Full text
Contents lists available at ScienceDirect Computer Networks journal homepage: www.elsevier.com/locate/comnet Survey paper A survey on 5G private and B5G network threats and safeguarding AI-based security mechanisms through the layered analysis Saman Tariqa,∗ , Eva Rodriguez Lunaa, Xavier Masip Bruina, Rodrigo Diazb, Josep Martratb, Panagiotis Trakadasc aAdvanced Network Architectures Lab (CRAAX), Universitat Politècnica de Catalunya (UPC), Vilanova i la Geltru, 08800, Barcelona, Spain bEviden Research & Innovation, 08020, Barcelona, Spain cGeneral Department, National and Kapodistrian University of Athens, Psahna, 34400, Evia, Greece A R T I C L E I N F O Keywords: 5G private network 5G security B5G/6G networks B5G security Key-enabling technologies Physical technologies Threat classification Threat modeling Threat impact Security solutions AI/ML in B5G A B S T R A C T The fifth-generation (5G) mobile network has shifted the paradigm in connectivity, high-speed data transmission, ultra-low latency, ultra-high throughput, multisense transmission, and ultra-high reliability. Today, industries are increasingly adopting 5G private networks, which also handle sensitive data related to business information, trade secrets, and personal data. Attacks on 5G private networks can potentially result in losing a competitive advantage since different security threats and vulnerabilities progressively target these networks. The unique infrastructure of the 5G network architecture and key enabling technologies exposes them to various vulnerabilities that attackers can target to breach sensitive data, steal information, and disrupt critical systems. Therefore, paying special attention to the security issues of 5G private networks is essential. The advancement of future wireless technology came about because of the different and diverse nature of connected devices, in contrast to the previous generation of mobile networks. The B5G network provides support to open network platforms, open interfaces, and the integration of different key enabling technologies helps manage network services and deploy new services needed for diverse requirements. At the same time, it has increased the attack surface compared to previous-generation networks. Therefore, it is imperative to conduct a review that focuses on addressing and classifying the different emerging threats in the private 5G and B5G networks in a distinctive way. In this paper, we have adopted a layered architecture from an industrial use case of 5G private networks to identify and classify different threats in 5G private networks. The study also characterized and modeled the different threats using information on the type of attack, entry points, and impact of the attack on the architecture layer. Moreover, an analysis of key enablers in 5G private and B5G networks and information on security threats and cyber-attacks is also presented. To accommodate the emerging threats in next-generation wireless technology, we have classified and modeled the different threats in the B5G domain using the common involved layer, which includes perception, network, and application layers in Hexa-x E2E and 6G IoT-enabled architecture. Organizations and projects that do not actively engage in cutting-edge technologies will lose their competitive advantage in the evolving technological landscape. This study has mapped the identified threat categories with different types of threats that could occur at different layers and assessed the entry points of the attacker. We have also identified the attack’s impact at each layer using security requirements related to confidentiality, availability, and integrity. Furthermore, this study reviews different AI-enabled solutions that can add value in preserving the security of 5G and B5G networks. Through this review analysis, we can conclude that the layered approach is quite beneficial in identifying the different threats and what security solutions can be offered to mitigate them. ∗Corresponding author. E-mail address: [email protected] (S. Tariq). https://doi.org/10.1016/j.comnet.2025.111594 Received 1 August 2024; Received in revised form 27 July 2025; Accepted 28 July 2025 Computer Networks 271 (2025) 111594 Available online 18 August 2025 1389-1286/© 2025 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ ).
S. Tariq et al. 1. Introduction 1.1. General context The 5G (Fifth Generation) networks play a vital role in mobile communication technology, ensuring high bandwidth and ultra-low latency. Initially, 5G architecture (Third Generation Partnership Project (3GPP) Rel-15) was designed for public use, however, there was a growing interest in the deployment of 5G networks for private use as well, which was added in the second phase of the 5G networks (3GPP Rel-16 and beyond) [1,2]. Consequently, the network was categorized into two main types: public and private. The main difference between the two networks is that the public network is owned and operated for public use within a particular region. In contrast, the private network is operated for private use within a factory or organization’s premises. Both types of 5G networks support cutting-edge technologies, which use different key enabling technologies. These technologies introduce new security threats and attacks to the 5G infrastructure. Despite its advantages, the 3GPP introduces security features to the 5G architecture. To support new and diverse services such as cloud-native applications, edge computing, multiple-input-multiple-output (MIMO), and multi-access edge computing (MEC), there is a further increase in the attack surface for 5G applications [3]. The architecture of the 5G network provides various services, including eMBB (Enhanced Mobile Broadband), mMTC (massive Machine Type Communication), and URLLC (Ultra Reliability Low Latency Communication). With time, new applications are developing that require high data transmission rates, low latency, ultra-high throughput, multi-sense transmission, and ultra-high reliability. They are beyond the vision of 5G use cases and services [4]. The diversity of new devices and heterogeneity will be anticipated by the beyond 5G (B5G) technology, offering high data rates, low latency, high mobility, and ultra-high reliability [5]. The future wireless technology has not yet been launched. Therefore, no unified and standardized architecture has been defined for it. However, some current initiatives working on that, such as 5G-PPP (Fifth Generation Public Partnership Project) and a new program on SNS (Smart Network and Service) architecture working group (WG) [6] have been started. The 5G-PPP is in the third phase, where many of its projects were launched and are currently underway. The key challenge of 5G-PPP is to protect European leadership from new and emerging threats. In addition, the integration of Internet of Things (IoT) networks with 5G and B5G technology has transformed the traditional industry and had a profound impact on connectivity. This integration has improved the user experience and redefined the interaction with the technology. However, the 5G and B5G network infrastructure is exposed to various threats and security risks [7]. The Emergence of IoT and edge computing in 5G and B5G has significantly increased the diversity and complexity of heterogeneous networks, making them vital for various applications. The openness and diverse characteristics of heterogeneous networks make them susceptible to various security threats and privacy attacks [8]. It also inherits the security attacks from the cloud computing environment. In contrast, a decentralized architecture and a diverse deployment environment raise security concerns to a new level. The list of attacks in a heterogeneous environment includes Denial-of-Service (DoS) attacks [9], malware propagation [10], and jamming attacks [11], which can affect system stability and data privacy. Providing a comprehensive analysis of all orchestration and management challenges is beyond this paper’s scope. However, the main focus of this survey is to examine different threats and attacks on private 5G and B5G networks, emphasizing the impact of security threats. Another aspect of security is to review various key enabling technologies in 5G private and B5G networks, which may be vulnerable to these threats. Threats in 5G and B5G networks encompass various aspects. The threats in 5G networks can arise from critical infrastructure and vulnerabilities in cloud computing and entry points in network architectures. Moreover, enabling technologies such as software-defined networking, edge computing, and virtualization can be targeted by virtual machine attacks, network slicing attacks, and edge-based attacks. For the first time, ENISA [12] has discussed the threats and vulnerabilities associated with the 5G-based system. Most of the studies are related to the threats of 5G public network attacks [13, 14]. Although some studies exist that have identified the threats in 5G private networks. However, no such study that comprehensively deals with the classification and modeling of threats in 5G-private and B5G-based networks has existed. It is also essential to see the different AI/ML solutions available in the existing state-of-the-art for detecting and predicting attacks in 5G and B5G networks. The cell structure in 5G and B5G networks represents a significant evolution in mobile communication systems, driven by enhanced performance, increased capacity, and novel applications. The cell structure is also susceptible to various attacks, including denial-of-service and unauthorized access. Moreover,5G networks introduce new features like massive MIMO and millimeter wave technology. B5G will enhance connectivity by adding new technologies and more complex architecture. Furthermore, the architecture of the B5G network needs to support the diverse nature of devices, and their applications rely upon the integration of artificial intelligence (AI) and the key technologies involved. This convergence and network heterogeneity increase the attack surface compared to the traditional mobile network, impacting the layer of the architecture and security requirements related to confidentiality, integrity, and availability. It is imperative to identify each attack distinctively and assess the impact of the attack. To the best of our knowledge, no such survey comprehensively identifies the occurrence of attacks concerning the layers of the architecture, or it is limited to specific key-enabling technologies and physical technologies. The main challenges addressed in this survey are presented below. •5G introduces new features like massive multiple-input-multiple output (m-MIMO) and millimeter wave (mm-Wave) technologies; these technologies introduce security threats and risks [15]. The B5G network will further enhance connectivity by adding new technologies and more complex architecture [3]. Thus, raises the attack surface in comparison to traditional wireless technologies. •Edge computing supports 5G and B5G networks to achieve its objective by supporting eMBB, URLLC, and mMTC. Due to its utilization in key technologies including distributed architecture, NFV, and wireless networks, edge computing and edge intelligence are susceptible to various security threats and attacks [16]. •New security threats and attacks are associated with the 5G and B5G/6G applications due to their open platform, open interface, and support of various cutting-edge technologies that leverage many important key enabling technologies [17]. Inspired by the taxonomies of different threats and the evaluation of security solutions with previous-generation mobile networks, this work provides a taxonomical view of different threats occurring at the different layers of the architecture to cope with the issues mentioned earlier. Our primary focus is to review the threats to the 5G private and B5G network, classify them, and model them concerning the layers of the architecture. Datasets are vital in training the ML models for anomaly detection models in 5G and B5G networks. Using classical and newly generated datasets for 5G and B5G-based networks provides a realistic simulation environment to test the security mechanism before deployment and develop predictive security models to identify future threats. The effectiveness of anomaly detection depends on the quality and diversity of the datasets used for model training and testing. Some notable 5G and B5G network datasets include CSE-CIC-IDS2018, CIC-DoS 2019, 5G NIDD, IoT-23, CIC-DoS 2019, BoT-IoT, and UNSW-NB15. This study briefly discusses the details of these classical datasets and why new datasets are needed for 5G and B5G networks. Moreover, this study provides an analysis of open-source software used for the development Computer Networks 271 (2025) 111594 2
S. Tariq et al. Fig. 1. Organizational structure of the survey. and testing of 5G infrastructure. Moreover, artificial intelligence (AI) plays a vital role in detecting and mitigating attacks and preserving the privacy and security of future wireless technology. This study will also review the recent AI solutions that can aid in privacy-preserving and security solutions in 5G and B5G networks. More specifically, the review will address the following research questions: RQ-1: What are the known threats associated with 5G private networks? RQ-2: What are the known threats associated with the key technologies in B5G/6G networks? RQ-3: How does AI play as a potential solution in preserving the privacy and security of 5G and B5G-based networks? 1.2. Contribution In contrast to the traditional work on 5G and B5G technologies, this work provides a review of different threats in 5G private and B5G networks and the characterization and modeling of threats concerning the layers of the architecture. From the existing state-of-the-art, a baseline architecture is selected to model the attacks occurring at different layers of the architecture. This work adopted the generic distribution of these layers as a baseline to explain the various types of threats in 5G and B5G networks. The study has provided a list of key enabling technologies in 5G and B5G networks, along with the details of security risks to them. Moreover, an analysis of privacy-preserving AI solutions and a list of datasets adopted for detecting threats in 5G and B5G networks have been briefly presented. In light of the above, the main contribution of this survey can be summarized as follows. 1. This study provides an overview of existing research efforts to design and develop the architecture for the 5G and subsequent B5G networks. 2. We discuss the different types of cell structures in 5G and B5G networks, highlighting their advantages, disadvantages, and associated threats. 3. The study overviews key enabling technologies, open source platforms, and identifies the threats in 5G private and B5G networks/systems. 4. We adopt a 5G private network architecture based on the industrial case to characterize and model threats in the application, network, middle, and physical layers. We analyze the different types of threats, their impact, and entry points for the attacker. Moreover, an analysis of open-source software is also briefly presented. 5. We extend the layered modeling by utilizing the baseline layered architecture (6G-IoT enabled, Hexa-X E2E) to characterize and model threats into the perception, connection, and application layers, respectively. We analyze the different types of attacks, their impact, and the entry points for the attacker initiating the threats. 6. The study lists classical datasets and the need for new datasets to detect and prevent cyberattacks in 5G and B5G networks. 7. The study reviews different AI-based attacks and privacy and security solutions, through layered analysis, that can help preserve the privacy and security of 5G and B5G networks. 8. This study presents some helpful future research directions to boost the characterization and modeling of threats in 5G and B5G networks. 1.3. Scope and paper organization This survey aims to investigate the state of the art in 5G private and B5G network architectures, cell structures, security threats, and key enabling technologies, emphasizing characterizing and modeling the threats with the layers of the architecture. This study emphasizes using Artificial Intelligence (AI) as a key enabler to provide security and privacy to future wireless technology. The rest of the paper is organized as follows. Section 2 presents the role of different surveys and this survey’s position in the ongoing research activities in 5G and B5G networks. Section 3 presents an overview of threats in traditional cellular networks, the trend of industry and academia moving towards private 5G networks, and the necessity of doing security analysis in 5G private, B5G, and 6G networks are all covered in this section. In addition, the details about the different architectures and the ongoing research efforts for the 5G and B5G networks are presented in Section 4 and Section 5. This section also provides information about identifying, classifying, and modeling threats associated with the 5G and B5G networks. A list of classical datasets for detecting and identifying cyber attacks in 5G and B5G networks is provided in Section 6, along with a particular dataset created using 5G-related traffic. Section 7 discusses the role of AI as a threat vector and privacy-preserving and security solutions in 5G and B5G networks. Section 8 summarizes the paper by addressing the research questions and the limitations of this study. Finally, concluding remarks and prospective future trends are summarized in Section 9.1, 9.2 respectively. The organizational structure of this survey is illustrated in Fig. 1 Computer Networks 271 (2025) 111594 3
S. Tariq et al. 2. Related work and our survey position In 5G and B5G networks, the cell structure refers to the organization and distribution of a limited geographical area served by the base station. The 5G network is designed as a heterogeneous system, including different small cell types. The small cells have the same characteristics as base stations and are deployed in indoor and outdoor regions to provide high data rates and low latency. Different cell types include pico cells, femto cells, and micro cells [18]. The cell structure is utilized to ensure low latency, improve signal quality, and enhance the coverage and throughput of the network. Femto cells are preferred due to their easy installation. They minimize the latency and address the issues related to cell edge coverage [19]. They are preferred in indoor applications as they enhance the system throughput and SINR (signal-to-interference-plus-noise-ratio). However, they are affected by the location obstacle, causing multipath propagation which reduces the SINR and coverage area [20]. Femtocells are replaced by picocells; they are used indoors and outdoors to provide a coverage radius of up to 200 m. If it is greater than 200 m, these cells are replaced by microcells. In [21], a detailed comparison of pico, femto, and microcells was briefly presented along with their applicability in indoor and outdoor applications. The internet-of-thing (IoT) use cases must be supported by the 5G infrastructure, and a growing number of IoT applications are expected in the future. Additionally, the adoption of new use cases will impact communication technologies [22]. The essential technologies are deployed in cells to meet the aforementioned 5G needs. In his review of 5G networks, Hani Attar et al. [15] emphasized m-MIMO and mm-Wave as the two main technologies. mm-Wave technology, which provides more bandwidth and faster data rates, and m-MIMO [23], which employs a lot of antennas at the base station to boost the capacity and effectiveness of the wireless network. The 5G network must also provide availability anywhere and anytime. It is expected that the future networks will offer huge mobility, improved connectivity, increased coverage and throughputs, and high data rates, which are not possible to achieve with poor quality signals [24]. In the context of the B5G networks, small cells, including femtocells, picocells, and microcells, play a key role in enhancing the wireless communication network [33]. These cells particularly improve the data rates and improve the capacity of the network, particularly in populated dense areas [34]. While definitions of picocells and microcells vary throughout the wireless industry, femtocells differ from small cells in that they are private, link to the network via the internet, and provide better interior coverage for smaller areas. Despite inconsistency in the terminological definitions of picocells and microcells within the wireless sector, femtocells, which are categorically different from small cells, connect to the network via the internet, are private, and provide enhanced indoor signal coverage for smaller locations. Similar to Wi-Fi hotspots, small cells are often deployed in crowded places like stadiums [35] to improve the network capacity and coverage. In [36], the study has highlighted that the limited resource utilization and reliance on backhaul connections make the small cells susceptible to DDoS attacks. DDoS attacks on small cells severely degrade the network’s performance by flooding specific nodes. Another study [37] highlights the bandwidth spoofing attacks targeting the small cells on a 5G network. Macro cell is another cell structure that provides coverage and supports higher mobility. Macro cells are essential for maintaining connectivity as the user moves between the cells, a process known as handover mobility. To handle this issue, macro cells are often deployed alongside pico cells to improve the system throughput [38]. The macro cell’s high capacity and extensive coverage make it an attractive target for large-scale attacks. Macro cells can be overwhelmed by a DDoS attack, where the flood of malicious traffic targets the network infrastructure to degrade the network’s performance. In [37], a study has been conducted on a macro cell infrastructure where a DDoS attack can severely impact the performance and functionality of the network slices in 5G networks. Another study in [39] utilized a fully IP-based architecture of 5G networks that can be exploited by malicious actors to launch a DDoS attack over the internet, affecting the macro cell structure. These attacks impact the layer of the architecture and security requirements related to confidentiality, integrity, and availability. It is imperative to identify each attack distinctively, concerning the architecture layer, and assess the attack’s impact. Security and privacy are critical issues that 5G and B5G networks must address. Security and privacy issues increase as the number of users increases and data exchange increases, increasing the number of threats and security attacks [40]. The primary focus of this survey is on the two key areas: (i) security threats and attacks in 5G and B5G networks, and provide threat characterization and modeling, (ii) AI-based potential security solutions. To identify the first area, research encompasses threats in communication technologies, key-enabling technologies, application-based threats, and integrationrelated threats. The second important topic was how AI can stop and identify threats in 5G and B5G networks. Table 1 provides a complete overview of surveys reviewing the threats in 5G, B5G/6G based networks concerning key enabling communication, and physical technologies. Moreover, it also provides key points presented as follows: •Layered Threat Modeling: Indicate whether the review paper considers the identified threats across 5G or B5G specific architectural layers (such as device layer, service layer, edge layer, application layer, and slicing layer, etc.) or component level. •AI methodology used: Indicate and highlight the use of AI methodologies related to supervised/unsupervised machine learning (ML), deep learning (DL), federated learning (FL), etc., in the surveyed work. •Depth of security evaluation: Quantitatively describe how the paper analyzes threat, threat impact, defense mechanism, and other integration-related issues by categorizing them as low, moderate, and high. Moreover, Table 1 provides a quick overview of the recent work concerning the privacy and security of 5G and B5G networks. We have provided a brief description of the threats associated with the integration of AI/ML, IoT, IT (Information Technology), OT (Operational Technology), and IIoT (Industrial Internet of Things) with the 5G and B5G-based system. The article [25] examines the occurrence of different attacks in 5G and B5G networks, emphasizing the layer of the architecture and the consequences of an attack. In [27], the authors reviewed the security and privacy issues of B5G/6G networks in the physical, connection, and service layers. The aforementioned study also identifies new threat vectors and security issues in distributed environment settings. Moreover, integrating pervasive intelligence (AI/ML) with future wireless technology is also considered a threat to the B5G and 6G networks. The first analysis of security and privacy issues in B5G is presented in [41]. The study has highlighted the importance of physical layer protection, deep slicing networks, quantum computing, AI security, novel data protection mechanisms like differential privacy, distributed ledger technology, and the use of AI to mitigate and protect personal data in B5G networks. The study also elaborated on the B5G threats and possible solutions concerning the layer of architecture including the physical layer, connection layer, and application layer. Different surveys [28,29] have been conducted, focused on identifying the AI/ML and integration-based threats. Moreover, integrating IT, OT, IoT, and IIT with the B5G network poses different security threats and cyber risks, as reviewed in [31,32,42]. The list of attacks is as follows, (1) Network slice theft & misconfiguration, (2) Adversarial attack on DL process, (3) Unauthorized access to SDN controller, (4) MITM, (5) Insider threat, (6) Side channel attack, (7) Malware, Computer Networks 271 (2025) 111594 4
S. Tariq et al. Table 1 Comparison of existing related surveys. Ref Year Paper Mobile Threats in 5G and B5G Layered threat modeling AI methodology used Depth of security evaluation Key contribution Threat taxonomy Layer identification Threat impact Integration related threats [14] 2022 review 5G Public Networks ✓✓ ✓X✓ (Architectural layers + component level) X N/A The study has focused on the modeling of threats and adversary groups in 5G-based public networks [25] 2021 Survey B5G, 6G X ✓ ✓ ✓ ✓ (Architectural layers) ✓ (ML, DL, FL) Moderate The study has focused on the identification of threats and security flaws along with providing potential solutions [26] 2022 Survey 5G Private Networks ✓X✓X✓ (Component level) ✓ (ML, DL, RL) Low The study discusses the different security issues in 5G private network [27] 2022 Survey B5G, 6G ✓X X ✓ ✓ (Architectural layer) ✓ (DL, FL) Moderate (Particular privacy-related) The study has discussed the different privacy perspectives in B5G/6G networks [28] 2020 Survey B5G, 6G ✓X✓ ✓ X✓ (ML, DL, NN) High The survey discusses the ML-based privacy attack and link privacy issues with the type of attack [29] 2024 Survey B5G, 6G ✓X✓ ✓ ✓ ✓ (ML, DL) High The survey focused on the AI-based threats in B5G/6G networks [30] 2023 review B5G, 6G ✓X✓X X X Moderate The study has focused on the taxonomy of threats in B5G/6G communication using the CIA [31,32] 2019, 2021 Survey B5G, 6G X ✓X✓X✓ (ML, DL,FL) Low The study focuses on the threats associated with the integration of IT, OT, and IIT with the B5G/6G networks Our survey 2024 Survey Private 5G, B5G network ✓ ✓ ✓ ✓ ✓ (Architectural layers) ✓ (ML, DL, FL, LLMs) High Our study has focused on 5G private threats and B5G, and AI-enabled security solutions (8) IP/MAC spoofing, (9) User identity theft, (10) Malicious payload injection, (11) DoS/DDoS, (12)Zero-day, (13) Session hijacking, (14) Network/ host intrusion, (15) Sensor spoofing, (16) IMSI catching, (17) Phishing, (18) botnet, (19) Ransomware, (20) False data injection, (21) social Engineering, (22) Brute force and (23) Eavesdropping. The aforementioned research fails to define the specific details of an attack, which layer is affected by the occurrence of the attack, the impact of the attack, and the component being affected. A review has been conducted to identify threats in 5G public networks using a layered approach [14]. In a recent survey [26], authors highlighted the threats and security issues in 5G private networks. However, the study neither classifies nor models the various threats to the layers of the architecture nor provides any information about the entry points for the attacker. Another similar study identifies the different threats in B5G/6G communication [30]. The study classified the attacks using these five categories (confidentiality, availability, integrity, authentication, and access control parameters) and helped to understand and mitigate the security risks in communication systems. However, none of the single surveys has discussed comprehensively the characterization of threats in 5G private networks and B5G/6G networks. It is imperative to have a holistic view of the threat modeling approach that can incorporate the future wireless technology threats distinctly at different layers of the architecture while considering the respective technologies and components involved in each architecture layer. The layered approach for the architecture will be beneficial for the operator and developers to identify the specific attack on each layer, along with the fundamental protocols or technologies that impact the B5G application. A detailed discussion on the privacy issues in B5G and 6G networks is presented in [27]. However, limited attention is paid to the cyber threats and security challenges in 5G private and B5G networks. In this survey, we are more concerned with the information security threats in 5G and B5G networks, along with reviewing the different security and privacy mechanisms linked with using AI to mitigate cyber-attacks. 3. Overview of the threats In this section, we provide an overview of threats associated with the generation of mobile networks from 1G to 5 G. The 5G network is involved in various key technologies. The threats associated with the key technologies involved are also briefly presented. In the next section, we provide the role of 5G public, private, and B5G networks in industry. More specifically, why is there a need for a security analysis of the 5G private and beyond networks? 3.1. Previous generation threats The evolution of mobile networks has faced many challenges, focusing on security considerations. In the first generation (1G) to transfer the data, an analog modulation technique was used, which has two main dominant issues: the handover problem and a lack of security consideration. In the second generation (2G), network security is improved by authentication and encryption; however, this generation still has many vulnerabilities associated with one-way authentication and encryption. In 2000, the 3G was launched, covering up the previous generation’s authentication issue using two-way authentication, increasing transmission speed, and internet access. Moreover, 3G also includes authentication and key agreement (AKA) and 3GPP (Third Generation Partnership Project), which allows complete access to control security system, air interface security, and user authentication. Although the 3GPP has developed security protocols, vulnerabilities still exist related to the registration of mobile devices, base stations, and wireless access, including data leakage, Denial-of-service (DoS), and downgrade attacks [43]. Despite the advancement of 3G, there are privacy concerns and IP vulnerabilities. The 4G architecture is based on IPs and utilizes cryptographic algorithms and protocols to secure communications. However, the media access control layer (MAC) of the 4G architecture is vulnerable to various attacks and struggles to Computer Networks 271 (2025) 111594 5
S. Tariq et al. Table 2 Threads associated with the previous generation. Generation Architecture feature Attacks Attack impact 3G security Five essential features are included, Security for user domains, network domains, network access, applications, and visibility of security configuration. Eavesdropping, Impersonate attacks, Man-in-the-middle attacks (MITM), spoofing, and location exposure [43] Compromising integrity, unauthorized access to the data and services, and other AKA sniffing attacks [43] 4G security 4G architecture based on IP, uses different sets of new cryptographic algorithms, cryptographic graphic protocols, and integrity algorithms. Theft of Service, DoS, User ID theft, IP Address spoofing, and intrusion attacks, APT and DDoS affect the security of the system [44]. Compromise integrity, Unauthorized access to the data, Authentication issues MAC(media access control) layer security Attacks are related to the execution of wireless application DoS, eavesdropping, replay attack, and malware application attacks [44] Compromising the integrity of the data [44] 5G security It consists of three main components such as old thread, heterogeneous connected devices Softwarization, virtualization, and network slicing Most of the attacks target the SDN controller and cloud Unavailability of services, compromising integrity, confidentiality violation SDN threats involve centralizing network flow (a DoS attack), exposing API to unwanted software, and launching open flow [45] Potential attacks on network slicing are DoS, theft of information via compromised slices, resource depletion, injection, and impersonate based attacks [46] efficiently manage the large number of connected devices, leading to a degradation of the performance and reliability of the network [44]. Moreover, the MAC layer lacks the flexibility to support emerging technologies such as network slicing, edge computing, and dynamic spectrum allocation. Detailed information on threats associated with the previous generation and concerns and their respective impact is presented in Table 2. 5G networks enable numerous cutting-edge technologies that utilize critical supporting technologies such as Network Function Virtualization (NFV), Software-Defined Networking (SDN), Multi-Access Edge Computing (MEC), and Network Slicing (NC). Despite having the benefits of these aforementioned technologies they are susceptible to various cyberthreats. For example, the centralized control plane of SDN makes it susceptible to DoS and injection attacks, among other types of attacks, which compromises the system’s integrity [45]. Hypervisors are the key components in NFV environment. Exploiting the vulnerabilities in hypervisors leads to different security attacks, including unauthorized access to other virtual machines (VMs), Man-in-the-Middle, and other application programming interface (API) attacks. Moreover, in a 5Gbased system, the operator orchestrates and manages the network, tailored to the demands of applications within the 5G core network of the 3GPP 5G system. Potential attacks on network slicing are Denialof-service (DoS), information theft via the compromised slices, and resource depletion attacks. Other types of attacks associated with network slicing include traffic injection and impersonation-based attacks [46]. These attacks are mostly related to the increase of threat surface and inadequate isolation among the slices at different levels [47] 3.2. 5G public, private, and beyond 5G networks In contrast to public networks, private networks are typically owned and operated by the industry and academic institutions. Due to digitization, industries increasingly rely on public cloud storage to store data and streamline business processes [48]. However, a couple of issues make it challenging for the industry and academia to share their workload and data on the public cloud and follow their strict guidelines and policies. Security is one of the major issues among them. Other issues include the strict latency requirements to process the data and the difficulties while making the connection remotely. In a world where data breaches and cyber-attacks are common, industries must use their customized security policies and local storage for their data and workload, which is impossible with the traditional 5G public networks. Due to this shortcoming, 5G private networks are gaining more attention. Moreover, productivity and safety can be improved with a 5G private network without needing a mobile network operator [49]. A couple of research efforts have been made in defining the B5G network architecture; some current initiatives, including HEXA-X and 5G-PPP, already exist in the literature about their design, development, and architecture. It is expected that future wireless technology will adopt several concepts from the previous generation, including enabling technologies and providing services to the diverse use cases while supporting cross-domain integration [50]. At the same time, it increases the attack surface compared to traditional technologies. concluding that 5G and B5G infrastructure is exposed to various threats and security risks. Most of the studies in existing state-of-the-art are related to the threats on 5G public networks [13]. For example, ENISA [12] has discussed the characterization of threats and vulnerabilities associated with the 5G-based system. The high-level classification of attacks includes eavesdropping, accidents, failure/malfunctions, disasters, outages, and legal, physical, and abuse of asset-related attacks. In [51], the authors have established a three-dimensional threat taxonomy for identifying NFV threats in a 5G-based system. In the existing stateof-the-art, most of the studies are related to the threats of 5G public network attacks [13]. Another study mentioned in [14] has classified the different threats and modeled them in various layers of the architecture. The modeling approach also provided us with information on the threat, entry points, the impact of the attack, and what components are being affected in each layer. Although some studies highlight the security issues in 5G-based private networks [48,52]. The study in [48] Computer Networks 271 (2025) 111594 6
S. Tariq et al. discussed the private 5G networks in the context of security policies and mechanisms to secure communication. In [52], the author has discussed the 3GPP architecture and the security issues with 5G private networks. Moreover, a report [53], discussed the different types of attacks has been presented that could occur on private 5G networks. In the realm of B5G networks, a couple of studies has been conducted that identify the different attacks in B5G applications using various communication technologies [54]. For instance, multi-sensory XR applications involving the use of molecular communication, terahertz (THz) communication, and quantum communication (QC) technology are susceptible to different attacks, including access control attacks, malicious behavior, and exposure of data transmission. Another B5G application, connected robotics and autonomous systems (CRAS), is involved in the key technology of AI and visible light communication (VLC). The most problematic attacks on CRAS are related to data transmission, encryption, and malicious behavior. A partial contribution is made in [25] by identifying the attacks corresponding to the layer of the architecture and the consequences of the particular attack in 5G and B5G infrastructure. Moreover, the study provided the first analysis of the privacy and security challenges associated with future wireless technology. Although the studies mentioned above do provide threat analysis in 5G and B5G networks, they are either focused on 5G public network threats or privacy and security issues concerning the B5G networks. To the best of our knowledge, there is no such study existing in the existing literature that focuses on the classification and modeling of threats in 5G-based private networks. As highlighted previously, the architecture of the B5G network needs to support the diverse nature of devices, and its applications rely upon the integration of artificial intelligence (AI) and the key technologies involved. This convergence and network heterogeneity increase the attack surface as compared to the traditional mobile network. These attacks have an impact on the layer of the architecture and security requirements related to confidentiality, integrity, and availability. It is imperative to identify each attack distinctively and assess the impact of the attack. In other words, there is no such survey that comprehensively identifies the occurrence of attacks concerning the layers of the architecture, or it is limited to specific key-enabling technologies and communication technologies. 4. Private 5G layered architecture & enabling technologies In this section, we list some open-source initiatives and research efforts for creating a 5G private network. These initiatives include open-source RAN targeting the user equipment (UE) and open-source core. Additionally, we presented the details of different architectures proposed for the 5G private networks and the key enablers that make them possible, along with the details of security threats and attacks associated with them. Finally, we have provided the characterization and modeling of threats using a layered architecture. 4.1. Private 5G layered architecture According to the 3GPP specification, two basic architectures were proposed for the 5G private network, namely (i) standalone (SA) and (ii) Public network integrated. The 5G SA architecture is comprised of 5G New Radio (NR) and 5G core network (5GC). It supports the different services and use cases in 5G networks. The second type of architecture is built with a private network deployment done with the support of public networks. This deployment has lower customization, self-control, and security [48]. The use case of private networks includes industry 4.0, video streaming, healthcare, AR/VR and smart grid adopted from [55]. Different open-source software has been offered for building core and RAN solutions for 5G and B5G-based networks. The srsRAN (also known as SRS LTE) [56], OpenAirInterface (OAI) [57], and UERANSIM (UE and RAN simulator) [58] are open-source RAN software solutions used for the development, experiment, and deployment of 4G LTE and 5G NR mobile communication networks. These solutions provide support for 5G standalone (SA) and non-standalone (NSA) modes for the development process, to enable the interaction of UE with gNB without needing physical hardware. The srsRAN and UERANSIM can simulate and emulate essential 5G components such as UE and RAN, but their real-world implementation is limited because of integration challenges with existing infrastructure and compliance with regulatory standards. srsRAN works only with single-input-singleoutput (SISO), whereas, OAI supports single-input-single-output (SISO) and MIMO and offers better throughput under the same signal-tonoise-plus-interference (SNIR) conditions. Moreover, in contrast to their performance, srsRAN performs better in uplink and OAI performs better in downlink tasks. In short, srsRAN, OpenAirInterface (OAI), and UERANSIM [59] are open-source RAN software solutions used for the development, experimentation, and deployment of 4G LTE and 5G NR mobile communication networks. These open-source RAN solutions are extensively used in academia and research due to their accessibility and adherence to standard protocols. srsRAN and UERANSIM can simulate and emulate essential 5G components such as UE and RAN, but their real-world implementation is limited due to integration challenges with existing infrastructure and compliance with regulatory standards. Open5GS, OpenAI5GC, OpenAI5GS, and Free5GCore (5GC) [59] are prominent open-source software solutions developed to support 5G core network functionalities in line with 3GPP specifications. In [60], the study highlights that these 5G core platforms provide transparency for auditing and verification purposes. Real-world applications require strong capabilities and features not entirely developed in the aforementioned platforms. For instance, these tools follow the 3GPP specifications; they may not support the latest features and optimizations, such as Network Data Analytics Function (NWDAF), which is crucial for network automation and management. Moreover, the performance indicator can also significantly vary in these platforms. For example, Open5GS provides better latency support for the control plane procedures, whereas OAI outperforms in data throughput, and Free5GS has the lowest power consumption and can contribute significantly to specific applications. So organizations need to make a tradeoff to choose the right platform depending on their needs. Furthermore, there is a notable gap between the Free5GS and OpenAI deployment options, as the complexity of installation and configuration is relatively easier for Free5GS compared to OpenAI due to the lower accessibility to the documentation. M. Amini et al. [61] highlighted in their study that one of the significant security concerns with OAI 5G RAN is the interoperability and interaction with various 5G core network software. P. Linh et al. have highlighted in their research [59] that Open AI and free5GC both rely on Docker-compose files using single host deployment. If one container is compromised, the attacker gains access to the entire host or interferes with the other containers. This single-host deployment has also led to scalability issues and a lack of redundancy in distributed multi-node setups. Therefore, single-node deployments cannot be applied in a multi-node or cloud environment. The open nature of aforementioned platforms often allows for broader community auditing and transparency, which can enhance security through collaborative scrutiny. Most of the open-source 5G core and RAN offer a valuable platform in building testbeds for research, testing, and prototype purposes, and are not always deployed directly in commercial and production-grade systems. In summary, transitioning these open-source platforms from a testbed environment to a fully operational 5G environment requires extensive testing and validation, representing a resource-intensive task that these platforms may not adequately address. The main concept behind using a private architecture is to fulfill the need for a specific application. The idea of a private 5G network for industrial communication is based on network slice eMBB, mMTC, and URLLC applications. Network slicing is the key enabling technology Computer Networks 271 (2025) 111594 7
S. Tariq et al. Fig. 2. 5G private architecture based on industry [64]. used for the deployment of public networks integrated with private networks. Each slice is built to fulfill the specific network capability and characteristics of a particular use case. The slicing architecture [62] consists of 3 layers: the physical layer, the network slice instance layer, and the application layer, respectively. In which the network slicing layer is responsible for the creation of multiple virtual networks on a single physical infrastructure. Each slice supports specific application requirements [63]. For example, eMBB supports applications related to AR/VR and video streaming to support high bandwidth, mMTC supports many devices requiring high bandwidth and special services associated with MIMO, and URLLC is used to support autonomous vehicles and remote surgery. Slicing seems crucial for autonomous vehicles and remote surveys; these types of applications are deployed with the help of edge computing capabilities. Slicing architecture can be applied to intelligent transportation, smart homes, smart grids, and Industry 4.0. The slicing architecture [62] consists of 3 layers: the physical layer, the network slice instance layer, and the application layer, respectively. Each slice is constructed to satisfy a particular use case’s unique network capabilities and characteristics. Network slicing is the key enabling technology in 5G private networks, which deploys public networks integrated with the private network. To support the vertical industry or industry 4.0, the edge computing architecture [65] has been proposed. It consists of three layers: device layer, edge layer, and cloud application layer. More importantly, the edge layer provides time-sensitive services, and the cloud application layer obtains and processes massive data from the edge layer to make non-real-time decisions. The edge layer utilizes SDN and NFV; threats related to the enabling technologies also apply to the edge layer. The edge layer is susceptible to DoS, side-channel, and VM-based attacks. To address the RQ-1, we have looked into the existing literature to identify the known threats in 5G private networks, considering the layered approach of the architecture. The layered approach helps to identify the different threats impacting the 5G-based application. The range of these threats is from RAN to core risks, air interface attacks, Application program interface (API) exposure attacks, 5G core and automation, passive attacks, and connected devices attacks. To demonstrate these threats, we have adopted a private 5G network architecture [64] based on an industrial case of video streaming as shown in Fig. 2. The private network architecture consists of four layers, including the perception layer, network layer, middle layer, and application layer. The details of each layer are presented below. •Perception layer: This layer is responsible for managing and controlling end user devices, providing connectivity and communication to private networks. The devices can range from mobile phones, drones, IoT devices, sensor data, and autonomous vehicles to network access points. •Middle Layer: It is responsible for providing the application data interface for the exchange of services in accordance with the Open Systems Interconnection (OSI) model. This layer acts as a hub for collecting and analyzing the data collected from the perception layer. The layer also uses some AI-based analytics to get valuable insights from the data. •Network Layer: It is responsible for communicating between different system components. It utilizes a private 5G network to ensure high data rates and seamless connectivity for real-time data sharing with users and devices. •The application layer: It is responsible for providing various applications and services to the user. The services related to the 5G private network include augmented reality, smart grid, smart healthcare, video streaming, smart transportation, and others. It also provides content to the user in an interactive manner. 4.2. Threat vector and dimension In this section, we explicitly clarified the structure and foundation of the threat classification as shown in Fig. 3. The term taxonomy in our work refers to a structured and hierarchical classification of 5G private-related threats based on the impact of the attack. To characterize threats, a 5G private architecture is selected as a baseline based on an industrial video streaming case and models threats using the perception, middle, network, and application layers, respectively. This approach was adopted from the layered methodology presented by Farooqui et al. [14], who proposed a layered-based threat model for 5G systems, where threats are grouped under unique categorization by the architectural layer and technological domains. Different threats concerning the layers of the 5G private network architecture are presented below. •The perception layer encompasses the threats related to communication technologies, key enabling technologies, basestations, and devices, sensor data-related threats, and security attacks. The attack surface for the devices is extremely volatile, and most of the attacks associated with this layer are malware, botnets, DOS/DDoS, and spoofing attacks. •The middle layer involves AI-related tasks. The security threats and risks are involved with the use of AI/ML, which include data manipulation, data exfiltration, and injection-based attacks, where the attacker can alter the processed data, compromising the overall confidentiality and integrity of the system. •The network layer provides the connectivity to the core network function, and components to the basestation. Several threats and security risks associated with the core network functions are identified in [66]. Both the user and the control plane are affected by these attacks, which include DoS and spoofing attacks on Access and Mobility Management function (AMF) as well as User Plane Function (UPF). •The application layer provides services and an application interface to the users. The services are provided through an Application programmable Interface (API), and the threat faced by the services has an overlap with the modern internet-based applications. This layer encompasses security attacks such as unauthorized access and exploitation of application vulnerabilities. Attackers might try to take over streaming services or augmented reality features, disrupting the services and unauthorized content distribution. Computer Networks 271 (2025) 111594 8
S. Tariq et al. Fig. 3. Threat vector for 5G private networks. Fig. 4. Key enablers of 5G private networks. 4.3. Enabling technologies In this section, we have provided a list of key-enabling technologies that are possible with the private 5G network, including URLLC, private edge computing, Device-to-Device (D2D) communication, and network slicing. The overview of the key technology is presented in Fig. 4. Communication technologies such as MIMO and mm-Wave are also presented, along with information on threats and security attacks. and the communication technologies. The details of these threats are presented below. •URLLC: This is a key enabling technology in 5G private networks. URLLC utilizes short transmission intervals, spatial diversity, nonorthogonal multiple access (NOMA) base station densification, and Device-to-device (D2D) communication collectively to improve value, reliability, reduce latency, and increase the efficiency of 5G private networks. The most common attack on the URLLC is the DoS attack, which can disrupt the low-latency requirements, affecting the critical application [48]. •Private Edge Computing: An essential enabling technology for 5G private networks that are pushing data-intensive tasks towards the edge. It offers several advantages such as location awareness, real-time response, high mobility support, low bandwidth requirements, high throughput, and low latency. It also offers customized services for local demands and network configurations. Moreover, it offers an open radio network platform to facilitate storage as well as processing capabilities. Through the application programming interface (API), private edge computing facilitates distributed AI and cloud computing in 5G-based private networks [67]. The extension of cloud and its services to the edge of the cloud, also known as mobile edge computing (MEC). Therefore, MEC has a wide range of applications such as healthcare, connected vehicles, video analytics, virtual or augmented reality, smart communities, mobile big data analytics, and smart grid [68]. •Network Slicing: Network slicing plays a critical role in 5G private networks due to the varying quality of service (QoS) to support the diverse use cases. Time-Division-Multi-Access (TDMA) is used to allocate resources and to prevent interference. Due to virtual isolation instead of physical isolation in the slicing, side-channel attacks are the most prevalent threats in slicing 5G private networks [69]. This virtual isolation often includes logical and temporal separation. Network slicing, a developing technology with several key benefits for the deployment of 5G private networks, has still raised a number of research issues for the business and networking sector. •Interference Management: In the use of public and private networks in 5G private networks, interference can occur from multiple signal transmissions. This interference leads to a negative impact on the latency and the reliability of the network. Management of interference is linked to attacks, such as unauthorized attacks, leading to misdirection and data breaches. Moreover, sending a harmful signal to the device, causing rapid battery depletion, these attacks cause serious issues in mission-critical applications and IIoT devices [70]. •localization and tracking: Many 5G applications, such as autonomous vehicles or robots, rely on accurate positioning systems. Radio frequency (RF) based localization is critical in 5G private networks. The 5G new radio (NR) uses multiple antennas to make accurate positioning possible. Despite having the advantages of private networks, the attacker can exploit vulnerabilities to the localized system via spoofing and side-channel attacks, to deduce the device’s location [71]. •Massive multiple input multiple output (mMIMO): The m-MIMO technology supports a large number of antennas compared to 4G, which utilizes 4–8 antennas. Despite having the advantages, they are also associated with different security attacks and risks; among them, the signaling threat is the most common in m-MIMO technology. Moreover, using AI with the m-MIMO technology introduces adversarial attacks that exploit the vulnerabilities in the AI models, resulting in performance issues and impacting the integrity of the 5G network [72]. •Millimeter Wave (mm-Wave): Frequency bands signal in mm-wave technology can travel only over short distances, resulting in smaller coverage capacity than conventional frequency bands. The technology also suffers from signal attenuation and poor diffraction caused by channel conditions and path losses that ultimately deteriorate the signal quality. The poor diffraction makes it vulnerable to blocking an obstacle under line-of-sight (LoS) transmission. To overcome the challenges of mm-Wave, the study in [73] proposes to deploy the mm-Wave with the integration of small cell, MIMO, and beamforming to improve latency, coverage, and capacity. •Beamforming: This is another key technology that allows the radio wave to travel in a particular direction. The focus of radio wave transmission increases spectral efficiency and reduces interference while maintaining the simultaneous delivery of data from multiple antennas, leading to an increased data rate [74]. The effectiveness of beamforming is often hindered by the challenges encountered in acquiring the channel state information (CSI), which leads the adversary to intercept or eavesdrop on the communication. This results in compromising the integrity and reliability of the network operations. Computer Networks 271 (2025) 111594 9
S. Tariq et al. resources, improves flexibility in deploying the network slices, and facilitates the integration of diverse communication, sensing, and localization services. Despite having the benefits, NFV is vulnerable to various attacks, NFV managers are also susceptible to eavesdropping, flooding, side-channel attacks, and DDoS attacks [45]. B5G/6G Network slicing is categorized into intraslicing and inter-slicing attacks. In an intra-slicing application, the attacker and target belong to the same network slice. In contrast, in an inter-slicing application, the attacker and target belong to different slices [117]. However, unauthorized persons can take remote control access to sub-network functions, novel applications, and external communication interfaces to impose vulnerabilities in deep slicing, leading to jamming attacks, spoofing, and DoS/DDoS attacks [118]. In the context of AI native networks, slicing also faces many threats, such as misconfiguration of the slice, theft of the slice, and misuse of the slice, including AI-based attacks used for intelligent network management. •Edge computing: Integration of AI with 5G and B5G networks, also known as edge intelligence (EI). In B5G networks, moving the data processing tasks closer to the edge rather than to a central cloud is essential. The edge server collects data from nearby devices and shares it collaboratively with the ML models. However, the data is collected from multiple sources, and the outcome of the AI/ML model is highly data-dependent. EI is linked to different security attacks and risks. The most common attacks on them include MITM attacks and DDoS attacks [119]. •Distributed Networking: Distributed networking in B5G/6G refers to the network architecture that distributes the network functions and resources across a wide geographical area. Unlike traditional networking, where the processing is done at a central location, distributed networking decentralizes the network functions to improve scalability and reliability, reducing latency and dependency on centralized infrastructure. Automated and distributed services [120] introduce several attacks in the micro-granular layer. Particularly, automation has led to some privacy concerns due to incorporating a dense variety of 5 G applications. •AI Driven network Management: AI enhances network management, threat detection, and incident response automation and improves system security. At the same time, AI opens the doors for adversarial attacks that can manipulate anomaly detection models. Attackers can manipulate the AI models using poisoned data, leading to incorrect decision-making or bypassing security. Moreover, the attacker can use the reverse engineering AI to predict and evade the detection algorithm or mechanism. •Container-based virtualization: Plays a vital role in B5G/6G networks by enabling the efficient deployment and management of network functions and services. The attacker could exploit the vulnerability to the internal VM (virtual machine) switch used for the communication of two VMs, or use a direct attack by hacking the existing VM to use it as an intermediate port for the attacker’s vRAN/vCore. The impact of this type of attack will result from rooting, DoS, packet sniffing, and malicious code propagation to the side-channel attacks on vRAN/vCore within the virtualized system [100]. •Management and Orchestration: Mainly, two components are involved in M&O [121]: closed-loop automation and intent-based interface (IBI). Although these components enable the dynamic and adaptive control of network services and resources, several security attacks are associated with deploying management and orchestration. Security threats to closed-loop automation include DDoS, MITM, and Deception attacks. Moreover, an Intentbased interface (IBI) used for the deployment of B5G infrastructure is vulnerable to information exposure, undesirable configuration, and abnormal behavior attacks, leading to additional compromises and assaults on the security goals of the system. •Heterogeneous Cloud: Cloud transformation in B5G/6G is done using the concept ‘‘Het-Cloud’’ [90]. Het-cloud enabled the services in B5G/6G networks such as AI/ML processing, immersive experiences, edge computing, and other distributed computing tasks. The most common security issues related to heterogeneous cloud include: unauthorized access, violation of access control policies, data privacy breaches, insecure interfaces and APIs, malicious attacks, DoS attacks, and loss of data [122]. Heterogeneity is also linked to information leakage for the various 5G and B5G applications, including smart healthcare, where the risk is very high if sensitive information like patient records, treatment, and specifications are not adequately protected. A. Categorization of Security Threats: The first is to classify the identified threats under a single category to present the different threats on a baseline B5G/6G architecture. Fig. 10 (https://bit.ly/3IFHkEW accessed on 26 July 2025) classifies the threats into various categories, whereas Fig. 12 (https://bit.ly/3INJNNx accessed on 26 July 2025), maps the threats with the layers of the architecture. The detailed information about the characterization and modeling of identified attacks concerning the layers of the architecture is presented in Table 4. The description of each threat category is mentioned below. •RAN threats: In 5G and B5G networks, RAN faces various security threats in B5G networks due to the complex architecture and open interfaces. The security attacks include a rough basestation, a fake basestation, and a compromised UE. One common attack on RAN is the DoS (Denial of Service) attack, in which the attacker targets the radio resource control (RRC) to establish a flooding of traffic, leading to resource exhaustion and disruption of operations [130]. Moreover, the implementation of open RAN (O-RAN) interfaces has led to the introduction of vulnerabilities related to supply chain attacks. •Edge computing threats: It plays a vital role in a heterogeneous decentralized environment in B5G/6G. The decentralized infrastructure of MEC makes it vulnerable to various network attacks targeting the edge nodes, such as data tampering, unauthorized access attacks, DoS/DDoS, impersonation-based attacks, session hijacking, and disclosure of sensitive information. MEC relies on local processing, making it susceptible to interception if encryption and authentication are weak. Moreover, if the edge server is compromised, it could affect multiple users and applications. In [131], the authors highlight the edge learning vulnerabilities of the 6G-IoT systems, including backdoor attacks, adversarial attacks, poisoning attacks, evasion attacks, and many privacy-related attacks. •SDN/NFV exploitation attacks: In B5G-based networks, Softwaredefined Wide Area Networks (SD-WAN) are utilized and are considered vulnerable to various security attacks such as DoS or DDoS, MITM, ARP spoofing, and insider adversaries, which compromise communication between the SDN switches and controllers or overwhelm the flow table storage capacity [116]. •Slicing attacks: The concept of slicing in 5G and B5G networks increases the risks of inter-slice attacks, cross-slice attacks, and misconfiguration attacks. Inter-slice attacks are where an attacker in one slice tries to compromise the other slice. Cross-slice attacks mostly occur where the isolation mechanism is weak between the slices, and the attacker can exploit the vulnerabilities in one slice and attempt to compromise the other slice. Moreover, improper configuration can lead to security challenges, such as misconfiguration attacks [45]. •AI/ML-based attacks: Integration of AI/ML in 5G and B5G is linked with various attacks such as poisoning, evasion, adversarial, and other API based attacks [124]. The detailed information on these threats can be found in Section 7.1. Computer Networks 271 (2025) 111594 16
S. Tariq et al. Fig. 9. Key enablers of B5G/6G networks. •Molecular communication attacks: Molecular communication is a key technology utilized in 5G and B5G networks, and a couple of security attacks are associated with MC. In [132], the study discusses various types of threats at different levels of MC, including flooding attacks, jamming, and desynchronization. •Quantum communication attacks: It is a key technology that utilizes QKD to secure communication. The attacker can exploit the vulnerabilities in the QKD systems to launch side-channel and other unauthorized access-related attacks. In [133], the research has indicated how a signal photon detector can be exploited through radio frequency (RF) radiation, allowing the attacker to intercept the quantum key transmission from a distance. •Malicious Code/Software: Malicious code or software represents considerable risks to the B5G networks due to vulnerabilities generated by the rapid advancement in wireless communication systems. Integrating machine learning with the B5G networks aims to enhance the network’s performance but exposes vulnerability by using malware, spyware, and other ransomware-related attacks impacting the integrity of the users and unavailability and destruction of the services [100]. •Physical attack: Theft of random keys is a significant security concern in B5G/6G wireless communication. Random keys are essential for encryption and securing communication; their theft leads to manipulation and data breaches. [123]. •Signaling threats: The signaling threats/storms come from the vulnerabilities in the radio technologies such as mMIMO [125], In this type of attack, the attacker disrupts communication before the establishment of communication between the two entities and is involved in key management, authentication, link creation and registration by sending an additional signal, which will put a heavy load on the base station and thus results in interruption of servic •DoS/Jamming attack: In a DoS attack scenario, the attacker impersonates the network devices with their IP address and injects a forged service request to inject malicious traffic with a botnet to flood the legal services. A similar attack scenario has been presented in Fig. 11(c), where the attacker can make use of the botnets to generate a larger number of requests In this way the attacker has gained access to multiple devices that are part of the bot and controlling them to compromise the edge computing services. In [134], different types of jamming attacks are discussed, such as active, reactive, and proactive jamming. These jamming attacks also lead to DoS attacks. In the physical layer of the future wireless communication system, the jamming attack can be performed on mmWave and NOMA networks. Consider an attack scenario, where the communication happens between two legitimate users, Bob and Alice, as shown in Fig. 11(a). The transmission signal uses a specific frequency channel to transmit the information. The attacker can inject the radio frequency (same as Bob) to occupy the shared wireless channel. Such an aggressive injection can prevent legitimate users from using the wireless channel to communicate, also called active jamming [25]. •Eavesdropping: It takes place when a malicious node tries to listen to the communication between the authorized nodes. In [105], authors categorize eavesdropping into three main branches: active, passive, and potential eavesdropping. In active eavesdropping, the attacker intentionally introduces noise, jamming, and disseminates false data. Meanwhile, in passive eavesdropping, the attacker passively listens to the messages without taking action. In passive eavesdropping, the attacker is within close range of the authorized node and extracts the data from the channel without inferring the communication, leading to compromise of the key distribution [96]. In potential eavesdropping, the attacker behaves like an authorized user under specific circumstances. Device tracking and interception are also significant threats where the node position is available to a third party. Consider the scenario of passive eavesdropping; in this case, the internal eavesdropper is a legitimate NOMA cluster user with access to the same beam scope as presented in Fig. 11(b). Since the NOMA users shared the same frequency and power spectrum, the eavesdropper can wiretap by intercepting the communication meant for the other users in an identical cluster. In this way, the eavesdropper can exploit its position within the beam scope to capture and analyze the transmitted signals. •Spoofing attack: Spoofing attacks or pilot spoofing attacks [78] can occur when an attacker manipulates the signal, phase, amplitude, or timing to disrupt the channel estimation phase of the transmitter. In this type of attack, the attacker sends the spoofing signal or messages with the fake identities of other wireless devices, such as MAC address, IP address, and radio frequency identification (RFID) tags of the mobile users, Base station (BS), and access point (AP) to take the illegal advantages. A similar attack scenario is presented in Fig. 11(c), where a fake edge attacker impersonates the nearby edge device by sending it fake computational results, Computer Networks 271 (2025) 111594 17
S. Tariq et al. Fig. 10. Taxonomy of B5G Network threat categorization. Computer Networks 271 (2025) 111594 18
S. Tariq et al. Table 4 Categories of the B5G/6G threats mapped with layers. Attack category Physical layer Connection layer Application layer RAN Threats [76,123] Rough Basestaation Fake Basestation DoS/DDoS RAN NA Supply chain attack Edge Computing attacks [123] Data leakage Side channel attack, Spoofing attack Session Hijacking, DoS/DDoS on edge node Data leakage, unauthorized access, Disclosure of sensitive information. SDN/NFV exploitation attacks [116] Tampering SDN/NFV SDN controller attack, Compromised VNF, Rough VNF Malicious deployment of VNF, Unauthorized access Slicing attacks [45] Cross-slice attack Inter-slice attack, Misconfigured slice Cross-slice attack AI/ML based attacks [124] Poisoning attack Adversarial attacks, API-based attacks NA Poisoning attack Adversarial attacks, Evasion attack, API-based attacks Molecular communication attacks [123] Flooding/jamming Desynchronization NA Flooding/Jamming Quantum communication attacks [123] Quantum key interception Side-channel attack NA Side-Channel attack Malicious code /Software [100] Ransomware, botnet Malicious network function, injection attack, protocol exploitation attack Malware, spyware, Deepfake agent Physical attack [123] Theft of random or physical keys, Sabotage of network hardware NA N/A Signaling threat [125] Signaling threat, Signaling strom Protocol exploitation Signaling DoS Denial-of-service attack [96] Radio Jamming, Protocol-aware jamming, jamming attack (reactive /proactive/ pilot jamming), and Edge node overloaded Flooding, DoS/DDoS attacks, resource exhaustion, flooding base station, and energy depletion attack DoS, DoS against XR services, and flooding attack Eavesdropping [105] Eavesdropping (active, passive and potential eavesdropping), proactive eavesdropping, device tracking, and interception attack Eavesdropping, IP spoofing and data interception Misuse of security software and applications (Identity tracking, breach sensitive data personal data) phishing and social engineering attacks, API interception Spoofing attack [126] Signal spoofing, Sybil spoofing, and pilot spoofing attacks Host-based spoofing attacks, impersonation attacks, DNS spoofing, data injection, and packet modification Fake application server spoofing, false data injection, and identity spoofing attacks. Contamination attack [127] Pilot contamination and Feedback attacks False pilot signal injection N/A Manipulation of network configuration/ Data forging [128] Modify sensor information, injecting false data, stealthy attacks, meta-surface manipulation Network misconfiguration attacks, protocol manipulation, DNS manipulation, routing table manipulation, misconfiguration or poorly configured network/services Interception and modifying attacks, data positioning attack Unauthorized access [119] MITM, data leakage, injecting false data, location exposure, and erroneous information to the receiver Unauthorized access to base station MITM attack, Session hijacking, traffic sniffing, data breaches, data tampering, and insider attack Session hijacking, MITM, False data injection, deception attack, replay attack, and fake beacon messages create virtual traffic jams Hardware/Software Manipulation [129] Side channel attack, hardware manipulation, and compromised UE False or fake base station, false gateways Side channel attack and a rough access point (AP) attacker can access the data of the mobile users. •Contamination attack: A special type of attack in a B5G network where the attacker deliberately sends or injects false data into the network is called a contamination attack. A pilot contamination attack (PCA) is a specific threat to the 6G-IoT network in which the attacker transmits the identical pilot sequences as the legitimate user to disrupt user detection and channel estimation [127]. PCA primarily occurs on a physical layer of wireless communication systems, like m-MIMO or beam-forming systems. Ultramassive MIMO and Multi-user MIMO are more susceptible to PCA. In these systems, pilot signals are used for channel estimation and user identification, crucial for effectively transmitting the data. During the uplink process, the user (Bob) transmits the pilot signal to the base station, which uses this information to estimate the channel condition and direct the downlink beam toward Bob as presented in Fig. 11(d). An eavesdropper (Eve) manages to send Computer Networks 271 (2025) 111594 19
S. Tariq et al. fake signals (spoofing uplink signals) during the uplink process, causing the base station to think Eve is Bob. The Base station directs the downlink beam to Eve, allowing it to intercept the communication meant for Bob [25]. •Manipulate network configuration/Data forging: AI in B5G can lead to a significant concern for the forging attack, where the attacker maliciously alters the data to deceive the system or users. The data forging attack can target the large amount of data processed by the AI applications in the B5G network. These attacks can compromise the integrity and reliability of the information, affecting the quality of intelligent services like indoor positioning or autonomous vehicles in B5G networks [128]. A scenario presented in Fig. 11(e), where the attacker embedded the malicious content during the training phase of the model, leads to inaccurate prediction of the attack or incorrect decision making. •Unauthorized access: The most common attacks on the transmission status of communication channels include MITM, injecting false data, traffic sniffing, and data tampering attacks, which lead to data leakage [119]. In this attack type, the attacker eavesdrops on the transmission, intercepts the communication between the two legitimate parties, and injects the manipulated messages into the B5G system to the device or even controls the radio device. Consider the example of the MITM attack in the mmWave system presented in Fig. 11(c), where the attacker intercepts the messages of the transmitter, replaces and modifies the intercepted message with the fake one, and then sends it back to the receiver. •Hardware/Software Manipulation: Towards deploying the B5G/6G network, hardware manipulation threats become a significant concern. Threats related to hardware manipulation involve the intentional modification or sabotage of physical components in the network infrastructure, which can lead to serious security vulnerabilities. These vulnerabilities also facilitate side-channel attacks. As the technology progresses toward B5G, fake base stations still exist in the 6G network, posing a serious security threat as they collect user information and launch a DoS attack [129]. Hardware manipulation has an impact on user data and the integrity of the network. B. Threat’s impact: In the second step, we have presented different types of threats based on the specific impact of the attack on security requirements, including confidentiality, integrity, and availability (as shown in Fig. 13). Detailed information about the threats impacting security requirements related to confidentiality, integrity, and availability and their solutions in B5G is mentioned below. Confidentiality: is related to data confidentiality and privacy. Data confidentiality mainly helps fight against passive attacks, and privacy prevents unauthorized users from analyzing or influencing the data. Homomorphic encryption is expected to be a key technology for preserving data confidentiality and privacy in B5G networks [137]. Cryptographic schemes such as digital signatures and certificates can restrict unauthorized user access to secure data confidentiality. Quantum-safe cryptographic schemes can also be considered a prospective solution to secure communication in B5G/6G networks. Jamming and eavesdropping attacks nearly impact every B5G application. The result of eavesdropping compromises confidentiality through the data transmission on an unsecured channel. B5G/6G physical key generation is also used to protect the confidentiality of the communication between the UE and the base station from eavesdropping and jamming attacks. More specifically, m-MIMO leverages to mitigate both active and passive eavesdropping. Availability is defined as the service or resource that is accessible and usable to a user anywhere and anytime. It is a measure of how robust a service is against any attack. For example, DoS and DDoS are the most common attacks in B5G networks that violate the availability of the network. In the infrastructure layer, jamming attacks are also used to disrupt the communication capabilities of the network by overwhelming the interferences or by adding noise [96]. For this purpose, the attacker could transfer the radio signal continuously on the wireless channel to disrupt the communication by decreasing the signal-to-noise (SNR) radio. This leads to the DoS attack at the physical layer. With the increased number of connected devices and heterogeneity, it will be very difficult to fight against jamming and DoS attacks to maintain the availability of the B5G wireless network. Integrity: Currently, there is no such mechanism that can avoid duplication and modification of the message, even if the message authentication mechanism confirms the source of the message. The B5G network aims to provide the availability to the different applications integral to human life such as e-health monitoring, autonomous vehicles, and immersive augmented reality. Distributed ledger technology (DLT) is considered a prospective solution to preserve the confidentiality and integrity of the B5G networks [138]. The important aspect of security in these applications of B5G is related to data integrity. The integrity ensures that the attacker cannot edit, modify, or copy messages. C. Modeling of Threats: As highlighted previously we have a baseline layered architecture based on a B5G network. In the third step, we have provided the modeling of different types of threats identified in the previous step and modeled them with the adopted layered architecture. The modeling offers information about the various types of attacks, the entry points that can be used to launch the attack, the impact of an attack, and the respective layer involved in executing the threats, as shown in Table 5. 6. Overview of datasets In this section, we discuss the different anomaly detection datasets used to detect and predict attacks in 5G and B5G networks. In addition, we have provided a list of challenges that are possible with the classical datasets and need to have specific 5G-related datasets. 6.1. Classical dataset In the current state-of-the-art, different datasets are available for detecting and preventing cyber-attacks. Notable datasets include 5G NIDD, IoT-23, CSE-CIC-IDS2018, CIC-DoS 2019, BoT-IoT, and UNSWNB15. Among these, CSE-CIC-IDS2018 [139] and CIC-DoS 2019 [140] are the two prominent datasets in cybersecurity. CSE-CIC-IDS2018 is primarily used to train the machine learning model and evaluate the effectiveness of the intrusion detection system (IDS). In contrast, CIC-DoS 2019 is used in pattern recognition and anomaly detection. The wireless sensor network plays a crucial role in 5G networks, enabling applications such as smart cities, healthcare, and environmental monitoring. In the context of 5G WSNs, different public datasets have been listed in existing literature, including information about the network topology, sensor-related data, and other traffic patterns. WSNDS (wireless sensor network dataset) is a prominent dataset in WSN that has been utilized to detect intrusion. The authors in [141] utilized this dataset to detect jamming attacks in multi-stage attack scenarios. The study classified different jamming attacks into constant, random, deceptive, and reactive jamming. Another important dataset is BoTIoT [142], created to address the security challenges related to the IoT environment. This dataset includes normal and different cyberattack flows. The dataset contains 46 features and five types of classes, one for the normal flow and four for different attack types, including DoS, DDoS, surveillance, and information theft. IoT-23 [143] is a semi-structured dataset containing log information from malicious and benign IoT network traffic packets. The dataset was created by Avast AIC laboratory using different IoT devices. The dataset consists of real data and labeled instances of IoT malware infection, three captures for the benign IoT devices, and 20 captures for the malware traffic. CIC-IoT 23 [144] is another important dataset based on IoT traffic, developed by the Brunswick Center of cybersecurity. The dataset encompasses 33 distinct features and 46 attributes, organized into seven main classes. The dataset includes both normal as well as malicious traffic associated Computer Networks 271 (2025) 111594 20
S. Tariq et al. Fig. 11. Security threats in B5G/6G scenarios [25,135,136]. with 105 unique IoT devices. This type of variety can be linked with the heterogeneity of 5G and 6G networks. Furthermore, the dataset encapsulates the architecture of IoT networks and the various types of attacks, reflecting the complexities inherent in the 6G networks. Lastly, the Edge-IIoTset dataset [145] is a comprehensive cybersecurity dataset for IoT and IIoT applications. The data is generated from an IoT/IIoT testbed with a large representative set of devices, sensors, protocols, and cloud/edge configurations. Fourteen IoT and IIoT network attacks are identified and analyzed, categorized into five threats: DoS/DDoS attacks, information gathering, man-in-the-middle attacks, injection attacks, and malware attacks. Different studies mentioned in [146,147] have used these datasets (Edge IIoTset and IoT-23) for network traffic analysis, malware, and attack detection. The network traffic information can be extracted in a semi-structured file using Wireshark and tcpdump in .pcap files. NSL-KDD [148] is another dataset that can be used to detect anomalies in a 5G network. Similarly, UNSW-NB15 [149] dataset contains information on normal and attack traffic. The attacks contain generic, exploit, fuzzers, DoS, reconnaissance, analysis, backdoors, shell code, and worms. It includes 49 different features and it comprises more than 2 million records stored in different CSV format files. The authors in [150] utilized NSL-KDD and UNSW-NB15 datasets to detect anomalies. They have used deep learning approaches, such as CNN and the Bidirectional LSTM model, to classify normal traffic from attack traffic. UNSW-NB15 is a dataset based on TCP, UDP, and other protocols, whereas 5G NIDD [151] is a new dataset based on 5G network traffic records. 6.1.1. Challenges with classical datasets Devices in 5G do not require traditional IP-based data transfer, particularly for IoT applications. So, a non-IP data delivery-based dataset was required in 5G for several reasons. Moreover, existing literature lacks DoS/DDoS-related datasets, particularly related to 5G-based network slicing. In addition, 5 G-related cyberattacks (especially on 5G Computer Networks 271 (2025) 111594 21
S. Tariq et al. Fig. 12. Taxonomy of the B5G network threats mapped with layers. Fig. 13. Overview of threat’s impact with security requirements. Core) and the sensitive nature of such data are not publicly available. This section presents an overview of open-source software for developing and testing 5G networks. We have also highlighted the security challenges associated with their deployment and implementation. These open-source software are used for RAN and Core components in different projects and test beds for the development, experimentation, and deployment of 4G and 5G mobile networks. 6.2. 5G specific dataset This section presents a list of datasets used to detect abnormal network behavior and anomalies in 5G-based network slicing, Wi-Fi networks, and WLAN networks, which are presented below. The details of these newly created datasets have been presented in Table 6 for detecting and preventing cyber-attacks in 5G and beyond 5G networks. Computer Networks 271 (2025) 111594 22
S. Tariq et al. Table 5 Modeling of threats with threats impact, entry points, and the layer being involved. Attack category Attack types Impact Entry points Affected layer Denial-of-service attack Radio jamming [25] Availability (disrupt legitimate communication and Jamming of particular frequencies, jamming of communication channels) Communication channels, during RF transmitter and receiver Perception layer Jamming [97] No standardized protocol Protocol-aware jamming, reactive jamming [25] Open protocol, system broadcasting Application layer DoS/ DDoS, and flooding attack [96] Unavailability of resources and services Access points, wireless channels, wireless clients, wireless infrastructure, Open API access Perception layer DoS depletion attack [46] Disable a batterypowered device, Availability of batterypowered devices DNS server, storage area Application and perception layer Energy depletion attacks [46] Availability Weak authentication mechanism Connection layer Signaling threat Signaling storm [90] Confidentiality, Integrity, Availability Cloud, radio access network, and communication links Perception layer Signaling DoS [90] Availability (overload and disruption of services) Communication protocol Application layer Eavesdropping Active eavesdropping, Passive eavesdropping, & Potential eavesdropping [105] Privacy violation, availability (unavailability of services, disruption of legitimate communication), and confidentiality Communication channels, insecure wireless network, compromised network infrastructure, and broadcast method Perception, Connection, and Application Spoofing attack Pilot spoofing attack [114] Confidentiality (Information leakage during downlink transmission) integrity (compromising the legitimate communication) Communication channel Perception layer Signal spoofing [43] Disrupt and intercept the communication and manipulate the footage Server/network functions Perception layer Contamination attack Pilot contamination attack, Feedback attack [114] Confidentiality, integrity, Availability pilot signal transmission Perception layer Unauthorized access Side channel attack, Data tampering, Insider attack [119] Compromising confidentiality, Integrity, Authentication and authorization issues, and other related to privacy Core network, security software, storage area, network server Connection layer MITM attack, Information leakage API exposes, network access, misconfiguration, weak security mechanism Perception, Connection, and Application layer Impersonation, and biometric data leakage [119] Physical attack Unauthorized physical access to the base station, theft of key [123] Compromising integrity, availability (disruption of radio frequency signal) Exploiting communication protocol, weak authentication mechanism Perception, Connection layer Manipulation of network configuration DNS manipulation, Data tampering, Malicious network function registration, Exploitation of misconfigured data [128] Compromising integrity, availability (disruption of radio frequency signal) SD-WAN controller, Network functions, DNS servers, Network management & orchestrator Perception, Connection layer Malicious code Injection attacks, Malware, Spyware, Ransomware-related, and Botnet attacks [100] Compromising integrity, Disruption of services Storage server network functions Application layer Hardware Manipulation Side-channel attack, false gateway, fake base station, compromise UE [129] User data, integrity of the network Virtual machines, Network functions, SD-WAN controller, user devices Perception, Connection Application layer •AWID3 Dataset: is particularly developed for the anomaly detection task in wireless networks. The dataset contains both extracted features in the CSV format and the raw pcap files publicly available on the [152]. It categorizes the attack into four main categories. i) Attack specific to 802.11, ii) attack against the local node, iii) attack against an external node, and (iv) multi-layer attack. This dataset is also used in machine learning-based wireless intrusion detection systems to identify flooding, impersonation, and injection attacks in Wi-Fi networks. Additionally, the dataset includes several assaults common to IEEE 802.3 networks, making it suitable for attacks in both wireless and wired networks. This dataset can be used to evaluate intrusion detection systems (IDS) in the IEEE 802.1X extensible authentication protocol (EAP) environment. Uszko et al. [153] developed a methodology to detect attacks occurring in the 5G network using the AWID3 dataset to train and test the system. The authors use the rules-based and machine learning approaches to detect the known and emerging nature of the attacks. The proposed methodology consists of both the packet inspection and rules-based modules. The utilization of both rulebased detection and machine learning makes this architecture quite reliable for the detection of both known and unknown attacks occurring in the 5G infrastructure. Their research used the AWID3 dataset to train and test the system. Computer Networks 271 (2025) 111594 23
S. Tariq et al. Table 6 Datasets used as a benchmark experiment in the evaluation of 5G network/system. Dataset Attack category Attack type Targeted use case System AWID3 Wi-Fi attack Beacon Flood, DE authentication attacks Detection of anomalies 5G WLAN [153] Wi-Fi network Flooding attack, impersonation, and injection attack Detection of attack Online learning [154] 5GAD-2022 5G core network attack Reconnaissance, AMF Detection of network-based attack 5G Core [155] 5G NIDD IoT-related attack (Non-IP Data Delivery) Data leakage Detection of anomalies in NIDD NIDD for IoT [156] 5GC PFCP PFCP attack 4 types of PFCP-related traffic flood Detection of attacks on 5G core PFCP traffic 5G core [157] DoS/DDoS Attacks on 5G Network Slices 5G network slicing attack DoS/DDoS attacks on a specific slice Ensure the security of 5G network slicing 5G network slicing [39] NCSRD-DS-5GDDoS 5G-based DDoS attack DDoS, Botnets, and volume-based attacks Detection of DDoS in 5G network environment 5G core and network [158] •DoS/DDoS Attack Dataset: is a dataset created by injecting various benign and attack traffic (DoS/DDoS) into the network slices within a simulated 5G network slicing testbed environment. This dataset is publicly available on IEEE DataPort [159]. Open-source software, Free5GC and UERANSIM simulators were used to create network slices. Benign traffic includes network traces of ICMP ping, ACK scan, UDP scan, SYN scan, FIN, PUSH, and URG scan. While the DoS/ DDoS traffic was generated using the hping3 tool UDP flooding, TCP sync attack, TCP push, TCP fin, and TCP start to generate DOS/DDoS traffic. In [39], the authors utilized 11 features for the analysis, including flow duration, destination IP, source port, and more. A significant feature called ‘slice’ was also introduced to represent the specific network slice. By employing a bidirectional LSTM model, the author has classified normal traffic from malicious DoS traffic. The dataset can classify benign traffic from DoS/DDoS traffic. •5G-SliciNdd Dataset: is a more generic dataset covering the global 5G network traffic and covering different types of network behavior and anomalies (based on the slice types, e.g., eMBB, mMTC, URLLC), not just DDoS-related attack information. It is designed to provide a more comprehensive view of anomalies and intrusion detection in 5G network slicing and can be accessed on Figshare [160]. The study presented in [161] utilizes the 5G-SliciNdd dataset to obtain optimal feature selection for the detection of attacks to improve the classification efficiency of the model. •The 5GAD-2022 Attack Detection: is another publicly available dataset on the GitHub repository, that contains 5G network traffic, including both the normal traffic and malicious traffic. The data was generated in a simulated environment by using open-source software named UERANSIM and Free5Gcore [162]. The data includes IP and slice-specific traffic. Normal traffic is categorized into two types: data collected from one UE and data collected using two UEs. The malicious data is divided into ten different types of attacks, which fall under three main categories: reconnaissance, denial-of-service, and network reconfiguration. The primary focus of the dataset is the detection of anomalies in network slicing. •5G NIDD Dataset : has a focus on delivering non-IP data (IoT and low latency traffic) within a 5G environment. It is developed for the malware traffic across various network protocols in 5G. It was generated from the actual mobile devices rather than simulated traffic and can be downloaded from the IEEE DataPort [163]. The dataset includes both the normal and attack traffic, featuring 8 different types of attacks such as UDP flood, HTTP flood, slow rate DoS, TCP connect Scan, SYN scan, UDP scan, SYN flood, and ICMP. Malicious and other benign traffic is distributed throughout this dataset. This variety of segments provides comprehensive information to the researcher interested in network security and intrusion detection systems within 5G networks. This dataset is particularly useful for developing effective intrusion detection models and addressing the security challenges associated with diverse 5G network traffic profiles. •5GC PFCP: also known as intrusion detection dataset in which different cyber-attacks are emulated by using k3Y again, Packet Forwarding Control Protocol (PFCP) between the session management function (SMF) and user plane function (UPF). To generate this dataset, a testbed was created using twelve dockerized 5G functions emulated using open5GC and UERANSIM. The dataset is publicly available [157] and helps identify the vulnerabilities to the 5G core, particularly DoS attacks. The dataset includes network function virtualized gNodeB (gNB), and a cyberattack impersonating the maliciously instantiated SMF. The particular cyber-attacks include PFCP session establishment DoS attack, PFCP session Deletion DoS attack, PFCP session modification DoS attack (DROP apply action), and PFCP session modification DoS attack (DUPL apply action). The PFCP attacks were executed, and for each attack, PCAP files were maintained with the transmission control protocol (TCP)/Internet Protocol (IP) and network flow traffic and PFCP flow statistics. The TCP/IP network flow statistics were produced by using CICFlowMeter, and PFCP flow statistics were generated using a custom PFCP Flow Generator. The network data of each device and entity was captured by Tshark for each network function and radio element, respectively. The dataset can support the development of a detection system tailored to a 5 G-based system. •NCSRD-DS-5G DDoS: is another dataset obtained from a realworld 5G testbed, is specifically designed for the analysis of DDoS attacks, and is available in [158]. The dataset was created using 5Gtestbed aligned with 3GPP standards, capturing both the benign and attack traffic within the 5G network. The benign traffic includes normal activities like users engaging in streaming YouTube content, whereas the malicious users engage in performing Distributed Denial of Service (DDoS) attacks, specifically UDP floods facilitated by hping3. The dataset captures both the radio and core metrics information, including uplink/downlink Computer Networks 271 (2025) 111594 24
S. Tariq et al. bitrates, retransmission, and session establishment metrics of the 5G network. This dataset can be used to see how the DDoS attack can be mitigated in the 5G infrastructure. 7. AI/ML in 5G and B5G networks AI plays a critical role in 5G and B5G networks, not only in the design and optimization of protocols and operations, but also in the design of early detection of threats and anomalies. Integrating AI with the B5G network presents a double-edged nature, as it can also become a target of attacks and a potential solution for mitigating attacks. Unlike the traditional 5G networks, where security solutions across all devices and base stations are configured with universal settings for certain types of attacks, it is apparent that such an approach cannot be applied in B5G networks. Intrusion Detection Systems (IDS) have been extensively used, but it is demonstrated that they fail in the detection of complex attacks. Nowadays, 5G networks are utilized by different machine learning (ML) algorithms to achieve dynamic and robust security mechanisms [164,165] to overcome their limitations in the detection of complex and zero-day attacks. Initially, signature-based and anomaly-based detection systems made extensive use of classical ML techniques; however, they lack automatic feature engineering, have a low detection rate, and are not efficient in detecting small variants of existing attacks. The research has shifted toward deep learning (DL) based solutions due to the increasing complexity of hacking incidents, zero-day attacks, and unknown malware. Cybersecurity attacks on B5G networks are dynamic, polymorphic, and sophisticated, using previously unseen custom code, able to communicate with external command and control entities to update their functionality. To detect cyber-attacks in B5G networks, IDS utilized both the ML and DL models to achieve a higher detection rate [166]. Moreover, the distributed learning models, deep reinforcement learning (DRL) [167], and federated learning (FL) [168] have proven their ability to detect complex attacks and zero-day attacks in distributed environments. The FL-based solutions keep data in the user’s proximity compared to cloud-based centralized learning to enhance data privacy and location privacy. 7.1. AI as a threat vector in 5G and B5G networks In this subsection, we focus on the role of AI as a weapon and a target for the different threats against the infrastructure. More specifically, we elaborate on the following attacks on AI key areas: •Adversarial Machine learning (AML): We have highlighted how AI systems are particularly vulnerable to adversarial inputs that mislead the AI-based intrusion detection system (IDS). In the existing literature, three main attacks that target the AI system include (I) data positioning, (ii) algorithm positioning attack, and (iii) model positioning attack. The positioning attack aims to insert wrong-labeled data in the dataset or change the input objects to mislead the ML algorithm. Algorithm poisoning is done by influencing the distributed learning process of an algorithm by uploading a manipulated weight to the local learning model, and model poisoning is done by replacing the deployed model with a malicious one. Data positioning attacks are more challenging than the input objects are accessible in the outer environment, and the attacker can easily make intelligent settings to carry out their intention [124]. •Poisoning attacks: Influence the learning phase of an ML system, which leads the model to learn inaccurately. For example, data injection, data manipulation, and logic corruption are some of the poisoning attacks. Adding malicious content to the data during the training phase of the data results in an influence on the integrity of the model. More specifically, poisonous attacks involve the manipulation of data during the training phase to produce a biased or incorrect model. In [169], the author has utilized the label-flipped attack to generate a data poisoning attack and a stealthy model positioning method for a model poisoning attack. In [170], the author used a local model poisoning attack that manipulated the local model sent from the compromised worker device to the master device. •Evasion attacks: Defeat the learning models or disrupt the testing data by injecting faults into the data. These attacks also avoid the model during the inference phase using carefully designed adversarial examples [124]. •API-based attacks: Are mainly categorized into: (i) model inversion, (ii) model extraction, and (iii) membership attacks. From the output of the targeted machine learning pattern, training data are generated by model inversion (recovering training data). An attacker can request and attack the API of an ML model to obtain the result of predictions. Attacks reproduce identical models by extracting model parameters from them, also called model extraction (disclosing the architecture) and membership attacks (exploiting the model output) [171]. Model inversion attacks could also be a source of privacy violation in 5G and B5G-based networks. •Physical attacks: The infrastructure was aimed at interfering with communication, causing deliberate outages, and altering the communication and computer infrastructure to make decisions and process data. These physical attacks can shut down the entire AI system [124]. •Privacy Attack: AI system has the potential to analyze large amounts of data in conjunction with high-speed computers and automation, which is a privacy concern in 5G and B5G based systems [124]. •GenAI-enabled attacks: The malicious use of GenAI applications, particularly large language models (LLMs) and diffusion models, poses a significant threat in the realm of cybersecurity. These malicious applications and LLM models can create hyper-realistic deep fakes and impersonate content [172], which facilitate network spoofing, social engineering, and phishing attacks, enabling the deceptive tactics against the network operator and automated agents [173]. •Automation of cyber-attacks: Unlike the traditional cyber system, cyber-attacks based on LLMs are autonomous, scalable, stealthy, and faster. The LLMs can be exploited to automate the different stages of cyberattacks, including reconnaissance, discovery of vulnerability, and malware code generation. This ability enables to launch of the most sophisticated attacks on the critical network assets of B5G networks. Existing state-of-the-art tools like FraudGPT and WormGPT are the prime examples of how LLMs can be modified for the use of malicious purposes, thus enabling the creation of malware and facilitating the execution of complex cyberattacks [174]. 7.2. AI-enabled security solutions for 5G and B5G networks To address the Rq-3, we have provided a review of different supervised, unsupervised, and semi-supervised studies for anomaly detection in future wireless networks concerning the three layers of the architecture Apart from ML, the DL model can help various B5G technologies, including m-MIMO and beamforming. The DL methods can also provide big data security support to the B5G E2E system, which includes crosslayer optimization such as optimizing channel coding, synchronization, and estimations. Secure communication and random key generation are of utmost importance in the physical layer, also referred to as Physical Layer Security (PLS). The physical layer suffers from authentication issues due to the propagation of communication channel conditions, authentication issues, and interferences. Ken St. Germain and Frank Kragh [175] proposed a supervised deep-learning scheme for the security of the mobile physical layer using a recurrent neural network and CSI to Computer Networks 271 (2025) 111594 25
S. Tariq et al. [122] Fairoz Pasha, Jayapandian Natarajan, Research on secure workload execution scheme in heterogeneous cloud environment, Indones. J. Electr. Eng. Comput. Sci. 29 (2) (2023) 1047–1054. [123] Talha F Rahman, Aly Sabri Abdalla, Keith Powell, Walaa AlQwider, Vuk Marojevic, Network and physical layer attacks and countermeasures to AI-enabled 6G O-RAN, 2021, arXiv preprint arXiv:2106.02494. [124] Van-Tam Hoang, Yared Abera Ergu, Van-Linh Nguyen, Rong-Guey Chang, Security risks and countermeasures of adversarial attacks on AI-driven applications in 6G networks: A survey, J. Netw. Comput. Appl. (2024) 104031. [125] Qili Shen, Jun Wu, Jianhua Li, Xiaofei Zhang, Kuan Wang, Communication modeling for targeted delivery under Bio-DoS attack in 6G molecular networks, in: ICC 2021-IEEE International Conference on Communications, IEEE, 2021, pp. 1–6. [126] Jie Yang, Xinsheng Ji, Feihu Wang, Kaizhi Huang, Lin Guo, A novel pilot spoofing scheme via intelligent reflecting surface based on statistical CSI, IEEE Trans. Veh. Technol. 70 (12) (2021) 12847–12857. [127] Ning Wang, Weiwei Li, Amir Alipour-Fanid, Long Jiao, Monireh Dabaghchian, Kai Zeng, Pilot contamination attack detection for 5G mmwave grant-free IoT networks, IEEE Trans. Inf. Forensics Secur. 16 (2020) 658–670. [128] Weiwei Li, Zhou Su, Ruidong Li, Kuan Zhang, Yuntao Wang, Blockchain-based data security for artificial intelligence applications in 6G networks, IEEE Netw. 34 (6) (2020) 31–37. [129] Ruoting Xiong, Kit-Lun Tong, Yi Ren, Wei Ren, Gerard Parr, From 5G to 6G: It is time to sniff the communications between a base station and core networks, in: Proceedings of the 29th Annual International Conference on Mobile Computing and Networking, 2023, pp. 1–2. [130] Raja Ettiane, Abdelaali Chaoub, Rachid Elkouch, Toward securing the control plane of 5G mobile networks against DoS threats: Attack scenarios and promising solutions, J. Inf. Secur. Appl. 61 (2021) 102943. [131] Mohamed Amine Ferrag, Burak Kantarci, Lucas C Cordeiro, Merouane Debbah, Kim-Kwang Raymond Choo, Poisoning attacks in federated edge learning for digital twin 6g-enabled iots: An anticipatory study, in: 2023 IEEE International Conference on Communications Workshops, ICC Workshops, IEEE, 2023, pp. 1253–1258. [132] Minghao Wang, Tianqing Zhu, Tao Zhang, Jun Zhang, Shui Yu, Wanlei Zhou, Security and privacy in 6G networks: New areas and new challenges, Digit. Commun. Netw. 6 (3) (2020) 281–291. [133] Kadir Durak, Naser Jam, An attack to quantum systems through RF radiation tracking, 2020, arXiv preprint arXiv:2004.14445. [134] Luca Arcangeloni, Enrico Testi, Andrea Giorgetti, Detection of jamming attacks via source separation and causal inference, IEEE Trans. Commun. 71 (8) (2023) 4793–4806. [135] Xiaozhen Lu, Liang Xiao, Pengmin Li, Xiangyang Ji, Chenren Xu, Shui Yu, Weihua Zhuang, Reinforcement learning-based physical cross-layer security and privacy in 6G, IEEE Commun. Surv. Tutorials 25 (1) (2022) 425–466. [136] Mumtaz Fatima Amy Chang, Safeguarding AI: A policymaker’s primer on adversarial machine learning threats, 2024, Available: https: //www.rstreet.org/commentary/safeguarding-ai-a-policymakers-primer-onadversarial-machine\-learning-threats/. [137] Latif U Khan, Ibrar Yaqoob, Nguyen H Tran, Zhu Han, Choong Seon Hong, Network slicing: Recent advances, taxonomy, requirements, and open research challenges, IEEE Access 8 (2020) 36009–36028. [138] Taras Maksymyuk, Juraj Gazda, Marcel Volosin, Gabriel Bugar, Denis Horvath, Mykhailo Klymash, Mischa Dohler, Blockchain-empowered framework for decentralized network management in 6G, IEEE Commun. Mag. 58 (9) (2020) 86–92. [139] V. Kanimozhi, T. Prem Jacob, Artificial intelligence based network intrusion detection with hyper-parameter optimization tuning on the realistic cyber dataset CSE-cic-IDS2018 using cloud computing, in: 2019 International Conference on Communication and Signal Processing, ICCSP, IEEE, 2019, pp. 0033–0036. [140] Iman Sharafaldin, Arash Habibi Lashkari, Saqib Hakak, Ali A Ghorbani, Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy, in: 2019 International Carnahan Conference on Security Technology, ICCST, IEEE, 2019, pp. 1–8. [141] Marouane Hachimi, Georges Kaddoum, Ghyslain Gagnon, Poulmanogo Illy, Multi-stage jamming attacks detection using deep learning combined with kernelized support vector machine in 5G cloud radio access networks, in: 2020 International Symposium on Networks, Computers and Communications, ISNCC, IEEE, 2020, pp. 1–5. [142] Nickolaos Koroniotis, Nour Moustafa, Elena Sitnikova, Benjamin Turnbull, Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset, Future Gener. Comput. Syst. 100 (2019) 779–796. [143] Nicolas-Alin Stoian, Machine Learning for Anomaly Detection in Iot Networks: Malware Analysis on the Iot-23 Data Set, B.S. thesis, University of Twente, 2020. [144] Shu-Ming Tseng, Yan-Qi Wang, Yung-Chung Wang, Multi-class intrusion detection based on transformer for IoT networks using CIC-IoT-2023 dataset, Futur. Internet 16 (8) (2024) 284. [145] Mohamed Amine Ferrag, Othmane Friha, Djallel Hamouda, Leandros Maglaras, Helge Janicke, Edge-iIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning, IEEE Access 10 (2022) 40281–40306. [146] Nicolas-Alin Stoian, Machine Learning for Anomaly Detection in Iot Networks: Malware Analysis on the Iot-23 Data Set, B.S. thesis, University of Twente, 2020. [147] Y. Liang, N. Vankayalapati, Machine learning and deep learning methods for better anomaly detection in iot-23 dataset cybersecurity, Prepr. (2022) Available Online: https:// Github. Com/ Yliang725/ AnomalyDetectionIoT23 (Accessed 22 December 2022). [148] Ruizhe Zhao, NSL-KDD, IEEE Dataport, 2022. [149] Nour Moustafa, Jill Slay, UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set), in: 2015 Military Communications and Information Systems Conference, MilCIS, IEEE, 2015, pp. 1–6. [150] Kaiyuan Jiang, Wenya Wang, Aili Wang, Haibin Wu, Network intrusion detection combined hybrid sampling with deep hierarchical network, IEEE Access 8 (2020) 32464–32476. [151] Sehan Samarakoon, Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Sang-Yoon Chang, Jinoh Kim, Jonghyun Kim, Mika Ylianttila, 5Gnidd: A comprehensive network intrusion detection dataset generated over 5g wireless network, 2022, arXiv preprint arXiv:2212.01298. [152] E. Chatzoglou, G. Kambourakis, C. Kolias, Empirical evaluation of attacks against IEEE 802.11 enterprise networks: The AWID3 dataset, IEEE Access 9 (2021) 34188–34205. [153] Krzysztof Uszko, Maciej Kasprzyk, Marek Natkaniec, Piotr Chołda, Rule-based system with machine learning support for detecting anomalies in 5g wlans, Electronics 12 (11) (2023) 2355. [154] Anibal Torrres, Wifi Anomaly Behavior Analysis Based Intrusion Detection Using Online Learning, International Foundation for Telemetering, 2021. [155] Rahul Kale, Kar Wai Fok, Vrizlynn L. L. Thing, Payload-based 5G attack detection, in: 2023 9th International Conference on Computer and Communications, ICCC, 2023, pp. 1262–1266. [156] Mohamed Aly Bouke, Azizol Abdullah, An empirical assessment of ML models for 5G network intrusion detection: A data leakage-free approach, EPrimeAdv. Electr. Eng. Electron. Energy 8 (2024) 100590. [157] George Amponis, Panagiotis Radoglou-Grammatikis, George Nakas, Sotirios Goudos, Vasileios Argyriou, Thomas Lagkas, Panagiotis Sarigiannidis, 5G core PFCP intrusion detection dataset, in: 2023 12th International Conference on Modern Circuits and Systems Technologies, MOCAST, 2023, pp. 1–4. [158] National Centre of Scientific Research "Demokritos", Space Hellas (Greece), NCSRD-DS-5GDDoS: 5G Radio and Core metrics containing sporadic DDoS attacks, 2024. [159] Md Sajid Khan, Behnam Farzaneh, Nashid Shahriar, Md Mahibul Hasan, DoS/DDoS attack dataset of 5G network slicing, 2023. [160] K. Tahori, 5G-slicindd. figshare. dataset, 2023, Available: https://doi.org/10. 6084/m9.figshare.24446515.v1. [161] Vinay Kumar Gugueoth, Enhanced security attack detection and prevention in 5G networks using CD-GELU-CNN and FMLRQC with HDFS-ECH-KMEANS, in: 2024 8th International Conference on Computer, Software and Modeling, ICCSM, 2024, pp. 36–43. [162] Cooper Coldwell, Denver Conger, Edward Goodell, Brendan Jacobson, Bryton Petersen, Damon Spencer, Matthew Anderson, Matthew Sgambati, Machine learning 5G attack detection in programmable logic, in: 2022 IEEE Globecom Workshops, GC Wkshps, 2022, pp. 1365–1370. [163] Sehan Samarakoon, Yushan Siriwardhana, Pawani Porambage, Madhusanka Liyanage, Sang-Yoon Chang, Jinoh Kim, Jonghyun Kim, Mika Ylianttila, 5GNIDD: A comprehensive network intrusion detection dataset generated over 5G wireless network, 2022. [164] Amir Afaq, Noman Haider, Muhammad Zeeshan Baig, Komal S Khan, Muhammad Imran, Imran Razzak, Machine learning for 5G security: Architecture, recent advances, and challenges, Ad Hoc Networks 123 (2021) 102667. [165] Eva Rodriguez, Beatriz Otero, Norma Gutierrez, Ramon Canal, A survey of deep learning techniques for cybersecurity in mobile networks, IEEE Commun. Surv. Tutorials 23 (3) (2021) 1920–1955. [166] Sangjun Kim, Kyung-Joon Park, Chenyang Lu, A survey on network security for cyber–physical systems: From threats to resilient design, IEEE Commun. Surv. Tutorials 24 (3) (2022) 1534–1573. [167] Xiaozhen Lu, Liang Xiao, Pengmin Li, Xiangyang Ji, Chenren Xu, Shui Yu, Weihua Zhuang, Reinforcement learning-based physical cross-layer security and privacy in 6G, IEEE Commun. Surv. Tutorials 25 (1) (2022) 425–466. Computer Networks 271 (2025) 111594 32
S. Tariq et al. [168] Nidal Nasser, Zubair Md Fadlullah, Mostafa M Fouda, Asmaa Ali, Muhammad Imran, A lightweight federated learning based privacy preserving B5G pandemic response network using unmanned aerial vehicles: A proof-of-concept, Comput. Netw. 205 (2022) 108672. [169] Saurabh Gajbhiye, Priyanka Singh, Shaifu Gupta, Data poisoning attack by label flipping on splitfed learning, in: International Conference on Recent Trends in Image Processing and Pattern Recognition, Springer, 2022, pp. 391–405. [170] Hyejun Jeong, Hamin Son, Seohu Lee, Jayun Hyun, Tai-Myoung Chung, FedCC: Robust federated learning against model poisoning attacks, 2022, arXiv preprint arXiv:2212.01976. [171] Jordi Ortiz, Ramon Sanchez-Iborra, Jorge Bernal Bernabe, Antonio Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz, Ricard Vilalta, Chrystel Gaber, et al., INSPIRE-5Gplus: Intelligent security and pervasive trust for 5G and beyond networks, in: Proceedings of the 15th International Conference on Availability, Reliability and Security, 2020, pp. 1–10. [172] Danny Kadyshevitch, Generative AI has democratised fraud and cybercrime, Comput. Fraud Secur. 2024 (5) (2024). [173] Emilio Ferrara, GenAI against humanity: Nefarious applications of generative artificial intelligence and large language models, J. Comput. Soc. Sci. 7 (1) (2024) 549–569. [174] Farzad Nourmohammadzadeh Motlagh, Mehrdad Hajizadeh, Mehryar Majd, Pejman Najafi, Feng Cheng, Christoph Meinel, Large language models in cybersecurity: State-of-the-art, 2024, arXiv preprint arXiv:2402.00891. [175] Ken St Germain, Frank Kragh, Mobile physical-layer authentication using channel state information and conditional recurrent neural networks, in: 2021 IEEE 93rd Vehicular Technology Conference, VTC2021-Spring, IEEE, 2021, pp. 1–6. [176] Stephan Frisbie, Mohamed Younis, AI-enabled jammer deception using decoy packets, in: GLOBECOM 2022-2022 IEEE Global Communications Conference, IEEE, 2022, pp. 5013–5018. [177] Arwa Aldweesh, Abdelouahid Derhab, Ahmed Z. Emam, Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues, Knowl.-Based Syst. 189 (2020) 105124. [178] Ahmad Hamarshe, Huthaifa I. Ashqar, Mohammad Hamarsheh, Detection of DDoS attacks in software defined networking using machine learning models, in: International Conference on Advances in Computing Research, Springer, 2023, pp. 640–651. [179] Anass Sebbar, Karim Zkik, Youssef Baddi, Mohammed Boulmalf, Mohamed Dafir Ech-Cherif El Kettani, MitM detection and defense mechanism CBNA-RF based on machine learning for large-scale SDN context, J. Ambient. Intell. Humaniz. Comput. 11 (12) (2020) 5875–5894. [180] Noe M Yungaicela-Naula, Cesar Vargas-Rosales, Jesús A Pérez-Díaz, SDN/NFVbased framework for autonomous defense against slow-rate DDoS attacks by using reinforcement learning, Future Gener. Comput. Syst. 149 (2023) 637–649. [181] Arij Elmajed, Armen Aghasaryan, Eric Fabre, Machine learning approaches to early fault detection and identification in NFV architectures, in: 2020 6th IEEE Conference on Network Softwarization, NetSoft, IEEE, 2020, pp. 200–208. [182] Yi Shi, Yalin E. Sagduyu, Tugba Erpek, M. Cenk Gursoy, How to attack and defend nextg radio access network slicing with reinforcement learning, IEEE Open J. Veh. Technol. 4 (2022) 181–192. [183] Neetesh Kumar, Syed Shameerur Rahman, Navin Dhakad, Fuzzy inference enabled deep reinforcement learning-based traffic light control for intelligent transportation system, IEEE Trans. Intell. Transp. Syst. 22 (8) (2020) 4919–4928. [184] Jaakko Marin, Karel Pärlin, Micael Bernhardt, Taneli Riihonen, Neural networks in the pursuit of invincible counterdrone systems, IEEE Potentials 41 (1) (2021) 14–21. [185] Sainath Reddy Sankepally, Nishoak Kosaraju, Vishwambhar Reddy, U Venkanna, Edge intelligence based mitigation of false data injection attack in IoMT framework, in: 2022 OITS International Conference on Information Technology, OCIT, IEEE, 2022, pp. 422–427. [186] Veeru Talreja, Matthew C. Valenti, Nasser M. Nasrabadi, Deep hashing for secure multimodal biometrics, IEEE Trans. Inf. Forensics Secur. 16 (2020) 1306–1321. [187] Mehran Mozaffari-Kermani, Susmita Sur-Kolay, Anand Raghunathan, Niraj K Jha, Systematic poisoning attacks on and defenses for machine learning in healthcare, IEEE J. Biomed. Heal. Inform. 19 (6) (2014) 1893–1905. [188] Shi Dong, Yuanjun Xia, Tao Peng, Network abnormal traffic detection model based on semi-supervised deep reinforcement learning, IEEE Trans. Netw. Serv. Manag. 18 (4) (2021) 4197–4212. [189] Md Tohidul Islam, Md Khalid Syfullah, Md Golam Rashed, Dipankar Das, Bridging the gap: advancing the transparency and trustworthiness of network intrusion detection with explainable AI, Int. J. Mach. Learn. Cybern. 15 (11) (2024) 5337–5360. [190] Raghav Shah, Amruta Pawar, Manni Kumar, Enhancing machine learning model using explainable AI, in: International Conference on Data & Information Sciences, Springer, 2023, pp. 287–297. [191] Ilhan Uysal, Utku Kose, Analysis of network intrusion detection via explainable artificial intelligence: Applications with SHAP and LIME, in: 2024 Cyber Awareness and Research Symposium, CARS, IEEE, 2024, pp. 1–6. [192] Priyanka Dass, Anjali Rajak, Rakesh Tripathi, Machine learning-enabled techniques for anomaly detection in 5G networks, in: 2024 15th International Conference on Computing Communication and Networking Technologies, ICCCNT, IEEE, 2024, pp. 1–7. [193] Yagmur Yigit, Christos Chrysoulas, Gokhan Yurdakul, Leandros Maglaras, Berk Canberk, Digital twin-empowered smart attack detection system for 6g edge of things networks, in: 2023 IEEE Globecom Workshops, GC Wkshps, IEEE, 2023, pp. 178–183. [194] Chip Elliott, Building the quantumnetwork, New J. Phys. 4 (1) (2002) 46. [195] Miralem Mehic, Stefan Rass, Peppino Fazio, Miroslav Voznak, Modern trends in quantum key distribution networks, in: Quantum Key Distribution Networks: A Quality of Service Perspective, Springer, 2022, pp. 209–223. [196] Abdulkadir Celik, Ahmed M. Eltawil, At the dawn of generative AI era: A tutorial-cum-survey on new frontiers in 6G wireless intelligence, IEEE Open J. Commun. Soc. (2024). Saman Tariq received her master’s degree in software engineering from the Comsats University Islamabad, Pakistan. Currently, she is pursuing a Ph.D degree in computer science at Universitat Politècnica de Catalunya. Her research interests include privacy, security, and the development of software modules, in particular, identifying threats, modeling threats, attack detection, assessing impact, and formal analysis and verification. Eva Rodriguez received her Ph.D in Computer Science from the Universitat Pompeu Fabra (UPF) in 2007 and her B.Sc. in Telecommunication Engineer from the Universitat Politècnica de Catalunya (UPC) in 2001. She is with the Department of Computer Architecture, UPC, as an Assistant Professor since 2005. From 2002 to 2005, she worked as a Researcher with the Department of Technology, UPF. Her research focuses on security, privacy, multimedia information retrieval, and object recognition, participating in several national and EU projects in the areas of security and multimedia information management. She has authored several international journals and conferences. Xavi Masip got an MSc and Ph.D. degree in Telecommunications Engineering both from the Technical University of Catalonia (UPC). He is currently a Full Professor at UPC, and the Director of the Advanced Network Architectures Lab (CRAAX). His publications include more than 200 papers in international refereed journals and conferences. He serves as editor for the Optical Switching and Networking (OSN) and for the Computer Communications journals. Xavi’s contributions were recognized with a 2016 IBM Faculty Award. Xavi has participated and/or led many national and regional projects and EU contracts as well as contracts with the industry Rodrigo Diaz, Master’s degree in Computer Science from the Universitat Autonoma de Barcelona, led 2010 the cyber security team within the R& D group in Spain. In February 2015, he joined the esteemed Atos Scientific Community, an elite community comprising the top 100 scientific minds within the organization, and since 2016, he has held membership in the Atos Expert Community. He served as a coordinator and technical manager in numerous EU-funded projects. Prior to his leadership role, he served as a Senior Engineer in the Aerospace and Communications Unit of the Atos Research and Innovation department in Barcelona until 2009. Computer Networks 271 (2025) 111594 33
S. Tariq et al. Josep Martrat holds a Degree in Telecommunication Engineering from the Technical University of Catalonia (UPC). He is currently Head of Smart Network and Edge Computing at Eviden Research and Innovation, an Atos business. His research activity includes the study of Cloud and Edge technologies, network virtualization (SDN/NFV), and 5G private networks. He has participated in several collaborative research projects in the areas of Edge-Cloud and software networks, serving as project coordinator in many of them, including BonFIRE, 5GTANGO, Affordable5G, and the ongoing HORSE research projects. Panagiotis Trakadas received the DiplIng. degree in electrical and computer engineering and the Ph.D. degree from the National Technical University of Athens (NTUA). He is currently an Associate Professor with the National and Kapodistrian University of Athens. He has been actively involved in many EU FP7, H2020 and HE Research Projects. He has published more than 170 papers in magazines, journals, and conferences. His research interests include wireless and mobile communications, wireless sensor networking, network function virtualization, and cloud computing. He is a Reviewer in several journals, including IEEE Transactions on Communications and IEEE Transactions on Electromagnetic Compatibility Computer Networks 271 (2025) 111594 34