Pith. sign in

REVIEW 4 minor 52 references

Rigid-Covert GNSS Spoofing of UAV Swarms: A Structural Blind Spot, Its Detection Limit, and Absolute-Anchor Defenses

T0 review · 0 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read Relative-only drone defenses cannot see a common GNSS shift; trusted anchors restore absolute positions.

desk verdict A well-scoped, honest simulation paper that proves a real gauge blind spot in relative-only swarm defenses and quantifies an anchor-based detection floor; the recovery claim rests on an explicitly stated trusted-communication assumption that limits its practical envelope but not its scientific validity. read the letter →

arxiv 2608.06885 v1 pith:LB2NREZI submitted 2026-08-07 cs.CR cs.RO

classification cs.CRcs.RO
keywords GNSSspoofingUAVswarmsecuritygaugefreedomcooperativelocalizationanchor-basedrecoveryByzantinerobustnesschange-pointestimationrigid-covert
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Rigid-covert GNSS spoofing is the scenario in which an attacker shifts the reported positions of every drone in a swarm by one common, slowly growing offset. The paper proves this attack is invisible to any defense that checks only relative quantities—inter-drone distances and differences of reported positions—because a common translation leaves those quantities unchanged. It then shows that a small subset of drones carrying GNSS-independent absolute-position references ("anchors") breaks that blindness: an anchor-residual detector has a drift-dependent detection floor, and anchor-rooted geometry recovery restores the positions of the whole swarm, including drones with no anchor of their own. Onboard inertial or signal-quality monitors can raise an alarm but cannot say where the swarm actually is, so the paper positions recovery, not just detection, as the capability that matters. If correct, this means cooperative defenses need an independent absolute reference, and it quantifies exactly when such a reference makes a covert shift observable.

What carries the argument

The load-bearing identity is the gauge-freedom map $z_i \mapsto z_i + c$: for any common $c \in \mathbb{R}^2$, the pairwise report differences $\{z_i - z_j\}$ and the measured ranges $\{d_{ij}\}$ are unchanged, so any detector built from those relative quantities has the same output before and after the attack. This is the same observability structure that makes anchor-free network localization determined only up to a global rigid transform. The recovery machinery is classical multidimensional scaling on the range matrix, which fixes the formation's shape up to translation, rotation, and reflection, followed by a robust rigid alignment onto trusted anchors; with at least three honest anchors not lying on one line, the alignment resolves the reflection ambiguity and fixes the absolute frame for the entire swarm.

What would settle it

Take a swarm of eight small drones with motion-capture ground truth, clean inter-drone ranging, and four trusted absolute anchors, and drive a single software-defined-radio spoofer with a slow common ramp until reported GNSS positions drift by about 10 m. The paper predicts the relative-only baselines stay at chance while anchor-rooted recovery returns the four non-anchored drones to roughly 0.4 m; seeing the baselines detect the shift, or the recovery fail by many meters under these conditions, would contradict the central claims.

Watch

Extended reading notes

Core claim

The paper's central claim is Proposition 1: any detector that is a function only of the relative quantities $\{z_i - z_j\}$ and $\{d_{ij}\}$ is invariant under a common translation $z_i \mapsto z_i + c$, so a common-mode bias $b(t)$ is unobservable from relative channels alone. From this it follows that cooperative defenses such as distance verification and semidefinite-feasibility checks are at chance against a rigid-covert ramp, which the paper confirms empirically. The defense half is an anchor-rooted recovery pipeline: reconstruct the formation shape from inter-drone ranges with classical multidimensional scaling, align that shape to a trusted-anchor subset with a Byzantine-robust fit, and read off every drone's absolute position from the aligned frame. In eight-vehicle software-in-the-loop runs the pipeline cuts a reported-vs-true GNSS drift of about 10.1 m to a median recovery error of 0.39 m for non-anchored drones, and to 7.1 cm in the smaller rendered-vision setting under 3.2 m of drift. The paper also derives the ideal detection floor $2\gamma/(1 - t_s/T)$ for a calibrated anchor-residual detector, measures a matching slope (2.66 versus the predicted 2.67), and identifies an additional per-frame noise floor; all results are simulation-based, with no RF spoofing hardware or physical swarm.

Load-bearing premise

The defense collapses if the attacker can compromise or forge the trusted absolute-reference anchors or the inter-drone ranging channel; recovery also requires an honest majority of anchors, at least three of them not lying on one line, and enough clean history to separate anchor drift from the attack.

Editorial extensions

If this is right

  • Relative-only cooperative detectors, such as pairwise distance checks, consensus localization, and geometry-feasibility solvers, cannot detect a perfectly common, geometry-preserving GNSS offset; any defense against this attack class needs an independent absolute reference.
  • Adding one trusted anchor makes a common translation observable, and the slowest covert ramp a calibrated anchor detector can catch grows linearly with the anchor's own drift rate, scaled by the detection horizon, with an additional noise floor that persists even for a drift-free anchor.
  • Anchor-rooted recovery propagates absolute trust from a small anchored subset to the whole formation: under roughly 10.1 m of GNSS drift in eight-vehicle software-in-the-loop runs, non-anchored drones are recovered to a median error of 0.39 m.
  • Byzantine-robust alignment tolerates a minority of actively compromised anchors, with recovery at 0.31 m under 25% compromise, but collapses at an anchor majority, which the paper identifies as a fundamental barrier.
  • Recovery degrades gracefully under sparse range graphs down to about 35% density and under heavy-tailed ranging noise, while vision-based anchors are usable only inside their measured coverage envelope.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • By extension, any future fusion of relative-only sensors—bearing, optical flow, RSSI, or inter-drone ranges—inherits the same blindness, because the invariance argument applies to any function of relative quantities; only a measurement tied to an absolute external frame breaks it.
  • The constant-rate detection floor should not be read as a universal attacker bound: the paper's own experiments show that a back-loaded ramp delays time-to-detect by 5.7×, so a defender should also constrain displacement or energy budgets for nonlinear attack profiles.
  • The $\tau \to 0$ aliasing barrier suggests a constructive design rule: anchor modalities should have heterogeneous drift signatures, such as a fixed radio beacon combined with vision, so that an attack simultaneous with one anchor's drift remains separable by another modality.
  • A physical-hardware replication of the eight-vehicle experiment, with a real software-defined-radio spoofer and motion-capture ground truth, would be the natural next test, because the paper's anchor channel is modeled or rendered rather than transmitted over the air.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

0 major / 4 minor

Summary. The paper studies a common-mode GNSS spoofing attack on UAV swarms (RigidShift) that preserves all pairwise inter-drone distances, and shows that any cooperative defense based only on relative positions and measured ranges is structurally blind to it (Prop. 1, a gauge-freedom argument). It derives a detection floor for a calibrated anchor-residual detector, Eq. (1), and validates it in simulation (measured slope 2.66 vs. predicted 2.667). It then proposes a centralized anchor-rooted recovery pipeline (MDS + RANSAC) that reconstructs the absolute positions of non-anchored drones from trusted anchors and ranges, together with a joint estimator for anchor drift, attack rate, and onset. Validation spans statistical sweeps, ArduPilot software-in-the-loop, and Gazebo-rendered vision anchors; all evaluations are simulation-based. The paper is explicit about its assumptions and limitations: trusted anchors, an unforgeable UWB channel, non-collinear anchors, Byzantine minority, tau-to-zero aliasing, and majority anchor compromise.

Significance. The gauge-freedom argument is correct and provides a clean formal explanation for why relative-geometry cooperative defenses fail against a common-mode translation. The derivation of Eq. (1) is a useful quantitative security index, and the paper is careful to distinguish the derived drift term from the empirically fitted noise floor. The anchor-rooted recovery pipeline is a practical template, and the explicit characterization of failure modes (anchor drift, coverage, Byzantine anchors, dilution, tau-to-zero aliasing) is valuable. The paper ships a reproducible artifact with seed-fixed results, and the multi-tier validation (statistical, SITL, vision renders) is a strength. The main limitation is that the defense's practical envelope is narrower than the title may suggest, because it depends on an unforgeable ranging and anchor channel; this is disclosed but not stress-tested.

minor comments (4)
  1. [§2.2 and §10] The recovery pipeline in §6.1 consumes the range matrix D as ground truth, and §2.2 places the UWB ranging channel in the trusted computing base, but the manuscript does not evaluate the effect of a small fraction of corrupted (spoofed) range measurements. Since a capable GNSS spoofer could plausibly also inject UWB packets unless the channel is authenticated, please add a short robustness experiment with partial range forgery or state the assumption more prominently in the abstract and contributions.
  2. [§4, Figure 2] The validation of Eq. (1) uses only five drift levels, and the reported 95% CI for the slope is [2.09, 3.23], which is wide; please report the individual data points or increase the sweep resolution to make the agreement with the predicted slope 2.667 more compelling.
  3. [§6.2, Algorithm 1] The joint estimator is described as recovering the attack direction, but Table 7 reports only onset and ramp-rate accuracy; please add a direction-error metric to substantiate that claim.
  4. [§8.3] The rendered-vision multi-SITL capstone uses only five seeds; the reported standard deviation is useful, but please also provide per-seed median errors so the reader can judge the spread directly.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: Prop. 1 and Eq. (1) are derived from the stated model, and the one fitted component (v_noise) is explicitly labeled empirical, not a prediction.

full rationale

The central blindness claim (Prop. 1) is a direct consequence of the definition of a relative-only detector: a common translation leaves {z_i - z_j} and {d_ij} unchanged. The paper explicitly calls this an instantiation of standard network-localization theory [2] and disclaims novelty for the proposition, so it is not a renamed result presented as new. The detection-floor law, Eq. (1), follows algebraically from the stated residual model r(t)=|v(t-t_s)_+ - gamma t| and the calibration band derived from the drift-only end-of-horizon peak; it is not fitted from the simulation. The measured slope 2.66 is compared against the independently derived 2.667, and the confidence interval contains the predicted value; this is a model-validation fit, not a fitted parameter renamed as a prediction. The additive term v_noise in Eq. (2) is fitted to the same measured floor, but the paper states plainly that Eq. (2) is 'an operational (empirical) decomposition' and that the dependence of v_noise on sigma_a, T, and alpha is 'not separately derived.' This is a disclosed empirical component, not a concealed circular reduction. The recovery pipeline is evaluated against known simulated true positions, with anchors and ranges as inputs, and the reference list contains no self-citations that carry load-bearing argumentative weight. The trusted-computing-base assumptions in Sec. 2.2 are stated as explicit limitations, not used to back-derive the claimed results. Overall, the derivation chain is self-contained for the simulation-scoped claims made in the paper.

Assumptions & free parameters 2 free parameters · 8 assumptions · 0 invented entities

No new physical entities are introduced. The RigidShift threat model combines cited attacker capabilities, namely GNSS-WASP and the exact N<=9 formation-preserving bound, and the large-scale common shift is explicitly an idealized oracle. The main free parameters are the empirically fitted detector noise floor and the hand-chosen RANSAC inlier threshold; the central detection-limit law itself has no fitted free parameter in its slope.

free parameters (2)
  • v_noise detector-specific noise floor = approx. 1.3 cm/s at sigma_a=0.5 m, t_s/T=0.25
    Linear-regression intercept of the measured detection floors in Section 4; enters Eq. (2) as the additive detector noise floor. It is fitted to the same simulation data and explicitly presented as an operational, empirical decomposition rather than a derived quantity.
  • RANSAC inlier threshold = 1.5 m
    Hand-chosen inlier threshold in RANSACAlign, Section 7. It affects the Byzantine recovery results and tie-breaking, but does not feed the detection-limit law.
assumptions (8)
  • domain assumption The absolute anchor channel and the UWB inter-drone ranging channel are independent of GNSS and unforgeable by the attacker; communication and aggregation infrastructure are trusted.
    Stated in Section 2.2 and used throughout as the trusted computing base. If false, the detection floor and recovery pipeline no longer apply.
  • domain assumption An attacker can impose an exactly common, geometry-preserving GNSS offset on all drones; exact for N<=9, at larger scale via a wide-area multi-transmitter spoofer, and N=128 is treated as an ideal distributed-spoofer oracle.
    Sections 2.2 and 8.1. The structural blind spot is conditional on an exact common-mode shift; a deformation epsilon self-reveals through the relative channel.
  • domain assumption Anchor drift is modeled as a slow affine process with worst-case rate gamma, and the attack is modeled as a constant-rate ramp with a single onset; worst-case anchor drift is aligned with the attack direction.
    Required for the derivation of Eq. (1) in Section 4. The paper acknowledges that nonlinear attack profiles need a separate analysis.
  • domain assumption At most f anchors are Byzantine with f < m/2, and at least three non-collinear honest anchors are available; m >= max(2f+1, f+3).
    Section 6.1. Recovery and Byzantine-robust alignment depend on an honest majority and non-collinear anchor geometry.
  • standard math Classical MDS recovers the swarm shape up to a rigid transform from a complete or connected range matrix, and RANSAC robustly fits the alignment to trusted anchors.
    Used in Eq. (3) and Section 6.1; both are cited standard results from the localization and robust-estimation literature.
  • domain assumption GNSS, range, and anchor measurement noises are approximately Gaussian with stated variances; detector thresholds are calibrated at a 5% false-alarm quantile.
    Section 2.1 and Section 7. Heavy-tailed real-UWB errors are tested separately in Appendix C, but the main law and recovery estimates use the Gaussian model.
  • domain assumption The covert offset and recovery are modeled in the horizontal plane only; altitude is barometric and outside the threat model.
    Section 6.1 and Section 10. Vertical spoofing is not analyzed.
  • standard math Gauge freedom of relative localization: functions of relative quantities are invariant under common translation, and anchor-free localization is observable only up to a global rigid transform.
    Prop. 1 and Prop. 2 in Section 2.3, cited to network localization theory; this is the formal basis of the claimed structural blind spot.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Rigid-Covert GNSS Spoofing of UAV Swarms: A Structural Blind Spot, Its Detection Limit, and Absolute-Anchor Defenses." pith.science (2026). https://pith.science/paper/LB2NREZI

@misc{pith2026260806885,
  author       = {Pith},
  title        = {Pith review of: Rigid-Covert GNSS Spoofing of UAV Swarms: A Structural Blind Spot, Its Detection Limit, and Absolute-Anchor Defenses},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/LB2NREZI}},
  note         = {Machine review of arXiv:2608.06885}
}
abstract

Cooperative UAV-swarm defenses commonly cross-check GNSS positions against measured inter-drone geometry. We show that this relative-geometry channel has a structural blind spot: a common, slowly varying translation (a rigid-covert shift, RigidShift) preserves all pairwise distances and is therefore unobservable to any relative-only detector (a gauge-freedom argument). We validate this blindness on distance-verification and semidefinite-feasibility baselines, while explicitly distinguishing it from onboard inertial/GNSS monitors that can raise a bare alarm but cannot recover the swarm's true position. To quantify when an external reference restores observability, we derive the drift-dependent detection floor $2\gamma/(1-t_s/T)$ for a calibrated anchor-residual detector and empirically identify an additional detector-specific noise floor (measured slope 2.66 vs. predicted 2.67). We then present a centralized anchor-rooted recovery pipeline that reconstructs swarm geometry from inter-drone ranges, aligns it to a trusted-anchor subset with Byzantine-robust fitting, and recovers the absolute positions of non-anchored drones. A segmented estimator jointly estimates anchor drift, attack rate, and onset when no clean-epoch label is available. Across statistical simulations, ArduPilot software-in-the-loop experiments, and Gazebo experiments with rendered vision anchors, the method recovers the positions of non-anchored drones to a median error of 0.39 m (20 seeds) under approximately 10.1 m of GNSS drift, and to 7.1 cm (5 seeds) in the rendered-vision multi-SITL setting. We also characterize the explicit limits imposed by non-collinear anchor geometry, anchor coverage, $\tau\to0$ drift-attack aliasing, and majority anchor compromise. All evaluations are simulation-based and use no RF spoofing hardware or physical swarm.

Figures

Figures reproduced from arXiv: 2608.06885 by the authors.

Figure 1
Figure 1. RigidShift threat. A coordinated GNSS spoofer adds a slow, common offset 𝑏(𝑡) to every drone, so the whole formation drifts together as a rigid body—shown solid at its actual drifted position, with the vacated intended position as the faded ghost. Because every pairwise distance 𝑑𝑖𝑗 is preserved, a cooperative defense, which sees only relative quantities, finds no inconsistency; being gradual, the shift also stays u… view at source ↗
Figure 2
Figure 2. Detection-limit law validation: the measured floor [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Anchor-rooted recovery. A few drones carry an anchor (green): they see a fixed ground landmark, giving them a GNSS-independent estimate of their true position that a GNSS spoof cannot alter. The inter-drone ranges 𝑑𝑖𝑗 fix the swarm’s shape but not its absolute placement (the gauge freedom of [PITH_FULL_IMAGE:figures/full_fig_p006_3.png] view at source ↗
Figures from the paper (10 more)
Figure 4
Figure 4. Figure 4: Recovery and cooperation gain (low-rate 0–1.0 cm/s, 400 s Tier-2 SITL harvest, ArduPilot EKF-in-the-loop; 10 seeds/rate). Reported-vs-true error ramps with the covert attack, while anchor-rooted recovery holds both anchored (0.45 m) and non-anchored (0.56 m) drones nea…
Figure 5
Figure 5. Figure 5: Component ablation (Tier-1, 60 seeds, 95% CIs). (A) MDS+align provides recovery (11.7→0.37 m); RANSAC’s benefit is specific to a Byzantine minority (25%: 5.4→0.76 m) and disappears at the 50% barrier. (B) Bootstrap drift-correction restores detection (0.12→0.97) when a…
Figure 6
Figure 6. Figure 6: Closed-loop multi-SITL validation. (a) Under a [PITH_FULL_IMAGE:figures/full_fig_p011_6.png]
Figure 9
Figure 9. Figure 9: Drift aliasing (attack 2 cm/s). Only anchor drift aligned with the attack (≈ 𝑣/2) masks a memoryless detector; anti-aligned drift does not, and orthogonal drift only par￾tially [PITH_FULL_IMAGE:figures/full_fig_p013_9.png]
Figure 7
Figure 7. Figure 7: Combined ROC under the common-mode covert [PITH_FULL_IMAGE:figures/full_fig_p013_7.png]
Figure 8
Figure 8. Figure 8: Security index: the attacker’s undetectable ramp [PITH_FULL_IMAGE:figures/full_fig_p013_8.png]
Figure 11
Figure 11. Figure 11: The covert-blind region is a single corner. [PITH_FULL_IMAGE:figures/full_fig_p014_11.png]
Figure 12
Figure 12. Figure 12: Attack vs. anchor-fault attribution (Caveat 1, pre [PITH_FULL_IMAGE:figures/full_fig_p014_12.png]
Figure 14
Figure 14. Figure 14: Two anchor-failure modes. (a) Correlated (common-mode) anchor failure collapses detection from 1.0 to 0.17–0.36 as anchors increasingly fail together (0.17 at 10% co-failure), far sharper than independent dropout. (b) With a fixed anchor count, far-from-anchor recover…
Figure 15
Figure 15. Figure 15: Range-graph sparsity (𝑁=16, geodesic completion, 95% CIs). (A) Random ranging packet loss degrades recovery and eventually disconnects the graph. (B) Under a communication radius, recovery holds ≤ 0.5 m down to ≈35% range-graph density. All-pairs ranging is not requir…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references · 50 canonical work pages

  1. [1]

    ArduPilot Development Team. 2024. ArduPilot: Open Source Autopilot / Software-in-the-Loop (SITL). https://ardupilot.org

  2. [2]

    Goldenberg, A

    James Aspnes, Tolga Eren, David K. Goldenberg, A. Stephen Morse, Walter Whiteley, Yang Richard Yang, Brian D. O. Anderson, and Peter N. Belhumeur

  3. [3]

    Chakshu Baweja. 2026. A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing.arXiv:2606.24210(2026)

  4. [4]

    Siguo Bi, Kai Li, Shuyan Hu, Wei Ni, Cong Wang, and Xin Wang. 2024. Detec- tion and Mitigation of Position Spoofing Attacks on Cooperative UAV Swarm Formations.IEEE Transactions on Information Forensics and Security19 (2024). arXiv:2312.03787

  5. [5]

    Wenxin Chen, Yingfei Dong, and Zhenhai Duan. 2024. Impacts of a Single GPS Spoofer on Multiple Receivers: Formal Analysis and Experimental Evaluation. InProc. IEEE Consumer Communications & Networking Conf. (CCNC)

  6. [6]

    Wenxin Chen, Yingfei Dong, and Zhenhai Duan. 2025. GPS Swarm Spoofing: The- oretical Analysis and Practical Solutions. InProc. IEEE International Conference on Communications (ICC). Montreal, Canada

  7. [7]

    Hongjun Choi, Sayali Kate, Yousra Aafer, Xiangyu Zhang, and Dongyan Xu. 2020. Software-based Realtime Recovery from Sensor Attacks on Robotic Vehicles. In Proc. RAID. 349–364

  8. [8]

    Hongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei, Zhan Tu, Xiangyu Zhang, Dongyan Xu, and Xinyan Deng. 2018. Detecting Attacks Against Robotic Vehicles: A Control Invariant Approach. InProc. ACM CCS. 801–816

Show all 52 references
  1. [9]

    Pritam Dash, Mehdi Karimibiuki, and Karthik Pattabiraman. 2019. Out of Con- trol: Stealthy Attacks Against Robotic Vehicles Protected by Control-based Tech- niques. InProc. ACSAC. 660–672

  2. [10]

    Pritam Dash, Guanpeng Li, Zitao Chen, Mehdi Karimibiuki, and Karthik Pattabi- raman. 2021. PID-Piper: Recovering Robotic Vehicles from Physical Attacks. In Proc. IEEE/IFIP DSN. 26–38

  3. [11]

    Pritam Dash, Guanpeng Li, Mehdi Karimibiuki, and Karthik Pattabiraman. 2024. Diagnosis-guided Attack Recovery for Securing Robotic Vehicles from Sensor Deception Attacks. InProc. ACM AsiaCCS

  4. [12]

    Drew Davidson, Hao Wu, Rob Jellinek, Vikas Singh, and Thomas Ristenpart

  5. [13]

    Kapel Dev, Yash Madhwal, Sofia Shevelo, Pavel Osinenko, and Yury Yanovich

  6. [14]

    Anthony Finn, Mengjie Jia, Yanyan Li, and Jiawei Yuan. 2024. Detecting Stealthy GPS Spoofing Attack Against UAVs Using Onboard Sensors. InProc. IEEE INFO- COM Workshops

  7. [15]

    Fischler and Robert C

    Martin A. Fischler and Robert C. Bolles. 1981. Random Sample Consensus: A Paradigm for Model Fitting with Applications to Image Analysis and Automated Cartography.Commun. ACM24, 6 (1981), 381–395

  8. [16]

    Jaron Fontaine et al. 2020. UWB Dataset from an Office, Industrial and University Environment. https://github.com/JaronFontaine/UWB-dataset-from-an-office- industrial-and-university-environment. IDLab, Ghent University – imec

  9. [17]

    Humphreys, Brent M

    Todd E. Humphreys, Brent M. Ledvina, Mark L. Psiaki, Brady W. O’Hanlon, and Paul M. Kintner. 2008. Assessing the Spoofing Threat: Development of a Portable GPS Civilian Spoofer. InProc. ION GNSS

  10. [18]

    Kai Jansen, Nils Ole Tippenhauer, and Christina Pöpper. 2016. Multi-Receiver GPS Spoofing Detection: Error Models and Realization. InProc. Annual Computer Security Applications Conf. (ACSAC). 237–250

  11. [19]

    Kerns, Daniel P

    Andrew J. Kerns, Daniel P. Shepard, Jahshan A. Bhatti, and Todd E. Humphreys

  12. [20]

    Amir Khazraei, Henry Meng, and Miroslav Pajic. 2024. Black-box Stealthy GPS Attacks on Unmanned Aerial Vehicles. InProc. IEEE Conference on Decision and Control (CDC). arXiv:2409.11405

  13. [21]

    Nathan Koenig and Andrew Howard. 2004. Design and Use Paradigms for Gazebo, an Open-Source Multi-Robot Simulator. InProc. IEEE/RSJ IROS. 2149–2154

  14. [22]

    Fanxin Kong, Meng Xu, James Weimer, Oleg Sokolsky, and Insup Lee. 2018. Cyber-Physical System Checkpointing and Recovery. InProc. ACM/IEEE ICCPS. 22–31

  15. [23]

    LeBlanc, Haotian Zhang, Xenofon Koutsoukos, and Shreyas Sundaram

    Heath J. LeBlanc, Haotian Zhang, Xenofon Koutsoukos, and Shreyas Sundaram

  16. [24]

    Lifen Meng, Liang Zhang, Le Yang, and Wei Yang. 2023. A GPS-Adaptive Spoofing Detection Method for the Small UAV Cluster.Drones7, 7 (2023), 461

  17. [25]

    Giulia Michieletto, Francesco Formaggio, Angelo Cenedese, and Stefano Tomasin

  18. [26]

    Carlos Murguia and Justin Ruths. 2016. Characterization of a CUSUM Model- Based Sensor Attack Detector. InProc. IEEE 55th Conf. on Decision and Control (CDC). 1303–1309

  19. [27]

    Pavlo Mykytyn, Marcin Brzozowski, Zoya Dyka, and Peter Langendoerfer. 2023. GPS-Spoofing Attack Detection Mechanism for UAV Swarms.arXiv:2301.12766 (2023)

  20. [28]

    Shoei Nashimoto, Daisuke Suzuki, Takeshi Sugawara, and Kazuo Sakiyama. 2018. Sensor CON-Fusion: Defeating Kalman Filter in Signal Injection Attack. InProc. ACM AsiaCCS. 511–524

  21. [29]

    Juhwan Noh, Yujin Kwon, Yunmok Son, Hocheol Shin, Dohyun Kim, Jaeyeong Choi, and Yongdae Kim. 2019. Tractor Beam: Safe-hijacking of Consumer Drones with Adaptive GPS Spoofing.ACM Transactions on Privacy and Security22, 2 (2019), 1–26

  22. [30]

    E. S. Page. 1954. Continuous Inspection Schemes.Biometrika41, 1/2 (1954), 100–115

  23. [31]

    Deepak Kumar Panda and Weisi Guo. 2025. Real-Time Bayesian Detection of Drift-Evasive GNSS Spoofing in Reinforcement-Learning-Based UAV Deconflic- tion.arXiv:2507.11173(2025)

  24. [32]

    Fabio Pasqualetti, Florian Dörfler, and Francesco Bullo. 2013. Attack Detection and Identification in Cyber-Physical Systems.IEEE Trans. Automat. Control58, 11 (2013), 2715–2729

  25. [33]

    Psiaki and Todd E

    Mark L. Psiaki and Todd E. Humphreys. 2016. GNSS Spoofing and Detection. Proc. IEEE104, 6 (2016), 1258–1270

  26. [34]

    Raul Quiñonez, Jairo Giraldo, Luis Salazar, Erick Bauman, Alvaro Cárdenas, and Zhiqiang Lin. 2020. SAVIOR: Securing Autonomous Vehicles with Robust Physical Invariants. InProc. USENIX Security Symposium

  27. [35]

    Yunmok Son, Hocheol Shin, Dongkwan Kim, Youngseok Park, Juhwan Noh, Kibum Choi, Jungwoo Choi, and Yongdae Kim. 2015. Rocking Drones with Inten- tional Sound Noise on Gyroscopic Sensors. InProc. USENIX Security Symposium. 881–896

  28. [36]

    Usman Tariq, Tariq Ahamed Ahanger, and Kamran Shaukat. 2026. Tri-stream Multi-model Architecture for Real-time Detection of BeiDou Signal Manipulation in UAV Swarms.Scientific Reports16 (2026), 15802. doi:10.1038/s41598-026-46655- y

  29. [37]

    Usman Tariq and Kamran Shaukat. 2026. Mission-aware BeiDou Spoofing De- fense in UAV Swarms with LLM-assisted Context Validation.Frontiers in Com- munications and Networks7 (2026), 1760543. doi:10.3389/frcmn.2026.1760543

  30. [38]

    Christopher Tibaldo, Harshad Sathaye, Giovanni Camurati, and Srdjan Čap- kun. 2025. GNSS-WASP: GNSS Wide Area SPoofing. InProc. USENIX Security Symposium

  31. [39]

    Rasmussen, and Srdjan Čap- kun

    Nils Ole Tippenhauer, Christina Pöpper, Kasper B. Rasmussen, and Srdjan Čap- kun. 2011. On the Requirements for Successful GPS Spoofing Attacks. InProc. ACM CCS. 75–86

  32. [40]

    Yazhou Tu, Zhiqiang Lin, Insup Lee, and Xiali Hei. 2018. Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial Sensors. InProc. USENIX Security Symposium. 1545–1562

  33. [41]

    Yuzhi Wang, Anqi Yang, Xiaoming Chen, Pengjun Wang, Yu Wang, and Huazhong Yang. 2017. A Deep Learning Approach for Blind Drift Calibra- tion of Sensor Networks.IEEE Sensors Journal17, 13 (2017), 4158–4171. arXiv:1707.03682

  34. [42]

    Nian Xue, Liang Niu, Xianbin Hong, Zhen Li, Larissa Hoffaeller, and Christina Pöpper. 2020. DeepSIM: GPS Spoofing Detection on UAVs Using Satellite Imagery Matching. InProc. ACSAC. 304–319

  35. [43]

    Yingao Elaine Yao, Pritam Dash, and Karthik Pattabiraman. 2026. Framework for Discovering GPS Spoofing Attacks in Drone Swarms.arXiv:2606.00904(2026)

  36. [44]

    Cárdenas

    Lin Zhang, Xin Chen, Fanxin Kong, and Alvaro A. Cárdenas. 2020. Real-time Attack-Recovery for Cyber-Physical Systems Using Linear Approximations. In Proc. IEEE RTSS. 205–217

  37. [45]

    Lin Zhang, Pengyuan Lu, Fanxin Kong, Xin Chen, Oleg Sokolsky, and Insup Lee. 2021. Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear- Quadratic Regulator.ACM Transactions on Embedded Computing Systems20, 5s (2021), 1–24

  38. [46]

    Linfeng Zhong, T. Tang, R. Li, Z. Xia, and M. Tang. 2026. Enhancing the Resilience of UAV Networks against GPS Spoofing Attacks via Byzantine Distributed De- tection Algorithm.Reliability Engineering & System Safety269 (2026), 112101. doi:10.1016/j.ress.2025.112101 A Open Scie...

  39. [2006]

    A Theory of Network Localization.IEEE Transactions on Mobile Computing 5, 12 (2006), 1663–1678

  40. [2013]

    Park and Yoo

    Resilient Asymptotic Consensus in Robust Networks.IEEE Journal on Selected Areas in Communications31, 4 (2013), 766–781. Park and Yoo

  41. [2014]

    Unmanned Aircraft Capture and Control via GPS Spoofing.Journal of Field Robotics31, 4 (2014), 617–636

  42. [2016]

    InUSENIX WOOT

    Controlling UAVs with Sensor Input Spoofing Attacks. InUSENIX WOOT

  43. [2023]

    Robust Localization for Secure Navigation of UAV Formations Under GNSS Spoofing Attack.IEEE Transactions on Automation Science and Engineering20, 4 (2023), 2383–2396

  44. [2025]

    SwarmRaft: Leveraging Consensus for Robust Drone Swarm Coordination in GNSS-Degraded Environments.arXiv:2508.00622(2025)

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.