Chameleon: Recovering Cyber-Physical Systems from Memory Corruption Attacks via ML Surrogates
cs.CR, cs.SY, eess.SY
Submitted: 2026-07-01
Updated: 2026-09-17
Code: https://github.com/PX4/PX4-Autopilot
License: http://creativecommons.org/licenses/by/4.0/
The gist: Cyber-physical systems (CPSs) can be compromised through memory corruption vulnerabilities, which can result in safety violations.
Terminology
Abstract
Cyber-physical systems (CPSs) can be compromised through memory corruption vulnerabilities, which can result in safety violations. Existing techniques mostly focus on detecting such attacks but respond by terminating or halting execution upon attack detection, which is not acceptable in CPSs as interrupted tasks can have catastrophic consequences. Other techniques replace compromised CPS components with simplified defaults that degrade system behavior, or reboot the system upon attack detection, which are not suitable for CPS deployed in safety-critical domains. We propose Chameleon, a novel framework for automatically recovering CPSs from memory corruption attacks using machine learning (ML)-based surrogates trained at compartment granularity that nearly replicate their original compartments' behavior but are implemented differently, and hence are unlikely to have the same memory corruption vulnerabilities. Upon attack detection, Chameleon replaces the compromised compartment with its trained ML surrogate. We implemented Chameleon using the LLVM compiler, and evaluated its efficiency and effectiveness on seven different robotic vehicles (RVs), including simulated and real ones. We found that Chameleon can generate surrogates that closely approximate the original compartments (with an average R squared =0.96), successfully recover the system despite real-world memory corruption attacks and complete their tasks while incurring low performance and memory overheads on real RVs.
Sources
- Precise Payload Delivery via Unmanned Aerial Vehicles: An Approach Using Object Detection Algorithms
- Concrete Problems in AI Safety
- RVDebloater: Mode-based Adaptive Firmware Debloating for Robotic Vehicles
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs