6G时代智能闭环安全系统,毫秒级防御物理威胁。
AI-Native Closed-Loop Security for 6G-Enabled Cyber-Physical Systems: From Edge Detection to Network-Wide Mitigation

- 在边缘计算层用通话记录和无线数据实时感知威胁
- 通过联邦学习与数字孪生实现全网自适应防御
- 适合研究6G安全与工业物联网的开发者和工程师
第六代网络中,数十亿个网络物理系统(如自动驾驶、智能电网、工业机器人、远程手术设备)将在超可靠低时延切片上运行,使远程攻击到物理伤害的时间缩短至毫秒级,传统防火墙与中心化安全体系已无法应对。本文将6G CPS安全重构为端到端的智能闭环流程:在多接入边缘计算层感知,利用分钟级话单记录进行基线学习,以亚毫秒级无线接入网(O-RAN)遥测数据支撑关键路径检测;本地决策采用压缩深度模型,网络级响应由软件定义网络(SDN)、网络功能虚拟化(NFV)和O-RAN控制器协同执行;并通过联邦学习与数字孪生回放机制实现持续重训练。我们为每个切片建立尾部时延约束(基于分位数p99),确保安全关键的超可靠低时延通信(URLLC)切片性能。基于PRISMA 2020协议梳理128篇同行评审文献(2017–2026),本文(i)将6G/CPS威胁面映射至MITRE ATT&CK框架与可观测话单特征空间;(ii)统一十二个数据集上边缘异常检测与分布式拒绝服务分类任务,涵盖统计、图神经网络与变压器模型;(iii)整合SDN/NFV/O-RAN能力形成统一闭环参考架构;(iv)将联邦学习、大语言模型、数字孪生、后量子密码、零信任架构与可解释人工智能作为跨领域使能技术而非并列模块;(v)归纳出涵盖数据、时延、信任、标准化与评估的五大开放挑战。
原文摘要 · Abstract (English)
In sixth-generation (6G) networks, billions of cyber-physical systems (CPSs) - autonomous vehicles, smart grids, industrial robots, and remote-surgical equipment - will run over ultra-reliable low-latency slices, collapsing the gap between a remote breach and physical harm to milliseconds, a budget perimeter firewalls and centralised security operations centres cannot meet. This survey reframes 6G CPS security as a closed-loop, AI-native pipeline that senses at the multi-access edge computing (MEC) tier, using minute-scale call-detail records (CDRs) for baseline learning and sub-millisecond RAN/Open-RAN (O-RAN) telemetry for the latency-critical path. It decides locally with compressed deep models, mitigates network-wide via SDN, NFV, and O-RAN controllers, and retrains through federated learning (FL) and digital-twin (DT) replay. We formalise a per-slice, tail-bounded latency contract on the sense, detect, and mitigate stages, enforced at a slice-dependent tail percentile (p99 for safety-critical URLLC slices). Organising 128 peer-reviewed studies (2017-2026) under a PRISMA 2020 protocol, we (i) map the 6G/CPS threat surface to MITRE ATT&CK and a CDR-observable feature space; (ii) unify edge anomaly detection and DDoS classification across twelve datasets and statistical, graph, and transformer models; (iii) synthesise SDN/NFV/O-RAN primitives into one closed-loop reference architecture; (iv) treat FL, large language models (LLMs), DT, post-quantum cryptography (PQC), zero-trust architecture (ZTA), and explainable AI as cross-cutting enablers, not parallel pillars; and (v) consolidate open problems into five directions spanning data, latency, trust, standardisation, and evaluation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。