Rigid-Covert UAV GNSS Spoofing
Abstract
Cooperative UAV-swarm defenses commonly cross-check GNSS positions against measured inter-drone geometry. We show that this relative-geometry channel has a structural blind spot: a common, slowly varying translation (a rigid-covert shift, RigidShift) preserves all pairwise distances and is therefore unobservable to any relative-only detector (a gauge-freedom argument). We validate this blindness on distance-verification and semidefinite-feasibility baselines, while explicitly distinguishing it from onboard inertial/GNSS monitors that can raise a bare alarm but cannot recover the swarms true position. To quantify when an external reference restores observability, we derive the drift-dependent detection floor 2 __ /(1 __ / __ ) for a calibrated anchor-residual detector and empirically identify an additional detector-specific noise floor (measured slope 2 _._ 66 vs. predicted 2 _._ 67). We then present a centralized anchor-rooted recovery pipeline that reconstructs swarm geometry from inter-drone ranges, aligns it to a trusted-anchor subset with Byzantine-robust fitting, and recovers the absolute positions of non-anchored drones. A segmented estimator jointly estimates anchor drift, attack rate, and onset when no clean-epoch label is available. Across statistical simulations, ArduPilot software-in-the-loop experiments, and Gazebo experiments with rendered vision anchors, the method recovers the positions of non-anchored drones to a median error of 0 _._ 39 m (20 seeds) under approximately 10 _._ 1 m of GNSS drift, and to 7 _._ 1 cm (5 seeds) in the rendered-vision multi-SITL setting. We also characterize the explicit limits imposed by noncollinear anchor geometry, anchor coverage, __ 0 driftattack aliasing, and majority anchor compromise. All evaluations are simulation-based and use no RF spoofing hardware or physical swarm.