Secure AFDM: High-Mobility Physical-Layer Security
- SE-AFDM is a secure extension of AFDM that uses dynamic chirp parameters, especially a secret c2 sequence, to provide physical-layer security in challenging channels.
- It employs time-varying, pseudo-random phase functions to complicate brute-force demodulation for eavesdroppers while preserving robust legitimate reception.
- Simulation and prototype studies show that while Bob’s bit error rate remains comparable to conventional AFDM, eavesdroppers face near-random decoding performance due to increased brute-force complexity.
Secure Affine Frequency Division Multiplexing (SE-AFDM) denotes a class of physical-layer secure extensions of affine frequency division multiplexing in which the affine or chirp-domain degrees of freedom of the waveform—most commonly the second AFDM parameter —are exploited as secret, time-varying, or difficult-to-estimate controls. In the published formulations, the legitimate receiver preserves AFDM’s robustness in doubly selective and high-mobility channels by compensating the secure parameterization with synchronized side information, while an eavesdropper that lacks that information faces either severe bit-error-rate degradation or sharply increased brute-force demodulation complexity (Wang et al., 23 Sep 2025, Wang et al., 2 Oct 2025, Liu et al., 14 May 2026).
1. AFDM foundations and the meaning of “secure” in SE-AFDM
AFDM is a chirp-based multicarrier waveform built on the discrete affine Fourier transform (DAFT). In its standard form, an affine-domain symbol vector is mapped to the time domain through the inverse DAFT,
or, equivalently in scalar form,
A chirp-periodic prefix (CPP) is appended so that transmission over multipath doubly selective channels can be represented by a structured effective channel in the affine domain (Bemani et al., 2021, Zheng et al., 2024).
The technical attraction of AFDM is that its parameterized chirp basis is matched to channels with both delay spread and Doppler spread. Foundational AFDM work shows that can be selected so that delay-Doppler paths become separable in the DAFT domain, yielding a sparse or structured input-output relation and full diversity under stated conditions. A 6G-oriented survey further identifies AFDM’s chirp parametrization as a native design lever for physical-layer security, in contrast to OFDM’s fixed DFT basis and OTFS’s more constrained configuration space (Bemani et al., 2021, Rou et al., 29 Jul 2025).
Within this literature, “SE-AFDM” refers to secure AFDM. That terminology requires care because in AFDM channel-estimation work the abbreviation “SE” is also used for spectral efficiency rather than security. In particular, “Channel Estimation for AFDM With Superimposed Pilots” treats SE as spectral efficiency and contains no adversarial or secrecy model (Zheng et al., 2024).
2. Core waveform constructions
The central secure design idea is to preserve the conventional AFDM role of for reliable communication in doubly selective channels while converting into the security-bearing parameter. In the first explicit SE-AFDM construction, is no longer a scalar but an index-varying vector
with entries selected from a public codebook
that uniformly discretizes 0. The selection is driven by a secret synchronized long-period pseudo-noise (LPPN) sequence, yielding a transmit-side diagonal matrix
1
The resulting SE-AFDM signal is
2
This is described as parameter-domain spreading: the data symbols themselves are not spread as in DSSS; rather, the waveform parameter is pseudo-randomly varied, so the payload spectral efficiency remains the same as in conventional AFDM (Wang et al., 23 Sep 2025, Wang et al., 2 Oct 2025).
A second secure construction generalizes the conventional quadratic 3 term into a generic phase function 4, producing
5
In that framework, the design objective is not synchronization asymmetry via an LPPN sequence but sensitivity amplification: the eavesdropper’s admissible parameter mismatch interval is controlled by the first derivative 6. The proposed family
7
preserves AFDM’s chirp structure while enlarging brute-force demodulation complexity beyond the conventional quadratic-phase case (Liu et al., 14 May 2026).
These constructions suggest a broader taxonomy of SE-AFDM. One branch secures AFDM by dynamic secret parameter trajectories generated from LPPN-controlled codebooks; another secures AFDM by phase-function redesign that makes parameter mismatch dramatically more destructive.
3. Legitimate reception, compensation, and synchronization
For the legitimate receiver, the crucial property is that the nonlinear effect introduced by secure 8 parameterization is known and can therefore be absorbed into the effective channel rather than appearing as unknown distortion. In the LPPN-driven design, Bob uses his own synchronized de-chirp matrix
9
and after CPP removal, multiplication by 0, DFT processing, and secure de-chirping, obtains
1
Detection is then performed by a standard linear receiver such as MMSE,
2
When LPPN synchronization holds, 3, so the secure phase law is part of a known effective channel and the legitimate BER remains essentially unchanged relative to AFDM (Wang et al., 23 Sep 2025).
The later formulation extends this idea with an explicit synchronization architecture. A frame is divided into a frame-synchronization block, an LPPN-sequence synchronization block, and a secure communication block,
4
During the first two blocks, the transmitter fixes 5, allowing Bob to perform header acquisition and to recover the LPPN generator state. The state vector
6
is spread with DSSS only for synchronization reliability, not for payload transmission. After desynchronization and local generator initialization, Bob reproduces the same dynamic 7 trajectory as Alice and removes it before payload detection (Wang et al., 2 Oct 2025).
This architecture is significant because early SE-AFDM analysis assumed LPPN synchronization and left its realization for future work, whereas the later design turns synchronization into an explicit system component. A plausible implication is that SE-AFDM’s practical feasibility depends as much on secure parameter alignment as on the secure waveform itself.
4. Eavesdropper model and security mechanism
The adversarial model in SE-AFDM is strong in waveform terms. Eve is typically assumed to know the public parameters 8, 9, the CPP length, and the 0 codebook, and may also estimate her own channel. What she does not know is the secret LPPN realization or generator configuration that determines Alice’s dynamic 1 sequence (Wang et al., 23 Sep 2025, Wang et al., 2 Oct 2025).
Under this asymmetry, Eve’s affine-domain observation can be rewritten as
2
where the data-like quantity presented to Eve is not 3 but
4
with
5
After equalization, Eve therefore recovers 6, not 7. Componentwise,
8
The published argument is an identifiability argument rather than a secrecy-capacity theorem: for each 9, the observation contains two unknowns, namely the information symbol 0 and the secure chirp factor determined by 1, so separation is impossible without the synchronized side information (Wang et al., 23 Sep 2025).
The same effect is expressed through an effective SINR analysis. Writing
2
the unknown secure rotation becomes self-interference. For the AWGN-based analysis, the eavesdropper SINR for symbol 3 is
4
When 5 is uniformly distributed over 6, the analysis shows that Eve’s SINR decreases as the 7 range expands, while Bob’s output SINR remains 8 because Bob does not incur self-interference from the known parameter sequence (Wang et al., 23 Sep 2025).
In the phase-function design approach, the security mechanism is instead formulated as brute-force demodulation resistance. If Eve uses 9, then after a first-order Taylor expansion,
0
so correct demodulation requires
1
The smaller this admissible mismatch interval, the denser the brute-force search grid must be (Liu et al., 14 May 2026).
5. Parameter design and secure design variants
A distinct line of secure AFDM work studies the design space of AFDM parameters themselves. In that analysis, four parameters are emphasized: 2 The main conclusions are that 3 is bounded by the actual Doppler support and the preset Doppler guard, 4 has minimum periodicity 5 and therefore effective range 6, and excessive 7 enlarges a “security-risk interval” for eavesdropping (Di et al., 25 Mar 2025).
More specifically, if
8
then secure-yet-decodable operation requires
9
or equivalently
0
If 1 is too small, some Doppler components are unresolved; if it is too large, the estimation region exceeds the preset guard interval and false paths are introduced (Di et al., 25 Mar 2025).
For 2, the same work shows
3
so 4 need only be searched or configured on 5. This periodicity is later echoed in the phase-function security design, where the effective 6 search interval is also treated as periodic with period 7, and where 8 is specifically identified as a poor operating point because the sine term in the derivative criterion can vanish (Di et al., 25 Mar 2025, Liu et al., 14 May 2026).
Delay-guard design is also security-relevant. If 9 is the actual maximum delay and 0 is the preset delay guard, then the interval
1
is characterized as a “security-risk interval”: any receiver, including an eavesdropper, that chooses an estimation limit inside that interval can fully estimate all delays. The recommended design is therefore
2
This shifts SE-AFDM parameterization away from purely communication-driven overprovisioning and toward security-aware guard sizing (Di et al., 25 Mar 2025).
The phase-function branch provides a different but complementary guideline. For the family
3
the derivative
4
implies eavesdropper search complexity 5, and with 6,
7
If 8 is also unknown, the joint exhaustive-search complexity becomes
9
This places SE-AFDM on a spectrum ranging from codebook-driven secret parameter hopping to continuous secure phase-law design (Liu et al., 14 May 2026).
6. Performance, implementation status, and limitations
Across the reported simulations, the dominant empirical result is consistent: Bob’s BER remains almost the same as that of conventional AFDM, whereas Eve’s BER worsens sharply as the secure parameter range expands and often tends toward 0, corresponding to random-guess performance for QPSK bits. In the original SE-AFDM simulations, Eve’s effective SINR under a single-path AWGN-oriented study with 1 dB decreases monotonically with 2 and eventually approaches about 3 dB. Under estimated CSI, using pilot SNR 4 dB and 5, Bob’s BER still coincides with AFDM while Eve’s BER remains near 6 (Wang et al., 23 Sep 2025).
The later synchronized SE-AFDM design reports a full high-mobility simulation setting with QPSK, 7 GHz, bandwidth 8 MHz, 9 kHz, 0, 1, 2, 3, delays 4, and maximum integer normalized Doppler 5, corresponding to 6 km/h. In that system, Bob again tracks conventional AFDM performance while Eve’s BER approaches 7 as 8 increases. The same work studies approximate brute-force search and reports that for 9, 00, and codebook interval 01, Eve requires a search interval below 02 to obtain BER below 03; BER exceeds 04 once the search interval is above 05 (Wang et al., 2 Oct 2025).
The phase-function design branch reports the same matched-user asymmetry in a different metric. For 06, QPSK, MMSE equalization, and the phase law
07
conventional AFDM has a mismatch interval around 08, whereas the proposed design with 09 reduces it to about 10, and with 11 the BER-versus-mismatch curve becomes impulse-like. In matched reception, conventional AFDM and the secure phase design exhibit essentially the same BER; under mismatch 12, conventional AFDM still decodes well while the secure design remains at a very high error floor (Liu et al., 14 May 2026).
Implementation evidence exists but is still limited. The synchronized SE-AFDM system has been validated on an SDR prototype with 13 GHz, 14 MHz, 15 kHz, 16, 17, 18, and 19, with an introduced frequency offset of 20 kHz to emulate approximately 21 km/h. In that prototype, Bob’s BER decreases with SNR while Eve exhibits an error floor around 22, indicating that synchronization failure, not merely thermal noise, remains the dominant impairment for the eavesdropper (Wang et al., 2 Oct 2025).
The limitations are equally clear in the literature. Published SE-AFDM analyses are not secrecy-capacity theorems; they are ambiguity-based, BER-based, SINR-based, or brute-force-complexity-based physical-layer security arguments. Security depends critically on protecting the LPPN generator configuration or the secure phase-function parameters. AWGN-based eavesdropper SINR derivations are available, but full multipath-fading security analysis remains incomplete. Active attacks, pilot contamination, authentication, covert communication, and multiuser secure AFDM are largely outside the present scope. The broader AFDM survey therefore treats physical-layer security as an inherent opportunity of chirp-parametrized AFDM rather than a completed security stack (Wang et al., 23 Sep 2025, Wang et al., 2 Oct 2025, Liu et al., 14 May 2026, Rou et al., 29 Jul 2025).