DETECTION OF REPLAY/RELAY ATTACKS IN WIRELESS SYSTEMS USING RF-FINGERPRINTING AND SDR
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1315Keywords:
radio frequency fingerprint, RF-fingerprinting, Replay attack, Relay attack, Software-Defined Radio, SDR, keyless entry, physical-layer authentication, Internet of Things, carrier frequency offset, IQ imbalanceAbstract
This paper systematizes methods for detecting Replay and Relay attacks in wireless systems based on radio-frequency fingerprinting (RF-fingerprinting) of the signal using Software-Defined Radio (SDR) receivers. It is shown that both attack types preserve data correctness at the protocol level, so their detection is only possible through analysis of physical hardware artifacts of the transmitter and propagation channel rather than cryptographic or timing protocol features. A comparative analysis of SDR platforms (RTL-SDR V3, HackRF One, ADALM-PLUTO, USRP B210) relevant to Replay/Relay detection is performed. A generalized, protocol-independent detection architecture is proposed, combining an SDR receiver, an IQ preprocessing module, an RF-fingerprint extractor, and a channel-analysis module that evaluates propagation delay and relay-induced distortions in parallel. The detection task is formalized as metric classification in embedding space combined with two additional criteria — payload correlation for Replay and a channel-anomaly indicator for Relay. A decision algorithm is developed that classifies a signal as original, Replay, Relay, or belonging to an unknown device. Analysis of available experimental results confirms the practical feasibility of the proposed approach, with reported accuracy of 95–99% for original/attack discrimination on both budget and high-end SDR hardware.
Downloads
References
Danev, B., Zanetti, D., & Capkun, S. (2012). On physical-layer identification of wireless devices. ACM Computing Surveys, 45(1), Article 6. https://doi.org/10.1145/2379776.2379782
Xie, L., Peng, L., Zhang, J., et al. (2024). Radio frequency fingerprint identification for Internet of Things: A survey. Security and Safety, 3, Article 2023022. https://doi.org/10.1051/sands/2023022
Abbas, S., Abu Talib, M., Nasir, Q., et al. (2024). Radio frequency fingerprinting techniques for device identification: A survey. International Journal of Information Security, 23(2), 1389-1427. https://doi.org/10.1007/s10207-023-00801-z
Francillon, A., Danev, B., & Capkun, S. (2011). Relay attacks on passive keyless entry and start systems in modern cars. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2011). https://eprint.iacr.org/2010/332
Rasmussen, K. B., & Capkun, S. (2010). Realization of RF distance bounding. In Proceedings of the 19th USENIX Security Symposium (pp. 389-402). USENIX Association.
Bianchi, T., Brighente, A., Conti, M., & Pavan, E. (2025). SoK: Stealing cars since remote keyless entry introduction and how to defend from it. In Proceedings of the 3rd USENIX Symposium on Vehicle Security and Privacy (VehicleSec 2025) (pp. 161-178). USENIX Association.
Wang, Y., Zou, J., & Zhang, K. (2023). Deep-learning-aided RF fingerprinting for NFC relay attack detection. Electronics, 12(3), Article 559. https://doi.org/10.3390/electronics12030559
Quintero, J. C. M., Cuesta, E. P. E., & Lopez, L. J. R. (2023). A new method for the detection and identification of the replay attack on cars using SDR technology and classification algorithms. Results in Engineering, 19, Article 101243. https://doi.org/10.1016/j.rineng.2023.101243
Ahmed, A., Quoitin, B., Gros, A., & Moeyaert, V. (2024). A comprehensive survey on deep learning-based LoRa radio frequency fingerprinting identification. Sensors, 24(13), Article 4411. https://doi.org/10.3390/s24134411
Al-Shawabka, A., et al. (2020). Exposing the fingerprint: Dissecting the impact of the wireless channel on radio fingerprinting. In IEEE INFOCOM 2020-IEEE Conference on Computer Communications (pp. 646–655). IEEE. https://doi.org/10.1109/INFOCOM41043.2020.9155259
Restuccia, F., D’Oro, S., Al-Shawabka, A., et al. (2019). DeepRadioID: Real-time channel-resilient optimization of deep learning-based radio fingerprinting algorithms. In Proceedings of the Twentieth ACM International Symposium on Mobile Ad Hoc Networking and Computing (pp. 51-60). Association for Computing Machinery. https://doi.org/10.1145/3323679.3326503
Dhakal, R., Kandel, L., & Shekhar, P. (2025). Radio frequency fingerprinting authentication for IoT networks using Siamese networks. IoT, 6(3), Article 47. https://doi.org/10.3390/iot6030047
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Георгій Лобан, Тарас Луковський

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.