5G Positioning: Security and Privacy Aspects 297
than the distances to the ANs in 5G. This changes the positioning geometry and therefore also capability of the monitoring to detect errors. In 5G, it is assumed that there are
also AoA estimates available, which provide even more redundancy, but also have different geometry effects to the fault detection function compared to TOA. If the number
of available measurements is smaller than 5 or the measurement geometry does not
allow positioning level integrity monitoring, the 5G positioning engine has to rely on
quality indicators produced by the measurement process in the fault detection.
In positioning mechanisms relying on a training database, such as the RSS‐based positioning or cloud GNSS (Section 13.4), the “health” of the training database, which is continuously updated, is of utmost importance. Thus, outlier detectors can be employed to
detect malicious nodes or other spurious effects in the database. Outlier detection techniques have been widely studied by the statistics and signal processing communities [69]
and similar approaches can be used to increase the training database robustness in 5G
positioning. A good survey of temporal data outliers can be found, for example in [69].
Following the classification in [69], we can divide the outlier detection schemes into:
1) Unsupervised discriminative approaches: which rely on a certain similarity metric to
identify the erroneous points in the database. Examples from this category are the
clustering methods, the rank‐based similarity methods (e.g. comparing the number
and identity of the transmitters heard in a certain location), cosine similarity methods, correlation‐based methods, etc.;
2) Unsupervised parametric approaches: which are based on building a statistical model
for the available databases and computing the probability that a certain pattern,
sequence or value belongs to the created model. Hidden Markov Modeling (HMM),
for example, belongs to this category;
3) Supervised approaches: which are valid in the presence of pilot data or some data,
which is highly reliable (e.g. data manually collected by the LISP may have more
reliability than the data collected in a crowd‐sourced mode). Examples here include
rule‐based classifiers, naive Bayes approaches or Support Vector machines (SVM).
For the estimation phase of fingerprinting, methods for detecting and removing
erroneous RSS measurements have been presented, for example in [115], where non‐
iterative RANdom SAmple Consensus (RANSAC) is adopted to detect faulty RSS, and
in [28], where an integrity monitoring method based on the “leave‐one‐out” approach
is proposed. Fingerprint database management is considered in [118], in order to keep
the crowd‐sourced database consistent and scalable. In addition of snap‐shot type of
fault detection, where only current measurements and probably the database are considered at a time, it is also possible to use the time series properties of the positioning
problem to detect anomalies in the positioning process. For this approach, the statistical prior knowledge of the user motion and position changes are used to formulate
robust filter or change detector [48].
13.8.2 Detection, Location and Estimation of Interference Signals
Interference signal sources can, according to [105], be categorized into:
1) Malicious interference: defined as radio frequency interference (RFI) intentionally
transmitted to prevent the use of the signals at hand or make the use hazardous for
as many users as possible;
than the distances to the ANs in 5G. This changes the positioning geometry and therefore also capability of the monitoring to detect errors. In 5G, it is assumed that there are
also AoA estimates available, which provide even more redundancy, but also have different geometry effects to the fault detection function compared to TOA. If the number
of available measurements is smaller than 5 or the measurement geometry does not
allow positioning level integrity monitoring, the 5G positioning engine has to rely on
quality indicators produced by the measurement process in the fault detection.
In positioning mechanisms relying on a training database, such as the RSS‐based positioning or cloud GNSS (Section 13.4), the “health” of the training database, which is continuously updated, is of utmost importance. Thus, outlier detectors can be employed to
detect malicious nodes or other spurious effects in the database. Outlier detection techniques have been widely studied by the statistics and signal processing communities [69]
and similar approaches can be used to increase the training database robustness in 5G
positioning. A good survey of temporal data outliers can be found, for example in [69].
Following the classification in [69], we can divide the outlier detection schemes into:
1) Unsupervised discriminative approaches: which rely on a certain similarity metric to
identify the erroneous points in the database. Examples from this category are the
clustering methods, the rank‐based similarity methods (e.g. comparing the number
and identity of the transmitters heard in a certain location), cosine similarity methods, correlation‐based methods, etc.;
2) Unsupervised parametric approaches: which are based on building a statistical model
for the available databases and computing the probability that a certain pattern,
sequence or value belongs to the created model. Hidden Markov Modeling (HMM),
for example, belongs to this category;
3) Supervised approaches: which are valid in the presence of pilot data or some data,
which is highly reliable (e.g. data manually collected by the LISP may have more
reliability than the data collected in a crowd‐sourced mode). Examples here include
rule‐based classifiers, naive Bayes approaches or Support Vector machines (SVM).
For the estimation phase of fingerprinting, methods for detecting and removing
erroneous RSS measurements have been presented, for example in [115], where non‐
iterative RANdom SAmple Consensus (RANSAC) is adopted to detect faulty RSS, and
in [28], where an integrity monitoring method based on the “leave‐one‐out” approach
is proposed. Fingerprint database management is considered in [118], in order to keep
the crowd‐sourced database consistent and scalable. In addition of snap‐shot type of
fault detection, where only current measurements and probably the database are considered at a time, it is also possible to use the time series properties of the positioning
problem to detect anomalies in the positioning process. For this approach, the statistical prior knowledge of the user motion and position changes are used to formulate
robust filter or change detector [48].
13.8.2 Detection, Location and Estimation of Interference Signals
Interference signal sources can, according to [105], be categorized into:
1) Malicious interference: defined as radio frequency interference (RFI) intentionally
transmitted to prevent the use of the signals at hand or make the use hazardous for
as many users as possible;
