Power-Related Side-Channel Attacks using the Android Sensor Framework

Mathias Oberhuber

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Android Security 1

Overview

In an era where mobile devices are central to our digital lives, the security of sensitive data processed on these platforms is paramount. This talk by Mathias Oberhuber from the NDSS Symposium unveils a novel and concerning class of power-related side-channel attacks that exploit the Android sensor framework. The core finding is that the Android sensor interface, typically used for functionalities like compass navigation or motion tracking, can be repurposed as an unprivileged, software-only proxy for measuring device power consumption. This circumvents the traditional security barriers that prevent direct access to power interfaces on Android, opening a new vector for data exfiltration.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: Android sensor framework for power side-channels
  2. 1:00 Motivation: Compass app deflection from CPU utilization
  3. 2:15 Systematic evaluation: CPU utilization affects sensor readings
  4. 3:20 Systematic evaluation: Distinguishing different instruction types
  5. 4:10 Key finding: Distinguishing data operands using sensor interface
  6. 5:20 Sensor profiling: Characterizing sensor integration intervals and windows
  7. 7:15 Peculiar finding: Orientation-dependent leakage observed in sensors

Power-Related Side-Channel Attacks using the Android Sensor Framework

Speakers: Mathias Oberhuber

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=5Ext7yQ48OE

Overview

In an era where mobile devices are central to our digital lives, the security of sensitive data processed on these platforms is paramount. This talk by Mathias Oberhuber from the NDSS Symposium unveils a novel and concerning class of power-related side-channel attacks that exploit the Android sensor framework. The core finding is that the Android sensor interface, typically used for functionalities like compass navigation or motion tracking, can be repurposed as an unprivileged, software-only proxy for measuring device power consumption. This circumvents the traditional security barriers that prevent direct access to power interfaces on Android, opening a new vector for data exfiltration.

The research demonstrates that CPU activity, ranging from general utilization to specific instruction execution and data operand manipulation, subtly but measurably influences sensor readings. Through a systematic analysis across nine diverse Android phones, the team identified significant correlations between computational workloads and sensor data, along with critical leakage properties such as integration intervals and orientation-dependent effects. These findings culminate in two compelling attack case studies: a local attacker scenario demonstrating AES key byte recovery from a malicious app, and a remote, web-based attack enabling cross-origin image content leakage via a pixel stealing technique.

This work is highly significant for the security community, as it exposes a fundamental hardware interaction vulnerability that can be exploited purely through software, without requiring any elevated privileges or specialized hardware. It challenges existing assumptions about the isolation of applications and web content on Android and calls for a re-evaluation of how sensor data is handled and protected. The implications extend to sensitive data processing, cryptographic operations, and privacy on mobile devices, urging developers and platform vendors to consider new defensive strategies against these subtle yet potent side-channel threats.

Background

▶ Watch: Introduction: Android sensor framework for power side-channels (0:00)

The foundation of this research stems from a critical security challenge on modern mobile platforms: the inability for unprivileged applications to directly monitor a device's power consumption. Operating systems like Android intentionally restrict access to power interfaces to prevent malicious actors from inferring sensitive information through power side channels. However, the talk highlights that this security measure might be inadvertently bypassed through an indirect channel: the device's integrated sensors.

The initial observation that spurred this research was surprisingly simple yet profound. The speaker describes a scenario where a basic compass application, relying on the Android sensor interface to determine orientation, exhibits erratic behavior when the CPU utilization of the device is concurrently varied. Specifically, the compass needle would deflect in response to changes in the CPU workload. This phenomenon suggested a direct, measurable interference between the CPU's computational activities and the readings from the device's sensors.

Expanding on this observation, the researchers posited that the CPU, responsible for all computations on the device, generates various forms of interference—such as electromagnetic radiation or other physical effects—that can impact the highly sensitive Analog-to-Digital Converters (ADCs) used by the onboard sensors. Sensors collect analog signals from the physical environment, convert them to digital data via ADCs, and then provide these digital readings to the device's operating system and applications. The core hypothesis of this work is that the power consumption fluctuations caused by CPU activity are somehow coupled into the sensor's measurement pipeline, manifesting as discernible changes in the sensor output. The specific root cause of this interference (e.g., electromagnetic, thermal, or voltage ripple) was not the primary focus; instead, the research aimed to quantify the extent to which this interference could be leveraged to extract secret information purely from software, without needing privileged access to the power interface. This approach bypasses the traditional barriers against power side-channel attacks, presenting a novel and potent threat vector.

Key Findings

▶ Watch: Systematic evaluation: CPU utilization affects sensor readings (2:15)

The research presents a comprehensive systematic evaluation across nine diverse Android phones, revealing profound insights into the nature and extent of power-related side-channel leakage through the sensor framework. This evaluation was structured into three primary analyses, followed by detailed profiling of specific leakage properties.

Firstly, the team investigated the impact of varying CPU utilization on sensor readings. By fluctuating the CPU load between 0% and 100% and simultaneously collecting sensor measurements at their highest refresh rates, they observed a direct correlation: sensor measurements visibly deflected in patterns mirroring the CPU utilization changes. Quantitatively, their analysis showed that approximately 18.9% of the evaluated sensors across the nine devices exhibited a strong correlation, with coefficients greater than 0.7, indicating a significant influence from CPU activity.

Secondly, the study differentiated between various instruction types. The researchers executed distinct instruction sets—including floating-point arithmetic, integer arithmetic, bit operations, memory stores, and cryptographic operations—for several seconds each in a random order. In parallel, sensor measurements were collected. The results clearly demonstrated that these different instruction types produced recognizably distinct patterns in the sensor traces. To validate that these patterns were indeed power-related, a rooted device was used to collect battery voltage as a ground truth. Comparing sensor traces with battery voltage plots revealed similar, albeit inversely proportional, patterns. Statistical analysis confirmed that around 12.5% of sensors, for instance, on a Pixel 6A, correlated heavily with battery voltage fluctuations, underscoring the power-related nature of the observed sensor changes.

Lastly, and perhaps most critically for data leakage, the researchers examined the ability to distinguish between different data operands. Focusing on the XOR instruction, they varied the number of toggled bits between two operands. Modern CPUs, particularly their CMOS gates, consume more power when bits switch states (from 0 to 1 or 1 to 0). Consequently, an XOR operation resulting in fewer toggled bits (e.g., 0 XOR 0 or 1 XOR 1 resulting in 0) consumes less power than an operation with more toggled bits (e.g., 0 XOR 1 resulting in 1). This power model was correlated with sensor measurements, revealing that approximately 43.8% of the evaluated sensors showed statistically significant correlations, above the noise level, concerning these data operands. This finding is crucial as it demonstrates that the actual data being processed, not just the type of operation, can leak through the sensor interface.

Beyond these systematic evaluations, the research delved into specific leakage properties of the most promising sensors, such as the geometric rotation vector sensor. One key property identified was the integration interval of sensor measurements. Sensors do not provide instantaneous readings; instead, they integrate signals over a specific time window. By executing high and low power workloads, each lasting for the sensor's measurement interval (ΔT), and precisely shifting their start times relative to the sensor's measurement events, the researchers could characterize this integration window. High correlations were observed when workloads aligned perfectly with the measurement window, while shifted workloads yielded lower or even negative correlations, allowing for the precise determination of the sensor's offset and the duration of its measurement window.

Another critical leakage property discovered was orientation-dependent leakage. The team found that the amplitude of the sensor signal (the difference between high and low readings during CPU load changes) varied significantly depending on the phone's physical orientation. By rotating the phone 360 degrees and repeating CPU utilization experiments, they observed that certain rotational placements, specifically along the "plane between north and south," resulted in the largest signal amplitudes. This suggests that the interference coupling between the CPU and the sensor is directional, potentially due to the physical layout of components or electromagnetic field patterns. These detailed leakage properties are vital for optimizing and refining side-channel attacks.

Technical Deep Dive

▶ Watch: Systematic evaluation: Distinguishing different instruction types (3:20)

The technical foundation of this attack vector lies in the fundamental interaction between a mobile device's central processing unit (CPU) and its integrated sensors. The core mechanism is that the power consumption fluctuations caused by CPU activity are not perfectly isolated but instead interfere with the highly sensitive Analog-to-Digital Converters (ADCs) used by the sensors. While the exact physical root cause (e.g., electromagnetic, voltage ripple, thermal) is acknowledged as complex, the research demonstrates the effect is consistently measurable through the Android sensor framework. This framework provides an unprivileged software interface to access sensor data, making the attack highly accessible.

The systematic evaluation methodology was meticulously designed to quantify this interference. Nine diverse Android phones were selected, spanning multiple vendors (Samsung, Google, Huawei, Honor) and release dates (from approximately 2010 to a recent Pixel 9 model). This broad selection demonstrated the widespread nature of the vulnerability, as leakage was observed across all tested devices and Android versions (e.g., Android 13 and 14). Sensor data was collected at the highest possible refresh rates to capture fine-grained fluctuations. The researchers used correlation coefficients to statistically quantify the relationship between CPU activity and sensor readings, providing a robust measure of the leakage. For validation, they employed a rooted device to obtain direct battery voltage measurements, serving as a reliable ground truth for power consumption. The observed correlation between sensor data and battery voltage confirmed that the sensor fluctuations were indeed indicative of underlying power changes.

To further refine the attack, the team undertook detailed profiling of the best sensor. The geometric rotation vector sensor was identified as a particularly strong candidate for exploitation. This sensor, which typically provides the device's orientation as a combination of an accelerometer, gyroscope, and magnetometer, proved highly susceptible to CPU interference.

A crucial aspect of the technical deep dive involved understanding the sensor's integration window. Sensors don't report instantaneous values; they average or integrate physical signals over a short duration. To characterize this, an experiment was devised:

  1. Define ΔT as the time interval between two consecutive sensor measurements.
  2. Execute two distinct workloads: one with high power consumption and one with low power consumption, each precisely of duration ΔT.
  3. Perform multiple experimental runs, in each run shifting the start time of these workloads relative to the sensor measurement event.
  4. Correlate the observed sensor signal with the expected power profile of the shifted workloads.

When the workloads aligned perfectly with the sensor's internal measurement window, a high correlation was observed. As the workloads were shifted, the correlation decreased, eventually becoming negative when the workloads aligned with the next sensor measurement window. This precise method allowed the researchers to determine both the offset of the sensor measurement relative to when the event occurred and the effective duration of the measurement window. This information is critical for timing attacks, enabling attackers to synchronize their malicious operations with the sensor's sampling cycle for maximum signal leakage.

The discovery of orientation-dependent leakage added another layer of complexity and opportunity. The experiment involved placing the phone on a flat surface and varying CPU utilization between 0% and 100%. This process was repeated after rotating the phone incrementally through a full 360 degrees. Plotting the amplitude of the sensor signal (the difference between high and low readings) against the rotational placement revealed that the interference was not uniform in all orientations. Specifically, the largest amplitudes were observed when the phone was oriented along the "plane between north and south." This suggests that the electromagnetic fields generated by the CPU, or other physical interference mechanisms, are directional and interact more strongly with the sensor's components when aligned in specific ways. An attacker aware of this could advise a user on optimal phone placement or simply try different orientations to maximize signal-to-noise ratio.

During the Q&A, the speaker provided a critical insight into the root cause of data operand leakage. The phenomenon where 0 XOR 0 consumes less power than 0 XOR 1 is attributed to the fundamental design of modern CPUs, particularly the behavior of CMOS (Complementary Metal-Oxide-Semiconductor) gates. These gates form the building blocks of digital logic circuits. CMOS gates consume power primarily when they switch states (from 0 to 1 or 1 to 0). If an operation results in fewer bits toggling (i.e., fewer gates switching), less power is consumed. Conversely, operations that cause more bits to toggle (e.g., when the input and output bits differ significantly, like 0 XOR 1 producing a 1) lead to higher power consumption. This "toggling" or "switching" power is directly measurable through the sensor interface, making data-dependent power consumption a practical side-channel.

Demo / Proof of Concept

▶ Watch: Sensor profiling: Characterizing sensor integration intervals and windows (5:20)

The research validated its findings with two distinct and impactful attack case studies, demonstrating the practical exploitability of this sensor-based side-channel.

The first proof of concept was a JavaScript pixel stealing attack, targeting remote web content. This attack leverages the fact that a malicious website can display legitimate, cross-origin content within an iframe. While same-origin policy prevents the attacker's JavaScript from directly reading the pixel data of the iframe, it can apply SVG filters (e.g., black and white conversion, scaling) to specific pixels within the iframe. The crucial insight is that applying these filters triggers CPU computations, and the nature of these computations varies depending on the original pixel color (e.g., converting a black pixel to black and white versus converting a white pixel). In parallel, the attacker's JavaScript collects sensor measurements from the browser. The team demonstrated that applying filters to black versus white regions of an image resulted in distinct patterns in the collected magnetometer traces, specifically fluctuating at different frequencies. By systematically applying these filters to individual pixels or regions and observing the corresponding sensor signals, the attacker can infer the original color of the pixels. The speaker demonstrated the recovery of a Google Chrome logo image. Using the magnetometer, they achieved an accuracy of 90.2% with a recovery time of 5 seconds per pixel. An alternative, the orientation sensor, also proved effective, yielding 70% accuracy at 10 seconds per pixel. This highlights a critical web security vulnerability where sensitive visual information, normally protected by cross-origin policies, can be exfiltrated.

The second attack case study focused on AES key byte recovery as a local attacker. Here, a malicious Android application installed on the device aims to extract secret cryptographic keys. The target was an AES implementation that utilizes hardware-accelerated instructions, specifically AESENC (AES encryption round) and AESMC (AES mix columns). These instructions, common in modern CPUs, perform sub-parts of an AES round. The attacker's strategy involved precisely timing the invocation of these AES instructions to align with the previously profiled sensor measurement intervals. This synchronization ensures that the power consumption patterns generated by the AES operations are captured effectively by the sensor. The core of the attack relies on the principle of data-dependent power consumption: different key bytes will cause different internal bit toggles during AES operations, leading to distinct power profiles. By collecting sensor signals during AES operations, and using a known power model (which predicts the power consumption for different hypothetical key bytes, often based on Hamming weight or bit toggling of intermediate values), the attacker can perform a correlation attack. The malicious app tries out different hypothetical key bytes, computes their expected power consumption according to the model, and correlates these predictions with the observed sensor traces. A high correlation indicates a likely correct key byte. Through this method, the researchers successfully recovered several AES key bytes, demonstrating a potent threat to cryptographic implementations on Android devices.

Defensive Implications

▶ Watch: Peculiar finding: Orientation-dependent leakage observed in sensors (7:15)

The discovery of power-related side-channel attacks via the Android sensor framework presents a formidable challenge for defenders, primarily due to the unprivileged, software-only nature of the attacks and their reliance on fundamental hardware interactions.

Mitigation Challenges:

  • Fundamental Design: The interference between CPU activity and sensor ADCs is a hardware-level phenomenon, making purely software-based patches difficult without significant performance overhead or hardware redesign.
  • Unprivileged Access: Since the attack requires no elevated permissions, traditional sandboxing and permission models are ineffective. Any app with access to sensors (which is almost all apps) could potentially mount such an attack.
  • Sensor Necessity: Sensors are integral to many legitimate Android functionalities. Disabling or severely restricting them would cripple device utility.
  • Subtlety of Leakage: The leakage is subtle and often manifests as small fluctuations in sensor readings, making detection challenging without specific anomaly detection systems.

Potential Defensive Strategies:

  1. Sensor Data Granularity and Noise Injection: One approach could be for the Android OS to introduce random noise or reduce the precision of sensor readings for unprivileged applications, particularly when significant CPU activity is detected. This could obscure the subtle power-related fluctuations without completely disabling the sensors. However, this might negatively impact legitimate applications requiring high-precision sensor data.
  2. Adaptive Sampling Rates: The OS could dynamically lower the sampling rate of sensors for background applications or when sensitive operations are known to be occurring. This would reduce the temporal resolution available to an attacker, making it harder to align attacks with specific computational events.
  3. CPU Scheduling and Isolation Enhancements: More aggressive CPU scheduling policies could be implemented to isolate sensitive computations. For example, when cryptographic operations are performed, the OS could attempt to minimize concurrent CPU activity from other applications or schedule the cryptographic task on a physically isolated core if available. This is complex and could introduce performance overhead.
  4. Hardware-Level Shielding and Design: Device manufacturers could improve the electromagnetic shielding around ADCs and sensor components to reduce their susceptibility to CPU interference. This is a long-term hardware solution but would be the most robust defense.
  5. API Restrictions and Anomaly Detection: The Android framework could introduce more granular permissions for sensor access, especially for high-frequency or specific sensitive sensors (like the geometric rotation vector sensor). Furthermore, on-device machine learning models could be developed to detect anomalous sensor patterns that correlate with suspicious CPU activity, potentially flagging malicious apps.
  6. Browser-Level Defenses for Web Attacks: For the pixel stealing attack, web browsers could enhance their isolation of iframes, particularly when SVG filters are applied to cross-origin content. Restricting sensor access to the main frame or introducing delays/noise in sensor readings during such operations could mitigate this specific vector.
  7. Randomization and Jitter for Cryptographic Operations: Developers of cryptographic libraries can implement countermeasures such as randomizing execution times or introducing dummy operations (jitter) into their algorithms. This makes the power consumption patterns less predictable and harder for an attacker to correlate.
  8. User Awareness: While not a technical defense, educating users about the risks of installing untrusted applications or visiting malicious websites remains crucial, as many side-channel attacks rely on the presence of attacker-controlled code on the device.

Ultimately, mitigating these attacks will likely require a multi-layered approach involving hardware design improvements, operating system enhancements, and developer best practices.

Key Takeaways

  • The Android sensor interface can be leveraged as an unprivileged, software-only proxy for measuring device power consumption, circumventing traditional security barriers.
  • CPU activity (utilization, instruction types, data operands) significantly influences sensor readings across a wide range of Android devices, with up to 43.8% of evaluated sensors showing statistically significant correlations with data operands.
  • Specific leakage properties, such as sensor integration intervals and orientation-dependent interference, can be precisely profiled and exploited to refine side-channel attacks.
  • The research demonstrated practical attack case studies, including a web-based pixel stealing attack (recovering images with 90.2% accuracy using the magnetometer) and a local AES key byte recovery attack from a malicious app.
  • The underlying cause for data-dependent power consumption leakage is the switching behavior of CMOS gates in the CPU, where more bit toggling consumes more power, which is then detectable via sensors.
  • Mitigating these attacks is challenging due to their software-only nature and reliance on fundamental hardware interactions, necessitating a multi-faceted defensive strategy involving hardware, OS, and application-level countermeasures.

About the Speaker(s)

Mathias Oberhuber is the speaker who presented the paper "Power-Related Side-Channel Attacks using the Android Sensor Framework" at the NDSS Symposium. His research focuses on identifying and exploiting subtle side-channel leakage through common device interfaces, specifically demonstrating how the Android sensor framework can be used as an indirect channel for power measurements. His work highlights critical vulnerabilities in mobile device security and contributes to the broader understanding of practical side-channel attacks in real-world scenarios.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid original research demonstrating that the Android sensor API leaks power side-channel information sufficient to recover AES key bytes and steal cross-origin pixel data — no privileges required. The attack surface is novel, the cross-device validation is rigorous, and the dual PoCs (local crypto and remote web) land the threat model convincingly. It stops just short of a 5 because the sensor-as-power-proxy intuition isn't entirely unprecedented in academic literature, and the AES key recovery results feel partially scoped rather than full-key.

Heather Calloway (CISO) — WEAK

Technically credible side-channel research with real findings — but it stops well short of telling anyone with authority what to do next. The gap between 'this is measurable' and 'here is how a security program responds' is never crossed.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025