
Yossi Oren
PCR Automation Threats and Mitigations
Wet-lab automation robots are cyber-physical systems designed to streamline experiments, production, and tests in the bio-medical sectors. A prominent recent example where automated bio-medical tests played a major role is the COVID19 PCR11PCR stands for Polymerase Chain Reaction. COVID-19 stands for the coronavirus disease of 2019. tests. Such tests are implemented through scripted biological protocols, obtained from Web-based repositories and executed by the robots. Biological protocols (manual in the past, automated today) are designed to maximize efficiency and withstand failures but are not hardened against adversarial intervention. We point out a security weakness in the design of the industry standard PCR protocol, and multiple vulnerabilities in an open-source wet-lab automation platform that implements it. We demonstrate an end-to-end attack which exploits these vulnerabilities to maliciously increase the false positive rate or the false negative rate of PCR tests. We also present several defensive strategies to mitigate the attack. Our results, analyzed using a calibration curve, highlight that not only the software and hardware stack need to be secured, but also the design of biological protocols should be hardened against adversarial intervention.
| Publication language | English |
| Pages | 141-151 |
| Publication status | Published - 01.01.2026 |