{"id":"150ff44f-d88b-48df-b57d-e89e608e27a7","arxiv_id":"2607.09659","paper_version":1,"verdict":"CONDITIONAL","confidence":"LOW","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Benign private-5G connectivity variations raise false positives in ML IDS for encrypted OPC UA traffic and often coincide with control-plane activity.","lead":"Legitimate private-5G connectivity events can raise false positives in ML intrusion detectors watching encrypted OPC UA industrial traffic. The work flags that control-plane context is needed so operators do not treat normal radio events as attacks.","discovery_kind":"extension","skeptic_critique":{"model":"grok-4.5","headline":"Abstract-only review cannot isolate whether benign connectivity events are the causal driver of elevated IDS false positives versus confounds such as traffic-volume shifts or labeling artifacts.","rationale":"The Reader correctly flags that the abstract asserts a causal impact of benign connectivity variations while providing no methods, numbers, or artifacts with which to test isolation from confounds. That isolation is load-bearing for the strongest claim; without it the claim reduces to a temporal coincidence observation. Because the full text is unavailable, no stronger or different concern can be verified, and inventing one would violate the good-faith rule. The existing CONDITIONAL / LOW-confidence verdict already encodes precisely this limitation, so no adjustment is warranted. The concrete test above is the minimal check that would settle whether the concern lands once the paper is readable.","tokens_in":1889,"tokens_out":476,"duration_ms":14908,"concrete_test":"When the full paper (or supplementary material) becomes available, extract the experimental protocol and recompute the reported FP-rate / anomaly-score deltas after (a) volume-normalizing the feature vectors or holding packet/byte rates constant across connectivity-event vs. steady-state windows, and (b) verifying attack-free ground truth via independent packet traces or process logs. If the FP elevation disappears or falls below practical significance under either control, the causal framing does not hold.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim (legitimate connectivity events in industrial private 5G noticeably increase ML-IDS false positives on encrypted OPC UA, and elevated scores frequently coincide with associated CP activity) is framed causally in the abstract. With only the abstract available, there is no experimental design, feature set, ground-truth labeling protocol, traffic-volume controls, or quantitative results that would allow verification that the observed FP increase is driven by the connectivity events themselves rather than by correlated confounds (volume changes, session re-establishment artifacts in the feature extractor, or imperfect attack-free labeling). The coincidence with CP activity is noted but not shown to be more than temporal correlation. This is exactly the weakest assumption the Reader identified; no additional load-bearing flaw can be substantiated from the abstract alone, and none is manufactured here.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript (available here only as an abstract) claims that legitimate connectivity events in industrial private 5G networks can noticeably raise false-positive activity of ML-based intrusion detection systems monitoring encrypted OPC UA traffic, even in the absence of attacks. It further asserts that elevated IDS anomaly scores frequently coincide with periods of control-plane activity associated with those benign events, and concludes that control-plane context should be considered when interpreting IDS outputs in such environments.","tokens_in":2029,"tokens_out":830,"duration_ms":14268,"significance":"If the claimed experimental findings hold under a well-controlled design, the work would be practically relevant for industrial private-5G security: it would caution operators against treating ML-IDS alerts on encrypted OPC UA as attack-indicative without control-plane context, and would motivate CP-aware post-processing or feature design. The topic sits at a useful intersection of industrial OT protocols, private 5G, and encrypted-traffic IDS evaluation. Significance cannot be fully scored from the abstract alone, because effect sizes, baselines, and reproducibility artifacts are not visible.","major_comments":[{"comment":"Abstract: the central causal framing (“impact of benign connectivity variations”) and the claim that legitimate connectivity events “can noticeably increase false positive activity despite the absence of attacks” are load-bearing. With only the abstract available, there is no experimental design, feature set, ground-truth labeling protocol, traffic-volume or session-reestablishment controls, IDS model description, or quantitative FP metrics against which to verify that connectivity events—not confounds—drive the reported FP increase. This isolation is required for the claim as stated.","section":null},{"comment":"Abstract: the second main claim—that elevated IDS anomaly scores “frequently coincide with periods of control-plane (CP) activity associated with these events”—is presented as more than temporal correlation. The abstract does not report coincidence rates, lag analysis, statistical tests, or a comparison against volume-matched non-CP periods. Without those (or equivalent) results in the full manuscript, the CP-context recommendation is under-supported relative to the strength of the wording.","section":null},{"comment":"Abstract: “experimental results” are asserted without any visible quantitative anchors (dataset size, number of connectivity events, FP rate deltas, anomaly-score distributions, error bars, or baselines). For a results-driven empirical paper, these quantities are load-bearing for the “noticeably increase” and “frequently coincide” statements; their absence from the only available text prevents assessment of effect size and robustness.","section":null}],"minor_comments":[{"comment":"Abstract: expand or define “connectivity variations” and “connectivity events” on first use so readers can distinguish UE attach/detach, handover, PDU-session re-establishment, and radio-link recovery without the full text.","section":null},{"comment":"Abstract: “ML-based IDSs” is left unspecified (supervised vs. unsupervised, flow vs. packet features, training regime). Even a one-phrase qualifier would help readers judge transferability.","section":null},{"comment":"Abstract: the final sentence (“highlight the importance of considering CP context”) is a recommendation; if the full paper does not evaluate a CP-aware mitigation, consider softening to a finding rather than an operational prescription.","section":null}],"recommendation":"uncertain","confidential_remarks":"Only the abstract was provided for this review; the full manuscript text was not available. Under those conditions a definitive accept/revise/reject decision is not possible, so the recommendation is uncertain. If the full paper is supplied, the review should focus on whether the experimental design isolates benign connectivity events from traffic-volume and feature-extractor confounds, and on the quantitative support for the CP-coincidence claim. Scope (cs.CR / industrial private 5G IDS) appears appropriate for the venue class indicated by the arXiv category."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is an abstract-only look, so treat everything as provisional. The punchline is a concrete, domain-specific measurement: legitimate connectivity events in industrial private 5G can noticeably lift false-positive activity of ML IDS watching encrypted OPC UA, and the elevated anomaly scores often line up with control-plane activity tied to those events. That is the thing worth knowing.\n\nWhat is new is the experimental characterization itself, not a new detector or a first-principles result. If the full paper actually runs the setup under realistic private-5G conditions and shows the FP rise under attack-free ground truth, that is useful within OT security and private-5G monitoring. It names a confounder people who deploy these systems will care about. Credit for framing a practical problem cleanly and for pointing at CP context as something operators should look at when reading IDS scores.\n\nThe soft spot is exactly the causal isolation the abstract claims. \"Impact of\" language needs traffic-volume controls, a clear feature set, labeling protocol, and numbers (FP rates, coincidence strength, error bars). Without those, we cannot tell whether the driver is the connectivity events themselves or correlated artifacts (volume shifts, session re-establishment in the feature extractor, imperfect attack-free labeling). The CP coincidence is noted but not yet shown to be more than temporal correlation. That is a real but ordinary experimental risk, not a manufactured flaw; the abstract does not invent entities or free parameters.\n\nWho it is for: people building or evaluating ML IDS on encrypted industrial traffic over private 5G. A serious referee should see the full paper if the methods and data are there; the question is important enough for the subfield. I would not cite from the abstract alone, and I would not bring it to reading group until we have the numbers. Send it to peer review rather than desk-reject; the claim is falsifiable and practically relevant once the design is checkable.","headline":"Abstract-only industrial measurement: benign private-5G connectivity events may raise ML-IDS false positives on encrypted OPC UA; claim is clear and useful if the full paper isolates the confound.","tokens_in":2673,"tokens_out":492,"would_cite":false,"duration_ms":5689,"reading_group":"no","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Benign 5G connectivity events raise false positives in ML IDS for encrypted OPC UA traffic.","keywords":["intrusion detection","encrypted traffic","OPC UA","private 5G","industrial networks","false positives","control plane","machine learning"],"falsifier":"A controlled re-run in which connectivity events are held constant while traffic volume and feature distributions are matched to the event periods; if false-positive rates and anomaly-score spikes still match those reported for the connectivity events, the claimed causal impact fails.","tokens_in":2772,"feed_emoji":"📡","tokens_out":662,"duration_ms":7738,"temperature":0.7,"pith_summary":"This paper argues that legitimate connectivity variations in industrial private 5G networks can drive noticeable false-positive activity in machine-learning intrusion detection systems that watch encrypted OPC UA traffic, even when no attacks are present. The authors show experimentally that elevated IDS anomaly scores often line up with control-plane activity linked to those everyday connectivity events. A sympathetic reader should care because factories increasingly rely on encrypted industrial protocols over private 5G and on ML-based monitors that only see traffic patterns; if ordinary network housekeeping looks like intrusion, operators will either ignore the IDS or drown in alerts. The work therefore presses the point that control-plane context must be taken into account when interpreting such detectors in real industrial 5G settings.","feed_headline":"Benign 5G events drive IDS false positives on encrypted OPC UA","feed_subtitle":"Legitimate connectivity changes make ML detectors flag clean industrial traffic as anomalous.","key_machinery":"The experimental linkage between benign private-5G connectivity events (and their associated control-plane activity) and spikes in ML-IDS anomaly scores on encrypted OPC UA traffic, used to quantify the false-positive impact under attack-free conditions.","core_discovery":"Legitimate connectivity events in industrial private 5G networks can noticeably increase false-positive activity of ML-based IDS monitoring encrypted OPC UA traffic, and elevated IDS anomaly scores frequently coincide with periods of control-plane activity associated with those events.","pith_inferences":["Feature sets that capture session setup or radio-state transitions may be especially sensitive to private-5G mobility and reattachment patterns.","Fusing lightweight control-plane telemetry with user-plane flow features could become a practical mitigation path for this class of false positives.","Similar effects may appear for other encrypted industrial protocols (e.g., MQTT-TLS, Modbus-TLS) whenever private 5G connectivity events reshape traffic statistics."],"forward_implications":["ML IDS outputs for encrypted OPC UA over private 5G cannot be treated as pure attack indicators without control-plane context.","Operators who ignore CP activity risk alert fatigue or missed detections when real attacks coincide with connectivity changes.","IDS design for industrial 5G should incorporate or condition on control-plane signals to suppress benign-event false positives.","Evaluation of industrial IDS must include realistic private-5G connectivity dynamics, not only steady-state traffic."],"fun_headline_variants":["Benign 5G connectivity events boost false positives in OPC UA IDS","Legitimate private 5G shifts cause ML IDS false alarms on encrypted OPC UA","Control-plane events coincide with elevated IDS scores on industrial OPC UA","Benign connectivity variations drive IDS false positives for encrypted OPC UA","ML IDS flags clean OPC UA traffic amid private 5G control-plane activity"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"That the experimental setup truly isolates benign connectivity variations as the cause of the false-positive rise rather than traffic-volume shifts, feature-extractor artifacts, or imperfect attack-free labeling.","fun_headline_variants_meta":{"raw":{"variants":["Benign 5G connectivity events boost false positives in OPC UA IDS","Legitimate private 5G shifts cause ML IDS false alarms on encrypted OPC UA","Control-plane events coincide with elevated IDS scores on industrial OPC UA","Benign connectivity variations drive IDS false positives for encrypted OPC UA","ML IDS flags clean OPC UA traffic amid private 5G control-plane activity"]},"model":"grok-4.5","effort":"low","cost_usd":0.008292,"raw_usage":{"total_tokens":1806,"prompt_tokens":636,"num_sources_used":0,"completion_tokens":98,"cost_in_usd_ticks":82920000,"prompt_tokens_details":{"text_tokens":636,"audio_tokens":0,"image_tokens":0,"cached_tokens":0},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1072,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":636,"tokens_out":98,"duration_ms":8632,"temperature":1.0,"reasoning_tokens":1072,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-13T01:23:08.052982+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"A controlled re-run in which connectivity events are held constant while traffic volume and feature distributions are matched to the event periods; if false-positive rates and anomaly-score spikes still match those reported for the connectivity events, the claimed causal impact fails.","supporting_citations":[],"review_version":1}