When LoRa Meets EMR: Electromagnetic Covert Channels Can Be Super Resilient
Cheng Shen, Tian Liu, Jun Huang, Rui Tan
Abstract
Due to the low power of electromagnetic radiation (EMR), EM convert channel has been widely considered as a short-range attack that can be easily mitigated by shielding. This paper overturns this common belief by demonstrating how covert EM signals leaked from typical laptops, desktops and servers are decoded from hundreds of meters away, or penetrate aggressive shield previously considered as sufficient to ensure emission security. We achieve this by designing EMLoRa – a super resilient EM covert channel that exploits memory as a LoRa-like radio. EMLoRa represents the first attempt of designing an EM covert channel using state-of-the-art spread spectrum technology. It tackles a set of unique challenges, such as handling complex spectral characteristics of EMR, tolerating signal distortions caused by CPU contention, and preventing adversarial detectors from demodulating covert signals. Experiment results show that EMLoRa boosts communication range by 20x and improves attenuation resilience by up to 53 dB when compared with prior EM covert channels at the same bit rate. By achieving this, EMLoRa allows an attacker to circumvent security perimeter, breach Faraday cage, and localize air-gapped devices in a wide area using just a small number of inexpensive sensors. To countermeasure EMLoRa, we further explore the feasibility of uncovering EMLoRa's signal using energy- and CNN-based detectors. Experiments show that both detectors suffer limited range, allowing EMLoRa to gain a significant range advantage. Our results call for further research on the countermeasure against spread spectrum-based EM covert channels.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers10
- Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your NeighborsZihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao et al.S&P 2022 · 41 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Noise-SDR: Arbitrary Modulation of Electromagnetic Noise from Unprivileged Software and Its Impact on Emission SecurityGiovanni Camurati, Aurélien FrancillonS&P 2022 · 12 citations
- Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-ChannelRui Xiao, Sibo Feng, Soundarya Ramesh, Jun Han et al.NDSS 2026 · 3 citations
- GPSBuster: Busting out Hidden GPS Trackers via MSoC Electromagnetic RadiationsYue Li, Zhenxiong Yan, Wenqiang Jin, Zhenyu Ning et al.CCS 2024 · 2 citations
Related papers
- TEMPEST-LoRa: Cross-Technology Covert CommunicationXieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen et al.CCS 2025 · 2 citations
- MagView: A Distributed Magnetic Covert Channel via Video Encoding and DecodingJuchuan Zhang, Xiaoyu Ji, Wenyuan Xu, Yi-Chao Chen et al.INFOCOM 2020 · 14 citations
- Electromagnetic Fingerprinting of Memory Heartbeats: System and ApplicationsCheng Shen, Jun Huang, Guangyu Sun, Jingshu ChenUbiComp 2022 · 6 citations
- A New Side-Channel Vulnerability on Modern Computers by Exploiting Electromagnetic Emanations from the Power Management UnitNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 37 citations
- TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel ModulationGuoming Zhang, Huiting Zhang, Zhenwei Lu, Heqiang Fu et al.USENIX Security 2026
