Volttack: Control IoT Devices by Manipulating Power Supply Voltage
Kai Wang, Shilin Xiao, Xiaoyu Ji, Chen Yan, Chaohao Li, Wenyuan Xu
Abstract
This paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing and actuating. Particularly, we discover a vulnerability in power supply modules and propose Volttack attacks. To launch a Volttack attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Eventually, Volttack attacks may cause the sensor measurement irrelevant to reality or maneuver the actuator in a way disregarding the desired command. To understand Volttack, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensor or actuator modules. Derived from these findings, we implement and validate Volttack on off-the-shelf products: 6 sensors and 3 actuators, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The consequences of manipulating the sensor measurement or actuation include doubled car braking distance and a natural gas leak. The root cause of such a vulnerability stems from the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9f8919f6-4d22-41eb-9dc2-278761af047bCited by top-tier papers6
- SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band VulnerabilitiesShilin Xiao, Wenjun Zhu, Yan Jiang, Kai Wang et al.NDSS 2026 · 3 citations
- SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference AttacksQinhong Jiang, Yan Long, Youqian Zhang, Chen Yan et al.USENIX Security 2026
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang et al.NDSS 2025
- LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic InterferenceFengchen Yang, Wenze Cui, Xinfeng Li, Chen Yan et al.NDSS 2025
- PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDARZizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan et al.NDSS 2025
Builds on12
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- Fingerprinting Electronic Control Units for Vehicle Intrusion DetectionKyong-Tak Cho, Kang G. ShinUSENIX Security 2016 · 524 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 218 citations
Related papers
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 348 citations
- Understanding and Securing Device Vulnerabilities through Automated Bug Report AnalysisXuan Feng, Xiaojing Liao, XiaoFeng Wang, Haining Wang et al.USENIX Security 2019 · 46 citations
- GhostTac: Manipulating Tactile Sensors without Physical ContactKun Wang, Xuancun Lu, Ruochen Zhou, Kai Wang et al.CCS 2026
- Scalable analysis of interaction threats in IoT systemsMohannad Alhanahnah, Clay Stevens, Hamid BagheriISSTA 2020 · 63 citations
- TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCsJieun Choi, Hae-Yong Yang, Dong-Ho ChoCCS 2020 · 33 citations
