Pith. sign in

REVIEW 2 major objections 2 minor 49 references

Capacitive Touchscreens at Risk: A Practical Side-Channel Attack on Smartphones via Electromagnetic Emanations

T0 review · 2 major / 2 minor · reviewed 2026-06-30 · grok-4.3

Pith's one-line read TESLA extracts PIN codes, keystrokes, and handwriting from smartphone touchscreen electromagnetic emanations using a nearby probe.

desk verdict The paper introduces TESLA, a contactless EM attack on phone touchscreens that claims to recover PINs, keystrokes, apps, and handwriting at high accuracy from emanations during scanning, but the abstract supplies almost no experimental details to back the practicality claims. read the letter →

arxiv 2605.14633 v1 pith:DKO4VED7 submitted 2026-05-14 cs.CR

classification cs.CR
keywords side-channelattackelectromagneticemanationscapacitivetouchscreensmartphonesecurityPINcodeextractionkeystrokeinferencehandwritingreconstructionEM
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper presents TESLA as a contactless attack that captures electromagnetic emanations produced while capacitive touchscreens scan for user input. These signals encode the timing and position of touches in a form that reveals specific actions. A probe placed near the device recovers screen-unlocking PIN codes, keyboard inputs, application categories, and handwriting trajectories. The approach operates on commercial phones in ordinary locations such as meeting rooms and libraries without requiring direct contact or special setups. Evaluations confirm high recovery rates across multiple device models.

What carries the argument

The unified leakage basis formed by inherent EM emanations during touchscreen scanning that encodes spatiotemporal touch interactions.

What would settle it

A measurement showing that EM signals captured near the phone during different known touch sequences are statistically indistinguishable or fail to support reconstruction above random chance.

Watch

Extended reading notes

Core claim

TESLA demonstrates that the electromagnetic emanations generated during touchscreen scanning encode the spatiotemporal evolution of touch interactions as a unified leakage basis. Capturing these signals with a secretly placed nearby EM probe allows reconstruction of screen-unlocking PIN codes, keyboard inputs, interacting application categories, and continuous handwriting trajectories on commercial smartphones in practical settings.

Load-bearing premise

The electromagnetic emanations from touchscreen scanning contain enough distinguishable information about touch positions and timing for a nearby probe to extract accurate reconstructions under normal conditions.

Editorial extensions

If this is right

  • PIN code recognition reaches 99.3 percent success rate on tested devices.
  • Keyboard input reconstruction achieves 97.6 percent accuracy.
  • Application category inference succeeds at 95.0 percent.
  • Handwriting trajectory reconstruction attains 76.8 percent character accuracy and Jaccard index of 0.74.
  • The attack functions on iPhone X, Xiaomi 10 Pro, Samsung S10, and Huawei Mate 30 Pro in everyday environments.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same emanation patterns could appear in other capacitive touch devices such as tablets or interactive kiosks.
  • Randomizing scan timing or adding hardware shielding might reduce the leakage without changing user experience.
  • The probe-based capture suggests value in testing EM emissions from other phone components like cameras or sensors during active use.
  • Manufacturers could evaluate whether software updates alone suffice or if hardware redesign is needed to limit such signals.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 2 minor

Summary. The manuscript presents TESLA, a contactless electromagnetic side-channel attack exploiting inherent EM emanations from capacitive touchscreen scanning on smartphones. It claims that a nearby probe can recover screen-unlocking PIN codes (99.3% success), keyboard inputs (97.6%), interacting application categories (95.0%), and continuous handwriting trajectories (76.8% character accuracy, Jaccard index 0.74) on four commercial devices (iPhone X, Xiaomi 10 Pro, Samsung S10, Huawei Mate 30 Pro) in practical settings such as meeting rooms and public libraries, offering broader targets and more efficient acquisition than prior attacks.

Significance. If the experimental results hold under the claimed conditions without restrictive setups, the work would be significant for identifying a unified EM leakage basis in touchscreen operation and demonstrating a practical, non-contact attack vector with multiple high-value targets. The evaluation across multiple phone models and real-world environments would strengthen the case for reevaluating EM side-channel risks in mobile devices.

major comments (2)
  1. [Abstract] Abstract: the abstract reports high success rates (99.3% PIN, 97.6% keyboard, etc.) across four phone models and practical environments but supplies no experimental details, controls, error analysis, or baseline comparisons, preventing assessment of whether the data actually support the stated claims.
  2. [Evaluation section] Evaluation (assumed §4 or equivalent): the load-bearing claim that the attack operates via a secretly placed nearby probe in everyday noisy settings (libraries, meeting rooms) at usable distances requires explicit reporting of probe-to-device distances, orientations, measured SNR values, and ambient noise levels; without these, it is unclear whether signal strength remains sufficient once the probe is moved beyond immediate contact (e.g., inside a bag).
minor comments (2)
  1. [Methodology] Clarify the exact model and bandwidth of the EM probe used, along with the signal processing steps for extracting spatiotemporal touch features.
  2. Ensure all result tables or figures report confidence intervals or standard deviations alongside the quoted success rates.

Simulated Author's Rebuttal

2 responses · 0 unresolved

We thank the referee for the detailed and constructive review. The comments focus on improving the clarity of experimental reporting, which we address point-by-point below. We will incorporate revisions to make the practical aspects of the attack more explicit while preserving the manuscript's core contributions.

read point-by-point responses
  1. Referee: [Abstract] Abstract: the abstract reports high success rates (99.3% PIN, 97.6% keyboard, etc.) across four phone models and practical environments but supplies no experimental details, controls, error analysis, or baseline comparisons, preventing assessment of whether the data actually support the stated claims.

    Authors: Abstracts are constrained by length and convention; they summarize results without the detailed methodology, controls, or error analysis that appear in the evaluation section. Section 4 provides multi-trial results with standard deviations, ambient noise considerations, device-specific controls, and comparisons to prior EM and side-channel attacks. We will add one sentence to the abstract noting 'validated through extensive multi-device experiments in real-world environments with reported error metrics' to better signal the supporting evidence, but we maintain that the abstract's role is high-level summary rather than exhaustive reporting. revision: partial

  2. Referee: [Evaluation section] Evaluation (assumed §4 or equivalent): the load-bearing claim that the attack operates via a secretly placed nearby probe in everyday noisy settings (libraries, meeting rooms) at usable distances requires explicit reporting of probe-to-device distances, orientations, measured SNR values, and ambient noise levels; without these, it is unclear whether signal strength remains sufficient once the probe is moved beyond immediate contact (e.g., inside a bag).

    Authors: The manuscript describes probe placements at 5–30 cm in the evaluated environments and notes signal acquisition under typical ambient conditions, but we agree that consolidated quantitative reporting would strengthen the practical claims. We will add a table in the revised evaluation section listing per-experiment distances, orientations, measured SNR ranges, and ambient noise levels (in dB) across the four devices and two settings. This will include analysis confirming usable signal strength at the reported distances. Experiments focused on nearby non-contact placement (table, adjacent seating); we will explicitly state that bag-concealed scenarios were not tested and clarify the demonstrated range. revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: purely empirical attack demonstration

full rationale

The paper describes an empirical side-channel attack (TESLA) that captures EM emanations from touchscreen scanning on commercial smartphones and reports measured inference accuracies for PINs, keystrokes, apps, and handwriting. No equations, derivations, fitted parameters, or mathematical claims appear in the provided text. No self-citations are used to justify uniqueness theorems, ansatzes, or load-bearing premises. The results rest on direct experimental validation rather than any reduction to prior inputs by construction, satisfying the criteria for a self-contained empirical finding.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

No mathematical model, parameters, or theoretical constructs described; the work is an empirical security demonstration.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Capacitive Touchscreens at Risk: A Practical Side-Channel Attack on Smartphones via Electromagnetic Emanations." pith.science (2026). https://pith.science/paper/DKO4VED7

@misc{pith2026260514633,
  author       = {Pith},
  title        = {Pith review of: Capacitive Touchscreens at Risk: A Practical Side-Channel Attack on Smartphones via Electromagnetic Emanations},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/DKO4VED7}},
  note         = {Machine review of arXiv:2605.14633}
}
read the original abstract

Capacitive touchscreens in modern smartphones introduce severe side-channel vulnerabilities. However, existing attacks often require restrictive conditions or invasive measurements. This paper presents TESLA, a novel, contactless electromagnetic (EM) side-channel attack that exploits inherent EM emanations during touchscreen scanning. We demonstrate that these emanations encode the spatiotemporal evolution of touch interactions, forming a unified leakage basis. By secretly placing an EM probe near the victim's device, TESLA enables attackers to extract highly sensitive information, including screen-unlocking PIN codes, keyboard inputs, interacting application categories, and continuous handwriting trajectories. Compared to existing attacks, TESLA offers a broader range of attack targets, more efficient sample acquisition, and operations in practical attack scenarios. Extensive evaluations on popular commercial smartphones, specifically the iPhone X, Xiaomi 10 Pro, Samsung S10, and Huawei Mate 30 Pro, validate the effectiveness of TESLA. It achieves remarkable inference accuracy in diverse settings such as private meeting rooms and public libraries, with success rates of 99.3% for PIN code recognition, 97.6% for keyboard input reconstruction, and 95.0% for application inference, respectively. Simultaneously, it attains a 76.8% character recognition accuracy and a high geometric similarity (Jaccard index of 0.74) for 2D handwriting trajectory reconstruction.

Figures

Figures reproduced from arXiv: 2605.14633 by the authors.

Figure 1
Figure 1. TESLA exploits the EM emanations generated [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. System architecture of capacitive touchscreen. [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Illustration of human coupling effect in touchscreen. [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figures from the paper (16 more)
Figure 5
Figure 5. Figure 5: EM emanation measurements for touch interactions. (a) Three touch interactions. (b) Details of the first touch [PITH_FULL_IMAGE:figures/full_fig_p005_5.png]
Figure 6
Figure 6. Figure 6: EM emanation measurements for different touch [PITH_FULL_IMAGE:figures/full_fig_p005_6.png]
Figure 7
Figure 7. Figure 7: EM emanation measurements under different animated visual feedback conditions. The EM features of touch [PITH_FULL_IMAGE:figures/full_fig_p007_7.png]
Figure 8
Figure 8. Figure 8: Attack scenarios in the public area and the private [PITH_FULL_IMAGE:figures/full_fig_p007_8.png]
Figure 9
Figure 9. Figure 9: Overview of the TESLA. EM emanation (mV) 0 2 4 6 8 10 12 14 16 60 40 20 0 -20 -40 -60 Trigger Signal Valid Signal Invalid Signal Time (ms) [PITH_FULL_IMAGE:figures/full_fig_p008_9.png]
Figure 10
Figure 10. Figure 10: EM emanation measurements of two touch sam [PITH_FULL_IMAGE:figures/full_fig_p008_10.png]
Figure 11
Figure 11. Figure 11: Touch heatmap for distinct application categories. (a) App Store application, (b) Mobile payment application, [PITH_FULL_IMAGE:figures/full_fig_p011_11.png]
Figure 12
Figure 12. Figure 12: The target smartphones and data collection [PITH_FULL_IMAGE:figures/full_fig_p011_12.png]
Figure 14
Figure 14. Figure 14: Effectiveness evaluation on screen-unlocking PIN [PITH_FULL_IMAGE:figures/full_fig_p012_14.png]
Figure 13
Figure 13. Figure 13: Effectiveness on in￾teraction classification. SU: screen unlocking; KI: key￾board input; AO: application operation [PITH_FULL_IMAGE:figures/full_fig_p012_13.png]
Figure 17
Figure 17. Figure 17: Evaluation results of touch position recovery. [PITH_FULL_IMAGE:figures/full_fig_p013_17.png]
Figure 15
Figure 15. Figure 15: Effectiveness evaluation on keyboard inputs re [PITH_FULL_IMAGE:figures/full_fig_p013_15.png]
Figure 16
Figure 16. Figure 16: Effectiveness evaluation on application categories [PITH_FULL_IMAGE:figures/full_fig_p013_16.png]
Figure 20
Figure 20. Figure 20: Impacts of probe-device distance and relative [PITH_FULL_IMAGE:figures/full_fig_p014_20.png]
Figure 19
Figure 19. Figure 19: Confusion matrix of character recognition results. [PITH_FULL_IMAGE:figures/full_fig_p014_19.png]
Figure 21
Figure 21. Figure 21: iPhone X Cross-device evaluation on screen [PITH_FULL_IMAGE:figures/full_fig_p015_21.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

49 extracted references · 49 canonical work pages

  1. [1]

    Recovering fingerprints from in-display fingerprint sensors via electromagnetic side channel,

    T. Ni, X. Zhang, and Q. Zhao, “Recovering fingerprints from in-display fingerprint sensors via electromagnetic side channel,” in Proceedings of the 2023 ACM SIGSAC Conference on Com- puter and Communications Security, CCS 2023, Copenhagen, Denmark, November 26-30, 2023, W. Meng, C. D. Jensen, C. Cremers, and E. Kirda, Eds. ACM, 2023, pp. 253–267

  2. [2]

    Periscope: A keystroke inference attack using human coupled electromagnetic emana- tions,

    W. Jin, S. Murali, H. Zhu, and M. Li, “Periscope: A keystroke inference attack using human coupled electromagnetic emana- tions,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 700–714

  3. [3]

    Charger-surfing: Exploiting a power line side-channel for smartphone information leakage,

    P. Cronin, X. Gao, C. Yang, and H. Wang, “Charger-surfing: Exploiting a power line side-channel for smartphone information leakage,” in 30th USENIX Security Symposium, USENIX Secu- rity 2021, August 11-13, 2021, M. D. Bailey and R. Greenstadt, Eds. USENIX Association, 2021, pp. 681–698. 17

  4. [4]

    On inferring browsing activity on smartphones via USB power analysis side-channel,

    Q. Yang, P. Gasti, G. Zhou, A. Farajidavar, and K. S. Bala- gani, “On inferring browsing activity on smartphones via USB power analysis side-channel,” IEEE Trans. Inf. Forensics Secur., vol. 12, no. 5, pp. 1056–1066, 2017

  5. [5]

    Uncovering user interactions on smartphones via contactless wireless charging side channels,

    T. Ni, X. Zhang, C. Zuo, J. Li, Z. Yan, W. Wang, W. Xu, X. Luo, and Q. Zhao, “Uncovering user interactions on smartphones via contactless wireless charging side channels,” in 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023. IEEE, 2023, pp. 3399–3415

  6. [6]

    Radsee: See your handwriting through walls using FMCW radar,

    S. Zhang, Q. Wang, M. Gan, Z. Cao, and H. Zeng, “Radsee: See your handwriting through walls using FMCW radar,” in 32nd Annual Network and Distributed System Security Symposium, NDSS 2025, San Diego, California, USA, February 24-28, 2025. The Internet Society, 2025

  7. [7]

    Screen gleaning: A screen reading TEMPEST attack on mobile devices exploiting an electromagnetic side channel,

    Z. Liu, N. Samwel, L. Weissbart, Z. Zhao, D. Lauret, L. Batina, and M. A. Larson, “Screen gleaning: A screen reading TEMPEST attack on mobile devices exploiting an electromagnetic side channel,” in 28th Annual Network and Distributed System Security Symposium, NDSS 2021, virtually, February 21-25, 2021. The Internet Society, 2021. [Online]. A vailable: ht...

  8. [8]

    mtrack: High-precision passive tracking using millimeter wave radios,

    T. Wei and X. Zhang, “mtrack: High-precision passive tracking using millimeter wave radios,” in Proceedings of the 21st Annual International Conference on Mobile Computing and Networking, MobiCom 2015, Paris, France, September 7-11, 2015, S. Fdida, G. Pau, S. K. Kasera, and H. Zheng, Eds. ACM, 2015, pp. 117–129

Show all 49 references
  1. [9]

    Capac- itive touchscreens at risk: Recovering handwritten trajectory on smartphone via electromagnetic emanations,

    Y. Cheng, S. Zhu, C. Ou, X. Han, Y. Li, and S. Zheng, “Capac- itive touchscreens at risk: Recovering handwritten trajectory on smartphone via electromagnetic emanations,” to appear in Proceedings of the 63st ACM/IEEE Design Automation Conference, DAC 2026, Long Beach, CA, USA,...

  2. [10]

    Comparative study of various touchscreen technologies,

    M. R. Bhalla and A. V. Bhalla, “Comparative study of various touchscreen technologies,” International Journal of Computer Applications, vol. 6, no. 8, pp. 12–18, 2010

  3. [11]

    Capacitive touch systems with styli for touch sensors: A review,

    O.-K. Kwon, J.-S. An, and S.-K. Hong, “Capacitive touch systems with styli for touch sensors: A review,” IEEE Sensors journal, vol. 18, no. 12, pp. 4832–4846, 2018

  4. [12]

    Review of capacitive touchscreen technologies: Overview, research trends, and machine learning approaches,

    H. Nam, K.-H. Seol, J. Lee, H. Cho, and S. W. Jung, “Review of capacitive touchscreen technologies: Overview, research trends, and machine learning approaches,” Sensors, vol. 21, no. 14, 2021. [Online]. A vailable: https://www.mdpi.com/142 4-8220/21/14/4776

  5. [13]

    Marionette: Manipulate your touchscreen via a charging cable,

    Y. Jiang, X. Ji, K. Wang, C. Yan, R. Mitev, A.-R. Sadeghi, and W. Xu, “Marionette: Manipulate your touchscreen via a charging cable,” IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 4, pp. 3309–3323, 2023

  6. [14]

    {GhostTouch}: Targeted attacks on touchscreens without physical touch,

    K. Wang, R. Mitev, C. Yan, X. Ji, A.-R. Sadeghi, and W. Xu, “{GhostTouch}: Targeted attacks on touchscreens without physical touch,” in 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 1543–1559

  7. [15]

    Frequency hopping and parallel driving with random delay especially suitable for the charger noise problem in mutual-capacitive touch applica- tions,

    S.-L. Huang, S.-Y. Hung, and C.-P. Chen, “Frequency hopping and parallel driving with random delay especially suitable for the charger noise problem in mutual-capacitive touch applica- tions,” IEEE Access, vol. 7, pp. 3980–3993, 2019

  8. [16]

    Low noise capacitive sensor for multi-touch mobile handset’s applications,

    S. Ko, H. Shin, J. Lee, H. Jang, B.-C. So, I. Yun, and K. Lee, “Low noise capacitive sensor for multi-touch mobile handset’s applications,” in 2010 IEEE Asian Solid-State Circuits Conference. IEEE, 2010, pp. 1–4

  9. [17]

    The distribution of the flora in the alpine zone. 1,

    P. Jaccard, “The distribution of the flora in the alpine zone. 1,” New phytologist, vol. 11, no. 2, pp. 37–50, 1912

  10. [18]

    The rise of keyloggers on smartphones,

    M. Hussain, A. Al-Haiqi, A. Zaidan, B. Zaidan, M. Mat Kiah, N. B. Anuar, and M. Abdulnabi, “The rise of keyloggers on smartphones,” Pervasive Mob. Comput., vol. 25, no. C, p. 1–25, Jan. 2016. [Online]. A vailable: https://doi.org/10.1016/j. pmcj.2015.12.001

  11. [19]

    S3: side-channel attack on stylus pencil through sensors,

    H. Farrukh, T. Yang, H. Xu, Y. Yin, H. Wang, and Z. B. Celik, “S3: side-channel attack on stylus pencil through sensors,” Proc. ACM Interact. Mob. Wearable Ubiquitous Technol., vol. 5, no. 1, pp. 8:1–8:25, 2021

  12. [20]

    Touchlogger: Inferring keystrokes on touch screen from smartphone motion,

    L. Cai and H. Chen, “Touchlogger: Inferring keystrokes on touch screen from smartphone motion,” in 6th USENIX Workshop on Hot Topics in Security, HotSec’11, San Francisco, CA, USA, August 9, 2011, P. D. McDaniel, Ed. USENIX Association, 2011

  13. [21]

    Practicality of accelerometer side channels on smartphones,

    A. J. A viv, B. Sapp, M. Blaze, and J. M. Smith, “Practicality of accelerometer side channels on smartphones,” in 28th Annual Computer Security Applications Conference, ACSAC 2012, Orlando, FL, USA, 3-7 December 2012, R. H. Zakon, Ed. ACM, 2012, pp. 41–50

  14. [22]

    Accessory: password inference using accelerometers on smartphones,

    E. Owusu, J. Han, S. Das, A. Perrig, and J. Zhang, “Accessory: password inference using accelerometers on smartphones,” in 2012 Workshop on Mobile Computing Systems and Applica- tions, HotMobile ’12, San Diego, CA, USA, February 28-29, 2012, G. Borriello and R. K. Balan, Eds. ...

  15. [23]

    Gyrophone: Recognizing speech from gyroscope signals,

    Y. Michalevsky, D. Boneh, and G. Nakibly, “Gyrophone: Recognizing speech from gyroscope signals,” in Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA, August 20-22, 2014, K. Fu and J. Jung, Eds. USENIX Association, 2014, pp. 1053–1067

  16. [24]

    Mole: Motion leaks through smartwatch sensors,

    H. Wang, T. T. Lai, and R. R. Choudhury, “Mole: Motion leaks through smartwatch sensors,” in Proceedings of the 21st Annual International Conference on Mobile Computing and Networking, MobiCom 2015, Paris, France, September 7-11, 2015, S. Fdida, G. Pau, S. K. Kasera, and H. Zh...

  17. [25]

    3d handwriting charac- ters recognition with symbolic-based similarity measure of gy- roscope signals embedded in smart phone,

    M. Taktak, S. Triki, and A. Kamoun, “3d handwriting charac- ters recognition with symbolic-based similarity measure of gy- roscope signals embedded in smart phone,” in 14th IEEE/ACS International Conference on Computer Systems and Applica- tions, AICCSA 2017, Hammamet, Tunisia...

  18. [26]

    Indoor localization and navigation using smartphone sensory data,

    H.-H. Hsu, J.-K. Chang, W.-J. Peng, T. K. Shih, T.-W. Pai, and K. L. Man, “Indoor localization and navigation using smartphone sensory data,” Annals of Operations Research, vol. 265, pp. 187–204, 2018

  19. [27]

    Touchsignatures: Identification of user touch actions based on mobile sensors via javascript,

    M. Mehrnezhad, E. Toreini, S. F. Shahandashti, and F. Hao, “Touchsignatures: Identification of user touch actions based on mobile sensors via javascript,” in Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, ser. ASIA CCS ’15. New York...

  20. [28]

    Pin skimming: Exploiting the ambient-light sen- sor in mobile devices,

    R. Spreitzer, “Pin skimming: Exploiting the ambient-light sen- sor in mobile devices,” in Proceedings of the 4th ACM Workshop on Security and Privacy in Smartphones & Mobile Devices, 2014, pp. 51–62

  21. [29]

    Power-related side-channel attacks using the android sensor framework,

    M. Oberhuber, M. Unterguggenberger, L. Maar, A. Kogler, and S. Mangard, “Power-related side-channel attacks using the android sensor framework,” in Network and Distributed System Security Symposium 2025: NDSS 2025, 2025

  22. [30]

    Sys- tematic classification of side-channel attacks: A case study for mobile devices,

    R. Spreitzer, V. Moonsamy, T. Korak, and S. Mangard, “Sys- tematic classification of side-channel attacks: A case study for mobile devices,” IEEE Communications Surveys & Tutorials, vol. 20, no. 1, pp. 465–488, 2018

  23. [31]

    No free charge theorem: A covert channel via usb charging cable on mobile devices,

    R. Spolaor, L. Abudahi, V. Moonsamy, M. Conti, and R. Poovendran, “No free charge theorem: A covert channel via usb charging cable on mobile devices,” in Applied Cryptography and Network Security, D. Gollmann, A. Miyaji, and H. Kikuchi, Eds. Cham: Springer International Publis...

  24. [33]

    Graphics peeping unit: Exploiting EM side- channel information of gpus to eavesdrop on your neighbors,

    Z. Zhan, Z. Zhang, S. Liang, F. Yao, and X. D. Koutsoukos, “Graphics peeping unit: Exploiting EM side- channel information of gpus to eavesdrop on your neighbors,” in 43rd IEEE Symposium on Security and Privacy, SP 2022, San Francisco, CA, USA, May 22-26, 2022. IEEE, 2022, pp....

  25. [34]

    Exploiting contactless side channels in wireless charging power banks for user privacy inference via few-shot 18 learning,

    T. Ni, J. Li, X. Zhang, C. Zuo, W. Wang, W. Xu, X. Luo, and Q. Zhao, “Exploiting contactless side channels in wireless charging power banks for user privacy inference via few-shot 18 learning,” in Proceedings of the 29th Annual International Conference on Mobile Computing and ...

  26. [35]

    Nonce@once: A single-trace EM side channel attack on several constant-time elliptic curve implementations in mobile platforms,

    M. Alam, B. B. Yilmaz, F. Werner, N. Samwel, A. G. Zajic, D. Genkin, Y. Yarom, and M. Prvulovic, “Nonce@once: A single-trace EM side channel attack on several constant-time elliptic curve implementations in mobile platforms,” in IEEE European Symposium on Security and Privacy,...

  27. [36]

    ECDSA key extraction from mobile devices via nonintrusive physical side channels,

    D. Genkin, L. Pachmanov, I. Pipman, E. Tromer, and Y. Yarom, “ECDSA key extraction from mobile devices via nonintrusive physical side channels,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, October 24-28, 2016, E. R...

  28. [37]

    Ensuring cross-device portability of electromagnetic side-channel analysis for digital forensics,

    L. Navanesan, N. Le-Khac, M. Scanlon, K. D. Zoysa, and A. P. Sayakkara, “Ensuring cross-device portability of electromagnetic side-channel analysis for digital forensics,” Forensic Sci. Int. Digit. Investig., vol. 48, p. 301684, 2024. [Online]. A vailable: https://doi.org/10.1...

  29. [38]

    Magattack: Guessing application launching and operation via smartphone,

    Y. Cheng, X. Ji, W. Xu, H. Pan, Z. Zhu, C. You, Y. Chen, and L. Qiu, “Magattack: Guessing application launching and operation via smartphone,” in Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, AsiaCCS 2019, Auckland, New Zealand, July 09-1...

  30. [39]

    EM eye: Characterizing electromagnetic side-channel eavesdropping on embedded cameras,

    Y. Long, Q. Jiang, C. Yan, T. Alam, X. Ji, W. Xu, and K. Fu, “EM eye: Characterizing electromagnetic side-channel eavesdropping on embedded cameras,” in 31st Annual Network and Distributed System Security Symposium, NDSS 2024, San Diego, California, USA, February 26 - March 1,...

  31. [40]

    Invisible finger: Practical electromagnetic interference attack on touchscreen-based electronic devices,

    H. Shan, B. Zhang, Z. Zhan, D. Sullivan, S. Wang, and Y. Jin, “Invisible finger: Practical electromagnetic interference attack on touchscreen-based electronic devices,” in 43rd IEEE Symposium on Security and Privacy, SP 2022, San Francisco, CA, USA, May 22-26, 2022. IEEE, 2022...

  32. [41]

    Ios device compatibility reference

    Apple, “Ios device compatibility reference. ” 2023. [Online]. A vailable: https://developer.apple.com/library/archive/docu mentation/DeviceInformation/Reference/iOSDeviceCompati bility/Displays/Displays.html#//apple_ref/doc/uid/TP400 13599-CH108-SW5&xcust=1-1-230654-1-0-0-0-0&...

  33. [42]

    Mi 10 pro faq

    Xiaomi, “Mi 10 pro faq. ” 2025. [Online]. A vailable: https: //www.mi.com/global/support/faq/details/KA-07244/

  34. [43]

    Specifications | samsung galaxy s10

    Samsung, “Specifications | samsung galaxy s10. ” 2021. [Online]. A vailable:https://www.samsung.com/latin_en/smartphones/ galaxy-s10/specs/

  35. [44]

    Huawei mate 30 pro specifications

    Huawei, “Huawei mate 30 pro specifications. ” 2022. [Online]. A vailable:https://consumer.huawei.com/au/phones/mate30-p ro/specs/

  36. [45]

    When csi meets public wifi: Inferring your mobile phone password via wifi signals,

    M. Li, Y. Meng, J. Liu, H. Zhu, X. Liang, Y. Liu, and N. Ruan, “When csi meets public wifi: Inferring your mobile phone password via wifi signals,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’16. New York, NY, USA: Associ...

  37. [46]

    Tap ’n ghost: A compilation of novel attack techniques against smartphone touchscreens,

    S. Maruyama, S. Wakabayashi, and T. Mori, “Tap ’n ghost: A compilation of novel attack techniques against smartphone touchscreens,” in 2019 IEEE Symposium on Security and Pri- vacy (SP), 2019, pp. 620–637

  38. [47]

    How to see who’s connected to your wi-fi net- work,

    C. Hoffman., “How to see who’s connected to your wi-fi net- work,” 2020, https://www.howtogeek.com/204057/how-to-see- whos-connected-to-your-wi-fi-network/

  39. [48]

    Even black cats cannot stay hidden in the dark: Full-band de-anonymization of bluetooth classic devices,

    M. Cominelli, F. Gringoli, P. Patras, M. Lind, and G. Noubir, “Even black cats cannot stay hidden in the dark: Full-band de-anonymization of bluetooth classic devices,” in 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 2020, pp. 534–548

  40. [49]

    Blueid: A practical system for bluetooth device identification,

    J. Huang, W. Albazrqaoe, and G. Xing, “Blueid: A practical system for bluetooth device identification,” in IEEE INFOCOM 2014 - IEEE Conference on Computer Communications, 2014, pp. 2849–2857

  41. [50]

    An overview of the tesseract ocr engine,

    R. Smith, “An overview of the tesseract ocr engine,” in ICDAR ’07: Proceedings of the Ninth International Conference on Document Analysis and Recognition. Washington, DC, USA: IEEE Computer Society, 2007, pp. 629–633. [Online]. A vailable:https://storage.googleapis.com/pub-too...

Pith tools

Reviewed June 30, 2026 · model on record in the stance chip above.