{"id":"05f2fbc4-ffe1-418b-81bb-c0249e0bf169","arxiv_id":"2507.23234","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"Closed-form expressions for secrecy rate, radar angle-estimation error, and estimation outage for two secure ISAC beamforming schemes in a fading MIMO downlink.","lead":"This paper derives formulas for how well a base station can keep both its data and its radar target measurements secret when a communication spy, a location-sensing spy, and a malicious target are all listening in a network with random channels. The closed-form results let engineers split transmit power between data, radar, and artificial noise to see the tradeoff between sensing accuracy and secrecy rate.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The claimed 'ergodic CRB' is infinite under the stated U(-π/2,π/2) angle model; the reported values rely on a truncated-domain proxy with an arbitrary cutoff, so the CRB-secrecy region is not for the claimed metric.","rationale":"I read the paper as genuinely aiming to provide a stochastic performance analysis of a random MIMO ISAC downlink, and several exact pieces of the derivation are correct: Lemma 11's eav ergodic rate follows from the χ²₂ and χ²_{2(N-2)} structure, Lemma 12's malicious-target leakage is exact by orthogonality, and the orthogonality identities used in the CRB simplification are internally consistent. The reader's weakest_assumption focuses on the CLT-based trivariate normal approximation and the assumed independence of S and K at finite N. That is a real concern, but it is an approximation whose error can in principle be quantified and checked against Monte Carlo. The concern I find more load-bearing is the divergence of the nominal 'ergodic CRB' under the model's stated uniform angle distribution. Every CRB formula contains a cos^{-2}(θ) or cos^{-2}(φ) factor, and the expectation over U(-π/2,π/2) is infinite. The paper handles this only in Appendix F by truncating the domain with δ=0.1, so the numerical curves and the CRB-secrecy region boundary are computed for a different, hand-chosen statistical object. This affects the central claim directly and would affect any attempt to use the tradeoff regions for design. It is correctable by redefining the metric, which is why I keep the reader's CONDITIONAL verdict rather than moving to REJECT; the exact ESR contributions and the structural framework remain valuable. My agreement is therefore partial: the reader noted the truncation in the rationale but did not make it the weakest-assumption focus, whereas I regard it as the primary risk to the central claim.","tokens_in":34533,"tokens_out":5441,"duration_ms":61556,"concrete_test":"Compute the exact mean CRB at the BS for SSJB from the LCRB expression in Appendix B by Monte Carlo over θ drawn from U(-π/2,π/2), with h and the other random parameters either fixed or averaged, using a very large sample that includes realizations within |θ-π/2| < δ. If the integrand is proportional to sec²θ, the empirical mean will grow without bound as samples approach the endpoints; compare it with the Appendix F finite value 2cot(δ)/(π-2δ) times the remaining constants. Equivalently, evaluate E[CRB] for δ ∈ {0.05, 0.1, 0.2}; if the truncated values change by a large factor, the reported region is an artifact of the arbitrary cutoff. A finite result under this test would refute the objection; a diverging or strongly δ-dependent result confirms that the 'ergodic CRB' must be redefined before the central claim can stand.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim that the paper derives the ergodic CRB is not supported as stated. In Sections V-VIII every CRB expression carries a factor proportional to cos^{-2}(θ) at the BS or cos^{-2}(φ) at the sensing eav; for example, the LCRB in Appendix B is 6σ_r² / [cos²(θ) M N π² L P |c3|² (...)] and Lemma 4 gives CRB(φ) ∝ 1/cos²(φ). Under the model's stated θ, φ ~ U(-π/2, π/2), the density is positive at ±π/2, so E[CRB(θ)] = ∫_{-π/2}^{π/2} (1/π) CRB(θ) dθ diverges because ∫ sec²θ dθ = tanθ → ∞. The same holds for φ. Appendix F replaces this object with a truncated expectation over [-π/2+δ, π/2-δ], using δ=0.1 and E[1/cos²θ] = 2cot(δ)/(π-2δ). Thus all E[CRB] values and the claimed CRB-secrecy-rate region boundaries in Figs. 3-4 are for a different, δ-dependent metric rather than the 'ergodic CRB' named in the abstract and Section II-A. Since the central tradeoffs 'sensing accuracy vs. secure rate' and 'security vs. privacy' are plotted against this proxy, the stochastic characterization is not of the stated model. This is a definitional problem, not an approximation-error issue: it persists for every N and for every Monte Carlo sample size. The fix is straightforward, rename and disclose the truncated metric or replace the uniform angle model with a bounded distribution, but until then the headline claim overreaches. The exact ESR results (Lemmas 10-12 and 14-15) are not affected by this concern.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper analyzes a downlink MIMO ISAC network with random Rayleigh fading channels and a uniformly distributed target angle, subject to an external communication eavesdropper, a strong or weak sensing eavesdropper, and a malicious-target scenario. The authors propose two closed-form precoding strategies, SSJB and SLB, and derive stochastic sensing metrics (CRB outage probability, ergodic CRB at the BS and at sensing eavesdroppers) and ergodic secrecy rate expressions, including exact formulas for the SSJB external-eavesdropper and malicious-target leakage rates. The results are used to plot CRB-secrecy-rate tradeoff regions and to compare the two precoders.","tokens_in":34857,"tokens_out":8979,"duration_ms":114168,"significance":"The paper targets a timely problem, and the exact SSJB eavesdropper-rate derivations (Lemmas 11 and 12) are clean and correct under the stated model; the two closed-form precoders and the explicit tradeoff discussion are useful contributions if the underlying stochastic metrics are sound. However, the central CRB results are currently tied to a truncated proxy of the advertised ergodic CRB, and several SLB secrecy-rate results are approximations whose accuracy is not quantified. The manuscript is therefore a promising framework that needs substantial revision before its headline claims can be accepted.","major_comments":[{"comment":"The claimed 'ergodic CRB' is not defined for the stated angle model. Under theta ~ U(-pi/2, pi/2), every CRB expression contains a factor 1/cos^2(theta) or 1/cos^2(phi) (e.g., the LCRB in Appendix B and Lemma 4), so E[CRB(theta)] = integral (1/pi) CRB(theta) dtheta diverges because the integrand behaves as sec^2(theta) near +/- pi/2. Appendix F explicitly truncates the domain to [-pi/2+delta, pi/2-delta] and uses E[1/cos^2(theta)] = 2 cot(delta)/(pi-2 delta). Consequently, Lemma 8 and all ergodic-CRB values in Figs. 3 and 4 are expectations of a delta-dependent truncated proxy, not of the 'ergodic CRB' named in the abstract and Section II-A. This is a definitional problem, not a finite-sample or Monte Carlo issue. The authors should either rename the metric throughout (e.g., 'delta-truncated ergodic CRB' with delta=0.1) or replace the uniform angle model with a bounded distribution and re-derive the corresponding formulas.","section":"Section VIII, Lemma 8, Appendix F"},{"comment":"The stochastic closed forms rely on a trivariate CLT approximation for (R,T,K) and, in Appendix F, on the additional approximation that S = R^2+T^2 is independent of K and distributed as N*Exp(1) while K ~ N(N,N). In the true model, S and K are correlated with a correlation that decays only as N^{-1/2}, which is not negligible at the paper's default N=15. The statement in Appendix B that 'for N > 9, the multidimensional CLT holds' is a self-referential assertion supported only by the paper's own Monte Carlo, and no error bound or quantitative accuracy criterion is provided. Because the CRB approximations contain the term 1/(K - S/N), this approximation directly affects the claimed tradeoff curves. The authors should explicitly label all such results as CLT-based approximations and provide a quantitative accuracy check, or supply a rigorous finite-N error bound.","section":"Appendix B, Appendix F, Section X"},{"comment":"The SLB ergodic rate at the communication eavesdropper is obtained by replacing E[log(1+SINR)] with log(1+E[SINR]) and then approximating E[SINR] by the ratio of expectations of the numerator and denominator. The proof steps are not justified for an ergodic rate, since Jensen's inequality gives only an inequality and the ratio-of-expectations is an uncontrolled approximation. This formula is used in the SLB secrecy-rate contours of Fig. 2 and the tradeoff regions of Fig. 4, so the SLB ESR is not derived at the same level of rigor as the SSJB exact results. The approximation status of Lemma 14 should be stated prominently in the contributions section, or an exact expression should be supplied.","section":"Lemma 14 and its proof"}],"minor_comments":[{"comment":"The figure labels contain typos: 'Ergpdic Rate' and 'Ergpdic CRB' should be 'Ergodic Rate' and 'Ergodic CRB'.","section":"Figures 2 and 3"},{"comment":"The heading for the proof of Lemma 11 reads 'Appendix and H'; this should be 'Appendix H'.","section":"Appendix H heading"},{"comment":"The proof of Lemma 16 omits the detailed covariance calculations 'due to space limitations'; since this lemma is load-bearing for every CLT-based approximation, the derivations should be included in a supplementary file or in the appendix text.","section":"Lemma 16 proof"},{"comment":"The notation in Lemma 9 is overloaded: M2(S,K), M3(S,K), and M4(S,K) are introduced without a unified definition, and the 'upper bound', 'lower bound', and 'approximation' variants of M2 are not clearly distinguished in the displayed expressions.","section":"Section VIII, Lemma 9"}],"recommendation":"major_revision","confidential_remarks":"The paper relies substantially on two self-citations ([1], [12]) for the framework and the basic SSJB idea; the novelty claim in Section I-C should be checked against those works during the revision process. The exact SSJB rate results are solid, but the CRB truncation issue must be resolved before the paper can be considered for publication."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: the paper's model combination is new and the exact secrecy-rate derivations are correct, but the 'ergodic CRB' that drives the tradeoff plots is not the claimed expectation. Under the stated θ, φ ~ U(-π/2, π/2), CRB(θ) and CRB(φ) scale as 1/cos², so E[CRB] diverges. The paper computes a truncated expectation over [-π/2+δ, π/2-δ] with δ=0.1, disclosed only in Appendix F. The stress-test note is right: this is a definitional problem, not an N-approximation error. Figures 3 and 4 therefore plot a δ-dependent proxy.\n\nWhat's good: this is the first joint communication-security and sensing-privacy stochastic analysis with external comm eav, strong/weak sensing eav, and a malicious target in one random network. Section I-C is a fair comparison with the prior work. Lemma 11 and Lemma 12 are exact and checkable; Lemma 16's CLT moments are correct; the steering-vector orthogonality identities hold. The Monte Carlo is independent of the derivations. The outage probabilities P(CRB > ε) are not affected by the divergence and remain useful. The citation pattern is unremarkable; self-citations supply the framework and are appropriate here.\n\nSoft spots, in proportion. The ergodic CRB issue is load-bearing for the claimed tradeoff regions, and it must be fixed by renaming/disclosing the truncated metric or replacing the uniform angle distribution. The CLT approximation treats S = R²+T² as N·Exp(1) independent of K, although the true correlation is 1/√N; only the paper's own Monte Carlo validates it, so an error analysis would help. The ESR is defined as (E[R_u] - E[R_e])^+, a valid lower-bound surrogate for E[(R_u - R_e)^+], but this should be stated plainly. Lemma 2's '0 otherwise' branch and several other typos are minor but need cleanup.\n\nWho it's for: ISAC researchers needing fast power-split evaluation and closed-form stochastic security metrics. It deserves a serious referee; the referee should require the ergodic CRB to be redefined or clearly disclosed before the tradeoff curves are accepted. Recommendation: send to peer review, conditional accept after that fix.","headline":"The exact secrecy-rate results are solid and the model combination is new, but the headline 'ergodic CRB' is a truncated proxy that diverges under the stated angle model, so the tradeoff plots need re-flagging before the paper is fully trusted.","tokens_in":35567,"tokens_out":4609,"would_cite":true,"duration_ms":48369,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["94A15","94A12"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that the stochastic security and sensing performance of a random MIMO ISAC downlink reduces to closed-form expressions for two secure precoders, and that these expressions trace the full CRB–secrecy-rate boundary.","keywords":["integrated sensing and communication","ISAC","physical layer security","ergodic secrecy rate","Cramér–Rao bound","sensing privacy","stochastic performance analysis","beamforming"],"falsifier":"Compute the paper's metrics without the Gaussian step: for the same parameters (for instance $N = 15$, $M = 17$, $N_e = 15$), evaluate the ergodic secrecy rate, $E[\\mathrm{CRB}(\\theta)]$, and $P(\\mathrm{CRB} > \\varepsilon)$ by Monte Carlo over the exact Rayleigh fading and uniform angle distributions, and compare against the closed forms. The precise weak spot to probe is the independence of $S = R^2 + T^2$ and $K$, whose true correlation is $1/\\sqrt{N}$; repeat the comparison at $N = 4, 9, 16, 25$ and locate the smallest $N$ at which the closed forms leave the Monte Carlo confidence band — if that $N$ lies at or above the operating array size, the central claim fails at that operating point.","tokens_in":34193,"feed_emoji":"📡","tokens_out":16928,"duration_ms":164687,"temperature":0.7,"pith_summary":"This paper tries to establish that the security and sensing performance of a random MIMO integrated sensing and communication (ISAC) downlink can be reduced to closed-form expressions, despite random Rayleigh fading, a uniformly random target angle, and three kinds of adversaries. The setting is one base station that simultaneously serves a single-antenna user, estimates a target's azimuth angle from its radar echo, and defends against a passive communication eavesdropper, a strong or weak multi-antenna sensing eavesdropper, and possibly a target that itself acts as an eavesdropper. For two structured precoders, SSJB and SLB, the paper derives the ergodic secrecy rate, the ergodic Cramér–Rao bound (CRB) for angle estimation at both the base station and the sensing eavesdropper, and the outage probability that the CRB exceeds a threshold. If the analysis is correct, these metrics, together with the three tradeoffs the paper identifies between sensing accuracy, secure rate, and sensing privacy, become computable from a handful of formulas and a single three-dimensional Gaussian integral, with no iterative optimization.","feed_headline":"Two secure beamformers collapse secrecy and sensing into closed forms","feed_subtitle":"Random fading and three eavesdropper types shrink to exact formulas and a single Gaussian integral.","key_machinery":"The load-bearing object is the trivariate Gaussian approximation of the channel sums. For $(R, T, K)$, the real part, imaginary part, and power sum of the randomized beam-channel terms, Lemma 16 fixes $\\mu_d = [0,0,1]^T$ and $\\Sigma_d = \\operatorname{diag}(1/2, 1/2, 1)$, giving $(R,T,K) \\to \\mathcal{N}_3(N\\mu_d, N\\Sigma_d)$ for large $N$; Appendix F then replaces $S = R^2 + T^2$ by an $N\\cdot\\mathrm{Exp}(1)$ variable independent of $K \\sim \\mathcal{N}(N,N)$. This single approximation converts every CRB and rate expression into an integral against a Gaussian density. The two precoders are the second piece of machinery: SSJB sends user data along a vector $t_1 = \\alpha \\tilde{a} + \\beta \\tilde{h}$ in the span of the target steering direction and the user channel, with artificial noise in the null space, while SLB splits power among the user direction $h/\\|h\\|$, the steering direction $a/\\|a\\|$, its derivative $a'/\\|a'\\|$, and artificial noise. Lemma 1 fixes the construction of the secure sensing part: the beamformer minimizing $\\mathrm{CRB}(\\theta) - \\mathrm{CRB}(\\varphi)$ lies in the span of $a$ and $a'$.","core_discovery":"The paper's central claim is that for a Rayleigh-fading MIMO ISAC downlink with uniformly distributed target azimuth, the security and privacy performance of two closed-form precoders, SSJB and SLB, is captured by a small set of analytic metrics: the ergodic secrecy rate, the ergodic Cramér–Rao bound (CRB) for target localization at the base station and at strong and weak sensing eavesdroppers, and outage probabilities of the form $P(\\mathrm{CRB} > \\varepsilon)$. The analytic engine is the multidimensional central limit theorem applied to $(R, T, K) = (\\mathrm{Re}\\sum_i e^{j f_i} h_i, \\mathrm{Im}\\sum_i e^{j f_i} h_i, \\sum_i |h_i|^2)$, which the paper treats as trivariate normal with mean $N[0,0,1]^T$ and covariance $N\\operatorname{diag}(1/2,1/2,1)$, so that $S = R^2 + T^2$ behaves as $N\\cdot\\mathrm{Exp}(1)$, independent of $K$. On this foundation the paper derives exact results such as the external eavesdropper's ergodic rate $\\int_0^\\infty e^{-T/(2C_1)}(1 + T C_2/C_1)^{-(N-2)}\\,dt$ and the malicious-target leakage $\\log(1 + P\\tau |c_5|^2 |\\alpha|^2 N / \\sigma_t^2)$, and from them traces the boundary of the CRB–secrecy-rate region. The boundary exposes three tradeoffs: sensing accuracy versus communication rate, sensing accuracy versus secure communication rate, and communication security versus sensing privacy.","pith_inferences":["Editorial inference: because Lemma 16 makes the Gaussian law of $(R,T,K)$ independent of the target angle, the same machinery should extend to other angle distributions and, with additional steering directions, to multiple targets; the open question is whether the derived bounds stay tight in those regimes.","Editorial inference: Lemma 12's exact leakage formula shows malicious-target leakage is controlled entirely by the power split $\\tau$ and the projection weight $\\alpha$; this is a concrete, testable design relationship that a hardware experiment could verify by measuring the target's decoded SINR against $\\tau$.","Editorial inference: since the true correlation is $\\mathrm{corr}(S,K) = 1/\\sqrt{N}$, the closed forms should degrade predictably as $N$ shrinks; a $1/\\sqrt{N}$ correction term to the independence approximation could extend the formulas to the small-array regime where the paper's own $N > 9$ claim does not apply."],"forward_implications":["Under the two precoders, the ergodic secrecy rate, ergodic CRB, and CRB outage probability come out in closed form or as tight bounds, so evaluating security and privacy in random ISAC no longer requires iterative non-convex optimization.","The CRB–secrecy-rate boundary gives designers a quantitative statement of three tradeoffs — sensing accuracy versus rate, sensing accuracy versus secure rate, and communication security versus sensing privacy — so the cost of a secrecy target can be read off directly as a loss in estimation accuracy.","SSJB can place user data orthogonal to the target direction, so it can drive malicious-target leakage to zero and is the more resilient scheme against malicious targets; SLB aligns with the user channel and therefore achieves higher rates and stronger protection against external eavesdroppers.","The secure-sensing-optimal beamformer provably lies in the span of the steering vector and its angle-derivative, so SLB's construction is supported by a structural lemma rather than chosen ad hoc."],"supporting_citations":[{"why":"Supplies the SJB and LB beamforming structures that SSJB and SLB secure versions extend, as well as the P(CRB > ε) sensing metric used throughout.","marker":"[12]"},{"why":"Provides the CRB expression for joint radar-communication beamforming and the lemma that the sensing-optimal beamformer lies in the span of the steering vector and user channel.","marker":"[23]"},{"why":"Its projection argument is the template for Lemma 1's proof that the secure sensing-optimal beamformer spans {a, a'}.","marker":"[68]"},{"why":"The multidimensional central limit theorem invoked to justify the trivariate normal law of (R, T, K).","marker":"[69]"},{"why":"Masked beamforming with artificial noise in the channel null space: the secure-communication-optimal subproblem embedded in both precoders.","marker":"[65]"},{"why":"Numerical method for integrating a multivariate normal density over arbitrary domains, used to evaluate the CRB outage probabilities.","marker":"[67]"},{"why":"Defines the ergodic secrecy rate as the positive part of the difference of ergodic user and eavesdropper rates, the framework for all secrecy results.","marker":"[60]"},{"why":"Cited to support the claim that CLT accuracy holds for N > 8, a premise on which the Gaussian approximation rests.","marker":"[30]"}],"fun_headline_variants":["Closed-form secrecy and sensing bounds for MIMO ISAC","Exact tradeoffs in secure ISAC: secrecy vs sensing","Rayleigh fading yields closed-form ISAC security stats","Stochastic ISAC security: from integrals to equations","Two precoders, one Gaussian integral: ISAC security"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"Everything rests on treating the three channel-derived quantities $(R, T, K)$ as jointly Gaussian with $S = R^2 + T^2$ effectively independent of $K$; that is only asymptotically true, since the true $S$ and $K$ are correlated, and if the approximation is inaccurate at the antenna count of interest, every closed-form metric and tradeoff boundary inherits the error.","fun_headline_variants_meta":{"raw":{"variants":["Closed-form secrecy and sensing bounds for MIMO ISAC","Exact tradeoffs in secure ISAC: secrecy vs sensing","Rayleigh fading yields closed-form ISAC security stats","Stochastic ISAC security: from integrals to equations","Two precoders, one Gaussian integral: ISAC security"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00071,"raw_usage":{"total_tokens":3295,"prompt_tokens":1140,"completion_tokens":2155,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":756,"completion_tokens_details":{"reasoning_tokens":2075}},"tokens_in":756,"tokens_out":2155,"duration_ms":19394,"temperature":1.0,"reasoning_tokens":2075,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T10:59:37.634775+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the paper's metrics without the Gaussian step: for the same parameters (for instance $N = 15$, $M = 17$, $N_e = 15$), evaluate the ergodic secrecy rate, $E[\\mathrm{CRB}(\\theta)]$, and $P(\\mathrm{CRB} > \\varepsilon)$ by Monte Carlo over the exact Rayleigh fading and uniform angle distributions, and compare against the closed forms. The precise weak spot to probe is the independence of $S = R^2 + T^2$ and $K$, whose true correlation is $1/\\sqrt{N}$; repeat the comparison at $N = 4, 9, 16, 25$ and locate the smallest $N$ at which the closed forms leave the Monte Carlo confidence band — if that $N$ lies at or above the operating array size, the central claim fails at that operating point.","supporting_citations":[{"cited_title":"R ange compression and waveform optimization for mimo radar: A cra m ´Er–rao bound based study,","cited_arxiv_id":null,"evidence_quote":"Its projection argument is the template for Lemma 1's proof that the secure sensing-optimal beamformer spans {a, a'}."},{"cited_title":"Central limit theorem — Wikipedia, the free encyclopedia,","cited_arxiv_id":null,"evidence_quote":"The multidimensional central limit theorem invoked to justify the trivariate normal law of (R, T, K)."},{"cited_title":"Secure transmission with m ultiple antennas i: The MISOME wiretap channel,","cited_arxiv_id":null,"evidence_quote":"Masked beamforming with artificial noise in the channel null space: the secure-communication-optimal subproblem embedded in both precoders."},{"cited_title":"Secure transmission with artiﬁ cial noise over fading channels: Achievable rate and optimal power all ocation,","cited_arxiv_id":null,"evidence_quote":"Defines the ergodic secrecy rate as the positive part of the difference of ergodic user and eavesdropper rates, the framework for all secrecy results."}],"review_version":1}