REVIEW 4 major objections 7 minor 2 cited by
GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers
T0 review · 4 major / 7 minor · reviewed 2026-08-04 · deepseek-v4-flash
Pith's one-line read Low-cost GNSS receivers can detect and classify jamming, spoofing, and blockage by plotting carrier-to-noise ratio against a calibrated received-power estimate.
desk verdict A solid, practical GNSS RFI monitoring paper whose jamming detection is well validated; the spoofing differentiation and cross-site threshold transferability claims are the weak spots, but it deserves serious peer review. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the two-dimensional detection region map in C/N0-versus-received-power space, anchored by a nominal distribution built from geostationary SBAS satellites. The received-power metric is produced by a four-step calibration chain: automatic gain control adjustment, temperature compensation to a 300 K reference, weighting of 500 kHz FFT bins by the L1 C/A power spectral density, and a lab-calibrated translation to absolute dBW/Hz. Detection thresholds are set by optimizing a boundary around the nominal distribution to meet a target false-positive rate, using importance-sampling/falsification to estimate rare-event probabilities. The "jamming path" — a roughly 1:1 slope
What would settle it
Collect a week of nominal (known interference-free) data from a receiver deployed at a site with substantially different multipath or antenna characteristics, recenter the nominal region to the local mean, and count the fraction of samples falling outside the paper's detection threshold. If that fraction significantly exceeds 10^-6, the transferability assumption is falsified.
Extended reading notes
Core claim
The central claim is that the two-dimensional metric C/N0 over received power separates four signal states using only observables a low-cost receiver already outputs. The paper shows that under jamming, C/N0 falls about 1 dB for every 1 dB of added noise, tracing a predictable "jamming path"; under blockage, C/N0 drops while noise power stays nominal; under spoofing, the receiver reports C/N0 values too high for the measured power, occupying an implausible region. The received-power axis is constructed from the receiver's internal FFT (SPAN) by applying AGC correction, temperature calibration, PSD-weighted integration over the GPS L1 C/A band, and a laboratory-derived conversion to dBW/Hz. T
Load-bearing premise
The spread of the nominal C/N0-versus-power distribution measured at the development site is assumed to transfer to new locations after only shifting its center, so if local multipath, antenna differences, or receiver variability change that spread, the claimed one-in-a-million false-positive rate will not hold.
Editorial extensions
If this is right
- If the method holds up, a dense network of sub-$400 receivers can monitor airports and other critical infrastructure for GNSS interference without expensive multi-beam antenna systems.
- Thresholds can be tuned to any desired false-positive rate, letting operators trade sensitivity against nuisance alarms.
- Spoofing can be flagged without pseudorange-level authentication whenever measured power and C/N0 are inconsistent; targeted weak spoofing remains a limitation.
- The same two-dimensional space can flag installation problems (the "unrealistic" region), helping maintain data quality in a monitoring network.
Reading between the lines
- A testable extension is to re-fit the full covariance of the nominal distribution at each new site rather than shifting only its center; comparing false-positive rates would tell whether the threshold shape is truly universal.
- The paper's linear "jamming path" suggests the method could estimate interference power from the displacement of a measured point, which the authors do not fully exploit.
- For moving platforms (e.g., the ship deployment), motion-induced C/N0 variation blurs the nominal region; a motion-compensated version might be needed for mobile monitoring.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a low-cost GNSS RFI monitoring methodology based on a two-dimensional metric formed from carrier-to-noise density (C/N0) and a calibrated received-power estimate derived from u-blox F9P SPAN data. The authors describe a calibration chain (AGC correction, temperature compensation, PSD-weighted bin aggregation, and absolute power conversion), define detection and classification regions in the C/N0-versus-received-power plane, and set a disturbance threshold using a Gaussian fit and importance-sampling falsification to target a 1-in-1,000,000 false-positive rate. The method is validated with a controlled jamming/spoofing exercise in Norway, which provides ground truth, and applied to uncontrolled data from northern Poland and the southeastern Mediterranean. The central claim is that, with proper calibration, COTS-based monitoring can reliably detect and distinguish nominal, jammed, spoofed, and blocked signal conditions.
Significance. If the result holds, the paper offers a meaningful contribution to scalable RFI monitoring: a dense network of sub-$400 receivers could fill a gap between expensive airport-grade systems and satellite/ADS-B-based approaches. The controlled Norway validation is a genuine strength: the detection thresholds were developed from Stanford data alone, and the Norway evaluation is therefore independent. The overall jamming detection accuracy of 99.4% (Table 2) and the near-perfect RFI detection in the spoofing test (Table 3) are encouraging. The paper is also candid about known weaknesses, including low spoofing-characterization sensitivity (42.1%) and the heuristic jamming/spoofing boundary. However, the central portability claim—that threshold transfer across sites requires only a mean shift—rests on an unexamined assumption of covariance invariance, and the calibration curves are presented without uncertainty quantification. These issues do not invalidate the core concept but need addressing before the method can be claimed as a turnkey monitoring solution.
major comments (4)
- [3.3/4] The threshold-transferability claim is load-bearing and is not supported by the presented evidence. Section 3.3 states that 'once the nominal region is correctly centered for a given setup, no changes are needed to the RFI detection thresholds.' Section 4 then applies only a mean re-centering based on local nominal data. The threshold in Section 3.1 was optimized using the Stanford nominal distribution's full shape (mean and covariance) to achieve a 1-in-1,000,000 false-positive rate. If the spread or orientation of the nominal distribution changes with site, antenna, multipath environment, or local RF conditions, the optimized threshold will not deliver the claimed false-positive rate. The Norway no-RFI result (Table 2: 0 false positives out of 7000 samples) is far too small to validate a 1e-6 false-positive probability, and no nominal-covariance comparison across Stanford, Norway, Pola
- [3.1] The false-positive rate estimation relies on importance sampling with a proposal distribution and 'fuzzing', but the manuscript does not specify the proposal distribution, the number of rollouts, or the convergence criteria. The nominal distribution is fit to a multivariate Gaussian and discretized to a 1-dB/1-dB-Hz grid, yet no goodness-of-fit test or sensitivity analysis is presented. Given that the 1-in-1,000,000 false-positive rate is a headline claim for the threshold design, the statistical procedure needs more detail: at minimum, report the proposal distribution, sample size, and confidence bounds on the estimated false-positive rate, and justify the Gaussian assumption against the observed multipath-influenced data shown in Figure 1.
- [2.2] The calibration chain (AGC offset multiplier 3.7x SPAN PGA in Section 2.2.1, temperature curve in Section 2.2.2, SPAN-to-dBW/Hz conversion in Section 2.2.4) is essential to the classification regions, but the fitted parameters are presented without error bars, validation on multiple receiver units, or analysis of how calibration uncertainty propagates into the detection/classification boundaries. For a paper claiming a framework adaptable to other COTS receivers, the receiver-specific nature of these constants and the resulting uncertainty in the absolute received-power measurement must be quantified. Otherwise, a systematically biased power estimate could shift points across the jamming/spoofing or nominal/jamming boundaries without the user knowing.
- [Table 3/Conclusion] The spoofing-characterization sensitivity of 42.1% means that the method fails to characterize the majority of spoofing events, even though it detects RFI nearly perfectly. The abstract and conclusion claim the method can 'differentiate' spoofed signal conditions, which overstates the results. The authors acknowledge the limitation in the text, but the central claim of a monitoring methodology for 'jamming and spoofing' should be balanced by a clear statement that spoofing characterization is currently unreliable for weak or non-capturing spoofing signals. The proposed pseudorange-consistency checks are listed as future work; until then, the paper should either downgrade the classification claim or present the work as primarily a jamming/blockage detector with an ancillary spoofing indicator.
minor comments (7)
- [Abstract/Intro] The abstract says 'southeast soars' should be 'southeast shores' (also appears in the Introduction).
- [Section 3.1] Equation labeling is inconsistent: the false-positive estimation equation is labeled '(1)' but it is the third numbered equation in the paper (after Eq. (1) in Section 2.2.3 and Eq. (2) in Section 2.2.3). Renumber accordingly.
- [Section 3.1] The indicator function in Eq. (3) uses a nonstandard symbol '⊮'; use the standard indicator notation 1{...} or define the notation.
- [Figure 5] Caption typo: 'GPA L1 C/A' should be 'GPS L1 C/A'.
- [Section 2.3] Figure 9 is described as a 24-hour observation, but Figure 10 shows data sampled from ten months. It would be helpful to explicitly state that Figure 9 is the same-day elevation-filtered subset from which the move to SBAS was motivated.
- [Section 4.1] The description of Table 2's 'Full Day' row could mention that the false positives (54) are dominated by the step-RFI recovery period; currently the text explains this only qualitatively.
- [References] References to 'Kochenderfer et al., 2025' and 'Kochenderfer & Wheeler, 2019' are appropriate, but the page numbers or chapter sections would help readers locate the importance-sampling formulation.
Circularity Check
No significant circularity: the detection regions and thresholds are fixed from Stanford data and then validated on independent external datasets.
full rationale
The paper's central derivation chain is: (1) calibrate receiver observables (C/N0 and SPAN-based received power) using lab measurements, (2) fit a nominal multivariate Gaussian to Stanford C/N0-over-received-power data, (3) optimize a disturbance detection threshold to a 1e-6 false-positive design target using fuzzing/importance sampling, (4) define jamming/spoofing/blocked regions from a lab-measured jamming slope and the 27 dB-Hz MOPS limit, and (5) apply these fixed regions to Norway, Poland, and the Mediterranean after only re-centering the nominal region. No step reduces to its own inputs by construction. The calibration constants (AGC offset, temperature curve, SPAN-to-dBW/Hz mapping) are fitted to receiver observables, not to classification outcomes. The detection threshold is optimized to the Stanford nominal distribution, but the external validation does not re-fit the detection boundary; the paper explicitly states: 'only live-sky and lab-based data from Stanford were used to develop the detection thresholds; therefore, the evaluation presented here is entirely independent of the training data.' The Norway controlled tests provide independent ground-truth validation, and the Poland/Mediterranean deployments are real-world demonstrations. The 1e-6 false-positive rate is a model-relative design target for the threshold fit, not an externally predicted quantity, so it is not a fitted-input-called-prediction. The self-citations (Lo et al. 2021; Kriezis et al. 2024a/b; 2025) are contextual and not load-bearing; the viability claim rests on the lab calibration and external benchmarks rather than on an unverified self-citation chain. The main limitation is that the covariance of the nominal distribution is assumed transferable across sites after only a mean shift, which is a robustness/transferability concern, not circularity. Therefore the paper is essentially self-contained against external benchmarks and the circularity score is low.
Assumptions & free parameters
free parameters (7)
- AGC offset multiplier =
3.7 (x SPAN PGA)
- Temperature calibration curve coefficients =
not stated
- SPAN-to-dBW/Hz conversion curve =
curve fit (Fig. 7)
- Nominal Gaussian mean and covariance =
not stated
- Detection threshold contour =
optimized contour (Fig. 12)
- Spoofing boundary line =
line from nominal top-right to 27 dB-Hz
- Jamming path slope =
~1 dB C/N0 per dB power
assumptions (7)
- domain assumption The SPAN FFT output, after AGC adjustment, linearly represents received power density.
- domain assumption A single temperature correction curve applies across all sites and seasons.
- domain assumption The nominal C/N0-over-received-power distribution is well approximated by a multivariate Gaussian.
- domain assumption The shape (covariance) of the nominal distribution transfers across sites after a mean shift.
- domain assumption Jamming causes a 1 dB/dB decrease of C/N0 with received power.
- domain assumption Spoofed signals cause implausibly high C/N0 relative to received power.
- standard math Importance sampling with the fuzzing proposal distribution gives unbiased failure probability estimates.
Cite this review
Pith. "Pith review of GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers." pith.science (2026). https://pith.science/paper/OZNVX52R
@misc{pith2026250913600,
author = {Pith},
title = {Pith review of: GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers},
year = {2026},
howpublished = {\url{https://pith.science/paper/OZNVX52R}},
note = {Machine review of arXiv:2509.13600}
}
read the original abstract
The Global Navigation Satellite System (GNSS) is increasingly vulnerable to radio frequency interference (RFI), including jamming and spoofing, which threaten the integrity of navigation and timing services. This paper presents a methodology for detecting and classifying RFI events using low-cost commercial off-the-shelf (COTS) GNSS receivers. By combining carrier-to-noise ratio (C/N0) measurements with a calibrated received power metric, a two-dimensional detection space is constructed to identify and distinguish nominal, jammed, spoofed, and blocked signal conditions. The method is validated through both controlled jamming tests in Norway and real-world deployments in Poland, and the Southeast Mediterranean which have experienced such conditions. Results demonstrate that COTS-based detection, when properly calibrated, offers a viable and effective approach for GNSS RFI monitoring.
Forward citations
Cited by 2 Pith papers
-
Wide-Area GNSS Interference Monitoring with CYGNSS GNSS-R Delay-Doppler Noise Floor Observations
Maximum aggregation of CYGNSS DDM noise floors detects more GNSS interference epochs than mean or kurtosis methods in documented jamming tests and persistent RFI regions.
-
Wide-Area GNSS Interference Monitoring with CYGNSS GNSS-R Delay-Doppler Noise Floor Observations
Replacing the mean with the maximum of CYGNSS's four channel-wise DDM noise floors flags more GNSS interference events, including weak partial-channel cases, but validation is limited by a data-fitted threshold and mi...
Reference graph
Works this paper leans on
-
[1]
Received: Revised: Accepted: DOI: 10.1109/xxx.xx.xxxx R E G U L A R P A P E R S GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers Argyris Kriezis1 | Yu-Hsuan Chen1 | Dennis Akos1,2 | Sherman Lo1 | Todd Walter1 1Stanford University 2University of Colorado, Boulder Correspondence Argyris Kriezis Email: akriezis@stanford.edu Abstract TheGlob...
arXiv 2019
-
[62]
Gebrekidan, S. (2023). Electronic warfare confounds civilian pilots, far from any battlefield.The New York Times. Goward, D. (2023).Dhs report on denver jamming – more questions than answers [Accessed: 2025-05-06].https://rntfnd.org/ 2023/01/12/dhs-report-on-denver-jamming-more-questions-than-answers-gps-world/ Hwang, P., & McGraw, G. (2014). Receiver aut...
arXiv 2023
-
[159]
(2022, March).Assessment of radio frequency interference relevant to the gnss (RTCA/DO- 235C). RTCA, Inc. San Miguel, N. R., Chen, Y.-H., Lo, S., Walter, T., & Akos, D. (2023). Calibration of rfi detection levels in a low-cost gnss monitor. 2023 IEEE/ION Position, Location and Navigation Symposium (PLANS) , 520–535.https://doi.org/10.1109/ PLANS53410.2023...
arXiv 2022
-
[2024]
, 3348–3360.https://doi.org/https://doi.org/10.33012/2024.19713 Kriezis, A., Chen, Y., Lo, S., & Walter, T. (2024a). Identifying low cost GNSS monitor metrics for robust RFI detection.Pro- ceedings of the International Technical Meeting of The Institute of Navigation, 426–440.https://doi.org/https://doi.org/ 10.33012/2024.19542 Kriezis, A., Chen, Y.-H., A...
arXiv 2024
Reviewed August 4, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.