Fake Base Station (FBS) detection has been a critical focus of cellular security research for over two decades. However, significant financial and regulatory barriers to accessing commercial FBS (C-FBS) devices have limited direct visibility into real-world operations, forcing detection systems to be designed and evaluated around self-built prototypes. In this paper, we present Devilray, a reconfigurable and reference-grade adversarial baseline designed to systematically explore the realistic adversarial space and identify adversarial blind spots in current detection -- regions of realistic adversarial behavior excluded by prevailing threat models. We establish an empirical ground truth through the first academic analysis of a C-FBS and extend these observations into specification-driven operational variants permitted by 3GPP standards. Devilray enables the systematic exploration of 2,592 feasible and realistic adversarial instances, capturing a wide range of operational possibilities. Using Devilray, we evaluate seven representative accessible FBS detectors and uncover coverage gaps across all seven, revealing blind spots rooted in assumption-bound design and evaluation. Our work provides the first robust adversarial model grounded in real-world behavior and specification analysis, enabling the community to develop and evaluate future detection mechanisms in a rigorous manner.
* Note that the analysis of detectors and detection primitives is provided in the second tab (“Primitive Analysis”) in the upper right.
* The logo design was generated with the assistance of Gemini.
Devilray is designed through a four-step methodology. First, it establishes a four-phase operational pipeline -- spanning scanning, launching, hijacking, and application -- through our empirical study of a commercial FBS and analysis of existing literature. Second, it employs specification-driven variation derivation to model realistic, standard-compliant adversarial strategies beyond single empirical observations. To ensure operational feasibility, the system integrates a semantics-aware dependency checker that validates compatibility and conflicts for adversarial configuration. Finally, Devilray is built as a modular, reconfigurable implementation that supports 2,592 unique adversarial instances.
This shows a modular and reconfigurable architecture of Devilray including its four-phase operational phases and seven variant dimensions.
We provide a complete list of configuration dependency rules used in Devilray. The rules are grouped into (1) intra-phase dependencies (constraints among parameters within the same phase) and (2) inter-phase dependencies (constraints that hold across phases). The below table complements the system overview (Section 5; dependency-checker design) by making the rules explicit and easy to inspect, filter, and cross-reference.
* For rule 20 (UE recovery), it is considered that the hijacked victim is in EMM-registered state and establishes NAS signalling connection with TAU Request or a Service Request
Devilray requires only one laptop and one or more USRPs (the demo uses B200s).
Through end-to-end configuration, Devilray effectively demonstrates IMSI-catching while emulating a legitimate cell (full adpatation). The complete setup can be stored and reused as a YAML-formatted configuration profile. For anonymity, sensitive network information such as the PLMN ID has been redacted.
Through pre-defined and reusable configuration profiles, Devilray can readily generate diverse adversarial instances.
Through a pre-defined and reusable configuration profile, Devilray effectively demonstrates 2G redirection and SMS injection while emulating a legitimate cell. For anonymity, sensitive network information such as the PLMN ID has been redacted.
To be released