USENIX Security2019Top-tier venue
RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided Testing
Taegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei, Zhan Tu, Gregory Walkup, Xiangyu Zhang, Xinyan Deng, Dongyan Xu
Abstract
Robotic vehicles (RVs) are being adopted in a variety of application domains. Despite their increasing deployment, many security issues with RVs have emerged, limiting their wider deployment. In this paper, we address a new type of vulnerability in RV control programs, called input validation bugs, which involve missing or incorrect validation checks on control parameter inputs. Such bugs can be exploited to cause physical disruptions to RVs which may result in mission failures and vehicle damages or crashes. Furthermore, attacks exploiting such bugs have a very small footprint: just one innocent-looking ground control command, requiring no code injection, control flow hijacking or sensor spoofing. To prevent such attacks, we propose RVFUZZER, a vetting system for finding input validation bugs in RV control programs through control-guided input mutation. The key insight behind RVFUZZER is that the RV control model, which is the generic theoretical model for a broad range of RVs, provides helpful semantic guidance to improve bug-discovery accuracy and efficiency. Specifically, RVFUZZER involves a control instability detector that detects control program misbehavior, by observing (simulated) physical operations of the RV based on the control model. In addition, RVFUZZER steers the input generation for finding input validation bugs more efficiently, by leveraging results from the control instability detector as feedback. In our evaluation of RVFUZZER on two popular RV control programs, a total of 89 input validation bugs are found, with 87 of them being zero-day bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0ca88eb2-5999-46bf-87ce-877f89a9a527Cited by top-tier papers21
- DriveFuzz: Discovering Autonomous Driving Bugs through Driving Quality-Guided FuzzingSeulbae Kim, Major Liu, Junghwan John Rhee, Yuseok Jeon et al.CCS 2022 · 65 citations
- ICSFuzz: Manipulating I/Os and Repurposing Binary Code to Enable Instrumented Fuzzing in ICS Control ApplicationsDimitrios Tychalas, Hadjer Benkraouda, Michail ManiatakosUSENIX Security 2021 · 42 citations
- M2MON: Building an MMIO-based Security Reference Monitor for Unmanned VehiclesArslan Khan, Hyungsub Kim, Byoungyoung Lee, Dongyan Xu et al.USENIX Security 2021 · 35 citations
- RoboFuzz: fuzzing robotic systems over robot operating system (ROS) for finding correctness bugsSeulbae Kim, Taesoo KimFSE 2022 · 32 citations
- Control Parameters Considered Harmful: Detecting Range Specification Bugs in Drone Configuration Modules via Learning-Guided SearchRuidong Han, Chao Yang, Siqi Ma, Jianfeng Ma et al.ICSE 2022 · 27 citations
Builds on9
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 326 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
Related papers
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark et al.CCS 2025
- ADGFUZZ: Assignment Dependency-Guided Fuzzing for Robotic VehiclesYuncheng Wang, Yaowen Zheng, Puzhuo Liu, Dongliang Fang et al.NDSS 2026 · 1 citation
- PGFUZZ: Policy-Guided Fuzzing for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik et al.NDSS 2021
- PatchVerif: Discovering Faulty Patches in Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi et al.USENIX Security 2023
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
