---
id: "20260908-0228-how-does-bit2watts-own"
title: "Capture: How does Bit2Watt's own reverse 'Watt2Bit' path allegedly exfiltrate data covertly via EMI side channels — and is it demonstrated or just proposed?"
type: "capture"
status: "promoted"
promoted_to: []
not_promoted: ["Claim 1 (the FSK-encoding/band-energy-ratio exfiltration mechanism, §4.4 + §5.3.5) — NOT a note. This is a specific technical-mechanism claim resting directly on Bit2Watt's own text (arXiv:2607.05993), which already anchors three claim-notes ([[claim-bit2watt-gpu-scheduling-destabilizes-power-grid]], [[claim-bit2watt-citations-omit-kocher-1999-zhao-suh-2018]], [[claim-power-side-channel-attacks-scaled-chip-to-grid-1999-2026]]) — the single-source concentration cap (sources.md, Cali 2026-07-29) is already at its ceiling of three with no independent corroboration. Held in full at [[question-corroborate-bit2watt-single-source-cap]].","Claim 2 (the empirical 99%-accuracy, zero-error, 50-bit EMI decode demonstration, §5.3.5) — NOT a note, same reason: a fourth Bit2Watt-sourced claim-note, blocked by the cap. Held in full at [[question-corroborate-bit2watt-single-source-cap]].","Claim 3 (the paper's own inconsistent hedging of the exfiltration finding across abstract/§1.1/§5.3.5/Conclusion) — NOT a note, same reason: also a Bit2Watt-sourced finding, also blocked by the cap. Held in full at [[question-corroborate-bit2watt-single-source-cap]].","Further lead (Bit2Watt's bibliography omits Guri/TEMPEST/air-gap citations, a possible second citation-omission pattern alongside [[claim-bit2watt-citations-omit-kocher-1999-zhao-suh-2018]]) — NOT a note. Doubly blocked: it would be a fourth+ Bit2Watt-sourced claim-note under the cap, and the capture itself flagged it as unverified to the rigor of the Kocher/Zhao-Suh finding (no exact-quote, page-by-page bibliography pass), 'worth a dedicated verification capture rather than asserting it here as a settled claim.' Held as a lead at [[question-corroborate-bit2watt-single-source-cap]].","Further lead (Watt2Bit's DoS sub-mechanism is analytically calculated, not independently hardware-tested like the exfiltration claim) — left as a future-capture lead, not acted on this session; also would be Bit2Watt-sourced and cap-blocked if written up.","Further lead (§5.3.4's EMI-based *detection* of the Bit2Watt grid-attack, a different EMI use than the Watt2Bit exfiltration channel) — left as a future-capture lead, not acted on this session; minor and not load-bearing enough on its own to warrant a note even absent the cap.","Entity candidates: Zhouhao Ji, Kaikai Pan, Wenyuan Xu (Bit2Watt authors) — NOT promoted to hubs; this repeats the 2026-07-25 finding (00-meta/seek-flags.md) that no session-verified biography beyond 'Zhejiang University co-author' exists yet.","Entity candidate: Mordechai Guri — NOT promoted to a hub this session, despite being real and clearly relevant (leads the academic air-gap EMI-exfiltration subfield Bit2Watt's own claim most resembles). This capture only noted his *absence* from Bit2Watt's bibliography; it never read any of his own work directly, so a hub page would have no primary-sourced content beyond a citation gap. Flagged to 00-meta/seek-flags.md for a future capture that reads his AirHopper/GSMem/MAGNETO/ODINI work directly.","Entity candidate: FSK (frequency-shift keying) — NOT promoted. First mention in the vault (checked: no prior claim-note or entity uses it); a generic, settled telecom concept that isn't yet load-bearing or recurring here. Revisit if it recurs.","Entity candidate: USRP B210 — NOT promoted. A one-off commodity-hardware mention, not a recurring or load-bearing vault concept.","Entity candidate: Watt2Bit — PROMOTED, but as a status: watching stub only ([[entity-watt2bit]]), not a hub — this is the vault's second substantive encounter with the term (named 2026-07-09, read in full 2026-09-08) but it still has zero claim-notes to anchor a hub's References list, since the cap blocked all three this session would have produced."]
origin: "batch"
writer_model: "claude-sonnet-5"
date_created: "2026-09-08T00:00:00.000Z"
provenance: "Batch run 2026-09-08. Answers question-watt2bit-emi-exfiltration-mechanism, an open lead saved from the 2026-07-09 Bit2Watt capture that had only read the paper's abstract. This session fetched the full Bit2Watt PDF (arXiv:2607.05993) via extract_pdf (TLS verified) and read it in full (28 pages), locating and reading the paper's own Watt2Bit sections (§3, §4.4, §5.3.5, Conclusion) in their entirety. All quotes below were checked against the extracted text with quote_check before being recorded."
derived_from: []
verifies: "question-watt2bit-emi-exfiltration-mechanism"
tags: ["hardware-security","side-channel","emi","covert-channel","bit2watt","watt2bit","exfiltration","cyber-physical-systems"]
source_url: "https://arxiv.org/pdf/2607.05993"
source_sha: "6834009eb974436daca05c718affa424f9053744ef9d79bf18f90c6103895ef4"
source_title: "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures"
source_author: "Zhouhao Ji, Kaikai Pan, Wenyuan Xu"
source_date: "2026-07-07T00:00:00.000Z"
source_venue: "arXiv preprint (accepted, IACR Transactions on Cryptographic Hardware and Embedded Systems / CHES 2026)"
source_tier: 1
seek_code_commit: "a619c8a"
---


> [!info] Core question resolved
> **Both.** Watt2Bit's EMI-exfiltration path is proposed as a general mechanism in the paper's threat framing ("a plausible Watt2Bit feedback path... covert information exfiltration via EMI side channels") **and** it has an actual lab-scale proof-of-concept demonstration (§5.3.5): binary data FSK-encoded onto the GPU power-modulation frequency, captured as EMI by a near-field antenna-coupled software-defined radio, and decoded with over 99% accuracy on a 50-bit test sequence with zero bit errors. The demonstration is real, but narrow — near-field only, one 50-bit test run, no distance/range or real-deployment testing reported — and the paper's own Conclusion, when it restates what Watt2Bit is, mentions only the denial-of-service side of the risk and drops the exfiltration finding entirely. Read together, Bit2Watt's authors treat the mechanism as demonstrated-in-principle but stop short of claiming it as an operationally proven exfiltration channel.

## Claim: Watt2Bit's exfiltration mechanism encodes bits by modulating the GPU-power/EMI attack signal's frequency, and decodes them from a ratio between two frequency bands in the captured EMI trace

**Claim type**: specific technical-mechanism claim
**Sourcing floor**: Tier 1–2 required
**Source tier achieved**: Tier 1 (direct primary read of the paper's own text)
**verifies**: question-watt2bit-emi-exfiltration-mechanism

Bit2Watt's §4.4 ("Watt2Bit Risk") first states the mechanism in general form: "an adversary could encode bits by modulating either the attack frequency or the attack amplitude, thereby inducing distinguishable patterns in the measured power/EMI traces. A receiver observing these side-channel emissions could then demodulate the corresponding spectral or amplitude features to recover the transmitted symbols." §5.3.5 then gives the concrete implementation used in the experiment: "binary bits are frequency-shift keying (FSK)-encoded on the GPU load profile using 2 kHz ("1") and 200 Hz ("0") modulation frequencies, with a 10 ms bit duration." Decoding uses a relative-energy metric between two fixed frequency bands of the captured EMI trace — "the relative energy ratio M = Eupper/Elower (Elower: 600–800 kHz; Eupper: 1080–1180 kHz) remains discriminative" — thresholded over a sliding window to recover each bit.

| Field | Value |
|---|---|
| source_url | https://arxiv.org/pdf/2607.05993 |
| source_sha | 6834009eb974436daca05c718affa424f9053744ef9d79bf18f90c6103895ef4 |
| source_author | Zhouhao Ji, Kaikai Pan, Wenyuan Xu |
| source_date | 2026-07-07 |
| source_venue | arXiv preprint (accepted, IACR TCHES / CHES 2026) |
| source_tier | 1 |
| exact_quote | "an adversary could encode bits by modulating either the attack frequency or the attack amplitude, thereby inducing distinguishable patterns in the measured power/EMI traces. A receiver observing these side-channel emissions could then demodulate the corresponding spectral or amplitude features to recover the transmitted symbols." (§4.4, p.13) and "binary bits are frequency-shift keying (FSK)-encoded on the GPU load profile using 2 kHz ("1") and 200 Hz ("0") modulation frequencies, with a 10 ms bit duration." (§5.3.5, p.21) |
| page | 13, 21 (of 28) |

---

## Claim: Watt2Bit's EMI exfiltration channel is empirically demonstrated, not merely proposed — a controlled lab test recovered a 50-bit sequence with over 99% decode accuracy and zero bit errors, using a near-field antenna and a software-defined radio

**Claim type**: quantitative claim
**Sourcing floor**: Tier 1–2 required
**Source tier achieved**: Tier 1 (direct primary read of the paper's own reported experiment)
**verifies**: question-watt2bit-emi-exfiltration-mechanism

Section 5.3.5 ("Watt2Bit Risk") reports an actual experiment, not just an analytical projection: "EMI traces captured via a near-field antenna-coupled USRP B210 reveal that while the absolute spectral power lacks discernible regularity... the relative energy ratio M... remains discriminative. By applying a threshold to a 10 ms sliding window, our decoder achieves an accuracy exceeding 99%. Figure 15(c) demonstrates the successful recovery of a 50-bit test sequence, where every transmitted bit is correctly identified with zero bit errors." This distinguishes Watt2Bit's exfiltration path from the paper's grid-destabilization claim (already recorded in [[claim-bit2watt-gpu-scheduling-destabilizes-power-grid]]) and from its own DoS sub-claim: both DoS and exfiltration are framed as consequences of the same underlying power-modulation attack, but exfiltration is the one given a dedicated hardware decode experiment here. The demonstration's scope is narrow: the receiver is a near-field-coupled antenna (i.e., physically close to the power delivery hardware, not a far-field/over-the-air setup), and only one 50-bit test sequence is reported — no distance, range, or multi-trial statistics are given.

| Field | Value |
|---|---|
| source_url | https://arxiv.org/pdf/2607.05993 |
| source_sha | 6834009eb974436daca05c718affa424f9053744ef9d79bf18f90c6103895ef4 |
| source_author | Zhouhao Ji, Kaikai Pan, Wenyuan Xu |
| source_date | 2026-07-07 |
| source_venue | arXiv preprint (accepted, IACR TCHES / CHES 2026) |
| source_tier | 1 |
| exact_quote | "EMI traces captured via a near-field antenna-coupled USRP B210 reveal that while the absolute spectral power lacks discernible regularity... the relative energy ratio M... remains discriminative. By applying a threshold to a 10 ms sliding window, our decoder achieves an accuracy exceeding 99%. Figure 15(c) demonstrates the successful recovery of a 50-bit test sequence, where every transmitted bit is correctly identified with zero bit errors." |
| page | 21 (of 28) |

---

## Claim: Bit2Watt's own text hedges the exfiltration finding as merely "plausible" and only a "potential" covert channel, and its Conclusion section — when restating what Watt2Bit is — mentions only the denial-of-service consequence, dropping exfiltration entirely

**Claim type**: historical/textual claim about the source document's own framing (uncontested — the quotes are the evidence)
**Sourcing floor**: Tier 3–4 acceptable for this kind of claim, but achieved Tier 1 (direct primary read)
**verifies**: question-watt2bit-emi-exfiltration-mechanism

The paper's abstract frames the whole Watt2Bit risk cautiously: "we analyze a plausible Watt2Bit feedback path, including denial-of-service risks and covert information exfiltration via EMI side channels." Its own §5.3.5 conclusion sentence, written immediately after reporting the 99%-accuracy, zero-error decode result, still hedges rather than asserts operational feasibility: "It suggests that the power modulation could potentially serve as a feasible covert channel for clandestine information exfiltration." Most tellingly, the paper's final Conclusion (§6), which restates the paper's contributions in summary form, describes Watt2Bit only in DoS terms — "The attack requires no compromise of grid or computing components, operating entirely as a legitimate tenant, and can propagate disturbances back to data centers, causing forced workload interruptions, termed Watt2Bit" — and does not mention exfiltration, EMI, or covert channels anywhere in that closing paragraph, despite the dedicated exfiltration experiment three pages earlier. The paper's own Contributions section (§1.1) is the one place that uses stronger language — "further demonstrate that the same mechanism may also enable covert information exfiltration via EMI side channels" — so the paper's certainty language is inconsistent across its own sections: "demonstrate" in the contributions list, "plausible"/"could potentially" in the abstract and discussion, and silent in the conclusion.

| Field | Value |
|---|---|
| source_url | https://arxiv.org/pdf/2607.05993 |
| source_sha | 6834009eb974436daca05c718affa424f9053744ef9d79bf18f90c6103895ef4 |
| source_author | Zhouhao Ji, Kaikai Pan, Wenyuan Xu |
| source_date | 2026-07-07 |
| source_venue | arXiv preprint (accepted, IACR TCHES / CHES 2026) |
| source_tier | 1 |
| exact_quote | Abstract: "we analyze a plausible Watt2Bit feedback path, including denial-of-service risks and covert information exfiltration via EMI side channels." §5.3.5: "It suggests that the power modulation could potentially serve as a feasible covert channel for clandestine information exfiltration." §6 Conclusion: "The attack requires no compromise of grid or computing components, operating entirely as a legitimate tenant, and can propagate disturbances back to data centers, causing forced workload interruptions, termed Watt2Bit." §1.1: "further demonstrate that the same mechanism may also enable covert information exfiltration via EMI side channels." |
| page | 1, 3, 21, 22 (of 28) |

> [!note] Seek's commentary:
> The interesting finding here wasn't the mechanism — FSK-over-power-noise is a fairly standard covert-channel idea — it was catching the paper hedge its own result. A team that ran the experiment and got zero bit errors on 50 bits still wrote "could potentially serve as a feasible" in the same section, and then left exfiltration out of the conclusion altogether. That gap between what got demonstrated and how confidently the authors were willing to state it is worth more than the number itself.

## Further leads

- Bit2Watt's Watt2Bit DoS sub-mechanism (thermal stress from harmonics, IEC 60255 protection-relay trip curves) is analytically calculated from standard trip-time curves, not an independent hardware experiment like the exfiltration test — worth checking whether "DoS" is demonstrated at the same evidentiary standard as exfiltration is, in a future capture (source: Bit2Watt PDF §5.3.5, Fig. 15(b), arXiv:2607.05993).
- §5.3.4 ("Detectability and Stealth Analysis") separately evaluates "EMI side channel sensing from the power line and VRM" as a *defender's* detection method against the Bit2Watt grid-attack itself (not the exfiltration channel), reporting it as the strongest of four monitoring settings at 69.33% true-positive rate at 1% false-positive rate — a different EMI use (detection, not exfiltration) worth distinguishing in any future note that cites "EMI" from this paper (source: Bit2Watt PDF §5.3.4, Fig. 14(b), arXiv:2607.05993).
- A full-text search of Bit2Watt's own 28 pages and 39-entry bibliography turns up no mention of "Guri," "TEMPEST," or "air-gap" — the established academic subfield of EM/acoustic/thermal air-gap covert-channel exfiltration (associated with Mordechai Guri's AirHopper/GSMem/MAGNETO/ODINI line of work) appears to go entirely uncited, despite being the closest prior art to Watt2Bit's own EMI-exfiltration claim. This parallels the vault's existing finding that Bit2Watt's related-work section omits Kocher 1999 and Zhao & Suh 2018 (see [[claim-bit2watt-citations-omit-kocher-1999-zhao-suh-2018]]); this would be a second, independent instance of the same citation-omission pattern and is worth a dedicated verification capture rather than asserting it here as a settled claim (source: Bit2Watt PDF full text and references pp. 1-28, arXiv:2607.05993).

## Entity candidates

- Mordechai Guri — person — flagged FIRST per the blind-spot instruction: leads the academic subfield (AirHopper, GSMem, MAGNETO, ODINI, and related papers) most directly comparable to Watt2Bit's EMI-exfiltration claim; Bit2Watt's bibliography appears to cite none of this line of work (see Further leads above) — the foundational figure this claim should be measured against, not yet flagged in this branch of the vault.
- Zhouhao Ji — person — Bit2Watt first author, Zhejiang University.
- Kaikai Pan — person — Bit2Watt corresponding author, Zhejiang University.
- Wenyuan Xu — person — Bit2Watt co-author, Zhejiang University.
- Watt2Bit — concept — Bit2Watt's own named "reverse" risk (grid disturbance propagating back into the computing domain); this capture's subject, distinct enough from Bit2Watt to warrant its own concept note if promoted.
- FSK (frequency-shift keying) — concept — the standard digital-modulation technique Watt2Bit's exfiltration channel reuses to encode bits onto the power/EMI signal; general/settled enough that a definitional note could cite outside sources rather than Bit2Watt itself.
- USRP B210 — term — the software-defined radio hardware used as the EMI receiver in the exfiltration experiment; a commodity SDR, not bespoke equipment, which is itself relevant to how easy the demonstrated attack would be to replicate.
