Preprint

False Channel Reports Could Disrupt 6G NOMA Decisions

A preprint traces manipulated channel feedback through power allocation, scheduling, decoding, fairness and secrecy, but reports no measured attack effects.

A preprint maps an attack surface in power-domain NOMA: decisions can be based on channel information that an attacker has deliberately distorted. It links false CSI to power allocation, user ranking, beamforming, decoding, fairness, throughput and secrecy, but gives no quantitative estimate of the effects. The authors frame this as a control-input integrity problem, meaning feedback is treated as strategically chosen input that can alter a base-station decision rather than as ordinary zero-mean estimation noise.

The document is a threat-modeling analysis rather than an empirical performance or countermeasure study, and it reports no empirical sample or dataset. It is a preprint submitted to IEEE Communications Magazine.

The order is part of the target

The paper sorts the threat model along two axes: the magnitude of the false report and its effect on user ordering. It distinguishes preserved-order cases, boundary cases and reversed-order cases. Those cases describe when near-far roles or the power split change before the receiver's successive interference cancellation, or SIC, check, a first-stage subtraction step. The concern is that SIC may then be evaluated against the wrong roles or power split.

Two ways to game the allocation

One route is selfish power capture. A strong-channel user reports a weaker channel, appears weaker to the system and is assigned a larger NOMA power share. The paper presents this as a qualitative scenario and reports no allocation magnitude or simulation result showing its size.

A weak user can take the opposite approach by overreporting its channel. In the article's description, the attacker receives a smaller NOMA power share while the inflated report supports manipulation of ranking-driven decisions such as scheduling, beam pointing or user pairing. The target, in other words, can be the ranking decision itself rather than a larger power share. No measured rate or scheduling change is reported.

Changing space, training and groups

Other attacks alter spatial CSI rather than its magnitude. Direction forgery, victim-correlated reports and RIS manipulation are described as spatial corruption associated with beam leakage toward the attacker. The article reports no beam-leakage measurement, so it identifies the exposure without estimating its scale.

Some attacks enter during training. Training-phase injection and pilot spoofing are described as corrupting the estimate used for NOMA ordering, allocation, grouping and beamforming. Reactive training jamming is presented as the denial-of-service variant because no usable estimate is obtained.

False reports can also change who shares a resource block. A group-changing attack crosses a pairing or clustering threshold and changes resource-block membership. Coordinated attacks spread bias across users, with aggregate allocation error larger than any individual false report suggests. No threshold, attacker-size or aggregate-error estimate is reported.

The effects can spread across decisions

With biased input, the allocation optimizer is described as locally optimal for the CSI it receives, while the resulting allocation is associated with lower aggregate spectral efficiency than the truthful baseline. The same misallocation is associated with power redirected away from genuinely weak users. That links the attack path to efficiency and fairness concerns, but the paper reports no throughput or fairness effect size.

When the receiver starts to struggle

At the receiver, the article describes a boundary scenario in which the SIC check is satisfied on paper even though the genuine channel gap is at or below a sensitivity floor. The scenario is associated with failed first-stage subtraction and residual interference, alongside sharply rising outage for both users. At the link layer, the symptoms named are block errors, retransmissions and fallback to lower-rate codes. No measured outage or block-error rate is reported.

Some effects may be harder to see. The article associates persistent, low-visibility, order-preserving bias with a fairness-weighted rate distribution shifting toward attackers. When resources reserved for genuine weak users are redirected, it describes degraded quality-of-service guarantees for those users. It reports no persistence threshold or rate distribution, leaving the scale of this effect unmeasured.

A qualitative warning, and an evidence gap

The security concern extends beyond reliability. In the beam-leakage setting, secrecy-rate degradation is associated with an eavesdropper who is also an authenticated user whose feedback the system relies on. The article's framing places that eavesdropper inside the feedback relationship used by the network, rather than treating it only as an outside listener. No secrecy-rate or overhearing measurement is reported.

Those failure paths lead the authors to call for a common false-CSI benchmark. The paper says severity comparisons are difficult when studies use different channel models, attacker objectives, user densities, pairing rules and assumptions about CSI error. Its contribution is a qualitative taxonomy and impact-propagation argument, not a measured estimate of real-world harm or a comparison and validation of defenses. The preprint leaves quantitative evaluation as the next step under clearly specified system assumptions.

Paper data and sources

Original title: False-CSI Attacks in Power-Domain NOMA for 6G: A Threat Taxonomy and System-Level Impacts
Authors: Samira Jafarli, Aysha Ebrahim, Suleyman Uludag
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-28
DOI: Not available
Original paper · Full text

Versions and corrections

  1. Published automatically after legal-source, freshness, evidence, and independent-verification gates passed.