Unmasking the Silent Bandwidth Thief: Detecting Selfish Carrier-Sensing in WiFi
Detecting selfish carrier-sense behavior in WiFi networks by passive monitoring
This paper presents a passive monitoring solution to detect selfish carrier-sensing behavior in 802.11 (WiFi) networks. By employing a Hidden Markov Model (HMM) to analyze merged traffic traces from distributed sniffers, the system identifies asymmetries in Clear Channel Assessment (CCA) behavior to pinpoint nodes that unfairly seize bandwidth.
TL;DR
With the rise of software-defined radios (SDRs), cheating in WiFi networks is becoming trivial. A selfish node can simply ignore the "Clear Channel Assessment" (CCA) and transmit whenever it wants, starving its neighbors. This paper introduces a passive monitoring system that uses Hidden Markov Models (HMM) to detect these cheaters by analyzing traffic traces from distributed sniffers, requiring zero changes to existing hardware.
The Problem: The Hardness of Detecting "Silence"
In a standard 802.11 (CSMA/CA) network, nodes must "listen" before they "talk." If the channel is busy, they defer. A "selfish" node can manipulate its CCA threshold so that the channel always looks idle.
Why is this hard to catch?
- Passive Nature: A node failing to sense carrier looks remarkably like a node that is simply out of range or experiencing a fade.
- Lack of Evidence: Traditional tools like DOMINO catch nodes that shorten their backoff timers (which is visible in timing), but missing a deferral is a "non-event" that is harder to prove.
Methodology: Reading Between the Packets with HMM
The authors' core insight is that while we can't see a node's internal state (whether it is in 'backoff' or 'defer'), we can observe the outcome of its decisions in the captured packets.
1. The Combined Markov Model
They model the interaction between two nodes as a state machine. The combined states (e.g., Node X is transmitting, Node Y is deferring) are "hidden." What we observe are the "symbols" in the traffic trace: (X transmits), (Y transmits), or (both transmit - a collision).

2. Inferring the Probabilities
By using the Baum-Welch algorithm, the system learns the transition probabilities that best explain the observed traffic. Specifically, it looks for the probability —the likelihood that X defers to Y.
3. Asymmetry and Witnesses
In a fair network, if X can hear Y, and should be roughly equal. If is high but is near zero, X is likely cheating. To prevent false alarms from temporary signal fading, the system requires multiple witnesses—other nodes that also see the same asymmetry from X.
Experimental Results
The authors validated the method using both a Soekris-based testbed and ns2 simulations.
- Signal-to-Noise Impact: The detection is strongest when the SNR is high enough that the node should have sensed the carrier.
- Degree of Selfishness: The algorithm doesn't just give a binary "guilty/innocent" verdict; it estimates the probability of cheating (the "selfishness metric"), which aligns closely with the actual behavior in simulations.

Critical Insight & Conclusion
The brilliance of this work lies in its passive elegance. By treating the entire network as a probabilistic system, it circumvents the need for specialized hardware or active probing.
Limitations:
- The current model relies on "pairwise" analysis. In extremely congested environments where 3 or more nodes frequently overlap, the complexity might grow.
- It assumes sniffers can capture a clean enough trace to distinguish short backoffs from long idles.
Future Outlook: As we move toward more open and programmable wireless infrastructures (like Open RAN), passive, AI-driven policing mechanisms will be essential to maintain fairness in shared spectrum environments.
