---
title: Average Secrecy Throughput (AST) Explained
url: https://www.emergentmind.com/topics/average-secrecy-throughput-ast
type: topic
---

# Average Secrecy Throughput (AST) Explained

Average Secrecy Throughput (AST) is a long-term physical-layer security metric for quantifying the rate at which confidential information is delivered securely under channel randomness, secrecy constraints, and, in many formulations, reliability constraints. The literature does not use a single universal AST definition. In measured multi-mode fiber (MMF) channels, AST is the expectation of the positive-part secrecy rate over the legitimate and eavesdropper channels [2105.03137]. In delay-limited and outage-based formulations, AST is the target secrecy rate multiplied by the probability of secure non-outage [2403.11117][2304.04314]. In finite-blocklength and short-packet settings, AST is written as an information rate discounted by average block error, leakage, or both [2308.13184][2603.17224][2509.14705]. Closely related papers also use the terms secrecy throughput, effective secrecy throughput (EST), and average achievable secrecy throughput (AAST) for the same general design objective [1709.01019][2111.06574][2603.17224].

## 1. Definitions and nomenclature

The mathematical form of AST depends on the communication regime, the secrecy model, and whether coding is asymptotic, outage-limited, or finite-blocklength. In the MMF wiretap model, the instantaneous secrecy rate is
\[
R_s(\mathbf{H},\mathbf{G})
=\bigl[C_b(\mathbf{H},Q_s,Q_n)-C_e(\mathbf{G},Q_s,Q_n)\bigr]^+,
\]
and the AST is
\[
\mathrm{AST}
=\mathbb{E}_{\mathbf{H},\mathbf{G}}\!\bigl[R_s(\mathbf{H},\mathbf{G})\bigr],
\qquad
\mathrm{AST}(\mathbf{H})
=\mathbb{E}_{\mathbf{G}}\!\bigl[R_s(\mathbf{H},\mathbf{G})\bigr]
\]
when \(\mathbf{H}\) is measured and deterministic over a block [2105.03137]. In the rotatable-antenna setting, two equivalent definitions are given:
\[
\mathrm{AST}= \mathbb{E}[C_s(\theta)]
=\mathbb{E}\!\bigl[\max(0,C_B(\theta)-C_E(\theta))\bigr],
\]
and
\[
\mathrm{AST}=R_s(1-P_{\mathrm{outage}}),
\qquad
P_{\mathrm{outage}}=\Pr\{C_s(\theta)<R_s\}
\]
[2511.18097]. In RIS-assisted ambient backscatter communication (AmBC), the secrecy throughput is
\[
T(R)=\bigl[1-P_{\mathrm{out}}(R)\bigr]R,
\]
with analogous per-stream quantities \(T_u^\psi(R_u)\) and \(T_c^\psi(R_c)\) for the ambient-source data signal and the backscatter signal under ipSIC or pSIC [2403.11117].

In finite-blocklength work, AST explicitly absorbs reliability and leakage penalties. For fading wiretap channels with average information leakage (AIL), the instantaneous secrecy throughput in slot \(i\) is
\[
\mathcal T[i]=(1-\varepsilon)\,\frac{m}{N[i]}\,\mathbf{1}\{\bar\delta[i]\le\phi\},
\]
and the AST is
\[
\bar{\mathcal T}=\frac1L\sum_{i=1}^L \mathcal T[i]
\]
over \(L\) independent fading blocks [2308.13184]. In short-packet fluid-antenna systems (FAS), the AST is
\[
T=\mathbb E_{\gamma_R,\gamma_E}\!\left[\frac{m}{M}(1-\varepsilon)\right]
=\frac{m}{M}\left[1-\mathbb E_{\gamma_R,\gamma_E}[\varepsilon(\gamma_R|\gamma_E)]\right]
\]
[2603.17224]. In RIS-assisted autonomous aerial vehicle (AAV) networks, AST is
\[
\tau=\frac{B}{m}(1-\bar\varepsilon)
\]
under decoding-error and information-leakage constraints [2509.14705].

| Regime | AST form | Representative source |
|---|---|---|
| MMF wiretap | \(\mathbb E[R_s]\) | [2105.03137] |
| Rotatable antenna | \(\mathbb E[C_s]\) or \(R_s(1-P_{\mathrm{outage}})\) | [2511.18097] |
| Delay-limited RIS-AmBC | \([1-P_{\mathrm{out}}(R)]R\) | [2403.11117] |
| Finite blocklength with AIL | time-average of \((1-\varepsilon)m/N\) under \(\bar\delta\le\phi\) | [2308.13184] |
| Short-packet FAS | \((m/M)[1-\mathbb E[\varepsilon]]\) | [2603.17224] |
| Short-packet RIS-AAV | \((B/m)(1-\bar\varepsilon)\) | [2509.14705] |

This range of definitions makes AST a family of operational secrecy-throughput metrics rather than a single invariant quantity. What remains common is the combination of confidential rate with a success mechanism: positive secrecy rate, outage complement, or finite-blocklength decoding success.

## 2. Canonical secrecy models underlying AST

AST is built from a wiretap model with a legitimate link and an eavesdropper link. In the MMF formulation, the baseband model is
\[
\mathbf y=\mathbf H\mathbf x+\mathbf n_b,\qquad
\mathbf z=\mathbf G\mathbf x+\mathbf n_e,
\]
with transmit covariance \(Q=\mathbb E[\mathbf x\mathbf x^\dagger]\), total power constraint \(\mathrm{tr}(Q)\le P_{\rm tot}\), perfect knowledge of \(\mathbf H\), and only distributional knowledge of \(\mathbf G\) at the transmitter [2105.03137]. The secrecy design uses a message covariance \(Q_s\) and an artificial-noise covariance \(Q_n\) satisfying
\[
Q=Q_s+Q_n,\qquad
Q_s\succeq0,\quad Q_n\succeq0,\quad \mathrm{tr}(Q_s+Q_n)\le P_{\rm tot},
\]
with \(Q_sQ_n=0\). The resulting legitimate and eavesdropper capacities are log-determinant expressions,
\[
C_b=\log\left|\mathbf I+(\sigma^2\mathbf I+\mathbf HQ_n\mathbf H^\dagger)^{-1}\mathbf HQ_s\mathbf H^\dagger\right|,
\]
\[
C_e=\log\left|\mathbf I+(\sigma^2\mathbf I+\mathbf GQ_n\mathbf G^\dagger)^{-1}\mathbf GQ_s\mathbf G^\dagger\right|,
\]
which then feed the positive-part secrecy rate [2105.03137].

Wireless AST models frequently replace matrix capacities by scalar SNR-based expressions. In the rotatable-antenna system, the channels are
\[
h_i(\theta)=\sqrt{L_iG_i(\theta)}\,u_i,\qquad i\in\{b,e\},
\]
with Rician fading, instantaneous SNRs \(\gamma_i(\theta)=\gamma|h_i(\theta)|^2\), and capacities
\[
C_i(\theta)=\log_2(1+\gamma_i(\theta))
\]
[2511.18097]. In RIS-assisted mixed RF-FSO and integrated RF-UWOC systems, the instantaneous secrecy capacity is written as
\[
C_s=\bigl[\log_2(1+\gamma_{\rm eq})-\log_2(1+\gamma_e)\bigr]^+,
\]
where \(\gamma_{\rm eq}\) is the end-to-end legitimate SNR, typically based on a dual-hop approximation, and \(\gamma_e\) is the wiretap SNR in the relevant eavesdropping scenario [2304.04314][2407.18766].

Finite-blocklength AST retains the same basic wiretap structure but replaces asymptotic secrecy capacity by a reliability-and-dispersion-limited expression. In the FAS short-packet model,
\[
R_s \simeq C_S-\sqrt{\frac{V_R}{M}}\frac{Q^{-1}(\varepsilon)}{\ln2}-\sqrt{\frac{V_E}{M}}\frac{Q^{-1}(\delta)}{\ln2},
\]
when \(\gamma_R>\gamma_E\), with
\[
C_S=\log_2(1+\gamma_R)-\log_2(1+\gamma_E),
\]
and an RU decoding-error expression \(\varepsilon(\gamma_R|\gamma_E)\) given by a Gaussian-\(Q\) function [2603.17224]. In the RIS-assisted AAV short-packet model, the block error likewise depends on
\[
\log\frac{1+\tilde\gamma_A}{1+\tilde\gamma_E}
\]
together with dispersion terms \(V_A\), \(V_E\), and the leakage parameter \(Q^{-1}(\delta)\) [2509.14705]. Across these formulations, AST inherits its statistical structure from the joint law of the main and wiretap channels and its operational meaning from the secrecy criterion enforced at the code level.

## 3. Optimization formulations and algorithmic approaches

AST is usually the objective of a constrained resource-allocation problem. In the MMF setting, the design problem is
\[
\max_{Q_s,Q_n}\ \mathbb E_{\mathbf H,\mathbf G}[R_s(\mathbf H,\mathbf G)]
\]
subject to positive semidefiniteness and the total power constraint. The associated Lagrangian introduces a scalar multiplier \(\lambda\) and Hermitian PSD multipliers \(\Phi_s,\Phi_n\), and the KKT conditions impose stationarity and complementary slackness. The paper states that \(R_s\) is a difference of two concave log-det functionals, so the problem is in general nonconvex [2105.03137]. To handle this, a threshold-based “Greedy AN Allocation” algorithm is proposed: compute the SVD of \(\mathbf H\), assign message power to modes with \(d_i^2>\Theta\), assign AN power to modes with \(d_i^2\le\Theta\), estimate \(\widehat{\mathrm{AST}}(\Theta)\) by Monte Carlo over \(\mathbf G\), and optimize over the threshold and relative power split by grid search or golden-section search [2105.03137].

The rotatable-antenna AST maximization problem is reduced to a scalar adjustment factor \(\alpha\in[1,\alpha_{\max}]\). The expected secrecy rate
\[
\mathbb E[C_s(\alpha)]
\]
is expressed as a double integral involving noncentral-\(\chi^2\) densities. The paper proves quasi-concavity with respect to \(\alpha\), establishes single-peaked behavior, and therefore uses bisection to find the unique maximizer. Under line-of-sight only, a closed-form near-optimal solution is derived; at high SNR,
\[
\alpha^*=\alpha_{\max}
=\frac{\|q_e\|^2}{\|q_e\|^2-q_e^Tq_b}
\]
with corresponding optimal deflection angles \(\theta_z^*\) and \(\theta_a^*\) [2511.18097].

Finite-blocklength AST optimization commonly couples coding parameters with AN or power-allocation variables. In the AIL-based formulation, one chooses blocklengths \(\{N[i]\}\) and AN power fractions \(\{\alpha[i]\}\) to maximize
\[
\bar{\mathcal T}
=\frac1L\sum_{i=1}^L (1-\varepsilon)\frac{m}{N[i]}\mathbf 1\{\bar\delta[i]\le\phi\}
\]
under a maximum blocklength, integrality of \(N[i]\), \(0<\alpha[i]\le1\), and the per-slot leakage constraint \(\bar\delta[i]\le\phi\). The adaptive design decomposes the problem into per-slot subproblems; because the secrecy constraint is nonconvex in \((N,\alpha)\), the paper proposes either a 2-D exhaustive or heuristic search, or a lower-complexity alternating scheme that first inverts the approximate AIL constraint to obtain the minimal feasible \(\tilde N^*(\alpha)\), then performs a one-dimensional maximization in \(\alpha\) with bisection, and finally rounds \(\tilde N^*(\alpha^*)\) to an integer [2308.13184]. The non-adaptive design replaces slot-wise adaptation by a single \((N,\alpha)\) chosen from channel statistics and an on-off threshold \(\gamma_1\) defined by
\[
\bar\delta(\gamma_b=\gamma_1)=\phi
\]
[2308.13184].

In the VBCM-based FAS short-packet framework, the paper proves that AAST is monotonically non-decreasing in the number of RU ports \(N_R\). This reduces a three-dimensional joint optimization over transmit power, blocklength, and port number to a two-dimensional grid search over \((P,M)\), with the corollary \(N_R^*=N_{\max}\) [2603.17224]. In RIS-assisted short-packet AAV networks, the blocklength problem
\[
\max_{m\in\mathbb Z^+}\ \tau(m)=\frac{B}{m}(1-\bar\varepsilon(m))
\]
is shown to be quasi-concave under continuous relaxation, so the optimizer satisfies
\[
\frac{\partial \tau(m)}{\partial m}\Big|_{m=m^*}=0,
\]
and can be found by bisection, with integer selection by comparing neighboring integers [2509.14705]. Across these systems, AST optimization is typically nonconvex but often admits dimensionality reduction, structural monotonicity, or one-dimensional searches once the physical model is exploited.

## 4. Finite-blocklength and short-packet formulations

Finite-blocklength AST departs from asymptotic secrecy-rate analysis by incorporating decoding error, information leakage, and latency directly into the throughput metric. In fading wiretap channels without instantaneous eavesdropper CSI, the AIL-based framework introduces the instantaneous secrecy throughput
\[
\mathcal T[i]=(1-\varepsilon)\frac{m}{N[i]}\mathbf 1\{\bar\delta[i]\le\phi\},
\]
where \(\bar\delta[i]\) is the average information leakage in slot \(i\) and \(\phi\) is the maximum tolerable AIL threshold [2308.13184]. The finite-blocklength secrecy rate approximation is based on the Polyanskiy–Yang–Poor bound, and the average leakage is approximated as
\[
\bar\delta\approx 1-F_{\gamma_e}(x_0),
\]
which produces tractable adaptive and non-adaptive AST designs [2308.13184]. The paper reports that allowing a small, nonzero AIL can drastically reduce the required blocklength or improve reliability by tens of dB in error probability, and that AN beamforming can drive \(\bar\delta\to0\) as SNR \(\to\infty\), whereas pure MRT asymptotes to a nonzero leakage floor [2308.13184].

The FAS short-packet framework introduces a variable block-correlation model (VBCM) for the spatially correlated fluid-antenna channels. The AST is
\[
T=\frac{m}{M}\left[1-\mathbb E[\varepsilon]\right],
\]
with the decoding error approximated by a three-segment linear function of \(\gamma_R\) conditioned on \(\gamma_E\). Closed-form and asymptotic expressions are obtained by combining this piecewise linearization with Gauss-Chebyshev quadrature [2603.17224]. The paper further proves that \(T\) is non-decreasing in \(N_R\), and its numerical results show an order-of-magnitude secrecy throughput improvement over conventional fixed-position antenna systems, with blocklength selection identified as the most critical design parameter [2603.17224].

In RIS-assisted AAV short-packet networks, the AST is
\[
\tau=\frac{B}{m}(1-\bar\varepsilon),
\]
and the external-eavesdropper case is expressed as a double integral over the AAV and eavesdropper SNRs,
\[
\tau^{\rm Ex}
=\frac{B}{m}\int_0^\infty\int_y^\infty [1-\varepsilon(x,y)]
\,f_{\tilde\gamma_A}(x)f_{\tilde\gamma_E}(y)\,dx\,dy
\]
[2509.14705]. The internal-eavesdropper case includes NOMA decoding of an untrusted user’s symbol, residual SIC interference, and a worst-case eavesdropper model. The paper gives
\[
\tau^{\rm In}
=\frac{B}{m}\Bigl[1-\mathbb E[\varepsilon_{A\to E}]-\mathbb E[\varepsilon_A]\Bigr]
\]
and states that the AST in the internal-eavesdropper case is invariably lower than in the external-eavesdropper case because of the two-stage SIC decoding [2509.14705]. The asymptotic analysis also shows that, in the external scenario, AST converges to a limit independent of \(P_G\) as \(P_G\to\infty\) [2509.14705].

A recurring structural feature of finite-blocklength AST is the rate–reliability–secrecy trade-off. In the AIL framework, too short a blocklength leads to high leakage and on-off suppression of throughput, whereas too long a blocklength reduces the per-block rate \(m/N\), so the optimum lies in a mid-range [2308.13184]. In the FAS and AAV short-packet models, AST is likewise unimodal in blocklength because the coding-rate term decreases with \(M\) or \(m\) while the error term improves [2603.17224][2509.14705].

## 5. Representative channel families and numerical behavior

Measured MMF channels provide a concrete example in which AST is improved by artificial noise adapted to the modal eigen-structure. For a 55-mode MMF, the paper reports positive average secrecy rates with the proper use of AN and compares Greedy AN with waterfilling. The mean secrecy throughput values are \(13.995\) versus \(14.667\) bits/s/Hz at \(0\) dB, \(23.800\) versus \(40.898\) bits/s/Hz at \(10\) dB, and \(26.870\) versus \(57.225\) bits/s/Hz at \(15\) dB for waterfilling and Greedy AN, respectively. At \(10\) dB this is described as a \(72\%\) increase, and at \(15\) dB the gain exceeds \(100\%\). The Greedy AN curve remains above the pessimistic ergodic lower bound and approaches the upper bound at high SNR [2105.03137].

RIS-assisted AmBC introduces a two-stream AST structure. The data-signal and backscatter ASTs are
\[
T_u^\psi(R_u)=\bigl[1-P_u^\psi(R_u)\bigr]R_u,
\qquad
T_c^\psi(R_c)=\bigl[1-P_c^\psi(R_c)\bigr]R_c,
\]
with separate outage behavior under ipSIC and pSIC [2403.11117]. The asymptotic analysis shows that the data-link secrecy diversity order is zero, because the backscatter link acts as residual interference in the SIC process, and that the backscatter link has \(d_c^{\mathrm{ipSIC}}=0\) but \(d_c^{\mathrm{pSIC}}=\alpha+1\propto M\) [2403.11117]. Numerical results confirm that AST versus the number of RIS elements \(M\) is non-monotonic, reflecting the balance between a stronger backscatter link and heavier interference on the data link; the reflecting coefficient \(\kappa\) has opposite effects on the two AST components; and stronger eavesdropping ability lowers both ASTs [2403.11117].

Integrated RF-UWOC IoT and mixed RF-FSO systems employ outage-based AST or EST,
\[
\mathrm{AST}=R_s(1-\mathrm{SOP}),
\]
under multiple eavesdropping scenarios [2407.18766][2304.04314]. In the integrated RF-UWOC model, the paper states that AST is unimodal in \(R_s\), because a higher \(R_s\) raises throughput but also increases SOP. It also identifies simultaneous RF and UOWC eavesdropping as the worst case, reports that increasing the number of RIS elements improves coherent beamforming underwater and hence AST, and notes that heterodyne detection outperforms IM/DD in secrecy [2407.18766]. The mixed RF-FSO RIS model reaches analogous conclusions: larger \(N_1,N_2\), stronger line-of-sight components, weaker turbulence, and smaller pointing error improve AST, and heterodyne detection performs better than IM/DD [2304.04314].

Free-space optical MIMOME systems under secrecy-outage constraints use EST as
\[
\Psi(R_E,R_B)=(R_B-R_E)\,[1-T(R_B)]\,[1-S(R_E)]
\]
in the unconstrained form, and set the metric to zero when the secrecy-outage constraint \(S(R_E)\le S^{\rm th}\) is violated [1709.01019]. The adaptive scheme fixes \(R_B=C_B\) so that the reliability outage vanishes, whereas the fixed-rate scheme optimizes both \(R_E\) and \(R_B\). The numerical results show that the adaptive scheme is always at least as large as the fixed-rate scheme and that more apertures greatly improve EST [1709.01019].

## 6. Recurring trade-offs and interpretive issues

A persistent source of ambiguity is that AST is not identical to secrecy capacity. In outage-based formulations, AST is not the expected secrecy capacity but the target secrecy rate multiplied by the non-outage probability:
\[
\mathrm{AST}=R_s(1-\mathrm{SOP})
\]
or
\[
T(R)=\bigl[1-P_{\mathrm{out}}(R)\bigr]R
\]
[2407.18766][2403.11117]. In expectation-based formulations, by contrast, AST is an average of the positive-part secrecy rate itself [2105.03137][2511.18097]. These are different operational metrics even when they are both called secrecy throughput.

Another recurring distinction is between asymptotic coding and finite blocklength. In finite blocklength, AST explicitly depends on blocklength and dispersion, and thus on a three-way compromise between spectral efficiency, reliability, and secrecy [2308.13184][2603.17224][2509.14705]. The AIL-based work states that the optimum non-adaptive \((N^*,\alpha^*)\) typically lies in the mid-range, while the FAS and AAV short-packet studies report unimodal dependence on blocklength [2308.13184][2603.17224][2509.14705]. This suggests that AST maximization in short-packet secrecy systems is inherently a joint coding-and-resource-allocation problem rather than a pure power-control problem.

Higher SNR does not uniformly translate into higher AST. In RIS-AmBC, ipSIC induces an error floor for both links, so both ASTs saturate and the secrecy diversity orders are zero [2403.11117]. In the internal-eavesdropper RIS-AAV setting with imperfect SIC, the numerical results show that AST peaks at a moderate \(P_G\) and then collapses because the residual interference term scales with transmit power [2509.14705]. In contrast, MMF with Greedy AN shows large AST gains at \(10\) dB and \(15\) dB and approaches the upper bound at high SNR [2105.03137]. The role of SNR is therefore model-dependent and strongly mediated by interference cancellation, AN structure, and short-packet penalties.

Additional degrees of freedom also have nonuniform effects. Increasing the number of RU ports in the VBCM-based FAS model provably makes AAST non-decreasing, with the optimizer at \(N_R=N_{\max}\) [2603.17224]. By contrast, the RIS-AmBC system has an overall AST that is non-monotonic in the number of RIS elements because stronger backscatter also intensifies interference on the data stream [2403.11117]. A plausible implication is that structural resources such as ports, RIS elements, apertures, or modes improve AST only when the corresponding receiver architecture and interference model preserve the gain rather than convert it into additional coupling or SIC burden.

Across these formulations, AST functions as an operational bridge between secrecy theory and secure-link design. It is the metric through which AN covariance shaping in MMF, deflection-angle control in rotatable antennas, blocklength and leakage management in finite-blocklength wiretap coding, and RIS or FAS architecture choices are rendered directly comparable at the system level [2105.03137][2511.18097][2308.13184][2603.17224].

Source: https://www.emergentmind.com/topics/average-secrecy-throughput-ast