Predictable by Design, Vulnerable by Nature: Security Consequences of Learnability in UAV State Estimators
arXiv:2407.15003
Abstract
If a mathematical function can be learned from its input/output behavior alone, can an adversary exploit that ``learnability'' to compromise it? What if the function is core to estimating the state of, and controlling, unmanned vehicles such as drones? We investigate this question by targeting state estimators in unmanned aerial vehicles (UAVs) - specifically Extended Kalman Filters (EKFs), an industry standard for autonomous systems, whose inherent modeling of uncertainties and sensor noise create an adversarial space that ML can exploit. We present REQUIEM, a machine-learning based framework for investigating such vulnerabilities. Our framework functions by, (i) constructing deep surrogate models that emulate the state estimation update function using only observed inputs and outputs and (ii) optimizing spoofer models to manipulate sensor values so that they're not easily detectable by standard anomaly detectors - all of which results in physical deviations by the autonomous vehicle. We evaluate REQUIEM's efficacy against both, standard PX4 controllers and the state-of-the-art SAVIOR anomaly detector. Across real-world quadrotor experiments and high-fidelity simulations (Gazebo/PX4), REQUIEM demonstrates significant deviations from planned mission paths while evading anomaly detection methods, without the need for intrusive root/administrative access. Our findings suggest that the very properties making state estimators reliable may constitute a security liability, motivating investigation into ``learnability'' as an attack surface in safety-critical systems.