GPS jamming interferes with a receiver’s ability to track satellite navigation signals, and GPS spoofing sends false GNSS-like signals that a receiver may accept as real. For a drone operator, the first can leave the aircraft without a satellite position; the second can leave it with a confident but wrong one. This page explains both from the operator’s side, with FAA and FCC guidance, autopilot documentation and recent research, and deliberately leaves out how attacks are carried out.

Independent explainer: this site is named after the domain once used by the First Responder UAS Triple Challenge, whose Shields Up! challenge covered this topic, and is not its organizer or affiliated with NIST or the universities involved.

GPS jamming can make satellite positioning unavailable; GPS spoofing can make a receiver keep a position fix while reporting the wrong position or time. On a drone, losing GNSS (the generic term for GPS and other satellite navigation systems) may or may not trigger a failsafe: that depends on whether the autopilot’s overall position estimate degrades, the flight mode and how the aircraft is configured. Spoofing is harder to notice, because the aircraft can drift off course while its navigation still looks valid, and a return-home that relies on GPS can be misled with it. The FAA tells operators to watch for anomalies, check NOTAMs (the official notices to air missions), report disruptions and be ready to operate without GNSS. For drones, public defenses combine cross-checking GNSS against other sensors, failsafes based on the quality of the position estimate, authenticated control links and crew procedures. Operating a jammer is illegal in the U.S. for almost everyone, including state and local police.

Key points:

  • A position fix is not proof of a correct position: under spoofing, a receiver can keep reporting confidently and wrongly.
  • Disagreement between GNSS and the drone’s other sensors, its clock or its expected track can point to spoofing or another navigation fault; no single sign settles it.
  • No single receiver feature removes the risk; defenses are layered and include crew procedures.
  • Interference is not only hostile: the U.S. government runs scheduled GPS tests announced through NOTAMs, so checking NOTAMs is part of flight planning.

What are GPS jamming and GPS spoofing?

Jamming blocks a receiver from tracking real satellite signals; spoofing feeds it false ones that it may track instead. Both affect GNSS, the global navigation satellite systems that include GPS, Galileo and others. The definitions below are the FAA’s, from its 2026 GNSS Interference Resource Guide, which says they match the Pilot/Controller Glossary.

Jamming Spoofing
FAA definition (paraphrased) Emissions that do not mimic GNSS signals but interfere with a civil receiver’s ability to acquire and track them Emissions of GNSS-like signals that a civil receiver may acquire and track alongside, or instead of, the real ones
What the receiver does Loses navigation, positioning and timing May keep a solution, but with false position, navigation or time information
How it looks to the crew Relatively easy to detect: the system reports it cannot receive GPS More insidious: position disagreements, unusual speed differences, time or date shifts, a drifting position
Timing During the interference Onset can be immediate or delayed, and effects can persist after the spoofing ends

The FAA guide adds that jamming is often used to set up a spoofing attack. Its indications are written for crewed aircraft. Our reading for drones: jamming is more likely to be visible as a loss of GNSS, if the drone’s software shows that to the pilot, while spoofing can look like normal navigation.

Why does spoofing matter so much for drones?

Because a drone’s automation trusts its position estimate, and spoofing corrupts that estimate without necessarily raising an alarm. Two 2026 studies show the effect from different angles.

  • Receivers keep a fix. In a laboratory test of five commercial GNSS receivers, jamming caused an immediate loss of positioning, while under spoofing most receivers kept a navigation fix carrying persistent, undetected errors. The authors conclude that fix continuity alone is not a reliable indicator of navigation integrity, and that multi-band receivers delayed acceptance of the false signal rather than preventing it. They caution that these were laboratory conditions.
  • Automation follows the false position. In controlled outdoor trials, a spoofed quadcopter flying an autonomous mission left its planned path, crossed its geofence and behaved unstably, ending in an uncontrolled descent instead of the intended return-to-launch. The aircraft’s other sensor data showed clear anomalies during the spoofed flights.

Our reading: any safety behavior that depends on GPS (geofence, return-to-home, position hold) inherits GPS’s weakness. A failsafe is only as trustworthy as the position it uses.

The FAA guide also notes where drones meet interference in practice. GNSS interference has been used to stop drone use at heavily attended events, the Department of Defense and certain law enforcement agencies can use counter-drone systems that jam or spoof GNSS to force unauthorized drones to land, and SAFO 24002 lists areas of counter-drone protection among the places disruptions occur. Separately, the U.S. government conducts GPS tests, training and exercises that interfere with GPS; these are scheduled and announced through NOTAMs and FAA public notices.

Two functions, which the Shields Up! challenge defined neatly. Navigation is the drone’s ability to move successfully between two points in 3D airspace; control is the ability of a pilot-controlled drone to keep flight control in 3D airspace. GNSS interference attacks navigation. The control link, the radio connection between the drone and its ground station, is a separate target. A 2026 systematic review of drone cybersecurity research describes the wider attack surface as flight-control and payload software, radio links and swarm coordination, with threats grouped as spoofing, jamming, intrusion and malware.

What is attacked Threat Typical effect Public defense category
Navigation (GNSS) Jamming GNSS position unavailable; a failsafe may follow, depending on the position estimate, flight mode and settings Other position sources; failsafe on position-estimate quality; crew able to fly without GNSS
Navigation (GNSS) Spoofing Confident but wrong position; drift, geofence breach, misdirected return-home Cross-sensor consistency checks; integrity monitoring; procedures
Control links Jamming Loss of the ground-station data link or of manual (remote control) input Separate failsafes for each, where enabled (PX4 documents both)
Control link Injected or forged commands Commands the operator did not send Message authentication, such as MAVLink 2 signing
Software and configuration Intrusion, malware, weak default settings Changed behavior or exposed data Updates, secure configuration, vulnerability disclosure

The payload link that carries video or relayed user traffic is a different channel again; our drone communications relay explainer covers how that traffic is carried and how it differs from the links that fly the aircraft.

How can spoofing and jamming be detected?

By looking for disagreement. Jamming is the easy case: the receiver reports that it has lost the signal. Spoofing may show up when GNSS stops agreeing with something else the aircraft or crew knows, although a disagreement can also have other causes. Indicators drawn from the FAA guide, adapted from crewed aircraft, and from the 2026 drone study:

  • Position disagreement between GNSS and other navigation sources, or a sudden jump in displayed position.
  • Speed that does not add up: the FAA lists abnormal differences between ground speed and airspeed; on a drone, GNSS-derived velocity can be compared with inertial and other sensor data.
  • Time or date shifts, since spoofing can corrupt timing as well as position.
  • Sensor anomalies during the event: the drone study found barometric altitude, yaw, magnetometer and vibration data behaving abnormally during spoofed flights, and proposed flagging deviations between GPS, inertial and barometric readings.
  • A track that does not match the plan or what the pilot sees, which is one practical reason to keep the aircraft in sight.

None of these is conclusive alone, and none was measured here. The lab study’s point stands: a steady fix is not evidence of a correct one, so checks that do not rely only on the GNSS receiver’s own fix, such as cross-sensor comparison, are one practical way to detect it.

What reduces the risk?

Layered measures, because each one covers a different failure. The table is our summary of public guidance and documentation; it is not a ranking or a guarantee.

Measure What it addresses Limit
Additional position sources (PX4 lists GNSS, optical flow, airspeed, visual-inertial odometry and auxiliary global position) Keeps an estimate when GNSS is lost or questionable Each source has its own conditions in which it works
Failsafe on position-estimate quality (PX4’s position loss failsafe) Reacts when the estimate becomes invalid or too inaccurate A spoofed estimate may still look valid
Data-link-loss and manual-control-loss failsafes (PX4) A configured action when the ground-station link or remote-control input is lost, if enabled for the current mode Does not tell jamming from ordinary range loss
Authenticated control messages (MAVLink 2 message signing) Lets the system verify that messages come from a trusted source Requires keys to be set up and protected on both ends
Updated software and secure configuration Closes known weaknesses in autopilot and ground software Depends on the manufacturer’s and operator’s update practice
Crew procedures (from SAFO 24002): check NOTAMs, monitor for anomalies, report disruptions, be prepared to operate without GNSS Human detection and a planned fallback Needs training and a drone that can be flown without GNSS assistance
Risk management framework (NIST IR 8323 Rev. 1, a voluntary profile for positioning, navigation and timing, or PNT) Organization-level identification and management of positioning and timing risks A framework, not a technical control
Layered defenses for drone navigation and control, from software and authenticated links to cross-checks, failsafes and crew procedures
Public defenses against GNSS interference and control-link attacks work in layers. Illustrative.

NIST’s PNT Profile was written under Executive Order 13905 (February 2020) on the responsible use of positioning, navigation and timing services. It treats PNT signals as susceptible to disruption and manipulation that can be natural or man-made, intentional or not, which is a useful framing for a drone program’s risk register.

Can you jam a drone yourself?

No, not legally, for almost anyone in the U.S. The FCC’s 2014 enforcement advisory states that using any device that blocks, jams or interferes with authorized communications is illegal, that “jammers” include GPS jammers, and that the prohibition covers every entity without a federal authorization, including state and local law enforcement. GPS.gov adds that local law enforcement agencies have no independent authority to use jamming equipment, that use by federal law enforcement is authorized only in limited cases under applicable statutes, and that advertising, selling or importing jammers to consumers is also unlawful.

Jamming also does not discriminate. The FCC notes that a jammer can stop GPS units, cell phones and Wi-Fi devices within its range from working, including a first responder’s ability to locate someone in an emergency. Questions about countering other people’s drones belong with the agencies that hold federal authority, not with a drone program’s own equipment list.

What did the 2021 Shields Up! challenge ask for?

Shields Up!, challenge 3.3 of NIST PSCR’s First Responder UAS Triple Challenge, asked contestants to identify real-world threats to drone flight, navigation and control, find countermeasures, and demonstrate both on a functional UAS. Attacks had to target open-source navigation or control software. The FAQ required a mission scenario to show that an attack mattered in a real public safety context, and said that disclosing a vulnerability found in proprietary software to its manufacturer was ethical. The challenge offered up to $200,000 and concluded in April 2022. The UAS Triple Challenge archive summarizes what the archived competition pages can confirm and links to NIST’s official results.

Questions to check in your drone program

Use these to review an aircraft type, its settings and your procedures. If you cannot answer one, treat it as an open risk:

  1. What does the aircraft do when it loses GNSS, and has the crew practiced it?
  2. Which position sources besides GNSS does it use, and in what conditions do they work?
  3. What triggers its position-loss failsafe, and what action is set?
  4. Does any check compare GNSS with inertial, barometric or other sensor data, and does the crew see the result?
  5. Do return-home and geofence rely only on GPS?
  6. Is the control link authenticated, and who manages the keys?
  7. How are autopilot and ground-station updates delivered and applied?
  8. Do flight plans include a NOTAM check for GPS interference and testing?
  9. Does the crew know how to report a GPS anomaly to the FAA?
  10. Does the manufacturer have a way to receive and act on vulnerability reports?

Method and sources

This page is compiled from public sources, not from our own testing, and it does not describe how to carry out an attack. Definitions and indicators come from the FAA’s 2026 GNSS Interference Resource Guide and SAFO 24002, both written for crewed aviation and applied here to drones by analogy. Legal points come from the FCC’s 2014 enforcement advisory and GPS.gov. Autopilot behavior comes from PX4 and MAVLink documentation as published on 7 October 2026; settings differ between versions and products. Research findings are taken from the papers’ published abstracts, and we do not repeat their measured rates. Competition details come from archived copies of the challenge website. Nothing here is legal, safety or compliance advice, or a judgment on any product.

Last updated: 7 October 2026.