Search papers, labs, and topics across Lattice.
Physical electromagnetic signal injection attacks (ESIA) can silently corrupt image sensor data to induce unsafe downstream vision model predictions, yet defending against them typically requires prohibitive hardware redesigns. The authors address this by monitoring anomalous signals within "optically black pixels"鈥攕hielded, non-exposed pixels already integrated into commodity image sensors for thermal calibration. This lightweight detection strategy achieves an ROC-AUC of up to 99.6% and an Equal Error Rate down to 0.027 across diverse injection conditions with negligible computational overhead.
Existing, unexposed calibration pixels in commodity camera sensors can double as physical intrusion detectors against electromagnetic adversarial attacks, flagging signal injection with up to 99.6% ROC-AUC without hardware modifications.
Electromagnetic signal injection attacks (ESIA) pose a growing threat to image sensors, which are increasingly used in different intelligent systems. By emitting electromagnetic interference, adversaries can manipulate pixel values, potentially misleading downstream artificial intelligence (AI) models and causing unsafe decisions in these systems. We present a lightweight detection method that leverages optically black pixels, which are non-exposed pixels already present in many modern image sensors, to identify the attacks. Our detection approach achieves an area under the receiver operating characteristic curve (ROC-AUC) of up to 99.6\% and an Equal Error Rate (EER) as low as 0.027 across diverse attack conditions. Our method requires minimal computational overhead and no hardware modifications, making it a practical and effective defense for securing vision-based systems against ESIA.