difficulty of identifying when sensitive typing begins.
The researchers also describe countermeasures such as changing typing style and adding misleading acoustic signals, but those approaches should not be mistaken for widely deployed, independently verified consumer protections. Their usefulness depends on the particular setup and requires further testing.
The study is therefore a warning about a plausible class of vulnerability, not evidence that everyone on a video call is already under attack. That distinction matters in the same way it matters when considering AI-assisted voice-cloning scams: a technically demonstrated capability becomes a public concern only when the conditions for misuse are understood accurately.
Why Ordinary Sounds Are Becoming Security Data
The deeper change is that machine learning can extract useful patterns from signals people previously treated as background noise. A keyboard click, a fragment of speech or a subtle radio reflection may look unimportant in isolation, yet become meaningful once compared across enough examples.
In April 2026, the NCSC formally strengthened its public position on passkeys, describing them as a more secure and user-friendly alternative to passwords. That advice was not issued specifically because of keyboard acoustics, but it illustrates why moving away from reusable typed credentials reduces several overlapping security risks.
For individuals and businesses, the proportionate response is not to assume every microphone is hostile. It is to mute when entering sensitive information, use passkeys where possible, rely on a reputable password manager, enable additional authentication and think carefully about the ordinary signals that connected devices collect.
The unsettling finding is not that AI has developed supernatural hearing. It is that a keyboard may already be telling a careful listener more than the person using it intended.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
