Skip to content
Conference

Joint Sensing-Security Optimization in Sensing-Integrated MLWE Under Noisy and Adversarial Environments

Aug 2026 · 2026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS) · pp. 1-6 · 0 citations · 13 references

Abstract

Module Learning with Errors (MLWE) cryptography normally treats decryption noise as a disturbance: it must be large enough to hide algebraic structure but small enough for reliable decoding. This paper studies a conditional design in which selected residual degrees of freedom also carry coarse physical sensing information. The construction is not presented as a dropin replacement for standardised ML-KEM. Instead, we specify the assumptions under which residual-layer sensing can be analysed, identify what must remain external to FIPS-approved ML-KEM, and give a Fujisaki-Okamoto (FO)/CCA compatibility roadmap. The paper contributes an explicit measurement-to-label pipeline $\boldsymbol{z}=Q(F(y))$, concrete ML-KEM parameter instantiations, residual-budget calculations including compression noise, formal bounds for security-decomposition terms, higher-order leakage bounds beyond balanced mean suppression, an adaptive tuning algorithm, and residual-level Monte Carlo validation. The central message is that structured residual information can be useful for cyber-physical trust only when distributionshape closeness, decoding reliability, sensing privacy, and contextspoofing resistance are all quantified.

View source

Similar papers

Preprint Aug 2026

Revisiting Continuous Noise Sampling for Multi-Party Differential Privacy

Combining secure multi-party computation (MPC) with differential privacy (DP) enables multiple parties to release aggregate statistics without a trusted curator, and the core primitive is the protocol to sample noise from a continuous distribution under finite-precision arithmetic. In this paper, we revisit the continuous noise sampling protocols and present several improvements in both security and efficiency. We start by identifying a vulnerability in widely used sample-and-scale constructions. We demonstrate that the scaling operation in arithmetic circuits confines the noise to a sparse, publicly known set of values, so that an adversary can observe the released noisy queries and decide which dataset produced them. As concrete demonstrations, we instantiate attacks on two systems employing such ``flawed''sampling protocols: Orchard (OSDI'20) for DP secure aggregation and DP-BREM$^+$ (USENIX Sec'25) for DP federated learning. We report a near-$100\%$ attack success rate on both systems, under any noise scaler $s\geq 2$ used in practice. The leakage we reveal is intrinsic to the scaling operation, and direct repairs either substantially sacrifice utility or add significant precision bits to make the sampling more expensive. To address the security and efficiency issues together, we turn to discrete sampling at the granularity of individual biased bits. We make several optimizations to the sampler and prove its security. Our implementation achieves $4\times \sim 612\times$ speedup over existing secure discrete samplers and orders-of-magnitude speedup over the insecure sample-and-scale paradigm, with negligible utility loss compared to the ideal continuous mechanism.

Yucheng Fu, Tianhao Wang · 0 citations
Open access Aug 2026

PCGM-Net: Policy-Conditioned Local Generative Masking for Privacy-Preserving Wi-Fi CSI Sensing

Wireless channel state information (CSI) enables device-free industrial safety monitoring, but the same representation can expose worker identity and sensitive locations. Existing CSI privacy methods typically protect fixed semantic targets or perturb the entire representation, providing limited control over what is protected and where modification occurs. This paper proposes PCGM-Net, a policy-conditionedlocal generative masking framework for selective CSI semantic release. To the best of our knowledge, it is the first representation-level Wi-Fi CSI framework to jointly combine explicit semantic privacy policies, a learned position-wise soft mask over the time–subcarrier plane, bounded residual transformation, and trusted retention of the source CSI. The mask determines where intervention is applied, whereas the residual patch determines how the selected regions are transformed. A single model supports identity-only, location-only, and joint protection. Under a test-set-isolated protocol, raw CSI yielded identity and location accuracies of 97.95% and 100.00%, respectively. Across three independently trained protection models selected using validation data only, joint protection retained 74.79±0.96% activity accuracy while reducing identity and location accuracies for the validation-selected evaluator to 6.09±2.40% and 0.29±0.14%. Removing the privacy-margin objective restored identity and location accuracies to 98.55% and 100.00%, confirming that suppression arose from targeted semantic optimization rather than incidental signal corruption. An independent temporal bidirectional gated recurrent unit (BiGRU) model recovered 94.09±1.16% activity accuracy after protected-domain adaptation, and the complete pipeline required 2.18 ms mean graphics processing unit (GPU) latency. PCGM-Net therefore provides low-latency, policy-selective inference-time semantic shielding under a bounded, evaluator-dependent threat model rather than irreversible anonymization.

Wei Zhang, Yifu Zeng, Qinglong Tian et al. · 0 citations
Open access 2026

Sensing-Aware Beamforming and Interpretable Analysis for Pilot-Spoofing Resilience in ISAC Systems

Detection-based defenses against pilot spoofing in integrated sensing and communication (ISAC) systems leave a structural gap. An adaptive eavesdropper that tunes its power below the detection threshold corrupts the uplink channel estimate and leaks signal to itself, yet evades every detector commonly proposed in the literature. This paper proposes a sensing-aided subspace projection defense. The defense operates continuously on the received signal covariance, suppresses the dominant interferer without a detector trigger, and reuses the eigenvalue decomposition already performed by the ISAC sensing subsystem. Evaluated against an adaptive attacker built from a reparametrized conditional generative adversarial network (cGAN), the defense recovers 8.1 dB of SINR at the legitimate user and attenuates information leakage toward the eavesdropper by 7 to 12 dB inside the stealth zone where conventional detectors fail. A triangulated interpretable analysis across three independent models yields design insights that position array sizing and sensing subsystem design as a joint optimization, and reveals a regime-dependent, non-monotonic dependence of post-defense SINR on array size under AoA-aware null-steering defenses with finite sensing precision.

E. Pacheco, C. Pedroso · 0 citations
Open access Aug 2026

Adversarial Latency Watermarking: Covertly Encoding Zero Bit Keys in Federated Learning Model Updates

These findings expose time as a first class security primitive in FL systems and recommend integrating timing randomization, lightweight monitoring, and scheduler level defenses into frameworks such as Tensor Flow Federated.

B. Ibrahim, Ahmed Hameed Shakir, Hasan Jameel · 0 citations
Open access Aug 2026

Compressed FHE

Experimental evaluations demonstrate that encrypted low-rank matrix multiplications achieve both significant runtime improvements and reduction of ciphertext sizes over direct or tree-based encrypted multiplications while maintaining the prescribed accuracy.

Dimitrios Schoinianakis, M. Sabzevari · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.