REVIEW 4 major objections 5 minor 1 cited by
Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs
T0 review · 4 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read An LSTM trained on user-equipment 5G radio metrics can detect DDoS attacks with F1 above 0.96 and explain each alert in plain language.
desk verdict A worthwhile AI-RAN security system paper whose headline F1 is undermined by tuning on the test set; fix the evaluation and it's a solid contribution. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is an LSTM binary classifier over (3 time steps × 14 features) windows of user-equipment performance measures, trained with a past-data ratio of 0.3 to keep old attack signatures alive during updates. Around it, the pipeline chains three components: Kernel SHAP and LIME for post-hoc local attributions, a hand-built prompt that carries feature statistics, input sequence, model output, and explanation tables, and an LLM that produces a human-readable summary with suggested mitigations. The LSTM is what the detection claim rests on; the XAI-LLM chain is what turns that verdict into something an operator can verify.
What would settle it
Measure the end-to-end detection loop on the same testbed or another 5G network—KPM collection, delivery to the controller, preprocessing, LSTM inference, and LLM explanation—and check whether average F1 stays above 0.96 and total latency stays within the near-real-time RIC budget; alternatively, rerun the training procedure on a fresh split or a different 5G dataset and see whether the 0.3 past-data ratio still yields F1 above 0.96.
Extended reading notes
Core claim
The paper's central discovery, on its own terms, is that temporal patterns in user-equipment performance measurements—sampled every five seconds and arranged into (3, 14) sequences—carry enough signal to separate DDoS traffic from normal traffic with average F1 above 0.96 across four test days. The key to maintaining that score over time is replaying a fraction (0.3) of past training data when updating the model, which prevents catastrophic forgetting; without it, the F1 for the last day drops to 0.36. The same LSTM is small enough that a single forward pass costs about 36K FLOPs, reported at 0.03 ms per sample on the CPU used in the experiments, which the paper takes as evidence the detector can fit near-real-time RIC operation. On the interpretability side, the paper shows that SHAP and LIME highlight consistent attack drivers such as uplink bitrate, uplink retransmissions, and downlink/uplink asymmetry, and that LLM-generated summaries turn those drivers into operator-readable text.
Load-bearing premise
The dataset from one small 5G testbed, with three cells and nine UEs, is assumed to behave like real production RAN traffic, and the measured 0.03 ms LSTM inference is assumed to fit the near-real-time budget once delivery, preprocessing, XAI, and LLM steps are included.
Editorial extensions
If this is right
- A DDoS detector can run inside the near-real-time RAN controller as an xApp on per-UE telemetry, with the heavy explanation stage offloaded to an rApp outside the real-time loop.
- Replaying 30% past data on each model update keeps detection stable across days, raising the worst-day F1 from 0.36 to 0.98.
- On the dataset used here, the proposed LSTM (F1 0.98, FPR 0.05%, FNR 6.31%) beats the CNN and LSTM baselines (0.93 and 0.90) and remains competitive with kNN/XGBoost (1.00) while capturing temporal structure and lower inference cost.
- Operators receive natural-language explanations with anomaly summary, misclassification likelihood, and mitigation steps, making automated RAN security review possible without a deep-learning expert.
- Global SHAP importance shows attack detection relies on uplink/downlink asymmetry, uplink bitrate, and retransmissions, so these features can be prioritized in monitoring.
Reading between the lines
- Beyond what the paper shows: the reported 0.03 ms covers only LSTM inference; the full loop through delivery, normalization, SHAP/LIME computation, and an LLM call will be much slower, so the near-real-time claim needs an end-to-end measurement before deployment.
- Because the detector is trained on one testbed with a 1.7% attack rate, its high F1 could reflect dataset-specific artifacts; testing on other RAN traces or with different attack types would reveal whether the feature patterns generalize.
- The LLM-generated mitigation advice is not validated for correctness; an operator who follows it without checking could act on a plausible-sounding but wrong suggestion, so the advisory role of the rApp is a sensible boundary.
- If the same three-step LSTM were evaluated with online learning instead of day-wise retraining, the past-data ratio could be tested as a continual-learning mechanism against real drift.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper combines a survey of XAI and LLM methods for intrusion detection in RANs with a proposed framework for DDoS detection in AI-RAN. The detection component is an LSTM trained on UE KPM time series extracted from E2 nodes, processed inside a Near-RT RIC xApp, followed by a separate rApp that applies LIME and SHAP and then uses LLMs to translate technical explanations into natural-language summaries. Experiments on the public NCSRD 5G testbed dataset report average F1 scores above 0.96, an inference time of 0.03 ms per sample on an Intel i7-10700 CPU, and readability scores for the LLM-generated explanations. The paper claims the framework is suitable for near-real-time deployment and provides interpretable, actionable outputs for non-expert operators.
Significance. If the claims were fully supported, the paper would be a useful contribution to AI-for-RAN security: it evaluates on a public, real-testbed dataset; it compares against prior NCSRD baselines; and it integrates detection, post-hoc XAI, and LLM-based summarization into a concrete O-RAN-style architecture. The survey portion is competently assembled, and the detection idea is plausible. However, the headline F1 claim currently rests on an evaluation protocol that selects hyperparameters on the same previous-day test sets used for final reporting, the near-real-time claim is based on a single component latency, and the interpretability evaluation measures readability rather than faithfulness. These issues are local and fixable, but they are load-bearing for the paper's central claims.
major comments (4)
- [Section IV-B and IV-C, Figs. 6-7, Table V] The grid search over window size and past-data ratio is evaluated on the same previous-day test sets that are then used to report the final F1 scores. The text selects window size 3 and ratio 0.3 based on performance on these sets, and Table V reports average F1 on the same previous-day test sets. Because the hyperparameters are chosen to optimize exactly the data used in the final table, the reported F1 > 0.96 is subject to selection bias and is not an unbiased estimate of generalization. A genuinely held-out evaluation, such as a completely unseen day or nested cross-validation, is required before the abstract's headline claim can be accepted.
- [Section IV-C] The near-real-time claim is supported only by the 0.03 ms LSTM inference time on an Intel i7-10700 CPU. The end-to-end pipeline also includes KPM preprocessing in the xApp, E2 transport, per-instance SHAP and LIME computation, LLM API calls, and rApp scheduling. Section III-A itself notes that LLM latency can exceed near-real-time constraints and places the XAI+LLM module in a non-real-time rApp. Without end-to-end latency measurements or a delay budget for each stage, the statement that the framework is 'well-suited for near real-time deployment' is not supported by the presented evidence.
- [Section IV-C and Table VII] The interpretability evaluation uses only Flesch Reading Ease and Gunning Fog Index. These readability metrics do not measure whether the LLM-generated summaries are faithful to the LSTM's actual decision process, whether they correctly reflect the underlying SHAP/LIME attributions, or whether operators can act correctly on them. The paper needs an evaluation of explanation correctness, such as consistency checks with the XAI outputs, expert ratings, or task-based user studies, before claiming that the framework delivers 'interpretable outputs' as a validated contribution.
- [Tables V and VI] The paper reports inconsistent headline numbers for the proposed detector. Table V gives average F1 values of 0.96-0.99 with ratio 0.3, while Table VI lists 'Proposed DDoS Detection' as 0.98 with FPR 0.05% and FNR 6.31%. The relationship between these numbers is not explained, and it is unclear which evaluation setup corresponds to the abstract's F1 > 0.96 claim. The final F1 claim should be tied to one clearly defined evaluation protocol.
minor comments (5)
- [Section IV-B] The 'past data ratio' is never formally defined; please specify exactly how previous-day samples are mixed with current training data and how the ratio is applied during training.
- [Section IV-A] The dataset description does not state whether the 80-20 split is random over samples or structured by day and UE. A time-based split should be described to rule out temporal leakage between training and test instances.
- [Fig. 7] The FPR and FNR heatmaps are shown only for window sizes 1-7, while the grid search described in the text covers window sizes 1-10; please explain or extend the figure.
- [Section IV-B] The text says MinMax normalization was applied but does not state whether the normalization parameters were computed on the training data only and then applied to test data; please clarify.
- [Table VII] The Gunning Fog Index values are reported inconsistently, with some entries as numbers and others as 'college' or 'college graduate'; please use a consistent format.
Circularity Check
No significant circularity: the F1 claim is an empirical evaluation, not a derivation; minor self-citations and test-set tuning caveats do not make the result circular.
full rationale
The paper's load-bearing claim is an empirical F1-score from a trained LSTM on the NCSRD 5G testbed, not a derivation that could reduce to its inputs. The LSTM weights are learned from labeled KPM sequences (Sections III-A and IV-B), and the reported F1/FPR/FNR values are computed on previous-day test splits (Section IV-C). The XAI and LLM stages are applied post-hoc to an already-trained model and do not feed back into training, so the interpretability pipeline cannot make the detection result circular. The only self-citations (e.g., [19], [20], [47]) appear in related work and are not used to justify the correctness of the proposed framework. The paper itself notes that operational deployment in a real Open RAN emulator is future work (Section V), which is an acknowledged limitation rather than a circular argument. A legitimate methodological concern is that window size and past-data ratio are selected on the same previous-day test sets later used for the final F1 report, which introduces selection bias; however, this is not a construction-level equivalence and does not meet the bar for circularity. The framework is compared against external baselines ([89], [90]) and uses an external public dataset [88], so the central empirical claim remains self-contained. The score of 2 reflects minor self-citations and the test-set tuning caveat, not any identified circular step.
Assumptions & free parameters
free parameters (3)
- window_size =
3
- past_data_ratio =
0.3
- lstm_hidden_units =
32
assumptions (5)
- domain assumption NCSRD KPM labels and measurements are accurate ground truth for DDoS activity.
- domain assumption A 3-step, 5-second-sampled KPM window contains sufficient temporal signal for DDoS detection.
- domain assumption LIME and Kernel SHAP are faithful local explanations for the LSTM.
- domain assumption The LLM produces accurate natural-language summaries and mitigation advice from the provided tables.
- domain assumption The 80-20 split and day-wise evaluation avoid temporal leakage.
Cite this review
Pith. "Pith review of Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs." pith.science (2026). https://pith.science/paper/HPAEII7X
@misc{pith2026250721193,
author = {Pith},
title = {Pith review of: Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs},
year = {2026},
howpublished = {\url{https://pith.science/paper/HPAEII7X}},
note = {Machine review of arXiv:2507.21193}
}
read the original abstract
Next generation Radio Access Networks (RANs) introduce programmability, intelligence, and near real-time control through intelligent controllers, enabling enhanced security within the RAN and across broader 5G/6G infrastructures. This paper presents a comprehensive survey highlighting opportunities, challenges, and research gaps for Large Language Models (LLMs)-assisted explainable (XAI) intrusion detection (IDS) for secure future RAN environments. Motivated by this, we propose an LLM interpretable anomaly-based detection system for distributed denial-of-service (DDoS) attacks using multivariate time series key performance measures (KPMs), extracted from E2 nodes, within the Near Real-Time RAN Intelligent Controller (Near-RT RIC). An LSTM-based model is trained to identify malicious User Equipment (UE) behavior based on these KPMs. To enhance transparency, we apply post-hoc local explainability methods such as LIME and SHAP to interpret individual predictions. Furthermore, LLMs are employed to convert technical explanations into natural-language insights accessible to non-expert users. Experimental results on real 5G network KPMs demonstrate that our framework achieves high detection accuracy (F1-score > 0.96) while delivering actionable and interpretable outputs.
Figures
Figures from the paper (7 more)
Forward citations
Cited by 1 Pith paper
-
(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations
An event-centric, multi-agent LLM framework explains network alerts through hypothesis-driven, retrieval-augmented investigation and claims to improve explanation quality and boundary-case classification.
Reference graph
Works this paper leans on
-
[1]
O-RAN White Paper: Towards an Open and Smart RAN,
O-RAN Alliance, “O-RAN White Paper: Towards an Open and Smart RAN,” 2018
2018
-
[2]
Under- standing O-RAN: Architecture, Interfaces, Algorithms, Security, and Research Challenges,
M. Polese, L. Bonati, S. D’Oro, S. Basagni, and T. Melodia, “Under- standing O-RAN: Architecture, Interfaces, Algorithms, Security, and Research Challenges,” IEEE Communications Surveys & Tutorials , vol. 25, no. 2, pp. 1376–1411, 2023
2023
-
[3]
RIC: A RAN Intelligent Controller Platform for AI-Enabled Cellular Networks,
B. Balasubramanian, E. S. Daniels, M. Hiltunen, R. Jana, K. Joshi, R. Sivaraj, T. X. Tran, and C. Wang, “RIC: A RAN Intelligent Controller Platform for AI-Enabled Cellular Networks,” IEEE Internet Computing, vol. 25, no. 2, pp. 7–17, 2021
2021
-
[4]
Intelligent Control in 6G Open RAN: Security Risk or Opportunity?
S. Soltani, A. Amanloo, M. Shojafar, and R. Tafazolli, “Intelligent Control in 6G Open RAN: Security Risk or Opportunity?” IEEE Open Journal of the Communications Society , vol. 6, pp. 840–880, 2025
2025
-
[5]
Slice- dRAN: Service-Aware Network Slicing Framework for 5G Radio Access Networks,
B. Ojaghi, F. Adelantado, A. Antonopoulos, and C. Verikoukis, “Slice- dRAN: Service-Aware Network Slicing Framework for 5G Radio Access Networks,” IEEE Systems Journal, vol. 16, no. 2, pp. 2556–2567, 2022
2022
-
[6]
Defining Intent-Based Service Management Automation for 6G Multi-Stakeholders Scenarios,
P. Alemany, R. Mu ˜noz, J. Castaneda Cisneros, M. Karaca, P. Porambage, H. Q. Tran, P. G. Giardina, I. Tzanettis, X. R. Sousa, J. Mar ´ıa Jor- quera Valero, B. Ojaghi, R. Vilalta, P. Rugeland, M. Boussard, G. Landi, A. Zafeiropoulos, S. Rodr ´ıguez, M. Gil P ´erez, S. Barmpounakis, M. A. Uusitalo, D. Lopez, and S. Kerboeuf, “Defining Intent-Based Service ...
2025
-
[7]
AI-RAN Alliance Vision and Mission White Paper,
AI-RAN Alliance, “AI-RAN Alliance Vision and Mission White Paper,” Dec. 2024
2024
-
[8]
AI- RAN: Transforming RAN with AI-driven Computing Infrastructure,
L. Kundu, X. Lin, R. Gadiyar, J.-F. Lacasse, and S. Chowdhury, “AI- RAN: Transforming RAN with AI-driven Computing Infrastructure,” 2025, arXiv:2501.09007
arXiv 2025
Show all 90 references
-
[9]
Toward 6G Security: Technology Trends, Threats, and Solutions,
D. Je, J. Jung, and S. Choi, “Toward 6G Security: Technology Trends, Threats, and Solutions,” IEEE Communications Standards Magazine , vol. 5, no. 3, pp. 64–71, 2021
2021
-
[10]
A Systematic Analysis of 5G Networks With a Focus on 5G Core Security,
Q. Tang, O. Ermis, C. D. Nguyen, A. D. Oliveira, and A. Hirtzig, “A Systematic Analysis of 5G Networks With a Focus on 5G Core Security,” IEEE Access, vol. 10, pp. 18 298–18 319, 2022
2022
-
[11]
O-RAN WG3 E2 Service Model (E2SM) KPM Specification,
“O-RAN WG3 E2 Service Model (E2SM) KPM Specification,” O-RAN Alliance, Tech. Rep. v06.00, February 2025
2025
-
[12]
O-RAN WG3 E2 General Aspects and Principles (E2GAP),
“O-RAN WG3 E2 General Aspects and Principles (E2GAP),” O-RAN Alliance, Tech. Rep. v07.00, February 2025
2025
-
[13]
O-RAN WG3 E2 Application Protocol (E2AP),
“O-RAN WG3 E2 Application Protocol (E2AP),” O-RAN Alliance, Tech. Rep. v07.00, February 2025
2025
-
[14]
Explainable Intrusion Detection Systems (X-IDS): A Survey of Current Methods, Challenges, and Opportunities,
S. Neupane, J. Ables, W. Anderson, S. Mittal, S. Rahimi, I. Banicescu, and M. Seale, “Explainable Intrusion Detection Systems (X-IDS): A Survey of Current Methods, Challenges, and Opportunities,” IEEE Access, vol. 10, pp. 112 392–112 415, 2022
2022
-
[15]
A Survey on Explainable Artificial Intelligence for Internet Traffic Classification and Prediction, and Intrusion Detection,
A. Nascita, G. Aceto, D. Ciuonzo, A. Montieri, V . Persico, and A. Pescap´e, “A Survey on Explainable Artificial Intelligence for Internet Traffic Classification and Prediction, and Intrusion Detection,” IEEE Communications Surveys & Tutorials , 2024
2024
-
[16]
NetGPT: An AI-Native Network Architecture for Provisioning Beyond Personalized Generative Services,
Y . Chen, R. Li, Z. Zhao, C. Peng, J. Wu, E. Hossain, and H. Zhang, “NetGPT: An AI-Native Network Architecture for Provisioning Beyond Personalized Generative Services,” IEEE Network , vol. 38, no. 6, pp. 404–413, 2024
2024
-
[17]
S-RAN: Semantic-aware radio access networks,
Y . Sun, L. Zhang, L. Guo, J. Li, D. Niyato, and Y . Fang, “S-RAN: Semantic-aware radio access networks,” IEEE Communications Maga- zine, vol. 63, no. 4, pp. 207–213, 2025
2025
-
[18]
Generative AI-driven semantic communication networks: Architecture, technologies, and applications,
C. Liang, H. Du, Y . Sun, D. Niyato, J. Kang, D. Zhao, and M. A. Imran, “Generative AI-driven semantic communication networks: Architecture, technologies, and applications,” IEEE Transactions on Cognitive Com- munications and Networking , vol. 11, no. 1, pp. 27–47, 2025
2025
-
[19]
A Collaborative Software Defined Network-Based Smart Grid Intrusion Detection System,
S. Chatzimiltis, M. Shojafar, M. B. Mashhadi, and R. Tafazolli, “A Collaborative Software Defined Network-Based Smart Grid Intrusion Detection System,” IEEE Open Journal of the Communications Society , vol. 5, pp. 700–711, 2024
2024
-
[20]
Intrusion Detection in Software Defined Networks with Imbalanced Attack Classes,
S. Chatzimiltis, S. R. Lucas, M. Shojafar, M. Boloursaz Mashhadi, and R. Tafazolli, “Intrusion Detection in Software Defined Networks with Imbalanced Attack Classes,” ITU Journal on Future and Evolving Technologies, vol. 5, no. 4, pp. 422 – 432, 2024
2024
-
[21]
SD-IIDS: Intelligent Intrusion Detection System for Software-Defined Networks,
N. S. Shaji, R. Muthalagu, and P. M. Pawar, “SD-IIDS: Intelligent Intrusion Detection System for Software-Defined Networks,”Multimedia Tools and Applications, vol. 83, no. 4, pp. 11 077–11 109, 2024
2024
-
[22]
Empirical Evaluation of Autoencoder Models for Anomaly Detection in Packet-based NIDS,
S. Hore, Q. H. Nguyen, Y . Xu, A. Shah, N. D. Bastian, and T. Le, “Empirical Evaluation of Autoencoder Models for Anomaly Detection in Packet-based NIDS,” in IEEE Conference on Dependable and Secure Computing (DSC), 2023, pp. 1–8
2023
-
[23]
Anomaly based Network Intrusion Detection for IoT Attacks Using Deep Learning Technique,
B. Sharma, L. Sharma, C. Lal, and S. Roy, “Anomaly based Network Intrusion Detection for IoT Attacks Using Deep Learning Technique,” Computers and Electrical Engineering , vol. 107, p. 108626, 2023
2023
-
[24]
Enhancing IoT security with CNN and LSTM-based intrusion detection systems,
A. Gueriani, H. Kheddar, and A. C. Mazari, “Enhancing IoT security with CNN and LSTM-based intrusion detection systems,” in IEEE 6th International Conference on Pattern Analysis and Intelligent Systems (PAIS), 2024, pp. 1–7
2024
-
[25]
LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in V ANETs,
J. Cui, J. Xiao, H. Zhong, J. Zhang, L. Wei, I. Bolodurina, and D. He, “LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in V ANETs,” IEEE Transactions on Mobile Computing, vol. 23, no. 12, pp. 12 195–12 210, 2024
2024
-
[26]
Improved IDS for Vehicular Ad-Hoc Network using Deep Learning Approaches,
A. Benziker, R. Arunagiri, and G. Maheswari, “Improved IDS for Vehicular Ad-Hoc Network using Deep Learning Approaches,” in IEEE 2nd International Conference on Automation, Computing and Renewable Systems (ICACRS), 2023, pp. 341–346
2023
-
[27]
Auto- Updating Intrusion Detection System for Vehicular Network: A Deep Learning Approach Based on Cloud-Edge-Vehicle Collaboration,
C. Fan, J. Cui, H. Jin, H. Zhong, I. Bolodurina, and D. He, “Auto- Updating Intrusion Detection System for Vehicular Network: A Deep Learning Approach Based on Cloud-Edge-Vehicle Collaboration,” IEEE Transactions on Vehicular Technology , vol. 73, no. 10, pp. 15 372– 15 384, 2024
2024
-
[28]
From Signatures to Behavior: Evolving Strategies for Next- Generation Intrusion Detection,
K. I. Iyer, “From Signatures to Behavior: Evolving Strategies for Next- Generation Intrusion Detection,” European Journal of Advances in Engineering and Technology, vol. 8, no. 6, pp. 165–171, 2021
2021
-
[29]
Outside the Closed World: On Using Machine Learning for Network Intrusion Detection,
R. Sommer and V . Paxson, “Outside the Closed World: On Using Machine Learning for Network Intrusion Detection,” in 2010 IEEE Symposium on Security and Privacy , 2010, pp. 305–316
2010
-
[30]
Network Intrusion Detection System: A Systematic Study of Machine Learning and Deep Learning Approaches,
Z. Ahmad, A. Shahid Khan, C. Wai Shiang, J. Abdullah, and F. Ahmad, “Network Intrusion Detection System: A Systematic Study of Machine Learning and Deep Learning Approaches,” Transactions on Emerging Telecommunications Technologies, vol. 32, no. 1, p. e4150, 2021
2021
-
[31]
A Systematic Literature Review for Network Intrusion Detection System (IDS),
O. H. Abdulganiyu, T. A. Tchakoucht, and Y . K. Saheed, “A Systematic Literature Review for Network Intrusion Detection System (IDS),” International Journal of Information Security , vol. 22, no. 5, pp. 1125– 1162, 2023
2023
-
[32]
Deep Learning-based Intrusion Detection Systems: A Survey,
Z. Xu, Y . Wu, S. Wang, J. Gao, T. Qiu, Z. Wang, H. Wan, and X. Zhao, “Deep Learning-based Intrusion Detection Systems: A Survey,” 2025, arXiv:2504.07839
2025
-
[33]
Survey on Federated Learning for Intrusion Detection System: Concept, Architec- tures, Aggregation Strategies, Challenges, and Future Directions,
A. Khraisat, A. Alazab, S. Singh, T. Jan, and A. Jr. Gomez, “Survey on Federated Learning for Intrusion Detection System: Concept, Architec- tures, Aggregation Strategies, Challenges, and Future Directions,” ACM Computing Surveys, vol. 57, no. 1, Oct. 2024
2024
-
[34]
Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey,
K. He, D. D. Kim, and M. R. Asghar, “Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey,” IEEE Communications Surveys & Tutorials, vol. 25, no. 1, pp. 538–566, 2023
2023
-
[35]
Deep Learning Advancements in Anomaly Detection: A Comprehensive Sur- vey,
H. Huang, P. Wang, J. Pei, J. Wang, S. Alexanian, and D. Niyato, “Deep Learning Advancements in Anomaly Detection: A Comprehensive Sur- vey,” IEEE Internet of Things Journal , 2025
2025
-
[36]
Deep Learning with Long Short-Term Memory for Time Series Prediction,
Y . Hua, Z. Zhao, R. Li, X. Chen, Z. Liu, and H. Zhang, “Deep Learning with Long Short-Term Memory for Time Series Prediction,” IEEE Communications Magazine , vol. 57, no. 6, pp. 114–119, 2019
2019
-
[37]
An optimized LSTM-based Deep Learning Model for Anomaly Network Intrusion Detection,
N. Dash, S. Chakravarty, A. K. Rath, N. C. Giri, K. M. AboRas, and N. Gowtham, “An optimized LSTM-based Deep Learning Model for Anomaly Network Intrusion Detection,”Scientific Reports, vol. 15, no. 1, p. 1554, 2025
2025
-
[38]
Attention- Based Deep Learning Frameworks for Network Intrusion Detection: An Empirical Study,
S. Bhattacharya, A. Khanna, S. Ganapaneni, and M. Najana, “Attention- Based Deep Learning Frameworks for Network Intrusion Detection: An Empirical Study,” International Journal of Global Innovations and Solutions (IJGIS), 2024
2024
-
[39]
Network Intrusion Detection Method Based on CNN-BiLSTM-Attention Model,
W. Dai, X. Li, W. Ji, and S. He, “Network Intrusion Detection Method Based on CNN-BiLSTM-Attention Model,” IEEE Access , vol. 12, pp. 53 099–53 111, 2024
2024
-
[40]
A Temporal Convolutional Network-Based Approach for Network Intrusion Detec- tion,
R. Nazre, R. Budke, O. Oak, S. Sawant, and A. Joshi, “A Temporal Convolutional Network-Based Approach for Network Intrusion Detec- tion,” in IEEE International Conference on Integrated Intelligence and Communication Systems (ICIICS) , Nov. 2024, p. 1–6
2024
-
[41]
FlowTransformer: A Transformer Framework for Flow-based Network Intrusion Detection Systems,
L. D. Manocchio, S. Layeghy, W. W. Lo, G. K. Kulatilleke, M. Sarhan, and M. Portmann, “FlowTransformer: A Transformer Framework for Flow-based Network Intrusion Detection Systems,” Expert Systems with Applications, vol. 241, May 2024
2024
-
[42]
Real- time Network Intrusion Detection via Decision Transformers,
J. Chen, H. Zhou, Y . Mei, G. Adam, N. D. Bastian, and T. Lan, “Real- time Network Intrusion Detection via Decision Transformers,” 2023, arXiv:2312.07696
2023 arXiv
-
[43]
Open RAN Security: Challenges and opportunities,
M. Liyanage, A. Braeken, S. Shahabuddin, and P. Ranaweera, “Open RAN Security: Challenges and opportunities,” Journal of Network and Computer Applications, vol. 214, p. 103621, 2023
2023
-
[44]
Intrusion Detection in 5G and Wi-Fi Networks: A Survey of Current Methods, Challenges, and Perspectives,
C. Hamroun, A. Fladenmuller, M. Pariente, and G. Pujolle, “Intrusion Detection in 5G and Wi-Fi Networks: A Survey of Current Methods, Challenges, and Perspectives,” IEEE Access, vol. 13, pp. 40 950–40 976, 2025
2025
-
[45]
A Survey for Intrusion Detection Systems in Open RAN,
E. N. Amachaghi, M. Shojafar, C. H. Foh, and K. Moessner, “A Survey for Intrusion Detection Systems in Open RAN,” IEEE Access, vol. 12, pp. 88 146–88 173, 2024
2024
-
[46]
Machine Learning-Based Early Attack Detection Using Open RAN Intelligent Controller,
B. M. Xavier, M. Dzaferagic, D. Collins, G. Comarela, M. Martinello, and M. Ruffini, “Machine Learning-Based Early Attack Detection Using Open RAN Intelligent Controller,” in IEEE International Conference on Communications (ICC), 2023, pp. 1856–1861
2023
-
[47]
An Efficient Intrusion Detection Solution for Near-Real-Time Open- RAN,
E. Amachaghi, S. A. Age, S. Chatzimiltis, M. Shojafar, and C. H. Foh, “An Efficient Intrusion Detection Solution for Near-Real-Time Open- RAN,” in IEEE Symposium on Computers and Communication (ISCC) , 2024
2024
-
[48]
Advancing O-RAN Security: Integrated Intrusion Detection and Secure Slicing xApps,
M. Kouchaki, J. Moore, M. Zhang, and V . Marojevic, “Advancing O-RAN Security: Integrated Intrusion Detection and Secure Slicing xApps,” in IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), 2024, pp. 1–2
2024
-
[49]
DDoS Detection and Mitigation Using d/xApp in O-RAN,
S. A. Soleymani, M. Eslamnejad, H. Alimohammadi, A. Akbas, C. H. Foh, and M. Shojafar, “DDoS Detection and Mitigation Using d/xApp in O-RAN,” in IEEE Future Networks World Forum (FNWF), 2024, pp. 283–290
2024
-
[50]
Anomaly Detection for Mitigating xApp and E2 Interface Threats in O-RAN Near-RT RIC,
C.-F. Hung, C.-H. Tseng, and S.-M. Cheng, “Anomaly Detection for Mitigating xApp and E2 Interface Threats in O-RAN Near-RT RIC,” IEEE Open Journal of the Communications Society , vol. 6, pp. 1682– 1694, 2025
2025
-
[51]
Peer- to-Peer Federated Learning Based Anomaly Detection for Open Radio Access Networks,
D. Attanayaka, P. Porambage, M. Liyanage, and M. Ylianttila, “Peer- to-Peer Federated Learning Based Anomaly Detection for Open Radio Access Networks,” in IEEE International Conference on Communica- tions (ICC), 2023, pp. 5464–5470
2023
-
[52]
Federated Learning for Anomaly Detection in Open RAN: Security Architecture Within a Digital Twin,
Y . Rumesh, D. Attanayaka, P. Porambage, J. Pinola, J. Groen, and K. Chowdhury, “Federated Learning for Anomaly Detection in Open RAN: Security Architecture Within a Digital Twin,” in IEEE Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), 2024
2024
-
[53]
DDoS Attack Detection Using Unsuper- vised Federated Learning for 5G Networks and Beyond,
S. Sheikhi and P. Kostakos, “DDoS Attack Detection Using Unsuper- vised Federated Learning for 5G Networks and Beyond,” in IEEE Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), 2023, pp. 442–447
2023
-
[54]
SENTINEL: Self Protecting 5G Core Control Plane from DDoS Attacks for High Availability Service,
A. Chilukuri, S. Vittal, and A. A. Franklin, “SENTINEL: Self Protecting 5G Core Control Plane from DDoS Attacks for High Availability Service,” in 15th International Conference on COMmunication Systems & NETworkS (COMSNETS) , 2023, pp. 554–562
2023
-
[55]
Deep Learning-based DDoS- Attack Detection for Cyber–Physical System over 5G Network,
B. Hussain, Q. Du, B. Sun, and Z. Han, “Deep Learning-based DDoS- Attack Detection for Cyber–Physical System over 5G Network,” IEEE Transactions on Industrial Informatics , vol. 17, no. 2, pp. 860–870, 2020
2020
-
[56]
DeepSecure: Detection of Distributed Denial of Service Attacks on 5G Network Slicing—Deep Learning Approach,
N. A. E. Kuadey, G. T. Maale, T. Kwantwi, G. Sun, and G. Liu, “DeepSecure: Detection of Distributed Denial of Service Attacks on 5G Network Slicing—Deep Learning Approach,” IEEE Wireless Com- munications Letters, vol. 11, no. 3, pp. 488–492, 2022
2022
-
[57]
LSTM-Based Anomaly Detection of PFCP Signaling Attacks in 5G Networks,
R. Pell, M. Shojafar, and S. Moschoyiannis, “LSTM-Based Anomaly Detection of PFCP Signaling Attacks in 5G Networks,” IEEE Consumer Electronics Magazine, vol. 14, no. 1, pp. 56–64, 2024
2024
-
[58]
Early Network Intrusion Detection Enabled by Attention Mechanisms and RNNs,
T. E. T. Djaidja, B. Brik, S. Mohammed Senouci, A. Boualouache, and Y . Ghamri-Doudane, “Early Network Intrusion Detection Enabled by Attention Mechanisms and RNNs,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 7783–7793, 2024
2024
-
[59]
Explainable Intrusion Detection for Cyber Defences in the Internet of Things: Opportunities and Solutions,
N. Moustafa, N. Koroniotis, M. Keshk, A. Y . Zomaya, and Z. Tari, “Explainable Intrusion Detection for Cyber Defences in the Internet of Things: Opportunities and Solutions,” IEEE Communications Surveys & Tutorials, vol. 25, no. 3, pp. 1775–1807, 2023
2023
-
[60]
A Survey on XAI for 5G and Beyond Security: Technical Aspects, Challenges and Research Directions,
T. Senevirathna, V . La, S. Marchal, B. Siniarski, M. Liyanage, and S. Wang, “A Survey on XAI for 5G and Beyond Security: Technical Aspects, Challenges and Research Directions,” IEEE Communications Surveys and Tutorials, vol. 27, no. 2, pp. 941–973, 2025
2025
-
[61]
Large Language Model (LLM) for Telecommunications: A Comprehensive Survey on Principles, Key Techniques, and Opportunities,
H. Zhou, C. Hu, Y . Yuan, Y . Cui, Y . Jin, C. Chen, H. Wu, D. Yuan, L. Jiang, D. Wu, X. Liu, J. Zhang, X. Wang, and J. Liu, “Large Language Model (LLM) for Telecommunications: A Comprehensive Survey on Principles, Key Techniques, and Opportunities,” IEEE Communications Survey...
1955
-
[62]
Transformers and Large Language Models for Efficient Intrusion Detection Systems: A Comprehensive Survey,
H. Kheddar, “Transformers and Large Language Models for Efficient Intrusion Detection Systems: A Comprehensive Survey,” Information Fusion, vol. 124, p. 103347, 2025
2025
-
[63]
Generative AI and Large Language Models for Cyber Security: All Insights You Need,
M. A. Ferrag, F. Alwahedi, A. Battah, B. Cherif, A. Mechri, and N. Tihanyi, “Generative AI and Large Language Models for Cyber Security: All Insights You Need,” 2024, arXiv:2405.12750
2024 arXiv
-
[64]
Large Language Models for Cyber Security: A Systematic Literature Review,
H. Xu, S. Wang, N. Li, K. Wang, Y . Zhao, K. Chen, T. Yu, Y . Liu, and H. Wang, “Large Language Models for Cyber Security: A Systematic Literature Review,” 2025, arXiv:2405.04760
2025
-
[65]
Advancing Cyber- security with LLMs: A Comprehensive Review of Intrusion Detection Systems and Emerging Applications,
H. Djallel, M. A. Ferrag, B. Nadjette, and S. Hamid, “Advancing Cyber- security with LLMs: A Comprehensive Review of Intrusion Detection Systems and Emerging Applications,” in Proceedings of the Interna- tional Conference on Informatics and Applied Mathematics (IAM), 2024
2024
-
[66]
Robust Network Intrusion Detection Through Explainable Artificial Intelligence (XAI),
P. Barnard, N. Marchetti, and L. A. DaSilva, “Robust Network Intrusion Detection Through Explainable Artificial Intelligence (XAI),” IEEE Networking Letters, vol. 4, no. 3, pp. 167–171, 2022
2022
-
[67]
XAInomaly: Explainable and Inter- pretable Deep Contractive Autoencoder for O-RAN Traffic Anomaly Detection,
O. T. Basaran and F. Dressler, “XAInomaly: Explainable and Inter- pretable Deep Contractive Autoencoder for O-RAN Traffic Anomaly Detection,” 2025, arXiv:2502.09194
2025 arXiv
-
[68]
RAN Explainable Anomaly Prediction for 6G Networks,
P. Marantis, K. Ramantas, and C. Verikoukis, “RAN Explainable Anomaly Prediction for 6G Networks,” in IEEE 29th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD) , 2024
2024
-
[69]
SpotLight: Accurate, Explainable and Efficient Anomaly Detection for Open RAN,
C. Sun, U. Pawar, M. Khoja, X. Foukas, M. K. Marina, and B. Radunovic, “SpotLight: Accurate, Explainable and Efficient Anomaly Detection for Open RAN,” ser. ACM MobiCom, 2024, p. 923–937
2024
-
[70]
Explainable Artificial Intelligence (XAI) to Enhance Trust Management in Intrusion Detection Systems using Decision Tree Model,
B. Mahbooba, M. Timilsina, R. Sahal, and M. Serrano, “Explainable Artificial Intelligence (XAI) to Enhance Trust Management in Intrusion Detection Systems using Decision Tree Model,” Complexity, vol. 2021, no. 1, p. 6634811, 2021
2021
-
[71]
Explainable AI for Intrusion Detection Systems: LIME and SHAP Applicability on Multi-Layer Perceptron,
D. Gaspar, P. Silva, and C. Silva, “Explainable AI for Intrusion Detection Systems: LIME and SHAP Applicability on Multi-Layer Perceptron,” IEEE Access, vol. 12, pp. 30 164–30 175, 2024
2024
-
[72]
Explainable AI and Random Forest based Reliable Intrusion Detection System,
S. Wali, Y . A. Farrukh, and I. Khan, “Explainable AI and Random Forest based Reliable Intrusion Detection System,” Computers & Security, vol. 157, p. 104542, 2025
2025
-
[73]
Harnessing the Advanced Capabilities of LLM for Adaptive Intrusion Detection Systems,
O. G. Lira, A. Marroquin, and M. A. To, “Harnessing the Advanced Capabilities of LLM for Adaptive Intrusion Detection Systems,” in Advanced Information Networking and Applications, 2024, pp. 453–464
2024
-
[74]
Finetuning Large Language Models for Vulnerability Detection,
A. Shestov, R. Levichev, R. Mussabayev, E. Maslov, A. Cheshkov, and P. Zadorozhny, “Finetuning Large Language Models for Vulnerability Detection,” 2024, arXiv:2401.17010
2024 arXiv
-
[75]
Intrusion Detection Technology Based on Large Language Models,
H. Lai, “Intrusion Detection Technology Based on Large Language Models,” in IEEE International Conference on Evolutionary Algorithms and Soft Computing Techniques (EASCT) , 2023, pp. 1–5
2023
-
[76]
Revolutionizing Cyber Threat Detec- tion with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices,
M. A. Ferrag, M. Ndhlovu, N. Tihanyi, L. C. Cordeiro, M. Debbah, T. Lestable, and N. S. Thandi, “Revolutionizing Cyber Threat Detec- tion with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices,” 2024, arXiv:2306.14263
2024 arXiv
-
[77]
Inte- grated LLM-Based Intrusion Detection with Secure Slicing xApp for Securing O-RAN-Enabled Wireless Network Deployments,
J. Moore, A. S. Abdalla, P. Khanal, and V . Marojevic, “Inte- grated LLM-Based Intrusion Detection with Secure Slicing xApp for Securing O-RAN-Enabled Wireless Network Deployments,” 2025, arXiv:2504.00341
2025 arXiv
-
[78]
Reasoning Beyond Limits: Advances and Open Problems for LLMs,
M. A. Ferrag, N. Tihanyi, and M. Debbah, “Reasoning Beyond Limits: Advances and Open Problems for LLMs,” 2025, arXiv:2503.22732
2025
-
[79]
6G-XSec: Explainable Edge Security for Emerging OpenRAN Archi- tectures,
H. Wen, P. Sharma, V . Yegneswaran, P. Porras, A. Gehani, and Z. Lin, “6G-XSec: Explainable Edge Security for Emerging OpenRAN Archi- tectures,” ser. HotNets, 2024, p. 77–85
2024
-
[80]
XAI for All: Can Large Language Models Simplify Explainable AI?
P. Mavrepis, G. Makridis, G. Fatouros, V . Koukos, M. M. Separdani, and D. Kyriazis, “XAI for All: Can Large Language Models Simplify Explainable AI?” 2024, arXiv:2401.13110
2024 arXiv
-
[81]
HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs),
T. Ali and P. Kostakos, “HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs),” 2023, arXiv:2309.16021
2023 arXiv
-
[82]
Large Language Models can Deliver Accurate and Interpretable Time Series Anomaly Detection,
J. Liu, C. Zhang, J. Qian, M. Ma, S. Qin, C. Bansal, Q. Lin, S. Rajmo- han, and D. Zhang, “Large Language Models can Deliver Accurate and Interpretable Time Series Anomaly Detection,” 2024, arXiv:2405.15370
2024 arXiv
-
[83]
ChatIDS: Explainable Cybersecurity Using Generative AI,
V . J ¨uttner, M. Grimmer, and E. Buchmann, “ChatIDS: Explainable Cybersecurity Using Generative AI,” 2023, arXiv:2306.14504
2023 arXiv
-
[84]
A Unified Approach to Interpreting Model Predictions,
S. M. Lundberg and S. I. Lee, “A Unified Approach to Interpreting Model Predictions,” in Advances in Neural Information Processing Systems, vol. 30, 2017
2017
-
[85]
”Why Should I Trust You?
M. T. Ribeiro, S. Singh, and C. Guestrin, “”Why Should I Trust You?” Explaining the Predictions of any Classifier,” in Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, 2016, pp. 1135–1144
2016
-
[86]
Large Language Models for Wireless Networks: An Overview from the Prompt Engineering Perspective,
H. Zhou, C. Hu, D. Yuan, Y . Yuan, D. Wu, X. Chen, H. Tabassum, and X. Liu, “Large Language Models for Wireless Networks: An Overview from the Prompt Engineering Perspective,” IEEE Wireless Communications, pp. 1–9, 2025
2025
-
[87]
Large Model Based Agents: State-of-the-Art, Cooperation Paradigms, Security and Privacy, and Future Trends,
Y . Wang, Y . Pan, Z. Su, Y . Deng, Q. Zhao, L. Du, T. H. Luan, J. Kang, and D. Niyato, “Large Model Based Agents: State-of-the-Art, Cooperation Paradigms, Security and Privacy, and Future Trends,” IEEE Communications Surveys & Tutorials , 2025
2025
-
[88]
NCSRD-DS-5GDDoS: 5G Radio and Core metrics containing sporadic DDoS attacks,
National Centre of Scientific Research ”Demokritos” and Space Hellas (Greece), “NCSRD-DS-5GDDoS: 5G Radio and Core metrics containing sporadic DDoS attacks,” Feb 2024. [Online]. Available: https://doi.org/10.5281/zenodo.10671494
2024 doi
-
[89]
User Terminals as Attackers: An Open Dataset Analysis of DDoS Attacks in 5G Networks,
M. Christopoulou, A. Garos, A. Vekraki, D. Santorinaios, I. Koufos, S. Karamitsiani, G. Xilouris, M.-A. Kourtis, G. Gardikis, and P. Trakadas, “User Terminals as Attackers: An Open Dataset Analysis of DDoS Attacks in 5G Networks,” in IEEE Conference on Standards for Communicat...
2024
-
[90]
Advancing Predictive Security for Con- sumer Applications in Beyond 5G/6G Networks With Annotated Datasets,
G. Xylouris, A. Vekraki, M. Christopoulou, M. A. Kourtis, E. K. Markakis, and P. Trakadas, “Advancing Predictive Security for Con- sumer Applications in Beyond 5G/6G Networks With Annotated Datasets,” IEEE Transactions on Consumer Electronics , 2025. Sotiris Chatzimiltis recei...
2025
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.