AI 中文总结
研究O-RAN架构下性能降级攻击难区分问题,提出C-RE-ACT框架,用结构不可知模型构建加权有向无环图,经图同构网络编码,在测试平台评估,能准确分离根本原因,提升LLM准确率及代理异常分类准确率。
AI 中文摘要
向O-RAN架构的转变是蜂窝安全的转折点,其开放性和模块化增加了攻击面。O-RAN联盟工作组11列出的安全威胁中,性能降级攻击占比最大,难以与操作事件区分。事件检测后,支持工程师需快速决定将事件工单路由到网络维护或升级到安全操作,这一分类阶段是事件响应生命周期中的关键瓶颈。为解决此问题,我们引入C-RE-ACT,一个旨在生成可操作事件报告的自动代理分类框架。C-RE-ACT使用结构不可知模型(SAM)在O-RAN指标上构建加权有向无环图(WDAG),通过与为ReAct代理提供支持的大语言模型(LLM)语言空间对齐的图同构网络(GIN)将因果拓扑编码为连续软令牌。我们在符合O-RAN的物理测试平台上对140个不同的性能降级实验进行评估。实证结果表明,因果排名在89%的实例中能在前三名候选者中分离出正确的根本原因。此外,图软提示将LLM在因果拓扑查询上的准确率从0.22(纯文本基线)提高到0.72。该自主代理对延迟异常的异常分类准确率为83%,对丢包异常的准确率为84%。
英文摘要
The shift to O-RAN architectures marks a turning point in cellular security, where increased openness and modularity directly translate into a broader attack surface. Among the security threats cataloged by the O-RAN Alliance Working Group 11, performance-degradation attacks constitute the largest class. These attacks induce packet losses and latency spikes that are hard to distinguish from operational events such as misconfigurations, transient congestion, or software regressions. Consequently, upon an adverse incident detection, support engineers must rapidly determine whether to route the corresponding incident ticket to network maintenance or escalate it to security operations. This triage phase represents a critical human-in-the-loop bottleneck in the incident response lifecycle. To address this vulnerability, we introduce C-RE-ACT (Causal RE-ACTing agent), an automated agentic triage framework designed to generate actionable incident reports. C-RE-ACT starts constructing a Weighted Directed Acyclic Graph (WDAG) over O-RAN metrics using the Structural Agnostic Model (SAM). The resulting causal topology is encoded into a continuous soft token via a Graph Isomorphism Network (GIN) aligned with the language space of the Large Language Model (LLM) powering a ReAct agent. We evaluate C-RE-ACT on a physical, O-RAN-compliant testbed across 140 distinct performance-degradation experiments. Empirical results demonstrate the causal ranking isolates the correct root cause within the top three candidates in 89% of instances. Furthermore, graph soft-prompting improves LLM accuracy on causal-topology queries from 0.22 (text-only baseline) to 0.72. The autonomous agent achieves anomaly classification accuracies of 83% for delay anomalies and 84% for packet-loss anomalies.