Reconfigurable Intelligent Surfaces (RISs) extend 5G New Radio (NR) coverage by redirecting signals toward Non-Line-of-Sight regions, but the same reflected footprint exposes Channel State Information (CSI) to passive eavesdroppers, who can train a Machine Learning classifier on it and perform unauthorized device-free Human Activity Recognition (HAR). Because the information leaks through the propagation environment rather than through transmitted content, encryption and access control are ineffective, and artificial-noise approaches either fail against trained neural networks or violate the strict Error Vector Magnitude (EVM) limits of 3GPP TS 38.104. This paper proposes a transmitter-side adversarial defense that obfuscates the CSI intercepted by a non-adaptive eavesdropper within the EVM budget of the active modulation. The defense reformulates the Carlini & Wagner attack for the radio-frequency domain, replacing additive norm-bounded perturbations with multiplicative amplitude scaling and phase rotation on the complex channel coefficients, and embeds the modulation-dependent EVM limits directly into the adversarial objective. An offline Universal Adversarial Perturbation (UAP) variant removes the per-packet optimization cost and meets the latency budget of Ultra-Reliable Low-Latency Communication services. The instance-specific attack achieves a feasible Attack Success Rate above 90% under QPSK and 16-QAM and above 83% under the 3.5% EVM budget of 256-QAM. The UAP retains 73% to 83% of this effectiveness with no online computation and transfers across receiver positions, reducing a target-position classifier from 83.6% to roughly 33% accuracy. End-to-end physical-layer simulations bound the cost to the legitimate link below 1 dB of Signal-to-Noise-Ratio penalty on Block Error Rate after Low-Density Parity-Check decoding.

Restuccia, G., Schilleci, S., Dino, A., Garlisi, D., Giuliano, F., Mangione, S., et al. (2026). Adversarial CSI Obfuscation Against Device-Free Activity Recognition in RIS-Assisted Systems. IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 7, 10768-10790 [10.1109/ojcoms.2026.3727754].

Adversarial CSI Obfuscation Against Device-Free Activity Recognition in RIS-Assisted Systems

Restuccia, Gabriele
;
Schilleci, Silvia;Dino, Alessandra;Garlisi, Domenico;Giuliano, Fabrizio;Mangione, Stefano;Tinnirello, Ilenia
2026-08-01

Abstract

Reconfigurable Intelligent Surfaces (RISs) extend 5G New Radio (NR) coverage by redirecting signals toward Non-Line-of-Sight regions, but the same reflected footprint exposes Channel State Information (CSI) to passive eavesdroppers, who can train a Machine Learning classifier on it and perform unauthorized device-free Human Activity Recognition (HAR). Because the information leaks through the propagation environment rather than through transmitted content, encryption and access control are ineffective, and artificial-noise approaches either fail against trained neural networks or violate the strict Error Vector Magnitude (EVM) limits of 3GPP TS 38.104. This paper proposes a transmitter-side adversarial defense that obfuscates the CSI intercepted by a non-adaptive eavesdropper within the EVM budget of the active modulation. The defense reformulates the Carlini & Wagner attack for the radio-frequency domain, replacing additive norm-bounded perturbations with multiplicative amplitude scaling and phase rotation on the complex channel coefficients, and embeds the modulation-dependent EVM limits directly into the adversarial objective. An offline Universal Adversarial Perturbation (UAP) variant removes the per-packet optimization cost and meets the latency budget of Ultra-Reliable Low-Latency Communication services. The instance-specific attack achieves a feasible Attack Success Rate above 90% under QPSK and 16-QAM and above 83% under the 3.5% EVM budget of 256-QAM. The UAP retains 73% to 83% of this effectiveness with no online computation and transfers across receiver positions, reducing a target-position classifier from 83.6% to roughly 33% accuracy. End-to-end physical-layer simulations bound the cost to the legitimate link below 1 dB of Signal-to-Noise-Ratio penalty on Block Error Rate after Low-Density Parity-Check decoding.
ago-2026
Restuccia, G., Schilleci, S., Dino, A., Garlisi, D., Giuliano, F., Mangione, S., et al. (2026). Adversarial CSI Obfuscation Against Device-Free Activity Recognition in RIS-Assisted Systems. IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 7, 10768-10790 [10.1109/ojcoms.2026.3727754].
File in questo prodotto:
File Dimensione Formato  
Adversarial_CSI_Obfuscation_Against_Device-Free_Activity_Recognition_in_RIS-Assisted_Systems.pdf

accesso aperto

Descrizione: This is an open access article under the terms of the Creative Commons Attribution License
Tipologia: Versione Editoriale
Dimensione 2.13 MB
Formato Adobe PDF
2.13 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10447/716605
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact