SWARMFLAWFINDER: Discovering and Exploiting Logic Flaws of Swarm Algorithms

SWARMFLAWFINDER: Discovering and Exploiting Logic Flaws of Swarm Algorithms
复制标题

DOI:
10.1109/sp46214.2022.9833685
复制
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon
Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon
中科院分区:
其他
文献类型:
--
作者:
Chi-Gon Jung;A. Ahad;Yuseok Jeon;Yonghwi Kwon

文献摘要

被引文献

相似文献

受自然界中群体的启发,群体机器人已经被开发用于执行各种具有挑战性的任务,如环境监测,灾难恢复,物流甚至军事行动。尽管群体对社会的重大潜在影响,相对较少的注意力给予对抗的情况下,对群体机器人。在本文中,我们探索了一种系统的方法来找到对手可以利用的群机器人算法的逻辑缺陷。具体来说,我们开发了一个自动测试系统,SWARMFLAWFINDER,群算法。我们识别并克服了理解和推理群算法执行过程中的各种挑战。特别是,我们提出了一种新的机器人行为的抽象,我们称之为因果贡献度(DCC),基于反事实因果关系的想法。然后,我们建立了一个反馈引导灰盒模糊测试系统称为SWARMFLAWFINDER,利用DCC作为反馈度量。我们评估SWARMFLAWFINDER与四个群体算法进行导航,搜索和救援任务。SWARMFLAWFINDER在群算法中发现了42个逻辑缺陷(所有这些缺陷都已被开发人员承认)。我们对缺陷的分析表明,群算法存在严重的逻辑错误/错误,或者存在不完整的实现,可以被对手利用。
Inspired by swarms in nature, swarm robotics have been developed to conduct various challenging tasks such as environmental monitoring, disaster recovery, logistics, and even military operations. Despite the significant potential impact of the swarm on society, relatively little attention is given to adversarial scenarios against swarm robotics. In this paper, we explore a systematic approach to find logical flaws of the swarm robotics algorithms that adversaries can exploit. Specifically, we develop an automated testing system, SWARMFLAWFINDER, for swarm algorithms. We identify and overcome various challenges in understanding and reasoning about the swarm algorithm execution. In particular, we propose a novel abstraction of robotics behavior, which we call the degree of causal contribution (DCC), based on the idea of counterfactual causality. Then, we build a feedback guided greybox fuzz testing system called SWARMFLAWFINDER, leveraging DCC as a feedback metric. We evaluate SWARMFLAWFINDER with four swarm algorithms conducting navigating, searching, and rescuing missions. SWARMFLAWFINDER discovers 42 logic flaws (and all of them have been acknowledged by the developers) in the swarm algorithms. Our analysis of the flaws reveals that the swarm algorithms have critical logic errors/bugs or suffer from incomplete implementations that can be exploited by adversaries.