arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33951cs.RO

RAVEN II 中恶意注入的完整性检测与表征

Integrity Detection and Characterization of Malicious Injections in RAVEN II

  • University of Louisiana at Lafayette(路易斯安那大学拉斐特分校)
  • University of Alabama(阿拉巴马大学)

机构由 AI 辅助整理,请以论文原文为准。

Xingli Zhang, Diba Afroze, Fei Hu, Xiali Hei

AI总结:

本文利用公共数据集,在窗口和会话两个时间尺度上表征RAVEN II手术机器人三个注入点、三种注入模式的恶意注入检测边界,量化最小可检测偏差,发现偏差的时间分布强烈影响可检测性,阶跃偏差可在远低于1毫米容差下被检测。

AI中文摘要:

机器人系统在外科手术中的日益普及,加上它们能支持的手术范围不断扩大以及所提供的自主性水平不断提高,已大幅增加了手术机器人的复杂性。随着这些系统集成更多的传感器、控制器、通信接口和模型驱动控制组件,其攻击面也在持续扩大。因此,手术机器人完整性的受损可能导致意外的机器人行为,并可能威胁到患者安全。在本文中,我们利用一个公共数据集来表征RAVEN II上恶意注入的检测边界,该数据集将平台的遥测数据与外部高分辨率编码器真值配对。我们确定了覆盖命令路径和观测路径的三个注入点,并评估了三种时间分散度递增的注入模式。为了捕捉不同的检测行为,我们在两个时间尺度上进行检测:窗口尺度和会话尺度。我们没有在任意选择的阈值下报告检测率,而是针对每个注入点和注入模式,量化了在保持手术操作可接受的报警率的同时,能够分辨的最小末端执行器偏差。我们的结果表明,可检测性受到注入偏差随时间分布方式的强烈影响。一个突然的阶跃可以在远低于1毫米临床容差的偏差下被检测到,而相同的总体偏差分散在一个窗口或会话中,则可能对单窗口统计隐藏。开源代码可在该http URL找到。

英文摘要:

The increasing adoption of robotic systems in surgery, together with the expanding range of procedures they can support and the growing level of autonomy they provide, has substantially increased the complexity of surgical robots. As these systems integrate more sensors, controllers, communication interfaces, and model-driven control components, their attack surface continues to expand. A compromise of the integrity of a surgical robot can therefore cause unintended robot behavior and potentially threaten patient safety. In this paper, we characterize the detection boundary of malicious injections on RAVEN II using a public dataset that pairs the platform's telemetry with external high-resolution encoder ground truth. We identify three injection points spanning the command and observation paths and evaluate three injection patterns with increasing temporal dispersion. To capture different detection behaviors, we perform detection at two timescales: the window scale and the session scale. Rather than reporting detection rates at an arbitrarily chosen threshold, we quantify, for each injection point and injection pattern, the smallest end-effector deviation that can be resolved while maintaining an alarm rate acceptable for surgical operation. Our results show that detectability is strongly influenced by how the injected deviation is distributed over time. An abrupt step can be detected at deviations well below the 1 mm clinical tolerance, whereas the same overall deviation spread across a window or a session can remain hidden from single-window statistics. The open source code can be found at http://github.com/RAVENIIROS/RAVENIIIntegrity.

↑