Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE Networks

Byeongdo Hong (Ability Institute of Three)

Network and Distributed System Security (NDSS) Symposium 2026 · Day 3 · Covert Sensing

Overview

This research demonstrates a fully passive method to identify users' GUTI (Globally Unique Temporary Identifier) in LTE networks by correlating camera observations with RF signal captures. By watching when users interact with their phones (visual events) and matching those to data scheduling bursts on the air interface (RF events), an attacker can progressively narrow down which GUTI belongs to which person. The method achieves 97% GUTI extraction success and 94% verification success for up to 10 devices simultaneously within a single camera field of view, typically requiring only about three interactions per device.

Watch on YouTube · Slides

Visual summary for Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE Networks by Byeongdo Hong
Visual summary for Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE Networks by Byeongdo Hong

Key moments

  1. 0:00 LTE identifiers: GUTI, RNTI, and why GUTIs persist for 33 days
  2. 2:00 Attack overview: camera + SDR correlation for GUTI identification
  3. 4:00 FSM-based identification: scan, collect, filter, verify
  4. 6:00 Filtering candidates through intersection across visual events
  5. 8:00 Results: 97% extraction, 94% verification for up to 10 devices
  6. 10:00 Post-identification location tracking via paging messages
  7. 12:00 Q&A: 5G operators still not updating GUTIs despite mandate

Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE Networks

Speakers: Byeongdo Hong

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=Tkskuht41tc

Overview

This research demonstrates a fully passive method to identify users' GUTI (Globally Unique Temporary Identifier) in LTE networks by correlating camera observations with RF signal captures. By watching when users interact with their phones (visual events) and matching those to data scheduling bursts on the air interface (RF events), an attacker can progressively narrow down which GUTI belongs to which person. The method achieves 97% GUTI extraction success and 94% verification success for up to 10 devices simultaneously within a single camera field of view, typically requiring only about three interactions per device.

Once a GUTI is identified, it enables numerous practical attacks: location tracking, signaling attacks (overshadowing, targeted DoS), and traffic intelligence (website/video fingerprinting). Critically, this attack requires no transmission and no phone number -- just a camera and an SDR (software-defined radio) receiver.

Background

▶ Watch: LTE identifiers: GUTI, RNTI, and why GUTIs persist for 33 days (0:00)

In LTE networks, GUTI is a temporary layer-3 identifier intended to protect user privacy by avoiding transmission of permanent identifiers (IMSI, MSISDN). However, measurements show GUTIs can remain unchanged for up to 33 days, effectively making them long-lived identifiers. The S-TMSI component of the GUTI is the primary target, as recovering it effectively recovers the full GUTI.

At layer 2, RNTI (Radio Network Temporary Identifier) is used for data scheduling within a cell. The attack correlates visual observations of phone usage with RNTI-associated data bursts, then maps RNTIs to GUTIs through control plane messages (random access and RRC messages containing Contention Resolution Identities).

Key Findings

▶ Watch: FSM-based identification: scan, collect, filter, verify (4:00)

  • 97% GUTI extraction success, 94% verification success across up to 10 devices per field of view
  • Fully passive -- no transmissions, no phone numbers needed, just camera + SDR
  • FSM-based correlation narrows candidates across events, typically needing ~3 interactions per device
  • GUTI lifetime up to 33 days in real networks despite standards recommending frequent updates
  • Validated across 4 operators in 2 countries (including South Korea)
  • Post-identification location tracking demonstrated using paging messages
  • 5G SA networks should mandate GUTI updates but measurements show many operators still don't change them

Technical Deep Dive

▶ Watch: Filtering candidates through intersection across visual events (6:00)

The attack uses a Finite State Machine (FSM) with stages: init, scan, collect, filter, verify. During scan, the camera records timestamps of phone usage while the SDR captures DCI (Downlink Control Information) bursts per RNTI. A data burst is defined when cumulative data within a time window exceeds a threshold. The filter stage intersects candidate GUTI sets across multiple visual events until only one remains. Verification confirms the identified GUTI by checking burst correlation during a timeout window. Time synchronization between camera and SDR uses NTP with ~0.2 second tolerance.

Demo / Proof of Concept

▶ Watch: Post-identification location tracking via paging messages (10:00)

Field testing across 4 operators in 2 countries using iPhones and Samsung Galaxy models. USRP B210 + srsRAN used for RF capture. Post-identification location tracking demonstrated using serving cell detection and paging area monitoring.

Defensive Implications

▶ Watch: Q&A: 5G operators still not updating GUTIs despite mandate (12:00)

The simplest mitigation is setting a maximum GUTI lifetime and refreshing regardless of user behavior -- a policy change requiring no protocol modifications. Assigning new GUTIs per service request (as the standard suggests) would also help but can be blocked by attackers. 5G SA networks mandate GUTI updates but Q&A revealed many operators still don't comply.

Key Takeaways

  • Camera + SDR correlation passively identifies user GUTIs with 97% success across up to 10 devices
  • GUTIs persist for up to 33 days in practice, enabling long-term tracking once identified
  • GUTI identification is a key enabler making many "non-vulnerability" attacks practical
  • Fully passive attack requiring no transmission and no target phone number
  • Simple policy fix: enforce maximum GUTI lifetime regardless of user behavior
  • 5G operators still not updating GUTIs despite mandatory standard requirements

About the Speaker(s)

Byeongdo Hong is from the ETRI (Electronics and Telecommunications Research Institute) in South Korea. Prior work with Yong Kim on GUTI extraction via prefix pattern analysis led to a change in the 3GPP standard.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

A practical passive GUTI identification attack using camera + SDR correlation that achieves 97% success on up to 10 simultaneous targets. The FSM-based approach requiring only ~3 interactions per device is operationally viable, and the attack enables location tracking, targeted DoS, and traffic fingerprinting. The Q&A revealing that even 5G operators don't update GUTIs despite mandatory requirements makes this immediately relevant.

Heather Calloway (CISO) — STRONG

A passive cellular surveillance technique that identifies user identifiers through camera and SDR correlation, enabling location tracking and targeted attacks. While primarily a concern for individuals at risk of targeted surveillance, the scalability to 10 simultaneous targets and the finding that 5G operators still don't update GUTIs despite mandatory requirements have broader policy implications.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2026

All talks from Network and Distributed System Security (NDSS) Symposium 2026