4.2. Design Parameters
Table 5 lists the eight design knobs and their default values used throughout this paper, and
Figure 3 illustrates each parameter on the P5 time–frequency plane. The band separation
is required by the orthogonality region
(
Section 4.3); the CAZAC length
N balances processing-gain contribution to D5 against chip duration
; and the root
r seeds the per-cell CAZAC codebook that serves R2.
The eight knobs fall into three functional groups: spectrum allocation
, time-domain structure
, and energy balance
. The HFM band sets Doppler-invariant timing (R1, Proposition 2), the LFM band sets range resolution
(R4, Proposition 3), and the inter-band gap
governs the orthogonality bound
(
dB idealized;
dB realized with chip leakage,
Section 3.2). The duration
T linearly trades LPI gain
against the channel coherence ceiling
s of the M2 submarine-UUV scenario. The CAZAC length
N sets the despreading advantage over a root-blind attacker (∼
, i.e., ∼24 dB at
and ∼27 dB at
) and is the strongest PSL lever (∼2–3 dB drop per doubling), while smaller
keeps chip duration
above 780 μs (a lower chip rate) for M4. The root
r (with
) selects one of
sequences for
, serving simultaneously as cell-ID and as a randomized parameter that prevents single-realization template memorization by classical feature detectors; a CNN trained on the randomized family, however, still recognizes the underlying chirp structure (
Section 4.6). The power split
is a continuous mission knob (
favors R1 timing;
favors R4 ranging), with
identified as the PSL optimum (
Section 5.3). The orthogonality region
of (
2) requires monotone
,
kHz,
,
, and
; all mission configurations of
Section 5.7 lie strictly inside
.
4.3. 2D Wideband Ambiguity Function
Because the CAZAC envelope is
multiplicative, the transmitted signal is the two-component sum
, and its WBAF expands into
four terms,
where the ZC-weighted cross-ambiguity functions are
with ZC kernel
and
. The two cross terms are retained separately because
in general (the delay/scale arguments of the two orderings differ), so the wideband cross-ambiguity is
not simply
; Proposition 1 bounds each ordering and, hence, their sum. The envelope-vs.-chirp cross-ambiguities
are
not additive terms of (
4) (the CAZAC factor enters every term through the common kernel
); they are functional-separation diagnostics, measured in
Section 3.2 to confirm that the CAZAC spreading does not reshape the chirp ridges.
Proposition 1 (Orthogonality of layers, smooth-envelope idealization)
. Under parameter conditions (including the Doppler-dependent gap condition ), the additive cross-term magnitudes of obey with and identically for by the same non-stationary-phase argument over the disjoint HFM/LFM supports. The left-hand expression is the rigorous smooth-envelope
constant derived in Supplementary S1; the right-hand form is the leading-order estimate (, ) quoted for intuition. Both describe the smooth-envelope idealization; the realized chip-modulated value is governed by the chip-leakage correction of Supplementary S1.4, and the envelope-vs.-chirp diagnostics are bounded separately in Supplementary S1.5. Proposition 2 (Doppler-invariance preservation, ideal HFM phase)
. For the HFM phase in (3), there exist and , with and , such that so a wideband Doppler scaling of the ideal
hyperbolic phase is absorbed exactly into a time shift plus the constant phase on . The identity is exact only for the unmodulated, infinite-support HFM phase; for the actual P5 waveform (finite support, the multiplicative CAZAC grid rescaled to , and the additive LFM component) the near-invariance of the HFM ridge is the numerical observation of Section 5.10 (Supplementary S2), not a corollary of (7) alone. Proposition 3 (Range Resolution). The LFM auto-term has a Rayleigh-like delay resolution (first-null width) where , corresponding, under the two-way (monostatic) underwater-acoustic propagation relation , to a two-target range resolution . The corresponding dB full mainlobe width for a rectangular-spectrum approximation is (about 11% narrower than the first-null width).
For the default parameters in
Table 5, three distinct figures must be kept separate (they are not one theorem evaluated three ways): the
leading-order smooth-envelope estimate
gives
dB; the
rigorous smooth-envelope constant derived in
Supplementary S1 (which retains the
prefactor and the
Doppler correction) tightens to
dB; and the
realized cross-term of the actual chip-modulated envelope is
dB (
Section 3.2), which is the operative value used in all orthogonality statements. The 8 dB gap between the first two is the dropped prefactor/correction, not an
ambiguity. Proposition 3 gives
cm as a
conservative, bandwidth-only (Rayleigh-like) reference; the realized ZC-weighted LFM branch is actually finer, and the operational two-target resolution is coarser (≈
m, sidelobe-limited), as measured in
Section 5.6. This
is in any case distinct from the
single-target precision reported in
Table 6:
is a two-target resolution scale set by
, whereas
is the single-target ranging precision measured by matched-filter Monte Carlo; R4a/R4b are verified against the empirical
of
Table 6, not inferred from
. The associated LFM delay–Doppler ambiguity retains the shallow-water behavior analyzed in [
33]. The full delay–Doppler cross-ambiguity peaks for the actual envelope-modulated layers are
dB (HFM-LFM),
dB (HFM-ZC), and
dB (LFM-ZC), all at least 12 dB below the
dB orthogonality threshold, confirming the three-layer decomposition while reflecting the chip-leakage correction to the idealized bound (
Section 3.2). Detailed proofs of Propositions 1–3 are provided in the
Supplementary Materials.
4.5. Bandwidth-Scaling Reference (CRLB-Style)
We do
not claim a tight Cramér–Rao bound [
34,
35] for the realized estimator; the expressions below are a
bandwidth-scaling reference that predicts how the empirical timing/Doppler/range RMSE
scales with bandwidth, SNR, and observation time, used only to interpret the Monte Carlo trends. For
and observation window
T, the CRLB-style scaling relations are
where
is the central-moment (unknown-phase, baseband) RMS bandwidth of the full preamble and
that of the LFM layer only. We fix the
unknown-phase convention throughout (the complex amplitude and its phase are nuisance parameters), so the central second moment of (
9) is the consistent choice. Because this central
underestimates the bandwidth the matched filter actually exploits, (
8) is
looser than the empirical RMSE—a scaling reference, not a numerical lower bound; the diagnostic
back-solved from the timing RMSE is the operative bandwidth, and the numerical FIM of
Supplementary S4 reconciles these bounds with the data: the Doppler-compensated receiver
searches (it does not know
), and the empirical RMSE is bracketed by the phase-coherent and joint-search CRLBs derived there.
Transmit-energy convention. The default-
T rows of
Table 6 assume unit transmit energy at
ms; the extended-
T row (
ms) assumes fixed transmit power, so that
and the CRLB improves as
. Under a strict fixed-energy constraint, the extended-
T gain would be zero.
Under Proposition 1,
separates cleanly between HFM and LFM contributions. Concretely, the central second moment
is taken around the spectral mean
on the
baseband-shifted spectrum so that absolute carrier offsets do not inflate
. For the disjoint-band P5 composite, this gives
where
,
. The third term captures the inter-band spectral separation between HFM and LFM allocations; it vanishes when the two bands coincide and is the dominant contribution at the default parameters. The numerical
values in
Table 6 are computed from matched-filter Monte Carlo and are independent of the bandwidth-convention choice.
Table 6 reports simulation-based matched-filter RMSEs for P3, P4, and P5 at
dB with default parameters, together with R4a/R4b target verification against
Table 1. The entries are empirical RMSEs from
Monte Carlo trials, not closed-form CRLB evaluations; their scaling is consistent with the CRLB trend (
8) and (
9) (wider effective bandwidth ⇒ lower timing and range RMSE). The diagnostic
is back-solved from the timing RMSE via
and is not a physical RMS bandwidth. Columns P5
def and P5
opt denote the default set
and the PSL-optimal set
of
Section 5.3.
P5 inherits the Doppler invariance of the HFM layer (Proposition 2); the LFM layer provides the ranging response (Proposition 3), while the CAZAC envelope contributes processing gain on top. Among the candidates evaluated here, P5 is the only waveform that combines all three properties simultaneously. Single-target range
precision, however, is not among the distinguishing properties. Re-verifying every waveform through the Qarabaqi–Stojanovic fine-multipath channel (
exp_sigmaR_reverify.m) shows that at 10 dB, the matched-filter range error is multipath-limited (
m) and statistically indistinguishable across the wideband chirp candidates (
Section 5.9); the AWGN-only jitter floor is sub-millimeter, so
is governed by the channel, not by waveform bandwidth. Under the
default parameter set
, P5
def meets R4a (
m vs. target
m)—as do all wideband chirp candidates—with an ≈
margin that is channel-sensitive: in denser multipath,
rises toward
m, while in benign short-range geometry, it falls to ≲
m.
R4b ( m) follows the same channel-conditioning. Because the range error is multipath-limited and SNR-independent, R4b is not reachable by raising SNR or extending T in dense multipath; it is met in the benign short-range (well-separated-arrival) geometry that defines the mission-critical R4b regime—M4 mine-ISAC and short-range AUV docking (quasi-static)—and does so uniformly across the wideband chirp candidates rather than as a P5-specific property. For M2 submarine-UUV, where s, a 200 ms preamble would violate the piecewise-stationary assumption underlying Proposition 2, so the extended-duration option is not admissible there; the short-range benign-geometry route remains the operative one.
The
PSL-optimal parameter set
, identified in
Section 5.3 by Pareto search, leaves range precision unchanged (
m, the same multipath-limited floor) and instead delivers a substantial
dB improvement in composite PSL (
vs.
dB). Throughout the remainder of this paper, we report both configurations: P5
def in theoretical and Doppler/timing-focused analyses where the balanced chirp allocation is the physically interpretable choice and P5
opt wherever sidelobe structure is the governing performance indicator (e.g., mission reconfigurability
Section 5.7 and LPI sweeps
Section 5.8). The full bandwidth-scaling (CRLB-style) derivation and its channel sensitivity are provided in the
Supplementary Materials.
4.6. LPI Processing Gain and Six-Attacker Analysis
A coherent matched filter that knows the transmitted P5 waveform integrates its energy over the time–bandwidth product of the two disjoint chirp bands, giving a cooperative processing gain of order
which evaluates to ≈31 dB at the default
ms,
kHz, and
kHz. The CAZAC envelope is part of the
known transmitted signal and therefore adds no separable
term on top of this chirp integration gain: writing
as a sum of two per-layer time–bandwidth gains
and an independent sequence-length gain would double-count the fixed total signal energy, so we do not use that decomposition. This
is the
factor relating the per-sample input SNR to the cooperative
output decision statistic (
Section 5.1),
not a gain added on top of the total-energy input SNR
. The operative LPI comparison is not this absolute gain but the attacker-input SNR required to reach a fixed
, reported per attacker in
Section 5.8; a first-principles re-derivation of each detector’s deflection coefficient/likelihood noncentrality is left to future work. We evaluate P5 against six non-cooperative attacker models spanning the known UWA LPD and covert-waveform threat space [
36,
37,
38]: the energy detector (ED) [
8]; the four hand-crafted
structure-aware detectors—cyclic feature (CFD) [
9], cyclic spectrum (CS), cepstrum (CEP), and square frequency-doubling (SFDM) [
10]—which target cyclostationary, periodic, or carrier-related structure that the CAZAC envelope scrambles; and a blind CNN-based ML classifier [
11] that recognizes the chirp time–frequency signature directly (analyzed separately,
Figure 4; a stronger 2-D spectrogram ResNet-18 variant of this learned-attacker class, added in revision, is analyzed alongside it and in
Supplementary S5.14).
Under Proposition 1 orthogonality and the chirp time-varying carrier, the attacker-input SNR each
classical structure-aware attacker requires to reach its
crossing against P5 is summarized in
Table 7. Among the four classical structure-aware attackers (excluding ED, which is structure-agnostic), the CS detector is the strongest—it reaches
at the lowest attacker-input SNR—yet still requires ≈
dB, far above the 0 dB D5 operating point, consistent with the chirp time-varying carrier and the CAZAC envelope’s periodicity scrambling, keeping hand-crafted feature extractors well above the cooperative operating point. Because the CAZAC-free baselines (B1, B5) also evade these detectors at 0 dB, the CAZAC-specific contribution is small: the no-CAZAC ablation of
Section 5.8 (
Supplementary Figure S3) isolates it at only
dB of worst-case breach SNR. These breach SNRs are convention-free attacker-input quantities (the operative LPI metric of
Section 5.8), not output-SNR conversions.
The attacker-input SNR margin of P5 at against the worst-case classical attacker (CS) is ≈ dB over B5 and dB over B1. The B5 margin lies within the statistical resolution of the sweep, so against the strongest classical attacker, P5 is best read as at least as resistant as any baseline, with a clear edge only over the single-HFM reference (B1).
As reported in
Section 5.8, P5
satisfies the strict D5 target (
) at 0 dB
for all four classical structure-aware attackers (CFD, CS, CEP, SFDM). The chirp time-varying carrier and the CAZAC phase coding together keep these hand-crafted feature extractors below the strict target; however, the CAZAC-free baselines pass at 0 dB as well, so this experiment does not isolate the CAZAC-specific contribution (the no-CAZAC ablation of
Section 5.8 isolates it at
dB).
Trained-CNN attacker: To characterize a learned adversary, we trained a compact 1-D CNN blind attacker (≈25.8 k parameters; full architecture and training in the toolbox) on the raw, energy-normalized I/Q window—so it must use time–frequency structure, not absolute energy. Every H1 realization of the -example set draws parameter-randomized P5 tuples over dB (per-sample; dB), so the network cannot memorize a single realization; the threshold is CFAR-calibrated at (, ), identical to the classical-attacker protocol. Removing the radiometric cue forces the CNN onto structure; a stronger hybrid attacker combining an energy detector with the learned features would be at least as capable and is left to future work.
As shown in
Figure 4, on the common
axis, the trained CNN outperforms every hand-crafted detector but is not effective at the strict operating point: its
crossing against P5 is at
dB
(strict
below
dB), so at the 0 dB operating point, it leaves P5 undetected (
) alongside the classical detectors and reaches
only above ≈
dB. Its breach SNR is thus only ≈3 dB below the strongest hand-crafted detector (CS,
dB) and ≈13 dB above the full-knowledge oracle (
dB): the learned attacker narrows, but does not close, the blind-detection gap. Both crossings lie below the
dB
training range (
dB), so these threshold-SNR values are extrapolations and are indicative rather than calibrated. The result is unchanged under a realistic blind observation model (random arrival time, Qarabaqi–Stojanovic multipath,
m/s Doppler), within
dB of the matched case. The mechanism is simple: the HFM and LFM layers carry a time–frequency energy ramp with time–bandwidth product
(≈29 dB of coherent gain), which a CNN learns to integrate; the CAZAC envelope is a phase modulation that scrambles
periodicity-based features but does not hide this broadband ramp. To confirm that this is a class-wide rather than a P5-specific weakness, we trained a
separate CNN per waveform (B1–B5, P1–P5) under one protocol, with training and evaluation extended down to
dB
, over
twelve training seeds. The full rerun fixes the Python 3.12.3, NumPy 1.26.4, PyTorch 2.6.0, and CUDA 12.4 seeds for each training seed. Restricting to runs in which training converged (8–12 of 12 per waveform), the conditional mean
crossings span
dB (
to
dB
; per-waveform means, standard deviations,
confidence intervals, and convergence rates in
Supplementary Table S3). P5 has the
highest conditional mean crossing (
dB; SD
dB; 95% CI
dB;
converged), but its interval overlaps those of several candidates, so the run does not resolve its rank. The learned attacker nevertheless reaches a crossing for every waveform family at comparable attacker-input SNR. Individual waveform–seed runs that do not reach
by
dB are counted as nonconverged and excluded from the conditional means; the intervals therefore quantify run-to-run variation among converged fits and do not account for this right-censoring. The class-wide limitation moreover holds in the
strong sense: a single
universal CNN trained on eight families (B1–B4, P1–P4) and
never shown B5 or P5 detects the held-out P5 at
dB and B5 at
dB—comparable to the seen families (
to
dB)—so a blind attacker generalizes to an
unseen chirp family, with P5 having the highest crossing in that run. A parameter/channel-disjoint adversarial campaign (adaptive retraining, realistic-array observation) is left to the extended-validation work. The CNN (like the structure-agnostic ED) is therefore excluded from the per-waveform D5 differentiation of
Section 5.9 and analyzed as a class-wide limitation in
Section 7.3.
Stronger learned attacker (2-D spectrogram ResNet-18): To probe how far a deeper time–frequency classifier shifts this picture, we trained a ResNet-18 (11.2 M parameters, from scratch, single-channel log-magnitude STFT input) under the same energy-normalized H1/H0 construction and CFAR calibration as the per-waveform 1-D CNN study, but with
online training data (fresh 3000 windows per epoch × 14 epochs, uniform training SNR across
dB
): a fixed few-thousand-sample set is memorized by a model of this capacity, and a non-cooperative attacker can synthesize unlimited training signals from the known waveform family, so the online budget is the realistic strong-attacker model. Over ten training seeds, the ResNet-18 reaches
against P5 at mean
dB
(SD
dB; 95% CI
dB) and
at mean
dB (SD
dB; 95% CI
dB). The
result is
dB below the deterministic-rerun per-waveform 1-D CNN conditional mean (
dB), making this the strongest evaluated blind attacker, though still about
dB above the full-knowledge oracle. A fairness control (the 1-D CNN retrained with the same online budget on P5, breaching at
dB) associates about
dB with the data-budget change and the remaining
dB with architecture and run-to-run differences. These are descriptive cross-protocol gaps, not a factorial causal decomposition. The class-wide picture is unchanged: all ten waveform means lie within a
dB band (
to
dB
). Within this single-sensor exact-template protocol, P5 has the highest mean crossing; its paired-seed margin over the next-highest P1 is
dB (95% CI
dB). We also retrained the P5 model for each seed and directly evaluated the 0-dB
operating point with 2000 fresh H1 windows per seed: mean
(seed-level 95% CI
), consistent with the
floor. This operating point lies outside the training-SNR range and is reported only as a direct protocol-specific check. Because the crossings lie inside the training-SNR range, they are interpolated, not extrapolated. The monotone trend—
(1-D CNN, fixed set; conditional mean)
(1-D CNN, online)
dB (ResNet-18, online)—is the empirical basis for treating every learned-attacker breach SNR reported here as a
lower bound on adversary capability: stronger architectures or larger training budgets may push the breach lower still, and only the full-knowledge-oracle floor (
dB) bounds that progression from below. Protocol details, per-waveform crossings, and the attacker comparison figure are given in
Supplementary S5.14.
In addition to the specific-detector bounds above, Park and Doherty’s Kullback–Leibler divergence framework [
22] provides a
detector-class lower bound on the miss probability under the stated NP observation model: for any non-cooperative receiver drawn from the class of Neyman–Pearson detectors with
n observation samples, the miss probability satisfies
with
the KL divergence between the ambient-noise and ambient-plus-P5 sample distributions. We state the idealized model explicitly and treat the result as a
detector-class sanity floor, not a calibrated operating point: for
n effective-independent complex-Gaussian samples whose mean is shifted by a weak signal of per-sample SNR
(the
below is the complex circular-Gaussian mean-shift factor), the per-sample KL divergence is
bits. The per-sample
relates to the total-energy axis
of
Figure 4 and
Section 5.8 by
, so a representative coherent sub-window of
effective samples (well below the full
, conservatively allowing for the non-independence of band-limited samples) at
dB gives, with
,
, i.e.,
for any Neyman–Pearson detector on this idealized model. We use this only as an order-of-magnitude detector-class floor under the Gaussian/independence assumptions: it does
not use the exact P5 observation covariance, is
not tied to the calibrated figure operating points, and does
not cover adversaries with full parameter knowledge, distributed coherent-array integration, or online adaptation against the specific
realization, which remain outside the present analysis.
Scope of the LPI analysis: The six-attacker comparison and the KL bound assume blind attackers with no prior knowledge of the P5 parameter set, observation windows matched to the cooperative receiver, and no hydrophone-array coherent integration. Full-knowledge and coherent-array adversaries are out of scope (
Section 7.3); a limited template-aware stress test is given as E-04 in
Section 5.10.