The active reconfigurable intelligent surface (RIS) offers a promising solution to overcome the double-fading attenuation inherent in passive RIS-aided systems. However, this capability can be exploited by adversaries to launch potent pilot spoofing attack (PSA). In this paper, we propose a novel active RIS-aided covert PSA scheme for time-division duplex systems, where a passive eavesdropper manipulates the channel state information (CSI) estimation at the legitimate transceiver during the uplink stage and steers downlink data towards itself during the downlink stage. Crucially, without requiring perfect instantaneous CSI, a practical challenge for eavesdroppers, we maximize the average eavesdropping signal-to-noise ratio (SNR) by jointly designing the RIS reflection coefficients for both stages. To ensure covertness, we integrate an anti-energy ratio detection (ERD) mechanism that constrains the detection probability below a predefined threshold. The resulting non-convex optimization problem is solved via an efficient alternating optimization algorithm combined with penalty methods, handling the rank-1 constraints and statistical CSI uncertainties. Simulations demonstrate that the proposed scheme achieves up to 26 dB SNR gain over passive RIS-aided PSA and reduces ERD detection probability compared to traditional PSA. This work reveals the dual-edged nature of the active RIS: while enhancing security, it introduces new attack schemes demanding advanced countermeasures.
Covert Pilot Spoofing Attack via Active Reconfigurable Intelligent Surface / Luo, Junshan; Qu, Zhengfei; He, Boxiang; Wang, Shilian; Taricco, Giorgio; Yuen, Chau. - In: IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS. - ISSN 1536-1276. - 25:(2026). [10.1109/twc.2025.3643349]
Covert Pilot Spoofing Attack via Active Reconfigurable Intelligent Surface
Taricco, Giorgio;
2026
Abstract
The active reconfigurable intelligent surface (RIS) offers a promising solution to overcome the double-fading attenuation inherent in passive RIS-aided systems. However, this capability can be exploited by adversaries to launch potent pilot spoofing attack (PSA). In this paper, we propose a novel active RIS-aided covert PSA scheme for time-division duplex systems, where a passive eavesdropper manipulates the channel state information (CSI) estimation at the legitimate transceiver during the uplink stage and steers downlink data towards itself during the downlink stage. Crucially, without requiring perfect instantaneous CSI, a practical challenge for eavesdroppers, we maximize the average eavesdropping signal-to-noise ratio (SNR) by jointly designing the RIS reflection coefficients for both stages. To ensure covertness, we integrate an anti-energy ratio detection (ERD) mechanism that constrains the detection probability below a predefined threshold. The resulting non-convex optimization problem is solved via an efficient alternating optimization algorithm combined with penalty methods, handling the rank-1 constraints and statistical CSI uncertainties. Simulations demonstrate that the proposed scheme achieves up to 26 dB SNR gain over passive RIS-aided PSA and reduces ERD detection probability compared to traditional PSA. This work reveals the dual-edged nature of the active RIS: while enhancing security, it introduces new attack schemes demanding advanced countermeasures.| File | Dimensione | Formato | |
|---|---|---|---|
|
paper.pdf
accesso aperto
Tipologia:
2. Post-print / Author's Accepted Manuscript
Licenza:
Pubblico - Tutti i diritti riservati
Dimensione
4.71 MB
Formato
Adobe PDF
|
4.71 MB | Adobe PDF | Visualizza/Apri |
|
Covert_Pilot_Spoofing_Attack_via_Active_Reconfigurable_Intelligent_Surface.pdf
accesso riservato
Tipologia:
2a Post-print versione editoriale / Version of Record
Licenza:
Non Pubblico - Accesso privato/ristretto
Dimensione
3.84 MB
Formato
Adobe PDF
|
3.84 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/11583/3006176
