Source-linked AI summary
Toward Security-Resilient Cell-Free Massive MIMO: A Multi-Stage Framework
Junbin Yu, Tianyu Lu, Mohammadali Mohammadi, Michail Matthaiou
TL;DR
Active pilot spoofing contaminates CSI in CF-mMIMO and can degrade secrecy, motivating rapid mitigation and recovery after attack detection. The paper develops a multi-stage robust framework combining local absorption with global restoration, PPZF, AN, worst-case Eve uncertainty, and unified SCA optimization. Numerical results show effective time-quality tradeoffs and the highest recovered secrecy for the proposed scheme, including gains up to 3.6%, 15.7%, and 56% over baseline schemes.
Problem
Active pilot spoofing contaminates the target user's channel estimate and increases information leakage, leaving immediate response and secrecy restoration under persistently contaminated CSI unresolved.
Method
The framework benchmarks attack-free service, performs low-overhead local absorption after detection, then jointly optimizes network-wide power with PPZF and AN under worst-case Eve uncertainty using unified SCA.
Results
The proposed sequential design improves secure absorption and restoration, with PPR-AN exceeding RPR-AN, PPR-RAN, and Abs-only recovered SSE1 by 3.6%, 15.7%, and 56% at M = 12.
Takeaways & Limitations
The framework provides rapid post-attack fallback followed by higher-secrecy restoration while operating under contaminated CSI and uncertain Eve-related fading.
Abstract
from arXiv · showhide
This paper develops a robust security-resilient transmission framework for cell-free massive multiple-input multiple-output (CF-mMIMO) systems under active pilot spoofing attacks. As a baseline, system performance is characterized under attack-free conditions to establish the target user's pre-attack service level. Upon attack detection, the system enters an absorption phase, during which, power allocation is adaptively adjusted across a limited subset of access points (APs) using contaminated channel state information (CSI). This phase quickly compensates for performance degradation while maintaining low operational overhead. Once the secrecy spectral efficiency (SSE) recovers to a prescribed loss level, the resulting power allocation initializes the restoration phase. Here, the transmit powers of all APs are jointly optimized, and a protective partial zero-forcing (PPZF) strategy further improves secrecy. In parallel, artificial noise (AN) is incorporated under a worst-case eavesdropping scenario accounting for large-scale fading uncertainty. The resulting stage-dependent non-convex problems are formulated within a unified framework and solved using successive convex approximation (SCA). Numerical results demonstrate that the proposed scheme achieves an effective time-quality tradeoff while maintaining the highest recovered secrecy; in a representative setup, it achieves gains of up to 3.6%, 15.7%, and 56% over the respective baseline schemes, with similar improvements under eavesdropper's channel uncertainty.
I. Introduction
CF-mMIMO improves coverage, reliability, and spectral efficiency through distributed AP cooperation, but active pilot spoofing can contaminate channel estimates and degrade secrecy. The paper proposes a multi-stage, robust recovery framework that addresses immediate mitigation and subsequent restoration under contaminated CSI.
- Distributed AP cooperation gives CF-mMIMO macro-diversity, user-centric service, and improved coverage uniformity while enhancing spectral efficiency and reliability.
- Active pilot spoofing contaminates the target user's channel estimate, partly steers downlink transmission toward Eve, and increases information leakage.
- Existing CF-mMIMO security designs use pilot assignment, power allocation, AP clustering, or artificial noise but largely overlook processing latency and persistent CSI contamination.
- The proposed framework separates long-term normal benchmarking from short-term post-attack absorption and restoration using stage-dependent action spaces.
- Absorption uses low-overhead local power reallocation over a small AP subset, while restoration uses artificial noise and protective partial zero-forcing reconfiguration for network-wide power allocation.
- The system models distributed APs, single-antenna users, Rayleigh fading, orthogonal pilots, and an active Eve transmitting the target user's identical pilot.
B. Two-Timescale Secure Framework
The two-timescale framework establishes a normal-stage service benchmark, then uses distinct post-detection action spaces for rapid absorption and network-wide restoration. Absorption stops at a prescribed SSE loss level, and its resulting allocation initializes restoration.
- The CPU establishes the targeted user's pre-attack service level from a normal benchmark on the long-term timescale.
- Post-detection recovery assumes an externally supplied pilot-spoofing alarm and focuses on absorption and restoration rather than attack detection.
- The absorption stage updates only a local AP subset for rapid, low-overhead mitigation while restoration prepares network-wide data and artificial-noise power control with PPZF topology updates.
- For performance absorption factor α ∈(0, 1), absorption stops at the prescribed SSE target and passes the obtained operating point to restoration.
C. Robust Worst-Case Model
The robust model addresses unavailable instantaneous Eve CSI under pilot spoofing by bounding Eve’s large-scale fading uncertainty. The same worst-case model is used in both absorption and restoration.
- Pilot spoofing mixes legitimate and eavesdropping channels, making Eve’s instantaneous CSI difficult for APs to obtain.
- Eve’s large-scale fading coefficient is modeled within an uncertainty set around its estimated value, controlled by uncertainty coefficient ϵ_e.
- The upper bound is ¯β_l,e = (1 + ϵ_e)ˆβ_l,e.
- The legitimate user’s large-scale fading is known from long-term statistics, while uncertainty applies only to Eve-related fading in absorption and restoration.
D. PPZF Precoding and Protection Reconfiguration
Stage-dependent PPZF combines partial zero-forcing for selected strong users with protective maximum-ratio transmission for weak users. Reconfiguration prioritizes the attacked user at selected APs while preserving spatial resources for protection or artificial noise.
- PPZF Precoding: PPZF applies PZF to selected strong users and PMRT to remaining weak users, balancing desired-signal enhancement with interference control.
- PPZF Precoding: The normal strong-user set is built from large-scale channel gains with at most M − 1 users, preserving one spatial degree of freedom.
- Protection: The residual spatial dimension supports PMRT or artificial-noise transmission rather than being consumed entirely by zero-forcing.
- Protection Reconfiguration: The top-N_p APs with the largest protection-priority metric µ_l are selected for PPZF reconfiguration.
- Protection Reconfiguration: At selected APs, the attacked user is forced into the recovered strong-user set during restoration.
- Protection Reconfiguration: Absorption retains the baseline topology, whereas restoration activates PPZF reconfiguration based on the selected APs.
E. Achievable SE and SSE with Stage-Dependent PPZF
The stage-dependent signal model includes PPZF transmission and optional artificial noise, then evaluates legitimate-user and worst-case Eve SINR and spectral efficiencies to obtain attacked-user SSE.
- Stage-Dependent PPZF: Each AP defines stage-specific strong-user and weak-user sets for its PPZF transmission.
- Stage-Dependent PPZF: The transmitted AP signal includes PPZF data transmission and an artificial-noise vector in the residual protected subspace.
- Stage-Dependent PPZF: Artificial noise is inactive when its stage-dependent activation variable ρ_l^(s) indicates no activation.
- SE and SSE: The formulation derives the achievable SINR for each legitimate user and the worst-case effective SINR for Eve.
- SE and SSE: User and Eve spectral efficiencies are obtained from their respective SINRs, and attacked-user SSE is then formed from these quantities.
III. Problem Formulation and Solution
The design distinguishes normal benchmark generation from post-disruption resilient control by formulating the system over two time scales.
- The formulation uses two time scales to separate normal benchmarking from post-disruption resilient control.
A. Normal-Stage Problem
The normal phase establishes a fair pre-attack service benchmark by maximizing users’ spectral efficiency under minimum QoS requirements. After attack detection, absorption locally reallocates power among selected APs while retaining other APs’ normal-stage powers until a target or iteration limit is reached.
- A. Normal-Stage Problem: The normal phase solves a max-min fairness problem that maximizes users’ SE while guaranteeing each user a minimum QoS.
- A. Normal-Stage Problem: UE1’s normal-stage service level is extracted as the pre-attack secrecy benchmark because no active eavesdropping is present.
- A. Normal-Stage Problem: After a pilot-spoofing alarm, absorption selects the top-Na APs using the local absorption priority metric and updates only that subset.
- A. Normal-Stage Problem: APs outside the selected subset retain their normal-stage powers during absorption, while the optimized subset satisfies the absorption-stage constraints.
- A. Normal-Stage Problem: Absorption ends when the absorbed secrecy performance reaches the prescribed target α or the maximum iteration count.
C. Restoration-Stage Problem
The restoration stage starts from the absorbed attacked-stage power allocation and expands optimization to all APs under a richer recovery action space.
- C. Restoration-Stage Problem: The absorbed attacked-stage power allocation initializes restoration, which jointly optimizes the full AP set under the richer recovery action space Arec.
- C. Restoration-Stage Problem: The restoration-stage formulation imposes the post-attack user constraints while optimizing the expanded network-wide recovery variables.
D. SCA Reformulation for Multi-Stage Optimization
The normal, absorption, and restoration problems are non-convex because of coupled SINR terms, but share a unified successive convex approximation treatment after stage-dependent structures are fixed.
- D. SCA Reformulation for Multi-Stage Optimization: Fixing each stage’s topology and coefficient sets enables a unified SCA treatment of the otherwise non-convex optimization problems.
- D. SCA Reformulation for Multi-Stage Optimization: For Eve, an auxiliary variable and affine denominator bounds support an upper-bounding SOC constraint for the worst-case SINR.
- D. SCA Reformulation for Multi-Stage Optimization: The legitimate-user SINR is replaced at each iteration by a concave lower-bound surrogate based on a first-order approximation.
- D. SCA Reformulation for Multi-Stage Optimization: The resulting convex SCA subproblems are solved iteratively under stage-specific feasible sets, with absorption and restoration sharing the machinery but differing in topology, AN availability, and optimized AP set.
- D. SCA Reformulation for Multi-Stage Optimization: Absorption reduces short-term computation by optimizing NaK variables, whereas restoration operates over the full AP set and therefore has a larger variable dimension.
IV. Numerical Results
Simulations evaluate post-attack secrecy recovery under active pilot spoofing, antenna scaling, and uncertainty in Eve’s large-scale fading. The proposed PPR-AN scheme consistently provides the strongest recovered secrecy, while absorption targets expose a time–quality tradeoff.
- IV. Numerical Results: The evaluation uses L = 20 APs, M = 8 antennas, K = 10 users, Na = 3, and an Eve attacking UE1 with the same pilot.
- IV. Numerical Results: After the alarm at t0 = 500 ms, UE1’s SSE1 drops and the system begins local power reallocation during absorption.
- IV. Numerical Results: The PPR-AN scheme achieves the highest restored secrecy by combining PPZF reconfiguration with artificial-noise-assisted recovery.
- IV. Numerical Results: A smaller absorption target α triggers restoration earlier, whereas a larger α permits more local recovery before restoration begins.
- IV. Numerical Results: At M = 12, PPR-AN improves recovered SSE1 by about 3.6%, 15.7%, and 56% over RPR-AN, PPR-RAN, and Abs-only, respectively.
- IV. Numerical Results: At ϵe = 0.2, PPR-AN achieves about 3.8%, 17.2%, and 60.6% higher recovered SSE1 than RPR-AN, PPR-RAN, and Abs-only, respectively.
V. Conclusion
The paper establishes a sequential security-resilient framework for CF-mMIMO under active pilot spoofing, combining attack-free benchmarking with absorption and restoration. Numerical results show improved secure absorption and restoration under contaminated CSI.
- V. Conclusion: The framework benchmarks normal operation before sequentially applying absorption and restoration after attack detection.The absorption stage provides a fast secure fallback, while restoration targets further secrecy recovery.
- V. Conclusion: The design incorporates worst-case large-scale fading uncertainty for Eve, PPZF reconfiguration, and restoration-stage artificial-noise power optimization.
- V. Conclusion: Numerical results showed that the sequential design improves both secure absorption and secure restoration under contaminated CSI.