ADS-B was built for openness, not security, its messages are unauthenticated, so a fabricated aircraft is technically possible. The good news: spoofed broadcasts almost always betray themselves by contradicting physics or their own metadata. Here are the signals that expose them, and how AeroScope applies every one.
ADS-B messages carry no signature and no encryption, so any transmitter could, in principle, inject a fabricated position. Documented research has shown ghost aircraft, altitude tampering and velocity tampering are all feasible. That’s why a serious platform treats every broadcast as a claim to be verified, not a fact. See the basics on ADS-B technology.
Real avionics report consistent NIC/NACp/NACv/SIL quality fields. A fabricated message often sets them wrong, or claims a precision its jittery track can’t support.
DO-260BA Kalman filter predicts where the aircraft should be next. A spoof that "teleports", accelerates impossibly or violates its performance envelope fails the normalised-innovation (NIS) test.
KALMAN NISGeometric-vs-barometric altitude, ground-speed-vs-Mach and track-vs-heading should agree on a real airframe. Contradictions between them betray a fabricated record.
RESIDUALSA real aircraft is heard by several independent receivers. A target seen by only one network, or whose multi-receiver timing doesn’t add up, deserves suspicion.
CROSS-CHECKAeroScope runs a DO-260B-style 7-check plus a Kalman normalised-innovation test and the three self-consistency residuals on every aircraft, every cycle, and fuses 60+ feeds so multi-receiver agreement is a free integrity signal. Suspect aircraft are surfaced with the contributing factors shown, see signal integrity and threat scoring. None of this uses a black-box neural network; it’s built on auditable, established methods.
Published research and observed incidents cluster into a handful of recognisable classes. Each leaves a different fingerprint, which is why several detectors are needed rather than one.
| Class | What the attacker does | How it betrays itself |
|---|---|---|
| Ghost aircraft | Injects an airframe that does not exist | No corroborating receiver geometry, integrity fields that do not match the claimed accuracy, and kinematics that are too clean or physically implausible. |
| Altitude tampering | Reports a false altitude for a real or fabricated track | The geometric and barometric altitudes stop agreeing, and the implied vertical rate conflicts with the reported one. |
| Velocity tampering | Reports speed or heading inconsistent with the track | Position deltas between messages do not integrate to the claimed velocity, and track diverges from heading beyond what wind can explain. |
| Replay | Rebroadcasts genuine historical messages | Timestamps and sequence behaviour are inconsistent, and the same identity can appear in impossible places. |
| Jamming or flooding | Degrades reception rather than faking content | Not a content problem at all. It shows up as sudden coverage loss, which is a coverage symptom rather than an integrity one. |
Any single detector tuned sensitively enough to catch real spoofing will also fire on ordinary data problems: a marginal reception, a momentary GPS degradation, an aircraft genuinely manoeuvring hard. Run one detector across hundreds of aircraft every cycle and you generate a stream of alerts nobody will read.
AeroScope therefore requires at least two independent detectors to agree before raising a flag. Because the detectors look at genuinely different things, a physics residual, an integrity field, a trajectory model and a statistical outlier score, their errors are largely uncorrelated. Two agreeing is far less likely to be coincidence than one firing alone.
The cost is honest and worth stating: consensus reduces sensitivity. A spoof that only trips one detector will not be flagged. That is a deliberate trade in favour of a signal an analyst can actually trust.
Every check below uses fields the platform already displays, so you can reach your own conclusion rather than trusting the flag.