ESROS2: Application Sandboxes for Secure ROS2

Dev Tejas Gandhi, Vinod Ganapathy.

Proceedings of the 2026 ACM SIGOPS Annual Technical Conference (ATC 2026); pages TBD; Hong Kong, November 15-18, 2026.

ROS2 has emerged as a popular middleware for several robotics platforms. It allows rapid prototyping of distributed robotics applications via a convenient publish/subscribe-based abstraction for application communication. Secure ROS2 (SROS2) is a set of patches to ROS2 that provides several basic security primitives to secure application communication, such as encrypted communication and limiting applications to only publish/subscribe to topics that are declared in a manifest.

Unfortunately, SROS2 is limited in its ability to confine application communication. Applications can freely communicate with each other by bypassing the SROS2 API and directly making system calls via the underlying operating system. This paper introduces ESROS2, which provides application sandboxing in SROS2. ESROS2 confines applications by limiting the set of system calls that they can issue at runtime. When an application issues a system call, ESROS2 determines whether the context in which the system call was issued is safe, and only then permits the system call to be issued. We describe the design of ESROS2 and its implementation using extended Berkeley Packet Filters (eBPF) and commodity intra-process memory isolation hardware (Intel MPK). We show that ESROS2 works on off-the-shelf application binaries, and effectively enforces application sandboxing while only imposing a modest runtime performance overhead.

Paper: [ PDF ]
Slides: [ PDF ]
DOI: [ TBD ]


Papers page