Giulia Focarelli

dblp:299/0883 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0002-0240-7827ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Predictable and Exposed: Eavesdropping and Exploitation of Positioning Reference Signals
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
ICC2
2026 Practical Blind Full-Frame Replay Attacks on OFDM-Based ISAC Systems
abstract
Integrated Sensing and Communication (ISAC) systems promise unprecedented capabilities by merging connectivity and situational awareness, but also expose new attack surfaces at the physical layer. In this work, we demonstrate a blind full-frame OFDM replay attack that manipulates sensing outputs by injecting false targets and concealing real ones, without disrupting communication. The blind nature of our attack lies in the fact that it requires neither synchronization nor any knowledge of the signal structure, reference signals, or sensing parameters, making it not only practically viable, but even (somewhat) straightforward to execute. By replaying entire OFDM frames with a controlled delay and a frequency shift, the attacker can distort range estimations and induce Doppler shifts, mimicking the presence of moving targets. We present a general analytical framework to characterize the attack’s impact on range-Doppler processing and validate it through both system-level simulations with 5G NR parameters and real-world experiments. Experimental results build directly on a working 5G testbed with software-defined radios and commercial off-the-shelf hardware, which we extend with sensing capabilities, thereby demonstrating the attack’s feasibility and impact in a realistic ISAC scenario.
Stefania Bartoletti, Giulia Focarelli, Ivan Palamà, Samuele Zanini, Nicola Blefari-Melazzi, Giuseppe Bianchi 0001
IEEE J. Sel. Areas Commun.2
2026 Positioning Security in 5G and Beyond: Model and Detection of Physical Layer Threats
abstract
Accurate localization is an essential functionality of 5G and beyond systems to enable location-based applications, such as autonomous vehicles and emergency response. Nevertheless, the integrity of location data faces challenges not only from unintentional sources of error, such as wireless propagation impairments and synchronization failures but also from malicious and intentional threats, such as spoofing attacks. This paper specifically addresses the risk to localization integrity posed by malicious attacks. It provides a framework for modeling security threats at the physical layer of cellular positioning, with a focus on 5G and beyond systems. Two detection methods are proposed to mitigate the impact of spoofing attacks, by leveraging cross-correlation analysis and Gaussian Mixture Models (GMMs). These methods leverage standard metrics already defined in the localization procedure, thus eliminating the need for additional signal processing steps. Simulation results in 3GPP standard-compliant scenarios demonstrate the effectiveness of these methods in significantly reducing the integrity risk under attack conditions, thus providing a foundation for developing resilient mobile network location-based services.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
IEEE Trans. Wirel. Commun.1
2025 Experimental Viability of Full-Frame 5G Meaconing Attacks
abstract
This demo paper experimentally explores the feasibility of full-frame meaconing attacks in 5th generation (5G) systems, wherein adversaries stealthily manipulate time-of-arrival (ToA) measurements without disrupting ongoing communications. By intercepting, delaying, and amplifying the entire 5G frames, including critical positioning signals from the gNodeB (gNB), the attack injects a bias into the ToA estimation process, leading to significant positioning errors while leaving the communication service uninterrupted. Our evaluation, conducted on a comprehensive end-to-end 5G testbed built with commercial-off-the-shelf (COTS) and Software-Defined Radio (SDR) devices, includes real-time monitoring of key performance metrics such as reference signal received power (RSRP) and signal to interference and noise ratio (SINR). The experimental results highlight a critical physical-layer vulnerability in 5G positioning, underscoring the urgent need for robust countermeasures to safeguard network integrity.
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Alessandro Rivitti, Giuseppe Bianchi 0001, Stefania Bartoletti
WCNC2
2025 WIP: Parrots in the Air: Experimental Validation of Full-Frame Meaconing in 5G Systems
abstract
While extensively studied in Global Positioning Systems, meaconing—i.e., the delay, amplification, and replay of a signal—is often regarded as impractical in cellular positioning systems due to the potential risk of communication disruption. We challenge this belief by experimentally validating full-frame meaconing attacks on 5G systems. Using off-the-shelf hardware, we demonstrate how an attacker can replay entire 5G frames, introducing o(μs) controlled TOA biases while maintaining uninterrupted communication. Our findings reveal the real world viability of these attacks, highlighting the urgent need for robust countermeasures to protect 5G localization systems.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Alessandro Rivitti, Stefania Bartoletti, Giuseppe Bianchi 0001
WoWMoM1