Source-linked AI summary

False-CSI Attacks in Power-Domain NOMA for 6G: A Threat Taxonomy and System-Level Impacts

Samira Jafarli, Aysha Ebrahim, Suleyman Uludag

arXiv:2608.28351v1cs.CReess.SP

TL;DR

False CSI is an attack surface in power-domain NOMA because channel inputs control ordering, allocation, pairing, clustering, beamforming, and SIC. The paper develops a two-axis taxonomy, extends it to coordinated and spatial or training-phase variants, and maps these attacks to system-level effects including fairness, throughput, QoS, and secrecy.

  • Problem

    NOMA decisions depend on CSI, but deliberately biased CSI can distort multiple linked mechanisms rather than merely introducing ordinary estimation noise.

  • Method

    The paper organizes false-CSI attacks by magnitude and ordering effect, then extends the taxonomy to coordinated, group-changing, direction-forgery, training-phase, pilot-spoofing, and RIS-induced variants.

  • Results

    The attack families are mapped to impacts on power allocation, SIC reliability, scheduler behavior, fairness, throughput, quality of service, and secrecy.

  • Takeaways & Limitations

    False CSI should be treated as a control-input integrity problem because small biases can propagate across multiple NOMA layers and produce system-wide consequences.

Abstract

from arXiv · show

Power-domain non-orthogonal multiple access (NOMA) remains a widely studied technique for improving spectral efficiency and supporting dense connectivity in beyond-5G and 6G networks. Its main operating mechanisms, however, depend on the integrity of channel-state information (CSI). Power allocation, user ordering, pairing, clustering, and beamforming can all be distorted when the CSI consumed by the base station is deliberately biased rather than merely noisy. This article examines false CSI as an attack surface in power-domain NOMA. We organize the threat space using a compact taxonomy with two primary axes: magnitude, which distinguishes underreporting from overreporting, and ordering effect, which distinguishes order-preserving, boundary, and order-reversing attacks. We then show how coordinated false- CSI behavior, group-changing attacks, direction forgery, pilot spoofing, training-phase injection, and RIS-induced channel manipulation extend this basic taxonomy. Finally, we map each attack family to system-level impacts on power allocation, SIC reliability, scheduler behavior, fairness, throughput, and secrecy. The central message is that false CSI should be treated not only as a channel-estimation problem, but also as a control-input integrity problem for 6G NOMA.

I. INTRODUCTION

Power-domain NOMA depends on trustworthy CSI for ordering, allocation, pairing, clustering, and beamforming. The article reframes deliberately biased CSI as a unified attack surface and maps its propagation to system-level harms.

  • NOMA’s security-sensitive mechanisms couple superposition coding, SIC, and channel-dependent power allocation.Small perturbations can propagate because these mechanisms are coupled.
  • Every NOMA decision ultimately acts on channel information obtained through reports, feedback, pilot estimation, or hybrid acquisition.The base station assumes this channel input is trustworthy at allocation time.
  • Adversarially biased CSI can distort power allocation, pairing, clustering, decoding order, and beamforming across the NOMA stack.The corrupted input propagates from allocation decisions to downstream system behavior.
  • Existing work commonly models CSI imperfection as zero-mean stochastic uncertainty rather than a unified attack mechanism.Related attacks are often treated separately under pilot spoofing, untrusted relays, adversarial scheduling, or malicious RISs.
  • The article organizes false-CSI threats by magnitude and ordering effect, then maps attack families to power misallocation, SIC failure, scheduler distortion, throughput loss, fairness degradation, and secrecy leakage.The taxonomy covers underreporting, overreporting, order preservation, boundary effects, and order reversal, alongside coordinated and spatial or training-phase variants.

II. NOMA IN 6G: WHY CSI INTEGRITY MATTERS

CSI is the control input that drives core power-domain NOMA decisions. Because one false report can affect both the reporting user and other users sharing its resource, CSI integrity is security-critical.

  • Power-domain NOMA lets users share time-frequency resources by separating signals through transmit power rather than orthogonal resource blocks.The base station superposes signals with different power coefficients.
  • The weaker user typically receives more power, while the stronger user uses SIC to decode and subtract the weaker user’s signal first.The stronger user then decodes its own lower-power signal from the residual.
  • The same CSI determines SIC order, power coefficients, pairing or clustering, and beam direction in MISO/MIMO-NOMA.This makes CSI a control input rather than only a performance variable.
  • False CSI is adversarially biased channel information consumed by NOMA decision logic before scheduling or allocation.It may involve reported gains, channel-quality indicators, spatial directions, or training-corrupted estimates.
  • Unlike in orthogonal access, one false report can alter the paired user’s decoding role, shared power split, and nearby users’ cluster or beam.The shared-resource coupling broadens the consequences beyond the reporting user’s own allocation.

C. The SIC Decoding Margin

False CSI manipulates SIC indirectly by causing the base station to choose incorrect near–far roles or power splits before checking the decoding margin. The resulting effects are ordering preservation, boundary fragility, or ordering reversal.

  • A two-user NOMA pair assigns more power to the weaker far user, while the stronger near user decodes and subtracts that signal through SIC.The exact feasibility condition depends on receiver, coding, modulation, channel, and residual-interference assumptions.
  • The paper uses a simplified received power-gap condition as an illustrative SIC margin for its taxonomy.The condition is presented as an illustration rather than a universal receiver-specific feasibility rule.
  • The illustrative margin uses P_far, P_near, |h_near|2, and ζ to represent allocated powers, near-user channel gain, and an effective SIC threshold.These quantities define the received power-gap condition used for taxonomy discussion.
  • False CSI can preserve ordering while skewing allocation, push users toward a fragile boundary, or reverse roles and validate the margin for the wrong assignment.The attack changes the decision inputs before the inequality is evaluated.

III. THREAT TAXONOMY OF FALSE-CSI ATTACKS

The taxonomy uses two operational axes: how the adversary changes the reported channel magnitude and how that change affects NOMA ordering. Additional attack families extend these cases while corrupting the same decision input.

  • The Two Axes: The magnitude axis distinguishes underreporting from overreporting of the relevant channel value.Magnitude is the adversarial lever in the taxonomy.
  • The Two Axes: The ordering-effect axis distinguishes preserved ordering, boundary ambiguity, and reversed ordering used for SIC decisions.Ordering effect represents the resulting NOMA decision consequence.
  • The Two Axes: Order-preserving attacks retain near–far roles but produce an incorrect power split.The base station keeps the same ordering while computing allocation from biased CSI.
  • The Two Axes: Boundary attacks make reported gains too close for a stable SIC margin, while order-reversing attacks assign roles to the wrong users.The wrong assignment can satisfy the SIC condition for an incorrect power allocation.
  • The Two Axes: Group-changing attacks cross pairing or clustering thresholds, coordinated attacks distribute bias across users, and direction or training attacks corrupt CSI before allocation.These variants extend the taxonomy without changing its central dependency on corrupted CSI.

B. Underreporting: Strong-to-Weaker False CSI

Underreporting by a strong user makes the base station treat that user as weaker, altering power allocation and potentially disrupting SIC, ordering, and pairing decisions.

  • Attack mechanism: A strong-channel attacker underreports its gain to appear weaker and capture a larger transmit-power share.NOMA assigns more power to weaker users.
  • Order-preserving case: Order-preserving underreporting keeps user ordering and SIC sequence unchanged but shifts the power gap toward the attacker.The attacker remains above its victim in reported gain, so the SIC margin remains satisfied.
  • Boundary case: Boundary underreporting makes the users indistinguishable, collapsing the SIC margin and sharply increasing outage probability for both users.Residual interference accumulates after power separation becomes insufficient for reliable SIC.
  • Order-reversing case: Order-reversing underreporting makes the base station assign the attacker the weak-user role and larger power coefficient, while the genuine weak user receives an unsupported decoding role.The attacker can decode easily because its true channel is strong, whereas the genuine weak user cannot support the assigned position.
  • Group-changing variant: If underreporting crosses a pairing or clustering threshold, the scheduler can move the attacker into another pair or cluster, creating resource-block churn.This extends the attack beyond the original two-user interaction.

C. Overreporting: Weak-to-Stronger False CSI

Overreporting by a weak user inflates its apparent channel quality, influencing ranking-driven scheduling and potentially collapsing or reversing NOMA ordering and SIC assignments.

  • Attack mechanism: A weak user that overreports receives less NOMA power, so overreporting primarily targets ranking, scheduling, beam pointing, or pairing decisions.The attack is generally not advantageous as pure rate-grabbing.
  • Order-preserving case: Order-preserving overreporting can make the attacker appear more deserving of proportional-fair or quality-of-service resources than its actual channel justifies.The attacker may capture service that would otherwise go to other users.
  • Boundary case: Boundary overreporting ties the reported gain to the strong user and collapses the SIC decoding margin.The attacker’s inflated report pulls the channel gap closed.
  • Order-reversing case: Order-reversing overreporting assigns the weak attacker a smaller power coefficient and incorrectly expects it to perform SIC.The genuine strong user instead receives the larger share without decoding instructions suited to its actual channel.
  • Additional variant: A strong user can also overreport, rarely changing scalar ordering but still biasing ranking-driven scheduling.Spatial beam-direction manipulation is treated separately.

D. Spatial and Training-Phase False CSI

Spatial and training-phase attacks corrupt CSI beyond a scalar channel gain, but they still enter the same NOMA decision pipeline and alter allocation, ordering, pairing, clustering, or beamforming.

  • Scope: The six scalar taxonomy cells describe upward or downward bias in a reported or estimated channel value.Non-scalar attacks are treated as additional corruption points rather than new taxonomy cells.
  • Spatial attacks: Spatial false CSI forges channel direction, potentially causing beams intended for victims to leak energy toward the attacker.Malicious RIS manipulation can create a similar apparent spatial channel without user-side collusion.
  • Training-phase attacks: Pilot contamination, spoofing, and training-phase injection bias estimates before scheduling, affecting ordering, power allocation, pairing, clustering, or beamforming.Reactive training jamming instead prevents the base station from obtaining a usable estimate.
  • Taxonomy relation: Spatial and training-phase attacks specify where false CSI enters, while magnitude and ordering effect specify how corrupted input changes NOMA decisions.Both attack types feed the same control-input pipeline.

E. Coordinated and Group-Changing Attacks

Coordination distributes false CSI across multiple users, making boundary and order-reversing attacks easier to engineer and enabling aggregate allocation errors and cooperative pilot spoofing.

  • Coordinated reports: Coordinated reports can make boundary and order-reversing attacks appear plausible because consistent near-victim values resemble a legitimate user pair.This can reduce the detectability of a single-user outlier.
  • Coordinated reports: Coordination can create an aggregate allocation error larger than any individual false report.The attack surface therefore extends beyond single-user manipulation.
  • Coordinated training attacks: Cooperative pilot spoofing distributes the false-pilot burden across attackers, defeating detectors based on a single source’s energy or spatial signatures.The same coordinated logic applies during training.
  • 6G amplification: Ultra-dense deployments and history-aware scheduling amplify coordinated threats by increasing compromised-pair likelihood and extending the window for bias to act.These 6G features motivate explicit treatment of coordinated behavior in threat models.

IV. SYSTEM-LEVEL IMPACT

False CSI propagates from corrupted channel inputs into allocation, pairing, SIC, throughput, fairness, and secrecy. The most severe effects arise when ordering is crossed or spatial manipulation enables silent leakage.

  • Power allocation distortion and pairing errors: Biased CSI distorts power allocation and pairing, causing efficiency loss, unfair resource redirection, and scheduler churn near clustering thresholds.The optimizer remains locally optimal for the false input, making the distortion difficult to distinguish from normal operation.
  • SIC failure and error propagation: Boundary attacks can satisfy SIC conditions on paper while leaving the true power gap at or below the sensitivity floor.The resulting decoding failure creates residual interference, higher outage probability, block errors, retransmissions, and lower-rate fallback.
  • SIC failure and error propagation: Order-reversing attacks assign SIC responsibility to a user with the weak true channel, causing errors to propagate within the pair and into next-slot scheduling.Hybrid-ARQ feedback and channel-quality reports inherit errors from the broken decoding chain.
  • Throughput, fairness, and quality of service: Order-preserving biases can quietly shift fairness-weighted rates toward attackers while resembling natural channel variation.Persistent false CSI makes this effect especially damaging at scale.
  • Confidentiality and secrecy leakage: Direction forgery and beam leakage reduce secrecy by illuminating attackers with signals intended for legitimate users.In this setting, the eavesdropper is an authenticated user whose feedback the system relies on, enabling selective overhearing.

V. IMPLICATIONS FOR 6G NOMA SECURITY

The paper frames false CSI as adversarial input that can exploit dense NOMA decision chains across scheduling, physical-layer processing, and control logic. It argues that evaluation and security practice need to account for persistent, coordinated, and hybrid manipulation.

  • Adversarial input: False CSI should be modeled as strategic adversarial input rather than only zero-mean estimation uncertainty.Attackers can target specific base-station decisions through underreporting, overreporting, or distributed small biases.
  • Dense deployment: Dense deployments amplify small reporting biases because one false value can alter clustering, resource sharing, and SIC responsibilities across many decisions.Many low-amplitude reports may be more damaging than one obvious outlier in massive machine-type communications.
  • Hybrid attacks: Pilot spoofing, direction forgery, and RIS-induced manipulation can corrupt different CSI entry points while affecting the same NOMA decision chain.Their combined effects can reach scheduling, power allocation, SIC, and secrecy.
  • AI-driven scheduling: Learning-based and history-aware schedulers increase the value of stealthy false CSI because channel quality, reliability, or service-demand biases can accumulate over time.Higher-layer adversarial behavior can compound false-CSI attacks at the NOMA layer.
  • Evaluation methodology: No common benchmark currently compares false-CSI attacks across models, attacker objectives, densities, pairing rules, and CSI-error assumptions.A useful benchmark should specify attacker knowledge, manipulated CSI fields, intended decision errors, and observable system consequences.

VI. CONCLUSION

False CSI forms a distinctive attack surface because one corrupted channel input shapes multiple NOMA decisions and downstream outcomes. The paper concludes that CSI integrity belongs inside the attack model for 6G NOMA.

  • VI. CONCLUSION: False CSI couples user ordering, power allocation, pairing, clustering, beamforming, SIC reliability, fairness, throughput, and secrecy through one channel input.The paper organizes attacks by underreporting versus overreporting and by preserved, collapsed, or reversed ordering.
  • VI. CONCLUSION: Small biases can produce system-wide effects, including altered power splits, weakened SIC margins, scheduler distortion, resource shifts, and silent secrecy leakage.These consequences may remain local in appearance while propagating across multiple system layers.
Loading 2608.28351v1…