VLDB 2026 Research / reviewers in the wild / expert
Samuele Zanini
dblp:383/6299
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0009-0007-7655-3313ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 2 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Predictable and Exposed: Eavesdropping and Exploitation of Positioning Reference Signals
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti |
ICC | 1 |
| 2026 | Practical Blind Full-Frame Replay Attacks on OFDM-Based ISAC SystemsabstractIntegrated Sensing and Communication (ISAC) systems promise unprecedented capabilities by merging connectivity and situational awareness, but also expose new attack surfaces at the physical layer. In this work, we demonstrate a blind full-frame OFDM replay attack that manipulates sensing outputs by injecting false targets and concealing real ones, without disrupting communication. The blind nature of our attack lies in the fact that it requires neither synchronization nor any knowledge of the signal structure, reference signals, or sensing parameters, making it not only practically viable, but even (somewhat) straightforward to execute. By replaying entire OFDM frames with a controlled delay and a frequency shift, the attacker can distort range estimations and induce Doppler shifts, mimicking the presence of moving targets. We present a general analytical framework to characterize the attack’s impact on range-Doppler processing and validate it through both system-level simulations with 5G NR parameters and real-world experiments. Experimental results build directly on a working 5G testbed with software-defined radios and commercial off-the-shelf hardware, which we extend with sensing capabilities, thereby demonstrating the attack’s feasibility and impact in a realistic ISAC scenario. Stefania Bartoletti, Giulia Focarelli, Ivan Palamà, Samuele Zanini, Nicola Blefari-Melazzi, Giuseppe Bianchi 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2026 | Positioning Security in 5G and Beyond: Model and Detection of Physical Layer ThreatsabstractAccurate localization is an essential functionality of 5G and beyond systems to enable location-based applications, such as autonomous vehicles and emergency response. Nevertheless, the integrity of location data faces challenges not only from unintentional sources of error, such as wireless propagation impairments and synchronization failures but also from malicious and intentional threats, such as spoofing attacks. This paper specifically addresses the risk to localization integrity posed by malicious attacks. It provides a framework for modeling security threats at the physical layer of cellular positioning, with a focus on 5G and beyond systems. Two detection methods are proposed to mitigate the impact of spoofing attacks, by leveraging cross-correlation analysis and Gaussian Mixture Models (GMMs). These methods leverage standard metrics already defined in the localization procedure, thus eliminating the need for additional signal processing steps. Simulation results in 3GPP standard-compliant scenarios demonstrate the effectiveness of these methods in significantly reducing the integrity risk under attack conditions, thus providing a foundation for developing resilient mobile network location-based services. Giulia Focarelli, Samuele Zanini, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti |
IEEE Trans. Wirel. Commun. | 2 |
| 2025 | Experimental Viability of Full-Frame 5G Meaconing AttacksabstractThis demo paper experimentally explores the feasibility of full-frame meaconing attacks in 5th generation (5G) systems, wherein adversaries stealthily manipulate time-of-arrival (ToA) measurements without disrupting ongoing communications. By intercepting, delaying, and amplifying the entire 5G frames, including critical positioning signals from the gNodeB (gNB), the attack injects a bias into the ToA estimation process, leading to significant positioning errors while leaving the communication service uninterrupted. Our evaluation, conducted on a comprehensive end-to-end 5G testbed built with commercial-off-the-shelf (COTS) and Software-Defined Radio (SDR) devices, includes real-time monitoring of key performance metrics such as reference signal received power (RSRP) and signal to interference and noise ratio (SINR). The experimental results highlight a critical physical-layer vulnerability in 5G positioning, underscoring the urgent need for robust countermeasures to safeguard network integrity. Samuele Zanini, Giulia Focarelli, Ivan Palamà, Alessandro Rivitti, Giuseppe Bianchi 0001, Stefania Bartoletti |
WCNC | 1 |
| 2025 | WIP: Parrots in the Air: Experimental Validation of Full-Frame Meaconing in 5G SystemsabstractWhile extensively studied in Global Positioning Systems, meaconing—i.e., the delay, amplification, and replay of a signal—is often regarded as impractical in cellular positioning systems due to the potential risk of communication disruption. We challenge this belief by experimentally validating full-frame meaconing attacks on 5G systems. Using off-the-shelf hardware, we demonstrate how an attacker can replay entire 5G frames, introducing o(μs) controlled TOA biases while maintaining uninterrupted communication. Our findings reveal the real world viability of these attacks, highlighting the urgent need for robust countermeasures to protect 5G localization systems. Giulia Focarelli, Samuele Zanini, Ivan Palamà, Alessandro Rivitti, Stefania Bartoletti, Giuseppe Bianchi 0001 |
WoWMoM | 2 |
| 2025 | Localization in 5G and Beyond: A Multi-Objective Approach for Accuracy, Latency, and ResilienceabstractThe integration of localization capabilities within the cellular architecture through dedicated 5G network functions has notably enhanced cellular positioning accuracy and enabled new location-based services. However, this architectural shift requires placing measurement acquisition and computation at the network edge and core, resulting in distributed computational resources and increased latency and security risks. As a result, minimizing latency and ensuring resilience against security threats, in addition to achieving high accuracy, become critical performance indicators in location-based services. This paper examines both 3GPP-standardized and O-RAN-based 5G architectures, detailing the key functions, interfaces, and parameters influencing the localization process, from measurement acquisition to position estimation. We define performance indicators for evaluating localization services and develop a system model that quantifies costs related to latency, accuracy, computation, and resilience against security threats. By jointly considering these factors, we formulate a multi-objective optimization problem that guides the selection of an optimal system configuration to simultaneously satisfy multiple localization requirements. We validate our approach through a case study of an end-to-end 5G system using both simulations and experimental data. Specifically, we evaluate various algorithms and implementations across standardized channels and scenarios. Furthermore, we conduct experimental measurements using Software-Defined Radios (SDRs) and open-source 5G platforms to assess operational latency with commercial-off-the-shelf (COTS) devices. Luca Petrucci, Samuele Zanini, Ivan Palamà, Nicola Blefari-Melazzi, Stefania Bartoletti |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Towards End-to-end Implementation of 5G Positioning with Off-the-shelf DevicesabstractDespite extensive research and standardization efforts aimed at developing and enhancing 5G localization services, a significant gap persists between theoretical findings and experimental deployments, impeding the validation of key results in real-world operational settings. This paper contributes to fill this gap by proposing an End-to-End (E2E) implementation of a 5G localization system to explore the existing support of commercial off-the-shelf (COTS) user devices and existing RAN solutions for the localization functionality. To this end, we first develop a standard-compliant implementation of the location management function (LMF), i.e., the standard network function responsible for managing location information in the 5G core network. Then, we integrate the LMF with open-source core networks to conduct comprehensive testing on a suite of COTS user equipments and existing 5G RAN solutions, comparing commercial with open-source alternatives. By documenting encountered limitations and releasing our LMF software implementation as open-source, our work significantly contributes to the advancement of 5G localization research and testing in real environments and advocates for increased experiment-readiness in 5G positioning systems. Samuele Zanini, Luca Petrucci, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti |
VTC Fall | 1 |