Noise-SDR: Arbitrary Modulation of Electromagnetic Noise from Unprivileged Software and Its Impact on Emission Security
Giovanni Camurati, Aurélien Francillon
Abstract
Electronic devices generate electromagnetic noise, also known as EM leakage when the noise leaks information. Many recent research papers exploit the fact that software activity can exploit this leakage to generate radio signals. This process breaks the isolation between simple unprivileged code and the radio spectrum, letting an attacker generate physical radio signals without accessing any radio interface. Previous work has discovered many leakage sources and covert communication channels, which generally use simple modulation schemes. However, a fundamental research question has been left unexplored: to which point can attackers shape electromagnetic leakage into signals of their choice? The answer to this question has an important security impact that goes beyond specific attacks or platforms. Indeed, arbitrary signal modulation is a useful primitive. This would allow attackers to use advanced modulations and better exploit the channel (leakage) capacity, for example, to establish advanced communication channels, or to inject malicious signals into victim receivers. At a first analysis, arbitrary modulation seems impossible: software has limited control on the leakage and existing attacks are therefore constrained to on-off keying or frequency-shift keying. In this paper, we demonstrate that shaping arbitrary signals out of electromagnetic noise is possible from unprivileged software. For this we leverage fully-digital radio techniques and call our method Noise-SDR because, similarly to a software-defined radio, it can transmit a generic signal synthesized in software. We demonstrate our approach with a practical implementation with DRAM accesses on ARMv7-A, ARMv8-A, x86-64, and MIPS32. We evaluate it on different types of devices, including smartphones, a laptop, a desktop, and a Linux-based IoT device. Although power, frequency and bandwidth are constrained by the properties of the leakage, we present several case studies, including transmission with advanced protocols, device tracking, and signal injection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 03436cf8-f8d0-45a0-a8c9-1069661fb37cCited by top-tier papers3
- TEMPEST-LoRa: Cross-Technology Covert CommunicationXieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen et al.CCS 2025 · 2 citations
- Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio ReceiversPaul Staat, Daniel Davidovich, Christof PaarCCS 2026
- TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel ModulationGuoming Zhang, Huiting Zhang, Zhenwei Lu, Heqiang Fu et al.USENIX Security 2026
Builds on12
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes et al.CCS 2018 · 186 citations
- Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPUPietro Frigo, Cristiano Giuffrida, Herbert Bos, Kaveh RazaviS&P 2018 · 178 citations
Related papers
- Wireless Signal Injection Attacks on VSAT Satellite ModemsRobin Bisping, Johannes Willbold, Martin Strohmeier, Vincent LendersUSENIX Security 2024 · 11 citations
- TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCsJieun Choi, Hae-Yong Yang, Dong-Ho ChoCCS 2020 · 33 citations
- Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware NonlinearityHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang et al.USENIX Security 2026
- SDR receiver using commodity wifi via physical-layer signal reconstructionWoojae Jeong, Jinhwan Jung, Yuanda Wang, Shuai Wang et al.MobiCom 2020 · 27 citations
- Screen Gleaning: A Screen Reading TEMPEST Attack on Mobile Devices Exploiting an Electromagnetic Side ChannelZhuoran Liu, Niels Samwel, Leo Weissbart, Zhengyu Zhao et al.NDSS 2021
