USENIX Security2018Top-tier venue
Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial Sensors
Yazhou Tu, Zhiqiang Lin, Insup Lee, Xiali Hei
Abstract
Inertial sensors provide crucial feedback for control systems to determine motional status and make timely, automated decisions. Prior efforts tried to control the output of inertial sensors with acoustic signals. However, their approaches did not consider sample rate drifts in analog-to-digital converters as well as many other realistic factors. As a result, few attacks demonstrated effective control over inertial sensors embedded in real systems. This work studies the out-of-band signal injection methods to deliver adversarial control to embedded MEMS inertial sensors and evaluates consequent vulnerabilities exposed in control systems relying on them. Acoustic signals injected into inertial sensors are out-of-band analog signals. Consequently, slight sample rate drifts could be amplified and cause deviations in the frequency of digital signals. Such deviations result in fluctuating sensor output; nevertheless, we characterize two methods to control the output: digital amplitude adjusting and phase pacing. Based on our analysis, we devise non-invasive attacks to manipulate the sensor output as well as the derived inertial information to deceive control systems. We test 25 devices equipped with MEMS inertial sensors and find that 17 of them could be implicitly controlled by our attacks. Furthermore, we investigate the generalizability of our methods and show the possibility to manipulate the digital output through signals with relatively low frequencies in the sensing channel.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers33
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World AttackTakami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia et al.USENIX Security 2021 · 152 citations
- Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionXiaoyu Ji, Yushi Cheng, Yuepeng Zhang, Kai Wang et al.S&P 2021 · 99 citations
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez et al.CCS 2019 · 87 citations
- SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityChen Yan, Hocheol Shin, Connor Bolton, Wenyuan Xu et al.S&P 2020 · 86 citations
Builds on6
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- 6thSense: A Context-aware Sensor-based Attack Detector for Smart DevicesAmit Kumar Sikder, Hidayet Aksu, A. Selcuk UluagacUSENIX Security 2017 · 129 citations
- Speechless: Analyzing the Threat to Speech Privacy from Smartphone Motion SensorsS. Abhishek Anand, Nitesh SaxenaS&P 2018 · 110 citations
- Securing Augmented Reality OutputKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2017 · 103 citations
Related papers
- Un-Rocking Drones: Foundations of Acoustic Injection Attacks and Recovery ThereofJinseob Jeong, Dongkwan Kim, Joon-Ha Jang, Juhwan Noh et al.NDSS 2023
- Paralyzing Drones via EMI Signal Injection on Sensory Communication ChannelsJoon-Ha Jang, ManGi Cho, Jaehoon Kim, Dongkwan Kim et al.NDSS 2023
- Physical-Layer Attacks Against Pulse Width Modulation-Controlled ActuatorsGökçen Yilmaz Dayanikli, Sourav Sinha, Devaprakash Muniraj, Ryan M. Gerdes et al.USENIX Security 2022
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
- From One Form of Energy to Another: Laser-Induced Injection Attacks on Acoustic SensingLupeng Zhang, Minhao Cui, Wenwei Li, Xuefu Dong et al.UbiComp 2026 · 1 citation
