---
title: Artificial Noise in Physical-Layer Security
url: https://www.emergentmind.com/topics/artificial-noise-an
type: topic
---

# Artificial Noise in Physical-Layer Security

Searching arXiv for recent and foundational papers on artificial noise in physical-layer security.
Artificial noise (AN) is a purposely generated interference signal injected by the legitimate transmitter, or by cooperating legitimate nodes, to degrade an eavesdropper’s channel while minimally affecting the legitimate receiver. In contemporary physical-layer security, AN is treated as a multi-domain security primitive rather than a single null-space jamming heuristic: it appears in MIMO wiretap beamforming, robust secrecy-rate maximization, training design, relay and full-duplex protocols, OFDM over heterogeneous media, visible-light systems with clipping, integrated sensing and communications, RIS-assisted links, and near-field beam focusing [2507.06500].

## 1. Canonical signal model and secrecy objective

In its most compact form, AN augments the confidential transmit signal by superposition. A standard model writes
$$
\mathbf{x}=\mathbf{s}+\mathbf{n},
$$
with $\mathbb{E}\{\mathbf{s}\mathbf{s}^H\}=Q_s$, $\mathbb{E}\{\mathbf{n}\mathbf{n}^H\}=Q_n$, $\mathbb{E}\{\mathbf{s}\mathbf{n}^H\}=0$, and $\operatorname{Tr}(Q_s+Q_n)\le P$. Bob and Eve receive
$$
\mathbf{y}=h_b^H\mathbf{x}+\mathbf{u},\qquad \mathbf{z}=h_e^H\mathbf{x}+\mathbf{v},
$$
and a standard secrecy-rate lower bound is
$$
R_s=[R_b-R_e]^+.
$$
The central design principle is to reduce the wiretap-channel capacity without materially reducing the legitimate-channel capacity [2507.06500].

For the classical MIMO AN construction, the legitimate channel matrix is decomposed as
$$
\mathbf{H}=\mathbf{U}\boldsymbol{\Lambda}\mathbf{V}^H,\qquad \mathbf{V}=[\mathbf{V}_1\ \mathbf{Z}],
$$
and the transmit vector is chosen as
$$
\mathbf{x}=\mathbf{V}_1\mathbf{u}+\mathbf{Z}\mathbf{v}.
$$
Because $\mathbf{H}\mathbf{Z}=\mathbf{0}$, Bob sees no AN, whereas Eve observes both the information-bearing signal and the AN term. This null-space design underlies the original Goel–Negi formulation revisited in later large-system analyses of average and instantaneous secrecy rate [1402.2091].

The standard null-space picture is not exhaustive. The survey literature distinguishes orthogonal AN, where AN is placed in Bob’s channel null space, from non-orthogonal AN, where AN is jointly optimized with the information beamformer when Eve CSI is partially or fully available [2507.06500]. This distinction is fundamental because many later results depart from strict orthogonality.

## 2. Core design paradigms

The most studied paradigm is joint beamforming and AN covariance design under a total power budget. In robust MISO secrecy with perfect CSI for Bob and uncertain CSI for multiple single-antenna eavesdroppers, the worst-case secrecy-rate maximization is formulated as
$$
R^*(P)=\max_{W\succeq0,\ \Sigma\succeq0,\ \operatorname{Tr}(W+\Sigma)\le P}\ \min_{k=1\ldots K} f_k(W,\Sigma),
$$
where $W$ is the signal covariance and $\Sigma$ the AN covariance. Because each Eve channel lies in an uncertainty set $B_k=\{g_k:\|g_k-\bar g_k\|_2\le \epsilon_k\}$, the problem is non-convex and semi-infinite; nevertheless, it admits a reformulation based on a slack variable $\beta$, Charnes–Cooper transformation, and the S-procedure, leading to a one-dimensional line search over SDPs. The optimal $W$ is rank one, implying that transmit beamforming is secrecy-rate optimal in the considered robust setting [1104.4260].

A second paradigm generalizes the conventional orthogonal design by permitting AN in the main-channel direction. For the fast-Rayleigh-fading MISO wiretap channel with perfect knowledge of $\mathbf{h}$ and only statistics of $\mathbf{g}$, the optimal message covariance is rank one and aligned with $\mathbf{h}$,
$$
\mathbf{Q}_s^*=\frac{P_U}{\|\mathbf{h}\|^2}\mathbf{h}\mathbf{h}^H,
$$
while the AN covariance shares the eigenbasis $\{\mathbf{h}/\|\mathbf{h}\|,\mathbf{h}_1^\perp,\ldots,\mathbf{h}_{n_T-1}^\perp\}$. This generalized AN-assisted beamforming enlarges the non-zero-secrecy regime relative to the original orthogonal-only construction, especially when the legitimate channel is much worse than the eavesdropper’s [1202.5830].

AN is also not confined to multi-antenna transmitters. In a single-antenna quasi-static fading system, Bob can seed AN in Phase 1 and Alice can forward a normalized version of the received AN jointly with the confidential symbol in Phase 2:
$$
x_a=\sqrt{\alpha}\,s+\sqrt{1-\alpha}\,\frac{y_{a,1}}{|y_{a,1}|}.
$$
Bob reconstructs and subtracts the forwarded AN exactly, whereas Eve cannot. In the related full-duplex-source model, Alan and Bob send AN simultaneously in Phase 1, and Alan transmits the mixed signal
$$
x_A^{(2)}=\sqrt{P_s}\,s_A+y_A
$$
in Phase 2; Bob cancels the AN component that depends on his own seed, but Eve retains substantial residual interference [1705.03036; 1710.06985].

A further paradigm places AN in the training phase. In discriminatory channel estimation, forward pilots are superimposed with AN in the null space of the source’s estimate so that Bob keeps a better CSI estimate than Eve. This creates a deliberate CSI gap before data transmission, after which secrecy beamforming and data-phase AN are performed on top of that asymmetry [1511.01791].

## 3. Optimization structure and mathematical machinery

AN design problems are usually fractional, coupled, and non-convex. The literature therefore relies on a comparatively stable toolkit. Robust worst-case SRM uses Charnes–Cooper, the S-procedure, LMIs, and a one-dimensional search over $\beta$ with SDP subproblems solvable in polynomial time; its KKT structure additionally yields the rank-one optimality of the signal covariance [1104.4260]. In clipping-aware visible-light systems, the same Charnes–Cooper device appears together with the convex-concave procedure (CCP) after the Bussgang-equivalent attenuation and clipping-noise terms are frozen at precomputed worst-case values [2210.00438].

Low-complexity designs often arise by decoupling geometry from power allocation. In near-field terahertz communications, the secrecy-rate maximization is reduced to two one-dimensional focus-point searches,
$$
\max_{(r_S,\theta_S)}\rho_1^2/\rho_3^2,\qquad \max_{(r_A,\theta_A)}\rho_4^2/\rho_2^2,
$$
followed by a closed-form power split $\alpha^*$ obtained from a quadratic condition on $\frac{dR_s}{d\alpha}=0$. This converts a coupled non-convex joint design into two searches of complexity $\mathcal{O}(NM)$ plus an $\mathcal{O}(1)$ power update [2502.08967].

When the architecture itself is hybrid or sparse, AN optimization is embedded in alternating optimization. In near-field FA-MIMO with fluid antennas, the secrecy-rate problem is split into a continuous BF+AN subproblem and a discrete port-selection subproblem. The continuous step uses BCD surrogates and generalized spectral water-filling; the discrete step uses a row-energy prune–refit rule aligned with KKT conditions of a group-sparsity surrogate [2512.02461]. In massive MIMO–NOMA, secrecy-rate and energy-efficiency formulations lead to block-coordinate updates across uplink training power and downlink power, with successive convex approximation and Dinkelbach’s transform for the fractional EE objective [1903.05752].

The methodological pattern is consistent across domains: AN design is rarely solved in its native form. It is transformed into convex surrogates, one-dimensional searches, alternating blocks, or asymptotically justified closed forms. This suggests that AN has evolved from a subspace intuition into an optimization-centered design problem.

## 4. Representative system realizations

In hybrid parallel PLC/wireless OFDM, the physical decoupling of media is itself exploited as an AN resource. Bob sends AN on the lower-CNR medium, while Alice transmits the information stream plus a noisy-amplified version of the received AN on the higher-CNR medium at each OFDM sub-channel. The per-subcarrier secrecy rate is
$$
R_s[k]=\Bigl[\log_2(1+\gamma_B[k])-\max\{\log_2(1+\gamma_E^{\mathrm{PLC}[k]}),\log_2(1+\gamma_E^{\mathrm{W}[k]})\}\Bigr]^+,
$$
and the secure throughput is $R_s=\sum_{k=1}^N R_s[k]$. Because the scheme does not require Eve’s instantaneous CSI, it is explicitly positioned as robust to eavesdropper uncertainty [1710.11009].

In visible-light communication, AN must coexist with clipping and LED linear-range constraints. The luminaire-$n$ current is
$$
x_n=v_n d+w_n z,
$$
and after clipping it is modeled by Bussgang decomposition as
$$
\tilde x_n=R_n(v_n d+w_n z)+I_{DC}+\zeta_n.
$$
Bob’s and Eve’s SINRs therefore depend jointly on AN leakage and clipping distortion:
$$
\mathrm{SINR}_B=\frac{(n_c(h_B\odot R)^Tv)^2}{(n_c(h_B\odot R)^Tw)^2+(n_c h_B^T\sigma_{clip})^2+\sigma_{B,norm}^2},
$$
with an analogous expression for Eve. The design problem maximizes Bob’s SINR subject to an Eve-SINR cap and per-luminary power constraints; a later extension separates LED chips into a data branch and an AN branch to reduce the RMS per chip and thus reduce clipping distortion [2210.00438; 2302.11125].

In ISAC, AN protects the sensing function rather than only the communication payload. The BS transmits a dual-functional waveform with beamforming matrix $\mathbf{W}$ and AN covariance $\mathbf{R}_N$, and the objective is to maximize the legitimate radar receiver’s mutual information while constraining Eve’s sensing MI and the CUs’ QoS. The AN is known to the radar receiver but unknown to Eve, so it is transparent to authorized sensing and hostile to unauthorized sensing [2312.00981].

In near-field terahertz, RIS-assisted, and fluid-antenna systems, AN is spatially focused rather than merely projected. Near-field THz designs choose a data focus point $Q_S$ and an AN focus point $Q_A$; RIS-assisted schemes partition the RIS into a communication-signal half and an AN half; FA-MIMO uses joint BF/AN design and port selection so that geometry and position-domain DoF participate directly in secrecy control [2502.08967; 2511.22910; 2512.02461]. In multi-cell cellular networks, by contrast, AN is inseparable from network interference and must be optimized against average connection-outage and secrecy-outage constraints using stochastic geometry [1608.05211].

## 5. Performance, trade-offs, and common misconceptions

A recurring empirical result is that AN can produce substantial secrecy gains, but those gains are regime dependent. In robust MISO secrecy, the SDP-based robust AN design outperforms a non-robust isotropic benchmark; for $N_t=4$, $K=3$, $\epsilon/\sqrt{\mathbb{E}\|g_k\|^2}=0.1$, and $P=20\,\mathrm{dB}$, the reported worst-case secrecy-rate gain is approximately $1.5\,\mathrm{bps/Hz}$ [1104.4260]. In hybrid PLC/wireless OFDM, typical numerical results show secrecy-rate improvements of $20$–$50\%$ over a no-AN scheme, especially when Eve is comparable to Bob on one medium but much worse on the other [1710.11009].

In low-complexity or hardware-constrained architectures, the benefit can hinge on geometry. In near-field terahertz communications, nonzero AN is beneficial only when Eve is closer to the BS than the legitimate user; in that regime the optimal AN fraction can reach $20$–$30\%$ and yields up to $3$–$5\,\mathrm{dB}$ secrecy gain over AN-free designs [2502.08967]. In near-field FA-MIMO, AN is critical for small arrays, whereas for large arrays optimal AN power can vanish because beam focusing alone already yields large secrecy rate [2512.02461].

Several widely repeated simplifications are explicitly contradicted by the literature. The claim that AN should always lie in Bob’s null space is too strong: generalized AN-assisted beamforming shows that injecting AN in the main-channel direction can be optimal in some regimes [1202.5830]. The claim that Gaussian AN is generically optimal is also too strong: in the SER-based untrusted-relay problem with square QAM and ML decoding, Gaussian-distributed AN is “generally not optimal,” and the optimum under average power constraint is a two-mass-point distribution [1506.07491]. The claim that AN is always beneficial is likewise false. When SNR is low, AN in training or data provides no advantage because CSI itself is difficult to obtain; in multicarrier VLC, clipping distortion can severely reduce secrecy; and in multi-cell networks, AN improves secrecy only after accounting for the reliability penalty induced by extra inter-cell interference [1511.01791; 2210.00438; 1608.05211].

Countermeasures at Eve impose explicit antenna thresholds. Under artificial-noise elimination (ANE), if $N_E>N_T-N_b$, Eve can enter a complete-elimination regime, and a key corollary states that when the eavesdropper possesses more than twice as many antennas as the transmitter, secure communication may no longer be guaranteed. The same work identifies conditions under which AN remains effective even against ANE and shows that AN can still outperform the no-AN baseline over a substantial antenna-count region [2603.09129].

## 6. Correlation, implementation constraints, and research directions

Transmitter and channel correlation do not simply degrade AN; they can also reshape its optimal structure. With transmitter-side correlation, the matrix
$$
Q=V_N^\dagger T V_N=W\Theta W^\dagger
$$
governs the AN subspace, and the correlation-based power allocation (CPA) concentrates all AN power on the principal eigen-direction of $Q$:
$$
\Omega^*=(N_t-1)\,w_I w_I^\dagger.
$$
In the large-system regime this minimizes secrecy-outage probability, is nearly optimal at moderate $N_t$, and differs qualitatively from uniform power allocation: as the number of correlated transmit antennas increases, CPA outage always reduces, whereas UPA exhibits a saturation point [1611.01939].

Implementation constraints increasingly define the frontier of AN design. Visible-light systems must handle LED bias, amplitude limits, Bussgang attenuation, and clipping noise; RIS-assisted schemes must optimize discrete phase shifts and often use iterative or DFT-based procedures; full-duplex AN must tolerate residual self-interference; hybrid beamforming architectures seek AN embedding in baseband without extra RF chains; and experimental work now reports software-defined-radio testbeds rather than simulation only [2302.11125; 2511.22910; 2512.02461]. This suggests that AN research has moved from purely information-theoretic feasibility toward architecture-aware realizability.

The current research agenda emphasizes robust AN under imperfect CSI, low-complexity AN optimization, AN in emerging 6G waveforms such as OTFS, joint sensing/localization/AN, intelligent surfaces and metasurfaces, space-air-ground integrated networks, covert communications, physical-layer authentication, and experimental prototypes and standardization [2507.06500]. A plausible implication is that AN will remain central not because null-space jamming is universally optimal, but because controlled interference can be re-parameterized to fit whichever domain—spatial, temporal, frequency, geometric, or hardware—is available in a given secure communication system.

Source: https://www.emergentmind.com/topics/artificial-noise-an