← Latest papers
💻 computer science

SatForensics: A Transformer-Based Multi-Modal Framework for Cyber-Attack Detection,Attribution, and Chain-of-Custody Forensics in Low-Earth-Orbit Satellite Communication Networks

This paper introduces SatForensics, a Transformer-based multi-modal framework that integrates satellite telemetry, RF interference, and GPS reflectometry to achieve high-accuracy cyber-attack detection and attribution while maintaining a tamper-evident chain of custody for Low-Earth-Orbit satellite networks.

Original authors: Keshav Kaushik, Mahran Al-Zyoud, Priyanka Gaur, Gaurav Rajput, Manpreet Singh, Rahul Joshi

Published 2026-09-22
📖 5 min read🧠 Deep dive

Original authors: Keshav Kaushik, Mahran Al-Zyoud, Priyanka Gaur, Gaurav Rajput, Manpreet Singh, Rahul Joshi

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The sky above us is no longer empty. It is becoming a crowded highway of thousands of small satellites, buzzing in low orbits just a few hundred miles above the Earth. These machines, part of massive constellations like Starlink and OneWeb, beam internet and communication signals to ships, planes, and remote villages. They are the invisible infrastructure of our modern world. But this new frontier brings a new kind of danger. Unlike a computer on a desk, these satellites cannot be easily reached for repairs, and their signals travel through open space where anyone with the right equipment can listen in or interfere. When a satellite is hacked, the evidence is often fleeting, scattered across different types of data, and difficult to piece together after the fact. Scientists have long struggled to build tools that can spot these attacks in real time, figure out who is responsible, and keep a secure record of what happened, all while dealing with the unique, chaotic nature of space travel.

A team of researchers has now introduced a new system called SatForensics, designed specifically to solve these problems for low-orbit satellite networks. Instead of relying on a single type of data, the system acts like a multi-sensory investigator, watching three different streams of information at once. It looks at the internal health reports of the satellite, known as housekeeping telemetry; it listens for strange radio noise that might indicate jamming or spoofing; and it watches for odd patterns in how GPS signals bounce off the Earth's surface. By feeding these three streams into a powerful computer model based on the Transformer architecture—a type of artificial intelligence known for spotting complex patterns in sequences—the system can detect an attack the moment it happens. It does not just sound an alarm; it immediately tries to identify the type of attack from five specific categories, such as signal jamming or unauthorized command injection, and then locks the evidence into a secure, unchangeable digital ledger.

The researchers tested this system using real-world data collected from three different sources: a global network of ground stations tracking amateur satellites, NASA's GPS reflection satellites, and international records of radio interference. The results were striking. In tests designed to mimic real-world conditions, SatForensics correctly identified cyber-attacks 97.6 percent of the time, a significant improvement over existing methods that rely on older technology or look at only one type of data. When the system did detect an attack, it was also able to correctly identify the specific type of threat 94.2 percent of the time. Perhaps most importantly for legal and security purposes, the system created a tamper-proof record of every event. It added a cryptographic seal to each piece of evidence in less than half a millisecond, ensuring that the record could not be altered or deleted without detection. This speed is crucial, as satellite networks generate data so fast that slower systems would fall behind.

What makes this approach different is how it handles the messy reality of space. Satellites often lose contact with the ground for short periods, or their sensors might be temporarily blinded by interference. Older systems often fail when data is missing, but SatForensics uses a "gated" mechanism that allows it to keep working even if one of its three senses goes blind. If the GPS sensor is jammed, for instance, the system automatically shifts its focus to the radio and telemetry data, maintaining its ability to spot trouble. The researchers also found that the system remained effective even when tested on satellite missions it had never seen before, proving that it can generalize its knowledge to new situations. This resilience suggests that the system is robust enough to handle the unpredictable environment of low-Earth orbit, where conditions change rapidly and data is often incomplete.

The study also addressed the difficult question of who is behind an attack. By categorizing threats into five distinct archetypes, the system moves beyond simply saying "something is wrong" to explaining exactly what is happening. It can distinguish between a simple signal jamming attempt and a more sophisticated effort to inject false data into the satellite's internal logs. This level of detail is vital for attribution, helping operators understand the nature of the threat and potentially trace it back to its source. The system achieved this high level of accuracy without requiring massive amounts of computing power, making it feasible to run on the ground stations that manage these networks. In fact, the researchers showed that with some compression, the system could even run directly on the satellites themselves, bringing advanced security to the edge of space.

While the results are promising, the authors are careful to note that this is a framework built for specific conditions and tested on available historical data. They suggest that future work will need to explore how to share threat intelligence between different satellite operators without revealing sensitive details, and how to use simulations to train the system on attack patterns that have not happened yet. For now, however, SatForensics offers a concrete step forward. It provides a way to watch the sky with multiple eyes, to understand the language of an attack, and to keep a record that cannot be erased. As our reliance on space-based technology grows, having a system that can not only see the danger but also preserve the truth of what happened becomes essential for keeping the digital world connected and secure.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →