Please use this identifier to cite or link to this item: http://hdl.handle.net/10397/120545
PIRA download icon_1.1View/Download Full Text
DC FieldValueLanguage
dc.contributorDepartment of Computingen_US
dc.creatorYan, Hen_US
dc.creatorShao, Zen_US
dc.creatorZhang, Sen_US
dc.creatorJiang, Qen_US
dc.creatorLong, Yen_US
dc.date.accessioned2026-08-18T08:43:42Z-
dc.date.available2026-08-18T08:43:42Z-
dc.identifier.isbn978-1-939133-58-8en_US
dc.identifier.urihttp://hdl.handle.net/10397/120545-
dc.description35th USENIX Security Symposium, August 12-14, 2026, Baltimore, MD, USAen_US
dc.language.isoenen_US
dc.publisherUSENIX Associationen_US
dc.rightsPosted with the permission of the author.en_US
dc.titleInjected and leaked : actively inducing side-channel leakage using electromagnetic injection and hardware nonlinearityen_US
dc.typeConference Paperen_US
dc.identifier.spage2485en_US
dc.identifier.epage2504en_US
dcterms.abstractElectromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively. This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage. We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30~m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs. Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.en_US
dcterms.accessRightsopen accessen_US
dcterms.bibliographicCitationIn Proceedings of the 35th USENIX Security Symposium: August 12-14, 2026, Baltimore, MD, USA, p. 2485-2504en_US
dcterms.issued2026-
dc.relation.ispartofbookProceedings of the 35th USENIX Security Symposium: August 12-14, 2026, Baltimore, MD, USAen_US
dc.description.validate202608 bcchen_US
dc.description.oaVersion of Recorden_US
dc.identifier.FolderNumbera4605-
dc.identifier.SubFormID53313-
dc.description.fundingSourceOthersen_US
dc.description.fundingTextThis work was supported in part by Guangdong Provincial Key Lab of Integrated Communication, Sensing, and Computation for Ubiquitous Internet of Things (No. 2023B1212010007).en_US
dc.description.pubStatusPublisheden_US
dc.description.oaCategoryCopyright retained by authoren_US
Appears in Collections:Conference Paper
Files in This Item:
File Description SizeFormat 
usenixsecurity26-yan-haoran.pdf11 MBAdobe PDFView/Open
Open Access Information
Status open access
File Version Version of Record
Access
View full-text via PolyU eLinks SFX Query
Show simple item record

Google ScholarTM

Check


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.