USENIX Security2026Top-tier venue
Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC
Mehdi Ziazi, Khalid Aleem, Harshad Sathaye, Martin Strohmeier
Abstract
This paper is currently under embargo, but the paper abstract is available now. The final paper PDF will be available on the first day of the conference. The Controller–Pilot Data Link Communications (CPDLC) system has become integral to modern air traffic management, particularly in high-density or oceanic airspace where voice communication is limited or unavailable. Designed to increase operational efficiency, CPDLC is an alternative to traditional VHF voice communication with standardized digital messages for altitude changes, heading adjustments, free-text messages, and frequency handovers. However, CPDLC does not implement encryption and relies primarily on protocol complexity and obscurity as a barrier to misuse. In this work, we present a full-stack security analysis of CPDLC and showcase several vulnerabilities that allow hijacking ATC-Pilot link with rogue ground station attacks and large-scale denial of service attacks that are capable of disabling CPDLC services for all aircraft in radio range. As a proof-of-concept, we also introduce cpdlc-gs, a first SDR based full-stack CPDLC ground-station implementation capable of injecting uplink messages to issue fake CPDLC flight instructions and effective denial of service attacks. Furthermore, to evaluate cpdlc-gs, together with air navigation service providers and avionics manufacturers, we develop a novel, fully-functional test environment with real, certifiable hardware from Universal Avionics. Through such a setup we conceptualize and validate several attacks and demonstrate that even isolated rogue stations can pose a substantial threat, especially when pilots are under high workload or in degraded communication scenarios. Overall, we argue that the heavy reliance and global adoption of CPDLC make it a high value target, and that the lagging aviation datalink security standard- ization process needs to be urgently addressed
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 608f99df-b2b5-47f8-b8ff-91d978ece283Builds on4
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
- Wireless Attacks on Aircraft Instrument Landing SystemsHarshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara NoubirUSENIX Security 2019 · 30 citations
- On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)Giacomo Longo, Martin Strohmeier, Enrico Russo, Alessio Merlo et al.USENIX Security 2024 · 8 citations
- A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic SystemsMatthew Smith, Martin Strohmeier, Jon Harman, Vincent Lenders et al.NDSS 2020
Related papers
- Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic SurveillanceKai Jansen, Liang Niu, Nian Xue, Ivan Martinovic et al.NDSS 2021
- An Experimental Study of GPS Spoofing and Takeover Attacks on UAVsHarshad Sathaye, Martin Strohmeier, Vincent Lenders, Aanjhan RanganathanUSENIX Security 2022
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich et al.USENIX Security 2019 · 59 citations
- A Formal Security Analysis of CAN XLZhaozhou Tang, Khaled Serag, Z. Berkay Celik, Vijay Ganesh et al.USENIX Security 2026
- Design and Implementation of a Physical Implant Attack on the Boeing 737Sam Crow, Stephen Checkoway, Patrick Mercier, Pat Pannuto et al.USENIX Security 2026
