# How RuView’s Adversarial Detector Identifies Spoofing Attempts

> Discover how RuView’s adversarial detector identifies spoofing by analyzing CSI patterns for physical impossibilities and unusual energy spikes, ensuring robust detection.

- Repository: [rUv/RuView](https://github.com/ruvnet/RuView)
- Tags: deep-dive
- Published: 2026-03-08

---

**RuView’s adversarial detector identifies spoofing attempts by calibrating a statistical baseline from the first 100 frames, then flagging physically impossible CSI patterns—such as phase jumps exceeding 2.5 radians, flat-lined amplitudes, or 50× energy spikes—while using a 20-frame cooldown to prevent alert flooding.**

The **adversarial detector** is a critical security component in the RuView open-source project, designed to protect WiFi-based sensing systems from replay attacks, signal injection, and hardware malfunction. Implemented in the `wifi-densepose-wasm-edge` crate, the detector processes Channel State Information (CSI) frames in real-time to distinguish legitimate human motion from adversarial spoofing attempts.

## Three-Stage Detection Pipeline

The adversarial detector operates through a sequential three-stage pipeline implemented in [`rust-port/wifi-densepose-rs/crates/wifi-densepose-wasm-edge/src/adversarial.rs`](https://github.com/ruvnet/RuView/blob/main/rust-port/wifi-densepose-rs/crates/wifi-densepose-wasm-edge/src/adversarial.rs).

### Stage 1: Baseline Calibration

Before detection begins, the system establishes a statistical baseline using the first `BASELINE_FRAMES` (100) frames. During this phase, the `process_frame` loop computes:

- Per-subcarrier mean amplitude
- Overall signal-energy baseline

This calibration occurs in lines 82-106 of [`adversarial.rs`](https://github.com/ruvnet/RuView/blob/main/adversarial.rs), ensuring the detector understands normal environmental conditions before evaluating anomalies.

### Stage 2: Heuristic Anomaly Checks

After calibration, each incoming frame undergoes four physical heuristic checks designed to identify spoofing attempts that violate electromagnetic propagation constraints:

**Phase-Jump Detection**
The detector computes the absolute phase difference between the current and previous frame for every subcarrier. If more than 50% of subcarriers exceed the `PHASE_JUMP_THRESHOLD` of 2.5 radians, the system flags an anomaly. This catches abrupt phase shifts impossible in natural human motion (lines 13-25).

**Amplitude Flat-Line Detection**
Calculating variance across subcarrier amplitudes, the detector identifies stuck sensors or replayed data when variance falls below `MIN_AMPLITUDE_VARIANCE` (0.001) while the mean remains non-zero (lines 28-46).

**Energy-Spike Detection**
Comparing current total energy against the calibrated baseline, the system detects physically impossible surges when the ratio exceeds `MAX_ENERGY_RATIO` (50×), typical of injected or replayed frames (lines 48-60).

**Cross-Consistency Check**
The detector implicitly couples phase and amplitude heuristics, requiring multiple anomalies to fire simultaneously before reporting spoofing, significantly reducing false positives from benign motion.

### Stage 3: Cooldown Gating

Upon detecting an anomaly, the system enters a cooldown period defined by `ANOMALY_COOLDOWN` (20 frames). During this window, additional anomalies are suppressed to prevent alert flooding on a single spoofing event (lines 68-74).

## Core Implementation in adversarial.rs

The adversarial detector is implemented as the `AnomalyDetector` struct in the WASM-edge crate, designed for zero-allocation, real-time operation.

```rust
use wifi_densepose_wasm_edge::adversarial::AnomalyDetector;

// Create a new detector (const‑fn, zero‑allocation)
let mut detector = AnomalyDetector::new();

// Feed frames one‑by‑one (phases & amplitudes from CSI)
for (phases, amps) in csi_stream {
    if detector.process_frame(&phases, &amps) {
        println!("⚠️  Spoofing / anomaly detected!");
    }
}

// Total anomalies seen since start
println!("Total anomalies: {}", detector.total_anomalies());

```

For Python environments, the compiled WASM module exposes the same interface via `wasmtime`:

```python
import wasmtime, json

# Load compiled WASM (built from the crate)

store = wasmtime.Store()
module = wasmtime.Module(store.engine, "wifi_densepose_wasm_edge.wasm")
instance = wasmtime.Instance(store, module, [])

# Grab exported functions

new = instance.exports(store)["anomaly_detector_new"]
process = instance.exports(store)["anomaly_detector_process_frame"]
total = instance.exports(store)["anomaly_detector_total_anomalies"]

det = new(store)

for frame in csi_frames:
    phases = frame["phases"]
    amps   = frame["amplitudes"]
    # Pass pointers / lengths according to the WASM ABI (omitted for brevity)

    if process(store, det, phases_ptr, len(phases), amps_ptr, len(amps)):
        print("Anomaly detected!")

print("Total anomalies:", total(store, det))

```

## Physical Heuristics Explained

The adversarial detector relies on electromagnetic propagation physics to distinguish legitimate human motion from spoofing attempts:

- **Phase coherence**: Natural human movement creates gradual phase shifts across subcarriers due to continuous path length changes. Spoofing via replay or injection often produces discontinuous phase jumps exceeding 2.5 radians instantaneously.

- **Amplitude diversity**: Real-world multipath environments exhibit variance across subcarrier amplitudes. Flat-lined amplitudes (variance < 0.001) indicate sensor malfunction or replayed static signals.

- **Energy conservation**: WiFi transmission power is physically constrained. Energy spikes 50× above baseline violate power budgets and indicate external injection or amplification attacks.

## Summary

- RuView’s **adversarial detector** operates in the `wifi-densepose-wasm-edge` crate as the `AnomalyDetector` struct.
- The system uses a **three-stage pipeline**: 100-frame baseline calibration, four heuristic anomaly checks, and 20-frame cooldown gating.
- **Four physical heuristics** identify spoofing: phase-jump detection (>2.5 rad), amplitude flat-line detection (<0.001 variance), energy-spike detection (>50× baseline), and cross-consistency validation.
- The implementation is **zero-allocation** and compatible with both Rust native and Python WASM runtimes.

## Frequently Asked Questions

### What types of spoofing attacks can the RuView adversarial detector identify?

The detector identifies **replay attacks**, where previously recorded CSI frames are retransmitted; **signal injection attacks**, where adversaries transmit crafted packets with impossible phase or energy characteristics; and **hardware malfunction**, such as stuck sensors producing flat-lined amplitude readings.

### How does the baseline calibration prevent false positives?

The **100-frame baseline calibration** establishes per-subcarrier mean amplitudes and overall energy levels specific to the current environment. By learning normal multipath conditions and transmission power levels before detection begins, the system avoids flagging benign environmental variations as anomalies.

### Can the detection thresholds be customized for different environments?

While the current implementation uses compile-time constants (`PHASE_JUMP_THRESHOLD`, `MAX_ENERGY_RATIO`, etc.) defined in [`adversarial.rs`](https://github.com/ruvnet/RuView/blob/main/adversarial.rs), the modular design allows recompilation with adjusted thresholds for high-interference industrial environments or low-power IoT deployments where physical constraints differ.

### What happens when the detector identifies a spoofing attempt?

When `process_frame` returns `true`, indicating an anomaly, the detector increments the internal anomaly counter and enters a **20-frame cooldown period**. During cooldown, subsequent frames are processed but suppressed from triggering additional alerts, preventing system flooding while maintaining a count of total detected events via `total_anomalies()`.