Where You Tap Matters: A Probe-and-Model Benchmark for Open-Set RF Fingerprinting
2026-07-23 • Cryptography and Security
Cryptography and Security
AI summaryⓘ
The authors studied how well Radio Frequency Fingerprint Identification (RFFI), a way to recognize devices based on signal quirks, works depending on where the signal is captured in the receiver processing steps. They found that collecting data after timing recovery or carrier recovery stages helps identify devices more accurately, while other stages make it harder. They tested multiple autoencoder models and found that simpler models worked just as well, showing that the choice of signal capture point is more important than the model complexity. Overall, the authors highlight that signal processing location greatly impacts RFFI performance more than advanced modeling techniques.
Radio Frequency Fingerprint IdentificationRFFIReceiver ChainBPSKCarrier RecoveryTiming RecoveryPulse ShapingGain NormalizationAutoencoderOpen-set Identification
Authors
Gabriele Oligeri, Savio Sciancalepore, Ingrid Huso, Fatima Al-Mousawi
Abstract
Radio Frequency Fingerprint Identification (RFFI) enables transmitter identification at the physical layer by learning device-specific impairments from received signals, yet the literature is inconsistent about where in the receiver chain those samples should be collected. Since distinct transformations are applied to the signal by the different receiver operations, i.e., carrier recovery, gain normalization, pulse shaping, and timing recovery, they can either tighten within-transmitter variability or suppress the features RFFI requires for classification. We present a systematic real-world evaluation of open-set, reconstruction-error RFFI using data collected at five probe points along a standard BPSK receiver chain. Our results show that RFFI is strongly probe-dependent: timing recovery and, to a lesser extent, carrier recovery enable low false-acceptance operation with limited in-distribution-out-of-distribution overlap, whereas other stages often require a false-acceptance ratio above 0.1 to achieve a true-acceptance ratio of 0.9. To test the validity of our findings across model selection, we benchmark several LLM-designed autoencoders using a controlled pipeline that holds preprocessing and MSE scoring fixed. These architectures confirm that RFFI is probe-dependent. Moreover, they do not outperform the baseline at the chosen operating point and typically increase training time. Overall, probe selection dominates reconstruction-based open-set RFFI performance, more than the autoencoder complexity.