AudioMarkNet: Audio Watermarking for Deepfake Speech Detection

Wei Zong

34th USENIX Security Symposium (USENIX Security '25) · Day 2 · ML and AI Security 2

Overview

This paper introduces ChoiceJacking, a novel family of USB-based attacks that effectively bypass the existing mitigations against JuiceJacking attacks, which were discovered about a decade ago. JuiceJacking exploits the dual-purpose nature of mobile device USB ports, allowing malicious chargers to establish data connections and compromise devices. In response, mobile operating systems like Android and iOS implemented user prompts requiring explicit consent before a USB host could initiate a data connection. The core assumption underlying these mitigations was that an attacker could not inject user input events while simultaneously establishing a data connection. The researchers demonstrate this assumption to be fundamentally flawed.

Read the paper · Download the PDF (PDF) · Slides

Paper abstract

JuiceJacking is an attack in which malicious chargers compromise connected mobile devices. Shortly after the attack was discovered about a decade ago, mobile OSs introduced user prompts for confirming data connections from a USB host to a mobile device. Since the introduction of this countermeasure, no new USB-based attacks with comparable impact have been found. In this paper, we present a novel family of USB-based attacks on mobile devices, ChoiceJacking, which is the first to bypass existing JuiceJacking mitigations. We observe that these mitigations assume that an attacker cannot inject input events while establishing a data connection. However, we show that this assumption does not hold in practice. We present a platform-agnostic attack principle and three concrete attack techniques for Android and iOS that allow a malicious charger to autonomously spoof user input to enable its own data connection. Our evaluation using a custom cheap malicious charger design reveals an alarming state of USB security on mobile platforms. Despite vendor customizations in USB stacks, ChoiceJacking attacks gain access to sensitive user files (pictures, documents, app data) on all tested devices from 8 vendors including the top 6 by market share. For two vendors, our attacks allow file extraction from locked devices. For stealthily performing attacks that require an unlocked device, we use a power line side-channel to detect suitable moments, i.e., when the user does not notice visual artifacts. We responsibly disclosed all findings to affected vendors. All but one (including Google, Samsung, Xiaomi, and Apple) acknowledged our attacks and are in the process of integrating mitigations.

Visual summary for AudioMarkNet: Audio Watermarking for Deepfake Speech Detection by Wei Zong
Visual summary for AudioMarkNet: Audio Watermarking for Deepfake Speech Detection by Wei Zong

ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago

Speakers: Florian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan Mangard, Researchers, Graz University of Technology and A-SIT Austria (Draschbacher)

Conference: USENIX Security

YouTube: This article is based on a peer-reviewed conference paper, not a recorded talk. Therefore, there is no accompanying video or timestamps.

Overview

This paper introduces ChoiceJacking, a novel family of USB-based attacks that effectively bypass the existing mitigations against JuiceJacking attacks, which were discovered about a decade ago. JuiceJacking exploits the dual-purpose nature of mobile device USB ports, allowing malicious chargers to establish data connections and compromise devices. In response, mobile operating systems like Android and iOS implemented user prompts requiring explicit consent before a USB host could initiate a data connection. The core assumption underlying these mitigations was that an attacker could not inject user input events while simultaneously establishing a data connection. The researchers demonstrate this assumption to be fundamentally flawed.

ChoiceJacking attacks leverage malicious chargers to autonomously spoof user input, allowing them to confirm their own data connections without genuine user interaction. The research highlights a critical vulnerability in the USB security posture of modern mobile platforms, revealing that devices from eight major vendors, including the top six by market share (Google, Samsung, Xiaomi, Apple, Oppo, Vivo, Huawei, Honor), are susceptible. For some vendors (Honor and Oppo), file extraction is even possible from locked devices. The findings have been responsibly disclosed to all affected vendors, with most acknowledging the vulnerabilities and actively working on or integrating mitigations, including Google and Samsung who have assigned CVEs (CVE-2024-43085 and CVE-2024-20900, respectively).

The significance of ChoiceJacking lies in its ability to restore the impact level of JuiceJacking attacks on modern devices, which was previously thought to be mitigated. By combining aspects of both malicious USB hosts and USB devices, ChoiceJacking creates a "hybrid" attack that can gain access to sensitive user files (pictures, documents, app data) and, in some cases, achieve code execution. The paper also introduces a power line side-channel (PLSC) technique to detect opportune moments for stealthy attacks, such as when a user is on a phone call and unlikely to notice visual artifacts on their screen. This comprehensive research underscores the need for a re-evaluation of USB security paradigms on mobile platforms, advocating for more stringent user consent mechanisms across all USB connection types.

Background

The evolution of mobile device connectivity has seen the Universal Serial Bus (USB) become the ubiquitous standard for both power delivery and data exchange. Since its inception in 1996, USB has undergone significant advancements, notably with the introduction of USB Type-C and USB Power Delivery (USB PD). These technologies brought about a dedicated Configuration Channel (CC) line and sophisticated negotiation capabilities, allowing devices to dynamically swap roles between a Downward Facing Port (DFP), typically a USB host (like a computer), and an Upward Facing Port (UFP), typically a USB device (like a peripheral). Crucially, USB PD allows for dynamic changes in both power roles (source/sink) and data roles (DFP/UFP), a feature central to the ChoiceJacking attack model.

A decade ago, the cybersecurity landscape was grappling with JuiceJacking attacks, where malicious charging stations could exploit the default trust placed in USB data connections to compromise connected mobile devices. These attacks allowed an attacker to access arbitrary files or even gain code execution without the user's knowledge (Section 1). In response, mobile OS developers, including Google for Android and Apple for iOS, implemented countermeasures. These mitigations typically involve user prompts that require explicit consent before a USB host can establish a data connection for protocols like Picture Transfer Protocol (PTP) or Media Transfer Protocol (MTP), which are used for file exchange, or Android Debug Bridge (ADB), which provides development access and shell capabilities (Section 2).

However, a critical gap in these mitigations persisted: mobile platforms continue to trust USB peripherals and accessories by default, requiring no explicit user consent for their connection. This oversight allowed for a new wave of USB-based attacks that acted as malicious peripherals. Examples include BadUSB attacks [29], which reprogram USB device firmware to inject input events, and malicious chargers that use USB-to-HDMI interfaces to access screen content [23, 24] or audio interfaces for voice assistant data extraction [50]. While impactful, none of these post-JuiceJacking mitigations achieved the broad access to sensitive files or code execution that JuiceJacking once did. The fundamental flaw identified by ChoiceJacking is the assumption that a USB host cannot simultaneously inject input events, an assumption rooted in the isolation of the USB protocol but broken when considering the mobile platform from a system perspective (Section 1, Section 3).

Key Findings

The ChoiceJacking research uncovers fundamental flaws in the JuiceJacking mitigations implemented across major mobile platforms, demonstrating their ineffectiveness against a novel class of hybrid USB attacks. The core findings are:

  1. Bypassing JuiceJacking Mitigations: ChoiceJacking is the first attack family to successfully bypass existing JuiceJacking countermeasures. It achieves this by exploiting the inherent conflict between mobile platforms' default trust in USB peripherals and the requirement for user consent for USB host data connections. Malicious chargers can simultaneously act as a USB host (to initiate a data connection) and an input device (to spoof user consent), effectively circumventing the intended security prompts (Section 1, Section 3).
  2. Platform-Agnostic Attack Principle: The research presents a platform-agnostic attack principle that combines characteristics of malicious USB hosts and USB devices. This hybrid approach enables a malicious charger to establish a secondary input channel to the victim device while the primary USB channel operates as a host, initiating a data connection. This conceptual framework is instantiated through three concrete attack techniques (T1, T2, T3) targeting both Android and iOS devices (Section 1, Section 3).
  3. Widespread Vulnerability Across Vendors: The evaluation, conducted on 11 current-generation mobile devices from 8 vendors (including Samsung, Xiaomi, Oppo, Vivo, Huawei, Honor, Google, and Apple), reveals an alarming state of USB security. All tested devices were susceptible to ChoiceJacking attacks, allowing access to sensitive user files (pictures, documents, app data) via PTP/MTP, and in many cases, code execution via ADB (Section 1, Section 6).
  4. Locked Device Exploitation: For two vendors, Honor and Oppo (representing 18% of tested devices), ChoiceJacking attacks could gain MTP file access even when the device was locked. This was achieved by exploiting further implementation flaws in their USB handling logic and Android Auto service, demonstrating a complete bypass of screen unlock requirements for data access (Section 1, Section 6).
  5. ADB Access on Non-Development-Enabled Devices: On Xiaomi devices, ChoiceJacking attacks were able to gain ADB development access (code execution) even if the device was not initially development-enabled. This was possible by using the injected input events to navigate the UI and enable developer settings and USB debugging, highlighting a severe security misconfiguration (Section 1, Section 6).
  6. Rapid Attack Execution: The fastest ChoiceJacking attack (Technique T1 on a Samsung Galaxy S20 FE) achieved MTP file access in just 133 milliseconds, less than half the duration of a human blink. The median attack duration for T1 was 334 milliseconds. Such speeds make the visual artifacts on the screen (a brief flicker) highly likely to go unnoticed by the user (Section 1, Section 6).
  7. Power Line Side-Channel for Stealth: To enable entirely stealthy attacks that require an unlocked device, the researchers developed a power line side-channel (PLSC). This technique allows the malicious charger to detect suitable moments when the user is unlikely to observe the screen, such as during a phone call when the proximity sensor typically turns off the display. This ensures attacks can be executed without alerting the victim (Section 1, Section 7).
  8. Responsible Disclosure and Vendor Response: The findings, including 16 vendor-specific security issues and 4 upstream Android vulnerabilities, were responsibly disclosed. All but one vendor, including Google, Samsung, Xiaomi, and Apple, acknowledged the attacks and are in the process of integrating mitigations. Google and Samsung have already assigned CVEs (CVE-2024-43085 and CVE-2024-20900) (Section 1).

Technical Deep Dive

ChoiceJacking attacks exploit the fundamental design flaw where mobile operating systems require explicit user consent for USB data connections but simultaneously trust USB peripherals and accessories by default. The malicious charger acts as a hybrid USB device, capable of switching roles between a USB host and a USB peripheral, or leveraging specific protocol implementations to achieve both functions conceptually. The attack principle hinges on establishing an "extra input channel" while initiating a data connection as a USB host, then using this channel to spoof user input and confirm the data connection prompt (Section 3).

The paper details three concrete attack techniques:

Technique 1 (T1): Exploiting Android Open Accessory Protocol (AOAP) Flaws

The Android Open Accessory Protocol (AOAP) [1] allows an accessory to register as an input device despite operating as a USB host. This protocol, designed for specific accessories, is typically trusted by default and does not require user consent for HID functionality. According to the AOAP specification, Android devices should only accept AOAP messages when in a special accessory mode, which explicitly disallows other data connections (Section 2.2).

However, the researchers discovered that all investigated Android devices violate this specification by accepting certain AOAP HID messages at all times, regardless of the current USB mode. This critical implementation flaw allows a malicious charger, acting as a USB host, to simultaneously inject input events. The attack sequence involves:

  1. The unlocked victim device is connected to the charger.
  2. The charger registers a Human Interface Device (HID) input device via AOAP.
  3. The malicious charger initiates an MTP or ADB data connection, triggering the user consent prompt.
  4. The charger autonomously accepts the prompt by injecting suitable HID events (e.g., key presses or touch events) (Section 4).

To overcome AOAP's limitation of only supplying 500mA charging current, the attacker can perform USB Power Delivery (USB PD) power negotiation before sending AOAP messages, ensuring rapid charging while the attack is mounted. This technique proved to be the fastest and most universally applicable across Android devices, achieving MTP access in as little as 133ms on the Samsung Galaxy S20 FE (Section 6). Furthermore, on Oppo and Honor devices, a specific flaw in AOAP input event handling could be triggered, forcing a re-initialization of the USB interface directly into MTP mode, allowing file access even on locked devices (Section 4, Section 6). For Xiaomi devices, T1 could even enable ADB access on non-development-enabled devices by navigating the UI to activate developer settings and USB debugging (Section 6).

Technique 2 (T2): Race Condition in Android's Input Dispatcher

This technique exploits a race condition within Android's input subsystem. Android's input dispatcher uses a queue to process input events from peripherals. Crucially, this queue retains events even if the generating device is disconnected, and the input dispatcher serializes key events, waiting for previous events to be fully processed (Section 4).

The attack proceeds as follows:

  1. The unlocked device connects to the charger.
  2. The charger performs a USB PD Data Role Swap, making the Android device act as a USB host and the charger as a USB HID device.
  3. The charger, as a USB HID device, floods the event queue with a specially crafted sequence of key events. These events are designed to trigger complex handling logic (delayers) and later confirm the user prompt (confirmers).
  4. The charger performs another USB PD Data Role Swap, becoming the USB host while the mobile device becomes the USB device.
  5. As the USB host, the charger triggers the user consent prompt (e.g., for MTP or ADB).
  6. While the Android OS is still processing the buffered input events from step 3, the "confirmers" in the queue are dispatched, autonomously accepting the user prompt (Section 4, Figure 3).

This technique was successful on 9 out of 10 evaluated Android devices for MTP access and 6 for ADB access, with a median attack duration of 13 seconds (Section 6). It leverages the inherent trust in USB peripherals and the buffering mechanism of the input dispatcher to inject input before the prompt appears, but after the initial role swap, ensuring the events are processed at the opportune moment.

Technique 3 (T3): Bluetooth HID Device Pairing

T3 is a platform-agnostic technique, working on both Android and iOS, that leverages an integrated Bluetooth (BT) HID device within the malicious charger.

  1. The unlocked victim device is connected to the charger.
  2. The charger performs a USB PD Data Role Swap, making the mobile device a USB host and the charger a USB input device.
  3. Using the USB input device, the charger injects input to enable Bluetooth and navigate to the Bluetooth pairing screen on the mobile device.
  4. The charger starts advertising itself as a BT input device.
  5. The charger identifies the mobile device's BT address and initiates pairing.
  6. Through the USB input device, the charger accepts the BT pairing dialog on the mobile device, thus connecting the malicious Bluetooth HID device.
  7. The charger performs another USB PD Data Role Swap, becoming the USB host.
  8. As the USB host, the charger initiates a data connection (e.g., PTP/MTP).
  9. Through the newly paired Bluetooth input device, the charger autonomously confirms its own data connection prompt (Section 4).

This technique was successful on 10 of 11 evaluated devices across both Android and iOS, including the Apple iPad Pro 2022. While slower due to the Bluetooth pairing process (median 24.5 seconds), its cross-platform applicability makes it highly versatile (Section 6).

Power Line Side-Channel (PLSC) for Stealth

To ensure stealth, especially for attacks requiring an unlocked screen, the researchers developed a power line side-channel (PLSC). This technique allows the malicious charger to detect when the victim device's screen is unobserved. Mobile device operations, particularly screen content changes, cause unique fluctuations in power consumption. The PLSC monitors the charging current to infer device activity (Section 7).

The proof-of-concept PLSC specifically targets the scenario of a phone call where the user holds the device to their face, causing the proximity sensor to turn off the screen. During this state, external input devices can still interact with the UI, but the user cannot observe the screen. By analyzing power traces (Figure 6), the researchers trained a one-dimensional convolutional neural network (CNN) classifier to detect call start/end events with 92.78% accuracy (Figure 7). A simple threshold comparator can then determine when the screen is off during a call. This allows the attacker to launch CHOICEJACKING attacks during these unobserved windows, minimizing the chance of detection by the user (Section 7).

Demo / Proof of Concept

The researchers implemented a proof-of-concept (PoC) malicious charger to validate the ChoiceJacking attacks. Recognizing that modifying commercial chargers was out of scope, they simulated the environment using a custom-designed printed circuit board (PCB) controlled by a Raspberry Pi 4 single-board computer (SBC) (Section 5, Figure 4).

The custom PCB was built around a Raspberry Pi RP2040 microcontroller unit (MCU). This MCU was crucial for hardware-level operations, including:

  • Implementing a native USB HID keyboard and mouse for input injection.
  • Providing a second bit-banged USB port for serial communication with the Raspberry Pi SBC.
  • Integrating a USB Power Delivery controller that acts as a DFP to the mobile device.
  • Controlling a USB multiplexer to dynamically connect the mobile device's USB data lines to either the MCU or the Raspberry Pi SBC. This multiplexer is essential for enabling the charger to switch between USB device and USB host roles (Section 5).

The Raspberry Pi 4 SBC served multiple roles:

  • Communicating with the RP2040 MCU on the PCB to control its hardware functions.
  • Acting as the primary USB host to establish data connections with the mobile device.
  • Operating as a Bluetooth HID device for Technique 3 (T3) (Section 5).

The total cost of this prototype was less than 100 USD, demonstrating that ChoiceJacking attacks can be mounted by relatively unsophisticated attackers. While the prototype was larger than a typical off-the-shelf charger, the electronics could be further miniaturized to fit within a USB-C connector, effectively creating a malicious cable (Section 5).

The evaluation phase used this PoC setup to test 11 mobile devices from 8 vendors running Android 12, 13, or 14, and iOS 17. The researchers measured the duration of visible UI interaction during attacks, capturing video at 30 frames per second. The results confirmed the effectiveness of ChoiceJacking, with Technique 1 (T1) being the fastest, achieving MTP file access in a median of 334ms across all Android devices, and as quickly as 133ms on a Samsung Galaxy S20 FE (Section 6). This rapid execution means the attack leaves only a brief screen flicker, which is easily overlooked by users. The PoC successfully demonstrated file extraction (MTP/PTP) and code execution (ADB) across a wide range of devices, including accessing files on locked Oppo and Honor devices and gaining ADB on non-development-enabled Xiaomi devices (Section 6). The PLSC was also demonstrated on a Xiaomi 12, using current measurements to detect phone calls and screen-off states, proving the feasibility of stealthy attack timing (Section 7).

Defensive Implications

The ChoiceJacking research reveals a critical blind spot in current mobile platform security, necessitating a re-evaluation of USB trust models. Defenders must recognize that the existing JuiceJacking mitigations, which rely on user consent for data connections, are insufficient when malicious chargers can autonomously spoof that consent.

The primary defensive implication is the need for user prompts for all types of USB access, extending beyond data connections to include USB host, USB device, and accessory modes. The default trust placed in USB input devices and accessories must be eliminated. The researchers propose introducing explicit user consent prompts before an input device or accessory is allowed to interact with the system. Once the USB Type-C Authentication Specification [46] becomes widely adopted, this consent could be granted upon first attachment and saved for subsequent connections, similar to how macOS handles new USB devices [2] (Section 8).

Beyond this fundamental change, several existing mitigations, while useful, have limitations against ChoiceJacking:

  • USB Data Blockers: These physical devices sever USB data lines, preventing data transfer. However, they rely on user awareness of the threat and can degrade charging speed by interfering with modern USB PD negotiation schemes. They are not a practical solution for the average user (Section 8).
  • User Authentication for Security-critical Functions: While Android and iOS require authentication for enabling features like USB debugging, the UI often fails to clearly indicate what is being authenticated. A malicious charger can trigger an authentication prompt that appears to the user as a routine screen unlock, which they might confirm without realizing its true purpose (Section 8).
  • Lockdown Mode: Features like Android's (since Android 15) and iOS's (since iOS 16) Lockdown Mode can disable USB data lines entirely when the device is locked. However, most ChoiceJacking attacks operate while the device is unlocked, rendering Lockdown Mode ineffective against them once the device is in active use. Furthermore, Lockdown Mode requires manual activation, again relying on user awareness (Section 8).

To counter ChoiceJacking, vendors should:

  • Strictly enforce AOAP specifications: Android devices must only accept AOAP HID messages when truly in accessory mode and not allow input injection while simultaneously establishing other USB data connections.
  • Address race conditions: The Android input dispatcher's behavior of buffering events from disconnected devices needs to be re-evaluated to prevent malicious input injection across role swaps.
  • Enhance UI clarity for authentication: Authentication prompts should explicitly state the security-critical action being authorized, not just ask for a general unlock.
  • Review vendor customizations: The research highlights how vendor-specific Android variants introduce unique vulnerabilities, such as Xiaomi's removal of authentication for USB debugging or Oppo/Honor's locked-device MTP access bugs. These customizations require rigorous security auditing.
  • Integrate PLSC detection: While currently an attacker's tool, understanding PLSCs could lead to defensive mechanisms that detect unusual power consumption patterns indicative of an attack, potentially triggering alerts or disabling USB data.

In summary, the ChoiceJacking attacks demonstrate that relying solely on user prompts for data connections is insufficient. A holistic security approach that scrutinizes all forms of USB interaction, including input device and accessory connections, for explicit user consent is essential to protect mobile devices from sophisticated charger-based compromises.

Key Takeaways

  • ChoiceJacking bypasses existing JuiceJacking mitigations: Mobile OS security measures, which relied on user consent for USB data connections, are rendered ineffective by ChoiceJacking attacks that autonomously spoof user input.
  • Hybrid attack model is effective: ChoiceJacking introduces a novel concept of "hybrid" USB attacks, combining aspects of malicious USB hosts (to initiate data connections) and USB devices (to inject input events), demonstrating a systemic flaw in how dual-role USB connectivity is secured.
  • Widespread vulnerability across major vendors: All 11 tested devices from 8 vendors, including market leaders like Google, Samsung, Xiaomi, and Apple, were found susceptible to ChoiceJacking, allowing access to sensitive files (PTP/MTP) and often code execution (ADB).
  • Rapid and stealthy execution is possible: The fastest attacks gain file access in as little as 133 milliseconds, often leaving only a brief, unnoticeable screen flicker. A power line side-channel (PLSC) further enables stealth by detecting moments when the user's screen is unobserved (e.g., during phone calls).
  • Locked devices and non-development-enabled devices are at risk: For Honor and Oppo devices, file extraction is possible even when the screen is locked. On Xiaomi devices, ChoiceJacking can enable ADB access and achieve code execution even if the device was not previously development-enabled.
  • New mitigation strategy proposed: The researchers advocate for user prompts for all forms of USB access (host, device, accessory) and a fundamental shift away from default trust in USB input devices and accessories to secure mobile platforms effectively.

About the Speaker(s)

The research on ChoiceJacking was conducted by Florian Draschbacher, Lukas Maar, Mathias Oberhuber, and Stefan Mangard. All authors are affiliated with Graz University of Technology, a prominent institution known for its contributions to computer science and cybersecurity research. Florian Draschbacher is also associated with A-SIT Austria, an organization focused on information security. Their collective expertise in system security, particularly in mobile platforms and hardware-software interaction, is evident in the detailed analysis and innovative attack techniques presented in this paper. Their work contributes significantly to understanding and mitigating sophisticated threats to mobile device security.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This is exactly the kind of research that makes you reassess assumptions you stopped questioning years ago. Graz TU systematically dismantles a decade of JuiceJacking mitigations across every major mobile vendor, with three distinct attack techniques, working PoC hardware, CVEs already assigned, and a side-channel for stealth timing. It's thorough, novel, and immediately consequential.

Heather Calloway (CISO) — STRONG ACCEPT

This is consequential research that should change how we think about USB security on mobile devices. The finding that decade-old JuiceJacking mitigations are fundamentally broken across every major vendor—including Apple—is something every CISO with a mobile fleet needs to know, even if the fix isn't in your hands.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)