Featured · Currently building
AegisFlight
ML-based intrusion detection for drones
AI/ML Software Systems Security
- Python
- scikit-learn
- NumPy
- Pandas
- pymavlink
- FastAPI
- WebSockets
- React
- pytest
An explainable intrusion-detection system for drones commanded over MAVLink 2. Four independent detectors watch the telemetry and command link; an evidence-fusion engine turns what they see into one severity-rated alert that says why it fired. Security is the problem it watches for — but machine learning, systems work and a real backend are what it's built from.
Problem
A drone trusts its telemetry and command link. GPS spoofing, forged telemetry, injected commands, link flooding and tampered firmware each leave different traces — and a single classifier trained on simulated attacks risks learning the simulator instead of the attack. Operators also need to know why an alert fired, not just that it did.
Approach
- Input Simulated flight emitting MAVLink 2, with injected attacks
- Features Decoded into 11 online features: network, navigation, sensor, command
-
Detectors
- Protocol rules
- Physics consistency
- ML anomaly
- Firmware integrity
- Fusion Severity, attack class and evidence per decision
- Output Hash-chained event log · FastAPI / WebSocket · React dashboard
HIGH · GPS_SPOOFING — position residual > 12 m (reported track
diverges from velocity)
How each detector works
- Protocol rules — message rate, sequence gaps, rogue sources, liveness and command provenance.
- Physics consistency — cross-checks physically coupled signals: position against the velocity-implied track, GPS against barometric altitude, heading against course, battery dynamics. Needs no attack data.
- ML anomaly detection — an Isolation Forest + Mahalanobis ensemble trained only on benign flights.
- Firmware integrity — SHA-256 manifest verification.
- Evidence fusion — alerts carry human-readable evidence, are written to a SHA-256 hash-chained log, and stream to the dashboard over WebSockets.
How it's evaluated
-
Leakage control
Session-level splits, and the anomaly model never sees an attack during training.
-
Reproducibility
Scripted benchmark across multiple random seeds and attack scenarios — 23k+ scored decisions. Results come straight from the scripts; nothing is hand-entered.
-
Ablation
The same benchmark with ML switched off, to isolate what the model actually adds.
-
Real flights
Public PX4 and ALFA flight logs replayed through the pipeline for false-alarm analysis.
-
Sim-to-real shift
Kolmogorov–Smirnov tests measure how far real telemetry features drift from the simulator's.
-
Tests
pytest suite across unit, integration, end-to-end and API paths.
Status
Stage 1 submitted; development is ongoing. Results so far come from a reproducible local simulation, so detection of real attacks has not been validated yet — the real-log replay exists to show where simulator-tuned thresholds stop transferring. Next: live MAVLink ingestion, then SITL and hardware-in-the-loop validation.