[Paper Review] Safety vs. Security: Attacking Avionic Systems with Humans in the Loop
This paper investigates the real-world impact of wireless cyberattacks on safety-critical avionics systems by conducting controlled experiments with 30 Airbus A320-rated pilots in a flight simulator. It demonstrates that novel, practical attacks on TCAS, GPWS, and ILS significantly disrupt flight handling, increase pilot workload, and cause 38% of pilots to disable safety systems—highlighting a critical gap in aviation's reliance on safety culture over active security measures.
Many wireless communications systems found in aircraft lack standard security mechanisms, leaving them fundamentally vulnerable to attack. With affordable software-defined radios available, a novel threat has emerged, allowing a wide range of attackers to easily interfere with wireless avionic systems. Whilst these vulnerabilities are known, concrete attacks that exploit them are still novel and not yet well understood. This is true in particular with regards to their kinetic impact on the handling of the attacked aircraft and consequently its safety. To investigate this, we invited 30 Airbus A320 type-rated pilots to fly simulator scenarios in which they were subjected to attacks on their avionics. We implement and analyse novel wireless attacks on three safety-related systems: Traffic Collision Avoidance System (TCAS), Ground Proximity Warning System (GPWS) and the Instrument Landing System (ILS). We found that all three analysed attack scenarios created significant control impact and cost of disruption through turnarounds, avoidance manoeuvres, and diversions. They further increased workload, distrust in the affected system, and in 38% of cases caused the attacked safety system to be switched off entirely. All pilots felt the scenarios were useful, with 93.3% feeling that simulator training for wireless attacks could be valuable.
Motivation & Objective
- To assess the real-world kinetic and operational impact of wireless cyberattacks on safety-critical avionics systems when pilots are actively involved in flight decisions.
- To investigate whether aviation’s existing safety culture and training are sufficient to mitigate deliberate, targeted wireless interference attacks.
- To evaluate pilot responses to novel, realistic wireless attacks on three key systems: TCAS, GPWS, and ILS.
- To determine the feasibility and value of using flight simulators for training pilots to recognize and respond to wireless cyberattacks.
- To identify actionable mitigations and recommend improvements for current and future avionics security, especially where security-by-design is not yet implemented.
Proposed method
- Developed and implemented three novel, practical wireless interference attacks on TCAS, GPWS, and ILS using software-defined radios (SDRs) to mimic real-world attack conditions.
- Conducted controlled flight simulator experiments with 30 professional Airbus A320-rated pilots, exposing them to realistic cyberattack scenarios in a human-in-the-loop environment.
- Collected in-simulator performance data, pilot workload metrics, and post-experiment debrief interviews to analyze behavioral and operational responses.
- Analyzed pilot decisions, including system disengagement, avoidance maneuvers, and workload changes, to quantify the impact of attacks on flight safety and handling.
- Evaluated the potential of spectrum monitoring and crowdsourced air traffic surveillance as early warning systems for detecting rogue transmissions.
- Proposed targeted, low-cost mitigations such as using DME for ILS signal authentication and advocating for future secure-by-design data links like AeroMACS.
Experimental results
Research questions
- RQ1How do pilots respond behaviorally and operationally when subjected to realistic wireless attacks on TCAS, GPWS, and ILS in a simulated flight environment?
- RQ2To what extent do existing safety culture and training practices mitigate the effects of deliberate wireless interference, or do they amplify the risk?
- RQ3What is the kinetic impact of these attacks on aircraft handling, including workload, control deviations, and system disengagement?
- RQ4Can flight simulator training for wireless cyberattacks improve pilot awareness and preparedness, and what are the risks of negative training effects?
- RQ5What practical, low-cost mitigations can be implemented in the near term to reduce the risk of such attacks before full security-by-design upgrades are feasible?
Key findings
- 38% of pilots disabled the attacked safety system during the scenarios, indicating a significant risk of system disengagement under stress or confusion.
- All three attack scenarios caused measurable disruption, including avoidance maneuvers, increased workload, and flight path deviations, with TCAS attacks being the most disruptive.
- 93.3% of pilots reported that simulator-based training for wireless cyberattacks would be valuable, highlighting strong support for such training programs.
- Pilots reported a perceived reduction in safety during attacks, even when they managed to maintain control, indicating that attacks can undermine confidence in critical systems.
- The lack of standard security mechanisms in current avionics systems leaves them fundamentally vulnerable to low-cost, accessible SDR-based attacks.
- Spectrum monitoring and crowdsourced surveillance networks were identified as promising early warning systems for detecting rogue transmissions on key aviation frequencies.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.