Hijacking 5G MIMO: a Downgrade Attack via Tampered Zero-Power Channel State Information
Alessandra Dino, Fabrizio Giuliano, Stefano Mangione, Domenico Garlisi, Ilenia Tinnirello
Abstract
In this paper we demonstrate a novel downgrade attack for 5G networks able to dramatically reduce the efficiency of Multi-Input-Multi-Output links, while remaining virtually invisible to standard intrusion monitors.By opportunistically injecting noise precisely aligned with silent reference signals in the radio frames (called Zero-Power Channel State Information Reference Signals), we show that an attacker can corrupt the feedback mechanism implemented at the User Equipment for channel estimation, forcing the base station to downgrade or disable spatial multiplexing. This mechanism is much simpler than pilot spoofing schemes and dramatically harder to defend: indeed, silent reference signals cannot be protected by integrity mechanisms and their sparsity keeps the average power of the injected noise difficult to detect.We design a robust mechanism for synchronizing the attacker transmissions to the silent reference signals, and quantify the latency of the attack under different SNR and cell load conditions. The approach has been implemented in a Software Defined Radio testbed and experimentally validated in a private network, by demonstrating a success probability higher than 82% on two different commercial smartphones and a throughput degradation up to 70%.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- SNI5GECT: A Practical Approach to Inject aNRchy into 5G NRShijie Luo, Matheus E. Garbelini, Sudipta Chattopadhyay, Jianying ZhouUSENIX Security 2025
- Your Locations May Be Lies: Selective-PRS-Spoofing Attacks and Defence on 5G NR Positioning SystemsKaixuan Gao, Huiqiang Wang, Hongwu Lv, Pengfei GaoINFOCOM 2023 · 17 citations
- Stemming Downlink Leakage from Training Sequences in Multi-User MIMO NetworksYunlong Mao, Yuan Zhang, Sheng ZhongCCS 2016 · 8 citations
- On the Criticality of Integrity Protection in 5G Fronthaul NetworksJiarong Xing, Sophia Yoo, Xenofon Foukas, Daehyeok Kim et al.USENIX Security 2024 · 15 citations
- Channel Access Deterrence Attack: An Attack Against Spectrum Coexistence Between NR-U and Wi-Fi in the 5 GHz BandMd. Rashedur Rahman, Moinul HossainINFOCOM 2025 · 2 citations
