IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial Vehicles
Sudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon, Junghwan Rhee, Tyler Summers, Hongjun Choi, Heejo Lee, Chung Hwan Kim
Abstract
Robotic aerial vehicles (RAVs), particularly drones, are crucial in civil and military sectors. However, researchers have found that adversaries can inject noise into sensor measurements and cause physical impacts on the RAVs like crashes. Although identifying such signal injection attacks is essential to evaluate and improve the robustness of an RAV, it is challenging to discover them since their impact depends on the RAV's physical states and the search space of noise signals and physical states is vast due to its dynamic nature. This paper proposes IMUFUZZER, a feedback-driven fuzzing framework, to automatically test an RAVs system and discover signal injection attacks. IMUFUZZER generates realistic noise signals for various inertial measurement unit (IMU) sensors, and monitors their impact on RAV control to detect mission failures, leveraging a high-fidelity RAV simulator. To find the physical states that attacks depend on, IMUFUZZER generates various mission paths that the RAV will fly through. We develop a novel feedback mechanism to quantify the resilience of the RAV against attacks and efficiently guide the fuzzing process to find signal injection attacks. Using IMUFUZZER, we have discovered 23 successful signal injection attacks on popular RAV control software (ArduPilot). We evaluate the correctness and effectiveness of our feedback-based sensor fuzzing and demonstrate the feasibility of the discovered attacks through physical experiments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0b8edfc7-64a4-46d8-b0de-95c93e80e139Builds on11
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei et al.CCS 2018 · 201 citations
- Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial SensorsYazhou Tu, Zhiqiang Lin, Insup Lee, Xiali HeiUSENIX Security 2018 · 132 citations
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei et al.USENIX Security 2019 · 92 citations
- SoK: Security and Privacy in the Age of Commercial DronesBen Nassi, Ron Bitton, Ryusuke Masuoka, Asaf Shabtai et al.S&P 2021 · 89 citations
- SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityChen Yan, Hocheol Shin, Connor Bolton, Wenyuan Xu et al.S&P 2020 · 86 citations
Related papers
- PGFUZZ: Policy-Guided Fuzzing for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik et al.NDSS 2021
- PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal FuzzingZhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren et al.NDSS 2026
- RSFuzz: A Robustness-Guided Swarm Fuzzing Framework Based on Behavioral ConstraintsRuoyu Zhou, Zhiwei Zhang, Haocheng Han, Xiaodong Zhang et al.ASE 2025
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark et al.CCS 2025
- ADGFUZZ: Assignment Dependency-Guided Fuzzing for Robotic VehiclesYuncheng Wang, Yaowen Zheng, Puzhuo Liu, Dongliang Fang et al.NDSS 2026 · 1 citation
