Pith. sign in

REVIEW 2 cited by

Scalable and Robust Mobile Activity Fingerprinting via Over-the-Air Control Channel in 5G Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2409.12572 v1 pith:YEGAVUB2 submitted 2024-09-19 cs.NI cs.CR

classification cs.NIcs.CR
keywords mobileactivitycontrolchannelchannelsover-the-airapplicationschanges
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

5G has undergone significant changes in its over-the-air control channel architecture compared to legacy networks, aimed at enhancing performance. These changes have unintentionally strengthened the security of control channels, reducing vulnerabilities in radio channels for attackers. However, based on our experimental results, less than 10% of Physical Downlink Control Channel (PDCCH) messages could be decoded using sniffers. We demonstrate that even with this limited data, cell scanning and targeted user mobile activity tracking are feasible. This privacy attack exposes the number of active communication channels and reveals the mobile applications and their usage time. We propose an efficient deep learning-based mobile traffic classification method that eliminates the need for manual feature extraction, enabling scalability across various applications while maintaining high performance even in scenarios with data loss. We evaluated the effectiveness of our approach using both an open-source testbed and a commercial 5G testbed, demonstrating the feasibility of mobile activity fingerprinting and targeted attacks. To the best of our knowledge, this is the first study to track mobile activity over-the-air using PDCCH messages.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR

    cs.CR 2026-07 conditional novelty 6.0 of 10

    A 5G attacker can infer a victim's application-layer goodput from unencrypted downlink control information and slash it by up to 50% with sparse, targeted jamming.

  2. Fingerprinting Deep Learning Models via Network Traffic Patterns in Federated Learning

    cs.LG 2025-06 reject novelty 5.0 of 10

    An attacker can classify CNN vs RNN traffic in a simulated federated learning setup with up to 100% accuracy, but the experiment conflates model architecture with dataset and uses only 39 traffic captures.

Pith tools