New Attack Fingerprints Federated Learning Models via 5G Side Channels

Md Nahid Hasan Shuvo, Mahmudul Hassan Ashik, Moinul Hossain· July 20, 2026 View original

Summary

Researchers developed FLINT, a black-box attack that can infer the architecture of Federated Learning (FL) models (CNNs, RNNs, Transformers) by analyzing 5G Physical (PHY) layer side-channel information. This method works even when user payloads are encrypted, posing a significant security risk to FL deployments over 5G networks.

This paper introduces FLINT, a novel black-box fingerprinting framework that can identify the architectural family of Federated Learning (FL) models, such as CNNs, RNNs, or Transformers. This is achieved by analyzing side-channel information from the 5G Physical (PHY) layer, specifically the scheduling metadata broadcast over the Physical Downlink Control Channel (PDCCH). Unlike previous attacks, FLINT does not require packet-level network visibility, which is often unavailable due to encryption and changing identifiers in 5G. FLINT overcomes these limitations by decoding PDCCH data, mapping dynamic Radio Network Temporary Identifiers (RNTIs) to specific user devices, and applying multi-view temporal modeling to discern architecture-specific training patterns. The ability to infer a client's model architecture from low-level 5G signals is a critical security vulnerability, as it can enable more targeted and effective downstream attacks. Experiments on a real 5G testbed demonstrated FLINT's high accuracy, achieving a macro F1-score of 0.930 for architecture classification.

Why it matters

This research highlights a critical security vulnerability in Federated Learning deployments over 5G, urging professionals to re-evaluate their security postures and consider new mitigation strategies.

How to implement this in your domain

  1. 1Assess the security implications of PHY-layer side-channel attacks on your 5G-enabled FL deployments.
  2. 2Investigate methods to obfuscate or randomize PHY-layer scheduling patterns during FL training.
  3. 3Collaborate with 5G network providers to understand and mitigate potential side-channel leakage.
  4. 4Implement robust anomaly detection systems to identify unusual traffic patterns indicative of reconnaissance.
  5. 5Review and update security protocols for FL clients, assuming potential knowledge of model architectures.

Who benefits

TelecommunicationsCybersecurityAI DevelopmentDefenseAutomotive

Key takeaways

  • 5G PHY-layer side channels can reveal Federated Learning model architectures.
  • FLINT is a black-box attack that works despite encryption and dynamic identifiers.
  • Knowledge of model architecture enables more targeted downstream attacks.
  • New security measures are needed for FL deployments over 5G networks.

Original post by Md Nahid Hasan Shuvo, Mahmudul Hassan Ashik, Moinul Hossain

"arXiv:2607.15469v1 Announce Type: cross Abstract: Federated Learning (FL) over 5G cellular networks protects raw data but remains vulnerable to side-channel leakage. Prior fingerprinting attacks assume packet-level network visibility, an assumption that does not hold at the 5G Ph…"

View on X

Originally posted by Md Nahid Hasan Shuvo, Mahmudul Hassan Ashik, Moinul Hossain on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses