Linning Peng

dblp:118/5837 · DBLP profile ↗
← Back
35ranked-venue papers
5as first author
26since 2021 · last 2026
0000-0001-5859-7119ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 5 first-author · 19 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Physical Layer Key Generation for V2X Communications with Doppler Shift Compensation
Wenhao Hou, Linning Peng
ICC3
2026 Adaptive Detrending-Based Channel Decoupling for Robust RF Fingerprint Identification Using CSI
Haichuan Peng, Linning Peng, Honghui Dai, Lingnan Xie, Junxian Shi, Wentao Jing
SECON2
2026 ES-PUF: A practical Physically Unclonable Function for wired networks using Ethernet physical-layer signals
Aiqun Hu, Linning Peng, Baofu Han, Tian Fang, Pan Feng
Comput. Networks4
2026 An Investigation of Power Amplifier Feature Modeling and Generation Method for RF Fingerprint Identification
abstract
Radio Frequency Fingerprint Identification (RFFI) exploits inherent hardware imperfections in devices for identification, and hardware imperfections generate Radio Frequency Fingerprint (RFF) including various features. The nonlinearity of the power amplifier (PA) is an important feature of RFF that has been widely used in radio frequency identification (RFFI) technology. In this paper, we constructed a testbed consisting of 60 IEEE 802.15.4 devices and a universal software radio peripheral (USRP) X310 software-defined radio (SDR) platform as the receiver for the estimation of PA parameters. Using this testbed, we modeled and estimated PA parameters using 60 real IEEE 802.15.4 devices to obtain real PA parameters and generate synthetic PA parameters for generation of synthetic devices. When the number of devices requiring identification or research is limited, this method can be employed to expand the device sample size to conduct identification model training or related studies. Experimental results demonstrated the feasibility of the synthetic data-based pre-training approach, whose performance approaches that of trained models without pre-training. In practical applications, legal device identity registration in device identification can be achieved with a low-cost fine-tuning compared to retraining.
Wentao Jing, Linning Peng, Junxian Shi, Lingnan Xie, Haichuan Peng
IEEE Internet Things J.2
2026 Occlusion-aware visual object tracking with explicit temporal state modeling and dual-memory mechanism
abstract
Visual Object Tracking (VOT) remains challenging under occlusion scenarios, where traditional trackers often suffer from feature degradation and target loss. To address this issue, we propose OASAMT, an occlusion-aware tracking framework that equips SAM2 with explicit temporal occlusion reasoning via two Temporal Convolutional Networks (TCNs) and a Dual-Memory Bank (DMB). Specifically, two TCN-based modules are designed to model temporal occlusion dynamics: the Temporal Occlusion Classifier (TOC) for inferring target occlusion states using confidence scores, mask IoU, and area ratio; and the Temporal Occlusion Predictor (TOP) for forecasting target bounding boxes during occlusion. The proposed DMB consists of a Non-Occlusion Memory Bank (N-OMB) and an Occlusion Memory Bank (OMB), explicitly decoupling reliable and occluded representations to prevent memory contamination and improve re-detection after occlusion. Additionally, to facilitate systematic evaluation under occlusion scenarios, we construct OccTrack, a dedicated occlusion-oriented dataset derived from four UAV-view benchmarks. Extensive experiments were conducted on the OccTrack, LaSOT, LaSOT ext , and GOT-10k datasets. The results demonstrate that OASAMT consistently outperforms SAM2.1 and other advanced trackers in both occlusion-specific and general tracking scenarios. The code and the dataset are available at https://github.com/ChaseFalcon99/OASAMT .
Linning Peng, Cheng Zeng 0002, Yi-Jin Pan, Jun-Bo Wang 0001
Pattern Recognit.2
2026 Toward Channel-Robust RF Fingerprint Identification Using Spectrum Averaging and High-Order Difference
Lingnan Xie, Linning Peng, Junqing Zhang
IEEE Trans. Inf. Forensics Secur.2
2026 Toward a Practical Key Generation System for V2X Communications
abstract
The vehicle to everything (V2X) serves as a crucial foundation for future intelligent transportation systems. Security concerns within the V2X have garnered significant attention and key generation from wireless channels have emerged as a promising technique. However, applying key generation to V2X is quite challenging because the fast moving vehicles result in very small coherence time and impact channel measurements correlation. This paper designed a practical V2X key generation by enhancing channel state information (CSI) reciprocity and carried out extensive experimental evaluation. In particular, the designed key generation consists of channel probing, CSI preprocessing, CSI compensation and key establishment. In the channel probing, we deliberately reduced the time delay between uplink and downlink transmissions, to allow almost simultaneous measurements. We then carefully designed CSI preprocessing to remove hardware carrier leakage and eliminate noise effects. Furthermore, we devised CSI compensation by using interpolation or deep learning prediction to further improve the reciprocity. Finally, key establishment converted the measured CSI into binary sequences and reconcile on a common key via low-density parity-check (LDPC) code. We adopted universal software radio peripheral (USRP) X310 platforms for channel measurements and implemented the above algorithms. We carried out extensive experiments in real-road environments with various vehicle speeds. These carefully designed algorithms enabled our system working robustly even in high mobility scenarios, e.g., 40 km/h. Experimental results demonstrated common and random key can be generated with a key block error rate (BER) less than 0.1.
Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu
IEEE Trans. Mob. Comput.2
2025 Towards Robust RF Fingerprint Identification Using Spectral Regrowth and Carrier Frequency Offset
Lingnan Xie, Linning Peng, Junqing Zhang
INFOCOM2
2025 A LoRa Radio Frequency Fingerprint Extraction Scheme Against Variable Channel Characteristics
abstract
Radio Frequency Fingerprint (RFF) recognition has emerged as a promising physical layer security technique, enabling the identification of wireless devices based on their unique RF characteristics. However, the performance of RFF recognition can be significantly hindered by interference stemming from variable channel conditions. To address this challenge, we propose a novel LoRa-based RFF extraction scheme that exploits the temporal variations in channel features. Initially, we compute the power spectrum by cross-correlating the received signal with a locally generated reference signal, effectively mitigating noise in the context of long-range LoRa communications. Subsequently, we derive both the linear and logarithmic differential spectra of the power spectrum based on received signals from different time instances, and then calculate the ratio of these two spectra to extract the RFF. Experimental results demonstrate that the proposed method exhibits strong resilience to channel variations, maintaining an average recognition accuracy above 96% across diverse environments and time intervals.
Yanbing Chen, Aiqun Hu, Linning Peng, Tianshu Chen
VTC2025-Fall3
2025 Towards Channel-Robust Radio Frequency Fingerprint Identification Using Contrastive Learning
abstract
Radio frequency fingerprint identification (RFFI) is an emerging device authentication technique that is based on intrinsic hardware impairments. Internet of things (IoT) devices can be identified and classified based on their wireless signals using RFFI. Developing a robust RFFI system that can maintain high classification accuracy across diverse communication scenarios is a critical challenge. In this paper, we proposed a contrastive learning-based RFFI approach to establish a channel-robust system using the spectrogram. Specifically, we leverage contrastive learning in the training stage, which has been implemented with data augmentation techniques to mitigate the influence of channels on RFFI. We carried out extensive experimental evaluations involving a public dataset and a self-collected dataset, both with ten LoRa devices. Utilizing these datasets, the performance of the system has been tested in various channel environments, including stationary, mobile, line-of-sight (LOS) and non-line-of-sight (NLOS) scenarios. The results demonstrated that our approach is effective and robust to channel variation, achieving 93% and 82% on static and dynamic channels. respectively.
Junqing Zhang, Guanxiong Shen, Linning Peng, Alan Marshall 0001
WCNC4
2025 Channel2Channel: Toward Robust Radio Frequency Fingerprint Extraction and Identification
abstract
In radio frequency fingerprint identification (RFFI) systems, mitigating channel interference remains a critical challenge. This paper introduces a robust RFFI system to tackle this issue effectively. Specifically, taking the IEEE 802.11 signal as the case study, a signal representation is designed based on the logarithmic spectrum, while an RFF extractor based on the U-Net neural network is employed which is guided by a proposed Channel2Channel (C2C) algorithm and powered by a designed data augmentation method. Furthermore, a collaborative identification mechanism is proposed based on a support vector machine (SVM) classifier, where a multi-frame RFF fusion method is designed to exploit the diversity across different frames of received signal. Extensive experimental evaluations are performed in various real-world scenarios using 7 mobile phones and a universal software radio peripheral (USRP) X310 receiver, where an average classification accuracy of 95.72% is obtained with a single frame of received signal, outperforming the neural network-based benchmarks, and an average accuracy of 99.46% is acquired with 10 signal frames based on the proposed collaborative identification method. In addition, the deployability of the system on a resource-constrained computing platform is also validated.
Lingnan Xie, Linning Peng, Junqing Zhang, Junxian Shi
IEEE J. Sel. Areas Commun.2
2025 Toward Channel-Robust and Receiver-Independent Radio Frequency Fingerprint Identification
abstract
Radio frequency fingerprint identification (RFFI) is an emerging method for authenticating Internet of Things (IoT) devices. RFFI exploits the intrinsic and unique hardware imperfections for classifying IoT devices. Deep learning-based RFFI has shown excellent performance. However, there are still remaining research challenges, such as limited public training datasets as well as impacts of channel and receive effects. In this paper, we proposed a three-stage RFFI approach involving contrastive learning-enhanced pretraining, Siamese network-based classification network training, and inference. Specifically, we employed spectrogram as signal representation to decouple the transmitter impairments from channel effects and receiver impairments. We proposed an unsupervised contrastive learning method to pretrain a channel-robust RFF extractor. In addition, the Siamese network-based scheme is enhanced by data augmentation and contrastive loss, which is capable of jointly mitigating the effects of channel and receiver impairments. We carried out a comprehensive experimental evaluation using three public LoRa datasets and one self-collected LoRa dataset. The results demonstrated that our approach can effectively and simultaneously mitigate the effects of channel and receiver impairments. We also showed that pretraining can significantly reduce the required amount of the fine-tuning data. Our proposed approach achieved an accuracy of over 90% in dynamic non-line-of-sight (NLOS) scenarios when there are only 20 packets per device.
Junqing Zhang, Guanxiong Shen, Linning Peng, Alan Marshall 0001
IEEE Trans. Inf. Forensics Secur.4
2025 An SNR-Aware Feature Reconstruction Method in Radio Frequency Fingerprint Identification
abstract
The radio frequency fingerprint (RFF) has gained significant traction in the identification of wireless Internet of Things (IoT) devices. However, RFFs extracted from wireless signals are inherently susceptible to noise, particularly for narrowband signals. Furthermore, the noisy domain adaptation (NDA) problem presents a substantial challenge for RFF identification due to the variable noise interference across different noisy domains. To address this, the squared cross power spectral density (SCPSD) as new device RFFs is derived theoretically as a function of signal-to-noise ratio (SNR). Combined with the proposed high-precision SNR estimation algorithm, SCPSDs under low SNR can be reconstructed to the same feature distribution as those under high SNR. Because of the interpretability, ten samples under high SNR from each device under test (DUT) and a shallow convolutional neural network (CNN) are trained for experimental evaluation on the NDA problem. Tested on 60 off-the-shelf ZigBee DUTs, the improvement of identification accuracy is around 26% for SNR between 5 dB and 10 dB, and the overall improvement is more than 20% compared to the baseline. It outperforms the three other compared methods across all testing SNR and is highly practical.
Junxian Shi, Linning Peng, Lingnan Xie, Aiqun Hu
IEEE Trans. Inf. Forensics Secur.2
2024 An Authentication Mechanism Based on Zero Trust With Radio Frequency Fingerprint for Internet of Things Networks
abstract
With the development of IoT and cloud networks, the security of edge networks, borderless networks and obscure networks are essential, so there are many security problems that need to be tackled, including over-trust in trust areas and security only based on security boundaries in traditional security architecture. According to characters of zero trust security architectures and integrative trust model, the zero trust architectures better adapt to handle these security problems compared to the integrative trust model for the Internet of Things (IoT) networks. Meanwhile, the radio frequency fingerprint (RFF) identification keeps high accuracy and high stability with researchers’ investigation, which makes RFF authentication feasible. Therefore, we propose a mechanism that combines the RFF authentication technique and zero trust architecture to improve security in IOT networks, including edge networks, borderless networks and obscure networks. The method resolves the difficulty of over-reliance on a trustable center or trust chain, and the method is suitable for borderless networks and obscure networks. Besides, this method resists data leakage, counterfeit attack and rouge AP attack with RFF authentication, and it can reduce the risk caused by compromised devices with zero trust concepts. With the analysis in the paper, the proposed method keeps high-level security and performance that method effectively against spoofing identity, tampering and information disclosure. The authentication accuracy of the method has reached 99%, and the authentication owns robustness in time cost and collision-resistant.
Wentao Jing, Linning Peng, Aiqun Hu
IEEE Internet Things J.2
2024 Channel-Robust Radio Frequency Fingerprint Identification for Cellular Uplink LTE Devices
abstract
Radio frequency fingerprint identification (RFFI) is a promising authentication mechanism for physical layer security. In this paper, we thoroughly validate the feasibility of using RFFI for cellular long-term evolution (LTE) devices. Firstly, we conduct simulations to examine the subtle impacts of hardware impairments on LTE signals. The simulated results reveal that I/Q imbalance and power amplifier non-linearity introduce significant distortions within in-band spectrum, forming unique hardware fingerprints. We then leverage the strong channel correlation between adjacent subcarriers and separate the channel-robust radio frequency fingerprints (RFF) from uplink demodulation reference signal (DMRS) in Msg3. Subsequently, we construct a hybrid feature matrix to serve as input for a shallow long short-term memory (LSTM) network. Due to the more effective channel mitigation strategy, our method outperforms three benchmarks in terms of classification accuracy under cross-scenario testing. Additionally, we explore the impacts of bandwidth configuration on RFFI, and experimental findings demonstrate that LTE terminals will exhibit more distinct RFF when occupying a larger number of physical resource blocks (RB) during transmission. We also investigate the stability of RFF towards frequency band variations. The results suggest that there will be a significant accuracy loss under training with one band but testing with another, indicating the importance of frequency band-independent feature extraction in practical environments. Lastly, we expose four key implications to pave the way for exploring corresponding solutions. To the best of our knowledge, it is the first performance evaluation of the RFFI system on different frequency bands and with multiple bandwidth configurations.
Linning Peng, Haichuan Peng, Ming Liu 0010
IEEE Internet Things J.1
2023 Channel-Robust Radio Frequency Fingerprint Identification for LTE Devices with Hybrid Feature
abstract
Radio frequency fingerprint (RFF) identification as a physical layer authentication technique by leveraging devices’ unique hardware-level imperfections in transmitted signals has been considered as a potential complement to combat spoofing attacks. In this paper, we develop a lightweight framework to identify long-term evolution (LTE) devices with intrinsic features extracted from Msg3. Channel-robust fingerprints from channel state information (CSI) in demodulation reference signal (DMRS) associated with physical uplink shared channel (PUSCH) are obtained. These modulation features are combined with transient-on features that are obtained from the cyclic prefix (CP). A hybrid feature matrix is constructed and fed into a shallow long short-term memory (LSTM) network, which improves the identification accuracy compared to using single feature representation. We carry out extensive experiments with five LTE devices in real-world environment via a pseudo base station. The robustness of our proposed scheme is evaluated by cross-scenario training and testing. Thanks to the hybrid information-rich feature matrix as input of network, the classification accuracy 90.90% obtained at 25 dB when training in static but testing in dynamic scenarios demonstrates that our scheme is channel-robust in the presence of channel variations.
Haichuan Peng, Linning Peng, Lingnan Xie, Junxian Shi, Wentao Jing
TrustCom2
2023 Robust RF Fingerprint Extraction Based on Cyclic Shift Characteristic
abstract
As a novel solution for identification of Internet of Things (IoT) devices, radio frequency fingerprint (RFF) has excellent features, such as uniqueness, stability, and nonreproducibility. We propose an RFF extraction method for a type of signals with the cyclic shift characteristic (CSC). The extracted RFF is robust in terms of data independence, noise resistance, and channel immunity. A unified RFF representation is derived by the cross-power spectral density (CPSD)-based extraction method, which utilizes all different symbols within one signal frame under the random sending symbol conditions. Theoretical analysis demonstrates that this representation can be superimposed to obtain effective device identification performance under the low signal-to-noise ratio (SNR) conditions. Additionally, a preamble spectrum correlation (PSC) algorithm is proposed to fast estimate and compensate the large carrier frequency offset (CFO) in the preprocessing process of CPSD-based feature extraction. Our method is verified by conducting extensive experiments with over 34000 frames from 60 ZigBee devices in various scenarios, including indoor/outdoor and line-of-sight/non-LOS (LOS/NLOS). The identification accuracy reaches 96.66% for 60 devices in the LOS scenario and 98.81% for 36 devices in the NLOS scenario both with the shortest frame compared to the existing methods in practice. Thanks to the robust RFF extraction, experimental results show that our method adopting a simple linear discriminant analysis (LDA) classifier outperforms the state-of-the-art RFF identification methods using deep learning-based neural networks.
Junxian Shi, Linning Peng, Aiqun Hu
IEEE Internet Things J.2
2023 Design of a Channel Robust Radio Frequency Fingerprint Identification Scheme
abstract
Radio frequency fingerprint (RFF) identification is an emerging device authentication technique that exploits the hardware imperfections resulting from the manufacturing process. Due to the varying impact of the wireless channel during RFF training and test stages, it is challenging to design channel-independent RFF techniques. This article designs a channel robust RFF identification scheme by leveraging the different spectrum of adjacent signal symbols, named the Difference of the Logarithm of the Spectrum (DoLoS), which does not rely on a single RFF feature or requires additional manipulation of the devices under test. Specifically, DoLoS exploits the fact that two different symbols in a packet exhibit different RFF features but have a similar channel response during the channel coherence time. We implemented the DoLoS with the IEEE 802.11 orthogonal frequency division multiplexing (OFDM) system as a case study. We carried out extensive experiments using seven Wi-Fi devices of the same model in different wireless channel environments, including 12 data collection positions in two completely different environments. Compared with conventional RFF identification schemes that do not eliminate channel effects, our scheme is robust to channel variations and the highest identification accuracy is 99.02% in the single-environment evaluation and 97.05% in the cross-environment evaluation.
Yuexiu Xing, Aiqun Hu, Junqing Zhang, Linning Peng, Xianbin Wang 0001
IEEE Internet Things J.4
2022 Signal-independent RFF Identification for LTE Mobile Devices via Ensemble Deep Learning
abstract
Radio frequency fingerprint (RFF)-based wireless device authentication is an emerging technique to prevent potential spoofing attacks in wireless communications. The random access preamble of the physical random access channel (PRACH) in Long Term Evolution (LTE) systems is the first message sent from a user equipment (UE). However, PRACH preambles change under different evolved Node B (eNB), which will affect the RFF extraction. In this paper, a signal-independent RFF extraction method is first proposed to extract varying LTE PRACH preambles under different LTE eNBs. Residual transient segment (RTS) features from the varying PRACH preambles are extracted for RFF identification. A convolutional neural network (CNN) based ensemble deep learning scheme is proposed to integrate benefits from different RFF features. An experimental system under real operator LTE eNB is designed to capture and identify real UE signals. Experimental results show that the classification accuracy of five UEs can reach more than 95% under the same eNB and 85% under different eNBs. Furthermore, longtime evaluations show that the UE RTS feature is robust over time.
Yanjin Qiu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu
GLOBECOM2
2022 Colluding RF Fingerprint Impersonation Attack Based on Generative Adversarial Network
abstract
Radio frequency fingerprint (RFF) is an effective way to improve the security of wireless communications. Existing research mainly focused on the classification capability and the robustness of RFFs but overlooked malicious attacks. In this paper, a colluding impersonation attack framework is proposed to emulate the RFF of legitimate users. A colluding attacker is introduced to observe the signal features of the impersonation attacker and the legitimate user and compare their difference. The difference is fed back to the impersonation attacker to help improve its RFF impersonation method. With this idea, the impersonation attack is realized by the Generative Adversarial Network (GAN) structure. The RFF impersonation is formulated as the generator whose objective is to output the signal with RFF similar to the legitimate user, viewed from the colluding attacker’s perspective. Simulation results show that the proposed method can effectively impersonate the legitimate user’s RFF under the dynamic block fading channel.
Ming Liu 0010, Linning Peng, Junqing Zhang
ICC3
2022 Authorized and Rogue LTE Terminal Identification Using Wavelet Coefficient Graph with Auto-encoder
abstract
The wide popularity of 4G/5G mobile terminals increase the requirements of wireless security. Radio frequency fingerprint (RFF) technology can strengthen 4G/5G air interface accessing security at the physical layer. In this paper, a wavelet transform (WT) coefficient graphs RFF extraction with auto-encoder (AE) based rogue terminal detection scheme is proposed. At first, WT coefficients at 48 scales are extracted from the transient-power-off part of LTE physical random access channel (PRACH) preamble. Then, an AE network structure aimed for 2D WT coefficient graph is designed for rogue terminal detection. We successfully distinguish 7 mobile phones and 1 USRP under the proposed mechanism, where the authorized terminals from the same manufacturer can be identified with an accuracy of 90.08%. In addition, extensive experiments are carried out at LOS and NOLS scenarios, respectively, the proposed LTE identification scheme has demonstrated robustness in dynamic environments.
Zhenni Wu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu
VTC Fall2
2021 LTE Device Identification Based on RF Fingerprint with Multi-Channel Convolutional Neural Network
abstract
Radio frequency fingerprint (RFF) identification technique has drawn great attention to wireless terminal authentication. Long-Term Evolution (LTE) has been widely deployed all over the world. RFF-based LTE terminal identifications can prevent the potential impersonation or denial of service (DoS) attacks in the physical layer. This paper proposes a novel multi-channel convolutional neural network (MCCNN) for LTE terminal identification. Differential constellation trace figure (DCTF) is extracted from the random access preamble of the physical random access channel (PRACH). To the best knowledge of the authors, this is the first work dedicated to RFF-based LTE terminal identification. The proposed scheme is evaluated in the hardware experimental system consisting of the LTE eNodeB implemented on the software-defined radio (SDR) platform and six LTE mobile phones. Experimental results show that the classification accuracy can reach 98.96% at the SNR level of 30 dB with the line-of-sight (LOS) scenarios. Furthermore, long-time evaluations show that the proposed DCTF-MCCNN scheme is robust over time.
Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu
GLOBECOM2
2021 Bidirectional IoT Device Identification Based on Radio Frequency Fingerprint Reciprocity
abstract
Existing research on Radio Frequency Fingerprint (RFF) mainly focus on unilateral device identification in one communication direction. In practice, it is difficult for IoT devices to identify the base station due to their hardware insufficiencies. In this paper, a bidirectional device identification method is proposed for IoT scenarios. The inherent reciprocity of the communication pair’s RFFs is exploited to offload the learning process, which is supposed to be proceeded by the IoT device, to the base station. An autoencoder-based RFF reciprocal conversion network is proposed to predict the downlink RFF based on the data samples acquired in the uplink, so that the training process of the downlink identification network can be accomplished by the base station and the computational complexity of IoT devices is reduced. Evaluations with real-world data show that, the IoT devices can achieve a high accuracy to identify the base station using the identification network trained by the base station.
Ming Liu 0010, Xiaoyi Han, Linning Peng
ICC4
2021 Radio Frequency Fingerprint Identification for LoRa Using Spectrogram and CNN
abstract
Radio frequency fingerprint identification (RFFI) is an emerging device authentication technique that relies on intrin-sic hardware characteristics of wireless devices. We designed an RFFI scheme for Long Range (LoRa) systems based on spectrogram and convolutional neural network (CNN). Specifically, we used spectrogram to represent the fine-grained time-frequency characteristics of LoRa signals. In addition, we revealed that the instantaneous carrier frequency offset (CFO) is drifting, which will result in misclassification and significantly compromise the system stability; we demonstrated CFO compensation is an effective mitigation. Finally, we designed a hybrid classifier that can adjust CNN outputs with the estimated CFO. The mean value of CFO remains relatively stable, hence it can be used to rule out CNN predictions whose estimated CFO falls out of the range. We performed experiments in real wireless environments using 20 LoRa devices under test (DUTs) and a Universal Software Radio Peripheral (USRP) N210 receiver. By comparing with the IQ-based and FFT-based RFFI schemes, our spectrogram-based scheme can reach the best classification accuracy, i.e., 97.61% for 20 LoRa DUTs.
Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Linning Peng, Xianbin Wang 0001
INFOCOM4
2021 A Robust Radio-Frequency Fingerprint Extraction Scheme for Practical Device Recognition
abstract
Radio-frequency fingerprinting (RFF) exploiting hardware characteristics has been employed for device recognition to enhance the overall security. However, the performance unreliability in long-term experiments, channel fading interference, and unauthorized devices verification are three open problems that restrict the development of RFF recognition. To address these issues, a robust RFF extraction scheme based on three corresponding algorithms is studied. For the first problem, a long-term stacking of repetitive symbols (LSRSs) algorithm is proposed to reduce the acquired signal variance, which contributes to the identification accuracy and long-term stability. For the second issue, we propose an artificial noise adding (ANA) algorithm to enhance the recognition robustness through regularization and channel adaptation. For the third issue, a verification algorithm based on the generative Gaussian probabilistic linear discriminant analysis (GPLDA) model is developed to handle unauthorized devices. Our robust RFF extraction scheme is verified in the experiments with 54 CC2530 ZigBee devices. It enables reliable node identification with the accuracy of 99.50% in the short rang line-of-sight (SLOS) scenarios for signals collected over 18 months, and 95.52% in the extensive multipath fading experiments. The equal error rate (EER) of the verification experiments with six authorized devices versus six unseen unauthorized devices is as low as 0.63%.
Xinyu Zhou 0005, Aiqun Hu, Guyue Li, Linning Peng, Yuexiu Xing, Jiabao Yu
IEEE Internet Things J.4
2021 Radio Frequency Fingerprint Identification for LoRa Using Deep Learning
abstract
Radio frequency fingerprint identification (RFFI) is an emerging device authentication technique that relies on the intrinsic hardware characteristics of wireless devices. This paper designs a deep learning-based RFFI scheme for Long Range (LoRa) systems. Firstly, the instantaneous carrier frequency offset (CFO) is found to drift, which could result in misclassification and significantly compromise the stability of the deep learning-based RFFI system. CFO compensation is demonstrated to be effective mitigation. Secondly, three signal representations for deep learning-based RFFI are investigated in time, frequency, and time-frequency domains, namely in-phase and quadrature (IQ) samples, fast Fourier transform (FFT) results and spectrograms, respectively. For these signal representations, three deep learning models are implemented, i.e., multilayer perceptron (MLP), long short-term memory (LSTM) network and convolutional neural network (CNN), in order to explore an optimal framework. Finally, a hybrid classifier that can adjust the prediction of deep learning models with the estimated CFO is designed to further increase the classification accuracy. The CFO will not change dramatically over several continuous days, hence it can be used to correct predictions when the estimated CFO is much different from the reference one. Experimental evaluation is performed in real wireless environments involving 25 LoRa devices and a Universal Software Radio Peripheral (USRP) N210 platform. The spectrogram-CNN model is found to be optimal for classifying LoRa devices which can reach an accuracy of 96.40% with the least complexity and training time.
Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Linning Peng, Xianbin Wang 0001
IEEE J. Sel. Areas Commun.4
2019 A Design of Deep Learning Based Optical Fiber Ethernet Device Fingerprint Identification System
abstract
This paper proposes a novel deep learning based hardware fingerprint identification method for optical fiber Ethernet devices. An adjacent constellation trance figure (ACTF) feature extraction method is firstly introduced for baseband modulation system with only amplitude waveform. A 2-dimensional convolutional neural network (2D-CNN) is designed to classify different optical fiber Ethernet devices via ACTF features. An intensity modulation / direct detection (IM/DD) experimental system with 24 optical fiber Ethernet devices is designed for evaluations. We optimize the ACTF parameter setups and compare the classification accuracy with another deep learning based long short-term memory (LSTM) network and classical statistical feature methods. Experimental results show that our proposed ACTF-CNN can achieve a classification accuracy as high as 99.49% and 96.29% under SNR levels of 30 dB and 10 dB, respectively, which significantly outperforms LSTM network and statistical feature based methods.
Linning Peng, Aiqun Hu
ICC1
2019 A Robust Radio Frequency Fingerprint Identification Scheme for LFM Pulse Radars
abstract
Radar transmitter identification technology based on pulse descriptor word (PDW) is broadly used in military and civilian applications. However, as the complexity of the electromagnetic environment has increased, radar identification has been challenging. Radio frequency fingerprint (RFF) is an intrinsic hardware characteristic and has been widely employed for device identification. In this paper, we propose a robust RFF identification scheme for linear frequency modulation (LFM) pulse radars. The scheme includes a proposed piecewise curve fitting based denoising (PCFD) algorithm and a hybrid RFF identification algorithm. The PCFD algorithm can reduce the noise of LFM pulses without undermining RFF features. The hybrid RFF identification algorithm extracts both transient-based and modulation-based RFF features. Experimental results demonstrate that the proposed radar identification scheme can achieve a 100% identification accuracy when the SNR is about 0 dB.
Yuexiu Xing, Aiqun Hu, Jiabao Yu, Guyue Li, Linning Peng, Fen Zhou 0001
WiMob5
2019 Radio Frequency Fingerprint Identification Based on Denoising Autoencoders
abstract
Radio Frequency Fingerprinting (RFF) is one of the promising passive authentication approaches for improving the security of the Internet of Things (IoT). However, with the proliferation of low-power IoT devices, it becomes imperative to improve the identification accuracy at low SNR scenarios. To address this problem, this paper proposes a general Denoising AutoEncoder (DAE)-based model for deep learning RFF techniques. Besides, a partially stacking method is designed to appropriately combine the semi-steady and steady-state RFFs of ZigBee devices. The proposed Partially Stacking-based Convolutional DAE (PSC-DAE) aims at reconstructing a high-SNR signal as well as device identification. Experimental results demonstrate that compared to Convolutional Neural Network (CNN), PSCDAE can improve the identification accuracy by 14% to 23.5% at low SNRs (from -10 dB to 5 dB) under Additive White Gaussian Noise (AWGN) corrupted channels. Even at SNR = 10 dB, the identification accuracy is as high as 97.5%.
Jiabao Yu, Aiqun Hu, Fen Zhou 0001, Yuexiu Xing, Guyue Li, Linning Peng
WiMob7
2019 Design of a Hybrid RF Fingerprint Extraction and Device Classification Scheme
abstract
Radio frequency (RF) fingerprint is the inherent hardware characteristics and has been employed to classify and identify wireless devices in many Internet of Things applications. This paper extracts novel RF fingerprint features, designs a hybrid and adaptive classification scheme adjusting to the environment conditions, and carries out extensive experiments to evaluate the performance. In particular, four modulation features, namely differential constellation trace figure, carrier frequency offset, modulation offset and I/Q offset extracted from constellation trace figure, are employed. The feature weights under different channel conditions are calculated at the training stage. These features are combined smartly with the weights selected according to the estimated signal to noise ratio at the classification stage. We construct a testbed using universal software radio peripheral platform as the receiver and 54 ZigBee nodes as the candidate devices to be classified, which are the most ZigBee devices ever tested. Extensive experiments are carried out to evaluate the classification performance under different channel conditions, namely line-of-sight (LOS) and nonline-of-sight scenarios. We then validate the robustness by carrying out the classification process 18 months after the training, which is the longest time gap. We also use a different receiver platform for classification for the first time. The classification error rate is as low as 0.048 in LOS scenario, and 0.1105 even when a different receiver is used for classification 18 months after the training. Our hybrid classification scheme has thus been demonstrated effective in classifying a large amount of ZigBee devices.
Linning Peng, Aiqun Hu, Junqing Zhang, Yu Jiang 0020, Jiabao Yu
IEEE Internet Things J.1
2019 A Robust RF Fingerprinting Approach Using Multisampling Convolutional Neural Network
abstract
With the increasing popularity of the Internet of Things (IoT), device identification, and authentication has become a critical security issue. Recently, radio frequency (RF) fingerprint-based identification schemes have attracted wide attention as they extract the inherent characteristics of hardware circuits which is very hard to forge. However, existing RF fingerprint-based approaches face the problems of unstable region of interest (ROI), high-cost feature design, and incomplete automation. To address these problems, this paper proposes a multisampling convolutional neural network (MSCNN) to extract RF fingerprint from the selected ROI for classifying ZigBee devices. A signal-to-noise ratio (SNR) adaptive ROI selection algorithm is also developed to alleviate the effect of semi-steady behavior of ZigBee devices owing to sleep mode switching. The proposed MSCNN uses multiple downsampling transformations for multiscale feature extraction and classification automatically. To validate and evaluate the performance of our proposed method, we design a testbed consisting of one low-cost universal software radio peripheral (USRP) as the receiver and 54 CC2530 devices as targets for identification. Extensive experiments are conducted to demonstrate the feasibility and reliability of MSCNN both in the line-of-sight (LOS) scenarios and non-LOS (NLOS) scenarios. The classification accuracy is as high as 97% under the LOS scenarios around SNR = 30 dB. Our scheme is robust over a wide range of SNRs under the LOS scenarios as well as under the NLOS scenarios.
Jiabao Yu, Aiqun Hu, Guyue Li, Linning Peng
IEEE Internet Things J.4
2019 An Investigation of Using Loop-Back Mechanism for Channel Reciprocity Enhancement in Secret Key Generation
abstract
Physical layer security key generation exploits unpredictable features from wireless channels to achieve high security, which requires high reciprocity in order to set up symmetric keys between two users. This paper investigates enhancing the channel reciprocity using a loop-back scheme with multiple frequency bands in time-division duplex (TDD) communication systems, in order to mitigate the effect of hardware fingerprint interference and synchronization offset. The scheme is evaluated to be robust to passive eavesdropping and active Man-in-the-Middle attack through both theoretical analyses and practical measurements. A secret key generation protocol is subsequently designed. The performance of the proposed secret key generation method is then evaluated through both numerical simulation and experiments. Results demonstrate that the proposed scheme can effectively mitigate non-reciprocity and outperforms the classical TDD scheme in both key disagreement rate and key generation rate.
Linning Peng, Guyue Li, Junqing Zhang, Roger F. Woods, Ming Liu 0010, Aiqun Hu
IEEE Trans. Mob. Comput.1
2018 High-Agreement Uncorrelated Secret Key Generation Based on Principal Component Analysis Preprocessing
abstract
Random and high-agreement secret key generation from noisy wideband channels is challenging due to the autocorrelation inside the channel samples and compromised cross correlation between channel measurements of two keying parties. This paper studies the signal preprocessing algorithms to establish high-agreement uncorrelated secret key in the presence of channel independent eavesdroppers. We first propose a general mathematical model for various preprocessing schemes, including principal component analysis (PCA), discrete cosine transform (DCT) and wavelet transform (WT). Among preprocessing schemes, PCA is proved to achieve the optimal secret key rate. Next, PCA with common eigenvector has been found to outperform PCA with private eigenvector in terms of an overall consideration of key agreement, information leakage, and computational expense. Then, we propose a system level design of key generation, including quantization, information reconciliation, and privacy amplification. Numerical results verify that the key generation enhanced by PCA with common eigenvector can achieve secret key with high key generation rate, low key error rate, and good randomness.
Guyue Li, Aiqun Hu, Junqing Zhang, Linning Peng, Chen Sun 0004, Daming Cao
IEEE Trans. Commun.4
2015 A Novel Transform for Secret Key Generation in Time-Varying TDD Channel under Hardware Fingerprint Deviation
abstract
Channel reciprocity can be used for providing sufficient key generation in time division duplex (TDD) system. However, in practice, its application is limited by the hardware fingerprint deviation (HFD) problem. In this paper, we propose a novel real-time transform that can cope with this problem in time- varying TDD channel without any calibration period or feedback loops. More specifically, a log-domain differential (LDD) transform is developed and the resulting performance is analyzed in terms of mean square error (MSE) between receptions at Alice and Bob and effective signal to error ratio (ESER). The analysis shows that the proposed transform can eliminate the impact of HFD, yet its performance is very sensitive to channel noise and moving speed. For this purpose, an enhanced version is proposed including an efficient noise reduction technique and the impact of mobility on parameter design is also analyzed. Numerical results show that the proposed LDD advanced transform provides performance comparable to the ideal case without HFD, and thus, can be used to form a simple, practical and flexible solution for secret key generation in time-varying TDD channel.
Guyue Li, Aiqun Hu, Yaning Zou, Linning Peng, Mikko Valkama
VTC Fall4
2013 Optimization of multi-band DFT-spread DMT system for polymer optical fiber communications
abstract
Recently, polymer optical fiber (POF) became a popular solution for the indoor communications. In this paper, a multi-band discrete-Fourier-transform spread (MB-DFT-S) discrete multi-tone (DMT) system is proposed to study and optimize in terms of POF communications. A joint optimization of used subcarrier number, used bandwidth and multi-band number is investigated. The transmission of MB-DFT-S DMT over 50 m POF link is implemented. Both theoretical and experimental results demonstrate that optimized MB-DFT-S DMT system outperforms the original DMT and DFT-S DMT systems, which means that it is a promising technique for future POF transmission systems.
Linning Peng, Maryline Hélard, Sylvain Haese
ICC1