In this paper we demonstrate a novel downgrade attack for 5G networks able to dramatically reduce the efficiency of Multi-Input-Multi-Output links, while remaining virtually invisible to standard intrusion monitors.By opportunistically injecting noise precisely aligned with silent reference signals in the radio frames (called Zero-Power Channel State Information Reference Signals), we show that an attacker can corrupt the feedback mechanism implemented at the User Equipment for channel estimation, forcing the base station to downgrade or disable spatial multiplexing. This mechanism is much simpler than pilot spoofing schemes and dramatically harder to defend: indeed, silent reference signals cannot be protected by integrity mechanisms and their sparsity keeps the average power of the injected noise difficult to detect.We design a robust mechanism for synchronizing the attacker transmissions to the silent reference signals, and quantify the latency of the attack under different SNR and cell load conditions. The approach has been implemented in a Software Defined Radio testbed and experimentally validated in a private network, by demonstrating a success probability higher than 82% on two different commercial smartphones and a throughput degradation up to 70%.
Dino, A., Giuliano, F., Mangione, S., Garlisi, D., Tinnirello, I. (2026). Hijacking 5G MIMO: A Downgrade Attack via Tampered Zero-Power Channel State Information. In Proceedings - IEEE INFOCOM (pp. 1-10). Institute of Electrical and Electronics Engineers Inc. [10.1109/INFOCOM59046.2026.11571763].
Hijacking 5G MIMO: A Downgrade Attack via Tampered Zero-Power Channel State Information
Dino A.;Giuliano F.;Mangione S.;Garlisi D.;Tinnirello I.
2026-05-01
Abstract
In this paper we demonstrate a novel downgrade attack for 5G networks able to dramatically reduce the efficiency of Multi-Input-Multi-Output links, while remaining virtually invisible to standard intrusion monitors.By opportunistically injecting noise precisely aligned with silent reference signals in the radio frames (called Zero-Power Channel State Information Reference Signals), we show that an attacker can corrupt the feedback mechanism implemented at the User Equipment for channel estimation, forcing the base station to downgrade or disable spatial multiplexing. This mechanism is much simpler than pilot spoofing schemes and dramatically harder to defend: indeed, silent reference signals cannot be protected by integrity mechanisms and their sparsity keeps the average power of the injected noise difficult to detect.We design a robust mechanism for synchronizing the attacker transmissions to the silent reference signals, and quantify the latency of the attack under different SNR and cell load conditions. The approach has been implemented in a Software Defined Radio testbed and experimentally validated in a private network, by demonstrating a success probability higher than 82% on two different commercial smartphones and a throughput degradation up to 70%.| File | Dimensione | Formato | |
|---|---|---|---|
|
ENERGY_ATTACK_5G_INFOCOM2026 (1).pdf
Solo gestori archvio
Tipologia:
Pre-print
Dimensione
1.53 MB
Formato
Adobe PDF
|
1.53 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
|
Hijacking_5G_MIMO_a_Downgrade_Attack_via_Tampered_Zero-Power_Channel_State_Information.pdf
Solo gestori archvio
Tipologia:
Versione Editoriale
Dimensione
2.25 MB
Formato
Adobe PDF
|
2.25 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


