{"id":"7f9d3da8-5117-4ec6-bdd4-2e78bcbf6824","arxiv_id":"2505.18402","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":1.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A literature review and position statement on AI/ML security challenges and defenses in 5G and beyond networks, based on sources through 2022.","lead":"This paper reviews how AI and machine learning can both protect and threaten 5G and future 6G networks, covering attacks, vulnerabilities, and defense approaches. It is a useful orientation for security engineers and researchers looking for a concise map of the field up to 2022.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The literature-gap claim that existing 5G/6G AI-ML security surveys overlook accountability and trustworthiness is unsupported and is contradicted by the paper's own cited surveys (Nguyen 2021; Porambage 2021-2; Ylianttila 2020).","rationale":"The paper is a narrative survey; its mapping claims about 5G/6G attack surfaces and AI/ML threats are broadly consistent with the sources it cites. The most load-bearing original inference is that prior surveys overlook accountability and trustworthiness, because this gap is what justifies the paper's recommendations and its stated contribution. That inference is not derived from the reported material: there is no sampling frame, no inclusion/exclusion criteria, and no textual evidence that the cited surveys omit trust or accountability. In fact, the paper's own Section 3.1 summaries point to works explicitly titled and described around trust, security, and privacy, so the conclusion is in internal tension with its own citations. The reader's weakest assumption about unsystematic reference collection is closely related, but I would sharpen it to this specific unsupported comparative claim: the problem is not only possible missing references, but that the paper's headline gap statement is contradicted by references it already includes. Because the broad attack-surface claim remains adequately supported, this does not warrant rejection; it warrants keeping the conditional verdict and requiring the gap claim to be supported or qualified before relying on it for future-research directions.","tokens_in":16241,"tokens_out":5578,"duration_ms":46059,"concrete_test":"Run a reproducible literature check: search Scopus and Web of Science for (5G OR 6G) AND security AND (AI OR ML) AND survey for 2018-2022, take the top 20 results by citations, and code each for whether accountability or trustworthiness appears as a substantive theme. Also code the four surveys the paper itself cites in Section 3.1: Nguyen 2021, Porambage 2021-2, Ylianttila 2020, and Siriwardhana 2021. If more than 10 of the 20, or at least two of the four cited surveys, substantively discuss trust or accountability, then Section 5's claim that 'most existing surveys... overlook accountability and trustworthiness' is false, and the paper's motivating gap must be revised.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The broad assertion that softwarized 5G/6G expands the attack surface and that AI/ML is both a defense and a threat source is adequately supported by cited ENISA and academic sources; I do not dispute that part. The load-bearing weakness is the comparative gap claim used to motivate the paper's recommendations. Section 5 states that 'most of the existing surveys on AI/ML 5G and beyond security mainly focus on the performance of AI/ML models and their accuracy, they often overlook the accountability and trustworthiness of the models' decisions,' and Section 3.1's analysis repeats this. No selection methodology, inclusion criteria, or coding of surveyed papers is provided, so the claim is not established by the review. More importantly, the paper itself summarizes surveys that explicitly address trust, security, and privacy: Nguyen et al. 2021 ('Security and privacy for 6G'), Porambage et al. 2021-2 ('The Roadmap to 6G Security and Privacy'), Ylianttila et al. 2020 ('6G White Paper: Research Challenges for Trust, Security and Privacy'), and Siriwardhana et al. 2021 ('AI and 6G security'). If these representative prior surveys already treat trust and accountability as central, the claimed research gap—the basis for the paper's future directions—does not hold as stated. Secondary issues such as reference inconsistencies (e.g., [Shaik 2021] dated 2019) are distracting but not decisive; the unsupported comparative claim is the substantive correctness risk.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript is a survey of cybersecurity challenges and AI/ML opportunities for 5G and beyond (toward 6G) networks. It argues that softwarization and virtualization—NFV, SDN, VNFs, VMs—increase the attack surface; that AI/ML is essential for defense but also introduces new vulnerabilities such as data poisoning, model theft, and adversarial manipulation; and that most existing surveys focus on model performance and accuracy while overlooking accountability and trustworthiness. The paper reviews 5G threat taxonomies, 6G security challenges, ML components in 5G networks, and ML-based intrusion detection methods, and it closes with future directions emphasizing transparency, holistic security/privacy/trust, and adaptive defenses.","tokens_in":16501,"tokens_out":3688,"duration_ms":30462,"significance":"If its claims are accurate, the paper provides a useful accessible map of the 5G/6G AI/ML security landscape, drawing on ENISA reports and key academic surveys. Its descriptive core—that virtualization expands the attack surface and that AI/ML is both a defense and a threat source—is adequately supported by the cited sources. The paper also gives a clear taxonomy of ML components and of ML-based intrusion detection categories (packet-, flow-, and session-based). However, the paper's main forward-looking contribution is its gap claim about prior surveys overlooking accountability and trustworthiness, and that claim is not established by the manuscript as written. No systematic methodology, coding, or inclusion criteria are provided, and some of the paper's own cited surveys appear to address trust and privacy directly. As a literature review, its value depends on the accuracy of its synthesis; the descriptive parts are credible, but the central gap analysis needs substantiation.","major_comments":[{"comment":"The claim that 'most of the existing surveys on AI/ML 5G and beyond security mainly focus on the performance of AI/ML models and their accuracy, but they often overlook the accountability and trustworthiness' is a comparative literature-gap claim, but the manuscript provides no methodology to support it—no search strategy, inclusion criteria, or coding of surveyed papers. Moreover, the paper itself cites surveys that explicitly place trust, privacy, and security at their center: Nguyen et al. 2021 ('Security and privacy for 6G'), Porambage et al. 2021-2 ('The Roadmap to 6G Security and Privacy'), Ylianttila et al. 2020 ('6G White Paper: Research Challenges for Trust, Security and Privacy'), and Siriwardhana et al. 2021 ('AI and 6G security'). These citations directly undermine the stated gap. Since this gap claim is the basis for the paper's future research directions, it must either be substantiated with a systematic review procedure or reformulated as a narrower, supported observation about a specific subset of the surveyed literature.","section":"Section 3.1 and Section 5"},{"comment":"The introduction states that the report 'aims to provide a comprehensive overview' based on studies published until the end of 2022, but no systematic methodology is described. The reference list appears to be an ad hoc selection rather than a reproducible corpus; no databases, search strings, inclusion/exclusion criteria, or screening counts are reported. Without this information, the reader cannot assess whether important surveys were missed, which directly affects the validity of the gap analysis in Sections 3.1 and 5. The authors should either add a methodology subsection describing the review process or soften 'comprehensive' to 'selected' or 'representative.'","section":"Section 1"}],"minor_comments":[{"comment":"The citation [Shaik 2021] refers to a 2019 Black Hat publication (Shaik and Borgaonkar), and the text uses it to support a statement about 5G vulnerabilities; the year in the citation key and in the reference entry should be corrected to 2019.","section":"References; Section 2.3"},{"comment":"The reference key [Pham 2020] is used for two different works: one on whale optimization for resource allocation and one on green 6G networks. This ambiguity makes it impossible to determine which source is actually cited in Sections 3.2 and 3.3.","section":"References"},{"comment":"There are duplicate and inconsistent entries for the same Porambage works: [Pawani 2021] appears twice, and [Porambage 2021], [Porambage 2021-1], and [Porambage 2021-2] are not consistently distinguished. The reference list should be unified.","section":"References; Section 3"},{"comment":"There are typographical and grammatical issues, such as 'ba sed' in the abstract, 'SDNs’ susceptible' in Section 2.1, and 'control pane threats' which should read 'control plane threats.'","section":"Abstract and Section 2.1"},{"comment":"The statement that relying on open data is problematic because 'attackers can learn how models trained on these tend to work' is asserted without citation or elaboration; it should be supported by a reference or phrased as the authors' opinion.","section":"Section 4.4"}],"recommendation":"major_revision","confidential_remarks":"The paper is a survey, and its descriptive sections are reasonably faithful to the cited ENISA and academic sources. The main substantive issue is the unsupported literature-gap claim about trustworthiness and accountability, which is contradicted by several references the authors themselves cite. This is a load-bearing weakness because it motivates the paper's recommendations, but it is fixable by either adding a systematic review methodology or carefully qualifying the claim. The reference inconsistencies and typos are secondary but should be cleaned up. I recommend major revision rather than rejection because the core descriptive content is useful and the gap claim can be reframed within the manuscript's scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Here's my take. This is a narrative survey, not a research paper, and the useful part is the first half: a readable aggregation of known 5G/6G security challenges from ENISA and academic sources, plus a clear taxonomy of ML components, threats to those components, and a solid recap of ML-based intrusion detection (heavily drawn from Liu and Lang). A newcomer wanting a compact orientation to why softwarization expands the attack surface and why ML is a double-edged sword will get value from this.\n\nThe problem is the comparative gap claim in Sections 3.1 and 5: that 'most existing surveys on AI/ML 5G and beyond security mainly focus on accuracy and overlook accountability and trustworthiness.' The stress-test note is right. The paper itself summarizes Nguyen et al. 2021 on security and privacy for 6G, Porambage et al. 2021 on the roadmap to 6G security and privacy, and Ylianttila et al. 2020 on trust, security and privacy research challenges for 6G. Those are not obscure; they are the field's anchor surveys. So the claimed gap does not hold as stated, and since that gap is used to motivate the future directions, the recommendations rest on shaky ground. The absence of a selection methodology for the 'comprehensive overview' makes it worse—there is no way to know whether the reference set is representative.\n\nMinor issues: a few citation slips (Shaik dated 2021 but actually 2019; duplicate and garbled Pham entries), and the 'analysis' paragraphs are mostly opinion. Those are easily fixed and not fatal.\n\nVerdict: conditional, leaning reject unless the authors either drop the gap claim or support it with a systematic review. For a serious editor, a survey with this many unsupported comparative statements probably shouldn't be sent to review without a rewrite, but it isn't incoherent—the authors know the literature and the survey chapters themselves are sound. I'd accept it for review if the venue handles surveys, but expect major revision.","headline":"A readable but unsystematic survey whose central gap claim is contradicted by its own cited literature.","tokens_in":17076,"tokens_out":2348,"would_cite":false,"duration_ms":18698,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"AI/ML is 5G's primary defense and its newest attack surface.","keywords":["5G security","6G security","AI/ML cybersecurity","intrusion detection","NFV/SDN threats","threat landscape","trustworthy AI","machine learning attacks"],"falsifier":"A falsifier would be a peer-reviewed 5G/6G security survey published before 2023 that already centers on accountability, explainability, and trustworthiness of AI/ML decisions; finding even one would weaken the paper's gap analysis. Alternatively, a demonstration that a deployed 5G intrusion detection system has no ML-specific vulnerabilities would undermine the double-edged claim.","tokens_in":16020,"feed_emoji":"🛡️","tokens_out":6392,"duration_ms":47330,"temperature":0.7,"pith_summary":"This review argues that 5G and future 6G networks, by moving network functions into software (NFV and SDN), open a wider attack surface than previous generations. It maps that landscape—from DDoS and signaling storms to threats aimed at the machine-learning components themselves—and reviews how AI/ML is used for defense, especially in intrusion detection. Its central point is that most existing surveys judge AI/ML security models by accuracy alone and overlook accountability and trustworthiness. The paper concludes that 6G security must become transparent, holistic (security plus privacy plus trust), and adaptive, with online learning and explainable AI as key tools.","feed_headline":"AI/ML is 5G's primary defense and its newest attack surface","feed_subtitle":"Virtualization and machine learning expand the 5G attack space; trustworthiness has been overlooked.","key_machinery":"The organizing device is a layered map of where ML sits in a 5G/beyond network (physical, middle, application) paired with a threat taxonomy for ML components—denial of service, denial of detection, unfair resource use, and data leakage. This map lets the paper connect general 5G threats to ML-specific ones, and to structure the review of intrusion detection methods by data type (packet, flow, session) and learning paradigm (supervised, unsupervised). It is what turns a list of attacks into an argument that security and ML security cannot be separated.","core_discovery":"The paper's central claim is that AI/ML in 5G and beyond is double-edged: it is the most promising tool for defending virtualized networks, yet each ML component adds its own vulnerabilities—denial of service, denial of detection, unfair resource use, and sensitive data leakage—so that the security of the network and the security of the ML models become inseparable. It further claims that the existing survey literature concentrates on model performance and accuracy, leaving the accountability and trustworthiness of automated security decisions underexplored. If this is right, the next generation of 6G security research should shift from benchmark accuracy to transparent, explainable, adaptive, and privacy-preserving AI/ML systems.","pith_inferences":["If the paper's gap analysis is correct, a natural next step is a benchmark that scores 6G security frameworks on explainability and accountability alongside accuracy.","The paper leaves implicit that 'denial of detection' attacks target the security system itself; future work could model such threats as an adversarial game between the defender's ML and an attacker who knows the ML.","The call for online learning implies a tradeoff between adaptivity and stability in 5G/beyond security that the survey does not quantify.","Because the review covers literature through 2022, a reader could test its central claim by checking whether later surveys still overlook trustworthiness."],"forward_implications":["6G security design should treat the ML model itself as part of the attack surface, not only as the defense.","Intrusion detection for 5G and beyond will need online, adaptive learning rather than static labeled datasets to keep pace with evolving attacks.","Evaluation of 6G security solutions should include transparency and accountability metrics, not just detection accuracy.","Practical deployment will require safeguards such as data cleaning, regularization, differential privacy, and strict control of model outputs.","Quantum machine learning is proposed as a direction for predicting 6G vulnerabilities and building adaptive defenses."],"supporting_citations":[{"why":"Supplies the NFV/5G security challenge taxonomy and attack categorization used in the threat landscape section.","marker":"[ENISA 2022]"},{"why":"Provides the taxonomy of threats to ML components in 5G: denial of service, denial of detection, unfair resource use, and data leakage.","marker":"[Suomalainen 2020]"},{"why":"Supplies the classification of ML-based intrusion detection methods and the three practical challenges of labeled data, accuracy, and efficiency.","marker":"[Liu 2019]"},{"why":"Backs the claim that scarcity of real training datasets is a major challenge for ML in 5G and beyond.","marker":"[Morocho-Cayamcela 2019]"},{"why":"Grounds the claim that there is no common understanding of what constitutes an attack on AI/ML systems.","marker":"[ETSI, 2020]"},{"why":"Provides the three-category 5G/beyond threat landscape: pre-6G issues, 6G architecture threats, and 6G technology threats.","marker":"[Siriwardhana 2021]"},{"why":"Lists the fundamental 5G security challenges and principal vulnerabilities cited in Section 2.","marker":"[Hassan 2022]"}],"fun_headline_variants":["AI/ML: 5G's double-edged sword for cybersecurity","5G's AI/ML is both the shield and the attack vector","AI/ML for 5G security: the trustworthiness challenge","In 5G, AI/ML is a new attack surface and defense","AI/ML in 5G: protecting the network, risking the models"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the set of surveys and reports gathered through 2022 is representative enough to support the claim that existing AI/ML security research overlooks accountability and trustworthiness.","fun_headline_variants_meta":{"raw":{"variants":["AI/ML: 5G's double-edged sword for cybersecurity","5G's AI/ML is both the shield and the attack vector","AI/ML for 5G security: the trustworthiness challenge","In 5G, AI/ML is a new attack surface and defense","AI/ML in 5G: protecting the network, risking the models"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000925,"raw_usage":{"total_tokens":3958,"prompt_tokens":934,"completion_tokens":3024,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":550,"completion_tokens_details":{"reasoning_tokens":2928}},"tokens_in":550,"tokens_out":3024,"duration_ms":16509,"temperature":1.0,"reasoning_tokens":2928,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T14:31:08.035779+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A falsifier would be a peer-reviewed 5G/6G security survey published before 2023 that already centers on accountability, explainability, and trustworthiness of AI/ML decisions; finding even one would weaken the paper's gap analysis. Alternatively, a demonstration that a deployed 5G intrusion detection system has no ML-specific vulnerabilities would undermine the double-edged claim.","supporting_citations":[{"cited_title":"Major Security Challenges in 5G Network","cited_arxiv_id":null,"evidence_quote":"Lists the fundamental 5G security challenges and principal vulnerabilities cited in Section 2."}],"review_version":1}