Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity
AuthorsHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang, Yan Long
Resources
The work shows that attackers can inject electromagnetic signals to make hidden audio and sensor data leak from ordinary electronic hardware.
Key results
InjectEave was tested across 11 commercial headphones, a landline, fans, and lamps.
Higher-power equipment recovered intelligible headphone speech at 30 m.
SGMSE increased average SNR from 7.0 dB to 16.1 dB on UGreen MAX2 recordings.
SGMSE improved STOI from 0.58 to 0.72.
Twisted-pair wiring reduced leakage SNR by 10.7 dB.
What the paper found
This paper introduces Injection-Induced EM Side Channels, a threat model in which an attacker injects a radio-frequency carrier and exploits nonlinear hardware—amplifiers, analog-to-digital converters, switching MOSFETs, and power converters—to modulate otherwise difficult-to-leak low-frequency analog secrets onto measurable electromagnetic emissions. The resulting InjectEave system combines a USRP B210, directional antennas, spectrum analysis, and the score-based generative speech-enhancement model SGMSE, trained with synthetic distortions derived from LibriSpeech. Testing across 11 commercial devices, including Sony and Apple headphones, Xiaomi smart appliances, and a Flyingvoice landline, recovered audio, fan activity, lamp brightness, and power-consumption patterns, including through walls. With higher-power equipment, intelligible headphone speech was recovered at 30 m. On UGreen MAX2 headphones, SGMSE increased average SNR from 7.0 dB to 16.1 dB and improved STOI from 0.58 to 0.72, suppressing nonlinear harmonics and carrier noise. The study also demonstrates a closed-loop attack that eavesdrops on a landline conversation, synthesizes a context-aware response with IndexTTS-2, and injects it back into the call. As a mitigation, replacing parallel wiring with twisted-pair wiring reduced leakage SNR by 10.7 dB, although the authors argue that robust protection requires electromagnetic hardening, active carrier detection, and analog-interface security co-design.
Original abstract
Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively. This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage. We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs. Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.
Read the original paperMore in AI Hardware
Browse all 34 papers →AI as a Compiler: Compiling Triton kernels without the Triton compiler
François Costa, Charly Castes, Thomas Bourgeat, Azalia Mirhoseini
An LLM learns to replace parts of the GPU compiler stack by translating Triton code directly into fast, verified PTX kernels.
Purlin: Separating Orchestration from the Datapath of Collectives
Osayamen Jonathan Aimuyo, Swapnil Gandhi, Christos Kozyrakis
Purlin makes GPU collective communication more modular and faster, improving large-scale LLM and diffusion inference across modern hardware.
RESOLVE: Language-Agnostic Validation of GPU Kernels Through Testing, Reduction, and Proof
Ashkan Vedadi Gargary, Guido Martínez, Sebastian Burckhardt, Gabriel Ebner, Abhinav Jangda, Madan Musuvathi, Tyler Sorensen
RESOLVE makes AI-written GPU kernels safer by combining race-finding tests with formal proofs that optimized code still computes the right result.