USENIX Security2022Top-tier venue
Lend Me Your Ear: Passive Remote Physical Side Channels on PCs
Daniel Genkin, Noam Nissan, Roei Schuster, Eran Tromer
Abstract
We show that built-in sensors in commodity PCs, such as microphones, inadvertently capture electromagnetic sidechannel leakage from ongoing computation. Moreover, this information is often conveyed by supposedly-benign channels such as audio recordings and common Voice-over-IP applications, even after lossy compression.
Thus, we show, it is possible to conduct physical sidechannel attacks on computation by remote and purely passive analysis of commonly-shared channels. These attacks require neither physical proximity (which could be mitigated by distance and shielding), nor the ability to run code on the target or configure its hardware. Consequently, we argue, physical side channels on PCs can no longer be excluded from remoteattack threat models.
We analyze the computation-dependent leakage captured by internal microphones, and empirically demonstrate its efficacy for attacks. In one scenario, an attacker steals the secret ECDSA signing keys of the counterparty in a voice call. In another, the attacker detects what web page their counterparty is loading. In the third scenario, a player in the Counter-Strike online multiplayer game can detect a hidden opponent waiting in ambush, by analyzing how the 3D rendering done by the opponent's computer induces faint but detectable signals into the opponent's audio feed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6fda66a7-6dd0-45aa-b505-c028b2cd29e1Cited by top-tier papers7
- Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelTao Ni, Xiaokuan Zhang, Qingchuan ZhaoCCS 2023 · 34 citations
- HammerScope: Observing DRAM Power Consumption Using RowhammerYaakov Cohen, Kevin Sam Tharayil, Arie Haenel, Daniel Genkin et al.CCS 2022 · 24 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- SpectrEM: Exploiting Electromagnetic Emanations During Transient ExecutionJesse De Meulemeester, Antoon Purnal, Lennert Wouters, Arthur Beckers et al.USENIX Security 2023
- Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel AttacksHongyue Jin, Yanan Guo, Zhenkai ZhangNDSS 2026
Builds on18
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
Related papers
- Sound of Interference: Electromagnetic Eavesdropping Attack on Digital Microphones Using Pulse Density ModulationArifu Onishi, S. Hrushikesh Bhupathiraju, Rishikesh Bhatt, Sara Rampazzi et al.USENIX Security 2025
- Synesthesia: Detecting Screen Content via Remote Acoustic Side ChannelsDaniel Genkin, Mihir Pattani, Roei Schuster, Eran TromerS&P 2019 · 63 citations
- A New Side-Channel Vulnerability on Modern Computers by Exploiting Electromagnetic Emanations from the Power Management UnitNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 37 citations
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
- Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio ReceiversPaul Staat, Daniel Davidovich, Christof PaarCCS 2026
