Unmanned Aerial Vehicles (UAVs) increasingly rely on wireless communication links for command, control, and data exchange, making them vulnerable to cyber-attacks that may compromise operational safety. This paper presents a learning-based perception framework for detecting anomalous UAV communication behavior using the UAV-NIDD dataset. The proposed approach treats network traffic analysis as a cyber-perception problem, where machine learning models infer deviations from normal communication patterns in real time, and includes a mitigation strategy based on explainable AI to define suitable mitigation actions. Supervised algorithms including Random Forest, XGBoost, Support Vector Machine, and Logistic Regression are evaluated for both binary (normal vs. attack) and multi-class (attack types) intrusion detection. Experimental results demonstrate near-perfect performance in binary classification and high macro-F1 scores in multi-class scenarios, highlighting the effectiveness of tree-based ensemble models in capturing non-linear packet-level patterns. Feature importance analysis and SHAP-based explainability reveal that transport-layer attributes (e.g., UDP packet length and source port), together with wireless-layer indicators, provide strong discriminative signals for identifying malicious activity. The findings show that UAV cyber-attacks exhibit structured statistical signatures that can be effectively perceived through data-driven learning models. This work contributes toward enhancing cyber-situational awareness and strengthening safety assurance in increasingly autonomous aerial operations.
Learning-Based Perception of Cyber Anomalies in UAV Communication for Safe Autonomous Operations / Ruseno, N., Sari, F.M.T., Farina, M., Bechina, A.A.A.. - (2026), pp. 365-372. (2026 International Conference on Unmanned Aircraft Systems, ICUAS 2026 Divani Corfu Palace, grc 2026) [10.1109/ICUAS69441.2026.11598626].
Learning-Based Perception of Cyber Anomalies in UAV Communication for Safe Autonomous Operations
Farina, M.Penultimo
Writing – Review & Editing
;
2026-01-01
Abstract
Unmanned Aerial Vehicles (UAVs) increasingly rely on wireless communication links for command, control, and data exchange, making them vulnerable to cyber-attacks that may compromise operational safety. This paper presents a learning-based perception framework for detecting anomalous UAV communication behavior using the UAV-NIDD dataset. The proposed approach treats network traffic analysis as a cyber-perception problem, where machine learning models infer deviations from normal communication patterns in real time, and includes a mitigation strategy based on explainable AI to define suitable mitigation actions. Supervised algorithms including Random Forest, XGBoost, Support Vector Machine, and Logistic Regression are evaluated for both binary (normal vs. attack) and multi-class (attack types) intrusion detection. Experimental results demonstrate near-perfect performance in binary classification and high macro-F1 scores in multi-class scenarios, highlighting the effectiveness of tree-based ensemble models in capturing non-linear packet-level patterns. Feature importance analysis and SHAP-based explainability reveal that transport-layer attributes (e.g., UDP packet length and source port), together with wireless-layer indicators, provide strong discriminative signals for identifying malicious activity. The findings show that UAV cyber-attacks exhibit structured statistical signatures that can be effectively perceived through data-driven learning models. This work contributes toward enhancing cyber-situational awareness and strengthening safety assurance in increasingly autonomous aerial operations.Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


