SFPF: Spatio-Frequency Polarization Fingerprint for Anomalous Wireless Device Detection
arXiv:2609.21873v1 [cs.CR] 18 Sep 2026
Xiaoxuan Huang, Jinlong Xu, Daoyuan Shen, Meng Zhang, Dong Wei
Abstract—Periodic inspection of deployed wireless devices is necessary because unauthorized hardware replacement may preserve communication functions, credentials, and logical identity, making anomalous devices difficult to detect. Such inspections are conducted under controlled measurement conditions to verify that each device remains consistent with its enrolled hardware state. Conventional radio-frequency fingerprint (RFF) may provide insufficient separation when replacement hardware closely resembles legitimate hardware, while a polarization fingerprint (PF) constructed at one observation direction may miss spatially nonuniform polarization changes. This paper proposes the spatio-frequency polarization fingerprint (SFPF), which jointly represents complex polarization responses over multiple frequencies and observation directions; conventional PF is its fixed-direction slice. We derive SFPF formation from hardwaredependent modal excitation, directional far-field radiation, and polarization projection. A first-order sensitivity analysis shows that the response to the same hardware change varies with both frequency and direction, motivating joint spatio-frequency acquisition. Electromagnetic simulations confirm the nonuniform spatio-frequency sensitivity and show that, under the same observation budget, SFPF improves normalized distance, Fisher score, and the inter-/intra-class ratio over PF by 17.7%, 45.8%, and 11.3%, respectively. Experiments show that SFPF consistently outperforms RFF and PF over 0–20 dB. At 15–20 dB, SFPF achieves anomalous-device F1 scores of 87.3–90.4% and AUROC values of 85.4–95.5%. Index Terms—spatio-frequency polarization fingerprint, anomalous device detection, physical-layer security, open-set recognition
I. I NTRODUCTION Wireless devices deployed over extended periods face the risk of unauthorized changes to their internal hardware. An adversary may replace one or more hardware modules in a wireless device with unauthorized, counterfeit, or maliciously modified alternatives. Counterfeit networking equipment found in practice can closely imitate a genuine product while using a different internal implementation [1]. Such hardware may enable unauthorized network access, traffic interception, sensitive-information exfiltration, or persistent service disruption. More importantly, a replaced device may retain its communication functions, software configuration, credentials, and apparent identity. It can therefore continue to pass credential-based authentication and software integrity verification even though its physical hardware has changed. Conventional hardware-integrity inspection often requires taking the device out of service and transferring it to a dedicated platform for disassembly, internal imaging, or probe-based measurements, which may disrupt normal operation or damage the device [2], [3]. Detecting this threat requires periodic, nonintrusive inspection of wireless devices to determine whether
each device still conforms to its enrolled legitimate hardware state. Physical-layer detection based on radiated wireless signals provides a non-contact way to detect hardware anomalies. Radio-frequency fingerprint (RFF) extracts hardwaredependent imperfections using transient and steady-state signatures such as carrier-frequency offset and I/Q imbalance, as well as raw I/Q samples, spectra, time–frequency features, and learned representations [4]–[6]. In a stealthy replacement attack, however, the adversary attempts to make the unauthorized module as similar as possible to the original hardware, leaving only subtle differences between legitimate and anomalous devices. Conventional RFF relies primarily on time- and frequency-domain signal characteristics, which provide insufficient separability for such subtle hardware anomalies [7]. In addition to time- and frequency-domain characteristics, wireless signals also contain polarization-domain characteristics. These polarization characteristics are affected by the hardware characteristics of the wireless device and form a device-dependent polarization fingerprint (PF) [8], [9]. PF exhibits both frequency-dependent and spatially dependent characteristics. However, existing PF methods construct each fingerprint at a single observation direction and do not fully exploit its spatial characteristics. When the polarization difference between a legitimate device and an anomalous device is weak at the selected direction, fixed-direction PF may omit useful anomaly information and provide limited separability. To address this limitation, we propose the spatio-frequency polarization fingerprint (SFPF) for periodic, non-intrusive hardware-anomaly inspection of wireless devices. SFPF jointly organizes complex polarization responses over multiple frequencies and observation directions, while a conventional PF is its fixed-direction slice. We derive its formation from modal excitation and directional far-field projection, and analyze the sensitivity of SFPF to hardware perturbations. A detection network (ADNet) then encodes each directional observation, fuses its direction coordinate, and aggregates the resulting feature set to identify enrolled devices and reject anomalous devices. Electromagnetic simulations and prototype experiments demonstrate that SFPF provides stronger separability between legitimate and anomalous devices than RFF and PF. The main contributions are as follows: •
We introduce SFPF as a joint frequency–direction polarization representation and establish conventional PF as its fixed-direction slice, thereby extending PF from a
single observation direction to the joint spatio-frequency domain. • We derive the SFPF formation mechanism from modal excitation, far-field radiation, and hardware-perturbation sensitivity. The analysis shows why hardware-induced polarization differences vary across frequency and observation direction, and why sampling multiple reliable directions reduces the risk of missing a hardware change. • Electromagnetic simulations show that hardware changes produce different SFPF responses across frequencies and observation directions, and that joint spatio-frequency sampling improves separability. Prototype experiments further demonstrate that SFPF achieves better anomalousdevice detection performance than RFF and PF. II. R ELATED W ORK Hardware-integrity sensing. Existing methods detect counterfeit components and malicious modifications through physical inspection, logic testing, or side-channel measurements such as timing, power, and near-field electromagnetic emissions [2], [3]. Physical inspection relies on imaging, microscopy, or backside access and often requires opening the enclosure or accessing internal components [2], [3]. Logic testing and timing- or power-based methods generally require wired access to chip pins, supply lines, or test interfaces, together with carefully designed stimuli [2]. Near-field electromagnetic methods can avoid direct electrical contact [10]– [12], but still require probes close to the chip or circuit board and may require removing the enclosure or shielding. Repeating these operations for periodic inspection of deployed wireless devices is time-consuming and risks disturbing or damaging the device. This limitation motivates non-contact approaches that assess hardware integrity directly from the device’s intended wireless transmissions. Radio-frequency fingerprint. RFF extracts hardwaredependent characteristics from wireless signals, thereby enabling non-contact anomaly detection without opening the device or accessing its internal test interfaces [4], [5]. Existing methods use turn-on transients, steady-state impairments, spectrograms, and learned representations [4]–[6]. In a stealthy replacement attack, the claimed logical identity may remain valid while the unauthorized hardware closely imitates the original hardware. The resulting difference between legitimate and anomalous states can be small, reducing the separability of conventional RFF representations constructed primarily from time-, frequency-domain signal characteristics [4]. Polarization fingerprint. PF provides a non-contact representation for hardware-anomaly detection because hardware changes in a wireless device alter the polarization state of its signal [8], [13]. Existing studies have established the formation mechanism of PF and identified its frequency-dependent and spatially dependent characteristics; PF has also been investigated for device identification, physical-layer authentication, spatial characterization, and artificial fingerprint injection [7]– [9], [13]. Nevertheless, each PF sample is still constructed at a single observation direction [8], [9], [13]. Existing PF
representations do not jointly model polarization variations across frequencies and observation directions, which limits their ability to expose subtle hardware anomalies. In summary, existing hardware-integrity methods are often intrusive, RFF may provide insufficient separation for subtle replacement anomalies, and existing PF methods do not fully exploit the spatial characteristics of polarization, potentially discarding discriminative information. SFPF addresses this limitation by incorporating observation direction as a physical dimension and jointly modeling polarization variations across frequency and space. It therefore preserves more discriminative information about hardware changes for anomalous-device detection. III. SFPF F ORMATION AND C ONSTRUCTION A. Formation Mechanism We use a single-radiating-element circularly polarized antenna to expose the principal physical mechanism underlying the spatio-frequency polarization fingerprint (SFPF). Its radiation is mainly dominated by two orthogonal near-degenerate characteristic modes. According to characteristic mode theory [14], [15], the surface current can be approximated as J(r′ , f ) = a1 (f )J1 (r′ ) + a2 (f )J2 (r′ ),
(1)
where Jn (r′ ) denotes the current distribution of the nth mode and an (f ) is its frequency-dependent complex excitation coefficient. Around resonance, the modal coefficient can be approximated as Vn , n = 1, 2, (2) an (f ) = 1 + jQn (f /fn − fn /f ) where Vn , Qn , and fn denote the feed-dependent excitation, quality factor, and resonant frequency, respectively. Hardware variations can perturb these quantities and thereby alter the relative modal amplitude and phase over frequency. For an observation direction (θ, ϕ), define T r̂(θ, ϕ) = sin θ cos ϕ sin θ sin ϕ cos θ . (3) Under the far-field approximation, the directional response of the nth mode and the total far-field vector response can be written as [16] Z ′ Fn (k, θ, ϕ) = Jn (r′ )ejkr̂(θ,ϕ)·r dS ′ , S
F(f, θ, ϕ) =
2 X
(4) an (f )Fn (k, θ, ϕ).
n=1
Frequency therefore changes the relative modal weights through an (f ), whereas observation direction changes the coherent addition of the distributed modal currents through Fn (k, θ, ϕ). Because the far-field electric field is transverse to the propagation direction, it can be expressed as [16] E(f, θ, ϕ) = C(r, f ) I − r̂r̂T F(f, θ, ϕ), (5)
where C(r, f ) collects propagation terms common to the field components. With two orthogonal receive components Ex and Ey , the complex polarization ratio is defined as [17] Ex (f, θ, ϕ) p(f, θ, ϕ) = . Ey (f, θ, ϕ)
∆p(f, θ, ϕ) ≈ ∇ξ p(f, θ, ϕ)T ∆ξ.
(7)
The sensitivity ∇ξ p(f, θ, ϕ) varies with both frequency and observation direction through (2)–(5). Consequently, the same hardware perturbation can produce nonuniform polarization deviations over the spatio-frequency domain. The difference may be weak at one frequency or observation direction but pronounced at another. A fixed-direction PF may therefore miss discriminative hardware information when the selected direction is insensitive to the particular perturbation. To describe how observable a hardware perturbation is at a given direction over the sampled frequency range, we define Nf X
2
|∆p(fl , θ, ϕ)| .
(8)
l=1
A larger Ddir (θ, ϕ) indicates that the hardware perturbation produces a more pronounced polarization difference at that direction, whereas a smaller value indicates a less informative direction. Since Ddir (θ, ϕ) is generally nonuniform over space, relying on a single observation direction can omit useful anomaly information. This nonuniform sensitivity, rather than increased feature dimensionality alone, motivates joint spatio-frequency acquisition. By sampling multiple frequencies and observation directions, SFPF retains polarization responses from a broader set of spatial and spectral conditions and is therefore less likely to discard informative hardware-induced deviations. B. SFPF and Its Relation to PF
N ,N
a f S = {p(fl , θa , ϕa )}a=1,l=1 ∈ CNa ×Nf .
In practical acquisition, Ns complex polarization-ratio samples are retained for each direction–frequency pair, giving the e ∈ CNa ×Nf ×Ns . sampled SFPF tensor S At a fixed observation direction (θ0 , ϕ0 ), a conventional polarization fingerprint (PF) is N
f pPF (θ0 , ϕ0 ) = {p(fl , θ0 , ϕ0 )}l=1 = S[a0 , :],
N
f F = {fl }l=1
denote the sampled frequency set, and let a R = {(θa , ϕa )}N a=1
(10)
where (θa0 , ϕa0 ) = (θ0 , ϕ0 ). Hence, conventional PF is a fixed-direction slice of SFPF. PF preserves polarization variation over frequency at one observation direction, but it does not capture how the frequency-dependent polarization response varies across observation directions. In contrast, SFPF jointly preserves polarization variations over frequency and space. Because hardwareinduced deviations can be spatially nonuniform, observations from multiple directions provide complementary information that may be absent from a fixed-direction PF. IV. SFPF-BASED H ARDWARE A NOMALY D ETECTION A. Threat Model We consider periodic hardware-anomaly inspection of enrolled wireless devices. The inspection receiver, dual-polarized antenna, enrolled SFPFs, and trained detector are assumed to be trusted. Before deployment, each authorized device is measured in its legitimate hardware configuration and enrolled as a reference. An authorized hardware change requires reenrollment; otherwise, any deviation from the enrolled hardware state is regarded as a hardware anomaly. The adversary is assumed to have physical access to the device and may replace the antenna (A), RF front end (R), or digital/baseband module (D), with functionally compatible unauthorized components. The compromised device may preserve its software configuration, credentials, protocol behavior, communication functions, and apparent logical identity, and may therefore continue to pass conventional upper-layer authentication. We assume that the adversary cannot compromise the trusted inspection chain, modify the enrolled fingerprints or detector parameters. For the set of enrolled device identities K, the detector maps an observed fingerprint X to G : X → K ∪ {anomalous}.
Let
(9)
(6)
Equations (2)–(6) show that the polarization response inherently depends on both frequency and observation direction. Frequency determines how the hardware-dependent modes are excited, while direction affects both their far-field coherent addition and their projection onto the orthogonal receive components. Thus, changing the observation direction does not merely change the received signal strength; it changes the observed polarization state itself. To characterize how a subtle hardware change appears in the spatio-frequency polarization response, let ξ collect effective hardware-dependent parameters governing modal excitation and radiation, and let ∆ξ denote a small perturbation. A firstorder expansion gives
Ddir (θ, ϕ) =
denote the set of distinct physical observation directions. The SFPF of a device is defined as
(11)
The security objective is to accept devices that remain in their enrolled hardware states and reject devices whose hardware states deviate from their enrolled states. We evaluate all seven nonempty replacement combinations of the three modules: A, R, D, A+R, A+D, R+D, and A+R+D.
The directional feature set is summarized using complementary mean and maximum pooling, " #! Na 1 X h=ψ qa ; max qa ∈ R128 , (15) 1≤a≤Na Na a=1
Fig. 1. Offline enrollment and training with periodic hardware inspection.
where ψ(·) is a 256-to-128 projection followed by layer normalization, GELU, and dropout. Mean pooling represents the overall device response, whereas maximum pooling retains localized directional variations caused by hardware replacement. A linear classifier maps h to the K enrolled device classes. The network is trained using only enrolled devices and the cross-entropy loss N
Lcls = −
B. Detection Framework Figure 1 illustrates the overall SFPF-based hardware anomaly detection framework, which consists of offline enrollment and training followed by periodic hardware inspection. During offline enrollment and training, SFPFs are collected only from authorized devices under their legitimate hardware configurations. Each SFPF is associated with the corresponding device identity and used to train the detector to learn the hardware-dependent characteristics of enrolled devices. During periodic inspection, the device under test is measured under the same acquisition settings, and its SFPF is constructed from the received signals. The trained detector then determines whether the observed SFPF is consistent with an enrolled device. If so, the corresponding device identity is reported; otherwise, the device is rejected as anomalous. C. Detection Network The anomalous-device detection network (ADNet) is a coordinate-aware set network for multi-directional SFPF. Its shared encoder and symmetric pooling follow the permutationinvariant set formulation in [18], while coordinate fusion retains the physical direction of each observation. Concatenating e along the sample dimenthe real and imaginary parts of S sion gives X ∈ RNa ×Nf ×2Ns . Each directional observation Xa ∈ RNf ×2Ns is processed independently by a shared threelayer 1-D CNN: k=9
k=7
k=5
s=4
s=4
s=4
Nf −−−→ 32 −−−→ 64 −−−→ 128. Each convolution is followed by batch normalization and GELU activation. Adaptive average pooling then produces a 128-dimensional directional feature ea = Gcnn (Xa ) ∈ R128 .
(12)
To retain the physical observation direction, each feature is augmented with its unit direction coordinate ca = [sin θa cos ϕa , sin θa sin ϕa , cos θa ]T .
(13)
The directional feature and coordinate are fused through a shared linear projection: qa = GELU(LN(Wc [ea ; ca ] + bc )) ∈ R128 .
(14)
1 X log pyi (Xi ). N i=1
(16)
No anomalous samples or auxiliary self-supervised objectives are required during training. ADNet rejects anomalous devices using class-conditional Mahalanobis distance [19] in the learned feature space. Let µk denote the feature mean of enrolled class k, and let Σ be the shared diagonal covariance estimated from known validation samples. The anomaly score is d(h) = min (h − µk )T Σ−1 (h − µk ). 1≤k≤K
(17)
The rejection threshold γ is determined exclusively from known-device validation scores. The final decision is ( arg maxk pk (X), d(h) ≤ γ, (18) y∗ = anomalous, d(h) > γ. V. E XPERIMENTAL E VALUATION A. Simulation Validation of SFPF We conduct simulations using Ansys Electronics 2022 R1. To construct PF and SFPF samples, data are collected over multiple observation angles and frequency points. Specifically, θ ranges from 0◦ to 90◦ , while ϕ ranges from 0◦ to 360◦ , with a default angular interval of 1◦ . The frequency range is 913– 917 MHz with a 0.5-MHz interval. To emulate the attack, a subtle structural modification is introduced into the antenna. The data before and after modification are used to construct the corresponding SFPF samples for the normal and anomalous hardware states, respectively. Figure 3 shows that the overall response remains similar after modification, while a localized region changes visibly. This behavior agrees with (7): hardware perturbation produces different polarization deviations across the angle–frequency domain, and a fixed-direction PF may miss an informative region. To compare RFF and SFPF under the same hardware perturbation, we evaluate the normal-to-anomalous difference at each observation direction. Figure 4 shows that the multi-angle RFF difference is relatively weak over most directions, while SFPF presents larger differences in several spatial regions. The results indicate that SFPF is more sensitive to subtle hardware changes and can reveal variations that are less evident in RFF.
Fig. 2. ADNet architecture. A shared 1-D CNN encodes each directional SFPF observation, coordinate fusion retains its physical direction, and mean– maximum pooling forms the device representation. A linear classifier identifies enrolled devices, while Mahalanobis-distance thresholding rejects anomalous devices.
(a) Enrolled hardware
(b) Modified hardware
Fig. 3. SFPF distributions before and after hardware perturbation. The highlighted local deviation illustrates direction-dependent hardware sensitivity.
(a) Multi-angle RFF difference
(b) SFPF difference
Fig. 4. Normal-to-anomalous device differences over observation direction under the same hardware perturbation.
B. Spatio-Frequency Sampling Analysis We compare four sampling modes, each using the same fixed budget of nine angle–frequency observations: singlefrequency single-angle (SF-SA), single-frequency multi-angle (SF-MA), multi-frequency single-angle (MF-SA, i.e., PF), and multi-frequency multi-angle (MF-MA, i.e., SFPF). SF-SA consists of nine repeated observations acquired at 915 MHz and (θ, ϕ) = (50◦ , 45◦ ); SF-MA uses 915 MHz with θ ∈ {20◦ , 50◦ , 80◦ } and ϕ ∈ {0◦ , 45◦ , 90◦ }; MF-SA uses nine frequencies from 913 to 917 MHz at 0.5-MHz intervals at
a fixed observation direction; and MF-MA uses 914.5, 915, and 915.5 MHz at (50◦ , 0◦ ), (50◦ , 45◦ ), and (50◦ , 90◦ ). For pre- and post-modification fingerprints pb and pa , the energy-normalized complex distance is dN = p
∥pb − pa ∥2 (∥pb ∥22 + ∥pa ∥22 )/2
.
(19)
Table I shows that MF-MA ranks first on all metrics. Relative to fixed-direction PF, it improves normalized distance by 17.7%, Fisher score by 45.8%, and the inter-/intra-class ratio
(a) SF-SA
(b) SF-MA
(c) MF-SA (PF)
(d) MF-MA (SFPF)
Fig. 5. Feature distributions under four sampling modes.
TABLE I F EATURE SEPARABILITY UNDER DIFFERENT SAMPLING MODES . Mode SF-SA SF-MA MF-SA (PF) MF-MA (SFPF)
dN 0.1070 0.1203 0.1072 0.1261
Fisher score Inter/intra ratio 4.3834 2.3915 4.8699 7.1015
3.2991 2.2896 3.6527 4.0654
by 11.3%. These results show that joint frequency–direction sampling improves the separability of SFPF features. Figure 6 further examines the spatial acquisition parameters. Frequency is fixed to 913–917 MHz at 0.5-MHz intervals. Expanding θ or ϕ does not improve separability uniformly; instead, the distance rises sharply when newly included regions contain sensitive directions. Fine angular sampling better retains these localized differences, whereas coarse grids may skip them. Figure 7 provides the frequency domain analysis, with angle fixed to θ ∈ [0◦ , 80◦ ], ϕ ∈ [0◦ , 90◦ ], and 5◦ intervals. Wider frequency coverage increases the cumulative distance because it captures more of the modal variation in (2), and the newly added outer bands are particularly sensitive. By contrast, changing the frequency interval within the same response region leaves the mean distance almost unchanged. These results indicate that covering informative spectral regions is more important than simply increasing sampling density. C. Experimental Setup The prototype contains ten communication devices enrolled with their original hardware. A USRP X310 with an orthogonal dual-polarized antenna is fixed 3 m from the device under test, which is mounted on a motorized pan–tilt platform. Measurements use nine frequencies from 913 to 917 MHz at 0.5MHz intervals and 1024 complex samples per angle–frequency pair. Elevation covers 0◦ –60◦ and azimuth covers 0◦ –120◦ , both at 5◦ intervals. Merging duplicate pole coordinates gives 301 physical directions per SFPF. Five devices are selected as attack targets. Each uses its own replacement antenna, RF front end, and digital/baseband module; no module is reused across targets. We evaluate A,
R, D, A+R, A+D, R+D, and A+R+D. Only normal samples at 20 dB are used for training, while non-overlapping normal and anomalous samples over 0–20 dB are used for testing. The coordinate-aware set network contains approximately 1.1 × 105 trainable parameters and is trained for 30 epochs using AdamW with an initial learning rate of 10−3 , weight decay 10−4 , and an effective batch size of 64. The learning rate is linearly warmed up for two epochs and then cosinedecayed to 10−5 ; dropout is set to 0.1, and the checkpoint with the highest known-device validation accuracy is used for testing. Class means, the shared diagonal covariance, and the rejection threshold are estimated exclusively from knowndevice validation features, with the threshold set to their 99thpercentile Mahalanobis score. RFF and SFPF are collected over the same set of observation angles. PF is independently measured at boresight (0◦ , 0◦ ), where both polarization components are reliable, over the same frequency set. PF measurements are repeated at the same observation direction to obtain the same number of samples as SFPF, without introducing additional spatial information. RFF, PF, and SFPF use the same devices for training and testing and the same detection configuration. D. Hardware Anomaly Detection Results Figure 8(a) compares the anomalous-device F1 scores of RFF, PF, and SFPF. SFPF consistently achieves higher F1 scores across the tested SNR range. At 15–20 dB, the F1 scores of RFF and PF range from 9.7–24.9% and 48.8–57.9%, respectively, whereas SFPF achieves 87.3–90.4%. These results demonstrate that SFPF is more effective in detecting subtle hardware changes. Figure 8(b) presents the open-set detection performance of SFPF. The AUROC increases from 70.9% at 0 dB to 95.5% at 20 dB, and ranges from 85.4% to 95.5% at 15–20 dB. Over the same SNR range, unknown-device recall ranges from 80.8% to 86.6%, while known-device accuracy ranges from 80.3% to 99.7%. These results show that SFPF maintains effective known-device identification and anomalous-device detection under different SNR conditions.
(a) θ coverage
(b) ϕ coverage
(c) Angular interval
Fig. 6. Effect of spatial acquisition parameters on normalized SFPF difference.
(a) Frequency coverage
(b) Frequency interval
Fig. 7. Effect of frequency acquisition parameters on normalized SFPF difference.
(a) Fingerprint comparison
(b) SFPF open-set performance Fig. 8. Detection results over 0–20 dB.
E. Security Performance To further evaluate the system from a security perspective, Fig. 9 reports the detection error rate DER = (F PK + F NU )/N , known-device false alarm rate FARK = F PK /(F PK +T NK ), and unknown-device miss rate MRU =
F NU /(T PU + F NU ), where N = T PU + F NU + F PK + T NK . At 10–20 dB, the scenario-wise DER ranges from 0.25% to 11.27%, while the known-device false alarm rate remains between 0.33% and 3.33% over the entire SNR range. At 15–20 dB, the unknown-device miss rate ranges from 0 to 33.33% across the seven replacement scenarios.
(a) Detection error rate
(b) Known-device false alarm rate
(c) Unknown-device miss rate
Fig. 9. Security performance under seven hardware-replacement scenarios; lower values are better.
F. Discussion At 0.05 s per angle–frequency observation, the 301direction, nine-frequency grid requires 135.45 s for one complete SFPF acquisition. The current acquisition process is intended for periodic hardware inspection, and reducing the acquisition time remains an important direction for future work. The sampling analysis shows that discriminative changes concentrate in selected angle–frequency regions, motivating sparse acquisition in future work. VI. C ONCLUSION This paper presented SFPF for non-intrusive periodic hardware-anomaly inspection of wireless devices. SFPF extends conventional PF from one observation direction to a joint frequency–direction representation. Its formation model and sensitivity analysis show that hardware-dependent modal excitation and far-field projection cause the same hardware change to produce nonuniform polarization differences over frequency and direction. Simulations confirmed this behavior and showed that, SFPF improved normalized distance, Fisher score, and the inter-/intra-class ratio over PF by 17.7%, 45.8%, and 11.3%, respectively. In prototype experiments with ten devices and seven hardware-replacement scenarios, SFPF consistently outperformed RFF and PF; at 15–20 dB, its anomalousdevice F1 reached 87.3–90.4% and its AUROC reached 85.4– 95.5%. These results support SFPF for periodic non-intrusive inspection. The current full-grid acquisition takes 135.45 s; future work will use sensitivity-guided sparse sampling to reduce this time. R EFERENCES [1] F-Secure Consulting, “The fake cisco: Hunting for backdoors in counterfeit cisco devices,” F-Secure Consulting, Tech. Rep., 2020, accessed: 2026-06-03. [Online]. Available: https://labs.withsecure.com/ content/dam/labs/docs/2020-07-the-fake-cisco.pdf [2] M. Tehranipoor and F. Koushanfar, “A survey of hardware trojan taxonomy and detection,” IEEE Design & Test of Computers, vol. 27, no. 1, pp. 10–25, 2010. [3] B. Zhou, A. Aksoylar, K. Vigil, R. Adato, J. Tan, B. Goldberg, M. S. Ünlü, and A. Joshi, “Hardware trojan detection using backside optical imaging,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 40, no. 1, pp. 24–37, 2021.
[4] N. Soltanieh, Y. Norouzi, Y. Yang, and N. C. Karmakar, “A review of radio frequency fingerprinting techniques,” IEEE Journal of Radio Frequency Identification, vol. 4, no. 3, pp. 222–233, 2020. [5] Y. Peng, C. Hou, Y. Zhang, Y. Lin, G. Gui, H. Gacanin, S. Mao, and F. Adachi, “Supervised contrastive learning for rff identification with limited samples,” IEEE Internet of Things Journal, vol. 10, no. 19, pp. 17 293–17 306, 2023. [6] T. Nhem, M. Weyn, M. Peeters, and R. Berkvens, “Explainable rff: Radio frequency fingerprint via spectrogram analysis,” in 2025 IEEE 36th International Symposium on Personal, Indoor and Mobile Radio Communications (PIMRC). IEEE, 2025, pp. 1–6. [7] J. Wang, J. Xu, D. Wei, and W. Huang, “Device identification based on artificial polarization fingerprint injection,” in 2025 IEEE Wireless Communications and Networking Conference (WCNC). IEEE, 2025, pp. 1–7. [8] J. Xu, D. Wei, and W. Huang, “Polarization fingerprint: A novel physical-layer authentication in wireless iot,” in 2022 IEEE 23rd International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM). IEEE, 2022, pp. 434–443. [9] ——, “Specific emitter identification via spatial characteristic of polarization fingerprint,” in 2022 IEEE Symposium on Computers and Communications (ISCC). IEEE, 2022, pp. 1–7. [10] D. Agrawal, S. Baktir, D. Karakoyunlu, P. Rohatgi, and B. Sunar, “Trojan detection using IC fingerprinting,” in 2007 IEEE Symposium on Security and Privacy, 2007, pp. 296–310. [11] H. Huang, A. Boyer, and S. Ben Dhia, “The detection of counterfeit integrated circuit by the use of electromagnetic fingerprint,” in 2014 International Symposium on Electromagnetic Compatibility, 2014, pp. 1118–1122. [12] D. Lee, J. Lee, Y. Jung, J. Kauh, and T. Song, “Robust hardware trojan detection method by unsupervised learning of electromagnetic signals,” IEEE Transactions on Very Large Scale Integration (VLSI) Systems, vol. 32, no. 12, pp. 2327–2340, 2024. [13] J. Xu and D. Wei, “Polarization fingerprint-based lorawan physical layer authentication,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 4593–4608, 2023. [14] R. F. Harrington and J. R. Mautz, “Theory of characteristic modes for conducting bodies,” IEEE Transactions on Antennas and Propagation, vol. 19, no. 5, pp. 622–628, 1971. [15] Y. Chen and C.-F. Wang, Characteristic Modes: Theory and Applications in Antenna Engineering. Hoboken, NJ, USA: John Wiley & Sons, 2015. [16] C. A. Balanis, Antenna Theory: Analysis and Design, 4th ed. Hoboken, NJ, USA: John Wiley & Sons, 2016. [17] A. C. Ludwig, “The definition of cross polarization,” IEEE Transactions on Antennas and Propagation, vol. 21, no. 1, pp. 116–119, 1973. [18] M. Zaheer, S. Kottur, S. Ravanbakhsh, B. Póczos, R. Salakhutdinov, and A. J. Smola, “Deep sets,” in Advances in Neural Information Processing Systems, vol. 30, 2017, pp. 3391–3401. [19] K. Lee, K. Lee, H. Lee, and J. Shin, “A simple unified framework for detecting out-of-distribution samples and adversarial attacks,” in Advances in Neural Information Processing Systems, vol. 31, 2018, pp. 7167–7177.