Real-World Adversarial Attacks on RF-Based Drone Detectors

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gazit, Omer, Itzhakev, Yael, Elovici, Yuval, Shabtai, Asaf
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918314114023424
author Gazit, Omer
Itzhakev, Yael
Elovici, Yuval
Shabtai, Asaf
author_facet Gazit, Omer
Itzhakev, Yael
Elovici, Yuval
Shabtai, Asaf
contents Radio frequency (RF) based systems are increasingly used to detect drones by analyzing their RF signal patterns, converting them into spectrogram images which are processed by object detection models. Existing RF attacks against image based models alter digital features, making over-the-air (OTA) implementation difficult due to the challenge of converting digital perturbations to transmittable waveforms that may introduce synchronization errors and interference, and encounter hardware limitations. We present the first physical attack on RF image based drone detectors, optimizing class-specific universal complex baseband (I/Q) perturbation waveforms that are transmitted alongside legitimate communications. We evaluated the attack using RF recordings and OTA experiments with four types of drones. Our results show that modest, structured I/Q perturbations are compatible with standard RF chains and reliably reduce target drone detection while preserving detection of legitimate drones.
format Preprint
id arxiv_https___arxiv_org_abs_2512_20712
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Real-World Adversarial Attacks on RF-Based Drone Detectors
Gazit, Omer
Itzhakev, Yael
Elovici, Yuval
Shabtai, Asaf
Cryptography and Security
Machine Learning
Radio frequency (RF) based systems are increasingly used to detect drones by analyzing their RF signal patterns, converting them into spectrogram images which are processed by object detection models. Existing RF attacks against image based models alter digital features, making over-the-air (OTA) implementation difficult due to the challenge of converting digital perturbations to transmittable waveforms that may introduce synchronization errors and interference, and encounter hardware limitations. We present the first physical attack on RF image based drone detectors, optimizing class-specific universal complex baseband (I/Q) perturbation waveforms that are transmitted alongside legitimate communications. We evaluated the attack using RF recordings and OTA experiments with four types of drones. Our results show that modest, structured I/Q perturbations are compatible with standard RF chains and reliably reduce target drone detection while preserving detection of legitimate drones.
title Real-World Adversarial Attacks on RF-Based Drone Detectors
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2512.20712