<node id="690808">
  <nid>690808</nid>
  <type>news</type>
  <uid>
    <user id="36253"><![CDATA[36253]]></user>
  </uid>
  <created>1781803952</created>
  <changed>1781805290</changed>
  <title><![CDATA[Research Gets to the Core of AI Drone Crashes]]></title>
  <body><![CDATA[<p>A drone powered by artificial intelligence crashes in a remote field, destroying its onboard computer and leaving investigators without the data needed to determine whether a cyberattack caused the failure.</p><p>Researchers at Georgia Tech say they have developed a system to help answer that question.</p><p>Known as FIRA, the tool analyzes drone crashes to determine whether they were caused by poisoned machine-learning (ML) models. The team will present its findings at the <a href="https://www.usenix.org/conference/usenixsecurity26">35th USENIX Security Symposium</a> in August.&nbsp;</p><p>The research addresses a growing safety challenge as drones are increasingly used for deliveries, infrastructure inspections, and agriculture.</p><p>As drones rely more on machine learning to navigate and make decisions, they also become vulnerable to model poisoning attacks. In these attacks, adversaries manipulate an AI system during its learning phase, embedding hidden triggers that can cause failures under specific conditions.</p><p>“Machine learning drones are making more decisions in flight, which makes ML a safety-critical component of these systems,” said&nbsp;<strong>Yizhi Huang</strong>, Ph.D. student and lead researcher on the project.&nbsp;</p><p>“When something goes wrong, investigators need a way to ask whether the model was responsible, but the model is the part of the system that no one can examine after a crash.&nbsp;FIRA&nbsp;gives investigators a way to investigate these cases by reconstructing what the model was doing during the crash. As more drones run with ML, this kind of forensic capability can help drones be used more effectively and safely.”</p><p>When a drone crashes, investigators must determine whether the cause was malicious interference, weather, or mechanical failure. Without reliable forensic tools, accountability is difficult to establish, and safety standards are harder to enforce.</p><p>FIRA identifies how drone components interact with machine learning models and monitors those interactions in real time, even with limited bandwidth.</p><p>The system functions like a flight recorder, capturing key system activity and reconstructing a timeline after a crash. It then analyzes the model’s behavior to determine whether a malicious trigger was introduced via poisoned ML training data.</p><p>In tests across multiple drone platforms and crash scenarios, FIRA identified failure causes and distinguished cyberattacks from environmental or mechanical issues.</p><p>The system does not require access to a drone’s source code, making it practical for real-world investigations.</p><p>“As commercial drone use expands, tools like FIRA could help improve accountability and trust in AI-powered systems operating in public airspace,” said&nbsp;Huang.&nbsp;</p><p><a href="https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_huang-yizhi.pdf"><em>FIRA: Enabling Automatic Forensic Investigation of Unmanned Aerial Vehicles</em></a> was led by Georgia Tech’s <a href="https://cyfi.ece.gatech.edu/">Cyber Forensics Innovation Lab</a> in cooperation with the <a href="https://sites.gatech.edu/capcpsec/">Cyber-Physical Security Lab</a>. These labs reside in the <a href="https://scp.cc.gatech.edu/">School of Cybersecurity and Privacy</a> and the <a href="https://ece.gatech.edu/">School of Electrical and Computing Engineering</a>.&nbsp;</p>]]></body>
  <field_subtitle>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_subtitle>
  <field_dateline>
    <item>
      <value>2026-06-18T00:00:00-04:00</value>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_dateline>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Researchers at Georgia Tech say they have developed a system to determine whether a cyberattack caused drone crashes.]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[<p>A drone powered by artificial intelligence crashes in a remote field, destroying its onboard computer and leaving investigators without the data needed to determine whether a cyberattack caused the failure.</p><p>Researchers at Georgia Tech say they have developed a system to help answer that question.</p>]]></value>
    </item>
  </field_summary>
  <field_media>
          <item>
        <nid>
          <node id="660599">
            <nid>660599</nid>
            <type>image</type>
            <title><![CDATA[CyFI Lab Sign]]></title>
            <body><![CDATA[]]></body>
                          <field_image>
                <item>
                  <fid>250302</fid>
                  <filename><![CDATA[SCP August 2022-66.png]]></filename>
                  <filepath><![CDATA[/sites/default/files/images/SCP%20August%202022-66.png]]></filepath>
                  <file_full_path><![CDATA[http://hg.gatech.edu//sites/default/files/images/SCP%20August%202022-66.png]]></file_full_path>
                  <filemime>image/png</filemime>
                  <image_740><![CDATA[]]></image_740>
                  <image_alt><![CDATA[Sign reading Cyber Forensics Innovation Laboratory The CyFI Lab]]></image_alt>
                </item>
              </field_image>
            
                      </node>
        </nid>
      </item>
      </field_media>
  <field_contact_email>
    <item>
      <email><![CDATA[jpopham3@gatech.edu]]></email>
    </item>
  </field_contact_email>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_contact>
    <item>
      <value><![CDATA[<p>John Popham</p><p>Communications Officer II at the School of Cybersecurity and Privacy</p>]]></value>
    </item>
  </field_contact>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <!--  TO DO: correct to not conflate categories and news room topics  -->
  <!--  Disquisition: it's funny how I write these TODOs and then never
         revisit them. It's as though the act of writing the thing down frees me
         from the responsibility to actually solve the problem. But what can I
         say? There are more problems than there's time to solve.  -->
  <links_related> </links_related>
  <files> </files>
  <og_groups>
          <item>47223</item>
          <item>1188</item>
          <item>660406</item>
          <item>660367</item>
      </og_groups>
  <og_groups_both>
          <item>
        <![CDATA[Artificial Intelligence]]>
      </item>
          <item>
        <![CDATA[Computer Science/Information Technology and Security]]>
      </item>
          <item>
        <![CDATA[Research]]>
      </item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>194606</tid>
        <value><![CDATA[Artificial Intelligence]]></value>
      </item>
          <item>
        <tid>153</tid>
        <value><![CDATA[Computer Science/Information Technology and Security]]></value>
      </item>
          <item>
        <tid>135</tid>
        <value><![CDATA[Research]]></value>
      </item>
      </field_categories>
  <core_research_areas>
          <term tid="193655"><![CDATA[Artificial Intelligence at Georgia Tech]]></term>
          <term tid="145171"><![CDATA[Cybersecurity]]></term>
      </core_research_areas>
  <field_news_room_topics>
      </field_news_room_topics>
  <links_related>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>47223</item>
          <item>1188</item>
          <item>660406</item>
          <item>660367</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[College of Computing]]></item>
          <item><![CDATA[Research Horizons]]></item>
          <item><![CDATA[School of Cybersecurity &amp; Privacy]]></item>
          <item><![CDATA[School of Cybersecurity and Privacy]]></item>
      </og_groups_both>
  <field_keywords>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
