HoLA Robots: Mitigating Plan-Deviation Attacks in Multi-Robot Systems with Co-Observations and Horizon-Limiting Announcements

HoLA Robots: Mitigating Plan-Deviation Attacks in Multi-Robot Systems with Co-Observations and Horizon-Limiting Announcements
复制标题

DOI:
10.48550/arxiv.2301.10704
复制
发表时间:
2023-01
期刊:
--
影响因子:
--
通讯作者:
Kacper Wardega;Max von Hippel;Roberto Tron;C. Nita-Rotaru;Wenchao Li
Kacper Wardega;Max von Hippel;Roberto Tron;C. Nita-Rotaru;Wenchao Li
中科院分区:
其他
文献类型:
--
作者:
Kacper Wardega;Max von Hippel;Roberto Tron;C. Nita-Rotaru;Wenchao Li

文献摘要

被引文献

相似文献

新兴的多机器人系统依赖于人类和机器人之间的合作,机器人遵循自动生成的运动计划来服务应用级任务。考虑到与接近人类和昂贵的基础设施相关的安全要求,重要的是要了解和减轻这些系统的安全漏洞,这些漏洞是由偏离其指定计划的受损机器人造成的。我们专注于集中式系统,其中 * 中央实体 *(CE)负责确定并将运动计划传输给机器人,机器人在按照计划移动时报告其位置。CE通过比较机器人的预期位置和它们自我报告的位置来检查机器人是否遵循分配的计划。我们表明,这种自我报告的监控机制容易受到 * 计划偏差攻击 *,其中受损的机器人不遵循其指定的计划,同时试图通过误报其位置来隐藏其运动。我们提出了一个双管齐下的缓解计划偏差攻击:(1)攻击检测技术,利用机器人的本地传感能力,报告其他机器人的观察和CE生成的 * 共同观察时间表 *,以及(2)预防技术,CE向机器人发出 * 地平线限制公告 *,减少他们对全局运动计划中的前向前瞻步骤的瞬时知识。在一个大规模的自动化仓库基准测试中,我们证明了我们的解决方案能够保证攻击预防来自一个已经损害了多个机器人的隐形攻击者。
Emerging multi-robot systems rely on cooperation between humans and robots, with robots following automatically generated motion plans to service application-level tasks. Given the safety requirements associated with operating in proximity to humans and expensive infrastructure, it is important to understand and mitigate the security vulnerabilities of such systems caused by compromised robots who diverge from their assigned plans. We focus on centralized systems, where a *central entity* (CE) is responsible for determining and transmitting the motion plans to the robots, which report their location as they move following the plan. The CE checks that robots follow their assigned plans by comparing their expected location to the location they self-report. We show that this self-reporting monitoring mechanism is vulnerable to *plan-deviation attacks* where compromised robots don't follow their assigned plans while trying to conceal their movement by mis-reporting their location. We propose a two-pronged mitigation for plan-deviation attacks: (1) an attack detection technique leveraging both the robots' local sensing capabilities to report observations of other robots and *co-observation schedules* generated by the CE, and (2) a prevention technique where the CE issues *horizon-limiting announcements* to the robots, reducing their instantaneous knowledge of forward lookahead steps in the global motion plan. On a large-scale automated warehouse benchmark, we show that our solution enables attack prevention guarantees from a stealthy attacker that has compromised multiple robots.