给机器人神经网络控制器植入隐蔽后门,可远程诱发危险行为。
Trojan Attacks on Neural Network Controllers for Robotic Systems
- 设计轻量级并行后门网络,隐藏在轨迹跟踪控制器中。
- 触发条件特定时,使机器人输出异常速度指令,导致失控。
- 仿真验证了攻击有效,警示神经控制系统的安全风险。
神经网络控制器正被广泛应用于机器人系统,执行轨迹跟踪和姿态稳定等任务。然而,其依赖于可能不可信的训练流程或供应链,带来了显著的安全漏洞。本文研究针对神经网络控制器的后门(特洛伊)攻击,以差速移动机器人平台为案例。假设机器人的轨迹跟踪控制器由神经网络实现,我们设计了一种轻量级、并行的特洛伊网络模块,可嵌入控制器中。该恶意模块在正常运行时保持休眠状态,但一旦检测到由机器人位姿和目标参数定义的高度特定触发条件,便会干扰主控制器的轮速指令,导致机器人产生非预期且潜在危险的行为。本文提供了所提特洛伊网络的概念验证实现,并通过两种不同攻击场景的仿真进行了验证。结果证实了该攻击的有效性,表明基于神经网络的机器人控制系统面临关键性的安全威胁。
原文摘要 · Abstract (English)
Neural network controllers are increasingly deployed in robotic systems for tasks such as trajectory tracking and pose stabilization. However, their reliance on potentially untrusted training pipelines or supply chains introduces significant security vulnerabilities. This paper investigates backdoor (Trojan) attacks against neural controllers, using a differential-drive mobile robot platform as a case study. In particular, assuming that the robot's tracking controller is implemented as a neural network, we design a lightweight, parallel Trojan network that can be embedded within the controller. This malicious module remains dormant during normal operation but, upon detecting a highly specific trigger condition defined by the robot's pose and goal parameters, compromises the primary controller's wheel velocity commands, resulting in undesired and potentially unsafe robot behaviours. We provide a proof-of-concept implementation of the proposed Trojan network, which is validated through simulation under two different attack scenarios. The results confirm the effectiveness of the proposed attack and demonstrate that neural network-based robotic control systems are subject to potentially critical security threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。