Spatial-Domain Wireless Jamming with Reconfigurable Intelligent Surfaces

Philipp Mackensen

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Wireless, Cellular & Satellite Security · Wireless, Cellular & Satellite Security

Overview

Wireless communication is fundamental to modern life, underpinning everything from smart home devices to critical infrastructure. However, the inherent openness of the wireless channel exposes these systems to various security threats, with wireless jamming being a long-standing and well-studied concern. Traditional jamming attacks typically involve an attacker broadcasting a strong interfering signal, effectively disabling all wireless devices within their operational range, leading to a denial-of-service condition. While effective, this broad-stroke approach lacks precision and can be easily detected.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to wireless jamming and device vulnerability
  2. 2:00 Explaining Reconfigurable Intelligent Surfaces (RAIS) technology
  3. 4:00 RAIS implementation details and open-source availability
  4. 4:30 The novel concept: spatial-domain jamming with RAIS
  5. 5:20 Overview of the experimental setup and attack strategy
  6. 6:00 Detailed explanation of passive optimization for signal shaping
  7. 8:00 Demonstrating active jamming and selective attack results

Spatial-Domain Wireless Jamming with Reconfigurable Intelligent Surfaces

Speakers: Philipp Mackensen

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=AgWX4uXTRvA

Overview

Wireless communication is fundamental to modern life, underpinning everything from smart home devices to critical infrastructure. However, the inherent openness of the wireless channel exposes these systems to various security threats, with wireless jamming being a long-standing and well-studied concern. Traditional jamming attacks typically involve an attacker broadcasting a strong interfering signal, effectively disabling all wireless devices within their operational range, leading to a denial-of-service condition. While effective, this broad-stroke approach lacks precision and can be easily detected.

This talk, presented by Philipp Mackensen and co-authored with Stefan Hayden, Zeskin Kristoff, Pa, and VHami, revisits the concept of wireless jamming through the lens of emerging wireless technologies. Specifically, the researchers investigate how Reconfigurable Intelligent Surfaces (RAIS) — a novel technology designed to actively manipulate the radio environment — can be leveraged to create highly sophisticated and spatially selective jamming attacks. Their work highlights a significant shift in attacker capabilities, demonstrating how RAIS can enable attackers to target individual or specific groups of devices while leaving others operational.

The core contribution of this research is the introduction and experimental validation of spatially selective jamming attacks using RAIS. By strategically controlling the reflection properties of an RAIS, an attacker can precisely steer jamming signals to specific victim devices, overcoming the indiscriminate nature of classical jamming. This advancement not only underscores the evolving threat landscape in wireless security but also serves as a vivid example of the potential for RAIS technology to be exploited for malicious purposes, significantly lowering the technical bar for sophisticated and targeted denial-of-service attacks.

Background

▶ Watch: Introduction to wireless jamming and device vulnerability (0:00)

Wireless communication, despite its ubiquity, operates on an inherently exposed medium: the open wireless channel. This fundamental characteristic makes all wireless devices vulnerable to interference, particularly wireless jamming. In a classical jamming scenario, an adversary simply emits a powerful, broadband interfering signal intended to overwhelm legitimate transmissions. This brute-force method, while effective at causing a denial of service, is typically indiscriminate, impacting all devices within the jammer's reach. Such attacks have real-world implications, with criminals reportedly using jamming to disable smart home security systems during burglaries.

The challenge with traditional jamming lies in its lack of granularity. There are many scenarios where an attacker might desire to disable only a specific subset of devices rather than an entire network. This is where the concept of smart radio environments and Reconfigurable Intelligent Surfaces (RAIS) becomes pivotal. Traditionally, wireless communication link optimization focuses on the transmitter and receiver, taking the propagation environment between them as a fixed given. Smart radio environments challenge this assumption by proposing that the environment itself can be actively adjusted to enhance wireless communication.

RAIS are the embodiment of this concept. These devices consist of numerous subwavelength reflective elements distributed across a surface. Each of these elements is individually addressable and can be digitally controlled to alter its reflection coefficient, typically between +1 and -1 in a binary tunable configuration. This allows the RAIS to dynamically adapt its reflection properties to steer wireless signals in desired directions, effectively shaping the propagation channel. The speakers noted that RAIS can be implemented as low-cost Printed Circuit Boards (PCBs), with reflective elements on the front and control circuitry on the back. Crucially for this research, such devices are becoming readily available, with open-source designs accessible on platforms like GitHub. The specific RAIS used in their study featured 768 elements, highlighting the fine-grained control these surfaces offer. The advent of RAIS technology necessitates a re-evaluation of wireless security threats, as these advancements inherently shift attacker capabilities and open new avenues for sophisticated attacks.

Key Findings

▶ Watch: RAIS implementation details and open-source availability (4:00)

The central discovery of this research is the successful demonstration of spatially selective jamming attacks against Wi-Fi networks by leveraging Reconfigurable Intelligent Surfaces (RAIS). This capability fundamentally transforms the nature of wireless jamming from an indiscriminate denial-of-service weapon into a precise, surgical instrument for targeted disruption.

The key findings include:

  • Single-Target Selective Jamming: The researchers conclusively showed that an attacker, equipped with an RAIS, can reliably jam a single, specific victim device within a wireless network while ensuring that all other devices in the same environment remain fully operational. This was experimentally validated for all devices in their testbed, demonstrating robust and consistent performance.
  • Multi-Target and Exclusionary Jamming: Beyond single-target attacks, the methodology extends to more complex scenarios. The team demonstrated the ability to jam multiple selected devices simultaneously or, conversely, to jam all devices except for a specific set. An extreme example involved jamming all but a single device, showcasing the flexibility of the approach.
  • Effectiveness in Close Proximity: The attack proved remarkably effective even when target and non-target devices were in very close physical proximity. Experiments with two Raspberry Pis placed just five millimeters apart confirmed that the RAIS could still differentiate and selectively jam one device while the other maintained connectivity, challenging assumptions about spatial separation as a defense.
  • Dynamic Targeting: The ability to dynamically switch RAIS configurations allows for real-time changes in jamming targets. This means an attacker can quickly reconfigure the RAIS to shift the jamming focus from one device to another, enabling adaptive and persistent disruption against moving or changing targets.
  • Lowered Bar for Sophisticated Attackers: The research concludes that RAIS technology significantly lowers the technical barrier for sophisticated jamming attacks. By enabling fine-grained spatial control over interference, RAIS allows attackers to execute highly targeted denial-of-service operations with greater precision and stealth than previously possible with classical jamming techniques. This capability requires only minimal observational input (Received Signal Strength Indicator or RSSI) from the adversary, without needing explicit knowledge of the room layout.

These findings underscore a critical shift in the wireless security landscape, demonstrating that emerging smart radio environment technologies, while promising for communication enhancement, also present potent new tools for adversaries.

Technical Deep Dive

▶ Watch: The novel concept: spatial-domain jamming with RAIS (4:30)

The proposed spatially selective jamming attack leverages the unique capabilities of Reconfigurable Intelligent Surfaces (RAIS) in a sophisticated two-step process: passive optimization followed by active jamming. The underlying principle relies on the RAIS's ability to dynamically shape the wireless propagation environment, coupled with the fundamental concept of channel reciprocity.

The experimental setup designed to validate this attack was meticulously constructed. It comprised two distinct rooms:

  1. Victim Room: This room hosted a standard Wi-Fi network, including an access point (AP) and ten Raspberry Pi devices acting as victim clients, all connected via Wi-Fi.
  2. Attacker Room: Located separately, this room contained the attacker's equipment. This primarily consisted of a directional antenna pointed towards an RAIS. The RAIS itself was a sophisticated device featuring 768 individual reflective elements, capable of precise signal manipulation.

The attack strategy unfolds in two critical phases:

Phase 1: Passive Optimization of the RAIS Configuration

The first phase is dedicated to intelligently configuring the RAIS without transmitting any jamming signals. The attacker's objective is to determine an RAIS configuration that will selectively enhance signal reception from the target device(s) while simultaneously minimizing reception from non-target devices.

  • Eavesdropping: The attacker passively listens to the wireless environment of the victim room. This involves monitoring the Received Signal Strength Indicator (RSSI) from the various devices. Crucially, the adversary does not require prior knowledge of the room layout or precise device locations; only the RSSI values are needed.
  • Greedy Optimization Algorithm: Given the vast number of possible configurations for an RAIS with 768 elements (2^768 possible states for a binary tunable RAIS), an exhaustive search is computationally infeasible. To overcome this, the researchers employed a greedy optimization algorithm. This algorithm systematically explores the configuration space to find a local optimum. The optimization goal is precisely defined: maximize the RSSI from the target device(s) while minimizing the RSSI from all other non-target devices.
  • Optimization Process: The algorithm was run for approximately 10,000 steps, taking around 5 minutes to converge. During this period, the RAIS's elements are iteratively adjusted, and the resulting RSSI changes are observed. The goal is to "shape the received signals" such that the target device experiences a strong signal path through the RAIS, while other devices experience weakened or destructive interference paths. This process effectively exploits the multipath propagation characteristics of the wireless channel and the spatial diversity offered by the RAIS.
  • Output: The culmination of this phase is an optimized RAIS configuration. This configuration effectively "encodes" the desired spatial reception pattern: strong reception from the target device(s) and weak reception from non-target devices.

Phase 2: Active Jamming Leveraging Channel Reciprocity

The second phase transitions from passive observation to active disruption, making use of the optimized RAIS configuration from Phase 1.

  • Exploiting Channel Reciprocity: The core principle enabling this phase is channel reciprocity. In physics, this principle states that if a signal can travel from point A to point B, it can also travel from point B to point A with the same channel characteristics. In the context of the RAIS attack, this means that if the RAIS configuration was optimized to receive a strong signal from a target device and a weak signal from non-target devices, then transmitting a signal through that same RAIS configuration will result in a strong signal reaching the target device and a weak signal reaching the non-target devices.
  • Jamming Signal Transmission: With the RAIS configured based on the passive optimization, the attacker's directional antenna then transmits a jamming signal. Due to channel reciprocity, this jamming signal is effectively steered by the RAIS. The target device(s) will consequently receive a very strong jamming signal, leading to a denial of service. Conversely, the non-target devices will receive only a very weak jamming signal, allowing them to remain operational.

This two-step process, combining intelligent passive optimization with the physical property of channel reciprocity, allows for unprecedented precision in wireless jamming. The use of an open-source RAIS design, readily available on platforms like GitHub, further underscores the accessibility and potential for widespread exploitation of this technique.

Demo / Proof of Concept

▶ Watch: Detailed explanation of passive optimization for signal shaping (6:00)

The researchers provided compelling experimental results to demonstrate the efficacy and versatility of their spatially selective jamming attack. These demonstrations were primarily based on measurements of packet reception for each device, serving as a direct indicator of connectivity and jamming effectiveness.

One key demonstration involved a matrix visualization of packet reception. In this matrix, each row represented the specific device targeted for jamming. The cells within the matrix indicated the packet reception rate for each of the ten Raspberry Pi devices in the victim room. Brighter values or cells signified great packet reception, indicating the device was fully operational, while dark purple cells meant the device was jammed and not operating normally. The diagonal of this matrix, where the row's target device matched the column's observed device, consistently showed dark purple, while off-diagonal elements remained bright. This visually confirmed that the attack successfully achieved single-target selective jamming for every individual device in the testbed.

Beyond single-target attacks, the team showcased more complex scenarios:

  • Jamming All But One: An extreme case was demonstrated where the goal was to jam all devices except for a single designated device. For instance, when attempting to jam all but device D1, the results showed that D1 remained operational, as did the access point. Interestingly, device D7 also remained operational in this specific scenario. The speakers attributed D7's resilience to its very close proximity to the access point, which resulted in an exceptionally strong legitimate signal, making it more challenging to overwhelm with the steered jamming signal. This highlights a practical limitation where extremely strong legitimate signals might resist jamming, but the overall selective nature of the attack remained intact for the majority of devices.
  • Close Proximity Test: To push the limits of spatial selectivity, an experiment was conducted with two Raspberry Pi devices placed in extremely close proximity – just five millimeters apart. The results confirmed that the RAIS could still differentiate between these two closely spaced devices. The researchers successfully demonstrated jamming device D5 while D6 remained operational, then jamming D6 while D5 operated normally, and finally jamming both devices simultaneously. This particular demonstration was crucial in proving the fine-grained spatial control offered by the RAIS, even in scenarios where physical separation is minimal.
  • Dynamic Targeting: The experiments also underscored the attack's dynamic nature. By simply switching the RAIS configuration, the attacker could rapidly change the target of the jamming signal. This capability allows for adaptive and real-time targeting, making the attack highly flexible and difficult to predict or counter based on static defenses.

In summary, the experimental proof of concept vividly illustrated that Reconfigurable Intelligent Surfaces enable sophisticated, spatially selective jamming. The detailed packet reception measurements and the specific scenarios tested (single-target, multi-target, close-proximity, dynamic) provided concrete evidence that this emerging technology significantly enhances attacker capabilities in the wireless domain.

Defensive Implications

▶ Watch: Demonstrating active jamming and selective attack results (8:00)

The advent of spatially selective jamming using Reconfigurable Intelligent Surfaces (RAIS) presents a novel and significant challenge to wireless network security. Defenders must evolve their strategies beyond traditional jamming countermeasures, which often assume indiscriminate, wide-area interference. The precision offered by RAIS-enabled attacks necessitates a multi-faceted defensive approach.

Here are key defensive implications and potential mitigation strategies:

  • RAIS Detection and Physical Security: The most direct defense would be to prevent unauthorized RAIS deployment. Organizations and individuals should be aware of what RAIS are and implement physical security measures to detect or prevent their installation in proximity to sensitive wireless environments. Given that RAIS can be low-cost PCBs and open-source, they could be discreetly deployed. Monitoring for unusual electromagnetic emissions or reflections in critical areas might also become necessary.
  • Advanced Jamming Detection: Current jamming detection systems primarily look for widespread signal disruption or high noise floors across broad frequency ranges. Spatially selective jamming, however, might only affect a small subset of devices, potentially appearing as isolated connection issues rather than a general network outage. Defenders need more sophisticated jamming detection algorithms capable of identifying localized or targeted interference patterns. This could involve anomaly detection based on individual device performance metrics (e.g., sudden, localized drops in packet reception or throughput for specific devices) rather than network-wide averages.
  • Dynamic Spectrum Access and Frequency Hopping: While the current attack operates on the physical layer spatially, the Q&A session hinted at combining this with spectral and temporal domains. Implementing frequency hopping spread spectrum (FHSS) or other forms of dynamic spectrum access (DSA) could make it harder for an attacker to maintain a consistent jamming signal on the target's operating frequency. If the target device frequently changes its operating channel, the attacker would need to continuously re-optimize the RAIS or apply a broadband jam, which would negate the selective advantage.
  • Protocol-Level Resilience: The Q&A also touched upon control plane jamming. While this attack focuses on the physical layer, future work might combine it with protocol-level targeting. Defenders should design wireless protocols with greater resilience to control channel disruption. This includes robust retransmission mechanisms, redundant control channels, and diverse channel access methods.
  • Signal Strength Monitoring and Anomaly Detection: Constant monitoring of Received Signal Strength Indicator (RSSI) and Signal-to-Noise Ratio (SNR) across all devices can provide early warnings. Sudden, localized drops in SNR for specific devices, especially if not correlated with environmental factors or device mobility, could indicate a targeted RAIS attack. Machine learning models could be trained to identify these anomalous patterns.
  • Physical Layer Security Measures: Exploring physical layer security techniques that make it harder for an adversary to passively eavesdrop or exploit channel reciprocity could be beneficial. This might include advanced encryption at the physical layer or techniques that deliberately make the channel non-reciprocal for unauthorized entities.
  • Network Segmentation: For critical infrastructure or sensitive smart home devices, network segmentation can limit the impact of a successful selective jamming attack. If an attacker can only jam devices within a specific segment, the overall system resilience is improved.

In conclusion, the emergence of RAIS-enabled spatial jamming necessitates a proactive and adaptive defensive posture. A combination of physical security, advanced detection mechanisms, dynamic spectrum management, and protocol-level resilience will be crucial in mitigating this evolving threat.

Key Takeaways

  • RAIS Enables Spatially Selective Jamming: Reconfigurable Intelligent Surfaces (RAIS) can be exploited to perform highly targeted wireless jamming attacks, moving beyond traditional indiscriminate denial-of-service.
  • Two-Step Attack Methodology: The attack involves a passive optimization phase using a greedy algorithm to configure the RAIS for selective signal reception, followed by an active jamming phase that leverages channel reciprocity to steer jamming signals precisely.
  • Minimal Adversary Knowledge Required: The attacker only needs to observe Received Signal Strength Indicator (RSSI) values; knowledge of the physical room layout or precise device locations is not necessary.
  • Proven Effectiveness: The attack successfully demonstrated single-target, multi-target, and exclusionary jamming, even against devices placed as close as five millimeters apart.
  • Dynamic and Adaptable: Attackers can dynamically reconfigure the RAIS to change jamming targets in real-time, enhancing the attack's flexibility and persistence.
  • Lowered Bar for Sophistication: RAIS technology significantly lowers the technical barrier for sophisticated attackers to execute precise and targeted wireless denial-of-service operations.

About the Speaker(s)

Philipp Mackensen was a key presenter for this research at the NDSS Symposium, sharing the findings of the paper titled "Spatial-Domain Wireless Jamming with Reconfigurable Intelligent Surfaces." He delivered the second part of the talk, detailing the experimental setup, methodology, and results of their innovative work. The research was a joint effort with his co-authors Stefan Hayden, Zeskin Kristoff, Pa, and VHami.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original wireless security research that weaponizes RIS technology in a way the field hasn't fully confronted yet. The two-phase attack — greedy passive optimization plus channel-reciprocity-based jamming — is technically clean and the 5mm proximity result is the kind of concrete, uncomfortable finding that makes a conference worth attending.

Heather Calloway (CISO) — WEAK

Technically sound and genuinely novel research demonstrating that RIS technology enables precise, targeted wireless jamming. The problem is real and the experimental work is credible — but the talk never crosses into operator territory, and the defensive section reads like a graduate thesis bibliography rather than guidance anyone can act on.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025