XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice Injection
Tao Ni, Yongliang Chen, Weitao Xu, Lei Xue, Qingchuan Zhao
摘要
Multi-port chargers, capable of simultaneously charging multiple mobile devices such as smartphones, have gained immense popularity and sold millions of units in recent years. However, this charging-targeted feature can also pose security and privacy risks by allowing one of the simultaneously charging devices to communicate with another one if not properly designed and implemented as these devices are actually interconnected. Unfortunately, such risks have not been thoroughly investigated and we have identified a novel attack surface in the circuit design of multi-port chargers, which allows an adversary to exploit one port to (𝑖) eavesdrop on the activities of other devices being charged and (𝑖𝑖) inaudibly inject malicious audio commands if the charging device supports voice assistants and USB-C interface.
In this paper, we design and implement a novel framework, XPorter, to analyze and demonstrate the uncovered security and privacy threats in multi-port chargers. Specifically, it leverages the changes in the voltage signals on one neighbor port to monitor the voltage changes of the charging port induced by various user activities, including recognizing the running apps and uncovering keystrokes. Moreover, XPorter can also achieve inaudible audio injection attacks The corresponding author.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- MicGuard: A Comprehensive Detection System against Out-of-band Injection Attacks for Different Level Microphone-based DevicesTiantian Liu, Feng Lin, Zhongjie Ba, Li Lu 等USENIX Security 2024 · 被引用 4 次
- CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View PerceptionSenkang Hu, Yihang Tao, Guowen Xu, Yiqin Deng 等AAAI 2025 · 被引用 1 次
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- HubBub: Contention-Based Side-Channel Attacks on USB HubsJunpeng Wan, Yanxiang Bi, Han Gao, Dave (Jing) TianUSENIX Security 2025
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao 等WWW 2026
它引用的顶会 Paper13
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang 等CCS 2017 · 被引用 753 次
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 被引用 62 次
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey 等S&P 2018 · 被引用 52 次
- USB Snooping Made Easy: Crosstalk Leakage Attacks on USB HubsYang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval YaromUSENIX Security 2017 · 被引用 41 次
- Wireless Charging Power Side-Channel AttacksAlexander S. La Cour, Khurram K. Afridi, G. Edward SuhCCS 2021 · 被引用 40 次
相关 Paper
- VoltSchemer: Use Voltage Noise to Manipulate Your Wireless ChargerZihao Zhan, Yirui Yang, Haoqi Shan, Hanqiu Wang 等USENIX Security 2024 · 被引用 10 次
- Inducing Wireless Chargers to Voice Out for Inaudible Command AttacksDonghui Dai, Zhenlin An, Lei YangS&P 2023
- GhostTalk: Interactive Attack on Smartphone Voice System Through Power LineYuanda Wang, Hanqing Guo, Qiben YanNDSS 2022
- Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile AppsShuai Li, Zhemin Yang, Nan Hua, Peng Liu 等CCS 2022 · 被引用 6 次
- mmSpyVR: Exploiting mmWave Radar for Penetrating Obstacles to Uncover Privacy Vulnerability of Virtual RealityLuoyu Mei, Ruofeng Liu, Zhimeng Yin, Qingchuan Zhao 等UbiComp 2025 · 被引用 13 次
