PGFUZZ: Policy-Guided Fuzzing for Robotic Vehicles
Hyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik, Dongyan Xu
摘要
—Robotic vehicles (RVs) are becoming essential tools of modern systems, including autonomous delivery services, public transportation, and environment monitoring. Despite their diverse deployment, safety and security issues with RVs limit their wide adoption. Most attempts to date in RV security aim to propose defenses that harden their control program against syntactic bugs, input validation bugs, and external sensor spoofing attacks. In this paper, we introduce PGF UZZ , a policy-guided fuzzing framework, which validates whether an RV adheres to identified safety and functional policies that cover user commands, configuration parameters, and physical states. PGF UZZ expresses desired policies through temporal logic formulas with time constraints as a guide to fuzz the analyzed system. Specifically, it generates fuzzing inputs that minimize a distance metric measuring “how close” the RV current state is to a policy violation. In addition, it uses static and dynamic analysis to focus the fuzzing effort only on those commands, parameters, and environmental factors that influence the “truth value” of any of the exercised policies. The combination of these two techniques allows PGF UZZ to increase the efficiencyofthefuzzingprocesssignificantly.Wevalidate PGF UZZ on three RV control programs, ArduPilot, PX4, and Paparazzi, with 56 unique policies. PGF UZZ discovered 156 previously unknown bugs, 106 of which have been acknowledged by their developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- SnapFuzz: high-throughput fuzzing of network applicationsAnastasios Andronidis, Cristian CadarISSTA 2022 · 被引用 56 次
- RoboFuzz: fuzzing robotic systems over robot operating system (ROS) for finding correctness bugsSeulbae Kim, Taesoo KimFSE 2022 · 被引用 32 次
- On the (In)Security of Secure ROS2Gelei Deng, Guowen Xu, Yuan Zhou, Tianwei Zhang 等CCS 2022 · 被引用 31 次
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh 等ICSE 2022 · 被引用 29 次
- A Systematic Study of Physical Sensor Attack HardnessHyungsub Kim, Rwitam Bandyopadhyay, Muslum Ozgur Ozmen, Z. Berkay Celik 等S&P 2024 · 被引用 27 次
它引用的顶会 Paper8
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei 等CCS 2018 · 被引用 201 次
- All Your GPS Are Belong To Us: Towards Stealthy Manipulation of Road Navigation SystemsKexiong Curtis Zeng, Shinan Liu, Yuanchao Shu, Dong Wang 等USENIX Security 2018 · 被引用 174 次
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders 等S&P 2018 · 被引用 135 次
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 被引用 135 次
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu 等NDSS 2018 · 被引用 127 次
相关 Paper
- ADGFUZZ: Assignment Dependency-Guided Fuzzing for Robotic VehiclesYuncheng Wang, Yaowen Zheng, Puzhuo Liu, Dongliang Fang 等NDSS 2026 · 被引用 1 次
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei 等USENIX Security 2019 · 被引用 92 次
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark 等CCS 2025
- PGPatch: Policy-Guided Logic Bug Patching for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi 等S&P 2022 · 被引用 15 次
- PatchVerif: Discovering Faulty Patches in Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi 等USENIX Security 2023
