VLDB 2026 Research / reviewers in the wild / expert
Giovanni Camurati
dblp:224/9311
· DBLP profile ↗
10ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-3510-6895ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security Analysis of Time-of-Arrival Estimation via Cross-Correlation under Narrow-Band ConditionsabstractTime-of-arrival (ToA) estimation via cross-correlation is an essential building block of time-of-flight ranging. However, in narrowband systems, it is notoriously difficult to protect against distance-decreasing attacks such as Early-Detect/Late-Commit (ED/LC). We present and analyze two new attacks that reshape ranging signals to compromise correlation-based ToA estimation. The first attack multiplies the signal by a symbol-periodic waveform in the time domain, while the second passes it through a negative group delay (NGD) filter. In contrast to ED/LC, our attacks do not require real-time symbol detection or adaptive compensation; they are completely symbol-agnostic. We describe implementation strategies for both attacks and discuss NGD filtering in the context of Bluetooth Channel Sounding (CS), a recent narrowband ranging system. To this end, we simulate an NGD circuit in LTspice and a ToA estimator in MATLAB, demonstrating that the attack can result in distance reductions of up to 18 m against Bluetooth CS RTT ranging. Finally, we verify the feasibility of the NGD approach by building a prototype using commercial off-the-shelf components. Claudio Anliker, Daniele Coppola, Giovanni Camurati, Srdjan Capkun |
WISEC | 3 |
| 2025 | LEO-Range: Physical Layer Design for Secure Ranging with Low Earth Orbiting Satellites
Daniele Coppola, Arslan Mumtaz, Giovanni Camurati, Harshad Sathaye, Mridula Singh, Srdjan Capkun |
USENIX Security Symposium | 3 |
| 2025 | GNSS-WASP: GNSS Wide Area SPoofing
Christopher Tibaldo, Harshad Sathaye, Giovanni Camurati, Srdjan Capkun |
USENIX Security Symposium | 3 |
| 2024 | PURE: Payments with UWB RElay-protection
Daniele Coppola, Giovanni Camurati, Claudio Anliker, Xenia Hofmeier, Patrick Schaller, David A. Basin, Srdjan Capkun |
USENIX Security Symposium | 2 |
| 2023 | EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus Systems
Marc Röschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh, Srdjan Capkun |
NDSS | 2 |
| 2023 | Time for Change: How Clocks Break UWB Secure Ranging
Claudio Anliker, Giovanni Camurati, Srdjan Capkun |
USENIX Security Symposium | 2 |
| 2022 | Noise-SDR: Arbitrary Modulation of Electromagnetic Noise from Unprivileged Software and Its Impact on Emission SecurityabstractElectronic devices generate electromagnetic noise, also known as EM leakage when the noise leaks information. Many recent research papers exploit the fact that software activity can exploit this leakage to generate radio signals. This process breaks the isolation between simple unprivileged code and the radio spectrum, letting an attacker generate physical radio signals without accessing any radio interface. Previous work has discovered many leakage sources and covert communication channels, which generally use simple modulation schemes. However, a fundamental research question has been left unexplored: to which point can attackers shape electromagnetic leakage into signals of their choice? The answer to this question has an important security impact that goes beyond specific attacks or platforms. Indeed, arbitrary signal modulation is a useful primitive. This would allow attackers to use advanced modulations and better exploit the channel (leakage) capacity, for example, to establish advanced communication channels, or to inject malicious signals into victim receivers. At a first analysis, arbitrary modulation seems impossible: software has limited control on the leakage and existing attacks are therefore constrained to on-off keying or frequency-shift keying. In this paper, we demonstrate that shaping arbitrary signals out of electromagnetic noise is possible from unprivileged software. For this we leverage fully-digital radio techniques and call our method Noise-SDR because, similarly to a software-defined radio, it can transmit a generic signal synthesized in software. We demonstrate our approach with a practical implementation with DRAM accesses on ARMv7-A, ARMv8-A, x86-64, and MIPS32. We evaluate it on different types of devices, including smartphones, a laptop, a desktop, and a Linux-based IoT device. Although power, frequency and bandwidth are constrained by the properties of the leakage, we present several case studies, including transmission with advanced protocols, device tracking, and signal injection. Giovanni Camurati, Aurélien Francillon |
SP | 1 |
| 2022 | Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Röschlin, Claudio Anliker, Matthias Hollick, Srdjan Capkun, Jiska Classen |
USENIX Security Symposium | 2 |
| 2018 | Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversabstractThis paper presents a new side channel that affects mixed-signal chips used in widespread wireless communication protocols, such as Bluetooth and WiFi. This increasingly common type of chip includes the radio transceiver along with digital logic on the same integrated circuit. In such systems, the radio transmitter may unintentionally broadcast sensitive information from hardware cryptographic components or software executing on the CPU. The well-known electromagnetic (EM) leakage from digital logic is inadvertently mixed with the radio carrier, which is amplified and then transmitted by the antenna. We call the resulting leak screaming channels. Attacks exploiting such a side channel may succeed over a much longer distance than attacks exploiting usual EM side channels. The root of the problem is that mixed-signal chips include both digital circuits and analog circuits on the same silicon die in close physical proximity. While processing data, the digital circuits on these chips generate noise, which can be picked up by noise-sensitive analog radio components, ultimately leading to leakage of sensitive information. We investigate the physical reasons behind the channel, we measure it on several popular devices from different vendors (including Nordic Semiconductor nRF52832, and Qualcomm Atheros AR9271), and we demonstrate a complete key recovery attack against the nRF52832 chip. In particular, we retrieve the full key from the AES-128 implementation in tinyAES at a distance of 10 m using template attacks. Additionally, we recover the key used by the AES-128 implementation in mbedTLS at a distance of 1 m with a correlation attack. Screaming channel attacks change the threat models of devices with mixed-signal chips, as those devices are now vulnerable from a distance. More specifically, we argue that protections against side channels (such as masking or hiding) need to be used on this class of devices. Finally, chips implementing other widespread protocols (e.g., 4G/LTE, RFID) need to be inspected to determine whether they are vulnerable to screaming channel attacks. Giovanni Camurati, Sebastian Poeplau, Marius Muench, Thomas P. Hayes, Aurélien Francillon |
CCS | 1 |
| 2018 | Inception: System-Wide Security Testing of Real-World Embedded Systems Software
Nassim Corteggiani, Giovanni Camurati, Aurélien Francillon |
USENIX Security Symposium | 2 |