arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.07976cs.CRcs.NI

量化运营商侧5G/O-RAN配置文件的隐私姿态

Quantifying the Privacy Posture of Operator-Side 5G/O-RAN Profiles

Nikolaos Kekatos, Apostolos Valiakos, Alexios Lekidis, Elpiniki Papageorgiou

首次发表
浏览论文内容

中文总结 AI 辅助

本研究量化运营商侧5G/O-RAN配置文件匿名化后的重新识别风险,提出复合隐私姿态指数(PPI),发现泛化与抑制结合能有效降低风险,但抑制损害少数类效用,PPI更适合作为监管摘要而非安全边界。

中文摘要 AI 辅助

源自5G/ORAN流量的运营商侧网络配置文件携带个人数据,如临时用户标识符、切片级KPI和控制面信令,在发布给联邦学习聚合器、威胁情报交换或机器学习训练管道之前必须进行匿名化处理。我们研究了标准运营商侧匿名化后残留的重新识别风险。我们使用k-匿名性、l-多样性和t-接近性量化隐私姿态,将它们聚合为复合隐私姿态指数(PPI),并在内部PCAP捕获和公共爱达荷实验室5GAD语料库上,在完全准标识符语法边界和两个模拟对手下,测量八种转换配置下的残留重新识别。评估规模适中,我们将趋势视为指示性而非确定性。出现了三个发现。仅假名化使重新识别保持不变;当准标识符通过泛化进行粗化,并可选地与抑制结合时,才会产生实质性的隐私增益。随后的下游分类任务表明,重度抑制的发布保留了多数类效用,但牺牲了大部分少数类召回率,这是聚合指标所隐藏的成本。最后,基于标准kmin的PPI与披露边界仅适度相关,与部分知识攻击完全不相关,而平均类大小变体PPI与所有三种披露/攻击度量强相关;因此,我们将PPI视为面向监管者的摘要,而非安全边界。这些配置文件由被动运营商侧监控和基于规则的深度包检测产生;我们的贡献是隐私量化层,它计算这些指标,应用转换策略,并通过可检查的仪表板展示两者。

英文摘要

Operator-side network profiles derived from 5G/ORAN traffic carry personal data such as ephemeral subscriber identifiers, slice-level KPIs, and control-plane signalling, and must be anonymised before release to a federated-learning aggregator, threat-intelligence exchange, or ML training pipeline. We study how much re-identification risk remains after standard operator-side anonymisation. We quantify privacy posture with k-anonymity, l-diversity and t-closeness, aggregate them into a composite Privacy-Posture Index (PPI), and measure residual re-identification across eight transformation configurations on internal PCAP captures and the public Idaho Labs 5GAD corpus, under a full-QI syntactic bound and two simulated adversaries. The evaluation is modest in scale, and we read its trends as indicative rather than definitive. Three findings emerge. Pseudonymisation alone leaves re-identification unchanged; material privacy gains arise when quasi-identifiers are coarsened through generalisation, optionally combined with suppression. A downstream classification task then shows that suppression-heavy releases retain majority-class utility but sacrifice much of their minority-class recall, a cost the aggregate metrics hide. Finally, the standard kmin-based PPI correlates only modestly with the disclosure bound and not at all with the partial-knowledge attack, whereas a mean-class-size variant PPI correlates strongly with all three disclosure/attack measures; we therefore read PPI as a regulator-facing summary, not a security bound. The profiles are produced by passive operator-side monitoring with rule-based DPI; our contribution is the privacy-quantification layer that computes these metrics, applies the transformation policy, and exposes both through an inspectable dashboard.

发表机构

  • University of Thessaly(塞萨利大学)

机构由 AI 辅助整理,请以论文原文为准。

↑