ANALYSIS · CYBERSECURITY · SPECTRUM

The electromagnetic spectrum as an attack surface

From signal physics to cyber-physical trust: electromagnetic warfare, autonomous systems and collective resilience

Author
Abdoul Karim Mamani Malam Goga
Published
12 September 2026
Reading time
15 minutes

ABSTRACT

Digital societies rely on an infrastructure that users rarely perceive: the electromagnetic spectrum. Mobile communications, microwave links, satellite systems, radar, GNSS navigation, telemetry, time synchronisation, drones, sensor networks and autonomous systems all use electromagnetic waves, directly or indirectly.

This dependence is gradually changing the nature of risk. Radio security has historically focused on frequency availability, link quality, electromagnetic compatibility and the control of harmful interference. Those dimensions remain fundamental, but they are no longer sufficient when spectrum-derived information feeds a position estimate, environmental perception, critical synchronisation or an automated decision.

In this article, I argue that the spectrum has become a genuine trust layer for some digital and cyber-physical architectures. The challenge is no longer limited to preventing a link from being interrupted. It also involves preventing an electromagnetic disturbance from being transformed into plausible but incorrect data, then into a false perception and ultimately into a wrong decision.

This perspective connects the physical foundations of radio links, interference and deception, PNT security, multi-sensor fusion, resilient estimation, cyber-electromagnetic convergence, cognitive electromagnetic warfare and regional resilience. In the context of the Confederation of Sahel States, it also raises the question of a coordinated electromagnetic situational-awareness capability grounded in national sovereignty, correlation and mutual warning.

Keywords: electromagnetic spectrum, electromagnetic warfare, cybersecurity, radio frequencies, GNSS, PNT, cyber-physical systems, multi-sensor fusion, electromagnetic resilience, AES.

02

The spectrum is shared: interference is part of the normal problem

Several systems may use the spectrum simultaneously in nearby locations and adjacent bands. Spectrum management exists precisely to make this coexistence possible. Under real conditions, a receiver never obtains only the signal of interest. A deliberately simplified model is:

r(t)=s(t)+i(t)+n(t)

In this expression, s(t) is the useful signal, i(t) represents interfering contributions and n(t) represents noise. The receiver must extract useful information from this environment. When interference becomes excessive, throughput may fall, errors may increase, synchronisation may become unstable and the service may eventually disappear.

Interference is not necessarily an attack. It can result from faulty equipment, poor planning, unwanted emissions, unusual propagation, cross-border coordination issues or the normal densification of uses. Observing an electromagnetic anomaly does not by itself establish hostile intent.

Spectrum monitoring is therefore essential. It makes it possible to measure, identify and characterise emissions, verify spectrum use and help resolve interference. Security begins with understanding what is normal in the electromagnetic environment; without that baseline, accidental disturbance and deliberate action are difficult to distinguish.

03

When the spectrum becomes an attack surface

The transition from interference to electromagnetic warfare introduces intentionality. NATO now favours the term Electromagnetic Warfare, emphasising the entire electromagnetic environment and spectrum. Its effects may concern communications, radar, navigation and detection functions.

Several outcomes must be distinguished. Denial makes a resource unavailable. Degradation allows the service to continue with reduced quality, accuracy or availability. Deception is subtler: the system still receives information and may regard it as valid even though it no longer represents reality correctly.

An outage is often visible and may trigger an alarm or fallback mode. Plausible but false information can continue through the processing chain, be accepted by the receiver, converted into data, fused with other observations and ultimately drive an action.

A failure is often visible; plausible but false information can continue through the entire processing chain.

04

The spectrum as the first layer of a trust chain

The issue becomes clearer when we consider the full path between an electromagnetic wave and a digital decision: spectrum, signal, receiver, data, estimation, fusion, decision and action. At every transition, information changes form.

Applications rarely use the raw physical signal. They use a digital representation derived from it. Even with protected software, controlled access, intact firmware and authenticated networks, a system can make the wrong decision if its physical inputs no longer correspond sufficiently to the real world.

I call this the cyber-electromagnetic chain of trust. The concept does not merge cybersecurity and radio artificially; it recognises that a weakness at the physical layer can cross several transformations before producing a software or physical effect.

Cyber-electromagnetic chain of trust
SpectrumPhysical environmentSignalElectromagnetic informationReceiverRF conversion / processingDataDigital informationEstimationState reconstructionFusionCross-checking sourcesDecisionProcessing algorithmiqueActionPhysical or operational effect
An electromagnetic disturbance introduced at the physical layer may produce its real effect several stages later, at the perception or decision layer.

05

PNT: when signal presence no longer guarantees information integrity

Positioning, Navigation and Timing systems provide the clearest illustration. GNSS constellations do more than display a position: they provide navigation and timing references on which telecommunications, distributed infrastructures and other critical functions may depend.

NIST explicitly treats PNT services as a cybersecurity dependency. Its Foundational PNT Profile addresses the identification of dependencies, protection, anomaly detection, response and recovery. Civil aviation likewise shows that the issue is operational: EASA and EUROCONTROL have documented increasing GNSS jamming and spoofing and updated mitigation guidance in 2026.

Jamming and deception must be distinguished. Loss of position can be detected; a coherent but false position may continue to guide decisions.

“Am I receiving something?” is not the same as “Can I still trust what I infer from it?”

06

Autonomous systems: when signal disruption becomes perception disruption

A drone, robot or autonomous vehicle does not fundamentally seek a GNSS signal or a radar value. It seeks to reconstruct a state: position, orientation, speed, obstacle location or environmental dynamics. A simplified observation model is:

z=h(x)+v+a

Here, x is the real state, h(x) the theoretical sensor observation, v normal measurement uncertainty and a an additional abnormal or potentially adversarial contribution. The system does not observe reality directly; it reconstructs it from measurements.

This distinction opens the field of resilient estimation. Fawzi, Tabuada and Diggavi showed, for the linear systems they studied, that state reconstruction can remain possible under certain conditions even when some sensors or actuators are corrupted. Pajic, Lee and Pappas extended this reasoning to noisy dynamic systems under attack.

Multi-sensor fusion can then confront several representations of the same world: GNSS with inertial navigation, radar with cameras, or trajectories derived from independent physical phenomena. I describe perceptual resilience as the ability to maintain a usable representation of reality when some information sources become unavailable, uncertain or potentially deceptive.

Redundancy is not the same as diversity. Three sensors sharing the same external GNSS dependency are not necessarily three independent sources. The objective is not merely to add sensors, but to organise confidence across genuinely different sources.

07

Cyber and electromagnetic domains: distinct domains with converging effect chains

A cyberattack and an electromagnetic action are not the same. NATO distinguishes cyber operations from electromagnetic operations: the former act within digital systems, while the latter exploit the electromagnetic environment.

Modern systems nevertheless make their effects interdependent. A radio may contain firmware, programmable components, DSP functions, an operating system and network configuration. A cyber vulnerability can alter radio behaviour without an initially hostile RF signal. Conversely, an RF disturbance may compromise no software component while producing data later consumed by software.

I therefore use cyber-electromagnetic convergence to describe a convergence of effect chains, not a doctrinal fusion of the two domains. Protecting the complete system requires understanding the continuity between physical interactions and digital processing.

08

Artificial intelligence and the emergence of more cognitive electromagnetic warfare

The electromagnetic environment is increasingly dynamic. Traditional architectures can compare observations with known signature libraries and apply predefined rules, but this approach reaches its limits when waveforms adapt, behaviours change rapidly and signal density grows.

Cognitive Electronic Warfare describes an evolution towards systems with more autonomous capabilities for sensing, interpretation, reasoning and adaptation. Machine learning may improve signal classification and environmental understanding, but it also introduces new dependencies on observations, extracted features, models and adaptation mechanisms.

A system that learns from its environment can potentially be led to learn an incorrect representation of that environment. The confrontation may then shift from a frequency or power contest towards an interaction between mechanisms of perception, decision and adaptation. This connects electromagnetic security with adversarial machine learning, estimation and game-theoretic reasoning at a conceptual level.

NATO DIANA’s 2026 challenge on contested electromagnetic environments illustrates the demand for resilient communications, navigation and surveillance, alternative navigation and more intelligent spectrum management. These ideas remain defensive and conceptual here; they do not provide operational parameters for designing or optimising interference systems.

09

From spectrum monitoring to electromagnetic situational awareness

A monitoring station can detect an emission, measure its level, analyse characteristics and sometimes contribute to location. A single observation remains ambiguous: equipment failure, non-compliant use, propagation, local interference or deliberate action can all be possible explanations.

Correlation changes the analytical value. Compatible events observed by geographically separated, synchronised stations within a related period provide more context than isolated measurements. Value emerges from interoperability, temporal and geographic context and shared event descriptions, not only from sensor quality.

Spectrum monitoring asks: ‘What am I observing here?’ Electromagnetic situational awareness asks: ‘What do observations made at different places and times mean together?’ This broader interpretation must preserve a crucial discipline:

Detection ≠ attribution

An anomaly can be detected without immediately determining whether its origin is accidental or deliberate, civilian or military. That distinction prevents a technical monitoring capability from becoming a mechanism for over-interpreting events.

10

Regional cooperation already has a technical foundation in Africa

Cross-border spectrum cooperation already exists on the continent. The HCM4A Agreement, developed through work involving the ITU and African Union, coordinates frequencies for fixed and land-mobile services, helps prevent harmful interference and improves shared spectrum use. Niger, Mali and Burkina Faso are participating administrations.

This framework is primarily regulatory, but it establishes an important principle: a radio event observed in one country may have causes or effects beyond its borders. ICAO work on GNSS interference adds a further step. In March 2026, an AFI regional workshop addressed procedures for reporting GNSS radio-frequency interference events.

A logical progression therefore appears: frequency coordination, event sharing, then regional correlation. This creates a technical bridge towards the question of electromagnetic resilience in the Sahel.

11

AES: from resource pooling to coordinated electromagnetic awareness

The Confederation of Sahel States is built around sovereignty, solidarity and collective capacity. Official presentations describe three pillars—Defence, Diplomacy and Development—and a transition from a defence pact to a sovereign confederation. Official publications also document the Unified Force and the pooling of air-force resources.

This raises a technically legitimate question: could the same philosophy support a coordinated electromagnetic situational-awareness capability? This is my personal conceptual proposal; it does not describe an existing, unpublished confederal capability.

A federated architecture would be consistent with sovereignty. Each State would retain its national stations, sensitive technical information, monitoring capabilities and institutional responsibilities. Confederal value would arise from sharing a sufficiently characterised event when it has cross-border relevance: detection time, affected area and band, probable phenomenon, observed impact and analytical confidence.

Raw RF data would not necessarily leave the collecting State. The sequence would be national observation, national analysis, normalised event, AES correlation and shared warning. An anomaly observed in Mali could alert Burkina Faso and Niger; simultaneous observations could be qualified with greater confidence; aviation reports could be compared with telecommunications or national spectrum-monitoring observations.

Mutual detection could therefore become mutual early warning and, with common doctrine, collective resilience. The starting point need not be expensive new equipment. It can begin with common terminology, reliable synchronisation, compatible data formats, comparable confidence levels and shared notification procedures.

Coordination can produce information that did not exist in any individual State.
Federated electromagnetic-awareness architecture
NigerNational stations · Monitoring · Telecommunications · PNT · Aviation · Other authorised sourcesNational analysisRaw data retained by the State
MaliNational stations · Monitoring · Telecommunications · PNT · Aviation · Other authorised sourcesNational analysisRaw data retained by the State
Burkina FasoNational stations · Monitoring · Telecommunications · PNT · Aviation · Other authorised sourcesNational analysisRaw data retained by the State
Normalised eventsAES correlationShared warning · situational awareness
A federated architecture could build shared awareness without requiring systematic centralisation of raw radio data.

12

Thinking about the Sahelian cyberspace also means examining its electromagnetic infrastructure

This reasoning directly complements my forthcoming book, Le cyberespace sahélien, un nouveau front. Cyberspace is often associated with information systems, IP networks, cloud platforms and data, but it has a physical infrastructure. Mobile networks use spectrum, microwave links carry traffic, satellites provide communications, digital systems depend on GNSS references and connected equipment exchanges information wirelessly.

Part of digital sovereignty therefore rests on an electromagnetic infrastructure that is less visible than data centres or IP networks but just as structural. My book addresses threats, dependencies and sovereignty at a strategic Sahelian scale; my parallel work on cyber-electromagnetic security moves towards physical and cyber-physical layers such as spectrum, radio, PNT, resilience and autonomous systems.

These levels should not be confused, but they answer the same underlying question: which dependencies actually support our digital capacity for action, and how can that capacity be maintained when those dependencies are contested?

C

Conclusion: protecting not only the signal, but the reality constructed from it

The electromagnetic spectrum is invisible, and so is much of its contribution to digital society. Yet a considerable share of our infrastructure depends on transmitting, receiving, measuring and interpreting electromagnetic phenomena correctly.

A frequency is not merely a value in hertz, a channel is not merely an assigned resource, and a radio link is not merely a connection between two antennas. They can become the first components of a chain connecting the physical world to a digital decision.

Electromagnetic warfare shows that the radio environment can be deliberately contested. PNT shows that a system may continue operating while the integrity of its estimate deteriorates. Autonomous systems show that incorrect data can become incorrect perception and then physical action. Multi-sensor fusion shows that part of the response lies in observation diversity and dynamic confidence reassessment.

At a wider scale, a national monitoring station observes part of the environment; coordinated stations produce better knowledge; States that share and correlate selected events can begin to build regional resilience. An AES capability could therefore begin with doctrine, definitions, formats, trust between sources and interoperability—then correlation, warning and resilience.

The central challenge is no longer only to protect spectrum from interference or a signal from jamming. It is to protect the chain connecting spectrum, signal, information, perception and decision. In cyber-physical and autonomous systems, protecting computation will no longer be enough; we must also preserve confidence in the reality from which the machine computes.

Further reading

This reflection forms one of the themes of my forthcoming work, Cyber-Electromagnetic Security of Radio Infrastructures: Spectrum, Resilience, Threats and Autonomous Systems.

I will examine radio-infrastructure security, spectrum dependencies, PNT resilience, spectrum monitoring and situational awareness, cyber-electromagnetic convergence, multi-sensor fusion, autonomous systems and the shift towards more adaptive detection and decision mechanisms.

This work extends, at a more technical level, the reflection begun in Le cyberespace sahélien, un nouveau front: understanding the infrastructures and dependencies from which the Sahel can build digital sovereignty and maintain its capacity for action when those infrastructures are contested.

Public sources and key references

International Telecommunication Union (ITU): Radio Regulations; spectrum definition and management documents; Handbook on Spectrum Monitoring; HCM4A work on cross-border frequency coordination in Africa; and ITU-R SM.2256-2 on spectrum-occupancy measurements. View source ↗
NATO: Electromagnetic Warfare and public work on contested electromagnetic environments and the relationships between electromagnetic warfare, cyber and other operational domains. View source ↗
NATO DIANA: Contested Electromagnetic Environments – 2026 Challenge, addressing resilient communications, navigation and surveillance in disrupted electromagnetic environments. View source ↗
NIST: work on the cybersecurity of PNT services and their integration into the Cybersecurity Framework. View source ↗
EASA and EUROCONTROL: 2025–2026 work on GNSS jamming and spoofing events and associated mitigation measures. View source ↗
ICAO: work on GNSS interference and the 2026 AFI regional procedure for reporting GNSS RFI events. View source ↗
Fawzi, H., Tabuada, P., Diggavi, S., Secure Estimation and Control for Cyber-Physical Systems Under Adversarial Attacks, IEEE Transactions on Automatic Control, 2014. View source ↗
Pajic, M., Lee, I., Pappas, G. J., Attack-Resilient State Estimation for Noisy Dynamical Systems, IEEE Transactions on Control of Network Systems, 2017. View source ↗
Huang, Z., Wang, X., Zhao, Y., Overview of Cognitive Electronic Warfare, Journal of National University of Defense Technology, 2023.
Confederation of Sahel States: Liptako-Gourma Charter and Treaty establishing the Confederation of Sahel States, official public documents.
Presidency of the Republic of Niger: institutional presentation of the AES, its sovereignty philosophy and its Defence, Diplomacy and Development pillars. View source ↗
Presidency of Burkina Faso: official publications on the AES Unified Force, the pooling of air-force resources and the consolidation of the Unified Force’s operational capabilities in 2026. View source ↗

Author’s note

This publication develops a personal scientific and technical reflection based on open sources. The discussion of a coordinated electromagnetic situational-awareness capability within the Confederation of Sahel States is a personal conceptual proposal and neither describes nor claims to reveal any operational capability that has not been publicly documented. The analyses and proposals expressed in this article do not represent any institution, authority or organisation with which I may be affiliated.