Telecom infrastructureGovernance
Signals in the Sky: The Promise and Limits of Telecom in Counter-Drone Defense
Why telecom belongs in a multilayered defence as a contributor, not as its foundation
Matteo Gatta10 min read

Executive Summary
Drones increasingly exploit LTE, 5G, and direct-to-phone satellites for navigation, video, and command-and-control. Recent LTE-guided first-person-view (FPV) strikes in Ukraine illustrate telecom's vulnerabilities but also its defensive potential via carrier-level controls — still secondary to radar. Emerging Integrated Sensing and Communications (ISAC) in 5G-Advanced further enhances this promise, enabling mmWave base stations to perform radar-like detection of small drones in real time, though deployment lags behind regulatory and integration hurdles. Some argue this dependence makes telecom networks the next frontier of air defence. This paper challenges that view: telecom intelligence adds value, but remains peripheral compared to radar, RF, and kinetic systems. Metadata can provide attribution and enrich cross-border coordination, but it cannot deliver real-time detection or neutralisation without multi-sensor fusion. Privacy law, technical ambiguity, and adversary adaptation impose hard ceilings that no AI-powered telco can solve alone. Telecom networks and roaming hubs should therefore be seen as contributors to a multilayered defence, not its foundation.
Drones in the Cross-Border Context
Drones are now an everyday feature of conflict and coercion. In Ukraine, in the Baltics, and over Northern European airbases, they have been used for reconnaissance, harassment, and disruption. Unlike traditional aircraft, they are cheap, numerous, and increasingly autonomous. Many use civilian LTE or 5G to transmit video or receive updates, roaming invisibly across borders under the same agreements that support ordinary smartphones [1] [6][8].
This does not mean networks are the right place to stop them. At best, it means networks create indirect traces — handovers, uplink surges, or timing anomalies — that analysts may later interpret as signs of airborne devices. But the promise of reliable real-time signatures is overstated. Aerial user equipment often connects via antenna sidelobes, triggers unstable handovers, and drowns in IoT noise [1][2][4]. Processing global signalling data in milliseconds at defence-grade accuracy remains a pipe dream [4]. Low-cost radar networks, such as RTX Raytheon's AI/ML-powered systems demonstrated in February 2025, offer more robust alternatives for real-time tracking.
How Drones Fly and Stay Connected
Civilian and low-cost military drones rely on autopilot software such as PX4 or ArduPilot [1], GNSS navigation [4], and sometimes onboard AI processors for autonomy [7]. They connect via short-range RF, proprietary radios, LTE/5G, or increasingly satellite links [5][9] [10]. Each channel leaves metadata in the system. Yet those trails are ambiguous. Millions of IoT devices, balloons, and even fast-moving trains produce similar anomalies [2][4]. Timing advance values and cell reselections may suggest altitude, but they rarely prove hostile intent. The sheer noise makes real-time detection infeasible without unacceptable false positives. Passive radar, leveraging ambient RF like mobile signals, offers a hybrid edge but still lags dedicated 3D arrays in cluttered skies.
A stark example of this adaptation are mothership UAVs which carry and release FPV drones 5-10 km from targets. These FPVs connect to civilian LTE/4G networks for real-time video and control, evading traditional 2.4/5.8 GHz jammers through frequency hopping and cell tower reliance — often striking up to 35 km inside borders. This tactic exemplifies telecom's dual role: a vulnerability for exploitation and a potential attribution vector via IMSI traces, though real-time interception remains elusive amid civilian traffic.
Roaming Hubs as UAV Sensors: Limits of the Vision
Roaming hubs sit at global junctions, processing roaming authentication and signalling [6]. It is tempting to imagine them as sentinels — flagging anomalies, tracing IMSIs, and throttling suspicious links.
In practice, their vantage point is narrow. They cannot see payloads (which are end-to-end encrypted) [2]. They cannot reliably distinguish a hostile drone from a legitimate IoT device. Any bounded action — throttling, rerouting — creates liability by degrading service for paying customers [3]. Static rules create false alarms; machine learning struggles with adversarial mimicry; and "agentic AI" cannot escape the fundamental signal-noise problem [7][8].
Equally, privacy and sovereignty pose immovable barriers. GDPR and EU jurisprudence have consistently struck down bulk metadata schemes [3]. Continuous monitoring of roaming traffic, or cross-border sharing with defence, would face regulatory blockades. Attempts to quarantine foreign SIMs risk extraterritorial overreach [3]. The 2025 enforcement wave makes clear that carve-outs for surveillance will not pass easily. As a result, roaming hubs may offer useful forensic intelligence — linking a SIM to an operator, attributing a drone to a region, or flagging unusual roaming paths [6]— but their role remains contextual and retrospective, not defensive in the moment.
The LTE-FPV evolution, however, is prompting nascent countermeasures: carrier coordination for SIM/IMEI blacklisting and sector-specific signal limits, tested in limited trials to minimize false positives. These tools enhance hubs' proactive potential but remain legally fraught under GDPR [3].
Yet this calculus shifts if inaction invites strikes: a successful drone attack, facilitated by its network's C2, exposes the MNO to massive business continuity losses that exceed any revenue from throttled traffic. This uninsurable risk will compel governments to mandate proactive mitigation as part of Critical Infrastructure duty of care.
Satellites: Expanding the Threat and the Control
Direct-to-phone satellite networks such as Starlink's Direct-to-Cell, Vodafone-AST SatCo, Lynk Global, and IRIS² [5][9][10] are sometimes described as a new layer of detection. In reality, they expand the problem tactically while creating new enforcement chokepoints strategically.
By bypassing terrestrial towers, drones can now cross continents invisibly. NTN traffic eventually lands in terrestrial gateways, but the only traces visible are Doppler and latency anomalies [5]. These are weak, often masked, and far easier for adversaries to spoof than radar signatures. Satellites widen the blind spot more than they widen the sensor net. Comparative trials through 2025 confirm radar and RF sensing outperform metadata-based methods, with multi-sensor AI integrations validating radar's 99% reliability edge [4].
Yet because NTN traffic is centralised through a handful of regulated terrestrial gateways, these gateways form a unique chokepoint for mandatory signal logging. Unlike terrestrial mobile networks, such gateways could provide clean, enforceable points for anomaly detection and continental-scale monitoring.
How Telecom Networks Can Contribute
Telecom networks are not front-line defenders, but they can play supporting roles in counter-UAS efforts. Metadata analysis can provide anomaly hints — such as unusual timing advances or rapid cell handovers — that may raise early suspicions, though error rates remain high [1][4]. They can also support attribution, linking drones to SIMs, operators, or regions through IMSI/IMEI traces, and even detecting non-terrestrial (NTN) anomalies in satellite-leaping drones [5][9]. Finally, roaming hubs can enable cross-border coordination, sharing insights across operators to align responses between nations. Emerging ISAC technologies in 5G-Advanced and 6G prototypes elevate this further:
mmWave massive MIMO base stations can repurpose communication waveforms for radarlike sensing, detecting small drones (0.2-1.0m) with high precision via range/angle estimation and micro-Doppler signatures — making "invisible" aerial targets electrically large at high frequencies. Recent vendors demonstrations, for instance, showcased 5G infrastructure detecting drones via integrated sensing, hinting at a shift from passive metadata to active physical-layer detection in densified networks. This aligns with the booming C-UAS market, projected to exceed $20 billion by 2030, driven by AI/ML for threat classification and multi-sensor fusion to mitigate false positives — affirming no "silver bullet" but telecom's growing sensor-array role.
These contributions remain modest. In controlled settings such as airports, metadata fusion has yielded 20-30% earlier warnings [4] showed attribution's post-strike value — but in both cases, kinetic defences proved decisive. Dedrone by Axon's 2025 Threat Report reinforces this, noting over 80% of detections via RF systems despite rising AI autonomy and RF-masking tactics; metadata aids attribution for masked threats but lags in real-time classification. Bounded response actions such as throttling or rerouting are legally fraught and operationally fragile under GDPR [3]. Emerging UAS communication disruptors (Frost Radar 2025) increasingly favor AI-driven jamming over telecom throttling, underscoring telecom's role as contextual support rather than core defence.
Policy Imperatives for Europe
Telecom intelligence should be pursued, but only in perspective. Aviation and telecom regulators should converge cautiously, linking EASA's U-Space with GSMA and 3GPP standards [2][3]. Roaming hubs may provide attribution and cross-border insights [6], yet they should not be elevated beyond their supporting role. Agentic AI should be trialled in controlled pilots, not treated as a silver bullet [7][8].
At the policy level, EU mandates would need to classify hubs as critical infrastructure under strict GDPR-compliant guardrails [3]. Recent October 2025 proposals for flagship counterdrone projects, including a "drone wall" by 2027, emphasize harmonized frameworks but reinforce GDPR's data minimization and purpose-limitation principles — ensuring any ISAC or metadata processing has a clear legal basis and privacy-by-design. Sovereignty concerns suggest embedding limited detection hooks into sovereign systems like IRIS², though their effectiveness will be constrained [10]. NATO's DiBaX 2025 experiment, concluded November 8, demonstrated 5G's role in cross-domain interoperability for counter-UAS, including secure UAV handovers across borders — validating calls for "plug-and-fight" 5G integration in U-Space with GDPR safeguards. Globally, roaming treaties could facilitate metadata sharing, but privacy law will cap their scope [3]. Europe must prioritise multisensor fusion hubs and kinetic defences over siloed telecom plays.
Conclusion
With the proliferation of UAS/UAV, telecom networks are sometimes portrayed as a meaningful actor in air defence. They are not. They are peripheral contributors: useful for attribution, modestly helpful for early warning in niche settings, and important for crossborder coordination. Recent LTE-FPV escalations in Ukraine highlight telecom's growing contextual edge in hybrid threats, while ISAC prototypes signal a technical leap toward real-time sensing — yet regulatory ceilings like GDPR and the need for multi-sensor AI fusion ensure they cannot reliably detect, classify, or neutralise hostile drones alone.
Radar, RF, electronic warfare, and kinetic interception remain the backbone of counter- UAS. Telecom's role is to add context — not to shoulder the burden. Europe should invest accordingly: integrating network intelligence as supporting infrastructure, while keeping its strategic focus on proven, robust defences. Defenders must also accept adversary adaptation as a constant: hostile systems increasingly mimic IoT traffic, reduce network dependence, or switch seamlessly to autonomous and satellite modes [8]. Interventions may even accelerate fallback behaviours where drones severed links mid-flight and continued their mission.
Amid current technical, legal, and economic friction points, telecom networks and roaming hubs remain supportive but far from decisive — yet MNOs will still face pressure to act as de facto real-time security actors, regardless of their preferred business model or legal guardrails.
References
- 3GPP, Study on Enhanced LTE Support for Aerial Vehicles, Release 15.
- GSMA, Mobile-Enabled Unmanned Aircraft Systems: Operator Guidelines.
- EASA, U-Space Regulatory Package & Easy Access Rules.
- Nokia, Cellular for UAV Command and Control.
- 3GPP, Non-Terrestrial Networks (NTN) Specifications, Release 17.
- BICS, Syniverse, Comfone — roaming hub and fraud analytics platforms (FraudGuard, Syniverse Clearing, Comfone Key2roam).
- Anduril, Lattice OS and Counter-UAS Systems.
- Mark Hay, Modern Air Defence Must Include Mobile Network Intelligence, Melrose Labs, 2025.
- GSMA, 5G and Non-Terrestrial Networks: NTN for IoT and Aviation.
- Vodafone AST, Direct-to-Cell Connectivity Plans, EU Briefings 2024-25.
- United24 Media, Russia Now Controls FPV Drones via 4G to Evade Ukraine's Jamming Systems, November 1, 2025.
- TURDEF, Russia Deploys LTE-Controlled FPV Drones in Ukraine, November 2025.
- Militarnyi, FPV Drone on Mobile Communication: Russians Use New Tactics for UAVs, 2025.
- NATO ACT, Improving Interoperability across Domains through Advanced Communications: DiBaX 2025 Concludes, November 2025.
- Dedrone by Axon, Intelligence Report 2025: Evolving Drone Tactics, September 9, 2025.
- Dronelife, Dedrone by Axon Report Highlights Evolving Drone Threats and Defense Challenges, September 11, 2025.
- 5G Americas, Transforming Industries with Integrated Sensing and Communications, June 2025.
- ZTE, mmWave ISAC: Driving Low-Altitude Economy, March 2025.
- HDIAC, Integrated Sensing and Communications for Small UAV Applications in Cellular Networks, June 2025.
- Qualcomm, Wireless Sensing for Aerial Drone Detection (YouTube Demonstration), February 2025.
- MarketsandMarkets, Counter-Unmanned Aircraft System (C-UAS) Market worth $20.31 Billion by 2030, October 2025.
- European Commission, EU Proposes Flagship Defence Projects to Counter Drones, October 2025.
Acronyms
- AI — Artificial Intelligence
- APN — Access Point Name
- AST — AST SpaceMobile (Vodafone-AST "SatCo" JV)
- BVLOS — Beyond Visual Line of Sight
- C2 — Command and Control
- C-UAS — Counter-Unmanned Aerial System
- DPAs — Data Protection Authorities
- D2P / D2D — Direct-to-Phone / Direct-to-Device (satellite connectivity)
- E2EE — End-to-End Encryption
- EASA — European Union Aviation Safety Agency
- ETSI — European Telecommunications Standards Institute
- EW — Electronic Warfare
- GDPR — General Data Protection Regulation
- GNSS — Global Navigation Satellite System (GPS, Galileo, GLONASS, etc.)
- GSMA — GSM Association (industry body)
- IMEI — International Mobile Equipment Identity
- IMSI — International Mobile Subscriber Identity
- IoT — Internet of Things
- IRIS² — Infrastructure for Resilience, Interconnectivity and Security by Satellite (EU LEO constellation programme)
- ISAC — Integrated Sensing and Communications
- LTE — Long Term Evolution (4G mobile standard)
- MIMO — Multiple Input Multiple Output
- MNO — Mobile Network Operator
- mmWave — Millimetre Wave
- NTN — Non-Terrestrial Networks (3GPP standard for satellite integration)
- QoS — Quality of Service
- RF — Radio Frequency
- RRC / RSRP / RSRQ — Radio Resource Control / Reference Signal Received Power / Reference Signal Received Quality
- SEPP — Security Edge Protection Proxy (5G interconnect security function)
- SIM / eSIM — Subscriber Identity Module / embedded SIM
- SS7 — Signalling System No. 7 (legacy interconnect protocol)
- TAC — Tracking Area Code
- UAS / UAV — Unmanned Aerial System / Unmanned Aerial Vehicle
- UTM / U-Space — Unmanned Traffic Management (European drone traffic management framework)
- 5G — Fifth-Generation Mobile Network