{"id":"dd55bb91-791b-486a-9249-c839d654938c","arxiv_id":"2602.20045","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A dual-layer beamforming design for ISAC systems uses artificial noise and engineered ambiguity-function sidelobes (artificial ghosts) to degrade both communication and sensing eavesdropping without Eve channel knowledge.","lead":"This paper designs transmit beamforming for MIMO-OFDM ISAC systems so that artificial noise and fake 'ghost' targets jointly block both communication and sensing eavesdroppers. It is worth reading because 6G integrated sensing and communication lacks defenses against passive sensing eavesdroppers that work without knowing the adversary's channel.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Sensing-security claim rests on Assumption 3 (Eve cannot know target AoD) but no argument prevents a capable Eve from estimating it from the same transmissions; if it can, the AG layer is ineffective.","rationale":"The reader's weakest assumption is exactly the load-bearing premise. The central claim—robust sensing security even with perfect reference recovery—hinges on the Eve being unable to identify the true AoD among the ghost peaks. All other issues (index inconsistencies in Eq. 22, missing convergence analysis, Monte-Carlo details, internal inconsistency in Section V.D) are secondary: even if Eq. 22 were correct and the simulations flawless, the security would still fail against an Eve that can estimate the AoD, because the AF is a property of the transmitted signal and is identical for all receivers. The paper grants the Eve enough capability to estimate AoD (large array, perfect reference recovery, beam-sweeping observation) without providing a countermeasure. This is not a disagreement with the existence of the optimization framework, but a missing justification for a security claim. The concrete test—giving the Eve the same angle-estimation capability and evaluating the detection probability—directly settles whether the assumption is secure. If the Eve's detection probability rises to the BS level, the two-layer design reduces to one layer (AN) for any Eve with AoD knowledge, and the paper's advertised 'robust even when the Eve recovers the reference perfectly' is not supported. Therefore, the CONDITIONAL verdict is appropriate: the paper's contribution is plausible but requires either a stronger justification of Assumption 3 or a design that actually prevents AoD estimation at the Eve.","tokens_in":20805,"tokens_out":11185,"duration_ms":109723,"concrete_test":"Re-run the Section V simulations with a modified Eve that first estimates the target AoD from the received echo using MUSIC or maximum-likelihood over the transmit-angle dimension (using N_mr=24 antennas and the perfectly recovered reference), then computes the delay-Doppler map at that estimated angle, applies CFAR with P_fa=10^-5, and measures the correct-detection probability. If this probability approaches the BS's curve in Fig. 6 (i.e., ghosts at other angles are discarded), then the AG layer's security gain collapses when the Eve can learn θ_l,t, confirming that Assumption 3 is load-bearing.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's second security layer—artificial ghosts that deceive sensing Eves—depends entirely on Assumption 3 (Section II): the BS knows the true target AoD, while the sensing Eve does not. The BS suppresses ghost peaks by filtering at the known target angle (Section V.D, Fig. 9). Yet the Eve is granted capabilities (Assumptions 1 and 4) that should make AoD recoverable: N_mr >> N_t antennas, perfect reference-signal recovery, and perfect AoA estimation. In particular, the beam-sweeping stage that 'realizes' Assumption 3 is an over-the-air transmission the Eve can observe; with a calibrated array it can estimate the transmit steering vectors and hence the target AoD from the echo. More directly, the AF (22) is the same for all receivers (it depends only on the transmitted W and Q); if the BS's mainlobe at (0,0,θ_l,t,θ_l,t) is unity, the Eve's matched filter will show a peak there too. The ghosts are simply additional sidelobes at different angles. An Eve that knows θ_l,t can ignore those other angles and retain the true target, so the detection-probability reductions in Figs. 6–9 reflect only the Eve's claimed ignorance, not a physical security barrier. The paper offers no analysis of the Eve's achievable AoD estimation error, no waveform design constraint that prevents it, and no argument that beam-sweeping information is unavailable to the adversary.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper proposes a two-layer physical-layer security design for MIMO-OFDM ISAC systems. The first layer injects artificial noise (AN) to degrade the reception of communication eavesdroppers and to limit the quality of the reference signal available to sensing eavesdroppers. The second layer shapes the three-dimensional ambiguity function to place artificial ghost (AG) peaks at selected angle–delay–Doppler coordinates, so that sensing eavesdroppers are misled, while the legitimate BS can suppress these ghosts because it knows the true target angle of departure. The transmit beamformers and AN covariance are jointly optimized to maximize the BS post-matched-filter sensing SNR subject to constraints on Eve reference-signal rate, AG peak and sidelobe levels, worst-case secrecy rate, and power, using SDR, DC surrogates, and Gaussian randomization. Simulations demonstrate trade-offs among sensing SNR, secrecy rate, and detection probabilities for the BS and sensing Eves.","tokens_in":21030,"tokens_out":10026,"duration_ms":93192,"significance":"If the security claims are substantiated, the paper would make a useful contribution to ISAC physical-layer security by unifying AN-based and ambiguity-function-based defenses in a single optimization framework. The problem formulation is systematic, and the SDR/DC solution pipeline is standard and reproducible. The paper explicitly models worst-case Eve capabilities (perfect reference recovery, large arrays) and provides extensive numerical results. However, the central security claim rests on an unexamined asymmetry in knowledge of the target AoD (Assumption 3), and the 'no CSI' claim is stronger than the formulation actually implements. These issues need to be resolved before the contribution can be accepted as a robust security mechanism.","major_comments":[{"comment":"The AG security layer relies entirely on the assumption that the BS knows the true target AoD while the sensing Eve does not. But the ambiguity function in (22) is a function only of the transmitted signals W and Q and is observable by all receivers. The BS's mainlobe at (0,0,θ_l,t,θ_l,t) is present in the Eve's matched-filter output as well. Given the capabilities granted to the Eve in Assumptions 1 and 4 (N_mr >> N_t, perfect reference recovery, perfect AoA estimation), it is not argued why the Eve cannot estimate θ_l.t, e.g., from the beam-sweeping stage that 'realizes' Assumption 3 or from joint multi-dimensional estimation across its array. If the Eve can estimate the true AoD, it can apply the same angular filtering as the BS, and the detection-probability reductions in Figs. 6–9 overstate the security provided by the AG layer. Please provide an explicit adversary model for AoD est","section":"Section II, Assumption 3; Section V.D, Fig. 9"},{"comment":"The abstract claims the design does not require Eve CSI, but constraints (29c) and (29f) involve sums over sets M_r and M_c and use explicit Eve angles θ_mr and θ_mc in the channel models (25) and (27). Under Assumption 2 (the BS has no knowledge of Eve positions or existence), these sets and angles are unavailable. To substantiate the Eve-agnostic claim, the constraints should be robust over a continuum of angles (e.g., worst-case over [-π/2, π/2]) or the claim should be softened. The simulations place Eves at fixed locations (e.g., (3,1) and (2,-8)), so they do not demonstrate operation without Eve knowledge.","section":"Section II.E, Assumption 2; (29c), (29f)"},{"comment":"The AG coordinates are fixed inputs ((0,5,62°), (0,2,35°), (3,4,40°)), and constraints (29d)–(29e) force the AF to have peaks at those coordinates. Consequently, the appearance of ghosts in Fig. 7(b) and part of the detection-probability reduction in Fig. 6 are direct consequences of the design constraints rather than independent evidence that the AGs confuse the Eve. Please include a baseline that allocates the same power to sidelobe shaping at arbitrary (non-AG) locations, or report the probability that the Eve's strongest peak is at the true target (not merely the presence of extra false alarms). In addition, report statistical variability over multiple noise realizations for the detection-probability curves, since only single curves are shown.","section":"Section V, AG coordinates; (29d)–(29e)"},{"comment":"The convexity claim for problem (34) is not fully transparent. Constraint (34b) is written as γ ≥ η_B, but γ in (20) is defined in terms of the original beamforming matrix W_{nc,ns}, not the lifted rank-one variables W_{nc,ns,k}. After SDR, γ should be explicitly expressed as (β²|a_r^H(θ_l,B)|²/σ_r²) Tr(a_t(θ_l,t)a_t^H(θ_l,t) Σ_k W_{nc,ns,k}), which is linear. Similarly, the matrices ar{W}^{(e)}_{nc,ns}, W^{(e)}, ar{Q}^{(e)} used in (30)–(33) are not defined in the main text; they are introduced in the notation block of (22). Please state these definitions and show that each constraint in (34) is convex in the final variables.","section":"Section IV.B, (34)"}],"minor_comments":[{"comment":"PSL_l is actually the AF value at a specific ghost coordinate g, not the peak sidelobe level. This naming is confusing; suggest renaming it 'ghost peak level' or clarifying the indexing in (29d).","section":"Equation (23)"},{"comment":"The subscripts g are missing; as written, PSL_l and ISL_l appear to be scalars per target, but (23) defines PSL_l for each ghost g. Please add the g index consistently.","section":"Equations (29d)–(29e)"},{"comment":"The quantity C_mr is called 'average data rate' but is actually the mutual information of a hypothetical LoS channel with AN treated as noise. Since the link to reference-signal estimation accuracy is not derived, please state explicitly that this is a design surrogate.","section":"Equation (25)"},{"comment":"The caption says the sensing Eve is at (3,1) in (b) and (e) but at (30,10) in (c) and (f); earlier in Section V the default Eve location is (3,1). Please clarify which locations are used in each subfigure.","section":"Section V.D, Fig. 7 caption"},{"comment":"The worst-case secrecy rate S_k = min_{m_c} [C_k - C_{k,m_c}]^+ requires knowledge of the set M_c. Under Assumption 2 this set is unknown; see major comment 2. A robust formulation over all angles would avoid this inconsistency.","section":"Section IV.A, (29f)"},{"comment":"The convergence criterion checks ar{W} and Q but not the surrogate linearization points; please cite or state a standard DC convergence result to justify termination.","section":"Algorithm 1"}],"recommendation":"major_revision","confidential_remarks":"The paper addresses a timely and important problem and the optimization framework is technically competent. However, the security contribution depends on an unexamined asymmetry in AoD knowledge between the BS and the sensing Eve; without an analysis of the Eve's AoD estimation capability, the AG layer is not established as a physical security barrier. The 'no CSI' claim also appears stronger than the formulation delivers. I recommend major revision, with emphasis on the adversary model for AoD estimation and on a robust (or explicitly sector-based) Eve-agnostic formulation."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear colleague,\n\nThe paper is a serious engineering attempt at a real gap: securing both communication and sensing in ISAC against passive Eves without Eve CSI. The two-layer idea—AN to spoil the sensing Eve's reference, plus AF-shaped artificial ghosts in angle-delay-Doppler—is new in this combination, and the optimization pipeline (SDR, DC surrogates, Gaussian randomization) is standard but competently put together. If the threat model held, the four-way trade-off plots and the CFAR detection results would be a useful addition to the ISAC security literature.\n\nThe soft spot is the threat model, not the math. Assumption 3 says the BS knows the target AoD and the Eve does not. But the Eve is handed, in Assumptions 1 and 4, a large antenna array, perfect reference recovery, and perfect AoA estimation. The AF in (22) is built from the same transmit signal for every receiver. If the BS's mainlobe sits at the true AoD, the Eve's matched filter will show a peak there too. The ghosts are additional peaks at other angles. An Eve that can estimate the transmit angle—and there is no argument in the paper that it cannot, given the capabilities already granted—would simply look at the true angle and ignore the ghosts. The detection-probability reductions in Figs. 6–9 then reflect the Eve's assumed ignorance rather than a physical barrier. This does not invalidate the AN layer, but it breaks the stronger claim that sensing security is ensured even under perfect reference recovery.\n\nThere are smaller issues worth fixing: constraint (29c) is written against Eve indices even though the BS has no Eve CSI; the derivation of (22) is compressed and appears to have index inconsistencies; Algorithm 1 has no convergence analysis; Fig. 6 has no error bars or Monte Carlo details; Section V.D says both that AGs are absent from the BS DD map and that they are present in the BS DA profile; and there are no baselines against the closest AF-engineering work [30], [31].\n\nWho should read it: people working on ISAC physical-layer security, especially those thinking about sensing-Eve models. The optimization framework is reusable, and the trade-off study is informative. I would send it to peer review rather than desk-reject, but with a strong request that the authors either justify Assumption 3 or weaken the claims accordingly.\n\nRecommendation: engage with it, but with the threat model as the central point.","headline":"Solid two-layer ISAC security optimization with an unjustified threat-model asymmetry that undermines the sensing-security claim.","tokens_in":21706,"tokens_out":10711,"would_cite":false,"duration_ms":101095,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that a single transmit-beamforming design can simultaneously protect MIMO-OFDM ISAC systems against passive communication and sensing eavesdroppers without knowing their CSI, by injecting artificial noise and embedding art","keywords":["ISAC","MIMO-OFDM","physical layer security","sensing eavesdropper","artificial noise","artificial ghosts","ambiguity function","beamforming"],"falsifier":"Run the proposed design against a sensing Eve that performs joint 3-D maximum-likelihood estimation of angle, delay, and Doppler (using the same beam-sweeping stage and large antenna array the paper grants it) and measure correct target detection probability; if it remains close to the no-security baseline, the second layer is falsified.","tokens_in":20523,"feed_emoji":"📡","tokens_out":4096,"duration_ms":37557,"temperature":0.7,"pith_summary":"The paper proposes a transmit-beamforming design for MIMO-OFDM ISAC that secures both communication and sensing against passive eavesdroppers whose CSI is unknown. It does this in two layers: artificial noise injected into the beamformer interferes with communication eavesdroppers and degrades the reference signal that sensing eavesdroppers need for matched filtering; and the same beamformer shapes the 3-D ambiguity function to place high-energy artificial ghosts at fake angle-delay-Doppler coordinates. Legitimate receivers can suppress those ghosts because the BS is assumed to know the true target angles, while sensing eavesdroppers cannot, so the ghosts trigger false detections and lower the Eve's probability of identifying real targets. The design is posed as a four-way trade-off optimization that maximizes the legitimate sensing SNR subject to secrecy-rate, Eve-reference-rate, and peak/ISL constraints. Simulations with CFAR detection show the Eve's detection probability drops significantly while the BS's sensing remains usable.","feed_headline":"One beamforming design fakes radar ghosts to blind ISAC eavesdroppers","feed_subtitle":"Two-layer defense: artificial noise plus ghost targets keeps legitimate sensing usable while cutting eavesdropper detection.","key_machinery":"The central object is the three-dimensional ambiguity function of the MIMO-OFDM waveform — the matched-filter output over angle, delay, and Doppler. The paper expresses this function as a linear function of the per-subcarrier per-symbol transmit covariance matrices for user beams and artificial noise (block-diagonal matrices W and Q), which turns waveform shaping into a convex problem after surrogate approximations. Peak-sidelobe-level (PSL) and integrated-sidelobe-level (ISL) constraints force the chosen ghost coordinates to have high response; the artificial-noise covariance simultaneously lowers the sensing Eve's reference-signal rate. The legitimate BS's ability to suppress ghosts rests","core_discovery":"On its own terms, the paper's central claim is that one jointly designed transmit beamformer can simultaneously defend an ISAC system against two passive adversaries without knowing their CSI: a communication Eve trying to decode user data and a sensing Eve trying to estimate target angle, delay, and Doppler from reflected echoes. The first defense uses artificial noise to limit the sensing Eve's reference-signal quality (constraint on average data rate at the Eve) while jamming communication Eves. The second defense shapes the waveform's ambiguity function so that artificial peaks appear at chosen angle-delay-Doppler cells; the legitimate BS, knowing the true target AoD, filters them out, b","pith_inferences":["If a sensing Eve is allowed to estimate AoD jointly rather than treat each angle hypothesis separately, the premise of Assumption 3 disappears; the same beam-sweeping stage that realizes the assumption would reveal the true AoD to the Eve, collapsing the second layer. This is not tested in the paper.","The AG mechanism is waveform-agnostic in spirit; a similar ambiguity-function shaping could be applied to OTFS or other delay-Doppler waveforms, provided the reference-signal degradation and AoD-secrecy assumptions carry over.","A natural testable extension is an adaptive adversary that runs a joint multi-dimensional estimator over angle-delay-Doppler and compares detection probability against the paper's per-dimension MF assumption; if detection probability does not drop materially, the AG layer's effectiveness would need revisiting."],"forward_implications":["Sensing eavesdropping can be mitigated in ISAC even when the transmitter has no CSI of the eavesdropper, closing a gap left by prior AN-only designs.","Artificial ghosts in the full angle-delay-Doppler domain make it much harder for an Eve to tell true targets from fakes, unlike range-domain-only fake targets.","The two defense layers are complementary: AN handles Eves with poor reference signals, while AGs still degrade even a perfect-reference Eve.","Enforcing communication secrecy automatically tightens sensing security, since both benefit from stronger artificial noise.","There is a quantifiable four-way trade-off: raising secrecy requirements or ghost strength lowers the legitimate BS's sensing SNR and, beyond a point, its detection probability."],"fun_headline_variants":["ISAC defense: fake radar ghosts and noise blind eavesdroppers","Beamforming trick: artificial ghosts shield ISAC from Eves","One design, two defenses: AGs and AN secure ISAC","Fake ghosts and noise protect ISAC from passive Eves","Without CSI, ISAC beamforming blocks sensing and communication Eves"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The whole second security layer rests on the assumption (Assumption 3, Section II) that the legitimate BS knows each target's true angle of departure while sensing eavesdroppers do not; if a sensing Eve can also recover that angle — for example by listening to the initial beam-sweeping stage — it can resolve the true target among the artificial ghosts.","fun_headline_variants_meta":{"raw":{"variants":["ISAC defense: fake radar ghosts and noise blind eavesdroppers","Beamforming trick: artificial ghosts shield ISAC from Eves","One design, two defenses: AGs and AN secure ISAC","Fake ghosts and noise protect ISAC from passive Eves","Without CSI, ISAC beamforming blocks sensing and communication Eves"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00045,"raw_usage":{"total_tokens":2107,"prompt_tokens":752,"completion_tokens":1355,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":496,"completion_tokens_details":{"reasoning_tokens":1265}},"tokens_in":496,"tokens_out":1355,"duration_ms":8989,"temperature":1.0,"reasoning_tokens":1265,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-02T21:26:35.083452+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the proposed design against a sensing Eve that performs joint 3-D maximum-likelihood estimation of angle, delay, and Doppler (using the same beam-sweeping stage and large antenna array the paper grants it) and measure correct target detection probability; if it remains close to the no-security baseline, the second layer is falsified.","supporting_citations":[],"review_version":1}