USENIX Security2026Top-tier venue
Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis
Ziyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang
Abstract
Core network (CN) is at the center of a cellular system and was historically protected by physical isolation, but the shift to cloud-native deployments breaks this protection and introduces new attack interfaces. Indeed, from reported GitHub issues, we found that many security flaws within CNs can be attributed to blind trust underlying interactions across different CN components. Under such trust assumptions, one component may fail to properly verify the syntactic and semantic content of messages received from other internal components, and may also grant resources to requesters without validation of resource availability. These weaknesses, once coupled with the risks of exposing internal interfaces to unauthorized external parties, as observed in our research, will lead to serious consequences, including session hijacking and denial of services. In our research, we call these newly discovered weaknesses implicit trust errors or iTrue . To detect iTrues and understand their security impacts, we designed and implemented a multi-agent framework, dubbed iFinder . iFinder automatically analyzes and summarizes known security flaws, and uses them as ``seeds'' to detect related vulnerabilities from the CN simulators. To suppress hallucinations produced by large language models (LLMs), not only have we developed a Chain of Thought (CoT) reasoning to guide agents, but we also build an innovative strategy that cross-checks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN simulators and analyzing results. Running iFinder on 7 prominent simulators, we discovered 84 previously unknown vulnerabilities. Among them 70 have already been confirmed with 40 CVE assignments already awarded. Our findings highlight the pervasiveness of iTrue risks across the cellular core networks and the urgent needs for elevated protection within the original trust domains. We plan to make the service of iFinder publicly available to help enhance the security qualities of cellular core networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fe59d74a-f906-4db6-b353-426b5f4bdffcBuilds on30
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration TestingGelei Deng, Yi Liu, Víctor Mayoral Vilches, Peng Liu et al.USENIX Security 2024 · 186 citations
Related papers
- Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisYi Chen, Yepeng Yao, XiaoFeng Wang, Dandan Xu et al.S&P 2021 · 57 citations
- Instructions Unclear: Undefined Behaviour in Cellular Network SpecificationsDaniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov et al.USENIX Security 2023
- RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core InterfacesNathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy et al.CCS 2024 · 9 citations
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park et al.CCS 2025
- Intender: Fuzzing Intent-Based Networking with Intent-State Transition GuidanceJiwon Kim, Benjamin E. Ujcich, Dave TianUSENIX Security 2023
