abstract
- question
- What should a tool do when the data isn't enough for a clear answer?
- method
- Two cases: celltrace (which tower serves a phone, without GPS) and AccessScope (what a Minecraft server replies). In both, the result carries its own uncertainty
- result
- celltrace gives low, medium or high confidence; AccessScope returns «ambiguous» when its rules disagree, and doesn't report an account problem as a ban
- limits
- There's no measurement of how much precision improves by abstaining; it's a design decision, backed by a well-known idea (Chow, 1970)
Some tools always give you an answer, even when they don't have one. In two of my projects I went the other way: if the data isn't enough, the result says so
What a phone knows about the network
A connected phone knows more than it shows: the country and carrier (MCC and MNC), the area (LAC in 3G, TAC in LTE and 5G), the cell serving it (Cell ID) and the signal quality. In LTE, the reference signal power is measured as RSRP and its quality as RSRQ (both defined in the 3GPP TS 36.214 specification); RSSNR is the signal-to-noise ratio. CellTraceLogger records all of it, on 5G NR, LTE and 3G
observation (one NDJSON line) │ MCC · MNC · TAC · Cell ID · RSRP · RSRQ · RSSNR ▼ celltrace ◄── OpenCellID: Cell ID → approximate position │ does one cell dominate over time? is the signal stable? ▼ most likely tower · confidence
Mind what a Cell ID identifies: the cell, usually one sector of an antenna, not an exact point. And a cell's position in OpenCellID comes from crowdsourced measurements, so it's approximate too. That's why celltrace infers infrastructure (which tower or sector), not where a person is
celltrace: low, medium or high confidence
Every inference comes with a confidence level, based on how stable the signal was and whether one cell dominates over time. If cells overlap or the network is unstable, it says so instead of picking one. The project page has a simulation: when the phone sits between two towers, the observations split and confidence goes down
AccessScope: rules that vote
AccessScope joins a Minecraft server like a player would (with Mineflayer) and classifies what the server replies: the kick message, the MOTD, the version. The classification uses hand-written rules, and the rules vote. If two point to different things, the result is «ambiguous» and none is picked:
message: "This server is whitelisted. Banned players cannot join." whitelist ✓ → whitelist ban ✓ → ban ───────────────────────────── result → ambiguous
It doesn't stretch the evidence either: an account problem isn't reported as a ban, because it's no evidence of one
The underlying idea: abstaining
This has a name in pattern recognition: a classifier with a reject option. C. K. Chow formalized it in 1970: if a system can decline to decide in doubtful cases, it makes fewer errors on the ones it does decide, at the cost of answering less often. It's a trade-off between precision and coverage
always answer → high coverage, more errors stated with confidence
abstain when unsure → lower coverage, fewer errors in what gets answered
and the doubtful cases stay in plain sightBoth tools pick the second side. And in AccessScope the aggregation rule is conservative on purpose: the majority doesn't win, there has to be no contradiction
ideaA wrong answer stated with confidence does more harm than an «I don't know». If the tool admits doubt, whoever uses it knows when to trust it and when to take a closer look
Limits
- AccessScope's rules only cover messages I've already seen; a new one stays unclassified until its rule is written. That happened with a ban message in Spanish it didn't recognize at first
- celltrace's quality depends on how many cells in the area are in OpenCellID; where data is scarce, confidence drops even with a good signal
- I didn't measure how much precision goes up by abstaining: the argument is a design one, not an experimental result
Frequently asked questions
Can you tell which cell tower serves your phone without GPS?
Yes, approximately. The phone knows the Cell ID of the cell serving it and the signal quality; matching that Cell ID against an open database like OpenCellID gives an approximate position for the tower or sector
Is locating a tower the same as locating a person?
No. A Cell ID identifies a cell, which can cover a large area. celltrace infers infrastructure, not anyone's exact location
What are RSRP and RSRQ?
Two LTE measurements defined by 3GPP: RSRP is the power of the reference signal reaching the phone, and RSRQ is its quality, taking interference into account
How can you tell if a Minecraft server has you banned or whitelisted?
From the message the server sends when it kicks you. AccessScope reads it, classifies it with rules, and if the rules disagree it answers «ambiguous» instead of guessing
Why should a tool be able to say «I don't know»?
Because abstaining in doubtful cases reduces errors in the cases it does answer. That is the idea of the classifier with a reject option (Chow, 1970)
References
- C. K. Chow · On optimum recognition error and reject tradeoff · IEEE Transactions on Information Theory, 1970
- 3GPP TS 36.214 · E-UTRA Physical layer measurements (RSRP and RSRQ definitions)
- OpenCellID · open database of cell towers · opencellid.org
- Mineflayer · Minecraft client for Node.js · github.com/PrismarineJS/mineflayer
- Nuulz/celltrace · the Python library · github.com/Nuulz/celltrace