Skip to main content
QUICK REVIEW

[Paper Review] Trick or Heat? Manipulating Critical Temperature-Based Control Systems Using Rectification Attacks

Yazhou Tu, Sara Rampazzi|arXiv (Cornell University)|Apr 10, 2019
Electrostatic Discharge in Electronics49 references20 citations
TL;DR

This paper demonstrates a physical-layer attack that exploits unintended rectification in operational and instrumentation amplifiers to remotely manipulate temperature sensor readings in critical control systems, such as infant incubators and refrigeration units, without triggering alarms. The attack induces controllable DC offsets via low-power electromagnetic interference, enabling remote heating or cooling to dangerous levels (e.g., 38.5°C or 29°C) at distances up to 1.9 m.

ABSTRACT

Temperature sensing and control systems are widely used in the closed-loop control of critical processes such as maintaining the thermal stability of patients, or in alarm systems for detecting temperature-related hazards. However, the security of these systems has yet to be completely explored, leaving potential attack surfaces that can be exploited to take control over critical systems. In this paper we investigate the reliability of temperature-based control systems from a security and safety perspective. We show how unexpected consequences and safety risks can be induced by physical-level attacks on analog temperature sensing components. For instance, we demonstrate that an adversary could remotely manipulate the temperature sensor measurements of an infant incubator to cause potential safety issues, without tampering with the victim system or triggering automatic temperature alarms. This attack exploits the unintended rectification effect that can be induced in operational and instrumentation amplifiers to control the sensor output, tricking the internal control loop of the victim system to heat up or cool down. Furthermore, we show how the exploit of this hardware-level vulnerability could affect different classes of analog sensors that share similar signal conditioning processes. Our experimental results indicate that conventional defenses commonly deployed in these systems are not sufficient to mitigate the threat, so we propose a prototype design of a low-cost anomaly detector for critical applications to ensure the integrity of temperature sensor signals.

Motivation & Objective

  • To investigate the security and safety risks of temperature-based control systems when subjected to physical-layer attacks on analog sensor components.
  • To demonstrate how electromagnetic interference (EMI) can induce unintended rectification in amplifiers, leading to spoofed temperature readings that bypass alarms.
  • To evaluate the feasibility and impact of such attacks on real-world safety-critical systems, including infant incubators and laboratory scales.
  • To analyze the vulnerability of other analog sensors—such as pressure and pH sensors—that use similar signal conditioning circuits.
  • To propose a low-cost analog anomaly detector prototype to improve sensor signal integrity and mitigate the threat.

Proposed method

  • The attack exploits unintended rectification in operational and instrumentation amplifiers, where incident electromagnetic signals generate a controllable DC voltage offset on the amplifier output.
  • Low-power, amplitude-modulated EMI signals in the UHF band (300 MHz – 3 GHz) are transmitted remotely to induce voltage offsets in sensor circuits without direct physical access.
  • Experiments were conducted using direct power injection (DPI) and remote signal injection on off-the-shelf temperature sensors and control systems, including infant incubators and precision scales.
  • The attack was validated on multiple systems: infant incubators, digital lab scales (CGOLDENWALL and Escali L600), and a pH meter, with varying attack distances and signal frequencies.
  • The effectiveness was measured by observing changes in sensor output (e.g., temperature, weight, pH) under EMI injection, with results quantified in degrees Celsius, grams, and pH units.
  • A prototype analog anomaly detector was designed to detect abnormal signal characteristics indicative of spoofing, enhancing sensor integrity in critical applications.

Experimental results

Research questions

  • RQ1Can electromagnetic interference be used to induce a controllable DC offset in temperature sensor signals via unintended rectification in amplifiers?
  • RQ2To what extent can such an attack remotely manipulate temperature readings in safety-critical systems like infant incubators without triggering alarms?
  • RQ3Are other analog sensors—such as pressure and pH sensors—that use similar signal conditioning circuits also vulnerable to this type of attack?
  • RQ4How do system-level factors (e.g., shielding, noise rejection, antenna type and orientation) affect the success and range of the attack?
  • RQ5Can conventional EMI defenses adequately mitigate this hardware-level vulnerability, or is a new detection mechanism required?

Key findings

  • An adversary can remotely manipulate an infant incubator’s temperature to 38.5°C (hyperthermia risk) or 29°C (hypothermia risk) at a distance of 1.9 m using 4 W of transmitted power.
  • The attack successfully induced a 6.37 g decrease in a CGOLDENWALL digital scale and a 7 g decrease or 13.9 g increase in an Escali L600 scale at 0.5 m distance using EMI at 685 MHz.
  • A pH meter’s reading was increased by 0.42 pH units at 0.5 m with EMI at 515 MHz, demonstrating vulnerability in SCADA and water treatment systems.
  • The attack remains effective even when systems employ traditional EMI defenses, indicating that conventional protections are insufficient against this physical-layer exploit.
  • The amount of induced DC offset is significantly influenced by system shielding, noise rejection circuitry, and antenna characteristics and orientation.
  • A prototype analog anomaly detector was proposed to detect spoofed signals, offering a practical defense mechanism for critical temperature-sensing applications.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.