From Inference to Attack: AI-Driven BFI Forgery Against Unknown MU-MIMO Schedulers via TD-MoE

Compressed beamforming feedback information (BFI) reduces feedback overhead in multi-user multiple-input multiple-output (MU-MIMO) systems, but it also exposes the feedback signal that drives user scheduling and precoding. This paper studies whether an external observer can learn an unknown BFI-based scheduler and then use the learned behavior to guide feedback forgery in a protocol-informed physical-layer MU-MIMO simulation. We propose Trajectory Decoding Mixture-of-Experts (TD-MoE), an AI-driven scheduler-inference model that predicts selected user subsets through progressive decoding and latent expert routing, without scheduler-identity labels. We then design a full-feedback BFI forgery method that combines feedback-geometry-guided finite perturbation search with a causal feedback-only attack-or-abstain policy for selecting attack-worthy feedback instances. The attack perturbs scheduler decisions and the feedback-side regularized zero-forcing (regularized-ZF) geometry. In the mixed-five-scheduler inference benchmark, TD-MoE achieves an average intersection over union (IoU) of 0.740 and a Top-1 exact-match accuracy of 0.543, outperforming baselines without trajectory supervision or expert specialization. Under online full-feedback forgery, blind all-attack and random triggering produce limited average degradation, whereas feedback-side selective triggering substantially improves large-drop targeting. In particular, under the default rescheduled full-feedback setting, the learned attack-or-abstain policy achieves an attacked-only mean drop of 22.66%, a median drop of 16.95%, and attack success rates of 58.00% and 47.20% at the 10% and 20% degradation thresholds, denoted by ASR10 and ASR20, respectively, without using true-channel measurements, achieved-rate feedback, future samples, or test-set sorting during online attack selection. These results show that, within this protocol-informed physical-layer simulation setting, BFI-based resource scheduling can be inferred from compressed feedback and that scheduler confidentiality alone does not protect feedback-driven wireless control loops.

Authors

Institutions

Publication Details

Journal
Electronics
Published
2026-09-15
DOI
https://doi.org/10.3390/electronics15184181
Primary Topic
Advanced MIMO Systems Optimization
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

From Inference to Attack: AI-Driven BFI Forgery Against Unknown MU-MIMO Schedulers via TD-MoE

Tao Guo, Ying Wan, Guanxiong Shen, Xiaoyu Zhao et al.
Electronics
Advanced MIMO Systems Optimization
article

From Inference to Attack: AI-Driven BFI Forgery Against Unknown MU-MIMO Schedulers via TD-MoE

Tao Guo, Ying Wan, Guanxiong Shen, Xiaoyu Zhao, Yusheng Chen
article en

Abstract

Compressed beamforming feedback information (BFI) reduces feedback overhead in multi-user multiple-input multiple-output (MU-MIMO) systems, but it also exposes the feedback signal that drives user scheduling and precoding. This paper studies whether an external observer can learn an unknown BFI-based scheduler and then use the learned behavior to guide feedback forgery in a protocol-informed physical-layer MU-MIMO simulation. We propose Trajectory Decoding Mixture-of-Experts (TD-MoE), an AI-driven scheduler-inference model that predicts selected user subsets through progressive decoding and latent expert routing, without scheduler-identity labels. We then design a full-feedback BFI forgery method that combines feedback-geometry-guided finite perturbation search with a causal feedback-only attack-or-abstain policy for selecting attack-worthy feedback instances. The attack perturbs scheduler decisions and the feedback-side regularized zero-forcing (regularized-ZF) geometry. In the mixed-five-scheduler inference benchmark, TD-MoE achieves an average intersection over union (IoU) of 0.740 and a Top-1 exact-match accuracy of 0.543, outperforming baselines without trajectory supervision or expert specialization. Under online full-feedback forgery, blind all-attack and random triggering produce limited average degradation, whereas feedback-side selective triggering substantially improves large-drop targeting. In particular, under the default rescheduled full-feedback setting, the learned attack-or-abstain policy achieves an attacked-only mean drop of 22.66%, a median drop of 16.95%, and attack success rates of 58.00% and 47.20% at the 10% and 20% degradation thresholds, denoted by ASR10 and ASR20, respectively, without using true-channel measurements, achieved-rate feedback, future samples, or test-set sorting during online attack selection. These results show that, within this protocol-informed physical-layer simulation setting, BFI-based resource scheduling can be inferred from compressed feedback and that scheduler confidentiality alone does not protect feedback-driven wireless control loops.

ElectronicsVol. 15(18)
Southeast University (CN)
Peace, Justice and strong institutions
Openalex Percentile: Top 20%
Advanced MIMO Systems Optimization
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.