Pith. sign in

REVIEW 2 major objections 4 minor 23 references

A temporal noise vector placed in the OFDM cyclic prefix can secure both data and sensing at once.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-01 22:32 UTC pith:5LIGM36M

load-bearing objection A clever dual-threat formulation with a load-bearing hole: the SU-as-Eve can cancel the AN it already knows as its sensing reference, so the data-security claim only holds if you restrict the adversary to a strawman receiver. the 2 major comments →

arxiv 2607.15710 v1 pith:5LIGM36M submitted 2026-07-17 eess.SP cs.ITmath.IT

Dual-Security for Indoor OFDM-ISAC Systems via Temporal Artificial Noise

classification eess.SP cs.ITmath.IT
keywords integrated sensing and communicationphysical layer securityartificial noiseOFDMdual securityeavesdroppingtarget impulse response estimationconvex optimization
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The paper sets out to close a gap in secure integrated sensing and communication (ISAC): prior work protects either the data link or the sensing function, not both. It considers an indoor OFDM system in which the sensing user may eavesdrop on data and the communication user may perform unauthorised sensing, and claims that a single temporal artificial-noise (AN) vector can handle both threats. The AN is hidden in the cyclic prefix and chosen to lie in the null space of the communication user's channel, so the CU's decoding is unaffected, while the SU's decoding SINR drops because the AN is not null at that user. Because the same AN appears in both the SU's reference signal and the target echo, the SU's sensing remains accurate, whereas the CU, lacking the AN, suffers a sensing mismatch; a convex power-allocation problem tunes these four effects.

Core claim

On the paper's own terms, the central discovery is that assigning AN in the time domain creates a useful asymmetry between two receivers. The transmitter sends x = w̃ + Uv with U chosen from the null space of R_CP H_CU, so after CP removal and FFT the CU sees only the clean data term H̃_CU W^{1/2} c. At the SU, the same AN survives and degrades the frequency-domain SINR. For sensing, both users receive echoes of the full transmitted frame; the SU knows x and therefore estimates the target response with error only from AWGN, while the CU, unaware of the AN, uses w̃ as reference and incurs an AN-induced error. The paper formulates an optimization that maximizes CU communication SNR minus SU se

What carries the argument

The load-bearing object is the temporal AN vector s = Uv, a low-dimensional signal superimposed on the OFDM time-domain waveform, with its precoder U chosen to lie in the null space of the CP-removed CU channel. Its work is to be simultaneously invisible at the CU's FFT output, visible at the SU's FFT output, present in both the SU's reference and echo for sensing, and absent from the CU's reference, producing the AN mismatch that degrades CU sensing. The least-squares target-response estimators (X^{-1} z at the SU, W̃^{-1} z at the CU) turn this presence/absence into the MSE gap used as the sensing-security metric.

Load-bearing premise

The design assumes the sensing user, when eavesdropping, uses only standard CP-removal and FFT and never applies the knowledge of the artificial noise, precoder, and its own channel that its legitimate sensing role gives it.

What would settle it

Construct an SU receiver that subtracts the AN term F R_CP H_SU Uv from its CP-removed FFT input using its known s, U, and channel estimate; if the resulting decoding SINR equals the clean-data level, the claimed communication-security protection is void.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • A single-antenna indoor OFDM-ISAC system can achieve dual security — communication and sensing — with one AN stream rather than separate mechanisms.
  • The SU's sensing MSE is independent of how power is split between data and AN; it depends only on total transmit power, so sensing security can be added without sacrificing the legitimate sensing user's accuracy.
  • Stricter data-security requirements (lower SU decoding SINR threshold) reduce the CU's communication SNR, exposing a tunable trade-off between security strength and legitimate communication quality.
  • Stricter sensing-security requirements (higher CU sensing MSE threshold) also reduce CU communication SNR, because more AN power is needed in the echo path.
  • The optimized power allocation can be found to global optimality via convex optimization, making the scheme implementable with standard solvers.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If an eavesdropping SU exploits the very knowledge it needs for sensing — the transmitted frame including s, the precoder U, and its own channel — it can subtract the AN interference before decoding; the paper's data-security conclusion therefore holds only for an SU that uses standard OFDM receiver processing rather than its full information.
  • The sensing-security argument depends on the CU never learning or estimating the AN; if the AN pattern is shared or predictable, the CU could include it in its reference and the sensing gap would close.
  • The same cyclic-prefix AN design could plausibly be extended to multi-antenna and outdoor OFDM-ISAC systems, where range-Doppler sensing replaces impulse-response estimation, but the presence/absence asymmetry would need to be re-derived for those channel models.
  • A testable extension is to evaluate secrecy rate directly instead of SINR, since the data-security guarantee is expressed only as a SINR ceiling; the mapping from SINR to information-theoretic secrecy is left implicit.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The paper studies dual-security (joint communication and sensing security) in an indoor OFDM-ISAC system with one transmitter, one communication user (CU), one sensing user (SU), and one target. The proposed scheme adds a temporal artificial-noise (AN) vector s=Uv to the OFDM time-domain signal, choosing U to lie in the null space of the CP-removal-plus-channel matrix R_CP H_CU, so the CU's communication is unaffected. The same AN is non-null at the SU, degrading its decoding SINR when the SU acts as a communication eavesdropper. Because the AN is present both in the SU's sensing reference signal (the full transmitted frame) and in the target echo, the SU's target estimation is unaffected, while the CU, which lacks the AN in its reference, suffers an increased sensing MSE. The authors formulate a convex optimization problem (Eq. 19) to maximize a weighted sum of CU communication SNR and SU sensing MSE subject to power, reference-SNR, SU-decoding-SINR, and CU-sensing-MSE constraints, and present numerical trade-off results.

Significance. The scenario of authorized but malicious sensing/communication users is timely and practically relevant. The idea of using a single temporal AN to protect both functions is elegant, and the convex reformulation (Eq. 19) is a clean contribution if the underlying models hold. However, the communication-security guarantee is not robust against the paper's own threat model: the SU, in its legitimate sensing role, is assumed to know the entire transmitted frame X=Toep(x) (Sec. II-C), which includes the AN. A rational SU can exploit this knowledge to cancel the AN before decoding, collapsing the claimed SINR degradation. The sensing-security analysis, especially the CU sensing MSE in Eq. (9), relies on an unvalidated Q-matrix approximation of Toeplitz statistics. The optimization framework and numerical trade-offs are useful, but the central dual-security claim is not established.

major comments (2)
  1. [Sec. II-C and III-B2, Eqs. (4)-(6), (13), constraint (14c)] The communication-security guarantee is invalid under the paper's own adversary model. The SU is modeled as using the entire transmitted frame X=Toep(x) as its sensing reference (Eqs. (4)-(5), (10)-(11)), which implies it knows (or can reconstruct) the AN vector s=Uv. Then, when acting as a communication eavesdropper, the SU can subtract the AN term F R_CP H_SU U v from the received signal in Eq. (6) before decoding, because it knows H_SU and U. More strongly, the full time-domain observation y_SU,ref is an invertible linear system in [c;v], so a sophisticated SU can solve for c directly. Therefore the SINR in Eq. (13) is not the actual decoding SINR of an authorized eavesdropper, and constraint (14c) does not ensure data security. The restriction to 'standard OFDM receiver processing' is not justified as an upper bound on adversary capability and contradicts the abstract's claim of an a
  2. [Eq. (9) and constraint (14d)] The CU sensing MSE in Eq. (9) is derived using a Q-matrix approximation of Toeplitz statistics borrowed from [19], but the paper does not derive this approximation, state its validity conditions, or provide a Monte Carlo check. Specifically, E[Toep(s) j_CU j_CU^H Toep(s)^H] is replaced by σ_j^2 Q U Σ U^H Q^H, and (Q^H R_{tilde(w)} Q)^{-1} is used for the inverse of the reference correlation. No error bounds are given. Since constraint (14d) and the sensing-security conclusions in the simulations depend on the accuracy of Eq. (9), the sensing-security guarantee is not convincingly established.
minor comments (4)
  1. [Abstract, Sec. VI vs. Eq. (1)] The text says the AN is 'embedded in the cyclic prefix (CP)', but Eq. (1) and Fig. 2 show the AN added after CP insertion, affecting the entire time-domain symbol, not just the CP. Please reconcile the wording.
  2. [Sec. II-A, Eq. (2)] The existence of a semi-unitary U with N_cp columns satisfying R_CP H_CU U = 0 requires the null space of R_CP H_CU to have dimension at least N_cp. The paper should state the channel-length condition that ensures this (e.g., L <= N_cp+1) and discuss what happens for longer channels.
  3. [Sec. III, Eq. (9) and (11)] The definition of the Q matrix is vague: 'accounts for the power distribution of the Toeplitz structure' with no formula. Please give an explicit construction (e.g., singular values of the Toeplitz operator) and cite the precise result from [19] that justifies it.
  4. [Sec. V-B, Fig. 5] The claim that the SU sensing MSE depends only on the total transmit power and not on the power allocation between data and AN is stated without proof. If true, it should be proved; otherwise it should be presented as an empirical observation for the chosen parameters.

Circularity Check

0 steps flagged

No significant circularity: the derivations are self-contained signal-processing results, and the security gaps are imposed as design constraints rather than predicted from fitted inputs.

full rationale

After walking the derivation chain, I find no circularity. The core identities are derived from explicit channel and noise models: Eq. (2) uses U in the null space of R_CP H_CU as a designed constraint, not as a fitted or predicted quantity; Eqs. (6) and (13) follow directly from the CP-removal/FFT model; and Eqs. (9) and (11) are least-squares MSE calculations from the stated Toeplitz/X models, with the Q approximation inherited from an external reference. Constraints (14c) and (14d) bound gamma_SU,decode and epsilon_CU, so any feasible design exhibits the security gaps by construction; however, the paper presents these as design constraints, not as data-fitted predictions, and the nontrivial content—power-allocation trade-offs, feasibility, and preservation of SU sensing—is derived rather than assumed. Reference [12] is a self-citation within a survey-style list ([8]–[12]) and is not load-bearing for any equation or theorem. The concern that the SU's sensing model gives it knowledge of X (and hence of s), while its decoding model in Eq. (6) assumes it cannot use that knowledge to cancel the AN, is a threat-model or correctness issue, not a circular reduction, so it does not raise the circularity score.

Axiom & Free-Parameter Ledger

4 free parameters · 6 axioms · 0 invented entities

The design depends on five load-bearing assumptions: perfect multi-user CSI at the transmitter (Assumption 1), quasi-static channels (Assumption 2), temporal separation of communication and echo (Assumption 3), invertibility of the transmitted-signal Toeplitz matrices for the LSE estimators, and the Q-matrix approximation for Toeplitz statistics. The security thresholds are user-chosen inputs, not fitted quantities, but they define the demonstrated security levels. No new physical entities are introduced.

free parameters (4)
  • Security thresholds η_b, η_c, η_d = η_b=10^2, η_c=10^-1, η_d=10^-3
    Chosen by hand in Sec. V; they directly define the demonstrated security levels — the displayed gaps ε_CU−ε_SU and γ_CU−γ_SU,decode are partly outputs of these chosen constraints.
  • Trade-off weights κ1, κ2 = 0.5, 0.5
    'Set to half to balance the services' (Sec. V); chosen by hand and affect which point on the Pareto front is displayed.
  • Target and sensing noise variances σ_j^2, σ_s^2 = not specified numerically
    Enter the MSE expressions (9) and (11); the values used in simulation are not reported.
  • Power budget, path loss, noise power, N_c, N_cp = P_t=15 dBm, path loss √10^-3, noise −70 dBm, N_c=64, N_cp=16
    Simulation settings; reasonable but arbitrary, and the resulting very high SNR (γ_CU of 60–110 dB in Fig. 3) makes the security constraints easy to satisfy.
axioms (6)
  • domain assumption Assumption 1: Tx has perfect knowledge of each user's service type and downlink CSI
    Needed to construct U in the null space of R_CP H_CU and to allocate power; perfect CSI of an SU that may eavesdrop is optimistic.
  • standard math Assumption 2: channel is quasi-static within each coherence block
    Common OFDM assumption; reduces analysis to a single OFDM symbol.
  • domain assumption Assumption 3: communication and echo signals are temporally separated
    Strong simplification; in full-duplex indoor ISAC the echo overlaps the transmitted signal. This assumption underlies the single-antenna no-self-interference model.
  • domain assumption Toeplitz matrices X and W̃ are invertible
    The LSE estimators (8) and (10) use direct inverses X^{-1} and W̃^{-1}; invertibility is justified only by a zero-padding construction for X, with no proof for W̃.
  • domain assumption Q-matrix approximation for Toeplitz-structured matrices (from [19])
    Eq. (9) factorizes expectations of products of Toeplitz matrices into products of expectations using a diagonal weight matrix Q; heuristic and unvalidated in this paper.
  • domain assumption SU knows the full transmit frame x (including AN) for its sensing reference
    Eqs. (4)-(5), (10)-(11): the SU's LSE uses X = Toep(x). This knowledge is exactly what would allow the SU to cancel the AN when decoding data, an interplay never analyzed.

pith-pipeline@v1.3.0-alltime-deepseek · 8512 in / 24380 out tokens · 199821 ms · 2026-08-01T22:32:50.546622+00:00 · methodology

0 comments
read the original abstract

With the rapid development of integrated sensing and communication (ISAC) as a key enabler for future wireless networks, ensuring the security of both communication and sensing functions has become increasingly important. Current secure ISAC studies focus restrictively either on the communication or the sensing security, but not both. To bridge this gap, this paper investigates security for both, i.e., dual-security, in indoor orthogonal frequency division multiplexing (OFDM) based ISAC systems. Specifically, we consider a scenario in which a sensing user (SU) is authorised for sensing but may eavesdrop on communication data, while a communication user (CU) is authorised for communication but may perform unauthorised sensing. We chose this scenario as the pathological case where an authorised eavesdropper has more information and is more effective than an unauthorised one. To address this case, we propose the use of temporal artificial noise (AN) to prevent malicious CU sensing by enlarging its time-domain sensing error, and simultaneously degrade SU data eavesdropping by reducing its frequency-domain signal-to-noise-plus-interference ratio (SINR) with standard OFDM receiver processing. Meanwhile, our proposed scheme guarantees the sensing performance of the SU and the communication performance of the CU. We present numerical results that demonstrate AN can effectively provide dual protection for sensing and communication in OFDM-ISAC systems while guaranteeing the performance of legitimate users.

Figures

Figures reproduced from arXiv: 2607.15710 by Julie A. McCann, Michael Breza, Prabhat Raj Gautam, Yathreb Bouazizi, Yinchao Yang.

Figure 1
Figure 1. Figure 1: An illustration of the considered ISAC system model with one Tx, [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 3
Figure 3. Figure 3: The CU communication performance γCU, versus SU decoding SINR threshold ηc, under different CU sensing MSE thresholds ηd. Power Budget Pt (dBm) 5 10 15 20 25 C o m m P erform ance G ap (dB) 60 65 70 75 80 85 2 c=1e-3, 2 d=1e-4 2 c=1e-1, 2 d=1e-4 2 c=1e-1, 2 d=1e-3 [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: The communication performance gap versus transmit power budget [PITH_FULL_IMAGE:figures/full_fig_p005_4.png] view at source ↗
Figure 6
Figure 6. Figure 6: The sensing performance gap versus transmit power budget [PITH_FULL_IMAGE:figures/full_fig_p006_6.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

23 extracted references · 2 linked inside Pith

  1. [1]

    Integrated sensing and communications over the years: An evolution perspective,

    D. Zhang, Y . Cui, X. Cao, N. Su, Y . Gong, F. Liu, W. Yuan, X. Jing, J. A. Zhang, J. Xuet al., “Integrated sensing and communications over the years: An evolution perspective,”IEEE Communications Surveys & Tutorials, 2026

  2. [2]

    Integrated sensing and communications (isac); use cases and deployment scenarios,

    I. I. ETSI and E. France, “Integrated sensing and communications (isac); use cases and deployment scenarios,”Use Cases and Deployment Scenarios, 1

  3. [3]

    Mu-mimo commu- nications with mimo radar: From co-existence to joint transmission,

    F. Liu, C. Masouros, A. Li, H. Sun, and L. Hanzo, “Mu-mimo commu- nications with mimo radar: From co-existence to joint transmission,” IEEE Transactions on Wireless Communications, vol. 17, no. 4, pp. 2755–2770, 2018

  4. [4]

    Wifi sensing on the edge: Signal processing techniques and challenges for real-world systems,

    S. M. Hernandez and E. Bulut, “Wifi sensing on the edge: Signal processing techniques and challenges for real-world systems,”IEEE Communications Surveys & Tutorials, vol. 25, no. 1, pp. 46–76, 2022

  5. [5]

    Integrating sensing and communications in 6g? not until it is secure to do so,

    N. Su, F. Liu, J. Zou, C. Masouros, G. C. Alexandropoulos, A. Mourad, J. L. Hernando, Q. Zhang, and T.-T. Chan, “Integrating sensing and communications in 6g? not until it is secure to do so,”arXiv preprint arXiv:2503.15243, 2025

  6. [6]

    Next-generation mimo transceivers for integrated sensing and communications: Unique security vulnerabilities and solutions,

    K. Han, C. Masouros, T. Riihonen, and M. G. Amin, “Next-generation mimo transceivers for integrated sensing and communications: Unique security vulnerabilities and solutions,”arXiv preprint arXiv:2511.20309, 2025

  7. [7]

    A survey on artificial noise for physical layer security: Opportunities, technologies, guidelines, advances, and trends,

    H. Niu, Y . Xiao, X. Lei, J. Chen, Z. Xiao, M. Li, and C. Yuen, “A survey on artificial noise for physical layer security: Opportunities, technologies, guidelines, advances, and trends,”IEEE Communications Surveys & Tutorials, 2025

  8. [8]

    Securing the sensing function- ality in isac networks: An artificial noise design,

    J. Zou, C. Masouros, F. Liu, and S. Sun, “Securing the sensing function- ality in isac networks: An artificial noise design,”IEEE Transactions on V ehicular Technology, vol. 73, no. 11, pp. 17 800–17 805, 2024

  9. [9]

    Sensing-secure isac: Ambiguity function engineering for impairing unauthorized sensing,

    K. Han, K. Meng, and C. Masouros, “Sensing-secure isac: Ambiguity function engineering for impairing unauthorized sensing,”IEEE Trans- actions on Wireless Communications, 2025

  10. [10]

    Securing the sensing function- ality in isac: Kld-based ambiguity function shaping,

    B. Du, K. Han, and C. Masouros, “Securing the sensing function- ality in isac: Kld-based ambiguity function shaping,”arXiv preprint arXiv:2512.19974, 2025

  11. [11]

    Sensing security in near-field isac: Exploiting scatterers for eavesdropper deception,

    J. Chen, X. Lei, K. Meng, K. Han, Y . Zhang, C. Masouros, and A. P. Petropulu, “Sensing security in near-field isac: Exploiting scatterers for eavesdropper deception,”arXiv preprint arXiv:2510.20140, 2025

  12. [12]

    Dual security for mimo-ofdm isac systems: Artificial ghosts or artificial noise,

    Y . Yang, P. R. Gautam, Y . Bouazizi, M. Breza, and J. McCann, “Dual security for mimo-ofdm isac systems: Artificial ghosts or artificial noise,”arXiv preprint arXiv:2602.20045, 2026

  13. [13]

    Regulation (EU) 2016/679 (General Data Protection Regulation), Article 9: Processing of Special Categories of Personal Data,

    European Union, “Regulation (EU) 2016/679 (General Data Protection Regulation), Article 9: Processing of Special Categories of Personal Data,” 2016. [Online]. Available: https://gdpr-info.eu/art-9-gdpr/

  14. [14]

    Biometric Information Privacy Act (BIPA),

    Illinois General Assembly, “Biometric Information Privacy Act (BIPA),” 740 ILCS 14/1, 2008, illinois Compiled Statutes

  15. [15]

    On the imple- mentation of location obfuscation in openwifi and its performance,

    L. Ghiro, M. Cominelli, F. Gringoli, and R. L. Cigno, “On the imple- mentation of location obfuscation in openwifi and its performance,” in 2022 20th Mediterranean Communication and Computer Networking Conference (MedComNet). IEEE, 2022, pp. 64–73

  16. [16]

    Mimo radar waveform design in the presence of clutter,

    T. Naghibi and F. Behnia, “Mimo radar waveform design in the presence of clutter,”IEEE Transactions on Aerospace and Electronic Systems, vol. 47, no. 2, pp. 770–781, 2011

  17. [17]

    Integrated Sensing And Communications (ISAC); Security, Pri- vacy, Trustworthiness and Sustainability,

    ETSI, “Integrated Sensing And Communications (ISAC); Security, Pri- vacy, Trustworthiness and Sustainability,” European Telecommunica- tions Standards Institute (ETSI), Group Report (GR) ETSI GR ISC 004 V1.1.1, Feb. 2026

  18. [18]

    Rethinking signaling design for isac: From pilot-based to payload-based sensing,

    Y . Li, Y . Zhang, C. Masouros, S. Pollin, and F. Liu, “Rethinking signaling design for isac: From pilot-based to payload-based sensing,” IEEE Communications Standards Magazine, 2026

  19. [19]

    Power allocation and time-domain artificial noise design for wiretap ofdm with discrete inputs,

    H. Qin, Y . Sun, T.-H. Chang, X. Chen, C.-Y . Chi, M. Zhao, and J. Wang, “Power allocation and time-domain artificial noise design for wiretap ofdm with discrete inputs,”IEEE Transactions on Wireless Communications, vol. 12, no. 6, pp. 2717–2729, 2013

  20. [20]

    Securing ofdm-based wireless links using temporal artificial-noise injection,

    M. F. Marzban, R. Chabaan, N. Al-Dhahir, and A. El Shafie, “Securing ofdm-based wireless links using temporal artificial-noise injection,” in 2018 15th IEEE Annual Consumer Communications & Networking Conference (CCNC). IEEE, 2018, pp. 1–6

  21. [21]

    Rethinking ergodic lmmse of random isac signals,

    Z. Chen, S. Lu, and F. Liu, “Rethinking ergodic lmmse of random isac signals,”IEEE Wireless Communications Letters, 2025

  22. [22]

    Channel estimation for ofdm,

    Y . Liu, Z. Tan, H. Hu, L. J. Cimini, and G. Y . Li, “Channel estimation for ofdm,”IEEE communications surveys & tutorials, vol. 16, no. 4, pp. 1891–1908, 2014

  23. [23]

    Majorization-minimization algo- rithms in signal processing, communications, and machine learning,

    Y . Sun, P. Babu, and D. P. Palomar, “Majorization-minimization algo- rithms in signal processing, communications, and machine learning,” IEEE Transactions on Signal Processing, vol. 65, no. 3, pp. 794–816, 2016