arXiv:2510.02236cs.LG2025-10

针对5G网络切片切换攻击,提出基于正负样本学习的异常检测方案。

PUL-Inter-slice Defender: An Anomaly Detection Solution for Distributed Slice Mobility Attacks

  • 利用正负样本学习与LSTM自编码器+K均值聚类识别攻击
  • 在10%~40%污染数据下仍保持超98.5%的F1分数
  • 适用于5G切片安全防护,尤其适合实际部署中的噪声环境

网络切片(NSs)是在共享物理基础设施上运行的虚拟网络,旨在满足特定应用需求并维持一致的服务质量。在第五代移动通信(5G)网络中,用户设备(UE)可连接并无缝切换多个网络切片以访问多样化服务。然而,这种灵活性——即切片间切换(ISS)——可能被利用发起分布式切片移动性(DSM)攻击,一种分布式拒绝服务(DDoS)攻击形式。为防御5G网络及其切片免受此类攻击,本文提出PUL-Inter-Slice Defender:一种基于正负样本学习(PUL)的异常检测方案,结合长短期记忆自编码器与K均值聚类。该方案采用3GPP关键性能指标和性能测量计数器作为特征,实现对多种DSM攻击变种的检测,并在存在污染训练数据时仍保持鲁棒性。在基于开源free5GC和UERANSIM(UE/无线接入网模拟器)搭建的5G测试床采集的数据上评估,当训练集攻击污染率为10%至40%时,该方案的F1得分超过98.50%,显著优于对比方案Inter-Slice Defender及其他结合单类支持向量机(OCSVM)、随机森林与XGBoost的PUL方法。

原文摘要 · Abstract (English)

Network Slices (NSs) are virtual networks operating over a shared physical infrastructure, each designed to meet specific application requirements while maintaining consistent Quality of Service (QoS). In Fifth Generation (5G) networks, User Equipment (UE) can connect to and seamlessly switch between multiple NSs to access diverse services. However, this flexibility, known as Inter-Slice Switching (ISS), introduces a potential vulnerability that can be exploited to launch Distributed Slice Mobility (DSM) attacks, a form of Distributed Denial of Service (DDoS) attack. To secure 5G networks and their NSs against DSM attacks, we present in this work, PUL-Inter-Slice Defender; an anomaly detection solution that leverages Positive Unlabeled Learning (PUL) and incorporates a combination of Long Short-Term Memory Autoencoders and K-Means clustering. PUL-Inter-Slice Defender leverages the Third Generation Partnership Project (3GPP) key performance indicators and performance measurement counters as features for its machine learning models to detect DSM attack variants while maintaining robustness in the presence of contaminated training data. When evaluated on data collected from our 5G testbed based on the open-source free5GC and UERANSIM, a UE/ Radio Access Network (RAN) simulator; PUL-Inter-Slice Defender achieved F1-scores exceeding 98.50% on training datasets with 10% to 40% attack contamination, consistently outperforming its counterpart Inter-Slice Defender and other PUL based solutions combining One-Class Support Vector Machine (OCSVM) with Random Forest and XGBoost.

5G安全异常检测切片攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。