{"id":"26aea80d-63f7-4db9-90f3-dfbfe2b7ecda","arxiv_id":"2508.19931","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A cell-free massive MIMO tag-based authentication scheme is proposed with closed-form detection and false-alarm probabilities, showing detection over 90% with 8 access points.","lead":"This paper shows how cell-free massive MIMO networks can authenticate several users at once using tag-based physical-layer authentication. If the analysis holds, it could make wireless authentication more scalable without needing extra radio resources.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Prop. 1's 'closed forms' depend on ξ_k, whose variance terms are never derived; without them (and without simulation) the central PFA/PD claims cannot be evaluated.","rationale":"I took the paper's central claim as Proposition 1 plus the numerical validation. The most load-bearing issue is that the proof stops before the terms that make the result computable. This is not a disagreement with consensus; it is internal incompleteness. The perfect-recovery assumption flagged by the reader is real but is an explicit modeling assumption with a citation; the undefined variances are an omission in the derivation of the claimed closed form. The R{·} inconsistency is an additional internal check that makes the simulation test necessary. I recommend keeping the reader's CONDITIONAL verdict: the framework is plausible, but the paper must supply the missing second-order moments and Monte Carlo verification before the result can be accepted. My concern does not compel rejection because these gaps are fixable in revision.","tokens_in":9562,"tokens_out":9115,"duration_ms":114053,"concrete_test":"Write an end-to-end Monte Carlo simulator for the system in Secs. II-III with M=8, N=10, K=4, and L ∈ {64, 128, 256, 512, 1024}, generating channel realizations, MMSE estimates, ZF combining, and computing λ_k = Re(t̃_k^H r_k) under H0/H1. Compare empirical PFA/PD at θ* from Eq. (28) with Eqs. (26)-(27), computing ξ_k either from the missing moments derived analytically or from the same realizations. If empirical PFA ≠ p_FA, or if empirical PD differs from the plotted curves by more than the statistical uncertainty, the claimed closed form is not supported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is Proposition 1, which states closed-form PFA, PD, and optimal threshold for each user. Equations (26)-(29) define the variance scale ξ_k through σ²_{k,k}, σ²_{k,k′}, σ²_{k,e}, and Tr(C_nk), but these moments of the ZF-combined effective channels are never computed anywhere in the paper or appendix. The proof in Appendix A stops after expressing Var(λ_k|H0) in terms of these symbols; the hardest part—marginalizing over the MMSE channel estimates under ZF combining—is omitted. Consequently, Eqs. (26)-(28) are not closed-form and cannot be evaluated by a reader. The numerical results in Figs. 2–4 are claimed to validate the theory, but the text does not state whether these variances were obtained analytically, by Monte Carlo averaging, or by fitting, and no independent simulation of the detection procedure is reported. Thus the >90% PD claim for M=8 is unsupported as presented. In addition, Eq. (20) defines λ_k as Re{t̃_k^H r_k}, yet Eqs. (24)-(25) and Appendix A treat λ_k as the complex quantity t_k^H r_k; for proper complex signals this changes the variance by a factor of 2. This further suggests the closed form is not yet correct as written.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a tag-based physical-layer authentication scheme for cell-free massive MIMO systems. Each legitimate user superimposes a secret-key-dependent tag on its data, APs perform local ZF combining, and the CPU tests, per user, whether the expected tag appears in the residual signal. The authors formulate a binary hypothesis test and, using a Gaussian approximation, derive purported closed-form expressions for the probability of false alarm, probability of detection, and the optimal threshold for each user. Numerical results are presented for PD as functions of tag length, number of APs, number of users, and power allocation. The central claim is that these expressions constitute a complete, evaluable performance analysis of the proposed authentication framework.","tokens_in":9900,"tokens_out":4804,"duration_ms":58714,"significance":"If the analysis were complete and correct, the paper would make a useful contribution: it extends active physical-layer authentication from single-receiver MIMO to the distributed cell-free massive MIMO architecture, allowing simultaneous authentication of multiple users. The conceptual framework—channel estimation, ZF combining, tag-based hypothesis testing, and per-user Neyman-Pearson thresholds—is well motivated, and the possibility of deriving closed-form PFA/PD expressions for such a system is of genuine interest. The paper does not fit free parameters to data; it is a mathematical derivation, which is a strength. However, the completeness and correctness of the derivation are not currently established: the key variance terms in the main result are never computed, and the numerical section evaluates only the derived expressions themselves without independent simulation. Credit should be given for the clear system model and the explicit identification of the hypothesis-testing framework, but the missing moment derivations and the real-part inconsistency block evaluation of the paper's central contribution.","major_comments":[{"comment":"The claimed closed-form expressions are incomplete. The quantities σ²_{k,k}, σ²_{k,k′}, σ²_{k,e}, and Tr(C_{nk}) in Eq. (29) are introduced as variances and a covariance, but they are never derived. Appendix A stops at Eq. (38), which merely writes Var(λ_k|H0) in terms of these symbols. The difficult part—computing the moments of the ZF-combined effective channels after MMSE channel estimation—is omitted. Consequently, Eqs. (26)–(28) cannot be evaluated by a reader, and the main result of the paper is not actually closed-form. Please provide these moment derivations or, if they are not analytically tractable, state clearly that the expressions require numerical evaluation of these moments.","section":"Section IV, Proposition 1 and Eq. (29)"},{"comment":"The numerical results are self-referential and do not validate the model. The text states that θ_k^* and PD,k are computed according to Proposition 1, so the figures verify only the algebra of the proposed formulas, not the accuracy of the Gaussian/CLT approximation or the system model. No independent Monte Carlo simulation of the received signal, channel estimation, residual computation, and hypothesis test is reported, and the text does not state whether the variances in Eq. (29) were evaluated analytically, by Monte Carlo averaging, or by fitting. Thus the >90% PD claim for M=8 (Fig. 2) and the comparative claims in Figs. 3 and 4 are unsupported as presented. At minimum, add a Monte Carlo simulation of the full detection procedure to confirm the analytic expressions.","section":"Section V, Figs. 2–4"},{"comment":"There is a notationally important inconsistency. The test statistic is defined as λ_k = Re{ t̃_k^H r_k } in Eq. (20), but Eqs. (24)–(25) and Appendix A treat λ_k as the complex quantity t_k^H r_k. For proper complex Gaussian terms, Var(Re{z}) = (1/2)Var(z), so the variance expression in Eq. (38) and hence ξ_k in Eq. (29) are off by a factor of 2 if the real-part definition is used. This changes the PFA, PD, and optimal threshold formulas. Please make the real-part extraction explicit throughout the derivation and adjust the variance computation accordingly.","section":"Eq. (20) vs. Eqs. (24)–(25) and Appendix A"},{"comment":"The derivation assumes perfect message recovery (ŝ_k = s_k) and perfect tag regeneration (t̃_k = t_k). The paper states this is feasible because robust hash functions can tolerate errors, but no model quantifies the effect of bit errors in ŝ_k on the regenerated tag. If the recovered message contains errors, the regenerated tag t̃_k differs from the transmitted tag t_k, changing the distribution of λ_k under H1 and degrading the detection probability. Since the numerical claims concern practical authentication performance, this error propagation is load-bearing and should be either analyzed (e.g., via a BER-aware tag-distribution model) or demonstrated by simulation. If the scope is deliberately limited to perfect recovery, that limitation should be stated and its practical impact discussed.","section":"Section III-B, perfect message recovery assumption"}],"minor_comments":[{"comment":"Under H0, when the user transmits only the message (ρ_s = 1), the expression still contains ρ_t in the denominators and treats the transmitted signal as ρ_s s_k. Please clarify the normalization conventions when ρ_t → 0, or define H0 as the case ρ_s = 1, ρ_t = 0 separately from the limit used in the algebra.","section":"Eq. (24)"},{"comment":"The notation σ²_{k,k}, σ²_{k,k′}, σ²_{k,e} is ambiguous for complex quantities. Define whether these are E{|a|²} − |E{a}|² or simply E{|a|²}, since a_{k,k} may have a nonzero mean under MMSE estimation.","section":"Eq. (29) and Appendix A"},{"comment":"The pilot length τ_p = 20 is used in the numerical setup while K is varied up to 15; orthogonality requires τ_p ≥ K, which holds, but the text should state this explicitly when discussing scalability.","section":"Section II-A"},{"comment":"In Fig. 4, ρ_s is varied; please state how ρ_t is chosen for each ρ_s (since ρ_s² + ρ_t² = 1), and how the power allocation affects the numerical results.","section":"Section V"}],"recommendation":"major_revision","confidential_remarks":"The paper addresses a relevant problem and the overall approach is plausible, but the central Theorem 1 is incomplete and the numerical section does not provide independent validation. The missing variance derivations and the complex/real inconsistency are fixable in a major revision, so I do not recommend rejection at this stage. Please ensure the revised version either supplies the missing moments analytically or includes a Monte Carlo validation that does not rely on the expressions under test."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Let me tell you directly: this paper has a nice idea and a clean system model, but the central result as written is not a closed form. Proposition 1's PFA/PD/threshold expressions depend on σ²_{k,k}, σ²_{k,k'}, σ²_{k,e}, and Tr(C_nk), and those quantities are never derived anywhere in the paper or appendix. The proof ends right at the point where the hard work should begin—computing the moments of the ZF-combined effective channels under MMSE estimation. So a reader cannot evaluate (26)-(28) from the paper.\n\nOn the positive side, the combination of tag-based PLA with CF-mMIMO to authenticate multiple users simultaneously without orthogonal resources is genuinely new and worth having. The system model is standard and clearly described: uplink pilots, MMSE estimation, local ZF combining, a hash-based tag, and a threshold test per user. The derivation strategy (Gaussian approximation via CLT) is appropriate for the regime, and the special-case check in Remark 1 is a good sanity check. I believe the authors know the CF-mMIMO literature well and are building on established foundations.\n\nThe soft spots are not minor. First, the missing variances. Without them, the 'closed-form' claim is unsupported; it's shorthand for an uncompleted derivation. The numerical results only plot these expressions, so they do not independently validate anything. There is no Monte Carlo simulation of the actual transmission and decision procedure anywhere. That means the paper's headline result—over 90% PD with 8 APs—is not demonstrated by the evidence presented.\n\nSecond, there is an apparent inconsistency between Eq. (20), which defines the test statistic as the real part of t^H r, and Eqs. (24)-(25), which treat λ as the complex quantity. For proper complex signals, this changes the variance by roughly a factor of two, so the current derivation may be wrong, not just incomplete. If I'm reading this correctly, that needs to be fixed.\n\nThird, the perfect message recovery / perfect tag regeneration assumption is stated but never relaxed or characterized. The authors note hash functions can correct errors, but they don't quantify the effect of residual error on the authentication decision. This is a known issue in tag-based PLA and should be addressed or at least bounded.\n\nI want to be fair: the paper is not sloppy in its narrative, the notation is consistent (aside from the real-part issue), and the references look appropriate. The missing analysis feels like the authors ran out of time or space rather than a deliberate attempt to mislead. But as it stands, it is a work in progress.\n\nWho is this for? Researchers working on physical-layer security in cell-free networks will be interested. It's a useful system model and a clear statement of the problem. But I would not cite the numerical conclusions until the variance terms are computed and independent simulations are added. A serious referee could help; the paper needs major revision before it is publishable.","headline":"Useful combination, but the central 'closed-form' result is incomplete because the key variances are never computed, and the numerics don't independently validate the detection claims.","tokens_in":10328,"tokens_out":2763,"would_cite":false,"duration_ms":30294,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Cell-free massive MIMO can authenticate many users simultaneously by checking secret-key tags hidden in their uplink signals, with closed-form detection and false-alarm probabilities for each user.","keywords":["physical-layer authentication","cell-free massive MIMO","tag-based authentication","hypothesis testing","probability of detection","impersonation attack","Neyman-Pearson","secret key"],"falsifier":"Run the same system over a real channel code and hash function, and compare simulated detection probability to equation (27) on blocks where the recovered message has bit errors; the point where the two curves separate marks the limit of the perfect-recovery assumption. Alternatively, Monte Carlo simulation with small M, N, and K can test whether the Gaussian approximation for λ_k holds in the tails.","tokens_in":9516,"feed_emoji":"🔐","tokens_out":5159,"duration_ms":57829,"temperature":0.7,"pith_summary":"The paper proposes a physical-layer authentication scheme for cell-free massive MIMO networks that authenticates multiple users at the same time, without giving each user its own time or frequency resource. Each legitimate user hides a short authentication tag, generated from a secret key and the message, inside its transmitted signal. Distributed access points estimate channels, forward combined signals to a central processor, and the processor tests whether the expected tag survives in the residual signal. The central result is a closed-form expression for the probability of detection, probability of false alarm, and optimal threshold for each user. The numerical results show detection above 90 percent with eight access points, and the scheme keeps working as the number of users grows.","feed_headline":"Closed-form test authenticates every user in cell-free massive MIMO","feed_subtitle":"Secret-key tags hidden in uplink signals keep detection above 90 percent despite impersonation attacks.","key_machinery":"The core object is the per-user test statistic λ_k = Re{t̃_k^H r_k}: the expected tag t̃_k is regenerated from the decoded message and secret key, r_k is the residual signal after message cancellation, and the CPU thresholds the match. Around this statistic the paper builds MMSE channel estimation, local zero-forcing combining across distributed access points, and a Neyman-Pearson threshold; the central-limit-theorem approximation of λ_k turns detection into Q-function formulas for every user.","core_discovery":"The paper establishes that a tag-based physical-layer authentication test can be carried out per user in a cell-free massive MIMO system, even while an attacker impersonates legitimate users. The CPU reconstructs the expected authentication tag from the decoded message and the shared secret key, then match-filters that tag against the residual received signal left after subtracting the estimated message. Under a Gaussian approximation of the test statistic, Proposition 1 gives closed-form expressions for PFA, PD, and the Neyman-Pearson optimal threshold for each user. The detection probability scales with the number of access points, the number of antennas per access point, the tag length, a","pith_inferences":["The perfect-recovery assumption means the paper's detection probabilities are an upper envelope; a real channel code with residual bit errors would bend the curves down, so the practical gain depends on how error-robust the hash function is.","The same closed-form machinery could be extended to user-specific power allocation, since detection depends directly on the message-tag power split ρ_s and ρ_t; optimizing per user could improve fairness without changing the test.","Attacker models beyond impersonation, such as replaying a captured tag or an attacker with channel knowledge, would add extra variance terms to λ_k, so extending the variance expression ξ_k is a natural next step.","The Gaussian approximation is asymptotic in the numbers of access points, antennas, and users; for very small networks the Q-function formulas may miss tail behavior, so Monte Carlo validation in that regime would be a cheap check of Proposition 1."],"forward_implications":["Operators can compute per-user detection probability and set thresholds in closed form, without running Monte Carlo simulations for every channel realization.","More distributed access points substitute for longer tags: raising the number of APs from 1 to 8 lifts detection probability by about 20 percent at a fixed tag length.","More antennas per access point offset multi-user interference: with 15 users, increasing antennas from 5 to 30 improves detection by 34 percent and keeps it above 50 percent.","The scheme authenticates all users within the same time-frequency resources, avoiding the orthogonal-resource scaling problem of single-receiver physical-layer authentication.","The formulas reduce to known single-receiver, single-user results when M = N = K = 1, so the framework generalizes earlier tag-based authentication analysis."],"supporting_citations":[{"why":"Supplies the tag-superimposition model and the practice of ignoring the tag when recovering the message.","marker":"[5]"},{"why":"Establishes the multi-user authentication setting and the assumption that tags from different users are uncorrelated.","marker":"[6]"},{"why":"Provides the MIMO authentication precedent and the central-limit-theorem justification for approximating the test statistic as Gaussian.","marker":"[8]"},{"why":"Defines the security model in which Eve knows the authentication process but not the secret key.","marker":"[10]"},{"why":"Foundational tag-based PLA framework; supplies the robust-hash argument for assuming perfect tag regeneration and the multi-block tag idea.","marker":"[12]"},{"why":"Gives the Neyman-Pearson criterion used to set the optimal decision threshold.","marker":"[14]"},{"why":"Supplies the cell-free massive MIMO channel and path-loss model used in the numerical setup.","marker":"[15]"},{"why":"Provides the MMSE channel estimation property that estimate and estimation error are independent, used in the proof.","marker":"[16]"}],"fun_headline_variants":["Secret-key tags authenticate every user in cell-free MIMO","Closed-form detection beats impersonation in cell-free massive MIMO","Per-user authentication stays secure as users scale in cell-free MIMO","Cell-free MIMO: tag-based authentication thwarts active attackers","Closed-form test keeps detection high despite impersonation in MIMO"],"cache_read_input_tokens":2688,"weakest_assumption_plain":"The derivation assumes every decoded message is bit-exact, so the regenerated tag always equals the transmitted tag; any bit errors break the match and lower the real detection probability.","fun_headline_variants_meta":{"raw":{"variants":["Secret-key tags authenticate every user in cell-free MIMO","Closed-form detection beats impersonation in cell-free massive MIMO","Per-user authentication stays secure as users scale in cell-free MIMO","Cell-free MIMO: tag-based authentication thwarts active attackers","Closed-form test keeps detection high despite impersonation in MIMO"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000596,"raw_usage":{"total_tokens":2584,"prompt_tokens":660,"completion_tokens":1924,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":404,"completion_tokens_details":{"reasoning_tokens":1852}},"tokens_in":404,"tokens_out":1924,"duration_ms":14212,"temperature":1.0,"reasoning_tokens":1852,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T15:19:54.133986+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the same system over a real channel code and hash function, and compare simulated detection probability to equation (27) on blocks where the recovered message has bit errors; the point where the two curves separate marks the limit of the perfect-recovery assumption. Alternatively, Monte Carlo simulation with small M, N, and K can test whether the Gaussian approximation for λ_k holds in the tails.","supporting_citations":[{"cited_title":"Tag-based PHY-layer authentication for RIS-assisted communication systems,","cited_arxiv_id":null,"evidence_quote":"Supplies the tag-superimposition model and the practice of ignoring the tag when recovering the message."},{"cited_title":"Multi-user physical-la yer authen- tication and classiﬁcation,","cited_arxiv_id":null,"evidence_quote":"Establishes the multi-user authentication setting and the assumption that tags from different users are uncorrelated."},{"cited_title":"MIMO authentication via delibe rate ﬁngerprinting at the physical layer,","cited_arxiv_id":null,"evidence_quote":"Provides the MIMO authentication precedent and the central-limit-theorem justification for approximating the test statistic as Gaussian."},{"cited_title":"Security model of authenti cation at the physical layer and performance analysis over fading channe ls,","cited_arxiv_id":null,"evidence_quote":"Defines the security model in which Eve knows the authentication process but not the secret key."},{"cited_title":"Physical-layer a uthentication,","cited_arxiv_id":null,"evidence_quote":"Foundational tag-based PLA framework; supplies the robust-hash argument for assuming perfect tag regeneration and the multi-block tag idea."},{"cited_title":"Authentication theory and hypothesis test ing,","cited_arxiv_id":null,"evidence_quote":"Gives the Neyman-Pearson criterion used to set the optimal decision threshold."},{"cited_title":"Massive MU- MIMO downlink TDD systems with linear precoding and downlink pil ots,","cited_arxiv_id":null,"evidence_quote":"Provides the MMSE channel estimation property that estimate and estimation error are independent, used in the proof."}],"review_version":1}