构建七层安全模型,系统评估人形机器人全链路风险
SoK: Cybersecurity Assessment of Humanoid Ecosystem
- 提出涵盖软硬件的七层安全架构,整合39类攻击与35种防御
- 通过蒙特卡洛验证的矩阵评分,实测三款机器人安全得分39.9%~79.5%
- 为研发者和采购方提供可量化的安全评估工具,适合关注机器人安全的团队
人形机器人正逐步应用于医疗、工业、国防和服务领域。尽管通常被视为网络物理系统(CPS),其依赖传统网络化软件栈(如Linux操作系统)、机器人操作系统(ROS)中间件及空中更新通道,形成了独特的安全特征,暴露于传统CPS模型未能覆盖的漏洞中。以往研究多聚焦特定威胁,如激光雷达欺骗或对抗性机器学习(AML),忽视了单个组件受攻后在机器人互联系统中的级联危害。本文通过知识体系化(SoK)方法,综合机器人学、CPS与网络安全领域的碎片化研究,提出适用于人形机器人的七层安全模型,将39种已知攻击与35种防御措施进行系统组织。基于该模型,构建39×35攻击-防御量化矩阵,并通过蒙特卡洛分析验证其有效性。以Pepper、G1 EDU和Digit三款实际机器人为例,评分结果显示各平台安全成熟度差异显著,得分范围为39.9%至79.5%。本研究提出一种结构化、基于证据的安全评估方法,支持跨平台基准测试,助力安全投资优先级决策。
原文摘要 · Abstract (English)
Humanoids are progressing toward practical deployment across healthcare, industrial, defense, and service sectors. While typically considered cyber-physical systems (CPSs), their dependence on traditional networked software stacks (e.g., Linux operating systems), robot operating system (ROS) middleware, and over-the-air update channels, creates a distinct security profile that exposes them to vulnerabilities conventional CPS models do not fully address. Prior studies have mainly examined specific threats, such as LiDAR spoofing or adversarial machine learning (AML). This narrow focus overlooks how an attack targeting one component can cascade harm throughout the robot's interconnected systems. We address this gap through a systematization of knowledge (SoK) that takes a comprehensive approach, consolidating fragmented research from robotics, CPS, and network security domains. We introduce a seven-layer security model for humanoid robots, organizing 39 known attacks and 35 defenses across the humanoid ecosystem-from hardware to human-robot interaction. Building on this security model, we develop a quantitative 39x35 attack-defense matrix with risk-weighted scoring, validated through Monte Carlo analysis. We demonstrate our method by evaluating three real-world robots: Pepper, G1 EDU, and Digit. The scoring analysis revealed varying security maturity levels, with scores ranging from 39.9% to 79.5% across the platforms. This work introduces a structured, evidence-based assessment method that enables systematic security evaluation, supports cross-platform benchmarking, and guides prioritization of security investments in humanoid robotics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。