The RF Device-Fingerprint Tier-0 Gate: An Out-of-Sample Test of Per-Entity Necessity for a Frozen Single-Token Encoder

The RF Device-Fingerprint Tier-0 Gate: An Out-of-Sample Test of Per-Entity Necessity for a Frozen Single-Token Encoder Randolph James Ferlic, M.D. and Kimberly Kate Ferlic — Fieldstone Analytics, LLC, Austin, TX, USA Preprint · Zenodo DOI: 10.5281/zenodo.23021404 · CC-BY 4.0 · Community: spiral-domain-encoder-campaign · a characterization of previously filed and published methods; no new algorithmic subject matter is disclosed. Abstract A companion capstone proposed a predictive theory of a frozen, deterministic, class-discriminant single-token encoder as an always-on Tier-0 sensing layer — four falsifiable laws for where the token wins, pays, and fails — and validated it out-of-sample on a chemical e-nose and, in a follow-on, on RF modulation classification. Both tests exercised three of the four laws but left one untestable: L2, per-entity necessity — that a label-free per-entity "self-twin" is needed if and only if the decision is entity-specific — because neither corpus carries a device identity. We supply that test here on RF device fingerprinting, the canonical non-biological entity-specific signal: a radio's identity is carried by involuntary hardware impairments (carrier-frequency offset, I/Q gain and phase imbalance, DC/oscillator leakage, power-amplifier nonlinearity). Using the same frozen encoder and a fixed 128-dimensional no-learned-parameters front-end, on the public WiSig corpus (150 Wi-Fi transmitters, 4 receivers, 4 capture days) we register and confirm six predictions. L2 holds decisively: a per-device self-twin verifies its own radio at area-under-curve (AUC) 0.986 while a different-device or population twin cannot (0.53 / 0.43), an own-minus-cross gap of +0.46 that survives a permutation null (collapse to 0.50) and a bootstrap interval excluding zero [0.443, 0.554] — the sharpest own-versus-cross separation in the program, and the direct opposite of the universal-extreme pole (a fall, where a population twin suffices). Device classification is in the token's competence zone (near-parity at few devices; a small cardinality-scaling tax, +0.05 at 139 devices, against a strong RandomForest baseline — a boosted-tree baseline instead underfits the many-class task, a comparison we report as an honest methodological caveat). The fingerprint does not transfer across receiver or day and must be re-commissioned (L3), the gate is deterministic and int8-free (L4), and a pooled self-twin flags an unenrolled rogue device at AUC 0.95. We then harden the result along every axis a skeptic would press. A cross-session test resolves the device-versus-session confound: own-versus-cross persists across a three-week day gap (+0.16) — the signature is device hardware, not a same-recording artifact — while collapsing across receivers, so enrollment is per-receiver; same-session authentication reaches a 2.3% equal-error-rate. A mechanism ablation shows device identity is distributed and redundant (dropping any single impairment barely moves accuracy) and is not reducible to a trivial carrier-frequency count (a single offset scalar verifies at 0.93 but classifies 150 devices at only 0.53). Commissioning is cheap (2 windows → AUC 0.92); the codebook self-twin matches Mahalanobis and 1-nearest-neighbor at bounded cost; a raw-IQ convolutional network trails only by +0.01–0.03; and, on an emulated impersonation corpus, the self-twin flags a protocol-level spoofer at AUC 0.90. The result replicates on a second, fully independent corpus (INRIA, 12 IoT radios, a different lab, receiver, and modality: own 0.84 ≫ cross 0.47). Per-entity necessity is thereby established across the full entity spectrum — universal-extreme (not necessary), biological (necessary), and now non-biological electromagnetic hardware (necessary) — completing the fourth law and closing the predictive theory. This is a characterization of previously described, filed methods; it discloses no new algorithmic subject matter, and the per-deployment / per-receiver selection of configuration is retained as trade secret. Highlights · Per-entity necessity (L2) holds decisively — a device's own self-twin verifies it at AUC 0.986 while a different-device (0.53) or pooled-population (0.43) twin cannot; the sharpest own-versus-cross separation in the program, and the opposite of the universal-extreme pole (a fall: own ≈ cross). · Permutation-controlled and bootstrapped — shuffling device labels collapses verification to 0.50; the own-minus-cross gap is +0.498 with a 95% interval [0.443, 0.554], positive in 100% of resamples. · The device-versus-session confound, resolved — own ≫ cross persists across a three-week day gap (device hardware, not a recording artifact) but collapses across receivers (receiver-bound → enroll per receiver); same-session authentication equal-error-rate 2.3%. · Distributed identity, not a trivial CFO count — dropping any single impairment barely moves accuracy; a single carrier-frequency scalar verifies (0.93) but cannot identify 150 devices (0.53) — the full vector is needed. · Exhaustively hardened — cheap commissioning (2–8 windows), a codebook self-twin that ties Mahalanobis/1-NN at bounded cost, a raw-IQ deep-network reference within +0.01–0.03, and a protocol-level spoofer flagged at AUC 0.90 (bounded probe). · Replicated on a second independent corpus (INRIA, 12 IoT radios) — the L2 law is not a WiSig artifact — completing the fourth law across the full spectrum of entity types. What this record contains · Manuscript_Paper55.pdf — the RF device-fingerprint test (6 figures, 40 references); and Manuscript_Paper55.docx, the editable source. · PAPER_55_ZENODO_ARCHIVE.zip — the reproducibility archive (md5 in ARCHIVE_MD5.txt): the frozen pre-registration (RFFP_PREREG.md, six predictions frozen before any device-fingerprint data was inspected); the WiSig and INRIA fetch/featurize (Modal + local), the fixed 128-dim device-fingerprint front-end (feats_rffp.py), the core boundary/verification runner, the strengthening runners (baseline panel, permutation, bootstrap, capacity), the tier-3 cross-session/EER runner, the tier-4 mechanism/sample-efficiency/monitor runner, the INRIA replication runner, the spoofing runner, the raw-IQ CNN trainer, the frozen token encoder module; the result records (JSON); the 6 figures; the figure builder; the manuscript source; and a README. Public data is not redistributed (fetched at run time); all paths and handles are scrubbed (PATH_TO_DATA/PATH_TO_SCRATCH, any cloud handle → MODAL_USER) and leak-scanned. Cite as R. J. Ferlic and K. K. Ferlic, "The RF device-fingerprint Tier-0 gate: an out-of-sample test of per-entity necessity for a frozen single-token encoder," Zenodo, 2026, doi: 10.5281/zenodo.23021404. License and patent notice Released under CC-BY 4.0. Consistent with that license, no patent or other intellectual-property right of the authors is licensed, waived, or conveyed by this deposit. This work characterizes previously described, filed, or published methods and discloses no new algorithmic subject matter; gradient boosting, random forests, k-means / vector quantization, Fisher discriminant analysis, the information bottleneck, higher-order-cumulant impairment features, nearest-centroid and Mahalanobis novelty detection, and convolutional networks are established prior art, used only as tools. The methods characterized — the class-discriminant single-token codebook encoder and its nearest-centroid monitor, the per-entity self-twin, the multi-token / token-ladder and soft-readout mechanisms, the inference-time co-channel fusion, and the foundation codebook — are the subject of filed and pending U.S. patent applications held by the authors, including U.S. Provisional Application No. 64/095,354 (the encoder), the personalization / on-device-adaptation applications (priority U.S. Application No. 19/467,303 and its continuations, which include the per-entity self-twin), the multi-token / token-ladder application (No. 64/119,487), and the inference-time fusion application (No. 64/137,805). The per-entity-necessity, competence-zone, re-commission, capacity, and cost results reported here are properties of the frozen filed method, not new subject matter; the two-tier escalation is established cascade / early-exit inference combined with the filed gate. The per-deployment / per-receiver selection of configuration and commissioning procedure is retained as a trade secret and is not disclosed here. RF device fingerprinting concerns transmitter identity; the capability is characterized for authentication and rogue-device detection, and its dual-use tracking implication is noted, consistent with the program's de-identification and unlinkability characterizations and template-protection practice (ISO/IEC 24745). © 2026 Fieldstone Analytics, LLC and the authors. Inquiries: [email protected]. Companion deposits (spiral-domain-encoder-campaign) · The Frozen Token — the predictive-theory capstone whose fourth law (per-entity necessity) this paper tests: doi:10.5281/zenodo.23002239 · The Constellation Boundary — the RF modulation out-of-sample test this paper follows: doi:10.5281/zenodo.23003249 · The Wrist-PPG Tier-0 Gate — the biological entity-specific pole (per-entity necessary): doi:10.5281/zenodo.23000837 · The mmWave Micro-Doppler Tier-0 Gate — the universal-extreme pole (per-entity not necessary): doi:10.5281/zenodo.22999908 · The Cheapest Digital Twin — the per-entity self-twin the L2 result rests on: doi:10.5281/zenodo.22922678 · The Acoustic Tier-0 Gate — machine-health entity-specific self-twin: doi:10.5281/zenodo.22968134 · The privacy characterizations — non-invertibility and unlinkability: doi:10.5281/zenodo.22819210 and doi:10.5281/zenodo.22838120 Keywords RF fingerprinting; device fingerprinting; physical-layer authentication; specific emitter identification; hardwa

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-28
DOI
https://doi.org/10.5281/zenodo.23021403
Primary Topic
Wireless Signal Modulation Classification
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

The RF Device-Fingerprint Tier-0 Gate: An Out-of-Sample Test of Per-Entity Necessity for a Frozen Single-Token Encoder

Randolph James Ferlic, Kimberly Kate Ferlic
Zenodo (CERN European Organization for Nuclear Research)
Wireless Signal Modulation Classification
preprint

The RF Device-Fingerprint Tier-0 Gate: An Out-of-Sample Test of Per-Entity Necessity for a Frozen Single-Token Encoder

Randolph James Ferlic, Kimberly Kate Ferlic
preprint en

Abstract

The RF Device-Fingerprint Tier-0 Gate: An Out-of-Sample Test of Per-Entity Necessity for a Frozen Single-Token Encoder Randolph James Ferlic, M.D. and Kimberly Kate Ferlic — Fieldstone Analytics, LLC, Austin, TX, USA Preprint · Zenodo DOI: 10.5281/zenodo.23021404 · CC-BY 4.0 · Community: spiral-domain-encoder-campaign · a characterization of previously filed and published methods; no new algorithmic subject matter is disclosed. Abstract A companion capstone proposed a predictive theory of a frozen, deterministic, class-discriminant single-token encoder as an always-on Tier-0 sensing layer — four falsifiable laws for where the token wins, pays, and fails — and validated it out-of-sample on a chemical e-nose and, in a follow-on, on RF modulation classification. Both tests exercised three of the four laws but left one untestable: L2, per-entity necessity — that a label-free per-entity "self-twin" is needed if and only if the decision is entity-specific — because neither corpus carries a device identity. We supply that test here on RF device fingerprinting, the canonical non-biological entity-specific signal: a radio's identity is carried by involuntary hardware impairments (carrier-frequency offset, I/Q gain and phase imbalance, DC/oscillator leakage, power-amplifier nonlinearity). Using the same frozen encoder and a fixed 128-dimensional no-learned-parameters front-end, on the public WiSig corpus (150 Wi-Fi transmitters, 4 receivers, 4 capture days) we register and confirm six predictions. L2 holds decisively: a per-device self-twin verifies its own radio at area-under-curve (AUC) 0.986 while a different-device or population twin cannot (0.53 / 0.43), an own-minus-cross gap of +0.46 that survives a permutation null (collapse to 0.50) and a bootstrap interval excluding zero [0.443, 0.554] — the sharpest own-versus-cross separation in the program, and the direct opposite of the universal-extreme pole (a fall, where a population twin suffices). Device classification is in the token's competence zone (near-parity at few devices; a small cardinality-scaling tax, +0.05 at 139 devices, against a strong RandomForest baseline — a boosted-tree baseline instead underfits the many-class task, a comparison we report as an honest methodological caveat). The fingerprint does not transfer across receiver or day and must be re-commissioned (L3), the gate is deterministic and int8-free (L4), and a pooled self-twin flags an unenrolled rogue device at AUC 0.95. We then harden the result along every axis a skeptic would press. A cross-session test resolves the device-versus-session confound: own-versus-cross persists across a three-week day gap (+0.16) — the signature is device hardware, not a same-recording artifact — while collapsing across receivers, so enrollment is per-receiver; same-session authentication reaches a 2.3% equal-error-rate. A mechanism ablation shows device identity is distributed and redundant (dropping any single impairment barely moves accuracy) and is not reducible to a trivial carrier-frequency count (a single offset scalar verifies at 0.93 but classifies 150 devices at only 0.53). Commissioning is cheap (2 windows → AUC 0.92); the codebook self-twin matches Mahalanobis and 1-nearest-neighbor at bounded cost; a raw-IQ convolutional network trails only by +0.01–0.03; and, on an emulated impersonation corpus, the self-twin flags a protocol-level spoofer at AUC 0.90. The result replicates on a second, fully independent corpus (INRIA, 12 IoT radios, a different lab, receiver, and modality: own 0.84 ≫ cross 0.47). Per-entity necessity is thereby established across the full entity spectrum — universal-extreme (not necessary), biological (necessary), and now non-biological electromagnetic hardware (necessary) — completing the fourth law and closing the predictive theory. This is a characterization of previously described, filed methods; it discloses no new algorithmic subject matter, and the per-deployment / per-receiver selection of configuration is retained as trade secret. Highlights · Per-entity necessity (L2) holds decisively — a device's own self-twin verifies it at AUC 0.986 while a different-device (0.53) or pooled-population (0.43) twin cannot; the sharpest own-versus-cross separation in the program, and the opposite of the universal-extreme pole (a fall: own ≈ cross). · Permutation-controlled and bootstrapped — shuffling device labels collapses verification to 0.50; the own-minus-cross gap is +0.498 with a 95% interval [0.443, 0.554], positive in 100% of resamples. · The device-versus-session confound, resolved — own ≫ cross persists across a three-week day gap (device hardware, not a recording artifact) but collapses across receivers (receiver-bound → enroll per receiver); same-session authentication equal-error-rate 2.3%. · Distributed identity, not a trivial CFO count — dropping any single impairment barely moves accuracy; a single carrier-frequency scalar verifies (0.93) but cannot identify 150 devices (0.53) — the full vector is needed. · Exhaustively hardened — cheap commissioning (2–8 windows), a codebook self-twin that ties Mahalanobis/1-NN at bounded cost, a raw-IQ deep-network reference within +0.01–0.03, and a protocol-level spoofer flagged at AUC 0.90 (bounded probe). · Replicated on a second independent corpus (INRIA, 12 IoT radios) — the L2 law is not a WiSig artifact — completing the fourth law across the full spectrum of entity types. What this record contains · Manuscript_Paper55.pdf — the RF device-fingerprint test (6 figures, 40 references); and Manuscript_Paper55.docx, the editable source. · PAPER_55_ZENODO_ARCHIVE.zip — the reproducibility archive (md5 in ARCHIVE_MD5.txt): the frozen pre-registration (RFFP_PREREG.md, six predictions frozen before any device-fingerprint data was inspected); the WiSig and INRIA fetch/featurize (Modal + local), the fixed 128-dim device-fingerprint front-end (feats_rffp.py), the core boundary/verification runner, the strengthening runners (baseline panel, permutation, bootstrap, capacity), the tier-3 cross-session/EER runner, the tier-4 mechanism/sample-efficiency/monitor runner, the INRIA replication runner, the spoofing runner, the raw-IQ CNN trainer, the frozen token encoder module; the result records (JSON); the 6 figures; the figure builder; the manuscript source; and a README. Public data is not redistributed (fetched at run time); all paths and handles are scrubbed (PATH_TO_DATA/PATH_TO_SCRATCH, any cloud handle → MODAL_USER) and leak-scanned. Cite as R. J. Ferlic and K. K. Ferlic, "The RF device-fingerprint Tier-0 gate: an out-of-sample test of per-entity necessity for a frozen single-token encoder," Zenodo, 2026, doi: 10.5281/zenodo.23021404. License and patent notice Released under CC-BY 4.0. Consistent with that license, no patent or other intellectual-property right of the authors is licensed, waived, or conveyed by this deposit. This work characterizes previously described, filed, or published methods and discloses no new algorithmic subject matter; gradient boosting, random forests, k-means / vector quantization, Fisher discriminant analysis, the information bottleneck, higher-order-cumulant impairment features, nearest-centroid and Mahalanobis novelty detection, and convolutional networks are established prior art, used only as tools. The methods characterized — the class-discriminant single-token codebook encoder and its nearest-centroid monitor, the per-entity self-twin, the multi-token / token-ladder and soft-readout mechanisms, the inference-time co-channel fusion, and the foundation codebook — are the subject of filed and pending U.S. patent applications held by the authors, including U.S. Provisional Application No. 64/095,354 (the encoder), the personalization / on-device-adaptation applications (priority U.S. Application No. 19/467,303 and its continuations, which include the per-entity self-twin), the multi-token / token-ladder application (No. 64/119,487), and the inference-time fusion application (No. 64/137,805). The per-entity-necessity, competence-zone, re-commission, capacity, and cost results reported here are properties of the frozen filed method, not new subject matter; the two-tier escalation is established cascade / early-exit inference combined with the filed gate. The per-deployment / per-receiver selection of configuration and commissioning procedure is retained as a trade secret and is not disclosed here. RF device fingerprinting concerns transmitter identity; the capability is characterized for authentication and rogue-device detection, and its dual-use tracking implication is noted, consistent with the program's de-identification and unlinkability characterizations and template-protection practice (ISO/IEC 24745). © 2026 Fieldstone Analytics, LLC and the authors. Inquiries: [email protected]. Companion deposits (spiral-domain-encoder-campaign) · The Frozen Token — the predictive-theory capstone whose fourth law (per-entity necessity) this paper tests: doi:10.5281/zenodo.23002239 · The Constellation Boundary — the RF modulation out-of-sample test this paper follows: doi:10.5281/zenodo.23003249 · The Wrist-PPG Tier-0 Gate — the biological entity-specific pole (per-entity necessary): doi:10.5281/zenodo.23000837 · The mmWave Micro-Doppler Tier-0 Gate — the universal-extreme pole (per-entity not necessary): doi:10.5281/zenodo.22999908 · The Cheapest Digital Twin — the per-entity self-twin the L2 result rests on: doi:10.5281/zenodo.22922678 · The Acoustic Tier-0 Gate — machine-health entity-specific self-twin: doi:10.5281/zenodo.22968134 · The privacy characterizations — non-invertibility and unlinkability: doi:10.5281/zenodo.22819210 and doi:10.5281/zenodo.22838120 Keywords RF fingerprinting; device fingerprinting; physical-layer authentication; specific emitter identification; hardwa

Zenodo (CERN European Organization for Nuclear Research)
Reduced inequalities
Wireless Signal Modulation Classification
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.