kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
GNSS Spoofing Detection Based on Opportunistic Position Information
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Software and Computer systems, SCS. (Networked Systems Security Group)ORCID iD: 0000-0002-9064-0604
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Software and Computer systems, SCS. (Networked Systems Security Group)ORCID iD: 0000-0002-3267-5374
2025 (English)In: IEEE Internet of Things Journal, ISSN 2327-4662, Vol. 12, no 17, p. 36168-36182Article in journal (Refereed) Published
Abstract [en]

The limited or no protection for civilian Global Navigation Satellite System (GNSS) signals makes spoofing attacks relatively easy. With modern mobile devices often featuring network interfaces, state-of-the-art signals of opportunity (SOP) schemes can provide accurate network positions in replacement of GNSS. The use of onboard inertial sensors can also assist in the absence of GNSS, possibly in the presence of jammers. The combination of SOP and inertial sensors has received limited attention, yet it shows strong results on fully custom-built platforms. We do not seek to improve such special-purpose schemes. Rather, we focus on countering GNSS attacks, notably detecting them, with emphasis on deployment with consumer-grade platforms, notably smartphones, that provide off-the-shelf opportunistic information (i.e., network position and inertial sensor data). Our Position-based Attack Detection Scheme (PADS) is a probabilistic framework that uses regression and uncertainty analysis for positions. The regression optimization problem is a weighted mean square error of polynomial fitting, with constraints that the fitted positions satisfy the device velocity and acceleration. Then, uncertainty is modeled by a Gaussian process, which provides more flexibility to analyze how sure or unsure we are about position estimations. In the detection process, we combine all uncertainty information with the position estimations into a fused test statistic, which is the input utilized by an anomaly detector based on outlier ensembles. The evaluation shows that the PADS outperforms a set of baseline methods that rely on SOP or inertial sensor-based or statistical tests, achieving up to 3 times the true positive rate at a low false positive rate.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE) , 2025. Vol. 12, no 17, p. 36168-36182
Keywords [en]
GNSS attack detection, opportunistic information, secure localization
National Category
Communication Systems Signal Processing Control Engineering
Identifiers
URN: urn:nbn:se:kth:diva-368747DOI: 10.1109/JIOT.2025.3581443ISI: 001556065500032Scopus ID: 2-s2.0-105008826704OAI: oai:DiVA.org:kth-368747DiVA, id: diva2:1990892
Note

QC 20260126

Available from: 2025-08-21 Created: 2025-08-21 Last updated: 2026-01-26Bibliographically approved
In thesis
1. Secure and resilient localisation in cyber-physical systems
Open this publication in new window or tab >>Secure and resilient localisation in cyber-physical systems
2025 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

Global navigation satellite system (GNSS) and other assisted positioning infrastructures provide ubiquitous, precise locations for cyber-physical system (CPS), from autonomous vehicles to location-based service (LBS) applications on mobile phones in daily lives. Combining multiple satellite constellations, network infrastructures, and onboard sensors typically makes the position solutions more accurate and robust than any single source alone. 

However, civilian GNSS signals, Wi-Fi beacons, and cellular pilot signals lack cryptographic protection and are therefore vulnerable to signal spoofing attacks. Even if they can be upgraded to support authentication, meaconing or wormhole attacks can relay and falsify the wireless signals and then manipulate the localisation. More seriously, an attacker can selectively jam the wireless signals from specific infrastructures to force CPS to downgrade to less secure signals, which are later spoofed; coordinated adversaries can also target multiple infrastructures simultaneously to manipulate the positioning result. 

This thesis is in the broad area of data trustworthiness for CPS, focusing on the security and resilience of localisation. Emphasis is given on securing the localisation based on GNSS, as they are relevant to a multiplicity of modern systems (e.g., connected vehicles, smartphones, and other Internet-of-Things (IoT) platforms). Significant efforts are dedicated to detecting attacks on position and providing secure and reliable location information, even in the presence of adversaries and benign faults (e.g., challenging propagation environments). Where perfect recovery is unlikely, the proposed methods aim for a best-effort position estimation by opportunistically fusing the remaining available benign signals. 

These efforts are concerned with designing, analysing, implementing, and evaluating diverse protocols that address GNSS-specific attacks, other positioning signal attacks, and simultaneous GNSS with other signal attacks. The approaches are theoretically rigorous, are evaluated through detailed simulations, real-world experiments, and system implementation, proposing concrete defense mechanisms.

Abstract [sv]

Global navigation satellite system (GNSS) och andra infrastrukturer för assisterad positionering tillhandahåller överallt närvarande, precisa positioner för cyber-physical system (CPS) — från autonoma fordon till location-based service (LBS)-applikationer i mobiltelefoner i vardagen. Fusionen av flera satellitkonstellationer, nätverksinfrastrukturer och ombordliggande sensorer gör positionslösningarna mer precisa och robusta än vad varje enskild lokaliseringsmetod kan erbjuda.

Avsaknaden av kryptografiskt skydd för GNSS-signaler, Wi-Fi-beacons och cellulära pilotsignaler gör dem dock sårbara för signalförfalskningsattacker. Även om systemen kan uppgraderas för att stödja autentisering, kan meaconing- och maskhålsattacker vidarebefordra och förfalska trådlösa signaler och därigenom manipulera positionsbestämningen. Ännu värre är att en angripare kan selektivt störa trådlösa signaler från specifika infrastrukturer för att tvinga CPS att falla tillbaka på mindre säkra signaler, vilka därefter kan förfalskas. På liknande sätt kan angriparen samordna attacker för att förfalska samtliga infrastrukturer.

Denna avhandling rör det breda området datatillförlitlighet för CPS, med fokus på säkerhet och motståndskraft vid lokalisering (positionering). Särskild tonvikt läggs på att säkra lokalisering baserad på GNSS, eftersom dessa är relevanta för en mängd moderna system — från smarta/uppkopplade fordon till smartphones och Internet-of-Things (IoT)-plattformar. Betydande insatser ägnas åt att upptäcka attacker mot positionsinformation och att tillhandahålla säker och tillförlitlig platsinformation även i närvaro av angripare och godartade fel (t.ex. i svåra utbredningsmiljöer). I vissa fall sker detta som en best-effort-lösning genom att utnyttja alternativa lokaliseringstekniker.

Dessa insatser omfattar design, analys, implementering och utvärdering av olika protokoll som hanterar GNSS-specifika attacker, andra attacker mot positioneringssignaler samt samtidiga attacker riktade mot GNSS och andra signaler. Metoderna är teoretiskt rigorösa och utvärderas genom detaljerade simuleringar, verkliga experiment och systemimplementation, och föreslår konkreta försvarsmekanismer.

Place, publisher, year, edition, pages
Stockholm: KTH Royal Institute of Technology, 2025. p. xxi, 39
Series
TRITA-EECS-AVL ; 2026:5
Keywords
Secure localisation, global navigation satellite system, spoofing detection, cyber physical system, location-based services, opportunistic position information, federated learning, self-supervised learning, multimodal sensing, Säker lokalisering, globalt satellitnavigationssystem, förfalskningsdetektering, cyberfysiska system, platsbaserade tjänster, opportunistisk positionsinformation, federerat lärande, självövervakat lärande, multimodal avkänning
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering
Identifiers
urn:nbn:se:kth:diva-374003 (URN)978-91-8106-496-4 (ISBN)
Public defence
2026-01-13, https://kth-se.zoom.us/j/62340383473, F3, Lindstedtsvägen 26, Stockholm, 09:00 (English)
Opponent
Supervisors
Note

QC 20251212

Available from: 2025-12-12 Created: 2025-12-11 Last updated: 2025-12-18Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Liu, WenjiePapadimitratos, Panos

Search in DiVA

By author/editor
Liu, WenjiePapadimitratos, Panos
By organisation
Software and Computer systems, SCS
In the same journal
IEEE Internet of Things Journal
Communication SystemsSignal ProcessingControl Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 109 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf