AmbSentry: Mitigating Sensing Eavesdropping in ISAC Systems by Harnessing Ambient IoT Devices
Yifan Zhang, Yu Bai, Riku Jantti, Zhu Han, Christos Masouros
Aalto University · Taiyuan University of Technology · University of Houston · University College London
cs.CR
Submitted: 2026-08-12
Updated: 2026-08-13
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 95/100
The gist: AmbSentry: Mitigating Sensing Eavesdropping in ISAC Systems by Harnessing Ambient IoT Devices Summary This paper proposes AmbSentry, a novel integrated sensing and communication (ISAC) system
Terminology
Summary
AmbSentry: Mitigating Sensing Eavesdropping in ISAC Systems by Harnessing Ambient IoT Devices
Summary
This paper proposes AmbSentry, a novel integrated sensing and communication (ISAC) system designed to prevent sensing eavesdropping by leveraging naturally distributed passive ambient IoT (AIoT) devices. The core idea is to configure these AIoT devices as cooperative jammers and ghost targets, introducing controllable interference into the sensing environment to degrade the performance of unauthorized sensing eavesdroppers (SEve) while maintaining quality-of-service (QoS) for legitimate receivers.
The paper addresses a critical security gap in ISAC systems: "the inherent openness of wireless transmission exposes ISAC systems to critical security risks, particularly regarding the privacy of the sensing information. Unauthorized sensing eavesdroppers can extract sensitive target parameters (e.g., range and velocity) by directly estimating open sensing echo channels, rendering traditional data-based protection techniques ineffective." The authors note that conventional physical layer security (PLS) methods, such as artificial noise (AN) injection or auxiliary devices like RIS and UAVs, either incur significant energy overhead or high deployment costs, and most existing sensing-security approaches rely on the unrealistic assumption of knowing the eavesdropper's CSI.
The proposed AmbSentry system overcomes these limitations by exploiting the passive, low-cost nature of AIoT devices (e.g., RFID tags, passive backscatter sensors), which eliminate the need for power-hungry RF chains, thereby achieving ultra-low power consumption and low hardware complexity.
These devices are strategically configured to reflect and modulate incident ISAC signals, introducing controllable multiplicative noise and artificial clutter into the propagation environment.
The legitimate sensing receiver (BS) can suppress this interference using prior knowledge of the AIoT devices' locations and modulations, whereas a passive sensing eavesdropper lacks this side information and experiences largely unmitigated artificial clutter.
The system model considers a monostatic ISAC system where a multi-antenna BS communicates with a single-antenna user, senses targets, and leverages K single-antenna AIoT devices. The BS transmits OFDM signals with beamforming vector w, and each AIoT device modulates the incident signal with a reflection coefficient αk. The legitimate BS cancels the AIoT backscattered signal using its knowledge of the devices, while the SEve, which uses a matched filter with an eavesdropped reference signal, suffers from the AIoT-induced interference.
A key contribution is the derivation of a closed-form expression for the integrated sidelobe level (ISL) as a security metric, which does not require knowledge of the eavesdropper's CSI. The ISL is defined as the ratio of the expected power of the ambiguity function at AIoT-induced delays to the mainlobe power: ∆ISL = (µ22 Σ k=1 K Σ n=0 N-1 q[n]e j(2π/N)l k n2 + K(µ4 − µ22) Σ n=0 N-1 q[n]2) / (µ22 Σ n=0 N-1 q[n]2 + (µ4 − µ22) Σ n=0 N-1 q[n]2).
This metric quantifies the jamming efficiency of AIoT devices against sensing eavesdroppers.
The paper formulates a joint optimization problem (P1) to maximize the ISL under QoS constraints, including a minimum communication rate for the user and a minimum sensing SINR for the BS. The problem is non-convex due to the fractional objective, the coupling between beamforming and AIoT modulations, and the discrete nature of reflection coefficients. To solve it, the authors develop an efficient iterative algorithm based on:
-
Generalized Dinkelbach transformation to handle the fractional objective.
-
Block coordinate descent (BCD) to decompose the problem into two subproblems: transmit beamforming optimization (P3) and AIoT device reflection coefficient optimization (P4).
-
Semidefinite relaxation (SDR) and successive convex approximation (SCA) to solve the non-convex subproblems.
The simulation results validate the effectiveness of AmbSentry. Key findings include:
-
Range profiles: The BS observes a clean range profile with a distinct target peak, while the SEve sees significant artificial clutter and high-level sidelobes that mask the true target.
-
Trade-offs: Increasing the sensing SINR or communication rate constraints decreases the maximized ISL, revealing fundamental conflicts between sensing security and S&C performance. However, increasing the number of AIoT devices (from K=2 to K=10) provides substantial performance gains (approximately 7.5 dB).
-
Detection gap: The BS achieves a detection probability approaching 1 at lower SNR, while the SEve requires approximately 14 dB higher SNR to achieve the same detection probability, creating a
sensing security zone.
-
Estimation gap: The legitimate sensing receiver achieves a range RMSE of approximately 10−2 m, while the eavesdropper's RMSE persists at around 101 m, a
hundred times lower estimation error
for the legitimate receiver. -
Robustness: The system shows robustness to imperfect AIoT device cancellation and sensing-channel estimation errors, with performance degrading gracefully and stabilizing at low RMSE once the SNR exceeds a threshold.
In conclusion, the paper demonstrates that AmbSentry significantly enhances sensing security, allowing the legitimate sensing receiver to achieve a 14-dB SNR advantage in detection probability and a hundred times lower estimation error compared to the eavesdropper.
The proposed framework provides a practical, energy-efficient, and cost-effective solution for securing ISAC systems against sensing eavesdropping without relying on active jamming, additional hardware, or knowledge of the eavesdropper's CSI.
Improvements for AI systems
Improvements to AI Systems:
- CSI-Free Security Optimization for ISAC Beamforming:
-
Improvement: Replace traditional PLS methods that require eavesdropper CSI with an AI-driven optimizer that directly maximizes the integrated sidelobe level (ISL) as a security metric. Use a deep reinforcement learning (DRL) agent trained on the closed-form ISL expression to adaptively tune beamforming vectors and AIoT reflection coefficients in real time, without needing any knowledge of the eavesdropper’s channel.
-
Capability: The AI system can autonomously secure sensing operations in dynamic environments, even when the eavesdropper’s location or channel is unknown, reducing reliance on unrealistic assumptions and improving robustness against passive attackers.
- Joint Beamforming and Reflection Coefficient Optimization via Learned Decomposition:
-
Improvement: Implement a neural network architecture that mimics the BCD + SCA algorithm but learns to predict near-optimal solutions for the non-convex joint optimization problem (P1) with lower computational latency. The network can be trained offline on simulated ISAC scenarios to output beamforming vectors and AIoT coefficients that maximize ISL while satisfying QoS constraints.
-
Capability: The AI system can perform real-time, low-latency security optimization for large-scale ISAC deployments (e.g., with many AIoT devices), enabling adaptive responses to changing traffic, target positions, or QoS requirements without iterative solver overhead.
- Adaptive AIoT Configuration for Graceful Degradation Under Imperfect Cancellation:
-
Improvement: Train a predictive model that estimates the impact of imperfect AIoT cancellation and sensing-channel estimation errors on ISL and detection performance. Use this model to proactively adjust AIoT reflection coefficients and beamforming to maintain a target security margin, even when the legitimate receiver’s side information is noisy.
-
Capability: The AI system can maintain a stable
sensing security zone
(e.g., 14 dB SNR advantage) under real-world hardware imperfections, ensuring reliable protection against eavesdroppers without sacrificing legitimate sensing accuracy.
- Multi-Objective Trade-off Management for S&C Security:
-
Improvement: Develop a multi-objective reinforcement learning agent that balances ISL maximization against communication rate and sensing SINR constraints. The agent learns Pareto-optimal policies, allowing operators to specify priorities (e.g., prioritize sensing security over communication throughput) and receive real-time adjustments.
-
Capability: The AI system can dynamically navigate the fundamental trade-offs identified in the paper (e.g., increasing sensing SINR reduces ISL) to provide flexible, scenario-aware security configurations for diverse ISAC use cases (e.g., autonomous driving vs. surveillance).
- AI-Driven Ghost Target Generation for Enhanced Eavesdropper Confusion:
-
Improvement: Use a generative model (e.g., a variational autoencoder) to design AIoT reflection coefficient sequences that create highly deceptive artificial clutter patterns in the eavesdropper’s range-Doppler map, specifically tailored to mask target velocity and range. The model can be trained to maximize the ambiguity function’s sidelobe energy at critical delay-Doppler cells.
-
Capability: The AI system can generate sophisticated, adaptive jamming patterns that not only raise the eavesdropper’s detection threshold but also actively mislead its parameter estimation, increasing the estimation error gap (e.g., from 101 m to even higher) beyond the paper’s demonstrated hundred-fold improvement.
- Scalable Security for Massive AIoT Networks:
-
Improvement: Implement a graph neural network (GNN) that operates on the ISAC system’s topology (BS, user, targets, and AIoT devices) to predict optimal configurations for hundreds of AIoT devices, overcoming the computational bottleneck of the proposed BCD algorithm in large-scale settings.
-
Capability: The AI system can secure ISAC systems with dense ambient IoT deployments (e.g., smart factories, smart cities), achieving the 7.5 dB gain scaling with K=10 devices and beyond, while maintaining real-time operation and low energy overhead.
Abstract
Integrated sensing and communication (ISAC) has emerged as a pivotal paradigm for 6G networks, enabling the synergistic convergence of spectral and hardware resources to maximize system efficiency. However, the inherent openness of wireless transmission exposes ISAC systems to critical security risks, particularly regarding the privacy of the sensing information. Unauthorized sensing eavesdroppers can extract sensitive target parameters (e.g., range and velocity) by directly estimating open sensing echo channels, rendering traditional data-based protection techniques ineffective. To mitigate this threat, this paper proposes AmbSentry, an ISAC system that prevents the leakage of sensing information to sensing eavesdroppers by harnessing naturally distributed passive ambient IoT (AIoT) devices. Specifically, these AIoT devices are strategically configured to act as cooperative jammers and ghost targets, introducing controllable interference into the sensing environment. Based on the proposed system, we formulate a joint optimization problem to maximize the integrated sidelobe level at the eavesdropper under quality-of-service (QoS) constraints, thereby degrading sensing eavesdropping performance while maintaining sensing and communication performance for legitimate receivers. Since the problem is non-convex, we further develop an efficient iterative algorithm to cooperatively design the transmit beamforming at the base station and the reflection modulations of the AIoT devices based on Dinkelbach transformation and block coordinate descent methods. The detailed results also demonstrate that AmbSentry significantly enhances sensing security, allowing the legitimate sensing receiver to achieve a 14-dB SNR advantage in detection probability and a hundred times lower estimation error compared to the eavesdropper.
Sources
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs