LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference

Fengchen Yang (Dr.)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Electromagnetic Attacks

Overview

This talk introduces LightAntenna, a novel and concerning electromagnetic interference (EMI) attack vector that leverages ubiquitous fluorescent lamps to inject malicious signals into nearby Internet of Things (IoT) devices and microphones. Presented by Yan Jang on behalf of the author, Dr. Fengchen Yang, this research delves into the previously unclarified underlying principles of how fluorescent lamps generate EMI and demonstrates their potential for targeted attacks. The work systematically characterizes the lamp's performance as an antenna, quantifies its impact, and explores its practical implications for sensor manipulation and voice command injection.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to LightAntenna and EMI problem
  2. 2:40 Underlying principle: fluorescent lamp as an antenna
  3. 4:10 Designing LightAntenna: controlling EMI generation
  4. 6:00 Successful EMI attacks on various sensors
  5. 6:25 Voice injection attack results and recognition rates
  6. 7:55 Real-world impact of grid components and devices
  7. 9:30 Summary of LightAntenna contributions and future work

LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference

Speakers: Fengchen Yang (Dr.)

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=WHwlvmZr3Yo

Overview

This talk introduces LightAntenna, a novel and concerning electromagnetic interference (EMI) attack vector that leverages ubiquitous fluorescent lamps to inject malicious signals into nearby Internet of Things (IoT) devices and microphones. Presented by Yan Jang on behalf of the author, Dr. Fengchen Yang, this research delves into the previously unclarified underlying principles of how fluorescent lamps generate EMI and demonstrates their potential for targeted attacks. The work systematically characterizes the lamp's performance as an antenna, quantifies its impact, and explores its practical implications for sensor manipulation and voice command injection.

The significance of LightAntenna cannot be overstated. Fluorescent lamps are pervasive across various environments, from homes and offices to medical facilities and industrial settings. While sporadic reports of fluorescent lamp-induced interference with devices like iPhone touchscreens, Surface laptops, and radio/TV signals have surfaced in the past, the fundamental mechanism remained poorly understood. This research not only elucidates this mechanism but also weaponizes it, transforming a common lighting fixture into an unexpected tool for cyberattacks. The ability to manipulate sensors or inject voice commands using existing infrastructure highlights a critical, overlooked vulnerability in the ever-expanding IoT landscape.

Background

▶ Watch: Introduction to LightAntenna and EMI problem (0:00)

The problem addressed by LightAntenna stems from a known, yet poorly understood, phenomenon: the electromagnetic interference generated by fluorescent lamps. For years, users and manufacturers have observed that fluorescent lighting can disrupt the operation of various electronic devices, including sensitive touchscreens, radio receivers, and even internet connections. Despite these anecdotal and reported interferences, a comprehensive technical explanation for why and how fluorescent lamps produce such interference, and more importantly, whether this interference could be intentionally controlled and weaponized, was lacking.

Traditional EMI attacks often rely on specialized, purpose-built antennas designed for efficient signal radiation. Fluorescent lamps, by contrast, are designed solely for illumination, not for transmitting controlled electromagnetic signals. This disparity posed a fundamental question: could a device not intended for signal transmission effectively function as an antenna? Furthermore, if it could, what were the limits of its performance, and what specific components of the lamp were responsible for the EMI? This research aimed to answer these questions by understanding the underlying principles of fluorescent lamp-induced EMI, quantifying its impact on IoT devices, and investigating its potential for manipulating various sensors and microphones. The goal was to move beyond mere observation of interference to a systematic characterization and demonstration of a controllable attack vector, thus revealing a new class of threats in environments where fluorescent lighting is prevalent.

Key Findings

▶ Watch: Designing LightAntenna: controlling EMI generation (4:10)

The LightAntenna research yielded several critical findings that fundamentally redefine our understanding of fluorescent lamp EMI and its potential for exploitation:

  1. Underlying Principle of EMI Generation: The core discovery is that the ionized gas within a fluorescent lamp forms a plasma with electrical conductivity. This plasma effectively transforms the lamp's tube into an antenna, capable of radiating electromagnetic signals. This explains why fluorescent lamps, unlike incandescent or LED lamps, are prone to generating significant EMI.
  2. EMI Source Localization: Through systematic measurements, the researchers conclusively demonstrated that the primary source of EMI is the tube of the fluorescent lamp, rather than the power source or the ballast circuit. This finding is crucial for understanding how to effectively control and modulate the emitted interference.
  3. Ideal Frequency Response for Attacks: The lamp-induced EMI exhibits an ideal frequency response, particularly within a band suitable for various EMI attacks. This characteristic makes it a viable medium for transmitting malicious signals.
  4. Successful Sensor Manipulation: The LightAntenna attack successfully manipulated eight different digital and analog sensor modules. A notable demonstration involved the precise manipulation of an industrial temperature sensor, achieving an "upturning manipulation" of its reported temperature value. This highlights the potential for disrupting critical infrastructure or industrial processes.
  5. High-Fidelity Voice Injection: The research achieved successful voice command injection into microphones, including those commonly found in meeting rooms (e.g., a gooseneck microphone). By injecting 50 sentences, the attack demonstrated impressive recognition rates of over 70% for sentences and 91% for individual words using typical speech recognition models. This capability enables silent, covert control of voice-activated smart devices.
  6. Antenna Performance Characterization: While the EMI performance of a fluorescent lamp was found to be weaker than dedicated directional antennas, it was comparable to the performance of near-field magnetic probes. This indicates that while not a long-range weapon, it is effective in close proximity, which is typical for many IoT deployments.
  7. Grid Impact and Environmental Factors: The study revealed that attack signals must be injected into the specific phase of the power grid connected to the target lamp. Crucially, common grid components like main switches and leakage protectors have minimal impact on the LightAntenna's effectiveness. However, isolation transformers were found to block the attack signal. Interestingly, the presence of another fluorescent lamp connected to the same grid branch as the target lamp enhanced the EMI signal, suggesting potential for signal amplification in multi-lamp environments. Other devices like desktop chargers and speakers had negligible effects.
  8. Practical Attack Device: To demonstrate real-world applicability, the researchers designed and implemented a portable and cost-saving attack device, showcasing that LightAntenna is not merely a theoretical concept but a practical and deployable attack method.

These findings collectively establish fluorescent lamps as a credible, controllable, and pervasive vector for EMI-based attacks, necessitating a re-evaluation of security postures in environments where these lamps are used.

Technical Deep Dive

▶ Watch: Successful EMI attacks on various sensors (6:00)

The technical foundation of LightAntenna rests on a clever exploitation of the physical properties of fluorescent lamps. Unlike incandescent bulbs that produce light through a heated filament or LEDs that use semiconductors, fluorescent lamps rely on the excitation of gas. When electricity passes through the inert gas (typically argon and mercury vapor) inside the glass tube, it ionizes, forming a plasma. This plasma is electrically conductive, and crucially, it can be modulated. The core insight of LightAntenna is that this plasma-filled tube can act as an antenna, radiating electromagnetic waves when the electrical signal driving it is manipulated.

To confirm the source of EMI, the researchers conducted comparative measurements. They tested incandescent lamps, LED lamps, the ballast of a fluorescent lamp, and the fluorescent lamp tube itself. The results unequivocally showed that the significant EMI emanated primarily from the tube, not the power source or the ballast. This established the lamp tube as the active radiating element.

The attack methodology involves two main steps:

  1. Controlling the Fluorescent Lamp to Generate EMI: This requires injecting malicious signals into the lamp's power line. Recognizing that fluorescent lamps can be powered by either an AC grid or a DC battery (e.g., emergency lighting), the researchers designed two specific couplers: an RF AC coupler and an RF DC coupler. These couplers allow the attacker to superimpose high-frequency attack signals onto the lamp's operational power supply. A critical question was whether the lamp's ballast circuit, designed to regulate current, would permit the transmission of these high-frequency attack signals. A comprehensive frequency sweep test on both AC and DC ballasts confirmed that they indeed allow the transmission of high-frequency signals, thus enabling the attack.
  2. Modulating EMI to Manipulate IoT Devices: The second step involves controlling the generated EMI to carry specific malicious data. The researchers adopted Amplitude Modulation (AM) as the method for encoding their signals. For simple attacks like manipulating a sensor with a specific frequency, the desired frequency wave was set as the baseband signal. For more complex attacks, such as injecting voice commands, the actual voice signal was used as the baseband.

For sensor manipulation, eight diverse digital and analog sensor modules were selected for testing. To ensure the integrity of their experiments and prevent external interference, an EMI shielding box was utilized. By injecting EMI of different frequencies into the fluorescent lamp, the researchers successfully achieved EMI attacks on all tested sensors. A particularly impactful demonstration involved an industrial temperature sensor, where they achieved an "upturning manipulation," causing the sensor to report an artificially inflated temperature value. This could have severe consequences in industrial control systems or critical infrastructure.

The voice injection attack targeted microphones, specifically a gooseneck microphone typical in meeting room settings. To verify the lamp's capability to inject signals within the human speech band, a modulated 0-2 kHz chirp signal was injected. The frequency response confirmed that the lamp-induced EMI could effectively cover the entire speech band. Drawing parallels to previous research like "Ghost Talk" (which also uses EMI for voice injection), the researchers compiled a dataset of 50 common sentences. These sentences were injected into the microphone via the fluorescent lamp and then processed by typical speech recognition models. The results were remarkably successful, with a recognition rate of over 70% for sentences and an even higher 91% for individual words. This demonstrates a potent capability for silently controlling voice-activated assistants or eavesdropping.

Further technical evaluation included characterizing the lamp's antenna performance by comparing its signal intensity and attack distance against eight different metal antennas. While the fluorescent lamp's EMI performance was weaker than dedicated directional antennas, it was found to be comparable to near-field magnetic probes, indicating its effectiveness in localized attack scenarios.

Finally, the research investigated the impact of real-world power grid components. A three-phase distribution cabinet was constructed for this evaluation. Key findings included:

  • The attack signal must be injected into the specific phase connected to the target lamp.
  • Common grid elements like main switches and leakage protectors had negligible impact on the LightAntenna's effectiveness.
  • Isolation transformers were identified as an effective blocker of the attack signal.
  • Other devices like working desktops, chargers, and speakers connected to the same branch had minimal effect.
  • Crucially, the presence of another fluorescent lamp on the same grid branch significantly enhanced the EMI signal, suggesting potential for amplified attacks in multi-lamp environments.

This detailed technical analysis underscores the sophistication of the LightAntenna attack, demonstrating a comprehensive understanding of the underlying physics, practical implementation challenges, and real-world environmental factors.

Demo / Proof of Concept

▶ Watch: Real-world impact of grid components and devices (7:55)

The talk included several compelling demonstrations and proofs of concept to validate the LightAntenna attack's feasibility and effectiveness.

For sensor manipulation, the researchers demonstrated successful EMI attacks on all eight selected digital and analog sensor modules. A particularly impactful example highlighted the manipulation of an industrial temperature sensor. By injecting specific EMI signals, they were able to achieve an "upturning manipulation" of the temperature value reported by the sensor, showcasing the potential for malicious data alteration in critical applications. This proof of concept validated the ability to introduce arbitrary, controlled errors into sensor readings.

The voice injection attack was vividly demonstrated by injecting voice commands into a common gooseneck microphone, similar to those found in conference rooms. The researchers successfully injected the "Okay Google" command, indicating the ability to trigger voice assistants covertly. Further, they systematically injected 50 distinct sentences into the microphone and processed the recorded audio through standard speech recognition models. The high recognition rates—over 70% for complete sentences and an even more impressive 91% for individual words—served as a strong proof of concept for the attack's effectiveness in delivering intelligible voice commands or even covert messages.

Beyond these specific attack demonstrations, the researchers also presented the design of a portable and cost-saving attack device. This physical proof of concept showcased that LightAntenna is not merely a theoretical exercise but a practical, deployable attack method. The existence of such a device underscores the real-world applicability and accessibility of this novel EMI attack. The systematic analysis of how fluorescent lamps generate and can be controlled to produce EMI, coupled with the successful attacks on various sensors and microphones, firmly established LightAntenna as a significant new threat vector.

Defensive Implications

▶ Watch: Summary of LightAntenna contributions and future work (9:30)

The LightAntenna research uncovers a pervasive and previously overlooked attack surface, necessitating a re-evaluation of security practices, especially in environments heavily reliant on fluorescent lighting and sensitive IoT devices. Defenders must consider several strategies to mitigate this novel threat:

  1. Switch to LED Lighting: The most straightforward and effective countermeasure highlighted by the researchers is the adoption of LED lamps. Unlike fluorescent lamps, LEDs do not rely on ionized gas and therefore do not inherently produce the same type of plasma-induced EMI that facilitates the LightAntenna attack. This provides a fundamental shift away from the vulnerable infrastructure.
  2. Physical Separation and Placement: For existing fluorescent lighting installations, a simple yet effective strategy is to increase the physical distance between sensitive IoT devices (especially microphones and critical sensors) and fluorescent lamps. As EMI intensity generally diminishes with distance, relocating devices "far from the fluorescent lamps" can significantly reduce the attack's efficacy.
  3. Electromagnetic Shielding: Implementing physical shielding around sensitive devices can provide a robust defense. The researchers suggest using "metal shields" that can block electromagnetic interference while still allowing light to pass through. This could involve integrating shielding into device enclosures or deploying shielded cabinets for critical equipment. This is particularly relevant for industrial and medical IoT devices where data integrity is paramount.
  4. Isolation Transformers: The research specifically identified isolation transformers as effective blockers of the LightAntenna attack signal. Deploying isolation transformers on power lines feeding critical devices or even entire network segments within vulnerable environments could prevent the malicious signals from reaching their targets.
  5. Device Hardening and EMI Resilience: Manufacturers of IoT devices, particularly those with embedded sensors or microphones, should consider integrating enhanced EMI resilience into their designs. This includes improved filtering on power inputs, robust grounding, and selecting components that are less susceptible to external electromagnetic fields.
  6. Awareness and Risk Assessment: Organizations, especially those in sectors like healthcare, manufacturing, and smart building management, must be made aware of the LightAntenna threat. Conducting thorough risk assessments for environments with fluorescent lighting and sensitive IoT deployments is crucial to identify potential vulnerabilities and prioritize mitigation efforts.
  7. Microphone Sensitivity and Filtering: For voice-controlled systems, exploring advanced audio processing techniques that can distinguish between human speech and machine-generated or EMI-injected speech could be a future defensive avenue. While the current research showed high recognition rates for injected speech, further research into AI-based speech recognition models with robust EMI filtering capabilities might offer some protection.

In conclusion, the LightAntenna attack underscores the need for a holistic approach to security that considers not just software and network vulnerabilities but also the physical and electromagnetic environment in which devices operate. Proactive measures, ranging from infrastructure upgrades to careful device placement and shielding, are essential to protect against this novel and pervasive threat.

Key Takeaways

  • Fluorescent lamp tubes, due to their ionized gas forming a plasma, can be repurposed as effective antennas for electromagnetic interference (EMI) attacks.
  • This novel attack vector, dubbed LightAntenna, leverages ubiquitous lighting infrastructure to inject malicious signals.
  • LightAntenna can successfully manipulate various IoT sensors, including industrial temperature sensors, demonstrating the potential for critical data corruption.
  • High-fidelity voice commands can be injected into microphones (e.g., "Okay Google") with high recognition rates (over 70% for sentences, 91% for words), enabling covert control of smart devices.
  • The attack is practical and deployable, as evidenced by the design of a portable, cost-saving attack device and its effectiveness despite common power grid components.
  • Effective mitigations include switching to LED lamps, increasing physical distance between devices and lamps, employing EMI shielding, and utilizing isolation transformers on power lines.

About the Speaker(s)

The paper "LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference" was authored by Dr. Fengchen Yang. The presentation at the NDSS Symposium was delivered by Yan Jang on behalf of Dr. Yang, who was unable to attend due to unexpected circumstances. No further biographical details or affiliations beyond "Dr." and "author" were provided in the transcript or metadata.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid novel research that turns a ubiquitous piece of infrastructure into a controlled attack surface — the plasma-as-antenna insight is genuinely clever and the empirical characterization (source localization, frequency sweep on ballasts, grid component analysis) shows real systematic work. Recognition rates on injected voice commands are high enough to matter in practice, and the industrial sensor manipulation demo is the kind of thing that makes ICS defenders pay attention.

Heather Calloway (CISO) — PASS

Technically credible EMI research that repurposes fluorescent lamp plasma physics as a novel attack vector. Outside my lane — no meaningful governance angle, no institutional accountability dimension, and no decision this produces for a CISO, board, or policy body.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025