Source-linked AI summary
Secure Massive MIMO Transmission with an Active Eavesdropper
Yongpeng Wu, Robert Schober, Derrick Wing Kwan Ng, Chengshan Xiao, Giuseppe Caire
TL;DR
The paper studies how an active eavesdropper can contaminate uplink pilots in TDD massive MIMO, causing downlink precoding to favor the eavesdropper. It derives asymptotic secrecy expressions and transmission designs, finding closed-form single-antenna power policies and complete mitigation under certain channel-correlation orthogonality conditions.
Problem
Pilot-contamination attacks are insufficiently addressed in physical-layer security for TDD massive MIMO, where existing studies often assume perfect channel state information and omit channel training.
Method
The paper models a multi-antenna active eavesdropper, derives asymptotic secrecy rates for matched-filter precoding with artificial noise, and develops power-allocation and correlation-based transmission designs.
Results
Under channel-covariance orthogonality, the active eavesdropper’s secrecy-rate impact can be completely eliminated; for a single-antenna eavesdropper, optimal power allocation and minimum secure transmit power have closed-form expressions.
Takeaways & Limitations
Transmit-correlation diversity can be exploited to improve secrecy, while secure operation requires allocating power between the information signal and artificial noise rather than relying on naive matched-filter transmission.
Abstract
from arXiv · showhide
In this paper, we investigate secure and reliable transmission strategies for multi-cell multi-user massive multiple-input multiple-output (MIMO) systems with a multi-antenna active eavesdropper. We consider a time-division duplex system where uplink training is required and an active eavesdropper can attack the training phase to cause pilot contamination at the transmitter. This forces the precoder used in the subsequent downlink transmission phase to implicitly beamform towards the eavesdropper, thus increasing its received signal power. Assuming matched filter precoding and artificial noise (AN) generation at the transmitter, we derive an asymptotic achievable secrecy rate when the number of transmit antennas approaches infinity. For the case of a single-antenna active eavesdropper, we obtain a closed-form expression for the optimal power allocation policy for the transmit signal and the AN, and find the minimum transmit power required to ensure reliable secure communication. Furthermore, we show that the transmit antenna correlation diversity of the intended users and the eavesdropper can be exploited in order to improve the secrecy rate. In fact, under certain orthogonality conditions of the channel covariance matrices, the secrecy rate loss introduced by the eavesdropper can be completely mitigated.
I. INTRODUCTION
The paper addresses physical-layer security in TDD multi-cell multi-user massive MIMO when an active eavesdropper contaminates uplink pilots, and develops transmission strategies to preserve secrecy. It combines pilot-contamination attack modeling, asymptotic secrecy analysis, power allocation, and correlation-based spatial processing.
- Research gap: Existing physical-layer security studies commonly assume perfect legitimate-channel CSI and omit the TDD channel-training phase.The paper targets the resulting gap for active eavesdropping in correlated fading channels.
- Motivation: Pilot contamination is a serious secrecy threat because it can direct transmitter beamforming toward the eavesdropper and drive the achievable secrecy rate toward zero.This threat arises during uplink training, before downlink precoding based on the contaminated channel estimate.
- Contributions: The paper introduces a closed-form pilot contamination precoder that maximizes the desired user’s total average channel-estimation error variance.The optimal attack direction is associated with the maximum-eigenvalue eigenvector of the eavesdropper’s receive correlation matrix.
- Contributions: For matched-filter precoding with artificial noise, the paper derives an asymptotic achievable secrecy rate and uses it to design power allocation against the attack.The asymptotic expression applies as the number of transmit antennas tends to infinity.
- System and attack model: The system comprises multi-cell TDD massive MIMO with K single-antenna users per cell and a multi-antenna eavesdropper targeting one user’s private message.The active eavesdropper sends the target user’s pilot during uplink training, contaminating the BS channel estimate.
B. Downlink Data Transmission
The downlink design uses matched-filter precoding together with artificial noise while avoiding the matrix inversions required by conventional null-space processing. The resulting schemes address pilot-contamination secrecy loss through asymptotic scaling, power allocation, and low-complexity artificial-noise shaping.
- B. Downlink Data Transmission: The BS allocates fractions p and q of downlink power to the information signal and artificial noise, respectively.The design normalizes the total asymptotic transmit power through the information and AN components.
- B. Downlink Data Transmission: Matched-filter precoding is adopted to avoid the high implementation complexity of matrix inversion required by zero-forcing and MMSE precoding.The matched-filter vector is constructed from the estimated channel.
- B. Downlink Data Transmission: The artificial-noise shaping matrix uses an asymptotic null space rather than recomputing a channel-estimate null space through matrix inversion.This choice keeps implementation complexity low for large antenna arrays.
- B. Downlink Data Transmission: The received downlink signals at the intended user and eavesdropper include the precoded transmission, artificial noise, and Gaussian receiver noise.The downlink SNR is defined as γ = P/N0,d.
- B. Downlink Data Transmission: Even with a single-antenna eavesdropper and pilot power half that of the desired user, the MF design without artificial noise can yield zero secrecy rate.This example illustrates the vulnerability of allocating all power to matched-filter information transmission.
III. MASSIVE MIMO SIGNAL DESIGN FOR COMBATING THE PILOT CONTAMINATION ATTACK
This section develops an achievable secrecy-rate analysis and transmission strategies for MF precoding with artificial noise against an active eavesdropper. It gives a general asymptotic expression and specializes the power-allocation design to a single-antenna eavesdropper.
- Signal and secrecy-rate model: The achievable ergodic secrecy rate is formulated as the desired user’s achievable rate minus the eavesdropper’s capacity.The eavesdropper-capacity model uses a worst-case assumption in which it cancels all other intra-cell and inter-cell users’ signals.
- Asymptotic secrecy rate: The analysis derives an asymptotic achievable secrecy-rate expression for MF-AN transmission as the number of transmit antennas tends to infinity.The expression applies to arbitrary information-signal and artificial-noise power allocation parameters p and q.
- Power allocation: For arbitrary multi-antenna eavesdroppers, the optimal information-signal power fraction can be found by a one-dimensional numerical search over 0 ≤ p ≤ 1.For a single-antenna eavesdropper, the optimal p is available in closed form.
- Power allocation: Without artificial noise, the asymptotic secrecy rate decreases with increasing SNR above a threshold γ_th.This behavior occurs because contaminated channel estimates can make the precoder implicitly beamform the information signal toward the eavesdropper, whose capacity can then grow faster than the desired user’s rate.
- Power allocation: Artificial noise is therefore advantageous when pilot contamination lets the active eavesdropper benefit from increased transmit power.The transmitter can allocate part of its power to AN to degrade the eavesdropper’s ability to decode the intended signal.
B. NS Design
The NS design transmits information in the eavesdropper channel’s null space, eliminating pilot-contamination impact when user and eavesdropper correlation matrices are orthogonal. Its benefit depends on available null-space rank and channel conditions.
- B. NS Design: Under statistical orthogonality between user and eavesdropper channels, the secrecy rate equals the desired user’s achievable rate.Thus, the pilot contamination attack has no impact on secrecy rate in this condition.
- B. NS Design: The NS design projects information-carrying signals into the null space of the eavesdropper’s transmit correlation matrix.The construction uses eigenvectors associated with zero eigenvalues and applies the resulting projection during uplink training.
- B. NS Design: NS-design performance depends on the rank of the eavesdropper-channel null space.The null space is constructed from Nt − Tl zero-eigenvalue directions, where Tl is the eavesdropper correlation-matrix rank.
- B. NS Design: For i.i.d. fading, the eavesdropper null space does not exist, so the NS design is not applicable.The design is instead expected to help in highly correlated channels, under strong pilot contamination, and at high SNR.
- B. NS Design: MF-AN is expected to outperform NS in weakly correlated channels, under weak pilot contamination, and at low SNR.This motivates combining both designs according to their operating conditions.
C. Unified Design
The unified design combines MF-AN and NS transmission to exploit their complementary advantages. Its mixture weights are selected by numerically maximizing the secrecy rate.
- C. Unified Design: The unified design combines conventional MF-AN and NS transmission schemes.The construction is intended to exploit the advantages of both designs.
- C. Unified Design: The weights α and β satisfy α + β = 1 and represent the MF-AN and NS contributions, respectively.The optimal weights are obtained through a one-dimensional numerical search using secrecy rate as the objective.
IV. THE SINGLE-ANTENNA EAVESDROPPER CASE
For a single-antenna active eavesdropper, the paper develops closed-form power-allocation and secure-transmission conditions for MF-AN, including a threshold for choosing between MF-AN and NS.
- IV. THE SINGLE-ANTENNA EAVESDROPPER CASE: The single-antenna case derives closed-form MF-AN power allocation and the minimum transmit-signal power for secure transmission.It also derives a closed-form threshold for switching optimally between MF-AN and NS.
- IV. THE SINGLE-ANTENNA EAVESDROPPER CASE: The optimal power allocation p maximizes the asymptotic achievable secrecy rate for Ne = 1.The solution is specified through the paper’s theorem and the secrecy-rate function Rsec, asy(p).
- IV. THE SINGLE-ANTENNA EAVESDROPPER CASE: For Ne = 1, positive asymptotic secrecy requires the transmit-signal power to satisfy the condition given in Theorem 6.When a1 − a2 = 0, secure transmission is possible for any p if b1 − b2 > 0, and impossible for every p otherwise.
- IV. THE SINGLE-ANTENNA EAVESDROPPER CASE: The MF-AN-versus-NS comparison uses fixed-point equations involving γ and candidate threshold solutions γt,1 and γt,2.The power-allocation candidates are evaluated through the asymptotic secrecy-rate function.
- IV. THE SINGLE-ANTENNA EAVESDROPPER CASE: When β(γ) = 0, MF-AN has higher asymptotic secrecy rate than NS; when β(γ) = 1, NS is higher.The threshold comparison applies as Nt approaches infinity with Ne = 1.
B. Single-Cell Single-User Case
The single-cell single-user analysis identifies when positive secrecy is achievable under pilot contamination and shows how statistical channel structure can neutralize the attack.
- Secrecy condition: Theorem 8 gives a condition that must hold for positive asymptotic secrecy in the single-antenna-eavesdropper case.The condition is expressed through coefficients η1 and η2.
- Secrecy condition: If η1 < 0, secure communication cannot be achieved in the high-SNR regime because the required power fraction would exceed its feasible range.When η1 > 0, secure communication can instead be achieved for arbitrary p < 1 at high SNR.
- i.i.d. fading: Under i.i.d. fading, η1’s sign is determined by whether the legitimate-user received power P01β01 exceeds the eavesdropper’s pilot-related power PEβE.The equivalence is η1 ≷ 0 when P01β01 ≷ PEβE.
- Design implication: Consequently, the classical MF-AN design may fail under a sufficiently strong pilot contamination attack, motivating a new design.The paper contrasts this limitation with a design based on statistical channel structure.
- Correlation-based mitigation: When η1 = 0 and η2 > 0, secure communication is achievable regardless of pilot contamination power PE and SNR γ.Massive-MIMO channels’ low-rank transmit correlation can enable joint processing that projects user and eavesdropper channels into suitable null spaces.
- Correlation-based mitigation: The proposed null-space design transmits along statistical eigen-directions and jointly processes uplink estimation with downlink transmission.This differs from conventional null-space processing for perfect CSI.
V. NUMERICAL RESULTS
Numerical evaluations compare asymptotic and exact secrecy rates across SNR, power allocation, pilot contamination, precoding design, and eavesdropper antenna count.
- Simulation setup: The simulations use a 128-antenna uniform linear array with truncated-Laplacian channel power angle spectra.The antenna spacing is half a wavelength, and the angular spread is set to σ = π/2.
- MF-AN evaluation: The asymptotic secrecy rate closely estimates the exact rate for the MF-AN design across the evaluated SNR and power-allocation settings.Exact rates are obtained by Monte Carlo simulation.
- MF-AN evaluation: At SNR = 2 dB with Ne = 1, p < 0.15 is necessary for reliable communication; p = 0.16 yields no positive secrecy rate.At low SNR, larger information-signal power helps, whereas at higher SNR more AN power is needed.
- Design comparison: The unified design performs best across the considered SNR, pilot-power, and eavesdropper-antenna settings.Its secrecy rate barely decreases as Ne increases in the reported experiments.
- Design comparison: Naive MF precoding cannot achieve positive secrecy at moderate-to-high SNRs under pilot contamination despite the large transmit-antenna array.For weak attacks, MF-AN can outperform NS; stronger attacks cause serious MF-AN loss but barely affect NS.
- Summary of findings: The study reports closed-form MF-AN power allocation and minimum transmit-power results, with simulations confirming analytical accuracy and proposed-design effectiveness.A decision threshold is also provided for choosing between MF-AN and NS in the single-antenna-eavesdropper case.
APPENDIX A PROOF OF THEOREM 1
Appendix A derives the optimal pilot-contamination precoder by reducing the design to an eigenvector optimization problem.
- Optimization reduction: The proof rewrites the pilot-precoder constraints and objective into an equivalent optimization problem.The derivation proceeds through equations (76)–(78).
- Optimal solution: The optimal solution is p = √Ne ue, where ue is the eigenvector corresponding to the largest eigenvalue of R0E,R.This establishes the closed-form direction used by the pilot contamination precoder.
- Asymptotic evaluation: The proof then evaluates the desired-user and eavesdropper SINRs as Nt approaches infinity.The resulting asymptotic desired-user SINR is obtained after substituting the intermediate expressions.
- Asymptotic evaluation: The asymptotic secrecy expression follows by combining the derived SINR components and simplifying their ratio.The appendix explicitly connects the substitutions to the expression for SINR0m, asy.
APPENDIX C PROOF OF THEOREM 3
Appendix C analyzes the secrecy condition by reducing it to a quadratic inequality in SNR and characterizing its feasible interval.
- Secrecy inequality: The proof simplifies 1 + SINReve, asy and relates it to 1 + SINR0m, asy through the asymptotic parameters.The resulting expression is used to determine when the secrecy condition holds.
- Parameter signs: The parameters θm, θb,p, and ˜θe are established as nonnegative under the channel assumptions.The receive correlation matrix is Hermitian positive semidefinite, supporting the sign argument.
- Root characterization: The resulting quadratic is nonnegative between its two roots and negative outside that interval.Because one root is non-positive, the proof then focuses on the feasible nonnegative-SNR region.
- Threshold: The SNR threshold is obtained by setting γth equal to the larger root γ2.This completes the proof of the threshold condition in Theorem 3.
APPENDIX D PROOF OF THEOREM 4
The appendix derives Theorem 4 through asymptotic secrecy-rate expressions and an algebraic optimization over transmit power. It also identifies the feasible region for a related theorem and gives the NS-design secrecy rate by an analogous derivation.
- Maximizing the asymptotic secrecy rate is reduced to maximizing a ratio involving 1 + SINR0m, asy and 1 + SINReve, asy.
- Differentiating the resulting quadratic-rational expression with respect to p and setting the derivative to zero yields the solution.
- The MF-AN design’s optimal asymptotic secrecy rate follows from Theorems 2 and 5.
- The asymptotic secrecy rate for the NS design is obtained using an approach similar to the preceding derivation.
- Theorem 7 follows by determining the feasible region of equation (123).
APPENDIX G PROOF OF THEOREM 8
The appendix proves Theorem 8 by specializing the asymptotic SINR expressions to a single-user, single-antenna-eavesdropper setting. Secure communication is then characterized through an SINR inequality whose positive denominators permit simplification to equation (69).
- For L = 0, K = 1, Ne = 1, and Nt →∞, the intended-user asymptotic SINR reduces to equation (124).
- Secure communication requires SINR01, asy > SINReve, asy, which is transformed into equation (126).
- The transmit correlation matrices are Hermitian positive-semidefinite, supporting the subsequent matrix-based inequality steps.
- The denominators in both terms of equation (126) are positive, allowing the inequality to be simplified without changing its direction.
- Simplifying equation (126) produces equation (69), completing the proof of Theorem 8.