Integrity Detection and Characterization of Malicious Injections in RAVEN II
Authors: Xingli Zhang, Diba Afroze, Fei Hu, Xiali Hei
Organizations: School of Computing and Informatics University of Louisiana at Lafayette Lafayette, USA · Department of Electrical and Computer Engineering University of Alabama Tuscaloosa, USA
The increasing adoption of robotic systems in surgery, together with the expanding range of procedures they can support and the growing level of autonomy they provide, has substantially increased the complexity of surgical robots. As these systems integrate more sensors, controllers, communication interfaces, and model-driven control components, their attack surface continues to expand. A compromise of the integrity of a surgical robot can therefore cause unintended robot behavior and potentially threaten patient safety. In this paper, we characterize the detection boundary of malicious injections on RAVEN II using a public dataset that pairs the platform's telemetry with external high-resolution encoder ground truth. We identify three injection points spanning the command and observation paths and evaluate three injection patterns with increasing temporal dispersion. To capture different detection behaviors, we perform detection at two timescales: the window scale and the session scale. Rather than reporting detection rates at an arbitrarily chosen threshold, we quantify, for each injection point and injection pattern, the smallest end-effector deviation that can be resolved while maintaining an alarm rate acceptable for surgical operation. Our results show that detectability is strongly influenced by how the injected deviation is distributed over time. An abrupt step can be detected at deviations well below the 1 mm clinical tolerance, whereas the same overall deviation spread across a window or a session can remain hidden from single-window statistics. The open source code can be found at http://github.com/RAVENIIROS/RAVENIIIntegrity.
Figures & tables
Fig. 1: System overview. Surgeon commands flow from the master console to the control PC and on to the RAVEN II; ravenstate return parameter feedback of the robot to the surgeon (Teleoperation mode). Injection point \small1⃝ perturbs the telemetry stream and injection point \small2⃝ perturbs the command stream (under tele-operated operation, on both the console–PC and PC–robot links; under autonomous operation, only on the PC–robot link). The telemetry monitor passively taps the same stream and raises an alarm when a residual exceeds a threshold set by a false-alarm budget.
(A) qd
(B) τ
(C) q^
Arm physically moves
yes
yes
no
Δq∼τ
yes
likely
broken
Torque-to-motion residual
no
likely no
0.81
Servo tracking error
2.85
0.53
1.35
TABLE I: Each feature detects different injection points, with detection floors reported in millimeters of tip deviation. Neither feature covers all three points alone; together, they cover all three.
command stream
observation stream
ratio
step
0.0389
0.0190
2.05×
ramp
none
0.1740
—
noise
none
0.0041
—
TABLE II: Detection floors on the command stream against the observation stream, in degrees of joint deviation. The two streams are strong on disjoint patterns.
step
ramp
noise
Construction
Channels edited
q^ only
q^ only
q^ only
Joints targeted
1
1 or 2
1
Magnitude reported as
∣δT∣
∣δT∣
RMS
Floor at AUC ≥0.9
Joint deviation
0.0190∘
0.1740∘
0.0041∘
TABLE III: The three injection patterns as applied to the observation path, with the floors they reach. All three edit the reported joint positions and leave every other channel as recorded, which is what makes them observation-path attacks and what lets the torque-to-motion residual see them. Under a threshold-free criterion noise has the best floor of the three; under any alarm budget our held-out data can estimate, none of the three has an operating point.