Method and system for detecting and mitigating an interference attack
The system addresses inefficiencies in jamming attack detection and mitigation in V2X networks by using power-related parameters and tailored mitigation strategies, enhancing network resilience and safety in autonomous vehicles.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HOCHSCHULE HAMM LIPPSTADT
- Filing Date
- 2025-10-24
- Publication Date
- 2026-05-07
AI Technical Summary
Existing methods for detecting and mitigating jamming attacks in wireless V2X communication networks are inefficient, particularly in handling advanced jamming techniques that target specific communication signals and are not effectively addressed by existing detection and remediation measures.
A system and method that utilizes power-related parameters to detect, classify, and mitigate radio interference by passively monitoring performance indicators, employing sequential probability ratio tests, and implementing tailored mitigation measures based on jammer characteristics and user capabilities, using hardware and network resources as needed.
Effectively identifies and counters jamming attacks by distinguishing genuine interference from false positives, optimizing resource use, and enhancing network resilience against advanced jamming techniques, improving safety and energy efficiency in autonomous vehicles.
Smart Images

Figure EP2025080756_07052026_PF_FP_ABST
Abstract
Description
[0001] Method and system for detecting and mitigating a jamming attack
[0002] The invention relates to a method for detecting and mitigating a jamming attack by a jammer in a wireless V2X communication network.
[0003] Furthermore, the invention relates to a system for detecting and mitigating a jamming attack by a jammer in a wireless communication network and to an autonomous vehicle.
[0004] The invention relates in particular to the detection, classification and mitigation of radio interference in Everything-to-Everything (X2X) communication systems, with a focus on mobility applications.
[0005] X2X communication describes the exchange of data between heterogeneous devices for sharing information, processing, transmitting, and redirecting packets. The specific class of X2X communication used in mobility applications is called Vehicle-to-Everything (V2X). Within the V2X framework, vehicles can communicate with other devices (V2D) such as handheld devices, other vehicles (V2V), smart grids (V2G), buildings (V2B), infrastructure (V2I), pedestrians (V2P), networks (V2N), and the cloud (V2C). This data exchange enables sensor fusion, collective perception, collision warnings, coordinated driving (e.g., platooning), advance warning of emergency vehicles and roadworks, infotainment, and business functions.
[0006] X2X communication can be drastically impaired by the presence of radio interference and other forms of electromagnetic interference (EMI). Therefore, the proposal of countermeasures against radio interference is of crucial importance.
[0007] Examples of V2X protocols include dedicated short-range communication (DSRC), whose standards are specified in IEEE 802.11p, and mobile networks such as 4G, 5G, and 6G.
[0008] A malicious actor can disrupt communication channels through deliberate EMI, thereby preventing data exchange between network participants. Such deliberate EMI can be generated cost-effectively and efficiently using a radio jammer. In some cases, the jamming can prevent the network from being established at all. A jammer can even be deployed on pedestrians, infrastructure, and vehicles, including aircraft such as drones, to further complicate the location of the source of the deliberate EMI or even to target a specific vehicle.
[0009] While traditional jammers simply emit a constant, high-power noise, modern jammers can employ advanced techniques to be more discreet and efficient. One simple technique a radio jammer can use to be less noticeable and save energy is to transmit either randomly or at regular intervals. A more advanced variant can transmit reactively, meaning it only transmits when it detects a signal of interest.
[0010] Radio jammers can also carry out more sophisticated attacks instead of simply transmitting high-power noise. Attacks can target specific parts of communication signals, such as... B. Preamble, pilot signals used in channel estimation, cyclic prefix, MAC packets such as Clear-to-Send (CTS) and Acknowledgement (ACK) packets, etc. (K. Grover, A. Lim, and Q. Yang, “Jamming and anti-jamming techniques in wireless networks: a survey,” International Journal of Ad Hoc and Ubiquitous Computing, vol. 17, no. 4, p. 197, 2014; and H. Pirayesh and H. Zeng, “Jamming Attacks and Anti-Jamming Strategies in Wireless Networks: A Comprehensive Survey,” IEEE Communications Surveys and Tutorials, vol. 24, no. 2, pp. 767–809, 2022.)
[0011] Since orthogonal frequency division multiplexing (OFDM) communication systems use pilot and training signals in the preamble for synchronization and equalization, the preamble portion of the communication frame (or subcarrier) itself can be disrupted.
[0012] An advanced radio jammer can also target pilot signals or the cyclic prefix. An advanced jammer can also intercept a receive-to-send (RTS) packet and wait for a short interframe space (SIFS) time slot to attack the incoming CTS packet, thus disrupting communication. Similarly, it can also attack ACK packets and cause the sender to retransmit data packets until the transport protocol limit is reached. US Patent 11,233,597 B2 discloses a simplified selection procedure for detecting radio jamming based on comparing two or more signal measurements. While simple, it only addresses attacks on the physical layer (PHY) and not on the medium access control (MAC) or other layers. It does not describe remediation measures or classify the attack, as the two measurements serve only to determine whether an attack is present.
[0013] US Patent 10,263,726 B2 discloses a system for detecting a radio jammer disrupting a communications network. Once it detects a jammer, it transmits a jamming message over the network, alerting other users to the intended interference. Detection is primarily based on continuously checking whether the radio channel is decodable, measuring the signal level, and, if the (lack of) decodability exceeds a threshold, checking whether the measurements have found an energy pattern. If no pattern is found, a jamming message is transmitted, as this indicates that the EMI originates from a malicious transmitter continuously feeding random noise into the medium—i.e., a jammer.
[0014] US Patent 2020 / 0153535 A1 discloses a system for detecting jamming attacks, using a reinforced learning approach to identify a jammer on the network. A cognitive radio approach is used for mitigation. This is a very general approach. Mitigation is of limited use in DSRC because there are only seven 10 MHz channels spanning 70 MHz, three of which—critical safety, control, and public safety—are constantly in use, leaving only four service channels available. A frequency monitoring attack, for example, can overload all channels simultaneously. US Patent 2015 / 0156215 A1 discloses a discrete-time mathematical model, based on the “Mafia game,” for detecting vehicles on a V2V network transmitting malicious messages and removing them from the network by having other network participants ignore them for a specified period.While this is effective in removing potential malicious actors, it has a limit to the number of malicious vehicles it can tolerate, does not account for the possibility of a false positive result, and may temporarily exclude an innocent participant.
[0015] However, the known state of the art has disadvantages that are overcome by the invention.
[0016] The object of the present invention is to provide a system and a method for detecting and mitigating a jamming attack by a jammer, as well as an autonomous vehicle, so that such a jamming attack can be dealt with more effectively.
[0017] To solve this problem, the invention has the features of claims 1, 8 and 14.
[0018] The particular advantage of the invention lies in the fact that the detection of interference attacks can be significantly simplified by processing power-related parameters of a received signal. By classifying the received signal as either a genuine or a spurious interference signal, only truly genuine interference signals can be effectively processed. After further classification of the genuine interference signal, a mitigation measure tailored to the detected interference signal can be implemented, thus attenuating the effect of the interference signal. To minimize radio interference in X2X communication networks, the invention specifically provides for the detection, classification, and mitigation of radio interference.
[0019] The present invention enables a balanced approach to interference mitigation by recruiting hardware and network resources as needed. The invention fulfills three main tasks: detection, classification, and mitigation of a radio interference source.
[0020] To detect radio interference, the invention passively monitors the environment using readily available performance indicators, including but not limited to the packet transmission ratio (PDR), the packet loss ratio (PLR), and the bit error rate (BER), to determine whether an upgrade is warranted by requiring a simple minimum threshold.
[0021] To classify radio interference, active parameters such as signal-to-noise ratio (SNR), signal-to-noise ratio (SINR), direction of arrival (DoA), total DoA delay (TDoA), power delay profile (PDP), channel impulse response (CIR), mean squared delay (RMS-DS), absolute and relative transmit power, and transmission energy pattern for line-of-sight (LOS) and non-line-of-sight (NLOS) components are preferably estimated. The energy pattern is important because unstructured signals are immediately considered likely sources of interference, while structured signals are initially classified as potentially malicious. In either case, a sequential probability ratio test (SPRT) can be used to balance the hypotheses of whether a jammer is present or if the result is a false positive.Once a jammer has been positively detected, a jamming alert is sent to the network. The parameters estimated in this phase, such as SINR, DoA, TDoA, and PDP, are also forwarded to the next phase for use in classifying radio jammers.
[0022] To mitigate radio interference caused by a reactive jammer, the jammer can be stimulated by transmitted signals to which it is likely to respond. This can help obtain more samples from the jammer, which are used for parameter estimation. These are used to classify the jammer's operating state and select appropriate remedial measures.
[0023] Mitigation, following further training, is achieved in simple cases by selecting a method that matches the characteristics of the jammer and the user's capabilities. For example, an attack on a single frequency against a user with a MIMO (Multiple-in-Multiple-out) array can be mitigated by spatially filtering out the jammer within their DoA (Dead On-Air), allowing the frequency to continue to be used, albeit with a reduced DoA range. A receiver with only one antenna might have to mitigate the same attack by switching channels. In another example, a frequency surveillance attack targeting DSRC (Dedicated Short-Range Communication) against a user who also uses cellular communications can be mitigated by redirecting the attack to cellular communications. An artificial intelligence (AI) algorithm can be used to select the appropriate mitigation method based on the attack characteristics and the user's capabilities.Mitigation measures with overlapping application scenarios can be differentiated by defining penalty functions for each method. These penalty functions can be based on cost factors such as computational effort, bandwidth, latency, and power consumption. Hardware operating in higher frequency ranges, such as millimeter-wave (mmWave), can utilize frequencies where jamming is ineffective due to strong fading effects. Moving to even higher operating bands, such as terahertz (THz) communication, jamming radio signals becomes virtually impossible. Estimating the jammer's location enables the use of multi-hop or device-to-device (D2D) routing, which simultaneously attenuates intentional EMI.
[0024] Vehicles equipped with mobile sensors, such as small drones, can significantly expand the vehicle's field of vision, enabling a more comprehensive and accurate perception of its surroundings. This capability is advantageous in challenging scenarios, such as driving on foggy roads, in environments under the influence of cyberattacks, or during complex maneuvers like parking. The present invention introduces this concept as a solution for next-generation autonomous vehicles, designed not only to ensure road safety but also to improve energy efficiency and traffic flow. The integrated drones enable the vehicle to overcome limitations in vision and perception, making it more resilient to adverse conditions and potential cyber threats.Furthermore, the use of mobile sensors contributes to more efficient and safer navigation, optimizes the use of energy resources, and reduces the risk of accidents, while facilitating adaptation to different driving scenarios. Such vehicle-launched drones, equipped with reconfigurable intelligent surfaces (RIS), can also be used as relays and for cooperative MIMO to mitigate jamming attacks.
[0025] Exemplary embodiments of the invention are explained in more detail with reference to the drawings.
[0026] Figure 1 shows a schematic representation of communication between mobile devices designed as vehicles, whereby a jamming signal is generated by means of a drone.
[0027] Fig. 2 shows a flowchart of a method according to the invention for detecting and mitigating the jamming attack,
[0028] Fig. 3 shows a flowchart of the jamming attack detection process as depicted in Figure 2.
[0029] Fig. 4 shows a flowchart of a hypothesis test as depicted in Figure 2,
[0030] Fig. 5 shows a flowchart of a preferably KL-based mitigation of the interference signal and
[0031] Fig. 6 shows an embodiment with a vehicle that is alternatively or additionally equipped with mobile sensors.
[0032] Without loss of general applicability, this section describes the preferred embodiment using a specific scenario. Although this is a scenario in which its use would be advantageous, it is not limited to other possible embodiments of the same invention. Therefore, variations of the present invention can easily be achieved by omitting a portion of the functional blocks.
[0033] Figure 1 illustrates a typical operating configuration of the present invention, which is not limited to a specific scenario and can be adapted as needed. Furthermore, the described methods can be used together or independently, as shown by way of example. In the depicted scenario, three vehicles 1, 3, and 5 are involved as mobile units, with vehicle 3 experiencing an anomaly in its transmission system that results in an unusually high-power signal. A jamming drone 7 is also present, and its operating area 8 is defined. It is worth noting that the vehicles can be replaced by devices in an Industry 6.0 environment or a smart city, thus expanding the scope of the invention.
[0034] In the present example, vehicles 1, 3, and 6 are in the passive phase (see Figure 2). At a specific time t, vehicle 3 transmits a signal to vehicle 1 via the wireless communication link 2. Vehicle 1 receives the signal with an antenna array, which then processes the received signal using detection means according to step 10 in Figure 2. As shown in more detail in Figure 3, which illustrates the processing according to step 10 in Figure 2, parameters of the received signal are selected according to step 18 and analyzed according to step 19. These parameters are power-related, and a disturbance signal is detected if they deviate from predefined power parameters.If an anomalous power of the received signal is detected according to step 20, vehicle 1 enters the "Active" phase according to step 11. If no anomalous power is detected, vehicle 1 remains in the original "Passive" phase according to step 9 in Figure 2.
[0035] If vehicle 1 is in the "Active" phase according to step 11, a hypothesis test is performed in a further step 13, which takes into account the parameter estimates according to step 12, including SNR, SINR, DoA, TDoA, PDP, CIR, RMS-DS, transmit power, and signal pattern. An energy pattern 21 is determined based on the estimated parameters. A KL-based classifier 22 can be used to determine whether the received signal should be considered in a reasonable probability sequence test (SPRT) according to step 23. These classification tools classify the interfering signal according to whether the interfering signal is a true ii.
[0036] The system identifies the interference signal as either a genuine or a false positive signal. After the appropriate probability sequence test (SPRT), the interference signal is either recognized as a genuine or false positive signal. If a false positive signal is detected, vehicle 1 reverts to the "Passive" phase according to step 9. If the interference signal is recognized as a genuine interference signal, vehicle 1 is switched to the "Reactive" state according to step 14, so that, depending on a classification according to step 15, a countermeasure or mitigation of the interference attack is subsequently implemented according to step 1.
[0037] At time t+1, the same process of detection and defusing is carried out in the communication between vehicles 5 and 3, see Figure 1.
[0038] At time t+2, assume that the jammer 7 transmits a signal to the vehicle 5 via the wireless communication link 6. The vehicle 5 receives the signal with its antenna array, which it then processes according to step 9. The parameters of the received signal are selected according to step 18 and analyzed according to step 19, see Figure 3. If an anomaly is detected in the received signal, the vehicle 5 enters the "Active" phase according to step 11. Subsequently, the hypothesis test is performed according to step 13, taking into account the estimated parameters 12, including SNR, SINR, DoA, TDoA, PDP, CIR, RMS-DS, transmit power, and signal pattern.
[0039] Based on the estimated parameters 12, the energy pattern 21 is determined, and a Kl-based classifier is used to determine whether the jamming signal should be considered a genuine jamming signal in a reasonable probability sequence test (SPRT). If it is determined to be a non-genuine jamming signal, the vehicle 5 is returned to the "passive" state 9. If a jamming attack has been detected by identifying the genuine jamming signal, the vehicle 5 enters the reactivity phase according to step 14.
[0040] In step 15, the jamming attack is classified based on the estimated, preferably performance-related parameters, and then a countermeasure is implemented in step 16 to mitigate the effect of the jamming attack.
[0041] The mitigation measure is selected based on parameters shown in the following table, preferably using a classification algorithm such as a decision tree. The actual jamming attack is classified according to the presence of different radio jamming attacks, which are listed as examples in the following table. If the checked parameter is, for example, "Parameter 4" according to step 29 in Figure 5, then "Mitigation D" according to step 32 is applied as the mitigation measure. Figure 5 shows a plurality of parameters 1 according to step 25, parameter 2 according to step 27, parameter 3 according to step 28, and parameter 4 according to step 29, where the parameters are the previously mentioned parameters SNR, SINR, DoA, TDoA, PDP, CIR, RMS-DS, transmit power, and signal pattern.Based on the available parameters, the appropriate mitigation measure A according to step 26, B according to step 30, C according to step 31, D according to step 32 and mitigation measure E according to step 33 is taken.
[0042] The mitigation measures A, B, C, D, E result from the reservoir of mitigation or mitigation measures shown in the following table, which are implemented depending on the identified classified disruptive attack.
[0043]
[0044] If the power output of the vehicle in question exceeds a predefined threshold, as determined in step 17, the power is reduced, allowing the vehicle to return to the active phase as described in step 1. This decision can be based on power tests or previously defined values. The system then returns to the active phase and repeats the detection, classification, and mitigation (implementation of countermeasures) process until the jamming attack is complete or the system is outside the range of jammer 7. If the vehicle's power output remains below the predefined threshold, the mitigation or implementation of countermeasures continues as described in step 16.
[0045] Figure 6 shows a vehicle 100 equipped with mobile sensors 102 and 103, which make a significant contribution to the next generation of vehicles. These mobile sensors 102, 103, such as drones, are attached to the vehicle 100 when not in use, for example, in the front and / or rear sections of the vehicle 100. There, they are detachably connected to the vehicle's body. When the mobile sensors 102, 103 are in use, they are removed from the vehicle 100 by their own propulsion system and moved to a position 104, where they can acquire enhanced sensor data about other road users compared to a fixed physical arrangement on the vehicle 100. This data can then be analyzed.
[0046] Alternatively or additionally, the mobile sensors 102, 103 can be operated while physically connected to the vehicle 100. They offer, for example, the flexibility of being able to operate in both fixed and mobile modes.
[0047] For example, the drone 102 / 103 shown in Figure 6 can remain attached to the vehicle 100 and function as a stationary sensor 102 / 103, even when not in flight. In this stationary mode, the drone 102 / 103 becomes an extension of the vehicle 100's sensor systems. With its integrated cameras, inertial measurement unit (IMU), and processor, it provides real-time data. This data can be transmitted to the vehicle 100's central system via a wired or wireless interface, enabling the vehicle 100 to use this information to enhance its environmental perception and decision-making capabilities.
[0048] The major advantage of this approach lies in the versatility and the expansion of the vehicle 100's field of vision and perception, particularly in challenging situations such as poor visibility, complex maneuvers, or navigation in densely populated urban areas. The integration of at least one mobile sensor 102,103, which can operate both coupled and autonomously, provides the vehicle 100 with an additional layer of safety and efficiency. It is able to anticipate obstacles, assess the environment in real time, and make decisions based on more comprehensive data.
[0049] Furthermore, this configuration allows the vehicle 100 to flexibly adapt its sensor strategy to the specific requirements. The drones 102 and 103 can be used to temporarily extend perception in critical situations, or they can remain in fixed mode for continuous monitoring. This not only improves the safety and energy efficiency of the vehicle 100 but also opens up new possibilities for using advanced functions, such as predictive maintenance, infrastructure monitoring, and emergency response. For example, the vehicle 100, as shown in Figure 6, can deploy its drones 102 and 103 to disable or track the spoofer drone.
[0050] Additionally, such drones 102 and 103, equipped with reconfigurable intelligent surfaces (RIS), can be used as relays and for cooperative MIMO to mitigate jamming attacks. This provides the vehicle 100 with an additional layer of protection against cyber threats and jamming attacks, as the drones 102 and 103 not only improve sensory and perception capabilities but also actively contribute to the defense and stabilization of the communication systems.
Claims
Patent claims 1. Method for detecting and mitigating a jamming attack (6) by a jammer (7) in a wireless V2X communication network (2, 4) in which several mobile devices communicate with each other, comprising: - Analyzing received signals (6) with respect to power-related parameters, wherein a disturbance signal is detected if there is a deviation from specified power parameters, - Classifying the disturbance signal according to whether the disturbance signal is a true disturbance signal or a false disturbance signal, wherein an energy pattern (21) of the disturbance signal is determined on the basis of the estimated parameters and wherein a Kl-based discriminator (22) is used, such that after a test with an appropriate probability sequence (23) either the disturbance signal is detected as a true disturbance signal or the disturbance signal is detected as a false disturbance signal, - Classifying the actual jamming signal into different radio jamming attacks, so that depending on the type of jamming attack identified, a mitigation measure (A, B, C, D, E) of the actual jamming signal is carried out in such a way that the effect of the jamming transmitter (7) is weakened.
2. Method according to claim 1, characterized in that the defusing measure (A, B, C, D, E) is maintained by a mobile device (1, 3, 5) until a transmission power of the mobile device (1, 3, 5) exceeds a predetermined threshold, wherein, upon exceeding the threshold, the defusing measure is terminated and the classification of the interference signal is restarted, and wherein, in the presence of a The defusing measure will continue even if the transmission power is below the threshold.
3. Method according to claim 1 or 2, characterized in that the energy pattern (21) is determined to distinguish the structured signal from the unstructured signal, wherein the unstructured noise signal is subjected to the test with an appropriate probability sequence (23) as a likely genuine noise signal, and wherein the structured noise signal is first subjected to the Kl-based discriminator (22) as an improbable genuine signal to determine whether the structured noise signal is then subjected to the test with an appropriate probability sequence (23) or not.
4. Method according to one of claims 1 to 3, characterized in that the mitigation measure (A, B, C, D, E) is formed by sending a stimulation signal, so that a jammer of the jamming attack is stimulated to generate further jamming signals which are analyzed and classified as received signals.
5. Method according to one of claims 1 to 4, characterized in that the further interference signals serve as samples for further parameter estimation in the analysis of the received signal.
6. Method according to one of claims 1 to 5, characterized in that the steps of analyzing, classifying and defusing in a mobile device are repeated during each communication with another mobile device.
7. Method according to any one of claims 1 to 6, characterized in that the communication between the mobile devices (1, 3, 5) does not use infrastructure network connectivity.
8. System for detecting and mitigating a jamming attack (7) in a wireless communication network containing a plurality of mobile devices (1, 3, 5) that exchange data with each other, comprising: - Detection means for identifying interference attacks based on power-related parameters of a received signal, wherein an interference signal is detected if the power-related parameters of the received signal deviate from specified power parameters, - Classification means for classifying the interference signal according to whether the interference signal is a true interference signal or a false interference signal, whereby an energy pattern (21) of the interference signal is determined on the basis of the estimated parameters, - Classification means for classifying the true interference signal according to different radio jamming attacks, so that depending on the type of jamming attack identified, a mitigation measure (A, B, C, D, E) of the true interference signal is carried out in such a way that the effect of the jammer is attenuated.
9. System according to claim 8, characterized in that the mitigation measure (A, B, C, D, E) can be selected from a reservoir of different types of mitigation measures depending on characteristics of the jamming attack and / or parameters of the jamming signal.
10. System according to claim 8 or 9, characterized in that, as a mitigation measure (A, B, C, D, E) in response to a jamming attack targeting a single frequency of the mobile device, a MIMO array is provided which is mitigated by spatially filtering out the jamming in its DoA.
11. System according to one of claims 8 to 10, characterized in that, as a mitigation measure (A, B, C, D, E) in a mobile device with a single antenna as a receiving device, a channel change of the communication link with another mobile device is provided.
12. System according to one of claims 8 to 11, characterized in that, as a mitigation measure (A, B, C, D, E) to a frequency monitoring attack, a communication band change to mobile communication with the other mobile device is provided.
13. System according to one of claims 8 to 12, characterized in that a computer-based algorithm is provided for selecting the defusing measure (A, B, C, D, E).
14. Autonomous vehicle (100) equipped with at least one mobile sensor (102, 103), in particular a drone, which has propulsion means so that it can be operated remotely from the vehicle (100), wherein this mobile sensor (102, 103) is equipped with an integrated camera, an inertial measurement unit (IMU) and a processor which provides real-time data which is transmitted to the central vehicle system of the vehicle (100) via a wired or wireless interface.
Citation Information
Patent Citations
Method of detecting a jamming transmitter affecting a communication user equipment
US10263726B2
Selective jamming detection based on comparing two or more signal measurement quantities
US11233597B2
System and method for detecting and evicting malicious vehicles in a vehicle communications network
US20150156215A1
Reinforcement learning based cognitive Anti-jamming communications system and method
US20200153535A1