Where We Are
Week 3 got CSI out of a commodity card and onto disk the only way the field currently can: by surgery. You flash a patched firmware, load a patched driver, put the card in monitor mode, and catch a channel estimate the hardware meant to discard. It works, it is what every public dataset and this lab's own AX210 rig do, and it is a hack — vendor-specific, undocumented, and dependent on whatever traffic happens to fly past.
This week is about what happens when the industry decides that catching that estimate should be a feature rather than a hack. IEEE 802.11bf — "WLAN Sensing" — is the amendment that promotes sensing to a first-class 802.11 service. Chartered as Task Group bf in 2020, it was ratified in 2024 and published as IEEE 802.11bf-2025 — so this is no longer a proposal on the horizon but a finished standard driving a wave of chipset and platform launches. The single most important thing to understand up front is what it does not do: it does not invent a new physical measurement. The object 802.11bf reports is the same per-subcarrier channel matrix \mathbf{H} that Week 2 derived and Week 3 extracted. What the standard adds is everything around that measurement — a negotiated session, a scheduled sounding, and an interoperable report format. The physics is Week 2's; the protocol is new.
That distinction is the spine of the whole week, and it is also the answer to the two questions a practitioner in this lab actually asks: can I run 802.11bf on my AX210? (Section 5) and does 802.11bf make my thesis contribution obsolete or does it make it more relevant? (Section 6). Both answers fall out of "same \mathbf{H}, new protocol."
A few terms recur, so fix them up front. An amendment is an addition to the 802.11 standard, ratified by a task group (here TGbf, chartered in 2020). A sensing service means the MAC/PHY exposes sensing as something you set up and negotiate, not something you scrape. A PPDU is a physical-layer frame; sounding is transmitting a frame whose only job is to let the receiver measure the channel; an NDP (Null Data Packet) is the sounding frame — it carries training fields and no data payload. A sensing initiator asks for a measurement; a responder makes it. Trigger-based means the AP schedules who sounds when. Grouping and quantization are the two knobs that shrink the report at the cost of fidelity. Each is defined again, in context, the first time it does real work below.
0. Wi-Fi as a Sensor — What It Detects, and Why Anyone Cares
Before the protocol, the point. Every Wi-Fi packet is a probe: as it travels from transmitter to receiver it reflects, diffracts, and scatters off everything in the room — walls, furniture, and people. A person moving through the space changes the multipath, and that change is written into the very channel matrix \mathbf{H} the receiver already estimates on every packet. Read the perturbation and you can infer what the environment is doing, without the target carrying any device at all. This is device-free sensing, and it is the reason a communication technology gets a sensing amendment.
What can you actually sense? A remarkable range, from the coarse to the almost implausible: presence (is anyone in the room, for occupancy-driven lighting and HVAC); crowd count and flow (how many, and where they move — this lab's target); activity recognition (walking, sitting, cooking, and the safety-critical case, falling); gesture (touchless control); fall detection for elderly care with no wearable; respiration and heart rate from the sub-millimetre chest motion that modulates the channel; localization and tracking at room granularity; and even gait-based identification. One radio, many tasks — and 802.11bf's purpose is to make all of them deployable on ordinary access points rather than on patched research cards.
Where is it used? The commercial pull is real and, since ratification, accelerating: smart homes (occupancy-aware automation and security), healthcare (elderly fall and vital-sign monitoring), retail (footfall, queue, and dwell analytics), commercial buildings (occupancy for energy and space planning), and security (intrusion and motion sensing that works in the dark). The standard is what turns each of these from a lab demo into a product line, because it removes the "every vendor a different hack" barrier that this course's Week 3 documented in painful detail.
Why Wi-Fi, specifically? Five honest advantages. It is device-free — the person carries nothing. It is privacy-preserving relative to cameras — there is no image, and it works in the dark. It sees through walls and in non-line-of-sight, where optics cannot. It reuses infrastructure that is already deployed — access points are everywhere. And it is low incremental cost — no new sensors to install. Set against that are four equally honest limitations, and they matter for the rest of this lecture: Wi-Fi sensing is coarse (counts and motion, not identities or images); it is environment-dependent (the same person reads differently in a different room); it is uncalibrated (raw CSI carries hardware and environment offsets — Week 5); and its inferences drift as the environment changes. Keep those four in view. They are precisely the problems 802.11bf does not solve, and precisely what this lab's thesis does (Section 6).
1. From a Hack to a Service — What Standardization Actually Buys
Recall the pipeline from Week 3: transmitter → channel → receiving NIC → patched firmware that copies CSI out before it is discarded → logger → file → parser. Every arrow was a place a study could quietly break, and the whole enterprise rested on the fact that the card throws CSI away by default. 802.11bf attacks that pipeline at the root. If sensing is a service, the card is supposed to hand you the channel estimate — there is a defined frame that carries it, a defined exchange that requests it, and a defined format it arrives in.
Three concrete things change, none of them physical:
Negotiation. Before any measurement, the two ends agree on parameters — bandwidth, how many subcarriers to report, how many bits per value, which antennas, how often. In Week 3 you took whatever the firmware happened to emit and reverse-engineered its format. Under 802.11bf the format is agreed in a measurement setup exchange and written in the specification.
Deliberate sounding. In Week 3, passive sniffing meant you measured the channel only when some other device transmitted. Under 802.11bf a sensing transmitter emits sounding NDPs on purpose, at a rate the session sets. You no longer depend on ambient traffic existing — Section 4 shows why that is the difference between seeing a walking person and missing them.
Interoperability. A Halperin trace off an Intel 5300 and a Nexmon trace off a Broadcom chip are different formats, different subcarrier orderings, different bit depths — Week 3's whole "gotchas" section existed because every tool is its own dialect. An 802.11bf report has one format that any compliant device produces and any compliant device can read. Sensing becomes a property of the infrastructure, not of your particular patched card.
What does not change is \mathbf{H} itself. This is worth stating as a slogan, because the rest of the week leans on it:
802.11bf standardizes the acquisition and reporting of CSI. It does not standardize — or improve, or calibrate — the CSI itself. The channel matrix an 11bf device reports is the same physical quantity your AX210 sniffs today.
Workbook §1 renders the full stack as a diagram: the PHY produces \mathbf{H}; 802.11bf sits directly on top and does acquisition-and-reporting only; the application wants a crowd count; and between the two sits a band the standard leaves completely open. Hold that gap — Section 6 is about it.

1.5 The Lineage — Which Wi-Fi Generation Carries Sensing, and Which Cards Expose CSI
Two practical questions decide whether you can do any of this: which Wi-Fi generation is 802.11bf built on, and which hardware can even hand you CSI. They are related, because sensing has ridden along with Wi-Fi for fifteen years.
Which generation. CSI itself is not new — the channel matrix \mathbf{H} has been extractable since 802.11n (2009), when the Linux 802.11n CSI Tool first exposed it on the Intel 5300. Each generation since widened the band, and wider band means more subcarriers, which means finer sensing: 802.11ac (2013) brought 80/160 MHz (and Nexmon CSI on Broadcom, including the Raspberry Pi); 802.11ax / Wi-Fi 6 (2021) brought the High-Efficiency (HE) PHY; 802.11be / Wi-Fi 7 (2024) brought the Extremely-High-Throughput (EHT) PHY at up to 320 MHz. 802.11bf is not a new radio — it is a service layer that reuses the HE (11ax) and EHT (11be) PHYs at sub-7 GHz, and the DMG/EDMG PHYs (11ad/11ay) above 45 GHz. So "which generation?" is answered twice: sensing observability dates to 11n, but the standard rides on 11ax/11be.
Which cards. Here is the portability problem the field lives with: CSI is not a Wi-Fi feature you switch on — it is a property of your specific chip plus a patched extraction tool, and the chip fixes the bandwidth and subcarrier count, hence how finely you can sense. The tools that matter:
| Card / chip | Wi-Fi generation | Bandwidth | Extraction tool | Notable |
|---|---|---|---|---|
| Intel IWL5300 | 802.11n | 20 / 40 MHz | Linux 802.11n CSI Tool (Halperin 2011) | 30 grouped subcarriers; the classic — most public datasets are built on it |
| Atheros ath9k (QCA) | 802.11n | 20 / 40 MHz | Atheros CSI Tool (Xie) | 56 subcarriers; runs on cheap OpenWrt routers |
| Broadcom / Cypress | 802.11ac | up to 80 MHz | Nexmon CSI | up to 4×4 MIMO; runs on the Raspberry Pi (bcm43455c0) |
| ESP32 | 802.11n | 20 MHz | ESP32-CSI-Tool | ≈ $5, battery/edge deployable; lower precision |
| Intel AX200 / AX210 | 802.11 a/g/n/ac/ax | 20 / 40 / 80 / 160 MHz | FeitCSI, PicoScenes, IAX | modern, wide-band, inject + extract — this lab's node |
The AX210 is the protagonist of this lecture's hardware story. It is the only commodity NIC family that exposes 802.11ax (HE) CSI — PicoScenes was the first, and for a time the only, public platform to extract 11ax-format CSI on commodity hardware, and FeitCSI does it across all formats and all bandwidths (20–160 MHz) with injection as well as extraction, under a GPL licence. Concretely, the AX210 reports raw \mathbf{H} at up to 160 MHz — 1992 = 2×996 subcarriers per stream — with no negotiated grouping or quantization. In this lab (IP-112) we port FeitCSI and IAX onto a Raspberry Pi 5 + AX210 running Linux 6.x, to build a commodity, deployable CSI sensor node for the real crowd-counting measurements of IP-106. Hold those four AX210 facts — 11ax, 160 MHz, raw, injectable — because Section 5 asks exactly what they can and cannot do for 802.11bf.
2. The Sensing Session — Negotiated and Scheduled, Not Opportunistic
The heart of the amendment is the sensing measurement session: a defined, stateful exchange between two roles. A sensing initiator (typically the AP) drives the procedure; a sensing responder (a station) participates. Orthogonally, for any single measurement one device is the sensing transmitter (it sends the sounding NDP) and the other is the sensing receiver (it measures \mathbf{H} from that NDP and, in the common case, reports it back). The session runs through five phases:
- Setup — the initiator and responder negotiate the measurement parameters: bandwidth, subcarrier grouping N_g, quantization depth b, antenna configuration, and repetition rate.
- Sounding — the sensing transmitter emits an NDP. This is not a new waveform: it reuses the 802.11ax/802.11be sounding machinery already built for MIMO beamforming, where an AP sounds the channel to compute a beamforming steering matrix. 802.11bf borrows that mechanism and keeps the channel estimate as the product rather than a means to an end.
- Measurement — the sensing receiver estimates \mathbf{H}(k) from the NDP's known training fields, exactly as in Week 2.
- Reporting — the receiver returns the (grouped, quantized) CSI in a standardized report frame. This is where the N_g and b knobs of Section 3 bite.
- Termination — the session is torn down, or, for continuous sensing, re-armed — a periodic session repeats sounding at the negotiated cadence.

The scheduling of that repetition comes in two flavours, and they map cleanly onto Week 3's active-versus-passive distinction:
- Trigger-based (TB) sensing — the AP sends a trigger and schedules exactly which stations sound and when. This is deterministic: the AP chooses the packet rate, and therefore chooses the temporal resolution of the sensing. It is the standardized descendant of Week 3's active stance.
- Non-trigger-based sensing relaxes that central scheduling and leans on measurements gathered around ordinary transmissions — closer to Week 3's passive stance, and inheriting its lack of a rate guarantee.
Finally, the amendment spans two frequency regimes, and only one is ours. Sub-7 GHz sensing builds on 802.11ax (HE) and 802.11be (EHT) PPDUs — wide-area, wall-penetrating, and the regime in which crowd counting, occupancy, and coarse motion live. The 60 GHz regime (DMG/EDMG, on 802.11ad/ay) is millimetre-wave: beam-based, short-range, high spatial resolution, aimed at gesture and proximity. For everything this course and this lab do, sub-7 GHz is the target; 60 GHz is a different instrument for a different job.
3. What a Standardized Report Costs — Grouping and Quantization
Here is the tension the standard has to resolve. A raw AX210 tensor is every subcarrier at essentially full numerical precision. The workbook's synthetic 80 MHz channel has 996 usable subcarriers spanning 77.8 MHz, with about 19.5 dB of amplitude structure across the band — that fine structure is exactly what carries sensing information. Reporting all of it, at float precision, costs 7 968 bytes per antenna pair, per sounding. Do that hundreds of times a second across a dense deployment and the sensing feedback drowns the communication the network exists for. So 802.11bf's measurement setup negotiates two deliberately lossy knobs.
Subcarrier grouping N_g reports only every N_g-th tone; the receiver interpolates the rest. The workbook measures the reconstruction error as normalized mean-squared error, \mathrm{NMSE} = \lVert H-\hat H\rVert^2/\lVert H\rVert^2 (in words: how far the reconstructed channel drifts from the true one, as a fraction of the channel's own energy — more-negative dB is better). Grouping trades tones for error smoothly:
| Grouping N_g | Reported tones | NMSE |
|---|---|---|
| 1 | 996 | lossless |
| 4 | 249 | −55.8 dB |
| 16 | 62 | −38.2 dB |

Quantization b represents each reported amplitude and phase in b bits over its observed range. Coarser bits, higher error: the workbook finds NMSE of −17.5 dB at 4 bits, −42.5 dB at 8 bits, and −66.5 dB at 12 bits. Combine the two — the typical compact report of N_g=4 grouping at b=8 bits — and you get a report that is 16× smaller than the raw tensor (498 bytes instead of 7 968) at a fidelity cost of NMSE −42.3 dB.

The lesson for downstream weeks: an 802.11bf report is a deliberately degraded version of what your AX210 gives you raw. Whether −42 dB of reconstruction error matters depends on the task — coarse occupancy (Week 6) will not notice; fine localization (Week 8) or a subtle Doppler signature (Week 7) might. When this course's later benchmarks are re-run on standardized rather than raw CSI, this is the knob that will move them, and it is negotiated per session, not fixed.
4. Why Scheduling Matters — the Packet-Rate Floor, Revisited
Week 3 gave us a hard ceiling. To see a person moving at radial speed v you must sample the channel faster than the Doppler shift they induce, f_D = 2v/\lambda; by Nyquist the fastest unambiguous speed at packet rate \mathrm{PRR} is
In words: double the Doppler, halve it again for Nyquist — the capture rate is a ceiling on the speed you can ever resolve, fixed before any algorithm runs. At the lab's 5 GHz band (\lambda = 5.64 cm), the workbook reproduces the same ladder as Week 3: 100 Hz → 1.41 m/s, and a quiet 40 Hz → only 0.56 m/s.
This is where 802.11bf's trigger-based scheduling earns its keep. A walking person at v = 1.0 m/s induces a Doppler of 35.5 Hz, which needs a packet rate above 71 Hz to resolve. When the AP chooses a 100 Hz cadence, it clears that bar and the workbook recovers the speed exactly: peak at 35.3 Hz, v = 1.00 m/s. When the same person is sensed off ambient traffic in a quiet room — an effective 40 Hz — the Doppler exceeds the 20 Hz Nyquist and folds to a false 4.7 Hz, reporting the walker as a 0.13 m/s crawl. Same person, same physics; the only difference is who set the rate.

Two honest caveats keep this from overselling. First, the workbook models the low ambient rate as steady to show the textbook fold cleanly; genuinely bursty arrivals are anti-aliasing — random sampling trades the sharp alias for a raised noise floor — but the practical outcome is the same: the walker is lost, because you never got to choose the rate. Second, this argues that scheduling is a guarantee, not that ambient sensing never works; it works precisely when the ambient rate happens to be high, which is exactly what you cannot rely on. 802.11bf turns "happens to be high" into "negotiated to be high."
5. Can You Run 802.11bf on an AX210?
This is the question this lab actually needs answered, so answer it plainly: no — the AX210 is not, and will not become, an 802.11bf-compliant sensing device — and that does not matter for the research.
The "no" is a firmware-and-silicon fact. 802.11bf compliance requires the MAC and firmware to implement the sensing-session machinery of Section 2 — the negotiation, the sounding scheduling, the report frames. The AX210's firmware is closed, Intel has shipped no 802.11bf sensing on it, and no amount of driver patching adds a MAC-layer service the firmware does not implement. As of now there is essentially no commodity 802.11bf sensing hardware to buy instead; all sensing research — this lab's included — runs on pre-standard CSI extraction (AX210/AX200 via FeitCSI or IAX, Nexmon on Broadcom, ESP32, the venerable Intel 5300).
There is, however, a sharper version of the question that does have a constructive answer: can you build a system that behaves like 802.11bf on an AX210? Here the answer is yes. FeitCSI and IAX let the AX210 not only extract CSI but inject its own frames — you can emit sounding packets at a rate you choose and read the resulting CSI. That is the functional core of a sensing session: deliberate, scheduled, active sounding plus a channel measurement, at a cadence you control. What you give up relative to standard 802.11bf is the standard-compliant negotiation and report frames, the cross-vendor interoperability, and the convenience of the AP scheduling it for you (you run the scheduler yourself). What you keep is the physics and the control. So the lab does not wait for 11bf silicon; it builds a research sensing system that behaves like 11bf — active scheduled sounding plus CSI — on an AX210 today, which is exactly what the IP-106 measurement protocol specifies.
The "does not matter" for compliance is the payoff of Section 1's slogan. What the AX210 hands you is the observable 802.11bf standardizes: the per-subcarrier channel matrix \mathbf{H}. The lab's IP-112 driver work confirms the AX210 exposes this raw at up to 160 MHz (1992 = 2×996 subcarriers per stream) with no negotiated grouping or quantization — i.e. at higher fidelity than a compact 11bf report, obtained through a non-standard path and without the scheduling layer. Put the two side by side:
| Property | AX210 raw CSI (FeitCSI / IAX) | IEEE 802.11bf report |
|---|---|---|
| Physical observable | channel matrix \mathbf{H}(k) | channel matrix \mathbf{H}(k) — identical |
| Subcarriers (80 MHz) | 996, full and raw | negotiated grouping N_g (fewer) |
| Amplitude/phase depth | ~float (high fidelity) | negotiated b bits (lossy) |
| How you obtain it | monitor mode + patched firmware (hack) | negotiated sensing session |
| Sampling | ambient traffic (uncontrolled) | AP-scheduled sounding (guaranteed) |
| Interoperable | no (vendor-specific) | yes (cross-vendor) |
| Available today | yes | no commodity hardware yet |
Read that table as a research strategy, not a shopping list. Standardization is a deployment and interoperability property — it is about the day every AP is a sensor — not a new physical signal. Because your findings are about what \mathbf{H} tells you about a crowd, and \mathbf{H} is what both columns carry, results obtained on pre-standard AX210 CSI transfer conceptually to the standardized world. The two places 11bf differs — quantized/grouped feedback, and AP-scheduled rather than ambient sampling — are exactly the two knobs Sections 3 and 4 quantified, so you know how to reason about the transfer rather than merely hoping for it. Choosing the AX210 today is not a compromise while you wait for silicon; it gives you the raw material at higher fidelity now.
6. Why This Matters for the Thesis — the Gap the Standard Leaves Open
Return to the stack diagram of Section 1, and to the band it left empty. 802.11bf standardizes how CSI is acquired and reported. It says nothing about three problems that stand between a channel matrix and a crowd count — and those three are, almost exactly, this lab's thesis contribution.
One: the CSI is uncalibrated. Amplitude and phase are device-, antenna-, and environment-relative — automatic gain control, carrier- and sampling-frequency offset, packet-detection delay, per-radio amplifier gain. 802.11bf standardizes the report; it does not remove any of these. (Week 5 is the signal-level half of this; the thesis's BLE re-anchoring is the system-level half.)
Two: there is no ground truth. A standardized \mathbf{H} everywhere does not tell you what a "count" is. The thesis's answer — periodic BLE calibration campaigns that turn device trajectories into a density field — is orthogonal to the standard and unaffected by it.
Three: the map drifts. The relationship between CSI and occupancy moves as furniture, multipath, and hardware change. This is the sharpest point, because standardization makes the drift problem worse, not better: when standardized CSI is everywhere, the drift problem is everywhere. This lab has already measured the phenomenon on real hardware — a cross-environment leave-one-environment-out study across seven environments and two platforms found that the variance→count rank relation is universal but the absolute map does not transfer, and that a single anchored recalibration recovers 42 % of the zero-shot penalty. That result is precisely the shape of the world 802.11bf creates at scale, and the thesis's calibration-inference-drift cycle is the answer to it (the cross-modal disagreement statistic that triggers recalibration tracks true CSI error at \rho = 0.93).
So the honest positioning is not defensive but confident: 802.11bf provides the sensor; the open problem it leaves — self-calibration and drift correction under changing environments — is what this thesis solves. The standard is the best thing that could happen to the thesis's motivation (it turns the core modality from a research hack into anticipated commodity infrastructure — "by the time this deploys, every AP is a sensor") while leaving the thesis's contribution entirely intact.
There is one more reason the fit is clean. The lab's whole apparatus already produces 11bf-shaped observables from both ends: the AX210+Pi5 node emits \mathbf{H}, and the coupled JuPedSim→Sionna in-silico pipeline emits synthetic \mathbf{H}. Both the real and the simulated halves of the thesis are, in the terms of this week, 802.11bf-anticipatory — they generate exactly the standardized observable, one through pre-standard silicon and one through ray tracing. Nothing in the empirical program has to change when the standard arrives; only the label on the sensor does.
7. Showcase — What This Lab Does With All of It
The abstractions above become concrete in the lab's experimental program, which is worth seeing because every experiment probes a point where the standard's clean picture meets messy reality. The apparatus has two halves that both emit the 802.11bf observable \mathbf{H}: a real AX210 + Raspberry Pi 5 node (IP-112 / IP-106), and a coupled in-silico pipeline in which pedestrian dynamics (JuPedSim) drive ray-traced CSI and BLE (Sionna). The simulator lets every mechanism be tested before hardware; both are 802.11bf-shaped by construction.
Four experiments anchor the course. EXP-001 (BLE-assisted ground truth) solves the labelling problem — BLE device trajectories supply the count a CSI trace is trained against, the thesis's answer to "what is a count?" EXP-002 (model drift over time) measures the collapse — high accuracy on Monday, guessing by Friday — as the channel moves under a fixed model. EXP-007 (packet-rate floor) validates the v_{\max} = \lambda\cdot\mathrm{PRR}/4 ceiling of Section 4 by sweeping PRR on ray-traced CSI. EXP-008 (inject vs sniff) asks whether non-uniform passive sampling destroys the Doppler signature even at an adequate mean rate — the honest caveat from Section 4, turned into a test.
The headline result already in hand is the cross-environment leave-one-environment-out study of Section 6, run over seven real environments and two hardware platforms: the variance→count ranking is universal (rank correlation up to +1.0), the absolute map does not transfer, and a single anchored recalibration recovers 42 % of the zero-shot penalty toward the in-environment oracle. That is exactly the drift problem 802.11bf universalizes, with the thesis's recalibration loop as the demonstrated answer — the standard delivering the sensor, the lab supplying the calibration.
What Week 5 Builds On
This week quantified what a standard discards on purpose — grouping and quantization, the negotiated fidelity of a report. Week 5 turns to what every capture gets wrong even at full fidelity: the amplitude still carries AGC and band-edge colouring, and the phase still carries the CFO/SFO/packet-boundary offsets Week 2 flagged and never removed. Crucially, 802.11bf standardizes the report and not the sanitization — so the CSI-ratio and conjugate-multiplication tricks of Week 5 are needed whether the tensor came off an AX210 or an 11bf device. The self-calibration theme this week opened at the system level (BLE re-anchoring closing the gap in the stack) returns next week at the signal level, on the same synthetic CSI the workbook built here.
References
The standard and surveys
- IEEE 802.11bf-2025, Amendment 4: Enhancements for Wireless LAN Sensing — ratified 2024, published 2025. https://standards.ieee.org/ieee/802.11bf/11574/. Task Group status: https://www.ieee802.org/11/Reports/tgbf_update.htm.
- F. Restuccia, "IEEE 802.11bf: Toward Ubiquitous Wi-Fi Sensing," 2021 — position paper on the amendment's goals and architecture. arXiv:2103.14918, https://arxiv.org/abs/2103.14918.
- R. Du et al., "An Overview on IEEE 802.11bf: WLAN Sensing," IEEE Communications Surveys & Tutorials, 2024 — the standards-level survey of session structure, roles, and measurement reporting. arXiv:2207.04859, https://arxiv.org/abs/2207.04859.
- F. Meneghello et al., "Toward Integrated Sensing and Communications in IEEE 802.11bf Wi-Fi Networks," 2023. arXiv:2212.13930, https://arxiv.org/abs/2212.13930.
- J. Yang, X. Zhang, et al., "Hands-on Wireless Sensing with Wi-Fi: A Tutorial," Tsinghua TNS, 2022 — the WST tutorial anchoring W3–W5. arXiv:2206.09532, https://arxiv.org/abs/2206.09532.
CSI extraction tools (the card table)
- FeitCSI — AX200/AX210, all formats, 20–160 MHz, inject + extract (GPL): https://feitcsi.kuskosoft.com/.
- PicoScenes — first public platform for 802.11ax-format CSI on commodity NICs (QCA9300, IWL5300, AX200, AX210): https://ps.zpj.io/.
- Nexmon CSI — Broadcom 802.11ac, runs on the Raspberry Pi: https://github.com/seemoo-lab/nexmon_csi.
- ESP32-CSI-Tool — low-cost edge CSI: https://github.com/StevenMHernandez/ESP32-CSI-Tool.
- Linux 802.11n CSI Tool (Halperin 2011) — Intel 5300, the pre-standard extraction lineage Week 3 built on: https://dhalperi.github.io/linux-80211n-csitool/.
- CSIKit — Python parser for Atheros / Intel / Nexmon / ESP32 / FeitCSI / PicoScenes formats: https://github.com/Gi-z/CSIKit.
Course and lab
- WS501 Week 2 (OFDM → CSI) and Week 3 (extraction toolchains) — the channel matrix \mathbf{H} and the v_{\max} = \lambda\cdot\mathrm{PRR}/4 ceiling reused here.
- This lab: IP-112 (AX210-on-Pi5 CSI capture), IP-106 (BLE-calibrated CSI hardware measurement protocol), and the cross-environment LOEO result (mechanism travels, scale does not).