ADAPTIVE HYBRID MACHINE LEARNING MODEL FOR DETECTING KNOWN AND ZERO-DAY ATTACKS IN 5G NETWORKS
ავტორი: Azamat Imanbayev, Roman Odarchenko, Sakhybai Tynymbayev, Rat Berdibayev
ორგანიზაცია: Kazakh-British Technical University, State University “Kyiv Aviation Institute”, International Information Technology University, Almaty University of Power Engineering and Telecommunications
კატეგორია:
საკვანძო სიტყვები: 5G security, intrusion detection, zero-day attacks, incremental learning, Adaptive Random Forest, autoencoder, CTGAN, 5G-NIDD, NWDAF, NEF
აბსტრაქტი. The proliferation of 5G networks introduces a new threat landscape characterized by ultra-low latency services, massive device density, and software-driven network functions. These properties make static signature-based intrusion detection systems insufficient for detecting evolving and previously unseen attacks. This paper presents an adaptive hybrid intrusion detection system (IDS) for 5G networks combining an incremental Adaptive Random Forest (ARF) classifier, a bottleneck autoencoder, and a Conditional Tabular GAN (CTGAN) augmentation module. Experiments use the public 5G-NIDD dataset — 1,215,016 flows after cleaning, nine classes — treated throughout as the 5G Network Intrusion Detection Dataset (not the 3GPP Non-IP Data Delivery service). Two strictly separate evaluation tasks are defined: (i) multiclass known-attack classification and (ii) binary anomaly detection for zero-day simulation. The Dn(x) discriminator score used in the fusion function is extracted offline from the pre-trained CTGAN discriminator and embedded as a static scoring function at inference; the GAN generator is not used at runtime. Under the multiclass task the hybrid model achieves weighted F1 = 0.98 (macro F1 = 0.97 ± 0.01 over five random seeds). Under the binary zero-day task, using a full leave-one-attack-type-out protocol across all eight attack classes, macro F1 = 0.86 ± 0.02. Per-class results, a condensed confusion matrix, fusion-weight ablation, and latency percentiles (mean / p95 / p99) are reported. The architecture maps onto 3GPP NWDAF logical functions and NEF northbound APIs.
ბიბლიოგრაფია
Goodfellow, I. J., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. (2014). Generative adversarial nets. Advances in Neural Information Processing Systems, 27, 2672–2680.
Gomes, H. M., Bifet, A., Read, J., Barddal, J. P., Enembreck, F., Pfahringer, B., Holmes, G., and Abdessalem, T. (2017). Adaptive random forests for evolving data stream classification. Machine Learning, 106, 1469–1495. https://doi.org/10.1007/s10994-017-5642-8
3GPP. (2025c). TS 29.522: 5G System; Network Exposure Function Northbound APIs; Stage 3, Release 18. 3rd Generation Partnership Project.
3GPP. (2025a). TS 23.501: System architecture for the 5G System (5GS), Release 18. 3rd Generation Partnership Project
3GPP. (2025b). TS 23.288: Architecture enhancements for 5G System (5GS) to support network data analytics services, Release 18. 3rd Generation Partnership Project.
Buczak, A. L., and Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys and Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
Ahmad, I., Kumar, T., Liyanage, M., Okwuibe, J., Ylianttila, M., and Gurtov, A. (2018). Overview of 5G security challenges and solutions. IEEE Communications Standards Magazine, 2(1), 36–43. https://doi.org/10.1109/MCOMSTD.2018.1700063
Samarakoon, S., Siriwardhana, Y., Porambage, P., Liyanage, M., Chang, S.-Y., Kim, J., Kim, J., and Ylianttila, M. (2022). 5G-NIDD: A comprehensive network intrusion detection dataset generated over 5G wireless network. arXiv:2212.01298. https://doi.org/10.48550/arXiv.2212.01298
Siriwardhana, Y., Samarakoon, S., Porambage, P., Liyanage, M., Chang, S.-Y., Kim, J., Kim, J., and Ylianttila, M. (2025). Descriptor: 5G Wireless Network Intrusion Detection Dataset (5G-NIDD). IEEE Data Descriptions. https://doi.org/10.1109/IEEEDATA.2025.3592888
Moustafa, N., and Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Military Communications and Information Systems Conference (MilCIS), 1–6. https://doi.org/10.1109/MilCIS.2015.7348942
Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proc. 4th ICISSP, 108–116. https://doi.org/10.5220/0006639801080116
Losing, V., Hammer, B., and Wersing, H. (2018). Incremental on-line learning: A review and comparison of state of the art algorithms. Neurocomputing, 275, 1261–1274. https://doi.org/10.1016/j.neucom.2017.06.084
Andresini, G., Appice, A., De Rose, L., and Malerba, D. (2021). CAFE: Concept drift adaptation framework for network intrusion detection applying encoder-decoder. Neural Computing and Applications, 33, 17011–17030. https://doi.org/10.1007/s00521-021-06259-5
Sakurada, M., and Yairi, T. (2014). Anomaly detection using autoencoders with nonlinear dimensionality reduction. MLSDA Workshop at ACM SenSys, 4–11. https://doi.org/10.1145/2689746.2689747
Xu, L., Skoularidou, M., Cuesta-Infante, A., and Veeramachaneni, K. (2019). Modeling tabular data using conditional GAN. Advances in Neural Information Processing Systems, 32, 7333–7343.
Lin, Z., Shi, Y., and Xue, Z. (2022). IDSGAN: Generative adversarial networks for attack generation against intrusion detection. Advances in Knowledge Discovery and Data Mining (PAKDD), LNAI 13282, 79–91. https://doi.org/10.1007/978-3-031-05981-0_7
Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., and Janicke, H. (2022). Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access, 10, 40281–40306. https://doi.org/10.1109/ACCESS.2022.3165809
Montiel, J., Halford, M., Mastelini, S. M., Bolmier, G., Sourty, R., Vaysse, R., Zouitine, A., Gomes, H. M., Read, J., Abdessalem, T., and Bifet, A. (2021). River: Machine learning for streaming data in Python. Journal of Machine Learning Research, 22(110), 1–8.
Gulrajani, I., Ahmed, F., Arjovsky, M., Dumoulin, V., and Courville, A. (2017). Improved training of Wasserstein GANs. Advances in Neural Information Processing Systems, 30.
3GPP. (2025d). TS 33.501: Security architecture and procedures for 5G System, Release 18. 3rd Generation Partnership Project.
Menu