Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio Receivers
Paul Staat, Daniel Davidovich, Christof Paar
Abstract
Extended paper version, including three additional appendices.
Physical isolation from external networks -an airgap -aims to minimize exposure to remote attacks. Yet capable adversaries still achieve code execution on air-gapped systems, and prior work has shown that they can then wirelessly exfiltrate data via unintended emissions. In this work, we demonstrate the reverse direction: malicious code on an embedded device enables wireless infiltration of air-gapped systems, granting attackers command-and-control over compromised targets. Leveraging physical effects previously studied in the context of electromagnetic interference (EMI), we show that parasitic radio frequency (RF) sensitivity in printed circuit board (PCB) traces and on-chip analog-to-digital converters (ADCs) turns commodity embedded devices into inadvertent radio receivers. Unlike prior infiltration techniques, our approach requires no dedicated sensors (e.g., microphones, LEDs, or temperature sensors) and works in non-line-of-sight scenarios. In our evaluation, an ordinary microcontroller evaluation board reliably recovers communication signals from tens of meters at data rates of up to 100 kbps. Applying a systematic methodology to discover such device-intrinsic RF sensitivity, we evaluate twelve commercial embedded devices and two custom prototypes, finding that all exhibit reception capabilities in the 300-1000 MHz range. Our findings challenge the assumption that embedded devices without radios lack an inbound radio paths and call for air-gap threat models that account for both emission-based leakage and unintended reception.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 20d8a3a5-6009-4b4c-950f-c761df8b56dbBuilds on13
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez et al.CCS 2019 · 87 citations
- When LoRa Meets EMR: Electromagnetic Covert Channels Can Be Super ResilientCheng Shen, Tian Liu, Jun Huang, Rui TanS&P 2021 · 50 citations
- Noise-SDR: Arbitrary Modulation of Electromagnetic Noise from Unprivileged Software and Its Impact on Emission SecurityGiovanni Camurati, Aurélien FrancillonS&P 2022 · 12 citations
- GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMIQinhong Jiang, Xiaoyu Ji, Chen Yan, Zhixin Xie et al.USENIX Security 2023
- DiskSpy: Exploring a Long-Range Covert-Channel Attack via mmWave Sensing of μm-level HDD VibrationsWeiye Xu, Danli Wen, Jianwei Liu, Zixin Lin et al.USENIX Security 2025
Related papers
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
- TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel ModulationGuoming Zhang, Huiting Zhang, Zhenwei Lu, Heqiang Fu et al.USENIX Security 2026
- SpiralSpy: Exploring a Stealthy and Practical Covert Channel to Attack Air-gapped Computing Devices via mmWave SensingZhengxiong Li, Baicheng Chen, Xingyu Chen, Huining Li et al.NDSS 2022
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang et al.NDSS 2025
- TEMPEST-LoRa: Cross-Technology Covert CommunicationXieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen et al.CCS 2025 · 2 citations
