From 2G to 5G: Literature Review of Identification and Location Attacks in Cellular Networks
Abstract
1. Introduction
- Section 1. Introduction to the context, motivation of the study, issues, objectives, contributions
- Section 2. Systematic review methodology, protocol, research questions
- Section 3. Theoretical foundations of identification and location mechanisms and conceptual framework
- Section 4. Review results, distribution and taxonomy of attacks, experimental techniques
- Section 5. Analysis of results, answers to Research Questions (RQs), vulnerabilities, limitation, mitigation measures and future directions
- Section 6. Study conclusions
2. Review Methodology
2.1. Protocol and Guideline Used
- Plan Review: formulating the study objectives, formulating research questions, choosing the protocol, choosing data sources and designing the search strategy, formulating inclusion/exclusion criteria and drafting the data extraction scheme.
- Conduct Review: execution of searches, results management, step-by-step screening (title, abstract, full-text), application of selection criteria and assessment of study quality.
- Document Review: organizing results, synthesizing findings, discussing limitations and formulating implications (operators, UE, standardization).
2.2. Research Questions (RQ)
- 1.
- RQ1: What types of identification and location attacks are documented in cellular networks and how can they be classified?This question aims to identify and classify the main types of attacks according to 2G–5G generation, capability (passive, semi-passive, active), vectors and procedures exploited (PHY/MAC/RRC/NAS/Core; paging, attach/registration, measurement, inter-RAT/downgrade, SS7/Diameter), nature of the attack (identification, location) and affected component (RAN/Core) [11] (PHY = Physical Layer; MAC = Medium Access Control; RRC = Radio Resource Control; NAS = Non-Access Stratum; Core = Core Network; inter-RAT = inter-Radio Access Technology; SS7 = Signaling System No. 7; Diameter = authentication, authorization, and accounting protocol used in mobile core networks; RAN = Radio Access Network).
- 2.
- RQ2: What are the capabilities and resources required to carry out these attacks?This question investigates the attack model described in the literature (cost, range, and technical complexity).
- 3.
- RQ3: What performance do the studies report?This question targets the metrics identified in the literature, targeting both qualitative and quantitative aspects (identification success rate, location accuracy, time, detectability).
- 4.
- RQ4: What countermeasures are described (standard, operator, mobile terminal), what is their effectiveness and what are the associated limitations?This question aims to classify countermeasures as follows: standard, operator-implemented, mobile terminal-level measurements, detection solutions (rule-based, crowd-sourcing).
- 5.
- RQ5: How does the attack surface evolve from 2G to 5G and what vulnerabilities persist?This question analyzes what vulnerabilities persist due to cross-generation compatibility and inter-RAT scenarios (fallback/downgrade, NSA anchoring).
2.3. Used Data Sources and Databases
- Elsevier: the platform that includes scientific journals in the field of communications, computer security, etc.
- IEEE Xplore Digital Library: database that includes articles published in IEEE journals and conferences relevant to cellular network security.
- Springer: database that includes papers published in journals and conference proceedings in the field of network security.
- Google Scholar: it was not used as the primary database in the systematic search, but rather as a complementary tool for snowballing, verifying citations, identifying related works, and accessing the full text of articles initially found in IEEE Xplore, ScienceDirect, or SpringerLink.
2.4. Search Strategy
2.4.1. IEEE Xplore
- Content type: Journals + Conferences
- Publication years: Years: 2018–2026
- Language: English
- Sort by: relevance
2.4.2. Elsevier/ScienceDirect
2.4.3. Springer
2.5. Inclusion and Exclusion Criteria
- IC1: Studies investigating user identification and location in 2G–5G cellular networks.
- IC2: Attacks that exploit network vectors (IMSI/TMSI/SUPI/SUCI, paging, TAC/LAI/TAI, Cell-ID/ECGI, timing advance, handover, RRC/NAS/S1AP, broadcast/system information).
- IC3: Studies published in journals, conference proceedings, or academic volumes, with full-text access available.
- IC4: Clarity of the attack mechanism or network vulnerabilities.
- IC5: Studies that include experimental results, analytical evaluation, simulation results, measurement-based evidence, or technically grounded discussion relevant to the research questions.
- IC6: Studies presenting countermeasures (operator/UE/detection/standard).
- EC1: Studies dealing with identification and location without connection to cellular networks.
- EC2: Studies without sufficient technical data.
- EC3: Studies without access to the full content.
- EC4: Studies outside the 2018–2026 timeframe.
- EC5: Studies on non-cellular technologies.
- EC6: Studies published in non-scientific formats.
2.6. Study Selection Process—Adapted PRISMA-Like Flow
- E1: Identification of studies: records from several academic databases, including IEEE Xplore, ScienceDirect, and SpringerLink, were collected and aggregated into a working database representing the initial set of candidate studies for analysis.
- E2: Identifying and removing duplicates: duplicate records were removed based on predefined criteria (title, authors, year) and the most complete versions were kept, the result being a unique set of records.
- E3: Title, abstract, and keyword screening: only the criteria that could be reliably assessed from the available bibliographic information were applied, namely IC1–IC3 and EC1–EC3. This step retained records that addressed identification or location attacks in 2G–5G cellular networks, relied on relevant cellular-network vectors, and were published in scientific venues with full-text access available.
- E4: Full-text eligibility assessment: the remaining studies were analyzed by examining their full content and applying the complete set of inclusion and exclusion criteria, namely IC1–IC6 and EC1–EC6. This step verified whether each study provided a clear attack mechanism or vulnerability description, reported experimental results, analytical evaluation, simulation results, measurement-based evidence, or technically grounded discussion, and, where applicable, presented relevant countermeasures. Studies outside the temporal scope, focused on non-cellular technologies, published in non-scientific formats, or providing only general descriptions without sufficient technical detail were excluded.
- E5: Final set of included studies: the studies that satisfied the full-text eligibility assessment formed the final corpus of the review and were subsequently used for data extraction and quality assessment (QA).
2.7. Data Extraction Diagram
2.8. Quality Assessment (QA) and Risk of Bias (0–12)
- QA1. Are the study objectives clearly defined?
- QA2. Is the technological context of the study clearly described?
- QA3. Are the attack model and assumptions clearly described?
- QA4. Is the methodology used described in detail for understanding the study?
- QA5. Are the exploited technical mechanisms identified?
- QA6. Does the study present relevant technical analysis?
- QA7. Are the attack metrics and results present?
- QA8. Are the limits and conditions of the attack discussed?
- QA9. Does the study reveal the impact on user security?
- QA10. Are mitigation mechanisms proposed?
- QA11. Is the research relevant to 2G–5G identification or location attacks?
- QA12. Can the attack be reproduced or understood?
- High (10–12): strong contribution.
- Medium (7–9): useful evidence, but with some limitations.
- Low (4–6): mainly indicative findings.
- Very low (0–3): context only.
- RoB1. Selection bias: analyzing certain technologies in isolation
- RoB2. Methodological bias: the study methodology is not described clearly enough
- RoB3. Experimental bias: experiment difficult to replicate
- RoB4. Reporting bias: positive results of experiments without failures or false positives
- Low: solid method with clear assumptions.
- Moderate: credible results with limitations.
- High: incomplete method with indicative results.
2.9. Synthesis Method
3. Technical Fundamentals and Conceptual Framework
3.1. Cellular Network Architecture (2G–5G)
3.1.1. 2G/GSM Architecture
3.1.2. 3G/UMTS Architecture
3.1.3. 4G/LTE Architecture
3.1.4. 5G Architecture
3.2. Identification Mechanisms in Cellular Networks (IMSI, TMSI, GUTI, SUCI)
3.3. Location Mechanisms in Cellular Networks
- Intra-cell handover: connection transfer within the same cell (between different radio channels)
- Inter-cell handover: the connection is transferred between two different base stations
- Inter-RAT handover: the connection is transferred between different radio technologies (LTE to 3G)
3.4. Attacker Model
3.5. IMSI Catcher Concept
3.6. Evolution of Protection Mechanisms (2G to 5G)
4. Review Results
4.1. Distribution of Studies
4.2. Taxonomy of Identification and Location Attacks
4.2.1. Classification by Adversary’s Capabilities
4.2.2. Classification by the Exploited Technical Mechanism
4.2.3. Classification by Operational Result of the Attack
4.2.4. Classification by Target Identifier
- Permanent identifiers: SUPI (5G), IMSI (2G–4G)
- Temporary identifiers: 5G-GUTI (5G), TMSI (2G), GUTI/S-TMSI (4G)
- Protected identifiers: SUCI (5G)
4.2.5. Classification by Network Generation
4.3. Experimental Techniques Used in Studies
4.3.1. LTE/5G Radio Infrastructure Emulation
4.3.2. Measurements in Real-World Networks
4.3.3. Signal Analysis
4.3.4. Simulation of Mobility and Paging Scenarios
4.3.5. RF Fingerprinting and Machine Learning
4.3.6. Cryptographic Evaluation
5. Analysis and Discussion
5.1. Answers to RQs
5.2. Persistent Vulnerabilities Between Generations
5.3. Mitigation Measures
5.3.1. Standardized Solutions (3GPP)
- Mutual authentication: reduces the attack surface for fake base station attacks [69];
- Use of temporary identifiers (TMSI/GUTI): replacing IMSI with temporary identifiers and relocating them more frequently without being reused frequently;
- Permanent identity protection (SUCI): rsignificantly reduces permanent identity exposure at the time of authentication [70];
- Downgrade prevention/inter-RAT: network policies to limit the transition to legacy 2G technologies;
5.3.2. Academic Solutions
- Methods for detecting fake base stations, including IMSI catcher and rogue base station scenarios: are based on the detection of inconsistencies (unusual cell parameters, lack of encryption, sudden changes), protocol inconsistency, machine learning models to distinguish legitimate from suspicious cells, Crowd-sourcing (aggregation of observations), machine learning models for classification [74].
- New identity protection schemes: pseudonym changes to prevent correlation, synchronized change mechanisms [77].
- Identifier protection: improved cryptographic schemes for identifiers.
- Reducing the possibility of paging correlation: paging randomization.
5.3.3. Commercial Solutions
- Fake base station and IMSI catcher detection systems (operator-side): commercial Mobile Threat Defense (MTD) products;
- Terminal applications (UE-side): to detect abnormal network behavior and alert the user;
- Threat intelligence and monitoring solutions: systems for detecting patterns associated with abuse [81];
5.3.4. Comparisons
5.4. Limitations of the Review
5.5. Recommendations for Future Research
5.6. Responsible Use Statement
6. Conclusions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| BTS | Base Transceiver Station |
| CN | Core Network |
| ECGI | E-UTRAN Cell Global Identifier |
| eNB | evolved NodeB |
| EPS-AKA | Evolved Packet System Authentication and Key Agreement |
| GGSN | Gateway GPRS Support Node |
| gNB | next generation NodeB |
| GUTI | Globally Unique Temporary UE Identity |
| 5G-GUTI | 5G Globally Unique Temporary UE Identity |
| SUCI | Subscription Concealed Identifier |
| SUPI | Subscription Permanent Identifier |
| MIB | Master Information Block |
| MME | Mobility Management Entity |
| MS | Mobile Station |
| MSC | Mobile Switching Center |
| NAS | Non-Access Stratum |
| NSA | Non-Standalone |
| O-RAN | Open Radio Access Network |
| HLR | Home Location Register |
| HSS | Home Subscriber Server |
| IMSI | International Mobile Subscriber Identity |
| inter-RAT | inter-Radio Access Technology |
| LAI | Location Area Identity |
| LTE | Long-Term Evolution |
| PDN | Packet Data Network |
| VLR | Visitor Location Register |
| SA | Standalone |
| SDR | Software-Defined Radio |
| AKA | Authentication and Key Agreement |
| AMF | Access and Mobility Management Function |
| AUSF | Authentication Server Function |
| BSC | Base Station Controller |
| SGSN | Serving GPRS Support Node |
| SGW | Serving Gateway |
| SIB | System Information Block |
| S1AP | S1 Application Protocol |
| SMF | Session Management Function |
| SS7 | Signaling System No. 7 |
| TAC | Tracking Area Code |
| TAI | Tracking Area Identity |
| TAU | Tracking Area Update |
| PGW | Packet Data Network Gateway |
| PHY | Physical Layer |
| PSTN | Public Switched Telephone Network |
| RAN | Radio Access Network |
| RNC | Radio Network Controller |
| RRC | Radio Resource Control |
| RSRP | Reference Signal Received Power |
| RSRQ | Reference Signal Received Quality |
| UPF | User Plane Function |
| TMSI | Temporary Mobile Subscriber Identity |
| UE | User Equipment |
| UMTS | Universal Mobile Telecommunications System |
Appendix A. Included Studies and Extracted Data
| ID | Authors | Title | Year | Source | Attack Type/Category | Generation | Exploited Mechanism | Adversary Model | Reported Metrics | Countermeasures/Solutions |
|---|---|---|---|---|---|---|---|---|---|---|
| S001 | A. A. R. Alsaeedy; E. K. P. Chong [72] | Tracking Area Update Procedure Unnecessary in 5G: Improving User Experience and Offloading Signaling Overhead | 2018 | IEEE Xplore; https://repository.qu.edu.iq/wp-content/uploads/sites/31/2024/09/Tracking-Area-Update.pdf (accessed on 19 March 2026) | Location tracking & mobility privacy; Semi-passive | 5G | paging; tracking area/update; mobility/location management | Semi-passive | Signaling overhead; UE power consumption; paging reachability/efficiency | gNB-based UE Mobility Tracking (UeMT); shifting location tracking from UE-triggered TAU to gNB/network-side tracking |
| S002 | L. Abdelrazek; M. A. Azer [5] | User Privacy in Legacy Mobile Network Protocols | 2018 | IEEE Xplore; https://doi.org/10.1109/icsrs.2018.8688870 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 2G/3G/4G legacy networks | IMSI/subscriber identity; paging/location management; signalling security | Semi-passive | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S003 | R. Ghannam; F. Sharevski; A. Chung [28] | User-targeted Denial-of-Service Attacks in LTE Mobile Networks | 2018 | IEEE Xplore; https://www.researchgate.net/publication/329953228_User-targeted_Denial-of-Service_Attacks_in_LTE_Mobile_Networks (accessed on 19 March 2026) | Rogue/fake base stations; Active | 4G/LTE | authentication privacy; rogue base station; signalling security | Active | Attack feasibility in LTE testbed; user-targeted service disruption; DoS impact | Not reported |
| S004 | Garima SinghDeepti Shrimankar [35] | A privacy-preserving authentication protocol with secure handovers for the LTE/LTE-A networks | 2018 | SpringerLink; https://www.ias.ac.in/public/Volumes/sadh/043/08/0128.pdf (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 4G/LTE-A | Authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Privacy-preserving authentication protocol with secure handovers for LTE/LTE-A |
| S005 | Mohsin KhanPhilip GinzboorgKimmo JärvinenValtteri Niemi [18] | Defeating the Downgrade Attack on Identity Privacy in 5G | 2018 | SpringerLink; https://arxiv.org/abs/1811.02293 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 5G | privacy | Active adversary, typically rogue/fake base station or malicious network element | Not reported | LTE pseudonym-based identity protection; LTE pseudonym update integrated into 5G identity privacy procedure |
| S006 | Mihajlo Pavloski [42] | Signalling Attacks in Mobile Telephony | 2018 | SpringerLink; https://doi.org/10.1007/978-3-319-95189-8_12 (accessed on 19 March 2026) | Protocol and signalling security; Passive | Not reported | signalling security | Passive | Not reported | Not reported |
| S007 | Alaa A. R. Alsaeedy and Edwin K. P. Chong [7] | Tracking Area Update and Paging in 5G Networks: a Survey of Problems and Solutions | 2018 | SpringerLink; https://www.researchgate.net/publication/328579958_Tracking_Area_Update_and_Paging_in_5G_Networks_a_Survey_of_Problems_and_Solutions (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 5G | paging; tracking area/update; mobility/location management | Not applicable/survey or review | Paging overhead; Tracking Area Update (TAU) overhead; signaling overhead | Surveyed solutions for TAU reduction, paging optimization and tracking-area/location-management design |
| S008 | H. Kim; J. Lee; E. Lee; Y. Kim [15] | Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane | 2019 | IEEE Xplore; https://doi.org/10.1109/SP.2019.00038 (accessed on 19 March 2026) | Protocol and signalling security; Active | 4G/LTE | LTE control-plane procedures; unauthenticated signalling messages; protocol-state and implementation vulnerabilities | Active | Security vulnerabilities and practical control-plane attacks | Dynamic security analysis; control-plane message protection; protocol-state validation |
| S009 | B. Aamer; H. Chergui; N. Chergui; K. Tourki; M. Benjillali; C. Verikoukis; M. Debbah [40] | Self-Tuning Spectral Clustering for Adaptive Tracking Areas Design in 5G Ultra-Dense Networks | 2019 | IEEE Xplore; https://arxiv.org/abs/1902.01342 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 5G | paging; tracking area/update; mobility/location management | Semi-passive | Q-metric; silhouette score; number of TAs; TAUs; paging requests/average paging requests per TA | Self-tuning spectral clustering for adaptive tracking-area design |
| S010 | A. Ali; G. Fischer [37] | Symbol-Based Statistical RF Fingerprinting for Fake Base Station Identification | 2019 | IEEE Xplore; https://doi.org/10.1109/RADIOELEK.2019.8733585 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Cellular networks | RF fingerprinting; amplitude and phase error characteristics; fake base station identification | Active adversary operating a fake or rogue base station | Amplitude and phase error statistics; RF fingerprinting classification and detection indicators | Symbol-based statistical RF fingerprinting for fake base station identification |
| S011 | A. Koutsos [47] | The 5G-AKA Authentication Protocol Privacy | 2019 | IEEE Xplore; https://arxiv.org/abs/1811.06922 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | Authentication/key agreement; subscriber identity protection; handover security | Active | Formal/privacy proof metrics; sigma-unlinkability; mutual authentication proof | Modified 5G-AKA protocol to prevent privacy attacks while retaining cost/efficiency constraints |
| S012 | A. Ali; G. Fischer [79] | The Phase Noise and Clock Synchronous Carrier Frequency Offset based RF Fingerprinting for the Fake Base Station Detection | 2019 | IEEE Xplore; https://ieeexplore.ieee.org/document/8765471/ (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Phase noise; clock-synchronous carrier frequency offset; RF fingerprint separability/detection indicators | RF fingerprinting using phase noise and clock-synchronous CFO for fake base station detection |
| S013 | Hashim A. Hashim and Mohammad A. Abido [32] | Location management in LTE networks using multi-objective particle swarm optimization | 2019 | ScienceDirect; https://arxiv.org/abs/1905.01136 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 4G/LTE | paging; tracking area/update; mobility/location management | Semi-passive | Total signaling overhead; TAU and paging cost; inter-list handover; power/battery consumption; comparison with MINLP | Multi-objective particle swarm optimization (MOPSO) for LTE location-management optimization |
| S014 | Ginés Escudero-AndreuKonstantinos KyriakopoulosJames A. FlintSangarapillai Lambotharan [41] | Detecting Signalling DoS Attacks on LTE Networks | 2019 | SpringerLink; https://repository.lboro.ac.uk/articles/conference_contribution/Detecting_signalling_DoS_attacks_on_LTE_networks/9548273/files/17179283.pdf (accessed on 19 March 2026) | Protocol and signalling security; Active | 4G/LTE | signalling security | Active | Time to collapse system; request rate (500 service requests/s); signalling DoS detection performance | Detection of LTE signalling DoS attacks using observable signalling/request behavior |
| S015 | F. Xu; Z. Tu; Y. Li [53] | Connecting the Dots: User Privacy is not Preserved in ID-Removed Cellular Data | 2020 | IEEE Xplore; https://www.researchgate.net/publication/315870338_Trajectory_Recovery_From_Ash_User_Privacy_Is_NOT_Preserved_in_Aggregated_Mobility_Data (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | privacy | Passive or semi-passive adversary using mobility/signalling/location data | Re-identification/record association effectiveness; trajectory/mobility pattern recovery | ID removal is shown insufficient; privacy implication is need for stronger anonymization than simple identifier removal |
| S016 | Fardan; Istikmal; I. Mawaldi; T. Anugraha; I. Ginting; N. Karna [30] | Experimental Security Analysis for Fake eNodeB Attack on LTE Network | 2020 | IEEE Xplore; https://doi.org/10.1109/isriti51436.2020.9315427 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 4G/LTE | IMSI/subscriber identity; fake base station; fake eNodeB | Active | Not reported | Not reported |
| S017 | M. Saedi; A. Moore; P. Perry; M. Shojafar; H. Ullah; J. Synnott; R. Brown; I. Herwono [46] | Generation of realistic signal strength measurements for a 5G Rogue Base Station attack scenario | 2020 | IEEE Xplore; https://pure.ulster.ac.uk/files/90882336/09162275.pdf (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Signal strength measurements; synthetic/realistic RSRP/RSSI-style datasets for RBS investigation | Generation of realistic signal-strength data to support rogue base station detection/investigation |
| S018 | H. Qi; Y. Shen; B. Yin [13] | Intelligent Trajectory Inference Through Cellular Signaling Data | 2020 | IEEE Xplore; https://www.researchgate.net/publication/312668648_On_location_privacy_in_LTE_networks (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | tracking/inference; location privacy/inference; signalling security | Passive or semi-passive adversary using mobility/signalling/location data | Not reported | Not reported |
| S019 | J. J. Checa; S. Tomasin [4] | Location-Privacy-Preserving Technique for 5G mmWave Devices | 2020 | IEEE Xplore; https://www.researchgate.net/publication/343782892_Location-Privacy_Preserving_Technique_for_5G_mmWave_Devices (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | fake base station; location privacy/inference; privacy | Active | Location privacy metric based on localization information/CRB-style evaluation | Location-privacy-preserving technique for 5G mmWave devices; beamforming/location privacy protection |
| S020 | M. Pauliac [70] | USIM in 5G Era | 2020 | IEEE Xplore; https://www.researchgate.net/publication/393945539_A_survey_of_existing_attacks_on_5G_SA (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication privacy; privacy | Passive | Not applicable; overview article | USIM/5G privacy and security features: authentication schemes, subscriber privacy, Steering of Roaming, UE Parameters Update over NAS, Long-Term Key Update |
| S021 | Haibat Khan and Keith M. Martin [48] | A survey of subscription privacy on the 5G radio interface - The past, present and future | 2020 | ScienceDirect; https://eprint.iacr.org/2020/101.pdf (accessed on 19 March 2026) | General cellular security/privacy; Passive | 5G | privacy | Not applicable/survey or review | Not applicable; survey paper | Countermeasures classified into cryptographic methods, human factors, and intrusion detection methods |
| S022 | An Braeken [6] | Symmetric key based 5G AKA authentication protocol satisfying anonymity and unlinkability | 2020 | ScienceDirect; https://www.researchgate.net/publication/342979788_Symmetric_key_based_5G_AKA_authentication_protocol_satisfying_anonymity_and_unlinkability (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Passive | Computational/communication efficiency; security properties: anonymity and unlinkability | Symmetric-key-based 5G-AKA protocol satisfying anonymity and unlinkability |
| S023 | S. Sivasankar; R. Challa [27] | Closed Loop Paging Optimization for Efficient Mobility Management | 2021 | IEEE Xplore; https://researchr.org/publication/ccnc-2021 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | paging; tracking area/update; mobility/location management | Semi-passive | Paging efficiency/signaling overhead | Closed-loop paging optimization for mobility management |
| S024 | D. Orlando; I. Palamà; S. Bartoletti; G. Bianchi; N. B. Melazzi [57] | Design and Experimental Assessment of Detection Schemes for Air Interface Attacks in Adverse Scenarios | 2021 | IEEE Xplore; https://arxiv.org/abs/2106.07199 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | rogue base station | Active | Detection probability (Pd) curves; performance under adverse scenarios; SDR LTE experiment | Three GLRT-based detection schemes using data from off-the-shelf receivers |
| S025 | I. Bang; T. Kim; H. S. Jang; D. K. Sung [24] | Impact of Uplink Power Control on User Location Tracking Attacks in Cellular Networks | 2021 | IEEE Xplore; https://icc2021.ieee-icc.org/program/technical-symposia.html (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | tracking/inference; location privacy/inference; privacy | Passive or semi-passive adversary using mobility/signalling/location data | Location tracking performance under uplink power control | Uplink power control considered as factor/mitigation for user location tracking attacks |
| S026 | I. Karim; S. R. Hussain; E. Bertino [2] | ProChecker: An Automated Security and Privacy Analysis Framework for 4G LTE Protocol Implementations | 2021 | IEEE Xplore; https://www.researchgate.net/publication/399371469_Leveraging_Hardware_Hacking_Tools_for_Unveiling_Vulnerabilities_in_Internet_of_Things_IoT_Devices_A_Comprehensive_Review (accessed on 19 March 2026) | Protocol and signalling security; Active | 4G/4G/LTE | privacy | Active | Number/types of detected specification violations or logical vulnerabilities | Automated security and privacy checking framework for 4G LTE protocol implementations |
| S027 | F. Liu; L. Su; B. Yang; H. Du; M. Qi; S. He [25] | Security Enhancements to Subscriber Privacy Protection Scheme in 5G Systems | 2021 | IEEE Xplore; https://www.researchgate.net/publication/367620100_Latest_Advances_on_Security_Architecture_for_5GTechnology_and_Services (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | SUCI/concealed identifier; SUPI/permanent identifier; privacy | Passive | Not reported | Security enhancements to subscriber privacy protection scheme in 5G systems |
| S028 | Ivan Palamà and Francesco Gringoli and Giuseppe Bianchi and Nicola Blefari-Melazzi [22] | IMSI Catchers in the wild: A real world 4G/5G assessment | 2021 | ScienceDirect; https://www.researchgate.net/publication/393170131_FlashCatch_Minimizing_Disruption_in_IMSI_Catcher_Operations (accessed on 19 March 2026) | Rogue/fake base stations; Active | 4G/5G | rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | IMSI catcher assessment; mitigation not reported |
| S029 | Tong ZhangMeihua XiaoRi Ouyang [69] | Proving Mutual Authentication Property of 5G-AKA Protocol Based on PCL | 2021 | SpringerLink; https://doi.org/10.1007/978-981-16-7443-3_13 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S030 | J. Zhao; Q. Li; Z. Yuan; Z. Zhang; S. Lu [44] | 5G Messaging: System Insecurity and Defenses | 2022 | IEEE Xplore; https://www.researchgate.net/publication/365604755_5G_Messaging_System_Insecurity_and_Defenses (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 5G | 5G messaging service; unauthenticated or weakly protected messaging procedures | Semi-passive | Not reported | Defenses for 5G messaging service insecurity |
| S031 | I. Bang; T. Kim; H. S. Jang; D. K. Sung [33] | An Opportunistic Power Control Scheme for Mitigating User Location Tracking Attacks in Cellular Networks | 2022 | IEEE Xplore; https://ieeexplore.ieee.org/document/9715139/ (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | tracking/inference; location privacy/inference; privacy | Passive or semi-passive adversary using mobility/signalling/location data | Not reported | Opportunistic power control scheme for mitigating user location tracking attacks |
| S032 | J. Shin; Y. Shin; J. -G. Park [78] | Network Detection of Fake Base Station using Automatic Neighbour Relation in Self-Organizing Networks | 2022 | IEEE Xplore; https://doi.org/10.1109/ictc55196.2022.9952901 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Detection, localization, or blacklisting method proposed |
| S033 | L. A. N. Oliveira; M. S. Alencar; W. T. A. Lopes; F. Madeiro [51] | On the Performance of Location Management in 5G Network Using RRC Inactive State | 2022 | IEEE Xplore; https://www.researchgate.net/publication/360907319_On_the_Performance_of_Location_Management_in_5G_Network_Using_RRC_Inactive_State (accessed on 19 March 2026) | Location tracking and mobility privacy; Active | 5G | paging; tracking area/update; mobility/location management | Active | Signaling cost; delay cost; simulator-based location-management performance | Genetic algorithm/optimized design using RRC Inactive State, RNA/TA association to reduce signaling cost |
| S034 | Tengshun Yang and Shuling Wang and Bohua Zhan and Naijun Zhan and Jinghui Li and Shuangqin [26] | Formal Analysis of 5G Authentication and Key Management for Applications (AKMA) | 2022 | ScienceDirect; https://doi.org/10.1016/j.sysarc.2022.102478 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S035 | Mohamed Taoufiq Damir and Valtteri Niemi [10] | Location Privacy, 5G AKA, and Enhancements | 2022 | SpringerLink; https://doi.org/10.1007/978-3-031-22295-5_3 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Semi-passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S036 | B. Aamer; H. Chergui; M. Benjillali [39] | Clustering-Enabled Tracking Areas Design for Beyond-5G Networks: A Live Network Demo | 2023 | IEEE Xplore; https://www.researchgate.net/publication/371811401_Clustering-Enabled_Tracking_Areas_Design_for_Beyond-5G_Networks_A_Live_Network_Demo (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 5G | paging; tracking area/update; mobility/location management | Semi-passive | Not reported | Clustering-enabled tracking area design for B5G networks |
| S037 | S. Kriaa; A. Feki; S. Papillon; T. Chene; I. Ouattara [74] | Detecting Fake Base Stations Using Knowledge Graphs and ML-Based Techniques | 2023 | IEEE Xplore; https://www.researchgate.net/publication/352806426_SecKG_Leveraging_attack_detection_and_prediction_using_knowledge_graphs (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | ML/knowledge graph detection metrics | Knowledge graph and ML-based fake base station detection |
| S038 | J. -H. Huang; S. -M. Cheng; R. Kaliski; C. -F. Hung [49] | Developing xApps for Rogue Base Station Detection in SDR-Enabled O-RAN | 2023 | IEEE Xplore; https://www.researchgate.net/publication/373500416_Developing_xApps_for_Rogue_Base_Station_Detection_in_SDR-Enabled_O-RAN (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Signal stability metrics; UE-reported metrics; Near-RT RIC/xApp processing not reported | xApp-based rogue base station detection in SDR-enabled O-RAN; distribution of detection outputs/metrics to UEs |
| S039 | C. Yu; S. Chen; Z. Cai [43] | LTE Phone Number Catcher: A Practical Attack Against Mobile Privacy | 2019 | Security and Communication Networks; https://doi.org/10.1155/2019/7425235 (accessed on 19 March 2026) | Identity and location privacy; Active | 4G/LTE | paging procedure; temporary identifiers; silent communication triggering; phone-number-to-radio-identifier correlation | Active | Practical association between the target phone number and LTE temporary identifiers; target presence confirmation and location tracking | Protection of paging identifiers; frequent temporary-identifier refresh; prevention of unauthorized paging triggering and identifier correlation |
| S040 | S. Basheer; G. Kumar; A. H. Nalband; C. Raveendran [83] | Securing 5G Networks: Strategies for Prevention, Detection, and Mitigation of Rogue Base Stations | 2023 | IEEE Xplore; https://doi.org/10.1109/icstcee60504.2023.10585168 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Detection, localization, or blacklisting method proposed |
| S041 | Zaher Haddad [77] | Blockchain-enabled anonymous mutual authentication and location privacy-preserving scheme for 5G networks | 2023 | ScienceDirect; https://www.scribd.com/document/637788795/Blockchain-enabled-anonymous-mutual-authentication-and-location (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Semi-passive | Security analysis; performance evaluation/efficiency compared with existing schemes | Blockchain + pseudonym-based anonymous mutual authentication and location privacy preservation |
| S042 | Teng Fei and Wenye Wang [31] | The vulnerability and enhancement of AKA protocol for mobile authentication in LTE/5G networks | 2023 | ScienceDirect; https://doi.org/10.1016/j.comnet.2023.109685 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 4G/LTE/5G | authentication/key agreement; subscriber identity protection; handover security | Semi-passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S043 | Lie YangChien-Erh WengHsing-Chung ChenYang-Cheng-Kuang ChenYung-Cheng Yao [11] | Attacks and Threats Verification Based on 4G/5G Security Architecture | 2023 | SpringerLink; https://doi.org/10.1007/978-3-031-35836-4_26 (accessed on 19 March 2026) | General cellular security/privacy; Passive | 4G/5G | cellular security relevance | Passive | Not reported | Not reported |
| S044 | Daniel FraunholzDominik BrunkeLorenz DumanskiHartmut Koenig [60] | Automating Device Fingerprinting Attacks in 4G and 5G NSA Mobile Networks | 2023 | SpringerLink; https://doi.org/10.1007/978-3-031-30122-3_12 (accessed on 19 March 2026) | Rogue/fake base stations; Semi-passive | 4G/5G | RF fingerprinting; signal features of base stations/devices | Semi-passive | Not reported | Not reported |
| S045 | U. Dixit; S. Vittal; A. F. A [19] | A Systematic Study for Understanding the Security Risks in 5G Core Network | 2024 | IEEE Xplore; https://doi.org/10.1109/comsnets59351.2024.10427440 (accessed on 19 March 2026) | Protocol and signalling security; Active | 5G | 5G core security | Active | Not reported | Not reported |
| S046 | S. Sun; I. Abualhaol; G. Poitau; A. Esswie; M. Repeta [64] | An Ensemble Approach for Fake Base Station Detection using Temporal Graph Analysis and Anomaly Detection | 2024 | IEEE Xplore; https://doi.org/10.1109/wts60164.2024.10536680 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Detection, localization, or blacklisting method proposed |
| S047 | S. Purification; S. Wuthier; J. Kim; J. Kim; S. -Y. Chang [84] | Fake Base Station Detection and Blacklisting | 2024 | IEEE Xplore; https://doi.org/10.1109/icccn61486.2024.10637542 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Detection, localization, or blacklisting method proposed |
| S048 | W. Fan; B. Shi; C. Peng [12] | NReplay: 5G Key Reinstallation Attack Based on NAS Layer Vulnerabilities | 2024 | IEEE Xplore; https://doi.org/10.1109/milcom61039.2024.10773741 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 5G/5G NR | privacy | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Defense or mitigation discussed |
| S049 | B. C. Tedeschini; G. Kwon; M. Nicoli; M. Z. Win [54] | Real-Time Bayesian Neural Networks for 6G Cooperative Positioning and Tracking | 2024 | IEEE Xplore; https://doi.org/10.1109/jsac.2024.3413950 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 6G | tracking/inference; location privacy/inference | Semi-passive | Not reported | Location-management, paging, or tracking mitigation/optimization discussed |
| S050 | S. Purification; K. Park; J. Kim; J. Kim; S. -Y. Chang [81] | Wireless Link Routing to Secure Against Fake Base Station in 5G | 2024 | IEEE Xplore; https://doi.org/10.1109/svcc61185.2024.10637367 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Not reported |
| S051 | Samuthira Pandi V and Anitha Juliette Albert and K. Naresh Kumar Thapa and R. Krishnaprasa [86] | A novel enhanced security architecture for sixth generation (6G) cellular networks using authentication and acknowledgement (AA) approach | 2024 | ScienceDirect; https://doi.org/10.1016/j.rineng.2023.101669 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 6G | authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S052 | Z. Haddad [62] | Enhancing Privacy and Security in 5G Networks with an Anonymous Handover Protocol Based on Blockchain and Zero Knowledge Proof | 2024 | ScienceDirect; https://doi.org/10.1016/j.comnet.2024.110544 (accessed on 19 March 2026) | Identity, authentication, and location privacy; Active | 5G | anonymous authentication; handover authentication; blockchain; zero-knowledge proof; subscriber identity and location privacy protection | Active adversary attempting impersonation, replay, man-in-the-middle, or identity-tracing attacks | Security analysis; computational and communication overhead; comparison with related authentication and handover protocols | Anonymous 5G handover authentication protocol based on blockchain and zero-knowledge proof |
| S053 | Chuan Yu and Shuhui Chen and Qianqian Xing and Ziling Wei [3] | Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution | 2024 | ScienceDirect; https://doi.org/10.1016/j.comnet.2024.110814 (accessed on 19 March 2026) | Location tracking and mobility privacy; Active | 4G/LTE/5G | tracking/inference; location privacy/inference; signalling security | Active | Not reported | Not reported |
| S054 | Danmarl ButadSteven Matthew TaoHarlee TudtudAlvin Joseph MacapagalPhilip Virgil AstilloGau [80] | Fake Base Station Detection and Localization in 5G Network: A Proof of Concept | 2024 | SpringerLink; https://doi.org/10.1007/978-981-97-4465-7_1 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | rogue/fake base station; subscriber identity exposure; radio access security | Active adversary, typically rogue/fake base station or malicious network element | Not reported | Detection, localization, or blacklisting method proposed |
| S055 | A. Triesch; T. Barsch; V. Moonsamy; M. Große-Kampmann [56] | 5G Under Siege: A Comprehensive Guide to Threats and Penetration Testing in 5G Campus Networks | 2025 | IEEE Xplore; https://doi.org/10.1109/iwcmc65282.2025.11059676 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | 5G | tracking/inference; 5G core security | Semi-passive | Not reported | Surveyed countermeasures and open challenges |
| S056 | Z. Sun; C. Peng [76] | 5G-HCLS: An Authentication Protocol to Protect Bootstrapping Messages in 5G Network | 2025 | IEEE Xplore; https://doi.org/10.1109/WCNC61545.2025.10978357 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | Bootstrapping-message authentication; base-station authentication; subscriber protection | Active | Not reported | Authentication protocol proposed to protect 5G bootstrapping messages against fake-base-station attacks |
| S057 | S. Fukuda; T. Akimoto; T. Hattori; Y. Murakami; H. Kawakami [34] | Applying Causal Inference to Quantify Effects of TA Allocation Optimization on Paging Load | 2025 | IEEE Xplore; https://doi.org/10.23919/icmu65253.2025.11219122 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | Paging; tracking area/update; mobility/location management | Semi-passive | Not reported | Location-management, paging, or tracking mitigation/optimization discussed |
| S058 | A. Tripathi; A. Rajput; A. K. Subudhi; K. Kondepu; A. Thakur; B. R. Tamma [45] | Denial of Service Attacks Targeting Layer 2 in 5G RAN | 2025 | IEEE Xplore; https://doi.org/10.1109/fnwf66845.2025.11317524 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | authentication privacy; fake base station | Active | Not reported | Defense or mitigation discussed |
| S059 | M. Saifuzzaman; K. Xie; T. Xie; X. Zhang; X. Lei [8] | Dissecting Privacy-Exposing Identifiers in 5G/4G Networks | 2025 | IEEE Xplore; https://doi.org/10.1109/dsc65356.2025.11260885 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 4G/5G | persistent or linkable identifiers; mobility/networking behavior correlation | Semi-passive | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S060 | I. J. Matheus Edward; H. Situmorang; S. N. Wijaya [1] | Exposing IMSI Vulnerabilities in 5G Non-Standalone Networks | 2025 | IEEE Xplore; https://doi.org/10.1109/icwt66752.2025.11181903 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | IMSI/subscriber identity; SUCI/concealed identifier; rogue base station | Active | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S061 | M. Aoude [29] | Hardening 5G Network Registration: An Analysis of ECIES Profiles and SHNIP | 2025 | IEEE Xplore; https://doi.org/10.1109/actea66485.2025.11189931 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | IMSI/subscriber identity; SUCI/concealed identifier; authentication privacy | Passive | Not reported | Not reported |
| S062 | M. Ouaissa; M. Ouaissa; A. Rhattoy [63] | An Efficient and Secure Authentication and Key Agreement Protocol of LTE Mobile Network for an IoT System | 2019 | International Journal of Intelligent Engineering and Systems; https://doi.org/10.22266/ijies2019.0831.20 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 4G/LTE; IoT | authentication and key agreement; subscriber identity protection; mutual authentication; session-key establishment | Active | Computational cost; communication overhead; security-property comparison with existing authentication protocols | Lightweight mutual-authentication and key-agreement protocol designed to resist replay, impersonation and man-in-the-middle attacks |
| S063 | S. Ramisetty; G. S. P. Ghantasala; R. Sharma R.; P. Vidyullatha; A. Sungheetha [68] | Mitigating Physical Layer Security Vulnerabilities in 4G and 5G Cellular Networks | 2025 | IEEE Xplore; https://doi.org/10.23919/indiacom66777.2025.11115596 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 4G/5G | IMSI/subscriber identity; authentication privacy; rogue base station | Active | Not reported | Not reported |
| S064 | Q. Khan; S. Purification; S. -Y. Chang [61] | Post-Quantum Key Exchange and ID Encryption Analyses for 5G Mobile Networking | 2025 | IEEE Xplore; https://doi.org/10.1109/noms57970.2025.11073683 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | SUCI/concealed identifier; 5G core security; privacy | Passive | Not reported | Not reported |
| S065 | R. P. Bhatt; S. Shetty; D. M.R.; S. N. P. [20] | Random Interleaving at MAC Layer for Privacy Protection in 6G RAN | 2025 | IEEE Xplore; https://doi.org/10.1109/smartnets65254.2025.11106854 (accessed on 19 March 2026) | Location tracking and mobility privacy; Active | 6G | tracking/inference; signalling security; privacy | Active | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S066 | S. R. Hussain; O. Chowdhury; S. Mehnaz; E. Bertino [66] | LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTE | 2018 | NDSS Symposium; https://doi.org/10.14722/ndss.2018.23313 (accessed on 19 March 2026) | Protocol and signalling security; Active | 4G/LTE | LTE attach, authentication, paging, detach and mobility-management procedures; unauthenticated control-plane messages; protocol-state inconsistencies | Active | Ten new attacks identified; attacks affecting authentication, confidentiality, availability and location privacy | Formal model checking and adversarial testing; integrity protection for pre-authentication messages; correction of protocol-state weaknesses |
| S067 | Y. Bi; C. Jia [36] | Towards Resilience 5G-V2N: Efficient and Privacy-Preserving Authentication Protocol for Multi-Service Access and Handover | 2025 | IEEE Xplore; https://doi.org/10.1109/tmc.2025.3532120 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | authentication/key agreement; subscriber identity protection; handover security | Active | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S068 | A. Szczegielniak-Rekiel; K. Kanciak; J. M. Kelner [16] | Zero-Knowledge Proof in 5G and Beyond Technologies: State of the Arts, Practical Aspects, Applications, Security Issues, Open Challenges, and Future Trends | 2025 | IEEE Xplore; https://doi.org/10.1109/access.2025.3596122 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 5G | authentication privacy; tracking/inference; location privacy/inference | Active | Not reported | Surveyed countermeasures and open challenges |
| S069 | Rajendra Patil and Zixu Tian and Mohan Gurusamy and Joshua McCloud [50] | 5G core network control plane: Network security challenges and solution requirements | 2025 | ScienceDirect; https://doi.org/10.1016/j.comcom.2024.107982 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication privacy; signalling security; 5G core security | Passive | Not reported | Not reported |
| S070 | Andrea Paci and Matteo Chiacchia and Giuseppe Bianchi [85] | 5GMap: Enabling external audits of access security and attach procedures in real-world cellular deployments | 2025 | ScienceDirect; https://doi.org/10.1016/j.comcom.2025.108091 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 5G | IMSI/subscriber identity; signalling security; privacy | Active | Not reported | Not reported |
| S071 | Kinzah Noor, Agbotiname Lucky Imoize, Michael Adedosu Adelabu, Cheng-Chi Lee [21] | A Comprehensive Survey on AI-Assisted Multiple Access Enablers for 6G and beyond Wireless Networks | 2025 | ScienceDirect; https://doi.org/10.32604/cmes.2025.073200 (accessed on 19 March 2026) | General cellular security/privacy; Passive | 6G | location privacy/inference; privacy | Not applicable/survey or review | Not reported | Surveyed countermeasures and open challenges |
| S072 | Stefan Rommer and Catherine Mulligan and Peter Hedman and Magnus Olsson and Lars Frid and Shabnam Sultana [17] | Chapter 6 - Security | 2025 | ScienceDirect; https://doi.org/10.1016/b978-0-443-29188-3.00010-7 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | tracking/inference; location privacy/inference; privacy | Not applicable/survey or review | Not reported | Surveyed countermeasures and open challenges |
| S073 | Yomna Ibrahim and Mai A. Abdel-Malek and Mohamed Azab and Mohamed RM Rizk [9] | Privacy-preserved mutually-trusted 5G communications in presence of pervasive attacks | 2025 | ScienceDirect; https://doi.org/10.1016/j.iot.2025.101491 (accessed on 19 March 2026) | Identity and authentication privacy; Active | 5G | 5G-AKA/authentication; authentication privacy; location privacy/inference | Active | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S074 | James WrightStephen Wolthusen [55] | A Fail-Safe Challenge-Response Mechanism for User Equipment to Detect Rogue IMSI/SUPI Catchers | 2025 | SpringerLink; https://doi.org/10.1007/978-3-031-81888-2_8 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Rogue/fake base station; subscriber identity exposure; radio access security | Active | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S075 | Wenao ZhangShuhui ChenZiling WeiXinyu ZhangQianqian XingJinshu Su [59] | Cellular-Snooper: A General and Real-Time Mobile Application Fingerprinting Attack in LTE Networks | 2025 | SpringerLink; https://doi.org/10.1007/978-981-96-9872-1_4 (accessed on 19 March 2026) | Rogue/fake base stations; Semi-passive | 4G/LTE | RF fingerprinting; signal features of base stations/devices | Semi-passive | Not reported | Not reported |
| S076 | Julian Parkin andMahesh Tripunitara [73] | Countering Subscription Concealed Identifier (SUCI)-Catchers in Cellular Communications | 2025 | SpringerLink; https://doi.org/10.1007/978-3-031-80020-7_6 (accessed on 19 March 2026) | Rogue/fake base stations; Active | Not reported | Persistent or linkable identifiers; mobility/networking behavior correlation | Active | Not reported | Privacy-preserving identifier, pseudonym, SUCI/SUPI protection or protocol hardening |
| S077 | K. SowjanyaPabitra PalAman VermaBijoy DasDhiman SahaAnand M. BaswadeBrejesh Lall [23] | SUPI-Rear: Privacy-Preserving Subscription Permanent Identification Strategy in 5G-AKA | 2025 | SpringerLink; https://doi.org/10.1007/978-3-031-74498-3_22 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S078 | S. Feng; B. Cui; J. Fu; M. Jiang; S. Chang [58] | Adaptive Target Device Model Identification Attack in 5G Mobile Network | 2026 | IEEE Xplore; https://doi.org/10.1109/tnsm.2025.3626804 (accessed on 19 March 2026) | Protocol and signalling security; Passive | 5G | signalling security | Passive | Not reported | Not reported |
| S079 | S. Duan; F. Lyu; S. Wang; Y. Ding; X. He; Y. Zhang [52] | Exploring Cellular User Re-Identification Risks With Networking Behaviors Analysis and Modeling | 2026 | IEEE Xplore; https://doi.org/10.1109/tmc.2025.3607772 (accessed on 19 March 2026) | Location tracking and mobility privacy; Semi-passive | Not reported | Persistent or linkable identifiers; mobility/networking behavior correlation | Passive or semi-passive adversary using mobility/signalling/location data | Not reported | Not reported |
| S080 | Y. Bi; C. Jia [38] | From Preparation to Execution: Security Protocol for Third-Party MES-Enabled 5G Support Handover Authentication and Key Evolution | 2026 | IEEE Xplore; https://doi.org/10.1109/tmc.2025.3599376 (accessed on 19 March 2026) | Rogue/fake base stations; Active | 5G | authentication/key agreement; subscriber identity protection; handover security | Active | Not reported | Authentication/key-agreement or handover-security protocol proposed |
| S081 | D. Scotece; G. Santaromita; C. Fiandrino; L. Foschini; D. Giustiniano [71] | On the Scalability of Access and Mobility Management Function: The Localization Management Function Use Case | 2026 | IEEE Xplore; https://doi.org/10.1109/tnsm.2026.3664546 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | Not reported | authentication privacy; location privacy/inference; signalling security | Semi-passive | Not reported | Detection, localization, or blacklisting method proposed |
| S082 | T. N. Turnip; B. Andersen; C. Vargas-Rosales [75] | Toward 6G Authentication and Key Agreement Protocol: A Survey on Hybrid Post Quantum Cryptography | 2026 | IEEE Xplore; https://doi.org/10.1109/comst.2025.3567439 (accessed on 19 March 2026) | Identity and authentication privacy; Semi-passive | 6G | authentication/key agreement; subscriber identity protection; handover security | Not applicable/survey or review | Not reported | Surveyed countermeasures and open challenges |
| S083 | Muhammad Asim and Abdelhamied A. Ateya and Mudasir Ahmad Wani and Gauhar Ali and Mohammed [65] | A Comprehensive Survey on Blockchain-Enabled Techniques and Federated Learning for Secure 5G/6G Networks: Challenges, Opportunities, and Future Directions | 2026 | ScienceDirect; https://doi.org/10.32604/cmc.2025.070684 (accessed on 19 March 2026) | General cellular security/privacy; Active | 5G/6G | privacy | Not applicable/survey or review | Not reported | Surveyed countermeasures and open challenges |
| S084 | T. Fei; W. Wang [67] | LTE Is Vulnerable: Implementing Identity Spoofing and Denial-of-Service Attacks in LTE Networks | 2019 | IEEE Xplore; https://doi.org/10.1109/GLOBECOM38437.2019.9013397 (accessed on 19 March 2026) | Identity and authentication attacks; Active | 4G/LTE | unprotected pre-authentication signalling; identity procedures; attach and authentication messages; LTE control-plane weaknesses | Active | Practical identity-spoofing and denial-of-service attacks implemented and evaluated in an LTE test environment | Integrity protection for initial signalling; stronger identity verification; authentication of pre-authentication control-plane messages |
| S085 | M. Chlosta; D. Rupprecht; T. Holz; C. Pöpper [82] | LTE Security Disabled: Misconfiguration in Commercial Networks | 2019 | ACM Digital Library; https://doi.org/10.1145/3317549.3324927 (accessed on 19 March 2026) | Protocol and signalling security; Semi-passive | 4G/LTE | null encryption and integrity configurations; weak or disabled LTE security algorithms; network-security misconfiguration | Semi-passive | Measurements of security configurations in commercial LTE networks; insecure deployments and disabled protection mechanisms identified | Correct network configuration; mandatory secure encryption and integrity algorithms; rejection of null or downgraded security configurations |
| S086 | Jignesh B. JoshiSankita J. PatelBalu L. ParneVivaksha J. JariwalaVishruti V. Desai [14] | DS-AKA: Digital Signature-Based Authentication and Key Agreement Protocol to Mitigate Fake Serving Network for 5G Communication Networks | 2026 | SpringerLink; https://doi.org/10.1007/978-981-95-2196-8_9 (accessed on 19 March 2026) | Identity and authentication privacy; Passive | 5G | authentication/key agreement; subscriber identity protection; handover security | Passive | Not reported | Authentication/key-agreement or handover-security protocol proposed |
Appendix B. Quality Assessment
| ID | QA1 | QA2 | QA3 | QA4 | QA5 | QA6 | QA7 | QA8 | QA9 | QA10 | QA11 | QA12 | Total | Category |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| S001 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S002 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S003 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 1 | 0 | 1 | 0.5 | 10 | High |
| S004 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S005 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S006 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 0.5 | 0 | 0.5 | 0 | 5 | Low |
| S007 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 11.5 | High |
| S008 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S009 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S010 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 0.5 | 1 | 10 | High |
| S011 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S012 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 0.5 | 1 | 10 | High |
| S013 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S014 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 11.5 | High |
| S015 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 10.5 | High |
| S016 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S017 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S018 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 6 | Low |
| S019 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S020 | 1 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 1 | 11.5 | High |
| S021 | 1 | 1 | 0.5 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 1 | 11 | High |
| S022 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S023 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 10.5 | High |
| S024 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 0.5 | 1 | 10 | High |
| S025 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 1 | 1 | 10.5 | High |
| S026 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S027 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S028 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S029 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S030 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S031 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8 | Medium |
| S032 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 7.5 | Medium |
| S033 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S034 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S035 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S036 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S037 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 0.5 | 1 | 10 | High |
| S038 | 1 | 0 | 1 | 1 | 1 | 1 | 1 | 0.5 | 1 | 1 | 0.5 | 1 | 10 | High |
| S039 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 0.5 | 0 | 5.5 | Low |
| S040 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S041 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 12 | High |
| S042 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S043 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S044 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S045 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 0.5 | 0 | 1 | 0 | 6.5 | Low |
| S046 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 7.5 | Medium |
| S047 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 7.5 | Medium |
| S048 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S049 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 8.5 | Medium |
| S050 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S051 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S052 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S053 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S054 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S055 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S056 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S057 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8 | Medium |
| S058 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S059 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S060 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S061 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S062 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 0.5 | 0 | 5.5 | Low |
| S063 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S064 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S065 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 8.5 | Medium |
| S066 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8 | Medium |
| S067 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S068 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S069 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S070 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S071 | 1 | 1 | 0.5 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8.5 | Medium |
| S072 | 0.5 | 0 | 0.5 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 6.5 | Low |
| S073 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S074 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8 | Medium |
| S075 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 7 | Medium |
| S076 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8 | Medium |
| S077 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S078 | 1 | 1 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 0.5 | 0 | 1 | 0 | 6.5 | Low |
| S079 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 6 | Low |
| S080 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| S081 | 1 | 0 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 7.5 | Medium |
| S082 | 1 | 1 | 0.5 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 0.5 | 0.5 | 8 | Medium |
| S083 | 1 | 1 | 0.5 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 8.5 | Medium |
| S084 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 1 | 0 | 6 | Low |
| S085 | 1 | 0 | 1 | 0 | 1 | 0.5 | 0 | 0.5 | 1 | 0 | 0.5 | 0 | 5.5 | Low |
| S086 | 1 | 1 | 1 | 0.5 | 1 | 0.5 | 0 | 0.5 | 1 | 1 | 1 | 0.5 | 9 | Medium |
| QA Category | Score Interval | Number of Studies |
|---|---|---|
| High | 10–12 | 24 |
| Medium | 7–9.5 | 52 |
| Low | 4–6.5 | 10 |
| Very low | 0–3.5 | 0 |
Appendix C. Cross-Generation Comparative Matrix
| Generation | Attack Vector | Affected Identifier | Exploited Procedure | Adversary Capability | Reported Metrics | Limitations | Mitigation | Representative Studies |
|---|---|---|---|---|---|---|---|---|
| 2G | Passive or semi-passive paging observation | TMSI, IMSI, paging identity | Paging procedure and temporary identifier reuse | Passive or semi-passive adversary monitoring broadcast and control channels | Paging correlation, user presence detection, coarse location inference | Requires knowledge of paging occasions or repeated observations; accuracy depends on cell size and paging policy | Frequent TMSI reallocation; paging policy randomization; reduction of identifier reuse; monitoring abnormal paging patterns | [7,27,42] |
| 2G | Fake base station/IMSI catcher | IMSI, TMSI | Location update, identity request, paging response | Active adversary operating a rogue BTS and attracting the UE | IMSI disclosure rate, attachment success, paging response, tracking feasibility | No mutual authentication; attack success depends on radio proximity, signal strength, and UE/operator configuration | Disable or restrict 2G where possible; operator-side anomaly detection; terminal warnings for suspicious cell behavior; stronger identity protection in later generations | [5,22,48] |
| 2G | Silent SMS/signalling-triggered localization | TMSI, IMSI, MSISDN-linked identity | Paging, SMS delivery, mobility management signalling | Semi-active adversary capable of triggering network events and observing radio responses | Location confirmation, paging response timing, user reachability | Requires ability to trigger signalling events; localization granularity is usually limited to cell or location area | Filtering abnormal signalling triggers; operator-side SMS and paging abuse detection; improved subscriber privacy policies | [28,42,43] |
| 3G | Paging and mobility-area tracking | TMSI, IMSI, location-area identifiers | Paging, routing area update, location area update | Passive or semi-passive adversary observing control-plane signalling | User presence detection, movement correlation, paging response behavior | Tracking precision depends on location area size, paging configuration, and identifier refresh frequency | More frequent temporary identifier refresh; optimized paging; mobility-management privacy controls; operator-side monitoring | [7,13,27] |
| 3G | Rogue base station forcing identity exposure or downgrade | IMSI, TMSI | Cell selection, identity request, fallback to 2G | Active adversary with rogue base station capability and possible downgrade strategy | IMSI capture, downgrade success, attachment attempt behavior | 3G introduces mutual authentication, but privacy may still be affected before full security activation or through fallback | Enforce mutual authentication; prevent unnecessary fallback to 2G; detect rogue cells; configure networks to avoid insecure interworking | [5,18,48] |
| 3G | Authentication and AKA-related privacy analysis | IMSI, temporary identifiers, authentication vectors | Authentication and key agreement, identity request, resynchronization behavior | Passive, semi-passive, or active adversary depending on the scenario | Linkability, identity exposure, authentication failure behavior | Practical feasibility depends on implementation details and access to signalling observations | Strict implementation of AKA procedures; improved error handling; privacy-preserving authentication responses; avoidance of unnecessary permanent identity requests | [31,47,48] |
| 4G | Paging-based location tracking | S-TMSI, GUTI, paging identity | Paging, tracking area update, idle-mode mobility | Passive or semi-passive adversary monitoring LTE control channels | Paging correlation, location-area inference, user presence detection, localization granularity | Requires repeated observations; accuracy depends on tracking area size and paging strategy | Frequent GUTI reallocation; paging obfuscation; optimized tracking area configuration; operator-side anomaly detection | [7,27,32,33] |
| 4G | LTE rogue eNodeB/fake base station | IMSI, GUTI, S-TMSI | Attach, identity request, tracking area update, security mode setup | Active adversary operating rogue LTE equipment or modified SDR stack | IMSI disclosure, attach behavior, downgrade feasibility, UE response patterns | LTE improves authentication but some procedures before security activation remain privacy-sensitive | Minimize IMSI requests; enforce proper GUTI allocation; rogue-cell detection; baseband and network-side validation mechanisms | [22,30,66,67] |
| 4G | Linkability through temporary identifier reuse | GUTI, S-TMSI | Attach, TAU, paging, idle-to-connected transition | Passive or semi-passive adversary correlating repeated identifiers or signalling patterns | Identifier lifetime, linkability rate, tracking duration | Effectiveness depends on operator policy for GUTI refresh and mobility patterns | Strict GUTI reallocation policies; shortened temporary identifier lifetime; unlinkability-aware mobility management | [8,15,53,66] |
| 4G | Downgrade or interworking abuse | IMSI, TMSI, GUTI | CSFB, fallback to 2G/3G, inter-RAT mobility | Active adversary influencing radio conditions or exploiting interworking procedures | Downgrade success, identity exposure, service disruption indicators | Requires suitable network configuration and UE support for legacy RATs | Disable insecure fallback where possible; restrict 2G interworking; monitor abnormal RAT changes; prefer VoLTE/secure services | [18,22,48,82] |
| 5G NSA | Fake base station or downgrade-assisted identification | IMSI, GUTI, S-TMSI, SUCI/SUPI depending on fallback path | LTE/NR interworking, fallback, identity request, registration-related signalling | Active adversary with rogue LTE/NR or downgrade capability | Identity exposure, fallback success, attach/registration response behavior | Attack feasibility depends heavily on deployment, UE configuration, and operator fallback policy | Restrict legacy fallback; validate network configurations; detect rogue cells; enforce privacy-preserving identity procedures | [1,18,22,46] |
| 5G NSA | LTE anchor-based privacy exposure | GUTI, S-TMSI, 5G temporary identifiers depending on deployment | EN-DC operation, LTE attach, tracking area update, paging through LTE anchor | Passive, semi-passive, or active adversary targeting the LTE control-plane anchor | Paging correlation, temporary identifier linkability, tracking feasibility | 5G NSA still depends on LTE/EPC or LTE control-plane elements, so some LTE privacy limitations persist | Strong LTE-side GUTI refresh; secure interworking policies; paging optimization; migration toward 5G SA where feasible | [1,8,22,60] |
| 5G NSA | Paging and mobility tracking across LTE-NR deployment | GUTI, S-TMSI, paging identity | Paging, tracking area management, idle-mode mobility | Passive or semi-passive adversary observing LTE/NR signalling patterns | Presence detection, paging correlation, mobility-area inference | Granularity depends on tracking area design and paging strategy; NSA deployments may inherit LTE weaknesses | Temporary identifier rotation; optimized tracking area planning; paging randomization; operator-side monitoring of paging abuse | [7,39,40,51] |
| 5G SA | Temporary identifier linkability | 5G-GUTI, temporary UE identifiers | Registration update, paging, mobility management | Passive or semi-passive adversary correlating temporary identifiers or signalling events | Linkability duration, paging correlation, tracking feasibility | Risk persists if 5G-GUTI is not refreshed frequently or if paging behavior is predictable | Frequent 5G-GUTI rotation; unlinkability-aware AMF policies; paging optimization; privacy-preserving mobility management | [8,10,23,25] |
| 5G SA | SUPI protection bypass or misconfiguration | SUPI, SUCI, 5G-GUTI | Registration, identity request, SUCI handling | Active adversary exploiting misconfiguration, implementation weakness, or forced identity procedure | SUPI exposure, SUCI misuse, registration failure behavior | 5G introduces SUCI, but protection depends on correct home-network public key configuration and UE implementation | Correct SUCI configuration; home network public key validation; avoid null-scheme misuse; strict SUPI exposure policies | [29,47,48,73] |
| 5G SA | Paging-based location and presence inference | 5G-GUTI, paging identity | Paging, idle-mode reachability, registration area management | Passive or semi-passive adversary monitoring broadcast/control signalling | User presence detection, paging response behavior, coarse localization | Localization is generally coarse and depends on registration area size, paging configuration, and observation capability | Paging policy hardening; registration area optimization; reduction of predictable paging patterns; operator-side anomaly detection | [7,27,51,72] |
| 5G SA | Implementation or deployment-specific privacy weakness | SUPI, SUCI, 5G-GUTI | Registration, authentication, paging, mobility management | Active or semi-active adversary exploiting vendor, configuration, or deployment weaknesses | Identity exposure, linkability, failed authentication behavior, tracking feasibility | Security guarantees depend on correct implementation and deployment; practical attacks may be operator- or device-specific | Conformance testing; implementation hardening; privacy audits; AMF policy enforcement; correct SUCI configuration and 5G-GUTI rotation | [31,47,50,85] |
Appendix D. Full-Text Eligibility Exclusions
| Study ID | Citation | Applied Exclusion Criterion | Reason for Exclusion |
|---|---|---|---|
| S087 | [87] | EC1 | The study proposes a GPS-based forest-fire detection and alert system and does not investigate identification or location attacks targeting cellular-network users or protocols. |
| S088 | [88] | EC1 | The study develops a personal-safety device using fingerprint authentication and location reporting, rather than analyzing identification or location attacks in cellular networks. |
| S089 | [89] | EC1 | The study presents an IoT-based assistive walking stick for visually impaired users and does not examine cellular-network identification or location vulnerabilities. |
| S090 | [90] | EC1 | The study uses location tracking to support accident detection and emergency-response notification, without analyzing attacks against cellular-network location or identity mechanisms. |
| S091 | [91] | EC1 | The study presents a voice-activated distress-detection and location-reporting system and is unrelated to identification or location attacks in cellular networks. |
| S092 | [92] | EC1 | The study proposes an accident-detection, location-tracking, and notification application rather than an analysis of cellular identification or location attacks. |
| S093 | [93] | EC1 | The study develops a fall-detection and location-tracking system for elderly users and does not investigate cellular-network identity or location vulnerabilities. |
| S094 | [94] | EC1 | The study focuses on GPS navigation and live tracking for visually impaired travelers, rather than attacks exploiting cellular identification or location procedures. |
| S095 | [95] | EC1 | The study presents a tracking and fall-detection solution for elderly users and does not analyze identification or location attacks in cellular networks. |
| S096 | [96] | EC1 | The study concerns RFID-based identification and tracking of construction components, not the identification or location of subscribers in cellular networks. |
| S097 | [97] | EC4/EC5 | The study focuses on control and optimization intelligence for future 6G mobile networks and, therefore, falls outside the review scope limited to identification and location attacks in 2G–5G networks. |
| S098 | [98] | EC4/EC5 | The study investigates hybrid quantum-classical optimization for tracking-area management in future networks, rather than identification or location attacks within the 2G–5G scope. |
| S099 | [99] | EC4/EC5 | The study addresses NextG positioning resilience against relay jamming and is outside the review scope restricted to identification and location attacks in 2G–5G cellular networks. |
| S100 | [100] | EC4/EC5 | The study proposes a quantum-resistant blockchain architecture for vehicular networks and does not analyze identification or location attacks in 2G–5G cellular systems. |
| S101 | [101] | EC4/EC5 | The study concerns secure LoRa ad-hoc communications in coverage dead zones and is not focused on identification or location attacks in 2G–5G cellular networks. |
| S102 | [102] | EC4/EC5 | The study investigates privacy-aware query processing in vehicular ad-hoc networks rather than identification or location attacks involving 2G–5G cellular protocols. |
| S103 | [103] | EC2 | The study optimizes signaling-overhead costs in 5G networks but does not analyze an attack targeting subscriber identification or location confidentiality. |
| S104 | [104] | EC2 | The study proposes a mobility-management mechanism for reducing power consumption and signaling overhead in 5G IoT devices, without examining identification or location attacks. |
| S105 | [105] | EC2 | The study predicts mobility-management demand from user behavior for network-planning purposes and does not investigate attacks against cellular identity or location mechanisms. |
| S106 | [106] | EC2 | The study addresses mobility management for 5G network slicing but does not analyze adversarial identification or location tracking. |
| S107 | [107] | EC2 | The study focuses on the authenticity and verifiability of public-warning messages and does not investigate subscriber identification or location attacks. |
| S108 | [108] | EC2 | The study surveys mobility management in ultra-dense cellular networks but does not provide an analysis of identification or location attacks relevant to the review questions. |
| S109 | [109] | EC2 | The study optimizes 5G-MEC service relocation with performance, availability, and privacy objectives but does not analyze attacks against cellular subscriber identity or location. |
| S110 | [110] | EC2 | The study proposes O-RAN-based anomaly recognition and network sensing but does not specifically analyze identification or location attacks against cellular users. |
| S111 | [111] | EC2 | The study develops carrier-phase positioning methods for tracking XR devices and does not investigate adversarial location tracking or subscriber-identification attacks. |
| S112 | [112] | EC2 | The study proposes a seamless handover and mobility-management mechanism for device-to-device communication, without analyzing identification or location attacks. |
| S113 | [113] | EC2 | The study aims to reduce signaling overhead associated with IoT-device mobility and does not examine attacks against cellular identification or location procedures. |
| S114 | [114] | EC2 | The study proposes a paging-occasion allocation mechanism for beyond-5G networks but does not analyze paging-based identification or location attacks. |
| S115 | [115] | EC2 | The study presents a general intrusion-detection method for the 5G core but does not specifically analyze subscriber-identification or location attacks. |
| S116 | [116] | EC2 | The study uses aggregated mobile-network signaling data to observe road-freight traffic and does not examine adversarial identification or location attacks against subscribers. |
| S117 | [117] | EC2 | The study proposes a privacy-preserving authentication protocol for medical IoT devices but does not analyze identification or location attacks exploiting cellular-network procedures. |
| S118 | [118] | EC2 | The study proposes an enhanced authentication and key-agreement protocol for LTE/LTE-A IoT systems but does not investigate identification or location attacks. |
| S119 | [119] | EC2 | The study applies machine learning to tracking-area selection and handover security but does not provide an analysis of subscriber-identification or location-tracking attacks within the review scope. |
| S120 | [120] | EC2 | The study optimizes UAV trajectories and resource allocation in 5G networks and does not address identification or location attacks against cellular subscribers. |
| S121 | [121] | EC2 | The study proposes a blockchain-based data-privacy mechanism for industrial IoT environments but does not analyze cellular identification or location attacks. |
| S122 | [122] | EC2/EC6 | The publication is a short poster survey of general 5G-IoT security challenges and does not provide a sufficiently detailed analysis or evaluation of a specific identification or location attack. |
| S123 | [123] | EC2/EC6 | The study provides a broad conceptual discussion of trustworthy communications in NextG networks without a detailed technical analysis of a cellular identification or location attack. |
| S124 | [124] | EC2/EC6 | The study surveys public-safety communication technologies in terrorism scenarios but does not investigate identification or location attacks against cellular subscribers. |
| S125 | [125] | EC2/EC6 | The study examines the limitations of inferring device location from the nearest cellular antenna for mobility-data analysis, rather than an adversarial identification or location attack. |
| S126 | [126] | EC2/EC6 | The study proposes a privacy-preservation algorithm for location-based services but does not analyze an attack exploiting cellular-network identification or location procedures. |
| S127 | [127] | EC2/EC6 | The study proposes a differential-privacy method for protecting location datasets but does not investigate identification or location attacks at the cellular-protocol level. |
| S128 | [128] | EC2/EC6 | The study applies generative adversarial networks to enhance location privacy but does not provide an attack-specific analysis of cellular identification or location procedures. |
| S129 | [129] | EC2/EC6 | The study addresses privacy preservation in 5G-enabled mobile crowdsensing but does not analyze an identification or location attack against cellular-network users or signaling procedures. |
| S130 | [130] | EC2/EC6 | The study proposes a privacy-preserving contact-tracing architecture using 5G and blockchain but does not investigate cellular identification or location attacks. |
| S131 | [131] | EC2/EC6 | The study proposes a privacy-preserving framework for collecting location data in edge-computing systems but does not analyze attacks against cellular identity or location mechanisms. |
| S132 | [132] | EC2/EC6 | The study proposes privacy-preservation mechanisms for location and trajectory data in vehicular social-network services but does not investigate identification or location attacks at the cellular-protocol level. |
| S133 | [133] | EC1 | The study focuses on general cybersecurity measures for next-generation connected electric vehicles and does not provide a relevant technical analysis of identification or location attacks in 2G–5G cellular networks. |
Appendix E. Performance Metrics by Attack Family
| Attack Family | Representative Studies | Attack Success Rate or Impact | Localization Accuracy | Time to Success | Cost and Equipment Assumptions | Detectability | Deployment Conditions and Assumptions |
|---|---|---|---|---|---|---|---|
| Paging-based location and presence tracking | S015, S017, S019, S007, S025, S036, S012, S028, S075, S033, S034, S049, S073 | Not reported as a common numerical success rate. Successful tracking was generally assessed through paging correlation, user-presence detection, or mobility-pattern recovery. | No common positioning-error metric was reported. The studies used indirect indicators such as paging correlation, signal strength, mobility patterns, or CRB-based privacy measures. | Not reported. | Passive or semi-passive monitoring of paging and control channels was assumed. Complete equipment specifications and monetary costs were not reported. | Not reported consistently. Repeated paging observations or artificially triggered paging events may be detectable through operator-side monitoring. | Requires observable paging traffic, repeated observations, and a sufficiently stable association between a temporary identifier and the target UE. Accuracy depends on cell size, tracking-area configuration, and paging policy. |
| Fake base station and IMSI-catcher attacks | S005, S044, S041, S068, S069, S048, S001, S017, S040 | Not reported consistently. The reviewed studies generally demonstrated UE attraction, identity disclosure, attachment attempts, or paging responses, but did not provide a common numerical attack-success rate. | Not reported. Localization was generally limited to confirming that the target was located within the coverage area of the rogue cell. | Not reported. | An active rogue BTS, eNodeB, or gNodeB, usually implemented through software-defined radio equipment or a cellular test platform, was assumed. Complete monetary costs were generally not reported. | Not reported consistently. Detection may rely on abnormal cell parameters, unexpected signal-strength changes, invalid network identifiers, or network- and UE-side rogue-cell detection mechanisms. | Requires radio proximity, sufficient transmit power to attract or retain the UE, appropriate frequency and network configuration, and support for the targeted cellular generation or fallback procedure. |
| Silent-SMS and signalling-triggered localization | S036, S026, S037 | Not reported as a common numerical success rate. Impact was evaluated through paging activation, reachability confirmation, or observable radio and mobility-management responses. | Generally limited to cell-, location-area-, tracking-area-, or registration-area-level inference. Exact distance errors were not reported. | Not reported. | Requires the ability to trigger an SMS, call, paging event, or another network-generated signalling transaction and to observe the corresponding radio response. Monetary cost was not reported. | Not reported. Repeated silent-SMS or paging triggers may be identifiable through operator-side anomaly detection or signalling-abuse monitoring. | Requires target reachability, successful generation of a network-triggered event, and access to the corresponding paging or mobility-management signalling. |
| Temporary-identifier linkability and reuse | S019, S068, S014, S008, S051, S001, S058, S041, S018, S045, S023 | Not reported as a common numerical success rate. Effectiveness was evaluated through identifier correlation, mobility-pattern recovery, subscriber linkability, or tracking feasibility. | No common localization-error metric was reported. The achievable granularity depends on the cell, location area, tracking area, or registration area in which the identifier is observed. | Not reported. | Passive or semi-passive observation of paging, attachment, registration, and mobility-management signalling was assumed. Equipment costs were not reported. | Not reported consistently. Purely passive correlation may be difficult to detect because it does not require transmission by the adversary. | Requires temporary identifiers to remain unchanged or otherwise linkable across multiple signalling events. Feasibility depends strongly on operator policies for TMSI, GUTI, S-TMSI, and 5G-GUTI reallocation. |
| Downgrade and interworking attacks | S017, S084, S041, S044, S001, S040 | Not reported consistently. The reviewed studies demonstrated downgrade feasibility, permanent-identity exposure, insecure fallback, or service degradation, but no common numerical downgrade-success rate was available. | Not reported. Location inference is generally obtained indirectly after the UE is forced onto a less secure radio access technology. | Not reported. | Requires an active radio adversary, rogue base-station capability, radio interference, or the ability to influence radio-access-technology selection. Complete monetary costs were not reported. | Not reported consistently. Abnormal RAT transitions, repeated fallback events, or suspicious neighboring cells may be detectable by the operator or UE. | Requires legacy RAT support, permissive fallback or interworking policies, suitable radio conditions, and a UE and operator configuration that permits inter-RAT mobility. |
| Authentication- and AKA-related privacy attacks | S042, S043, S044, S018, S045, S023, S074, S027 | Not reported consistently. Reported impact included subscriber linkability, identity exposure, distinguishable authentication failures, or privacy leakage through authentication-related responses. | Not reported. | Not reported. | Passive, semi-passive, or active access to authentication and identity-related signalling was assumed, depending on the attack model. Equipment and monetary costs were generally not reported. | Not reported consistently. Detection may depend on identifying repeated authentication failures, unusual synchronization requests, or abnormal permanent identity requests. | Requires access to authentication, identity-request, resynchronization, or error-handling exchanges and may depend on protocol implementation and operator configuration. |
| Signalling-overload and mobility-management attacks | S001, S008, S009, S013, S014, S033 | Reported impact included 500–800 and up to 1500 messages per UE, 34% MME load events, and system collapse in approximately 30 s. Mitigation-oriented studies reported 92% signalling-overhead reduction, 8% fewer TAUs, 30% fewer paging requests, and more than 30% signalling-cost reduction. | Not applicable or not reported, because the primary objective was signalling load or service disruption rather than localization. | Approximately 30 s to system collapse was reported in S014. S033 used 100 GA runs and 300 stopping iterations, although these values describe algorithmic evaluation rather than direct attack execution time. | The studies assumed the ability to generate, amplify, or repeatedly trigger registration, attachment, paging, TAU, or other mobility-management procedures. Complete monetary equipment costs were not reported. | S014 reported a detection rate above 96% and a false-positive rate below 3.8%. Detectability was not reported consistently by the remaining studies. | Depends on the signalling volume, number of affected UEs, MME or AMF capacity, mobility behavior, paging configuration, tracking-area policy, and the adversary’s ability to repeatedly trigger control-plane procedures. |
| Radio- and signal-based location inference | S015, S017, S024 | A common numerical attack-success rate was not reported. Effectiveness was assessed using tracking feasibility, signal-derived indicators, spatial distributions, or detection probability. | No directly comparable distance-error metric was reported. Some studies used signal-strength measurements or CRB-derived privacy indicators instead of localization error. | Not reported. | Requires access to radio measurements, signal-strength information, carrier phase, or control-channel observations. Hardware configurations and monetary costs were not consistently reported. | S024 reported detection probabilities close to 1 for NCD and MNCD and below 0.5 for SpD. Other studies did not report consistent detection-rate or false-positive-rate values. | Depends on propagation conditions, target mobility, cell geometry, measurement density, observation duration, and the availability of radio or spatial-distribution information. |
| Paging- and control-plane anomaly detection | S014, S024 | The studies primarily evaluated attack-detection or mitigation effectiveness rather than direct attack-success rates. S014 reported a detection rate above 96%, while S024 reported detection probability values for different indicators. | Not applicable or not reported. | Not reported as attack time. Detection and processing times were not reported consistently. | Assumes access to operator-side signalling traces, radio observations, or control-plane measurements and sufficient computational resources for anomaly analysis. Monetary costs were not reported. | Detection rate above 96% and false-positive rate below 3.8% were reported in S014. Detection probability was close to 1 for NCD and MNCD and below 0.5 for SpD in S024. | Performance depends on the availability and quality of signalling data, selection of detection thresholds, attack intensity, network configuration, training data, and the representativeness of normal traffic. |
| SUPI/SUCI protection and permanent-identity exposure | S001, S043, S044, S045, S023, S074, S027 | Not reported consistently. The reported impact included SUPI exposure, incorrect SUCI processing, use of an unprotected identity scheme, registration failure, or permanent-identity disclosure. | Not reported. | Not reported. | Requires active interaction with registration or identity procedures, access to a rogue or misconfigured network, or exploitation of implementation and configuration weaknesses. Monetary cost was not reported. | Not reported consistently. Detection may depend on registration logs, invalid SUCI use, repeated identity requests, or home-network validation mechanisms. | Depends on correct home-network public-key configuration, UE implementation, SUCI protection-scheme selection, operator policy, and the prevention of unnecessary SUPI requests. |
| Implementation- and deployment-specific privacy weaknesses | S042, S043, S086, S047 | Not reported consistently. Demonstrated impact included identity exposure, temporary-identifier linkability, authentication failure behavior, paging correlation, or tracking feasibility. | Not reported. | Not reported. | Requires access to vulnerable devices, operator configurations, protocol implementations, or registration and mobility-management exchanges. Complete monetary costs were not reported. | Not reported consistently. Detectability depends on vendor logging, conformance testing, privacy audits, and network-side anomaly detection. | Feasibility is vendor-, UE-, operator-, and deployment-specific and may depend on incorrect SUCI configuration, insufficient temporary-identifier rotation, predictable paging behavior, or non-compliant protocol implementation. |
References
- Matheus Edward, I.J.; Situmorang, H.; Wijaya, S.N. Exposing IMSI Vulnerabilities in 5G Non-Standalone Networks. In Proceedings of the 2025 11th International Conference on Wireless and Telematics (ICWT), Lampung, Indonesia, 3–4 July 2025. [Google Scholar] [CrossRef] [Scilit]
- Karim, I.; Hussain, S.R.; Bertino, E. ProChecker: An Automated Security and Privacy Analysis Framework for 4G LTE Protocol Implementations. In Proceedings of the 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS), Virtual Conference, 7–10 July 2021; pp. 773–785. [Google Scholar] [CrossRef] [Scilit]
- Yu, C.; Chen, S.; Xing, Q.; Wei, Z. Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution. Comput. Netw. 2024, 254, 110814. [Google Scholar] [CrossRef] [Scilit]
- Checa, J.J.; Tomasin, S. Location-Privacy-Preserving Technique for 5G mmWave Devices. IEEE Commun. Lett. 2020, 24, 2692–2695. [Google Scholar] [CrossRef] [Scilit]
- Abdelrazek, L.; Azer, M.A. User Privacy in Legacy Mobile Network Protocols. In Proceedings of the 2018 3rd International Conference on System Reliability and Safety (ICSRS), Barcelona, Spain, 23–25 November 2018. [Google Scholar] [CrossRef] [Scilit]
- Braeken, A. Symmetric key based 5G AKA authentication protocol satisfying anonymity and unlinkability. Comput. Netw. 2020, 181, 107424. [Google Scholar] [CrossRef] [Scilit]
- Alsaeedy, A.A.R.; Chong, E.K.P. Tracking Area Update and Paging in 5G Networks: A Survey of Problems and Solutions. Mob. Netw. Appl. 2019, 24, 578–595. [Google Scholar] [CrossRef] [Scilit]
- Saifuzzaman, M.; Xie, K.; Xie, T.; Zhang, X.; Lei, X. Dissecting Privacy-Exposing Identifiers in 5G/4G Networks. In Proceedings of the 2025 IEEE Conference on Dependable and Secure Computing (DSC), Taipei, Taiwan, 18–20 October 2025. [Google Scholar] [CrossRef] [Scilit]
- Ibrahim, Y.; Abdel-Malek, M.A.; Azab, M.; Rizk, M.R. Privacy-preserved mutually-trusted 5G communications in presence of pervasive attacks. Internet Things 2025, 30, 101491. [Google Scholar] [CrossRef] [Scilit]
- Damir, M.T.; Niemi, V. Location Privacy, 5G AKA, and Enhancements. In Secure IT Systems; Springer: Cham, Switzerland, 2022. [Google Scholar] [CrossRef] [Scilit]
- Yang, L.; Weng, C.-E.; Chen, H.-C.; Chen, Y.-C.-K.; Yao, Y.-C. Attacks and Threats Verification Based on 4G/5G Security Architecture. In Innovative Mobile and Internet Services in Ubiquitous Computing; Springer: Cham, Switzerland, 2023; pp. 240–249. [Google Scholar] [CrossRef] [Scilit]
- Fan, W.; Shi, B.; Peng, C. NReplay: 5G Key Reinstallation Attack Based on NAS Layer Vulnerabilities. In Proceedings of the MILCOM 2024—2024 IEEE Military Communications Conference (MILCOM), Washington, DC, USA, 28 October–1 November 2024. [Google Scholar] [CrossRef] [Scilit]
- Qi, H.; Shen, Y.; Yin, B. Intelligent Trajectory Inference Through Cellular Signaling Data. IEEE Trans. Cogn. Commun. Netw. 2020, 6, 586–596. [Google Scholar] [CrossRef] [Scilit]
- Joshi, J.B.; Patel, S.J.; Parne, B.L.; Jariwala, V.J.; Desai, V.V. DS-AKA: Digital Signature-Based Authentication and Key Agreement Protocol to Mitigate Fake Serving Network for 5G Communication Networks. In Information Security, Privacy and Digital Forensics; Springer: Singapore, 2026; pp. 151–163. [Google Scholar] [CrossRef] [Scilit]
- Kim, H.; Lee, J.; Lee, E.; Kim, Y. Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane. In Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 19–23 May 2019; pp. 1153–1168. [Google Scholar] [CrossRef] [Scilit]
- Szczegielniak-Rekiel, A.; Kanciak, K.; Kelner, J.M. Zero-Knowledge Proof in 5G and Beyond Technologies: State of the Arts, Practical Aspects, Applications, Security Issues, Open Challenges, and Future Trends. IEEE Access 2025, 13, 138352–138380. [Google Scholar] [CrossRef] [Scilit]
- Rommer, S.; Mulligan, C.; Hedman, P.; Olsson, M.; Frid, L.; Sultana, S. Chapter 6—Security. In The Core Network for 5G Advanced, 2nd ed.; Elsevier: Amsterdam, The Netherlands, 2025. [Google Scholar] [CrossRef] [Scilit]
- Khan, M.; Ginzboorg, P.; Järvinen, K.; Niemi, V. Defeating the Downgrade Attack on Identity Privacy in 5G. In Security Standardisation Research; Springer: Cham, Switzerland, 2018. [Google Scholar] [CrossRef] [Scilit]
- Dixit, U.; Vittal, S.; A, A.F. A Systematic Study for Understanding the Security Risks in 5G Core Network. In Proceedings of the 2024 16th International Conference on COMmunication Systems & NETworkS (COMSNETS), Bengaluru, India, 3–7 January 2024. [Google Scholar] [CrossRef] [Scilit]
- Bhatt, R.P.; Shetty, S.; M.R., D.; P., S.N. Random Interleaving at MAC Layer for Privacy Protection in 6G RAN. In Proceedings of the 2025 International Conference on Smart Applications, Communications and Networking (SmartNets), Istanbul, Turkiye, 22–24 July 2025. [Google Scholar] [CrossRef] [Scilit]
- Noor, K.; Imoize, A.L.; Adelabu, M.A. A Comprehensive Survey on AI-Assisted Multiple Access Enablers for 6G and beyond Wireless Networks. CMES-Comput. Model. Eng. Sci. 2025, 145, 1575–1664. [Google Scholar] [CrossRef] [Scilit]
- Palamà, I.; Gringoli, F.; Bianchi, G.; Blefari-Melazzi, N. IMSI Catchers in the wild: A real world 4G/5G assessment. Comput. Netw. 2021, 194, 108137. [Google Scholar] [CrossRef] [Scilit]
- Sowjanya, K.; Pal, P.; Verma, A.; Das, B.; Saha, D.; Baswade, A.M.; Lall, B. SUPI-Rear: Privacy-Preserving Subscription Permanent Identification Strategy in 5G-AKA. In Stabilization, Safety, and Security of Distributed Systems; Springer: Cham, Switzerland, 2025. [Google Scholar] [CrossRef] [Scilit]
- Bang, I.; Kim, T.; Jang, H.S.; Sung, D.K. Impact of Uplink Power Control on User Location Tracking Attacks in Cellular Network. In Proceedings of the ICC 2021—IEEE International Conference on Communications, Montreal, QC, Canada, 14–23 June 2021. [Google Scholar] [CrossRef] [Scilit]
- Liu, F.; Su, L.; Yang, B.; Du, H.; Qi, M.; He, S. Security Enhancements to Subscriber Privacy Protection Scheme in 5G Systems. In Proceedings of the 2021 International Wireless Communications and Mobile Computing (IWCMC), Harbin, China, 28 June–2 July 2021; pp. 451–456. [Google Scholar] [CrossRef] [Scilit]
- Yang, T.; Wang, S.; Zhan, B.; Zhan, N.; Li, J.; Xiang, S.; Xiang, Z.; Mao, B. Formal Analysis of 5G Authentication and Key Management for Applications (AKMA). J. Syst. Archit. 2022, 126, 102478. [Google Scholar] [CrossRef] [Scilit]
- Sivasankar, S.; Challa, R. Closed Loop Paging Optimization for Efficient Mobility Management. In Proceedings of the 2021 IEEE 18th Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 9–12 January 2021. [Google Scholar] [CrossRef] [Scilit]
- Ghannam, R.; Sharevski, F.; Chung, A. User-targeted Denial-of-Service Attacks in LTE Mobile Networks. In Proceedings of the 2018 14th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob), Limassol, Cyprus, 15–17 October 2018. [Google Scholar] [CrossRef] [Scilit]
- Aoude, M. Hardening 5G Network Registration: An Analysis of ECIES Profiles and SHNIP. In Proceedings of the 2025 Sixth International Conference on Advances in Computational Tools for Engineering Applications (ACTEA), Zouk Mosbeh, Lebanon, 24–26 September 2025. [Google Scholar] [CrossRef] [Scilit]
- Fardan, I.; Mawaldi, I.; Anugraha, T.; Ginting, I.; Karna, N. Experimental Security Analysis for Fake eNodeB Attack on LTE Network. In Proceedings of the 2020 3rd International Seminar on Research of Information Technology and Intelligent Systems (ISRITI), Yogyakarta, Indonesia, 10 December 2020; pp. 140–145. [Google Scholar] [CrossRef] [Scilit]
- Fei, T.; Wang, W. The vulnerability and enhancement of AKA protocol for mobile authentication in LTE/5G networks. Comput. Netw. 2023, 228, 109685. [Google Scholar] [CrossRef] [Scilit]
- Hashim, H.A.; Abido, M.A. Location management in LTE networks using multi-objective particle swarm optimization. Comput. Netw. 2019, 157, 78–88. [Google Scholar] [CrossRef] [Scilit]
- Bang, I.; Kim, T.; Jang, H.S.; Sung, D.K. An Opportunistic Power Control Scheme for Mitigating User Location Tracking Attacks in Cellular Networks. IEEE Trans. Inf. Forensics Secur. 2022, 17, 1131–1144. [Google Scholar] [CrossRef] [Scilit]
- Fukuda, S.; Akimoto, T.; Hattori, T.; Murakami, Y.; Kawakami, H. Applying Causal Inference to Quantify Effects of TA Allocation Optimization on Paging Load. In Proceedings of the 2025 Fifteenth International Conference on Mobile Computing and Ubiquitous Networking (ICMU), Busan, Republic of Korea, 10–12 September 2025. [Google Scholar] [CrossRef] [Scilit]
- Singh, G.; Shrimankar, D. A Privacy-Preserving Authentication Protocol with Secure Handovers for the LTE/LTE-A Networks. Sādhanā 2018, 43, 128. [Google Scholar] [CrossRef] [Scilit]
- Bi, Y.; Jia, C. Towards Resilience 5G-V2N: Efficient and Privacy-Preserving Authentication Protocol for Multi-Service Access and Handover. IEEE Trans. Mob. Comput. 2025, 24, 5446–5463. [Google Scholar] [CrossRef] [Scilit]
- Ali, A.; Fischer, G. Symbol-Based Statistical RF Fingerprinting for Fake Base Station Identification. In Proceedings of the 2019 29th International Conference Radioelektronika (RADIOELEKTRONIKA), Pardubice, Czech Republic, 16–18 April 2019; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Bi, Y.; Jia, C. From Preparation to Execution: Security Protocol for Third-Party MES-Enabled 5G Support Handover Authentication and Key Evolution. IEEE Trans. Mob. Comput. 2026, 25, 1009–1026. [Google Scholar] [CrossRef] [Scilit]
- Aamer, B.; Chergui, H.; Benjillali, M. Clustering-Enabled Tracking Areas Design for Beyond-5G Networks: A Live Network Demo. In Proceedings of the 2023 International Wireless Communications and Mobile Computing (IWCMC), Marrakesh, Morocco, 19–23 June 2023; pp. 375–379. [Google Scholar] [CrossRef] [Scilit]
- Aamer, B.; Chergui, H.; Chergui, N.; Tourki, K.; Benjillali, M.; Verikoukis, C.; Debbah, M. Self-Tuning Spectral Clustering for Adaptive Tracking Areas Design in 5G Ultra-Dense Networks. In Proceedings of the 2019 IEEE Wireless Communications and Networking Conference (WCNC), Marrakesh, Morocco, 15–18 April 2019. [Google Scholar] [CrossRef] [Scilit]
- Escudero-Andreu, G.; Kyriakopoulos, K.; Flint, J.A.; Lambotharan, S. Detecting Signalling DoS Attacks on LTE Networks. In Industrial Networks and Intelligent Systems; Springer: Cham, Switzerland, 2019; pp. 283–301. [Google Scholar] [CrossRef] [Scilit]
- Pavloski, M. Signalling Attacks in Mobile Telephony. In Security in Computer and Information Sciences; Springer: Cham, Switzerland, 2018; pp. 130–141. [Google Scholar] [CrossRef] [Scilit]
- Yu, C.; Chen, S.; Cai, Z. LTE phone number catcher: A practical attack against mobile privacy. Secur. Commun. Netw. 2019, 2019, 7425235. [Google Scholar] [CrossRef] [Scilit]
- Zhao, J.; Li, Q.; Yuan, Z.; Zhang, Z.; Lu, S. 5G Messaging: System Insecurity and Defenses. In Proceedings of the 2022 IEEE Conference on Communications and Network Security (CNS), Austin, TX, USA, 3–5 October 2022. [Google Scholar] [CrossRef] [Scilit]
- Tripathi, A.; Rajput, A.; Subudhi, A.K.; Kondepu, K.; Thakur, A.; Tamma, B.R. Denial of Service Attacks Targeting Layer 2 in 5G RAN. In Proceedings of the 2025 IEEE Future Networks World Forum (FNWF), Bengaluru, India, 10–12 November 2025; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Saedi, M.; Moore, A.; Perry, P.; Shojafar, M.; Ullah, H.; Synnott, J.; Brown, R.; Herwono, I. Generation of Realistic Signal Strength Measurements for a 5G Rogue Base Station Attack Scenario. In Proceedings of the 2020 IEEE Conference on Communications and Network Security (CNS), Avignon, France, 29 June–1 July 2020; pp. 1–7. [Google Scholar] [CrossRef] [Scilit]
- Koutsos, A. The 5G-AKA Authentication Protocol Privacy. In Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden, 17–19 June 2019; pp. 464–479. [Google Scholar] [CrossRef] [Scilit]
- Khan, H.; Martin, K.M. A survey of subscription privacy on the 5G radio interface—the past, present and future. J. Inf. Secur. Appl. 2020, 53, 102537. [Google Scholar] [CrossRef] [Scilit]
- Huang, J.-H.; Cheng, S.-M.; Kaliski, R.; Hung, C.-F. Developing xApps for Rogue Base Station Detection in SDR-Enabled O-RAN. In Proceedings of the IEEE INFOCOM 2023—IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Hoboken, NJ, USA, 20 May 2023; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Patil, R.; Tian, Z.; Gurusamy, M.; McCloud, J. 5G Core Network Control Plane: Network Security Challenges and Solution Requirements. Comput. Commun. 2025, 229, 107982. [Google Scholar] [CrossRef] [Scilit]
- Oliveira, L.A.N.; Alencar, M.S.; Lopes, W.T.A.; Madeiro, F. On the Performance of Location Management in 5G Network Using RRC Inactive State. IEEE Access 2022, 10, 65520–65532. [Google Scholar] [CrossRef] [Scilit]
- Duan, S.; Lyu, F.; Wang, S.; Ding, Y.; He, X.; Zhang, Y. Exploring Cellular User Re-Identification Risks With Networking Behaviors Analysis and Modeling. IEEE Trans. Mob. Comput. 2026, 25, 2462–2479. [Google Scholar] [CrossRef] [Scilit]
- Xu, F.; Tu, Z.; Li, Y. Connecting the Dots: User Privacy Is Not Preserved in ID-Removed Cellular Data. IEEE Trans. Netw. Serv. Manag. 2020, 17, 147–159. [Google Scholar] [CrossRef]
- Tedeschini, B.C.; Kwon, G.; Nicoli, M.; Win, M.Z. Real-Time Bayesian Neural Networks for 6G Cooperative Positioning and Tracking. IEEE J. Sel. Areas Commun. 2024, 42, 2322–2338. [Google Scholar] [CrossRef] [Scilit]
- Wright, J.; Wolthusen, S. A Fail-Safe Challenge-Response Mechanism for User Equipment to Detect Rogue IMSI/SUPI Catchers. In Critical Infrastructure Protection XVIII; Springer: Cham, Switzerland, 2025; pp. 155–178. [Google Scholar] [CrossRef] [Scilit]
- Triesch, A.; Barsch, T.; Moonsamy, V.; Große-Kampmann, M. 5G Under Siege: A Comprehensive Guide to Threats and Penetration Testing in 5G Campus Networks. In Proceedings of the 2025 International Wireless Communications and Mobile Computing Conference (IWCMC), Abu Dhabi, United Arab Emirates, 12–16 May 2025; pp. 1312–1317. [Google Scholar] [CrossRef] [Scilit]
- Orlando, D.; Palamà, I.; Bartoletti, S.; Bianchi, G.; Melazzi, N.B. Design and Experimental Assessment of Detection Schemes for Air Interface Attacks in Adverse Scenarios. IEEE Wirel. Commun. Lett. 2021, 10, 1989–1993. [Google Scholar] [CrossRef] [Scilit]
- Feng, S.; Cui, B.; Fu, J.; Jiang, M.; Chang, S. Adaptive Target Device Model Identification Attack in 5G Mobile Network. IEEE Trans. Netw. Serv. Manag. 2026, 23, 1028–1042. [Google Scholar] [CrossRef] [Scilit]
- Zhang, W.; Chen, S.; Wei, Z.; Zhang, X.; Xing, Q.; Su, J. Cellular-Snooper: A General and Real-Time Mobile Application Fingerprinting Attack in LTE Networks. In Advanced Intelligent Computing Technology and Applications; Springer: Singapore, 2025; pp. 39–53. [Google Scholar] [CrossRef] [Scilit]
- Fraunholz, D.; Brunke, D.; Dumanski, L.; Koenig, H. Automating Device Fingerprinting Attacks in 4G and 5G NSA Mobile Networks. In Foundations and Practice of Security; Springer: Cham, Switzerland, 2023; pp. 192–207. [Google Scholar] [CrossRef] [Scilit]
- Khan, Q.; Purification, S.; Chang, S.-Y. Post-Quantum Key Exchange and ID Encryption Analyses for 5G Mobile Networking. In Proceedings of the NOMS 2025—2025 IEEE/IFIP Network Operations and Management Symposium, Honolulu, HI, USA, 12–16 May 2025; pp. 1–9. [Google Scholar] [CrossRef] [Scilit]
- Haddad, Z. Enhancing Privacy and Security in 5G Networks with an Anonymous Handover Protocol Based on Blockchain and Zero Knowledge Proof. Comput. Netw. 2024, 250, 110544. [Google Scholar] [CrossRef] [Scilit]
- Ouaissa, M.; Ouaissa, M.; Rhattoy, A. An efficient and secure authentication and key agreement protocol of LTE mobile network for an IoT system. Int. J. Intell. Eng. Syst. 2019, 12, 212–222. [Google Scholar] [CrossRef] [Scilit]
- Sun, S.; Abualhaol, I.; Poitau, G.; Esswie, A.; Repeta, M. An Ensemble Approach for Fake Base Station Detection Using Temporal Graph Analysis and Anomaly Detection. In Proceedings of the 2024 Wireless Telecommunications Symposium (WTS), Oakland, CA, USA, 10–12 April 2024; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Asim, M.; Ateya, A.A.; Wani, M.A.; Ali, G.; ElAffendi, M.; Abd El-Latif, A.A.; Siyal, R. A Comprehensive Survey on Blockchain-Enabled Techniques and Federated Learning for Secure 5G/6G Networks: Challenges, Opportunities, and Future Directions. Comput. Mater. Contin. 2026, 86, 3. [Google Scholar] [CrossRef] [Scilit]
- Hussain, S.; Chowdhury, O.; Mehnaz, S.; Bertino, E. LTEInspector: A systematic approach for adversarial testing of 4G LTE. In Proceedings of the Network and Distributed Systems Security (NDSS) Symposium 2018, San Diego, CA, USA, 18–21 February 2018. [Google Scholar] [CrossRef] [Scilit]
- Fei, T.; Wang, W. LTE Is Vulnerable: Implementing Identity Spoofing and Denial-of-Service Attacks in LTE Networks. In Proceedings of the 2019 IEEE Global Communications Conference (GLOBECOM), Waikoloa, HI, USA, 9–13 December 2019; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Ramisetty, S.; Ghantasala, G.S.P.; Sharma, R.R.; Vidyullatha, P.; Sungheetha, A. Mitigating Physical Layer Security Vulnerabilities in 4G and 5G Cellular Networks. In Proceedings of the 2025 12th International Conference on Computing for Sustainable Global Development (INDIACom), New Delhi, India, 2–4 April 2025. [Google Scholar] [CrossRef] [Scilit]
- Zhang, T.; Xiao, M.; Ouyang, R. Proving Mutual Authentication Property of 5G-AKA Protocol Based on PCL. In Theoretical Computer Science; Springer: Singapore, 2021; pp. 222–233. [Google Scholar] [CrossRef] [Scilit]
- Pauliac, M. USIM in 5G Era. J. ICT Stand. 2020, 8, 29–40. [Google Scholar] [CrossRef] [Scilit]
- Scotece, D.; Santaromita, G.; Fiandrino, C.; Foschini, L.; Giustiniano, D. On the Scalability of Access and Mobility Management Function: The Localization Management Function Use Case. IEEE Trans. Netw. Serv. Manag. 2026, 23, 2624–2635. [Google Scholar] [CrossRef] [Scilit]
- Alsaeedy, A.A.R.; Chong, E.K.P. Tracking Area Update Procedure Unnecessary in 5G: Improving User Experience and Offloading Signaling Overhead. In Proceedings of the 2018 9th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), New York, NY, USA, 8–10 November 2018; pp. 967–973. [Google Scholar] [CrossRef] [Scilit]
- Parkin, J.; Tripunitara, M. Countering Subscription Concealed Identifier (SUCI)-Catchers in Cellular Communications. In Proceedings of the 20th International Conference on Information Systems Security (ICISS 2024), Jaipur, India, 16–20 December 2024; Springer: Cham, Switzerland, 2025; pp. 107–126. [Google Scholar] [CrossRef] [Scilit]
- Kriaa, S.; Feki, A.; Papillon, S.; Chene, T.; Ouattara, I. Detecting Fake Base Stations Using Knowledge Graphs and ML-Based Techniques. In Proceedings of the 2023 IEEE Virtual Conference on Communications (VCC), Online, 28–30 November 2023; pp. 37–42. [Google Scholar] [CrossRef] [Scilit]
- Turnip, T.N.; Andersen, B.; Vargas-Rosales, C. Towards 6G Authentication and Key Agreement Protocol: A Survey on Hybrid Post-Quantum Cryptography. IEEE Commun. Surv. Tutor. 2025, 28, 3311–3345. [Google Scholar] [CrossRef] [Scilit]
- Sun, Z.; Peng, C. 5G-HCLS: An Authentication Protocol to Protect Bootstrapping Messages in 5G Network. In Proceedings of the 2025 IEEE Wireless Communications and Networking Conference (WCNC), Milan, Italy, 24–27 March 2025; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Haddad, Z. Blockchain-enabled anonymous mutual authentication and location privacy-preserving scheme for 5G networks. J. King Saud. Univ.-Comput. Inf. Sci. 2023, 35, 101458. [Google Scholar] [CrossRef] [Scilit]
- Shin, J.; Shin, Y.; Park, J.-G. Network Detection of Fake Base Station Using Automatic Neighbour Relation in Self-Organizing Networks. In Proceedings of the 2022 13th International Conference on Information and Communication Technology Convergence (ICTC), Jeju Island, Republic of Korea, 19–21 October 2022; pp. 968–970. [Google Scholar] [CrossRef] [Scilit]
- Ali, A.; Fischer, G. The Phase Noise and Clock Synchronous Carrier Frequency Offset Based RF Fingerprinting for the Fake Base Station Detection. In Proceedings of the 2019 IEEE 20th Wireless and Microwave Technology Conference (WAMICON), Cocoa Beach, FL, USA, 8–9 April 2019; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Butad, D.; Tao, S.M.; Tudtud, H.; Macapagal, A.J.; Astillo, P.V.; Choudhary, G.; Dragoni, N. Fake Base Station Detection and Localization in 5G Network: A Proof of Concept. In Mobile Internet Security; Springer: Singapore, 2024; pp. 3–17. [Google Scholar] [CrossRef] [Scilit]
- Purification, S.; Park, K.; Kim, J.; Kim, J.; Chang, S.-Y. Wireless Link Routing to Secure Against Fake Base Station in 5G. In Proceedings of the 2024 Silicon Valley Cybersecurity Conference (SVCC), Seoul, Republic of Korea, 17–19 June 2024. [Google Scholar] [CrossRef] [Scilit]
- Chlosta, M.; Rupprecht, D.; Holz, T.; Pöpper, C. LTE security disabled: Misconfiguration in commercial networks. In Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks; Association for Computing Machinery: New York, NY, USA, 2019; pp. 261–266. [Google Scholar] [CrossRef] [Scilit]
- Basheer, S.; Kumar, G.; Nalband, A.H.; Raveendran, C. Securing 5G Networks: Strategies for Prevention, Detection, and Mitigation of Rogue Base Stations. In Proceedings of the 2023 Fourth International Conference on Smart Technologies in Computing, Electrical and Electronics (ICSTCEE), Bengaluru, India, 8–9 December 2023. [Google Scholar] [CrossRef] [Scilit]
- Purification, S.; Wuthier, S.; Kim, J.; Kim, J.; Chang, S.-Y. Fake Base Station Detection and Blacklisting. In Proceedings of the 2024 33rd International Conference on Computer Communications and Networks (ICCCN), Kailua-Kona, HI, USA, 29–31 July 2024. [Google Scholar] [CrossRef] [Scilit]
- Paci, A.; Chiacchia, M.; Bianchi, G. 5GMap: Enabling external audits of access security and attach procedures in real-world cellular deployments. Comput. Commun. 2025, 234, 108091. [Google Scholar] [CrossRef] [Scilit]
- Samuthira Pandi, V.; Albert, A.J.; Thapa, K.N.K.; Krishnaprasanna, R. A Novel Enhanced Security Architecture for Sixth Generation (6G) Cellular Networks Using Authentication and Acknowledgement (AA) Approach. Results Eng. 2024, 21, 101669. [Google Scholar] [CrossRef] [Scilit]
- Rao, C.V.; Vandana, C.; Reddy, M.K.V.S.; Raju, K.S.; Sirisha, R.V.P.; Killamsetti, H. Advanced forest fire alert system with real-time GPS location tracking. In Proceedings of the 2023 2nd International Conference on Automation, Computing and Renewable Systems (ICACRS), Pudukkottai, India, 11–13 December 2023; pp. 95–99. [Google Scholar] [CrossRef] [Scilit]
- Alam, D.E.R.; Amelia, F.; Ogi, D.; Marlena, D. Design and development of a woman safety device prototype with fingerprint authentication. In Proceedings of the 2024 International Conference on Intelligent Cybernetics Technology & Applications (ICICyTA), Bali, Indonesia, 17–19 December 2024; pp. 790–795. [Google Scholar] [CrossRef] [Scilit]
- Hassain, M.M. IoT based smart walking stick for enhanced mobility of the visually impaired. In Proceedings of the 2024 International Conference on Innovations in Science, Engineering and Technology (ICISET), Chittagong, Bangladesh, 26–27 October 2024; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Aung, N.W.; Thein, T.L.L. Location tracking of accident detection on expressway for informing nearest rescue service. In Proceedings of the 2023 IEEE Conference on Computer Applications (ICCA), Yangon, Myanmar, 27–28 February 2023; pp. 369–374. [Google Scholar] [CrossRef] [Scilit]
- Jansi, S.; Sanjeevaiah, K.; Aruna, S.; Reddy, P.V.; Ganesh, D.; Suresh, J. Real-time distress detection and location tracking using a voice-activated system. In Proceedings of the 2025 10th International Conference on Communication and Electronics Systems (ICCES), Coimbatore, India, 28–30 October 2025; pp. 716–721. [Google Scholar] [CrossRef] [Scilit]
- Sarker, S.; Rahman, M.S.; Sakib, M.N. An approach towards intelligent accident detection, location tracking and notification system. In Proceedings of the 2019 IEEE International Conference on Telecommunications and Photonics (ICTP), Dhaka, Bangladesh, 28–30 December 2019; pp. 1–4. [Google Scholar] [CrossRef] [Scilit]
- Fung, N.M.; Wong Sing Ann, J.; Tung, Y.H.; Seng Kheau, C.; Chekima, A. Elderly fall detection and location tracking system using heterogeneous wireless networks. In Proceedings of the 2019 IEEE 9th Symposium on Computer Applications & Industrial Electronics (ISCAIE), Kota Kinabalu, Malaysia, 27–28 April 2019; pp. 44–49. [Google Scholar] [CrossRef] [Scilit]
- Ebenezer, P.R.; Priya, V.M.; Nivetha, B. GPS navigation with voice assistance and live tracking for visually impaired travelers. In Proceedings of the 2019 International Conference on Smart Structures and Systems (ICSSS), Chennai, India, 14–15 March 2019; pp. 1–4. [Google Scholar] [CrossRef] [Scilit]
- Fauziah, R.J.; Mutiara, G.A.; Periyadi. Smart tracking and fall detection for golden age’s citizen. Procedia Comput. Sci. 2019, 161, 1233–1240. [Google Scholar] [CrossRef] [Scilit]
- Heuer, C.; Jung, V.; Brell-Cokcan, S. A hardware-based RFID identification and tracking system for components in digitalised construction logistics. Dev. Built Environ. 2025, 23, 100726. [Google Scholar] [CrossRef] [Scilit]
- Park, S.H.; Shin, S.; Hong, S.; Kim, B.; Kim, T. Towards a control and optimization intelligence for 6G mobile networks. In Proceedings of the 2025 IEEE International Conference on Big Data (BigData); IEEE: New York, NY, USA, 2025; pp. 8312–8314. [Google Scholar] [CrossRef] [Scilit]
- Soualhia, M.; Ullah, M.A.; Yu, P. A hybrid quantum-classical computing for tracking area management for future networks. In Proceedings of the 2026 IEEE 23rd Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 9–12 January 2026; pp. 1–7. [Google Scholar] [CrossRef] [Scilit]
- Roensch, W.; Kwon, H.M.; Bhattarai, S.; Banavath, M.N. NextG positioning at user equipment against amplify-and-forward relay jamming. In Proceedings of the MILCOM 2025—2025 IEEE Military Communications Conference, Los Angeles, CA, USA, 6–10 October 2025; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Asim, M.; Wu, J.; Li, W.; Lin, Z.; Zhang, P.; He, H.; Wei, D.; Mohi-ud-Din, G. Quantum-resistant blockchain architecture for secure vehicular networks: An ML-KEM-enabled approach with PoA and PoP consensus. Future Gener. Comput. Syst. 2026, 180, 108391. [Google Scholar] [CrossRef] [Scilit]
- SLACOZE: Secure LoRa ad-hoc communication network over the dead zone. In Proceedings of the 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT), Delhi, India, 6–8 July 2023; pp. 1–7. [CrossRef] [Scilit]
- Lai, Y.; Xu, Y.; Yang, F.; Lu, W.; Yu, Q. Privacy-aware query processing in vehicular ad hoc networks. Ad. Hoc Netw. 2019, 91, 101876. [Google Scholar] [CrossRef] [Scilit]
- Sanwal, A.; Singh, S.P.; Pradhan, P.M. Development of an algorithm for reducing signalling overhead cost in 5G networks. In Proceedings of the 2021 Advanced Communication Technologies and Signal Processing (ACTS), Virtual, 15–17 December 2021; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Alsaeedy, A.A.R.; Chong, E.K.P. Mobility management for 5G IoT devices: Improving power consumption with lightweight signaling overhead. IEEE Internet Things J. 2019, 6, 8237–8247. [Google Scholar] [CrossRef] [Scilit]
- Makai, L.B.; Varga, P. Predicting mobility management demands of cellular networks based on user behavior. In Proceedings of the NOMS 2023—2023 IEEE/IFIP Network Operations and Management Symposium, Miami, FL, USA, 8–12 May 2023; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Wen, R.; Feng, G.; Zhou, J.; Qin, S. Mobility management for network slicing based 5G networks. In Proceedings of the 2018 IEEE 18th International Conference on Communication Technology (ICCT), Chongqing, China, 8–11 October 2018; pp. 291–296. [Google Scholar] [CrossRef] [Scilit]
- Purification, S.; Chang, S.-Y. Verifiable alerts for 4G/5G public warning system. In Proceedings of the 2025 IEEE Conference on Communications and Network Security (CNS), Avignon, France, 8–11 September 2025; pp. 1–9. [Google Scholar] [CrossRef] [Scilit]
- Zaidi, S.M.A.; Manalastas, M.; Farooq, H.; Imran, A. Mobility management in emerging ultra-dense cellular networks: A survey, outlook, and future research directions. IEEE Access 2020, 8, 183505–183533. [Google Scholar] [CrossRef] [Scilit]
- Sarah, A.; Nencioni, G.; Olimid, R.F. Multi-objective 5G-MEC service relocation: A joint view on performance, availability, and privacy. Future Gener. Comput. Syst. 2026, 176, 108211. [Google Scholar] [CrossRef] [Scilit]
- Dimou, S.; Noubir, G. ARGOS: Anomaly recognition and guarding through O-RAN sensing. In Proceedings of the 2025 IEEE Conference on Communications and Network Security (CNS), Avignon, France, 8–11 September 2025; pp. 1–11. [Google Scholar] [CrossRef] [Scilit]
- Talvitie, J.; Säily, M.; Valkama, M. Orientation and location tracking of XR devices: 5G carrier phase-based methods. IEEE J. Sel. Top. Signal Process. 2023, 17, 919–934. [Google Scholar] [CrossRef] [Scilit]
- Sumathi, D.; Prakasam, P.; Nandakumar, S.; Balaji, S. Efficient seamless handover mechanism and mobility management for D2D communication in 5G cellular networks. Wirel. Pers. Commun. 2022, 125, 2253–2275. [Google Scholar] [CrossRef] [Scilit]
- Kato, T.; Sasaki, C.; Tagami, A. Reducing signaling overhead in 5G mobile network for IoT device mobility. In Advanced Information Networking and Applications; Springer: Cham, Switzerland, 2024. [Google Scholar] [CrossRef] [Scilit]
- Agiwal, M.; Agiwal, A.; Maheshwari, M.K.; Muralidharan, S. Split PO for paging in B5G networks. J. Netw. Comput. Appl. 2022, 205, 103430. [Google Scholar] [CrossRef] [Scilit]
- Thulasinathan, Y.; Carvalho, G.H.S.; Woungang, I. BERT-driven intrusion detection system for 5G core security. In Proceedings of the 2025 4th International Conference on Computing, Management and Telecommunications (ComManTel), Madrid, Spain, 14–17 December 2025; pp. 64–69. [Google Scholar] [CrossRef] [Scilit]
- Scholler, R.; Alaoui-Ismaïli, O.; Couchot, J.-F.; Ballot, E.; Renaud, D. Observing road freight traffic from mobile network signalling data while respecting privacy and business confidentiality. In Privacy and Identity Management. Between Data Protection and Security; Springer: Cham, Switzerland, 2022. [Google Scholar] [CrossRef] [Scilit]
- Patruni, M.R.; Humayun, A.G. PPAM-mIoMT: A privacy-preserving authentication with device verification for securing healthcare systems in 5G networks. Int. J. Inf. Secur. 2024, 23, 679–698. [Google Scholar] [CrossRef] [Scilit]
- Parne, B.L.; Gupta, S.; Chaudhari, N.S. PSE-AKA: Performance and security enhanced authentication key agreement protocol for IoT-enabled LTE/LTE-A networks. Peer-to-Peer Netw. Appl. 2019, 12, 1156–1177. [Google Scholar] [CrossRef] [Scilit]
- Nyangaresi, V.O. Target tracking area selection and handover security in cellular networks: A machine learning approach. In Proceedings of the Third International Conference on Sustainable Expert Systems; Springer: Singapore, 2023. [Google Scholar] [CrossRef] [Scilit]
- Mahmood, A.; Vu, T.X.; Khan, W.U.; Chatzinotas, S.; Ottersten, B. UAV-assisted 5G networks: Mobility-aware 3D trajectory optimization and resource allocation for dynamic environments. In Proceedings of the 2025 IEEE 102nd Vehicular Technology Conference (VTC2025-Fall), Chengdu, China, 19–22 October 2025; pp. 1–7. [Google Scholar] [CrossRef] [Scilit]
- Wang, X.; Li, T.; Xiong, X.; Gao, Y.; Ning, Z. Federation chain for data privacy protection in industrial Internet of Things: The perspective from 5G core networks. IEEE Internet Things J. 2025, 12, 39260–39271. [Google Scholar] [CrossRef] [Scilit]
- Mir, A.; Zuhairi, M.F.; Musa, S.; Syed, T.A.; Alrehaili, A. POSTER: A survey of security challenges with 5G-IoT. In Proceedings of the 2020 First International Conference of Smart Systems and Emerging Technologies (SMARTTECH), Riyadh, Saudi Arabia, 3–5 November 2020; pp. 249–250. [Google Scholar] [CrossRef] [Scilit]
- Ibrahim, Y.; Abdel-Malek, M.A.; Azab, M.; Rizk, M.R. Towards in-depth trustworthy communications in NextG networks. In Proceedings of the 2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA, 6–8 January 2025; pp. 977–982. [Google Scholar] [CrossRef] [Scilit]
- Masood, A.; Scazzoli, D.; Sharma, N.; Le Moullec, Y.; Ahmad, R.; Reggiani, L.; Magarini, M.; Alam, M.M. Surveying pervasive public safety communication technologies in the context of terrorist attacks. Phys. Commun. 2020, 41, 101109. [Google Scholar] [CrossRef] [Scilit]
- Ogulenko, A.; Benenson, I.; Toger, M.; Östh, J.; Siretskiy, A. The fallacy of the closest antenna: Towards an adequate view of device location in the mobile network. Comput. Environ. Urban Syst. 2022, 95, 101826. [Google Scholar] [CrossRef] [Scilit]
- Liu, Y.; Tian, J.; Du, Y.; Li, S. A random sensitive area based privacy preservation algorithm for location-based service. Wirel. Pers. Commun. 2021, 119, 1179–1192. [Google Scholar] [CrossRef] [Scilit]
- Zhang, S.; Kang, H.; Yu, D. An enhanced location-data differential privacy protection method based on filter. In Smart Grid and Internet of Things; Springer: Cham, Switzerland, 2022. [Google Scholar] [CrossRef] [Scilit]
- Qu, Y.; Zhang, J.; Li, R.; Zhang, X.; Zhai, X.; Yu, S. Generative adversarial networks enhanced location privacy in 5G networks. Sci. China Inf. Sci. 2020, 63, 220303. [Google Scholar] [CrossRef] [Scilit]
- Li, M.; Yang, Q.; Zheng, X.; Nawaf, L. Spatiotemporal location privacy preservation in 5G-enabled sparse mobile crowdsensing. In Proceedings of the International Conference on Computing and Communication Networks; Springer: Singapore, 2022; pp. 277–295. [Google Scholar] [CrossRef] [Scilit]
- Zhang, C.; Xu, C.; Sharif, K.; Zhu, L. Privacy-preserving contact tracing in 5G-integrated and blockchain-based medical applications. Comput. Stand. Interfaces 2021, 77, 103520. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Yao, A.; Pal, S.; Li, X.; Zhang, Z.; Dong, C.; Jiang, F.; Liu, X. A privacy-preserving location data collection framework for intelligent systems in edge computing. Ad Hoc Netw. 2024, 161, 103532. [Google Scholar] [CrossRef] [Scilit]
- Liao, D.; Li, H.; Sun, G.; Zhang, M.; Chang, V. Location and trajectory privacy preservation in 5G-enabled vehicle social network services. J. Netw. Comput. Appl. 2018, 110, 108–118. [Google Scholar] [CrossRef] [Scilit]
- Ashok, P.; Prabhu, S. Attack-Resistant Cybersecurity Measures for Next-Generation Connected Electric Vehicles. Recent Adv. Electr. Electron. Eng. 2026, 19, 1–16. [Google Scholar] [CrossRef] [Scilit]














| Database | Number of Results |
|---|---|
| IEEE Xplore | 188 |
| Elsevier/ScienceDirect | 113 |
| Springer | 754 |
| Total | 1055 |
| Search Type | Search String |
|---|---|
| General search | ((Publication Title: “IMSI catcher” OR “fake base station” OR “rogue base station” OR “location tracking” OR “subscriber identity exposure”) OR (Abstract: “IMSI catcher” OR “fake base station” OR “rogue base station” OR “location tracking” OR “subscriber identity exposure” OR “identity leakage” OR “re-identification” OR “user tracking”)) AND (Abstract: “cellular network” OR “mobile network” OR GSM OR UMTS OR LTE OR “4G” OR “5G” OR NR) |
| Mapping search | (Abstract: “paging” OR “paging message” OR “temporary identifier” OR TMSI OR GUTI OR SUPI OR SUCI OR “timing advance” OR “measurement report” OR “cell ID” OR TAC OR ECGI OR “control plane” OR NAS OR RRC OR S1AP) AND (Abstract: “paging” OR “paging message” OR “temporary identifier” OR TMSI OR GUTI OR SUPI OR SUCI OR “timing advance” OR “measurement report” OR “cell ID” OR TAC OR ECGI OR “control plane” OR NAS OR RRC OR S1AP) AND (Abstract: “cellular network” OR “mobile network” OR GSM OR UMTS OR LTE OR “4G” OR “5G”) |
| Search Type | Generation | Search String |
|---|---|---|
| General search | 2G—GSM | (identity OR privacy OR tracking) AND (location OR localization) AND (GSM OR “2G”) |
| General search | 3G—UMTS | (identity OR privacy OR tracking) AND (location OR localization) AND (UMTS OR “3G”) |
| General search | 4G—LTE | (identity OR privacy OR tracking) AND (location OR localization) AND (LTE OR “4G”) |
| General search | 5G | (identity OR privacy OR tracking) AND (location OR localization) AND (“5G”) |
| Mapping search | 2G/3G | (identifier OR paging OR “temporary identifier”) AND (privacy OR tracking) AND (GSM OR UMTS) |
| Mapping search | 4G—LTE | (identifier OR paging OR “timing advance”) AND (tracking OR localization) AND (LTE) |
| Mapping search | 5G | (identifier OR “control plane”) AND (privacy OR tracking) AND (“5G”) |
| Search Type | Search String |
|---|---|
| General search | (“IMSI catcher” OR “fake base station” OR “rogue base station” OR “location tracking” OR “subscriber identity exposure” OR “identity leakage” OR “re-identification” OR “user tracking” OR “location privacy”) AND (“cellular network” OR “mobile network” OR GSM OR UMTS OR LTE OR “4G” OR “5G”) |
| Mapping search | (“paging” OR “paging message” OR “temporary identifier” OR TMSI OR GUTI OR SUPI OR SUCI OR “timing advance” OR “measurement report” OR “cell ID” OR TAC OR ECGI OR “control plane” OR NAS OR RRC OR S1AP) AND (“privacy” OR “tracking” OR “location inference” OR “re-identification” OR “identity exposure” OR “information leakage”) AND (“cellular network” OR “mobile network” OR GSM OR UMTS OR LTE OR “4G” OR “5G”) |
| Stage | Number of Articles |
|---|---|
| Identified records | 1055 |
| Duplicates removed | 91 |
| Title/abstract screening | 964 |
| Excluded articles | 831 |
| Full-text articles assessed | 133 |
| Studies included in the literature review | 86 |
| Field | Description |
|---|---|
| Network generation | 2G/3G/4G/5G |
| Analyzed architecture | GSM, UMTS, LTE, 5G NSA, 5G SA |
| Analyzed network component | RAN, Core Network, NAS, RRC |
| Field | Description |
|---|---|
| ID | Unique identifier of the study |
| Author(s) | Authors of the paper |
| Year of publication | Year in which the study was published |
| Publication type | Journal, conference paper, or book chapter |
| Field | Description |
|---|---|
| Attack type | Identification/location |
| Attack category | IMSI catcher, paging attack, tracking attack |
| Exploited mechanism | Paging, mobility update, measurement reporting, identity request |
| Attack level | Passive/active |
| Field | Description |
|---|---|
| Exploited identifier | IMSI, TMSI, GUTI, SUPI, SUCI |
| Exploited procedures | Attach, registration, paging, handover |
| Exploited radio parameters | Timing advance, RSRP, RSRQ |
| Used metadata | Cell ID, tracking area |
| Field | Description |
|---|---|
| Attack objective | Identification/location |
| Attack success rate | If available |
| Attack limitations | Required conditions for carrying out the attack |
| Field | Description |
|---|---|
| Countermeasure type | Standard mechanism/proposed solution |
| Implementation level | Network/terminal |
| Reported effectiveness | If evaluated |
| Characteristic | 5G NSA | 5G SA |
|---|---|---|
| Architecture and core network | Non-standalone deployment using 5G New Radio (NR) with an LTE/EPC anchor. | Standalone deployment using 5G New Radio (NR) with the 5G Core. |
| Subscriber identity handling | May inherit LTE/EPC identity handling, relying on IMSI, GUTI, and S-TMSI depending on the procedure and fallback scenario. | Uses SUPI as the permanent identity, SUCI as its concealed form, and 5G-GUTI as the temporary identity. |
| Control and mobility management | Control-plane and mobility procedures are largely LTE/EPC-dependent, commonly involving the eNodeB and MME. | Control-plane and mobility procedures are 5G-native, involving the gNodeB and AMF. |
| Main privacy risks | LTE anchor exposure, GUTI/S-TMSI linkability, LTE paging correlation, rogue eNodeB scenarios, and fallback/interworking risks. | 5G-GUTI linkability, paging-based presence inference, SUCI/SUPI misconfiguration, and implementation-specific weaknesses. |
| Mitigation focus | Frequent GUTI refresh, LTE paging hardening, rogue-cell detection, secure interworking, and restriction of insecure fallback. | Correct SUCI configuration, frequent 5G-GUTI rotation, AMF policy enforcement, privacy-preserving paging, and conformance testing. |
| Generation | Permanent Identifier | Temporary Identifier | Over-the-Air Identifier |
|---|---|---|---|
| 2G (GSM) | IMSI | TMSI | TMSI |
| 3G (UMTS) | IMSI | P-TMSI | P-TMSI |
| 4G (LTE) | IMSI | GUTI | GUTI [22] |
| 5G (NR) | SUPI | 5G-GUTI | SUCI, 5G-GUTI [23] |
| Generation | Procedure |
|---|---|
| 2G | Location Update |
| 3G | Location Area Update/Routing Area Update |
| 4G | Attach [30] |
| 5G | Registration [31] |
| Technology | Procedure |
|---|---|
| GSM | Location Area Update (LAU) |
| UMTS | Routing Area Update (RAU) |
| LTE | Tracking Area Update (TAU) [33] |
| 5G | Registration Update/Mobility Registration Update [7] |
| Technology | Procedure |
|---|---|
| GSM | Paging Request |
| UMTS | Paging |
| LTE | Paging Message [15] |
| 5G | Paging [7] |
| Generation | Mechanism |
|---|---|
| 2G (GSM) | Handover controlled by the BSC |
| 3G (UMTS) | Soft handover managed by the RNC |
| 4G (LTE) | X2 handover/S1 handover [37] |
| 5G (NR) | NG handover [38] |
| Algorithm | Generation | Qualified Security Status | References |
|---|---|---|---|
| A5/1 | 2G | Legacy cipher; practically broken. | [5,48] |
| A5/2 | 2G | Legacy weakened cipher; broken. | [5,48] |
| COMP128-1 | 2G | Legacy authentication algorithm; vulnerable. | [5,48] |
| KASUMI | 3G | Standardized, but affected by academic cryptanalysis. | [48] |
| SNOW 3G | 3G/4G | Standardized; no practical break reported in reviewed studies. | [48] |
| AES | 4G/5G | Standardized; security depends on mode, key length, and implementation. | [48] |
| ZUC | 4G/5G | Standardized; no practical break reported in reviewed studies. | [48] |
| Thematic Domain | Number of Studies | Percentage |
|---|---|---|
| Fake base stations | 28 | 32.6% |
| Authentication privacy | 27 | 31.4% |
| Location tracking | 12 | 14.0% |
| Cellular privacy | 10 | 11.6% |
| Protocol and signalling security | 6 | 7.0% |
| Reviews | 2 | 2.3% |
| Paging and mobility management | 1 | 1.2% |
| Attack Type | Number of Studies | Percentage |
|---|---|---|
| Semi-passive | 37 | 43.0% |
| Active | 32 | 37.2% |
| Passive | 17 | 19.8% |
| Performance Aspect | Studies | Directly Measured Metrics | Reported Quantitative Evidence |
|---|---|---|---|
| Location-tracking quality | S019, S015, S017 | Mobility-pattern recovery; signal-strength indicators; CRB-based privacy indicators | No common location-error metric; qualitative or indirect tracking indicators only. |
| Attack impact/ service disruption | S014 | Time to system collapse | System collapse in approximately 30 s. |
| Signalling overhead/ network cost | S001, S013, S033, S008, S009 | Messages per UE; MME load events; signalling-overhead reduction; TAU reduction; paging-request reduction; signalling-cost reduction | 500–800 and up to 1500 messages/UE; 34% MME load events; 92% overhead reduction; 8% fewer TAUs; 30% fewer paging requests; >30% signalling-cost reduction. |
| Execution time/ algorithmic convergence | S014, S033 | Collapse time; number of GA runs; stopping iterations | 30 s collapse time; 100 GA runs; 300 stopping iterations. |
| Detection performance | S014, S024 | Detection rate; false-positive rate; detection probability | Detection rate > 96%; false-positive rate < 3.8%; detection probability close to 1 for NCD/MNCD and <0.5 for SpD. |
| Mitigation Solution | Category | Level | Advantages | Practical Limitations/Operational Constraints | Representative Studies |
|---|---|---|---|---|---|
| Temporary identifier reallocation | Standardized/operator | Core/mobility management | Reduces long-term tracking through TMSI, GUTI, S-TMSI, and 5G-GUTI refresh. | Frequent refresh may increase signalling; infrequent refresh preserves linkability risks. | [7,8,10,48] |
| SUPI concealment through SUCI | Standardized | UE/Core/NAS | Protects permanent 5G identity; reduces direct SUPI/IMSI exposure. | Depends on correct SUCI configuration, key management, UE support, and avoidance of weak/null profiles. | [23,25,29,48,73] |
| Paging policy hardening and paging optimization | Standardized/operator/ academic | Core/RAN | Limits paging correlation, presence inference, and idle-mode exposure. | May affect reachability, latency, and signalling load; requires privacy-efficiency trade-offs. | [7,27,34,51,72] |
| Restriction of insecure fallback and inter-RAT mobility | Standardized/operator | Core/RAN/interworking | Reduces downgrade and legacy-procedure exposure. | Constrained by service continuity, roaming, emergency services, and legacy UE support. | [18,22,48,82] |
| Tracking area/registration area optimization | Academic/operator | Core/mobility management | Reduces unnecessary paging and can limit coarse location exposure. | May increase update overhead or conflict with signalling efficiency. | [32,34,39,40,72] |
| Rogue base station detection | Academic/commercial | RAN/terminal/monitoring | Detects fake BTS/eNodeB/gNodeB and supports operator or terminal alerts. | Accuracy depends on coverage, thresholds, radio conditions, and attacker behavior; false alarms may occur. | [22,49,55,57,74,78,80,83,84] |
| Cryptographic enhancements to authentication and identity protection | Academic/standard-oriented | UE/Core/protocol | Improves anonymity, unlinkability, and resistance to replay, downgrade, or fake-network attacks. | Often needs protocol changes, extra computation, standardization, and infrastructure compatibility. | [3,6,9,14,25,31,47,77] |
| Terminal-side suspicious cell detection | Academic/commercial | UE/terminal | Warns about suspicious cells, abnormal radio conditions, or identity requests. | Limited by OS/baseband access, device diversity, battery cost, and false positives/negatives. | [22,48,55,57] |
| Anomaly detection in signalling behavior | Academic/commercial | Core/RAN/monitoring | Identifies abnormal paging, attach, registration, or mobility-management patterns. | Requires visibility, baseline models, threshold tuning, and adaptation to roaming/heterogeneous traffic. | [2,28,41,50,64] |
| Operator-side monitoring and audit tools | Commercial/operator | Operator/RAN/core | Provides operational visibility, rogue-cell detection, anomaly monitoring, and audits. | Limited by vendor dependency, cost, integration complexity, transparency, and operator policies. | [22,49,50,84,85] |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Asimionesei, D.; Popescu, N.A. From 2G to 5G: Literature Review of Identification and Location Attacks in Cellular Networks. Computers 2026, 15, 446. https://doi.org/10.3390/computers15070446
Asimionesei D, Popescu NA. From 2G to 5G: Literature Review of Identification and Location Attacks in Cellular Networks. Computers. 2026; 15(7):446. https://doi.org/10.3390/computers15070446
Chicago/Turabian StyleAsimionesei, Daniel, and Nirvana Alina Popescu. 2026. "From 2G to 5G: Literature Review of Identification and Location Attacks in Cellular Networks" Computers 15, no. 7: 446. https://doi.org/10.3390/computers15070446
APA StyleAsimionesei, D., & Popescu, N. A. (2026). From 2G to 5G: Literature Review of Identification and Location Attacks in Cellular Networks. Computers, 15(7), 446. https://doi.org/10.3390/computers15070446

