High-Order Liquid Evidence Encoding for Gradual GNSS Spoofing Detection in Autonomous Driving
Muhammad Ayub Sabir, Junbiao Pang, Fatima Ashraf
Beijing University of Technology
cs.LG
Submitted: 2026-08-12
Updated: 2026-08-13
Code: https://github.com/pangjunbiao/GNSS_Spoofing
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 95/100
The gist: The paper proposes a causal high-order liquid evidence framework for detecting gradual and subtle GNSS spoofing attacks in autonomous driving.
Terminology
Summary
The paper proposes a causal high-order liquid evidence framework for detecting gradual and subtle GNSS spoofing attacks in autonomous driving. The method addresses the challenge that continuous and subtle attacks are difficult to detect because individual GNSS observations may remain plausible while the inconsistency between GNSS-implied displacement and onboard vehicle motion gradually increases. Existing methods often rely on static vehicle-behavior features or a single residual signal and do not explicitly model this evolution.
The framework first constructs a physics-guided GNSS–motion inconsistency residual by comparing GNSS-implied displacement with onboard-motion-derived displacement. It then forms separate evidence streams for the residual level and its first- and second-order discrete variations, with relevant contextual cues selected according to the evidence order. Each stream is processed by a separate adaptive liquid encoder, and the resulting temporal states are hierarchically coupled to predict spoofing at the window endpoint using only current and past observations.
Experiments on three subsets of the real-world AV-GPS dataset show that the proposed method achieves the highest F1-scores among the evaluated temporal models on Dataset 1 and Dataset 3, reaching 0.9535 and 0.9777, respectively. On Dataset 3, it detects both labeled normal-to-attack transitions within four sampling steps. Code and datasets are publicly available at: https://github.com/pangjunbiao/GNSS Spoofing.git.
The main contributions are: (1) formulating subtle GNSS spoofing detection as a causal displacement-consistency problem between GNSS and onboard motion, and deriving physics-guided residual evidence from their disagreement; (2) constructing a high-order evidence representation comprising the residual level and its first- and second-order discrete variations, with relevant contextual cues selected according to the evidence order; (3) designing separate adaptive liquid encoders to model the within-window evolution of the three evidence orders, and hierarchically coupling their hidden states for causal spoofing prediction at the window endpoint.
The residual is defined as the difference between GNSS-implied displacement and onboard-motion-implied displacement, normalized by an uncertainty matrix. The high-order evidence includes the zeroth-order residual level, the first-order step-to-step change, and the second-order change in that variation. Each order is processed by an independent liquid encoder with input-dependent time constants, and the hidden states are hierarchically coupled so that higher-order states are conditioned on lower-order context. The terminal fused representation yields the spoofing probability for the window endpoint, trained with positive-class-weighted binary cross-entropy.
On Dataset 1, the proposed method is consistently strongest across reported metrics, with simultaneous improvement in F1-score, FAR, and FNR. On Dataset 3, it provides the strongest overall balance across F1-score, FAR, accuracy, and precision, while retaining the second-lowest FNR. In the cross-location stress test on Dataset 2, all models retain high attack sensitivity with FNR below 0.002, but the proposed method shows weaker transfer of false-alarm control, with a higher FAR of 0.1260 compared to TCN's 0.0904.
Ablation studies confirm the complementary roles of high-order residual evidence and adaptive liquid encoding. Removing the second-order components yields slightly lower FNR but higher FAR and lower F1-score, accuracy, and precision. Replacing the adaptive liquid encoder with LSTM or GRU degrades every reported metric. Sensitivity analysis shows that window length L=10, hidden dimension dh=64, and minimum liquid time constant τmin=0.10 provide the best balance. Compared with the best-F1 published GPS-IDS classifier, the proposed method achieves higher F1-score, accuracy, and recall on both Dataset 1 and Dataset 3, while the GPS-IDS references retain higher precision.
Improvements for AI systems
Improvements to AI systems:
-
Causal high-order temporal evidence modeling – The system can explicitly model the evolution of a residual signal (level, first-order change, second-order change) rather than relying on static features or a single residual. This enables detection of gradual, subtle anomalies where each individual observation remains plausible but the trend diverges over time.
-
Physics-guided residual construction – By fusing domain-specific physical constraints (e.g., GNSS-implied displacement vs. onboard-motion-derived displacement) into the input representation, the AI system can detect inconsistencies that are invisible to purely data-driven models, improving robustness in safety-critical applications.
-
Adaptive liquid encoders with input-dependent time constants – The system can adjust its temporal dynamics based on the input signal’s variability, allowing it to respond faster to abrupt changes while maintaining sensitivity to slow drifts. This improves detection latency and reduces false alarms in non-stationary environments.
-
Hierarchical coupling of evidence orders – The system conditions higher-order temporal states (e.g., acceleration of the residual) on lower-order context (e.g., residual level), enabling it to capture multi-scale dynamics and distinguish between benign noise and malicious gradual manipulation.
-
Positive-class-weighted training for rare-event detection – The system can be trained to prioritize recall of rare attack events without sacrificing overall precision, making it suitable for real-world deployment where attacks are infrequent but high-impact.
What the improved AI system can do:
-
Detect gradual and subtle GNSS spoofing attacks in autonomous driving in real time, using only current and past observations (causal, no future leakage), with F1-scores above 0.95 on real-world datasets.
-
Detect normal-to-attack transitions within 4 sampling steps (e.g., sub-second response) while maintaining low false alarm rates.
-
Transfer to new locations with high attack sensitivity (FNR < 0.002) and provide tunable false-alarm control for deployment-specific risk tolerance.
-
Provide interpretable evidence streams (residual level, change, and acceleration) that can be visualized or audited for explainability in safety reviews.
-
Serve as a general framework for detecting other types of gradual sensor spoofing or drift (e.g., IMU, radar, lidar) by replacing the physics-guided residual with domain-specific consistency checks.
Sources
- GPS-IDS: An Anomaly-based GPS Spoofing Attack Detection Framework for Autonomous Vehicles
- Prediction-Based GNSS Spoofing Attack Detection for Autonomous Vehicles
- Anomaly Transformer: Time Series Anomaly Detection with Association Discrepancy
- TranAD: Deep Transformer Networks for Anomaly Detection in Multivariate Time Series Data
- TimesNet: Temporal 2D-Variation Modeling for General Time Series Analysis
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks