Integrity Detection and Characterization of Malicious Injections in RAVEN II
Authors: Xingli Zhang, Diba Afroze, Fei Hu, Xiali Hei
Organizations: School of Computing and Informatics University of Louisiana at Lafayette Lafayette, USA · Department of Electrical and Computer Engineering University of Alabama Tuscaloosa, USA
The increasing adoption of robotic systems in surgery, together with the expanding range of procedures they can support and the growing level of autonomy they provide, has substantially increased the complexity of surgical robots. As these systems integrate more sensors, controllers, communication interfaces, and model-driven control components, their attack surface continues to expand. A compromise of the integrity of a surgical robot can therefore cause unintended robot behavior and potentially threaten patient safety. In this paper, we characterize the detection boundary of malicious injections on RAVEN II using a public dataset that pairs the platform's telemetry with external high-resolution encoder ground truth. We identify three injection points spanning the command and observation paths and evaluate three injection patterns with increasing temporal dispersion. To capture different detection behaviors, we perform detection at two timescales: the window scale and the session scale. Rather than reporting detection rates at an arbitrarily chosen threshold, we quantify, for each injection point and injection pattern, the smallest end-effector deviation that can be resolved while maintaining an alarm rate acceptable for surgical operation. Our results show that detectability is strongly influenced by how the injected deviation is distributed over time. An abrupt step can be detected at deviations well below the 1 mm clinical tolerance, whereas the same overall deviation spread across a window or a session can remain hidden from single-window statistics. The open source code can be found at http://github.com/RAVENIIROS/RAVENIIIntegrity.
Figures & tables
Fig. 1: System overview. Surgeon commands flow from the master console to the control PC and on to the RAVEN II; ravenstate return parameter feedback of the robot to the surgeon (Teleoperation mode). Injection point \small1⃝ perturbs the telemetry stream and injection point \small2⃝ perturbs the command stream (under tele-operated operation, on both the console–PC and PC–robot links; under autonomous operation, only on the PC–robot link). The telemetry monitor passively taps the same stream and raises an alarm when a residual exceeds a threshold set by a false-alarm budget.
(A) qd
(B) τ
(C) q^
Arm physically moves
yes
yes
no
Δq∼τ
yes
likely
broken
Torque-to-motion residual
no
likely no
0.81
Servo tracking error
2.85
0.53
1.35
TABLE I: Each feature detects different injection points, with detection floors reported in millimeters of tip deviation. Neither feature covers all three points alone; together, they cover all three.
command stream
observation stream
ratio
step
0.0389
0.0190
2.05×
ramp
none
0.1740
—
noise
none
0.0041
—
TABLE II: Detection floors on the command stream against the observation stream, in degrees of joint deviation. The two streams are strong on disjoint patterns.
step
ramp
noise
Construction
Channels edited
q^ only
q^ only
q^ only
Joints targeted
1
1 or 2
1
Magnitude reported as
∣δT∣
∣δT∣
RMS
Floor at AUC ≥0.9
Joint deviation
0.0190∘
0.1740∘
0.0041∘
TABLE III: The three injection patterns as applied to the observation path, with the floors they reach. All three edit the reported joint positions and leave every other channel as recorded, which is what makes them observation-path attacks and what lets the torque-to-motion residual see them. Under a threshold-free criterion noise has the best floor of the three; under any alarm budget our held-out data can estimate, none of the three has an operating point.
In multi-robot collaboration, task handovers rely on downstream verifiers performing remote attestation, which inspects sensor telemetry to ensure a robot's physical behavior strictly matches its assigned task. But can this telemetry be trusted? We show that it often cannot. In this paper, we uncover a severe vulnerability in Robot Operating System (ROS) 2: by modifying a single environment variable, an adversary can execute a pre-built hook to covertly intercept and inject both telemetry and control signals before they are published. Consequently, adversaries can hijack a robot to perform dangerous tasks while spoofing downstream verifiers with synthesized fake telemetry. Worse still, by exploiting the widespread reliance on third-party Docker containers and auxiliary tools, attackers can distribute compromised packages embedded with these malicious hooks to launch such attacks easily. On a physical Franka Emika robotic arm running Secure ROS 2, our attack injects fabricated telemetry in real time with only around 3 ms of jitter, preserving temporal synchronization and hardware integrity while achieving an 87% success rate even against an AI-based detector. We have responsibly disclosed these findings to the ROS 2 development team. We prepared a demo video available at https://youtu.be/ExeiGqUrnhQ.
Leming Shen, Shikai Geng, Yuanqing Zheng +1
University College London · The Hong Kong Polytechnic University
While not yet in clinical deployment, learning-based policies are increasingly considered to augment the dexterity of human surgeons in robot-assisted surgery. Can the end-to-end mapping from visual observations to robot actions be vulnerable to adversarial attacks? We present the first study of adversarial vulnerabilities in learning-based policies for surgical robotics, conducted in a laboratory white-box setting where the attacker is assumed to have access to policy information and injects perturbations into the video stream transmitted over the network. Two attack modes are considered: (a) disruptive attacks, where subtle visual perturbations interrupt policy execution without being noticed by a surgeon, and (b) steering attacks, where perturbations steer policy actions toward attacker-specified directions. We study three adversarial attack methods, each with increasing access to policy information, and evaluate their impact on two surgical subtasks: debridement and suturing, performed on phantoms. Our evaluation covers three end-to-end policy architectures: ACT, Diffusion Policy, and pi0. In addition, we identify a vulnerability to photometric perturbations, which mimic natural visual changes such as lighting variation. Results from 620 physical experiments suggest that state-of-the-art policies can be significantly disrupted, resulting in an average 61% reduction in surgical subtask success rates. These findings suggest that adversarial vulnerabilities are important to consider for learned telesurgery policies. Project page: https://surgical-robotics.github.io/adversarial-vulnerability/
Shutong Jin, Ziyang Chen, Preethi Satish +3
University of California, Berkeley · KTH Royal Institute of Technology
Imitation learning has shown increasing promise for autonomous robotic surgery, yet safe deployment remains challenging due to the safety-critical nature of surgical tasks and the complexity and variability of surgical environments. Failure detection is therefore an essential safeguard, but its development remains difficult due to the challenges of scarce failure data, highly variable manipulation dynamics, and the need to balance missed detections against disruptive false alarms. To address these challenges, we introduce FoMo-FD (Flow-Matching World Model for Failure Detection), a failure detection method that learns nominal short-horizon visual dynamics with an action-conditioned flow-matching world model. FoMo-FD scores the inverse-transport nonconformity of observed endpoint latents, enabling window-level detection of visual-action inconsistencies without requiring failure demonstrations. Detection thresholds are obtained by conformal calibration on successful executions, yielding task-specific alarms without assuming future failure types. We evaluate FoMo-FD on four surgically relevant manipulation tasks with twenty failure modes across simulation and real-world experiments using the da Vinci Research Kit (dVRK). Results show that FoMo-FD outperforms observation-level anomaly baselines and a prediction-error variant of the same world model, with the wrist-camera view achieving the strongest performance, including a 96.6% failure detection rate (FDR) at a 1.3% false alarm rate (FAR).