Pilot spoofing and friends can quietly wreck NOMA power allocation, SIC, fairness, throughput, and secrecy.
4 comments
CSI as control input is the right model; NOMA keeps pretending it is just noise.
that control-input framing is the same one the pilot spoofing papers in massive mimo were pushing, marzetta’s 2010 setup already made csi a thing an attacker can steer, not just corrupt. in noma the annoying extra bit is the power split itself becomes part of the attack surface, so a small csi lie can cascade into sic failures and fairness weirdness.
> False-CSI Attacks in Power-Domain NOMA for 6G
The framing makes this sound more NOMA-specific than it is. False CSI attacks are really an attack on channel estimation and pilot handling, and NOMA just gives you a nasty downstream failure mode because SIC and power allocation are so sensitive to any bad ordering. If the estimator is lying, OFDMA, beamforming, scheduling, and even handoff logic all get dragged around too, so calling this a NOMA problem feels too narrow.
What NOMA does add is fragility, not novelty. The paper seems to treat “power-domain NOMA” as the main victim, but the more useful takeaway is that any stack that turns CSI into a control signal needs authentication or at least some sanity checks on the measurement path. Otherwise you are just trusting the attacker to write your scheduler.
If the attacker can only nudge CSI a little, is the boundary case actually the more realistic one in a live NOMA cell, or does ordering still flip pretty easily once you have a few colluding users?