Source-linked AI summary

CSI-RFF: Leveraging Micro-Signals on CSI for RF Fingerprinting of Commodity WiFi

Ruiqi Kong, He Chen

arXiv:2602.22738v1eess.SP

TL;DR

CSI-RFF addresses the difficulty of extracting stable RF fingerprints from CSI when hardware and wireless-channel distortions are intertwined. It uses micro-CSI and a signal-space extraction method for LoS conditions, achieving near-99% attack detection with 0% false alarms while revealing scope limits under NLoS conditions.

  • Problem

    CSI-based RF fingerprinting must separate subtle hardware distortions from changing wireless-channel distortions, while conventional physical-layer sampling often requires expensive instruments unavailable in COTS systems.

  • Method

    CSI-RFF uses micro-signals in CSI as fingerprints, extracts them with a signal-space method under LoS, averages CSI measurements to suppress noise, and normalizes fingerprints.

  • Results

    Close to 99% average attack detection rate with 0% false alarm rate was achieved across static and mobile conditions using 20 CSI measurements per fingerprint.

  • Takeaways & Limitations

    Micro-CSI provides a candidate device-specific fingerprint for open-set authentication of WiFi 4/5/6 NICs and mobile robots in the evaluated settings.

  • Takeaways & Limitations

    The approach is primarily demonstrated in LoS scenarios, with performance expected to decline under NLoS conditions because multipath interference reduces distinct channel taps for extraction.

Abstract

from arXiv · show

This paper introduces CSI-RFF, a new framework that leverages micro-signals embedded within Channel State Information (CSI) curves to realize Radio-Frequency Fingerprinting of commodity off-the-shelf (COTS) WiFi devices for open-set authentication. The micro-signals that serve as RF fingerprints are termed ``micro-CSI''. Through experimentation, we have found that the presence of micro-CSI can primarily be attributed to imperfections in the RF circuitry. Furthermore, this characteristic signal is detectable in WiFi 4/5/6 network interface cards (NICs). We have conducted further experiments to determine the most effective CSI collection configurations to stabilize micro-CSI. Yet, extracting micro-CSI for authentication purposes poses a significant challenge. This complexity arises from the fact that CSI measurements inherently include both micro-CSI and the distortions introduced by wireless channels. These two elements are intricately intertwined, making their separation non-trivial. To tackle this challenge, we have developed a signal space-based extraction technique for line-of-sight (LoS) scenarios, which can effectively separate the distortions caused by wireless channels and micro-CSI. Over the course of our comprehensive CSI data collection period extending beyond one year, we found that the extracted micro-CSI displays unique characteristics specific to each WiFi device and remains invariant over time. This establishes micro-CSI as a suitable candidate for device fingerprinting. Finally, we conduct a case study focusing on area access control for mobile robots. Our experimental results demonstrate that the micro-CSI-based authentication algorithm can achieve an average attack detection rate close to 99% with a false alarm rate of 0% in both static and mobile conditions when using 20 CSI measurements to construct one fingerprint.

I. INTRODUCTION

CSI-RFF uses micro-signals embedded in CSI curves as RF fingerprints for authenticating COTS WiFi devices. The framework attributes micro-CSI mainly to RF-circuit imperfections, extracts it under LoS conditions, and demonstrates near-99% attack detection with 0% false alarms.

  • CSI-based RF fingerprinting is difficult because hardware and changing wireless-channel distortions are entangled, while subtle RF distortions can be degraded by noise.
  • CSI-RFF introduces micro-CSI, the micro-signals embedded in CSI curves, as fingerprints for COTS WiFi device authentication.
  • Experiments suggest micro-CSI primarily originates from RF-circuit imperfections and appears in all tested WiFi 4/5/6 NICs.
  • The framework extracts micro-CSI by exploiting signal-space properties to disentangle small-scale hardware signals from wireless-channel distortions under strong LoS conditions.
  • Close to 99% average attack detection rate and 0% false alarm rate were achieved across static and mobile conditions in tests of 15 COTS WiFi NICs.

II. RELATED WORK

Prior RF fingerprinting often requires dedicated physical-layer sampling instruments, whereas CSI-based approaches use measurements available from commodity WiFi devices. The paper motivates micro-CSI by observing repeatable signals after noise suppression and linking them to hardware distortions.

  • Existing RF fingerprinting commonly relies on physical-layer samples collected with expensive instruments, limiting direct use in COTS systems.
  • CSI contains both wireless-channel distortions and RF-circuit distortions because hardware alters reference and received sequences during transmission and reception.
  • Micro-signals appear across measurements collected at different times and positions, although they look random at single-measurement granularity.
  • Averaging replicate CSI measurements suppresses noise, after which micro-CSI becomes relatively stable and suitable as a WiFi device fingerprint.

IV. MICRO-CSI EXTRACTION

The extraction design selects acquisition configurations that preserve distinct micro-CSI and accounts for receiver-chain effects. Single-antenna transmission and multiple receiver chains support stable collection across environments.

  • Reliable fingerprint extraction must address hardware and fluctuating-channel distortions in CSI measurements and preserve fingerprint properties during acquisition.
  • Multiple transmitter chains can mix non-orthogonal fingerprints, so the system uses a single-antenna transmitter for more stable and distinct micro-CSI.
  • Receiver chains of the same device introduce insignificant micro-CSI differences, allowing SIMO collection to gather CSI from multiple receiver chains.

B. ACK CSI Toolkit

The framework models CSI as a mixture of channel response, hardware-induced micro-CSI, and noise, then uses signal-space structure under strong LoS to estimate and remove the channel component. Element-wise division yields an extracted, channel-independent micro-CSI estimate.

  • CSI acquisition: The CSI estimation algorithm used by the framework is least squares, and the SDR setup collects I/Q samples for CSI reports from different transmitters.
  • CSI model: CSI measurements combine wireless-channel information, hardware-induced micro-CSI, and noise, making channel-independent fingerprint construction non-trivial.
  • Signal-space extraction: The signal-space method exploits channel sparsity so micro-CSI in unoccupied time-domain dimensions can be separated from channel information under strong LoS.
  • Signal-space extraction: The method estimates the frequency-domain channel with limited channel taps and then divides the CSI measurement element-wise by the estimated channel.
  • Signal-space extraction: The extracted micro-CSI is determined by device-specific hardware distortions and is independent of the wireless channel.

V. MICRO-CSI-BASED RF FINGERPRINTING

Constructing micro-CSI-based RF fingerprints is difficult because RF distortions in CSI can be weak and contaminated by noise, requiring robustness evaluation and a fingerprint matcher.

  • Micro-CSI fingerprint construction must account for weak RF distortions and noise contamination.

A. Fingerprint Construction

The fingerprint construction pipeline aggregates micro-CSIs, removes abnormal observations and outliers, suppresses noise, and normalizes the resulting fingerprint.

  • Each fingerprint aggregates micro-CSIs from Ncsi CSI measurements and Nrx receiver chains, yielding |Nm| = Nrx × Ncsi.
  • Outlier Elimination: Z-score filtering removes unusually large or small micro-CSI observations separately for each subcarrier.The method retains observations within the selected standardized threshold using subcarrier-specific sample statistics.
  • The remaining denoised fingerprint is normalized with a Z-score to improve stability across subcarriers.

B. Evaluations of Fingerprint Robustness

Experiments evaluate whether micro-CSI fingerprints are unique across NICs, stable over time, and resistant to noise under different CSI collection conditions.

  • Device Uniqueness: Fingerprints from eight NICs remain distinguishable across brands, models, and even devices of the same model.Different-model similarities are small, while same-model fingerprints are more similar but remain distinguishable.
  • Time Invariance: After a 14-month gap, fingerprints remain stable, with Z-score normalization improving amplitude-domain stability.The evaluation used two Realtek RTL8812BU NICs and averaged 50 micro-CSIs per fingerprint.
  • Noise Resistance: The required Ncsi stays at or below 10 in the best-case scenario and below 25 in the worst-case scenario across evaluated distances.The best case is RTL8812BU and the worst case is ESP32.

C. Fingerprint Matcher

CSI-RFF uses a fingerprint matcher to compare an arriving device's fingerprint with stored legitimate fingerprints and support rogue-device detection.

  • The fingerprint matcher compares a pending device against legitimate fingerprints stored in a library.
  • The study evaluates IForest, LOF, OCSVM, DBSCAN, and KNN for rogue-device detection.
  • KNN Fingerprint Matcher: The KNN matcher calculates Manhattan distances between a denoised, normalized fingerprint and library fingerprints for the claimed identity.

VI. A ROBOTIC USE CASE

The robotic use case applies micro-CSI-based RF fingerprints to authenticate mobile robots for restricted-area access. This addresses the difficulty of identifying non-biological robots with traditional biometric measures.

  • CSI-RFF targets restricted areas such as hazardous-material storage, research laboratories, and equipment rooms.
  • AMRs require alternative identity-verification methods because traditional biometric measures are difficult to apply to similar-looking, non-biological robots.
  • The framework uses WiFi-module micro-CSI fingerprints to establish and verify robot identity for area access control.

A. Mobility Study

The mobility study evaluates whether robot motion affects micro-CSI fingerprints and describes the indoor robot-authentication setup. The authors attribute the observed mobility robustness to channel coherence exceeding CSI-training transmission time.

  • Mobility impact: Robot mobility can introduce Doppler shifts that may affect construction of micro-CSI-based fingerprints.
  • Mobility impact: The experiment moved an AgileX Scout Mini robot from 3m to 2m at speeds of 0, 0.5, 1, and 1.5m/s.
  • Mobility impact: The channel coherence time greatly exceeds training-symbol transmission time, rendering Doppler-induced shifts inconsequential for CSI estimation.
  • Authentication setup: CSI-RFF uses request-response access control: a robot requests access, the controller collects ACK-based CSI, and the system processes the resulting fingerprint.
  • Authentication setup: The evaluation used 15 WiFi NICs from three manufacturers in two indoor rooms with static and mobile collection conditions.
  • Authentication setup: Experiments used 2.4GHz, 20MHz-bandwidth 802.11n operation, with WiFi 5 and 6 devices configured on the 2.4GHz band.

D. Open-Set Authentication Performance

CSI-RFF evaluates open-set authentication using attack detection rate and false alarm rate across static and mobile conditions. It achieves high detection with zero false alarms, including across environmental changes and device mobility.

  • The evaluation defines ADR as rogue-device detection probability and FAR as the probability of rejecting a legitimate device.
  • Static conditions: Static testing used each of 15 NICs as the legitimate device while the remaining 14 NICs acted as attackers across rooms.
  • Static conditions: When fingerprints from Room B form the library and Room A fingerprints authenticate devices, CSI-RFF achieves similar performance.
  • Static conditions: CSI-RFF achieves 99.96% ADR with 0% FAR when increasing Ncsi, including attackers and legitimate NICs of different or identical models.
  • Mobile conditions: 99.57% ADR with 0% FAR is achieved under mobile conditions when Ncsi = 20.
  • Mobile conditions: The mobile-condition results indicate that micro-CSI-based fingerprints are highly resistant to device mobility.

E. Discussions

CSI-RFF’s evaluation examines anomaly detection, distance metrics, normalization and outlier elimination, bandwidth and carrier frequency, and collection overhead. KNN with Manhattan distance, fingerprint normalization, and outlier elimination support robust authentication across tested conditions.

  • Anomaly Detection Algorithms: KNN achieved the highest minimum ADR of 96.15% when FAR ≤1%, indicating robustness against challenging same-model attacks.All tested algorithms reached 100% maximum ADR, but KNN had the strongest minimum performance.
  • Anomaly Detection Algorithms: Around 99% averaged ADR was achieved overall, and KNN was superior in challenging scenarios while also being fastest in the implementation.The comparison included IForest, LOF, DBSCAN, OCSVM, and KNN.
  • Distance Metrics: Manhattan distance outperformed the other evaluated metrics in both static and mobile conditions and was selected as most suitable for CSI-RFF.The comparison used Chebyshev, Euclidean, Manhattan, Hermitian-angle, and Euclidean-angle distances.
  • Fingerprint Normalization and Outlier Elimination: Fingerprint normalization improved ADR by 38.75%, 11.71%, 3.76%, and 0.03% at Ncsi = 1, 5, 10, and 20, respectively.Using normalization and outlier elimination together produced at least a 37.08% increment over the scheme without them.
  • Bandwidth and Carrier Frequency: 100% ADR with 0% FAR was obtained on both tested 2.4GHz and 5GHz channels when Ncsi = 20 and Nrx = 4.The fingerprint library and authentication tests were conducted under consistent same-room conditions.
  • Overhead: CSI collection consumed around 1 millisecond for Ncsi = 20, indicating low collection overhead under the experimental packet configuration.The setup used ACK packets emitted approximately every 50 microseconds.

VII. LIMITATIONS AND FUTURE WORK

The paper identifies scale, device similarity, and non-line-of-sight operation as boundaries for CSI-RFF. Future work targets additional features, larger device populations, advanced authentication algorithms, and improved extraction under multipath conditions.

  • Scalability: Authentication becomes less practical as more devices of the same model increase fingerprint similarity.The authors plan to evaluate larger systems with more same-model devices and diverse brands.
  • Future Directions: Future work will combine CSI-derived features, such as angle of arrival, with micro-CSI fingerprints to reduce similarity and tolerate more noise and processing errors.The paper also proposes investigating advanced authentication algorithms, including deep learning-based approaches.
  • Propagation Conditions: The approach is primarily demonstrated in LoS scenarios, with performance expected to decline under NLoS conditions because multipath interference leaves fewer distinct channel taps for extraction.The authors identify more advanced channel-effect and hardware-distortion separation techniques as a future direction.
  • Demonstrated Scope: Across 14 months, CSI-RFF evaluated device uniqueness, time invariance, and mobility independence, and authenticated 15 COTS WiFi 4/5/6 NICs in a robot access-control use case.The conclusion reports close to 99% performance for the demonstrated authentication application.
Loading 2602.22738v1…