<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" dtd-version="2.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Electron.</journal-id>
<journal-title>Frontiers in Electronics</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Electron.</abbrev-journal-title>
<issn pub-type="epub">2673-5857</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">856284</article-id>
<article-id pub-id-type="doi">10.3389/felec.2022.856284</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Electronics</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Statistical Analysis Based Feature Selection Enhanced RF-PUF With <inline-formula id="inf1">
<mml:math id="m1">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>99.8% Accuracy on Unmodified Commodity Transmitters for IoT Physical Security</article-title>
<alt-title alt-title-type="left-running-head">Bari&#x2009; et al.</alt-title>
<alt-title alt-title-type="right-running-head">RF-PUF on Unmodified Commodity Devices</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Bari&#x2009;</surname>
<given-names>Md Faizul</given-names>
</name>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/1637190/overview"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Agrawal&#x2009;</surname>
<given-names>Parv</given-names>
</name>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Chatterjee&#x2009;</surname>
<given-names>Baibhab</given-names>
</name>
<uri xlink:href="https://loop.frontiersin.org/people/1646395/overview"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Sen&#x2009;</surname>
<given-names>Shreyas</given-names>
</name>
<uri xlink:href="https://loop.frontiersin.org/people/579313/overview"/>
</contrib>
</contrib-group>
<aff>
<institution>Department of ECE</institution>, <institution>Purdue University</institution>, <addr-line>West Lafayette</addr-line>, <addr-line>IN</addr-line>, <country>United States</country>
</aff>
<author-notes>
<fn fn-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1317829/overview">Yogesh Singh Chauhan</ext-link>, Indian Institute of Technology Kanpur, India</p>
</fn>
<fn fn-type="edited-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1638890/overview">Nikhil Rangarajan</ext-link>, New York University Abu Dhabi, United Arab Emirates</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1022165/overview">Chinmay Chakraborty</ext-link>, Birla Institute of Technology, Mesra, India</p>
</fn>
<corresp id="c001">&#x2a;Correspondence: Md Faizul Bari&#x2009;, <email>mbari@purdue.edu</email>
</corresp>
<fn fn-type="other">
<p>This article was submitted to Integrated Circuits and VLSI, a section of the journal Frontiers in Electronics</p>
</fn>
</author-notes>
<pub-date pub-type="epub">
<day>25</day>
<month>04</month>
<year>2022</year>
</pub-date>
<pub-date pub-type="collection">
<year>2022</year>
</pub-date>
<volume>3</volume>
<elocation-id>856284</elocation-id>
<history>
<date date-type="received">
<day>17</day>
<month>01</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>14</day>
<month>03</month>
<year>2022</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2022 Bari&#x2009;, Agrawal&#x2009;, Chatterjee&#x2009; and Sen&#x2009;.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Bari&#x2009;, Agrawal&#x2009;, Chatterjee&#x2009; and Sen&#x2009;</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>Due to the diverse and mobile nature of the deployment environment, smart commodity devices are vulnerable to various spoofing attacks which can allow a rogue device to get access to a large network. The vulnerability of the traditional digital signature-based authentication system lies in the fact that it uses only a key/pin, ignoring the device fingerprint. To circumvent the inherent weakness of the traditional system, various physical signature-based RF fingerprinting methods have been proposed in literature and RF-PUF is a promising choice among them. RF-PUF utilizes the inherent nonidealities of the traditional RF communication system as features at the receiver to uniquely identify a transmitter. It is resilient to key-hacking methods due to the absence of secret key requirements and does not require any additional circuitry on the transmitter end (no additional power, area, and computational burden). However, the concept of RF-PUF was proposed using MATLAB-generated data, which cannot ensure the presence of device entropy mapped to the system-level nonidealities. Hence, an experimental validation using commercial devices is necessary to prove its efficacy. In this work, for the first time, we analyze the effectiveness of RF-PUF on commodity devices, purchased off-the-shelf, without any modifications whatsoever. We have collected data from 30 Xbee S2C modules used as transmitters and released as a public dataset. A new feature has been engineered through PCA and statistical property analysis. With a new and robust feature set, it has been shown that 95% accuracy can be achieved using only &#x223c;1.8&#xa0;ms of test data fed into a neural network of 10 neurons in 1 layer, reaching <inline-formula id="inf2">
<mml:math id="m2">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>99.8% accuracy with a network of higher model capacity, for the first time in literature without any assisting digital preamble. The design space has been explored in detail and the effect of the wireless channel has been investigated. The performance of some popular machine learning algorithms has been tested and compared with the neural network approach. A thorough investigation of various PUF properties has been done. With extensive testing of 41238000 cases, the detection probability for RF-PUF for our data is found to be 0.9987, which, for the first time, experimentally establishes RF-PUF as a strong authentication method. Finally, the potential attack models and the robustness of RF-PUF against them have been discussed.</p>
</abstract>
<kwd-group>
<kwd>IoT</kwd>
<kwd>machine learning</kwd>
<kwd>physical security</kwd>
<kwd>PUF</kwd>
<kwd>neural network (NN)</kwd>
<kwd>radio frequency</kwd>
<kwd>RF fingerprinting</kwd>
<kwd>Xbee dataset</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<title>1 Introduction</title>
<p>The fourth industrial revolution, fueled by low-power, high-speed modern communication systems has ushered in a new era of immersive and unprecedented user experience through smart devices. These devices are connected not only with each other but also to the cloud and are popularly known as the Internet of Things (IoT). The global IoT market is experiencing a rapid boost and according to a prediction by Norton, there will be around 21 billion connected devices by 2025 (<xref ref-type="bibr" rid="B56">Symanovich 2019</xref>). Researchers are already talking about the Internet of Everything (IoE) which essentially refers to people, data, and smart things connected to form an ecosystem that ensures a better and smarter lifestyle. The diverse application environment of the smart devices has rendered them vulnerable to a wide attacking surface. The weakest point in a network defines its overall security. The resource-limited, user-end devices are the weakest nodes of the IoT networks where a security compromise can provide access to a rogue device that can pose a massive threat to all the connected nodes and user data. So, the question of secure authentication before granting access to a large network is of increasing importance.</p>
<p>Traditional methods such as symmetric-key cryptography and asymmetric-key cryptography use secret private keys or public/private key pairs respectively, for encryption/decryption. Key-based methods require the storage of a secret key in a nonvolatile memory (NVM) or SRAM. However, they are vulnerable to different invasive/semi-invasive key-hacking attacks and side-channel attacks (<xref ref-type="bibr" rid="B30">Kocher et al., 1999</xref>; <xref ref-type="bibr" rid="B47">Quisquater and Samyde 2001</xref>; <xref ref-type="bibr" rid="B22">Hospodar et al., 2011</xref>). Multi-factor authentication (MFA) (<xref ref-type="bibr" rid="B57">Ting et al., 2015</xref>; <xref ref-type="bibr" rid="B39">Ometov et al., 2018</xref>) requires one or more verification factors (e.g., biometric factor, two-factor code from authentication app, etc.) along with the secret key. The widely-used open authentication (OAuth 2.0) protocol (<xref ref-type="bibr" rid="B38">OAuth 2.0 and OAuth 2022</xref>) for current IoT networks suffers from cross-site request forgery (CSRF) attacks (<xref ref-type="bibr" rid="B7">Barth et al., 2008</xref>; <xref ref-type="bibr" rid="B54">Siddiqui and Verma 2011</xref>). Both OAuth and MFA are inconvenient for large networks as they require manual verification. In addition to these vulnerabilities, the use of digital signatures also puts additional power and area burden which are typically small but could be significant for extremely energy and resource constraint edge devices.</p>
<p>To circumvent this, the idea of radio frequency physical unclonable function (RF-PUF) has been recently proposed (<xref ref-type="bibr" rid="B12">Chatterjee et al., 2019</xref>) using physical signature instead of or in addition to the digital signature. The concept of RF-PUF is explained in <xref ref-type="fig" rid="F1">Figure 1</xref>. RF-PUF exploits the <italic>inherent</italic> device imperfections due to manufacturing process variation and other system-level nonidealities (e.g., LO frequency offset, I-Q mismatch, DC offset, attenuation, fading, Doppler shift, etc.) as unique physical signatures. These signatures are used as features and fed to a neural network at the receiver to train it. Once trained, this network can be employed at the receiver for authentication. RF-PUF does not demand any additional preamble, digital keys, or assistive communication medium for authentication purposes. The absence of an external security key or preamble makes RF-PUF highly resilient to different types of key-hacking attacks and alleviates the need for preamble obfuscation (<xref ref-type="bibr" rid="B11">Chacko 2017</xref>). Also, it does not require any secured memory block for key storage. Thus, both power and area overhead is reduced on the resource-constrained edge-node side of an <italic>asymmetric</italic> IoT network.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption>
<p>The concept of RF-PUF exploits the inherent physical signature embedded in the device which manifests itself as different imperfections, which are used as features to train a neural network at the receiver end for authentication. The challenges involve developing a proper feature set, choosing a proper neural network architecture, and evaluating the concept in real, commodity devices.</p>
</caption>
<graphic xlink:href="felec-03-856284-g001.tif"/>
</fig>
<p>In (<xref ref-type="bibr" rid="B12">Chatterjee et al., 2019</xref>), the idea of RF-PUF was presented primarily based on simulation data using I-Q samples as features. However, the PUF output is stochastic in nature and it is very hard to accurately capture the device nonidealities in simulation. This calls for addressing the open research needs of experimental validation of RF-PUF and demonstration of high-accuracy on devices found &#x2018;in-the-wild&#x2019;. In this work, we address both these research problems by 1) analyzing the efficacy of RF-PUF on unmodified commodity devices and 2) introducing effective feature selection to increase RF-PUF accuracy <inline-formula id="inf3">
<mml:math id="m3">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>99.8</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula>. To achieve this, an improved and robust feature set is necessary to provide a reliable authentication method. We purchased commercially available 30 Xbee S2C devices and used them as unmodified commodity COTS (Components off-the-self) devices to experimentally validate RF-PUF. 155.4&#xa0;GB of data have been collected from the Xbee transceiver systems and 2.5&#xa0;GB of data have been used for experimentation. This dataset has also been made public on GitHub along with this paper, for further development and validation by the RF-Security community.</p>
<p>It has been shown that 95<italic>%</italic> accuracy can be achieved even with a lightweight, single-layer neural network with 10 neurons and <inline-formula id="inf4">
<mml:math id="m4">
<mml:mo>&#x223c;</mml:mo>
<mml:mn>1.8</mml:mn>
</mml:math>
</inline-formula>&#xa0;ms (30&#xa0;kB) of test data, which ensures the feasibility of RF-PUF in a low-latency network. With statistical analysis, a new feature has been augmented that massively boosts the performance of the network. The impact of the variation in neural network model capacity and the amount of training data on detection accuracy has been explored. Along with artificial neural networks, experiments have been performed with multiple traditional machine learning algorithms, and their performance is compared in terms of the number of devices. A detailed analysis of the PUF properties has been done to evaluate the eligibility of RF-PUF as a PUF. Inter-PUF and intra-PUF hamming distances have been calculated and it has been proved that for commodity COTS (Components off-the-self) devices without any modification, RF-PUF shows strong identifiability with a very high (99.87<italic>%</italic>) detection probability. As an authentication method, possible vulnerabilities and attack models for RF-PUF have been investigated and the robustness of RF-PUF against them has been proved. The insights gathered from these analyses and experiments may prove to be extremely important for the design and implementation of RF-PUF in the future in realistic application scenarios with &#x201c;in-the-wild&#x201d; devices.</p>
<sec id="s1-1">
<title>1.1 Our Contribution</title>
<p>In this work, through thorough statistical analysis of unmodified commodity devices, we have found an optimum feature that improves the accuracy of RF-PUF significantly on a suite of commodity hardware devices leading to <inline-formula id="inf5">
<mml:math id="m5">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula> 99.8% accuracy, along with PUF property analysis and security vulnerability analysis. Detailed contributions are as follows:<list list-type="simple">
<list-item>
<p>(1) Feature engineering: Principal component analysis has been performed on the existing feature set found in the literature to find the dominant feature. Through moment analysis on the dominant feature (i.e. carrier frequency offset) we demonstrate that the addition of a feature called COV (ratio of standard deviation and mean of carrier frequency offset) significantly helps in achieving high <inline-formula id="inf6">
<mml:math id="m6">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>&#x3e;</mml:mo>
<mml:mn>99.8</mml:mn>
<mml:mi>%</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> accuracy (<xref ref-type="sec" rid="s4-3">Section 4.3</xref>).</p>
</list-item>
<list-item>
<p>(2) Highest accuracy achieved with unmodified COTS devices: 30 Xbee S2C modules have been used without the help of any assisting communication preamble or any modification to the devices whatsoever. Using data received over a wireless channel with a suitable feature set and a lightweight neural network, 99.8<italic>%</italic> accuracy can be achieved which, to our best knowledge, is the highest accuracy using this many commodity COTS devices considering the wireless channel (<xref ref-type="sec" rid="s4-4">Section 4.4</xref>).</p>
</list-item>
<list-item>
<p>(3) RF-PUF established as a strong PUF: Any distinct PUF class is identified through some properties that make it a separate class. They include constructability, evaluability, uniqueness, reliability, and identifiability. We have explored these properties for RF-PUF in detail, calculated intra-PUF and inter-PUF hamming distances and in an extensive test of 41238000 cases, we have shown that the probability of proper identification of an RF-PUF instance is 0.9987. This is the first time analysis of RF-PUF as a PUF class which experimentally demonstrates RF-PUF as a strong and unique PUF class by itself (<xref ref-type="sec" rid="s6">Section 6</xref>).</p>
</list-item>
<list-item>
<p>(4) Performance evaluation using popular machine learning algorithms and comparison with neural network (NN) based approach. It has been shown that even a lightweight NN with a single hidden layer can handle <inline-formula id="inf7">
<mml:math id="m7">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>300 devices with 99.9% accuracy, unlike ML algorithms (<xref ref-type="sec" rid="s5-4">Section 5.4</xref>).</p>
</list-item>
<list-item>
<p>(5) Wireless channel variability analysis on the accuracy of RF-PUF and the effect of network depth on accuracy with and without a wireless channel has been presented. Discussion on possible important attack models and the robustness of RF-PUF against such attacks (<xref ref-type="sec" rid="s5-5">Section 5.5</xref>).</p>
</list-item>
<list-item>
<p>(6) Public Dataset: Our collected data have been released as a public dataset for the whole community to explore and experiment with (<xref ref-type="sec" rid="s3-3">Section 3.3</xref>).</p>
</list-item>
</list>
</p>
<p>The rest of the paper is structured as follows: <xref ref-type="sec" rid="s2">Section 2</xref> provides relevant works on RF fingerprinting and device authentication. <xref ref-type="sec" rid="s3">Section 3</xref> provides an overview of our experimental setup, data collection, and data processing method. <xref ref-type="sec" rid="s4">Section 4</xref> presents a new feature set development using statistical analysis and corresponding performance enhancement. <xref ref-type="sec" rid="s5">Section 5</xref> explores the design space in detail. <xref ref-type="sec" rid="s6">Section 6</xref> analyzes various PUF properties in the context of RF-PUF. <xref ref-type="sec" rid="s7">Section 7</xref> discusses possible attack models and the resilience of RF-PUF against them. Finally, <xref ref-type="sec" rid="s8">section 8</xref> concludes this paper.</p>
</sec>
</sec>
<sec id="s2">
<title>2 Related Works</title>
<p>Traditional RF fingerprinting approaches use modulation domain metrics, statistical parameters, transient properties, wavelet-based approaches, etc. In (<xref ref-type="bibr" rid="B10">Brik et al., 2008</xref>), authors used various modulation domain metrics such as frequency and IQ offset, magnitude and phase error, sync correlation, etc. to propose a radio device identification method called PARADIS (PAssive RAdiometic Device Identification System). They collected data from 138 Atheros network interface cards (NIC) and tested their proposed methods (SVM-based and kNN-based) on the ORBIT testbed facility (<xref ref-type="bibr" rid="B40">ORBIT 2022</xref>). They achieved an error rate of 3% for 138 NIC classification. In (<xref ref-type="bibr" rid="B69">Zhuo et al., 2017</xref>) authors have used IQ imbalance-based features for device fingerprinting. Based on simulation data from 5 transmitters and 400 signals from each of them, they have shown that they can achieve <inline-formula id="inf8">
<mml:math id="m8">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>90% accuracy for SNR &#x2265; 15&#xa0;dB and <inline-formula id="inf9">
<mml:math id="m9">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>99% accuracy for SNR &#x2265; 20&#xa0;dB. Authors in (<xref ref-type="bibr" rid="B16">Danev et al., 2009</xref>) have used modulation shape and spectral features to identify RFIDs (Radio Frequency Identification Devices). They collected data from 50 JCOP NXP 4.1 smart cards and 8 e-passports and matched the extracted fingerprints with the reference using standardized Euclidean distances. For 50 RFIDs, they achieved 95% accuracy when spectral features are used standalone and 97.5% accuracy when the features are combined. In (<xref ref-type="bibr" rid="B24">Huang and Zheng 2012</xref>), authors have used constellation deviation from ideal constellation as features. This work is similar to previously mentioned works in the sense that constellation error contains information about IQ imbalances, magnitude and phase error, etc. They collected data from 7 TDMA satellites for testing and achieved an accuracy of <inline-formula id="inf10">
<mml:math id="m10">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>95%.</p>
<p>Several fingerprinting methods use transients during device start-up and extract features from them. But before feature extraction, proper detection of the transients is a major challenge and several approaches for that are described in (<xref ref-type="bibr" rid="B53">Shaw and Kinsner 1997</xref>; <xref ref-type="bibr" rid="B20">Hall et al., 2003</xref>). Authors in (<xref ref-type="bibr" rid="B15">Danev and Capkun 2009</xref>) have used data from 50 COTS devices (Tmote Sky sensor) and FFT-based Fisher features to show an accuracy of <inline-formula id="inf11">
<mml:math id="m11">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>99%. An interesting approach was described in (<xref ref-type="bibr" rid="B66">Yuan et al., 2014</xref>) where authors calculated energy distribution of transients in time and frequency domain using Hilbert-Huang Transform (<xref ref-type="bibr" rid="B23">Huang 2014</xref>) which uses IMFs in EMD (<xref ref-type="bibr" rid="B3">Bari and Anowarul Fattah 2020</xref>) with Hilbert transform. However, their dataset was very small, consisting of 8&#xa0;GSM mobile phones used as transmitters. Similar work was proposed in (<xref ref-type="bibr" rid="B58">Ur Rehman et al., 2012</xref>), where authors calculated energy envelopes for Bluetooth devices. Their dataset was also small, containing only 7 Bluetooth devices. In this small dataset, they could achieve 99.9% accuracy. Some wavelet-based approaches have also been used in literature. For example, authors in (<xref ref-type="bibr" rid="B29">Klein et al., 2009</xref>) have used DT-CWT (dual-tree complex wavelet transform) based features to fingerprint RF devices. At low SNR (8dB), they could achieve 80% accuracy. Authors in (<xref ref-type="bibr" rid="B8">Bertoncini et al., 2012</xref>) have used dynamic wavelet fingerprints to classify 146 RFID devices. They used four types of classifiers (LDC, QDC, k-NN, and SVM) and achieved 99% accuracy. Another work (<xref ref-type="bibr" rid="B27">Kennedy et al., 2008</xref>) involved frequency domain analysis with a k-NN classifier which achieved 97% accuracy at 30&#xa0;dB SNR.</p>
<p>There are other works that have used various time and frequency domain properties of individual transmitters for RF fingerprinting (<xref ref-type="bibr" rid="B48">Rasmussen and Capkun 2007</xref>; <xref ref-type="bibr" rid="B52">Scanlon et al., 2010</xref>; <xref ref-type="bibr" rid="B37">Nguyen et al., 2011</xref>; <xref ref-type="bibr" rid="B9">Bihl et al., 2016</xref>; <xref ref-type="bibr" rid="B59">Vo-Huu et al., 2016</xref>; <xref ref-type="bibr" rid="B44">Peng et al., 2018</xref>; <xref ref-type="bibr" rid="B63">Xie et al., 2018</xref>). However, both time and frequency domain analysis have their limitations in the form of detecting the start and end of the transients, high oversampling ratios, and the need for fixed preambles to avoid data dependency. MAC layer and other upper layers of the communication protocol have also been used for RF-fingerprinting (<xref ref-type="bibr" rid="B64">Xu et al., 2016a</xref>). However, device identifiers in upper layers like IMEI number, IP address, MAC address, etc. can be spoofed (<xref ref-type="bibr" rid="B13">Chomsiri 2007</xref>; <xref ref-type="bibr" rid="B31">Kumar et al., 2015</xref>; <xref ref-type="bibr" rid="B2">Alotaibi and Elleithy 2016</xref>; <xref ref-type="bibr" rid="B62">Wang and Yang 2017</xref>). Several statistical parameter-based approaches have also been proposed. For example, authors in (<xref ref-type="bibr" rid="B43">Patel 2015</xref>) have used various statistical features to identify 4 Xbee devices. Using a Random Forrest classifier (<xref ref-type="bibr" rid="B42">Pal 2005</xref>), they could achieve 97% accuracy for SNR &#x2265; 10&#xa0;dB. Another work (<xref ref-type="bibr" rid="B33">Lukacs et al., 2015</xref>) has used RF-DNA (Radio Frequency Distinct Native Attribute) dependent RF fingerprinting. RF-DNA uses various statistical features. For a 7 class dataset, authors have achieved an average accuracy of 81% for the MDA/ML classifier. For real-time device authentication, authors in (<xref ref-type="bibr" rid="B4">Bari et al., 2021a</xref>) have used a dynamic irregular clustering approach. One attractive feature here is that this algorithm learns incrementally with more input data.</p>
<p>Recently deep learning-based RF fingerprinting has gained popularity. Different types of deep networks (convolutional neural networks or CNN (<xref ref-type="bibr" rid="B1">Albawi et al., 2017</xref>; <xref ref-type="bibr" rid="B28">Kim 2017</xref>), recurrent neural network or RNN (<xref ref-type="bibr" rid="B36">Medsker and Jain 2001</xref>; <xref ref-type="bibr" rid="B32">Liu et al., 2016</xref>), generative adversarial networks or GAN (<xref ref-type="bibr" rid="B35">Mao et al., 2017</xref>; <xref ref-type="bibr" rid="B14">Creswell et al., 2018</xref>), etc.) are being used extensively for RF device identification and authentication. Hanna et al. utilized power amplifier nonlinearity with deep learning to fingerprint RF devices (<xref ref-type="bibr" rid="B21">Hanna and Cabric 2019</xref>) using simulation data. In (<xref ref-type="bibr" rid="B51">Sankhe et al., 2020</xref>), authors proposed a new method called ORACLE (Optimized Radio clAssification through Convolutional neuraL nEtworks) using the AlexNet-like CNN framework. With data from 16 USRP X310 transmitters, they could achieve 87.13 and 99% accuracy for the static and quasi-static channels respectively. However, wireless data are contaminated with noise and interference, any use of the RF data without processing always posits a risk of huge performance drop in scenarios where environmental nonidealities can go beyond the estimation that was used while designing the network. Processing data, extracting a proper feature set, and unraveling the mystery of the design space can render a robust authentication method that is less vulnerable to environmental factors and provides more flexibility to the designer. That is why RF-PUF performs better than the CNN-based approach as shown in (<xref ref-type="bibr" rid="B5">Bari et al., 2021b</xref>). In (<xref ref-type="bibr" rid="B55">Soltani et al., 2020</xref>), authors have used multiple deep networks and integrated their outputs to make a final prediction. They collected data from 7 UAVs or drones (DJI M100) and got maximum accuracy of 99% with data augmentation. Using data from 5 USRP devices and bispectrum of the received signal as the feature, authors in (<xref ref-type="bibr" rid="B17">Ding et al., 2018</xref>) have achieved 75% accuracy with a custom CNN. Another work (<xref ref-type="bibr" rid="B45">Peng et al., 2020</xref>) also used custom CNN with DCTF (Differential Constellation Trace Figure) as features to fingerprint 16 Xbee devices. For SNR &#x2265; 15&#xa0;dB, they achieved 90% accuracy. In (<xref ref-type="bibr" rid="B70">Zong et al., 2020</xref>), authors have used CNN to identify 5 transmitter devices. Although they achieved 99% accuracy, their dataset is quite small.</p>
<p>A much bigger and more extensive dataset is the DARPA RFMLS dataset, containing data from 10000 devices (<xref ref-type="bibr" rid="B25">Jian et al., 2020</xref>). The authors have presented two architecture based on AlexNet and ResNet-50 to perform multiple learning tasks. On this dataset, another group of researchers has used a modified CNN called ADCC (augmented dilated causal convolution network) (<xref ref-type="bibr" rid="B49">Robinson et al., 2020</xref>). Apart from these traditional or modified CNN-based methods, there are some works reported in the literature that use GAN. For example, AC-WGAN (Auxiliary Classifier Wasserstein Generative Adversarial Networks) achieves 95% accuracy for UAV classification (<xref ref-type="bibr" rid="B68">Zhao et al., 2018</xref>). For a low number of devices (8 USRP B210), authors have achieved 99.9% accuracy using GAN (<xref ref-type="bibr" rid="B50">Roy et al., 2019</xref>). Some other prominent works for RF fingerprinting using deep learning are mentioned in (<xref ref-type="bibr" rid="B41">O&#x2019;Shea and Hoydis 2017</xref>; <xref ref-type="bibr" rid="B60">Wang et al., 2017</xref>; <xref ref-type="bibr" rid="B61">Wang et al., 2018</xref>; <xref ref-type="bibr" rid="B67">Zhang et al., 2019</xref>). A detailed review of RF fingerprinting methods can be found in (<xref ref-type="bibr" rid="B65">Xu et al., 2016b</xref>; <xref ref-type="bibr" rid="B19">Guo et al., 2019</xref>; <xref ref-type="bibr" rid="B26">Jagannath et al., 2022</xref>). Our experimental study in this work shows <inline-formula id="inf12">
<mml:math id="m12">
<mml:mo>&#x3e;</mml:mo>
</mml:math>
</inline-formula>99.8% detection accuracy which is better than almost all the studies mentioned above. Only a few have achieved 99.9% accuracy, but with a much smaller dataset (containing less than 10 devices) compared to our dataset of 30 devices.</p>
</sec>
<sec id="s3">
<title>3 Experimental Setup</title>
<sec id="s3-1">
<title>3.1 Physical Device Setup</title>
<p>For experimental validation, 30 XBee S2C modules are chosen (IEEE 802.15.4 standard) which is designed for industrial and commercial use. <xref ref-type="fig" rid="F2">Figure 2A</xref> shows the Xbee devices whereas <xref ref-type="fig" rid="F2">Figure 2B</xref>, and <xref ref-type="fig" rid="F2">Figure 2C</xref> show the block diagram and the actual setup. The TX and RX are kept 1&#xa0;m apart. Using SMA cable, a HackRF One software-defined radio (SDR) module has been connected either to the TX (case 1) or to the RX (case 2) to extract data excluding (case 1) or including (case 2) wireless channel.</p>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption>
<p>
<bold>(A)</bold> Commodity off-the-shelf devices (30 Xbee S2C modules) used as transmitters for data collection. <bold>(B)</bold> Conceptual experimental setup. <bold>(C)</bold> Actual experimental setup in the lab. The TX and RX are placed 1&#xa0;m apart (they are close here for image capturing purposes only) and a HackRF module was used to collect data either from the TX (case 1) or RX (case 2). GNU Radio records the collected data and shows a live constellation (visible on-screen). The rotating constellation is later processed in MATLAB through coarse and fine frequency compensation.</p>
</caption>
<graphic xlink:href="felec-03-856284-g002.tif"/>
</fig>
</sec>
<sec id="s3-2">
<title>3.2 Data Collection and Filtering Noise</title>
<p>A 31-bit pseudo-random bit sequence (PRBS) is generated in MATLAB and fed to each TX which transmits this data for 60&#xa0;s with QPSK modulation at 2.465&#xa0;GHz and 230,400&#xa0;bps baud rate. These data were captured in a Xbee RX module. Simultaneously, data were also captured by a HackRF one software-defined radio (SDR) module, sampled at 6&#xa0;MSps, and stored by GNU Radio. The captured data are divided into several frames, each containing a number of samples. From the constellation diagram of the frame data (<xref ref-type="fig" rid="F3">Figure 3</xref>), it is found that some frames have no significant data points and contain only noise as the Xbee devices transmit data intermittently due to their buffer limitation. These blank frames containing only noise were discarded.</p>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption>
<p>Grouping collected data in a number of frames and filtering of data for acceptable frames. This step is required as the Xbee module transmits data on an interval.</p>
</caption>
<graphic xlink:href="felec-03-856284-g003.tif"/>
</fig>
</sec>
<sec id="s3-3">
<title>3.3 Public Dataset</title>
<p>This dataset contains raw data collected from 30 Xbee S2C transmitters for both cases (excluding and including the channel) in binary format. The total size of the dataset is 155.4&#xa0;GB (each transmitter data is &#x223c;2.5&#xa0;GB). It can be downloaded from Sparclab RF-PUF Dataset (<xref ref-type="bibr" rid="B6">Bari and Sen 2022</xref>).</p>
</sec>
</sec>
<sec id="s4">
<title>4 Feature Extraction</title>
<sec id="s4-1">
<title>4.1 Initial Feature Set</title>
<p>In our work, CFO and I-Q data are taken as features just as in the original RF-PUF paper (<xref ref-type="bibr" rid="B12">Chatterjee et al., 2019</xref>). The previously generated frames are filtered using matched filtering, frequency compensated (both fine and coarse), and finally synchronized using timing recovery. In this process, CFO is found as a byproduct. Along with CFO, the compensated in-phase and quadrature-phase components in four quadrants are used as features. The 9 features (CFO &#x2b; 4 I-components &#x2b; 4 Q-components) from each frame and 1,000 frames from each TX lead to a feature set of 9 &#xd7; 1000. The final feature matrix is a combination of these feature sets from all 30 devices and has a size of 9 &#xd7; 30000.</p>
</sec>
<sec id="s4-2">
<title>4.2 Accuracy With Carrier Frequency Offset and I-Q Features</title>
<p>The whole feature data are divided into 70%, 15%, and 15<italic>%</italic> respectively for training, validation, and test purposes and fed into a neural network (NN). The performance of the neural network is tested by varying the number of neurons and hidden layers. <xref ref-type="fig" rid="F4">Figure 4A</xref> shows the accuracy of the trained model for different neural networks. The accuracy is less than 75<italic>%</italic> in all test cases. Since exploring different NN configurations does not provide expected accuracy, our choice here is to: 1) form an improved feature set to be used with the NN 2) use different machine learning (ML) algorithms 3) use more data. We first search for an improved feature set for better accuracy. Later, the effect of more data is shown in <xref ref-type="sec" rid="s5-1">subsection 5.1</xref>, <xref ref-type="sec" rid="s5-2">5.2</xref> and a comparison of different ML algorithms and NN is discussed in <xref ref-type="sec" rid="s5-4">subsection 5.4</xref>.</p>
<fig id="F4" position="float">
<label>FIGURE 4</label>
<caption>
<p>
<bold>(A)</bold> Accuracy vs. the number of neurons in each hidden layer. Even after increasing the number of hidden layers, the accuracy remains <inline-formula id="inf13">
<mml:math id="m13">
<mml:mo>&#x3c;</mml:mo>
<mml:mn>75</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula>. <bold>(B)</bold> Principal Component Analysis (PCA) reveals that the first principal component (PC) causes most variation, which in turn depends mostly on the carrier frequency offset, CFO. <bold>(C)</bold> Mean (<italic>&#x3bc;</italic>) and standard deviation (<italic>&#x3c3;</italic>) of the dominant feature (CFO) were analyzed in search of a new feature. It reveals that these statistical parameters vary significantly among transmitters. So, their ratio or coefficient of frequency offset variation, COV &#x3d; <inline-formula id="inf14">
<mml:math id="m14">
<mml:mfrac>
<mml:mrow>
<mml:mtext>standard&#x2009;deviation</mml:mtext>
<mml:mspace width="0.3333em"/>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>&#x3c3;</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="0.3333em"/>
<mml:mtext>of&#x2009;CFO</mml:mtext>
</mml:mrow>
<mml:mrow>
<mml:mtext>mean</mml:mtext>
<mml:mspace width="0.3333em"/>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>&#x3bc;</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="0.3333em"/>
<mml:mtext>of&#x2009;CFO</mml:mtext>
</mml:mrow>
</mml:mfrac>
</mml:math>
</inline-formula> is taken as the 10<sup>th</sup> feature. <bold>(D)</bold> The inclusion of COV shows significant improvement in the detection accuracy. Using a single hidden layer with only 10 neurons, 95<italic>%</italic> accuracy is achieved, and <inline-formula id="inf15">
<mml:math id="m15">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>99.8</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy is reached for <inline-formula id="inf16">
<mml:math id="m16">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>50</mml:mn>
</mml:math>
</inline-formula> neurons.</p>
</caption>
<graphic xlink:href="felec-03-856284-g004.tif"/>
</fig>
</sec>
<sec id="s4-3">
<title>4.3 Statistical Analysis</title>
<sec id="s4-3-1">
<title>4.3.1 Principal Component Analysis</title>
<p>We start the investigation by performing Principal Component Analysis (PCA) with feature matrix as input (each feature represents one input dimension). <xref ref-type="fig" rid="F4">Figure 4B</xref> shows the principal components and their contribution to the variances. The first principal component (PC) contributes to most of the variances and the input to PC mapping reveals that the CFO is the most dominant feature. So, an in-depth statistical property analysis of the CFO can help in deriving a new feature.</p>
</sec>
<sec id="s4-3-2">
<title>4.3.2 Moment Analysis</title>
<p>Since CFO varies from frame to frame (i.e., with time), it is intuitive to look at the moments of their distribution. Specifically, we want to look at first and second-order moments (mean and variance). <xref ref-type="fig" rid="F4">Figure 4C</xref> shows the absolute values of mean and standard deviation (square root of variance) of CFO. These parameters vary significantly from TX to TX in most cases. And even if for any two TX, the mean is similar, the standard deviation is different, and vice versa. If they can be combined to form a new feature, that can provide significant discrimination among transmitters and lead to much better accuracy. In statistics, the ratio of standard deviation and mean is known as the coefficient of variation. So, using this statistical parameter, we form a new feature named the coefficient of frequency offset variation (COV) which is defined as:<disp-formula id="equ1">
<mml:math id="m17">
<mml:mi>C</mml:mi>
<mml:mi>O</mml:mi>
<mml:mi>V</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mfenced open="|" close="|">
<mml:mrow>
<mml:mfrac>
<mml:mrow>
<mml:mtext mathvariant="italic">Standard deviation of CFO</mml:mtext>
</mml:mrow>
<mml:mrow>
<mml:mtext mathvariant="italic">Mean of CFO</mml:mtext>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
</p>
</sec>
</sec>
<sec id="s4-4">
<title>4.4 Performance Using Coefficient of Frequency Offset Variation Feature</title>
<p>COV is included as the 10<sup>th</sup> feature in our existing feature matrix. From PCA analysis, it is already revealed that the I-Q features contribute to much fewer variances and can be discarded by trading some accuracy. Since our goal is to achieve maximum possible accuracy, we still keep them as features. Also, I-Q values contain channel information, which will help the NN to compensate for the wireless channel (channel effect is explained in <xref ref-type="sec" rid="s5-5">subsection 5.5</xref>).</p>
<p>After including COV as the 10<sup>th</sup> feature, our neural network was trained, validated, and tested again with the new feature matrix. <xref ref-type="fig" rid="F4">Figure 4D</xref> shows that the performance of the network has improved drastically. With just a single hidden layer, <inline-formula id="inf17">
<mml:math id="m18">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>95</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy can be achieved using 10 neurons and can hit up to 99.9<italic>%</italic> accuracy by increasing the number of neurons.</p>
</sec>
</sec>
<sec id="s5">
<title>5 Evaluation of Design Parameters</title>
<sec id="s5-1">
<title>5.1 Effect of Number of Samples</title>
<p>
<xref ref-type="fig" rid="F5">Figure 5A</xref> shows the plot of detection accuracy versus the number of samples in each frame for different neural networks. The general trend (Bold red arrow) is that, for each NN configuration, detection accuracy improves with the increase in the number of samples (along the <italic>x</italic>-axis). This is expected because a higher number of samples provide more information and hence better performance. We want to mention that there might be some temporary sporadic drops in accuracy (as in the red line where accuracy slightly drops from 50 to 100 samples), but that does not represent the general trend which clearly shows that more samples translate to better accuracy. Also, <inline-formula id="inf18">
<mml:math id="m19">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>95</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy point is reached at around 150 samples per frame which is equivalent to 12.5&#xa0;ms of total data (or 1.8&#xa0;ms test data). Hence, we can reach the 95<italic>%</italic> accuracy bar using quite small test data.</p>
<fig id="F5" position="float">
<label>FIGURE 5</label>
<caption>
<p>
<bold>(A)</bold> Detection accuracy vs. the number of samples per frame for different neural networks which shows a trend of accuracy improvement (indicated by red arrow) with the increase in sample number. <bold>(B)</bold> Detection accuracy for different frame numbers shows higher frame number renders better performance. <bold>(C)</bold> Detection accuracy versus the number of neurons per layer. The general trend shows that accuracy improves with the increase in the number of neurons in each layer. Also, accuracy typically improves with more hidden layers until the higher model order causes overfitting and degrades performance.</p>
</caption>
<graphic xlink:href="felec-03-856284-g005.tif"/>
</fig>
</sec>
<sec id="s5-2">
<title>5.2 Effect of the Number of Frames in Feature Set</title>
<p>
<xref ref-type="fig" rid="F5">Figure 5B</xref> shows accuracy versus the number of neurons per layer for two different frame numbers, 500 and 1000. With a higher frame number, the information content of each transmitter device increases. As the NN gets more information about the device, its performance improves and the detection accuracy gets better as shown by the blue (1000 frames) and red lines (500 frames) respectively. We can generalize the previous subsection (sample number effect) and this subsection as this: more data render better performance.</p>
</sec>
<sec id="s5-3">
<title>5.3 Effect of the Neural Network Parameters</title>
<p>
<xref ref-type="fig" rid="F5">Figure 5C</xref> shows the plots of accuracy versus the number of neurons in each hidden layer. As the number of neurons increases along the <italic>x</italic>-axis, accuracy, in general, gets better (there might be sporadic peaks or drops as in the case of the blue line with an outlier peak at 30 neurons, but this does not represent a general trend). Also, as the number of hidden layers increases, the network performs better initially (from blue to red line), but later it creates an overfitting problem (the green line) where the model capacity is too large compared to data. This phenomenon directly manifests itself as a degradation in performance. Hence, there is an optimum model capacity up to which accuracy increases, and beyond that accuracy drops.</p>
</sec>
<sec id="s5-4">
<title>5.4 Using Simple Machine Learning Algorithm</title>
<p>It has been observed that the COV values vary significantly among different transmitters. When a simple feature displays a significant separation among different classes, it can be modeled with a complex <italic>if-else ladder</italic> structure. This implies that even simple ML algorithms (e.g. Tree) can show good results. <xref ref-type="fig" rid="F6">Figure 6A</xref> shows that some popular ML algorithm achieves <inline-formula id="inf19">
<mml:math id="m20">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>95</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy.</p>
<fig id="F6" position="float">
<label>FIGURE 6</label>
<caption>
<p>
<bold>(A)</bold> Popular ML algorithms show high accuracy for 30 Xbee devices. <bold>(B)</bold> The accuracy of simple ML networks drops when the number of TX is large, wherein the neural network still holds up with <inline-formula id="inf20">
<mml:math id="m21">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>99.9</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy.</p>
</caption>
<graphic xlink:href="felec-03-856284-g006.tif"/>
</fig>
<p>The true power of the neural network comes into play when the number of TX increases as shown in <xref ref-type="fig" rid="F6">Figure 6B</xref>. For this, features are generated for 300 TX devices following a Gaussian distribution (as in (<xref ref-type="bibr" rid="B12">Chatterjee et al., 2019</xref>)) with the same mean and variance as that of the original 30 TX devices, for both inter and intra-class variations. <xref ref-type="fig" rid="F6">Figure 6B</xref> shows that as the number of TX increases, accuracy falls after a certain point (<inline-formula id="inf21">
<mml:math id="m22">
<mml:mo>&#x223c;</mml:mo>
<mml:mn>100</mml:mn>
</mml:math>
</inline-formula> TX) even for support vector machines (SVM), and it fails to converge for <inline-formula id="inf22">
<mml:math id="m23">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>150</mml:mn>
</mml:math>
</inline-formula> TX.</p>
</sec>
<sec id="s5-5">
<title>5.5 Effect of Wireless Channel</title>
<p>So far, nonidealities due to TX were considered and the wireless channel was ignored (TX and RX are connected via SMA cable). But the channel itself adds some nonidealities. Here, the effect of a static wireless channel (1&#xa0;m of fixed TX-RX separation) has been analyzed. <xref ref-type="fig" rid="F7">Figure 7</xref> shows accuracy versus neuron number in a single layer, with and without the wireless channel. For iso-accuracy of 95<italic>%</italic>, wireless channel demands slightly higher model capacity (10 vs. 15 neurons). But when the number of neurons increases <inline-formula id="inf23">
<mml:math id="m24">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>&#x3e;</mml:mo>
<mml:mn>50</mml:mn>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, both curves merge and render similar accuracy.</p>
<fig id="F7" position="float">
<label>FIGURE 7</label>
<caption>
<p>Comparison of the network performance in the cases of including and excluding the wireless channel data. The network needs 15 neurons compared to 10 neurons in a hidden layer to achieve 95<italic>%</italic> accuracy for the case where the channel is considered. But with higher model capacity, both lines converge and the network learns the channel effect on data. d the network learns the channel effect on data. The light red box shows the region where the network fails to learn transmitter variation, light yellow box shows the region where the network learns transmitter variation but fails to learn the variation due to the wireless channel. The light green box shows the region where the network learns both the transmitter and channel variation properly.</p>
</caption>
<graphic xlink:href="felec-03-856284-g007.tif"/>
</fig>
<p>In one of our recent works (<xref ref-type="bibr" rid="B5">Bari et al., 2021b</xref>), we applied RF-PUF on the ORACLE dataset which contains data for 16 USRP X310 TX for both static and quasi-static (variable TX-RX separation) cases with a channel length varying from 2 to 62&#xa0;ft. We have shown that RF-PUF achieves 100<italic>%</italic> accuracy up to 38&#xa0;ft and <inline-formula id="inf24">
<mml:math id="m25">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>95</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy even at 62&#xa0;ft channel length. This result confirms that the RF-PUF approach can make the channel compensation with the help of NN and render high performance even in a long wireless channel. On a side note, that work combined with current work, also confirms that RF-PUF achieves high accuracy on experimental data in different platforms (XBee vs. USRP radios using WiFi) for different devices.</p>
</sec>
<sec id="s5-6">
<title>5.6 Computational Complexity of RF-PUF</title>
<p>RF-PUF does not add any additional circuitry on the TX side. Hence there is no extra computational burden at the TX end. On the receiver side, it employs just a multilayer perceptron (MLP) or NN along with the standard receiver. The standard receiver corrects the received signal and in the process discards various system-level nonidealities which are used as features to the NN. Hence, the computational complexity of RF-PUF is that of a neural network. For an n-dimensional input (<italic>n</italic> &#x3d; 10 for our case), the training phase (done only once) has a computational complexity on the order of <inline-formula id="inf25">
<mml:math id="m26">
<mml:mi mathvariant="script">O</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>5</mml:mn>
</mml:mrow>
</mml:msup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, whereas the inference phase has a computational complexity on the order of <inline-formula id="inf26">
<mml:math id="m27">
<mml:mi mathvariant="script">O</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>4</mml:mn>
</mml:mrow>
</mml:msup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> (a derivation of the orders can be found at (<xref ref-type="bibr" rid="B18">Fredenslund 2022</xref>)). Also, the statistical feature formation requires mean and standard deviation calculation which has computational complexity in the order of <inline-formula id="inf27">
<mml:math id="m28">
<mml:mi mathvariant="script">O</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, which is negligible compared to the inference order.</p>
</sec>
</sec>
<sec id="s6">
<title>6 Analysis of PUF Properties</title>
<p>PUF response to a particular challenge is a probabilistic function. In this section, we will determine intra-PUF hamming distance and inter-PUF hamming distance and discuss various PUF properties ((<xref ref-type="bibr" rid="B34">Maes 2013</xref>; <xref ref-type="bibr" rid="B46">Plusquellic 2018</xref>)) in light of those distances.</p>
<sec id="s6-1">
<title>6.1 Constructability</title>
<p>A PUF class <inline-formula id="inf28">
<mml:math id="m29">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> is constructible if we can create a new PUF instance <inline-formula id="inf29">
<mml:math id="m30">
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>f</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> through a process, <inline-formula id="inf30">
<mml:math id="m31">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula>.Create: <inline-formula id="inf31">
<mml:math id="m32">
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>f</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2190;</mml:mo>
<mml:mi mathvariant="double-struck">P</mml:mi>
<mml:mtext>.Create</mml:mtext>
</mml:math>
</inline-formula>, where <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> has entropy that makes it distinct from other PUF instances <italic>puf</italic>
<sub>
<italic>n</italic>,<italic>n</italic>&#x2260;<italic>m</italic>
</sub>. In the case of RF-PUF, the source of entropy is the manufacturing process variation. During fabrication of ICs, we have within die and die-to-die variation which is due to the limitation of the manufacturing process. In contrast to many other PUF classes where we need a separate mechanism for PUF instance creation, the manufacturing process of the integrated circuit itself serves as the creation process for RF-PUF which is one of its advantages.</p>
</sec>
<sec id="s6-2">
<title>6.2 Evaluability</title>
<p>A PUF class <inline-formula id="inf32">
<mml:math id="m33">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> is evaluable if for a random PUF instance <inline-formula id="inf33">
<mml:math id="m34">
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>f</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> and a random challenge (<italic>x</italic>), we can evaluate a response <italic>y</italic>: <italic>y</italic> &#x2190; <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>(<italic>x</italic>). In our case, the challenge is a randomly generated bitstream in MATLAB that is fed into the transmitter and the corresponding response is the analog signal that contains the unique physical signature of the transmitter.</p>
</sec>
<sec id="s6-3">
<title>6.3 Inter PUF Distance - Uniqueness</title>
<p>Uniqueness refers to how different each instance of a PUF class <inline-formula id="inf34">
<mml:math id="m35">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> is from each other. A measurement metric that is used to represent PUF uniqueness is called inter-PUF hamming distance and is defined as:<disp-formula id="equ2">
<mml:math id="m36">
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2245;</mml:mo>
<mml:mi>d</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>e</mml:mi>
<mml:mfenced open="[" close="]">
<mml:mrow>
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
</p>
<p>Here, <inline-formula id="inf35">
<mml:math id="m37">
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf36">
<mml:math id="m38">
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> are the responses from <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> and <italic>puf</italic>
<sub>
<italic>n</italic>
</sub> (two instances of PUF class <inline-formula id="inf37">
<mml:math id="m39">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula>) under the same environmental condition <italic>&#x3b1;</italic> and same challenge x. Ideally, these inter-chip hamming distances should be much greater than any intra-chip hamming distances to distinguish them separately. In our experiment, our PUF class <inline-formula id="inf38">
<mml:math id="m40">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> &#x3d; RF-PUF and <italic>puf</italic>
<sub>
<italic>i</italic>
</sub>, (where <italic>i</italic> &#x3d; 1, 2, &#x2026;, 30) are the instances of that class (30 Xbee devices).</p>
<p>To calculate <italic>HD</italic>
<sub>
<italic>inter</italic>
</sub>, the first 1000 frames from each of the transmitters are taken. Each frame contains 3600 samples. Our features remain unchanged: CFO, eight I-Q component values, and COV. But after taking 10 features from each of 1000 frames, instead of using them as a feature matrix for each transmitter, the mean values of the features are taken across all the frames. This means that instead of representing each transmitter as a 10 &#xd7; 1000 feature matrix, it is represented as a 10 &#xd7; 1 feature vector. The reason for taking the average value across the frames is that the frames have an associated timestamp with them i.e., each frame data are collected from time to time. So, each frame faces slightly different environmental conditions such as heating of the transmitter due to data transmission for a long time, external interference, noise, etc. Averaging the feature values across a large number of frames mitigates the environmental factors, especially noise. Also, taking the first 1000 frames from each transmitter ensures the same initial heating pattern across devices. So the final outcome is that the feature vector for each transmitter has a very similar environmental factor <italic>&#x3b1;</italic>, which is one of the conditions of inter-chip hamming distance calculation.</p>
<p>After taking the feature vector from each transmitter, the Euclidean distance was calculated in ten-dimensional feature space as hamming distance. For <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>, let us denote <italic>CFO</italic>
<sub>
<italic>m</italic>
</sub> &#x3d; carrier frequency offset, <italic>COV</italic>
<sub>
<italic>m</italic>
</sub> &#x3d; coefficient of frequency offset variation, <italic>I</italic>
<sub>
<italic>k</italic>,<italic>m</italic>
</sub> &#x3d; in-phase component in the <italic>k</italic>
<italic>
<sup>th</sup>
</italic> quadrant, and <italic>Q</italic>
<sub>
<italic>k</italic>,<italic>m</italic>
</sub> &#x3d; quadrature-phase component in the <italic>k</italic>
<italic>
<sup>th</sup>
</italic> quadrant. Then distance <italic>d</italic>
<sub>
<italic>m</italic>,<italic>n</italic>
</sub> between <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> and <italic>puf</italic>
<sub>
<italic>n</italic>
</sub> instances is given by:<disp-formula id="e1">
<mml:math id="m41">
<mml:mtable class="aligned">
<mml:mtr>
<mml:mtd columnalign="right">
<mml:msubsup>
<mml:mrow>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>F</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>O</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>F</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>O</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2b;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>O</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>O</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2b;</mml:mo>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="right"/>
<mml:mtd columnalign="left">
<mml:munderover accentunder="false" accent="false">
<mml:mrow>
<mml:mo>&#x2211;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>4</mml:mn>
</mml:mrow>
</mml:munderover>
<mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>I</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>I</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2b;</mml:mo>
<mml:munderover accentunder="false" accent="false">
<mml:mrow>
<mml:mo>&#x2211;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>4</mml:mn>
</mml:mrow>
</mml:munderover>
<mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>Q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>Q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msup>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
<label>(1)</label>
</disp-formula>
</p>
<p>The inter-chip distances were calculated for each transmitter with respect to all 30 transmitters (including the chip under test), which leads to a 30 &#xd7; 30 symmetric matrix (upper and lower triangular matrices with same values since <italic>d</italic>
<sub>
<italic>m</italic>,<italic>n</italic>
</sub> &#x3d; <italic>d</italic>
<sub>
<italic>n</italic>,<italic>m</italic>
</sub> &#x3d; inter-chip distance between <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> and <italic>puf</italic>
<sub>
<italic>n</italic>
</sub>) with a principal diagonal of zeros (self-distance). It is found that the worst-case scenario with minimum distance, <italic>HD</italic>
<sub>
<italic>inter</italic>,<italic>min</italic>
</sub> &#x3d; 0.2307, and the best-case scenario with maximum distance, <italic>HD</italic>
<sub>
<italic>inter</italic>,<italic>max</italic>
</sub> &#x3d; 10.149.</p>
<p>In literature, often a mean inter-puf distance, <italic>&#x3bc;</italic>
<sub>
<italic>inter</italic>
</sub>, is reported which is the average of all <italic>HD</italic>
<sub>
<italic>inter</italic>
</sub>. The formula is:<disp-formula id="equ3">
<mml:math id="m42">
<mml:mtable class="aligned">
<mml:mtr>
<mml:mtd columnalign="right">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3bc;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mover accent="true">
<mml:mrow>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo>&#x304;</mml:mo>
</mml:mover>
</mml:mrow>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="right"/>
<mml:mtd columnalign="left">
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>N</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>f</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xd7;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>N</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>f</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#xd7;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>N</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2211;</mml:mo>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>Where <italic>N</italic>
<sub>
<italic>puf</italic>
</sub> is the number of puf instances (<italic>N</italic>
<sub>
<italic>puf</italic>
</sub> &#x3d; 30 for us), and <italic>N</italic>
<sub>
<italic>chal</italic>
</sub> is the number of challenges (<italic>N</italic>
<sub>
<italic>chal</italic>
</sub> &#x3d; 1, since we are not varying our challenge). Using this formula, we find that <italic>&#x3bc;</italic>
<sub>
<italic>inter</italic>
</sub> &#x3d; 3.703.</p>
<p>
<xref ref-type="fig" rid="F8">Figure 8C</xref> shows the probability mass function distribution of <inline-formula id="inf39">
<mml:math id="m43">
<mml:mn>435</mml:mn>
<mml:mspace width="0.3333em"/>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>30</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>29</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> inter-PUF distances. The density function is right-skewed, that&#x2019;s why Weibull fitting (which is exponential in nature) fits it more accurately than normal distribution fitting. This fitting shows that on the right side the curve is more sparse but on the left side it is more centered instead of being sparse, which is good because that will ensure that the inter-PUF values don&#x2019;t go to overlap intra-PUF distances which should ideally be at zero.</p>
<fig id="F8" position="float">
<label>FIGURE 8</label>
<caption>
<p>Data distribution of <bold>(A)</bold> intra-PUF hamming distances and <bold>(C)</bold> inter-PUF hamming distances. Due to skewness, Weibull distribution fitting is a more accurate representation in these cases. <bold>(B)</bold> The two Weibull curves are superimposed on top of each other. It is seen that there is a very slight overlap (yellow region) between the curves which is shown in a zoomed inset. Although trivial, this overlapping is the source of the detection error.</p>
</caption>
<graphic xlink:href="felec-03-856284-g008.tif"/>
</fig>
</sec>
<sec id="s6-4">
<title>6.4 Intra PUF Distance&#x2013;Reliability</title>
<p>PUF responses are in general dependent on various environmental factors that render any PUF instance response as a probabilistic function. This means that a particular PUF instance can provide slightly different values of features based on varying environmental conditions. For authentication purposes, this poses an issue. Reliability refers to how resilient a PUF instance is against environmental factors e.g. noise, interference, temperature, supply voltage, etc.</p>
<p>A measurement metric that is used to represent how reliable a particular instance of a PUF class <inline-formula id="inf40">
<mml:math id="m44">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> is intra-puf hamming distance and is defined as:<disp-formula id="equ4">
<mml:math id="m45">
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2245;</mml:mo>
<mml:mi>d</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>e</mml:mi>
<mml:mfenced open="[" close="]">
<mml:mrow>
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>Here, <inline-formula id="inf41">
<mml:math id="m46">
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf42">
<mml:math id="m47">
<mml:msubsup>
<mml:mrow>
<mml:mi>Y</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> are the responses from <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> under two distinct environmental conditions <italic>&#x3b1;</italic> and <italic>&#x3b2;</italic> and same challenge x. Many <italic>HD</italic>
<sub>
<italic>intra</italic>
</sub> distances are calculated at different environmental conditions. Ideally, these intra-chip hamming distances should be zero.</p>
<p>To calculate <italic>HD</italic>
<sub>
<italic>intra</italic>
</sub>, we follow two steps. Let us consider one particular PUF instance <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>. In step 1, the first 1000 frames (frame number 1 to frame number 1000) were taken from <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>, each frame containing 3600 samples. Then mean values of the previously mentioned ten features were taken just as before to represent it as a 10 &#xd7; 1 feature vector. Let us represent this vector as <italic>f</italic>
<sub>
<italic>v</italic>,1</sub>. Then in step 2, the first 5 frames are skipped and the next 1000 frames are taken from frame number &#x3d; 6 to frame number &#x3d; 1005. Step 1 is repeated here to get the next feature vector <italic>f</italic>
<sub>
<italic>v</italic>,2</sub>. Then next 1000 frames are taken from frame number &#x3d; 11 to frame number &#x3d; 1010 and a feature vector <italic>f</italic>
<sub>
<italic>v</italic>,3</sub> is formed. This process is repeated 80 times to form 80 different feature vectors <italic>f</italic>
<sub>
<italic>v</italic>,<italic>&#x3b1;</italic>
</sub>; <italic>&#x3b1;</italic> &#x3d; 1, 2, &#x2026; , 80. These 10 &#xd7; 1 feature vectors are stacked together to form a feature vector set <italic>f</italic>
<sub>
<italic>set</italic>,<italic>m</italic>
</sub> of size 10 &#xd7; 80 for <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>. The whole process is then repeated for all 30 devices.</p>
<p>The purpose of taking frame-shifted or time-shifted frame groups is to consider the time factor. Each frame has a duration of 0.6&#xa0;<italic>ms</italic>, so 5 frames gap in between two frame groups renders a time difference of at least 3&#xa0;<italic>ms</italic> (in reality the difference is much larger since the transmitter transmits data for a small time and most of the frames are just noise which are filtered in data pre-processing step). The 80 time-spaced frames, in reality, cover almost half a minute. Our 2.4&#xa0;<italic>GHz</italic> clock will have LO drift cycle time in the nanoseconds range. Hence, half-minute data can incorporate significant environmental factors into frame data. So, it can be assumed that the feature vectors <italic>f</italic>
<sub>
<italic>v</italic>,<italic>&#x3b1;</italic>
</sub>; <italic>&#x3b1;</italic> &#x3d; 1, 2, &#x2026; , 80 in feature vector set <italic>f</italic>
<sub>
<italic>set</italic>,<italic>m</italic>
</sub> of <italic>puf</italic>
<sub>
<italic>m</italic>
</sub> represents <italic>&#x3b1;</italic> &#x3d; 80 different environmental conditions.</p>
<p>Now, for each instance <italic>puf</italic>
<sub>
<italic>m</italic>
</sub>, Euclidean distance is calculated in 10-dimensional feature space among the feature vectors in the feature vector set using <xref ref-type="disp-formula" rid="e1">Eq. 1</xref>. This results in a symmetric matrix of size 80 &#xd7; 80 with a principal diagonal of zeros. This process is repeated for other transmitters as well. Essentially it gives us 30 matrices of size 80 &#xd7; 80 for intra-PUF distances. In the best-case scenario, the minimum distance is <italic>HD</italic>
<sub>
<italic>intra</italic>,<italic>min</italic>
</sub> &#x3d; 7.23 &#xd7; 10<sup>&#x2013;5</sup> and in the worst case scenario, the maximum distance is <italic>HD</italic>
<sub>
<italic>intra</italic>,<italic>max</italic>
</sub> &#x3d; 0.73.</p>
<p>
<xref ref-type="fig" rid="F8">Figure 8A</xref> shows the probability mass function distribution of <inline-formula id="inf43">
<mml:math id="m48">
<mml:mn>94800</mml:mn>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>30</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>80</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>79</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> intra-PUF distances. The density function is right-skewed and Weibull distribution gives better fitting for it just like inter-PUF cases. This fitting shows that on the left side the curve is strongly centered towards zero, but has a diminishing trail on the right. this trail goes on to overlap inter-puf distances slightly and causes a few detection errors. Detection probability is discussed in the next subsection.</p>
<p>Finally, a mean intra-PUF distance, <italic>&#x3bc;</italic>
<sub>
<italic>intra</italic>
</sub>, is calculated which is the average of all <italic>HD</italic>
<sub>
<italic>intra</italic>
</sub>. The formula is:<disp-formula id="equ5">
<mml:math id="m49">
<mml:mtable class="aligned">
<mml:mtr>
<mml:mtd columnalign="right">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3bc;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mover accent="true">
<mml:mrow>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo>&#x304;</mml:mo>
</mml:mover>
</mml:mrow>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="right"/>
<mml:mtd columnalign="left">
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>N</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>f</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xd7;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>N</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xd7;</mml:mo>
<mml:mi>&#x3b1;</mml:mi>
<mml:mo>&#xd7;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2211;</mml:mo>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>Where <italic>N</italic>
<sub>
<italic>puf</italic>
</sub> is the number of puf instances (<italic>N</italic>
<sub>
<italic>puf</italic>
</sub> &#x3d; 30 for us), <italic>N</italic>
<sub>
<italic>chal</italic>
</sub> is the number of challenges (<italic>N</italic>
<sub>
<italic>chal</italic>
</sub> &#x3d; 1, since we are not varying our challenge) and <italic>&#x3b1;</italic> is the number of environmental conditions (<italic>&#x3b1;</italic> &#x3d; 80 in our study). Using this formula, it is found that <italic>&#x3bc;</italic>
<sub>
<italic>intra</italic>
</sub> &#x3d; 0.136.</p>
</sec>
<sec id="s6-5">
<title>6.5 Identifiability</title>
<p>In the previous two subsections, both inter-PUF and intra-PUF hamming distances and their mean values: <italic>&#x3bc;</italic>
<sub>
<italic>inter</italic>
</sub> &#x3d; 3.703 and <italic>&#x3bc;</italic>
<sub>
<italic>intra</italic>
</sub> &#x3d; 0.136 are calculated. Their comparison shows that <italic>&#x3bc;</italic>
<sub>
<italic>inter</italic>
</sub> &#x3e; <italic>&#x3bc;</italic>
<sub>
<italic>intra</italic>
</sub>, which establishes that on average the PUF instances can be distinguished from each other. But the mean value does not depict the full story. <xref ref-type="fig" rid="F8">Figure 8B</xref> shows the fitted distribution curves superimposed on each other. The brown curve (intra-PUF distribution) is skewed to the left and the blue curve (inter-PUF distribution) is skewed to the right and they mostly cover different regions. However, there is slight overlapping between them which is shown in the inset as a zoomed version of the overlapping area. Ideally, there should be no overlapping. But in a practical scenario, this overlapping region is the source of detection error.</p>
<p>From the definition of identifiability, a PUF class <inline-formula id="inf44">
<mml:math id="m50">
<mml:mi mathvariant="double-struck">P</mml:mi>
</mml:math>
</inline-formula> is identifiable if it is reliable as well as unique, and if the probability of inter-PUF variation being greater than intra-PUF variation is very high. Mathematically:<disp-formula id="equ6">
<mml:math id="m51">
<mml:mi>P</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>y</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3e;</mml:mo>
<mml:mi>H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2248;</mml:mo>
<mml:mn>1</mml:mn>
</mml:math>
</disp-formula>
</p>
<p>In the previous two subsections, <inline-formula id="inf45">
<mml:math id="m52">
<mml:mn>94800</mml:mn>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>30</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>80</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>79</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> intra-PUF distances and <inline-formula id="inf46">
<mml:math id="m53">
<mml:mn>435</mml:mn>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mfenced open="(" close="">
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>30</mml:mn>
<mml:mo>&#xd7;</mml:mo>
<mml:mn>29</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:mfenced>
</mml:math>
</inline-formula> inter-PUF distances have been calculated. Now, each of these inter-puf distances is compared with each of the intra-PUF distances that leads us to 435 &#xd7; 94800 &#x3d; 41238000 cases, among which, <italic>HD</italic>
<sub>
<italic>inter</italic>
</sub> &#x3e; <italic>HD</italic>
<sub>
<italic>intra</italic>
</sub> is found in 41184206 cases.<disp-formula id="equ7">
<mml:math id="m54">
<mml:mi mathvariant="bold-italic">P</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
<mml:mi mathvariant="bold-italic">o</mml:mi>
<mml:mi mathvariant="bold-italic">b</mml:mi>
<mml:mi mathvariant="bold-italic">a</mml:mi>
<mml:mi mathvariant="bold-italic">b</mml:mi>
<mml:mi mathvariant="bold-italic">i</mml:mi>
<mml:mi mathvariant="bold-italic">l</mml:mi>
<mml:mi mathvariant="bold-italic">i</mml:mi>
<mml:mi mathvariant="bold-italic">t</mml:mi>
<mml:mi mathvariant="bold-italic">y</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="bold-italic">H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="bold-italic">i</mml:mi>
<mml:mi mathvariant="bold-italic">n</mml:mi>
<mml:mi mathvariant="bold-italic">t</mml:mi>
<mml:mi mathvariant="bold-italic">e</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3e;</mml:mo>
<mml:mi mathvariant="bold-italic">H</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">D</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="bold-italic">i</mml:mi>
<mml:mi mathvariant="bold-italic">n</mml:mi>
<mml:mi mathvariant="bold-italic">t</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
<mml:mi mathvariant="bold-italic">a</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x3d;</mml:mo>
<mml:mn mathvariant="bold">0.9987</mml:mn>
</mml:math>
</disp-formula>
</p>
<p>This is a very high probability and close to 1. This proves that RF-PUF has strong identifiability and this property along with reliability, uniqueness, constructability, and evaluability manifests RF-PUF as a distinct PUF class. This is the first-ever experimental validation of RF-PUF as a distinct and strong PUF class by itself.</p>
</sec>
</sec>
<sec id="s7">
<title>7 Possible Attack Models on RF-PUF</title>
<p>RF-PUF does not store any digital key and hence, is not susceptible to malicious PUF models which assume that the adversary can have access to all the challenge-response pairs through a built-in logger software/implanted Trojan. However, there is a possibility of a machine learning-based attack that needs to be discussed (<xref ref-type="fig" rid="F10">Figure 10</xref>). For RF-PUF, ML attack is a two-step process:<list list-type="simple">
<list-item>
<p>&#x2022; Step 1: model/profile the victim TX (Unsupervised)</p>
</list-item>
<list-item>
<p>&#x2022; Step 2: use that model for spoofing/replay attacks</p>
</list-item>
</list>
</p>
<p>In step 1, the rogue device tries to learn the feature/parameter values of the victim TX. Unlike the intended RX, this is an unsupervised problem for the attacker. We have utilized k-means clustering to divide the feature map into 30 clusters and compare the predicted and true labels (<xref ref-type="fig" rid="F9">Figure 9</xref>). The process was repeated 1,000 times as k-means isn&#x2019;t unique without specific conditions. Our analysis shows that clustering achieves <inline-formula id="inf47">
<mml:math id="m55">
<mml:mo>&#x223c;</mml:mo>
<mml:mn>3.63</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy on average, which is very close to the probability of random detection <inline-formula id="inf48">
<mml:math id="m56">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mfrac>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>30</mml:mn>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>3.3</mml:mn>
<mml:mi>%</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>. So, practically it is almost impossible to get the right feature value and label.</p>
<fig id="F9" position="float">
<label>FIGURE 9</label>
<caption>
<p>Heatmap of unsupervised learning in the attacker using k-means clustering. <bold>(A)</bold> The worst-case accuracy of 0.09<italic>%</italic> and <bold>(B)</bold> the best-case accuracy of 6.8<italic>%</italic>. Repeated clustering 1000 times shows 3.63<italic>%</italic> accuracy on average.</p>
</caption>
<graphic xlink:href="felec-03-856284-g009.tif"/>
</fig>
<p>If somehow the attacker succeeds in step 1, then in step 2, the attacker needs to produce an RF signal that contains the same imperfections as the victim TX with high accuracy. This requires a high speed and high-resolution circuitry. <xref ref-type="fig" rid="F10">Figure 10</xref> shows that the physical signature of the transmitter, S, goes through transformation T<sub>TX</sub> at TX and T<sub>RX</sub> at RX. The transformations in the attacker are T<sub>A</sub>, T<sub>ML1</sub>, T<sub>ML2</sub>, and T<sub>D</sub> respectively. Full transformation for the original device is T<sub>RX</sub> (T<sub>TX</sub>(S)) and for the adversary is T<sub>RX</sub> (T<sub>D</sub> (T<sub>ML2</sub> (T<sub>ML1</sub> (T<sub>A</sub> (T<sub>TX</sub>(S)))))). The adversary ML2 framework needs to make these two transformations equal by undoing the effect of its ADC/DAC which requires almost infinite resolution, rendering it practically impossible (typical ADC/DAC are 8/16-bit). This Resolution limitation in ADC/DAC and bandwidth limitation in filters and other RF components also prevent replay attack, which requires the attacker to convert the TX signal in the digital domain, incorporate malicious contents and then transform it back into the RF domain with very high precision. Further analysis of precision requirements for a practical attack will be included in future work. The robustness of RF-PUF against malicious PUF model, ML attack, and replay attack proves its strong candidacy of employment for RF security.</p>
<fig id="F10" position="float">
<label>FIGURE 10</label>
<caption>
<p>ML attack model. Adversary ML networks cannot undo the effect of ADC and DAC which requires extremely high precision and resolution, making the attack impractical.</p>
</caption>
<graphic xlink:href="felec-03-856284-g010.tif"/>
</fig>
</sec>
<sec id="s8">
<title>8 Conclusion</title>
<p>In this work, data collected from off-the-shelf commodity components (30 Xbee modules) were used to develop a new feature called the coefficient of frequency offset variation (COV) through PCA and moment analysis. The new feature leads to 95<italic>%</italic> accuracy for a single hidden layer with 10 neurons and <inline-formula id="inf49">
<mml:math id="m57">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>99.8</mml:mn>
<mml:mi>%</mml:mi>
</mml:math>
</inline-formula> accuracy for a single hidden layer with <inline-formula id="inf50">
<mml:math id="m58">
<mml:mo>&#x3e;</mml:mo>
<mml:mn>50</mml:mn>
</mml:math>
</inline-formula> neurons, for the first time in literature without any assisting digital preamble. The dataset containing 155.4&#xa0;GB of data has also been released for public use. The design space has been explored and the effect of the wireless channel is analyzed to provide design insights. The scalability issue of simple ML algorithms for high accuracy has also been explored. The PUF properties of RF-PUF have been explored in detail. The inter-PUF and intra-PUF hamming distances are calculated and with their distribution, it has been shown that they have trivial overlapping. A detailed analysis reveals that the probability of <italic>HD</italic>
<sub>
<italic>inter</italic>
</sub> &#x3e; <italic>HD</italic>
<sub>
<italic>intra</italic>
</sub> &#x3d; 0.9987, which resonates with the claim that RF-PUF has a very high device authentication probability. Finally, possible important attack models are discussed and the robustness of RF-PUF against them is analyzed. This work experimentally validates RF-PUF with high accuracy, which can contribute to a secure authentication system using inherent physical signatures without extra power, area, or computational overhead on the resource-constrained IoT transmitter side.</p>
</sec>
</body>
<back>
<sec id="s9">
<title>Data Availability Statement</title>
<p>The datasets presented in this study can be found in online repositories. The names of the repository/repositories and accession number(s) can be found below: <ext-link ext-link-type="uri" xlink:href="https://github.com/SparcLab/Sparclab-RF-PUF-Dataset">https://github.com/SparcLab/Sparclab-RF-PUF-Dataset</ext-link>.</p>
</sec>
<sec id="s10">
<title>Author Contributions</title>
<p>PA prepared an initial framework of 4 Xbee devices for data collection. MB has set up the test environment, prepared and conducted the experiment with 30 Xbee modules in a renewed framework, processed data, performed the statistical analysis, feature engineering, and evaluated performance. BC helped both PA and MB in setting up the experimental framework and data processing as well as guiding with technical feedback. SS supervised the whole work. MB wrote the manuscript while both BC and SS helped in writing the paper, reviewing and updating it as needed.</p>
</sec>
<sec id="s11">
<title>Funding</title>
<p>This work was supported in part by the National Science Foundation, under Grant 1935573.</p>
</sec>
<sec sec-type="COI-statement" id="s12">
<title>Conflict of Interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="disclaimer" id="s13">
<title>Publisher&#x2019;s Note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Albawi</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Mohammed</surname>
<given-names>T. A.</given-names>
</name>
<name>
<surname>Al-Zawi</surname>
<given-names>S.</given-names>
</name>
</person-group> &#x201c;<article-title>Understanding of a Convolutional Neural Network</article-title>,&#x201d; in <conf-name>2017 international conference on engineering and technology (ICET)</conf-name> (<publisher-name>IEEE</publisher-name>), <fpage>1</fpage>&#x2013;<lpage>6</lpage>. <pub-id pub-id-type="doi">10.1109/icengtechnol.2017.8308186</pub-id> </citation>
</ref>
<ref id="B2">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Alotaibi</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Elleithy</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2016</year>). <article-title>A New Mac Address Spoofing Detection Technique Based on Random Forests</article-title>. <source>Sensors</source> <volume>16</volume> (<issue>3</issue>), <fpage>281</fpage>. <pub-id pub-id-type="doi">10.3390/s16030281</pub-id> </citation>
</ref>
<ref id="B3">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bari</surname>
<given-names>M. F.</given-names>
</name>
<name>
<surname>Anowarul Fattah</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Epileptic Seizure Detection in EEG Signals Using Normalized IMFs in CEEMDAN Domain and Quadratic Discriminant Classifier</article-title>. <source>Biomed. Signal Process. Control.</source> <volume>58</volume>, <fpage>101833</fpage>. <pub-id pub-id-type="doi">10.1016/j.bspc.2019.101833</pub-id> </citation>
</ref>
<ref id="B4">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Bari</surname>
<given-names>M. F.</given-names>
</name>
<name>
<surname>Chatterjee</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Sen</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2021a</year>). &#x201c;<article-title>DIRAC: Dynamic-IRregulAr Clustering Algorithm with Incremental Learning for RF-Based Trust Augmentation in IoT Device Authentication</article-title>,&#x201d; in <conf-name>2021 IEEE International Symposium on Circuits and Systems (ISCAS)</conf-name> (<publisher-loc>IEEE)</publisher-loc>, <fpage>1</fpage>&#x2013;<lpage>5</lpage>. </citation>
</ref>
<ref id="B5">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Bari</surname>
<given-names>M. F.</given-names>
</name>
<name>
<surname>Chatterjee</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Sivanesan</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Yang</surname>
<given-names>L. L.</given-names>
</name>
<name>
<surname>Sen</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2021b</year>). &#x201c;<article-title>High Accuracy RF-PUF for EM Security through Physical Feature Assistance Using Public Wi-Fi Dataset</article-title>,&#x201d; in <conf-name>2021 IEEE MTT-S International Microwave Symposium (IMS)</conf-name>, <fpage>108</fpage>&#x2013;<lpage>111</lpage>. <pub-id pub-id-type="doi">10.1109/ims19712.2021.9574917</pub-id> </citation>
</ref>
<ref id="B6">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Bari</surname>
<given-names>M. F.</given-names>
</name>
<name>
<surname>Sen</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Sparclab RF-PUF Dataset,&#x201d; GitHub</article-title>. <comment>[Online]. Available at: <ext-link ext-link-type="uri" xlink:href="https://github.com/SparcLab/Sparclab-RF-PUF-Dataset">https://github.com/SparcLab/Sparclab-RF-PUF-Dataset</ext-link> (Accessed March 6, 2022)</comment>. </citation>
</ref>
<ref id="B7">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Barth</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Jackson</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Mitchell</surname>
<given-names>J. C.</given-names>
</name>
</person-group> (<year>2008</year>). &#x201c;<article-title>Robust Defenses for Cross-Site Request Forgery</article-title>,&#x201d; in <conf-name>Proceedings of the 15th ACM conference on Computer and communications security</conf-name>, <fpage>75</fpage>&#x2013;<lpage>88</lpage>. <pub-id pub-id-type="doi">10.1145/1455770.1455782</pub-id> </citation>
</ref>
<ref id="B8">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bertoncini</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Rudd</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Nousain</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Hinders</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2012</year>). <article-title>Wavelet Fingerprinting of Radio-Frequency Identification (Rfid) Tags</article-title>. <source>IEEE Trans. Ind. Electron.</source> <volume>59</volume> (<issue>12</issue>), <fpage>4843</fpage>&#x2013;<lpage>4850</lpage>. <pub-id pub-id-type="doi">10.1109/tie.2011.2179276</pub-id> </citation>
</ref>
<ref id="B9">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Bihl</surname>
<given-names>T. J.</given-names>
</name>
<name>
<surname>Bauer</surname>
<given-names>K. W.</given-names>
</name>
<name>
<surname>Temple</surname>
<given-names>M. A.</given-names>
</name>
</person-group> (<year>2016</year>). <article-title>Feature Selection for RF Fingerprinting with Multiple Discriminant Analysis and Using ZigBee Device Emissions</article-title>. <source>IEEE Trans. Inf. Forensics Secur.</source> <volume>11</volume> (<issue>8</issue>), <fpage>1862</fpage>&#x2013;<lpage>1874</lpage>. <pub-id pub-id-type="doi">10.1109/TIFS.2016.2561902</pub-id> </citation>
</ref>
<ref id="B10">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Brik</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Banerjee</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Gruteser</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Oh</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2008</year>). &#x201c;<article-title>Wireless Device Identification with Radiometric Signatures</article-title>,&#x201d; in <conf-name>Proceedings of the 14th ACM International Conference on Mobile Computing and Networking (MobiCom &#x2019;08)</conf-name> (<publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name>), <fpage>116</fpage>&#x2013;<lpage>127</lpage>. <pub-id pub-id-type="doi">10.1145/1409944.1409959</pub-id> </citation>
</ref>
<ref id="B11">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Chacko</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2017</year>). &#x201c;<article-title>Physical Gate Based Preamble Obfuscation for Securing Wireless Communication</article-title>,&#x201d; in <conf-name>International Conference on Computing, Networking and Communications (ICNC)</conf-name>, <fpage>293</fpage>&#x2013;<lpage>297</lpage>. </citation>
</ref>
<ref id="B12">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Chatterjee</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Das</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Maity</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Sen</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>RF-PUF: Enhancing IoT Security through Authentication of Wireless Nodes Using <italic>In-Situ</italic> Machine Learning</article-title>. <source>IEEE Internet Things J.</source> <volume>6</volume> (<issue>1</issue>), <fpage>388</fpage>&#x2013;<lpage>398</lpage>. <pub-id pub-id-type="doi">10.1109/JIOT.2018.2849324</pub-id> </citation>
</ref>
<ref id="B13">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Chomsiri</surname>
<given-names>T.</given-names>
</name>
</person-group> (<year>2007</year>). &#x201c;<article-title>HTTPS Hacking protection</article-title>,&#x201d; in <conf-name>21st International Conference on Advanced Information Networking and Applications Workshops (AINAW&#x2019;07)</conf-name>, <fpage>590</fpage>&#x2013;<lpage>594</lpage>.<volume>1</volume> </citation>
</ref>
<ref id="B14">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Creswell</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>White</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Dumoulin</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Arulkumaran</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Sengupta</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Bharath</surname>
<given-names>A. A.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Generative Adversarial Networks: An Overview</article-title>. <source>IEEE Signal. Process. Mag.</source> <volume>35</volume> (<issue>1</issue>), <fpage>53</fpage>&#x2013;<lpage>65</lpage>. <pub-id pub-id-type="doi">10.1109/msp.2017.2765202</pub-id> </citation>
</ref>
<ref id="B15">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Danev</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Capkun</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2009</year>). &#x201c;<article-title>Transient-based Identification of Wireless Sensor Nodes</article-title>,&#x201d; in <conf-name>2009 International Conference on Information Processing in Sensor Networks</conf-name>, <fpage>25</fpage>&#x2013;<lpage>36</lpage>. </citation>
</ref>
<ref id="B16">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Danev</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Heydt-Benjamin</surname>
<given-names>T. S.</given-names>
</name>
<name>
<surname>Capkun</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2009</year>). &#x201c;<article-title>Physical-layer Identification of Rfid Devices</article-title>,&#x201d; in <source>USENIX Security Symposium</source>, <fpage>199</fpage>&#x2013;<lpage>214</lpage>. </citation>
</ref>
<ref id="B17">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ding</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>W.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Specific Emitter Identification via Convolutional Neural Networks</article-title>. <source>IEEE Commun. Lett.</source> <volume>22</volume> (<issue>12</issue>), <fpage>2591</fpage>&#x2013;<lpage>2594</lpage>. <pub-id pub-id-type="doi">10.1109/lcomm.2018.2871465</pub-id> </citation>
</ref>
<ref id="B18">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Fredenslund</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Computational Complexity of Neural Networks</article-title>. <comment>[Online]. Available at: <ext-link ext-link-type="uri" xlink:href="https://kasperfred.com/series/introduction-to-neural-networks/computational-complexity-of-neural-networks">https://kasperfred.com/series/introduction-to-neural-networks/computational-complexity-of-neural-networks</ext-link> (Accessed March 6, 2022)</comment>. </citation>
</ref>
<ref id="B19">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Guo</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Chang</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2019</year>). &#x201c;<article-title>Survey of mobile Device Authentication Methods Based on Rf Fingerprint</article-title>,&#x201d; in <conf-name>IEEE INFOCOM 2019 - IEEE Conference on Computer Communications Workshops</conf-name> (<publisher-name>Infocom Wkshps</publisher-name>), <fpage>1</fpage>&#x2013;<lpage>6</lpage>. <pub-id pub-id-type="doi">10.1109/infocomwkshps47286.2019.9093755</pub-id> </citation>
</ref>
<ref id="B20">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hall</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Barbeau</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Kranakis</surname>
<given-names>E.</given-names>
</name>
</person-group> (<year>2003</year>). <article-title>Detection of Transient in Radio Frequency Fingerprinting Using Signal Phase</article-title>. <source>Wireless Opt. Commun.</source>, <fpage>13</fpage>&#x2013;<lpage>18</lpage>. </citation>
</ref>
<ref id="B21">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Hanna</surname>
<given-names>S. S.</given-names>
</name>
<name>
<surname>Cabric</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2019</year>). &#x201c;<article-title>Deep Learning Based Transmitter Identification Using Power Amplifier Nonlinearity</article-title>,&#x201d; in <conf-name>2019 International Conference on Computing, Networking and Communications</conf-name> (<publisher-loc>HonoluluHI, USA</publisher-loc>: <publisher-name>ICNC</publisher-name>), <fpage>674</fpage>&#x2013;<lpage>680</lpage>. <pub-id pub-id-type="doi">10.1109/ICCNC.2019.8685569</pub-id> </citation>
</ref>
<ref id="B22">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hospodar</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Gierlichs</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Mulder</surname>
<given-names>E. D.</given-names>
</name>
<name>
<surname>Verbauwhede</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Vandewalle</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2011</year>). <article-title>Machine Learning in Side-Channel Analysis: a First Study</article-title>. <source>J. Cryptographic Eng.</source> <volume>1</volume> (<issue>4</issue>), <fpage>293</fpage>. <pub-id pub-id-type="doi">10.1007/s13389-011-0023-x</pub-id> </citation>
</ref>
<ref id="B23">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Huang</surname>
<given-names>N. E.</given-names>
</name>
</person-group> (<year>2014</year>). <source>Hilbert-huang Transform and its Applications</source>, <volume>16</volume>. <publisher-loc>New Jersey</publisher-loc>: <publisher-name>World Scientific</publisher-name>. </citation>
</ref>
<ref id="B24">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Huang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2012</year>). &#x201c;<article-title>Radio Frequency Fingerprinting Based on the Constellation Errors</article-title>,&#x201d; in <conf-name>2012 18th Asia-Pacific Conference on Communications</conf-name> (<publisher-name>APCC</publisher-name>), <fpage>900</fpage>&#x2013;<lpage>905</lpage>. <pub-id pub-id-type="doi">10.1109/apcc.2012.6388238</pub-id> </citation>
</ref>
<ref id="B25">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Jian</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Rendon</surname>
<given-names>B. C.</given-names>
</name>
<name>
<surname>Ojuba</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Soltani</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Sankhe</surname>
<given-names>K.</given-names>
</name>
<etal/>
</person-group> (<year>2020</year>). <article-title>Deep Learning for Rf Fingerprinting: A Massive Experimental Study</article-title>. <source>IEEE Internet Things M.</source> <volume>3</volume> (<issue>1</issue>), <fpage>50</fpage>&#x2013;<lpage>57</lpage>. <pub-id pub-id-type="doi">10.1109/iotm.0001.1900065</pub-id> </citation>
</ref>
<ref id="B26">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Jagannath</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Jagannath</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Kumar</surname>
<given-names>P. S. P. V.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>A Comprehensive Survey on Radio Frequency (RF) Fingerprinting: Traditional Approaches, Deep Learning, and Open Challenges</article-title>. <source>arXiv</source> <comment>[Preprint]</comment>. <pub-id pub-id-type="doi">10.48550/arXiv.2201.00680</pub-id> </citation>
</ref>
<ref id="B27">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Kennedy</surname>
<given-names>I. O.</given-names>
</name>
<name>
<surname>Scanlon</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Mullany</surname>
<given-names>F. J.</given-names>
</name>
<name>
<surname>Buddhikot</surname>
<given-names>M. M.</given-names>
</name>
<name>
<surname>Nolan</surname>
<given-names>K. E.</given-names>
</name>
<name>
<surname>Rondeau</surname>
<given-names>T. W.</given-names>
</name>
</person-group> (<year>2008</year>). &#x201c;<article-title>Radio Transmitter Fingerprinting: A Steady State Frequency Domain Approach</article-title>,&#x201d; in <conf-name>2008 IEEE 68th Vehicular Technology Conference</conf-name>, <fpage>1</fpage>&#x2013;<lpage>5</lpage>. </citation>
</ref>
<ref id="B28">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kim</surname>
<given-names>P.</given-names>
</name>
</person-group> (<year>2017</year>). &#x201c;<article-title>Convolutional Neural Network</article-title>,&#x201d; in <source>MATLAB Deep Learning: With Machine Learning, Neural Networks and Artificial Intelligence</source> (<publisher-loc>Berkeley, CA</publisher-loc>: <publisher-name>Apress</publisher-name>), <fpage>121</fpage>&#x2013;<lpage>147</lpage>. <pub-id pub-id-type="doi">10.1007/978-1-4842-2845-6_6</pub-id> </citation>
</ref>
<ref id="B29">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Klein</surname>
<given-names>R. W.</given-names>
</name>
<name>
<surname>Temple</surname>
<given-names>M. A.</given-names>
</name>
<name>
<surname>Mendenhall</surname>
<given-names>M. J.</given-names>
</name>
</person-group> (<year>2009</year>). <article-title>Application of Wavelet-Based Rf Fingerprinting to Enhance Wireless Network Security</article-title>. <source>J. Commun. Netw.</source> <volume>11</volume> (<issue>6</issue>), <fpage>544</fpage>&#x2013;<lpage>555</lpage>. <pub-id pub-id-type="doi">10.1109/jcn.2009.6388408</pub-id> </citation>
</ref>
<ref id="B30">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Kocher</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Jaffe</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Jun</surname>
<given-names>B.</given-names>
</name>
</person-group> (<year>1999</year>). &#x201c;<article-title>Differential Power Analysis</article-title>,&#x201d; in <source>Annual International Cryptology Conference</source> (<publisher-loc>Berlin, Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>388</fpage>&#x2013;<lpage>397</lpage>. <pub-id pub-id-type="doi">10.1007/3-540-48405-1_25</pub-id> </citation>
</ref>
<ref id="B31">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Kumar</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Kaur</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Amritsar</surname>
<given-names>G. N. D. U.</given-names>
</name>
</person-group> (<year>2015</year>). &#x201c;<article-title>Vulnerability Detection of International mobile Equipment Identity Number of Smartphone and Automated Reporting of Changed IMEI Number</article-title>,&#x201d; in <conf-name>International Journal of Computer Science and Mobile Computing</conf-name>, <fpage>527</fpage>&#x2013;<lpage>533</lpage>.<volume>4</volume>
<issue>5</issue> </citation>
</ref>
<ref id="B32">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Liu</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Qiu</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>X.</given-names>
</name>
</person-group> (<year>2016</year>). <article-title>Recurrent Neural Network for Text Classification with Multi-Task Learning</article-title>. <source>arXiv</source> <comment>[Preprint]</comment>. <pub-id pub-id-type="doi">10.48550/arXiv.1605.05101</pub-id> </citation>
</ref>
<ref id="B33">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lukacs</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Collins</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Temple</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2015</year>). <article-title>Classification Performance Using &#x27;RF&#x2010;DNA&#x27; Fingerprinting of Ultra&#x2010;wideband Noise Waveforms</article-title>. <source>Electron. Lett.</source> <volume>51</volume> (<issue>10</issue>), <fpage>787</fpage>&#x2013;<lpage>789</lpage>. <pub-id pub-id-type="doi">10.1049/el.2015.0051</pub-id> </citation>
</ref>
<ref id="B34">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Maes</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2013</year>). <source>Physically Unclonable Functions: Constructions, Properties and Applications</source>. <publisher-loc>New York</publisher-loc>: <publisher-name>Springer Science &#x26; Business Media</publisher-name>. <pub-id pub-id-type="doi">10.1007/978-3-642-41395-7</pub-id> </citation>
</ref>
<ref id="B35">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Mao</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Xie</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Lau</surname>
<given-names>R. Y.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Paul Smolley</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2017</year>). &#x201c;<article-title>Least Squares Generative Adversarial Networks</article-title>,&#x201d; in <conf-name>Proceedings of the IEEE international conference on computer vision</conf-name>, <fpage>2794</fpage>&#x2013;<lpage>2802</lpage>. <pub-id pub-id-type="doi">10.1109/iccv.2017.304</pub-id> </citation>
</ref>
<ref id="B36">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Medsker</surname>
<given-names>L. R.</given-names>
</name>
<name>
<surname>Jain</surname>
<given-names>L. C.</given-names>
</name>
</person-group> (<year>2001</year>). <article-title>Recurrent Neural Networks</article-title>. <source>Des. Appl.</source> <volume>5</volume>, <fpage>64</fpage>&#x2013;<lpage>67</lpage>. </citation>
</ref>
<ref id="B37">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Nguyen</surname>
<given-names>N. T.</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Han</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2011</year>). &#x201c;<article-title>Device Fingerprinting to Enhance Wireless Security Using Nonparametric Bayesian Method</article-title>,&#x201d; in <conf-name>2011 Proceedings IEEE INFOCOM</conf-name>, <fpage>1404</fpage>&#x2013;<lpage>1412</lpage>. <pub-id pub-id-type="doi">10.1109/infcom.2011.5934926</pub-id> </citation>
</ref>
<ref id="B38">
<citation citation-type="web">
<collab>OAuth 2.0, OAuth</collab> (<year>2022</year>). <comment>[Online] Available at: <ext-link ext-link-type="uri" xlink:href="https://oauth.net/2/">https://oauth.net/2/</ext-link>
</comment>(<comment>Accessed 14Jan, 2022)</comment>.</citation>
</ref>
<ref id="B39">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ometov</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Bezzateev</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>M&#xe4;kitalo</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Andreev</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Mikkonen</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Koucheryavy</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Multi-factor Authentication: A Survey</article-title>. <source>Cryptography</source> <volume>21</volume> (<issue>1</issue>), <fpage>1</fpage>. <pub-id pub-id-type="doi">10.3390/cryptography2010001</pub-id> </citation>
</ref>
<ref id="B40">
<citation citation-type="web">
<collab>ORBIT</collab> (<year>2022</year>). <article-title>Open-access Research Testbed for Next-Generation Wireless Networks (Orbit)</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.orbit-lab.org/">https://www.orbit-lab.org/</ext-link>
</comment>. </citation>
</ref>
<ref id="B41">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>O&#x2019;Shea</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Hoydis</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>An Introduction to Deep Learning for the Physical Layer</article-title>. <source>IEEE Trans. Cogn. Commun. Netw.</source> <volume>3</volume> (<issue>4</issue>), <fpage>563</fpage>&#x2013;<lpage>575</lpage>. <pub-id pub-id-type="doi">10.1109/TCCN.2017.2758370</pub-id> </citation>
</ref>
<ref id="B42">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Pal</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2005</year>). <article-title>Random forest Classifier for Remote Sensing Classification</article-title>. <source>Int. J. remote sensing</source> <volume>26</volume> (<issue>1</issue>), <fpage>217</fpage>&#x2013;<lpage>222</lpage>. <pub-id pub-id-type="doi">10.1080/01431160412331269698</pub-id> </citation>
</ref>
<ref id="B43">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Patel</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2015</year>). &#x201c;<article-title>Non-parametric Feature Generation for Rf-Fingerprinting on Zigbee Devices</article-title>,&#x201d; in <conf-name>2015 IEEE Symposium on Computational Intelligence for Security and Defense Applications</conf-name> (<publisher-name>CISDA</publisher-name>), <fpage>1</fpage>&#x2013;<lpage>5</lpage>. <pub-id pub-id-type="doi">10.1109/cisda.2015.7208645</pub-id> </citation>
</ref>
<ref id="B44">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Peng</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Hu</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Jiang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Yan</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Design of a Hybrid RF Fingerprint Extraction and Device Classification Scheme</article-title>. <source>IEEE Internet Things J.</source> <volume>6</volume> (<issue>1</issue>), <fpage>349</fpage>&#x2013;<lpage>360</lpage>. <pub-id pub-id-type="doi">10.1109/JIOT.2018.2838071</pub-id> </citation>
</ref>
<ref id="B45">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Peng</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Hu</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Deep Learning Based Rf Fingerprint Identification Using Differential Constellation Trace Figure</article-title>. <source>IEEE Trans. Veh. Technol.</source> <volume>69</volume> (<issue>1</issue>), <fpage>1091</fpage>&#x2013;<lpage>1095</lpage>. <pub-id pub-id-type="doi">10.1109/tvt.2019.2950670</pub-id> </citation>
</ref>
<ref id="B46">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Plusquellic</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Physical Unclonable Functions 1</article-title>. <comment>[Online]. Available at: <ext-link ext-link-type="uri" xlink:href="http://ece-research.unm.edu/jimp/HOST/slides/PUF1.pdf">http://ece-research.unm.edu/jimp/HOST/slides/PUF1.pdf</ext-link> (Accessed &#x3d; Feb 6, 2022)</comment>. </citation>
</ref>
<ref id="B47">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Quisquater</surname>
<given-names>J.-J.</given-names>
</name>
<name>
<surname>Samyde</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2001</year>). &#x201c;<article-title>Electromagnetic Analysis (Ema): Measures and Counter-measures for Smart Cards</article-title>,&#x201d; in <conf-name>International Conference on Research in Smart Cards</conf-name> (<publisher-loc>Berlin, Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>200</fpage>&#x2013;<lpage>210</lpage>. <pub-id pub-id-type="doi">10.1007/3-540-45418-7_17</pub-id> </citation>
</ref>
<ref id="B48">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Rasmussen</surname>
<given-names>K. B.</given-names>
</name>
<name>
<surname>Capkun</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2007</year>). &#x201c;<article-title>Implications of Radio Fingerprinting on the Security of Sensor Networks</article-title>,&#x201d; in <conf-name>2007 Third International Conference on Security and Privacy in Communications Networks and the Workshops-Secure Comm 2007</conf-name> (<publisher-name>IEEE, Sep.</publisher-name>), <fpage>331</fpage>&#x2013;<lpage>340</lpage>. <pub-id pub-id-type="doi">10.1109/seccom.2007.4550352</pub-id> </citation>
</ref>
<ref id="B49">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Robinson</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Kuzdeba</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Stankowicz</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Carmack</surname>
<given-names>J. M.</given-names>
</name>
</person-group> (<year>2020</year>). &#x201c;<article-title>Dilated Causal Convolutional Model for Rf Fingerprinting</article-title>,&#x201d; in <conf-name>roc. of 10th Annual Computing and Communication Workshop and Conference</conf-name> (<publisher-name>CCWC</publisher-name>), <fpage>0157</fpage>. <pub-id pub-id-type="doi">10.1109/ccwc47524.2020.9031257</pub-id>
<source>P</source> </citation>
</ref>
<ref id="B50">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Roy</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Mukherjee</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Chatterjee</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Pasiliao</surname>
<given-names>E.</given-names>
</name>
</person-group> (<year>2019</year>). &#x201c;<article-title>Detection of Rogue Rf Transmitters Using Generative Adversarial Nets</article-title>,&#x201d; in <conf-name>2019 IEEE Wireless Communications and Networking Conference</conf-name> (<publisher-name>WCNC</publisher-name>), <fpage>1</fpage>&#x2013;<lpage>7</lpage>. <pub-id pub-id-type="doi">10.1109/wcnc.2019.8885548</pub-id> </citation>
</ref>
<ref id="B51">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Sankhe</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Belgiovine</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Zhou</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Angioloni</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Restuccia</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>D&#x27;Oro</surname>
<given-names>S.</given-names>
</name>
<etal/>
</person-group> (<year>2020</year>). <article-title>No Radio Left behind: Radio Fingerprinting through Deep Learning of Physical-Layer Hardware Impairments</article-title>. <source>IEEE Trans. Cogn. Commun. Netw.</source> <volume>6</volume> (<issue>1</issue>), <fpage>165</fpage>&#x2013;<lpage>178</lpage>. <pub-id pub-id-type="doi">10.1109/TCCN.2019.2949308</pub-id> </citation>
</ref>
<ref id="B52">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Scanlon</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Kennedy</surname>
<given-names>I. O.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2010</year>). <article-title>Feature Extraction Approaches to RF Fingerprinting for Device Identification in Femtocells</article-title>. <source>Bell Labs Tech. J.</source> <volume>15</volume> (<issue>3</issue>), <fpage>141</fpage>&#x2013;<lpage>151</lpage>. <pub-id pub-id-type="doi">10.1002/bltj.20462</pub-id> </citation>
</ref>
<ref id="B53">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Shaw</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Kinsner</surname>
<given-names>W.</given-names>
</name>
</person-group> (<year>1997</year>). &#x201c;<article-title>Multifractal Modelling of Radio Transmitter Transients for Classification</article-title>,&#x201d; in <conf-name>IEEE WESCANEX 97 Communications, Power and Computing. Conference Proceedings</conf-name>, <fpage>306</fpage>&#x2013;<lpage>312</lpage>. </citation>
</ref>
<ref id="B54">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Siddiqui</surname>
<given-names>M. S.</given-names>
</name>
<name>
<surname>Verma</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2011</year>). &#x201c;<article-title>Cross Site Request Forgery: A Common Web Application Weakness</article-title>,&#x201d; in <conf-name>2011 IEEE 3rd International Conference on Communication Software and Networks</conf-name> (<publisher-name>IEEE</publisher-name>), <fpage>538</fpage>&#x2013;<lpage>543</lpage>. <pub-id pub-id-type="doi">10.1109/iccsn.2011.6014783</pub-id> </citation>
</ref>
<ref id="B55">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Soltani</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Reus-Muns</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Salehi</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Dy</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Ioannidis</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Chowdhury</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Rf Fingerprinting Unmanned Aerial Vehicles with Nonstandard Transmitter Waveforms</article-title>. <source>IEEE Trans. Vehicular Technology</source> <volume>69</volume> (<issue>12</issue>), <fpage>15 518</fpage>&#x2013;<lpage>615 531</lpage>. <pub-id pub-id-type="doi">10.1109/tvt.2020.3042128</pub-id> </citation>
</ref>
<ref id="B56">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Symanovich</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2019</year>). <source>The Future of IOT: 10 Predictions about the Internet of Things</source>. <publisher-name>Norton</publisher-name>, <fpage>14</fpage>. <comment>[Online]. Available at: <ext-link ext-link-type="uri" xlink:href="https://us.norton.com/internetsecurity-iot-5-predictions-for-the-future-of-iot.html">https://us.norton.com/internetsecurity-iot-5-predictions-for-the-future-of-iot.html</ext-link> (Accessed Jan, 2022)</comment>. </citation>
</ref>
<ref id="B57">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Ting</surname>
<given-names>D. M.</given-names>
</name>
<name>
<surname>Hussain</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>LaRoche</surname>
<given-names>G.</given-names>
</name>
</person-group> (<year>2015</year>). <source>Systems and Methods for Multi-Factor Authentication</source>. <publisher-loc>Washington, DC</publisher-loc>: <publisher-name>U.S. Patent and Trademark Office</publisher-name>. <comment>U.S. Patent No. 9,118,656</comment>. </citation>
</ref>
<ref id="B58">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Ur Rehman</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Sowerby</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Coghill</surname>
<given-names>C.</given-names>
</name>
</person-group> (<year>2012</year>). &#x201c;<article-title>Rf Fingerprint Extraction from the Energy Envelope of an Instantaneous Transient Signal</article-title>,&#x201d; in <conf-name>2012 Australian Communications Theory Workshop</conf-name> (<publisher-name>CTW</publisher-name>), <fpage>90</fpage>&#x2013;<lpage>95</lpage>. <pub-id pub-id-type="doi">10.1109/ausctw.2012.6164912</pub-id> </citation>
</ref>
<ref id="B59">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Vo-Huu</surname>
<given-names>T. D.</given-names>
</name>
<name>
<surname>Vo-Huu</surname>
<given-names>T. D.</given-names>
</name>
<name>
<surname>Noubir</surname>
<given-names>G.</given-names>
</name>
</person-group> (<year>2016</year>). &#x201c;<article-title>Fingerprinting Wi-Fi Devices Using Software Defined Radios</article-title>,&#x201d; in <conf-name>Proceedings of the 9th ACM Conference on Security &#x26; Privacy in Wireless and Mobile Networks</conf-name>, <fpage>3</fpage>&#x2013;<lpage>14</lpage>. <pub-id pub-id-type="doi">10.1145/2939918.2939936</pub-id> </citation>
</ref>
<ref id="B60">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Wen</surname>
<given-names>C.-K.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Gao</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Jiang</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Jin</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>Deep Learning for Wireless Physical Layer: Opportunities and Challenges</article-title>. <source>China Commun.</source> <volume>14</volume> (<issue>11</issue>), <fpage>92</fpage>&#x2013;<lpage>111</lpage>. <pub-id pub-id-type="doi">10.1109/cc.2017.8233654</pub-id> </citation>
</ref>
<ref id="B61">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Mao</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>RF Sensing in the Internet of Things: A General Deep Learning Framework</article-title>. <source>IEEE Commun. Mag.</source> <volume>56</volume> (<issue>9</issue>), <fpage>62</fpage>&#x2013;<lpage>67</lpage>. <pub-id pub-id-type="doi">10.1109/mcom.2018.1701277</pub-id> </citation>
</ref>
<ref id="B62">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Yang</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2017</year>). &#x201c;<article-title>Ethical Hacking and Network Defense: Choose Your Best Network Vulnerability Scanning Tool</article-title>,&#x201d; in <conf-name>2017 31st International Conference on Advanced Information Networking and Applications Workshops</conf-name> (<publisher-name>WAINA</publisher-name>), <fpage>110</fpage>&#x2013;<lpage>113</lpage>. <pub-id pub-id-type="doi">10.1109/waina.2017.39</pub-id> </citation>
</ref>
<ref id="B63">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xie</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Wen</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Hu</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>Y.</given-names>
</name>
<etal/>
</person-group> (<year>2018</year>). <article-title>Optimized Coherent Integration-Based Radio Frequency Fingerprinting in Internet of Things</article-title>. <source>IEEE Internet Things J.</source> <volume>5</volume> (<issue>5</issue>), <fpage>3967</fpage>&#x2013;<lpage>3977</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2018.2871873</pub-id> </citation>
</ref>
<ref id="B64">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xu</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Saad</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Han</surname>
<given-names>Z.</given-names>
</name>
</person-group> (<year>2016a</year>). <article-title>Device Fingerprinting in Wireless Networks: Challenges and Opportunities</article-title>. <source>IEEE Commun. Surv. Tutorials</source>. <volume>18</volume>, <fpage>94</fpage>&#x2013;<lpage>104</lpage>. <pub-id pub-id-type="doi">10.1109/COMST.2015.2476338</pub-id> </citation>
</ref>
<ref id="B65">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xu</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Saad</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Han</surname>
<given-names>Z.</given-names>
</name>
</person-group> (<year>2016b</year>). <article-title>Device Fingerprinting in Wireless Networks: Challenges and Opportunities</article-title>. <source>IEEE Commun. Surv. Tutorials</source> <volume>18</volume> (<issue>1</issue>), <fpage>94</fpage>&#x2013;<lpage>104</lpage>. <pub-id pub-id-type="doi">10.1109/comst.2015.2476338</pub-id> </citation>
</ref>
<ref id="B66">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Yuan</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Wu</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>X.</given-names>
</name>
</person-group> (<year>2014</year>). <article-title>Specific Emitter Identification Based on Hilbert-Huang Transform&#x2010;based Time-Frequency-Energy Distribution Features</article-title>. <source>IET Commun.</source> <volume>8</volume> (<issue>13</issue>), <fpage>2404</fpage>&#x2013;<lpage>2412</lpage>. <pub-id pub-id-type="doi">10.1049/iet-com.2013.0865</pub-id> </citation>
</ref>
<ref id="B67">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Patras</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Haddadi</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Deep Learning in mobile and Wireless Networking: A Survey</article-title>. <source>IEEE Commun. Surv. Tutorials</source> <volume>21</volume> (<issue>3</issue>), <fpage>2224</fpage>&#x2013;<lpage>2287</lpage>. <pub-id pub-id-type="doi">10.1109/comst.2019.2904897</pub-id> </citation>
</ref>
<ref id="B68">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Zhao</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Cai</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Shi</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Du</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Guizani</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2018</year>). &#x201c;<article-title>Classification of Small Uavs Based on Auxiliary Classifier Wasserstein gans</article-title>,&#x201d; in <conf-name>2018 IEEE Global Communications Conference</conf-name> (<publisher-name>GLOBECOM</publisher-name>), <fpage>206</fpage>&#x2013;<lpage>212</lpage>. <pub-id pub-id-type="doi">10.1109/glocom.2018.8647973</pub-id> </citation>
</ref>
<ref id="B69">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhuo</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>chen</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>Radio Frequency Fingerprint Extraction of Radio Emitter Based on I/q Imbalance</article-title>. <source>Proced. Computer Sci.</source> <volume>107</volume>, <fpage>472</fpage>&#x2013;<lpage>477</lpage>. <pub-id pub-id-type="doi">10.1016/j.procs.2017.03.092</pub-id> </citation>
</ref>
<ref id="B70">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Zong</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Yuan</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2020</year>). &#x201c;<article-title>A Rf Fingerprint Recognition Method Based on Deeply Convolutional Neural Network</article-title>,&#x201d; in <conf-name>Proc. of IEEE 5th Information Technology and Mechatronics Engineering Conference (ITOEC)</conf-name>, <fpage>1778</fpage>&#x2013;<lpage>1781</lpage>. <pub-id pub-id-type="doi">10.1109/itoec49072.2020.9141877</pub-id> </citation>
</ref>
</ref-list>
</back>
</article>