GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards
Qinhong Jiang, Yanze Ren, Yan Long, Chen Yan, Yumai Sun, Xiaoyu Ji, Kevin Fu, Wenyuan Xu
Abstract
Keyboards are the primary peripheral input devices for various critical computer application scenarios. This paper performs a security analysis of the keyboard sensing mechanisms and uncovers a new class of vulnerabilities that can be exploited to induce phantom keys-fake keystrokes injected into keyboards' analog circuits in a contactless way using electromagnetic interference (EMI). Besides regular keystrokes, such phantom keys also include keystrokes that human operators cannot achieve, such as rapidly injecting over 10,000 keys per minute and injecting hidden keys that do not exist on the physical keyboard. The underlying principles of phantom key injections consist in inducing false voltages on keyboard sensing GPIO pins through EMI coupled onto matrix circuits. We investigate the voltage and timing requirements of injection signals both theoretically and empirically to establish the theory of phantom key injection. To validate the threat of keyboard sensing vulnerabilities, we design GhostType that can cause denial-of-service of the keyboard and inject random keystrokes as well as certain targeted keystrokes of the adversary's choice. We have validated GhostType on 48 of 50 off-the-shelf keyboards/keypads from 20 brands, including both membrane/mechanical structures and USB/Bluetooth protocols. Some example consequences of GhostType include completely blocking keyboard operations, crashing and turning off downstream computers, and deleting computer files. Finally, we glean lessons from our investigations and propose countermeasures, including shielding keyboards with metal materials and enhancing the keystroke sensing mechanism.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a0276146-5a62-4149-b191-beb3cd8eb726Cited by top-tier papers8
- From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverXingli Zhang, Yazhou Tu, Yan Long, Liqun Shan et al.S&P 2024 · 6 citations
- RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke InferenceQijun Wang, Chunqi Qian, Huacheng ZengS&P 2026 · 2 citations
- DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity KeyboardsXiaomeng Chen, Jike Wang, Zhenyu Chen, Qi Alfred Chen et al.NDSS 2026 · 1 citation
- GhostTac: Manipulating Tactile Sensors without Physical ContactKun Wang, Xuancun Lu, Ruochen Zhou, Kai Wang et al.CCS 2026
- SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference AttacksQinhong Jiang, Yan Long, Youqian Zhang, Chen Yan et al.USENIX Security 2026
Builds on14
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz et al.CCS 2017 · 98 citations
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez et al.CCS 2019 · 87 citations
- SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityChen Yan, Hocheol Shin, Connor Bolton, Wenyuan Xu et al.S&P 2020 · 86 citations
- SoK: Keylogging Side ChannelsJohn V. MonacoS&P 2018 · 56 citations
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 39 citations
Related papers
- GhostTouch: Targeted Attacks on Touchscreens without Physical TouchKai Wang, Richard Mitev, Chen Yan, Xiaoyu Ji et al.USENIX Security 2022
- Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic DevicesHaoqi Shan, Boyi Zhang, Zihao Zhan, Dean Sullivan et al.S&P 2022 · 17 citations
- I Know Your Keyboard Input: A Robust Keystroke Eavesdropper Based-on Acoustic SignalsJia-Xuan Bai, Bin Liu, Luchuan SongACM MM 2021 · 24 citations
- KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel Gruss, Samuel Weiser et al.NDSS 2018 · 68 citations
- PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDARZizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan et al.NDSS 2025
