The ADS-B Ghost Flight Problem, the Unauthenticated Broadcast Protocol Anyone Can Spoof, and the Security Vulnerability Built Into Every Traffic Display Flying Today

ADS-B's unauthenticated broadcast protocol allows anyone with accessible hardware to inject false traffic into cockpit displays - a known vulnerability with no near-term regulatory fix.

Aviation Technology Analyst

Every ADS-B message your traffic display receives is unauthenticated. There is no digital signature, no certificate chain, and nothing in the protocol that proves a broadcast came from the aircraft whose identifier it carries. This design decision, made in the 1990s for legitimate technical reasons, has created a security gap that researchers have documented for over fifteen years - and that the aviation industry has not yet resolved.

How ADS-B Works and Why the Architecture Matters

ADS-B stands for Automatic Dependent Surveillance Broadcast. “Automatic” because the aircraft broadcasts without ground interrogation. “Dependent” because position data comes from the aircraft’s own GPS rather than an independent radar measurement. “Broadcast” because the signal goes to any receiver capable of picking it up.

An ADS-B Out transponder continuously transmits GPS position, altitude, groundspeed, vertical rate, heading, and transponder identification. The FAA’s ground network - roughly 800 stations covering the continental United States, Alaska, and the Gulf of Mexico - relays those broadcasts to ATC facilities. Aircraft equipped with ADS-B In receive the same signals directly, displaying traffic on electronic flight bags, panel MFDs, or dedicated traffic units. The system also carries FIS-B, the uplinked weather service that delivers free NEXRAD imagery, METARs, TAFs, PIREPs, and NOTAMs to the cockpit.

Two formats carry this traffic. The 1090 MHz Extended Squitter (1090ES) format serves commercial aviation and high-performance GA. The Universal Access Transceiver (UAT) format at 978 MHz is the lower-cost option favored by most general aviation below 18,000 feet. Both share the same fundamental security architecture: unauthenticated open broadcast.

Why ADS-B Was Built Without Authentication

The ADS-B protocol was designed beginning in the late 1980s and finalized into International Civil Aviation Organization standards through the 1990s and early 2000s. The engineering team’s priority was correct for that era: get accurate position data out of the aircraft to any receiver with minimum latency and maximum reliability. Messages had to be compact. Processing had to be near-instantaneous. The transponder hardware of that generation ran on microcontrollers with kilobytes of working memory.

Adding cryptographic authentication to a real-time aviation message stream was not a practical option at the hardware cost and processing constraints of the time. The threat model was signal interference and multipath fading - not a human actor deliberately injecting false data.

The result is that the full technical specification for the 1090ES format is a published international standard, available publicly, describing the complete message structure: the aircraft address field, the position encoding, the velocity encoding - all of it.

How the Spoofing Attack Actually Works

Software-defined radio (SDR) uses general-purpose computing hardware to perform signal processing in software rather than fixed circuits. The most common hobbyist SDR hardware costs between $20 and $35. Open-source software to receive and decode ADS-B signals from these devices has existed since at least 2012 - it is the technical foundation of the distributed receiver networks behind FlightAware and Flightradar24, which together operate hundreds of thousands of volunteer ground stations worldwide.

Transmit-capable SDR hardware, which costs somewhat more but remains broadly accessible, can inject false ADS-B messages. The attack requires defining false aircraft parameters in software - an ICAO 24-bit address, a position, an altitude, a velocity, a heading, and a broadcast rate - then transmitting. Every ADS-B receiver within range displays that aircraft as real traffic.

This has been demonstrated in controlled research environments by multiple institutions. Researchers at NC State University published detailed demonstrations. A team at the Georgia Institute of Technology analyzed the threat model in depth. MITRE Corporation, which conducts extensive technical work for the FAA and federal clients, has published analysis of ADS-B protocol vulnerabilities.

Two Distinct Attack Types - and Why They Differ

These are different attacks with different signatures, and the defenses are not the same.

Injection creates aircraft that do not exist. A receiver displays a target with no physical aircraft behind it. The key detection opportunity: TCAS works by actively interrogating Mode C and Mode S transponders and waiting for a reply. A ghost aircraft has no real transponder and cannot respond. A target appearing on ADS-B In with no corresponding TCAS detection is a meaningful discrepancy - but only if the pilot is actively cross-referencing both systems in real time.

GPS spoofing is the attack with the larger documented real-world footprint. A false satellite signal overwhelms authentic GPS signals at the receiver. The GPS locks onto the false signal and reports an incorrect position with full confidence. The ADS-B Out transponder, drawing its position from that GPS receiver, then broadcasts the false position entirely correctly. The aircraft is functioning exactly as designed. The deception occurred one layer below ADS-B.

When GPS spoofing affects an entire region, multiple aircraft simultaneously broadcast incorrect positions. Traffic displays across the affected area become unreliable. The relative geometry between aircraft becomes meaningless. Terrain warning systems, which calculate clearance margins against an onboard database using GPS position, can generate alerts that are false or misleading.

The Documented Incidents

This is not a theoretical attack surface. The aviation safety community has documented GPS spoofing incidents in specific geographic regions at scale.

The Black Sea area produced incident reports beginning around 2018. Airspace near Iran and across parts of the eastern Mediterranean has been documented extensively in airline safety reporting. The Aviation Information Sharing and Analysis Center, which collects safety data from aviation operators, has tracked hundreds of incidents from these regions over recent years.

Airlines operating in affected areas have developed operational responses. Flight management systems on newer Boeing and Airbus aircraft include inertial reference cross-check logic that flags large discrepancies between GPS position and inertial position. When the inertial system - operating independently of GPS via accelerometers and gyroscopes - disagrees significantly with the GPS-reported position, the flight deck receives an alert.

General aviation aircraft typically lack this cross-check capability. The GPS position, the ADS-B broadcast, and the moving-map display all trace back to a single GPS signal. If that signal is false, every downstream system is wrong simultaneously.

What a Fix Would Look Like - and Why It’s Taking So Long

The solution concept is called broadcast authentication for ADS-B. The technical foundation is asymmetric cryptography - the same mathematical structure securing financial transactions and HTTPS web traffic. Each transponder would be issued a private key. Every ADS-B message would carry a cryptographic signature generated with that key. Any receiver can verify the signature using the corresponding public key distributed through trusted infrastructure. A spoofed message lacking the correct signature is flagged or discarded.

The technology is mature. The implementation challenges are specific to aviation.

Latency: Cryptographic operations must complete fast enough to not degrade message rates on hardware with tight real-time constraints. Fleet replacement: Older transponders cannot be software-updated to add cryptographic signing - this means hardware replacement, not a firmware push, with a very different cost and compliance timeline. Global key infrastructure: Key management must be operational across every aviation authority in every country with a common trust model. Transition complexity: During the period when authenticated and legacy unauthenticated messages coexist in the same airspace, the trust model becomes genuinely complicated.

EUROCAE, the European aviation standards organization, has working groups examining ADS-B authentication. RTCA, formerly the Radio Technical Commission for Aeronautics, has parallel working groups in the United States. No regulatory timeline is currently defined. Given that the ADS-B Out mandate itself ran from the initial rulemaking notice around 2010 to the compliance deadline of January 1, 2020 - roughly a decade - a follow-on authentication mandate is likely measured in years, not months.

Why This Is Also a Drone Airspace Problem

The FAA’s Remote ID rule requires drones operating under federal regulations to broadcast identification and position data using Bluetooth and WiFi formats. The authentication gap is identical: Remote ID messages are unauthenticated. A compliant operator broadcasts their location with no verification mechanism. A non-compliant operator can transmit false Remote ID data.

As Unmanned Traffic Management - the framework being built to integrate drone operations into low-altitude airspace - relies increasingly on Remote ID as a surveillance input, the security gap becomes a question of airspace management infrastructure integrity, not only individual situational awareness.

What Pilots Can Do Right Now

Know the geographic risk. GPS spoofing incidents are heavily concentrated in specific regions. Before any international flight, check NOTAMs for GPS testing or interference activity, review FAA and ICAO publications on GPS interference zones, and assess whether your routing passes through documented high-risk areas. Flying from South Florida to the Bahamas and flying from Cyprus to Dubai represent fundamentally different threat environments.

Develop position cross-checking habits. Use VOR radials, DME distance, and non-GPS RNAV inputs to periodically verify your GPS position on cross-country flights. A GPS position that drifts relative to your other nav sources is worth investigating before it becomes a crisis.

Understand what ADS-B traffic actually is. ADS-B traffic is advisory. It is not certified for separation services and is not independently verified. When an approach controller tells you traffic is not a factor while your display shows otherwise, the controller’s radar - which uses active interrogation independent of ADS-B - is the more authoritative source. When your traffic display and TCAS disagree, treat the discrepancy as a flag worth investigating rather than defaulting to either system.

Report anomalies. GPS interference reports filed through the FAA and through the NASA Aviation Safety Reporting System feed the databases that researchers and regulators use to understand the scope of the problem. If your GPS behaves unexpectedly, log it and report it.

Key Takeaways

  • Every ADS-B message is transmitted without encryption or authentication - the protocol has no mechanism to verify a broadcast came from the aircraft it claims to represent
  • Injection attacks (false aircraft) can be cross-checked against TCAS; GPS spoofing corrupts the entire position chain simultaneously and offers fewer detection cues in a general aviation cockpit
  • Documented GPS spoofing campaigns in the Black Sea region (from approximately 2018), near Iran, and across the eastern Mediterranean have produced hundreds of confirmed incident reports
  • A cryptographic fix is technically well understood, but global fleet replacement and key management infrastructure requirements make a regulatory mandate likely years away
  • ADS-B traffic is advisory, not authoritative - controller radar, TCAS, and traditional navigation cross-checks remain essential layers of independent situational awareness

Radio Hangar. Aviation talk, built by pilots. Listen live | More articles