arXiv ScienceSearch

arXiv · 2404.05946

Differential fuzz testing to detect tampering in sensor systems and its application to arms control authentication

Abstract

In future nuclear arms control treaties, it will be necessary to authenticate the hardware and software components of verification measurement systems, i.e., to ensure these systems are functioning as intended and have not been tampered with by malicious actors. While methods such as source code hashing and static analysis can help verify the integrity of software components, they may not be capable of detecting tampering with environment variables, external libraries, or the firmware and hardware of radiation measurement systems. In this article, we introduce the concept of physical differential fuzz testing as a challenge-response-style tamper indicator that can holistically and simultaneously test all the above components in a cyber-physical system. In essence, we randomly sample (or "fuzz") the untampered system's parameter space, including both normal and off-normal parameter values, and consider the time series of outputs as the baseline signature of the system. Re-running the same input sequence on a untampered system will produce an output sequence consistent with this baseline, while running the same input sequence on a tampered system will produce a modified output sequence and raise an alarm. We then apply this concept to authenticating the radiation measurement equipment in nuclear weapon verification systems and conduct demonstration fuzz testing measurements with a sodium iodide (NaI) gamma ray spectrometer. Because there is Poisson noise in the measured output spectra, we also use a mechanism for comparing inherently noisy or stochastic fuzzing sequences. We show that physical differential fuzz testing can detect two types of tamper attempts, and conclude that it is a promising framework for authenticating future cyber-physical systems in nuclear arms control, safeguards, and beyond.

Explore related subjects

Keep this discovery

BibTeXRIS

Jayson R Vavrek, Luozhong Zhou, Joshua Boverhof, Elisa R Heymann, Barton P Miller, Sean Peisert. 2024-04-09. Differential fuzz testing to detect tampering in sensor systems and its application to arms control authentication. https://doi.org/10.1080/08929882.2025.2599015

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

High-Speed Semi-FE Readout Module for ATLAS MDT at HL-LHC: Design and Production-Level Characterization

The High-Luminosity upgrade of the Large Hadron Collider (HL-LHC) introduces increased demands on the ATLAS Muon Spectrometer, particularly in terms of data throughput, timing distribution and system reliability. The Phase-II Chamber Service Module (CSM) is a key component of the upgraded Monitored Drift Tube (MDT) trigger and readout system, providing a high-speed interface between the front-end electronics and the backend systems. This paper describes the design and implementation of the Phase-II CSM, together with its validation. The results show that the CSM supports two independent optical uplinks, each operating at a line rate of 10.24 Gbps, together with clock distribution and slow control in the expected operating environment. Integration with small-diameter MDT (sMDT) chambers and tests with the prototype L0MDT trigger system are also presented. The CSM boards are now in production and will be used for installation and integration during the upcoming LHC Long Shutdown.

physics.ins-det

Spectral Discrimination of Deposited Gamma-Ray Energies in a Simulated CeBr$_3$ Scintillator

We show that wavelength measurements of individual detected optical photons may provide additional information about gamma-ray energy deposited in a CeBr$_3$ crystal when the detected-photon-count distributions overlap for nearby gamma-ray energies. Monoenergetic 662 and 629 keV gammas are used in a Geant4 simulation of a $25\times25\times20~\mathrm{mm^3}$ CeBr$_3$ crystal. Assuming a light yield of $6.0\times10^4$ photons/MeV, a wavelength-independent photon-detection efficiency of 30%, and a wavelength resolution of $\sigma_{\lambda}=40$ nm, we find that the fraction of photons reconstructed above 385 nm gives an event-level separation of $\sim$ 2 standard deviations between the 662 and 629 keV event populations selected within the same $\sim$ 1%-wide detected-photon-count interval. No timing or reconstructed interaction-position information is used. The result demonstrates, within the present simulation model, that event-dependent optical spectra can retain energy information beyond an undifferentiated photon count.

physics.ins-det

Operation of a negative ion gas time projection chamber without electronegative fill gases

The high fidelity reconstruction of particle tracks in micropatterned gaseous time projection chambers renders this technology ideal for future rare-event searches, including direction-sensitive dark matter experiments. Large drift distances are typically required for such experiments, so that the overall spatial resolution is limited by diffusion. Negative ion drift exhibits lower diffusion than electron drift and is thus an attractive option for realising a large-scale detector. The use of electronegative gases to create negative ions introduces technical challenges, most notably a reduction in gain when compared to conventional gas mixtures. In this study, we demonstrate a new method for negative ion generation via dissociative electron attachment using the conventional molecular fill gas CF$_4$. Our optical measurements of negative ion drift indicate electron attachment lengths of $<$1 mm and comparable gain to electron avalanches. The individual negative ion avalanches were also time-resolved, allowing the number of ions reaching the readout to be counted. We measure an improved energy resolution by single ion counting, relative to an integrated electron avalanche signal measured under identical gain conditions.

physics.ins-det