PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal Fuzzing
Zhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren, Chen Yan, Xiaoyu Ji, Wenyuan Xu
Abstract
Sensor vulnerabilities can be exploited by physical signal attacks to cause erroneous sensor measurements, endangering systems that rely on sensors to make critical decisions. While hundreds of existing studies have discovered numerous sensor vulnerabilities, they are all driven by manual expert analysis and require a time-consuming process of trial and error. The absence of automated approaches to assist in the detection of sensor vulnerabilities has posed a major roadblock to bridging the gap between sensor security research and industrial applications. In this paper, we propose PhyFuzz, a new emphphysical signal fuzzing paradigm that relies on physical testing signals to detect existing and potentially new types of sensor vulnerabilities without human in the loop. To cope with the unprecedented challenges of fuzzing with physical signals, such as the infinite searching space of signal parameters and the black-box design of diverse sensor hardware, we design a unique fuzzing algorithm that enables efficient testing signal construction and effective feature discretization for sensor vulnerability identification and assessment. We implement PhyFuzz as a prototype that can support fuzz testing with acoustic, laser, and electromagnetic signals. Our experiment shows that it can identify 46 vulnerabilities on 13 sensors of 9 different types, including 6 undisclosed cases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6ba0e75-b521-4f44-8259-beba6a19e99aBuilds on19
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionXiaoyu Ji, Yushi Cheng, Yuepeng Zhang, Kai Wang et al.S&P 2021 · 99 citations
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei et al.USENIX Security 2019 · 92 citations
Related papers
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang et al.S&P 2026 · 3 citations
- HIFuzz: Human Interaction Fuzzing for Small Unmanned Aerial VehiclesTheodore Chambers, Michael Vierhauser, Ankit Agrawal, Michael Murphy et al.CHI 2024 · 11 citations
- Active fuzzing for testing and securing cyber-physical systemsYuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun et al.ISSTA 2020 · 25 citations
- PhantomMotion: Laser-Based Motion Injection Attacks on Wireless Security Surveillance SystemsYan He, Guanchong Huang, Song FangNDSS 2026
