With the rapid proliferation of IoT devices and its growing usage in safety-critical systems, securing these devices from malicious attacks has become increasingly challenging. Due to the resource-constrained nature of IoT devices, real-time software-based malware detection is difficult or infeasible. Alternatively, a promising approach is utilizing hardware malware detection techniques. In this paper, we introduce a novel hardware immune system (HWIS), a stand-alone, hardware-supported malware detection approach for microprocessors that leverages artificial immune systems for detecting botnet activity. This technique is suitable for low-power, resource constrained and network facing embedded devices. The proposed model is capable of detecting botnet behavior with an accuracy of 96.7
Lower urinary tract dysfunction (LUTD) is a debilitating condition that affects millions of individuals worldwide, greatly diminishing their quality of life. The use of wireless, catheter-free implantable devices for long-term ambulatory bladder monitoring, combined with a single-sensor system capable of detecting various bladder events, has the potential to significantly enhance the diagnosis and treatment of LUTD. However, these systems produce large amounts of bladder data that may contain physiological noise in the pressure signals caused by motion artifacts and sudden movements, such as coughing or laughing, potentially leading to false positives during bladder event classification and inaccurate diagnosis/treatment. Integration of activity recognition (AR) can improve classification accuracy, provide context regarding patient activity, and detect motion artifacts by identifying contractions that may result from patient movement. This work investigates the utility of including data from inertial measurement units (IMUs) in the classification pipeline, and considers various digital signal processing (DSP) and machine learning (ML) techniques for optimization and activity classification. In a case study, we analyze simultaneous bladder pressure and IMU data collected from an ambulating female Yucatan minipig. We identified 10 important, yet relatively inexpensive to compute signal features, with which we achieve an average 91.5% activity classification accuracy. Moreover, when classified activities are included in the bladder event analysis pipeline, we observe an improvement in classification accuracy, from 81% to 89.0%. These results suggest that certain IMU features can improve bladder event classification accuracy with low computational overhead.Clinical Relevance: This work establishes that activity recognition may be used in conjunction with single-channel bladder event detection systems to distinguish between contractions and motion artifacts for reducing the incorrect classification of bladder events. This is relevant for emerging sensors that measure intravesical pressure alone or for data analysis of bladder pressure in ambulatory subjects that contain significant abdominal pressure artifacts.
Biosignal monitoring using wearable and implantable devices (WIMDs) is driving the advent of highly personalized medicine. However, such devices may suffer from the same faulty behavior as any electronic system and may furthermore be targeted by malicious actors seeking to do harm. Closed-loop medical control systems, which monitor biosignals for data acquisition, contain and interact with many other components, any of which may be maliciously targeted or suffer a naturally occurring fault. Any measure aiming to improve the security and reliability of these systems must also consider the interplay between each component. In this paper, we explore the vulnerability of closed-loop medical control systems considering both individual system components and the system as a whole and utilize a predictive model based on a nonlinear autoregressive neural network (NARNN) to detect and correct faulty behavior in real time. We present a case study using a human bladder pressure dataset from nine subjects undergoing acute urodynamics testing. Signals are corrupted to simulate faulty sensor readings or malicious attacks and then processed using a custom bladder event detection algorithm designed for use in a closed-loop neuromodulation system. Using the proposed technique, 100 0.022 mm^2 and a total power consumption of 0.31 mW, which is suitable for WIMDs.
Physiological closed-loop control systems (PCLCS) automatically regulate physiological parameters, enabling widespread personalized treatments for diverse diseases. Medical device regulatory agencies such as the US Food and Drug Administration (FDA), have begun providing guidance to PCLCS device manufacturers with respect to designing disturbance and uncertainty scenarios, to conduct comprehensive stress testing under clinically relevant worst-case conditions. Due to their complexity, evaluating PCLCS through animal or clinical studies in all relevant scenarios is impractical. In this work, we discuss the development of a modular hardware emulation platform, which offers an efficient and cost-effective alternative for PCLCS assessment. The platform enables the simulation of any physiological system for which a mathematical model exists; the modular hardware architecture thus enables the emulation of faults, attacks, and the testing of countermeasures in either software, hardware, or cross-layer modality. We also present a case study for an artificial pancreas system (APS) that demonstrates the versatility of the platform in modeling - and countering - two different attack scenarios. Overall, this novel hardware emulation platform is a significant advancement for evaluating PCLCS, efficiently addressing security and reliability challenges in healthcare applications.
Year after year, computing systems continue to grow in complexity at an exponential rate. While this can have farranging positive impacts on society, it has become extremely difficult to ensure the security of these systems in the field. Hardware security - in conjunction with more traditional cybersecurity topics like software and network security - is critical for designing secure systems. Moving forward, hardware security education must ensure the next generation of engineers have the knowledge and tools to address this growing challenge. A good foundation in hardware security draws on concepts from several different fields, including fundamental hardware design principles, signal processing and statistics, and even machine learning for modeling complex physical processes. It can be difficult to convey the material in a manageable way, even to advanced undergraduate students. In this paper, we describe how we have leveraged Python, and its rich ecosystem of open-source libraries, and scaffolding with Jupyter notebooks, to bridge the gap between theory and implementation of hardware security topics, helping students learn through experience.
Energy-efficient hardware acceleration platforms for edge deployment of artificial intelligence (AI) and machine learning (ML) applications has been an ongoing research endeavor. Many efforts have focused on optimizing the algorithms and compute structures for use in resource-constrained hardware such as field-programmable gate arrays (FPGAs). Indeed, the difficult nature of crafting the best model makes the ML model itself a valuable intellectual property (IP) asset. This can be problematic, as the IP can now be exposed to an attacker through physical interfaces, enabling threats from side-channel analysis (SCA) attacks. One of the more devastating attacks is the model extraction attack, which threatens piracy and cloning of the valuable IP. While the problem of SCA-based model extraction on FPGA-deployed neural networks has been well-studied, it does not capture the full picture of what vulnerabilities may be present in those platforms. In this paper, we demonstrate how bitstream analysis can be used to obtain neural network parameters and connectivity information from block RAMs (BRAMs). We leverage the knowledge gleaned from the bitstream to mount a power SCA attack to further refine the network reconstruction effort. This is the first method that has approached the problem of ML-IP theft from the angle of FPGA bitstream analysis and suggests that further work is needed to improve security assurance for edge intelligence.
Hardware security is an emerging field with farranging impacts on the design and implementation of the devices we use in our everyday lives – from wearable and implantable medical devices, to personal mobile devices, and even cloud devices powering the software services that drive our society forward. Practical, hands-on experience is vital to the training of students in this and other security-related fields. We are developing a new model for hardware security education using readily available, cost-efficient, off-the-shelf development boards, with hands-on experiments that offer new learning opportunities for students. Beyond this, we are experimenting with different pedagogical methods to improve student engagement. In particular, we aim to gamify a subset of the experiments and evaluate the impact on student engagement and learning. This work-inprogress paper describes our initial approach to the gamification of hardware security labs and reports on baseline results from our control study using a more traditional, non-gamified approach.
Wearable and Implantable Medical Devices (WIMDs) and Physiological Closed-loop Control Systems (PCLCS) are crucial elements in the advancing field of the Internet of Medical Things (IoMT). Enhancing the safety and reliability of these devices is of utmost importance as they play a significant role in improving the lives of millions of people every year. Medical devices typically have an alert system that can safeguard patients, facilitate rapid emergency response, and be customized to individual patient needs. However, false alarms are a significant challenge to the alert mechanism system, resulting in adverse outcomes such as alarm fatigue, patient distress, treatment disruptions, and increased healthcare costs. Therefore, reducing false alarms in medical devices is crucial to promoting improved patient care. In this study, we investigate the security vulnerabilities posed by WIMDs and PCLCS and the problem of false alarms in closed-loop medical control systems. We propose an implementation-level redundancy technique that can mitigate false alarms in real-time. Our approach, FAMID, utilizes a cloud-based control algorithm implementation capable of accurately detecting and mitigating false alarms. We validate the effectiveness of our proposed approach by conducting experiments on a blood glucose dataset. With our proposed technique, all the false alarms were detected and mitigated so that the device didn’t trigger any false alarms.
Physiological closed-loop control systems (PCLCS) provide reliable and efficient treatment in medical care, but it is crucial to ensure patient safety when examining the potential advantages. Traditional animal and clinical studies are resource-intensive and costly, making them impractical for evaluating PCLCS in every relevant clinical scenario. Therefore, computational or mathematical models have emerged as an alternative for assessing PCLCS. Hardware-in-the-loop testing platforms can provide a more efficient alternative to traditional animal and clinical studies. The platforms utilize computational or mathematical models to simulate PCLCS, providing a cost-effective and efficient approach that can minimize errors during the development process. Although various software simulation platforms can model specific physiological systems, there is a lack of hardware emulation platforms for PCLCS. In this demonstration, we present a novel physiological emulation platform (PEP) using a hardware-in-the-loop method developed to connect a computational model of the patient's physiology to the actual PCLC device hardware, enabling real-time testing of the device while incorporating the hardware components.
Practical, hands-on hardware experience is an essential component of computer engineering education. Due to the COVID-19 pandemic, courses with laboratory components such as Computer Logic Design or FPGA Design were subject to interruption from sudden changes in course modality. While simulators can cover some aspects of laboratory work, they cannot fully replace the hands-on experience students receive working with and debugging hardware. For hardware security in particular, experimenting with attacks and countermeasures on real hardware is vital. In this paper, we describe our approach to designing a practical, hands-on hardware security course that is suitable for HyFlex delivery. We have developed a total of nine experiments utilizing two inexpensive, portable, and self-contained development boards which generally obviate the need for bench equipment. We discuss the trade-offs inherent in the course and experiment design, as well as issues relating to deployment and support for the required design software.
Deep Convolutional Neural Networks (DCNNs) have revolutionized and improved many aspects of modern life. However, these models are increasingly more complex, and training them to perform at desirable levels is difficult undertaking; hence, the trained parameters represent a valuable intellectual property (IP) asset which a motivated attacker may wish to steal. To better protect the IP, we propose a method of lightweight input obfuscation that is undone prior to inference, where input data is obfuscated in order to use the model to specification. Without using the correct key and unlocking sequence, the accuracy of the classifier is reduced to a random guess, thus protecting the input/output interface and mitigating model extraction attacks which rely on such access. We evaluate the system using a VGG-16 network trained on CIFAR-10, and demonstrate that with an incorrect deobfuscation key or sequence, the classification accuracy drops to a random guess, with an inference timing overhead of 4.4% on an Nvidia-based evaluation platform. The system avoids the costs associated with retraining and has no impact on model accuracy for authorized users.
A Body Sensor Network (BSN) is a system made up of low-power sensor nodes that monitor the wearer’s body and surroundings. BSNs have emerged as a prominent technology, largely influenced by the increased health consciousness, widespread availability of wireless-enabled consumer electronics, and growing wireless connectivity infrastructure. In this paper, we present an extensible, cloud-connected BSN platform leveraging lightweight, efficient compression and encryption techniques suitable for edge computing. The platform includes a tunable wavelet-based compression algorithm, suitable for biosignal compression, a lightweight, secure block cipher (SPARX) to encrypt data during transmission, and Amazon Web Services (AWS) connectivity via Message Queuing Telemetry Transport (MQTT). We utilize this platform to evaluate the benefits of compressing sensor data by comparing the delay, power, and energy efficiency on the BSN platform when transmitting encrypted data to the cloud. The tunable compression algorithm efficiently reduces the size of transmitted packets on diverse types of sensor data, with low reconstruction error. When paired with a lightweight block cipher, the combination enables improvements in energy consumption (38%) and energy efficiency (58%) when compared to encryption alone.
Practical, hands-on experience is an essential component of computer science and engineering education, especially in the cybersecurity domain. In this project, we are investigating techniques for improving student learning in such courses, first by developing a new hands-on hardware security course, then by testing the impact of gamification on student learning. The experiments utilize only inexpensive, open-source or freely-available software and hardware, and upon project completion, the modules themselves will also be made freely available online. Improving student learning in this critical area can have a wide-spread positive societal impact as we encourage students to have a security-first, secure-by-design mindset.
Medical devices, such as continuous glucose monitors (CGMs) and drug-delivery pumps, are often combined in closed-loop systems for treating chronic diseases. Generally, these systems consist of sensors and actuators whose operation is modulated based on sensed stimuli. Closed-loop systems may be susceptible to a number of different security and reliability issues which may result in incorrect operation which may endanger patients. Nonlinear autoregressive neural networks (NARNNs) may be used in such systems for error detection and correction due to their predictive capabilities; however, an efficient implementation is needed for use in wearables and biomedical implants. In this paper, we present an area-and energy-efficient, pipelined NARNN hardware architecture suitable for such constrained devices. The architecture was tested on FPGA to confirm functionality, then synthesized targeting the SAED 32nm EDK. This NARNN implementation requires an estimated area of $0.02 mm^{2},0.54\mu s$ and $0.76 nJ$ per inference.
Urodynamics is the current gold-standard for diagnosing lower urinary tract dysfunction, but uses non-physiologically fast, retrograde cystometric filling to obtain a brief snapshot of bladder function. Ambulatory urodynamics allows physicians to evaluate bladder function during natural filling over longer periods of time, but artifacts generated from patient movement necessitate the use of an abdominal pressure sensor, which makes long-term monitoring and feedback for closed-loop treatment impractical. In this paper, we analyze the characteristics of single-channel bladder pressure signals from human and feline datasets, and present an algorithm designed to estimate detrusor pressure, which is useful for diagnosis and treatment. We utilize multiresolution analysis techniques to maximize the attenuation of probable abdominal pressure components in the vesical pressure signal. Results indicate a strong correlation, averaging 0.895 ± 0.121 (N = 40) and 0.812 ± 0.113 (N = 16) between the estimated detrusor pressure obtained by the proposed method and recorded urodynamic data from human and feline subjects, respectively. Clinical Relevance— This work establishes that signal pro-cessing techniques may be applied to vesical pressure alone to accurately reconstruct pressures generated independently by the detrusor muscle. This is relevant for emerging sensors that measure vesical pressure alone or for data analysis of bladder pressure in ambulatory subjects which contains significant abdominal pressure artifacts
Malware is a major threat to present-day computing systems. With the rapid growth of Internet of Things (IoT) devices and their usage in safety critical systems, security has become increasingly important. Securing IoT devices is a challenge for designers, as they are generally resource constrained, which makes real-time software-based malware detection difficult or infeasible. A promising alternative approach is to utilize intrinsic hardware-based malware detectors to alleviate power and performance overheads. In this brief, we introduce a novel Hardware Immune System (HWIS), a stand-alone, hardware-supported malware detection approach for microprocessors that leverages Artificial Immune Systems for detecting botnet activity. This technique is intended for low-power, resource constrained and network facing embedded devices. The proposed model is capable of detecting botnet behavior with an accuracy of 96.7% and F1-score of 0.96. The technique is implemented in hardware and verified using Spartan-7 FPGA. Our technique achieves power, LUTs, FFs, DSPs, and BRAMs utilization overheads of 0.6%, 8.5%, 11.8%, 0%, and 0%, respectively, with no impact on delay using the RISC-V CPU as a baseline.
Implantable and wearable medical devices (IWMDs) provide a wide range of benefits, including monitoring various physiological conditions and providing patients real-time treatment and emergency support. The latest generation of IWMDs incorporates greater communication and computation capabilities, enabling personalized healthcare. Security and reliability of these devices is therefore paramount. In this paper, we discuss potential vulnerabilities and attacks on IWMDs, including attacks which may interfere with the availability and correctness of integrated sensors. We propose effective countermeasures that can improve devices’ resilience towards these attacks. We utilize a set of statistical and machine learning (ML) models as virtual biosensors, which serve to both detect and correct anomalous biosensor measurement errors in real-time. Experiments with a blood glucose dataset demonstrate that the virtual biosensors can not only detect anomalous measurements, but also fix measurement errors or even DoS-style attacks, which impact the availability of the sensor.
With the rapid growth of the Internet of Things (IoT) and increasing reliance on network-connected devices, IoT security, which integrates components of hardware and cybersecurity, is more important than ever. Hence, we must improve and expand training opportunities for students in IoT security. Experiential learning is an essential component of education for engineering and cybersecurity in particular. In this work, we describe three comprehensive hands-on IoT security experiments built using off-the-shelf development boards which can provide a low-cost and accessible experiential learning opportunity for students in this area.
Adversarial machine learning is a prominent research area aimed towards exposing and mitigating security vulnerabilities in AI/ML algorithms and their implementations. Data poisoning and neural Trojans enable an attacker to drastically change the behavior and performance of a Convolutional Neural Network (CNN) merely by altering some of the input data during training. Such attacks can be catastrophic in the field, e.g. for self-driving vehicles. In this paper, we propose deploying a CNN as an ecosystem of variants , rather than a singular model. The ecosystem is derived from the original trained model, and though every derived model is structurally different, they are all functionally equivalent to the original and each other. We propose two complementary techniques: stochastic parameter mutation , where the weights θ of the original are shifted by a small, random amount, and a delta-update procedure which functions by XOR’ing all of the parameters with an update file containing the Δ θ values. This technique is effective against transferability of a neural Trojan to the greater ecosystem by amplifying the Trojan’s malicious impact to easily detectable levels; thus, deploying a model as an ecosystem can render the ecosystem more resilient against a neural Trojan attack.
Wearable and implantable biomedical devices are becoming increasingly commonplace in the assessment and treatment of chronic disease. Meanwhile, improvements in machine learning (ML) and artificial intelligence (AI), especially in the healthcare domain, are leading to widespread use in automated analysis of physiological data and subsequent identification and eventual treatment of underlying pathophysiologies. On-chip ML/AI for the purpose of real-time analysis of biosignals has many benefits, including faster response times for treatment applications, lower power consumption, and mitigation of privacy concerns. However, realizing these complex algorithms on-chip requires careful design space exploration and analysis to ensure accuracy and minimize area and power for ultra-constrained devices. In this paper, we present an automated framework for design space exploration of AI hardware for biomedical applications. We focus on the implementation of a nonlinear autoregressive neural network (NARNN) suitable for on-chip time series prediction, such as prediction of blood glucose levels, and discuss and analyze the trade-offs. Using this framework, we found the optimal NARNN implementation for this application to be with parameters quantized to Q10.8 fixed-point notation.
Srinivas Katkoori合作论文数Department of Computer Science and Engineering, College of Engineering, University of South Florida8