Search arXiv⌕ Search

arXiv · 2610.05007

Toward Lightweight Aerial 5G gNBs: Reproducible OAI Testbed on Commodity ARM Platforms

Abstract

For a battery-powered UAV base station, every gram and watt devoted to RAN-compute competes with flight-duration margin. We therefore keep the 5G Core (5GC) and central unit (CU) on the ground and design the airborne unit around only the backhaul endpoint, distributed unit (DU), and radio. The key question is then a practical one: can widely available commodity ARM computers sustain a real radio OpenAirInterface (OAI) 5G DU with useful performance over heterogeneous F1? We answer it with Raspberry Pi~5 and Jetson Orin Nano as DUs, a USRP B210, a commercial handset, and Ethernet, Wi-Fi/GRE, and 5G/WireGuard backhaul. Jetson preserves 88.4% of x86 split-DU Ethernet DL throughput and 87.5-89.0% across all three bearers; 5G/WireGuard preserves 76.4-77.1% of each host's wired DL rate. The validated Jetson/B210/RM500Q-GL electronics weigh 657.4 g and draw about 28 W under sustained traffic (757.4 g with integration allowance). A controlled link adaptation intervention raises split DL from 23.4 to 99.4 Mb/s as the dominant Modulation and Coding Scheme (MCS) moves from 3 to 26. Finally, synchronized radio, F1-U, CPU, and UHD evidence narrows the remaining monolithic-split gap to split-path scheduling/timing behavior. Beyond performance, this capability serves the emergency-response use case that motivates the aerial cell: once deployed above an affected area, it can broadcast a PWS warning message. We release the OAI patch that carries the single-segment Write-Replace Warning over F1 from CU to DU, where SIB8 is scheduled to the handset. The public artifact makes the payload, performance, and emergency-broadcast baseline reproducible with laboratory-accessible hardware.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Marc Duboc, Ammar El Falou. 2026-10-04. Toward Lightweight Aerial 5G gNBs: Reproducible OAI Testbed on Commodity ARM Platforms. https://arxiv.org/abs/2610.05007

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Rethinking Latency Denial-of-Service: Attacking the LLM Serving Framework, Not the Model

LLM inference is inherently expensive, even a modest slowdown can translate into substantial operating costs and severe availability risks. Recently, a growing body of research known as latency attacks focuses on crafting inputs to trigger worst-case output lengths. However, we report a contrary finding that these algorithmic-level latency attacks are largely ineffective against modern LLM serving systems. We reveal that system-level optimization such as continuous batching provides a logical isolation to mitigate contagious latency impact on co-located users. Thus, in this paper, we shift our focus from the algorithm to the system layer, and introduce a new Fill and Squeeze attack strategy targeting the state transition of the scheduler. ``Fill'' first exhausts the global KV cache to induce Head-of-Line blocking, while ``Squeeze'' forces the system into repetitive preemption. By manipulating output lengths using different attack prompts, and leveraging side-channel probing of memory status, we demonstrate that the attack can succeed in a practical black-box setting with much less cost. Extensive evaluations on vLLM indicate up to $75-742\times$ TTFT degradation relative to benign baselines and $1.5-4\times$ average slowdown on Time Per Output Token compared to existing attacks with 30-40% lower attack cost. Code: https://github.com/Phil-Fan/FS-attack

cs.CR↗

mAVE: A Watermark for Joint Audio-Visual Generation Models

Watermarking joint audio-visual generation supports vendor copyright protection and content provenance. However, independently valid audio and video watermarks do not establish a shared generation session. An adversary can splice watermarked modalities from different sessions, causing the pair to be mistaken for the vendor's original joint output. We introduce mAVE (Manifold Audio-Visual Entanglement), a training-free watermarking framework that strengthens vendor attribution through session binding in native joint audio-visual diffusion transformers. mAVE separates public record retrieval from secret session authentication: a fixed public index locates the server record, while a randomized payload binds audio bits to a session-keyed video grid through a cryptographic digest. One prompt-conditioned joint inversion supports provider-assisted verification of both modalities against a session record, without modifying generator weights or training auxiliary watermark networks. Our analysis establishes implementation-matched distribution preservation and a full-initialization routing/clipping budget, alongside adaptive session-pool security and stable local-perturbation bounds. Experiments on LTX-2 and MOVA show comparable generation quality. mAVE achieves 99.8\% true-positive rate and 0\% observed false-positive rate in the evaluated swap test, and retains 99.2\% true-positive rate under FrameAvg temporal averaging. Same-prompt and similarity-selected swaps further test session authentication beyond perceptual compatibility.

cs.CR↗

Context-Binding Gaps in Stateful Zero-Knowledge Proximity Proofs: Taxonomy, Separation, and Mitigation

A zero-knowledge proximity proof certifies geometric nearness but carries no commitment to an application context. In stateful geo-content systems, where drops can share coordinates, policies evolve, and content has persistent identity, this gap can permit proof transfer between application objects. We present a systems-security analysis of this deployment problem: a taxonomy of context-binding vulnerabilities; a formal model whose replay game asks whether a recorded proof transcript can be re-bound to a different application context (fresh in-radius proving is provably beyond any statement-level mechanism and is delegated to an orthogonal presence layer); an assumption comparison across five binding strategy classes; and a concrete instantiation, Zairn-ZKP, that embeds drop identity, policy version, and session context as public circuit inputs. In-proof binding removes the nonce-to-drop mapping and nonce-uniqueness invariants from the operational assumption set and adds no measurable proving cost over a sound geo-only baseline. A hardened stored-digest check blocks the same transfer attacks under per-request nonces, but its resistance comes from an in-statement challenge digest -- a hybrid, not a purely off-circuit design -- while purely off-circuit strategies cannot resist an adversary able to request fresh challenges; holding nonce policy constant, in-proof context binding is the only strategy blocking same-epoch transfer under shared nonces. Measurements across six network conditions, seven venues in four countries, and an epoch-window simulation indicate same-epoch transfer is a realistic concern in dense urban deployments. Evaluation spans five platforms, seven strategies, and an end-to-end transfer attack; all artifacts are public.

cs.CR↗