arXiv:2602.03596cs.LG2026-02被引 1

提出5G核心网异常检测的实战评估指南,应对真实攻击者对抗性行为。

SAGE-5GC: Security-Aware Guidelines for Evaluating Anomaly Detection in the 5G Core Network

  • 基于领域知识设计安全感知评估框架,模拟真实攻击场景。
  • 对抗攻击使检测率下降超40%,暴露现有模型脆弱性。
  • 无需了解检测模型即可优化攻击策略,适合安全研究人员使用。

基于机器学习的异常检测系统正被越来越多地应用于5G核心网,以监控复杂且高流量的网络行为。然而,现有方法大多在理想条件下评估,如独立同分布(IID)数据假设和无适应性攻击者,这些条件在实际部署中极少成立。本文聚焦于真实环境中5G攻击的检测问题,提出一套安全感知的评估指南(SAGE-5GC),结合领域知识与潜在对抗威胁。利用真实的5G核心网数据集,我们训练多个异常检测器,并评估其在标准5GC控制面攻击(针对PFCP服务)下的基线性能。随后,引入对抗性设置:攻击者在保持恶意流量功能不变的前提下,操纵可观测特征以逃避检测。通过随机扰动可控特征,分析模型敏感性与鲁棒性。最后,提出一种基于遗传算法的实用优化策略,仅作用于攻击者可操控的特征,无需了解检测模型内部结构。实验结果表明,对抗性构造的攻击可显著降低检测性能,凸显了在真实部署中采用鲁棒、安全感知评估方法的必要性。

原文摘要 · Abstract (English)

Machine learning-based anomaly detection systems are increasingly being adopted in 5G Core networks to monitor complex, high-volume traffic. However, most existing approaches are evaluated under strong assumptions that rarely hold in operational environments, notably the availability of independent and identically distributed (IID) data and the absence of adaptive attackers. In this work, we study the problem of detecting 5G attacks in the wild, focusing on realistic deployment settings. We propose a set of Security-Aware Guidelines for Evaluating anomaly detectors in 5G Core Network (SAGE-5GC), driven by domain knowledge and consideration of potential adversarial threats. Using a realistic 5G Core dataset, we first train several anomaly detectors and assess their baseline performance against standard 5GC control-plane cyberattacks targeting PFCP-based network services. We then extend the evaluation to adversarial settings, where an attacker tries to manipulate the observable features of the network traffic to evade detection, under the constraint that the intended functionality of the malicious traffic is preserved. Starting from a selected set of controllable features, we analyze model sensitivity and adversarial robustness through randomized perturbations. Finally, we introduce a practical optimization strategy based on genetic algorithms that operates exclusively on attacker-controllable features and does not require prior knowledge of the underlying detection model. Our experimental results show that adversarially crafted attacks can substantially degrade detection performance, underscoring the need for robust, security-aware evaluation methodologies for anomaly detection in 5G networks deployed in the wild.

5G安全异常检测对抗攻击评估框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。