Abstract:Mechanisms for dynamically converting cyber threat intelligence (CTI) into actionable detection capabilities are necessary due to the rapid evolution of Advanced Persistent Threats (APTs). Sigma rules are an essential part of contemporary threat detection workflows because they offer a platform-independent framework for expressing detection logic that can be converted into particular queries across SIEM systems. Conventional techniques for manually crafting Sigma rules are prone to mistakes, and necessitate extensive knowledge, which restricts their scalability. Although there are open-source and industry-maintained Sigma rule repositories, they often fail to keep pace with emerging threats and require frequent customization to fit diverse operational environments. This emphasizes the necessity of dynamic rule generation that is adapted to evolving attack techniques as well as particular use cases. In this work, we design AUTOSIGMA, an automated solution for transforming unstructured CTI reports into relevant Sigma rules. Rather than relying solely on language models, AUTOSIGMA leverages a structured knowledge base to enrich partial inputs, matches the enriched content against a repository of existing Sigma rules, and then employs an LLM-as-a-Judge mechanism to iteratively validate the rules. By combining knowledge-driven enrichment, template-based rule grounding, and a multi-stage solution, AUTOSIGMA enables accurate, context-aware, and relevant rule generation. Evaluations across multiple real-world APT reports and multiple security blogs demonstrate that AUTOSIGMA outperforms alternative solutions and LLM models in rule validity, rule relevancy, MITRE ATT&CK technique coverage, and robustness to input quality. AUTOSIGMA's Demo: https://youtu.be/iSr6IurQ6BM
Abstract:Secure energy efficiency (SEE) has emerged as a key performance metric for next-generation wireless networks, where energy sustainability and information security must be jointly guaranteed. This paper investigates secure uplink transmission in a full-duplex (FD) base station (BS) system equipped with movable antennas (MAs) and assisted by a movable-element reconfigurable intelligent surface (ME-RIS) in the presence of multiple cooperative passive eavesdroppers. The objective is to maximize SEE by jointly optimizing the users' transmit powers, BS receive postcoders, artificial noise (AN) transmit power and beamforming, RIS phase shifts, and the two-dimensional positions of both the BS antennas and RIS elements. The resulting optimization problem is highly nonconvex due to the fractional SEE objective, coupled secrecy-rate expressions, residual self-interference (SI), unit-modulus RIS phase-shift constraints, movable-position constraints, inter-element spacing requirements, and the nonlinear dependence of the channels on the movable antenna and RIS-element positions. To address these challenges, we propose a hybrid gradient-based meta-learning (H-GML) framework. In the proposed method, the BS receive postcoders and AN direction are updated using closed-form solutions derived from generalized Rayleigh quotient formulations, while the remaining coupled variables are updated by neural meta-optimizers that learn gradient-based update directions directly from the SEE optimization objective without requiring offline labeled training data. Simulation results show that the proposed H-GML design achieves better performance than the AO benchmark and significantly outperforms fixed-geometry, random RIS, no-AN, and no-Eve-knowledge baselines.
Abstract:This letter investigates a symbol-level precoder design for movable antenna (MA)-enhanced dual-functional radar-communication (DFRC) systems. To enhance radar sensing capabilities, we formulate an optimization problem aimed at maximizing the minimum radar signal-to-interference-plus-noise ratio (SINR) across multiple targets in a cluttered environment. Our approach jointly designs the space-time transmitted waveforms, receiving filters, and antenna placement. However, the resulting problem is intractable to solve due to practical waveform constraints and the non-linear mapping from antenna positions to the corresponding channel coefficients. To address these challenges, we develop a bi-level optimization framework by leveraging deep reinforcement learning (DRL). Specifically, the twin delayed deep deterministic policy gradient (TD3) algorithm is employed in the outer layer to optimize antenna placement, while penalty convex-concave procedure (CCP) and majorization-minimization (MM) techniques are incorporated in the inner layer for regularizing waveform design. Simulation results demonstrate that the proposed method significantly improves radar SINR and achieves a superior sensing-communication trade-off compared to benchmark schemes.
Abstract:The integration of multimodal sensing and millimeter-wave (mmWave) communications is a key enabler for highly mobile vehicle-to-infrastructure (V2I) networks. However, continuous high-resolution visual sensing incurs prohibitive computational energy, while delayed sensing information worsens beam misalignment. In this paper, we establish a physics-aware multimodel integrated sensing and communication (M-ISAC) framework that quantifies the mathematical trade-off between sensing energy and communication reliability using the semantic age of information (AoI). To address the coupled challenges of temporal AoI evolution and instantaneous non-convex constant modulus constraints, we propose a novel reinforcement learning approach empowered by a heterogeneous mixture-of-experts (RL-H-MoE) architecture. By strictly decoupling the temporal scheduling and spatial phase mapping, the RL-H-MoE avoids prevalent gradient conflicts in multi-task learning. Extensive simulations demonstrate that the proposed architecture achieves an optimal event-triggered sensing policy, significantly minimizing the long-term system cost while guaranteeing ultra-low sensing errors and reliable physical-layer link connectivity.
Abstract:This paper investigates energy efficiency (EE) optimization for an uplink multiuser system assisted by a movable-element reconfigurable intelligent surface (ME-RIS) and a base station equipped with movable antennas (MA-BS). We jointly optimize the uplink postcoder vectors, user transmit powers, RIS phase shift, and the positions of both the BS antennas and RIS elements to maximize the system EE. The resulting non-convex fractional problem is solved using an alternating optimization (AO) framework, where subproblems are handled via Dinkelbach's method combined with successive convex approximation (SCA). Simulation results show that the proposed scheme achieves significant EE gains over fixed-antenna BS and fixed-element RIS benchmarks.
Abstract:Movable antenna (MA) has emerged as a promising technology to flexibly reconfigure wireless channels by adjusting antenna placement. In this paper, we study a secured dual-functional radar-communication (DFRC) system aided by movable antennas. To enhance the communication security, we aim to maximize the achievable sum rate by jointly optimizing the transmitter beamforming vectors, receiving filter, and antenna placement, subject to radar signal-to-noise ratio (SINR) and transmission covertness constraints. We consider multiple Willies operating in both non-colluding and colluding modes. For noncolluding Willies, we first employ a Lagrangian dual transformation procedure to reformulate the challenging optimization problem into a more tractable form. Subsequently, we develop an efficient block coordinate descent (BCD) algorithm that integrates semidefinite relaxation (SDR), projected gradient descent (PGD), Dinkelbach transformation, and successive convex approximation (SCA) techniques to tackle the resulting problem. For colluding Willies, we first derive the minimum detection error probability (DEP) by characterizing the optimal detection statistic, which is proven to follow the generalized Erlang distribution. Then, we develop a minimum mean square error (MMSE)-based algorithm to address the colluding detection problem. We further provide a comprehensive complexity analysis on the unified design framework. Simulation results demonstrate that the proposed method can significantly improve the covert sum rate, and achieve a superior balance between communication and radar performance compared with existing benchmark schemes.
Abstract:This paper investigates a rate-splitting multiple access (RSMA) for uplink pinching antenna system (PASS). Our objective is to maximize the uplink sum rate by jointly optimizing a continuous antenna positioning and user's transmission power. The formulated problem is highly non-convex and difficult to solve directly; to address this challenge, we propose an alternating optimization (AO) framework which decomposes the original problem into two tractable sub-problems, namely (i) power allocation optimization sub-problem and (ii) antenna position optimization sub-problem. Both sub-problems are solved using successive convex approximation (SCA)-based algorithm and solved alternatively until convergence. The RSMA access for PASS is compared with conventional non-orthogonal multiple access (NOMA) and space-division multiple access (SDMA) techniques. The performance of discrete antenna activation with PASS strategy is also examined. Simulation results demonstrate that our proposed framework significantly enhances the achievable sum rate compared to other multiple access methods.
Abstract:This paper explores a joint optimization of transmit power allocation and radiation coefficients in a downlink Pinching Antenna SyStem (PASS) employing Non-Orthogonal Multiple Access (NOMA). By leveraging the PASS-enabled flexible channel adjustment and NOMA's power allocation adaptability, a sum rate maximization problem is formulated with the objective of simultaneously optimizing base station (BS)'s transmit power coefficients and pinching antenna (PA)'s radiation powers. Due to its non-convexity and complexity, the formulated optimization problem is challenging to solve directly. Hence, we decompose the main problem into two sub-problems, namely transmit power allocation sub-problem and PA radiation power allocation sub-problem. In the first sub-problem, closed-form solutions are derived for the BS's power allocation among NOMA users. Meanwhile, in the second sub-problem, we optimize the PA's radiation power utilizing successive convex approximation (SCA). These two sub-problems are solved alternatively using Alternating Optimization (AO) until convergence. It should be noted that decoding order plays a significant role in NOMA-assisted PASS. Hence, two variations of decoding order are considered, namely: i) a high-complexity exhaustive search approach, and, ii) a low-complexity alternative that utilizes pre-determined channel information. Numerical results show that our proposed approach substantially improves the system's sum-rate compared to widely adopted equal power allocation PASS schemes.
Abstract:Network Slices (NSs) are virtual networks operating over a shared physical infrastructure, each designed to meet specific application requirements while maintaining consistent Quality of Service (QoS). In Fifth Generation (5G) networks, User Equipment (UE) can connect to and seamlessly switch between multiple NSs to access diverse services. However, this flexibility, known as Inter-Slice Switching (ISS), introduces a potential vulnerability that can be exploited to launch Distributed Slice Mobility (DSM) attacks, a form of Distributed Denial of Service (DDoS) attack. To secure 5G networks and their NSs against DSM attacks, we present in this work, PUL-Inter-Slice Defender; an anomaly detection solution that leverages Positive Unlabeled Learning (PUL) and incorporates a combination of Long Short-Term Memory Autoencoders and K-Means clustering. PUL-Inter-Slice Defender leverages the Third Generation Partnership Project (3GPP) key performance indicators and performance measurement counters as features for its machine learning models to detect DSM attack variants while maintaining robustness in the presence of contaminated training data. When evaluated on data collected from our 5G testbed based on the open-source free5GC and UERANSIM, a UE/ Radio Access Network (RAN) simulator; PUL-Inter-Slice Defender achieved F1-scores exceeding 98.50% on training datasets with 10% to 40% attack contamination, consistently outperforming its counterpart Inter-Slice Defender and other PUL based solutions combining One-Class Support Vector Machine (OCSVM) with Random Forest and XGBoost.



Abstract:This paper investigates a full-duplex (FD) scenario where a base station (BS) equipped with movable antennas (MAs) simultaneously provides communication services to a set of downlink (DL) and uplink (UL) users while also enabling sensing functionalities for target detection, thereby supporting integrated sensing and communication (ISAC) technology. Additionally, a receiving BS, also equipped with MAs (denoted as BS R), is responsible for capturing the reflected echo. To optimize this setup, we formulate an optimization problem aimed at maximizing the signal-to-noise and interference ratio (SINR) of the captured echo. This is achieved by jointly optimizing the transmit beamforming vectors at the FD BS, the receiving beamforming vectors at both the FD BS and BS R, the UL users' transmit power, and the MAs' positions at both BSs, all while satisfying the quality-of-service (QoS) requirements for both sensing and communication. Given the non-convex nature of the problem and the high coupling between the variables, we employ a gradient-based meta-learning (GML) approach tailored for large-scale optimization. Numerical results demonstrate the effectiveness of the proposed meta-learning approach, achieving results within 99% of the optimal solution. Furthermore, the MA-based scheme outperforms several benchmark approaches, highlighting its advantages in practical ISAC applications.