Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio Receivers
Paul Staat, Daniel Davidovich, Christof Paar
摘要
Extended paper version, including three additional appendices.
Physical isolation from external networks -an airgap -aims to minimize exposure to remote attacks. Yet capable adversaries still achieve code execution on air-gapped systems, and prior work has shown that they can then wirelessly exfiltrate data via unintended emissions. In this work, we demonstrate the reverse direction: malicious code on an embedded device enables wireless infiltration of air-gapped systems, granting attackers command-and-control over compromised targets. Leveraging physical effects previously studied in the context of electromagnetic interference (EMI), we show that parasitic radio frequency (RF) sensitivity in printed circuit board (PCB) traces and on-chip analog-to-digital converters (ADCs) turns commodity embedded devices into inadvertent radio receivers. Unlike prior infiltration techniques, our approach requires no dedicated sensors (e.g., microphones, LEDs, or temperature sensors) and works in non-line-of-sight scenarios. In our evaluation, an ordinary microcontroller evaluation board reliably recovers communication signals from tens of meters at data rates of up to 100 kbps. Applying a systematic methodology to discover such device-intrinsic RF sensitivity, we evaluate twelve commercial embedded devices and two custom prototypes, finding that all exhibit reception capabilities in the 300-1000 MHz range. Our findings challenge the assumption that embedded devices without radios lack an inbound radio paths and call for air-gap threat models that account for both emission-based leakage and unintended reception.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez 等CCS 2019 · 被引用 87 次
- When LoRa Meets EMR: Electromagnetic Covert Channels Can Be Super ResilientCheng Shen, Tian Liu, Jun Huang, Rui TanS&P 2021 · 被引用 50 次
- Noise-SDR: Arbitrary Modulation of Electromagnetic Noise from Unprivileged Software and Its Impact on Emission SecurityGiovanni Camurati, Aurélien FrancillonS&P 2022 · 被引用 12 次
- GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMIQinhong Jiang, Xiaoyu Ji, Chen Yan, Zhixin Xie 等USENIX Security 2023
- DiskSpy: Exploring a Long-Range Covert-Channel Attack via mmWave Sensing of μm-level HDD VibrationsWeiye Xu, Danli Wen, Jianwei Liu, Zixin Lin 等USENIX Security 2025
相关 Paper
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
- TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel ModulationGuoming Zhang, Huiting Zhang, Zhenwei Lu, Heqiang Fu 等USENIX Security 2026
- SpiralSpy: Exploring a Stealthy and Practical Covert Channel to Attack Air-gapped Computing Devices via mmWave SensingZhengxiong Li, Baicheng Chen, Xingyu Chen, Huining Li 等NDSS 2022
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang 等NDSS 2025
- TEMPEST-LoRa: Cross-Technology Covert CommunicationXieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen 等CCS 2025 · 被引用 2 次
