{"id":"1f73a234-0432-431d-8abb-bc5f5c13642a","arxiv_id":"2608.10467","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A Mamba-augmented graph neural network jointly designs analog and digital beams, true-time delayers, and radar covariance to maximize minimum secrecy rate under localization constraints in cooperative terahertz ISAC.","lead":"This paper designs a machine learning system that controls beams and radar signals at multiple base stations so they can communicate securely with users while detecting eavesdropping targets in a terahertz network. It claims the system beats conventional optimization and other learning methods in simulations, with fast inference and the ability to adapt to different network sizes.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Feasibility of the constrained problem is unverified: CRB_m <= Omega is only soft-penalized in the training loss, and the paper's own power-allocation step is admitted to break precoding consistency.","rationale":"The reader's weakest_assumption concerns the training/deployment gap over exact target locations and RCS. I regard that as a real but secondary limitation, because the paper explicitly assumes target CSI is available at the BSs, and the channel inputs A_l and B_l already encode target geometry in the simulations. The more load-bearing weakness is internal to the ideal setting: the CRB constraint in problem (14) is only soft-penalized in the loss, and the paper never verifies feasibility of the output against CRB_m <= Omega or the per-BS power constraints. This is exactly the kind of missing support that a conditional verdict should hinge on. I also weight the manuscript's own admission in Section III-B7 that the power-allocation normalization causes inconsistent scaling and degrades interference suppression and leakage mitigation; that is an explicit, self-identified limitation of the proposed solution, not a mere implementation detail. The proposed concrete test directly targets the feasibility question: if the constraint is violated on test samples, the secrecy-rate comparisons in Figs. 6-9 cannot be interpreted as solving (14). Since the reader already returned CONDITIONAL, my stress-test does not change the verdict; it sharpens the condition under which the paper should be accepted: report verifiable CRB feasibility and power-budget checks, or explicitly recast the contribution as a heuristic penalty-based tradeoff rather than a constrained solution.","tokens_in":24764,"tokens_out":8985,"duration_ms":94688,"concrete_test":"Take the trained network from Section IV (or retrain with the same reported setup), draw 1000 fresh test realizations under the Fig. 6 settings (N=3, L=3, N_RF=4 and 16, P=10-30 dBm), compute CRB_m from Theorem 1 for every target m, and report the fraction of samples satisfying max_m CRB_m <= Omega together with the slack distribution. Then recompute the Fig. 6 minimum secrecy-rate curves restricted to feasible samples and compare with the Alt-Min baseline. If the violation rate is non-negligible, or if the feasible-only curves drop below the baseline, the claim that the method satisfies the sensing constraint is refuted; if all constraints hold and the feasible-only curves match Fig. 6, the concern is settled in the paper's favor.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Problem (14) is a constrained optimization: the central claim is that the learned precoder keeps CRB_m <= Omega for all m while maximizing the minimum secrecy rate. In Section III-D, the constraint enters only through the penalty term omega_2 * sum_m (CRB_m - Omega)_+ in L(Theta); a finite penalty does not enforce feasibility. The simulations in Section IV report secrecy rate and runtime, but no test-time CRB values, no violation rate, and no per-BS power-budget verification appear anywhere. Consequently, nothing establishes that the reported secrecy-rate gains are achieved at feasible points of (14). Figure 11 only shows a tradeoff curve and does not compare the achieved CRB against the threshold Omega for the tested configurations. This weakness is compounded by Section III-B7, where the authors explicitly list two unresolved problems caused by their power-allocation normalization: inconsistent scaling across BSs and degraded interference suppression and leakage mitigation. If the trained network operates with CRB_m > Omega on a non-negligible fraction of samples, or if the normalization corrupts the ZF nulling of target channels, then the claimed advantage over the baselines is not a solution of (14), and the central claim is unsupported. This concern is internal to the paper's own stated setup and does not depend on the separate deployment question of whether exact target positions are available.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript studies a cooperative THz bistatic ISAC system in which multiple BSs equipped with ELAA serve K users while localizing M targets, some of which are treated as malicious eavesdroppers. It formulates problem (14), which maximizes the worst-case secrecy rate subject to per-target CRB constraints, with optimization over phase-shifter matrices, TTD delays, digital precoders, and the sensing covariance matrix. The authors derive the FIM and CRB in Theorem 1 and Appendix B, encode the network as a heterogeneous graph, and train a Mamba-empowered GNN with an unsupervised loss that combines the secrecy-rate objective and a penalty on CRB exceedance. Simulations compare the proposed scheme against an Alt-Min optimization benchmark and two learning-based baselines, reporting secrecy-rate gains, generalization over K and M, beampatterns, runtime, and sensitivity to the number of message-passing layers.","tokens_in":25034,"tokens_out":8766,"duration_ms":82278,"significance":"If the central claims were established, the paper would offer a scalable learning-based solution for a genuinely difficult nonconvex, tightly coupled, near-field secure ISAC design problem. The CRB derivation is systematic, the unsupervised training avoids a labeled-data requirement, and the graph architecture is designed to be permutation-invariant and to have linear complexity, all of which are strengths. The paper is also explicit about the limitations of its own power-allocation step. However, the constrained optimization problem is not actually solved as stated: the CRB constraint is only penalized, no feasibility evidence is provided, and the deployment setting appears inconsistent with the information used during training. These are load-bearing gaps, so the current evidence does not support the headline comparison.","major_comments":[{"comment":"The CRB constraint in (14) is implemented only as the penalty term omega_2 * sum_m (CRB_m - Omega)_+ in L(Theta), and a finite weighted penalty does not enforce CRB_m <= Omega. Section IV reports secrecy rates, runtime, beampatterns, and tradeoff curves, but it provides no test-time CRB values, no violation rates, and no per-BS power-budget verification. Figure 11 shows a secrecy-rate/CRB tradeoff but does not compare the achieved CRB against the threshold Omega for the tested configurations. The paper therefore does not establish that the reported secrecy-rate gains are obtained at feasible points of problem (14). Please add a CRB feasibility evaluation and either enforce the constraint by projection, augmented Lagrangian, or a similar mechanism, or explicitly reframe the claim as a penalized tradeoff rather than a solution of (14).","section":"Section III-D and Section IV"},{"comment":"The power-allocation normalization in Section III-B7 is explicitly admitted to introduce inconsistent scaling across BSs and to degrade interference suppression and leakage mitigation. This is not a cosmetic caveat: the digital precoder D_l is constructed by projecting onto the nullspace of the target-channel matrix A_eq_l, and independently rescaling the per-BS blocks D_{n,l} by different lambda_D-dependent factors generally takes the concatenated precoder out of that nullspace. The resulting transmit design may leak information to the targets and may also violate the per-BS power budget. Please verify after normalization that A_eq_l D_l is zero (or negligible) and that the per-BS power constraints are satisfied, or modify the power-allocation step so that it preserves the null-space property.","section":"Section III-B7"},{"comment":"The training loss L(Theta) and the CRB penalty require exact target locations, RCS values, and target channel responses, because the CRB depends on theta, Q, A_l, and B_l. The footnote in Section III-D states that during deployment the network uses only available CSI without exact target locations, but no experiment or analytical argument demonstrates that a model trained with full target geometry transfers to this CSI-only deployment setting. Please either evaluate the deployment scenario explicitly, for example using estimated target parameters, or restrict the claimed operational regime to one in which target locations and RCS values remain available.","section":"Section III-D, deployment footnote"},{"comment":"The FIM derivation appears to have a factor-of-two ambiguity: Eq. (29) includes the standard factor 2 in front of the real part, while the typical-entry expression in Eq. (32) and the block expression in Eq. (13) do not show this factor. If the factor is absorbed into the outer 2 in Theorem 1, please state this explicitly, because the numerical CRB values used in the training loss depend on the correct scaling.","section":"Appendix B, Eq. (29) and Eq. (32)"}],"minor_comments":[{"comment":"The Notations paragraph contains a typo: \"matirx\" should be \"matrix\".","section":"Notations"},{"comment":"In the paragraph on vertices and features, \"TDD matrix\" should read \"TTD matrix\" to match the terminology used throughout the paper.","section":"Section III-A"},{"comment":"The table entry \"Racian factor\" should be \"Rician factor\".","section":"Table III"},{"comment":"The spacing in \"Cram ´er-Rao\" is inconsistent; it should be typeset as \"Cramér-Rao\" throughout.","section":"Abstract and body"},{"comment":"The notation for the digital precoder before and after normalization is not always distinguished; please clarify when D_l denotes the unnormalized ZF output and when it denotes the final power-normalized precoder.","section":"Figure 4 and Algorithm 1"}],"recommendation":"major_revision","confidential_remarks":"The core obstacles are the missing CRB feasibility check and the self-admitted power-allocation flaw in Section III-B7, not the novelty of the architecture. If the authors can add violation-rate results and fix the normalization so that the null-space property and power budgets are preserved, the manuscript could become publishable; otherwise the central claim should be weakened to a penalized objective."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short take: this is a competent and genuinely novel architecture, but the headline claim—that the learned precoder solves the constrained problem (14)—is not actually verified anywhere in the paper. It deserves a serious referee, with major revisions.\n\nWhat is new: the Mamba-empowered GNN is a real architectural combination. It uses heterogeneous graph message passing to handle three coupled design variables (phase shifters, TTDs, and radar covariance) and adds Mamba blocks for selective feature exploitation in near-field THz ISAC. The CRB derivation in Theorem 1 and Appendix B is careful and, as far as I can tell, correct. The unsupervised loss is aligned with the secrecy objective, and the generalization experiments across K and M are a nice touch. The linear complexity claim is plausible.\n\nWhere it goes soft: the CRB constraint in problem (14) is only a soft penalty in the training loss. There is no test-time CRB violation rate, no comparison of achieved CRB against Omega, and no per-BS power-budget verification anywhere in Section IV. So the paper's claim to \"satisfy the sensing requirements\" is unsupported. Section III-B7 is honest about the power allocation problems—inconsistent scaling across BSs and degraded interference/leakage suppression—but that means the actual implemented design deviates from the ZF-based design the authors describe. The deployment gap is real: training uses exact target locations and RCS, while deployment is claimed to work from CSI alone. No experiment evaluates this transfer. Finally, there are no error bars and no released code, so the reported margins are hard to assess.\n\nNone of this is fatal. The paper is a solid contribution to the learning-based ISAC literature, and the directionally positive results are plausible. But the central feasibility claim needs to be demonstrated, not just penalized.\n\nWho this is for: researchers working on GNN-based beamforming, ISAC, or physical-layer security who want a strong baseline and a new architecture to compare against. It is a conference-paper-plus; with the constraint verification added, it could be a solid journal paper. The authors should be asked to supply CRB violation statistics, power-budget checks, error bars, and ideally a deployment simulation with mismatched target information. I'd read it carefully if I were working in this area, but I wouldn't trust the headline numbers until the feasibility evidence appears.","headline":"Competent new architecture, but the constrained-feasibility claim is unverified; deserves peer review with major revisions.","tokens_in":25578,"tokens_out":3097,"would_cite":true,"duration_ms":29459,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A Mamba-empowered graph neural network can jointly design secure THz ISAC transmissions, and simulations show it beats both optimization-based and learning-based benchmarks.","keywords":["terahertz ISAC","secure communication","graph neural network","Mamba","hybrid beamforming","Cramer-Rao bound","near-field communication","extremely large-scale antenna array"],"falsifier":"Run the trained network on test samples where target positions and RCS values are withheld and only the channel-state information presumed available at deployment is fed in; if the minimum secrecy rate drops below the baselines or any $\\mathrm{CRB}_m > \\Omega$ appears, the deployment claim fails.","tokens_in":24570,"feed_emoji":"📡","tokens_out":5549,"duration_ms":48807,"temperature":0.7,"pith_summary":"The paper tries to establish that a graph neural network augmented with Mamba state-space blocks can jointly design analog beamforming, true-time delayers, digital precoding, and sensing covariance in cooperative terahertz ISAC. The aim is to maximize the worst-case secrecy rate against eavesdropping targets while keeping localization error below a Cramér-Rao bound threshold. If the claim holds, secure communication and sensing can be coordinated in a single forward pass that scales linearly with the number of users, replacing costly alternating optimization in near-field ELAA systems. Simulations are presented as evidence that the learned design outperforms both an alternating-minimization baseline and two deep-learning baselines, with inference around $10^{-2}$ seconds.","feed_headline":"GNN-Mamba precoding beats optimization for secure THz ISAC","feed_subtitle":"A learned message-passing design maximizes worst-case secrecy rate while holding localization error in check, in about 10 ms.","key_machinery":"The machinery is a heterogeneous graph whose vertices are users, targets, transmitting-BS RF chains, and a receiving antenna array, with edges carrying the relevant channel vectors. Message passing over this graph produces the analog phase-shifter matrix, the true-time-delay matrix, and the sensing covariance, while a zero-forcing null-space projection and a power-allocation block settle the digital precoder. The Mamba block — a state-space sequence model with an input-dependent selection mechanism — refines the aggregated features and is claimed to keep the overall computational cost linear in the number of users and RF chains.","core_discovery":"The paper's central claim is that problem (14) — maximize the worst-case secrecy rate among users and subcarriers subject to a Cramér-Rao bound constraint on each target's location estimate — can be solved by learned inference instead of iterative optimization. The proposed Mamba-empowered GNN encodes the network as a heterogeneous graph of users, targets, transmitting BS RF chains, and a receiving antenna array, and through message passing produces the phase-shifter matrix, the true-time-delay matrix, and the sensing covariance matrix. A zero-forcing null-space projection supplies the digital precoder, and a power-allocation block splits power between communication and sensing. The paper reports that this learned design achieves higher minimum secrecy rates than the alternating-minimization baseline and the deep-learning baselines while satisfying the sensing constraint, and that it generalizes across different numbers of users and targets.","pith_inferences":["The largest unexamined step is the jump from training with exact target locations and RCS values to deployment with channel state information only; a testable extension is to train with CSI-only features and compare secrecy and CRB on the same test set.","Because the digital precoder nulls the sensing channels, the claimed secrecy depends on how accurately the BS knows the eavesdropper channels; imperfect or adversarial channel knowledge could be probed by adding estimation error.","The same graph-plus-Mamba pattern could be applied to covert ISAC or network-level resource allocation, since the message-passing structure is not specific to THz."],"forward_implications":["Secure ISAC precoding for many users becomes a single forward inference, taking around $10^{-2}$ seconds per sample rather than an iterative solve.","One trained model can serve network topologies with different numbers of users and targets, because the graph representation is permutation-invariant.","The sensing constraint is enforced as a soft penalty during training, so the same architecture can trade secrecy rate against localization accuracy by adjusting the loss weights.","The TTD-assisted hybrid architecture mitigates beam split across subcarriers, making wideband THz secure links more practical.","If the performance advantage holds at scale, learning-based design becomes a viable replacement for alternating optimization in near-field ELAA ISAC systems."],"supporting_citations":[{"why":"Supplies the alternating-minimization baseline that the proposed method must beat.","marker":"[32]"},{"why":"Supplies the zero-forcing hybrid precoding scheme used to compute the digital precoder inside the GNN.","marker":"[41]"},{"why":"Supplies the Mamba state-space architecture whose selection mechanism is the core enhancement.","marker":"[42]"},{"why":"Supplies the conference-version CVNN baseline compared in simulations.","marker":"[1]"},{"why":"Supplies the CNN-LSTM deep-learning baseline extended to the TTD-aided wideband architecture.","marker":"[33]"},{"why":"Supplies the near-field ISAC Cramér-Rao bound characterization used in the sensing constraint.","marker":"[40]"},{"why":"Supplies the wideband near-field ISAC signal model whose FIM structure the paper extends.","marker":"[9]"}],"fun_headline_variants":["GNN-Mamba precoding outpaces iterative THz ISAC","Mamba-GNN precoder secures THz ISAC with high secrecy","Cooperative THz ISAC: GNN-Mamba precoding maximizes secrecy","Learned Mamba-GNN precoding for secure THz ISAC","GNN-Mamba precoding secures THz ISAC in milliseconds"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The network is trained with exact target positions and reflection strengths, but at deployment it is supposed to work using only channel measurements, and the paper provides no evidence that those measurements alone are enough to steer nulls at the right targets.","fun_headline_variants_meta":{"raw":{"variants":["GNN-Mamba precoding outpaces iterative THz ISAC","Mamba-GNN precoder secures THz ISAC with high secrecy","Cooperative THz ISAC: GNN-Mamba precoding maximizes secrecy","Learned Mamba-GNN precoding for secure THz ISAC","GNN-Mamba precoding secures THz ISAC in milliseconds"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001021,"raw_usage":{"total_tokens":4345,"prompt_tokens":1019,"completion_tokens":3326,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":635,"completion_tokens_details":{"reasoning_tokens":3229}},"tokens_in":635,"tokens_out":3326,"duration_ms":19570,"temperature":1.0,"reasoning_tokens":3229,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T14:20:06.692821+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the trained network on test samples where target positions and RCS values are withheld and only the channel-state information presumed available at deployment is fed in; if the minimum secrecy rate drops below the baselines or any $\\mathrm{CRB}_m > \\Omega$ appears, the deployment claim fails.","supporting_citations":[{"cited_title":"TTD configurations for near- field beamforming: Parallel, serial, or hybrid?","cited_arxiv_id":null,"evidence_quote":"Supplies the alternating-minimization baseline that the proposed method must beat."},{"cited_title":"On ergodic energy efficiency of mmWave heterogeneous cell-free systems with ZF hybrid precoders,","cited_arxiv_id":null,"evidence_quote":"Supplies the zero-forcing hybrid precoding scheme used to compute the digital precoder inside the GNN."},{"cited_title":"Unsupervised CVNN hybrid beamforming for secure near-field THz-ISAC in XL- MIMO,","cited_arxiv_id":null,"evidence_quote":"Supplies the conference-version CVNN baseline compared in simulations."},{"cited_title":"A CNN-LSTM-based fusion separation deep neural network for 6G ultra-massive MIMO hybrid beamforming,","cited_arxiv_id":null,"evidence_quote":"Supplies the CNN-LSTM deep-learning baseline extended to the TTD-aided wideband architecture."},{"cited_title":"Near-field integrated sensing and communication with extremely large-scale antenna array,","cited_arxiv_id":null,"evidence_quote":"Supplies the near-field ISAC Cramér-Rao bound characterization used in the sensing constraint."},{"cited_title":"Wideband near-field integrated sensing and communication with sparse transceiver design,","cited_arxiv_id":null,"evidence_quote":"Supplies the wideband near-field ISAC signal model whose FIM structure the paper extends."}],"review_version":1}