PowerRadio: Manipulate Sensor Measurement via Power GND Radiation
Yan Jiang (PhD candidate · Jan University)
Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Sensor Attacks
Overview
In an era increasingly reliant on sensor-driven systems for everything from smart homes to critical infrastructure, the integrity of sensor readings is paramount. This talk, "PowerRadio: Manipulate Sensor Measurement via Power GND Radiation," presented by Yan Jiang, a PhD candidate from Jan University, unveils a novel and insidious attack vector that challenges conventional assumptions about sensor security. The research, a joint effort with Peking University, demonstrates how attackers can inject malicious signals into a building's power ground cable to remotely and surreptitiously manipulate sensor measurements.
Key moments
- 0:00 Introduction to PowerRadio and sensor security problem
- 2:00 PowerRadio concept: Attacker injects into socket
- 3:50 Key injection method: Using the ground cable
- 4:30 Understanding PowerRadio's internal interference mechanism
- 6:00 Shaping signals to achieve desired specific outputs
- 7:50 Experimental setup and attack demonstrations on systems
- 9:00 Attack universality and proposed mitigation strategies
PowerRadio: Manipulate Sensor Measurement via Power GND Radiation
Speakers: Yan Jiang, PhD candidate, Jan University
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=8NS1pZmXo1E
Overview
In an era increasingly reliant on sensor-driven systems for everything from smart homes to critical infrastructure, the integrity of sensor readings is paramount. This talk, "PowerRadio: Manipulate Sensor Measurement via Power GND Radiation," presented by Yan Jiang, a PhD candidate from Jan University, unveils a novel and insidious attack vector that challenges conventional assumptions about sensor security. The research, a joint effort with Peking University, demonstrates how attackers can inject malicious signals into a building's power ground cable to remotely and surreptitiously manipulate sensor measurements.
The core of PowerRadio lies in exploiting the interconnected nature of ground cables within local power grids and the inherent vulnerabilities within sensor circuits. By radiating carefully crafted electromagnetic interference (EMI) from the ground cable to adjacent analog signal lines inside a sensor, attackers can induce false readings without direct physical access to the sensor itself. This work is significant because it introduces a previously unaddressed threat vector, bypassing common physical security measures and existing isolation mechanisms, thereby necessitating a re-evaluation of sensor system resilience and security protocols.
The implications of PowerRadio are far-reaching. Faulty sensor readings, as the speaker highlights, can lead to severe consequences, from data center outages due to incorrect hard disk readings to catastrophic plane crashes caused by erroneous angle sensor values. By exposing this new method of manipulation, PowerRadio calls for urgent attention to improve the security of sensor systems, particularly those operating in environments where wireless signal penetration is difficult but access to power outlets is common.
Background
▶ Watch: Introduction to PowerRadio and sensor security problem (0:00)
The security of sensor systems has been a long-standing concern in the cybersecurity community. Prior research has extensively documented various methods of physically manipulating sensors, ranging from the use of radiated electromagnetic interference (EMI) to disrupt cameras, to invisible laser attacks that can spoof microphones. These attacks often require specific line-of-sight access or the ability to generate powerful, directed signals that can penetrate enclosures or directly interact with the sensor's transducer. While effective, these methods often face limitations, particularly when sensors are well-protected within enclosed spaces or when an attacker lacks direct, overt access to the device.
The fundamental challenge addressed by PowerRadio stems from these limitations. The researchers posed a critical question: are there other potential threat vectors for diverse sensor types, especially under conditions where sensors are physically protected and traditional wireless signals struggle to penetrate? The realization that nearly every sensor requires power and that their ground cables are universally interconnected within a local power grid, such as a home or office wiring system, provided the crucial insight. This ubiquitous electrical infrastructure, previously considered benign, emerged as a potential conduit for attack.
The problem, therefore, is not merely about interfering with a sensor, but about doing so covertly, across a power grid, and without direct access to the sensor's sensitive components. Existing isolation and filtering mechanisms built into power systems and individual devices are designed to protect against power fluctuations and electrical noise. Overcoming these inherent defenses to deliver a precise, malicious signal to a sensor's internal circuitry represented a significant hurdle. PowerRadio aims to bridge this gap by demonstrating how an attacker can leverage the common power ground as an indirect, yet highly effective, medium for sensor manipulation.
Key Findings
▶ Watch: Key injection method: Using the ground cable (3:50)
The PowerRadio research uncovers a critical new threat vector: the manipulation of sensor measurements by injecting signals into the power ground cable. The core findings revolve around two major challenges that the researchers successfully addressed:
- Interfering with Sensor Measurement Across Sockets/Power Grid: The first key finding is the demonstration of how an attacker can effectively transmit an attack signal across a local power grid, overcoming built-in isolation and filtering mechanisms. The researchers identified the ground cable as the optimal injection port, as it is interconnected and can transmit signals without immediately damaging sensitive low-voltage components, unlike direct injection into power lines. Crucially, they discovered that an attack signal injected into the ground cable flows through the internal ground of the victim sensor and then radiates into nearby analog signal cables. This radiation induces a common mode current, which is subsequently converted into a differential mode voltage due due to inherent asymmetries in the sensor's internal circuits and components. This differential voltage then leads to false digital outputs. The effectiveness of this process is highly dependent on the signal's frequency and magnitude, requiring careful parameter selection to maximize sensor degradation.
- Creating Desired Output with Limited Access: The second major finding is the ability to shape the injected signal to produce specific, desired sensor outputs, rather than just random noise. This is achieved by exploiting the imperfect properties of various signal processing modules within sensors, such as amplifiers, filters, and comparators, as well as the aliasing effect of Analog-to-Digital Converters (ADCs). The researchers found that the non-linearity of amplifiers can introduce new frequencies, low-pass filters may not completely block high-frequency signals, and improper hysteresis in comparators can generate unexpected pulses. By understanding and leveraging these imperfections, PowerRadio can craft signals to induce targeted behaviors. Three specific methods were developed:
- Linear-based AC injection: Suitable for sensors like microphones that produce alternating currents.
- Jitter-based pulse injection: Effective for encoders that output pulsed signals.
- Aliasing effect of ADC: A method to induce a direct current (DC) output.
These findings collectively establish PowerRadio as a potent, stealthy attack method that can bypass traditional security measures and precisely manipulate a wide array of sensors by leveraging the ubiquitous power ground infrastructure.
Technical Deep Dive
▶ Watch: Understanding PowerRadio's internal interference mechanism (4:30)
The PowerRadio attack fundamentally exploits the electromagnetic coupling between the internal ground plane of a sensor and its sensitive analog signal lines, all initiated by an attacker injecting a specific signal into the common power ground. The technical mechanism can be broken down into several stages:
- Signal Injection and Transmission via Ground Cable: The attacker, assumed to have access to a power socket within the victim's local power grid, injects an attack signal. Instead of targeting the live or neutral wires, which carry high voltage and are often heavily filtered, the attack leverages the ground cable. This is a strategic choice because ground cables are interconnected across a local power grid, enabling the signal to propagate, and they typically operate at a lower potential, reducing the risk of damaging the victim device's power management unit (PMU) or being aggressively filtered. The attack signal is generated by a signal generator and amplified by an amplifier to achieve the necessary magnitude for propagation and effect.
- Internal Ground Propagation and Radiation: Once injected into the power ground, the attack signal travels through the building's wiring to the victim sensor. Inside the sensor, the signal flows along the device's internal ground plane or ground cable. Due to the close proximity and often unshielded nature of internal wiring, this internal ground conductor acts as an antenna. It radiates the attack signal as electromagnetic waves into adjacent wires, specifically targeting the analog signal cable connecting the transducer to the Analog-to-Digital Converter (ADC). Analog signals are particularly vulnerable because they are typically low-voltage, continuous waveforms, making them susceptible to even subtle electromagnetic interference.
- Common Mode to Differential Mode Conversion: The radiated EMI induces a common mode current on the analog signal cable. A common mode current flows in the same direction on both signal lines (e.g., positive and negative inputs to a differential amplifier). However, for the sensor to interpret this as a legitimate signal, it needs to be converted into a differential mode voltage. This crucial conversion occurs due to inherent asymmetries in the sensor's internal circuitry and components. These asymmetries can arise from manufacturing tolerances, slight differences in trace lengths, varying impedances, or imperfect matching within differential amplifiers. When the common mode current encounters these asymmetries, it creates a voltage difference between the signal lines, effectively converting the common mode noise into a differential mode signal that the sensor's ADC can misinterpret.
- Signal Shaping and Exploiting Module Imperfections: To produce desired, rather than random, outputs, PowerRadio meticulously crafts the injected signal by exploiting non-ideal characteristics of sensor processing modules:
- Amplifiers: Real-world amplifiers exhibit non-linearity, meaning their output is not perfectly proportional to their input, especially at higher signal magnitudes. This non-linearity can introduce harmonic frequencies or intermodulation products that were not present in the original attack signal, allowing for the generation of complex waveforms.
- Filters: Low-pass filters are designed to block high-frequency signals. However, they are not perfect and may allow a small amount of high-frequency content to "leak" through, or their cutoff frequency might be slightly off. By tuning the attack signal's frequency to exploit these imperfections, specific high-frequency components can be introduced into the analog path.
- Comparators: Comparators convert analog signals into digital ones by comparing them against a threshold. Ideally, they switch cleanly. However, due to improper hysteresis (the difference between the turn-on and turn-off thresholds), a comparator might switch erratically or produce unintended pulses when subjected to a noisy or specific analog signal.
- Analog-to-Digital Converters (ADCs): ADCs convert continuous analog signals into discrete digital values. A key phenomenon exploited is aliasing, where a high-frequency analog signal, sampled at a rate lower than its Nyquist frequency, appears as a lower-frequency signal in the digital domain. By carefully selecting the attack signal frequency relative to the ADC's sampling rate, the researchers can induce a bias signal (effectively a DC offset) or other specific low-frequency artifacts in the digital output.
The research established a signal transmission model and conducted simulations to understand the critical roles of signal frequency and magnitude in energy conversion and efficiency. Physical experiments involved sweeping these parameters to identify optimal attack configurations where sensor degradation was maximized. This systematic approach allowed for the precise crafting of three primary injection methods:
- Linear-based AC injection: For sensors like microphones that output alternating current signals.
- Jitter-based pulse injection: For sensors like encoders that generate pulse-based outputs.
- Aliasing effect of ADC: For sensors where a direct current (DC) offset or a low-frequency interpretation of a high-frequency signal is desired.
The experimental setup involved a standard signal generator to produce the base waveform, an amplifier to boost its power, and connection to the victim device's ground cable via a power socket. This setup demonstrates a practical and achievable attack methodology.
Demo / Proof of Concept
▶ Watch: Experimental setup and attack demonstrations on systems (7:50)
The researchers conducted extensive evaluations to demonstrate the feasibility, versatility, and impact of the PowerRadio attack. Their proof-of-concept demonstrations spanned various sensor types and application scenarios, highlighting the critical vulnerabilities exposed by this novel threat vector.
One primary demonstration focused on surveillance systems. The attacker successfully injected adversary noise into captured images. This noise was not merely random static but specifically crafted to manipulate image processing. For example, the injected noise could effectively bypass a detection model designed to identify specific objects or events, rendering the surveillance system ineffective or misleading. This proves that PowerRadio can compromise the integrity of visual data, which has significant implications for security monitoring and automated analysis.
Another compelling demonstration involved broadcast systems, particularly those relying on audio input. The researchers were able to make the broadcast system play pre-designed malicious commands. This could manifest as unauthorized voice commands being issued, emergency alerts being triggered falsely, or critical instructions being distorted or replaced with harmful messages. The ability to control audio output remotely via the power ground highlights a severe vulnerability in voice-controlled systems and public address networks. The audio complexity evaluation further validated the attack's feasibility in generating intelligible and coherent audio outputs, not just simple tones or static.
Beyond these specific applications, the researchers emphasized the universality and broad applicability of PowerRadio. They tested the attack on 70 other common mode sensors, and in all cases, the attack proved successful. This broad compatibility underscores that the underlying principle – electromagnetic coupling from the ground plane to analog signal lines – is a fundamental vulnerability across a wide range of sensor designs.
Furthermore, the evaluations considered real-world conditions by testing the attack within a household wiring system. The results confirmed that PowerRadio remains effective even under complex electrical conditions, including variations in wiring, the presence of different types of electrical noise, and varying distances between the injection point and the victim sensor. This indicates that the attack is not merely a laboratory curiosity but a practical threat in typical environments. The researchers also demonstrated the attack's ability to affect different device models of the same sensor type, further solidifying its generalizability. This robust validation across numerous sensor types, complex electrical environments, and diverse device models strongly supports the claim that PowerRadio opens up a significant and pervasive new threat vector.
Defensive Implications
▶ Watch: Attack universality and proposed mitigation strategies (9:00)
The discovery of PowerRadio necessitates a significant re-evaluation of sensor system security and the implementation of robust defensive strategies. The traditional focus on protecting sensors from direct physical tampering or conventional wireless interference is insufficient against this new threat. Defenders must consider the power ground as a potential conduit for attack.
The researchers indicate that they "presented effective detection and prevention methods" to mitigate this threat. While the specifics of these countermeasures were not detailed in the provided transcript, the nature of the attack points towards several potential areas for defense:
- Enhanced Grounding Design and Isolation: The most direct implication is the need for more secure and isolated grounding schemes. This could involve segmenting ground planes within devices and across power grids to prevent attack signal propagation. Implementing active noise cancellation or adaptive filtering on ground lines could also help suppress malicious injections.
- Improved Internal Sensor Shielding: Since the attack relies on electromagnetic radiation from the internal ground to analog signal lines, enhanced electromagnetic shielding around sensitive analog components and signal paths within sensors is crucial. This could involve using shielded cables, Faraday cages, or conductive coatings to minimize coupling.
- Differential Signal Integrity: Strengthening the design of differential signaling paths and improving the common mode rejection ratio (CMRR) of operational amplifiers and ADCs would make sensors more resilient. Reducing internal circuit asymmetries that facilitate common-mode to differential-mode conversion is also vital.
- Anomaly Detection in Power Lines: Monitoring the electrical characteristics of the power ground network for unusual signal injections could serve as a detection mechanism. This would involve deploying specialized sensors or current transducers to detect specific frequencies or magnitudes that deviate from normal operational noise.
- Software-Level Validation and Redundancy: At the application layer, implementing plausibility checks on sensor readings and using sensor fusion (combining data from multiple, diverse sensors) can help identify anomalous or manipulated data. Redundant sensors, especially those with different underlying physical principles or power sources, could provide a fallback if one sensor type is compromised.
- Physical Security of Power Infrastructure: While PowerRadio bypasses direct sensor access, it still requires access to a power socket. Enhancing the physical security of power outlets in critical environments can be a deterrent.
Ultimately, mitigating PowerRadio requires a multi-layered approach, combining hardware-level design improvements, enhanced electrical engineering practices, and intelligent software-based anomaly detection. The focus must shift from merely securing the sensor itself to securing the entire electrical environment it operates within.
Key Takeaways
- New Threat Vector Unveiled: PowerRadio introduces a novel and stealthy attack vector that manipulates sensor measurements by injecting malicious signals into the ubiquitous power ground cable, bypassing traditional physical and wireless security measures.
- Exploits Universal Infrastructure: The attack leverages the interconnected nature of ground cables within local power grids, making it broadly applicable to almost any sensor connected to a power outlet.
- Mechanism of Attack: The attack works by radiating electromagnetic interference from the internal ground cable to nearby analog signal lines within a sensor, inducing a common mode current that is converted into a differential mode voltage due to circuit asymmetries, resulting in false digital outputs.
- Precise Signal Manipulation: Researchers demonstrated the ability to craft specific, desired sensor outputs (e.g., malicious commands, image noise) by exploiting imperfections in sensor components like amplifiers, filters, comparators, and the aliasing effect of ADCs.
- Widespread Applicability: The attack was successfully validated across 70 different common mode sensors, various device models, and under complex household wiring conditions, proving its practical feasibility and universality.
- Urgent Need for New Defenses: PowerRadio highlights the critical need for enhanced grounding design, improved internal sensor shielding, robust common mode rejection, and anomaly detection in power lines to safeguard against this insidious form of sensor manipulation.
About the Speaker(s)
The lead speaker for "PowerRadio: Manipulate Sensor Measurement via Power GND Radiation" was Yan Jiang, a PhD candidate affiliated with the USS lab at Jan University. This research was conducted as a joint work with Peking University, indicating a collaborative effort between these academic institutions. Yan Jiang's presentation showcased deep technical understanding and expertise in the field of hardware security and sensor vulnerabilities.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
PowerRadio is a legitimate hardware security research contribution — a novel side-channel attack path using power ground infrastructure as a signal injection vector to manipulate analog sensors without direct physical access. The mechanism is well-reasoned, the threat model is realistic, and the 70-sensor validation across real household wiring gives it genuine breadth. A PhD candidate presenting at NDSS with Peking University co-authorship on this caliber of work is worth your time.
Heather Calloway (CISO) — WEAK
Technically sound research demonstrating a novel EMI-based sensor manipulation vector via power ground infrastructure, validated across a broad sensor set. But it ends where operator relevance should begin — no threat model context, no risk prioritization, and no actionable path for the security leaders or infrastructure owners who actually need to respond to this.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025