Pith. sign in

REVIEW 4 major objections 7 minor 2 cited by

GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers

T0 review · 4 major / 7 minor · reviewed 2026-08-04 · deepseek-v4-flash

Pith's one-line read Low-cost GNSS receivers can detect and classify jamming, spoofing, and blockage by plotting carrier-to-noise ratio against a calibrated received-power estimate.

desk verdict A solid, practical GNSS RFI monitoring paper whose jamming detection is well validated; the spoofing differentiation and cross-site threshold transferability claims are the weak spots, but it deserves serious peer review. read the letter →

arxiv 2509.13600 v2 pith:OZNVX52R submitted 2025-09-17 eess.SP

classification eess.SP
keywords GNSSRFImonitoringjammingdetectionspoofingC/N0receivedpowerCOTSreceiversSBAS
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that a low-cost commercial GNSS receiver, once its internal power measurement is calibrated, can reliably detect and classify radio-frequency interference: jamming, spoofing, and simple signal blockage. The proposed method plots each satellite's carrier-to-noise ratio (C/N0) against a calibrated received-power estimate, forming a two-dimensional space where nominal, jammed, blocked, and spoofed conditions fall in distinct regions. Using geostationary SBAS satellites keeps the nominal distribution tight, and thresholds are tuned to a one-in-a-million false-positive rate. The method is validated with controlled jamming tests and two real-world deployments, reporting detection accuracy above 99% in the controlled setting.

What carries the argument

The load-bearing object is the two-dimensional detection region map in C/N0-versus-received-power space, anchored by a nominal distribution built from geostationary SBAS satellites. The received-power metric is produced by a four-step calibration chain: automatic gain control adjustment, temperature compensation to a 300 K reference, weighting of 500 kHz FFT bins by the L1 C/A power spectral density, and a lab-calibrated translation to absolute dBW/Hz. Detection thresholds are set by optimizing a boundary around the nominal distribution to meet a target false-positive rate, using importance-sampling/falsification to estimate rare-event probabilities. The "jamming path" — a roughly 1:1 slope

What would settle it

Collect a week of nominal (known interference-free) data from a receiver deployed at a site with substantially different multipath or antenna characteristics, recenter the nominal region to the local mean, and count the fraction of samples falling outside the paper's detection threshold. If that fraction significantly exceeds 10^-6, the transferability assumption is falsified.

Watch

Extended reading notes

Core claim

The central claim is that the two-dimensional metric C/N0 over received power separates four signal states using only observables a low-cost receiver already outputs. The paper shows that under jamming, C/N0 falls about 1 dB for every 1 dB of added noise, tracing a predictable "jamming path"; under blockage, C/N0 drops while noise power stays nominal; under spoofing, the receiver reports C/N0 values too high for the measured power, occupying an implausible region. The received-power axis is constructed from the receiver's internal FFT (SPAN) by applying AGC correction, temperature calibration, PSD-weighted integration over the GPS L1 C/A band, and a laboratory-derived conversion to dBW/Hz. T

Load-bearing premise

The spread of the nominal C/N0-versus-power distribution measured at the development site is assumed to transfer to new locations after only shifting its center, so if local multipath, antenna differences, or receiver variability change that spread, the claimed one-in-a-million false-positive rate will not hold.

Editorial extensions

If this is right

  • If the method holds up, a dense network of sub-$400 receivers can monitor airports and other critical infrastructure for GNSS interference without expensive multi-beam antenna systems.
  • Thresholds can be tuned to any desired false-positive rate, letting operators trade sensitivity against nuisance alarms.
  • Spoofing can be flagged without pseudorange-level authentication whenever measured power and C/N0 are inconsistent; targeted weak spoofing remains a limitation.
  • The same two-dimensional space can flag installation problems (the "unrealistic" region), helping maintain data quality in a monitoring network.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A testable extension is to re-fit the full covariance of the nominal distribution at each new site rather than shifting only its center; comparing false-positive rates would tell whether the threshold shape is truly universal.
  • The paper's linear "jamming path" suggests the method could estimate interference power from the displacement of a measured point, which the authors do not fully exploit.
  • For moving platforms (e.g., the ship deployment), motion-induced C/N0 variation blurs the nominal region; a motion-compensated version might be needed for mobile monitoring.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. The paper presents a low-cost GNSS RFI monitoring methodology based on a two-dimensional metric formed from carrier-to-noise density (C/N0) and a calibrated received-power estimate derived from u-blox F9P SPAN data. The authors describe a calibration chain (AGC correction, temperature compensation, PSD-weighted bin aggregation, and absolute power conversion), define detection and classification regions in the C/N0-versus-received-power plane, and set a disturbance threshold using a Gaussian fit and importance-sampling falsification to target a 1-in-1,000,000 false-positive rate. The method is validated with a controlled jamming/spoofing exercise in Norway, which provides ground truth, and applied to uncontrolled data from northern Poland and the southeastern Mediterranean. The central claim is that, with proper calibration, COTS-based monitoring can reliably detect and distinguish nominal, jammed, spoofed, and blocked signal conditions.

Significance. If the result holds, the paper offers a meaningful contribution to scalable RFI monitoring: a dense network of sub-$400 receivers could fill a gap between expensive airport-grade systems and satellite/ADS-B-based approaches. The controlled Norway validation is a genuine strength: the detection thresholds were developed from Stanford data alone, and the Norway evaluation is therefore independent. The overall jamming detection accuracy of 99.4% (Table 2) and the near-perfect RFI detection in the spoofing test (Table 3) are encouraging. The paper is also candid about known weaknesses, including low spoofing-characterization sensitivity (42.1%) and the heuristic jamming/spoofing boundary. However, the central portability claim—that threshold transfer across sites requires only a mean shift—rests on an unexamined assumption of covariance invariance, and the calibration curves are presented without uncertainty quantification. These issues do not invalidate the core concept but need addressing before the method can be claimed as a turnkey monitoring solution.

major comments (4)
  1. [3.3/4] The threshold-transferability claim is load-bearing and is not supported by the presented evidence. Section 3.3 states that 'once the nominal region is correctly centered for a given setup, no changes are needed to the RFI detection thresholds.' Section 4 then applies only a mean re-centering based on local nominal data. The threshold in Section 3.1 was optimized using the Stanford nominal distribution's full shape (mean and covariance) to achieve a 1-in-1,000,000 false-positive rate. If the spread or orientation of the nominal distribution changes with site, antenna, multipath environment, or local RF conditions, the optimized threshold will not deliver the claimed false-positive rate. The Norway no-RFI result (Table 2: 0 false positives out of 7000 samples) is far too small to validate a 1e-6 false-positive probability, and no nominal-covariance comparison across Stanford, Norway, Pola
  2. [3.1] The false-positive rate estimation relies on importance sampling with a proposal distribution and 'fuzzing', but the manuscript does not specify the proposal distribution, the number of rollouts, or the convergence criteria. The nominal distribution is fit to a multivariate Gaussian and discretized to a 1-dB/1-dB-Hz grid, yet no goodness-of-fit test or sensitivity analysis is presented. Given that the 1-in-1,000,000 false-positive rate is a headline claim for the threshold design, the statistical procedure needs more detail: at minimum, report the proposal distribution, sample size, and confidence bounds on the estimated false-positive rate, and justify the Gaussian assumption against the observed multipath-influenced data shown in Figure 1.
  3. [2.2] The calibration chain (AGC offset multiplier 3.7x SPAN PGA in Section 2.2.1, temperature curve in Section 2.2.2, SPAN-to-dBW/Hz conversion in Section 2.2.4) is essential to the classification regions, but the fitted parameters are presented without error bars, validation on multiple receiver units, or analysis of how calibration uncertainty propagates into the detection/classification boundaries. For a paper claiming a framework adaptable to other COTS receivers, the receiver-specific nature of these constants and the resulting uncertainty in the absolute received-power measurement must be quantified. Otherwise, a systematically biased power estimate could shift points across the jamming/spoofing or nominal/jamming boundaries without the user knowing.
  4. [Table 3/Conclusion] The spoofing-characterization sensitivity of 42.1% means that the method fails to characterize the majority of spoofing events, even though it detects RFI nearly perfectly. The abstract and conclusion claim the method can 'differentiate' spoofed signal conditions, which overstates the results. The authors acknowledge the limitation in the text, but the central claim of a monitoring methodology for 'jamming and spoofing' should be balanced by a clear statement that spoofing characterization is currently unreliable for weak or non-capturing spoofing signals. The proposed pseudorange-consistency checks are listed as future work; until then, the paper should either downgrade the classification claim or present the work as primarily a jamming/blockage detector with an ancillary spoofing indicator.
minor comments (7)
  1. [Abstract/Intro] The abstract says 'southeast soars' should be 'southeast shores' (also appears in the Introduction).
  2. [Section 3.1] Equation labeling is inconsistent: the false-positive estimation equation is labeled '(1)' but it is the third numbered equation in the paper (after Eq. (1) in Section 2.2.3 and Eq. (2) in Section 2.2.3). Renumber accordingly.
  3. [Section 3.1] The indicator function in Eq. (3) uses a nonstandard symbol '⊮'; use the standard indicator notation 1{...} or define the notation.
  4. [Figure 5] Caption typo: 'GPA L1 C/A' should be 'GPS L1 C/A'.
  5. [Section 2.3] Figure 9 is described as a 24-hour observation, but Figure 10 shows data sampled from ten months. It would be helpful to explicitly state that Figure 9 is the same-day elevation-filtered subset from which the move to SBAS was motivated.
  6. [Section 4.1] The description of Table 2's 'Full Day' row could mention that the false positives (54) are dominated by the step-RFI recovery period; currently the text explains this only qualitatively.
  7. [References] References to 'Kochenderfer et al., 2025' and 'Kochenderfer & Wheeler, 2019' are appropriate, but the page numbers or chapter sections would help readers locate the importance-sampling formulation.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the detection regions and thresholds are fixed from Stanford data and then validated on independent external datasets.

full rationale

The paper's central derivation chain is: (1) calibrate receiver observables (C/N0 and SPAN-based received power) using lab measurements, (2) fit a nominal multivariate Gaussian to Stanford C/N0-over-received-power data, (3) optimize a disturbance detection threshold to a 1e-6 false-positive design target using fuzzing/importance sampling, (4) define jamming/spoofing/blocked regions from a lab-measured jamming slope and the 27 dB-Hz MOPS limit, and (5) apply these fixed regions to Norway, Poland, and the Mediterranean after only re-centering the nominal region. No step reduces to its own inputs by construction. The calibration constants (AGC offset, temperature curve, SPAN-to-dBW/Hz mapping) are fitted to receiver observables, not to classification outcomes. The detection threshold is optimized to the Stanford nominal distribution, but the external validation does not re-fit the detection boundary; the paper explicitly states: 'only live-sky and lab-based data from Stanford were used to develop the detection thresholds; therefore, the evaluation presented here is entirely independent of the training data.' The Norway controlled tests provide independent ground-truth validation, and the Poland/Mediterranean deployments are real-world demonstrations. The 1e-6 false-positive rate is a model-relative design target for the threshold fit, not an externally predicted quantity, so it is not a fitted-input-called-prediction. The self-citations (Lo et al. 2021; Kriezis et al. 2024a/b; 2025) are contextual and not load-bearing; the viability claim rests on the lab calibration and external benchmarks rather than on an unverified self-citation chain. The main limitation is that the covariance of the nominal distribution is assumed transferable across sites after only a mean shift, which is a robustness/transferability concern, not circularity. Therefore the paper is essentially self-contained against external benchmarks and the circularity score is low.

Assumptions & free parameters 7 free parameters · 7 assumptions · 0 invented entities

The central claim relies on several calibration constants fit to receiver data (AGC offset, temperature curve, SPAN-to-power curve), a nominal-distribution fit, and an optimized threshold. None of these are fit to the external validation outcomes, so circularity is low, but they are site- and hardware-specific and would need re-derivation for new deployments. The paper introduces no new physical entities.

free parameters (7)
  • AGC offset multiplier = 3.7 (x SPAN PGA)
    Derived from a single observed AGC event in Section 2.2.1; applied to all SPAN bins; no uncertainty given.
  • Temperature calibration curve coefficients = not stated
    Fit to year-round Stanford outdoor data in Section 2.2.2; used to normalize measurements to 300 K; curve equation not given.
  • SPAN-to-dBW/Hz conversion curve = curve fit (Fig. 7)
    From lab AWGN experiment in Section 2.2.4 mapping processed SPAN output to true power density; fit equation and residuals not shown.
  • Nominal Gaussian mean and covariance = not stated
    Fit to 10 months of SBAS SV 131 C/N0 and power data at Stanford in Section 3.1; defines the nominal region and threshold.
  • Detection threshold contour = optimized contour (Fig. 12)
    Nelder-Mead optimization on the nominal distribution to achieve 1e-6 false-positive rate in Section 3.1; contour not given numerically.
  • Spoofing boundary line = line from nominal top-right to 27 dB-Hz
    Heuristic rule in Section 3.2; no derivation or sensitivity analysis.
  • Jamming path slope = ~1 dB C/N0 per dB power
    Observed in a lab experiment in Section 2.3.1; used to locate the jamming region.
assumptions (7)
  • domain assumption The SPAN FFT output, after AGC adjustment, linearly represents received power density.
    Section 2.2: receiver manufacturer does not document the mapping; inferred from observations.
  • domain assumption A single temperature correction curve applies across all sites and seasons.
    Section 2.2.2: fit at Stanford, applied to Norway, Poland, and the Mediterranean.
  • domain assumption The nominal C/N0-over-received-power distribution is well approximated by a multivariate Gaussian.
    Section 3.1: used for threshold optimization and importance sampling.
  • domain assumption The shape (covariance) of the nominal distribution transfers across sites after a mean shift.
    Section 4: only the center is re-calibrated locally, not the covariance or thresholds.
  • domain assumption Jamming causes a 1 dB/dB decrease of C/N0 with received power.
    Section 2.3.1: lab result; basis for the jamming path.
  • domain assumption Spoofed signals cause implausibly high C/N0 relative to received power.
    Section 3.2: basis for the spoofing region.
  • standard math Importance sampling with the fuzzing proposal distribution gives unbiased failure probability estimates.
    Section 3.1: standard Monte Carlo importance sampling (Kochenderfer et al., 2025).

how reviews work

0 comments
Cite this review

Pith. "Pith review of GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers." pith.science (2026). https://pith.science/paper/OZNVX52R

@misc{pith2026250913600,
  author       = {Pith},
  title        = {Pith review of: GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/OZNVX52R}},
  note         = {Machine review of arXiv:2509.13600}
}
read the original abstract

The Global Navigation Satellite System (GNSS) is increasingly vulnerable to radio frequency interference (RFI), including jamming and spoofing, which threaten the integrity of navigation and timing services. This paper presents a methodology for detecting and classifying RFI events using low-cost commercial off-the-shelf (COTS) GNSS receivers. By combining carrier-to-noise ratio (C/N0) measurements with a calibrated received power metric, a two-dimensional detection space is constructed to identify and distinguish nominal, jammed, spoofed, and blocked signal conditions. The method is validated through both controlled jamming tests in Norway and real-world deployments in Poland, and the Southeast Mediterranean which have experienced such conditions. Results demonstrate that COTS-based detection, when properly calibrated, offers a viable and effective approach for GNSS RFI monitoring.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Wide-Area GNSS Interference Monitoring with CYGNSS GNSS-R Delay-Doppler Noise Floor Observations

    eess.SP 2026-03 conditional novelty 4.0 of 10

    Maximum aggregation of CYGNSS DDM noise floors detects more GNSS interference epochs than mean or kurtosis methods in documented jamming tests and persistent RFI regions.

  2. Wide-Area GNSS Interference Monitoring with CYGNSS GNSS-R Delay-Doppler Noise Floor Observations

    eess.SP 2026-03 conditional novelty 4.0 of 10

    Replacing the mean with the maximum of CYGNSS's four channel-wise DDM noise floors flags more GNSS interference events, including weak partial-channel cases, but validation is limited by a data-fitted threshold and mi...

Reference graph

Works this paper leans on

4 extracted references · 1 linked inside Pith · cited by 1 Pith paper

  1. [1]

    jamming path,

    Received: Revised: Accepted: DOI: 10.1109/xxx.xx.xxxx R E G U L A R P A P E R S GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers Argyris Kriezis1 | Yu-Hsuan Chen1 | Dennis Akos1,2 | Sherman Lo1 | Todd Walter1 1Stanford University 2University of Colorado, Boulder Correspondence Argyris Kriezis Email: akriezis@stanford.edu Abstract TheGlob...

  2. [62]

    Gebrekidan, S. (2023). Electronic warfare confounds civilian pilots, far from any battlefield.The New York Times. Goward, D. (2023).Dhs report on denver jamming – more questions than answers [Accessed: 2025-05-06].https://rntfnd.org/ 2023/01/12/dhs-report-on-denver-jamming-more-questions-than-answers-gps-world/ Hwang, P., & McGraw, G. (2014). Receiver aut...

  3. [159]

    RTCA, Inc

    (2022, March).Assessment of radio frequency interference relevant to the gnss (RTCA/DO- 235C). RTCA, Inc. San Miguel, N. R., Chen, Y.-H., Lo, S., Walter, T., & Akos, D. (2023). Calibration of rfi detection levels in a low-cost gnss monitor. 2023 IEEE/ION Position, Location and Navigation Symposium (PLANS) , 520–535.https://doi.org/10.1109/ PLANS53410.2023...

  4. [2024]

    , 3348–3360.https://doi.org/https://doi.org/10.33012/2024.19713 Kriezis, A., Chen, Y., Lo, S., & Walter, T. (2024a). Identifying low cost GNSS monitor metrics for robust RFI detection.Pro- ceedings of the International Technical Meeting of The Institute of Navigation, 426–440.https://doi.org/https://doi.org/ 10.33012/2024.19542 Kriezis, A., Chen, Y.-H., A...

Pith tools

Reviewed August 4, 2026 · model on record in the stance chip above.