{"id":"1f0b6272-9ee5-4204-af0b-d0ec2967be86","arxiv_id":"2505.04968","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"An artificial-noise dynamic precoder for near-field multiuser systems scrambles passive eavesdroppers in both angle and distance while preserving legitimate user rates.","lead":"This paper designs a wireless precoding method that scrambles messages for nearby eavesdroppers without knowing where they are, while keeping signals clean for intended users. It exploits near-field spherical waves and large antenna arrays to focus security in both direction and distance, which far-field methods cannot do.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The AN-nulling condition in Sec. III-D is stated at the wrong layer: because the analog precoder F is rank-deficient (N_RF < N), the correct condition for zero AN at an eavesdropper is F^H h(re) not in span(F^H h(ru_1),...,F^H h(ru_M)), not h(re) not in span(H_U); the 'any undesired position'…","rationale":"The reader's weakest assumption correctly points to the AN vanishing when the eavesdropper's channel lies in the legitimate-user span. However, the manuscript's stated condition is not merely incomplete; it is stated at the wrong layer. The hybrid architecture inserts AN in the digital domain after the rank-N_RF analog combiner F, so the quantity that matters is F^H h(re), not h(re) itself. Because F^H has a large null space, the set of channel vectors that are invisible to the AN is much larger than the user span. This is a genuine mathematical flaw in the proof of the 'any undesired position' claim, not just an unquantified edge case. At the same time, the paper's core construction and the algebraic steps in Propositions 1 and 2 appear coherent, and the corrected condition may still hold for most physical positions. The numerical test described above would settle whether the flaw has practical consequences for the simulated array geometry. Since the reader already recommended CONDITIONAL and our concern supports that conditional reading without changing the overall verdict, the verdict remains unchanged.","tokens_in":25319,"tokens_out":15226,"duration_ms":163869,"concrete_test":"Numerically evaluate the AN leakage metric gamma(r) = ||H_M^perp F^H h(r)|| / ||F^H h(r)|| over a dense grid of eavesdropper positions in the near-field region, using the paper's setup (N=1600, N_RF=40, M=2). Flag positions that are far from the user span, i.e. with ||h(r)-proj_{span(H_U)}h(r)|| large, but have gamma(r) approximately zero or below a small threshold such as 1%. If any such position exists, the 'any undesired position' guarantee is disproved for the simulated geometry; if gamma(r) is uniformly large away from a small neighborhood of the users, the practical impact of the rank-deficient projection is limited.","verdict_should_be":"UNCHANGED","load_bearing_attack":"In Sec. III-D, after Eq. (35), the paper asserts security when h(re_q) is not in span(h(ru_1),...,h(ru_M)), claiming then H_M^perp F^H h(re_q) != 0. This implication is false for the hybrid architecture. The AN component at the eavesdropper is h(re_q)^H F H_M^perp W0(k), and it vanishes for all W0(k) iff F^H h(re_q) lies in col(H_M) = span(F^H h(ru_1),...,F^H h(ru_M)). Since F is N x N_RF with N_RF < N, F^H has an (N-N_RF)-dimensional null space. Hence every vector h_out = h(ru_m)+z with z in null(F^H) satisfies F^H h_out in col(H_M) while generically h_out is not in span(H_U). The set of channel vectors annihilated by the AN is (N-N_RF+M)-dimensional, much larger than the M-dimensional user span. The paper gives no argument that the 3-D manifold of physical eavesdropper positions avoids this preimage, nor does it quantify the size of near-degenerate regions where the AN component is small. The secrecy maps in Sec. V-G already show outage probability close to 1 near the user positions, consistent with this failure mode. This does not invalidate the algebraic core (Propositions 1-2 are internally sound), but it removes the 'any undesired position' guarantee and requires the claim to be restated in terms of projected channels.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a dynamic hybrid precoding scheme for near-field MU-MISO downlink secrecy. The analog precoder is obtained from the dominant right singular vectors of the legitimate-user channel matrix, and the baseband precoder is a symbol-level ZF design in the equivalent (projected) channel domain, with random artificial noise injected into the null space of the equivalent legitimate-user channel. The authors derive a power-constrained choice of the AN amplitude, expressions for average SINR, achievable rate, secrecy capacity, secrecy outage probability, and a secrecy zone, and support the analysis with simulations including constellation diagrams, BER maps, secrecy maps, and secrecy-rate comparisons against ZF and WMMSE. The paper claims secure transmission at 'any undesired position' without eavesdropper CSI, in both angle and distance dimensions.","tokens_in":25672,"tokens_out":5782,"duration_ms":61871,"significance":"If the central claim were fully supported, the paper would be a useful contribution: it extends artificial-noise directional modulation to multi-user near-field systems with a low-complexity hybrid architecture, gives a closed-form average-SINR analysis, and characterizes secrecy outage and secrecy-zone metrics in the LoS case. The algebraic derivations in Propositions 1 and 2 are internally consistent, the power-constrained AN construction in Algorithm 1 is clearly specified, and the simulation study is reasonably extensive. However, the paper's headline security guarantee rests on a condition about eavesdropper channel vectors that is stated at the wrong layer of the hybrid architecture, and the theoretical secrecy-rate analysis relies on a ratio-of-expectations approximation whose accuracy is not quantified. These issues do not invalidate the algebraic core, but they require the main claims to be restated and further supported before the paper can be accepted.","major_comments":[{"comment":"The security condition is stated incorrectly. The paper claims that secure transmission is ensured when h(re_q) is not in span(h(ru_1),...,h(ru_M)), and that then H_M^\\perp F^H h(re_q) \\neq 0. This implication is false for the hybrid architecture. The AN term at the eavesdropper is h^H(re_q) F H_M^\\perp W0(k), and it vanishes for all W0(k) if and only if F^H h(re_q) belongs to col(H_M) = span(F^H h(ru_1), ..., F^H h(ru_M)). Because F is N x N_RF with N_RF < N, the map F^H has an (N-N_RF)-dimensional null space, so every vector of the form h(ru_m) + z with z in null(F^H) yields zero AN at the eavesdropper while generically lying outside span(H_U). The set of channel vectors annihilated by the AN is therefore (N-N_RF+M)-dimensional, much larger than the M-dimensional user span. The paper gives no argument that the physical positions of eavesdroppers avoid this preimage, and the secrecy maps in Fig. 10 already show outage probability close to 1 near the user positions. The 'any undesired position' claim in the abstract and in Section III-D must be restated in terms of the projected channels, and the size of the protected region should be quantified.","section":"Section III-D, after Eq. (35)"},{"comment":"The average SINR is defined as a ratio of expectations, E[A]/(E[B]+\\sigma^2), rather than the expectation of the SINR ratio. This approximation is exact at the legitimate-user positions because the AN term cancels there and the interference vanishes deterministically, but it is not exact at eavesdropper positions, where the numerator and denominator depend on the same random W(k) and the same channel h(r). The subsequent secrecy-capacity approximation in Eq. (46) inherits this approximation, yet the paper does not provide a bound on the error or a discussion of the regimes in which the approximation is tight. Since the theoretical secrecy-rate claims are central to the paper, the authors should either justify the approximation more rigorously, provide a finite-N error bound, or clearly label the secrecy-rate expressions as heuristic approximations whose accuracy is only demonstrated by simulation.","section":"Section IV-A, Eq. (39)"},{"comment":"The multi-path analysis assumes that the channel at an unintended position r is independent of the legitimate-user channels and therefore independent of W(k), and that its covariance is the same R as that of the legitimate users. In a shared-scatterer geometry, which is the setup used in the simulations of Section V-D, the eavesdropper channels and the user channels are generated from the same scatterer positions, so these assumptions are questionable. The paper should either use a model in which the independence is explicitly enforced or discuss the error introduced when scatterers are shared. This is load-bearing for the claimed applicability of the proposed scheme to multi-path near-field channels.","section":"Section III-E and Eq. (43)"}],"minor_comments":[{"comment":"The phrase 'does not lie in the null subspace of the equivalent baseband channel matrix' is ambiguous; the paper should distinguish between the null space of H_M^H and the orthogonal complement of col(H_M).","section":"Section III-D, sentence before Remark 3"},{"comment":"The value of \\xi is set manually to 2\\times10^{-6} without checking that it satisfies the power constraint in Eq. (22) or explaining how it relates to the closed-form choices in Eqs. (27) and (34); please clarify.","section":"Section V-C3"},{"comment":"The doubly non-central F distribution is introduced without defining its parameters in the notation list; for readability, define the degrees of freedom and non-centrality parameters explicitly in the text rather than only in the PDF expression.","section":"Eq. (62)"},{"comment":"The comparison with ZF and WMMSE in Fig. 9(b) compares the proposed AN-aided scheme against baselines that do not include any AN or security mechanism; the authors should state that this is a comparison against non-secure benchmarks, otherwise the '20% higher secrecy rate' claim may be read as a comparison against secure alternatives.","section":"Section V-E1"},{"comment":"The notation for H_M^\\perp is not defined in the notation list; it is used before its formal definition in Eq. (20) and should be added for completeness.","section":"Throughout"}],"recommendation":"major_revision","confidential_remarks":"The paper's algebraic core is sound, and the topic is timely for near-field physical-layer security. The main concern is that the security argument in Section III-D is stated for the wrong subspace: the AN is nulled whenever F^H h(re) lies in col(H_M), which is a much larger set than span(H_U). This undermines the 'any undesired position' claim in the abstract. This is a fixable issue if the authors restate the condition in the projected domain, quantify the protected region, and temper the corresponding claims. The other concerns (ratio-of-expectations approximation, multi-path independence) are secondary but should be addressed in revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Here's my take for your files.\n\nWhat's actually new: this extends AN-aided dynamic symbol-level precoding to multi-user near-field MU-MISO with a hybrid analog/digital architecture, and it adds a real performance analysis—average SINR, achievable rate, secrecy outage probability via a doubly non-central F distribution, and secrecy-zone maps. The algebraic core, Propositions 1 and 2, is correct. The idea of using the ELAA null space for symbol-level AN without eavesdropper CSI is reasonable, and the complexity claim is credible.\n\nThe main soft spot is Section III-D. The paper says security holds when h(re) is not in the span of user channels, then asserts H⊥_M F^H h(re)≠0. That implication is false for the hybrid architecture. The AN term at the eavesdropper is h^H(re) F H⊥_M W0(k), and it vanishes for all W0(k) when F^H h(re) lies in the column space of H_M = F^H H_U, i.e., in span(F^H h(ru_1),...,F^H h(ru_M)). Because F is N×N_RF with N_RF<N, F^H has an (N−N_RF)-dimensional null space, so the set of channels that the AN cannot touch is (N−N_RF+M)-dimensional—much larger than the M-dimensional user span. The paper never quantifies how likely a random eavesdropper position is to land there, and it does not discuss near-degenerate regions where the AN is small. The 'any undesired position' claim is therefore not supported. The secrecy maps in Section V-G already show outage probability near 1 around the user positions, which is exactly this failure mode, but the paper does not read it that way. This doesn't kill the paper, but the security condition must be restated in terms of F^H h(re), and the claim should be tempered.\n\nTwo smaller points. The 20% secrecy-rate gain is against ZF and WMMSE precoders that do not inject AN; those are not secure baselines, so the gain is demonstrative, not a calibrated advantage. And Eq. (50) uses the eavesdropper position/CSI to set ξ, which is at odds with the passive-eavesdropper premise; it's an analysis device, but should be flagged. The SINR is a ratio-of-expectations approximation and the outage analysis is LoS-limited; both are acknowledged in the text. No code or data, which is a minor reproducibility limitation.\n\nWho it's for: anyone working in near-field physical-layer security or hybrid precoding will find this a useful reference for both the technique and the outage methodology. It deserves a serious referee. I'd send it out, but with the expectation of major revision to fix the guarantee and recalibrate the claims.","headline":"A useful near-field AN-aided precoding paper with a solid algebraic core, but the security guarantee is stated at the wrong layer and needs to be restated.","tokens_in":26261,"tokens_out":5439,"would_cite":true,"duration_ms":50343,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Near-field precoding can scramble passive eavesdroppers' constellations everywhere except the intended users' positions, with no eavesdropper CSI, while keeping zero-forcing user rates.","keywords":["near-field communications","physical layer security","artificial noise","dynamic precoding","hybrid beamforming","MU-MISO","secrecy rate","extremely large-scale antenna arrays"],"falsifier":"Place a passive eavesdropper at the exact coordinates of one legitimate user and run Algorithm 1 over 800 slots; the projection term $H_M^{\\perp} F^H h(r_e)$ is zero there, so the measured constellation should be a static PSK or QAM cloud rather than the scrambled cloud shown for eavesdroppers. A complementary Monte-Carlo check would sample random eavesdropper positions in the near-field region, compute $\\|H_M^{\\perp} F^H h(r_e)\\|$, and compare the fraction of positions with near-zero projection against the paper's claim that security holds at any undesired position.","tokens_in":25059,"feed_emoji":"🔒","tokens_out":8683,"duration_ms":79899,"temperature":0.7,"pith_summary":"Near-field base stations equipped with extremely large arrays can make a transmitted message decodable only at the exact coordinates of the intended users, even when the base station has no information about the eavesdroppers. The paper proposes a dynamic hybrid precoder that adds symbol-level random artificial noise in the null space of the legitimate users' channels, so any other position receives a constellation that changes randomly from slot to slot. It claims this secures both the angular and the distance dimension, works for arbitrary modulation formats and array geometries, and preserves the signal-to-interference-plus-noise-ratio that zero-forcing would give the users. The derived statistical analysis covers average SINR, achievable rate, secrecy capacity, secrecy outage probability, and the secrecy zone, and the simulations report about 20 percent higher secrecy rates than zero-forcing and WMMSE baselines.","feed_headline":"Symbol-level noise scrambles eavesdroppers with no CSI","feed_subtitle":"Near-field arrays secure both angle and distance, lifting secrecy rates about 20% over ZF and WMMSE.","key_machinery":"The load-bearing object is the projection matrix $H_M^{\\perp} = I_{N_{\\mathrm{RF}}} - H_M H_M^{\\dagger}$ onto the null space of the equivalent baseband channel $H_M = F^H H_U$, with $F$ built from the dominant right singular vectors of $H_U$. The random artificial noise $W_0(k)$ has independent entries $\\xi e^{j\\phi_{n,m}(k)}$ with $\\phi_{n,m}(k) \\sim U(0,2\\pi)$, and the projection sends that noise to zero on the legitimate users' subspace while leaving a nonzero random component for any channel outside that subspace. A time-agnostic choice of $\\xi$ from a triangle-inequality bound keeps the total transmit power within $P_t$, giving a low-complexity algorithm whose main cost is one SVD and one projection computation.","core_discovery":"On its own terms, the paper establishes that secure downlink transmission to multiple single-antenna users in the near field does not require eavesdropper CSI. The baseband precoder is written as $W(k) = (H_M^{\\dagger})^H B_M + H_M^{\\perp} W_0(k)$, where $H_M = F^H H_U$ is the equivalent channel after the SVD-based analog precoder $F$, $B_M$ is the diagonal matrix of desired symbol gains, and $W_0(k)$ is a matrix of independent random phases scaled by $\\xi$. The term $H_M^{\\perp} W_0(k)$ lives in the null space of the users' equivalent channel, so it is exactly invisible at the user positions; anywhere else, it survives and randomizes the received constellation at every time slot, preventing an eavesdropper from aggregating symbols across slots. The paper derives the closed-form power-scaling constant $\\xi$, the average SINR, the secrecy capacity, the secrecy outage probability based on the doubly non-central $F$ distribution, and the secrecy zone, and supports the claims with beampattern, BER, and secrecy-rate simulations.","pith_inferences":["The 'any undesired position' statement is shorthand for a graded condition: the noise term is proportional to the projection of the eavesdropper's channel onto the null space, so an eavesdropper whose channel is nearly a combination of the users' channels sees only weak scrambling; quantifying the probability of that event over random placements is a natural next step.","If the null-space condition is read as a design constraint, the legitimate users' coordinates act like a spatial key, and the secrecy level is set by how far an eavesdropper is from the user subspace; this suggests location-based security metrics such as the minimum distance to the subspace for a required secrecy rate.","The imperfect-CSI simulations indicate that position estimation error mainly lowers the intended user's SNR while the eavesdropper remains scrambled, which points to a robustness bound relating the location-error radius to the residual leakage of the noise onto the user subspace.","The same null-space randomization could be transferred to near-field MU-MIMO, wideband OFDM with per-subcarrier projections, or reconfigurable-surface-aided systems, where the channel's position dependence would play the same role."],"forward_implications":["An eavesdropper in the same angular direction as a user but at a different distance receives a scrambled constellation, so near-field security extends along the distance dimension that far-field beamforming cannot control.","Because the design needs only the legitimate users' channels, it works against passive, non-cooperative eavesdroppers and avoids the complexity of CSI-based secrecy beamforming.","Legitimate users keep the SINR of pure zero-forcing, so the security gain does not come from sacrificing their rates.","The closed-form outage probability yields a computable secrecy zone, letting an operator mark the physical regions where an eavesdropper's interception probability stays below a threshold.","When the null space is large enough, roughly RF chains at least twice the number of users, hybrid beamforming matches fully digital performance; when users exhaust the null space, the secrecy gain disappears."],"supporting_citations":[{"why":"Supplies the non-uniform spherical wave near-field channel model and the multipath channel formulation used throughout the paper.","marker":"[7]"},{"why":"Introduces artificial-noise-aided zero-forcing synthesis for secure directional modulation, the conceptual precursor the paper extends to near-field multiuser systems.","marker":"[32]"},{"why":"A near-field secure beamforming scheme that requires eavesdropper CSI and serves as the baseline the proposed method improves upon by removing that requirement.","marker":"[33]"},{"why":"Near-field wideband secure analog beamfocusing approach, another prior work that relies on eavesdropper CSI and motivates the passive-eavesdropper scenario.","marker":"[34]"},{"why":"Near-field directional modulation that supports only a single legitimate user, which the paper extends to multiple users with low complexity.","marker":"[35]"},{"why":"SVD-based low-complexity hybrid precoding whose dominant right-singular-vector selection is used to design the analog precoder F.","marker":"[54]"},{"why":"Establishes zero-forcing precoding and generalized inverses, the baseband solution and channel-hardening rationale underlying the precoder formula.","marker":"[56]"},{"why":"Gives the doubly non-central F distribution representation used to derive the secrecy outage probability and the secrecy zone.","marker":"[59]"}],"fun_headline_variants":["Near-field precoding secures links without eavesdropper CSI","Null-space noise jams eavesdroppers in near-field MISO","Dynamic precoding thwarts eavesdroppers with zero CSI","Near-field beamforming lifts secrecy rate by 20%"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The scheme only works when no eavesdropper sits at a legitimate user's position, or at a spot whose channel is a combination of the users' channels, because in those cases the injected noise cancels out and the eavesdropper sees a stationary, decodable constellation.","fun_headline_variants_meta":{"raw":{"variants":["Near-field precoding secures links without eavesdropper CSI","Null-space noise jams eavesdroppers in near-field MISO","Dynamic precoding thwarts eavesdroppers with zero CSI","Near-field beamforming lifts secrecy rate by 20%"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000592,"raw_usage":{"total_tokens":2819,"prompt_tokens":1033,"completion_tokens":1786,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":649,"completion_tokens_details":{"reasoning_tokens":1716}},"tokens_in":649,"tokens_out":1786,"duration_ms":13082,"temperature":1.0,"reasoning_tokens":1716,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T23:17:03.080477+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Place a passive eavesdropper at the exact coordinates of one legitimate user and run Algorithm 1 over 800 slots; the projection term $H_M^{\\perp} F^H h(r_e)$ is zero there, so the measured constellation should be a static PSK or QAM cloud rather than the scrambled cloud shown for eavesdroppers. A complementary Monte-Carlo check would sample random eavesdropper positions in the near-field region, compute $\\|H_M^{\\perp} F^H h(r_e)\\|$, and compare the fraction of positions with near-zero projection against the paper's claim that security holds at any undesired position.","supporting_citations":[{"cited_title":"Ne ar-ﬁeld communications: A tutorial review,","cited_arxiv_id":null,"evidence_quote":"Supplies the non-uniform spherical wave near-field channel model and the multipath channel formulation used throughout the paper."},{"cited_title":"Artiﬁcial-noise-aided zero- forcing synthesis approach for secure multi-beam directional modulation,","cited_arxiv_id":null,"evidence_quote":"Introduces artificial-noise-aided zero-forcing synthesis for secure directional modulation, the conceptual precursor the paper extends to near-field multiuser systems."},{"cited_title":"Nea r-ﬁeld wideband secure communications: An analog beamfocusing ap proach,","cited_arxiv_id":null,"evidence_quote":"Near-field wideband secure analog beamfocusing approach, another prior work that relies on eavesdropper CSI and motivates the passive-eavesdropper scenario."},{"cited_title":"Ph ysical layer security for near-ﬁeld communications via direction al modulation,","cited_arxiv_id":null,"evidence_quote":"Near-field directional modulation that supports only a single legitimate user, which the paper extends to multiple users with low complexity."},{"cited_title":"SVD-based low-com plexity hybrid precoding for millimeter-wave MIMO systems,","cited_arxiv_id":null,"evidence_quote":"SVD-based low-complexity hybrid precoding whose dominant right-singular-vector selection is used to design the analog precoder F."},{"cited_title":"Zero-forcing pre coding and generalized inverses,","cited_arxiv_id":null,"evidence_quote":"Establishes zero-forcing precoding and generalized inverses, the baseband solution and channel-hardening rationale underlying the precoder formula."},{"cited_title":"On representations of the doubly non-ce ntral F distri- bution,","cited_arxiv_id":null,"evidence_quote":"Gives the doubly non-central F distribution representation used to derive the secrecy outage probability and the secrecy zone."}],"review_version":1}