Cross-Slice Co-Location Risk-Aware SFC Provisioning in Multi-Slice LEO Satellite Networks
arXiv:2605.03656v1 [cs.NI] 5 May 2026
Mohammed Mahyoub, Wael Jaafar, Sami Muhaidat, and Halim Yanikomeroglu
Abstract—We address cross-slice co-location risk in multi-slice low Earth orbit (LEO) satellite edge networks, where virtual network functions (VNFs) from different network slices sharing the same satellite instance create a cross-slice security exposure channel. We formulate a risk-aware service function chain (SFC) placement problem as a mixed-integer linear program (MILP) over a dynamically evolving LEO satellite constellation, jointly optimizing cross-slice co-location risk, CPU resource consumption, and VNF migration stability under satellite capacity, intersatellite link (ISL) capacity, visibility, and end-to-end (E2E) delay constraints. The risk model employs a multiplicative colocation formulation, inspired by the risk assessment principles from ISO/NIST frameworks, with exact and coarse (slice-level) formulations that analytically establish bounds on the co-location exposure. To solve this problem, we propose a three-stage hybrid optimizer combining time epoch preprocessing, simulated annealing-based warm-start, and branch-and-bound refinement. Experimental evaluation demonstrates a 40% reduction in colocation risk and an 80% reduction in avoidable VNF migrations relative to the greedy baseline at negligible CPU overhead, and a 23× warm-start speedup from 256 s cold-start to 11 s per epoch, confirming real-time viability from the second epoch. Index Terms—LEO satellite, SFC, network slicing, cross-slice security risk, optimization, simulated annealing, 6G NTN.
I. I NTRODUCTION The rapid growth of global connectivity demands and emerging applications, e.g., autonomous systems, maritime communications, and large-scale Internet-of-Things (IoT), has accelerated the development of Non-Terrestrial Networks (NTNs) as a key pillar of 6G [1]. Among NTN segments, Low Earth Orbit (LEO) satellite constellations are attracting particular attention and emerging as edge computing platforms for next-generation services, due to their global coverage, low propagation delay, and flexible service provisioning [2]. Enabling multi-slice service provisioning on these platforms requires integration of network function virtualization (NFV) and network slicing, allowing satellites to host VNFs and instantiate dedicated service function chains (SFCs) for multiple isolated slices [3]. SFC provisioning, which determines where each ordered VNF sequence is deployed and how traffic traverses it, is consequently a central orchestration task [4]. SFC provisioning in LEO satellite networks faces many interdependent challenges absent in terrestrial settings, such as scarse on-board computing that limits the number of simultaneously hosted VNFs [5], and the highly dynamic LEO topology that triggers frequent inter-satellite link (ISL) availability changes, forcing costly VNF migrations across satellites. When VNFs from different slices share a satellite instance, cross-slice co-location risk arises, whereby a compromised or inferencesusceptible shared instance may expose sensitive functions
of unrelated slices [6], [7]. Jointly addressing these issues requires a risk-aware orchestration framework that existing SFC provisioning do not provide. SFC provisioning has been extensively studied in NFVenabled infrastructures [8]. Mixed-integer linear programming (MILP)-based approaches yield optimal placements under resource and delay constraints [9], while metaheuristics, including genetic algorithms and simulatefd annealing (SA) address scalability [10]. Also, dynamic settings include migration costs for stability [4], [11]. Nevertheless, most works assume trusted infrastructures and omit security risk from the placement objective [7]. Recent studies explored resource allocation and VNF placement in satellite edge computing. For instance, Doan et al. [12] applied multi-agent reinforcement learnign (MARL) to SFC placement in LEO networks, while Qin et al. [13] modelled multi-SFC embedding in ultra-dense hybrid LEO-terrestrial 6G systems. Alse, Yue et al. [14] addressed delay-aware VNF placement in 6G NTN. Network slicing orchestration across hybrid satellite-terrestrial segments was studied in [15], [16]. Despite these advances, most works treated security as a binary isolation constraint and did not jointly model the interaction between resource efficiency, migration stability and security placement. Security-aware VNF placement has been studied in terrestrial and edge contexts [17]–[19], where strict isolation rules reduce colocation attack surface but limit resource allocation efficiency. In LEO systems, Ahmad et. al [20] surveyed satellite-terrestrial security challenges, and Yue et. al [21] analyzed LEO-specific security risks, neither addressing risk-aware SFC placement. To the best of our knowledge, no prior work jointly modeled cross-slice security risk, resource utilization, and migration stability for SFC provisioning in LEO satellite networks. Hence, the main contributions of this paper are as follows: • We formulate a multi-objective MILP for SFC provision-
ing in LEO networks combining cross-slice co-location risk, resource consumption, and migration stability. • We propose a risk modelling framework with exact and coarse-grained formulation, and analytically establish bounds that quantify the approximation gap while significantly reducing computational complexity. • We introduce a novel migration-aware stabilization mechanism that distinguishes unavoidable topology-induced changes from avoidable ones. • We develop a hybrid optimization framework combining SA warm-starting and branch-and-bound refinement for efficient security-aware SFC provisioning.
II. S YSTEM M ODEL AND P ROBLEM F ORMULATION A. Network and Service Model We consider a multi-slice LEO satellite network observed at discrete time epochs t. At each time epoch, the network is represented as a directed graph Gt = (S, Et ), where S is the set of satellites and Et the set of active ISLs. Each satellite s ∈ S is characterized by a finite CPU capacity Capcpu and s an inter-satellite link (ISL) neighborhood Hs = {s} ∪ {ŝ : (s, ŝ) ∈ Et }, where |Hs | = 4, comprising two intra-plane links to the fore and aft satellites within the same orbital plane, and two inter-plane cross-links to the nearest satellites in the adjacent orbital planes [13]. A user u from slice n can connect to satellite s only if its t t elevation angle θn,u,s satisfies θn,u,s ≥ θmin where θmin is the minimum elevation angle. The set of visible satellites for user t t u in slice n at epoch t is Vn,u = {s : θn,u,s ≥ θmin }. The acc corresponding access delay dn,u,s is computed using standard slant-range geometry [22]. Let N be the set of slices, Un the users of slice n, F the set of VNF types, and I is the set of instances for any function. Each slice n requires an ordered SFC Fn = (f1n , . . . , fLnn ) where fℓn is the ordered VNF ℓ in the SFC Fn and Ln is the chain length [7]. Each VNF instance (f, i, s) is characterized cpu by activation cost bcpu f,i,s , per-user processing cost af,i,s (n, u), and processing delay τf,i,s . Finally, each user has an end-toend (E2E) delay budget T̄n,u . To ensure tractability, we adopt the following assumptions: i) Processing delays are deterministic, ii) CPU consumption scales linearly with the number of assigned users, iii) Traffic demand is static in each epoch, and iv) Queueing and congestion are not explicitly modelled. These assumptions are valid for low traffic load scenarios, where satellite utilization remains well below 20%, making queueing delays negligible.
once, i.e., X i,s βn,u,ℓ = 1,
∀n ∈ N , u ∈ Un , ℓ = 1, . . . , Ln .
Second, assignments are valid only if the instance is active, i,s i.e., βn,u,ℓ ≤ γfs n ,i , thus ensuring the activation overhead bcpu f,i,s ℓ is charged whenever any user is assigned to that instance. Without it, the solver could assign users to inactive instances, thus avoiding overhead but yielding infeasible solutions. Then, the total CPU usage per satellite, from both instance activation overheads and per-user processing demands, must not exceed its capacity Cap cpu , i.e., X cpu X cpu s i,s s bf,i,s γf,i + af n ,i,s (n, u) βn,u,ℓ ≤ Cap cpu s , ∀s ∈ S. ℓ
f,i
n,u,ℓ,i
(2) For each consecutive VNF pair (ℓ, ℓ+1), the routing s,ŝ indicator ζn,u,ℓ ∈ [0, 1] equals 1 iff user (n, u) traverses ISL (s, ŝ) between those two VNF positions. It is coupled to the placement variables via McCormick linearization: P i,s P i,ŝ s,ŝ ζn,u,ℓ ≥ i βn,u,ℓ + i βn,u,ℓ+1 − 1, (3) P i,s s,ŝ ζn,u,ℓ ≤ i βn,u,ℓ , (4) P i,ŝ s,ŝ ζn,u,ℓ ≤ i βn,u,ℓ+1 , (5) ∀ n, u ∈ Un , ℓ ∈ {1, . . . , Ln }, (s, ŝ) ∈ Et , where (4) and (5) prevent routing on a link unless both endpoints host the respective functions. When two consecutive VNFs are colocated on the same satellite, no ISL is used, and all ζ are zero, correctly contributing neither ISL delay to (6) nor flow to (7). Each consecutive VNF pair (ℓ, ℓ + 1) is assigned a s,ŝ single routing variable ζn,u,ℓ , implicitly assuming that interVNF traffic traverses a single ISL hop. Consequently, the E2E delay must not exceed the user’s delay budget T̄n,u , i.e., Ln X I X I X X X i,s i,s τfℓn ,i,s βn,u,ℓ dacc β + n,u,s n,u,1 t i=1 s∈Vn,u
B. Decision Variables Based on the above network and service model, several decision variables are defined as follows: i,s • βn,u,ℓ ∈ {0, 1} equals 1 if user u ∈ Un of slice n ∈ N executes function fℓn in its SFC on instance i ∈ I hosted
on satellite s ∈ S, and is 0 otherwise. Where needed, we i,s write βn,u,f with f = fℓn to index by VNF type. s • γf,i ∈ {0, 1} equals 1 if an instance i of function type f ∈ F is activated on satellite s ∈ S, and 0 otherwise. s,ŝ • ζn,u,ℓ ∈ {0, 1} equals 1 if the traffic of user u ∈ Un is routed between function positions ℓ and ℓ + 1 via the link from satellite s to satellite ŝ ∈ Hs and 0 otherwise. • µn,u,ℓ ∈ [0, 1] indicates whether an avoidable migration occurs for user u ∈ Un at function position ℓ. It is 1 if the previous placement was feasible but not retained, and 0 otherwise.
(1)
i,s
| +
ℓ=1 i=1 s∈S
{z
access delay
LX n −1 X X
|
}
{z
processing delays
s,ŝ δs,ŝ ζn,u,ℓ ≤ T̄n,u ,
}
∀ n ∈ N , u ∈ Un .
ℓ=1 s∈S ŝ∈Hs
|
{z
ISL propagation
}
(6) Moreover, the aggregated flow per ISL link is bounded by the link capacity C ISL , such that Ln X X X s,ŝ ζn,u,ℓ ≤ C ISL ,
∀ (s, ŝ) ∈ Et ,
(7)
n∈N u∈Un ℓ=1
while the ingress VNFs (i.e. VNFs at position ℓ = 1) must be placed on visible satellites, i.e., X i,s t βn,u,1 = 0, ∀ n ∈ N , u ∈ Un , s ∈ / Vn,u . (8) i∈I
D. Cross-Slice Co-location Risk Model C. Constraints To enforce feasibility, the following constraints should be satisfied. First, each user-function pair is assigned exactly
In multi-slice LEO satellite networks, VNFs from different slices may be instantiated on shared satellite resources. While such co-location improves resource efficiency, it may introduce
cross-slice security exposure, where vulnerabilities in one slice can affect others through shared infrastructure [19], [20]. This work models such exposure as a relative co-location risk metric, intended to guide placement decisions. We model cross-slice co-location risk as a function of three key factors: i) Function sensitivity R[f ] that captures the security criticality of a VNF type (e.g., encryption or intrusion detection functions are more sensitive than traffic monitoring), ii) Slice criticality C[n] that reflects the importance or impact level of a slice (e.g., mission-critical vs. best-effort services), and iii) Isolation policy coefficient Φ[n, n′ ] that represents the degree of enforced isolation between slices, where Φ = 0 indicates strict isolation and Φ = 1 indicates no isolation risk guarantees. These factors are combined as wn,n ′ ,f = R[f ] · ′ ′ Φ[n, n ] · C[n] · C[n ], ensuring that risk is nullified when any factor is zero (e.g., strict isolation or non-sensitive functions), and increases proportionally when risk factors are present. The exact risk model captures user-level co-location, where exposure arises when users from different slices share the same VNF instance. Let binary variable pi,s n,u,n′ ,u′ ,f indicate whether users u ∈ Un and u′ ∈ Un′ are both assigned to instance (f, i, s), ∀n ̸= n′ . Consequently, this assignment should respect the following constraints: i,s pi,s n,u,n′ ,u′ ,f ≤ βn,u,f ,
(9)
i,s pi,s n,u,n′ ,u′ ,f ≤ βn′ ,u′ ,f ,
(10)
i,s i,s pi,s n,u,n′ ,u′ ,f ≥ βn,u,f + βn′ ,u′ ,f − 1,
(11)
and the exact co-location risk is defined as X X X X risk wn,n Risk ex = ′ ,f n<n′ f ∈Fn ∩Fn′ i,s
pi,s n,u,n′ ,u′ ,f .
u∈Un , u′ ∈Un′
(12) This formulation provides a fine-grained representation of colocation exposure but introduces O(N |2 U |2 F I S) auxiliary binary variables, where N = |N |, U = maxn |Un |, F = |F |, I is the maximum number of instances per function type per satellite, and S = |S|, which may limit scalability. To improve scalability, we introduce a slice-level approxi,s imation. Speciifcally, let zn,f ∈ {0, 1} indicate whether any user of slice n is assigned to instance (f, i, s). Then, this binary variable is linked to β through i,s i,s zn,f ≥ βn,u,f , ∀ u ∈ Un , X i,s i,s and zn,f ≤ βn,u,f .
(13) (14)
u∈Un i,s ′ Also, let yn,n ′ ,f ∈ {0, 1} indicate whether slices n and n co-locate on instance i. Then, their relation is defined via a i,s logical AND of zn,f and zni,s′ ,f as follows: i,s i,s yn,n ′ ,f ≤ zn,f , i,s i,s yn,n ′ ,f ≤ zn′ ,f , i,s i,s i,s and yn,n ′ ,f ≥ zn,f + zn′ ,f − 1.
(15) (16) (17)
Hence, the resulting coarse risk bounds approximation are
given by Risk LB =
X
i,s risk wn,n ′ ,f y n,n′ ,f ,
(18)
i,s risk |Un | |Un′ | wn,n ′ ,f y n,n′ ,f .
(19)
n<n′ ,f,i,s
and Risk UB =
X n<n′ ,f,i,s
This coarse-grained formulation reduces complexity to O(N 2 F I S), enabling efficient optimization for larger systems. The coarse formulation provides a bounded approximation of the exact risk, i.e., Risk LB ≤ Risk ex ≤ Risk UB .
(20)
Table I summarizes the variable-count and solution-quality properties of both formulations. TABLE I: Exact vs. Coarse Risk Model Comparison Property
Exact (12)
Coarse (18)
Granularity User-pair Slice-pair Risk variables O(N 2 U 2 F IS) O(N 2 F IS) Variable reduction — U2 Objective optimized Risk ex (exact) Risk LB (lower bound) Bound guarantee Exact value Risk LB ≤ Risk ex ≤ Risk UB Primary use case small-scale large-scale
E. Migration Stabilization prev,i,s Let βn,u,ℓ be the prior epoch’s placement (a fixed paramP prev,i,s i,s eter). The keep-indicator kn,u,ℓ = i,s βn,u,ℓ ·βn,u,ℓ equals 1 if the assignment is unchanged. The preprocessing parameter πn,u,ℓ ∈ {0, 1} indicates whether the prior assignment remains feasible. A migration is considered avoidable if the previous assignment remains feasible under current visibility and capacity constraints but is not retained by the optimizer. Therefore, the avoidable-migration indicator is µn,u,ℓ ≥ πn,u,ℓ − kn,u,ℓ ,
(21)
µn,u,ℓ ≤ πn,u,ℓ , and µn,u,ℓ ≤ 1 − kn,u,ℓ .
(22)
µn,u,ℓ ∈ {0, 1} equals 1 only when the prior assignment was feasible but was not retained. the total migration P Thus, mig disruption cost is Mig = Dis µn,u,ℓ , where n,u,ℓ fℓn mig Dis f n ≥ 0 is the per-type disruption cost, capturing stateℓ transfer overhead and transient service downtime during VNF migration. F. Optimization Objective Let CapUse be the total satellite CPU consumption, consistent with the capacity constraint (2), i.e., X cpu X cpu i,s s CapUse = bf,i,s γf,i + af n ,i,s (n, u) βn,u,ℓ . (23) ℓ
s,f,i
n,u,ℓ,i,s
The objective is to minimize a normalized and weighted combination of resource consumption, co-location risk, and migration as CapUse Risk Mig min ωcap + ωrisk + ωmig , (24) CapUse Mig Risk where ωcap , ωrisk , ωmig ≥ 0 with ωcap + ωrisk + ωmig = 1, and the normalization bounds CapUse, Risk , and Mig are
precomputed via analytical upper bounds. The weights allow operators to express policy preferences. For instance, a securitysensitive operator sets a large ωrisk , while an efficiencydriven operator prioritizes ωcap . The problem is NP-hard, as it contains bin-packing [23]. Adding cross-slice risk and migration objectives does not alter the complexity class but substantially increases the model size, motivating the following scalability strategies.
Network Snapshot t epoch t, Gt , Vn,u
Pre-processing πn,u,ℓ , bounds, norms
Hybrid Optimization Engine
Simulated Annealing fast feasible β SA
MILP Warm-Start
incumbent: β SA /β prev
MILP Refinement branch-and-bound + cuts
G. Scalable Hybrid Optimization The 3-stage hybrid optimizer shown in Fig. 1 handles the NP-hardness of the MILP within practical 60-second epoch budgets as follows: 1) Stage 1 - Preprocessing: At each epoch, visibility t sets Vn,u , feasibility flags πn,u,ℓ , and normalization bounds (CapUse, Risk , Mig) are computed via upper bounds. 2) Stage 2 - SA warm-start: The SA begins from a greedy feasible placement constructed as follows. For each user u ∈ Un and function chain position ℓ, the ingress VNF is t assigned to the nearest satellite in the visibility set Vn,u that has sufficient residual CPU capacity. Each subsequent VNF is assigned to the satellite with the smallest hop count from the ingress satellite that again satisfies the CPU constraint. At each iteration k ∈ {1, . . . , K}, a single user-satellite pair is chosen uniformly at random, and its current satellite assignment is proposed to change from s to a uniformly sampled candidate t s′ ∈ Vn,u . The move is accepted via the Metropolis criterion, i.e., ( 1 ∆ ≤ 0, P (accept) = (25) exp(−∆/Tk ) otherwise, where ∆ is the change in the normalized weighted objective (24) induced by the proposed reassignment, and k/K Tk = T0 (Tend /T0 ) is the temperature at iteration k under a geometric cooling schedule, with T0 and Tend denoting the initial and final temperatures, respectively, and K the total number of SA iterations. To avoid a full objective recompute at every iteration, the objective change ∆ is evaluated incrementally. Relocating (n, u, ℓ) from s to s′ affects only three localized quantities: (i) the CPU loads on exactly two satellites, s and s′ , which are updated by adding or removing the activation and per-user CPU of the moved VNF, (ii) the co-location risk, whose delta is computed in O(|Un |) steps by scanning only the users of the same function type already hosted on s and s′ , and (iii) the E2E delay for user u alone, recomputed along the updated satellite sequence using precomputed shortest-path delays. Moves that violate CPU capacity or the E2E delay budget are rejected without computing ∆. 3) Stage 3 - MILP refinement: The SA solution β SA warmstarts branch-and-bound with a 0.5% optimality gap. This tolerance was chosen as the tightest gap achievable within the residual epoch budget across all evaluated epochs. The previous epoch’s placement β prev serves as a fallback incumbent when preprocessing confirms its continued feasibility.
Deployment β, γ, ζ, µ
store β prev
Fig. 1: Proposed 3-stage hybrid optimization workflow. Preprot cessing computes the visibility set Vn,u , feasibility indicators πn,u,ℓ , and objective normalization bounds. SA generates a fast feasible incumbent β SA , and the MILP refines it via branch-and-bound. At each epoch, β prev is updated for the subsequent epoch’s warm-start.
III. S IMULATION S ETUP The full implementation of this work is publicly accessible to support reproducibility and enable future research1 . A Walker-Star constellation with |S| = 60 satellites across 4 orbital planes (15 per plane), at 550 km altitude and 53◦ inclination is simulated using MATLAB Satellite Communications Toolbox. 15 consecutive 60-second epochs (total of 15 minutes) are simulated. At 550 km altitude, one orbital period is approximately 95 minutes. The 15-epoch window captures the most dynamic phase of each pass, satellite rise, peak visibility, and is sufficient to observe multiple ISL topology changes. The minimum elevation angle is set to 10◦ according to 3GPP recommendations [24]. N = |N | = 5 network slices are anchored at geographically dispersed ground stations (London, New York, Tokyo, Sydney, Paris), each serving |Un | = 10 users, ∀n = 1, . . . , 5, as the current evaluation focuses on realistic initial deployments. F = |F | = 5 VNF types are used, such that F = {FW, IDS, ENC, TM, SIEM}. Each SFC has length Ln ∈ {2, 3, 4}, drawn uniformly with repeated types permitted (motivating position-based indexing). Finally, E2E budgets are T̄n,u ∼ Uniform[75, 150] ms. Function risk sensitivities R[f ] are calibrated against NIST SP 800-53 security impact levels as follows: ENC → R = 0.9 (HIGH: key material exposure), IDS → R = 0.8 (HIGH: detection evasion), FW → R = 0.6 (MODERATE: policy bypass), SIEM → R = 0.6 (MODERATE: log tampering), TM → R = 0.4 (LOW: passive monitoring). These mappings follow the confidentiality impact ratings from NIST SP 800-53 control families SC (System and Communications Protection) and AU (Audit and 1 https://github.com/Mahyoub/LEO-SFC-PROVISIONING
24.0
250 B1 Res-Min B2 Risk-Unaware B3 Greedy Proposed
Risk
200 150 100 50 0
Satellite CPU util. (%)
300
18.0 12.0
9.8%
3
5
7
9
11
13
6.0
15
0.53%
B1 Res-Min
Epoch
Accountability). Also, slice criticality C[n] ∼ Uniform[1, 3], following 3GPP TS 22.261 tiers, and the isolation policy Φ[n, n′ ] ∼ Uniform[0, 1] per ETSI GS NFV-SEC 026. For the SA approach, initial temperature T0 = 1, final temperature Tend = 0.01, and the iteration limit K = 50000. The chosen values minimized the normalized objective while keeping the SA runtime below 2 sec. Moreover, we set the objective weights as ω = (ωcap , ωrisk , ωmig ) = (0.3, 0.5, 0.2), reflecting a security-centric deployment scenario. Finally, 3 baselines are considered, namely B1 (resource-min MILP, ω = (1, 0, 0)), B2 (stability-aware MILP, ω = (0.5, 0, 0.5), no risk term), and B3 (greedy nearest-satellite heuristic). IV. E XPERIMENTAL R ESULTS Fig. 2 presents the per-epoch evolution of the risk as a line series over the 15-epoch simulation window. As shown, the proposed method achieves risk reduction to 18.12 constant across all 15 epochs, representing a 93.4% reduction versus B1 (risk of 276.6) and 93.2% decrease versus B2 (risk of 264.9). Even though B3 benefits from incidental geographic separation, the proposed method reduces risk by 39.8% compared to it. The constant risk across epochs demonstrates that the riskminimizing placement pattern is topologically robust under Walker-Star orbital dynamics. However, the elevated risks of B1 and B2 are a direct consequence of their consolidation objectives. Indeed, minimizing CPU activation overhead packs all slices onto minimal satellites, thus maximizing cross-slice instance sharing. Moreover, B1 shows risk spikes (up to 308.9) at topology-change epochs where re-consolidation yields an even more co-location-intensive configuration. Fig. 3 provides a grouped bar chart of both average CPU utilization (Avg util.) and peak per-satellite utilization (Peak util.) to reveal hot-spot behaviour. The proposed method consumes 0.61% total constellation CPU, versus 0.32% for the most efficient baseline (B1). This gap is the quantitative “price of security”. Indeed, in this case, the 93% risk reduction costs only 0.29% CPU usage. The risk-motivated geographic spread also provides implicit load balancing. Also, the proposed method’s peak per-satellite CPU (at 9.2%) is below both B2 and B3’s hotspot peaks, as the letter co-locate more VNFs within a smaller number of satellites. Fig. 4 illustrates avoidable VNF migrations per epoch over the 15-epoch window. B1 incurs an average of 69.3 migrations
B2 Risk-Unaware
0.60%
0.61%
B3 Greedy
Proposed
Fig. 3: Mean active-satellite CPU utilization (light bars) and mean peak per-satellite CPU utilization (dark bars). Avoidable migrations / epoch
Fig. 2: Per-epoch risk over 15 epochs for each method.
9.2%
6.2%
0.32%
1
Avg util. Peak util.
18.9%
60 B1 Res-Min B2 Risk-Unaware B3 Greedy Proposed
40 20 0 1
3
5
7
9
11
13
15
Epoch
Fig. 4: Avoidable VNF migrations per epoch for each method.
per epoch, essentially restarting placement from scratch every 60 s, while B3 still accumulates an average of 6.7 due to its lack of migration awareness. In contrast, the proposed method achieves an average of 1.33 avoidable migrations per epoch, concentrated at epochs with significant topology changes. Indeed, 12 of the 15 epochs show zero unnecessary reassignments. The 80% reduction relative to B3 and 98.1% relative to B1 confirms that the keep-indicator mechanism effectively suppresses unnecessary placements. Fig. 5 presents the per-epoch runtime trajectory to reveal warm-start benefits. The cold-start at the first epoch requires 256s, exceeding the 60-second epoch budget. This occurs once at system initialization, before any prior placement β prev is available. In operational deployments, this can be handled by (i) pre-computing an initial placement during the preceding handover window using a coarser LP relaxation as an incumbent, or (ii) deferring service activation by one epoch. From epoch 2 onwards, SA warm-starting (0.5 − 1.8s) reduces the mean MILP runtime to 11.1 s, a 23× reduction, confirming practical viability within 60-second epoch intervals. The proposed method’s runtime matches the simpler baselines (B1 at 12.0 s and B2 at 10.9 s), demonstrating that the additional risk variables impose insignificant material overhead once warm-start benefits are realized. B3 solves in ≈4 ms per epoch via its O(S U L) polynomial heuristic. Finally, Fig. 6 shows Risk LB , Risk ex , and Risk UB for each method. The coarse upper bound Risk UB equals Risk ex exactly for all methods. This equality holds because the riskaware optimizer avoids dense co-location, ensuring at most one user per slice occupies any shared instance, collapsing the upper bound to the exact value. For resource-minimizing
250
B1 Res-Min B2 Risk-Unaware B3 Greedy Proposed
Runtime (s)
200 150 100 50 0 1
3
5
7
9
11
13
15
Epoch
cold start
Fig. 5: Per-epoch solve runtime for each method. UB=EX
UB=EX
RiskLB Riskex
Co-location risk
250
RiskUB
200 150 100 50 0
UB=EX
B1 Res-Min
B2 Risk-Unaware
B3 Greedy
UB=EX
Proposed
Fig. 6: Mean Risk LB , Risk ex , and Risk UB for each method. baselines, the same equality holds due to the small number of users per slice relative to available instances. Despite the loose lower bound, the coarse model drives placement decisions that achieve near-optimal exact risk, confirming its practical effectiveness as an optimization proxy. V. C ONCLUSION AND F UTURE W ORK This paper formulated risk-aware SFC placement in multislice LEO satellite edge networks as an MILP jointly minimizing cross-slice co-location risk, resource consumption, and migration disruption. A 3-stage hybrid optimizer (epoch preprocessing & SA warm-start & branch-and-bound) achieved a 23.0× per-epoch speedup, delivering 40% co-location risk reduction and 80% avoidable-migration reduction versus the greedy baseline at negligible CPU overhead, with sub-12second re-optimization within 60-second orbital epochs. While this work assumes static slices and fixed E2E delay budgets, future research should address dynamic slice arrivals and departures in rapidly evolving 6G networks. R EFERENCES [1] M. Y. Abdelsadek, A. U. Chaudhry, T. Darwish, E. Erdogan, G. Karabulut-Kurt, P. G. Madoery, O. Ben Yahia, and H. Yanikomeroglu, “Future space networks: Toward the next giant leap for humankind,” IEEE Trans. Commun., vol. 71, no. 2, pp. 949–1007, 2023. [2] I. del Portillo, B. G. Cameron, and E. F. Crawley, “A technical comparison of three low earth orbit satellite constellation systems to provide global broadband,” Acta Astronautica, vol. 159, pp. 123–135, 2019. [3] A. Petrosino, G. Piro, L. A. Grieco, and G. Boggia, “On the optimal deployment of virtual network functions in non-terrestrial segments,” IEEE Trans. Netw. Serv. Mngt., vol. 20, no. 4, pp. 4831–4845, 2023. [4] M. Mahyoub, W. Jaafar, S. Muhaidat, and H. Yanikomeroglu, “STARS: Stability-aware SFC orchestration and associations in LEO satellite networks,” IEEE Trans. Netw. Serv. Mngt., vol. 23, pp. 3326–3340, 2026.
[5] J. Li, W. Shi, H. Wu, S. Zhang, and X. Shen, “Cost-aware dynamic SFC mapping and scheduling in SDN/NFV-enabled space–air–groundintegrated networks for internet of vehicles,” IEEE Internet of Things Journal, vol. 9, no. 8, pp. 5824–5838, 2022. [6] M. Mahyoub, A. AbdulGhaffar, E. Alalade, E. Ndubisi, and A. Matrawy, “Security analysis of critical 5G interfaces,” IEEE Communications Surveys & Tutorials, vol. 26, no. 4, pp. 2382–2410, 2024. [7] C. Wang, D. Zheng, X. Liu, W. Tang, H. Xu, and X. Cao, “Towards cost optimization in security-aware service function chaining and embedding over multi-vendor edge networks,” Computer Networks, vol. 257, p. 111002, 2025. [8] A. Satpathy, M. Narayan Sahoo, C. Swain, P. Bellavista, M. Guizani, K. Muhammad, and S. Bakshi, “Virtual network embedding: Literature assessment, recent advancements, opportunities, and challenges,” IEEE Communications Surveys & Tutorials, vol. 27, no. 6, pp. 3861–3914, 2025. [9] V. R. Chintapalli, B. R. Killi, R. Partani, B. R. Tamma, and C. S. R. Murthy, “Energy- and reliability-aware provisioning of parallelized service function chains with delay guarantees,” IEEE Transactions on Green Communications and Networking, vol. 8, no. 1, pp. 205–223, 2024. [10] K. Alizadeh Noghani, A. Kassler, J. Taheri, P. Öhlén, and C. Curescu, “Multiobjective genetic algorithm for fast service function chain reconfiguration,” IEEE Trans. Netw. Serv. Mngt., vol. 20, no. 3, pp. 3501–3522, 2023. [11] S. N. Afrasiabi, A. Ebrahimzadeh, N. Promwongsa, C. Mouradian, W. Li, A. Recse, R. Szabó, and R. H. Glitho, “Cost-efficient cluster migration of VNFs for service function chain embedding,” IEEE Trans. Netw. Serv. Mngt., vol. 21, no. 1, pp. 979–993, 2024. [12] K. Doan, M. Avgeris, A. Leivadeas, I. Lambadaris, and W. Shin, “Service function chaining in LEO satellite networks via multi-agent reinforcement learning,” in IEEE Glob. Commun. Conf. (GLOBECOM), 2023, pp. 7145–7150. [13] X. Qin, T. Ma, Z. Tang, X. Zhang, H. Zhou, and L. Zhao, “Service-aware resource orchestration in ultra-dense LEO satellite-terrestrial integrated 6G: A service function chain approach,” IEEE Transactions on Wireless Communications, vol. 22, no. 9, pp. 6003–6017, 2023. [14] Y. Yue, X. Tang, W. Yang, X. Zhang, Z. Zhang, C. Gao, and L. Xu, “Delay-aware and resource-efficient VNF placement in 6G non-terrestrial networks,” in IEEE WCNC, 2023, pp. 1–6. [15] H. H. Esmat, B. Lorenzo, and W. Shi, “Toward resilient network slicing for satellite–terrestrial edge computing IoT,” IEEE Internet of Things Journal., vol. 10, no. 16, pp. 14 621–14 645, 2023. [16] A. Kak and I. F. Akyildiz, “Towards automatic network slicing for the Internet of space things,” IEEE Trans. Netw. Serv. Mngt., vol. 19, no. 1, pp. 392–412, 2022. [17] A. Petrosino, G. Piro, L. A. Grieco, and G. Boggia, “An optimal allocation framework of security virtual network functions in 6G satellite deployments,” in IEEE Consum. Commun. Network. Conf. (CCNC), 2022, pp. 917–920. [18] A. AbdulGhaffar, M. Mahyoub, and A. Matrawy, “On the impact of flooding attacks on 5G slicing with different VNF sharing configurations,” in DRCN, 2024, pp. 136–142. [19] M. Mahyoub, A. AbdulGhaffar, E. Alalade, and A. Matrawy, “A securityaware network function sharing model for 5G slicing,” SECURITY AND PRIVACY, vol. 8, no. 3, p. e70039, 2025. [20] I. Ahmad, J. Suomalainen, P. Porambage, A. Gurtov, J. Huusko, and M. Höyhtyä, “Security of satellite-terrestrial communications: Challenges and potential solutions,” IEEE Access, vol. 10, pp. 96 038– 96 052, 2022. [21] P. Yue, J. An, J. Zhang, J. Ye, G. Pan, S. Wang, P. Xiao, and L. Hanzo, “Low earth orbit satellite security and reliability: Issues, solutions, and the road ahead,” IEEE Communication Surveys & Tutorials., vol. 25, no. 3, pp. 1604–1652, 2023. [22] M. Mahyoub, H. Yanikomeroglu, G. Karabulut Kurt, and S. Martel, “Visibility-aware user association and resource allocation in multi-slice leo satellite networks,” IEEE Trans. Netw. Serv. Mngt., vol. 23, pp. 1596–1614, 2026. [23] M. R. Garey and D. S. Johnson, Computers and Intractability: A Guide to the Theory of NP-Completeness. New York, NY, USA: W. H. Freeman and Company, 1979. [24] “Study on new radio (NR) to support non-terrestrial network,” 3GPP, Sophia Antipolis, France, Technical Report TR 38.811, 2020.