When the UE Turns Adversary: Real-Time Uplink Jamming from Within 5G Networks
For 5G network security researchers and operators, this work reveals a new vulnerability in the Physical Uplink Shared Channel, demonstrating that reactive jamming from within the network is practically feasible under realistic constraints.
This paper introduces STORM-RJ, a reactive jamming attack that exploits decoded Downlink Control Information to selectively interfere with specific User Equipment's uplink transmissions in 5G NR networks, achieving microsecond-scale synchronization through low-level radio control.
This paper presents an investigation of a novel class of stealthy and selective reactive jamming attacks targeting the Physical Uplink Shared Channel (PUSCH) in 5G New Radio (NR) networks. We design and implement STORM-RJ (Stealthy Timing Obstruction and Radio Manipulation -- Reactive Jamming), a Software-Defined Radio (SDR)-based adversarial framework that enables highly precise, time-frequency aligned interference by dynamically adapting the bandwidth and center frequency of injected noise bursts in real time. STORM-RJ leverages decoded Downlink Control Information (DCI) to identify Uplink-Grants (UL-Grants) and synchronizes interference exactly with the resource blocks allocated to a target User Equipment (UE). We further characterize and mitigate the dominant latency sources -- both at the software processing and hardware Radio Frequency (RF) frontend levels -- to achieve a rapid jamming response upon grant detection. We conduct a comparative analysis of high-level versus low-level radio control strategies, demonstrating that only low-level tuning provides the microsecond-scale responsiveness necessary to meet 5G-NR timing constraints for effective reactive jamming. We analyze the practical feasibility of such selective jamming under realistic hardware and timing constraints, highlighting key trade-offs between SDR flexibility, processing latency, and synchronization accuracy. Finally, we discuss potential mitigation strategies, including Hybrid Automatic Repeat reQuest (HARQ) anomaly detection.