Source-linked AI summary

From Identification to Authentication for Micro-CSI RF Fingerprinting in OFDM Systems

Matteo Varotto, Stefano Tomasin

arXiv:2608.29845v1eess.SP

TL;DR

The paper asks whether M-CSI-based OFDM authentication remains secure against capable spoofers. It analyzes a colluding attack, derives test-statistic distributions and error probabilities, and finds that sufficient observations can reduce authentication to random guessing.

  • Problem

    Prior authentication work often assumes hardware fingerprints are inherently difficult to replicate, leaving the security limits of M-CSI-based authentication under smart spoofing insufficiently established.

  • Method

    The paper models colluding attackers that estimate device fingerprints, derives approximate closed-form test-statistic distributions and error probabilities, and validates the approximations with simulations and experimental fingerprints.

  • Results

    As attacker observations increase, the AUC monotonically converges to 0.5, and under equal noise conditions the authentication system becomes a random classifier.

  • Takeaways & Limitations

    M-CSI-based authentication provides no meaningful security guarantee against a sufficiently capable adversary.

Abstract

from arXiv · show

We consider a scenario where a legitimate user (Alice) authenticates itself to an authenticator (Bob) by transmitting orthogonal frequency division multiplexing (OFDM) pilots, from which the authenticator extracts the Micro-CSI (M-CSI) fingerprint and compares it against a stored reference via a likelihood test (LT)-based test. We introduce a new spoofing attack, where two adversarial devices collude to first jointly estimate the M-CSI fingerprints of Alice and Bob and then construct a forged signal able to break the authentication mechanism with high probability, limited only by noise effects on the estimates. We derive approximate closed-form distributions of the authentication test statistic under both the legitimate and spoofing hypotheses, enabling the derivation of false alarm and misdetection probabilities in closed-form. We then validate our analytical results against M-CSI fingerprints extracted from experimental data. The results reveal that, given sufficient pilot observations or an equivalent noise statistic between Bob and the attackers, the latter can always drive the test statistics to a random classifier, vanishing the security of M-CSI-based authentication.

I. INTRODUCION

The paper studies M-CSI-based authentication in OFDM and challenges the assumption that hardware fingerprints are inherently difficult to forge. It models a colluding attack in which adversaries estimate fingerprints and construct a spoofing signal against Bob’s likelihood test.

  • RFF-based authentication uses hardware impairments as physical-layer device features without higher-layer key-management overhead.
  • Existing RFF literature primarily addresses identification, while authentication considers devices that impersonate legitimate users.
  • The proposed attack uses colluding devices to estimate relevant M-CSI fingerprints and forge a transmission that resembles Alice’s stored reference at Bob.
  • Bob estimates CSI from known OFDM pilots by dividing each received subcarrier signal by its pilot symbol.
  • The composite fingerprint combines transmitter and receiver hardware impairments in the frequency-domain CSI model.

B. Signal Space Projection and Channel Estimation

The method separates the physical channel from the hardware fingerprint in the time domain, then projects CSI onto a channel subspace to estimate and remove the channel contribution. The resulting fingerprint estimate is channel-invariant and supports the authentication framework under stated attacker and pilot assumptions.

  • Signal-space separation: The physical channel concentrates energy in Np taps around the central CIR tap, whereas hardware-induced fingerprint energy spreads across many time-domain taps.This structural separation motivates signal-space projection.
  • Signal-space separation: The projection subspace V is spanned by DFT columns associated with delays in L = {−Np, . . . , Np} mod N.The matrix FL collects the corresponding DFT columns.
  • Channel estimation: Projecting CSI onto V retains the channel contribution while suppressing fingerprint energy predominantly outside the subspace, producing a smoothed channel estimate.The estimate includes a channel estimation error term ˆz.
  • Fingerprint estimation: The composite M-CSI fingerprint is estimated by element-wise division of CSI by the smoothed channel estimate, removing the channel contribution.The approximation assumes ˆh ≈ h and leaves residual AWGN after fingerprint estimation.
  • Authentication framework: The extracted fingerprint is invariant to the wireless channel regardless of transmitter position or propagation environment.The framework stores Alice’s reference during enrollment and compares future extracted fingerprints during authentication.
  • Attacker and pilot assumptions: The considered attack uses colluding receivers Trudy and Chuck, who share measurements and exploit public pilots while Trudy transmits the spoofing signal.Alice is assumed unaware of the attackers and their fingerprints.

B. Authentication Phase

During authentication, Bob estimates the incoming composite fingerprint and compares it with Alice’s enrolled reference using a noise-weighted likelihood-test statistic. The threshold controls the false-alarm and misdetection trade-off, while Bob’s own fingerprint cancels from the comparison.

  • Authentication decision: At each authentication round, Bob receives NA OFDM symbols and decides between legitimate transmission H0 and spoofed transmission H1.The decision uses the estimated fingerprint from the received signal.
  • Fingerprint extraction: Bob estimates Alice’s composite fingerprint by applying channel estimation to each received observation and averaging across the NA OFDM symbols.For spoofing, Trudy transmits a designed signal through the Trudy–Bob channel before Bob performs the same extraction.
  • Likelihood test: Bob compares the extracted fingerprint with Alice’s stored reference using a noise-weighted squared Euclidean distance across all K subcarriers.The total noise variance per subcarrier determines the weighting in the likelihood-test statistic.
  • Decision threshold: Bob accepts or rejects the authentication hypothesis by comparing the test statistic with a threshold τ.The threshold is selected to meet a false-alarm constraint.
  • Decision threshold: A higher τ reduces the false-alarm probability PFA while increasing the misdetection probability PMD.This trade-off motivates setting τ according to a target PFA.
  • Residual structure: Bob’s fingerprint appears identically in enrollment and authentication residuals, so it cancels exactly regardless of the transmitting device or its fingerprint structure.The cancellation follows from Bob being fixed across both phases.

IV. COLLUDING ATTACK OF THE M-CSI PLA MECHANISM

The attack uses colluding devices to estimate individual hardware fingerprints and the Trudy–Bob channel, then construct a spoofing signal whose fingerprint Bob recognizes as Alice’s.

  • Trudy constructs a spoofing signal whose fingerprint extracted by Bob is recognized as legitimate.
  • With perfect estimates, the spoofed CSI at Bob equals the CSI produced when Alice transmits, yielding PMD = 1 − PFA.
  • Trudy estimates the Trudy–Bob channel directly using signal-space projection and least squares after multiple pilot observations.The projection preserves the estimation-error variance relative to the fingerprint-free case.
  • Trudy estimates her own and Alice’s fingerprints, while Chuck forwards measurements to support the joint estimation.The attackers observe pilot exchanges and centrally solve the estimation problem using measurements shared over an error-free channel.
  • The shifted composite fingerprint estimates form a global system with effective noise covariance reduced by averaging independent observations.Weighted least squares is the maximum-likelihood estimator because the noise is known and complex Gaussian.

WLS Solution:

The WLS solution provides closed-form estimates of the device fingerprints and their estimation-error covariance, with Alice’s and Trudy’s estimates obtained from selected entries.

  • The WLS estimator has a closed-form solution for the joint fingerprint parameters.
  • Alice’s and Trudy’s fingerprint estimates are the second and third entries of the estimated parameter vector.
  • The estimation error is zero-mean complex Gaussian with covariance determined by the WLS solution.
  • The variances of Alice’s and Trudy’s estimates are the (2, 2) and (3, 3) diagonal entries of the covariance matrix, obtained from cofactors of J.
  • Chuck is strictly required because Trudy’s hardware fingerprint is imprinted on her transmission and must be estimated and pre-canceled.

C. Trudy’s Forged Signal

The forged-signal analysis models channel, hardware, receiver-noise, and fingerprint-estimation errors, then derives approximate authentication-statistic distributions and error probabilities.

  • Bob receives Trudy’s spoofing signal through the true Trudy–Bob channel and extracts a fingerprint after channel estimation and division.
  • The analysis represents Trudy’s, Alice’s, and channel estimates with independent complex-Gaussian errors.
  • A first-order Taylor expansion approximates the forged fingerprint when estimation errors are small relative to the corresponding channel and hardware terms.
  • The total distortion is the sum of four independent zero-mean complex-Gaussian contributions from hardware, channel, receiver-noise, and Alice-fingerprint estimation.
  • The resulting authentication-statistic distributions support closed-form false-alarm analysis and numerical misdetection computation.

A. False Alarm Probability

Under legitimate transmission, the test statistic is derived from the difference between live and enrollment fingerprint estimates and normalized across subcarriers to obtain an analytically calibrated threshold.

  • Under H0, Bob compares the live extracted fingerprint with Alice’s stored enrollment reference, which contains enrollment noise.
  • The live and enrollment errors are independent, so their difference is zero-mean complex Gaussian with a combined variance.
  • When live estimation and enrollment share the same channel and noise variance, the variance contributions simplify.
  • Per-subcarrier normalization makes the real and imaginary components independent standard normal variables.
  • 2K degrees of freedom result from summing the normalized contributions across K subcarriers, producing a central χ2 distribution.
  • The threshold τ can be set for any target false-alarm probability by inverting the central-χ2 CDF relation.

B. Misdetection Probability

The proposed analytical distributions closely match attack simulations and show that increasing attacker observations drives authentication toward random guessing. This convergence persists despite larger enrollment counts or substantially higher attacker noise.

  • Attacker observations: As attacker weight increases, the AUC monotonically tends toward 0.5, corresponding to a random-guess classifier unable to distinguish legitimate from spoofed transmissions.Higher attacker weight represents more pilot observations and lower estimation variance.
  • Attacker observations: Sufficient observations let Trudy forge Alice’s individual fingerprint accurately enough to make Bob’s authentication test statistically indistinguishable from the legitimate case.This remains possible even when the attacker’s noise variance is orders of magnitude higher than Bob’s.
  • Enrollment effects: A larger enrollment count reduces Bob’s enrollment noise and tightens the decision boundary, but the AUC ultimately converges to 0.5 regardless of enrollment count.The enrollment advantage is overcome as attacker weight grows.
  • Noise effects: For any fixed noise level at Bob, a sufficiently capable attacker eventually drives the AUC to 0.5, although higher Bob noise delays convergence.Bob’s noise degrades live fingerprint estimation and loosens the decision boundary, making the system easier to fool at lower attacker weights.
  • Analytical validation: Theoretical distributions almost perfectly fit Monte-Carlo attack simulations using M-CSI fingerprints extracted from the WiSig dataset.The dataset contains 174 WiFi transmitters, 41 USRP receivers, and CSI computed from 52 pilots; simulations use Np = 8.

C. Detection Error Tradeoff Performance

The DET results show that attacker observations and noise conditions can drive M-CSI authentication toward random classification, while increasing Alice’s observations can temporarily improve the defender’s operating point. Analytical curves closely match Monte-Carlo simulations.

  • DET curves: As σ2_T decreases toward Bob’s noise level, the DET curve approaches the diagonal, eliminating an operating point with simultaneously low PFA and PMD.When σ2_T matches Bob’s noise level, Bob becomes a random classifier.
  • Attack model: The four-node Alice–Bob–Trudy–Chuck scenario analytically characterizes authentication security against a colluding smart adversary.The attack jointly estimates device fingerprints and constructs a forged signal to fool authentication.
  • AUC results: As attacker observations accumulate, AUC converges to 0.5 regardless of enrollment count or attacker noise variance.This convergence makes the authentication test equivalent to random classification.

APPENDIX A DERIVATION OF (11)

This appendix derives Bob’s stored M-CSI reference from repeated pilot observations by estimating CSI, forming composite fingerprints, and averaging across enrollment transmissions.

  • CSI estimation: Bob estimates CSI by dividing each received pilot observation by its known pilot symbol.The resulting CSI is then used in the subsequent fingerprint construction.
  • Fingerprint construction: Bob forms the composite fingerprint by dividing the received CSI by the channel estimate.This operation produces the fingerprint for each observation before enrollment averaging.
  • Reference construction: The stored reference is obtained by averaging the composite fingerprints over N_E observations.The appendix separately defines the corresponding enrollment noise term.
  • Noise characterization: The enrollment noise term is zero-mean complex Gaussian and independent across observations, with variance determined in the derivation.The passage identifies h_AB,k as deterministic and ε_Bob,k as the resulting noise term.
  • Attacker-side estimation: Trudy’s analogous repeated pilot observations are normalized by the known pilot symbol before least-squares averaging estimates the relevant quantity.The estimation error is also zero-mean complex Gaussian under the stated independent Gaussian-noise model.

APPENDIX C DERIVATION OF (47)

This appendix linearizes the spoofed fingerprint expression by factoring denominator terms, applying a first-order reciprocal approximation, and discarding products of error terms.

  • Algebraic preparation: The derivation first factors (1 + f_T,k) and h_TB,k out of the denominator before simplifying the resulting fractions.It also uses the small-fingerprint approximation 1 + f_T,k ≈ 1 + f_B,k.
  • First-order approximation: Under small-error conditions, the reciprocal approximation 1/(1+x) ≈ 1 − x is applied to each factor.The conditions require ε_T,k to be small relative to 1 + f_T,k and ε_est,k to be small relative to h_TB,k.
  • Error truncation: Products of error terms are discarded so the resulting expression retains only first-order contributions.Examples include ε_A,kε_T,k and ε_A,kε_est,k.
  • Fingerprint simplification: The simplified expression uses small-fingerprint identities for (1+f_A,k)(1+f_B,k) and approximates ϕ_k as 1 for the ε_A,k term.These substitutions produce the first-order fingerprint relation used in the derivation.
  • Final expression: Bob’s receiver-noise term z_B,k/h_TB,k is added to obtain the final approximate spoofed fingerprint expression.The resulting expression is summarized as ˆf_TB,k ≈ (1 + f_A,k + f_B,k) − 1 + f_A,k + f_B,k.
Loading 2608.29845v1…