[Submitted on 26 Feb 2025 (v1), last revised 22 Jul 2026 (this version, v2)]

View PDF HTML (experimental)

Abstract:The broadcast nature of the wireless medium and openness of wireless standards, e.g., 3GPP releases 16-20, invite adversaries to launch various active and passive attacks on cellular and other wireless networks. This work identifies one such loose end of wireless standards and presents a novel passive attack method enabling an eavesdropper (Eve) to localize a line-of-sight stationary wireless user (Bob) who is communicating with a base station or WiFi access point (Alice). The proposed attack involves two phases. In the first phase, Eve performs modulation classification by intercepting the downlink channel between Alice and Bob. This enables Eve to utilize the publicly available modulation and coding scheme tables to do pesudo-ranging, i.e., the Eve determines the ring within which Bob is located, which drastically reduces the search space. In the second phase, Eve sniffs the uplink channel, and employs multiple strategies to further refine Bob's location within the ring. In simulations, the proposed attack is validated for single-user, multi-user, and multiple-antenna scenarios. Towards the end, we present our thoughts on how this attack can be extended to other scenarios such as non-line-of-sight and mobile users e.g., cars, drones, pedestrians, and how this attack could act as a scaffolding to construct a malicious digital twin map.

Submission history

From: Muhammad Mahboob Ur Rahman [view email]
[v1] Wed, 26 Feb 2025 17:32:38 UTC (337 KB)
[v2] Wed, 22 Jul 2026 08:52:28 UTC (385 KB)