SearcharxivSearch

arXiv subjects

Haofan Dong

Publications and source records attributed to Haofan Dong.

At least 19 recordsLinked to original sources

Reliability Limits and Decoding for Partial Nanopore Protein Rereads With Persistent State

Repeated observations of one physical object need not constitute independent channel uses. We model partial nanopore protein rereads as a finite-alphabet channel with canonical content, persistent readout, and pass-local coverage and synchronization. For exact compound-pass data, matched inference approaches the equivalence-class canonical posterior, and sitewise excess Bayes risk admits an action-aware achievable exponent. In an aligned specialization, observation-local redraw can cause linear-in-$K$ growth in true-label negative log-likelihood (NLL). We derive order-$b$ projection-stability bounds and an exact passwise-fusion diagnostic. On a PASTOR-informed semi-synthetic hard-symbol channel, label-blind deterministic-mixture importance sampling (LB-IS) agrees with exact enumeration at $L=7$. At $L=24, K=10$, LB-IS meets every prespecified aggregate absolute marginal-posterior and score-agreement criterion against a fixed high-allocation reference in three selected conditions. Joint agreement holds for the representative and high-NLL conditions, while the near-zero condition remains inconclusive. Exact $L \leq 6$ benchmarks identify order 4 as the smallest tested common cap. At target scale, the reference supports selected unprojected functionals, while neither order 4 nor 5 attains joint agreement, defining a tested finite-memory boundary. Across 16 cells, the order-4 shared branch lowers NLL by 0.033-0.224 nats per residue relative to pass-local.

cs.IT

Deadline-Bound Finite-Object Delivery over Intermittent LEO Satellite Contact Plans under Residual-Service Accounting

Low-Earth-orbit (LEO) relay networks deliver finite objects -- sensing tiles, telemetry blocks, model updates, and checkpoints -- over intermittent inter-satellite and space-to-ground contact plans. Partial delivery is insufficient when the complete object misses its deadline. When an object is split across candidate paths, a path-private evaluation can count the same contact service more than once and silently under-count completion. We develop a residual-service-aware delivery layer that consumes candidate paths from contact-plan route generation and tests whether the complete object can be delivered before its deadline under per-edge first-in-first-out residual service. Under controlled shared-contact contention, path-private evaluation under-counts completion by up to 154 s and can report finite completion for a fixed plan with no residual-service completion. For edge-disjoint complementary contacts, the layer reduces to fixed-path service; we derive a sufficient service-budget condition under which two-way striping strictly enlarges the feasible payload region. We verify a restricted exhaustive reference, characterize runtime over a 20-180-satellite procedural contact model, and show that bounded two-way striping reduces mean and median gaps to the restricted reference by about 40%, while P90 and worst-case gaps remain unchanged.

eess.SP

A reversed solar illumination dependence of unintended emission from Starlink Direct-to-Cell satellites at 72-234 MHz with the EDA2

Second-generation Starlink Direct-to-Cell (DTC) satellites carry an additional payload for direct cellular phone connectivity whose unintended electromagnetic radiation (UEMR) at sub-300 MHz frequencies has not been individually characterised. We reanalyse 112,534 detections from 1,806 Starlink satellites observed with the Engineering Development Array version 2 (EDA2) at 21 frequencies between 72.685 and 234.375 MHz (Grigg et al. 2025), separating 175 DTC and 1,623 Ku-only v2-Mini comparison satellites via the McDowell General Catalogue (McDowell 2020). DTC satellites emit a range-corrected flux density 1.45x that of the Ku-only comparison (Cliff's delta = +0.30, p = 2.6e-11). At 230.469 MHz the XX detection fraction reaches 0.811 against a 0.481 baseline (p ~ 1e-274), and 11 of 21 frequency channels show Benjamini-Hochberg-significant polarisation anomalies. The DTC population is brighter in eclipse than in sunlight (illuminated/eclipsed flux density ratio 0.47) while the Ku-only comparison shows the opposite sense (1.18); the reversal persists across altitude, sub-satellite latitude, frequency, and launch-epoch matching. The reversal strongly disfavours UEMR mechanisms that scale monotonically with instantaneous solar photocurrent and favours an active on-board source whose effective duty cycle is larger at lower equilibrium temperature. Within the 230.469 MHz coarse channel, fine-channel inspection isolates the excess to a single ~24 kHz bin near 230.627 MHz, tail-driven and absent at five control channels. Three falsifiable mechanism-discrimination tests show this feature is not coincident with the LOFAR-resolved Bassa et al. (2024) clock fundamentals, is unresolved at the EDA2 24 kHz resolution, and is heterogeneously expressed across the v2-Mini fleet rather than driven by a few permanently bright units or by uniform thermal scaling.

eess.SP

Graph Representation Learning Augmented Model Manipulation on Federated Fine-Tuning of LLMs

Federated fine-tuning (FFT) has emerged as a privacy-preserving paradigm for collaboratively adapting large language models (LLMs). Built upon federated learning, FFT enables distributed agents to jointly refine a shared pretrained LLM by aggregating local LLM updates without sharing local raw data. However, FFT-based LLMs remain vulnerable to model manipulation threats, in which adversarial participants upload manipulated LLM updates that corrupt the aggregation process and degrade the performance of the global LLM. In this paper, we propose an Augmented Model maniPulation (AugMP) strategy against FFT-based LLMs. Specifically, we design a novel graph representation learning framework that captures feature correlations among benign LLM updates to guide the generation of malicious updates. To enhance manipulation effectiveness and stealthiness, we develop an iterative manipulation algorithm based on an augmented Lagrangian dual formulation. Through this formulation, malicious updates are optimized to embed adversarial objectives while preserving benign-like parameter characteristics. Experimental results across multiple LLM backbones demonstrate that the AugMP strategy achieves the strongest manipulation performance among all competing baselines, reducing the global LLM accuracy by up to \(26\%\) and degrading the average accuracy of local LLM agents by up to \(22\%\). Meanwhile, AugMP maintains high statistical and geometric consistency with benign updates, enabling it to evade conventional distance- and similarity-based defense methods.

cs.LG

CisLunarSense: Opportunistic ISAC for Debris Detection at the Lunar Gateway

We propose CisLunarSense, an opportunistic integrated sensing and communication (ISAC) framework that exploits the Lunar Gateway's Ka-band relay for monostatic debris detection, addressing the absence of cislunar space situational awareness infrastructure beyond the reach of ground-based radars. Using NASA/ESA-documented system parameters with author-selected sensing settings and a CR3BP-based 9:2 near-rectilinear halo orbit model, we derive the orbit-phase-dependent Cram\'{e}r--Rao bound under OFDM inter-carrier interference, quantify a 36~dB cislunar sensing advantage over a ground-based Ka-band reference, and design a velocity-adaptive processor with mode switching at 337~m/s. Gateway operational debris ($v_\mathrm{rel} < 50$~m/s) is detectable within 700~km with over 30~minutes of warning; external threats ($v_\mathrm{rel}$ up to 500~m/s) remain detectable within 400--630~km. An orbit-phase-adaptive allocation reduces the sensing duty cycle from 60\% to 19\%, increasing relay throughput from 44 to 90~Mbps. A closed-form sensing outage probability for $K$-CPI non-coherent integration under Swerling~I fluctuation shows that the 10\%-outage detection range reaches 91\% of the deterministic maximum at the nominal operating point $K = 16$.

eess.SP

Rain Rate Estimation Bounds and Weather-Adaptive Pilot Allocation for LEO Satellite ISAC

Rain attenuates Ku-band satellite signals by up to 20~dB, encoding precipitation information along the Earth-space slant path. This paper derives the Bayesian Cram\'{e}r-Rao bound (BCRB) for rain rate estimation from LEO broadband OFDM downlinks. Using corrected ITU-R P.838-3 coefficients, the standard CRB yields a minimum detectable rain rate $R_{\min} \approx 4.3\mmh$ for a single link at the $38^\circ$ reference elevation. We derive the prior Fisher information in closed form for log-normal rain ($c_v = 1.05$, from 186{,}292 samples) and show that a single-snapshot BCRB reduces $R_{\min}$ to $1.1\mmh$; exploiting temporal correlation ($\rho = 0.95$) over a 30-min window further tightens it to $0.95\mmh$, while multi-link fusion across $N = 215$ links lowers the operating-point RMSE \emph{lower bound} at $R = 20\mmh$ to approximately $0.07\mmh$. Building on these bounds, we formulate a weather-adaptive pilot allocation that minimizes the BCRB subject to a hard spectral-efficiency constraint, characterize its three-regime structure (full-sensing, throughput-tracking, outage), and pair it with a CUSUM rain onset detector achieving sub-10-min delay for $R \geq 20\mmh$. A closed-form analysis of dynamic LEO slant geometry identifies a sensing-optimal elevation at the P.618-validity floor of $15^\circ$ that yields a $1.58\times$ geometric improvement over the $38^\circ$ baseline, exposing a structural anti-correlation between sensing- and communication-optimal elevations along an orbital pass. Validation against 9.4~million radar samples from 215 Ku-band GEO satellite links ($r = 0.72$, RMSE~$= 1.24\dB$) and 113 rain gauges confirms the underlying attenuation model; the bounds transfer to LEO constellations under matched OFDM signal parameters, with dedicated LEO validation left for future work.

eess.SP

Fisher Information Limits of Satellite RF Fingerprint Identifiability for Authentication

RF fingerprinting authenticates satellite transmitters by exploiting hardware-specific signal impairments, yet existing methods operate without theoretical performance guarantees. We derive the Fisher information matrix (FIM) for joint estimation of in-phase/quadrature (IQ) imbalance and power amplifier (PA) nonlinearity parameters, establishing Cram\'{e}r-Rao bounds (CRBs) whose structure depends on constellation moments. A necessary condition for full IQ identifiability is that the identifiability factor~$\beta$ exceeds zero; for binary phase-shift keying (BPSK), $\beta = 0$ yields a rank-deficient FIM, rendering IQ parameters unidentifiable. This provides a plausible theoretical explanation for OrbID's near-random performance (area under the ROC curve, AUC~$= 0.53$) on Orbcomm. From the FIM, we define a discrimination metric that predicts which hardware parameters dominate authentication for a given modulation. For constant-modulus PSK signals, PA nonlinearity features are predicted to dominate while IQ features are ineffective. We validate the framework on 24~Iridium satellites using two recording campaigns, achieving cross-file PA fingerprint correlation $r = 0.999$ and confirming all four CRB predictions. A discrimination-ratio-weighted (DR-weighted) authentication test achieves AUC~$= 0.934$ from six features versus $0.807$ with equal weighting, outperforming machine-learning classifiers (AUC~$\leq 0.69$) on the same data.

eess.SP

Distortion Is Not Noise: On the Limits of the Kappa Model for Monostatic ISAC

Monostatic ISAC sensing differs from communication because the transmitter can monitor its distorted transmit waveform. Thus, the aggregate $\kappa$ distortion model, which treats impairments as unknown noise, is appropriate for communication but pessimistic for monostatic sensing. We derive PA-aware sensing Cram\'er--Rao bounds (CRBs) and a PN-aware CRB that reveals an irreducible velocity-error floor, and quantify when $\kappa$-based bounds overestimate sensing degradation. Simulations validate the analysis and show robustness to practical DPD template errors (less than 1~dB overhead at a typical $-25$~dB NMSE).

eess.SP

Performance Bounds and Robust Filtering for LEO Inter-Satellite Synchronization under Cross-Epoch Doppler Coupling

Low Earth orbit (LEO) inter-satellite links (ISLs) must achieve joint synchronization and ranging under severe hardware impairments, namely oscillator phase noise, clock drift, and measurement outliers, exacerbated by rapid relative dynamics exceeding 7~km/s. In coherent Doppler processing, the frequency observable depends on the \emph{difference} between consecutive carrier phase states, creating a cross-epoch coupling structure that fundamentally affects estimation-theoretic performance limits. This paper makes three contributions. First, we prove analytically that this cross-epoch Doppler coupling is \emph{necessary} to avoid unbounded carrier phase uncertainty: without it, phase variance grows linearly without bound. Second, we derive a posterior Cram\'{e}r-Rao bound (PCRB) via the Tichavsk\'{y} recursion that explicitly incorporates the resulting 10$\times$10 block information structure. Third, we propose a hybrid robust filtering framework combining hard gating for impulsive cycle-slip outliers with Huber M-estimation for heavy-tail contamination, using TASD-aware innovation covariance to account for cross-epoch uncertainty in residual normalization. Monte Carlo simulations at Ka-band confirm that the PCRB accurately lower-bounds estimator performance under nominal conditions, while the hybrid method reduces 95th-percentile phase error by 27--93\% compared to standard extended Kalman filtering across different outlier regimes.

eess.SP

Edge-Side Fingerprints of Service Tiering and Quota Throttling in Starlink

We design and evaluate an edge-side measurement procedure for auditing service tiering and quota-based throttling in Starlink. Using a 232.8-hour plan-hopping campaign on a UK residential terminal, we align 1 Hz terminal telemetry with host-side probes to obtain portal-labeled traces spanning priority, post-quota throttling, stay-active operation, and residential service. These regimes manifest as distinct signatures in goodput, PoP RTT, and an internal-to-user ratio \(R=C_{\mathrm{int}}/T_{\mathrm{user}}\). We further show that high-speed \(R\) is stable over 30-minute sub-windows, that low-rate clusters have no aligned persistent obstruction or PoP-loss signature, and that clean high-speed dips do not move \(R\) into the low-rate band. A lightweight rule on windowed medians separates high-speed from low-rate operation on this trace without operator visibility.

eess.SP

Cramer--Rao Bounds for Magneto-Inductive Integrated Sensing and Communications

Magnetic induction (MI) enables communication in RF-denied environments (underground, underwater, in-body), where the medium conductivity imprints a deterministic signature on the channel. This letter derives a closed-form Cram\'{e}r--Rao bound (CRB) for the joint estimation of range and medium conductivity from MI pilot observations in an integrated sensing and communication (ISAC) framework. The Fisher information matrix reveals that the joint estimation penalty converges to 3\,dB in the near-field regime, meaning conductivity sensing adds at most a factor-of-two loss in ranging precision. Monte Carlo maximum-likelihood simulations confirm that the CRB is achievable under practical operating conditions.

eess.SP

MI-ISAC: Magneto-Inductive Integrated Sensing and Communication in the Reactive Near-Field for RF-Denied Environments

Radio-frequency integrated sensing and communication (RF-ISAC) is ineffective inunderground, underwater, and in-body environments where conductive media attenuate electromagnetic waves by tens of dB per meter. This article presents magneto-inductive ISAC (MI-ISAC), a paradigm that exploits the reactive near-field quasi-static coupling inherent to MI links, enabling a fundamentally different approach to ISAC in these RF-denied environments. Five foundational results are established: (i)~tri-axial coils are necessary and sufficient for identifiable joint range-and-angle estimation; (ii)~coupling strength changes sharply with range, enabling theoretical sub-millimeter accuracy at typical MI distances despite kHz-level bandwidth; (iii)~time-of-flight is ineffective under such narrow bandwidth, but the coupling gradient provides approximately six orders of magnitude finer resolution; (iv)~MI-ISAC can provide 4--10+\,dB sensing gain over time-division baselines; and (v)~the MI-MIMO channel is geometry-invariant and well-conditioned across all orientations. Applications and a research roadmap are discussed.

eess.SP

Environment-to-Link ISAC with Space-Weather Sensing for Ka-Band LEO Downlinks

Ka-band low-Earth-orbit (LEO) downlinks can suffer second-scale reliability collapses during flare-driven ionospheric disturbances, where fixed fade margins and reactive adaptive coding and modulation (ACM) are either overly conservative or too slow. This paper presents a GNSS-free, link-internal predictive controller that senses the same downlink via a geometry-free dual-carrier phase observable at 10~Hz: a high-pass filter and template-based onset detector, followed by a four-state nearly-constant-velocity Kalman filter, estimate $\Delta$VTEC and its rate, and a short look-ahead (60~s) yields an endpoint outage probability used as a risk gate to trigger one-step discrete MCS down-switch and pilot-time update with hysteresis. Evaluation uses physics-informed log replay driven by real GOES X-ray flare morphologies under a disjoint-day frozen-calibration protocol, with uncertainty reported via paired moving-block bootstrap. Across stressed 60~s windows, the controller reduces peak BLER by 25--30\% and increases goodput by 0.10--0.15~bps/Hz versus no-adaptation baselines under a unified link-level abstraction. The loop runs in $\mathcal{O}(1)$ per 0.1~s epoch (about 0.042~ms measured), making on-board implementation feasible, and scope and deployment considerations for dispersion-dominated events are discussed.

eess.SP

Performance Limits of Hardware-Constrained THz Inter-Satellite MIMO-ISAC Systems

Terahertz inter-satellite links (THz-ISL) offer unprecedented bandwidth for future space networks but face fundamental constraints from onboard power and thermal budgets. This paper establishes theoretical performance limits for MIMO Integrated Sensing and Communication (ISAC) systems under per-element constant-envelope (CE) transmission constraints. We demonstrate that hardware distortions -- specifically power amplifier nonlinearity, ADC quantization, and oscillator phase noise -- impose a capacity ceiling that cannot be overcome by increasing transmit power. A unified link budget framework integrates wideband beam squint, aperture pointing errors, and colored noise sources through a spectral consistency principle that ensures residual phase noise is counted exactly once across communication and sensing analyses. The sensing bounds are derived via the Whittle-Fisher Information Matrix under a Constant Acceleration kinematic model with jerk noise, yielding closed-form scaling laws: residual phase noise variance scales as $\alpha^{-1}$ while dynamic state-estimation error (DSE) variance scales as $\alpha^{-5}$ with pilot overhead $\alpha$. Numerical results show divergent MIMO scaling: sensing precision improves with array size ($\mathrm{RMSE} \propto 1/\sqrt{N_t N_r}$), while the critical SNR exhibits scale invariance regarding array size, implying that the distortion-limited transition point stabilizes regardless of the array scale. The steep $\alpha^{-5}$ DSE scaling creates an operationally infeasible region at $\alpha < \alpha^* \approx 0.16$, where $\alpha^* = (C_{\mathrm{DSE}}/C_{\mathrm{PN}})^{1/4}$ -- a constraint-driven threshold under the adopted baseline for LEO operation. These findings provide design guidelines for hardware-efficient THz-ISL constellations.

eess.SP

Graph Representation-based Model Poisoning on the Heterogeneous Internet of Agents

Internet of Agents (IoA) envisions a unified, agent-centric paradigm where heterogeneous large language model (LLM) agents can interconnect and collaborate at scale. Within this paradigm, federated fine-tuning (FFT) serves as a key enabler that allows distributed LLM agents to co-train an intelligent global LLM without centralizing local datasets. However, the FFT-enabled IoA systems remain vulnerable to model poisoning attacks, where adversaries can upload malicious updates to the server to degrade the performance of the aggregated global LLM. This paper proposes a graph representation-based model poisoning (GRMP) attack, which exploits overheard benign updates to construct a feature correlation graph and employs a variational graph autoencoder to capture structural dependencies and generate malicious updates. A novel attack algorithm is developed based on augmented Lagrangian and subgradient descent methods to optimize malicious updates that preserve benign-like statistics while embedding adversarial objectives. Experimental results show that the proposed GRMP attack can substantially decrease accuracy across different LLM models while remaining statistically consistent with benign updates, thereby evading detection by existing defense mechanisms and underscoring a severe threat to the ambitious IoA paradigm.

cs.NI

Fundamental Limits of Cooperative Integrated Sensing and Communications over Low-Earth Orbit THz Satellite Channels

Terahertz inter-satellite links enable unprecedented sensing precision for Low Earth Orbit (LEO) constellations, yet face fundamental bounds from hardware impairments, pointing errors, and network interference. We develop a Network Cram\'er-Rao Lower Bound (N-CRLB) framework incorporating dynamic topology, hardware quality factor $\Gamma_{\text{eff}}$, phase noise $\sigma^2_\phi$, and cooperative effects through recursive Fisher Information analysis. Our analysis reveals three key insights: (i) hardware and phase noise create power-independent performance ceilings ($\sigma_{\text{ceiling}} \propto \sqrt{\Gamma_{\text{eff}}}$) and floors ($\sigma_{\text{floor}} \propto \sqrt{\sigma^2_\phi}/f_c$), with power-only scaling saturating above $\text{SNR}_{\text{crit}}=1/\Gamma_{\text{eff}}$; (ii) interference coefficients $\alpha_{\ell m}$ enable opportunistic sensing with demonstrated gains of 5.5~dB under specific conditions (65~dB processing gain, 50~dBi antennas); (iii) measurement correlations from shared timing references, when properly modeled, do not degrade performance and can provide common-mode rejection benefits compared to mismodeled independent-noise baselines. Sub-millimeter ranging requires co-optimized hardware ($\Gamma_{\text{eff}}<0.01$), oscillators ($\sigma^2_\phi<10^{-2}$), and appropriate 3D geometry configurations.

eess.SP

Fundamental Limits of THz Inter-Satellite ISAC Under Hardware Impairments

This paper establishes a theoretical framework for analyzing the fundamental performance limits of terahertz (THz) Low Earth Orbit (LEO) inter-satellite link (ISL) Integrated Sensing and Communications (ISAC) systems. We develop a unified, end-to-end signal model that, jointly captures the effects of extreme orbital dynamics, cascaded non-ideal hardware impairments, and micro-radian beam pointing errors. Through Bayesian Cram\'er-Rao Lower Bound (BCRLB) analysis, we derive the ultimate sensing accuracy for range and range-rate, revealing a quadratic ($1/f_c^2$) improvement in estimation variance with carrier frequency, which is ultimately floored by signal-dependent hardware distortion. For communication, we show that system performance is not power-limited but hardware-limited, deriving a closed-form capacity ceiling under the joint effect of phase noise and PA nonlinearity: $C_{\text{sat}} = \log_2(1 + e^{-\sigma_\phi^2}/\Gamma_{\text{eff}})$, where $\Gamma_{\text{eff}}$ is a proposed hardware quality factor. Our numerical results, based on state-of-the-art component data and the identified trade-offs, suggest that favorable operational conditions may exist in the sub-THz frequency range (200-600 GHz) where the quadratic sensing gain with frequency is balanced against hardware quality degradation. Power Amplifier (PA) nonlinearity emerges as the dominant performance bottleneck, exceeding other impairments by one to two orders of magnitude.

eess.SP

Graph Representation-based Model Poisoning on Federated Large Language Models

Federated large language models (FedLLMs) enable powerful generative capabilities within wireless networks while preserving data privacy. Nonetheless, FedLLMs remain vulnerable to model poisoning attacks. This article first reviews recent advancements in model poisoning techniques and existing defense mechanisms for FedLLMs, underscoring critical limitations, especially when dealing with non-IID textual data distributions. Current defense strategies predominantly employ distance or similarity-based outlier detection mechanisms, relying on the assumption that malicious updates markedly differ from benign statistical patterns. However, this assumption becomes inadequate against adaptive adversaries targeting billion-parameter LLMs. The article further investigates graph representation-based model poisoning (GRMP), an emerging attack paradigm that exploits higher-order correlations among benign client gradients to craft malicious updates indistinguishable from legitimate ones. GRMP can effectively circumvent advanced defense systems, causing substantial degradation in model accuracy and overall performance. Moreover, the article outlines a forward-looking research roadmap that emphasizes the necessity of graph-aware secure aggregation methods, specialized vulnerability metrics tailored for FedLLMs, and evaluation frameworks to enhance the robustness of federated language model deployments.

cs.CR