Pith. sign in

REVIEW 3 major objections 6 minor 31 references

HoloTrace: a Location Privacy-Preserving Framework for mmWave MIMO-OFDM Systems

T0 review · 3 major / 6 minor · reviewed 2026-08-04 · deepseek-v4-flash

Pith's one-line read HoloTrace claims that a user can spoof its position to a single base station by perturbing only the pilot signal, with complete spoofing under full channel-gain knowledge and obfuscation without it.

desk verdict Solid oracle-only spoofing math; practical claim outruns the CSI assumption. read the letter →

arxiv 2509.23444 v2 pith:5IZXNSMV submitted 2025-09-27 eess.SP

classification eess.SP
keywords 6Glocalizationlocationprivacysignalspoofingsingle-anchorpositioningmmWaveMIMO-OFDMTDoA/AoDpilotperturbationphysical-layersecurity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

HoloTrace claims that a user equipment in a single-base-station mmWave MIMO-OFDM link can prevent non-consensual localization by strategically perturbing only its pilot transmissions. The perturbation is designed so the base station's channel estimator sees a fictitious geometric channel—shifted angles of arrival/departure and time differences of arrival—while the communication precoder stays untouched. With full knowledge of the complex channel gains, the oracle version achieves complete spoofing: the base station's position estimate lands exactly at the user-chosen fake position. Without gain knowledge, the blind version cannot reliably spoof but can still obfuscate the location. The significance is a waveform-level privacy mechanism that needs no protocol changes or network-side cooperation.

What carries the argument

The central object is the pilot tensor perturbation, constructed by element-wise (Hadamard) division of a spoofed channel steering tensor by the true channel steering tensor. This division cancels the true geometric factors in the received signal and replaces them with the spoofed ones, so the base station's least-squares estimator is minimized at the fake parameters. In the oracle regime this yields closed-form pilots for AoA, AoD, ToA, and their joint MIMO-OFDM combination; in the blind regime, Kronecker-structured pilots split the manipulation into independent AoA, AoD, and delay factors, enabling approximate spoofing or obfuscation without channel-gain knowledge.

What would settle it

Run the oracle HoloTrace design on a testbed where the UE knows its position and a map but has no instantaneous complex path gains, then have the BS estimate position with a standard multipath estimator at high SNR. If the BS estimate does not systematically land at the chosen fake location—or if the blind design's error is no larger than the no-spoofing error—the central spoofing claim fails under realistic CSI.

Watch

Extended reading notes

Core claim

The paper's central claim is that a single pilot perturbation block, inserted at the UE's pilot generator, can reshape the geometric trace of the transmitted waveform so that a single-BS localization procedure based on AoA, AoD, and TDoA estimates a fake position. The spoofing is posed as a unified rank-constrained projection problem, with closed-form pilots in the oracle (CSI-known) regime and blind constructions in the no-CSI regime. Under the oracle assumption the perturbation is exact: the estimator's output matches the theoretical spoofing offset, meaning the BS is fully deceived while the precoder remains unchanged and the link capacity loss is small if the spoofed position is chosen w

Load-bearing premise

The exact complete-spoofing result depends on the user knowing the complex gains (amplitudes and phases) of all propagation paths, which the paper says are rarely available; without that knowledge the blind methods only obfuscate and suffer a path-pairing error.

Editorial extensions

If this is right

  • If the oracle claim holds, a UE with accurate self-location and channel-gain knowledge can force a single-BS estimator to report any feasible fake position with error equal to the chosen spoofing offset.
  • The spoofing is invisible to the precoder: no beamforming or protocol changes are needed, so it can run on analog-array hardware.
  • Link capacity impact is controllable by choosing a spoofing position whose channel slice aligns with the true one; an optimized fake position can keep rate comparable to no-spoofing.
  • Blind spoofing, needing no gain knowledge, still moves the estimated position far from the true location, even if it cannot reliably hit a chosen fake position.
  • Shift-only spoofing methods fail against difference-based single-anchor localization, since the position estimator is invariant to common delays.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: complete spoofing requires the UE to know instantaneous complex path gains, which the paper itself notes are rarely available; the practical privacy guarantee is therefore obfuscation, not precise location forgery, unless UE-side gain estimation improves.
  • Editorial inference: the same pilot-perturbation capability could complicate physical-layer authentication, because a device that can reshape its spatial and delay signature may evade location-based identity checks; the paper notes this dual-use tension but does not develop defences.
  • Editorial inference: a direct next step is a hardware testbed with a real analog-array UE and a single BS; if measured position errors track the spoofing offset under oracle conditions, the waveform-level approach transfers to practice.
  • Editorial inference: the blind Kronecker pilot's path-pairing problem suggests that decoupled per-dimension estimators or pilot designs preserving angle-delay association could turn current obfuscation into reliable blind spoofing, which the paper lists as future work.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper proposes HoloTrace, a UE-side pilot perturbation framework for spoofing the AoA, AoD, and TDoA estimates used by a single BS for mmWave MIMO-OFDM localization. Spoofing is formulated as choosing a pilot tensor so that the noiseless received signal matches a target channel model with attacker-chosen geometric parameters, while leaving the precoder unchanged. The paper gives closed-form 'oracle' constructions under full knowledge of the complex path gains (Props. 1–3), and 'blind' constructions that avoid gain knowledge (Props. 4–6), including an approximate subspace method and a fake-path-injection scheme. Simulations with the FLEX estimator show that the oracle solution matches the desired spoofing offset at high transmit power, the angle-only blind solution approximates it, and the full blind solution obfuscates but fails to reliably spoof due to a pairing problem.

Significance. The oracle derivation is a useful and non-circular construction: the pilot is an explicit pre-image that forces the noiseless received signal onto the spoofed channel manifold, and the target location is chosen independently of the estimator. This is a clean theoretical upper bound and an advance over shift-based approaches such as DAIS, which the paper correctly shows are ineffective for single-anchor difference-based localization. The treatment of asynchronous UEs, analog arrays, and single-BS multipath geometry is valuable. However, the practical significance of the headline claim rests on the availability of exact complex channel gains at the UE, an assumption the paper itself states is rarely met; the blind alternatives do not achieve reliable position spoofing in the paper's own results. The work is therefore best viewed as an oracle-benchmark plus a partial blind-obfuscation design, and the claims should be scaled accordingly.

major comments (3)
  1. [§III-A, §III-B5, §IV-D4] The paper's 'complete spoofing' result is established only for the oracle solution (O-HT), which requires exact knowledge of the complex path gains α and the geometric parameters ρ. Section III-A explicitly states that these gains are 'rarely available at the UE side.' The constructions in Props. 1–3 divide by the true channel tensor (e.g., Eq. (29)), so any error in α propagates directly into the spoofed pilot and hence into the BS estimate. The robustness test in Sec. IV-D4 perturbs only the UE location (σ_UE), not the channel gains, so it does not address this missing input. To support the practical claim, the authors need either a concrete mechanism for obtaining α with a quantified error model, or a significant reframing of O-HT as an oracle upper bound.
  2. [§III-C5, §IV-D2, Fig. 6–7] There is a mismatch between the claims for the blind Kronecker solution and its simulated behavior. Proposition 6 states that the blind construction enables independent manipulation of AoA, AoD, and TDoA 'achieving blind, multi-parameter spoofing,' while Sec. IV-D2 reports that B-HT 'cannot reliably spoof' and 'obfuscate but cannot reliably spoof,' with a pairing problem shown in Fig. 7; Fig. 6 omits B-HT entirely because of the large error. The residual bias does not vanish with increasing transmit power. The abstract's phrase 'including scenarios with and without CSI knowledge' therefore overstates what is supported. The authors should either revise the blind design to overcome the pairing issue or substantially qualify the claims about blind spoofing.
  3. [§III-B, Eqs. (25), (26), (29)] The closed-form pilot constructions allow arbitrary complex pilot entries and impose only a loose total-power constraint through the choice of λ. In practical OFDM/analog-array transmitters, pilot symbols must satisfy per-antenna peak-power or constant-modulus constraints. Since the constructions are pointwise divisions by entries of the true channel tensor (e.g., Eq. (29) divides by A×1 B×2 C×3 D), near-zero entries of the denominator can make the pilot entries arbitrarily large even if the total power is fixed. The paper does not discuss whether the spoofing construction remains feasible under realistic per-antenna constraints. This is load-bearing for the claimed practical deployment and should be addressed, even if only by stating explicit feasibility conditions.
minor comments (6)
  1. [§I-C] Typo: 'The is organized as follows.' should read 'The paper is organized as follows.'
  2. [Fig. 3] The caption for Fig. 3b says 'Fig. 3a gives an illustrative example of AoD spoofing'; it should refer to Fig. 3b.
  3. [§II-A] The definition of F is inconsistent: the text says F=[f0 ... f_{M-1}], but f_s is defined for s=0,...,S-1 and C=F^H A_NT should have S columns. Please correct the index range.
  4. [Appendix C, §III-C1] In the single-path case, the sentence 'as long as no component of b(θ0) when the corresponding component...' is garbled; the zero-component condition needs to be stated cleanly.
  5. [§III-C3] The fake-path-injection TDoA result assumes the BS delay estimator selects the two smallest ToAs (or a shortest-path rule). This estimator behavior is not part of the system model in Sec. II and should be stated explicitly as an assumption in the threat model.
  6. [Abstract and §III] The abstract describes the problem as a 'rank-constrained projection problem,' but no rank constraint appears in Eqs. (13)–(15); the formulation is a feasibility/projection problem. Please align the terminology.

Circularity Check

1 steps flagged · score 6.0 of 10

AoB-HT evaluation retrofits the spoofing target from the method's own output, making its 'spoofing deviation' a self-fulfilling metric; the oracle and blind constructions are otherwise direct and not circular.

  1. self definitional [Sec. IV-D2, Fig. 6 (Performance Metrics vs Transmit Power)]
    "Location #3 is derived from (8) using the estimated measurements of the AoB-HT solution (see Sec. IV-D3). In Fig. 6b, ... The purple diamond curve, instead, shows the spoofing deviation of AoB-HT with respect to the location #3. ... (iv) Angle-only blind (AoB-HT) offers a more promising spoofing capability than B-HT. ... it better approximates the spoofed location, especially at higher transmit powers."

    For the AoB-HT variant, the 'desired spoofed location' (#3) is not chosen a priori; it is computed from the estimator's own output by plugging the AoB-HT estimated measurements into equation (8). The spoofing deviation metric then measures the distance between the estimator output and this retroactively defined target. Since the target is a deterministic function of the output, the reported small deviation is forced by construction. The subsequent claim that AoB-HT 'better approximates the spoofed location' is therefore tautological: the 'spoofed location' has been defined as whatever the AoB-HT estimator produces.

full rationale

The central derivation is constructive rather than circular: Proposition 3 (Eq. 29) explicitly constructs the pilot as the Hadamard quotient of the spoofed and true channel tensors, so the noiseless received signal equals the spoofed channel by design; the BS LS estimator then returns the spoofed parameters. That is a direct pre-image construction, not a fitted-parameter prediction, and the target location is chosen before running the estimator. The blind B-HT result is honestly reported to suffer a path-pairing problem (Sec. IV-D2, Fig. 7), and the oracle's practical limitation — exact complex path gains 'rarely available at the UE side' (Sec. III-A) — is explicitly acknowledged; these are correctness risks, not circularity. Self-citations ([14], [31]) are not load-bearing: the L=1 blind case is re-derived in Appendix C, and FLEX is an independent estimator used in simulation. The one genuine circular step is the AoB-HT 'location #3' metric: the spoofing target is derived from AoB-HT's own estimated measurements via Eq. (8), so the spoofing deviation to that target is forced by construction and cannot support the claim that AoB-HT 'better approximates the spoofed location.' This is a partial, secondary circularity, giving a score of 6.

Assumptions & free parameters 3 free parameters · 6 assumptions · 0 invented entities

The framework introduces no new physical entities; it relies on standard signal models, a specific BS estimator, and attacker knowledge assumptions. The main unpublished costs are the channel-gain knowledge for the oracle, the unspecified choice of spoofing gains and fake-path amplitudes, and the loose treatment of transmitter power constraints.

free parameters (3)
  • spoofed path gain vector lambda = arbitrary, not specified
    In Props. 1-3 (oracle) and Prop. 6 (blind), the vector lambda (or tensor L) shapes the spoofed pilot. The paper says it is 'also used to constrain the pilot power' but gives no method to choose it under per-antenna power limits, so the central feasibility result depends on this unspecified choice.
  • fake path injection coefficients {lambda_i} = unspecified complex scalars
    Sec. III-C3b says to 'select amplitudes {lambda_i} for energy normalization or further control' but never specifies the selection rule; the claimed arbitrary TDoA control relies on these values, yet the estimator's path-selection behavior is not tied to them.
  • simulation scenario geometry = p_UE=[10,5], p_spoof#1=[30,-20], #2 optimized by rate, #3 from AoB-HT
    The rate heatmap (Fig. 4) and RMSE comparisons (Fig. 6) use hand-picked positions; location #2 is specifically optimized post hoc to show a favorable rate result, so the 'minimal impact on link capacity' conclusion depends on this selection.
assumptions (6)
  • domain assumption The mmWave channel is sparse with L paths, single-bounce NLoS, ULA steering vectors, and known 2D geometry (Eq. 1)
    Section II-A: the entire localization and spoofing model rests on this channel model.
  • domain assumption The BS estimates channel parameters via LS/ML against the agreed pilot model and localizes via TDoA plus two angles (Eqs. 8-11)
    Section II-B and III-A: the spoofing design assumes the BS follows this specific estimator and the single-anchor TDoA localization rule.
  • domain assumption The UE knows its true geometric parameters rho and the environment map (SP positions) for both oracle and blind designs
    Section III-A: 'geometric parameters can be derived from external information, such as GNSS and environmental maps'; this is load-bearing because any location uncertainty propagates to spoofing error (Fig. 9).
  • domain assumption The UE knows the complex path gains alpha (amplitudes and phases) for the oracle solutions
    Section III-A: the coherent regime is defined as knowledge of both alpha and rho; the paper itself notes alpha is 'rarely available at the UE side', making the precise-spoofing regime contingent.
  • ad hoc to paper Spoofed pilots may take arbitrary complex values under only a loose total-power constraint; no constant-modulus or per-antenna peak constraint is enforced
    Section III-A states 'subject to UE-side power constraints' but the closed-forms (e.g., Eq. 26) involve Hadamard division that can produce unbounded entries; practical analog-array transmitters have peak power limits.
  • ad hoc to paper The TDoA estimator selects the two smallest ToAs (or a 'shortest path' rule) among the injected and true delays
    Section III-C3b: the fake-path-injection guarantee depends on the estimator choosing the intended delay pair, but no proof or amplitude-based selection mechanism is given.

how reviews work

0 comments
Cite this review

Pith. "Pith review of HoloTrace: a Location Privacy-Preserving Framework for mmWave MIMO-OFDM Systems." pith.science (2026). https://pith.science/paper/5IZXNSMV

@misc{pith2026250923444,
  author       = {Pith},
  title        = {Pith review of: HoloTrace: a Location Privacy-Preserving Framework for mmWave MIMO-OFDM Systems},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/5IZXNSMV}},
  note         = {Machine review of arXiv:2509.23444}
}
read the original abstract

The technological innovation towards 6G cellular networks introduces unprecedented capabilities for user equipment (UE) localization, but it also raises serious concerns about physical layer location privacy. This paper introduces HoloTrace, a signal-level privacy preservation framework that relies on user-side spoofing of localization-relevant features to prevent the extraction of precise location information from the signals received by a base station (BS) in a mmWave MIMO-OFDM system. Spoofing is performed by the user on location parameters such as angle of arrival (AoA), angle of departure (AoD), and time difference of arrival (TDoA). Without requiring any protocol modification nor network-side support, our method strategically perturbs pilot transmissions to prevent a BS from performing non-consensual UE localization. The methodology allows the UE to spoof its position, keeping the precoder unchanged. We formulate spoofing as a unified rank-constrained projection problem, and provide closed-form solutions under varying levels of channel state information (CSI) at the UE, including scenarios with and without CSI knowledge. Simulation results confirm that the proposed approach enables the UE to deceive the BS, inducing significant localization errors, while the impact on link capacity varies depending on the spoofed position. Our findings establish HoloTrace as a practical and robust privacy-preserving solution for future 6G networks.

Figures

Figures reproduced from arXiv: 2509.23444 by the authors.

Figure 1
Figure 1. Considered single-BS positioning scenario where UE and BS [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Oracle knowledge spoofing: (a) MF AoA estimation with [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. Blind spoofing: (a) AoA estimation with NR = M = 24, (b) AoD estimation with NT = S = 8, and (c) ToA estimation with K = 120 kHz. The solid blue lines show the MF estimations without spoofing. The red and black dashed lines correspond to the first and 10th iterations of the blind spoofing method, respectively. The dashed markers indicate the true values (blue) and the spoofed values (red). The red dotted lines highl… view at source ↗
Figures from the paper (6 more)
Figure 4
Figure 4. Figure 4: Channel rate evaluation heatmap for each spoofing position [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: Channel rate performance comparison. 1) Channel Rate vs Transmit Power: To assess how the communication link quality is influenced by the selected spoofing position, we analyze the channel rate R, as defined in (10), over the BS coverage area within a radius of 50 m an…
Figure 6
Figure 6. Figure 6: Performance metrics comparison between the different [PITH_FULL_IMAGE:figures/full_fig_p010_6.png]
Figure 7
Figure 7. Figure 7: Pairing problem example for Blind HoloTrace solution, [PITH_FULL_IMAGE:figures/full_fig_p011_7.png]
Figure 8
Figure 8. Figure 8: HoloTrace (a) AoA and (b) AoD measurement deviation of [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]
Figure 9
Figure 9. Figure 9: Oracle HoloTrace robustness to UE location uncertainty. [PITH_FULL_IMAGE:figures/full_fig_p011_9.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

31 extracted references · 4 linked inside Pith

  1. [1]

    Positioning using wireless networks: Applications, recent progress, and future challenges,

    Y . Yanget al., “Positioning using wireless networks: Applications, recent progress, and future challenges,”IEEE Journal on Selected Areas in Communications, vol. 42, no. 9, pp. 2149–2178, 2024

  2. [2]

    A tutorial on 5G positioning,

    L. Italiano, B. Camajori Tedeschini, M. Brambilla, H. Huang, M. Nicoli, and H. Wymeersch, “A tutorial on 5G positioning,”IEEE Communications Surveys & Tutorials, vol. 27, no. 3, pp. 1488–1535, 2025

  3. [3]

    Positioning and sensing in 6G: Gaps, challenges, and opportunities,

    A. Behravanet al., “Positioning and sensing in 6G: Gaps, challenges, and opportunities,”IEEE Vehicular Technology Magazine, vol. 18, no. 1, pp. 40–48, 2022

  4. [4]

    Location privacy in B5G/6G: Systematization of knowledge,

    H. B. Pasandi and F. Parastar, “Location privacy in B5G/6G: Systematization of knowledge,”arXiv preprint arXiv:2406.00359, 2024

  5. [5]

    Cooperative ISAC under spoofing attacks,

    U. Ali, N. B. Melazzi, and S. Bartoletti, “Cooperative ISAC under spoofing attacks,”IEEE Wireless Communications Letters, pp. 1–1, 2025

  6. [6]

    OFDM-based JCAS under attack: The dual threat of spoofing and jamming in WLAN sensing,

    H. Can Yildirim, M. Furkan Keskin, H. Wymeersch, and F. Horlin, “OFDM-based JCAS under attack: The dual threat of spoofing and jamming in WLAN sensing,”IEEE Internet of Things Journal, vol. 12, no. 10, pp. 14 511–14 525, 2025

  7. [7]

    Location-privacy-preserving technique for 5G mmwave devices,

    J. J. Checa and S. Tomasin, “Location-privacy-preserving technique for 5G mmwave devices,”IEEE Communications Letters, vol. 24, no. 12, pp. 2692–2695, 2020

  8. [8]

    Privacy preservation in MIMO-OFDM localization systems: A beamforming approach,

    Y . Zhanget al., “Privacy preservation in MIMO-OFDM localization systems: A beamforming approach,”IEEE Wireless Communications Letters, vol. 14, no. 7, pp. 1979–1983, 2025

Show all 31 references
  1. [9]

    Users are closer than they appear: Protecting user location from WiFi APs,

    R. Ayyalasomayajula, A. Arun, W. Sun, and D. Bharadia, “Users are closer than they appear: Protecting user location from WiFi APs,” in Proceedings of the 24th International Workshop on Mobile Computing Systems and Applications. Newport Beach California: ACM, 2023, pp. 124–130

  2. [10]

    Beamforming and artificial noise for cross-layer location privacy of e-health cellular devices,

    S. Tomasin, “Beamforming and artificial noise for cross-layer location privacy of e-health cellular devices,” in2022 IEEE International Conference on Communications Workshops (ICC Workshops). IEEE, 2022, pp. 568–573

  3. [11]

    Channel state information-free location-privacy enhancement: Fake path injection,

    J. Li and U. Mitra, “Channel state information-free location-privacy enhancement: Fake path injection,”IEEE Transactions on Signal Processing, vol. 72, pp. 3745 – 3760, 2024

  4. [12]

    Delay-angle information spoofing for channel state information- free location-privacy enhancement,

    ——, “Delay-angle information spoofing for channel state information- free location-privacy enhancement,”arXiv preprint arXiv:2504.14780, 2025

  5. [13]

    Leveraging angle of arrival estimation against impersonation attacks in physical layer authentication,

    T. M. Pham, L. Senigagliesi, M. Baldi, R. F. Schaefer, G. P. Fettweis, and A. Chorti, “Leveraging angle of arrival estimation against impersonation attacks in physical layer authentication,”arXiv preprint arXiv:2503.11508, 2025

  6. [14]

    AoA-based physical layer authentication in analog arrays under impersonation attacks,

    M. Srinivasan, L. Senigagliesi, H. Chen, A. Chorti, M. Baldi, and H. Wymeersch, “AoA-based physical layer authentication in analog arrays under impersonation attacks,” in2024 IEEE 25th International Workshop on Signal Processing Advances in Wireless Communications (SPAWC). IEE...

  7. [15]

    Cooperative impersonation in angle-based physical layer authentication,

    A. Pourafzal, H. Chen, M. Srinivasan, Y . Zhang, and H. Wymeersch, “Cooperative impersonation in angle-based physical layer authentication,” inIEEE International Conference on Communications (ICC). IEEE, 2025

  8. [16]

    Your locations may be lies: Selective-PRS-spoofing attacks and defence on 5G NR positioning systems,

    K. Gao, H. Wang, H. Lv, and P. Gao, “Your locations may be lies: Selective-PRS-spoofing attacks and defence on 5G NR positioning systems,” inIEEE INFOCOM 2023 - IEEE Conference on Computer Communications. New York City, NY , USA: IEEE, May 2023, pp. 1–10

  9. [17]

    Surgical strike on 5G positioning: Selective-PRS-spoofing attacks and its defence,

    K. Gao, H. Wang, and H. Lv, “Surgical strike on 5G positioning: Selective-PRS-spoofing attacks and its defence,”IEEE Journal on Selected Areas in Communications, vol. 42, no. 10, pp. 2922–2937, 2024

  10. [18]

    Tomasin, H

    S. Tomasin, H. Fang, and X. Wang,Physical-Layer Authentication for 6G Systems. John Wiley & Sons, Ltd, 2024, ch. 11, pp. 221–237

  11. [19]

    A comparative study of 3D UE positioning in 5G new radio with a single station,

    B. Sun, B. Tan, W. Wang, and E. S. Lohan, “A comparative study of 3D UE positioning in 5G new radio with a single station,”Sensors, vol. 21, no. 4, p. 1178, 2021

  12. [20]

    Single-anchor two-way localization bounds for 5G mmwave systems,

    Z. Abu-Shaban, H. Wymeersch, T. Abhayapala, and G. Seco-Granados, “Single-anchor two-way localization bounds for 5G mmwave systems,” IEEE Transactions on Vehicular Technology, vol. 69, no. 6, pp. 6388– 6400, 2020

  13. [21]

    Experimental validation of single BS 5G mmWave positioning and mapping for intelligent transport,

    Y . Geet al., “Experimental validation of single BS 5G mmWave positioning and mapping for intelligent transport,”IEEE Transactions on Vehicular Technology, vol. 73, no. 11, pp. 16 744–16 757, 2024

  14. [22]

    Position information from reflecting surfaces,

    A. Kakkavas, M. H. Casta ˜neda Garc ´ıa, G. Seco-Granados, H. Wymeersch, R. A. Stirling-Gallacher, and J. A. Nossek, “Position information from reflecting surfaces,”IEEE Wireless Communications Letters, vol. 10, no. 6, pp. 1300–1304, 2021

  15. [23]

    5G vehicle positioning in tunnels with single anchor TDOA exploiting multipath reflectors,

    L. Italiano, M. Brambilla, and M. Nicoli, “5G vehicle positioning in tunnels with single anchor TDOA exploiting multipath reflectors,” in 33rd European Signal Processing Conference (EUSIPCO). Palermo, Italy: IEEE, 2025, pp. 1–5

  16. [24]

    Beam training and tracking in mmwave communication: A survey,

    W. Yi, W. Zhiqing, and F. Zhiyong, “Beam training and tracking in mmwave communication: A survey,”China Communications, vol. 21, no. 6, pp. 1–22, 2024

  17. [25]

    The integrated sensing and communication revolution for 6G: Vision, techniques, and applications,

    N. Gonz ´alez-Prelcicet al., “The integrated sensing and communication revolution for 6G: Vision, techniques, and applications,”Proceedings of the IEEE, vol. 112, no. 7, pp. 676–723, 2024

  18. [26]

    Joint initial access and localization in millimeter wave vehicular networks: a hybrid model/data driven approach,

    Y . Chen, J. Palacios, N. Gonz ´alez-Prelcic, T. Shimizu, and H. Lu, “Joint initial access and localization in millimeter wave vehicular networks: a hybrid model/data driven approach,” in2022 IEEE 12th Sensor Array and Multichannel Signal Processing Workshop (SAM), 2022, pp. 355– 359

  19. [27]

    Learning to localize with attention: From sparse mmwave channel estimates from a single BS to high accuracy 3D location,

    Y . Chen, N. Gonz ´alez-Prelcic, T. Shimizu, and H. Lu, “Learning to localize with attention: From sparse mmwave channel estimates from a single BS to high accuracy 3D location,”arXiv preprint arXiv:2307.00167, 2023

  20. [28]

    Performance bounds for parameter estimation under misspecified models: Fundamental findings and applications,

    S. Fortunati, F. Gini, M. S. Greco, and C. D. Richmond, “Performance bounds for parameter estimation under misspecified models: Fundamental findings and applications,”IEEE Signal Processing Magazine, vol. 34, no. 6, pp. 142–157, 2017

  21. [29]

    Some notes on alternating optimization,

    J. C. Bezdek and R. J. Hathaway, “Some notes on alternating optimization,” inAdvances in Soft Computing—AFSS 2002: 2002 AFSS International Conference on Fuzzy Systems Calcutta, India, February 3–6, 2002 Proceedings. Springer, 2002, pp. 288–300

  22. [30]

    A unified RCS modeling of typical targets for 3GPP ISAC channel standardization and experimental analysis,

    Y . Zhanget al., “A unified RCS modeling of typical targets for 3GPP ISAC channel standardization and experimental analysis,”arXiv preprint arXiv:2505.20673, 2025

  23. [31]

    FLEX: Low-complexity 5D beamspace channel estimation for mmWave MIMO-OFDM,

    A. Pourafzal, H. Huang, V . Pettersson, M. F. Keskin, and H. Wymeersch, “FLEX: Low-complexity 5D beamspace channel estimation for mmWave MIMO-OFDM,” in33rd European Signal Processing Conference (EUSIPCO). Palermo, Italy: IEEE, 2025, pp. 1–5

Pith tools

Reviewed August 4, 2026 · model on record in the stance chip above.