Skip to the content.

Awesome RIS Attacks and Defenses

This repository contains a collection of papers and resources on security and privacy issues related to reconfigurable intellegent surface (RIS).

Table of Contents

📃Survey

Application Focus

Year Publication Paper
2016 Reports on progress in physics A review of metasurfaces: physics and applications
2020 IEEE TCCN Reconfigurable intelligent surfaces for wireless communications: Principles, challenges, and opportunities
2022 IEEE STSP An overview of signal processing techniques for RIS/IRS-aided wireless systems
2022 Intelligent and Converged Networks Reconfigurable intelligent surfaces for wireless communications: Overview of hardware designs, channel models, and estimation techniques
2023 IET Communications A survey on reconfigurable intelligent surfaces: Wireless communication perspective
2023 IEEE Wireless Communications Integrated sensing and communication with reconfigurable intelligent surfaces: Opportunities, applications, and future directions
2022 Proceedings of the IEEE Toward ubiquitous sensing and localization with reconfigurable intelligent surfaces
2025 IEEE Communications Surveys & Tutorials The emergence of multi-functional and hybrid reconfigurable intelligent surfaces for integrated sensing and communications-a survey

Security Focus

Year Publication Paper
2025 IEEE Internet of Things Journal RIS-based physical layer security for integrated sensing and communication: A comprehensive survey
2023 IEEE OJ-COMS Security and privacy for reconfigurable intelligent surface in 6G: A review of prospective applications and challenges
2025 Discover Internet of Things A comprehensive survey on 6G-security: physical connection and service layers
2024 IEEE Communications Surveys & Tutorials Ris-assisted physical layer security in emerging rf and optical wireless communication systems: A comprehensive survey
2024 IEEE Open Journal of Vehicular Technology A survey on reconfigurable intelligent surface for physical layer security of next-generation wireless communications

Tutorial & Technical Document

Year Publication Paper
2022 IEEE Signal Processing Magazine Reconfigurable intelligent surfaces: A signal processing perspective with wireless applications
2023 ETSI Reconfigurable Intelligent Surfaces (RIS); Communication Models, Channel Models, Channel Estimation and Evaluation Methodology

⚔️Attacks

Attacking RIS-assisted Systems

Year Publication Attack Type Paper Code💻 / Demo✅
2020 IEEE Wireless Communications Letters Jamming IRS-based wireless jamming attacks: When jammers can attack without power
2022 ASIA CCS '22 Jamming Mirror, mirror on the wall: Wireless environment reconfiguration attacks based on fast software-controlled surfaces
2025 NDSS 2025 Jamming Spatial-domain wireless jamming with reconfigurable intelligent surfaces
2022 HotMobile '22 Eavesdropping Malicious mmWave reconfigurable surface: Eavesdropping through harmonic steering
2023 WiSec '23 Eavesdropping Wavefront manipulation attack via programmable mmWave metasurfaces: from theory to experiments
2024 IEEE S&P 2024 Eavesdropping MetaFly: Wireless Backhaul Interception via Aerial Wavefront Manipulation
2025 arXiv Spoofing RIS-Aided Positioning Under Adverse Conditions: Interference from Unauthorized RIS
2025 IEEE CSCN 2025 Spoofing MALRIS: Malicious Hardware in RIS-Assisted Wireless Communications
2024 Remote Sensing Spoofing & Jamming A broadband information metasurface-assisted target jamming system for synthetic aperture radar
2022 IEEE ISIT 2022 Denial-of-Service Controller manipulation attack on reconfigurable intelligent surface aided wireless communication

RIS for Attack

Year Publication Attack Type Paper Code💻 / Demo✅
2023 IEEE TWC Jamming Disco intelligent reflecting surfaces: Active channel aging for fully-passive jamming attack
2025 NDSS 2025 Jamming Spatial-domain wireless jamming with reconfigurable intelligent surfaces
2020 IEEE TWC Eavesdropping Intelligent reflecting surface aided pilot contamination attack and its countermeasure
2022 WiSec '22 Eavesdropping Metasurface-in-the-Middle Attack: From Theory to Experiment
2023 IEEE CNS 2023 Eavesdropping RMDM: Using Random Meta-Atoms to Send Directional Misinformation to Eavesdroppers
2022 HotMobile '22 Eavesdropping Malicious mmWave reconfigurable surface: Eavesdropping through harmonic steering
2023 WiSec '23 Eavesdropping Wavefront manipulation attack via programmable mmWave metasurfaces: from theory to experiments
2023 Nature Electronics Eavesdropping Metasurface-enabled smart wireless attacks at the physical layer
2023 HotMobile '23 Eavesdropping Remotely Positioned MetaSurface-Drone Attack
2025 GetMobile Eavesdropping MetaFly: Aerial "MetaSurface-in-The-Middle" Attacks on Wireless Backhaul Links
2025 arXiv Spoofing RIS-Aided Positioning Under Adverse Conditions: Interference from Unauthorized RIS
2023 IEEE S&P 2023 Spoofing mmSpoof: Spoofing Attacks on Automotive FMCW Radars using Millimeter-wave Reflect Array
2023 NDSS 2023 Spoofing MetaWave: Attacking mmWave Sensing with Meta-material-enhanced Tags
2023 SenSys '23 Spoofing RIStealth: Practical and Covert Physical-Layer Attack against WiFi-based Intrusion Detection via Reconfigurable Intelligent Surface
2024 CCS '24 Spoofing RISiren: Wireless Sensing System Attacks via Metasurface
2025 arXiv Spoofing Sensing Safety Analysis for Vehicular Networks with Integrated Sensing and Communication (ISAC)
2025 arXiv Eavesdropping Stealthy Voice Eavesdropping with Acoustic Metamaterials: Unraveling a New Privacy Threat
2025 IEEE TIFS Spoofing A Portable and Stealthy Inaudible Voice Attack Based on Acoustic Metamaterials

🛡️Defenses

Defending attacks on RIS-assisted systems

Year Publication Threat Type Paper Code💻 / Demo✅
2022 IEEE Access Jamming Anti-jamming RIS communications using DQN-based algorithm
2023 IEEE Wireless Communications Letters Jamming A Countermeasure Against RIS Jamming Attack in Physical-Layer Key Generation
2023 GLOBECOM 2023 Jamming An anti-jamming strategy for disco intelligent reflecting surfaces based fully-passive jamming attacks
2023 Electronics Jamming & Eavesdropping RIS-assisted robust beamforming for UAV anti-jamming and eavesdropping communications: A deep reinforcement learning approach
2025 arXiv Eavesdropping Hiding in Plain Sight: RIS-Aided Target Obfuscation in ISAC
2022 IEEE Transactions on Vehicular Technology Eavesdropping Reconfigurable intelligent surface-assisted secure mobile edge computing networks
2022 IEEE Wireless Communications Eavesdropping Secure beamforming for IRS-enhanced NOMA networks
2024 Sensors Eavesdropping An Underwater source location privacy protection scheme based on game theory in a multi-attacker cooperation scenario
2024 Photonics Eavesdropping Reconfigurable Intelligent Surface-Aided Security Enhancement for Vehicle-to-Vehicle Visible Light Communications
2022 The Journal of Supercomputing Eavesdropping Security performance analysis of RIS-assisted UAV wireless communication in industrial IoT
2024 Photonics Eavesdropping Reconfigurable Intelligent Surface-Aided Security Enhancement for Vehicle-to-Vehicle Visible Light Communications
2022 ICC 2022 Eavesdropping Robust design for STAR-RIS secured Internet of Medical Things
2024 IEEE Transactions on Communications Eavesdropping Security Enhancement for RIS-Aided MEC Systems with Deep Reinforcement Learning
2025 ICNC 2025 Eavesdropping Secure-IRS: Defending Against Adversarial Physical-Layer Sensing in ISAC System
2023 IEEE Transactions on Industrial Informatics Eavesdropping Deep reinforcement learning for RIS-aided secure mobile edge computing in industrial Internet of Things
2022 Physical Communication Eavesdropping Deep reinforcement learning based IRS-assisted mobile edge computing under physical-layer security

Defending against RIS for attack

Early Detection of Unauthorized RIS

Year Publication Paper Code💻 / Demo✅
2023 Optics Express Detection and mapping of specular surfaces using multibounce lidar returns
2025 ICC 2025 On the Detection of Non-Cooperative RISs: Scan B-Testing via Deep Support Vector Data Description
2025 arXiv Analysis and Detection of RIS-based Spoofing in Integrated Sensing and Communication (ISAC)
2022 IEEE Pervasive Computing See no evil: Discovering covert surveillance devices using thermal imaging

System-level Defenses

Year Publication Paper Code💻 / Demo✅
2024 IEEE SPAWC 2024 Benign and Malicious Reconfigurable Intelligent Surfaces in MISO Wiretap Channels
2023 IEEE Wireless Communications Letters A Countermeasure Against RIS Jamming Attack in Physical-Layer Key Generation
2023 IEEE OJ-COMS Counteracting eavesdropper attacks through reconfigurable intelligent surfaces: A new threat model and secrecy rate optimization
2025 Drones Cooperative Jamming for RIS-Assisted UAV-WSN Against Aerial Malicious Eavesdropping

RIS for Defense

Year Publication Method Paper Code💻 / Demo✅
2023 Electronics Optimization RIS-assisted robust beamforming for UAV anti-jamming and eavesdropping communications: A deep reinforcement learning approach
2023 IEEE OJ-COMS Optimization Counteracting eavesdropper attacks through reconfigurable intelligent surfaces: A new threat model and secrecy rate optimization
2024 GLOBECOM 2024 Optimization Online DRL-based Beam Selection for RIS-Aided Physical Layer Security: An Experimental Study
2024 IEEE Systems Journal Optimization Self-Sustainable Active Reconfigurable Intelligent Surfaces for Antijamming in Wireless Communications
2025 arXiv Optimization Optimizing Indoor RIS-Aided Physical-Layer Security: A Codebook-Generation Methodology and Measurement-Based Analysis
2023 Entropy Optimization A communication anti-jamming scheme assisted by RIS with angular response
2024 Photonics Optimization Reconfigurable Intelligent Surface-Aided Security Enhancement for Vehicle-to-Vehicle Visible Light Communications
2022 IEEE S&P 2022 Introducing Randomness IRShield: A countermeasure against adversarial physical-layer wireless sensing 💻
2022 MobiCom '22 Introducing Randomness Protego: securing wireless communication via programmable metasurface
2023 Applied Physics Letters Introducing Randomness Physical-level secure wireless communication using random-signal-excited reprogrammable metasurface
2025 Nature Communications Introducing Randomness Chaotic information metasurface for direct physical-layer secure communication
2024 Optica Spoofing the Attacker Audio misinformation encoding via an on-phone sub-terahertz metasurface
2025 IEEE S&P 2025 Spoofing the Attacker Spoofing eavesdroppers with audio misinformation
2024 IEEE Wireless Communications Letters Spoofing the Attacker Intelligent reflecting surface-aided radar spoofing
2025 IEEE CNS 2025 Spoofing the Attacker MetaHeart: Spoofing Vibrational Biometrics via Dynamic Metasurfaces
2025 Nature Communications Spoofing the Attacker Anti-radar based on metasurface
2023 IEEE Access Attenuation Mitigating inaudible ultrasound attacks on voice assistants with acoustic metamaterials
2023 JASA Attenuation 3D printed acoustic metamaterial filters for the mitigation of inaudible ultrasound attacks on smart speakers
2025 MobiCom 2025 Attenuation MetaGuardian: Enhancing Voice Assistant Security through Advanced Acoustic Metamaterials 💻

🛠️Tools

Year Publication / Organization Resources
2024 Mathworks Introduction to Reconfigurable Intelligent Surfaces (RIS)
2024 Mathworks Radar Sensing with Reconfigurable Intelligent Surfaces (RIS)
2024 Mathworks Model Reconfigurable Intelligent Surfaces with CDL Channels
2019 ASU Wireless Intelligence Lab DeepMIMO
2022 NVIDIA Sionna
2024 InterDigital NeoRadium
2023 ISAP 2023 Open Source RIS
2025 / RIS-Codes-Collection