arXiv Machine Learning

Explainability Boosted Anomaly Detection Framework for O-RAN based NextG Networks

arXiv:2608. 14826v1 Announce Type: cross Abstract: The wireless networks have historically faced significant security vulnerabilities, necessitating advanced anomaly detection mechanisms, especially as networks evolve towards 6G and beyond.

arXiv Machine Learning
Sep 14

Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks

The paper introduces ExCYDER, an explainable AI framework for anomaly detection in Distributed Energy Resource (DER) networks. It combines LightGBM with SHAP to self-verify alerts, ensuring that each detection aligns with feature‑attribution evidence. Experiments on a realistic DNP3 dataset show over 98% detection accuracy, 44.6% rule‑SHAP consistency, 14.5 ms SHAP latency per alert, and minimal confidence deviation, while distinguishing coherent from inconsistent alerts without sacrificing accuracy.

By Damilola Popoola, Souradeep Bhattacharya, Manimaran Govindarasu
arXiv AI
Aug 17

Interactive Analysis of Global Explanations using Aggregated Class Activation Maps for Network Data

arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.

By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
arXiv Machine Learning
Aug 7

Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining

arXiv:2608. 05605v1 Announce Type: cross Abstract: Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems.

By Mohammad Arafath Uddin Shariff, Byrav Ramamurthy
arXiv AI
Jul 14

Closing the Loop: An Access-Control Architecture for Automated, Anomaly-Driven Network Revocation in IoT Deployments

arXiv:2607. 11649v1 Announce Type: cross Abstract: Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate.

By Muhammet Emir Korkmaz, Kemal Bicakci, Yusuf Uzunay
arXiv Machine Learning
Aug 27

FedQoS: Federated QoS-Risk Learning for Heterogeneous Indoor-Outdoor Access Selection

FedQoS is a federated learning framework that predicts future QoS failure probabilities for candidate access links in dynamic indoor‑outdoor environments, enabling reliable access‑node selection without centralizing user data. Each access node trains locally on its network logs, while a global QoS‑risk predictor is built through federated aggregation. Simulations using physics‑based synthetic datasets show that FedQoS reduces QoS‑failure rates compared to signal‑based and historical‑QoS heuristics, achieving near‑centralized performance even under non‑IID data conditions.

By Nguyen Van Thieu, Ti Ti Nguyen, Ons Aouedi, Zerihun Huruy, Vu Nguyen Ha, Symeon Chatzinotas
arXiv Machine Learning
Sep 14

On Identifying Adversarial Intent Injection in AI-Native 6G Networks

The paper introduces a threat model for malicious intent injection in AI‑native 6G networks and examines four injection strategies: stealth‑mode, random distribution, increasing frequency, and decreasing frequency. It proposes a dual‑path detection framework combining a CNN with TF‑IDF features for supervised detection and an AutoEncoder trained on benign data for one‑class detection. Evaluation shows the framework achieves higher accuracy (0.97) and F1‑score (0.98) than the state‑of‑the‑art baseline.

By Nilesh Chakraborty, Petar Djukic, Burak Kantarci
arXiv Machine Learning
5d ago

Probabilistic Robustness-driven Universal Adversarial Perturbations with Explainability against Deep Reinforcement Learning-based Intrusion Detection System

The paper introduces a new method for generating universal adversarial perturbations (UAPs) against deep reinforcement learning (DRL)-based intrusion detection systems (IDS). It leverages Probabilistic Robustness (PR) as a post‑hoc metric to guide UAP creation, integrating PR directly into the optimization objective. The authors further develop PX‑UAP, which incorporates explainable AI (XAI) to shape perturbations within realistic domain constraints, and provide a theoretical analysis of its design. Experiments show PX‑UAP outperforms existing UAP techniques in attack effectiveness.

By Hongsen Zhang, Lu Zhang, Mingjing Xu, Yi Zhang, Gregory Epiphaniou, Carsten Maple