Preprint

GPS Spoofing Study Redirects Drones While Detectors See Little

Preprint: Software-emulated GPS spoofing redirected a test UAV indoors and outdoors, but the study assumed an initial GPS takeover.

A preprint reports that a black-box GPS-spoofing pipeline redirected a test unmanned aerial vehicle toward selected destinations while two anomaly detectors, known as chi-square and CUSUM, recorded few detections in the reported indoor and outdoor trials. In indoor tests, the mean redirection error was 0.125 metres across 10 randomly sampled destinations; outdoors, the mean error was 0.476 metres.

The result comes with a crucial qualification: the evaluation assumed that an attacker had already taken over the GPS signal. The researchers then injected false navigation data in software instead of carrying out an over-the-air spoofing attack against a live receiver.

A black-box attack with a narrow view

The study asks whether an attacker working with only limited information can divert a UAV to a chosen destination without setting off anomaly detection. In the physical setup, a stationary attacker platform used an Intel NUC computer, a RealSense D435i camera and a Livox Mid-360 LiDAR to track the victim UAV, which carried a Pixhawk 6X flight controller and a GMKtec computer. The attacker was given only the victim’s GPS noise profile.

Before redirecting the aircraft, the pipeline estimated how much false movement could be introduced without looking abnormal. It calibrated that stealthiness bound with Monte Carlo trials, or repeated simulated runs, using the victim’s GPS noise profile and a Clopper–Pearson confidence interval. The method retained spoofing magnitudes whose detection probability was statistically consistent with the system’s nominal false-alarm behaviour.

A closed-loop controller then took the target and calibrated spoofing bound as inputs. It updated the tracked victim position and velocity and calculated position and velocity errors relative to the target.

The simulations kept the apparent flight on course

Offline checks found that Monte Carlo rollouts reached a broader empirical boundary than the reachability-based estimates. The reachability estimates were tighter and conservative, and became more precise as more information about the mission was available.

In simulations of three representative mission trajectories, the reported true path moved toward the designated target while the trajectory believed by the UAV stayed close to the nominal mission path. The reported result was therefore a split between the aircraft’s actual movement and its apparent movement.

Indoor precision fell outdoors

In the indoor targeted case study, the UAV landed within a predefined acceptance radius of 0.3 metres. Across 10 randomly sampled destinations, the mean redirection error was 0.125 metres, with a standard deviation, a measure of spread, of 0.107 metres.

The indoor detector results were low in the reported case study and across 10 attack trials. The case-study outcomes were reported as 0.025% and 0.000%; across the trials, the mean normalized scores were 0.6 for the chi-square detector and 0.1 for CUSUM, with an observed chi-square detection rate of 0.005% and zero CUSUM detections.

Performance was less precise outdoors. The mean redirection error rose to 0.476 metres, with a standard deviation of 0.351 metres, approximately 3.8 times the indoor mean error and 3.2 times the indoor standard deviation.

For the outdoor tests, detector thresholds were tuned to a nominal false-positive rate of 0.1%, and the observed nominal rate was 0.105%. The case study had no detections; across the outdoor attacks, the reported detection rate was 0.08% for chi-square and 0.00% for CUSUM.

The same attack pipeline was used to report three kinds of target behaviour during moving flight: a lateral diversion, a halt and a turn-back. In a separate intermittent tracker-loss test, losses occurred before and after redirection with very large tracking errors, yet the authors reported that the controller’s diversion remained coherent.

The tracker used 73.9% of the Intel NUC’s CPU and 4.7% of its RAM. End-to-end tracking and attack latency averaged 265.9 milliseconds, with a 95th-percentile latency of 613.4 milliseconds; YOLO identification ran asynchronously without directly adding to redirection delay.

A proof of concept, not a live takeover

Because spoofing was injected in software after an assumed takeover, the study did not show that an attacker could seize a live GPS receiver over the air.

The physical attacker platform was stationary, so the evaluation did not test a moving aerial attacker. The reported detector performance also does not establish that the attack would evade every anomaly detector or autopilot.

The work is an arXiv version 1 preprint, arXiv:2608.26011v1, dated 26 August 2026. Its acknowledgments report support from ONR agreement N00014-23-1-2206, AFOSR award FA9550-19-1-0169, NSF NAIAD Award 2332744, Grant CNS-2112562 and Army Research Office Cooperative Agreement W911NF-26-2-A165.

Paper data and sources

Original title: Phantom Navigator: Stealthy and Precise Unmanned Aerial Vehicle Redirection with Real-Time Tracking and GPS Spoofing
Authors: Haocheng Meng, Shaocheng Luo, Songqiao Xie, Miroslav Pajic
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-26
DOI: Not available
Original paper · Full text

Versions and corrections

  1. Published automatically after legal-source, freshness, evidence, and independent-verification gates passed.