Source-linked AI summary
Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity
Haoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang, Yan Long
TL;DR
Passive EM side-channel analysis has limited access to low-frequency analog secrets because their frequencies may not efficiently radiate. This paper introduces Injection-Induced EM Side Channels, using active carriers and hardware nonlinearity to induce measurable leakage. InjectEave demonstrates leakage from household devices, including intelligible headphone audio at up to 30 m and through-wall scenarios.
Problem
Passive EM side-channel analysis is limited for low-frequency analog secrets because their frequencies and amplitudes may not couple efficiently into measurable external emissions.
Method
The paper models and measures how nonlinear hardware modulates analog secrets onto injected EM carriers, then implements the InjectEave eavesdropping design.
Results
The evaluation of 11 commercial devices demonstrates injection-induced leakage of audio, control signals, and power traces, including intelligible headphone audio at up to 30 m and through walls.
Takeaways & Limitations
Injection-induced EM side channels expose a broad confidentiality threat at analog interfaces and motivate integrated analysis of EM injection and side-channel leakage.
Takeaways & Limitations
The evaluation focuses on common audio-output devices and smart-home applications, while broader target classes such as internal communication signals and analog sensor inputs remain future work.
Abstract
from arXiv · showhide
Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively. This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage. We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs. Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.
1 Introduction
The paper reframes active EM injection as a way to induce and control side-channel leakage from low-frequency analog secrets. Its framework, modeling, and InjectEave evaluation show leakage across household devices, including through-wall and 30 m eavesdropping scenarios.
- Motivation: Existing passive EM side-channel analysis is limited for low-frequency analog secrets because internal signal frequencies often mismatch efficient EM coupling bands.The limitation also reflects low operating voltages and stronger shielding in modern electronics.
- Core insight: Nonlinear hardware can modulate internal analog secrets onto injected EM carriers, converting them into secret-bearing emissions.The framework connects active injection with side-channel leakage rather than treating injection only as an integrity attack.
- Core insight: Theoretical modeling and measurements identify amplifiers, analog-to-digital converters, power converters, and switching MOSFETs as relevant nonlinear hardware components.These components provide the physical basis for reshaping the effective leakage spectrum.
- Evaluation: 30 m is the maximum reported distance for recovering intelligible headphone audio, while most evaluated devices were vulnerable from over 2 m away and through walls.The evaluation covered 11 commercial off-the-shelf household devices.
- Attack design: InjectEave combines active EM injection and leakage reception to demonstrate eavesdropping on low-frequency analog secrets, including speech audio and smart-home activity signals.The attack design is presented as an example of the newly characterized vulnerability.
- Evaluation: The paper characterizes the threat across 11 commercial devices and discusses mitigation approaches for stronger EM security protection.Its stated scope includes analog interfaces carrying audio, actuator controls, and device power traces.
2 Background
Conventional EM side channels passively observe hardware emissions, but frequency mismatch limits access to low-frequency analog signals. EM injection exploits nonlinear hardware to place such secrets onto efficient carrier frequencies, creating a leakage channel for confidentiality attacks.
- Conventional EM side channel: A conventional EM side channel models secret voltage leakage as Veav(t) = htx(Vsec(t)), where htx represents the leakage source and propagation transfer function.The channel is an unintended one-way communication path from the device to the eavesdropper.
- Conventional EM side channel: Efficient EM coupling bands often mismatch the frequencies of low-frequency secrets, limiting the measurable leakage available to passive eavesdroppers.Human speech occupies 20 Hz–20 kHz, whereas many unintentional antenna structures operate efficiently at frequencies on the order of MHz.
- Conventional EM side channel: EM side-channel leakage has therefore remained primarily demonstrated for high-voltage digital transmissions, leaving low-frequency analog secrets less accessible.Examples include computer display images and keyboard inputs transmitted over USB cables.
- EM injection: EM injection physically introduces false analog signals by exploiting nonlinear hardware to bridge malicious-signal frequencies and effective injection bands.Prior work used amplitude-modulated carriers to inject kHz-range fake speech into microphone readings.
- EM injection: This paper extends EM injection from compromising data integrity to inducing side-channel leakage by having hardware nonlinearity modulate secrets onto EM carriers.The resulting perspective targets confidentiality attacks against low-frequency analog information.
3 Injection-Induced EM Side Channel
The paper models injection-induced EM side channels as secret-signal modulation onto an injected carrier through nonlinear hardware, enabling controllable upconversion and leakage of otherwise difficult-to-observe analog signals. Experiments show amplification benefits across common nonlinear components, while higher-order inter-modulation distorts wideband secrets and motivates InjectEave.
- Threat model: The threat model assumes an adversary injects and receives EM signals to infer low-frequency analog secrets such as audio, power consumption, and actuation controls.The added capability over conventional EM eavesdropping is active injection using commercial RF equipment.
- Injection-Modulation-Emission model: Nonlinear hardware mixes secret signals with an injected carrier, modulating secret information onto sidebands that can propagate through conductive paths and radiate externally.The cross-product term from the nonlinear response provides the modulation mechanism, while device paths act as unintended transmitting antennas.
- Leakage modeling: Tuning the carrier frequency to maximize |Htx(fc)Hrx(fc)| and increasing injection amplitude can amplify leakage even when secrets are weak and far below efficient emission frequencies.The modeled leakage amplitude depends on secret-signal and injection strengths, with the dominant second-order term producing the controllable signal component.
- Susceptibility of common nonlinear electronics: Across four nonlinear hardware types, passive sweeps showed no discernible secret-correlated leakage, whereas replacing nonlinear components with linear loads also removed injection-induced leakage.The tested component classes included amplifiers, ADCs, switching MOSFETs, and power converters.
- Susceptibility of common nonlinear electronics: Power-converter measurements exposed a 50 Hz mains secret and harmonics such as 100 Hz and 150 Hz, illustrating leakage of low-frequency analog information under injection.The power-consumption trace is represented by the AC mains voltage at 50 Hz.
- Leakage characteristics and InjectEave: Higher-order inter-modulation creates harmonics that can overlap wideband components, degrading complex secrets such as speech; InjectEave therefore targets higher-fidelity recovery with diffusion-based denoising.The design uses training data simulated from the quantitative model, and enhanced audio improves standard quality metrics and intelligibility.
4 Evaluation in a Laboratory Setting
Laboratory evaluations across 11 commercial devices show that InjectEave can recover audio and infer smart-home activity through injection-induced leakage, with performance shaped by device hardware, distance, orientation, and barriers.
- Evaluation scope: 11 commercial devices across headphones, a landline, smart fans, and smart lamps were evaluated for high-fidelity audio recovery and human-activity inference.The study used five device categories and treated audio peripherals as speech-eavesdropping surfaces, while smart-home states exposed presence and behavioral patterns.
- Audio peripherals: Near-100% recognition was achieved across tested wired and wireless audio devices at 50 cm, with device-specific injection-sensitive frequency ranges.The Sony wired-headphone setup retained effective ranges of 5 m and 4 m in two host configurations, while Apple Earbuds reached 1 m with 5.9 dB SNR.
- Audio peripherals: 23.1 dB SNR, 100% recognition, and 6 m range were achieved on the UGreen MAX2 wireless headphones; PHILIPS also reached 100% recognition and 6 m.The HP H231R achieved 29/30 recognition with a 4 m distance, and through-wall validation was conducted separately.
- Audio enhancement: 7.0 dB to 16.1 dB average SNR improvement was obtained by applying the audio enhancement model to UGreen MAX2 recordings.The evaluation used two minutes of speech recorded at 50 cm and 65 dB volume, measuring both SNR and STOI.
- Profile transferability: 100% cross-device profiling attacks succeeded on three UGreen MAX2 headphones, with transferred leakage SNRs of 23.2–24.6 dB and 0.8–2.9% relative deviation.The same profiled 942 MHz carrier frequency was reused without re-profiling the other devices.
- Human-activity inference: Smart-device leakage exposed operational states and household activity through motor-driven fan modulation and power-converter modulation in lamps.The OIDIRE fan reached 38.6 dB SNR and 6 m recognition, while the Xiaomi 1S lamp reached 21.6 dB SNR; the fan maintained 100% ASR across tested conditions.
- Environmental impact: Glass and wood caused only 1–2 dB attenuation, while concrete caused 5.8 dB for headphones and approximately 2.5 dB for fans and lamps.These measurements indicate that common barriers had limited influence on leakage SNR in the tested non-line-of-sight settings.
5 Audio Eavesdropping in the Wild
InjectEave extends injection-induced EM leakage to realistic audio eavesdropping, including through-wall and long-distance scenarios. The attack remains effective under lower playback volumes and environmental interference, while supporting closed-loop speech manipulation.
- Real-World Audio Eavesdropping: InjectEave recovers intelligible speech through a 30 cm concrete wall in hotel-room and meeting-room scenarios.The attacks target wireless headphones during confidential video calls from an adjacent room.
- Real-World Audio Eavesdropping: The eavesdropped spectrogram retains speech harmonics despite wall attenuation, and enhancement sharpens them while suppressing interference.The case study recovers a detailed personal agenda from the victim’s speech.
- Robustness Evaluation: At 65 dB playback, InjectEave recovers speech with approximately 10 dB SNR and roughly 22% WER.The attack remains effective at a volume associated with private business conversations.
- Robustness Evaluation: Frequency and spatial selectivity help preserve attack performance amid nearby electronics and ambient RF interference.Carrier tuning targets the victim device, while antenna realignment can provide spatial selectivity when device responses overlap.
- Stealthiness: The injected carrier produces little audible distortion, with STOI deviation averaging 0.008 under an aggressive 18 dBm near-field test.Single-frequency carriers are filtered by analog front-ends, preserving stealthiness.
- Extended Threats: An extended setup reaches up to 30 m, while a landline-phone case enables eavesdropping, speech synthesis, and reinjection.The closed-loop chain uses recovered speech as a speaker reference and triggers identity-specific responses.
6 Discussion
The discussion frames the work as a foundation for characterizing injection-induced EM threats and expanding evaluation to broader analog interfaces. It also argues that conventional analog protection and physical hardening remain incomplete.
- Limitations and Future Work: The work presents theoretical framework and exemplary designs rather than a complete characterization of all injection-induced EM threats.The authors identify follow-up research on additional susceptible interfaces and protections.
- Attack Surface Generalizability: The evaluated attack surface centers on audio devices and smart-home applications, while broader unshielded nonlinear analog interfaces remain future targets.Candidate extensions include internal electrical communication signals and analog sensor inputs.
- Range Boundary: The current range boundary is set by injection and receiving hardware, with dmax ∝ |Vinj|·|Vsec|/Nsys.Higher-gain antennas and lower-noise spectrum analyzers could mitigate this hardware-dependent constraint.
- Mitigation: Cryptographic masking and randomized clocking are mostly ineffective for analog interfaces because masking continuous waveforms can degrade signal fidelity and device integrity.The authors call for research on analog protection and utility-security tradeoffs.
- Mitigation: EMC hardening can attenuate coupling but does not guarantee security against higher-power injection, motivating active detection and mitigation.Suggested directions include anomalous-carrier monitoring, DC-offset detection, sensor fusion, and encoding.
- Hardware Mitigation: Twisted-pair wiring showed greater attack resistance than standard parallel wiring in teardown analysis and proof-of-concept evaluation.The comparison used the same USB speaker and operating frequency while changing the cable connection.
7 Related Work
Related work has largely separated active EM injection from passive EM side-channel leakage. InjectEave connects them through hardware nonlinearity and differs from reflection-based sensing and prior leakage-amplification approaches.
- EM Injection and Side-Channel Leakage: Prior EM research generally treats injection as an integrity or availability threat and side-channel leakage as a passive confidentiality threat.This separation leaves the combined attack model underexplored.
- EM Injection and Side-Channel Leakage: InjectEave uses hardware nonlinearity to induce secret-bearing emissions from injected carriers, enabling closed-loop eavesdropping and control.The framework reframes the boundary between active injection and passive confidentiality attacks.
- Comparison with Prior EM Leakage: InjectEave reaches over 30 m, whereas cited passive EM side channels such as MagEar and Periscope are restricted to 0.5–1.5 m.The comparison is presented as evidence of expanded eavesdropping capability.
- Comparison with Prior EM Leakage: Unlike DeHiREC, which amplifies existing ADC leakage, InjectEave induces new controllable signals through hardware nonlinearity.The distinction separates amplification of existing leakage from modulation of low-frequency analog secrets onto injected carriers.
- Contactless Sensing and Backscattering: Backscattering work commonly relies on intentional or preliminary impedance modulation, whereas InjectEave studies unintentional nonlinear modulation in commodity hardware.This places the framework adjacent to, but distinct from, backscattering-based sensing.
8 Conclusion
The paper introduces Injection-Induced EM Side Channels as a framework for exploiting commodity hardware nonlinearity to expose low-frequency analog secrets. Evaluation across 11 commercial devices indicates a widespread vulnerability and motivates analog-interface protections.
- Conclusion: The framework bridges conventional side-channel analysis and active EM injection by modulating low-frequency analog secrets onto injected carriers.The result is a threat model for secrets that are otherwise inefficiently emitted.
- Conclusion: Evaluation of 11 commercial devices indicates that injection-induced leakage affects a broad range of commodity analog interfaces.The conclusion identifies analog interfaces as an overlooked protection target.
Ethical Considerations
The authors describe controlled, safety-conscious experimentation and publication choices intended to reduce privacy and security risks while informing defenders. They withhold sensitive attack details and report twisted-pair wiring as a practical countermeasure.
- Potential Impact: The work highlights privacy risks for home activities and private conversations, while identifying manufacturers, end users, and defenders as key stakeholders.The authors suggest manufacturers may need stronger shielding or differential signaling and that users need greater EM-security awareness.
- Research Conduct: Experiments used author-controlled devices, synthesized conversations, and cleared settings to avoid targeting private communications or non-consenting systems.Through-wall and hotel-room scenarios were conducted under controlled conditions.
- Risk Mitigation: The authors withhold vulnerable injection frequencies and active injection-control logic from public artifacts because manufacturers had not yet responded.Access to this security-sensitive information is restricted to trusted researchers upon request.
- Risk Mitigation: Twisted-pair wiring is presented as a practical defense because it suppresses induced surface currents.This mitigation is reported alongside the decision to restrict sensitive attack details.
- Publication Rationale: The authors justify publication by arguing that assuming low-frequency signals are safe from EM leakage creates a false sense of security.They frame disclosure as necessary for manufacturers and defenders while removing detailed attack parameters.
Open Science
The authors provide public access to demonstration materials, case-study recordings, and speech-enhancement code through a project website and Zenodo.
- Public Materials: Demo videos and case-study audio recordings are available on the project website.The website is listed as https://injecteave.github.io/.
- Public Materials: Research artifacts, including received case-study audio recordings and the speech-enhancement codebase, are available through Zenodo.The repository is identified by DOI 10.5281/zenodo.20432240.