Source-linked AI summary
GNSS Signal Authentication via Power and Distortion Monitoring
Kyle D. Wesson, Jason N. Gross, Todd E. Humphreys, Brian L. Evans
TL;DR
Civil GNSS receivers need practical, autonomous authentication against spoofing and jamming without signal changes, external hardware, or network connectivity. The paper proposes the Power-Distortion detector, which jointly monitors received power and correlation distortion, and reports detection of all malicious attacks with a single-channel false-alarm rate below 0.6%.
Problem
Civil GNSS signals are vulnerable to spoofing, while practical authentication methods must avoid changes to signals-in-space, additional hardware, and network connectivity.
Method
The Power-Distortion detector is a receiver-autonomous Bayesian classifier that jointly monitors received power and complex correlation-function distortion to classify four GNSS signal conditions.
Results
All malicious spoofing and jamming attacks were correctly flagged, while multipath-rich data produced false alarms 0.57% of the time.
Takeaways & Limitations
The detector provides a low-cost, firmware-implementable approach for detecting carry-off spoofing and jamming without external hardware or a network connection.
Abstract
from arXiv · showhide
We propose a simple low-cost technique that enables civil Global Positioning System (GPS) receivers and other civil global navigation satellite system (GNSS) receivers to reliably detect carry-off spoofing and jamming. The technique, which we call the Power-Distortion detector, classifies received signals as interference-free, multipath-afflicted, spoofed, or jammed according to observations of received power and correlation function distortion. It does not depend on external hardware or a network connection and can be readily implemented on many receivers via a firmware update. Crucially, the detector can with high probability distinguish low-power spoofing from ordinary multipath. In testing against over 25 high-quality empirical data sets yielding over 900,000 separate detection tests, the detector correctly alarms on all malicious spoofing or jamming attacks while maintaining a <0.6% single-channel false alarm rate.
I. INTRODUCTION
Civil GNSS receivers are vulnerable to spoofing, while existing authentication approaches often require signal changes, extra hardware, multiple antennas, sensors, or network connectivity. The Power-Distortion detector addresses this gap by jointly monitoring received power and correlation-function distortion to detect carry-off spoofing and jamming.
- Motivation: Open-access, predictable civil GNSS signals enable spoofing that can mislead receivers about position or time.This vulnerability poses risks for critical infrastructure and safety-of-life applications.
- Prior approaches: Existing authentication approaches include cryptographic, geometric, and signal-processing techniques, but civil signals lack cryptographic modulation.Some alternatives rely on multiple antennas, antenna motion, horizon assumptions, inertial or vision sensors, or network connectivity.
- Design requirements: Practical authentication should require no GNSS signal changes, additional hardware, or network connection and support receiver-autonomous software or firmware implementation.These requirements define the near-term deployment target for civil GNSS receivers.
- Design gap: Power-only and correlation-distortion-only monitors are unreliable when used separately for signal authentication.An anomalous-power threshold can miss subtle spoofing, while interference may remain beneath the correlation monitor’s noise floor.
- Proposed detector: The Power-Distortion detector combines anomalous received-power and correlation-profile-distortion tests to classify interference-free, multipath, spoofed, and jammed signals.Its key insight is that low-power spoofing produces distortion or ineffective attack power, whereas high-power spoofing produces anomalously high total received power.
- Contributions: The paper contributes detection-statistic models, a Monte-Carlo method for Bayes-optimal decisions, cost-function analysis, and evaluation on spoofing, multipath, and jamming recordings.The evaluation uses the Texas Spoofing Test Battery, RNL Multipath and Interference Recordings, and jamming recordings.
- Signal model: The receiver model includes an authentic signal, a structurally identical interference signal representing multipath, spoofing, or jamming, and additive noise after AGC scaling.Correlation with a local replica and accumulation over T seconds produce the receiver’s signal-processing inputs.
B. Post-Correlation Model
The receiver forms a complex correlation function by AGC-scaling the incoming signal, correlating it with a local replica, and accumulating over an interval. The resulting function is modeled as authentic-signal, interference, and thermal-noise components shaped by the spreading-code autocorrelation.
- Correlation and accumulation: Correlation and accumulation over T seconds produce the complex-valued accumulation product ξk(τ), viewed as the receiver’s correlation function versus replica lag τ.The product is normalized by 1/T for convenience.
- Receiver processing: The standard receiver block diagram applies AGC scaling before correlation and accumulation, producing ξk(τ) from β(t)r(t) and the conjugated local replica.This sequence defines the post-correlation quantity used by the detector.
- Component model: The correlation function contains authentic, interference, and thermal-noise components, with AGC represented by the average scaling factor βk.The interference component can represent multipath, spoofing, or jamming under the signal model.
- Code correlation: The spreading-code interaction is represented by R(τ), the expected product of the received and local code replicas.The authentic and interference correlation components are modeled in terms of this function and their code and carrier offsets.
- Noise model: Thermal-noise correlation components have independent zero-mean Gaussian in-phase and quadrature parts.Samples within 2τc are correlated because of the spreading-code structure, while more distant samples are uncorrelated.
III. HYPOTHESIS TESTING FRAMEWORK
The detector frames classification as a Bayesian composite hypothesis-testing problem over four GNSS signal conditions. Decisions use received power and symmetric-difference observations, with prior distributions and costs determining the selected hypothesis.
- Hypotheses: The four hypotheses represent interference-free operation H0, multipath H1, spoofing H2, and jamming H3.The framework is M-ary because it selects among four possible signal conditions.
- Parameterization: Each hypothesis corresponds to a disjoint parameter set Λi within Λ, where θ = [η, ∆τ, ∆θ]T contains interference power, code offset, and carrier offset.Because θ spans ranges of values, the testing problem is composite.
- Bayesian formulation: The Bayesian model treats θ as random, assigning each hypothesis a prior probability πi and a conditional parameter density wi(θ).These distributions encode uncertainty about the physical interference parameters under each hypothesis.
- Observations: At each measurement time, the observation vector is zk = [Dk, Pk]T, combining symmetric-difference and received-power measurements.Each hypothesis specifies the conditional distribution of this observation vector.
- Decision rule: A decision rule partitions the observation space Γ into disjoint regions Γi and selects Hi when zk falls in Γi.The rule maps each observed pair of detector measurements to one signal-condition hypothesis.
- Decision criterion: The optimum Bayesian rule chooses the hypothesis with the lowest average conditional cost, minimizing Bayes risk over the decision regions.The cost function can depend directly on the actual parameter vector θ rather than only on the hypothesis class.
- Model construction: The parameter distributions can be informed by empirical data, but dataset-specific characterization risks biasing the model toward the observed examples.The framework therefore highlights the induction problem in constructing priors for composite hypotheses.
H0: No interference
The no-interference hypothesis provides the baseline against which multipath, spoofing, and jamming are modeled. Its assumptions characterize ordinary reception and the conditions under which multipath becomes difficult to distinguish from low-power spoofing.
- Under H0, η=0, so interference-related delay and phase parameters have no effect on the received-signal model.
- The multipath model bounds echo power by η1=1 and delay by ∆τ1=2τc, because sufficiently delayed echoes do not distort the correlation function.
- Severe shadowing can produce η>1 in urban environments, making multipath indistinguishable from low-power spoofing unless such cases are excluded.
- The multipath characterization uses the Land Mobile Satellite Channel Model, including stochastic urban and suburban obstacles, attenuation, diffraction, and delay.
- Worst-case multipath scenarios resemble spoofing most closely and arise especially for low-elevation satellite signals in urban environments.
- Empirical analysis found ∆θ uniformly distributed on [0,2π) and η and ∆τ significantly correlated, with ρ≈−0.23.
H2: Spoofing
The spoofing hypothesis models carry-off attacks as correlated interference whose power and delay are constrained to remain plausible for reliable spoofing. Received-power measurement supplies one observable, but anomalous power alone is vulnerable to benign interference and therefore requires complementary distortion monitoring.
- Carry-off spoofing is modeled with η≥1 and |∆τ|<2τc; larger delays are classified as jamming because the interference is uncorrelated with the authentic signal.
- The spoofing parameter distributions are chosen to resemble multipath while allowing code pull-off, with log-normal η, exponential ∆τ, and uniform ∆θ.
- Received power Pk is a useful interference indicator, but solar radio bursts and personal privacy devices can also raise it above nominal levels.
- Power monitoring alone may require an alarm threshold that misses subtle spoofing, motivating its combination with correlation-distortion measurements.
- In the TEXBAT example, the spoofing spectrum is examined at tk=130 seconds, with ηi≈4, ∆θi≈π, and ∆τi≈0.
- The detector’s power measurement can use filtered complex samples averaged over a selected bandwidth, or an AGC setpoint in AGC-equipped receivers.
B. Symmetric Difference Measurement
The symmetric difference measures asymmetry between early and late correlation-function taps. It is simple and shape-insensitive for symmetric GNSS correlations, but its distribution requires simulation when coherent spoofing interactions create strong asymmetry.
- The symmetric difference is attractive because it is simple, insensitive to correlation-function shape, and sensitive to spoofing distortion.
- Dk is computed as the normalized magnitude of the complex difference between early and late taps at ±τd.
- When interference is absent or uncorrelated, the scaled complex difference is modeled as zero-mean complex Gaussian and Dk has a Rayleigh distribution.
- In the interference-free case, βk=1 and σN=σN0, yielding the simplified variance expression σd^2=8τd.
- Structured-signal jamming increases σd^2 with jamming power, making jamming harder to distinguish from spoofing.
- When coherent interaction is present, pDk cannot be modeled analytically and is instead studied by Monte Carlo over interference parameters and tracking assumptions.
C. Combined Measurement Vector
The detector combines received power and symmetric-difference measurements into a channel-specific observation vector for Bayesian classification. The framework extends naturally to simultaneous multi-channel interference when correlations between channels are modeled.
- Each tracking channel combines received power with its symmetric difference to form a channel-specific observation vector.
- When multiple GNSS signals are affected simultaneously, using the multi-channel observation vector improves detection performance.
- The Bayesian detection strategy uses the per-channel vector as its observation, omitting the channel superscript for notation.
- The multi-channel extension follows from the per-channel test together with a model for correlation among the symmetric-difference measurements.
V. THE POWER-DISTORTION TRADEOFF UNDER SPOOFING
Spoofers face a power-distortion tradeoff: reducing correlation distortion conflicts with reliable tracking-loop capture, while stronger attacks risk detection through received-power monitoring. Nulling or blocking can suppress distortion but impose difficult practical requirements.
- Power-Distortion Tradeoff: Matched-power spoofing significantly distorts the correlation function through interaction between authentic and spoofed signals.The relevant regime is 0.1 < η < 10.
- Nulling or Blocking: Perfect nulling-and-replacement attacks cannot be detected by this technique.Such attacks require centimeter-level attacker knowledge and an accurate fading model for the attacker-to-receiver path.
- Nulling or Blocking: The detector assumes nulling-and-replacement is impractically difficult and that attackers cannot physically block the receiving antenna.The latter assumption may be problematic when the receiver is accessible, including some vessel-monitoring scenarios.
- Overpowered Spoofing: Overpowered spoofing can eliminate authentic-signal interaction by driving authentic signals below the noise floor through AGC action.A received-power alarm limits covert spoofing to η < ηmax.
C. Underpowering
The detector uses Bayesian decision regions over received power and symmetric correlation distortion, estimated by Monte Carlo because general analytical observation densities are unavailable. The cost structure prioritizes avoiding undetected spoofing and jamming while permitting some benign multipath misclassification.
- Underpowering: Reliable, covert spoofing requires ηmin < η < ηmax, so a sufficiently low ηmax forces detectable correlation distortion during tracking-loop capture.The paper identifies ηmin ≈ 0.4 dB as the lower bound for reliable capture.
- Decision Rule: The Bayes-optimal rule selects, for each observation, the hypothesis minimizing posterior expected cost.Decision regions partition the observation space according to this rule.
- Monte Carlo Decision Regions: Monte Carlo simulation supplies the decision regions because analytical p(z_k|θ) models are generally unavailable.The procedure samples parameter vectors and measurements, partitions the observation space into cells, and iteratively improves boundary assignments.
- Cost Function: Undetected spoofing and jamming receive the highest costs because they can lead to hazardously misleading receiver output.Misclassifying spoofing as jamming or vice versa has lower cost when the receiver suppresses its navigation solution.
- Figures: Figure 6 models spoofing observations as concentrated in a low-power band, whereas Figure 7 displays colored decision regions for the four hypotheses.The regions correspond to no interference, multipath, spoofing, and jamming.
B. θ-Dependent Cost
The detector’s cost model varies with interference parameters rather than treating all errors equally. It assigns costs according to harmfulness, priors, and the operational decision rule applied to two-dimensional observations.
- θ-Dependent Cost: The θ-dependent cost increases with multipath-induced code-phase error and saturates at a specified maximum.Close-in, weak spoofing can receive multipath-like treatment under the stated parameter condition.
- θ-Dependent Cost: Jamming cost increases linearly with η in decibels until reaching the high-cost ceiling C03.This models stronger jamming as more harmful up to saturation.
- Prior Probabilities: The prior probabilities are situation-dependent, with the paper using π0 = 0.6, π1 = 0.2, π2 = 0.05, and π3 = 0.15 for a heightened-threat scenario.The spoofing prior may be increased in areas where spoofers have historically been active.
- Application of the Decision Rule: The Bayes-optimal detector classifies z_k = [D_k(τ_d), P_k]^T into regions Γ_i using priors, conditional densities, and θ-dependent costs.An observation in Γ_i is assigned to hypothesis H_i.
- Classification Performance: Multipath is often classified as interference-free, while multipath is misclassified as spoofing less than 1.7% of the time in simulation.The first behavior follows from the low cost assigned to benign multipath.
- Aggregation: Temporal and multi-channel aggregation can lower spoofing false alarms because slowly executed attacks produce repeated spoofing declarations across time or channels.A self-consistent spoofing attack must affect more than N − N_m signals to evade simple RAIM-type alarms.
VII. EXPERIMENTAL DATA
The experimental evaluation uses 27 recordings spanning spoofing, multipath, jamming, and negligible-interference conditions from several public and laboratory data sources. The data-processing pipeline derives correlation and power observations for applying the detector’s decision regions.
- TEXBAT: TEXBAT provides high-fidelity civil GPS spoofing recordings with static and dynamic scenarios and controllable spoofing parameters.The laboratory spoofer controls η, Δτ, and Δθ and can generate self-consistent aligned navigation data bits.
- TEXBAT: TEXBAT recordings tb2–tb6 contain quantization and aliasing noise that makes detection easier than predicted by the models, while tb7 lacks that noise and permits early nulling.The detector’s nulling assumption is therefore violated specifically by tb7.
- Multipath Recordings: The multipath and interference recordings span mild-to-severe multipath, mild unintentional jamming, and light-to-dense urban environments.Static and dynamic scenarios are included.
- Jamming Recordings: The jamming recordings use a low-cost privacy-device waveform swept across 1550.02–1606.72 MHz with a 26 µs period.The interference was combined with clean static receiver data and re-recorded.
- Reference Recordings: Three recordings were selected as negligible-interference references, containing little multipath beyond thermal and multi-access noise.These were static recordings from quiet RF environments.
- Preprocessing: Raw samples were converted into 100-Hz correlation accumulations at 41 uniformly spaced taps, while filtered wideband samples produced aligned received-power histories.Power was filtered to 2 MHz, averaged over 200 ms, and interpolated to 10-Hz P_k observations.
VIII. EXPERIMENTAL RESULTS
Across 27 experimental recordings, the PD detector alarmed on every malicious spoofing and jamming attack while keeping single-channel false alarms below 0.6%. Its decisions tracked attack evolution, detecting attacks immediately but sometimes classifying spoofing as jamming as correlation distortion changed during pull-off.
- Experimental setup: 27 experimental recordings were used to assess the PD detector, excluding tb7 because it violates the detector’s nulling assumption.The assessment applied decision regions from Fig. 7 to the recordings listed in Table II.
- Data preparation: Power spikes in sm2 identified low-level unintentional jamming, which was thresholded and excised from the multipath data.The empirical CDF inflection point defined the threshold separating H3 jamming from H1 multipath.
- Decision histories: In example jamming and spoofing scenarios, attacks were detected immediately at onset, but spoofing classifications changed as pull-off altered correlation distortion.The cumulative decision histories are shown for a single tracking channel in Fig. 10.
- Spoofing example: A low-power spoofing attack was caught despite an intended power advantage of η = 0.4 dB and an effective advantage of approximately 1.5 dB.During pull-off, spoofing was first recognized when increased correlation distortion revealed the attack, then later classified as jamming as distortion subsided.
- Classification performance: All spoofing and jamming instances were flagged as attacks, although experimental spoofing was declared jamming more than four-fifths of the time.Jamming was always categorized correctly; spoofing misclassification reflected initially aligned attacks and changing distortion during pull-off.
- False alarms: 0.57% was the false-alarm rate for multipath-rich H1 data, while clean H0 data produced no false alarms.Under the stated urban multi-channel assumptions, any subset of 6 among N ≤20 channels would simultaneously false alarm on average once every 2.5 years.