Skip to main content
QUICK REVIEW

[论文解读] Pilot Spoofing Attack by Multiple Eavesdroppers

Ke-Wen Huang, Hui‐Ming Wang|arXiv (Cornell University)|Jul 24, 2018
Wireless Communication Security Techniques参考文献 37被引用 3
一句话总结

本文提出了一种先进的导频欺骗攻击(PSA)策略,其中多个单输入单输出的窃听者协作,在TDD大规模MIMO系统中破坏信道估计,以最大化其窃听的信噪比(SNR)。作者提出MM-ADMM算法来求解非凸优化问题,在计算效率方面优于半定规划松弛基准,且性能接近最优。

ABSTRACT

In this paper, we investigate the design of a pilot spoofing attack (PSA) carried out by multiple single-antenna eavesdroppers (Eves) in a downlink time-division duplex (TDD) system, where a multiple antenna base station (BS) transmits confidential information to a single-antenna legitimate user (LU). During the uplink channel training phase, multiple Eves collaboratively impair the channel acquisition of the legitimate link, aiming at maximizing the wiretapping signal-to-noise ratio (SNR) in the subsequent downlink data transmission phase. Two different scenarios are investigated: (1) the BS is unaware of the PSA, and (2) the BS attempts to detect the presence of the PSA. For both scenarios, we formulate wiretapping SNR maximization problems. For the second scenario, we also investigate the probability of successful detection and constrain it to remain below a pre-designed threshold. The two resulting optimization problems can be unified into a more general non-convex optimization problem, and we propose an efficient algorithm based on the minorization-maximization (MM) method and the alternating direction method of multipliers (ADMM) to solve it. The proposed MM-ADMM algorithm is shown to converge to a stationary point of the general problem. In addition, we propose a semidefinite relaxation (SDR) method as a benchmark to evaluate the efficiency of the MM-ADMM algorithm. Numerical results show that the MM-ADMM algorithm achieves near-optimal performance and is computationally more efficient than the SDRbased method.

研究动机与目标

  • 设计一种由多个单输入单输出窃听者在TDD大规模MIMO系统中协同实施的导频欺骗攻击。
  • 通过污染上行链路信道训练,最大化下行链路数据传输期间的窃听信噪比(SNR)。
  • 同时考虑两种场景:基站未察觉攻击,以及基站尝试检测攻击。
  • 在检测感知场景下,确保攻击的检测概率低于预设阈值。
  • 开发一种高效且收敛的算法,用于求解由此产生的非凸优化问题。

提出的方法

  • 在未察觉和检测感知两种场景下,统一构建非凸优化问题以最大化窃听SNR。
  • 应用最小化-最大化(MM)方法构造一个上界原目标函数的代理函数,使其更易于优化。
  • 结合交替方向乘子法(ADMM)处理约束优化问题,实现分布式且高效的计算。
  • 采用半定规划松弛(SDR)方法作为基准,评估所提MM-ADMM算法的性能。
  • 利用KKT条件推导最优性必要条件,并证明在特定假设下,解必须具有秩一结构。
  • 利用随机矩阵理论证明,当窃听者数量不超过基站天线数量时,矩阵T = A^H A以概率1为满秩,从而支持秩一解的合理性。

实验结果

研究问题

  • RQ1多个窃听者如何通过污染TDD大规模MIMO系统中的上行链路信道训练,联合最大化其窃听SNR?
  • RQ2当基站未察觉导频欺骗攻击时,窃听者的最优策略是什么?
  • RQ3基站如何检测导频欺骗攻击的存在?应施加何种约束以限制检测概率?
  • RQ4在存在检测机制的情况下,攻击的有效性与可检测性之间的性能权衡如何?
  • RQ5能否设计一种高效且收敛的算法,求解由多窃听者导频欺骗攻击引发的非凸优化问题?

主要发现

  • 所提出的MM-ADMM算法收敛至非凸优化问题的驻点,确保了可靠的收敛性。
  • 数值结果表明,MM-ADMM算法在最大化窃听SNR方面实现了接近最优的性能。
  • 与基准SDR方法相比,MM-ADMM算法在高维场景下具有更高的计算效率。
  • 证明了最优解矩阵的秩为1(以概率1),从而简化了最优攻击波束成形器的结构。
  • 攻击的检测概率可被控制在阈值以下,使攻击在检测感知型基站下仍能实现隐蔽运行。
  • 随机矩阵理论的应用证实,当窃听者数量不超过基站天线数量时,矩阵T = A^H A以概率1为满秩。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。