Computer Security, Privacy, and DNA Sequencing: Compromising Computers with Synthesized DNA, Privacy Leaks, and More
Peter Ney, Karl Koscher, Lee Organick, Luis Ceze, Tadayoshi Kohno
摘要
The rapid improvement in DNA sequencing has sparked a big data revolution in genomic sciences, which has in turn led to a proliferation of bioinformatics tools. To date, these tools have encountered little adversarial pressure. This paper evaluates the robustness of such tools if (or when) adversarial attacks manifest. We demonstrate, for the first time, the synthesis of DNA which -when sequenced and processed -gives an attacker arbitrary remote code execution. To study the feasibility of creating and synthesizing a DNA-based exploit, we performed our attack on a modified downstream sequencing utility with a deliberately introduced vulnerability. After sequencing, we observed information leakage in our data due to sample bleeding. While this phenomena is known to the sequencing community, we provide the first discussion of how this leakage channel could be used adversarially to inject data or reveal sensitive information. We then evaluate the general security hygiene of common DNA processing programs, and unfortunately, find concrete evidence of poor security practices used throughout the field. Informed by our experiments and results, we develop a broad framework and guidelines to safeguard security and privacy in DNA synthesis, sequencing, and processing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Oligo-Snoop: A Non-Invasive Side Channel Attack Against DNA Synthesis MachinesSina Faezi, Sujit Rokka Chhetri, Arnav Vaibhav Malawade, John Charles Chaput 等NDSS 2019 · 被引用 28 次
- "There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical DevicesRonald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel VotipkaUSENIX Security 2024 · 被引用 15 次
相关 Paper
- GeneBreaker: Jailbreak Attacks against DNA Language Models with Pathogenicity GuidanceZaixi Zhang, Zhenghong Zhou, Ruofan Jin, Le Cong 等ICLR 2026 · 被引用 17 次
- Analysis of the Security Design, Engineering, and Implementation of the SecureDNA SystemAlan T. Sherman, Jeremy J. Romanik Romano, Edward Zieglar, Enis Golaszewski 等NDSS 2026 · 被引用 1 次
- Genotype Extraction and False Relative Attacks: Security Risks to Third-Party Genetic Genealogy Services Beyond Identity InferencePeter Ney, Luis Ceze, Tadayoshi KohnoNDSS 2020
- On Utility and Privacy in Synthetic Genomic DataBristena Oprisanu, Georgi Ganev, Emiliano De CristofaroNDSS 2022
- Securing the Language of Life: Inheritable Watermarks from DNA Language Models to ProteinsZaixi Zhang, Ruofan Jin, Le Cong, Mengdi WangNeurIPS 2025 · 被引用 6 次
