VLDB 2026 Research / reviewers in the wild / expert
Harshad Sathaye
dblp:241/1422
· DBLP profile ↗
8ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-6225-9769ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LEO-Range: Physical Layer Design for Secure Ranging with Low Earth Orbiting Satellites
Daniele Coppola, Arslan Mumtaz, Giovanni Camurati, Harshad Sathaye, Mridula Singh, Srdjan Capkun |
USENIX Security Symposium | 4 |
| 2025 | GNSS-WASP: GNSS Wide Area SPoofing
Christopher Tibaldo, Harshad Sathaye, Giovanni Camurati, Srdjan Capkun |
USENIX Security Symposium | 2 |
| 2023 | Location-independent GNSS Relay Attacks: A Lazy Attacker's Guide to Bypassing Navigation Message AuthenticationabstractIn this work, we demonstrate the possibility of spoofing a GNSS receiver to arbitrary locations without modifying the navigation messages. Due to increasing spoofing threats, Galileo and GPS are evaluating broadcast authentication techniques to validate the integrity of navigation messages. Prior work required an adversary to record the GNSS signals at the intended spoofed location and relay them to the victim receiver. Our attack demonstrates the ability of an adversary to receive signals close to the victim receiver and in real-time generate spoofing signals for an arbitrary location without modifying the navigation message contents. We exploit the essential common reception and transmission time method used to estimate pseudorange in GNSS receivers, thereby potentially rendering any cryptographic authentication useless. We build a proof-of-concept real-time spoofer capable of receiving authenticated GNSS signals and generating spoofing signals for any arbitrary location and motion without requiring any high-speed communication networks or modifying the message contents. Our evaluations show that it is possible to spoof a victim receiver to locations as far as 4000~km away from the actual location and with any dynamic motion path. This work further highlights the fundamental limitations in securing a broadcast signaling-based localization system even if all communications are cryptographically protected. Maryam Motallebighomi, Harshad Sathaye, Mridula Singh, Aanjhan Ranganathan |
WISEC | 2 |
| 2022 | On the Implications of Spoofing and Jamming Aviation Datalink ApplicationsabstractAviation datalink applications such as controller-pilot datalink communications (CPDLC) and automatic dependent surveillance-contract (ADS-C) were designed to supplement existing communication systems to accommodate increasing air traffic. These applications are typically used to provide departure clearance, en-route services such as altitude and flight plan changes, air traffic surveillance and reporting, and radio frequency assignments. Unlike most attacks proposed so far where the attacker influences decision-making through manipulated instruments, attacks on aviation datalink provide adversaries with a new attack vector to influence the flight crew’s decision-making through direct instructions. In this work, we perform a security analysis of these applications and outline the requirements for executing a successful attack. Specifically, we propose a coordinated multi-aircraft attack and show how an adversary capable of spoofing datalink messages and reactive jamming can influence the flight crew’s decision-making. Through geospatial analysis of historical flight data, we identify 48 vulnerable regions where an attacker has a 90% chance of encountering favorable conditions for coordinated multi-aircraft attacks. Next, we implement a reactive jammer that ensures stealthy attack execution by targeting messages from a specific aircraft with a reaction time of 1.48 ms and 98.85% jamming success. Even though by themselves these attacks have a lower probability of endangering the safety of the aircraft, the threat is magnified when combined with attacks on other avionics. Finally, we discuss the possibility of executing integrated attacks on aircraft system as a whole emphasizing the importance of securing individual components in the aviation ecosystem. Harshad Sathaye, Guevara Noubir, Aanjhan Ranganathan |
ACSAC | 1 |
| 2022 | SemperFi: Anti-spoofing GPS Receiver for UAVs
Harshad Sathaye, Gerald LaMountain, Pau Closas, Aanjhan Ranganathan |
NDSS | 1 |
| 2022 | An Experimental Study of GPS Spoofing and Takeover Attacks on UAVs
Harshad Sathaye, Martin Strohmeier, Vincent Lenders, Aanjhan Ranganathan |
USENIX Security Symposium | 1 |
| 2019 | Wireless Attacks on Aircraft Instrument Landing Systems
Harshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara Noubir |
USENIX Security Symposium | 1 |
| 2019 | Wireless attacks on aircraft landing systems: demoabstractModern aircraft heavily rely on several wireless technologies for communications, control, and navigation. In this work, we demonstrate the vulnerability of aircraft instrument landing systems to wireless attacks. We show that it is possible to fully and in finegrain control the course deviation indicator, as displayed by the ILS receiver, in real-time, and demonstrate it on aviation-grade ILS receivers. We develop a tightly-controlled closed-loop ILS spoofer that autonomously adjusts the adversary's transmitted signals based on the aircraft's GPS location to cause an undetected off-runway landing. We demonstrate the integrated attack on an FAA certified flight-simulator (X-Plane)'s AI-based auto-land feature and show success rate with offset touchdowns of 18 meters to over 50 meters. Harshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara Noubir |
WiSec | 1 |