Sizhuang Liang

dblp:276/0091 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2022 Hiding My Real Self! Protecting Intellectual Property in Additive Manufacturing Systems Against Optical Side-Channel Attacks
Sizhuang Liang, Saman A. Zonouz, Raheem A. Beyah
NDSS1
2021 Physical Logic Bombs in 3D Printers via Emerging 4D Techniques
abstract
Rapid prototyping makes additive manufacturing (or 3D printing) useful in critical application domains such as aerospace, automotive, and medical. The rapid expansion of these applications should prompt the examination of the underlying security of 3D printed objects. In this paper, we present Mystique, a novel class of stealthy attacks on printed objects that leverage the fourth dimension of emerging 4D printing technology to introduce embedded logic bombs through manufacturing process manipulation. Mystique enables visually benign objects to behave maliciously upon the activation of the logic bomb during operation. It leverages the manufacturing process to embed a physical logic bomb that can be triggered with specific stimuli to change the physical and mechanical properties of the printed objects. These changes in properties can potentially cause catastrophic operational failures when the objects are used in critical applications such as drones, prosthesis, or medical applications.
Tuan Le, Sriharsha Etigowni, Sizhuang Liang, Xirui Peng, H. Jerry Qi, Mehdi Javanmard, Saman A. Zonouz, Raheem A. Beyah
ACSAC3
2021 Physics-Aware Security Monitoring against Structural Integrity Attacks in 3D Printers
abstract
STereoLithography (STL) files describe the geometry of objects to be printed in additive manufacturing. Previous studies have shown that the STL files that describe functional objects can be attacked such that the objects appear normal during inspection, but fail during operation. Such attacks lead to damage to systems that use the objects and possibly loss of life. The detection of any defects caused due to the attacks nowadays is limited to the quality control process after the objects are manufactured.We present a Trusted Integrity Verifier (TIV) to detect such attacks on 3D printed objects in the early stage of the manufacturing process. These type of new attacks cannot be detected by traditional software security mechanisms since they only focus on the printers and do not consider the inputs (STL design files) to the printer. Early detection of attacks prevents from printing malicious objects resulting in saving time, resources and manufacturing efforts. TIV detects malicious STL files using multidisciplinary approaches unlike the traditional integrity verification techniques. TIV develops a void detection module based on computer vision techniques to identify the internal defects such as voids. Some of these features could be from the design and some could be due to the attack. To differentiate the malicious features from the design features, TIV develops safety verification module based on a numerical method. TIV's safety verification module is used to differentiate the malicious features from the design features by calculating the load bearing mechanical stress on the objects. These mechanical stresses are compared to the safety operational conditions to determine if the printed object will break or fail during its normal operation.To illustrate TIV's generality and scalability, we conducted a large-scale analysis on 16,000 real-world 3D print STL files. TIV verified the STL files successfully as either safe or malicious with high accuracy of 92% for object classification and 96.5% for void detection.
Sriharsha Etigowni, Sizhuang Liang, Saman A. Zonouz, Raheem A. Beyah
DSN2
2021 A Practical Side-Channel Based Intrusion Detection System for Additive Manufacturing Systems
abstract
We propose NSYNC, a practical framework to compare side-channel signals for real-time intrusion detection in Additive Manufacturing (AM) systems. The motivation to develop NSYNC is that we find AM systems are asynchronous in nature and there is random variation in timing in a printing process. Although this random variation, referred to as time noise, is very small compared with the duration of a printing process, it can cause existing Intrusion Detection Systems (IDSs) to fail. To deal with this problem, NSYNC incorporates a dynamic synchronizer to find the timing relationship between two signals. This timing relationship, referred to as the horizontal displacement, can not only be used to mitigate the adverse effect of time noise on calculating the (vertical) distance between signals, but also be used as indicators for intrusion detection. An existing dynamic synchronizer is Dynamic Time Warping (DTW). However, we found in experiments that DTW not only consumes an excessive amount of computational resources but also has limited accuracy for processing side-channel signals. To solve this problem, we propose a novel dynamic synchronizer, called Dynamic Window Matching (DWM), to replace DTW. To compare NSYNC against existing IDSs, we built a data acquisition system that is capable of collecting six different types of side-channel signals and performed a total of 302 benign printing processes and a total of 200 malicious printing processes with two printers. Our experiment results show that existing IDSs leveraging side-channel signals in AM systems can only achieve an accuracy from 0.50 to 0.88, whereas our proposed NSYNC can reach an accuracy of 0.99.
Sizhuang Liang, Xirui Peng, H. Jerry Qi, Saman A. Zonouz, Raheem A. Beyah
ICDCS1
2021 UNIFUZZ: A Holistic and Pragmatic Metrics-Driven Platform for Evaluating Fuzzers
Yuwei Li 0002, Shouling Ji, Sizhuang Liang, Wei-Han Lee, Yueyao Chen, Chenyang Lyu, Chunming Wu 0001, Raheem A. Beyah, Peng Cheng 0001, Kangjie Lu, Ting Wang 0006
USENIX Security Symposium4