arXiv:2605.26679cs.CRcs.AI2026-05

6G网络攻击溯源实现毫秒级精准定位,解决资源竞争导致的误判问题。

Certified Causal Attribution for Real-Time Attack Forensics in 6G Network Slicing

论文配图:Certified Causal Attribution for Real-Time Attack Forensics in 6G Network Slicing
图 1 · 摘自论文原文
  • 引入资源条件化格兰杰因果与资源争用模型,消除虚假关联干扰。
  • 在15个切片上实现89.2%准确率,响应时间仅87毫秒,快2.7倍且更准。
  • 具备形式化认证能力,支持抗欺骗、差分隐私部署,适合高安全场景。

6G网络跨切片攻击溯源需在100毫秒内识别通过共享基础设施传播的因果链。现有方法因资源共享引发的虚假相关性难以与真实因果关系区分,在标准格兰杰检验下准确性下降。本文提出DA-GC框架,融合资源条件化格兰杰因果与公理推导的资源争用模型(RCM),系统性阻断资源介导的混淆因素。在包含1,100个攻击场景的15切片生产级仿真测试中,DA-GC实现89.2%的溯源准确率,耗时87毫秒。相比最强基线,准确率提升7.9个百分点,延迟降低2.7倍,并验证了跨拓扑泛化与概念漂移鲁棒性。关键的是,DA-GC配备完整形式化认证体系:证明了在序列依赖遥测与分段平稳条件下的统计有效性;建立了严格安全边界,包括对抗性资源利用伪造的破裂点δ*≈0.95;并定义了实现可证明私密性与鲁棒性的最小差分隐私噪声水平。

原文摘要 · Abstract (English)

Cross-slice attack attribution in 6G networks requires identifying causal propagation chains through shared infrastructure in under 100 ms. Existing methods struggle to satisfy this strict SLA without sacrificing accuracy, because shared resource contention creates spurious correlations that are indistinguishable from genuine causal links under standard Granger tests. We propose DA-GC, a certified causal attribution framework that integrates resource-conditioned Granger causality with an axiomatically derived Resource Contention Model (RCM) to systematically block resource-mediated confounding. On a 15-slice production-emulation 6G testbed with 1,100 attack scenarios, DA-GC achieves 89.2% attribution accuracy at 87 ms. This represents a 7.9 percentage-point improvement over the strongest baseline at 2.7x lower latency, alongside demonstrated cross-topology generalization and concept-drift resilience. Crucially, DA-GC is backed by a comprehensive formal certification stack. We provide mathematically proven validity certificates for statistical soundness under serially dependent telemetry and piecewise-stationarity. Furthermore, we establish strict security bounds, including an adversarial utilization spoofing breakdown point of $δ^* \approx 0.95$, and define the minimum differential-privacy noise required for a provably private and robust deployment.

6G安全攻击溯源因果推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。