Score
Preprocessing and analysing raw GNSS measurements (pseudoranges, ephemerides) to reconstruct receiver clock and position trajectories, detect spoofing effects, and produce derived products (e.g., ZWD) formatted for ingestion into downstream models.
Civilian GNSS receivers are vulnerable to time spoofing attacks, which compromise timing integrity without requiring physical access. Method: This paper proposes a hardware-agnostic, real-time detection framework that fuses multiple trusted time sources—including network time synchronization and high-stability crystal oscillators—to construct a constellation- and attack-type-agnostic time verification architecture. It establishes a high-precision clock bias model and designs dual-stage detection algorithms: microsecond-level (150 μs) abrupt jump detection and nanosecond-level (30 ns) smooth hijacking identification, supporting cross-layer adversarial evaluation—including simulated network-coordinated attacks. Contribution/Results: The method achieves 100% detection accuracy across all attack scenarios—abrupt jumps, smooth hijacking, and composite attacks—while precisely identifying sub-30-ns timing deviations. Deployment requires zero modifications to existing GNSS receivers or infrastructure, ensuring full operational transparency and minimal integration overhead.
This study addresses the vulnerability of GNSS timing receivers to undetected, significant time errors under slow common-mode spoofing attacks, which conventional RAIM and clock status flags fail to adequately mitigate. The authors propose a conditional Timing Protection Level (TPL) that integrates the static detectability lower bound from a model-agnostic monitor with oscillator holdover error. This work demonstrates, for the first time, that single-clock-assisted monitoring cannot guarantee unconditional timing integrity and instead formulates a closed-form, reproducible TPL reliant on inter-satellite consistency checks. Using L1 pseudorange and broadcast ephemeris to reconstruct clock trajectories and validating with the Kshana simulator, the calibrated TPL yields error budgets of 114 ns and 458 ns under 1-second recovery and 60-second holdover conditions, respectively—three orders of magnitude tighter than actual spoofing-induced errors and substantially outperforming traditional sequential detection methods.
GNSS is vulnerable to time-pushing spoofing attacks, and conventional supervised detection methods struggle against previously unseen zero-day attacks. This paper proposes a quantum-classical hybrid autoencoder (HQC-AE) tailored for static GNSS receivers, which extracts multidimensional features solely from authentic GNSS signals during the tracking phase—enabling unsupervised anomaly detection prior to PNT solution computation. To our knowledge, this is the first application of a quantum-classical autoencoder to GNSS spoofing detection, eliminating reliance on labeled spoofing data. Experimental results demonstrate that HQC-AE achieves an average detection accuracy of 97.71% and a false negative rate of only 0.62% across diverse unknown time-pushing attacks. Under high-complexity spoofing scenarios, it maintains 98.23% accuracy and a 1.85% false negative rate—significantly outperforming state-of-the-art supervised and unsupervised approaches.
GNSS/GPS systems face dual malicious interference threats—spoofing and jamming—compromising positioning, navigation, and timing (PNT) integrity. To address this, we propose the first unified detection framework that jointly models both attack types. Our approach innovatively integrates time-frequency signal features with visualized signal representations, enabling a multimodal deep learning architecture—Hybrid CNN-LSTM—that overcomes the limited generalizability and poor scene adaptability of conventional methods. Unlike prior works relying solely on signal processing or unimodal learning, our framework achieves 99% jamming detection accuracy on real-world datasets—a ~5% improvement over state-of-the-art—and sets a new benchmark for spoofing detection performance. This significantly enhances the robustness and practical deployability of PNT systems under adversarial conditions.
Civilian GNSS signals lack encryption and are thus vulnerable to spoofing attacks. To address this, this paper proposes a probabilistic detection framework leveraging opportunistic sensor information. Methodologically, it introduces a novel integration of motion-model-constrained regression with Gaussian process uncertainty modeling, utilizing heterogeneous on-device signals—including IMU measurements, clock readings, and network connectivity—to jointly estimate position/velocity priors and observation likelihoods. A statistically rigorous detection criterion is then derived from the Neyman–Pearson lemma to maximize detection sensitivity under strict false-alarm constraints. Experimental evaluation demonstrates that the method achieves significantly higher spoofing detection rates than state-of-the-art approaches across diverse spoofing scenarios, while reducing false-alarm rates by 42%. Crucially, it requires no additional hardware or trusted infrastructure, ensuring high practicality and deployment feasibility.
This study addresses the vulnerability of TDD mobile networks to synchronization attacks due to their reliance on GNSS timing and the absence of standardized GNSS spoofing detection and reporting mechanisms in existing 3GPP frameworks. The work proposes the first integration of GNSS spoofing detection into the 3GPP standardization体系, leveraging existing specifications TS 28.111 and TS 28.552 for alarms and performance counters without introducing new interfaces or compromising multi-generation network compatibility. By analyzing the topological correlation between grandmaster clocks and gNB-DUs, a lightweight detection and monitoring framework is established, seamlessly interfacing with fault management and SECHAND event handling. In well-configured PTP networks, the approach achieves over 95% detection accuracy for spoofing attacks with drift rates ≥0.5 ns/s, maintains a false alarm rate below 1%, and effectively discriminates between signal loss, hardware faults, and transient maintenance events.
GNSS is vulnerable to time-of-arrival (ToA) spoofing attacks, against which existing cryptographic authentication mechanisms—such as Galileo’s TESLA—offer no protection due to their inability to detect malicious time manipulation. This paper proposes TRICK, the first scheme that jointly leverages low-Earth-orbit (LEO) satellite two-way ranging and multi-source one-way broadcast signals, enforcing verifiable multilateration via ellipsoidal geometric constraints. TRICK closes the ToA manipulation loophole with only a single trusted reference node and minimal communication overhead. It integrates TESLA-enhanced authentication, lightweight integrity verification, and multi-source fusion modeling. We formally prove that TRICK achieves security guarantees equivalent to classical verifiable positioning schemes and reliably detects arbitrary ToA spoofing attacks. Its computational overhead is negligible, and it significantly reduces dependence on ground-based infrastructure.
This study addresses the vulnerability of V2X communication systems to GNSS spoofing attacks, which exploit the reliance on Global Navigation Satellite Systems for spatiotemporal information and pose serious threats to traffic safety. The authors propose a physical-layer GNSS spoofing method leveraging a low-cost software-defined radio (HackRF One) to generate high-fidelity GPS baseband signals that emulate false trajectories under high-speed mobility scenarios. By integrating Haversine distance computation, constant-velocity modeling, and linear interpolation, the approach effectively synthesizes realistic spoofed signals. For the first time, the attack is validated on real-world Commsignia onboard units (OBUs) and roadside units (RSUs), demonstrating significant degradation of cooperative perception services with minimal detectability. Successful spoofing is achieved at speeds of 90, 145, and 200 km/h, underscoring the urgent need for robust security mechanisms to protect the integrity of positional data in current V2X deployments.
This work proposes SpAmming, a novel hybrid attack paradigm addressing the limitations of existing GNSS anti-spoofing and anti-jamming mechanisms against emerging composite threats. Exploiting the CDMA multiplexing characteristics of GNSS, SpAmming leverages software-defined radio platforms to generate carefully crafted spoofing signals that integrate fake signal transmission, Doppler shift manipulation, and code-phase offsetting. This approach simultaneously achieves effective interference while evading conventional detection schemes. Experimental results demonstrate that SpAmming can successfully disrupt receiver signal acquisition during cold start and significantly degrade performance under hot-start and steady-state positioning conditions. Its impact is further amplified when coordinated with other attacks, underscoring its high level of stealth and disruptive potential.
Location-based services (LBS) are vulnerable to low-cost attacks—including Wi-Fi spoofing and GNSS jamming—as well as coordinated position-spoofing threats. To address this, we propose a proactive defense framework based on redundant multi-source localization fusion. Our approach innovatively extends the Receiver Autonomous Integrity Monitoring (RAIM) paradigm by integrating heterogeneous signals—namely GNSS, Wi-Fi, Bluetooth, cellular, IP geolocation databases, and in-vehicle sensors—into a cross-modal integrity verification mechanism. Crucially, it requires no additional hardware, leveraging only existing platform sensing capabilities. This design significantly enhances robustness against sophisticated spoofing attacks and improves trustworthy position recovery accuracy. Experimental evaluation demonstrates up to a 62% improvement in attack detection accuracy over baseline methods, alongside effective reconstruction of verifiable positions. The solution offers a lightweight, deployable integrity assurance mechanism for real-world LBS systems.