Privacy in Workplace Wearables: Machine Learning-Enabled Privacy Risks, Adversarial Threat Modeling, and Cybersecurity Countermeasures
Authors: Aryan Javed, Sher Ali, Aoun Muhammad, Sana Tariq
Abstract
Workplace wearable devices such as smartwatches, fitness trackers, EDA sensors, IMUs, and EMG wristbands continuously collect biometric data from employees. This data includes heart rate, body movements, skin responses, and daily activity patterns. The collected information helps organizations monitor employee health, activity levels, and overall well-being using machine learning (ML) algorithms that identify unusual activities, predict employee fatigue, and estimate mental workload with a high level of accuracy. However, these devices also create security and privacy challenges: sensitive biometric data can be exposed to data breaches, unauthorized access, excessive monitoring, and other security risks. From a cybersecurity perspective, these devices use Bluetooth Low Energy (BLE) communication, which is susceptible to security weaknesses including CVE-class spoofing, passive advertisement eavesdropping, and Man-in-the-Middle (MITM) attacks. This paper proposes a multilayer threat taxonomy spanning protocol, model, and governance layers, benchmarks five ML architectures on the WESAD multivariate physiological sensor dataset, and evaluates adversarial robustness under L∞-bounded perturbations. Experimental results demonstrate that a two-layer stacked LSTM with attention mechanism achieves 97.68%±0.31% classification accuracy and 0.989 AUC-ROC across five independent runs.
