Pith. sign in

REVIEW 3 major objections 6 minor 44 references

A physically consistent non-reciprocal smart surface can silently break TDD channel reciprocity, cutting downlink throughput and enabling passive eavesdropping, while a deep-reinforcement-learning precoder restores most of the lost performa

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

A physically consistent NR-RIS can covertly attack TDD systems by breaking channel reciprocity, and a DRL-based SecureCoder precoder can mitigate the damage.

T0 review reviewed 2026-08-04 challenge →

load-bearing objection A plausible extension of the authors' own CRACK work with a clean system model, but the physical realizability of the NR-RIS scattering matrix is inherited and unvalidated, and the DRL results need statistical support. the 3 major comments →

arxiv 2509.11117 v1 pith:FCVG353C submitted 2025-09-14 eess.SP

Nonreciprocal RIS-Aided Covert Channel Reciprocity Attacks and Countermeasures

classification eess.SP
keywords channel reciprocity attacknon-reciprocal RISTDD MU-MISOphysical layer securitypassive jammingdeep reinforcement learningprecodingeavesdropping
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that a passive, physically realizable non-reciprocal reconfigurable intelligent surface (NR-RIS) can covertly attack time-division duplex (TDD) wireless systems by breaking the channel-reciprocity assumption that the base station uses to compute downlink precoding. Because the NR-RIS scattering matrix is non-symmetric, the uplink channel the base station estimates differs from the actual downlink channel, so otherwise well-designed precoders—maximum-ratio transmission (MRT) and especially zero-forcing (ZF)—leak energy as multiuser interference and toward eavesdroppers. The attack requires no CSI about the legitimate network, no synchronization with its pilot or data phases, no active transmission, and no fast reconfiguration, making it look like ordinary multipath. The paper further proposes SecureCoder, a deep-reinforcement-learning precoding framework that uses only the estimated uplink CSI and user rate feedback to restore throughput and secrecy. If correct, this means TDD systems with conventional reciprocity-based precoding are vulnerable to a stealthy, low-cost attack that cannot be countered by adding base-station antennas or by standard channel-estimation refinements.

Core claim

Central claim: a physically consistent NR-RIS, built from circulator-loaded two-port units realizing Φ = [[0,e^{jφ1}],[e^{jφ2},0]] with Φ ≠ Φ^T, breaks the TDD reciprocity assumption H_down = H_up^T. Because the uplink estimate includes (Φ − I_N) while the true downlink uses its transpose, the mismatch persists even for a static surface that looks like natural scattering. In simulation this cuts ergodic sum rate by about 90% (MRT) and 92% (ZF) at N=256, M=128, while raising secrecy outage and strengthening with partial CSI. The countermeasure, SecureCoder, is a deep-reinforcement-learning agent mapping uplink CSI to a precoder; in simulation it restores much of the lost rate and secrecy.

What carries the argument

The engine of the attack is the non-symmetric, unitary scattering matrix Φ of the NR-RIS, realized by pairing elements into two-port 'NR dual-element units' built from a 3-port circulator and tunable reactive loads; the resulting block-diagonal Φ has off-diagonal entries e^{jφ1} and e^{jφ2} and no diagonal terms, so Φ ≠ Φ^T. When placed in the channel, the surface contributes (Φ − I_N) to the uplink path and (Φ − I_N)^T to the downlink path, and because the base station cannot separate the direct user-BS channel from the RIS-induced channel, it precodes against a reciprocal channel that does not exist. The block architecture (small paired groups, e.g., L=8) makes the attack nearly as effecti

Load-bearing premise

The attack's severity rests on the assumption that a unit built from a 3-port circulator and tunable reactances can physically realize the ideal non-reciprocal scattering matrix [[0, e^{jφ1}], [e^{jφ2}, 0]] with high efficiency across the operating bandwidth; if the unit is lossy, narrowband, or needs active amplification, the simulated rate and secrecy losses may not materialize.

What would settle it

Build a prototype NR dual-element unit (circulator plus tunable impedances) and measure its 2×2 scattering parameters over the intended band. If |S12| and |S21| cannot both approach unity with independently settable phases, the attack model overstates the threat. Alternatively, in the paper's MU-MISO simulation, give the base station a way to separate the direct user-BS channel from the RIS-induced component (e.g., a known RIS training sequence); if the attack's throughput collapse disappears when the BS can identify and null the RIS path, then the unidentifiability assumption is the load-bear

Watch this falsifier. Get emailed when new claim-graph text bears on it.

If this is right

  • TDD systems that derive downlink precoders from uplink measurements are exposed to a passive, static RIS attack that needs no CSI or synchronization; adding base-station antennas does not remove the impairment once the surface-BS link is strong enough.
  • Zero-forcing precoding suffers more than MRT, because the reciprocity mismatch destroys the orthogonality that ZF is built on and turns the precoder into a source of inter-user interference.
  • A modest block size (around 8 paired elements) achieves nearly the same attack strength as a fully interconnected non-reciprocal surface, lowering the attacker's hardware complexity.
  • The same surface enhances passive eavesdropping: the distorted precoder scatters energy away from intended users and raises secrecy outage probability, even when the attacker never optimizes for the eavesdropper.
  • SecureCoder, trained on uplink CSI and rate feedback, restores a substantial fraction of the downlink throughput and secrecy in the simulated scenarios and also mitigates earlier diagonal-RIS passive jamming attacks.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: if the circulator-based NR-RIS unit works as modeled, other reciprocity-dependent protocols—physical-layer key generation, channel sounding, reciprocity calibration—face the same covert attack, so defenses may need explicit reciprocity-violation detection (e.g., comparing downlink feedback with uplink estimates) rather than relying on channel statistics.
  • Editorial inference: SecureCoder's learned mapping suggests the BS could treat the uplink-downlink mismatch as an observable environment state; a similar agent could be used online to detect CRACK by flagging rate anomalies that appear without any detectable channel-time variation.
  • Editorial inference: the attack's dependence on the RIS-BS path-loss exponent means deployment geometry matters—an attacker who can place the surface near the base station gets a disproportionately strong effect; defenders could screen for suspicious stationary scatterers close to the BS.
  • Editorial inference: the block-size result implies that even a partially interconnected non-reciprocal surface, built with modest switching complexity, could pose a realistic threat, so the countermeasure problem is not limited to laboratory-scale fully connected designs.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper studies a covert attack, termed CRACK, against TDD MU-MISO downlink precoding. An adversarial non-reciprocal RIS (NR-RIS) with a non-symmetric scattering matrix breaks the usual uplink/downlink channel reciprocity, so the BS designs MRT or ZF precoders from uplink estimates that do not match the actual downlink channel, degrading throughput and increasing eavesdropping success. The paper models the NR-RIS using a physically motivated two-port unit with a 3-port circulator, evaluates three attack variants (blind, eavesdropping-aided, knowledge-driven), and proposes SecureCoder, a PPO-based deep reinforcement learning countermeasure that learns a robust precoder from uplink CSI and user rate feedback. Numerical simulations (Figs. 4–13) demonstrate large rate/secrecy degradation for MRT/ZF and partial recovery with SecureCoder.

Significance. If the NR-RIS scattering model is physically realizable, the paper identifies a serious and highly covert threat to TDD systems that does not require synchronization, CSI, or rapid configuration changes—a significant step beyond prior reciprocity attacks based on quickly varying or idealized non-diagonal RIS models. The inclusion of the structural scattering term (Φ−I_N) in the cascaded channel model is a useful physical refinement. The paper also provides a first countermeasure and evaluates it against MRT, ZF, and DRL baselines. However, the central attack results depend on an unvalidated physical realizability assumption inherited from a self-cited preprint, and the DRL results are presented without statistical confidence. The work is valuable but requires additional validation before the quantitative claims can be considered robust.

major comments (3)
  1. [Section II-C, Eq. (9)] The entire attack and countermeasure analysis assumes that a passive lossless NR dual-element unit can realize the unitary non-symmetric scattering matrix Φ = [[0,e^{jφ1}],[e^{jφ2},0]]. This is asserted with reference to [35], but no derivation or independent validation is provided in this manuscript. Since this assumption is load-bearing for all simulation results (Figs. 4–13), please include a self-contained derivation or a circuit-level S-parameter verification. In particular, quantify the effect of non-ideal circulator isolation/insertion loss and finite antenna matching; if |S12| and |S21| fall below 1, the reciprocity mismatch Φ−Φ^T is reduced and the >90% rate loss observed in Fig. 5 may shrink materially.
  2. [Section V-E, Figs. 11-13] The DRL results are presented as single learning curves and single point estimates. DRL is sensitive to random seeds, initialization, and hyperparameters. To support the claim that SecureCoder reliably mitigates CRACK, please report the mean and standard deviation (or confidence intervals) over multiple random seeds, and specify the number of training episodes, environment setups, and hyperparameter sensitivity. Without this, the reported 'nearly 300% enhancement' and the secrecy-outage improvements in Fig. 13 may not be reproducible.
  3. [Section II-A and Section V-B] The comparison of NR-RIS with the ND-RIS and D-RIS benchmarks may be confounded by the use of the structural scattering term (Φ−I_N) in the NR-RIS cascaded channel model. The benchmarks are described 'as assumed in [24,25,28,29]', which conventionally use Φ (without the −I_N term). If the benchmarks do not include structural scattering, the improved attack performance of NR-RIS in Fig. 8 could be partly due to this additional term rather than non-reciprocity. Please clarify whether the benchmarks also use the (Φ−I_N) model, or provide a version of Fig. 8 in which all RIS models adopt the same structural scattering assumption.
minor comments (6)
  1. [Section IV-B, Eq. (11)] The reward is defined as r_t = Σ_k log(1 + r_{t,k}), where r_{t,k} is already the achievable rate log(1+SINR). This yields a double logarithm of SINR. Please clarify whether the intended reward is Σ_k log(1+SINR_{t,k}) or Σ_k log(r_{t,k}), and justify the current form.
  2. [Table I] The discount factor is listed as γ=0, which contradicts the text in Section IV-B that says the agent maximizes 'long-term cumulative reward.' For an i.i.d. channel per coherence block, γ=0 is acceptable, but it makes the problem a contextual bandit; please clarify or correct the value.
  3. [Figure 11] The training convergence plot lacks axis labels and a clear legend. Please add labels, and report the reward scale and the number of episodes used for training in the text.
  4. [Section III-A] The sentence 'the reconfiguration interval △t of the RIS ∆t is significantly shorter' uses duplicate symbols for the same quantity. Please edit.
  5. [Section II-C] The contribution list states 'We introduce a novel NR-RIS model using multiport network analysis,' but the model is adopted from [35]. Please revise the wording to avoid overclaiming novelty.
  6. [References/Code] Reference [35] is an arXiv preprint; if a published version exists, please cite it. Also, footnote 3 says the source code 'will be available soon'; for reproducibility, provide a working link or include the code as supplementary material.

Circularity Check

0 steps flagged

No significant circularity: the paper's results are simulations under an explicitly stated non-reciprocal-RIS model; the self-cited physical realizability result is a dependency but not a circular reduction.

full rationale

The paper's derivation chain is conditional on an assumed non-reciprocal unitary RIS scattering matrix Phi (Sec. II-A: 'Phi satisfying Phi Phi^H = I_N and Phi != Phi^T'), and then evaluates SINR/rate expressions under MRT/ZF precoding. No parameter is fitted to the reported rate, secrecy-rate, or SOP outcomes; the NR-RIS phases are either random or chosen by the stated HA heuristic that maximizes the uplink-downlink LoS difference, which is an attack objective rather than a fit to the evaluation metric. The DRL-based SecureCoder is trained to maximize the sum-log-rate reward in (11), so its performance on that same metric is an optimization result, not a circular prediction. The main external dependency is the physically-consistent NR-RIS model in Eq. (9), which is attributed to the self-cited preprint [35]: 'As shown in [35], by properly choosing the RIS element impedances and the terminating impedance Z3, the equivalent 2 x 2 scattering matrix for the unit can be made to satisfy Phi = [[0,e^{j phi1}],[e^{j phi2},0]].' This citation is load-bearing for the physical-consistency claim and is a validation risk, but it is not a circular reduction: the present paper does not redefine its conclusions as inputs, and the simulations are conditional on an external, parameter-free circuit-theoretic achievability result. The later channel mismatch H_down != H*_down follows by construction from Phi != Phi^T, but that is a modeling implication, not a fitted prediction. No circular step meeting the evidence bar is present, so the circularity score is 0.

Axiom & Free-Parameter Ledger

7 free parameters · 4 axioms · 0 invented entities

The paper introduces no new physical entities; the NR-RIS is an existing concept. The free parameters listed are simulation and training choices, not fitted to data. The main assumptions are the physically consistent non-reciprocal RIS model and the separability limitation at the BS. No evidence of circular fitting of parameters to target outcomes was found.

free parameters (7)
  • Path loss exponents (ι_{k,r}, ι_{k,b}, ι_{e,r}, ι_{e,b}, ι_{r,b}) = 2.5, 3.5, 2.5, 3.2, 2
    Chosen simulation parameters that determine the attack effectiveness. They are not fitted to data but are hand-set.
  • Rician factors (κ_{k,r}, κ_{k,b}, κ_{e,r}, κ_{e,b}, κ_{r,b}) = 6, 3, 8, 4, 12
    Chosen to define the channel model in simulations.
  • NR-RIS phase offset (φ1 - φ2) = π (heuristic)
    The authors adopt the heuristic setting φ1 - φ2 = π to strengthen non-reciprocity, rather than deriving it from first principles.
  • DRL discount factor γ = 0
    A discount factor of 0 means the agent only optimizes immediate reward. This choice simplifies training and is listed in Table I.
  • DRL batch size I = 2000
    Training hyperparameter chosen for the PPO algorithm.
  • Block size L = varies (2 to 128)
    The block size of the NR-RIS is varied in simulations to study its impact. Not fitted, but chosen to explore the design space.
  • Heuristic weighting β_k in HA = α_{k,r} α_{r,b} κ_{k,r} κ_{r,b} / ((1+κ_{k,r})(1+κ_{r,b}))
    Used in the knowledge-driven attack heuristic to emphasize LoS components. Chosen ad hoc and not derived from optimization.
axioms (4)
  • domain assumption TDD channel reciprocity holds in the absence of non-reciprocal scatterers.
    Standard assumption in TDD systems, used in Section II to define the expected downlink channel.
  • domain assumption The NR-RIS dual-element unit can be configured to realize Φ = [[0, e^{jφ1}], [e^{jφ2}, 0]] using a 3-port circulator and tunable impedances.
    Taken from [35], which is co-authored by three of the current authors. Not derived or experimentally validated in this paper.
  • domain assumption The structural scattering term (Φ - I_N) correctly models the RIS's full effect, including virtual direct links.
    Based on [36,37]. The paper adopts this without independent derivation.
  • domain assumption The base station cannot separate the direct and RIS-induced channel components from uplink pilots alone.
    Assumed in the attack model in Section II. The paper states this as a limitation of the available CSI.

reviewed 2026-08-04 · how reviews work

0 comments
Cite this review

Pith. "Pith review of Nonreciprocal RIS-Aided Covert Channel Reciprocity Attacks and Countermeasures." pith.science (2026). https://pith.science/paper/FCVG353C

@misc{pith2026250911117,
  author       = {Pith},
  title        = {Pith review of: Nonreciprocal RIS-Aided Covert Channel Reciprocity Attacks and Countermeasures},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/FCVG353C}},
  note         = {Machine review of arXiv:2509.11117}
}
Share X Bluesky LinkedIn Reddit HN
read the original abstract

Reconfigurable intelligent surface (RIS) technology enhances wireless communication performance, but it also introduces new vulnerabilities that can be exploited by adversaries. This paper investigates channel reciprocity attack (CRACK) threats in multi-antenna wireless systems operating in time-division duplexing mode using a physically consistent non-reciprocal RIS (NR-RIS) model. CRACK can degrade communication rate and facilitate passive eavesdropping behavior by distorting the downlink precoding, without requiring any additional signal transmission or channel state information (CSI). Unlike conventional RIS jamming strategies, the NR-RIS does not need synchronization with the legitimate system and thus can operate with slow or fixed configurations to implement CRACK, obscuring the distinction between the direct and RIS-induced channels and thereby complicating corresponding defensive precoding designs. To counter the CRACK threat posed by NR-RIS, we develop ``SecureCoder,'' a deep reinforcement learning-based framework that can mitigate CRACK and determine an improved downlink precoder matrix using the estimated uplink CSI and rate feedback from the users. Simulation results demonstrate the severe performance degradation caused by NR-RIS CRACK and validate the effectiveness of SecureCoder in improving both throughput and reducing security threats, thereby enhancing system robustness.

Figures

Figures reproduced from arXiv: 2509.11117 by A. Lee Swindlehurst, Haoyu Wang, Jiaqi Xu, Jiawei Hu, Ying Ju.

Figure 1
Figure 1. Figure 1: Illustration of a TDD MU-MISO system with a malicious NR-RIS [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Illustration of a NR dual-element unit. B. Achievable Rate under MRT and ZF Precoding To explore the impact of NR-RIS CRACK on TDD MU￾MISO systems, two widely used linear precoding technologies, maximum ratio transmission (MRT) and zero-forcing (ZF) precoding are adopted in the simulations to facilitate perfor￾mance comparisons with other related works [24, 25, 28, 29]. The respective precoding matrices fo… view at source ↗
Figure 3
Figure 3. Figure 3: Framework of DRL-based SecureCoder to lie in the range [0, 1] by modeling the output distributions of the actor network using Beta distributions. Before generating the precoder, Wa t is normalized as √ PtotalWa t /∥Wa t ∥F to satisfy the total transmit power constraint. Then, the complex￾valued precoding matrix Wt is realized as Wt = Wa t ⊙ e j·2πWp t , where ⊙ represents an element-wise product. As with t… view at source ↗
Figure 4
Figure 4. Figure 4: Ergodic sum rate, sum secrecy rate, and SOP with and without NR-RIS for MRT and ZF, where N=128 and M=32. [PITH_FULL_IMAGE:figures/full_fig_p010_4.png] view at source ↗
Figure 6
Figure 6. Figure 6: Impact of BS-RIS path loss exponent ιr,b on ergodic sum rate versus number of BS antennas M. 20 40 60 80 100 120 Block Size, L 0 5 10 15 20 25 30 Ergodic Sum Rate, Mb/s MRT (N=128) CRACK (M=32) CRACK (M=128) No CRACK (M=32) No CRACK (M=128) 20 40 60 80 100 120 L 0 10 20 30 40 50 60 70 80 90 Ergodic Sum Rate, Mb/s ZF (N=128) CRACK (M=32) CRACK (M=128) No CRACK (M=32) No CRACK (M=128) 10 20 4 6 8 5 10 7 8 9 … view at source ↗
Figure 7
Figure 7. Figure 7: Ergodic sum rate versus NR-RIS block size [PITH_FULL_IMAGE:figures/full_fig_p010_7.png] view at source ↗
Figure 8
Figure 8. Figure 8: Attack effect comparisons among NR-RIS, ND-RIS and D-RIS. [PITH_FULL_IMAGE:figures/full_fig_p011_8.png] view at source ↗
Figure 11
Figure 11. Figure 11: Comparison of training convergence behavior. [PITH_FULL_IMAGE:figures/full_fig_p011_11.png] view at source ↗
Figure 12
Figure 12. Figure 12: Performance comparison for blind CRACK (M=32). [PITH_FULL_IMAGE:figures/full_fig_p012_12.png] view at source ↗
Figure 13
Figure 13. Figure 13: Performance comparison for CRACK with an eavesdropper (M=32). [PITH_FULL_IMAGE:figures/full_fig_p012_13.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

44 extracted references · 3 linked inside Pith

  1. [1]

    A survey on wireless security: Technical challenges, recent advances, and future trends,

    Y . Zou, J. Zhu, X. Wang, and L. Hanzo, “A survey on wireless security: Technical challenges, recent advances, and future trends,” Proc. IEEE , vol. 104, no. 9, pp. 1727–1765, Sept. 2016

  2. [2]

    Principles of physical layer security in multiuser wireless networks: A survey,

    A. Mukherjee, S. A. A. Fakoorian, J. Huang, and A. L. Swindlehurst, “Principles of physical layer security in multiuser wireless networks: A survey,” IEEE Commun. Surv. & Tutor ., vol. 16, no. 3, pp. 1550–1573, 3st Quat. 2014

  3. [3]

    Safeguarding 5G wireless communication networks using physical layer security,

    N. Yang, L. Wang, G. Geraci, M. Elkashlan, J. Yuan, and M. D. Renzo, “Safeguarding 5G wireless communication networks using physical layer security,” IEEE Commun. Mag. , vol. 53, no. 4, pp. 20–27, Apr. 2015. 13

  4. [4]

    A survey on reconfigurable intelligent surface for physical layer security of next-generation wireless communications,

    R. Kaur, B. Bansal, S. Majhi, S. Jain, C. Huang, and C. Yuen, “A survey on reconfigurable intelligent surface for physical layer security of next-generation wireless communications,” IEEE Open J. V eh. Technol., vol. 5, pp. 172–199, Jan. 2024

  5. [5]

    Reconfigurable intelligent surface for physical layer security in 6G-IoT: Designs, issues, and advances,

    W. Khalid, M. A. U. Rehman, T. Van Chien, Z. Kaleem, H. Lee, and H. Yu, “Reconfigurable intelligent surface for physical layer security in 6G-IoT: Designs, issues, and advances,”IEEE Internet Things J., vol. 11, no. 2, pp. 3599–3613, Jul. 2024

  6. [6]

    Reconfigurable intelligent surfaces for 6G systems: Prin- ciples, applications, and research directions,

    C. Pan, H. Ren, K. Wang, J. F. Kolb, M. Elkashlan, M. Chen, M. Di Renzo, Y . Hao, J. Wang, A. L. Swindlehurst, X. You, and L. Hanzo, “Reconfigurable intelligent surfaces for 6G systems: Prin- ciples, applications, and research directions,” IEEE Commun. Mag. , vol. 59, no. 6, pp. 14–20, June 2021

  7. [7]

    Reconfigurable intelligent surfaces for wireless communi- cations: Principles, challenges, and opportunities,

    M. A. ElMossallamy, H. Zhang, L. Song, K. G. Seddik, Z. Han, and G. Y . Li, “Reconfigurable intelligent surfaces for wireless communi- cations: Principles, challenges, and opportunities,” IEEE Trans. Cogn. Commun. Netw., vol. 6, no. 3, pp. 990–1002, Sept. 2020

  8. [8]

    Reconfigurable intelligent surfaces: Principles and opportunities,

    Y . Liu, X. Liu, X. Mu, T. Hou, J. Xu, M. Di Renzo, and N. Al-Dhahir, “Reconfigurable intelligent surfaces: Principles and opportunities,” IEEE Commun. Surv. & Tutor ., vol. 23, no. 3, pp. 1546–1577, 3st Quat. 2021

  9. [9]

    Smart and secure wireless communica- tions via reflecting intelligent surfaces: A short survey,

    A. Almohamad, A. M. Tahir, A. Al-Kababji, H. M. Furqan, T. Khattab, M. O. Hasna, and H. Arslan, “Smart and secure wireless communica- tions via reflecting intelligent surfaces: A short survey,” IEEE Open J. Commun. Soc. , vol. 1, pp. 1442–1456, Sept. 2020

  10. [10]

    Secure intelligent reflecting surface-aided integrated sensing and communica- tion,

    M. Hua, Q. Wu, W. Chen, O. A. Dobre, and A. L. Swindlehurst, “Secure intelligent reflecting surface-aided integrated sensing and communica- tion,” IEEE Trans. Wireless Commun. , vol. 23, no. 1, pp. 575–591, Jan. 2024

  11. [11]

    RIS-assisted robust hybrid beamforming against simultaneous jamming and eavesdropping attacks,

    Y . Sun, K. An, Y . Zhu, G. Zheng, K.-K. Wong, S. Chatzinotas, H. Yin, and P. Liu, “RIS-assisted robust hybrid beamforming against simultaneous jamming and eavesdropping attacks,” IEEE Trans. Wireless Commun., vol. 21, no. 11, pp. 9212–9231, Nov. 2022

  12. [12]

    Physical layer security enhancement with reconfigurable intelligent surface-aided net- works,

    J. Zhang, H. Du, Q. Sun, B. Ai, and D. W. K. Ng, “Physical layer security enhancement with reconfigurable intelligent surface-aided net- works,” IEEE Trans. Inf. F orensics Secur ., vol. 16, pp. 3480–3495, May 2021

  13. [13]

    Counteracting eavesdropper attacks through reconfigurable intelligent surfaces: A new threat model and secrecy rate optimization,

    G. C. Alexandropoulos, K. D. Katsanos, M. Wen, and D. B. Da Costa, “Counteracting eavesdropper attacks through reconfigurable intelligent surfaces: A new threat model and secrecy rate optimization,” IEEE Open J. Commun. Soc. , vol. 4, pp. 1285–1302, June 2023

  14. [14]

    Safeguarding MIMO communications with reconfigurable metasurfaces and artificial noise,

    G. C. Alexandropoulos, K. Katsanos, M. Wen, and D. B. Da Costa, “Safeguarding MIMO communications with reconfigurable metasurfaces and artificial noise,” in Proc. IEEE Int’l Conf. on Communications (ICC) , Montreal, Canada, June 2021

  15. [15]

    RIS-assisted green secure communications: Active RIS or passive RIS?

    W. Lv, J. Bai, Q. Yan, and H. M. Wang, “RIS-assisted green secure communications: Active RIS or passive RIS?” IEEE Wireless Commun. Lett., vol. 12, no. 2, pp. 237–241, 2023

  16. [16]

    Metasurface manipulation attacks: Potential security threats of RIS-aided 6G communications,

    H. Alakoca, M. Namdar, S. Aldirmaz-Colak, M. Basaran, A. Basgu- mus, L. Durak-Ata, and H. Yanikomeroglu, “Metasurface manipulation attacks: Potential security threats of RIS-aided 6G communications,” IEEE Commun. Mag. , vol. 61, no. 1, pp. 24–30, Jan. 2023

  17. [17]

    Metasurface-enabled smart wireless attacks at the physical layer,

    M. Wei, H. Zhao, V . Galdi, L. Li, and T. J. Cui, “Metasurface-enabled smart wireless attacks at the physical layer,” Nat Electron 6 , p. 610618, Aug. 2023

  18. [18]

    Wireless communication in the presence of illegal reconfigurable intelligent sur- face: Signal leakage and interference attack,

    Y . Wang, H. Lu, D. Zhao, Y . Deng, and A. Nallanathan, “Wireless communication in the presence of illegal reconfigurable intelligent sur- face: Signal leakage and interference attack,” IEEE Wireless. Commun. , vol. 29, no. 3, pp. 131–138, June 2022

  19. [19]

    Use of intelligent reflecting surfaces for and against wireless communication security,

    S. Sarp, H. Tang, and Y . Zhao, “Use of intelligent reflecting surfaces for and against wireless communication security,” in Proc. IEEE 4th 5G World F orum (5GWF), Montreal, Canada, Nov. 2021, pp. 374–377

  20. [20]

    Silent flickering RIS aided covert attacks via intermittent cooperative jamming,

    L. Dai, H. Huang, C. Zhang, and K. Qiu, “Silent flickering RIS aided covert attacks via intermittent cooperative jamming,” IEEE Wireless Commun. Lett. , vol. 12, no. 6, pp. 1027–1031, June 2023

  21. [21]

    IRS-based wireless jamming attacks: When jammers can attack without power,

    B. Lyu, D. T. Hoang, S. Gong, D. Niyato, and D. I. Kim, “IRS-based wireless jamming attacks: When jammers can attack without power,” IEEE Wireless Commun. Lett. , vol. 9, no. 10, pp. 1663–1667, Oct. 2020

  22. [22]

    Active RIS-empowered signal cancellation attacks,

    L. Dai, C. Zhang, S. Wang, S. Jia, H. Huang, and K. Qiu, “Active RIS-empowered signal cancellation attacks,” IEEE Trans. V ehic. Tech., vol. 73, no. 3, pp. 4487–4492, Mar. 2024

  23. [23]

    Malicious recon- figurable intelligent surfaces: How impactful can destructive beamform- ing be?

    S. Rivetti, O. Demir, E. Bj ¨ornson, and M. Skoglund, “Malicious recon- figurable intelligent surfaces: How impactful can destructive beamform- ing be?” IEEE Wireless Commun. Lett. , vol. 13, no. 7, pp. 1918–1922, May 2024

  24. [24]

    Illegal intelligent reflecting surface based active channel aging: When jammer can attack without power and CSI,

    H. Huang, Y . Zhang, H. Zhang, C. Zhang, and Z. Han, “Illegal intelligent reflecting surface based active channel aging: When jammer can attack without power and CSI,” IEEE Trans. V ehic. Tech., vol. 72, no. 8, pp. 11 018–11 022, Aug. 2023

  25. [25]

    Disco intelligent reflecting surfaces: Active channel aging for fully- passive jamming attacks,

    H. Huang, Y . Zhang, H. Zhang, Y . Cai, A. L. Swindlehurst, and Z. Han, “Disco intelligent reflecting surfaces: Active channel aging for fully- passive jamming attacks,” IEEE Trans. Wireless Commun., vol. 23, no. 1, pp. 806–819, Jan. 2024

  26. [26]

    Disco intelligent omni-surface based fully-passive jamming attacks,

    Y . Zhang, H. Huang, H. Zhang, B. Di, W. Mei, J. Yuan, and Y . Cai, “Disco intelligent omni-surface based fully-passive jamming attacks,” in Proc. IEEE/CIC Int’l Conf. on Communications in China (ICCC) , 2024, pp. 1881–1886

  27. [27]

    Malicious RIS versus massive MIMO: Securing multiple access against RIS-based jamming attacks,

    A. S. de Sena, J. Kibida, N. H. Mahmood, A. Gomes, and M. Latva-Aho, “Malicious RIS versus massive MIMO: Securing multiple access against RIS-based jamming attacks,” IEEE Wireless Commun. Lett. , vol. 13, no. 4, pp. 989–993, Jan. 2024

  28. [28]

    Anti-jamming precoding against Disco intelligent reflecting surfaces based fully-passive jamming attacks,

    H. Huang, L. Dai, H. Zhang, Z. Tian, Y . Cai, C. Zhang, A. L. Swindle- hurst, and Z. Han, “Anti-jamming precoding against Disco intelligent reflecting surfaces based fully-passive jamming attacks,” IEEE Trans. Wireless Commun., vol. 23, no. 8, pp. 9315–9329, Feb. 2024

  29. [29]

    Channel reciprocity attacks using intelligent surfaces with non-diagonal phase shifts,

    H. Wang, Z. Han, and A. L. Swindlehurst, “Channel reciprocity attacks using intelligent surfaces with non-diagonal phase shifts,” IEEE Open J. Commun. Soc. , vol. 5, pp. 1469–1485, 2024

  30. [30]

    Reconfigurable intelligent surfaces relying on non-diagonal phase shift matrices,

    Q. Li, M. El-Hajjar, I. Hemadeh, A. Shojaeifard, A. A. M. Mourad, B. Clerckx, and L. Hanzo, “Reconfigurable intelligent surfaces relying on non-diagonal phase shift matrices,” IEEE Trans. V ehic. Tech., vol. 71, no. 6, pp. 6367–6383, June 2022

  31. [31]

    Joint transceiver and reconfigurable intelligent surface design for multiuser mmWave MIMO systems relying on non-diagonal phase shift matrices,

    J. Singh, S. Srivastava, A. K. Jagannatham, and L. Hanzo, “Joint transceiver and reconfigurable intelligent surface design for multiuser mmWave MIMO systems relying on non-diagonal phase shift matrices,” IEEE Open J. Commun. Society , vol. 4, pp. 2897–2912, Oct. 2023

  32. [32]

    RIS-jamming: Breaking key consistency in channel reciprocity-based key generation,

    G. Li, P. Staat, H. Li, M. Heinrichs, C. Zenger, R. Kronberger, H. Elders- Boll, C. Paar, and A. Hu, “RIS-jamming: Breaking key consistency in channel reciprocity-based key generation,” IEEE Trans. Info. F orensics & Security, vol. 19, pp. 5090–5105, Apr. 2024

  33. [33]

    A countermeasure against RIS jamming attack in physical-layer key generation,

    Z. Wan, X. Hu, X. Sun, X. Xu, K. Huang, and L. Jin, “A countermeasure against RIS jamming attack in physical-layer key generation,” IEEE Wireless Commun. Lett. , vol. 12, no. 12, pp. 2193–2197, Sept. 2023

  34. [34]

    Beyond-diagonal RIS attacks on physical layer key generation,

    H. Wang, J. Nossek, and A. Swindlehurst, “Beyond-diagonal RIS attacks on physical layer key generation,” in Proc. IEEE Int’l Workshop on Signal Processing Advances in Wireless Communications (SPA WC) , 2024, pp. 946–950

  35. [35]

    Non-reciprocal reconfigurable intelligent surfaces,

    J. Xu, H. Wang, R. Liu, J. A. Nossek, and A. L. Swindlehurst, “Non-reciprocal reconfigurable intelligent surfaces,” 2024. [Online]. Available: https://arxiv.org/abs/2411.15617

  36. [36]

    Non-reciprocal beyond diagonal RIS: Multiport network models and performance benefits in full-duplex systems,

    H. Li and B. Clerckx, “Non-reciprocal beyond diagonal RIS: Multiport network models and performance benefits in full-duplex systems,” arXiv preprint arXiv:2411.04370, 2024

  37. [37]

    Physically consistent modeling of wireless links with reconfigurable intelligent surfaces using multiport network analysis,

    J. A. Nossek, D. Semmler, M. Joham, and W. Utschick, “Physically consistent modeling of wireless links with reconfigurable intelligent surfaces using multiport network analysis,” IEEE Wireless Commun. Lett., vol. 13, no. 8, pp. 2240–2244, June 2024

  38. [38]

    Beyond diagonal reconfig- urable intelligent surfaces utilizing graph theory: Modeling, architecture design, and optimization,

    M. Nerini, S. Shen, H. Li, and B. Clerckx, “Beyond diagonal reconfig- urable intelligent surfaces utilizing graph theory: Modeling, architecture design, and optimization,” IEEE Trans. Wireless Commun., vol. 23, no. 8, pp. 9972–9985, Feb. 2024

  39. [39]

    Proactive eavesdropping via jamming for rate maximization over rayleigh fading channels,

    J. Xu, L. Duan, and R. Zhang, “Proactive eavesdropping via jamming for rate maximization over rayleigh fading channels,” IEEE Wireless Commun. Lett. , vol. 5, no. 1, pp. 80–83, 2016

  40. [40]

    Alternate-jamming-aided wireless physical-layer surveillance: Protocol design and performance analysis,

    L. Sun, Y . Zhang, and A. Swindlehurst, “Alternate-jamming-aided wireless physical-layer surveillance: Protocol design and performance analysis,” IEEE Trans. Info. F orensics & Security, vol. 16, pp. 1989– 2003, Dec. 2021

  41. [41]

    Pilot contamination for active eavesdropping,

    X. Zhou, B. Maham, and A. Hjorungnes, “Pilot contamination for active eavesdropping,” IEEE Trans. Wireless Commun., vol. 11, no. 3, pp. 903– 907, Feb. 2012

  42. [42]

    A novel pilot spoofing scheme via intelligent reflecting surface based on statistical CSI,

    J. Yang, X. Ji, F. Wang, K. Huang, and L. Guo, “A novel pilot spoofing scheme via intelligent reflecting surface based on statistical CSI,” IEEE Trans. V eh. Technol., vol. 70, no. 12, pp. 12 847–12 857, Oct. 2021

  43. [43]

    Prox- imal policy optimization algorithms,

    J. Schulman, F. Wolski, P. Dhariwal, A. Radford, and O. Klimov, “Prox- imal policy optimization algorithms,” arXiv preprint arXiv:1707.06347 , 2017

  44. [44]

    Soft actor-critic: Off- policy maximum entropy deep reinforcement learning with a stochastic actor,

    T. Haarnoja, A. Zhou, P. Abbeel, and S. Levine, “Soft actor-critic: Off- policy maximum entropy deep reinforcement learning with a stochastic actor,” in Proc. Int’l Conf. on Machine Learning (ICML) , 2018, pp. 1861–1870

This paper was first reviewed by deepseek-v4-flash on August 4, 2026.