Artifact for "<Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities>" (USENIX Security 2026)
Description
This record contains the artifact release (v1.0) for the USENIX
Security 2026 paper "<Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities>".
The artifact provides an end-to-end implementation of a constraint-
driven analysis and test case generation pipeline for 5G RRC messages.
It includes:
- (A1) a simulation-based 5G SA testbed built on an OAI gNB with updated
downlink interception hooks; - (A2) a modular, constraint-driven toolchain for document preprocessing,
IE collection extraction, field-pair context extraction,
LLM-assisted constraint synthesis, and DSL-guided test case
generation; and - (A3) simulation-oriented test cases and proof-of-concept exploits that
demonstrate semantic constraint violations via the gNB message
delivery path.
All exploit code provided in this artifact is intended solely for use
in controlled simulation environments. Exploits that require over-the-
air (OTA) injection against commercial devices are intentionally
excluded for ethical and safety reasons.
Files
CONSET-usenix-sec26-artifact-v1.0.zip
Additional details
Dates
- Issued
-
2025-12-18