1
A Novel Framework for Transmitter Privacy in Integrated Sensing and Communication
arXiv:2604.16068v1 [eess.SP] 17 Apr 2026
Vaibhav Kumar, Member, IEEE, Ahmad Bazzi, Senior Member, IEEE, Christina Pöpper, Senior Member, IEEE, and Marwa Chafii, Senior Member, IEEE
Abstract—Integrated sensing and communication (ISAC) systems introduce new privacy risks, since an unintended sensing node may exploit the shared radio waveform to infer transmitterrelated information even when the communication payload itself remains secure. In this paper, transmitter privacy, defined here as limiting unauthorized inference of transmitter-related information through channel estimation, is investigated in a reconfigurable intelligent surface (RIS)-aided multi-antenna wireless system comprising a transmitter, a legitimate receiver, a malicious sensor, and a RIS. The malicious sensor is assumed to estimate the transmitter–sensor channel, and the acquired channel state information may subsequently be used for unauthorized sensing, inference, or related signal-processing tasks. To counter this threat, a privacy-oriented design is considered in which the transmitter employs a superposition-based signaling strategy combining a message-bearing signal and transmit-side artificial noise (AN), while the RIS is used to shape the propagation environment in a privacy-aware manner. The channel-estimation performance at the malicious sensor is first characterized under imperfect prior knowledge, and both the true and predicted mean-squareerror expressions are derived. Based on this characterization, a joint active–passive beamforming design problem is formulated to maximize the malicious sensor’s predicted channel-estimation error subject to a communication quality-of-service requirement, a transmit-power budget, and the unit-modulus constraints of the RIS. The resulting non-convex problem is addressed via a numerically efficient alternating optimization framework based on an augmented Lagrangian reformulation. Numerical results show that RIS-assisted propagation shaping can significantly impair unauthorized channel estimation compared to the nonRIS counterpart while maintaining reliable communication, and further reveal that the resulting privacy gains extend to a more direct sensing metric, namely the angle-of-arrival (AoA) estimation accuracy at the malicious sensor. Index Terms—Sensing-centric security, integrated sensing and communication (ISAC), reconfigurable intelligent surface (RIS), channel estimation
I. I NTRODUCTION NTEGRATED sensing and communication (ISAC) is emerging as an important architectural direction for future wireless networks, as it enables both data transmission and
I
Vaibhav Kumar, Ahmad Bazzi, and Marwa Chafii are with the Wireless Research Lab, Engineering Division, New York University Abu Dhabi (NYUAD), UAE. Ahmad Bazzi and Marwa Chafii are also with NYU WIRELESS, NYU Tandon School of Engineering, NewYork, USA (e-mail: [email protected]; [email protected]; [email protected]). Christina Pöpper is heading the Cyber Security & Privacy (CSP) Lab, Center for Cyber Security, Science Division, New York University Abu Dhabi (NYUAD), UAE (e-mail: [email protected]). This work was supported by the Center for Cyber Security through New York University Abu Dhabi Research Institute under Award G1104. The work of Marwa Chafii was also supported in part by Tamkeen under the Research Institute NYUAD grant CG017.
environmental sensing over a common radio platform [1]– [3]. Through the shared use of spectrum, infrastructure, hardware chain, and signaling resources, ISAC can improve spectrum utilization, reduce deployment cost, and support a broad range of emerging services, including localization and tracking, autonomous driving, industrial automation, smart environments, digital twins, and immersive extended-reality applications [4]. These advantages have attracted significant interest from academia and industry, and have positioned ISAC as a realistic design paradigm for next-generation wireless systems. This momentum is also reflected in the ongoing 3GPP Release 19 effort, where ISAC has entered formal study activities through TR 22.837 [5], service-level specification efforts through TS 22.137 [6], and channel modeling efforts in TR 38.901 [7]. More broadly, this indicates that future wireless networks may no longer treat sensing as a secondary function supported indirectly by communication, but instead as a native capability embedded into the network architecture. At the same time, however, such close integration also brings new concerns. When communication and sensing share the same radio interface, the transmitted and reflected signals may reveal much more information about users, devices, and the surrounding environment than in conventional communicationonly systems. Consequently, in addition to the performance gains enabled by ISAC, it becomes necessary to understand the security and privacy risks created by this tight coupling between communication and environmental inference. Recent research has begun to address the security challenges of ISAC from a physical-layer perspective [8], [9]. A first line of work focuses on secrecy-oriented secure ISAC design, including secure beamforming [10]–[12], artificial-noise (AN) injection [13]–[15], and secrecy-rate maximization [16], [17], where the objective is to protect confidential communication while maintaining the desired sensing and communication functionalities. The aforementioned direction has also been extended to reconfigurable intelligent metasurface (RIS)-assisted settings, where the programmable propagation environment is jointly optimized with the transmission design to enhance communication confidentiality [18]–[22]. In parallel, covert ISAC has also gained significant attention, where the objective is not merely to secure the message content but to conceal the very existence of communication from a warden [23]–[25]. Compared to conventional communication-only systems, security in ISAC has a fundamentally broader meaning, since it involves not only communication-centric security but also sensing-centric security. Communication-centric security follows the classical physical-layer security paradigm, where
2
the goal is to prevent an unintended receiver from decoding the confidential message. In ISAC, communication-centric security can be broadly achieved in two ways. When the eavesdropper is spatially separated from the sensing target, the transmitter may steer nulls toward the suspicious direction to degrade the received signal quality at the eavesdropper. When the eavesdropper coincides with the sensing target, the transmitter may instead inject strong interference or AN so as to impair message decoding at that node. However, such approaches are not sufficient for sensing-centric security, where the malicious node may not be interested in the communication message at all, but rather in performing channel estimation, parameter estimation, detection, localization, or other sensingrelated inference tasks. In this case, high interference or noise does not necessarily eliminate the sensing threat, and steering a null toward the malicious sensor may itself be infeasible, particularly when the transmitter has only a small number of antennas, as is typical for user devices. Therefore, unlike conventional physical-layer security, sensing-centric security in ISAC cannot be characterized solely through communication secrecy, and instead calls for dedicated designs that explicitly limit unauthorized sensing and inference. Encouragingly, a small but growing body of work have begun to move beyond communication-centric secrecy and toward sensing-centric security in ISAC. In particular, RISassisted target-obfuscation designs have been developed to protect a sensing region from an adversarial detector by jointly optimizing the transmit beamformer, RIS configuration, and RIS meta-atom assignment so as to reduce the detector’s sensing capability while preserving the intended communication and sensing functions [26]. In a related direction, transmitter location privacy has been investigated through beam-pattern obfuscation, where the angular power distribution observed by a sensing-capable receiver is deliberately reshaped so that a false direction appears dominant without nulling the lineof-sight component, thereby showing that privacy may be achieved through controlled obfuscation rather than pure suppression [27]. More recently, sensing-secure ISAC signaling has been proposed via ambiguity-function engineering, where artificial ghost targets are introduced into the unauthorized observer’s range profile to degrade its sensing performance without requiring prior knowledge of the observer’s channel state information (CSI) [28]. These works constitute important first steps toward sensingcentric security, since they explicitly recognize that unauthorized sensing may remain possible even when communication secrecy is preserved. Here, sensing-centric security refers to the broader objective of preventing, limiting, or degrading malicious sensing capabilities in ISAC systems, whereas sensing privacy more specifically concerns protecting sensitive information about legitimate entities from being inferred through sensing. In this paper, we use the term transmitter privacy to denote the ability of a transmitter to communicate while limiting an unauthorized sensing node’s ability to infer transmitterrelated information from the shared waveform, particularly through estimation of the transmitter–sensor channel and the downstream inference tasks enabled by that estimate, such as localization, tracking, or AoA inference. Under this definition, transmitter privacy is broader than transmitter location privacy,
which focuses only on concealing the transmitter position, and is also distinct from target obfuscation or waveformlevel sensing degradation, which primarily protect the sensed target or disrupt a particular sensing output. By contrast, the setting of interest here focuses on malicious channel estimation as a fundamental leakage mechanism, since an estimate of the transmitter–sensor channel can serve as an enabler for subsequent coherent processing, parameter inference, and environment-aware sensing tasks. Motivated by the above observations, this paper studies RISaided transmitter privacy in a multi-antenna wireless system with a legitimate receiver and a malicious sensing node. The malicious node is assumed to estimate transmitter-related channel information from the received waveform and use it for unauthorized sensing or inference. To impair such malicious estimation, we propose a privacy-oriented joint design of the transmit precoder and RIS reflection coefficients, where AN and RIS-assisted propagation shaping are exploited to degrade the sensing capability of the malicious node while guaranteeing reliable communication at the legitimate receiver. The resulting design problem is non-convex due to the coupling between active transmission and passive propagation control. An efficient alternating optimization (AO)-based approach is developed to solve it. The results show that the proposed RISaided design achieves clear transmitter-privacy gains compared with a non-RIS counterpart. The main contributions of this work are summarized as follows: 1) A RIS-aided framework for transmitter privacy is developed for a wireless system with a legitimate receiver and a malicious sensing node, where transmitter privacy is defined as limiting the unauthorized inference of transmitter-related information through malicious estimation of the transmitter–sensor channel. Within this framework, malicious channel estimation is treated as a fundamental leakage mechanism that can enable subsequent sensing and inference tasks, and transmitter privacy is operationalized through the deliberate degradation of such unauthorized channel estimation. 2) A privacy-oriented joint design problem is formulated for the transmit precoder and RIS reflection coefficients, with the objective of maximizing the malicious sensor’s predicted channel-estimation error while ensuring reliable communication at the legitimate receiver under a transmit-power budget and the unit-modulus constraints of the RIS. 3) To solve the resulting non-convex problem, an efficient AO-based algorithm is proposed for the joint design of active transmit signaling and passive RIS control, and its convergence and computational complexity are analyzed. 4) Numerical results demonstrate that RIS-assisted propagation shaping can significantly degrade unauthorized channel estimation relative to non-RIS benchmarks while preserving the desired communication performance, further illustrate the effects of key system parameters such as the RIS size, antenna configuration, observation length, transmit power, and prior mismatch, and show that the resulting privacy gains also manifest in degraded angleof-arrival (AoA) estimation at the malicious sensor.
3
The remainder of this paper is organized as follows. Section II presents the considered system model and introduces the channel-estimation framework at the malicious sensor, along with the adopted privacy metric and problem formulation. Section III develops the proposed AO-based design for the joint optimization of the transmit precoder and RIS reflection coefficients. Section IV provides numerical results to evaluate the privacy performance of the proposed scheme and to illustrate the impact of key system parameters. Finally, Section V concludes the paper. Notation: Bold uppercase and lowercase letters denote matrices and vectors, respectively. The set of all M × N complex-valued matrices is denoted by CM ×N , and the set of positive real numbers is denoted by R+ . For a matrix X, the transpose, Hermitian transpose, trace, determinant, Frobenius norm, and expectation are denoted by XT , XH , tr(X), det(X), ∥X∥F , and E{X}, respectively. The notation ∥ · ∥ denotes the Euclidean norm for vectors. The operator diag(x) returns a diagonal matrix whose main diagonal is formed by the entries of x, vecd (X) denotes the column vector formed by the diagonal entries of X, vec(X) denotes the column vector obtained by stacking the columns of X, unvecM ×N (x) denotes the inverse operation of vec(·) that reshapes x into an M × N matrix, and X ⊗ Y denotes the Kronecker product of X and Y. For a real-valued function f (·), the gradient with respect to a complex-valued variable h i ∂f (·) ∂f (·) ∂f (·) 1 X is defined as ∇X f (·) ≜ ∂X∗ = 2 ∂ℜ{X} + j ∂ℑ{X} , where X∗ denotes the complex conjugate of X, and ℜ{X} and ℑ{X} denote its real and imaginary parts, respectively. The operator d(·) denotes the differential of its argument. The Euclidean projection of x onto a feasible set X is defined as ΠX (x) ≜ argminx̃∈X ∥x̃ − x∥2 . II. S YSTEM M ODEL AND P ROBLEM F ORMULATION We consider the RIS-aided communication system shown in Fig. 1, which consists of a transmitter (A), a legitimate receiver (B), a malicious sensor (S), and an RIS (R).1 The numbers of antennas at A, B, and S are denoted by mA , mB , and mS , respectively, while the RIS is equipped with mR reflecting meta-atoms. The wireless channels corresponding to the A–B, A–S, A–R, R–B, and R–S links are denoted by HAB ∈ CmB ×mA , HAS ∈ CmS ×mA , HAR ∈ CmR ×mA , HRB ∈ CmB ×mR , and HRS ∈ CmS ×mR , respectively. In this system, A communicates with B, while S seeks to estimate the transmitter–sensor channel HAS , thereby enabling unauthorized sensing and inference about the transmitter. A. Transmit Signal Model The transmitter adopts a superposition-based signaling strategy that combines a message-bearing communication signal with a transmit-side AN component. Accordingly, the transmitted signal vector is expressed as x = Fc wc + Fs ws , (1) 1 For analytical tractability, this work restricts attention to a single legitimate receiver and a single malicious sensor; extensions to multi-user and multiattacker settings are left for future work.
Fig. 1. A typical RIS-aided communication system with a malicious sensor.
where wc ∈ Cmmin ×1 denotes the communication symbol vector, with 1 ≤ mmin ≤ min{mA , mB }, and Fc ∈ CmA ×mmin denotes the corresponding communication precoder. In addition, ws ∈ CmA ×1 denotes the transmit-side AN vector, and Fs ∈ CmA ×mA is its associated precoder. Notably, the dimensionality of Fs depends only on the transmitterside dimensions and is therefore independent of the sensor antenna configuration. We assume that E{wc } = E{ws } = 0, E{wc wcH } = Immin , E{ws wsH } = ImA , and E{wc wsH } = 0. Unless otherwise stated, we set mmin = min{mA , mB } for notational simplicity. The AN component is introduced to impair the sensor’s ability to estimate HAS accurately, thereby enhancing transmitter privacy. Since the AN signal is given by Fs ws and E{ws wsH } = I, its covariance is Fs FH s , which shows that the AN spatial covariance is optimized implicitly through the precoder Fs . Moreover, the dedicated AN precoder provides an additional spatial degree of freedom for RIS-assisted channel manipulation. In particular, by jointly designing Fs and the RIS reflection coefficients, the reflected interference can be spatially shaped and preferentially directed toward the sensor through the cascaded A–R–S link, while maintaining the desired communication performance at the legitimate receiver.
B. Communication Model Using (1), the received signal at B is given by yB = (HAB + HRB ΘHAR )x + nB = ZAB x + nB , (2) where Θ = diag(θ) denotes the RIS reflection matrix, and 2 nB ∼ CN (0, σB ImB ) denotes the additive white Gaussian noise (AWGN) vector at B. Moreover, the RIS reflectioncoefficient vector is modeled as θ = [θ1 , θ2 , . . . , θmR ]T ∈ CmR ×1 , where θκ = exp(jϕκ ) with ϕκ ∈ [0, 2π) denoting the phase shift induced by the κ-th RIS meta-atom, for all κ ∈ MR ≜ {1, 2, . . . , mR }. We assume that A has imperfect CSI for the A–B and R– b AB + ∆AB and B links.2 Specifically, we model HAB = H 2 This assumption is adopted for analytical tractability and to isolate the impact of RIS-assisted interference shaping and AN design. It is also standard in RIS-aided systems, since the A–R link can often be estimated more accurately through calibration and control signaling between the transmitter and the RIS controller, and its estimation errors are comparatively less critical to the communication-privacy trade-off considered in this work.
4
b RB + ∆RB , where H b AB and H b RB are the available HRB = H channel estimates, and ∆AB and ∆RB denote the corresponding CSI error matrices. The entries of ∆AB and ∆RB are assumed to be independent and identically distributed (i.i.d.) 2 2 and follow CN (0, ςAB ) and CN (0, ςRB ), respectively [29]. Based on (2), the achievable rate at B for a given (F, θ), measured in nats/s/Hz, is conservatively modeled as −1 b AB Fc FH Z bH CAB (F, θ) = ln det I + Z (3) c AB QAB , b b b where F ≜ [Fc , Fs ], ZAB = HAB + HRB ΘHAR denotes the estimated composite A–B channel, and QAB denotes the interference-plus-noise covariance matrix. Using the independence of ∆AB and ∆RB , a conservative approximation3 of QAB is given by 2 b AB Fs FH Z bH QAB = σB Im B + Z s AB H H +E ∆AB Fc FH c +Fs Fs ∆AB +E ∆RB ΘHAR H H × Fc FH ∆RB ΘHAR c +Fs Fs 2 ⟨a⟩ 2 H H b AB Fs FH Z bH = Z s AB + σB + ςAB tr Fc Fc +Fs Fs H 2 H + ςRB tr(HAR Fc FH (4) c +Fs Fs HAR ) ImB , H where step ⟨a⟩ follows from the identity E{XYX } = σ 2 tr(Y)I for a random matrix X with i.i.d. entries distributed as CN (0, σ 2 ) and any deterministic matrix Y of compatible dimension.
C. Sensing Model By listening to the transmission from A, the sensor S attempts to estimate the channel HAS . To this end, S collects the transmitted signal from A over K time-slots. For analytical tractability, we assume that all channels remain unchanged over these K time-slots. With a slight abuse of notation, we denote the transmit signal from A over K time-slots by X = Xc + Xs , where Xc = Fc Wc , Xs = Fs Ws , Wc = [wc,1 , . . . , wc,K ] ∈ Cmmin ×K , and Ws = [ws,1 , . . . , ws,K ] ∈ CmA ×K . Here, wc,k and ws,k denote the communication and AN vectors transmitted during the k-th time-slot, respectively, for k ∈ K ≜ {1, 2, . . . , K}. Accordingly, the observation at S can be written as YS = HAS + HRS ΘHAR X + NS = HAS X + HRS ΘHAR X + NS , (5) 2 where the entries of NS are i.i.d. and follow CN (0, σS ), and NS denotes the AWGN matrix at S. By vectorizing (5), the observation can be expressed as e AS + X̆hRS + nS , yS = vec(YS ) = Xh (6) T T T e where X = X ⊗ ImS , X̆ = X HAR Θ ⊗ ImS , hAS = vec(HAS ), hRS = vec(HRS ), and nS = vec(NS ). Here, we T have used the identity vec(XY) = vec(IXY) = Y ⊗ I vec(X). We model the true channel statistics of hAS and hRS as hAS ∼ CN (µAS , ΣAS ) and hRS ∼ CN (0, ΣRS ), 3 The approximation is conservative because the CSI-error terms are not exploited as part of the useful signal; instead, their contribution is entirely incorporated into QAB as effective interference-plus-noise via their secondorder moments. As a result, the rate expression is a pessimistic surrogate for the actual achievable rate under imperfect CSI.
respectively.4 To account for imperfect prior knowledge at S, we assume that only erroneous statistical information is b S,AS , and Σ b S,RS , which denote the b S,AS , Σ available, namely µ presumed mean of hAS , the presumed covariance of hAS , and the presumed covariance of hRS , respectively. Under the LMMSE framework [30], the estimate of hAS at S is given by b S,AS = µ eµ b S,AS + RS (yS − X b S,AS ), h (7) where RS denotes the mismatched LMMSE gain and is given by b S,AS X eH X eΣ b S,AS X e H + X̆S Σ b S,RS X̆H +σ 2 Im m −1 , RS = Σ S S S A (8) b T Θ) ⊗ Im , and H b S,AR = HAR + where X̆S = (XT H S S,AR δS,AR denotes the estimate of HAR available at S. Note that yS is generated using the true cascaded term, and hence depends on X̆, whereas the sensor designs the LMMSE gain using its presumed model, and hence depends on X̆S and the erroneous priors. The following proposition characterizes the mean, covariance, and Bayesian MSE of the estimation error at S under mismatched prior information. Proposition 1. Define the estimation error as eS ≜ hAS − b S,AS . Then, for a given (F, θ), its mean is given by h e µAS − µ b S,AS , E{eS } = ImS mA −RS X (9) and its covariance is given by e AS (Im m −RS X) e H Cov{eS } = (Im m −RS X)Σ S
A
S
A
+ RS (ΣARS +σS2 ImS mA )RH S,
(10)
H
where ΣARS ≜ X̆ΣRS X̆ . Consequently, the true Bayesian MSE at S is given by (11), shown on the next page. Proof: See Appendix A. It is worth emphasizing that, in (11), the filter RS is b S,AS , Σ b S,RS , designed using the priors available at S, i.e., Σ and X̆S , as indicated in (8). Now, we assume that A also has erroneous prior inforb A,AS ∼ mation about hAS and hRS , which is modeled as h b b b b A,AS , ΣA,AS ) and hA,RS ∼ CN (0, ΣA,RS ), respecCN (µ tively. Based on these priors, the corresponding mismatched MSE expression for HAS at A is given by (12), shown on the b A,ARS ≜ X̆Σ b A,RS X̆H , and the predicted next page, where Σ LMMSE filter is defined as b A,AS X e H (X eΣ b A,AS X e H + X̆Σ b A,RS X̆H +σ 2 Im m )−1 . RA = Σ S S A (13) However, since A is unaware that its priors are erroneous, the e b A,AS )∥2 ) is not bias term (i.e., ∥(ImS mA − RA X)(µ AS − µ accessible to A. Therefore, the predicted MSE available at A is given by ξpred (F, θ) 4 The non-zero-mean model for h AS is retained because hAS is the channel to be inferred by the malicious sensor, and allowing a non-zero mean provides a more general prior model that can capture a deterministic component. By contrast, the zero-mean assumption for hRS is adopted primarily for analytical tractability. Specifically, since hRS appears as a nuisance term in the cascaded RIS contribution, modeling it as zero-mean ensures that its effect is fully captured by ΣRS , which considerably simplifies the derivation of the mismatched linear minimum mean square error (LMMSE) estimator and the associated Bayesian MSE expressions.
5
e b S,AS )∥2 MSEtrue (F, θ) = ∥(ImS mA − RS X)(µ AS − µ e AS (Im m − RS X) e H + tr RS (ΣARS + σ 2 Im m )RH . + tr (ImS mA − RS X)Σ S S S A S A
(11)
e b A,AS )∥2 MSEpred (F, θ) = ∥(ImS mA − RA X)(µ AS − µ e Σ b A,AS (Im m − RA X) e H + tr RA (Σ b A,ARS + σ 2 Im m )RH . + tr (ImS mA − RA X) S A S A S A
(12)
e Σ b A,AS (Im m − RA X) e H = tr (ImS mA − RA X) S A b A,ARS + σ 2 Im m )RH . (14) + tr RA (Σ S A S A
D. Problem Formulation for Transmitter Privacy We now formulate an optimization problem to jointly design the precoding matrix F and the passive beamforming vector θ so as to maximize ξpred (F, θ), while guaranteeing a communication QoS between A and B. The resulting optimization problem is given by maximize ξpred (F, θ), (15a) F,θ
subject to CAB (F, θ) ≥ CAB ,
(15b)
∥F∥2F ≤ pmax ,
(15c) |θκ | = 1, ∀κ ∈ MR . (15d) In (15), the objective is to maximize the predicted MSE at A. Constraint (15b) ensures that the achievable rate at B is no smaller than the threshold CAB , (15c) imposes the maximum transmit-power budget pmax , and (15d) enforces the unitmodulus constraint on each RIS meta-atom. The formulation in (15) captures the trade-off between reliable communication at B and transmitter privacy against S.
III. AO-BASED P ROPOSED S OLUTION Due to the non-convexity of the rate constraint in (15b), directly handling (17) is challenging. To facilitate the subsequent algorithm design, we first reformulate this constraint. Specifically, for a non-negative real variable τ , (15b) can be equivalently written as 1 1+τ − (18) CAB (F, θ) = 0. CAB {z } | ≜f (F,θ,CAB ,τ )
Then, following the primal-dual decomposition (PDD) framework in [31], the augmented Lagrangian associated with (17) can be expressed as gν,ρ (F, θ, τ ) = ξ¯pred (F, θ) − νf (F, θ, CAB , τ ) 1 2 f (F, θ, CAB , τ ), (19) 2ρ where ν is the Lagrange multiplier and ρ is the penalty parameter. Using (19), the problem in (17) can be transformed into maximize gν,ρ (F, θ, τ ) | τ ∈ R+ , (15c), (15d) . (20) −
F,θ,τ
It can be observed that the constraints in (20) are now decoupled, whereas the design variables remain coupled in the objective function. Motivated by this structure, we adopt an AO-based scheme to obtain a stationary solution. In particular, we employ an alternating projected gradient ascent method to develop a low-complexity solution to (20). Before presenting the proposed algorithm, we first derive the complex-valued gradients of gν,ρ (F, θ, τ ) with respect to Fc , Fs , and θ in the following theorems.
Remark 1. It is worth emphasizing that, in (15), the objective is to maximize the predicted MSE at S based on the prior information available at A. Solving (15) yields the optimal transmit design (Fopt , θ opt ) to be employed by A. For performance evaluation, however, the true MMSE achieved at S is computed using (11) for (Fopt , θ opt ). It is also important to note that the value of ξpred (F, θ) can be very small, which may lead to numerical instability during the optimization process. To address this issue, we define the normalized objective 1 ξpred (F, θ). ξ¯pred (F, θ) = (16) tr ΣAS Using (16), the optimization problem in (15) can be equivalently reformulated as maximize ξ¯pred (F, θ) | (15b), (15c), (15d) . (17)
Theorem 2. A closed-form expression for ∇θ gν,ρ (F, θ, τ ) is given by (23), shown on the next page.
It is readily seen that (17) is non-convex due to the objective function in (16), the QoS constraint in (15b), and the unitmodulus constraint in (15d). Moreover, the coupling between the optimization variables F and θ, together with the equality constraint in (15d), makes the problem particularly challenging to solve. In addition, developing a low-complexity solution to (17) is crucial, since the computational burden can become prohibitive when the number of RIS meta-atoms is large. Motivated by these challenges, the next section develops a numerically efficient solution for (17).
Proof: See Appendix C. Equipped with Theorems 1 and 2, we now develop an iterative AO framework to obtain a stationary solution to (20). The overall AO-based procedure is summarized in Algorithm 1. Specifically, the algorithm starts from initial values F(0) and θ (0) , while setting τ (0) = ν = 0, µF = µθ = 100, ρ = 10, and κ = 0.1. For given (ν, ρ), the variables (F, θ, τ ) are updated via Algorithm 2, whereas the Lagrange multiplier ν and the penalty parameter ρ are updated in steps 4 and 5 of Algorithm 1, respectively.
Theorem 1. A closed-form expression for ∇F gν,ρ (F, θ, τ ) is given by ∇Fc gν,ρ (F, θ, τ ), ∇Fs gν,ρ (F, θ, τ ) , where ∇Fc gν,ρ (F, θ, τ ) and ∇Fs gν,ρ (F, θ, τ ) are respectively given by (21) and (22), shown on the next page. Proof: See Appendix B.
F,θ
6
T 1 T unvecmA ×mmin vecT MT ImA ⊗ G c + Uc tr ΣAS 2 1 2 b H −1 b − ν + ρ1 f (F, θ, CAB , τ ) tr DAB ςAB ImA + ςRB HH AR HAR − ZAB EAB ZAB Fc . (21) CAB T 1 T unvecmA ×mA vecT MT ImA ⊗ Gs ∇Fs gν,ρ (F, θ, τ ) = s + Us tr ΣAS H 1 2 2 H b Z b ν + ρ1 f (F, θ, CAB , τ ) tr DAB Z − AB AB + ςAB ImA + ςRB HAR HAR Fs . (22) CAB ∇Fc gν,ρ (F, θ, τ ) =
∇θ gν,ρ (F, θ, τ ) = vecd
h
T i 1 unvecmR ×mR vecT V3T + JT I ⊗ G m θ 4 R tr ΣAS 1 b H LAB HH . ν + ρ1 f (F, θ, CAB , τ ) vecd H − RB AR CAB
(23)
Algorithm 1: AO-Based Proposed Algorithm to Solve (20)
Algorithm 2: Penalty-Based AO Algorithm to Solve (20) for Fixed (ν, ρ)
Input: F(0) , θ (0) , τ (0) , µF , µθ , ν, ρ, κ Output: Fopt , θ opt 1 ȷ ← 1; 2 repeat /* Update (F, θ, τ ) for fixed (ν, ρ) */ 3 Obtain F(ȷ+1) , θ (ȷ+1) , τ (ȷ+1) via Algorithm 2; /* Update ν */ 4 ν ← ν + ρ1 f F(ȷ+1) , θ (ȷ+1) , CAB , τ (ȷ+1) ; /* Update ρ */ 5 ρ ← κρ; /* Update iteration counter */ 6 ȷ ← ȷ + 1; 7 until convergence; /* Final assignment */ (ȷ) (ȷ) 8 Fopt ← F , θopt ← θ ;
Input: F(ȷ) , θ (ȷ) , τ (ȷ) , µF , µθ , ν, ρ Output: F(ȷ̄+1) , θ (ȷ̄+1) , τ (ȷ̄+1) /* Initial assignment */ 1 ȷ̄ ← 1; (ȷ̄) 2 F ← F(ȷ) , θ (ȷ̄) ← θ (ȷ) , τ (ȷ̄) ← τ (ȷ) ; 3 repeat /* Update F for fixed (θ, τ ) */ 4 F(ȷ̄+1) ← ΠF F(ȷ̄) + µF ∇F gν,ρ F(ȷ̄) , θ (ȷ̄) , τ (ȷ̄) ; /* Update θ for fixed (F, τ ) */ 5 θ (ȷ̄+1) ← Πϑ θ (ȷ̄) + µθ ∇θ gν,ρ F(ȷ̄+1) , θ (ȷ̄) , τ (ȷ̄) ; /* Update τ for fixed (F, θ) */ 6 τ (ȷ̄+1) ← 1 max 0, CAB CAB F(ȷ̄+1) , θ (ȷ̄+1) − 1 − νρ ; /* Update iteration counter */ 7 ȷ̄ ← ȷ̄ + 1; 8 until convergence; /* Update assignment */ (ȷ+1) 9 F ← F(ȷ̄) , θ (ȷ+1) ← θ (ȷ̄) , τ (ȷ+1) ← τ (ȷ̄) ;
In Algorithm 2, the transmit precoding matrix F is first updated for fixed (θ, τ ) in step 4, where µF denotes the stepsize and F denotes the feasible set of transmit precoders, defined as F ≜ F ∈ CmA ×(mmin +mA ) : ∥F∥2F ≤ pmax . (24) The projection onto the feasible set F is given by e max ∥F∥ e F , √pmax . e = √pmax F/ (25) ΠF {F} After updating F, the RIS beamforming vector is updated. The corresponding feasible set ϑ is given by ϑ ≜ θ ∈ CmR ×1 : |θκ | = 1, ∀κ ∈ MR , (26) e and the projection onto ϑ is given by Πϑ {θ} = [θ̄1 , . . . , θ̄mR ]T ,(where for each κ ∈ MR , we have θeκ /|θeκ |, if θeκ ̸= 0, θ̄κ = (27) exp(jϕ), ϕ ∈ [0, 2π), otherwise. Finally, it is worth noting that although we initialize the stepsizes as µF = µθ = 100, their effective values at each iteration are determined via a backtracking line search based on the Armijo–Goldstein condition [32]. a) Convergence Analysis: The convergence of the proposed algorithm can be justified within the standard penalty
dual decomposition framework combined with cyclic block coordinate optimization. For any fixed multiplier–penalty pair (ν, ρ), Algorithm 2 generates a sequence by successively updating the blocks F, θ, and τ through the corresponding subproblems of the augmented formulation in (20), while keeping the remaining blocks fixed. Since each block update is designed to optimize the augmented objective with respect to the corresponding variable block, the resulting inneriteration objective sequence is monotonically nondecreasing. Furthermore, the transmit power constraint and the unitmodulus RIS constraint ensure that the feasible set associated with (F, θ) is compact, whereas the auxiliary variable τ is bounded by construction. Hence, the augmented objective is bounded from above over the feasible set, which guarantees convergence of the inner objective sequence; accordingly, the inner loop converges to a first-order stationary point of (20) for the given (ν, ρ). In the outer loop, the multiplier update
7
1 is given by ν (ȷ+1) = ν (ȷ) + ρ(ȷ) f (F(ȷ+1) , θ (ȷ+1) , τ (ȷ+1) ), where f (F, θ, τ ) = 0 denotes the equality representation of the transformed QoS constraint. Equivalently, this yields f (F(ȷ+1) , θ (ȷ+1) , τ (ȷ+1) ) = ρ(ȷ) ν (ȷ+1) − ν (ȷ) . Therefore, if the multiplier sequence {ν (ȷ) } is bounded and the penalty parameter satisfies ρ(ȷ) → 0, then the equality-constraint residual vanishes asymptotically, namely, f (F(ȷ+1) , θ (ȷ+1) , τ (ȷ+1) ) → 0, thereby establishing asymptotic primal feasibility. Consequently, every accumulation point generated by Algorithm 1 is feasible for the transformed problem (20) and satisfies its first-order optimality condition, and therefore fulfills the Karush–Kuhn–Tucker (KKT) conditions of (20). Finally, since (18) constitutes an equivalent reformulation of the QoS constraint in (15b), the transformed problem in (20) is equivalent to the original problem in (15). It follows that any accumulation point satisfying the KKT conditions of (20) is also a KKT point of (15).
b) Complexity Analysis: It is evident that the computational complexity of the proposed PDD-AO framework is dominated by the inner updates in Algorithm 2. Hence, the complexity of Algorithm 1 can be quantified by counting the required number of complex multiplications in one inner iteration of Algorithm 2 and then multiplying by the numbers of outer and inner iterations. Let mF ≜ mmin + mA denote the number of columns of F = [Fc , Fs ], and let Iout and Iin denote the numbers of outer and inner iterations, respectively. First, consider the update of F in Step 4 of Algorithm 2. From Theorem 1, the dominant cost in evaluating ∇F gν,ρ (F, θ, τ ) comes from: i) forming the matrix X = FW and the associated cascaded sensing terms, which requires O(mA nF K +mR mA KmS ) operations; ii) constructing and inverting the predicted LMMSE covariance matrix eΣ b A,AS X e H + X̆Σ b A,RS X̆H +σ 2 I of dimension KmS ×KmS , X S whose complexity is O((KmS )3 ); and iii) evaluating the communication-related matrices QAB , EAB , and DAB , whose dominant cost is O(m3B ), while the remaining matrix products contribute O(mA nF mB ). Moreover, the projection onto the Frobenius-norm ball in (25) has complexity O(mA nF ). Therefore, the total complexity associated with the F-update is O((KmS )3 +m3B +mA nF (K +mB )+mR mA KmS ). Next, consider the update of θ in Step 5 of Algorithm 2. From Theorem 2, the dominant operations in evaluating ∇θ gν,ρ (F, θ, τ ) again include the inversion of the same KmS × KmS covariance matrix and the computation of the communicationside inverse/factorization, which contribute O((KmS )3 ) and O(m3B ), respectively. However, unlike a naïve implementation, the gradient in (23) involves the operator vecd (·), so only the diagonal entries of the intermediate mR × mR matrices are required. In addition, the commutation matrices appearing in the derivative expressions are used only as permutation operators and need not be explicitly constructed. Consequently, the RIS-related arithmetic is obtained by directly evaluating the required mR diagonal bilinear forms, which incurs complexity O(mR mA (KmS + mB )), while the projection onto the unit-modulus set in (27) is elementwise and has negligible complexity. Thus, the total complexity of the θ-update is O((KmS )3 +m3B +mA nF K +mR mA (KmS +mB )). Finally, the update of τ in Step 6 is available in closed form and
therefore has negligible complexity. Putting these observations together, the per-inner-iteration complexity of Algorithm 2 3 3 can be expressed as O 2(Km S ) +2mB +mA nF (2K +mB )+ mR mA (2KmS + mB ) . Accordingly, the overall computational complexity of Algorithm 1 is given by O Iout Iin 2(KmS )3 + 2m3B + mA nF (2K + mB ) + mR mA (2KmS + mB ) . It is worth noting that, because only the diagonal terms are needed in the θ-gradient and the commutation matrices are implemented implicitly, the dependence on the number of RIS meta-atoms mR is linear rather than quadratic or cubic. Hence, under a practical implementation, the dominant computational burden arises from the sensing- and communication-side matrix inversions, whereas the RIS-related operations remain scalable even for large mR . IV. R ESULTS AND D ISCUSSION In this section, we provide comprehensive numerical results to evaluate the performance of the system under consideration and provide detailed discussion on the results to obtain important system design insights. For this purpose, we first provide the details of the system setup, followed by numerical results and corresponding discussion. A. System Setup The transmitter (A), receiver (B), RIS (R), and sensor (S) are located at (0, 0, 0) m, (100, 20, 5) m, (50, 10, 5) m, and (20, 5, 0) m, respectively. The adopted node geometry is similar to representative setups commonly used in the RIS literature, e.g., [33], [34]. The small-scale fading on the A–B, A–S, and R–B links is modeled as Rician with Rician factor 3 dB, whereas the R–S link is modeled as Rayleigh faded. The A–R link is assumed to be purely line-of-sight. The large-scale path loss between any two nodes is modeled as −30 − 10α log10 (d/d0 ) dB, where d denotes the inter-node distance, d0 = 1 m is the reference distance, and α is the path-loss exponent; specifically, α = 3.6 for the A–B and A–S links, and α = 2.2 for the A–R, R–S, and R–B links. Unless stated otherwise, we set mA = mS = 4, mB = 16, mR = 64, K = 16, mmin = min{mA , mB }, pmax = 10 dBm, and CAB = 5 nats/s/Hz. The carrier frequency and system bandwidth are 2 GHz and 20 MHz, respectively, and the noise power spectral density is −174 dBm/Hz, which yields −174−30 2 σB = σS2 = σ 2 = 10 10 × 20 × 106 W. Furthermore, we 2 2 set ςAB = ςRB = 102 σ 2 . The spatial correlation matrices at A, B, and S follow Hermitian Toeplitz structures corresponding to uniform linear arrays (ULAs) with exponential correlation and adjacent-element correlation coefficient 0.5, whereas the RIS correlation matrix is generated according to [35] with inter-meta-atom spacing λ/4. To model prior mismatch, we set b A,AS = ΣAS + ς 2 Im m , Σ b S,AS = ΣAS + ς 2 Im m , Σ S A S A A,AS S,AS 2 b b S,RS = ΣRS + ΣA,RS = ΣRS + ςA,RS ImS mR , and Σ 2 b A,AS = µAS + ςA,AS rA,AS and ςS,RS ImS mR , together with µ b S,AS = µAS + ςS,AS rS,AS , where rA,AS , rS,AS ∼ CN (0, I). µ Unless stated otherwise, the prior-error variances are chosen
8
1
1.6
Augmented objective: gν,ρ (F, θ, τ )
Imperfect prior at S Imperfect prior Perfect prior Imperfect prior at A
True objective: ξ pred (F, θ)
1.4
NMSE
0.6 ρ = 0.01
ρ=1
0.4
ρ = 0.1
Average NMSE
0.8
1.2 1 0.8
Lines: Analytical Markers: Simulation
0.2 0.6
ρ = 10 0
0.4
1
20
40
60
80
100
Iteration number
Fig. 2. Convergence behavior of the proposed AO algorithm. 2 2 2 2 as ςA,AS = ςS,AS = 0 and ςA,RS = ςS,RS = 0 under perfect2 2 prior assumptions, and as ςA,AS = ςS,AS = (5 × 105 )σ 2 and 2 2 ςA,RS = ςS,RS = (5 × 105 )σ 2 under imperfect-prior assumptions. All NMSE results are averaged over 1000 independent channel realizations.
B. Convergence Results In Fig. 2, we illustrate the convergence behavior of the proposed AO framework in Algorithm 1 for the RIS-aided setting under perfect prior knowledge of the HAS and HRS links at both A and S. The figure shows that the algorithm reaches convergence within a limited number of iterations. Starting from ν = 0 and ρ = 10, the inner AO loop in Algorithm 2 updates (F, θ, τ ) for fixed (ν, ρ), thereby yielding a monotonic increase of the augmented Lagrangian gν,ρ (F, θ, τ ) until convergence of the inner subproblem. Subsequently, the multiplier ν and the penalty parameter ρ are updated according to Algorithm 1, and the process is repeated. The sharp drops observed in the augmented objective at the outer iterations are expected, since the updates of ν and ρ jointly tighten the enforcement of the equality constraint. More specifically, reducing ρ strengthens the quadratic penalty component, while the multiplier update ν ← ν + ρ1 f (F, θ, CAB , τ ) also increases the influence of the linear dual term associated with the constraint residual. Consequently, after each outer update, constraint violations are penalized more aggressively, which leads to the observed downward jump in the augmented objective. Moreover, the noticeable mismatch between the true objective and the augmented objective during the early iterations indicates that, although the iterates improve the penalized problem in (20), they are not yet primal-feasible for the original formulation in (17), i.e., the residual f (F, θ, CAB , τ ) remains nonzero. As the outer loop advances, the joint updates of ν and ρ drive this residual toward zero, so that the iterates eventually satisfy the original constraint as well, and the gap between the augmented and true objectives consequently vanishes. C. Impact of the Number of RIS Meta-Atoms In Fig. 3, we examine the impact of the number of RIS metaatoms on the average NMSE at the sensor for four different prior-knowledge configurations. Here, “Perfect prior” denotes the case in which both A and S possess correct statistical priors, “Imperfect prior” corresponds to the case in which both
0 42
82
122
162
Number of RIS elements (mR )
Fig. 3. Impact of the number of meta-atoms at the RIS on the NMSE at S.
nodes operate with erroneous priors, and “Imperfect prior at A” (resp. “Imperfect prior at S”) denotes the case in which only A (resp. S) has imperfect prior knowledge while the other node has perfect priors. The solid curves are obtained analytically from the closed-form true Bayesian MSE expression in (11), evaluated at the optimized design (F, θ) and then normalized to produce the NMSE, whereas the markers are obtained by Monte Carlo simulation, where the received signal at S is generated according to the sensing model, the mismatched LMMSE estimator in (7)–(8) is applied, and the resulting channel-estimation error is averaged over random realizations. It is observed that the analytical curves closely match the simulation markers for all values of mR , thereby validating the accuracy of the developed NMSE characterization. Moreover, the average NMSE increases monotonically with mR in all four cases, which shows that a larger RIS offers additional spatial degrees of freedom for shaping the reflected signal over the A–R–S path and, consequently, for degrading the sensing capability at S. In particular, the point mR = 0 corresponds to the non-RIS scenario, and it yields the smallest NMSE in each prior setting; therefore, the non-RIS case is the least favorable from the transmitter-privacy perspective. This observation clearly demonstrates the privacy advantage enabled by RIS deployment. The figure also reveals a clear ordering among the four prior settings: the highest NMSE is achieved when the prior is imperfect at S, followed by the case in which both A and S have imperfect priors, then the perfect-prior case, whereas the lowest NMSE is obtained when the prior is imperfect only at A. This behavior is physically intuitive. When A has imperfect priors, it optimizes (F, θ) using a mismatched predicted objective, so the resulting design is no longer well aligned with the true channel statistics governing the sensor’s estimator; as a result, the actual degradation induced at S is reduced, leading to a lower NMSE. In contrast, when S has imperfect priors, its Wiener filter is itself mismatched to the true observation model, which directly deteriorates channelestimation accuracy and leads to a larger NMSE. When both nodes have imperfect priors, these two effects coexist: the prior mismatch at S still degrades the estimator, whereas the prior mismatch at A partially weakens the effectiveness of the privacy-oriented design. Consequently, the corresponding performance lies between the cases of “Imperfect prior at S” and “Perfect prior”.
9
1.2
w/o RIS (perfect prior at S)
w/ RIS (perfect prior at S)
w/o RIS (imperfect prior at S)
w/ RIS (imperfect prior at S)
1
w/o RIS (perfect prior at S)
w/ RIS (perfect prior at S)
w/o RIS (imperfect prior at S)
w/ RIS (imperfect prior at S)
1
w/o RIS (perfect prior at S)
w/ RIS (perfect prior at S)
w/o RIS (imperfect prior at S)
w/ RIS (imperfect prior at S)
1
0.6 0.4
0.8 Average NMSE
Average NMSE
Average NMSE
0.8 0.8
0.6
0.4
0.2
0.2 0 6
8
10
Number of transmit antennas (mA )
Fig. 4. Impact of the number of transmit antennas on the NMSE at S.
0.4
0.2
0 4
0.6
0 2
3
4
5
Number of sensing antennas (mS )
Fig. 5. Impact of the number of sensor antennas on the NMSE at S.
D. Impact of the Number of Transmit Antennas For the remaining figures, we restrict attention to the case of imperfect prior at A and consider two representative subcases at S, namely, “perfect prior at S” and “imperfect prior at S”, since these two settings most clearly reveal the privacy implications of transmitter-side prior mismatch under different sensing conditions at the adversarial sensor. In Fig. 4, we investigate the impact of the number of transmit antennas on the average NMSE at the sensor for both RIS-aided and non-RIS architectures. It is observed that the average NMSE increases monotonically with mA in all four cases. This trend can be understood from two complementary perspectives. First, for fixed K and mS , increasing mA enlarges the dimension of the unknown channel HAS ∈ CmS ×mA to be estimated, whereas the size of the observation available at the sensor, YS ∈ CmS ×K , remains unchanged. Equivalently, in the vectorized model, the number of unknown coefficients in hAS grows with mA , while the number of observation dimensions remains fixed at KmS . Hence, the estimation problem at S becomes progressively more challenging as mA increases, which naturally results in a higher NMSE. Second, a larger transmit array provides additional spatial degrees of freedom for the design of the transmit precoder, and, in the RIS-aided case, these degrees of freedom can be further exploited jointly with the RIS phase profile to more effectively impair sensing at S while maintaining the communication requirement at B. This explains why, for every value of mA , the RIS-aided scheme consistently outperforms its non-RIS counterpart under the same prior setting. Moreover, the ordering between the perfectprior and imperfect-prior cases at S remains consistent with that already observed in Fig. 3. Overall, Fig. 4 shows that increasing the number of transmit antennas is beneficial for transmitter privacy, and that RIS assistance further amplifies this gain. E. Impact of the Number of Sensor Antennas In Fig. 5, we investigate the impact of the number of sensor antennas on the average NMSE for both RIS-aided and non-RIS architectures, while keeping the transmitter-side prior imperfect and considering the two representative cases of perfect prior at S and imperfect prior at S. A first noteworthy observation is that, when S has perfect prior knowledge, the
4
8
12
16
Number of observation slots (K)
Fig. 6. Impact of the observation length on the NMSE at S.
average NMSE remains nearly unchanged as mS increases. This behavior can be understood by noting that increasing mS enlarges not only the observation matrix at the sensor but also the dimension of the channel HAS ∈ CmS ×mA to be estimated. Hence, the sensor acquires a larger spatial observation space, but it must simultaneously infer a proportionally larger number of channel coefficients. Since the estimator at S is statistically matched in the perfect-prior case, these two effects largely balance each other in normalized terms, and the resulting average NMSE changes only marginally with mS . In contrast, when S operates with imperfect prior knowledge, the average NMSE decreases as mS increases. In this case, the additional sensing antennas provide a richer spatial observation that partially compensates for the prior mismatch, thereby improving the conditioning of the estimation problem and reducing the mismatch-induced error. The figure further shows that, for both prior settings at S and for all values of mS , the RIS-aided architecture consistently achieves a higher NMSE than its nonRIS counterpart. Therefore, although increasing the sensing capability of the adversarial node can alleviate the impact of prior mismatch at S, RIS assistance continues to provide a clear privacy advantage throughout the entire range of mS .
F. Impact of the Observation Length In Fig. 6, we study the effect of the observation length K on the average NMSE at the sensor. As expected, the average NMSE decreases with K for all considered cases. This behavior follows directly from the fact that a larger observation horizon provides the sensor with more temporal samples, thereby increasing the effective number of measurements available for channel inference and improving the accuracy of the LMMSE estimator. In other words, a longer sensing duration reduces the uncertainty in the channel estimate and strengthens the sensing capability of the adversarial node. Nevertheless, the RIS-aided scheme consistently yields a higher NMSE than the non-RIS scheme for both prior settings at S across the entire range of K. This is an important observation, since it shows that the privacy benefit of RIS assistance is not limited to short observation windows; rather, it persists even when the sensor is allowed to collect a substantially larger number of samples. Thus, while increasing K is beneficial for the sensor from an
w/ RIS (imperfect prior at S) w/o RIS (imperfect prior at S) w/ RIS (perfect prior at S) w/o RIS (perfect prior at S)
0.6
0.5
Average NMSE
Average NMSE
0.6
0.4 0.3 0.2 0.1 10
AoA estimation RMSE (degree)
10
w/ RIS (imperfect prior at S) w/o RIS (imperfect prior at S) w/ RIS (perfect prior at S) w/o RIS (perfect prior at S)
0.5
0.4
15
20
25
30
Transmit power budget (dBm)
Fig. 7. Impact of transmit power budget on the NMSE at S.
1
2
3
4
5
(ς 2 /σ 2 ) × 105
Fig. 8. Impact of imperfect prior on the NMSE at S.
estimation standpoint, the proposed RIS-aided design remains effective in preserving transmitter privacy. G. Impact of Transmit Power Budget In Fig. 7, we examine the impact of the transmit power budget on the average NMSE at the sensor for both RISaided and non-RIS architectures, while restricting attention to the case of imperfect prior at A and considering the two representative subcases of perfect prior at S and imperfect prior at S. It is observed that the average NMSE decreases monotonically with pmax in all four cases. Although a larger power budget gives A greater flexibility to design (F, θ) in a privacy-aware manner, the dominant effect is that the received observation at S becomes stronger as pmax increases. More specifically, the same transmit signal X simultaneously drives both the desired sensing component HAS X and the RIS-induced nuisance component HRS ΘHAR X. Hence, increasing pmax does not merely intensify interference at S; it also strengthens the direct A–S observation from which S estimates the channel. Since the cascaded RIS term constitutes a structured impairment rather than an independently powered jammer, the net effect of increasing pmax is an improvement in the effective observation quality at S, which leads to a lower NMSE. Nevertheless, for every value of pmax , the RIS-aided scheme consistently yields a higher NMSE than the corresponding non-RIS benchmark under the same prior setting. This shows that, although a larger transmit power budget improves the sensing capability of the adversarial node, RIS-assisted propagation shaping continues to preserve a nonnegligible privacy advantage across the entire operating range. H. Impact of the Imperfect Priors In Fig. 8, we investigate the impact of the prior-error variance on the average NMSE at the sensor for both RISaided and non-RIS architectures, while restricting attention to the case of imperfect prior at A and considering the two representative subcases of perfect prior at S and imperfect prior at S. Here, whenever prior mismatch is present, the corresponding prior-error variances are set equal to a common value ς 2 . A clear contrast is observed between the two sensing conditions at S. When S has perfect prior knowledge, the average NMSE decreases as ς 2 increases. This behavior is
w/ RIS (imperfect prior at S) w/o RIS (imperfect prior at S) 0.7
0.6
0.5
0.4
0.3
16
18
20
22
24
Transmit power budget (dBm)
Fig. 9. Impact of transmit power budget on the AoA estimation RMSE at S.
physically intuitive, since a larger prior mismatch at A makes the design of (F, θ) increasingly driven by an inaccurate predicted objective. As a result, the resulting privacy-oriented design becomes less aligned with the true channel statistics governing the sensor’s estimator, so that the actual impairment induced at S is weakened and the sensor can estimate the channel more accurately, thereby reducing the NMSE. In contrast, when S also operates with imperfect prior knowledge, the average NMSE increases monotonically with ς 2 . In this case, increasing ς 2 not only preserves the transmitter-side design mismatch, but also directly worsens the mismatch in the Wiener filter employed at S, and this estimator mismatch becomes the dominant effect, leading to a larger NMSE. The figure further shows that, for every value of ς 2 and under both prior settings at S, the RIS-aided architecture consistently achieves a higher NMSE than its non-RIS counterpart. Therefore, although severe transmitter-side prior mismatch can partially reduce the effectiveness of the privacy-oriented design, RIS assistance continues to provide a clear privacy advantage, and this advantage becomes particularly pronounced when the sensor itself also suffers from prior mismatch. I. AoA Privacy Interpretation To connect transmitter privacy to a more direct sensing metric, we next evaluate the AoA estimation performance b AS , at the malicious sensor using the estimated channel H via a Bartlett spatial-spectrum search over candidate angles. We restrict attention here to the case of imperfect prior at S, since when S has perfect prior knowledge, the prior mean may already contain deterministic transmitter-direction b AS is no information, and therefore AoA estimation from H longer a meaningful privacy indicator. Fig. 9 shows that the root mean square error (RMSE) of AoA estimation decreases with the transmit-power budget for both the RIS-aided and non-RIS schemes, which is consistent with the trend already observed in Fig. 7 for the channel-estimation NMSE, i.e., as pmax increases, the observation quality at S improves, and the resulting estimate of HAS becomes more accurate. Nevertheless, the RIS-aided scheme consistently yields a higher AoA RMSE than the non-RIS benchmark over the entire range of pmax . This observation is important because it shows that the privacy benefit of the proposed design is not limited to the intermediate channel-estimation metric, but also translates
11
into degraded inference of a physically meaningful transmitter attribute, namely, its angle of arrival at the sensor. Therefore, RIS-assisted propagation shaping helps preserve transmitter privacy not only in terms of channel-estimation error, but also in terms of the AoA estimation accuracy achieved at the sensor. V. C ONCLUSION This paper studied transmitter privacy in an RIS-aided multi-antenna wireless system in the presence of a malicious sensing node seeking to estimate the transmitter–sensor channel. A privacy-oriented joint optimization framework was developed for the transmit precoder and RIS reflection coefficients, with the aim of maximizing the malicious sensor’s predicted channel-estimation error while guaranteeing the desired communication performance at the legitimate receiver under power and RIS constraints. To tackle the resulting non-convex problem, an AO-based method was proposed. The numerical results showed that RIS-assisted propagation shaping can significantly impair unauthorized channel estimation and provide clear privacy gains relative to non-RIS benchmarks, without sacrificing reliable communication. They further showed that these gains are also reflected in degraded AoA estimation at the malicious sensor, thereby providing a more direct sensinglevel interpretation of transmitter privacy. An important direction for future work is to extend the proposed framework to multi-user scenarios with multiple legitimate receivers and multiple possibly colluding malicious sensors, where spatially distributed attackers may share observations and/or local channel estimates, leading to a richer joint estimation model and potentially different privacy– communication tradeoffs. A PPENDIX A P ROOF OF P ROPOSITION 1 Substituting (6) into (7), the estimation error can be written as b S,AS = hAS − µ eµ b S,AS + RS yS − X b S,AS eS = hAS − h e AS + X̆hRS +nS − X eµ b S,AS +RS Xh b S,AS = hAS − µ e AS = hAS −RS Xh eµ b S,AS − RS X b S,AS −RS X̆hRS + nS − µ e hAS − µ b S,AS − RS X̆hRS + nS = Im S m A − R S X e hAS −µAS = ImS mA −RS X e µAS − µ b S,AS −RS X̆hRS + nS . + ImS mA −RS X (28) Since E{hAS − µAS } = 0, E{hRS } = 0, and E{nS } = 0, taking expectation on both sides of (28) yields e µAS − µ b S,AS , E{eS } = ImS mA − RS X (29) which proves (9). Next, define the zero-mean error fluctuation as e eS = eS − E{eS } e hAS − µAS − RS X̆hRS + nS . = ImS mA − RS X (30) Using (30), the error covariance is given by Cov{eS } = E e eS e eH S
e hAS − µAS = E ImS mA − RS X H e H × hAS − µAS Im S m A − R S X H + E RS X̆hRS + nS X̆hRS + nS RH S H e − E ImS mA −RS X hAS −µAS X̆hRS +nS RH S H H e − E RS X̆hRS +nS hAS −µAS ImS mA −RS X . (31) Because hAS − µAS , hRS , and nS are mutually independent and zero-mean, the last two cross terms in (31) vanish. Moreover, E (hAS − µAS )(hAS − µAS )H = ΣAS , (32) and H E X̆hRS + nS X̆hRS + nS H H = X̆E hRS hH RS X̆ + E nS nS = X̆ΣRS X̆H + σS2 I = ΣARS + σS2 I. (33) Using (32) and (33), the expression in (31) becomes equal to (10). Finally, since vectorization preserves the Frobenius norm, we have b S,AS ∥2 = ∥eS ∥2 . b S,AS ∥2 = ∥hAS − h ∥HAS − H (34) F Using the identity E{∥x∥2 } = ∥E{x}∥2 + tr(Cov{x}) for any random vector x, and (34), the true Bayesian MSE at S is given by (11). This completes the proof. A PPENDIX B P ROOF OF T HEOREM 1 With Fs , θ and τ being fixed, the complex-valued differential of gν,ρ (F, θ, τ ) w.r.t. Fc can be obtained as d gν,ρ (F, θ, τ ) = d ξ¯pred (F, θ) − ν + ρ1 f (F, θ, CAB , τ ) d f (F, θ, CAB , τ ). (35) For the first term on the RHS, we have d ξ¯pred (F, θ) h 1 e Σ b A,AS (I − RA X) e H tr (I − RA X) = d tr ΣAS i b A,ARS + σ 2 I)RH + tr RA (Σ S A h 1 e Σ b A,AS (I − RA X) e H d tr (I − RA X) = tr ΣAS i b A,ARS + σ 2 I)RH . (36) + d tr RA (Σ S A By representing RA = RA1 R−1 A2 , the expression for d tr (I− e Σ b A,AS (I − RA X) e H can be obtained as RA X) e Σ b A,AS (I − RA X) e H d tr (I − RA X) H e e H = tr d(I − RA X)M 1 + tr M1 d(I − RA X) eH = tr M2 d RA2 − tr M3 d X = tr M4c + M5c d F∗c ⊗ ImS = tr Mc d F∗c ⊗ ImS ∗ = vecT MT c d vec Fc ⊗ ImS = vecT MT ImA ⊗ Gc d vec F∗c , (37) c where b A,AS (I − RA X) e H, M1 = Σ (38a)
12
H H e H −1 e M2 = R−1 A2 XM1 RA + RA M1 X RA2 , H H e b M3 = R−1 A2 XM1 ΣA,AS + RA M1 , eΣ b A,AS − M3 , M4c = Wc∗ ⊗ ImS M2 X b A,RS Θ∗ H∗ ⊗ Im M5c = W∗ ⊗ Im M2 X̆Σ
(38b) (38c) (38d)
, (38e) c AR S S Mc = M4c + M5c , (38f) Gc = (CmS mmin ⊗ ImS )(Immin ⊗ vec(ImS )), (38g) mX mY ×mX mY and CmX mY ∈ R matrix. is the commutation b A,ARS + σ 2 I)RH is Similarly, the expression for d tr RA (Σ S A obtained as b A,ARS + σ 2 I)RH d tr RA (Σ S A b A,ARS + tr UH d RH = tr U1 d RA + tr U2 d Σ 1 A b eH = tr R−1 A2 U1 ΣA,AS d X b A,RS d X̆H − tr U3 d RA2 + tr U2 X̆Σ e H + tr U5 d X̆H = tr U4 d X ∗ = vecT UT c d vec Fc ⊗ ImS = vecT UT ImA ⊗ Gc d vec F∗c , (39) c where b A,ARS + σ 2 I RH , U1 = Σ (40a) S A U2 = RH A RA ,
∇Fs ξ¯pred (F, θ) =
(40b)
H H −1 U3 = R−1 (40c) A2 U1 RA + RA U1 RA2 , −1 e b U4 = RA2 U1 − U3 X ΣA,AS , (40d) b U5 = U2 − U3 X̆ΣA,RS , (40e) ∗ ∗ ∗ Uc = Wc ⊗ ImS U4 + U5 Θ HAR ⊗ ImS . (40f) Therefore, using (36), (37) and (39), one can write 1 ∇Fc ξ¯pred (F, θ) = tr ΣAS T T × unvecmA ×mmin vecT MT ImA ⊗ Gc . (41) c + Uc Next, we obtain d f (F, θ, CAB , τ ) as follows: 1 d CAB (F, θ) d f (F, θ, CAB , τ ) − CAB 1 −1 b AB Fc FH Z bH =− d ln det I + Z c AB QAB CAB 1 d ln det QAB − ln det EAB = CAB 1 −1 = tr Q−1 AB d QAB − tr EAB d EAB CAB 1 −1 = tr Q−1 AB − EAB d QAB CAB H b H E−1 Z b − tr Z . (42) AB AB AB Fc d Fc H bH b where EAB = QAB + ZAB Fc Fc ZAB . Then using (42) and [36, Table III], one can obtain 2 1 ∇Fc f (F, θ, CAB , τ ) = tr DAB ςAB Im A CAB 2 b H −1 b + ςRB HH AR HAR − ZAB EAB ZAB Fc , (43) −1 where DAB = Q−1 AB − EAB . Using (35), (41) and (43), a closed-form expression for ∇Fc gν,ρ (F, θ, τ ) is given by (21).
Analogous to (41), we obtain the expression for ∇Fs ξ¯pred (F, θ) as
1 tr ΣAS T T vecT MT ImA ⊗ Gs , (44) s + Us
× unvecmA ×mA where Ms = M4s + M5s , M4s =
(45a)
eΣ b A,AS − M3 , Ws∗ ⊗ ImS M2 X b A,RS Θ∗ H∗ ⊗ Im Ws∗ ⊗ ImS M2 X̆Σ AR S
(45b)
M5s = , (45c) Gs = (CmS mA ⊗ ImS )(ImA ⊗ vec(ImS )), (45d) ∗ ∗ ∗ (45e) Us = Ws ⊗ ImS U4 + U5 Θ HAR ⊗ ImS . Similarly, following (43), we obtain 1 tr DAB ∇Fs f (F, θ, CAB , τ ) = CAB bH Z b AB + ς 2 Im + ς 2 HH HAR Fs . (46) × Z AB AB RB AR A Using (44) and (46), a closed-form expression for ∇Fs gν,ρ (F, θ, τ ) is given by (22). This completes the proof. A PPENDIX C P ROOF OF T HEOREM 2 When F and τ are held fixed, the complex-valued differential of gν,ρ (F, θ, τ ) w.r.t. θ can be obtained as d gν,ρ (F, θ, τ ) = d ξ¯pred (F, θ) − ν + ρ1 f (F, θ, CAB , τ ) d f (F, θ, CAB , τ ). (47) For the first term on the RHS, we have d ξ¯pred (F, θ) h 1 e Σ b A,AS (I − RA X) e H tr (I − RA X) = d tr ΣAS i b A,ARS + σ 2 I)RH + tr RA (Σ S A h 1 e Σ b A,AS (I − RA X) e H d tr (I − RA X) = tr ΣAS i b A,ARS + σ 2 I)RH . (48) + d tr RA (Σ S A e Σ b A,AS (I − RA X) e H can The expression for d tr (I − RA X) be obtained as e Σ b A,AS (I − RA X) e H d tr (I − RA X) H e e H = tr d(I − RA X)M 1 + tr M1 d(I − RA X) −1 = tr RA2 V1 R−1 d RA2 ∗A2 ∗ = tr V2 d Θ HAR X∗ ⊗ ImS = tr V3 d Θ∗ ⊗ ImS = vecT V3T ImR ⊗ Gθ d vec Θ∗ . (49) H e e where M1 is given in (38a), V1 = XM1 RA1 + XM1 RA1 , −1 ∗ b V2 = R−1 H∗AR A2 V1 RA2 X̆ΣA,RS , V3 = X ⊗ ImS V2 , Gθ = CmR mS ⊗ ImS ImR ⊗ vec ImS , and CmR mS is b A,ARS + the commutation matrix. Similarly, for d tr RA (Σ σS2 I)RH , we have A b A,ARS + σ 2 I)RH d tr RA (Σ S A b A,ARS +tr UH d RH = tr U1 d RA +tr U2 d Σ 1 A = tr J1 d R−1 + tr J2 d X̆H = tr J3 d X̆H A2 ∗ = tr J4 d Θ∗ ⊗ ImS = vecT JT 4 d vec Θ ⊗ ImS = vecT JT ImR ⊗ Gθ d vec Θ∗ , (50) 4
13
where U1 is given in (40a), U2 is given in (40b), J1 = H b U1 RA1 + U1 RA1 , J2 = U2 X̆Σ , J3 = J2 − ∗ A,RS −1 −1 b A,RS , and J4 = H X∗ ⊗Im J3 . ThereRA2 J1 RA2 X̆Σ S AR fore, using (48), (49) and (50), a closed-form expression for ∇θ ξ¯pred (F, θ) is given by h 1 ∇θ ξ¯pred (F, θ) = vecd tr ΣAS T i × unvecmR ×mR vecT V3T + JT Im R ⊗ G θ . (51) 4 Moreover, a closed-form expression for d f (F, θ, CAB , τ ) is obtained as follows: 1 d CAB (F, θ) d f (F, θ, CAB , τ ) = − CAB 1 −1 tr Q−1 = AB d QAB − tr EAB d EAB CAB 1 H bH b = tr DAB d QAB − tr E−1 AB ZAB Fc Fc d ZAB CAB H 1 1 bH b LAB HH d ΘH , tr LAB d Z tr H = AB = RB AR CAB CAB (52) where EAB and DAB are given in Appendix B, and LAB = H b b AB Fs FH − E−1 Z DAB Z s AB AB Fc Fc . Hence, one can obtain ∇θ f (F, θ, CAB , τ ) is given by 1 b H LAB HH . (53) ∇θ f (F, θ, CAB , τ ) = vecd H RB AR CAB Using (51) and (53), a closed-form expression for ∇θ gν,ρ (F, θ, τ ) is given by (23); this concludes the proof. R EFERENCES [1] D. Zhang et al., “Integrated sensing and communications over the years: An evolution perspective,” IEEE Commun. Surveys Tuts., vol. 28, pp. 5014–5048, 2026. [2] M. Chafii, L. Bariah, S. Muhaidat, and M. Debbah, “Twelve scientific challenges for 6G: Rethinking the foundations of communications theory,” IEEE Commun. Surveys Tuts., vol. 25, no. 2, pp. 868–904, 2023. [3] L. He et al., “Design of uplink ISAC systems with cooperative sensing: Power control and receive beamforming,” IEEE Trans. Wireless Commun., vol. 25, pp. 14 337–14 350, 2026. [4] A. Magbool, V. Kumar, Q. Wu, M. Di Renzo, and M. F. Flanagan, “A survey on integrated sensing and communication with intelligent metasurfaces: Trends, challenges, and opportunities,” IEEE Open J. Commun. Soc., vol. 6, pp. 7270–7318, 2025. [5] 3GPP, “Study on Integrated Sensing and Communication,” 3rd Generation Partnership Project (3GPP), Technical Report TR 22.837, 2022, Release 19. [Online]. Available: https://portal.3gpp.org/desktopmodules/ Specifications/SpecificationDetails.aspx?specificationId=4044 [6] ——, “Integrated Sensing and Communication,” 3rd Generation Partnership Project (3GPP), Technical Specification TS 22.137, 2023, Release 19. [Online]. Available: https://portal.3gpp.org/desktopmodules/ Specifications/SpecificationDetails.aspx?specificationId=4198 [7] ——, “Study on channel model for frequencies from 0.5 to 100 GHz,” 3rd Generation Partnership Project (3GPP), Technical Report TR 38.901, 2026, Release 19. [Online]. Available: https://portal.3gpp.org/desktopmodules/Specifications/ SpecificationDetails.aspx?specificationId=3173 [8] K. Qu, J. Ye, X. Li, and S. Guo, “Privacy and security in ubiquitous integrated sensing and communication: Threats, challenges and future directions,” IEEE Internet Things Mag., vol. 7, no. 4, pp. 52–58, 2024. [9] X. Zhu et al., “Enabling intelligent connectivity: A survey of secure ISAC in 6G networks,” IEEE Commun. Surveys Tuts., vol. 27, no. 2, pp. 748–781, 2025. [10] B. He, F. Wang, and J. Cheng, “Joint secure transceiver design for integrated sensing and communication,” IEEE Trans. Wireless Commun., vol. 23, no. 10, pp. 13 377–13 393, 2024. [11] S. Li et al., “Secure hybrid beamforming design for mmWave integrated sensing and communication systems,” IEEE Trans. Veh. Technol., vol. 74, no. 7, pp. 10 622–10 638, 2025.
[12] K. Yu et al., “Physical layer security design and performance evaluation for 3D communication-2D sensing enabled spatial separation and interference decoupling in ISAC-IoV networks,” IEEE J. Sel. Areas Commun., vol. 44, pp. 2102–2115, 2026. [13] Z. Ren, L. Qiu, J. Xu, and D. W. K. Ng, “Robust transmit beamforming for secure integrated sensing and communication,” IEEE Trans. Commun., vol. 71, no. 9, pp. 5549–5564, 2023. [14] A. Bazzi and M. Chafii, “Secure full duplex integrated sensing and communications,” IEEE Trans. Inf. Forensics Security, vol. 19, pp. 2082– 2097, 2024. [15] M. Liu et al., “Joint beamforming design for integrated sensing and communication systems with hybrid-colluding eavesdroppers,” IEEE Trans. Commun., vol. 73, no. 8, pp. 6484–6498, 2025. [16] D. Xu, X. Yu, D. W. K. Ng, A. Schmeink, and R. Schober, “Robust and secure resource allocation for ISAC systems: A novel optimization framework for variable-length snapshots,” IEEE Trans. Commun., vol. 70, no. 12, pp. 8196–8214, 2022. [17] H. Zhu, Z. Li, and Y.-C. Wu, “Unified framework for outage-constrained rate maximization in secure ISAC under various sensing metrics,” IEEE J. Sel. Areas Commun., vol. 44, pp. 3812–3827, 2026. [18] Y. Li et al., “RIS-based physical layer security for integrated sensing and communication: A comprehensive survey,” IEEE Internet Things J., vol. 12, no. 16, pp. 32 444–32 468, 2025. [19] V. Kumar and M. Chafii, “Beamforming design for secure RIS-enabled ISAC: Passive RIS versus active RIS,” IEEE Trans. Wireless Commun., vol. 24, no. 9, pp. 7719–7732, 2025. [20] A. Kazymova, V. Kumar, C. Pöpper, and M. Chafii, “Achievable sum secrecy rate of STAR-RIS-enabled MU-MIMO ISAC,” in IEEE ICC Workshops, 2025, pp. 947–952. [21] Y. Wen et al., “Exploring passive eves with self-refine sensing: A novel ISAC-aided secure communication system with STAR-RIS,” IEEE Trans. Wireless Commun., vol. 25, pp. 1209–1222, 2026. [22] H. Zhang et al., “Beamforming and phase shift design for STAR-RISassisted secure sensing and communication in ISAC systems,” IEEE J. Sel. Areas Commun., vol. 44, pp. 4037–4050, 2026. [23] Y. Wu et al., “Covert ISAC against collusive wardens,” IEEE Trans. Wireless Commun., vol. 24, no. 11, pp. 9763–9776, 2025. [24] L. Guo et al., “Joint secure and covert communications for active STARRIS assisted ISAC systems,” IEEE Trans. Wireless Commun., vol. 24, no. 9, pp. 7501–7516, 2025. [25] Y. Zhang et al., “ISAC-assisted covert transmission: Joint secure sensing and communication,” IEEE J. Sel. Areas Commun., vol. 44, pp. 2038– 2051, 2026. [26] A. Magbool, V. Kumar, M. Di Renzo, and M. F. Flanagan, “Hiding in plain sight: RIS-aided target obfuscation in ISAC,” IEEE Trans. Wireless Commun., vol. 25, pp. 14 550–14 563, 2026. [27] U. A. Khan, L. Ho, H. Claussen, M. F. Flanagan, and C. Kundu, “On beamforming for transmitter location privacy in MIMO systems,” in IEEE ICC, 2026. [Online]. Available: https://arxiv.org/abs/2508.09882 [28] K. Han, K. Meng, and C. Masouros, “Sensing-secure ISAC: Ambiguity function engineering for impairing unauthorized sensing,” IEEE Trans. Wireless Commun., vol. 25, pp. 5386–5400, 2026. [29] J. Yaswanth, M. Katwe, K. Singh, S. Prakriya, and C. Pan, “Robust beamforming design for active-RIS aided MIMO SWIPT communication system: A power minimization approach,” IEEE Trans. Wireless Commun., vol. 23, no. 5, pp. 4767–4785, 2024. [30] L. L. Scharf and C. J. Demeure, Statistical Signal Processing: Detection, Estimation, and Time Series Analysis. Addison-Wesley Publishing Company, 1991. [31] Q. Shi and M. Hong, “Penalty dual decomposition method for nonsmooth nonconvex optimization—Part I: Algorithms and convergence analysis,” IEEE Trans. Signal Process., vol. 68, pp. 4108–4122, 2020. [32] L. Armijo, “Minimization of functions having lipschitz continuous first partial derivatives,” Pacific Journal of Mathematics, vol. 16, no. 1, pp. 1–3, 1966. [33] Q. Wu, S. Zhang, B. Zheng, C. You, and R. Zhang, “Intelligent reflecting surface-aided wireless communications: A tutorial,” IEEE Trans. Commun., vol. 69, no. 5, pp. 3313–3351, 2021. [34] C. Hu, L. Dai, S. Han, and X. Wang, “Two-timescale channel estimation for reconfigurable intelligent surface aided wireless communications,” IEEE Trans. Commun., vol. 69, no. 11, pp. 7736–7747, 2021. [35] E. Björnson and L. Sanguinetti, “Rayleigh fading modeling and channel hardening for reconfigurable intelligent surfaces,” IEEE Wireless Commun. Lett., vol. 10, no. 4, pp. 830–834, 2020. [36] A. Hjørungnes and D. Gesbert, “Complex-valued matrix differentiation: Techniques and key results,” IEEE Trans. Signal Process., vol. 55, no. 6, pp. 2740–2746, 2007.