ICRA 2026poster0 citations

The Case of Metadata Leakage in ROS 2: Fingerprintability, Security Implications, and Internet-Wide Vulnerability Measurements

Fayzah Alshammari, Sam Der, Qi Alfred Chen

Abstract

The Robot Operating System (ROS) is widely adopted in the robotics community, powering applications from self-driving vehicles to industrial automation. ROS 2 utilizes the Data Distribution Service (DDS) middleware for decentralized communication, making it inherently susceptible to reconnaissance and exploitation attacks. Previous research has examined the security implications of DDS implementations but has not systematically distinguished ROS 2 nodes from standalone DDS deployments, a critical distinction that significantly influences the execution and outcome of cyberattacks. This paper presents the first systematic fingerprinting framework designed specifically for ROS 2, demonstrating how DDS-based metadata leakage can facilitate precise identification and targeted exploitation of robotic systems. Through controlled experiments and an Internet-wide scan of DDS deployments, we identify extensive metadata exposure across actively supported ROS 2 implementations. Despite existing security solutions such as Secure ROS 2 (SROS2), deployments using default configurations remain vulnerable, highlighting the need for enhanced metadata obfuscation, stricter network access policies, and deployment of real-time anomaly detection mechanisms to strengthen the security posture of ROS 2 systems.

Networked RobotsSoftware, Middleware and Programming Environments
The Case of Metadata Leakage in ROS 2: Fingerprintability, Security Implications, and Internet-Wide Vulnerability Measurements · ICRA 2026