用大模型让5G RAN的异常检测既准又看得懂
Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs
- 用时序性能指标+LSTM识别恶意用户设备行为
- 真实5G数据上检测准确率超96%(F1分数)
- 大模型把技术解释转成普通人能看懂的话
下一代无线接入网(RAN)通过智能控制器实现可编程性、智能化和近实时控制,增强了RAN及更广泛5G/6G基础设施的安全性。本文综述了大语言模型(LLMs)辅助的可解释性入侵检测(XAI-ID)在安全未来RAN环境中的机遇、挑战与研究空白。为此,我们提出一种基于大语言模型的可解释异常检测系统,用于分布式拒绝服务(DDoS)攻击检测,利用近实时RAN智能控制器(Near-RT RIC)中E2节点提取的多变量时间序列关键性能指标(KPMs)。采用LSTM模型基于这些KPMs训练以识别恶意用户设备(UE)行为。为提升透明度,应用LIME和SHAP等后处理局部可解释性方法解析单个预测结果,并借助大语言模型将技术性解释转化为非专业用户可理解的自然语言洞察。在真实5G网络KPM数据上的实验表明,该框架在保持高检测精度(F1-score > 0.96)的同时,提供可操作且可解释的输出。
原文摘要 · Abstract (English)
Next generation Radio Access Networks (RANs) introduce programmability, intelligence, and near real-time control through intelligent controllers, enabling enhanced security within the RAN and across broader 5G/6G infrastructures. This paper presents a comprehensive survey highlighting opportunities, challenges, and research gaps for Large Language Models (LLMs)-assisted explainable (XAI) intrusion detection (IDS) for secure future RAN environments. Motivated by this, we propose an LLM interpretable anomaly-based detection system for distributed denial-of-service (DDoS) attacks using multivariate time series key performance measures (KPMs), extracted from E2 nodes, within the Near Real-Time RAN Intelligent Controller (Near-RT RIC). An LSTM-based model is trained to identify malicious User Equipment (UE) behavior based on these KPMs. To enhance transparency, we apply post-hoc local explainability methods such as LIME and SHAP to interpret individual predictions. Furthermore, LLMs are employed to convert technical explanations into natural-language insights accessible to non-expert users. Experimental results on real 5G network KPMs demonstrate that our framework achieves high detection accuracy (F1-score > 0.96) while delivering actionable and interpretable outputs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。