SearcharxivSearch

arXiv subjects

Stefano Tomasin

Publications and source records attributed to Stefano Tomasin.

At least 19 recordsLinked to original sources

From Identification to Authentication for Micro-CSI RF Fingerprinting in OFDM Systems

We consider a scenario where a legitimate user (Alice) authenticates itself to an authenticator (Bob) by transmitting orthogonal frequency division multiplexing (OFDM) pilots, from which the authenticator extracts the Micro-CSI (M-CSI) fingerprint and compares it against a stored reference via a likelihood test (LT)-based test. We introduce a new spoofing attack, where two adversarial devices collude to first jointly estimate the M-CSI fingerprints of Alice and Bob and then construct a forged signal able to break the authentication mechanism with high probability, limited only by noise effects on the estimates. We derive approximate closed-form distributions of the authentication test statistic under both the legitimate and spoofing hypotheses, enabling the derivation of false alarm and misdetection probabilities in closed-form. We then validate our analytical results against M-CSI fingerprints extracted from experimental data. The results reveal that, given sufficient pilot observations or an equivalent noise statistic between Bob and the attackers, the latter can always drive the test statistics to a random classifier, vanishing the security of M-CSI-based authentication.

eess.SP

Towards Lawful ISAC in Cellular Networks

Integrated sensing and communication (ISAC) enables the tracking and detection of passive objects, including the human body, by leveraging standard wireless communication signals. While already standardized in IEEE 802.11bf for Wi-Fi, ISAC is currently being defined by 3GPP for the upcoming generations of cellular networks. This transition scales the ISAC technology from localized, uncoordinated Wi-Fi deployments into a pervasive, centralized network deployment managed by mobile network operators. However, such nationwide coverage introduces critical user privacy challenges that must comply with stringent data protection legislative frameworks, most notably the General Data Protection Regulation in the European Union. This paper provides a comprehensive analysis of applicable norms to cellular ISAC, highlights the open technical challenges in its implementation, and explores potential mitigation strategies at both the architectural and signal processing levels, establishing tiered data access levels for various stakeholder categories and detailing how these protocols can be lawfully integrated into cellular network architectures.

eess.SP

ISAC-Assisted Channel Knowledge Map Generation for Physical Layer Authentication

Integrated sensing and communication (ISAC) enables the acquisition of environmental information by leveraging wireless signals transmitted for communication purposes. In this paper, we utilize this capability to reconstruct the layout of objects surrounding multiple receivers. Ray tracing is then applied to the reconstructed environment to infer the propagation channels for various transmitter positions, thereby constructing a channel knowledge map (CKM). The CKM is then used to verify the position of a legitimate transmitter, authenticating it against an adversarial device attempting to impersonate it from a different location. This physical layer authentication (PLA) mechanism utilizes the approximate known position of the legitimate transmitter, obtained, for instance, from the network as in cross-layer authentication, to compare the channel estimated from the received signal with the corresponding CKM data. We evaluate the impact on the PLA performance of both ISAC-induced CKM reconstruction errors and receiver-side channel estimation noise, in terms of false alarm and missed detection probabilities. Finally, the proposed approach is validated using an ISAC dataset from the literature.

eess.SP

Security Analysis of RIS-Assisted Physical-Layer Authentication Over Multipath Channels

In physical layer authentication, verification of a user's identity is based on the characteristics of the transmission channel through which signals are delivered to the authenticator (Bob). In this paper, we assume that the signals received by Bob pass through a \ac{RIS} (controlled by Bob) and that the legitimate transmitter (Alice) is equipped with one antenna. Conversely, the attacker (Trudy) has multiple antennas and uses precoding to deceive Bob's verification. Assuming that Trudy knows all the channel matrices, we first derive her optimal attack strategy. Then, we analyse the conditions under which the channel estimated by Bob is indistinguishable when either Alice or Trudy is transmitting. When Trudy has a single antenna, we show that the indistinguishability condition cannot be met when the channels to the RIS are the result of propagation over multiple paths. For single-path line-of-sight (LOS) conditions, instead, Trudy can impersonate Alice although transmitting from a different position. We verify these results numerically and assess the security of the considered scenario, even when the indistinguishability conditions cannot be met.

cs.IT

Physical Layer Authentication With Channel Knowledge Maps in Indoor Environments

Physical layer authentication (PLA) allows to authenticate the user by comparing measurements over time, assuming their time consistency or by modeling their evolution. However, these assumptions become problematic when devices are in motion and in indoor environments due to multipath propagation and obstructions. In this paper, we propose a PLA mechanism for moving devices in indoor environments, where multiple access points (APs) estimate the dominant channel tap path loss (PL) and angle of arrival (AoA) from the received signals and compare them with previously collected channel knowledge maps (CKMs). Specifically, the measurements are compared to those in the neighborhood of the previously known position obtained from CKMs. A comprehensive security analysis is conducted under both random and optimal attacks. Numerical results in a representative indoor scenario, with CKM obtained via ray tracing, validate the effectiveness of the proposed PLA approach.

cs.CR

ISAC Privacy: Challenges and Solutions for 6G

Integrated sensing and communication (ISAC) is a promising feature of future communication networks. While spatial sensing can improve network performance and enable external services, it also creates privacy challenges that go beyond the confidentiality of communication content. Future networks using millimeter-wave (mmWave) and sub-terahertz (THz) frequencies may collect or infer detailed information about people, devices, bystanders, passive objects, and environments in a sixth-generation (6G) deployment area. Such sensing can reveal location and environment data, support behavioral profiling such as movement or activity recognition, and, in advanced cases, expose physiological information such as breathing frequency or heart-rate-related data. Thus, the capabilities of spatial sensing must be controlled to satisfy privacy requirements. In this work, we organize privacy-sensitive ISAC data into three sensing levels: location and environment data, behavioral data, and physiological data, and use this classification as the organizing principle throughout the paper. Based on this classification, we discuss internal and external ISAC applications, identify privacy challenges related to consent, transparency, data ownership, profiling, bystander exposure, and sensitive sensing data, review representative solution directions, and outline future research directions for privacy-preserving ISAC.

cs.IT

Lightweight Pilot Estimation on LEO Satellite Signals for Enhanced SOP Navigation

The computation of positioning, navigation and timing (PNT) via signal of opportunity (SOP), where signals originally transmitted for communication, such as 5G, Wi-Fi, or DVB-S, are exploited due to their ubiquity and spectral characteristics, is an emerging research field. However, relying on these signals presents challenges, including limited knowledge of the signal modulation and the need to identify recurring sequences for correlation. We offer a guide to implement a receiver capable of capturing broadband downlink Ku-band signals from low Earth orbit (LEO) satellites (e.g., Starlink and OneWeb) and estimating the recurring symbols for SOP measurements. The methodology integrates recent approaches in the literature, highlighting the most effective aspects while guiding the replication of experiments even under limitations on the front-end gain and bandwidth. Using the proposed model, we can identify recurring symbols transmitted by Starlink satellites, which are then used to collect Doppler shift measurements over a 600 s interval. A position, velocity, and time (PVT) solution is also computed via least squares (LS), which achieves a positioning error of approximately 268 m after a post-fit refinement.

eess.SP

Challenge-Response Authentication for LEO Satellite Channels: Exploiting Orbit-Specific Uniqueness

The number of low Earth orbit (LEO) satellite constellations has grown rapidly in recent years, bringing a major change to global wireless communications. As LEO satellite links take on a growing role in critical services such as emergency communications, navigation, wide-area data collection, and military operations, keeping these links secure has become an important concern. In particular, verifying the identity of a satellite transmitter is now a basic requirement for protecting the services that rely on satellite access. In this article, we propose an active challenge-response authentication framework in which the verifier checks the satellite at randomly chosen times that are not known in advance, removing the fixed measurement window that existing passive methods expose to adversaries. The proposed framework uses the deterministic yet unpredictably sampled nature of orbital observables to establish a physics based root of trust for satellite identity authentication. This approach transforms satellite authentication from static feature matching into a spatiotemporal consistency verification problem inherently constrained by orbital dynamics, providing robust protection even against trajectory-aware spoofing attacks.

eess.SP

Model-Driven Learning-Based Physical Layer Authentication for Mobile Wi-Fi Devices

The rise of wireless technologies has made the Internet of Things (IoT) ubiquitous, but the broadcast nature of wireless communications exposes IoT to authentication risks. Physical layer authentication (PLA) offers a promising solution by leveraging unique characteristics of wireless channels. As a common approach in PLA, hypothesis testing yields a theoretically optimal Neyman-Pearson (NP) detector, but its reliance on channel statistics limits its practicality in real-world scenarios. In contrast, deep learning-based PLA approaches are practical but tend to be not optimal. To address these challenges, we proposed a learning-based PLA scheme driven by hypothesis testing and conducted extensive simulations and experimental evaluations using Wi-Fi. Specifically, we incorporated conditional statistical models into the hypothesis testing framework to derive a theoretically optimal NP detector. Building on this, we developed LiteNP-Net, a lightweight neural network driven by the NP detector. Simulation results demonstrated that LiteNP-Net could approach the performance of the NP detector even without prior knowledge of the channel statistics. To further assess its effectiveness in practical environments, we deployed an experimental testbed using Wi-Fi IoT development kits in various real-world scenarios. Experimental results demonstrated that the LiteNP-Net outperformed the conventional correlation-based method as well as state-of-the-art Siamese-based methods.

cs.LG

STAR Beyond Diagonal RISs with Amplification: Modeling and Optimization

This paper develops a physically consistent signal model with hardware constraints for a simultaneous transmitting and reflecting beyond-diagonal RIS (STAR BD-RIS) endowed with per-element amplification and lossless power splitting. We explicitly decouple (i) amplification via a diagonal gain matrix, (ii) element-wise reflection/transmission splitting, and (iii) passive beyond-diagonal coupling on each branch, while enforcing practical feasibility through per-element emission caps and an aggregate RIS power budget under the operating covariance. Building on this model, we cast downlink sum-rate maximization as an equivalent weighted minimum mean-square error (WMMSE) problem and propose an alternating optimization framework with provable monotonic descent. The method admits closed-form updates for MMSE combiners and weights, waterfilling-like beamformer updates via a single dual variable, a per-element amplification update that satisfies emission constraints, and a STAR power-splitting update based on cyclic coordinate descent with a global acceptance test. For the beyond-diagonal coupling matrices, we derive Riemannian gradient steps on the complex Stiefel manifold with QR/polar retraction method, preserving passivity at every iterate. Furthermore, the proposed approach decouples the optimization of the reflective and transmissive responses of the BD-RIS, enabling efficient distributed implementation. Numerical results demonstrate substantial sum-rate gains compared to the conventional passive BD-RIS.

cs.IT

Digital Twin-Based Beamforming for Interference Mitigation in AF Relay MIMO Systems

Beamforming in multiple-input multiple-output (MIMO) systems should take interference mitigation into account. However, for beamform design, accurate channel state information (CSI) is needed, which is often difficult to obtain due to channel variability, feedback overhead, or hardware constraints. For example, amplify-and-forward (AF) relays passively forward signals without measurement, precluding full CSI acquisition to and from the relay. To address these issues, this paper introduces a novel prediction-assisted optimization (PAO) framework for beamform design in AF relay-assisted multiuser MIMO systems. The proposed solution in the AF relay aims at maximizing the signal-plus-interference-to-noise ratio (SINR). Unlike other methods, PAO relies solely on received power measurements, making it suitable for scenarios where CSI is unreliable or unavailable. PAO consists of two stages: a supervised-learning-based neural network (NN) that predicts the positions of transmitters using signal observations, and an optimization algorithm, guided by a digital twin (DT), that iteratively refines the beam direction of the relay in a simulated radio environment. As a key contribution, we validate the proposed framework using realistic measurements collected on a custom-built experimental millimeter wave (mmWave) platform, which enables training of the NN model under practical wireless conditions. The estimated information is then used to update the digital twin with knowledge of the surrounding environment, enabling online optimization. Numerical results show the trade-off between localization accuracy and beamforming performance and confirm that PAO maintains robustness even in the presence of localization errors while reducing the need for real-world measurements.

eess.SP

BRISC: A Dataset of Channel Measurements at 5 GHz With a Reflective Intelligent Surface

We introduce the broadband reconfigurable intelligent surface (RIS) channel (BRISC) dataset. The dataset comprises measurements of channel state information (CSI) collected at 5.53 GHz using a 256-element RIS with binary states. In the measurement campaign, the transmitter and receiver are two software defined radios (SDRs), phase-synchronized via an OctoClock, where the transmitter (receiver) is equipped with one (two) antenna(s). To manage complexity, the RIS elements are grouped into blocks of different sizes, where all elements within a block share the same state. CSIs have been captured for multiple a) transmitter positions (and fixed receiver location), b) pilot block sizes, and c) state configurations. Furthermore, we calibrated the parameters of state-of-the-art RIS channel models to fit the measured CSI. With approximately 10000 configurations explored per transmitting position, BRISC serves as a robust benchmark in communication applications. We also show here an example of its use for physical-layer authentication.

eess.SP

Jamming Detection in Cell-Free MIMO with Dynamic Graphs

Jamming attacks pose a critical threat to wireless networks, particularly in cell-free massive MIMO systems, where distributed access points and user equipment (UE) create complex, time-varying topologies. This paper proposes a novel jamming detection framework leveraging dynamic graphs and graph convolutional neural networks (GCN) to address this challenge. By modeling the network as a dynamic graph, we capture evolving communication links and detect jamming attacks as anomalies in the graph evolution. A GCN-Transformer-based model, trained with supervised learning, learns graph embeddings to identify malicious interference. Performance evaluation in simulated scenarios with moving UEs, varying jamming conditions and channel fadings, demonstrates the method's effectiveness, which is assessed through accuracy and F1 score metrics, achieving promising results for effective jamming detection.

cs.IT

VBSF: A Visual-Based Spam Filtering Technique for Obfuscated Emails

Recent spam email techniques exploit visual effects in text messages, such as poisoning text, obfuscating words, and hidden text salting techniques. These effects were able to evade spam detection techniques based on the text. In this paper, we overcome this limitation by introducing a novel visual-based spam detection architecture, denoted as visual-based spam filter (VBSF). The multi-step process mimics the human eye's natural way of processing visual information, automatically rendering incoming emails and capturing their content as it appears on a user screen. Then, two different processing pipelines are applied in parallel. The first pipeline pertains to the perceived textual content, as it includes optical character recognition (OCR) to extract rendered textual content, followed by naive Bayes (NB) and decision tree (DT) content classifiers. The second pipeline focuses on the appearance of the email, as it analyzes and classifies the images of rendered emails through a specific convolutional neural network. Lastly, a meta classifier integrates text- and image-based classifier outputs, exploiting the stacking ensemble learning method. The performance of the proposed VBSF is assessed, showing that it achieves an accuracy of more than 98%, which is higher than the compared existing techniques on the designed dataset.

cs.CR

Secret Key Generation on Aerial Rician Fading Channels Against a Curious Receiver

Secret key generation at the physical layer is expected to be a fundamental enabler for next-generation networks. We consider a network where the user equipment is a drone and propose a novel secret key generation solution when the eavesdropper is another node belonging to the network (curious device). We exploit drone mobility over realistic Rician fading channels. In our protocol, after a prior training phase, drone Alice chooses a trajectory of positions in space and transmits a message to Bob, on the ground, from each position. From the received messages, Bob estimates the channel gain from which a secret key is extracted. The choice of the positions is made to maximize a lower bound on the secret key capacity. Numerical simulations are used to prove the effectiveness of the proposed approach.

eess.SP

Physical Layer-Based Device Fingerprinting for Wireless Security: From Theory to Practice

The identification of the devices from which a message is received is part of security mechanisms to ensure authentication in wireless communications. Conventional authentication approaches are cryptography-based, which, however, are usually computationally expensive and not adequate in the Internet of Things (IoT), where devices tend to be low-cost and with limited resources. This paper provides a comprehensive survey of physical layer-based device fingerprinting, which is an emerging device authentication for wireless security. In particular, this article focuses on hardware impairment-based identity authentication and channel features-based authentication. They are passive techniques that are readily applicable to legacy IoT devices. Their intrinsic hardware and channel features, algorithm design methodologies, application scenarios, and key research questions are extensively reviewed here. The remaining research challenges are discussed, and future work is suggested that can further enhance the physical layer-based device fingerprinting.

cs.CR

Learning The Likelihood Test With One-Class Classifiers for Physical Layer Authentication

In physical layer authentication (PLA) mechanisms, a verifier decides whether a received message has been transmitted by a legitimate user or an intruder, according to some features of the physical channel over which the message traveled. To design the authentication check implemented at the verifier, typically either the statistics or a dataset of features are available for the channel from the legitimate user, while no information is available when under attack. When the statistics are known, a well-known good solution is the likelihood test (LT). When a dataset is available, the decision problem is one-class classification (OCC) and a good understanding of the machine learning (ML) techniques used for its solution is important to ensure security. Thus, in this paper, we aim at obtaining ML PLA verifiers that operate as the LT. We show how to do it with the neural network (NN) and the one-class least-squares support vector machine (OCLSSVM) models, trained as two-class classifiers on the single-class dataset and an artificial dataset. The artificial dataset for the negative class is obtained by generating channel feature (CF) vectors uniformly distributed over the domain of the legitimate class dataset. We also derive a modified stochastic gradient descent (SGD) algorithm that trains a PLA verifier operating as LT without the need for the artificial dataset. Furthermore, we show that the one-class least-squares support vector machine with suitable kernels operates as the LT at convergence. Lastly, we show that the widely used autoencoder classifier generally does not provide the LT. Numerical results are provided considering PLA on both wireless and underwater acoustic channels.

cs.LG

Physical Layer Authentication With Colored RIS in Visible Light Communications

We study a visible light communication (VLC) system that employs a colored reconfigurable intelligent surface (CRIS) based on dichroic mirrors that reflect light at tunable frequencies. A verifier can use the CRIS to authenticate transmissions by comparing received multicolor power profiles with expected patterns. Four CRIS configuration strategies are evaluated: a deterministic cyclic pattern, static random reflectance, dynamic random reflectance, and dynamic random permutation of fixed profiles. Randomized configurations, especially dynamic ones, achieve superior authentication, enabling a novel challenge-response physical-layer authentication scheme over CRIS.

eess.SP