MULTILAYER ANALYSIS OF VULNERABILITY OF CYBERPHYSICAL SYSTEMS USING THE EXAMPLE OF UNMANNED AIRCRAFT

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.028613

Abstract

The article examines the complex nature of vulnerabilities of modern unmanned aerial vehicles (UAVs) as a class
of cyber-physical systems (CFS). The authors theoretically substantiated and detailed the concept of a "security
vacuum" – the systemic insecurity of the drone architecture, which arises as a result of the rapid integration of computing
algorithms and physical processes while ignoring the basic security criteria. Within the Control-Theoretic Approach, a
layer-by-layer decomposition analysis of three critical levels of UAV architecture: navigation, network, and information
were carried out. It is mathematically and empirically proven that the openness of civil GNSS signals in combination with
the hardware architecture with one antenna (Single-Receiver) makes KFS defenseless against hidden attacks of false data
injection (False Data Injection). Mechanisms of control channel compromise due to MAVLink protocol vulnerabilities
using Replay Attacks were investigated. Special attention is paid to the information level, where the possibility of
deanonymization of the strategy of using the system through the analysis of the encrypted traffic profile (Side-Channel
Attacks) is demonstrated. Based on the analysis of the world's leading researches, the law of the multiplicity of risks of
the CFS was formulated and systemic recommendations for the transition to the Security by Design paradigm were
proposed.
Keywords: cyber-physical systems (CFS), unmanned aerial vehicles (UAVs), security vacuum, GPS spoofing,
jamming, MAVLink protocol, replay attack, false data injection (FDI), third-party channel analysis, multiplicity of risks,
Security by Design.

References
1.Teixeira, A., Shames, I., Sandberg, H., & Johansson, K. H. (2015). A secure control framework for cyberphysical systems. Foundations and Trends in Systems and Control, 2(3-4), 243–410. https://doi.org/10.1561/2600000008.
2.. Wesson, T. Humphreys, Hacking drones. Sci. Am. 309(5), 54–59 (2013).
3.N. Tippenhauer, C. Pöpper, K. Rasmussen, On the Requirements for Successful GPS Spoofing Attacks (n.d.).
Retrieved March 27, 2023, from https://www.cs.ox.ac.uk/files/6489/gps.pdf.
4.Sulima O. Model of multilevel access system // Ukrainian Scientific Journal of Information Security, 2017, vol.
23, issue 2, p. 122-129. DOI: 10.18372/2225-5036.23.11817.

Published

2026-06-25

Issue

Section

Articles