EMIRIS: Eavesdropping on Iris Information via Electromagnetic Side Channel

Wenhao Li (Shano University)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Electromagnetic Attacks

Overview

The talk "EMIRIS: Eavesdropping on Iris Information via Electromagnetic Side Channel" presented by Wenhao Li from Shano University, unveils a novel and concerning vulnerability in iris recognition systems. Iris recognition, lauded for its high entropy and stability, is widely deployed in critical security applications, ranging from ID verification and airport security to banking machines. However, this research demonstrates that the near-infrared (NIR) sensors fundamental to these systems inadvertently emit electromagnetic (EM) signals during operation, creating an exploitable side channel.

Watch on YouTube · Slides

Key moments

  1. 0:41 EMIRIS attack model and preliminary experiment
  2. 2:00 Mapping EM signals to iris data
  3. 3:40 Improving iris reconstruction: noise reduction and image processing
  4. 4:50 Introducing Diffusion Model for realistic iris reconstruction
  5. 6:40 Experimental setup and high-similarity reconstruction results
  6. 8:20 Successfully spoofing various iris recognition models
  7. 9:00 Attack on commercial devices and potential defenses

EMIRIS: Eavesdropping on Iris Information via Electromagnetic Side Channel

Speakers: Wenhao Li, Shano University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=PUyDUmuvg0o

Overview

The talk "EMIRIS: Eavesdropping on Iris Information via Electromagnetic Side Channel" presented by Wenhao Li from Shano University, unveils a novel and concerning vulnerability in iris recognition systems. Iris recognition, lauded for its high entropy and stability, is widely deployed in critical security applications, ranging from ID verification and airport security to banking machines. However, this research demonstrates that the near-infrared (NIR) sensors fundamental to these systems inadvertently emit electromagnetic (EM) signals during operation, creating an exploitable side channel.

The EMIRIS attack model postulates an adversary remotely capturing these EM emissions from a victim's iris scan without physical access to the device or prior knowledge of the victim. By meticulously processing these faint EM signals, the attacker can reconstruct highly similar iris patterns, posing a significant privacy and security risk. The presented preliminary experiments showcased reconstructed iris images bearing a striking resemblance to the originals, immediately highlighting the gravity of this previously unaddressed threat to biometric security.

Background

▶ Watch: EMIRIS attack model and preliminary experiment (0:41)

Iris recognition technology has long been considered one of the most robust and secure biometric identification methods. Its strength lies in the unique and complex patterns of the human iris, which are highly stable throughout a person's life and possess a significantly higher entropy than fingerprints or facial features. Consequently, it has found widespread adoption in environments demanding stringent security, such as government facilities, international borders, and financial institutions. The underlying mechanism typically involves a near-infrared (NIR) camera capturing an image of the iris, which is then processed into a unique digital template for matching.

The fundamental problem that EMIRIS exploits stems from the operational characteristics of these NIR sensors. As the sensors capture and transmit digital data representing the iris image, they inadvertently generate electromagnetic emissions. These emissions are not part of the intended communication channel but are rather a byproduct of the electronic circuits' activity. In essence, the digital signals being processed within the device "leak" into the electromagnetic spectrum, creating a side channel. The EMIRIS attack model is predicated on the ability of an attacker to intercept these unintended emissions from a distance. The attacker positions a receiving antenna to passively capture the EM signals emanating from the NIR sensor while a victim's iris is being scanned. Crucially, the attacker operates without direct physical access to the recognition device and possesses no prior information about the victim, making it a highly practical and pervasive threat scenario. During the Q&A, it was clarified that the attack could be performed from a distance of up to 2 meters, demonstrating its remote applicability. Further investigation revealed that the primary source of these exploitable EM radiations was the digital cables connecting components within the NIR sensor system, rather than the sensor itself, and that most NIR sensors utilize similar data transmission patterns, making the attack broadly applicable.

Key Findings

▶ Watch: Improving iris reconstruction: noise reduction and image processing (3:40)

The EMIRIS research yielded several critical findings that underscore the vulnerability of current iris recognition systems:

  1. Successful Iris Reconstruction from EM Side Channels: The core finding is the undeniable ability to reconstruct detailed iris patterns solely from electromagnetic emissions leaked by near-infrared sensors. Initial reconstructions demonstrated a high visual similarity to the original iris, capturing its main texture.
  2. High Reconstruction Fidelity: Through a sophisticated methodology involving noise reduction, image enhancement techniques, and the integration of a diffusion model guided by Half-Quadratic Splitting (HQS), EMIRIS achieved highly realistic and detailed iris reconstructions. Quantitative metrics like SSIM (Structural Similarity Index Measure) and FID (Frechet Inception Distance) consistently showed strong performance across various conditions and different NIR sensors, indicating high fidelity and realism.
  3. Spoofing Capability Against Recognition Models: The reconstructed iris images were successfully used to bypass five different iris recognition models developed by the researchers. The Receiver Operating Characteristic (ROC) curves and spoofing success rates demonstrated that EMIRIS can effectively spoof these models, highlighting a direct security threat.
  4. Effectiveness Against Commercial Devices: The attack was not limited to laboratory setups but also proved effective against commercial iris recognition devices. The method successfully recovered detailed iris information from these real-world systems, escalating the practical implications of the vulnerability.
  5. Identification of Primary Emission Source: Through targeted antenna measurements, the researchers identified the digital cables within the NIR sensor system as the primary source of the high-amplitude EM signals that facilitate the attack. This specificity is crucial for developing targeted countermeasures.
  6. Broad Applicability: The research indicated that while not applicable to every near-infrared sensor, the attack methodology is effective against most common NIR sensors (tested on five different models) because they tend to use similar data transmission patterns. This suggests a widespread architectural vulnerability rather than an isolated flaw in specific devices.

Technical Deep Dive

▶ Watch: Introducing Diffusion Model for realistic iris reconstruction (4:50)

The EMIRIS attack hinges on a sophisticated methodology for mapping electromagnetic signals back to intelligible iris data. The reconstruction process is mathematically modeled and refined through several stages to achieve high fidelity.

The fundamental model for iris reconstruction is expressed as:

$I_{reconstructed} = ME(MD(EM_{signals}))$

Where $I_{reconstructed}$ is the reconstructed iris grayscale matrix, $EM_{signals}$ represents the captured electromagnetic signals, $MD$ is a function that maps digital signals from the NIR sensor into an iris matrix based on the device's specific format, and $ME$ maps the raw EM signals to the iris matrix based on the observed iris data transmission pattern. The $MD$ function is often well-defined and publicly known for most inference sensors, allowing the researchers to derive the $ME$ function based on this existing knowledge.

The core principle behind the EM-to-iris mapping is that pixel intensity directly influences the amplitude of the EM emissions. By capturing these amplitude variations, they can be converted into grayscale values. These grayscale values are then mapped into an iris matrix according to the established $MD$ function. After an initial reconstruction, the iris data is segmented and normalized to facilitate easier comparison with the ground truth, revealing a visible, albeit somewhat noisy, texture similarity.

To significantly enhance the clarity and realism of the reconstructed iris images, the EMIRIS methodology incorporates several advanced signal processing and image enhancement techniques:

  1. Noise Reduction in EM Signals:

The captured EM signals are inherently noisy due to channel interference and external factors. The researchers model this noise as $WF$. To optimize signal quality, two primary approaches are employed:

  • Digital Domain Optimization: Single Carrier Frequency Domain Equalization is applied to enhance signal quality digitally. This technique helps to mitigate distortions introduced during signal transmission.
  • Physical Domain Optimization: Low Noise Amplifiers (LNAs) are used in the hardware setup to improve the Signal-to-Noise Ratio (SNR) of the captured EM signals before digital processing. This physical enhancement is critical for capturing faint variations.
  1. Image Processing Techniques:

After initial noise reduction, standard image processing algorithms are applied to the raw reconstructed image to refine its structure:

  • Edge Detection Filters: Laplacian and Sobel filters are utilized to highlight edges and key structural features within the iris pattern. These filters are effective at emphasizing abrupt changes in pixel intensity, which correspond to the intricate textures of the iris.
  • Dynamic Histogram Equalization (DHE): This algorithm is applied to enhance local contrast and bring out more subtle details in the reconstructed image. DHE adaptively adjusts the image's contrast, making previously indistinct features more prominent.
  1. Denoising and Realism with Diffusion Models and HQS:

For the ultimate refinement and to generate highly realistic iris images, EMIRIS introduces a sophisticated approach combining a diffusion model with Half-Quadratic Splitting (HQS). The speaker clarified that the diffusion model is used as a condition, not merely a prior, guiding the reconstruction process.

  • Diffusion Model Principle: A classic diffusion model learns to generate high-quality images by first corrupting them with Gaussian noise in a "forward process" and then learning to reverse this process to recover the original structure.
  • Integration with HQS: EMIRIS leverages this power by integrating the diffusion model with HQS to formulate iris reconstruction as a joint optimization program. This means the initial, somewhat noisy, EM-reconstructed iris image acts as a condition that guides the diffusion model. Instead of generating an image from pure noise, the model is directed towards a specific structure already hinted at by the EM side channel.
  • HQS for Consistency: HQS is employed to enforce consistency between the generated image ($X$) and the EM-based iris reconstruction ($y$). This involves a sub-iteration process with two key steps:
  1. Optimize ZT: In the first step, an auxiliary variable $Z_T$ is optimized to stay close to $X_T$. This optimization is guided by a prior $P(Z_T|X_T)$ which encourages the model to generate an image that matches realistic iris patterns.
  2. Update X: In the second step, $X_{T-1}$ is updated to stay close to $Z_T$. Crucially, this step also incorporates the initial iris image ($y$) reconstructed from the EM signals, ensuring that the generated image aligns with the expected pixel distribution derived from the side-channel data.

By iteratively repeating these steps, the model gradually refines the iris image, enhancing its structure, detail, and overall quality while remaining faithful to the information extracted from the EM signals.

Model Training: The diffusion model was trained on an extensive dataset comprising over 46,000 iris images sourced from four different datasets, ensuring broad diversity and robustness. Key training parameters, including the optimizer, number of epochs, and diffusion steps, were meticulously configured, though specific values were not detailed in the presentation.

Evaluation Metrics: The effectiveness of the reconstruction was quantitatively evaluated using two standard image quality metrics:

  • Structural Similarity Index Measure (SSIM): A higher SSIM value indicates greater similarity between the reconstructed iris and the ground truth.
  • Frechet Inception Distance (FID): A lower FID value signifies that the generated iris images are more realistic and better match the distribution of real iris images.

The results consistently demonstrated that EMIRIS performed exceptionally well across different conditions for both SSIM and FID, validating the high quality of the reconstructed images.

Demo / Proof of Concept

▶ Watch: Successfully spoofing various iris recognition models (8:20)

The practical demonstration of EMIRIS involved a carefully constructed experimental setup designed to validate the attack's feasibility and effectiveness. The core components of the setup included:

  1. Iris Capture Module: This was built using a standard near-infrared (NIR) sensor paired with a single-board computer. This module simulated a typical iris recognition device, capturing the victim's iris while simultaneously emitting the unintended EM signals.
  2. EM Signal Capture: A USRP (Universal Software Radio Peripheral), equipped with a directional antenna, was used to passively receive the electromagnetic emissions emanating from the iris capture module. The directional antenna allowed for precise targeting of the emission source, which was identified as the digital cables within the NIR sensor system.

The results of this experimental setup were visually compelling. The reconstructed iris images exhibited a high similarity with the ground truths, demonstrating that the EMIRIS methodology could effectively extract and re-formulate complex biometric data. The presentation included side-by-side comparisons of the original and reconstructed irises, clearly showing that the reconstructed images captured the main texture and intricate features. Furthermore, segmented portions of the reconstructed irises revealed similar feature patterns to the ground truth, underscoring the fidelity of the reconstruction beyond mere visual resemblance.

Beyond the custom-built setup, the researchers extended their proof of concept to commercial iris recognition devices. By using the USRP to receive EM emissions from these off-the-shelf systems, they successfully recovered detailed iris information. This crucial demonstration validates that EMIRIS is not merely a theoretical attack but a practical threat to widely deployed commercial biometric systems, making the findings far more impactful. The ability to reconstruct irises from different near-infrared sensors further highlighted the broad applicability of the attack, as evidenced by consistent performance across various sensor models as measured by SSIM and FID scores.

Defensive Implications

▶ Watch: Attack on commercial devices and potential defenses (9:00)

The EMIRIS attack exposes a significant vulnerability in current iris recognition systems, necessitating robust defensive strategies. The primary defensive implication derived from this research is the critical need for advanced electromagnetic (EM) shielding.

Since the digital cables within near-infrared sensors were identified as the main source of EM leakage, shielding these components becomes paramount. Defenders should:

  • Integrate EM Shielding Materials: Device cables and enclosures should be designed with integrated EM shielding materials. This could involve using shielded cables (e.g., coaxial or twisted-pair with metallic braids/foils) or incorporating metallic enclosures and internal shielding partitions.
  • Utilize Effective Shielding Materials: The research specifically highlighted that metal-based materials are more effective in blocking EM leakage compared to other materials. Therefore, designs should prioritize the use of conductive metals or alloys for shielding components. The presentation showed a clear reduction in attack effectiveness when EM shielding was present, demonstrating its viability as a countermeasure.

However, it is equally important to acknowledge the current limitations of the EMIRIS attack, which consequently define areas where existing defenses remain effective or where future defensive efforts might need to focus:

  • 2D Iris Reconstruction Limitation: Currently, EMIRIS only reconstructs a 2D iris image. This means it cannot bypass sophisticated liveness detection mechanisms employed by advanced iris recognition systems. Liveness detection typically checks for dynamic biometric features such as pupil response to light changes, blinking, or subtle eye movements, which are not present in a static 2D image.
  • Future Attack Vectors: While EMIRIS in its current form cannot bypass liveness detection, the researchers acknowledge this limitation and plan to explore advanced biometric spoofing methods. These include techniques like bionic eyes or specialized contact lenses designed to mimic dynamic liveness features. This indicates that while EM shielding is a crucial first step, continuous innovation in liveness detection remains vital to stay ahead of evolving spoofing techniques.

In summary, the immediate defensive action is to enhance EM shielding around NIR sensor components, particularly digital cables, using effective metallic materials. Concurrently, the industry must continue to invest in and refine liveness detection capabilities to counter the inevitable evolution of biometric spoofing attacks.

Key Takeaways

  • EM Side-Channel Vulnerability: Iris recognition systems, despite their high security reputation, are vulnerable to electromagnetic side-channel attacks (EMIRIS) that exploit unintended EM emissions from near-infrared sensors.
  • High-Fidelity Reconstruction: EMIRIS can successfully reconstruct detailed and realistic iris patterns from these leaked EM signals, achieving high similarity to ground truth images through advanced signal processing, image enhancement, and diffusion models.
  • Spoofing Capability: The reconstructed iris images are sufficiently accurate to bypass existing iris recognition models and even compromise commercial biometric devices, posing a direct threat to identity verification systems.
  • Primary Emission Source: Digital cables within near-infrared sensor systems have been identified as the main source of exploitable electromagnetic leakage, providing a specific target for defensive measures.
  • Effective Countermeasure (Shielding): Implementing advanced EM shielding, particularly with metal-based materials, in device cables and enclosures can significantly reduce the effectiveness of the EMIRIS attack.
  • Liveness Detection Gap: The current EMIRIS attack is limited to 2D image reconstruction and cannot bypass sophisticated liveness detection mechanisms, highlighting the importance of dynamic biometric checks and the need for ongoing research into advanced spoofing countermeasures.

About the Speaker(s)

Wenhao Li is a researcher from Shano University. He presented the work on EMIRIS at the NDSS Symposium. During the Q&A session, he confirmed that he is the first author of the paper, indicating his primary role and expertise in this research. His work focuses on identifying and exploiting security vulnerabilities in biometric systems, particularly through side-channel analysis.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original EM side-channel research applied to a target — iris biometrics — that hasn't been thoroughly abused in this way before. The methodology is credible, the threat model is realistic, and the commercial device validation elevates it above a pure lab exercise. The diffusion model integration for reconstruction is clever, not gimmicky.

Heather Calloway (CISO) — WEAK

Technically credible TEMPEST-class research applied to biometric systems, with real proof-of-concept results and a plausible threat model. But the talk stops at the vulnerability and never closes the loop for the people who actually operate these systems — procurement leads, standards bodies, airport security architects, or the vendors shipping affected hardware.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025