Power-Related Side-Channel Attacks using the Android Sensor Framework
Mathias Oberhuber, Martin Unterguggenberger, Lukas Maar, Andreas Kogler, Stefan Mangard
Abstract
—Software-based power side-channel attacks are a significant security threat to modern computer systems, enabling adversaries to extract confidential information. Existing attacks typically exploit direct power signals from dedicated interfaces, as demonstrated in the PLATYPUS attack, or power-dependent timing variations, as in the case of the Hertzbleed attack. As access to direct power signals is meanwhile restricted on more and more platforms, an important question is whether other exploitable power-related signals exist beyond timing proxies. In this paper, we show that Android mobile devices expose numerous power-related signals that allow power side-channel attacks. We systematically analyze unprivileged sensors provided by the Android sensor framework on multiple devices and show that these sensors expose parasitic influences of the power consumption. Our results include new insights into Android sensor leakage, particularly a novel leakage primitive: the rotation-dependent power leakage of the geomagnetic rotation vector sensor. We extensively evaluate the exposed sensors for different information leakage types. We compare them with the corresponding ground truth, achieving correlations greater than 0.9 for some of our tested sensors. In extreme cases, we observe not only statistical results but also, e.g., changes in a compass app’s needle by approximately 30° due to CPU stress. Additionally, we evaluate the capabilities of our identified leakage primitives in two case studies: As a remote attacker via the Google Chrome web browser and as a local attacker running inside an installed app. In particular, we present an end-to-end pixel-stealing attack on different Android devices that effectively circumvents the browser’s cross-origin isolation with a leakage rate of 5-10s per pixel. Lastly, we demonstrate a proof-of-concept AES attack, leaking individual key bytes using our newly discovered leakage primitive.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 46977013-bcbe-4ac6-a946-c0d705f03128Cited by top-tier papers4
- Pixnapping: Bringing Pixel Stealing out of the Stone AgeAlan Wang, Pranav Gopalkrishnan, Yingchen Wang, Christopher W. Fletcher et al.CCS 2025 · 1 citation
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- KernelSnitch: Side Channel-Attacks on Kernel Data StructuresLukas Maar, Jonas Juffinger, Thomas Steinbauer, Daniel Gruss et al.NDSS 2025
- Scheduled Disclosure: Turning Power into Timing Without Frequency ScalingInwhan Chun, Isabella Siu, Riccardo PaccagnellaS&P 2025
Builds on14
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz et al.S&P 2021 · 242 citations
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 62 citations
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie et al.USENIX Security 2021 · 42 citations
- On the effectiveness of mitigations against floating-point timing channelsDavid Kohlbrenner, Hovav ShachamUSENIX Security 2017 · 40 citations
Related papers
- Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCsHritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van Schaik et al.USENIX Security 2023
- DVFS Frequently Leaks Secrets: Hertzbleed Attacks Beyond SIKE, Cryptography, and CPU-Only DataYingchen Wang, Riccardo Paccagnella, Alan Wandke, Zhao Gang et al.S&P 2023
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Wireless Charging Power Side-Channel AttacksAlexander S. La Cour, Khurram K. Afridi, G. Edward SuhCCS 2021 · 40 citations
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu et al.ISCA 2026 · 1 citation
