We study how ambient energy harvesting may be used as an attack vector in the battery-less Internet of Things (IoT). Battery-less IoT devices rely on ambient energy harvesting and are employed in a multitude of applications, including safety-critical ones such as biomedical implants. Due to scarce energy intakes and limited energy buffers, their executions become intermittent, alternating periods of active operation with periods of recharging energy buffers. Through an independent exploratory study and a follow-up systematic analysis, we demonstrate that by exerting limited control on ambient energy one can create situations of livelock, denial of service, and priority inversion, without physical device access. We call these situations energy attacks. Using concepts of approximate intermittent computing and machine learning, we design a technique that can detect energy attacks with 92%+ accuracy, that is, up to 37% better than the baselines, and with up to one fifth of their energy overhead. Crucially, by design, our technique does not cause any additional energy failure compared to the regular intermittent processing. We conclude with directions to inspire defense techniques and a discussion on the feasibility of energy attacks.
翻译:我们研究了环境能量采集如何被用作无电池物联网中的攻击向量。无电池物联网设备依赖环境能量采集,并应用于多种场景,包括生物医学植入物等安全关键型应用。由于能量摄入稀缺且能量缓冲区有限,其执行过程变得间歇性,在有源操作阶段与能量缓冲充电阶段之间交替。通过一项独立的探索性研究和后续的系统性分析,我们证明,在无需物理访问设备的情况下,对环境能量施加有限控制即可引发活锁、拒绝服务及优先级反转等情形。我们将这些情形称为能量攻击。利用近似间歇计算和机器学习的概念,我们设计了一种技术,能够以92%以上的准确率检测能量攻击,相比基线方法性能提升最高达37%,且能量开销仅为基准的五分之一。关键的是,通过设计,该技术相比常规间歇处理不会导致任何额外的能量故障。最后,我们提出了启发防御技术的方向,并讨论了能量攻击的可行性。