Robust Anomaly Detection in O-RAN: Leveraging LLMs against Data Manipulation Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dayaratne, Thusitha, Pham, Ngoc Duy, Vo, Viet, Lai, Shangqi, Abuadbba, Sharif, Suzuki, Hajime, Yuan, Xingliang, Rudolph, Carsten
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915439872835584
author Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
author_facet Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
contents The introduction of 5G and the Open Radio Access Network (O-RAN) architecture has enabled more flexible and intelligent network deployments. However, the increased complexity and openness of these architectures also introduce novel security challenges, such as data manipulation attacks on the semi-standardised Shared Data Layer (SDL) within the O-RAN platform through malicious xApps. In particular, malicious xApps can exploit this vulnerability by introducing subtle Unicode-wise alterations (hypoglyphs) into the data that are being used by traditional machine learning (ML)-based anomaly detection methods. These Unicode-wise manipulations can potentially bypass detection and cause failures in anomaly detection systems based on traditional ML, such as AutoEncoders, which are unable to process hypoglyphed data without crashing. We investigate the use of Large Language Models (LLMs) for anomaly detection within the O-RAN architecture to address this challenge. We demonstrate that LLM-based xApps maintain robust operational performance and are capable of processing manipulated messages without crashing. While initial detection accuracy requires further improvements, our results highlight the robustness of LLMs to adversarial attacks such as hypoglyphs in input data. There is potential to use their adaptability through prompt engineering to further improve the accuracy, although this requires further research. Additionally, we show that LLMs achieve low detection latency (under 0.07 seconds), making them suitable for Near-Real-Time (Near-RT) RIC deployments.
format Preprint
id arxiv_https___arxiv_org_abs_2508_08029
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Robust Anomaly Detection in O-RAN: Leveraging LLMs against Data Manipulation Attacks
Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
Cryptography and Security
Emerging Technologies
Machine Learning
The introduction of 5G and the Open Radio Access Network (O-RAN) architecture has enabled more flexible and intelligent network deployments. However, the increased complexity and openness of these architectures also introduce novel security challenges, such as data manipulation attacks on the semi-standardised Shared Data Layer (SDL) within the O-RAN platform through malicious xApps. In particular, malicious xApps can exploit this vulnerability by introducing subtle Unicode-wise alterations (hypoglyphs) into the data that are being used by traditional machine learning (ML)-based anomaly detection methods. These Unicode-wise manipulations can potentially bypass detection and cause failures in anomaly detection systems based on traditional ML, such as AutoEncoders, which are unable to process hypoglyphed data without crashing. We investigate the use of Large Language Models (LLMs) for anomaly detection within the O-RAN architecture to address this challenge. We demonstrate that LLM-based xApps maintain robust operational performance and are capable of processing manipulated messages without crashing. While initial detection accuracy requires further improvements, our results highlight the robustness of LLMs to adversarial attacks such as hypoglyphs in input data. There is potential to use their adaptability through prompt engineering to further improve the accuracy, although this requires further research. Additionally, we show that LLMs achieve low detection latency (under 0.07 seconds), making them suitable for Near-Real-Time (Near-RT) RIC deployments.
title Robust Anomaly Detection in O-RAN: Leveraging LLMs against Data Manipulation Attacks
topic Cryptography and Security
Emerging Technologies
Machine Learning
url https://arxiv.org/abs/2508.08029