---
title: 'D-RISE: Defensive RIS Architecture'
url: https://www.emergentmind.com/topics/d-rise
type: topic
---

# D-RISE: Defensive RIS Architecture

Searching arXiv for “D-RISE” and closely related terms to ground the article in current literature.
“D-RISE” (*Editor’s term*) denotes the defensive reconfigurable intelligent surface scheme D-RIS introduced in “Defensive Reconfigurable Intelligent Surface (D-RIS) Based on Non-Reciprocal Channel Links” [2407.04905]. It is a physical-layer security construction for RIS-assisted wireless systems that addresses the RIS-In-The-Middle (RITM) attack by deliberately creating a non-reciprocal channel between a base station (BS) and user equipment (UE). In this design, the uplink (UL) and downlink (DL) channel state information (CSI) become a unique pair for each legitimate device, and that pair is used by dedicated precoding, combining, and channel-estimation procedures. The stated objective is to preserve the customary RIS advantages—beam steering, coverage extension, and signal-quality improvement—while making eavesdropping and false data injection substantially more difficult.

## 1. Threat model and security motivation

A reconfigurable intelligent surface is described as a customizable signal reflector made of low-cost passive and reflective meta-materials with beam steering capability. The same property that improves a legitimate wireless link can also be exploited adversarially. The paper considers the RIS-In-The-Middle attack, in which an adversary deploys an RIS to jeopardize the direct channel between two transceivers by providing an alternative one with higher signal quality. Under that threat model, the adversary can eavesdrop on exchanged data and can also perform false data injection to the receiver [2407.04905].

The security difficulty arises because ordinary RIS-assisted links are typically reciprocal, so the same propagation relationship can be exploited in both communication directions. D-RIS changes the problem formulation by treating reciprocity itself as a liability. Rather than assuming that UL and DL should share the same effective channel, it engineers direction-dependent CSI and then uses that asymmetry as a physical-layer secret. This suggests a shift from RIS as a purely coverage-enhancing object to RIS as an active component of link authentication and secrecy enforcement.

## 2. Non-reciprocal channel construction

The core mechanism is slot-dependent phase reconfiguration of the defensive surface. For the D-RIS-assisted channel component, the paper writes

$$
h_{a,n} = e^{j\varphi_{a,n}} h_a ,
$$

where $h_a$ is the standard reciprocal D-RIS-assisted channel component and $\varphi_{a,n}$ is a time-varying, slot-dependent phase shift applied jointly to all D-RIS elements. The common phase is assigned differently in downlink and uplink slots:

$$
\varphi_{a,n} =
\begin{cases}
\varphi_a^{\mathrm{DL}}, & n \in \mathcal{N}^{\mathrm{DL}} \\
\varphi_a^{\mathrm{UL}}, & n \in \mathcal{N}^{\mathrm{UL}} .
\end{cases}
$$

The resulting cascaded channels are therefore

$$
h_a^{\mathrm{DL}} = e^{j\varphi_a^{\mathrm{DL}}} h_a, \qquad
h_a^{\mathrm{UL}} = e^{j\varphi_a^{\mathrm{UL}}} h_a .
$$

In the paper’s terminology, conventional RIS-assisted channels are reciprocal, whereas D-RIS deliberately makes the UL and DL channels different [2407.04905].

The immediate significance is that the legitimate BS and UE do not rely on a single reusable channel description. Instead, the UL/DL pair acts as a joint channel “key.” A plausible implication is that an adversary must infer a temporally varying, direction-specific structure rather than a single effective link, which increases the difficulty of transparent interception or replay.

## 3. Defensive precoding and combining

D-RIS associates the non-reciprocal channel pair with dedicated transmitter and receiver operations. The downlink precoder at the BS and the uplink precoder at the UE are given as

$$
v_{b,n} = h_a^{\mathrm{DL}*} e^{j\theta_a^{\mathrm{UL}}}, \qquad
v_{u,n} = h_a^{\mathrm{UL}*} e^{j\theta_a^{\mathrm{DL}}},
$$

where $\theta_a^{\mathrm{UL}} = \arg(h_a^{\mathrm{UL}})$ and $\theta_a^{\mathrm{DL}} = \arg(h_a^{\mathrm{DL}})$. The receiver then applies a complementary combining operation:

$$
z_{u,n} = e^{-j\theta_a^{\mathrm{UL}}} y_{u,n}, \qquad
z_{b,n} = e^{-j\theta_a^{\mathrm{DL}}} y_{b,n}.
$$

The stated interpretation is that the receiver removes the second phase rotation and verifies the sender’s authenticity by decoding only transmissions that are consistent with the correct joint key pair [2407.04905].

This construction has two stated defensive consequences. First, an eavesdropper would have to deduce both precoders rather than a single reciprocal channel description. Second, for false data injection, the receiver-side combiner depends on both links; injected symbols are therefore described as distorted or “garbled” unless the adversary has solved both key channels. The same section of the paper also notes a fail-secure behavior during contaminated training: if adversarial interference pollutes CSI estimation on the D-RIS path, legitimate decoding fails, the system blocks rather than forfeiting security, and higher layers can be notified to reinitiate secure training.

## 4. Channel estimation under broken reciprocity

Because D-RIS intentionally breaks reciprocity, UL and DL CSI cannot be inferred from one another. The paper identifies this as a direct challenge to standard time-division duplex practice, since conventional reciprocal systems use reciprocity to reduce CSI overhead. Explicit CSI feedback is also treated as a vulnerability, because an eavesdropper could intercept feedback and infer the precoders.

The proposed remedy is a channel-estimation procedure described as “phase flipping” CEP. Within specially allocated OFDM symbols, the D-RIS alternates its common phase between the DL and UL values. With coordinated pilot allocation and knowledge of the training phase sequence, the BS and UE can use simple linear algebra to estimate both $h_a^{\mathrm{DL}}$ and $h_a^{\mathrm{UL}}$ without explicit feedback. The paper states that this adds only one extra pilot symbol per slot compared with reciprocal techniques, and that the training phase schedules are coordinated via secure control and can be randomized [2407.04905].

Operationally, this is central to the feasibility of D-RIS. The defensive concept would be much weaker if the system had to export the relevant CSI through an observable feedback channel. By embedding dual-channel estimation inside the air interface and the D-RIS phase schedule, the scheme treats estimation itself as part of the security boundary.

## 5. Secrecy analysis, fake-data robustness, and comparative properties

The paper analyzes robustness using achievable secrecy rate and probability expressions associated with fake-data attacks. For the D-RIS path, it gives

$$
C_a = \eta_a \log_2(1+\rho_a),
$$

with signal-to-noise ratio

$$
\rho_a = M_a \frac{\sigma_{q_a}^2 \sigma_{g_a}^2}{\sigma_w^2},
$$

where $M_a$ is the number of D-RIS elements. In the presence of an eavesdropper, the achievable secrecy rate is written as

$$
E_{an} = \eta_a \log_2(1+\rho_a) - \left(1-\frac{N_n}{N}\right)\log_2(1+\rho_e),
$$

where $N_n$ is the time it takes the adversary to deduce both precoders. The paper states that secrecy is preserved during that window and notes the favorable regime $\rho_a > \rho_e$ [2407.04905].

For false data injection, the summary gives

$$
P_r = \left[1-\frac{N_n'}{N}\right]
\exp\left(
-\frac{M_a \sigma_{q_a}^2 \sigma_{g_a}^2 + \sigma_d^2 + \sigma_w^2}
{M_e \sigma_e^2 \sigma_{g_v}^2}
\right),
$$

where $N_n'$ is the time for the adversary to deduce both precoders and combiners, and $M_e$ is the number of elements in the adversarial RIS. The summary characterizes this as making the probability negligible for a reasonably sized legitimate D-RIS and moderate adversarial resources until the adversary cracks all keys.

The paper’s simulation summary states that D-RIS yields significantly higher achievable secrecy rate and a much lower probability of successful manipulation than reciprocal RIS, that increasing D-RIS size improves both metrics, and that the added pilot overhead is negligible while the throughput penalty is minimal. The comparison presented in the source can be organized as follows:

| Aspect | Conventional RIS | D-RIS |
|---|---|---|
| Channel reciprocity | Yes | No (engineered) |
| Security against RITM | Weak | Strong |
| Attack detectability | No | Yes |
| Eavesdropper requirements | 1 key | 2 keys, more time |
| Additional overhead | None or minimal | +1 pilot symbol/slot |

The broader implication is not that D-RIS eliminates the physical-layer attack surface, but that it alters the attacker’s time scale and information requirements. In the paper’s formulation, success depends on inferring a two-direction key structure quickly enough to remain within a slot-level operational window.

## 6. Protocol implications and nomenclature

Beyond link-level defense, the paper presents D-RIS as a basis for new protocols and algorithms in physical-layer security. The proposed scheme retains the conventional RIS roles of beam steering, coverage extension, and signal-quality enhancement, while embedding a dynamic physical-layer key into the channel itself. The discussion specifically points to dynamic keying and channel authentication, randomization or negotiation of the D-RIS phase pattern, graceful degradation and fallback when training attacks are detected, and fine-grained access control arising from user-specific BS–UE channel keys [2407.04905].

The term “RISE” is used elsewhere in the arXiv literature with unrelated meanings. “RISE: Relay Inference and Online Scheduling for Efficient Edge-Device Collaborative Diffusion Model Services” denotes an edge-device text-to-image diffusion serving method based on relay inference and a contextual bandit scheduler [2606.17378]. “Adaptive RISE Control for Dual-Arm Unmanned Aerial Manipulator Systems with Deep Neural Networks” uses RISE to mean robust integral of the sign of the error in nonlinear control for aerial manipulation [2504.05985]. “The Rise of Dark Energy” is a cosmology paper on model-independent constraints on the dark energy fraction at redshift $z=1.5$ to $2.5$ [2106.09581]. These usages are lexically similar but technically unrelated to defensive RIS security.

In that narrower and specific sense, D-RISE refers to a non-reciprocal, RIS-based physical-layer defense architecture whose defining idea is to replace conventional reciprocal channel symmetry with engineered asymmetry, and then to exploit that asymmetry for secrecy, authenticity, and attack detection.

Source: https://www.emergentmind.com/topics/d-rise