GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference
Yanze Ren
Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Electromagnetic Attacks
Overview
In a groundbreaking presentation at the NDSS Symposium, Yanze Ren unveiled "GhostShot," a novel attack demonstrating the ability to manipulate images captured by Charge-Coupled Device (CCD) cameras using precisely engineered Electromagnetic Interference (EMI) signals. This research significantly expands the known attack surface against these pervasive imaging sensors, which are critical components in a vast array of intelligent systems, including fire detection, night vision, barcode scanning, and medical diagnostics. The talk highlighted the severe implications of such an attack, where an adversary could inject arbitrary, colorful patterns into camera feeds under normal lighting conditions, potentially leading to catastrophic misjudgments by automated systems or human operators.
Key moments
- 0:00 Introduction to GhostShot and research question
- 1:50 Demonstrating practical attack examples (false cars, fire)
- 2:30 Explaining CCD camera workflow and EMI vulnerability
- 3:50 Technical explanation: Aliasing effect and color generation
- 5:00 Controlling injected image morphology, brightness, and color
- 7:00 Evaluation results and real-world case studies
- 8:40 Proposed countermeasures and conclusion
GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference
Speakers: Yanze Ren
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=mJOC0xrPCz0
Overview
In a groundbreaking presentation at the NDSS Symposium, Yanze Ren unveiled "GhostShot," a novel attack demonstrating the ability to manipulate images captured by Charge-Coupled Device (CCD) cameras using precisely engineered Electromagnetic Interference (EMI) signals. This research significantly expands the known attack surface against these pervasive imaging sensors, which are critical components in a vast array of intelligent systems, including fire detection, night vision, barcode scanning, and medical diagnostics. The talk highlighted the severe implications of such an attack, where an adversary could inject arbitrary, colorful patterns into camera feeds under normal lighting conditions, potentially leading to catastrophic misjudgments by automated systems or human operators.
The core innovation of GhostShot lies in its capability to achieve fine-grained, colorful image injection, moving beyond prior work that was limited to grayscale patterns or required dark environments. By exploiting the analog nature of CCD camera components, particularly the Analog-to-Digital Converter (ADC), the research team demonstrated how targeted EMI could induce specific visual alterations. This talk serves as a stark warning about the often-overlooked vulnerabilities in ubiquitous camera systems and underscores the urgent need for robust defensive measures to protect against sophisticated electromagnetic attacks.
Background
▶ Watch: Introduction to GhostShot and research question (0:00)
The ubiquitous nature of CCD cameras makes them a prime target for adversarial manipulation. These devices are fundamental to the operation of countless systems where visual information drives critical decisions. Prior research has explored various methods to interfere with camera functionality, ranging from laser signals causing pixel saturation and blinding, to acoustic signals inducing vibrations and image distortions, and even preliminary forms of intentional EMI that could blur images, introduce rolling colors, or generate glitch patterns.
More recently, the security community has seen the emergence of attacks capable of more precise manipulation, specifically the injection of grayscale images into camera feeds, albeit primarily in dark environments. This prior work, while significant, hinted at a deeper vulnerability that GhostShot aimed to fully explore. The central question driving the GhostShot research was whether it was possible to overcome these limitations – to inject arbitrary, vibrant, and colorful patterns into images captured by CCD cameras, not just in controlled dark settings, but under normal, ambient light conditions, and to understand the full extent of an attacker's capabilities and the potential harm. The answers presented in this talk reveal a concerning expansion of the attack surface, demonstrating that such sophisticated visual deception is not only possible but alarmingly effective.
Key Findings
▶ Watch: Explaining CCD camera workflow and EMI vulnerability (2:30)
The GhostShot research conclusively demonstrates that it is indeed possible to inject arbitrary, colorful patterns into images captured by CCD cameras under any ambient light conditions. This capability represents a significant advancement over previous attacks. The team successfully validated their attack methodology across a diverse set of 15 CCD cameras, encompassing both analog and digital models, achieving 100% success in image injection. Their findings reveal a sophisticated control mechanism allowing for the precise manipulation of morphology, brightness, and color of the injected patterns.
The practical implications of this attack were highlighted through several compelling case studies:
- Medical Diagnosis: GhostShot could facilitate "creation attacks" (injecting false anomalies) or "hiding attacks" (obscuring real issues), leading to misdiagnosis by automated detection algorithms or human clinicians.
- Fire Detection Systems: The injection of artificial fires could trigger false alarms or, conversely, hide genuine fire incidents, with potentially catastrophic consequences.
- Barcode Scanning: Malicious barcodes could be injected, leading to incorrect product identification, fraudulent transactions, or supply chain disruptions.
- Night Vision Systems: Adversaries could inject false objects, such as non-existent cars or humans, into night vision feeds, confusing security personnel or autonomous vehicles.
Furthermore, user studies conducted by the researchers indicated that human observers monitoring the affected CCD camera feeds often failed to detect the injected manipulations, mistaking them for genuine elements within the captured scene. This finding underscores the stealth and effectiveness of the GhostShot attack, making it a potent tool for deception and disruption.
Technical Deep Dive
▶ Watch: Technical explanation: Aliasing effect and color generation (3:50)
The GhostShot attack meticulously exploits the fundamental workflow and inherent vulnerabilities within CCD camera architecture. A CCD sensor operates by converting light into an electrical charge, which is then processed to form an image. This process involves several key components:
- Photo Diodes: These convert incoming light photons into an electrical charge. Most modern CCD cameras utilize color filters (typically Bayer filters for RGB) over individual photo diodes, meaning each diode only registers a specific color (red, green, or blue).
- Shift Registers: After charge accumulation, these registers read out the accumulated charges from the photo diodes, typically row by row, transferring them sequentially.
- Analog-to-Digital Converter (ADC): This crucial component takes the analog electrical charges from the shift registers and converts them into digital values, which are then assembled to form the final digital image.
The core vulnerability targeted by GhostShot lies within the ADC component. Being an analog part of the camera's processing chain, the ADC is particularly susceptible to Electromagnetic Interference (EMI). The researchers conducted preliminary experiments, sweeping various frequencies of EMI signals, and observed that different frequencies induced distinct patterns, such as stripes or varying grayscale levels, in the captured images. Furthermore, even unmodulated EMI signals were capable of inducing color into these patterns, suggesting a deeper interaction with the camera's color processing.
The underlying principle explaining these manipulations is the aliasing effect. When an analog signal (like the electrical charge from the photo diodes) is sampled by the ADC, if the sampling frequency is not at least twice the highest frequency component of the analog signal (Nyquist-Shannon sampling theorem), aliasing occurs. This means that high-frequency components in the EMI signal can "fold back" into lower frequencies within the sampled digital signal, creating artifacts that appear as real image data. The relationship between the alias frequency and the camera's internal sampling frequency directly influences the form and appearance of the injected patterns.
Crucially, the researchers discovered how to generate color in the injected images. If the EMI signal induces a synchronized sampling across the red, green, and blue (RGB) channels, the resulting injected pattern appears black and white. However, by carefully crafting EMI signals to induce insynchronized sampling between the RGB channels, the attack can generate a wide spectrum of colors. This differential interference across color channels is key to GhostShot's ability to inject vibrant, colorful patterns.
To achieve precise control over the injected images, GhostShot employs sophisticated EMI signal modulation techniques:
- Morphology Control (Shape and Form): The attack uses Amplitude Modulation (AM). By modulating the amplitude of the EMI carrier frequency differently for various "rows" or scan lines of the camera sensor, specific shapes and patterns can be formed. Altering the carrier frequency itself further refines the clarity and definition of these injected patterns.
- Brightness Control: Phase Modulation (PM), specifically phase shifting the EMI signals, is utilized to manipulate the brightness or intensity of the injected patterns. By adjusting the phase relationship between the interfering signal and the camera's internal timing, the perceived luminance of the injected pixels can be controlled.
- Color Control: The most advanced aspect of GhostShot's technical prowess involves combining both Amplitude Modulation and Phase Modulation. This dual-modulation strategy allows for the independent manipulation of amplitude and phase across different color channels or during different stages of the camera's readout, thereby enabling the generation of specific and arbitrary colors within the injected image. (For intricate details on the precise interplay of AM and PM for color generation, the authors refer to their full paper.)
The overall attack workflow comprises three main stages:
- Image Pre-processing: A target image (e.g., a false car, a malicious barcode) is first pre-processed. This involves decomposing the image into its constituent components and carefully computing the necessary parameters, such as the spatial location and color values, that need to be replicated through EMI. This stage requires prior knowledge of the target camera's characteristics to accurately map the desired image onto the sensor's readout process.
- EMI Signal Generation: Based on the pre-processed image data, the corresponding EMI signals are synthesized. This involves calculating the precise amplitude, phase, and frequency modulation schemes required to induce the desired aliasing effects and insynchronized sampling across the RGB channels.
- Signal Injection: The generated EMI signals are then transmitted, typically through an antenna, to interfere with the target CCD camera. The camera's ADC, being susceptible to these analog interferences, then incorporates the malicious patterns into its digital output, resulting in the injected image appearing seamlessly within the camera's live feed.
Demo / Proof of Concept
▶ Watch: Evaluation results and real-world case studies (7:00)
While the live demonstration itself was not included in the provided transcript, the talk extensively showcased the capabilities of the GhostShot attack through visual examples and described case studies, serving as compelling proofs of concept. The speaker presented "images captured after our attack" at the 2:00 mark, which vividly illustrated the injection of false cars, malicious barcodes, and artificial fires.
Further demonstrations of the attack's efficacy were detailed through the practical case studies:
- In the context of medical diagnosis, the research indicated how malicious EMI could create or hide critical features in medical images, thus demonstrating a direct impact on diagnostic accuracy.
- For fire detection systems, the ability to inject "artificial fires" into the camera feed directly demonstrated how GhostShot could mislead automated systems designed to detect emergencies.
- The injection of malicious barcodes highlighted the potential for industrial sabotage or fraud, showing a clear, actionable attack vector against scanning systems.
- Lastly, the ability to inject "some human or cars into the night vision cameras" exemplified the attack's potential to disrupt surveillance and autonomous navigation systems operating in low-light conditions.
These scenarios, coupled with the successful evaluation across 15 different CCD cameras, collectively serve as a robust proof of concept, illustrating the practical feasibility and significant threat posed by the GhostShot attack. The mention of an online demo ("find our website") further suggests the availability of a functional implementation, allowing interested parties to witness the attack firsthand.
Defensive Implications
▶ Watch: Proposed countermeasures and conclusion (8:40)
The GhostShot attack reveals a significant blind spot in the security posture of many systems reliant on CCD cameras. To mitigate this novel threat, the researchers proposed several potential countermeasures, encompassing both hardware and software solutions:
- EMI Shielding: The most direct hardware defense involves physically shielding CCD cameras. Encasing cameras in materials that block or attenuate electromagnetic radiation, such as metallic enclosures or Faraday cages, can prevent malicious EMI signals from reaching the sensitive internal components, particularly the ADC. This approach aims to reduce the signal-to-noise ratio of the attacker's EMI below the threshold required for successful manipulation.
- Low-Pass Filters: Implementing low-pass filters at the input stage of the camera's analog signal processing chain, especially before the ADC, can help. These filters are designed to block high-frequency signals, including those used by the GhostShot attack to induce aliasing. By filtering out frequencies above the legitimate signal bandwidth, the camera can become more resilient to out-of-band EMI. This could be a hardware modification or an integrated circuit design decision.
- Image Forgery Detection (Software): On the software front, developing and deploying advanced image forgery detection algorithms is crucial. These algorithms could analyze incoming video streams for anomalies indicative of EMI-induced manipulation. This might involve looking for unusual pixel patterns, inconsistencies in color distribution, or deviations from expected sensor noise characteristics that are difficult for an attacker to perfectly mimic. Machine learning models trained on both legitimate and EMI-attacked images could potentially identify such subtle indicators, providing an alert mechanism to human operators or downstream intelligent systems.
These proposed defenses underscore the need for a multi-layered security approach, combining physical protection against electromagnetic threats with intelligent software-based anomaly detection to safeguard critical camera-dependent systems.
Key Takeaways
- Arbitrary Colorful Image Injection: GhostShot demonstrates the unprecedented ability to inject arbitrary, colorful patterns into CCD camera feeds, even under normal ambient light conditions, overcoming limitations of prior grayscale or dark-environment attacks.
- Widespread Vulnerability: The attack was successfully validated against 15 different CCD cameras, highlighting a pervasive vulnerability across various models, including both analog and digital types.
- Exploitation of ADC and Aliasing: The core of the attack lies in exploiting the analog nature of the CCD camera's Analog-to-Digital Converter (ADC) and leveraging the aliasing effect caused by precisely timed Electromagnetic Interference (EMI) signals.
- Fine-Grained Control: Adversaries can achieve precise control over the injected image's morphology (shape), brightness, and color through sophisticated Amplitude Modulation (AM) and Phase Modulation (PM) of the EMI signals, especially by inducing insynchronized sampling across RGB channels for color.
- Severe Real-World Impact: Case studies demonstrate the potential for significant harm across critical applications, including misdiagnosis in medical systems, false alarms/suppression in fire detection, fraudulent barcode scanning, and deception in night vision systems.
- Multi-Layered Defense Needed: Proposed countermeasures include hardware solutions like EMI shielding and low-pass filters, alongside software-based image forgery detection algorithms, emphasizing the need for comprehensive protection.
About the Speaker(s)
Yanze Ren is the presenting speaker for the "GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference" paper. While the transcript does not provide specific details about Yanze Ren's title or affiliation, the speaker explicitly stated, "it's my honor again to present this paper on behalf of my colleagues," indicating that this research is a collaborative effort by a team, with Yanze Ren serving as a key researcher and presenter for the group.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
GhostShot is legitimate hardware security research that advances the state of the art on transient electromagnetic injection attacks against CCD imaging pipelines. The jump from prior grayscale-only, dark-environment injection to arbitrary colorful patterns under ambient light conditions is a real technical contribution — not a marginal one — and the 100% success rate across 15 devices suggests the vulnerability class is structural, not incidental.
Heather Calloway (CISO) — WEAK
Technically credible research demonstrating a real and underappreciated attack surface against CCD cameras. But the talk stops at 'here's what we broke' and never closes the distance to the people responsible for protecting the systems being broken.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025