Project DetailsThis project investigates whether a malicious laptop battery can harvest sensitive information about host activity and exfiltrate it to an attacker without requiring any hardware modifications of the battery. Modern laptops and their batteries exchange control data via a serial I²C interface. To analyze this interface, we developed a testbed to monitor (and, in later stages, modify) the messages exchanged between the host and battery. We evaluated whether passive observation alone, avoiding anomalous battery-originated traffic, could reveal useful information about system activity, and found that the observed message rate and content are insufficient to reliably infer host behavior, even when applying side-channel analysis techniques. Finally, we outline further research directions exploring laptop attacks executed through software-only modifications to battery firmware.
