REVIEW 1 major objections 2 minor 1 cited by
A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing
T0 review · 1 major / 2 minor · reviewed 2026-06-25 · grok-4.3
Pith's one-line read A Timing Protection Level conditionally bounds undetected time error to oscillator holdover plus a model-free monitor floor under GNSS spoofing, if an independent check detects the attack.
desk verdict No unconditional undetected time error bound exists under a single self-referential monitor, but the paper supplies a workable conditional TPL once an independent cross-satellite check is assumed to trigger. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The Timing Protection Level (TPL), formed as the sum of a model-free monitor's static detectability floor and the oscillator coast during detection latency, conditional on an independent cross-satellite consistency check detecting the attack.
What would settle it
A field recording of a coherent spoof in which the cross-satellite consistency check fails to alarm before the served-time error exceeds the calculated TPL value.
Extended reading notes
Core claim
Against an adversary free to choose ramp rate, no finite unconditional bound on undetected time error exists under a single self-referential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step is never alarmed while the error grows without limit. The Timing Protection Level (TPL) is therefore defined as a model-free monitor's static detectability floor plus the oscillator's coast over the detection latency; this bound holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step. Each term is closed-form over primitives verified in the open Kshana simulator, and calibration on the recor
Load-bearing premise
An independent cross-satellite consistency check will detect the spoof attack and the spoofer will not drive that check in lock-step with the timing receiver.
Editorial extensions
If this is right
- A clock-aided sequential test alone alarms only near the ~1 ms capture and therefore supplies essentially no protection against the slow ramp.
- The model-free monitor alarms during the ramp itself, supplying the detectability floor that enters the TPL.
- The resulting TPL is thousands of times smaller than the 1.01 ms error accepted by the receiver in the recorded attack.
- The bound is reported as a band at long coast and carries no integrity-risk budget.
Reading between the lines
- If receivers routinely run both the model-free monitor and an independent consistency check, served-time error could be kept to sub-microsecond levels even under slow coherent spoofing.
- The open-source simulator and closed-form expressions allow direct substitution of different oscillator specifications or monitor thresholds without re-deriving the entire bound.
- The same conditional structure could be examined for other common-mode threats, such as ionospheric or ephemeris manipulation, provided an independent detector exists.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript reports a field measurement from the JammerTest 2024 campaign in which a u-blox ZED-F9P receiver experienced a 1.01 ms served-time error under spoofing while its internal accuracy flag reported at most 51 ns. It proves that no finite unconditional bound on undetected time error exists under any single self-referential clock-aided monitor, because an adversary can always choose a sufficiently slow ramp that keeps the disciplined reference in lock-step. It then defines a conditional Timing Protection Level (TPL) as the sum of a model-free monitor's static detectability floor plus the oscillator coast over detection latency, conditioned on detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step. Each term is given in closed form over primitives verified in the open Kshana simulator; when calibrated on the recorded attack the TPL evaluates to 114 ns at 1 s recovery and 458 ns at 60 s coast. The simulator, expressions, and calibration are released under AGPL-3.0.
Significance. If the conditioning assumption holds, the TPL supplies a reproducible, hand-verifiable bound on undetected time error that is thousands of times tighter than the observed attack error and directly addresses the failure of position-domain RAIM against common-mode time pulls. The explicit open-source release of the simulator, the closed-form expressions, and the calibration example constitutes a verifiable and extensible contribution to GNSS timing integrity.
major comments (1)
- [Abstract, third contribution] Abstract, third contribution: the claim that the TPL holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step is load-bearing for the entire conditional result. The manuscript supplies no measurement model for the check, no demonstration that coherence precludes lock-step driving of the residuals, and no counter-example search within the Kshana simulator, leaving the robustness of the conditioning assumption unverified.
minor comments (2)
- The abstract correctly states that the bound is calibrated rather than field-validated and carries no integrity-risk budget; repeating this disclaimer in the conclusions would improve clarity for readers who reach only the final section.
- Notation for the model-free monitor's static detectability floor and the oscillator coast parameters should be introduced with explicit symbols in the main text before the closed-form expressions are presented.
Simulated Author's Rebuttal
We thank the referee for the constructive review and for highlighting the centrality of the conditioning assumption. We address the single major comment below.
read point-by-point responses
-
Referee: [Abstract, third contribution] Abstract, third contribution: the claim that the TPL holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step is load-bearing for the entire conditional result. The manuscript supplies no measurement model for the check, no demonstration that coherence precludes lock-step driving of the residuals, and no counter-example search within the Kshana simulator, leaving the robustness of the conditioning assumption unverified.
Authors: We agree that the conditioning assumption is load-bearing and that the manuscript would be strengthened by additional substantiation. The cross-satellite consistency check is defined as independent of the self-referential clock-aided monitor; under a coherent spoofer the common-mode time pull leaves the differential residuals (and thus the check) unaffected, so the check cannot be driven in lock-step. However, the current text provides no explicit measurement model, derivation, or simulator counter-example search. We will revise to add a short dedicated paragraph supplying the measurement model for the check, showing why coherence precludes lock-step driving of its residuals, and stating the assumption explicitly as a prerequisite (with the associated limitation). revision: yes
Circularity Check
Derivation is self-contained; no circular steps identified
full rationale
The paper defines TPL explicitly as the sum of two closed-form terms (model-free monitor static floor + oscillator coast over latency) under a stated external condition (detection by independent cross-satellite check that a coherent spoofer does not drive in lock-step). Each term is described as derived from primitives verified in the open Kshana simulator, making the structure reproducible by hand independent of the specific attack dataset. The numerical values (114 ns, 458 ns) are openly labeled as 'calibrated on the recorded attack' with the explicit disclaimer that the bound 'is calibrated, not field-validated' and 'carries no integrity-risk budget.' This calibration is transparent and does not reduce the claimed derivation to its inputs by construction. No self-citations appear in the load-bearing steps, no uniqueness theorems are imported from prior author work, and the impossibility result for unconditional bounds is logically separate from the conditional construction. The central claim therefore remains self-contained against external benchmarks.
Assumptions & free parameters
free parameters (2)
- static detectability floor
- oscillator coast time
assumptions (1)
- domain assumption An independent cross-satellite consistency check detects coherent spoofers that a clock-aided monitor misses.
Cite this review
Pith. "Pith review of A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing." pith.science (2026). https://pith.science/paper/AFSUYA3N
@misc{pith2026260624210,
author = {Pith},
title = {Pith review of: A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing},
year = {2026},
howpublished = {\url{https://pith.science/paper/AFSUYA3N}},
note = {Machine review of arXiv:2606.24210}
}
read the original abstract
A GNSS timing receiver under spoofing has no nominal-geometry fault for position-domain RAIM to bound: the threat is a slow, common-mode pull of served clock time that the receiver's own time-accuracy flag need not reveal. We make three graded contributions. First, a field measurement: solving the receiver clock trajectory from raw L1 pseudoranges and broadcast ephemeris, we show a recorded over-the-air spoof from the public JammerTest 2024 campaign pulled a u-blox ZED-F9P by about 1.01 ms of served time while it reported at most 51 ns, a gap near 20,000x. Second, an impossibility: against an adversary free to choose the ramp rate, no finite unconditional bound on undetected time error exists under a single self-referential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step is never alarmed while the error grows without limit, so any finite guarantee is conditional. Third, the conditional bound: the Timing Protection Level (TPL), a model-free monitor's static detectability floor plus the oscillator's coast over the detection latency, holds given detection by an independent cross-satellite consistency check a coherent spoofer does not drive in lock-step. Each term is a closed form over a primitive verified in the open Kshana simulator, so the sum is reproducible by hand. Calibrated on the recorded attack, the budget is 114 ns at one-second recovery and 458 ns at a 60-second coast, thousands of times below the 1.01 ms accepted; a clock-aided sequential test alone gives essentially no protection on this slow ramp (it alarms only near the ~1 ms capture), while the model-free monitor alarms during the ramp. We are explicit: the bound is calibrated, not field-validated; carries no integrity-risk budget; and is reported as a band at long coast. The simulator, bound, and calibration example are open source under AGPL-3.0.
Figures
Forward citations
Cited by 1 Pith paper
-
Rigid-Covert GNSS Spoofing of UAV Swarms: A Structural Blind Spot, Its Detection Limit, and Absolute-Anchor Defenses
A common, geometry-preserving GNSS shift is invisible to distance-only swarm defenses, but a small set of trusted anchors can restore absolute positions, and a derived detection floor predicts how fast a covert ramp m...
Reference graph
Works this paper leans on
-
[1]
GNSS dataset under jam- ming, spoofing, and meaconing conditions (JammerTest 2024),
M. I. Sayyaf, M. Ortiz, and V . Renaudin, “GNSS dataset under jam- ming, spoofing, and meaconing conditions (JammerTest 2024),” dataset, Universit´e Gustave Eiffel, Zenodo, 2025, GPL-3.0-or-later. Version DOI 10.5281/zenodo.15911589 (concept DOI 10.5281/zenodo.15910563). [Online]. Available: https://doi.org/10.5281/zenodo.15911589
-
[2]
GNSS spoofing and detection,
M. L. Psiaki and T. E. Humphreys, “GNSS spoofing and detection,” Proc. IEEE, vol. 104, no. 6, pp. 1258–1270, 2016
2016
-
[3]
Assessing the spoofing threat: development of a portable GPS civilian spoofer,
T. E. Humphreys, B. M. Ledvina, M. L. Psiaki, B. W. O’Hanlon, and P. M. Kintner, “Assessing the spoofing threat: development of a portable GPS civilian spoofer,” inProc. ION GNSS, 2008
2008
-
[4]
On the requirements for successful GPS spoofing attacks,
N. O. Tippenhauer, C. P ¨opper, K. B. Rasmussen, and S. ˇCapkun, “On the requirements for successful GPS spoofing attacks,” inProc. ACM Conf. Computer and Communications Security (CCS), 2011, pp. 75–86
2011
-
[5]
Who’s afraid of the spoofer? GPS/GNSS spoofing detection via automatic gain control (AGC),
D. M. Akos, “Who’s afraid of the spoofer? GPS/GNSS spoofing detection via automatic gain control (AGC),”NAVIGATION, vol. 59, no. 4, pp. 281–290, 2012
2012
-
[6]
Receiver- autonomous spoofing detection: experimental results of a multi-antenna receiver defense against a portable civil GPS spoofer,
P. Y . Montgomery, T. E. Humphreys, and B. M. Ledvina, “Receiver- autonomous spoofing detection: experimental results of a multi-antenna receiver defense against a portable civil GPS spoofer,” inProc. ION Int. Tech. Meeting (ITM), 2009
2009
-
[7]
Dovis,GNSS Interference Threats and Countermeasures
F. Dovis,GNSS Interference Threats and Countermeasures. Norwood, MA: Artech House, 2015
2015
-
[8]
GPS vulnerability to spoofing threats and a review of antispoofing techniques,
A. Jafarnia-Jahromi, A. Broumandan, J. Nielsen, and G. Lachapelle, “GPS vulnerability to spoofing threats and a review of antispoofing techniques,”Int. J. Navig. Obs., vol. 2012, art. 127072, 2012
2012
Show all 28 references
-
[9]
A survey and analysis of the GNSS spoofing threat and countermeasures,
D. Schmidt, K. Radke, S. Camtepe, E. Foo, and M. Ren, “A survey and analysis of the GNSS spoofing threat and countermeasures,”ACM Comput. Surv., vol. 48, no. 4, art. 64, pp. 1–31, 2016
2016
-
[10]
A baseline GPS RAIM scheme and a note on the equivalence of three RAIM methods,
R. G. Brown, “A baseline GPS RAIM scheme and a note on the equivalence of three RAIM methods,”NAVIGATION, vol. 39, no. 3, pp. 301–316, 1992
1992
-
[11]
Weighted RAIM for precision approach,
T. Walter and P. Enge, “Weighted RAIM for precision approach,” in Proc. ION GPS, 1995
1995
-
[12]
Baseline advanced RAIM user algorithm and possible improvements,
J. Blanchet al., “Baseline advanced RAIM user algorithm and possible improvements,”IEEE Trans. Aerosp. Electron. Syst., vol. 51, no. 1, pp. 713–732, 2015
2015
-
[13]
A navigation message authentication proposal for the Galileo open service,
I. Fern ´andez-Hern´andez, V . Rijmen, G. Seco-Granados, J. Simon, I. Rodr ´ıguez, and J. D. Calle, “A navigation message authentication proposal for the Galileo open service,”NAVIGATION, vol. 63, no. 1, pp. 85–102, 2016
2016
-
[14]
Requirements for secure clock synchronization,
L. Narula and T. E. Humphreys, “Requirements for secure clock synchronization,”IEEE J. Sel. Topics Signal Process., vol. 12, no. 4, pp. 749–762, 2018
2018
-
[15]
Statistics of atomic frequency standards,
D. W. Allan, “Statistics of atomic frequency standards,”Proc. IEEE, vol. 54, no. 2, pp. 221–230, 1966
1966
-
[16]
W. J. Riley,Handbook of Frequency Stability Analysis, NIST Special Publication 1065. Boulder, CO: National Institute of Standards and Technology, 2008
2008
-
[17]
Computing integrals involving the matrix exponential,
C. F. Van Loan, “Computing integrals involving the matrix exponential,” IEEE Trans. Autom. Control, vol. 23, no. 3, pp. 395–404, 1978
1978
-
[18]
Continuous inspection schemes,
E. S. Page, “Continuous inspection schemes,”Biometrika, vol. 41, no. 1/2, pp. 100–115, 1954
1954
-
[19]
Basseville and I
M. Basseville and I. V . Nikiforov,Detection of Abrupt Changes: Theory and Application. Englewood Cliffs, NJ: Prentice Hall, 1993
1993
-
[20]
Evaluation of the vulnerability of phasor measurement units to GPS spoofing attacks,
D. P. Shepard, T. E. Humphreys, and A. A. Fansler, “Evaluation of the vulnerability of phasor measurement units to GPS spoofing attacks,”Int. J. Critical Infrastructure Protection, vol. 5, no. 3–4, pp. 146–153, 2012
2012
-
[21]
Navstar GPS space segment / navigation user segment interfaces,
Global Positioning System Directorate, “Navstar GPS space segment / navigation user segment interfaces,” Interface Specification IS-GPS-200, Rev. N, 2022
2022
-
[22]
E. D. Kaplan and C. J. Hegarty,Understanding GPS/GNSS: Principles and Applications, 3rd ed. Norwood, MA: Artech House, 2017
2017
-
[23]
Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System,
J. A. V olpe National Transportation Systems Center, “Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System,” U.S. Department of Transportation, 2001
2001
-
[24]
Executive Order 13905: strengthen- ing national resilience through responsible use of positioning, naviga- tion, and timing services,
Executive Office of the President, “Executive Order 13905: strengthen- ing national resilience through responsible use of positioning, naviga- tion, and timing services,”Federal Register, vol. 85, no. 32, p. 9359, Feb. 2020
2020
-
[25]
Measuring relays and protection equipment – Part 118-1: synchrophasor for power systems – measurements,
IEC/IEEE, “Measuring relays and protection equipment – Part 118-1: synchrophasor for power systems – measurements,” IEC/IEEE 60255- 118-1:2018
2018
-
[26]
Timing characteristics of pri- mary reference time clocks,
International Telecommunication Union, “Timing characteristics of pri- mary reference time clocks,” ITU-T Recommendation G.8272, 2018
2018
-
[27]
IEEE standard for a precision clock synchronization protocol for networked measurement and control systems,
IEEE, “IEEE standard for a precision clock synchronization protocol for networked measurement and control systems,” IEEE Std 1588-2019, 2020
2019
-
[28]
Kshana: an open, reproducible PNT-resilience simulator,
C. Baweja, “Kshana: an open, reproducible PNT-resilience simulator,” software, version 0.19.0, AGPL-3.0-only, 2026. [Online]. Available: https://github.com/AshfordeOU/kshana
2026
Reviewed June 25, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.