Crowdsourced navigation apps infer traffic from GPS traces reported by drivers, and that trust is exactly what a Sybil attack exploits. Researchers at Columbia University are proposing a countermeasure built from street cameras: verify the traffic the apps claim to see.
The team, led by Jhonatan Tavori and Gil Zussman with colleagues including Salvatore Stolfo at Columbia, studied how adversaries can inject fabricated vehicles and synthetic slowdowns into navigation platforms using emulation tools, automated client scripts, and phone farms. Fake congestion can reroute real drivers, distort traffic control decisions, and poison the city-scale estimates these platforms now feed.
Their defense uses existing street camera infrastructure to check whether reported traffic matches what the physical world shows. By cross-validating crowdsourced telemetry against camera observations at city scale, the system can flag clusters of impossible vehicles and slowdowns that never happened.
The approach treats the camera network as a trusted reference layer, avoiding reliance on the same device-reported data the attackers manipulate. The work was presented at the VehicleSec 2026 infrastructure security session in Baltimore.
Traffic integrity matters beyond convenience: emergency routing, congestion pricing, and automated traffic control increasingly depend on real-time estimates, and a platform-level deception could shift thousands of vehicles at once.