Drone Security and the Mysterious Case of DJI's DroneID
Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, Thorsten Holz
Abstract
Consumer drones enable high-class aerial video photography, promise to reform the logistics industry, and are already used for humanitarian rescue operations and during armed conflicts. Contrasting their widespread adoption and high popularity, the low entry barrier for air mobility---a traditionally heavily regulated sector---poses many risks to safety, security, and privacy. Malicious parties could, for example, (mis-)use drones for surveillance, transportation of illegal goods, or cause economic damage by intruding the closed airspace above airports. To prevent harm, drone manufacturers employ several countermeasures to enforce safe and secure use of drones, e.g., they impose software limits regarding speed and altitude, or use geofencing to implement no-fly zones around airports or prisons. Complementing traditional countermeasures, drones from the market leader DJI implement a tracking protocol called DroneID, which is designed to transmit the position of both the drone and its operator to authorized entities such as law enforcement or operators of critical infrastructures.
In this paper, we analyze security and privacy claims for drones, focusing on the leading manufacturer DJI with a market share of 94%. We first systemize the drone attack surface and investigate an attacker capable of eavesdropping on the drone's over-the-air data traffic. Based on reverse engineering of DJI firmware, we design and implement a decoder for DJI's proprietary tracking protocol DroneID, using only cheap COTS hardware. We show that the transmitted data is not encrypted, but accessible to anyone, compromising the drone operator's privacy. Second, we conduct a comprehensive analysis of drone security: Using a combination of reverse engineering, a novel fuzzing approach tailored to DJI's communication protocol, and hardware analysis, we uncover several critical flaws in drone firmware that allow attackers to gain elevated privileges on two different DJI drones and their remote control. Such root access paves the way to disable or bypass countermeasures and abuse drones. In total, we found 16 vulnerabilities, ranging from denial of service to arbitrary code execution. 14 of these bugs can be triggered remotely via the operator's smartphone, allowing us to crash the drone mid-flight.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a4d7b947-a540-4f2a-9619-eaf2323452e0Cited by top-tier papers6
- MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic FirmwareMichael Chesser, Surya Nepal, Damith C. RanasingheUSENIX Security 2024 · 13 citations
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking SystemsShaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari et al.NDSS 2026 · 5 citations
- RouthSearch: Inferring PID Parameter Specification for Flight Control Program by Coordinate SearchSiao Wang, Zhen Dong, Hui Li, Liwei Shen et al.ISSTA 2025 · 1 citation
- RSFuzz: A Robustness-Guided Swarm Fuzzing Framework Based on Behavioral ConstraintsRuoyu Zhou, Zhiwei Zhang, Haocheng Han, Xiaodong Zhang et al.ASE 2025
- AidFuzzer: Adaptive Interrupt-Driven Firmware Fuzzing via Run-Time State RecognitionJianqiang Wang, Qinying Wang, Tobias Scharnowski, Li Shi et al.USENIX Security 2025
Builds on16
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
Related papers
- Drones' Cryptanalysis - Smashing Cryptography with a FlickerBen Nassi, Raz Ben-Netanel, Adi Shamir, Yuval EloviciS&P 2019 · 35 citations
- DronePrint: Acoustic Signatures for Open-set Drone Detection and Identification with Online DataHarini Kolamunna, Thilini Dahanayaka, Junye Li, Suranga Seneviratne et al.UbiComp 2021 · 51 citations
- SoK: Security and Privacy in the Age of Commercial DronesBen Nassi, Ron Bitton, Ryusuke Masuoka, Asaf Shabtai et al.S&P 2021 · 89 citations
- Wi-Fly?: Detecting Privacy Invasion Attacks by Consumer DronesSimon Birnbach, Richard Baker, Ivan MartinovicNDSS 2017 · 58 citations
- Paralyzing Drones via EMI Signal Injection on Sensory Communication ChannelsJoon-Ha Jang, ManGi Cho, Jaehoon Kim, Dongkwan Kim et al.NDSS 2023
