security//Sybil attack
A Sybil attack is an attack on a distributed system in which one adversary creates or impersonates many identities, so as to carry more weight in any vote, average or reputation the system computes from its members; it threatens drone swarms that agree by consensus, sensor networks that fuse their readings, peer-to-peer networks and blockchains alike. The defence it calls for is simple to state and hard to run: each participant must prove who it is.
A Sybil attack is an attack on a distributed system in which one adversary creates or impersonates many identities, so as to carry more weight in any vote, average or reputation the system computes from its members; it threatens drone swarms that agree by consensus, sensor networks that fuse their readings, peer-to-peer networks and blockchains alike. The defence it calls for is simple to state and hard to run: each participant must prove who it is.
The damage follows from how the group decides. A fleet running a consensus protocol averages its neighbours' estimates of a wind speed or a target position; if one attacker shows up as ten neighbours, its value enters the average ten times and drags the group's agreement toward it. A majority vote among sensors is captured the moment the attacker's fake identities outnumber the honest ones. Algorithms that tolerate a bounded number of misbehaving members, such as resilient consensus or Byzantine fault tolerance, assume that number is known; a Sybil attacker breaks the assumption by manufacturing members.
A message saying I am drone 7 proves nothing.
Identity must be bound to something the attacker cannot copy cheaply: a cryptographic key installed at manufacture and a signature on every message (cryptography), a registration with a central authority, or, in open systems, a cost per identity (computation or stake in a blockchain).
In drone fleets the practical defence is conventional cryptography: MAVLink 2 supports message signing, and keys are provisioned per vehicle and revoked when one is lost (MAVLink). Key management, the unglamorous part, is where most deployments are weak.
Physical checks add a second line: a claimed neighbour whose radio signal strength or time of flight does not match its reported position is suspect, a cross-check in the spirit of the residuals of cyber-physical security.
A Sybil attack differs from a single node that lies (a Byzantine member): the liar has one voice and resilient algorithms can discard it, while the Sybil attacker multiplies its voice until discarding the extremes no longer helps.