Lune

USENIX Security2026顶会

ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical Systems

Ruizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang, Yunbo Wang

出版方
2026年份

摘要

Real-time embedded systems are prevalent in cyber-physical applications such as drones and autonomous vehicles. Due to their high complexity, the environmental uncertainties, and the openness to remote control, these systems are vulnerable to control-flow hijacking and data-only attacks that compromise runtime integrity and reliability. Traditional control-flow integrity (CFI) and data-flow integrity (DFI) approaches impose excessive overhead, while the control-flow attestation (CFA) allows detection latency incompatible with real-time constraints. This paper presents ARTO, the first control-flow and data-flow protection approach that integrates the control-flow attestation to provide strong security with competitive runtime overhead. Through the prover-side path segmentation and hash-based validation result caching, ARTO provides partial context-sensitive protection at minimal runtime cost, offloading complete context-sensitive detection to the remote verifier. Furthermore, ARTO implements an equivalence-class-based data-flow protection that combines the address-based target check for memory reads with the value-based checks to protect critical variables, stronger than the SOTA operation integrity enforcement in validating the read source for critical variables. Extensive evaluations on robotic vehicle autopilots confirm ARTO's efficacy in mitigating both control-flow and data-only attacks while maintaining runtime overhead within real-time limits, outperforming SOTA CFA and operation-integrity enforcement methods in operation execution time.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper17

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖