arrow
Return

SecCSI: Securing Wireless Environment With RIS Against CSI-Forgery Attacks

delete2026-01-28
delete0
PRE
AI
Y
Yicheng Liu
Z
Zhao Li
K
Kang G. Shin
Z
Zheng Yan
J
Jia Liu
S
Siwei Le
DOI:10.1109/TIFS.2026.3659002delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Channel state information (CSI) is known to be crucial for both enhancing the transmission performance and ensuring physical-layer security (PLS) in wireless communication systems. To estimate a channel’s CSI, the transmitter (Tx) typically broadcasts a predetermined pilot signal, then the receiver (Rx) computes the channel coefficients based on the received pilot signal and returns the estimated CSI to the Tx. Most, if not all, of existing communication algorithms simply assume that the fed-back CSI is reliable/secure. However, in practice, a malicious terminal may send falsified CSI to the infrastructure, thus compromising the throughput and/or security of the communication over the channel. Although some researchers have already identified this vulnerability, demonstrated the feasibility of the CSI-forgery attacks, and designed countermeasures thereof, their methods either i) are tailored to specific types of attacks, thus lacking generality, or ii) require modifications to the pilot sequence and hence the protocol. To counter the CSI-forgery attacks and remove/mitigate the deficiencies of existing countermeasures, we first develop a comprehensive CSI-forgery model that can subsume the existing CSI-forgery attacks as special instances to facilitate the design of general countermeasures. Then, we propose a novel approach, called <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">SecCSI</monospace>, to detect potential CSI-forgery activities and identify their initiators using reconfigurable intelligent surface (RIS). <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">SecCSI</monospace> leverages the RIS to secretly and dynamically modify the wireless environment transparently to the receiver (Rx) in which the pilot signal is transmitted. The infrastructure can, therefore, detect any attempted manipulation of CSI by appropriately configuring the reflection coefficient matrix of the RIS, transmitting the pilot signal, and analyzing all CSI feedback. <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">SecCSI</monospace> can serve as a guard module for existing communication systems that simply accept the fed-back CSI without checking its trustworthiness. Our theoretical analysis, experimental and numerical evaluations have shown <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">SecCSI</monospace> to effectively detect the CSI-forgery attacks and identify the attacker.
Keywords:
Channel state information (CSI)
physical-layer security (PLS)
CSI-forgery attacks
reconfigurable intelligent surface (RIS)

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

X
xidian university
Scholars:
5.9K
Papers: 2.0K
Citations: 0
N
national institute of informatics
Scholars:
37
Papers: 36
Citations: 0
U
university of michigan
Scholars:
8.6K
Papers: 4.1K
Citations: 1
researcher View more organizations