SearcharxivSearch

arXiv · 2012.07727

Localization Attack by Precoder Feedback Overhearing in 5G Networks and Countermeasures

Abstract

In fifth-generation (5G) cellular networks, users feed back to the base station the index of the precoder (from a codebook) to be used for downlink transmission. The precoder is strongly related to the user channel and in turn to the user position within the cell. We propose a method by which an external attacker determines the user position by passively overhearing this unencrypted layer-2 feedback signal. The attacker first builds a map of fed back precoder indices in the cell. Then, by overhearing the precoder index fed back by the victim user, the attacker finds its position on the map. We focus on the type-I single-panel codebook, which today is the only mandatory solution in the 3GPP standard. We analyze the attack and assess the obtained localization accuracy against various parameters. We analyze the localization error of a simplified precoder feedback model and describe its asymptotic localization precision. We also propose a mitigation against our attack, wherein the user randomly selects the precoder among those providing the highest rate. Simulations confirm that the attack can achieve a high localization accuracy, which is significantly reduced when the mitigation solution is adopted, at the cost of a negligible rate degradation.

Explore related subjects

Keep this discovery

BibTeXRIS

Stefan Roth, Stefano Tomasin, Marco Maso, Aydin Sezgin. 2020-12-14. Localization Attack by Precoder Feedback Overhearing in 5G Networks and Countermeasures. https://arxiv.org/abs/2012.07727

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

A Mathematical Theory of Pragmatic Information

We propose a pragmatic information theory unifying communication, control, and decision-making. Its core is the isoteleia mapping, formalizing equifinality: distinct semantic paths leading to the same optimal action are pragmatically equivalent. This induces a three-tier hierarchy of syntactic, semantic, and pragmatic information, each abstraction discarding task-irrelevant distinctions. We develop pragmatic entropy, up/down mutual information, channel capacity, and rate-distortion, and prove three coding theorems generalizing Shannon's classical results. We introduce pragmatic value (VoI) and cost (CoI) of information as decision-theoretic duals to rate-distortion and capacity, respectively, and formulate a Lagrangian dual framework for cross-layer optimization. The pragmatic efficiency bound $\mathcal{E}_p(\lambda)=\sup_R[\Phi_p(R)-\lambda\,\mathrm{CoI}_p(R)]$ quantifies the maximum net utility any resource-constrained intelligent system can extract, thereby establishing a fundamental behavioral capacity limit---generalizing Shannon's symbol-level capacity to goal-directed action. Extensions to continuous messages yield closed-form Gaussian expressions, while dynamic settings are addressed via a Bellman equation for sequential decision-making. This framework provides a rigorous foundation for task-oriented communication, networked control, autonomous systems, and embodied AI, shifting focus from symbol fidelity to the effectiveness of information in guiding actions, and offers a unified mathematical language for next-generation intelligent systems.

cs.IT

Data Protection in Function-Correcting Symbol-Pair Codes: Redundancy Bounds and Protection Profiles

In several storage systems, including DNA storage and flash memory, errors affect neighbouring symbols jointly, and the Hamming metric does not adequately capture such error patterns. The symbol-pair read channel, introduced by Cassuto and Blaum~\cite{cassuto2011codes}, addresses this by reading consecutive pairs of symbols rather than individual symbols. Motivated by this, we introduce function-correcting symbol-pair codes with data protection (FCSPC-DP), which guarantee reliable recovery of a desired function of the message while simultaneously protecting the message itself against symbol-pair errors. We derive bounds on the optimal redundancy of such codes and establish a relationship with joint-pair distance matrices. We also give explicit constructions of FCSPC-DP for locally pair-bounded functions and symbol-pair weight functions. We introduce the pair-separation constant of a function, the minimum symbol-pair distance between messages sharing a function value, and show that when it is sufficiently large, data protection requires no additional redundancy: the optimal redundancy coincides with that of the corresponding code without data protection. Considering the symbol-pair analogue of the $\alpha$-distance graph, we introduce two code invariants, the generation profile and the disconnection threshold, and use them to characterise a code's protection properties. Relating the two metrics through these invariants yields upper and lower bounds on the symbol-pair threshold in terms of its Hamming counterpart, both of which are attained. We further extend the classical Plotkin and sphere-packing bounds to this setting.

cs.IT

Physics of Information Geometry - Part II: Small-Step Active Inference on the Probability Simplex

This paper is the second in a two-part investigation of the physics of information geometry. While Part I develops a physical foundation for distributional motion on the probability simplex, the present paper studies how that framework manifests in active inference. The treatment is fully self-contained and does not require familiarity with Part I. We focus in particular on active inference through small distributional steps and the geometric structure induced by such local motion. Starting from an initial distribution, an agent evolves its belief state toward a final target distribution through a sequence of constrained updates. We define a relative free energy functional with respect to the preferred distribution and extend it to a relative potential energy analogous to the Helmholtz/Gibbs free-energy decomposition. The evolution is subject to a per-step kinetic constraint expressed through the Kullback-Leibler (KL) divergence between consecutive distributions, which serves as a discrete kinetic energy on the probability simplex. Using the information-geometric Pythagorean theorem on KL balls, we show that sufficiently small local moves dominate large direct jumps, and that greedy maximization of free-energy reduction is globally optimal under the kinetic constraint. This leads to a sequential variational principle in which the optimal trajectory minimizes the associated Lagrangian of the optimization problem. Similar to classical mechanics, the Lagrangian takes on the form as the difference between the kinetic and potential terms, establishing a least-action principle for distributional motion on the simplex. The resulting optimal update admits a closed form as an exponentially tilted version of the current distribution toward the preferred distribution, parametrized by an inverse-temperature-like multiplier. We further extend the framework to incorporate state-dependent geodesic...

cs.IT