Pith. sign in

REVIEW 3 major objections 5 minor 1 cited by

A Fisher Information Density limit on shared trajectories keeps reconstruction error above a hard privacy floor no matter how strong the sensing or how clever the adversary.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-12 23:45 UTC pith:DZLX2FZP

load-bearing objection Useful FID-based control for ISAC trajectory sharing with solid OpenTraj numbers, but the 'hard guarantee against any post-processing' overclaims what CRB actually buys. the 3 major comments →

arxiv 2604.08743 v2 pith:DZLX2FZP submitted 2026-04-09 eess.SP cs.NI

Balancing Functionality and GDPR-Driven Privacy in ISAC Trajectory Sharing

classification eess.SP cs.NI
keywords ISACtrajectory privacyFisher Information DensityGDPR data minimisationPrivacy Leak RatioCramér-Rao boundmovement predictionLSTM
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Integrated Sensing and Communications systems can improve beamforming and cooperative perception by sharing user trajectories, but that same data can reveal precise location and behaviour, clashing with GDPR data-minimisation rules. This paper shows that the right quantity to control is not raw noise power but Fisher Information Density—the local rate at which sensing information accumulates. By keeping that density below a chosen threshold, the method forces every segment of the shared trajectory to retain a guaranteed minimum reconstruction error. Fixed-noise schemes fail when sensing power rises or an adversary smooths the data; the FID constraint does not, because the Cramér–Rao bound itself cannot be beaten. Simulations on real pedestrian traces confirm that average privacy-leak ratios stay under 20–25 % and continuous leak segments under 2–2.5 s, while an LSTM still predicts position and velocity usefully. The result is a single, model-agnostic dial that lets operators share only as much trajectory quality as the task needs.

Core claim

Enforcing a local upper bound on Fisher Information Density guarantees that no post-processing can drive trajectory reconstruction error below a prescribed threshold, thereby bounding the Privacy Leak Ratio independently of sensing power or adversarial smoothing—something fixed-noise methods cannot achieve.

What carries the argument

Fisher Information Density (FID): the continuous-time rate of Fisher information (inverse of the Cramér–Rao bound) accumulated along a trajectory; constraining it supplies the hard local uncertainty floor used for privacy.

Load-bearing premise

That the Cramér–Rao bound remains an unbreakable lower limit on reconstruction error even when the adversary is free to use biased estimators or machine-learning denoisers.

What would settle it

Train a modern trajectory smoother or neural reconstructor on FID-constrained OpenTraj data and check whether the fraction of points recovered inside the privacy radius ϵ exceeds the claimed PLR bound for high sensing power.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • ISAC operators can publish a single FID threshold as a GDPR-auditable privacy guarantee that does not depend on the sensing algorithm or the adversary’s post-processing.
  • Downstream predictors (beamforming, resource allocation, cooperative perception) receive trajectories whose quality is deliberately capped once the privacy floor is hit, aligning utility with data minimisation.
  • Fixed-noise baselines become obsolete for high-power regimes; any privacy scheme that ignores information density will leak longer contiguous segments as sensing improves.
  • The same FID dial can be re-tuned per user or per task, giving a quantitative privacy–utility trade-off curve instead of an all-or-nothing decision.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If regulators accept FID as a measurable proxy for ‘necessary’ data quality, MNOs could certify trajectory-sharing pipelines without revealing their internal sensing parameters.
  • The same density constraint might transfer to other continuous personal signals (heart-rate streams, keyboard dynamics) where Fisher information can be estimated locally.
  • An open question left implicit is how tightly the FID threshold must track real-time channel fluctuations; adaptive thresholds could further reduce unnecessary noise in low-information segments.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper proposes a Fisher Information Density (FID)-constrained trajectory sharing scheme for MIMO-ISAC systems, motivated by GDPR data minimisation. Sensing quality is characterised via the Cramér–Rao bound (CRB) and its continuous-time density (FID); when local FID exceeds a threshold η, zero-mean Gaussian noise with a saturating variance schedule (Eqs. 9–10) is added before sharing. Privacy is quantified by a Privacy Leak Ratio (PLR) and by average/maximum leak-segment durations; utility is measured by one-second-ahead position, velocity and heading errors of a lightweight LSTM trained on OpenTraj trajectories. Simulations claim that average PLR stays below 20–25 % and maximum leak duration under 2–2.5 s for all sensing powers, while fixed-noise baselines either leak more or destroy utility.

Significance. If the privacy claims hold, the work supplies an interpretable, resource-aware criterion for GDPR-oriented trajectory release in ISAC, with clearer power-independent behaviour than fixed-noise baselines and a concrete utility check on a public pedestrian dataset. The FID construction and the PLR/leak-duration metrics are useful engineering contributions even if the strongest theoretical language is relaxed. The empirical privacy–utility curves (Figs. 3–4) and the comparison against fixed-error baselines are reproducible in principle and constitute a solid starting point for privacy-aware ISAC design.

major comments (3)
  1. [Abstract / Sec. II.A–B] Abstract and Sec. II.A–B repeatedly claim “hard, quantifiable privacy guarantees by construction” and that “no post-processing or denoising by an adversary can recover the original trajectory beyond a prescribed accuracy.” The supporting argument equates the CRB/FID of each sensing update with a lower bound on the Euclidean reconstruction error e_i(t_k) after arbitrary post-processing. The classical CRB bounds only unbiased estimators of a fixed parameter; trajectory reconstruction is a filtering/smoothing/sequence-modelling task whose estimators (Kalman smoothers, LSTMs, diffusion denoisers, etc.) are typically biased and exploit temporal correlation. Consequently the point-wise CRB does not translate into a hard lower bound on e_i(t_k) after adversarial post-processing. The “regardless of \ldots adversarial post-processing” language must be withdrawn or replaced by a precise statement
  2. [Sec. II.B / Fig. 2–3] Privacy evaluation (Fig. 2, Fig. 3, PLR definition (8)) uses a single reconstruction procedure—heavy 7-point smoothing of the shared measurements. The paper itself already shows continuous “Privacy Leak Zones” under this smoother. Stronger sequence models would only enlarge those zones. The reported PLR and leak-duration bounds therefore characterise leakage under the authors’ own reconstructor, not under a worst-case adversary. Either (i) evaluate PLR against a stronger adversarial suite (e.g., process-model Kalman smoother, trajectory LSTM, or non-parametric smoother) or (ii) explicitly restrict the claim to the reconstruction model used in the experiments.
  3. [Eqs. (9)–(10) / Tab. I] The noise schedule (10) is a hand-designed, thresholded saturating function of FID with free parameters α, β, η. There is no derivation showing that the resulting shared process has CRB (or any other information measure) that forces e_i(t_k) ≥ ϵ for the chosen ϵ = 0.3 m. When J_i(t) ≤ η the schedule adds zero noise, so any residual leakage is controlled only by the raw sensing quality. The link between the FID threshold, the injected variance and the privacy threshold ϵ should be made explicit (analytic or via a calibrated worst-case bound), otherwise the “by construction” guarantee reduces to an empirical observation for the chosen parameter set.
minor comments (5)
  1. [Fig. 2] Figure 2 axis labels and legend contain broken words (“R eal T ajecto y”, “Sha ed ISAC Measu.”, “P ivacy Leak Zone”). These should be corrected for readability.
  2. [Fig. 4] Figure 4(c) legend and axis text are similarly corrupted (“No pr )acy pro(ec( on”, “F x ed error”). Clean the vector graphics before resubmission.
  3. [Tab. I / Fig. 3–4] Table I lists η = 50, 250 while the figure legends use “FID Constrained 250/500”; reconcile the threshold values used in the plots with the table.
  4. [Sec. II.B] The angular-error model is deferred to reference [14]; a short self-contained statement of the SNR-to-angle mapping used for e_i(t_k) would improve reproducibility.
  5. [Index Terms] Index terms list only “B5G; ISAC; Privacy; LSTM”; adding “Fisher information”, “data minimisation” or “trajectory privacy” would improve discoverability.

Circularity Check

1 steps flagged

No load-bearing circularity in the FID-to-PLR chain; only a minor background self-citation for the sensing error model used in simulations.

specific steps
  1. self citation load bearing [Sec. II.B (privacy leak model paragraph)]
    "To simplify the analysis, we adopt a tractable angular error model parameterized by the Signal to Noise Ratio (SNR); the detailed error modelling is provided in [14]."

    The quantitative PLR and prediction-error results rest on a generative sensing-error model taken from the authors' own prior paper. While the theoretical FID construction does not depend on it, the empirical curves that support the 'hard guarantee' claim have no independent external grounding without this self-citation.

full rationale

The paper defines Fisher information from the standard CRB expression (Eqs. 1-2), constructs the continuous-time FID density (Eqs. 5-6), then designs a thresholded additive Gaussian noise schedule (Eqs. 9-11) that caps FID at a designer-chosen η. PLR is separately defined as the empirical fraction of points whose reconstruction error falls below a fixed ϵ (Eq. 8) and is measured on OpenTraj trajectories under that noise schedule. The reported PLR bounds and utility curves are therefore independent Monte-Carlo outcomes, not algebraic identities of the free parameters α, β, η. The sole self-citation ([14]) supplies only the angular-error generative model used to produce the raw measurements; it is not invoked to prove the privacy guarantee itself. Consequently the central claim does not reduce by construction to its inputs, and the circularity score remains minimal.

Axiom & Free-Parameter Ledger

4 free parameters · 4 axioms · 2 invented entities

The load-bearing claim rests on treating CRB/Fisher information as a privacy proxy, on the hand-crafted saturating noise function of FID, and on the paper-specific definitions of FID and PLR. Free parameters (thresholds, noise shape, ϵ) are chosen rather than derived; the two invented metrics have no independent external validation.

free parameters (4)
  • η (FID threshold) = 50, 250, 500
    Hand-selected values (50/250/500) that directly set the reported PLR operating points; not derived from first principles.
  • α, β in Δσ(t) (Eq. 10) = 0.5, 1.5
    Shape parameters of the saturating noise schedule; chosen to balance privacy-utility trade-off.
  • ϵ (privacy error threshold) = 0.3 m
    Defines the binary “leaked” decision inside PLR; arbitrary accuracy floor that controls all privacy numbers.
  • LSTM hyperparameters (H, L, lr, batch, epochs) = H=64, L=3, lr=1.6e-3, B=64, 1000 epochs
    Utility evaluation depends on this fixed architecture and training regime; not ablated.
axioms (4)
  • domain assumption The CRB expression (1) lower-bounds position estimation variance for any unbiased estimator under the stated MIMO-ISAC model.
    Used throughout Sec. II.A to convert sensing power and symbols into Fisher information and thence into a privacy bound; standard under regularity conditions but not guaranteed for arbitrary adversarial estimators.
  • standard math Fisher information is exactly the reciprocal of the CRB and its continuous-time density (FID) can be constrained segment-wise.
    Eqs. (2)–(6); definitional once the CRB is accepted.
  • ad hoc to paper Zero-mean Gaussian noise whose variance follows the thresholded saturating function (10) of FID is sufficient to keep reconstruction error above ϵ against any post-processing.
    Core privacy mechanism of Sec. II.B; the functional form is postulated without hardness proof.
  • ad hoc to paper The point-wise Privacy Leak Ratio (8) with threshold ϵ is an adequate quantitative proxy for GDPR data-minimisation risk on trajectories.
    Defined and used as the sole privacy metric; assumes position error alone captures behavioural inference risk.
invented entities (2)
  • Fisher Information Density (FID) no independent evidence
    purpose: Local continuous-time measure of trajectory informativeness that serves as the control variable for privacy-constrained sharing.
    Introduced in Eqs. (5)–(6); no prior literature treats this density as a privacy knob, and no external measurement validates it outside the paper.
  • Privacy Leak Ratio (PLR) no independent evidence
    purpose: Fraction of trajectory samples reconstructible within ϵ, used to quantify and bound privacy leakage.
    Defined in Eq. (8); paper-specific metric whose numerical values constitute the central empirical claim.

pith-pipeline@v1.1.0-grok45 · 12130 in / 3243 out tokens · 59125 ms · 2026-07-12T23:45:13.383894+00:00 · methodology

0 comments
read the original abstract

Integrated Sensing and Communications (ISAC) enables trajectory sharing that enhances beamforming, resource allocation, and cooperative perception, yet raises fundamental privacy concerns under the General Data Protection Regulation (GDPR) data minimisation principle. This paper proposes a Fisher Information Density (FID)-constrained trajectory sharing framework that enforces a local lower bound on estimation uncertainty, providing hard, quantifiable privacy guarantees by construction. Unlike fixed-noise approaches, the proposed method bounds the Privacy Leak Ratio (PLR) regardless of sensing power or adversarial post-processing, ensuring that no trajectory segment can be reconstructed beyond a prescribed accuracy threshold. Simulations on the OpenTraj dataset demonstrate that the framework keeps the average PLR below 20-25% and the maximum leakage segment duration under 2-2.5 s, while preserving data utility for downstream tasks such as movement prediction. The resulting criterion is interpretable, model-agnostic, and compatible with GDPR-compliant ISAC system design.

Figures

Figures reproduced from arXiv: 2604.08743 by Bin Han, Hans D. Schotten, Zexin Fang, Zhuojun Tian.

Figure 1
Figure 1. Figure 1: In particular, the data minimisation principle mandates [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Demonstration of trajectory privacy leakage. The [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: Privacy evaluation with different metrics: (a) average privacy leak segment duration; (b) the maximum privacy leak [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: Utility evaluation: (a) one-second-ahead position error; (b) absolute velocity error; (c) heading angle error. The error-free [PITH_FULL_IMAGE:figures/full_fig_p004_4.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. GDPR-Aware Trajectory Sharing for ISAC-Assisted Robot Navigation: A Case Study on FID-Constrained Collision Prediction

    cs.RO 2026-07 conditional novelty 4.0

    FID-controlled trajectory perturbation yields lower reconstruction leakage and shorter continuous exposure than fixed-error noise at matched missed-conflict rates on real pedestrian traces.

Reference graph

Works this paper leans on

15 extracted references · cited by 1 Pith paper

  1. [1]

    Temporal-assisted beamforming and trajectory prediction in sensing-enabled uav communications,

    S. Zhou, H. Yang, L. Xianget al., “Temporal-assisted beamforming and trajectory prediction in sensing-enabled uav communications,”IEEE Transactions on Communications, vol. 73, no. 7, pp. 5408–5419, 2024

  2. [2]

    Cooperative sensing-assisted predictive beam tracking for mimo-ofdm networked isac systems,

    X. Yang, Z. Wei, J. Xuet al., “Cooperative sensing-assisted predictive beam tracking for mimo-ofdm networked isac systems,”IEEE Transac- tions on Wireless Communications, 2025

  3. [3]

    Attention-based spatial-temporal gcn for sensing-aided beam prediction in ris-assisted isac systems,

    J. Li, W. Wang, R. Jianget al., “Attention-based spatial-temporal gcn for sensing-aided beam prediction in ris-assisted isac systems,”IEEE Transactions on Cognitive Communications and Networking, 2026

  4. [4]

    Recent advances in resource alloca- tion and beam prediction for large language models empowered isac systems,

    X. Li, Y . Gao, M. Zenget al., “Recent advances in resource alloca- tion and beam prediction for large language models empowered isac systems,”IEEE Communications Magazine, 2026

  5. [5]

    Goal-oriented semantic communication for isac-enabled robotic obstacle avoidance,

    W. Liu, Y . Deng, and H. Wymeersch, “Goal-oriented semantic communication for isac-enabled robotic obstacle avoidance,” 2026. [Online]. Available: https://arxiv.org/abs/2603.02291

  6. [6]

    Isac-assisted collision avoidance mechanism for vehicle-to-infrastructure systems,

    Z. Ye, C. Yu, H. Zhuet al., “Isac-assisted collision avoidance mechanism for vehicle-to-infrastructure systems,”IEEE Transactions on Intelligent V ehicles, 2024

  7. [7]

    Collaborative positioning optimization for multiple moving users in uav-enabled isac,

    Y . Hu, X. Zhuo, Z. Menget al., “Collaborative positioning optimization for multiple moving users in uav-enabled isac,”IEEE Transactions on Cognitive Communications and Networking, 2025

  8. [8]

    Joint radar and communi- cation design: Applications, state-of-the-art, and the road ahead,

    F. Liu, C. Masouros, A. P. Petropuluet al., “Joint radar and communi- cation design: Applications, state-of-the-art, and the road ahead,”IEEE Transactions on Communications, vol. 68, no. 6, pp. 3834–3862, 2020

  9. [9]

    Optimal resource allocation for integrated sensing and communications in internet of vehicles: A deep reinforce- ment learning approach,

    C. Liu, M. Xia, J. Zhaoet al., “Optimal resource allocation for integrated sensing and communications in internet of vehicles: A deep reinforce- ment learning approach,”IEEE Transactions on V ehicular Technology, vol. 74, no. 2, pp. 3028–3038, 2025

  10. [10]

    Respec: A super-resolution algorithm for multi-target sensing in ofdm-isac systems,

    M. Yin, J. Li, Q. Liet al., “Respec: A super-resolution algorithm for multi-target sensing in ofdm-isac systems,” in2025 IEEE Wireless Communications and Networking Conference (WCNC), 2025, pp. 1–6

  11. [11]

    Joint beamforming for multi-target detection and multi-user communication in isac systems,

    Z. Zhao, Z. Liu, R. Jianget al., “Joint beamforming for multi-target detection and multi-user communication in isac systems,”IEEE Trans- actions on V ehicular Technology, vol. 74, no. 9, pp. 14 938–14 942, 2025

  12. [12]

    Performance trade-off for ultra-reliable and low-latency service in multi-functional isac network,

    Z. Liu, Y . Zhu, Y . Huet al., “Performance trade-off for ultra-reliable and low-latency service in multi-functional isac network,”IEEE Transactions on Network Science and Engineering, pp. 1–19, 2026

  13. [13]

    Fundamental crb-rate tradeoff in multi-antenna isac systems with information multicasting and multi- target sensing,

    Z. Ren, Y . Peng, X. Songet al., “Fundamental crb-rate tradeoff in multi-antenna isac systems with information multicasting and multi- target sensing,”IEEE Transactions on Wireless Communications, vol. 23, no. 4, pp. 3870–3885, 2024

  14. [14]

    Unauthorized radio sensing and privacy risks: A sampling error-based defense,

    Z. Fang, B. Han, W. Chenet al., “Unauthorized radio sensing and privacy risks: A sampling error-based defense,” in2025 IEEE 36th International Symposium on Personal, Indoor and Mobile Radio Com- munications (PIMRC), 2025, pp. 1–6

  15. [15]

    Opentraj: Assessing prediction complexity in human trajectories datasets,

    J. Amirian, B. Zhang, F. V . Castroet al., “Opentraj: Assessing prediction complexity in human trajectories datasets,” inComputer Vision – ACCV 2020, H. Ishikawa, C.-L. Liu, T. Pajdlaet al., Eds. Cham: Springer International Publishing, 2021, pp. 566–582