All techniques
EX-0014.03
ST0004Execution
sub-technique

Sensor Data

Parent: EX-0014

Description

The attacker presents fabricated or biased measurements that estimation and control treat as ground truth. Targets include attitude/position sensors (star trackers, gyros/IMUs, sun sensors, magnetometers, GNSS), environmental and health sensors (temperatures, currents, voltages, pressures), and payload measurements used in autonomy. Spoofs may be injected electrically at interfaces, optically (blinding/dazzling trackers or sun sensors), magnetically, or by crafting packets fed into sensor gateways. Even small, consistent biases can drive filters to incorrect states; stepwise changes can trigger fault responses or mode switches. Downstream, timestamps, quality flags, and derived products inherit the deception, creating uncertainty for operators and potentially inducing temporary loss of service as autonomy reacts to a world that never existed.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on sensor-data interfaces resists fabricated-measurement injection between sensors and FSW.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    derived

    Security testing of estimation pipelines and outlier-rejection logic surfaces fragility that fabricated sensor data exploits.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Sensor-data integrity is part of network-and-information-system properties under 84(2)'s Annex VII point 5.1; spoofed sensor frames at gateways must be filtered.

  • eu-space-actArt. 84(3)
    addresses
    moderate
    direct

    84(3)'s authorized-devices rule governs sensor gateways — limiting which sensor sources can write into estimation/control pipelines.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Sensor-derived state inconsistencies (estimator divergence, abrupt mode transitions, contradictions between fused sources) are detectable via cross-correlation; Art. 21(2)(b)'s incident-handling capability must surface those anomalies even when individual readings pass sanity checks.

  • nis2-implAnnex 6.5.1
    addresses
    moderate
    derived

    Security testing of estimation pipelines, sensor-fusion sanity checks and outlier-rejection logic surfaces fragility that fabricated sensor data exploits.

  • nis2-implAnnex 6.5.2
    addresses
    high
    derived

    Sensor-data-spoofing testing scope (sensor-fusion sanity checks, outlier-rejection logic, estimator robustness under fabricated measurements) is what Annex 6.5.2 requires the entity to define for its security-testing policy.

  • nis2-implAnnex 6.5.3
    addresses
    moderate
    derived

    Sensor-data spoofing reaches estimation and control through several distinct injection surfaces (electrical interfaces, optical blinding of trackers, magnetic, and crafted packets at sensor gateways), so the planned-interval review obligation in Annex 6.5.3 is the duty that keeps the testing policy's coverage current as those surfaces are characterized. The obligation is to review and where appropriate update the testing policy itself, which is governance over what gets tested rather than detection of the fabricated measurements, supporting an addresses relationship at moderate confidence.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the protection of sensor-data interfaces between sensors and FSW; integrity protection on those interfaces resists fabricated-measurement injection.

ENISA controls

  • Real-time physics-model verification of sensor inputs to bus and payload is the named defense against fabricated/biased measurements.

  • Anomaly detection with established baseline and event correlation flags consistent biases or stepwise sensor changes that EX-0014.03 introduces.

  • Reinforcement-learning agents detecting anomalous events and ignoring malicious data are an explicit control against fabricated sensor measurements.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0014.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.