Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings

Andrew Logan

DEF CON 33 · Day 2 · Main Stage

Overview

Andrew Logan, an audio engineer attending his fourth DEF CON, presents a sobering threat scenario: the use of AI voice cloning technology to impersonate air traffic controllers on VHF aviation communi

Watch on YouTube · Slides

Visual summary for Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings by Andrew Logan
Visual summary for Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings by Andrew Logan

Key moments

  1. 6:25 Voice cloning basics: how synthetic speech can mimic ATC controller voices
  2. 8:13 And there are legitimate use cases for AM transceivers.
  3. 33:15 Um, but the Coast Guard flight sadly did not fare as well.
  4. 39:57 And I hope that's what I'm doing here today.
  5. 41:52 US airports and we're trying to get to 75 by 2026, but we are behind schedule.
  6. 43:51 Um, I want to thank the Defcon CFP board for having me again.

Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings

Speakers: Andrew Logan

Conference: DEF CON 33

YouTube: https://www.youtube.com/watch?v=JKwxsGYcZq4

Slides: https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Andrew%20Logan%20-%20Voice%20Cloning%20Air%20Traffic%20Control%20Vulnerabilities%20at%20Runway%20Crossings.pdf

Overview

Andrew Logan, an audio engineer attending his fourth DEF CON, presents a sobering threat scenario: the use of AI voice cloning technology to impersonate air traffic controllers on VHF aviation communication frequencies in order to issue false taxi or runway crossing clearances. The nightmare scenario at the center of the talk — a sophisticated attacker intermittently injecting false ATC instructions, particularly during adverse weather conditions that impede visual confirmation — could cause runway incursions, pilot confusion, and in the worst case, catastrophic crashes.

The talk arrives in the immediate context of the American Airlines Flight 5342 crash on January 29th (which killed 67 people when a Blackhawk helicopter struck the regional jet) and ongoing public scrutiny of the FAA's aging communication infrastructure. Logan is careful to position this as threat analysis rather than a how-to, but the technical argument is grounded: the VHF AM radio system used for aviation communication has essentially no authentication layer, AI voice synthesis has reached production-quality speaker cloning with minimal samples, and the cost and expertise required to transmit on aviation frequencies is low.

This is a critical infrastructure security talk aimed at raising awareness among policymakers, aviation security professionals, and the broader security community about a threat vector that has not received proportionate attention relative to other aviation cybersecurity concerns.

Background

▶ Watch: Voice cloning basics: how synthetic speech can mimic ATC controller voices (6:25)

Aviation VHF Communication Architecture

Air traffic control communication between controllers and pilots relies on VHF (Very High Frequency) AM radio in the 118–136 MHz band. Key characteristics of this system:

  • Open, unauthenticated broadcast: Any radio transmitter capable of operating in the VHF aviation band can transmit on ATC frequencies. There is no cryptographic or challenge-response authentication mechanism.
  • Party line: Multiple aircraft share a single frequency. All transmissions are heard by all aircraft tuned to that frequency, as well as by the controller.
  • Simplex or half-duplex operation: Aircraft and controllers cannot transmit simultaneously. If a rogue transmitter "steps on" a legitimate transmission, both are garbled or neither is clearly received.
  • Legacy design: The fundamental VHF AM communication technology in aviation has not changed substantially in decades. Proposals for digital voice and data communications (VDL Mode 2, Future Air Navigation System) exist but deployment has been slow.

The threat model for radio interference is not new — aviation authorities and pilot training have long acknowledged the risk of "frequency jamming" and inadvertent frequency blockage. What has changed recently is the quality and accessibility of AI voice synthesis.

The Role of Phraseology and Trust

ATC instructions follow highly standardized phraseology (defined by ICAO and FAA). Pilots are trained to read back instructions verbatim, which provides a check on misunderstood messages. However, this check relies on the pilot recognizing that an instruction is anomalous. A clearance to cross a runway is a normal instruction — pilots receive such clearances routinely. A voice-cloned instruction that exactly matches the known ATC phraseology for a runway crossing clearance, delivered in a convincing facsimile of the actual controller's voice, would be very difficult to distinguish from a legitimate clearance.

The "runway crossing" scenario is specifically dangerous because runway incursions are among the most catastrophic aviation accidents. Runway incursions occur when an aircraft or vehicle enters a runway in a way that conflicts with another aircraft's intended use. The FAA classifies runway incursion events and invests significant resources in reducing them — but all current mitigation focuses on procedural and visual safeguards, not on the integrity of radio communications.

AI Voice Cloning Capabilities

Logan, as an audio engineer, is well-positioned to assess the current state of AI voice synthesis and cloning. Key developments relevant to the threat:

  • Commercial voice cloning services can produce high-quality clones from as little as a few seconds of reference audio
  • Speaker diarization and cloning pipeline — recording a specific controller's voice from publicly accessible LiveATC streams (which broadcast real ATC communications for enthusiasts), extracting a clean reference sample, and producing a cloned voice — is technically feasible with widely available tools and consumer hardware
  • Synthesis quality is sufficient to be convincing in the context of VHF radio, where audio fidelity is already constrained by the radio transmission chain's compression and noise

The research does not present a working attack deployment, but it demonstrates the threat by showing how each component of the attack pipeline is within reach of a motivated, technically capable adversary.

Key Findings

▶ Watch: Um, but the Coast Guard flight sadly did not fare as well. (33:15)

Threat Model and Attack Scenario

Logan constructs a detailed threat scenario:

  1. Target selection: A busy airport with high traffic and complex taxiway geometry, where pilots are most dependent on ATC instructions and visual runway confirmation is most difficult (adverse weather, night operations)
  2. Voice sampling: The attacker collects recordings of the target controller's voice from LiveATC.net or similar services. No physical proximity to the airport is required — LiveATC streams are available for hundreds of airports globally.
  3. Voice cloning: Using a commercial or open-source voice cloning system, the attacker trains a model on the collected reference audio and synthesizes new utterances in the controller's voice
  4. Transmission: Using a radio transmitter operating in the VHF aviation band (which can be purchased as a handheld for general aviation use), the attacker transmits the synthesized clearance on the target airport's ground or tower frequency
  5. Effect: A pilot operating on the target frequency receives what sounds like a legitimate ATC instruction from the known controller, and acts on it

The attacker's optimal timing is during high-traffic, adverse-weather conditions when pilots have elevated cognitive load and when visual confirmation is least reliable.

Feasibility Analysis

Logan provides a technical assessment of each step's feasibility:

Radio transmission: VHF aviation band radios are widely available (for legitimate GA pilot use). Federal law (FCC regulations and the Federal Aviation Act) prohibits unauthorized transmission on aviation frequencies, and doing so would be a serious federal crime. However, from a pure technical capability standpoint, the barrier is low. A transmitter with a few watts of output from near the airport perimeter could reach aircraft on the ground.

Voice quality: VHF AM aviation radio has relatively low audio fidelity (8 kHz bandwidth, mono). This actually works in the attacker's favor: the compression and noise characteristics of the radio channel mask minor artifacts in synthetic speech. A voice clone that would be detectable in high-fidelity audio may be indistinguishable from the real controller when transmitted over VHF radio.

Phraseology accuracy: ICAO and FAA ATC phraseology is publicly documented and extensively available in pilot training materials. An attacker does not need insider knowledge of ATC procedures — the scripts for common clearances are in the FAA Pilot/Controller Glossary.

Intermittent Attack Strategy

Logan emphasizes the "intermittent" nature of the optimal attack. A sustained transmission would be noticed immediately (it would jam the frequency and trigger a rapid response). The sophisticated attack involves:

  • Listening to the actual ATC frequency to monitor real traffic
  • Identifying a moment when a specific aircraft is likely to expect a crossing clearance
  • Injecting a single, plausible false clearance at the right moment
  • Going silent immediately after

This intermittent approach maximizes the window before the attack is detected, because from the perspective of the real controller and other pilots, the anomalous transmission could be attributed to a radio malfunction, a misheard readback, or a momentary atmospheric issue.

Comparison to Existing Aviation Security Efforts

Logan notes that considerable effort has been spent on ATC cybersecurity in domains like ACARS, ARINC 429, and the digital systems of modern aircraft — but voice communication integrity has received very little attention. This is partly because voice is perceived as "low-tech" and partly because the open nature of VHF radio has been a feature (ensuring interoperability) rather than a bug. The emergence of production-quality AI voice cloning changes this calculus.

Logan references the ADSB security debate (which he also addressed in a prior DEF CON talk) as an example of an aviation communication vulnerability that received public attention and has been gradually addressed. He argues that voice communication integrity deserves similar treatment.

Technical Deep Dive

▶ Watch: And I hope that's what I'm doing here today. (39:57)

LiveATC as an Intelligence Source

LiveATC.net aggregates real-time radio streams from volunteer receivers at airports worldwide. For aviation enthusiasts and researchers, it provides access to live ATC communications for thousands of airports. Logan demonstrates how a multi-hour recording from a specific facility can yield many minutes of clean reference audio from a single controller's voice — more than sufficient for modern voice cloning systems.

Voice Cloning Pipeline

The attack chain conceptually consists of:

  1. Audio collection: Recording from LiveATC with sufficient reference material (a few minutes of clean speech from the target speaker)
  2. Voice cloning training: Using tools such as VITS, YourTTS, or commercial APIs (ElevenLabs, similar) to train a speaker model
  3. Synthesis: Generating audio of arbitrary ATC phraseology in the target speaker's voice
  4. Post-processing: Optional radio-channel simulation (adding VHF radio characteristics to the synthetic audio) to increase plausibility

Logan, as an audio engineer, validates that the output of current voice cloning systems is convincing enough to pass the "radio quality" bar. He plays audio examples to illustrate the point.

Countermeasure Analysis

Logan analyzes potential countermeasures and their limitations:

Digital Voice Communications (VDL Mode 2, LDACS): Digital ATC communication would enable message authentication and would make voice injection attacks much harder. However, deployment timelines are long, and retrofitting the existing global aviation infrastructure is a multi-decade project.

Controller voice authentication tokens (watermarking): Embedding inaudible cryptographic watermarks in ATC transmissions could allow receiving equipment to verify authenticity. This would require modification to both transmitting and receiving equipment and a key management infrastructure.

Pilot challenge procedures: Training pilots to challenge unexpected or unusual clearances, particularly runway crossing instructions received without a prior position readback, is a near-term procedural mitigation. Logan notes that runway crossing clearances are already among the most carefully verified instructions due to their safety implications.

Direction finding and monitoring: Radio monitoring systems can identify and locate unauthorized transmitters. However, an intermittent attacker who transmits briefly and moves frequently is difficult to localize and apprehend before causing harm.

Demo / Proof of Concept

▶ Watch: US airports and we're trying to get to 75 by 2026, but we are behind schedule. (41:52)

Logan presents audio demonstrations of voice-cloned ATC-style audio, illustrating the quality achievable with current tools. He does not demonstrate an actual attack against a live aviation frequency — this would be a serious federal crime — but plays synthesized examples showing how convincing the output would be over a simulated VHF radio channel.

The demo makes the threat concrete for an audience that might otherwise consider AI voice cloning too immature or too difficult to weaponize in this context.

Defensive Implications

▶ Watch: Um, I want to thank the Defcon CFP board for having me again. (43:51)

For aviation regulators (FAA, ICAO, EASA):

  • Commission a formal threat assessment of AI-enabled voice injection against ATC frequencies, analogous to the threat assessments that drove ADSB security improvements
  • Accelerate the evaluation and deployment timeline for digital ATC communications that include message authentication
  • Update ATC training to specifically address the threat of AI voice injection and establish procedures for pilot challenges when receiving anomalous runway crossing clearances

For pilots and flight crew:

  • Be skeptical of unexpected clearances, particularly runway crossing instructions during high-workload, low-visibility conditions
  • Use visual verification (checking runway visual range indicators, ensuring no other aircraft are in the runway environment) even when a crossing clearance has been received
  • Report any instances of garbled, unexpected, or potentially anomalous ATC communications to the controlling facility

For airport security:

  • Consider deploying radio direction-finding equipment near runway crossings at high-risk airports to detect unauthorized transmissions in the VHF aviation band
  • Establish communication protocols for rapidly alerting pilots if an unauthorized transmission has been detected on a specific frequency

For the security research community:

  • The intersection of AI-generated media and safety-critical communication systems deserves sustained attention — aviation is one example, but VHF maritime communications, military communications, and emergency services radio share similar vulnerability characteristics

Key Takeaways

  • AI voice cloning technology, combined with the open, unauthenticated nature of VHF aviation radio, creates a credible threat scenario in which an attacker could inject false ATC clearances in a convincing imitation of the real controller's voice.
  • Runway crossing instructions are the highest-impact target because runway incursions are consistently among the most catastrophic aviation accidents.
  • The attack components — voice sampling from publicly available LiveATC streams, voice cloning with commercially available tools, transmission on a VHF radio — are technically within reach of a motivated attacker with moderate resources.
  • Current aviation communication security posture does not account for this threat; existing safety procedures assume that ATC voices on the frequency are authentic.
  • Near-term mitigations include pilot procedural training for challenging unexpected clearances; longer-term mitigations require digital communication infrastructure with message authentication.

About the Speaker

Andrew Logan is an audio engineer who has attended DEF CON since his 30th anniversary edition and has spoken at the conference before on the topic of military aircraft tracking using ADSB. He is not a pilot or air traffic controller, but brings deep audio expertise relevant to the voice synthesis and radio transmission components of the threat he describes. His prior DEF CON talk addressed military use of ADSB exemptions, and he is an active advocate for aviation safety and communications transparency at coperspotter.com.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Real threat, technically competent framing, but this is a threat analysis paper delivered as a DEF CON talk — no novel research, no demonstrations against real systems, and the 'AI voice cloning' hook carries less weight when the attack is fundamentally just rogue radio transmission.

Heather Calloway (CISO) — MUST SEE

AI voice cloning applied to unauthenticated aviation radio is a safety-critical infrastructure problem that has no current technical mitigation — and the regulatory conversation hasn't started yet.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33