{"id":"c3faaa39-74c2-43bb-968a-bce817e46b26","arxiv_id":"2411.17830","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"The paper jointly optimizes BS and RIS beamforming against a full-duplex active eavesdropper using alternating WMMSE and semidefinite relaxation, and simulations show secrecy rate improvements from the RIS.","lead":"Researchers propose an alternating optimization algorithm to maximize secrecy rate in a RIS-aided wireless network where a full-duplex attacker simultaneously eavesdrops and jams. The work matters for 6G security because it shows how the attacker's jamming signal, reflected by the smart surface, can reduce both the user's quality and the attacker's own interception.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Eq. (37a) makes the passive-beamforming subproblem inequivalent to the secrecy-rate objective, so the central optimality claim is not supported as printed.","rationale":"The reader's weakest_assumption (perfect and complete CSI of all channels, including the attacker's, with v fixed and known) is a legitimate limitation. However, the more immediate threat to the central claim is internal: the passive-beamforming subproblem as printed is not equivalent to maximizing the secrecy rate, so even under the ideal CSI assumption the algorithm lacks a valid foundation. The reader noticed Eq. (37a) as doubtful but did not elevate it to the main load-bearing concern; I do. A second, related modeling concern is that Section II assumes perfect self-interference cancellation at the full-duplex eavesdropper, yet the eavesdropper's rate in (4) includes the reflected jamming term HIeθGeI v as noise; a perfect-SIC eavesdropper should cancel its own transmitted jamming signal, which would further change the numerical secrecy-rate conclusions. I keep the verdict UNCHANGED at CONDITIONAL because the derivation errors are potentially fixable in revision, but they must be corrected and re-validated before the optimality claim can be credited.","tokens_in":20556,"tokens_out":14330,"duration_ms":126166,"concrete_test":"Re-derive Eq. (37a) symbolically from Eq. (34) using Lemma 1 with scalar auxiliary variables ε4, ε5, keeping the '+1' terms in A2/A3; if the printed signs, the duplicated σu², and the EBIu/EBID subscript do not match the derivation, the passive subproblem is not equivalent to secrecy-rate maximization. Alternatively, implement the passive update exactly as printed on one random channel realization with w fixed and compute Rs before and after the update; if Rs decreases, the passive step does not solve the claimed subproblem.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central claim is that Algorithm 1 maximizes the secrecy rate Rs in (5), which requires each alternating subproblem to be solved correctly. The passive-beamforming subproblem is not correctly derived. Starting from (34), Rs = log(T1) - log(T2) - log(T3) + log(T4), with T1 = Tr(EeIuΘ)+σu²+Tr(EBIDΘ), T2 = Tr(EeIeIΘ)+σe²+Tr(EBIeΘ), T3 = Tr(EeIuΘ)+σu², and T4 = Tr(EeIeIΘ)+σe². Applying Lemma 1 to -log(T2) and -log(T3) gives a maximization over ε4, ε5 of log(T1) - ε4T2 + log ε4 + log(T4) - ε5T3 + log ε5. Instead, (37a) is written as a minimization, the first log term has the wrong sign and a duplicated σu², the subscript EBIu/EBID is inconsistent, and the ε4, ε5 terms have signs that do not match Lemma 1. Additionally, A2 and A3 in the active-beamforming section drop the '+1' identities from the normalized log expressions, so the WMMSE reformulation of the eavesdropper rate is also not equivalent. Since Algorithm 1's passive update (step 2d) solves problem (37), the printed algorithm is not maximizing (5). This is an internal correctness issue independent of CSI: even with perfect CSI and known v, the proposed iteration need not increase Rs.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies an RIS-aided downlink in which a full-duplex active eavesdropper simultaneously overhears the legitimate transmission and sends jamming signals. The authors formulate a secrecy-rate maximization over the BS beamforming vector and the RIS phase shifts, and they propose an alternating optimization algorithm that combines WMMSE-based active beamforming with semidefinite relaxation for the RIS phase design. Numerical results are provided for secrecy rate versus transmit power, numbers of antennas, and RIS elements.","tokens_in":57,"tokens_out":13033,"duration_ms":272073,"significance":"If the derivation and algorithm were correct, the paper would offer a useful design procedure for a timely scenario: physical-layer security against active eavesdropping in RIS-assisted networks. The use of AO with WMMSE and SDR is a standard and reasonable approach, and the inclusion of direct channels between BS and user/eavesdropper is more realistic than in some related work. However, the central claim that Algorithm 1 maximizes the secrecy rate is not supported as printed because the passive-beamforming subproblem is derived with incorrect signs and optimization direction, and the active-beamforming reformulation has a related equivalence error. The paper does not provide code or machine-checked proofs, and its numerical claims rest on the flawed derivations.","major_comments":[{"comment":"The passive-beamforming subproblem is not equivalent to the secrecy-rate objective. Starting from (34), Rs = log(T1) - log(T2) - log(T3) + log(T4), and applying Lemma 1 to -log(T2) and -log(T3) gives a maximization over ε4, ε5 of log(T1) - ε4 T2 + log ε4 + log(T4) - ε5 T3 + log ε5. In contrast, (37a) is written as a minimization, the first log term has a negative sign and a duplicated σ_u^2, the matrix EBIu appears instead of EBID, the ε4 and ε5 terms have signs opposite to those required by Lemma 1, and -log(ε4) - log(ε5) should be +log(ε4) + log(ε5). Consequently, step 2d of Algorithm 1 solves a different problem, and the printed iteration is not guaranteed to increase Rs. This is a load-bearing error for the paper's central claim.","section":"III-B, Eq. (37a)"},{"comment":"The WMMSE reformulation of A3 drops the identity matrix. The expression in (16), A3 = max_{ε3>0} log(ε3) - Tr[ε3((HIeI vv^H H_IeI^H) + (HBeI ww^H H_BeI^H))], corresponds to -log det of the sum without the identity, whereas the actual eavesdropper rate term is log det(I + HIeI vv^H H_IeI^H + HBeI ww^H H_BeI^H). Although the update for ε3 in (24) correctly includes I, the objective used in the w-subproblem (25)-(26) is not equivalent to Re, so the active-beamforming update does not maximize the original secrecy rate either.","section":"III-A, Eq. (16)"},{"comment":"The assumption of perfect self-interference cancellation at the full-duplex eavesdropper is inconsistent with the eavesdropper rate expression. If the eavesdropper perfectly cancels its own jamming signal as stated before (2), then the term HIe θ GeI v a in (2) should be removed before defining Re, and the denominator in (4) should not contain ∥(HIe θ GeI)v∥^2. As printed, the jamming signal appears as self-interference in the eavesdropper's received signal, contradicting the stated assumption and biasing the numerical results. The model should be corrected, e.g., by removing that term or by explicitly modeling residual self-interference.","section":"II, Eqs. (2) and (4)"},{"comment":"The paper's abstract and conclusion state that the proposed algorithm maximizes the secrecy rate, but no global optimality proof is given and the alternating algorithm is at best a local method. Moreover, the convergence criterion in Algorithm 1 divides by Rs^{t-1}, which can be zero, and monotonic increase of Rs is not established and does not follow from the incorrect subproblem (37a). The authors should either prove convergence of the corrected iteration or soften the optimality claim.","section":"III-C, Algorithm 1 and Abstract"}],"minor_comments":[{"comment":"The symbol θ is used both for the diagonal reflection matrix and for the vector of phase shifts; the notation should be made consistent, e.g., by writing θ = diag(φ) and using a distinct symbol for the augmented vector in (29b).","section":"II, Eqs. (1)-(4)"},{"comment":"There is a misplaced parenthesis in the expression for ε4: it should read ε4 = 1 / (Tr(EeIeI Θ) + Tr(EBIe Θ) + σ_e^2), not Tr(EBIe Θ + σ_e^2).","section":"III-B, Eq. (38)"},{"comment":"The displayed equation for the active beamforming subproblem contains corrupted placeholder tokens and should be typeset cleanly; the readable portions omit the '+1' terms in the logarithms that are needed for the WMMSE equalities.","section":"III-A, Eq. (10a)"},{"comment":"The complexity expression O(T2(((K^2 + 2Nr^3) + T1(L+1)^4.5))log(ϵ)) mixes an inner iteration count T1 and an outer iteration count T2 in a way that should be clarified, and the use of log(ϵ) inside the big-O is unusual.","section":"III-C, complexity analysis"},{"comment":"The sentence 'without reflective elements, the secrecy rate remains constant regardless of the number of such elements added' is confusing; it presumably means the 'without RIS' benchmark curve is flat, which should be stated more clearly.","section":"IV, Fig. 4 description"}],"recommendation":"major_revision","confidential_remarks":"The manuscript would benefit from a thorough editing pass; in particular, Eqs. (10) and (37a) are severely corrupted. The authors should be asked to provide a clean, correct derivation of the passive-beamforming subproblem, to address the self-interference modeling inconsistency between Eqs. (2) and (4), and to re-run the simulations after those corrections. The topic is timely for the physical-layer-security community, but the current version does not support its central optimality claim."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the scenario is a legitimate new combination and the AO machinery is standard; the printed math, however, has load-bearing errors, so the central optimality claim is not supported as written. It is fixable and worth a referee's time, but it needs a major revision.\n\nWhat's actually new: a full-duplex attacker that both eavesdrops and jams, with a direct BS-user link and an RIS, is not in the cited prior work. The problem (maximize Rs subject to power and unit-modulus constraints) is clearly posed, and the decomposition into active WMMSE and passive SDR is sensible. The paper is self-contained, with no fitted parameters or self-citation, and the simulation trends are plausible. Credit is due for those.\n\nWhere it wobbles: the stress-test holds up. Starting from (34), the WMMSE reformulation in (37a) has the wrong sign on the first log term, a duplicated σ_u^2, an inconsistent subscript (EBIu vs EBID), and it is written as a minimization when the equivalent problem is a maximization. The ε4/ε5 terms also have signs that do not follow from Lemma 1. In the active-beamforming part, A2 and A3 drop the '+I' identities, so the eavesdropper rate reformulation is not equivalent either. Since Algorithm 1 solves exactly these printed subproblems, the claimed monotonic convergence in Fig. 5 is not backed by the derivation. The contribution bullet also contradicts the simulation text on whether more attacker antennas increase or decrease secrecy rate. The perfect-CSI assumption, including knowledge of v, is heavy but standard in this niche. There is no strong baseline and the Monte Carlo curves show no error bars or averaging details.\n\nProportionately: these are serious but curable errors. The intended derivations are recoverable from the standard WMMSE/SDR toolkit, and the core idea is plausible. It is not a fatal flaw, but the paper cannot be accepted without a careful rewrite of Section III and a check of the algorithm's monotonicity claim.\n\nWho this is for: PLS researchers working on RIS-aided systems against active adversaries. A serious referee should engage with it; the paper deserves peer review rather than a desk reject, with expectation of heavy revision. I would not cite it in its current form.","headline":"A legitimate new scenario with standard tools, but the printed derivations have load-bearing errors—most importantly Eq. (37a)—so the central optimality claim is not supported as written; it is fixable and deserves a serious referee.","tokens_in":21387,"tokens_out":8584,"would_cite":false,"duration_ms":68680,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A proposed algorithm jointly tunes a base station's beamformer and an RIS's phase shifts to maximize the secrecy rate against a full-duplex attacker that both eavesdrops and jams.","keywords":["physical layer security","reconfigurable intelligent surface","full-duplex active eavesdropping","secrecy rate","alternating optimization","beamforming design","jamming"],"falsifier":"A concrete observation that would settle the central claim: run the proposed alternating-optimization algorithm with imperfect channel estimates for the attacker's links (or with an attacker that changes $\\mathbf{v}$ during transmission) and check whether the predicted secrecy rate still holds; if the rate collapses, the perfect-CSI and fixed-$\\mathbf{v}$ assumptions are the load-bearing part of the design.","tokens_in":20293,"feed_emoji":"🔒","tokens_out":11314,"duration_ms":80269,"temperature":0.7,"pith_summary":"The paper studies a base station with multiple antennas serving a single user with the help of a reconfigurable intelligent surface (RIS), while a full-duplex active attacker both listens and transmits jamming signals. It claims that jointly optimizing the base station's beamforming vector and the RIS's phase shifts maximizes the secrecy rate, defined as the difference between the user's achievable rate and the attacker's wiretap rate. The proposed method splits this non-convex problem into two sub-problems solved iteratively by alternating optimization, with the active beamforming step handled through a weighted MMSE reformulation and the passive phase-shift step through semidefinite relaxation. A sympathetic reader would care because an attacker that both eavesdrops and jams is a harsher and more realistic threat than a passive eavesdropper, and the numerical results quantify both the damage done by jamming and the value of the RIS in mitigating it.","feed_headline":"Joint BS-RIS tuning maximizes secrecy against active eavesdroppers","feed_subtitle":"A full-duplex attacker that snoops and jams is the hardest case; here both beamformers are optimized to counter it.","key_machinery":"The central object is the effective channel that bundles the direct and RIS-reflected links at each receiver: at the user, $\\mathbf{h}_{Bu}^H + \\mathbf{h}_{Iu}^H \\boldsymbol{\\theta} \\mathbf{H}_{BI}$; at the eavesdropper, $\\mathbf{H}_{Be} + \\mathbf{H}_{Ie} \\boldsymbol{\\theta} \\mathbf{H}_{BI}$. The attacker's full-duplex jamming signal enters as extra interference terms, $|(\\mathbf{g}_{eu}^H + \\mathbf{h}_{Iu}^H \\boldsymbol{\\theta} \\mathbf{G}_{eI})\\mathbf{v}|^2$ at the user and $\\|\\mathbf{H}_{Ie} \\boldsymbol{\\theta} \\mathbf{G}_{eI} \\mathbf{v}\\|^2$ at the eavesdropper. Two reformulation tools carry the optimization: Lemma 1, the identity $-\\log \\det(\\mathbf{E}) = \\max_{\\mathbf{S} \\succeq 0} -\\operatorname{Tr}(\\mathbf{S}\\mathbf{E}) + \\log|\\mathbf{S}| + N$ with optimum $\\mathbf{S} = \\mathbf{E}^{-1}$, which turns the log-ratio secrecy objective into a tractable weighted mean-square-error form; and the variable change $\\boldsymbol{\\phi} = [1, \\varphi]^H$ that rewrites every RIS-coupled quadratic term as $\\operatorname{Tr}(\\mathbf{E}_{\\cdot} \\boldsymbol{\\Theta})$ with $\\boldsymbol{\\Theta} = \\boldsymbol{\\phi}\\boldsymbol{\\phi}^H$, allowing the unit-modulus phase constraints to be handled by semidefinite relaxation and Gaussian randomization.","core_discovery":"The central claim is that the secrecy rate $R_s = [R_u - R_e]^+$ can be maximized by an alternating optimization algorithm that jointly designs the base station transmit beamforming vector $\\mathbf{w}$ and the RIS phase-shift matrix $\\boldsymbol{\\theta}$. The algorithm converts the rate expressions into a weighted MMSE form, alternates between updating auxiliary weights and the beamformer for fixed RIS phases, and then solves the RIS phase sub-problem by semidefinite relaxation with Gaussian randomization. Under the assumption of perfect channel state information for every link, including the attacker's channels, and with the attacker's jamming beamforming vector $\\mathbf{v}$ treated as fixed and known, the procedure yields a design that increases the secrecy rate as the BS power, the number of BS antennas, and the number of RIS elements grow, and decreases as the number of attacker antennas grows.","pith_inferences":["Beyond the paper: the perfect-CSI and fixed-attacker-beamforming assumptions are the load-bearing premises; a natural extension is a robust formulation that only knows the attacker's channels within an error ball, or a game-theoretic version where the attacker adapts $\\mathbf{v}$ to the legitimate beamformer.","Beyond the paper: the WMMSE-plus-SDR machinery could be transplanted to neighboring problems such as multi-user RIS-aided secrecy, weighted sum secrecy rate with artificial noise, or RIS-aided covert communication, where similar log-ratio objectives appear.","Beyond the paper: because the numerical results rest on a simulated Rician channel model, a testable extension is to verify the reported trends (secrecy rate versus RIS elements and attacker antennas) under different channel distributions or in a measurement campaign.","Beyond the paper: the paper assumes perfect self-interference cancellation at the full-duplex attacker; relaxing that to realistic residual self-interference could change the effective jamming power and is worth checking."],"forward_implications":["If the algorithm is correct, it gives a concrete design procedure for securing an RIS-aided link against an attacker that simultaneously eavesdrops and jams, under the perfect-CSI assumption.","The wider secrecy-rate gap between jammed and non-jammed scenarios as RIS elements increase means that the value of deploying an RIS grows precisely in the presence of active attacks.","Secrecy rate scales with BS transmit power and the number of BS antennas, so conventional spatial and power resources remain effective defenses under jamming.","Each additional attacker antenna lowers the secrecy rate, so the legitimate network must account for the attacker's hardware scale when sizing its own array."],"supporting_citations":[{"why":"Supplies the secrecy-rate expression $R_s = [R_u - R_e]^+$ and the Rician channel model used in simulations, and justifies dropping the positive-part operation.","marker":"[27]"},{"why":"Provides the weighted MMSE (WMMSE) and block-coordinate-descent framework that the active-beamforming sub-problem uses to convert the non-convex rate objective.","marker":"[28]"},{"why":"Supplies Lemma 1, the log-determinant identity used to introduce auxiliary weight matrices for the rate terms.","marker":"[29]"},{"why":"Cited for the alternating-optimization structure and for the semidefinite relaxation and Gaussian randomization used to recover the RIS phase-shift vector.","marker":"[22]"},{"why":"Cited for the Gaussian randomization procedure used when the rank-1 phase solution is not directly obtained.","marker":"[30]"},{"why":"Cited as the method by which perfect CSI of the eavesdropper's channels can be obtained, by treating the eavesdropper as an untrusted active user.","marker":"[8]"}],"fun_headline_variants":["Joint BS-RIS beamforming thwarts full-duplex eavesdroppers","Optimized RIS and BS counter active jamming eavesdropper","Secrecy rate maximized against full-duplex attacker with AO","RIS-aided security: joint design defeats active eavesdropping","Alternating optimization boosts secrecy in RIS networks"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The scheme requires the legitimate system to know perfectly every channel in the network, including the channels to and from the attacker, and to know the attacker's jamming beamforming vector $\\mathbf{v}$, which is treated as fixed and known throughout.","fun_headline_variants_meta":{"raw":{"variants":["Joint BS-RIS beamforming thwarts full-duplex eavesdroppers","Optimized RIS and BS counter active jamming eavesdropper","Secrecy rate maximized against full-duplex attacker with AO","RIS-aided security: joint design defeats active eavesdropping","Alternating optimization boosts secrecy in RIS networks"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000227,"raw_usage":{"total_tokens":1480,"prompt_tokens":965,"completion_tokens":515,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":581,"completion_tokens_details":{"reasoning_tokens":430}},"tokens_in":581,"tokens_out":515,"duration_ms":4848,"temperature":1.0,"reasoning_tokens":430,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T11:48:09.093368+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete observation that would settle the central claim: run the proposed alternating-optimization algorithm with imperfect channel estimates for the attacker's links (or with an attacker that changes $\\mathbf{v}$ during transmission) and check whether the predicted secrecy rate still holds; if the rate collapses, the perfect-CSI and fixed-$\\mathbf{v}$ assumptions are the load-bearing part of the design.","supporting_citations":[{"cited_title":"Secure Wireless Communication via Intelligent Reflecting Surface,","cited_arxiv_id":null,"evidence_quote":"Supplies the secrecy-rate expression $R_s = [R_u - R_e]^+$ and the Rician channel model used in simulations, and justifies dropping the positive-part operation."},{"cited_title":"An iteratively weighted MMSE approach to distributed sum-utility maximization for a MIMO interfering broadcast channel,","cited_arxiv_id":null,"evidence_quote":"Provides the weighted MMSE (WMMSE) and block-coordinate-descent framework that the active-beamforming sub-problem uses to convert the non-convex rate objective."},{"cited_title":"On Robust Weighted-Sum Rate Maximization in MIMO Interference Networks,","cited_arxiv_id":null,"evidence_quote":"Supplies Lemma 1, the log-determinant identity used to introduce auxiliary weight matrices for the rate terms."},{"cited_title":"Securing Wireless Transmissions with RIS-Receiver Coordination: Passive Beamforming and Active Jamming,","cited_arxiv_id":null,"evidence_quote":"Cited for the alternating-optimization structure and for the semidefinite relaxation and Gaussian randomization used to recover the RIS phase-shift vector."},{"cited_title":"Joint Active and Passive Beamforming for Reconfigurable Intelligent Surface Enhanced Symbiotic Radio System,","cited_arxiv_id":null,"evidence_quote":"Cited for the Gaussian randomization procedure used when the rank-1 phase solution is not directly obtained."},{"cited_title":"Physical Layer Security Enhancement Exploiting Intelligent Reflecting Surface,","cited_arxiv_id":null,"evidence_quote":"Cited as the method by which perfect CSI of the eavesdropper's channels can be obtained, by treating the eavesdropper as an untrusted active user."}],"review_version":1}