{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T12:29:37Z","timestamp":1780316977637,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2403050"],"award-info":[{"award-number":["2403050"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,3]]},"DOI":"10.1145\/3680207.3723469","type":"proceedings-article","created":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T13:19:18Z","timestamp":1763731158000},"page":"201-215","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Automated Model-Based Fuzzing for 5G O-RAN"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0694-1753","authenticated-orcid":false,"given":"Sixu","family":"Tan","sequence":"first","affiliation":[{"name":"University of California, Riverside, Riverside, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-8335-4619","authenticated-orcid":false,"given":"Zeyu","family":"Li","sequence":"additional","affiliation":[{"name":"University of California, Riverside, Riverside, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-4076-6045","authenticated-orcid":false,"given":"Zhutian","family":"Liu","sequence":"additional","affiliation":[{"name":"University of California, Riverside, Riverside, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2562-7920","authenticated-orcid":false,"given":"Harsh","family":"Patel","sequence":"additional","affiliation":[{"name":"University of California, Riverside, Riverside, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0118-7917","authenticated-orcid":false,"given":"Zhaowei","family":"Tan","sequence":"additional","affiliation":[{"name":"University of California, Riverside, Riverside, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"O-RAN Alliance. https:\/\/www.o-ran.org\/."},{"key":"e_1_3_2_1_2_1","unstructured":"NOKIA O-RAN. https:\/\/www.nokia.com\/networks\/radio-access-networks\/open-ran\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Mavenir O-RAN. https:\/\/www.mavenir.com\/portfolio\/mavair\/radio-access\/openran\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Vodafone O-RAN. https:\/\/www.vodafone.com\/about-vodafone\/what-we-do\/mobile-and-fixed-networks\/open-ran."},{"key":"e_1_3_2_1_5_1","volume-title":"Attacking o-ran interfaces: Threat modeling, analysis and practical experimentation","author":"Baguer Pau","year":"2024","unstructured":"Pau Baguer, Girma M Yilma, Esteban Municio, Gines Garcia-Aviles, Andres Garcia-Saavedra, Marco Liebsch, and Xavier Costa-P\u00e9rez. Attacking o-ran interfaces: Threat modeling, analysis and practical experimentation. IEEE Open Journal of the Communications Society, 2024."},{"key":"e_1_3_2_1_6_1","volume-title":"Evaluating the security of open radio access networks. arXiv","author":"Mimran Dudu","year":"2022","unstructured":"Dudu Mimran, Ron Bitton, Yehonatan Kfir, Eitan Klevansky, Oleg Brodt, Heiko Lehmann, Yuval Elovici, and Asaf Shabtai. Evaluating the security of open radio access networks. arXiv 2022."},{"key":"e_1_3_2_1_7_1","unstructured":"O-RAN Work Group 11 (Security Work Group). O-RAN Security Threat Modeling and Risk Assessment. https:\/\/specifications.o-ran.org\/download?id=697."},{"key":"e_1_3_2_1_8_1","unstructured":"ORAN-WG8.IOT.0-R003-v08.00. https:\/\/www.o-ran.org\/specifications."},{"key":"e_1_3_2_1_9_1","unstructured":"Two big open ran successes and two big problems. https:\/\/www.rcrwireless.com\/20231003\/fundamentals\/two-big-open-ran-successes-and-two-big-problems."},{"key":"e_1_3_2_1_10_1","unstructured":"OpenAirInterface Software Alliance. OpenAirInterface5G. https:\/\/openairinterface.org\/."},{"key":"e_1_3_2_1_11_1","volume-title":"Understanding o-ran: Architecture, interfaces, algorithms, security, and research challenges","author":"Polese Michele","year":"2023","unstructured":"Michele Polese, Leonardo Bonati, Salvatore D'oro, Stefano Basagni, and Tommaso Melodia. Understanding o-ran: Architecture, interfaces, algorithms, security, and research challenges. IEEE Communications Surveys & Tutorials, 2023."},{"key":"e_1_3_2_1_12_1","unstructured":"O-RAN Specifications. https:\/\/www.o-ran.org\/specifications."},{"key":"e_1_3_2_1_13_1","unstructured":"NG-RAN; F1 Application Protocol (F1AP)."},{"key":"e_1_3_2_1_14_1","unstructured":"Sulley. https:\/\/github.com\/OpenRCE\/sulley."},{"key":"e_1_3_2_1_15_1","unstructured":"Spike. https:\/\/gitlab.com\/kalilinux\/packages\/spike."},{"key":"e_1_3_2_1_16_1","unstructured":"American Fuzzy Lop. https:\/\/github.com\/google\/AFL."},{"key":"e_1_3_2_1_17_1","unstructured":"radamsa. https:\/\/github.com\/google\/AFL."},{"key":"e_1_3_2_1_18_1","unstructured":"honggfuzz. https:\/\/github.com\/google\/AFL."},{"key":"e_1_3_2_1_19_1","volume-title":"Sage: White-box fuzzing for security testing: Sage has had a remarkable impact at microsoft. Queue","author":"Godefroid Patrice","year":"2012","unstructured":"Patrice Godefroid, Michael Y. Levin, and David Molnar. Sage: White-box fuzzing for security testing: Sage has had a remarkable impact at microsoft. Queue 2012."},{"key":"e_1_3_2_1_20_1","unstructured":"Nick Stephens John Grosen Christopher Salls Andrew Dutcher Ruoyu Wang Jacopo Corbetta Yan Shoshitaishvili Christopher Kruegel and Giovanni Vigna. Driller: Augmenting fuzzing through selective symbolic execution. In NDSS 16."},{"key":"e_1_3_2_1_21_1","unstructured":"Boofuzz. https:\/\/github.com\/jtpereyda\/boofuzz."},{"key":"e_1_3_2_1_22_1","volume-title":"American fuzzy lop. URL: http:\/\/lcamtuf.coredump.cx\/afl","author":"Zalewski Michal","year":"2014","unstructured":"Michal Zalewski. American fuzzy lop. URL: http:\/\/lcamtuf.coredump.cx\/afl, 2014."},{"key":"e_1_3_2_1_23_1","volume-title":"Learning regular sets from queries and counterexamples. Information and computation","author":"Angluin Dana","year":"1987","unstructured":"Dana Angluin. Learning regular sets from queries and counterexamples. Information and computation, 1987."},{"key":"e_1_3_2_1_24_1","unstructured":"Spirent. Comprehensive Open RAN Testing. https:\/\/www.spirent.com\/campaign\/how-to-test-open-ran."},{"key":"e_1_3_2_1_25_1","first-page":"34","volume-title":"USENIX Security 22","author":"Chen Yi","unstructured":"Yi Chen, Di Tang, Yepeng Yao, Mingming Zha, XiaoFeng Wang, Xiaozhong Liu, Haixu Tang, and Dongfang Zhao. Seeing the forest for the trees: Understanding security hazards in the {3GPP} ecosystem through intelligent analysis on change requests. In USENIX Security 22, pages 17\u201334."},{"key":"e_1_3_2_1_26_1","unstructured":"Syed Rafiul Hussain Imtiaz Karim Abdullah Al Ishtiaq Omar Chowdhury and Elisa Bertino. Noncompliance as deviant behavior: An automated black-box noncompliance checker for 4g lte cellular devices. In CCS 21."},{"key":"e_1_3_2_1_27_1","volume-title":"NFV-SDN","author":"Jiang Hao","year":"2023","unstructured":"Hao Jiang, Hyunseok Chang, Sarit Mukherjee, and Jacobus Van der Merwe. Oztrust: An o-ran zero-trust security system. In NFV-SDN 2023."},{"key":"e_1_3_2_1_28_1","volume-title":"IEEE TMC","author":"Groen Joshua","year":"2024","unstructured":"Joshua Groen, Salvatore D'Oro, Utku Demir, Leonardo Bonati, Davide Villa, Michele Polese, Tommaso Melodia, and Kaushik Chowdhury. Securing o-ran open interfaces. IEEE TMC, 2024."},{"key":"e_1_3_2_1_29_1","unstructured":"RRC Specifications. https:\/\/portal.3gpp.org\/."},{"key":"e_1_3_2_1_30_1","unstructured":"NAS Specifications. https:\/\/portal.3gpp.org\/."},{"key":"e_1_3_2_1_31_1","unstructured":"Daniel Klischies Moritz Schloegel Tobias Scharnowski Mikhail Bogodukhov David Rupprecht and Veelasha Moonsamy. Instructions unclear: Undefined behaviour in cellular network specifications. In USENIX Security 23."},{"key":"e_1_3_2_1_32_1","volume-title":"Mobicom","author":"Raza Muhammad Taqi","year":"2019","unstructured":"Muhammad Taqi Raza and Songwu Lu. A systematic way to lte testing. In Mobicom 2019."},{"key":"e_1_3_2_1_33_1","unstructured":"Bernhard K. Aichernig Edi Muskardin and Andrea Pferscher. Learning-Based Fuzzing of IoT Message Brokers. In ICST Porto de Galinhas Brazil."},{"key":"e_1_3_2_1_34_1","volume-title":"ICNP","author":"Hsu Yating","year":"2018","unstructured":"Yating Hsu, Guoqiang Shu, and David Lee. A model-based approach to security flaw detection of network protocol implementations. In ICNP 2018."},{"key":"e_1_3_2_1_35_1","volume-title":"GLOBECOM","author":"Garbelini Matheus E.","year":"2022","unstructured":"Matheus E. Garbelini, Zewen Shang, Sudipta Chattopadhyay, Sumei Sun, and Ernest Kurniawan. Towards Automated Fuzzing of 4G\/5G Protocol Implementations Over the Air. In GLOBECOM 2022, Rio de Janeiro, Brazil."},{"key":"e_1_3_2_1_36_1","unstructured":"Prakhar Sharma and Vinod Yegneswaran. PROSPER: Extracting Protocol Specifications Using Large Language Models. In ACM HotNets 23."},{"key":"e_1_3_2_1_37_1","unstructured":"Yi Chen and Di Tang. Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning."},{"key":"e_1_3_2_1_38_1","volume-title":"l*lm: Learning automata from examples using natural language oracles. arXiv preprint arXiv:2402.07051","author":"Vazquez-Chanlatte Marcell","year":"2024","unstructured":"Marcell Vazquez-Chanlatte, Karim Elmaaroufi, Stefan J Witwicki, and Sanjit A Seshia. l*lm: Learning automata from examples using natural language oracles. arXiv preprint arXiv:2402.07051, 2024."},{"key":"e_1_3_2_1_39_1","volume-title":"ICST","author":"Pham Van-Thuan","year":"2020","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, and Abhik Roychoudhury. Aflnet: a greybox fuzzer for network protocols. In ICST 2020."},{"key":"e_1_3_2_1_40_1","unstructured":"OpenAI. Claude3. https:\/\/claude.ai\/."},{"key":"e_1_3_2_1_41_1","unstructured":"Anthropic. GPT4.0. https:\/\/chatgpt.com\/."},{"key":"e_1_3_2_1_42_1","volume-title":"Fuzzing: a survey for roadmap. ACM Computing Surveys (CSUR), 54(11s):1\u201336","author":"Zhu Xiaogang","year":"2022","unstructured":"Xiaogang Zhu, Sheng Wen, Seyit Camtepe, and Yang Xiang. Fuzzing: a survey for roadmap. ACM Computing Surveys (CSUR), 54(11s):1\u201336, 2022."},{"key":"e_1_3_2_1_43_1","unstructured":"DOT Language. https:\/\/graphviz.org\/doc\/info\/lang.html."},{"issue":"3","key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","first-page":"417","DOI":"10.1007\/s11334-022-00449-3","article-title":"an active automata learning library","volume":"18","author":"Mu\u0161kardin Edi","year":"2022","unstructured":"Edi Mu\u0161kardin, Bernhard K Aichernig, Ingo Pill, Andrea Pferscher, and Martin Tappler. Aalpy: an active automata learning library. Innovations in Systems and Software Engineering, 18(3):417\u2013426, 2022.","journal-title":"Innovations in Systems and Software Engineering"},{"key":"e_1_3_2_1_45_1","unstructured":"Wireshark Org. tshark. https:\/\/www.wireshark.org\/docs\/man-pages\/tshark.html."},{"key":"e_1_3_2_1_46_1","unstructured":"Pycrate. https:\/\/github.com\/pycrate-org\/pycrate."},{"key":"e_1_3_2_1_47_1","unstructured":"pysctp. https:\/\/pypi.org\/project\/pysctp\/."},{"key":"e_1_3_2_1_48_1","unstructured":"OpenAirInterface Software Alliance. OAI 5G CN. https:\/\/openairinterface.org\/oai-5g-core-network-project\/."},{"key":"e_1_3_2_1_49_1","unstructured":"GNU. gcov. https:\/\/gcc.gnu.org\/onlinedocs\/gcc\/Gcov.html."},{"key":"e_1_3_2_1_50_1","unstructured":"Jinsheng Ba Marcel B\u00f6hme Zahra Mirzamomen and Abhik Roy-choudhury. Stateful greybox fuzzing. In USENIX Security 22."},{"key":"e_1_3_2_1_51_1","volume-title":"Sgpfuzzer: A state-driven smart graybox protocol fuzzer for network protocol implementations","author":"Yu Yingchao","year":"2020","unstructured":"Yingchao Yu, Zuoning Chen, Shuitao Gan, and Xiaofeng Wang. Sgpfuzzer: A state-driven smart graybox protocol fuzzer for network protocol implementations. IEEE Access, 2020."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28865-9_18"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24556"},{"key":"e_1_3_2_1_54_1","unstructured":"Haohuang Wen Phillip Porras Vinod Yegneswaran Ashish Gehani and Zhiqiang Lin. 5g-spector: An o-ran compliant layer-3 cellular attack detection service. In NDSS 24."},{"key":"e_1_3_2_1_55_1","volume-title":"Security threats to xapps access control and e2 interface in o-ran","author":"Hung Cheng-Feng","year":"2024","unstructured":"Cheng-Feng Hung, You-Run Chen, CHI-Heng Tseng, and Shin-Ming Cheng. Security threats to xapps access control and e2 interface in o-ran. IEEE Open Journal of the Communications Society, 2024."},{"key":"e_1_3_2_1_56_1","unstructured":"Kashyap Thimmaraju Altaf Shaik Sunniva Fl\u00fcck Pere Joan Fullana Mora Christian Werling and Jean-Pierre Seifert. Security testing the o-ran near-real time ric & a1 interface. In ACM WISEC 24."},{"key":"e_1_3_2_1_57_1","first-page":"1938","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Yang Tianchang","year":"2024","unstructured":"Tianchang Yang, Syed Md Mukit Rashid, Ali Ranjbar, Gang Tan, and Syed Rafiul Hussain. {ORANalyst}: Systematic testing framework for open {RAN} implementations. In 33rd USENIX Security Symposium (USENIX Security 24), pages 1921\u20131938, 2024."}],"event":{"name":"ACM MOBICOM '25: 31st Annual International Conference on Mobile Computing and Networking","location":"Kerry Hotel, Hong Kong Hong Kong China","acronym":"ACM MOBICOM '25","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"]},"container-title":["Proceedings of the 31st Annual International Conference on Mobile Computing and Networking"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3680207.3723469","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T13:23:56Z","timestamp":1763731436000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3680207.3723469"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,3]]},"references-count":57,"alternative-id":["10.1145\/3680207.3723469","10.1145\/3680207"],"URL":"https:\/\/doi.org\/10.1145\/3680207.3723469","relation":{},"subject":[],"published":{"date-parts":[[2025,11,3]]},"assertion":[{"value":"2025-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}