Seeing is Not Believing: Breaking the Physical-to-Digital Trust Boundary in Robotics

📅 2026-09-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
论文揭示了ROS 2系统中的一个严重漏洞,通过修改环境变量,攻击者可以拦截并注入遥测数据和控制信号,导致机器人执行危险任务。
📝 Abstract
In multi-robot collaboration, task handovers rely on downstream verifiers performing remote attestation, which inspects sensor telemetry to ensure a robot's physical behavior strictly matches its assigned task. But can this telemetry be trusted? We show that it often cannot. In this paper, we uncover a severe vulnerability in Robot Operating System (ROS) 2: by modifying a single environment variable, an adversary can execute a pre-built hook to covertly intercept and inject both telemetry and control signals before they are published. Consequently, adversaries can hijack a robot to perform dangerous tasks while spoofing downstream verifiers with synthesized fake telemetry. Worse still, by exploiting the widespread reliance on third-party Docker containers and auxiliary tools, attackers can distribute compromised packages embedded with these malicious hooks to launch such attacks easily. On a physical Franka Emika robotic arm running Secure ROS 2, our attack injects fabricated telemetry in real time with only around 3 ms of jitter, preserving temporal synchronization and hardware integrity while achieving an 87% success rate even against an AI-based detector. We have responsibly disclosed these findings to the ROS 2 development team. We prepared a demo video available at https://youtu.be/ExeiGqUrnhQ.
Problem

Research questions and friction points this paper is trying to address.

Robot Operating System (ROS) 2
telemetry
vulnerability
multi-robot collaboration
remote attestation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Robot Operating System (ROS) 2
telemetry injection
security vulnerability
remote attestation
adversarial attack
🔎 Similar Papers