
The transition to 6G necessitates advanced experimental capabilities across diverse, heterogeneous testbed infrastructures. Current approaches to integrating these platforms often suffer from complexity, limited interoperability, and proprietary interfaces, hindering rapid innovation and cross-domain experimentation. This paper introduces a novel open-source Software Development Kit (SDK) designed to simplify the federation and integration of heterogeneous testbed environments across Europe. The SDK achieves this by providing a unified interface that translates standardised service Application Programming Interfaces (APIs), primarily those defined by the Linux Foundation (LF) CAMARA initiative and the GSMA Operator Platform Group (OPG) for the East-Westbound Interface (EWBI), into platform-specific operations for both edge cloud and 5G core networks. It fills crucial gaps by introducing mechanisms for local and cross-domain artefact upload, application onboarding, and instantiation, as well as network exposure capabilities, fully compliant with GSMA OPG and 3GPP Network Exposure Function (NEF) specifications. By abstracting federation complexity, the SDK enables seamless deployment and management of applications across federated domains without requiring awareness of underlying operator topologies or administrative policies. We detail the SDK’s architecture, highlighting its modular design, the implementation of reusable Transformation Functions (TFs) for edge cloud orchestration and network exposure capabilities, and its support for various underlying platforms. This work forms a significant advancement towards the realisation of an open, interoperable, and application-centric toolkit to deploy and test next-generation applications in federated, operator-like environments, laying crucial groundwork for sustainable and interoperable 6G experimentation.
The integration of the Internet of Things into the healthcare sector has resulted in the emergence of the Internet of Medical Things (IoMT) technology. However, IoMT networks remain susceptible to various types of threats due to their heterogeneity and resource-constrained characteristics. Therefore, novel security solutions, such as efficient and accurate Anomaly-based Intrusion Detection Systems (AIDSs), considering the inherent limitations of IoMT networks are required to be developed, before IoMT networks realize their full potential in the market. In our previous work, we focused on developing an AIDS for protecting Linux-based IoMT devices. In this paper, we extend our previous work by presenting the first AIDS specifically designed for resource-constrained IoMT devices using the popular Zephyr RTOS. The implementation details of the proposed AIDS are described, and the runtime performance of the implemented MDA component of the AIDS is evaluated using an nRF52840 Development Kit (DK). The runtime performance evaluation showed a minimized resource consumption (i.e., less than 1% CPU and RAM usage, approximately 1% ROM usage).
This paper focuses on how the concepts conceptualized by ETSI ZSM in the Intent Management project and TM Forum in the Autonomous Networks project have been adopted and enhanced by 6G-INTENSE. Specifically, we demonstrate how intent translation, decomposition, and propagation have been realized across the operational domains of the architecture, to control the management and orchestration of resources at the infrastructure level. We propose an LLM-based Conversational Assistant (Chatbot) for Intent-driven Management to ease the process of Service Ordering by Verticals. Our Chatbot intelligently translates natural language requests into business requests, which are subsequently processed to generate actions at the infrastructure level, as demonstrated in the results section
This proof-of-concept demonstration introduces an LLM-based framework that automates model selection for network use cases, driven by user intent, to improve performance and reduce complexity.
Healthcare 4.0 (H4.0) applications such as tele-health and Internet of Medical things (IoMT) demand ultra-high capacity, low latency, extensive coverage, energy efficiency, and massive connectivity, stressing the limits of traditional Terrestrial Networks (TNs) infrastructure. The lack of ubiquitous terrestrial coverage and X-haul capacity bottlenecks necessitate integrated Terrestrial and Non-Terrestrial 6G Networks (TN-NTNs). However, high deployment cost and energy limitations of NTNs demand efficient solutions to ensure scalable and sustainable healthcare delivery. This paper focuses on minimizing the Total Cost of Ownership (TCO) of the integrated 6G TN-NTN formulated as a joint offline cost-aware user association, traffic routing and Virtual Network Function (VNF) placement problem. A cost-efficient low complexity heuristic algorithm (named CHEUR) is developed and evaluated via simulations. The proposed solution is shown to significantly outperform the State-of-Art (SoA) in terms of energy and cost-efficiency, with CHEUR achieving up to 1.64 times higher energy efficiency and 73.85% TCO reduction. The problem is introduced within a H4.0 scenario which includes healthcare focused service function chains (SFCs) aligned with the latest ITU-R framework for IMT-2030.
Cross-slice lateral movement attacks pose a critical security threat to NFV/SDN-based 6G networks, where adversaries exploit compromised Virtual Network Functions (VNFs) to infiltrate other slices. While prior works have employed Deep Q-Learning (DQL) for Moving Target Defense (MTD), these single-agent solutions lack coordination and scalability across network slices. To overcome these limitations, this paper proposes a MultiAgent Deep Deterministic Policy Gradient (MADDPG) framework for orchestrating Software-Defined Networking (SDN)-based path randomization in service-oriented cloud networks based on NFV and SDN principles. The architecture leverages centralized training with decentralized execution, enabling collaborative decision-making among agents assigned to individual slices. Evaluated in a realistic OpenStack testbed with Tacker integration, the proposed method achieves over 60% reduction in attack success rate and a 2.5x improvement in Mean Time-To-Compromise (MTTC) compared to random path-hopping, all while maintaining low latency (<50 ms) and minimal control overhead (<20 flow modifications per minute). These results validate the effectiveness and deployability of the proposed multi-agent MTD approach in real-world 6G cloud infrastructures.
Recent advances in intelligent data-plane designs have enabled efficient inference of machine learning models on programmable switches using P4. However, existing solutions focus primarily on classifying traffic that belongs to previously observed classes, i.e., in-distribution traffic, and often overlook the impact of concept drift, i.e., the emergence of out-of-distribution traffic. In this paper, we propose an approach that not only accurately classifies in-distribution traffic but also detects drifting samples that deviate from known classes. Our approach leverages a triplet network to learn an encoder that maps traffic input features to a latent space where representations of the same class form compact clusters. Drifting samples are identified based on their distance to class centroids in the latent space. Experimental results on two use cases demonstrate that our method achieves superior drifting sample detection performance compared to confidence-based schemes, while maintaining comparable in-distribution classification accuracy.
The evolution from beyond 5G to 6G networks has envisioned the adoption of various healthcare 4.0 applications, including telemedicine, e-Health, robotic surgery, and many more. These applications require stringent KPIs, including ultra-low latency, massive device connectivity, reliability, and robust security, which are not feasible in the traditional network architecture. The softwarisation of networks by SDN and NFV has enabled the logical partitioning of the physical infrastructure across the RAN, CN, and TN domains as an E2E network slice for user-specific services, which are tailored, isolated, managed, and orchestrated across virtual networks using Zero-Touch Management (ZTM). This paper presents the KPI requirements for healthcare 4.0 use cases, a brief survey on recent AL/ML-based slicing and orchestration frameworks, and then discusses challenges and future research directions for automated healthcare network slices. It also discusses open research directions towards ZTM of slices, including semantic intent translation specific to domains, cross-domain observability of QoS, AI-enabled closed-loop assurance, and the integration of emerging 6G enablers. It aims to guide the healthcare services in a scalable, flexible, secure, and dynamic way over mobile networks.
The emergence of 6G networks promises ultra-low latency, massive connectivity and intelligent edge computing capabilities, enabling a new generation of distributed applications. However, existing development methodologies are insufficient for managing the inherent complexity, dynamic behavior, and stringent performance requirements of such environments. To address these challenges, this paper is proposing an integrated software development and deployment toolchain that creates an innovative cross-layer strategy for Next-Generation networked applications. The proposed tool chain leverages the X-by-Construction (XbC) paradigm to ensure that applications are robust, scalable, and capable of satisfying both functional and non-functional requirements from the outset. This holistic approach provides a foundation for building resilient applications capable of dynamic reconfiguration and real-time optimization within future 6G ecosystems.
In this paper we exploit and discuss the ability of Large Language Models (LLMs) in detecting out-of-distribution (OOD) attacks within the context of 6G networks, by applying them to the 5G-NIDD, an openly-accessible dataset. The study benchmarks three LLM-based against a non-LLM (LightGBM) method. The data samples are properly converted to text before being fed to the LLMs and to feature vectors before being injected into LightGBM. To assess the accuracy of the four models’ predictions, we employ a leave-one-attack-out approach, allowing evaluation of each model’s performance on completely unseen attack types. Eight attack types are evaluated, namely UDP Flood, HTTP Flood, Slowrate DoS, TCP Connect Scan, SYN Scan, UDP Scan, SYN Flood and ICMP Flood. Results demonstrate that the proposed method can achieve a malicious recall of around 76%, with up to 5% improvement over a non-LLM baseline (LightGBM) under leave-one-attack-out OOD protocol.
Fifth-generation and beyond (B5G) networks, driven by Open Radio Access Network (O-RAN) principles, offer flexibility, interoperability, and intelligence through disaggregated and virtualized components. However, the decoupled Control and User Plane Separation (CUPS) architecture introduces new security challenges, particularly targeting the Centralized Unit-User Plane (CU-UP), a critical component of the RAN for user data handling. Existing approaches primarily focus on detecting threats without enabling runtime mitigation or preserving service continuity. The proposed framework EXODUS-5G showcases a cyber-resilient framework that autonomously migrates the CU-UP under attack to a remote site via an Optical Transport Network (OTN). The proposed framework integrates two xApps - Key Performance Metrics (KPM) for telemetry collection and Adaptive Cyber Threat (ACT) for threat detection using a pre-trained Multi-Layer Perceptron (MLP) - within the Near-RT RIC. Experimental results using the OpenAirInterface (OAI) and FlexRIC stack report that the MLP-based ACT xApp achieves a maximum F1score of 0.956 with the inference time of 32.5 microseconds per prediction, significantly outperforming other baseline ML models. Across different detection window configurations (2-5 seconds), the system exhibits average detection times ranging from 6.014 to 10.013 seconds and consistent migration times of approximately 1.2 seconds, with limited packet loss while executing CU-UP migration procedures.
In this work we study the offloading decision and computing resource allocation of tasks generated by internet-of-medical-things (IoMT) devices into a non-terrestrial network, comprised of local coordinating low-altitude platforms (LAPs) working also as multi-access edge computing (MEC) servers, and a common low Earth-orbit (LEO) satellite, which acts as a common MEC server across the LAPs. We solve the problem of total delay minimization across the tasks in the system. Given the NP-hard nature of the offloading decision problem, we solve it with a sequential greedy heuristic. To avoid biasing the of-floading decision due to the computing resource initialization, we formulate a mechanism for dynamically initializing the resources at each step. We propose several methods for the computing resource initialization, and show in simulations, regions where each method is the most effective depending on the parameters of the system.
This demo showcases how nonlinear processing can enable massive, scalable connectivity, demonstrating that even with a single antenna access point, we can support multiple concurrently transmitted information streams at the same time-frequency resources.
The dynamic and heterogeneous nature of B5G networks, creates fertile ground for Zero-Day attacks that evade signature-based defenses. This paper presents a novel approach that utilizes a Deep Neural Network framework based on Multiple Instance Learning for detecting Indicators of Compromise (IOC) from weakly labeled traffic data. By modeling traffic as bags of flows, our method avoids reliance on per-flow labels and uses attention-based pooling to discover suspicious features that indicate anomalous traffic within each bag. Experiments demonstrate strong performance in detecting previously unknown threats, offering a scalable and interpretable solution for next-generation network security. The mechanism is linked to a Large Language Model that provides insights concerning the IOC and proposes steps to mitigate the detected threats.
Modern mobile networks and edge computing infrastructure typically rely on fixed edge servers to deploy latency-sensitive applications. We propose a Far-Edge Computing Enablement (FCE) framework that extends the edge cloud into the realm of end-user devices - turning ordinary smartphones and IoT devices into on-demand compute nodes at the extreme edge of the network. Our framework introduces new architectural components and standardized interfaces that allow user equipment (UE) devices to securely join a far-edge compute cluster orchestrated by the mobile network, and to host containerized workloads on behalf of application providers. We describe the architecture and design of the FCE framework, including the protocols for UE cluster onboarding and workload orchestration. A prototype implementation using Docker Swarm demonstrates the practicality of our approach, leveraging standard container technology and 5G networking features. The proposed solution transforms UEs into opportunistic edge compute resources, enabling new ultra-distributed services with improved latency and scalability, all while maintaining the security and integrity of both network and device.
Network embedding in Software Defined Networks and Network Function Virtualization is an evolving area, moving from static, rule-based methods to intelligent, adaptive algorithms for various functions and topology optimizations. As networks become more dynamic and service-oriented, embedding strategies must balance efficiency, scalability, and service quality, with Machine Leaning (ML) techniques playing an increasingly central role. In this paper, we focus on the network embedding itself and address how network embedding can tackle efficiently dynamic networks. More specifically, we propose ML-based approaches for embedding new nodes in an already embedded topology thus avoiding computational costs, while maintaining accuracy. The core idea of our approach (LHR) is to maintain the geometric consistency of the hyperbolic space while minimizing re-computation. Our evaluation results demonstrate the efficacy of our approach and set a basis for more advanced exploitation of ML in network embedding.
Zero-touch network service automation in the future mobile networks, alike 6G, is a key enabler for their agile network service management and closed-loop handling. Towards this new technological breakthrough, there exist several SotA global standards, for instance the Zero-touch network and service management (ZSM) intelligent framework, that manage to instantiate, deploy, and govern a variety of such closed-loops (thus enabling zero-touch administration) of the 6G end-to-end user resource demanding network services across versatile management domains (from the resource layer, business and to the service layer, above). However, the hierarchical closed-loop automation (from top to bottom and the opposite) of the service handling operation of virtually numerous such closed loops, due to the extreme computational and networking resource-hungry 6G applications, together with the plethora of end-users is left as on open challenge. In such trivial occasions, it is almost non avoidable that there will exist intent conflicts between users and resources. These conflicts, if not detected at all, will create bottlenecks in the idle network conditions of 6G testbeds, deployments and interdomain scenarios, therefore causing disharmony in the ZSM concept. In this paperwork, we depict a ready-state software prototype solution that is based on a Private LLM (Qwen 2.5) that is properly and ad-hoc configured to detect such intent-based contradictions and alongside provide very astute eXplainability (XAI) features and quick conflict recognition. The results received appear quite promising.
Contemporary service architectures have become complex and challenging to maintain. The continuous demand for high performance, low-latency services in today’s intricate technological landscape necessitates robust, scalable and resource-efficient infrastructures. Acknowledging the challenges that arise, service providers aim to meet the growing demand within existing infrastructure by employing advanced cloud techniques. These approaches have emerged at the forefront, offering streamlined solutions for organizing service architectures while contending with ongoing maintenance requirements and the need for continuous improvement. The focus of service providers has shifted toward the integration of artificial intelligence (AI), both as a service and as a resource orchestrator. AI models have become popular, due to their ability to identify complex patterns and propose optimal solutions at the service level, particularly with regard to system resource utilization. The primary objective of this paper is to tackle the auto-scaling problem, so as to achieve optimal resource utilization in cloud-edge environments, using reinforcement learning (RL). We propose two complementary system models: an online Kubernetes-based auto-scaling model for real-time resource utilization and a novel offline RLOps pipeline for training RL models, designed to minimize system overhead during training and accelerate experimentation with multiple model candidates.
The Network Exposure Function (NEF) is a key component of the 5G and Beyond 5G (B5G) network, providing standardized access for third-party applications to network data and capabilities. Among these capabilities is the Event Monitoring API, which allows external applications to subscribe to specific network events. One such event is the reporting of user equipment (UE) location changes, enabling services that rely on real-time location awareness. In this context, this paper presents the design and implementation of an open-source, cloud-based NEF Event Monitoring Application Programming Interface (API) that adheres to relevant 3rd Generation Partnership Project (3GPP) standards. The proposed architecture minimizes integration complexity and provides a flexible framework for efficient deployment and utilization of future 6G location services, fostering innovation in intelligent environments and enabling a wide range of third-party applications.
Our previous work combined Wi-Fi FTM and PDR for indoor localization, but lacked prediction. We introduce a Spatio-Temporal Fusion Transformer (STFT) that, in simulation, matches LSTM in accuracy and mean error, while providing robust early-epoch performance in low-data regimes.