HubBub: Contention-Based Side-Channel Attacks on USB Hubs
Junpeng Wan (PT student · Purdue University)
34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Hardware Security 2
Overview
The "HubBub" talk at USENIX Security unveils a novel class of side-channel attacks that exploit hardware contention within Universal Serial Bus (USB) hubs. Presented by Junpeng Wan from Purdue University, this research highlights how the shared nature of USB bus resources, a fundamental aspect of hub design, can be leveraged by attackers to infer sensitive information from co-located devices. This work is particularly pertinent given the increasing reliance on USB hubs in modern computing environments, especially with the proliferation of laptops featuring fewer integrated ports, necessitating external expansion.

Key moments
- 0:00 Introduction to HubBub and USB hub contention
- 2:00 Attacker models: Host-based vs. device-based
- 2:20 Attack A: Inferring victim's website visits
- 3:00 Technical steps: Saturating USB hub bandwidth
- 4:40 Attack A evaluation results and hub generalizability
- 5:55 Attack B: Inferring webcam activities (light on/off)
- 6:30 Attack C: Capturing keystrokes from USB keyboard
HubBub: Contention-Based Side-Channel Attacks on USB Hubs
Speakers: Junpeng Wan, PT Student, Purdue University
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=aymKFBXHTH0
Overview
The "HubBub" talk at USENIX Security unveils a novel class of side-channel attacks that exploit hardware contention within Universal Serial Bus (USB) hubs. Presented by Junpeng Wan from Purdue University, this research highlights how the shared nature of USB bus resources, a fundamental aspect of hub design, can be leveraged by attackers to infer sensitive information from co-located devices. This work is particularly pertinent given the increasing reliance on USB hubs in modern computing environments, especially with the proliferation of laptops featuring fewer integrated ports, necessitating external expansion.
The core premise of HubBub is that when multiple USB devices share a single upstream connection via a hub, their data transfers inevitably compete for bandwidth. This contention creates measurable timing variations in data access, which an attacker can monitor to deduce the activity of other devices on the same hub. The research demonstrates the feasibility of these attacks across various USB standards, including USB 2.0, 3.0, and 3.1, and showcases their efficacy against common peripherals like network interface cards (NICs), webcams, and keyboards. The implications are significant, challenging the traditional assumption of isolation between devices connected to a shared USB hub and opening new avenues for covert data exfiltration and surveillance.
Background
▶ Watch: Introduction to HubBub and USB hub contention (0:00)
Hardware sharing is a well-established vector for side-channel attacks across various computing components. Historically, vulnerabilities like Flash+Reload have exploited shared memory, Prime+Probe has targeted shared CPU caches, and Rowhammer has leveraged shared DRAM rows. Beyond memory, other shared resources such as CPU ports, interconnects like Intel's QPI and UPI (formerly M and RI links), and memory controllers have all been identified as potential leakage points. The fundamental reason these vulnerabilities persist is that hardware sharing inherently improves system flexibility, reduces manufacturing costs, and enhances performance by allowing multiple components or processes to efficiently utilize a single resource. However, this efficiency comes at the cost of potential information leakage if not properly isolated.
In this context, USB hubs represent another critical instance of hardware sharing that has largely been overlooked as a side-channel attack surface. A typical USB hub features multiple downstream ports—ranging from standard USB-A and USB-C connectors to HDMI, network interface card (NIC) ports, and USB Power Delivery ports—all funneling their data through a single upstream port to the host system. This architectural design dictates that all connected devices must share the same underlying USB bus bandwidth. While this design is efficient for resource utilization, the research identifies it as a significant security blind spot. The problem is exacerbated by the widespread adoption of USB hubs, both as external peripherals and increasingly as integrated components within monitors and even directly soldered onto motherboards (internal hubs), making them ubiquitous in daily computing. HubBub fills this gap by exploring the information leakage potential arising from contention on these shared USB bus resources.
Key Findings
▶ Watch: Attack A: Inferring victim's website visits (2:20)
The HubBub research makes several critical contributions to the field of hardware security, establishing a new class of side-channel attacks targeting USB hubs. The primary findings include:
- Novel Attack Class: HubBub introduces the first known contention-based side-channel attacks specifically designed to exploit the shared bandwidth of USB hubs. This demonstrates that the implicit sharing of the USB bus can be a significant source of information leakage.
- Broad Applicability Across USB Standards: The attacks were successfully demonstrated on a wide range of USB hub versions, including USB 2.0, USB 3.0, and USB 3.1 hubs. This indicates that the vulnerability is not confined to a specific generation or implementation of USB technology but rather stems from the fundamental shared-bus architecture.
- Extensive Hub Compatibility: The research confirmed the efficacy of HubBub attacks on a diverse set of hardware, including 10 distinct USB 3.0 hubs, four USB 3.1 hubs, one USB 2.0 hub, one internal hub (soldered onto a motherboard), and even a monitor with integrated USB hub functionality. This broad compatibility underscores the pervasive nature of the vulnerability.
- Successful Information Leakage from Multiple Peripherals: HubBub proved capable of extracting sensitive information from at least three common USB peripherals:
- USB Network Interface Cards (NICs): Enabling the inference of visited websites (website fingerprinting).
- USB Webcams: Allowing the deduction of ambient room activities, such as whether a light is turned on or off.
- USB Keyboards: Facilitating the capture of keystrokes.
- High Attack Accuracy: For the website fingerprinting attack (Attack A), the researchers achieved an impressive over 98% accuracy in identifying websites from the top 100 list using machine learning classifiers, highlighting the precision and effectiveness of the side channel.
These findings collectively reveal a previously unaddressed vulnerability in the widely deployed USB ecosystem, demonstrating that the convenience and cost-effectiveness of shared USB hubs come with significant security risks.
Technical Deep Dive
▶ Watch: Technical steps: Saturating USB hub bandwidth (3:00)
The HubBub attack leverages the fundamental principle that when multiple devices connected to a single USB hub transmit data, they contend for the limited upstream bandwidth. This contention introduces measurable delays in data transfer, which can be observed by a malicious actor. The research outlines a general methodology consisting of three main steps, applicable across different attack scenarios.
Threat Models
The HubBub framework considers two primary threat models:
- Host-Based Attacker: This attacker is malicious software running on the host system. It could be a standard process, a program isolated within a virtual machine (VM), or even a malicious script embedded in a web browser. The key requirement is that the attacker has access to at least one USB device connected to the shared hub, which it can control to generate contention.
- Device-Based Attacker: This attacker is a malicious USB device physically attached to the USB hub. This device itself generates the contention and observes the timing variations, potentially without any malicious software running on the host, though often collaborating with host-side software for data processing.
Attack Methodology
The core of HubBub involves a three-step process to exploit USB hub contention:
Step 1: Saturating USB Hub Bandwidth
The first crucial step for the attacker is to create significant contention on the shared USB bus. This is achieved by performing high-speed I/O operations from an attacker-controlled USB device. For instance, in the website fingerprinting attack, the attacker uses a USB SSD and a framework like iouring to perform rapid data accesses.
The researchers conducted a throughput analysis on a typical USB 3.0 hub to understand its effective bandwidth. While the theoretical bandwidth for USB 3.0 is 5 Gbps, practical limitations due to encoding, packet framing, and flow control overhead reduce the actual effective throughput. Their measurements showed that the effective throughput for a USB 3.0 hub was approximately 3.2 Gbps. They found that by adjusting the I/O size to 4 KB, the attacker program could effectively saturate the USB bandwidth, which is critical for inducing measurable contention. This saturation ensures that any additional traffic from a victim device will cause a noticeable delay in the attacker's operations.
Step 2: Recording Timestamps and Analyzing Intervals
Once the hub's bandwidth is saturated, the attacker continuously records the timestamps of its own I/O operations using precise timing mechanisms, such as the RDTSC (Read Time-Stamp Counter) instruction. The intervals between these operations are then calculated. When a victim device (e.g., a USB NIC, webcam, or keyboard) performs an activity, it generates its own unique traffic pattern on the shared USB bus. This victim traffic causes varying levels of congestion, which in turn manifests as distinct fluctuations in the attacker's observed I/O intervals.
The presentation included visual traces demonstrating these distinct patterns. For example, when accessing different websites, the network traffic generated by the USB NIC creates unique "fingerprints" in the contention patterns, which are clearly discernible from each other. These patterns are the raw data that the attacker uses to infer victim activity.
Step 3: Pre-processing and Classification
The raw timing traces collected in Step 2 are often noisy and require pre-processing. After cleaning and normalizing the data, the final step involves training a machine learning or deep learning classifier. The researchers used models such as Gated Recurrent Units (GRU) and attention models to learn the correlation between specific contention patterns and victim activities.
With a properly trained classifier, the attacker can then analyze new, unseen traces to identify the victim's activity. This machine learning approach allows for robust and accurate inference, even in the presence of minor variations or noise.
Specific Attack Scenarios
The research showcased three concrete HubBub attack scenarios:
Attack A: Website Fingerprinting
- Goal: To infer which website the victim is visiting.
- Setup: A USB Network Interface Card (NIC) used by the victim for web browsing is connected to the same USB hub as the attacker's USB SSD. The attacker controls a program (either a standard process or isolated in a VM) with access to the SSD.
- Mechanism: As the victim browses different websites, the web traffic generated by the USB NIC creates unique bandwidth usage patterns. These patterns cause varying levels of contention, which the attacker observes as fluctuations in the read/write times to their USB SSD.
- Evaluation: The researchers evaluated this attack on a USB 3.0 hub. They selected the top 100 websites and collected over 500 traces for each website. This dataset was then split for training and testing. By training GRU and attention models, they achieved an accuracy of over 98% on the test set, demonstrating highly effective website identification. The attack was also confirmed to work on 10 USB 3.0 hubs, four 3.1 hubs, one 2.0 hub, one internal hub, and one monitor with USB hub functionality, highlighting its broad applicability.
Attack B: Webcam Activity Inference
- Goal: To infer activities captured by a webcam, such as whether the room light is turned on or off.
- Setup: A USB webcam and a USB NIC (or another attacker-controlled USB device) are connected to a shared USB hub. The attacker is a JavaScript program embedded in a web page, which can interact with the USB NIC or another device to generate contention. The webcam is activated and monitoring the room.
- Mechanism: The video stream from the webcam, particularly when there are changes in the scene (e.g., light turning on/off), generates distinct traffic patterns on the USB bus. These patterns interfere with the attacker's contention-generating traffic, allowing the attacker to distinguish between different webcam activities. The presentation showed traces that clearly differentiated between the room light being on versus off.
Attack C: Keystroke Capture
- Goal: To capture keystrokes typed on a USB keyboard.
- Setup: A USB keyboard and the attacker's USB device (e.g., a USB SSD or NIC) are connected to the same USB hub. The user types sensitive text on the USB keyboard.
- Mechanism: Each keystroke generates a small, but distinct, packet of data on the USB bus. Although individual keystrokes are low bandwidth, their timing and frequency create unique micro-contention patterns that the attacker's monitoring program can detect and correlate. The presentation showed traces indicating that keystrokes could be inferred by observing these patterns. This attack is particularly concerning due to the sensitive nature of keyboard input.
These detailed attack scenarios demonstrate the versatility and potency of the HubBub methodology, showing how shared USB hubs can become a conduit for covert information leakage from a variety of common peripherals.
Demo / Proof of Concept
▶ Watch: Attack B: Inferring webcam activities (light on/off) (5:55)
While the talk did not feature a live, interactive demo in the traditional sense, the research itself constitutes a comprehensive proof of concept for the HubBub attacks. The presentation meticulously detailed three distinct attack scenarios, each serving as a compelling demonstration of the vulnerability and its practical implications.
The most thoroughly detailed proof of concept was Attack A: Website Fingerprinting. The researchers presented empirical data, including throughput analysis graphs that illustrated how an attacker could saturate a USB 3.0 hub's bandwidth using a USB SSD with 4KB I/O sizes, achieving an effective throughput of approximately 3.2 Gbps (compared to the theoretical 5 Gbps). They then showed distinct contention traces collected when the victim accessed different websites, visually demonstrating the unique patterns generated by web traffic. The success of this PoC was quantified with a high 98% accuracy in identifying websites from a dataset of the top 100 sites, using advanced machine learning models (GRU and attention models). Furthermore, the broad validation across 10 USB 3.0 hubs, four 3.1 hubs, one 2.0 hub, one internal hub, and one monitor with integrated hub functionality underscored the robustness and widespread applicability of this attack vector.
For Attack B: Webcam Activity Inference and Attack C: Keystroke Capture, the talk provided clear conceptual setups and visual examples of the distinct contention patterns observed when a webcam's activity changed (e.g., light on/off) or when keystrokes were entered. These recaps, though not as deeply elaborated as Attack A during the presentation, served as strong demonstrations of the feasibility of inferring sensitive data from these peripherals through the same contention-based mechanism. The inclusion of these varied attack targets solidifies the claim that HubBub is a versatile class of side-channel attacks capable of exploiting different types of USB device traffic.
The systematic evaluation across multiple hardware configurations and USB standards effectively served as the "demo," proving that HubBub is not a theoretical vulnerability but a practical threat across a wide range of real-world deployments.
Defensive Implications
▶ Watch: Attack C: Capturing keystrokes from USB keyboard (6:30)
The HubBub research reveals a fundamental weakness in the security model of shared USB hubs, necessitating a re-evaluation of how we design, deploy, and utilize USB peripherals. The defensive implications are multi-faceted, spanning hardware design, operating system mechanisms, and user best practices.
- Hardware Isolation: The most robust defense would be hardware-level isolation. This could involve:
- Dedicated USB Controllers: Systems could be designed with physically separate USB controllers for sensitive devices (e.g., keyboard, smart card reader) versus less trusted or attacker-controlled devices.
- Isolated Hub Ports: Future USB hub designs might incorporate hardware mechanisms to isolate traffic between specific ports, preventing contention-based leakage. This could involve separate arbitration logic or dedicated bandwidth allocations, though this would likely increase cost and complexity.
- Physical Separation: Users should be advised to connect highly sensitive devices (e.g., hardware security keys, primary keyboard) to direct host ports rather than shared hubs, or at least to separate physical hubs if direct connection is not possible.
- Software Mitigations: Operating systems and virtualization environments can implement software-based defenses:
- Timing Noise/Obfuscation: Restricting access to high-resolution timers like
RDTSCfor untrusted processes, or providing only coarse-grained timers, could reduce the attacker's ability to precisely measure contention patterns. Introducing random delays or noise into I/O operations could also obfuscate the side channel, though this might impact performance. - Bandwidth Throttling/Prioritization: Operating systems could implement intelligent USB bandwidth management, dynamically throttling the I/O of untrusted or less critical devices when sensitive operations are detected. Conversely, critical devices could be given absolute priority, potentially starving attacker traffic. However, this is complex to implement without impacting legitimate performance or introducing new side channels.
- Anomaly Detection: While challenging, monitoring USB traffic patterns for unusual contention or sustained high-bandwidth usage from unexpected devices could potentially flag an ongoing HubBub attack. This would require sophisticated heuristics to differentiate malicious activity from legitimate, bursty USB traffic.
- Virtual Machine (VM) Isolation: For host-based attackers in VMs, hypervisors need to ensure that USB device passthrough or virtual USB controllers do not inadvertently expose contention side channels between VM guests or between the guest and host.
- User Awareness and Best Practices:
- Avoid Untrusted Devices on Shared Hubs: Users should be cautious about connecting untrusted USB devices (e.g., free promotional USB drives, unknown charging cables) to hubs that also host sensitive peripherals like keyboards, webcams, or external hard drives containing critical data.
- Consider Internal Hubs: The research noted that internal hubs (soldered onto motherboards) are also vulnerable. This means even if a user avoids external hubs, their internal USB architecture could still pose a risk, highlighting the need for hardware-level solutions.
- Regular Software Updates: While not a direct mitigation for hardware side channels, keeping operating systems and device drivers updated can help patch any software vulnerabilities that an attacker might leverage to gain control over a USB device necessary for the attack.
- Future USB Specifications: The USB Implementers Forum (USB-IF) and hardware manufacturers should consider these contention-based side channels in future USB specifications and hub designs. Implementing clearer isolation mechanisms or more secure arbitration policies at the hardware level will be crucial to securing the ubiquitous USB ecosystem against this new class of threats.
In essence, defending against HubBub requires a multi-layered approach, acknowledging that the convenience of shared hardware can introduce subtle yet powerful side-channel vulnerabilities.
Key Takeaways
- USB Hubs are a New Side-Channel Attack Surface: HubBub introduces a novel class of attacks that exploit contention on shared USB bus bandwidth, revealing a previously unaddressed vulnerability in widely used USB hubs.
- Broad Applicability Across USB Standards and Hardware: The attacks are effective across USB 2.0, 3.0, and 3.1 hubs, and have been demonstrated on a diverse range of hardware, including internal hubs and monitor-integrated hubs, indicating a systemic issue.
- Sensitive Information Leakage is Possible: HubBub can infer highly sensitive information from co-located peripherals, including visited websites (website fingerprinting), webcam activity (e.g., room light status), and even keystrokes from USB keyboards.
- High Accuracy Achieved: For website fingerprinting, the attack demonstrated over 98% accuracy in identifying websites from the top 100 list using machine learning classifiers, highlighting its precision and effectiveness.
- Attackers Can Be Host-Based or Device-Based: The threat models include malicious software running on the host system (even within VMs or web browsers) or a malicious physical USB device attached to the hub, making the attack surface broad.
- Mitigation Requires Multi-faceted Approach: Defenses necessitate a combination of hardware isolation (e.g., dedicated USB controllers), software mitigations (e.g., timing obfuscation, bandwidth management), and user awareness regarding connecting untrusted devices to shared hubs.
About the Speaker(s)
The talk "HubBub: Contention-Based Side-Channel Attacks on USB Hubs" was presented by Junpeng Wan, who is identified as a PT student at Purdue University. This research was conducted in collaboration between Purdue University and CK.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
HubBub is legitimate academic security research that surfaces a genuinely underexplored attack surface — USB hub contention as a side channel. The threat model is realistic, the implementation is rigorous, and 98% website fingerprinting accuracy across 15+ distinct hub configurations is not a cherry-picked lab result. Solid USENIX-tier work from a grad student who clearly did the grind.
Heather Calloway (CISO) — WEAK
Technically credible side-channel research that establishes a real and previously unaddressed attack class. But it stops at demonstration — the defensive guidance is generic, the threat modeling is underdeveloped from an operational standpoint, and there is nothing here that changes how a security program, a CISO, or a procurement team operates tomorrow.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)