Conceptio › Archive › arXiv CS
arXiv CSopen access

She Spoofed Sea Ships by the Sea Shore: Measuring Large-Scale GPS Spoofing in Global Maritime Traffic

Anna Raymaker et al. · arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

She Spoofed Sea Ships by the Sea Shore: Measuring Large-Scale GPS Spoofing in Global Maritime Traffic

Anna Raymaker, Ryan Von Brock, Ryan Pickren, Animesh Chhotaray, Frank Li, Saman Zonouz, Raheem Beyah

arXiv:2609.37676v1 [cs.CR] 29 Sep 2026

Georgia Institute of Technology

Abstract—GPS spoofing has emerged as a serious threat to maritime security, yet its global prevalence, persistence, and structure remain largely unmeasured. In this paper, we present the first large-scale measurement study of maritime GPS spoofing, using global Automatic Identification System (AIS) data, which contain the GPS coordinates broadcasted over time by ships across the world. We focus on large-scale regional spoofing, where external interference displaces many vessels across an area at once, leaving a recognizable signature of physically implausible motion correlated across ships; our motionaware, marine-specific framework identifies this signature and grades the evidence for GPS spoofing in each region it finds. Applying our approach to AIS data from over 367,000 vessels collected between late November 2024 and early February 2025, we identify 31 persistent anomalous hotspots across hightraffic maritime regions, at least 22 of which show strong evidence of GPS spoofing, with spatial and temporal structure aligning with regional conflict and economic sanctions. Notably, our method found that the spoofing activity in the Red Sea responsible for the highly-publicized grounding of the 75,000ton container ship, MSC Antonia, was ongoing months before the incident, which has not been previously documented. Similarly, we detected persistent spoofing in the Strait of Hormuz over a year before the 2026 Iran war brought commercial shipping through the Strait to near-standstill. Together, this work establishes GPS spoofing as a widespread, recurring, and measurable threat to global maritime navigation.

1. Introduction Maritime systems form an essential part of global infrastructure and play a central role in sustaining the world economy. Around 90% of global trade is transported by sea [1], and maritime operations also support critical services such as energy transport, logistics, and undersea communication infrastructure. The safety and efficiency of these systems depend on reliable satellite-based positioning and navigation, particularly the Global Positioning System (GPS). However, recent incidents demonstrate that interference with GPS signals can lead to navigational errors, operational disruptions, and physical damage to vessels [2], [3]. In fact, reports found that over 80% of marine casualties involved human or navigational factors in 2024, underscoring the stakes of degraded positioning [4]. A recent event, shown in

SAUDI ARABIA

SAUDI ARABIA

*Grounded here* SUDAN

SUDAN

Real Route

Spoofed Route

Figure 1. (Top) The MSC Antonia grounded in the Red Sea in May 2025 after a spoofing incident [5]. (Bottom) AIS comparison showing the vessel’s true route and grounding point (left) versus the spoofed route (right).

Figure 1, is the grounding of the 75,000-ton container ship MSC Antonia in the Red Sea, a major incident attributed to GPS spoofing [5]. The grounding immobilized the vessel for more than five weeks, incurring multi-million-dollar costs in salvage, recovery, and operational disruption [6], [7], [8]. Such incidents are becoming more common, with reports linking GPS interference to vessel groundings, collisions, and geopolitical tension [9], [10], [11], [12]. Interviews with professional mariners further indicate that GPS spoofing is a recurrent operational concern [13]. Although these findings confirm a growing threat, the overall scale and distribution of maritime GPS spoofing remain unclear. Prior research has extensively demonstrated GPS spoofing across automotive and aerial domains [14], [15], [16], [17], [18], and proposed detection and mitigation techniques in controlled settings [19], [20], [21]. However, these efforts do not measure spoofing prevalence or persistence at global scale, nor do they characterize spoofing using real-world

maritime traffic.

2. Background and Related Work

To address this gap, we present the first global measurement of large-scale maritime GPS spoofing using real-world vessel movement data. Our approach starts from a simple question: what would large-scale external GPS spoofing of a region look like in vessel movement data? Because such interference overpowers GPS across an area, it displaces the reported positions of many vessels at once rather than any single ship. This produces a recognizable signature: affected vessels report physically implausible motion, their displacements coincide in space and time, and they concentrate within the bounded region the source covers. These properties are invariants of regional external spoofing, holding regardless of the spoofer’s equipment or intent. Our framework is built to identify them: it flags physically implausible motion on each vessel using a Kalman-based motion model, finds where these anomalies correlate across independent vessels, and isolates the persistent regions into spoofing zones.

This section summarizes the technical background of AIS and GPS spoofing and reviews prior work to contextualize our global measurement study. AIS and Maritime Cybersecurity. AIS is a transponderbased communication protocol mandated by the International Maritime Organization (IMO) for vessels exceeding 300 gross tons and all passenger ships [23]. Each AIS message broadcasts a vessel’s identity (including its Maritime Mobile Service Identity, or MMSI) together with GPS-derived position, speed, course, and voyage data [24]. Because civilian GPS signals are typically unencrypted and unauthenticated, AIS-reported positions are inherently vulnerable to spoofing attacks [14], [25]. Prior work has shown that the maritime domain amplifies spoofing risks through insecure protocols and infrastructure, with demonstrated attacks against AIS [17], satellite terminals [18], marine communication stacks [26], and cyber-physical ship control systems [27]. Broader analyses emphasize the historically underexplored state of maritime cybersecurity [28]. More recently, several studies have leveraged AIS data to detect spoofing or falsified vessel behavior, including protocol-level validation, trajectory-based anomaly detection, and forensic or domain-specific analyses [29], [30], [31], [32]. While these efforts demonstrate that AIS can reveal spoofing, they remain localized or attack-specific, and do not provide a global measurement of spoofing prevalence or persistence. Our work fills this gap by systematically measuring maritime GPS spoofing at global scale using real-world AIS traffic. GPS Spoofing and Detection Techniques. GPS1 spoofing involves transmitting counterfeit satellite signals to manipulate a receiver’s perceived position or time [33], [34], [35]. Unlike jamming, spoofing preserves apparent functionality while providing false coordinates [36], [37]. In maritime settings, spoofing can induce kilometer-scale displacements or false convergence that violate physical motion constraints [38], [39], [40], in contrast to multipath interference, which typically produces meter-scale deviations [41], [42]. Extensive research has demonstrated GPS spoofing across automotive, aerial, and autonomous domains [14], [15], [16], [43], [44], [45], [46], [47], [48]. A wide range of detection and mitigation techniques have been proposed, including angle-of-arrival filtering [19], vision-based crosschecks [20], statistical anomaly detection [21], and specialized anti-spoofing receivers [49]. Crowd-GPS-Sec detects attacks using crowdsourced aircraft data [50], but requires dense multilateration coverage unavailable at sea. Complementary approaches include secure LEO-based ranging [51] and distributed spoofers that enhance stealth and range [52]. Collectively, these studies establish that GPS spoofing is technically feasible and operationally disruptive, yet none quantify its global prevalence or persistence in the maritime domain. Our work provides the first systematic, global measurement of maritime GPS spoofing by analyzing motion

We evaluate this framework on global AIS data from late November 2024 to early February 2025, identifying and clustering spoofing-like anomalies across more than 367,000 vessels worldwide. In total, the system identified over 17,000 anomalous episodes spanning 31,000 cumulative hours of physically implausible navigation. The resulting global map of 31 hotspots of anomalous GPS activity reveals both expected patterns in conflict-adjacent waters, such as the Black Sea and Eastern Mediterranean, and surprising anomalies in civilian zones, like the Gulf of Mexico and Canary Islands. The MSC Antonia grounding underscores the operational significance of these findings. Our framework identified the same spoofing pattern in the Red Sea near Sudan, at the identical location, five months earlier in January 2025. Similarly, we detected persistent spoofing in the Strait of Hormuz over a year before the 2026 Iran war drove widespread GPS interference across the Persian Gulf [22]. This recurrence indicates that both incidents were part of a longer-lived spoofing zone our system could have identified in advance. Together, these results show that systematic measurement can explain known incidents and reveal emerging patterns of maritime GPS interference. In summary, our contributions are as follows: The first global measurement of large-scale maritime GPS spoofing using real-world AIS data from over 367,000 vessels to quantify the prevalence, persistence, and geographic distribution of spoofing worldwide. • A motion-aware, marine-specific AIS anomaly analysis framework that enables reliable identification of spoofinglike behavior in noisy AIS data by combining physically grounded trajectory modeling, cross-vessel consensus, and spatial clustering. • An empirical characterization of 31 persistent anomalous hotspots, of which at least 22 show strong evidence of GPS spoofing, including regional case studies that reveal recurring spoofing patterns and their geopolitical context. •

1. Although the broader term GNSS encompasses multiple constellations, we use “GPS” generically since AIS does not specify the system.

anomalies across worldwide AIS traffic and aggregating them into persistent spoofing hotspots.

3. Methodology We first define our threat model (Section 3.1) and datasets (Section 3.2), then describe our pipeline whose two stages mirror the invariants of regional external spoofing introduced in Section 1. Stage 1 identifies the per-vessel invariant: using a Kalman-based motion model, we flag physically implausible motion in each vessel’s trajectory (Section 3.3). Stage 2 identifies the cross-vessel and spatial invariants: we cluster these anomalies by spatial and temporal overlap into persistent zones, separating interference that affects many vessels at once from irregularities that affect only one (Section 3.4). We then discuss the limitations of this design (Section 3.5) and validate the pipeline across global maritime traffic (Section 3.6).

3.1. Threat Model Our threat model is large-scale external GPS spoofing: many vessels’ reported positions are displaced at once, rather than any one ship. The adversary broadcasts a counterfeit GPS-like signal stronger than the authentic satellite transmissions at the receiver, causing a vessel’s navigation system to compute an erroneous position; the navigation system forwards this false fix to the AIS transponder, which broadcasts the spoofed coordinates to nearby ships and monitoring services (Figure 2). Because the source acts over a bounded area, it affects many vessels within its footprint simultaneously, inducing the kilometer-scale, regionally coherent displacements our measurement targets. This threat model is grounded in documented real-world operations: large-area spoofing affecting many vessels simultaneously has been reported in the Black Sea [39], [53], off the Chinese coast [54], [55], and recently in the Strait of Hormuz [22]. Outside this threat model are anomalies confined to a single vessel, whether from faulty transponders, recycled MMSI identifiers, or deliberate falsification of AIS messages while the onboard GPS computes correctly, which we term self-spoofing. Our pipeline separates these from external interference, since each affects one vessel rather than many across a region (Section 3.4); we examine self-spoofing further in Section 4.2.

3.2. Dataset Our study draws on three AIS datasets that share the same record structure, each providing per-vessel timestamps, position, speed, course, heading, identity, and operational status. Because no public AIS feed offers global coverage, we center our measurement on a global commercial feed from Spire Global and draw on two public regional feeds, from NOAA and the Danish Maritime Authority, that span U.S. and European waters [56], [57]. Spire collects AIS data from low-Earth orbit satellites, providing near-real-time global coverage used operationally

Stronger Signal

GPS Spoofing

GPS

Nav Equip Broadcast

AIS Trans.

Nearby Ships Spoofed Position

Figure 2. Maritime GPS spoofing threat model. A nearby terrestrial or airborne transmitter overrides genuine GPS signals with a stronger counterfeit, causing the vessel’s navigation system to compute a false position that the AIS transponder broadcasts to nearby ships.

by national authorities and governments [58], [59]. Its feed spans late November 2024 to early February 2025 and integrates both satellite and ground-based reception, giving comprehensive global coverage and precise timestamp alignment with minimal reporting gaps. Over this period it comprises 379,416 unique vessels, of which 125,569 appeared in both December and January. Importantly, the data captures where vessels report themselves to be rather than their independently verified locations, making it well suited to analyzing positional inconsistencies and identifying spoofing-consistent behavior. The two public feeds are regional but comparable to Spire in format and fidelity. Running our pipeline on them reproduces our findings in both the U.S. and Europe from open data alone, confirming that the results do not depend on any single source and supporting independent verification.

3.3. Stage 1: Per-Vessel Anomaly Analysis This stage analyzes each vessel in isolation. We treat each vessel identifier (MMSI) as a single vessel and flag motion that violates physical or environmental plausibility, such as abrupt jumps, implausible speeds, or movement over land. At this stage, we do not attribute a cause: a flagged trajectory may reflect external interference, deliberate selfspoofing, or a faulty transponder. Stage 2 (Section 3.4) distinguishes these by testing whether the same anomaly appears across many vessels at once. As shown in Figure 3, the per-ship anomalyidentification pipeline proceeds through six steps: ( 1 ) input AIS parsing, ( 2 ) cleaning, ( 3 ) Kalman prediction, ( 4 ) violation checks, ( 5 ) finite-state grouping, and ( 6 ) output generation. These stages transform raw AIS tracks into temporally coherent anomaly episodes characterized

For Every AIS Point No 11. Input AIS Route

33. Kalman Prediction (Predict Next Point)

55. FSM: If Else Block Violations = 0

space and corrects it with the new AIS reading, subject to measurement noise vt . Model equations. The resulting linear system is:

[Update] CurrState = IDLE CurrState = IDLE and (Violations > 0 and < MV in RW)

22. Cleaning

44. Violation Check

a. Remove Duplicate Timestamps b. Sort Timestamps c. Remove Stationary (docked) Vessels

a. Land? b. Speed > 60 knots? c. Deviation > 5km?

Yes

[Update] CurrState = CONFIRMED

[State] Violations = 0

[Update] Violations += 1

CurrState = CONFIRMED and CGE in clean minutes

[Update] CurrState = CANDIDATE CurrState = CANDIDATE and Violations >=MV in RW

[Update] CurrState = IDLE [Update] Violations = 0

66. Output Anomaly Segment

Figure 3. Overview of the per-ship anomaly-identification stage MV = Minimum violations; RW = Rolling window; CGE = Clean gap end

by physically implausible motion or location patterns. The following subsections describe each component in detail. 1 - 2 Input AIS Route and Cleaning. Each vessel’s raw AIS data is parsed into timestamp-ordered trajectories containing latitude, longitude, speed, and course fields. We sort entries by time and deduplicate reports that share the same timestamp and position. Finally, vessels that remain stationary within a 0.5 km radius are discarded, filtering out AIS base stations and permanently moored transmitters while tolerating minor GPS jitter. 3 Kalman Prediction. To estimate intermediate vessel positions and suppress measurement noise, we employ a linear Kalman filter2 for trajectory state estimation. The filter alternates between a prediction step (propagating a motion model forward) and an update step (correcting with new AIS observations), optimally weighting model dynamics and sensor reliability under Gaussian noise assumptions [63]. Given the reporting cadence of AIS transmissions, which ranges from 2 seconds to 3 minutes depending on vessel class and speed [64], we adopt a constant-velocity motion model that assumes each vessel maintains its speed and heading between updates. Because ships exhibit high inertia and rarely undergo abrupt acceleration or deceleration, this assumption provides a realistic short-term approximation of vessel motion. Process and measurement noise covariances were set to 10−5 and 10−4 , respectively, corresponding to roughly kilometer-scale GPS uncertainty, so the filter tracks smooth motion yet remains responsive to course changes. In the vessel’s state vector xt =  the Kalman formulation, ⊤ encodes latitude (ϕt ), longitude (λt ), ϕt λt ϕ̇t λ̇t and their time derivatives  (velocity ⊤ components). The measurement vector zt = ϕt λt contains the observed AIS positions. During the prediction step, the state-transition matrix F(∆t) advances the previous position forward in time using ∆t (in hours), while process noise wt models unobserved accelerations. In the update step, the measurement matrix H projects the predicted state to observation 2. Kalman filters are widely used in navigation and sensor fusion, including satellite positioning and real-time tracking [60], [61], [62].

xt+∆t = F(∆t) xt + wt ,   1 0 ∆t 0 0 1 0 ∆t , F(∆t) =  0 0 1 0 0 0 0 1

zt = H x t + v t ,  1 H= 0

0 1

0 0

(1)  0 , 0

(2) with wt ∼ N (0, Q) and vt ∼ N (0, R). Longitude differences are normalized to the principal branch to handle ±180◦ wrap. − At each update, the predicted position (ϕ̂− t , λ̂t ) is compared with the new AIS observation (ϕt , λt ) to compute a − geodesic residual et = dhav ϕ̂− t , λ̂t ; ϕt , λt , where dhav is the Haversine great-circle distance between two latitudelongitude coordinates: λ2 − λ1 ϕ2 − ϕ 1 + cos ϕ1 cos ϕ2 sin2 , 2 √  2 dhav (ϕ1 , λ1 ; ϕ2 , λ2 ) = 2R⊕ arcsin a a := sin2

(3)

where R⊕ = 6371 km is the Earth’s mean radius. This formulation avoids distortions introduced by planar projections and ensures that deviation thresholds (e.g., 5 km) correspond to true geodesic distances globally [65], [66]. A deviation violation is triggered when et > 5 km, indicating that the vessel’s reported position departs significantly from its predicted path. Because estimation error accumulates rapidly with sparse updates, the filter is re-initialized whenever two consecutive AIS messages are separated by more than seven minutes. As shown in Figure 18 in the appendix, over 92% of timestamp gaps in our dataset are shorter than this threshold, making seven minutes a natural empirical cutoff that balances continuity with stability. 4 Violation Checks. Each cleaned trajectory is analyzed at minute-level granularity using three violation checks: (1) Land points, locations outside a coastal-water buffer using the Global Surface Water Occurrence dataset with a 1 km buffer to avoid overflagging near coastlines [67], [68]; (2) Deviation points, positions whose Kalman-predicted and reported locations differ by more than 5 km, indicating motion inconsistent with realistic vessel dynamics; and (3) Speed violations, instantaneous velocities above 60 knots (kn). We enforce physical feasibility constraints using empirically validated thresholds. For speed, typical large commercial vessels operate well below 30 kn in service, with design speeds around 19-25 kn for common container-ship classes [69], and fast patrol craft commonly reach sprint speeds in the 35-45 kn range [70], [71], [72]; we therefore conservatively set 60 kn as an upper bound for physically plausible movement. For the deviation check, the 5 km cutoff was derived from the dataset-wide distribution of Kalman residuals (Figure 17 in the appendix). Before filtering, 98.5% of residuals fall below 5 km, yet 36.1% of vessels exhibit at least one extreme outlier above this limit (5-10 km:

18.4%; 10-20 km: 5.9%; 20-50 km: 2.6%; >50 km: 9.2%). After removing physically implausible points, those with on-land positions or speeds exceeding 60 kn, the remaining clean dataset shows only 0.3% of residuals above 5 km; thus, 5 km separates normal positional noise from rare, large deviations that persist even after conservative filtering. We deliberately avoid a smaller cutoff (e.g., 1-2 km) because benign GPS and AIS timing errors, coastal multipath reflections, reporting jitter, and ionospheric disturbances during geomagnetic storms can reach hundreds of meters [41], [42], [73]; a tighter threshold would increase false positives without improving sensitivity to spoofing. 5 Temporal Grouping via Finite-State Machine (FSM). To aggregate point-level anomalies into temporally coherent anomaly episodes, we employ an FSM that enforces persistence and recovery rules. The FSM operates on minutebinned AIS data and formalizes episode identification using three parameters: Minimum Violations (M V ), a Rolling Window (RW ), and a Clean Gap End (CGE ); see Figure 3. Each minute is labeled anomalous if any of its AIS points trigger a land, speed, or deviation violation. We then slide a 30-minute rolling window (RW ) across time and compute the ratio rt = ARW /NRW , where ARW is the number of anomalous points and NRW is the total points in that window. A minimum violation threshold (M V ) is defined as MV = ⌈0.70 × NRW ⌉, requiring at least 70% of points in a full 30-minute window to be anomalous before confirming an episode. This conservative cutoff was selected from the dataset-wide window-ratio distribution, where fewer than 10% of all 30-minute windows exceed the 70% mark. As shown in Figure 20 in the appendix, the curve flattens well below this level, making 70% a deliberately strict threshold that minimizes false positives while still capturing clear, persistent spoofing. State Logic. The FSM progresses through three phases that capture the temporal structure of spoofing activity: • IDLE: The default monitoring phase in which no sustained anomalies are present. For each new minute, the rolling window is updated. If a few anomalies appear (0 < ARW < MV), the FSM transitions into the CANDIDATE state to monitor whether the anomalies persist or not. • CANDIDATE: A provisional phase that is triggered when anomalies begin to accumulate but remain below the threshold. If the quorum condition (rt ≥ 0.70 in a fully covered 30-minute window) is reached, the FSM escalates to an ACTIVE state; otherwise, if anomalies subside before this threshold is met, it returns to IDLE. • ACTIVE: A confirmed anomaly episode, which persists until a clean streak of 120 consecutive minutes (CGE ) with no anomalies occurs, marking recovery and returning the FSM to IDLE. This temporal logic encoded in the FSM ensures that transient spikes or isolated errors do not trigger false positives. Short-lived or low-density anomaly bursts remain contained within the CANDIDATE phase and naturally expire, whereas persistent, high-density anomalies satisfy both the M V (≥ 70% in 30 min) and CGE (120 clean min)

11. Input anomaly segments

22. Preprocessing a. Extract last clean point before and first clean point after each anomaly segment b. Handle edge cases (only one boundary point available)

33. Find hotspots with clustering 3a. Connect and Analyze Jumps: Draw lines between boundaries to identify jump patterns and intersections

3b. Cluster Anomaly Origins: Group intersection zones into regional anomaly clusters

44. Filter and Stabilize

55. Generate Outputs

a. Drop isolated/selfspoofers b. Remove outlier ships c. Keep persistent zones

a. Map of boundary points and connections b. Cluster timelines and region summaries c. List of self-spoofers

Figure 4. Overview of anomaly-zone clustering/attribution stage.

criteria before being confirmed. The 120-minute clean-gap threshold was chosen empirically: 61.5% of inter-event gaps occur within two hours, after which the distribution drops sharply (Figure 19 in the appendix). This cutoff provides a conservative recovery window that separates consecutive anomaly events without merging unrelated ones. The Startby-Quorum / End-by-Consecutive formulation provides temporal stability in high-noise AIS environments. The four parameters governing this stage are derived from the observed data distributions; we test their influence on our findings in Section 3.6. 6 Outputs. Each ACTIVE period yields a single episode record with start and end timestamps, duration, anomalytype histograms, and geometric deviations between observed and Kalman-predicted paths. Episodes shorter than 30 minutes or containing fewer than one AIS sample are discarded. The resulting set of per-vessel anomaly segments forms the baseline input for the subsequent cluster-level analysis.

3.4. Stage 2: Anomaly-Zone Clustering This stage aggregates anomaly segments from Stage 1 to identify regional patterns and probable interference origins. It transitions from vessel-level analysis to multi-vessel inference, combining spatial geometry, temporal overlap, and density-based clustering to reveal persistent anomaly zones. 1 Input Anomaly Segments. All anomaly segments extracted in Stage 1 serve as inputs to this stage. Each segment captures a temporally bounded interval of physically implausible motion, including start and end timestamps, vessel identifiers, and segment geometry. 2 Preprocessing. For every anomaly segment, we extract the last clean AIS point preceding the episode and the first clean point following it. These boundary points delineate the apparent entry and exit of anomalous motion, effectively the “jump endpoints” of the anomalous movement. When only one boundary is available (e.g., truncated or missing trajectories), it is retained as a single-ended edge to preserve partial spatial information.

3 Jump-Line Construction and Clustering. This step connects vessel-level anomaly episodes into shared regional patterns using a two-part process. First, each episode’s boundary points are connected to form a “jump line” representing the vessel’s apparent displacement during the anomaly episode. Spatial intersections among multiple jump lines mark candidate regions where independent vessels exhibit correlated anomalous behavior, an indicator of common false coordinates. This helps us connect per-vessel anomaly events to group-level patterns. Next, we apply DBSCAN to cluster nearby intersections into potential anomaly zones [74], [75]. This nonparametric algorithm groups points that lie within a fixed spatial neighborhood of each other, forming clusters when at least a minimum number of nearby intersections (MinPts) occur within a radius ε. Here, each point corresponds to the intersection of jump lines (latitude-longitude coordinates). We set ε = 50 km and MinPts = 5. The relevant spatial scale for ε is the footprint of an interfering emitter: for plausible emitter and vessel antenna heights, the radio horizon spans roughly 30-65 km, placing 50 km mid-range. Airborne emitters have wider footprints, so this choice fragments a single footprint across clusters instead of merging distinct sources. For MinPts, prior work [74], [75] reports 4 as a standard default for twodimensional data, and larger values are recommended for very large or noisy datasets [75]; we set 5 on that basis. We do not rely on these arguments alone: sweeping ε from 25 to 100 km recovers the same geographic regions throughout, with the clustering unchanged from 50 to 100 km and some regions subdividing into multiple clusters below 50 km, while sweeping MinPts from 3 to 5 leaves the recovered regions unchanged. Our results are therefore not sensitive to the choice of ε or MinPts. 4 Filter and Stabilize. To retain only the meaningful and persistent anomaly zones identified in the previous step, we apply three stabilization filters. First, vessels that never share spatial or temporal overlap with others are excluded as self-spoofers or individual reporting faults. Second, we remove spatial outliers whose anomalous locations lie more than three times the mean intra-cluster distance from the centroid, a standard outlier-rejection heuristic that filters detached points without fragmenting dense clusters. On average, clusters contained only 1% of such outliers, arising when jump lines from unrelated vessels overlapped in the same region, causing DBSCAN to group them despite representing distinct anomaly incidents. Finally, clusters that recur consistently across multiple time windows are merged and marked as persistent zones, indicating stable or repeated anomaly activity in that region. 5 Generate Outputs and Attribution Labels. Building on the filtered anomaly zones from the previous step, we assign vessel-level classification labels to distinguish coordinated anomalies from isolated or faulty transmissions. Each vessel receives one of two primary classification labels. Vessels whose anomalous segments coincide spatially and temporally with others inside a persistent cluster are labeled cluster-associated, reflecting potential coordinated

or externally induced spoofing. Episodes occurring alone, outside any cluster, are labeled self-spoofed or faulty. We further subdivide the self-spoofed/faulty category to distinguish between likely MMSI reusers and genuinely malfunctioning transmitters. Specifically, vessels that retain the same MMSI but change associated metadata such as name, callsign, or flag are classified as probable MMSI reusers, suggesting recycled identifiers across different ships. In contrast, vessels with stable identifiers yet unusually high flag rates are labeled as faulty transmitters, indicative of persistent AIS hardware or reporting errors. The final outputs include maps linking anomaly-segment boundaries, temporal cluster timelines, and a list of self-spoofers.

3.5. Limitations Our framework targets large-scale regional spoofing and may miss stealthy interference that evolves within plausible bounds. Concretely, four classes of activity fall outside detection by construction: displacements smaller than the 5 km deviation threshold, episodes shorter than the 30 min candidate window, windows in which fewer than 70% of points are anomalous, and interference affecting only a single vessel, which Stage 2 excludes as self-spoofing or a reporting fault. Each of these bounds removes activity rather than adding it. Our measurements therefore represent a lower bound on global spoofing activity. Our time window also cannot capture seasonal or longer-term trends. AIS reports the position a vessel’s receiver computed, not the signal it received, so we cannot localize transmitters, attribute interference to specific actors, or observe the spoofing-system implementation and signal-generation mechanism. Our geopolitical context and attacker objectives (Section 4.2), such as air-defense spillover near Gaza, are therefore inferred as hypotheses, and confirming them requires RF measurement or operator accounts.

3.6. Validation Because no onboard ground truth exists for maritime GPS spoofing at scale, we validate our findings through complementary checks: ruling out alternative causes of AIS anomalies, testing the sensitivity of our results to the detection parameters, testing for over-flagging in dense traffic, distinguishing external interference from self-spoofing, and corroborating identified zones against documented incidents. Filtering Out Alternative Root Causes. Several phenomena besides external spoofing can produce anomalous AIS positions. Each must arise somewhere along the path a position report travels: satellite signals propagate to the vessel, the GPS receiver computes a fix from them, the AIS transponder broadcasts that fix under a vessel identity, and our data sources aggregate the reports. Our pipeline excludes the alternatives at every stage. Along the signal path, ionospheric disturbances during even severe geomagnetic storms degrade GPS accuracy on the order of tens of meters [73], and multipath and jitter at the receiver cause deviations of at most a few hundred meters [41], [42]; both fall two orders

TABLE 1. A LTERNATIVE EXPLANATIONS EXCLUDED AT EACH STAGE OF THE PATH A POSITION REPORT TRAVELS , FROM SATELLITE SIGNAL TO AGGREGATED DATASET. T HESE CHECKS APPLY UNIFORMLY ACROSS ALL 31 ANOMALY ZONES BEFORE TIER ASSIGNMENT. Alternative

Pipeline Exclusion Mechanism

SIGNAL PATH

Space-weather effects GPS jamming

Tens-of-meter errors, far below 5 km threshold (Section 3.3) Causes loss of fix and reporting gaps, not coherent false tracks (Section 2)

GPS RECEIVER

Multipath / jitter Isolated receiver errors Persistent receiver errors

Hundreds-of-meter errors, below 5 km threshold (Section 3.3) FSM persistence: 70% anomalous over 30 min + 120 min recovery (Section 3.3) Affects one vessel only, excluded by cross-vessel clustering (Section 3.4)

AIS TRANSPONDER

Faulty transmitters MMSI reuse Single-vessel self-spoofing

High anomaly rate with consistent metadata (Section 3.4) Metadata consistency classification (Section 3.4) Affects one vessel only, excluded by cross-vessel clustering (Section 3.4)

AGGREGATE DATA

Coordinated self-spoofing Over-flagging traffic

Vessel diversity: median 30 flag states, 5 ship types per cluster (Table 8) in dense Validation across 22 ports with no reported spoofing (Table 9)

of magnitude below our 5 km deviation threshold. Jamming, the other deliberate form of signal interference, produces loss of fix and reporting gaps rather than coherent false tracks (Section 2). Isolated receiver errors are removed by the FSM persistence requirement (Section 3.3). Persistent receiver errors affect only a single vessel and are excluded by the cross-vessel clustering requirement, alongside selfspoofing (Section 3.4). At the AIS transponder, faulty hardware and reused MMSI identities are separated by metadataconsistency checks (Section 3.4). At the aggregation stage, over-flagging in dense traffic and coordinated self-spoofing across many vessels are tested directly later in this section. Table 1 summarizes each alternative and their exclusion. Validation in Dense Maritime Traffic. To evaluate robustness under dense vessel activity and potential GPS multipath interference, we analyzed AIS traffic in 22 of the world’s busiest commercial ports (Table 9 in the appendix) [76], [77]. Across all ports, none of which have reported spoofing, the median fraction of vessels flagged by our pipeline is below 0.1%, and no port exceeds 1%. High-traffic hubs such as Los Angeles, Rotterdam, and Singapore exhibit similarly low rates, indicating that vessels operating in dense maritime environments are not systematically misclassified. We further find that the small number of residual false positives are primarily attributable to AIS artifacts such as MMSI reuse or faulty transmitters, rather than algorithmic errors (see Appendix B for more analysis). External vs. Self-spoofing Validation. To assess whether identified clusters could plausibly arise from coordinated

self-spoofing, we examine vessel diversity and pattern consistency within each cluster. Across clusters, flagged vessels span a wide range of flag states and ship types, with a median of 30 distinct flag states and 5 vessel classes per cluster, making coordinated self-spoofing unlikely given the need for independent operators across jurisdictions and vessel types to deploy similar behavior simultaneously (Table 8). Moreover, vessels within each cluster exhibit a shared spoofing-like geometry, with a median of 72% of vessels per cluster following the same displacement pattern despite this operational diversity. We note that one cluster is dominated by a single flag state, which is expected given its location in inland China; however, this cluster still spans multiple vessel types and has consistent spoofing-like geometry, supporting external-interference instead of coordinated self-spoofing. Parameter Sensitivity. Four Stage-1 parameters are derived from the observed data distributions (Section 3.3). To test whether our findings depend on those choices, we ran a parameter sweep, varying each independently over a wide range. Recovery is measured geographically. A zone counts as recovered if a cluster from the swept setting falls within 100 km of its baseline center, twice the clustering radius, with each cluster matched to at most one zone. The criterion is insensitive to whether a zone subdivides or merges. Some zones also lie close enough that one cluster may cover several, so we additionally group the 31 zones into the 17 geographic regions they occupy, such as the Black Sea or the Gulf of Mexico, and report how many regions are recovered. The deviation threshold, the parameter most directly tied to our detection criterion, has no effect: all 31 zones are recovered at every value from 2 to 10 km, even though the underlying episode count varies by a third across that range. Across the 20 parameter configurations tested, all 17 geographic regions are recovered in 13 of those configurations, with the full 30-360 min CGE range and the 50-70% MV range leaving the identified regions unchanged. Losses are confined to the smallest zones: outside the two most aggressive settings (MV = 90%, reset = 3 min), every zone that drops out has 12 or fewer vessels, while every zone with more than 12 vessels is recovered in every configuration. Detection therefore degrades as vessel traffic decreases. Appendix B reports the full parameter sweep. Corroboration Against Documented Incidents. Finally, we cross-reference identified zones against independent incident reports and conflict timelines. As detailed in Section 4.1.4, 13 of 31 zones align with externally documented spoofing, providing ground-truth-adjacent confirmation that the pipeline recovers real interference.

4. Results Below, Section 4.1 quantifies the global scope and structure of anomaly activity and grades the spoofing inference for each zone, while Section 4.2 interprets these patterns through regional case studies that connect identified hotspots to real-world events, including conflict-linked interference along the Gaza coast and the Red Sea pattern preceding the MSC Antonia grounding.

TABLE 2. D ISTRIBUTION OF ANOMALY EPISODE DURATIONS (ED*) AND NUMBER OF ANOMALY EPISODES PER VESSEL (E P V ⋄ ). ED*

Count

%

EpV⋄

<60 min 1–2 h 2–4 h 4–8 h 8–24 h >24 h

12,702 2,468 1,372 812 514 68

70.8 13.8 7.6 4.5 2.9 0.4

1 2 3–4 5–9 10–19 ≥20

Count

%

1,439 303 249 261 198 213

54.0 11.4 9.4 9.8 7.4 8.0

United States United States of America of America

Mexico Mexico

10

23 Caribbean Caribbean Sea Sea

Gulf Gulf ofof Mexico Mexico

Panama Panama

Columbia Columbia

Figure 6. Global anomaly hotspots across the Americas.

5

15 27 0

Europe Europe

24 28

Russia Russia

6

Africa Africa

2 21

China China

20

17

26 30

11

29

7

18

16

9

13

8

TABLE 3. R EGIONAL SUMMARY OF ANOMALY HOTSPOTS .

22

12 4

19

14

3

25 1 South South Philippines Philippines China Sea China Sea

Figure 5. Global anomaly hotspots across Afro-Eurasia.

Region

Cluster IDs

Black Sea Eastern Mediterranean & Red Sea North Sea & Baltic East Asia Seas China Inland Rivers Russia Inland Rivers Caspian Sea Atlantic Corridors Gulf of Mexico & Panama Corridor Strait of Hormuz

2, 6, 9, 13 7, 11 0, 4, 12, 15, 24 1, 3, 5, 14, 19, 25 16, 17, 18, 26, 30 21, 22 20 8, 27, 28 10, 23 29

4.1. Identification and Characterization Applying our vessel-level anomaly analysis (Section 3.3) to the late November 2024-early February 2025 global AIS dataset produced 17,936 anomaly episodes across 2,663 distinct vessels, totaling 31,328 hours of anomalous operation. Most episodes arose from deviation (52%) or speed (45%) violations, while only 3% involved physically impossible land positions. Deviation anomalies correspond to vessels whose reported positions deviated by more than 5 km from their Kalman-predicted trajectories, whereas speed anomalies reflect instances where instantaneous velocity exceeded 60 knots, surpassing the physically plausible range for vessels. Recall that we define an anomaly episode as any interval in which at least 70% of reported positions within a 30-minute window violate one or more anomaly constraints, a conservative criterion later used for clustering. As summarized in Table 2, anomaly events were typically short-lived: 71% lasted less than 60 minutes with a median duration of 40 minutes. A small number, however, persisted for many hours, potentially indicating sustained or repeated interference. Per-vessel frequency was similarly skewed: 54% of flagged ships experienced only one episode, whereas roughly 8% exhibited twenty or more. These longtail cases suggest recurrent exposure within stable interference zones or deliberate transponder manipulation. 4.1.1. Maritime Anomaly Hotspots. We next move from ships to space: aggregating anomaly episodes across vessels and time to locate global hotspots. Using the clustering framework described in Section 3.4, we identify 31 persistent anomaly zones (Clusters 0-30) detected across more than two months of AIS traffic. Their regional distribution

is summarized in Table 3; the full ID-to-area map with coordinates is shown in Table 10 in the appendix. Each cluster aggregates multiple independent vessels exhibiting spatially and temporally correlated spoofing-like motion. To ensure robustness under varying analysis thresholds, we evaluate each cluster under two complementary thresholds: a lower bound, which captures high-confidence anomaly episodes, and an upper bound, which estimates the total potential exposure. The lower bound requires at least 30 minutes with ≥70% anomalous points before confirming an anomaly. The upper bound includes any point violating the 60 knots speed, 5km kalman filter deviation, or on-land position constraints. Together, these bracket the plausible range of interference activity observed. Figures 5 and 6 illustrate the global distribution of anomaly clusters visually, grouped into Afro-Eurasian and Pan-American regions. Most zones appear in geopolitically sensitive areas such as the Black Sea, Eastern Mediterranean, and South China Sea, aligning with regions previously linked to GPS interference and electronic warfare activity [53], [54], [55]. In contrast, several unexpected clusters emerged in civilian or low-risk regions, including the Canary Islands and Gulf of Mexico, where no prior public reporting of GPS spoofing exists. At their monthly peaks, the Canary Islands cluster affected 7 vessels under lower-bound criteria and 403 under the upper bound, while the Gulf of Mexico cluster affected 13 and 1,196 vessels, respectively. Both this event and the Baltic cluster near Copenhagen (Cluster 12) were independently reproduced on public NOAA and Danish AIS data (Section 3.2), recovering the same patterns from open sources. These are the only clusters with sufficient coverage in the public feeds;

이

+

8 이

이

이

이

o

이

o

Russia

0 이

Krasnaya

Polyana

Ο

Sochi

이

이

Black Sea 이 Ο

Georgia 8

O

Figure 7. Circular loops in the Black Sea region, showing multiple vessels exhibiting spoofing-like trajectories. Gagra

이

+

Leaflet |OpenStreetMap contributors © CARTO

00000000000

0

000000 00

0

Port Sudan

PORTS

Red Sea

이 AWAKIN

Figure 8. Linear displacements in the Red Sea, showing the same lines that the MSC Antonia Exhibited before grounding. Leaflet |

OpenStreetMap contributors

CARTO

coverage is too sparse for any other nearby clusters (e.g., Cluster 24), underscoring the need for Spire’s global feed as our primary source. Across all 31 clusters from Spire’s feed, median flagged-vessel counts ranged from 22 to 1,852, spanning small transient events to large sustained zones. 4.1.2. Recurring Geometric Signatures. Having mapped where anomaly hotspots occur globally, we next examine how they manifest spatially within each region. The flagged vessel trajectories reveal distinct geometric patterns that characterize different modes of interference. In both prior incident reports and our manual review of thousands of flagged trajectories, four recurring forms: circular, linear, convergent, and irregular, consistently appeared as the dominant modes of distortion [53], [54], [55], [78], [79], [80]. These patterns capture recognizable ways in which spoofing alters reported motion, whether holding a vessel at a false point, shifting it along a line, or scattering it erratically, and can be systematically identified from AIS geometry. This list is not intended to be comprehensive; rather, it reflects the geometries documented across incident reports and observed in our dataset. Together, they reveal different operational behaviors of interference, from how easily activity can be detected in open-source data to whether ships were the intended targets at all. Additionally, the feasibility of producing these patterns is established by documented real-world incidents: the same circular and linear geometries we observe have been independently confirmed as deliberate spoofing in the Black Sea, China, and the Strait of Hormuz [22], [53], [55]. 1. Circular loops. Vessels appeared to travel in near-perfect

circles, maintaining stable speed and course values while their reported positions rotated around a fixed point. We classified a cluster as circular when at least one vessel’s anomalous positions could be fitted to a circle with a radius between 0.2 km and 50 km, covering at least 180° of arc, and with ≥70% of points lying close to that circle (mean radial deviation ≤300 m or ≤5% of the radius). This behavior was most prominent in the Black Sea and the East China Sea/Chinese-coast regions, aligning with prior reports of “crop-circle” GPS spoofing in China and Russia [53], [55]. Circular trajectories are the most visually recognizable spoofing signature; they stand out clearly in vessel tracks and online mapping platforms, making detection easier for both analysts and casual observers [81]. The recurrence of these patterns in Russian and Chinese conflict-adjacent zones has given them a reputation as a hallmark of largescale, state-linked interference [53], [54]. Their precision and frequency across many vessels suggest a persistent, coherent interference field rather than isolated noise [43]. 2. Linear displacements. Vessels abruptly jumped from their true locations onto perfectly straight, uniform trajectories that extended for tens of kilometers before snapping back to their real positions. We classified these as linear when the anomalous positions aligned along a straight path ≥10 km in length with ≥75% of points close to the line (orthogonal deviation ≤250 m). The MSC Antonia incident (Figure 1) exemplifies this pattern, where the vessel’s AIS track shifted onto a fixed-bearing line before grounding in the Red Sea. The defining feature of this pattern is its geometric regularity: straight, constant-bearing tracks that extend for tens of kilometers, a form of movement that is highly unnatural for real vessels and reflects deliberate falsification instead of noise [14], [43]. 3. Point convergence. In one region, multiple vessels simultaneously “teleported” to the same small inland area near Jordan’s Queen Alia Airport before returning to their true maritime positions. We classify a pattern as convergence when a compact area of radius ≤300 m contains at least 25% of anomalous points from ≥5 vessels. Such collective displacement reflects broad-area interference affecting many receivers at once. Because the spoofed position is stationary and clearly impossible for ships, appearing on land at an airport, mariners would immediately recognize it as erroneous, indicating that vessels may be collateral recipients of interference directed at other systems. This behavior matches reports of regional anti-drone and airdefense GPS disruption [80], which pulls nearby receivers toward a single false fix. 4. Irregular displacements. Some vessels exhibited scattered jumps or drifts within a confined area without forming stable geometric patterns. Clusters that failed the above criteria were labeled irregular, consistent with low-power or intermittent spoofing where false signals sporadically overpower authentic satellite reception [43]. Although less structured, these patterns are analytically significant: irregular trajectories are hardest to distinguish from benign anomalies such as AIS/GPS dropouts, MMSI reuse, or multipath reflections. Their presence underscores the need for cross-

Clusters (IDs)

Circular loops Linear displacements

0, 1, 2, 6, 7, 14, 16, 20, 21, 22, 25 3, 5, 8, 10, 12, 13, 17, 18, 19, 23, 24, 26, 29, 30 11 4, 9, 15, 27, 28

Point convergence Irregular displacements

modal validation (e.g., speed consistency and cross-vessel timing) when inferring spoofing from open-source data. Figures 7 and 8 illustrate representative examples of the first two categories, (1) circular loops and (2) linear displacements, captured from the Black Sea and Red Sea, respectively. Together, these patterns demonstrate that anomalies are not uniform in manifestation: some zones maintain stable false coordinates for hours or even days, while others produce sporadic or partial positional distortions. Table 4 summarizes the dominant geometric pattern across all clusters. Linear displacements were the most prevalent, appearing in 14 of 31 clusters, while circular loops were observed in roughly one-third. This prevalence suggests that many interference sources generate simple, fixed-direction offsets that vessels interpret as straight-line motion, while a smaller subset produce stable circular trajectories that dominate receiver solutions for extended periods. Only one cluster (11, near Israel) exhibited a pointconvergence pattern, which may be consistent with spillover from localized anti-drone or air-defense interference, and five clusters showed irregular trajectories indicative of weak or intermittent spoofing. Taken together, these four geometries capture the main operational “shapes” of anomalous motion we observe in AIS data. 4.1.3. Temporal Persistence Patterns. Having characterized anomalous geometries, we next examine where and when these anomalies occur globally. Building on the 31 anomaly hotspots previously identified, we analyze how activity within these clusters evolves over time. Each zone represents a region where multiple vessels showed correlated spoofing-like motion over overlapping intervals. Anomaly zones exhibit diverse temporal dynamics: some operate continuously for days, others reappear in bursts, and some vanish after brief episodes. For each cluster, we generated a one-minute-resolution time series representing the number of flagged vessels active at each point in time. This was computed by merging all overlapping anomalous intervals across ships within the same cluster, so that any period when multiple vessels experienced simultaneous anomalies appears as a single continuous interval. Figure 9 illustrates the four temporal signatures observed across clusters: 1. Sustained. Clusters were labeled as sustained when vessel anomalous activity remained continuously elevated for at least seven consecutive days, with daily flagged vessel counts varying by no more than 10%. This criterion captures long-duration interference zones characterized by stable intensity over time (Figure 9, Cluster 2).

316/8k Cluster 2 237/6k 158/4k 79/2k 0/0 13/1k Cluster 10 9.8/897 6.5/598 3.2/299 0/0

Lower Bound

Upper Bound

Cluster 3

Cluster 11

11/30 12/07 12/14 12/21 12/28 01/04 01/11 01/18 01/25 02/01 11/30 12/07 12/14 12/21 12/28 01/04 01/11 01/18 01/25 02/01

Geometric Pattern

Lower/Upper Bound Ship Count

TABLE 4. C LUSTERS GROUPED BY DOMINANT GEOMETRIC PATTERN , DERIVED FROM VESSEL TRAJECTORIES .

Date

6/1k 4.5/907 3/604 1.5/302 0/0 2/1k 1.5/819 1/546 0.5/273 0/0

Date

Figure 9. Representative temporal patterns: (top left) sustained multi-day activity in the Black Sea (Cluster 2); (top right) intermittent bursts in the Taiwan Strait (Cluster 3); (bottom left) a single isolated event in the Gulf of Mexico (Cluster 10); and (bottom right) recurrent anomalies off the Gaza coast (Cluster 11) TABLE 5. C LUSTERS GROUPED BY TEMPORAL PERSISTENCE PATTERNS . Temporal Pattern

Clusters (IDs)

Sustained Recurrent Intermittent

0, 2, 4, 5, 29 1, 11, 16, 22 3, 6, 7, 8, 12, 14, 17, 18, 20, 21, 25, 26, 30 9, 10, 13, 15, 19, 23, 24, 27, 28

Isolated

2. Recurrent. Clusters were classified as recurrent when the flagged vessel count exhibited at least three activity peaks separated by approximately regular intervals (coefficient of variation of inter-peak spacing <0.3). These clusters correspond to regions where anomalies reoccur on a periodic or scheduled basis (Figure 9, Cluster 11). 3. Intermittent. Clusters were labeled as intermittent when they contained multiple irregular bursts of anomalous activity separated by quiet periods but did not meet the regularity or duration thresholds for sustained or recurrent behavior. This category captures sporadic or short-lived anomaly events (Figure 9, Cluster 3). 4. Isolated. Clusters were identified as isolated when activity was dominated by a single short peak lasting fewer than three days, with all other peaks below 25% of the maximum intensity. These represent one-off incidents or localized anomalies (Figure 9, Cluster 10). We classify all 31 anomaly hotspots identified in Figures 5 and 6 according to the empirical criteria described above. Table 5 summarizes the dominant temporal persistence pattern for each cluster. Three broad trends emerge. First, sustained multi-day anomalies appear in the Black Sea, North Sea, and Strait of Hormuz, consistent with ongoing military spoofing activity [82]. The Hormuz zone (Cluster 29) is notable for what came later: it appeared over a year before the 2026 Iran war drove mass GPS interference across the Persian Gulf [22], underscoring the predictive

Balti

Shakhty

+

Nikopol

OBLAST

OBLAST

Ukraine

CHISINĂU.

Kherson

0000

KHERSON OBLAST

ODESA-

Volgode

ROS Mariupol

Melitopol

Tiraspol

TABLE 6. P ER - CLUSTER EVIDENCE GRADING . T IERS REFLECT THE STRENGTH OF positive evidence SUPPORTING GPS SPOOFING . Corroborated: EXTERNAL CORROBORATION . Newly Identified: STRONG INTERNAL EVIDENCE WITHOUT EXTERNAL CORROBORATION . Suggestive: WEAKER OR LESS - STRUCTURED INTERNAL EVIDENCE .

ROSTOV OBLAST

ZAPORIZHIA

MYKOLAIV

MOLDOVA

Russia

ODESA OBLAST Cahul

KRASNODAR

AUTONOMOUS

KRAI

REPUBLIC OF

CRIMEA

tya

Crimea

REPUBLIC OF CRIMEА

Smferopol

SE

KRASNODAR

Region (IDs)

Tier

Positive Evidence

Black Sea (2, 6, 9, 13)

Corroborated

Crop-circle patterns; C4ADS corroboration [53]; conflict context

Red Sea (7)

Corroborated

Linear pattern; MSC Antonia 5th-decimal match

Gaza coast (11)

Corroborated

Point convergence; daily alignment with conflict timeline

Hormuz (29)

Corroborated

Detected >1yr before Iran tensions; prior Iranian interference

Armavir STAVROPOL

REPUBLIC OF ADYGEA

Cherkessk

CONSTANTA

KARACHAY-

CHERKESIA

KABARD BALKAR

Black Sea

Sukhum

Georgia Leaflet|OpenStreetMap contributors

Figure 10. Anomalous GPS points across the Black Sea. Dense clusters occur along the Russian and Crimean coasts.

value of persistent anomaly zones. Second, recurrent and intermittent patterns dominate East Asian waterways and the Eastern Mediterranean, potentially reflecting localized and repeated interference events [83]. Finally, shorter-lived and isolated incidents in the Gulf of Mexico and Panama Canal show that brief episodes occur even in regions without known conflict. These temporal signatures highlight both the persistence and diversity of global anomaly activity, showing that interference can be prolonged in conflict zones while remaining sporadic elsewhere. Interference leaves fingerprints: anomaly zones recur with consistent geometries in the same places, on observable schedules. These zones can therefore be tracked over time, and in many regions, anticipated. 4.1.4. From Anomalies to Spoofing. Now that we have identified 31 anomalous zones with characterized geometric and temporal patterns, we infer which zones are consistent with GPS spoofing. Recall that every zone has already passed the pipeline-level filtering of alternative explanations validated in Section 3.6 (Table 1). What remains is to grade each zone by the strength of positive evidence supporting a spoofing interpretation. Grading positive evidence. We grade each remaining zone by the kind of evidence supporting a spoofing interpretation, defined by whether the spoofing is externally documented and how distinctive its signature is. Tier assignments follow the geometric and temporal criteria from Sections 4.1.2 and 4.1.3, and were reviewed independently by multiple authors (not blinded), including a maritimedomain expert, who reached consensus on each label. 1. Corroborated spoofing: a distinctive spoofing signature together with external corroboration, through incident reports, fine-grained alignment with documented conflict events, or documented prior spoofing in the region (e.g., Black Sea crop-circles corroborated by multiple news reports). These are zones where independent evidence confirms spoofing is occurring. 2. Newly identified spoofing: a distinctive geometric or temporal signature without external corroboration (e.g., Gulf

CARTO

East Asia Corroborated (1, 3, 5, 14, 19, 25)

Crop-circle documented spoofing

Baltic (0, 4, 12, 15, 24)

Newly identified

Sustained cross-vessel coherence; geometric regularity; high flag-state diversity

Mexico Newly identified

Cross-shaped jumps across ∼200 vessels; synchronized timing; high vessel diversity

Panama Canal (23) Newly identified

Coherent isolated-day geometry; cross-vessel consistency

Canary Islands (8)

Newly identified

Recurrent pattern; cross-vessel coherence

Caspian Sea (20)

Newly identified

Crop-circle pattern; consistent across vessels

Inland rivers Suggestive (16, 17, 18, 21, 22, 26, 30)

Linear displacements; crossvessel agreement; less flag diversity than other clusters

Atlantic/Adriatic (27, 28)

Irregular patterns; cross-vessel correlation but less structured signatures

Gulf (10)

of

Suggestive

patterns; Shanghai/China

of Mexico synchronized linear jumps across roughly 200 vessels). Although no public report documents these zones, the signature itself is strong evidence: such geometries are implausible for genuine navigation and appear coherently across many independent vessels within a bounded region, the invariant pattern of regional external spoofing. These represent spoofing zones our measurement surfaces that have not, to our knowledge, been previously reported. 3. Suggestive: anomalies shared across vessels but with less distinctive signatures (e.g., inland river clusters and irregular displacement zones) and no external corroboration, consistent with spoofing but not individually conclusive. Of 31 zones, 13 are corroborated spoofing, 9 are newly identified spoofing supported by a strong internal signature, and 9 are suggestive. Detailed per-cluster grading appears in Table 6. Under the most conservative interpretation, counting only corroborated zones, our results document spoofing across five geopolitical regions and more than 1,000 vessels;

ADY

SEVASTOPOL

ES Călăraşi

the newly identified tier extends this to previously unreported regions. The case studies that follow examine both corroborated zones and zones of distinct analytical interest, including unexpected civilian-zone anomalies and sanctionsrelated self-spoofing.

Cherkessk

CONSTANTA

KARACHAY-

Black Sea

Dobrich-

CHERKESIA

Sochi

Varna Sukhum

Burgas

Poti

Edirne

Batumi

Istanbul

ISTANBLL

Tekirdağ.

Across 31 anomaly zones, 22 show strong evidence of large-scale GPS spoofing. Of these, 13 align with documented incident reports, indicating our approach catches real, corroborated spoofing. The remaining 9 are previously undocumented, showing our approach finds what existing sources miss.

Kocaeli

+

Bolu

Turkey

Trabzon

Amasya

BURSA-

Canakkale

ANKARA

Erzurum

Kırıkkale

Eskisehir

Erzincai

Sivas

Balıkesir

Mytilene

Russia

Dagomys Uşak

Afyonkarahisar

Kayseri

Krasnaya

Polyana

Leaflet |

Sochi

OpenStreetMap contributors

CARTO

SOCHI

Black Sea

4.2. Case Studies and Geopolitical Context

Georgia

Sirius

ALBANIA

ISTAN

ARMENIA Having established the global structure Nap of spoofing activity, this section examines why these zones emerge and Figure 11. Spoofing spillover on the civilian cruise ship Astoria Grande. TURKEY (Top) Distorted AIS track between Sochi, Istanbul, and Trabzon, showing persist, integrating geopolitical, operational, and economic GREECE ATHE unreadable routing from heavy interference. (Bottom) Circular spoofed factors. We contextualize spoofing hotspots using conflict points off Sochi, showing the ship was caught up in regional spoofing. timelines, vessel attributes, and sanction status. Three repreAleppo Kont sentative examples capture both conflict-linked and civilian Mediterranean CYPR anomalies. A fourth case study explores how sanctioned SYRIA NON SIA vessels use self-spoofing to evade tracking (16-215 vessels IRAQ Tripoli under our bounds). These case studies corroborate that the detected clusters reflect real interference. ISRAF Case Study 1: Black Sea and Russia. The Black Sea exhibIsrael ited the most sustained and spatially widespread spoofing in KUWAIT our dataset, affecting between 902 and 2,297 vessels across both lower bound and upper bound thresholds. Interference LIBYA concentrated around Sevastopol, Sochi, and Novorossiysk, EGYPT Egypt SAUDI ARABIA Saudi Arabia extending eastward toward the Caucasus coast, while the northwestern shelf near Odesa and Constant, a showed comparatively little activity. This east-west contrast suggests that spoofing is targeted within the region. Circular “crop-circle” loops dominate nearly every active zone, sometimes persisting for several consecutive days. Port Sudan These loops are interspersed with abrupt, long-range jumps ER across the basin; linear displacements that project vessels Figure 12. Spoofed points across Israel and the Red Sea. Linear displaceYEMEN onto false positions sometimes hundreds of kilometers away. ERITREА ments appear near Port Sudan, while dense convergence clusters occur CHAD Such geometry could indicate high-power, multi-receiver inland near Israel and Jordan. SUDAN spoofing consistent with electronic-warfare [53], [82]. Collateral impacts were also visible on civilian traffic. Nyala Two dominant interference patterns emerge in the IsraelDJIBOUTI The passenger cruise ship Astoria Grande,N'Djamena with a capacity Red Sea corridor (Figure 12): pointETHIOPIA convergence and linear of 1,699 passengers and crew [84], was repeatedly spoofed Hargeisa displacements. Near Gaza and the eastern Mediterranean into circular trajectories off Sochi, rendering its AIS record coast, multiple SOUTH vessels exhibited point convergence, where nearly unreadable (Figure 11). MarineTraffic data confirm its independent AIS tracks abruptly snapped to the same small legitimate route between Sochi, Istanbul, and Trabzon [85], inland coordinates at Queen Alia International Airport in [86], indicating that the interference was external to the vesJordan. These convergence events were observed across sel rather than self-induced. This spillover demonstrates how dozens of vessels and occurred in repeated bursts that temlarge-area spoofing operations can inadvertently endanger porally aligned with major escalations in the Gaza conflict civilian vessels transiting conflict-adjacent waters. shown in Figure 13. Case Study 2: Israel and the Red Sea. Spoofing activity These temporal overlaps are not isolated anecdotes. Inidentified across the Eastern Mediterranean and Red Sea dependent timelines from Reuters, Al Jazeera, and Doctors exhibited both regional recurrence and distinct geometric signatures. Throughout the observation window, between 58 Without Borders report similar peaks of hostilities, including heavy airstrikes (Dec 5–12), renewed raids (Dec 17–21), and and 1,002 vessels (lower and upper bounds, respectively) major assaults in early January (Jan 7–8), which coincide were flagged for spoofing within this corridor, corresponding primarily to Clusters 7 and 11 from Figure 5. with observed spoofing activity [87], [88], [89]. Together, Thessalonik

Spoofed Points Only

Pal

-

AZERBAIJAN

Yerevan

Ankara

Baku

Gagra

MMSI 511100759

Total segments: 35

Total points: 4781

Pitsunda

Total duration: 305.5 hours

Red: Spoofed points only

πελα

Leaflet |

So

Valletta

OpenStreetMap contributors

CARTO

TEHRAN-

Sea

Benqhazi

Jen

I

Isfahan

mma

Alexandria

CAIRO

Shiraz

Sabha

Luxor

RIYADH-

Jeddah

Dongola.

Khartoum

Mecca

Port Sudarn

Kassala-

Asmara

Sana'a

Abéché

Gonder

Aden

Maroua

ADDIS ABABA

Ndélé

SOMALIA

Wau

QAT

D

UN

AR

EMIR

Number of Spoofed Ships

AUSTIN

Texas

LAFAYETTE

EAUMONT

PORT ARTHUR

AN ANTONIO CAL

4 5

3

1 2

6

7

8

TON

9 CORPUS CHRISTI

Cluster 10 Bounds

NOTH AMEICA

2

5-8 11-12 17 20-21 December 2024

30-31

7-8

EUROPЕ

ASIA

14 21-24 January 2025

RICA

+

Lake Charles

Port Houston

Figure 13. Timeline of spoofing near Israel and Gaza, annotated with major conflict events (orange: upper bound; blue: lower bound); peaks align with reported escalations. 1: Ceasefire violated; 2: Gaza offensive; 3: Heavy OCEANIA AUSTRALIA strikes; 4: Ceasefire talks fail; 5: Houthi missile; 6: Year-end strikes; 7: Final Gaza strikes; 8: Day before ceasefire; 9: Post-truce raids

AMERICA

ASIA

AFRICA

SOUTH AMERICA AUSTRALIA

RED SEA STATE

Figure 15. Gulf of Mexico vessels (Cluster 10) show horizontal and vertical jumps, characteristic of GPS interference. Red lines indicate ship jump paths and black dots indicate the start and end locations of each jump.

Port Sudan

DORT

akin

Red Sea

Jubayt

Figure 14. Bulk carrier Charmous with linear displacement in the Red Sea five months prior to MSC Antonia grounding. Sinkāt

Hayya

Leaflet |

OpenStreetMap contributors

CARTO

these overlaps suggest that the spoofing was likely caused by air-defense activity, demonstrating how electronic-warfare during conflict can unintentionally disrupt civilian navigation and place vessels at risk. Along the Red Sea corridor near Port Sudan, we observe recurrent linear displacements, parallel false tracks projecting tens of kilometers from the coast. These paths follow the exact same latitude, to the fifth decimal point, as those recorded from the MSC Antonia prior to its grounding (Figure 1), suggesting repeated or continued operation of the same interference source five months apart. The Charmous, a bulk carrier flagged under Palau, provides a representative example. On January 21st 2025, its AIS track abruptly shifted into an artificial straight-line projection extending northeast from Port Sudan (Figure 14). At least 11 other vessels (lower bound) recorded within 50 km of this event showed the same displacement at overlapping timestamps, suggesting an external interference source. Collectively, these findings show that the Israel-Red Sea corridor features two recurring spoofing geometries: convergence near Israeli and Jordanian airspace, and linear displacements near Port Sudan. The Gaza-coast events consistently coincide with periods of active air-defense and drone operations, showing that spoofing traces may serve as useful signals for tracking regional military activity. In contrast, the repeated Red Sea displacements, first seen five months before the MSC Antonia grounding (Figure 1), show that persistent spoofing zones can be monitored over time and may help warn mariners of navigation risks. Case Study 3: Unexpected Spoofing Zones. Beyond active conflict regions, we also identified spoofing in purely civilian maritime corridors, notably near the Canary Islands (Cluster 8), the Gulf of Mexico (Cluster 10), and

the Panama Canal (Cluster 23). These short-lived, lowmagnitude episodes lacked any connection to known conflicts or electronic-warfare. At their peaks, the Canary Islands cluster affected between 7 and 403 vessels, the Gulf of Mexico between 13 and 1,196, and the Panama Canal between 9 and 559 (lower-upper bounds). While the Gulf and Panama incidents appeared as isolated single-day events (December 31 and January 31, respectively), the Canary Islands exhibited recurrent spoofing throughout the observation period, including a sharp spike on December 31. In the Gulf of Mexico, on December 31, almost 200 vessels exhibited synchronized positional jumps radiating north-south and east-west across thousands of kilometers (Figure 15). The uniform directions and simultaneous timing rule out multipath, random receiver error, or the geomagnetic storm that struck later that day. 3 Instead, the observed geometry is more consistent with large-scale GPS spoofing, potentially originating from a coastal or airborne transmitter affecting multiple AIS receivers simultaneously. Given the region’s history of United States Navy and Coast Guard counter-narcotics and drone operations, this interference may reflect localized testing or operational GPS spoofing [91], [92]. Furthermore, we reproduced the Gulf of Mexico event using public AIS data from NOAA [56], recovering the same synchronized displacement pattern across 10 to 634 vessels (lower and upper bounds) on December 31. These track our Spire-based counts (13 and 1,196), with the lower NOAA figures reflecting its US-coastal terrestrial coverage versus Spire’s global satellite feed. This independent result corroborates the finding and shows the pipeline generalizes across datasets. Case Study 4: Sanctions and Self-Spoofing. Crossreferencing spoofed vessel identifiers (MMSIs) with OFAC, EU, and UK sanctions lists revealed a small but significant 3. The storm and the jumps occurred at different times, and storminduced errors would be far too small anyway [90] (Section 3.6).

Leaflet |

OpenStreetMap c

+

Laoheishan

Luozigou

ment. Using our lower and upper bounds, we identify 16215 sanctioned vessels engaged in likely self-spoofing [93], showing that GPS falsification has become a deliberate tool of sanctions evasion.

Razdolnoe

Russia Fuxing

Artyom

Trud

Smolyaninovo

Chunhua

Ulaanbaatar

Qiqihar

+

Bolshoy

VLADIVOSTOK

MONGOLIA

Partisansk

Kamen

Vladivostok

From conflict zones to commercial corridors, GPS spoofing has multiple motives: weapon, byproduct, and cover. In warzones it mirrors defense systems; at sea it entangles civilians; and along trade routes it conceals sanctioned movement. Together, these cases show how geopolitics shapes navigation integrity.

Harbin

Fokino

EN Hadamen

Changchun

Yangpao Hunchun

Vladivostol Dunay

Slavyanka

Russia

Vladimi

Sapporo

Preobrazheniye

Aleksandrovskoe

NAKHODKA Shenyang

Banshi Baotou

Zarubino

Spoofed Points Only

-

Total points: 256

Tianjin

Pyongyang"

Yinchuan MMSI 314958000

Taiyuan

Total segments: 3

North Korea

Японское

Mоре/

동해/조

선동해

SEOUL

South /항 SOUTH KORE 해/조선Korea

Zibo

Jinan

Xining Lanzhou

Total duration: 12.4 hours

日本海/

NORTH KOREA

BEIJING

Jiayuguan

Japan JAPAN TOKYO

서해

CHINA

Zhengzhou

Hirosh

Xi'an

Red: Spoofed points only 만포

China

OSAKA Leaflet |

OpenStreetMap contributors © CARTO

5. Concluding Discussion

Nagasaki-

Huainan.

Nanjing SHANGHAI

CHENGDU

Wuhan

Hangzhou

Chongqing Changsha

Nanchang

중국해

Pingxiang

Figure 16. Self-spoofing by the sanctioned tanker Hyperion. (Top) Spoofed inland circular positions near Vladivostok. (Bottom) Route showing crude transport between Russian Pacific ports and China during the G7+ oil embargo period. Guiyang

Fuzhou

Guilin

Kunming

TAIPEI

TAIWAN

Nanning

Guangzhou

Dongguan

Shenzhen ten

Shantou

HONG KONG

Kaohsiung

subset of vessels, primarily oil tankers, linked to sanctioned entities [93]. Several exhibited repeated spoofing or MMSI reuse along export corridors from Russian ports, showing they likely intentionally concealed their real locations. The Hyperion, was sanctioned by the U.S., EU, U.K., and others between January and July 2025 for transporting Russian oil using irregular, high-risk shipping practices. During our observation window, the vessel’s AIS data showed clusters of false inland positions near Vladivostok (Figure 16), temporally aligned with its legitimate voyages to China. Other ships transiting the same corridor during the same period exhibited no comparable anomalies, indicating that the interference was localized to the vessel, consistent with self-spoofing. A natural question is why a sanctioned vessel would falsify AIS positions rather than simply disable AIS. Prior work on sanctions-evasion notes that “going dark” is itself a major compliance red flag for insurers, ports, and classification societies, which routinely monitor AIS silence as a sign of illicit activity [94]. Tankers engaged in sanctioned trade still require insurance and port access, making persistent outages more suspicious than misleading data [95]. Manipulating coordinates, therefore, allows a vessel to maintain continuous transmission while obscuring its true movements. Importantly, this self-spoofing is not meant to deceive nearby mariners or port authorities, who can physically observe the ship. The deception targets distant observers, satellite AIS receivers, commodity trackers, and regulators, whose global feeds can be misled during short falsified windows near loading or discharge sites [95]. In Hyperion’s case, spoofing was confined to port approaches: local actors would not be fooled, but remote monitors would record an altered movement history. Beyond single-vessel manipulation, some sanctioned MMSIs were reused by other ships, and in other cases sanctioned vessels alternated between valid and falsified identifiers. This ambiguity, whether a sanctioned ship is hiding its location or being impersonated, complicates enforce-

Leaflet |

Our analysis shows that GPS spoofing in maritime environments is neither rare nor random. Applying our two-stage framework to AIS data from late November 2024 to early February 2025, we identify 17,936 anomaly episodes across 2,663 vessels and 31 anomaly hotspots worldwide, of which at least 22 show strong evidence of GPS spoofing (Sections 4.1.1 and 4.1.4). While many corroborate documented incidents, others are previously unreported spoofing regions that our measurement is the first to surface. These zones cluster around conflict regions, major trade corridors, and sanctions-linked routes, and exhibit distinctive geometric (circular, linear, convergent, irregular) and temporal (sustained, recurrent, intermittent, isolated) signatures, as characterized in Sections 4.1.2 and 4.1.3. In total, these findings demonstrate that maritime GPS interference is a structured, recurring feature of the global navigation environment, not merely isolated anomalies. Operational and Strategic Risks. Spoofing imposes operational hazards far beyond data integrity. Ships misled by falsified coordinates can drift into restricted waters, collide in dense corridors, or run aground, as exemplified by the MSC Antonia incident, whose straight-line displacement matches a persistent Red Sea spoofing pattern (Figures 8 and 1). Circular and linear geometries that appear as “clean” tracks over tens of kilometers are particularly dangerous: they are plausible enough to be followed, yet entirely divorced from the ship’s true position. In high-traffic regions such as the Eastern Mediterranean, Gulf of Mexico, and Panama Canal, even brief interference bursts can simultaneously affect hundreds of vessels (Figure 15). At the strategic level, sustained and recurrent clusters in the Black Sea, Eastern Mediterranean, and East Asian waterways align with ongoing conflict and air-defense activity (Figures 10 and 12), while sanctions-linked tankers like the Hyperion illustrate how self-spoofing serves regulatory evasion rather than purely military aims (Figure 16). Human and Infrastructural Fragility. Modern ship navigation relies heavily on GPSes, leaving crews with few practical alternatives when spoofing occurs [96], [97]. Some spoofing geometries, such as vessels teleported onto an inland airport, are obvious to mariners; others, such as smooth straight-line drifts or irregular scatter, are much harder to detect in real time. Large commercial vessels require one to two nautical miles to stop or significantly alter course [98],

OpenStreetMap contributors

CARTO

so even short delays in recognizing spoofing can translate into groundings or collisions, especially near shore where under-keel clearance is limited [99]. In practice, the skill and vigilance of mariners remain the last line of defense. From Measurement to Early Warning. A central insight from our study is that spoofing is measurable and, in many regions, predictable. Many hotspots exhibit stable or recurring temporal patterns, multi-day activity in the Black Sea and North Sea, recurrent bursts off Gaza, and intermittent episodes along Asian rivers and straits (Figure 9, Table 5). The Strait of Hormuz makes the predictive value concrete: our framework flagged sustained anomalies there in early 2025, over a year before the 2026 Iran war turned the same corridor into one of the most disrupted GPS environments in the world [22]. Had such monitoring been operational, the persistence of that zone would have been visible well in advance. Because these interference zones reappear in the same locations with characteristic geometries, they can be monitored over time to produce risk maps akin to weather charts. Outputs from pipelines like ours (Section 4.1) could be used for safety advisories or charting overlays, allowing ships to adjust routing and readiness before entering high-risk zones. For regulators, insurers, and coastal states, spoofing statistics provide intelligence on where navigation reliability is degraded and where enforcement or infrastructure hardening should be prioritized. Future Directions. Future work should extend this measurement over longer periods to capture seasonal and geopolitical variation, use additional sensors (e.g., radar, inertial logs) for stronger cross-validation, and adapt the pipeline to run continuously as a near-live monitoring system. Equally important is collaboration with maritime authorities and industry to translate measurement into operational tools such as alert services, dashboards, and risk indices usable by mariners with minimal additional training. Our results suggest that spoofing has evolved from isolated incidents into a persistent, organized feature of the maritime environment. Because many interference zones recur over time and exhibit distinctive geometries, continuous measurement enables early warning that could help prevent the next MSC Antonia-like disaster.

[6]

R. Willmington, “Msc ship sails through bab el mandeb for first time since red sea exodus,” 2025, https://www.lloydslist.com/LL1154079/MSC-ship-sails-throughBab-el-Mandeb-for-first-time-since-Red-Sea-exodus.

[7]

WEC, “New casualty - msc antonia - grounding,” 2025, https://www.wecoxclaimsgroup.com/casualty-notices/new-casualtymsc-antonia-grounding/.

[8]

Lockton, “Cyber-physical risk in the marine sector: a wake-up call from the msc antonia,” 2025, https://global.lockton.com/cca/en/ news-insights/cyber-physical-risk-in-the-marine-sector-a-wake-upcall-from-the-msc-antonia.

[9]

Windward, “Gps jamming falsely placed vlcc front eagle in iran prior to collision,” 2025, https://windward.ai/blog/gps-jammingfalsely-placed-front-eagle-in-iran-prior-to-collision/.

[10]

M. W. Bockmann, “Seized uk tanker likely ’spoofed’ by iran,” 2019, https://www.lloydslist.com/LL1128820/Seized-UK-tankerlikely-spoofed-by-Iran.

[11]

S. Chambers, “Msc ship aground off jeddah, likely victim of gps spoofing,” 2025, https://splash247.com/msc-ship-aground-offjeddah-likely-victim-of-gps-spoofing/.

[12]

C. Woody, “The navy’s 4th accident this year is stirring concerns about hackers targeting us warships,” 2017, https://www.businessinsider.com/hacking-and-gps-spoofinginvolved-in-navy-accidents-2017-8.

[13]

A. Raymaker, A. Kumar, M. Y. Wong, R. Pickren, A. Chhotaray, F. Li, S. Zonouz, and R. Beyah, “A sea of cyber threats: Maritime cybersecurity from the perspective of mariners,” in ACM Conference on Computer and Communications Security (CCS), 2025.

[14]

N. O. Tippenhauer, C. Pöpper, K. B. Rasmussen, and S. Capkun, “On the requirements for successful gps spoofing attacks,” in ACM Conference on Computer and Communications Security (CCS), 2011.

[15]

K. C. Zeng, S. Liu, Y. Shu, D. Wang, H. Li, Y. Dou, G. Wang, and Y. Yang, “All your gps are belong to us: Towards stealthy manipulation of road navigation systems,” in USENIX Security, 2018.

[16]

H. Sathaye, M. Strohmeier, V. Lenders, and A. Ranganathan, “An experimental study of gps spoofing and takeover attacks on uavs,” in USENIX Security, 2022.

[17]

M. Balduzzi, A. Pasta, and K. Wilhoit, “A security evaluation of ais automated identification system,” in Proceedings of the 30th annual computer security applications conference, 2014.

[18]

J. Pavur, D. Moser, M. Strohmeier, V. Lenders, and I. Martinovic, “A tale of sea and sky on the security of maritime vsat communications,” in IEEE Symposium on Security and Privacy (S&P), 2020.

[19]

S. Liu, X. Cheng, H. Yang, Y. Shu, X. Weng, P. Guo, K. C. Zeng, G. Wang, and Y. Yang, “Stars can tell: a robust method to defend against gps spoofing attacks using off-the-shelf chipset,” in USENIX Security, 2021.

[20]

B. Davidovich, B. Nassi, and Y. Elovici, “Visas–detecting gps spoofing attacks against drones by analyzing camera’s video stream,” in Network and Distributed System Security Symposium (NDSS), 2022.

[21]

A. Amro, A. Oruc, V. Gkioulos, and S. Katsikas, “Navigation data anomaly analysis and detection,” in Information, 2022.

[22]

D. E. Béchard, “Why ships in the strait of hormuz can’t trust their navigation screens,” 2026, https://www.scientificamerican.com/ article/gps-spoofing-is-scrambling-ships-in-the-strait-of-hormuz/.

[23]

IMO, “Ais transponders,” https://www.imo.org/en/ourwork/safety/ pages/ais.aspx.

[24]

USCG, “Automatic identification system (ais) overview,” https:// www.navcen.uscg.gov/automatic-identification-system-overview.

[25]

E. Lee, A. J. Mokashi, S. Y. Moon, and G. Kim, “The maturity of automatic identification systems (ais) and its implications for innovation,” Journal of Marine Science and Engineering, 2019.

References [1]

ICS, “Shipping and world trade: World seaborne trade,” 2025, https://www.ics-shipping.org/shipping-fact/shipping-and-worldtrade-largest-beneficial-ownership-countries/.

[2]

I. MacIntyre, “The potentially catastrophic threat of gps spoofing in shipping,” 2025, https://www.imarest.org/resource/mp-thepotentially-catastrophic-threat-of-gps-spoofing-in-shipping.html.

[3]

[4]

[5]

T. E. Team, “Vessels navigating in china report gps spoofing incidents,” 2020, https://safety4sea.com/vessels-navigating-in-chinareport-gps-spoofing-incidents/. EMSA, “Annual overview of marine casualties and incidents 2024,” 2024, https://iims-media-library.s3.eu-west-2.amazonaws.com/wpcontent/uploads/2024/12/17115213/Annual-Overview-of-MarineCasualties-and-Incidents-2024.pdf#page=2.16. P. Hancock, “Msc antonia,” 2025, https://shipwrecklog.com/log/ 2025/05/msc-antonia/.

[26]

K. Tran, S. Keene, E. Fretheim, and M. Tsikerdekis, “Marine network protocols and security risks,” in Journal of Cybersecurity and Privacy, 2021.

[46]

J. Yang, A. Estornell, and Y. Vorobeychik, “Location spoofing attacks on autonomous fleets,” in Symposium on Vehicles Security and Privacy, 2023.

[27]

I. Progoulakis, P. Rohmeyer, and N. Nikitakos, “Cyber physical systems security for maritime assets,” in Journal of Marine Science and Engineering, 2021.

[47]

C. Tibaldo, H. Sathaye, G. Camurati, and S. Capkun, “Gnss-wasp: Gnss wide area spoofing,” in USENIX Security, 2025.

[48]

[28]

J. DiRenzo, D. A. Goward, and F. S. Roberts, “The little-known challenge of maritime cyber security,” in International Conference on Information, Intelligence, Systems and Applications (IISA), 2015.

J. Zhang, S. Cheng, L. Hu, J. Zhang, C. Shi, X. Han, T. Zhang, Y. Cheng, and W. Zhang, “The ghost navigator: Revisiting the hidden vulnerability of localization in autonomous driving,” in USENIX Security, 2025.

[29]

M. Louart, J.-J. Szkolnik, A.-O. Boudraa, J.-C. Le Lann, and F. Le Roy, “Detection of ais messages falsifications and spoofing by checking messages compliance with tdma protocol,” Digital Signal Processing, 2023.

[49]

H. Sathaye, G. LaMountain, P. Closas, and A. Ranganathan, “Semperfi: Anti-spoofing gps receiver for uavs,” in Network and Distributed System Security Symposium (NDSS), 2022.

[50]

[30]

H. Zheng, Q. Hu, C. Yang, Q. Mei, P. Wang, and K. Li, “Identification of spoofing ships from automatic identification system data via trajectory segmentation and isolation forest,” Journal of Marine Science and Engineering, 2023.

K. Jansen, M. Schäfer, D. Moser, V. Lenders, C. Pöpper, and J. Schmitt, “Crowd-gps-sec: Leveraging crowdsourcing to detect and localize gps spoofing attacks,” in IEEE Symposium on Security and Privacy (S&P), 2018.

[51]

[31]

A. Androjna, M. Perkovič, I. Pavic, and J. Mišković, “Ais data vulnerability indicated by a spoofing case-study,” Applied Sciences, 2021.

D. Coppola, A. Mumtaz, G. Camurati, H. Sathaye, M. Singh, and S. Capkun, “Leo-range: Physical layer design for secure ranging with low earth orbiting satellites,” in USENIX Security, 2025.

[52]

[32]

A. Androjna, I. Pavić, L. Gucma, P. Vidmar, and M. Perkovič, “Ais data manipulation in the illicit global oil trade,” Journal of Marine Science and Engineering, 2023.

X. Cheng, H. Yang, S. Liu, and Y. Yang, “Distributed multi-antenna gps spoofing attack using off-the-shelf devices,” in ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2025.

[53]

[33]

J. Bhatti and T. E. Humphreys, “Hostile control of ships via false gps signals: Demonstration and detection,” NAVIGATION: Journal of the Institute of Navigation, 2017.

C4ADS, “Above us only stars: Exposing gps spoofing in russia and syria,” 2019, https://c4ads.org/wp-content/uploads/2022/05/ AboveUsOnlyStars-Report.pdf.

[54]

[34]

Y. Xu, X. Han, G. Deng, J. Li, Y. Liu, and T. Zhang, “Sok: Rethinking sensor spoofing attacks against robotic vehicles from a systematic view,” in IEEE European Symposium on Security and Privacy (EuroS&P), 2023.

M. Harris, “Ghost ships, crop circles, and soft gold: A gps mystery in shanghai,” 2019, https://www.technologyreview.com/2019/11/15/ 131940/ghost-ships-crop-circles-and-soft-gold-a-gps-mystery-inshanghai/.

[55]

[35]

Y. Xu, G. Deng, X. Han, G. Li, H. Qiu, and T. Zhang, “Physcout: Detecting sensor spoofing attacks via spatio-temporal consistency,” in ACM Conference on Computer and Communications Security (CCS), 2024.

J. Trevithick, “New type of gps spoofing attack in china creates “crop circles” of false location data,” 2019, https://www.twz.com/31092/new-type-of-gps-spoofing-attackin-china-creates-crop-circles-of-false-location-data.

[56]

[36]

C. Clover and C. Cook, “How russia is jamming gps around europe,” 2025, https://www.ft.com/content/44cb37b6-2d82-402f8c96-98b951f464af.

N. A. Data, https://coast.noaa.gov/htdata/CMSP/AISDataHandler/ 2024/index.html.

[57]

D. M. A. A. Data, http://aisdata.ais.dk/.

[58]

S. Global, https://spire.com/.

[59]

I. Spire Global, “Spire global awarded ca $1.41 million contract from government of canada for ship tracking data,” 2024, https://ir.spire.com/news-events/press-releases/detail/227/spireglobal-awarded-ca-1-41-million-contract-from.

[60]

J. Wendel, C. Schlaile, and G. F. Trommer, “Direct kalman filtering of gps/ins for aerospace applications,” in International Symposium on Kinematic Systems in Geodesy, Geomatics and Navigation (KIS2001), 2001.

[61]

M. Al-Absi, R. Fu, K. Kim, Y.-S. Lee, A. Al-Absi, and S. Lee, “Tracking unmanned aerial vehicles based on the kalman filter considering uncertainty and error aware,” Electronics, 2021.

[62]

D. K. Nishad, S. Khalid, D. Prakash, V. K. Singh, and P. Sahani, “Advanced algorithms for uav tracking of targets exhibiting startstop and irregular motion,” Scientific Reports, 2025.

[37]

[38]

C. J. Gahnström, “Free article : Jamming and spoofing,” 2024, https://www.nautinst.org/resources-page/free-article-jamming-andspoofing.html. J. Spravil, C. Hemminghaus, M. von Rechenberg, E. Padilla, and J. Bauer, “Detecting maritime gps spoofing attacks based on nmea sentence integrity monitoring,” Journal of Marine Science and Engineering, 2023.

[39]

M. Jones, “Spoofing in the black sea: What really happened?” 2017, https://www.gpsworld.com/spoofing-in-the-blacksea-what-really-happened/.

[40]

D. M. Zorri and G. C. Kessler, “Position, navigation, and timing weaponization in the maritime domain: Orientation in the era of great systems conflict,” 2024, https://ndupress.ndu.edu/Media/ News/News-Article-View/Article/3678180/position-navigationand-timing-weaponization-in-the-maritime-domain-orientation/.

[41]

L. R. Weill, “Conquering mutlipath: The gps accuracy battle,” GPS world, 1997.

[63]

L. J. Levy, “The kalman filter: navigation’s integration workhorse,” GPS World, 1997.

[42]

E. S. Agency, “Multipath,” 2023, https://gssc.esa.int/navipedia/index. php/Multipath.

[64]

[43]

M. L. Psiaki and T. E. Humphreys, “Gnss spoofing and detection,” Proceedings of the IEEE, 2016.

I. T. Union, “Recommendation itu-r m.1371-5,” 2014, https://www.itu.int/dms pubrec/itu-r/rec/m/R-REC-M.1371-5201402-S!!PDF-E.pdf.

[65]

K. S. University, “Distance between points on the earth’s surface,” https://www.math.ksu.edu/∼dbski/writings/haversine.pdf.

[66]

R. Bansal, “Deriving and testing the great circle theory,” International Journal of Statistics and Applied Mathematics, 2021.

[67]

J.-F. Pekel, A. Cottam, N. Gorelick, and A. S. Belward, “Highresolution mapping of global surface water and its long-term changes,” in Nature, 2016.

[44]

[45]

S. Narain, A. Ranganathan, and G. Noubir, “Security of gps/ins based on-road location tracking systems,” in IEEE Symposium on Security and Privacy (S&P), 2019. J. Shen, J. Y. Won, Z. Chen, and Q. A. Chen, “Drift with devil: Security of multi-sensor fusion based localization in high-level autonomous driving under gps spoofing,” in USENIX Security, 2020.

[90]

J. Faber, D. Nelissen, G. Hon, H. Wang, and M. Tsimplis, “Regulated slow steaming in maritime transport,” 2012, https://theicct.org/ wp-content/uploads/2021/06/CEDelft slow steaming 2012.pdf.

NOAA, “G3 (strong) geomagnetic storm watch for 31 dec,” 2024, https://www.swpc.noaa.gov/news/g3-strong-geomagnetic-stormwatch-31-dec.

[91]

U. S. C. Guard, “Response boat–medium: Project profile,” 2024, https://www.dcms.uscg.mil/Our-Organization/AssistantCommandant-for-Acquisitions-CG-9/Programs/SurfacePrograms/Response-Boat-Medium/RBM-Profile-Copy/.

I. GNSS, “The unsolved mystery of the 2022 texas interference,” 2023, https://insidegnss.com/the-unsolved-mystery-of-the2022-texas-interference/.

[92]

A. Hoag and G. Sirigu, “Dca tcas anomalies explained,” 2025, https: //aireon.com/dca-tcas-anomalies-explained/.

[93]

TankerTrackers, “Officially blacklisted tankers,” 2025, https:// tankertrackers.com/report/sanctioned/results.

[94]

I. Bolton, “Sanctions at sea: Ais manipulation,” 2025, https://sanctionssos.com/myanmar-sanctions/f/sanctions-at-seaais-manipulation.

[95]

I. Markit, “Sanctions advistories for the maritime industry,” 2022, https://library.iccwbo.org/content/tfb/pdf/AIS Whitepaper IHS IIBLP ACSS.pdf.

[68]

J. R. Centre, “Global surface water - data access,” https://globalsurface-water.appspot.com/download.

[69]

[70]

[71]

U. Navy, “Mark vi patrol boat – fact file,” 2018, https://www.navy.mil/Resources/Fact-Files/Display-FactFiles/ Article/2173363/mark-vi-patrol-boat/.

[72]

I. Shipyards, “Shaldag fast patrol craft (mk ii) - specifications,” 2025, https://www.israel-shipyards.com/naval-002.asp.

[73]

NOAA, “Space weather and gps systems,” https://www.swpc.noaa. gov/impacts/space-weather-and-gps-systems.

[74]

M. Ester, H.-P. Kriegel, J. Sander, X. Xu et al., “A density-based algorithm for discovering clusters in large spatial databases with noise,” in KDD, 1996.

[96]

N. Oceanic and A. Administration, “Sunsetting traditional noaa paper charts,” 2019, https://nauticalcharts.noaa.gov/publications/docs/ raster-sunset.pdf.

[75]

E. Schubert, J. Sander, M. Ester, H. P. Kriegel, and X. Xu, “Dbscan revisited, revisited: why and how you should (still) use dbscan,” ACM Transactions on Database Systems (TODS), 2017.

[97]

I. Ibañez, “Teaching celestial navigation in the age of gnss,” TransNav: International Journal on Marine Navigation and Safety of Sea Transportation, 2018.

[76]

W. S. Council, “The top 50 container ports,” https://www. worldshipping.org/top-50-container-ports.

[98]

[77]

L. List, “One hundred container ports 2023,” 2023, https://www. lloydslist.com/one-hundred-container-ports-2023.

D.-I. F. Wirz, “Optimisation of the crash-stop manoeuvre of vessels employing slow-speed two-stroke engines and fixed pitch propellers,” Journal of Marine Engineering & Technology, 2012.

[99]

[78]

I. GNSS, “Msc antonia grounding in the red sea attributed to suspected gnss spoofing,” 2025, https://insidegnss.com/msc-antoniagrounding-in-the-red-sea-attributed-to-suspected-gps-spoofing/.

T. Navigator, “All you ever wanted to know about under keel clearance. . . but were afraid to ask,” 2021, https://www.nautinst.org/resources-page/all-you-ever-wantedto-know-about-under-keel-clearance-but-were-afraid-to-ask.html.

[79]

R. Raza, “Container vessel msc antonia grounded in red sea; gps spoofing suspected,” 2025, https://www.marinetraffic.com/ en/maritime-news/14/accidents/2025/12071/container-vessel-mscantonia-grounded-in-red-sea-gps-spoofin.

[100] Anonymous, “Maritime spoofing,” 2026, https://anonymous. 4open.science/r/maritime spoofing detection anonymousEEBB/README.md.

[80]

J. Arraf, “Israel fakes gps locations to deter attacks, but it also throws off planes and ships,” 2024, https://www.npr.org/2024/04/22/ 1245847903/israel-gps-spoofing.

Appendix A. Open Science

[81]

I. GNSS, “Sinister spoofing in shanghai,” 2019, https://insidegnss. com/sinister-spoofing-in-shanghai/.

[82]

T. Turgeon, “Gps spoofing at russia’s borders: What to know,” 2024, https://www.gnssjamming.com/post/gps-spoofing-report-october2024.

[83]

S. Poizner, “From ukraine to taiwan, jamming of 50-year-old gps is a defense tech nightmare,” 2024, https://breakingdefense.com/2024/07/from-ukraine-to-taiwanjamming-of-50-year-old-gps-is-a-defense-tech-nightmare/.

[84]

ShipCruises, “Astoria grande,” https://www.shipcruises.org/vessels/ Astoria%20Grande/Ocean/10014.

[85]

M. Traffic, “Astoria grande,” 2025, https://www.marinetraffic. com/en/ais/details/ships/shipid:276298/mmsi:511100759/imo: 9112789/vessel:ASTORIA GRANDE.

[86]

CruiseMapper, “Astoria grande,” 2025, https://www.cruisemapper. com/ships/Astoria-Grande-657.

[87]

A. J. Staff, “Timeline: The path to the israel-hamas ceasefire deal in gaza,” 2025, https://www.aljazeera.com/features/2025/1/19/timelinethe-path-to-the-israel-hamas-ceasefire-deal-in-gaza.

[88]

Reuters, “Israel-gaza war: A timeline of key events,” 2025, https://www.reuters.com/world/middle-east/major-moments-israelgaza-war-2025-01-15/.

[89]

D. without Borders, “Timeline: Bearing witness to genocide in gazan,” 2024, https://www.doctorswithoutborders.org/latest/ timeline-bearing-witness-genocide-gaza.

In the interest of open science, we provide our measurement and clustering implementation in an anonymous repository, including documented thresholds, algorithm parameters, and code structure corresponding to the methodology described in Sections 3.3 and 3.4 [100]. To support independent verification, our repository includes a fully reproducible pipeline on NOAA’s public AIS data [56], which recovers the Gulf of Mexico spoofing event, and the Danish Maritime Authority’s feed [57], which reproduces the Baltic event from open data alone.

Appendix B. Additional Validation Complementing Section 3.6, the only port with a slightly elevated flag rate, Hamburg (0.8%), was attributable to MMSI reuse, where multiple ships broadcasting under one identifier produce spoofing-like jumps between distant locations. Manual investigation of representative false positives confirmed they stem from reused identifiers, cloned transmitters, or rare sensor-level GPS faults rather than genuine classification errors; such anomalies do not persist or recur

35

VARIED INDEPENDENTLY WITH THE OTHERS HELD AT THEIR PUBLISHED VALUES ( BOLD ). E PISODE COUNTS SHOW THAT EACH PARAMETER TAKES EFFECT; RECOVERY IS MEASURED GEOGRAPHICALLY AGAINST THE BASELINE RUN .

30

9 12 13 13

Reset (min)

across multiple vessels and are excluded during secondstage clustering. We classify these as “faulty” transmissions, distinct from spoofing. Parameter Sensitivity. Table 7 reports the sweep described in Section 3.6. We set each range from outside our own data. The deviation threshold runs from 2 km, just above the largest benign GPS error, to 10 km, twice our value. MV runs from 50% to 90%. RW runs from 10 minutes, the shortest window that still holds several AIS reports, to 60 minutes. CGE runs from 30 to 360 minutes, well below and well above the 120-minute point where the observed gap distribution drops off sharply. The Kalman reset runs from 3 minutes, the longest reporting interval AIS mandates, to 12 minutes. We also recomputed spoofing zone recovery using 50 km and 150 km matching distances instead of 100 km; the counts change by at most three zones, and usually not at all. The episode column shows that each parameter does take effect: changing the deviation threshold moves the episode count by a third, yet every zone and region is still recovered. Our published setting recovers all 31 zones by definition, since recovery is measured against it; what matters is how far each parameter can move before the recovered set changes. Overall, our findings are not sensitive to these choices: plausible values far from the ones we selected recover nearly the same zones and regions.

0m 0m -1 km 12k m 25k m 510 k 10 m -2 0k 20 m -5 0k m 50 km +

13 17 17 17

050

22 28 31 30

50

17,571 18,295 17,936 15,122

20

3 5 7 12

CGE (min)

0m

12 13 13 13 13

0m

17 17 17 17 17

020

28 29 31 30 30

10

19,789 18,723 17,936 17,702 17,596

m

30 60 120 180 360

RW (min)

-1 0

12 13 13 13 12

50

17 16 17 17 13

m

26 29 31 30 23

-5 0

10,777 11,456 17,936 15,270 12,141

30

10 20 30 45 60

MV (%)

m

12 12 13 12 7

-3 0

17 17 17 15 10

20

29 29 31 27 17

0 10 m

26,427 21,827 17,936 13,772 7,680

5

-2 0

50 60 70 80 90

10

0-

13 13 13 13 13

15

10

17 17 17 17 17

20

Distance Buckets

Figure 17. Error distribution across all AIS points before outlier filtering (left/blue) and after outlier filtering (right/orange).

40

35.3

92.3% under 7 min

30 20

15.7

10 0

0-1

7.7

5.3

2.7

1-2

15.4

2-3

3-4

4-5

5-6

10.2

7.6

6-7

7+

Gap between consecutive AIS messages (min)

Figure 18. Distribution of time gaps between consecutive AIS points, motivating the 7-minute Kalman reset.

16 14 12 10 8 6 4 2 0 2m 2- in 5m 5- in 10 10 m i -3 n 0 30 mi -6 n 0m i 1- n 2h r 2- s 3h r 3- s 4h r 4- s 5h r 5- s 6h r 6- s 7h r 7- s 8h r 8- s 9h 9- rs 10 10 h rs -1 2 12 h rs -2 4h 1- rs 3d a >3 ys da ys

31 31 31 31 31

Post-Outlier Filtering

<=

19,401 19,240 17,936 16,399 14,571

% of gaps

2 3 Deviation (km) 5 7 10

Pre-Outlier Filtering

25

Percentage of Events

Value Episodes Zones Regions Corrob. /31 /17 /13

Time Buckets

Figure 19. Distribution of clean-data gaps between events, motivating the 120-minute end threshold.

% of Windows Meeting Threshold

Parameter

Percentage of Dataset

TABLE 7. S TAGE -1 PARAMETER SENSITIVITY. E ACH PARAMETER IS

5 min 20 min 40 min

100 90 80 70 60 50 40 30 20 10 0 10

20

30

40

10 min 25 min 50 min

50

60

70

15 min 30 min 60 min

80

90

100

% of Points Flagged in Window

Figure 20. Empirical analysis of window size and anomaly ratio, justifying the 30min/70% start threshold.

TABLE 8. D IVERSITY AND PATTERN CONSISTENCY OF DETECTED SPOOFING CLUSTERS . H IGH FLAG - STATE AND VESSEL - TYPE DIVERSITY, COMBINED WITH SHARED SPOOFING GEOMETRIES , MAKES COORDINATED SELF - SPOOFING UNLIKELY.

Metric Unique flag states Unique ship types Dominant pattern share (%)

Min

Median

Max

1 2 55

30 5 72

97 10 94

Appendix C. Ethical Considerations Stakeholders. Relevant stakeholders include mariners and passengers whose navigation may be affected by GPS interference; vessel owners and operators; the specific vessels discussed as case studies; ports, Vessel Traffic Services, coast guards, and navigation authorities; AIS data providers; governments and security organizations operating in regions where interference is observed; sanctions and maritimeenforcement authorities; researchers and maritime-security practitioners; and communities and industries that depend on safe commercial shipping. State or non-state actors conducting GPS interference are also stakeholders, because our analysis reveals that their activity is externally observable. Respect for People. The study is passive and retrospective. We did not interact with vessels, crews, operators, navigation systems, or interference sources, and we did not transmit signals or alter maritime operations. AIS records identify vessels, but our analysis does not identify individual crew members, passengers, or other private persons. Results are primarily reported at the regional or aggregate level. We use named-vessel examples when they are important to explain a finding or connect it to a documented event. We do not attribute responsibility to a vessel or crew when the evidence concerns external interference. Likewise, geographic or temporal association with an active conflict is treated as contextual evidence, not as attribution to any government, organization, or individual. Beneficence. The study is intended to improve understanding of a navigation-safety threat that already affects commercial shipping. Systematically identifying persistent interference can support mariner awareness, future warning systems, and research into more resilient navigation. We also considered potential harms from reporting previously undocumented zones, including reputational harm, unsupported attribution, and revealing that an interference campaign is externally observable. We mitigate these risks by distinguishing Corroborated, Newly Identified, and Suggestive findings; avoiding attribution where the data cannot support it; focusing claims on observable interference patterns; and reporting findings primarily at the regional level. We do not release unnecessary per-vessel intermediate data for newly identified events. Justice. The risks and benefits of this work are not distributed uniformly. Mariners and commercial operators can be affected by regional GPS interference despite having no

role in causing it, and vessels may appear in our dataset simply because they transit an affected region. We therefore treat affected vessels as potential victims or observers of interference, not as responsible parties, unless vessel-local manipulation is specifically supported by the evidence. AIS coverage is also uneven. High-traffic regions and areas with better reception are more observable than remote maritime regions. We account for this as a measurement limitation and do not interpret an absence of detected activity as evidence that a region is free from interference. Respect for Law and Public Interest. The study analyzes passively collected AIS data obtained through a licensed commercial provider and publicly available government sources. We did not bypass access controls, interfere with maritime systems, or perform active security testing. The paper also distinguishes observation from attribution. Our data can support inference of regional GPS spoofing and characterize its observable effects, but generally cannot identify a transmitter or a responsible actor. This distinction is especially important for findings associated with geopolitical or military events. We believe publication serves the public interest by documenting a safety-relevant phenomenon from passive observations while avoiding unsupported attribution. Dual-Use Risk. We recognize that the pipeline has a dualuse dimension. An actor conducting GPS interference could use AIS data and our methodology to assess whether a campaign leaves an observable maritime footprint. However, the work does not provide instructions for generating counterfeit GPS signals, transmitting them, defeating receiver defenses, or making spoofing more effective. The dual-use information is primarily that sufficiently large regional interference can leave correlated signatures in vessel traffic. We balance this risk against the safety value of allowing researchers and maritime operators to recognize persistent interference. Our reporting emphasizes regional patterns and does not provide unnecessary per-vessel intermediate outputs or operational detail beyond what is needed to support the scientific findings. Stakeholder Notification. We did not notify vessels, port authorities, the USCG, military organizations, or other operators. This study does not identify a specific exploitable vulnerability in a stakeholder’s system, or an ongoing compromise that a particular organization can remediate. It retrospectively measures regional interference from observational data, and in many cases the data does not establish who generated the interference or which organization would be the appropriate disclosure recipient. Contacting an affected vessel could also incorrectly imply that the vessel or its operator was responsible for an externally induced anomaly, while contacting a suspected state or military actor would require an attribution that our evidence does not support. For these reasons, we treated this as a retrospective measurement study and did not conduct a vulnerability-disclosure process.

TABLE 9. VALIDATION OF FALSE - POSITIVES IN HIGH - TRAFFIC PORT REGIONS ; SHOWS PIPELINE STABILITY UNDER DENSE GPS CONDITIONS .

Port Rotterdam Singapore Guangzhou Shenzen Ningbo Zhoushan Busan Hong Kong Tanger Med Los Angeles Savannah Colombo

% Spoofed 0.21% 0.01% 0.05% 0.11% 0.04% 0.08% 0.08% 0% 0.09% 0.20% 0%

Raw Spoofed 28 1 5 9 3 5 5 0 1 1 0

Total transited 13,073 12,826 10,199 7,906 6,814 6,265 5,900 4,910 1,167 493 387

TABLE 10. C LUSTER ID S MAPPED TO GEOGRAPHIC AREAS WITH APPROXIMATE CENTER COORDINATES .

ID

Geographic area

Center (lat, lon)

0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30

North Sea and Baltic corridor South China Sea near Hong Kong Eastern and northern Black Sea Taiwan Strait North Sea and Baltic corridor Yellow Sea Crimean sector of the Black Sea Red Sea near Port Sudan Canary Islands, off Western Sahara Western Black Sea Gulf of Mexico Eastern Med. off Gaza coast Baltic Sea near Copenhagen Southern Black Sea near Bosphorus South China Sea west of Hainan North Sea off Norway Yangtze River near Yueyang Yangtze River segment Yangtze River segment Gulf of Thailand Northern Caspian Sea Don River near Rostov Oblast Volga River near Kazan Panama Canal North Sea off Denmark South China Sea (open water) Yangtze River segment Celtic Sea Adriatic Sea Strait of Hormuz Yangtze River segment

(53.3934, 6.9707) (22.3627, 113.8641) (45.1837, 37.9976) (23.9420, 117.9925) (54.6332, 19.8848) (38.6142, 118.3766) (44.5062, 33.3763) (19.5410, 37.2871) (28.2174, -15.7286) (44.7943, 29.4153) (29.4044, -95.0533) (32.0352, 35.0947) (55.4358, 12.7245) (41.1786, 29.3281) (21.5156, 108.7343) (60.6318, 5.0696) (29.5911, 113.3469) (31.2860, 118.0208) (31.7975, 120.3062) (13.5558, 100.6272) (46.3833, 48.0174) (47.5948, 42.1854) (55.7906, 49.0417) (9.0218, -79.6625) (54.9593, 5.7168) (22.4166, 113.4405) (29.6902, 121.4221) (51.7103, -5.5655) (43.3878, 16.3694) (24.6216, 54.6840) (30.2764, 117.1088)

Port Antwerp Tianjin Xingang Algeciras Piraeus Athens Kaohsiung Qingdao Hamburg New York Dubai Klang Tanjung

% Spoofed 0.26% 0.23% 0% 0.05% 0.05% 0% 0.80% 0% 0% 0% 0%

Raw Spoofed 12 6 0 1 1 0 11 0 0 0 0

Total transited 4,656 2,577 2,243 2,198 2,077 1,584 1,373 1,292 1,015 904 729

Record · ID 1122192 · SHA-256 ee118a5cd345bf30
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.