1. Introduction
Sensor networks are evolving from simple data-acquisition systems into distributed cyber-physical systems. They now combine exposed sensing nodes, optical front ends, embedded inference, gateways, cloud services, and safety-relevant decision loops. This shift changes the security problem. A sensor network no longer needs only protected packets. It also needs trustworthy device identity, measurement integrity, resilient local inference, lifecycle control, and protection against physical manipulation of exposed sensing hardware and infrastructure. These requirements are well recognized in wireless sensor network, IoT, cyber-physical-system, and operational-technology security guidance [
1,
2,
3,
4,
5,
6].
At the same time, optical and photonic technologies have moved closer to the sensing edge. Modern systems increasingly use optical links, photonic integrated circuits, optical fingerprints, in-sensor processing, photonic edge intelligence, and distributed fiber sensing to acquire, transport, and interpret data [
7,
8,
9]. These developments create an opportunity to reconsider sensor-network security from a hardware-and-physics perspective. Light can carry information, but it can also constrain propagation, expose tampering, generate device-specific responses, compute analog transforms, and observe physical space.
This survey uses the term security by light for mechanisms in which optical or photonic phenomena directly realize, constrain, compute, or observe a security-relevant function. The scope is intentionally broader than optical communication security. It includes photonic roots of trust, visible-light communication (VLC) and LiFi physical-layer security, attack-aware photonic intelligence, reservoir and chaotic photonic transforms, and distributed photonic sensing for intrusion or tamper telemetry. It excludes ordinary cryptographic protocols that merely run over an optical bearer without relying on an optical security property.
Light-enabled mechanisms can strengthen security when they are tied to explicit assets, adversaries, validation settings, lifecycle controls, and conventional security mechanisms. Optical novelty, spatial confinement, analog complexity, or high-dimensional dynamics are not security assurance by themselves. This distinction matters because the reviewed literature contains both direct security evidence and security-adjacent photonic capability. A VLC secrecy-rate paper, a photonic PUF paper, an adversarial ONN paper, a chaotic reservoir paper, and a DAS intrusion paper support different kinds of claims. Treating them as equivalent would overstate the field.
VLC and LiFi security surveys discuss leakage, jamming, rogue transmitters, and physical-layer secrecy [
10,
11]. PUF and hardware-security surveys analyze challenge–response behavior, unclonability, helper data, and key derivation [
12,
13]. Optical neural network and photonic-computing reviews focus on architectures, training, nonlinearities, and implementation constraints [
14,
15]. Reservoir-computing perspectives explain nonlinear dynamical processing and emerging hardware directions [
16]. Distributed-fiber-sensing surveys cover infrastructure monitoring, DAS event recognition, and sensing performance [
17,
18,
19]. These surveys are necessary background, but they do not by themselves provide a security-role synthesis across device identity, optical-link protection, photonic inference assurance, nonlinear optical transforms, and infrastructure telemetry for sensor-networked systems.
This survey makes five contributions:
It defines security by light as a cross-layer security concept for sensor-networked systems.
It provides a structured narrative review with documented scoping searches across arXiv, IEEE Xplore, ACM Digital Library, and Scopus.
It develops a three-axis taxonomy organized by security role, optical mechanism, and deployment layer, with evidence roles used to calibrate claims.
It gives a deep mechanism-family synthesis for photonic roots of trust, VLC/LiFi security, photonic intelligence, reservoir and chaotic photonics, and photonic sensing infrastructure.
It proposes integration patterns, maturity criteria, explicit answers to the research questions, and a research agenda focused on attacker-aware validation, reproducible benchmarking, lifecycle integration, false-alarm control, privacy, and governance.
Positioning Relative to Existing Surveys
The gap identified is that sensor-network security needs a system-layered synthesis. A designer must decide whether a photonic PUF belongs at onboarding, whether a VLC fingerprint can support transmitter authentication, whether a photonic classifier is trustworthy enough to influence policy, whether a chaotic transform has a meaningful leakage argument, and whether a DAS alarm is mature enough to change trust in nearby assets. Existing surveys typically answer one part of that question. This paper connects the parts.
Table 1 positions this paper relative to adjacent survey types.
2. Scope and Review Method
This article is written as a structured narrative review supported by documented scoping searches. It does not claim to be a fully exhaustive systematic review of all optical-security, photonic-hardware, and cyber-physical-security literature. The methodological aim is narrower: to identify, screen, and compare mechanism families in which light or photonic phenomena make a direct or materially relevant contribution to sensor-network security. The review therefore emphasizes traceability of the search logic, explicit separation of evidence roles, and conservative interpretation of security claims. A full PRISMA-style systematic or scoping review protocol [
21,
22] was not used because the paper does not evaluate one narrowly bounded intervention, outcome, technology class, or empirical domain. Instead, it compares heterogeneous mechanism families across photonic hardware identity, optical wireless security, photonic inference, nonlinear optical transforms, and distributed sensing. For this reason, a structured state-of-the-art review with documented scoping searches was considered more appropriate than an exhaustive systematic review protocol.
2.1. Research Questions
The review is organized around five research questions:
RQ1: Which sensor-network security functions can be implemented, strengthened, or materially informed by optical and photonic mechanisms?
RQ2: Which light-enabled mechanism families have direct security evidence, and which are mainly security-adjacent enabling technologies?
RQ3: Which deployment layers best match each mechanism family?
RQ4: What evidence exists for attacker awareness, robustness, calibration burden, scalability, lifecycle integration, and deployment realism?
RQ5: Which research gaps prevent light-enabled mechanisms from becoming dependable security controls?
2.2. Review Scope and Boundaries
The inclusion boundary was security-functional rather than purely optical. A record was considered in scope when it connected an optical or photonic phenomenon to at least one security-relevant function: identity and provenance, optical-link protection and keying, measurement or inference assurance, protected nonlinear transformation, intrusion or tamper telemetry, lifecycle control, or governance-relevant evidence. Ordinary cryptographic protocols that simply run over an optical channel were excluded unless the optical channel or photonic hardware materially changed the security argument.
Two boundary choices are important. First, quantum optical security and quantum key distribution were not treated as a separate mechanism family because they form a mature and specialized field with different assumptions, metrics, and deployment literature. Such records were considered only when they directly affected the sensor-network integration question. Second, light-based attacks against cameras, LiDAR, photodiodes, optical receivers, or optical front ends were considered only when they clarified measurement integrity, photonic inference assurance, or optical-link security. The paper is therefore not a general survey of optical sensor attacks, but it does use attack evidence when it changes the interpretation of a light-enabled security mechanism.
2.3. Databases, Search Logic, and Audit Trail
Searches were conducted in May 2026 across arXiv, IEEE Xplore, ACM Digital Library, and Scopus. IEEE Xplore and ACM Digital Library were included because sensor-network security, physical-layer security, embedded systems, and cyber-physical-security work are strongly represented there. arXiv was included to capture recent preprint-stage work in photonic intelligence, optical wireless security, and photonic hardware security. Scopus was included as the broad bibliographic index used to capture optics, photonics, sensing, and distributed-fiber-sensing records that may appear across specialist publisher platforms. Because publisher-level specialist databases such as Optica Publishing Group, SPIE Digital Library, SpringerLink, ScienceDirect, and Web of Science were not searched as independent sources, the search should be interpreted as a documented scoping strategy rather than an exhaustive systematic search across all possible venues.
Five mechanism families guided the search: photonic roots of trust; optical wireless, VLC, and LiFi security; secure sensing and photonic intelligence; reservoir and chaotic photonics for security; and photonic sensing infrastructure for intrusion monitoring. Broad standalone words such as
optical,
photonic,
fiber, or
security were avoided as independent anchors because they produced many records unrelated to the review question. Instead, searches combined mechanism terms with security-function terms.
Table 2 summarizes the query logic. The core Boolean query strings used for the search are reported in
Table 3. The source-specific fielding adjustments are described below, and the resulting deduplicated screening counts are reported in
Figure 1 and
Table 4.
The source-specific fielding reflected database constraints. arXiv searches used title and abstract fields. IEEE Xplore searches used title, abstract, and index-term variants according to query family. ACM Digital Library searches used title, abstract, and author-keyword fields. Scopus searches used title, abstract, and keyword fields. Records were exported with bibliographic metadata where possible. Search results were then screened by title and abstract, followed by full-text or extended-context review for records retained after the first screening pass.
2.4. Deduplication and Screening
A review record was defined as a unique intellectual contribution relevant to one mechanism family. Duplicate and near-duplicate records were consolidated using DOI, title, author list, venue, year, and substantive overlap. When conference and journal versions appeared to report the same contribution, the most complete or archival version was retained as the primary record unless the earlier version contained distinct security evidence. Preprints were retained when they provided timely evidence not yet available in archival form, but their maturity interpretation was kept conservative.
Records were included when they met three conditions: (i) an optical or photonic mechanism was central rather than incidental; (ii) a security role, attack, fault, trust, or governance implication could be identified; and (iii) the record contributed evidence, terminology, or a boundary condition for sensor-networked systems. Records were excluded when they used generic optical, photonic, fiber, or communication terminology without a security-relevant function; when the security interpretation depended only on unsupported claims of complexity or physical obscurity; or when the work was unrelated to sensor-network deployment layers.
Figure 1 gives the screening flow used for the synthesis. The counts are reported at the deduplicated review-record level after final manual screening. Core/contextual status describes how centrally the record is used in the synthesis, whereas direct/adjacent/background status describes the evidence role assigned during appraisal. These are independent coding dimensions: a contextual record may still clarify a boundary condition, and a core record may still be direct, adjacent, or background/framework evidence depending on the claim it supports.
The final counts differ from an unfiltered bibliography. Some source records were retained as core evidence, some were retained as contextual evidence, and some were excluded even when they contained optical or security vocabulary. For example, a VLC physical-layer pitfalls paper was re-screened and retained because it explicitly analyzes VLC attacker models and the limits of adapting RF physical-layer security mechanisms to VLC [
23]. By contrast, generic sensing or communication papers without a security role were excluded.
2.5. Evidence Roles and Appraisal
A central methodological decision was to separate evidence role from topic relevance. A paper could be relevant to photonics but weak as security evidence. Conversely, a short attack or fault paper could be highly relevant because it clarified the security boundary of a mechanism. The review uses the evidence levels in
Table 5. These levels calibrate the strength of claims made in the synthesis; they are not a quality ranking of the papers themselves.
To make the term
confidence-rated evidence operational, each evidence item was interpreted as an audit record
where
A is the protected asset or trust function,
T is the adversary, fault, or misuse condition,
M is the optical or photonic mechanism,
L is the deployment layer,
is the evidence role from
Table 5,
V is the validation setting,
B records robustness or calibration boundaries,
D records deployment and lifecycle fit,
P records reproducibility conditions, and
records freshness or context of the evidence. This notation is not intended as a cryptographic proof of security. It is a traceability device that prevents a photonic capability claim from being promoted to a security-control claim unless the asset, threat, validation, boundary, and deployment assumptions are visible.
For each retained work, extraction focused on security function, optical mechanism, adversary or failure mode, validation setting, deployment layer, evidence role, and principal limitation. The mechanism-family sections below use direct evidence for demonstrated security claims and adjacent evidence only for architectural plausibility or future research needs. Mechanism-level claims are therefore phrased according to the confidence-rating scheme in
Table 6: direct evidence supports demonstrated or conditional security claims, whereas security-adjacent evidence is used only to motivate integration patterns, design constraints, or future research needs. This is why the paper sometimes treats two technically similar papers differently: one may contain an attacker model and security metric, while the other may only show photonic functionality.
2.6. Methodological Boundaries
Five limitations shape interpretation. First, database fielding and export behavior differ across sources, especially for manual exports. Second, conference and journal versions can appear as duplicate or near-duplicate records. Third, specialist optics and photonics publisher platforms were not searched independently of Scopus, so the search is auditable but not exhaustive. Fourth, mechanism families differ in validation culture: VLC security is often analytic or simulation-heavy, PUF work mixes laboratory prototypes and modeling studies, photonic intelligence includes attack/fault evidence plus platform demonstrations, chaos work mixes communication experiments and transform studies, and DFOS work includes field-like sensing evidence. Fifth, evidence maturity cannot be inferred from publication count alone. It depends on threat-model clarity, validation setting, reproducibility, environmental robustness, deployment realism, and lifecycle fit.
3. Security Requirements and Threat Model for Sensor-Networked Systems
Security in sensor-networked systems is not limited to confidentiality of packets in transit. Measurements are collected by exposed devices, transformed by local computation, transported through heterogeneous links, interpreted by edge or cloud services, and often used to trigger physical actions. An attack may therefore target identity, measurement provenance, optical inputs, local inference, physical infrastructure, or lifecycle processes rather than only network traffic.
3.1. Security Requirements
The first requirement is trustworthy device identity and lifecycle control. Exposed sensors, gateways, replaceable optical modules, and field-installed components can be captured, counterfeited, swapped, or recommissioned over long lifetimes. IoT and WSN security guidance treats identity, configuration, update, and key management as core risks [
1,
2,
3]. Photonic roots of trust are relevant because they can add physical identity evidence to enrollment, onboarding, replacement checks, and re-attestation.
The second requirement is measurement integrity and provenance. In cyber-physical systems, false, delayed, or misattributed data can be as damaging as data theft. NIST cyber-physical and operational-technology guidance treats abnormal process data, sensor manipulation, denial of service, and unsafe actuation as security-relevant because they directly affect physical operation [
4,
5,
6]. Light-enabled mechanisms matter only when they clarify whether a device, measurement path, optical event, or local inference result should be trusted.
The third requirement is optical-link confidentiality, integrity, and availability. VLC and LiFi links may have spatial constraints that differ from RF links, but practical security cannot rest on room confinement alone. Reflections, gaps, windows, receiver sensitivity, rogue transmitters, and jamming can change the attack surface [
23,
24,
25,
26]. Optical wireless security must therefore be analyzed as a direct mechanism family.
The fourth requirement is trust in local and edge intelligence. As sensor networks move toward in-sensor, pre-sensor, and near-sensor processing, the security boundary includes model parameters, optical input encoding, calibration state, laser sources, memory, electronic control, and fallback behavior [
8,
27]. Photonic inference can reduce latency, but it can also become an attack surface.
The fifth requirement is infrastructure-level situational awareness. Distributed photonic sensing can detect vibration, intrusion, cable disturbance, and route-level events over long distances, including through deployed telecom fibers [
28,
29,
30]. This makes DAS and DFOS relevant to security, but only if alerts are reliable enough to support policy, verification, or incident response.
3.2. Connection to IoT Security Architecture, Zero Trust, and Cyber-Physical Resilience
The security-by-light framing is intended to complement, not replace, established cybersecurity architecture. In zero-trust architecture, access decisions are made per request and depend on explicit identity, device state, policy, and contextual evidence rather than implicit network location [
31]. Light-enabled evidence can therefore be interpreted as an additional physical or cyber-physical signal that helps a policy engine evaluate device authenticity, link exposure, inference trust, or infrastructure state. Similarly, IoT security baselines and cybersecurity frameworks emphasize device identity, secure configuration, update capability, vulnerability management, monitoring, incident response, and governance [
3,
32,
33]. Photonic roots of trust, VLC/LiFi fingerprints, photonic fault indicators, and DAS/DFOS events are useful only when they are mapped to these conventional security functions.
The same interpretation applies to cyber-physical resilience and digital-twin security. Cyber-physical frameworks treat trustworthiness, lifecycle, physical process state, safety, and security as coupled concerns [
34]. Digital twins and AI-enabled IoT systems increase the need for trustworthy measurement streams, model-state integrity, and continuous validation because decisions may be made from synchronized physical and virtual representations or from near-edge AI models [
35,
36]. Security by light contributes to this architecture by providing confidence-rated physical evidence, not by becoming a parallel security architecture. The evidence-to-policy model in
Section 10 is therefore a bridge between photonic mechanisms and mainstream cybersecurity control, resilience, and governance frameworks.
3.3. Threat Model
The threat model spans five layers. At the device layer, an adversary may capture a node, extract stored credentials, replace a legitimate component, insert a counterfeit module, or query a PUF repeatedly to learn a model. Photonic roots of trust address this layer by adding optical identity evidence, but the evidence must survive environmental variation, modeling attacks, and reader compromise [
37,
38,
39].
At the sensing layer, an adversary may inject false optical inputs, blind a detector, saturate a front end, spoof environmental features, or exploit calibration drift. This includes attack patterns against cameras, LiDAR-like front ends, photodiodes, optical receivers, and vision-oriented sensing modules when the attack changes measurement integrity or inference reliability. At the optical-link layer, an adversary may eavesdrop through reflected paths, use a high-sensitivity receiver, jam visible-light channels, inject rogue optical signals, or manipulate key-extraction assumptions. At the photonic-compute layer, an adversary may perturb optical inputs, exploit physical nonidealities, induce laser faults, corrupt memory, or compromise control electronics around a photonic accelerator [
40,
41,
42,
43,
44,
45]. At the infrastructure layer, an adversary may disturb, tap, cut, or physically approach optical assets. Distributed fiber sensing can supply physical telemetry, but it must handle nuisance events, false alarms, privacy, and response integration.
Table 7 summarizes the threat-to-mechanism mapping used in the synthesis.
4. Light-Enabled Security Taxonomy
The taxonomy uses three axes: security role, optical mechanism, and deployment layer. A fourth interpretation column records the evidence condition needed before the mechanism can be treated as a security control. The taxonomy is intentionally security-led. It prevents a common error in emerging photonic-security work: assuming that a mechanism is secure because it is optical, complex, analog, high-dimensional, or hard to visualize.
4.1. Axis I: Security Role
The security-role axis asks what the optical mechanism is supposed to do for the security architecture. The roles are identity and provenance, optical-link protection and keying, photonic inference assurance, secure transforms and entropy, and infrastructure telemetry. Each role corresponds to a different security question. Identity asks whether a device, module, path, or tag is genuine. Link protection asks whether optical propagation or transmitter behavior can reduce leakage or improve availability. Inference assurance asks whether a photonic processor can be trusted under adversarial and physical perturbation. Transform and entropy mechanisms ask whether nonlinear dynamics provide defensible security-relevant processing. Infrastructure telemetry asks whether optical-sensing events can support physical-security decisions.
4.2. Axis II: Optical Mechanism
The optical-mechanism axis describes the physical source of evidence: scattering, speckle, material disorder, photonic fabrication variation, LED or circuit fingerprints, constrained optical propagation, optical beamforming, artificial noise, photonic neural computation, reservoir dynamics, laser or electro-optic chaos, distributed Rayleigh backscatter, and fiber event classification. Mechanisms differ physically, but the review treats them comparably by asking what security property they support and under which assumptions.
4.3. Axis III: Deployment Layer
The deployment layer can be a sensor device, replaceable module, optical transceiver, optical link, access point, gateway, edge accelerator, deployed fiber route, or infrastructure corridor. The same mechanism can have different security meaning at different layers. For example, an LED fingerprint may authenticate a VLC transmitter at the link layer, while a fiber fingerprint can verify a physical path. DAS can monitor a corridor, but its output becomes security evidence only when integrated with policy and response.
Table 8 summarizes the resulting light-enabled security taxonomy.
5. Photonic Roots of Trust: PUFs, Optical Fingerprints, and Lifecycle Identity
Photonic roots of trust are the most direct example of security by light. They use disorder, fabrication variation, scattering, speckle, nonlinear response, or device-specific optical behavior as authentication material. The general idea follows physical one-way functions and PUFs: a physical object produces responses that are easy to verify through measurement but difficult to clone or predict without the object [
12,
46]. In photonic versions, light probes microscopic structure, waveguide disorder, spectral response, material randomness, or path-dependent scattering.
This family is attractive for sensor networks because exposed nodes often cannot rely only on stored digital secrets. A captured or replaced node may present valid software credentials if those credentials are extracted. A photonic PUF or optical fingerprint adds a physical evidence channel. It can support device enrollment, module replacement checks, supply-chain assurance, re-attestation, and in some cases key derivation. In the confidence-rating terminology of
Table 6, modeling-attack and prototype authentication studies are treated as direct evidence for identity claims, while label, material, or platform demonstrations without explicit attacker or lifecycle evaluation are treated as security-adjacent evidence.
5.1. From Optical Uniqueness to Root of Trust
Optical uniqueness is not enough. A root of trust requires repeatability for the legitimate device, separation among devices, resistance to cloning or emulation, and a protected protocol around enrollment and verification. Early optical one-way functions established the intuition that random optical media can produce hard-to-clone challenge–response behavior [
46]. Later work made the measurement and assurance problem more explicit. Lio et al. quantified sensitivity and unclonability in optical PUFs, showing that physical perturbations could produce measurable response separation [
47]. This kind of quantification is essential because visual complexity alone does not establish security.
Integrated photonic PUFs move the concept toward deployable sensor-network hardware. Grubel et al. demonstrated a silicon photonic PUF based on nonlinear interactions in a chaotic microcavity [
48]. Tarik et al. advanced the deployment argument by demonstrating scalable and CMOS-compatible silicon photonic PUFs for supply-chain assurance [
49]. Mahdian et al. framed silicon photonic PUFs as hardware-assurance mechanisms for optical systems, which is especially relevant to photonic modules and trusted interfaces [
50].
5.2. Device Classes and Deployment Fit
The screened literature indicates four deployment-relevant classes. For readability,
Table 9 splits the first class into two subgroups: integrated silicon photonic PUFs and nonlinear or amorphous-silicon PUFs. These are not intended as two separate deployment classes but as two evidence subgroups within integrated photonic roots of trust. The first is integrated silicon or amorphous-silicon photonic PUFs. These are natural candidates for photonic modules, secure chiplets, optical transceivers, and sensor nodes because the security primitive can be close to the physical sensing or communication hardware [
38,
48,
49,
50]. The second is material, label, or metasurface PUFs for anti-counterfeiting and object identity. Cholesteric reflectors, multilevel polymer PUFs, all-silicon multidimensional optical PUFs, and FRET-based quantum-dot PUFs illustrate the range of optical label designs [
51,
52,
53,
54]. The third is programmable or reconfigurable photonic PUFs, which offer flexibility but introduce control-plane risk because programmability expands the state that must be protected [
55]. The fourth is fiber or subsystem fingerprinting, where the trusted object is an optical path, reader, or subsystem rather than only an endpoint device [
56,
57].
5.3. Modeling Resistance and Machine Learning Attacks
The main scientific shift in photonic roots of trust is from uniqueness claims toward attacker-aware evaluation. If an attacker can collect enough challenge–response pairs and learn a predictive model, a visually complex optical PUF may still fail as a security primitive. This is why modeling-resistance papers are central to the maturity of the family. Albright et al. analyze learnability of optical PUFs through a learning-with-errors perspective, showing why PUF security depends on the physical response distribution and the challenge space [
37]. Kilic et al. investigate machine learning attacks against amorphous-silicon photonic PUFs and relate resistance to nonlinear response [
38]. Atakhodjaev et al. and Henderson et al. provide design-specific evidence that nonlinear silicon or photonic PUFs can resist tested learning attacks under stated settings [
39,
58].
The correct conclusion is not that photonic PUFs are generally secure against machine learning. The conclusion is that photonic PUF security must be evaluated like cryptographic engineering in physical hardware: define attacker access, bound query exposure, report modeling baselines, account for noise and helper data, and connect the PUF output to an authenticated protocol.
5.4. Lifecycle Integration
For sensor networks, the strongest deployment role is lifecycle security. A photonic root of trust can be enrolled during manufacturing or commissioning, verified during onboarding, rechecked during maintenance, and used to support revocation or replacement decisions. This maps to trusted onboarding guidance, which treats device identity and posture verification as prerequisites for credential provisioning and lifecycle management [
59,
60]. The PUF is not the onboarding protocol. It is a physical evidence source used by the protocol.
Several practical issues remain. Helper data and fuzzy extraction may be necessary when noisy responses are stabilized as cryptographic keys [
13]. The reader or verifier must be trusted, because a compromised reader can leak challenges or responses. Environmental drift and packaging variation must be part of acceptance testing. A fleet-scale deployment also needs revocation, update, re-enrollment, and auditability. These are not weaknesses unique to photonic PUFs, but they determine whether optical uniqueness becomes operational security.
6. Optical Wireless, VLC, and LiFi Security
VLC and LiFi security deserve a full mechanism-family section because the screened evidence base shows dense direct security work on eavesdropping, jamming, secrecy, artificial noise, fingerprints, key extraction, and LiFi-assisted bootstrapping. The security contribution comes from optical propagation, illumination constraints, transmitter hardware, receiver placement, and channel conditions. These are physical properties, not merely data-link details. Most mechanism-level claims in this section are therefore C2 or C3 claims: leakage experiments and transmitter-fingerprint studies provide direct evidence for tested settings, while secrecy-rate, jamming, RIS/IRS, and key-extraction results remain conditional on geometry, receiver assumptions, and protocol binding.
6.1. Limitations of Room-Confinement Assumptions
VLC is often described as naturally secure because light does not penetrate opaque walls. That statement is incomplete. Classen et al. experimentally showed that VLC transmissions can be intercepted through reflected paths, gaps, and windows, including cases where the eavesdropper is outside the direct beam [
24]. Marin-Garcia et al. further analyze practical eavesdropping scenarios in VLC systems [
25]. Classen et al. also argue that RF physical-layer-security mechanisms cannot simply be transferred to VLC without modeling VLC-specific attacker capabilities, blockage, reflections, and receiver hardware [
23]. Rogue-transmitter work adds an integrity dimension: the optical channel can be attacked not only by listening but also by injecting unauthorized visible-light signals [
26].
The implication is precise. VLC and LiFi can reduce some exposure compared with RF in some environments, but security depends on geometry, surfaces, receiver field of view, sensor sensitivity, illumination constraints, mobility, and adversary placement. A secure sensor-network design should specify those assumptions rather than relying on generic confinement language.
6.2. Secrecy, Jamming, and Artificial Noise
The physical-layer-security literature uses secrecy rate, jamming, beamforming, artificial noise, and reflective-surface control to shape what legitimate and illegitimate receivers can observe. Mostafa and Lampe show friendly jamming as a means to improve VLC secrecy under optical constraints [
61]. Pham et al. study artificial-noise design for VLC channels with clipping, explicitly accounting for LED dynamic-range effects [
62]. Guo et al. study RIS-aided physical-layer security for VLC, showing how controllable optical reflection can shape secrecy assumptions [
63].
These mechanisms support direct security claims only under stated channel models. Many studies assume knowledge of eavesdropper channels, fixed geometry, or simulation settings. In sensor networks, the practical question is how secrecy mechanisms behave under changing room layout, lighting constraints, mobility, device aging, and limited receiver information. The evidence is therefore strong for the existence of optical wireless countermeasures but more conditional for deployment-ready security.
6.3. Transmitter Fingerprints and Optical Device Identity
VLC and LiFi also connect naturally to identity. LED fingerprints and optic fingerprints use transmitter-specific behavior as a device-identification signal. Shi et al. demonstrate LED fingerprint extraction and identification for VLC systems [
64]. Chen et al. propose optic fingerprints that use inherent circuit and optical characteristics of VLC devices for physical-layer identification [
65]. These works shift optical wireless security from channel secrecy alone to transmitter provenance.
The design caution mirrors PUFs. A fingerprint is useful only if it remains stable under temperature, aging, drive circuits, replacement, and maintenance. It also needs a protocol role. A gateway can use an LED fingerprint to detect an unexpected transmitter, but the fingerprint should complement cryptographic authentication and logging rather than replace them.
6.4. Key Extraction and LiFi-Assisted Bootstrapping
Optical channel randomness can also support key extraction or bootstrapping. AquaKey uses underwater visible-light channel variation for symmetric key extraction and demonstrates reliable key generation under its experimental conditions [
66]. This is direct evidence that optical channel conditions can contribute to key material in a specific environment. It does not imply that arbitrary VLC links have enough reciprocal randomness for key extraction.
LiFi-assisted bootstrapping extends the idea by using a local optical channel to help secure another wireless protocol. LightGuard illustrates this direction by using LiFi as a physical-layer bootstrapping channel for WiFi security, but it should be treated as preprint-stage demonstration evidence until archival and independent validation are available [
67]. The architectural value is still important: optical locality can help bootstrap trust, but only when the resulting protocol has authentication, replay protection, downgrade handling, and fallback behavior.
Table 10 summarizes the main VLC and LiFi security directions and their conditions.
7. Secure Sensing and Photonic Intelligence
Photonic intelligence moves computation into or near the optical sensing path. It can reduce latency, energy, and raw-data movement, but it also makes optical inference part of the security boundary. This section separates two claims: photonic inference as a platform capability, and assurance of photonic inference under attack or fault. Accordingly, platform-capability papers are treated as C1 security-adjacent evidence unless they evaluate an explicit adversarial, fault, calibration, or drift condition; attack and fault studies are treated as C2 or C3 evidence depending on validation realism.
7.1. Platform Capability and Security Relevance
Optical neural networks and photonic processors can perform linear operations, convolution-like transforms, image classification, and pre-sensor computation with high optical bandwidth [
14,
15]. In-sensor photonic intelligence and photonic edge intelligence extend this idea to sensing systems, where optical computation can occur before full digitization or before raw data leave the device [
7,
8]. Wang et al. and Huang et al. illustrate image sensing and pre-sensor optical computation directions that can reduce data movement and latency [
68,
69]. Baek et al. provide broader edge-intelligence context for why near-sensor processing matters in distributed systems [
27].
These works support architectural plausibility. They show why photonic intelligence could help a sensor network screen events close to the physical signal. They do not by themselves establish security. A fast optical classifier is a security component only when its inputs, model, calibration, faults, and outputs are evaluated under security assumptions.
7.2. Attack Surface of Photonic Learning Systems
Direct security evidence comes from attack and fault studies. Li et al. show that diffractive neural networks can be vulnerable to physical adversarial examples [
40]. Jiao et al. analyze adversarial attacks on optical neural networks [
41]. Chen et al. develop physics-aware adversarial evaluation, which is important because optical perturbations are constrained by physical propagation rather than arbitrary digital pixel changes [
42]. These studies show that optical inference does not escape adversarial-machine-learning problems. It changes their physical form.
Photonic accelerators introduce additional hardware attack surfaces. De Magalhaes et al. analyze attacks on photonic AI hardware [
43]. Nishida et al. study laser fault attacks, and Queiroz et al. examine memory faults in photonic neural-network contexts [
44,
45]. Lu et al. show that photonic nonidealities can affect adversarial behavior and may sometimes contribute to robustness in specific settings [
70]. The correct interpretation is conditional: physical nonidealities can matter for defense, but they do not create universal robustness.
7.3. Use in Sensor Networks
In sensor networks, photonic intelligence is most defensible as a confidence-rated policy input. It can flag an abnormal optical waveform, classify a local event, estimate confidence before forwarding data, or trigger fallback sampling. It should not be a single point of trust. A policy layer should compare photonic inference with device identity, network telemetry, conventional anomaly detection, and infrastructure context. This is especially important for safety-relevant systems, where a high-speed but poorly calibrated optical model could amplify an attack or fault.
Table 11 summarizes the evidence types and security interpretation for photonic intelligence.
8. Optical Reservoir Computing, Chaotic Photonics, and Secure Transforms
Reservoir and chaotic photonics attract security interest because they provide high-dimensional dynamics, synchronization behavior, entropy-like signals, and difficult-to-invert transformations. These properties can be useful, but they are not security proofs. A security claim requires an adversary, an observable channel, a leakage metric, and a comparison baseline. For this reason, this section assigns higher confidence only to studies that include leakage, time-delay-signature, synchronization, or attacker-observation analysis; transform or source-separation papers without such analysis remain C1 security-adjacent evidence.
8.1. Chaos Communication and Protected Links
Chaos communication is the most established security-relevant direction in this family. Mirasso et al. review chaos-based encryption and communication concepts [
20]. Argyris et al. demonstrate chaos-based optical communication over commercial fiber networks, showing that synchronized chaotic carriers can support protected optical links under stated conditions [
71]. Mao et al. demonstrate high-rate optical chaos communication over long fiber transmission using semiconductor lasers [
72]. These works provide direct evidence that chaotic optical links can be built and recovered by legitimate receivers.
The assurance question is what an attacker observes and what can be inferred. If the evaluation only shows that the legitimate receiver can recover the signal, it does not fully establish confidentiality. Stronger claims require leakage analysis, key or parameter secrecy assumptions, synchronization robustness, and comparison with conventional cryptographic or coding baselines.
8.2. Time-Delay Signatures and Leakage
Time-delay signatures illustrate how a physical feature can become a security-relevant leakage channel. Cheng et al. study time-delay concealment in electro-optic chaos [
73]. Huang et al. analyze electro-optic chaos systems designed to be immune to time-delay signatures [
74]. Gong et al. show time-delay signature extraction using reservoir computing from short and noisy time series [
75]. Together, these works support a mature security principle: concealment claims should be tested against increasingly strong extraction methods.
8.3. Reservoir-Assisted Transforms and Keying Primitives
Reservoir-assisted secure communication and transforms are promising but heterogeneous. Liu et al. study reservoir-based secure communication [
76]. Zhu et al. propose security-enhanced electro-optic chaos using reservoir ideas [
77]. Zaminga et al. address optical chaotic recovery [
78]. Jiang et al. use optical reservoir computing for image transformation, and Shao et al. discuss optical chaos key-distribution primitives [
79,
80]. A recent source-separation chaotic optical communication architecture by Zhu et al. is relevant as contextual or adjacent evidence for reservoir-based decryption architecture, but this review does not treat it as direct proof of attacker-side security assurance without stronger leakage validation [
81].
Table 12 summarizes the security-relevant value and assurance gaps for reservoir and chaotic photonics.
9. Photonic Sensing Infrastructure for Safety and Security Monitoring
Distributed photonic sensing is the most deployment-facing family in the review. DAS, DFOS, phase-sensitive optical time-domain reflectometry, PON sensing, and DWDM sensing can monitor long physical routes and infrastructure [
9,
17,
18,
82]. This makes photonic sensing relevant to security, but the evidence must be interpreted carefully. A deployed sensing substrate is not automatically a validated security-control input. Intrusion and field-sensing papers can support C2 or C3 sensing-performance claims, but they support lower-confidence security-decision claims unless false-alarm handling, incident-response interfaces, privacy constraints, and cross-site transfer are specified.
9.1. From Securing Devices to Securing Space
Photonic sensing expands security from endpoint trust to spatial awareness. A fiber route can detect vibration, intrusion, cable tamper, or disturbance near assets. This is important for sensor networks deployed along pipelines, railways, perimeters, utilities, telecom routes, and restricted corridors. The security value is not only that the fiber detects an event. The value is that the event can change trust in nearby devices, trigger verification, dispatch response, or correlate physical and cyber evidence.
9.2. Intrusion Evidence, Deployment Evidence, and Standards Evidence
The evidence separates into three groups. The first is intrusion-detection evidence. Several intrusion-oriented studies support detection, localization, and classification of intrusion-like or perimeter events using fiber-optic sensing [
28,
83,
84,
85]. The second is deployment and coexistence evidence. Han et al. and Kotrla et al. show the relevance of telecom-cable and deployed-network sensing, while Tang et al. and Wang et al. address PON and DWDM service-oriented sensing [
9,
29,
30,
82]. The third is standards and operational-interface evidence. Wakisaka et al. discuss ITU-T work relevant to DFOS, which helps operationalization but does not validate intrusion analytics by itself [
86].
AI-assisted event interpretation adds another layer. Jeong et al., Cao et al., and Wu et al. show how graph diffusion, AI/ML, and multitask learning can improve distributed-sensing event interpretation [
19,
87,
88]. These methods are useful, but they inherit the same security questions as other inference systems: domain shift, label scarcity, nuisance events, adversarial conditions, and calibration.
9.3. Policy-Ready Security Telemetry
The main integration challenge is to turn sensing alerts into policy-ready evidence. A DAS event should carry location, confidence, event type, uncertainty, and operational context. It may lower trust in nearby devices, trigger re-attestation, request camera verification, initiate maintenance, or escalate incident response. It should not automatically become a security decision without false-alarm management and governance. This is also a privacy issue: wide-area fiber sensing can reveal human activity and operational patterns, so access control, retention, auditability, and acceptable-use policy are necessary [
89,
90].
Table 13 summarizes the evidence types and security interpretation for photonic sensing infrastructure.
10. System Integration and Evidence-to-Policy Architecture
The mechanism-family sections show that light-enabled security is not a single technology. It is an evidence architecture. Photonic roots of trust, VLC/LiFi security, photonic inference, reservoir or chaotic transforms, and distributed fiber sensing all produce different types of evidence. Their practical value depends on whether this evidence is consumed by onboarding protocols, gateway policy, cryptographic workflows, anomaly detection, fallback logic, incident response, and governance. In this architecture, confidence-rated evidence is the policy-facing representation of an optical or photonic observation after it has been annotated with its asset, threat/failure mode, evidence level, validation setting, calibration boundary, lifecycle relevance, and reproducibility condition.
10.1. Integration Principles
Four principles guide integration. First, use layered trust rather than single-point trust. A photonic PUF, an LED fingerprint, a photonic classifier, or a DAS alarm should normally complement rather than replace cryptographic authentication, access control, and monitoring. Second, design for lifecycle. Enrollment, onboarding, re-attestation, update, replacement, retirement, and audit determine whether an optical primitive remains useful over time [
59,
60]. Third, enforce security at resource boundaries. This is consistent with zero-trust thinking, where resource access is continuously evaluated rather than assumed from location [
31]. Fourth, require fallback and auditability. If an optical mechanism loses calibration, produces low confidence, or conflicts with other telemetry, the system should enter a restrictive and reviewable state rather than silently accepting the optical output.
10.2. Integration Patterns
Four recurring patterns follow from
Figure 2.
Device-anchored trust places photonic roots of trust at device, module, or path boundaries; it is strongest for supply-chain assurance, exposed nodes, replaceable sensing heads, and optical modules [
49,
50,
57].
Optical-link protection treats the optical channel as a security surface, combining VLC/LiFi leakage analysis, jamming state, fingerprinting, key extraction, and optical bootstrapping with authenticated protocols.
Photonic inference as policy input uses a photonic front end or accelerator to estimate confidence, detect abnormal optical inputs, classify events, or trigger fallback; this pattern is plausible only when adversarial, fault, drift, and calibration behavior are measured [
42,
44,
70].
Infrastructure-aware security overlay uses distributed photonic sensing to provide spatial context so that DAS or DFOS events can adjust trust in nearby assets, request re-attestation, trigger inspection, or correlate cyber alerts with physical disturbance.
Table 14 summarizes the four integration patterns associated with this evidence-to-policy architecture.
11. Comparative Evaluation, Maturity, and Research Agenda
Comparing light-enabled mechanisms is difficult because the families differ in physics, metrics, validation setting, and deployment layer. A PUF paper may report false acceptance and response stability. A VLC paper may report secrecy rate. A photonic intelligence paper may report adversarial accuracy or fault detection. A chaos paper may report synchronization quality or leakage indicators. A DAS paper may report event classification and false alarms. These metrics cannot be pooled, but they can be interpreted through common evaluation dimensions. To make this comparison explicit, this paper uses a structured qualitative scoring scheme. The scoring is not a universal quantitative performance metric; it is a transparency device that shows which dimensions drive the maturity judgment for each mechanism family.
11.1. Cross-Cutting Evaluation Dimensions
The first dimension is security assurance: the protected asset, adversary, security metric, and validation setting. The second is operational performance: latency, energy, throughput, footprint, calibration, and maintenance burden. The third is environmental robustness: temperature, aging, alignment, illumination, turbulence, site conditions, and drift. The fourth is deployment fit: where the mechanism belongs in the network and which protocol or policy consumes it. The fifth is reproducibility: whether results can be checked beyond one bench setup, one device batch, one simulated geometry, or one field site.
Table 15 summarizes these cross-cutting evaluation dimensions.
Table 16 defines the ordinal scoring criteria used for the maturity synthesis.
11.2. Maturity and Research Priorities
The maturity view is qualitative because validation cultures differ across mechanism families. It is not a ranking of scientific importance. It indicates how close the evidence is to a dependable security-control role. The criteria in
Table 16 are applied in
Table 17, which combines maturity interpretation with the research agenda to avoid repeating the same family-level conclusions in separate tables.
These maturity dimensions should be interpreted as horizontal requirements across all mechanism families rather than as an additional mechanism category. Reproducibility, benchmark transparency, privacy, governance, lifecycle reporting, and explicit threat assumptions influence the confidence that can be assigned to every family in
Table 17. A mechanism with strong laboratory evidence may therefore still receive a limited maturity interpretation if these cross-cutting conditions are weakly reported or absent.
Across all families, the same evaluation discipline is needed: state the protected asset, adversary, deployment layer, assumptions, and failure mode. This is especially important for reservoir and chaotic photonics, where synchronization, concealment, and time-delay behavior must be related to explicit leakage and attacker observations [
73,
74,
75]. It is also important for VLC/LiFi, where leakage and secrecy depend on physical geometry rather than only nominal room confinement [
23,
24,
25,
62]. Finally, it is necessary for distributed photonic sensing, where a fiber event becomes security evidence only when confidence, location, false-alarm behavior, and operational meaning are clear [
28,
29,
84,
86].
Privacy and governance cut across the mechanism families. Light-enabled security can expand observability over devices, infrastructure, and human activity. Governance should address access control, data minimization, retention, auditability, acceptable use, and AI risk management [
89,
90]. This is especially important when distributed fiber sensing and photonic inference feed operational decision systems.
12. Synthesis of Research Questions
Table 18 summarizes the answers to the research questions. Confidence reflects the screened evidence base and appraisal rubric, not a claim of field-wide completeness.
13. Conclusions
This review examined security by light as a structured design space for sensor-networked systems. The evidence supports five roles: physical identity and provenance, optical-link protection and keying, assurance of photonic inference, nonlinear transforms and synchronization, and infrastructure-scale physical telemetry. The contribution is not a claim that light replaces conventional security engineering. It is a framework for deciding where optical and photonic mechanisms can add defensible evidence to a layered security architecture.
The most important conclusion is that optical evidence must be interpreted according to its security role. Photonic roots of trust provide identity evidence only when modeling resistance, protected readers, helper data, and lifecycle integration are addressed. VLC and LiFi mechanisms provide optical-link evidence, but operational claims depend on geometry, receiver assumptions, and authenticated protocol binding. Photonic intelligence is relevant when evaluated as an attackable inference substrate, not merely as a fast optical classifier. Reservoir and chaotic photonics offer protected-link and transform components only when leakage and attacker observations are explicit. Distributed photonic sensing is comparatively mature as sensing infrastructure, but its security value depends on false-alarm control, cross-site transfer, privacy, and response integration.
The architectural implication is that light-enabled mechanisms are strongest as confidence-rated evidence sources. Their dependable use requires conventional cryptography, secure onboarding, access control, monitoring, fallback, incident response, and governance. Future work should therefore make security semantics explicit, validate against realistic adversaries, report reproducible physical conditions, and design interfaces that turn optical evidence into auditable security decisions.