Pith. sign in

REVIEW 4 major objections 4 minor 52 references

By assigning each row of a reconfigurable intelligent surface two beam patterns that agree at the communication receiver but oppose at the target, PrivISAC masks sensitive channel-state information from eavesdroppers while keeping legitimat

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-04 06:21 UTC pith:Z4MUEOW3

load-bearing objection PrivISAC is a genuine hardware-validated RIS privacy system — the two-vector-per-row design and shared-key demasking work — but the privacy claim currently only holds for well-separated target and communication directions, and the paper never tests or analyzes that boundary. the 4 major comments →

arxiv 2601.04488 v3 pith:Z4MUEOW3 submitted 2026-01-08 eess.SP

Invisible Walls: Privacy-Preserving ISAC Empowered by Reconfigurable Intelligent Surfaces

classification eess.SP
keywords integrated sensing and communicationprivacy protectionreconfigurable intelligent surfacebeamforming designphysical layer securitywireless sensingchannel state informationeavesdropping
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Integrated sensing and communication (ISAC) systems read human activity from wireless signals, but those signals also leak private information to anyone who listens. PrivISAC proposes a low-cost, plug-and-play defense: a reconfigurable intelligent surface (RIS) that assigns each row two beamforming vectors, designed so the two configurations look nearly identical toward the legitimate communication receiver but produce near-opposite phases toward the sensing target. Randomly switching among a small set of configurations perturbs the channel state information (CSI) seen by an attacker, crashing its gesture-recognition accuracy to roughly 30%, while a shared-key time-domain demasking method lets the legitimate receiver recover clean CSI and sustain 94.2% accuracy. The paper demonstrates the full system on commodity WiFi hardware, including a 1-bit RIS, and shows the privacy hold-up against stronger attackers with more antennas or self-trained models.

Core claim

The central claim is that a passive RIS can simultaneously preserve the communication channel and inject strong, random perturbations into the sensing direction—if each row is assigned a pair of unit-modulus beamforming vectors whose responses coincide at the communication receiver's angle and differ by about π at the target's angle. PrivISAC casts this as a joint optimization over all rows, solved via block coordinate descent with a worst-case communication objective, and extends to 1-bit RIS via a relaxation-and-penalty method. To let the legitimate receiver see through the random switching, the paper pairs the design with a time-domain masking/demasking protocol: a fixed sync segment reve

What carries the argument

The core mechanism is a pair of beamforming vectors per RIS row, jointly optimized so their far-field responses are nearly identical toward the communication direction (-20°) but ~π out of phase toward the sensing direction (50°). This asymmetry makes randomly switched configurations almost invisible to the legitimate communication link while strongly perturbing the CSI observable along the sensing direction. Supporting the core is a BCD-based beamforming design with guaranteed convergence to a KKT point, a 1-bit phase extension with a penalty relaxation, and a time-domain mask/demask protocol: a shared key plus embedded sync segments let the legitimate receiver detect the active configurati

Load-bearing premise

The design requires the communication receiver and the sensing target to be sufficiently separated in angle; if they are close together, one pair of beamforming vectors cannot simultaneously keep the communication response nearly stable and make the sensing response swing by π, and the claimed privacy protection weakens.

What would settle it

Run the same gesture-recognition experiments with the sensing target placed at the same angle as the communication receiver (or at progressively smaller angular separations). If attacker accuracy remains near 30% even at zero separation, the privacy claim holds beyond the paper's geometry; if it rises toward the baseline as separation shrinks, the angular-separation assumption is confirmed as load-bearing. A complementary probe: artificially shorten the channel coherence time and measure the legitimate receiver's demasked CSI error to identify when the synchronization/gain-estimation step brea

Watch this falsifier. Get emailed when new claim-graph text bears on it.

Share X Bluesky LinkedIn Reddit HN

If this is right

  • If the central claim holds, ISAC systems can gain privacy protection on low-cost, single-antenna IoT hardware: the RIS does the work, so no full-duplex jammers or multi-antenna encryption are needed.
  • Legitimate sensing is not collateral damage: with the shared-key demasking, a legitimate receiver sustains 94.2% gesture-recognition accuracy (vs. 93.3% baseline), and the method generalizes from classification to model-based tasks like respiration monitoring.
  • The privacy defense survives stronger attackers: aggregating multiple NICs into a 12-antenna array or letting the attacker self-train on raw perturbed CSI still leaves accuracy near 30% or below.
  • A 1-bit RIS—the most physically realistic low-cost surface—can realize the beamforming pattern with only a modest performance loss, so the privacy layer is implementable on practical hardware.
  • The design improves communication reliability relative to baseline at high MCS levels, because the two vectors are constructed to avoid switching-induced SNR fluctuations during packet transmission.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Because attacker accuracy remains at ~30% (well above the 11% chance level for 9 classes), some residual sensing information appears to leak through the perturbations; whether a more sophisticated attacker—e.g., one that explicitly models the RIS switching schedule or uses blind source separation—can exploit this remains an open question.
  • The whole scheme hinges on angular separation between the communication direction and the target direction (70° in the experiments). If the target moves close to the communication receiver, the objective in Eq. (8) forces a tradeoff between communication stability and privacy; the paper does not characterize this boundary, but a direct experiment placing target and Rx at the same angle would map t
  • The demasking protocol depends on channel coherence: adjacent packets from different configurations are assumed to share the same underlying channel so their ratio yields a relative gain. In fast-fading or highly mobile environments, synchronization and gain estimation could fail; testing with shorter coherence times or with moving receivers would show how brittle the method is.
  • The privacy guarantee is ultimately bound to the secrecy of the shared key and the synchronization pattern: if the RIS schedule ever leaks, an attacker could in principle demask the CSI exactly as the legitimate receiver does. A formal security analysis of the masking/demasking protocol (e.g., under a known-plaintext or chosen-configuration attack) would quantify this risk.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper proposes PrivISAC, a privacy-preserving integrated sensing and communication (ISAC) system built on a reconfigurable intelligent surface (RIS). For each RIS row, two unit-modulus beamforming vectors are optimized so that their responses are nearly identical toward the communication receiver but have near-opposite phases toward the sensing target. A small set of RIS configurations is formed by randomly choosing one of the two vectors per row, and the configurations are switched in time to mask CSI from eavesdroppers. A time-domain masking and demasking method lets the legitimate sensing receiver synchronize with the RIS and compensate configuration-induced gain variations using a shared secret key. The paper derives a block coordinate descent (BCD) algorithm for the beamforming design and a penalized extension for 1-bit RIS. The prototype uses an 8x16 1-bit RIS and commodity Wi-Fi devices. Experiments report that attacker gesture-recognition accuracy drops from about 93% to about 30%, while legitimate sensing accuracy is 94.2%, and communication success ratios improve over a no-RIS baseline.

Significance. If the claims hold, PrivISAC would be a practical, low-cost privacy mechanism for ISAC that does not sacrifice legitimate communication or sensing. The paper's strengths include a real 1-bit RIS implementation, a concrete beamforming formulation with an exact elementwise update rule, a shared-key demasking protocol, and adversarial evaluations that go beyond the basic threat model (multi-antenna attackers, self-trained attackers, respiration monitoring). The work is likely to be of interest to the wireless security and ISAC communities. However, the current evidence supports the headline claim only for a single favorable geometry, and several reproducibility gaps prevent full verification of the design's generality.

major comments (4)
  1. [Section V-B / Eq. (8)] The privacy and communication objectives in Eq. (8) fundamentally conflict as the sensing direction approaches the communication direction. The privacy term wants (hS_k)^H φ_{k,1} ≈ -(hS_k)^H φ_{k,2}, while the communication term wants (hC_k)^H φ_{k,1} ≈ (hC_k)^H φ_{k,2}; when ϑS ≈ ϑC these goals cannot be met simultaneously. The only experimental geometry places the target at 50° and the communication Rx at -20°, a 70° separation, far beyond the ~10° 3-dB beamwidth shown in Fig. 11(c). No experiment or simulation sweeps the angular separation, so the general claim that PrivISAC 'provides effective privacy protection while preserving high-quality communication and sensing' is not supported for the common case where the sensing target and communication receiver are in similar directions. Please add an analytical trade-off bound or a separation sweep, and state the angular regime in which
  2. [Section VI] The evaluation compares PrivISAC only against a 'Baseline' scenario without RIS and with an omnidirectional antenna. Since Section I explicitly motivates PrivISAC relative to IRShield [40] and PhyCloak [26], and claims that prior work either degrades communication or is costly, the absence of any measured comparison with these methods means the asserted advantages over existing privacy-preserving RIS/jamming defenses are not empirically supported. At minimum, IRShield should be implemented on the same prototype and evaluated with the same privacy, sensing, and communication metrics.
  3. [Section III-A / Eq. (8)] The objective in Eq. (8) is governed by the weighting factors ω1, ω2, and ω3, and the 1-bit extension in Section III-C depends on the penalty parameter ρ, yet none of these values are reported in Section V. The paper also omits initialization, the tolerance δ, and Lmax used in Algorithm 1. Without these details, the beamforming design cannot be reproduced or the parameter sensitivity assessed. This is particularly important because the privacy-communication trade-off is controlled by these weights.
  4. [Section III-B] The paper states that Algorithm 1 'is guaranteed to converge to a KKT point of problem (8)' by invoking Proposition 2.7.1 in [41]. Problem (8) is nonconvex, nonsmooth (due to the min operator), and constrained by unit-modulus constraints. The cited proposition is not a BCD convergence theorem of the kind needed here, and exact coordinate minimization does not by itself establish KKT stationarity for this nonsmooth/nonconvex problem. Please provide a tailored convergence proof, state the additional assumptions required, or soften the claim to empirical convergence, which Fig. 11(a) already demonstrates.
minor comments (4)
  1. [Section VI-B] The text refers to 'Fig. 12(c)' when discussing the confusion matrix without demasking; this should be Fig. 13(c).
  2. [Footnote 3] The claim that 2-bit RIS experiments 'omitted due to space' show strong performance is not verifiable. Either provide the results or remove the assertion.
  3. [Figures 12-16] Accuracy and success ratios are reported as point estimates without error bars or confidence intervals. Given six subjects and repeated gestures, reporting standard deviation across subjects or runs would substantially strengthen the empirical claims.
  4. [Section IV-B] The relative gain matrix W is estimated from the same CSI sequence that is later demasked and classified. To rule out optimistic evaluation, a separate calibration segment or cross-validation procedure for gain estimation would be preferable.

Circularity Check

0 steps flagged

No circularity: the beamforming design, demasking, and privacy evaluation are forward operations with independent test data.

full rationale

The central derivation is self-contained. Algorithm 1 optimizes Eq. (8) with two objectives—privacy perturbation in the sensing direction and communication stability—and the beam patterns in Fig. 11 are a verification of that optimization, not a prediction of an input. The time-domain demasking (Sec. IV-B) estimates per-configuration relative gains from the received CSI itself and normalizes by them; this is standard self-calibration of nuisance parameters and does not encode gesture labels, so the 94.2% legitimate sensing accuracy and the attacker's ~30% accuracy are not forced by construction. The attacker is evaluated with the same pre-trained classifier and, in the stronger model, with a self-trained classifier on masked CSI (Sec. VI-D); neither reduces to the system's own fitted parameters. Self-citations (e.g., [45] for RIS-based localization) are background support, not load-bearing. Omitted derivations (1-bit subproblem, 2-bit experiments) and the unanalyzed angular-separation regime are limitations or correctness risks, not circularity. No step of the paper's derivation is equivalent to its inputs by definition.

Axiom & Free-Parameter Ledger

4 free parameters · 5 axioms · 0 invented entities

The central claim rests on a LoS-dominant geometric channel model, an angular separation between communication and sensing directions, a secure shared key, and a coherence-time assumption for gain estimation. These are domain assumptions, not ad hoc inventions; no new physical entities are introduced.

free parameters (4)
  • ω1, ω2, ω3 = not reported
    Weighting factors in the objective (8a) balancing sensing gain, phase opposition, and communication alignment; values are hand-tuned but not disclosed.
  • ρ = not reported
    Penalty factor in the 1-bit RIS extension (Section III-C); adaptively adjusted, value not given.
  • NR = 4 (default)
    Number of candidate RIS configurations; chosen as 4 in experiments with no sensitivity analysis.
  • TRIS and Tsync = 2 ms and 0.5 s
    RIS switching period and synchronization interval; fixed in experiments, effect not studied.
axioms (5)
  • domain assumption Strong LoS between RIS and communication Rx, with GC_k approximated as a rank-1 steering-vector product
    Used to derive the closed-form communication SNR and the beamforming objective in Section II-B.
  • domain assumption LoS path between Tx and RIS, with the Tx using a directional antenna pointed at the RIS
    System model assumes the transmitted signal passes entirely through the RIS (Fig. 1 and Section II-B).
  • domain assumption Sensing target direction θS and communication direction θC are known and sufficiently separated
    Tx estimates ϑC and ϑS via existing algorithms (Section IV); experiments use 50° and -20°.
  • domain assumption CSI remains nearly constant within the channel coherence time
    Used for relative-gain estimation in the demasking method (Section IV-B).
  • domain assumption Attacker lacks the shared key and cannot infer the RIS configuration sequence
    Security analysis and privacy evaluation rely on this (Sections IV-C and VI-B).

pith-pipeline@v1.3.0-alltime-deepseek · 24328 in / 11927 out tokens · 123933 ms · 2026-08-04T06:21:11.389205+00:00 · methodology

0 comments
Cite this review

Pith. "Pith review of Invisible Walls: Privacy-Preserving ISAC Empowered by Reconfigurable Intelligent Surfaces." pith.science (2026). https://pith.science/paper/Z4MUEOW3

@misc{pith2026260104488,
  author       = {Pith},
  title        = {Pith review of: Invisible Walls: Privacy-Preserving ISAC Empowered by Reconfigurable Intelligent Surfaces},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/Z4MUEOW3}},
  note         = {Machine review of arXiv:2601.04488}
}
Share X Bluesky LinkedIn Reddit HN
read the original abstract

The environmental and target-related information inherently carried in wireless signals, such as channel state information (CSI), has brought increasing attention to integrated sensing and communication (ISAC). However, it also raises pressing concerns about privacy leakage through eavesdropping. While existing efforts have attempted to mitigate this issue, they either fail to account for the needs of legitimate communication and sensing or rely on hardware with high cost. To overcome these limitations, we propose PrivISAC, a plug-and-play, low-cost solution that leverages reconfigurable intelligent surface (RIS) to protect user privacy while preserving ISAC performance. At its core, PrivISAC constructs a small set of RIS configurations from two beamforming vectors per RIS row and randomly activates one configuration per time slot to perturb CSI and mask sensitive sensing information from eavesdroppers. The two vectors are designed to maintain similar communication-direction responses while creating distinct sensing-direction responses, thereby preserving transmission quality and masking sensitive CSI from eavesdroppers. To enable legitimate sensing, we introduce a time-domain masking and demasking method that maps CSI samples to their RIS configurations and removes configuration-induced discrepancies. We implement PrivISAC on commodity wireless devices and conduct extensive experiments. Results show that PrivISAC provides effective privacy protection while preserving high-quality communication and sensing performance for legitimate receivers.

Figures

Figures reproduced from arXiv: 2601.04488 by (2) Nanjing University), Jun Luo (1) ((1) Nanyang Technological University, Lei Xie (2), Long Fan (2), Yinghui He (1).

Figure 1
Figure 1. Figure 1: PrivISAC: RIS is leveraged to achieve high [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 3
Figure 3. Figure 3: The communication performance: (a) successful tran [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figure 2
Figure 2. Figure 2: (a) Amplitude, (b) phase, and (c)-(d) time-frequenc [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 4
Figure 4. Figure 4: The CSI after reconstruction: (a) amplitude and phas [PITH_FULL_IMAGE:figures/full_fig_p005_4.png] view at source ↗
Figure 6
Figure 6. Figure 6: Overview of PrivISAC [PITH_FULL_IMAGE:figures/full_fig_p007_6.png] view at source ↗
Figure 7
Figure 7. Figure 7: Timing diagram with proposed strategy. and sensing Rx. Upon receiving the requests, the Tx estimates its channels to both the communication Rx and the sensing Rx, which are used to obtain ϑ C and ϑ S . This can be achieved using existing RIS-based channel estimation and localization algorithms [27], [32], [44], [45]. Then, the Tx exe￾cutes Algorithm 1 to determine the RIS beamforming vectors. Simultaneousl… view at source ↗
Figure 8
Figure 8. Figure 8: Time synchronization between the Rx and the RIS with [PITH_FULL_IMAGE:figures/full_fig_p008_8.png] view at source ↗
Figure 9
Figure 9. Figure 9: CSI distribution with t-SNE. Here, “T1+C1” means the [PITH_FULL_IMAGE:figures/full_fig_p009_9.png] view at source ↗
Figure 10
Figure 10. Figure 10: Prototype and experiment setup. panels arranged to form a single 8×16 array, as shown in [PITH_FULL_IMAGE:figures/full_fig_p010_10.png] view at source ↗
Figure 13
Figure 13. Figure 13: The confusion matrices of the legitimate sensing Rx [PITH_FULL_IMAGE:figures/full_fig_p011_13.png] view at source ↗
Figure 14
Figure 14. Figure 14: Successful ratio under (a) different MCS indices an [PITH_FULL_IMAGE:figures/full_fig_p012_14.png] view at source ↗
Figure 15
Figure 15. Figure 15: Sensing performance under (a) different number of [PITH_FULL_IMAGE:figures/full_fig_p012_15.png] view at source ↗
Figure 17
Figure 17. Figure 17: Training loss and testing loss/accuracy under (a) t [PITH_FULL_IMAGE:figures/full_fig_p013_17.png] view at source ↗
Figure 18
Figure 18. Figure 18: Respiration monitoring: (a) respiration waveform [PITH_FULL_IMAGE:figures/full_fig_p013_18.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

52 extracted references · 1 linked inside Pith

  1. [1]

    Vision, application scenarios, and key technology trend s for 6G mobile communications,

    Z. Wang, Y . Du, K. Wei, K. Han, X. Xu, G. Wei, W. Tong, P . Zhu, J. Ma, J. Wang et al., “Vision, application scenarios, and key technology trend s for 6G mobile communications,” Sci. China Inf. Sci. , vol. 65, no. 5, p. 151301, Mar. 2022

  2. [2]

    The ITU visi on and framework for 6G: Scenarios, capabilities, and enablers,

    R. Liu, L. Zhang, R. Y .-N. Li, and M. Di Renzo, “The ITU visi on and framework for 6G: Scenarios, capabilities, and enablers,” IEEE V eh. Technol. Mag., vol. 20, no. 2, pp. 114–122, Jun. 2025

  3. [3]

    Integrated sensing and communications: Toward dual-func tional wire- less networks for 6G and beyond,

    F. Liu, Y . Cui, C. Masouros, J. Xu, T. X. Han, Y . C. Eldar, an d S. Buzzi, “Integrated sensing and communications: Toward dual-func tional wire- less networks for 6G and beyond,” IEEE J. Sel. Areas Commun. , vol. 40, no. 6, pp. 1728–1767, Jun. 2022

  4. [4]

    Near-field integrated sensing and comm unication: Opportunities and challenges,

    J. Cong, C. Y ou, J. Li, L. Chen, B. Zheng, Y . Liu, W. Wu, Y . Go ng, S. Jin, and R. Zhang, “Near-field integrated sensing and comm unication: Opportunities and challenges,” IEEE Wireless Commun. , vol. 31, no. 6, pp. 162–169, Dec. 2024

  5. [5]

    Int egrating CSI sensing in wireless networks: Challenges to privacy and cou ntermea- sures,

    R. L. Cigno, F. Gringoli, M. Cominelli, and L. Ghiro, “Int egrating CSI sensing in wireless networks: Challenges to privacy and cou ntermea- sures,” IEEE Net. , vol. 36, no. 4, pp. 174–180, Jul./Aug. 2022

  6. [6]

    T oward inte- grated sensing and communications in IEEE 802.11 bf Wi-Fi ne tworks,

    F. Meneghello, C. Chen, C. Cordeiro, and F. Restuccia, “T oward inte- grated sensing and communications in IEEE 802.11 bf Wi-Fi ne tworks,” IEEE Commun. Mag. , vol. 61, no. 7, pp. 128–133, Jul. 2023

  7. [7]

    Forward-Compatibl e Integrated Sensing and Communication for WiFi,

    Y . He, J. Liu, M. Li, G. Y u, and J. Han, “Forward-Compatibl e Integrated Sensing and Communication for WiFi,” IEEE J. Sel. Areas Commun. , vol. 42, no. 9, pp. 2440–2456, Sep. 2024

  8. [8]

    Integrated sensing, comp utation, and communication: System framework and performance optim ization,

    Y . He, G. Y u, Y . Cai, and H. Luo, “Integrated sensing, comp utation, and communication: System framework and performance optim ization,” IEEE Trans. Wireless Commun. , vol. 23, no. 2, pp. 1114–1128, Feb. 2024

  9. [9]

    Mult iSense: Enabling multi-person respiration sensing with commodity WiFi,

    Y . Zeng, D. Wu, J. Xiong, J. Liu, Z. Liu, and D. Zhang, “Mult iSense: Enabling multi-person respiration sensing with commodity WiFi,” Proc. ACM Interact. Mob. W earable Ubiquitous Technol. , vol. 4, no. 3, pp. 1–29, Sep. 2020

  10. [10]

    CSI-fingerprinting in door local- ization via attention-augmented residual convolutional n eural network,

    B. Zhang, H. Sifaou, and G. Y . Li, “CSI-fingerprinting in door local- ization via attention-augmented residual convolutional n eural network,” IEEE Trans. Wireless Commun. , vol. 22, no. 8, pp. 5583–5597, Aug. 2023

  11. [11]

    Cro ss- domain dual-functional OFDM waveform design for accurate s ens- ing/positioning,

    F. Zhang, T. Mao, R. Liu, Z. Han, S. Chen, and Z. Wang, “Cro ss- domain dual-functional OFDM waveform design for accurate s ens- ing/positioning,” IEEE J. Sel. Areas Commun. , vol. 42, no. 9, pp. 2259– 2274, Sep. 2024

  12. [12]

    Positioning using wireless networks: Applicat ions, recent progress and future challenges,

    Y . Y ang, M. Chen, Y . Blankenship, J. Lee, Z. Ghassemlooy , J. Cheng, and S. Mao, “Positioning using wireless networks: Applicat ions, recent progress and future challenges,” IEEE J. Sel. Areas Commun. , vol. 42, no. 9, pp. 2149–2178, Sep. 2024

  13. [13]

    Privacy-a ware time- series data sharing with deep reinforcement learning,

    E. Erdemir, P . L. Dragotti, and D. G¨ und¨ uz, “Privacy-a ware time- series data sharing with deep reinforcement learning,” IEEE Trans. Inf. F orensics Security, vol. 16, pp. 389–401, 2020

  14. [14]

    Safeguarding UA V communi cations against full-duplex active eavesdropper,

    C. Liu, J. Lee, and T. Q. Quek, “Safeguarding UA V communi cations against full-duplex active eavesdropper,” IEEE Trans. Wireless Com- mun., vol. 18, no. 6, pp. 2919–2931, Jun. 2019

  15. [15]

    Channel correlati on in multi- user covert communication: friend or foe?

    J. Lee, H. Y eom, S.-H. Lee, and J. Ha, “Channel correlati on in multi- user covert communication: friend or foe?” IEEE Trans. Inf. F orensics Security, vol. 19, pp. 1469–1482, 2023

  16. [16]

    A compre hensive survey on cooperative relaying and jamming strategies for p hysical layer security,

    F. Jameel, S. Wyne, G. Kaddoum, and T. Q. Duong, “A compre hensive survey on cooperative relaying and jamming strategies for p hysical layer security,” IEEE Commun. Surveys Tuts. , vol. 21, no. 3, pp. 2734–2771, 3rd Quart. 2018

  17. [17]

    Federated learn ing with local differential privacy: Trade-offs between privacy, utilit y, and communi- cation,

    M. Kim, O. G¨ unl¨ u, and R. F. Schaefer, “Federated learn ing with local differential privacy: Trade-offs between privacy, utilit y, and communi- cation,” in Proc. IEEE ICASSP , Jun. 2021, pp. 2650–2654

  18. [18]

    An overview of information-theoretic security and privacy: Metrics, limits and applications,

    M. Bloch, O. G¨ unl¨ u, A. Y ener, F. Oggier, H. V . Poor, L. Sankar, and R. F. Schaefer, “An overview of information-theoretic security and privacy: Metrics, limits and applications,” IEEE J. Sel. Areas Inf. Theory , vol. 2, no. 1, pp. 5–22, Mar. 2021

  19. [19]

    When CSI meets public WiFi: Inferring your mobile phone password via WiFi signals,

    M. Li, Y . Meng, J. Liu, H. Zhu, X. Liang, Y . Liu, and N. Ruan , “When CSI meets public WiFi: Inferring your mobile phone password via WiFi signals,” in Proc. ACM CCS , Oct. 2016, pp. 1068–1079

  20. [20]

    Password-stealing without hacking: Wi-Fi enabled practi cal keystroke eavesdropping,

    J. Hu, H. Wang, T. Zheng, J. Hu, Z. Chen, H. Jiang, and J. Lu o, “Password-stealing without hacking: Wi-Fi enabled practi cal keystroke eavesdropping,” in Proc. ACM CCS , Nov. 2023, pp. 239–252

  21. [21]

    Keystroke rec ognition using WiFi signals,

    K. Ali, A. X. Liu, W. Wang, and M. Shahzad, “Keystroke rec ognition using WiFi signals,” in Proc. ACM MobiCom , Sep. 2015, pp. 90–102

  22. [22]

    Et Tu Alexa? When commodity WiFi devices turn into adversarial motion sensors,

    Y . Zhu, Z. Xiao, Y . Chen, Z. Li, M. Liu, B. Y . Zhao, and H. Zh eng, “Et Tu Alexa? When commodity WiFi devices turn into adversarial motion sensors,” in Proc. ISOC NDSS , Feb. 2020, pp. 1–15

  23. [23]

    Lend me your be am: Privacy implications of plaintext beamforming feedback in WiFi,

    R. Xiao, X. Chen, Y . He, J. Han, and J. Han, “Lend me your be am: Privacy implications of plaintext beamforming feedback in WiFi,” in Proc. ISOC NDSS , Feb. 2025, pp. 1–17

  24. [24]

    Spider Mon: Towards using cell towers as illuminating sources for keyst roke moni- toring,

    K. Ling, Y . Liu, K. Sun, W. Wang, L. Xie, and Q. Gu, “Spider Mon: Towards using cell towers as illuminating sources for keyst roke moni- toring,” in Proc. IEEE INFOCOM , Jul. 2020, pp. 666–675

  25. [25]

    MIMOCrypt : Multi- user privacy-preserving Wi-Fi sensing via MIMO encryption ,

    J. Luo, H. Cao, H. Jiang, Y . Y ang, and Z. Chen, “MIMOCrypt : Multi- user privacy-preserving Wi-Fi sensing via MIMO encryption ,” in Proc. IEEE S&P , May 2024, pp. 2812–2830

  26. [26]

    PhyCloak: Obfuscating sensing from communication signals,

    Y . Qiao, O. Zhang, W. Zhou, K. Srinivasan, and A. Arora, “ PhyCloak: Obfuscating sensing from communication signals,” in Proc. USENIX NSDI, Mar. 2016, pp. 685–699

  27. [27]

    Intelligent reflecting surface- enhanced OFDM: Channel estimation and reflection optimization,

    B. Zheng and R. Zhang, “Intelligent reflecting surface- enhanced OFDM: Channel estimation and reflection optimization,” IEEE Wireless Com- mun. Lett. , vol. 9, no. 4, pp. 518–522, Apr. 2019

  28. [28]

    A path to smart rad io environments: An industrial viewpoint on reconfigurable in telligent surfaces,

    R. Liu, Q. Wu, M. Di Renzo, and Y . Y uan, “A path to smart rad io environments: An industrial viewpoint on reconfigurable in telligent surfaces,” IEEE Wireless Commun. , vol. 29, no. 1, pp. 202–208, Feb. 2022

  29. [29]

    Multi-RIS-aided wireless systems: Statistical cha racterization and performance analysis,

    T. N. Do, G. Kaddoum, T. L. Nguyen, D. B. Da Costa, and Z. J. Haas, “Multi-RIS-aided wireless systems: Statistical cha racterization and performance analysis,” IEEE Trans. Commun., vol. 69, no. 12, pp. 8641– 8658, Dec. 2021

  30. [30]

    RIS-assisted communica tion radar coexistence: Joint beamforming design and analysis,

    Y . He, Y . Cai, H. Mao, and G. Y u, “RIS-assisted communica tion radar coexistence: Joint beamforming design and analysis,” IEEE J. Sel. Areas Commun., vol. 40, no. 7, pp. 2131–2145, Jul. 2022

  31. [31]

    Implementing neu- ral networks over-the-air via reconfigurable intelligent s urfaces,

    M. Hua, C. Bian, H. Wu, and D. Gunduz, “Implementing neu- ral networks over-the-air via reconfigurable intelligent s urfaces,” arXiv:2508.01840, 2025

  32. [32]

    Intelligent reflecting s urface assisted multi-user OFDMA: Channel estimation and training design,

    B. Zheng, C. Y ou, and R. Zhang, “Intelligent reflecting s urface assisted multi-user OFDMA: Channel estimation and training design, ” IEEE Trans. Wireless Commun. , vol. 19, no. 12, pp. 8315–8329, Apr. 2020

  33. [33]

    Reconfigurable intelligent surfaces for energy ef ficiency in wireless communication,

    C. Huang, A. Zappone, G. C. Alexandropoulos, M. Debbah, and C. Y uen, “Reconfigurable intelligent surfaces for energy ef ficiency in wireless communication,” IEEE Trans. Wireless Commun., vol. 18, no. 8, pp. 4157–4170, Aug. 2019

  34. [34]

    Join t beamforming for RIS-assisted integrated sensing and commu nication systems,

    Y . Xu, Y . Li, J. A. Zhang, M. Di Renzo, and T. Q. Quek, “Join t beamforming for RIS-assisted integrated sensing and commu nication systems,” IEEE Trans. Commun. , vol. 72, no. 4, pp. 2232–2246, Apr. 2024

  35. [35]

    Reconfigurable intelligen t surface assisted multiuser miso systems exploiting deep reinforce ment learning,

    C. Huang, R. Mo, and C. Y uen, “Reconfigurable intelligen t surface assisted multiuser miso systems exploiting deep reinforce ment learning,” IEEE J. Sel. Areas Commun. , vol. 38, no. 8, pp. 1839–1850, Aug. 2020

  36. [36]

    Secure intelligent reflecting surface-aided integrated sensing a nd communica- tion,

    M. Hua, Q. Wu, W. Chen, O. A. Dobre, and A. L. Swindlehurst , “Secure intelligent reflecting surface-aided integrated sensing a nd communica- tion,” IEEE Trans. Wireless Commun. , vol. 23, no. 1, pp. 575–591, Jan. 2024

  37. [37]

    Rec onfigurable intelligent surface-assisted passive beamforming attack ,

    H. Niu, Y . Xiao, X. Lei, L. Dan, W. Xiang, and C. Y uen, “Rec onfigurable intelligent surface-assisted passive beamforming attack ,” IEEE Trans. Inf. F orensics Security, vol. 19, pp. 8236–8247, 2024. 15

  38. [38]

    Secu rity and privacy for reconfigurable intelligent surface in 6G: A r eview of prospective applications and challenges,

    F. Naeem, M. Ali, G. Kaddoum, C. Huang, and C. Y uen, “Secu rity and privacy for reconfigurable intelligent surface in 6G: A r eview of prospective applications and challenges,” IEEE Open J. Commun. Soc. , vol. 4, pp. 1196–1217, 2023

  39. [39]

    On the efficie nt design of stacked intelligent metasurfaces for secure siso transm ission,

    H. Niu, X. Lei, J. An, L. Zhang, and C. Y uen, “On the efficie nt design of stacked intelligent metasurfaces for secure siso transm ission,” IEEE Trans. Inf. F orensics Security, vol. 20, pp. 60–70, 2025

  40. [40]

    IRShield: A countermeasure against adversarial physical-layer wireless sensing,

    P . Staat, S. Mulzer, S. Roth, V . Moonsamy, M. Heinrichs, R. Kronberger, A. Sezgin, and C. Paar, “IRShield: A countermeasure against adversarial physical-layer wireless sensing,” in Proc. IEEE S&P , May 2022, pp. 1705–1721

  41. [41]

    Bertsekas, Nonlinear Programming, 2nd ed

    D. Bertsekas, Nonlinear Programming, 2nd ed. Belmont, MA, USA: Athena Scientific, 1999

  42. [42]

    An overview of limited feedback in wireless communi cation systems,

    D. J. Love, R. W. Heath, V . K. Lau, D. Gesbert, B. D. Rao, an d M. An- drews, “An overview of limited feedback in wireless communi cation systems,” IEEE J. Sel. Areas Commun. , vol. 26, no. 8, pp. 1341–1365, Oct. 2008

  43. [43]

    Cooperative dou ble-irs aided communication: Beamforming design and power scaling,

    Y . Han, S. Zhang, L. Duan, and R. Zhang, “Cooperative dou ble-irs aided communication: Beamforming design and power scaling,” IEEE Wireless Commun. Lett. , vol. 9, no. 8, pp. 1206–1210, Aug. 2020

  44. [44]

    RIScan: RIS-aided multi-user indoor localization using C OTS Wi-Fi,

    C. Li, Q. Huang, Y . Zhou, Y . Huang, Q. Hu, H. Chen, and Q. Zh ang, “RIScan: RIS-aided multi-user indoor localization using C OTS Wi-Fi,” in Proc. ACM SenSys , Nov. 2023, pp. 445–458

  45. [45]

    Sense with pol yface mirror: Enhancing Wi-Fi sensing diversity via programmable metasu rfaces,

    L. Fan, Y . He, L. Xie, S. Zhang, and J. Luo, “Sense with pol yface mirror: Enhancing Wi-Fi sensing diversity via programmable metasu rfaces,” in Proc. ACM SenSys , May 2026, pp. 1–15

  46. [46]

    FarS ense: Pushing the range limit of WiFi-based respiration sensing w ith CSI ratio of two antennas,

    Y . Zeng, D. Wu, J. Xiong, E. Yi, R. Gao, and D. Zhang, “FarS ense: Pushing the range limit of WiFi-based respiration sensing w ith CSI ratio of two antennas,” Proc. ACM Interact. Mob. W earable Ubiquitous Technol., vol. 3, no. 3, pp. 1–26, Sep. 2019

  47. [47]

    Visualizing data using t- SNE,

    L. v. d. Maaten and G. Hinton, “Visualizing data using t- SNE,” J. Mach. Learn. Res. , vol. 9, pp. 2579–2605, Nov 2008

  48. [48]

    A 1- bit 10x10 reconfigurable reflectarray antenna: design, opti mization, and experiment,

    H. Y ang, F. Y ang, S. Xu, Y . Mao, M. Li, X. Cao, and J. Gao, “A 1- bit 10x10 reconfigurable reflectarray antenna: design, opti mization, and experiment,” IEEE Trans. Antennas Propag. , vol. 64, no. 6, pp. 2246– 2254, Jun. 2016

  49. [49]

    Eliminating the barriers: Demystify ing Wi-Fi baseband design and introducing the PicoScenes Wi-Fi sensing platform,

    Z. Jiang, T. H. Luan, X. Ren, D. Lv, H. Hao, J. Wang, K. Zhao , W. Xi, Y . Xu, and R. Li, “Eliminating the barriers: Demystify ing Wi-Fi baseband design and introducing the PicoScenes Wi-Fi sensing platform,” IEEE Internet Things J. , vol. 9, no. 6, pp. 4476–4496, Mar. 2021

  50. [50]

    Reconfigurable intelligent surface based RF sensing : Design, optimization, and implementation,

    J. Hu, H. Zhang, B. Di, L. Li, K. Bian, L. Song, Y . Li, Z. Han , and H. V . Poor, “Reconfigurable intelligent surface based RF sensing : Design, optimization, and implementation,” IEEE J. Select. Areas Commun. , vol. 38, no. 11, pp. 2700–2716, Nov. 2020

  51. [51]

    SignFi: Sig n language recognition using WiFi,

    Y . Ma, G. Zhou, S. Wang, H. Zhao, and W. Jung, “SignFi: Sig n language recognition using WiFi,” Proc. ACM Interact. Mob. W earable Ubiquitous Technol., vol. 2, no. 1, pp. 1–21, Mar. 2018

  52. [52]

    RISENSE: Long-ra nge in- band wireless control of passive reconfigurable intelligen t surfaces,

    S. P . Deram, M. Rossanese, A. Garcia-Saavedra, S. W. H. S hah, V . Scian- calepore, J. Widmer, and X. Costa-Perez, “RISENSE: Long-ra nge in- band wireless control of passive reconfigurable intelligen t surfaces,” in Proc. ACM MobiSys , Jun. 2025, pp. 347–360