One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices

Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli, Ahmad-Reza Sadeghi

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 5

Overview

This talk introduces RAGE, a novel approach to control-flow attestation (CFA) for embedded devices that leverages Graph Neural Networks (GNNs) to detect code reuse attacks like Return-Oriented Programming (ROP) and Data-Oriented Programming (DOP). Presented by Marco Chilese and his colleagues from the Technical University of Darmstadt, Nvidia, and the University of Southampton, this work addresses the escalating security challenges posed by the proliferation of IoT devices and the increasing sophistication of remote code execution vulnerabilities. Traditional CFA schemes often suffer from limitations such as requiring complete control-flow graphs, risking information leakage, or necessitating custom hardware, making them unsuitable for resource-constrained, off-the-shelf embedded systems.

Watch on YouTube

Visual summary for One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices by Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli, Ahmad-Reza Sadeghi
Visual summary for One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices by Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli, Ahmad-Reza Sadeghi

Key moments

  1. 0:00 Introduction: Need for Control Flow Attestation
  2. 0:40 Understanding Control Flow Attestation (CFA) basics
  3. 2:00 Detailed explanation of Code Reuse Attacks (ROP, DOP)
  4. 3:20 Limitations of existing Control Flow Attestation schemes
  5. 4:15 Leveraging Machine Learning (GNNs) for CFA
  6. 5:40 Key advantages and features of the RAGE approach
  7. 8:50 RAGE system overview: training and attestation

One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices

Speakers: Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli, Ahmad-Reza Sadeghi

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=sRs87WeS9Pk

Overview

This talk introduces RAGE, a novel approach to control-flow attestation (CFA) for embedded devices that leverages Graph Neural Networks (GNNs) to detect code reuse attacks like Return-Oriented Programming (ROP) and Data-Oriented Programming (DOP). Presented by Marco Chilese and his colleagues from the Technical University of Darmstadt, Nvidia, and the University of Southampton, this work addresses the escalating security challenges posed by the proliferation of IoT devices and the increasing sophistication of remote code execution vulnerabilities. Traditional CFA schemes often suffer from limitations such as requiring complete control-flow graphs, risking information leakage, or necessitating custom hardware, making them unsuitable for resource-constrained, off-the-shelf embedded systems.

The core innovation of RAGE lies in its ability to relax these restrictive assumptions by employing unsupervised GNNs to learn benign execution patterns directly from basic block addresses (program counter values). This method avoids the need for a complete reference control-flow graph and prevents sensitive data leakage, as only program counter values are transmitted. The research demonstrates that RAGE is platform-agnostic, requires no custom hardware or data labeling, and is remarkably lightweight, capable of running on devices as modest as a Raspberry Pi. Its proven efficacy in precisely detecting both real-world and simulated stealthy ROP and DOP attacks underscores its potential to significantly enhance the security posture of vulnerable embedded systems.

Background

▶ Watch: Introduction: Need for Control Flow Attestation (0:00)

The landscape of cybersecurity has seen a dramatic increase in remote code execution (RCE) vulnerabilities alongside an exponential growth in the deployment of Internet of Things (IoT) devices. This confluence creates a critical exposure point for code reuse attacks in low-security IoT environments. Control-Flow Attestation (CFA) emerges as a vital security primitive designed to verify the integrity of a device's execution flow. In its most generic form, CFA involves three parties: a verifier, a prover (the device being attested), and a third party. The verifier challenges the prover to provide evidence of its execution state. The prover collects this evidence, which the verifier then assesses against a known benign state, ultimately disseminating a signed report to the third party confirming the prover's integrity.

Code reuse attacks represent a significant threat to software integrity. A control-flow graph (CFG) visually depicts the possible execution paths of a program, with nodes representing basic blocks and edges representing transitions. A benign execution might follow a path from V1 to V7, as illustrated by the green or violet paths in a typical CFG. Return-Oriented Programming (ROP) attacks manipulate the program's control flow by chaining together small, legitimate code snippets (called "gadgets") to achieve malicious functionality. This is depicted as adding extra, illegitimate transitions to the CFG, for example, jumping from V6 to V3 on a path that would normally go V1-V7. While the start and end points might appear legitimate, the intermediate path is altered. In contrast, Data-Oriented Programming (DOP) attacks are more insidious; they reuse existing benign transitions within the CFG but still alter the program's control flow by manipulating data values, leading to malicious outcomes without introducing new edges. An example might be an execution path V1-V4-V7, where V1-V4 is reused from a green benign path, and V4-V7 from a violet benign path, but the combination leads to an unintended malicious state.

Existing CFA schemes typically fall into three categories, each with inherent limitations. Some rely on a complete control-flow graph as a reference, which is a strong assumption, often impossible to generate for complex or dynamically loaded software. Others depend on accessing memory content for evidence collection, posing a risk of information leakage during evidence gathering or transmission to the verifier. Finally, schemes relying on custom hardware are expensive to design and are not applicable to the vast majority of off-the-shelf embedded devices. These limitations prompted the central research question addressed by this work: can these strong assumptions be relaxed by leveraging machine learning techniques, specifically Graph Neural Networks?

Key Findings

▶ Watch: Detailed explanation of Code Reuse Attacks (ROP, DOP) (2:00)

The core contribution of this work is the development of RAGE, a novel GNN-based control-flow attestation approach that overcomes the fundamental limitations of prior CFA schemes. The key findings and design principles underpinning RAGE are:

  1. Relaxed Assumptions via Unsupervised GNNs: RAGE does not rely on a complete control-flow graph as a reference. Instead, it uses an unsupervised Graph Neural Network (specifically, a Variational Graph Autoencoder, VGAE) to learn the inherent execution patterns of benign software. This model is shown to effectively distinguish between benign and malicious executions based on these learned patterns.
  2. Information Leakage Prevention: To avoid information leakage, RAGE collects only basic block addresses (program counter values) as evidence. These program counter values are processed into an execution graph and then into embeddings, preventing the exposure of sensitive memory content to the verifier or during transit.
  3. Platform Agnostic and Hardware Independent: RAGE is designed to be platform-agnostic, capable of running on any platform equipped with a Trusted Execution Environment (TE). Crucially, it requires no custom hardware, making it applicable to a wide range of existing off-the-shelf embedded devices.
  4. No Data Labeling Required: The unsupervised nature of the GNN model eliminates the need for manual data labeling, significantly simplifying the training process and reducing human effort.
  5. Lightweight and Efficient: The RAGE model is exceptionally lightweight, comprising less than 9,000 parameters. This minimal footprint allows it to be efficiently deployed and run even on resource-constrained devices like a Raspberry Pi, demonstrating its practicality for edge computing.
  6. Precise Detection of Code Reuse Attacks: RAGE is capable of precisely detecting both Return-Oriented Programming (ROP) and Data-Oriented Programming (DOP) attacks. This includes the successful identification of real-world attacks that the model had never encountered during training, showcasing its generalization capabilities. The system achieved F1 scores in the high 90s for both simulated ROP and DOP attacks, indicating robust detection performance.

Technical Deep Dive

▶ Watch: Limitations of existing Control Flow Attestation schemes (3:20)

RAGE's technical foundation rests upon the intelligent application of Graph Neural Networks (GNNs) to model and attest program control flow. The central idea is to transform an execution trace into a graph representation, extract features, and then use a GNN to learn an embedding that captures the "normal" control flow behavior.

The choice of GNN model for RAGE is a Variational Graph Autoencoder (VGAE). VGAEs are state-of-the-art generative models adept at learning to reconstruct input graphs into output graphs, effectively capturing the underlying structural and behavioral properties. The researchers designed a custom encoder for their VGAE, specifically tailored to extract rich latent features pertinent to control-flow analysis. This customized VGAE is instrumental in capturing the intricacies of control-flow graph behavior within its output embeddings.

The encoder design is a critical component, consisting of four graph convolutional layers. These layers vary in dimensionality, specifically from 15 to 48. This variation is a deliberate design choice: the dimensionality is initially increased to expand and enrich the features extracted during the feature engineering phase, and then slightly reduced in later layers to discard noisy or less relevant features, optimizing the trade-off between model complexity and performance. Dropout layers are strategically interleaved between the convolutional layers to regularize training and prevent overfitting. The overall architecture was chosen after a careful model selection process, balancing the need for expressive embeddings with computational efficiency.

The attestation process in RAGE begins with evidence collection. The prover collects basic block addresses (program counter values) of the executed software. This is a crucial design decision as it avoids information leakage; only these addresses, rather than sensitive memory contents, are transmitted. These raw program counter values are then processed into an execution graph. During this preprocessing step, features are extracted from the graph's nodes and edges. The transcript emphasizes that no assumptions are made about the completeness of this graph, as it's derived directly from a single execution trace.

The system operates in two main phases: training and attestation.

Training Phase:

  1. Trace Collection: The software intended for attestation is executed, and its execution trace (sequence of basic block addresses) is collected.
  2. Preprocessing: This trace is then pre-processed into a graph representation, and relevant features are extracted for each node and edge.
  3. Model Training: This graph serves as input to the custom VGAE model. The model is trained to learn the benign execution patterns, effectively encoding the control flow behavior into a set of embeddings.
  4. Threshold Tuning: After training, the model's embeddings are used to calculate distances between benign executions. An attestation threshold is then tuned on a validation set. This threshold defines the boundary beyond which an execution is considered malicious.

Attestation Phase:

  1. Trace Collection: When an execution needs to be attested, the software is traced again, collecting its basic block addresses.
  2. Preprocessing: This new trace is pre-processed into an execution graph, similar to the training phase.
  3. Embedding Extraction: The pre-processed graph is fed into the trained VGAE encoder, which extracts its corresponding embeddings.
  4. Distance Computation: The system computes the distance between these newly extracted embeddings and the previously learned benign training embeddings.
  5. Malicious Detection: This computed distance is then compared against the pre-tuned attestation threshold. If the distance exceeds the threshold, the system discerns the execution as malicious; otherwise, it is deemed benign.

A key intuition highlighted by the speakers is the maintenance of a one-to-one correlation between elements from the execution trace, over the execution graph, and into the final execution embeddings. This ensures that the learned embeddings faithfully represent the control flow of the original execution.

Demo / Proof of Concept

▶ Watch: Key advantages and features of the RAGE approach (5:40)

The efficacy of RAGE was rigorously evaluated through both real-world and simulated attack scenarios, demonstrating its robust capabilities across various embedded platforms.

For real-world evaluation, the researchers extended the well-known RIPE framework, a collection of code reuse attacks. The extensions included a gadget length configuration option to test different ROP chain lengths and the integration of benign application logic to collect traces from additional software, specifically from the Mbed IoT dataset. The evaluation was conducted on diverse hardware targets: a BeagleBone Black, a Xilinx UltraScale+, and an Nvidia Jetson device, showcasing RAGE's platform independence. The results for RIPE framework attacks were striking: RAGE consistently and correctly separated benign and malicious traces, often with a "great distance" in the embedding space. The reason for this significant separation is that RIPE framework attacks are generally not stealthy; they typically terminate the benign application and result in a shell, making their deviation from benign control flow quite pronounced.

To assess RAGE's ability to detect more sophisticated, stealthy code reuse attacks, the team developed an algorithm to simulate such attacks. This algorithm injected malicious ROP and DOP sequences into benign traces. Crucially, these simulated attacks were designed to ensure that the control flow always returned to the benign program after the malicious operation, making them significantly harder to detect than typical RIPE attacks. The evaluation encompassed 23 different software applications, resulting in the collection of approximately one terabyte of trace data. This extensive dataset included applications from OpenSSL and the aforementioned Mbed IoT dataset.

The results for these simulated stealthy attacks were highly encouraging. RAGE achieved F1 scores in the high 90s for both ROP and DOP attacks across these diverse datasets. The speakers noted that ROP attacks were generally easier to detect because they introduce new edges into the control-flow graph, which are stark deviations from benign paths. DOP attacks, however, proved harder to detect as they reuse existing benign edges, relying more heavily on the subtle alterations in data flow captured by the extracted features. The paper provides further detailed evaluation on the impact of specific features on DOP detection. The evaluation also explored the detection capabilities for different ROP chain lengths, with detailed findings available in the full paper. For the OpenSSL dataset, a clear separation was observed between benign (yellow) and malicious (blue) executions, indicating that most attacks were easy to detect.

Finally, the performance evaluation highlighted RAGE's practicality for resource-constrained environments. A Raspberry Pi 4 (2GB version) was used to demonstrate that both the prover and verifier could be edge devices. On the prover side, even with average trace step lengths ranging from 100,000 to 10 million, the pre-processing time was only around 4 seconds. The size of the processed trace sent over the network averaged a mere 0.73 kilobytes, demonstrating very low communication overhead. The researchers noted a trade-off: pre-processing could be done on the verifier side, but this would necessitate sending the entire, larger trace over the network. On the verifier side, the initial model training time was only 5 minutes on a Raspberry Pi, which is entirely feasible for deployment. More importantly, the inference runtime of the VGAE model was exceptionally fast, taking just 0.005 seconds per execution trace. These performance metrics underscore RAGE's viability for real-time or near real-time attestation on embedded systems.

Defensive Implications

▶ Watch: RAGE system overview: training and attestation (8:50)

The RAGE framework offers significant defensive implications for securing embedded and IoT devices against sophisticated code reuse attacks. Its ability to detect both ROP and DOP attacks without relying on strong assumptions or custom hardware makes it a highly practical and impactful security measure.

Firstly, RAGE provides a proactive and immediate detection mechanism against critical RCE vulnerabilities. By continuously monitoring the control flow and comparing it against learned benign patterns, it can quickly identify deviations indicative of malicious activity. This is particularly crucial for IoT devices, which are often deployed with minimal security and represent a growing attack surface.

Secondly, the platform-agnostic nature and lack of custom hardware requirement mean that RAGE can be readily integrated into existing off-the-shelf embedded systems. This significantly lowers the barrier to entry for robust control-flow integrity, enabling a broader adoption of advanced security features in devices that traditionally lack them. Organizations can leverage RAGE to enhance the security of their current IoT fleet without requiring costly hardware redesigns or replacements.

Thirdly, the lightweight model footprint (less than 9,000 parameters) and efficient runtime performance (5 minutes for training, 0.005 seconds for inference on a Raspberry Pi) make RAGE suitable for resource-constrained edge devices. This addresses a critical challenge in embedded security, where traditional heavy-duty security solutions are often infeasible. The minimal communication overhead (0.73 KB processed trace) further enhances its practicality for remote attestation over limited bandwidth networks.

Furthermore, RAGE's proven capability to detect stealthy simulated attacks that return control flow to the benign application is a major defensive advantage. Such attacks are designed to evade simpler detection mechanisms, and RAGE's GNN-based approach demonstrates a deeper understanding of control flow patterns required to catch them. This robust detection extends to Data-Oriented Programming (DOP) attacks, which are notoriously difficult to detect due to their reuse of benign control flow edges.

The unsupervised learning approach means that RAGE can adapt to changes in benign software behavior (e.g., through legitimate updates or patches) with retraining, without requiring extensive manual re-labeling of attack data. This flexibility is vital for maintaining security in dynamic environments. RAGE can be deployed as part of a runtime integrity monitoring system, providing continuous assurance of software execution. It can also complement secure boot processes by ensuring that even after a legitimate boot, the system's runtime behavior remains untampered.

In summary, RAGE offers a powerful, flexible, and efficient solution for protecting embedded devices from a class of attacks that are increasingly prevalent and difficult to detect, thereby significantly bolstering the overall security posture of the vast and expanding IoT ecosystem.

Key Takeaways

  • RAGE introduces a novel Graph Neural Network (GNN)-based approach for control-flow attestation (CFA) in embedded devices.
  • It effectively detects Return-Oriented Programming (ROP) and Data-Oriented Programming (DOP) attacks without relying on a complete control-flow graph, custom hardware, or risking information leakage.
  • The system uses an unsupervised Variational Graph Autoencoder (VGAE) to learn benign execution patterns from basic block addresses (program counter values).
  • RAGE is lightweight (<9,000 parameters), platform-agnostic, and demonstrates high performance, with training taking 5 minutes and inference 0.005 seconds on a Raspberry Pi.
  • It achieved F1 scores in the high 90s for detecting both ROP and stealthy DOP attacks across diverse real-world and simulated datasets.
  • This approach offers a practical and efficient solution for enhancing the security of resource-constrained IoT and embedded devices against sophisticated code reuse vulnerabilities.

About the Speaker(s)

The research presented in this talk was a collaborative effort involving several distinguished individuals from academia and industry. Marco Chilese, who presented the work, is among the key contributors. The team also includes Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli, and Ahmad-Reza Sadeghi. Their collective affiliations span prominent institutions: the Technical University of Darmstadt, a leading research university in Germany; Nvidia, a global technology company known for its advancements in AI and computing; and the University of Southampton, a research-intensive university in the United Kingdom. This diverse collaboration brings together expertise in embedded systems, machine learning, and cybersecurity, which is evident in the innovative and practical nature of the RAGE framework.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This work introduces RAGE, a groundbreaking GNN-based control-flow attestation scheme that elegantly solves critical limitations in embedded device security. By leveraging unsupervised VGAEs, it detects sophisticated ROP/DOP attacks without relying on complete CFGs, custom hardware, or risking information leakage, making it highly practical for resource-constrained IoT.

Heather Calloway (CISO) — STRONG ACCEPT

This talk introduces RAGE, a vital advancement in securing embedded and IoT devices through GNN-based control-flow attestation. It offers a practical, lightweight, and platform-agnostic solution for detecting sophisticated code reuse attacks, directly addressing a critical and growing area of business risk. This research provides a clear path for defenders to enhance runtime integrity and institutional accountability in resource-constrained environments.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024