ConceptioArchivearXiv CS
arXiv CSopen access

Security Analysis of RIS-Assisted Physical-Layer Authentication Over Multipath Channels

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

Security Analysis of RIS-Assisted Physical-Layer Authentication Over Multipath Channels Linda Senigagliesi1 , Anna V. Guglielmi2 , Marco Baldi3 , and Stefano Tomasin2 ETIS UMR 8051, CYU, ENSEA, CNRS, Cergy, France, 2 University of Padova, Italy, 3 Università Politecnica delle Marche, Ancona, Italy email: [email protected],{annavaleria.guglielmi, stefano.tomasin}@unipd.it, [email protected]

arXiv:2607.05042v1 [cs.IT] 6 Jul 2026

1

Abstract—In physical layer authentication, verification of a user’s identity is based on the characteristics of the transmission channel through which signals are delivered to the authenticator (Bob). In this paper, we assume that the signals received by Bob pass through a reconfigurable intelligent surface (RIS) (controlled by Bob) and that the legitimate transmitter (Alice) is equipped with one antenna. Conversely, the attacker (Trudy) has multiple antennas and uses precoding to deceive Bob’s verification. Assuming that Trudy knows all the channel matrices, we first derive her optimal attack strategy. Then, we analyse the conditions under which the channel estimated by Bob is indistinguishable when either Alice or Trudy is transmitting. When Trudy has a single antenna, we show that the indistinguishability condition cannot be met when the channels to the RIS are the result of propagation over multiple paths. For single-path line-of-sight (LOS) conditions, instead, Trudy can impersonate Alice although transmitting from a different position. We verify these results numerically and assess the security of the considered scenario, even when the indistinguishability conditions cannot be met. Index Terms—Physical Layer Authentication, Reconfigurable Intelligent Surface, Impersonation Attack, Line of Sight.

I. I NTRODUCTION Authentication is the process by which a receiver can verify the identity of a transmitter. Authentication mechanisms based on cryptographic algorithms remain secure provided that no computational breakthrough occurs, i.e., for new attack algorithms or the introduction of quantum computing. They typically entail high complexity, unsuitable in scenarios with limited power and computational resources, e.g., the Internet of Things. Alternative approaches are based on informationtheoretic or physical-layer security, which are not affected by the computational capability of attackers. In physical layer authentication (PLA), transmitters are differentiated only based on the electromagnetic characteristics of their transmission channels. PLA has been studied in the literature for quite some time, using various features of received signals, such as channel frequency response (CFR) and channel impulse response (CIR), to distinguish a legitimate user from a potential attacker, [1]. M. Baldi is supported by the project SERICS (PE00000014) under the MUR National Recovery and Resilience Plan, funded by the European Union - Next Generation EU. M. Baldi and S. Tomasin are in part supported by European Union (EU) COST Action CA22168—Physical Layer Security for Trustworthy and Resilient 6G Systems (6G-PHYSEC). The work of L. Senigagliesi and S. Tomasin are supported by the European Commission through the Horizon Europe/Smart Networks and Services Joint Undertaking (JU SNS) Project ROBUST-6G under Grant 101139068.

Recently, the angle of arrival (AoA) of the signal has been shown to be a robust feature for PLA, [2], [3]. In addition, user classification has been done using both classical statistical approaches and modern tools based on machine learning. In parallel, wireless communications have evolved through the introduction of RISs that, with their ability to shape the propagation environment, improve energy efficiency, reduce hardware complexity, and improve coverage. RISs have also been considered to improve PLA. Variable and random configurations can be set on the RIS to generate challenge-response pairs and propose a challenge-response PLA protocol based on the channel state information (CSI), [4]–[7]. In [8], the authors consider CFR-based PLA in the presence of a hybrid RIS, also capable of acting as a receiver and estimating the channels of impinging signals; thus, this estimate is exploited for authentication. Authentication in a scenario with an RIS is studied also in [9], however, also exploiting pre-shared keys used for asymmetric cryptography; thus, it cannot be considered working purely at the physical layer. In [10] PLA based on the CIR in a dynamic wireless communication environment, is studied, and convolutional neural networks are used to perform classification: this overcomes the limitations of the classical statistical approach based on hypothesis testing when the wireless channel is time-varying. In this paper, we consider that signals received by Bob are reflected through a RIS that he controls, and the legitimate transmitter, Alice, is equipped with a single antenna. In contrast, the adversary, Trudy, possesses multiple antennas and employs precoding techniques to attempt to bypass the verification process. Assuming Trudy has full knowledge of all channel matrices, we first determine her optimal attack strategy. We then examine the conditions under which Bob’s channel estimation is identical regardless of whether Alice or Trudy is transmitting. When Trudy is limited to a single antenna, we derive conditions based on the angle of arrival at the RIS. Our analysis shows that under multipath propagation conditions to the RIS, the indistinguishability requirement cannot be satisfied. However, in the case of a single-path lineof-sight (LOS) scenario, Trudy can successfully impersonate Alice by transmitting from a different location. These findings are supported by numerical simulations. We also evaluate the system’s security in situations where indistinguishability cannot be achieved. The rest of the paper is organized as follows. Section II

Alice transmits suitable pilot symbols to let Bob estimate the channel, which is used for authentication. The pilot signal is assumed to be known to Trudy. We denote as T the matrix of the channel from Trudy to the RIS. To impersonate Alice, Trudy precodes the transmitted signal (including pilots) with vector q and the resulting TrudyRIS-Bob channel is then

scatterer scatterer Trudy

Bob

Alice

hTRB = GΩT q ∈ CM ×1 . RIS

(3)

All channels (f , G, and T ) are time-invariant. A. Channel Model

scatterer

scatterer

Fig. 1. System model.

presents the system model. Section III describes the PLA mechanism and, then, in Section IV, a security analysis is performed, focusing on conditions that make the attack indistinguishable from a legitimate signal. Numerical results are discussed in Section V and, finally, conclusions are drawn in Section VI.

In the presence of objects around the transmitter and the receiver, the transmitted signal reaches the receiver through multiple paths. At the mmWave band, channels typically have only a few relevant paths; thus, we use a geometric model for their description. We define the K-size array response column vector for angle of arrival (AoA) θ as 2π 2π 1 eK (θ) = √ [1, e−j λc d sin θ , . . . , e−j(K−1) λc d sin θ ]T . (4) K For a generic channel with L paths, we define the L-paths array response matrix with AoA angles θ = [θ1 , ..., θL ]T as

EN (θ) = [eN (θ1 ), ..., eN (θL )]. II. S YSTEM M ODEL We consider the uplink scenario shown in Fig. 1, where the base station (BS) (Bob) aims to authenticate a user equipment (UE) (Alice) in a single-input multiple-output (SIMO) communication system, with Alice equipped with a single antenna and Bob with a uniform linear array (ULA) of M antennas. The signal transmitted by Alice reaches Bob through a reconfigurable intelligent surface (RIS), while a blockage obstructs the Alice-Bob direct link. An attacker device, Trudy, attempts to impersonate Alice by transmitting messages that Bob may mistake as originating from Alice. Trudy is equipped with a ULA of NT antennas. We also assume that no direct communication is possible between Trudy and Bob, and that all of her messages are transmitted through the RIS. Transmissions occur at millimeter-wave (mmWave) frequencies. ULA antennas are uniformly spaced by a distance d = λc /2, where λc is the carrier wavelength. Moreover, we assume that the field of view of Bob is 120◦ . The RIS, controlled by Bob, has N reflecting elements spaced by the same distance d. The n-th element, n = 0, 1, . . . , N −1, of the RIS introduces a phase shift ωn = ejφn on the equivalent baseband signal and has unitary gain. The RIS configuration matrix is defined as Ω = diag{[ejφ0 , . . . , ejφN −1 ]}.

(1)

We denote the baseband equivalent vector for the channel from Alice to the RIS as f ∈ CN ×1 , the channel matrix from the RIS to Bob as G ∈ CM ×N . Thus, the resulting Alice-RISBob cascaded channel is hARB = GΩf .

(2)

(5)

Let Lf be the number of paths between Alice and the RIS, and ϕf,l , θf,l , and γf,l represent the angle of departure (AoD) at Alice, the AoA at the RIS, and the complex path gain for the l-th path i.e., l = 1, ..., Lf , respectively. Let us also define ϕf = [ϕf,1 , ..., ϕf,Lf ]T and θf = [θf,1 , ..., θf,Lf ]T . Moreover, 1Lf , EN (θf ), and Γf = diag([γf,1 , ..., γf,Lf ]T ) denote the L-size column vector of ones corresponding to Alice’s array response matrix, the RIS array response matrix, and diagonal path gain matrix, respectively. The baseband channel matrix between Alice and the RIS is modeled as [11] s Lf KN X γf,l eN (θf,l )eH f= 1 (ϕf,l ) = EN (θf )Γf 1Lf . Lf l=1 (6) The RIS-Bob channel matrix is modeled as H G = EM (θG )ΓG EN (ϕG ) ∈ CM ×N ,

(7)

where θG and ϕG are the vectors of AoAs to Bob and AoDs from the RIS, and ΓG is the diagonal matrix of path gains. Similarly, the Trudy–RIS channel is modeled as H T = EN (θt )Γt EN (ϕt ) ∈ CN ×NT , t

(8)

where θt and ϕt are the vectors of AoAs to the RIS and AoDs from Trudy, and Γt is the diagonal Lt × Lt matrix of the Lt path gains. B. Assumptions on Trudy Trudy is assumed to perfectly know all the channels, including the Alice-RIS and RIS-Bob channel matrices f and G. This assumption is very generous to Trudy, because she

typically is neither co-located with Alice nor Bob. Moreover, the channels corresponding to f and G are only experienced in cascade through the RIS. Note that Alice and Bob can easily estimate the overall cascaded Alice-RIS-Bob channel, while it is harder for them, and even more so for Trudy, to estimate the individual channels represented by f and G. Consequently, considering the attacker with complete channel knowledge will result in a conservative estimate of the security performance, corresponding to a worst-case condition for the legitimate receiver. We also assume that Trudy chooses the transmit power without restrictions. Finally, we assume that neither Alice nor Bob knows the instantaneous channels with Trudy nor their statistics. In particular, Alice and Bob do not know where Trudy is located, so they cannot infer anything about the propagation of signals transmitted or received by Trudy.

Since we do not exploit any information on Trudy’s channel for this test, we resort to the likelihood test (LT) on ĥ, based on the norm-2 distance between the current channel estimate and that obtained in the association phase [13], i.e., ζ = ∥ĥ − h̄∥2 .

(11)

The LT providing a decision Ĥ between the two hypotheses is obtained by thresholding ζ as follows ζ < τ : Ĥ = H0 ,

ζ ≥ τ : Ĥ = H1 ,

(12a)

where τ is a suitably chosen threshold.

C. Communication-Optimal RIS Configuration Since the RIS is used for communication purposes between Alice and Bob, its configuration should be optimized accordingly by Bob. We indicate the communication-optimal RIS configuration maximizing the spectral efficiency as Ω = diag(ej φ̄1 , . . . , ej φ̄N ),

hARB s0 + n, where n is a circularly-symmetric complex Gaussian vector with zero mean and variance σn2 per entry. Bob obtains an estimate of the channel as n r̂ = hARB + . (10) ĥ = s0 s0

(9)

where φ̄n , n = 0, . . . , N − 1, represent the communicationoptimal phase shifts of the N RIS elements. Various works in the literature have proposed methods for optimizing the RIS configuration. Here we consider the technique of [12]. III. P HYSICAL L AYER AUTHENTICATION M ECHANISM We consider a physical layer authentication (PLA) mechanism, where Bob aims at deciding between the two hypotheses H0 : the signal comes from Alice, H1 : the signal comes from the attacker Trudy. To this end, the channel vector estimated by Bob operates as a distinguishing feature between the transmissions done by Alice and Trudy. The PLA mechanism includes two phases, namely the association and verification phases. Since we assume that Bob does not know the cascade channel when Trudy is transmitting, we will not exploit this information for PLA. In the association phase, Alice transmits some known pilot signal s0 to Bob, who exploits its knowledge to obtain a noisy estimate of hARB that we denote h̄. We assume that such a phase is authenticated at a higher layer; thus, it provides a reliable estimate of the Alice-Bob channel. The association phase has to be repeated every time the Alice-Bob channel changes. In the subsequent verification phase, upon reception of a signal Bob estimates the channel over which such a signal traveled, assuming that s0 was transmitted, and obtaining the estimate ĥ. Then, Bob performs a test on the obtained estimate to decide whether the transmitter was Alice or not. Let r denote the signal received by Bob when Alice is transmitting. Assuming that Bob knows s0 and the communicationoptimal RIS configuration Ω, the received signal is r =

A. Security Metrics Two possible error events might occur in the authentication mechanism: the false alarm (FA), when Bob discards a message as forged by Trudy while it is coming from Alice, and the misdetection (MD), when Bob accepts a message coming from Trudy as legitimate. Specifically, an FA occurs when, under hypothesis H0 , ζ ≥ τ , whereas, an MD occurs when, under hypothesis H1 , ζ < τ . As security metrics, we then consider the probabilities of FA and MD, i.e. PFA = P[ζ ≥ τ |H0 ] ,

PMD = P[ζ < τ |H1 ] .

(13)

IV. S ECURITY A NALYSIS We now analyze the security of PLA for the considered scenario. The obtained results will highlight how the structure of the channel, due to the few reflection paths, has an impact on the error probabilities of PLA. First, we compute the optimal precoding vector for Trudy that maximizes the probability of her attack succeeding, i.e., maximizes the MD probability. Then, we discuss the impact of the number of paths on the security. Let us define the cascade channels when Alice and Trudy are transmitting as H cA = EM (θG )ΓG EN (ϕG )ΩEN (θf )Γf 1Lf , H H cT = EM (θG )ΓG EN (ϕG )ΩEN (θt )Γt EN (ϕt )q t

= c′T q ,

(14) (15)

where q is the precoding vector used by Trudy to try to falsify Alice’s channel. Then, the channel estimated by Bob when Alice is transmitting can be written as ĥA = cA +n, while the estimated channel when Trudy is transmitting with precoding vector q is ĥT = c′T q + n̂. A. Trudy Optimal Transmit Power Trudy’s goal is to maximize the probability that Bob accepts her message as legitimate, i.e., to maximize PMD . Considering the likelihood (11) used in the LT, Trudy must choose q to

minimize ζ, as Trudy knows the Alice-Bob cascade channel cA . However, she does not know the noise of the estimate obtained by Bob in the association phase. Therefore, we obtain the following impersonation optimization problem q

= arg min ∥c′T q − cA ∥2 . q

for µA,l1 l2 = (sin ϕG,l1 −sin θf,l2 ), and zT as a LG -size vector with entry [zT ]l1 =

l2 =1

(16)

′ H H H H ′ = r H cA − c H A cT q − q cT r + q cT cT q,

= cTH (c′T cTH )−1 cA .

(18)

B. Indistinguishability Conditions When ζ = 0, the Alice-Bob channel is indistinguishable from the Trudy-Bob channel, and Bob cannot detect an attack. Let us investigate which are the conditions under which this may occur. Clearly, when Trudy is in the same position as Alice, they have the same channel to Bob. The interesting point here is to understand if there are other positions of Trudy that (together with some optimum precoding vector q) provide the same indistinguishability condition. Such positions may exist, since Bob estimates only the cascade channel from Alice, and signals transmitted by Trudy pass through the same RIS used by Alice. From (16) we note that indistinguishability is achieved when the system of complex linear equations c′T q = cA

(19)

is solvable. However, determining general conditions on the Trudy-RIS channel that ensure the solution is challenging. Therefore, in the following, we focus on the special case in which also Trudy has a single transmit antenna, for which a theoretical analysis is feasible. C. Indistinguishability Conditions for NT = 1 Let us focus on the case in which Trudy has a single antenna and both Alice-RIS and Trudy-RIS channels have L paths. Thus (15) becomes H cT = EM (θG )ΓG EN (ϕG )ΩEN (θt )Γt 1L q ,

(20)

and the precoding vector boils down to the scalar q. To understand the conditions for indistinguishability in this H case, let us define W = EM (θG )EM (θG ) ∈ CLG ×LG as the matrix with entry [W ]ii = M and M X

e−j(m−1)κ(sin θG,i −sin θG,j ) ,

for i ̸= j (21)

m=1

zA as a LG -size vector with entry l1 = 1, . . . , LG Lf

[zA ]l1 =

X l2 =1

e−j[κ(n−1)µT ,l1 l2 +φ̄n ] ,

γf,l2

N X n=1

(23)

n=1

e−j[κ(n−1)µA,l1 l2 +φ̄n ] ,

(22)

(24)

cTH c′T = zTH ΓH G W ΓG zT ,

(25)

′ H H cH A cT = zA ΓG W ΓG zT ,

(26)

H ′ H cTH cA = zTH ΓH G W ΓG zA = (cA cT ) .

(27)

(17)

and by nulling the derivative with respect to q, the solution of the minimization problem (16) is

[W ]ij =

N X

H H cH A cA = zA ΓG W ΓG zA ,

ζ = ||c′T q − cA ||2

q

γt,l2

for µT,l1 l2 = sin ϕG,l1 − sin θt,l2 . We also have

Now, we have

Lt X

Now, substituting (24), (25), (26), and (27) into (17), and for W̃ = ΓH G W ΓG , we have H H ζ = zA W̃ zA − qzA W̃ zT − q ∗ zTH W̃ zA + qq ∗ zTH W̃ zT . (28) H H Defining b=zA W̃ zA , c=zA W̃ zT , and d=zTH W̃ zT , (28) becomes ζ = d|q|2 − cq − (cq)∗ + b . (29)

We are now ready to investigate the indistinguishability condition. Replacing q = βejα in (29), such condition can be written as dβ 2 − 2|c|β cos(α + ρ) + b = 0 ,

(30)

with c = |c|e . We firstly note that (by definition) ζ ≥ 0 and it is minimized for α⋆ = −ρ. Substituting α⋆ in (30), we have dβ 2 − 2|c|β + b = 0, which has solutions only if |c|2 − bd ≥ 0, or, equivalently, if H H |zA W̃ zT |2 ≥ (zA W̃ zA )(zTH W̃ zT ).

(31)

However, by the Cauchy-Schwarz inequality H H |zA W̃ zT |2 ≤ (zA W̃ zA )(zTH W̃ zT ),

(32)

and thus (31) p equality. However, this happens if pmust hold with and only if W̃ zA and W̃ zT are linearly dependent. Note that this does not generally imply zA and zT to be linearly dependent unless W̃ is a full rank matrix. By definition, the rank of W̃ is the same of W (due to ΓG being diagonal), G which is full rank if and only if the vectors {eM (θG,i )}L i=1 (i.e., the columns of EM (θG )) are linearly independent. This condition is satisfied when LG ≤ M and the angles θG,i related to the different paths are distinct, i.e., sin θG,i ̸= sin θG,j , ∀i, j = 1, . . . , LG , with i ̸= j. Since each entry of W is given by the inner product of array response vectors (21), which depend only on sin(·) and are periodic over π for ULAs with half-wavelength spacing, we must have θG,i ̸= θG,j + u π,

(33)

for any integer u. Since we assume Bob has a field of view of 2 3 π, we are also ensuring W to be full rank when LG ≤ M . In this case, it can be stated that (31) holds with equality if and only if zA and zT are linearly dependent. From the definitions

in (22) and (23), we conclude that the indistinguishability conditions require that Alice and Trudy have the same number of paths (Lt = Lf ), the AoA angles at the RIS corresponding to Alice and Trudy match exactly, yielding sin θf,l = sin θt,l ,

l = 1, . . . , Lt = Lf ,

(34)

and their path gains are proportional, i.e., γf,l = λ γt,l ,

l = 1, . . . , Lt = Lf .

(35)

These are then the indistinguishability conditions for NT = 1. D. Single-Path RIS-Bob Channel When the RIS–Bob channel is single-path (LG =1), zA and zT collapse to complex scalars. This dimensionality reduction significantly simplifies the attacker’s task, as linear dependence now can be trivially achieved in C, where any two non-zero scalars are always linearly dependent if one is a scaled version of the other. Hence, it becomes easier for the attacker to find values of α and β such that (30) is satisfied. Indeed, in this case, even when Trudy does not show the same angles and path gains of Alice (zT ̸= zA ), indistinguishability can still be achieved by appropriately tuning α and β so that (30) holds. In formulas, this happens for α = −ρ + uπ, u even, α ∈ [−π, π], and β =

|zA | |zT |

(36)

α = −ρ + uπ, u odd, α ∈ [−π, π], and β = −

|zA | . |zT |

(37)

Fig. 2. Contour plot of ζ (under hypothesis H1 ) for LG =1, Lf =Lt =3, M =16, N =64. The red cross marks the values of α and β that minimize ζ. We consider different angles and path gains for the Trudy-RIS and Alice-RIS channels.

or

The case LG =1 inherently poses a higher impersonation risk, as it offers fewer spatial degrees of freedom to differentiate between Alice and Trudy. This result could also be directly inferred from the structure of the cascaded channels in (14) and (20). Since the common H (ϕG ) of the RIS-Bob channel has rank term EM (θG )ΓG EN 1, the cascaded channels lie in the same one-dimensional subspace. Therefore, no matter how different Trudy’s and Alice’s angles and path gains are, once they pass through it, the result is always confined to a single spatial direction, limiting Bob’s ability to distinguish between them. In fact, any differences in Alice and Trudy transmissions are effectively collapsed into a single direction by the rank-one projection of G and, then, Trudy can more easily mimic Alice’s cascaded channel. V. N UMERICAL R ESULTS In this section, we assess the performance of the considered authentication method investigating both single-path (i.e., LG = 1) and multipath (i.e., LG = 3) scenarios for the RISBob channel. We consider Lf = Lt = 3 and path gains γf,l , γG,l , and γt,l distributed as CN (0, 1). We assume that the angles at the RIS and the  AoDs from the transmitters are uniformly distributed in − π2 , π2 , while  the AoAs at Bob are uniformly distributed in the range − π6 , π6 . Angles and gains are generated independently for Alice and Trudy. Bob is

Fig. 3. Contour plot of ζ (under hypothesis H1 ) for LG =Lf =Lt =3, M =16, N =64. The red cross marks the values of α and β that minimize ζ. We consider different angles and path gains for the Trudy-RIS and Alice-RIS channels.

equipped with M ∈ {4, 8, 16, 32} antennas, while Alice and Trudy are single-antenna devices. The number of RIS elements is N = 64. Fig. 2 shows a contour plot of the test function ζ under attack conditions for a single-path RIS-Bob channel (i.e., LG = 1). Note that different angles and path gains for the Trudy-RIS and Alice-RIS channels are considered. The red cross marks the values of α and β that minimize ζ: when Trudy chooses the value of q ⋆ corresponding to these optimal values of α and β, we have ζ = 0. Similarly, Fig. 3 shows a contour plot of the test function ζ under attack conditions for LG = 3. Comparing Figs. 3 and 2, we observe that, for LG > 1, even if Trudy uses the optimal

VI. C ONCLUSIONS We analyzed the security of a RIS-assisted PLA scheme in scenarios with no direct link between the transmitter and the receiver, and multipath propagation conditions of the channels to and from the RIS. Assuming the worst case scenario of an attacker Trudy having full channel knowledge, we determined her optimal attack strategy. Then, we examined the conditions under which Bob’s channel estimation may have the same statistics regardless of whether Alice or Trudy is transmitting, deriving the conditions based on the AoAs at the RIS for single antenna attacker. Numerical results show that when the RIS–Bob channel is single-path, impersonation is feasible even with mismatched channel parameters. Conversely, increasing the number of RIS–Bob paths significantly enhances authentication robustness by limiting the attacker’s ability to mimic the legitimate user. Fig. 4. DET curves for different value of M , LG ∈ {1, 3}. The crosses mark the points for which PMD = PFA .

q ⋆ , the resulting minimum of the test function ζ is strictly greater than zero. This confirms that, unlike the scenario with LG = 1, perfect impersonation becomes impossible to achieve. Indeed, the presence of LG paths increases the rank of the RIS–Bob channel matrix, thereby introducing additional spatial diversity that makes it harder for Trudy to align her cascade channel with that of Alice by setting the proper q ⋆ . The result is also confirmed by Fig. 4, which shows the detection error trade-off (DET) curves for different values of M and LG ∈ {1, 3}. The crosses mark the points for which PMD = PFA . All the curves show that reducing PFA results in an increase in PMD , and vice versa. It can also be noticed that for LG = 1, we have PMD = 1 − PFA , regardless of the number of Bob’s antennas M . In fact, in this case, Trudy can always find an attack strategy that yields to indistinguishability with Alice; thus the probability that Bob decides for hypothesis H1 (i.e., attack condition) is the same irrespective of who is transmitting. For LG > 1, instead, the optimal attack does not usually lead to indistinguishability (since the AoAs from Trudy and Alice are independent). Indeed, the DET curves do not start from the top-left corner as is typically the case. This is due to the statistical nature of the test and imperfections in Trudy’s impersonation of Alice. In fact, when LG > 1, the perfect alignment between Trudy’s and Alice’s cascaded channels is not achievable, even if Trudy uses q ⋆ . Hence, the minimum achievable PMD is strictly less than 1, emphasizing a significant limit on the success of the impersonation attack. Hence, we can conclude that a higher LG enhances authentication robustness by limiting the ability of Trudy to fully mimic Alice’s cascaded channel. Moreover, we observe that, as M increases, the DET curves move towards smaller PMD for a target PFA . This shows that having more receive antennas allows for better distinction between Alice and Trudy.

R EFERENCES [1] J. Zhang, F. Ardizzon, M. Piana, G. Shen, and S. Tomasin, “Physical layer-based device fingerprinting for wireless security: From theory to practice,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 5296–5325, 2025. [2] T. M. Pham, L. Senigagliesi, M. Baldi, G. P. Fettweis, and A. Chorti, “Machine learning-based robust physical layer authentication using angle of arrival estimation,” in GLOBECOM 2023 - 2023 IEEE Global Communications Conference, 2023, pp. 13–18. [3] M. Srinivasan, L. Senigagliesi, H. Chen, A. Chorti, M. Baldi, and H. Wymeersch, “Aoa-based physical layer authentication in analog arrays under impersonation attacks,” in 2024 IEEE 25th International Workshop on Signal Processing Advances in Wireless Communications (SPAWC), 2024, pp. 496–500. [4] S. Tomasin, H. Zhang, A. Chorti, and H. V. Poor, “Challenge-response physical layer authentication over partially controllable channels,” IEEE Communications Magazine, vol. 60, no. 12, pp. 138–144, 2022. [5] S. Tomasin, T. N. M. M. Elwakeel, A. V. Guglielmi, R. Maes, N. Noels, and M. Moeneclaey, “Analysis of challenge-response authentication with reconfigurable intelligent surfaces,” IEEE Trans. Inf. Forensics Security, vol. 19, pp. 9494–9507, Sep. 2024. [6] A. V. Guglielmi and S. Tomasin, “Fast iterative configuration of reconfigurable intelligent surfaces in mmWave systems,” in Proc. 2023 IEEE Global Commun. Conf., pp. 631–636, Dec. 2023. [7] L. Crosara, A. V. Guglielmi, N. Laurenti, and S. Tomasin, “Divergenceminimizing attack against challenge-response authentication with IRSs,” in Proc. IEEE Int. Conf. on Comm. Workshops (ICC worksh.), 2024. [8] M. M. Selim and S. Tomasin, “Physical layer authentication with simultaneous reflecting and sensing RIS,” in 2023 IEEE 97th Vehicular Technology Conference (VTC2023-Spring), 2023, pp. 1–5. [9] P. Zhang, Y. Teng, Y. Shen, X. Jiang, and F. Xiao, “Tag-based PHYlayer authentication for RIS-assisted communication systems,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 6, pp. 4778–4792, 2023. [10] H. Liu, L. Li, X. Tang, W. Lin, F. Yang, T. Yin, and Z. Han, “Reconfigurable intelligent surface-aided physical layer authentication with deep learning,” in 2024 IEEE 99th Vehicular Technology Conference (VTC2024-Spring), 2024, pp. 1–6. [11] K. F. Masood, J. Tong, J. Xi, J. Yuan, and Y. Yu, “Inductive matrix completion and root-MUSIC-based channel estimation for intelligent reflecting surface (IRS)-aided hybrid MIMO systems,” IEEE Transactions on Wireless Communications, vol. 22, no. 11, pp. 7917–7931, 2023. [12] A. M. Sayeed, “Optimization of reconfigurable intelligent surfaces through trace maximization,” in Proc. IEEE Inter. Conf. on Commun. Workshops (ICC Workshops), Jun. 2021, pp. 1–6. [13] P. Baracca, N. Laurenti, and S. Tomasin, “Physical layer authentication over MIMO fading wiretap channels,” IEEE Trans. Wirel. Commun., vol. 11, no. 7, pp. 2564–2573, 2012.

Record · ID 343365 · SHA-256 fff8b0b2f0327c4a
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.