~ similar to 2605.14633v1· 20 results
The paper demonstrates that the Brazilian e-Voting Machine interface generates a simple and highly distinctive electromagnetic spectral signature, raising significant concerns about its susceptibility…
The paper introduces PINSIGHT, a novel methodology that rigorously assesses Wi-Fi PIN code inference attacks by separating environmental effects from typing effects, concluding that current state-of-t…
Elie Bursztein, Michael Gruber, Karel Král, Jean-Michel Picod +2 more
This paper proposes training a single neural network using EM traces collected from multiple probe positions to detect cryptographic leakage across a larger area of a target device, validated by cross…
This paper provides the first comprehensive review of threats and defenses specifically targeting on-device AI inference, revealing a significant imbalance where certain attack types, like adversarial…
Zijian Ling, Jianbang Chen, Hongwei Li, Hongda Zhai +5 more
BioMoTouch is a multi-modal touch authentication framework that jointly models physiological contact structures (from capacitive screens) and behavioral motion dynamics (from inertial sensors) to achi…
ThermalTap presents the first passive, non-contact side-channel attack that fingerprints virtual reality (VR) applications by analyzing the long-wave infrared (LWIR) thermal radiation emitted by the h…
The paper introduces VRSafe, a novel virtual QWERTY keyboard designed to significantly mitigate keystroke inference attacks in virtual reality by introducing false positive keystrokes and incorporatin…
This paper investigates a novel vulnerability in tactile sensing by demonstrating that targeted Electromagnetic Interference (EMI) can induce strong, misleading 'phantom forces' in Hall-effect fingert…
TriSweep proposes a novel four-drone swarm framework for autonomous, standoff electromagnetic side-channel analysis, achieving high key rank recovery even with significant signal degradation and jitte…
Tobias Kröll, Stephan Kleber, Frank Kargl, Matthias Hollick +1 more
The authors reverse-engineered and fuzz-tested the undocumented Apple Remote Invocation (ARI) interface, revealing a significant, untested Remote Code Execution (RCE) attack surface on iOS.
Taekkyung Oh, Duckwoo Kim, Hansung Bae, Beomseok Oh +7 more
The paper introduces Devilray, a comprehensive adversarial model that systematically tests the realistic operational space of fake base stations, revealing significant blind spots in existing detectio…
The paper introduces DECKER, a domain-invariant framework that significantly improves cross-keyboard keystroke inference by normalizing device variations and leveraging linguistic context, demonstrati…
The paper reverse-engineers Apple's Private Cloud Compute (PCC) implementation to independently benchmark its model and evaluate its privacy claims, addressing the lack of transparency in Apple's syst…
Zilong Hu, Hongming Fei, Prosanta Gope, Jack Miskelly +2 more
The paper introduces a quantitative, cell-level circuit framework to model DRAM vulnerability by linking physical charge leakage and disturbance pathways to system-level security properties like volat…
The paper proposes an on-device framework to detect and prevent the forwarding of images that have been physically recaptured (photographed) from a mobile screen, addressing the Screen Recaptured Anal…
The paper introduces SCAgent, an automated framework that uses LLM-assisted agents to systematically discover, analyze, and assess side-channel leakage risks in complex systems like iOS, moving beyond…
This paper introduces a dual-layer side-channel attack framework that exploits the variable workload introduced by dynamic image preprocessing in local Vision-Language Models (VLMs) to infer sensitive…
The paper proposes a constant-time implementation methodology for activation functions on microcontrollers to prevent timing side-channel attacks during embedded neural-network inference.
This paper models PIN entry as a stochastic communication channel, proposing a probabilistic inference framework to quantify reliability loss and QoS degradation caused by partial information leakage.
The paper proposes Rowhammer Vulnerability Counter (RVC), a novel framework that improves RowHammer mitigation by tracking a row's actual vulnerability to bit flips rather than relying on simple activ…