{"id":"f0de3b80-aab2-4ce4-a757-6c798fdf8f61","arxiv_id":"2509.11117","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":7,"one_line_summary":"A physically consistent NR-RIS can covertly attack TDD systems by breaking channel reciprocity, and a DRL-based SecureCoder precoder can mitigate the damage.","lead":"This paper shows that a non-reciprocal reconfigurable intelligent surface can silently break the channel reciprocity assumption in time-division duplexing systems, harming throughput and enabling eavesdropping without extra transmission or synchronization. It also presents SecureCoder, a deep reinforcement learning based countermeasure that learns a more robust downlink precoder from uplink channel estimates and user rate feedback.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The central attack claim rests on the unvalidated assumption that a passive lossless NR-RIS can realize the unitary non-reciprocal scattering matrix used in all simulations; the paper defers to [35] for this result and does not simulate the circuit-level implementation.","rationale":"The paper is a coherent simulation study: the reciprocity-mismatch argument in Section II is mathematically sound given Φ ≠ Φ^T, and the three attack scenarios plus the DRL defense are clearly formulated. The graphs support the stated trends under the stated model. The single most load-bearing assumption, however, is the realizability of the non-reciprocal unitary scattering matrix. This is not a question of consensus—non-reciprocal components exist—but of whether the specific passive, lossless, continuously tunable two-port unit assumed in (9) is actually achievable with the circuit in Fig. 2. The paper does not provide the derivation, referring instead to the self-cited preprint [35]; no code or measurement is supplied. Because every numerical result inherits this model, a larger-than-expected insertion loss or a constrained phase relation would weaken the attack quantitatively, and could also shrink the observed advantage of SecureCoder. An independent circuit-level re-derivation or simulation, followed by a sensitivity rerun, would settle this. The reader's weakest_assumption aligns with this concern; I therefore agree with the conditional verdict and recommend no change.","tokens_in":19804,"tokens_out":15996,"duration_ms":192432,"concrete_test":"Independently reproduce the derivation of [35] for the NR dual-element unit of Fig. 2, or perform a full-wave/circuit simulation (e.g., ADS/SPICE) of a 3-port circulator terminated in a tunable varactor and connected to two dipole/microstrip RIS elements. Extract the achievable 2×2 S-matrix over the band of interest, including realistic circulator loss and isolation. Then rerun the Section V experiments (Fig. 5 and Fig. 8) using the lossy, possibly phase-constrained S-matrix in place of the ideal [[0,e^{jφ1}],[e^{jφ2},0]] blocks. If the ergodic sum-rate degradation with N=256 drops from the reported ~90% (e.g., to <50%), or if SecureCoder's relative gain over ZF is no longer significant, the central claims require revision.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central claim—that a physically consistent NR-RIS can covertly cause severe rate degradation and leakage—rests on the specific scattering matrix model of Section II-C: an N-port unitary, non-symmetric matrix Φ assembled from 2×2 blocks [[0,e^{jφ1}],[e^{jφ2},0]]. This model is not derived or validated here; it is attributed to the self-cited arXiv preprint [35]. All attack simulations (Figs. 4-10) and the SecureCoder results (Figs. 11-13) instantiate Φ directly as an abstract matrix rather than simulating the 3-port circulator + tunable impedance circuit of Fig. 2. If realistic circulator insertion loss, finite isolation, or bandwidth constraints make the achievable S-matrix non-unitary (e.g., |S12||S21|<1) or constrain the phases (e.g., S21 fixed relative to the circulator), the magnitude of the reciprocity mismatch Φ−Φ^T shrinks, and the observed >90% rate loss could be materially smaller. Since the 'physically consistent' label is the paper's claimed advance over [29], this untested assumption is load-bearing: a weaker physical model would reduce both the attack severity and the apparent need for SecureCoder.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies a covert attack, termed CRACK, against TDD MU-MISO downlink precoding. An adversarial non-reciprocal RIS (NR-RIS) with a non-symmetric scattering matrix breaks the usual uplink/downlink channel reciprocity, so the BS designs MRT or ZF precoders from uplink estimates that do not match the actual downlink channel, degrading throughput and increasing eavesdropping success. The paper models the NR-RIS using a physically motivated two-port unit with a 3-port circulator, evaluates three attack variants (blind, eavesdropping-aided, knowledge-driven), and proposes SecureCoder, a PPO-based deep reinforcement learning countermeasure that learns a robust precoder from uplink CSI and user rate feedback. Numerical simulations (Figs. 4–13) demonstrate large rate/secrecy degradation for MRT/ZF and partial recovery with SecureCoder.","tokens_in":20185,"tokens_out":9023,"duration_ms":105992,"significance":"If the NR-RIS scattering model is physically realizable, the paper identifies a serious and highly covert threat to TDD systems that does not require synchronization, CSI, or rapid configuration changes—a significant step beyond prior reciprocity attacks based on quickly varying or idealized non-diagonal RIS models. The inclusion of the structural scattering term (Φ−I_N) in the cascaded channel model is a useful physical refinement. The paper also provides a first countermeasure and evaluates it against MRT, ZF, and DRL baselines. However, the central attack results depend on an unvalidated physical realizability assumption inherited from a self-cited preprint, and the DRL results are presented without statistical confidence. The work is valuable but requires additional validation before the quantitative claims can be considered robust.","major_comments":[{"comment":"The entire attack and countermeasure analysis assumes that a passive lossless NR dual-element unit can realize the unitary non-symmetric scattering matrix Φ = [[0,e^{jφ1}],[e^{jφ2},0]]. This is asserted with reference to [35], but no derivation or independent validation is provided in this manuscript. Since this assumption is load-bearing for all simulation results (Figs. 4–13), please include a self-contained derivation or a circuit-level S-parameter verification. In particular, quantify the effect of non-ideal circulator isolation/insertion loss and finite antenna matching; if |S12| and |S21| fall below 1, the reciprocity mismatch Φ−Φ^T is reduced and the >90% rate loss observed in Fig. 5 may shrink materially.","section":"Section II-C, Eq. (9)"},{"comment":"The DRL results are presented as single learning curves and single point estimates. DRL is sensitive to random seeds, initialization, and hyperparameters. To support the claim that SecureCoder reliably mitigates CRACK, please report the mean and standard deviation (or confidence intervals) over multiple random seeds, and specify the number of training episodes, environment setups, and hyperparameter sensitivity. Without this, the reported 'nearly 300% enhancement' and the secrecy-outage improvements in Fig. 13 may not be reproducible.","section":"Section V-E, Figs. 11-13"},{"comment":"The comparison of NR-RIS with the ND-RIS and D-RIS benchmarks may be confounded by the use of the structural scattering term (Φ−I_N) in the NR-RIS cascaded channel model. The benchmarks are described 'as assumed in [24,25,28,29]', which conventionally use Φ (without the −I_N term). If the benchmarks do not include structural scattering, the improved attack performance of NR-RIS in Fig. 8 could be partly due to this additional term rather than non-reciprocity. Please clarify whether the benchmarks also use the (Φ−I_N) model, or provide a version of Fig. 8 in which all RIS models adopt the same structural scattering assumption.","section":"Section II-A and Section V-B"}],"minor_comments":[{"comment":"The reward is defined as r_t = Σ_k log(1 + r_{t,k}), where r_{t,k} is already the achievable rate log(1+SINR). This yields a double logarithm of SINR. Please clarify whether the intended reward is Σ_k log(1+SINR_{t,k}) or Σ_k log(r_{t,k}), and justify the current form.","section":"Section IV-B, Eq. (11)"},{"comment":"The discount factor is listed as γ=0, which contradicts the text in Section IV-B that says the agent maximizes 'long-term cumulative reward.' For an i.i.d. channel per coherence block, γ=0 is acceptable, but it makes the problem a contextual bandit; please clarify or correct the value.","section":"Table I"},{"comment":"The training convergence plot lacks axis labels and a clear legend. Please add labels, and report the reward scale and the number of episodes used for training in the text.","section":"Figure 11"},{"comment":"The sentence 'the reconfiguration interval △t of the RIS ∆t is significantly shorter' uses duplicate symbols for the same quantity. Please edit.","section":"Section III-A"},{"comment":"The contribution list states 'We introduce a novel NR-RIS model using multiport network analysis,' but the model is adopted from [35]. Please revise the wording to avoid overclaiming novelty.","section":"Section II-C"},{"comment":"Reference [35] is an arXiv preprint; if a published version exists, please cite it. Also, footnote 3 says the source code 'will be available soon'; for reproducibility, provide a working link or include the code as supplementary material.","section":"References/Code"}],"recommendation":"major_revision","confidential_remarks":"The paper relies heavily on the authors' own prior work [35] for the physical NR-RIS model; the new contributions here are the CRACK application, the block architecture, and the DRL countermeasure. The manuscript would be considerably strengthened by including the derivation/sensitivity analysis for the scattering model and by reporting DRL results with multiple seeds. I see no evidence of circularity or fabrication; the concern is unvalidated physical assumptions and insufficient statistical rigor for the DRL claims."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Worth a look if you follow RIS security, but keep the right expectations. The genuinely new pieces are the block-based architecture for the non-reciprocal RIS, the three attack scenarios (blind CRACK, CRACK-aided eavesdropping, knowledge-driven CRACK), and the SecureCoder DRL countermeasure. The system model in Sections II and III is spelled out cleanly; the reciprocity mismatch argument for why ZF breaks down is sound and the block-size result—where L=8 performs like a fully connected surface—is a nice practical point.\n\nThe soft spots are real. The central attack model assumes each NR dual-element unit realizes the unitary non-symmetric scattering matrix [[0,e^{jφ1}],[e^{jφ2},0]] with arbitrary phases, citing the authors' own prior work [35]. This paper does not derive that result, nor does it simulate the circuit with circulator losses, finite isolation, or bandwidth limits. If those effects make the achievable matrix non-unitary or constrain the phases, the reciprocity mismatch shrinks and the reported 90% rate losses could be materially smaller. That assumption is load-bearing, and the paper's claim to improve on the idealized ND-RIS model of [29] rests on it. The stress-test note is on target; the authors need to either provide an independent derivation or, better, S-parameter measurements or a circuit-level simulation.\n\nThe DRL results are also presented without confidence intervals, repeated seeds, or released code. The paper says code will be available soon, so right now the SecureCoder curves are not reproducible. That is a fixable but genuine deficiency, especially given the 300% improvement claim. The phrase \"physically undetectable\" is an overclaim as stated; it is undetectable only against the specific monitoring and estimation strategies considered.\n\nThat said, the paper is honestly written and the math that is derived here is internally consistent. It does not hide its reliance on prior work. The problem is that the most important physical premise is deferred rather than demonstrated. This is a subfield contribution, not a paradigm shift, but it is a legitimate question for the RIS-security community.\n\nBottom line: it deserves a serious referee, but only with a request for the missing reproducibility and for a sensitivity analysis or direct validation of the non-reciprocal unit model. I would not desk-reject it, and I would not accept it as is.","headline":"A plausible extension of the authors' own CRACK work with a clean system model, but the physical realizability of the NR-RIS scattering matrix is inherited and unvalidated, and the DRL results need statistical support.","tokens_in":20689,"tokens_out":1615,"would_cite":false,"duration_ms":25635,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A physically consistent non-reciprocal smart surface can silently break TDD channel reciprocity, cutting downlink throughput and enabling passive eavesdropping, while a deep-reinforcement-learning precoder restores most of the lost performa","keywords":["channel reciprocity attack","non-reciprocal RIS","TDD MU-MISO","physical layer security","passive jamming","deep reinforcement learning","precoding","eavesdropping"],"falsifier":"Build a prototype NR dual-element unit (circulator plus tunable impedances) and measure its 2×2 scattering parameters over the intended band. If |S12| and |S21| cannot both approach unity with independently settable phases, the attack model overstates the threat. Alternatively, in the paper's MU-MISO simulation, give the base station a way to separate the direct user-BS channel from the RIS-induced component (e.g., a known RIS training sequence); if the attack's throughput collapse disappears when the BS can identify and null the RIS path, then the unidentifiability assumption is the load-bear","tokens_in":19694,"feed_emoji":"📡","tokens_out":9588,"duration_ms":104599,"temperature":0.7,"pith_summary":"This paper argues that a passive, physically realizable non-reciprocal reconfigurable intelligent surface (NR-RIS) can covertly attack time-division duplex (TDD) wireless systems by breaking the channel-reciprocity assumption that the base station uses to compute downlink precoding. Because the NR-RIS scattering matrix is non-symmetric, the uplink channel the base station estimates differs from the actual downlink channel, so otherwise well-designed precoders—maximum-ratio transmission (MRT) and especially zero-forcing (ZF)—leak energy as multiuser interference and toward eavesdroppers. The attack requires no CSI about the legitimate network, no synchronization with its pilot or data phases, no active transmission, and no fast reconfiguration, making it look like ordinary multipath. The paper further proposes SecureCoder, a deep-reinforcement-learning precoding framework that uses only the estimated uplink CSI and user rate feedback to restore throughput and secrecy. If correct, this means TDD systems with conventional reciprocity-based precoding are vulnerable to a stealthy, low-cost attack that cannot be countered by adding base-station antennas or by standard channel-estimation refinements.","feed_headline":"Silent non-reciprocal RIS cuts TDD downlink rates ~90%","feed_subtitle":"Uses no power, channel info, or sync: one static surface breaks reciprocity; deep-RL precoding restores secure links.","key_machinery":"The engine of the attack is the non-symmetric, unitary scattering matrix Φ of the NR-RIS, realized by pairing elements into two-port 'NR dual-element units' built from a 3-port circulator and tunable reactive loads; the resulting block-diagonal Φ has off-diagonal entries e^{jφ1} and e^{jφ2} and no diagonal terms, so Φ ≠ Φ^T. When placed in the channel, the surface contributes (Φ − I_N) to the uplink path and (Φ − I_N)^T to the downlink path, and because the base station cannot separate the direct user-BS channel from the RIS-induced channel, it precodes against a reciprocal channel that does not exist. The block architecture (small paired groups, e.g., L=8) makes the attack nearly as effecti","core_discovery":"Central claim: a physically consistent NR-RIS, built from circulator-loaded two-port units realizing Φ = [[0,e^{jφ1}],[e^{jφ2},0]] with Φ ≠ Φ^T, breaks the TDD reciprocity assumption H_down = H_up^T. Because the uplink estimate includes (Φ − I_N) while the true downlink uses its transpose, the mismatch persists even for a static surface that looks like natural scattering. In simulation this cuts ergodic sum rate by about 90% (MRT) and 92% (ZF) at N=256, M=128, while raising secrecy outage and strengthening with partial CSI. The countermeasure, SecureCoder, is a deep-reinforcement-learning agent mapping uplink CSI to a precoder; in simulation it restores much of the lost rate and secrecy.","pith_inferences":["Editorial inference: if the circulator-based NR-RIS unit works as modeled, other reciprocity-dependent protocols—physical-layer key generation, channel sounding, reciprocity calibration—face the same covert attack, so defenses may need explicit reciprocity-violation detection (e.g., comparing downlink feedback with uplink estimates) rather than relying on channel statistics.","Editorial inference: SecureCoder's learned mapping suggests the BS could treat the uplink-downlink mismatch as an observable environment state; a similar agent could be used online to detect CRACK by flagging rate anomalies that appear without any detectable channel-time variation.","Editorial inference: the attack's dependence on the RIS-BS path-loss exponent means deployment geometry matters—an attacker who can place the surface near the base station gets a disproportionately strong effect; defenders could screen for suspicious stationary scatterers close to the BS.","Editorial inference: the block-size result implies that even a partially interconnected non-reciprocal surface, built with modest switching complexity, could pose a realistic threat, so the countermeasure problem is not limited to laboratory-scale fully connected designs."],"forward_implications":["TDD systems that derive downlink precoders from uplink measurements are exposed to a passive, static RIS attack that needs no CSI or synchronization; adding base-station antennas does not remove the impairment once the surface-BS link is strong enough.","Zero-forcing precoding suffers more than MRT, because the reciprocity mismatch destroys the orthogonality that ZF is built on and turns the precoder into a source of inter-user interference.","A modest block size (around 8 paired elements) achieves nearly the same attack strength as a fully interconnected non-reciprocal surface, lowering the attacker's hardware complexity.","The same surface enhances passive eavesdropping: the distorted precoder scatters energy away from intended users and raises secrecy outage probability, even when the attacker never optimizes for the eavesdropper.","SecureCoder, trained on uplink CSI and rate feedback, restores a substantial fraction of the downlink throughput and secrecy in the simulated scenarios and also mitigates earlier diagonal-RIS passive jamming attacks."],"fun_headline_variants":["Static non-reciprocal RIS crushes TDD rates by 90%","Covert RIS attack cuts downlink 90% without power or sync","Deep-RL precoder restores secure links after RIS reciprocity break","Nonreciprocal RIS: silent 90% rate drop, deep-RL fix","One static RIS breaks TDD assumptions, deep-RL saves the day"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The attack's severity rests on the assumption that a unit built from a 3-port circulator and tunable reactances can physically realize the ideal non-reciprocal scattering matrix [[0, e^{jφ1}], [e^{jφ2}, 0]] with high efficiency across the operating bandwidth; if the unit is lossy, narrowband, or needs active amplification, the simulated rate and secrecy losses may not materialize.","fun_headline_variants_meta":{"raw":{"variants":["Static non-reciprocal RIS crushes TDD rates by 90%","Covert RIS attack cuts downlink 90% without power or sync","Deep-RL precoder restores secure links after RIS reciprocity break","Nonreciprocal RIS: silent 90% rate drop, deep-RL fix","One static RIS breaks TDD assumptions, deep-RL saves the day"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000545,"raw_usage":{"total_tokens":2466,"prompt_tokens":789,"completion_tokens":1677,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":533,"completion_tokens_details":{"reasoning_tokens":1579}},"tokens_in":533,"tokens_out":1677,"duration_ms":12501,"temperature":1.0,"reasoning_tokens":1579,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-04T17:03:12.107372+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Build a prototype NR dual-element unit (circulator plus tunable impedances) and measure its 2×2 scattering parameters over the intended band. If |S12| and |S21| cannot both approach unity with independently settable phases, the attack model overstates the threat. Alternatively, in the paper's MU-MISO simulation, give the base station a way to separate the direct user-BS channel from the RIS-induced component (e.g., a known RIS training sequence); if the attack's throughput collapse disappears when the BS can identify and null the RIS path, then the unidentifiability assumption is the load-bear","supporting_citations":[],"review_version":1}