Tolga O. Atalay

dblp:320/8614 · DBLP profile ↗
← Back
20ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0002-9195-4007ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 6 first-author · 13 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Towards Securing Access Control in 5G and Beyond with Zero Trust
abstract
The Fifth Generation (5G) specifications have set a precedent for the evolution of next-generation mobile networks. Standardized interfaces and Network Function Virtualization (NFV) technology enable network operators to break free from vendor lock-in, while delivering more customized and agile services to their customers. However, the heterogeneous and multi-vendor composition of the Next-Generation Network (NGN), as envisioned in 5G specifications, also expands the existing attack surface and complicates trust relationships. Consequently, the traditional perimeter-based security model has become inadequate for effectively ensuring trust in such a complex network environment. On the other hand, Zero Trust has emerged as a promising security model well-suited for protecting complex and large-scale networks. Unfortunately, the current access control mechanism in the 5G core network lacks key features, rendering it incompatible with Zero Trust principles. To bridge this gap, we introduce the Continual Access Monitoring (CAM) framework that enables operators to seamlessly incorporate key security metrics into the existing access control mechanism. Furthermore, CAM introduces continual access policy evaluation, a critical requirement of the Zero Trust paradigm. The CAM framework illustrates a practical strategy for integrating Zero Trust principles into the 5G service-based architecture and scales efficiently in large 5G deployments, supporting access policy monitoring for up to 6,000 network functions at an operational cost of USD 0.2 per hour on AWS.
Sudip Maitra, Kenechukwu Nwodo, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
CODASPY3
2026 RAIDER: A Lightweight UAV-Based Relay Mesh and Edge VNF Framework for Tactical Connectivity
Tolga O. Atalay, Alireza Famili, Amirreza Ghafoori, Angelos Stavrou
ICC1
2026 SlicePilot: Demystifying Network Slice Placement in Heterogeneous Cloud Infrastructures
Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas
INFOCOM2
2026 5GC-Bench: A Framework for Stress-Testing and Benchmarking 5G Core VNFs
abstract
The disaggregated, cloud-native design of the 5G Core (5GC) enables flexibility and scalability but introduces significant challenges. Control-plane procedures involve complex interactions across multiple Virtual Network Functions (VNFs), while the user plane must sustain diverse and resource-intensive traffic. Existing tools often benchmark these dimensions in isolation, rely on synthetic workloads, or lack visibility into fine-grained resource usage. This paper presents 5GC-Bench, a modular framework for stress-testing the 5GC under realistic workloads. 5GC-Bench jointly emulates signaling and service traffic, supporting both VNF profiling and end-to-end service-chain analysis. By characterizing bottlenecks and resource demands, it provides actionable insights for capacity planning and performance optimization. We integrated 5GC-Bench with the OpenAirInterface (OAI) 5GC and deployed it on a real 5G testbed, demonstrating its ability to uncover resource constraints and expose cross-VNF dependencies under scenarios that mirror operational 5G deployments. To foster reproducibility and further research, we release publicly all the artifacts.
Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas
WCNC2
2025 5G-STREAM: Service Mesh Tailored for Reliable, Efficient and Authorized Microservices in the Cloud
abstract
Existing registration, discovery, and authorization mechanisms in the 5G core control plane present scalability and efficiency challenges. As cellular deployments scale to accommodate diverse user demands, the 5G core control plane suffers from increased inter-Virtual Network Function (VNF) communication latency, thus deteriorating the reliability of critical procedures. To address this problem, we propose 5G-STREAM (Service mesh Tailored for Reliable, Efficient, and Authorized Microservices) to optimize control plane traffic in distributed cloud environments by establishing a topology awareness of service chains across cloud hierarchies. Leveraging this awareness, 5G-STREAM dynamically configures communication pathways to reduce discovery and authorization signaling overhead, thus increasing the reliability of inter-VNF communication. We develop a prototype of 5G-STREAM and evaluate its performance. Our evaluation results show that 5G-STREAM significantly reduces the process completion time in core service chains by up to 2× inter VNF-Network Repository Function (NRF) latency per transaction, with more pronounced benefits in larger service chains. Furthermore, we show that the cost required to deploy 5G-STREAM is an additional 0.1 USD/hr on AWS for a VNF handling a sustained rate of 50,000 requests/minute.
Tolga O. Atalay, Alireza Famili, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
DSN1
2025 HEAL: Healthcare Robot Localization using Efficient Anchor Layout
Alireza Famili, Tolga O. Atalay, Angelos Stavrou
HealthCom2
2025 5G-MAP: Demystifying the Performance Implications of Cloud-Based 5G Core Deployments
abstract
The Fifth Generation (5G) core network is designed as a set of Virtual Network Functions (VNFs) hosted on Commercial-Off-the-Shelf (COTS) hardware. This creates a growing demand for general-purpose computing resources. Given their elastic infrastructure, cloud services like Amazon Web Services (AWS) are attractive platforms to address this need. Therefore, it is crucial to understand the Quality of Service (QoS) requirements associated with deploying the 5G core in the cloud. We developed the 5G-MAP (5G Measurement and Assessment Platform) to understand the trade-offs between different deployment strategies. Our framework facilitates detailed control and user plane performance assessments in varied deployment scenarios. We integrated 5G-MAP with the OpenAirInterface (OAI) 5G core and utilized it in a series of deployments across seven countries, leveraging eight AWS regions and eighteen edge zones. Our evaluations cover from HTTP transactions to user plane throughput and packet loss. We identify topologies that can considerably lower the 5G core service chain latencies due to a significant reduction in the number of inter-site hops. Such actionable performance improvements illustrate how operators can leverage 5G-MAP to optimize their cloud-based 5G deployments.
Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001
MobiCom1
2025 Precise Positioning for Healthcare Robotics with Retroreflective Tags in 5G Small Cell Networks
Alireza Famili, Tolga O. Atalay, Angelos Stavrou
Networking2
2025 Enhancing Secure Communication: Deep Q-Learning for Location-Based Authentication
abstract
In the evolving landscape of next-generation wireless networks, ensuring secure communications in covert military operations is paramount. This paper proposes an advanced localization-based security system utilizing passive receivers and Time Difference of Arrival (TDOA) techniques to continuously authenticate the signals of a commander in dynamic operational scenarios. Our system effectively counters physical layer spoofing attacks by distinguishing between the precise locations of a legitimate entity and potential adversaries. To that end, we derive the positioning error bound (PEB) specific to TDOA systems, emphasizing the critical impact of receiver arrangement on localization accuracy. Furthermore, we introduce a novel application of deep Q-learning for the NP-hard problem of optimal placement of receivers, addressing the challenge of spatial geometry, which significantly influences localization accuracy. Through extensive testing, we demonstrate that our proposed approach notably outperforms traditional placement methods in mitigating geometry-induced errors and enhancing overall localization precision. Ultimately, this facilitates realizing and maintaining a secure zone where users can authenticate each other through localization.
Alireza Famili, Shihua Sun, Tolga O. Atalay, Angelos Stavrou
NOMS3
2025 An OpenRAN Security Framework for Scalable Authentication, Authorization, and Discovery of xApps With Isolated Critical Services
abstract
The OpenRAN initiative promotes an open Radio Access Network (RAN) and offers operators fine-grained control over the radio stack. To that end, O-RAN introduces new components to the 5G ecosystem, such as the near real-time RAN Intelligent Controller (near-RT RIC) and the accompanying extensible Applications (xApps). The introduction of these entities expands the 5G threat surface. Furthermore, with the movement from proprietary hardware to virtual environments enabled by Network Functions Virtualization (NFV), attack vectors that exploit the existing NFV attack surface pose additional threats. To deal with these threats, we propose the xApp repository function (XRF) framework for scalable authentication, authorization, and discovery of xApps. To harden the XRF microservices, we isolate them using Intel Software Guard Extensions (SGX). We benchmark the XRF modules individually and compare how different microservices behave in terms of computational overhead when deployed in virtual and hardware-based isolation sandboxes. Our evaluation shows that the XRF framework scales efficiently in a multi-threaded Kubernetes environment. The isolation of the XRF microservices introduces different amounts of processing overhead depending on the sandboxing strategy. Finally, a security analysis is conducted to show how the XRF framework addresses chosen key issues from the O-RAN and 5G standardization efforts.
Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Towards Shielding 5G Control Plane Functions
abstract
Network Functions Virtualization (NFV) enables flexible and scalable 5G core deployment but it also introduces new attack vectors into the mobile network ecosystem, especially when network functions are deployed on public cloud infrastructure. To address this issue, Third Generation Partnership Project (3GPP) standardization body recommends isolating critical 5G core functionalities inside Hardware Mediated Execution Enclaves (HMEEs). However, the use of HMEEs can incur debilitating QoS degradation in control plane functions including Authentication and Key Agreement (AKA) protocol. In this paper, we design and implement network slices with HMEE-enforced isolation for sensitive AKA functions and characterize their performance. Our findings reveal that the use of HMEE leads to 1.2 to 1.5× increase in function execution time and 2.2 to 2.9× increase in response time for the isolated containers. While appearing very large, this overhead is a small fraction of the end-to-end session setup latency. To evaluate the feasibility of HMEE, we use a real commercial User Equipment (UE) to register with the 5G core network through the isolated AKA functions. Finally, we discuss the role of HMEEs in addressing the key issues introduced by NFV.
Sudip Maitra, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
DSN2
2024 RAPID: Reinforcement Learning-Aided Femtocell Placement for Indoor Drone Localization
abstract
Mobile networks are swiftly advancing to accommodate the burgeoning spectrum of applications. The architecture of 5G networks integrates the principle of network slices, logically isolated end-to-end segments tailored to offer specific services. In this architectural schema, drones have emerged as a significant service category. Achieving the successful deployment of drone networks is heavily contingent upon the ability to accurately localize them in a three-dimensional (3D) setting, beyond the critical requirement for tight latency control. Transitioning from 4G to 5G, these networks are characterized by their operation at elevated frequency spectrums and more densely packed deployment configurations. Within such environments, the task of ensuring precise indoor localization poses a significant challenge, primarily due to the distinctive signal behavior at higher frequencies. To achieve this goal, we propose the RAPID framework, utilizing foundational principles from the third-generation partnership project (3GPP) to design a radio access network (RAN) that includes 5G femtocells. This architecture aims to shift positioning responsibilities from outdoor base stations (BSs) to improve indoor localization performance. Our study’s principal contribution is the demonstration of how the spatial distribution of 5G femtocells significantly influences the accuracy of drone positioning. To address the challenges inherent in femtocell deployment, we develop an innovative optimization framework coupled with a deep reinforcement learning (DRL) strategy, aimed at solving the NP-hard problem. Our findings reveal that adopting our DRL-based placement strategy significantly improves positioning accuracy compared to regular arbitrary deployment approaches.
Alireza Famili, Amin Tabrizian, Tolga O. Atalay, Angelos Stavrou
ICCCN3
2024 5G-WAVE: A Core Network Framework with Decentralized Authorization for Network Slices
abstract
5G mobile networks leverage Network Function Virtualization (NFV) to offer services in the form of network slices. Each network slice is a logically isolated fragment constructed by service chaining a set of Virtual Network Functions (VNFs). The Network Repository Function (NRF) acts as a central OpenAuthorization (OAuth) 2.0 server to secure inter-VNF communications resulting in a single point of failure. Thus, we propose 5G-WAVE, a decentralized authorization framework for the 5G core by leveraging the WAVE framework and integrating it into the OpenAirInterface (OAI) 5G core. Our design relies on Side-Car Proxies (SCPs) deployed alongside individual VNFs, allowing point-to-point authorization. Each SCP acts as a WAVE engine to create entities and attestations and verify incoming service requests. We measure the authorization latency overhead for VNF registration, 5G Authentication and Key Agreement (AKA), and data session setup and observe that WAVE verification introduces 155ms overhead to HTTP transactions for decentralizing authorization. Additionally, we evaluate the scalability of 5G-WAVE by instantiating more network slices to observe 1.4x increase in latency with 10x growth in network size. We also discuss how 5G-WAVE can significantly reduce the 5G attack surface without using OAuth 2.0 while addressing several key issues of 5G standardization.
Tolga O. Atalay, Hans-Andrew Gibbs, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
INFOCOM2
2024 Precision Tracking in Geofencing Systems using Deep Reinforcement Learning
abstract
Geofencing technologies have emerged as crucial tools in establishing virtual boundaries within both physical and digital spaces, providing a secure method to manage and supervise specified zones. They are now recognized as vital instruments for delineating and managing boundaries in a range of applications, from ensuring aviation safety in drone operations to regulating access in mixed reality environments such as the metaverse. Successful geofencing depends significantly on accurate tracking, which is essential for preserving the integrity and effectiveness of these systems. Utilizing the benefits of 5G technology, such as its broad bandwidth and widespread availability, offers a promising approach to improve geofencing performance. In this paper, we present DEFENCE: Deep Reinforcement Learning for Geofencing Enhancement, an innovative method for precise geofencing that utilizes "5G Points" within indoor 5G small cell networks, optimally placed using a deep Q-learning framework. Through the computation of the Cramér-Rao Lower Bound (CRLB), we evaluate tracking errors arising from spatial configurations and ranging inaccuracies. Our proposed deep Q-learning model tackles the NP-hard challenge of identifying the optimal placement of 5G Points to reduce errors caused by spatial geometry. We implemented an extensive testing campaign to assess the efficacy of DEFENCE. Our findings reveal that this strategic deployment enhances tracking accuracy by a factor of 100 over conventional placement methods. This breakthrough considerably bolsters geofencing systems, enhancing their defense against potential threats such as unauthorized drone incursions and security breaches within metaverse environments.
Alireza Famili, Shihua Sun, Tolga O. Atalay, Angelos Stavrou
IPCCC3
2023 Demystifying 5G Traffic Patterns with an Indoor RAN Measurement Campaign
abstract
The deployment of commercial 5G network is gaining momentum while research is already moving towards more advanced features. Currently, the lack of an easy-to-construct, open-source testbed that can support commercial off-the-shelf (COTS) devices has hindered academic research. In this paper, we build an open-source over-the-air testbed leveraging advanced features of 5G radio access and core networks developed by the OpenAirInterface (OAI) project. We evaluate the quality of service (QoS) achievable using this testbed and provide visibility into the compute consumption of individual components. Additionally, we present a method to utilize WiFi devices for experimenting with 5G QoS. We collect resource consumption analytics from the 5G user plane in correlation to raw traffic patterns. Our results show that the OAI testbed sustains sub-20ms latency with up to 80Mbps throughput over a 25m range using COTS devices. Device connection remains stable while supporting different use cases such as AR/VR, online gaming, video streaming and voice over IP (VoIP). Finally, we illustrate how these popular use cases affect the CPU utilization in the user plane. This provides insight into the capabilities of existing 5G solutions by demystifying the resource needs of specific use cases. All our results can be recreated using COTS equipment.
Tolga O. Atalay, Alireza Famili, Dragoslav Stojadinovic, Angelos Stavrou
GLOBECOM1
2023 Securing 5G OpenRAN with a Scalable Authorization Framework for xApps
abstract
The ongoing transformation of mobile networks from proprietary physical network boxes to virtualized functions and deployment models has led to more scalable and flexible network architectures capable of adapting to specific use cases. As an enabler of this movement, the OpenRAN initiative promotes standardization allowing for a vendor-neutral radio access network with open APIs. Moreover, the O-RAN Alliance has begun specification efforts conforming to OpenRAN’s definitions. This includes the near-real-time RAN Intelligent Controller (RIC) overseeing a group of extensible applications (xApps). The use of these potentially untrusted third-party applications introduces a new attack surface to the mobile network plane with fundamental security and system design requirements that are yet to be addressed. To secure the 5G O-RAN xApp model, we introduce the xApp Repository Function (XRF) framework, which implements scalable authentication, authorization, and discovery for xApps. We first present the framework’s system design and implementation details, followed by operational benchmarks in a production-grade containerized environment. The evaluation results, centered on active processing and operation times, show that our proposed framework can scale efficiently in a multi-threaded Kubernetes microservice environment and support a large number of clients with minimal overhead.
Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
INFOCOM1
2023 Wi-Five: Optimal Placement of Wi-Fi Routers in 5G Networks for Indoor Drone Navigation
abstract
In the near future, unmanned aerial vehicles (UAVs) will be used to automate the logistics between organizations and their customers by relying on high accuracy localization. In this paper, we propose a framework that leverages the multi radio access technology (RAT) 5G network to solve the cellular positioning problem for such high mobility targets. For indoors, we utilize wireless fidelity (Wi-Fi) routers, denoted as Wi-Five dots, to improve positioning accuracy where the 5G signal is weaker compared with outdoor environments. These anchor points will use the 5G backhaul to report to the same location management function (LMF) as the cellular 5G access network. The primary contribution of this work is showing how the geometry of these indoor Wi-Five dots significantly affects positioning accuracy. Through a novel optimization algorithm based on the Evolutionary Algorithm (EA) class, we solve the NP-Hard problem of finding the optimal placement of Wi-Five dots for three-dimensional high-accuracy positioning of a mobile target. Our results show that the final positioning accuracy is the product of both the ranging errors and the geometric dilution of precision (GDOP). We experimentally verify that for the latter, the error stems primarily from the Z-axis estimations rather than the errors in the X − Y plane. Finally, we evaluate the results of our optimal placement to show it drastically improves positioning estimations in a three-dimensional space compared with arbitrary beacon placement.
Alireza Famili, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
VTC2023-Spring2
2023 OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs
abstract
The pursuit of high-accuracy localization without relying on the global positioning system (GPS) has gained significant interest in recent years. The deployment of autonomous vehicles (AVs) in diverse indoor applications exemplifies a prominent domain where the demand for a robust positioning system is evident. With the advancements in 5G and beyond radio access networks (RAN), the availability of new positioning signals presents an opportunity to deliver accurate location estimates for these applications. Nevertheless, these signals encounter substantial path losses in indoor environments. Additionally, the precise localization within existing frameworks requires stringent synchronization, which is challenging to meet. In this paper, we propose OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs, a novel positioning framework that is robust against multipath and does not require strict synchronization between anchor-anchor or anchor-target entities. Specifically, OFDRA is designed to operate in scenarios where the line of sight (LOS) exists. The first design objective of OFDRA is the mitigation of ranging errors by leveraging a compact reconfigurable intelligent surface (RIS) mounted on top of AVs acting as a programmable mirror in a 5G network. The second design objective is to achieve optimal anchor placement in three-dimensional indoor spaces, thereby reducing the geometric dilution of precision (GDOP) and mitigating geometric-induced errors in the final position estimation. Our experimental verification reveals that the localization error is influenced by GDOP, encompassing both the$X-Y$plane and$Z$-axis estimations. Through optimized anchor placement, OFDRA demonstrates a seven-fold enhancement in$Z$-axis accuracy compared to the state-of-the-art, achieving a sub-1 m three-dimensional accuracy for more than 95% of cases.
Alireza Famili, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
IEEE J. Sel. Areas Commun.2
2022 Network-Slice-as-a-Service Deployment Cost Assessment in an End-to-End 5G Testbed
abstract
The next generation of mobile networks will support a wide range of service requirements over a shared virtual infrastructure. Network functions virtualization (NFV) enables the deployment of Radio Access Network (RAN) and core network functions as virtual network functions (VNFs) on commodity hardware instead of proprietary servers. The deployment of the 5G core will be orchestrated between mobile virtual network operators (MVNOs) and cloud infrastructure providers by middle-men Network-slice-as-a-service (NSaaS) providers that will consume Infrastructure-as-a-service (IaaS) from the latter and offer network slices to the former. In this paper, we seek to leverage an end-to-end emulated 5G deployment to offer insight into the cost implications surrounding large-scale core network deployments. Our deployment features real-life traffic patterns corresponding to practical use cases which are fitted with network slicing models. These models are implemented in a 5G testbed to gather compute resource consumption. This data is used to formulate infrastructure procurement costs for popular cloud providers. Our results show steady patterns in compute consumption across all use cases, which we use to make high scale cost projections. In the end, we are able to observe the trade-off between cost and throughput achieved by decentralizing the network slices and offloading the user plane.
Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001
GLOBECOM1
2022 Scaling Network Slices with a 5G Testbed: A Resource Consumption Study
abstract
The next generation of networks will be utilized by multiple industry verticals with different service requirements on top of a common infrastructure. Through network function virtualization (NFV), the 5G core and Radio Access Network (RAN) functions are now implemented as virtual network functions (VNFs) on commercial off-the-shelf (COTS) hardware. The use of virtualized micro-services to implement these 5G VNFs enables end-to-end logically isolated network slices on a large scale. In this paper, we seek to measure, analyze, and understand the limits of 5G micro-service virtualization when using lightweight containers to realize different network slicing models with different service guarantees. Our deployment consists of the OpenAirInterface (OAI) core and a simulated RAN in a containerized setting to create a universally deployable testbed. We perform stress tests on individual VNFs and create network slicing models applicable to real-life scenarios. Our analysis captures the increase in compute resource consumption of individual 5G VNFs during various core network procedures. Furthermore, using different network slicing models, we are able to see the progressive increase in resource consumption as the service guarantees of the slices become more demanding. The framework created using this testbed is the first to provide such analytics on lightweight virtualized 5G core VNFs with large scale end-to-end connections.
Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
WCNC1