Pith. sign in

REVIEW 1 major objections 2 minor 1 cited by

A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing

T0 review · 1 major / 2 minor · reviewed 2026-06-25 · grok-4.3

Pith's one-line read A Timing Protection Level conditionally bounds undetected time error to oscillator holdover plus a model-free monitor floor under GNSS spoofing, if an independent check detects the attack.

desk verdict No unconditional undetected time error bound exists under a single self-referential monitor, but the paper supplies a workable conditional TPL once an independent cross-satellite check is assumed to trigger. read the letter →

arxiv 2606.24210 v1 pith:AFSUYA3N submitted 2026-06-23 eess.SP cs.CR

classification eess.SPcs.CR
keywords GNSSspoofingtimingprotectionlevelholdoverundetectedtimeerrormodel-freemonitorcross-satelliteconsistencyoscillatorcoast
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper demonstrates that a GNSS timing receiver can be pulled by over a millisecond of served time during a recorded spoof while its own accuracy flag reports only 51 ns. It shows that no finite unconditional bound on undetected error is possible against an adversary who chooses an arbitrarily slow ramp, because a self-referential clock-aided monitor will stay locked and never alarm. The paper therefore defines a conditional Timing Protection Level as the sum of a model-free monitor's static detectability floor and the oscillator coast during the time to detection. This sum is expressed in closed form from simulator-verified primitives and yields 114 ns at one-second recovery or 458 ns at a 60-second coast when calibrated on the public JammerTest 2024 attack data. The bound is presented as calibrated rather than field-validated and carries no integrity-risk allocation.

What carries the argument

The Timing Protection Level (TPL), formed as the sum of a model-free monitor's static detectability floor and the oscillator coast during detection latency, conditional on an independent cross-satellite consistency check detecting the attack.

What would settle it

A field recording of a coherent spoof in which the cross-satellite consistency check fails to alarm before the served-time error exceeds the calculated TPL value.

Watch

Extended reading notes

Core claim

Against an adversary free to choose ramp rate, no finite unconditional bound on undetected time error exists under a single self-referential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step is never alarmed while the error grows without limit. The Timing Protection Level (TPL) is therefore defined as a model-free monitor's static detectability floor plus the oscillator's coast over the detection latency; this bound holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step. Each term is closed-form over primitives verified in the open Kshana simulator, and calibration on the recor

Load-bearing premise

An independent cross-satellite consistency check will detect the spoof attack and the spoofer will not drive that check in lock-step with the timing receiver.

Editorial extensions

If this is right

  • A clock-aided sequential test alone alarms only near the ~1 ms capture and therefore supplies essentially no protection against the slow ramp.
  • The model-free monitor alarms during the ramp itself, supplying the detectability floor that enters the TPL.
  • The resulting TPL is thousands of times smaller than the 1.01 ms error accepted by the receiver in the recorded attack.
  • The bound is reported as a band at long coast and carries no integrity-risk budget.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If receivers routinely run both the model-free monitor and an independent consistency check, served-time error could be kept to sub-microsecond levels even under slow coherent spoofing.
  • The open-source simulator and closed-form expressions allow direct substitution of different oscillator specifications or monitor thresholds without re-deriving the entire bound.
  • The same conditional structure could be examined for other common-mode threats, such as ionospheric or ephemeris manipulation, provided an independent detector exists.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

1 major / 2 minor

Summary. The manuscript reports a field measurement from the JammerTest 2024 campaign in which a u-blox ZED-F9P receiver experienced a 1.01 ms served-time error under spoofing while its internal accuracy flag reported at most 51 ns. It proves that no finite unconditional bound on undetected time error exists under any single self-referential clock-aided monitor, because an adversary can always choose a sufficiently slow ramp that keeps the disciplined reference in lock-step. It then defines a conditional Timing Protection Level (TPL) as the sum of a model-free monitor's static detectability floor plus the oscillator coast over detection latency, conditioned on detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step. Each term is given in closed form over primitives verified in the open Kshana simulator; when calibrated on the recorded attack the TPL evaluates to 114 ns at 1 s recovery and 458 ns at 60 s coast. The simulator, expressions, and calibration are released under AGPL-3.0.

Significance. If the conditioning assumption holds, the TPL supplies a reproducible, hand-verifiable bound on undetected time error that is thousands of times tighter than the observed attack error and directly addresses the failure of position-domain RAIM against common-mode time pulls. The explicit open-source release of the simulator, the closed-form expressions, and the calibration example constitutes a verifiable and extensible contribution to GNSS timing integrity.

major comments (1)
  1. [Abstract, third contribution] Abstract, third contribution: the claim that the TPL holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step is load-bearing for the entire conditional result. The manuscript supplies no measurement model for the check, no demonstration that coherence precludes lock-step driving of the residuals, and no counter-example search within the Kshana simulator, leaving the robustness of the conditioning assumption unverified.
minor comments (2)
  1. The abstract correctly states that the bound is calibrated rather than field-validated and carries no integrity-risk budget; repeating this disclaimer in the conclusions would improve clarity for readers who reach only the final section.
  2. Notation for the model-free monitor's static detectability floor and the oscillator coast parameters should be introduced with explicit symbols in the main text before the closed-form expressions are presented.

Simulated Author's Rebuttal

1 responses · 0 unresolved

We thank the referee for the constructive review and for highlighting the centrality of the conditioning assumption. We address the single major comment below.

read point-by-point responses
  1. Referee: [Abstract, third contribution] Abstract, third contribution: the claim that the TPL holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step is load-bearing for the entire conditional result. The manuscript supplies no measurement model for the check, no demonstration that coherence precludes lock-step driving of the residuals, and no counter-example search within the Kshana simulator, leaving the robustness of the conditioning assumption unverified.

    Authors: We agree that the conditioning assumption is load-bearing and that the manuscript would be strengthened by additional substantiation. The cross-satellite consistency check is defined as independent of the self-referential clock-aided monitor; under a coherent spoofer the common-mode time pull leaves the differential residuals (and thus the check) unaffected, so the check cannot be driven in lock-step. However, the current text provides no explicit measurement model, derivation, or simulator counter-example search. We will revise to add a short dedicated paragraph supplying the measurement model for the check, showing why coherence precludes lock-step driving of its residuals, and stating the assumption explicitly as a prerequisite (with the associated limitation). revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

Derivation is self-contained; no circular steps identified

full rationale

The paper defines TPL explicitly as the sum of two closed-form terms (model-free monitor static floor + oscillator coast over latency) under a stated external condition (detection by independent cross-satellite check that a coherent spoofer does not drive in lock-step). Each term is described as derived from primitives verified in the open Kshana simulator, making the structure reproducible by hand independent of the specific attack dataset. The numerical values (114 ns, 458 ns) are openly labeled as 'calibrated on the recorded attack' with the explicit disclaimer that the bound 'is calibrated, not field-validated' and 'carries no integrity-risk budget.' This calibration is transparent and does not reduce the claimed derivation to its inputs by construction. No self-citations appear in the load-bearing steps, no uniqueness theorems are imported from prior author work, and the impossibility result for unconditional bounds is logically separate from the conditional construction. The central claim therefore remains self-contained against external benchmarks.

Assumptions & free parameters 2 free parameters · 1 assumptions · 0 invented entities

The TPL rests on the domain assumption of an independent monitor that the spoofer cannot control in lock-step; the numerical bound is calibrated to one recorded attack.

free parameters (2)
  • static detectability floor
    Primitive verified in Kshana simulator; value not given in abstract but used as input to the sum.
  • oscillator coast time
    Depends on detection latency; calibrated on the 2024 attack data.
assumptions (1)
  • domain assumption An independent cross-satellite consistency check detects coherent spoofers that a clock-aided monitor misses.
    Stated as the condition under which the TPL holds (third contribution).

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing." pith.science (2026). https://pith.science/paper/AFSUYA3N

@misc{pith2026260624210,
  author       = {Pith},
  title        = {Pith review of: A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/AFSUYA3N}},
  note         = {Machine review of arXiv:2606.24210}
}
read the original abstract

A GNSS timing receiver under spoofing has no nominal-geometry fault for position-domain RAIM to bound: the threat is a slow, common-mode pull of served clock time that the receiver's own time-accuracy flag need not reveal. We make three graded contributions. First, a field measurement: solving the receiver clock trajectory from raw L1 pseudoranges and broadcast ephemeris, we show a recorded over-the-air spoof from the public JammerTest 2024 campaign pulled a u-blox ZED-F9P by about 1.01 ms of served time while it reported at most 51 ns, a gap near 20,000x. Second, an impossibility: against an adversary free to choose the ramp rate, no finite unconditional bound on undetected time error exists under a single self-referential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step is never alarmed while the error grows without limit, so any finite guarantee is conditional. Third, the conditional bound: the Timing Protection Level (TPL), a model-free monitor's static detectability floor plus the oscillator's coast over the detection latency, holds given detection by an independent cross-satellite consistency check a coherent spoofer does not drive in lock-step. Each term is a closed form over a primitive verified in the open Kshana simulator, so the sum is reproducible by hand. Calibrated on the recorded attack, the budget is 114 ns at one-second recovery and 458 ns at a 60-second coast, thousands of times below the 1.01 ms accepted; a clock-aided sequential test alone gives essentially no protection on this slow ramp (it alarms only near the ~1 ms capture), while the model-free monitor alarms during the ramp. We are explicit: the bound is calibrated, not field-validated; carries no integrity-risk budget; and is reported as a band at long coast. The simulator, bound, and calibration example are open source under AGPL-3.0.

Figures

Figures reproduced from arXiv: 2606.24210 by the authors.

Figure 2
Figure 2. The model-free monitor signal. Cross-satellite clock consistency [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Measured overlapping Allan deviation of the reconstructed receiver / [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figure 5
Figure 5. The TPL is floor-governed at long coast. Sweeping the long-tau [PITH_FULL_IMAGE:figures/full_fig_p006_5.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Rigid-Covert GNSS Spoofing of UAV Swarms: A Structural Blind Spot, Its Detection Limit, and Absolute-Anchor Defenses

    cs.CR 2026-08 accept novelty 6.0 of 10

    A common, geometry-preserving GNSS shift is invisible to distance-only swarm defenses, but a small set of trusted anchors can restore absolute positions, and a derived detection floor predicts how fast a covert ramp m...

Reference graph

Works this paper leans on

28 extracted references · 1 canonical work pages · cited by 1 Pith paper

  1. [1]

    GNSS dataset under jam- ming, spoofing, and meaconing conditions (JammerTest 2024),

    M. I. Sayyaf, M. Ortiz, and V . Renaudin, “GNSS dataset under jam- ming, spoofing, and meaconing conditions (JammerTest 2024),” dataset, Universit´e Gustave Eiffel, Zenodo, 2025, GPL-3.0-or-later. Version DOI 10.5281/zenodo.15911589 (concept DOI 10.5281/zenodo.15910563). [Online]. Available: https://doi.org/10.5281/zenodo.15911589

  2. [2]

    GNSS spoofing and detection,

    M. L. Psiaki and T. E. Humphreys, “GNSS spoofing and detection,” Proc. IEEE, vol. 104, no. 6, pp. 1258–1270, 2016

  3. [3]

    Assessing the spoofing threat: development of a portable GPS civilian spoofer,

    T. E. Humphreys, B. M. Ledvina, M. L. Psiaki, B. W. O’Hanlon, and P. M. Kintner, “Assessing the spoofing threat: development of a portable GPS civilian spoofer,” inProc. ION GNSS, 2008

  4. [4]

    On the requirements for successful GPS spoofing attacks,

    N. O. Tippenhauer, C. P ¨opper, K. B. Rasmussen, and S. ˇCapkun, “On the requirements for successful GPS spoofing attacks,” inProc. ACM Conf. Computer and Communications Security (CCS), 2011, pp. 75–86

  5. [5]

    Who’s afraid of the spoofer? GPS/GNSS spoofing detection via automatic gain control (AGC),

    D. M. Akos, “Who’s afraid of the spoofer? GPS/GNSS spoofing detection via automatic gain control (AGC),”NAVIGATION, vol. 59, no. 4, pp. 281–290, 2012

  6. [6]

    Receiver- autonomous spoofing detection: experimental results of a multi-antenna receiver defense against a portable civil GPS spoofer,

    P. Y . Montgomery, T. E. Humphreys, and B. M. Ledvina, “Receiver- autonomous spoofing detection: experimental results of a multi-antenna receiver defense against a portable civil GPS spoofer,” inProc. ION Int. Tech. Meeting (ITM), 2009

  7. [7]

    Dovis,GNSS Interference Threats and Countermeasures

    F. Dovis,GNSS Interference Threats and Countermeasures. Norwood, MA: Artech House, 2015

  8. [8]

    GPS vulnerability to spoofing threats and a review of antispoofing techniques,

    A. Jafarnia-Jahromi, A. Broumandan, J. Nielsen, and G. Lachapelle, “GPS vulnerability to spoofing threats and a review of antispoofing techniques,”Int. J. Navig. Obs., vol. 2012, art. 127072, 2012

Show all 28 references
  1. [9]

    A survey and analysis of the GNSS spoofing threat and countermeasures,

    D. Schmidt, K. Radke, S. Camtepe, E. Foo, and M. Ren, “A survey and analysis of the GNSS spoofing threat and countermeasures,”ACM Comput. Surv., vol. 48, no. 4, art. 64, pp. 1–31, 2016

  2. [10]

    A baseline GPS RAIM scheme and a note on the equivalence of three RAIM methods,

    R. G. Brown, “A baseline GPS RAIM scheme and a note on the equivalence of three RAIM methods,”NAVIGATION, vol. 39, no. 3, pp. 301–316, 1992

  3. [11]

    Weighted RAIM for precision approach,

    T. Walter and P. Enge, “Weighted RAIM for precision approach,” in Proc. ION GPS, 1995

  4. [12]

    Baseline advanced RAIM user algorithm and possible improvements,

    J. Blanchet al., “Baseline advanced RAIM user algorithm and possible improvements,”IEEE Trans. Aerosp. Electron. Syst., vol. 51, no. 1, pp. 713–732, 2015

  5. [13]

    A navigation message authentication proposal for the Galileo open service,

    I. Fern ´andez-Hern´andez, V . Rijmen, G. Seco-Granados, J. Simon, I. Rodr ´ıguez, and J. D. Calle, “A navigation message authentication proposal for the Galileo open service,”NAVIGATION, vol. 63, no. 1, pp. 85–102, 2016

  6. [14]

    Requirements for secure clock synchronization,

    L. Narula and T. E. Humphreys, “Requirements for secure clock synchronization,”IEEE J. Sel. Topics Signal Process., vol. 12, no. 4, pp. 749–762, 2018

  7. [15]

    Statistics of atomic frequency standards,

    D. W. Allan, “Statistics of atomic frequency standards,”Proc. IEEE, vol. 54, no. 2, pp. 221–230, 1966

  8. [16]

    W. J. Riley,Handbook of Frequency Stability Analysis, NIST Special Publication 1065. Boulder, CO: National Institute of Standards and Technology, 2008

  9. [17]

    Computing integrals involving the matrix exponential,

    C. F. Van Loan, “Computing integrals involving the matrix exponential,” IEEE Trans. Autom. Control, vol. 23, no. 3, pp. 395–404, 1978

  10. [18]

    Continuous inspection schemes,

    E. S. Page, “Continuous inspection schemes,”Biometrika, vol. 41, no. 1/2, pp. 100–115, 1954

  11. [19]

    Basseville and I

    M. Basseville and I. V . Nikiforov,Detection of Abrupt Changes: Theory and Application. Englewood Cliffs, NJ: Prentice Hall, 1993

  12. [20]

    Evaluation of the vulnerability of phasor measurement units to GPS spoofing attacks,

    D. P. Shepard, T. E. Humphreys, and A. A. Fansler, “Evaluation of the vulnerability of phasor measurement units to GPS spoofing attacks,”Int. J. Critical Infrastructure Protection, vol. 5, no. 3–4, pp. 146–153, 2012

  13. [21]

    Navstar GPS space segment / navigation user segment interfaces,

    Global Positioning System Directorate, “Navstar GPS space segment / navigation user segment interfaces,” Interface Specification IS-GPS-200, Rev. N, 2022

  14. [22]

    E. D. Kaplan and C. J. Hegarty,Understanding GPS/GNSS: Principles and Applications, 3rd ed. Norwood, MA: Artech House, 2017

  15. [23]

    Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System,

    J. A. V olpe National Transportation Systems Center, “Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System,” U.S. Department of Transportation, 2001

  16. [24]

    Executive Order 13905: strengthen- ing national resilience through responsible use of positioning, naviga- tion, and timing services,

    Executive Office of the President, “Executive Order 13905: strengthen- ing national resilience through responsible use of positioning, naviga- tion, and timing services,”Federal Register, vol. 85, no. 32, p. 9359, Feb. 2020

  17. [25]

    Measuring relays and protection equipment – Part 118-1: synchrophasor for power systems – measurements,

    IEC/IEEE, “Measuring relays and protection equipment – Part 118-1: synchrophasor for power systems – measurements,” IEC/IEEE 60255- 118-1:2018

  18. [26]

    Timing characteristics of pri- mary reference time clocks,

    International Telecommunication Union, “Timing characteristics of pri- mary reference time clocks,” ITU-T Recommendation G.8272, 2018

  19. [27]

    IEEE standard for a precision clock synchronization protocol for networked measurement and control systems,

    IEEE, “IEEE standard for a precision clock synchronization protocol for networked measurement and control systems,” IEEE Std 1588-2019, 2020

  20. [28]

    Kshana: an open, reproducible PNT-resilience simulator,

    C. Baweja, “Kshana: an open, reproducible PNT-resilience simulator,” software, version 0.19.0, AGPL-3.0-only, 2026. [Online]. Available: https://github.com/AshfordeOU/kshana

Pith tools

Reviewed June 25, 2026 · model on record in the stance chip above.