← Back to list

Agentic AI and Side-Channel Espionage

Autonomous agents could listen to isolated machines via acoustic, thermal, or electromagnetic leaks with precision no human operator can…

James Marinero, MSc, MBA. in The Dock on the Bay · 2026-07-31 05:31 · 143 claps · 6.8 min read paywalled
#agentic-ai #side-channel-attacks #air-gapped-systems #cyber-espionage #ai-security
Open on Medium ↗
Wiki topics: AGT · AI Agents

Espionage and AI

Agentic AI and Side-Channel Espionage

Autonomous agents could listen to isolated machines via acoustic, thermal, or electromagnetic leaks with precision no human operator can match — an emerging threat at the frontier of cyber spying

Illustrative image of the use of a laser interferometer

Illustrative image of the use of a laser interferometer

It seems like an age ago when I first wrote about side-channel espionage. In fact it was in 2010. The plot was in ‘Gate of Tears’ and the Chinese were bugging MI6 using a laser interferometer.

This technology traces back to mid-20th-century intelligence efforts, most notably with the Soviet development of systems such as Operation Buran, which used infrared beams to monitor foreign embassies in Moscow. While early iterations faced significant challenges regarding signal stability, environmental interference, and the need for line-of-sight, modern advancements have improved the efficacy of these tools.

Current systems are capable of operating over distances of several hundred metres. The quality of the audio captured is often dependent on the acoustic impedance of the target surface. Materials that are thin or possess low mass — such as paper, plastic, or standard glass — respond more readily to sound vibrations and thus yield clearer audio signals than denser, more rigid materials.

In the sixteen years since I used the device in my fictional plot, espionage has come along way. It’s now automated and part of warfare at the speed of light.

The evolution of side-channel espionage

Side-channel attacks represent a departure from traditional digital intrusion methods. While conventional cyber attacks target software vulnerabilities or misconfigured network ports, side-channel operations exploit the physical realities of hardware.

Computers, though perceived as abstract logic engines, are physical objects that interact with their environment. Every process performed by a processor generates unintended physical byproducts. These include minute variations in power consumption, subtle fluctuations in electromagnetic emissions, and faint acoustic signals from electronic components. Even keystrokes generate signals — and sounds.

By monitoring these phenomena, an observer can reconstruct internal system states, including the retrieval of cryptographic keys or the identification of sensitive data being processed.

Historically, the detection of these signals required specialised equipment and significant human expertise. An operator needed to position probes, collect data over extended periods, and perform complex statistical analysis to discern meaningful information from ambient noise.

This manual process limited the frequency and scope of such operations.

The integration of agentic artificial intelligence into this domain changes the nature of the threat. Unlike static scripts, agentic AI systems possess the capacity for autonomous planning, tool orchestration, and long-term goal pursuit.

These systems can coordinate the collection of side-channel data across vast, distributed environments, adjusting their methodologies in real time based on observed signals without continuous human intervention.

Agentic AI primer

In case you missed it, Agentic artificial intelligence refers to systems capable of autonomous decision-making and goal pursuit. Unlike static models, these agents plan, use tools, and adapt to environments to achieve complex tasks without constant human oversight.

They operate by ‘perceiving’ their surroundings, reasoning about optimal actions, and executing them to reach objectives.

Autonomous agents and physical signal analysis

The core capability of agentic AI in this context is its ability to process multi-modal data streams at a scale and speed unattainable by human actors.

An autonomous agent can manage multiple sensors simultaneously, correlating acoustic data from one location with electromagnetic readings from another.

This capacity allows for the triangulation of signals within complex environments. For instance, a system might utilise a microphone near a server room to capture the subtle acoustic signatures of capacitor whine or cooling fan speeds, which correlate with specific computational loads.

The AI can then map these sounds to the execution of specific tasks or even the presence of specific users within a secure facility.

They can even be used to analyse what side channels might be available at a given facility and adapt to defensive measures. If a facility increases its security protocols, such as installing signal-shielding or noise-generating devices, an agentic system can dynamically refine its sampling techniques to identify weaker, less obvious signals.

The autonomous nature of these models means they can persist in an environment, performing long-term observation and slowly building a profile of the target system’s operations. This persistent, self-directed reconnaissance converts sporadic, manual espionage into a continuous, automated intelligence stream.

The frontier of cyber spying

The application of this technology marks a critical development at the frontier of cyber espionage. By bypassing the need to interact directly with the software layer, attackers can circumvent many traditional security controls such as firewalls, intrusion detection systems, and access management policies.

Because the exfiltration occurs through physical emanations, the target system’s logs may appear entirely benign. The activity occurs outside the observable domain of traditional security operations, leaving the victim unaware that their secure, isolated hardware is broadcasting its internal state to a remote observer.

This capability poses a direct challenge to the notion of air-gapped security.

Systems that are physically disconnected from external networks to prevent data exfiltration were once considered immune to remote attacks. However, the sensitivity of modern AI models to low-signal-to-noise ratios allows for the potential interception of information from these systems through long-range observation of physical leaks.

The ability of an agent to autonomously manage this process means that high-value targets, previously beyond the reach of remote cyber actors, are now accessible.

Faraday cages

Faraday cages have been a fundamental method for electromagnetic shielding, yet their effectiveness against modern, agentic AI-driven side-channel threats is flaky. While they are highly effective at blocking radio frequency (RF) and electromagnetic interference (EMI) when properly constructed, they are not a total preventative for all forms of data leakage.

Faraday cage. Wikipedia

Faraday cage. Wikipedia

Their limitations in this context include:

Frequency and type of signal: While solid cages attenuate a broad range of frequencies, they struggle to block very low-frequency magnetic fields, such as those generated by power lines, which can sometimes carry data-sensitive information.

Physical integrity: Any opening in the cage — such as for ventilation, power cables, or data ports — must be meticulously engineered to avoid becoming an antenna that allows signals to escape.

Complexity of leaks: Agentic AI-assisted espionage can exploit signals that are not limited to electromagnetic emissions, such as acoustic vibrations from electronic components or thermal variations, which are not mitigated by traditional Faraday shielding.

Internal complexity: In some settings, installing shielding can inadvertently create standing wave patterns and electromagnetic complexity within the space, as signals reflect off the conductive walls, potentially making internal data patterns easier to correlate or harder to manage.

The “insider” challenge: If an agentic system is already present within a secure environment — such as through a compromised software process or a tainted supply chain component — a Faraday cage does not prevent that agent from collecting and exfiltrating data via alternative, non-shielded channels.

And as you can see from the picture, light is not stopped. But most sensitive locations protect against lip readers.

Security concerns and the Mythos restriction

The rapid advance of these espionage capabilities has forced a reassessment of how the most powerful artificial intelligence models are distributed and managed.

A prominent example of this tension is the recent treatment of Anthropic’s Mythos model. The US government, concerned about the potential for such highly capable AI to identify and exploit novel cybersecurity vulnerabilities at an unprecedented rate, ordered a temporary suspension of access to the model.

Security consultants highlighted the risk that if such a model were deployed by malicious actors, it could be tasked with automating complex attack chains, including those involving sophisticated side-channel data collection.

[embed]

This decision reflects a broader, ongoing debate within national security circles about the proliferation of frontier AI. While there is a recognition of the need to maintain a technological advantage, there is equal concern that the mechanisms required for these models to be truly effective — their autonomy and their ability to plan complex operations — are the exact features that make them dangerous if diverted toward offensive espionage.

The restriction on Mythos highlights the perceived necessity of maintaining a degree of oversight over models that demonstrate a capacity to operate autonomously within the digital and, potentially, the physical threat landscape.

Managing the emergent threat

Addressing the threat posed by agentic AI-assisted side-channel espionage requires a transition from reactive, rule-based security to a model focused on physical and architectural resilience.

Because Agentic AI attacks leave no digital footprint in the traditional sense, defenders must focus on reducing the observability of hardware signals.

This includes the implementation of robust physical shielding, such as Faraday cages (with their recognised limitations) or sound-dampening enclosures, to limit electromagnetic and acoustic leakage. Additionally, hardware design must incorporate active noise injection or signal-masking techniques that prevent the correlation of physical emissions with internal processing tasks.

Equally important is the development of governance frameworks that address the autonomous nature of modern threats. As agentic AI becomes a standard component of both defensive and offensive operations, the ability to monitor the intent and actions of these systems becomes paramount.

But we all know that most governments will not observe these governance rules.

Meanwhile in China (or wherever you are) Deep Seek is free to all*.

DeepSeek, a Chinese AI company, offers powerful, cost-efficient models like the latest V4 series. These models excel in reasoning, coding, and agentic workflows. They are notable for high efficiency, often achieving competitive performance with significantly lower computational resources and costs.

You can download and run early versions yourself if you have the hardware.

I wonder how that will work out in out Brave New World?

*terms and conditions apply, as you would expect.

By the way, if you want to read ‘Gate of Tears’, you can do so right here, on Medium.

[embed]Gate of Tears: Chapter Index Chapter index to this full length techno thriller where gold, greed and intrigue collide in the Red Seamedium.com

[embed]The AI Clash: Cyber Warfare Between Ethical Guardians and Unrestrained Machines Unpacking the Pentagon’s Push Against Anthropic and the Rise of Machine-Speed Conflicts in National Securitymedium.com


메타데이터
post_id
2a881cd0cbca
slug
agentic-ai-and-side-channel-espionage-2a881cd0cbca
url
https://medium.com/the-dock-on-the-bay/agentic-ai-and-side-channel-espionage-2a881cd0cbca
canonical_url
https://medium.com/the-dock-on-the-bay/agentic-ai-and-side-channel-espionage-2a881cd0cbca
author_url
https://medium.com/@james-marinero
status
ok
fetched_at
2026-08-19 01:22:14