{"id":"60caab7d-7b12-4641-a21b-7fd44d7dddc7","arxiv_id":"2501.06798","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"An SDR-based jammer can inject fake targets into an OFDM WLAN sensing receiver and invalidate real target echoes by forcing synchronization and exploiting carrier frequency offset.","lead":"This paper shows that a software-defined radio can impersonate a Wi-Fi sensing target and jam the legitimate sensing picture by forcing the receiver to synchronize to the attacker. If real, it means WLAN sensing needs physical-layer security work before it is used in safety-relevant applications.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The attack requires Bob to synchronize to Eve, but the paper's sync model and experiments omit the 802.11 preamble; until a standards-compliant NDP receiver is shown to lock onto Eve, the central claim is unproven.","rationale":"The reader's weakest assumption and this stress-test converge: forced synchronization is the critical enabler, and it is validated only under a simplified single-OFDM-symbol sync model. I agree with the CONDITIONAL verdict because the theoretical construction is coherent and the simulation/experiment alignment is supportive, but the missing standard preamble is a real gap rather than a cosmetic detail. The paper's own footnote and Section VI-A acknowledgments make the gap explicit. A standards-compliant receiver has a state machine that looks for L-STF periodicity, estimates CFO from L-LTF, and checks PHY header fields; a stronger arbitrary OFDM burst is not automatically selected as the sync reference. This is exactly the condition that must hold for Eq. 12 to describe the receiver output. The proposed test is feasible and binary: either a full-preamble spoofed NDP is accepted and the predicted RDM appears, or it is not. Because the concern does not refute the model under the paper's assumptions but does invalidate the claim for unmodified commercial WLAN sensing unless tested, the verdict remains CONDITIONAL; no adjustment is needed.","tokens_in":20861,"tokens_out":6488,"duration_ms":69851,"concrete_test":"Implement a full 802.11ac NDP receiver (e.g., MATLAB WLAN Toolbox or gr-ieee802-11) with Alice transmitting a legitimate NDP and Eve transmitting a spoofed full NDP at JSR = 10-12 dB, Eve CFO offset 5 ppm, and Eve's VHT-LTF carrying ar H \\odot S for an artificial target at (10 m, 5 m/s). Record whether Bob's L-STF/L-LTF acquisition locks to Eve, whether L-SIG/VHT-SIG-A pass decoding and CRC, and whether the VHT-LTF channel estimate reproduces Eq. 12 with the artificial target. If Bob rejects Eve's frame or locks to Alice, the central claim fails for standard receivers; if it locks, the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing step is the claim that Bob can be forced to synchronize to Eve (Section III-B3). The supporting model uses a lag-1 autocorrelator over repeated OFDM symbols separated by Ts (Appendix A, Eq. 4), with CFO estimated from the phase of that correlation. That is not how an 802.11ac receiver acquires a frame: packet detection and CFO estimation are done on L-STF and L-LTF, and the receiver validates L-SIG/VHT-SIG-A before using VHT-LTF for channel estimation. The paper explicitly simplifies the NDP to 'only the VHT-LTF' (Section II-B2), and the experiments omit L-STF/L-LTF as 'straightforward to implement' (Section VI-A), so neither the model nor the experiment tests whether a standard receiver locks to Eve. Footnote 2 concedes that the CFO phase in Eq. 4 uses Ts and would need To for standard compliance, which still is not the L-STF short-symbol correlation. If Eve must mimic the whole preamble and pass PHY validation, the 3 dB power rule for a single correlation peak is insufficient; a standards-compliant receiver could reject Eve's frame or continue tracking Alice. Without this link, the RDM manipulation in Eq. 12 is not established for real WLAN sensing.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper considers an OFDM-based WLAN sensing system in which Alice transmits periodic NDPs, Bob performs lag-1 autocorrelation synchronization and RDM-based radar processing, and Eve, after eavesdropping the unprotected sensing negotiation, transmits OFDM symbols modulated by an artificial channel transfer function. The core modeling result is Eq. (12): once Bob is forced to synchronize to Eve, the estimated CTF separates into G1 = B0 ⊙ H̄, which injects artificial targets and their combinations with real Eve-Bob targets, and G2 = H′ ⊙ C, which spreads real surveillance peaks into ICI ridges. The paper proposes strategies A1-A3 for target spoofing and B1-B2 for surveillance invalidation, analyzes them qualitatively in Table IV, evaluates them in Monte Carlo simulations with CFAR detection, and demonstrates the RDMs on USRP X310 hardware. It concludes that above about 10 dB JSR and 3 ppm CFO difference, target spoofing and deceptive jamming are highly effective.","tokens_in":16,"tokens_out":12016,"duration_ms":191622,"significance":"If the forced-synchronization precondition holds, the paper is a useful contribution: it shows that arbitrary target injection and surveillance invalidation are possible without DRFM hardware, quantifies operational regimes via Monte Carlo, and validates the RDM phenomenology on SDRs. The high-level framework in Eqs. (8)-(17) is coherent, the thresholds such as 3 ppm and 10 dB JSR emerge from the simulations rather than being forced, and the four combined strategies are demonstrated on hardware. However, the paper's central precondition, that Bob locks onto Eve, is neither modeled nor experimentally tested with a standards-compliant 802.11ac preamble, and the analytic ICI term in Eq. (12) is presented in a form that needs clarification. The significance is therefore conditional on closing these gaps.","major_comments":[{"comment":"The forced-synchronization step is the load-bearing precondition for Eq. (12), but it is modeled and tested with a frame reduced to a single VHT-LTF-like OFDM symbol used for both synchronization and channel estimation. A standards-compliant 802.11ac NDP receiver performs packet detection and CFO estimation on L-STF/L-LTF, validates L-SIG/VHT-SIG-A, and only then uses VHT-LTF for channel estimation. The lag-1 autocorrelation in Eq. (4) over symbols separated by Ts (or To per Footnote 2) is not the L-STF short-symbol correlator. Section VI-A explicitly omits L-STF/L-LTF as straightforward to implement, so the paper has not shown that a real receiver locks to Eve when Eve must mimic the full preamble. This unproven link is central to the spoofing/jamming claim in Section VII; please add a preamble-aware synchronization model and a full-NDP simulation or experiment.","section":"§II-B2, §III-B3, §VI-A, Appendix A"},{"comment":"Equation (12) is presented as an exact decomposition, but the ICI treatment appears inconsistent with the standard CFO model. The matrix P in Eq. (15) is a full Q×Q coupling matrix, and the LS channel estimate under CFO takes the form of a matrix-vector product over subcarriers, not an elementwise Hadamard product with a single matrix C. For BPSK training, the correct expression is Ĥ_q[m] = Σ_i P_{q,i} S_i[m] S_q[m] H′_i[m] Λ_{m,m}, which cannot be written as H′ ⊙ C for a C that is independent of H′. Please clarify whether Eq. (12) is an approximation, state the conditions under which it holds, or correct the model; as written, the statement in Section III-C2 that the ICI term spreads energy across range is not a direct consequence of Eq. (16).","section":"§III-B4, Eq. (15)"},{"comment":"For strategy A2 (selective target injection), the experiments bypass the AoA estimation stage and compute the angles manually before designing the precoder. This validates beamforming with known angles but does not validate the claimed capability to obtain those angles stealthily from the negotiation phase via MUSIC or ESPRIT. The text should either validate the full A2 chain or state this limitation explicitly.","section":"§VI-A, §VI-B2"},{"comment":"The experimental validation is qualitative: the comparison with simulations is based on visual inspection of RDMs, and no detection probability or CFAR-based KPI is reported for the hardware results, although the paper identifies target PD as the main KPI. Please add quantitative experimental metrics or explicitly limit the experimental claims to RDM phenomenology.","section":"§VI-B3"}],"minor_comments":[{"comment":"The text says 'following a short inter-frame space (SISF)'; this should be SIFS (short interframe space).","section":"§II-B2"},{"comment":"The sentence says the expected number of detected targets is calculated using the analytical expression in (13), but Eq. (13) defines G1; the reference should be corrected or the missing derivation should be added.","section":"§V-B6"},{"comment":"The coordinates of Eve and the target are both given as (5m,10m); if this is intentional, please explain, since it affects the bistatic geometry and the A2 nulling scenario, and if it is a typo, correct it.","section":"Table V"}],"recommendation":"major_revision","confidential_remarks":"The manuscript's own Footnote 2 and Section VI-A concede the central simplification of the sensing frame. I am not convinced that the attack transfers to a standards-compliant NDP receiver without additional modeling and validation, so I recommend major revision rather than acceptance. The paper is otherwise technically coherent and the extension of the conference paper [33] is substantive enough for journal publication if the synchronization gap and the ICI modeling issue are addressed."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper gives a clean model for spoofing and deceptive jamming in WLAN sensing and backs it with SDR experiments showing that a few dB of JSR lets Eve inject fake targets and wash out real ones. The genuinely new piece is CFO-based forced synchronization, which removes the random time-alignment dependence of their RadarConf24 work and makes the deception deterministic. The strategy taxonomy (A1-A3, B1-B2) is useful, and the full-chain simulations match the experiments in the RDM shapes. They are also honest about the simplification: they explicitly say the NDP is reduced to only the VHT-LTF, and the experiments omit L-STF and L-LTF as \"straightforward to implement.\"\n\nThe soft spots are in proportion to how central they are. The biggest is the preamble. They model synchronization with a lag-1 autocorrelator over repeated OFDM symbols separated by Ts, and the footnote concedes that a standards-compliant version would have to use To. Real 802.11ac/ax receivers do packet detection on the L-STF short symbols, then validate L-SIG and VHT-SIG-A before using VHT-LTF. Neither the model nor the experiments test whether a standards-compliant Bob locks to Eve or rejects her frame. The 3 dB rule for a single correlation peak is not enough to establish the central claim. This is a real gap, not a cosmetic one. It could be closed with an experiment using a full NDP, but as it stands the attack is proven for a simplified receiver, not for WLAN sensing as deployed. Two smaller items: strategy A2 is validated with the AoA estimation stage bypassed (angles computed manually), and A3 is not validated at all. No code or data are released, so the experiments cannot be independently checked.\n\nWho gets value from this? Researchers working on 802.11bf security, physical-layer attacks on JCAS, and countermeasures. The paper deserves a serious referee because the framework is coherent and the vulnerability is plausible, but the referee should push hard on the synchronization-to-Eve link. My recommendation: send to peer review, and require either a standard-compliant demonstration or a much more careful argument about why the simplified sync model carries over.","headline":"A genuinely useful framework for spoofing and deceptive jamming in WLAN sensing, but the load-bearing claim that a standard 802.11 receiver can be forced to synchronize to the jammer is only shown for a simplified preamble-less model.","tokens_in":21669,"tokens_out":1982,"would_cite":true,"duration_ms":21892,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that an SDR attacker can hijack a WLAN sensing receiver's synchronization, then inject fake targets and erase real ones via standardized OFDM training symbols.","keywords":["WLAN sensing","joint communication and sensing","target spoofing","deceptive jamming","OFDM","carrier frequency offset","range-Doppler map","software-defined radio"],"falsifier":"Run the same attack against a standards-compliant IEEE 802.11ac null-data-packet receiver that first processes L-STF and L-LTF for joint time-frequency synchronization: if the receiver still synchronizes to Alice's LOS peak (or rejects Eve's preamble) when Eve is 10 dB stronger, the forced-synchronization premise fails; conversely, observing Bob's range-Doppler map show the fake target and ICI ridges would confirm it.","tokens_in":20667,"feed_emoji":"📡","tokens_out":8841,"duration_ms":67138,"temperature":0.7,"pith_summary":"WLAN sensing treats Wi-Fi's OFDM signals as radar pulses, so a receiver's range-Doppler map is only as trustworthy as the training symbols it synchronizes to. This paper tries to establish that an attacker with a software-defined radio can break that trust without specialized digital radio-frequency memory hardware: by transmitting standardized OFDM symbols loaded with a fake channel response and making that signal arrive stronger than the legitimate one, Eve can force Bob to synchronize to her and then populate his range-Doppler map with arbitrary fake targets while smearing real targets into noise-like ridges. If the claim holds, a commodity attacker can spoof and jam WLAN sensing in the same transmission. The authors support it with a mathematical model of the jammed channel estimate, a qualitative comparison of jamming strategies, simulations of target detection probability, and indoor experiments with USRP radios.","feed_headline":"A Wi-Fi jamming signal can inject fake targets and erase real ones","feed_subtitle":"Software-defined radios can spoof Wi-Fi sensing maps without costly DRFM hardware, the paper shows.","key_machinery":"The load-bearing mechanism is Bob's lag-1 autocorrelation synchronization: Bob computes $\\Xi[k] = \\sum_{n=-Q_{\\mathrm{cp}}}^{Q} r[n+k,m] r^*[n+k,m+1]$ and locks to the largest peak. Eve exploits this by ensuring $20\\log_{10}(|\\alpha_0^{(b)}|) - 20\\log_{10}(|\\alpha_0|) > 3$ dB, so Bob estimates Eve's CFO and arrival time instead of Alice's. The second piece is the standardized training symbol $\\mathbf{S}$: because it is a known BPSK sequence, Eve can generate an artificial channel transfer function $\\bar{\\mathbf{H}} = \\mathbf{F}_Q^H \\bar{\\mathbf{Y}}_j \\mathbf{F}_M = \\mathbf{1} + \\bar{a}\\mathbf{d}(\\bar{\\tau})\\mathbf{b}^H(\\bar{f})$ by reversing the radar processing chain, transmit $\\bar{\\mathbf{H}} \\odot \\mathbf{S}$, and thereby place a fake target at any delay-Doppler cell. Equation (12) is the resulting decomposition of Bob's estimated channel transfer function into Eve's contribution $\\mathbf{B}_0 \\odot \\bar{\\mathbf{H}}$, the desynchronized surveillance channel multiplied by the ICI matrix $\\mathbf{C}$, and noise.","core_discovery":"The paper's central claim is that a WLAN sensing receiver that synchronizes by picking the strongest peak of a lag-1 autocorrelation can be hijacked: if the attacker's signal arrives at Bob at least 3 dB stronger than Alice's line-of-sight signal, Bob locks to Eve's timing and carrier frequency offset. From that point the standardized OFDM training structure lets Eve fabricate the entire channel estimate. Bob's estimated channel transfer function becomes Eq. (12), $\\hat{\\mathbf{H}}_j = \\mathbf{B}_0 \\odot \\bar{\\mathbf{H}} + \\mathbf{H}' \\odot \\mathbf{C} + \\mathbf{Z}$, where the first Hadamard product carries Eve's artificial range-Doppler map (including a fake target at an arbitrary delay-Doppler cell) and the second product turns Alice's desynchronized surveillance channel into CFO-induced inter-carrier interference ridges that replace real target peaks. The paper argues, and demonstrates by simulation and USRP experiments, that an SDR without DRFM can therefore both inject arbitrary artificial targets and invalidate real surveillance targets whenever the jamming-to-signal ratio is above 8-12 dB and the CFO difference is at least about 3 ppm (6 ppm for 802.11ac-class subcarrier spacing).","pith_inferences":["Beyond the paper: a receiver that uses a fixed, narrow timing window based on round-trip-time distance estimates would shut down the 'preceding jamming signal' variant (Case 1), but would still face the forced-synchronization variant (Case 2) whenever Eve's signal is stronger.","Beyond the paper: the cleanest countermeasure suggested by the model is to randomize or authenticate the training symbols per null data packet so that Eve cannot precompute $\\bar{\\mathbf{H}} \\odot \\mathbf{S}$, and to make synchronization robust to the strongest-peak rule, e.g., by verifying the candidate peak against the expected LOS delay.","Beyond the paper: the same Hadamard-product structure likely applies to other OFDM-based JCAS systems that reuse training fields for sensing, so the attack is not limited to 802.11ac-class WLAN; testing it on 802.11ax/be NDP frames would show how broadly the vulnerability extends.","Beyond the paper: the experiments do not include L-STF and L-LTF, so a fair next test is to check whether a real receiver locks to Eve when the full NDP preamble is mimicked; until then, the practical efficacy in standards-compliant deployments remains an open question."],"forward_implications":["Above 8-12 dB JSR and with a CFO difference of roughly 3 ppm (6 ppm for 312.5 kHz subcarrier spacing), Bob's probability of detecting the real target collapses while the artificial target is detected, so spoofing and deceptive jamming succeed together.","Narrower subcarrier spacing, as in 802.11ax (78.125 kHz), makes the surveillance channel more fragile: the real target's detection probability drops once CFO exceeds about 1 ppm.","Combining selective target injection (beamforming toward Bob with a null toward other paths) with a preceding jamming signal produces the cleanest deception: Bob sees only the artificial target, no true targets and no ridges.","The presence of CFO-induced ridges is a detectable fingerprint: a receiver that sees ridges can infer it is being jammed, and Eve can unintentionally hide her own fake target when ridges align with it.","Because Eve can update the artificial target parameters across snapshots following Newtonian kinematics, she can make the fake target trackable, forcing Bob's tracking filter to follow it."],"supporting_citations":[{"why":"supplies the WLAN sensing framework, the NDPA/NDP frame structure, and the unprotected sensing negotiation that Eve eavesdrops on.","marker":"[1]"},{"why":"prior work on preamble injection and spoofing attacks in Wi-Fi networks that this paper adapts from throughput attacks to sensing.","marker":"[4]"},{"why":"the authors' earlier conference paper that first showed time-synchronization-based deceptive jamming in WLAN sensing and is extended here with joint synchronization and CFO.","marker":"[33]"},{"why":"provides the joint time-frequency synchronization scheme that Bob implements as a lag-1 autocorrelation.","marker":"[36]"},{"why":"gives the robust OFDM frequency and timing synchronization approach whose strongest-peak rule Eve exploits.","marker":"[37]"},{"why":"supplies the ICI matrix model $\\mathbf{C}=\\mathbf{P}\\mathbf{S}\\boldsymbol{\\Lambda}$ used to describe CFO-induced ridges in the jammed channel estimate.","marker":"[38]"},{"why":"the baseband receiver design reference for the claim that Bob synchronizes to the largest amplitude peak at the correlator output.","marker":"[42]"},{"why":"prior work on interference in OFDM radars that explains the ridge pattern replacing real target peaks.","marker":"[44]"}],"fun_headline_variants":["Wi-Fi attackers can spoof sensing maps with cheap SDRs","Jamming Wi-Fi sensing: fake targets, erased real ones","SDRs can hijack Wi-Fi sensing without DRFM hardware","Wi-Fi sensing vulnerable to spoofing and jamming attacks","Cheap radios can forge and erase Wi-Fi sensing targets"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The attack assumes Bob's receiver actually locks to the strongest autocorrelation peak and that Eve can learn the sensing parameters from the unprotected negotiation; the experiments also omit the real 802.11 preamble fields (L-STF and L-LTF), so the paper has not demonstrated that a standards-compliant NDP receiver locks to Eve when the full preamble must be mimicked.","fun_headline_variants_meta":{"raw":{"variants":["Wi-Fi attackers can spoof sensing maps with cheap SDRs","Jamming Wi-Fi sensing: fake targets, erased real ones","SDRs can hijack Wi-Fi sensing without DRFM hardware","Wi-Fi sensing vulnerable to spoofing and jamming attacks","Cheap radios can forge and erase Wi-Fi sensing targets"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000681,"raw_usage":{"total_tokens":3098,"prompt_tokens":955,"completion_tokens":2143,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":571,"completion_tokens_details":{"reasoning_tokens":2056}},"tokens_in":571,"tokens_out":2143,"duration_ms":13687,"temperature":1.0,"reasoning_tokens":2056,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T20:49:33.588056+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the same attack against a standards-compliant IEEE 802.11ac null-data-packet receiver that first processes L-STF and L-LTF for joint time-frequency synchronization: if the receiver still synchronizes to Alice's LOS peak (or rejects Eve's preamble) when Eve is 10 dB stronger, the forced-synchronization premise fails; conversely, observing Bob's range-Doppler map show the fake target and ICI ridges would confirm it.","supporting_citations":[{"cited_title":"An Overview on IEEE 802.11bf: WLAN Sensing","cited_arxiv_id":"2207.04859","evidence_quote":"supplies the WLAN sensing framework, the NDPA/NDP frame structure, and the unprotected sensing negotiation that Eve eavesdrops on."},{"cited_title":"Preamble injection and spoofing attacks in Wi-Fi networks,","cited_arxiv_id":null,"evidence_quote":"prior work on preamble injection and spoofing attacks in Wi-Fi networks that this paper adapts from throughput attacks to sensing."},{"cited_title":"Deceptive jamming in WLAN sensing,","cited_arxiv_id":null,"evidence_quote":"the authors' earlier conference paper that first showed time-synchronization-based deceptive jamming in WLAN sensing and is extended here with joint synchronization and CFO."},{"cited_title":"A time and frequency synchronization scheme for multiuser OFDM,","cited_arxiv_id":null,"evidence_quote":"provides the joint time-frequency synchronization scheme that Bob implements as a lag-1 autocorrelation."},{"cited_title":"Robust frequency and timing synchronization for ofdm,","cited_arxiv_id":null,"evidence_quote":"gives the robust OFDM frequency and timing synchronization approach whose strongest-peak rule Eve exploits."},{"cited_title":"Horlin and A","cited_arxiv_id":null,"evidence_quote":"supplies the ICI matrix model $\\mathbf{C}=\\mathbf{P}\\mathbf{S}\\boldsymbol{\\Lambda}$ used to describe CFO-induced ridges in the jammed channel estimate."},{"cited_title":"Chiueh, P.-Y","cited_arxiv_id":null,"evidence_quote":"the baseband receiver design reference for the claim that Bob synchronizes to the largest amplitude peak at the correlator output."},{"cited_title":"Impact of interference on OFDM based radars,","cited_arxiv_id":null,"evidence_quote":"prior work on interference in OFDM radars that explains the ridge pattern replacing real target peaks."}],"review_version":1}