Stefania Bartoletti

dblp:16/10063 · DBLP profile ↗
← Back
21ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0003-1428-9776ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 4 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 2Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2026 Predictable and Exposed: Eavesdropping and Exploitation of Positioning Reference Signals
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
ICC5
2026 Practical Blind Full-Frame Replay Attacks on OFDM-Based ISAC Systems
abstract
Integrated Sensing and Communication (ISAC) systems promise unprecedented capabilities by merging connectivity and situational awareness, but also expose new attack surfaces at the physical layer. In this work, we demonstrate a blind full-frame OFDM replay attack that manipulates sensing outputs by injecting false targets and concealing real ones, without disrupting communication. The blind nature of our attack lies in the fact that it requires neither synchronization nor any knowledge of the signal structure, reference signals, or sensing parameters, making it not only practically viable, but even (somewhat) straightforward to execute. By replaying entire OFDM frames with a controlled delay and a frequency shift, the attacker can distort range estimations and induce Doppler shifts, mimicking the presence of moving targets. We present a general analytical framework to characterize the attack’s impact on range-Doppler processing and validate it through both system-level simulations with 5G NR parameters and real-world experiments. Experimental results build directly on a working 5G testbed with software-defined radios and commercial off-the-shelf hardware, which we extend with sensing capabilities, thereby demonstrating the attack’s feasibility and impact in a realistic ISAC scenario.
Stefania Bartoletti, Giulia Focarelli, Ivan Palamà, Samuele Zanini, Nicola Blefari-Melazzi, Giuseppe Bianchi 0001
IEEE J. Sel. Areas Commun.1
2026 Positioning Security in 5G and Beyond: Model and Detection of Physical Layer Threats
abstract
Accurate localization is an essential functionality of 5G and beyond systems to enable location-based applications, such as autonomous vehicles and emergency response. Nevertheless, the integrity of location data faces challenges not only from unintentional sources of error, such as wireless propagation impairments and synchronization failures but also from malicious and intentional threats, such as spoofing attacks. This paper specifically addresses the risk to localization integrity posed by malicious attacks. It provides a framework for modeling security threats at the physical layer of cellular positioning, with a focus on 5G and beyond systems. Two detection methods are proposed to mitigate the impact of spoofing attacks, by leveraging cross-correlation analysis and Gaussian Mixture Models (GMMs). These methods leverage standard metrics already defined in the localization procedure, thus eliminating the need for additional signal processing steps. Simulation results in 3GPP standard-compliant scenarios demonstrate the effectiveness of these methods in significantly reducing the integrity risk under attack conditions, thus providing a foundation for developing resilient mobile network location-based services.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
IEEE Trans. Wirel. Commun.5
2025 Experimental Viability of Full-Frame 5G Meaconing Attacks
abstract
This demo paper experimentally explores the feasibility of full-frame meaconing attacks in 5th generation (5G) systems, wherein adversaries stealthily manipulate time-of-arrival (ToA) measurements without disrupting ongoing communications. By intercepting, delaying, and amplifying the entire 5G frames, including critical positioning signals from the gNodeB (gNB), the attack injects a bias into the ToA estimation process, leading to significant positioning errors while leaving the communication service uninterrupted. Our evaluation, conducted on a comprehensive end-to-end 5G testbed built with commercial-off-the-shelf (COTS) and Software-Defined Radio (SDR) devices, includes real-time monitoring of key performance metrics such as reference signal received power (RSRP) and signal to interference and noise ratio (SINR). The experimental results highlight a critical physical-layer vulnerability in 5G positioning, underscoring the urgent need for robust countermeasures to safeguard network integrity.
Samuele Zanini, Giulia Focarelli, Ivan Palamà, Alessandro Rivitti, Giuseppe Bianchi 0001, Stefania Bartoletti
WCNC6
2025 WIP: Parrots in the Air: Experimental Validation of Full-Frame Meaconing in 5G Systems
abstract
While extensively studied in Global Positioning Systems, meaconing—i.e., the delay, amplification, and replay of a signal—is often regarded as impractical in cellular positioning systems due to the potential risk of communication disruption. We challenge this belief by experimentally validating full-frame meaconing attacks on 5G systems. Using off-the-shelf hardware, we demonstrate how an attacker can replay entire 5G frames, introducing o(μs) controlled TOA biases while maintaining uninterrupted communication. Our findings reveal the real world viability of these attacks, highlighting the urgent need for robust countermeasures to protect 5G localization systems.
Giulia Focarelli, Samuele Zanini, Ivan Palamà, Alessandro Rivitti, Stefania Bartoletti, Giuseppe Bianchi 0001
WoWMoM5
2025 Localization in 5G and Beyond: A Multi-Objective Approach for Accuracy, Latency, and Resilience
abstract
The integration of localization capabilities within the cellular architecture through dedicated 5G network functions has notably enhanced cellular positioning accuracy and enabled new location-based services. However, this architectural shift requires placing measurement acquisition and computation at the network edge and core, resulting in distributed computational resources and increased latency and security risks. As a result, minimizing latency and ensuring resilience against security threats, in addition to achieving high accuracy, become critical performance indicators in location-based services. This paper examines both 3GPP-standardized and O-RAN-based 5G architectures, detailing the key functions, interfaces, and parameters influencing the localization process, from measurement acquisition to position estimation. We define performance indicators for evaluating localization services and develop a system model that quantifies costs related to latency, accuracy, computation, and resilience against security threats. By jointly considering these factors, we formulate a multi-objective optimization problem that guides the selection of an optimal system configuration to simultaneously satisfy multiple localization requirements. We validate our approach through a case study of an end-to-end 5G system using both simulations and experimental data. Specifically, we evaluate various algorithms and implementations across standardized channels and scenarios. Furthermore, we conduct experimental measurements using Software-Defined Radios (SDRs) and open-source 5G platforms to assess operational latency with commercial-off-the-shelf (COTS) devices.
Luca Petrucci, Samuele Zanini, Ivan Palamà, Nicola Blefari-Melazzi, Stefania Bartoletti
IEEE Trans. Mob. Comput.5
2025 Efficient Localization via Soft Information With Generic Sensing Measurements
abstract
Accurate location awareness is essential for various context-based applications. This calls for efficient methodologies to collect, communicate and process position-dependent measurements, especially in situations with limited computational resources. The soft information (SI) approach has recently shown significant improvements in accuracy over conventional localization methods. By developing efficient SI-based techniques, it is possible to achieve higher precision also in case of stringent computational constraints. This paper proposes new SI-based localization techniques that utilize belief condensation and maximum entropy methods to reduce both communication burden and computational complexity. In addition, the techniques presented enable the use of generic sensing measurements, including those taking discrete and categorical values. Through two case studies involving time and angle measurements, we demonstrate how the proposed approach can significantly improve localization accuracy and computational efficiency.
Stefania Bartoletti, Santiago Mazuelas, Andrea Conti 0001, Moe Z. Win
IEEE Trans. Wirel. Commun.1
2024 Towards End-to-end Implementation of 5G Positioning with Off-the-shelf Devices
abstract
Despite extensive research and standardization efforts aimed at developing and enhancing 5G localization services, a significant gap persists between theoretical findings and experimental deployments, impeding the validation of key results in real-world operational settings. This paper contributes to fill this gap by proposing an End-to-End (E2E) implementation of a 5G localization system to explore the existing support of commercial off-the-shelf (COTS) user devices and existing RAN solutions for the localization functionality. To this end, we first develop a standard-compliant implementation of the location management function (LMF), i.e., the standard network function responsible for managing location information in the 5G core network. Then, we integrate the LMF with open-source core networks to conduct comprehensive testing on a suite of COTS user equipments and existing 5G RAN solutions, comparing commercial with open-source alternatives. By documenting encountered limitations and releasing our LMF software implementation as open-source, our work significantly contributes to the advancement of 5G localization research and testing in real environments and advocates for increased experiment-readiness in 5G positioning systems.
Samuele Zanini, Luca Petrucci, Ivan Palamà, Giuseppe Bianchi 0001, Stefania Bartoletti
VTC Fall5
2024 5G positioning with software-defined radios
abstract
Positioning is a key focus in 5G standardization, starting with 3GPP Release 16. However, most of the effort from the research community and work presented in the technical standardization has been limited mainly to simulation studies. This paper explores the use of software-defined radios (SDRs) platforms for 5G positioning, presenting an overview of the current state-of-the-art and available open-source platforms. Utilizing an advanced SDR-based multi-gNodeBs (gNBs) synchronized testbed, the paper conducts a series of time-based, over-the-air measurements. Results offer insights into the impact of various real-world system parameters, such as the number of gNBs, transmission bandwidth, signal processing techniques, and localization algorithms on positioning accuracy and Time to First Fix (TTFF). These findings provide a pathway for the cost-effective and efficient implementation of high-precision 5G localization systems. The paper contributes to advancing both theoretical understanding and practical applications, serving as a guide for the development of 5G positioning technology.
Ivan Palamà, Yago Lizarribar 0001, Lorenzo Maria Monteforte, Giuseppe Santaromita, Stefania Bartoletti, Domenico Giustiniano, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
Comput. Networks5
2024 Dominance of Smartphone Exposure in 5G Mobile Networks
abstract
The deployment of 5G networks is sometimes questioned due to the impact of ElectroMagnetic Field (EMF) generated by Radio Base Station (RBS) on users. The goal of this work is to analyze such issue from a novel perspective, by comparing RBS EMF against exposure generated by 5G smartphones in commercial deployments. The measurement of exposure from 5G is hampered by several implementation aspects, such as dual connectivity between 4G and 5G, spectrum fragmentation, and carrier aggregation. To face such issues, we deploy a novel framework, called5G-EA, tailored to the assessment of smartphone and RBS exposure through an innovative measurement algorithm, able to remotely control a programmable spectrum analyzer. Results, obtained in both outdoor and indoor locations, reveal that smartphone exposure (upon generation of uplink traffic) dominates over the RBS one. Moreover, Line-of-Sight locations experience a reduction of around one order of magnitude on the overall exposure compared to Non-Line-of-Sight ones. In addition, 5G exposure always represents a small share (up to 38%) compared to the total one radiated by the smartphone.
Luca Chiaraviglio, Chiara Lodovisi, Stefania Bartoletti, Ahmed Elzanaty, Mohamed-Slim Alouini
IEEE Trans. Mob. Comput.3
2023 Innovative Attack Detection Solutions for Wireless Networks With Application to Location Security
abstract
Modern wireless communication networks are threatened by new generations of radio hackers. These are skilled attackers equipped with low-cost software radios, suitably instrumented so as to monitor, degrade, or even alter the radio signals. The aim of this paper is to devise innovative detection architectures against the most common classes of threats: broadband noise jammers, whose goal is to reduce the signal-to-noise ratio, and spoofing/meaconing attacks, which aim to inject false or incorrect information into the receiver. To this end, we resort to the hypothesis testing theory and solve the associated problems by means of the GLRT possibly accounting for penalty terms. The resulting decision schemes represent the main technical novelty of this work. The analysis of their performance focuses on a location security case study for 4G/5G cellular networks. To this end, we leverage measurement models from the cellular localization literature and generate data according to these models. The numerical results show the effectiveness of the proposed approaches in comparison with suitable counterparts.
Danilo Orlando, Stefania Bartoletti, Ivan Palamà, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
IEEE Trans. Wirel. Commun.2
2022 5G Positioning with SDR-based Open-source Platforms: Where do We Stand?
abstract
While GPS has traditionally been the primary positioning technology, 3GPP has more recently begun to include positioning services as native, built-in features of future-generation cellular networks. With Release 16 of the 3GPP, finalized in 2021, a significant standardization effort has taken place for positioning in 5G networks, especially in terms of physical layer signals, measurements, schemes, and architecture to meet the requirements of a wide range of regulatory, commercial and industrial use cases. However, experimentally-driven research aiming to assess the real-world performance of 5G positioning is still lagging behind, root causes being i) the slow integration of positioning technologies in open-source 5G frameworks, ii) the complexity in setting up and properly configuring a 5G positioning testbed and iii) the cost of a multi-BS deployment. This paper sheds some light on all such aspects. After a brief overview of state of the art in 5G positioning and its support in open-source platforms based on software-defined radios, we provide advice on how to set-up positioning testbeds, and we demonstrate, via a set of real-world measurements, how to assess aspects such as reference signal configurations, localization algorithms, and network deployments, even with a cost-constrained limited-size testbed.
Ivan Palamà, Stefania Bartoletti, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
PEMWN2
2022 Enhancing the 5G-V2X Sidelink Autonomous Mode through Full-Duplex Capabilities
abstract
Efforts are underway to finalize the fifth generation (5G) vehicle-to-everything (V2X) communication technology. Direct communication among vehicles over the sidelink interface through the autonomous selection of radio resources is among the main and more challenging capabilities of such a connectivity solution. Nonetheless the crucial enhancements conceived by the Third Generation Partnership Project (3GPP) in Release 16, the autonomous resource allocation (a.k. a. Mode 2) still suffers from collisions due to the wrong estimation of the resource occupancy status enforced by half-duplex (HD) transceivers. In this paper, we argue in favour of the usage in vehicles of in-band full-duplex (FD) transceivers, gaining momentum in the research towards sixth generation (6G) systems thanks to their simultaneous transmission and reception capability. Exploiting FD, we propose to enhance the autonomous mode by detecting collisions and triggering resource reselection procedures in a more conscious manner. Simulation results show that the conceived proposal allows sidelink V2X to achieve significant improvements in terms of reliability and timeliness when compared against the legacy Mode 2.
Claudia Campolo, Alessandro Bazzi, Vittorio Todisco, Stefania Bartoletti, Nicolò Decarli, Antonella Molinaro, Antoine O. Berthet, Richard A. Stirling-Gallacher
VTC Spring4
2021 Location Security under Reference Signals' Spoofing Attacks: Threat Model and Bounds
abstract
Most localization systems rely on measurements gathered from signals emitted by stations whose position is assumed known as ground truth, namely anchors. As demonstrated by a significant bulk of experimental research, location security is threatened when an attacker becomes able to tamper either the signals emitted by the stations, or convince the user that the anchor station is in a different position than the true one. With this paper, we first propose a formal threat model which captures the above-mentioned wide class of attacks, and permits to quantitatively evaluate how tampering of one or more anchor locations undermines the user’s localization accuracy. We specifically derive a Cramér Rao Bound for the localization error, and we assess a number of example scenarios. We believe that our study may provide a useful formal benchmark for the design and analysis of detection and mitigation solutions.
Stefania Bartoletti, Giuseppe Bianchi 0001, Danilo Orlando, Ivan Palamà, Nicola Blefari-Melazzi
ARES1
2021 On the Performance of the IEEE 802.11p/bd Sensing Procedure Under Co-channel C-V2X Interference
abstract
On the path towards fully connected and automated vehicles, two sets of technologies are under consideration for enabling short-range vehicle-to-everything (V2X) communications within the intelligent transport system (ITS) band around 5.9 GHz. The first group of technologies includes IEEE 802.11p plus its upcoming evolution IEEE 802.11bd. The second group includes the 3rd generation partnership project (3GPP)-defined sidelink cellular-V2X (C-V2X) standards. However, the coexistence of these technologies and the resulting interference pose new challenges for guaranteeing reliable operation in emerging vehicular networks. In this work, we investigate the impact of the interference resulting from C-V2X transmission on the sensing procedure of IEEE 802.11p/bd. To this end, we develop a detection framework based on clear channel assessment (CCA) mechanism in the IEEE 802.//p/bd network under the assumption of Rayleigh distribution channel fading; where we employed stochastic geometry and the characteristic function approach. It is shown through analytical evaluations that a lower threshold than the one defined in the specifications could better cope with the received interference without sensibly increasing the impact of false alarms.
Babak Mafakheri, Stefania Bartoletti, Omid Semiari, Alessandro Bazzi
VTC Fall2
2019 Soft Information for Localization-of-Things
abstract
Location awareness is vital for emerging Internet-of-Things applications and opens a new era for Localization-of-Things. This paper first reviews the classical localization techniques based on single-value metrics, such as range and angle estimates, and on fixed measurement models, such as Gaussian distributions with mean equal to the true value of the metric. Then, it presents a new localization approach based on soft information (SI) extracted from intra- and inter-node measurements, as well as from contextual data. In particular, efficient techniques for learning and fusing different kinds of SI are described. Case studies are presented for two scenarios in which sensing measurements are based on: 1) noisy features and non-line-of-sight detector outputs and 2) IEEE 802.15.4a standard. The results show that SI-based localization is highly efficient, can significantly outperform classical techniques, and provides robustness to harsh propagation conditions.
Andrea Conti 0001, Santiago Mazuelas, Stefania Bartoletti, William C. Lindsey, Moe Z. Win
Proc. IEEE3
2019 Scanning the Issue
abstract
The month’s regular papers issue covers machine learning at the wireless network edge, soft-informationbased localization techniques, and Antenna-in-Package technology.
Jihong Park, Sumudu Samarakoon, Mehdi Bennis, Mérouane Debbah, Andrea Conti 0001, Santiago Mazuelas, Stefania Bartoletti, William C. Lindsey, Moe Z. Win, Yueping Zhang, Peter M. Grant, John S. Thompson
Proc. IEEE7
2018 Threshold Profiling for Wideband Ranging
abstract
This letter establishes a methodology to design threshold profiles for wideband ranging systems. Differently from conventional methods using a single threshold value that is designed based on the signal detection and false-alarm probability requirements, we propose a threshold profile that is designed based also on the ranging error requirement. The proposed method relies only on channel statistics without requiring channel estimation. A case study shows that, compared to conventional methods, the proposed method for threshold profiling significantly improves the performance in terms of false-alarm probability, detection probability, and ranging error.
Stefania Bartoletti, Andrea Conti 0001, Wenhan Dai, Moe Z. Win
IEEE Signal Process. Lett.1
2017 Device-Free Counting via Wideband Signals
abstract
Counting people and things (targets) in a monitored area, also known as crowd-counting, enables several applications in diverse scenarios, including smart building, intelligent transportation, and public safety. In many scenarios, device-free systems relying on the signal backscattering from targets are preferred to device-based systems relying on the communication with the targets via dedicated or personal devices. However, the use of conventional radar techniques (e.g., for multi-target detection) requires us to associate a different set of measured data with each detected target. Data association is a redundant operation for counting and results in high complexity even with few targets. The need of lower dimensionality and complexity calls for signal features to associate the measured signals directly with the number of targets. This paper proposes a mathematical framework for the design of device-free counting systems. First, a maximum a posteriori algorithm is developed for counting via wideband signal backscattering by relying on model order selection. Then, a method that relies on low-level features is proposed to lower the computational complexity. The proposed method is verified via sample-level simulations in realistic operating conditions and compared with current solutions.
Stefania Bartoletti, Andrea Conti 0001, Moe Z. Win
IEEE J. Sel. Areas Commun.1
2014 Detection of Multiple Tags Based on Impulsive Backscattered Signals
abstract
Passive and semipassive ultrawideband (UWB) radio-frequency identification (RFID) technology has been recently proposed to offer high-accuracy localization capabilities in next-generation RFID systems. This technology relies on the modulation of backscattered signals, i.e., backscatter modulation, from multiple tags present in the environment. The detection of multiple tags based on backscattered signals is challenging in harsh environments with nonideal conditions such as clutter, near-far interference effects, and clock drift. This paper analyzes the detection of multiple tags employing UWB backscatter modulation and proposes practical signaling, spreading codes, and detection schemes that are robust to nonideal conditions. A case study is presented to evaluate the performance of the proposed technique for the detection of multiple tags based on impulsive backscattered signals.
Francesco Guidi, Nicolò Decarli, Stefania Bartoletti, Andrea Conti 0001, Davide Dardari
IEEE Trans. Commun.3
2010 Analysis of UWB Radar Sensor Networks
abstract
Radar sensor networks (RSNs) are gaining importance in the context of passive localization and tracking. The performance of RSNs is affected by disturbances, system's parameters, network topology, and the number of radar elements. In this paper, we derive a unified analytical framework that takes all this aspects into account and allows the derivation of probability of detection and localization uncertainty. The results enable the system designer to have a clear understanding on the effects of each system parameter and the trade-off between performance and complexity. Moreover, the potential for high-accuracy passive localization of ultrawide bandwidth (UWB) systems is shown.
Stefania Bartoletti, Andrea Conti 0001, Andrea Giorgetti
ICC1