Researchers at Ben-Gurion University of the Negev published two papers in September 2026 showing that the scheduling logic inside low Earth orbit satellite constellations, not just their radios or ground stations, can be manipulated to knock out service. The papers, JANUS and HYDRA, target Starlink-class networks that dynamically reallocate limited satellite resources based on where demand is highest.
JANUS turns the scheduler against itself
JANUS, posted to arXiv on September 24 by Yuval Aviv, Roee Idan, Roy Peled, Asaf Shabtai and Yuval Elovici, attacks beam hopping, the technique LEO operators use to point a satellite's limited beams at whichever ground cells need capacity most at a given moment. A network operations center collects traffic demand from each cell and computes a hopping pattern that the satellite then follows, repeating every few milliseconds to seconds depending on the constellation.
The attack does not touch the radio link or the satellite bus. It feeds the scheduler false demand signals. A small botnet of compromised ground terminals injects legitimate-looking traffic into cells near a target, inflating their apparent demand so the scheduler routes beam time away from the victim cell. Against a deep reinforcement learning scheduler, the authors report excluding the victim cell from up to 92 percent of scheduling decisions and cutting its throughput by 77 to 81 percent, using only public information about cell boundaries and a limited set of compromised sources. The paper evaluates the attack across multiple constellation profiles, scheduler types and attacker knowledge levels, including a black box version that works without inside access to the scheduling algorithm.
The compromised terminals JANUS relies on do not need privileged access to the network. Consumer LEO user terminals authenticate to the satellite but their traffic still counts toward a cell's measured demand, so a modest number of subscriber-grade dishes running attacker-controlled traffic generators is enough to bias the scheduler's view of where capacity is needed. The paper's authors frame this as a case where demand-aware resource allocation, built to make constellations more efficient, doubles as an unauthenticated input channel that operators have not had to defend before.
HYDRA needs fewer bots to flood the same links
The second paper, submitted September 14 by Roee Idan, Rami Puzis, Asaf Shabtai and Yuval Elovici, revisits link flooding, a style of attack against LEO networks first demonstrated by ETH Zurich researchers in the 2021 paper ICARUS, presented at USENIX ATC. Because LEO satellites route traffic along a limited set of inter-satellite links determined by orbital geometry, congesting the right link can cut off an entire ground region without the target ever being contacted directly, making the attack far harder to detect than a conventional flood aimed at a single host.
HYDRA reframes link flooding as a botnet minimization problem: given a target region, what is the smallest set of compromised terminals and the smallest volume of traffic needed to congest the links serving it. Under matched stealth constraints, the authors report matching ICARUS's disruption using 34 percent fewer bots and 23 percent less aggregate attack traffic. That efficiency gain matters operationally, since a smaller, quieter botnet is harder for a network operator to spot in traffic logs before the congestion takes hold.
Both Ben-Gurion papers pair their attacks with candidate defenses rather than leaving operators empty handed. For JANUS, the authors point to demand-source verification and anomaly detection tuned to flag traffic that arrives from a narrow set of terminals but claims to represent broad cell demand. For HYDRA, they suggest randomizing routing decisions and adding redundancy to inter-satellite links so that no single congested path can isolate a ground region, an approach that trades some routing efficiency for resilience against an adversary who has mapped the network's topology in advance.
The weak point is at the edge, not the core
A third paper reinforces why this matters. Researchers including Bintao Yuan and Hongbin Luo published a separate paper, also named HYDRA, proposing a hypergraph based risk model for LEO constellations in February 2026. Using real Starlink orbital data, they found that the most damaging failure points are not the densely interconnected satellites at the network's core but the ground-space interfaces at its edge, nodes that look structurally minor until they fail and cascade. JANUS and the Ben-Gurion HYDRA both exploit that same edge, in one case the ground terminals feeding demand data, in the other the inter-satellite links those terminals ultimately depend on.
Simulated attacks, real infrastructure
None of the three papers describe an attack observed in the wild. All three rely on simulation and modeling rather than tests against an operational constellation, and the authors note mitigation strategies alongside their results. But the underlying infrastructure is not hypothetical. Starlink has more than 8,000 satellites in orbit and Amazon's Kuiper began commercial service in 2026, and both rely on demand aware scheduling of the kind JANUS targets. The Ben-Gurion group presented related work, including a separate September paper on open-source software risk in onboard satellite systems, at the SpaceSec 2026 workshop, part of a small but growing academic circuit treating satellite network management as security critical infrastructure rather than a pure performance engineering problem.
First detailed on arXiv by the Ben-Gurion University of the Negev research group behind JANUS and HYDRA.




