
The DNS protocol, which is typically not blocked by firewalls, enables attackers to easily and efficiently establish tunnels and exfiltrate user information. Despite extensive research on DNS tunnel detection with promising results, a significant gap remains between experimental settings and real-world scenarios. This gap stems from the fact that existing methods predominantly depend on the quality of the training set, while attackers can adapt evasion techniques to create more covert and previously unknown tunnel types. To narrow this gap, we propose EvaSense, a real-time alert system for detecting DNS tunnels that employ diverse, potentially unseen evasion strategies. Our approach combines a behavior-based tunnel detection method with an agent-based online labeling method. We designed multiple DNS tunnels employing evasion strategies and conducted experiments on both real campus network traffic and public datasets. The experimental results demonstrate that EvaSense effectively detects these tunnels.
As 5G-Advanced evolves toward 6G, the Radio Access Network (RAN) is expected to become AI-native and intent-driven, delivering closed-loop autonomy under stringent operational resource and overhead constraints. Yet today’s RAN automation remains largely KPI-centric. AI models are deployed as static, opaque add-ons, while their data pipelines are treated as implementation details rather than controllable system assets. We address a central challenge: under dynamic intents and resource constraints, how can deployed RAN AI models and pipelines be treated as controllable objects, enabling observability, reconfigurability, and governance? We propose AI2N-RAN, an agentic intent-to-network architecture that couples a slow intent-to-policy loop with a fast evidence-to-action loop, unified by an assurance-and-learning plane. AI2N-RAN defines explicit interfaces to compile intents into auditable policies and monitoring specifications, and is designed to support evidence-driven, budget-aware reconfiguration with risk-aware governance across network, model, and data states. Using beam prediction as an illustrative use case, we instantiate selected AI2N-RAN interfaces and evaluate a governed model–data adaptation workflow using logged real-network measurements. Across selected model families, reconstruction-enabled candidates improve Top-1 accuracy by 21.03–42.30 percentage points and reduce selected-run training latency by 45.35%–48.39%. Additional measurements of training and inference costs expose configuration-dependent resource trade-offs and illustrate how the proposed architecture supports evidence-based candidate screening.
The transition to 6G will bring unprecedented heterogeneity, density, and energy demands, requiring networks to self-organize with minimal human intervention. This article addresses the challenge of predictive and energy-aware resource allocation in such environments, where reactive and centralized controllers struggle under dynamic conditions. We present an Agentic AI architectural blueprint that embeds autonomous edge agents capable of anticipating load, making local decisions, and coordinating through the Model Context Protocol. A lightweight prototype, PRIMAL (Proactive Resource Intelligent Management with Agentic Learning), implements this vision by combining predictive telemetry, adaptive thresholds, and capacity-aware admission control. Experiments using realistic workload traces show that PRIMAL achieves approximately 31% higher task acceptance and 10% lower energy consumption than reactive baselines, highlighting the potential of agentic orchestration for sustainable AI-native 6G systems.
Preservation of resolution on a semantic level. Semantic preserving resolution has been of interest in intelligent 6G services since data intensive applications such as immersive media and autonomous systems are increasing at high rates. The key issue with the existing models of semantic communication is that compression and transmission of models affect the spatial resolution of the model which affects the quality of reconstruction and the accuracy of tasks at the receiver end. The problem is severe in the circumstances of dynamism of networks, where the bandwidth and the latency restrictions of the services vary. It suggests a Resolution Preserving Multi Scale Semantic Communication Architecture (RP-MSCA) that features a network-based architecture and offers semantic control on the service level and edge cloud orchestration. The method introduces a hierarchical encoder that extracts the characteristics of different spatial scales and structural consistency among layers. A conscious attention control that is aware of the significance of features in response to channel conditions, resource adaptation and semantic cross-layer optimization govern successful transmission. The compression and fidelity are traded off using a joint source channel optimization scheme. With a combination of multi scale semantic cues, a decoder is used to rebuild signals in a more understandable manner. Experimental results show that there are enhancements in peak signal-to-noise ratio (improvement of about 10-15%), structural similarity index (improvement of about 8-12%), and task accuracy (improvement of about 7-10%), when the channel noise is at different levels as compared to baseline models. The architecture is consistent with low bandwidth performance and it provides efficient utilization of resources (≈12-18% better). The resolution preservation can increase the reliability of semantic communication in 6G environments and can be leveraged to facilitate intelligent service, which needs to have high-fidelity data transfer at low cost of transmission.
Facial recognition models are increasingly employed by commercial enterprises, government agencies, and cloud service providers for identity verification, consumer services, and surveillance. These models are often trained using vast amounts of facial data processed and stored in cloud-based platforms, raising significant privacy concerns. Users’ facial images may be exploited without their consent, leading to potential data breaches and misuse. In this study, we present an overview of methods for preserving facial image privacy in cloud-based services. We categorize these methods into two primary approaches: image obfuscation-based protection and adversarial perturbation-based protection. We provide an in-depth analysis of both categories, offering qualitative and quantitative comparisons of their effectiveness. Additionally, we highlight unresolved challenges and propose future research directions to improve privacy preservation in cloud computing environments.
Next-generation AI-native wireless networks will depend on large populations of autonomous agents to support extended reality, digital twins, connected mobility, and other latency-sensitive services. However, today’s command-driven orchestration frameworks are poorly suited to coordinating thousands of cloud, edge, radio, and device agents that compete for compute, memory, bandwidth, energy, and latency-critical resources. This article presents MAESTRO, a hierarchical agentic-AI framework that replaces per-node commands with tokenized coordination. MAESTRO introduces the Standard Compute Token (SCT), a compute-native unit that expresses heterogeneous resource costs in terms of measurable AI-inference effort. Cloud agents publish bounded SCT price and quota envelopes, near-edge agents clear lightweight local auctions, and radio/device agents make fast local decisions using compact signed messages. Critical Ultra-Reliable Low-Latency Communication (URLLC) and emergency traffic bypass the auction through a strict-priority reserved path. A city-scale 6G metaverse traffic-twin evaluation shows that MAESTRO preserves sub-millisecond admitted URLLC latency, reduces control-plane overhead, improves resilience under cascading failures, and limits welfare loss under adversarial bidding. These results suggest that tokenized coordination can provide a scalable, resilient, and carbon-aware foundation for self-organizing next-generation wireless networks.
The increasing complexity of 6G networks, driven by heterogeneous services and strict performance requirements, has made traditional manual network management difficult to maintain and scale. To address this, Intent-Based Networking (IBN) allows operators to define desired outcomes instead of managing low-level configurations. However, existing IBN systems typically rely on structured inputs, limiting usability for users with limited domain knowledge. The industry is therefore moving toward natural language IBN powered by AI agents. However, significant challenges remain: (i) user intents can span multiple domains, i.e., Radio Access Network (RAN), Core Network (CN), and Mobile Edge Computing (MEC), requiring complex decomposition, and (ii) valid intents may be rejected if the infrastructure cannot meet resource demands. To tackle these issues, we propose IntentWeave, an Agentic AI framework powered by Large Language Models (LLMs) to clarify user intents, decompose them across domains, perform feasibility negotiation, activate and ensure intents. Experiments in real-world scenarios validate its effectiveness in enhancing user experience.
Optimization, which lies at the core of network operations, is usually associated with extensive expert knowledge and manual overhead, which impedes its efficient implementation. To address this issue, this study illustrates the potential of a paradigm shift from algorithmic solvers to semantic agents for network optimization. Specifically, we envision a generalized Large Language Model (LLM)-based framework, called ComLLM, for addressing fundamental problems in mobile communication networks. Without explicit mathematical problem formulation, ComLLM can understand the semantic context (i.e., high-level, human-interpretable goals and constraints) and autonomously call incorporated prediction modules to generate adaptive optimization decisions. A case study on mobile edge computing demonstrates that ComLLM effectively performs joint data transmission rate prediction and autonomous vehicle task scheduling. ComLLM can be used for minimizing end-to-end latency or maximizing revenue. Furthermore, the paper provides insights into ComLLM and discusses open challenges.
As 6G networks evolve from bit-perfect transmission to semantic-oriented delivery, multimodal semantic communication (SemCom) has emerged as a key enabler for applications like the metaverse and autonomous driving. However, current multimodal systems suffer from “architecture islands”—relying on separate, redundant encoders for text and images—and often struggle with synchronization in dynamic wireless channels. To overcome these bottlenecks, we propose a unified vision-centric semantic communication (VC-SemCom) framework based on multimodal visual compression. By rendering non-visual modalities (e.g., text) into the visual domain, we utilize a single, parameter-efficient vision transformer (ViT) for unified encoding. We further address the vulnerability of semantic tokens in fading channels by introducing a semantic redundancy fusion mechanism. Finally, we demonstrate a dual-path decoding architecture suitable for edge computing. Simulation results show that our approach outperforms traditional multi-tower architectures in both compression efficiency and robustness against low signal-to-noise ratio (SNR). The visual compression-based unified image-text encoder provides an efficient and parameter-compact solution for multimodal semantic communication in 6G networks.
The emergence of sixth-generation (6G) mobile networks is driving a transition from bit-centric communication toward semantic and goal-oriented service delivery, where the value of transmitted information depends on task relevance, context, and timing. This article presents a semantic communication enabled architecture for interactive game design in 6G mobile networks, a service scenario characterized by heterogeneous and mixed-criticality traffic, including player control actions, collaborative design edits, scene-state updates, event triggers, rendering requests, and background analytics. The proposed framework integrates semantic perception, interaction-aware prioritization, cross-layer orchestration, and adaptive edge-cloud execution to preserve responsiveness, synchronization quality, and service continuity in dynamic operating conditions. A semantic-state policy matrix is introduced to map interaction families to differentiated communication and execution strategies across stable links, congestion, bandwidth fluctuations, edge overload, and mobility handovers. A semantic decision workflow further connects intent recognition, context interpretation, and system state awareness to real-time transmission and scheduling actions. Comparative evaluation shows that the proposed framework reduces end-to-end latency, improves deadline satisfaction for interaction-critical traffic, lowers bandwidth consumption, preserves semantic fidelity under network stress, and sustains stronger service continuity than conventional bit-centric and nonsemantic adaptive baselines. These results demonstrate the practical value of semantic communication as a system-level networking solution for interactive sixth-generation (6G) services.
Immersive sports broadcasting is emerging as a demanding 6G service that combines multi-view and panoramic media with stringent requirements for latency, reliability, continuity, and bandwidth efficiency. However, conventional adaptive streaming and QoS-driven networking still treat media traffic mainly according to transport conditions rather than the meaning and service importance of the transmitted content. This limitation is particularly critical in live sports, where decisive moments such as goals, referee decisions, and replay-critical actions have far greater impact on user experience than low-saliency background regions. This article presents a semantic-aware adaptive networking framework for immersive sports broadcasting over 6G networks. The proposed architecture jointly integrates sports-content semantics, immersive user context, and runtime network-edge state to drive cross-layer decisions on packet prioritization, bitrate adaptation, reliability protection, edge orchestration, and continuity-preserving service control. A public-data-driven, trace-based evaluation using SoccerNet-derived sports semantics and Panonut360-derived immersive behavior traces compares the framework with conventional bitrate adaptation and QoS-aware adaptive networking under representative 6G stress conditions. Results show consistent gains in end-to-end latency, semantic fidelity retention, traffic reduction, immersive continuity, and critical-event delivery robustness. These findings indicate that semantic-aware adaptation can serve as a practical foundation for efficient, resilient, and user-centered immersive media services in future 6G mobile networks.
Despite remarkable strides in communication performance achieved by terrestrial networks, their high-cost deployments pose significant barriers to extending coverage in remote regions. The sixth generation mobile communication system aspires to realize ubiquitous connectivity; yet, the acute scarcity of spectrum resources renders integrated satellite-terrestrial networks (ISTNs) vulnerable to interference challenges during spectrum sharing. This article categorizes various interference phenomena encountered within ISTNs and delineates the corresponding mitigation methods from the dual perspectives of processing location and domain. Existing interference mitigation techniques remain constrained by scenario dependency, exhibiting limited scalability and adaptability when confronted with inherently open environments, difficulties in updates, and stringent payload limitations of ISTNs. To address these obstacles, we propose software defined waveform (SDW). Following an exposition of boundaries of software and hardware components, triggering mechanisms, and a strategic framework underpinned by knowledge graph, we design and simulate two reconfigurable waveforms as cases, namely generalized orthogonal frequency division multiplexing and generalised 2-D modulation, thereby substantiating the effectiveness of SDW. The article concludes with analyses and discussions of the prospective advantages and issues of our proposal.
The evolution toward sixth-generation (6G) wireless networks shifts the focus of communication systems from reliably delivering bits to transmitting meaning, intent, and task-relevant information. In this context, semantic communication has emerged as a promising paradigm that supports intelligent applications, such as autonomous driving, smart cities, and human-artificial intelligence (AI) collaboration, by improving efficiency, robustness, and adaptability. However, this shift fundamentally reshapes the security landscape because, in semantic paradigms, adversaries can target learned semantic representations, AI models, and shared knowledge directly. This paves the way for attacks that manipulate or infer meaning, even when conventional bit-level protections are in place. Therefore, this article examines the security challenges unique to semantic communication and explains why traditional security measures are ineffective. We develop a detailed threat model that addresses three key risks: keeping semantic information confidential, maintaining its integrity, and ensuring system availability while facing intelligent and adaptive adversaries empowered by generative artificial intelligence (GenAI). We then propose an integrated framework that embeds semantic-layer protection throughout the communication process, including encoding, transmission, decoding, and knowledge management. We present a smart city case study that illustrates how semantic-layer attacks can compromise safety-critical decisions and demonstrate how security-aware semantic communication significantly improves task robustness under adversarial conditions. By unifying threat modeling, adversarial resilience, and system-level design, our work establishes a practical basis for secure, reliable, and scalable semantic communication in future 6G networks.
The rapid increase in Internet of Things (IoT) devices and their connections, along with their inherent vulnerabilities, poses significant security risks for their widely adopted safety-critical applications such as autonomous driving and industrial systems. To tackle these challenges, reinforcement learning (RL) based high-interaction honeypots have become a promising solution, leveraging RL techniques to generate responses to entice attackers. In this work, we first analyze the issues of these IoT high-interaction honeypots and clarify the challenges that current RL-based IoT honeypots face in complex IoT threat environments. Then, we design a Bidirectional Encoder Representation from Transformers (BERT)-based safe RL honeypot (BeRLpot). BeRLpot incorporates a low-interaction component to mimic IoT device operating systems and protocols, along with a high-interaction component that models honeypot-attacker interactions as a constrained Markov decision process. Leveraging a fine-tuned BERT, BeRLpot classifies IoT requests to identify various states. With this state information, BeRLpot applies safe RL to optimize response strategies to allure attackers. Experimental results demonstrate that BeRLpot significantly enhances its ability to resist pre-attack checks, enabling it to capture nearly twice as many malicious attacks as the existing RL-based IoT honeypot, IoTCandyJar. Finally, we discuss the fundamental challenges in building safe RL-based IoT honeypots and outline potential directions for future research.
The rapid expansion of autonomous vehicular systems (AVSs), from connected vehicles to smart cities (SCs), is introducing new challenges in security and privacy. Traditional approaches often struggle to keep pace with the dynamic, large-scale, and distributed nature of connected vehicular networks (VNs). In this magazine, we explore the role of agentic artificial intelligence (AI), i.e., autonomous, decision-making AI agents, in addressing such challenges. Agentic AI proactively detects cyber threats, enforce privacy-preserving measures, and maintain system integrity across heterogeneous autonomous VNs. We present several case studies, including securing AVSs, managing privacy in SCs, and protecting data in intelligent transportation networks, demonstrating the potential of agentic AI in building resilient and secure SC. Simulation results obtained from a high-fidelity autonomous vehicular and SCs simulation environment demonstrate that the proposed agentic AI framework achieves up to 17.8% improvement in secrecy rate and 20.5% enhancement in threat detection accuracy compared with conventional intrusion detection system (IDS), rule-based AI, and deep learning-based security approaches.
The open radio access network (O-RAN) exposes rich control and telemetry interfaces across the non-real-time RAN intelligent controller (non-RT RIC), near-real-time RIC (Near-RT RIC), and distributed units, but also complicates the operation of multi-tenant, multi-objective RANs in a safe and auditable manner. In parallel, agentic artificial intelligence (AI) systems with explicit planning, tool use, memory, and self-management offer a natural way to structure long-lived control loops. This article studies how such agentic controllers can be brought into O-RAN. We contrast agentic controllers with conventional machine learning (ML)/reinforcement learning (RL) xApps and organize the O-RAN task landscape around three clusters: network slice life-cycle, radio resource management (RRM) closed loops, and cross-cutting security, privacy, and compliance. We then introduce a compact set of agentic primitives —Plan-Act-Observe-Reflect, skills as tool use, memory and evidence, and self-management gates— and show, in a multi-cell O-RAN simulation, that they improve slice life-cycle and RRM performance relative to conventional baselines and ablations that remove individual primitives. The framework achieves an average 8.83% reduction in resource usage across three classic network slices.
To support emerging multi-modal services, cross-modal communication has emerged as a crucial enabling paradigm. By leveraging semantic correlations among modalities, it enables collaborative multi-modal streaming and signal processing. Existing regular cross-modal communications, which have relatively abundant resources, are primarily designed to improve user’s immersive experience. However, in scenarios with extremely low communication and computing resources, such schemes cannot achieve reliable transmission and lightweight processing. To address this issue, we construct a new cross-modal communication architecture inspired by human’s cognitive mechanisms. Specifically, a contrastive learning-based cross-modal signal compression scheme is first developed to eliminate redundancy among multi-modal signals while preserving critical semantics. Then, a continual learning-driven multi-modal stream transmission scheme is proposed to enable adaptive resource allocation through mechanisms such as experience accumulation and memory consolidation. Finally, a progressive learning-guided cross-modal signal restoration approach is presented to decompose complex restoration tasks from coarse-grained restoration to fine-grained refinement, thereby balancing computational cost and restoration quality. Experimental results validate the effectiveness of the proposed architecture.