Nav: Home

Sonic cyber attack shows security holes in ubiquitous sensors

March 14, 2017

ANN ARBOR -- Sound waves could be used to hack into critical sensors in a broad array of technologies including smartphones, automobiles, medical devices and the Internet of Things, University of Michigan research shows.

The new work calls into question the longstanding computer science tenet that software can automatically trust hardware sensors, which feed autonomous systems with fundamental data they need to make decisions.

The inertial sensors involved in this research are known as capacitive MEMS accelerometers. They measure the rate of change in an object's speed in three dimensions.

It turns out they can be tricked. Led by Kevin Fu, U-M associate professor of computer science and engineering, the team used precisely tuned acoustic tones to deceive 15 different models of accelerometers into registering movement that never occurred. The approach served as a backdoor into the devices--enabling the researchers to control other aspects of the system.

"The fundamental physics of the hardware allowed us to trick sensors into delivering a false reality to the microprocessor," Fu said. "Our findings upend widely held assumptions about the security of the underlying hardware.

"If you look through the lens of computer science, you won't see this security problem. If you look through the lens of materials science, you won't see this security problem. Only when looking through both lenses at the same time can one see these vulnerabilities."

The researchers performed several proof-of-concept demonstrations: They used a $5 speaker to inject thousands of fictitious steps into a Fitbit. They played a malicious music file from a smartphone's own speaker to control the phone's accelerometer trusted by an Android app to pilot a toy remote control car. They used a different malicious music file to cause a Samsung Galaxy S5's accelerometer to spell out the word "WALNUT" in a graph of its readings.

All accelerometers have an analog core--a mass suspended on springs. When the object the accelerometer is embedded in changes speed or direction, the mass moves accordingly. The digital components in the accelerometer process the signal and ferry it to other circuits.

"Analog is the new digital when it comes to cybersecurity," Fu said. "Thousands of everyday devices already contain tiny MEMS accelerometers. Tomorrow's devices will aggressively rely on sensors to make automated decisions with kinetic consequences."

Autonomous systems like package delivery drones and self-driving cars, for example, base their decisions on what their sensors tell them, said Timothy Trippel, a doctoral student in computer science and engineering and first author of a new paper on the findings.

"Humans have sensors, like eyes, ears and a nose. We trust our senses and we use them to make decisions," Trippel said. "If autonomous systems can't trust their senses, then the security and reliability of those systems will fail."

The trick Trippel and Fu introduced exploits the same phenomenon behind the legend of the opera singer breaking a wine glass. Key to that process is hitting the right note--the glass' resonant frequency.

The researchers identified the resonant frequencies of 20 different accelerometers from five different manufacturers. Then instead of shattering the chips, they tricked them into decoding sounds as false sensor readings that they then delivered to the microprocessor.

Trippel noticed additional vulnerabilities in these systems as the analog signal was digitally processed. Digital "low pass filters" that screen out the highest frequencies, as well as amplifiers, haven't been designed with security in mind, he said. In some cases, they inadvertently cleaned up the sound signal in a way that made it easier for the team to control the system.

The researchers recommend ways to adjust hardware design to eliminate the problems. They also developed two low-cost software defenses that could minimize the vulnerabilities, and they've alerted manufacturers to these issues.

The university is pursuing patent protection for the intellectual property and is seeking commercialization partners to help bring the technology to market.
-end-
The researchers will present a paper on the work April 26 in Paris at the IEEE European Symposium on Security and Privacy. The paper is titled "WALNUT: Waging Doubt on the Integrity of MEMS Accelerometers with Acoustic Injection Attacks." The research was supported by the National Science Foundation.

University of Michigan

Related Sound Waves Articles:

Sound waves bypass visual limitations to recognize human activity
Video cameras continue to gain widespread use, but there are privacy and environmental limitations in how well they work.
It's a one-way street for sound waves in this new technology
Imagine being able to hear people whispering in the next room, while the raucous party in your own room is inaudible to the whisperers.
'Meta-mirror' reflects sound waves in any direction
Researchers at Duke University have constructed a 'meta-mirror' device capable of perfectly reflecting sound waves in any direction.
A study by the UC3M researches the limits of topological insulators using sound waves
Research in which the Universidad Carlos III de Madrid (UC3M) is taking part analyses the future of topological insulators using sound waves, meaning materials that behave like acoustic insulators in their interior, but at the same time allow the movement of sound waves at their surface.
KU Leuven researchers use sound waves to prevent small chemical reactors from clogging up
Companies are keen to use miniature chemical reactors to make pharmaceuticals and fine chemicals, but are discouraged by their tendency to clog up.
Revealing hidden information in sound waves
By essentially turning down the pitch of sound waves, University of Michigan engineering researchers have devised a way to unlock greater amounts of data from acoustic fields than ever before.
Stop -- hey, what's that sound?
In a new study, researchers were able to see where in the brain, and how quickly -- in milliseconds -- the brain's neurons transition from processing the sound of speech to processing the language-based words of the speech.
Photonic chips harness sound waves to speed up local networks
Technology to support financial markets, 5G networks and Internet-of-Things
Printing with sound
Harvard University researchers have developed a new printing technology that uses sound waves to control the size of liquid droplets independent of fluid viscosity.
Treating dementia with the healing waves of sound
Ultrasound applied to the brain could help treat patients with dementia.
More Sound Waves News and Sound Waves Current Events

Best Science Podcasts 2019

We have hand picked the best science podcasts for 2019. Sit back and enjoy new science podcasts updated daily from your favorite science news services and scientists.
Now Playing: TED Radio Hour

Rethinking Anger
Anger is universal and complex: it can be quiet, festering, justified, vengeful, and destructive. This hour, TED speakers explore the many sides of anger, why we need it, and who's allowed to feel it. Guests include psychologists Ryan Martin and Russell Kolts, writer Soraya Chemaly, former talk radio host Lisa Fritsch, and business professor Dan Moshavi.
Now Playing: Science for the People

#538 Nobels and Astrophysics
This week we start with this year's physics Nobel Prize awarded to Jim Peebles, Michel Mayor, and Didier Queloz and finish with a discussion of the Nobel Prizes as a way to award and highlight important science. Are they still relevant? When science breakthroughs are built on the backs of hundreds -- and sometimes thousands -- of people's hard work, how do you pick just three to highlight? Join host Rachelle Saunders and astrophysicist, author, and science communicator Ethan Siegel for their chat about astrophysics and Nobel Prizes.