Conceptio › Archive › arXiv CS
arXiv CSopen access

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based Human Activity Recognition for Privacy Protection

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based Human Activity Recognition for Privacy Protection Byungjun Kim★, Amogh Panchagatti⋄ , Peter Gerstoft⋄ , Xinyu Zhang⋄ , Minsung Kim★ Wi-Fi Router

GRAW

arXiv:2609.24173v1 [cs.NI] 21 Sep 2026

Abstract

Perturbation +0.3 -0.5 -0.1 Signal Gen.

★Rutgers University, ⋄ UCSD ··· +0.1

Wi-Fi Router Perturbation

Remote +0.3 -0.5 -0.1 ··· +0.1 The growing capabilityWi-Fi of Wi-Fi +1 +1to identify LTF: devices -1 ··· human +1 Signal Gen. Attacker activities using channel state information (CSI) raises privacy concerns. To counter this threat, we propose GRAW, Human Activity: Running +1 Wi-Fi LTF +1 -1 ··· +1 an adversary system—acting as a privacy defender—that deMalicious grades the human activityDevice recognition (HAR) system at the Human Activity: Running user device by perturbing the router’sTrue signals thatRunning the device Activity: Malicious User Device uses to estimate CSI. GRAW employs Perturbation generative Signal adversarial CSI imitation learning (GAIL) to construct perturbation signals, True Activity: Running NN-based Misidentified: Sleeping and thereby eliminates need for any information on the Wi-Fithe HAR Perturbation Signal target HAR systems and their inputs (i.e., zero-knowledge CSI Misidentified: Sleeping Wi-Fi HAR operation). We evaluate GRAW against seven representative HAR models, using datasets collected in five environments, Figure 1: Remote adversarial attack against Wi-Fi including our own dataset. We observe that GRAW is the HAR. The adversary in the Wi-Fi router attacks neural only remote attack scheme that degrades every tested HAR network-based HAR in the malicious device by adding model to a random-selection level. At the same perturbation perturbation signals to Wi-Fi LTF preambles from the level, GRAW achieves an attack success ratio up to 76.7% Wi-Fi Router router side, aiming to disable or degrade HAR. higher than comparison methods, while maintaining over Perturbation User Antenna-1 CSI +0.3 -0.5 -0.1 ··· +0.1 GRAW 99% packet success rate on regular Wi-Fi communication. Signal Gen. input manipulation approach is called a digital attack. In We demonstrate the feasibility of GRAW through real-time, User Antenna-2 CSI digital Rece +1 +1simple Wi-Fi LTF attacks, -1 methods ··· +1 like the fast gradient method over-the-air experiments with software-defined radios. (FGM) have proven effective [39]. However, digital-attack scenarios assume adversarial attacker systems have direct 1 Introduction Surrogate GAIL-base access to HAR inputs at the Wi-Fi HAR device, which is Model Generato Trainin g As Wi-Fi devices become prevalent indoors, Wi-Fi sensing impractical; for example, the used CSI sequenceData is estimated Reference P using channel state information (CSI) has been used for varwithin the HAR device, beyond the attacker’s control. Pur turb atio n S ignal ious purposes, including indoor localization [40, 43], radio To address this limitation, recent work [15, 24] has infingerprinting [4, 29], and human mesh construction with vestigated the manipulation of Wi-Fi preamble signals to millimeter-wave Wi-Fi [44]. One emerging application of remotely disrupt HAR systems on the receiving end of the Wi-Fi sensing is human activity recognition (HAR) [31, 47], communication link, which we refer to as a remote attack. In which aims to identify human activities using Wi-Fi CSI seWi-Fi systems, a router sends a Long Training Field (LTF) sigquence and neural networks. The enhanced capabilities of nal, i.e., a preamble known to both the router and users, to a modern Wi-Fi HAR systems, while beneficial for legitimate user device, and the device estimates the CSI based on the reapplications, also pose serious privacy threats [25, 55] due to ceived LTF (§2). In remote attacks, the adversary manipulates unauthorized surveillance capabilities, such as unintended this Wi-Fi LTF at a router by adding “perturbation signals” to Wi-Fi Routerobfuscate HAR at the HAR device, as illustrated in Figure 1. motion sensing [58] and keystroke eavesdropping [14]. Input CSI Such unauthorized HAR may be performed on malicious The core problem is howTransmit to design these perturbation signals, Recent CSI HAR devices—user devices that recognize activities from CSI which poses two fundamental Perturbed LTFchallenges:User Orginal 1 Practical without consent. To protect user privacy from these devices, remote adversarial attacker systems must LTF adversarial attacks have been extensively studied, where be able to operate without any information on HAR deGAIL-based Multi-Antenna & Receive Amp. Adjustment Generator of the attacker deliberately degrades the HAR performance vices. Unlike digital attacks, the adversaryPerturbed in remote LTF attacks Real-Time doesS/MIMO-Compatible their neural networks. Previous research has explored the not have access to any (input) information on HAR Purturbation Signal Purturbation Signal direct manipulation of inputs on HAR devices, such as HAR devices. For example, exact HAR input CSI and models are classifier’s loss functions and CSI sequences [51, 55]; this unavailable to the adversary; it must generate perturbation

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim

signals only using recent CSI data available at the moment of LTF manipulation. This mismatch in inputs between the adversary and HAR makes the design of effective perturbation signals more challenging. A recent remote attack system called C&W [24] has addressed the model mismatch by using a surrogate model, but it still assumes the knowledge of HAR’s sliding-window (i.e., input sequence) parameters, such as HAR time duration, sampling rate, and input CSI length, for synchronizing the perturbation with the HAR input window. Typical HAR systems, however, employ varying sequence parameters across implementations [5, 17, 52], and these are unavailable to the adversary. Thus, such synchronized attacks are often impractical. Table 1 summarizes the limitations of existing Wi-Fi-HAR adversarial systems. 2 Perturbation signals in remote attacks must not cause significant degradation to regular Wi-Fi data communications, the primary function of Wi-Fi systems. In remote attacks, while perturbation signals are added only to the LTF, not the payload, a strong perturbation could lead to severely distorted channels and thus degrade regular communication performance. Therefore, a sophisticated design and power control of perturbation signals are essential. In this regard, multi-antenna diversity, common in Wi-Fi, can help preserve data communication even under perturbation [28]. In remote attacks, however, multi-antenna systems, such as Single-Input or Multi-Input Multi-Output (SIMO or MIMO) environments, impose a fundamental constraint: LTF manipulation at the router simultaneously affects CSI estimation across multiple antennas at the user, constraining the achievable distortion patterns [57]. As a result, existing remote attack systems, designed for single-antenna settings, cannot leverage multi-antenna gains, as shown in Table 1. In this paper, we present GRAW (§4), a zero-knowledge remote adversarial attack system against Wi-Fi HAR, which operates without any prior information about target HAR systems. To do so (challenge 1 ), GRAW adopts a surrogate model approach and generative adversarial imitation learning (GAIL). A surrogate model is an accessible approximation of an unknown target model. In GRAW, the surrogate model is a locally-built Bi-LSTM model, commonly used for WiFi-based HAR classifiers [5, 11, 17–19, 52, 54]. GRAW generates full-window reference perturbation signals targeting this surrogate, based on historical CSI and FGM-generated adversarial examples. This CSI-to-perturbation mapping allows for generating reference perturbation signals without requiring direct access to actual target HAR models, and hence, addresses the model mismatch problem inherent in remote Wi-Fi HAR attacks. The underlying principle relies on “adversarial transferability”, where the adversarial examples generated against surrogate models effectively transfer to unknown target systems [34]. C&W directly uses this

Table 1: Comparison of adversarial attacker systems against Wi-Fi HAR systems (see §3 for details). Attacker system

Attack type

S/MIMO compat.

AAEN [55] ADG [56] WiCAM [51] Universal [49] IS-WARS [15] C&W [24] GRAW (ours)

Digital Digital Digital Digital Remote Remote Remote

N/A N/A N/A N/A X X

✓

Need for information on target HAR system Classifier HAR HAR Sampling model CSI window duration rate required required required required required not req. not req.

required required required required required required not req.

required required required required required required not req.

required required required required required required not req.

full-window reference perturbation for LTF manipulation. However, this surrogate model approach alone cannot fully resolve the input mismatch; the full-window reference must synchronize with the HAR’s unknown input window, otherwise causing misaligned perturbations (§8.4). GRAW enables the zero-knowledge operation by employing GAIL, an imitation learning (IL) technique. In GRAW, GAIL learns the temporal relationship between the surrogate model’s input CSI and the generated reference perturbation signal. Once trained, GAIL generates GRAW’s perturbation using only recent CSI via online inference, removing the need for synchronized attacks. Like reinforcement learning (RL), GAIL learns a policy that maps states (recent CSI) to actions (online perturbation). However, RL requires reward feedback, i.e., the degraded HAR accuracy in our scenario, which is unavailable during online inference [46]. IL resolves this by training the policy to imitate the experts’ state-action pairs made by the surrogate (historical CSI and pre-computed reference adversarial examples), without immediate reward feedback. Among IL methods, behavioral cloning, which utilizes conventional time-series neural networks, can also learn this temporal mapping, but its performance often degrades in unseen environments due to covariate shift [9]. GAIL mitigates this issue by learning a policy that adapts to changes in the environment through adversarial training [13]. To our best knowledge, GRAW is the first Wi-Fi HAR adversarial system to leverage GAIL, thus completely eliminating the need for information on target HAR systems. GRAW also minimizes the degradation in Wi-Fi communication performance (challenge 2 ) by dynamically controlling the perturbation signal amplitudes. Specifically, GRAW adjusts each perturbation signal power based on the running average of past signals, keeping its ratio to the LTF amplitude under a target threshold (§7). In addition, as GRAW determines each online perturbation from the recent samples, its power distribution is flatter than the reference perturbations, preventing spikes in the perturbation signal powers, which are critical to communication degradation. GRAW also addresses the aforementioned S/MIMO constraint by projecting the multi-antenna perturbation signals onto a shared single LTF, to best approximate the intended CSI distortion across all receive antennas (§6). This S/MIMO compatibility allows

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

for keeping improving the regular data communications performance with more antennas using spatial diversity (e.g., Maximum Ratio Combining). We evaluate GRAW against seven target architectures using datasets collected in five environments, including our own dataset. Our evaluation encompasses scenarios of unknown input timing and sampling rate as well as unmatched models between surrogate and HAR classifiers. From our evaluations, it is observed that GRAW is the only remote attack scheme capable of degrading every evaluated HAR model to a random-selection level, with up to 76.7% higher attack success ratio (ASR) than existing methods at the same perturbation amplitude. We also demonstrate the feasibility of GRAW through real-time, over-the-air (OTA) experiments using software-defined radios (SDR). We implement GRAW’s pipeline — the inference model, MIMO processing, and online amplitude adjustment — as real-time C++ GNU Radio blocks for 2 × 2 MIMO. The hardware demonstration shows that GRAW with 1000-byte packets achieves over 50% ASR at perturbation-to-signal ratio (PSR) -4 dB while maintaining a 99.7% packet success rate under spatial multiplexing. The source code of GRAW is publicly available.1

2 Background 2.1 Wi-Fi-based HAR In Wi-Fi communications, the orthogonal frequency-division multiplexing (OFDM)-MIMO system with a transmitter (TX) with 𝑁 TX antennas and a receiver (RX) with 𝑁 RX antennas is modeled as: y𝑖 𝑗 = H𝑖 𝑗 x𝑖 𝑗 + n𝑖 𝑗 (1) with 1 ≤ 𝑖 ≤ 𝑀, 1 ≤ 𝑗 ≤ 𝑁 SC , x𝑖 𝑗 ∈ C𝑁TX , y𝑖 𝑗 ∈ C𝑁RX , H𝑖 𝑗 ∈ C𝑁RX ×𝑁TX , and n𝑖 𝑗 ∈ C𝑁RX denoting the transmitted signal, the received signal, the CSI matrix, and the noise vector respectively. An RX uses known LTF (x𝑖 𝑗 ) for channel estimation (H𝑖 𝑗 ) using the received signals (y𝑖 𝑗 ). In our HAR scenarios, a Wi-Fi router is a TX, while an HAR device is an RX. An HAR classifier at the user device typically takes a sequence of CSI matrices from TX as input and outputs the probability of each activity. LSTM is commonly used for a neural network model of the classifier in Wi-Fi HAR [5, 7, 38, 52]. LSTM HAR classifier, 𝑓𝐶 , also takes as an input sequence of CSI matrices, H ∈ R𝑀 ×𝑁SC ×𝑁RX ×𝑁TX ≜ {|H𝑖 𝑗 |}1≤𝑖 ≤𝑀,1≤ 𝑗 ≤𝑁SC , where |H𝑖 𝑗 | is the matrix containing the amplitudes of H𝑖 𝑗 ’s elements. The classifier outputs a vector of elements, each of which represents the probability of each activity. Since different activities take different durations, the length of each input sequence is not fixed. Since activity durations vary, GRAW adopts a Bi-LSTM-based surrogate model (§5), which handles variable-length CSI inputs. 1 https://github.com/byungjunkim12/25-adv_HAR

2.2

Adversarial Attacks

Adversarial attacks against neural networks have been widely studied, as carefully crafted perturbations can significantly degrade the performance of a target model even when they are (nearly) imperceptible. In our HAR attack setting, the classifier inputs are CSI sequences, so the perturbed CSI serves as the adversarial example. Thus, the adversarial example, a perturbed input, is Ĥ = H + Â that remains close to the original input H in some norm, but is intentionally designed so that the classifier’s prediction changes (e.g., 𝑓 ( Ĥ ) ≠ 𝑓 (H )). For example, FGM [10] creates an adversarial example Ĥ : Ĥ = H + 𝛼∇ H L (𝑓 (H ), z)

(2)

where z ∈ R𝑁𝐶 is the one-hot encoded label of H , 𝛼 is a parameter to control the perturbation magnitude, L is the loss function of 𝑓 , and 𝑁𝐶 is the number of classes. FGM alone, however, cannot compute adversarial examples when the adversary lacks access to the target classifier information. This scenario, known as a black-box attack [34], occurs when the adversary has limited knowledge of the target model, such as its architecture or training data. In this case, one can employ a surrogate model, 𝑓C′ (H ), instead of 𝑓 (H ), to generate adversarial examples using only adversary-accessible data. This approach relies on adversarial transferability [34], where adversarial examples made against a surrogate model remain effective against unknown target models. In this work, we specifically focus on the case where the adversary has “no information” about the target model, except for the ground-truth activity labels of the available training data.

2.3

Reinforcement and Imitation Learning

GRAW utilizes a Reinforcement Learning (RL) architecture to address a real-time adversarial attack problem. In realtime adversarial attack scenarios, adversarial examples must be computed at each time step using the sequence of CSI estimated up to that point. This challenge aligns with the RL paradigm, where a policy function 𝜋 (𝑎𝑖 |𝑠𝑖 ) determines actions 𝑎𝑖 based on observed states 𝑠𝑖 and influences subsequent state transitions. RL aims to find the optimal policy function 𝜋 that maximizes the cumulative reward function 𝑀 . over a trajectory, 𝜏 = {(𝑠𝑖 , 𝑎𝑖 )}𝑖=1 In our Wi-Fi HAR attack scenarios, estimated CSI up to the current time, paired with corresponding adversarial examples, form a state-action pair and the reward function represents the degraded accuracy of the target HAR. In RL, such as REINFORCE [46], the learning agent interacts with the reward function for feedback on its actions. However, this interaction is infeasible in our attack scenarios, since the adversary determines the accuracy of the target classifier only after processing the entire input. Thus, GRAW resolves

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim Length = ℓ

Wi-Fi Router

Streaming Wi-Fi CSI:

Most Recent CSI

GRAW Historical CSI under activity

Original Wi-Fi LTF

Length = ℓ Partial CSI

FGM w/ surrogate (§5.1) Surrogate Model

Ref. Perturbation Time

Pre-Train: Expert Demo.

Learn Temporal Relationship (Alg. 1) Perturbation at next time step Time

GAIL Training

Transmit Perturbed LTF

Target HAR Device Corresponding Payload

Data Communication RX Pipeline

Successful Decoding

New CSI (Distorted) GRAW Active

Len gth = ?

HAR-CSI Input Unknown Misidentification HAR Classifier

Figure 2: GRAW’s remote adversarial attack operation. this issue by adopting Imitation Learning (IL), a specialized form of RL, where a training agent learns to replicate expert behavior solely from given expert trajectories (§5.2).

3

Related Work and Limitation

Adversarial attacks targeting Wi-Fi-based HAR systems for privacy protection have attracted significant research attention; we summarize and compare prior works in Table 1. Early studies focused on digital attacks, where techniques from other adversarial ML domains, such as image classification, could be more directly applied since the attacker directly manipulates the classifier input. Early works on digital attacks, such as AAEN [56] and ADG [55], suggest modifying the HAR classifier’s loss functions to prevent the detection of specific activities. However, these approaches assume adversaries can retrain classifiers—a highly unrealistic threat model in practice, considering that adversaries need to interfere with the training process. Other approaches, like WiCAM [51] and Ref. [49], manipulate the CSI input sequences rather than attacking during training, eliminating model training access requirements. Nevertheless, these methods still require direct access to the target HAR system input sequences, which is impractical since the CSI data in user devices is not publicly accessible. To address the impracticality of digital attacks, remote attack methods have emerged where adversaries operate outside target devices without direct system access. A denialof-service approach [25] jams packet transmissions via WiFi collision-avoidance protocols, preventing HAR systems from receiving CSI sequences but also disrupting normal data communication. PhyCloak [35] instead deploys a full-duplex relay that selectively obfuscates RF features for illegitimate Wi-Fi sensing while preserving a designated legitimate sensor. However, it targets traditional RF sensors that extract physical features such as Doppler shifts, and its selective preservation depends on physically co-locating the legitimate sensor with the relay, requiring dedicated hardware. Its single-antenna obfuscation further limits it to SISO settings. Other works, including WiAdv [57], IS-WARS [15], LTFbased C&W perturbations [24], and LTF-based FGM [20], build over-the-air adversarial or spoofing signals, but require

unrealistic assumptions, such as the knowledge of target model architectures and perfect synchronizations with the target input. Furthermore, most of the remote attack systems assume single-antenna scenarios, as manipulating LTF signals from a TX affects CSI estimation across multiple RX antennas simultaneously, constraining the achievable distortion patterns. In contrast, GRAW generates perturbation signals without requiring knowledge of target models or synchronization requirements, while explicitly addressing practical multi-antenna RX constraints.

4 GRAW Overview GRAW is a privacy-protecting adversary at the router against the HAR device’s activity recognition. GRAW modifies the downlink LTF so that the CSI estimated at the HAR device becomes an adversarial example to the HAR classifier, causing misclassification. GRAW achieves this without significantly degrading Wi-Fi data communications (§8.5, §8.6). GRAW requires no prior knowledge on target HAR devices; we refer to this a zero-knowledge operation (i.e., zero knowledge on the target) in this paper. It relies only on a surrogate classifier trained on CSI pre-collected for the target activities. For deployments, we envision that the users (de)activate GRAW on demand to protect their privacy, sharing their activity timing; we also discuss its automated opportunistic operation in Section 9. Operation. Figure 2 overviews GRAW’s operation. For remote attacks, GRAW computes and adds a transmit perturbation signal to the router’s LTF, through the following stages: 1 Expert Demonstration Generation. GRAW first builds the surrogate HAR classifier using historical CSI under activity and generates reference perturbations by applying FGM to this surrogate (§5.1). This provides the expert demo to GAIL. 2 GAIL Training. Based on this demo, the GAIL-based online perturbation generator is trained to learn the temporal relationship between the ℓ samples from the historical CSI and the corresponding step reference perturbation (§5.2). 3 GAIL Inference. The perturbation generator computes online perturbation A𝑖 ∈ R𝑁SC ×𝑁RX ×𝑁TX , at time step 𝑖, based on the ℓ most recent CSI samples estimated at the router.

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

4 Post-processing. When the RX has multiple antennas

(𝑁 RX > 1), A𝑖 cannot be applied directly, as a single LTF is shared across all RX antennas. GRAW therefore converts A𝑖 into B̄𝑖 ∈ R𝑁SC ×𝑁TX whose combined effect at the RX best approximates A𝑖 (§6). Finally, the amplitudes of B̄𝑖 are adjusted online to keep its ratio to the LTF under a target threshold, yielding the transmit perturbation signal B𝑖 (§7). 𝑀 ∈ GRAW then adds transmit perturbation signals B ≜ {B𝑖 }𝑖=1 𝑀 ×𝑁 ×𝑁 SC TX R to LTF. Note that only Step 3 & 4 are online. At the RX, the CSI matrix is estimated using the perturbed LTF, which leads to degradation of the target HAR classifier 𝑓C . Thus, GRAW seeks B that minimizes the accuracy of 𝑓C . GRAW requires two capabilities: extracting CSI and manipulating the transmitted LTF. CSI extraction is standard on commodity NICs (up to 1 kHz [12], far above GRAW’s up to 50 Hz update rate). LTF manipulation, however, requires physical-layer access beyond commodity NICs; we realize it with an SDR (§8.6) and discuss commodity deployment in (§9). By Wi-Fi’s TDD channel reciprocity, the CSI the router estimates from a received packet equals the CSI the HAR device observes, provided that a packet is exchanged within the channel coherence time. GRAW therefore updates the perturbation within the channel coherence time, 20 ms for 5 GHz Wi-Fi under human movement at 1.5 m/s (𝑓𝑑 = 25 Hz, 𝑇𝑐 = 1/(2𝑓𝑑 ) ≈ 20 ms) [50], which also satisfies the 41.7 ms coherence time at 2.4 GHz.

5

Online Perturbation Generation

GRAW trains its online perturbation generator via GAIL, as illustrated in Figure 2. First, the adversary builds a surrogate model to compute reference perturbation (§5.1). Using this surrogate model, black-box FGM computes these reference perturbations on the surrogate, which are then paired with the CSI the router estimates. Using GAIL, the policy network is then trained to map the CSI sequences to online perturbations by imitating references. (§5.2).

5.1

Surrogate Model

The goal of the surrogate model is to compute reference perturbations that will serve as expert demonstrations for training the GAIL policy network later. Since the target HAR classifier is unknown to the adversary, we train a surrogate model using available CSI data. We adopt a Bi-LSTM layer as the surrogate classifier 𝑓C′ , commonly used in Wi-Fi-based HAR classifiers [5, 11, 17– 19, 52, 54]. Owing to the transferability of adversarial examples across deep learning models [34], perturbations computed against the surrogate are expected to be effective against the target HAR classifier as well, and we therefore use them as expert demonstrations for the GAIL policy network. Using the surrogate, black-box FGM computes  ∈

R𝑀 ×𝑁SC ×𝑁RX ×𝑁TX and thus an adversarial example:  Ĥ = H + 𝛼∇ H L 𝑓C′ (H ), z = H + Â,

(3)

where 𝑓 in (2) is replaced with the surrogate model 𝑓C′ . The resulting  then feeds into the GAIL policy network as expert demonstrations (§5.2). We also present the performance of black-box FGM as a reference baseline (§8.4), although it cannot be directly used for remote attacks against Wi-Fi HAR since it requires the CSI sequence over entire action, including those not yet observed at attack time.

5.2

GAIL-based Perturbation Generator

In a remote attack scenario, perturbation signals must be generated online, as the HAR input CSI may be unavailable at generation time. To address this, our GAIL-based perturbation generator is trained to imitate the mapping from recent CSI to the reference perturbation (§5.1) computed from the surrogate via FGM at the current time step. The GAIL-based generator takes the ℓ most recent CSI esti−1 ∈ Rℓ ×𝑁 SC ×𝑁 RX ×𝑁 TX , mates preceding time step 𝑖, H𝑖ℓ ≜ {H 𝑗 }𝑖𝑗=𝑖 −ℓ and outputs an online perturbation, A𝑖 . The goal is to find the policy function 𝜋 (A𝑖 |H𝑖ℓ ) that minimizes the accuracy of 𝑀 ∼ 𝜋 (·|H ℓ ). Since the HAR 𝑓C (H + A), where A ≜ {A𝑖 }𝑖=1 𝑖 classifier 𝑓C takes the entire CSI sequence H as input, directly optimizing this objective requires the entire sequence that is unavailable at time step 𝑖. We instead train 𝜋 to imitate the reference perturbations  computed by black-box FGM in Eq. (3). The generator thereby learns to reproduce these references from only the past CSI H𝑖ℓ . To learn this imitation, we employ GAIL, an IL algorithm 𝑀 . We choose that learns from expert trajectories, {H𝑖ℓ , Â𝑖 }𝑖=1 GAIL because it generalizes to unseen environments, unlike behavioral cloning, which does not [13] (§8.4). GAIL casts imitation as adversarial distribution matching: like a generative adversarial network (GAN), it comprises a discriminator (𝐷 𝑤 ) that distinguishes expert from learner trajectories 𝑀 | {H𝑖ℓ , A𝑖 }𝑖=1 A𝑖 ∼𝜋𝜃 (· | H𝑖ℓ ) and a policy (𝜋𝜃 ) trained to fool it. The complete GAIL objective is: min max E ( H𝑖ℓ ,A𝑖 )∼𝜋𝜃 (A𝑖 | H𝑖ℓ ) [log(𝐷 𝑤 (H𝑖ℓ , A𝑖 ))]+ 𝜋𝜃

𝐷𝑤

(4)

E ( H ℓ ,Â𝑖 ) [log(1 − 𝐷 𝑤 (H𝑖ℓ , Â𝑖 )] − 𝜆𝐺 𝐻 (𝜋). 𝑖

Detailed optimization steps are presented in Algorithm 1. For each iteration of Algorithm 1, the learner trajectories 𝜏 = {H𝑖ℓ , A𝑖 } pair CSI available to the router with the corresponding online perturbations A𝑖 that the policy function 𝜋𝜃𝑘 (·|H𝑖ℓ ) generates. The discriminator and policy functions are alternately optimized using these learner and expert trajectories. In line 3, the discriminator function parameters, 𝑤,

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim TX TX

Algorithm 1: Training the online perturbation generator using GAIL

33mm TX TX

Data: Expert trajectories 𝜏𝐸 = {H𝑖ℓ , Â𝑖 } where 𝑖 = {1, 2, · · · , 𝑀 }, initial parameters for discriminator 𝑤 0 and policy function 𝜃 0 1 for 𝑘 = 0, 1, · · · , 𝐾 − 1 do 2 Sample trajectories using the learner policy 𝜏𝑘 ∼ 𝜋𝜃𝑘 (A𝑖 |H𝑖ℓ ); 3 Update discriminator parameters to increase the objective: 𝑤𝑘+1 ← 𝑤𝑘 + ∇𝑤𝑘 𝐽 (𝑤𝑘 ) (5) 4 Update policy function parameters to decrease the objective: 𝜃 𝑘+1 ← 𝜃 𝑘 − ∇𝜃𝑘 𝐾 (𝜃 𝑘 ) (6) 5 end Output: Trained policy network 𝜋𝜃 𝐾 (A𝑖 |H𝑖ℓ ) that generates online perturbations

+E ( H ℓ ,Â𝑖 ) [∇𝑤 log(1 − 𝐷 𝑤 (H𝑖ℓ , Â𝑖 ))]. 𝑖

TX TX RX RX

7.6 7.6m m

(a) TAR 22mm

RX RX

11mm

TX TX

TX

RX

RX RX

(b)22mmJAR

33mm

RX RX

TX TX

10.1 m

5.44 5.44 m m

4.7 4.7mm RX RX

(c) RUAR

22mm

Figure 3:RXRXData collection environments. TX TX 1.5 1.5mm

22mm

RX RX

(a) RUAR environment.

(b) USRP X310 SDR devices.

Figure 4: Our experimental measurement setup (RUAR).

are updated using the gradient: ∇𝑤 𝐽 (𝑤) = E ( H𝑖ℓ ,A𝑖 )∼𝜋𝜃 [∇𝑤 log(𝐷 𝑤 (H𝑖ℓ , A𝑖 ))] 𝑘

TX TX

achieve this goal, the perturbation must satisfy: h𝑘𝑖𝑗 (𝑥𝑖𝑘𝑗 + b𝑘𝑖𝑗 )/𝑥𝑖𝑘𝑗 = (h𝑘𝑖𝑗 + a𝑘𝑖𝑗 ) ⇒ a𝑘𝑖𝑗 = h𝑘𝑖𝑗 b𝑘𝑖𝑗 /𝑥𝑖𝑘𝑗 .

(5)

Line 4 describes the policy gradient, which minimizes the cost function evaluated on learner trajectories while maximizing the regularizer to encourage exploration,

(7)

However, when 𝑁 RX > 1, an exact solution for b𝑘𝑖𝑗 may not exist. Thus, we project the online perturbation a𝑘𝑖𝑗 onto 𝑘

the feasible space, yielding b̄𝑖 𝑗 : b̄𝑖 𝑗 = arg min ||h𝑘𝑖𝑗 b𝑘𝑖𝑗 /𝑥𝑖𝑘𝑗 − a𝑘𝑖𝑗 || = 𝑥𝑖𝑘𝑗 (h𝑘𝑖𝑗 · a𝑘𝑖𝑗 )/||h𝑘𝑖𝑗 || 2 . (8) 𝑘

∇𝜃 𝐾 (𝜃 ) = E𝜏𝑖 [∇𝜃 log 𝜋𝜃 (A𝑖 |H𝑖ℓ )𝐶 (H𝑖ℓ , A𝑖 )] − 𝜆𝐺 ∇𝜃 𝐻 (𝜋𝜃 ), (6)

where cost function 𝐶 (H𝑖ℓ , A𝑖 ) = E𝜏𝑘 [log(𝐷 𝑤𝑘+1 (H𝑖ℓ , A𝑖 ))]. As 𝐶 (H𝑖ℓ , A𝑖 ) depends on policy through the sampled trajectory 𝜏𝑘 , computing ∇𝜃 𝐾 (𝜃 ) is non-trivial. As in GAIL, we use trust region policy optimization (TRPO) [36] (Appendix A).

6

Multi-Antenna LTF Manipulation

When an HAR device has multiple antennas (i.e., 𝑁 RX > 1), manipulating a single LTF from a router affects CSI estimation at all receiver antennas, making it impossible to arbitrarily adjust multiple CSIs through a single LTF modification. However, the online perturbation A𝑖 from GAIL (§5.2) is designed to adjust each receiver antenna’s CSI independently, creating dimension mismatch with the LTF symbols; thus it cannot be added directly. To overcome this limitation, we design a multi-antenna LTF manipulation scheme based on projection, which generates the transmit perturbation signal B𝑖 by projecting A𝑖 onto a one-dimensional subspace spanned by the SIMO channel vector. This projection finds the LTF perturbation whose resulting CSI estimate is as close as possible to the target, i.e., the sum of H𝑖 and A𝑖 . For the 𝑘-th antenna of the TX, the adversary adds perturbation, b𝑘𝑖𝑗 ≜ [B𝑖 ] 𝑗𝑘 ∈ R, to LTF, 𝑥𝑖𝑘𝑗 ∈ R, at 𝑖-th time step, 𝑗-th subcarrier. The goal is to make the router misestimate the original CSI, h𝑘𝑖𝑗 ∈ R𝑁RX as h𝑘𝑖𝑗 + a𝑘𝑖𝑗 , where a𝑘𝑖𝑗 ∈ R𝑁RX is the corresponding element of the output of GAIL, A. To

b𝑘𝑖𝑗 𝑘

b̄𝑖 𝑗 is then added to the original LTF, and the router antenna 𝑘

𝑘 transmits the manipulated LTF 𝑥𝑖𝑘𝑗 + b̄𝑖 𝑗 . We experimentally validate this in §8.3, where GRAW achieves comparable performance to the ideal case (LTF-oracle) where a separate LTF is used for each TX-RX antenna pair. Since each TX antenna transmits an orthogonal LTF whose CSI is estimated separately at the RX, the projection in (8) applies independently per TX antenna, extending directly to MIMO.

7

Online Amplitude Adjustment

To regulate the impact on the communication link, GRAW scales the perturbation signals so their average amplitude ratio to the LTF meets a target 𝛾, while preserving the temporal power distribution of B̄𝑖 from the MIMO processing (§6). Since the future perturbation signals are unknown during online perturbation generation, we adjust the amplitudes of 𝑘 B̄𝑖 ≜ {b̄𝑖 𝑗 } 𝑗,𝑘 in Eq. (8) using only B̄ up to the current time step, B̄1:𝑖 = {B̄𝑚 }𝑚≤𝑖 . 𝛾 is chosen to balance attack strength and communication impact. B𝑖 = 𝛾 B̄𝑖 · ∥x1:𝑖 ∥/∥ B̄1:𝑖 ∥.

(9)

The rationale behind Eq. (9) is that ∥ B̄1:𝑖 ∥/∥x1:𝑖 ∥ reliably estimates the amplitude ratio over the entire activity. This estimator works effectively because B̄1:𝑖 exhibits a flat power

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

Table 2: Dataset parameters Dataset TAR JAR RUAR

Carrier Sampling {𝑁 TX , No. No. Eval. No. freq. Rate 𝑁 RX } Activities Envs. Days Participants (GHz) (Hz) 5 2.4 2.4

{1, 3} {1, 3} {2, 2}

6 6 5

1 3 1

8 1 3

6 30 6

1000 320 100

Table 3: Wi-Fi-based HAR classifiers

smaller ones shorten the covered duration and reduce attack performance. Human movement induces Doppler shifts of at most 30 Hz [21], with most activity-relevant energy concentrated at lower frequencies. Sampling in the tens-of-Hz range therefore retains the components needed for activity classification, which we confirm empirically in §8.3. Accordingly, we use 50 Hz for TAR and RUAR, and 40 Hz for JAR (an integer factor of its original 320 Hz rate). Hyperparameters for training the surrogate classifier (Table 5) and GAIL policy network (Table 6) are also summarized.

HAR model

Dataset

Input features

Classifier structure

Input length

Sampling rate (Hz)

Model A [52]

TAR

CSI

2s

500

8.2

Model B [5]

TAR

CSI

2s

500

Model C [17]

JAR

LSTM LSTM + Attention CNN + LSTM

1.6 s

1000

RF

1.6 s

1000

CNN Transformer

Variable 2s

100 100

We test three digital-attack schemes (classifier input manipulation) and two remote-attack schemes (LTF manipulation) as comparison schemes: WiCAM. WiCAM [51] is a digital attack that uses an attentionbased surrogate model [23] to select critical subcarriers and time steps, and applies FGM only on those positions. The surrogate expects fixed-length inputs, so CSI sequences for variable durations are resampled to fixed length. We set 𝑡 = 0.4, following the original paper’s recommendation. Black-box FGM. Black-box FGM perturbation  in Eq. (3) is computed using the surrogate model 𝑓C′ . Knowledge of full-activity CSI sequence is assumed. Universal FGM. Universal FGM is a single fixed perturbation per activity class by averaging black-box FGM perturbations  computed on the adversary’s training data [30]. All  are resampled to the longest activity duration before averaging, and the average perturbation is then resampled to the action length and used to generate the LTF perturbation. This attack does not require the full-activity CSI sequence, but does assume prior knowledge of the activity duration. For these black-box/universal FGM methods, we also test them for remote attacks but under unrealistic assumptions. C&W. C&W refers to the remote attack method based on the Carlini & Wagner scheme proposed in [24]. Since C&W only takes fixed-length sequences as input and does not consider the MIMO constraint (Table 1), we manually resample the CSI sequences and adapt them for the MIMO (or SIMO) environments using GRAW’s scheme (§6). Behavioral cloning. Behavioral cloning [41] is an IL-based remote-attack approach. Like GRAW, it uses black-box FGM computed on the recent CSI and the pairs, (H𝑖ℓ , Â𝑖 ). A BiLSTM classifier 𝑓BC (H𝑖ℓ ) is trained in a supervised learning manner (cf. GAIL in GRAW) using the pairs as inputs and labels and is deployed as an online perturbation generator. As in GRAW, behavioral cloning operates without knowledge of the target classifier, the new HAR CSI, or activity duration.

Model D [18]

JAR

Model E [53] Model F [27]

RUAR RUAR

CSI Statistical features STFT STFT

distribution over time, unlike the gradient-based attack (further discussed in §8.4). We also validate this in §8.3.

8 Evaluation 8.1 Datasets and Target Models We evaluate GRAW using two public datasets, TAR [52] and JAR [1], as well as a dataset we collect using SDR called RUAR. These datasets together span both 2.4 GHz (JAR, RUAR) and 5 GHz (TAR) Wi-Fi frequency bands. Table 2 summarizes the dataset specifications, and Figure 3 illustrates data collection environments, with floor plans sourced from the original dataset documents [1, 52]. JAR is collected across three distinct environments, including a non-line-ofsight (NLOS) scenario, and TAR spans eight days, enabling evaluations under both spatial and temporal diversity. RUAR: Our SDR-based dataset. RUAR uses a 2 × 2 MIMO setting, while TAR and JAR use 1 × 3 SIMO. Figure 3c and Figure 4 describe the environment where RUAR is measured. We deploy two SDRs, USRP X310, for both transmitting and receiving signals. We collect 1,440 activity samples from 6 volunteers over 3 different days. HAR classifiers. We assess GRAW against architectures matched to the surrogate (Bi-LSTM) and unmatched (CNN, attention, random forest, and transformer) in Table 3, assessing cross-architecture transferability. We further test classifiers taking either raw CSI or statistical features as input, including variance and SNR [18] or short-time Fourier transform (STFT) [53]. For TAR and JAR, we train the surrogate classifier and the online perturbation generator on the downsampled CSI. The downsampling lets a fixed input length ℓ cover a longer time duration. We heuristically set ℓ = 5 since larger values increase model complexity and degrade training stability, while

Comparison Schemes

8.3 Experimental GRAW Design Validations We validate design components of GRAW. We first introduce the evaluation metrics. We use attack success ratio (ASR) as

HAR Accuracy (%)

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim

100 80 JAR TAR RUAR

60 40

100 10 Sampling frequency (Hz)

1

(a) Surrogate model accuracy vs. (b) Perturbation signals for one "lie down" sample in the JAR dataset (GRAW vs. Oracle): ∥B𝑖 ∥ CSI sampling rate. vs. 𝛾 · ∥ B̄𝑖 ∥ over time (left); B1 vs. 𝛾 · B̄1 (middle); and B𝑀 vs. 𝛾 · B̄𝑀 (right) across subcarriers.

Attack Success Ratio (ASR) (%)

Figure 5: Experimental validation of GRAW’s design components: the surrogate model taking downsampled CSI sequences (we select 50, 40, and 50 Hz on TAR, JAR, and RUAR, respectively) in Figure 5a, while the real-time amplitude adjustment in Figure 5b. PSR stands for Perturbation-to-Signal Ratio. JAR (1#3 SIMO, 2.4 GHz)

100

RUAR (2#2 MIMO, 2.4 GHz)

75 50 GRAW LTF-Oracle

25 0 -20

-10 0 PSR (dB)

10 -20

-10 0 PSR (dB)

10

Figure 6: Validation of GRAW’s multi-antenna LTF manipulation scheme under SIMO and MIMO datasets. TAR (1#3 SIMO)

ASR (%)

100

JAR (1#3 SIMO)

RUAR (2#2 MIMO)

80 60 40 20 0 -20 GRAW

-10 0 PSR (dB) C&W

10 -20

Black-box FGM

-10 0 PSR (dB) Universal FGM

10 -20

-10 0 PSR (dB)

Behavioral cloning

10

Random noise

(a) ASR comparison with remote attacks. TAR (1#3 SIMO)

ASR (%)

100

JAR (1#3 SIMO)

RUAR (2#2 MIMO)

80 60 40 20 0 -20

-10 0 10 -20 -10 0 10 -20 PSR (dB) PSR (dB) GRAW (remote attack) WiCAM Black-box FGM

-10 0 10 PSR (dB) Universal FGM

(b) ASR comparison with digital attacks.

Figure 7: ASR (Attack Success Ratio) of HAR attacker schemes on the Bi-LSTM-based target classifier across PSRs under various datasets. Dotted lines highlight ASR that makes HAR accuracy random, i.e., accuracy 1/6 (TAR and JAR) and 1/5 (RUAR). Recall that, except for GRAW and behavioral cloning, all the attacker systems have impractical assumptions (§8.2). the main metric, along with the HAR accuracy. We define ASR = (𝐴0 − 𝐴)/𝐴0 , where 𝐴 and 𝐴0 denote the classifier accuracy with and without attack, respectively. We further

introduce perturbation-to-signal ratio (PSR), defined as the average amplitude ratio of perturbation |b𝑘𝑖𝑗 | to LTF |𝑥𝑖𝑘𝑗 | across all time steps, subcarriers, and TX antennas, to compare each attack method’s degrading efficiency. A desired attack scheme achieves higher ASR at lower PSR. Surrogate model. As the surrogate model is trained on downsampled CSI (§8.1), we first determine the downsampling rate by evaluating surrogate accuracy under different rates in Figure 5a. The surrogate accuracy deteriorates when the sampling rate is below 10 Hz. This confirms that our chosen rates, 50 Hz for TAR and RUAR and 40 Hz for JAR, are sufficient to maintain high accuracy. High surrogate accuracy is essential, as it indicates that the surrogate captures HARrelevant CSI features. The resulting perturbations transfer across diverse target architectures (§8.4). In our experiments, these models have 93% average surrogate accuracy across all three datasets (all surrogate accuracies >88% per activity), demonstrating that the Bi-LSTM-based structure can serve as a surrogate for generating reference perturbations. Multi-antenna LTF manipulation. We validate GRAW’s multi-antenna LTF manipulation, by comparing against an LTF-oracle, which assumes that each TX-RX antenna pair can use a separate LTF. Figure 6 plots their ASR across PSR with TAR (SIMO) and RUAR (MIMO) datasets. Gray lines in the figures represent ASR values needed to reduce the target system accuracy to random-selection level. GRAW achieves comparable ASR to that of the LTF-oracle across PSR in both SIMO and MIMO settings, with less than 1.9 dB and 0.1 dB PSR difference to achieve 50% ASR and to degrade the target classifier to random-selection accuracy, respectively, validating the multi-antenna manipulation design. Online amplitude adjustment. We test whether GRAW’s online amplitude adjustment mechanism (§7) ensures that the perturbation signals closely match their target amplitude ratio throughout the activity duration. The left panel of Figure 5b shows the vector norm of adjusted perturbation signals B𝑖 of Eq. (9) (GRAW), and the scaled output of Eq. (8) 𝛾 · B̄𝑖 , which is the desired result (Oracle). The middle and

ASR (%)

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

100 80 60 40 20 0 -10

TAR, Model A

-7 -3 PSR (dB)

TAR, Model B

0-10

-7 -3 PSR (dB) GRAW

C&W

JAR, Model C

0-10

-7 -3 PSR (dB)

Black-box FGM

JAR, Model D

0-10

-7 -3 PSR (dB)

Universal FGM

RUAR, Model E

0-10

-7 -3 PSR (dB)

Behavioral cloning

RUAR, Model F

0-10

-7 -3 PSR (dB)

0

Random noise

HAR accuracy (%)

(a) ASR comparison of remote attack schemes with unmatched classifier models (in Table 3). TAR (1#3 SIMO, 5 GHz), Model A (LSTM)

100

RUAR (2#2 MIMO, 2.4 GHz), Model E (CNN) Without attack GRAW C&W Behavioral cloning

50 0

"lie down"

"fall"

"run"

"sit down" "stand up"

"walk"

Activity

"walk"

"run"

"sit/stand"

"turn"

"still"

Activity

(b) HAR classification accuracy per activity with/without remote attacks (with -3 dB PSR) under TAR and RUAR datasets.

Figure 8: GRAW and comparative remote attack scheme results on various target classifiers, where surrogate classifier and HAR classifier models are unmatched (cf. both Bi-LSTM-based classifiers in Figure 7). right panels illustrate B𝑖 and 𝛾 · B̄𝑖 at first and last time step, respectively. Although they differ at the first time step due to insufficient history for the amplitude estimator, the two converge over time and become nearly identical at the last time step. This convergence is enabled by the flat temporal amplitude distribution of B̄𝑖 , which makes ∥ B̄1:𝑖 ∥/∥x1:𝑖 ∥ a reliable estimator of the amplitude ratio over the entire activity duration. Across all datasets, GRAW’s online adjustment yields an average mismatch between B1:𝑀 and 𝛾 B̄1:𝑀 of less than 5% over the activity duration (TAR: 3.5%, JAR: 4.9%, RUAR: 3.8%). This indicates that the amplitude adjustment effectively approximates the perturbation scaled by the target amplitude using only recent CSI.

8.4

Adversarial Attack Performance

Figure 7a shows the ASR under various remote attack schemes, including GRAW. The target model employs an identical Bi-LSTM architecture and sampling rate as the surrogate, representing a matched model scenario. Gray lines indicate the ASR at which the target classifier is degraded to randomselection accuracy, as in Figure 6. Across all datasets, GRAW achieves performance comparable to or better than the comparison methods, despite its zero-knowledge operation. Notably, in TAR, GRAW reaches 50% and 80% ASR with 2 dB and 11 dB lower PSR, respectively, than the second-best scheme. The ASR compared to digital attack schemes is plotted in Figure 7b. Across all the datasets, GRAW matches the accuracy degradation of digital attacks with a comparable PSR, requiring 1.6 dB and 1.9 dB higher PSR for 50% and 80% ASR in the worst cases, respectively. These results are notable, given that GRAW operates entirely OTA, without the new HAR CSI access that digital attacks require.

Cross-Model Evaluation. We also test GRAW’s transferability to target architectures that differ from its Bi-LSTM surrogate. In Figure 8a, GRAW consistently delivers the highest or near-highest ASR across all PSR values. While C&W occasionally approaches GRAW (e.g., Model C), but is unstable elsewhere. Universal FGM shows similar inconsistency, occasionally matching GRAW (e.g., Model E) but often collapsing (e.g., Model F), as its fixed per-class perturbation cannot adapt to the target. GRAW remains effective against attention-based architectures—the attention model (Model B) and the Transformer (Model F)—achieving the highest ASR especially at low PSR, despite using only a Bi-LSTM surrogate. Overall, the results highlight the robustness of GRAW across diverse HAR models, maintaining strong performance. We further analyze per-activity accuracy for GRAW, behavioral cloning, and C&W in Figure 8b. Interestingly, the impact of perturbation varies substantially across activities. For example, against Model A, perturbations with a PSR of -3 dB drive the accuracy on “fall” data nearly to 0%, while the accuracy on “run” data drops far less. In RUAR, most perturbed CSI sequences are misclassified as “turn”, revealing that perturbations tend to drive the classifier toward a dominant decision region. Even so, the average accuracy across activities falls to the random-selection level. This activitydependent vulnerability suggests that GRAW could be further strengthened by adaptively tuning the PSR per activity. The efficiency of GRAW across diverse target model structures is attributed to the temporal distribution of perturbation signal power. To analyze this, we compute the perturbation amplitude ratio per time step 𝑟𝑖 , averaging |𝑏𝑖𝑘𝑗 |/|𝑥𝑖𝑘𝑗 | over subcarrier 𝑗 and TX antenna 𝑘. Figure 9 illustrates 𝑟𝑖

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim Train: LOS!Test: NLOS

PSR (dB)

10

Train: NLOS!Test: LOS

GRAW C&W Black-box FGM Universal FGM Behavioral cloning

5 0 -5

50%

80%

50%

ASR

(b) “turn” data in JAR

Figure 9: Required PSR over time (𝑟𝑖 ) to reduce Bi-LSTM classifier HAR accuracy to a random-selection level. Compared to other designs, GRAW requires relatively consistent and low PSRs (§7). over time for one “stand up” sample in TAR and “turn” sample in JAR under PSR values configured to degrade the target HAR accuracy to random-selection level. GRAW and behavioral cloning generate flatter and more consistent amplitude distributions than other methods, as they produce outputs based only on the past ℓ steps and thus cannot significantly amplify specific temporal segments. In contrast, the other methods compute their perturbations by processing the CSI over entire activity at once, making them concentrate perturbation power on critical time steps (e.g., universal FGM at 40 ≤ 𝑖 ≤ 60 in Fig. 9a). Target classifiers such as [5, 17] in Table 3 may take only time indices with low amplitudes (e.g., black-box FGM at 75 ≤ 𝑖 ≤ 125 in Fig. 9b) as input, thereby diminishing attack effectiveness. However, the flat power distribution of GRAW avoids this limitation, efficiently degrading target HARs regardless of their input timing. Cross-Environment Evaluation. Figure 10 reports the PSR values needed to degrade the target classifier accuracy to 50% and random-selection level ASR (80% for line-of-sight (LOS)→NLOS, 75% for NLOS→LOS) when training and test environments differ on the JAR dataset. When the surrogate is trained on LOS and tested on NLOS (Fig. 3b), GRAW achieves both ASR targets with PSR comparable to black-box FGM. By contrast, C&W and universal FGM, which apply perturbations computed on training data without adaptation, require over 5 dB PSR to reach random-selection level ASR. In the reverse NLOS→LOS setting, GRAW reaches the 75% ASR at -3 dB PSR, whereas behavioral cloning needs 3 dB. This robustness stems from GAIL’s distribution matching, which generalizes better than behavioral cloning’s pointwise state-action fitting (§5.2).

8.5

Impact on Data Communication Link

Since communication is the primary goal of Wi-Fi, the transmit perturbation signal aims to degrade the classifier without disrupting communication. This subsection evaluates GRAW’s impact on communication performance. Note that

Figure 10: Cross-environment evaluations with required PSR to degrade Bi-LSTM classifier HAR accuracy to ASR (50%, 80% (LOS → NLOS), 75% (NLOS → LOS)) on the JAR dataset. Throughput (Mbps)

(a) “stand up” data in TAR

75%

ASR

TAR (1#3 SIMO, 5 GHz) 20 10 0

RUAR (2#2 MIMO, 2.4 GHz)

GRAW C&W Black-box FGM Universal FGM Behavioral cloning

5

20

SNR (dB)

5

20

SNR (dB)

Figure 11: Estimated throughput across SNRs of WiFi data communication under attacker systems with TAR and RUAR datasets, where PSR is set to degrade the target classifier to random-selection level. Spatial diversity MIMO is used. measured bit error rate (BER) and packet success rate results appear in §8.6, as measuring them requires payload transmission (beyond channel datasets in TAR and JAR). Even at the same PSR, different perturbation amplitude distributions can lead to different effects on the link. To capture this, we quantify the interference using estimated throughput based on per-subcarrier signal-to-perturbation-and-noise ratio (SPNR) over time, 𝑟¯𝑖 𝑗 , assuming maximum ratio transmission (MRT) and maximum ratio combining (MRC) for TX and RX sides, respectively, as follows. First, we compute 2 SPNR under a chosen SNR, 𝑟𝑖𝑘𝑗 = |𝑥𝑖𝑘𝑗 | 2 /(|𝑏𝑖𝑘𝑗 | + |𝑛𝑘𝑖𝑗 | 2 ), where 𝑛𝑘𝑖𝑗 depends on the SNR. Next, we sum 𝑟𝑖𝑘𝑗 across TX antennas 𝑘 in the linear domain and add 10 log10 (𝑁 RX ) to account for receiver diversity. Then, we map the resulting SPNR, 𝑟¯𝑖 𝑗 , to the highest modulation and coding scheme (MCS) supported, according to the Wi-Fi standard table [16]. Figure 11 shows the average estimated throughput, when PSR is set to degrade the target classifier to random-selection level. In TAR, GRAW achieves the highest estimated throughput, as it requires smaller PSR than other schemes. At 5 dB SNR, black-box and universal FGM nearly eliminate data communication, with throughput approaching 0 Mbps. In RUAR, GRAW achieves lower throughput than black-box and universal FGM because GRAW requires a higher PSR to reach random-selection level in this dataset. Nevertheless, GRAW still outperforms C&W and behavioral cloning, which do not assume full-activity CSI sequence.

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

Table 4: Estimated power consumptions

Figure 12: CDF of per-subcarrier PSR values over time required to degrade the target classifier to randomselection level. The vertical dashed lines indicate PSR thresholds for reliable Wi-Fi communication without MRC (gray) and with MRC (black).

Figure 12 shows the CDF of per-subcarrier PSR values over time. The gray (left) and black vertical dashed lines (right) indicate PSR thresholds for reliable communication without and with MRC, respectively; green and red regions indicate reliable and unreliable zones. Perturbations whose PSR exceeds these thresholds disrupt link availability due to the channel distortion. With MRC, GRAW keeps all persubcarrier PSR values below the threshold (0.0%) in both datasets, while C&W and behavioral cloning exceed it by 52.5%/19.7% and 43.6%/44.2%, respectively; without MRC, GRAW still maintains a lower fraction than competing schemes. This stems from two factors: GRAW’s smaller PSR (Fig. 7a) and its flatter amplitude distribution (Fig. 9), which avoids spikes that push per-subcarrier PSR above the threshold.

8.6

Real-Time Over-the-Air Experiments

We also evaluate GRAW on SDRs in a real-time, OTA manner to demonstrate its deployment feasibility. We implement the inference stage as an out-of-tree GNU Radio [8] block in C++, given that training is performed offline. The block performs channel estimation from received LTF signals, computes the perturbation using the trained policy network, and transmits the modified LTF in real-time on our SDR platforms (RUAR). The inference latency of 0.6 ms on CPUs is well below the 20 ms sampling period, confirming hardware timing feasibility without any modifications. Attack performance. The upper panel of Figure 13a shows that the real-time demo follows a similar trend to offline processing across PSR values. In particular, at low PSR, the real-time demo achieves higher ASR than offline processing. Minor differences arise from analog and PHY effects in the RF pipeline (e.g., DAC non-linearities, CFO) absent in offline processing. Understanding how RF chains affect perturbation may provide insights for future perturbation designs. Impact on data communication link: BER and packet success rate. The lower panel of Figure 13a shows BER and packet success rate measured in a spatial multiplexing MIMO environment. At PSR = -4 dB and -3 dB, GRAW achieves over

Power consumption

GRAW

Behavioral cloning

C&W

Black-box FGM

Universal FGM

WiCAM

(mW)

11

10

0.73

560

30

1140

50% ASR while maintaining a 99.7% and 96.3% packet success rate, respectively, confirming its minimal degradation on regular Wi-Fi data communications. With the diversity gain from MRT and MRC, this reliability extends to higher perturbation levels (PSR = 2 dB), beyond the point where GRAW already reaches the random-selection level (PSR = -2 dB). Interestingly, at PSR = -4 dB and -3 dB, the measured BER of 3 × 10−4 and 6 × 10−4 would suggest a much lower packet success rate than the observed 99.7% and 96.3% if the errors were uniformly distributed over 1000-byte (8000-bit) packets. We found that this discrepancy arises because perturbation signals corrupt channel estimation, causing error bits to concentrate in specific packets, as shown in Figure 13b. While most packets are zero-error, the remaining packets suffer severe channel estimation errors, and thus most of their following data payload bits are in error. This is directly observed in the figure with rapid drops in the CCDF around 3700–4000 bit errors out of 8000 bits (Fig. 13b). Power Consumption. We evaluate GRAW’s power consumption (§5.2, §6, and §7) via FLOP analysis. Generating a perturbation signal for one LTF requires 2.2 × 105 FLOPs, or 1.1 × 108 FLOPs/s at the 50 Hz update rate. Assuming an energy of ≈ 0.6 pJ/FLOP for an RTX-4080Ti GPU [32] and ≈ 0.9 nJ/FLOP for a Cortex-A53 CPU [42], commonly used in commodity Wi-Fi routers, the additional power cost is about 0.067 mW on the GPU and 0.1 W on the CPU, below 1% of the maximum power consumption of the GPU and a commodity Wi-Fi router, 450 W and 12 W. Table 4 summarizes the estimated power consumption of GRAW and comparison schemes. GRAW consumes only 11 mW, comparable to behavioral cloning. Gradient-based methods that compute perturbations at runtime (Black-box FGM and WiCAM) require far more power (560 and 1140 mW), while Universal FGM (30 mW), which reuses precomputed per-class perturbations, and C&W (0.73 mW) remain low. Memory footprint. The perturbation generator is a fourlayer MLP with 0.19–0.33 M parameters, occupying 0.7–1.3 MB in FP32, a small fraction of the RAM on commodity APs (typically tens to hundreds of MB). Thus GRAW fits comfortably alongside routing and NAT tables.

9

Discussion

Practical deployments. PHY-level operations such as LTF manipulation are inaccessible on commodity Wi-Fi chipsets; even open-source Wi-Fi router firmware (e.g., OpenWRT [33], DD-WRT [6]) does not expose them. We therefore envision chipset and router vendors natively integrating GRAW into

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim #2 MIMO, 2.4 GHz) RUAR (2#

100

/ /

75

25

/ /

0 1

/ / / /

0.8 0.6

0

-20

-15

-10

10

-1

10 -3 10

/ /

0.2

0

-2

BER Packet success rate

0.4

10

/ /

-5

-4

-3

-2

-1

0

10

-4

10

-5

ASR (%)

Real-time Demo Offline processing

50

PSR (dB)

(a) ASR, BER, and packet success rate across PSRs.

CCDF

100

PSR = -4dB

10-1 10-2

PSR = -2dB

-1

10

10-3 10-4

PSR = -3dB

-2

10

0

0

20

40

1000

2000 3000 4000 No. of error bits (b) Per-packet BER distribution. Most of the errors are observed in specific packets (i.e., burst error).

Figure 13: OTA, real-time demonstration of GRAW under spatial multiplexing MIMO, measured under RUAR setting in Figure 4. their products as a privacy-protection feature. Although this vendor-level integration may appear to limit immediate deployability, this constraint is appropriate for our privacy objective. The PHY-level security functionality should remain within the trusted router hardware; exposing it to untrusted user-space software or external devices could introduce another privacy and security risk. Unlike denial-of-service jamming [25], GRAW modifies only the router’s own transmission without blocking other devices’ channel access. Opportunistic operation. GRAW has reduced the negative impact on the communication link, but its perturbations noticeably degrade link quality for high ASRs. Therefore, the GRAW active duration should be minimized; it should operate only opportunistically rather than continuously, for example, by activating perturbations only when a malicious user device running a HAR application is detected. However, such detection is currently infeasible, as HAR runs entirely within the user device. Still, one might approximate the unauthorized HAR activity state, e.g., monitoring indirect signals such as periodic CSI-request patterns. Given the growing importance of privacy in Wi-Fi HAR, automated detection of unauthorized HAR will become increasingly essential. Furthermore, the co-existence of legitimate and malicious devices would present an interesting scenario. In such mixed environments, the router must target only malicious HAR while avoiding unnecessary degradation for legitimate HAR devices. We will explore these challenges in our future work.

Adversarial training

PCA filtering

80 60 40 20 0 -20

BER

Packet success rate

ASR (%)

100

GRAW

-10 0 PSR (dB) C&W

10 -20

Black-box FGM

-10 0 PSR (dB)

Universal FGM

10

Behavioral Cloning

Figure 14: ASR across PSR against a Bi-LSTM-based HAR classifier with defense systems (adversarial training and PCA filtering) on the TAR dataset. Robustness against defense algorithms. Recently, defense systems against adversarial attacks have also emerged, generally aiming to either mitigate or withstand (malicious) perturbations. In this context, we also test GRAW against two representative defense mechanisms, adversarial training [22] and principal component analysis (PCA) based defense [2]. As shown in Figure 14, under adversarial training, GRAW outperforms behavioral cloning and C&W. Under the PCA filtering, however, behavioral cloning achieves the highest ASR, while GRAW experiences a larger drop in ASR. We will explore advanced GRAW designs in our future work, targeting malicious HAR devices with such defense systems. Other possible applications. Beyond Wi-Fi HAR, remote adversarial attacks have been explored in various neural network–based wireless applications. Perturbation signals are designed to attack DL-based modulation classification [45], autoencoder-based decoders [3], device-identification systems, and DL-based indoor localization [26]. However, these methods [45, 48] often assume perfect synchronization between the adversary’s and the target system’s inputs, making the practical deployment infeasible. Therefore, the GRAWbased approach can be adapted and applied to these applications, to enable the adversarial attacks without requiring synchronization (or any information on the target system).

10

Conclusion

This paper presents GRAW, a remote adversarial attacker system against Wi-Fi-based HAR. To our best knowledge, this is the first application of GAIL to remote adversarial attacks against Wi-Fi HAR and thus completely eliminates the need for information on the target HAR systems. GRAW also resolves a constraint in multi-antenna environments and maintains a consistently low perturbation signal power, thus minimizing its negative impact on regular Wi-Fi data communication at the same time. Given the impressive performances observed, we believe this GAIL-based zero-knowledge adversarial attack approach is worth exploring further, not just for Wi-Fi HAR, but also for a variety of applications such as mmWave radar and wireless indoor localization.

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

References [1] Alsaify Baha’A, Mahmoud M Almazari, Rami Alazrai, and Mohammad I Daoud. 2020. A dataset for Wi-Fi-based human activity recognition in line-of-sight and non-line-of-sight indoor environments. Data in Brief 33 (2020), 106534. doi:10.1016/j.dib.2020.106534 [2] Arjun Nitin Bhagoji, Daniel Cullina, Chawin Sitawarin, and Prateek Mittal. 2018. Enhancing robustness of machine learning systems via data transformations. In 2018 52nd Annual conference on information sciences and systems (CISS). IEEE, 1–5. [3] Jung-Woo Chang, Ke Sun, Nasimeh Heydaribeni, Seira Hidano, Xinyu Zhang, and Farinaz Koushanfar. 2023. Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems. arXiv preprint arXiv:2311.00207 (2023). doi:10.48550/ arXiv.2311.00207 [4] Yogita Chapre, Aleksandar Ignjatovic, Aruna Seneviratne, and Sanjay Jha. 2014. Csi-mimo: Indoor wi-fi fingerprinting system. In Proc. IEEE LCN. IEEE, 202–209. doi:10.1109/LCN.2014.6925773 [5] Zhenghua Chen, Le Zhang, Chaoyang Jiang, Zhiguang Cao, and Wei Cui. 2018. WiFi CSI based passive human activity recognition using attention based BLSTM. IEEE Trans. Mobile Comput. 18, 11 (2018), 2714–2724. doi:10.1109/TMC.2018.2878233 [6] DD-WRT. 2025. DD-WRT. https://dd-wrt.com/ [7] Shuya Ding, Zhe Chen, Tianyue Zheng, and Jun Luo. 2020. RF-net: A unified meta-learning framework for RF-enabled one-shot human activity recognition. In Proc. ACM Sensys. 517–530. doi:10.1145/3384419. 3430735 [8] GNU Radio 2025. GNU Radio. Retrieved Sept. 3, 2025 from https: //gnuradio.org [9] Yuan Gong, Boyang Li, Christian Poellabauer, and Yiyu Shi. 2019. Realtime adversarial attacks. In Proc. IJCAI. 4672–4680. doi:10.24963/ijcai. 2019/649 [10] Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In Proc. ICLR. doi:10.48550/arXiv.1412.6572 [11] Linlin Guo, Lei Wang, Chuang Lin, Jialin Liu, Bingxian Lu, Jian Fang, Zhonghao Liu, Zeyang Shan, Jingwen Yang, and Silu Guo. 2019. Wiar: A public dataset for wifi-based activity recognition. IEEE Access 7 (2019), 154935–154945. doi:10.1109/ACCESS.2019.2947024 [12] Daniel Halperin, Wenjun Hu, Anmol Sheth, and David Wetherall. 2011. Tool release: Gathering 802.11 n traces with channel state information. ACM SIGCOMM Computer Communication Review 41, 1 (2011), 53–53. doi:10.1145/1925861.1925870 [13] Jonathan Ho and Stefano Ermon. 2016. Generative adversarial imitation learning. Proc. NeurIPS 29 (2016). doi:10.48550/arXiv.1606.03476 [14] Jingyang Hu, Hongbo Wang, Tianyue Zheng, Jingzhi Hu, Zhe Chen, Hongbo Jiang, and Jun Luo. 2023. Password-stealing without hacking: Wi-Fi enabled practical keystroke eavesdropping. In Proc. ACM CCS. 239–252. [15] Pei Huang, Xiaonan Zhang, Sihan Yu, and Linke Guo. 2021. IS-WARS: Intelligent and stealthy adversarial attack to wi-fi-based human activity recognition systems. IEEE Trans. Dependable and Secure Comput. 19, 6 (2021), 3899–3912. doi:10.1109/TDSC.2021.3110480 [16] IEEE 802.11be. 2024. Part 11: Wireless LAN medium access control (MAC) and physical layer (PHY) specifications amendment 2: enhancements for high-efficiency WLAN. [17] Md Shafiqul Islam, Mir Kanon Ara Jannat, Mohammad Nahid Hossain, Woo-Su Kim, Soo-Wook Lee, and Sung-Hyun Yang. 2022. STCNLSTMNet: an improved human activity recognition method using convolutional neural network with NLSTM from WiFi CSI. Sensors 23, 1 (2022), 356. doi:10.3390/s23010356

[18] Mir Kanon Ara Jannat, Md Shafiqul Islam, Sung-Hyun Yang, and Hui Liu. 2023. Efficient Wi-Fi-based human activity recognition using adaptive antenna elimination. IEEE Access (2023). doi:10.1109/ACCESS. 2023.3320069 [19] Pritam Khan, Bathula Shiva Karthik Reddy, Ankur Pandey, Sudhir Kumar, and Moustafa Youssef. 2020. Differential channel-stateinformation-based human activity recognition in IoT networks. IEEE Internet of Things J. 7, 11 (2020), 11290–11302. doi:10.1109/JIOT.2020. 2997237 [20] Byungjun Kim, Amogh Panchagatti, and Peter Gerstoft. 2025. Realtime Adversarial Attack to Deep Learning-based Wi-Fi Human Activity Recognition. In 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1–5. [21] Youngwook Kim and Hao Ling. 2009. Human activity classification based on micro-Doppler signatures using a support vector machine. IEEE Trans. Geosci. Remote Sens. 47, 5 (2009), 1328–1337. doi:10.1109/ TGRS.2009.2012849 [22] Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016). [23] Bing Li, Wei Cui, Wei Wang, Le Zhang, Zhenghua Chen, and Min Wu. 2021. Two-stream convolution augmented transformer for human activity recognition. In Proceedings of the AAAI conference on artificial intelligence, Vol. 35. 286–293. [24] Changming Li, Mingjing Xu, Yicong Du, Limin Liu, Cong Shi, Yan Wang, Hongbo Liu, and Yingying Chen. 2024. Practical Adversarial Attack on WiFi Sensing Through Unnoticeable Communication Packet Perturbation. In Proc. ACM MobiCom. 373–387. [25] Jianwei Liu, Yinghui He, Chaowei Xiao, Jinsong Han, and Kui Ren. 2023. Time to think the security of WiFi-based behavior recognition systems. IEEE Trans. on Dependable and Secure Comput. (2023). doi:10. 1109/TDSC.2023.3261328 [26] Zikun Liu, Changming Xu, Emerson Sie, Gagandeep Singh, and Deepak Vasisht. 2023. Exploring practical vulnerabilities of machine learningbased wireless systems. In Proc. USENIX NSDI. 1801–1817. https: //www.usenix.org/conference/nsdi23/presentation/liu-zikun [27] Fei Luo, Salabat Khan, Bin Jiang, and Kaishun Wu. 2024. Vision transformers for human activity recognition using WiFi channel state information. IEEE Internet of Things Journal 11, 17 (2024), 28111– 28122. [28] Gian Marti and Christoph Studer. 2023. Universal MIMO jammer mitigation via secret temporal subspace embeddings. In 2023 57th Asilomar Conference on Signals, Systems, and Computers. IEEE, 309– 316. [29] Francesca Meneghello, Michele Rossi, and Francesco Restuccia. 2022. DeepCSI: Rethinking Wi-Fi radio fingerprinting through MU-MIMO CSI feedback deep learning. In Proc. IEEE ICDCS. IEEE, 1062–1072. doi:10.1109/ICDCS54860.2022.00106 [30] Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. In Proc. IEEE CVPR. 1765–1773. doi:10.1109/CVPR.2017.17 [31] Muhammad Muaaz, Ali Chelli, Ahmed Abdelmonem Abdelgawwad, Andreu Català Mallofré, and Matthias Pätzold. 2020. WiWeHAR: Multimodal human activity recognition using Wi-Fi and wearable sensing modalities. IEEE Access 8 (2020), 164453–164470. doi:ACCESS. 2020.3022287 [32] NVIDIA. 2025. GeForce RTX 4080 SUPER and RTX 4080 Graphics Cards | NVIDIA. https://www.nvidia.com/en-us/geforce/graphics-cards/40series/rtx-4080-family/#specsmodal/ [33] OpenWRT. 2025. [OpenWrt] Welcome to the OpenWrt Project. https: //openwrt.org/ [34] Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft, Xinyu Zhang, Minsung Kim

using adversarial samples. arXiv preprint arXiv:1605.07277 (2016). doi:10.48550/arXiv.1605.07277 [35] Yue Qiao, Ouyang Zhang, Wenjie Zhou, Kannan Srinivasan, and Anish Arora. 2016. PhyCloak: Obfuscating sensing from communication signals. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16). 685–699. [36] John Schulman, Sergey Levine, Pieter Abbeel, Michael Jordan, and Philipp Moritz. 2015. Trust region policy optimization. In Proc. ICML. 1889–1897. doi:10.48550/arXiv.1502.05477 [37] John Schulman, Philipp Moritz, Sergey Levine, Michael Jordan, and Pieter Abbeel. 2015. High-dimensional continuous control using generalized advantage estimation. arXiv preprint arXiv:1506.02438 (2015). doi:10.48550/arXiv.1506.02438 [38] Biyun Sheng, Fu Xiao, Letian Sha, and Lijuan Sun. 2020. Deep spatial– temporal model based cross-scene action recognition using commodity WiFi. IEEE Internet of Things J. 7, 4 (2020), 3592–3601. doi:10.1109/ JIOT.2020.2973272 [39] Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013). [40] Xinyu Tong, Hao Li, Xiaohua Tian, and Xinbing Wang. 2021. Wi-Fi localization enabling self-calibration. IEEE/ACM Trans. Netw. 29, 2 (2021), 904–917. doi:10.1109/TNET.2021.3051998 [41] Faraz Torabi, Garrett Warnell, and Peter Stone. 2018. Behavioral cloning from observation. In Proc. IJCAI. 4950–4957. doi:10.24963/ ijcai.2018/687 [42] TP-Link. 2025. Archer AX-1800 | AX-1800 Duao-band Wi-Fi 6 Router | TP-Link. https://www.tp-link.com/us/home-networking/wifi-router/ archer-ax1800/ [43] Xuyu Wang, Xiangyu Wang, and Shiwen Mao. 2018. Deep convolutional neural networks for indoor localization with CSI images. IEEE Trans. Netw. Sci. Eng. 7, 1 (2018), 316–327. doi:10.1109/TNSE.2018. 2871165 [44] Yichao Wang, Yili Ren, Yingying Chen, and Jie Yang. 2022. Wi-mesh: A wifi vision-based approach for 3d human mesh construction. In Proc. ACM Sensys. 362–376. doi:10.1145/3560905.3568536 [45] Zhaowei Wang, Weicheng Liu, and Hui-Ming Wang. 2024. Wireless Universal Adversarial Attack and Defense for Deep Learning-Based Modulation Classification. IEEE Commun. lett. (2024). doi:10.1109/ LCOMM.2024.3355156 [46] Ronald J Williams. 1992. Simple statistical gradient-following algorithms for connectionist reinforcement learning. Machine learning 8 (1992), 229–256. doi:10.1007/BF00992696 [47] Wei Xi, Dong Huang, Kun Zhao, Yubo Yan, Yuanhang Cai, Rong Ma, and Deng Chen. 2015. Device-free human activity recognition using CSI. In Proc. ACM CSAR Workshop. 31–36. doi:10.1145/2820716.2820727 [48] Fei Xiao, Yong Huang, Yingying Zuo, Wei Kuang, and Wei Wang. 2023. Over-the-air adversarial attacks on deep learning Wi-Fi fingerprinting. IEEE Internet of Things J. 10, 11 (2023), 9823–9835. doi:10.1109/JIOT. 2023.3236314 [49] Yucheng Xie, Ruizhe Jiang, Xiaonan Guo, Yan Wang, Jerry Cheng, and Yingying Chen. 2023. Universal Targeted Adversarial Attacks Against mmWave-based Human Activity Recognition. In Proc. IEEE INFOCOM. IEEE, 1–10. doi:10.1109/INFOCOM53939.2023.10228887 [50] Yaxiong Xie, Zhenjiang Li, and Mo Li. 2015. Precise Power Delay Profiling with Commodity WiFi. In Proc. MobiCom (Paris, France). ACM, New York, NY, USA, 53–64. doi:10.1145/2789168.2790124 [51] Leiyang Xu, Xiaolong Zheng, Xiangyuan Li, Yucheng Zhang, Liang Liu, and Huadong Ma. 2022. WiCAM: Imperceptible Adversarial Attack on Deep Learning based WiFi Sensing. In Proc. IEEE SECON. 10–18. doi:10.1109/SECON55815.2022.9918564

[52] Siamak Yousefi, Hirokazu Narui, Sankalp Dayal, Stefano Ermon, and Shahrokh Valaee. 2017. A survey on behavior recognition using WiFi channel state information. IEEE Commun. Mag. 55, 10 (2017), 98–104. doi:10.1109/MCOM.2017.1700082 [53] Changsheng Zhang and Wanguo Jiao. 2023. Imgfi: A high accuracy and lightweight human activity recognition framework using csi image. IEEE Sensors J. (2023). doi:10.1109/JSEN.2023.3296445 [54] Jin Zhang, Fuxiang Wu, Bo Wei, Qieshi Zhang, Hui Huang, Syed W Shah, and Jun Cheng. 2020. Data augmentation and dense-LSTM for human activity recognition using WiFi signal. IEEE Internet of Things J. 8, 6 (2020), 4628–4641. doi:10.1109/JIOT.2020.3026732 [55] Wei Zhang, Siwang Zhou, Dan Peng, Liang Yang, Fangmin Li, and Hui Yin. 2020. Understanding and modeling of WiFi signal-based indoor privacy protection. IEEE Internet of Things J. 8, 3 (2020), 2000–2010. doi:10.1109/JIOT.2020.3015994 [56] Siwang Zhou, Wei Zhang, Dan Peng, Yonghe Liu, Xingwei Liao, and Hongbo Jiang. 2019. Adversarial WiFi sensing for privacy preservation of human behaviors. IEEE Commun. Lett. 24, 2 (2019), 259–263. doi:10. 1109/LCOMM.2019.2952844 [57] Yuxuan Zhou, Huangxun Chen, Chenyu Huang, and Qian Zhang. 2022. WiAdv: Practical and robust adversarial attack against WiFi-based gesture recognition system. Proc. ACM IMWUT 6, 2 (2022), 1–25. doi:10.1145/3534618 [58] Yanzi Zhu, Zhujun Xiao, Yuxin Chen, Zhijing Li, Max Liu, Ben Y Zhao, and Haitao Zheng. 2018. Et tu alexa? when commodity wifi devices turn into adversarial motion sensors. arXiv preprint arXiv:1810.10109 (2018).

A

TRPO detailed steps

Policy gradient aims to increase the probabilities of actions that yield higher returns along learner trajectories. The GAIL training process includes a policy gradient to align the policy function closely with expert trajectories. We implement trust region policy optimization (TRPO) as our policy gradient algorithm, which optimizes two key components; the policy function 𝜋 (A𝑖 |H𝑖ℓ ) and the value function, 𝑉 (H𝑖ℓ ). Following [36]. For value function estimation, we employ generalized advantage estimation (GAE) [37]. In 𝑘th iteration of GAIL, the detailed TRPO steps executed in line 4 in Algorithm 1 are as follows:

(1) Compute temporal difference (TD) error: 𝑉𝜙 𝛿𝑖 𝑘 = −𝐶 (H𝑖ℓ , A𝑖 ) + 𝛾𝑉𝜙𝑘 (H𝑖+1 ) − 𝑉𝜙𝑘 (H𝑖ℓ ) at all time steps 𝑖 ∈ {1, 2, · · · , 𝑀 } Í∞ 𝑉𝜙 (2) Compute advantage values: 𝐴ˆ𝑖 = 𝑙=0 (𝛾𝜆𝐺 )𝑙 𝛿𝑚+𝑙𝑘 at all time steps 𝑖 ∈ {1, 2, · · · , 𝑀 }

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based HAR for Privacy Protection

(3) Update the parameters 𝜙 of value function 𝑉𝜙 (H𝑖ℓ ) to decrease the objective, 𝐾 (𝜙): 𝜙𝑘+1 ← 𝜙𝑘 − ∇𝜙 𝐾 (𝜙) 𝐾 (𝜙) =

𝑀 ∑︁

||𝑉𝜙 (H𝑖ℓ ) − 𝑉ˆ𝑖 || 2

B

Neural network parameters

Table 5: Surrogate Bi-LSTM HAR classifier model parameters

𝑖=1

1 ∑︁ ||𝑉𝜙 (H𝑖ℓ ) − 𝑉ˆ𝑖 || 2 ≤ 𝜖𝐾 , 𝑀 𝑖=1 2𝜎 2 𝑀

subject to where 𝑉ˆ𝑖 =

∞ ∑︁

𝑀

𝛾 𝑙 𝑟𝑖+𝑙 and 𝜎 2 =

𝑙=0

1 ∑︁ ||𝑉𝜙𝑘 (H𝑖ℓ ) − 𝑉ˆ𝑖 || 2 . 𝑀 𝑖=1

(4) Update the parameters 𝜃 of policy function 𝜋𝜃 to decrease the objective, 𝐿𝜃𝑘 (𝜃 ): 𝜃 𝑘+1 ← 𝜃 𝑘 − ∇𝜃 𝐿𝜃𝑘 (𝜃 )

Parameter

Value

Parameter

Value

LSTM hidden layer dimension

200

Learning rate

1 × 10 −5

Loss function

Crossentropy

Epoch

400

Table 6: GAIL network parameters

𝜃𝑘 subject to KL divergence, 𝐷 KL (𝜋𝜃𝑘 , 𝜋𝜃 ) ≤ 𝜖𝜋 𝑀

where 𝐿𝜃𝑘 (𝜃 ) =

1 ∑︁ 𝜋𝜃 (A𝑖 |H𝑖ℓ ) ˆ 𝐴𝑖 𝑀 𝑖=1 𝜋𝜃𝑘 (A𝑖 |H𝑖ℓ )

𝜃𝑘 𝐷 KL (𝜋𝜃𝑘 , 𝜋𝜃 ) =

1 ∑︁ 𝐷 KL (𝜋𝜃𝑘 (·|H𝑖ℓ )||𝜋𝜃 (·|H𝑖ℓ )). 𝑀 𝑖=1

𝑁

Parameter

Value

Parameter

Value

Epochs Input length (ℓ) 𝜖𝐾 , 𝜖 𝜋 Discount factor (𝛾 )

4000

𝐷 𝑤 learning rate Hidden layer dimension No. hidden layers Policy regularizer coefficient (𝜆𝐺 )

2 × 10 −5

5 0.01 0.99

200 4 0.01

Record · ID 1028629 · SHA-256 0934fbfdb57bb2b2
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.