Malicious Pseudo-Ranging and Localization of Static LOS Wireless Users via Downlink Modulation Classification and Uplink Refinement
This paper proposes a novel passive attack that enables an eavesdropper to localize a stationary line-of-sight user by first using downlink modulation classification to pseudo-range the user's location and then refining that position via uplink channel sniffing.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Technical Summary: Malicious Pseudo-Ranging and Localization of Static LOS Wireless Users
Problem Statement
The openness of wireless standards (e.g., 3GPP Releases 16–20 and IEEE 802.11xx) and the broadcast nature of the wireless medium create vulnerabilities that adversaries can exploit. While existing countermeasures often focus on active attacks (e.g., jamming, rogue base stations), this paper identifies a "loose end" in public Modulation and Coding Scheme (MCS) tables. These tables, essential for Adaptive Modulation and Coding (AMC), map channel quality to specific modulation schemes. The paper posits that an eavesdropper (Eve) can reverse-engineer these public tables to infer the Signal-to-Noise Ratio (SNR) of a link, and consequently, the geographic distance between a Base Station (Alice) and a stationary Line-of-Sight (LOS) user (Bob), without deploying any anchor nodes or engaging in active probing.
Methodology
The proposed attack is a passive, two-phase process designed to localize a static user:
Downlink Phase (Pseudo-Ranging):
- Eve intercepts the downlink broadcast from Alice to Bob.
- A Deep Learning-based modulation classifier (specifically a 2D Convolutional Neural Network with four convolutional layers) is employed to identify the modulation scheme (e.g., BPSK, QPSK, 16-QAM, 64-QAM) of the intercepted signal.
- Using the publicly available MCS tables, Eve maps the detected modulation scheme to a specific SNR range.
- By applying the Friis transmission equation and assuming known transmit power and frequency, Eve converts this SNR range into distance bounds. This narrows the user's possible location from the entire cell coverage area to a specific concentric ring around the base station.
Uplink Phase (Refinement):
- Eve moves to the identified ring and traverses it in a circular path.
- Eve sniffs the uplink transmission from Bob. Since uplink power is typically lower, Eve must be in close proximity to capture a high-quality signal.
- At each grid point along the circle, Eve measures the received SNR. The location yielding the maximum SNR is declared as the initial estimate of Bob's position.
- To refine this estimate, Eve performs a secondary, smaller circular motion around the initial estimate (using the distance derived from the SNR) to pinpoint the location with the highest SNR. This process can be repeated iteratively.
- Extensions: The methodology is also evaluated with multiple antennas (using a Uniform Linear Array and root-MUSIC algorithm for Direction of Arrival estimation) and in multi-user scenarios where Eve monitors multiple orthogonal sub-carriers.
Key Contributions
- Novel Passive Attack: This work introduces the first known passive attack that utilizes MCS tables for user localization without requiring anchor nodes or active interference.
- Search Space Reduction: The attack effectively reduces the localization search space from a full cell to a specific ring (pseudo-ranging) via downlink modulation classification.
- Infrastructure-Free: Unlike traditional non-cooperative source localization, this method requires no pre-deployed infrastructure with known locations.
- Validation: The approach is validated through simulations across single-user, multi-user, and multiple-antenna scenarios using frequencies of 5 GHz, 28 GHz, and 100 GHz.
Results
- Modulation Classification: The CNN-based classifier achieved validation accuracies exceeding 80% across all simulated scenarios. Testing accuracy varied based on Eve's proximity to the base station and the transmit power; closer proximity to the base station yielded higher accuracy, which is critical for correct ring identification.
- Localization Accuracy:
- Localization error increases with higher transmit powers (due to larger coverage rings) but decreases at higher frequencies (mmWave) due to higher path loss and smaller coverage areas.
- Knowledge of the exact transmit power of the user significantly improves accuracy compared to knowing only a power range.
- In a single-user scenario at 28 GHz, the average localization error was approximately 0.66 meters.
- Multi-User: The attack successfully localized two simultaneous users with comparable accuracy (0.66m and 0.67m) to the single-user case, though it requires increased receiver bandwidth and processing resources.
- Multiple Antennas: Equipping Eve with a 10-element Uniform Linear Array reduced the average localization error significantly to 0.27 meters by leveraging Direction of Arrival (DoA) estimation.
- Complexity: The computational complexity is modest (approx. 59 MFLOPs for the CNN), suggesting the attack is feasible for deployment on edge devices with standard GPU capabilities.
Significance and Claims
The paper frames this work as an "ethical hacking" disclosure intended to raise awareness about the security implications of public wireless standards. The authors claim that the openness of 3GPP and IEEE standards allows adversaries to map observed MCS indices to geographic regions, threatening spatial privacy and enabling long-term tracking, deanonymization, and the construction of malicious "digital twin" maps of user mobility.
The authors emphasize that while the current study is limited to Line-of-Sight (LOS) and static users, the attack serves as a "scaffolding" for more complex scenarios. They discuss potential extensions to Non-Line-of-Sight (NLOS) environments (using radio fingerprinting) and mobile users (using Markov chains and Kalman filtering). The paper concludes that while private 5G networks might be immune, public 5G and WiFi networks remain vulnerable to this infrastructure-less, passive sensing attack, necessitating a re-examination of standard security profiles in the era of 6G and AI-native networks.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.