
Weldon School of Biomedical Engineering
Wednesday, January 19, 2022
9:30-10:20am
MJIS 1001 or Via Zoom:
https://purdue-edu.zoom.us/j/95150439811?pwd=a3hOK0o0bmpkS3poTVBCbVhDNU9FZz09
Security Engineering for Medical Products:
Sensors, Signals, Semiconductors, Software Systems
Kevin Fu, Ph.D.
Associate Professor, Electrical Engineering and Computer Science, University of Michigan
Acting Director of Medical Device Cybersecurity at U.S. FDA’s Center for Devices and Radiological Health (CDRH) and Program Director for Cybersecurity at the Digital Health Center of Excellence (DHCoE),
Abstract: Medical devices, healthcare delivery, and other cyberphysical systems depend on sensors to make safety-critical, automated decisions. My research lab investigates the problem of how to protect
cyberphysical systems from adversaries who can maliciously control sensor output by subverting its semiconductor physics. Finding principled, systematic solutions is extremely important to give consumers confidence in innovative medical devices and other emerging
technology. Unique to our embedded security research contributions is an emphasis on protecting the longevity of implanted batteries and using software-only approaches to mitigate design flaws in legacy hardware. These contributions were important to creating
the field of medical device security; advancing the academic community's ability to measurably defend against signal injection attacks on sensors; and changing how international regulators evaluate security of consumer products. In this talk, I will highlight
academic research on protecting sensor semiconductors from maliciously modulated sound waves, radio waves, and lasers that can compromise software systems in cyberphysical systems such as pacemakers and vaccine cold-chain transportation.
Bio: Kevin Fu is Associate Professor of EECS at the University of Michigan. His security research led to a decade of revolutionary improvements at medical device manufacturers, global regulators, and international healthcare safety standards
bodies. Security solutions resulting from this research foresaw the risks of malicious software affecting hospitals a decade before ransomware began to disrupt clinical workflow at worldwide. Fu is presently on leave from Michigan while serving as the inaugural
Acting Director of Medical Device Cybersecurity at U.S. FDA’s Center for Devices and Radiological Health (CDRH) and Program Director for Cybersecurity at the Digital Health Center of Excellence (DHCoE). Fu was recognized as an IEEE Fellow, Sloan Research
Fellow, and MIT Technology Review TR35 Innovator of the Year. He received several best paper awards from top conferences in computer security. His research on pacemaker security received an IEEE Test of Time Award. He co-founded healthcare cybersecurity startup
Virta Labs. Fu was commissioned by the National Academy of Medicine to publish a report on trustworthy medical device software. He serves as a member of the Association for the Advancement of Medical Instrumentation (AAMI) Biomedical Instrumentation & Technology
Editorial Board, the ACM Committee on Computers and Public Policy, and the USENIX Security Steering Committee. He co-chaired the AAMI cybersecurity working group to create the first FDA-recognized consensus standards to improve the security of medical device
manufacturing. He founded the Archimedes Center for Healthcare and Device Security (secure-medicine.org). He co-founded the N95decon.org team for emergency reuse decontamination of N95 masks during pandemic shortages. Fu served as a member of the U.S. NIST
Information Security and Privacy Advisory Board and federal science advisory groups. Fu received his Ph.D. from MIT. He earned a certificate of artisanal bread making from the French Culinary Institute, builds wood-fired brick ovens, and enjoys woodworking.
~BME Faculty Host: Dr. Young Kim
~