Next Article in Journal
From Simulation to Semi-Physical Validation: An Intelligent Jammer-Assisted Radar Anti-Jamming Evolution Method
Previous Article in Journal
Smart Sensor Based on Multiple Cascaded Michelson Interferometers with a Long-Period Fiber Grating for Recognition of Paracetamol Concentrations in Solutions
Previous Article in Special Issue
Self-Evolving Multi-Agent Fuzzing for Industrial IoT with Knowledge-Driven Cognitive Reasoning
 
 
Article
Peer-Review Record

Game-Theoretic Obfuscation of Wi-Fi MAC-Layer Traffic Against IoT Device Fingerprinting Attacks

Sensors 2026, 26(15), 4690; https://doi.org/10.3390/s26154690
by Abdulmajeed Alghamdi 1,2, Mnassar Alyami 3, Inad Alqurashi 4 and Cliff C. Zou 5,*
Reviewer 1: Anonymous
Reviewer 2: Anonymous
Sensors 2026, 26(15), 4690; https://doi.org/10.3390/s26154690
Submission received: 27 May 2026 / Revised: 13 July 2026 / Accepted: 20 July 2026 / Published: 23 July 2026
(This article belongs to the Special Issue Cybersecurity and Trustworthiness in IoT Devices)

Round 1

Reviewer 1 Report

Comments and Suggestions for Authors

I have the following comments for improvements: 

- The manuscript is longer than necessary for the presented contribution. At approximately 45 pages, many sections contain redundant explanations, repeated justifications.

- The manuscript repeatedly emphasizes Nash equilibrium guarantees and optimal defender strategies. However, these guarantees hold only within the finite set of evaluated classifiers and obfuscation configurations.


- The paper acknowledges that the primary cost of the defense is bandwidth overhead, particularly for donor-based injection which operates at approximately 100% overhead. However, the impact of this additional traffic on network performance is not investegated. 


- The experimental evaluation is conducted using only four IoT devices within a single residential Wi-Fi environment.


Author Response

Please see the attachment.

Author Response File: Author Response.pdf

Reviewer 2 Report

Comments and Suggestions for Authors

The paper presents an interesting and original idea for defending against IoT device fingerprinting by using donor-based mimicry rather than purely synthetic cover traffic. The key insight that realistic traffic patterns from paired IoT devices can provide stronger obfuscation than artificial dummy traffic is valuable and worth further investigation.

However, I have two major concerns that should be addressed before publication.

First, although the paper evaluates several machine-learning classifiers, the attacker model is still limited because it mainly considers pairing-unaware classifiers. The proposed donor mimicry method appears to create confusion between paired devices. Therefore, a pairing-aware attacker who knows or can infer the donor relationship may be able to reverse or reduce this confusion. The paper should evaluate such an adaptive attacker model or, at minimum, discuss more clearly how robust the proposed defense is when the device pairing is known.

Second, the proposed method depends heavily on the availability of behaviorally similar donor pairs. In realistic smart-home environments, some IoT devices may not have a suitable paired device with similar traffic characteristics. The paper should explain how the defense would operate for devices that cannot be paired effectively, or provide a strategy for donor selection when no natural pair exists.

Overall, the paper has a creative and promising core idea, but the current evaluation does not fully demonstrate robustness against pairing-aware attackers or scalability to devices without suitable donor pairs. I recommend substantial revision to address these issues.

Author Response

Please see the attachment.

Author Response File: Author Response.pdf

Round 2

Reviewer 1 Report

Comments and Suggestions for Authors

the authors addressed my concerns.

Back to TopTop