Score
Designs, builds, and evaluates signal- and waveform-level mechanisms that protect communication channels at the physical layer from eavesdropping, detection, and jamming. Work includes waveform, modulation, timing and spatial obfuscation; covert signaling; spread‑spectrum and anti‑jamming techniques; and their hardware/firmware or signal‑processing implementations and protocol integration while optimizing overhead and resilience.
This work addresses the vulnerability of physical-layer communications to side-channel attacks, which can lead to data theft, eavesdropping, and denial-of-service, as traditional protocols often fail to ensure the confidentiality and integrity of data types and destinations. To counter these threats, the paper proposes a novel physical-layer security protocol framework that integrates data-flow awareness with integrity verification mechanisms. By synergistically combining side-channel analysis, anomaly behavior detection, and physical-layer security techniques, the framework effectively mitigates man-in-the-middle and advanced persistent threats targeting copper, fiber-optic, and wireless media. Experimental results demonstrate that the proposed approach significantly enhances data confidentiality and resilience against interference at the physical layer, while substantially reducing the success rate of advanced persistent physical attacks.
The broadcast nature of wireless communications poses severe challenges to physical-layer security. Artificial noise (AN) exploits spatial degrees of freedom in multi-antenna channels to generate directional interference, significantly degrading eavesdropper channel capacity without compromising legitimate user performance—thereby enhancing secrecy rate. This paper provides a systematic survey of AN’s evolution, channel-aware modeling methodologies, and application paradigms in large-scale MIMO and beamforming systems. We establish a unified research framework encompassing design principles, fundamental performance limits, and integration with emerging technologies. Innovatively, we categorize prevailing AN schemes by their applicability conditions and inherent limitations, and explicitly identify three critical open challenges: low-overhead AN design, dynamic channel adaptation, and cross-layer coordination. The work delivers a structured technical roadmap and forward-looking guidance for advancing physical-layer secure communications.
This work addresses the dual challenges of insufficient communication security and vulnerable sensing privacy in integrated sensing and communication (ISAC) systems by proposing a novel signal modulation architecture tailored for frequency-modulated continuous-wave (FMCW) radar. The approach uniquely integrates index modulation (IM) with a purpose-designed phase coding (PC) scheme to simultaneously enhance physical-layer security and sensing privacy. Specifically, IM strengthens communication confidentiality, while the customized phase coding deliberately distorts the radar ambiguity function, thereby impeding unauthorized receivers from accurately estimating target range and velocity. Simulation results demonstrate that the proposed method significantly improves both communication security and sensing privacy protection without compromising high data throughput.
Provable covert communication based on the square-root law (SRL) remains experimentally unvalidated in the radio-frequency (RF) domain; existing demonstrations are confined to optical channels. Method: This work presents the first RF implementation of a mathematically provable covert communication system using software-defined radio (SDR), achieving high-precision time–frequency synchronization and ultra-low-power modulation under strict SRL constraints. Contribution/Results: Experimental results closely match information-theoretic predictions, empirically validating the SRL’s applicability in RF environments and refuting the conventional assumption that standard RF links are inherently unsuitable for covert transmission. By bridging the gap between theory and practice, this study establishes the first empirical foundation for RF-based low-probability-of-detection (LPD) communication, providing both critical experimental evidence and a practical technical pathway toward real-world deployment.
To address the vulnerability of radar parameters to passive eavesdropping and the inherent trade-off between security and sensing performance in Integrated Sensing and Communication (ISAC) systems, this paper proposes a Random Frequency and Pulse Repetition Interval Agile (RFPA) waveform design. The framework integrates Channel Reciprocity-based Key Generation (CRKG) with hybrid information embedding—combining ASK, PSK, Index Modulation, and Spatial Modulation—enabling decentralized secure communication-sensing coexistence. A novel sparse matched-filter receiver is devised to jointly achieve high-accuracy Doppler and PRI estimation while ensuring low-bit-error-rate (BER) data decoding. Experimental results demonstrate a significant reduction in passive eavesdroppers’ success rate for estimating critical radar parameters; ambiguity function analysis confirms improved range-Doppler resolution and enhanced clutter suppression; and communication throughput increases substantially with markedly reduced BER.
This work addresses the dual security challenges in integrated sensing and communication (ISAC) systems, where a shared waveform simultaneously supports secure communication and environmental sensing, yet remains vulnerable to both eavesdropping and sensing privacy leakage. The paper establishes the first unified physical-layer security framework that explicitly characterizes the intrinsic coupling between communication secrecy and sensing privacy. It proposes a joint security mechanism integrating feedback-based key extraction, eavesdropper-channel coding, and resolvability-based coding. By optimizing the joint input distribution, the study reveals the fundamental trade-offs among secrecy rate, legitimate sensing performance, and adversarial sensing suppression capability, derives the achievable secure performance region, and validates the proposed approach through numerical experiments, thereby laying a theoretical foundation for secure ISAC system design.
This study addresses a critical security gap in public safety communication systems—such as TETRA, TETRAPOL, and P25—whose signaling planes have long transmitted metadata in plaintext, even when voice payloads are encrypted. By leveraging software-defined radio (SDR) for passive eavesdropping, combined with protocol reverse engineering and metadata correlation analysis, this work demonstrates for the first time that nationwide network mapping and user tracking are feasible using signaling data alone. The research uncovers a standards-level confidentiality flaw in TETRAPOL’s emergency call mechanism and successfully recovers key operational parameters, including base station and terminal identities, group mobility patterns, key domain boundaries, and rotation cycles. Notably, it also extracts unencrypted voice content from TETRAPOL transmissions, underscoring fundamental weaknesses in the signaling confidentiality design of current public safety networks.
This study addresses the vulnerability of Bluetooth Low Energy (BLE) to covert flooding attacks in military medical and wearable Internet-of-Things (IoT) applications, which can lead to resource exhaustion and communication disruption. The work presents the first systematic, quantitative evaluation framework that integrates empirical testbeds—such as Raspberry Pi and Flipper Zero—with wireless channel modeling to accurately assess the real-world impact of such attacks in dense IoT environments. Furthermore, it proposes a lightweight defense mechanism based on channel agility that substantially increases the cost of launching successful attacks. Experimental results demonstrate that even low-cost adversarial devices can inflict severe service degradation, whereas the proposed strategy effectively mitigates these threats and enhances system robustness, making it well-suited for resource-constrained battlefield scenarios.
This study addresses a critical limitation of traditional electromagnetic shielding, which effectively suppresses passive radiation leakage but fails to protect against active radio-frequency (RF) probing attacks. For the first time, this work systematically demonstrates that even within shielded environments, impedance modulation caused by device state transitions can leak sensitive information via backscatter. To validate this vulnerability, the authors construct prototype platforms using FPGAs and microcontrollers, integrating three industrial-grade shielding configurations. Through controlled RF injection and analysis of reflected signals, experiments reveal that passive measurement techniques lose discriminative capability post-shielding, whereas active backscatter remains highly effective in distinguishing different computational workloads. These findings expose a previously overlooked security risk wherein existing shielding mechanisms can be subverted by active probing, thereby challenging the conventional security evaluation paradigm that focuses exclusively on passive emissions.
This study investigates the detrimental impact of artificial noise elimination (ANE) on the physical-layer security performance of artificial noise (AN) schemes, with a focus on the sustainability of secrecy rates in multi-antenna eavesdropping channels. Employing information-theoretic methods, the work establishes, for the first time, scaling laws for both average and instantaneous secrecy rates to quantitatively characterize the erosion of AN’s security gains due to ANE. The key contribution lies in uncovering a critical relationship among the numbers of antennas at the transmitter, legitimate receiver, and eavesdropper: secure communication may fail when the eavesdropper’s antenna count exceeds twice that of the transmitter. Furthermore, the paper provides a sufficient condition under which AN remains effective despite ANE. These findings offer theoretical foundations and practical design guidelines for robust physical-layer security systems resilient to ANE attacks.