arXiv is now an independent nonprofit! Learn more
License: CC BY 4.0
arXiv:2609.28916v1 [eess.SP] 24 Sep 2026

Fast Frame Rate Estimation in Electromagnetic Side-Channel Attacks on Public Systems

Alyson Isaluski1    Leonardo Teodoro1    Kleber V. Cardoso2    Antonio Oliveira-Jr2,3 Affiliation: Saulo Queiroz1
Abstract

Frame refresh rate estimation is a fundamental step in identifying compromising harmonic frequencies in electromagnetic side-channel attacks. Methods based on discrete linear autocorrelation (DLA) are robust across different scenarios and require a computational complexity of O⁡(N​log⁡N)O(N\log N) for a signal containing NN samples. This work proposes reducing this complexity to O⁡(N)O(N) by exploiting prior knowledge of the target system’s display resolution, as is available for certain models of the Brazilian electronic voting machine. Experiments using software-defined radios show that the proposed method preserves the accuracy of the conventional approach in the evaluated scenarios.

   
1 Federal University of Technology – Paraná (UTFPR)
Ponta Grossa – PR – Brazil
{alysonisaluski, lteodoro}@alunos.utfpr.edu.br,
{kleber, antoniojr}@ufg.br,
sauloqueiroz@utfpr.edu.br
2Federal University of Goiás (UFG)
Goiânia – GO – Brazil.
3Fraunhofer Portugal AICOS, Porto 4200-135, Portugal.
 

1 Introduction

Electromagnetic side-channel attacks (e-SCAs) refer to a class of security threats in which sensitive information is inferred from unintentional electromagnetic emissions produced by the movement of electric charges. These attacks are commonly known as TEMPEST attacks [1]. In this work, we use the term TEMPEST specifically to denote e-SCAs targeting video devices.

A critical challenge in TEMPEST attacks is estimating the frame refresh rate (FRR) from the leaked signal, which is necessary to reconstruct the intercepted image and helps identify a compromising harmonic frequency. Various methods for FRR estimation have been considered in the literature [8], [2], [7]. Among these, discrete linear autocorrelation (DLA) stands out as a popular method in practical TEMPEST libraries because of its effective estimation across diverse scenarios [3], [6].

This work proposes a method to reduce the computational complexity of DLA from O⁡(N​log⁡N)O(N\log N) to O⁡(N)O(N) in scenarios where the target system’s display resolution is known beforehand, as observed in [11] for some Brazilian electronic voting machine (UEB) models currently in use. The proposed method is validated using real TEMPEST signals obtained in experiments with software-defined radio (SDR).

2 TEMPEST Signal Model

This section introduces the theoretical foundations of this work. First, Subsection 2.1 presents the TEMPEST signal parameters required by the proposed method. Next, Subsection 2.2 presents the DLA method, whose computational complexity is optimized in this work.

2.1 Basic TEMPEST Parameters

The VGA signal assumed in this work can be modeled as a sum of rectangular pulses:

x⁡(t)=∑n=−∞∞x⁡[n]​p​(t−n​Tp),x(t)=\sum_{n=-\infty}^{\infty}x[n]p(t-nT_{p}), (1)

where x⁡(t)x(t) represents the real-valued continuous-time signal at time tt. The period (i.e., duration) TpT_{p} of each pixel (pulse) in the cable depends on the display resolution and frame refresh rate. TpT_{p} can be defined as

Tp=1Px​Py​fvs,T_{p}=\frac{1}{P_{x}P_{y}f_{v}}\quad\textrm{s}, (2)

where PxP_{x}, PyP_{y}, and fvf_{v} denote the number of pixels per line (including synchronization pixels, i.e., blanking pixels), the number of lines per display frame, and the refresh rate, respectively. TEMPEST attacks are made possible by distortions inherent in the analog components of the video system, which cause leakage at harmonic frequencies that are multiples of the pixel rate [1], [4], [5]. An adversary who tunes an SDR to one of these frequencies can recover the image carried by the signal.

2.2 FRR Estimation Using the DLA Method

After acquiring the raw signal using an SDR in a TEMPEST attack, the frame refresh rate fvf_{v} must be estimated. The DLA method relies on identifying the dominant peak of the autocorrelation function. For a discrete complex-valued signal x⁡[n]x[n] containing NN samples, the autocorrelation at lag τ\tau is given by

Rx​x​(τ)\displaystyle R_{xx}(\tau) =\displaystyle= ∑n=τN−1x⁡[n]​x∗​[n−τ],0≤τ<N,\displaystyle\sum_{n=\tau}^{N-1}x[n]x^{*}[n-\tau],\qquad 0\leq\tau<N, (3)

where x∗​[n]x^{*}[n] denotes the complex conjugate of x⁡[n]x[n]. For a sampling rate fsf_{s}, the FRR estimate is obtained as

fv\displaystyle f_{v} ≈\displaystyle\approx fs/τmax,\displaystyle f_{s}/\tau_{\max}, (4)

where τmax\tau_{\max} is the lag associated with the highest peak in (3).

A direct implementation of DLA evaluates the autocorrelation at all lags of interest, resulting in a complexity of O⁡(N2)O(N^{2}). To reduce this cost, widely used TEMPEST tools [3], [6] rely on the Wiener–Khinchin theorem, according to which autocorrelation can be obtained from the inverse Fourier transform of the signal’s power spectrum. Thus, using the fast Fourier transform (FFT) algorithm and its inverse (IFFT), the DLA method runs in O⁡(N​log⁡N)O(N\log N) time. Although efficient in the general case, the computational cost of processing signals containing millions of samples—such as the TEMPEST signals considered in this work—may become a limiting factor in critical applications subject to stringent timing constraints, as demonstrated in [9].

3 The Fast DLA (F-DLA) Method

The proposed method, called F-DLA (fast DLA), reduces the computational complexity of conventional DLA by exploiting TEMPEST scenarios in which the parameters PxP_{x} and PyP_{y} may be known a priori. Although this is a strong assumption in general TEMPEST scenarios, the assumption that the target system’s parameters are unknown can be relaxed in contexts governed by transparency principles, as in the Brazilian electoral system. Public specifications establish resolutions of 1280×7681280\times 768 for the UE2013/UE2015 models [12] and at least 1280×7201280\times 720 for the UE2020 model [13]. Thus, even without prior knowledge of the model in use, the VESA standard restricts the set of candidate FRRs to only R=4R=4 values for these resolutions: 60, 75, 85, and 120 Hz [15]. Accordingly, the first significant autocorrelation peak is expected at one of the lags {fs/60,fs/75,fs/85,fs/120}\{f_{s}/60,f_{s}/75,f_{s}/85,f_{s}/120\}, with R=O⁡(1)R=O(1) with respect to NN.

Correct operation of the DLA method assumes that channel-induced distortions do not shift the dominant autocorrelation peak beyond the interval associated with the correct FRR. Otherwise, even conventional DLA would produce an incorrect estimate. Therefore, in scenarios where conventional DLA operates correctly, the shift δ\delta must remain bounded by a constant independent of NN. Consequently, only the lags within a neighborhood of δ\delta samples around the RR candidates need to be evaluated. Since R=O⁡(1)R=O(1) and δ=O⁡(1)\delta=O(1), the set 𝒯\mathcal{T} of candidate lags whose autocorrelation values must be evaluated has size

|𝒯|=(2​δ+1)​R=O⁡(1).\displaystyle|\mathcal{T}|=(2\delta+1)R=O(1). (5)

Similarly to Eq. (4), F-DLA estimates the FRR as

fv\displaystyle f_{v} ≈\displaystyle\approx fsτF​-​D​L​A,\displaystyle\frac{f_{s}}{\tau_{F\textrm{-}DLA}}, (6)

where τF​-​D​L​A∈𝒯\tau_{F\textrm{-}DLA}\in\mathcal{T} is the lag that maximizes the autocorrelation function:

Rx​x​(τF​-​D​L​A)=maxτ∈𝒯⁡Rx​x​(τ)\displaystyle R_{xx}(\tau_{F\textrm{-}DLA})=\max_{\tau\in\mathcal{T}}R_{xx}(\tau) (7)

Since each lag in 𝒯\mathcal{T} is evaluated in O⁡(N)O(N) time (3) and this list has constant size (5), the overall complexity of F-DLA is

TF−D​L​A​(N)=|𝒯|​N=O⁡(N),\displaystyle T_{F-DLA}(N)=|\mathcal{T}|N=O(N), (8)

which is therefore lower than the O⁡(N​log⁡N)O(N\log N) complexity of conventional DLA. Under severe channel degradation, the assumption δ=O⁡(1)\delta=O(1) may no longer hold, compromising FRR estimation by both DLA and F-DLA. Since this work aims to validate F-DLA as an alternative to DLA in at least one real-world scenario, evaluation under degraded channel conditions is left for future work.

4 Preliminary Results

This section compares the proposed F-DLA method with conventional DLA in terms of execution time and the accuracy of the fvf_{v} estimate, using signals obtained in a real SDR-based TEMPEST experiment. The experiments used a VGA monitor displaying the UEB interface (available in [14]), configured with an FRR of fv=60f_{v}=60 Hz and a display resolution of 1280×7201280\times 720, compatible with the UE2020 model. For this configuration, Px=1650P_{x}=1650 pixels and Py=750P_{y}=750 lines per frame, according to the VESA standard [15]. For further details on the results presented in this section, as well as additional results omitted owing to space limitations, the reader is referred to the lead author’s repository11 1 https://github.com/AlysonIsa/SBSeg-FDLA..

The video TEMPEST signal was captured using an Ettus USRP B200 SDR connected to a digital TV antenna positioned ≈\approx 20 cm from the monitor, with the SDR operating at a sampling rate of fs=54f_{s}=54 MHz. Both methods used N=221N=2^{21} samples. This number is sufficient to capture the minimum of two consecutive frames, corresponding to 2​(fs/fv)=1.8×1062(f_{s}/f_{v})=1.8\times 10^{6} samples in the scenario considered. The xcorr function from GNU Octave’s signal package was used as the reference implementation of conventional DLA. For the proposed F-DLA method, the smallest value of δ\delta that produced the correct fvf_{v} estimate in the experiments was 1. Although preliminary, the experimental results support the theoretical gains discussed in Section 3. A more comprehensive experimental evaluation is planned for an extended version of this work.

Figure 1(a) shows the autocorrelation function of the TEMPEST signal whose image, reconstructed using the gr-tempest module [3], is shown in Fig. 1(b). The time lag τs\tau_{s}, in seconds, was obtained using τs=τ/fs\tau_{s}=\tau/f_{s}. The autocorrelation peak identified by F-DLA (red bar) at τs=0.016667\tau_{s}=0.016667 s coincides with that obtained by DLA (blue curve) and corresponds to the expected FRR of 1/τs≈601/\tau_{s}\approx 60 Hz. However, F-DLA produced this estimate in approximately 0.30 s, with a confidence interval (CI) of ±0.01\pm 0.01 s (95% confidence), whereas conventional DLA required approximately 0.67 s, with a CI of ±0.02\pm 0.02 s. The observed difference reflects implementation constants and optimizations in the xcorr function, as well as the asymptotic orders of the algorithms. This result indicates that restricting the set of candidate lags based on prior knowledge of PxP_{x} and PyP_{y}, as in the case of the UEB, can reduce the computational cost of estimation without compromising FRR accuracy in the evaluated scenario.

Refer to caption
(a) Autocorrelation function plot.
Refer to caption
(b) TEMPEST image reconstructed from the experiments.
Figure 1: F-DLA (proposed) and DLA (conventional): FRR identification in an experimental TEMPEST channel. The autocorrelation peak at τs≈0.016667\tau_{s}\approx 0.016667 s obtained by both methods in (a) corresponds to the correct FRR of 60 Hz for the reconstructed image in (b).

5 Conclusion

This work presented Fast DLA (F-DLA), a low-complexity alternative for frame refresh rate estimation in TEMPEST attacks. The method exploits scenarios where the target graphics system’s parameters may be known a priori, restricting the set of candidate lags evaluated through autocorrelation. Under this assumption, the computational complexity was shown to decrease from O⁡(N​log⁡N)O(N\log N) to O⁡(N)O(N). Results from a real SDR-based TEMPEST experiment showed that F-DLA preserves the FRR estimation accuracy of conventional DLA while reducing processing time. Although preliminary, these results support the theoretical analysis and indicate the approach’s potential for applications with more stringent computational constraints. Future work will extend the experimental evaluation to different scenarios and parameters and consider complexity optimization techniques based on sparse FFTs, e.g., [10].

Acknowledgments

This work was partially funded by the Advanced Multimodal Sensing (AIMS) project, supported by the Advanced Knowledge Center in Immersive Technologies (AKCIT), with funding from MCTI’s PPI IoT program under Agreement No. 057/2023 with EMBRAPII. The authors also thank the Goiás Research Foundation (FAPEG) for the financial support provided for this research (Project No. 64448878/2024).

References

  • [1] M. Ahmed Leghari, S. Mei Pralle, S. F. Peik, S. Luetje, and W. Henkel (2025) Waveform classification from TEMPEST attacks. IEEE Access 13 (), pp. 167405–167423. External Links: Document Cited by: §1, §2.1.
  • [2] S. Fernández, E. Martínez, J. Varela, P. Musé, and F. Larroca (2024) Deep-tempest: using deep learning to eavesdrop on hdmi from its unintended electromagnetic emanations. In Proc. 13th Latin Amer. Symp. Dependable Secure Comput. (LADC), External Links: Document Cited by: §1.
  • [3] F. Larroca, P. Bertrand, F. Carrau, and V. Severi (2022) gr-tempest: an open-source GNU Radio implementation of TEMPEST. In 2022 Asian Hardware Oriented Security and Trust Symposium (AsianHOST), Vol. , pp. 1–6. External Links: Document Cited by: §1, §2.2, §4.
  • [4] E. Lee, D. Choi, T. Nam, I. Kim, Y. Yu, and J. Yook (2025) Complete coherent demodulation and recovery of spread spectrum clocking-based electromagnetic information leakage: theory and demonstration. IEEE Trans. Inf. Forensics Security 20, pp. 3804–3818. Cited by: §2.1.
  • [5] H. S. Lee, D. H. Choi, K. Sim, and J. Yook (2019) Information recovery using electromagnetic emanations from display devices under realistic environment. IEEE Transactions on Electromagnetic Compatibility 61 (4), pp. 1098–1106. External Links: Document Cited by: §2.1.
  • [6] M. Marinov (2014) TempestSDR: remote video eavesdropping using a software-defined radio platform. Note: https://github.com/martinmarinov/TempestSDRAcessado em: 28 maio 2026 Cited by: §1, §2.2.
  • [7] O. Meynard, D. Réal, S. Guilley, F. Flament, J. Danger, and F. Valette (2011) Characterization of the electromagnetic side channel in frequency domain. In Inf. Security Cryptol. (Inscrypt), LNCS 6584, pp. 471–486. Cited by: §1.
  • [8] T. Nam, D. Choi, E. Lee, and J. Yook (2025) Integrating Advanced Signal Analysis and Deep Learning in TEMPEST Techniques. In Proc. IEEE Int. Symp. Electromagn. Compat., Signal & Power Integr. (EMC+SIPI), Vol. , pp. 66–71. External Links: Document Cited by: §1.
  • [9] S. Queiroz, J. P. Vilela, and E. Monteiro (2022) Is FFT Fast Enough for Beyond 5G Communications? A Throughput-Complexity Analysis for OFDM Signals. IEEE Access 10 (), pp. 104436–104448. External Links: Document Cited by: §2.2.
  • [10] S. Queiroz, J. P. Vilela, and E. Monteiro (2025) Fast computation of the discrete fourier transform square index coefficients. IEEE Signal Process. Mag. 42 (2), pp. 88–92. External Links: Document Cited by: §5.
  • [11] L. Teodoro, K. L. Vieira, and S. Queiroz (2026) Pre-Characterization of Electromagnetic Side-Channel Leakage Using Publicly Available Information: A Case Study on E-Voting Interfaces. Note: Proc. IEEE Int. Conf. Acoust., Speech Signal Process.(ICASSP), Show & Tell Demo Session.Disponível em: https://2026.ieeeicassp.org/industry_program/#DMOS_530 Cited by: §1.
  • [12] Tribunal Regional Eleitoral de Santa Catarina (2026) Modelos de urna eletrônica. Note: https://www.tre-sc.jus.br/eleicoes/urna-eletronica/modelos/Acesso em: 3 jun. 2026 Cited by: §3.
  • [13] Tribunal Superior Eleitoral (2019) Audiência Pública UE2020: Especificações Técnicas de Hardware (Anexo II). Note: Disponível em: https://www.tse.jus.br/servicos-judiciais/audiencias-publicas/arquivos/ue2020/tse-audiencia-publica-ue2020-especificacoes-tecnicas-hardwareAcesso em: 26 maio 2026 Cited by: §3.
  • [14] Tribunal Superior Eleitoral (2026) Simulador de Votação da Urna Eletrônica Brasileira. Note: Disponível em: https://www.tse.jus.br/hotsites/simulador-de-votacao/inicioVotacao.htmlAcesso em: 23 maio 2026 Cited by: §4.
  • [15] Video Electronics Standards Association (VESA) (2013) Industry Standards and Guidelines for Computer Display Monitor Timing (DMT), ver. 1.13, 2013. Note: Acesso em: 22 maio 2026. External Links: Link Cited by: §3, §4.