Source-linked AI summary
A Comprehensive Survey on Radio Frequency (RF) Fingerprinting: Traditional Approaches, Deep Learning, and Open Challenges
Anu Jagannath, Jithin Jagannath, Prem Sagar Pattanshetty Vasanth Kumar
TL;DR
The paper addresses the need for comprehensive RF-fingerprinting knowledge as massive IoT deployments expand wireless threat surfaces and existing surveys remain narrow. It systematically surveys traditional and deep-learning approaches, applications, datasets, and research challenges, reporting representative identification results while highlighting dataset and simulation-to-reality limitations.
Problem
Massive, diverse IoT deployments enlarge wireless threat surfaces, while existing RF-fingerprinting surveys provide limited coverage of methods, applications, datasets, and challenges.
Method
The article systematically reviews RF-fingerprinting approaches across traditional and deep-learning methods, applications, datasets, and open research directions.
Results
Reported studies include up to 99% accuracy for detecting new UAVs, 97.21% accuracy for four-device classification with a DNN, and 96.6% for eight-device classification with a DNN.
Takeaways & Limitations
RF fingerprinting is presented as a candidate technology for device authentication, access control, intrusion detection, and related wireless applications.
Takeaways & Limitations
The survey identifies limited access to standardized, large-scale real-world datasets and a simulation-to-reality gap that hinders generalization to actual radio emissions.
Abstract
from arXiv · showhide
Fifth generation (5G) network and beyond envision massive Internet of Things (IoT) rollout to support disruptive applications such as extended reality (XR), augmented/virtual reality (AR/VR), industrial automation, autonomous driving, and smart everything which brings together massive and diverse IoT devices occupying the radio frequency (RF) spectrum. Along with the spectrum crunch and throughput challenges, such a massive scale of wireless devices exposes unprecedented threat surfaces. RF fingerprinting is heralded as a candidate technology that can be combined with cryptographic and zero-trust security measures to ensure data privacy, confidentiality, and integrity in wireless networks. Motivated by the relevance of this subject in the future communication networks, in this work, we present a comprehensive survey of RF fingerprinting approaches ranging from a traditional view to the most recent deep learning (DL)-based algorithms. Existing surveys have mostly focused on a constrained presentation of the wireless fingerprinting approaches, however, many aspects remain untold. In this work, however, we mitigate this by addressing every aspect - background on signal intelligence (SIGINT), applications, relevant DL algorithms, systematic literature review of RF fingerprinting techniques spanning the past two decades, discussion on datasets, and potential research avenues - necessary to elucidate this topic to the reader in an encyclopedic manner.
I. INTRODUCTION
RF fingerprinting extracts transmitter hardware characteristics embedded in waveforms to identify devices, supporting authentication and access control in increasingly dense beyond-5G networks. The article surveys RF signal intelligence, applications, traditional and deep-learning methods, datasets, and open challenges.
- Background: RF fingerprinting extracts unintentionally embedded hardware characteristics from transmitted waveforms to identify transmitter hardware using a passive receiver.It is defined through feature identification, feature extraction, and device identification.
- Motivation: Ultra-dense beyond-5G connectivity increases network threat surfaces and makes security and privacy crucial for emerging wireless technologies.The expected device density is 10× that of 5G, while technologies such as UM-MIMO, VLC, and THz introduce additional security challenges.
- Background: Device-specific hardware imperfections can provide location-independent fingerprint features, whereas vendor-specific features may vary after firmware or software upgrades.Relevant imperfections include phase offset and clock skew from components such as power amplifiers, filters, and clocks.
- Scope and gap: The survey addresses a gap in comprehensive coverage of RF fingerprinting evolution from principled algorithms to supervised deep learning.It also places fingerprinting within broader RF signal intelligence, including modulation recognition and wireless protocol classification.
- Scope and contributions: The article organizes background, applications, traditional and deep-learning methods, datasets, and future research directions into an encyclopedic survey.Its stated scope includes categorized literature review, application areas, relevant deep-learning techniques, and open challenges.
A. Automatic modulation classification
The article situates automatic modulation classification within RF signal intelligence and traces its evolution from likelihood- and feature-based methods toward machine learning and deep learning. It also distinguishes related recognition tasks and connects RF identification with authentication, tracking, and intrusion detection.
- Traditional approaches: AMC approaches are broadly divided into likelihood-based and feature-based methods, with likelihood methods offering Bayesian optimality but often requiring substantial computation.Feature-based classifiers can provide near-optimal performance with lower computational demands.
- Evolution toward deep learning: Supervised AMC initially used engineered features with SVMs and ANNs before CNNs increasingly exploited their stronger feature-extraction capability.Later approaches also classified modulation or signal types from raw IQ samples.
- Related signal-intelligence tasks: Wireless signal recognition identifies the wireless standard or protocol that generated an RF waveform, including standards such as WiFi, Zigbee, and Bluetooth.One seven-class system achieved 93% accuracy but required a high-SNR regime.
- Identification and security applications: RF device identification supports authentication and authorization by distinguishing legitimate devices from impostors, including replay or imitation attackers.The paper distinguishes identification, authentication, and authorization as separate stages in access management.
- Tracking and intrusion detection: RF fingerprints can also support implicit tracking and localization by overhearing communication signals, while creating privacy risks if illegitimate entities identify and track devices.Intrusion-detection systems can register approved fingerprints and alert operators to unauthorized transmissions.
D. Application Domains
RF fingerprinting is presented across 6G application domains and demonstrated through traditional radiometric and modulation- or spectral-feature methods. Reported examples span healthcare, smart grids, device identification, RFID, and security-sensitive wireless systems.
- Application context: Beyond-5G applications make user and asset security and privacy paramount, motivating RF fingerprinting across envisioned 6G domains.The surveyed applications include immersive services and other revolutionary communication scenarios.
- Healthcare and infrastructure: Intelligent telehealth and IoMT are presented as 6G application areas involving real-time health monitoring, hospital services, analytics, and connected medical communications.The passage also identifies smart grids as supporting dense IoT connectivity and real-time anomaly detection.
- PARADIS: PARADIS identifies radiometric device identities by exploiting minor transmitter-hardware variations in transmitted signals.Its features include frequency error, SYNC correlation, IQ offset, magnitude error, and phase error, averaged across multiple frames.
- PARADIS: 0.0034% error rate was achieved by PARADIS with SVMs when classifying 138 identical 802.11 NICs; k-NN produced a 3% error rate.The evaluation used 138 Atheros NICs configured as 802.11b access points on the ORBIT indoor testbed.
- RFID fingerprinting: RFID identification methods extract fingerprints from modulation-shape and spectral features of signals emitted by transponders under reader excitation.The experimental setup included 50 JCOP NXP 4.1 smart cards and 8 electronic passports, using standard, varied-frequency, burst, and frequency-sweep captures.
- RFID fingerprinting: 0% error rate was reported for classifying signals from 8 e-passports and 50 JCOP NXP cards into three classes using modulation and spectral techniques.Spectral features used modified PCA, while matching employed standardized Euclidean and Mahalanobis distances.
4) Weighted Voting-Based Classification of Modulation Domain Signals:
Modulation-domain RF fingerprinting identifies transmitters from imperfections in received signal constellations and related physical characteristics. Reviewed methods use weighted classifier ensembles, constellation-error features, statistical RF-DNA features, and transient processing, with reported accuracies reaching 99.7%.
- Weighted voting: Weighted voting combines 14 classifiers based on frequency, magnitude, phase, distance-vector, and IQ-origin-offset differences to identify six WARP radio cards.The classifiers are trained using the first 200 frames of 1844 random QPSK symbols from each board.
- Weighted voting: 88% average accuracy is achieved by the weighted-voting classifier for detecting six radio cards.
- Constellation-error features: Constellation-error fingerprints use 41 SDA-extracted features from synchronized burst QPSK signals collected from seven TDMA satellite terminals.The features represent errors between received and ideal constellations.
- Constellation-error features: Accuracy exceeds 95% when the SDA feature-extraction bin size is greater than 12.
- RF-DNA features: RF-DNA methods classify UWB noise-radar emitters using time-domain moments together with normalized PSD and discrete Gabor-transform features.The reviewed classifiers include MDA/ML and GRLVQI.
- Transient-based methods: Transient-based fingerprinting detects turn-on transients, extracts distinctive features, and classifies devices, with phase-based detection proposed for gradual transient gradients.
1) Fast Fourier Transform (FFT)-based Fisher features:
FFT-based Fisher features and related transient-domain methods extract device-specific information from radio turn-on behavior. Reported evaluations show very high identification accuracy, robustness to several conditions, and vulnerabilities to polarization changes, limited templates, and jamming.
- FFT-based Fisher features: FFT-based Fisher features identify 50 COTS Tmote Sky sensors with accuracy higher than 99.5%.The evaluation uses over 600 IEEE 802.15.4 samples from nodes sharing the same manufacturer signature.
- FFT-based Fisher features: The system is robust against distance, multipath propagation, and voltage changes, but polarization changes reduce recognition accuracy.
- Security evaluation: Few signals used to build the fingerprint template can leave the system vulnerable to hill-climbing impersonation attacks.Jamming-based denial-of-service also prevents device recognition because the received signal superposes original and jamming signals.
- Transient features: HHT-based SEI extracts time-frequency-energy-distribution features, reduces dimensionality with PCA, and classifies eight GSM phones using an SVM.The feature set includes energy, duration, and time- and frequency-distribution statistics.
- Transient features: Bluetooth transient fingerprints use energy-envelope features and a 3-nearest-neighbor classifier trained from seven phone transceivers.Features include normalized-curve area, transient duration, maximum slope, kurtosis, skewness, and variance.
D. Wavelet-based approach
Wavelet-domain RF fingerprinting applies DT-CWT features to non-transient 802.11a preambles and evaluates performance across signal-to-noise conditions. It matches time-domain methods at high SNR but provides an advantage at lower SNR.
- Wavelet-based approach: Wavelet-domain fingerprints use DT-CWT features from non-transient 802.11a preambles and Fisher-based MDA/ML classification.The evaluation considers channel SNR, burst-detection error, and mismatched training and classification SNRs.
- DT-CWT: DT-CWT decomposes signals into time- and frequency-localized wavelets while addressing the shift-invariance limitation of DWT.The transform uses two real-valued filter banks, with the second corresponding to Hilbert-transform counterparts.
- Feature construction: Wavelet-domain fingerprints contain 135 features, compared with 27 features for the corresponding time-domain fingerprints.
- Performance comparison: 80% accuracy is achieved at SNR ≈11 dB with wavelet-domain fingerprinting, approximately 7 dB better than equivalent time-domain fingerprinting.
- Performance comparison: The two techniques perform identically for SNR ≥25 dB, while wavelet-domain fingerprinting is superior for −2 < SNR < 24 dB.
- Performance comparison: With equal 27-feature dimensionality, wavelet-domain fingerprinting outperforms time-domain fingerprinting only for 0 < SNR < 20 dB, by approximately 2 dB.This indicates additional information from DT-CWT features contributes to the observed advantage.
2) Dynamic wavelet:
Traditional RF fingerprinting methods use wavelet, frequency-domain, entropy, and composite fingerprints with classical classifiers to identify transmitters, devices, or locations. Their evaluations span RFID tags, micro-UAV controllers, identical USRPs, radios, IoT devices, and WiFi access points.
- Dynamic wavelet: 146 RFID tags are fingerprinted using dynamic wavelet processing, image-based feature extraction, wavelet packet decomposition, and supervised classifiers.The combined feature vector includes statistical and correlation features and is evaluated with LDC, QDC, k-NN, and SVM classifiers.
- Wavelet domain-based Bayes approach: A wavelet-domain Bayes method detects micro-UAV signals and extracts statistical fingerprints from energy transients for controller classification.The pipeline uses three-stage wavelet decomposition, spectrogram-based energy-transient detection, NCA dimensionality reduction, and classifiers including k-NN, DA, SVM, and NN.
- Steady State Frequency Domain Approach: 97% accuracy at 30 dB SNR and 66% at 0 dB SNR identify eight identical USRP transmitters using frequency-domain characteristics and k-NN.The evaluation uses UMTS RACH preambles captured from eight individually measured USRPs.
- Permutation entropy: Multidimensional permutation entropy forms envelope-based fingerprint vectors that are classified with an RBF-kernel SVM.The method is evaluated on data collected from three AKDS700 radios.
- Received Signal Strength: 96.5% probability of zero positioning error and a 0.14m average localization error are achieved by fusing RSS, SSD, and HLF fingerprints with multiple classifiers.LDA selects 12 features from 49, retaining more than 95% of the information.
4) Permutation entropy and Dispersion entropy:
Entropy-based traditional fingerprinting augments statistical signal features with permutation and dispersion entropy, while neural-network methods learn composite mappings from inputs to outputs through layered transformations.
- Permutation entropy and Dispersion entropy: PE and DE features combined with statistical features improve classifier accuracy by 24% to 30% over statistical features alone for nine IoT devices.The evaluated devices are nRF24LU1+ units transmitting fixed MySensors payloads.
- Feedforward Neural Networks: Feedforward neural networks map an input vector x to an output y through a composition of layer functions without internal feedback connections.An N-layer FNN is represented as y = f_N(f_N−1(···f_1(x))).
- Feedforward Neural Networks: FNN training learns network parameters Γ* consisting of layer weight matrices and bias vectors to approximate a target composite function from available samples.The parameter set is Γ = {W1,W2,W3,b1,b2,b3} for the illustrated three-layer network.
2) Convolutional Neural Networks:
CNNs extract spatially local features through convolution and reduce representation size through pooling, whereas RNNs model temporal dependencies with recurrent hidden states for sequential RF data.
- Convolutional Neural Networks: CNNs convolve an input tensor with depth-matched kernels to produce feature maps whose dimensions depend on kernels, stride, padding, and input size.The convolution operation performs efficient feature extraction and reduces data dimension and network parameters.
- Convolutional Neural Networks: CNN neurons use sparse local connectivity and receptive fields, responding primarily to spatially local input patterns before features reach regression or classification outputs.Pooling further reduces dimensionality and is illustrated through max and mean pooling operations.
- Convolutional Neural Networks: Pooling produces an output volume determined by input dimensions, pooling dimensions, stride, and unchanged depth, while imparting translation invariance.Small input shifts generally leave the pooled output largely unaffected.
- Convolutional Neural Networks: CNN efficiency and trainability derive from parameter sharing, sparse connectivity, and dimensionality reduction.These properties distinguish CNNs from fully connected feedforward networks in the tutorial’s discussion.
- Recurrent Neural Networks: RNNs capture temporal dependencies in sequential data by using recurrent connections and internal memory states.They operate on sequence vectors x_t and map them to output sequence vectors y_t through hidden states.
- Recurrent Neural Networks: Bidirectional RNNs combine past-state and future-state processing, extending recurrent modeling beyond architectures that use only past hidden states.The paper identifies time-series RF applications including spectrum forecasting and spectrum usage analysis.
4) Generative Adversarial Networks (GANs):
GANs use competing generator and discriminator networks to create and distinguish synthetic samples. In the reviewed RF fingerprinting work, CNN-based ORACLE classification achieves high accuracy, while transmitter-side impairments are explored to improve robustness under dynamic channels.
- Generative Adversarial Networks (GANs): GANs train a generator to deceive a discriminator while the discriminator distinguishes dataset samples from generated samples.The discriminator is updated with real and fake samples before the generator is updated to produce more deceptive samples.
- ORACLE: ORACLE is a CNN framework for RF fingerprinting evaluated on COTS WiFi devices and 16-bit-similar USRP X310 radios.The study reports evaluations involving more than 100 COTS WiFi devices and 16-bit-similar SDRs.
- ORACLE: The ORACLE study examines hardware-driven IQ variation under static and dynamic channel environments.The focused impairments include IQ imbalance and DC offset, with receiver channel estimation informing transmitter-side modifications in dynamic channels.
- ORACLE: 99% median classification accuracy is achieved for up to 100 devices, decreasing to 96% for 140 devices, while 16 X310 radios reach close to 98.6%.The architecture uses raw IQ input, convolutional and fully connected layers, ReLU activations, and a final softmax classifier.
- Limitations: Controlled transmitter impairments can improve differentiability under dynamic channels but may be unavailable in commercial and tactical applications.The review also questions whether deliberately introduced impairments represent an intrinsic RF fingerprint or an artificial device tag.
2) Unmanned Aerial Vehicles With Non-Standard Transmitter Waveforms:
The reviewed UAV and emitter-identification studies use deep neural classifiers with specialized signal representations and ensemble or augmentation strategies. Their results show strong gains in controlled settings, while performance remains sensitive to channel variation, motion, signal quality, and representation size.
- Unmanned Aerial Vehicles With Non-Standard Transmitter Waveforms: A UAV dataset contains signals from seven identical DJI M100 UAVs recorded at four receiver distances in an RF anechoic chamber.Signals were collected with a USRP X310 and UBX 160 daughterboard.
- UAV classification: AlexNet1D and ResNet1D classify UAV signals using modified one-dimensional CNN architectures.AlexNet1D uses stacked one-dimensional convolutional blocks, max pooling, and fully connected layers.
- UAV classification: 50% accuracy occurs when models trained on the first three UAV bursts are tested on burst 4, reflecting sensitivity to hovering-related channel variation and motion.A 12-network score-aggregation scheme raises accuracy from 50% to 91% in the reported evaluation.
- UAV classification: Data augmentation with normalized batches and multi-tap complex FIR filtering improves the multi-classifier accuracy to up to 95%.The same approach reports 99% accuracy for detecting UAVs absent from the training dataset, with longer training and testing but no model-size increase compared with a single ResNet1D.
- Bispectrum-based identification: Bispectrum-CNN identification reaches 75% accuracy for five USRPs, 85% for ten modeled emitters, and 87% for five modeled emitters.The method estimates third-order cumulant bispectra, compresses them, and classifies the reduced representation with a CNN.
- Differential Constellation Trace Figure (DCTF): DCTF-CNN performance depends on image size and SNR, reaching 93.8% at 15 dB and 99.1% at 30 dB with 65x65 DCTF images.Smaller images blur features, whereas larger images require more samples and higher complexity.
5) RF signal spectrum:
RF-spectrum fingerprinting studies apply image-based and one-dimensional CNNs to large and varied transmitter populations. Across evaluations, multi-burst processing improves accuracy, while environmental, channel, and signal-to-noise differences remain important sources of performance variation.
- RF signal spectrum: STFT converts time-domain signals into time-frequency RF spectra that a modified VGG-16 classifies into transmitter labels.The modified network adds batch normalization after convolutional layers and dropout before later processing.
- A Massive Experimental Study: The DARPA study analyzes 400 GB of WiFi and ADS-B waveforms from 10,000 devices using modified AlexNet and ResNet-50-1D architectures.Its WiFi and ADS-B subsets contain 5,117 and 5,000 emitters, respectively.
- A Massive Experimental Study: The large-scale evaluation reports graceful scaling with device population, higher accuracy for multiburst tasks, and improved accuracy with more training transmissions.Environmental and channel conditions affect predictions, and ADS-B classification is reported as easier than WiFi classification.
- Dilated Causal Convolutional Model: The ADCC model combines dilated causal convolutional residual blocks with traditional convolution and pooling blocks for fingerprint classification.Its evaluation uses the same broad Task 1 through Task 4 framework as the large-scale study.
- Dilated Causal Convolutional Model: ADCC accuracy drops drastically when training and validation channels differ, while reducing training size from 501 to 313 causes only a 2% drop.Multiburst accuracy exceeds single-burst accuracy, and ADS-B accuracy is higher than WiFi accuracy in the reported evaluations.
- Multi-burst processing: Multi-burst inference combines class-probability vectors from multiple bursts of the same unknown device and reports accuracy above 95% across WiFi and ADS-B.The approach uses repeated bursts to reduce noise before deriving a final class prediction.
C. Generative Adversarial Networks
The surveyed adversarial-learning approaches use GANs, CNNs, and DNNs to identify RF transmitters and classify UAV signals. Reported results include 99.9% trusted-transmitter identification and greater than 95% UAV classification at 5 dB SNR.
- Classification based on Auxiliary Classifier Wasserstein GANs: 95%+ accuracy was achieved for classifying four UAV types and WiFi signals at 5 dB SNR using AC-WGANs with PCA.The system outperformed standard SVM and AC-GAN models and supported real-time classification over 10–400 m.
- GANs with Adversarial learning: 99.9% accuracy was reported for identifying eight trusted transmitters with the proposed GAN model.The GAN discriminator distinguishes trusted-transmitter signals from generated signals before classification.
- GANs with Adversarial learning: 97.21% and 96.6% accuracy were obtained by the DNN for four and eight USRP devices, respectively.The corresponding CNN accuracies were 89.07% and 81.59%; GAN-based screening improved DNN accuracy to 99.9%.
- Energy spectrum based approach: Transient-based fingerprinting extracts energy-spectrum features from detected signal transients and classifies devices with a probabilistic neural network.The method uses Bayesian transient detection, spectral coefficients, and Bayes-rule classification.
- Energy spectrum based approach: 90% and 97.91% accuracy were reported for eight IEEE 802.11b WiFi devices at 0 dB and 25 dB, respectively.The evaluation used 100 transmissions from each device.
2) Effect of Sampling Rate on Transient-based fingerprinting:
The section highlights attentional and hybrid architectures for RF and Bluetooth fingerprinting, while identifying dataset availability and standardization as major practical challenges. The reviewed Bluetooth model reduced computational cost while retaining emitter-identification performance.
- Attentional architectures: A cross-domain attentional architecture extracts spatio-temporal, temporal, and time-frequency features from raw IQ samples.It combines 1D/2D CNNs, GRUs, and STFT processing for emitter and protocol recognition.
- Attentional learning for Bluetooth fingerprinting: 16.9× fewer FLOPs and 7.5× fewer trainable parameters were reported for a scalable CNN-GRU Bluetooth model.The architecture processed frequency-hopping Bluetooth waveforms and achieved up to 91% accuracy for 10 COTS emitters.
- Open RF fingerprinting datasets: RF research lacks diverse, large-scale, uniform datasets that integrate readily with Keras, PyTorch, and TensorFlow.Recently released modulation and protocol datasets are not yet integrated with these frameworks because common organization standards are lacking.
- Open RF fingerprinting datasets: Bluetooth recordings from COTS smartphones were collected across different makes, models, and sampling rates over several months.The dataset reflects the observation that hardware-impairment fingerprints do not vary significantly over short periods.
7) Exposing the Fingerprint Dataset:
The survey catalogs open RF fingerprinting datasets and frames dataset realism, receiver effects, spoofing, multipath, and multiple-emitter operation as open challenges. It also reports that SigMF-compliant synthetic datasets integrate more easily with AI/ML frameworks than several real-world datasets.
- Open RF fingerprinting datasets: The survey summarizes open datasets spanning WiFi SDRs, UAVs, aircraft ADS-B emissions, and other wireless emitters.Table VI is presented to contrast distinguishing dataset features.
- Open RF fingerprinting datasets: SigMF-compliant synthetic datasets integrate more easily with AI/ML frameworks, whereas other real-world datasets require specific import scripts.The comparison covers datasets and – alongside other discussed real-world datasets.
- Research challenges and future directions: Receiver phase noise, clock offsets, filter distortions, IQ imbalance, sampling rate, bandwidth, antenna orientation, and polarization can alter fingerprint extraction.Higher sampling rates can retain side-lobe fingerprint features but also increase noise.
- Research challenges and future directions: Broadcast wireless emissions remain susceptible to identity spoofing, while passive listeners can build datasets for cognitive RFFS attacks.The survey identifies fingerprint obfuscation and stronger defenses as open research problems.
- Research challenges and future directions: Most fingerprinting studies assume one active emitter, leaving separation of multiple emitter signatures from signal clutter as a realistic open challenge.Multipath can also distort PSD side lobes carrying identity information, and receiver equalization remains unresolved.
- Research challenges and future directions: Synthetic-data training generalizes poorly to actual radio emissions when hardware and fading assumptions differ from real conditions.This simulation-reality gap arises from differences between modeled transmitter imperfections and environmental effects and their actual counterparts.