1. Introduction
Modern airborne radar stations for small carriers are increasingly implemented as multichannel (MIMO-type) systems with several parallel transceiver paths, digital beamforming, and spatio-temporal processing [
1,
2,
3,
4]. MIMO (Multiple-Input Multiple-Output) is a wireless technology that uses multiple transmitting and receiving antennas for simultaneous data transmission. MIMO architecture increases the bandwidth of the communication channel and improves connection stability through the use of spatial multiplexing.
This architecture improves angular resolution, enhances interference robustness, and enables reliable detection of low-contrast targets, including ground objects with a small effective scattering area (ESA), which is essential for civil search-and-monitoring missions. At the same time, multichannel operation substantially increases the volume of internal data exchange between receive modules, digitization units, beamforming/processing blocks, and the central computing module. In addition to radar data, the amount of service traffic grows (mode-control commands, synchronization markers, status telemetry, and aggregated primary-processing outputs). For small onboard radar stations (SORA), external connectivity to ground infrastructure also becomes more demanding, and bandwidth/latency constraints are frequently reported as a bottleneck when transferring complex radar modes to small platforms [
5,
6,
7,
8].
In response to these challenges, increasing attention has been devoted to optical wireless communication (OWC) links in the “SORA carrier–ground infrastructure” segment. Such links use laser or LED emitters as radiation sources and can provide high service data throughput without competing for the congested radio-frequency spectrum and without being directly affected by electromagnetic interference in the radar operating environment [
9,
10,
11].
Within optical wireless technologies, LED-based visible light communication (VLC) occupies a distinct position. Compared with narrow-beam laser links, VLC enables a combination of illumination (or optical beaconing) and data transmission using the same emitter, while maintaining a practically stable communication link whenever line-of-sight visibility is available. Surveys of VLC solutions relevant to multichannel SORA indicate that the technology has matured in recent years for both indoor (enclosed) and outdoor (open-space) deployments, including scenarios where channel conditions vary due to geometry and ambient illumination [
5,
12,
13,
14,
15].
For multichannel SORA platforms, this is particularly attractive because the carrier typically establishes a line-of-sight interval with the ground station during operation, and LED emitters can simultaneously serve as a service optical beacon and as a dedicated service data channel. Existing studies on OWC/VLC links for airborne or mobility-relevant settings demonstrate that stable transmission in the visible and near-infrared ranges can be achieved in the “SORA carrier–ground infrastructure” channel by applying appropriate compensation for atmospheric attenuation and geometry-induced distortions.
As a result, a natural two-link communication architecture emerges for SORA carriers. The radio-frequency (RF) channel supports the conventional exchange of telemetry and control commands and, when required, the transfer of radar products. The LED-based VLC channel provides a dedicated low-emission service path for transmitting operating parameters of the radar and the carrier, synchronization markers, results of primary processing, and other service/measurement data. In a multichannel SORA configuration, this separation allows VLC to carry time-critical service information under favorable optical conditions. The RF channel remains the universal link and a fallback path when VLC conditions degrade [
16,
17].
For a long time, VLC was considered more secure at the physical layer due to the geometrically limited reception area and the inability of light to propagate through opaque obstacles. However, recent VLC-security studies show that practical deployments remain exposed to a broad range of attacks. These include passive interception via reflected components or side-lobe radiation, as well as active illumination of the photodetector with high-intensity optical radiation that can push the receiving path into non-linear operation or saturation. Attacks may also involve injecting false optical packets into the receive path (e.g., by replacing the preamble or the payload) and other physical layer impacts that deliberately distort the power, spectrum, or temporal structure of the optical signal, thereby degrading communication quality. A number of works propose physical layer security mechanisms (e.g., non-Lambertian patterns and controllable reflective surfaces), but these approaches are mainly developed for stationary rather than mobile SORA platforms [
18,
19,
20].
Despite the often-cited physical layer security of VLC due to spatial confinement, recent studies show that practical VLC links remain vulnerable to active adversarial impacts. An attacker does not need to decode the payload to cause harm. It is sufficient to manipulate the optical front-end and, consequently, the photon-count statistics observed at the receiver. In open-space deployments, an external light source can inject continuous illumination or time-aligned pulses, which bias the receiver and distort preamble- and control-segment statistics. An adversary can also inject structured optical packets (spoofing) or retransmit previously recorded legitimate fragments (replay), thereby violating message freshness and logical consistency.
In the considered compact airborne radar architecture, the service VLC channel is used to deliver synchronization markers, telemetry, and mode-control information. Therefore, the dominant security objective is not confidentiality but the integrity and availability of the service link: even short disturbances or subtle manipulations can trigger incorrect mode transitions, desynchronize subsystems, or degrade coordination between sensing and control components, ultimately affecting radar functionality and platform safety.
Accordingly, the threat model is formulated in terms of attacks that perturb the receiver-side photon-counting process, either by shifting the background component (continuous illumination/blinding), introducing short, synchronized flashes (preamble/control distortion), or altering the structure and timing consistency of service messages (spoofing/replay). These mechanisms operate at the physical and protocol-adjacent layers by deliberately shaping the observed counting features, which directly motivates real-time integrity monitoring based on intra-packet statistics over the “preamble + control” segment.
In parallel with the development of physical layer security mechanisms, machine-learning techniques have been increasingly adopted in VLC to improve robustness to interference and to support adaptive link operation. Prior work shows that ML/DL models can assist with channel-state estimation and tracking, suppression of structured optical noise during decoding, and adaptive selection of modulation/coding and operating parameters under changing illumination and geometry conditions [
21,
22,
23]. However, when ML is integrated into the receiver processing chain, the learned decision function itself becomes part of the attack surface. As emphasized in the broader literature on embedded and IoT-class networked devices, ML models are vulnerable to targeted evasion and online data poisoning: carefully crafted perturbations of the input can induce misclassification, while contamination of adaptation data can shift decision boundaries and degrade reliability over time [
24,
25,
26].
These observations motivate the use of interpretable, resource-efficient anomaly detection architectures that can operate in real time and remain resilient to adversarial impacts on the observed data stream, which is particularly important for multichannel SORA platforms with strict onboard constraints [
27,
28]. Consequently, at the intersection of three converging trends—multi-channel SORA deployment on small carriers, the adoption of service VLC links in “carrier–ground infrastructure” architectures, and the growing reliance on ML within communication and cyber–physical pipelines—the problem of ensuring the resilience of the service VLC channel to intentional interference becomes practically relevant and insufficiently addressed.
At the same time, much of the existing security literature for OWC/VLC and the robustness literature for ML-based detectors predominantly targets stationary indoor VLC/LiFi installations or RF-centric protocols, and therefore provides limited guidance for service VLC channels embedded into onboard avionics-grade sensor control loops on small, unmanned carriers. The key challenge is that the onboard AI subsystem that monitors the service VLC link becomes the primary target for evasion and poisoning attacks, while the protection mechanism must remain interpretable and executable in near–real- time on a CPU without graphical acceleration.
Accordingly, this study develops and evaluates an interpretable protection architecture for the AI subsystem that monitors the service VLC channel in a compact multichannel SORA system under constrained onboard resources. The work formalizes a threat model for the considered VLC link (including evasion, spoofing, replay, and online poisoning), proposes a lightweight detector ensemble driven by intra-packet features extracted from a Poisson photon-counting observation model, and quantitatively evaluates performance in terms of detection probability, false-alarm probability, and end-to-end response latency to assess suitability for near–real-time operation.
2. Service VLC Channel Data Processing and Anomaly Detection in the AI Subsystem of a Multichannel SORA System
The objective of the present study is to develop and evaluate service VLC channel data processing and AI-based anomaly detection for a multichannel SORA system installed on a small carrier and operating as a radar–computing complex. For external data exchange with ground infrastructure, the multichannel SORA system employs two logically independent communication channels: a radio-frequency channel and a service VLC channel based on light-emitting diodes. The specific type of carrier hosting the multichannel SORA system is considered in this formulation only through constraints on mass, dimensions, and power consumption, as well as through geometric constraints on the line-of-sight region.
Figure 1 presents the structural diagram of the multichannel SORA system and the placement of the artificial intelligence (AI) module within the onboard processing loop. Onboard the carrier, the SORA radar chain exchanges radar data and sounding commands with the SORA onboard computer. The onboard computer interfaces the RF modem (radio link) for service RF data exchange with the ground infrastructure. It also interfaces the VLC optical modem/Digital interfaces that implement the service VLC chain.
Throughout the manuscript, the term “AI subsystem” refers to the onboard ML-based decision layer for VLC integrity monitoring (logistic regression + one-class detection + fusion), whereas the Poisson photon-counting model is used only as a physics-consistent observation model for feature formation. The contribution of the present work is limited to developing and investigating the feature-formation mapping Φ(N, S) and the ML decision layer implemented as an interpretable detector ensemble f(x; θ) executable on a central processing unit without graphical acceleration, for protecting the AI subsystem under adversarial impacts on the service VLC channel.
In the proposed pipeline, the Poisson photon-counting model is used strictly as a physics-consistent observation model that stabilizes the formation of intra-packet features Φ(N, S). The ML component is the trainable decision layer f(x; θ) (logistic regression + one-class modeling with calibrated thresholds) and its ensemble fusion rule executed on a CPU. Hence, the protection problem addressed in this paper is the robustness of the ML decision layer against adversarial evasion and online poisoning, rather than proposing a new photon-counting model.
The radio-frequency channel is used to transmit telemetry data on the state of the carrier and onboard systems, control commands, and, when required, aggregated radar products. The service visible light communication channel is employed as a low-emission dedicated link for transmitting operating-mode parameters of the SORA system, timing and synchronization markers, diagnostic messages, and a subset of service and measurement data.
The onboard computing module provides the software implementation of the AI subsystem, which is used to monitor the state of the service VLC channel. The AI software subsystem compares feature vectors corresponding to nominal and anomalous channel operation and, in a near–real-time mode, generates decisions regarding the channel state, issuing control signals to adjust system parameters based on the results of the feature-based state assessment.
Let the data transmission over the service VLC channel be represented as a sequence of service bit packets with a fixed structure. At the physical layer, each packet is realized as a sequence of optical radiation pulses of fixed duration, generated according to a pulse modulation scheme in accordance with the binary service data sequence of the transmitted packet. At the logical layer, each packet comprises three consecutively arranged segments of the optical signal: a preamble segment, a payload (service data) segment, and a control sequence of check bits.
The preamble is defined by a predefined binary bit sequence of the service packet, which, according to the employed modulation method, is mapped onto a corresponding sequence of optical radiation pulses. The preamble is used for acquisition and tracking of time synchronization, as well as for estimating the current channel state based on deviations of the registered preamble realization from its known binary template. The control sequence of check bits is specified by a predefined binary sequence associated with the service packet and is used to verify the integrity of the payload segment and to assess the channel state based on deviations of the registered realization of the check sequence from its known binary template.
For a mathematical description of photon-counting observations at the photodetector output during the reception of service messages over the VLC link, we adopted a standard counting model for optical radiation detection. The combined “preamble + control bit sequence” segment of a single service message is partitioned into
L identical time intervals of duration Δ
T (s). In the
k-th interval (
k = 1, 2, …,
L), the number of registered events is described by (1):
where
Nk (counts) is a random variable representing the number of photons registered within the
k-th time interval of duration Δ
T;
N0 denotes the set of non-negative integers (dimensionless).
The vector N = (N1, N2, …, NL) describes a single realization of a discrete-time counting process of photon detection of optical radiation over the combined segment “preamble + control bit sequence” of one service packet.
Here,
N is an
L-dimensional vector (dimensionless) and each component
Nk is measured in counts. In the nominal reception mode of service bit packets over the VLC channel, a discrete-time Poisson model of photon registration is adopted, as given in (2):
where Pois(λ
k) denotes a Poisson distribution on
N0 with parameter λ
k;
λk (counts per time interval ΔT) is the expected number of registered photons in the k-th time interval of duration ΔT.
Conditional independence of the values Nk for different intervals is assumed at fixed values of the parameters λk.
Here, the discrete-time Poisson model is used at the observation level to describe photon registration in the service VLC channel: each random variable Nk is the number of registered photons (counts) within the k-th time interval of duration ΔT, and the parameter λk (counts per time interval ΔT) is the expected number of registered photons in that interval. The intensity parameter λk is represented in the manuscript as the sum of the expected contribution from the LED transmitter during the transmission of a service bit packet and the expected background component; the background component explicitly includes background illumination and the components of the internal noise current of the receiver front-end. Consequently, more complex interference and noise patterns in practical scenarios are reflected in the realized intensity profile {λk} of the service segment, i.e., in the expected useful and background photon counts across the L intervals, which directly determines the nominal distribution of the Poisson-counting feature vector under the hypothesis H0 used for threshold setting (2).
The explicit probability mass function under the nominal hypothesis
H0 is provided in
Appendix A.1.
The parameter λ
k is represented as the sum of the contributions of the useful optical signal radiation and the background component, including natural interference sources, as given in (3):
where
(counts per interval) is the expected number of photons registered in the
k-th time interval of duration Δ
T, caused by the useful optical signal emitted by the LED transmitter during the transmission of a service bit packet;
(counts per interval) is the expected number of photons registered in the same k-th time interval of duration ΔT, caused by background illumination and internal noise sources of the photodetector receiving chain, including photodetector dark current noise, thermal noise of resistive elements, noise of amplification stages, and other components of the internal noise current of the receiver front-end.
The optional physical relationship between expected photon counts and received optical power is provided in
Appendix A.1.
The ranges of variation in the expected number of registered photons due to the useful optical signal of the LED transmitter, and the expected number of registered photons caused by the ambient background illumination and internal noise of the optoelectronic receiver chain of the photodetector in the numerical simulation setup are specified as a regular finite grid of values over and within the operating ranges of the average optical power of the transmitting device and the background illumination levels of the “SORA carrier–ground infrastructure” link.
A formalized description of the characteristics of possible attacks (attack profile) on the considered system is defined as a set of parametric scenarios that modify the intensity of the useful and background optical radiation and, consequently, the statistical properties of the photon-counting registration process. These modifications are reflected in the parameters and of the counting-signal model and, ultimately, in the distribution of the observation vector N.
As studies on the security of VLC and OWC systems indicate, typical active threats at the physical layer and the optical channel protocol layer can be grouped into several persistent categories: illumination- and interference-based attacks (jamming, blinding), injection and modification of optical information (injection, spoofing), and replay attacks. Passive interception (eavesdropping) is typically treated separately as a threat to channel confidentiality [
29,
30,
31]. For communication tasks in transport platforms and unmanned systems, it has been shown that jamming, spoofing, and replay attacks contribute most substantially to the risk of communication failure and loss of control stability [
32,
33]. Most existing active protection schemes for VLC channels primarily target these attack classes, highlighting their fundamental and critical importance [
34].
To explicitly account for the random occurrence of the most critical active attacks, we introduce three Bernoulli event variables per received service packet (equivalently, per observation window). For Monte Carlo realization m, let ZDC ∈ {0, 1}, Zsp ∈ {0, 1}, and Zrep ∈ {0, 1} denote the presence of DC-jamming/blinding, spoofing, and replay, respectively. Their occurrence can be characterized by prior probabilities Pr[ZDC = 1] = πDC, Pr[Zsp = 1] = πsp, Pr[Zrep = 1] = πrep, which depend on the operational environment and the adversary’s capability. Under the nominal hypothesis H0, no active attack is present, i.e., (ZDC, Zsp, Zrep) = (0, 0, 0). The alternative hypothesis is composite and corresponds to the presence of at least one active attack event, H1:(ZDC, Zsp, Zrep) ≠ (0, 0, 0). These event variables are used at the modeling level to select the realization-specific expected-value profile λ(m) (k) under H1, i.e., to activate the corresponding parametric deviation of {λk} from the nominal reference λ(0) (k). This preserves the binary detection setup (H0 versus composite H1) while keeping the occurrence of the dominant attack mechanisms explicit in the generative description of the photon-count observations.
In the considered architecture, the VLC channel is used for unidirectional transmission of service and telemetry messages from the multichannel SORA system to the ground infrastructure; passive interception in this context does not affect the correct operation of the SORA system itself, whereas impacts that compromise the availability and integrity of service messages are critical. Therefore, the threat profile includes four parametric classes of impacts: continuous illumination and synchronization-aligned light flashes (an analog of jamming/blinding), as well as spoofing and replay of service messages (spoofing/replay). This attack scenario is minimally sufficient for analyzing the sensitivity of the AI subsystem to energy-based and protocol-level attacks while maintaining a controlled dimensionality of the parameter space.
Based on the above classification and attack scenario, this study considers four basic types of active impacts on the service VLC channel.
The first type comprises attacks in the form of sustained (continuous) illumination of the optical receiver. In this attack scenario, there exist time intervals in which a non-zero background brightness is present, i.e., a persistent background impact produced by a directed light flux from an external radiation source. Let such attacks be modeled by adding a constant component to the intensity parameter of the background term, as given in (4):
where Δλ
(DC) (counts per interval) is the increment of the expected number of registered photons of optical radiation caused by sustained directed illumination;
KDC is the subset of indices of discrete time intervals k ∈ {1, 2, …, L}, in which a persistent external optical impact is present, resulting in a shift in the expected number of registered photons.
In the case of attacks in the form of synchronized flashes reproduced in time intervals coinciding with elements of the preamble or the control sequence of the signal packet, short-duration optical pulses are generated by an external light source. These pulses lead to an increase in the number of photons registered at the receiver side, which can be described as in (5):
where
≥ 0 (counts per interval) is the increment of the expected number of registered photons in the
k-th time interval caused by an external optical flash;
Kpulse is a subset of indices of time intervals (dimensionless set) corresponding to flashes synchronized with known segments of the service packet structure.
In the case of spoofing attacks on service messages, an optical signal is generated that imitates the structure of the original service message, while the legitimate signal is suppressed, typically either geometrically (by removing the LED transmitter from the line-of-sight region), energetically (by dominance in optical power), or through a combined attack scheme. In this case, for the time intervals onto which the spoofed message is projected, a substitution of the useful signal component is realized as in (6):
where
(counts per interval) is the expected number of registered photons of the useful signal in the nominal operating mode;
Ksp (dimensionless set) is the subset of indices of time intervals k ∈ {1, 2, …, L} over which the spoofed service packet is present;
(counts per interval) is the expected number of registered photons due to the useful signal generated by the attacker during the transmission of the spoofed service packet.
Depending on the attack scenario, may implement:
- (i)
A binary structure of the preamble and control sequence that differs from the nominal one;
- (ii)
Scaling of the legitimate structure in terms of optical power;
- (iii)
A combination of segments whose statistics are close to the nominal ones and segments with deliberately introduced distortions.
In all cases, spoofing is realized as a transition from the parameter vector λ = (λ1, …, λL) to the vector λ(sp) = (λ1(sp), …, λL(sp)) which leads to a systematic shift in the distribution of the counting-observation vector N defined in (1) and (2) with the intensity decomposition given in (3), and consequently in the feature vector formed on the basis of the “preamble + control bit sequence” segment. The corresponding parametric modifications of vector λ for the considered impact classes are specified in (4)–(6).
The final type of attack considered in this study is a replay of service messages. In this case, the attack consists of recording a legitimate service message and subsequently re-emitting its optical equivalent at a different point in time. Unlike spoofing attacks on service messages, this scenario relies on a previously generated legitimate message; however, its temporal relevance and contextual binding to the current state of the multichannel SORA system are violated.
Then, at the time instant when there is a service bit packet with index
i∗, and s is expected from the multichannel SORA system, under such an attack, instead of the expected set of useful-signal intensity parameters, a set corresponding to substituted data is realized at the receiver side, and a service bit packet with index
j appears as given in (7):
where
Krep (dimensionless set) is the subset of indices of time intervals corresponding to the “preamble + control bit sequence” segment of the replayed service packet;
j ≠ i∗ is the index of the original service bit packet used to construct the replay attack;
(counts per interval) is the corresponding set of intensity parameters for the packet with index j, whose optical signal was previously recorded by the attacker and is reproduced during the replay attack.
Under a replay attack on a service message, for time intervals
k ∈
Krep, the intensity of the counting process λ
k is determined as the sum of the intensity of the false useful signal and the background component
, as given in (8):
In the presence of dynamically varying service fields (such as packet counters, timestamps, or pseudorandom preamble templates), for the expected service packet with index i∗, the nominal operating mode should exhibit statistics consistent with the current state of the multichannel SORA system. Replaying a service packet characterized by the parameter set leads to the emergence of structural inconsistencies between the observed counting realizations and the predicted statistics corresponding to the current service message, while maintaining the energy characteristics within the nominal range. As a result, replay attacks constitute a typical class of impacts aimed at violating the logical consistency of service communication while introducing minimal distortion to low-level energy-based features.
Problem Formulation for Attack Detection in the Artificial Intelligence Subsystem
The considered attack types and scenarios can be described as controlled modifications of the vector of expected numbers of registered photons over the “preamble + control bit sequence” segment of a single service bit packet. For each time interval k = 1, 2, …, L λk denotes the expected number of photons registered in that interval and can be written as the sum of the useful-signal term and the background term .
Let these values be combined into the vector λ = (λ1, λ2, …, λL), where λ is the vector of expected numbers of registered photons over all L time intervals of the “preamble + control bit sequence” segment of a single service bit packet; each component λk is measured in counts per time interval of duration ΔT.
Let us assume that the operating range of the service VLC channel in the nominal mode is defined by the set (9):
where Λ
0 denotes the set of all vectors λ of expected numbers of registered photons over the “preamble + control bit sequence” segment of a single service bit packet that arise for admissible values of the average optical power of the LED transmitter and the background illumination level of the “SORA carrier–ground infrastructure” link in the absence of attacks.
Similarly, the set (10) is introduced:
where Λ
att denotes the set of all vectors
of expected numbers of registered photons over the “preamble + control bit sequence” segment of a single service bit packet in the presence of adversarial impacts, realized through the increments Δλ
(DC),
and through the index sets of time intervals
KDC,
Kpulse,
Ksp,
Krep, as well as through admissible structures of spoofed and replayed service bit packets.
For λ ∈ Λ
0, the realization of the counting-observation vector
N = (
N1,
N2, …,
NL), previously introduced as a single experimental outcome of the discrete-time photon-counting process over the “preamble + control bit sequence” segment of a single service bit packet, belongs to the set (11):
For λ
(a) ∈ Λ
att the realization of the counting-observation vector under an attack belongs to the set (12):
where
Natt denotes the set of all realizations of the counting-observation vector in the presence of one of the considered attacks on the service VLC channel;
is the counting-observation vector under attack.
The optical modem of the VLC channel and the onboard computer of the multichannel SORA system form a channel-state feature vector (whose deviations indicate anomalies) based on the vector of photon-counting observations registered in each time interval over the “preamble + control bit sequence” segment and on the known structure of the service bit packet, as given in (13):
where
x ∈
Rd is the channel-state feature vector (with anomalies corresponding to non-nominal deviations) in the AI subsystem of dimension
d (each component of the vector
x is a deterministic function of the component
Nk and the set of structural parameters
S of the service bit packet);
Φ(⋅,⋅) is the feature-formation mapping from the counting-observation vector over the “preamble + control bit sequence” segment and the structure of the service bit packet;
S is the set of structural parameters of the service bit packet (binary preamble template, binary template of the control bit sequence, indices of time intervals corresponding to these templates, and the parameters defining the partitioning of the segment into L intervals of duration ΔT);
d is the dimension of the feature space describing the nominal channel state of the service VLC channel; anomalies are represented as non-nominal feature vectors in the same space.
The mapping Φ(
N,
S) defines two classes of feature vectors corresponding to the nominal channel state and to anomalous (attack-induced) conditions in terms of interaction with the AI subsystem, as given in (14):
where
X0 denotes the set of feature vectors of the AI subsystem corresponding to the nominal operating mode of the service VLC channel, as given in (15):
where
Xatt denotes the set of feature vectors of the AI subsystem corresponding to the presence of attacks on the service VLC channel.
The AI subsystem implements a binary decision rule, as given in (16):
where
f(
x; θ) = 0 denotes the decision that the service VLC channel operates in the nominal mode (hypothesis
H0);
f(x; θ) = 1 denotes the decision that the service VLC channel operates in an anomalous mode (hypothesis H1), corresponding to the presence of at least one of the considered attack types (without attributing the decision to a specific attack class);
θ is the parameter vector of the detector ensemble of the AI subsystem (logistic-model coefficients, one-class detector parameters, and threshold values) implemented on the central processing unit of the onboard computer of the multichannel SORA system.
To avoid ambiguity between the decision output and the reference class information, two binary quantities are distinguished. The binary output of the AI subsystem is a decision produced from the currently observed feature vector and represents an estimate of the operating condition (“nominal” versus “attack-present”). In contrast, the variable y introduced in the dataset description is a reference class label assigned to simulated (labeled) realizations for supervised training and for performance evaluation; it indicates whether a given realization was generated under the nominal operating mode or under one of the considered attack scenarios. Consequently, y specifies which hypothesis holds for a labeled realization, whereas the AI subsystem output provides the corresponding estimated decision; false-alarm and missed-detection probabilities are evaluated by comparing these decisions to the reference labels over the nominal and attack-induced feature distributions.
The distribution of channel-state features in the nominal operating mode is denoted by
P0, while the distribution of channel-state features in the attacked (anomalous) mode is denoted by
Patt as given in (17):
where
P0 is the distribution of the AI subsystem feature vector over the set
X0, induced by the Poisson model of the photon-counting registration process for λ ∈ Λ
0 and a fixed structure
S of the service bit packet; similarly,
Patt is defined as in (18):
where
Patt (dimensionless) is the aggregated distribution of the AI subsystem state (anomaly) feature vector over the set
Xatt induced by the Poisson model of the photon-counting registration process for λ
(a) ∈ Λ
att across all considered attack scenarios.
For a fixed parameter vector θ, the false-alarm probability and the missed-detection probability of the AI subsystem are defined as in (19) and (20):
where
PFA(θ) (dimensionless) is the probability that, under the nominal operating mode of the service VLC channel (feature distribution
P0), the AI subsystem erroneously produces a decision indicating an anomalous mode;
where
PMD(θ) is the probability that, in the presence of attacks on the service VLC channel (feature distribution
Patt), the AI subsystem erroneously produces a decision indicating a nominal operating mode (dimensionless).
From the perspective of attacks on artificial intelligence systems, the scenarios of sustained illumination and synchronized flashes implement evasion attacks against the AI subsystem: the attacker selects a vector λ(a) ∈ Λatt such that the corresponding features x(a) ∈ Xatt lead, with non-zero probability, to the decision f(x(a); θ) = 0 despite the actual presence of attacks.
The spoofing and replay scenarios of service bit packets, in addition to evasion attacks, also create the possibility of online data poisoning: when service traffic is used to adapt the parameter vector θ false (anomalous) channel-state feature vectors x(a) ∈ Xatt, may be incorporated into the training dataset. This results in a systematic bias in the estimates of nominal-mode statistics and a shift in the class decision boundary in the feature space.
The working hypothesis of this study is that, for the service VLC channel of a multichannel SORA system, it is possible to construct a feature-formation mapping Φ(
N,
S) and a detector ensemble
f(
x; θ), implementable on a central processing unit without graphical acceleration, such that, under physical constraints on the attack parameters λ
(a) ∈ Λ
att there exists a parameter vector θ
∗ of the anomaly detector ensemble for the service VLC channel satisfying the inequalities in (21):
where
(dimensionless) is the prescribed admissible level of the false-alarm probability of the service VLC channel of the multichannel SORA system;
(dimensionless) is the prescribed admissible level of the missed-detection probability for attacks on the service VLC channel of the multichannel SORA system;
θ∗ is the parameter vector of the detector ensemble of the artificial intelligence subsystem, optimal with respect to the selected attack detection performance criterion under the given constraints on and .
The data-processing scheme in the service VLC channel and the operation of the AI subsystem are illustrated in
Figure 2.
The lower part of the diagram (
Figure 2) shows the sequence of data processing in the service VLC channel during the carrier flight (online mode). The light-emitting diode transmitter generates an optical signal that propagates in an open environment, where it may be affected by natural background illumination and atmospheric effects, as well as by intentional adversarial impacts. After the optical signal is registered by the photodetector, time discretization is performed and photon-counting observations are formed within a fixed observation window divided into
L intervals of duration Δ
T.
The upper part of
Figure 2 describes the formation of synthetic and semi-synthetic datasets of counting observations (offline stage), which are used to construct training datasets of channel-state features, to estimate nominal-mode statistics, and to train the parameters of channel anomaly detectors and the AI subsystem. At this stage, the threat profile (attack scenarios) is also formalized, incorporating the attack types described above.
3. Simulation Setup and Attack Emulation
The simulation model of the service VLC channel is constructed as a physico-mathematical interpretation of the photon-registration process at the receiver, based on specified parameters of the light-emitting diode transmitter, the propagation path, and the photodetector, in order to generate synthetic realizations of the counting-observation vector N = (N1, …, NL), which are used by the AI subsystem.
The relationship between the optical power incident on the photodetector aperture and the parameter of the counting process is defined by a quantum-optical relation, as given in (22):
For reproducibility of the physical layer setup, we specify the effective received optical power levels at the photodetector aperture that correspond to the nominal mean photon-count levels used in the Monte Carlo study. The photon-counting (Poisson) observation model and the mapping between received optical power and mean photon counts are widely used in low-power optical wireless communication analyses [
35].
For physical interpretability of the receiver-side parameters, we align the representative values used here with a standard silicon PIN photodiode datasheet (Hamamatsu Photonics, “Si photodiode S9219 series (S9219-01)”): the datasheet reports a peak sensitivity wavelength of 550 nm, photosensitivity of approximately 0.22 A/W at the peak, and microsecond-scale temporal response (typical rise time ≈0.5 μs under the stated test conditions). Accordingly, we use a representative visible wavelength λopt = 550 nm (ν = c/λopt), adopt an integration time ΔT = 1 μs, and set the quantum efficiency to a conservative reproducible value η = 0.5 for the Monte Carlo setup. For these settings, the nominal mean counts {λp,nom, λc,nom, λb,nom} = {14, 7, 2} per interval correspond to effective received optical powers {1.0 × 10−11, 5.1 × 10−12, 1.4 × 10−12} W for the preamble “1”-intervals, the CRC/control “1”-intervals, and the background component, respectively. In this work, transmitter power, link geometry, receiver aperture, and pointing angles are not fixed to a single hardware configuration; instead, their combined impact is represented by the Poisson intensity profile λk via an effective channel transfer coefficient and an additive background term, consistent with the line-of-sight Lambertian assumptions stated below.
The line-of-sight optical channel transfer coefficient is modeled using the standard Lambertian DC-gain expression; the explicit formulation is provided in
Appendix A.1 for completeness.
Here, it is assumed that within a single interval ΔT, the optical power (t) is approximately constant.
To focus on the tasks of protecting the AI subsystem and on analyzing the impact of attacks on counting features, a number of assumptions are introduced in the simulation model:
- -
A line-of-sight (LOS) channel is only considered. Multiple reflections, diffuse scattering, and multipath effects are not explicitly modeled, and their overall contribution is assumed to be absorbed into variations in the effective channel transfer coefficient and the background optical power.
- -
Within the counting-observation time window, which includes a fixed number of equal-duration intervals, the propagation geometry and background conditions are assumed to be quasi-stationary; that is, for each realization of the simulation experiment, the distance between the transmitter and the receiver, the orientation of the optical axes of the emitter and the photodetector, the average background optical power at the photodetector aperture, and the effective level of internal noise of the receiver front-end are fixed and do not change within a single window.
- -
The photodetector front-end operates in the linear regime. Photodetector saturation and nonlinear effects of the amplification stages are not considered, and it is assumed that the optical power levels in the considered operating modes do not drive the system outside the linear range.
- -
Intersymbol interference is not modeled. The time intervals ΔT are chosen such that each interval corresponds to a single symbol position in the preamble or the control sequence, and the receiver response does not overlap across adjacent intervals.
- -
Timing synchronization errors and mismatches in selecting the counting-observation time window are not considered. It is assumed that the “preamble + control bit sequence” segment is correctly identified at the receiver and that synchronization is maintained by lower-layer protocol mechanisms.
The simulation model implements the data-processing scheme shown in
Figure 2. The modeling process is divided into two loops:
- -
A synthetic data generation loop (offline stage), which includes forming reference intensity templates, modeling the effects of the channel and attacks, and generating counting observations and features for training and testing the detectors;
- -
An anomaly detection loop (online stage/online emulation), which includes applying the trained detector ensemble to the generated feature stream to estimate the false-alarm probability PFA and the detection probability PD.
The transmit chain is simulated under the assumption that the transmitter converts the logical structure of the service packet S into a sequence of optical pulses. A binary one (bit ‘1’) is mapped to a rectangular optical pulse of duration ΔT with average optical power P1. A bit ‘0’ corresponds to the absence of radiation (power P0 ≈ 0). For the preamble, the transmitter optical power level Pp is used, and for the control sequence Pc, is used, with Pp > Pc. The ratio Pp/Pc = 2 is chosen to prioritize synchronization.
The optical channel model is simulated based on the assumption that the signal propagates through the “SORA carrier–ground infrastructure” link, which is characterized by:
- -
Geometric losses, calculated using a Lambertian radiation model for a given transmission distance, photodetector aperture area, and orientation angles;
- -
Atmospheric attenuation, which depends on the signal propagation range (distance between the transmitter and the receiver) and meteorological conditions;
- -
Background illumination, which creates a constant background irradiance at the photodetector.
For each realization, the true channel-state label y ∈ {0, 1}, is additionally fixed, where y = 0 corresponds to the nominal operating mode (hypothesis H0), and y = 1 corresponds to the presence of an attack (hypothesis H1). This enables the formation of simulation datasets {(x(m), y(m))} for training and testing the detector ensemble f(x; θ).
The proposed protection architecture is scalable in the sense that the online computation in the AI subsystem is O(L) per received service packet: feature formation Φ(N, S) consists of linear-time aggregation over the index sets Kp, Kc, and K0, and the one-class, energy, and logistic detectors operate on a fixed feature dimension d = 5.
Adaptability to different operational environments (including varying link geometry, background illumination, and meteorological conditions that affect atmospheric attenuation) is achieved by treating their combined impact as a realized Poisson-intensity profile λk (effective channel transfer coefficient plus an additive background term) and by calibrating nominal-mode feature statistics and detector thresholds on environment-specific nominal data. Under this interpretation, changing atmospheric conditions primarily manifest as increased inter-window variability of the useful and background components and, consequently, as heavier tails of the nominal feature distributions that control PFA through threshold tuning. The applicability boundary under extreme environmental variability is defined by the modeling assumptions stated above: within-window quasi-stationarity, LOS dominance with multipath absorbed into effective parameters, and linear operation of the photodetector front-end without saturation.
Ensemble of Channel-State Feature Detectors for the Artificial Intelligence Subsystem
In the AI subsystem of the service VLC channel, an ensemble of lightweight anomaly detectors is used, implemented on the central processing unit of the multichannel SORA system without graphical acceleration. The ensemble operates in the space of channel-state features (with anomalies corresponding to non-nominal deviations in the same feature space) x ∈ Rd, formed from the counting-observation vector N and the set of structural parameters S of the service bit packet.
A total of d = 5 state features is considered for the protected channel and the AI subsystem.
The adopted feature dimension is fixed at five because the channel-state feature vector is defined as a five-component aggregation of counting observations over the service-packet structure. Specifically, the components quantify relative deviations over the preamble and control sequence, the contrast with respect to the background segment, an integral deviation measure over the service segment, and the variability of deviations over background intervals where the useful signal is absent. This compact representation preserves the observability of the main non-nominal effects considered in the manuscript while keeping the online detector computations lightweight.
To describe the service packet structure, three index sets are introduced:
Kp ⊂ {1, …, L} is the set of indices of time intervals corresponding to preamble elements;
Kc ⊂{1, …, L} is the set of indices of time intervals corresponding to elements of the control sequence;
K0 ⊂{1, …, L} is the set of indices of time intervals corresponding to the background segment (absence of a useful signal).
The cardinalities ∣Kp∣, ∣Kc∣, ∣K0∣ (dimensionless quantities) are determined by the structure of the service bit packet and the parameter L.
If is the reference vector of expected photon counts over the preamble-and control-segment under the nominal operating mode, then, for a single realization N = (N1, …, NL), consistent with the line-of-sight Lambertian assumptions stated below, channel-state feature vector x = (x1, …, x5) is defined as follows.
First, deviations of the observed photon counts in the preamble and in the control sequence from their reference values are quantified; these deviations are sensitive to changes in the useful-signal level and propagation conditions. Second, (i) the contrast relative to the ambient background illumination, (ii) the sum of squared deviations from the reference profile over the service segment, and (iii) the variance of deviations over background intervals where the useful signal is absent and the observations are dominated by ambient illumination and receiver front-end noise are computed.
Then, the mean relative deviation over the preamble is defined as in (23):
where
x1 (dimensionless) is the mean relative deviation of the number of registered photons from the reference expected value, averaged over the preamble elements; mean relative deviation over the control sequence is defined as in (24):
where
x2 (dimensionless) is the mean relative deviation averaged over the intervals of the control sequence; the remaining notations coincide with those in the formula for
x1.
The preamble contrast with respect to the background illumination is defined as the difference between the mean photon counts over the preamble and background segments, as given in (25):
where
x3 (counts) is the difference between the mean values of the number of registered photons in the preamble and in the background segment; the first sum yields the mean photon count over the preamble intervals, and the second sum yields the mean photon count over the background intervals.
The sum of squared deviations over the service segment (the “preamble + control bit sequence” segment) is defined as in (26):
where
x4 (counts
2) is the unnormalized sum of squared deviations of the observed values
Nk from the reference values
over the “preamble + control bit sequence” segment, i.e., an integral measure of the overall deviation level across the entire service part of the packet.
The variance of the background noise component is defined as in (27):
where
is given by (28):
where
x5 (counts
2) is the variance of deviations of the number of registered photons from the reference expected value
over those time intervals
k ∈
K0, in which the useful signal of the service packet is absent; this quantity characterizes the noise level due to background illumination and internal noise in the receiver front-end; (counts) is the sample mean deviation over the background segment.
(counts) is the sample mean deviation over the background segment.
The ensemble includes three lightweight detectors implemented on the central processing unit and operating on the channel-state feature vector x defined in (13) (with components x1, …, x5 given in (23)–(28)):
- -
A one-class (OC) detector models the feature distribution in the nominal operating mode. For each new feature vector, a deviation score with respect to the reference distribution is computed, and an anomaly decision is issued if the score exceeds a threshold.
- -
An energy detector computes the total energy of the feature vector (the sum of squares of its components) and compares it with a threshold. High energy values indicate large joint deviations across the features.
- -
A logistic-regression (LR) detector is trained on a labeled dataset containing both nominal-mode samples and attack examples. For each feature vector, an estimate of the attack probability is computed, and a positive decision is issued if it exceeds a threshold.
The explicit detector scoring functions and threshold calibration procedures for the OC detector, the energy detector, and the LR detector are provided in
Appendix A.2.
Within the implementation of the one-class elliptical detector, the sample of channel-state features corresponding to the nominal operating mode X0 = {x(m):y(m) = 0} is used to obtain sample estimates of the mean feature vector in the nominal mode μ0 ∈ R5 and the covariance matrix Σ0 ∈ R5×5. These dimensions follow directly from the five-component definition of the channel-state feature vector.
The local decision rule of the one-class detector is given in (29):
where the threshold γ
OC is determined using the simulation sample of nominal-mode features
X0.
For each feature vector x(m) ∈ X0, the corresponding scoring value is computed. Based on the set of obtained values, an empirical distribution consisting of M0 = ∣X0∣ points is constructed. The threshold γOC is then selected as the level of this empirical distribution such that the fraction of nominal-mode realizations exceeding the threshold does not exceed the prescribed admissible false-alarm probability. In this way, γOC is uniquely determined from the sample X0 and defines a controlled false-alarm level for the one-class detector.
The decision rule for the energy detector has the form (30):
where
is the binary decision of the energy detector; the value 1 is interpreted as the presence of an anomaly.
In what follows, the “energy” of the feature vector refers specifically to the quantity i.e., the sum of squares of its components, by analogy with the notion of the energy of a discrete-time signal in signal processing theory; this is not physical energy in the sense of joules, but a convenient scalar characteristic of the scale of feature deviations.
The local decision of the logistic detector is given by (31):
where
fLR(x;
θLR) = 1 corresponds to classifying the realization as an attack.
The parameters w and b are determined from the simulated labeled dataset {x(m), y(m)} as the solution of the problem of minimizing the mean logistic loss function: w and b, are chosen such that the values of are as close as possible to 0 for nominal-mode realizations (y(m) = 0) and as close as possible to 1 for attack realizations (y(m) = 1).
The complete detector ensemble in the AI subsystem implements the decision rule in the form of a logical expression, as given in (32):
where
is the ensemble decision;
is the joint parameter set of all three detectors, i.e., the parameter vector of the detector ensemble implemented on the central processing unit of the onboard computer of the multichannel SORA system.
This means that the ensemble declares the presence of an attack according to a “2-out-of-3” voting rule. The “2-out-of-3” rule operates on the three local binary decisions produced by the one-class detector, the energy detector, and the logistic detector for the same observation window and the same channel-state feature vector. An attack-present decision is issued only when at least two of the three detectors declare an anomaly/attack; otherwise, the ensemble output corresponds to the nominal mode. This fusion rule reduces sensitivity to occasional excursions of a single detector while preserving the low-false-alarm operating point ensured by nominal-mode threshold calibration of the individual detectors.
Under extreme adversarial conditions, the performance of the ensemble (one-class detector, energy detector, and logistic-regression (LR) detector) combined by the “2-out-of-3” voting rule is limited by whether spoofing produces a detectable shift in the Poisson-counting feature vector x = Φ(N, S) = (x1, …, x5) beyond the nominal H0 variability at the fixed low-false-alarm thresholds (γOC, γEN, τLR). In the spoofing impact model considered in this manuscript, spoofing modifies the expected-value profile λ(k) over the “preamble + CRC” intervals and therefore typically shifts the aggregated features x1–x5. The limiting extreme case corresponds to a high-capability spoofing process engineered to reproduce the nominal photon-count feature statistics of the service bit packet under H0. This would require simultaneous matching of the “preamble + CRC” expected-value profile λ(k) that governs the mean-deviation and energy-related features (x1, x2, x4) and matching of the background level and background variability over the interval set K0 that directly determines the contrast feature x3 and the background-variance feature x5.
Operationally, this implies fine synchronization with the receiver sampling grid Δ
T, accurate knowledge of the instantaneous optical channel gain (Lambertian DC gain with atmospheric attenuation) and background illumination, and the ability to shape injected optical power across the service segment without inducing excess energy or excess variability in the background intervals. The quantitative sensitivity curves for spoofing and the most challenging close-to-
H0 case (replay) are reported in
Section 4 (
Figure 3g,h).
4. Results and Baseline Analysis
The objective of the numerical experiment is to obtain (i) the empirical false-alarm probability
PFA of the AI subsystem in the nominal operating mode of the service VLC channel (hypothesis
H0) and (ii) the sensitivity characteristics of the attack detection probability (hypothesis H
1)
PD(ξ) as a function of the attack strength parameter ξ applied to the communication channel or the AI subsystem for each impact type
a ∈ {DC-jamming, pulsed, spoofing, replay}. The detector thresholds are fixed using the nominal-mode sample and are not retuned when the attack strength ξ is varied; this ensures a physically consistent comparison of the sensitivity of the detectors and the ensemble based on the plots in
Figure 3e–h.
The results in this section are reported both for the individual detectors and for their ensemble. For the individual-detector curves, the corresponding local binary decision is used. For the ensemble curves, the final decision is formed by the “2-out-of-3” voting rule applied to the three local decisions within the same observation window: an attack-present decision is issued only when at least two local decisions indicate an anomaly/attack; otherwise, a nominal decision is retained.
The numerical experiment is implemented using the Monte Carlo method within a discrete-time Poisson model of photon-counting over the “preamble + control bit sequence” segment of a single service packet. For each realization, a vector of expected numbers of registered photons over the observation-window intervals
(counts per interval Δ
T) is formed, after which a vector of photon-counting observations
is generated according to the procedure described in
Section 2.
A reference (nominal) profile of the expected numbers of registered photons is then introduced.
By reference, the following is meant: it is a deterministic (non-random) vector λ(0) that describes the expected number of registered photons λk that should be realized in the nominal operating mode at each interval of the observation window, given nominal levels of the useful and background radiation components and a known structure of the service packet. The reference profile λ(0) is used only as a baseline when computing the features Φ(N, S), which measure deviations of the observed values Nk from the nominal statistics of the normal operating mode.
The nominal statistical levels of the normal operating mode are specified as the nominal expected numbers of registered photons over the corresponding segments of the observation window. A graphical representation of λ
(0)(
k) is shown in
Figure 3a.
In each Monte Carlo realization, a realization-specific profile λ(m) is used, which incorporates variations in channel conditions and, when applicable, adversarial impacts.
That is, λ(0) represents the reference nominal statistics of the normal operating mode, whereas λ(m)—corresponds to the statistics of a specific realization according to which the photon counts Nk(m) are actually generated.
The initial prescribed parameters used for the simulation modeling, providing comparable data structures and comparable sensitivity curves, are summarized in
Table 1.
The number of observation-window intervals L = 20 is chosen as minimally sufficient to ensure that a single window simultaneously contains: (i) preamble intervals, from which deviation and contrast features are formed; (ii) control bit sequence (CRC) intervals, from which independent deviation features are formed for the second service segment; and (iii) a separate background segment, from which the level and variability of the background component are estimated. The presence of a dedicated background segment is essential for reproducible computation of the background-variance feature and for stable computation of the “service intervals–background intervals” contrast; therefore, 10 background intervals are used rather than 1–2.
The partitioning into five preamble intervals, five CRC intervals, and 10 background intervals is sufficient for two reasons. First, averaging over the preamble and CRC is based on at least five samples, which yields stable mean deviations (otherwise, a single random Poisson outlier would begin to dominate the feature). Second, estimating the variance of the background component over 10 intervals ensures stability of the estimate; when variance is estimated from only 2–3 points, the estimation spread is excessively large and begins to “noise” at the detector level.
The interval duration ΔT = 1 μs is chosen as a compromise between: (i) the requirement of the discrete-time photon-counting model that “one interval corresponds to one element of the service sequence”; (ii) neglecting intersymbol interference within the observation window; and (iii) ensuring a sufficient number of photons per interval for reproducible computation of statistical features. At the level of the numerical experiment setup, ΔT = 1 μs defines a typical time scale of the elementary structure of the service segment and is consistent with the assumption of quasi-stationarity of conditions within a single observation window.
Varying the number of observation-window intervals L affects both the statistical stability of the Poisson-counting feature formation Φ(N, S) and the decision latency of the protection block. If L is reduced (and, consequently, fewer intervals are available in the “preamble + CRC” segment and in the background set K0), the sample-mean and sample-variance estimates implicit in the features x1–x5 become noisier, which widens the nominal feature distribution under H0 and tends to either increase the false-alarm probability for fixed thresholds or require more conservative thresholds that reduce detection sensitivity. If L is increased while keeping the same relative partitioning between preamble, CRC, and background, feature estimates become more stable, but the observation-window duration LΔT increases the reaction time and may challenge the within-window quasi-stationarity assumption for the intensity profile λ(k), which can again broaden the nominal H0 statistics. For this reason, L = 20 is used as a minimally sufficient configuration that preserves stable estimation in all three segments while keeping latency low under the adopted ΔT.
The nominal expected numbers of registered photons in the normal operating mode are listed in
Table 2.
The values λp,nom, λc,nom, λb,nom define the nominal expected numbers of registered photons over the “preamble + control bit sequence” segment of a single service bit packet in the normal operating mode of the service VLC channel. Here, λp,nom applies to those observation-window time intervals in which, according to the binary preamble template, a bit ‘1’ is transmitted; λc,nom applies to those observation-window time intervals in which, according to the binary control-sequence template, a bit ‘1’ is transmitted; λb,nom applies to those observation-window time intervals in which the useful signal is absent, and the counting is formed by background illumination and internal noise of the receiver front-end.
These nominal levels are selected such that the contrast between service intervals and background intervals of the observation window is pronounced at the level of the expected values λk, while preserving the Poisson variability of the counting process, which subsequently manifests itself in the realizations Nk.
To prevent the nominal statistics from becoming an “ideal template”, inter-window variability of reception conditions is modeled in each Monte Carlo realization: each realization corresponds to one observation window (one received service bit packet over the “preamble + control bit sequence” segment), and the variability is introduced as variations in the expected values λk(s) and λk(b) between such observation windows.
Numerical values of the inter-realization variability parameters and the Monte Carlo sample sizes used for threshold tuning, testing, and sweeping over the attack strength are summarized in
Table 3.
The sample sizes are chosen to ensure statistically stable estimates of trigger rates. The nominal-mode test sample size Mtest,0 = 20,000 provides sufficient capability to estimate the false-alarm probability at the level of a few 10−3, while the number of realizations per sweep point Msweep = 4000 yields sufficiently smooth detection-probability curves without noticeable “jitter” with respect to the attack-strength parameter applied to the channel and the AI subsystem. The nominal-mode training sample size Mtrain,0 = 80,000 is required for stable threshold tuning based on the tails of the nominal feature distributions (without overfitting to random outliers), and 20,000 attack examples per attack type used to train the logistic detector ensure representativeness of within-scenario attack variations and stability of the learned weights under fixed thresholds.
The empirical false-alarm probability of the AI subsystem is estimated on an independent nominal-mode test sample as the fraction of realizations for which a decision indicating an attack is produced, as given in (33):
where I(⋅) is the event indicator function (dimensionless).
The sensitivity characteristic of the attack detection probability is constructed for a fixed impact type and a fixed attack strength as the fraction of attack realizations recognized as an attack, as given in (34):
where
(dimensionless vector of the corresponding dimension) is the feature vector for the
m-th realization under an impact of type
a and attack strength ξ.
The numerical experiment is implemented in Python 3.12.2 (Anaconda distribution): Poisson counting realizations are generated using NumPy 1.26.4 and SciPy 1.12.0, and the AI subsystem detectors are implemented and trained using Scikit-learn 1.3.0. The simulation is organized as a sequence of fixed steps for each observation window of a single service packet.
First, a realization-specific profile of expected values over the observation window is formed: a background component with inter-window fluctuation is specified, and then, on the “1”-intervals of the preamble and the control bit sequence, a useful component is added with inter-window variation in the useful-signal level. Next, if an impact is present, the expected-value profile is modified according to the selected impact type. Based on the resulting expected-value profile, a counting-observation vector for the observation window is generated under the Poisson model, after which the AI subsystem feature vector is computed from the counting observations and the decisions of the one-class detector, the energy detector, the logistic detector, and the ensemble (using the “2-out-of-3” rule) are obtained.
That is, in the model, an impact modifies the expected photon-counting values over the observation window, while changes in the channel-state features and detector decisions are a consequence of changes in the counting observations generated under the modified statistics.
The results of the simulation modeling of the attack detection system for the VLC channel with the AI subsystem are presented in
Figure 3a–h.
In
Figure 3a, the reference nominal expected-value profile λ
(0)(k) is shown and used as the
H0 baseline for computing Φ(
N,
S), i.e., deviations of photon counts are measured relative to a physically consistent nominal profile on both service and background intervals.
Figure 3b clarifies the observability mechanisms of the considered impact types at the level of λ(
k): DC-jamming mainly shifts the background intervals upward, pulsed interference adds excess counts on a subset of service intervals, spoofing disrupts the correspondence between the service-interval structure and the nominal expected counts, and replay partially preserves the service structure while mixing recorded fragments.
Figure 3c indicates that the Poisson variability is preserved for a fixed observation-window structure; consequently, decisions are formed statistically over the window rather than by deterministic template matching. The feature projection in
Figure 3d provides an empirical consistency check that Φ(
N,
S) induces separation between
H0 and
H1, which is consistent with the high ranking performance of the monotonic logistic component (0.952).
Figure 3e–h quantify sensitivity margins for a fixed deployed operating point because all thresholds are calibrated on
H0 only and then kept unchanged during the sweep over the impact-strength parameter ξ. Therefore, the resulting
PD(ξ) curves should be interpreted as
margins of a fixed deployed configuration at a fixed
H0-calibrated operating point, rather than as performance after retuning to each ξ. On an independent
H0 test sample, the ensemble false-alarm probability is
PFA = 0.045, while the component trigger rates are comparable (OC = 0.0468; Energy = 0.0506; LR = 0.0508), which confirms consistent
H0-based calibration across heterogeneous scoring rules and enables a fair comparison of
PD(ξ) across impact types.
Figure 3.
Results of the simulation experiment for evaluating false alarms and the sensitivity of the artificial intelligence subsystem under adversarial impacts on the service VLC channel and the AI subsystem of the onboard computer of a multichannel SORA system.
Figure 3.
Results of the simulation experiment for evaluating false alarms and the sensitivity of the artificial intelligence subsystem under adversarial impacts on the service VLC channel and the AI subsystem of the onboard computer of a multichannel SORA system.
For the “2-out-of-3” ensemble, the minimum impact strength required to achieve
PD ≥ 0.90 is Δλ
DC ≈ 7.56 for DC-jamming (
Figure 3e), Δλ
pulse ≈ 12.89 for pulsed interference (
Figure 3f), and α ≈ 1.02 for spoofing (
Figure 3g). These thresholds have a direct interpretation in terms of the nominal expected-count levels used in the model: DC-jamming becomes reliably observable once the upward shift in background intervals produces a window-level deviation that dominates the nominal Poisson variability, whereas pulsed interference requires a larger Δλ because it affects only a subset of service intervals and its effect is partially averaged in the aggregated features. Spoofing reaches the same detectability margin at a small parameter change because it is a structural mismatch impact relative to λ
(0)(k) on the service segment, which produces persistent inconsistency in the service-interval aggregates used by Φ(
N,
S). In contrast, for replay, the target level
PD ≥ 0.90 is not reached on the specified grid of β (
Figure 3h). This identifies replay as the limiting case for the current feature set within the selected range: replay can preserve a substantial fraction of the service-segment structure and therefore induce smaller shifts in the same window-level Poisson-counting aggregates relative to
H0 than interference-type impacts and spoofing. From an operational viewpoint, achieving the same detectability margin for replay-like impacts with CPU-only processing requires either a more informative control structure within the service packet or an augmented feature map that is more sensitive to segment reuse while remaining compatible with the low-dimensional Poisson-counting formalism.
It is important to emphasize the practical link to the quality of the LED emitter, since it determines the stability and reproducibility of the photon-counting statistics on which the AI subsystem is trained and calibrated. Optical power instability, temperature drift, growth of the noise component, and luminous-flux degradation (aging) lead to systematic shifts in the nominal statistics and an increase in inter-window variability, which directly affects P
FA (through heavier tails of the
H0 feature distributions) and P
D(ξ) (through reduced separability of
H0 and
H1). Therefore, the curves in
Figure 3 should be interpreted as sensitivity estimates under the specified source-quality level (stable nominal levels and limited variations). A natural extension of the model is to introduce a parameterization of LED instability/degradation [
36].
Benchmarking Against AI-Based Methods and Poisson Baselines
A quantitative performance comparison is provided using (i) representative security-detection results reported in the literature with explicit numerical metrics, and (ii) an internal apples-to-apples benchmark of Poisson photon-counting baselines and lightweight ML detectors within the unified photon-counting control-segment model.
In this work, the AI component is the learned decision layer that classifies integrity states from photon-counting features. Logistic regression operates as a supervised ML classifier, while the final decision is produced by an AI-assisted fusion rule combining LR, a robust one-class anomaly detector, and a conventional energy statistic. This setting corresponds to AI-assisted security because the integrity decision is driven by a trainable ML component and decision fusion rather than by a single fixed-form statistical test.
All internal detectors are calibrated on nominal data to the same operating point PFA ≈ 0.05 and compared using the minimum attack strength required to achieve PD ≥ 0.90, or the maximum achieved PD when the target is not reached on the tested grid. Under this criterion, LR yields the highest sensitivity to DC-jamming and spoofing, whereas EN (a representative Poisson-statistic baseline) can be insensitive to DC-jamming in the integrity-attack setting. Replay remains the most challenging case for all tested detectors within the examined β range.
For VLC-specific attack detection, a cooperative attack detection method for LED-based VLC reports 91% attack detection accuracy and a minimum detection rate of 84% in obstacle-rich environments [
37].
As a widely used ML-security baseline for jamming detection in wireless communications, Arjoune et al. report
PD = 97.5% with
PFA = 5.6% for a Random-Forest detector [
38].
Table 4 summarizes these reference results alongside the internal benchmark obtained under matched false-alarm constraints.
Table 4 should be interpreted under the fixed low-false-alarm operating point
PFA ≈ 0.05, which is required for an onboard integrity monitor. Hence, the lower replay detection at β = 0.7 is not a flaw but an expected consequence of a physically consistent photon-counting setting: replay preserves much of the nominal control-segment structure and therefore remains statistically close to
H0 within Poisson variability and channel fluctuations, making moderate replay a limiting hard case for the given feature set and segment length. This conservative behavior indicates that the benchmark does not artificially inflate separability and helps localize the dominant residual risk.
Table 4 also provides the requested performance comparison by aligning the internal benchmark with representative AI/security reference results and by contrasting learning-based detectors with conventional Poisson photon-counting baselines under the same unified model.