SpecGuard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks
Pritam Dash, Ethan Chan, Karthik Pattabiraman
Abstract
Robotic Autonomous Vehicles (RAVs) rely on their sensors for perception, and follow strict mission specifications (e.g., altitude, speed, and geofence constraints) for safe and timely operations. Physical attacks can corrupt the RAVs' sensors, resulting in mission failures. Recovering RAVs from such attacks demands robust control techniques that maintain compliance with mission specifications even under attacks to ensure the RAV's safety and timely operations. We propose SpecGuard, a technique that complies with mission specifications and performs safe recovery of RAVs. There are two innovations in SpecGuard. First, it introduces an approach to incorporate mission specifications and learn a recovery control policy using Deep Reinforcement Learning (Deep-RL). We design a compliance-based reward structure that reflects the RAV's complex dynamics and enables SpecGuard to satisfy multiple mission specifications simultaneously. Second, SpecGuard incorporates state reconstruction, a technique that minimizes attack induced sensor perturbations. This reconstruction enables effective adversarial training, and optimizing the recovery control policy for robustness under attacks. We evaluate SpecGuard in both virtual and real RAVs, and find that it achieves 92% recovery success rate under attacks on different sensors, without any crashes or stalls. SpecGuard achieves 2X higher recovery success than prior work, and incurs about 15% performance overhead on real RAVs. CCS CONCEPTS • Security and privacy → Systems security; • Computer systems organization → Robotic control; Embedded and cyberphysical systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 691c64a0-14e3-4e4e-94a4-f3a5e25dc052Cited by top-tier papers2
- Automated Discovery of Semantic Attacks in Multi-Robot Navigation SystemsDoguhan Yeke, Kartik Anand Pant, Muslum Ozgur Ozmen, Hyungsub Kim et al.USENIX Security 2025
- Software Availability Protection in Cyber-Physical SystemsAo Li, Jinwen Wang, Ning ZhangUSENIX Security 2025
Builds on15
- Robust Deep Reinforcement Learning against Adversarial Perturbations on State ObservationsHuan Zhang, Hongge Chen, Chaowei Xiao, Bo Li et al.NeurIPS 2020 · 437 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- The Effects of Reward Misspecification: Mapping and Mitigating Misaligned ModelsAlexander Pan, Kush Bhatia, Jacob SteinhardtICLR 2022 · 293 citations
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei et al.CCS 2018 · 201 citations
- Adaptive Reward-Poisoning Attacks against Reinforcement LearningXuezhou Zhang, Yuzhe Ma, Adish Singla, Xiaojin ZhuICML 2020 · 154 citations
Related papers
- Learn-to-Respond: Sequence-Predictive Recovery from Sensor Attacks in Cyber-Physical SystemsMengyu Liu, Lin Zhang, Vir V. Phoha, Fanxin KongRTSS 2023 · 13 citations
- On the Robustness of Safe Reinforcement Learning under Observational PerturbationsZuxin Liu, Zijian Guo, Zhepeng Cen, Huan Zhang et al.ICLR 2023 · 9 citations
- Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear ApproximationsLin Zhang, Xin Chen, Fanxin Kong, Alvaro A. CárdenasRTSS 2020 · 59 citations
- Towards Robust and Safe Reinforcement Learning with Benign Off-policy DataZuxin Liu, Zijian Guo, Zhepeng Cen, Huan Zhang et al.ICML 2023 · 14 citations
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
