Pith. sign in

REVIEW 2 major objections 5 minor 16 references

AI/ML for 5G and Beyond Cybersecurity

T0 review · 2 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read AI/ML is 5G's primary defense and its newest attack surface.

desk verdict A readable but unsystematic survey whose central gap claim is contradicted by its own cited literature. read the letter →

arxiv 2505.18402 v1 pith:6Q6CTJFJ submitted 2025-05-23 cs.CR

classification cs.CR
keywords 5Gsecurity6GAI/MLcybersecurityintrusiondetectionNFV/SDNthreatsthreatlandscapetrustworthyAImachinelearningattacks
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This review argues that 5G and future 6G networks, by moving network functions into software (NFV and SDN), open a wider attack surface than previous generations. It maps that landscape—from DDoS and signaling storms to threats aimed at the machine-learning components themselves—and reviews how AI/ML is used for defense, especially in intrusion detection. Its central point is that most existing surveys judge AI/ML security models by accuracy alone and overlook accountability and trustworthiness. The paper concludes that 6G security must become transparent, holistic (security plus privacy plus trust), and adaptive, with online learning and explainable AI as key tools.

What carries the argument

The organizing device is a layered map of where ML sits in a 5G/beyond network (physical, middle, application) paired with a threat taxonomy for ML components—denial of service, denial of detection, unfair resource use, and data leakage. This map lets the paper connect general 5G threats to ML-specific ones, and to structure the review of intrusion detection methods by data type (packet, flow, session) and learning paradigm (supervised, unsupervised). It is what turns a list of attacks into an argument that security and ML security cannot be separated.

What would settle it

A falsifier would be a peer-reviewed 5G/6G security survey published before 2023 that already centers on accountability, explainability, and trustworthiness of AI/ML decisions; finding even one would weaken the paper's gap analysis. Alternatively, a demonstration that a deployed 5G intrusion detection system has no ML-specific vulnerabilities would undermine the double-edged claim.

Watch

Extended reading notes

Core claim

The paper's central claim is that AI/ML in 5G and beyond is double-edged: it is the most promising tool for defending virtualized networks, yet each ML component adds its own vulnerabilities—denial of service, denial of detection, unfair resource use, and sensitive data leakage—so that the security of the network and the security of the ML models become inseparable. It further claims that the existing survey literature concentrates on model performance and accuracy, leaving the accountability and trustworthiness of automated security decisions underexplored. If this is right, the next generation of 6G security research should shift from benchmark accuracy to transparent, explainable, adaptive, and privacy-preserving AI/ML systems.

Load-bearing premise

The load-bearing premise is that the set of surveys and reports gathered through 2022 is representative enough to support the claim that existing AI/ML security research overlooks accountability and trustworthiness.

Editorial extensions

If this is right

  • 6G security design should treat the ML model itself as part of the attack surface, not only as the defense.
  • Intrusion detection for 5G and beyond will need online, adaptive learning rather than static labeled datasets to keep pace with evolving attacks.
  • Evaluation of 6G security solutions should include transparency and accountability metrics, not just detection accuracy.
  • Practical deployment will require safeguards such as data cleaning, regularization, differential privacy, and strict control of model outputs.
  • Quantum machine learning is proposed as a direction for predicting 6G vulnerabilities and building adaptive defenses.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the paper's gap analysis is correct, a natural next step is a benchmark that scores 6G security frameworks on explainability and accountability alongside accuracy.
  • The paper leaves implicit that 'denial of detection' attacks target the security system itself; future work could model such threats as an adversarial game between the defender's ML and an attacker who knows the ML.
  • The call for online learning implies a tradeoff between adaptivity and stability in 5G/beyond security that the survey does not quantify.
  • Because the review covers literature through 2022, a reader could test its central claim by checking whether later surveys still overlook trustworthiness.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The manuscript is a survey of cybersecurity challenges and AI/ML opportunities for 5G and beyond (toward 6G) networks. It argues that softwarization and virtualization—NFV, SDN, VNFs, VMs—increase the attack surface; that AI/ML is essential for defense but also introduces new vulnerabilities such as data poisoning, model theft, and adversarial manipulation; and that most existing surveys focus on model performance and accuracy while overlooking accountability and trustworthiness. The paper reviews 5G threat taxonomies, 6G security challenges, ML components in 5G networks, and ML-based intrusion detection methods, and it closes with future directions emphasizing transparency, holistic security/privacy/trust, and adaptive defenses.

Significance. If its claims are accurate, the paper provides a useful accessible map of the 5G/6G AI/ML security landscape, drawing on ENISA reports and key academic surveys. Its descriptive core—that virtualization expands the attack surface and that AI/ML is both a defense and a threat source—is adequately supported by the cited sources. The paper also gives a clear taxonomy of ML components and of ML-based intrusion detection categories (packet-, flow-, and session-based). However, the paper's main forward-looking contribution is its gap claim about prior surveys overlooking accountability and trustworthiness, and that claim is not established by the manuscript as written. No systematic methodology, coding, or inclusion criteria are provided, and some of the paper's own cited surveys appear to address trust and privacy directly. As a literature review, its value depends on the accuracy of its synthesis; the descriptive parts are credible, but the central gap analysis needs substantiation.

major comments (2)
  1. [Section 3.1 and Section 5] The claim that 'most of the existing surveys on AI/ML 5G and beyond security mainly focus on the performance of AI/ML models and their accuracy, but they often overlook the accountability and trustworthiness' is a comparative literature-gap claim, but the manuscript provides no methodology to support it—no search strategy, inclusion criteria, or coding of surveyed papers. Moreover, the paper itself cites surveys that explicitly place trust, privacy, and security at their center: Nguyen et al. 2021 ('Security and privacy for 6G'), Porambage et al. 2021-2 ('The Roadmap to 6G Security and Privacy'), Ylianttila et al. 2020 ('6G White Paper: Research Challenges for Trust, Security and Privacy'), and Siriwardhana et al. 2021 ('AI and 6G security'). These citations directly undermine the stated gap. Since this gap claim is the basis for the paper's future research directions, it must either be substantiated with a systematic review procedure or reformulated as a narrower, supported observation about a specific subset of the surveyed literature.
  2. [Section 1] The introduction states that the report 'aims to provide a comprehensive overview' based on studies published until the end of 2022, but no systematic methodology is described. The reference list appears to be an ad hoc selection rather than a reproducible corpus; no databases, search strings, inclusion/exclusion criteria, or screening counts are reported. Without this information, the reader cannot assess whether important surveys were missed, which directly affects the validity of the gap analysis in Sections 3.1 and 5. The authors should either add a methodology subsection describing the review process or soften 'comprehensive' to 'selected' or 'representative.'
minor comments (5)
  1. [References; Section 2.3] The citation [Shaik 2021] refers to a 2019 Black Hat publication (Shaik and Borgaonkar), and the text uses it to support a statement about 5G vulnerabilities; the year in the citation key and in the reference entry should be corrected to 2019.
  2. [References] The reference key [Pham 2020] is used for two different works: one on whale optimization for resource allocation and one on green 6G networks. This ambiguity makes it impossible to determine which source is actually cited in Sections 3.2 and 3.3.
  3. [References; Section 3] There are duplicate and inconsistent entries for the same Porambage works: [Pawani 2021] appears twice, and [Porambage 2021], [Porambage 2021-1], and [Porambage 2021-2] are not consistently distinguished. The reference list should be unified.
  4. [Abstract and Section 2.1] There are typographical and grammatical issues, such as 'ba sed' in the abstract, 'SDNs’ susceptible' in Section 2.1, and 'control pane threats' which should read 'control plane threats.'
  5. [Section 4.4] The statement that relying on open data is problematic because 'attackers can learn how models trained on these tend to work' is asserted without citation or elaboration; it should be supported by a reference or phrased as the authors' opinion.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: this is a literature review with no derivation chain, fitted parameters, or self-citation load-bearing argument.

full rationale

The paper is a survey/report on AI/ML for 5G and beyond cybersecurity. It contains no equations, no fitted parameters, no predictions derived from a model, and no uniqueness theorem. Its claims are supported by external sources such as ENISA reports and published academic surveys, not by definitions internal to the paper. The only potentially contestable assertion is the comparative literature-gap claim in Section 5 that 'most of the existing surveys on AI/ML 5G and beyond security mainly focus on the performance of AI/ML models and their accuracy, they often overlook the accountability and trustworthiness of the models' decisions.' This claim may be under-supported or contradicted by some of the paper's own cited surveys, but that is a correctness/coverage issue, not circularity: the claim is not built into the paper's definitions or derived from the same data it purports to assess. The paper also does not rely on a self-citation chain to justify its central premises; the authors cite external work throughout. Accordingly, none of the seven circularity failure modes apply, and the honest finding is no significant circularity with score 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

No free parameters or invented entities appear because the paper is a review with no derivation. The central claims rest on the accuracy and representativeness of cited prior work and on the assumed 5G and 6G architecture.

assumptions (3)
  • domain assumption Cited ENISA, ETSI, and academic sources accurately describe the 5G and beyond threat landscape.
    The paper's taxonomies and vulnerability lists in Sections 2.2 and 2.3 are adopted from these sources without independent validation.
  • domain assumption AI/ML components will be embedded in all layers of 5G and beyond networks as described by Kaur et al.
    Section 4.1 uses this layered model to structure the discussion of ML threats; if the architecture assumption is wrong, the threat enumeration is incomplete.
  • domain assumption The selection of literature through the end of 2022 is representative of the field.
    The 'comprehensive overview' claim in Section 1 depends on the representativeness of the unsystematic citation list.

how reviews work

0 comments
Cite this review

Pith. "Pith review of AI/ML for 5G and Beyond Cybersecurity." pith.science (2026). https://pith.science/paper/6Q6CTJFJ

@misc{pith2026250518402,
  author       = {Pith},
  title        = {Pith review of: AI/ML for 5G and Beyond Cybersecurity},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/6Q6CTJFJ}},
  note         = {Machine review of arXiv:2505.18402}
}
read the original abstract

The advancements in communication technology (5G and beyond) and global connectivity Internet of Things (IoT) also come with new security problems that will need to be addressed in the next few years. The threats and vulnerabilities introduced by AI/ML based 5G and beyond IoT systems need to be investigated to avoid the amplification of attack vectors on AI/ML. AI/ML techniques are playing a vital role in numerous applications of cybersecurity. Despite the ongoing success, there are significant challenges in ensuring the trustworthiness of AI/ML systems. However, further research is needed to define what is considered an AI/ML threat and how it differs from threats to traditional systems, as currently there is no common understanding of what constitutes an attack on AI/ML based systems, nor how it might be created, hosted and propagated [ETSI, 2020]. Therefore, there is a need for studying the AI/ML approach to ensure safe and secure development, deployment, and operation of AI/ML based 5G and beyond IoT systems. For 5G and beyond, it is essential to continuously monitor and analyze any changing environment in real-time to identify and reduce intentional and unintentional risks. In this study, we will review the role of the AI/ML technique for 5G and beyond security. Furthermore, we will provide our perspective for predicting and mitigating 5G and beyond security using AI/ML techniques.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

16 extracted references · 13 canonical work pages

  1. [1]

    The roadmap to 6G security and privacy

    [Afaq 2021] Afaq, A., Haider, N., Baig, M. Z., Khan, K. S., Imran, M., & Razzak, I. (2021). Machine learning for 5G security: Architecture, recent advances, and challenges. Ad Hoc Networks, 123, 102667. [Hussain 2021] Hussain, R., Hussain, F., Zeadally, S., & Lee, J. (2021). On the adequacy of 5G security for vehicular ad hoc networks. IEEE Communications...

  2. [5]

    Survey on 6G frontiers: Trends, applications, requirements, technologies and future research,

    [De 2021] C. de Alwis et al., “Survey on 6G frontiers: Trends, applications, requirements, technologies and future research,” IEEE Open J. Commun. Soc., vol. 2, pp. 836–886,

  3. [6]

    Security and privacy in 6G networks: New areas and new challenges

    [Ylianttila 2021] Ylianttila, M., Kantola, R., Gurtov, A., Mucchi, L., Oppermann, I., Yan, Z., ... & Röning, J. (2020). 6g white paper: Research challenges for trust, security and privacy. arXiv preprint arXiv:2004.11665. [Tang 2019] Tang, F, Y Kawamoto, N Kato and J Liu (2019). Future intelligent and securevehicular network toward 6G: Machine-learning ap...

  4. [7]

    [Xu 2022] Xu, C., Wu, H., Zhang, Y., Dai, S., Liu, H., & Tian, J. (2022). A real-time complex road AI perception based on 5G-V2X for smart city security. Wireless Communications and Mobile Computing,

  5. [9]

    6G Security Challenges and Potential Solutions,

    "6G Security Challenges and Potential Solutions," 2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), 2021, pp. 622-627, doi: 10.1109/EuCNC/6GSummit51104.2021.9482609. [Porambage 2021-2] Pawani Porambage et al

  6. [11]

    A survey: Distributed Machine Learning for 5G and beyond

    "A survey: Distributed Machine Learning for 5G and beyond." Computer Networks 207 (2022): 108820. [Kantola 2020] Kantola, Raimo. "Trust networking for beyond 5G and 6G." 2020 2nd 6G wireless summit (6G SUMMIT). IEEE,

  7. [792]

    https://doi.org/10.1007/978-981-16-4625-6_87 [Ioannou 2022] Ioannou, I., Christophorou, C., Vassiliou, V., & Pitsillides, A

    Springer, Singapore. https://doi.org/10.1007/978-981-16-4625-6_87 [Ioannou 2022] Ioannou, I., Christophorou, C., Vassiliou, V., & Pitsillides, A. (2022). A novel Distributed AI framework with ML for D2D communication in 5G/6G networks. Computer Networks, 211, 108987. [Yang 2022] Yang, T., Qin, M., Cheng, N., Xu, W., & Zhao, L. (2022). Liquid software-base...

  8. [1122]

    Security and privacy for 6G: A survey on prospective technologies and challenges

    https://doi.org/10.1109/OJCOMS.2021.3078081. [Nguyen 2021] Nguyen, Van-Linh, et al. "Security and privacy for 6G: A survey on prospective technologies and challenges." IEEE Communications Surveys & Tutorials 23.4 (2021): 2384-2428. [Nassef 2022] Nassef, Omar, et al

Show all 16 references
  1. [1701]

    A., Derdour, M., & Janicke, H

    [Ahmim 2019] Ahmim, A., Maglaras, L., Ferrag, M. A., Derdour, M., & Janicke, H. (2019, May). A novel hierarchical intrusion detection system based on decision tree and rules-based models. In 2019 15th International Conference on Distributed Computing in Sensor Systems (DCOSS) ...

  2. [2017]

    (1999, November)

    [Roesch 1999] Roesch, M. (1999, November). Snort: Lightweight intrusion detection for networks. In Lisa (Vol. 99, No. 1, pp. 229-238). [Goeschel 2016] Goeschel, K. (2016, March). Reducing false positives in intrusion detection systems using data-mining techniques utilizing sup...

  3. [2018]

    [Zeng 2019] Zeng, Y., Gu, H., Wei, W., & Guo, Y. (2019). $ Deep-Full-Range $: a deep learning-based network encrypted traffic classification and intrusion detection framework. IEEE Access, 7, 45182-45190. [Yu 2017] Yu, Y., Long, J., & Cai, Z. (2017). Network intrusion detectio...

  4. [2020]

    [Lavanya 2022] Lavanya, K.S., Nagajayanthi, B. (2022). A Survey: Beyond 5G Toward 6G — Network Security Issues, Thrust Areas and Challenges. In: Sivasubramanian, A., Shastry, P.N., Hong, P.C. (eds) Futuristic Communication and Network Technologies. VICFCNT

  5. [2021]

    Major Security Challenges in 5G Network

    [Hassan 2022] Khan, Abid Hasan, Abdullahi Hassan Yusuf, and Tahorima Benzear Lira. "Major Security Challenges in 5G Network", IEEE Access, pp.1-10, 2022 [Ijaz 2018] Ijaz Ahmad, Shahriar Shahabuddin, Tanesh Kumar, Jude Okwuibe, Andrei Gurtov, Mika Ylianttila, "Security for 5G a...

  6. [2022]

    Huang, W

    [Pham 2020] Pham T. Huang, W. Yang, J. Wu, J. Ma, X. Zhang, D. Zhang A survey on green 6g network: architecture and technologies IEEE Access, 7 (2019), pp. 175758-175768 [Hireche 2022] Hireche, O., Benzaïd, C., & Taleb, T. (2022). Deep data plane programming and AI for zero- t...

  7. [3819]

    5G Security Threat Assessment in Real Networks

    [Saha 2022] Saha, S., Priyoti, A. T., Sharma, A., & Haque, A. (2022, January). Towards an Optimal Feature Selection Method for AI -Based DDoS Detection System. In 2022 IEEE 19th Annual Consumer Communications & Networking Conference (CCNC) (pp. 425-428). IEEE. [Shaik 2021] Sha...

  8. [5524]

    Towards 6G wireless communication networks:Vision, enabling technologies, and new paradigm shifts,

    [Kim 2019] Kim, H.; Lee, J.; Lee, E.; Kim, Y. Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane. In Proceedings of the 2019 IEEE Symposium on Security & Privacy (SP), San Francisco, CA, USA, 19–23 May 2019 [Marco 2019] Marco Lourenço, Louis Marinos,...

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.