Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
By Ramana Ranganatham 1, Chirag Adiga 1, Michael Zuzak 2, Tejasvi Das 1
1 RAMLab, the Department of Electrical and Microelectronic Engineering, Rochester Institute of Technology.
2 Department of Computer Engineering, Rochester Institute of Technology, Rochester, NY, 14623

Abstract
Mixed-signal SoCs rely on nominally input-only analog pins to acquire off-chip signals, but the directionality of these interfaces is generally treated as a functional property rather than explicitly verified as a security property. This work identifies and experimentally demonstrates a directionality-based class of analog and mixed-signal (AMS) exfiltration attacks in which data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. We analytically model the attack mechanism and identify three enabling host conditions: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. This attack class is validated through a representative silicon case study using a photoplethysmography (PPG) analog front-end (AFE) fabricated in a commercial 55-nm CMOS process. The payload incurs <0.001% area overhead relative to typical biosensing AFEs. Under the evaluated conditions, payload activation reduces the filtered PPG-output SNR by only 0.03~dB, while the maximum HT-induced perturbation of 5.9% of the PPG amplitude remains within the 34.3% benign variation at the exposed sensor-input pin across process and temperature. The raw exfiltration SINR remains below -20~dB, while targeted filtering increases it above 14~dB and enables signal recovery. Silicon measurements demonstrate data exfiltration through the input pin at bit rates up to 10~kbps and error-free recovery of a PRBS message. These results expose a conventional test-observability gap and establish analog pin directionality as an AMS security property requiring explicit verification, test coverage, and defense rather than being inferred from nominal signal flow.
Index Terms — Analog security, hardware security, hardware trojan (HT), exfiltration, analog front end (AFE), input-referred offset, analog pin directionality
To read the full article, click here
Related Semiconductor IP
- 40nm 1.1V AFE comprising 12-bit IQ ADC, 12-bit IQ DAC and Clock-PLL
- Ultra Low-Power High-Performance AFE on TSMC 16nm
- Ultra Low-Power High-Performance AFE in 12nm
- Ultra Low-Power High-Performance AFE on 12nm
- Highly-integrated AFE with 16 ADCs and 18 DACs on TSMC 16nm FFC
Related Articles
- 7 myths of analog and mixed-signal ASIC design
- An Introduction to Direct RF Sampling in a World Evolving Towards Chiplets - Part 1
- Quantifying Uncertainty in FMEDA Safety Metrics: An Error Propagation Approach for Enhanced ASIC Verification
- Analog and Mixed-Signal Connectivity IP at 65nm and below
Latest Articles
- Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
- SIMT-Aware Lockstep Verification and Functional-Coverage Closure Methodology for an Open-Source RISC-V GPGPU: A UVM 1.2 Environment
- Efficient Hardware Information-Flow Tracking for Pre-Silicon Security Testing
- REACH: Controller-Managed Long-Span ECC for HBM AI Inference
- FPGA Acceleration of Fully Homomorphic Encryption with Adaptive Key Switching