Computer Science · MapleScholar Plus

The AI Hacker Swarm: How Automated Agents Found 84 Flaws in the World's 5G Backbone

Human security engineers spent a decade auditing 5G cellular infrastructure; an autonomous swarm of AI agents uncovered over eighty critical security flaws in core carrier networks in days. By simulating adversarial protocol exploits across open-source telecom code, this automated penetration tool patched catastrophic session-hijacking vulnerabilities before malicious state actors could exploit them.

Author
Ziyu Lin et al.
Published
2026
Journal
arXiv (Cornell University)
Last updated
September 2026
The AI Hacker Swarm: How Automated Agents Found 84 Flaws in the World's 5G Backbone

The global mobile network connecting billions of smartphones and emergency services relies on massive, million-line telecommunications protocols. Because software modules assume their internal partners are trustworthy, microscopic logical blind spots have slipped past human code reviewers for years.

Cybersecurity researchers unleashed a collaborative swarm of artificial intelligence agents designed to hunt implicit trust bugs. Working like a team of white-hat hackers, the AI agents probed 4G and 5G software, discovering eighty-four major zero-day vulnerabilities that allowed attackers to hijack cellular sessions and eavesdrop on calls.

This AI discovery resulted in eighty-one official emergency security patches across global carrier software. By uncovering deep structural flaws in national cellular backbones, by defending critical emergency communications, and by automating telecom defense, multi-agent cybersecurity shields global telecommunications.

Reference

Lin, Z., Wang, Z., Li, X., Dong, W., & Wang, X. F. (2026). Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis (Version 1). arXiv.

Title

Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis

Abstract

Cellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. From a root-cause analysis of security flaws reported in GitHub issues for opensource CN implementations, we found a recurring pattern of blind trust among CN components. Components may omit syntactic validation, fail to enforce semantic invariants, or allocate resources without checking availability. Once internal interfaces become reachable, these weaknesses can lead to severe impacts such as denial of service and session hijacking. We call these vulnerabilities implicit trust errors (iTrue). To detect iTrues and understand their security impacts, we designed iFinder, an LLM-driven multi-agent system that summarizes known flaws, distills them into detection patterns, and applies them to discover new iTrues in CN implementations. To suppress hallucinations produced by large language models (LLMs), we built an innovative strategy that crosschecks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN implementations and analyzing results. Running iFinder on seven prominent open-source CN implementations, we discovered 84 previously unknown vulnerabilities. Among them, 83 have already been confirmed and 81 have been assigned CVEs. Importantly, a session-hijacking flaw has been confirmed on real-world commercial 5G core networks.

Cited 0 times · View on doi.org

Continue

Continue Exploring

Ask this paper your own questions, or keep browsing the verified research catalogue.