Related Experiment Video
Updated: Aug 19, 2025

Design and Analysis for Fall Detection System Simplification
Published on: April 6, 2020
Experiments on Adversarial Examples for Deep Learning Model Using Multimodal Sensors
Ade Kurniawan1, Yuichi Ohsita1,2, Masayuki Murata1
1Graduate School of Information Science and Technology, Osaka University, Suita 565-0871, Osaka, Japan.
This study examines how hackers can trick artificial intelligence systems by manipulating only a small portion of available sensor data, rather than needing access to every device in a network. By testing a human activity recognition model, the researchers show that compromising just one or two sensors is enough to cause significant errors in system output.
Area of Science:
- Cybersecurity and adversarial examples in machine learning systems
- Internet of Things (IoT) sensor network security
Background:
No prior work had resolved the full extent of security vulnerabilities when only partial sensor access is available to malicious actors. It was already known that artificial intelligence systems relying on interconnected devices face significant threats from sophisticated digital intrusions. Adversarial examples represent a primary concern, as these manipulated inputs force machine learning architectures to produce erroneous results. Prior research has shown that deep neural networks are susceptible to such interference when attackers control the entire feature set. That uncertainty drove the need to investigate scenarios where full system compromise remains unachievable. This gap motivated an exploration into whether limited sensor hacking could still undermine model reliability. The current literature often assumes that total data visibility is a prerequisite for successful exploitation. This study addresses the missing evidence regarding the impact of restricted access on overall system integrity.
Purpose Of The Study:
The aim of this study is to evaluate the feasibility of adversarial attacks on deep neural network models when an attacker only compromises a limited number of sensors. This research addresses the critical uncertainty regarding whether full system access is mandatory for successful model manipulation. The authors seek to challenge the common assumption that security threats require control over the entire feature set of a machine learning system. By focusing on scenarios with restricted access, the study provides a more realistic assessment of potential vulnerabilities in interconnected environments. The motivation stems from the increasing reliance on artificial intelligence systems that integrate data from multiple hardware devices. This investigation explores the specific conditions under which partial sensor hacking can lead to incorrect classification outputs. The researchers intend to demonstrate that even minimal interference with a subset of devices can undermine the integrity of the entire model. This work establishes a foundation for understanding the risks posed by targeted attacks on specific components within a larger sensor network.
Main Methods:
The review approach involved designing a series of controlled experiments to test the resilience of a human activity recognition model. Investigators utilized three distinct wearable devices attached to the chest, wrist, and ankle to collect movement data. The team simulated a threat scenario where an attacker gains unauthorized control over a subset of these hardware components. Researchers then modified the values obtained from these specific compromised sensors while keeping the remaining data streams authentic. This methodology allowed for a systematic evaluation of how partial input manipulation affects deep neural network performance. The design focused on identifying the minimum number of hacked devices required to force incorrect classification results. Statistical analysis was performed to compare the accuracy of the model under normal conditions versus the adversarial state. This approach provided a clear framework for assessing the security risks inherent in multi-sensor network architectures.
Main Results:
Key findings from the literature indicate that adversarial attacks remain effective even when an attacker only controls a small fraction of the total sensor array. The experiments confirm that manipulating data from a single sensor is sufficient to cause the human activity recognition model to generate incorrect outputs. The researchers observed that the deep neural network failed to maintain classification accuracy once the adversarial inputs were injected into the system. These results demonstrate that the model is highly sensitive to localized data corruption within the multi-sensor configuration. The study provides quantitative evidence that full feature access is not a prerequisite for successful exploitation of deep learning architectures. The data show that targeted modifications to the chest, wrist, or ankle sensor values consistently lead to system errors. These findings highlight a significant security gap in current models that rely on aggregated sensor information. The observed success rate of these attacks confirms that partial compromise poses a substantial risk to the reliability of artificial intelligence systems.
Conclusions:
The authors demonstrate that compromising a limited subset of hardware is sufficient to induce failures in deep neural network models. Their synthesis suggests that current security protocols for human activity recognition systems may be inadequate against targeted, partial-input attacks. The findings imply that designers must account for the vulnerability of individual sensor nodes within a larger network. This work highlights that full feature access is not a requirement for successful adversarial manipulation. The researchers propose that future defensive strategies should prioritize securing individual data streams rather than relying solely on perimeter protection. The evidence indicates that even minimal interference can lead to incorrect classification outcomes in real-world deployments. These results underscore the necessity of developing robust models capable of maintaining accuracy despite localized data corruption. The study provides a foundation for understanding the risks associated with fragmented sensor network exploitation.
Frequently Asked Questions
The researchers propose that attackers manipulate specific sensor inputs to force the deep neural network into misclassification. By altering data from only a subset of devices, such as the chest or wrist, the system generates incorrect activity labels despite the integrity of other connected sensors.
The study utilizes a human activity recognition model, which integrates data from three distinct wearable devices. These sensors are positioned on the chest, wrist, and ankle to track movement patterns, serving as the primary testbed for evaluating the impact of partial data manipulation.
The authors state that hacking a small number of sensors is sufficient to compromise the model. This technical necessity arises because the deep neural network relies on the combined input of all sensors; altering a single stream shifts the overall feature vector toward an adversarial state.
The researchers employ sensor data as the primary input type for their adversarial experiments. By selectively modifying these values, they simulate a scenario where an attacker controls specific hardware nodes while the remaining data streams continue to provide legitimate, uncompromised information to the system.
The team measures the success of the attack by tracking the frequency of incorrect activity recognition outputs. They compare the performance of the original model against the manipulated version, observing how specific sensor modifications lead to predictable classification errors across different user activities.
The authors suggest that their findings necessitate a shift in security design for interconnected devices. They propose that developers must assume that individual sensors can be compromised and should therefore implement verification methods that do not rely on the assumption of total system integrity.
Related Concept Videos
Multi-input and Multi-variable systems
In the absence...
Force Classification
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
Sensory Modalities
General senses refer to the broad category of sensory information detected by receptors in the body and can be further grouped into somatic and visceral senses. Somatic sensations include touch, pressure, temperature, and pain and are essential for navigating our environment and...

