Score
Designs and implements data-processing pipelines and algorithms that ingest raw GNSS observables and produce corrected timing and positioning products. Work includes parsing raw L1 pseudoranges and carrier-phase measurements, applying broadcast/precise ephemeris and clock corrections, modeling and reconstructing receiver clock trajectories, estimating time offsets and signal delays, and detecting anomalies such as timing pulls or spoofing.
This work addresses timing uncertainty in embedded systems arising from the coupling of hardware interrupts, buffering mechanisms, and distributed communication. The paper proposes a federated GNSS correction data pipeline based on Lingua Franca, introducing explicit logical time semantics to this domain for the first time. It unifies the modeling of interrupt ticks, ring buffer evolution, and physical-logical jitter within a coherent framework. By integrating a time-triggered GNSS receiver, UART interrupt stream modeling, FIFO buffer analysis, and a federated execution architecture, the approach enables analyzable and predictable end-to-end timing behavior. Experimental results demonstrate that the pipeline achieves deterministic and reproducible timing performance.
为解决民用GNSS接收器易受欺骗攻击的问题,本文通过实现Galileo的信号认证服务(SAS)来验证测距测量的真实性,从而提供经过认证的时间解决方案。
Civilian GNSS receivers are vulnerable to time spoofing attacks, which compromise timing integrity without requiring physical access. Method: This paper proposes a hardware-agnostic, real-time detection framework that fuses multiple trusted time sources—including network time synchronization and high-stability crystal oscillators—to construct a constellation- and attack-type-agnostic time verification architecture. It establishes a high-precision clock bias model and designs dual-stage detection algorithms: microsecond-level (150 μs) abrupt jump detection and nanosecond-level (30 ns) smooth hijacking identification, supporting cross-layer adversarial evaluation—including simulated network-coordinated attacks. Contribution/Results: The method achieves 100% detection accuracy across all attack scenarios—abrupt jumps, smooth hijacking, and composite attacks—while precisely identifying sub-30-ns timing deviations. Deployment requires zero modifications to existing GNSS receivers or infrastructure, ensuring full operational transparency and minimal integration overhead.
To address unreliable GNSS positioning in vehicular systems caused by real-world interference, this study systematically evaluates supervised (CNN, LSTM, Transformer) and pseudo-label-based unsupervised learning for interference signal classification, using large-scale real-world measurements from German highways and Austrian Alpine roads. Its key contributions include: (i) the first empirical validation of pseudo-labeling unsupervised learning in large-scale realistic vehicular GNSS scenarios; (ii) identification of cross-regional environmental discrepancies as a critical constraint on model generalization; and (iii) proposal of a synergistic adaptation framework integrating anomaly detection (Isolation Forest), domain adaptation (DANN), and time-frequency-domain data augmentation. Experimental results show a classification accuracy of 98.2%, with pseudo-labeling achieving 92% of supervised method performance; DANN improves cross-scenario F1-score by 37%, significantly mitigating data distribution shift.
Civilian GNSS signals lack encryption and are thus vulnerable to spoofing attacks. To address this, this paper proposes a probabilistic detection framework leveraging opportunistic sensor information. Methodologically, it introduces a novel integration of motion-model-constrained regression with Gaussian process uncertainty modeling, utilizing heterogeneous on-device signals—including IMU measurements, clock readings, and network connectivity—to jointly estimate position/velocity priors and observation likelihoods. A statistically rigorous detection criterion is then derived from the Neyman–Pearson lemma to maximize detection sensitivity under strict false-alarm constraints. Experimental evaluation demonstrates that the method achieves significantly higher spoofing detection rates than state-of-the-art approaches across diverse spoofing scenarios, while reducing false-alarm rates by 42%. Crucially, it requires no additional hardware or trusted infrastructure, ensuring high practicality and deployment feasibility.
This study addresses the challenge of deploying conventional GNSS spoofing defense mechanisms on smartphones constrained by limited hardware resources. By integrating GNSS signal processing, radio-frequency interference analysis, and mobile security detection algorithms, this work pioneers a spoofing threat taxonomy and countermeasure evaluation framework specifically tailored to the unique hardware constraints of mobile architectures, thereby filling a critical gap in existing surveys. The research systematically reviews vulnerability characteristics and detection techniques, constructing a comparative framework for mobile-adapted defense strategies that elucidates the trade-offs of each approach on smartphone platforms. Ultimately, this paper provides a comprehensive guide for advancing GNSS spoofing protection within resource-constrained mobile environments.
This study addresses the vulnerability of GNSS timing receivers to undetected, significant time errors under slow common-mode spoofing attacks, which conventional RAIM and clock status flags fail to adequately mitigate. The authors propose a conditional Timing Protection Level (TPL) that integrates the static detectability lower bound from a model-agnostic monitor with oscillator holdover error. This work demonstrates, for the first time, that single-clock-assisted monitoring cannot guarantee unconditional timing integrity and instead formulates a closed-form, reproducible TPL reliant on inter-satellite consistency checks. Using L1 pseudorange and broadcast ephemeris to reconstruct clock trajectories and validating with the Kshana simulator, the calibrated TPL yields error budgets of 114 ns and 458 ns under 1-second recovery and 60-second holdover conditions, respectively—three orders of magnitude tighter than actual spoofing-induced errors and substantially outperforming traditional sequential detection methods.
This study addresses the vulnerability of V2X communication systems to GNSS spoofing attacks, which exploit the reliance on Global Navigation Satellite Systems for spatiotemporal information and pose serious threats to traffic safety. The authors propose a physical-layer GNSS spoofing method leveraging a low-cost software-defined radio (HackRF One) to generate high-fidelity GPS baseband signals that emulate false trajectories under high-speed mobility scenarios. By integrating Haversine distance computation, constant-velocity modeling, and linear interpolation, the approach effectively synthesizes realistic spoofed signals. For the first time, the attack is validated on real-world Commsignia onboard units (OBUs) and roadside units (RSUs), demonstrating significant degradation of cooperative perception services with minimal detectability. Successful spoofing is achieved at speeds of 90, 145, and 200 km/h, underscoring the urgent need for robust security mechanisms to protect the integrity of positional data in current V2X deployments.
This study addresses the vulnerability of TDD mobile networks to synchronization attacks due to their reliance on GNSS timing and the absence of standardized GNSS spoofing detection and reporting mechanisms in existing 3GPP frameworks. The work proposes the first integration of GNSS spoofing detection into the 3GPP standardization体系, leveraging existing specifications TS 28.111 and TS 28.552 for alarms and performance counters without introducing new interfaces or compromising multi-generation network compatibility. By analyzing the topological correlation between grandmaster clocks and gNB-DUs, a lightweight detection and monitoring framework is established, seamlessly interfacing with fault management and SECHAND event handling. In well-configured PTP networks, the approach achieves over 95% detection accuracy for spoofing attacks with drift rates ≥0.5 ns/s, maintains a false alarm rate below 1%, and effectively discriminates between signal loss, hardware faults, and transient maintenance events.
This work addresses the challenge of achieving high-precision positioning with low-cost, single-frequency GNSS receivers, which are typically constrained by hardware limitations and the absence of base station support. The authors propose a tightly coupled multi-sensor fusion approach that integrates single-frequency carrier-phase measurements with arbitrary motion sensors—such as wheel odometry, cameras, or LiDAR—within a sliding-window factor graph framework. A virtual anchor mechanism is introduced to replace physical base stations, thereby preserving carrier-phase continuity. By incorporating robust cycle-slip detection and recovery alongside multimodal motion priors, the method achieves decimeter-level accuracy without reliance on external infrastructure. Experimental results demonstrate that the system consistently reduces positioning errors from several meters to the decimeter level across diverse real-world scenarios, offering a solution that is accurate, cost-effective, and highly robust.