Hardware Security

‍Designing autonomous systems for the reality of physical capture | #2

Multiple authors
|
-
|
Oct 2026
Back to all articles
SHARE

In the first article of this series, we looked at why the security perimeter moves when intelligence moves to the edge of autonomous defense systems. This second article takes the next step: what happens when one of those devices ends up out of its operator's hands.

Written in collaboration with Ido Govrin, it examines what an adversary can realistically learn from a captured platform, why protections such as zeroization can fail in the field, and how side-channel analysis and fault injection can expose secrets that encryption alone does not protect.

Ido Govrin is a Program Coordinator at the Israel Innovation Institute, responsible for InnovaCyberBridge, a cybersecurity startup program run in partnership with the Institute. He served as a UAV systems operator, giving him firsthand operational insight into drone platforms and how they're used in the field.

‍

‍Physical possession should be part of the threat model

Modern military autonomous systems are sophisticated computers in the sky, on the ground and on the water. They combine navigation, communications, sensor processing, autonomous decision-making and increasingly AI inference in platforms that are expected to operate close to the mission.

For many digital products, physical possession by an attacker is exceptional. For a military UAV or other autonomous defence platform, it should be considered from the beginning. Drones crash. They are intercepted. They are jammed and forced to land. Components are recovered from battlefields. Commercial and dual-use platforms can also be acquired and studied.

The relevant cybersecurity question is therefore not only whether an adversary can compromise the platform remotely. It is what the adversary can learn once they have unrestricted physical access.

‍

A captured system becomes an attack surface

Inside a recovered platform lies a spectrum of critical assets. Every operational system—from simple dual-use drones to advanced military platforms—carries vital operational intelligence, such as cached maps, flight logs, waypoints, and comms settings. Advanced platforms layer on proprietary algorithms, AI models, and cryptographic keys. Regardless of complexity, if zeroization fails, this onboard memory becomes an immediate goldmine for the adversary.

Automated key erasure (zeroization) is a vital line of defense, but relying solely on logical triggers creates a dangerous false sense of security. The entire mechanism depends on a critical first step: the onboard system must correctly identify that a compromise is taking place.

In practice, this initial detection phase regularly breaks down:

  • Operators are forced out of the loop: Loss of communication is a routine operational event. Because operators receive no telemetry during a comms drop, they cannot determine in real-time whether a platform is temporarily out of range or actively crashing. Manual remote-wipe decisions are practically impossible, leaving detection entirely up to the platform's onboard automation.
  • Intact landings under recovery logic: When faced with signal loss or RF interference, onboard flight controllers typically execute Return-to-Home (RTH) or emergency soft-landing protocols. The drone can land completely intact in hostile territory while believing it is executing a standard safety routine - keeping erasure logic completely idle.
  • Kinetic damage to the erasure mechanism: A mid-air strike or physical impact should trigger zeroization, but the kinetic event itself frequently severs power rails or destroys processing components before the wipe command can execute.
  • Advanced telemetry spoofing: Modern electronic warfare goes beyond GPS manipulation to spoof flight data such as barometric altitude or orientation. If onboard sensors report a stable flight envelope, the platform remains completely unaware of its actual compromise.

If the platform fails to recognize the situation, zeroization never triggers -leaving cryptographic keys and sensitive data completely intact in physical memory.

Encryption alone does not solve the physical-capture problem. A cryptographic algorithm may be mathematically secure while its implementation leaks information. Firmware readout protection may stop a straightforward extraction while remaining vulnerable when the processor is deliberately disturbed.

Once the device is on an adversary's bench, they do not need to respect its intended electrical, software or environmental conditions. They can probe interfaces, alter power or clock signals, observe electromagnetic emissions, instrument execution and repeatedly reset and manipulate the target.

‍

Two attack families illustrate the problem

Side-channel analysis observes physical effects created by computation. Power consumption, electromagnetic emissions, timing and related signals can reveal information that should remain secret. eShard security research has included cryptographic-key recovery on a UAV through side-channel analysis, illustrating why a key can be stored inside a device yet still be recoverable from its implementation.

Fault injection takes the opposite approach: instead of observing the target, it deliberately makes the processor misbehave. Voltage or clock glitches, electromagnetic pulses and other techniques can cause operations to be skipped or corrupted. Depending on the implementation, this can contribute to bypassing security checks, defeating readout protection or exposing otherwise inaccessible firmware and secrets.

eShard's research and security work has also included reproducing an STM32 readout-protection bypass using fault injection, showing why component-level security properties must still be evaluated in the context of the final system.

‍

Assume capture. Engineer resilience.

The practical starting point is not to ask whether every possible physical attack can be prevented. It is to identify what must remain protected even after the platform is lost.

Engineering teams can identify the critical assets, map where they exist across hardware and software, understand the mechanisms protecting them, and then test whether those mechanisms survive realistic adversarial conditions.

Because in defence, losing the hardware should not have to mean losing the secrets inside it.