Explorerโ€บComputer Scienceโ€บCybersecurity
Research PaperResearchia:202610.08009

Receiver-Domain Behavioral Probing for Backdoor-Resilient Federated GPS Spoofing Detection in UAV Networks

Will Jedrzejczak

Abstract

Federated learning lets a UAV fleet train a shared GPS spoofing detector without raw receiver data leaving any aircraft, and several recent UAV-FL designs weight each client by the validation accuracy it reports about itself. We show this self-report is an exploitable attack lever: two compromised clients of ten that poison part of their data, scale their updates, and inflate their reported accuracy raise backdoor lift to +0.3036, higher than the same attack achieves without lying. We propose re...

Submitted: October 8, 2026Subjects: Cybersecurity; Computer Science

Description / Details

Federated learning lets a UAV fleet train a shared GPS spoofing detector without raw receiver data leaving any aircraft, and several recent UAV-FL designs weight each client by the validation accuracy it reports about itself. We show this self-report is an exploitable attack lever: two compromised clients of ten that poison part of their data, scale their updates, and inflate their reported accuracy raise backdoor lift to +0.3036, higher than the same attack achieves without lying. We propose receiver-domain behavioral probing, in which the coordinator evaluates every submitted model on counterfactual spoofed samples built by driving each discriminative GPS feature to a benign value, weighting clients by what their models do rather than what they claim. Under independent and identically distributed clients this reduces attacker-induced lift to -0.0265, statistically indistinguishable from an honest fleet, while flagging the compromised aircraft. Unlike Byzantine-robust aggregation it needs no exact attacker count, only an honest majority: when the true count exceeds the configured value, Multi-Krum degrades from +0.0061 to +0.2837 while ours stays near baseline. Evaluation uses one public single-receiver dataset partitioned into simulated clients; we also report where the mechanism fails, under strong client heterogeneity.


Source: arXiv:2610.10360v1 - http://arxiv.org/abs/2610.10360v1 PDF: https://arxiv.org/pdf/2610.10360v1 Original Link: http://arxiv.org/abs/2610.10360v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Oct 8, 2026
Topic:
Computer Science
Area:
Cybersecurity
Comments:
0
Bookmark