{"id":"70ddb794-b4a3-4aa2-9d69-19cf3a027943","arxiv_id":"2509.06898","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A 5G base station can detect, classify, and localize radar pulses by canceling its own uplink traffic and correlating the leftover signal with templates trained on synthetic data.","lead":"The authors build a radar-sensing system that runs on ordinary 5G base stations, canceling out uplink traffic to reveal radar pulses in shared spectrum. It could let cellular networks detect, classify, and locate radar signals in real time without dedicated sensors.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Unverified data-symbol demodulation in §5.1: if hard decisions in Eq. (1) fail under 24.3–38.4 dB INR, residual 5G leakage contaminates Y_res and the zero-shot detection results are not established.","rationale":"The central claim is zero-shot template generation, but the input to the templates is Y_res, and Y_res is only radar-like if the §5.1 cancellation works. Eq. (1) is a hard-decision slice under the explicit assumption that interfered data symbols are demodulated correctly; the paper gives no OTA SER/BLER measurements. The INR reduction numbers in §7.1 are aggregate and do not rule out localized decision errors. The PUSCH P0N#1 detection collapse to 8.95% is consistent with residual 5G surviving, though low pulse energy is also a plausible contributor. A loopback/decoder-comparison experiment would settle which is responsible. Because this is an unverified load-bearing assumption rather than a demonstrated contradiction, the conditional verdict stands; I agree with the reader's weakest_assumption. Secondary issues such as experimental threshold calibration and conditioned localization metrics are real but less central to the zero-shot claim.","tokens_in":19946,"tokens_out":6511,"duration_ms":64932,"concrete_test":"On the OTA PUSCH dataset, obtain ground-truth transmitted data symbols (loopback test or srsRAN decoder output after FEC) for resource elements overlapped by radar pulses. Compute the per-symbol error rate of Eq. (1) hard decisions and the residual grid energy using Eq. (1) versus using true symbols. Then rerun detection/classification/localization with ideal cancellation; if P0N#1 PUSCH detection or the aggregate detection probability changes by more than ~5 percentage points, the reported performance depends on cancellation accuracy rather than solely on the zero-shot templates. Also report BLER/SER under the INR conditions.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section 5.1 reconstructs uplink 5G by hard-decision slicing equalized data symbols (Eq. 1) and asserts that interfered symbols 'can still be correctly demodulated (or corrected by the following decoding process).' The paper never measures whether this holds in the OTA PUSCH experiments at INR 24.3–38.4 dB. If a radar pulse pushes an equalized symbol across a decision boundary, Eq. (1) produces the wrong constellation point; subtracting bh5G⊙bxdata_5G then injects a spurious 5G component into the residual grid Y_res instead of canceling it. The decoder is absent from the BatStation pipeline (Fig. 3), so the parenthetical 'corrected by decoding' is not actually implemented—hard decisions are used directly for reconstruction. Wrong decisions on even a modest fraction of overlapping resource elements can create correlation energy comparable to a short/narrow P0N#1 pulse, the case that collapses to 8.95% detection on PUSCH. The reported 21.7–32.9 dB INR reduction is an aggregate power measure and does not establish per-symbol decision correctness; residual 5G can be concentrated in the time/frequency locations where templates search for radar. Thus the zero-shot claim is contingent on an unverified interference-cancellation assumption. This is a correctness risk, not a disagreement with consensus.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents BatStation, an in-situ radar sensing system for 5G base stations in shared spectrum (CBRS). It separates radar signals from concurrent 5G uplink transmissions by reconstructing and canceling the 5G signal from hard-decision demodulation, reshapes the residual time-frequency grid via re-FFT and max pooling, and uses radar templates initialized and fine-tuned on purely synthetic data. The system is evaluated on an SDR testbed with commodity smartphones and OTA radar signals, reporting detection probabilities of 97.02% (PUCCH) and 79.23% (PUSCH), classification accuracies of 97.00% and 95.30%, median frequency localization errors of 2.68–6.20 MHz, median time localization errors of 24.6–32.4 µs, and GPU/CPU latencies around 0.11/0.94 ms.","tokens_in":20334,"tokens_out":4536,"duration_ms":48410,"significance":"If the claims hold, the contribution is significant: it offers a standard-compatible, lightweight, in-situ radar sensing capability for 5G BSs without dedicated sensing hardware, with a linear template-correlation model having only 4,560 parameters. The OTA evaluation with real 5G traffic and the comparison against three baselines are strengths, and the paper is generally clear. However, the central 'true zero-shot' claim and the reported detection/localization numbers are not fully established because the detection threshold is calibrated on experimental no-radar data and because the signal-separation module rests on an unverified hard-decision demodulation assumption. These issues are load-bearing for the paper's main claims, though they appear addressable with additional measurements or a modified threshold-selection procedure.","major_comments":[{"comment":"The zero-shot claim is weakened by threshold selection in §7.2. Detection in Eq. (7) depends on Y_th, and Y_th is set to the 95th percentile of Y* from experimental no-radar resource grids, separately for PUCCH (28.8 dB) and PUSCH (35.1 dB). This is experimental calibration of the detector, so the end-to-end system is not 'true zero-shot' as stated in §5.3. All detection probabilities and downstream tasks depend on this threshold. Please either rephrase the claim to scope zero-shot to template generation only, or derive Y_th from synthetic/noise-only data (e.g., a CFAR-style rule) and re-evaluate.","section":"§7.2 and §5.3"},{"comment":"The radar signal separation assumes interfered uplink data symbols can still be correctly demodulated or corrected by decoding, but the pipeline in Fig. 3 uses hard decisions directly and does not implement a decoder. Under INR of 24.3–38.4 dB, radar interference can push equalized symbols across decision boundaries; a wrong hard decision in Eq. (1) makes the subtraction in Eq. (3) inject residual 5G energy into Y_res, which can then correlate with radar templates. The reported aggregate INR reduction of 21.7–32.9 dB does not verify per-symbol decision correctness. Please report measured demodulation error rate or BLER under the OTA INR conditions, or independently validate cancellation quality against known 5G content.","section":"§5.1, Eqs. (1)–(3)"},{"comment":"The localization evaluation appears to be conditioned on successful detection, but this is not stated explicitly. For PUSCH, P0N#1 is detected with only 8.95% probability (§7.2), yet a median normalized time error of 18.06% (90.3 µs) is reported for this type. If the localization statistics are computed only on the detected subset, they describe a small, non-representative set of pulses. Please state the conditioning explicitly and, ideally, report localization error over all test samples, treating undetected pulses as failures or providing a separate error floor.","section":"§7.4 and §7.2"}],"minor_comments":[{"comment":"Typo: 'P3N#1' should be 'P0N#1'.","section":"§5.3"},{"comment":"Latency numbers are inconsistent: the abstract says 0.11/0.94 ms on GPU/CPU, the introduction says 0.11/0.90 ms on CPU/GPU, and §7.5 reports 0.11/0.20 ms on GPUs and 0.94 ms on Intel Xeon. Please reconcile.","section":"Abstract and §7.5"},{"comment":"The text refers to a 'log threshold' without specifying whether Y_th is applied to the log-domain or linear output. Clarify the scale and the false-alarm definition.","section":"Fig. 10"},{"comment":"References [56] and [57] appear to be the same paper and should be merged.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The OTA experiments appear internally consistent, and the main risk is overclaiming zero-shot capability rather than data fabrication. The paper does not state plans for releasing code or datasets; releasing the synthetic waveform generator and template-generation scripts would substantially strengthen reproducibility. The comparison against synthetic-only-trained ML baselines is fair for the zero-shot claim, but an additional comparison against an experimentally fine-tuned variant of BatStation's own templates would help isolate the effect of threshold calibration."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The thing to know about this paper: it is a genuine systems contribution, not a repackaged idea. The combination of decode-based cancellation of 5G uplink with synthetic-only template correlation for radar sensing is new, and they back it with a real SDR testbed, commodity phones, and the full Open5GS/srsRAN stack. The latency numbers (0.11 ms on GPU) and the model size (4,560 parameters) are compelling. The OTA evaluation is substantial and the reported INR reduction from cancellation is credible. Table 1 is fair: no cited prior system does all six capabilities. I believe the central capability—detecting moderate-to-high-energy radar pulses during PUSCH—is largely demonstrated.\n\nThe soft spots are real but manageable. First, the 'zero-shot' claim is overstated. The templates are trained on synthetic data, which is legitimately zero-shot, but the detection threshold in Section 7.2 is set on experimental no-radar resource grids. That is threshold calibration on the test distribution, not zero-shot. The paper should say 'zero-shot template generation with a calibration threshold' or move the threshold to a held-out validation set. Second, the §5.1 assumption that interfered data symbols are correctly demodulated is load-bearing and unverified. The pipeline uses hard decisions in Eq. (1) and the decoder is not in the loop, so a radar pulse that pushes symbols across a decision boundary injects residual 5G energy into the same time-frequency locations where the templates search. This could plausibly explain why P0N#1—short, narrow, low-energy—collapses to 8.95% detection on PUSCH. The paper does not report BLER or per-symbol decision accuracy, so we cannot tell whether the cancellation works as advertised or whether the correlation is partly matching 5G leakage. That is a correctness risk, not a fatal flaw. Third, localization metrics are conditioned on detected pulses, which flatters the numbers by ignoring the missed pulses. Fourth, no code or data is released, so the OTA results are not independently checkable.\n\nNone of this destroys the contribution. The system is coherent, the evaluation is far above what we often see, and the issues are addressable in a revision. The reader's conditional verdict is about right. This deserves a serious referee, and I would encourage them to focus on the demodulation question and the threshold calibration. If those hold up, this is a strong TMC/INFOCOM-quality system paper.","headline":"Solid systems paper with real OTA evidence, but the 'zero-shot' label is weaker than it claims because the detection threshold is fit to experimental no-radar grids and the cancellation assumption is never verified.","tokens_in":20748,"tokens_out":1629,"would_cite":true,"duration_ms":19952,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper shows a 5G base station can detect, classify, and localize radar pulses from its own uplink resource grids using zero-shot templates generated from purely synthetic data, with no experimental fine-tuning.","keywords":["radar sensing","5G base station","CBRS spectrum sharing","zero-shot template generation","signal cancellation","template correlation","uplink resource grid","SDR testbed"],"falsifier":"Inject radar pulses into a live 5G uplink at INR 24-38 dB while logging the decoder's block error rate and the residual grid energy after BatStation's cancellation; if data symbols are frequently not demodulated correctly or the residual grid still correlates with scheduled 5G data, the separation step fails. A cleaner test: compare detection probability when the base station knows the true uplink data symbols (ideal cancellation) versus when it must round the constellation; a large gap would confirm the demodulation assumption is load-bearing.","tokens_in":19855,"feed_emoji":"📡","tokens_out":6912,"duration_ms":65822,"temperature":0.7,"pith_summary":"BatStation asks whether a 5G base station can act as an in-situ radar sensor in shared bands like CBRS, where naval radar and uplink 5G traffic occupy the same spectrum. The paper's central claim is that a radar pulse can be extracted from the base station's received resource grid by reconstructing and canceling the concurrent 5G uplink signal, then correlated against a small set of radar templates generated entirely from synthetic data. Because the templates are built from simulated radar waveforms rather than experimental recordings, the sensing model is hardware-portable and light enough to run in real time: 4,560 parameters, 40M MACs, and sub-millisecond latency. Experiments with real 5G traffic report mean detection probabilities of 97.02% on light-control uplink slots (PUCCH) and 79.23% on heavy-data uplink slots (PUSCH), classification accuracy up to 97.00%, and median localization errors of 2.68-6.20 MHz in frequency and 24.6-32.4 microseconds in time. If correct, this points to a path where spectrum sharing is driven by the base station itself rather than by dedicated radar sensors.","feed_headline":"Zero-shot radar templates turn 5G base stations into radar sensors","feed_subtitle":"Trained only on simulated radar, a 4,560-parameter model detects pulses in live uplink traffic and localizes them to MHz and microseconds.","key_machinery":"The load-bearing object is the radar template set: a small collection of 2D patterns, one or two per radar type (for up- and down-chirps), encoding how each radar pulse appears on the reshaped 5G resource grid. Template correlation acts as a single 2D convolutional layer with no nonlinearities, so its outputs scale linearly with receiver gain, which is what makes the model portable across hardware and trainable on synthetic data alone. Supporting mechanisms are radar signal separation, which reconstructs and subtracts the 5G uplink signal using Hampel-filtered DMRS channel estimates and nearest-constellation rounding of data symbols, and resource grid reshaping, which uses a re-FFT to improv","core_discovery":"The paper's central discovery is that the radar pattern visible on a 5G uplink resource grid is stable enough within a radar type to be captured by a single template, and that this template does not need to be learned from real radar recordings. BatStation constructs templates by simulating radar waveforms, projecting them through the same reshaping the received grid undergoes, averaging the resulting patterns per radar type, and fine-tuning on the synthetic corpus with a cross-entropy loss. At inference, sensing is a 2D correlation between the reshaped residual grid and the template set; the maximum over radar type, frequency, and time indexes gives detection, classification, and localizati","pith_inferences":["Editorial inference: if the decoder's error rate under radar interference is not negligible, the one-shot constellation rounding in the separation step will leak 5G energy; a natural variant would iterate between decoding and radar estimation.","Editorial inference: the same resource-grid reshaping plus template correlation recipe could generalize to other incumbent signals in shared bands, provided their time-frequency footprints can be simulated.","Editorial inference: the reported median frequency errors of up to 6-14 MHz on wideband chirps suggest that localization granularity is set by the pooled subcarrier spacing; finer localization would require smaller pooling factors or sub-grid interpolation at higher computational cost.","Editorial inference: because classification relies on learned negative regions in the templates, confusion among narrowband types under nonlinear channel effects such as clipping or Doppler is the first place portability could break; testing the templates on recorded radar data from diverse receivers would expose that."],"forward_implications":["If the templates transfer zero-shot, a deployed base station can sense new radar types by extending the synthetic corpus, without collecting experimental radar data.","The sub-millisecond runtime (0.11 ms on GPU, 0.94 ms on CPU) is compatible with the 5 ms TDD periodicity, so sensing output can feed scheduling decisions in the same loop that allocates uplink and downlink slots.","The linearity of template correlation means the same templates can be applied on different base station hardware with no recalibration except the detection threshold.","Residual 5G leakage after cancellation behaves like extra interference: detection on data-heavy PUSCH slots is roughly 15 dB worse than on control-heavy PUCCH slots, so separation quality determines the sensing range.","Multiple radar pulses in one resource grid can be reported as multiple local maxima above threshold, extending the design from single-pulse detection to burst-level sensing without changing the model."],"supporting_citations":[{"why":"Supplies the simulated radar waveform generator and the radar-type definitions used to construct the synthetic training corpus for zero-shot template generation.","marker":"[11, 35]"},{"why":"Defines the laboratory procedures and parameter ranges for the five CBRS radar types that the templates encode.","marker":"[42]"},{"why":"Provides the robust median-based filter used to clean DMRS channel estimates so the 5G uplink can be reconstructed and canceled.","marker":"[25]"},{"why":"Classic energy detection method that serves as the baseline for radar existence detection and localization.","marker":"[52]"},{"why":"Deep-learning radar sensing baseline; its need for experimental training data is contrasted with BatStation's zero-shot templates.","marker":"[44]"},{"why":"YOLO-based radar detection baseline used to compare model size, MAC count, and runtime latency.","marker":"[45]"}],"fun_headline_variants":["Zero-shot radar sensing rides on 5G base stations","5G base stations spot radar using synthetic-only templates","No real radar data: 5G base stations sense radar","Zero-shot template turns 5G uplink into radar sensor","In-situ radar sensing on 5G with zero-shot templates"],"cache_read_input_tokens":2688,"weakest_assumption_plain":"Uplink data symbols that a radar pulse lands on can still be demodulated, or corrected by channel decoding, so the transmitted 5G constellation can be reconstructed and subtracted; otherwise residual 5G energy leaks into the correlation and breaks sensing.","fun_headline_variants_meta":{"raw":{"variants":["Zero-shot radar sensing rides on 5G base stations","5G base stations spot radar using synthetic-only templates","No real radar data: 5G base stations sense radar","Zero-shot template turns 5G uplink into radar sensor","In-situ radar sensing on 5G with zero-shot templates"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000948,"raw_usage":{"total_tokens":3938,"prompt_tokens":857,"completion_tokens":3081,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":601,"completion_tokens_details":{"reasoning_tokens":3008}},"tokens_in":601,"tokens_out":3081,"duration_ms":21571,"temperature":1.0,"reasoning_tokens":3008,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-04T22:50:56.589510+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Inject radar pulses into a live 5G uplink at INR 24-38 dB while logging the decoder's block error rate and the residual grid energy after BatStation's cancellation; if data symbols are frequently not demodulated correctly or the residual grid still correlates with scheduled 5G data, the separation step fails. A cleaner test: compare detection probability when the base station knows the true uplink data symbols (ideal cancellation) versus when it must round the constellation; a large gap would confirm the demodulation assumption is load-bearing.","supporting_citations":[{"cited_title":"2017.Procedures for laboratory testing of environ- mental sensing capability sensor devices","cited_arxiv_id":null,"evidence_quote":"Defines the laboratory procedures and parameter ranges for the five CBRS radar types that the templates encode."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the robust median-based filter used to clean DMRS channel estimates so the 5G uplink can be reconstructed and canceled."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Classic energy detection method that serves as the baseline for radar existence detection and localization."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Deep-learning radar sensing baseline; its need for experimental training data is contrasted with BatStation's zero-shot templates."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"YOLO-based radar detection baseline used to compare model size, MAC count, and runtime latency."}],"review_version":1}