O-RAN enables a disaggregated baseband stack with programmable functions that communicate over standardized open interfaces. The same openness that enables multi-vendor composition also expands the attack surface across logically decoupled tiers that make up the compute continuum. Among these threats, Denial-of-Service and performance-degradation attacks, which account for the majority of catalogued O-RAN threats, are particularly difficult to detect. Traditional Time-Series Anomaly Detection (TSAD) methods fail in this new regime where labelled baselines are scarce, threats evolve faster than detectors can be retrained, and the high-dimensional multivariate telemetry overwhelms monolithic inference models. To address these challenges, we present DAST, a zero-shot multi-agent framework for cross-interface anomaly detection in O-RAN that chains a three-stage VLM → LLM → VLM pipeline. DAST converts multivariate KPI streams into visual representations, scores textual per-interface descriptions against O-RAN domain knowledge, and verifies suspects on high-resolution heatmaps to output the problematic interfaces, the anomalous time intervals, an indicative O-RAN WG11-aligned operational impact rating and the decision rationale. We evaluate DAST on real network traces collected from an O-RAN testbed under representative performance degradation scenarios, achieving 0.910 F1-Score and 0.843 Accuracy, outperforming state-of-the-art TSAD baselines.
As 6G networks grow more complex, managing resources and orchestrating services across diverse, dynamic, and energy-efficient environments becomes challenging. This paper presents a programmable Orchestration-as-a-Service (OaaS) Framework from the 6G-Cloud project that enables dynamic, scalable, and intelligent orchestration. The framework separates service orchestration from resource orchestration, supports network service-agnostic management, and integrates AI-driven optimization, digital twins (DT), and Cloud Continuum technologies. Finally, we demostrate the functionality and feasibility of the proposed architecture through an early-stage implementation, where an AI-powered use case for dynamic resource orchestration is validated, showing significant improvements in power efficiency and proactive resource scaling compared to baseline methods.
The shift to O-RAN architectures marks a turning point in cellular security, where increased openness and modularity directly translate into a broader attack surface. Among the security threats cataloged by the O-RAN Alliance Working Group 11, performance-degradation attacks constitute the largest class. These attacks induce packet losses and latency spikes that are hard to distinguish from operational events such as misconfigurations, transient congestion, or software regressions. Consequently, upon an adverse incident detection, support engineers must rapidly determine whether to route the corresponding incident ticket to network maintenance or escalate it to security operations. This triage phase represents a critical human-in-the-loop bottleneck in the incident response lifecycle. To address this vulnerability, we introduce C-RE-ACT (Causal RE-ACTing agent), an automated agentic triage framework designed to generate actionable incident reports. C-RE-ACT starts constructing a Weighted Directed Acyclic Graph (WDAG) over O-RAN metrics using the Structural Agnostic Model (SAM). The resulting causal topology is encoded into a continuous soft token via a Graph Isomorphism Network (GIN) aligned with the language space of the Large Language Model (LLM) powering a ReAct agent. We evaluate C-RE-ACT on a physical, O-RAN-compliant testbed across 140 distinct performance-degradation experiments. Empirical results demonstrate the causal ranking isolates the correct root cause within the top three candidates in 89
5G cellular systems are currently being deployed worldwide delivering the promised unprecedented levels of throughput and latency to hundreds of millions of users. At such scale and reach, security is crucial. Consequently, the 5G standard includes a new series of features to improve the security of its predecessors (i.e., 3G and 4G). In this work, we evaluate the security of currently deployed 5G commercial networks in Europe and North America. Specifically, by collecting 5G signaling traffic in the wild in several cities in Spain, Germany, France, Canada, and the USA, we i) fact-check which 5G security enhancements are implemented in current deployments, ii) provide a rich overview of the implementation status of each 5G security feature in a selection of 5G commercial networks in Europe and North America and compare it with previous results in China, iii) analyze the implications of optional features not being deployed, and iv) discuss on the still remaining 4G-inherited vulnerabilities. Our findings indicate that the rollout of 5G security features in the analyzed commercial networks is still a work in progress. On the one hand, several networks continue to rely on 4G for their core network operations, which hinders the deployment of new security features (e.g., SUCI) and, on the other hand, fully-fledged 5G deployments lack mandatory security measures such as GUTI reallocation after paging. Moreover, we find that some operators fail to provide proper temporary identifier randomization, in both 4G and 5G networks. Some of the obtained results are aligned with results previously reported from China [1] and keep the European and North American studied networks vulnerable to some 4G attacks, during their migration period from 4G to 5G. Conversely, studied networks deployed in North America exhibit stronger adherence to 5G security standards, with near-complete compliance observed, in contrast to deployments in China and Europe, where comparatively lower compliance levels have been observed.
The evolution of cloud computing towards a cloud continuum, including cloud, edge, and far-edge resources, is revolutionizing the deployment, management, and orchestration of Network Services (NSs) and applications. Traditional, centralized orchestration approaches are increasingly inadequate for handling the complexity, scale, and dynamic nature of this continuum. In this paper, we present a data-driven approach for AI-powered service orchestration based on the European 6G-CLOUD project. Specifically, we introduce the Decentralized Service Orchestrator (DSO) framework, an AI-powered, decentralized orchestration model that leverages the capabilities of the Artificial Intelligence and Machine Learning Framework (AI/MLF) to enable intelligent, autonomous, and scalable service lifecycle management across heterogeneous environments. Key contributions include the detailed architecture of the DSO, its workflows, and its integration with the Cloud Continuum and with an AI/MLF that manage the AI lifecycle, enabling models provision to the different components. By enabling decentralized AI-driven decision-making, this framework enhances service reliability, scalability, operational efficiency, and innovation acceleration, paving the way for next-generation cloud continuum orchestration.
The Service-Based Architecture (SBA) has been successfully employed in the 5G Core since Release 15. Its modular and loosely coupled approach to network function interaction, based on the producer/consumer paradigm, perfectly pairs with the softwarization trend mobile networks have undergone over the last decade. Still, the Radio Access Network (RAN) did not leverage this approach, retaining the traditional Protocol-Based Architecture (PBA). In this paper, we make the case for adopting the SBA in the RAN, a transition we argue is both advantageous and feasible. We first present a comprehensive analysis of the benefits, such as enhanced flexibility and innovation, while also considering potential implementation challenges. Then, we detail how the SBA can be used to provide two exemplary procedures currently performed using the PBA, showing the feasibility of a fully service-based 5G network architecture.
Localization of in-body devices is beneficial for Gastrointestinal (GI) diagnosis and targeted treatment. Traditional methods such as imaging and endoscopy are invasive and limited in resolution, highlighting the need for innovative alternatives. This study presents an experimental framework for Radio Frequency (RF)-backscatter-based in-body localization, inspired by the ReMix approach, and evaluates its performance in real-world conditions. The experimental setup includes an in-body backscatter device and various off-body antenna configurations to investigate harmonic generation and reception in air, chicken and pork tissues. The results indicate that optimal backscatter device positioning, antenna selection, and gain settings significantly impact performance, with denser biological tissues leading to greater attenuation. The study also highlights challenges such as external interference and plastic enclosures affecting propagation. The findings emphasize the importance of interference mitigation and refined propagation models to enhance performance.
A new generation of open and disaggregated Radio Access Networks (RANs) enabling multi-vendor, flexible, and cost-effective deployments is being promoted by the Open Radio Access Network (O-RAN) Alliance. However, this new level of disaggregation in the RAN also entails new security risks that must be carefully addressed. The O-RAN Alliance has established Working Group 11 (WG11) to ensure that the new specifications are secure by design. Acknowledging the new security challenges arising from the expanded threat surface, O-RAN WG11 provides procedures to identify threats and assess and mitigate risks. Reportedly, as of 2024, 60% of found risks are related to Denial of Service (DoS) and performance degradation. Therefore, in this work, we analyse a vanilla O-RAN deployment and evaluate the endurance of different O-RAN interfaces under attacks in scenarios involving DoS and performance degradation. To do so, we use a reference O-RAN open source deployment to report, risks found, weak points, and counter-intuitive recommended design choices for both control plane (A1, E2, and F1-c) and user plane (F1-u) interfaces. Consequently, we map O-RAN WG11’s threat model and risk assessment methodology to our considered DoS and performance degradation scenarios, and dissect existing threats and potential attacks over O-RAN interfaces that may compromise the security of O-RAN architectural deployments. Finally, we identify mechanisms to mitigate risks and discuss approaches aimed at improving the robustness of future O-RAN networks.
Open and virtualized Radio Access Networks (vRANs) are breeding a new market with unprecedented opportunities. However, carrier-grade vRANs today are expensive and energy-hungry, as they rely on hardware accelerators (HAs) that are dedicated to individual distributed units (DUs). In this paper, we argue that sharing pools of heterogeneous processors among DUs leads to more cost- and energy-efficient vRANs. We then design CloudRIC, a system that, powered by lightweight data-driven models, meets specific reliability targets while (8) coordinating access between DUs and heterogeneous computing infrastructure; and (88) assisting DUs with compute-aware radio scheduling procedures. Experiments on a GPU-accelerated O-Cloud show that CloudRIC can achieve, respectively, 3x and 15x mean gains in energy- and cost-efficiency under real RAN workloads while ensuring 99.999% reliability even in dense scenarios.
As research in mobile networks is already transitioning from 5G to 6G, we identify a set of fundamental barriers in the current 5G architecture that limit efficient and global operations. We propose innovative architectural solutions that can remove such barriers and lay the foundation for 6G systems. Specifically, we introduce three novel architectural components: the Global Service-Based Architecture (GSBA), the Compute Continuum Layer (CCL), and the Zero-Trust Layer (ZTL). These components collectively aim to enhance network efficiency, security, and scalability, addressing future mobile networks’ dynamic and demanding needs. Furthermore, we discuss the integration of Network Intelligence (NI) that exploits the afore-mentioned architectural innovations to ensure global operations and services. Ultimately, our proposed vision entails a more adaptive, secure, and intelligent network architecture, setting the groundwork for the next generation of mobile networks.
Among the foretold claims of the transition from 5G to 6G, Beyond-Visual-Line-of-Sight (BVLoS) drone operation has emerged as a prominent Internet-of-Robots enabler. However, safety concerns have been raised since BVLoS imposes strict requirements on performance and dependability on the technology, and requires robust regulatory frameworks. While current 5G technologies promise to meet the performance requirements in terms of throughput and latency, there is a lack of studies regarding how to achieve full reliability in practice. To address this challenge, the research community is actively working on open-source projects that allow for experimental validation in the field. Fortunately, new Open Radio Access Network (O-RAN) standards are paving the way for such approaches in an integrated, native manner. In this work, we deploy a state-of-the-art 5G O-RAN open-source BVLoS operational system, report current limitations, and address them via advanced capabilities natively available in O-RAN: Slicing. Our proposed deployment minimizes trajectory errors due to 5G link congestion and keeps latency well below the 3GPP limits defined for BVLoS operation. Finally, we discuss on the challenges ahead and the opportunities that 5G O-RAN-enabled networks may bring to BVLoS drone operation.
5G and B5G/6G foundations heavily rely on virtualization technologies, and virtualized Radio Access Networks (vRANs) are one of their major keystones. However, while vRANs have been traditionally suffering from significant hardware/software coupling, next generation vRANs aim for open, standardized interfaces, and multi-vendor, interoperable components to enable truly flexible deployments following the cloud-native principles. In this line, the O-RAN Alliance is promoting a novel Open RAN architecture to further boost flexibility and cost efficiency. In order to reduce costs and effectively achieve the promised disaggregation levels, O-RAN must ensure shared, integrated transport networks in opposition to dedicated, overprovisioned links from traditional approaches. However, keeping deterministic performance requirements in such cost-effective networks (i.e., general-purpose Ethernet networks), especially in those interfaces that are time-critical, is a challenge. In this article, we review the most relevant Time Sensitive Networking (TSN) standards that may bring compelling benefits to O-RAN, (i.e., IEEE 802.1CM, IEEE 802.1Qbu, and IEEE 802.1Qbv) for providing determinism over cost-efficient networks. We explore the design space for a TSN-enabled O-RAN architecture, reporting on the requirements and deployment options and finally, we discuss on the opportunities and challenges that O-RAN will face when adopting TSN technologies to fully open the vRAN ecosystem.
As network complexity escalates, there is an increasing need for more sophisticated methods to manage and operate these networks, focusing on enhancing efficiency, reliability, and security. A wide range of Artificial Intelligence (AI)/Machine Learning (ML) models are being developed in response. These models are pivotal in automating decision-making, conducting predictive analyses, managing networks proactively, enhancing security, and optimizing network performance. They are foundational in shaping the future of networks, collectively forming what is known as Network Intelligence (NI). Prominent Standard-Defining Organizations (SDOs) are integrating NI into future network architectures, particularly emphasizing the closed-loop approach. However, existing methods for seamlessly integrating NI into network architectures are not yet fully effective. This paper introduces an in-depth architectural design for a Network Intelligence Stratum (NI Stratum). This stratum is supported by a novel end-to-end NI orchestrator that supports closed-loop NI operations across various network domains. The primary goal of this design is to streamline the deployment and coordination of NI throughout the entire network infrastructure, tackling issues related to scalability, conflict resolution, and effective data management. We detail exhaustive workflows for managing the NI lifecycle and demonstrate a reference implementation of the NI Stratum, focusing on its compatibility and integration with current network systems and open-source platforms such as Kubernetes and Kubeflow, as well as on its validation on real-world environments. The paper also outlines major challenges and open issues in deploying and managing NI.
5G cellular systems are slowly being deployed worldwide delivering the promised unprecedented levels of throughput and latency to hundreds of millions of users. At such scale security is crucial, and consequently, the 5G standard includes a new series of features to improve the security of its predecessors (i.e., 3G and 4G). In this work, we evaluate the actual deployment in practice of the promised 5G security features by analysing current commercial 5G networks from several European operators. By collecting 5G signalling traffic in the wild in several cities in Spain, we i) fact-check which 5G security enhancements are actually implemented in current deployments, ii) provide a rich overview of the implementation status of each 5G security feature in a wide range of 5G commercial networks in Europe and compare it with previous results in China, iii) analyse the implications of optional features not being deployed, and iv) discuss on the still remaining 4G-inherited vulnerabilities. Our results show that in European 5G commercial networks, the deployment of the 5G security features is still on the works. This is well aligned with results previously reported from China [16] and keeps these networks vulnerable to some 4G attacks, during their migration period from 4G to 5G.
Lidia Fuentes合作论文数Dpto. Lenguajes y Ciencias de la Computaci??n;ETSI Telecomunicaci??n;Universidad de M??laga2