TickTock: Detecting Microphone Status in Laptops Leveraging Electromagnetic Leakage of Clock Signals
Soundarya Ramesh, Ghozali Suhariyanto Hadi, Sihun Yang, Mun Choon Chan, Jun Han
Abstract
We are witnessing a heightened surge in remote privacy attacks on laptop computers. These attacks often exploit malware to remotely gain access to webcams and microphones in order to spy on the victim users. While webcam attacks are somewhat defended with widely available commercial webcam privacy covers, unfortunately, there are no adequate solutions to thwart the attacks on mics despite recent industry efforts. As a first step towards defending against such attacks on laptop mics, we propose TickTock, a novel mic on/off status detection system. To achieve this, TickTock externally probes the electromagnetic (EM) emanations that stem from the connectors and cables of the laptop circuitry carrying mic clock signals. This is possible because the mic clock signals are only input during the mic recording state, causing resulting emanations. We design and implement a proof-of-concept system to demonstrate TickTock's feasibility. Furthermore, we comprehensively evaluate TickTock on a total of 30 popular laptops executing a variety of applications to successfully detect mic status in 27 laptops. Of these, TickTock consistently identifies mic recording with high true positive and negative rates. * This is an extended version of the conference paper in the proceedings of ACM CCS 2022 with the same title. Lenovo Outlet Laptops shipped together with TickTock TickTock Server … Identified Mic Clock Freq Sticker Marking Leakage Location (a) (b) (c) (d) … … … 2 MHz 2 MHz … 2 MHz 2 MHz 3 MHz Figure 3: Bootstrapping scenarios -(a) depicts bootstrapping performed by laptop manufacturers, e.g., Lenovo, who subsequently ship laptops with stickers denoting leakage location, 𝑙 mic , and an accompanying TickTock device set to detect mic clock frequency, 𝑓 mic . (b) depicts a crowd-sourcing scenario where users upload 𝑓 mic , along with an image of 𝑙 mic to TickTock's public server. (c) depicts a scenario where a user locally performs bootstrapping. (d) depicts a deployment scenario, where a user deploys TickTock to detect mic on/off status by placing the TickTock device at the location of the sticker, and by setting the TickTock device to detect 𝑓 mic .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f446d89c-a29d-4f50-9dce-938aa83420f5Cited by top-tier papers5
- MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage SignalsRui Xiao, Tianyu Li, Soundarya Ramesh, Jun Han et al.MobiCom 2023 · 20 citations
- Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-ChannelRui Xiao, Sibo Feng, Soundarya Ramesh, Jun Han et al.NDSS 2026 · 3 citations
- SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band VulnerabilitiesShilin Xiao, Wenjun Zhu, Yan Jiang, Kai Wang et al.NDSS 2026 · 3 citations
- GPSBuster: Busting out Hidden GPS Trackers via MSoC Electromagnetic RadiationsYue Li, Zhenxiong Yan, Wenqiang Jin, Zhenyu Ning et al.CCS 2024 · 2 citations
- Sound of Interference: Electromagnetic Eavesdropping Attack on Digital Microphones Using Pulse Density ModulationArifu Onishi, S. Hrushikesh Bhupathiraju, Rishikesh Bhatt, Sara Rampazzi et al.USENIX Security 2025
Builds on7
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes et al.CCS 2018 · 186 citations
- Wearable Microphone JammingYuxin Chen, Huiying Li, Shan-Yuan Teng, Steven Nagels et al.CHI 2020 · 62 citations
- USB Snooping Made Easy: Crosstalk Leakage Attacks on USB HubsYang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval YaromUSENIX Security 2017 · 41 citations
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 34 citations
- TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCsJieun Choi, Hae-Yong Yang, Dong-Ho ChoCCS 2020 · 33 citations
Related papers
- Sniffing Location Privacy of Video Conference Users Using Free Audio ChannelsLong Huang, Chen WangS&P 2025
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
- mmEcho: A mmWave-based Acoustic Eavesdropping MethodPengfei Hu, Wenhao Li, Riccardo Spolaor, Xiuzhen ChengS&P 2023
- DeHiREC: Detecting Hidden Voice Recorders via ADC Electromagnetic RadiationRuochen Zhou, Xiaoyu Ji, Chen Yan, Yi-Chao Chen et al.S&P 2023
- LAM-assisted Acoustic Eavesdropping in Multi-speaker Scenarios via Commercial mmWave RadarGuodong Liu, Lei Wang, Minjun Jiang, Qianran Qiao et al.UbiComp 2026
