arXiv:2509.21634cs.CRcs.AI2025-09被引 5

用AI自动应对6G网络攻击,实现从发现到处置的闭环防御。

MobiLLM: An Agentic AI Framework for Closed-Loop Threat Mitigation in 6G Open RANs

  • 基于大模型的多智能体系统,分工协作处理安全任务。
  • 响应延迟显著降低,能有效执行复杂防御策略。
  • 适合需要自动化安全运维的6G运营商与企业用户。

6G网络的发展正由开放无线接入网(O-RAN)范式加速推动——一种开放、互操作的架构,可在公共电信和私有企业领域部署智能、模块化应用。然而,这种开放性虽带来创新机遇,也扩大了攻击面,亟需高效、低成本、自主的安全部署方案。传统防护手段仍以被动响应为主,耗时费力且难以应对下一代系统的规模与复杂性。现有O-RAN应用主要聚焦网络优化或被动威胁检测,缺乏闭环自动化响应能力。为此,本文提出MobiLLM,一个面向6G O-RAN环境的智能体式AI框架,实现端到端自动化威胁缓解。该框架通过大型语言模型驱动的模块化多智能体系统,实现安全流程编排:威胁分析智能体负责实时数据筛选,威胁分类智能体利用检索增强生成(RAG)将异常映射至具体应对措施,威胁响应智能体则通过O-RAN控制接口安全执行缓解动作。框架依托可信知识库如MITRE FiGHT框架与3GPP规范,并配备健全的安全约束机制,为可信的AI驱动网络安全提供蓝图。初步评估表明,MobiLLM可有效识别并协调复杂缓解策略,显著降低响应延迟,验证了6G环境下自主安全运营的可行性。

原文摘要 · Abstract (English)

The evolution toward 6G networks is being accelerated by the Open Radio Access Network (O-RAN) paradigm -- an open, interoperable architecture that enables intelligent, modular applications across public telecom and private enterprise domains. While this openness creates unprecedented opportunities for innovation, it also expands the attack surface, demanding resilient, low-cost, and autonomous security solutions. Legacy defenses remain largely reactive, labor-intensive, and inadequate for the scale and complexity of next-generation systems. Current O-RAN applications focus mainly on network optimization or passive threat detection, with limited capability for closed-loop, automated response. To address this critical gap, we present an agentic AI framework for fully automated, end-to-end threat mitigation in 6G O-RAN environments. MobiLLM orchestrates security workflows through a modular multi-agent system powered by Large Language Models (LLMs). The framework features a Threat Analysis Agent for real-time data triage, a Threat Classification Agent that uses Retrieval-Augmented Generation (RAG) to map anomalies to specific countermeasures, and a Threat Response Agent that safely operationalizes mitigation actions via O-RAN control interfaces. Grounded in trusted knowledge bases such as the MITRE FiGHT framework and 3GPP specifications, and equipped with robust safety guardrails, MobiLLM provides a blueprint for trustworthy AI-driven network security. Initial evaluations demonstrate that MobiLLM can effectively identify and orchestrate complex mitigation strategies, significantly reducing response latency and showcasing the feasibility of autonomous security operations in 6G.

6G安全AI防御多智能体O-RAN

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。