PatchVerif: Discovering Faulty Patches in Robotic Vehicles
Hyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi, Dongyan Xu
摘要
Modern software is continuously patched to fix bugs and security vulnerabilities. Patching is particularly important in robotic vehicles (RVs), in which safety and security bugs can cause severe physical damages. However, existing automated methods struggle to identify faulty patches in RVs, due to their inability to systematically determine patch-introduced behavioral modifications, which affect how the RV interacts with the physical environment. In this paper, we introduce PATCHVERIF, an automated patch analysis framework. PATCHVERIF's goal is to evaluate whether a given patch introduces bugs in the patched RV control software. To this aim, PATCHVERIF uses a combination of static and dynamic analysis to measure how the analyzed patch affects the physical state of an RV. Specifically, PATCHVERIF uses a dedicated input mutation algorithm to generate RV inputs that maximize the behavioral differences (in the physical space) between the original code and the patched one. Using the collected information about patchintroduced behavioral modifications, PATCHVERIF employs support vector machines (SVMs) to infer whether a patch is faulty or correct. We evaluated PATCHVERIF on two popular RV control software (ArduPilot and PX4), and it successfully identified faulty patches with an average precision and recall of 97.9% and 92.1%, respectively. Moreover, PATCHVERIF discovered 115 previously unknown bugs, 103 of which have been acknowledged, and 51 of them have already been fixed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A Systematic Study of Physical Sensor Attack HardnessHyungsub Kim, Rwitam Bandyopadhyay, Muslum Ozgur Ozmen, Z. Berkay Celik 等S&P 2024 · 被引用 27 次
- ADGFUZZ: Assignment Dependency-Guided Fuzzing for Robotic VehiclesYuncheng Wang, Yaowen Zheng, Puzhuo Liu, Dongliang Fang 等NDSS 2026 · 被引用 1 次
- SoK: Towards Effective Automated Vulnerability RepairYing Li, Faysal Hossain Shezan, Bomin Wei, Gang Wang 等USENIX Security 2025
- Automated Discovery of Semantic Attacks in Multi-Robot Navigation SystemsDoguhan Yeke, Kartik Anand Pant, Muslum Ozgur Ozmen, Hyungsub Kim 等USENIX Security 2025
它引用的顶会 Paper12
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei 等CCS 2018 · 被引用 201 次
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei 等USENIX Security 2019 · 被引用 92 次
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 被引用 91 次
- Automating Patching of Vulnerable Open-Source Software Versions in Application BinariesRuian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi 等NDSS 2019 · 被引用 63 次
相关 Paper
- PGPatch: Policy-Guided Logic Bug Patching for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi 等S&P 2022 · 被引用 15 次
- An exploratory study of autopilot software bugs in unmanned aerial vehiclesDinghua Wang, Shuqing Li, Guanping Xiao, Yepang Liu 等FSE 2021 · 被引用 60 次
- PGFUZZ: Policy-Guided Fuzzing for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik 等NDSS 2021
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark 等CCS 2025
- Cyber-Physical Inconsistency Vulnerability Identification for Safety Checks in Robotic VehiclesHongjun Choi, Sayali Kate, Yousra Aafer, Xiangyu Zhang 等CCS 2020 · 被引用 22 次
