Abstract:Radio frequency fingerprint identification (RFFI) exploits transmitter-specific hardware imperfections as physicallayer identity cues for Internet of Things (IoT) devices, but deep models often degrade across acquisition environments. In multi-antenna reception, antenna topology and frequencyoffset dynamics structure receiver observations, while capturedependent variation distorts target embeddings and misaligns source-trained decision boundaries. This article proposes physicsinformed structure anchoring with capture-aware prototype calibration (PISA-CAPC) to address both representation and decision mismatches. The two stages separate source representation construction from target decision correction. During source training, PISA organizes antenna tokens through a topology-guided graph, conditions propagation on CFO-derived acquisition dynamics, and applies bounded contextual residual suppression to preserve identity evidence. At deployment, unlabeled capture-aware prototype calibration (U-CAPC) estimates capture-local prototypes and recalibrates target decision scores while keeping the representation and source classifier fixed. Thus, calibration uses neither target labels nor target-domain backbone updates. On a measured WiFi benchmark with four receive antennas and ten transmitters, PISA-CAPC achieves a mean target-domain Macro-F1 of 0.9257 under a balanced transductive setting. Component ablations support complementary roles for topology-guided anchoring, CFO-conditioned modulation, reliability-aware token aggregation, contextual suppression, and capture-aware calibration. These results indicate that physically motivated representation learning can be combined with labelfree decision calibration to improve cross-environment RFFI under the evaluated protocol without changing the deployed backbone.
Abstract:Radio frequency fingerprint identification (RFFI) provides a physical-layer credential for Internet of Things devices, but open-set decisions become fragile when a threshold calibrated on a source receiver is transferred to a target receiver. Receiver shift can lower the confidence of known transmitters and cause false rejection; closed-set alignment can have the opposite effect by pulling unseen target transmitters into known regions and increasing false acceptance. This letter presents CRODA-ST, a structure-first adaptation framework for singlesource single-target cross-receiver open-set RFFI. Its two components target the bottlenecks behind unreliable source-calibrated rejection: Discriminative Structure Anchoring (DSA) restores target-receiver known-class references from limited labeled target enrollment samples, and Rejection-Oriented Alignment (ROA) reduces receiver-sensitive confidence fluctuations around the anchored structure. On the WiSig ManyTx dataset, CRODA-ST reaches 0.9092 known-class accuracy, 0.9692 AUROC, and 0.9580 OSCR. Score-sweep analysis further reduces FPR90 to 0.0469.
Abstract:Deep neural networks (DNNs) are vulnerable to backdoor attacks, where an attacker manipulates a small portion of the training data to implant hidden backdoors into the model. The compromised model behaves normally on clean samples but misclassifies backdoored samples into the attacker-specified target class, posing a significant threat to real-world DNN applications. Currently, several empirical defense methods have been proposed to mitigate backdoor attacks, but they are often bypassed by more advanced backdoor techniques. In contrast, certified defenses based on randomized smoothing have shown promise by adding random noise to training and testing samples to counteract backdoor attacks. In this paper, we reveal that existing randomized smoothing defenses implicitly assume that all samples are equidistant from the decision boundary. However, it may not hold in practice, leading to suboptimal certification performance. To address this issue, we propose a sample-specific certified backdoor defense method, termed Cert-SSB. Cert-SSB first employs stochastic gradient ascent to optimize the noise magnitude for each sample, ensuring a sample-specific noise level that is then applied to multiple poisoned training sets to retrain several smoothed models. After that, Cert-SSB aggregates the predictions of multiple smoothed models to generate the final robust prediction. In particular, in this case, existing certification methods become inapplicable since the optimized noise varies across different samples. To conquer this challenge, we introduce a storage-update-based certification method, which dynamically adjusts each sample's certification region to improve certification performance. We conduct extensive experiments on multiple benchmark datasets, demonstrating the effectiveness of our proposed method. Our code is available at https://github.com/NcepuQiaoTing/Cert-SSB.