Hiding My Real Self! Protecting Intellectual Property in Additive Manufacturing Systems Against Optical Side-Channel Attacks
Sizhuang Liang, Saman A. Zonouz, Raheem Beyah
Abstract
—We propose an optical side-channel attack to recover intellectual property in Additive Manufacturing (AM) systems. Specifically, we use a deep neural network to estimate the coordinates of the printhead as a function of time by analyzing the video of the printer frame by frame. We found that the deep neural network can successfully recover the path for an arbitrary printing process. By using data augmentation, the neural network can tolerate a certain level of variation in the position and angle of the camera as well as the lighting conditions. The neural network can intelligently perform interpolation and accurately recover the coordinates of an image that is not seen in the training dataset. To defend against the optical side-channel attack, we propose to use the optical noise injection method. Specifically, we use an optical projector to artificially inject carefully crafted optical noise onto the printing area in an attempt to confuse the attacker and make it harder to recover the printing path. We found that existing noise generation algorithms, such as replaying, random blobs, white noise, and full power, can effortlessly defeat a naive attacker who is not aware of the existence of the injected noise. However, an advanced attacker who knows about the injected noise and incorporates images with injected noise in the training dataset can defeat all of the existing noise generation algorithms. To defend against such an advanced attacker, we propose three novel noise generation algorithms: channel uniformization, state uniformization, and state randomization. Our experiment results show that noise generated via state randomization can successfully defend against the advanced attacker.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 63fcc966-569e-442c-9b24-b1ee2ed7ad5dCited by top-tier papers3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- One Video to Steal Them All: 3D-Printing IP Theft through Optical Side-ChannelsTwisha Chattopadhyay, Fabricio Ceschin, Marco E. Garza, Dymytriy Zyunkin et al.CCS 2025 · 1 citation
- XCheck: Verifying Integrity of 3D Printed Patient-Specific Devices via Computing TomographyZhiyuan Yu, Yuanhaur Chang, Shixuan Zhai, Nicholas Deily et al.USENIX Security 2023
Builds on4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- My Smartphone Knows What You Print: Exploring Smartphone-based Side-channel Attacks Against 3D PrintersChen Song, Feng Lin, Zhongjie Ba, Kui Ren et al.CCS 2016 · 122 citations
- Leave Your Phone at the Door: Side Channels that Reveal Factory Floor SecretsAvesta Hojjati, Anku Adhikari, Katarina Struckmann, Edward Chou et al.CCS 2016 · 78 citations
- See No Evil, Hear No Evil, Feel No Evil, Print No Evil? Malicious Fill Patterns Detection in Additive ManufacturingChristian Bayens, Tuan Le, Luis Garcia, Raheem A. Beyah et al.USENIX Security 2017 · 53 citations
Related papers
- MEA-Defender: A Robust Watermark against Model Extraction AttackPeizhuo Lv, Hualong Ma, Kai Chen, Jiachen Zhou et al.S&P 2024 · 22 citations
- Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?Run Wang, Haoxuan Li, Lingzhou Mu, Jixing Ren et al.ACM MM 2022 · 9 citations
- DFD: Adversarial Learning-based Approach to Defend Against Website FingerprintingAhmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang et al.INFOCOM 2020 · 51 citations
- Morié Attack (MA): A New Potential Risk of Screen PhotosDantong Niu, Ruohao Guo, Yisen WangNeurIPS 2021 · 14 citations
- Safe and Robust Watermark Injection with a Single OoD ImageShuyang Yu, Junyuan Hong, Haobo Zhang, Haotao Wang et al.ICLR 2024 · 4 citations
