1. Management Summary
The autonomous combat drone of 2036 is built so that the loss of its links does not stop it: it identifies its target on board, locates and destroys it on its own, and navigates without emitting a radio signal — rendering it largely immune to electronic jamming. A previous study measured this threat; the present one asks for the response: What defense is possible in 2036?
The central finding is this: there is no silver-bullet system. The only effective answer is a layered, networked defense built from four interlocking functions — see, decide, act, protect.
See. Because radar loses small, slow, radio-silent targets in the clutter, only the fusion of many sensors (radar, electro-optical/infrared, acoustic, passive radio detection, LiDAR) can sustain the situational picture and early warning.
Decide. AI-assisted planning automation solves the weapon-target assignment in real time under saturation, while the human stays above the loop and retains release authority.
Act. A full effector program: high-power microwaves thin the swarm across an area (and work precisely because they do not jam the radio link but strike the circuits); high-energy lasers and programmable fragmentation clouds catch the leakage one target at a time; kinetic interceptors and net catchers engage even under total radio silence.
Protect. A jam-resistant, EW-secure networked communications backbone holds the networked fire together, and a layered self-protection — microwave, laser, net, hardening — defends the command structures that direct the system.
The honest limits are named: no layer is leakproof (residual leakage is a design parameter), very large swarms strain magazine depth and energy, the use of microwaves within one’s own airspace threatens one’s own electronics (fratricide), and economics decide the matter — a “gold-plated” defense turns the cost asymmetry back against the defender.
The final chapter translates the system into an organization: the creation of a counter-drone battalion of the Swiss Armed Forces (commanded by a lieutenant colonel, subordinated to BODLUV Br 33, organized into staff functions S1–S6 and six batteries — from the sensor/early-warning battery, through the effector batteries for directed energy and counter-drones, to logistics). The official building blocks — Air2030 with Patriot and IRIS-T SLM, the Securiton emergency procurement against mini-drones, the Drone Task Force — are real and are clearly separated from the projection onto 2036.
The essence of both studies: the path from threat to defense is technically feasible, but it demands architecture instead of a wonder weapon, discipline instead of escalation — and the decision over life and death must remain with the human. Technology does not wait.
2. The Starting Point: The Threat in 2036
This study is the flip side of another. A prior investigation took the measure of how far the autonomous combat drone has matured by the year 2036 — and arrived at an uncomfortable conclusion: it is built so that the loss of its links does not stop it. Anyone who wants to defend against it must first understand what they are up against. This chapter traces the threat to which all the following chapters respond.
2.1 The Autonomous Combat Drone — State of the Art in 2036
The drone of 2036 rests on four matured pillars. Its inertial backbone measures acceleration and rate of rotation without any external reference; tactical MEMS inertial sensors reach the required quality at a fraction of their former size and cost [1]. Its artificial eye sees where satellites fall silent: event-based cameras with roughly 140 dB of dynamic range and microsecond latency [2], coupled with terrain-referenced navigation that is matched against stored maps even at five thousand meters of altitude [3]. Its brain thinks onboard, in the single-digit watt range: ternary language models without floating-point multiplication [4] and neuromorphic processing units that consume fractions of a millijoule per decision [5]. And its nervous system networks the drones covertly via electronically steered phased-array directional beams that are hard to intercept and hard to jam.
2.2 The Attacker’s Fail-Safe Kill Chain
From these pillars grows a closed attack chain that needs no humans. The drone classifies its target onboard: deep neural networks recognize military targets from radar, electro-optical, and infrared data without any need for a datalink to an evaluation station [6]. It finds the target itself and distributes it across the formation — weapon-target assignment within the swarm has been solved as a learning-based decision problem [7] — and cooperating swarms fly at the physical limits, beyond what a human could control [8]. It destroys the target automatically, and should the radio link fail along the way, it makes no difference: a layered self-navigation carries the mission through on its own — from the satellite signal through image- and terrain-based positioning all the way down to pure inertia. The latter is, in principle, unstable and drifts over time [9], yet over the few seconds of the terminal approach its error stays smaller than the target radius [10]. The attacker has simply severed the vulnerability that once made it vulnerable — the wire to the operator.
2.3 Why It Is So Hard to Counter
It is precisely this autonomy that blunts conventional air defense. Four properties interlock:
Radio silence and EW resistance. A drone that navigates optically and inertially and recognizes its target onboard receives nothing that could be jammed. Electronic warfare — for years the cheapest and most wide-area means of counter-drone defense — comes to nothing against a radio-silent, autonomous swarm [11]. Even sophisticated satellite spoofing is actively countered by the attacker: receivers such as SemperFi expose the false signal through a forced flight maneuver and restore the true position within fractions of a second [12].
Low signature. The small, slow, low-flying targets (in the jargon, “Low, Slow, Small”) vanish into radar clutter among birds and terrain echoes.
Saturation. A swarm turns quantity into a qualitatively new threat: a defense that reliably hits a single target becomes ineffective when twenty or two hundred targets arrive simultaneously — it runs out of time and rounds.
Cost asymmetry. On the attacker’s side stand many cheap, replaceable links; on the defender’s side, a few expensive effectors. Model calculations from recent conflicts cite cost-exchange ratios of up to 190:1 against the defender [13] — to be read as an estimate, yet in its order of magnitude the economic core of the problem.
The uncomfortable sum: against the autonomous, radio-silent drone that appears en masse, every single means fails. There is, as one U.S. official put it, no “silver-bullet system.” What works is only a layered, networked defense made of many complementary tiers — and it is precisely those building blocks that this study takes the measure of.
2.4 Research Question, Methodology, and Structure
The investigation asks: Which countermeasures against the autonomous drone threat are possible in the year 2036 — and how does one assemble them into a functioning whole? It is a synthesis of literature and technology; its factual basis draws, wherever possible, on scientific primary publications, supplemented by reports from government agencies and institutes and — for the Swiss organization — by official sources, which are marked as such. It adopts the documented foundation of the preceding drone study and expands it with its own in-depth research into defense.
The structure follows the logic of the engagement. Part I addresses seeing and deciding: detection and early warning (Chapter 3), and the situational picture, command, and planning automation (Chapter 4). Part II unfolds the full effector program: high-power microwaves (5), high-energy lasers (6), programmable fragmentation effects (7), kinetic interceptors (8), physical net protection (9), and electronic warfare (10). Part III is devoted to networking and self-protection: EW-secure networked communication (11), the protection of the command structures themselves (12), and the economics of defense (13). Part IV integrates the whole: the synthesis of a layered system together with a scenario (14), the legal classification (15), and — as the closing chapter — the concrete establishment of a counter-drone battalion of the Swiss Armed Forces (16).
3. Early Warning Against the Radio-Silent, Small, Swarming Target
Every defense begins with seeing. What the combat drone of 2036 accomplishes on board — autonomous recognition, covert networking, fail-safe navigation — the defense must reproduce in its own nervous system: it must detect the small, slow, radio-silent target before it strikes. The true bottleneck of counter-drone defense lies not with the effector, but one step earlier — in early warning. To one who fails to see in time, even the sharpest weapon is of no use.
3.1 Why a Single Sensor Fails
The technical literature captures the drone as a detection problem under the acronym LSS — “low, slow, small.” Against this target, each individual class of sensor runs up against a limit of its own: the radar cross section is tiny, the thermal signature is faint, the velocity lies close to the clutter threshold, and the autonomous drone emits no continuous radio signal in the first place. The authoritative survey works arrive in unison at the same conclusion: no sensor alone closes the gap, only multilayered multi-sensor fusion [11], [14], [15].
The strengths and weaknesses of the sensor classes complement one another almost as if by textbook [16], [17]:
Radio-frequency detection (RF) is passive and acts early — but blind to the radio-silent, autonomous drone that transmits nothing.
Radar is all-weather capable and long-ranged — but struggles with the weak radar cross section and confuses the drone with birds.
Electro-optical/infrared (EO/IR) delivers identification — but only within line of sight and in good weather.
Acoustics is inexpensive and works independently of radio silence — but only at close range and is sensitive to wind and noise.
Every serious C-UAS architecture therefore breaks down into three layers: sensors (detection, identification, localization, tracking), command and control (C2), and effect [11]. The first two are the core of this chapter and the next — and the sore point of the entire chain.
3.2 Multi-Sensor Fusion: What Can Be Measured Today
Fusion is not a promise but something measurable. An open research framework from 2026 merges six processing layers — radio classification, acoustic motor signature, AI-based image detection, evidence-weighted sensor fusion, a behavioral classification, and a swarm module built on a graph neural network. Across three real-world datasets it achieves 96.1% detection accuracy at a 3.2% false-alarm rate and an end-to-end latency of 142 milliseconds on commodity hardware; the behavioral analysis yields a predictive early-warning time of roughly 30 seconds [18]. This is the order of magnitude in which an autonomous early-warning system operates in 2036: sharp detection, low false-alarm rate, a response in fractions of a second.
The complementarity of the sensor classes is also documented in the open field. On a testbed operated under U.S. research funding, a network of passive radio sensors and a Ku-band radar were fused by way of a Kalman filter; the result shows that radar and radio, under changing geometry, catch one another — the fusion suppresses large single-sensor errors and increases tracking coverage without losing performance relative to the individual sensors [19].
As long as the drone transmits anything at all, the pre-classification can become very sharp. A radio-based fingerprint detector achieves 99.8% detection at 2.8% false alarm at a 10 dB signal-to-noise ratio; a classifier distinguishes 15 controller types with 98.1% accuracy — even alongside Wi-Fi and Bluetooth interferers [20]. Should the drone even transmit its identifier, early warning becomes trivial: decoding the Drone ID delivers real-time telemetry at 1.3 to 3.7 kilometers [21]. But this is precisely the easy case. The hard case is the drone that stays silent.
Abbildung 1: Layered model of counter-drone early warning: no single sensor closes the LSS gap. Source: Chapter 3.
3.3 When the Drone Stays Silent: Acoustics and Dense Sensor Networks
Against radio silence there is no miracle weapon, but two viable answers. The first is acoustics, which works independently of any radio signal. A drone’s propeller drive is loud, and its sound betrays it even when it is electromagnetically silent: a multi-node acoustic system with learning-based signal analysis reaches its maximum range without dead angles when the nodes are arranged in a semicircle at roughly 75 meters from the protected object [22] — a concrete planning value for the deployment of a sensor network.
From this principle a national acoustic sensor network emerges when nodes are combined: an area-wide net of many individually very cheap microphone nodes that report their sound detections over cellular networks to a central situational picture, which reconstructs the target’s track and flight direction out of the multitude of reports. The model is the Ukrainian system Sky Fortress: thousands of acoustic sensors distributed across the country at roughly 400 to 1,000 US dollars apiece, which contribute more than a fifth of all inbound targets — precisely against the low- and slow-flying, propeller-driven attack drone of the Shahed type that a classic radar can barely grasp in ground clutter [23]. The value of such a network lies not in the precision of the single node but in its density and cheapness: it is the most cost-effective layer with which to blanket an entire country with a first, radio-silence-capable early warning, and it complements passive radar (PCL) and the remaining sensor classes rather than replacing them.
The second answer is density. When a single cheap sensor is too noisy, numbers help: only the multitude of scattered nodes turns uncertain single measurements into a reliable picture. How dense the network must be can be computed — for a level-based detector, closed-form expressions yield the critical sensor density that maximizes the average detection probability at a given false-alarm rate [24]. The rule of thumb behind it is the root-N logic of statistics: averaging N independent, noisy measurements drops the random error in proportion to the square root of N. Four sensors halve the noise, a hundred press it down to a tenth. Early warning against the swarm is therefore a question of scattering many cheap eyes, not of a single expensive one.
3.4 Radar Against LSS: The Staring Gaze and Detection Below the Threshold
Radar remains the workhorse sensor — but only in a new design. In place of a mechanically rotating antenna, staring (holographic) radar is gaining ground: a fully digitally sampled array that keeps every cell of space continuously in view. The long dwell time is decisive for integrating the weak echoes of an LSS target over time. In an urban network of several such radars, bistatic and monostatic arrangements deliver comparable accuracy; the real problem is the synchronization of the network, solved through the evaluation of the direct signal [25]. When the radar simultaneously tracks the rotor-induced micro-Doppler signature, it separates drone from bird considerably more reliably [26].
With the high classification rates so often cited, caution is in order: they mostly stem from a high signal-to-noise ratio under laboratory conditions; under a real-world low signal-to-noise ratio, in clutter and with bird confusion, the operational figures diverge [27]. It is precisely here that the most effective radar method against LSS comes into play: track-before-detect (TBD). Instead of first setting a threshold and then tracking, TBD integrates the raw signal along the hypothetical flight path and only decides afterward — the only way to capture targets below the classic detection threshold that an ordinary CFAR detector would discard [28], [29]. Coherent TBD integrates over monostatic, bistatic, and multistatic arrangements for arbitrarily long periods and detects targets “that are not detectable with conventional techniques” [30]. In a distributed sensor network that jointly evaluates the waveforms of all nodes, the localization error drops, as proven in real trials, to 20 to 42 centimeters at full detection rate in clutter [31]. And where one’s own sensor network is overloaded or jammed, software-defined nodes passively absorb the detection failure by exploiting foreign signals (signals of opportunity) — early warning survives a partial disruption [32].
3.5 Passive Radar (PCL): Seeing Without Transmitting
There is a class of radar that solves the core problem of the radio-silent threat from the opposite direction — by remaining radio-silent itself. Passive Coherent Location (PCL) transmits nothing; it exploits the already-present transmission signals of broadcast and cellular networks as illuminators of opportunity and evaluates their reflections off the target [33]. The principle is bistatic or multistatic: transmitter and receiver are spatially separated; what is measured is the bistatic time-difference-of-arrival (TDOA) and the bistatic Doppler (FDOA). A constant time-difference-of-arrival defines an ellipsoid of revolution with transmitter and receiver as its foci, on which the target lies; only the intersection of at least three such ellipsoids yields the 3D position, solved by weighted least squares or closed-form approaches and tracked with an (extended) Kalman filter [34], [35], [36]. The fusion of time-of-flight and Doppler suppresses ghost targets in the process, because a genuine target must be consistent both geometrically and kinematically at once [37].
For this study, PCL is for three reasons perhaps the most elegant answer to the radio-silent drone. First, it is itself emission-free: it cannot be jammed and cannot be located through its own radiation — the defender sees without giving himself away. Second, it strikes exactly at the hard target: the slow- and low-flying, propeller-driven attack drone with a small radar cross section that a classic radar loses in ground clutter can be drawn out through long coherent Doppler integration; and low-frequency illuminators in the VHF band (FM, DAB+) produce resonance effects at structural sizes in the meter range, which render even low-signature targets visible [38]. Third, it works with existing civilian infrastructure and can thus be deployed cheaply and sovereignly — a weighty argument precisely for a neutral state with a dense transmitter network.
The choice of illuminator determines the trade-off between range and resolution [33]. FM broadcast (VHF, high transmit power) reaches beyond 150 kilometers but, owing to low bandwidth, resolves spatially only coarsely — which can be improved by deconvolution methods [39]. DAB+ (bandwidth ~1.5 MHz, a noise-like OFDM signal with a near-ideal ambiguity function) delivers about 100 meters of resolution at the regional scale [40]. DVB-T/T2 (8 MHz) achieves 20 to 40 meters for precise tracking [38], and 5G New Radio promises, through the continuously transmitted synchronization signal blocks (SSB), near-meter resolution in the drone’s close range [41], [42]. The central technical hurdle is direct path interference — the transmitter’s direct signal is 60 to 100 dB stronger than the echo — which is filtered out with the Extensive Cancellation Algorithm and its Doppler-sensitive variants [43], [44]; receiver-side beamforming and learning-based resource allocation in the sensor network raise performance still further [45], [46].
Operationally, the maturity is proven. In the NATO measurement campaign SET-258 (Poland, September 2024, with Swiss participation), a passive system of the Hensoldt TwInvis type detected targets from light aircraft to ballistic missiles at ranges up to 300 kilometers and, for the first time, fed its tracks into a military network — the fusion of active and passive radar detection in concert [47], [48]. For Switzerland the starting position is favorable: a dense DAB+ single-frequency network and almost nationwide 5G coverage form an almost ideal PCL environment [49], and armasuisse is already researching the joint use of sensing and communication with the RadCom project [50]. PCL does not replace active radar, but it fills its gaps — above all in the topographically shadowed Alpine region — and adds to the staggered early warning a layer that the adversary can neither jam nor locate.
3.6 The Handover Point: From the Wide Sensor to the Narrow
Detection is not effect. Between the two stands the sensor handover — the orderly chain from the wide, coarse sensor to the narrow, precise one. In its proven form, the radar leads the initial detection, a wide-angle infrared sensor takes over coarse tracking, and a fine sensor on a fast-slewing mirror handles fine tracking, increasingly AI-controlled [51]. Even with two cameras this succeeds while conserving resources: a static wide-angle camera detects the small target, and a zooming camera on a pan-and-tilt turret is steered onto it [52]. This handover is the very core of every engagement chain — and it can be modeled before construction: simulation models for detection probability, false alarm, and measurement error of active as well as passive sensors make it possible to dimension an early-warning network before the first mast stands [53]. The lesson from airport doctrine applies equally to the military position: only layered multi-sensor fusion closes the LSS gap, embedded in a common situational picture [54].
But many sharp individual tracks do not yet make a situational picture. They must be merged into one recognized air picture, interpreted jointly, and presented to a decision-maker in a form he can grasp under time pressure. That is the work of command — and the subject of the next chapter.
4. Situational Picture, Command, and Planning Automation
Defense is won not by the strongest effector, but by the shortest, most robust loop between seeing and acting. If the previous chapter showed how the defense detects the radio-silent target in the first place, this one addresses what happens between detection and effect: the fusion of many tracks into a single air picture, the automated allocation of scarce effectors across many targets, and the continuation of all of this even when one’s own networking is itself disrupted. Here the battle against the saturation swarm is decided.
4.1 The Single Recognized Air Picture
Military command is distributed, dynamic decision-making under uncertainty — sensors, communications, computers, and effectors must be brought together into one process whose performance can be measured [55]. The situational picture is therefore not a screen but the fused basis for decision: the single recognized air picture, in which all individual tracks converge into a jointly interpreted situation. Its prerequisite is a common data semantics — without a standardized command language there is no common air picture and no rapid handover between sensor and shooter; the RAND program for a universal C2 language addresses precisely this interoperability across system boundaries [56].
The bottleneck against LSS swarms is not the effector, but the shortening of the decision loop. NATO doctrine and its analyses agree that accelerating the OODA cycle — observe, orient, decide, act — decides victory or defeat; the integration of unmanned systems “could shorten the time to engagement and increase precision” [57], [58]. The only firmly documented end-to-end figure remains the detection latency of 142 milliseconds and the 30-second early-warning time of a fusing early-warning system [18]; the full loop reduction in seconds is operational and mostly classified. The direction, however, is unambiguous: whoever moves faster from seeing to acting wins.
4.2 Architecture of the Battle Management System
For a distributed situational picture to hold, it requires a service-oriented, loosely coupled architecture: scalable, reusable, survivable, and interoperable across a common data bus, so that the commander can direct a dynamic, robust situation [59]. That this interoperability is not mere theory is shown by NATO’s technical interoperability exercises: across four editions, 60 to 70 systems each — sensors, effectors, jammers, threat drones — were tested live on detection, identification, and neutralization and on their interplay across manufacturer boundaries [60]. NATO’s first counter-UAS doctrine, adopted at the end of 2023, expressly advises member states to take layered approaches and to conduct joint operator training; it was trialed under real jamming conditions in an exercise on the Black Sea [58], [61]. The doctrine, however, lags behind the threat: planning against swarms demands a deeper redistribution of roles across all domains than existing force structures allow [62].
4.3 Planning Automation: Weapon-Target Assignment Under Saturation
Once the air picture is fused, the saturation attack poses the truly hard question: Which effector engages which target first? With dozens of simultaneous tracks, this assignment exceeds human real-time capacity — and this is where planning automation begins. Weapon-Target Assignment (WTA) is “the decisive decision support in command and operations.” Against swarming, cheap, low-risk targets, the classic point-to-point saturation salvo fails economically; the problem must be reformulated for area targets and under realistic operational constraints — collateral damage, safety distance, damage threshold, preference assignment [63]. The next step couples seeing and acting in one optimization problem: the dynamic sensor-and-weapon-target assignment model unites threat assessment, detection probability, damage probability, and decision timing, and solves them via an evolutionary algorithm [64].
Abbildung 2: Weapon-target assignment under saturation: from the attacking swarm through the optimizer to heterogeneous effectors. Source: Chapter 4.
4.4 When Learning Beats the Heuristic
The key finding of recent research: against kamikaze swarms, a learning policy beats the hand-crafted rule. A reinforcement-learning agent learns in high-fidelity simulation to coordinate multiple effectors and to optimize interception priority; against a rule-based baseline, it achieves consistently lower average damage and higher defense efficiency across hundreds of attack scenarios while protecting critical zones — as a strategic layer that complements existing fire-control systems rather than replacing them [65]. The finding is robust: improved deep-RL methods beat classical dynamic WTA solvers in win rate, reward, and resource efficiency [66], and swarm-intelligent variants scale the assignment into “large-scale extreme conditions” [67]. Instead of a single solution, multi-objective optimization presents the decision-maker with a Pareto set of alternative plans that simultaneously minimizes collateral damage and resource consumption [63] — it relieves the operator of the burden of real-time computation without taking away the choice.
4.5 Effector Coordination and Swarm Against Swarm
Assignment alone is not enough; the effectors must also coordinate. A networked defensive swarm self-organizes its interception formation upon detection, tracks the enemy aircraft through self-balancing clustering, and remains resilient to communication losses — a fully decentralized approach that continues without a central authority [68]. The bottleneck of cooperative multi-agent systems is communication itself: methods that restrict messages to reachable neighbors and optimize partner selection under jamming are directly transferable to coordinated effectors in the contested spectrum [69], [70]. Even the order in which the effectors make their decisions is a learnable factor that influences overall performance — important when scarce effectors must be allocated sequentially [71].
4.6 The Human Above the Loop
This raises the decisive question: why let the machine decide at all — and why, even so, only under human control? The answer lies in time. A fusing early-warning system closes its detection and classification loop in roughly 142 milliseconds [18]; a human needs, for perception, decision, and action in response to a single stimulus, fractions of a second up to several seconds — and a multiple of that to evaluate dozens of simultaneous tracks and assign effectors to them. Against a saturation swarm that floods in within seconds, the machine is therefore faster not gradually but by orders of magnitude. This speed gap is not a convenience but a hard limit: weapon-target assignment under saturation fundamentally exceeds human real-time capacity, which is why it must be automated [63], [65]. Whoever refuses to let the machine compute here will lose — not from any weakness of the personnel, but because the physics of the inbound attack is faster than human cognition.
Precisely for that reason, however, automation belongs under control. The more the machine takes over the assignment, the sharper the question of the human’s role becomes. With a loop that closes in milliseconds, “the human in the loop” — releasing each effect individually — is no longer sustainable; the role shifts to the human above the loop, who sets the rules of engagement, supervises the automated proposal, and can override and abort at any time. This is exactly how the manufacturer of the Patriot system describes its operation: “automated operation with override capability” [72]. And this is exactly where the danger lies. The highly automated Patriot fratricides of 2003 — the downing of friendly and allied aircraft — were a mixture of human and machine failure; their core lesson is that override becomes a fiction the moment the operator can no longer verify the automatic tracks [73], [74]. Automation bias is not a theoretical risk: systems that fail to capture operational complexity “kill allies” — with immediate consequences for the responsibility of the operators [75], [76].
There is a constructive way out. Decision support that adaptively narrows the human’s options to a meaningful subset preselected by the AI let humans perform markedly better than on their own in a controlled large-scale study — proof that “human above the loop” works through deliberate option narrowing, rather than having to choose between full autonomy and full manual overload [77]. Here, trust and reliance must be cleanly distinguished: trust in the defense system is a fluctuating quantity measured over time, with thresholds of its own, not a static switch — and any claim about “trust in the automation” must capture this dynamic [78], [79]. The normative depth of this question is treated in the legal chapter; for command, the sober core holds: the machine accelerates detection and proposal, the human retains the release authority.
4.7 Command in the Disrupted Network
All of this presupposes that the command system still functions at all. The adversary of 2036 will attack exactly that — the networking of the defense itself. Future command must therefore operate under DDIL conditions: denied, degraded, intermittent, limited communications. The linear command practices inherited from the industrial age are too slow to maintain the edge; what is required is robust human-AI partnerships and a streamlined command process [80]. At the same time, the honest counter-voice cautions: delegating command functions to an AI can even increase the fragility of the system and lead to catastrophic errors. The remedy is a design principle drawn from agility and antifragility — a system that learns from shocks and emerges from them strengthened, rather than breaking [81], [82].
The formal foundation for this is provided by control theory: distributed control laws guarantee resilient consensus and collision avoidance without global state knowledge, even under changing topology and faulty or adversarially manipulated nodes [83], [84]. And the early warning itself survives partial disruption: if one’s own network fails, software-defined sensor nodes passively absorb the detection outage through external signals [32]. The defense of 2036 thus mirrors the drone it fights — just as the combat drone recognizes autonomously, networks covertly, and navigates with fail-safe robustness, the defense must see radio-silent swarms across multiple sensors, fuse them into a single air picture, solve the assignment automatically under saturation, and carry all of this forward in the disrupted network, with the human above rather than in the loop.
5. High-Power Microwaves (HPM): Area Effect Against Swarms
If any effector can defeat the autonomous, radio-silent drone not by denying it value but by striking it, this is the one. The high-power microwave is the only layer of defense against which the attacker’s silence offers no protection — and at the same time the only one that engages several targets at once. It therefore opens the effector program.
5.1 Operating Principle: Energy Driven Directly Into the Circuitry
The high-power microwave couples electromagnetic energy directly into the target’s electronics — independent of software architecture, communication protocol, or degree of autonomy [85]. This is precisely its strategic value: a drone navigating optically and inertially, receiving nothing and immune to jamming, remains vulnerable to a microwave pulse, because the pulse does not attack its radio link but its semiconductors. The primary coupling path is so-called back-door coupling: internal wiring harnesses act as unintended receiving antennas, and the effect sets in long before the semiconductors burn out — as a violation of logic thresholds in the signal between flight computer and motor controller [85].
5.2 Performance Parameters and Area Effect
A multiphysics model with ten thousand Monte Carlo runs quantifies the effect of a 2.45 GHz reference system with precision [85]. Resonance is decisive: motor-controller signal lines 5 to 8 cm long lie in half-wave resonance and experience an induced voltage five to ten times higher than other conductor lengths. In continuous-wave operation at 25 kW, the kill probability is 51.4 ± 1.0 % at 20 m and falls to 13.1 ± 0.7 % at 40 m; in pulsed operation at 500 kW peak (1 % duty cycle, a thermally manageable 5 kW average power), the 90 % kill range rises from roughly 18 m to 88 m [85]. The geometry is decisive for swarm defense: at 30 m the beam cone covers about 7.5 m in diameter — that is, several closely flying drones at once, which drastically lowers the requirement for precise mechanical tracking [85]. Experimentally validated sources such as the Magnetically Insulated Line Oscillator (MILO) deliver 3 GW L-band pulses as a blueprint for vehicle-mounted systems [86].
Abbildung 3: High-power microwave vs. swarms: effect over distance. Source: Chapter 5.
5.3 Systems
On the industry and government side (to be read as such, since performance data are largely classified), the U.S. Army is fielding IFPC-HPM in containerized form, built on the technology base of the AFRL program THOR and its successor, Mjölnir [87]. Epirus Leonidas — a solid-state phased-array HPM, also mounted on the Stryker and available as a compact pod — is marketed explicitly against radio-silent, fiber-optically controlled drones. In Europe, Diehl offers a container or vehicle solution with its HPEM effector SkyWolf. What they all share is the “unlimited magazine”: because the effector works purely electrically, only the power supply limits the number of shots.
5.4 The Advantage — and Its Limits
Strategically, the microwave excels against electronics and swarms and is more atmospherically robust than the laser, but it suffers from limited range, adversary hardening, and thermal management [87]. Its “one-to-many” area effect mitigates the saturation problem, yet against very large swarms multiple integration remains necessary — limited by electrical energy and cooling. And it has an economic Achilles’ heel: a cheap vanguard drone can bait the expensive microwave weapon into firing, whose effect signature then warns the following elements and betrays its position [88]. The microwave is thus the load-bearing outermost layer against the hardest threat — but no layer unto itself. The next ring belongs to the laser.
6. High-Energy Laser (HEL): Precise Single-Target Engagement
What the microwave thins out across an area, the high-energy laser takes down one by one, surgically. It is the precise middle layer of the defense — with a deep magazine, as long as the energy holds, but bound by one hard physical constraint: at any given moment it can engage exactly one target.
6.1 Thermophysics of Ablation
The laser works through heat. A near-infrared beam (1.06–1.55 µm) is absorbed within a micrometer-thin layer, conducts heat inward, melts and vaporizes the material, and at extreme power densities turns it into plasma [89]. The target material governs the engagement time: aluminum alloys initially reflect strongly, conduct heat away efficiently, and demand energy — penetrating a 2 mm shell requires roughly 44.4 kJ, while at more than 10 kW/cm² perforation is achieved within seconds [90]. Carbon fiber–reinforced polymer (CFRP), by contrast, absorbs strongly but conducts heat laterally only poorly; the result is localized thermal runaway, delamination, and spalling — CFRP fails markedly faster than metal [91].
6.2 System Maturity and Power Classes
Europe is well advanced here: Rheinmetall and MBDA tested a roughly 20 kW naval demonstrator for more than a year aboard the frigate “Sachsen,” with projected operational readiness from 2029 (industry figure). On land, EOS “Apollo” (manufacturer figure) scales from 50 to 150 kW and claims more than 20 Class 1 drones per minute; compact short-range systems such as SkyLANX (3–8 kW) penetrated 1.2 mm of steel at 1,100 m in 10 s during testing. Established industry knowledge (to be read as such) includes Rafael Iron Beam (~100 kW), Britain’s DragonFire (~50 kW), and Lockheed HELIOS (~60 kW). Fiber lasers have the highest maturity level for operational deployment; the power roadmap leads from the ~150 kW practicable today to the 500 kW class [92].
Abbildung 4: High-energy laser: dwell time vs. distance and power class. Source: Chapter 6.
6.3 The Swarm Dilemma
Here lies the limit of the laser. It is sequential: each effector engages only one target at any given moment [93]. The time spent on the target (dwell time) amounts to about 1.3 s against a Class 1 drone at 50 kW and up to 4.4 s against a Class 2 drone [90]. More treacherous still is the paradoxical kinematics: as the swarm closes in, the required dwell time does fall, yet the angular separation between the drones grows, so that the tracking time (slew time) rises drastically — slew and dwell add up, and a saturation swarm may not be fully destroyed before the remainder reaches the target [90]. Added to this are the environment (atmospheric attenuation, thermal blooming) and the energy store as the true magazine limit [94]. Against very large swarms, multiple integration is therefore necessary, and a monolithic dependence on the laser is out of the question.
6.4 The Laser in Asset Protection
Despite these constraints, the laser is indispensable: as the surgical layer against the leakage that the microwave lets through, and against hardened single targets against which HPM fails. Its central self-protection advantage is magazine depth as a function of the energy supply rather than of ammunition — with a generator available, the number of shots is practically unlimited [92]. Whatever even the laser cannot bring down in time falls to the next, kinetic ring — programmable fragmentation effect.
7. Programmable Munitions: Controlled Fragmentation and Anti-Aircraft Artillery
Against a tightly clustered swarm at close range, the most effective tool is not directed energy but an old idea rendered with new precision: the gun that detonates its round exactly where the swarm is flying.
7.1 AHEAD: Muzzle Programming and a Steered Fragment Cloud
The Skynex system by Rheinmetall/Oerlikon, firing 35 mm AHEAD munitions (Advanced Hit Efficiency And Destruction), turns the spread shot into a controlled effect [95]. A muzzle measurement captures the actual muzzle velocity of each individual projectile and transmits the exact fuze time to it by means of an induction coil. Just short of the calculated intercept point, the round breaks apart and ejects 152 heavy tungsten sub-projectiles as a cone-shaped cloud that stands in the path of the incoming drone, kinetically penetrating its aerodynamics, electronics, and sensors [95].
Abbildung 5: AHEAD principle: muzzle programming and a steered fragmentation cloud. Source: Chapter 7.
7.2 The Advantage Against Clustered Swarms
This is precisely where its strength over the laser lies: a single, precisely placed burst can neutralize several closely spaced drones at once, whereas the sequential laser would have to work through them one after another. For dense formations at close range, the programmable fragment cloud is therefore superior to the laser — and it is weather-independent, where atmospheric attenuation and thermal blooming weaken directed energy.
7.3 Placement Within the Layered System
Programmable anti-aircraft artillery is not the outermost layer but the innermost: short range, high effect density, robust all-weather capability. It catches what microwave and laser let through, and it closes the gap that every form of directed energy leaves open at short distance and in poor visibility. As the successor to the 35 mm line being phased out in Switzerland, it therefore remains an integral part of credible close-range protection. Whatever slips past it during the outer approach is in turn taken on by mobile hunters — kinetic interceptors, to which the next chapter is devoted.
8. Kinetic Interceptors: The Mobile Hunters
What microwave, laser, and gun fire let slip during the outer approach is taken on by mobile hunters — drones that intercept other drones. They are the only layer of effect that follows the attacker onto its own ground: into the air, into the motion, into the swarm itself. And they are the only kinetic layer that inverts the ruinous cost curve of air defense.
8.1 The Economic Inversion
The guided missile hits almost without fail, yet costs a thousand times the price of its target — against mass that is untenable (cf. Chapter 13). The interceptor drone reverses this ratio: with unit costs on the order of 1,200 to 3,500 USD, it stands eye to eye with the attacking drone and, for the first time, makes defense scalable [96]. It is thus the kinetic answer to the cost asymmetry: not an expensive missile against a cheap drone, but a cheap hunter against a cheap attacker. For that to work, the hunter must be capable of two things — striking precisely and scaling in numbers. Both are today the subject of robust research.
8.2 The Art of Hitting in Midair
To ram a target in flight with one’s own platform, or to catch it with a net, is a hard control-engineering problem: the target maneuvers, the image processing lags, the wind interferes. The breakthrough is called image-based visual servoing (IBVS). It decouples the hunter’s flight dynamics from the orientation of its camera and combines them with proportional navigation and a delay-compensating Kalman filter. In simulation, the method achieves a hit radius of 0.089 meters — nearly 73 percent better than the best comparison value — and, in the open field, an interception rate above 80 percent at winds below 4 m/s and a terminal speed of 20 m/s [97]. A robust variant with a fixed-mounted camera confirms this terminal performance against maneuvering targets in hardware-in-the-loop and free-flight tests [98]. And the range is growing: a sector line-of-sight guidance scheme presented in 2026, running on a lifting-wing quadcopter with nothing more than a monocular camera, still intercepts agile targets in real wind at up to 138 meters — roughly half again as much usable thrust as conical guidance methods provide [99]. The hunter of 2036 does not hit by chance; it hits predictably.
8.3 Three Ways to Take Effect: Net, Ramming Strike, Fragmentation
How the hunter wrestles its target down branches into several options. The net is the lowest-collateral effect: the operating principle is entanglement rather than destruction — the net wraps around rotors and airframe, blocks the propulsion, and brings the target to the ground without any detonation, with the chain of evidence preserved [14]. Scientifically, drone-against-drone net capture has been validated as an autonomous multi-UAV defense system [100], and the only peer-reviewed hardware study characterizes the launcher itself [101]. How large the net must be is not a constant but a function of the target’s kinematics — and the central finding reads: the faster the hunter closes in, the smaller the net it needs [102]. The ramming strike dispenses with a payload entirely: the DLR interceptor drone CUSTODIAN detects, tracks, and neutralizes the hostile aircraft through an autonomous strike in midair [103]. And the fragmentation approach, finally, turns the hunter itself into a projectile: Diehl’s electric interceptor CICADA is dual-purpose by design — optionally with a fragmentation warhead (lethal) or a capture net (non-lethal) [104]. One operating principle for every situation, from the forensically usable apprehension to hard destruction.
8.4 Operational Systems
The family is real and in the field. The radar-guided platform Fortem DroneHunter F700 captures fully autonomously with a tethered or free net, detects with its own onboard radar at roughly 3 kilometers, and tows captured targets away [105]. The Delft Dynamics DroneCatcher, with its pneumatic net cannon, has been in service with the Dutch police since 2017 and pulls small drones out of sensitive airspace [106]. For the fast, heavy attacker there are high-speed kinetic hunters: a system such as MARSS reaches roughly 290 km/h, enough to run down Shahed-type attack drones (~185 km/h) [96]; the U.S. counterparts Coyote Block 2 and Roadrunner-M stand in the same class of reusable kinetic interceptors. The ground-based edge is covered by the shoulder-fired net launcher SkyWall Patrol (up to ~100 m) and the automated SkyWall 300 with computer-assisted tracking (250 m, 8 m² net, reload in seconds) [107], [108] — both take effect without any electronic countermeasure, precisely where jamming is legally ruled out.
The peer-reviewed core reference for the radio-silent threat models exactly the case of this study: a GPS-denied, bomb-carrying, uncontrolled kamikaze drone over urban infrastructure. The proposed solution is two net-cannon drones — the first catches the drone, the second the dropped payload — one of which additionally carries an EMP weapon to shorten the capture time; compared with the state of the art, neutralization time and total cost fall measurably [109].
Abbildung 6: Kinetic interceptors: range and carrier platform. Source: Chapter 8.
8.5 The Sequentiality Trap and the Swarm’s Answer
Here lies the hard limit. A single hunter — whether a ground launcher or an interceptor drone — engages exactly one target per shot. Against a saturation swarm, the linear single catcher loses structurally, the same trap as with the sequential laser. Game theory makes it rigorous: in k-capture, the catch succeeds only if the target lies inside the convex hull of the pursuers — against an agile target, this therefore requires a plurality of coordinated hunters, not one [110]. And if the hunter is slower than the target, a barrier exists beyond which the attacker is guaranteed to get through — speed superiority is not a comfort metric but a condition of existence [111].
The answer to the swarm is therefore the swarm. An autonomous defensive drone swarm organizes its interception and capture formation itself, operates GPS-free and resilient against communication losses — that is, hardened even against electronic jamming [112]. A criticality-driven online allocation with a provably finite time to first capture achieves 85.6 percent neutralization under uncertain sensing and 99.9 percent under deterministic sensing [113]. So that the hunters do not get in each other’s way while doing this, a collision-aware integer optimization method assigns the defenders to the attackers in such a way that the sum of capture times remains minimal and self-collisions are avoided [114]; where the swarm splits up, the choice is either to intercept or to herd it into a safe zone [115], and a hierarchical interception chain explicitly scales the method against “large-scale, highly maneuverable swarm intruders” [116]. Above it all, a learning prioritization layer orchestrates which hunter takes which target first, and consistently lowers the average damage below that of a rule-based control [65].
8.6 The Containerized Loitering Magazine
From these building blocks — a cheap hunter, precise terminal guidance, mesh coordination, and 1:1 assignment — assembles a form of defense that tips the reaction-time race against the saturation swarm in the defender’s favor: the containerized loitering magazine. Picture it as a ground-based cartridge of flying interceptors.
At rest, the interceptor drones wait packed inside weatherproof launch canisters — a magazine of vertical-launch tubes distributed around the protected asset, energetically ready yet inconspicuous and low-emission. When the layered early warning (Chapters 3 and 4) detects the incoming swarm and estimates its strength, the fire control triggers a threat-matched salvo launch: not the whole magazine takes off, but exactly as many interceptors as the weapon-target assignment demands against the detected number of attackers — a cost-conscious dosing that avoids expensive oversaturation and keeps reserves for the second wave. The launched drones do not climb straight into the attack but enter a loitering mode: they gather in a waiting layer between the magazine and the expected approach corridor, hold position and energy, and link up over a mesh radio network into a formation. This waiting is the real trick — it decouples the (slow) launch from the (fast) intercept and places the hunters in a favorable geometric starting position before the adversary is within range.
Within the mesh, the hunters negotiate target distribution in a decentralized manner: each interceptor takes exactly one enemy drone, with double assignments and self-collisions resolved across the formation — a distributed, collision-aware assignment that needs no central authority and tolerates the loss of individual nodes [114], [112]. If a hunter drops out or an additional target appears, reassignment happens in real time [113]; a learning prioritization decides which hunter strikes first, and a hierarchical interception chain scales the scheme against large, highly maneuverable swarms [65], [116]. Only at the right moment — when the assigned target enters the optimal intercept geometry — does the drone leave its loitering point and go into the terminal run under image-based guidance [97], [99], where it subdues its target by net or ram (8.3). Speed superiority in the terminal strike remains an existential condition, for a slow hunter is guaranteed to lose against the fast target [111], [110].
Operationally, this architecture is already taking shape in real, reusable ground-launched interceptors — systems of the Coyote and Roadrunner class launch from canisters, can loiter, and, if not used, return for reuse [96]. The appeal of the concept lies in the sum of its properties: it is EW-independent in effect (it hijacks no radio, it catches mechanically), economically scalable (cheap hunters, dosed launch), suited to radio silence (it needs no signal from the target), and antifragile (mesh rather than central control). It is precisely this combination that makes the containerized loitering magazine perhaps the most convincing kinetic answer to the autonomous saturation swarm of 2036.
Abbildung 7: Containerized loitering magazine: ground-launched interceptor drones, mesh-coordinated 1:1 assignment against the swarm. Source: Chapter 8.
8.7 Assessment
The kinetic hunter is the most cost-honest layer of the defense and the only one whose effect electronic jamming cannot devalue — for a net does not ask the target about its radio channel. Its price is scaling: one hunter catches one drone; against the swarm it takes a swarm of hunters, fast enough and numerous enough to close the hull. What it does not catch falls to the ground — and it is exactly there, at the plummeting debris and at the overtaxed shelter, that the next chapter on purely physical protection begins.
9. Physical Protection: Protective Nets and Cages
There is one defensive layer that survives every electronic and every active countermeasure, because it depends on none of them. It does not transmit, it does not aim, it does not count — it simply stands there. Passive physical protection inverts the principle of defense: rather than capturing the target, it stretches a barrier across the protected space that stops every drone that flies into it. It is the plainest and at the same time the most robust answer to the radio-silent swarm.
9.1 The Inverted Principle: Spanning Instead of Capturing
A net stretched over an ammunition depot, command post, trench, or supply route works purely mechanically — and is therefore entirely independent of the electromagnetic domain and indifferent to swarm size. It does not distinguish between one and a hundred incoming drones; it catches every one that flies into it [117]. This is not a concept but field reality: a field study of the Russo-Ukrainian war records that lasers, high-power microwaves, and radio jammers do not reliably neutralize weaponized drones — and that both sides therefore resort to metal grids and nylon net barriers that “destroy and stop drones to a certain degree” [117]. The photographic evidence comes from a military-medical journal: an enemy FPV drone that attacked an armored ambulance and became caught, along with its attached munition, in the protective net [118]. The net accomplished what no jammer could.
9.2 Mesh Size, Load, and the Physics of Design
As simple as the principle is, the design is precise. The central parameter is mesh size versus drone size: the mesh must be smaller than the smallest enclosable cross-section of rotor and airframe of the expected threat pattern, or the drone will punch through the net. At the same time, a finer mesh drives up weight, wind load, and obstruction of sight, and the supporting structure — masts, cable bracing, frames — must absorb the dynamic impact load plus its own weight [117]. The underlying impact physics is the same as in active net capture and is analytically tractable: the target kinematics determine which area a barrier must cover and what load it must bear [102]. The design of a protective net is thus an engineering problem with clear control variables, not an improvisation.
9.3 The Protective Cage: Passive Protection with a Hard Data Base
Where the net relies on entanglement, the protective cage (cope cage) relies on pre-detonation. The most rigorous peer-reviewed source on passive protection examines cage structures against FPV kamikaze drones that strike thinly armored turret and roof zones at a nearly vertical angle. Using explicit detonation simulation, it compares materials; the optimized multilayer configuration reduces the transmitted pressure by 78 percent and the displacement by 96.5 percent relative to the unprotected structure, with high-strength low-alloy steel delivering the best strength-to-deformation balance and hybrid designs incorporating fiber composites delivering the best pressure mitigation [119]. Cage and net complement each other: the cage triggers premature detonation of the shaped charge at a standoff distance, while the net catches the low-flying drone through entanglement before it detonates. Both are passive, mechanical, and immune to jamming — they simply cover different threats [119], [117].
Abbildung 8: Passive physical protection: protective cage and protective net compared. Source: Chapter 9.
9.4 The Structural Advantage and Its Limit
Here lies the real value of this layer. Passive protection is swarm-indifferent: unlike any active effector with a finite rate of fire, the barrier does not respond to the number, coordination, or degree of autonomy of the attackers, but solely to the physical impact. It is the rare case of a defense whose effectiveness does not collapse as swarm size grows — while lasers, anti-aircraft guns, and interceptors fail at saturation, the stretched net remains equally effective against each individual arriving drone.
The price of this robustness is the reach of the protection. A stretched net covers an area or an object, not an airspace — it is point and object protection, not area protection, and it costs obstruction of sight, weight, and wind load [117], [102]. It protects what lies beneath it, and nothing beyond. Research concepts attempt to shift the area effect into the air — for instance, the controlled dispersion of a cloud of biodegradable adhesive microfibers intended to entangle several rotors at once — yet this remains a concept study without a prototype, sensitive to weather and untested in altitude as well as in civilian environments; interesting as a research direction, but not yet available as a system [120]. In layered defense concepts, passive protection therefore forms the innermost, jamming-independent fallback layer behind detection, command, electronic, and kinetic engagement [121].
9.5 The Insurance Policy
Physical protection and net capture are the insurance policy against the autonomous, radio-silent drone of 2036 — the effect chain that takes hold when every electronic countermeasure rebounds off the silent, independently navigating target [109]. Passive protection is the one component whose effectiveness does not collapse with attacker numbers, bought at the cost of being confined to the point it spans. No defender will net its entire area of operations; but every command post, every depot, every high-value node can be placed under a net that relieves the expensive active layers — and it is precisely this interlocking of active and passive protection that leads to the self-protection of command structures, the subject of the chapter after next.
10. Electronic Warfare as a Defense — Possibilities and Hard Limits
For years, electronic warfare was regarded as the cheapest and most area-wide means of counter-drone defense: jam the radio link and the drone falls from the sky. Against the autonomous drone of 2036, this approach runs into a fundamental limit — and yet it remains a tool whose strengths and weaknesses must be understood precisely.
10.1 Operating Principle: Jamming and Spoofing the Defense
Classic soft-kill defense saturates the drone’s control link (typically 2.4/5.8 GHz) or overrides its satellite signal. When a remotely piloted drone loses its link, its fail-safe behavior takes over — hovering, landing, returning home; if its GNSS is spoofed, it can be steered to a false position [11]. The appeal lies in the economics: very low cost per engagement and broad area coverage. Precisely for this reason, EW is today the first choice in both civilian and military counter-drone defense.
10.2 RF Cyber Takeover: Soft-Kill Without Jamming
A more sophisticated, less collateral variant of soft-kill dispenses with the brute-force drowning-out of the radio link and instead takes over the drone through its own control protocol. This protocol-based radio takeover (RF cyber takeover) belongs to the soft-kill family of counter-drone defense and works in three steps: it passively detects and localizes the drone by its radio traffic, identifies the control protocol in use against a signature library, and then intervenes precisely in the control channel to assume command — landing the drone in a controlled manner, sending it back to its launch point, or steering it out of the protected zone [11], [14]. The great advantage over the broadband jammer is the way it spares the surroundings: because nothing is drowned out and only the single control channel is hijacked, satellite navigation, public-safety radio, and legitimate drones in the vicinity remain undisturbed — which makes this class of system attractive for sensitive, jointly used civilian spaces such as airports, city centers, and critical infrastructure.
As elegant as this is, its limits are just as sharp — and for this study they are the decisive ones. The takeover presupposes two things that the autonomous drone of 2036 specifically denies. First, it requires an active radio control channel into which it can intervene; a drone that navigates optically and inertially and flies under radio silence offers no channel for takeover — there is simply nothing to hijack. Second, the method depends on a library of known drone protocols; against unknown, proprietary, encrypted, or frequency-hopping protocols that are not on file, the takeover comes to nothing. The protocol-based takeover thus shares the fundamental fate of every soft-kill: highly effective against the great mass of commercially available, remotely piloted drones — and ineffective against the radio-silent, autonomous spearhead that is the concern of this study. It is the best possible answer to the drone of yesterday, not to the drone of 2036.
The three soft-kill methods can be compared by operating principle, collateral effect, and the hard limit they share:
All three work against the remotely piloted mass — none against the radio-silent, autonomous spearhead.
10.3 Detection and Localization via Emission
When the drone transmits, it gives itself away. Passive radio detection recognizes and localizes control and telemetry links and can use them as a trigger for targeted jamming or a kinetic engagement [11]. Against spoofing, in turn, a mature detection capability exists on the receiver side — from signal-feature analysis to machine-learning methods — that makes the defense more robust [122].
10.4 The Absolute Limit
Here the reach of electronic warfare ends. A drone that navigates optically and inertially, recognizes its target on board, and flies under radio silence receives nothing that could be jammed — against it, EW is ineffective [11]. Even a sophisticated satellite deception is actively countered by the advanced adversary: receivers such as SemperFi expose the false signal through a forced maneuver and recover the true position within fractions of a second [12]. Electronic warfare thus remains effective against the great mass of simple, remotely piloted drones — but not against the autonomous spearhead that is the concern of this study.
10.5 Counters and Collateral
Two further barriers come into play. First, one’s own airspace: broadband jamming in jointly used civilian spaces (airports, large events) disrupts public-safety and emergency communications and is therefore subject to authorization and locally limited [11]. Second, the adversary’s adaptation: a cheap vanguard drone can lure the defense into transmitting or engaging and thereby warn the following, radio-silent elements [88]. The sober conclusion: EW is a valuable, low-cost layer against the mass — but it cannot stop the autonomous swarm on its own. It needs the kinetic and energetic layers of the preceding chapters and, above all, a nervous system that holds even under interference. To this the following chapters turn.
11. EW-Resilient Communication Among the Formations
A defense is only as strong as the network that binds its parts together. Sensors, effectors, and command posts act as a single system only once they exchange tracks, orders, and weapons-release authorizations in real time — and it is precisely this networked fabric that the adversary of 2036 attacks, through jamming, deception, and the suppression of the satellite signal. Where the airborne nervous system of the swarm (Chapter 2) aims at faster swarming, the terrestrial backbone of the defense aims at the opposite: holding harder. It must carry the load at exactly the moment it is being jammed.
11.1 The Requirement: Networked Fire in a Contested Spectrum
Networked fire — the coherent fusion of many sensors and the coordinated triggering of distributed effectors — demands three things at once: a jam-resistant data link, a guaranteed sub-millisecond delivery, and a common time base in the nanosecond range. Each of these three pillars is a target in its own right. Jam-resistant networked command and control therefore rests on four interlocking answers: hardened data links with receiver-side jamming suppression, a self-healing ground network, a GNSS-independent time base, and — in the event of a total blackout of the radio spectrum — a retreat into media that are physically hard to jam.
11.2 Hardened Data Links and Receiver-Side Null Steering
The foundation has been proven for decades. The tactical data link Link 16 (JTIDS) owes its jam resistance to a stack of combined measures — frequency hopping, direct-sequence spreading, jitter, double-pulse redundancy, and Reed-Solomon coding [123] — and it retains its anti-jam margin even when the usable frequency band is trimmed in favor of civil aviation [124]. Its NATO successor SATURN (STANAG 4372) replaced the HAVE-QUICK systems, which had become eavesdroppable, starting in 2023, and synchronizes the network over a common time base [125], while TTNT, as the most recent generation, is tailored to time-critical, rapidly re-networked targets — exactly the profile of counter-drone defense [126]. Which anti-jam measure takes effect, and when, is no longer static but an adaptively chosen mix of mechanisms [127]; looking ahead, concurrent-code spreading even eliminates the need for a pre-shared key, and thus the attack surface that comes with it [128].
The transmitter-side art of hiding is mirrored by the receiver-side art of filtering out. A Controlled Reception Pattern Antenna (CRPA) shapes its reception pattern adaptively and places a spatial null in the direction of the jammer — achieving up to 34 dB of jamming suppression even with coarsely quantized 2-bit phase shifters. The difference is measurably the one between “the network holds” and “the network fails”: at a jam-to-signal ratio of roughly 70 dB, the protected receiver sustains a usable signal, while the unprotected one degrades to the tracking threshold [129]. Reconfigurable metasurface antennas raise the degrees of freedom still further, so that a single ground node can null several jammers at once [130].
11.3 The Self-Healing Ground Network: Around the Jammer, Not Through It
Physical jamming suppression alone is not enough in a multi-hop network. The more powerful lever is routing: a networked fabric should route around the jammer, not merely transmit through it. Routing that explicitly accounts for the jamming environment of each path saves energy and requires only the jamming measured at each node [131]. Over this lies a self-healing layer that cures failures in the physical network and contains the contagion of cascading outages [132].
For time-critical effector triggering, “arrives eventually” is not enough — it requires guaranteed latency and guaranteed delivery. Frame Replication and Elimination for Reliability (FRER, IEEE 802.1CB) replicates each frame across redundant paths and discards the duplicates upon merging; in simulation, this eliminates packet loss entirely and achieves sub-millisecond recovery from link and node failures [133], [134]. This gain does not come for free: replication increases burstiness and packet misordering and can raise the delay in the nodes that are traversed — a warning against naive redundancy design in a latency-critical network [135]. Robustness must be dimensioned, not blindly doubled.
11.4 Time That Survives GNSS
The most delicate dependency is time. Networked fire requires a common time base with nanosecond accuracy, and GNSS delivers it today — but it is the first thing the adversary jams or falsifies. The answer is threefold. First, holdover: a centimeter-sized chip-scale atomic clock keeps a sensor node’s timing for hours without GNSS [136]; as a reference class, rubidium fountain clocks show that continuously running atomic clocks stay within a few nanoseconds over years [137]. Second, spoofing detection before the time base is poisoned: even inexpensive receivers distinguish, through combined signal metrics, the states nominal, jammed, spoofed, and blocked [138], and learning-based methods proactively detect unknown time-manipulation attacks with more than 97 percent accuracy [139]. Here a hard lesson applies: cryptography alone is not enough. Even authenticated GNSS signals can be displaced by relay attacks to locations thousands of kilometers from the true position, without breaking a single cryptographic operation [140]. Third, therefore, the network-internal, GNSS-independent distribution of time: self-stabilizing, Byzantine fault-tolerant clock synchronization keeps the network in sync even when GNSS fails and individual nodes are compromised and feed in false times [141], [142]. Over a fiber-optic backbone, the White Rabbit method distributes sub-nanosecond time across the entire field — in a large-scale experiment to under 500 picoseconds across thousands of nodes, with temperature correction down to 50 picoseconds [143].
11.5 The Retreat Into Physics
When the omnidirectional radio spectrum is fully contested, networked command and control falls back on media that are physically hard to jam. Directional mmWave point-to-point links are jam-resistant and covert at the same time: the high atmospheric absorption of the upper millimeter-wave bands limits an eavesdropper’s range on its own, and adaptive tuning to this absorption creates covert communication zones that are quickly adjusted to moving nodes [144]; the narrow beam and the steep path loss, an annoyance in civil mobile-network planning, become a resilience feature here [145]. Free-space optics (laser communication) is practically impossible to intercept and offers high capacity; an urban 4.6-kilometer link achieves 99 percent availability without slow fading effects [146], and ground-based terminals today lock onto one another in under a second, which makes optics practicable even for rapidly reconfiguring positions [147]. The immune foundation beneath all of this remains fiber optics: inherently insensitive to radio jamming and radio reconnaissance, and at the same time a carrier of both data and time — the base on which fixed command posts and radar positions layer their wireless, directional, and optical links as the last mile.
11.6 Zero Trust Against the Infiltrated Node
A resilient waveform and redundant routing protect against the physical attack; against the compromised or infiltrated node, the only protection is an architecture that trusts no node implicitly. Zero Trust overcomes the perimeter-based model through continuous authentication, microsegmentation, and access control: every sensor, effector, and command node authenticates itself continuously, rather than being deemed trustworthy once it is “inside the perimeter” [148]. In an ad hoc network, this further requires a layered defense against nodes that drop packets, and a distributed decision-making process that remains correct as long as the intact nodes possess a minimal redundancy [149], [150]. The fact that the authentication layer must be designed to be cost- and energy-aware while also being quantum-safe is, for the many small, battery-powered networked nodes of 2036, not an academic nicety but a design constraint [151]. In a network that must treat the infiltrated node as the normal case, the implicit trust of the perimeter is the last gap left to close — and with that, the arc closes back to the antifragile command and control of the fourth chapter.
12. Self-Protection of Command Structures
A command post is stationary, or it relocates only slowly — and is therefore predictable for enemy reconnaissance. A saturation swarm can be directed at precisely its known position. Protecting the command echelon is thus not a special case of counter-drone defense but its most demanding one: here the layered defense must be dense, and here the defense itself becomes a target.
12.1 Defense-in-Depth: No Silver-Bullet System
The protection of a high-value asset follows a multilayer model — five concentric layers running from detection through identification, tracking, and decision to engagement [152]. The doctrine is unambiguous: “no silver bullet, no one system to rule them all,” but rather a “system-of-systems” approach built from deliberately diverse platforms — kinetic and non-kinetic, fixed and mobile [153]. A single layer can be defeated; only the combination closes the gap.
12.2 Engagement Sequence HPM → HEL → Kinetic
The layers follow a natural sequence. As a “one-to-many” weapon, the microwave thins the incoming pack before it reaches the inner rings; the laser, as a surgical middle layer, takes the individual targets and the leakage; the kinetic residual layer (programmable flak, interceptors) catches, as the innermost ring, whatever directed energy cannot physically subdue in time. The U.S. Army is developing its containerized IFPC-HPM explicitly as a partner to the IFPC-HEL, “as part of a layered defense to protect fixed and semi-fixed sites” [92]. Which drone is engaged by which effector and in which order is an NP-hard dynamic assignment problem, solved in real time through swarm-intelligence heuristics and rolling-horizon methods — the formal basis of an AI-orchestrated engagement sequence [154], [155].
Abbildung 9: Layered self-protection: engagement order and exclusion zones. Source: Chapter 12.
12.3 Mobile Systems to Protect Mobile Command Posts
When the command post relocates, the effector must move with it. The U.S. Army fields a 50 kW laser on the Stryker (DE M-SHORAD, proven effective against mortar rounds in trials) and the microwave as the Stryker-Leonidas; the Air Force protects airfields with the vehicle-mounted HELWS (range up to ~3 km) and the HPM component CHIMERA [92]. The decisive self-protection advantage of mobile directed energy is magazine depth as a function of the power supply — dozens of shots per charge with the HELWS, and unlimited shots while tied to the generator [92]. Here mobility is not merely a matter of range but a survival trait: a relocatable position is harder to detect and to attack than a fixed one.
12.4 The Defense System as a Target
A stationary position around a headquarters is itself a high-value target. Its protection begins with the hardening of one’s own electronics against microwaves — shielding, filtering, architecture, and above all the internal cabling, which otherwise acts as a receiving antenna [156]. Where full hardening is too expensive, redundancy and rapid fault response help: redundant channels, online fault detection, and a targeted “rapid power off” of sensitive stages during a detected interference event [157]. The modular, field-replaceable amplifier architecture of some microwave systems is a survival property by design. And the layered sensor chain is at the same time a form of redundancy: if one sensor type fails through jamming, radio silence, or weather, another carries the load.
12.5 The Self-Protection Paradox: Fratricide and Exclusion Zones
Here lies the uncomfortable truth about employing microwaves in one’s own area. The microwave “could affect all unshielded electronic systems within range” — it does not distinguish friend from foe, and every piece of one’s own unshielded electronics within the effective range, up to and including the very headquarters being protected, is at risk [92]. There are two countermeasures, both imperfect: hardening one’s own systems, and spatial-temporal separation (keeping friendly systems out of range, or imposing a cease-fire). For a 25 kW reference system, safety distances of 72 m (personnel) and 161 m (civilian population) define the minimum geometry of a position in inhabited terrain [92]. Software-limited effect zones mitigate this, but they are only as reliable as the fire-control system that enforces them. The protective weapon can endanger the protected asset — this paradox is the price of the one layer that does not negate the radio-silent autonomy of the attacker, and it leads directly to the economic and legal trade-offs of the following chapters.
13. The Economics of Defense
The technical effectiveness of an effector does not decide its worth. A defense that hits every drone but costs a multiple of the drone for each hit loses the war at the cash register. Economics is therefore not an appendix but a selection criterion.
13.1 Cost-per-Engagement Across Five Orders of Magnitude
A model calculation (not peer-reviewed, to be read as an estimate) evaluates nineteen defensive systems and finds that the cost per engagement varies across more than five orders of magnitude — and that a higher level of technical maturity does not, in fact, mean better economics [13]. The range extends from the guided missile (USD 1.0 to 4.75 million, the highest probability of a hit but economically untenable against mass) through the interceptor drone (~USD 3,500) and programmable flak (several thousand USD per burst) to the high-energy laser (a few USD of pure energy, limited by sequentiality) and the jammer (~USD 0.01, but ineffective against the autonomous cutting edge).
(Values as a model estimate after [13]; not peer-reviewed.)
Abbildung 10: The economics of defense: cost per engagement (model estimate, log scale). Source: Chapter 13.
13.2 Magazine Depth, Energy, and Industry
With directed energy, the magazine is not a stack of ammunition but the generator: low per-shot costs as long as the current flows [94]. The bottleneck thus shifts from the logistics of ammunition to the logistics of energy. Beyond the individual effector, industry itself becomes a strategic factor: in protracted conflicts, victory goes to whoever can produce, repair, and reload at scale — magazine depth and reloadability become the decisive quantity [158]. There is an explicit warning against “gold-plated” defense: overpriced effectors undermine the economics and turn the cost asymmetry back against the defender.
13.3 The Diversified Portfolio as the Answer
The architecture that is sustainable both economically and operationally is therefore not a single system but a diversified portfolio — a “layered air defense” [159], [87]. High-volume swarms are countered with cheap area and multiple-target effects (microwave, flak), expensive missile interceptors remain reserved for the few high-value targets, and cheap vanguard counters must not let the expensive layers fire into the void [88]. The future of counter-drone defense is the network-based orchestration of many means — not the search for the one flawless weapon. How viable this portfolio proves to be thus depends as much on networking and self-protection as on the effectors themselves; the synthesis in the next part brings the two together.
14. Synthesis: The Integrated Counter-Drone System of 2036
The preceding chapters dissected defense into its building blocks—sensors, effectors, communications, self-protection. This chapter puts them back together. For the central finding of the entire study is a statement about the system, not about its individual parts: against the autonomous, radio-silent drone arriving in mass, victory goes not to the best piece of equipment but to the best architecture.
14.1 Layered Defense as a System
Four functions mesh together. Seeing—a distributed multi-sensor network that teases the small, radio-silent swarm out of the clutter, because no single sensor type can do it alone [11]. Deciding—a common operating picture and planning automation that solve the weapon-target assignment problem in real time under saturation, while the human above the loop retains release authority. Acting—an echelon of complementary effectors in which high-power microwaves thin out the pack across an area, high-energy lasers and programmable fragmentation clouds catch the leakage one by one, and net interceptors take hold even in total radio silence. Protecting—jam-resistant networked communications and a self-protection capability that keeps the defense itself alive. None of these functions is decisive on its own; their interplay is. Official doctrine captures it in a single phrase: there is “no silver-bullet system,” only a “system-of-systems” approach combining kinetic and non-kinetic, fixed and mobile layers [153].
Abbildung 11: The integrated defense system 2036: layered rings around the protected asset. Source: Chapter 14.
14.2 Levels of Maturity and Remaining Gaps
An honest synthesis separates the proven from the hoped-for. Mature are the core physical parameters of directed energy [85], the imaging-based interceptors [160], the net-capture physics, and the jam-resistant data links—much of it backed by peer-reviewed evidence. Immature or still emerging are three things. First, leakage: no layer is leakproof, and exercise series show that even well-drilled base defense operates with gaps—residual leakage is a design parameter, not an exception. Second, the saturation tail: against very large swarms, every single layer runs up against its magazine depth or its energy and cooling limits. Third, the fratricide paradox of self-protection: a microwave weapon, operating in one’s own often civilian-shared airspace, also strikes one’s own unshielded electronics, which forces exclusion zones and hardening. And over all of it looms the matter of cost discipline—a “gold-plated” defense turns the cost asymmetry back against the defender [13]; the adversary can moreover defeat it economically with cheap vanguard drones whose sole purpose is to induce the expensive defense to fire and thereby betray its position [88].
14.3 A 2036 Scenario: A Wave Beaten Back
By way of illustration—expressly constructed, resting only on the documented values of this study—consider the protection of a command post. The attack comes not as a single drone but as a layered wave: a cheap vanguard, behind it the actual radio-silent strike swarm. The vanguard is meant to trigger the defense. The distributed sensor network detects it early enough that the common operating picture sees through the intent and holds the microwave layer back rather than betraying itself against decoys. As the strike swarm enters the outer ring, a microwave pulse seizes a dozen members at once—effective precisely because it does not jam a radio link that does not exist, but strikes the circuitry instead. What gets through falls one by one to the laser and to the programmable fragmentation cloud at close range; two drones that remain in the blind spot of the directed energy are caught by a net interceptor drone that needs no radio link to the target whatsoever. While all of this unfolds, the jam-resistant networked communications keep the coordinated fires in sync, even as the adversary floods the satellite signal and the radio band. The wave is broken—not by any single weapon, but by the depth of the layering. And yet the same vignette reveals the limit: had the swarm been three times as large, the magazine depth of the inner rings would have decided whether the last members reached their target.
14.4 Limitations of the Study
This investigation is a synthesis of the literature, not a field trial with troops. Concrete rates of fire, magazine depths, and sensor performance under real-world jamming conditions are operationally classified; the figures that can be relied upon here come from open research, government reports, and—for the Swiss organization—official sources, which are marked as such. The projection to 2036 extends documented lines of development; it cannot foresee discontinuities. Three questions remain open and carry over into the following chapter: how much decision-making may one entrust to the machine in defense? How does one act within one’s own inhabited airspace without doing more harm than the attacker? And who bears responsibility when the defense strikes the wrong thing?
15. Legal and Operational-Law Classification
The technical feasibility established in the preceding chapters compels a normative question. A defense that interlocks sensors, effectors, and AI bears directly on the law: How much of the decision may the machine make, and how does one act within one’s own, often inhabited, airspace without inflicting more harm than the attacker?
15.1 Autonomy in Defense
Defensive autonomy is easier to justify, both legally and ethically, than offensive autonomy — and it has precedent: point-defense systems have engaged incoming threats largely automatically, under human supervision, for decades. The functional definition offered by the International Committee of the Red Cross remains decisive: an autonomous weapon system selects targets and applies force without a human determining the specific target, the place, or the moment [161]. The eleven Guiding Principles of the CCW group of states affirm that international humanitarian law applies in full and that human responsibility must be retained across the entire life cycle — it cannot be delegated to machines [162]. For counter-drone defense, this means that the human remains on the loop — supervising, authorizing, and able to abort — even as the time pressure of a saturation attack heightens the push toward full automation. It is precisely this compression of decision time that constitutes the dangerous lever, and operationalizing meaningful human control remains an open and actively debated problem [163], [164].
15.2 Engagement Within One’s Own, Civilian-Shared Airspace
The most difficult legal constraint is the location of the defense. It operates not over foreign territory but over one’s own — often populated — airspace. The cardinal duties of international humanitarian law therefore apply directly: distinction between target and bystanders, proportionality of collateral damage, and precautions in carrying out the engagement. Within its effect zone, the microwave weapon also strikes unshielded civilian electronics; the laser poses an eye hazard beyond the target; falling debris from intercepted drones endangers people on the ground. Engagement within one’s own airspace is therefore primarily a question of authorization and rules of engagement, not merely a technical one: Who may act, when, and with which means? Functional features such as non-lethal sensor dazzling or a software-bounded effect zone are not a matter of convenience here but a legal prerequisite.
15.3 Escalation, Strategic Stability, and Automation Bias
Defensive automation, too, has a security-policy downside. AI-enabled, highly automated reaction systems can increase the risk of inadvertent escalation — a misclassified track, an automatic counter-response, and a situation tips faster than humans can rein it in [165]. Compounding this is automation bias: operators tend to overtrust machine outputs, so that nominal “on the loop” supervision, under compressed reaction times, withers into a mere act of confirmation. Soberly considered, today’s military in any case uses artificial intelligence less for lethal full autonomy than to accelerate reconnaissance and the targeting process [166] — and it is precisely there, in accelerating detection and decision, that the legitimate, legally defensible core of AI in counter-drone defense lies. The release to engage, however — and this is the normative guardrail of this study — belongs in human hands.
16. Organization: Building a Counter-Drone Battalion for the Swiss Armed Forces
Up to this point, this study has been a study of systems. Yet systems do not fight drones — people do, within an organization that commands, trains, and sustains them. This concluding chapter turns the layered defensive system of the preceding chapters into a force: a counter-drone battalion of the Swiss Armed Forces. In doing so, it cleanly separates what is officially in force today (A) from the reasoned projection to 2036 (P) — for no such battalion yet exists.
16.1 The Swiss Point of Departure (Official)
Switzerland’s ground-based air defense is consolidated within the Air Force, in the Ground-Based Air Defense Brigade 33 (BODLUV Br 33, formed in 2023 out of the Air Defense Training Unit 33, based at the Emmen anti-aircraft barracks). The brigade comprises roughly 100 professional and 3,500 militia members, organized into three light air-defense guided-missile battalions (the Stinger system, 96 fire units) and three medium air-defense battalions (the 35 mm gun with fire-control unit, 27 fire units) [167], [168]. A telling feature of the air-defense branch: the unit body is called a battalion in name (in Swiss usage, an “Abteilung,” not “Bataillon”), and its subunit a battery (not a company) — functionally one and the same [169].
This force is in the midst of renewal. Through the Air2030 program, Switzerland is procuring Patriot (long range, PAC-2 GEM-T, federal resolution of 2022) and five IRIS-T SLM systems (medium range, ~40 km, manufactured by Diehl, within the framework of the European Sky Shield Initiative; completion on schedule for 2032) [170], [171]. IRIS-T SLM expressly takes over the tasks of the phasing-out 35 mm gun and newly establishes an area-oriented early-warning capability against cruise missiles and RAM threats [171]. For the actual close-in drone domain, however, a gap remains: only at the end of 2025 did armasuisse urgently procure semi-mobile mini-drone-defense systems from the Swiss supplier Securiton (CHF 3.5 million), after a field trial in Meiringen had confirmed a capability gap against hostile mini-drones [172]. In parallel, an interagency Drone Task Force has been consolidating development since 2024 — with a permanent testbed running through 2027 and two thrusts, among them counter-drone defense using drones (C-UAV) at short range [173].
16.2 Placement: The Battalion as the Innermost Layer (Projection)
Everything that follows is reasoned projection (P) built on these official trends — not an adopted Swiss undertaking.
Within a future Integrated Air Defence, a counter-drone battalion fits in as the lowest, innermost layer: Patriot covers the long range, IRIS-T SLM the medium range — the battalion the close and very-close range against small, autonomous swarms (C-sUAS), precisely the gap that Securiton and the Drone Task Force fill only provisionally today. It embodies the guiding principle of this study, that there is no silver-bullet system, only a layered, networked defense composed of many complementary tiers [153]. In air-defense parlance it would properly be a “counter-drone Abteilung”; for the sake of clarity, however, it will be referred to throughout as a battalion.
16.3 Unit Body and Command
The battalion is commanded, as is customary in the Swiss Armed Forces, by a lieutenant colonel and is subordinate to BODLUV Br 33 [169]. Its staff follows the proven structure of the staff functions (S1–S6): S1 personnel, S2 intelligence/situation, S3 operations (the core cell in which the battle is fought), S4 logistics, S6 command support/communications; planning and training (S5/S7) are attached as the situation requires [169]. The order of magnitude — one staff battery plus several units of roughly 120–160 members of the armed forces each — yields a unit body of roughly 700 to 900 members of the armed forces, consistent with the span of real Swiss battalions (P; the historical anchor of an infantry battalion stood at 740 personnel).
Abbildung 12: Organizational structure of the counter-drone battalion 2036 (projection). Source: Chapter 16.
16.4 Organization into Six Batteries
Staff and Command-Support Battery. Here sits the brain: the battalion staff (S1–S6), the C2 node tied into the national air picture, and an EW/cyber cell that jams enemy data links and satellite navigation wherever the adversary does transmit, and that hardens one’s own network — in liaison with the Cyber Command. It operates the EW-resilient networked communications described in Chapter 11.
Sensor and Early-Warning Battery. It operates the distributed multi-sensor network from Chapter 3 — radar, passive radio-frequency detection, electro-optical/infrared, acoustic — and fuses it into the situation picture. It is the first to see the radio-silent swarm, and it ties into the real RAM early-warning capability (IRIS-T SLM, TRML-4D radar) [171].
Close-Range Effector Battery (Kinetic). Barrel weapon and programmable fragmentation effect — successor to the phasing-out 35 mm line with air-bursting, AHEAD-type ammunition — plus short-range guided missiles. The weather-independent innermost ring, superior against dense packs (Chapter 7).
Directed-Energy Effector Battery. High-energy lasers and high-power microwaves (Chapters 5 and 6) — the layers with the lowest “cost per shot” and, given a power supply, the deepest magazine [92]. The HPM component is the only effector that does not render the attacker’s radio-silent autonomy worthless.
C-UAV Effector Battery (Defensive Drones). Interceptor and net-capture drones as well as swarm-versus-swarm defense (Chapters 8 and 9) — the direct counterpart to the real task-force thrust of “counter-drone defense using drones” [173].
Logistics and Maintenance Battery. Ammunition and guided-missile logistics, but above all the power supply — for directed energy is hungry, and in the field it is the generator, not the magazine, that determines staying power [92].
16.5 Functions and Personnel Distribution
A battery is led by a captain, a platoon by a lieutenant or first lieutenant, a section by a sergeant [169]. The professional core would remain small — an estimated 10 to 15 percent, concentrated on the most delicate systems (HEL/HPM, C2, EW) and on round-the-clock readiness — with the remainder militia, analogous to the real ratio of roughly 100 professional to 3,500 militia members of BODLUV Br 33 [167] (P). What is genuinely new is a shift of weight in the personnel: away from the “gun crew,” toward the operator of networked effectors. The center of gravity would lie with sensor, C2, and EW functions — with the people who read the situation picture, oversee the weapon-to-target assignment, and release the effect.
16.6 Who Does What — A Wave Repelled
Imagine the worst case, drawn from the chapters of this study. The sensor battery detects the inbound swarm first not on radar, but in the fusion of several sensors that carve the small, radio-silent target out of the clutter, and it gains seconds of warning time. In the S3 of the staff battery, this condenses into the situation picture; the AI-assisted planning proposes a weapon-to-target assignment, yet the release to engage remains with the human on the loop — a deliberate decision against automation bias, whose legal rationale is carried by Chapter 15. The directed-energy battery thins the pack with a microwave pulse that captures several drones at once and does not disturb their autonomy but strikes their electronics. What gets through, the high-energy laser takes one at a time; what escapes the laser is caught at very close range by the programmable fragmentation cloud or by a net catcher of the C-UAV battery — the latter works even when the adversary has severed every radio link. Over all of it, the EW cell holds one’s own network together and synchronizes the networked fire even when the adversary smothers the satellite signal. And the logistics battery sees to it that the generator runs when the second wave comes. No layer is impervious on its own; their interplay is the defense.
16.7 Concluding Reflection and Outlook
The autonomous combat drone of 2036 is built, and it is built well — radio-silent, self-classifying, in mass. This study has shown that there is nonetheless an answer, but not a simple one: not a wonder weapon, but a layered, networked, economically considered system, in which directed energy thins the mass, lasers and fragmentation catch the leakage, nets take hold even under radio silence, a jam-resistant command holds the whole together, and the human retains the decision over life and death. This system is embodied not by a single piece of equipment, but by an organization — here played out through the counter-drone battalion of the Swiss Armed Forces. That Switzerland is already laying the first real building blocks — with Air2030, the Securiton emergency procurement, and the Drone Task Force — shows that the path from threat to defense has been embarked upon. Whether it is embarked upon quickly enough is no longer a technical question, but one of will and means — and technology, that is the sober lesson of these two studies, does not wait.
Annex A — List of Abbreviations and Acronyms
Annex B — Glossary of Key Terms
Fail-safe kill chain. The design principle of the attacking drone (from the preceding study): onboard target recognition and layered self-navigation make it independent of radio and satellite — the reference point against which the entire defense must contend.
Defense-in-depth / layered defense. Protection of an asset through multiple complementary rings (detect → decide → engage → protect) rather than through a single weapon; the foundation of the “no silver-bullet system” doctrine.
Catcher swarm. A controlled formation of defensive drones that disperses and attrites the adversary swarm before it can reach the protected asset.
Fratricide. Self-inflicted harm to one’s own side — here: within its engagement zone, the high-power microwave also strikes one’s own unshielded electronics; it compels hardening and exclusion zones.
Directed Energy Weapon (DEW). Umbrella term for high-energy lasers and high-power microwaves; low “cost per shot,” with magazine depth limited by energy supply rather than by ammunition.
High-Energy Laser (HEL). Engages individual targets with precision through thermal ablation; sequential (one target at a time), weather-dependent.
High-Power Microwave (HPM). Couples energy across an area into the circuits of several drones at once — effective independently of radio and autonomy, ideal against radio-silent swarms.
Low, Slow, Small (LSS). The hard-to-detect target class of small, slow, low-flying drones that vanish into radar clutter.
Recognized Air Picture (RAP). The fused, managed air situation picture that feeds weapon-target assignment.
Saturation attack. The simultaneous approach of many targets, overwhelming the defense not through precision but through the exhaustion of time, projectiles, and energy.
Protective net / Cope Cage. Passive physical protection by nets or grid structures over the asset; effective independently of electronic jamming, but protecting only a single point.
Weapon-Target Assignment (WTA). The (NP-hard) problem of which effector engages which target in what order; solved in real time under saturation, the foundation of planning automation.
Zero-Trust Architecture (ZTA). A security model that grants no node implicit trust; it hardens networked tactical communication against cyber and spoofing attacks.
References
[1] El-Sheimy, N.; Youssef, A. A. — Inertial sensors technologies for navigation applications: state of the art and future trends. Satellite Navigation 1:2, 2020. https://doi.org/10.1186/s43020-019-0001-5
[2] Gallego, G.; Delbrück, T.; Orchard, G. et al.; Scaramuzza, D. — Event-Based Vision: A Survey. IEEE TPAMI 44(1), 2020. https://doi.org/10.1109/tpami.2020.3008413
[3] Kim, T.; Nam, S.; Lee, H.; Oh, J. — Verification of Vision-Based Terrain-Referenced Navigation Using the Iterative Closest Point Algorithm Through Flight Testing. Sensors 25(18):5813, 2025. https://doi.org/10.3390/s25185813
[4] Ma, S.; Wang, H.; Ma, L. et al.; Wei, F. — The Era of 1-bit LLMs: All Large Language Models are in 1.58 Bits. arXiv:2402.17764, 2024. https://arxiv.org/abs/2402.17764
[5] Hajizada, E.; Rager, D.; Shea, T. et al. — Online Continual Learning on Intel Loihi 2 via a Co-designed Spiking Neural Network. arXiv:2511.01553, 2025. https://arxiv.org/abs/2511.01553
[6] Jiang, W.; Wang, Y.; Li, Y.; Lin, Y.; Shen, W. — Radar Target Characterization and Deep Learning in Radar Automatic Target Recognition: A Review. Remote Sensing 15(15):3742, 2023. https://doi.org/10.3390/rs15153742
[7] Li, S.; He, X.; Xu, X.; Zhao, T.; Song, C.; Li, J. — Weapon-Target Assignment Strategy in Joint Combat Decision-Making Based on Multi-Head Deep Reinforcement Learning. IEEE Access 11, 2023. https://doi.org/10.1109/access.2023.3324193
[8] Kaufmann, E.; Bauersfeld, L.; Loquercio, A.; Müller, M.; Koltun, V.; Scaramuzza, D. — Champion-level drone racing using deep reinforcement learning. Nature 620(7976):982–987, 2023. https://doi.org/10.1038/s41586-023-06419-4
[9] Wright, M.; Anastassiou, L.; Mishra, C. et al.; Ralph, J. F. — Cold atom inertial sensors for navigation applications. Frontiers in Physics 10:994459, 2022. https://doi.org/10.3389/fphy.2022.994459
[10] Wheeler, J. M.; Chamoun, J. N.; Dangui, V.; Digonnet, M. J. F. — Analytic Method for Estimating Aircraft Fix Displacement from Gyroscope’s Allan-Deviation Parameters. arXiv:2202.09360, 2022. https://arxiv.org/abs/2202.09360
[11] Kang, H.; Joung, J.; Kim, J.; Kang, J.; Cho, Y. S. — Protect Your Sky: A Survey of Counter Unmanned Aerial Vehicle Systems. IEEE Access 8, 2020. https://doi.org/10.1109/access.2020.3023473
[12] Sathaye, H.; LaMountain, G.; Closas, P.; Ranganathan, A. — SemperFi: Anti-spoofing GPS Receiver for UAVs. NDSS Symposium, 2022. https://doi.org/10.14722/ndss.2022.23071
[13] Cost-Effectiveness Analysis of Counter-UAS Technologies: A Comparative Study of Kinetic, EW, and Directed Energy Countermeasures (2022–2026). ResearchGate-Preprint (Multi-Layered Defense Economics Model), nicht peer-reviewed. https://www.researchgate.net/publication/401707891
[14] Park, S.; Kim, H. T.; Lee, S.; Joo, H.; Kim, H. — Survey on Anti-Drone Systems: Components, Designs, and Challenges. IEEE Access 9, 2021. https://doi.org/10.1109/access.2021.3065926
[15] Samaras, S. et al. — Deep Learning on Multi Sensor Data for Counter UAV Applications — A Systematic Review. Sensors 19(22):4837, MDPI, 2019. https://doi.org/10.3390/s19224837
[16] Rahman, M. H. et al. — A Comprehensive Survey of Unmanned Aerial Vehicles Detection and Classification Using Machine Learning Approach. Remote Sensing 16(5):879, MDPI, 2024. https://doi.org/10.3390/rs16050879
[17] Yan, X.-C. et al. — UAV Detection and Tracking in Urban Environments Using Passive Sensors: A Survey. Applied Sciences 13(20):11320, MDPI, 2023. https://doi.org/10.3390/app132011320
[18] Bayizere, M. — DroneShield-AI: A Multi-Modal Sensor Fusion Framework for Real-Time Autonomous Drone Threat Detection, Behavioral Intent Classification, and Swarm Intelligence in Contested Airspace. arXiv:2606.11687, 2026. https://arxiv.org/abs/2606.11687
[19] Dickerson, C. et al. — Fusion of Cellular ISAC and Passive RF Sensing for UAV Detection and Tracking. arXiv:2512.14608, 2025 (NSF AERPAW). https://arxiv.org/abs/2512.14608
[20] Ezuma, M.; Erden, F.; Anjinappa, C. K.; Ozdemir, O.; Guvenc, I. — Detection and Classification of UAVs Using RF Fingerprints in the Presence of Wi-Fi and Bluetooth Interference. IEEE Open J. Communications Society 1, 2019. https://doi.org/10.1109/ojcoms.2019.2955889
[21] Aouladhadj, D. et al. — Drone Detection and Tracking Using RF Identification Signals. Sensors 23(17):7650, MDPI, 2023. https://doi.org/10.3390/s23177650
[22] Yang, B.; Matson, E. T.; Smith, A.; Dietz, J. E.; Gallagher, J. C. — UAV Detection System with Multiple Acoustic Nodes Using Machine Learning Models. IEEE IRC, 2019. https://doi.org/10.1109/irc.2019.00103
[23] United24 Media — Sky Fortress: Ukraine’s Acoustic Detection System That Tracks Drones — Cheap and Fast. 2025. https://united24media.com/war-in-ukraine/sky-fortress-ukraines-acoustic-detection-system-that-tracks-drones-cheap-and-fast-9451
[24] Sinha, P.; Yapici, Y.; Guvenc, I.; Turgut, E.; Gursoy, M. C. — RSS-Based Detection of Drones in the Presence of RF Interferers. arXiv:1905.03471, 2019. https://arxiv.org/abs/1905.03471
[25] Griffiths, D.; Jahangir, M.; Kannanthara, J.; Donlan, G.; Baker, C. J.; Antoniou, M.; Singh, Y. — Fully digital, urban networked staring radar: Simulation and experimentation. IET Radar, Sonar & Navigation, 2023. https://doi.org/10.1049/rsn2.12499
[26] Ahmad, B. I.; Harman, S.; Godsill, S. — A Bayesian track management scheme for improved multi-target tracking and classification in drone surveillance radar. IET Radar, Sonar & Navigation, 2023. https://doi.org/10.1049/rsn2.12458
[27] Ahmad, B. I. et al. — A Review of Automatic Classification of Drones Using Radar: Key Considerations, Performance Evaluation, and Prospects. IEEE Aerospace & Electronic Systems Magazine, 2023. https://doi.org/10.1109/maes.2023.3335003
[28] Ito, N.; Godsill, S. — A Multi-Target Track-Before-Detect Particle Filter Using Superpositional Data in Non-Gaussian Noise. IEEE Signal Processing Letters, 2020. https://doi.org/10.1109/LSP.2020.3002704
[29] Meister, D.; Holder, M. F.; Winner, H. — A Track-Before-Detect Approach to Multi-Target Tracking on Automotive Radar Sensor Data. arXiv:2006.02755, 2020. https://arxiv.org/abs/2006.02755
[30] Kim, K.; Uney, M.; Mulgrew, B. — Coherent Track Before Detect: Detection via simultaneous trajectory estimation and long time integration. arXiv:1709.00310, 2017. https://arxiv.org/abs/1709.00310
[31] Yan, B.; Giorgetti, A.; Paolini, E. — A Track-Before-Detect Algorithm for UWB Radar Sensor Networks. arXiv:2108.00501, 2021. https://arxiv.org/abs/2108.00501
[32] Dickerson, C.; Khawaja, W.; Guvenc, I. — Adaptive 5G Resource Allocation for Multistatic ISAC-Based UAV Detection and Tracking. arXiv:2606.21677, 2026. https://arxiv.org/abs/2606.21677
[33] Bournaka, G. et al. — Design and performance evaluation of a FM/DAB/DVB-T multi-illuminator passive radar system. 2014. https://www.researchgate.net/publication/260524420
[34] Target Localization from Bistatic Range Measurements in Multi-Transmitter Multi-Receiver Passive Radar. IEEE Signal Processing, 2015. https://www.researchgate.net/publication/283776180
[35] Two-Dimensional Target Localization Approach via a Closed-Form Solution Using Range Difference Measurements Based on Pentagram Array. Remote Sensing 16(8):1370, MDPI, 2024. https://www.mdpi.com/2072-4292/16/8/1370
[36] Passive Radar Tracking in Clutter Using Range and Range-Rate Measurements. Sensors (PMC10300973), 2023. https://pmc.ncbi.nlm.nih.gov/articles/PMC10300973/
[37] TDOA–FDOA method for tracking of a moving target in a distributed sensor scenario. ITM Web of Conferences (ICAECT), 2023. https://www.itm-conferences.org/articles/itmconf/pdf/2023/07/itmconf_icaect2023_01007.pdf
[38] Harms, H. A.; Davis, L. M.; Palmer, J. — Understanding the Signal Structure in DVB-T Signals for Passive Radar Detection. Washington University in St. Louis / IEEE Radar, 2009. https://www.ese.wustl.edu/~nehorai/paper/Radar_Harms.pdf
[39] Range resolution improvement in FM-based passive radars using deconvolution. Bilkent University, 2014. https://yoksis.bilkent.edu.tr/pdf/files/12333.pdf
[40] ETH Zürich (TIK) — DAB+ Positioning (Semesterarbeit), 2020. https://pub.tik.ee.ethz.ch/students/2020-HS/SA-2020-58.pdf
[41] SSB-Based Signal Processing for Passive Radar Using a 5G Network. IEEE, 2023. https://ieeexplore.ieee.org/iel7/4609443/9973430/10083170.pdf
[42] Analysis of 5G New Radio Waveform as an Illuminator of Opportunity for Passive Bistatic Radar. 2022. https://www.researchgate.net/publication/358931205
[43] An Improved Extensive Cancellation Method for Clutter Removal in Passive Bistatic Radar. Sensors (PMC12610278), 2024. https://pmc.ncbi.nlm.nih.gov/articles/PMC12610278/
[44] An Inter-Subband Processing Algorithm for Complex Clutter Suppression in Passive Bistatic Radar. Remote Sensing 13(23):4954, MDPI, 2021. https://www.mdpi.com/2072-4292/13/23/4954
[45] Beamforming Techniques for Passive Radar: An Overview. Sensors 23(7):3435, MDPI, 2023. https://www.mdpi.com/1424-8220/23/7/3435
[46] Learning Resource Allocation in Active-Passive Radar Sensor Networks. Frontiers in Signal Processing, 2022. https://www.frontiersin.org/journals/signal-processing/articles/10.3389/frsip.2022.822894/full
[47] Janes — NATO demonstrates fusion of active and passive radar detection in military network (SET-258, Polen 2024). 2024. https://www.janes.com/osint-insights/defence-news/nato-demonstrates-fusion-of-active-and-passive-radar-detection-in-military-network
[48] HENSOLDT — TwInvis: Passive Radar Surveillance of Noiseless Objects. https://www.hensoldt.net/products/twinvis-passive-radar-surveillance-of-noiseless-objects
[49] BAKOM — DAB+ transmitter networks for digital broadcasting by radio stations. https://www.bakom.admin.ch/en/dab-transmitter-networks-for-digital-broadcasting-by-radio-stations
[50] armasuisse W+T — The project «RadCom» – Sensory Analysis and Communications embark on a collaboration. https://www.ar.admin.ch/en/project-radcom
[51] AI Automates Drone Defense With High Energy Lasers. Mobility Engineering Technology (Naval Postgraduate School, High Energy Laser Beam Control Research Testbed). https://www.sae.org/mobilityengineering
[52] Unlu, E.; Zenou, E.; Rivière, N.; Dupouy, P.-É. — Deep learning-based strategies for the detection and tracking of drones using several cameras. IPSJ Trans. Computer Vision and Applications, 2019. https://doi.org/10.1186/s41074-019-0059-x
[53] Besada, J. A.; Campaña, I.; Carramiñana, D.; Bergesio, L.; de Miguel, G. — Review and Simulation of Counter-UAS Sensors for Unmanned Traffic Management. Sensors 22(1):189, MDPI, 2021. https://doi.org/10.3390/s22010189
[54] Samu, J.; Yang, C. — Airport Ground-Based Aerial Object Surveillance Technologies for Enhanced Safety: A Systematic Review. Drones 10(1):22, MDPI, 2025. https://doi.org/10.3390/drones10010022
[55] Athans, M. — Command and control (C2) theory: A challenge to control science. IEEE Trans. Automatic Control 32(4), 1987. https://doi.org/10.1109/tac.1987.1104607
[56] Dimarogonas, J. et al. — Universal Command and Control Language Early System Engineering. RAND Corporation RR-A744-2, 2023. https://www.rand.org/pubs/research_reports/RRA744-2.html
[57] Ciolponea, C.-A.; Bârsan, G. — NATO Corps HQ – Land Component – Integration of Unmanned Aerial Vehicles (UAVs). Revista Academiei Forțelor Terestre, 2022. https://doi.org/10.2478/raft-2022-0041
[58] Palestini, C. (zit.) — NATO to adopt first-ever counter-drone doctrine for member nations. C4ISRNET, 2023. https://www.c4isrnet.com/unmanned/2023/10/20/nato-to-adopt-first-ever-counter-drone-doctrine-for-member-nations/
[59] Bassil, Y. — Service-Oriented Architecture for Weaponry and Battle Command and Control Systems in Warfighting. arXiv:1204.0179, 2012. https://arxiv.org/abs/1204.0179
[60] NATO Communications and Information Agency — NATO tests counter drone technology during interoperability exercise (C-UAS TIE). https://www.ncia.nato.int/about-us/newsroom/nato-tests-counter-drone-technology-during-interoperability-exercise–2
[61] NATO tests counter-drone playbook amid real-life jamming in Romania. Defense News, 2024. https://www.defensenews.com/global/europe/2024/07/08/nato-tests-counter-drone-playbook-amid-real-life-jamming-in-romania/
[62] Kallenborn, Z. — Countering Swarms: Strategic Considerations and Opportunities in Drone Warfare. Joint Force Quarterly 107, NDU Press, 2022. https://ndupress.ndu.edu/Joint-Force-Quarterly/Joint-Force-Quarterly-107/Article/Article/3197193/
[63] Zhang, K.; Zhou, D.; Yang, Z.; Pan, Q.; Kong, W. — Constrained Multi-Objective Weapon Target Assignment for Area Targets by Efficient Evolutionary Algorithm. IEEE Access 7, 2019. https://doi.org/10.1109/access.2019.2955482
[64] Zhang, K.; Zhou, D.; Yang, Z.; Kong, W.; Zeng, L. — A Novel Heterogeneous Sensor-Weapon-Target Cooperative Assignment for Ground-to-Air Defense by Efficient Evolutionary Approaches. IEEE Access 8, 2020. https://doi.org/10.1109/access.2020.3043667
[65] Palmas, A. — Reinforcement Learning for Decision-Level Interception Prioritization in Drone Swarm Defense. arXiv:2508.00641, 2025. https://doi.org/10.48550/arXiv.2508.00641
[66] Li, T.; Wang, G.; Fu, Q.; Guo, X.; Zhao, M.; Liu, X. — An Intelligent Algorithm for Solving Weapon-Target Assignment Problem: DDPG-DNPE Algorithm. Computers, Materials & Continua 76(3), 2023. https://doi.org/10.32604/cmc.2023.041253
[67] He, S. et al. — Target Assignment Algorithm for Joint Air Defense Operation Based on Spatial Crowdsourcing Mode. Electronics 11(11):1779, MDPI, 2022. https://doi.org/10.3390/electronics11111779
[68] Brust, M. R.; Danoy, G.; Bouvry, P.; Gashi, D.; Pathak, H.; Gonçalves, M. P. — Defending against Intrusion of Malicious UAVs with Networked UAV Defense Swarms. IEEE LCN Workshops, 2018. https://arxiv.org/abs/1808.06900
[69] Cheng, Z. et al. — Interference-Aware K-Step Reachable Communication in Multi-Agent Reinforcement Learning. arXiv:2603.15054, 2026. https://arxiv.org/abs/2603.15054
[70] Zhu, C.; Dastani, M.; Wang, S. — A Survey of Multi-Agent Deep Reinforcement Learning with Communication. arXiv:2203.08975, 2022. https://arxiv.org/abs/2203.08975
[71] Takayama, S.; Fujita, K. — AOAD-MAT: Transformer-based multi-agent deep reinforcement learning model considering agents’ order of action decisions. arXiv:2510.13343, 2025. https://arxiv.org/abs/2510.13343
[72] Brookings Institution — Understanding the errors introduced by military AI applications. https://www.brookings.edu/articles/understanding-the-errors-introduced-by-military-ai-applications/
[73] Hawley, J. K. — Patriot Wars: Automation and the Patriot Air and Missile Defense System. Center for a New American Security (CNAS), 2017. https://www.cnas.org/publications/reports/patriot-wars
[74] Air University, Office of Sponsored Programs — Ethical, Legal and Operational Challenges of AI-Driven Warfare and Autonomous Systems. 2025. https://www.airuniversity.af.edu/Office-of-Sponsored-Programs/Research/Article-Display/Article/4459074/
[75] Algorithmic Fratricide: When Artificial Intelligence Bias Becomes a Force-Protection Hazard. Small Wars Journal, 2025. https://smallwarsjournal.com/2025/12/25/algorithmic-fratricide/
[76] Exploring the Impact of Automation Bias and Complacency on Individual Criminal Responsibility for War Crimes. Journal of International Criminal Justice 21(5), Oxford University Press, 2023. https://doi.org/10.1093/jicj/mqad037
[77] Straitouri, E.; Tsirtsis, S.; Artola Velasco, A.; Gomez-Rodriguez, M. — Narrowing Action Choices with AI Improves Human Sequential Decisions. arXiv:2510.16097, 2025. https://arxiv.org/abs/2510.16097
[78] Scharowski, N.; Perrig, S. A. C.; von Felten, N.; Brühlmann, F. — Trust and Reliance in XAI — Distinguishing Between Attitudinal and Behavioral Measures. arXiv:2203.12318, 2022. https://arxiv.org/abs/2203.12318
[79] Wang, J. C.-H. et al. — Flight Testing an Optionally Piloted Aircraft: a Case Study on Trust Dynamics in Human-Autonomy Teaming. arXiv:2503.16227, 2025. https://arxiv.org/abs/2503.16227
[80] McDowell, K.; Novoseller, E.; Madison, A.; Goecks, V. G.; Kelshaw, C. — Re-Envisioning Command and Control. arXiv:2402.07946, 2024 (US Army Research Laboratory). https://arxiv.org/abs/2402.07946
[81] Simpson, J.; Oosthuizen, R.; El Sawah, S.; Abbass, H. — Agile, Antifragile, Artificial-Intelligence-Enabled, Command and Control. arXiv:2109.06874, 2021. https://arxiv.org/abs/2109.06874
[82] Madison, A. et al. — “New” Challenges for Future C2: Commanding Soldier-Machine Partnerships. arXiv:2503.08844, 2025. https://arxiv.org/abs/2503.08844
[83] Lee, H.; Panagou, D. — Distributed Resilience-Aware Control in Multi-Robot Networks. arXiv:2504.03120, 2025. https://arxiv.org/abs/2504.03120
[84] Shinohara, T.; Johansson, K. H.; Sandberg, H. — Distributed Resilient State Estimation and Control with Strategically Implemented Security Measures. arXiv:2507.12052, 2025. https://arxiv.org/abs/2507.12052
[85] Jafari, A. A.; Anbarjafari, G. — A Multi-physics Simulation Framework for High-power Microwave Counter-unmanned Aerial System Design and Performance Evaluation. arXiv:2602.08477, 2026. https://arxiv.org/abs/2602.08477
[86] Min, S.-H. et al. — Analysis of Electromagnetic Pulse Effects Under High-Power Microwave Sources. IEEE Access 9, 2021. https://doi.org/10.1109/access.2021.3117395
[87] Christie, L. — Shaping Modern Warfare: The Strategic Role of High-Power Microwave Directed Energy Weapons in Multi-Domain Operations. Defence Science Journal, 2026. https://doi.org/10.14429/dsj.21114
[88] Cumpson, P. J. — Movement To Contact and Vanguard UAVs: Strategies for Swarm UAV Battlefield Economics in the era of Microwave Directed Energy Weapons. Security and Defence Quarterly, 2026. https://doi.org/10.35467/sdq/221147
[89] Karkadakattil, A. — Laser-Based Directed Energy Weapons: Technological Capabilities, Material Interaction, and Strategic Deployment Pathways. Defence Science Review (PNO), 2026. https://doi.org/10.37055/pno/216776
[90] Counter-Unmanned Aerial Vehicles Study: Shipboard Laser Weapon System Engagement Strategies for Countering Drone Swarm Threats. NPS/DTIC AD1165019. https://apps.dtic.mil/sti/trecms/pdf/AD1165019.pdf
[91] Siora, O.; Lukashenko, V.; Bernatskyi, A. — An interdisciplinary study of the effect of laser radiation on carbon fiber-reinforced polymer, in the context of counteracting unmanned aerial vehicles. History of Science and Technology 15(1), 2025. https://doi.org/10.32703/2415-7422-2024-15-1-195-215
[92] Congressional Research Service — Department of Defense Directed Energy Weapons: Background and Issues for Congress, R46925, 2024. https://www.congress.gov/crs_external_products/R/PDF/R46925/R46925.8.pdf
[93] Gupta, T. — The role of High Energy Laser as a U.S. Army Counter-small Unmanned Aircraft System (UAS) Weapon. DTIC AD1230685. https://apps.dtic.mil/sti/trecms/pdf/AD1230685.pdf
[94] Michnewich, D. A. — Modeling Energy Storage Requirements for High-Energy Lasers on Navy Ships. Naval Postgraduate School, 2018. http://hdl.handle.net/10945/59554
[95] Rheinmetall — Oerlikon Skynex Air Defence System (35-mm-AHEAD-Munition), Broschüre B200e0424. https://www.rheinmetall.com
[96] Interceptor Drones: Technological, Economic, Operational Requirements and Comparative Analysis. ResearchGate-Preprint, 2025 (nicht peer-reviewed). https://www.researchgate.net/publication/398735315
[97] Yan, H.; Yang, K.; Cheng, Y.; Wang, Z.; Li, D. — Precise Interception Flight Targets by Image-based Visual Servoing of Multicopter. arXiv:2409.17497, 2024. https://doi.org/10.48550/arxiv.2409.17497
[98] Yang, K.; Bai, C.; She, Z.; Quan, Q. — High-Speed Interception Multicopter Control by Image-based Visual Servoing. arXiv:2404.08296, 2024. https://arxiv.org/abs/2404.08296
[99] Liu, L. Y.; Yang, K.; Zou, H. et al. — Planar-Sector LOS Guidance for Interception of Agile Targets with Lifting-Wing Quadcopters. arXiv:2606.10639, 2026. https://arxiv.org/abs/2606.10639
[100] Rothe, J.; Strohmeier, M.; Montenegro, S. — Autonomous Multi-UAV Net Defense System for Aerial Drone Interception. 2025 10th Int. Conf. on Control and Robotics Engineering (ICCRE), IEEE, S. 171–177. https://doi.org/10.1109/iccre65455.2025.11093305
[101] Yu, D.; Judasz, A.; Zheng, M.; Botta, E. M. — Design and Testing of a Net-Launch Device for Drone Capture. AIAA SciTech 2022 Forum. https://doi.org/10.2514/6.2022-0273
[102] Tupitsyn, N. — Estimation of the Required Dimension of Net to Capture Drone. Electronics and Control Systems 1(67):94–99, National Aviation University, 2021. https://doi.org/10.18372/1990-5548.67.15623
[103] Deutsches Zentrum für Luft- und Raumfahrt (DLR) — Reliable drone defence (CUSTODIAN-Projekt), 2025. https://www.dlr.de/en/latest/news/2025/reliable-drone-defence
[104] Diehl Defence — Drohnenabwehr | Counter-UAS (SKY SPHERE, CICADA). https://new.diehl.com/defence/de/produkte/drohnenabwehr-counter-uas
[105] Fortem Technologies — DroneHunter F700 (Produktseite & Datasheet). Abgerufen 2026-06-23. https://fortemtech.com/products/dronehunter-f700/
[106] Delft Dynamics — DroneCatcher / AISAR-Katalog. Abgerufen 2026-06-23. https://www.aisar.tech/catalog/defence/delft-dronecatcher
[107] OpenWorks Engineering — SkyWall Patrol — Handheld UAS Capture System. Abgerufen 2026-06-23. https://openworksengineering.com/skywall-patrol/
[108] OpenWorks Engineering — SkyWall300 Automatic Drone Capture System (Datasheet, via Counter Drone Solutions), 2018. https://counterdronesolutions.com.au/wp-content/uploads/2018/06/SkyWall300-Automatic-Drone-Capture-System-Datasheet.pdf
[109] Skraparlis, A.; Ntalianis, K.; Tsapatsoulis, N. — A novel framework to intercept GPS-denied, bomb-carrying, non-military, kamikaze drones: Towards protecting critical infrastructures. Defence Technology, Elsevier, 2024. https://doi.org/10.1016/j.dt.2024.05.001
[110] Bopardikar, S. D.; Suri, S. — k-Capture in Multiagent Pursuit Evasion, or the Lion and the Hyenas. arXiv:1108.1561, 2011. https://arxiv.org/abs/1108.1561
[111] Das, G.; Dorothy, M.; Bell, Z. I.; Shishika, D. — Defending a Static Target Point with a Slow Defender. arXiv:2311.03338, 2023. https://arxiv.org/abs/2311.03338
[112] Brust, M. R.; Danoy, G.; Stolfi, D. H.; Bouvry, P. — Swarm-based counter UAV defense system. Discover Internet of Things 1, 2021. https://doi.org/10.1007/s43926-021-00002-x
[113] Pandey, S.; Muniraj, D. — Critical Infrastructure Defense Against Aerial Swarms Under Sensing Uncertainty: Online Allocation With Finite-Time Guarantees. arXiv:2605.26838, 2026. https://arxiv.org/abs/2605.26838
[114] Chipade, V. S.; Wang, X.; Panagou, D. — IDCAIS: Inter-Defender Collision-Aware Interception Strategy against Multiple Attackers. arXiv:2112.12098, 2021. https://arxiv.org/abs/2112.12098
[115] Chipade, V. S.; Panagou, D. — Aerial Swarm Defense using Interception and Herding Strategies. arXiv:2306.02482, 2023. https://arxiv.org/abs/2306.02482
[116] Zuo, L.; Wang, Y.; Liu, J.; Lu, Y.; Gu, R. — A Hierarchical Cooperative Interception Framework for Multi-UAV Defense Against Large-Scale Swarm Intrusions. Drones 10(6):418, MDPI, 2026. https://doi.org/10.3390/drones10060418
[117] Chaari, M. Z. — Analysis of the power of drones and limitations of the anti-drone solutions on the Russian-Ukrainian battlefield. Security and Defence Quarterly, 2025. https://doi.org/10.35467/sdq/208347
[118] Bulletin of the Russian Military Medical Academy — Bildbeleg «An enemy FPV drone that attacked an armored ambulance and became stuck in the protective net», 2025. https://doi.org/10.17816/brmma649350-4389516
[119] Sharma, A. K.; Panigrahi, R. K.; Sharma, P. K. — Computational Analysis and Material Optimization of Protective Cage Structures Against FPV Kamikaze Drone Delivered Explosive Payloads. Journal of Physics: Conf. Ser. 3196(1):012061, IOP, 2026. https://doi.org/10.1088/1742-6596/3196/1/012061
[120] Babanatsas, T.; Babanatis-Merce, R. M. — A Conceptual Model for Eco-Friendly Low-Cost Counter-Drone Defence Using Biodegradable Sticky Microfibers. Preprints, 2025. https://doi.org/10.20944/preprints202509.1486.v1
[121] Muda, N. R. S.; Fadilah, M. F. — Effectiveness of Combined Tactical Forward Posts in Countering Enemy Drone Attacks. Cendekia 3(5), 2026. https://doi.org/10.62335/cendekia.v3i5.2550
[122] Radoš, K.; Brkić, M.; Begušić, D. — Recent Advances on Jamming and Spoofing Detection in GNSS. Sensors 24(13):4210, 2024. https://doi.org/10.3390/s24134210
[123] Fan Yan — Anti-jamming Performance Evaluation of Link-16 Tactical Data Link System and its Simulation. 2009. OpenAlex W2370978264.
[124] Lee, K.; Noh, H.; Lee, J.; Lim, J. — Performance Analysis of Link-16 Waveform considering Frequency Remapping under PBNJ. KICS, 2013. https://doi.org/10.7840/kics.2013.38c.11.955
[125] Yang, T.-H. et al. — Anti-Jamming and Time Delay Performance Analysis of Future SATURN Upgraded Military Aerial Communication Tactical Systems. KSII TIIS, 2022. https://doi.org/10.3837/tiis.2022.09.011
[126] Zheng, W.; Jin, H.; Liu, Y.; Yu, Q. — Analysis and Research on TTNT Data Link. FMSMT, 2017. https://doi.org/10.2991/fmsmt-17.2017.132
[127] Ning, X.; Wang, Y.; Wang, Z.; Sun, Z. — Link-16 Anti-Jamming Performance Evaluation Based on Grey Relational Analysis and Cloud Model. Journal of Systems Engineering and Electronics, 2024. https://doi.org/10.23919/jsee.2023.000120
[128] Bahn, W. L. — Concurrent code spread spectrum: theory and performance analysis of jam resistant communication without shared secrets. 2007. OpenAlex W2520312125. http://hdl.handle.net/10976/247
[129] Soner, B.; Uzun, E.; Aksoy, C. — Low-Cost GNSS Anti-Jamming Through 2-Bit Phase Shift Beamforming with Machine Learning. arXiv:2605.10264, 2026. https://arxiv.org/abs/2605.10264
[130] Huang, K. et al. — Robust Anti-jamming Communications with DMA-Based Reconfigurable Heterogeneous Array. arXiv:2310.09466, 2023. https://arxiv.org/abs/2310.09466
[131] Sheikholeslami, A.; Ghaderi, M.; Pishro-Nik, H.; Goeckel, D. — Energy-Efficient Routing in Wireless Networks in the Presence of Jamming. IEEE Trans. Wireless Commun., 2016. https://doi.org/10.1109/TWC.2016.2591016
[132] Behfarnia, A.; Eslami, A. — Message Passing for Analysis and Resilient Design of Self-Healing Interdependent Cyber-Physical Networks. arXiv:1606.00955, 2016. https://arxiv.org/abs/1606.00955
[133] Seliem, M.; Pesch, D.; Roedig, U.; Sreenan, C. — Resilient Time-Sensitive Networking for Industrial IoT: Configuration and Fault-Tolerance Evaluation (IN2C). arXiv:2507.11250, 2025. https://arxiv.org/abs/2507.11250
[134] Danielis, P.; Parzyjegla, H.; Mühl, G.; Schweissguth, E.; Timmermann, D. — Frame Replication and Elimination for Reliability in Time-Sensitive Networks. arXiv:2109.13677, 2021. https://arxiv.org/abs/2109.13677
[135] Thomas, L.; Mifdaoui, A.; Le Boudec, J.-Y. — Worst-case Delay Bounds in Time-Sensitive Networks with Packet Replication and Elimination. IEEE/ACM Trans. Netw., 2022. https://doi.org/10.1109/TNET.2022.3180763
[136] Martinez, G. D.; Li, C.; Staron, A.; Kitching, J.; Raman, C.; McGehee, W. R. — A chip-scale atomic beam clock. Nature Communications, 2023. https://doi.org/10.1038/s41467-023-39166-1
[137] Peil, S.; Akin, T. G.; Whalen, J. D. — 100-ns-level timing holdover after 12 years for rubidium atomic fountains. Physical Review, 2025. https://doi.org/10.1103/61yv-3ltl
[138] Kriezis, A.; Chen, Y.-H.; Akos, D.; Lo, S.; Walter, T. — GNSS Jamming and Spoofing Monitoring Using Low-Cost COTS Receivers. arXiv:2509.13600, 2025. https://arxiv.org/abs/2509.13600
[139] Enan, A.; Chowdhury, M.; Dasgupta, S.; Rahman, M. — Quantum-Classical Hybrid Framework for Zero-Day Time-Push GNSS Spoofing Detection. arXiv:2508.18085, 2025. https://arxiv.org/abs/2508.18085
[140] Motallebighomi, M.; Sathaye, H.; Singh, M.; Ranganathan, A. — Cryptography Is Not Enough: Relay Attacks on Authenticated GNSS Signals. arXiv:2204.11641, 2022. https://arxiv.org/abs/2204.11641
[141] Daliot, A.; Dolev, D.; Parnas, H. — Linear-time Self-stabilizing Byzantine Clock Synchronization. arXiv:cs/0608096, 2006. https://arxiv.org/abs/cs/0608096
[142] Bund, J.; Lenzen, C.; Rosenbaum, W. — Fault Tolerant Gradient Clock Synchronization. arXiv:1902.08042, 2019. https://arxiv.org/abs/1902.08042
[143] Li, H.; Gong, G.; Pan, W.; Du, Q.; Li, J. — Temperature Effect and Correction Method of White Rabbit Timing Link. arXiv:1406.4223, 2014. https://arxiv.org/abs/1406.4223
[144] Harvey, J.; Steer, M. B.; Rappaport, T. S. — Exploiting High Millimeter Wave Bands for Military Communications, Applications, and Design. IEEE Access, 2019. https://doi.org/10.1109/ACCESS.2019.2911675
[145] Rappaport, T. S.; MacCartney, G. R.; Samimi, M. K.; Sun, S. — Wideband Millimeter-Wave Propagation Measurements and Channel Models for Future Wireless Communication System Design. IEEE Trans. Commun., 2015. https://doi.org/10.1109/tcomm.2015.2434384
[146] van Vliet, V.; van den Hout, M.; Gümüş, K.; Tangdiongga, E.; Okonkwo, C. — Experimental Investigation of Availability in a 4.6 km Terrestrial Urban Coherent Free-Space Optical Communications Link. ECOC, 2025. https://doi.org/10.1109/ECOC66593.2025.11263027
[147] Wang, J.; Su, Z.; Li, B.; Zheng, W.; Gao, H. — Ground-Based Verification Method for Pointing and Acquisition Performance of Space Optical Communication System with Sub-Second Acquisition Time. arXiv:2508.08950, 2025. https://arxiv.org/abs/2508.08950
[148] Dhiman, P. et al. — A Review and Comparative Analysis of Relevant Approaches of Zero Trust Network Model. Sensors, 2024. https://doi.org/10.3390/s24041328
[149] Djahel, S.; Naït-Abdesselam, F.; Zhang, Z. — Mitigating Packet Dropping Problem in Mobile Ad Hoc Networks: Proposals and Challenges. IEEE Communications Surveys & Tutorials, 2011. https://doi.org/10.1109/surv.2011.072210.00026
[150] Gupta, N.; Doan, T. T.; Vaidya, N. H. — Byzantine Fault-Tolerance in Decentralized Optimization under Minimal Redundancy. arXiv:2009.14763, 2020. https://arxiv.org/abs/2009.14763
[151] Saarinen, M.-J. O. — Mobile Energy Requirements of the Upcoming NIST Post-Quantum Cryptography Standards. arXiv:1912.00916, 2019. https://arxiv.org/abs/1912.00916
[152] Wallace, R. J.; Loffi, J. M. — Examining Unmanned Aerial System Threats & Defenses: A Conceptual Analysis. International Journal of Aviation, Aeronautics, and Aerospace 2(4), 2015. https://doi.org/10.15394/ijaaa.2015.1084
[153] CSIS Missile Defense Project — Countering Uncrewed Aerial Systems: A Conversation with General Sean Gainey, 14.11.2023. https://www.csis.org/analysis/countering-uncrewed-aerial-systems-conversation-general-sean-gainey
[154] Kong, L.; Wang, J.; Zhao, P. — Solving the Dynamic Weapon Target Assignment Problem by an Improved MOPSO. Applied Sciences 11(19):9254, 2021. https://doi.org/10.3390/app11199254
[155] Cao, M.; Fang, W. — Swarm Intelligence Algorithms for Weapon-Target Assignment in a Multilayer Defense Scenario. Symmetry 12(5):824, 2020. https://doi.org/10.3390/sym12050824
[156] Clarke, C. A.; Larsen, W. E. — Aircraft Electromagnetic Compatibility. NASA/Ames, 1987. http://hdl.handle.net/2060/19870014423
[157] Huang, Q. — Investigation of radiation-hardened design of electronic systems with applications to post-accident monitoring. PhD, University of Western Ontario, 2019. https://ir.lib.uwo.ca/etd/6025
[158] Grachauskas, A. — Modern Warfare Tendencies and Implications for the Baltic Region: Adapting to a New Era of Conflict. Military Science Journal 41(1), 2026. https://doi.org/10.47459/mz.2026.41.1.3
[159] Nallamalli, R.; Singh, K.; Kumar, I. D. — Technological Perspectives of Countering UAV Swarms. Defence Science Journal 73, 2023. https://doi.org/10.14429/dsj.73.18695
[160] Abir, T. A.; Le, V.; Kuantama, E. et al. — Detection and Tracking of Drone Swarms using LiDAR (LiSWARM). ACM MobiSys, 2025. https://doi.org/10.1145/3711875.3729156
[161] International Committee of the Red Cross — ICRC position on autonomous weapon systems. 12.05.2021. https://www.icrc.org/en/document/icrc-position-autonomous-weapon-systems
[162] CCW Group of Governmental Experts — Guiding Principles affirmed by the GGE on Emerging Technologies in the Area of LAWS, CCW/MSP/2019/9 Annex III, 2019. https://ccdcoe.org/uploads/2020/02/UN-191213_CCW-MSP-Final-report-Annex-III_Guiding-Principles-affirmed-by-GGE.pdf
[163] Amoroso, D. — A Normative Model of Meaningful Human Control over Weapons Systems. In: Autonomous Weapons Systems and International Law, Nomos, 2020. https://doi.org/10.5771/9783748909538-217
[164] Cummings, M. L. — Lethal Autonomous Weapons: Meaningful Human Control or Meaningful Human Certification? IEEE Technology and Society Magazine 38(4), 2019. https://doi.org/10.1109/mts.2019.2948438
[165] Johnson, J. — Inadvertent escalation in the age of intelligence machines: A new model for nuclear risk in the digital age. European Journal of International Security 6(4), 2021. https://doi.org/10.1017/eis.2021.23
[166] King, A. — Digital Targeting: Artificial Intelligence, Data, and Military Intelligence. Journal of Global Security Studies 9(2):ogae009, 2024. https://doi.org/10.1093/jogss/ogae009
[167] Stab BODLUV Br 33 — Organigramm BODLUV Br 33 (gültig ab 1.1.2024); ergänzend Wikipedia Bodengestützte Luftverteidigungsbrigade 33. https://de.wikipedia.org/wiki/Bodengest%C3%BCtzte_Luftverteidigungsbrigade_33
[168] VBS — Das VBS in Zahlen (Bestände, Feuereinheiten Flab/Stinger), Stand 19.12.2025. https://www.vbs.admin.ch/de/vbs-in-zahlen
[169] Dienstreglement der Schweizer Armee (DR04), Art. 18 «Hierarchie der Verbände». https://www.rechtundgesetz.ch/14_65_291_DR04_gesetzestexte_artikel_18_18_Hierarchie_der_Verbaende.html
[170] VBS — Armeebotschaft 2022 (F-35A + Patriot). https://www.vbs.admin.ch/de/armeebotschaft-2022
[171] armasuisse — Bodluv MR: Vertrag zur kooperativen Beschaffung von IRIS-T SLM unterzeichnet, 22.7.2025. https://www.ar.admin.ch/de/newnsb/ZjsNYPpgoETj
[172] admin.ch — Abwehr von Mini-Drohnen: armasuisse beschafft Drohnenabwehrsysteme des Schweizer Lieferanten Securiton, 20.11.2025. https://www.admin.ch/de/newnsb/kFV63fJYMPRSwA3npzNdi
[173] armasuisse — Taskforce Drohnen (TFD), 2025. https://www.ar.admin.ch/de/taskforce-drohnen
| Soft-kill method | Operating principle | Collateral in friendly airspace | Limit against the autonomous, radio-silent drone |
|---|---|---|---|
| Broadband jamming | drowns out the control or satellite signal | high — disrupts public-safety radio and GNSS nearby | ineffective: no reception left to jam |
| GNSS spoofing | injects a falsified satellite signal | moderate — may deceive neighboring receivers | actively counterable (e.g., SemperFi); ineffective against pure inertial navigation |
| Protocol takeover (RF cyber takeover) | hijacks the control channel specifically | low — only the single channel affected | ineffective: no control channel present, protocol unknown |
| Category | Cost per Engagement (estimate) | Assessment Against Mass Swarms |
|---|---|---|
| Guided missile (Patriot, IRIS-T) | USD 1.0–4.75 million | highest Pk, but immediate magazine depletion |
| Programmable flak (AHEAD) | several thousand USD/burst | best value for money in the close-in zone |
| Interceptor drone | ~USD 3,500 | reverses the cost curve, scalable magazine depth |
| High-energy laser | <USD 10 (pure energy) | lowest shot cost, limited by sequentiality |
| High-power microwave | purely electrical | “unlimited magazine” given a power supply |
| EW / RF jammer | ~USD 0.01 | virtually free, ineffective against the autonomous cutting edge |
| Abbreviation | Meaning |
|---|---|
| AESA | Active Electronically Scanned Array (actively electronically steered radar) |
| AHEAD | Advanced Hit Efficiency And Destruction (programmable fragmentation munition) |
| ATR | Automatic Target Recognition |
| BODLUV | Ground-based air defense (Swiss Armed Forces) |
| C2 | Command and Control |
| C-RAM | Counter Rocket, Artillery and Mortar |
| C-sUAS / C-UAS | Counter-(small-)Unmanned Aircraft Systems (counter-drone defense) |
| C-UAV | Counter-UAV, here: counter-drone defense using drones |
| CRPA | Controlled Reception Pattern Antenna (adaptive anti-jam antenna array) |
| DDIL | Denied, Degraded, Intermittent, Limited (contested connectivity environment) |
| DEW | Directed Energy Weapon |
| EO/IR | Electro-Optical / Infrared |
| ESSI | European Sky Shield Initiative |
| EW | Electronic Warfare |
| FGG | Staff function (staff area S1–S6) |
| FOC / IOC | Full / Initial Operational Capability |
| FRER | Frame Replication and Elimination for Reliability (IEEE 802.1CB) |
| FSO | Free-Space Optics (free-space/laser communication) |
| GBAD | Ground-Based Air Defence |
| HEL | High-Energy Laser |
| HPM | High-Power Microwave |
| IAD | Integrated Air Defence |
| IFPC | Indirect Fire Protection Capability (U.S. Army; -HEL / -HPM) |
| IRIS-T SLM | Infra Red Imaging System Tail/Thrust Vector-Controlled — Surface-Launched Medium Range |
| J/S | Jamming-to-Signal Ratio |
| JTIDS | Joint Tactical Information Distribution System (Link 16) |
| KRITIS | Critical infrastructure |
| LAAD | Low-Altitude Air Defense |
| LSS | Low, Slow, Small (target class of small, slow, low-flying drones) |
| LWL | Optical fiber (glass fiber) |
| MADL | Multifunction Advanced Data Link (stealth data link) |
| mmWave | Millimeter waves (high-frequency directional radio link) |
| OODA | Observe–Orient–Decide–Act (Boyd’s decision loop) |
| PAC-2 / PAC-3 | Patriot Advanced Capability 2 / 3 (guided-missile variants) |
| PNT | Positioning, Navigation and Timing |
| RAM | Rockets, Artillery, Mortars (rocket, artillery, and mortar attacks) |
| RAP | Recognized Air Picture |
| RF | Radio Frequency |
| SHORAD | Short-Range Air Defense |
| TFD | Drone Task Force (armasuisse) |
| TRML-4D | AESA radar by Hensoldt (sensor for IRIS-T SLM) |
| UAS / UAV | Unmanned Aircraft System / Vehicle |
| VBS | Swiss Federal Department of Defence, Civil Protection and Sport |
| WTA | Weapon-Target Assignment |
| ZTA | Zero-Trust Architecture |