arXiv:2606.06261cs.NIcs.AI2026-06

用视觉语言模型和大模型检测开放无线网络中的异常,无需标注数据。

DAST: A VLM-LLM Framework for Cross-Interface Anomaly Detection in O-RAN

论文配图:DAST: A VLM-LLM Framework for Cross-Interface Anomaly Detection in O-RAN
图 1 · 摘自论文原文
  • 三阶段多智能体框架:视觉模型转为图像,大模型分析描述,再用热力图验证。
  • 在真实测试中达到0.910的F1分数,优于现有时序异常检测方法。
  • 适合网络安全研究员、O-RAN运维人员快速定位异常接口与影响范围。

O-RAN通过标准化开放接口实现基带栈的解耦与可编程化,但同时也扩大了跨逻辑层级的攻击面。其中,拒绝服务与性能下降类攻击占已知威胁的多数,且难以检测。传统时序异常检测(TSAD)方法在缺乏标注基准、威胁演化快于模型更新、高维多变量遥测数据过载等新场景下表现不佳。为此,我们提出DAST,一种面向O-RAN跨接口异常检测的零样本多智能体框架,采用视觉语言模型(VLM)→大语言模型(LLM)→视觉语言模型(VLM)的三阶段链式结构。DAST将多变量关键性能指标(KPI)流转化为视觉表示,基于领域知识评估各接口文本描述,再通过高分辨率热力图验证可疑项,输出异常接口、异常时间区间、符合O-RAN WG11标准的操作影响评级及决策依据。我们在实测O-RAN测试床中对代表性性能下降场景进行评估,获得0.910的F1分数和0.843准确率,显著优于当前最优的TSAD基线方法。

原文摘要 · Abstract (English)

O-RAN enables a disaggregated baseband stack with programmable functions that communicate over standardized open interfaces. The same openness that enables multi-vendor composition also expands the attack surface across logically decoupled tiers that make up the compute continuum. Among these threats, Denial-of-Service and performance-degradation attacks, which account for the majority of catalogued O-RAN threats, are particularly difficult to detect. Traditional Time-Series Anomaly Detection (TSAD) methods fail in this new regime where labelled baselines are scarce, threats evolve faster than detectors can be retrained, and the high-dimensional multivariate telemetry overwhelms monolithic inference models. To address these challenges, we present DAST, a zero-shot multi-agent framework for cross-interface anomaly detection in O-RAN that chains a three-stage VLM $\rightarrow$ LLM $\rightarrow$ VLM pipeline. DAST converts multivariate KPI streams into visual representations, scores textual per-interface descriptions against O-RAN domain knowledge, and verifies suspects on high-resolution heatmaps to output the problematic interfaces, the anomalous time intervals, an indicative O-RAN WG11-aligned operational impact rating and the decision rationale. We evaluate DAST on real network traces collected from an O-RAN testbed under representative performance degradation scenarios, achieving 0.910 F1-Score and 0.843 Accuracy, outperforming state-of-the-art TSAD baselines.

O-RAN异常检测多模态大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。