USENIX Security2017Top-tier venue
Computer Security, Privacy, and DNA Sequencing: Compromising Computers with Synthesized DNA, Privacy Leaks, and More
Peter Ney, Karl Koscher, Lee Organick, Luis Ceze, Tadayoshi Kohno
Abstract
The rapid improvement in DNA sequencing has sparked a big data revolution in genomic sciences, which has in turn led to a proliferation of bioinformatics tools. To date, these tools have encountered little adversarial pressure. This paper evaluates the robustness of such tools if (or when) adversarial attacks manifest. We demonstrate, for the first time, the synthesis of DNA which -when sequenced and processed -gives an attacker arbitrary remote code execution. To study the feasibility of creating and synthesizing a DNA-based exploit, we performed our attack on a modified downstream sequencing utility with a deliberately introduced vulnerability. After sequencing, we observed information leakage in our data due to sample bleeding. While this phenomena is known to the sequencing community, we provide the first discussion of how this leakage channel could be used adversarially to inject data or reveal sensitive information. We then evaluate the general security hygiene of common DNA processing programs, and unfortunately, find concrete evidence of poor security practices used throughout the field. Informed by our experiments and results, we develop a broad framework and guidelines to safeguard security and privacy in DNA synthesis, sequencing, and processing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1fd0e22a-5963-477a-8a57-7b3a003d07f2Cited by top-tier papers2
- Oligo-Snoop: A Non-Invasive Side Channel Attack Against DNA Synthesis MachinesSina Faezi, Sujit Rokka Chhetri, Arnav Vaibhav Malawade, John Charles Chaput et al.NDSS 2019 · 28 citations
- "There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical DevicesRonald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel VotipkaUSENIX Security 2024 · 15 citations
Related papers
- GeneBreaker: Jailbreak Attacks against DNA Language Models with Pathogenicity GuidanceZaixi Zhang, Zhenghong Zhou, Ruofan Jin, Le Cong et al.ICLR 2026 · 17 citations
- Analysis of the Security Design, Engineering, and Implementation of the SecureDNA SystemAlan T. Sherman, Jeremy J. Romanik Romano, Edward Zieglar, Enis Golaszewski et al.NDSS 2026 · 1 citation
- Genotype Extraction and False Relative Attacks: Security Risks to Third-Party Genetic Genealogy Services Beyond Identity InferencePeter Ney, Luis Ceze, Tadayoshi KohnoNDSS 2020
- On Utility and Privacy in Synthetic Genomic DataBristena Oprisanu, Georgi Ganev, Emiliano De CristofaroNDSS 2022
- Securing the Language of Life: Inheritable Watermarks from DNA Language Models to ProteinsZaixi Zhang, Ruofan Jin, Le Cong, Mengdi WangNeurIPS 2025 · 6 citations
