REVIEW 2 cited by
Scalable and Robust Mobile Activity Fingerprinting via Over-the-Air Control Channel in 5G Networks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
5G has undergone significant changes in its over-the-air control channel architecture compared to legacy networks, aimed at enhancing performance. These changes have unintentionally strengthened the security of control channels, reducing vulnerabilities in radio channels for attackers. However, based on our experimental results, less than 10% of Physical Downlink Control Channel (PDCCH) messages could be decoded using sniffers. We demonstrate that even with this limited data, cell scanning and targeted user mobile activity tracking are feasible. This privacy attack exposes the number of active communication channels and reveals the mobile applications and their usage time. We propose an efficient deep learning-based mobile traffic classification method that eliminates the need for manual feature extraction, enabling scalability across various applications while maintaining high performance even in scenarios with data loss. We evaluated the effectiveness of our approach using both an open-source testbed and a commercial 5G testbed, demonstrating the feasibility of mobile activity fingerprinting and targeted attacks. To the best of our knowledge, this is the first study to track mobile activity over-the-air using PDCCH messages.
Forward citations
Cited by 2 Pith papers
-
DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR
A 5G attacker can infer a victim's application-layer goodput from unencrypted downlink control information and slash it by up to 50% with sparse, targeted jamming.
-
Fingerprinting Deep Learning Models via Network Traffic Patterns in Federated Learning
An attacker can classify CNN vs RNN traffic in a simulated federated learning setup with up to 100% accuracy, but the experiment conflates model architecture with dataset and uses only 39 traffic captures.
Discussion (0). Continue with ORCID to comment.