This page provides a tutorial on how to construct a radio-frequency fingerprint identification (RFFI) system. The implementation depends on the wireless technology and the selected transmitter and receiver platforms. This tutorial provides general guidelines for designing such a system.

Overview

As shown below, an RFFI system consists of several devices under test (DUTs) and a receiver. Its objective is to identify or classify the DUTs by analysing the physical-layer signals captured by the receiver.

Deep-learning-based RFFI system workflow
Deep-learning-based RFFI system workflow. Source.

The software workflow involves signal collection, when required, followed by signal processing and machine learning. Collecting a new dataset requires signal-acquisition algorithms to capture wireless waveforms; alternatively, a public dataset can be used. Deep learning has been widely adopted in RFFI to improve classification accuracy.

Transmitter (DUTs)

Hardware

Many wireless devices can be used as DUTs. Although a custom device can be built, commercial off-the-shelf (COTS) development boards and kits usually reduce implementation time.

In general, they can be categorized into programmable and non-programmable. Vendors with programmable devices are listed as follows.

The table below summarises several LoRa development boards suitable for RFFI research.

Board Name Platform and Programming Language Link
Pycom LoPy4 Micropython (Python) https://docs.pycom.io/firmwareapi/pycom/network/lora/
Pycom FiPy Micropython (Python) https://docs.pycom.io/firmwareapi/pycom/network/lora/
Dragino LoRa Shields Arduino (C) Code Examples
Semtech LoRa Transceivers Mbed (C) Libraries vary with the boards (chips), e.g., SX1276MB1xAS

Non-programmable devices can also be used. For example, our smartphones support Wi-Fi and Bluetooth.

Software

Different development boards use different programming languages and development platforms. The transmitter must be programmed to send wireless packets, often by adapting examples from the manufacturer’s documentation. Vendors usually provide the required development software and software development kit (SDK).

For non-programmable devices, traffic can be generated through normal applications. For example, video streaming creates sustained Wi-Fi traffic on a smartphone, while a laptop can generate controlled traffic using the ping command.

Receiver

Hardware

Most COTS gateways, access points, and receivers do not provide access to physical-layer signals. Software-defined radios (SDRs) are therefore commonly used as receivers. An SDR uses a flexible analogue front end to convert the desired radio signal to baseband or an intermediate frequency. An analogue-to-digital converter then samples the signal to produce digital in-phase and quadrature (IQ) samples. Subsequent communication functions, such as packet detection and decoding, are implemented in software, giving researchers access to the physical-layer samples.

The table below summarises several SDRs available in our laboratory. The receiver should be selected according to the target communication technology, such as Wi-Fi, Zigbee, or LoRa. For example, RTL-SDR is unsuitable for Wi-Fi research because of its frequency-range and bandwidth limitations.

SDR Name Rx Frequency Range Bandwidth Development Platform
USRP N210+UBX 40 Daughter Board 10 MHz~6GHz 40 MHz MATLAB, UHD (C/Python APIs), GNU Radio, LabVIEW, etc.
Zynq+AD9361 70 MHz~6 GHz 56 MHz MATLAB, libiio (C/Python APIs), GNU Radio, etc.
ADALM-PLUTO 325 MHz~3.8 GHz 20 MHz MATLAB, libiio (C/Python APIs), GNU Radio, etc.
RTL-SDR 22 MHz~2.2 GHz 3.2 MHz MATLAB, pyrtlsdr (Python APIs), GNU Radio, etc.

Useful material to learn SDR: https://pysdr.org/index.html

Software

Signal Collection Module

Software is a critical part of SDR applications. For RFFI research, a signal-reception program is required to capture valid wireless packets. The figure below shows the flow chart of a basic signal-collection program.

Flow chart of an SDR signal-collection program
Basic processing flow for an SDR signal-collection program.

Packet detection, synchronisation, and carrier-frequency-offset (CFO) compensation can be implemented in MATLAB, Python, or C, depending on the real-time and data-rate requirements. Some applications also require MAC-address decoding to verify that each captured packet originated from the intended DUT. Signals can be stored in formats such as CSV, HDF5, MAT, or text, provided that they can be loaded correctly by the machine-learning module.

MATLAB provides several signal-collection examples. Select the documentation for the target communication protocol and study how each processing stage is implemented:

Deep Learning Module

After collecting sufficient signals from the DUTs, a deep-learning classifier can be trained using an architecture such as a CNN, LSTM, GRU, or transformer. Suitable frameworks include PyTorch, TensorFlow, and MATLAB Deep Learning Toolbox. PyTorch and TensorFlow are particularly well supported by their developer communities.

The neural network can operate directly on the collected IQ samples or on features produced through signal processing. For example, a fast Fourier transform (FFT) can convert the received signals into frequency-domain inputs.

If you are new to deep learning, the following introductory resources may be useful.

The following two examples provide implementations for RFFI:

  1. MATLAB, Detect WLAN Router Impersonation
  2. Tensorflow, Towards Scalable and Channel-Robust Radio Frequency Fingerprint Identification for LoRa

Note

Signal collection and machine learning do not need to use the same programming language. For example, MATLAB can collect and save the dataset, which can then be processed in Python for model development.

Wireless Monitoring (Optional)

Before developing the signal-collection software, confirm that the required wireless traffic is present. Wireshark is useful for monitoring and verification, although it may require a separate receiver.

Public Datasets

Several public datasets are available for RFFI research; see the RFFI datasets page for details. Using a public dataset removes the need for signal-acquisition hardware, although a suitable computer is still required for processing and model training.

General Procedures

  1. Program the development boards to transmit packets.
  2. Optionally verify the wireless transmissions using Wireshark.
  3. Develop the signal-collection program to capture packets from the development boards.
  4. Collect packets from all DUTs and save the IQ samples as training and test datasets.
  5. Design and train a neural network using the training data.
  6. Evaluate the trained model using the test data, typically through overall accuracy and a confusion matrix.

Steps 1-4 are not required if you are using public datasets.

  1. Guanxiong Shen, Junqing Zhang*, and Alan Marshall, “Deep Learning-Powered Radio Frequency Fingerprint Identification: Methodology and Case Study,” IEEE Communications Magazine, IEEE

  2. J. Zhang, R. Woods, M. Sandell, M. Valkama, A. Marshall, and J. Cavallaro, “Radio frequency fingerprint identification for narrowband systems, modelling and classification,” IEEE Trans. Inf. Forensics Security, vol. 16, pp. 3974–3987, 2021

    This paper systematically models the hardware impairments of narrowband transmitters and receivers, providing a deeper understanding of the principles underlying RFFI.

  3. G. Shen, J. Zhang, A. Marshall, L. Peng, and X. Wang, “Radio frequency fingerprint identification for LoRa using deep learning,” IEEE J. Sel. Areas Commun., vol. 39, no. 8, pp. 2604–2616, Aug. 2021.

    This LoRa-RFFI study explains how to select a signal representation according to the modulation characteristics and compares several basic neural-network architectures.

  4. G. Shen, J. Zhang, A. Marshall, and J. Cavallaro. “Towards Scalable and Channel-Robust Radio Frequency Fingerprint Identification for LoRa,” IEEE Trans. Inf. Forensics Security, 2022.

    This LoRa-RFFI study focuses on mitigating channel effects and also examines open-set recognition.

Datasets and Code

Please visit our datasets and code page for the RFFI datasets and source code shared by our group.