Yongdae Kim / KAIST SysSec RAN Security Papers Summary
Cellular security research landscape

RAN Security
Papers Summary

A curated view of 17 in-scope published papers by Professor Yongdae Kim or the KAIST SysSec cellular-security team. LTE dominates the corpus, with the strongest 5G-relevant risk concentrated in baseband integrity, lower-layer fuzzing, and control-plane conformance gaps that can spill into multi-mode or fallback-heavy private 5G deployments.

17 published papers LTE-heavy evidence base 5G direct signal: LLFuzz No primary O-RAN paper found

Executive Summary

The strongest primary source is the KAIST SysSec publication list. Across the set, recurring themes are baseband implementation flaws, LTE and 5G lower-layer fuzzing, RRC and NAS negative testing, broadcast and control-channel weaknesses, localization and tracking, VoLTE and IMS mis-implementations, and core or infrastructure conformance gaps.

Main Security Themes

  • Baseband firmware and lower-layer parser flaws
  • LTE RRC, NAS, and control-plane negative testing
  • Broadcast and control-channel integrity weaknesses
  • Tracking, localization, and metadata privacy leakage

External Evidence Status

Roughly half the findings have external support from CVEs, vendor advisories, GSMA disclosures, standards discussions, or later independent research. Several tool and methodology papers remain only partially reproduced outside the original team.

5G Mission-Critical View

LLFuzz, BaseComp, BaseSpec, and DoLTEst are the most important 5G-relevant results because private 5G devices still depend on multi-mode basebands, shared firmware logic, and LTE or NSA fallback in real-world deployments.

Source Limitations

Some ACM and IEEE pages were access-restricted. Open PDFs, KAIST and author pages, USENIX or NDSS pages, ResearchGate metadata, and official CVE or NVD records were used when publisher full text was not openly available.

Inclusion Criteria

A paper counted as in scope only when authorship, topic, publication status, affected-generation basis, corroboration quality, and mission-critical relevance all met the stated bar.

1

Team Link

Yongdae Kim authorship or a clear KAIST SysSec cellular-security team origin.

2

Topic Scope

Cellular RAN, baseband, LTE or 5G radio protocols, control plane, localization, VoLTE, or mobile infrastructure security.

3

Publication Status

Accepted or published conference, journal, or workshop paper. Untied preprints were excluded.

4

Generation Basis

Each affected generation is marked explicit, inferred, or not specified based on paper evidence.

5

Corroboration Standard

Needed substantive support such as a CVE, vendor bulletin, GSMA disclosure, standards record, or independent peer work.

6

5G Impact Test

Assessed only where the paper directly affects 5G, shared basebands, LTE fallback, or private 5G operational patterns.

Paper Explorer

Reverse-chronological paper cards with searchable details, severity, corroboration status, and mission-critical framing.

Mission-Critical 5G Impact Matrix

The highest operational concern is not every LTE result in isolation, but the way multi-mode basebands, LTE fallback, and private-network device fleets inherit the same trust and robustness assumptions.

Cross-Paper Synthesis

The papers form a consistent story: cellular security failures persist where standards are complex, implementations are opaque, integrity is assumed rather than verified, and radio metadata remains exposed.

Protocol and Implementation Gaps

DoLTEst, LTEFuzz, BaseSpec, BaseComp, FirmState, LLFuzz, and CITesting all highlight brittle state machines, exception handling errors, or spec drift that only appears under negative or adversarial input.

Baseband Research Progression

The research arc moves from static conformance analysis to integrity-protection comparison, state-aware emulation, device negative testing, and finally over-the-air lower-layer fuzzing. That progression is the clearest mission-critical 5G signal in the set.

Privacy Becomes Operational Security

GUTI tracking, video identification, passive 3D tracking, UMA, and LTESniffer show that exposed scheduling, paging, and uplink signals can reveal people, devices, and movement patterns without privileged access.

Broadcast and Control Trust Gaps

SigOver is the clearest example of structural weakness: critical radio information can be manipulated when integrity is absent or incomplete on broadcast or paging-related paths.

Infrastructure Is Also the Attack Surface

CITesting, VoLTE, IPv6 middlebox, and accounting papers show the risk is not only at the handset. Core state integrity, operator policy, IMS logic, and charging behavior are all security boundaries.

Recurring Root Causes

  1. Missing or incomplete integrity protection
  2. Complex state machines with weak negative testing
  3. Opaque vendor baseband implementations
  4. Standards ambiguity and optional behavior
  5. Multi-generation fallback and backward compatibility
  6. Operator-specific policy differences
  7. Unencrypted scheduling, paging, or radio metadata

Bibliography Snapshot

Primary papers, corroborating records, and excluded or de-prioritized candidates from the original source material.

Standalone HTML page generated from the provided research summary. Open index.html directly in a browser.