Ivan Palamà

dblp:274/3356 · DBLP profile ↗
← Back
14ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0002-7001-7743ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 3 first-author · 10 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Predictable and Exposed: Eavesdropping and Exploitation of Positioning Reference Signals
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
ICC3
2026 Practical Blind Full-Frame Replay Attacks on OFDM-Based ISAC Systems
abstract
Integrated Sensing and Communication (ISAC) systems promise unprecedented capabilities by merging connectivity and situational awareness, but also expose new attack surfaces at the physical layer. In this work, we demonstrate a blind full-frame OFDM replay attack that manipulates sensing outputs by injecting false targets and concealing real ones, without disrupting communication. The blind nature of our attack lies in the fact that it requires neither synchronization nor any knowledge of the signal structure, reference signals, or sensing parameters, making it not only practically viable, but even (somewhat) straightforward to execute. By replaying entire OFDM frames with a controlled delay and a frequency shift, the attacker can distort range estimations and induce Doppler shifts, mimicking the presence of moving targets. We present a general analytical framework to characterize the attack’s impact on range-Doppler processing and validate it through both system-level simulations with 5G NR parameters and real-world experiments. Experimental results build directly on a working 5G testbed with software-defined radios and commercial off-the-shelf hardware, which we extend with sensing capabilities, thereby demonstrating the attack’s feasibility and impact in a realistic ISAC scenario.
Stefania Bartoletti, Giulia Focarelli, Ivan Palamà, Samuele Zanini, Nicola Blefari-Melazzi, Giuseppe Bianchi 0001
IEEE J. Sel. Areas Commun.3
2026 Positioning Security in 5G and Beyond: Model and Detection of Physical Layer Threats
abstract
Accurate localization is an essential functionality of 5G and beyond systems to enable location-based applications, such as autonomous vehicles and emergency response. Nevertheless, the integrity of location data faces challenges not only from unintentional sources of error, such as wireless propagation impairments and synchronization failures but also from malicious and intentional threats, such as spoofing attacks. This paper specifically addresses the risk to localization integrity posed by malicious attacks. It provides a framework for modeling security threats at the physical layer of cellular positioning, with a focus on 5G and beyond systems. Two detection methods are proposed to mitigate the impact of spoofing attacks, by leveraging cross-correlation analysis and Gaussian Mixture Models (GMMs). These methods leverage standard metrics already defined in the localization procedure, thus eliminating the need for additional signal processing steps. Simulation results in 3GPP standard-compliant scenarios demonstrate the effectiveness of these methods in significantly reducing the integrity risk under attack conditions, thus providing a foundation for developing resilient mobile network location-based services.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
IEEE Trans. Wirel. Commun.3
2025 Experimental Viability of Full-Frame 5G Meaconing Attacks
abstract
This demo paper experimentally explores the feasibility of full-frame meaconing attacks in 5th generation (5G) systems, wherein adversaries stealthily manipulate time-of-arrival (ToA) measurements without disrupting ongoing communications. By intercepting, delaying, and amplifying the entire 5G frames, including critical positioning signals from the gNodeB (gNB), the attack injects a bias into the ToA estimation process, leading to significant positioning errors while leaving the communication service uninterrupted. Our evaluation, conducted on a comprehensive end-to-end 5G testbed built with commercial-off-the-shelf (COTS) and Software-Defined Radio (SDR) devices, includes real-time monitoring of key performance metrics such as reference signal received power (RSRP) and signal to interference and noise ratio (SINR). The experimental results highlight a critical physical-layer vulnerability in 5G positioning, underscoring the urgent need for robust countermeasures to safeguard network integrity.
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Alessandro Rivitti, Giuseppe Bianchi 0001, Stefania Bartoletti
WCNC3
2025 FlashCatch: Minimizing Disruption in IMSI Catcher Operations
abstract
IMSI catchers are surveillance tools that intercept cellular signals to capture user identifiers, such as the IMSI. By imitating a legitimate BS and compelling phones to connect via jamming or stronger signal, they cause temporary disconnection, risking service disruption and raising suspicion, which limits their covert effectiveness. This paper presents FlashCatch, an IMSI-catching approach that significantly accelerates the two primary factors leading to service disruption. First, by exploiting 3GPP standard vulnerabilities, FlashCatch reduces IMSI capture time by over 200 times. Second, it improves the detachment phase through intentional authentication failures, inducing a rapid switch back to a legitimate cell and barring the FBS cell from further reconnection, thus reducing overall noticeable service disruption by at least 50-fold. Laboratory experiments on 7 devices featuring basebands from three different manufacturers demonstrate sub-second IMSI retrieval with seamless service continuity, while dedicated VoLTE and VoIP experiments confirm that ongoing calls resume without termination after a transient small disruption. In-the-wild field tests with 50 volunteers further validate its stealth and operational effectiveness. Moreover, FlashCatch preserves the UE's security context, retaining temporary identifiers that enable linkability attacks for subsequent tracking.
Andrea Paci, Gabriele Bologna, Ivan Palamà, Giuseppe Bianchi 0001
WISEC3
2025 WIP: Parrots in the Air: Experimental Validation of Full-Frame Meaconing in 5G Systems
abstract
While extensively studied in Global Positioning Systems, meaconing—i.e., the delay, amplification, and replay of a signal—is often regarded as impractical in cellular positioning systems due to the potential risk of communication disruption. We challenge this belief by experimentally validating full-frame meaconing attacks on 5G systems. Using off-the-shelf hardware, we demonstrate how an attacker can replay entire 5G frames, introducing o(μs) controlled TOA biases while maintaining uninterrupted communication. Our findings reveal the real world viability of these attacks, highlighting the urgent need for robust countermeasures to protect 5G localization systems.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Alessandro Rivitti, Stefania Bartoletti, Giuseppe Bianchi 0001
WoWMoM3
2025 Localization in 5G and Beyond: A Multi-Objective Approach for Accuracy, Latency, and Resilience
abstract
The integration of localization capabilities within the cellular architecture through dedicated 5G network functions has notably enhanced cellular positioning accuracy and enabled new location-based services. However, this architectural shift requires placing measurement acquisition and computation at the network edge and core, resulting in distributed computational resources and increased latency and security risks. As a result, minimizing latency and ensuring resilience against security threats, in addition to achieving high accuracy, become critical performance indicators in location-based services. This paper examines both 3GPP-standardized and O-RAN-based 5G architectures, detailing the key functions, interfaces, and parameters influencing the localization process, from measurement acquisition to position estimation. We define performance indicators for evaluating localization services and develop a system model that quantifies costs related to latency, accuracy, computation, and resilience against security threats. By jointly considering these factors, we formulate a multi-objective optimization problem that guides the selection of an optimal system configuration to simultaneously satisfy multiple localization requirements. We validate our approach through a case study of an end-to-end 5G system using both simulations and experimental data. Specifically, we evaluate various algorithms and implementations across standardized channels and scenarios. Furthermore, we conduct experimental measurements using Software-Defined Radios (SDRs) and open-source 5G platforms to assess operational latency with commercial-off-the-shelf (COTS) devices.
Luca Petrucci, Samuele Zanini, Ivan Palamà, Nicola Blefari-Melazzi, Stefania Bartoletti
IEEE Trans. Mob. Comput.3
2024 Towards End-to-end Implementation of 5G Positioning with Off-the-shelf Devices
abstract
Despite extensive research and standardization efforts aimed at developing and enhancing 5G localization services, a significant gap persists between theoretical findings and experimental deployments, impeding the validation of key results in real-world operational settings. This paper contributes to fill this gap by proposing an End-to-End (E2E) implementation of a 5G localization system to explore the existing support of commercial off-the-shelf (COTS) user devices and existing RAN solutions for the localization functionality. To this end, we first develop a standard-compliant implementation of the location management function (LMF), i.e., the standard network function responsible for managing location information in the 5G core network. Then, we integrate the LMF with open-source core networks to conduct comprehensive testing on a suite of COTS user equipments and existing 5G RAN solutions, comparing commercial with open-source alternatives. By documenting encountered limitations and releasing our LMF software implementation as open-source, our work significantly contributes to the advancement of 5G localization research and testing in real environments and advocates for increased experiment-readiness in 5G positioning systems.
Samuele Zanini, Luca Petrucci, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
VTC Fall3
2024 5G positioning with software-defined radios
abstract
Positioning is a key focus in 5G standardization, starting with 3GPP Release 16. However, most of the effort from the research community and work presented in the technical standardization has been limited mainly to simulation studies. This paper explores the use of software-defined radios (SDRs) platforms for 5G positioning, presenting an overview of the current state-of-the-art and available open-source platforms. Utilizing an advanced SDR-based multi-gNodeBs (gNBs) synchronized testbed, the paper conducts a series of time-based, over-the-air measurements. Results offer insights into the impact of various real-world system parameters, such as the number of gNBs, transmission bandwidth, signal processing techniques, and localization algorithms on positioning accuracy and Time to First Fix (TTFF). These findings provide a pathway for the cost-effective and efficient implementation of high-precision 5G localization systems. The paper contributes to advancing both theoretical understanding and practical applications, serving as a guide for the development of 5G positioning technology.
Ivan Palamà, Yago Lizarribar 0001, Lorenzo Maria Monteforte, Giuseppe Santaromita, Stefania Bartoletti, Domenico Giustiniano, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
Comput. Networks1
2023 Attacks and vulnerabilities of Wi-Fi Enterprise networks: User security awareness assessment through credential stealing attack experiments
abstract
Enterprise Wi-Fi networks are essential for businesses and public administrations as they provide a perfectly scalable and secure system. In the university environment, they are often deployed to offer services to students. One of the most famous university Wi-Fi Enterprise networks is Eduroam, which stands for education roaming; it is a worldwide Wi-Fi access and roaming service widely adopted by the international research and education community. It is based on 802.1x mechanisms that use TLS tunnels for achieving mutual authentication goals, and, as such, it requires careful configuration of mobile devices and responsible users’ behaviors to avoid trivial attacks carried out with rogue Access Points (APs). Differently than employees in a corporate network whose devices are properly configured by ICT teams, the user base of Eduroam consists of (likely) millions of students and professors around the world, with a myriad of different and uncontrolled devices. To assess the security of 802.1x in general, and more specifically that of Eduroam, we ran attacks against two communities of students of increasing size in order to test how users (and their devices) react when rogue 802.1x APs appear in the list of available networks. We then focused our attention on devices, and investigated their detailed dependence on different WPA-Enterprise configurations and certificate settings. The aftermath is that, even with a completely passive attack (users are keeping devices in their pockets), it is possible to steal credentials from more than one-third of the students. While most of the 802.1x vulnerabilities employed in this work should be considered somewhat known (being disclosed in former technical papers), our work appears to raise a threefold concern: (i) most pragmatic 802.1x configurations appear to be grossly insecure; (ii) no Apple’s iPhone felt in our attack unless explicitly forced by the user, owing to its reduced possibility for a user to misconfigure the terminal; and (iii) the awareness of Wi-Fi authentication threats even in relatively skilled end users is close to zero.
Ivan Palamà, Alessandro Amici, Gabriele Bellicini, Francesco Gringoli, Fabio Pedretti, Giuseppe Bianchi 0001
Comput. Commun.1
2023 Innovative Attack Detection Solutions for Wireless Networks With Application to Location Security
abstract
Modern wireless communication networks are threatened by new generations of radio hackers. These are skilled attackers equipped with low-cost software radios, suitably instrumented so as to monitor, degrade, or even alter the radio signals. The aim of this paper is to devise innovative detection architectures against the most common classes of threats: broadband noise jammers, whose goal is to reduce the signal-to-noise ratio, and spoofing/meaconing attacks, which aim to inject false or incorrect information into the receiver. To this end, we resort to the hypothesis testing theory and solve the associated problems by means of the GLRT possibly accounting for penalty terms. The resulting decision schemes represent the main technical novelty of this work. The analysis of their performance focuses on a location security case study for 4G/5G cellular networks. To this end, we leverage measurement models from the cellular localization literature and generate data according to these models. The numerical results show the effectiveness of the proposed approaches in comparison with suitable counterparts.
Danilo Orlando, Stefania Bartoletti, Ivan Palamà, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
IEEE Trans. Wirel. Commun.3
2022 5G Positioning with SDR-based Open-source Platforms: Where do We Stand?
abstract
While GPS has traditionally been the primary positioning technology, 3GPP has more recently begun to include positioning services as native, built-in features of future-generation cellular networks. With Release 16 of the 3GPP, finalized in 2021, a significant standardization effort has taken place for positioning in 5G networks, especially in terms of physical layer signals, measurements, schemes, and architecture to meet the requirements of a wide range of regulatory, commercial and industrial use cases. However, experimentally-driven research aiming to assess the real-world performance of 5G positioning is still lagging behind, root causes being i) the slow integration of positioning technologies in open-source 5G frameworks, ii) the complexity in setting up and properly configuring a 5G positioning testbed and iii) the cost of a multi-BS deployment. This paper sheds some light on all such aspects. After a brief overview of state of the art in 5G positioning and its support in open-source platforms based on software-defined radios, we provide advice on how to set-up positioning testbeds, and we demonstrate, via a set of real-world measurements, how to assess aspects such as reference signal configurations, localization algorithms, and network deployments, even with a cost-constrained limited-size testbed.
Ivan Palamà, Stefania Bartoletti, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
PEMWN1
2021 Location Security under Reference Signals' Spoofing Attacks: Threat Model and Bounds
abstract
Most localization systems rely on measurements gathered from signals emitted by stations whose position is assumed known as ground truth, namely anchors. As demonstrated by a significant bulk of experimental research, location security is threatened when an attacker becomes able to tamper either the signals emitted by the stations, or convince the user that the anchor station is in a different position than the true one. With this paper, we first propose a formal threat model which captures the above-mentioned wide class of attacks, and permits to quantitatively evaluate how tampering of one or more anchor locations undermines the user’s localization accuracy. We specifically derive a Cramér Rao Bound for the localization error, and we assess a number of example scenarios. We believe that our study may provide a useful formal benchmark for the design and analysis of detection and mitigation solutions.
Stefania Bartoletti, Giuseppe Bianchi 0001, Danilo Orlando, Ivan Palamà, Nicola Blefari-Melazzi
ARES4
2021 IMSI Catchers in the wild: A real world 4G/5G assessment
Ivan Palamà, Francesco Gringoli, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
Comput. Networks1