scieee AI-readable full text Open interactive document viewer

Securing the Sensing Functionality in ISAC Networks: An Artificial Noise Design

6G-MUSICAL

Abstract

Integrated sensing and communications (ISAC) systems employ dual-functional signals to simultaneously accomplish radar sensing and wireless communication tasks. However, ISAC systems open up new sensing security vulnerabilities to malicious illegitimate eavesdroppers (Eves) that can also exploit the transmitted waveform to extract sensing information from the environment. In this paper, we investigate the beamforming design to enhance the sensing security of an ISAC system, where the communication user (CU) serves as a sensing Eve. Our objective is to maximize the mutual information (MI) for the legitimate radar sensing receiver while considering the constraint of theMI for the Eve and the quality of service to the CUs. Then, we consider the artificial noise (AN)-aided beamforming to further enhance the sensing security. Simulation results demonstrate that our proposed methods achieve MI improvement of the legitimate receiver while limiting the sensingMI of the Eve, compared withthe baseline scheme, and that the utilization of AN further contributes to sensing security.

Full text

17800 IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 Securing the Sensing Functionality in ISAC Networks: An Artificial Noise Design Jiaqi Zou , Graduate Student Member, IEEE, Christos Masouros , Fellow, IEEE, Fan Liu , Senior Member, IEEE, and Songlin Sun , Senior Member, IEEE Abstract—Integrated sensing and communications (ISAC) systems employ dual-functional signals to simultaneously accomplish radar sensing and wireless communication tasks. However, ISAC systems open up new sensing security vulnerabilities to malicious illegitimate eavesdroppers (Eves) that can also exploit the transmitted waveform to extract sensing information from the environment. In this paper, we investigate the beamforming design to enhance the sensing security of an ISAC system, where the communication user (CU) serves as a sensing Eve. Our objective is to maximize the mutual information (MI) for the legitimate radar sensing receiver while considering the constraint of the MI for the Eve and the quality of service to the CUs. Then, we consider the artificial noise (AN)-aided beamforming to further enhance the sensing security. Simulation results demonstrate that our proposed methods achieve MI improvement of the legitimate receiver while limiting the sensing MI of the Eve, compared with the baseline scheme, and that the utilization of AN further contributes to sensing security. Index Terms—Integrated sensing and communications, sensing security, mutual information, artificial noise. I. INTRODUCTION Integrated sensing and communications (ISAC) is identified as a key 6G technology that will support various futuristic applications through the co-design of sensing and communication functionalities. In particular, supported by the implementation of the dual-functional waveform and the base stations (BSs), ISAC provides a step change from the spectral coexistence of radar and communication systems to the shared utilization of costly hardware platforms. Inspired by these favorable characteristics, various designs have been proposed for the dual-functional waveforms to promote sensing and communication performance. For example, recent works in [1] considered the Manuscript received 3 October 2023; revised 26 January 2024 and 29 April 2024; accepted 5 June 2024. Date of publication 5 July 2024; date of current version 7 November 2024. This work was supported in part by the National Natural Science Foundation of China Grant 62331023, in part by Project 6GMUSICAL Part of the Smart Networks and Services Joint Undertaking (SNS JU) through the European Union’s Horizon Europe Research and Innovation Programme under Grant 101139176, and in part by Shenzhen Fundamental Research Program under Grant 20220815100308002. The review of this article was coordinated by Dr. Yuanwei Liu. (Corresponding author: Jiaqi Zou.) Jiaqi Zou is with the School of Information and Communication Engineering, Beijing University of Posts and Telecommunications (BUPT), Beijing 100876, China, and also with the Department of Electrical and Electronic Engineering, University College London, WC1E 7JE London, U.K. (e-mail: [email protected]). Christos Masouros is with the Department of Electronic and Electrical Engineering, University College London, WC1E 7JE London, U.K. (e-mail: [email protected]). Fan Liu is with the School of System Design and Intelligent Manufacturing, Southern University of Science and Technology, Shenzhen 518055, China (e-mail: [email protected]). Songlin Sun is with the Beijing University of Posts and Telecommunications (BUPT), Beijing 100876, China (e-mail: [email protected]). Digital Object Identifier 10.1109/TVT.2024.3422036 Cramér-Rao bound (CRB) minimization subject to the minimum signalto-interference-plus-noise ratio (SINR) constraints for each communication user (CU), and intelligent reflecting surface assisted sensing is studied in [2]. However, the aforementioned works have overlooked the consideration of security issues, which avail unique vulnerabilities in ISAC systems. Due to the inherent broadcast nature of wireless signals, it is inevitable that wireless communication/sensing systems are susceptible to potential security threats. Compared with the communication-only systems, ISAC systems encounter more intricate security issues which can be generally categorized into the information security for communication and the sensing security for radar. The former arises from the fact that the probing ISAC waveform is modulated with information, which could potentially be leaked to the sensed targets that can act as eavesdroppers (Eves). To deal with this, physical layer security schemes have been proposed, such as [3] that maximized the secrecy rate by jointly optimizing the beamforming vector, the duration of snapshots, and the covariance matrix of the artificial noise (AN). Besides, the work in [4] optimized the beamforming and AN design to minimize the signal-to-noise ratio (SNR) at the Eve. The work in [5] designed the ISAC systems for securing confidential information from wiretapping from the viewpoint of information theory and studied the inner and outer bounds on its secrecy-distortion region. Additionally, a few works have highlighted the issue of radar privacy in the radar-communication spectrum sharing scenarios. In such cases, the radar information embedded within a precoder could be utilized by an adversary to infer the radar’s location [6]. In contrast, the sensing security issue in ISAC systems has not been well investigated. In future ISAC deployments, there will be users subscribing to a communication service, others to a sensing service and others to both. In this case, we consider a very realistic scenario where a CU subscribing to a communication service, should not be able to exploit ISAC signals for its own sensing. Security solutions for this scenario will be of paramount importance. In particular, the transmitted waveform could be exploited by a CU, which acts as a malicious passive sensing Eve to extract sensing information about targets or their surroundings. In comparison with networks dedicated solely to communication, such a possibility introduces a unique and significant risk: the potential for privacy breaches concerning environmental and target information, as any CU within the network can illegally use the waveform for sensing. This risk poses significant challenges and the urgent need to secure the sensing functionality of ISAC networks. Against this background, our work proposes to address the sensing security issue for ISAC systems. In particular, we consider a bi-static ISAC scenario, simultaneously achieving multiple user communication and bi-static target estimation with a legitimate radar receiver. In this scenario, one of the CUs, granted access only to communication services, seeks unauthorized access to illegitimate sensing, therefore taking the role of a sensing Eve. To prevent sensing information leakage from the sensing Eve in ISAC networks, we formulate the sensing security problem to maximize the radar mutual information (MI) of the legitimate receiver, subject to the limitation of the radar MI of the Eve, the minimum SINR constraints of each CU and the maximum transmit power budget. Since the formulated problem is nonconvex, we propose a successive convex approximation (SCA) method combined with semidefinite relaxation (SDR) to deal with the non-convexity. Furthermore, we propose an AN-aided secure sensing method to provide spatial degrees of freedom to degrade the radar MI of the Eve. 0018-9545 © 2024 IEEE. Personal use is permitted, but republication/redistribution requires IEEE permission. See https://www.ieee.org/publications/rights/index.html for more information. Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 17801 Different from the AN in communication-only scheme which need to be carefully designed to avoid interfering with legitimate CU, we show that in sensing, the AN can act as a useful signal for the legitimate radar receiver but is harmful to the sensing Eve. Different from the AN used in communication-only schemes, which requires careful design to avoid interference with legitimate CUs, we demonstrate that in sensing functionalities, AN can serve a dual role. It acts as a useful signal for the legitimate radar receiver while simultaneously impeding sensing capabilities of the Eve. We give the derivation of radar MI with AN for the first time, and then jointly optimize the beamforming and the covariance of AN. Simulation results demonstrate significant improvement in the sensing MI of our proposed methods compared with the baseline and also reveal that through adding AN to the transmit signals of the BS, the secure sensing performance can be effectively improved. II. SYSTEM MODEL We consider a bistatic multiple-input multiple-output (MIMO) ISAC system, which consists of a central BS transmitting dual-functional signals to a legitimate radar receiver and Ksingle-antenna CUs. Simultaneously, a CU serves as an unauthorized sensing Eve who perfectly knows/intercepts the transmitted signals and also wishes to sense the targets/environment. We assume that the transmitter is equipped with a uniform linear array (ULA) of Ntantennas and that the legitimate receiver and the Eve are equipped with Nrand Neantennas, respectively. A. Communication Signal Model and Metrics Let hk∈CNt×1represent the communication channel vector for the k-th use. We assume that the channel follows a slow-fading block Rician fading channel, given as hk=Kk Kk+1hLoS,k +1 Kk+1hNLoS,k,(1) where Kkdenotes the Rician factor of the channel between the k-th CU and the BS. hLoS,k denotes the deterministic LoS channel component with hLoS,k =[1,...,e −jπ(Nt−1)cosθk],whereθk∈[0,π]is the angle-of-arrival (AoA) of the line-of-sight (LoS) link from the k-th CU to the BS and we assume half-wavelength antenna spacing. hNLoS,k represents the random scattered components whose elements follows CN(0,1). Let us denote the beamforming matrix as W=[w1,w2,...,wk]∈ CNt×K,wherewk∈CNt×1stands for the beamforming vector of the kth user. Then, the transmitted signal at the l-th time slot can be expressed as x[l]=Ws[l],(2) where s[l]∈C K×1includes Kparallel communication symbol streams to be communicated to Kusers. Without loss of generality, we assume the communication symbols have unit power, i.e., E[s[l]s[l]H]=I,and the communication channel matrix is perfectly estimated and known at the BS side. Then, we have the SINR at the k-th CU as SINRk=hH kwk 2 σ2 c+K j=1,j=k|hH kwj|2,(3) where σ2 cis the variance of additive white Gaussian noise. B. Radar Signal Model We consider a bistatic radar sensing scenario where the transmitted signals are shared between the transmitter and receiver through a control center. Denoting X=[x[1],x[2],...,x[L]] ∈C Nt×Las the transmitted waveform during Ltime slots, the received signal matrix at the legitimate receiver and the Eve can be expressed, respectively, as Yr=Hr(θr)X+Zr,Ye=He(θe)X+Ze,(4) where Zrand Zeare the noise matrices at the legitimate receiver and the Eve, respectively and each columns of Zrand Zefollow CN(0,σ2 rI) and CN(0,σ2 eI), respectively. Hrand Heare the target response matrices from the transmitter to the legitimate receiver and the Eve, respectively, which are determined by the target parameters of interests θrand θe.1Note that θr=θesince the legitimate receiver and the Eve may have different sensing interests to estimate different angles and ranges, etc. As Eve is a legitimate CU, we note that Hecan also be known at the BS, which is achievable by leveraging the knowledge of Eve’s location [9]. For radar sensing, it is essential to estimate the target response matrix, i.e., Hror He, as it contains the sensing information. With estimated Hror Heat hand, one can extract the sensing parameters in real time, such as the range, radial velocity, angular direction [10],[11]. To measure the sensing performance at the receivers, we adopt the MI between the received radar signal and target response matrix, as MI characterizes the amount of sensing information of the radar to estimate the parameters describing the target. It is also implied in [12],[13] that maximing the sensing MI enables improved performance in target parameter estimation, classification, and identification. Following [14], the sensing MI of the legitimate receiver can be given as Ir(Yr;θr|X)=Ir(Yr;Hr|X).(5) Vectorizing Y,wehave vec(Yr)= ˜ Xhr+zr,(6) where ˜ X=XT⊗INr,hr=vec(Hr),andzr=vec(Zr)[15, 1.11.20]. Following the assumptions are also used in [11], we assume the target response vector hris zero-mean circular-symmetric Gaussian distributed with covariance Rh. As the transmitted waveform is perfectly known, the MI between Yrand Hrat the legitimate receiver can be expressed as Ir(Yr;Hr|X)=h(Yr|X)−h(Yr|Hr,X)(7a) =logdet(I+σ−2 r˜ XRhr˜ XH)(7b) =logdet(I+σ−2 rRhr(X∗XT⊗INr)),(7c) where we used the property of matrix determinant that det(I+AB)= det(I+BA).LetRhr=UrΛrUH rbe the eigenvalue decomposition of Rhr,andKbe a real commutation matrix satisfying KKT=I.We then have Ir=logdet(I+σ−2 rΛrUH rK(INr⊗X∗XT)KTUr) =logdet(I+σ−2 rLΛr Nr  i=1 PiR∗ XPH i),(8) 1At the transmitter side, the beam direction from the transmitter to the target and the target response matrices are generally predefined, which is determined based on the location of target identified in previous observations or the central angle of the sector of interest [1],[3],[7],[8]. Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply. 17802 IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 where P=UH rK=[P1,P2,...,PNr]and RXdenotes the covariance matrix of the transmit signal, given as [1] RX=1 LXXH≈WWH= K  k=1 wkwH k,(9) where the approximation holds when Lis large enough. Similarly, the MI between Yrand Hrat the Eve can be expressed as Ie(Ye;He|X)= logdet(I+σ−2 eRhe(X∗XT⊗INe)) =logdet(I+σ−2 eLΛe Ne  i=1 QiR∗ XQH i),(10) where Rhedenotes the covariance of zero-mean circular-symmetric Gaussian distributed he=vec(He), whose eigenvalue decomposition is given as Rhe=UeΛeUH e.Q=UH eK=[Q1,Q2,...,QNe]. III. BEAMFORMING DESIGN FOR SENSING SECURITY WITHOUT AN In this section, we first investigate the beamforming design without the aid of AN to guarantee secure sensing. Our objective is to maximize the MI of the legitimate receiver while keeping the MI of the Eve lower than the preset threshold, and satisfying multiple users’ required SINR and the power budget. The optimization problem can be formulated as follows max {Wk}K k=1 Ir=logdetI+σ−2 rLΛr Nr  i=1 PiR∗ XPH i(11a) s.t.I e=logdet I+σ−2 eLΛe Ne  i=1 QiR∗ XQH i≤, (11b) tr(RX)≤P0,(11c) tr hkWkhH k K k=1,k=itr (hkWihH k)+σ2 c ≥γk,∀k, (11d) RX= K  k=1 Wk,Wk0,rank(Wk)=1,∀k, (11e) where Wk=wkwH k. In general, it is challenging to solve problem (11) directly, due to the nonconvexity of the constraint (11b),(11d),and the rank-1 constraint in (11e). For addressing the nonconvex constraint (11b), we notice that Ieis a concave function in RX. Thus, we give the upper-bound of (11b) based on first-order Taylor expansion at a given transmit covariance matrix ˜ RX=K k=1˜ Wkas ˜ Ief(˜ RX)+tr Re 2σ−2 eL Ne  i=1 QT i(M−1)∗ΛeQ∗ iRX −tr Re 2σ−2 eL Ne  i=1 QT i(M−1)∗ΛeQ∗ i˜ RX.(12) where M=I+σ−2 eLΛeNe i=1Qi˜ R∗ XQH i. The details are given in Appendix A. As such, it can be easily observed that the approximated function is convex on RX. Thus, RXcan be iteratively obtained by updating ˜ RX. Then, we focus on dealing with the rank-1 constraint in (11e), which can be equivalently transformed into an equivalent linear matrix inequality (LMI) as Wkwk wH k10,(13a) tr(Wk)−wH kwk≤0,∀k. (13b) Additionally, the non-convexity in (13b) can be handled by the firstorder Taylor expansions at ˜ wkas tr(Wk)−˜ wH k˜ wk−2Re ˜ wH kwk≤0,(14) where Re(·)denotes the real part of the argument and ˜ wkcan be updated at each iteration. Therefore, a convex approximation of problem (11) is reformulated as max {wk,Wk}K k=1 Ir(15a) s.t. ˜ Ie≤, (15b) tr(RX)≤P0,(15c) Wk0,RX= K  k=1 Wk,(15d) tr hkWkhH k−γk K  k=i,k=1 tr hkWkhH k≥γkσ2 c,∀k, (15e) (13a),(14),(15f) which is easily shown to be convex, and hence, Wkcan be iteratively obtained by solving problem (15) based on updating ˜ wkand ˜ Wkin an iterative manner. However, due to the stringent requirement introduced by (15b) and (13b), it is generally non-trivial to directly obtain a feasible solution as an initial point. Alternatively, we can adopt the penalty SCA [16] and introduce auxiliary variables ¯p, ρk,κto transform problem (15) into max {wk,Wk,ρk}K k=1,κ Ir−¯pκ −¯p K  k=1 ρk(16a) s.t. ˜ Ie≤+κ, (16b) tr(Wk)−˜ wH k˜ wk−2Re ˜ wH kwk≤ρk,(16c) (13a),(15c),(15d),(15e),(16d) where ¯pand ρk,κdenote the weight coefficient and the penalty terms, respectively. We present the proposed iterative algorithm in Algorithm 1. IV. SECURE SENSING WITH AN In this section, we consider utilizing AN to assist secure sensing. Note that the instantaneous AN matrix, N, can be known to the legitimate receiver but remains unknown to the Eve.2 Firstly, we give the received signal at the legitimate receiver as Yr=Hr(θr)X+Hr(θr)N+Zr.(17) 2As indicated in the literature of physical layer secuirity [17],[18],[19],a large set of seeds for a Gaussian pseudorandom generator can be prestored at both transmitter and legitimate sensing receiver. Then, the transmitter regularly picks up one seed and securely delivers its index to the legitimate sensing receiver through the control center. Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 17803 Algorithm 1: Proposed Iterative Algorithm for Handling (16) Randomly set {w(0) k,W(0) k},¯p(0)=10−3,λ>1, i=0; repeat i←i+1; ˜ w(i) k,˜ W(i) k←w(i−1) k,W(i−1) k; Solve problem (15) to obtain the optimal w(i) k,W(i) k; ¯p(i)←λ¯p(i−1) until both I(i) r−I(i−1) rand the penalty terms ρk,κare significantly small. Then, the MI of the legitimate receiver can be expressed as Ir(Yr;θr|X,N)=Ir(Yr;Hr|X,N)(18a) =h(Yr|X,N)−h(Yr|Hr,X,N)(18b) =logdet(I+σ−2 r(˜ X+˜ N)Rhr(˜ X+˜ N)H)(18c) =logdet(I+σ−2 r(˜ X+˜ N)H(˜ X+˜ N)Rhr)(18d) (a) ≈log det I+σ−2 rLK(INr⊗(R∗ X+R∗ N))KTRhr(18e) =logdetI+σ−2 rLΛr Nr  i=1 Pi(R∗ X+R∗ N)PH i,(18f) where ˜ N=NT⊗INrand RN=1 LNNH. On the other hand, as the Eve has no prior knowledge of AN, the received signal and the MI at the Eve can be given as Ye=He(θe)X+He(θe)N+Ze,(19) and Ie(Ye;θe|X)=Ie(Yr;He|X)=h(Ye|X)−h(Ye|He,X), (20) respectively. Then, we have h(Ye|He,X) =−X,Y,H f(X,Y,H)logf(Y|X,H)dXdYdH =−X,H f(X,H)Y f(Y|X,H)logf(Y|X,H)dYdXdH =X,H f(X,H)log(2πe)n det L(R∗ N⊗INe )hehH e+σ2 eIdXdH ≈1 J J  j=1 log det 2πeL(R∗ N⊗INe)he,j hH e,j +σ2 eI, =1 J J  j=1 log det 2πeLK(INe⊗R∗ N)KThe,j hH e,j +σ2 eI(21a) where he,j (θ)is the j-th sample of the random variable he(θ).However, it’s still difficult to derive the exact expression of h(Ye|X)due to the additive non-Gaussian noise of He(θe)N. To deal with this, we can give the upper bound of h(Ye|X)as ¯ h(Ye|X)=logdet2πeσ2 eI+RHN,(22) where RHN denotes the covariance of vec(HN), given as RHN=EH,N[(IL⊗He)vec(N)(vec(N))H(IL⊗He)H] =EH [(IL⊗He)EH [vec(N)(vec(N))H]( IL⊗He)H] =EH[(IL⊗He)(IL⊗RN)(IL⊗He)H] ≈1 J J  j=1 (IL⊗He,j )(IL⊗RN)(IL⊗He,j )H(23a) Combining with (22), we derive the approximate upper bound of Ie as Ie=h(Ye|X)−h(Ye|He,X)<¯ Ie=¯ h(Ye|X)−h(Ye|He,X), (24) where ¯ Ie≈logdet σ2 eI+1 J J  j=1 (IL⊗He,j )(IL⊗RN)(IL⊗He,j )H  −1 J J  j=1 log det LK(INe⊗R∗ N)KThe,j hH e,j +σ2 eI. Then, the problem of sensing security with AN can be formulated as max {Wk}K k=1,RN Ir(Yr;θr|X,N)(25a) s.t.¯ Ie≤, (25b) tr hkWkhH k K k=1,k=itr (hkWihH k)+hkRNhH k+σ2 c ≥γk,∀k, (25c) tr K  k=1 Wk+RN≤P0, (11e).(25d) As previously discussed, the formulated problem is not convex due to the nonconvexity of (25b). Hence, we introduce an auxiliary matrix Q and reformulate (25b) based on the Taylor expansion at ˜ Qas log det( ˜ Q)+tr(˜ Q(Q−˜ Q)) (26a) −1 J J  j=1 log det LK(INe⊗R∗ N)KThe,j hH e,j +σ2 eI≤, Q−σ2 eI+1 J J  j=1 (IL⊗He,j )(IL⊗RN)(IL⊗He,j )H0. (26b) Therefore, a convex approximation of problem (25) is reformulated as max {wk,Wk}K k=1,RN Ir(27a) s.t.(13a),(14),(15d),(25c),(25d),(26a),(27b) which can be solved in a similar iterative manner as in Algorithm 1. Convergence and complexity analysis: We can note that in the iterative procedure of the algorithm, (27) can be optimally solved and the optimal value of its objective function serves as a lower bound on that of (25). Therefore, it can be guaranteed that the optimal value Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply. 17804 IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 Fig. 1. System model. The BS transmits ISAC waveform for a dual purpose: simultaneously sensing the target and serving multiple CUs. Fig. 2. MI of the legitimate receiver versus the number of iterations. The limitation of Eve’s MI is =5 nats and SINR threshold is γk=20 dB. at n-th iteration n, denoted as p(n) ∗, always satisfies p(n) ∗≥p(n−1) ∗. Therefore, the algorithm produces a non-decreasing objective function of problem (25). As there exists KLMI constraints of size Nt+1, and KLMI constraints of size Ntin (27), the worst-case computational complexity is O(M6.5K3.5Iiter ln(1/0)) given the required accuracy 0>0, where Iiter denotes the number of iterations [20]. V. SIMULATION RESULTS In this section, we provide numerical analysis to evaluate the performance of the proposed algorithms, including secure sensing de without AN and MI gap maximization with AN. We consider a dual-functional BS transceiver equipped with Nt=6 transmit antennas for MIMO radar sensing and multi-user communication, serving K=3 CUs where one of the CU serves as the sensing Eve. The legitimate radar receiver is equipped with Nr=2 receive antennas. Unless stated otherwise, the available power budget Pmax =30 dBm and the frame length L=30. Fig. 2firstly demonstrates the convergence behavior of the proposed method without the aid of AN, under different power budgets and numbers of users. It can be seen that all three cases converge after 3 iterations, which verifies the fast convergence rate and the efficiency of our proposed alternating algorithm. With increasing P0, the MI increases, since more power budget can be utilized to sense the target and satisfy the SINR constraints of multiple users. Moreover, increasing the number of CUs leads to a slight reduction in the sensing performance. Fig. 3compares the MI performance with different transmitted power budgets. We compare our proposed methods with two baseline schemes: the widely-used zero-forcing beamforming (ZF) and multi-user broadcasting beamforming design [21, Sec. 7.6.1] (MU-BC). It can be seen that Irof the proposed method is higher than that of the baseline schemes, with constrained Iethat guarantees sensing security. With the increase of transmit power budget, the gap between Irand Ieof the proposed algorithms achieves over 2 times higher than that of the baseline schemes. Moreover, it can be observed that the use of AN Fig. 3. MI versus the transmit power budget, in both with and without ANaided case, compared with the baselines. The limitation of the MI of the Eve is set as =5 nats and the SINR threshold is γk=28 dB. further improves the sensing MI of the legitimate receiver and while simultaneously increasing the MI performance gap. This observation indicates that the incorporation of AN can assisted sensing security with guaranteed communication SINR performance. This effectiveness arises because AN serves a dual role: it provides beneficial power for the legitimate receiver while acting as interference for the Eve. Plus, the designed AN simultaneously aligns closely with the null space of the communication channel to avoid degrading communication performance. VI. CONCLUSION AND FUTURE WORKS This paper addressed the sensing security issue for ISAC systems by beamforming design. The MI of radar sensing between the legitimate receiver was maximized while taking into account the MI of the potential Eve, power budget, and SINR constraints. Additionally, we adopted AN to further guarantee secure sensing. Simulation results demonstrated the effectiveness of the proposed methods in achieving a superior MI compared to the baseline scheme, with the AN further contributing to sensing security. The theoretical analysis and simulation results show that to secure sensing, network designers have the option to employ beamforming only, which can meet the basic sensing security requirements. However, for the tasks requiring higher sensitivity and enhanced sensing security, the joint design of transmit beamforming and AN should be considered. This approach, while offering superior security, necessitates more intricate derivations and analysis. Future works can consider the sensing security in ISAC networks that incorporate multi-antenna CUs, including the investigation of the joint transmitter-receiver design. APPENDIX A Here, we provide the proof for the MI approximation for the Eve in (10) based on a Taylor series expansion. First, defining f(RX)= log det(I+σ−2 eTΛeNr i=1QiR∗ XQH i), we have the Jacobian matrix of f(RX)expressed as DR∗ Xf(RX)=σ−2 eT Ne  i=1 QH iM−1ΛeQi.(28) Following [21, Sec. 1.1.11] and [15, Sec. 3.1], the gradient of f(RX) can be given as ∇RXf(RX)=2∇R∗ Xf(RX)=2σ−2 eT Ne  i=1 QT iΛe(M−1)TQ∗ i, Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. 73, NO. 11, NOVEMBER 2024 17805 Then, an affine Taylor series approximation of f(RX)at RX=˜ RX can be written as f(RX)≃f(˜ RX)+tr Re ∇f(˜ RX)HRX−˜ RX =f(˜ RX)+tr Re 2σ−2 eT Ne  i=1 QT i(M−1)∗ΛeQ∗ iRX −tr Re 2σ−2 eT Ne  i=1 QT i(M−1)∗ΛeQ∗ i˜ RX (29) REFERENCES [1] F. Liu, Y.-F. Liu, A. Li, C. Masouros, and Y. C. Eldar, “Cramér-Rao bound optimization for joint radar-communication beamforming,” IEEE Trans. Signal Process., vol. 70, pp. 240–253, 2022. [2] M. Hua, Q. Wu, W. Chen, Z. Fei, H. C. So, and C. Yuen, “Intelligent reflecting surface assisted localization: Performance analysis and algorithm design,” IEEE Wireless Commun. Lett., Jan., vol. 13, no. 1, pp. 84–88, Jan. 2024. [3] D. Xu, X. Yu, D. W. K. Ng, A. Schmeink, and R. Schober, “Robust and secure resource allocation for ISAC systems: A novel optimization framework for variable-length snapshots,” IEEE Trans. Commun., vol. 70, no. 12, pp. 8196–8214, Dec. 2022. [4] N. Su, F. Liu, and C. Masouros, “Secure radar-communication systems with malicious targets: Integrating radar, communications and jamming functionalities,” IEEE Trans. Wireless Commun., vol. 20, no. 1, pp. 83–95, Jan. 2021. [5] O. Günlü, M. R. Bloch, R. F. Schaefer, and A. Yener, “Secure integrated sensing and communication,” IEEE J. Sel. Areas Commun.,vol.4, pp. 40–53, 2023. [6] A. Dimas, M. A. Clark, B. Li, K. Psounis, and A. P. Petropulu, “On radar privacy in shared spectrum scenarios,” in Proc. IEEE Int. Conf. Acoust. Speech Signal Process., Brighton, U.K., May 2019, pp. 7790–7794. [7] J. Li and P. Stoica, “MIMO radar with colocated antennas,” IEEE Signal Process. Mag., vol. 24, no. 5, pp. 106–114, Sep. 2007. [8] H. Hua, J. Xu, and T. X. Han, “Optimal transmit beamforming for integrated sensing and communication,” IEEE Trans. Veh. Technol., vol. 72, no. 8, pp. 10588–10603, Aug. 2023. [9] O. Kanhere and T. S. Rappaport, “Position location for futuristic cellular communications: 5G and beyond,” IEEE Commun. Mag., vol. 59, no. 1, pp. 70–75, Jan. 2021. [10] C. Ouyang, Y. Liu, H. Yang, and N. Al-Dhahir, “Integrated sensing and communications: A mutual information-based framework,” IEEE Commun. Mag., vol. 61, no. 5, pp. 26–32, May 2023. [11] Y. Yang and R. S. Blum, “MIMO radar waveform design based on mutual information and minimum mean-square error estimation,” IEEE Trans. Aerosp. Electron. Syst., vol. 43, no. 1, pp. 330–343, Jan. 2007. [12] B. Tang and J. Li, “Spectrally constrained MIMO radar waveform design based on mutual information,” IEEE Trans. Signal Process., vol. 67, no. 3, pp. 821–834, Feb. 2019. [13] M. R. Bell, “Information theory and radar waveform design,” IEEE Trans. Inf. Theory, vol. 39, no. 5, pp. 1578–1597, Sep. 1993. [14] F. Liu, Y. Xiong, K. Wan, T. X. Han, and G. Caire, “Deterministic-random tradeoff of integrated sensing and communications in Gaussian channels: A rate-distortion perspective,” in Proc. IEEE Int. Symp. Inf.. Taipei, Taiwan, 2023, pp. 2326–2331. [15] X. Zhang, Matrix Analysis and Applications, 2nd ed. Beijing, China: Tsinghua Univ. Press, 2013. [16] C. Wang, Z. Li, T.-X. Zheng, D. W. K. Ng, and N. Al-Dhahir, “Intelligent reflecting surface-aided secure broadcasting in millimeter wave symbiotic radio networks,” IEEE Trans. Veh. Technol., vol. 70, no. 10, pp. 11050–11055, Oct. 2021. [17] R. Zhang, L. Song, Z. Han, and B. Jiao, “Physical layer security for twoway untrusted relaying with friendly jammers,” IEEE Trans. Veh. Technol., vol. 61, no. 8, pp. 3693–3704, Oct. 2012. [18] L. Hu, H. Wen, B. Wu, J. Tang, F. Pan, and R.-F. Liao, “Cooperativejamming-aided secrecy enhancement in wireless networks with passive eavesdroppers,” IEEE Trans. Veh. Technol., vol. 67, no. 3, pp. 2108–2117, Mar. 2018. [19] J. Li, A. P. Petropulu, and S. Weber, “On cooperative relaying schemes for wireless physical layer security,” IEEE Trans. Signal Process., vol. 59, no. 10, pp. 4985–4997, Oct. 2011. [20] A. Ben-Tal and A. Nemirovski, Lectures on Modern Convex Optimization: Analysis, Algorithms, and Engineering Applications. Philadelphia, PA, USA: SIAM, 2001. [21] C.-Y. Chi, W.-C. Li, and C.-H. Lin, Convex Optimization for Signal Processing and Communications: From Fundamentals to Applications. Boca Raton, FL, USA: CRC Press, 2017. Authorized licensed use limited to: University College London. Downloaded on January 16,2025 at 10:32:13 UTC from IEEE Xplore. Restrictions apply.