This paper focuses on the challenge-response physical-layer authentication (CR-PLA) scheme where a reflecting intelligent surface (RIS) is under the control of a receiving base station (BS) (Bob) who aims at checking if received messages come from a legitimate user equipment (UE) Alice or from an impersonating device (Trudy). To this end, Bob sets a random configuration of the RIS which remains secret to the attacker, and verifies that the channel estimated on the received message corresponds to the set configuration. We design the probability distribution of RIS configurations chosen by the verifier to maximize average capacity while satisfying an upper bound on missed detection (MD) probability for a given false alarm (FA) probability. The balance of communication and security metrics demonstrated by the numerical results shows the effectiveness and potential of the CR-PLA scheme.
The computation of positioning, navigation and timing (PNT) via signal of opportunity (SOP), where signals originally transmitted for communication, such as 5G, Wi-Fi, or DVB-S, are exploited due to their ubiquity and spectral characteristics, is an emerging research field. However, relying on these signals presents challenges, including limited knowledge of the signal modulation and the need to identify recurring sequences for correlation. We offer a guide to implement a receiver capable of capturing broadband downlink Ku-band signals from low Earth orbit (LEO) satellites (e.g., Starlink and OneWeb) and estimating the recurring symbols for SOP measurements. The methodology integrates recent approaches in the literature, highlighting the most effective aspects while guiding the replication of experiments even under limitations on the front-end gain and bandwidth. Using the proposed model, we can identify recurring symbols transmitted by Starlink satellites, which are then used to collect Doppler shift measurements over a 600 s interval. A position, velocity, and time (PVT) solution is also computed via least squares (LS), which achieves a positioning error of approximately 268 m after a post-fit refinement.
The rise of wireless technologies has made the Internet of Things (IoT) ubiquitous, but the broadcast nature of wireless communications exposes IoT to authentication risks. Physical layer authentication (PLA) offers a promising solution by leveraging unique characteristics of wireless channels. As a common approach in PLA, hypothesis testing yields a theoretically optimal Neyman-Pearson (NP) detector, but its reliance on channel statistics limits its practicality in real-world scenarios. In contrast, deep learning-based PLA approaches are practical but tend to be not optimal. To address these challenges, we proposed a learning-based PLA scheme driven by hypothesis testing and conducted extensive simulations and experimental evaluations using Wi-Fi. Specifically, we incorporated conditional statistical models into the hypothesis testing framework to derive a theoretically optimal NP detector. Building on this, we developed LiteNP-Net, a lightweight neural network driven by the NP detector. Simulation results demonstrated that LiteNP-Net could approach the performance of the NP detector even without prior knowledge of the channel statistics. To further assess its effectiveness in practical environments, we deployed an experimental testbed using Wi-Fi IoT development kits in various real-world scenarios. Experimental results demonstrated that the LiteNP-Net outperformed the conventional correlation-based method as well as state-of-the-art Siamese-based methods.
Integrated sensing and communication (ISAC) is a promising feature of future communication networks. While spatial sensing can improve network performance and enable external services, it also creates privacy challenges that go beyond the confidentiality of communication content. Future networks using millimeter-wave (mmWave) and sub-terahertz (THz) frequencies may collect or infer detailed information about people, devices, bystanders, passive objects, and environments in a sixth-generation (6G) deployment area. Such sensing can reveal location and environment data, support behavioral profiling such as movement or activity recognition, and, in advanced cases, expose physiological information such as breathing frequency or heart-rate-related data. Thus, the capabilities of spatial sensing must be controlled to satisfy privacy requirements. In this work, we organize privacy-sensitive ISAC data into three sensing levels: location and environment data, behavioral data, and physiological data, and use this classification as the organizing principle throughout the paper. Based on this classification, we discuss internal and external ISAC applications, identify privacy challenges related to consent, transparency, data ownership, profiling, bystander exposure, and sensitive sensing data, review representative solution directions, and outline future research directions for privacy-preserving ISAC.
Due to their ability to manipulate (EM) fields with high flexibility and low-cost implementation, metasurfaces have emerged as a promising technology to enhance the performance of cellular networks. We propose a novel reconfigurable antenna using transmitting metasurfaces for cellular base stations. This antenna is formed by surrounding radiating elements with multiple metasurfaces that can be configured to be transparent or absorptive to electromagnetic waves. This increases the directionality of the resulting emitted signal, improves reception, and limits interference. We present a baseband equivalent channel model for downlink transmission that incorporates the reconfigurable antenna and describes the diffraction phenomena resulting from the metasurfaces’ specific configuration. Next, we optimize the metasurface configuration, the transmit and receive beamformers, and the transmit power at multiple coordinated base stations to maximize the network sum-rate. Numerical results in a (5G) networks confirm that the proposed structure considerably increases the sum-rate compared to traditional antenna arrays.
The number of low Earth orbit (LEO) satellite constellations has grown rapidly in recent years, bringing a major change to global wireless communications. As LEO satellite links take on a growing role in critical services such as emergency communications, navigation, wide-area data collection, and military operations, keeping these links secure has become an important concern. In particular, verifying the identity of a satellite transmitter is now a basic requirement for protecting the services that rely on satellite access. In this article, we propose an active challenge-response authentication framework in which the verifier checks the satellite at randomly chosen times that are not known in advance, removing the fixed measurement window that existing passive methods expose to adversaries. The proposed framework uses the deterministic yet unpredictably sampled nature of orbital observables to establish a physics based root of trust for satellite identity authentication. This approach transforms satellite authentication from static feature matching into a spatiotemporal consistency verification problem inherently constrained by orbital dynamics, providing robust protection even against trajectory-aware spoofing attacks.
Physical layer authentication (PLA) allows to authenticate the user by comparing measurements over time, assuming their time consistency or by modeling their evolution. However, these assumptions become problematic when devices are in motion and in indoor environments due to multipath propagation and obstructions. In this paper, we propose a PLA mechanism for moving devices in indoor environments, where multiple access points (APs) estimate the dominant channel tap path loss (PL) and angle of arrival (AoA) from the received signals and compare them with previously collected channel knowledge maps (CKMs). Specifically, the measurements are compared to those in the neighborhood of the previously known position obtained from CKMs. A comprehensive security analysis is conducted under both random and optimal attacks. Numerical results in a representative indoor scenario, with CKM obtained via ray tracing, validate the effectiveness of the proposed PLA approach.
Research on integrated sensing and communication is among the most promising research directions of sixthgeneration (6G) wireless communications. In particular, dualfunction radar-communication (DFRC) systems improve the communication performance by exploiting sensing capabilities to track moving connected devices. Reconfigurable intelligent surfaces (RISs) recently emerged as an enabling technology, offering low cost, power efficiency, and high flexibility. In this article, we propose a novel RIS-based base station (BS) architecture to reduce hardware complexity and thus enhance power efficiency. Specifically, instead of using a large antenna array with its associated large number of power-hungry radio-frequency (RF) chains of DFRC. We propose to use a pair of transmissive RIS-single-antenna modules, one for transmission and one for reception, building a DFRC BS. Furthermore, we propose a novel sensing-assisted communication scheme that utilizes the high passive beamforming gain provided by the RISs to detect and track the spatial direction of the impinging signal in a vehicularto- infrastructure communication setup. Simulation results show the effectiveness of the proposed method while maintaining low hardware complexity.
With the growing interest in underwater acoustic networks (UWANs), such as in the Internet of underwater things, we need mechanisms that guarantee communication security. In turn, security mechanisms often require legitimate devices to share secret keys. In this paper, we propose a physical-layer key generation (PKG) scheme for UWANs where a pair of legitimate users process the respective channel observation by two neural networks (NNs) to extract a raw key. Inspired by the lower bound on the secret key capacity, we train key extractors to maximize reciprocity and uniformity while minimizing the information leakage to the eavesdropper. Specifically, a custom architecture and loss function have been designed to accomplish these tasks. The performance of the proposed PKG mechanism based on machine learning (ML) has been evaluated considering both additive white Gaussian noise (AWGN) and UWAN scenarios, with the latter using measurements extracted from an experimental dataset. The results highlight the benefits of the proposed mechanism over the state-of-the-art solutions.
In wireless networks, in-region location verification (IRLV) refers to the problem of verifying whether a transmitting device is inside a region of interest, based on the channel estimated from the received signal. In this paper, we consider multiple regions of interest and multiple base stations (BSs), each locally performing IRLV with a machine-learning (ML) model on estimated channels. We exploit the spatial correlation of channels and adopt a federated learning strategy among the BSs. Still, we also want to obtain different local models to reflect the different statistics of observed channels. We propose FedLoss, a personalized federated learning framework tailored to physical-layer IRLV under non-IID channel conditions. FedLoss operates in two phases: a federated averaging stage that learns a shared representation across BSs, and a locally regularized fine-tuning stage that adapts the global model to each BS’s channel statistics. A loss-based switching criterion determines the transition between the two phases, enabling efficient and stable training. We evaluate the proposed approach using realistic 3GPP-inspired channel models in a multi-base-station 6G scenario.
We consider a scenario where a legitimate user (Alice) authenticates itself to an authenticator (Bob) by transmitting orthogonal frequency division multiplexing (OFDM) pilots, from which the authenticator extracts the Micro-CSI (M-CSI) fingerprint and compares it against a stored reference via a likelihood test (LT)-based test. We introduce a new spoofing attack, where two adversarial devices collude to first jointly estimate the M-CSI fingerprints of Alice and Bob and then construct a forged signal able to break the authentication mechanism with high probability, limited only by noise effects on the estimates. We derive approximate closed-form distributions of the authentication test statistic under both the legitimate and spoofing hypotheses, enabling the derivation of false alarm and misdetection probabilities in closed-form. We then validate our analytical results against M-CSI fingerprints extracted from experimental data. The results reveal that, given sufficient pilot observations or an equivalent noise statistic between Bob and the attackers, the latter can always drive the test statistics to a random classifier, vanishing the security of M-CSI-based authentication.
We introduce the broadband reconfigurable intelligent surface (RIS) channel (BRISC) dataset. The dataset comprises measurements of channel state information (CSI) collected at 5.53 GHz using a 256-element RIS with binary states. In the measurement campaign, the transmitter and receiver are two software defined radios (SDRs), phase-synchronized via an OctoClock, where the transmitter (receiver) is equipped with one (two) antenna(s). To manage complexity, the RIS elements are grouped into blocks of different sizes, where all elements within a block share the same state. CSIs have been captured for multiple a) transmitter positions (and fixed receiver location), b) pilot block sizes, and c) state configurations. Furthermore, we calibrated the parameters of state-of-the-art RIS channel models to fit the measured CSI. With approximately 10000 configurations explored per transmitting position, BRISC serves as a robust benchmark in communication applications. We also show here an example of its use for physical-layer authentication.
Integrated sensing and communication (ISAC) enables the acquisition of environmental information by leveraging wireless signals transmitted for communication purposes. In this paper, we utilize this capability to reconstruct the layout of objects surrounding multiple receivers. Ray tracing is then applied to the reconstructed environment to infer the propagation channels for various transmitter positions, thereby constructing a channel knowledge map (CKM). The CKM is then used to verify the position of a legitimate transmitter, authenticating it against an adversarial device attempting to impersonate it from a different location. This physical layer authentication (PLA) mechanism utilizes the approximate known position of the legitimate transmitter, obtained, for instance, from the network as in cross-layer authentication, to compare the channel estimated from the received signal with the corresponding CKM data. We evaluate the impact on the PLA performance of both ISAC-induced CKM reconstruction errors and receiver-side channel estimation noise, in terms of false alarm and missed detection probabilities. Finally, the proposed approach is validated using an ISAC dataset from the literature.
We consider a robot (Alice) moving in an industrial environment while transmitting messages to nearby endpoints through fixed access-points (APs). An intruder robot (Trudy) aims at transmitting malicious messages to the endpoints, impersonating Alice. We aim at detecting Trudy’s transmissions by comparing the expected position of the transmitter with two estimates of it obtained from a) the channel-state-information (CSI) estimated on the signals received by the APs, and b) the traffic information in the network. Such estimates are obtained with convolutional neural-network (CNN) and support vector regressor (SVR) models along with Kalman filters to exploit the trajectory evolution. Numerical results obtained using the DICHASSUS dataset confirm the effectiveness of our proposed solution.
This paper develops a physically consistent signal model with hardware constraints for a simultaneous transmitting and reflecting beyond-diagonal RIS (STAR BD-RIS) endowed with per-element amplification and lossless power splitting. We explicitly decouple (i) amplification via a diagonal gain matrix, (ii) element-wise reflection/transmission splitting, and (iii) passive beyond-diagonal coupling on each branch, while enforcing practical feasibility through per-element emission caps and an aggregate RIS power budget under the operating covariance. Building on this model, we cast downlink sum-rate maximization as an equivalent weighted minimum mean-square error (WMMSE) problem and propose an alternating optimization framework with provable monotonic descent. The method admits closed-form updates for MMSE combiners and weights, waterfilling-like beamformer updates via a single dual variable, a per-element amplification update that satisfies emission constraints, and a STAR power-splitting update based on cyclic coordinate descent with a global acceptance test. For the beyond-diagonal coupling matrices, we derive Riemannian gradient steps on the complex Stiefel manifold with QR/polar retraction method, preserving passivity at every iterate. Furthermore, the proposed approach decouples the optimization of the reflective and transmissive responses of the BD-RIS, enabling efficient distributed implementation. Numerical results demonstrate substantial sum-rate gains compared to the conventional passive BD-RIS.
We consider beyond-diagonal reconfigurable intelligent surfaces (BD-RISs) whose elements are connected in groups and aim at optimizing their configuration to maximize the achievable rate of the cascade channel. We propose two suboptimal approaches (i.e., semidefinite programming (SDP) and projected gradient ascent (PGA) solutions) to first find the BD-RIS configuration that maximizes the composite channel trace and then locally maximizes the achievable rate by a randomization approach. We impose a constraint on the choice of the coefficients to ensure that the BD-RIS is passive, i.e., it does not emit more power than that received. Still, our solution has a high communication overhead for a large number of connections among the BD-RIS elements. We then propose a dynamic mapping between the BD-RIS configuration and a small number of control variables. The mapping is provided by the encoder part of an autoencoder, trained to minimize a suitable loss function on the optimal configurations in the specific deployment. We also design the BD-RIS configuration directly in the latent space of the autoencoder, reducing the complexity. By simulations in a typical cellular communication scenario, we show that the group-connected BD-RIS can achieve up to 95% of the rate obtained for a fully-connected BD-RIS with two orders of magnitude lower complexity, while the autoencoder compression and configuration optimization in the latent space reduces the control rate by 90% with negligible rate loss.
This paper proposes a new physical-layer authentication (PLA) mechanism that operates in environments where the receiver partially controls the channel conditions. We focus in particular on a channel controlled by an intelligent reflecting surface (IRS). It combines a channel-based challenge-response PLA (CH-CRPLA), which uses instantaneous channel state information (CSI), and a coding-based PLA (CD-PLA), which uses a shared key. The combination allows for reaping the benefits of CD-PLA in a high signal-to-noise ratio (SNR) of the legitimate channel and CH-CRPLA, imposing a high variation of channels even at low SNRs of the legitimate channel, thanks to the increased secrecy (wiretap) capacity. We investigate the trade-off between the pilot symbols for CSI estimation (for CH-CRPLA) and the key bits (for CD-PLA) and evaluate security in terms of the number of secret bits needed by an attacker to succeed. Numerical results confirm the advantage of the proposed hybrid approach over standalone methods.
Physical layer message authentication in underwater acoustic networks (UWANs) leverages the properties of the underwater acoustic channel (UWAC) to identify the transmitting device. However, as the device moves, its UWAC changes, and the authentication mechanism must track such changes. In this paper, we propose an authentication mechanism that works in two steps: first, we estimate the position of the transmitting device, and then we predict its future position based on the previously estimated locations. Next, the position prediction error is used to verify the authenticity of the transmission. The position is estimated using a convolutional neural network (CNN) that takes as input the sample covariance matrix (SCM) of the estimated UWACs. The predictor is implemented via a Kalman filter or a long short term memory (LSTM)-based recurrent neural network (RNN). Numerical results obtained using the Bellhop ray tracer under various environmental conditions (water salinity, pH, and temperature) confirm the effectiveness of the proposed approach and show that the Kalman filter-based predictor outperforms RNN when a precise measurement and evolution model are available. Conversely, when such a model is not provided, the RNN performs better than the Kalman filter.
Integrated sensing and communication (ISAC) enables the tracking and detection of passive objects, including the human body, by leveraging standard wireless communication signals. While already standardized in IEEE 802.11bf for Wi-Fi, ISAC is currently being defined by 3GPP for the upcoming generations of cellular networks. This transition scales the ISAC technology from localized, uncoordinated Wi-Fi deployments into a pervasive, centralized network deployment managed by mobile network operators. However, such nationwide coverage introduces critical user privacy challenges that must comply with stringent data protection legislative frameworks, most notably the General Data Protection Regulation in the European Union. This paper provides a comprehensive analysis of applicable norms to cellular ISAC, highlights the open technical challenges in its implementation, and explores potential mitigation strategies at both the architectural and signal processing levels, establishing tiered data access levels for various stakeholder categories and detailing how these protocols can be lawfully integrated into cellular network architectures.
Beamforming in multiple-input multiple-output (MIMO) systems should take interference mitigation into account. However, for beamform design, accurate channel state information (CSI) is needed, which is often difficult to obtain due to channel variability, feedback overhead, or hardware constraints. For example, amplify-and-forward (AF) relays passively forward signals without measurement, precluding full CSI acquisition to and from the relay. To address these issues, this paper introduces a novel prediction-assisted optimization (PAO) framework for beamform design in AF relay-assisted multiuser MIMO systems. The proposed solution in the AF relay aims at maximizing the signal-plus-interference-to-noise ratio (SINR). Unlike other methods, PAO relies solely on received power measurements, making it suitable for scenarios where CSI is unreliable or unavailable. PAO consists of two stages: a supervised-learning-based neural network (NN) that predicts the positions of transmitters using signal observations, and an optimization algorithm, guided by a digital twin (DT), that iteratively refines the beam direction of the relay in a simulated radio environment. As a key contribution, we validate the proposed framework using realistic measurements collected on a custom-built experimental millimeter wave (mmWave) platform, which enables training of the NN model under practical wireless conditions. The estimated information is then used to update the digital twin with knowledge of the surrounding environment, enabling online optimization. Numerical results show the trade-off between localization accuracy and beamforming performance and confirm that PAO maintains robustness even in the presence of localization errors while reducing the need for real-world measurements.
Pascal Casari合作论文数Dept. of Inf. Eng., Univ. of Padova, Padova6
Leonardo Badia合作论文数Department of Information Engineering, University of Padova4