JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
1
When the UE Turns Adversary: Real-Time Uplink Jamming from Within 5G Networks
arXiv:2606.14465v1 [cs.NI] 12 Jun 2026
Rosolino Alaimo , Alessandra Dino , Ilenia Tinnirello , and Domenico Garlisi
Abstract—This paper presents an investigation of a novel class of stealthy and selective reactive jamming attacks targeting the Physical Uplink Shared Channel (PUSCH) in 5G New Radio (NR) networks. We design and implement STORM-RJ (Stealthy Timing Obstruction and Radio Manipulation – Reactive Jamming), a Software-Defined Radio (SDR)-based adversarial framework that enables highly precise, time–frequency aligned interference by dynamically adapting the bandwidth and center frequency of injected noise bursts in real time. STORM-RJ leverages decoded Downlink Control Information (DCI) to identify Uplink-Grants (UL-Grants) and synchronizes interference exactly with the resource blocks allocated to a target User Equipment (UE). We further characterize and mitigate the dominant latency sources — both at the software processing and hardware Radio Frequency (RF) frontend levels — to achieve a rapid jamming response upon grant detection. We conduct a comparative analysis of high-level versus low-level radio control strategies, demonstrating that only low-level tuning provides the microsecond-scale responsiveness necessary to meet 5G-NR timing constraints for effective reactive jamming. We analyze the practical feasibility of such selective jamming under realistic hardware and timing constraints, highlighting key trade-offs between SDR flexibility, processing latency, and synchronization accuracy. Finally, we discuss potential mitigation strategies, including Hybrid Automatic Repeat reQuest (HARQ) anomaly detection. Index Terms—5G-NR, physical layer security, reactive jamming, software-defined radio, downlink control information, PUSCH, uplink scheduling.
I. I NTRODUCTION Modern telecommunication systems are characterized by an ever-increasing level of architectural complexity, driven by the demand for higher throughput, lower latency, and massive device connectivity. While these advancements enable a wide range of new applications, they also expand the potential attack surface of wireless infrastructures. Despite continuous improvements in protocol design and security mechanisms, undiscovered vulnerabilities may still remain within communication systems, posing risks to both network availability and the confidentiality of transmitted data. Consequently, modern communication protocols must integrate advanced security mechanisms aimed at reducing exposure to malicious external attacks, a design principle that has guided the evolution of telecommunication systems from early architectures to contemporary 5G networks [1]. Among the various threats affecting wireless networks, jamming attacks represent one of the most critical concerns at the physical layer. By intentionally injecting interference into the wireless medium, an adversary This work has been submitted to the IEEE for possible publication. Copyright may be transferred without notice, after which this version may no longer be accessible.
can degrade link quality, reduce throughput, or completely disrupt communication services. While traditional jamming techniques rely on wideband interference that affects large portions of the spectrum, recent research has demonstrated the feasibility of more selective and energy-efficient attacks that exploit knowledge of the communication protocol to target specific transmissions. These techniques allow attackers to concentrate interference on carefully chosen time–frequency resources, significantly increasing the effectiveness of the attack while reducing its detectability [2]. The 5G New Radio (5G-NR) architecture introduces new opportunities for such targeted attacks due to its highly dynamic and flexible resource allocation mechanisms. In particular, uplink transmissions are scheduled dynamically by the Next-Generation NodeB (gNB) through the Physical Downlink Control Channel (PDCCH), which carries the encoded Downlink Control Information (DCI) containing all scheduling parameters assigned to a specific UE. These messages specify both the time and frequency resources assigned to a User Equipment (UE). If an adversary gains access to this scheduling information, it becomes possible to align interference precisely with the scheduled uplink transmission, enabling highly selective reactive jamming strategies. This study investigates a novel attack model in which the adversary leverages a compromised UE to extract decoded DCI and forward it to an external jamming device. Building upon this concept, we design and implement STORM-RJ (Stealthy Timing Obstruction and Radio Manipulation – Reactive Jamming), a Software-Defined Radio (SDR) framework capable of generating interference bursts that are precisely aligned with the bandwidth and central frequency of the targeted uplink transmission. The present study extends the original STORM architecture [3] by enabling highly selective interference of uplink transmissions through dynamic bandwidth adaptation and ultra-fast DSP-based frequency retuning. This enables interference to be precisely aligned in time and frequency while matching the bandwidth of the dynamically scheduled uplink resources of the target UE. A key challenge in implementing such reactive attacks lies in meeting the strict timing constraints imposed by the 5G-NR scheduling framework. In particular, the jammer must react within the short interval between the reception of the Uplink-Grant (UL-Grant) and the actual transmission of the UE. To address this challenge, this study investigates multiple engineering aspects that determine the practical feasibility of real-time reactive jamming, including latency sources in SDR platforms, frequency tuning strategies, and bandwidthadaptive interference generation. Specifically, this work makes the following contributions:
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
Design and implementation of STORM-RJ, an SDRbased framework capable of performing selective reactive jamming of 5G-NR uplink transmissions. • Analysis of latency constraints affecting reactive jamming, including the delays associated with schedulinginformation acquisition, Radio Frequency (RF) retuning and signal generation. • Comparison of high-level and low-level frequency tuning strategies with different hardware, demonstrating that digital baseband tuning enables microsecond-scale frequency adjustments suitable for real-time operation. • Analysis of throughput and Hybrid Automatic Repeat reQuest (HARQ) retransmission under attack conditions, demonstrating full channel degradation control. • Discussion of potential countermeasures, including anomaly detection based on HARQ feedback patterns and physical-layer signal fingerprinting. Through experimental validation using multiple SDR platforms, we demonstrate that selective uplink jamming aligned with dynamically scheduled resources is practically achievable under realistic hardware constraints. The remainder of this paper is organized as follows. Section II reviews papers on the relative jamming attacks. Section III provides the technical background on the 5G-NR uplink resource structure and scheduling mechanisms relevant to the attack model. Section IV describes the experimental setup and the architecture of the proposed STORM-RJ framework, including the techniques used for dynamic bandwidth selection and frequency tuning. Section V presents the experimental results and evaluates the effectiveness of the proposed jamming approach under different hardware configurations. Section VI discusses possible defensive strategies and mitigation techniques against this class of attacks. Finally, Section VII concludes the paper and outlines directions for future research. •
II. R ELATED W ORKS As discussed in [4], jamming represents one of the most critical and actively researched threats in Physical-Layer security for wireless communication systems. In terms of the 5G system, the vulnerabilities of 5G-NR channels and signals are qualitatively analyzed in the context of smart jamming attacks in [5]. The study highlights how certain structural aspects of the 5G-NR standard may be exploited by adversaries. However, it does not include practical implementations or experimental validations of the proposed attack scenarios. The paper in [6] developed a jammer capable of extracting the C-RNTIs of UEs connected to the network using a custom technique based on polar decoding lattices. This enables the attacker to decode UL-Grants and identify the specific uplink resources assigned to each UE. Unlike that work, the approach presented in this paper relies on a different attack strategy, leveraging a compromised UE to obtain the UL-Grant information. The work presented in [3] introduces a system capable of disrupting the 5G Synchronization Signal Block (SSB), which UEs rely on for initial synchronization and cell selection during network access [7]. It demonstrates a jamming approach that improves energy efficiency by confining the
2
attack to a specific frequency bandwidth aligned with SSB resources. Time and frequency domain synchronization are addressed in [8], which presents a preliminary version of the STORM framework. This version is capable of intercepting and selectively targeting payload data transmitted by the UE. The proposed approach includes traffic analysis mechanisms designed to extract the exact Transmission Time Interval (ttitx ) from the UL-Grant. This information allows the jammer to precisely inject white noise over the scheduled uplink resources, both in time and frequency. To achieve this level of precision, accurate synchronization is required; accordingly, the study focuses on identifying appropriate reference signals to align the attacker with the gNB timing. A quantitative evaluation of the resulting uplink throughput degradation is also provided. It is important to emphasize that the jammer’s reaction time is a critical factor for the success of the attack. If either recognized mechanism fails to respond with sufficient promptness, white noise may be injected with excessive delay, thereby reducing the attack effectiveness and increasing the likelihood of detection through basic approaches like spectrum analysis. Moreover, prior works rely on limited-bandwidth configurations, which do not accurately reflect realistic deployment scenarios. In practical environments, resource allocations may vary dynamically across slots due to different forms of frequency hopping, further complicating timely and precise jamming operations [9]. For these reasons, this paper presents a detailed study on methods for adapting the jamming process to effectively target the Physical Uplink Shared Channel (PUSCH) under realistic conditions. It addresses scenarios involving frequency hopping [10], ensuring that interference remains aligned with the dynamically changing frequency allocations, as well as cases in which the bandwidth of the data transmitted over the PUSCH varies across slots. We note that real-time adaptation of bandwidth and central frequency is particularly challenging because of hardware-induced latency [11] [12], which arises from the need to reconfigure these parameters prior to each payload transmission. In this paper, we explore techniques to mitigate such delays, allowing the proposed framework to dynamically tune its transmission settings to align with the bandwidth and central frequency of the targeted uplink resources. This adaptive approach improves the energy efficiency of the attack: by confining the interference to only the resources allocated to the target UE, STORMRJ achieves the same disruptive effect as a wideband jammer while transmitting over a fraction of the spectrum. A nonselective jammer covering the entire system bandwidth would waste transmit power on unoccupied or irrelevant resources, whereas precise time–frequency alignment ensures that all radiated power is directed exclusively toward disrupting the intended transmission. III. T ECHNICAL BACKGROUND A thorough understanding of how time-frequency resources are organized and scheduled in the 5G-NR air interface is essential for designing an effective jamming strategy. In 5GNR, radio transmissions are structured in frames of 10 ms, each composed of 10 subframes of 1 ms. Each subframe is further
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
3
Frame
divided into slots, whose duration depends on the selected numerology, a central concept in NR denoted by µ which defines the Subcarrier Spacing (SCS) as
RB #1 RB #2
(1)
and consequently determines the Orthogonal Frequency Division Multiplexing (OFDM) symbol duration and slot length. At the same time, the numerology also impacts the number of slots per frame as NFRAME = 10 · 2µ slot
(2)
Higher numerology values correspond to larger SCS, shorter symbol duration, and reduced transmission time intervals, enabling lower latency and improving robustness to phase noise. Table I summarizes the relationship between µ, SCS, and slot duration. When µ = 0, according to (1) and to (2), the
RB #3 Frequency - subcarriers 9.36 MHz
∆f = 15 × 2µ kHz,
RB #4 RB #5 RB #6 RB #7 RB #8
RB #52 Time - slots
10ms
Fig. 1. 5G-NR time-frequency resource grid for one frame. TABLE I I MPACT OF N UMEROLOGY ON 5G-NR F RAME S TRUCTURE Numerology µ 0 1 2 3 4 5 6
SCS (kHz) 15 30 60 120 240 480 960
Slot duration (ms) 1.000 0.500 0.250 0.125 0.063 0.031 0.016
number of slots within a frame equals the number of subframes in the same frame [13]. At the opposite extreme, µ = 6 is employed in millimeter-wave (mmWave) deployments, where the wider subcarrier spacing provides increased robustness against Doppler spread while supporting the shorter slot durations required for low-latency transmissions [14][15]. In such a system, the smallest addressable unit in the time–frequency grid is the Resource Element (RE), which corresponds to one subcarrier in frequency over one OFDM symbol in time [16]. A Resource Block (RB), instead, is defined in the frequency domain as a group of 12 consecutive subcarriers, each spaced according to the SCS and so to the selected numerology µ. Therefore, an RB spans a bandwidth of 12 × ∆f . In the time domain, the RB extends over a given number of OFDM symbols, depending on the resource allocation. Fig. 1 shows a 5G-NR time-frequency resource grid for one frame (52 RB, e.g. 9.36 MHz excluding guard bands). When considering Type-A mapping for the PUSCH, as specified in [17], the RB allocation follows a slot-based structure. In this configuration, an RB consists of 12 contiguous subcarriers in frequency over the duration of one slot. It is important to consider that a UE transmits a certain number of RBs within a single slot. This number may vary from slot to slot and is communicated to the UE via the UL-Grant, which is delivered by the gNB through the PDCCH. In a representative uplink allocation scenario, in a 5G-NR cell configured with a 10 MHz channel bandwidth and numerology µ = 0, a UE can be scheduled with up to 52 RBs within a single slot. This value corresponds
to the maximum number of resource blocks available. The corresponding occupied bandwidth is therefore 52 × 12 × 15 kHz = 9.36 MHz, excluding guard bands. However, the number of RBs allocated to a UE is dynamically determined by the gNB scheduler based on multiple factors, including buffer status reports, channel quality indicators, selected modulation and coding scheme, and overall uplink load conditions [18]. As a result, RB assignments may vary on a slot-by-slot basis, enabling fine-grained and adaptive time–frequency resource utilization in response to traffic demand and radio channel conditions. When the gNB sends an UL-Grant to the UE, it specifies both the number of RBs the UE is allowed to use and the exact timing for its transmission in terms of slot. 3GPP specifications defines the time-domain resource assignment for a UE [17]. As described in [19], it depends on the parameter K2 , that represents the number of slots between the reception of the UL-Grant and the actual payload transmission on the PUSCH. Starting from all the information described above, it is already possible to determine both the signal bandwidth and the exact time slot in which the UE will transmit to the gNB. Consequently, this information may be exploited by a jammer to precisely determine both the transmission timing and the bandwidth over which to transmit interference, such as white noise. This could enable a highly selective and covert jamming strategy: selective because it disrupts only the specific portion of the spectrum allocated to the target transmission and covert because it minimizes unintended spectral emissions, thereby reducing the likelihood of detection by conventional spectrum monitoring and interference analysis systems. For example, a jammer system can obtain such sensitive information through a backdoor that can be embedded within a legitimate application or introduced via malware that conceals a covert communication channel, activated under specific conditions once installed [20]. However, once the jammer acquires this
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
STORM-RJ PUSCH
STORM-RJ
Frequency [MHz]
20 RB
26 RB 58 RB
50 RB 72 RB
Time [ms]
Fig. 2. Time–Frequency illustration of dynamic uplink RB allocations across consecutive slots. The figure highlights how varying bandwidth assignments over time require the jammer to adapt both its center frequency and occupied bandwidth on a per-slot basis to maintain alignment with the scheduled PUSCH resources.
scheduling information, it must compensate for four latency components in order to successfully execute the attack scenario illustrated in Fig. 2. These components are: 1) The time required by the UE to decode the DCI from the PDCCH and the subsequent transmission of the decoded UL-Grant to the jammer through the backdoor. While the former contribution is UE-dependent and not characterized in this work, the latter has been experimentally measured in [3] at an average of approximately 121 µs. 2) signal generation latency, namely the time required to synthesize and prepare the white-noise burst for transmission. This delay scales with the target interference bandwidth, which in turn depends on the number of RBs allocated to the UE in the UL-Grant. Wider RB allocations require broader-band noise generation, increasing processing and RF front-end reconfiguration time. 3) latency to configure the appropriate center frequency corresponding to the scheduled PUSCH allocation. This involves translating the RB index into an absolute frequency location within the NR carrier bandwidth, taking into account the active numerology and carrier configuration. 4) delay required by the jammer to configure the Phase Locked Loop (PLL) to the previously computed center frequency, as this determines when the burst containing the white noise bandwidth can actually be available for transmission. The cumulative effect of these latencies determines whether the interference can be precisely aligned in both time and frequency with the targeted uplink transmission. Only after accounting for all these latency components can the feasibility of the attack be properly assessed: the jammer can successfully align its transmission with the target PUSCH only if the total
4
accumulated delay is shorter than the time interval between the UE’s DCI reception and the actual UE uplink transmission on the PUSCH. If this timing constraint is satisfied, the jammer can precisely schedule the onset of the interference in both time and frequency. Building on this principle, we integrated the complete synchronization and reactive jamming chain leading to the development of STORM-RJ, a multithreaded system architecture. STORM-RJ initially behaves as a standard UE, performing cell search [21], time–frequency synchronization, MIB decoding, and PBCH processing to acquire the necessary system parameters from the gNB [22]. Once synchronization is established and scheduling information becomes accessible, the system switches to jamming mode. To support this dual behavior, we implemented a custom state machine that orchestrates the full detection and synchronization pipeline — covering cell acquisition, PBCH decoding, and system information extraction — while intentionally bypassing the random access procedure. Instead of completing network attachment, the framework initializes the reactive jamming logic while maintaining slot-level synchronization with the gNB’s timing reference. IV. M ETHODS The experimental setup consists of three separated hosts running Linux Mint 21.3, each connected to a Universal Software Radio Peripheral-SDR (USRP-SDR) from Ettus Research. The first host runs the UE using the srsRAN-4G framework, while the second host executes STORM-RJ, implemented by modifying the open-source free5GRAN framework [23]. The third host executes the open-source Open5GS framework [24] to implement the Core Network (CN), responsible for handling user registration and authentication procedures within the cell. At the same time, it deploys a gNB using the srsRAN-Project framework [25], which enables UEs to establish and maintain connectivity with the network. srsRAN-Project was preferred over srsRAN-4G as it provides native support for PUSCH frequency hopping, which is not fully implemented in srsRAN-4G due to its limited DCI format support [26]. Both the gNB and the UE are connected to two different Ettus Research USRP-B210 devices, each exhibiting slight frequency offsets of 0.85 and 0.83 parts per million (PPM) [27], respectively. For the jammer, we employed two different USRP platforms to compare their performance: a USRP-N310 and a USRP-B210. Another USRPN310 is included in the setup to passively monitor the PUSCH channel, using the Inspectrum tool [28]. To generate User Datagram Protocol (UDP) traffic between the UE and the gNB over the PUSCH, the iPerf tool [29] is used. The iPerf server runs on the gNB host, while the client is executed on the UE host. To evaluate the practicality of targeted uplink jamming, we implemented a backdoor in our UE, specifically designed to forward the decoded DCI content directly to our jammer device. To operate the transmission of the ULGrant from the UE to STORM-RJ, we established a clientserver communication between the two devices, emulating the behavior of a backdoor capable of reliably delivering the UL-Grant to STORM-RJ. The experiment was conducted in
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
tPLL
tCALL
(a)
5
tPLL
tDSP
(b)
Fig. 3. Schematic representations of the two center frequency tuning approaches. (a) High-level tuning: the analog LO is retuned at every UL-Grant, incurring both an API call delay tCALL and a PLL locking delay tPLL . (b) Low-level tuning: the analog LO is fixed at initialization and frequency shifting is performed digitally via the NCO, introducing only the DSP processing delay tDSP on a per-grant basis.
our laboratory, as it demonstrates that the experiment can be reliably reproduced even outside an isolated environment, bringing the setup closer to a realistic deployment scenario. In the physical arrangement of the setup, the UE is positioned 150 cm from the gNB. The attacker is placed in between, located 50 cm from the UE and 100 cm from the gNB. In our setup, communication operates in Frequency Division Duplex (FDD) mode, while the gNB was configured with an Absolute Radio Frequency Channel Number (ARFCN) of 394000, corresponding to the 3GPP n2 band [30], with center frequencies of 1970 MHz for the downlink and 1890 MHz for the uplink channels respectively. A channel bandwidth (BCH ) of 20 MHz was configured, allowing for a maximum of 106 RBs per slot. We operate with numerology µ = 0, which implies an SCS of 15 kHz. A resource mapping of typeA is adopted as well. As a consequence of these settings, the time interval between the transmission of the UL-Grant and the actual uplink payload transmission over the PUSCH channel by the UE — already defined in III as K2 — is 4 ms [17]. This interval is configured by the gNB to provide the UE with sufficient time to decode the DCI carried on the PDCCH and prepare the uplink transmission — including resource allocation, power control, and waveform generation — before the designated PUSCH slot begins [31]. To ensure the effectiveness of the attack, it is essential to perform a timing analysis that quantifies the latency budget available to the jammer. Upon reception of each UL-Grant, STORM-RJ generates an interference burst covering the exact bandwidth allocated to the target UE. However, to further minimize the delay between successive UL-Grants, STORM-RJ was designed to pre-generate 106 interference bursts prior to the actual start of the attack, each lasting the duration of one slot and covering a bandwidth that is an integer multiple of 180 kHz, that is the width of a single Physical Resource Block (PRB) — a group of 12 consecutive subcarriers over one slot — at 15 kHz SCS, ranging from a minimum of 180 kHz (single PRB) to a maximum of 19.08 MHz (106 PRBs). At runtime, the appropriate burst is selected based on the number of PRBs indicated in the UL-Grant, enabling immediate transmission without incurring waveform generation overhead. Secondly, we investigated two different tuning methods for configuring the USRP used in the jamming process: i) high-level tuning and ii) low-level tuning. They are subsequently described:
1) High-level tuning. As illustrated in Fig. 3a, center frequency reconfiguration is performed by retuning the analog Local Oscillator (LO) of the AD9361 RF transceiver via a high-level UHD Application Programming Interface (UHD-API) call. This process requires updating the internal PLL configuration and waiting for it to lock onto the target frequency, introducing two sequential delays: the API call processing time tCALL and the PLL locking time tPLL . 2) Low-level tuning. As illustrated in Fig. 3b, frequency reconfiguration is performed entirely in the digital domain by adjusting the Numerically Controlled Oscillator (NCO), implemented either in the USRP-FPGA or in the internal digital mixer of the AD9361. Unlike highlevel tuning, where tCALL and tPLL are incurred at every UL-Grant to retune the LO to the new target frequency, this approach requires the UHD-API call only once at initialization to fix the analog LO, and subsequently shifts the baseband spectrum digitally on a per-grant basis. This eliminates the PLL relock overhead entirely, achieving a substantially lower reconfiguration latency compared to high-level tuning. A. Central Frequency Configuration STORM-RJ’s architecture is designed to generate and radiate short bursts of white noise, whose central frequency and bandwidth dynamically depend on the radio resource allocation received from the UE’s UL-Grant. The center frequency of each transmission burst is defined according to the PRBs allocated for the uplink transmission. Given the zero-based idx indices of the first and last allocated PRB (PRBidx start and PRBend , both inclusive), the center frequency corresponding to the PRB group assigned to the target UE in the current slot (fcPRBx ) is computed as: idx PRBidx PRBidx end − PRBstart · BRB PRBx start fc = fc + (3) 2 where BRB = 180 kHz is the bandwidth of a single RB PRBidx for numerology µ = 0, and fc start is the center frequency of the PRB identified by the index PRBidx start , whose position within the PUSCH resource grid is determined by the ULGrant and may correspond to any PRB in the grid. This computation yields the center frequency corresponding to the
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
6
BGUARD 2
idx
idx idx − PRBstart ⋅ BRB PRBend
PRBend
2
BGRID
𝑓𝑐PUSCH
BCH
𝑓𝑐PRBx
idx idx − PRBstart ⋅ BRB PRBend
idx idx − PRBstart ⋅ BRB PRBend 2
idx start
𝑓c PRB
idx PRBstart
180 KHz
BGUARD
∆DSP = fLO − fcPRBx
2
Fig. 4. Graphical representation of the frequency-domain parameters used in this work, showing the spatial relationship between BCH , Bgrid , Bguard , and the jamming center frequency fcPRBx as a function of the allocated PRB range.
midpoint of the allocated PRB range, enabling STORM-RJ to precisely align with the spectral location of the target resources within the 5G-NR uplink frame structure. In 5G-NR, the center frequency of the lowest-indexed PRB in the PUSCH resource grid is defined according to the reference grid specified in [32], which outlines how the resource grid is aligned in frequency relative to the ARFCN and the corresponding carrier center frequency. The offset between the center frequency of the PUSCH (fcPUSCH ) and the lowest-indexed PRB in the PUSCH resource grid depends on the numerology index µ, the SCS, and the total channel bandwidth BCH , as introduced in Section III. According to this specification, our setup allows for a maximum of 106 PRBs to be allocated for uplink transmission, with indices ranging from 0 to 105: NUL RB = 106 PRB.
(4)
Given that each PRB spans a bandwidth of 180 kHz, the effective total bandwidth of the resource grid is: Bgrid = NUL RB · BRB = 19.08 MHz,
Substituting the values of our experimental setup into (7) with fcPUSCH = 1890 MHz, if we consider for instancewhere BRB = 180 kHz is the bandwidth of a single RB for PRBidx numerology µ = 0, and fc start is the center frequency of the PRB identified by the index PRBidx start , whose position within the PUSCH resource grid is determined by the UL-Grant and may correspond to any PRB in the grid. PRBidx start = 0, we PRBidx start obtain fc = 1880.55 MHz, which corresponds to the case in which PRBidx start coincides with the lowest-indexed PRB PRBidx of the PUSCH resource grid. In general, however, fc start shifts by BRB for each unit increase in PRBidx start . Consequently, the last PRB in the grid, PRB105 , is centered at fcPRB105 = 1899.45 MHz. Once the center frequency corresponding to the target PRB group is determined via (3), STORM-RJ computes the appropriate frequency at which to transmit the interference burst. To this end, STORM-RJ sets the LO to match the PUSCH carrier frequency, i.e., fLO = fcPUSCH , and applies a fine digital frequency shift defined as:
(5)
where Bgrid is the usable bandwidth of the PUSCH resource grid available for uplink payload transmission. This value is slightly less than the nominal channel bandwidth of 20 MHz, as the remaining bandwidth is reserved for guard bands at both edges of the spectrum [32]. The guard band on each side is therefore: Bguard BCH − Bgrid = = 0.46 MHz. (6) 2 2 The center frequency of the PRB identified by PRBidx start can thus be expressed as: Bgrid 1 PRBidx fc start = fcPUSCH − + PRBidx + · BRB (7) start 2 2
(8)
This digital offset allows STORM-RJ to precisely align its transmitted signal with the frequency of the targeted PRB group. As a result, the actual transmission frequency is given by: fTX = fLO − ∆DSP (9) The value of fTX is updated upon the reception of each ULGrant. To prevent aliasing effects during digital frequency shifting, an appropriate sampling rate must be used. In our implementation, we adopted a sampling rate of fs = 23.04 MHz, which ensures safe and accurate low-level tuning within the valid frequency range. B. Bandwidth Selection and Noise Generation The bandwidth of each burst is directly proportional to the number of allocated PRBs, according to: Bburst = NRB · BRB
(10)
where NRB is given by the difference between PRBend and PRBstart . For each possible allocation, a pre-computed burst of complex white noise is generated through an Inverse Fast Fourier Transform (IFFT) procedure that ensures the desired spectral confinement. The noise generation process starts by defining a frequency-domain vector F of length N, corresponding to the number of samples in a 1 ms burst: fs (11) 1000 Where fs denotes the sampling frequency. A set of K active subcarriers is determined by the target bandwidth Bburst and the frequency resolution ∆f = fs /N, i.e., Bburst K= (12) ∆f N=
Random samples drawn from a zero-mean Gaussian distribution N (0, 1) populate the frequency bins corresponding to positive spectral indices, while the remaining bins are assigned
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
Required time to generate 1ms white-noise buffers 350
Time [ s]
300
250
200
150 21
41
61
81
101
Number of RB Fig. 5. Average generation time required to synthesize 1 ms white-noise bursts as a function of the number of allocated PRBs. Results are averaged over 1000 iterations. Larger bandwidth allocations increase the computational latency, motivating the adoption of a pre-buffering strategy.
according to the Hermitian symmetry constraint to ensure a real-valued time-domain signal: K (13) F [−k] = F ∗ [k], k = 1, 2, . . . , 2 Finally, the burst waveform is computed as: 1 x[n] = IFFT{F [k]}, n = 0, 1, . . . , N − 1 (14) N thus, the burst is subsequently normalized to prevent signal clipping and stored in memory for future use. Fig. 5 illustrates the generation delays associated with producing 1 ms bursts as a function of the number of PRBs contained within each burst. An error bar plot is used to illustrate the statistics computed over 1000 iterations. As expected, larger burst bandwidths require longer generation time. Although the delay introduced by burst generation is relatively small, it becomes non negligible when strict timing constraints are imposed. To eliminate this overhead during runtime, we precompute and store all possible burst configurations in a dedicated buffer. This ensures that, upon receiving an UL-Grant, the corresponding pre-generated burst matching the required bandwidth can be immediately retrieved and transmitted, significantly reducing computational latency in time sensitive operations. Upon receiving an UL-Grant and determining the UE’s allocated bandwidth, STORM-RJ selects the corresponding pre generated burst and transmits it at the appropriate center frequency, as explained in IV-A. During execution, the selected white noise vector, corresponding to the required bandwidth, is retrieved from memory and transmitted immediately following the frequency tuning phase. The sequence of operations described above is summarized in Algorithm 1, which provides a structured representation of the complete STORM-RJ workflow. V. R ESULTS In this section, we present the results obtained from the two different setups illustrated in Fig. 3a and Fig. 3b. Rather
7
than the paper presented in [8], where the impact of selective uplink jamming on throughput degradation and radio link failure was demonstrated, this paper focuses on the engineering challenges that determine the real-world feasibility of such attacks, namely the precise time–frequency alignment of interference under dynamic resource scheduling, variable bandwidth allocation, and frequency hopping conditions. We define the jamming idle interval (Jidle ) as the minimum time duration, expressed in milliseconds, during which STORMRJ discards incoming UL-Grants without processing them, refraining from transmitting any jamming burst between two successive attack events. By adjusting Jidle , STORM-RJ can precisely control the temporal density of the interference, and consequently the degree of throughput degradation imposed on the target UE. To illustrate the effect of Jidle , Fig. 7 shows an example of an attack configured with Jidle = 4 ms. Note that Jidle represents a lower bound on the inter-attack interval rather than a fixed periodicity: once the idle period expires, STORM-RJ resumes monitoring incoming UL-Grants and triggers the next jamming burst on the first grant received from the target UE. Since each UL-Grant refers to a future uplink Algorithm 1 STORM-RJ Workflow 1: Phase 0: Network Setup and UL Payload Generation 2: Establish a standard UE–gNB connection with a compro-
mised UE 3: Start uplink traffic generation using iPerf (UE → gNB) 4: Phase 1: STORM-RJ Boot 5: Start STORM-RJ, initially operating as a standard UE 6: Perform cell search and time–frequency synchronization
with the gNB 7: Switch STORM-RJ to jamming mode after synchroniza-
tion 8: Pre-generate and store 1 ms complex white-noise bursts
for multiple bandwidth configurations 9: Set Jidle and initialize the timer tlast jam 10: Phase 3: Reactive Jamming Loop 11: while STORM-RJ is running do 12: Wait for a backdoored UL-Grant packet from the UE 13: Parse (ttitx , PRBstart , PRBend ) and derive the target band-
width using (10) Compute the burst center frequency associated with the allocated PRBs using (7) and (3) 15: Compute the low-level tuning offset using (8) 16: Set the USRP-B210 transmit frequency according to (9) 17: Wait until the transmission instant corresponding to ttitx , accounting for all hardware-induced and processing delays 18: if elapsed time since tlast jam ≥ Jidle then 19: Transmit the pre-buffered 1 ms burst matching the target bandwidth 20: Update tlast jam ← 0 21: else 22: Discard the incoming UL-Grant 23: end if 24: end while 14:
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
tCALL
2800
2850
2900
8
tPLL
Mean: 2867.332 µs Median: 2860.810 µs Std: 36.374 µs
2950
3000
20
40
60
Mean: 66.712 µs Median: 57.628 µs Std: 23.753 µs
80
Time [µs]
Time [µs]
(a)
(b)
100
Fig. 6. Measured latency distributions for high-level tuning on the USRP-B210 over 1000 repetitions. (a) Distribution of the UHD-API call delay tCALL , showing a tightly concentrated response around 2867 µs. (b) Distribution of the PLL locking delay tPLL , exhibiting higher variability with a mean around 67 µs. The cumulative effect of both delays approaches 3 ms, confirming the incompatibility of high-level tuning with the timing constraints of reactive jamming.
slot, the actual jamming event will necessarily occur after the idle period has elapsed, with the exact timing determined by when the next UL-Grant is received and the residual reaction window available to STORM-RJ at that moment. This behavior is governed by the USRP timer tlast jam , which is reset after each jamming event. A new attack is triggered only when tlast jam ≥ Jidle and a new UL-Grant is received, even if one or more UL-Grants arrive during the idle period. In the example shown in Fig. 7, the payload transmission from the UE is represented by darker signals with lower power, while STORM-RJ transmission is depicted in a lighter color due to its higher power. The temporal offset visible between the UE’s uplink transmission and the jamming burst is a direct consequence of the tCALL + tPLL delays introduced by the high-level tuning procedure, which prevent STORM-RJ from completing the LO retuning process before the target
Jammed Slot
t
CALL
+ tPLL delay
1890 MHz
Jamming Idle: 4ms
Fig. 7. Spectrogram of STORM-RJ transmissions under high-level tuning (Jidle = 7 ms), showing the temporal offset between each UE uplink transmission and the corresponding jamming burst. The offset is a direct consequence of the tCALL + tPLL retuning latency, which prevents the jammer from aligning with the intended slot. Idle slots between consecutive jamming events reflect the configured Jidle
slot begins. Jammer power was increased to enhance visibility and enable a direct comparison with the signals transmitted by the UE. It should be noted that in a real attack scenario, the jammer transmission power would be reduced to minimize spectral footprint and avoid detection through conventional spectrum analysis. The configurability of STORM-RJ makes it possible to select the desired level of degradation on the PUSCH channel: lower Jidle values result in more frequent jamming events and, therefore, in a stronger degradation of the throughput. An example of a higher Jidle configuration is shown in Fig. 11. A. High-level tuning The first setup we analyze is the one illustrated in Fig. 3a. For each received UL-Grant, STORM-RJ reconfigures the LO of the RF front-end, as previously described in Section IV. Fig. 6a and Fig. 6b clearly show that this approach is not effective for reactive jamming, as the measured reconfiguration delays approach 3 ms, leaving insufficient reaction time before the target PUSCH slot begins. Supporting this conclusion, Fig. 7 demonstrates how, under this setup, STORM-RJ consistently fails to jam the intended slot in time, with the jamming burst being delivered after the target slot has already elapsed. A complete explanation of this behavior would require a detailed characterization of all latency contributions in the pipeline — including UE-side DCI processing time and potential scheduling overhead introduced by the operating system — which falls outside the scope of this work and is left as a direction for future investigation. Nevertheless, it is reasonable to conclude that the combined effect of these contributions, together with the ≈3 ms incurred by the LO retuning procedure, exceeds the available reaction window, causing the jamming burst to consistently miss the intended slot. B. Low-level tuning In contrast to the previous setup, low-level tuning operates entirely at the DSP level and works as illustrated in Fig. 3b.
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
9
USRP B210 — DSP Offset Time
USRP N310 — DSP Offset Time Mean: 88.266 ms Median: 83.618 ms Std: 25.219 ms
Mean: 19.872 µs Median: 16.864 µs Std: 9.700 µs
10
15
20
25
30
35
30
50
70
90
Time [µs]
Time [ms]
(a)
(b)
110
130
150
Fig. 8. Low-level tuning evaluation and comparison across hardware platforms. (a) Distribution of DSP retuning delay for the USRP-B210 over 1000 frequency updates. (b) Equivalent measurement for the USRP-N310, highlighting substantially higher reconfiguration latency.
Instead of reprogramming the LO of the RF front-end, a digital frequency translation is applied directly to the complex baseband signal by means of a NCO. The NCO multiplies the in-phase and quadrature (I/Q) samples by a complex exponential, as shown in (15), effectively shifting the spectrum by a desired offset prior to digital to analog conversion. s′ (t) = s(t) · ej2πfDSP t
(15)
fDSP represents the digital frequency offset, while s′ (t) is the newly shifted signal. Since this operation is performed entirely in the digital domain, the analog LO remains fixed, and no reconfiguration or locking delay is introduced by the PLL. As a result, frequency adjustments can be performed with microsecond level latency, enabling fast and precise spectral repositioning. This makes low-level tuning particularly suitable for applications requiring real time reconfiguration or agile frequency hopping. The valid range for fDSP is inherently limited by the sampling frequency fs . According to the Shannon criterion [33], the maximum shift that can be applied without aliasing is given by (16): fs (16) 2 In practice, however, this theoretical limit cannot be fully exploited due to attenuation introduced by digital filters near the spectral edges. To ensure spectral integrity and minimize distortion, the effective range is reduced as described in (17): |fDSP | <
|fDSP | ≤ 0.45 fs
(17)
For instance, when the sampling rate is fs = 23.04 MHz, and the LO is fixed at fLO = 1890 MHz, the theoretical maximum DSP offset, is shown in (18), fs = 11.52 MHz (18) 2 Nonetheless, considering the filtering constraints, the practical offset is limited to approximately ±10 MHz. Therefore, the |fDSP,max | =
effective transmitted carrier frequency can be tuned digitally within the range described in (19): fTX = fLO ± fDSP ≈ [1880, 1900] MHz
(19)
fixing fLO to 1890 MHz, without requiring any future modification of the analog PLL. Operating outside this range may introduce aliasing and spectral distortion, thereby compromising signal purity. C. Evaluation results on USRP-B210 device Fig. 8a illustrates the delay distribution obtained from 1000 center frequency changes performed using low-level tuning on the USRP-B210. The results confirm that this device achieves substantially reduced reconfiguration latency, averaging below 20 µs, making it highly suitable for reactive jamming applications. The spectral behavior of the system is shown in Fig. 9, where the device successfully shifts the center frequency of the transmitted interference within the duration of a single slot, even when both bandwidth and center frequency are varied simultaneously on a per-slot basis. Fig. 10 illustrates a preliminary attack scenario with Jidle = 0 ms in which STORM-RJ attempts to jam every received UL-Grant. It is worth noting that the UL-Grant contains explicit timing information specifying the exact slot in which the UE will transmit its payload. In this figure, STORM-RJ was intentionally configured to transmit the jamming burst immediately upon UL-Grant receiving, without waiting for the designated transmission slot (ttitx ). As a result, the interference burst precedes the UE payload by approximately two slots. Despite this timing offset, bandwidth and central frequency alignment between the jamming burst and the target PRBs allocation is precise, confirming the effectiveness of the NCO-based frequency tuning. Notably, STORM-RJ selectively targets only the PUSCH resources, leaving the Physical Uplink Control Channel (PUCCH) transmissions unaffected. The complete and synchronized attack scenario is presented in Fig. 11, which
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
10
shown in Fig. 8b, switching between transmissions with different center frequencies and bandwidths incurs a reconfiguration delay of approximately 88 ms. Such latency is incompatible with the stringent timing requirements of our system, which demands rapid central frequency updates to selectively jam specific time-frequency slots with minimal delay. Indeed, the USRP-N310 is designed to deliver high RF performance, wide instantaneous bandwidth, and robust signal quality, rather than rapid retuning. Its architecture, based on AD9371 transceivers and controlled through FPGA and UHD software, imposes tuning delays due to the internal PLL and VCO lock times required to preserve spectral purity and phase coherence. These delays are not the result of suboptimal implementation but stem from deliberate design trade offs aimed at maximizing signal fidelity [36]. E. Impact of Jidle on UL HARQ Performance and Throughput
Fig. 9. Spectrogram of STORM-RJ transmissions using low-level tuning on the USRP-B210, showing per-slot variation of center frequency and bandwidth across consecutive slots.
constitutes the core experimental result of this work. In this Figure, STORM-RJ operates with Jidle = 15 ms and low-level tuning, selectively jamming only the designated PUSCH slots while leaving all remaining uplink resources — including PUCCH — entirely unaffected. The precise time–frequency alignment of each jamming burst with the corresponding UE payload confirms the effectiveness of the NCO-based tuning strategy combined with the pre-buffering mechanism. A notable consequence of the selective interference is visible in the spectrogram: the UE transmits a significantly higher number of uplink payload than expected under unperturbed conditions. This behavior is a direct consequence of the HARQ retransmission mechanism. When a jammed PUSCH transmission causes a Cyclic Redundancy Chech (CRC) failure at the gNB, the scheduler issues a negative Acknowledgement (NACK) and re-schedules the same Transport Block (TB) for retransmission; the receiver then performs soft combining of successive attempts to improve decoding probability. This process repeats until either the CRC succeeds or the maximum number of retransmissions is exhausted, after which the TB is permanently discarded at the MAC layer [34]. As a result, the UE is required to serve not only its regular traffic but also the retransmissions triggered by the attack, effectively increasing the uplink load. The Jidle is set sufficiently large to prevent a Radio Resource Control (RRC) Release, allowing the attack to persist without disrupting network connectivity — consistent with the stealthy design objective of STORM-RJ.
Fig. 12 reports the UL HARQ permanent failure rate and UL throughput as a function of Jidle , measured across the full symmetric sweep from 15 ms down to 1 ms and back. For Jidle values between 8 and 15 ms, the UL throughput remains effectively constant at approximately 2.2 Mbit/s despite a progressively increasing permanent failure rate, which rises from 12.4% at Jidle = 15 ms to 22% at Jidle = 8 ms. This behavior is consistent with the HARQ retransmission mechanism absorbing the interference: when a jammed transmission fails its CRC check, the scheduler re-allocates the same TB up to 3 times, and soft combining of successive attempts restores decodability without any visible throughput loss. Below Jidle = 3 ms the system crosses into a qualitatively different operating point. Now the permanent failure rate reaches 50% and throughput drops to 1.40 Mbit/s. At Jidle = 2 ms, failure rate climbs to 65% and throughput collapses to 0.97 Mbit/s. A step before the maximum aggressiveness (Jidle = 1 ms) the failure rate saturates at 73.4% and throughput reaches its minimum of 0.73 Mbit/s, a reduction of 66.9% relative to the 1.230000
1.240000
1.250000
1.260000
1.270000
1890 MHz
UE-Payload
STORM-RJ Burst
PUCCH Jamming Idle: 0ms
D. Evaluation results on USRP-N310 device We also tested low-level tuning with the USRP-N310 to evaluate whether it could offer improved performance compared to the USRP-B210. However, as indicated in the official documentation [35], this device is not optimized for fast tuning. Our experimental validation confirmed this constraint: as
Fig. 10. Spectrogram of a STORM-RJ attack (Jidle = 0) using low-level tuning. The jamming burst is intentionally transmitted immediately upon UL-Grant decoding, without synchronization to the designated PUSCH slot, resulting in a two-slot anticipation with respect to the UE payload. Bandwidth alignment with the target PRB allocation is precise, and PUCCH transmissions remain unaffected, confirming the selectivity of the attack.
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
3.570000
11
3.580000
3.590000
3.600000
3.610000
1890 MHz
UE-Payload
STORM-RJ Burst
PUCCH Jamming Idle: 15ms
Fig. 11. Spectrogram of a complete STORM-RJ attack using low-level tuning (Jidle = 15 ms), demonstrating precise time–frequency alignment between the jamming bursts and the target PUSCH allocations. The increased number of UE uplink transmissions is attributable to HARQ-triggered retransmissions of jammed packets. PUCCH resources remain unaffected, confirming the selectivity of the attack. Jidle is set to prevent RRC release while maintaining persistent interference.
Jidle = 15 ms baseline. The symmetric ramp-up path produces nearly identical values at each Jidle level, confirming that the observed degradation reflects steady-state channel conditions rather than transient effects.
To mitigate this risk, defensive strategies must focus on both the control and physical layers of the 5G-NR stack. We refer to these two aspects in the rest of this section. A. Control-Plane Integrity and Anomaly Detection
VI. D EFENSIVE C ONSIDERATIONS The vulnerability exploited in this study does not rely on weaknesses in the radio interface itself, but rather on the unauthorized leakage of control plane information, specifically the DCI contents, via a malicious backdoor running on a compromised UE. Although the DCI is encrypted and can only be decrypted by the intended recipient, the presence of a software level backdoor within the UE allows the attacker to extract and exfiltrate the decoded uplink scheduling information without breaking the encryption, thus enabling selective jamming with precise timing and frequency targeting.
At the control-plane level, a possible mitigation strategy is the implementation of integrity verification mechanisms designed to assess the consistency between scheduled ULGrants and the actual uplink transmission outcomes. More specifically, the gNB can maintain statistical logs of the HARQ feedback and analyze retransmission patterns over time to detect anomalous behaviors. HARQ is a reliability mechanism used in telecommunication systems that combines forward error correction with retransmissions[37]. Under normal operating conditions, HARQ retransmissions are typically associated with poor radio channel conditions, which are often
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
12
UL HARQ NACK Rate & Throughput vs. Jidle UL HARQ NACK rate [%] UL throughput [Mbit/s] Jidle [ms]
80
3.0 2.5
UL throughput [Mbit/s]
UL HARQ NACK rate [%]
100
60
2.0
40
1.5 1.0
20
0.5 0 15
14
13
12
11
10
9
8
7
6
5
4
3
2
1
Jidle [ms]
2
3
4
5
6
7
8
9
10
11
12
13
14
15
0.0
Fig. 12. UL-HARQ permanent failure rate and UL-Throughput as a function of Jidle . Two Throughput anomalies are visible: the peak at Jidle = 4 ms on the descending ramp is attributed to a favorable timing alignment between the jammer period and the HARQ round-trip time, which transiently increases the average decoded TB-size per successful grant; the sharp peak at Jidle = 9 ms on the ascending ramp reflects MAC/RLC buffer drainage, as the UE flushes data accumulated during the aggressive jamming phases once channel conditions improve sufficiently.
reflected by low Received Signal Strength Indicator (RSSI). Consequently, decoding failures tend to correlate with degraded channel measurements. In contrast, if frequent HARQ retransmissions occur despite relatively high received signal strength, this discrepancy may indicate that the decoding failure is not caused by channel attenuation but by interference, such as a reactive jamming attack targeting the scheduled resources. In parallel, real time anomaly detection mechanisms at the gNB level, potentially assisted by machine learning classifiers trained on performance indicators such as packet error rate, packet delivery ratio, or received signal strength, have been investigated as jamming detection strategies in wireless networks [38]. Such approaches may provide early warning signals of abnormal interference patterns. These systems could flag UEs whose HARQ feedback deviates from expected statistical models, or whose uplink traffic exhibits abnormal latency, packet loss, or throughput degradation under otherwise favorable radio conditions. B. Physical Layer Behavior Analysis Jamming attacks based on decoded DCI information produce interference that is non-random and time-synchronized with specific uplink transmissions, making them fundamentally distinguishable from ambient noise or conventional wideband jamming. This deterministic temporal and spectral correlation can be exploited by the gNB to identify interference patterns that consistently overlap with PUSCH resources allocated to a specific UE — a signature that is unlikely to arise from stochastic interference sources. Physical layer fingerprinting techniques [39] can further enhance detection capabilities. Each SDR-based jammer inherently exhibits hardware-specific RF impairments — such as IQ imbalance, LO phase-noise, and Error Vector Magnitude (EVM) anomalies — that constitute a distinctive device fingerprint. By comparing the observed interference signature against the known fingerprint of the legitimate UE, the gNB can determine whether the received signal originates from an authorized transmitter. Persistent
interference that fails to match the UE fingerprint, yet consistently appears during its scheduled uplink transmissions, constitutes a strong indicator of an external attacker exploiting insider scheduling information. By combining temporal correlation analysis with RF fingerprinting, network operators can substantially improve the resilience of 5G-NR systems against this class of insider-assisted attacks, where the adversary leverages partial knowledge of the scheduling state to degrade uplink performance selectively and covertly. VII. C ONCLUSION AND F UTURE W ORK This paper presents an investigation into selective and stealthy jamming attacks in 5G-NR environments, with a particular focus on the PUSCH channel. We introduce STORMRJ and demonstrate how it can efficiently target uplink transmissions by exploiting UL-Grant information obtained via a backdoor embedded in the UE. By using this information, STORM-RJ is able to align interference precisely in both time and frequency, selectively jamming the assigned RBs while remaining undetectable through conventional spectral analysis. Experimental results revealed that low-level tuning significantly outperforms high-level tuning in terms of latency, enabling center frequency adjustments with microsecond-level responsiveness and facilitating a real time attack. Jidle was introduced and used to characterize the temporal distribution of the interference, illustrating how STORM-RJ can flexibly degradate PUSCH channel. By combining fast frequency tuning and burst preselection, the system achieves a high degree of temporal accuracy and energy efficiency. Future research will focus on four main directions. First, we intend to extend the attack framework to target downlink communications by jamming the PDSCH. This requires ultra-lowlatency execution, as the time between downlink grant (DLGrant) reception and actual downlink transmission is less than 1 ms. Second, we plan to evaluate the proposed attack under more realistic conditions, introducing variables such as UE mobility, multi-path fading, and concurrent transmissions from multiple UEs exploiting Arena, an open-access SDR-based
JOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020
testbed featuring 64 ceiling-mounted antennas and 24 symbollevel synchronized radios[40]. These scenarios will help assess the scalability, effectiveness, and robustness of STORM-RJ in practical deployments. Third, a comprehensive end-toend latency analysis will be conducted to characterize all timing contributions involved in the reactive jamming pipeline, including UE-side DCI processing time. Fourth, the security implications of the proposed attack will be investigated in the context of Open Radio Access Network (O-RAN) architectures [41]. The open and standardized interfaces introduced by O-RAN may further expand the attack surface exploitable by a reactive jammer, as scheduling information could be intercepted at multiple points along the disaggregated RAN chain. Assessing the feasibility and impact of STORM-RJ in an O-RAN deployment represents a natural and timely extension of this research. ACKNOWLEDGMENT This work was partially supported by the European Union Next Generation EU under the Italian National Recovery and Resilience Plan (NRRP), Mission 4, Component 2, Investment 1.3, CUPE83C22004640001, CUP E63C22002070006, CUP F83C22001690001, and CUP B53C22004050001, partnership on “Telecommunications of the Future”, PE00000001 - program “RESTART”, and Investement 7PE00000014 - CUP D33C22001300002, program SERICS. R EFERENCES [1] S. Chen and J. Zhao, “The requirements, challenges, and technologies for 5g of terrestrial mobile telecommunication,” IEEE Communications Magazine, vol. 52, no. 5, pp. 36–43, 2014. [2] M. Harvanek, J. Bolcek, J. Kufa, L. Polak, M. Simka, and R. Marsalek, “Survey on 5g physical layer security threats and countermeasures,” Sensors (Basel, Switzerland), vol. 24, no. 17, p. 5523, 2024. [3] R. Alaimo et al., “Undercover disruption: Stealth jamming attacks on 5g synchronization stages,” 2025. In Proceedings of ITASEC-2025, (Bologna, Italy). [4] H. Pirayesh and H. Zeng, “Jamming attacks and anti-jamming strategies in wireless networks: A comprehensive survey,” IEEE Communications Surveys & Tutorials, vol. 24, no. 2, pp. 767–809, 2022. [5] Y. Arjoune and S. Faruque, “Smart jamming attacks in 5g new radio: A review,” in 2020 10th Annual Computing and Communication Workshop and Conference (CCWC), pp. 1010–1015, 2020. [6] M. E. Flores, D. D. Poisson, C. J. Stevens, A. V. Nieves, and A. M. Wyglinski, “Implementation and evaluation of a smart uplink jamming attack in a public 5g network,” IEEE Access, vol. 11, pp. 75993–76007, 2023. [7] F. Chen, X. Li, Y. Zhang, and Y. Jiang, “Design and implementation of initial cell search in 5g nr systems,” China Communications, vol. 17, no. 5, pp. 38–49, 2020. [8] R. Alaimo, I. Tinnirello, and D. Garlisi, “Exploiting dci leakage: A stealthy 5g uplink jamming attack using compromised ue,” in 2025 IEEE International Conference on Omni-layer Intelligent Systems (COINS), pp. 1–6, 2025. [9] Z. Kostic, I. Maric, and X. Wang, “Fundamentals of dynamic frequency hopping in cellular systems,” IEEE Journal on Selected Areas in Communications, vol. 19, no. 11, pp. 2254–2266, 2001. [10] V. B. Ristić, B. M. Todorović, and N. M. Stojanović, “Frequency hopping spread spectrum: History, principles and applications,” Vojnotehnicki glasnik/Military Technical Courier, vol. 70, no. 4, pp. 856– 876, 2022. [11] C. Laskos, A. Zubow, and F. Dressler, “Latency analysis of sdrbased experimental c-ran / o-ran systems,” in 2025 IEEE International Conference on Communications Workshops (ICC Workshops), pp. 893– 898, 2025.
13
[12] N. B. Truong, Y.-J. Suh, and C. Yu, “Latency analysis in gnu radio/usrpbased software radio platforms,” in MILCOM 2013 - 2013 IEEE Military Communications Conference, pp. 305–310, 2013. [13] https://www.sharetechnote.com/html/5G/5G FrameStructure.html. [14] J. Flores de Valgas, J. F. Monserrat, and H. Arslan, “Flexible numerology in 5g nr: Interference quantification and proper selection depending on the scenario,” Mobile Information Systems, vol. 2021, no. 1, p. 6651326, 2021. [15] 3GPP, “Ts 138.211.” https://www.etsi.org/deliver/etsi ts/138200 138299/138211/18.02.00 60/ts 138211v180200p.pdf. [16] “TS 38.211 - NR; NR and NG-RAN Overall Description.” https://www.etsi.org/deliver/etsi ts/138200 138299/138211/18.06.00 60/ts 138211v180600p.pdf?utm source=chatgpt.com, 2024. Release 17, version 17.6.0. [17] 3GPP, “Ts 138.214.” https://www.etsi.org/deliver/etsi ts/138200 138299/138214/16.02.00 60/ts 138214v160200p.pdf. [18] M. Mamode and T. P. Fowdur, “Comparative analysis of scheduling algorithms in 5g uplink transmission,” Journal of Engineering Research and Sciences, 2022. [19] N. Patriciello, S. Lagen, L. Giupponi, and B. Bojovic, “The impact of nr scheduling timings on end-to-end delay for uplink traffic,” in 2019 IEEE Global Communications Conference (GLOBECOM), pp. 1–6, 2019. [20] S. A. Roseline and S. Geetha, “A comprehensive survey of tools and techniques mitigating computer and mobile malware attacks,” Computers & Electrical Engineering, vol. 92, p. 107143, 2021. [21] https://www.sharetechnote.com/html/5G/5G CellSearch.html. [22] A. Omri et al., “Synchronization procedure in 5g nr systems,” IEEE Access, vol. 7, pp. 41286–41295, 2019. [23] https://github.com/free5G/free5GRAN. [24] O. Project, “Open5gs.” https://open5gs.org/, 2024. [25] S. Project, “Srsran 4g.” https://docs.srsran.com/projects/project/en/ latest/, 2024. [26] S. 4G, “Srsran 4g.” https://www.srsran.com/4g, 2024. [27] S. Mangione, A. Dino, G. Garbo, and D. Croce, “Crystal oscillator error compensation in software defined radios for 5g network testbeds,” in 2024 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), pp. 1–5, 2024. [28] M. Stapelberg, “inspectrum: A tool for analysing captured signals.” https://github.com/miek/inspectrum, 2015. Accessed: 2025-12-04. [29] iPerf.fr, “iperf3 user documentation.” https://iperf.fr/iperf-doc.php. [30] ShareTechnote, “5g frequency range and bandwidth.” https://www. sharetechnote.com/html/5G/5G FR Bandwidth.html. [31] 3GPP, “Ts 138.214.” https://www.etsi.org/deliver/etsi ts/138200 138299/138213/16.02.00 60/ts 138213v160200p.pdf. [32] “TS 38.104 - NR; NR and NG-RAN Overall Description.” https://www.etsi.org/deliver/etsi ts/138100 138199/138104/16.04. 00 60/ts 138104v160400p.pdf, 2024. Release 17, version 17.6.0. [33] C. Shannon, “Communication in the presence of noise,” Proceedings of the IRE, vol. 37, no. 1, pp. 10–21, 1949. [34] 3GPP, “Ts 138.321.” https://www.etsi.org/deliver/etsi ts/138300 138399/138321/17.14.00 60/ts 138321v171400p.pdf. [35] Ettus Research, “Usrp n310 product page.” https://www.ettus.com/ all-products/usrp-n310/, 2025. Accessed: 2025-12-04. [36] Ettus Research, “Usrp n310 product page.” https://files.ettus.com/ manual/page usrp n3xx.html, 2025. Accessed: 2025-12-04. [37] ShareTechnote, “5g/nr-harq.” https://www.sharetechnote.com/html/5G/ 5G HARQ.html. [38] H. Pirayesh and H. Zeng, “Jamming attacks and anti-jamming strategies in wireless networks: A comprehensive survey,” IEEE communications surveys & tutorials, vol. 24, no. 2, pp. 767–809, 2022. [39] J. Zhang, F. Ardizzon, M. Piana, G. Shen, and S. Tomasin, “Physical layer-based device fingerprinting for wireless security: From theory to practice,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 5296–5325, 2025. [40] L. Bertizzolo, L. Bonati, E. Demirors, A. Al-Shawabka, S. D’Oro, F. Restuccia, and T. Melodia, “Arena: A 64-antenna sdr-based ceiling grid testing platform for sub-6 ghz 5g-and-beyond radio spectrum research,” Computer Networks, vol. 181, p. 107436, 2020. [41] M. Polese, L. Bonati, S. D’Oro, S. Basagni, and T. Melodia, “Understanding o-ran: Architecture, interfaces, algorithms, security, and research challenges,” IEEE Communications Surveys & Tutorials, vol. 25, no. 2, pp. 1376–1411, 2023.