ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters

Fengchen Yang (Jodang University)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Electromagnetic Attacks

Overview

This talk, titled "ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters," presented by Fengchen Yang from Jodang University, delves into a critical and often overlooked security vulnerability in modern power infrastructure. The presentation highlights how electromagnetic interference (EMI) can be weaponized to manipulate the vital sensors within power inverters, leading to severe consequences ranging from suboptimal power output to complete grid shutdowns and even physical destruction of the hardware. Given the increasing global reliance on renewable energy sources, which heavily depend on power inverters to integrate DC power into the AC grid, understanding and mitigating these threats is paramount for ensuring grid stability and national security.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to power inverters and attack goals
  2. 2:00 Power inverter stages and sensor error consequences
  3. 3:20 Demonstrating EMI's effect on sensor readings
  4. 4:00 Explaining EMI conversion to DC offset via op-amp
  5. 6:00 Achieving controllable sensor manipulation with amplitude modulation
  6. 6:30 Realizing Denial of Service (DOS) attacks
  7. 8:00 Explaining the physical damage (burnout) attack
  8. 9:50 Evaluation of attacks, including real-world scenarios

ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters

Speakers: Fengchen Yang, Jodang University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=IXcYlvHKtR8

Overview

This talk, titled "ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters," presented by Fengchen Yang from Jodang University, delves into a critical and often overlooked security vulnerability in modern power infrastructure. The presentation highlights how electromagnetic interference (EMI) can be weaponized to manipulate the vital sensors within power inverters, leading to severe consequences ranging from suboptimal power output to complete grid shutdowns and even physical destruction of the hardware. Given the increasing global reliance on renewable energy sources, which heavily depend on power inverters to integrate DC power into the AC grid, understanding and mitigating these threats is paramount for ensuring grid stability and national security.

The research explores the feasibility of non-contact attacks on power inverters, where an attacker, armed with prior knowledge of the target inverter, can induce disruptions without physical access. This novel attack vector bypasses traditional cyber defenses by targeting the physical layer through electromagnetic means. The implications are profound, as successful exploitation could lead to localized power blackouts, significant economic losses, and pose a severe risk to critical infrastructure.

The talk systematically breaks down the mechanism through which EMI signals can induce controllable DC offsets in inverter sensors, details three distinct attack types—Denial of Service (DoS), Damage, and Damping—and demonstrates their real-world feasibility. The findings underscore an urgent need for re-evaluating the physical security and electromagnetic resilience of power inverter systems, paving the way for more robust defensive strategies against this emerging class of threats.

Background

▶ Watch: Introduction to power inverters and attack goals (0:00)

The global push towards sustainable energy has led to a proliferation of renewable energy sources such as solar and wind power. However, these sources typically generate direct current (DC), which cannot be directly fed into the existing alternating current (AC) power grid. This is where power inverters become indispensable. These devices are responsible for transforming the DC power from renewable sources into the standard AC power required by the grid. Their critical role means that any malfunction or compromise can have cascading effects on power supply and grid stability.

Power inverters operate in two primary stages: a DC-to-DC stage and a DC-to-AC stage. The DC-to-DC stage converts substandard input voltage into a standardized bus voltage, while the DC-to-AC stage transforms this standard DC voltage into the required standard AC voltage for the grid. Both of these stages are critically dependent on accurate readings from voltage and current sensors. These sensors provide feedback to control algorithms, ensuring efficient power conversion and stable output frequency. A deviation of just two hertz in the output frequency, for instance, can trigger a shutdown from the grid, potentially causing localized power blackouts.

The inherent reliance on these sensors creates a significant vulnerability. If the feedback from these vital sensors is incorrect, a range of detrimental outcomes can occur. Firstly, during input control, incorrect sensor feedback can lead to suboptimal power conversion, a phenomenon referred to as damping, where the system fails to converge to its optimal operating point. Secondly, at the output side, erroneous sensor readings can result in a denial-of-service (DoS) attack, as protection mechanisms might be falsely triggered, shutting down the inverter. Lastly, for bus voltage control, the consequences are even more severe. If the real voltage is lower than the sensor's reported reading, protection mechanisms will activate, leading to a DoS. Conversely, and more critically, if the real voltage is higher than the sensor's reported reading, the system will attempt to compensate, causing the real voltage to gradually increase. This escalation can eventually exceed the inverter's operational thresholds, leading to physical burnout and permanent damage to the device. The existence of these critical dependencies and the potential for severe outcomes highlight why power inverters represent a high-value target for sophisticated attacks.

Key Findings

▶ Watch: Demonstrating EMI's effect on sensor readings (3:20)

The research presented in "ReThink" reveals several groundbreaking findings regarding the susceptibility of power inverters to EMI-based attacks. The core discovery is the feasibility of inducing a DC offset on voltage and current sensors using injected AC noise, i.e., electromagnetic interference. This offset can be manipulated to be either positive or negative, granting an attacker precise control over the perceived sensor readings.

The presentation meticulously explains the underlying mechanism: the operational amplifier within the sensor circuitry plays a crucial role. It receives the injected AC noise, rectifies and amplifies it, and then, through a filtering phase, converts this AC noise into a stable DC offset. The ability to induce both positive and negative offsets stems from the differential nature of the amplifier's inputs. With different physical lengths, these inputs experience varying coupling frequencies from the injected noise, resulting in a differential voltage that can be either positive or negative.

Crucially, the researchers demonstrated that Amplitude Modulation (AM) can be effectively used to achieve controllable manipulation of these sensor readings. By varying the amplitude of the injected EMI signal, attackers can precisely dictate the magnitude and direction of the DC offset, enabling sophisticated attack strategies.

Building upon this controllable manipulation, the talk identified and successfully implemented three distinct types of attacks against power inverters:

  1. Denial of Service (DoS) Attack: Causing immediate shutdown by triggering protection mechanisms.
  2. Damage Attack: Subtly manipulating sensor readings to induce a gradual, uncontrolled increase in real voltage, leading to physical burnout of the inverter.
  3. Damping Attack: Misleading the inverter's optimization algorithms, preventing them from converging to optimal operating points and resulting in suboptimal power output.

These attacks were not only theoretical but were successfully evaluated on both analog and digital sensors in laboratory settings. Furthermore, the research included a real-world simulated attack on a 400-kilowatt (kW) microgrid, demonstrating the practical viability of the attack vector. During this simulated test, the researchers successfully decreased the microgrid's frequency by two hertz, a critical threshold for grid stability, before ceasing further experimentation due to ethical considerations. The development of a portable attack device further underscores the practical threat posed by this research.

Technical Deep Dive

▶ Watch: Achieving controllable sensor manipulation with amplitude modulation (6:00)

The technical core of "ReThink" lies in understanding the intricate interaction between EMI signals and the sensitive sensor circuitry within power inverters. The power inverter architecture, as described, comprises a DC-to-DC stage for voltage standardization and a DC-to-AC stage for grid integration. Both stages are governed by feedback loops that rely heavily on accurate measurements from embedded voltage and current sensors. These sensors typically consist of a sensing element, an amplifier, and filtering components.

The fundamental vulnerability exploited by the researchers is the unintentional rectification of injected AC noise by the operational amplifier (op-amp). When an EMI signal, which is essentially AC noise, couples onto the Printed Circuit Board (PCB) traces connected to the op-amp's inputs, it introduces an unwanted AC component. The op-amp, designed for high gain and often operating with non-linear characteristics at high frequencies or large input excursions, can inadvertently rectify this AC noise into a DC voltage. This rectified DC component is then amplified and passes through subsequent filtering stages, ultimately manifesting as a stable DC offset in the sensor's output reading.

The ability to induce both positive and negative DC offsets is a critical aspect of the attack's sophistication. This phenomenon is explained by the differential nature of the op-amp's inputs. Typically, an op-amp has two inputs: an inverting input and a non-inverting input. Due to variations in PCB trace lengths, component placement, and parasitic capacitances, the injected EMI signal will exhibit different coupling frequencies and amplitudes on these two inputs. When the op-amp processes these differentially coupled noise signals, the resulting rectified DC offset can be either positive or negative, depending on which input experiences a stronger or phase-shifted noise component. This differential coupling is key to achieving versatile manipulation.

To achieve controllable manipulation of sensor readings, the research leveraged Amplitude Modulation (AM). The equation for an AM signal is given as AC (1 + SM) cos(2πFCt), where AC is the amplitude of the carrier wave, SM is the modulated signal (which carries the desired manipulation pattern), and FC is the carrier frequency. By carefully selecting the carrier frequency (FC) to match the resonant frequencies of the sensor circuitry and modulating its amplitude (AC) with a specific signal (SM), the attackers can precisely control the magnitude and waveform of the induced DC offset. This allows for injecting not just a static offset, but also dynamic changes like triangular or sine waves into the sensor readings.

With this controllable manipulation, three distinct attack types were realized:

  1. Denial of Service (DoS) Attack:
  • DC Side DoS: Achieved by inducing a sudden and drastic change in the DC voltage sensor reading. This abrupt deviation triggers the inverter's internal protection mechanisms, designed to prevent damage from sudden input fluctuations, leading to an immediate shutdown. The AM manipulation allows for generating such sharp, instantaneous offsets.
  • AC Side DoS: Targeted the current sensor on the AC output. By injecting a sine wave into the current sensor's readings, the perceived current rapidly exceeds the predefined threshold. This again triggers protection mechanisms, leading to a shutdown of the AC output and a denial of service.
  1. Damage Attack: This is a more insidious attack, designed for physical destruction rather than immediate shutdown. The key here is subtle manipulation to avoid triggering immediate protection mechanisms.
  • The attacker first uses frequency sweeping to identify the specific EMI signal parameters (frequency, amplitude) that cause the target sensor's reading to decrease relative to the real value.
  • Once identified, this signal is applied, and its magnitude is gradually increased. The inverter's control system, believing the voltage is lower than it actually is, attempts to compensate by increasing the real output voltage.
  • This compensatory action leads to a gradual, uncontrolled rise in the real bus voltage. Eventually, this voltage exceeds the inverter's maximum operating threshold, resulting in physical burnout of components like capacitors, IGBTs (Insulated Gate Bipolar Transistors), or other power electronics.
  1. Damping Attack: This attack targets the efficiency and stability of the inverter's power control algorithms.
  • The goal is to prevent the optimization algorithm from converging to the optimal operating point.
  • This is achieved by injecting a complex EMI signal composed of two distinct frequencies (f1 and f2). One frequency might induce a positive offset, while the other induces a negative one.
  • This creates a chaotic or noisy input to the control algorithm, causing it to mislead the optimization process. The algorithm struggles to find a stable and efficient operating point, leading to non-convergence and suboptimal power output, effectively "damping" the inverter's performance.

The detailed understanding and implementation of these mechanisms demonstrate a sophisticated approach to exploiting a fundamental physical vulnerability in critical power infrastructure.

Demo / Proof of Concept

▶ Watch: Realizing Denial of Service (DOS) attacks (6:30)

The "ReThink" presentation backed its theoretical findings with robust experimental evaluations and demonstrations, showcasing the practical feasibility of EMI-based attacks on power inverters. The initial phase of evaluation focused on the core mechanism: sensor manipulation. Researchers successfully demonstrated the ability to induce both positive and negative offsets on a variety of sensors, specifically testing four analog sensors and three digital sensors. This broad success across different sensor types underscores the generalizability of the attack vector. Furthermore, they showed that they could inject complex waveforms, such as triangular or sine waves, into the sensor readings, providing the precision needed for sophisticated attacks.

Following sensor-level validation, the team moved to evaluating the full attack scenarios on actual power inverters within a laboratory environment. They successfully implemented and demonstrated:

  • DoS Attacks: Both on the DC and AC sides, showing how sudden sensor reading changes or injected sine waves could trigger protection mechanisms, leading to immediate inverter shutdowns.
  • Damping Attacks: Illustrating how the introduction of specific EMI signals could disrupt the inverter's control algorithms, preventing them from achieving optimal power conversion and leading to inefficient operation.
  • Damaging Attacks: While not physically burning out inverters repeatedly for ethical reasons, the methodology for subtly decreasing sensor readings to induce a gradual, uncontrolled increase in real voltage was validated, confirming the path to physical destruction.

Perhaps the most compelling proof of concept was the real-world simulated attack conducted on a 400-kilowatt (kW) microgrid. This large-scale test moved beyond the lab to assess the attack's impact in a more realistic operational setting. The researchers successfully demonstrated their ability to decrease the frequency of this live microgrid by two hertz (2 Hz). This is a critical threshold, as a 2 Hz drop is sufficient to trigger grid protection mechanisms and cause a localized power outage. Due to strict ethical considerations, the experiment was halted at this point, and the subsequent steps leading to a full power outage were simulated. This partial success in a real-world environment provides strong evidence of the attack's practical viability and the significant threat it poses to grid stability.

To further emphasize the practicality of the attack, the researchers also constructed a portable attack device. This device, designed to be easily carried and deployed, highlights that such attacks are not confined to specialized laboratories but could potentially be executed by adversaries in various field scenarios.

Defensive Implications

▶ Watch: Evaluation of attacks, including real-world scenarios (9:50)

The findings from "ReThink" necessitate a proactive re-evaluation of security postures for power inverters and, by extension, the broader renewable energy infrastructure. Defenders must consider this new class of physical-layer attacks that bypass traditional cyber defenses. Several key defensive implications emerge:

  1. Hardware Modification and Component Selection:
  • Improved Op-Amp Design: Manufacturers should investigate op-amps less susceptible to unintentional rectification of high-frequency noise. This might involve using op-amps with better common-mode rejection at high frequencies or incorporating active filtering at the chip level.
  • Robust Sensor Design: Designing sensors with integrated EMI hardening, such as internal shielding or specialized input filtering, can make them less vulnerable.
  • PCB Layout Best Practices: Adhering to strict PCB design guidelines, including minimizing trace lengths, using ground planes effectively, and implementing differential routing with matched lengths, can reduce EMI coupling.
  1. Electromagnetic Shielding:
  • Enclosures and Cages: Implementing robust EMI shielding around sensitive components, particularly sensors and control circuitry, is crucial. This could involve using metal enclosures, Faraday cages, or conductive coatings to attenuate incident EMI signals.
  • Cable Shielding: Ensuring all signal and power cables are properly shielded and grounded can prevent EMI from coupling into the system.
  • Component-Level Shielding: Applying localized shielding directly to vulnerable sensors or op-amps can offer an additional layer of protection.
  1. Detection Mechanisms:
  • Anomaly Detection in Sensor Readings: Implementing sophisticated software-based anomaly detection algorithms that monitor sensor readings for sudden, inexplicable offsets or patterns inconsistent with normal operation. Machine learning models could be trained on legitimate sensor data to identify malicious manipulations.
  • EMI Monitoring Systems: Deploying dedicated EMI monitoring equipment in proximity to critical inverters could detect unusual electromagnetic activity indicative of an attack. This would require establishing baseline EMI profiles for normal operation.
  • Cross-Verification of Sensor Data: Where possible, implementing redundant sensors or cross-verifying sensor readings with other system parameters (e.g., comparing expected output power with measured values) can help identify manipulated data.
  • Physical Security and Access Control: While the attack is non-contact, restricting physical access to the vicinity of inverters can deter attackers from deploying portable EMI devices.
  1. Firmware and Control Algorithm Enhancements:
  • Adaptive Protection Mechanisms: Inverter firmware could be made more resilient by incorporating adaptive protection mechanisms that differentiate between legitimate operational fluctuations and malicious manipulations.
  • Redundant Control Paths: Designing control systems with redundant sensor inputs and decision-making logic can increase fault tolerance against compromised sensors.

The "ReThink" research serves as a stark reminder that security in critical infrastructure extends beyond the digital realm and must encompass the physical and electromagnetic layers. A multi-layered defense strategy combining hardware hardening, effective shielding, and intelligent detection is essential to mitigate the threat of EMI attacks on power inverters.

Key Takeaways

  • Power inverters, critical for integrating renewable energy into the grid, are vulnerable to electromagnetic interference (EMI) attacks.
  • EMI can induce controllable DC offsets on vital voltage and current sensors within inverters, primarily through the unintended rectification properties of operational amplifiers.
  • Attackers can achieve precise manipulation using Amplitude Modulation (AM), enabling the injection of specific offsets or waveforms into sensor readings.
  • Three distinct and impactful attack types were demonstrated: Denial of Service (DoS), Damage (leading to physical burnout), and Damping (reducing efficiency).
  • The feasibility of these attacks was validated through lab experiments on various sensor types and a real-world simulated attack on a 400 kW microgrid, where a 2 Hz frequency drop was successfully induced.
  • Defensive strategies must include hardware modifications, robust EMI shielding, advanced anomaly detection in sensor data, and EMI monitoring to protect critical power infrastructure.

About the Speaker(s)

Fengchen Yang is a researcher affiliated with Jodang University. The presentation at the NDSS Symposium highlights their expertise in cybersecurity, particularly in the domain of physical layer attacks and the security of critical infrastructure components like power inverters. Yang's work, as demonstrated in this talk, focuses on uncovering novel vulnerabilities and understanding their mechanisms to inform future defensive strategies.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid ICS security research that takes the well-worn 'EMI can mess with sensors' premise and does the hard work of actually operationalizing it against a specific, high-value target class with real-world grid consequences. The 400 kW microgrid demo and the three-attack taxonomy (DoS, Damage, Damping) elevate this above the typical 'we injected noise into a thing' paper — the damage attack in particular, where you trick the inverter's control loop into voluntarily destroying itself, is genuinely clever. Speaker is a graduate researcher, not a seasoned practitioner, which shows in the depth of defensive recommendations, but the offensive contribution carries the talk.

Heather Calloway (CISO) — WEAK

Technically credible research on a real attack surface — EMI manipulation of power inverter sensors is a legitimate and underexplored threat vector. But the talk stops at the lab bench. It does not reach the operators, utilities, regulators, or procurement officials who would need to act on it.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025