arXiv:2606.22939cs.CRcs.LG2026-06被引 1

用手机能测的信道数据,实时发现并识别未知干扰攻击。

CITADEL: CSI-Based Jamming Detection and Open-Set Classification for IIoT Networks

论文配图:CITADEL: CSI-Based Jamming Detection and Open-Set Classification for IIoT Networks
图 1 · 摘自论文原文
  • 仅用设备自带的信道状态信息,分两阶段检测干扰
  • 已知攻击检测率100%,未知攻击检测率达97.1%
  • 对黑客伪装攻击有强防御力,适合大规模工业物联网

射频干扰严重威胁无线工业物联网(IIoT)网络可用性。现有检测方法要么特征粗糙,要么需昂贵硬件且吞吐量不达标。本文提出CITADEL,一种轻量级两级架构,仅利用商品化IIoT设备原生支持的信道状态信息(CSI)实现干扰检测与分类,包括未见过的新型攻击。尽管先前研究已发现干扰会留下可识别的CSI痕迹,但CITADEL是首个将此洞察转化为端到端系统的方法,同时实现已知攻击闭集分类、零日攻击开集检测及对抗规避抵抗。在6种已知攻击和15种零日场景下测试,已知攻击检测率达100%,零日攻击检测率为97.1%,端到端误报率仅0.4%。在白盒与黑盒对抗评估中,基于梯度的逃逸攻击均低于2%,最强公开的CSI攻击生成器平均逃逸率也低于5%。与八种基线系统对比,无一能在检测、泛化与鲁棒性三方面全面超越。整个流程在边缘GPU上耗时14.2毫秒,功耗95.9毫焦,具备大规模部署可行性。

原文摘要 · Abstract (English)

Radio frequency jamming poses a critical threat to the availability of wireless Industrial Internet of Things (IIoT) networks. Existing detection and classification techniques are poorly suited to this setting: coarse signal-strength and cross-layer features lack information richness, while raw I/Q baseband approaches require hardware and throughput that is impractical at the scale of hundred-node IIoT deployments. This paper presents CITADEL, a lightweight two-stage hierarchical pipeline that uses only Channel State Information (CSI) measurements, which are natively available on commodity IIoT devices, to detect and classify jamming attacks including previously unseen ones. While prior work has shown that jamming leaves observable CSI signatures, CITADEL is the first system to translate this insight into an end-to-end pipeline that jointly achieves closed-set classification of known attacks, open-set detection of zero-day attacks, and resistance to adversarial evasion. Evaluated across 6 known attack types and 15 zero-day scenarios, CITADEL achieves 100% known-attack detection and 97.1% zero-day detection at a 0.4% end-to-end false positive rate. Under adversarial evaluation spanning white-box and black-box threat models, gradient-based evasion remains below 2% across all tested perturbation budgets and the strongest published CSI attack generator achieves less than 5% average evasion. A systematic comparison against eight baselines confirms that no existing method achieves comparable performance on CSI data across all three axes: detection, generalization, and robustness. The full pipeline completes inference in 14.2 ms at 95.9 mJ on an edge GPU, establishing CITADEL as a practical solution for large-scale IIoT network security.

网络安全工业物联网信号检测对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。