Paper deep dive
Secure Coordination for Vertiport Sequencing in Advanced Air Mobility
Jaehan Im, Filippos Fotiadis, Ufuk Topcu, David Fridovich-Keil
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 92%
Last extracted: 7/8/2026, 6:38:11 PM
Summary
This paper addresses secure vertiport sequencing for Advanced Air Mobility (AAM) under sensing uncertainty. It proposes a robust coordination framework where a central coordinator integrates self-reported Remote-ID data with external surveillance measurements to generate separation-feasible arrival schedules. The study models two types of false reporting: self-interested misreporting, where vehicles strategically manipulate arrival times for personal gain, and malicious spoofing, where attackers inject false data to degrade system performance. By formulating sequencing as a robust design problem over surveillance-consistent uncertainty sets, the authors develop robust sequencing rules to mitigate these vulnerabilities while maintaining operational efficiency.
Entities (8)
Relation Signals (8)
Self-Interested Misreporting → modeledas → Strategic Deviation
confidence 95% · Self-interested misreporting is modeled as a strategic deviation that improves the reporting vehicle's own sequencing outcome
Malicious Spoofing → modeledas → Adversarial Disturbance
confidence 95% · malicious spoofing is modeled as an adversarial disturbance that degrades the system-level objective.
Advanced Air Mobility → requires → Vertiport Sequencing
confidence 95% · Advanced air mobility operations will require reliable coordination mechanisms for managing dense traffic near vertiports.
Remote-ID → vulnerableto → Self-Interested Misreporting
confidence 95% · Self-interested vehicles may misreport their arrival times to obtain favorable landing priority
Remote-ID → vulnerableto → Malicious Spoofing
confidence 95% · malicious actors may spoof information to disrupt sequencing decisions or induce unnecessary congestion.
Coordinator → combines → Remote-ID and Surveillance Measurements
confidence 90% · We consider a coordinator that combines self-reported Remote-ID information with externally obtained surveillance measurements to check reports and assign separation-feasible arrival schedules.
Robust Sequencing Rules → formulatedover → Uncertainty Sets
confidence 90% · We therefore formulate sequencing as a robust design problem over this uncertainty region.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Advanced air mobility operations will require reliable coordination mechanisms for managing dense traffic near vertiports. However, sequencing decisions may become vulnerable when they rely on potentially falsified self-reported information such as estimated time of arrival. Self-interested vehicles may misreport their arrival times to obtain favorable landing priority, while malicious actors may spoof information to disrupt sequencing decisions or induce unnecessary congestion. This paper studies secure coordination for vertiport sequencing under sensing uncertainty. We consider a coordinator that combines self-reported Remote-ID information with externally obtained surveillance measurements to check reports and assign separation-feasible arrival schedules. Since surveillance-based estimates are uncertain, falsified reports may remain consistent with the sensing uncertainty region and cannot always be rejected outright. We therefore formulate sequencing as a robust design problem over this uncertainty region. Self-interested misreporting is modeled as a strategic deviation that improves the reporting vehicle's own sequencing outcome, whereas malicious spoofing is modeled as an adversarial disturbance that degrades the system-level objective. The final paper will develop robust sequencing rules over surveillance-consistent uncertainty sets and evaluate their performance in representative vertiport sequencing scenarios.
Tags
Links
- Source: https://arxiv.org/abs/2605.21771v1
- Canonical: https://arxiv.org/abs/2605.21771v1
Trouble viewing inline? Open PDF directly →
Full Text
21,038 characters extracted from source content.
Expand or collapse full text
Secure Coordination for Vertiport Sequencing in Advanced Air Mobility Jaehan Im⋆111Graduate Research Assistant, Department of Aerospace Engineering and Engineering Mechanics, email: jaehan.im@utexas.edu Filippos Fotiadis⋆222Postdoctoral Researcher, Oden Institute for Computational Engineering & Sciences, email: ffotiadis@utexas.edu Ufuk Topcu333Professor, Oden Institute for Computational Engineering & Sciences, email: utopcu@utexas.edu and David Fridovich-Keil444Assistant Professor, Department of Aerospace Engineering and Engineering Mechanics, email: dfk@utexas.edu Abstract Advanced air mobility operations will require reliable coordination mechanisms for managing dense traffic near vertiports. However, sequencing decisions may become vulnerable when they rely on potentially falsified self-reported information such as estimated time of arrival. Self-interested vehicles may misreport their arrival times to obtain favorable landing priority, while malicious actors may spoof information to disrupt sequencing decisions or induce unnecessary congestion. This paper studies secure coordination for vertiport sequencing under sensing uncertainty. We consider a coordinator that combines self-reported Remote-ID information with externally obtained surveillance measurements to check reports and assign separation-feasible arrival schedules. Since surveillance-based estimates are uncertain, falsified reports may remain consistent with the sensing uncertainty region and cannot always be rejected outright. We therefore formulate sequencing as a robust design problem over this uncertainty region. Self-interested misreporting is modeled as a strategic deviation that improves the reporting vehicle’s own sequencing outcome, whereas malicious spoofing is modeled as an adversarial disturbance that degrades the system-level objective. The final paper will develop robust sequencing rules over surveillance-consistent uncertainty sets and evaluate their performance in representative vertiport sequencing scenarios. †footnotetext: ⋆Equal contribution 1 Nomenclature N = number of vehicles approaching the vertiport i = vehicle index, i∈1,…,Ni∈\1,…,N\ τi _i = true estimated time of arrival of vehicle i before sequencing intervention τ^i τ_i = reported estimated time of arrival of vehicle i τ~i τ_i = surveillance-inferred estimated time of arrival of vehicle i δi _i = reporting deviation of vehicle i, where τ^i=τi+δi τ_i= _i+ _i δ = vector of reporting deviations, δ=(δ1,…,δN)δ=( _1,…, _N) δ−i _-i = reporting deviations of all vehicles except vehicle i iU_i = uncertainty-consistent feasible falsification set for vehicle i εi _i = bound on arrival-time estimation uncertainty for vehicle i aia_i = assigned arrival time of vehicle i after sequencing smins_ = minimum required temporal separation between consecutive arrivals JiJ_i = schedule-adjustment cost of vehicle i JsysJ_sys = system-level sequencing cost ℳM = set of vehicles whose reports are treated as potentially false θ = robustification parameter for the sequencing rule SθS_θ = parameterized sequencing rule that maps reported arrival times to an assigned arrival schedule Sθ,iS_θ,i = assigned arrival time of vehicle i, i.e., the iith component of SθS_θ 2 Introduction Advanced air mobility (AAM) will require reliable coordination mechanisms for managing dense traffic near vertiports. As multiple vehicles approach a shared landing facility, sequencing decisions must be made under limited landing capacity, local congestion, and uncertain arrival-time information. Broadcast-based information, such as Remote-ID, can support this coordination by providing vehicle identity, position, and other operational data. However, such coordination mechanisms become vulnerable when they rely on self-reported information. Self-interested vehicles may strategically manipulate their reported states or arrival times to obtain more favorable sequencing outcomes. Moreover, because Remote-ID is not inherently spoofing-proof, the same coordination infrastructure may also be exposed to adversarial attacks that aim to induce unnecessary congestion, disrupt sequencing decisions, or increase collision risk [1, 2]. While related vulnerabilities are already recognized in conventional air traffic management [3, 4, 5, 6], we expect them to become more pronounced in AAM operations, where higher traffic density and tighter sequencing margins increase the operational impact of false information. This vulnerability of AAM to false reporting is particularly relevant in vertiport sequencing. When several vehicles are expected to arrive within a similar time window, even a small change in reported estimated time of arrival can affect the assigned landing order [6, 4, 5]. This order then determines the separation-feasible arrival schedule issued by the coordinator. As a result, a vehicle that moves earlier in the sequence may receive a reassigned arrival time closer to its preferred plan, whereas other vehicles may be delayed or required to adjust their approach. Thus, false reporting can transfer delay or adjustment burden to other vehicles and undermine the reliability of the sequencing mechanism. A natural defense is to compare self-reported information with independently obtained measurements. In this work, we assume that a coordinator is equipped with an active surveillance system, similar to conventional air traffic management systems [7, 8, 9], that estimates vehicle positions and uses these estimates to infer vehicle arrival times. Unlike self-reported Remote-ID information, these externally obtained measurements are therefore not directly affected by falsified Remote-ID reports. However, surveillance-based estimates are not perfect [8, 9]. Measurement noise and estimation error create uncertainty in the inferred vehicle state and arrival time. Consequently, surveillance does not eliminate manipulation; it only restricts feasible falsification to reports that remain consistent with the uncertainty region. This limited detectability creates a strategic coordination problem. A strategic vehicle or malicious attacker may choose the most advantageous false report within the uncertainty-consistent set, while the coordinator must decide how such reports should affect the landing sequence. We investigate secure coordination for AAM vertiport sequencing under sensing uncertainty by considering two sources of false reporting. The first is strategic misreporting by self-interested vehicles, whose objective is to improve their own assigned arrival time or reduce their own schedule-adjustment cost. The second is malicious spoofing by an external attacker, whose objective is not to improve the outcome of a particular vehicle but to degrade the overall sequencing performance. To address these two sources, we formulate robust sequencing problems over surveillance-consistent uncertainty sets. For self-interested misreporting, the false report is modeled as a strategic deviation selected to improve the reporting vehicle’s own sequencing outcome. For malicious spoofing, the false report is modeled as an adversarial disturbance selected to degrade the system-level sequencing objective. These formulations allow the coordinator to protect sequencing decisions against potentially false reports while preserving the distinction between self-interested and malicious false-reporting behaviors. 3 Vertiport Sequencing Problem We consider a set of N vehicles approaching a shared vertiport. Each vehicle i∈1,…,Ni∈\1,…,N\ has a true estimated time of arrival τi _i, which represents the arrival time expected under its current approach plan before sequencing intervention. The coordinator receives a reported arrival time τ^i=τi+δi, τ_i= _i+ _i, (1) where δi _i denotes the reporting deviation. A truthful report corresponds to δi=0 _i=0, whereas δi≠0 _i≠ 0 represents false reporting. Negative values of δi _i correspond to reports that claim an earlier arrival time. The coordinator also receives surveillance-based measurements, which are used to infer an independent estimate of the vehicle’s arrival time. Because these measurements are uncertain, false reports may not always be distinguishable from truthful reports. We represent the feasible falsification region for vehicle i by an uncertainty set δi∈i, _i _i, (2) where iU_i contains the deviations that remain consistent with the surveillance uncertainty. For example, iU_i may be represented by an interval [−εi,εi][- _i, _i], where εi _i captures the uncertainty in arrival-time estimation from surveillance data. Reports outside this set can be rejected as inconsistent with the independent measurements, whereas reports inside this set cannot be identified as false. Given the reported arrival times, the coordinator assigns a landing sequence and constructs a separation-feasible arrival schedule. Let ai∈ℝa_i denote the assigned arrival time for vehicle i after sequencing. Each vehicle incurs an adjustment cost relative to its true arrival plan, Ji(ai,τi)=(ai−τi)2.J_i(a_i, _i)=(a_i- _i)^2. (3) This cost captures the operational burden of requiring a vehicle to arrive earlier or later than its original arrival plan. However, the coordinator does not directly observe τi _i and instead computes the nominal schedule using the reported arrival time τ^i τ_i. The reported system-level sequencing cost is therefore Jsys(a,τ^)=∑i=1NJi(ai,τ^i).J_sys(a, τ)= _i=1^NJ_i(a_i, τ_i). (4) The coordinator computes a separation-feasible arrival schedule by solving mina _a ∑i=1NJi(ai,τ^i) _i=1^NJ_i(a_i, τ_i) (5) s.t. ai+1−ai≥smin,i=1,…,N−1, a_i+1-a_i≥ s_ , i=1,…,N-1, where we index the vehicles according to the assigned landing order for notational simplicity, and smins_ denotes the minimum required temporal separation between arrivals. False reporting or spoofing affects this optimization by changing the reported arrival-time information used to determine the landing order and, consequently, the separation-feasible assigned arrival times. A false report can therefore alter both an individual vehicle’s adjustment cost and the total system-level sequencing cost. 4 Secure Coordination and Future Plans 4.1 Sources of false information We consider two sources of false information in vertiport sequencing. The first is self-interested misreporting. In this case, a vehicle manipulates its reported estimated time of arrival to improve its own sequencing outcome after observing the coordination rule; for example, it may report an earlier arrival time to obtain an earlier landing slot. The second source is malicious spoofing. In this case, vehicles are assumed to report truthfully, but an external attacker injects false information with the objective of degrading system-level sequencing performance. Unlike a self-interested vehicle, the attacker is not modeled as minimizing the cost of a particular vehicle. Instead, the attacker seeks reports that produce unfavorable sequencing outcomes, such as unnecessary congestion, increased delay, disrupted arrival ordering, or increased operational risk. This distinction leads to two robust coordination models. Self-interested misreporting is modeled as a strategic response to the coordination rule, whereas malicious spoofing is modeled as adversarial information injection against the system-level sequencing objective. In both cases, the coordinator protects the sequencing decision against false reports that remain consistent with the surveillance uncertainty region. 4.2 Surveillance-consistent uncertainty sets Using the uncertainty-set model introduced in Section˜3, we let ℳ⊆1,…,NM \1,…,N\ denote the set of vehicles whose reports are treated as potentially false, i.e., not fully trusted. For each vehicle i∈ℳi , the coordinator protects the sequencing decision against surveillance-consistent deviations δi∈i _i _i, where iU_i is defined in Equation˜2. For vehicles outside ℳM, the coordinator uses the reported arrival time directly, as in the nominal sequencing problem Equation˜5. In this extended abstract, we treat ℳM as given. In the complete paper, we will study how this set can be selected from reported arrival-time patterns, surveillance measurements, and operational risk indicators. 4.3 Robust formulations for false reporting Let SθS_θ denote a parameterized sequencing rule that maps reported arrival times to an assigned arrival schedule, a=Sθ(τ^).a=S_θ( τ). (6) The nominal coordination problem in Equation˜5 corresponds to the baseline case θ=θ0θ= _0, where vehicles are sequenced directly from the reported arrival times. In the robust setting, θ represents robustification parameters, such as report-confidence thresholds, detection effort, or uncertainty-reduction rules for vehicles in ℳM. The coordinator selects θ to steer the sequencing outcome so that it becomes less sensitive to surveillance-consistent false reports. For self-interested misreporting, a potentially false-reporting vehicle is modeled as selecting a feasible report that improves its own sequencing outcome after observing the coordination rule. This interaction has a Stackelberg structure: the coordinator first specifies the robustification parameter θ, and each self-interested vehicle then chooses a surveillance-consistent report in response. Since vehicle i knows its true arrival time τi _i but observes only the reported arrival times of the other vehicles, its false-reporting behavior can be modeled as δi⋆(θ)∈argminδi∈iJi(Sθ,i(τi+δi,τ^−i),τi),i∈ℳ. _i (θ)∈ _ _i _iJ_i\! (S_θ,i( _i+ _i, τ_-i), _i ), i . (7) Here, δi⋆(θ) _i (θ) emphasizes that the self-interested reporting decision is a best response to the announced coordination rule parameter θ. The coordinator then seeks a robust sequencing parameter that accounts for these individually beneficial deviations. Let δℳ⋆(θ) _M (θ) denote the vector collecting the self-interested deviations δi⋆(θ) _i (θ) for all i∈ℳi , with zero entries for vehicles outside ℳM. The corresponding robust sequencing problem is minθ _θ ∑i=1NJi(Sθ,i(τ+δℳ⋆(θ)),τi) _i=1^NJ_i\! (S_θ,i(τ+ _M (θ)), _i ) (8) s.t. Sθ,i+1(τ+δℳ⋆(θ))−Sθ,i(τ+δℳ⋆(θ))≥smin,i=1,…,N−1. S_θ,i+1(τ+ _M (θ))-S_θ,i(τ+ _M (θ))≥ s_ , i=1,…,N-1. Here, τ+δℳ⋆(θ)τ+ _M (θ) denotes the reported-time vector induced by the self-interested deviations of vehicles in ℳM. For malicious spoofing, false reports are modeled as adversarial disturbances selected to degrade the system-level sequencing outcome. In this model, vehicles themselves are assumed to report truthfully. The corresponding robust coordination problem is minθmaxδi∈i,i∈ℳ _θ _ _i _i,\ i ∑i=1NJi(Sθ,i(τ+δℳ),τi) _i=1^NJ_i\! (S_θ,i(τ+ _M), _i ) (9) s.t. Sθ,i+1(τ+δℳ)−Sθ,i(τ+δℳ)≥smin,i=1,…,N−1, S_θ,i+1(τ+ _M)-S_θ,i(τ+ _M)≥ s_ , i=1,…,N-1, where δℳ _M denotes the vector of adversarial deviations over vehicles in ℳM, again with zero entries outside ℳM. This formulation captures an attacker that selects uncertainty-consistent false reports to worsen the total sequencing outcome. Together, these formulations address different false-reporting behaviors through robust sequencing. The self-interested model protects against individually beneficial false reports, whereas the malicious model protects against worst-case system-level disruption. 4.4 Planned Numerical Study In the complete version of the paper, we will evaluate the effect of secure coordination through numerical vertiport sequencing scenarios. The goal is to quantify the nominal efficiency loss caused by adding robustness and the security benefit obtained under false reporting. We will compare baseline sequencing, self-interested robust sequencing, and malicious robust sequencing under truthful and falsified reporting conditions. Table 1: Planned experiment cases. Case Reporting condition Coordination rule Evaluation purpose 1 Truthful reporting Baseline sequencing Evaluate nominal efficiency loss due to robust secure coordination 2 Truthful reporting Self-interested robust sequencing 3 Truthful reporting Malicious robust sequencing 4 Self-interested misreporting Baseline sequencing Evaluate security benefit under false reporting 5 Self-interested misreporting Self-interested robust sequencing 6 Malicious spoofing Baseline sequencing 7 Malicious spoofing Malicious robust sequencing The truthful-reporting cases will show the efficiency cost of robustness, since robust schedules may be more conservative than the baseline schedule. The false-reporting cases will show the security benefit of robustness by comparing how much delay, schedule-adjustment cost, and sequencing disruption are reduced when robust sequencing is used. We will also conduct sensitivity studies with respect to traffic density, arrival-time separation, surveillance noise, and the size of the potentially false-reporting set ℳM. These studies will identify when secure coordination provides the largest benefit and how accurate the surveillance system must be for the proposed approach to remain effective. As a future extension, we will study surveillance resource allocation as a mechanism for reducing false-reporting vulnerability. In this extension, the coordinator allocates limited surveillance resources, such as sensing time, resolution, or power, across vehicles to reduce the uncertainty sets of selected vehicles. This allocation can be viewed as part of the robustification parameter θ, which steers the sequencing rule by changing the effective uncertainty region. This would allow the coordinator to harden sequencing decisions around vehicles that are more likely to provide false information. References Bjorkman et al. [2026] Bjorkman, B., Zheng, S., Coursey, A., Lemieux-Mack, C., Gonzalez, S., Diaz-Gonzalez, A., Dahle, N. W., Koroma, N., Canady, R. E., Koutsoukos, X., Biswas, G., Taye, A., and Ward, B., Remote ID Spoofing Attacks and Defenses, 2026. 10.2514/6.2026-2665. Keizer et al. [2024] Keizer, M., Sciancalepore, S., and Oligeri, G., “Ghostbuster: Detecting misbehaving remote id-enabled drones,” 2024 IEEE 21st Consumer Communications & Networking Conference (CCNC), IEEE, 2024, p. 324–332. SKYbrary [2022] SKYbrary, “Pilot-Controller Communications (OGHFA BN),” , 2022. URL https://skybrary.aero/articles/pilot-controller-communications-oghfa-bn, sKYbrary Aviation Safety, accessed 2026-05-19. Eurocontrol [2020] Eurocontrol, “Environmental Assessment: European ATM Network Fuel Inefficiency Study,” Network Manager, Brussels, 2020. Hirte et al. [2026] Hirte, G., Jaekel, J., and Niemeier, H.-M., “Horizontal approach flight efficiency and emissions at the lower airspace,” Journal of Air Transport Management, Vol. 132, 2026, p. 102936. Robinson et al. [2010] Robinson, M., Reynolds, H. D., and Evans, J. E., “Traffic management advisor (TMA) weather integration,” 14th Conference on Aviation, Range, and Aerospace Meteorology, 2010. Federal Aviation Administration [2024] Federal Aviation Administration, “Aeronautical Information Manual, Chapter 4, Section 5: Surveillance Systems,” https://w.faa.gov/air_traffic/publications/atpubs/aim_html/chap4_section_5.html, 2024. Accessed 2026-05-19. Eurocontrol [1997] Eurocontrol, “Eurocontrol Standard for Radar Surveillance in En-Route Airspace and Major Terminal Areas,” Tech. Rep. SUR.ET1.ST01.1000-STD-01-01, European Organisation for the Safety of Air Navigation, Brussels, Belgium, Mar. 1997. Weber et al. [2014] Weber, M., Wood, M., Franz, J., Conway, D., and Cho, J., “Secondary Surveillance Phased Array Radar (SSPAR): Initial Feasibility Study,” Lincoln Laboratory, Massachusetts Institute of Technology: Lexington, MA, USA, 2014.