Related Experiment Video
Updated: Jun 10, 2025

11:18
Closed-loop Neuro-robotic Experiments to Test Computational Properties of Neuronal Networks
Published on: March 2, 2015
10.3K
Data Poisoning Attack against Neural Network-Based On-Device Learning Anomaly Detector by Physical Attacks on Sensors
Takahito Ino1, Kota Yoshida1, Hiroki Matsutani2
1College of Science and Engineering, Ritsumeikan University, Kusatsu 525-8577, Japan.
Sensors (Basel, Switzerland)
|October 16, 2024
Summary
This study demonstrates a data poisoning attack on edge AI anomaly detection systems. Physical attacks can compromise machine learning models, preventing accurate detection of factory machine abnormalities.
Area of Science:
- Artificial Intelligence
- Machine Learning Security
- Industrial IoT
Background:
- Edge AI systems for industrial anomaly detection are vulnerable to physical attacks.
- On-device learning models can be compromised through data poisoning, degrading performance.
- Risk assessments for physical attacks on Edge AI are limited.
Purpose of the Study:
- To demonstrate a data poisoning attack on an on-device learning Edge AI for anomaly detection.
- To investigate the security risks associated with physical tampering of Edge AI training data.
- To evaluate the impact of data poisoning on the accuracy of machine vibration anomaly detection.
Main Methods:
- An on-device learning anomaly detection system using MEMS accelerometers for factory machine vibration analysis was targeted.
- A data poisoning attack was executed by exposing the MEMS accelerometer to specific acoustic waves, falsifying vibration data.
- The falsified data was used to retrain the anomaly detection model, which included concept drift detection and multiple normal pattern models.
Main Results:
- The data poisoning attack successfully degraded the Edge AI's ability to detect abnormal machine conditions.
- Falsified acceleration data, when used for training, rendered the anomaly detector ineffective.
- The system failed to identify abnormal states after being subjected to the acoustic manipulation attack.
Conclusions:
- Physical attacks, specifically data poisoning via acoustic manipulation, pose a significant threat to the integrity of on-device learning Edge AI systems.
- The accuracy of anomaly detection in industrial settings can be severely compromised by tampering with sensor data.
- Understanding these vulnerabilities is crucial for developing robust security countermeasures for Edge AI in critical infrastructure.

