Hiding My Real Self! Protecting Intellectual Property in Additive Manufacturing Systems Against Optical Side-Channel Attacks
Sizhuang Liang, Saman A. Zonouz, Raheem Beyah
摘要
—We propose an optical side-channel attack to recover intellectual property in Additive Manufacturing (AM) systems. Specifically, we use a deep neural network to estimate the coordinates of the printhead as a function of time by analyzing the video of the printer frame by frame. We found that the deep neural network can successfully recover the path for an arbitrary printing process. By using data augmentation, the neural network can tolerate a certain level of variation in the position and angle of the camera as well as the lighting conditions. The neural network can intelligently perform interpolation and accurately recover the coordinates of an image that is not seen in the training dataset. To defend against the optical side-channel attack, we propose to use the optical noise injection method. Specifically, we use an optical projector to artificially inject carefully crafted optical noise onto the printing area in an attempt to confuse the attacker and make it harder to recover the printing path. We found that existing noise generation algorithms, such as replaying, random blobs, white noise, and full power, can effortlessly defeat a naive attacker who is not aware of the existence of the injected noise. However, an advanced attacker who knows about the injected noise and incorporates images with injected noise in the training dataset can defeat all of the existing noise generation algorithms. To defend against such an advanced attacker, we propose three novel noise generation algorithms: channel uniformization, state uniformization, and state randomization. Our experiment results show that noise generated via state randomization can successfully defend against the advanced attacker.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- One Video to Steal Them All: 3D-Printing IP Theft through Optical Side-ChannelsTwisha Chattopadhyay, Fabricio Ceschin, Marco E. Garza, Dymytriy Zyunkin 等CCS 2025 · 被引用 1 次
- XCheck: Verifying Integrity of 3D Printed Patient-Specific Devices via Computing TomographyZhiyuan Yu, Yuanhaur Chang, Shixuan Zhai, Nicholas Deily 等USENIX Security 2023
它引用的顶会 Paper4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- My Smartphone Knows What You Print: Exploring Smartphone-based Side-channel Attacks Against 3D PrintersChen Song, Feng Lin, Zhongjie Ba, Kui Ren 等CCS 2016 · 被引用 122 次
- Leave Your Phone at the Door: Side Channels that Reveal Factory Floor SecretsAvesta Hojjati, Anku Adhikari, Katarina Struckmann, Edward Chou 等CCS 2016 · 被引用 78 次
- See No Evil, Hear No Evil, Feel No Evil, Print No Evil? Malicious Fill Patterns Detection in Additive ManufacturingChristian Bayens, Tuan Le, Luis Garcia, Raheem A. Beyah 等USENIX Security 2017 · 被引用 53 次
相关 Paper
- MEA-Defender: A Robust Watermark against Model Extraction AttackPeizhuo Lv, Hualong Ma, Kai Chen, Jiachen Zhou 等S&P 2024 · 被引用 22 次
- Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?Run Wang, Haoxuan Li, Lingzhou Mu, Jixing Ren 等ACM MM 2022 · 被引用 9 次
- DFD: Adversarial Learning-based Approach to Defend Against Website FingerprintingAhmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang 等INFOCOM 2020 · 被引用 51 次
- Morié Attack (MA): A New Potential Risk of Screen PhotosDantong Niu, Ruohao Guo, Yisen WangNeurIPS 2021 · 被引用 14 次
- Safe and Robust Watermark Injection with a Single OoD ImageShuyang Yu, Junyuan Hong, Haobo Zhang, Haotao Wang 等ICLR 2024 · 被引用 4 次
