[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85200-en":3,"doc-seo-85200-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85200,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",8,"Research & Report","Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis","Cellular core networks (CNs) depend on an assumed internal trust zone, but cloud-native transitions weaken physical isolation and expose component interfaces to external attackers. Root-cause analysis of GitHub-reported flaws in open-source CN implementations reveals a recurring blind-trust pattern: missing syntactic validation, weak semantic invariants, and unchecked resource availability. These implicit trust errors (iTrues) can enable denial of service and session hijacking. To find iTrues, iFinder uses an LLM-driven multi-agent workflow with spec–code crosschecking and automated PoC generation refined by execution, uncovering 84 new vulnerabilities across seven implementations.","Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis  \nZiyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang Nanyang Technological University  \narXiv :2607 . 103 15v 1 [ cs .CR] 11 Jul 2026  \nAbstract  \nCellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. From a root-cause analysis of security flaws reported in GitHub issues for opensource CN implementations, we found a recurring pattern of blind trust among CN components. Components may omit syntactic validation, fail to enforce semantic invariants, or allocate resources without checking availability. Once internal interfaces become reachable, these weaknesses can lead to severe impacts such as denial of service and session hijacking. We call these vulnerabilities implicit trust errors (iTrue) .  \nTo detect iTrues and understand their security impacts, we designed iFinder, an LLM-driven multi-agent system that summarizes known flaws, distills them into detection patterns, and applies them to discover new iTrues in CN implementations. To suppress hallucinations produced by large language models (LLMs), we built an innovative strategy that crosschecks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN implementations and analyzing results. Running iFinder on seven prominent open-source CN implementations, we discovered 84 previously unknown vulnerabilities. Among them, 83 have already been confirmed and 81 have been assigned CVEs. Importantly, a session-hijacking flaw has been confirmed on real-world commercial 5G core networks. Our findings highlight the pervasiveness of iTrue risks across the cellular core networks and the urgent need for elevated protection within the original trust domains. We plan to make iFinder publicly available to help enhance the security of cellular core networks.  \n1 Introduction  \nCellular core networks are critical infrastructure underpinning everyday communication for billions of users. Vulnerabilities in these systems can cause large-scale service disruptions and compromise user privacy, making their security of paramount importance [1] . Historically, core network (CN) security has relied on physical isolation: internal interfaces between network functions operate within a trusted zone, often deployed without strong encryption or mutual authentication [2] . This trust model, however, is increasingly fragile. As operators migrate CNs to cloud-native deployments, the security perimeter shifts from physically isolated private infrastructure to shared cloud environments with complex network topologies [3] . Prior work has demonstrated that attackers can reach CN interfaces through cloud misconfigurations or by abusing GTP-U tunnels to inject arbitrary traffic [4] . These architectural changes expose internal interfaces to external adversaries, invalidating the implicit-trust assumption that has long underpinned core network security.  \nVulnerabilities in CN. Given these emerging attack surfaces, there is an urgent need for systematic approaches to uncover vulnerabilities in core network implementations. Yet, prior work has largely focused on analyzing interactions either between user equipment (UE) and CN components through the Non-Access Stratum (NAS) [5–9], or between base stations and the CN via protocols such as the Next-Generation Application Protocol (NGAP) [7, 9] and the GPRS Tunnelling Protocol User Plane (GTP-U) [9] . To ","cbCaigaJzZMm20iH","https://ap.wps.com/l/cbCaigaJzZMm20iH","pdf",6318650,2,1,19,"English","en",105,"# Introduction\n## Trust model fragility in cloud-native core networks\n## Need for systematic vulnerability discovery\n## Root-cause analysis of GitHub-reported flaws\n# iFinder for detecting implicit trust errors","[{\"question\":\"What are implicit trust errors (iTrues) in cellular core networks?\",\"answer\":\"iTrues are security vulnerabilities that arise when CN components implicitly trust each other’s inputs and states. They commonly result from missing syntactic validation, missing semantic enforcement, or failure to check resource availability once internal interfaces become externally reachable.\"},{\"question\":\"Why does the risk of iTrues increase during cloud-native deployments?\",\"answer\":\"Cloud-native migration weakens the physical isolation that originally kept interfaces in a trusted zone. Misconfigurations and network tunneling abuse can make internal CN interfaces reachable from external adversaries, breaking the implicit-trust assumption.\"},{\"question\":\"How does iFinder detect and validate iTrues?\",\"answer\":\"iFinder summarizes known flaws into detection patterns, then applies them to discover new iTrues in CN implementations. It reduces hallucinations by crosschecking 3GPP specifications and CN code, generates PoC exploits with LLMs, and iteratively refines them by automatically executing and analyzing results.\"}]",1784201703,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"understanding-implicit-trust-errors-in-core-carrier-networks-through-multi-agent-flaw-discovery-and-analysis","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/understanding-implicit-trust-errors-in-core-carrier-networks-through-multi-agent-flaw-discovery-and-analysis/85200/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are implicit trust errors (iTrues) in cellular core networks?","Question",{"text":75,"@type":76},"iTrues are security vulnerabilities that arise when CN components implicitly trust each other’s inputs and states. They commonly result from missing syntactic validation, missing semantic enforcement, or failure to check resource availability once internal interfaces become externally reachable.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why does the risk of iTrues increase during cloud-native deployments?",{"text":80,"@type":76},"Cloud-native migration weakens the physical isolation that originally kept interfaces in a trusted zone. Misconfigurations and network tunneling abuse can make internal CN interfaces reachable from external adversaries, breaking the implicit-trust assumption.",{"name":82,"@type":73,"acceptedAnswer":83},"How does iFinder detect and validate iTrues?",{"text":84,"@type":76},"iFinder summarizes known flaws into detection patterns, then applies them to discover new iTrues in CN implementations. It reduces hallucinations by crosschecking 3GPP specifications and CN code, generates PoC exploits with LLMs, and iteratively refines them by automatically executing and analyzing results.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]