arXiv:2505.01816cs.CRcs.LG2025-05被引 7

攻击者可伪造数据让基站多分用户资源,检测方法准确率达99.2%

Rogue Cell: Adversarial Attack and Defense in Untrusted O-RAN Setup Exploiting the Traffic Steering xApp

  • 用伪造的性能指标欺骗流量调度,实现资源劫持
  • 攻击使恶意基站获248.5%超额用户设备分配
  • 基于LSTM自编码器的检测框架准确率超99%

开放无线接入网(O-RAN)通过开放架构和AI管理提升灵活性与降低成本,但其多运营商部署引入了新型安全风险。本文首次关注从单运营商向多运营商架构转型带来的威胁,提出并验证了一种名为APATE的逃避攻击:恶意基站篡改关键性能指标(KPI),诱导流量调度机制错误分配用户设备(UE)。为此,我们构建了集成无线仿真与官方O-RAN软件社区(OSC)RIC集群的测试平台,真实采集数据。为防御该攻击,提出基于LSTM自编码器的检测框架MARRS,可学习网络上下文特征监测异常遥测。评估显示,执行APATE后,攻击者可获得比正常情况高出248.5%的用户设备资源;而MARRS检测准确率达99.2%,F1得分为0.978。

原文摘要 · Abstract (English)

The Open Radio Access Network (O-RAN) architecture is revolutionizing cellular networks with its open, multi-vendor design and AI-driven management, aiming to enhance flexibility and reduce costs. Although it has many advantages, O-RAN is not threat-free. While previous studies have mainly examined vulnerabilities arising from O-RAN's intelligent components, this paper is the first to focus on the security challenges and vulnerabilities introduced by transitioning from single-operator to multi-operator RAN architectures. This shift increases the risk of untrusted third-party operators managing different parts of the network. To explore these vulnerabilities and their potential mitigation, we developed an open-access testbed environment that integrates a wireless network simulator with the official O-RAN Software Community (OSC) RAN intelligent component (RIC) cluster. This environment enables realistic, live data collection and serves as a platform for demonstrating APATE (adversarial perturbation against traffic efficiency), an evasion attack in which a malicious cell manipulates its reported key performance indicators (KPIs) and deceives the O-RAN traffic steering to gain unfair allocations of user equipment (UE). To ensure that O-RAN's legitimate activity continues, we introduce MARRS (monitoring adversarial RAN reports), a detection framework based on a long-short term memory (LSTM) autoencoder (AE) that learns contextual features across the network to monitor malicious telemetry (also demonstrated in our testbed). Our evaluation showed that by executing APATE, an attacker can obtain a 248.5% greater UE allocation than it was supposed to in a benign scenario. In addition, the MARRS detection method was also shown to successfully classify malicious cell activity, achieving accuracy of 99.2% and an F1 score of 0.978.

O-RAN安全流量劫持恶意基站LSTM检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。