UWBAD: Towards Effective and Imperceptible Jamming Attacks Against UWB Ranging Systems with COTS Chips
Yuqiao Yang, Zhongjie Wu, Yongzhao Zhang, Ting Chen, Jun Li, Jie Yang, Wenhao Liu, Xiaosong Zhang, Ruicong Shi, Jingwei Li, Yu Jiang, Zhuo Su
Abstract
UWB ranging systems have been adopted in many critical and security sensitive applications due to its precise positioning and secure ranging capabilities. We present a practical jamming attack, namely UWBAD, against commercial UWB ranging systems, which exploits the vulnerability of the adoption of the normalized cross-correlation process in UWB ranging and can selectively and quickly block ranging sessions without prior knowledge of the configurations of the victim devices, potentially leading to severe consequences such as property loss, unauthorized access, or vehicle theft. UWBAD achieves more effective and less imperceptible jamming due to: (i) it efficiently blocks every ranging session by leveraging the fieldlevel jamming, thereby exerting a tangible impact on commercial UWB ranging systems, and (ii) the compact, reactive, and selective system design based on COTS UWB chips, making it affordable and less imperceptible. We successfully conducted real attacks against commercial UWB ranging systems from the three largest UWB chip vendors on the market, e.g., Apple, NXP, and Qorvo. We reported our findings to Apple, related Original Equipment Manufacturers (OEM), and the Automotive Security Research Group, triggering internal security incident response procedures at Volkswagen, Audi, Bosch, and NXP. As of the writing of this paper, the related OEM has acknowledged this vulnerability in their automotive systems and has offered a $5, 000 reward as a bounty. CCS Concepts • Security and privacy → Mobile and wireless security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28f01183-d1bf-49c0-a0eb-60a8f88c4d8cBuilds on5
- UWB with Pulse Reordering: Securing Ranging against Relay and Physical-Layer AttacksMridula Singh, Patrick Leu, Srdjan CapkunNDSS 2019 · 57 citations
- Secure Ranging with IEEE 802.15.4z HRP UWBXiliang Luo, Cem Kalkanli, Hao Zhou, Pengcheng Zhan et al.S&P 2024 · 7 citations
- Protecting HRP UWB Ranging System Against Distance Reduction AttacksKyungho Joo, Dong Hoon Lee, Yeonseon Jeong, Wonsuk ChoiCCS 2023 · 7 citations
- Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB RangingPatrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Roeschlin et al.USENIX Security 2022
- Time for Change: How Clocks Break UWB Secure RangingClaudio Anliker, Giovanni Camurati, Srdjan CapkunUSENIX Security 2023
Related papers
- UWBKey: Using Contrastive Learning for Efficient Secure Key Generation in UWBHaige Chen, Ashutosh DhekneUbiComp 2026 · 1 citation
- On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long DistanceTakami Sato, Ryo Suzuki, Yuki Hayakawa, Kazuma Ikeda et al.NDSS 2025
- Sync Under Siege: Spoofing Attack and Detection in 5G NR-V2X SynchronizationMd Imran Hossain, Jiang XieINFOCOM 2026
- Physical-World Attack towards WiFi-based Behavior RecognitionJianwei Liu, Yinghui He, Chaowei Xiao, Jinsong Han et al.INFOCOM 2022 · 25 citations
- V-Range: Enabling Secure Ranging in 5G Wireless NetworksMridula Singh, Marc Roeschlin, Aanjhan Ranganathan, Srdjan CapkunNDSS 2022
