VYPR
researchPublished Sep 8, 2026· 1 source

InjectEave Attack Leverages Electromagnetic Signals to Eavesdrop on Headphones from 30 Meters

Researchers have developed a novel electromagnetic attack, dubbed InjectEave, capable of eavesdropping on audio played through wired and wireless headphones from up to 30 meters away, even through walls.

A groundbreaking electromagnetic attack named InjectEave has been developed by researchers, enabling adversaries to eavesdrop on audio from wired and wireless headphones at distances of up to 30 meters, and even through solid walls. This novel technique, detailed in a paper accepted at USENIX Security '26, actively injects a radio-frequency signal into the target device, exploiting hardware nonlinearities to modulate and re-radiate the audio signal.

Unlike traditional passive electromagnetic (EM) side-channel attacks that rely on detecting stray emissions, InjectEave employs an active "Injection-Modulation-Emission" model. It injects a tuned RF carrier signal that interacts with nonlinear components commonly found in audio amplifiers, analog-to-digital converters, and power converters within headphones and other electronic devices. This interaction effectively "mixes" the secret audio signal with the injected carrier, allowing it to be re-radiated on a higher frequency that can travel much farther than passive leakage.

The effectiveness of InjectEave stems from its ability to overcome the inherent distance limitations of prior EM eavesdropping methods. Previous research, such as MagEar and Periscope, was constrained by the low frequencies of audio signals (20 Hz to 20 kHz) and the inefficient radiation from device wiring at these frequencies, limiting eavesdropping to under 1.5 meters. InjectEave circumvents this by actively shaping the leakage, allowing attackers to tune an optimal injection frequency for each target.

In tests conducted by the research team from the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University, InjectEave demonstrated remarkable success. Using commercially available radio-frequency equipment, the attack achieved near-100% audio recognition rates on 11 different devices, including headphones from major brands like Sony, Apple, and Philips, as well as VoIP phones and smart home gadgets. At a baseline distance of 50 centimeters, signal-to-noise ratios were impressively high.

When an external power amplifier was introduced, boosting injection power, the effective eavesdropping range extended to a significant 30 meters for certain headphone models. Crucially, the attack proved resilient to physical barriers. Glass and wood caused minimal signal loss, and even solid concrete walls only attenuated the signal by approximately 5.8 dB for headphones, making through-wall eavesdropping feasible in various environments like offices and conference rooms.

The researchers also showcased a sophisticated "Eavesdrop-Synthesize-Inject" attack against a landline phone. In this scenario, an attacker could eavesdrop on one party, use AI voice-cloning tools to synthesize the speaker's voice upon detecting keywords, and then inject the deepfaked audio back into the target's headset in real-time. The synthesized audio was found to be nearly indistinguishable from the original, with minimal deviation in intelligibility metrics.

To enhance the clarity of the recovered audio, which is inherently noisy due to harmonic distortion, the team developed a signal-enhancement module utilizing a diffusion-based speech-denoising model. This module significantly improved the signal-to-noise ratio and intelligibility of the eavesdropped audio, making it more usable for malicious purposes.

While the research highlights the potential for exploitation, it also points to potential mitigation strategies. The study noted that twisted-pair cabling could reduce leakage by up to 20 dB compared to standard parallel wiring, offering hardware manufacturers a path to partially mitigate such attacks.

Synthesized by Vypr AI