EDBT 2026 Demo / reviewers in the wild / expert
Ryan M. Gerdes
dblp:73/1832
· DBLP profile ↗
39ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0003-0876-1181ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 5 first-author · 14 since 2021Systems, architecture and hardware · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionabstractCooperative perception (CP) enhances situational awareness of connected and autonomous vehicles by exchanging and combining messages from multiple agents. While prior work has explored adversarial integrity attacks that degrade detection accuracy, little is known about CP's robustness against attacks on timeliness (or availability), a safety-critical requirement for autonomous driving. In this paper, we present CP-FREEZER, the first latency attack that maximizes the computation delay of CP algorithms by injecting adversarial perturbation via V2V messages. Our attack resolves several unique challenges, including the non-differentiability of point cloud preprocessing, asynchronous knowledge of the victim’s input due to transmission delays, and uses a novel loss function that effectively maximizes the execution time of the CP pipeline. Extensive experiments show that CP-FREEZER increases end-to-end CP latency by over 90×, pushing per-frame processing time beyond 3 seconds with a 100% success rate on our real-world vehicle testbed. Our findings reveal a critical threat to the availability of CP systems, highlighting the urgent need for robust defenses. Chenyi Wang 0005, Ruoyu Song 0001, Raymond Muller, Jean-Philippe Monteuuis, Z. Berkay Celik, Jonathan Petit, Ryan M. Gerdes, Ming Li 0003 |
AAAI | 7 |
| 2026 | Fine-Grained Vehicle Classification Using Loop Detectors: A Wireless Fingerprinting Approach
Abdullah Zubair Mohammed, Alok K. Singh, Louis Jenkins, Ryan M. Gerdes, Mani Mina |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | EM-Flow: Advanced Electromagnetic Control Flow Verification for Embedded SystemsabstractEmbedded devices play a major role in supporting critical infrastructure, but lack many of the security pro-tections of sophisticated systems. Determining whether these devices are compromised is, therefore, a challenge. In this work, we describe a novel control flow verification methodology via electromagnetic (EM) emanations. We design a framework that incorporates signal processing and training to detect subtle control flow deviations as small as three clock cycles, the minimum required to execute a return with malicious activity on modern embedded hardware. Our methodology leverages basic block detection, enabling the discovery of these subtle control flow deviations that escape conventional detection approaches. We evaluate our framework's ability to detect insertion and modification control flow attacks on six different case studies of real-world critical operations and two processors featuring different architectures. Our results show 96.6% detection accuracy across all tested programs and attacks. Finally, we show the transferability of our methodology to different instances of our evaluated processors, reaching up to 98.7% convergence with our baseline models while requiring a third of the collected EM samples compared to standard retraining. In doing so, we reveal the feasibility of fine-grained EM-based control flow monitoring for low-power microcontrollers. Carson Stillman, Jennifer Sheldon, Ian Y. Garrett, Patrick Traynor, Ryan M. Gerdes, Sara Rampazzi, Kevin R. B. Butler |
ACSAC | 5 |
| 2025 | From Transients to Flips: Hardware-level Bit Manipulation of In-Vehicle Serial CommunicationabstractIn a modern automobile, the in-vehicle communication network interconnects multiple subsystems, including those that perform safety-critical functions such as engine control, anti-lock braking, and airbag deployment, among many others. Therefore, the loss of data integrity in the network can have serious consequences for the safety of the vehicle. To that extent, CAN protocol, the most common in-vehicle communication standard, employs error-handling mechanisms such as bit-monitoring and cyclic-redundancy check to detect intentional or unintentional data manipulation. In this work, we exploit the transmission line nature of the CAN physical layer (a twisted pair cable) to induce voltage transients that result in bit manipulations. Specifically, we demonstrate bidirectional bit flip attacks, recessive to dominant (R→D) and dominant to recessive (D→R) with the aid of multiple compromised nodes (electronic control units) in the network. In addition, both the attacks, the simpler R→D, and the complex D→R are designed to be undetectable to the aforementioned error-handling mechanisms. The attacks become effective for distances ≥ 4m for D→R and ≥ 1m for R→D between the transmitter and receiver nodes. By demonstrating these bit flips, we challenge two fundamental physical layer assumptions of CAN: the impossibility of turning a dominant bit to recessive without an external current source, and having nonidentical signals on two nodes at the same time. The theory behind the attacks is presented, backed by circuit simulations, in-lab validations, and real-world demonstrations in a vehicle. These bit-level attacks, designed at the physical layer, circumvent software-based CAN defenses and lay the groundwork for a broader spectrum of potential attacks, including the manipulation of a data frame that we demonstrate. Abdullah Zubair Mohammed, Ryan M. Gerdes |
AsiaCCS | 2 |
| 2025 | Domain Adaptation for Cross-Device Profiled ML Side-Channel Attacks
Ian Y. Garrett, Ryan M. Gerdes |
ICICS (3) | 2 |
| 2025 | Mad Monk: Arbitrary Criticality Escalation in Mixed Criticality Real-Time SystemsabstractIn safety critical computing, real-time and security concerns are often considered separately, though the behavior of a scheduling model itself may be an attack surface which can be exploited by an attacker to reduce system performance. In this work, we explore how the semantics of mode changes in mixed-criticality systems could be used as one such attack vector. This attack, dubbed Mad Monk, uses a mixed criticality scheduler's mode switches against itself by allowing a task of a lower criticality to interfere with tasks of a higher criticality, thereby forcing a disruptive mode switch which could possibly reduce service to some tasks. We describe this attack in detail, along with a case study demonstrating its risk. Furthermore, extensive simulations of this attack demonstrate its potential effectiveness based on a variety of timing and system factors. Mitchell Duncan, Ao Li 0006, Nathan Fisher, Ning Zhang 0017, Ryan M. Gerdes, Tanmaya Mishra, Thidapat Chantem |
ISORC | 5 |
| 2025 | Investigating Physical Latency Attacks Against Camera-Based PerceptionabstractCamera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems. Raymond Muller, Ruoyu Song 0001, Chenyi Wang 0005, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
SP | 8 |
| 2025 | From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative Perception
Chenyi Wang 0005, Raymond Muller, Ruoyu Song 0001, Jean-Philippe Monteuuis, Jonathan Petit, Yanmao Man, Ryan M. Gerdes, Z. Berkay Celik, Ming Li 0003 |
USENIX Security Symposium | 7 |
| 2024 | Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial TrajectoryabstractMulti-Object Tracking (MOT) is a critical task in computer vision, with applications ranging from surveillance systems to autonomous driving. However, threats to MOT algorithms have yet been widely studied. In particular, incorrect association between the tracked objects and their assigned IDs can lead to severe consequences, such as wrong trajectory predictions. Previous attacks against MOT either focused on hijacking the trackers of individual objects, or manipulating the tracker IDs in MOT by attacking the integrated object detection (OD) module in the digital domain, which are model-specific, non-robust, and only able to affect specific samples in offline datasets. In this paper, we present AdvTraj, the first online and physical ID-manipulation attack against tracking-by-detection MOT, in which an attacker uses adversarial trajectories to transfer its ID to a targeted object to confuse the tracking system, without attacking OD. Our simulation results in CARLA show that AdvTraj can fool ID assignments with 100% success rate in various scenarios for white-box attacks against SORT, which also have high attack transferability (up to 93% attack success rate) against state-of-the-art (SOTA) MOT algorithms due to their common design principles. We characterize the patterns of trajectories generated by AdvTraj and propose two universal adversarial maneuvers that can be performed by a human walker/driver in daily scenarios. Our work reveals under-explored weaknesses in the object association phase of SOTA MOT systems, and provides insights into enhancing the robustness of such systems. Chenyi Wang 0005, Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes, Jonathan Petit |
ACSAC | 6 |
| 2024 | The IEMI Effect: On the Efficacy of PCB-Level Countermeasures in Adversarial EnvironmentsabstractSensing data integrity in a cyber-physical system (CPS) is critical to its safe operation. Intolerable data manipulation can potentially lead to very hazardous consequences. Numerous countermeasures have proven capable of protecting sensitive circuitry, cabling, and their signals from the effects of electromagnetic interference (EMI). However, in the case of intentional electromagnetic interference (IEMI), existing countermeasures possess limited efficacy. IEMI-capable adversaries attack the signal processing circuits and signal paths between sensors/actuators and the controller, seeking to manipulate the signals and falsify data. On a printed circuit board (PCB), the traces carrying these signals act as unintentional receiving antennae to a time-varying electromagnetic field generated by an adversary. In this paper, we demonstrate IEMI attacks on the PCBs used in electric vehicle (EV) charging systems, a highly safety-critical CPS. To mitigate these attacks, we implement passive PCB-level countermeasures, namely, differential signaling, via-fencing, and optical fiber for interconnects. In addition, we propose and implement a multiplexer-based defense that dynamically modifies the route path and evades the adversary. All four countermeasures have been extensively evaluated against multiple adversarial setups and ranked based on their impact. Further, adaptive attacker strategies have been proposed to circumvent the effective countermeasures. Abdullah Zubair Mohammed, Louis Jenkins, Rees R. Hatch, Gökçen Yilmaz Dayanikli, Craig Simpson, Ryan M. Gerdes, Hongjie Wang 0001 |
EuroS&P | 6 |
| 2024 | VOGUES: Validation of Object Guise using Estimated Components
Raymond Muller, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
USENIX Security Symposium | 4 |
| 2024 | Remote Perception Attacks against Camera-based Object Recognition Systems and CountermeasuresabstractIn vision-based object recognition systems, imaging sensors perceive the environment and then objects are detected and classified for decision-making purposes, e.g., to maneuver an automated vehicle around an obstacle or to raise alarms for intruders in surveillance settings. In this work we demonstrate how camera-based perception can be unobtrusively manipulated to enable an attacker to create spurious objects or alter an existing object, by remotely projecting adversarial patterns into cameras, exploiting two common effects in optical imaging systems, viz., lens flare/ghost effects and auto-exposure control. To improve the robustness of the attack, we generate optimal patterns by integrating adversarial machine learning techniques with a trained end-to-end channel model. We experimentally demonstrate our attacks using a low-cost projector on three different cameras, and under different environments. Results show that, depending on the attack distance, attack success rates can reach as high as 100%, including under targeted conditions. We develop a countermeasure that reduces the problem of detecting ghost-based attacks into verifying whether there is a ghost overlapping with a detected object. We leverage spatiotemporal consistency to eliminate false positives. Evaluation on experimental data provides a worst-case equal error rate of 5%. Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2023 | That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency
Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes |
USENIX Security Symposium | 5 |
| 2022 | Wireless Manipulation of Serial CommunicationabstractWired serial communication (e.g., UART, I2C) is widely used to exchange information between sensors, actuators, and controllers in automation, control, and cyber-physical systems. In this work, it is demonstrated that intentional electromagnetic interference (IEMI) can be utilized to not only induce spurious serial communications but to also alter legitimate communications, arbitrarily and at a distance, through attacks that cause controlled, bidirectional bit flips. To prove the efficacy of such attacks, two attack signal types, which require differing levels of attacker knowledge and resources to be effective, are proposed and evaluated against UART and I2C serial communication systems. The first attack waveform, which we call simple, is an inexpensive--to--produce narrowband waveform that has high power and tight timing constraints, but requires little attacker knowledge about the targeted system, while the second waveform, which we call complex, leverages a wideband signal that requires less power to achieve the same effect, is more tolerant of timing error in the signal processing phase, but requires a high amount of attacker knowledge of the targeted system. The simple waveform is shown to be over 98.3% effective at inducing a desired bit sequence into randomly transmitted UART frames, which indicates that an attacker could also choose to inject spurious UART frames, at will. On the I2C data streams, the complex waveform is demonstrated to be overall 75% effective in inducing random bits. Countermeasures are discussed and experimentally validated in high-IEMI scenarios. Gökçen Yilmaz Dayanikli, Abdullah Zubair Mohammed, Ryan M. Gerdes, Mani Mina |
AsiaCCS | 3 |
| 2022 | Physical Hijacking Attacks against Object TrackersabstractModern autonomous systems rely on both object detection and object tracking in their visual perception pipelines. Although many recent works have attacked the object detection component of autonomous vehicles, these attacks do not work on full pipelines that integrate object tracking to enhance the object detector's accuracy. Meanwhile, existing attacks against object tracking either lack real-world applicability or do not work against a powerful class of object trackers, Siamese trackers. In this paper, we present AttrackZone, a new physically-realizable tracker hijacking attack against Siamese trackers that systematically determines valid regions in an environment that can be used for physical perturbations. AttrackZone exploits the heatmap generation process of Siamese Region Proposal Networks in order to take control of an object's bounding box, resulting in physical consequences including vehicle collisions and masked intrusion of pedestrians into unauthorized areas. Evaluations in both the digital and physical domain show that AttrackZone achieves its attack goals 92% of the time, requiring only 0.3-3 seconds on average. Raymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li 0003, Ryan M. Gerdes |
CCS | 5 |
| 2022 | Secure CV2X Using COTS Smartphones over LTE Infrastructure
Spandan Mahadevegowda, Ryan M. Gerdes, Thidapat Chantem, Rose Qingyang Hu |
SecureComm | 2 |
| 2022 | Physical-Layer Attacks Against Pulse Width Modulation-Controlled Actuators
Gökçen Yilmaz Dayanikli, Sourav Sinha, Devaprakash Muniraj, Ryan M. Gerdes, Mazen Farhood, Mani Mina |
USENIX Security Symposium | 4 |
| 2022 | Passive Drone Localization Using LTE SignalsabstractDrones raise significant privacy and security threats, by intruding into the airspace of private properties or unauthorized regions. Being able to detect and localize the encroaching drones is essential to build geofencing systems to prevent drone misuse. While most existing approaches focus on detecting and localizing active drones, passive drones that do not emit signals are particularly challenging to localize, without requiring advanced hardware. In this work, we propose a novel, low-cost passive drone localization approach, by leveraging opportunistic environmental RF signals (e.g., LTE or WiFi) that reflect off the target drone, with only a single wireless receiver. We implement a prototype system on a USRP-device based testbed, with standard LTE signals emitted by multiple distributed transmitters, and conduct experiments on top of a campus building to evaluate its performance. We also perform a drone detection range analysis to extrapolate the real-world applicability of our scheme Mingshun Sun, Zhiwu Guo, Ming Li 0003, Ryan M. Gerdes |
WISEC | 4 |
| 2022 | Survey of Control-flow Integrity Techniques for Real-time Embedded SystemsabstractComputing systems, including real-time embedded systems, are becoming increasingly connected to allow for more advanced and safer operation. Such embedded systems are also often resource-constrained, for example, with lower processing capabilities compared to general-purpose computing systems like desktops or servers. With the advent of paradigms such as internet-of-things (IoT), embedded systems in both commercial and industrial contexts are being increasingly interconnected and exposed to the external networks to improve automation and efficiency of operation. However, allowing external interfaces to such embedded systems increases their exposure to attackers. With an increase in attacks against embedded systems ranging from home appliances to industrial control systems operating critical equipment that have real-time requirements, it is imperative that defense mechanisms be created that explicitly consider such resource and real-time constraints. Control-flow integrity (CFI) is a family of defense mechanisms that prevent attackers from modifying the flow of execution. We survey CFI techniques, ranging from the basic to state of the art, that are built for embedded systems and real-time embedded systems and find that there is a dearth, especially for real-time embedded systems, of CFI mechanisms. We then present open challenges to the community to help drive future research in this domain. Tanmaya Mishra, Thidapat Chantem, Ryan M. Gerdes |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2020 | GhostImage: Remote Perception Attacks against Camera-based Image Classification Systems
Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
RAID | 3 |
| 2020 | Spotr: GPS spoofing detection via device fingerprintingabstractAs the world's predominant navigation system, GPS is critical to modern life, finding applications in diverse areas like information security, healthcare, marketing, and power and water grid management. Unfortunately this diversification has only served to underscore the insecurity of GPS and the critical need to harden this system against manipulation and exploitation. A wide variety of attacks against GPS have already been documented, both in academia and industry. Several defenses have been proposed to combat these attacks, but they are ultimately insufficient due to scope, expense, complexity, or robustness. With this in mind, we present our own solution: fingerprinting of GPS satellites. We assert that it is possible to create signatures, or fingerprints, of the satellites (more specifically their transmissions) that allow one to determine nearly instantly whether a received GPS transmission is authentic or not. Furthermore, in this paper we demonstrate that this solution detects all known spoofing attacks, that it does so while being fast, cheap, and simpler than previous solutions, and that it is highly robust with respect to environmental factors. Mahsa Foruhandeh, Abdullah Zubair Mohammed, Gregor Kildow, Paul Berges, Ryan M. Gerdes |
WISEC | 5 |
| 2020 | SVM: secure vehicle motion verification with a single wireless receiverabstractConnected vehicles leverage wireless interfaces to broadcast their motion state information for improved traffic safety and efficiency. It is crucial for their motion claims (location and velocity) to be verified at the receivers to detect spoofing attacks. Existing approaches typically require multiple cooperative distributed verifiers, which is not applicable to vehicular networks. In this work, we propose a secure motion verification scheme based on Angle-of-Arrival and Frequency-of-Arrival that only requires a single verifier, by exploiting opportunistic signal reflection paths in the environment to create multiple virtual verifiers. We analyze the security of our scheme both theoretically and under realistic road topology. We also carry out real-world experiments with two vehicles in a campus environment, and results show that our scheme can accurately detect false motion claims in a low relative speed vehicular network. Mingshun Sun, Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
WISEC | 4 |
| 2020 | Message Integrity Protection Over Wireless Channel: Countering Signal Cancellation via Channel RandomizationabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel signal cancellation attack framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments as well as the online nature of the attack. Based on theoretical results, we propose a practical channel randomization approach to defend against signal cancellation attack, which exploits state diversity and swift reconfigurability of reconfigurable antenna to increase randomness and meanwhile reduce correlation of channel state information. We show that by proactively mimicking the attacker and placing restrictions on the attacker's location, we can bound the attacker's knowledge of channel state information, thereby achieve a guaranteed level of message integrity protection in practice. Besides, we conduct extensive experiments and simulations to show the security and performance of the proposed approach. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yanjun Pan 0001, Yantian Hou, Ming Li 0003, Ryan M. Gerdes, Kai Zeng 0001, Md. Asaduzzaman Towfiq, Bedri A. Cetiner |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | SIMPLE: single-frame based physical layer identification for intrusion detection and prevention on in-vehicle networksabstractThe Controller Area Network (CAN) is a bus standard commonly used in the automotive industry for connecting Electronic Control Units (ECUs) within a vehicle. The broadcast nature of this protocol, along with the lack of authentication or strong integrity guarantees for frames, allows for arbitrary data injection/modification and impersonation of the ECUs. While mitigation strategies have been proposed to counter these attacks, high implementation costs or violation of backward compatibility hinder their deployment. In this work, we first examine the shortcomings of state-of-the-art CAN intrusion detection and identification systems that rely on multiple frames to detect misbehavior and attribute it to a particular ECU, and show that they are vulnerable to a Hill-Climbing-style attack. Then we propose SIMPLE, a real-time intrusion detection and identification system that exploits physical layer features of ECUs, which would not only allow an attack to be detected using a single frame but also be effectively nullified. SIMPLE has low computational and data acquisition costs, and its efficacy is demonstrated by both in-lab experiments with automotive-grade CAN transceivers as well as in-vehicle experiments, where average equal error rates of close to 0% and 0.8985% are achieved, respectively. Mahsa Foruhandeh, Yanmao Man, Ryan M. Gerdes, Ming Li 0003, Thidapat Chantem |
ACSAC | 3 |
| 2019 | On the Pitfalls and Vulnerabilities of Schedule Randomization Against Schedule-Based AttacksabstractSchedule randomization is one of the recently introduced security defenses against schedule-based attacks, i.e., attacks whose success depends on a particular ordering between the execution window of an attacker and a victim task within the system. It falls into the category of information hiding (as opposed to deterministic isolation-based defenses) and is designed to reduce the attacker's ability to infer the future schedule. This paper aims to investigate the limitations and vulnerabilities of schedule randomization-based defenses in real-time systems. We first provide definitions, categorization, and examples of schedule-based attacks, and then discuss the challenges of employing schedule randomization in real-time systems. Further, we provide a preliminary security test to determine whether a certain timing relation between the attacker and victim tasks will never happen in systems scheduled by a fixed-priority scheduling algorithm. Finally, we compare fixed-priority scheduling against schedule-randomization techniques in terms of the success rate of various schedule-based attacks for both synthetic and real-world applications. Our results show that, in many cases, schedule randomization either has no security benefits or can even increase the success rate of the attacker depending on the priority relation between the attacker and victim tasks. Mitra Nasri, Thidapat Chantem, Gedare Bloom, Ryan M. Gerdes |
RTAS | 4 |
| 2019 | The Disbanding Attack: Exploiting Human-in-the-Loop Control in Vehicular Platooning
Ali Al-Hashimi, Pratham Oza, Ryan M. Gerdes, Thidapat Chantem |
SecureComm (2) | 3 |
| 2019 | Crowdsourced measurements for device fingerprintingabstractPhysical layer identification allows verifying a user's identity based on their transmitter hardware. In contrast with digital identifiers at higher protocol layers, physical layer identification or device fingerprinting can identify unique signal characteristics at the physical layer introduced by manufacturing variability specific to each device. Recently, dynamic spectrum access has been proposed to allow a larger number of devices to efficiently access wireless spectrum. In such a system many low-cost devices may be distributed over a large area with spectrum allocated and managed by a central authority. Traditional authentication methods may not be secure, or adequate to identify existing users in a backwards compatible way: Identifiers such as MAC addresses can be impersonated, and the number of devices and their distributed nature may make key distribution and revocation difficult. Consequently, physical layer identification can be used to augment other security measures. Seth Andrews, Ryan M. Gerdes, Ming Li 0003 |
WiSec | 2 |
| 2018 | Electromagnetic Induction Attacks Against Embedded SystemsabstractEmbedded and cyber-physical systems are critically dependent on the integrity of input and output signals for proper operation. Input signals acquired from sensors are assumed to correspond to the phenomenon the system is monitoring and responding to. Similarly, when such systems issue an actuation signal it is expected that the mechanism being controlled will respond in a predictable manner. Recent work has shown that sensors can be manipulated through the use of intentional electromagnetic interference (IEMI). In this work, we demonstrate thatboth input and output signals, analog and digital, can be remotely manipulated via the physical layer---thus bypassing traditional integrity mechanisms. Through the use of specially crafted IEMI it is shown that the physical layer signaling used for sensor input to, and digital communications between, embedded systems may be undermined to an attacker's advantage. Three attack scenarios are analyzed and their efficacy demonstrated. In the first scenario the analog sensing channel is manipulated to produce arbitrary sensor readings, while in the second it is shown that an attacker may induce bit flips in serial communications. Finally, a commonly used actuation signal is shown to be vulnerable to IEMI. The attacks are effective over appreciable distances and at low power. Jayaprakash Selvaraj, Gökçen Yilmaz Dayanikli, Neelam Prabhu Gaunkar, David Ware, Ryan M. Gerdes, Mani Mina |
AsiaCCS | 5 |
| 2017 | Regular: Attacker-Induced Traffic Flow Instability in a Stream of Semi-Automated VehiclesabstractWe show that a stream of automated vehicles traveling along the highway can be destabilized to catastrophic effect through modification of the control laws of individual vehicles. Specifically, one active attacker who introduces errors, in addition to one or many passive attackers who amplify the error, may, by the modification of a single parameter, induce oscillatory traffic jams that cause delay, driver discomfort, excess energy expenditure, and increased risk of accidents that could result in serious injury or death. We determine the conditions under which an attacker(s) is able to violate the primary design criterion of automated vehicle streams, known as string stability, to guarantee system instability. Furthermore, we prove that once the stream has been destabilized it will continually deviate from the desired state, even in the absence of additional input to the system-i.e. the jammed condition will self-perpetuate. Through a comparison with a behavioral human driver model, this work demonstrates that automated vehicle systems are more vulnerable to disruption than their non-automated counterparts. The postulated attack is demonstrated on a scaled system and identification of attackers is discussed. Daniel D. Dunn, Samuel A. Mitchell, Imran Sajjad, Ryan M. Gerdes, Rajnikant Sharma, Ming Li 0003 |
DSN | 4 |
| 2015 | Vehicular Platooning in an Adversarial EnvironmentabstractIn this paper, we show that a single, maliciously controlled vehicle can destabilize a vehicular platoon, to catastrophic effect, through local modifications to the prevailing control law. Specifically, by combining changes to the gains of the associated law with the appropriate vehicle movements, the attacker can cause the platoon to oscillate at a resonant frequency, causing accidents that could result in serious injury or death. We determine the range of gains, and their corresponding frequencies, that allow an attacker to violate the string stability and stability criteria at different positions in the platoon. Furthermore, we prove that the attack can be successful at any position in the platoon and at frequencies that can be realized by the other vehicles in the platoon. Our work implies that neither the string stability nor stability conditions, when used singly, ensure proper platoon operation, and that neither can be used to ensure the other. Finally, we show that an attacker is theoretically capable of gaining control over the individual position and velocity (states) of other vehicles in the platoon; two attacks are demonstrated for this vulnerability. Soodeh Dadras, Ryan M. Gerdes, Rajnikant Sharma |
AsiaCCS | 2 |
| 2015 | Message Integrity Protection over Wireless Channel by Countering Signal Cancellation: Theory and PracticeabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel correlated jamming framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments. Besides, we design a practical physical layer message integrity protection protocol based on ON/OFF keying and Manchester coding, which provides quantitative security guarantees in the real-world. Such a guarantee is achieved by bounding the attacker's knowledge about the future channel via proactively measuring channel statistics (mimic the attacker), so as to derive a lower-bound to the defender's signal-detection probability under optimal correlated jamming attacks. We conduct extensive experiments and simulations to show the security and performance of the proposed scheme. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yantian Hou, Ming Li 0003, Ruchir Chauhan, Ryan M. Gerdes, Kai Zeng 0001 |
AsiaCCS | 4 |
| 2015 | Physical-Layer Detection of Hardware Keyloggers
Ryan M. Gerdes, Saptarshi Mallick |
RAID | 1 |
| 2015 | Remote Activation of Hardware Trojans via a Covert Temperature Channel
Priyabrat Dash, Chris Perkins, Ryan M. Gerdes |
SecureComm | 3 |
| 2014 | POSTER: Analysis and Comparison of Secure Localization Schemes for Intelligent Transportation SystemsabstractIn this work, we employ distance bounding (DB) and verifiable trilateration (VT) for secure localization in an intelligent transportation system (ITS). We first demonstrate several possible attack scenarios, and then establish an analytical framework to evaluate the security of these schemes. Results are derived in terms of the probability of a given position being spoofed by maliciously-controlled vehicles assuming randomly distributed colluding attackers. The results show that while VT outperforms DB, both methods have a high probability of being spoofed. Bhaswati Deka, Ryan M. Gerdes, Ming Li 0003, Kevin P. Heaslip |
CCS | 2 |
| 2014 | Friendly Jamming for Secure Localization in Vehicular Transportation
Bhaswati Deka, Ryan M. Gerdes, Ming Li 0003, Kevin P. Heaslip |
SecureComm (1) | 2 |
| 2013 | CPS: an efficiency-motivated attack against autonomous vehicular transportationabstractThis work describes a new type of efficiency attack that can be used to degrade the performance of automated vehicular transportation systems. Next-generation transportation technologies will leverage increasing use of vehicle automation. Proposed vehicular automation systems include cooperative adaptive cruise control and vehicle platooning strategies which require cooperation and coordination among vehicles. These strategies are intended to optimize through-put and energy usage in future highway systems, but, as we demonstrate, they also introduce new vulnerabilities. In this work we show that a typical platooning system would allow a maliciously controlled vehicle to exert subtle influence on the motion of surrounding vehicles. This effect can be used to increase the energy expenditure of surrounding vehicles by 20% to 300%. Ryan M. Gerdes, Chris Winstead, Kevin P. Heaslip |
ACSAC | 1 |
| 2012 | Towards a Framework for Evaluating the Security of Physical-Layer Identification Systems
Ryan M. Gerdes, Mani Mina, Thomas Daniels 0001 |
SecureComm | 1 |
| 2012 | Physical-Layer Identification of Wired Ethernet DevicesabstractThis work sets forth a systematic approach for the investigation and utilization of the signal characteristics of digital devices for use in a security context. A methodology, built upon an optimal detector, the matched filter, is proposed that allows for the reliable identification and tracking of wired Ethernet cards by use of their hardware signaling characteristics. The matched filter is found to be sensitive enough to differentiate between devices using only a single Ethernet frame; an adaptive thresholding strategy employing prediction intervals is used to cope with the stochastic nature of the signals. To demonstrate the validity of the methodology, and to determine which portions of the signal are useful for identification purposes, experiments were performed on three different models of 10/100 Ethernet cards, totaling 27 devices in all. In selecting the cards, an effort was made to maximize intramodel similarity and thus present a worst-case scenario. While the primary focus of the work is network-based authentication, forensic applications are also considered. By using data collected from the same devices at different times, it is shown that some models of cards can be reidentified even after a month has elapsed since they were last seen. Ryan M. Gerdes, Mani Mina, Steve Russell, Thomas Daniels 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | Device Identification via Analog Signal Fingerprinting: A Matched Filter Approach
Ryan M. Gerdes, Thomas Daniels 0001, Mani Mina, Steve Russell |
NDSS | 1 |