TY - JOUR
T1 - Cybersecurity in Cyber-Physical Systems
T2 - Wireless Jamming Attack Detection in Noisy LoRaWAN Environment
AU - Su, Xiaoyi
AU - Wang, Chao
AU - Zhou, Zhixin
AU - Luo, Rui
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s). Publication rights licensed to ACM.
PY - 2026/4/22
Y1 - 2026/4/22
N2 - Cybersecurity in safety-critical data communication infrastructures presents a significant and open challenge for cyber-physical systems (CPS). While extensive research exists on wireless jamming, effectively detecting attacks in noisy wireless environments remains difficult. This article introduces a novel framework for detecting mobile jamming attacks in LoRaWAN-based CPS, designed to operate robustly in the presence of communication faults. Unlike traditional methods that rely on physical-layer metrics like RSSI from end devices, our strategy uses only data upload statistics available at the backend network server. We propose a multi-stage filtering approach that first identifies anomalous upload failures and then distinguishes jamming attacks from communication faults by analyzing their distinct spatio-temporal signatures. Furthermore, the framework can reconstruct the attacker’s trajectory from the identified attack events. We evaluate the proposed strategy via extensive discrete-time simulations under various network densities and attacker speeds. Results demonstrate high efficacy, achieving an F1-score of up to 1.00 for event detection and a trajectory reconstruction mean absolute error (MAE) as low as 7.07 meters in dense networks, even in the presence of faults. This work’s primary contribution is a backend-centric, fault-tolerant detection methodology that enhances situational awareness without imposing additional overhead on resource-constrained end devices.
AB - Cybersecurity in safety-critical data communication infrastructures presents a significant and open challenge for cyber-physical systems (CPS). While extensive research exists on wireless jamming, effectively detecting attacks in noisy wireless environments remains difficult. This article introduces a novel framework for detecting mobile jamming attacks in LoRaWAN-based CPS, designed to operate robustly in the presence of communication faults. Unlike traditional methods that rely on physical-layer metrics like RSSI from end devices, our strategy uses only data upload statistics available at the backend network server. We propose a multi-stage filtering approach that first identifies anomalous upload failures and then distinguishes jamming attacks from communication faults by analyzing their distinct spatio-temporal signatures. Furthermore, the framework can reconstruct the attacker’s trajectory from the identified attack events. We evaluate the proposed strategy via extensive discrete-time simulations under various network densities and attacker speeds. Results demonstrate high efficacy, achieving an F1-score of up to 1.00 for event detection and a trajectory reconstruction mean absolute error (MAE) as low as 7.07 meters in dense networks, even in the presence of faults. This work’s primary contribution is a backend-centric, fault-tolerant detection methodology that enhances situational awareness without imposing additional overhead on resource-constrained end devices.
KW - communication faults
KW - fault detection
KW - frequency change detection
KW - Jamming attack detection
KW - sensor localization
UR - https://www.scopus.com/pages/publications/105038217642
UR - https://www.scopus.com/pages/publications/105038217642#tab=citedBy
U2 - 10.1145/3777454
DO - 10.1145/3777454
M3 - Article
AN - SCOPUS:105038217642
SN - 2378-962X
VL - 10
JO - ACM Transactions on Cyber-Physical Systems
JF - ACM Transactions on Cyber-Physical Systems
IS - 2
M1 - 18
ER -