System and method for detecting GNSS signals spoofing attacks
The system uses a multi-frequency and multi-constellation GNSS antenna with a pre-trained machine learning model to accurately detect and identify GNSS signal spoofing attacks, addressing limitations in existing methods by precisely determining the affected constellation, satellite, and frequency.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2026-03-12
AI Technical Summary
Existing GNSS signal spoofing detection methods are limited in accuracy and applicability due to the lack of sufficient training data, particularly for multi-frequency and multi-constellation systems, and fail to precisely identify the constellation, satellite, and frequency under attack.
A system and method utilizing a multi-frequency and multi-constellation GNSS antenna, combined with a pre-trained machine learning model, to analyze GNSS signal parameters and detect spoofing attacks by identifying the constellation, satellite, and frequency under attack.
Accurately identifies and alerts on GNSS signal spoofing attacks in real-time, providing precise identification of the affected constellation, satellite, and type of attack, enhancing the reliability of GNSS systems.
Smart Images

Figure IB2025058896_12032026_PF_FP_ABST
Abstract
Description
[0001] SYSTEM AND METHOD FOR DETECTING GNSS SIGNALS SPOOFING ATTACKS
[0002] * * *
[0003] The present invention relates to the communications sector and, in particular, to a system and method for detecting GNSS signals spoofing attacks.
[0004] GNSS, i.e. Global Navigation Satellite Systems such as GPS, Galileo and BeiDou, provide crucial positioning, navigation and timing services (also called PNT services) in many sectors, including transport, agriculture, sensing and telecommunications. The GNSS signals, transmitted by such systems, are however vulnerable to interference and spoofing attacks, i.e. attacks in which altered GNSS signals are transmitted to mislead GNSS signal receivers. Spoofing attacks can also have serious consequences, such as ship hijacking, financial fraud, and disruption of critical infrastructure, and in recent years, the reported number of incidents due to such attacks has generally increased.
[0005] Detecting GNSS signal spoofing is challenging, as altered the GNSS signals closely resemble the authentic ones, and the traditional detection methods, based on the strength of the received GNSS signals or the analysis of their structure have limitations in identifying sophisticated spoofing attacks. Although recently there has been some interest in the use of machine learning (or ML) algorithms for the detection of this type of attacks, the use of such algorithms is not so widespread, due to the enormous difficulties encountered in obtaining large amounts of altered GNSS signals, to be used for the training of the same.
[0006] In fact, acquiring sets of altered GNSS signals is strictly prohibited by laws and regulations in many countries, including Italy (Legislative Decree no. 173 of 09 / 12 / 2020, in implementation of the European Union Directive 2018 / 197) and, for this reason, sets of simulated signals are usually used, which are very complex to obtain (in fact, there are few facilities in the world capable of generating signals of realistic spoofing attacks at the radio frequency level) also in terms of time and costs. Only recently, the ESA (European Space Agency) has organized in Norway, on the island of Andenes, far from sensitive facilities, some Jamming and Spoofing test campaigns with real signals but the data collected are still limited. For this reason, only a very limited number of algorithms based on machine learning for spoofing detection are available in the scientific literature, presented as preliminary investigations, rather than as solutions ready to be implemented.
[0007] For example, Semanjski et al. in recent articles, "Use of supervised machine learning for GNSS signal spoofing detection with validation on real-world meaconing and spoofing data— Part / ", Sensors (Switzerland), 20(4), 2020 and "Cyber-threats analytics for detection of GNSS spoofing", 7thInternational Conference on Data Analytics (pp. 136-140), I ARIA, 2018, proposed a method based on the ML Support Vector Machines (SVM) algorithm, able to discriminate between authentic and altered (non-authentic) GNSS signals, which uses multi-frequency signals from different constellations (such as GPS / Galileo) to reproduce a typical real use case and, although the method is accurate (with a correct identification rate of more than 95%), several critical issues emerge that could reduce its applicability in the real world. The solution developed by Semanjski et al. is, in fact, limited to the distinction of GNSS signals in the case of "meaconing" type attacks (which consist of recording and broadcast retransmission of authentic GNSS signals with a controlled delay) and, although "meaconing" is a very common spoofing type attack, it is certainly not the only one that can be implemented to alter the GNSS signals. In addition, the amount of data used for both training and the test of the method developed by Semanjski et al. is very limited (two test campaigns were conducted, each with a maximum of 5,000 data points between training data set and test data set). Not only that, the method of Semanjski et al. analyzes the individual GNSS signals and does not implement a procedure to make an overall assessment of the status of the incoming signals from a single constellation. In fact, albeit accurate, an algorithm based on ML has a certain error rate, and it is therefore necessary, after analyzing all the signals coming from the same constellation, a strategy to establish whether the constellation as a whole is under attack, mitigating any prediction errors made on individual satellites. This appears crucial for real-time applications, which require a general indication of the probability that the GNSS signal, of each GNSS satellite and in each epoch, may or may not be under spoofing attack.
[0008] Other ML algorithms have also been shown to provide similar results. For example, Aissou et al. in "Tree-based Supervised Machine Learning Models for Detecting GPS Spoofing Attacks on UAS". IEEE 12thAnnual Ubiquitous Computing, Electronics and Mobile Communication Conference, UEMCON (pp. 649-653), 2021, compared various models such as the Random Forest and XGBoost model on a data set composed of 10,055 data points, almost equally divided between authentic and altered single-band GPS signals. Three different types of spoofing attacks have been tested: "meaconing" both on the single signal and on signals from multiple satellites, and the"advanced attack" that is, in which the attack knows the position of the target (for example, using calibrated and georeferenced LIDARs). Aissou et al. shows in this article how the models developed achieve an overall precision of 96% in the classification between authentic and altered signals, with the XGBoost model surpassing the others in terms of precision. Despite this, the work of Aissou et al. also has several limitations. In particular, it only takes into account single-band signals from the GPS constellation, and it is therefore not applicable to multi-frequency and multi-constellation devices, which represent the current market trend for accurate GNSS localization (now that smartphones, for example, are also equipped with dual-frequency multi-constellation GNSS chips).
[0009] Several "tailor-made" approaches have also been developed, to be used under specific conditions. For example, Gallardo et al., in the article "SCER Spoofing Attacks on the Galileo Open Service and Machine Learning Techniguesfor End-User Protection" IEEE Access, 2020, developed an ML model based on decision trees, to be used specifically for the Galileo constellation against "Secure Code Estimation and Replay" (SCER) type attacks, which represent the most challenging spoofing type attack. In particular, the Galileo constellation provides a service, the "Open Service Navigation Message Authentication" (OSNMA), intended to protect the GNSS users from simple attacks based on the generation of false GNSS signals. This offers a first line of protection against various types of spoofing attacks, although defense is not always guaranteed. However, since OSNMA protection itself appears ineffective against SCER-type spoofing attacks, the authors proposed a complementary ML-based method to detect spoofing attacks. The approach developed by Gallardo et al. should however only be used in combination with the OSNMA service and in case the original GNSS signal has not been cancelled. The data set to test the effectiveness of the system also in this case is very limited and comprises about 1500 samples of authentic and altered GNSS signals, showing a 98% accuracy in distinguishing between authentic and altered GNSS signals.
[0010] Some traditional attack detection systems of some types of GNSS signal spoofing are described in CN116087994A, KR20210144517, US11500109, US12025712B2, JP2024515652A, CN116482720B, US2012 / 098699A1 and in the scientific articles by Xu Patrie et al. "Detect GNSS Spoofing Signals Using a Machine Learning Method" ITM 2022 - PROCEEDINGS OF THE 2022 INTERNATIONAL TECHNICAL MEETING OF THE INSTITUTE OF NAVIGATION; THE INSTITUTE OF NAVIGATION, 8551 RIXLEW LANE SUITE 360 MANASSAS, VA 20109 USA, by E. Shafiee et al. "Detection of Spoofing Attack using Machine Learning based on Multi-Layer Neural Network in Single-Frequency GPS Receivers" Journal of Navigation 71(l):l-20, and Rados Katarina et al. "GNSS Signal Classification based on Machine Learning Methods", 2024 47th MIPRO ICT and Electronics Convention (MIPRO). None of the systems described therein can precisely identify the exact constellations, satellites, and frequency bands that are corrupted by a spoofing attack.
[0011] There is, therefore, a need to improve the state of the art in the communications sector and, in particular, in the sector of receiving GNSS signals and data, and the main aim of the present invention is, therefore, to provide a system and a method for detecting GNSS signal spoofing attacks, which allow any type of spoofing attack to be detected.
[0012] A further object of the present invention is to provide a system and method for detecting GNSS signals spoofing attacks, which allow spoofing attacks to be detected more accurately than the traditional systems.
[0013] A still further object of the present invention is to provide a system and method for detecting GNSS signal spoofing attacks, which allow to precisely identify the GNSS constellation under attack.
[0014] Another object of the present invention is to provide a system and a method for detecting GNSS signal spoofing attacks, which allow to accurately identify the satellite or satellites, under attack, of a GNSS constellation under attack.
[0015] A still further object of the present invention is to provide a system and a method for detecting GNSS signal spoofing attacks, which allow to accurately identify the frequency of the GNSS signals under attack.
[0016] Another object of the present invention is to provide a system and a method for detecting GNSS signal spoofing attacks, which allow to recognize the specific type of GNSS signal spoofing attack received.
[0017] A specific object of the invention is a system for detecting a GNSS signal spoofing attack, comprising:
[0018] - a multi-frequency and multi-constellation GNSS antenna, configured to operate at the frequency bands of a plurality of GNSS constellations and receive, for each epoch, a plurality of GNSS signals;
[0019] - a GNSS receiver, configured to operate at a given sampling frequency, operationally connected to the GNSS antenna and configured to receive and process, for each epoch, the plurality of GNSS signals received by the GNSS antenna, and output, encoded in an input signal, a plurality of values for a respective plurality of parameters of interest for each GNSS signal of the plurality of GNSS signals;
[0020] - a memory configured to store configuration parameters of at least one machine learning model, pre-trained with a training data set including authentic GNSS signals data and altered GNSS signals data for different types of spoofing attacks;
[0021] - a processing unit, operationally connected to the GNSS receiver and to the memory and, for each epoch, configured for receiving the input signal from the GNSS receiver and selecting, for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna, whose parameters of interest are encoded in the signal, a set of N (N=l, 2, ...) parameters of interest; receiving, from memory, the configuration parameters of the at least one pre-trained machine learning model; for each set of N parameters of interest thus selected, implementing the at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory 4, providing the machine learning model with this selected set of N parameters of interest, and obtaining from the machine learning model at least one respective output parameter, whose value depends on whether the GNSS signal associated with this set of N parameters of interest provided as input is authentic or not; and processing a corresponding output signal, wherein, for each GNSS signal associated with the respective set of N parameters of interest, at least one output parameter outputted from the machine learning model is encoded; and
[0022] - an emitter, operationally connected to the processing unit and configured to receive the output signal and emit a corresponding spoofing detection signal of the plurality of GNSS signals.
[0023] According to one aspect of the invention, the number N and the parameters of interest that can be selected from the plurality of parameters of interest encoded in the input signal may depend on the specific type of application of the system and its operating modes, optionally on whether the system is installed in a fixed or mobile location, optionally between: a reference station for network synchronization, a wheeled vehicle, a drone, an earthmoving machine, a boat, an aircraft, a train, a satellite, and also depend on the computing capabilities of the processing unit.
[0024] According to another aspect of the invention, the number N of parameters of interest may be between 5 and 46 parameters and is optionally determined based on the data from the training dataset, optionally by means of a Backward Feature Elimination method.
[0025] According to a further aspect of the invention, the output signal obtained from the machine learning model may contain therein encoded, for each epoch and for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna at the abovesaid epoch, in addition to the at least one output parameter, also one or more of the following information:
[0026] - the epoch;
[0027] - an identifier of the GNSS constellation or constellations subjected to attack;
[0028] - an identifier of the GNSS constellation satellite or satellites, involved in the attack;
[0029] - an identifier of the frequency band or bands involved in the spoofing attack; and optionally
[0030] - an identifier of the spoofing type.
[0031] According to a further aspect of the invention, the plurality of GNSS constellations may comprise two or more constellations between: GPS, Galileo, Beidou, GLONASS, EGNOS, WAAS, QZSS, NavIC and PNT constellations in LEO orbits.
[0032] According to another aspect of the invention, the spoofing attack may be of the type: meaconing, synchronized spoofing, advanced attack, SCER attack, stationary meaconing with variable power and exposure time, non-coherent spoofing by stationary spoofer using synthetic ephemeris, non-coherent spoofing by stationary spoofer using true transmitted ephemeris, coherent spoofing by stationary spoofer using true transmitted ephemeris, non-coherent temporal spoofing from stationary spoofer using synthetic ephemeris, coherent temporal spoofing from stationary spoofer using true transmitted ephemeris, position non-coherent spoofing and GNSS time from mobile spoofer, stationary non-coherent spoofing with extreme time shifts.
[0033] According to a further aspect of the invention, the at least one machine learning model may be a model between: a support vector machine, a feed-forward neural network, a long- and short-term memory recurrent neural network, a KAN neural network, a Random Forest, an XGBoost, a convolutional neural network.
[0034] According to a further aspect of the invention, the at least one machine learning model may include at least one support vector machine with at least one kernel function between: radial, polynomial, or Gaussian.
[0035] According to another aspect of the invention, the at least one machine learning model may comprise at least one feed-forward neural network, including:
[0036] - an input layer, having as many neurons as the N parameters of interest are, selected by the processing unit from those encoded in the input signal for the respective GNSS signal, and a number of parameters equal to P=[4 x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive the value of a respective parameter of interest; - a plurality of hidden layers, optionally between 2 and 20, each having a number of neurons between 40 and 150, optionally between 50 and 100, set based on the application and computational capacity of the processing unit of the system, and a fixed number of parameters equal to P=[no. of Previous Layer Neurons] x [No. of Current Layer Neurons] + [No. of Previous Layer Neurons] parameters and as activation function for each neuron of this layer, a function chosen between Softmax and ReLu function; and
[0037] - an output layer, having as many neurons as the information to be encoded in the output signal to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons] and as an activation function, for each neuron of this layer, a Softmax function; wherein each neuron is connected to all neurons in the next layer.
[0038] According to a further aspect of the invention, if the neural network comprises a single neuron in the output layer, the activation function for each neuron of that layer may be a Sigmoid function.
[0039] According to a further aspect of the invention, the machine learning model may comprise at least one long-term and short-term memory recurrent neural network, including an array of units, wherein the number of units comprised in the array of units may correspond to the number of epochs that one would like to consider.
[0040] According to another aspect of the invention, the long-term and short-term memory recurrent neural network may comprise:
[0041] - an input layer, having as many neurons as the N parameters of interest are, selected by the processing unit from those encoded in the input signal for the respective GNSS signal, and a number of parameters equal to P=[4 x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive the value of a respective parameter of interest;
[0042] - an array of E units, where E corresponds to the number of epochs, wherein each unit can implement one of the activation functions between Tanh and ReLu, as activation function for each neuron; and
[0043] - an output layer, having as many neurons as the information to be encoded in the output signal to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons], considering the number of neurons of the last layer of the unit of the last epoch, and a Softmax function as an activation function for each neuron of that layer. According to a further aspect of the invention, each unit may comprise four feed-forward neural networks.
[0044] According to a further aspect of the invention the number E of epochs may be between 5 and 200, optionally between 15 and 150, more optionally between 60 and 150 for static applications, between 30 and 90 for low dynamic applications and between 15 and 60 for high dynamic applications.
[0045] According to another aspect of the invention, the parameters of interest of the plurality of parameters of interest may include: lock time, carrier to noise ratio, pseudorange, Doppler Frequency, full carrier phase, multipath correction, code variance, carrier variance, Doppler variance, carrier multipath correction, receiver clock bias, receiver clock drift, carrier multipath correlation, smoothing correction, ACG gain, I and Q samples of signal correlation, Week number, SV Health Status, SV Configuration, Signal Health Status, Ephemeris Reference Time, SV Clock corrections, the orbital parameters that accurately define the orbit wherein each satellite moves: Sine Harmonic Correction Term to Orbit Radius, Mean Motion Difference from Computed Value, Mean Anomaly at Reference Time, Cosine Harmonic Correction Term to Argument of Latitude, Eccentricity, Sine Harmonic Correction Term to Argument of Latitude, Square Root of the Semi-Major Axis, Longitude of Ascending Node of Orbit Plane at Weekly Epoch, Cosine Harmonic Correction Term to Angle of Inclination, Inclination Angle at Reference Time, Sine Harmonic Correction Term to Angle of Inclination, Cosine Harmonic Correction Term to Orbit Radius, Argument of Perigee, Rate of Right Ascension, Broadcast Group Delay, which describes the differential delay between two GNSS signal frequencies transmitted by each satellite.
[0046] According to a further aspect of the invention, the training data set may comprise authentic GNSS signal data, both real and simulated, of the GPS constellation at L1 / L5 frequencies and Galileo constellation at El / E5a frequencies, and altered GNSS signal data, both real and simulated, for the following spoofing attacks: meaconing, at two different delays; synchronized spoofing; advanced attacks; SCER attacks; stationary meaconing with variable power and exposure time; non-coherent spoofing by stationary spoofer using synthetic ephemeris; ■ non-coherent spoofing by stationary spoofer using real broadcast ephemeris; coherent spoofing from stationary spoofer using real broadcast ephemeris; non-coherent temporal spoofing from stationary spoofer using synthetic ephemeris; coherent temporal spoofing from stationary spoofer using real broadcast ephemeris; position non-coherent spoofing and GNSS time from mobile spoofer; and stationary non-coherent spoofing with extreme time shifts and wherein, for each GNSS signal of the training data set, the values of all the above parameters of interest have been calculated.
[0047] It is also a specific object of the invention a method for detecting the spoofing of a GNSS signal, comprising, for each epoch, the following operational steps:
[0048] A. through a multi-frequency and multi-constellation GNSS antenna, configured to operate at the frequency bands of a plurality of GNSS constellations, receiving a plurality of GNSS signals;
[0049] B. by means of a GNSS receiver, operationally connected to the GNSS antenna, receiving and processing the GNSS signals of the plurality of GNSS signals received by the GNSS antenna, and outputting, encoded in an input signal, a plurality of values for a respective plurality of parameters of interest for each GNSS signal of the plurality of GNSS signals;
[0050] C. by means of a processing unit, operationally connected to the GNSS receiver and to a memory, wherein the configuration parameters of at least one pre-trained machine learning model are stored:
[0051] Cl. receiving as input the input signal associated with the plurality of received GNSS signals,
[0052] C2. selecting a set of N parameters of interest for each GNSS signal of the plurality of GNSS signals, the parameters of interest being encoded in the input signal;
[0053] C3. for each set of N parameters of interest thus selected, implementing at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory, providing this selected set of parameters as input to the machine learning model N parameters of interest, and obtaining at least one respective output parameter as output from the machine learning model, the value of which depending on whether the GNSS signal associated with that set of N selected parameters of interest provided as input is authentic or not; and
[0054] C4. processing a corresponding output signal, encoding, for each GNSS signal associated with the respective set of selected N parameters of interest, the at least one output parameter obtained from the machine learning model,
[0055] Dl.through an emitter operationally connected to the processing unit, receiving the output signal and emitting a corresponding detection signal, for notification to an operator.
[0056] According to another aspect of the invention, the number N and the parameters selected by the data processing unit, among all the parameters of interest calculated by the GNSS receiver and encoded in the input signal, can be predefined or can be updated cyclically, as the number of data available for training the at least one machine learning model increases, and can depend on the application and operating modes of the system of the invention, optionally on whether the system is intended to be static or a low or high dynamic system, as well as on the computational capacity of the processing unit.
[0057] According to a further aspect of the invention, the method may comprise, preliminarily to step A or step C, a selection step of at least one machine learning model whose parameters are stored in memory, with which the plurality of GNSS signals received by the GNSS antenna are to be analyzed.
[0058] According to a further aspect of the invention, the at least one machine learning model implemented by the method may be a model between: a support vector machine, a feedforward neural network, a long- and short-term memory recurrent neural network, a KAN neural network, a Random Forest, an XGBoost, a convolutional neural network.
[0059] According to another aspect of the invention, the method may comprise, after step C:
[0060] D21. by means of the processing unit, based on the output signal, counting the number of GNSS signals of the plurality of GNSS signals, subject to spoofing attack for each GNSS constellation; and
[0061] D31. if the number of predicted GNSS signals, subject to spoofing attack for a GNSS constellation exceeds a predetermined threshold value, via the emitter, emitting an alert signal to signal the attack of the entire constellation GNSS.
[0062] According to a further aspect of the invention, the method may comprise, after step B:
[0063] D22. through the processing unit, analyzing the input signal to verify whether one or more of the values of the plurality of parameters associated with the plurality of GNSS signals, optionally the ACG gain value, is anomalous and indicates a jamming attack, and
[0064] D32. if so, through the emitter, emitting an alert signal to signal a possible jamming attack on the GNSS signal.
[0065] The invention will be now described, for illustrative but not limitative purposes, according to its preferred embodiments, with particular reference to the Figures in the accompanying drawings, in which: figure 1 shows a schematic representation of the system for detecting a GNSS signal spoofing attack according to the present invention; figure 2 is a possible schematic representation of the content of an input signal, processed from a plurality of GNSS signals, received by the system of Figure 1; figure 3 illustrates a possible optional schematic representation of the content of an output signal, processed by the system of Figure 1; figures 4a and 4b show a graphical representation of an ML model implementable by the system of Figure 1, according to a particular first embodiment of the invention; figure 5 is another schematic representation of the ML model of Figures 4a and 4b; figures 6 and 7 are schematic representations of an ML model implemented by the system of Figure 1, according to a particular second embodiment of the invention; figures 8 and 9 illustrate a possible optional schematic representation of a detail of the ML model implemented by the system of Figure 1, according to a particular third embodiment of the invention; and figure 10 shows the main steps of a method for detecting GNSS signal spoofing attacks, according to the invention.
[0066] With particular reference to the attached figures, it will be noted how a system for detecting GNSS signal spoofing attacks according to the present invention, is generally indicated with reference 1 and comprises a multi-frequency and multi-constellation GNSS antenna 2, configured to operate at the frequency bands of a plurality of GNSS constellations and receive, for each epoch, a plurality of GNSS signals. The GNSS antenna 2 of the system 1 of the invention is therefore able to receive signals from all the satellites of each GNSS constellation that, at a certain moment (more precisely, at a certain "time epoch" or "epoch"), are "visible" to it, that is, they are within its reception field. By way of non-limiting example, the constellations and GNSS signals that the GNSS antenna 2 of the system 1 of the invention can receive are signals associated with two or more constellations between: GPS, Galileo, Beidou, GLONASS, EGNOS, WAAS, QZSS and PNT constellations in LEO orbits.
[0067] The system 1 of the invention further comprises a GNSS receiver 3, configured to operate at a given sampling frequency, operationally connected to the GNSS antenna 2 and configured to receive and process (including sampling at the given sampling frequency), for each epoch, the plurality of GNSS signals received by the GNSS antenna 2, and output, encoded in an input signal SIN, a plurality of values for a respective plurality of parameters of interest for each GNSS signal of the plurality of GNSS signals.
[0068] In particular, the GNSS receiver 3 is configured to calculate, for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna 2, at least the following parameters of interest, namely:
[0069] - lock time, i.e. the time necessary for the GNSS receiver 3 to tune to the GNSS signal of a given satellite N, from the moment the signal was visible to the receiver;
[0070] - carrierto noise ratio, i.e. the ratio between the carrier signal and the background noise, in other words the Power level of this GNSS signal, received by the GNSS receiver s under noise operating conditions;
[0071] - pseudorange, i.e. the distance measured between the GNSS receiver 3 and the satellite that emitted the signal;
[0072] - Doppler frequency, that is, the measurement of the doppler frequency of the GNSS signal of the satellite that emitted the signal, measured by the GNSS receiver 3;
[0073] - Full carrier phase, i.e. the measurement of the distance between the satellite associated with the received GNSS signal and the GNSS receiver, expressed in units of cycles of the carrier frequency of the GNSS signal;
[0074] - multipath correction, estimation of the multipath induced error on the detection of the pseudorange of the GNSS receiver 3;
[0075] - code variance, i.e. the standard deviation of the pseudorange error in the GNSS receiver 3;
[0076] - carrier variance, i.e. the standard deviation of the carrier phase error, in the GNSS receiver 3;
[0077] - Doppler variance, i.e. the standard deviation of the Doppler measurement error of the GNSS receiver 3;
[0078] - carrier multipath correction, i.e. the estimation of the multipath error on the carrier phase detection of the GNSS receiver 3;
[0079] - receiver clock bias, that is, the clock bias of the GNSS receiver 3, of the PVT solution (Position, Speed, Time), with respect to the UTC time reference (coordinated universal time);
[0080] - receiver clock drift, i.e. the clock drift of the GNSS receiver 3, obtained from the error of the GNSS receiver 3 clock, with respect to the UTC time reference;
[0081] - carrier multipath correlation, i.e. the correlation value of the multipath effect on the measurement of the carrier phase. This parameter is calculated using the APME (A-Post Multipath Estimation) technique that uses additional correlators, to estimate the multipath error on the pseudorange and carrier phase measurements.
[0082] - smoothing correction, i.e. the correction to be applied to the pseudorange to mitigate its errors, using carrier phase measurements;
[0083] - AGC gain, i.e. information on the gain applied by the Automatic Gain Control, to the incoming GNSS signal;
[0084] - I and Q samples of signal correlation, i.e. the results of the correlation, in phase (I) and in quadrature (Q), between the internal replication of the signal and that received from the GNSS satellites, also calculated on the basis of the given sampling frequency of the GNSS receiver;
[0085] - Week Number, i.e. the progressive number of weeks starting from a given date that is different for each GNSS system;
[0086] - SV Health Status, i.e. a parameter indicating whether the GNSS satellite from which the GNSS signal originates, i.e. the data and signals transmitted by it, can be considered usable by the GNSS receiver 3;
[0087] - SV Configuration, i.e. a parameter containing information on the health status of the satellite, on the status of the GNSS signal and on the operating mode of the satellite (e.g. Normal, under test, under maintenance);
[0088] - Signal Health Status, one per frequency, which indicates the health status of each of the GNSS signals, at the different transmission frequencies L2, L5 / E5a, E6, transmitted by the satellite;
[0089] - Ephemeris Reference Time;
[0090] - the epoch correction parameters transmitted by the satellite (SV Clock corrections a_fO, a_fl, a_f2), given in 3 parameters aO, al and a2 of a second-degree polynomial, which provide the model to be applied to the drift of the satellite's on-board clock from a known instant;
[0091] - the orbital parameters that accurately define the orbit on which each satellite moves: Sine Harmonic Correction Term to Orbit Radius, Mean Motion Difference from Computed Value, Mean Anomaly at Reference Time, Cosine Harmonic Correction Term to Argument of Latitude, Eccentricity, Sine Harmonic Correction Term to Argument of Latitude, Square Root of the SemiMajor Axis, Longitude of Ascending Node of Orbit Plane at Weekly Epoch, Cosine Harmonic Correction Term to Angle of Inclination, Inclination Angle at Reference Time, Sine Harmonic Correction Term to Angle of Inclination, Cosine Harmonic Correction Term to Orbit Radius, Argument of Perigee, Rate of Right Ascension; - Broadcast Group Delay - BGD, which describe the differential delay between two GNSS signal frequencies transmitted by each satellite (Broadcast Group Delay (L1-L2), Broadcast Group Delay (L1-L5), Broadcast Group Delay (L2-L5), Broadcast Group Delay (El-E5a), Broadcast Group Delay (E1-E6), Broadcast Group Delay (E5a-E6)).
[0092] The system 1 of the present invention further comprises a memory 4, configured to store configuration parameters of at least one machine learning (ML) model, pre-trained with a training data set including authentic GNSS signal data and altered GNSS signal data, for spoofing attacks, some of which will be better explained below.
[0093] The system 1 of the invention further comprises a processing unit 5, operationally connected to the GNSS receiver 3 and to the memory 4 and, for each epoch, configured for:
[0094] - receiving the input signal SIN from the GNSS receiver 3 and selecting, for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna 2, whose parameters of interest are encoded in the signal SIN, a set of N (N=l, 2, ...) parameters of interest;
[0095] - receiving the configuration parameters of the at least one pre-trained machine learning model;
[0096] - for each set of N parameters of interest thus selected, implementing the at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory 4, providing the machine learning model with this selected set of N parameters of interest, and obtaining from the machine learning model at least one respective output parameter, whose value depends on whether the GNSS signal associated with this set of N parameters of interest provided as input is authentic or not; and
[0097] - processing a corresponding output signal SOUT, wherein, for each GNSS signal associated with the respective set of N parameters of interest, at least one output parameter outputted from the machine learning model is encoded.
[0098] In other words, according to a preferred embodiment of the invention, the output signal SOUT output by the machine learning model has therein encoded at least one output parameter for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna 2, the value of which varies based on the prediction or not, by means of the ML algorithm, of a spoofing attack for the respective GNSS signal. Optionally but advantageously, the output signal SOUT output by the processing unit 5 also has therein encoded one or more of the following information:
[0099] - the epoch, referred to by the plurality of GNSS signals received by the GNSS antenna 2 and transmitted from the GNSS receiver 3 to the processing unit 5 for analysis; - an identifier of the GNSS constellation subject to spoofing attack;
[0100] - an identifier of the satellite or satellites of this GNSS constellation, involved in the attack;
[0101] - an identifier of the frequency band or bands involved in the spoofing attack; and optionally
[0102] - an identifier of the spoofing type.
[0103] According to an advantageous aspect of the present invention, the processing unit 5 is configured to select among all the parameters of interest calculated by the GNSS generator 3, those to be used in the machine learning model as well as their number N, based on the specific type of application and operating modes of the system 1 of the invention. For example, if the system 1 of the invention is installed on a drone, which is therefore intended to operate on the move, the number N of parameters of interest selected by the processing unit 5 may be 15, optionally corresponding to the first 15 parameters of the above list. If, on the other hand, the system 1 of the invention is installed on a reference station for network synchronization, which is therefore fixed, the number N of parameters of interest selected by the processing unit 5 may also be higher, for example it may comprise all 46 reference parameters listed above. Still different can be both the number N and / or the actual reference parameters selected from those calculated by the GNSS receiver 3 from the processing unit 5, if the system is installed on a train, a satellite, a boat, an earthmoving machine, a wheeled vehicle, an aircraft, etc. The selection of the number N and the parameters of interest operated by the processing unit 5, based on the application and the operating modes of the system 1 of the present invention can be predefined or updated cyclically, for example by any selection method suitable for the purpose, optionally a "backward feature elimination" method (for example, as described in the article by Rizgar R. Zebari et al., "A Comprehensive Review of Dimensionality Reduction Techniques for Feature Selection and Feature Extraction", Journal of Applied Science and Tecnology Trends, vol. 1, No. 02, pp 56-70 (2020)), as the number of data available for machine learning model training increases.
[0104] Examples of representation, given purely by way of non-limiting example, of an input signal SIN and an output signal SOUT are provided in Figures 2 and 3, respectively. With regard to Fig. 2, a plurality of four GNSS signals are represented in the form of a table, all received by the GNSS receiver 3 of a system 1 installed on a drone, at the same epoch and, more specifically, two GNSS signals received by a satellite (Sat. 1) at frequencies Freq. 1 and Freq. 2 and two GNSS signals received by another satellite (Sat. 2) at the same frequencies Freq. 1 and Freq. 2. For each of these GNSS signals, as seen in this figure, the input signal includes fifteen parameters of interest, but as already mentioned above, the person skilled in the art will have no difficulty in understanding how, depending on the application and the operating modes of the system 1 of the invention, the number N of parameters of interest may vary. Specifically, the table of Fig. 2 presents an example of the content of the input signal SIN, i.e. 16 columns of which: the first, contains a value indicative of the epoch when the GNSS signals were received by the GNSS receiver 3 and the following fifteen, contain the values of the abovesaid fifteen parameters of interest, calculated by the GNSS receiver 3 for each of the four received GNSS signals. The method of the present invention, as will also be explained below, provides for real-time operation and, therefore, the table in Fig. 2 will generally include for each instant, as many rows as there are GNSS signals received by the GNSS receiver 3 for each frequency of such signals, and 1+N columns, i.e. a first column for the instant of time (epoch) present to be processed, and N columns, one for each parameter of interest of the specific GNSS signal.
[0105] With regard to Fig. 3, therein the signal SOUT is also represented by means of a table, including as many rows as the satellites of each constellation are that can be detected by the GNSS antenna 2 (in the figure the satellites of the Beidou, Galileo and GPS constellations are represented) and as many columns as the operating frequencies are at which the GNSS receiver 3 is configured to operate (in the case depicted, two frequencies for each constellation, but the person skilled in the art will have no difficulty in understanding how a GNSS receiver 3 can also operate at a number greater than two frequencies) to detect the signals transmitted by each of these constellations, plus two columns, one marked with the name "PRN" and containing an identifier of each satellite of each constellation and another column ("Spoofed flag" in Fig. 3) containing the value "1" to indicate that at least one corresponding received GNSS signal is altered (i.e., not authentic) or "0" to indicate that all corresponding received GNSS signals are authentic. The other abovesaid information contained in the output signal SOUT can be, for example, encoded in additional strings, one for each GNSS signal, or integrated into the table of Fig. 3. In any case, the person skilled in the art will have no difficulty in understanding how the signal SOUT output by the processing unit 5 can be represented in any other way suitable for the purpose, noting for the purposes of the invention not so much the particular form of its representation, as its information content.
[0106] Returning to the processing unit 5 and the at least one ML model that it is configured to implement, this can be selected from: a support vector machine (SVM), a feed-forward neural network, a long- and short-term memory recurrent neural network (or LSTM), a KAN neural network (of "Kolmogorov-Arnold"), a Random Forest (RF), an XGBoost, a convolutional neural network (CNN).
[0107] According to a first embodiment of the invention, the ML model comprises a support vector machine (SVM), with one or more kernels, wherein the number of kernels and the respective functions are selected in a known manner from the training data set of the ML models, for example but not limited to a radial, polynomial or Gaussian function.
[0108] By way of non-limiting example, in Figs. 4A, 4B and 5 a schematic representation of the operation of the SVM model is provided, wherein Figures 4A and 4B represent the classification operated by the kernel, given the binary classification problem (authentic GNSS signal / altered GNSS signal). For simplicity of discussion, assume that each given point is characterized by only two parameters (coordinates in the parameter space, in this case 2D), as represented in Fig. 4A. The aim of the SVM algorithm is to construct a (hyper) separation plane between the two classes. To do this, given that in this case, as for many problems of real interest, the data points are not linearly separable (Fig. 4A), the first operation performed by the kernel is the projection of the data points onto a new space where the problem can be solved. The Kernel then maps the data of the plurality of GNSS signals received by the GNSS receiver 3 (i.e., the N parameters of interest selected for each GNSS signal) from their original space, to a larger size space. Different "Kernel" functions clearly perform different transformations. In the case depicted in the image of Fig. 4B, by way of non-limiting example, the Kernel has mapped the parameters of interest of each GNSS signal from a 2D to a 3D space, through a radial transformation, which makes it possible to separate the classes.
[0109] Fig. 5, given the same binary classification problem (authentic GNSS signal / altered GNSS signal), represents for simplicity, a two-dimensional case, where the separator plane is reduced to a straight line, able to perfectly separate the signals into two classes. The points of the two classes closest to the separation plane, which are circled in the image, are called "support vectors", and represent the points that the algorithm uses to build the separation plane. The plane is built with the constraint of maximizing the so-called "margin" between the two classes, that is, the distance between the parallel planes that contain the support vectors of the two classes (represented, in the image, as two lines parallel to the separation plane). The SVM algorithm, therefore, identifies, among all the possible planes capable of separating the two classes (authentic GNSS signal / altered GNSS signal), the one that maximizes the distance between the classes themselves, thus increasing the generalization capacity of the model. Alternatively, according to another (second) embodiment of the invention, the at least one ML model comprises a feed-forward neural network. Such a neural network, in addition to the input and output layers, comprises a number of hidden layers greater than or equal to 2, optionally between 2 and 20, more optionally between 2 and 5, which may vary based on the application and computational capacity of the processing unit 5 of the system 1, wherein each hidden layer has a number of neurons between 40 and 150, optionally between 50 and 100.
[0110] By way of non-limiting example, according to an embodiment of the invention and in the case of application of the system 1 of the invention, the feed-forward neural network may comprise:
[0111] - an input layer, having as many neurons as the N parameters of interest are, selected by the processing unit 5 from those encoded in the input signal SIN for the respective GNSS signal, and a number of parameters equal to P=[4 x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive the value of a respective parameter of interest;
[0112] - a plurality of hidden layers, for example three hidden layers, each having a number of neurons and a fixed number of parameters equal to P=[no. of Previous Layer Neurons] x [No. of Current Layer Neurons] + [No. of Previous Layer Neurons] parameters and as activation function for each neuron of this layer, a Softmax function and ReLu function; and
[0113] - an output layer, having as many neurons as the information to be encoded in the output signal (SOUT) to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons] and as an activation function, for each neuron of this layer, a Softmax function.
[0114] It should be noted that the number of neurons is equal for each hidden layer of the feedforward network and is set based on the application and computational capacity of the processing unit 5 of the system 1.
[0115] According to a variant of the feed-forward neural network, in the simple case of binary classification, in which the neural network comprises a single neuron in the output layer, a number of parameters equal to K= [no. neurons previous layer] x[No. of current layer neurons] + [No. of previous layer neurons] parameters is provided in the output layer and as an activation function for each neuron of this layer, a Sigmoid function.
[0116] In the feed-forward neural network, as is known, each neuron is connected to all neurons of the next layer.
[0117] According to a variant of the present embodiment, the type and functions of expected activations for each neuron in each hidden layer could also be different, based on the application and computational capacity of the processing unit 5 of the system 1. For example, in the above case in Fig. 6, the Softmax activation function of each neuron of the first hidden layer could be replaced with the ReLu activation function employed for each neuron of the second hidden layer and vice versa.
[0118] In Fig. 6, by way of non-limiting example, a schematic representation of a specific feedforward neural network that can be implemented in the ML model of the system 1 of the invention is provided, in the event that the system 1 of the invention is installed on a drone (example of high dynamic application). In Fig. 6, the feed-forward neural network comprises an input layer having fifteen neurons for corresponding fifteen parameters of interest (e.g. the first fifteen) described above and three hidden layers. Each hidden layer comprises 64 neurons and a corresponding number of parameters calculated according to the above formula and the output layer comprises four neurons, i.e. one for each spoofing type attack to be identified among: synchronized, advanced meaconing or SCER, whereby the corresponding output signal SOUT will comprise at least four output parameters, each with value for example, "0" or "1", depending on the specific spoofing type attack predicted by the neural network, for the respective GNSS signal. In case the corresponding analyzed GNSS signal is predicted as authentic, the values of the four output parameters will be, for example, all equal to zero.
[0119] Fig. 7 provides, on the other hand, a clear purely schematic representation of the flow of information (links) that crosses the neurons of the various layers of the feed-forward neural network, in the case of binary classification, or in the case in which the neural network must distinguish between altered or authentic GNSS signals.
[0120] According to a third embodiment of the system 1 of the invention, the ML model comprises a long-term and short-term memory recurrent (or LSTM) neural network, each in turn including an array of units, wherein each unit comprises four feed-forward neural networks, for example of the type described above: input gate, output gate, forget gate, cell state.
[0121] The number of units included in the array of units corresponds to the number of epochs that one would like to consider.
[0122] By way of non-limiting example, according to an embodiment of the invention, the LSTM neural network may contain:
[0123] - an input layer, having N neurons, i.e. as the N parameters of interest are, selected by the processing unit 5 among those encoded in the input signal SIN forthe respective GNSS signal, and a number of parameters equal to P=[4x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive as input the value of a respective parameter of interest;
[0124] - an array of E units, where E corresponds to the number of epochs, wherein each unit can implement one of the activation functions between Tanh and ReLu, as activation function for each neuron; and
[0125] - an output layer, having as many neurons as the information to be encoded in the output signal (SOUT) to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons], considering the number of neurons of the last layer of the unit of the last epoch, and a Softmax function as an activation function for each neuron of that layer..
[0126] In turn, each of the four feed-forward neural networks of each unit of the LSTM network array comprises:
[0127] - an input layer, having as many neurons as the parameters of interest are, selected by the processing unit 5 from those encoded in the input signal SIN for the respective GNSS signal, and a number of parameters equal to P= [4 x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive the value of a respective parameter of interest;
[0128] - a plurality of hidden layers, each having a fixed number of neurons set based on the application and computational capacity of the processing unit 5 of system 1, and a fixed number of parameters equal to P=[no. of Previous Layer Neurons] x [No. of Current Layer Neurons] + [No. of Previous Layer Neurons] parameters and as an activation function for each neuron of this layer, respectively, a Softmax function in the first hidden layer, and a ReLu function in the second and third hidden layers; and
[0129] - an output layer, having as many neurons as the information to be encoded in the output signal to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons] and as an activation function, for each neuron of this layer, a Softmax function.
[0130] Again, the number of hidden layers in each feed-forward neural network of the LSTM neural network, may vary based on the application and computational capacity of the processing unit 5 of the system 1 and is greater than or equal to 2, optionally between 2 and 20, more optionally between 2 and 5. In addition, each hidden layer has a number of neurons between 40 and 150, optionally between 50 and 100.
[0131] Furthermore, according to a variant of the LSTM neural network, in the simple case of binary classification, where a feed-forward neural network of a unit comprises a single neuron in the output layer, a number of parameters equal to K= [no. neurons previous layer] x[No. of current layer neurons] + [No. of previous layer neurons] parameters is provided in the output layer and as an activation function for each neuron of this layer, a Sigmoid function.
[0132] According to a further variant of the present embodiment, the order of use of the activation functions provided in each unit of the array could also be different, depending on the application and computational capacity of the processing unit 5 of the system 1.
[0133] The number of epochs E, in the LSTM neural network may also vary depending on the type of application of the system 1 of the invention. For example, for static applications (e.g. Reference Station) the number of epochs E may be between 60 and 150, while for low dynamic applications (e.g. earthmoving machines) the number E of usable epochs may be between 30 and 90. For high dynamic applications (e.g. drones) the number E of usable epochs can be between 15 and 60.
[0134] By way of non-limiting example, in Fig. 8 a schematic representation of a specific LSTM network is provided for a system 1 to be installed on drones, in which therefore N is equal to 15 parameters of interest selected by the processing unit 5 and the number of epochs E is equal to 30 (1 epoch corresponding to one second in time terms). The LSTM network of Fig. 8 therefore comprises:
[0135] - an input layer, having 15 neurons as many the 15 parameters of interest are, encoded in the input signal SIN for the respective GNSS signal and selected by the processing unit 5 and a number of parameters equal to P=[4xNo. of neurons of the input layer] parameters, wherein each neuron is configured to receive as input the value of a respective parameter of interest;
[0136] - an array of 30 units, i.e. corresponding to the number of epochs (in this case 30), each having 100 neurons per unit (and therefore 3000 in total) and 46400 neural network parameters per unit (and therefore 1392000 in total). These units may implement one of the activation functions between Tanh and ReLu as an activation function for each neuron; and
[0137] - an output layer, having as many neurons as the information encoded in the output signal SOUT is, in this example case equal to 4, and 500 neural network parameters (i.e., 100x4 +100) and as an activation function for each neuron of that layer, a Softmax function.
[0138] Fig. 9 schematically represents the information flow exchanged between two consecutive units (one for each time epoch of a GNSS signal of the plurality of received GNSS signals) of the LSTM network. Returning to the at least one ML model implemented by the processing unit 5, for the training of each of its three embodiments described above (SVM, RR feed-forward and LSTM) the same set of training data was used, comprising about 50 million of real and simulated data points of authentic signals, about 75 million of simulated data points of signals with spoofing attacks and about 20 million of real data points of signals with spoofing attacks. More specifically, the set of training data used comprises:
[0139] - data points of authentic signals, both real and simulated, of the GPS constellation, at the two frequencies LI and L5, and of the Galileo constellation, at the two frequencies El and E5a in which, for each authentic GNSS signal, all the parameters of interest described above have been calculated; and
[0140] - data points of altered GNSS signals, both real and simulated, including the corresponding values of the same parameters of interest, for each of the types of spoofing attack between: meaconing, at a plurality of different delays; synchronized spoofing; advanced attack;
[0141] SCER attack; stationary meaconing with variable power and exposure time; non-coherent spoofing by stationary spoofer using synthetic ephemeris; non-coherent spoofing by stationary spoofer using real broadcast ephemeris; coherent spoofing from stationary spoofer using real broadcast ephemeris; non-coherent temporal spoofing from stationary spoofer using synthetic ephemeris; coherent temporal spoofing from stationary spoofer using real broadcast ephemeris; position non-coherent spoofing and GNSS time from mobile spoofer; and stationary non-coherent spoofing with extreme time shifts (e.g. + / - 1 to 2 years).
[0142] Of all the data included in the training dataset, about 30% was used to train each ML algorithm (SVM, RR feed-forward and LSTM) implementable by the processing unit 5, the remaining 70% was instead used as a test dataset.
[0143] The system 1 of the present invention also comprises an emitter 6, operationally connected to the processing unit 5 and configured to receive the output signal SOUT and emit a corresponding spoofing detection signal SD of the plurality of GNSS signals. The emitter 6 of the detection signal SD is configured to transmit this signal, optionally also remotely, for notification to an operator. The signal SD can be a video or audio signal, in any case a signal suitable to provide the operator with the information encoded in the output signal SOUT for his immediate intervention.
[0144] The system 1 described above is configured to implement a method 10 for detecting the spoofing of GNSS signals, which is also the subject-matter of the present invention and includes, for each epoch, the following operational steps:
[0145] A. through a multi-frequency and multi-constellation GNSS antenna 2, configured to operate at the frequency bands of a plurality of GNSS constellations, receiving a plurality of GNSS signals;
[0146] B. by means of a GNSS receiver 3, operationally connected to the GNSS antenna 2, receiving and processing the GNSS signals of the plurality of GNSS signals received by the GNSS antenna 2, and outputting, encoded in an input signal SIN, a plurality of values for a respective plurality of parameters of interest for each GNSS signal of the plurality of GNSS signals;
[0147] C. by means of a processing unit 5, operationally connected to the GNSS receiver 3 and to a memory 4, wherein the configuration parameters of at least one pre-trained machine learning model are stored:
[0148] Cl. receiving as input the input signal SIN associated with the plurality of received GNSS signals,
[0149] C2. selecting a set of N parameters of interest for each GNSS signal of the plurality of GNSS signals, the parameters of interest being encoded in the input signal SIN;
[0150] C3. for each set of N parameters of interest thus selected, implementing at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory 4, providing this selected set of parameters as input to the machine learning model N parameters of interest, and obtaining at least one respective output parameter as output from the machine learning model, the value of which depending on whether the GNSS signal associated with that set of N selected parameters of interest provided as input is authentic or not; and
[0151] C4. processing a corresponding output signal SOUT, encoding, for each GNSS signal associated with the respective set of selected N parameters of interest, the at least one output parameter obtained from the machine learning model;
[0152] DI. through an emitter 6 operationally connected to the processing unit 5, receiving the output signal SOUT and emitting a corresponding spoofing detection signal SD of the plurality of GNSS signals, for notification to an operator. According to a preferred embodiment of the invention, the number N and the parameters selected by the data processing unit 5, among all the parameters of interest calculated by the GNSS receiver 3 and encoded in the input signal SIN, depends on the application and operating modes of the system 1 of the invention, for example depending on whether the system 1 is intended to be static or a low or high dynamic system as described above.
[0153] The method 10 of the invention, according to a preferred embodiment of the invention, comprises, for example preliminarily to step A or in any case preliminarily to step C, a selection step of at least one machine learning model whose parameters are stored in memory 4, with which the plurality of GNSS signals received by the GNSS antenna 2 are to be analyzed. Thus, for example, the choice between machine learning models can be influenced by various factors, such as:
[0154] - scenario complexity: each model has been trained with data from three types of scenarios, from the simplest (for example, open field without background noise and low levels of multipath / interference errors) to the most complex (for example, urban environment, areas or environments with tall vegetation nearby);
[0155] - the required computational load: an operator can in fact select an ML model based on the available computational resources, since the computational load of the ML models described above differs, especially if the processing unit 5 is not highly performing.
[0156] - the required performance: depending on the accuracy requirements, a user can choose the model that best meets their needs, balancing between accuracy and resource consumption.
[0157] Returning to the method 10 of the invention, according to a variant thereof, the method 10 comprises, in a step D21 subsequent to step C, by means of the processing unit 5, counting, on the basis of the output signal SOUT, the number of GNSS signals of the plurality of GNSS signals, subject to spoofing attack for each GNSS constellation and, if the number of predicted GNSS signals, subject to spoofing attack, for a GNSS constellation exceeds a predetermined threshold value, a step D31 of emitting, via the emitter 6, an alert signal SA of a type suitable for the purpose, to signal the attack of the entire GNSS constellation.
[0158] According to yet another variant of the invention, the method 10 comprises, by means of the processing unit 5, subsequently to B, a step D22 of analyzing the input signal SIN to verify whether the GNSS signals are undergoing a jamming attack (for example because in the input signal SIN at least one parameter of the ACG gain has an abnormal value) and, if so, a subsequent step D32 of emitting, through the emitter, an alert signal SA of a type suitable for the purpose, to signal a possible jamming attack of the respective GNSS signal, which could be preparatory to a subsequent spoofing attack.
[0159] The system 1 and method 10 described above achieve the aims stated in the introduction. The system 1 and method 10 of the invention allow to recognize any GNSS signals spoofing attack and identify a wide range of spoofing attacks in a more precise manner than traditional systems, i.e. with an accuracy higher than that of currently implemented systems, in the case of binary classification, i.e. in the case where the system is configured to recognize a signal altered by an authentic one.
[0160] The system 1 of the invention has a very high accuracy even in the case of multi-class classification, that is, in the case where the system is configured not only to recognize a signal altered by an authentic one but also to provide an indication of the spoofing type attack, which is certainly an important added value compared to the traditional methodologies.
[0161] The system 1 described above, thanks to the method 10, allows to precisely identify the satellite or satellites of several GNSS constellations under attack and works in multi-frequency, thus satisfying the growing market demand.
[0162] The preferred embodiments and possible versions of the invention have been outlined above, but it is to be understood that the persons skilled in the art may make modifications and changes without infringing the scope of protection, as defined in the attached claims.
[0163] Thus, for example, although the system 1 has been described as a single hardware device, the person skilled in the art will have no difficulty in understanding how the system 1 can also be a distributed system, in which the various hardware components, instead of being wired together, can communicate remotely via any suitable communication network.
[0164] Still, the GNSS receiver 3 and the processing unit 5 have been described as separate entities from each other, but the person skilled in the art will have no difficulty in understanding how these can also be integrated with each other, without however departing from the scope of protection of the present invention.
[0165] Furthermore, the GNSS antenna 2 of the GNSS signals and the GNSS receiver 3 have been described as separate entities from each other, but the person skilled in the art will have no difficulty in understanding how the respective functionalities can also be integrated into a single device, without however departing from the scope of protection of the present invention.
[0166] The memory 4 can also be physically integrated, for example, into the processing unit 5, without thereby departing from the scope of protection of the present invention. Furthermore, although it has not been described in detail, the person skilled in the art will have no difficulty in understanding how, the memory 4 is configured to store all the intermediate processing parameters, necessary for the GNSS receiver 3 for the implementation of the respective calculations and the processing unit 5 forthe implementation of the respective ML models.
[0167] Not least, although only three ML models (SVM, Feed-forward Neural Networks and LSTM) have been described in detail in the present description, the person skilled in the art will recognize that he will have no difficulty in implementing the other types of machine learning models mentioned above, given the abovesaid training set and knowing the input layer and the output layer.
Claims
CLAIMS1. System (1) for detecting a GNSS signal spoofing attack, comprising:- a multi-frequency and multi-constellation GNSS antenna (2), configured to operate at the frequency bands of a plurality of GNSS constellations and receive, for each epoch, a plurality of GNSS signals;- a GNSS receiver (3), configured to operate at a given sampling frequency, operationally connected to the GNSS antenna (2) and configured to receive and process, for each epoch, the plurality of GNSS signals received by the GNSS antenna (2), and output, encoded in an input signal (SIN), a plurality of values for a respective plurality of parameters of interest for each GNSS signal of the plurality of GNSS signals;- a memory (4) configured to store configuration parameters of at least one machine learning model, pre-trained with a training data set including authentic GNSS signals data and altered GNSS signals data for different types of spoofing attacks;- a processing unit (5), operationally connected to the GNSS receiver (3) and to the memory (4) and, for each epoch, configured for receiving the input signal (SIN) from the GNSS receiver (3) and selecting, for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna (2), whose parameters of interest are encoded in the signal (SIN), a set of N (N=l, 2, ...) parameters of interest; receiving, from memory (4), the configuration parameters of the at least one pre-trained machine learning model; for each set of N parameters of interest thus selected, implementing the at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory (4), providing the machine learning model with this selected set of N parameters of interest, and obtaining from the machine learning model at least one respective output parameter, whose value depends on whether the GNSS signal associated with this set of N parameters of interest provided as input is authentic or not; and processing a corresponding output signal (SOUT), wherein, for each GNSS signal associated with the respective set of N parameters of interest, at least one output parameter outputted from the machine learning model is encoded; and- an emitter (6), operationally connected to the processing unit (5) and configured to receive the output signal (SOUT) and emit a corresponding spoofing detection signal of the plurality of GNSSsignals; wherein the output signal (SOUT) output by the machine learning model has therein encoded, in case of spoofing attack, for each epoch and for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna (2) at the abovesaid epoch, in addition to at least one output parameter, also the following information:- an identifier of the GNSS constellation or constellations subjected to attack;- an identifier of the GNSS constellation satellite ore satellites, involved in the attack; and- an identifier of the frequency band or bands involved in the spoofing attack.
2. System (1) according to claim 1, wherein the number N and the parameters of interest that can be selected from the plurality of parameters of interest encoded in the input signal (SIN) depend on the specific type of application of the system (1) and its operating modes, optionally on whether the system (1) is installed in a fixed or mobile location, optionally between: a reference station for network synchronization, a wheeled vehicle, a drone, an earthmoving machine, a boat, an aircraft, a train, a satellite, and also depend on the computing capabilities of the processing unit (5).
3. System (1) according to claim 1 or 2, wherein the number N of parameters of interest is between 5 and 46 parameters, and is optionally determined on the basis of the data from the training dataset, optionally by means of a Backward Feature Elimination method.
4. System (1) according to any previous claim, wherein the output signal (SOUT) obtained from the machine learning model, for each epoch and for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna (2) at the abovesaid epoch, has also encoded therein the epoch and optionally an identifier of the spoofing type.
5. System (1) according to any previous claim, wherein the plurality of GNSS constellations includes two or more constellations between: GPS, Galileo, Beidou, GLONASS, EGNOS, WAAS, QZSS, NavIC and PNT constellations in LEO orbits.
6. System (1) according to any previous claim, wherein the spoofing attack is of the type comprised between: meaconing, synchronized spoofing, advanced attack, SCER attack, stationary meaconing with variable power and exposure time, non-coherent spoofing by stationary spoofer using synthetic ephemeris, non-coherent spoofing by stationary spoofer using true transmitted ephemeris, coherent spoofing by stationary spoofer using true transmitted ephemeris, non-coherent temporal spoofing from stationary spoofer using synthetic ephemeris, coherent temporal spoofing from stationary spoofer using truetransmitted ephemeris, position non-coherent spoofing and GNSS time from mobile spoofer, stationary non-coherent spoofing with extreme time shifts.
7. System (1) according to any previous claim, wherein at least one machine learning model is a model between: a support vector machine, a feed-forward neural network, a long- and short-term memory recurrent neural network, a KAN neural network, a Random Forest, an XGBoost, a convolutional neural network.
8. System (1) according to claim 7, wherein at least one machine learning model includes at least one support vector machine with at least one kernel function between: radial, polynomial, or Gaussian.
9. System (1) according to claim 7, wherein at least one machine learning model comprises at least one feed-forward neural network, including:- an input layer, having as many neurons as the N parameters of interest are, selected by the processing unit (5) from those encoded in the input signal (SIN) for the respective GNSS signal, and a number of parameters equal to P=[4 x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive the value of a respective parameter of interest;- a plurality of hidden layers, optionally between 2 and 20, each having a number of neurons between 40 and 150, optionally between 50 and 100, set based on the application and computational capacity of the processing unit (5) of the system (1), and a fixed number of parameters equal to P=[no. of Previous Layer Neurons] x [No. of Current Layer Neurons] + [No. of Previous Layer Neurons] parameters and as activation function for each neuron of this layer, a function chosen between Softmax and ReLu function; and- an output layer, having as many neurons as the information to be encoded in the output signal (SOUT) to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons] and as an activation function, for each neuron of this layer, a Softmax function; wherein each neuron is connected to all neurons in the next layer.
10. System, according to claim 9, wherein if the neural network comprises only one neuron in the output layer, the activation function for each neuron in that layer is a Sigmoid function.
11. System (1) according to claim 7, wherein the machine learning model comprises at least one long-term and short-term memory recurrent neural network, including an array of units, wherein the number of units comprised in the array of units corresponds to the numberof epochs that one would like to consider.
12. System (1) according to claim 11, wherein the long-term and short-term memory recurrent neural network comprises:- an input layer, having as many neurons as the N parameters of interest are, selected by the processing unit (5) among those encoded in the input signal (SIN) for the respective GNSS signal, and a number of parameters equal to P=[4x No. of neurons of the input layer] parameters, wherein each neuron is configured to receive as input the value of a respective parameter of interest;- an array of E units, where E corresponds to the number of epochs, wherein each unit can implement one of the activation functions between Tanh and ReLu, as activation function for each neuron; and- an output layer, having as many neurons as the information to be encoded in the output signal (SOUT) to be obtained is, a predetermined number of parameters equal to K= [no. of previous layer neurons] x [No. of current layer neurons] + [No. of previous layer neurons], considering the number of neurons of the last layer of the unit of the last epoch, and a Softmax function as an activation function for each neuron of that layer.
13. System (1) according to claim 12, wherein each unit comprises four feed-forward neural networks.
14. System (1) according to any claim 11 to 13, wherein the number E of the epochs is between 5 and 200, optionally between 15 and 150, more optionally between 60 and 150 for static applications, between 30 and 90 for low dynamic applications and between 15 and 60 for high dynamic applications.
15. System (1) according to any previous claim, wherein the parameters of interest of the plurality of parameters of interest include: lock time, carrier to noise ratio, pseudorange, Doppler Frequency, full carrier phase, multipath correction, code variance, carrier variance, Doppler variance, carrier multipath correction, receiver clock bias, receiver clock drift, carrier multipath correlation, smoothing correction, ACG gain, I and Q samples of signal correlation, Week number, SV Health Status, SV Configuration, Signal Health Status, Ephemeris Reference Time, SV Clock corrections, the orbital parameters that accurately define the orbit wherein each satellite moves: Sine Harmonic Correction Term to Orbit Radius, Mean Motion Difference from Computed Value, Mean Anomaly at Reference Time, Cosine Harmonic Correction Term to Argument of Latitude, Eccentricity, Sine Harmonic Correction Term to Argument of Latitude,Square Root of the Semi-Major Axis, Longitude of Ascending Node of Orbit Plane at Weekly Epoch, Cosine Harmonic Correction Term to Angle of Inclination, Inclination Angle at Reference Time, Sine Harmonic Correction Term to Angle of Inclination, Cosine Harmonic Correction Term to Orbit Radius, Argument of Perigee, Rate of Right Ascension, Broadcast Group Delay, which describes the differential delay between two GNSS signal frequencies transmitted by each satellite.
16. System (1) according to claim 15, wherein the training data set comprises authentic GNSS signal data, both real and simulated, of the GPS constellation at L1 / L5 frequencies and Galileo constellation at El / E5a frequencies, and altered GNSS signal data, both real and simulated, for the following spoofing attacks: meaconing, at two different delays; synchronized spoofing; advanced attacks;SCER attacks; stationary meaconing with variable power and exposure time; non-coherent spoofing by stationary spoofer using synthetic ephemeris; non-coherent spoofing by stationary spoofer using real broadcast ephemeris; coherent spoofing from stationary spoofer using real broadcast ephemeris; non-coherent temporal spoofing from stationary spoofer using synthetic ephemeris; coherent temporal spoofing from stationary spoofer using real broadcast ephemeris; position non-coherent spoofing and GNSS time from mobile spoofer; and stationary non-coherent spoofing with extreme time shifts and wherein, for each GNSS signal of the training data set, the values of all the parameters of interest according to claim 15 have been calculated.
17. Method (10) for detecting the spoofing of a GNSS signal, comprising, for each epoch, the following operational steps:A. through a multi-frequency and multi-constellation GNSS antenna (2), configured to operate at the frequency bands of a plurality of GNSS constellations, receiving a plurality of GNSS signals;B. by means of a GNSS receiver (3), operationally connected to the GNSS antenna (2), receiving and processing the GNSS signals of the plurality of GNSS signals received by the GNSS antenna (2), and outputting, encoded in an input signal (SIN), a plurality of values for a respectiveplurality of parameters of interest for each GNSS signal of the plurality of GNSS signals;C. by means of a processing unit (5), operationally connected to the GNSS receiver (3) and to a memory (4), wherein the configuration parameters of at least one pre-trained machine learning model are stored:Cl. receiving as input the input signal (SIN) associated with the plurality of received GNSS signals,C2. selecting a set of N parameters of interest for each GNSS signal of the plurality of GNSS signals, the parameters of interest being encoded in the input signal (SIN);C3. for each set of N parameters of interest thus selected, implementing at least one pretrained machine learning model, configured with the corresponding configuration parameters stored in memory (4), providing this selected set of parameters as input to the machine learning model N parameters of interest, and obtaining at least one respective output parameter as output from the machine learning model, the value of which depending on whether the GNSS signal associated with that set of N selected parameters of interest provided as input is authentic or not; andC4. processing a corresponding output signal (SOUT), encoding, for each GNSS signal associated with the respective set of selected N parameters of interest, the at least one output parameter obtained from the machine learning model,DI. through an emitter (6) operationally connected to the processing unit (5), receiving the output signal (SOUT) and emitting a corresponding detection signal (SD), for notification to an operator wherein the output signal (SOUT) output by the machine learning model has therein encoded, in case of spoofing attack, for each epoch and for each GNSS signal of the plurality of GNSS signals received by the GNSS antenna (2) at the abovesaid epoch, in addition to at least one output parameter, also the following information:- an identifier of the GNSS constellation or constellations subjected to attack;- an identifier of the GNSS constellation satellite ore satellites, involved in the attack; and- an identifier of the frequency band or bands involved in the spoofing attack.
18. Method (10) according to claim 17, wherein the number N and the parameters selected by the data processing unit (5), among all the parameters of interest calculated by the GNSS receiver (3) and encoded in the input signal (SIN), are predefined or are updated cyclically, as the number of data available for training the at least one machine learning model increases,and depend on the application and operating modes of the system (1) of the invention, optionally on whether the system (1) is intended to be static or a low or high dynamic system, as well as on the calculation capacity of the processing unit (5).
19. Method (10) according to claim 17 or 18 comprising, preliminarily to step A or step C, a selection step of at least one machine learning model whose parameters are stored in memory (4), with which the plurality of GNSS signals received by the GNSS antenna (2) are to be analysed.
20. Method (10) according to any claim 17 to 19, wherein the at least one machine learning model is a model comprised between: a support vector machine, a feed-forward neural network, a long- and short-term memory recurrent neural network, a KAN neural network, a Random Forest, an XGBoost, a convolutional neural network.
21. Method (10) according to any claim 17 to 20, comprising, after step C:D21. by means of the processing unit (5), based on the output signal (SOUT), counting the number of GNSS signals of the plurality of GNSS signals, subject to spoofing attack for each GNSS constellation; andD31. if the number of predicted GNSS signals, subject to spoofing attack for a GNSS constellation exceeds a predetermined threshold value, via the emitter (6), emitting an alert signal (SA) to signal the attack of the entire constellation GNSS.
22. Method (10) according to any claim 17 to 21, comprising, subsequent to step B:D22. through the processing unit (5), analysing the input signal (SIN) to verify whether one or more of the values of the plurality of parameters associated with the plurality of GNSS signals, optionally the ACG gain value, is anomalous and indicates a jamming attack, andD32. if so, through the emitter (6), emitting an alert signal (SA) to signal a possible jamming attack on the GNSS signal.
Citation Information
Patent Citations
Machine learning-based deception jamming detection method
CN116087994A
Exposure control apparatus and method for camera of vehicle
KR102717906B1
Detection of spoofing and meaconing for geolocation positioning system signals
US11500109B2
Satellite relaying for geolocation and mitigation of GNSS denial
US12025712B2
GNSS deception detection method based on machine learning
CN115932900A