Multi-user physical layer authentication method based on unsupervised KAN-AE

A multi-user physical layer authentication method constructed using an unsupervised Kolmogorov-Arnold neural network autoencoder (KAN-AE) solves the data dependency and environmental robustness issues of hardware fingerprint authentication in consumer-grade WiFi scenarios, achieving dynamic expansion of multi-user authentication and high accuracy.

CN121865261APending Publication Date: 2026-04-14SICHUAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN UNIV
Filing Date
2025-12-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing physical layer authentication schemes based on hardware fingerprints rely on large-scale labeled data in consumer-grade WiFi scenarios, which are not robust enough to noise and environmental changes and have limited dynamic expansion capabilities for multiple users.

Method used

A multi-user physical layer authentication method is constructed using an unsupervised Kolmogorov-Arnold neural network autoencoder (KAN-AE). By combining a dual autoencoder structure and a two-stage adversarial training strategy with CSI-RFF features, a highly robust authentication method under few-sample conditions is achieved, and dynamic expansion to multiple users is supported.

Benefits of technology

It achieves highly robust and low-cost multi-user physical layer authentication on consumer-grade WiFi devices, reducing reliance on expensive hardware and manual labeling, improving authentication accuracy and stability under noise and environmental changes, and supporting dynamic user expansion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121865261A_ABST
    Figure CN121865261A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-user physical layer authentication method based on an unsupervised KAN-AE. According to the method, a double-auto-encoder structure KAN-AE of a Kolmogov-Arnod network (KAN) is adopted, a shared encoder and two symmetrical decoders are constructed, and a two-stage adversarial training strategy is provided; self-adaptively calculating an authentication threshold value of each legal device based on a reconstruction error of the verification set sample on an auto-encoder; during online authentication, reconstructing a received CSI sample, calculating a score, and comparing the score with a corresponding threshold value to judge whether the CSI sample comes from target equipment or not; an exclusive KAN-AE model is constructed for each device passing the upper layer authentication, and physical layer authentication and dynamic extension of a user set in a multi-user scene are realized; the method does not need a large amount of labeled data, and has high authentication accuracy and robustness in noise interference and various actual environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication security, and in particular to an identity authentication technology based on channel state information radio frequency fingerprints, specifically a multi-user physical layer authentication method based on an unsupervised Kolmogorov-Arnold neural network autoencoder. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), a massive number of low-cost wireless devices are being deployed in smart homes, smart cities, and industrial automation. These devices mostly interact via wireless channels, and traditional authentication mechanisms relying on unique identifiers (such as MAC addresses) are facing serious security threats due to broadcast channels and the ease with which devices can be forged. While MAC address randomization protects user privacy to some extent, it also introduces identity uncertainty; malicious attacks such as Sybil attacks can even allow a single physical device to impersonate multiple false identities, thereby interfering with network management and the effective implementation of security policies, leading to resource abuse and data breaches.

[0003] Therefore, Physical Layer Authentication (PLA) technology based on Radio Frequency Fingerprint (RFF) was proposed and has gradually become a supplementary means to traditional encryption authentication. RFF utilizes the slight signal distortion introduced by unavoidable hardware defects during device manufacturing to create a naturally difficult-to-copy "fingerprint" for the device. Compared with traditional cryptographic authentication, RFF-PLA can provide additional anti-counterfeiting capabilities while reducing key management complexity and computational overhead.

[0004] In recent years, deep learning technology has been widely applied in RFF-PLA to improve device recognition capabilities under complex and dynamic channel conditions. Existing research has achieved high recognition rates on specific experimental platforms using structures such as convolutional neural networks (CNNs), recurrent neural networks (e.g., LSTM), and residual networks. However, existing work generally suffers from the following limitations: many methods rely on professional-grade software-defined radio (SDR) equipment to acquire I / Q waveforms or high-quality baseband data, resulting in high hardware costs and hindering large-scale deployment in consumer-grade WiFi systems; most deep learning-based PLA schemes employ supervised learning frameworks, heavily relying on a large number of labeled samples. Once the environment or user set changes, data needs to be re-acquired and labeled, leading to high deployment costs; in scenarios with only a few training samples, existing models lack generalization ability and robustness, failing to meet the high requirements of authentication accuracy and security in real-world systems; while some unsupervised or self-supervised methods reduce label dependence, they still suffer from training instability and large performance fluctuations under noise interference, complex multipath environments, and multi-user scenarios.

[0005] With the development of WiFi-based Channel State Information (CSI) measurement tools, CSI can be directly obtained from consumer-grade WiFi devices, providing a low-cost and easily deployable implementation path for constructing CSI-RFF and performing physical layer authentication using CSI. Existing research has demonstrated that, under line-of-sight (LoS) and certain environmental conditions, stable hardware-related features contained in CSI can be extracted into CSI-RFF and used to distinguish legitimate devices from spoofed devices. However, existing CSI-RFF-based PLA schemes either still rely on large amounts of labeled data or exhibit insufficient robustness with small sample sizes, noise interference, and environmental changes. In multi-user scenarios, they often employ a "single-model multi-classification" approach, where model structure and training complexity increase sharply with the number of users, resulting in poor support for dynamically added or removed devices.

[0006] Therefore, there is an urgent need for an unsupervised physical layer authentication method that is based on CSI-RFF in consumer-grade WiFi scenarios, can maintain robustness in environments with few samples and high noise, and supports dynamic authentication for multiple users. Summary of the Invention

[0007] The purpose of this invention is to propose a multi-user physical layer authentication method based on an unsupervised Kolmogorov-Arnold neural network autoencoder, which addresses the problems of existing hardware fingerprint-based physical layer authentication schemes, such as reliance on large-scale labeled data, insufficient robustness to noise and environmental changes, and limited dynamic expansion capabilities for multiple users. This enables highly robust, multi-user, and low-sample physical layer authentication of wireless device identities in consumer-grade WiFi scenarios.

[0008] The objective of this invention is achieved as follows:

[0009] First, a multi-user wireless communication system model is constructed, incorporating multiple legitimate transmitters, malicious attackers, and legitimate receivers. Channel state information (CSI) is collected from consumer-grade WiFi devices, and CSI-RFF features are constructed through frequency domain amplitude extraction and normalization. Then, considering the small-scale characteristics and noise sensitivity of CSI-RFF, a dual autoencoder structure, KAN-AE, based on Kolmogorov-Arnold Networks (KAN), is designed. A two-stage adversarial training strategy is proposed, enabling the model to reconstruct the CSI of legitimate devices with high quality while also recognizing input data that does not contain the target device's CSI-RFF. Subsequently, the reconstruction error of the validation set samples on the first autoencoder is used to construct an adaptive threshold for each legitimate device, thereby achieving automatic threshold adjustment and reducing the uncertainty caused by manual threshold setting. Finally, by adopting the approach of "building a dedicated KAN-AE model for each legitimate device that has passed upper-layer authentication", the multi-user physical layer authentication problem is transformed into a set of single-user single-class classification problems. In the online stage, the decision is made based on the reconstruction error of the received signal and the adaptive threshold to complete the multi-user physical layer authentication, and the model can be dynamically extended to new devices based on the higher-layer authentication results.

[0010] The specific method is as follows:

[0011] A multi-user physical layer authentication method based on unsupervised KAN-AE includes the following steps:

[0012] Step 1: Construct a system model and CSI acquisition model. Establish a multi-user wireless communication system model that includes multiple legitimate transmitters, illegal attackers, and a single legitimate receiver. Introduce an adversarial multipath scattering environment. Collect CSI sequences between legitimate transmitters and receivers based on consumer-grade WiFi devices. Define the initialization phase, transmission time slots, and authentication phase.

[0013] Step 2: CSI-RFF feature extraction and preprocessing. The collected complex CSI tensors are processed according to the selection of transmitting and receiving antennas, frequency domain amplitude calculation and normalization operation to obtain the normalized CSI-RFF feature matrix, and then processed as the model input dataset.

[0014] Step 3: Construct a KAN-AE dual autoencoder model based on KAN. For CSI-RFF features, design a KAN-AE structure containing one encoder and two decoders. The encoder is composed of multiple KAN layers to achieve layer-by-layer dimensionality reduction and nonlinear feature extraction. The two decoders are symmetrical to the encoder structure and constitute two autoencoders AE_1 and AE_2 with a shared encoder, respectively.

[0015] Step 4: Two-stage adversarial training and adaptive threshold calculation of KAN-AE. In the first stage, the model is trained to accurately reconstruct legitimate CSI data by minimizing the reconstruction errors of AE_1 and AE_2. In the second stage, AE_2 is introduced to reconstruct the output of AE_1, constructing an adversarial training objective of "AE_1 as generator and AE_2 as discriminator". The ability of the model to distinguish between CSI-RFF containing and not containing the target is improved through alternating optimization. At the same time, the authentication threshold of each legitimate device is adaptively calculated based on the reconstruction error statistics of the validation set samples on AE_1.

[0016] Step 5: Score calculation and single-user authentication decision based on KAN-AE. For a model corresponding to a given legitimate device, AE_1 is used to reconstruct the newly arrived sample. The reconstruction error of the sample is calculated as the score. The score is compared with the adaptive threshold of the device. If the score is lower than the threshold, it is determined to be from the target device; otherwise, it is determined to be from a non-target user or an illegal attacker.

[0017] Step 6: Multi-user physical layer authentication and dynamic expansion based on a dedicated model. In multi-user scenarios, a dedicated KAN-AE model and corresponding threshold are trained for each legitimate device that passes upper-layer authentication. During online authentication, the corresponding device model is selected for physical layer verification based on the upper-layer identifier. Samples that fail authentication by any device model are identified as unauthorized attackers. If the supplementary authentication passes, the new device can be included in the set of legitimate users, and a dedicated KAN-AE model can be trained and maintained for it, thereby achieving multi-user physical layer authentication that is insensitive to the number of users and can be dynamically expanded.

[0018] Furthermore, the construction of the multi-user wireless communication system model in step 1 includes the system containing N legitimate transmitters A. j , j∈{1,...,N}, M illegal attackers E k Given k∈{1,...,M}, and a valid receiver Bob; each transmitting device is in a multipath scattering environment with respect to Bob, and the distance between them is greater than one wavelength; a valid transmitter A jSecure communication is established between Bob and the server during the initialization phase. An upper-layer authentication mechanism ensures the legitimacy of the CSI data collected during this phase. During the initialization phase, the legitimate sender A... j Send T channel response samples to Bob for training, denoted as:

[0019]

[0020] During the online transmission time slot t > T, Bob acquires the current channel estimate while receiving data packets. As a sample to be authenticated; Attacker E k The MAC address is disguised as that of a legitimate sender, attempting to inject a forged signal into the channel to mislead Bob into believing it is his true identity.

[0021] Furthermore, step 2, CSI-RFF feature extraction and preprocessing, includes acquiring raw CSI data H using a consumer-grade WiFi device (e.g., a terminal equipped with an Intel 5300 network card) and a CSI acquisition tool. raw (t), which, after analysis, yields a complex tensor H of dimension (N,R,T). tensor (t), where N is the number of subcarrier groups, R is the number of receive antennas, and T is the number of transmit antennas; select a specified transmit antenna link (e.g., T). x =0) and all receiving antennas, to obtain a complex matrix. Convert the complex matrix into a frequency domain amplitude matrix:

[0022]

[0023] The amplitude matrix at each time t is normalized to obtain the normalized CSI-RFF features:

[0024]

[0025] in and These are the maximum and minimum values ​​of the sample, respectively; the normalized feature is denoted as H(t), which serves as the input sample for KAN-AE, thus using a unified form of CSI-RFF representation in the subsequent training and certification stages.

[0026] Furthermore, the construction of the KAN-AE model in step 3 includes: the encoder E adopts a three-layer KAN structure, performing layer-by-layer dimensionality reduction and nonlinear transformation on the input features; the first layer maps the input dimension d to... The second layer mapping is The third layer maps to the low-dimensional latent space z. The two decoders, D1 and D2, are structurally symmetrical with the encoder and also employ a three-layer KAN to progressively map the latent representation z back to the original dimension. The encoder layers and the first two layers of the decoder use the ReLU activation function σ(x) = max(0,x), while the last layer of the decoder uses the Sigmoid activation function. To ensure that the output value is consistent with the normalized CSI-RFF range, two autoencoders are constructed by sharing encoder E:

[0027] AE1(H)=D1(E(H)),AE2(H)=D2(E(H))

[0028] Where H represents the CSI-RFF sample of a legitimate device.

[0029] Furthermore, step 4, the adversarial training and adaptive threshold calculation of KAN-AE, includes minimizing the reconstruction errors of AE1 and AE2 respectively in the first stage:

[0030]

[0031] In the second stage, the results of the secondary reconstruction are introduced:

[0032] AE2(AE1(H))=D2(E(D1(E(H))))

[0033] An adversarial training objective is constructed such that AE1 attempts to minimize the error between the input H and the secondary reconstruction result, while AE2 attempts to maximize that error:

[0034]

[0035] To balance the goals of both stages, the comprehensive loss is defined in the nth training cycle:

[0036]

[0037] During training, a portion (e.g., 20%) of the collected samples is used as the validation set, and the reconstruction error of the validation set on AE1 is calculated at each training epoch. After N e After training epochs, the adaptive threshold θ j Calculate as follows:

[0038]

[0039] Where μ is the threshold coefficient, N e This represents the number of training cycles.

[0040] Furthermore, step 5, the KAN-AE-based scoring calculation and single-user authentication decision, includes, for CSI-RFF samples received in time slot t > T Using a trained AE j,1 Calculate the reconstruction results Define sample scores:

[0041]

[0042] Rating With corresponding device A j Adaptive threshold θ j In comparison, when At that time, the sample is determined to be from target device A. j ,when At that time, the sample was determined to be from a non-target user or an unauthorized attacker; by using only AE j,1 By performing scoring calculations, the proportion of false positives (misidentifying non-target users or attackers as target users) can be reduced while ensuring detection capabilities.

[0043] Furthermore, step 6, multi-user physical layer authentication and dynamic extension, includes, for each legitimate device A that has passed upper-layer authentication... j Using their CSI-RFF data respectively Training a dedicated KAN-AE model AE j and its adaptive threshold θ j During online authentication, the corresponding AE model is selected based on the sender's identity declaration in the higher-level protocol. j Physical layer authentication is performed on the received sample. If the sample passes AE... j If the threshold is met, physical layer authentication is passed; if the sample fails the threshold under the declared identity model, a supplementary authentication mechanism is initiated. Samples that fail authentication under any legitimate device model are identified as belonging to an unauthorized attacker, E. k When a new device passes upper-layer authentication and has stable CSI-RFF characteristics at the physical layer, CSI samples can be collected for it and the corresponding KAN-AE model can be trained, thereby achieving dynamic expansion of the multi-user set without retraining other user models.

[0044] The positive effects of this invention are:

[0045] This invention, featuring CSI-RFF, introduces an unsupervised KAN-AE adversarial autoencoder structure and adaptive threshold design to achieve device physical layer authentication and dynamic multi-user expansion under limited sample conditions in consumer-grade WiFi scenarios, without requiring large-scale labeled data. The proposed method maintains high authentication accuracy and low instability index even in noisy and diverse real-world environments, exhibiting better robustness and applicability compared to existing supervised and unsupervised PLA schemes. This method not only reduces the system's dependence on expensive hardware and manual annotation but also lowers online computational complexity and actual deployment costs while ensuring security. Attached Figure Description

[0046] Figure 1 This is a flowchart of the multi-user physical layer authentication method based on an unsupervised Kolmogorov-Arnold neural network autoencoder provided by the present invention.

[0047] Figure 2 This is a schematic diagram of a multi-user wireless communication system model in an adversarial multipath environment with multiple scattering clusters. Detailed Implementation

[0048] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0049] like Figure 1 As shown, the multi-user physical layer authentication method based on an unsupervised Kolmogorov-Arnold neural network autoencoder of the present invention mainly includes the following steps:

[0050] Step 1: Build the system model and define the authentication process, such as... Figure 2 As shown, a multi-user wireless communication system contains N valid transmitters A. j M illegal attackers E k And a legitimate receiver named Bob, with all transmitting devices and Bob situated in a multipath scattering environment. During the initialization phase, the legitimate transmitter establishes a secure upper-layer connection with Bob, ensuring the legitimacy of samples during this phase through upper-layer authentication. After the initialization phase, the system enters the online transmission and authentication phase, where Bob receives data packets and estimates the channel response within time slot t. As a sample to be certified;

[0051] Step 2: CSI-RFF feature extraction and preprocessing. Bob collects raw CSI data from consumer-grade WiFi devices, obtains complex CSI tensors through parsing, selects the CSI of specific transmitting antennas and all receiving antennas, and obtains normalized CSI-RFF features H(t) through amplitude calculation and normalization operations, which are used as inputs for subsequent models.

[0052] Step 3: Construct a KAN-based dual autoencoder model, KAN-AE. The KAN-AE model consists of an encoder E and two decoders D1 and D2. The encoder uses a three-layer KAN structure to achieve a nonlinear mapping from the original dimension to the low-dimensional latent space z. The decoder structure is symmetrical to the encoder, and the three-layer KAN gradually restores the latent representation to the original dimension. By sharing the encoder, autoencoders AE1 and AE2 are formed for subsequent adversarial training and scoring calculation.

[0053] Step 4: KAN-AE two-stage adversarial training and adaptive threshold calculation. During the training phase, for each legitimate device A... j CSI-RFF dataset First, AE1 and AE2 are used to minimize their own reconstruction errors, enabling the model to reconstruct legitimate CSIs effectively. Then, the output of AE1 is input into AE2 to construct a secondary reconstruction result. AE1 is treated as the generator, and AE2 as the discriminator, forming a minimum-maximum adversarial objective. During training, the autoencoder reconstruction objective and the adversarial objective are combined into a comprehensive loss using weighting coefficients that vary with the training epochs. A portion of the training samples is used as the validation set, and the reconstruction error on AE1 is calculated in each training epoch. The accumulated error is then used to obtain the adaptive threshold θ for each device according to a defined formula. j ;

[0054] Step 5: Scoring and Single-User Physical Layer Authentication. During the online authentication phase, for CSI-RFF samples received in time slot t > T... Select the corresponding device model (AE) based on the declared identity as instructed by the upper level. j Using AE j,1 right Perform forward reconstruction and calculate the reconstruction error. As a score, and compare the score with a threshold θ j Comparison. When At that time, it is determined that the current sample comes from the target user AE. j Authentication is successful; otherwise, it is determined to be from a non-target user or an unauthorized attacker.

[0055] Step 6: Multi-user Physical Layer Authentication and Dynamic Expansion. In a multi-user scenario, a KAN-AE model and its threshold are independently trained for each legitimate device that has passed upper-layer authentication. During online authentication, the corresponding model is selected for physical layer verification based on the declared identity. If a sample fails physical layer verification under the model corresponding to its declared identity, a supplementary authentication mechanism can be initiated to determine whether to accept it. If a sample fails authentication under all legitimate device models, it is determined to be an unauthorized attacker. For new devices that have passed supplementary authentication and have stable CSI-RFF characteristics, their CSI samples can be collected and a new KAN-AE model can be trained, thereby achieving dynamic expansion and maintenance of the multi-user set.

Claims

1. A multi-user physical layer authentication method based on unsupervised KAN-AE, characterized in that, The method includes the following steps: Step 1: Construct the system model and CSI acquisition model. The multi-user wireless communication system consists of N legitimate transmitters A j M illegal attackers E k It consists of a legitimate receiver named Bob. In an adversarial multipath scattering environment, the legitimate transmitter establishes a secure connection with Bob through upper-layer authentication during the initialization phase and sends a CSI sample set for training to Bob. Step 2: Preprocess the CSI data collected by Bob at the receiving end, including selecting the CSI of a specified transmitting antenna and all receiving antennas from the original complex CSI tensor, calculating the frequency domain amplitude and normalizing it to obtain the normalized CSI-RFF feature matrix H(t) as the model input. Step 3: Construct a dual autoencoder model KAN-AE based on Kolmogorov-Arnold network. KAN-AE includes an encoder E and two decoders D1 and D2. The encoder is composed of multiple KAN layers to realize the mapping of input features to a low-dimensional latent space. The two decoders are symmetrical to the encoder structure and form autoencoders AE1 and AE2 by sharing the encoder. Step 4: For each legitimate sender AE j The CSI-RFF sample set was used to train KAN-AE using a two-stage adversarial training strategy, and the adaptive threshold θ of the corresponding device was calculated based on the reconstruction error of the validation set samples on AE1. j ; Step 5: During online authentication, process the CSI-RFF samples received in time slot t. Select the corresponding device's autoencoder AE based on the identity declared by the upper layer. j,1 Reconstruct the data and calculate the reconstruction error as a score. And the score is compared with the threshold θ j In comparison, when The sample is determined to originate from the target device AE. j Otherwise, the sample is determined to be from a non-target user or an unauthorized attacker. Step 5: For multi-user scenarios, train a dedicated KAN-AE model and threshold for each legitimate device that has passed upper-layer authentication. During the online phase, select the corresponding model for physical layer authentication based on the declared identity. Samples that fail authentication under any legitimate device model are identified as illegal attackers. When the supplementary authentication is successful, train a new KAN-AE model for the new device to achieve dynamic expansion of the multi-user set.

2. The multi-user physical layer authentication method based on unsupervised KAN-AE as described in claim 1, characterized in that, The construction of the CSI acquisition model in step 1 includes: legitimate sender A j During the initialization phase, T channel response samples are sent to Bob, denoted as... During the online phase, Bob's channel estimation collected in time slot t > T is the sample to be authenticated. Attacker E k It attempts to inject forged signals by spoofing the MAC address of a legitimate sender.

3. The multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, Step 2, CSI-RFF feature extraction and preprocessing, includes: extracting the parsed complex CSI tensor H... tensor The complex matrix (t) is selected from the specified transmitting antenna and all receiving antennas. pass Calculate the amplitude matrix and use Normalization was performed, where and Let H(t) be the maximum and minimum amplitude values ​​for each sample, respectively, and the normalized result is denoted as H(t).

4. The multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, In step 3, encoder E adopts a three-layer KAN structure, which is implemented sequentially. The mapping; the two decoders D1 and D2 are symmetrical with the encoder, and are implemented sequentially. The mapping is such that each layer of the encoder and the first two layers of the decoder use the ReLU activation function, while the last layer of the decoder uses the Sigmoid activation function.

5. A multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, In step 3, two autoencoders are constructed by sharing an encoder: AE1(H) = D1(E(H)) and AE2(H) = D2(E(H)), where H is a CSI-RFF sample of a legitimate device.

6. The multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, Step 4 of the KAN-AE two-stage adversarial training includes: the first stage, minimizing... as well as In the second stage, the secondary reconstruction result AE2(AE1(H))=D2(E(D1(E(H)))) is introduced to construct the adversarial training objective.

7. The method according to claim 6, characterized in that, In the nth training epoch, the comprehensive loss function is defined as: Where ||·||2 represents the Euclidean distance.

8. A multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, In step 4, the adaptive threshold θ j The calculation is as follows: a portion of the training samples is used as the validation set, in N e The reconstruction error of the validation set on AE1 is calculated for each training cycle. The threshold is calculated as follows: Where μ is the threshold coefficient, N e This represents the number of training cycles.

9. A multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, Step 5, the scoring calculation and authentication decision, includes: via AE... j,1 calculate Reconstruction results Define rating when At that time, the sample is determined to be from target device A. j ,when At that time, the sample will be identified as coming from a non-target user or an illegal attacker.

10. A multi-user physical layer authentication method based on unsupervised KAN-AE according to claim 1, characterized in that, Step 6, multi-user physical layer authentication and dynamic expansion, includes: training a dedicated KAN-AE model and its threshold for each legitimate device that passes upper-layer authentication; selecting the corresponding model for authentication based on the upper-layer declared identity during the online phase; determining samples that fail to pass authentication by any legitimate device model as illegal attackers; collecting CSI samples and training a new KAN-AE model for new devices that pass supplementary authentication, without needing to retrain existing legitimate user models, thereby achieving dynamic expansion of the multi-user set.