Source-linked AI summary

SonicNudge: Controlled Displacement of Hovering UAVs via Estimator-Controller Coupling

Shaocheng Luo, Ashir Raza, Haocheng Meng, David Hunt, Miroslav Pajic

arXiv:2608.25319v1eess.SYcs.RO

TL;DR

SonicNudge addresses whether gyroscope perturbations, rather than direct navigation spoofing, can displace hovering or slow-moving UAVs in a controlled way. It combines ultrasonic resonance, estimator–controller analysis, simulation, and physical experiments, finding repeatable lateral displacement with stable flight. The results motivate treating estimator–controller coupling as a UAV and IMU-based vehicle attack surface.

  • Problem

    Existing displacement attacks target position or translational-motion sensors, leaving whether gyro errors can produce controlled position effects as an open UAV security question.

  • Method

    SonicNudge injects ultrasonic resonance-induced gyro bias and analyzes its propagation through a PX4-style EKF and cascaded controller, using simulation and flight experiments.

  • Results

    The study demonstrates repeatable lateral displacement while preserving stable flight, including approximately 1.1 m displacement in physical experiments and up to approximately 1.5 m outdoors.

  • Takeaways & Limitations

    Low-level inertial errors can become position-level physical effects, so defenses should consider how residual sensing errors propagate through estimation and control.

  • Takeaways & Limitations

    Practicality is constrained by sensor, controller, triggering, resonance, estimator tuning, environmental conditions, and the paper’s exclusion of fully detached black-box moving-target deployment.

Abstract

from arXiv · show

UAV displacement attacks have traditionally relied on spoofing sensors that directly report position or translational motion, such as GNSS and optical flow. In this work, we introduce SonicNudge, a new attack primitive that instead targets the gyroscope and shows that low-level inertial errors can be transformed into controlled displacement of hovering or slow-moving UAVs. The attack exploits estimator--controller coupling: a small gyroscope perturbation by ultrasonic resonance can persist as an attitude-estimation bias, and the flight controller can convert this biased estimate into a shifted hover point. This behavior is especially relevant to UAV tasks that require hovering, station-keeping, slow approach, or precise final alignment, such as perimeter denial, inspection, docking, landing alignment, and close-proximity operation, where meter-scale position errors can be operationally meaningful. We analyze this attack primitive in a PX4-style flight stack and validate it through 81 simulation runs and more than 10 indoor/outdoor physical experiments, showing that displacement is governed by estimator weighting, bias observability, and closed-loop position correction. Our study suggests that UAV and vehicle-system security should look beyond direct navigation spoofing and pay closer attention to low-level inertial errors and estimator--controller coupling as a subtle but important attack surface.

I. INTRODUCTION

SonicNudge introduces controlled UAV displacement by perturbing gyroscopes rather than directly spoofing navigation sensors. Ultrasonic resonance, estimator retention, and cascaded control jointly convert small inertial errors into a stable, programmable hover offset.

  • Impact: The attack is relevant to hovering, station-keeping, inspection, docking, landing alignment, and other tasks where meter-scale errors matter.The paper frames controlled displacement as a predictable alternative to destructive disruption.
  • Mechanism: Ultrasonic resonance aliases into a bias-like gyro component that can persist as a roll/pitch estimation error.The flight controller attenuates the carrier while the EKF may retain the aliased component.
  • Mechanism: A biased attitude estimate causes the cascaded controller to converge to a displaced hover equilibrium rather than restoring the original hover point.The resulting offset scales with residual tilt bias and outer-loop gains.
  • Motivation: SonicNudge targets gyroscopes to induce lateral displacement without directly spoofing navigation inputs.The attack exploits a gyro-to-position pathway through attitude estimation and control.
  • Analysis: 81 simulation runs show strongest impact under weak accelerometer correction, while slower gyro-bias adaptation can prolong displacement after excitation stops.The study sweeps a 9 × 9 grid of estimator settings.
  • Validation: Physical experiments report approximately 5.5° peak roll-estimation bias and approximately 1.1 m lateral displacement while maintaining stable position control.AGR achieved a 46.7% phase-aligned trigger rate in a representative run.

B. Adversary Model

The adversary model assumes a directional ultrasonic projector, accessible MAVLink telemetry, and a PX4-style multirotor operating in hover or slow flight. Practical feasibility is bounded by geometry, acoustic power, sensor variation, and platform-specific axis coupling.

  • Attacker capabilities: The attacker uses a directional ultrasonic projector while maintaining line of sight, favorable incidence angle, and sufficient acoustic pressure.The evaluated cases require more than 105 dB at the target IMU.
  • Feedback channel: The attacker receives ordinary MAVLink telemetry for alias-phase scheduling and attacker–victim geometry, without injecting commands or modifying the mission.Telemetry-free operation is identified as an undemonstrated extension.
  • Targeting: The attacker identifies the vehicle or IMU family, sweeps near the expected resonance band, and monitors low-frequency attitude response to find a responsive carrier.The procedure avoids assuming exact prior knowledge of the aliased frequency.
  • Operating boundary: The evaluation focuses on hover or slow flight because changing geometry makes faster deployment require stronger tracking, pointing, and acoustic-power management.Short standoff distances and safety-bounded conditions are used rather than range maximization.
  • Sensor assumptions: The attack targets commodity MEMS gyroscopes with narrow ultrasonic resonances, but carrier band, affected axis, and coupling strength vary across sensors and installations.The prototype uses an MPU-6500 as a representative sensor.
  • Axis dependence: Roll/pitch-dominant coupling is in scope; yaw-dominant resonance may instead produce yaw drift or other closed-loop effects.The paper treats yaw-dominant resonance as a boundary condition for generality.

B. Bias Injection in Gyroscope Readings

The paper develops methods for converting resonant ultrasonic excitation into a signed, low-frequency gyro bias despite AC-coupled hardware. It compares envelope modulation, waveform-coherent switching, and Alias-Gated Resonance, selecting phase-gated feedback as the most practical physical mechanism.

  • Design challenge: A direct DC offset is ineffective because typical audio amplifiers and tweeters reject low-frequency and DC components.The bias must instead be encoded through the envelope or gating of an AC-coupled resonant signal.
  • Digital Amplitude Modulation: Digital Amplitude Modulation uses different positive- and negative-half-cycle gains to create a nonzero sampled mean.With A− = 0, the stated maximum bias is µ*DAM = A+/π.
  • Waveform-Coherent Switching: Waveform-Coherent Switching changes between same-alias frequencies with phase alignment, producing a half-wave-rectified waveform and maximum bias µ*WCS = 2A/π.The method is limited because reliably finding twin frequencies in real time is difficult.
  • Alias-Gated Resonance: Alias-Gated Resonance tracks a low-frequency phase proxy from telemetry and excites only the desired half-cycle of the aliased response.It avoids direct carrier tracking, per-sample amplitude programming, and twin-frequency handling.

V. SONICNUDGE CONTROL SCHEME

SonicNudge converts a retained gyro-induced attitude bias into lateral drift through PX4’s cascaded estimator–controller stack. During and after excitation, estimator weighting and bias adaptation determine drift and recentering.

  • Overview: The attack analysis maps injected gyro bias to attitude error, controller response, lateral displacement, and post-attack recovery.Simulation uses smoothly controlled DAM envelopes, while physical experiments use reliable on/off gating.
  • A. During the Attack: During excitation, the EKF can retain a residual roll/pitch error when accelerometer corrections are weak, and the cascaded controller converts it into lateral drift.Gyro-bias adaptation affects how much of the injected component is absorbed but is not required for drift during the active attack.
  • C. After the Attack: After excitation stops, slow gyro-bias adaptation can preserve the residual attitude offset and keep the UAV near the nudged hover point.Faster bias recentering lets the position controller pull the UAV back toward its original hover point.
  • B. Controller Response: In hover, biased attitude feedback makes the inner loops drive the estimated attitude toward its setpoint, creating physical tilt and lateral acceleration.The controller regulates using the estimated attitude rather than the true attitude.
  • B. Controller Response: The outer position loop commands counter-tilt until lateral acceleration is near zero, producing a finite displaced hover equilibrium.Under near-hover assumptions, the offset grows with residual tilt bias and decreases with stiffer outer-loop gains.

VI. SIMULATION EXPERIMENTS

MATLAB simulations evaluate SonicNudge in a modeled small quadrotor, first demonstrating baseline displacement and then testing estimator-weighting effects. The results show bounded drift under nominal conditions and stronger, approximately linear responses to larger injected biases, with saturation producing rapid growth.

  • Simulation Setup: The MATLAB model represents a 1 kg rigid-body quadrotor with gravity g = 9.81 m/s2 and included rotor dynamics.The assumed diagonal inertia is Isys = diag(0.016, 0.016, 0.0274) kg · m2.
  • Baseline Attack Injection and Analysis: The simulated attack begins at t0 = 10 s and ends at t1 = 30 s after the UAV settles at the desired hover position (0, 0, 1 m).Single-channel injection makes the simulated drift effectively one-dimensional.
  • Baseline Attack Injection and Analysis: During the baseline attack, the UAV drifts laterally at about 0.05 m/s while maintaining altitude with vertical deviation < 5 cm.The vehicle converges to a new offset hover point as lateral velocity decays toward zero.
  • Baseline Attack Injection and Analysis: With a roll-setpoint limit of approximately 10°, position-loop saturation leaves persistent lateral acceleration and produces approximately quadratic displacement growth.The resulting rapidly increasing drift can persist for some time after the attack is lifted.
  • Baseline Attack Injection and Analysis: As µDAM increases from 0.009/π to 0.054/π, average drift speed and steady-state estimated roll error increase approximately linearly.Negative biases produce symmetric displacement in the opposite direction.
  • Baseline Attack Injection and Analysis: The simulation validates the gyro-bias-to-displacement mechanism and the bounded equilibrium predicted by Equation (12).The observed behavior links biased gyro readings to biased attitude estimates and controller-generated lateral motion.

B. Attack Sensitivity to Diverse EKF Weighting

An 81-run sweep varies accelerometer measurement covariance and gyro-bias random-walk covariance to connect EKF weighting with attack impact. The results show predictable gain changes, larger residual attitude bias with weaker accelerometer correction, and reduced bias with faster adaptation.

  • Attack Impact: Residual roll bias increases with Rscale and decreases with Qscale during the attack window.The baseline setting is (Rscale, Qscale) = (1, 1).
  • Sweep Design: The sensitivity study evaluates Rscale and Qscale over a 9 × 9 grid, yielding 81 EKF weighting experiments.Rscale scales accelerometer tilt noise, while Qscale scales gyro-bias random-walk covariance.
  • Gain Sensitivity: With Qscale = 1, mean Kϕ,k decreases monotonically as Rscale increases, indicating weaker accelerometer correction of the attitude estimate.The measured trend broadly follows the expected inverse gain–covariance relationship.
  • Gain Sensitivity: With Rscale = 1, mean |Kb,p| increases with Qscale, consistent with faster bias adaptation at larger bias random-walk covariance.The heatmap measures |mean(ˆϕ)| over t = [13, 23] s.
  • Attack Impact: The gyro perturbation remains effective across a wide range of EKF weightings, with steady-state Euler-angle influence varying predictably with measurement trust and bias adaptation.The results identify stronger bias adaptation and less conservative accelerometer correction as estimator-level hardening levers.
  • Physical Validation: Physical validation uses a Pixhawk 6X/PX4 platform with indoor motion capture and outdoor GNSS positioning, while AGR schedules signed acoustic excitation through telemetry.The setup uses an MPU6500 primary IMU and a directed tweeter-based attack configuration.
  • Physical Validation: Speaker-detached tests demonstrate sensor susceptibility up to 1.52 m, while fully detached black-box moving-target free-flight deployment remains future work.This defines the nearest practical boundary of the reported physical evaluation.

C. Real Experiment Analysis

Physical experiments and sensor tests show that phase-aligned acoustic gyro excitation produces signed, safety-bounded displacement through estimator–controller coupling. The effect depends on trigger timing, sensor characteristics, estimator tuning, and outer-loop control.

  • Estimator response: The gyro-to-attitude pathway shows large resonance oscillations but subtle per-trigger rate changes, with dominant EKF roll and pitch growth during biased phase triggers.Under resonance, the x-axis gyro reached roughly ±40 deg/s while remaining visually centered; the same pattern held for pitch.
  • Flight displacement: Approximately 5.5° peak roll-estimation bias and −1.1 m lateral displacement were observed while stable position control was maintained.The displacement was intentionally limited to avoid wall collisions in the 3 m × 3 m arena.
  • Trigger timing: A 20 ms phase-alignment window over at least three consecutive cycles distinguishes effective triggers from mismatched triggers.Phase-aligned triggers reinforce the injected-bias sign, whereas phase mismatch attenuates the bias and slows or inconsistently affects displacement.
  • Trigger timing: 47% of scheduled trigger windows were phase-aligned in the full attack window, with a 5.8-percentage-point standard deviation across 10 repeated indoor trials.The full-window count was 16 phase-aligned triggers out of 34 scheduled windows.
  • Cross-IMU characterization: Several tested sensors were susceptible, with strongest coupling usually on roll and pitch rather than yaw and dependence on model, installation geometry, affected axis, and relative position.Dmax measured the largest standoff exceeding 0.1 rad/s disturbance, while Tmin measured time to at least 5° attitude-estimation error at Dmax; the single-tweeter setup was not range- or power-optimized.
  • Estimator and controller factors: The induced bias follows from downweighted accelerometer updates and small gyro-bias random-walk variance, while outer-loop integral action could reduce steady-state displacement but risks instability and windup.The proposed integral-action tradeoff requires anti-windup logic, reset handling, and careful gain scheduling.

B. Limitations and Generalizability

SonicNudge’s practicality is bounded by sensor and geometry variability, controller tuning, and phase-locked triggering requirements. Subject to these limitations, the estimator–controller pathway may extend beyond multirotors to other IMU-driven feedback systems.

  • Axis and direction limits: Sensor axis asymmetry and UAV yaw can alter both the displacement magnitude and its world-frame direction.Precise directional control may require continuous geometry and yaw compensation.
  • Controller dependence: Platform- and mission-specific outer-loop gains make precise drift prediction on an unknown target difficult.More aggressive or conservative Kvel,P and Kpos,P settings could reduce or amplify the effect.
  • Triggering robustness: AGR triggering can lose accuracy because aliasing, sampling-rate drift, and nonlinear-fitting delay shift or miss the desired phase window.Missed timing can weaken the induced bias or reverse its sign.
  • Generalizability: The mechanism may apply to camera gimbals, head-mounted displays, and self-balancing personal transporters that use resonance-susceptible MEMS IMUs and attitude feedback.This broader applicability is explicitly qualified as subject to the stated limitations.
  • Security framing: SonicNudge differs from destructive or direct navigation-spoofing approaches by targeting angular-rate sensing to produce bounded displacement as an estimator–controller outcome.The paper frames this as a non-destructive diversion primitive rather than a crash or direct position-spoofing objective.
  • Relation to prior work: The paper extends prior acoustic IMU attacks by analyzing how quasi-steady gyro bias is retained by the EKF and converted into directionally programmable lateral displacement.Prior work largely focused on sensor corruption, denial-of-service, imbalance, or crash.

APPENDIX

The appendix models how PX4’s EKF and cascaded controller process gyro perturbations, and explains when injected bias persists as an attitude error. Weak accelerometer correction and slow bias adaptation allow the EKF to retain a low-frequency injected component.

  • PX4 estimator and controller: PX4 fuses high-rate gyroscope and accelerometer data with slower absolute sensors to estimate position, velocity, attitude, and IMU biases.The gyroscope and accelerometer stream at approximately 1 kHz, while EKF2 produces state estimates at a few hundred hertz.
  • PX4 estimator and controller: The cascaded controller maps position and velocity errors to attitude and rate commands, while the rate loop tracks body rates from the raw gyroscope.The outer loop runs at about 50 Hz, the attitude controller at about 250 Hz, and the rate controller at about 1 kHz.
  • Attack pathway: SonicNudge injects a bias-like low-frequency component into the gyro stream; the rate loop attenuates the ultrasonic carrier, but EKF2 can integrate the residual into roll or pitch error.The mechanism relies on estimator tuning and the differing roles of the fast rate loop and slower estimator.
  • EKF model: The EKF state contains roll, pitch, and corresponding roll- and pitch-rate gyro bias states, with process and measurement noise governing their updates.The model explicitly fuses gyroscope and accelerometer tilt information.
  • Bias retention: When accelerometer corrections are weakened and bias adaptation is slow, the injected DC component becomes a persistent attitude bias while the AC component remains zero-mean fluctuation.The bias-preserving regime depends on small angle-update gain and slow bias-state adaptation.

D. Control Derivation and Boundary Conditions

The control derivation links biased attitude feedback to a finite lateral hover offset. Position control commands counter-tilt, but biased feedback prevents simultaneous elimination of attitude and position errors.

  • Control derivation: The position controller converts lateral position and velocity errors into a desired acceleration and corresponding attitude setpoint.For small angles, the roll setpoint is approximately the desired lateral acceleration divided by gravity.
  • Displaced equilibrium: When the estimated roll contains residual error εϕ and attitude tracking is tight, the resulting lateral acceleration yields ∆y ≈ gεϕ/(Kvel,P Kpos,P ) at equilibrium.This expresses the displacement as a function of residual attitude bias and outer-loop proportional gains.

2) Practical limits and larger-excursion regimes:

The attack’s practical behavior is bounded by tilt, controller, and sensing limits, while two-stage sampling can fold ultrasonic excitation into the estimator band. Sweep-and-lock exploits the resulting many-to-one frequency mapping.

  • Practical limits: Tilt limits constrain residual attitude error, while insufficient counter-tilt, integrator clamping, or degraded absolute-position updates can produce continued drift beyond the equilibrium offset.In that regime, excursions continue until tilt, velocity, or failsafe limits intervene.
  • Practical limits: A 1° residual tilt yields approximately 0.6 m of lateral displacement per degree of bias under representative controller gains.The calculation uses Kvel,P ≈ 0.3 s−1 and Kpos,P ≈ 1.0 s−1.
  • Two-stage aliasing: IMU sampling makes ultrasonic resonances appear as lower-frequency discrete-time components, and subsequent flight-stack rate conversion can fold them further into the EKF band.The two-stage IMU-to-EKF process is central to producing estimator-observable perturbations.
  • Frequency selection: The estimator-observed frequency lies in the EKF band even when the physical excitation is ultrasonic, creating multiple candidate excitation frequencies for a desired alias.The mapping is many-to-one, so nearby tones can produce related estimator-band responses.
  • Frequency selection: A continuous sweep with feedback can identify a carrier and modulation pair that produces a stable low-frequency estimator response without knowing exact sensor resonance or sampling details beforehand.The paper illustrates a representative approximately 1 Hz component, but the selected frequency can vary within the EKF band.

F. Gyro Bias Scheduling Algorithm

The gyro-bias scheduling algorithm locks onto an observed oscillation, gates activation at phase-specific extrema, and selects waveform polarity to accumulate a signed effect. The resulting biased gyro signal integrates into a drifting attitude estimate.

  • Algorithm pipeline: Algorithm 1 fits a sinusoid to a selected gyro axis, locks its frequency and phase, predicts extrema, and schedules gated activation over attack periods.Its inputs include a gyro stream, window length, axis, sign, and number of periods.
  • Signed scheduling: Type-A and Type-B waveforms are separated by 180° and selected according to the desired sign, enforcing a rising or falling local slope at activation.Phase-consistent selection produces a consistently signed cumulative effect.
  • Signed scheduling: The gate aligns activation with the appropriate half-cycle: peak-to-trough for positive sign and trough-to-peak for negative sign.The applied modulation is the selected waveform multiplied by the enable gate.
  • Accumulated effect: Repeated phase-gated injection accumulates a signed gyro-rate bias, whose integration produces a slowly drifting Euler-angle estimate with inherited oscillatory fluctuations.The figure traces the process from biased gyro readings to roll, pitch, and yaw estimates.

G. Speaker-Detached IMU Benchmark Testbed

The speaker-detached benchmark isolates acoustic coupling and gyro-bias pathways while keeping the PX4 estimator and attitude response active without uncontrolled free flight. Outdoor validation then links gyro-rate bias, attitude deviations, and lateral displacement, while revealing wind-related measurement instability.

  • Testbed design: The benchmark separates the ultrasonic projector from the UAV to test IMU susceptibility under consistent attacker–victim geometry.The projector is placed behind the evaluated sensor along the body-frame +x direction.
  • Testbed design: A constrained 3-DoF platform keeps the PX4 estimator, IMU, and attitude response active while avoiding uncontrolled motion during acoustic probing.Tests sweep or lock to responsive resonant bands and record gyro disturbance, affected axes, and attitude-estimation error.
  • Scope: The detached benchmark evaluates IMU generality and standoff behavior rather than demonstrating a fully detached moving-target attack.Its Dmax and Tmin measurements characterize whether each IMU supports the gyro-bias pathway under detached excitation.
  • Outdoor validation: The outdoor run used onboard GNSS and optical flow instead of VICON, with the attack enabled from t0 = 7 s to t1 = 55 s and 16 AGR triggers.Relative motion was reported from the fused state because commodity GNSS provides only ∼3–5 m absolute accuracy.
  • Outdoor validation: Up to ∼1.5 m lateral displacement followed injected p-to-roll and q-to-pitch gyro biases, while wind reduced oscillation SNR and sometimes caused AGR cycle skips.The corresponding relationships are shown for gyro rate versus attitude and biased attitude versus lateral displacement.
Loading 2608.25319v1…