Computer Science editorial
Open AccessOA2026
CITADEL: CSI-Based Jamming Detection and Open-Set Classification for IIoT Networks
A lightweight two-stage pipeline achieving 100% known-attack detection and 97.1% zero-day detection at 0.4% false positive rate, with inference in 14.2 ms on an edge GPU.
Aymen Bouferroum; Ildi Alla; Valeria Loscri; Abderrahim Benslimane; Vincent Lendersยท 2026ยท DOI 10.48550/arXiv.2606.22939
The core problem
Radio frequency (RF) jamming poses a critical threat to the availability of wireless Industrial Internet of Things (IIoT) networks. Existing detection and classification techniques are poorly suited to this setting: coarse signal-strength and cross-layer features lack information richness, while raw I/Q baseband approaches require hardware and throughput that is impractical at the scale of hundred-node IIoT deployments. This paper presents CITADEL, a lightweight two-stage hierarchical pipeline that uses only Channel State Information (CSI) measurements, which are natively available on commodity IIoT devices, to detect and classify jamming attacks including previously unseen ones. While prior work has shown that jamming leaves observable CSI signatures, CITADEL is the first system to translate this insight into an end-to-end pipeline that jointly achieves closed-set classification of known attacks, open-set detection of zero-day attacks, and resistance to adversarial evasion. The system is evaluated across 6 known attack types and 15 zero-day scenarios, and compared against eight baselines.
Innovation
CITADEL achieves 100% known-attack detection and 97.1% zero-day detection at a 0.4% end-to-end false positive rate. Under adversarial evaluation spanning white-box and black-box threat models, gradient-based evasion remains below 2% across all tested perturbation budgets, and the strongest published CSI attack generator achieves less than 5% average evasion. A systematic comparison against eight baselines confirms that no existing method achieves comparable performance on CSI data across all three axes: detection, generalization, and robustness. The full pipeline completes inference in 14.2 ms at 95.9 mJ on an edge GPU. These results establish CITADEL as a practical solution for large-scale IIoT network security.
Radio frequency (RF) jamming poses a critical threat to the availability of wireless Industrial Internet of Things (IIoT) networks. Existing detection and classification techniques are poorly suited to this setting: coarse signal-strength and cross-layer features lack information richness, while raw I/Q baseband approaches require hardware and throughput that is impractical at the scale of hundred-node IIoT deployments. This paper presents CITADEL, a lightweight two-stage hierarchical pipeline that uses only Channel State Information (CSI) measurements, which are natively available on commodity IIoT devices, to detect and classify jamming attacks including previously unseen ones. While prior work has shown that jamming leaves observable CSI signatures, CITADEL is the first system to translate this insight into an end-to-end pipeline that jointly achieves closed-set classification of known attacks, open-set detection of zero-day attacks, and resistance to adversarial evasion. The system is evaluated across 6 known attack types and 15 zero-day scenarios, and compared against eight baselines.
CITADEL employs a two-stage hierarchical pipeline. The first stage performs binary detection of jamming versus normal operation using CSI features. The second stage classifies the detected jamming into known attack types or flags it as a zero-day (unknown) attack. The pipeline is designed to be lightweight, leveraging only CSI measurements that are natively available on commodity IIoT devices. The architecture is illustrated below:
Why it matters
The results demonstrate that CITADEL effectively addresses the limitations of existing jamming detection and classification techniques for IIoT networks. By leveraging CSI, which is natively available on commodity devices, CITADEL avoids the hardware and throughput requirements of raw I/Q approaches while providing richer information than coarse signal-strength features. The two-stage hierarchical design enables both closed-set classification of known attacks and open-set detection of zero-day attacks, a capability not jointly achieved by prior systems. The resistance to adversarial evasion, with gradient-based evasion below 2% and the strongest CSI attack generator achieving less than 5% average evasion, highlights the robustness of the approach. The low inference latency and energy consumption on an edge GPU make CITADEL suitable for deployment in large-scale IIoT networks with hundreds of nodes. The systematic comparison against eight baselines confirms that CITADEL outperforms existing methods across detection, generalization, and robustness. Future work may explore extending the approach to other wireless technologies and attack types.
Who should read this
CS practitioners and researchers
Opening member contentโฆ