arXiv:2607.01019v1 [cs.CR] 1 Jul 2026
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks BIDUSHI BARUA, Department of Computer Science, University of York, UK AHSAN KHAN, Department of Computer Science, University of York, UK KANGFENG YE, Department of Computer Science, University of York, UK PANAGIOTIS PAPANASTASIOU, Department of Computer Science, University of York, UK YIFAN LIU, Department of Computer Science, University of York, UK MOHIT BIDIKAR, Department of Computer Science, University of York, UK ANTHONY MOULDS, Department of Computer Science, University of York, UK JULIE MCCANN, Department of Computing, Imperial College London, UK POONAM YADAV, Department of Computer Science, University of York, UK Sixth Generation (6G) communication networks are expected to evolve into AI-native, highly autonomous ecosystems that integrate communication, computing, sensing, and artificial intelligence. While these capabilities enable unprecedented connectivity and intelligent services, they also create a highly heterogeneous security and privacy landscape that cannot be addressed through isolated, technology-specific solutions. This paper presents a comprehensive survey of security and privacy in AI-native 6G networks from a cross-layer perspective. We first examine the fragmentation of existing security and privacy approaches across emerging technologies, network architectures, AI systems, and standardization efforts, motivating the need for a unified security and privacy framework. Building upon this framework, we develop a cross-layer threat taxonomy encompassing infrastructure, network and architectural, AI, privacy, and security management domains, and analyze representative threats across key AI-native 6G technologies. Furthermore, we map these threats to corresponding cross-layer countermeasures, including standards harmonization as a security function, and identify critical research gaps and future priorities for secure, interoperable, and trustworthy AI-native 6G ecosystems. Finally, we discuss future research directions toward realizing secure, privacy-preserving, resilient, and globally interoperable 6G networks. This survey provides researchers, practitioners, and standardization communities with a holistic foundation for the design, evaluation, and deployment of trustworthy AI-native 6G systems. CCS Concepts: • Networks → Network security; • Security and privacy → Distributed systems security; Privacy protections; • Computing methodologies → Machine learning. Additional Key Words and Phrases: 6G, AI-native networks, network security, privacy, artificial intelligence, threat taxonomy, security management, standards harmonization, zero trust, post-quantum cryptography
1
Introduction
Wireless communication networks have evolved from voice-centric systems to intelligent, highly connected infrastructures supporting broadband services, massive machine-type communications, and ultra-reliable low-latency applications [77, 126]. Building upon this evolution, 6th Generation (6G) is envisioned as an AI-native network that Authors’ Contact Information: Bidushi Barua, Department of Computer Science, University of York, York, UK, [email protected]; Ahsan Khan, Department of Computer Science, University of York, York, UK; Kangfeng Ye, Department of Computer Science, University of York, York, UK; Panagiotis Papanastasiou, Department of Computer Science, University of York, York, UK; Yifan Liu, Department of Computer Science, University of York, York, UK; Mohit Bidikar, Department of Computer Science, University of York, York, UK; Anthony Moulds, Department of Computer Science, University of York, York, UK; Julie McCann, Department of Computing, Imperial College London, York, UK; Poonam Yadav, Department of Computer Science, University of York, York, UK. 2026. Manuscript submitted to ACM Manuscript submitted to ACM
1
2
Barua, et al.
integrates communication, sensing, computing, and artificial intelligence to enable connected intelligence across diverse applications and services [94]. However, 5th Generation (5G) is insufficient to support emerging applications requiring ultra-low latency, ultra-high reliability, pervasive intelligence, and real-time decision making. Future services, including extended reality (XR), digital twins, autonomous systems, and the Internet of Everything (IoE), demand seamless integration of communication, sensing, computing, and AI, driving the evolution toward adaptive, intelligent, and autonomous 6G networks [126, 77, 94]. To support emerging intelligent applications, 6G is envisioned as an AI-native network that tightly integrates communication, sensing, computing, and intelligence across terrestrial, aerial, satellite, and edge infrastructures. Enabled by technologies such as RIS, JCAS, NTNs, O-RAN, network slicing, edge intelligence, and foundation models, AI-native 6G is expected to deliver substantial improvements in capacity, latency, reliability, and energy efficiency [44, 30]. While this convergence enables unprecedented capabilities, it also fragments the security and privacy landscape, as heterogeneous technologies, AI-driven network functions, and distributed infrastructures introduce interdependent threats that cannot be addressed through isolated security mechanisms. Unlike traditional threat models that primarily focus on communication networks, AI-native 6G systems are vulnerable to a broader spectrum of attacks targeting physical infrastructures, virtualized network functions, AI models, sensing environments, privacy-sensitive data, and security management mechanisms. Furthermore, the increasing reliance on distributed intelligence, autonomous decision making, and cross-domain interoperability creates complex interdependence among technologies, making security and privacy risks more difficult to identify, isolate, and mitigate. Consequently, threats originating in one layer may propagate across multiple domains, leading to cascading impacts on network reliability, privacy preservation, trust establishment, and service resilience. Although extensive research efforts have investigated 6G security and privacy (as described in Table 1), existing surveys primarily address individual technologies or specific security mechanisms, leaving a limited understanding of how threats, countermeasures, and standardization efforts interact across AI-native 6G ecosystems. In parallel, standards development organizations (e.g., International Telecommunication Union (ITU), 3rd Generation Partnership Project (3GPP), European Telecommunications Standards Institute (ETSI), and Internet Engineering Task Force (IETF)) and industry alliances (e.g., O-RAN Alliance, AI-RAN Alliance, Next Generation Mobile Network Alliance (NGMN), and Next G Alliance) are developing complementary security and privacy requirements, resulting in an evolving but fragmented landscape. To address this gap, this survey presents a cross-layer perspective on 6G security and privacy. Specifically, we analyze the fragmentation of current security and privacy approaches, and propose a cross-layer threat taxonomy encompassing infrastructure threats, network and architectural threats, AI and intelligence threats, privacy threats, and security management threats. Building upon this taxonomy, we identify standardization gaps, synthesize emerging countermeasures, and discuss the foundations of a unified security and privacy framework for AI-native 6G networks. The main contributions of this survey are summarized as follows: • We review the evolving vision of AI-native 6G networks and identify the fragmentation challenges associated with security and privacy. • We analyze security and privacy standardization efforts, emerging policy initiatives, and harmonization challenges across major standards organizations, industry alliances, and research initiatives. • We propose a cross-layer threat taxonomy encompassing infrastructure, network and architectural, AI, privacy, and security management threats. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
3
• We propose a cross-layer countermeasure framework comprising identity and access management, security orchestration and automation, AI governance and assurance, privacy governance and compliance, and standards harmonization, and identify the associated open research challenges. • We present a unified security and privacy framework for AI-native 6G networks that integrates the proposed taxonomy, and countermeasures. Table 1. Comparative Analysis of Existing Literature on 6G Security and Privacy Ref Focus Area [126] Standardization and 6G security threats [77] Prospective 6G technologies and associated risks [3] Security overview for 5G and beyond [1] Security in B5G and 6G communication networks [70] Security and privacy for RIS in 6G [53] FL and blockchain-based security in 6G V2X [85] Security, privacy, and trust in O-RAN for 6G [73] Enabling technologies and challenges in 6G NTNs [27] Edge learning security for 6Genabled IoT [63] Security and privacy at 6G network edge [74] FL integration in IoT with privacy/security focus [128] Decentralized federated learning [24] Security review for V2X in VANETs [62] RL-based physical and crosslayer security in 6G [21] Role of physical layer security in 6G [19] Security of network slicing in 5G/6G [95] AI convergence with 6G communication networks This Unified Security and Privacy work Objectives, Cross-Layer Threat Taxonomy and Countermeasures in AI-native 6G
2
Enablers Covered RIS, THz, ML, AI-native infra
Threat Domains General threat types, trust models, DoS, spoofing RIS, THz, AI/ML, Blockchain Spoofing, poisoning, eavesdropping, trust models Network slicing, SDN, NFV, Eavesdropping, jamming, rogue slicblockchain ing, side-channel attacks UAVs, THz, RIS, blockchain Privacy leakage, spoofing, data integrity, authentication threats RIS (reflection control, deploy- Eavesdropping, spoofing, signal mament) nipulation FL, blockchain, V2X, edge AI Model poisoning, Sybil attacks, data tampering RIC, ZTA, AI anomaly detection, Rogue xApps, data leakage, interblockchain face tampering Satellites, UAVs, HAPS, RIS Handover failures, dynamic spectrum risks, latency threats Federated Learning, Edge AI Data poisoning, backdoors, adversarial examples, privacy leakage Edge computing, zero-trust, im- Identity spoofing, inference leakage, mersive services access control, trust models FL, blockchain, differential pri- Poisoning, inference, model manipvacy ulation DFL, peer collaboration, FL over Poisoning, Sybil attacks, unstable edge convergence VANETs, V2V, V2I, encryption, Sybil attacks, message falsification, trust models DoS, privacy leakage RIS, THz, RL, edge AI Jamming, spoofing, eavesdropping
Limitations Lacks taxonomy, no detailed treatment of applicationlayer security No application-layer security, lacks taxonomy and integrated defense framework 5G-centric; lacks detailed 6G enabler analysis and forward-looking security models Lacks structured taxonomy and defense mapping; generalist perspective Narrow focus on RIS; lacks integration with broader 6G architecture or enabler inter-dependencies Focused on V2X; lacks generalizability across other 6G use cases or layers Focused on O-RAN; lacks integration with other 6G domains and cross-layer threats Lacks focus on E2E security, privacy-preserving methods, and zero-trust integration Focuses only on IoT edge learning; lacks broader enabler and architectural security coverage Lacks system-wide threat taxonomy and enabler diversity (e.g., RIS, JCAS) Focused on IoT-FL; lacks integration with broader 6G enablers and cross-layer security view Strong DFL focus; lacks broader 6G enabler context and system-level integration Limited to VANETs; lacks alignment with 6G enablers and future-proof models Focused on RL methods; lacks broad threat taxonomy and architectural-level security analysis PLS, AN injection, beamforming, Eavesdropping, jamming, spoofing Strong PHY focus; lacks cross-layer integration and secure CSI AI-driven adaptability AI-based slice monitoring, Slice hijacking, isolation failure, Focused on slicing; lacks integration with other 6G blockchain, secure orchestration rogue slice enablers and holistic architecture Semantic comm., beamforming, AI-based attacks, lack of trans- Focused on AI integration; lacks detailed privacy modthreat detection parency, adversarial examples els and threat taxonomy RIS, JCAS, NTN, THz,XL-MIMO, Infrastructure, NetO-RAN, Network Slicing, iZTA, work&Architecture, AI/Intelligence, IBN, MEC, FL, AI-RAN, AI agents, Privacy and Security Management LLMs, XR and Metaverse, Seman- Threats and Fragmentation Across tic Communications, PQC, Secure Networks Boot and Remote Attestation
Fragmentation in 6G Security and Privacy
AI-native 6G introduces fragmented security and privacy challenges through the convergence of communication, sensing, computing, and AI. Heterogeneous technologies, distributed architectures, AI-driven decision making, and evolving standards create inconsistencies in security assumptions, protection mechanisms, and governance models. As a result, developing interoperable and end-to-end security solutions for AI-native 6G remains a significant challenge. The major sources of fragmentation can be broadly categorized into five dimensions: • Technology Fragmentation: Diverse technologies such as RIS, JCAS, NTN, THz communications, and digital twins introduce heterogeneous attack surfaces. Manuscript submitted to ACM
4
Barua, et al.
AI-Native 6G
Security and Privacy Fragmentation
Technology
Architecture
AI
Standards
Security Management
Need for a Unified Security and Privacy Framework
Fig. 1. Fragmentation in Security and Privacy of AI-native 6G Networks.
• Architectural Fragmentation: O-RAN, network slicing, edge computing, and cloud-native infrastructures create distributed trust boundaries and management complexities. • AI Fragmentation: Federated learning, foundation models, AI-RAN, and autonomous agents introduce new threats related to adversarial AI and autonomous decision making. • Standards Fragmentation: Multiple standardization bodies define security requirements from different perspectives, leading to interoperability challenges. • Security Management Fragmentation: Diverse approaches to identity management, authentication, and quantum-safe security create inconsistencies across domains. These fragmentation dimensions collectively contribute to a highly interconnected threat landscape in which vulnerabilities originating in one domain can propagate across multiple layers. Consequently, a cross-layer perspective is required to systematically identify, analyze, and mitigate security and privacy risks in AI-native 6G networks. Figure 1 illustrates the major dimensions of fragmentation in 6G security and privacy. These dimensions span technological, architectural, intelligence-driven, and standards-related perspectives, collectively creating a complex and highly dynamic threat landscape. The fragmentation of security and privacy requirements across heterogeneous technologies, architectures, AI systems, standards, and management domains highlights the need for a holistic protection strategy. To address this challenge, we propose a Unified Security and Privacy Framework for AI-native 6G networks. The framework organizes security and privacy requirements into five security domains and five cross-layer security functions that collectively provide end-to-end protection across the 6G ecosystem. The proposed framework serves as the foundation for the subsequent threat taxonomy, standards harmonization, and countermeasure analysis presented in this paper. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
5
Security and Privacy Objectives (Confidentiality, Integrity, Availability, Privacy, and Resilience)
Privacy Protection Layer
AI/Intelligence Security Layer Network & Architectural Security Layer
AI Governance and Assurance
Security Management Layer
Standards Harmonization
Cross-Layer Functions
Privacy Governance and Compliance
Security Orchestration and Automation
Identity and Access Management
Cross-Layer Functions
Infrastructure Security Layer
Fig. 2. Proposed Unified Security and Privacy Framework for AI-Native 6G Networks.
3
Proposed Unified Security and Privacy Objectives for AI-Native 6G Networks
The proposed Unified Security and Privacy Framework adopts a defense-in-depth approach for AI-native 6G networks by integrating layer-specific security mechanisms with cross-layer security functions. The framework organizes security and privacy requirements into five security domains, namely Infrastructure Security, Network and Architectural Security, AI Security, Privacy Protection, and Security Management, which collectively address the diverse threat landscape identified in the proposed cross-layer taxonomy. To ensure end-to-end protection, five cross-layer functions—Identity and Access Management, Security Orchestration and Automation, AI Governance and Assurance, Privacy Governance and Compliance, and Standards Harmonization—operate across all layers to provide continuous authentication, policy enforcement, risk management, accountability, and regulatory compliance. Through the coordinated interaction of these components, the framework aims to achieve key security and privacy objectives, including confidentiality, integrity, availability, privacy preservation, resilience, trustworthiness, and compliance across heterogeneous AI-native 6G ecosystems. 4
Cross-Layer Threat Taxonomy
The heterogeneous and AI-native nature of 6G networks introduces a diverse threat landscape that extends beyond traditional communication systems. Due to integration of advanced communication technologies, distributed intelligence, autonomous decision-making, integrated sensing, and highly decentralized infrastructures, 6G networks create new attack surfaces across multiple layers of the network. To systematically analyze these threats and identify their security and privacy implications, we propose a cross-layer threat taxonomy that classifies threats into five major categories: Infrastructure Threats, Network Threats, AI Threats, Privacy Threats, and Security Management Threats. This taxonomy Manuscript submitted to ACM
6
Barua, et al.
Infrastructure threats
Network and Architectural Threats
AI/Intelligence Threats
Privacy Threats
Security Management Threats
Description
Threats targeting the physical and radio infrastructure, spectrum, devices & sensing environment
Threats exploiting the network architecture, virtualization & control mechanisms
Threats targeting AIdriven components, data, models, and autonomous decisions
Threats causing unlawful collection, inference, tracking or misuse of user data
Threats targeting security management functions, identity, credentials and security lifecycle management
Key Technologies
RIS, JCAS, NTN, THz, XL-MIMO & Advanced MIMO
O-RAN, Network Slicing, IBN, MEC & Edge Intelligence
FL, Foundation models and LLMs, AI-RAN , MAS
JCAS Data, Digital Twins, XR and Metaverse, Semantic Communications
ZTA, PQC, Secure Boot and Attestation
Representative Threats
RIS manipulation & spoofing, JCAS data leakage, NTN spoofing and jamming, XLMIMO eavesdropping & signal manipulation
O-RAN interface attacks, network slice breaches, MEC compromise, intent manipulation and control plane attacks
Data poisoning and model manipulation, adversarial attacks & evasion, model extraction & invasion, malicious agent attacks
Unauthorized data collection & inference, tracking and behavioral profiling, re-identification & likability, context leakage
Identity spoofing and policy manipulation, cryptographic attacks & quantum threats, platform integrity violations
Impact
Communication disruption, signal manipulation, confidentiality loss
Network compromise, service disruption, loss of isolation
Incorrect decisions, model compromise, autonomous system failures
Privacy violations, re-identification, regulatory noncompliance
Identity compromise, loss of platform trust, long-term security degradation
Threat domain
Fig. 3. Cross-Layer Taxonomy of Threats in AI-Native 6G.
provides a unified framework for understanding the evolving 6G threat landscape and serves as the basis for the subsequent analysis of vulnerabilities, standardization gaps, and security requirements. 4.1
Infrastructure Layer Threats
The Infrastructure Layer forms the foundation of AI-native 6G networks and encompasses the physical communication, sensing, and connectivity technologies that enable ubiquitous and ultra-reliable services. Key infrastructure enablers include Reconfigurable Intelligent Surfaces (RIS), Joint Communication and Sensing (JCAS), Non-Terrestrial Networks (NTN), and Massive Multiple-Input Multiple-Output (mMIMO) systems. While these technologies significantly enhance network coverage, capacity, intelligence, and sensing capabilities, they also introduce new attack surfaces that extend beyond those encountered in conventional wireless networks. Threats at this layer primarily target the integrity, confidentiality, and availability of physical communications, sensing operations, radio resources, and distributed infrastructure components. The following subsections examine the major security and privacy threats associated with these enabling technologies and discuss their implications for future 6G deployments. 4.1.1 Reconfigurable Intelligent Surface Threats: Reconfigurable Intelligent Surfaces (RIS) are expected to become key infrastructure components of AI-native 6G networks, enabling programmable control of wireless propagation environments and improving coverage, reliability, and spectral efficiency. However, their programmable and distributed nature introduces new security and privacy risks beyond those encountered in conventional wireless systems. Adversaries may exploit RIS control mechanisms to manipulate signal propagation, intercept communications, infer user information, or disrupt network operations. Furthermore, the large-scale deployment of AI-orchestrated RIS infrastructures increases Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
7
Table 2. Major Infrastructure Threats in RIS-Enabled 6G Networks
Threat Passive Eavesdropping [131] Illegal or Rogue RIS [49]
Description RIS reflections unintentionally expose signals to unauthorized receivers. Unauthorized RIS devices manipulate signal propagation or redirect traffic. Malicious Reconfiguration Attackers compromise RIS controllers and [124] modify reflection parameters. Control Channel Attacks Compromise of RIS control signaling and [124] management interfaces. Side-Channel Information Analysis of RIS control signals to infer netLeakage [124] work behavior. Location and Behavioral In- RIS-assisted sensing and propagation characteristics reveal user context. ference [70]
Potential Impact in 6G Networks Disclosure of confidential communications and user information. Traffic interception, service disruption, and data leakage. Beam manipulation, degraded communication quality, and denial of service. Unauthorized configuration changes and loss of network integrity. Exposure of operational information and traffic patterns. Privacy leakage involving location, mobility, and behavioral patterns.
Table 3. Major Infrastructure Threats in JCAS-Enabled 6G Networks
Threat Sensing Data Manipulation [14, 81] Data Poisoning [136]
Unauthorized Sensing and Consent Violations [79, 81] Authentication and Access Control Attacks [81, 35] Edge Data Exploitation [19]
Description Attackers tamper with sensing information through spoofing, replay, jamming, or falsified measurements. Malicious sensing data are injected to manipulate sensing models and inference processes. Sensing activities are performed without user awareness or explicit consent. Unauthorized entities gain access to sensing data or manipulate disclosure mechanisms. Sensitive sensing information processed at edge nodes is extracted or misused.
Potential Impact in 6G Networks Incorrect sensing outcomes and compromised decision making. Reduced sensing accuracy and unreliable network intelligence. Regulatory non-compliance and privacy breaches. Compromised data integrity, confidentiality, and trustworthiness. Exposure of personally identifiable information and operational data.
the risk of unauthorized reconfiguration and malicious control, highlighting the need for secure RIS management and trust mechanisms. Table 2 summarizes the major security and privacy threats associated with RIS-enabled 6G networks. 4.1.2 Joint Communication and Sensing Security Threats: Joint Communication and Sensing (JCAS) is a key enabling technology for AI-native 6G networks that integrates communication and sensing functionalities within a unified wireless framework. By leveraging shared radio resources, JCAS supports applications such as environmental perception, localization, autonomous transportation, digital twins, and intelligent infrastructure. However, the simultaneous processing of communication and sensing information introduces unique security and privacy challenges that are not present in conventional wireless systems. Adversaries may exploit sensing capabilities to infer sensitive information, manipulate sensing data, compromise data integrity, or gain unauthorized access to contextual information. Table 3 summarizes the major security and privacy threats associated with JCAS-enabled 6G networks. 4.1.3 Non-Terrestrial Network Threats: Non-Terrestrial Networks (NTN), comprising satellites, High-Altitude Platform Stations (HAPSs), and Unmanned Aerial Vehicles (UAVs), are expected to play a crucial role in AI-native 6G networks by Manuscript submitted to ACM
8
Barua, et al. Table 4. Major Infrastructure Threats in NTN-Enabled 6G Networks
Threat Eavesdropping and Signal Interception [73, 43]
Description Long-distance broadcast transmissions expose communications to unauthorized interception. Jamming and Denial-of- Adversaries disrupt NTN communication Service [43] links through interference and signal jamming. Cross-Domain Trust and Exploitation of authentication and trust Authentication Attacks [1] mechanisms across terrestrial, aerial, and satellite domains. Virtualization and Control Attacks targeting SDN/NFV, O-RAN interPlane Attacks [73, 105] faces, and cloudified space infrastructures. AI-Induced Threats [64, 45]
Supply Chain and COTS Vulnerabilities [73] Privacy Leakage [1]
Potential Impact in 6G Networks Disclosure of sensitive information and loss of communication confidentiality. Service degradation, communication outages, and reduced network availability. Unauthorized access and compromised network interoperability.
Compromised network control, resource manipulation, and service disruption. Poisoning, evasion, model theft, and manip- Incorrect spectrum allocation, beamulation of AI-driven NTN operations. forming, and network management decisions. Exploitation of vulnerabilities in System compromise and propagation commercial-off-the-shelf hardware of malicious code across network segand software components. ments. Exposure of user, operational, and contex- Privacy violations and unauthorized tual information across multiple domains. tracking of users and devices.
extending connectivity beyond terrestrial infrastructures. Through the integration of space-air-ground networks, NTN enable global coverage, ubiquitous IoT connectivity, disaster recovery services, and mission-critical communications. However, their highly distributed architecture, long-distance wireless links, reliance on commercial-off-the-shelf components, virtualization technologies, and increasing use of AI-driven automation introduce significant security and privacy challenges. The heterogeneous and multi-domain nature of NTN further complicates trust establishment, authentication, and end-to-end security. Table 4 summarizes the major security and privacy threats associated with NTN-enabled 6G networks. 4.1.4 Threats in Emerging Spectrum Technologies: Emerging spectrum technologies, including Terahertz (THz) communications and Optical Wireless Communications (OWC) systems such as Visible Light Communications (VLC) and LiFi, are expected to play a vital role in enabling ultra-high data rates, massive capacity, and low-latency services in AI-native 6G networks. While these technologies offer highly directional transmissions and improved spectrum utilization, they also introduce new security and privacy challenges. The unique propagation characteristics of THz and optical channels create vulnerabilities related to eavesdropping, signal interception, jamming, spoofing, and data manipulation. Furthermore, the increasing deployment of hybrid RF-optical systems and public-access communication infrastructures expands the attack surface and complicates security management. Table 5 summarizes the major security and privacy threats associated with emerging spectrum technologies in 6G networks. 4.1.5 Extremely Large-Scale MIMO and Advanced MIMO Threats: Massive MIMO (mMIMO) technologies are evolving in 6G toward Extremely Large MIMO (XL-MIMO), Cell-Free Massive MIMO, and Distributed MIMO architectures, enabling higher spectral efficiency, enhanced coverage, ultra-precise beamforming, and AI-driven radio resource management. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
9
Table 5. Major Infrastructure Threats in Emerging Spectrum Technologies for 6G Networks
Threat THz Eavesdropping [132, 80]
Description Line-of-sight THz transmissions may be intercepted despite highly directional beamforming. Beam Misalignment and Hi- Adversaries exploit beam training or beam jacking [54] steering procedures to intercept or redirect highly directional transmissions. Optical Signal Injection [86] Malicious optical transmitters inject forged VLC/LiFi signals into legitimate communication channels. Jamming and Interference Intentional optical or THz interference deAttacks [86] grades communication quality and availability. Cooperative Eavesdropping Multiple adversaries collaborate to intercept [86] VLC or hybrid RF-optical transmissions. Hybrid RF-Optical Attack Propagation [50] Privacy Leakage [77]
Potential Impact in 6G Networks Disclosure of confidential communications and sensitive information. Loss of communication confidentiality, degraded link performance, and service disruption. False data delivery, communication disruption, and compromised system integrity. Reduced throughput, denial of service, and communication outages.
Enhanced capability to recover confidential information and infer user activities. Vulnerabilities in one communication do- Cross-domain security breaches and exmain (RF or optical) are leveraged to com- panded attack surfaces. promise the other. Communication patterns, localization infor- Unauthorized profiling, tracking, and mation, or contextual data reveal user be- privacy violations. havior and activities.
However, the increased spatial resolution, distributed deployment, and integration of AI-driven beam management introduce new security and privacy challenges. Adversaries may target channel estimation procedures, beamforming mechanisms, machine learning models, and wireless propagation characteristics to compromise confidentiality, integrity, and availability. Furthermore, the fine-grained spatial awareness provided by advanced MIMO systems raises concerns regarding user privacy and location inference. Table 6 summarizes the major security and privacy threats associated with XL-MIMO and advanced MIMO technologies in AI-native 6G networks. 4.2
Network and Architectural Threats
The Network and Architectural Layer encompasses the software-defined, cloud-native, and intelligent networking technologies that underpin AI-native 6G systems. 6G networks are expected to rely extensively on open architectures, distributed cloud infrastructures, autonomous network management, and intelligent security mechanisms to support highly dynamic and heterogeneous services. Key architectural enablers include Open Radio Access Networks (O-RAN), Network Slicing, Intent-Based Networking (IBN), Multi-Access Edge Computing (MEC) and Edge Intelligence. While these technologies enhance flexibility, scalability, automation, and service agility, they also introduce new attack surfaces associated with virtualization, orchestration, distributed control, open interfaces, and autonomous decision making. Consequently, vulnerabilities at the network and architectural layer can have system-wide impacts, affecting service availability, network integrity, privacy, and trust. The following subsections examine the major security and privacy threats associated with these architectural enablers and their implications for AI-native 6G deployments. Manuscript submitted to ACM
10
Barua, et al. Table 6. Major Infrastructure Threats in XL-MIMO and Advanced MIMO Systems
Threat Description Eavesdropping and Spoof- Attackers exploit uplink training and downing [68] link transmissions to intercept communications or impersonate legitimate users. Pilot Contamination and In- Malicious manipulation of pilot signals corjection [46] rupts Channel State Information (CSI) and beamforming processes. Beamforming Manipulation Adversaries influence beam selection or [16] steering mechanisms to redirect or disrupt transmissions. Adversarial Machine Learn- Poisoning, evasion, and model inversion ating Attacks [10] tacks target AI-driven channel estimation and beam prediction systems. Side-Channel Inference [66] Spatial signal characteristics are exploited to infer user location, mobility patterns, or application behavior. Jamming and Interference Malicious interference targets large-scale Attacks [125] antenna arrays and beamforming operations. CSI Manipulation [16] Attackers tamper with channel estimation information used for resource allocation and transmission optimization.
Potential Impact in 6G Networks Compromised confidentiality, unauthorized access, and degraded trust. Reduced communication quality and degraded beamforming accuracy. Service degradation, signal leakage, and denial of service. Compromised network optimization and unreliable AI-assisted decisions. Privacy leakage and unauthorized user profiling. Reduced availability and communication reliability. Incorrect scheduling, resource allocation, and communication failures.
4.2.1 Open RAN Threats: Open RAN (O-RAN) is a key architectural enabler of AI-native 6G networks, promoting openness, programmability, virtualization, and multi-vendor interoperability through standardized interfaces and disaggregated network functions. While these characteristics enhance flexibility and innovation, they also expand the attack surface compared with traditional vendor-specific RAN deployments. In particular, the integration of cloud-native infrastructures, Service Management and Orchestration (SMO) platforms, Near-Real Time (Near-RT) and Non-Real Time (Non-RT) RAN Intelligent Controllers (RICs), and AI-driven xApps/rApps introduces new vulnerabilities associated with open interfaces, intelligent control loops, software supply chains, and third-party applications. Consequently, future O-RAN deployments must address threats targeting interface security, AI-enabled network control, virtualization platforms, and security management across heterogeneous ecosystems. Table 7 summarizes the major security and privacy threats associated with O-RAN-enabled 6G networks. 4.2.2 Network Slicing Threats: Network slicing is a fundamental architectural capability of AI-native 6G networks that enables multiple virtualized and logically isolated services to coexist on a shared physical infrastructure. While this flexibility supports diverse application requirements and efficient resource utilization, it also introduces new security and privacy challenges arising from virtualization, multi-tenancy, dynamic orchestration, and resource sharing. In particular, vulnerabilities in slice isolation, orchestration platforms, and trust relationships can be exploited to compromise service confidentiality, integrity, and availability. Furthermore, the increasing integration of edge intelligence and AI-enabled services within network slices raises additional concerns regarding data leakage and privacy preservation. Table 8 summarizes the major security and privacy threats associated with network slicing in AI-native 6G networks. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
11
Table 7. Major Network and Architectural Threats in O-RAN-Enabled 6G Networks
Threat Open Interface Attacks [60, 37]
Description Exploitation of E2, A1, O1, O2, and Open Fronthaul interfaces through message tampering, unauthorized access, or protocol abuse. Denial-of-Service (DoS) At- Overloading or disrupting open interfaces, tacks [107] RIC functions, or management platforms. Malicious xApps/rApps [85] Compromised or malicious third-party applications manipulate RAN control decisions and policies. AI/ML Model Manipulation Poisoning, evasion, model theft, or adversar[85, 84] ial attacks targeting AI-driven control functions within Near-RT and Non-RT RICs. Cloud-Native Infrastructure Container breakout, privilege escalation, latAttacks [98] eral movement, and attacks on virtualized infrastructure. Supply Chain Attacks [60, Exploitation of vulnerabilities in hardware, 42] software, firmware, or update mechanisms across multiple vendors . API and Orchestration At- Abuse of exposed APIs, orchestration plattacks [84] forms, or SMO functions. Data Leakage and Privacy Exposure of telemetry, operational, and Attacks [102] user-related information across open interfaces.
Potential Impact in 6G Networks Compromised network integrity, information leakage, and service disruption.
Service degradation and reduced network availability. Incorrect resource allocation, degraded performance, and network instability. Unreliable network optimization and compromised autonomous decision making. Compromise of hosting platforms and critical network functions. Backdoor insertion, unauthorized access, and trust violations. Unauthorized configuration changes and service manipulation. Privacy violations and disclosure of sensitive network information.
Table 8. Major Network and Architectural Threats in Network Slicing for AI-Native 6G Networks
Threat Slice Isolation Breaches [21, 29] Resource Exhaustion Attacks [21] Orchestration and Management Attacks [23, 21] Data Leakage and Privacy Attacks [63, 57] Inter-Slice Trust Exploitation [21] Slice Misconfiguration [21]
Description Exploitation of vulnerabilities in logical isolation mechanisms between slices. Malicious consumption of shared compute, storage, or bandwidth resources . Compromise of slice orchestration, life cycle management, or control interfaces . Exposure of user, application, or operational data through shared infrastructures . Abuse of trust relationships among slices, tenants, or service providers . Incorrect or malicious modification of slice policies and security settings.
Potential Impact Unauthorized access, lateral attacks, and compromise of tenant isolation. QoS degradation and denial of service to critical slices. Service hijacking, malicious reconfiguration, and network disruption. Privacy violations and sensitive information disclosure. Privilege escalation and cross-slice compromise. Unauthorized access and weakened security controls.
4.2.3 Intent-Based Networking Threats: Intent-Based Networking (IBN) is emerging as a key architectural enabler of AI-native 6G networks, allowing operators and applications to specify high-level service intents that are automatically translated into network configurations and operational policies. By leveraging AI, automation, and closed-loop Manuscript submitted to ACM
12
Barua, et al. Table 9. Major Network and Architectural Threats in Intent-Based Networking for AI-Native 6G Networks
Threat Intent Manipulation [15, 56]
Description Malicious modification of user or operator intents before execution. Intent Translation Attacks Compromise of intent-to-policy translation [15] mechanisms and decision engines. Intent Conflict Exploitation Injection of conflicting or ambiguous in[9] tents to trigger unintended actions. AI Model Manipulation Poisoning or evasion attacks targeting AI [115] models used for intent interpretation and orchestration. Orchestration Platform At- Unauthorized access to orchestration and tacks [56] policy management functions . Privacy Leakage [15] Exposure of user intents, operational policies, and contextual information during intent processing. Trust and Explainability Lack of transparency or validation in autoFailures [9] mated intent execution.
Potential Impact Unauthorized network behavior and policy violations. Incorrect network configurations and service disruption. Resource misallocation and degraded service performance. Compromised autonomous decision making and unreliable automation. Service hijacking and malicious network reconfiguration. Disclosure of sensitive business and user information. Reduced trust in autonomous network operations.
orchestration, IBN enables autonomous network management, dynamic service provisioning, and adaptive resource optimization. However, the abstraction of network control through intent-driven automation introduces new security and privacy challenges. Adversaries may manipulate intent definitions, compromise intent translation mechanisms, exploit AI-driven decision engines, or target orchestration platforms to influence network behavior. Furthermore, the increasing reliance on AI models and autonomous policy enforcement raises concerns regarding trustworthiness, explainability, and resilience against adversarial manipulation. Table 9 summarizes the major security and privacy threats associated with Intent-Based Networking in AI-native 6G networks. 4.2.4 Multi-Access Edge Computing and Edge Intelligence Threats: Multi-Access Edge Computing (MEC) and Edge Intelligence are expected to play a pivotal role in AI-native 6G networks by enabling distributed computing, real-time analytics, intelligent service orchestration, and low-latency AI applications closer to end users. By hosting network functions, AI models, digital twins, and data-intensive applications at the network edge, MEC significantly enhances responsiveness and resource efficiency. However, the distributed and resource-constrained nature of edge environments introduces new security and privacy challenges. Adversaries may target edge nodes, virtualized workloads, AI models, and data processing pipelines to compromise service integrity, confidentiality, and availability. Furthermore, the proximity of edge platforms to end users and IoT devices increases the risk of privacy leakage, unauthorized access, and exploitation of sensitive contextual information. Table 10 summarizes the major security and privacy threats associated with MEC and Edge Intelligence in AI-native 6G networks. 4.3
AI/Intelligence Threats
AI-native 6G networks fundamentally transform network operation by embedding AI into communication, resource management, service orchestration, and autonomous decision making. While AI enables intelligent and adaptive network behavior, it also introduces a new class of security threats targeting AI models, training data, inference processes, and autonomous agents. Unlike conventional cyberattacks, AI-specific threats can manipulate model behavior, compromise Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
13
Table 10. Major Network and Architectural Threats in MEC and Edge Intelligence for AI-Native 6G Networks
Threat Edge Node Compromise [122] Virtualization and Container Attacks [122, 88]
Description Compromise of edge servers hosting applications, network functions, or AI services . Exploitation of virtual machines, containers, or orchestration platforms deployed at the edge. Data Leakage and Privacy Exposure of user, contextual, or operational Attacks [122] data processed at edge nodes. AI Model Poisoning and Ma- Poisoning or adversarial manipulation of AI nipulation [115] models deployed for edge intelligence . Resource Exhaustion At- Malicious consumption of computing, stortacks [122] age, or communication resources at the edge. Unauthorized Service Mi- Manipulation of workload migration and gration [88] service placement mechanisms . Trust and Authentication Exploitation of weak authentication or trust Attacks [12] management among edge nodes and users.
Potential Impact Service disruption, unauthorized access, and data leakage. Privilege escalation and compromise of multiple edge services. Privacy violations and disclosure of sensitive information. Incorrect inference and compromised autonomous decisions. QoS degradation and denial of service.
Service hijacking and operational disruption. Unauthorized access and compromised service integrity.
Table 11. Major AI/Intelligence Threats in Federated Learning for AI-Native 6G Networks
Threat Data Poisoning [40, 92] Model Poisoning [59, 41] Backdoor Attacks [8] Model Inversion [33, 104] Membership Inference [91] Gradient Leakage [91] Sybil Attacks [113]
Description Malicious clients inject manipulated training samples to corrupt the learning process. Attackers manipulate gradient updates or model parameters during aggregation. Insertion of trigger patterns that induce malicious model behavior during inference. Reconstruction of sensitive training data from shared model updates. Inference of whether a specific data sample participated in training. Recovery of private information from exchanged gradients. An adversary creates multiple fake clients to influence model aggregation.
Potential Impact in 6G Reduced model accuracy and unreliable AI-driven network decisions. Compromised model integrity and targeted misclassification. Hidden vulnerabilities in AI-enabled network services. Privacy leakage in digital twins, healthcare, and smart-city applications. Disclosure of sensitive user information and participation. Exposure of user, sensing, and operational data. Manipulation of global model updates and trust mechanisms.
decision making, and propagate across distributed AI ecosystems, potentially affecting multiple network functions simultaneously. As AI becomes a core component of AI-native 6G, ensuring the security, robustness, and trustworthiness of intelligent systems throughout the AI life cycle has become a critical research challenge. The following subsections review the major AI and intelligence-related technologies in 6G and analyze their associated security threats. 4.3.1 Federated Learning Threats: Federated Learning (FL) is considered a key enabler of AI-native 6G networks due to its ability to support distributed intelligence while preserving data locality and reducing communication overhead. However, despite keeping raw data on local devices, FL remains vulnerable to a variety of security and privacy attacks. The decentralized nature of FL allows malicious participants to manipulate model training through poisoning attacks, Manuscript submitted to ACM
14
Barua, et al. Table 12. Major AI/Intelligence Threats in Foundation Models and LLMs for AI-Native 6G Networks
Threat Description Prompt Injection & Jail- Malicious prompts manipulate model bebreak Attacks [127, 82] havior, override system instructions, or bypass safety mechanisms. Training Data Poisoning & Adversarial samples inserted during trainBackdoor Attacks [135, 112] ing or fine-tuning create hidden malicious behaviors. Privacy Leakage & Sensi- Models unintentionally reveal training data, tive Information Disclosure user information, or proprietary knowl[18, 58] edge. Membership Inference & Attackers infer whether specific records Model Inversion [31] were used for training or reconstruct sensitive information. Model Extraction & Model Repeated queries are used to replicate model Theft [133, 110] functionality or steal proprietary parameters. Retrieval-Augmented Gen- Manipulation of external knowledge eration (RAG) Poisoning sources used by LLMs. [82] Excessive Agency & Au- Attackers exploit AI outputs to trigger untonomous Decision Manip- intended actions through connected tools ulation [82, 110] or controllers. Adversarial Prompting & Carefully crafted inputs cause incorrect preEvasion Attacks [36, 110] dictions or responses during inference.
Potential Impact in 6G Compromised network orchestration, incorrect policy enforcement, disruption of autonomous management. Reduced model integrity, unreliable decision making, compromised AI-driven security functions. Exposure of user data, network telemetry, digital twin information, and sensing data. Privacy violations in personalized services, healthcare, ITS, and digital twins. Loss of intellectual property, replication of AI services, weakened security assurance. Injection of malicious knowledge into network management and decision support systems. Compromised resource allocation, slice management, orchestration, and network control. Bypassing AI-based intrusion detection and security analytics.
while shared model updates may leak sensitive information through inference and reconstruction attacks. These threats are particularly significant in 6G environments characterized by massive connectivity, heterogeneous edge devices, digital twins, intelligent transportation systems, and mission-critical applications. Table 11 summarizes the major security and privacy threats associated with FL in AI-native 6G networks. 4.3.2 Foundation Model and Large Language Model Threats: Foundation models and Large Language Models (LLMs) are expected to support autonomous network management, orchestration, digital twins, and edge intelligence in AI-native 6G networks. However, they introduce novel attack surfaces, including prompt injection and jailbreak attacks, training-data poisoning and backdoors, privacy leakage through inference and extraction attacks [116], model extraction and intellectual property theft, and autonomous decision manipulation. These threats may compromise model integrity, confidentiality, trustworthiness, and network reliability, necessitating robust AI assurance and privacy-preserving safeguards. Table 12 summarizes the major security and privacy threats associated with foundation models and LLMs. 4.3.3 Threats against AI-enabled network operations: AI-RAN and Edge Intelligence are emerging as fundamental components of AI-native 6G networks, enabling intelligent radio resource management, autonomous network optimization, predictive maintenance, energy-efficient operation, and real-time service orchestration. By integrating AI directly into the Radio Access Network (RAN) and edge infrastructure, these technologies facilitate low-latency decision-making and distributed intelligence across heterogeneous network environments. However, their extensive reliance on AI models, edge computing resources, and open network architectures introduces new security and privacy challenges. Adversaries may target AI training pipelines, edge infrastructure, model repositories, or decision-making processes to Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
15
Table 13. Major AI/Intelligence Threats in AI-RAN and Edge Intelligence for AI-Native 6G Networks
Threat Model Poisoning [21] Adversarial Evasion [36, 110] Edge Node Compromise [26] Model Theft and Extraction [26] Privacy Leakage [116] Data Poisoning [87] Resource Exhaustion [52] AI Decision Manipulation [82, 110]
Description Manipulation of AI-RAN training data or model updates. Crafted inputs cause AI models to generate incorrect predictions or classifications. Compromise of edge servers hosting AI models and network functions. Reconstruction or replication of deployed AI models through repeated queries. Exposure of user, telemetry, or operational data processed at edge nodes. Manipulation of telemetry or training datasets used by AI models. Consumption of computational or communication resources at edge nodes. Exploitation of autonomous AI-driven control loops and orchestration systems.
Potential Impact in 6G Networks Incorrect AI-driven network decisions. Bypassing AI-enabled intrusion detection and anomaly detection systems. Service disruption, unauthorized access, and data leakage. Intellectual property loss and unauthorized duplication of AI services. Disclosure of sensitive information and privacy violations. Reduced model accuracy and unreliable network decisions. Service degradation and denial of AIassisted network functions. Incorrect slice management, resource allocation, and service orchestration.
Table 14. Major AI/Intelligence Threats in Multi-Agent Systems for AI-Native 6G Networks
Threat Agent Impersonation [52]
Description Malicious entities masquerade as legitimate agents to gain unauthorized participation.
Potential Impact in 6G Networks Unauthorized access, trust violations, and manipulation of collaborative decisions. Trust Poisoning [76] Attackers manipulate reputation or trust Selection of malicious agents and degrascores used among agents. dation of network reliability. Malicious Agent Insertion Compromised or rogue agents join the sys- Disruption of orchestration, resource al[134] tem and participate in coordination tasks. location, and service management. Collusion Attacks [26] Multiple malicious agents cooperate to in- Biased outcomes and coordinated mafluence collective decision making. nipulation of network behavior. Communication Manipula- Interception, modification, or spoofing of Loss of integrity and reliability of distion [26] inter-agent messages. tributed coordination. Privacy Leakage [103] Sensitive information exchanged among Disclosure of user, operational, and conagents is exposed or inferred. textual information. Reward Manipulation [121] Attackers manipulate feedback or reward Suboptimal or adversarial agent behavsignals used for learning. ior. Autonomous Decision Ma- Exploitation of autonomous planning and Incorrect orchestration, resource allocanipulation [48] decision-making mechanisms. tion, and service delivery. manipulate network operations, degrade service quality, or compromise sensitive information. Table 13 summarizes the major security and privacy threats associated with AI-RAN and Edge Intelligence in AI-native 6G networks. 4.3.4 Multi-Agent System Threats: Multi-Agent Systems (MAS) are expected to play a central role in AI-native 6G networks by enabling autonomous coordination among distributed intelligent entities, including network controllers, Manuscript submitted to ACM
16
Barua, et al. Table 15. Major Privacy Threats in JCAS-Enabled AI-Native 6G Networks
Threat Location Tracking [90, 61]
Behavioral Profiling [5, 19, 90] Biometric Information Leakage [79, 90] Unauthorized Sensing [19, 81] Identity Re-identification [5, 19] Information Leakage and Eavesdropping [61, 5, 38, 79]
Description Exploitation of sensing signals to continuously monitor user positions and mobility patterns. Inference of user activities, habits, and routines from sensing observations. Extraction of physiological attributes such as heart rate, gait, or motion signatures from sensing data. Collection of environmental or personal information without user knowledge or consent. Correlation of sensing data with external information sources to identify individuals. Communication and sensing operations expose sensitive channel, localization, or contextual information.
Potential Impact Loss of location privacy and unauthorized surveillance. User profiling and privacy erosion. Disclosure of sensitive personal and health-related information. Violation of privacy regulations and user autonomy. Loss of anonymity and personal privacy. Disclosure of user location, mobility patterns, and confidential communications.
edge nodes, digital twins, autonomous vehicles, and service orchestrators. Through collaborative decision-making and task allocation, MAS can support self-organizing networks, intelligent resource management, and adaptive service delivery. However, the distributed and autonomous nature of MAS introduces unique security and privacy challenges. Adversaries may exploit communication channels, manipulate trust relationships, compromise individual agents, or influence collaborative decision-making processes to disrupt network operations. As autonomous agents increasingly interact with critical network functions, ensuring trustworthy coordination and resilient cooperation becomes essential. Table 14 summarizes the major security and privacy threats associated with Multi-Agent Systems in AI-native 6G networks. 4.4
Privacy Threats
The 6G applications have very demanding performance requirements, which are provided by highly complex applications with highly malicious actors in the network. This leads to stringent security requirements in these networks. To understand the security and privacy threats in these applications, we discuss the threat landscape for digital twins, and AI agents. Although these applications are not enabling technologies, it is necessary to identify and find countermeasures for making these applications secure and resilient, which finally makes them enablers of secured 6G technology. 4.4.1 JCAS Privacy Threats: As discussed in subsection 4.1.2, JCAS integrates sensing and communication functionalities within a unified wireless framework. However, the pervasive and often passive nature of sensing introduces significant privacy concerns. Unlike conventional communication systems, JCAS can continuously collect, infer, and process contextual information about users and their surroundings, potentially without explicit user awareness. Consequently, adversaries may exploit sensing capabilities to infer sensitive information, track user behavior, reconstruct personal attributes, or conduct large-scale surveillance. Table 15 summarizes the major privacy threats associated with JCASenabled AI-native 6G networks. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
17
Table 16. Major Privacy Threats in Digital Twins for AI-Native 6G Networks
Threat Identity Re-identification [51, 69] Behavioral Profiling [75, 51]
Description Correlation of DT data with external information sources to identify users. Inference of user habits, activities, and preferences from DT observations. Location and Mobility Continuous synchronization enables moniTracking [69, 83] toring of user movements and trajectories. Sensitive Data Leakage [51, Disclosure of personal, operational, or con120] textual information stored within DTs. Cross-Domain Data Aggre- Integration of data from multiple sources gation [69, 75] enables comprehensive user inference. Inference and Reconstruc- Attackers infer hidden attributes or recontion Attacks [83, 120] struct sensitive information from DT data streams. Digital Twin Data Misuse Unauthorized use or sharing of DT informa[51] tion by third parties.
Potential Impact Loss of anonymity and personal privacy. Unauthorized profiling and surveillance. Exposure of location privacy and movement patterns. Privacy violations and information disclosure. Excessive collection and misuse of personal information. Exposure of confidential personal and organizational data. Loss of data sovereignty and regulatory compliance risks.
4.4.2 Digital Twin Privacy Threats: Digital Twins (DTs) are expected to become a fundamental component of AI native 6G networks by creating real-time virtual representations of physical entities, users, devices, networks, and environments. Through continuous synchronization between physical and digital spaces, DTs enable predictive analytics, intelligent automation, network optimization, and immersive digital experiences. However, the extensive collection, aggregation, and processing of contextual information across physical and virtual domains in Digital Twins (DTs) introduce significant privacy concerns. Since DTs maintain highly detailed representations of users and environments, adversaries may exploit these systems to infer sensitive information, reconstruct user identities, track behaviors, or gain unauthorized access to personal and operational data. The integration of AI, edge intelligence, and large-scale sensing further amplifies these risks by enabling sophisticated inference and profiling attacks. Table 16 summarizes the major privacy threats associated with Digital Twins in AI-native 6G networks. 4.4.3 XR and Metaverse Privacy Threats: Extended Reality (XR) and Metaverse applications are expected to become prominent AI-native 6G services, enabling immersive human-machine interactions, digital collaboration, virtual environments, and real-time digital experiences. These applications rely on continuous collection and processing of multi-modal data, including user location, motion trajectories, eye movements, facial expressions, biometric signals, voice interactions, and environmental context. While such data are essential for delivering immersive and personalized experiences, they also introduce significant privacy risks. The integration of AI-driven analytics, edge intelligence, digital twins, and pervasive sensing further increases the possibility of user profiling, identity inference, behavioral tracking, and unauthorized disclosure of sensitive information. Consequently, preserving privacy in XR and Metaverse ecosystems represents a critical challenge for future AI-native 6G networks. Table 17 summarizes the major privacy threats associated with XR and Metaverse applications. 4.4.4 Semantic Communication Privacy Threats: Semantic Communications (SemCom) are emerging as a key enabling technology for AI-native 6G networks, aiming to transmit the semantic meaning of information rather than raw data to improve communication efficiency, intelligence, and resource utilization. By incorporating AI and knowledge-driven Manuscript submitted to ACM
18
Barua, et al. Table 17. Major Privacy Threats in XR and Metaverse Applications for AI-Native 6G Networks
Threat Location and Mobility Tracking [114, 108]
Description Continuous monitoring of user position, movement patterns, and spatial interactions. Biometric Information Exposure of eye-tracking, facial expressions, Leakage [114, 93] gestures, voice, and physiological signals. Behavioral Profiling [108, Inference of user preferences, habits, emo114] tions, and activities from XR interactions. Identity Linkage and Re- Correlation of virtual identities with realidentification [114] world identities using behavioral and contextual data. Digital Twin Data Leakage Exposure of personal or environmental in[114, 108] formation stored in digital twin representations. Contextual Information In- Extraction of environmental, social, or situference [114] ational information from immersive interactions. Cross-Platform Data Aggre- Collection and fusion of user data across gation [114] multiple XR, AI, and Metaverse services.
Potential Impact Loss of location privacy and user tracking. Identity disclosure and biometric profiling. Unauthorized profiling and targeted manipulation. Loss of anonymity and privacy violations. Disclosure of sensitive personal and contextual information. Unauthorized knowledge of user activities and surroundings. Comprehensive user surveillance and privacy erosion.
processing into communication systems, SemCom enables context-aware services, intelligent edge applications, and human-centric communications. However, the extraction, representation, and transmission of semantic information introduce unique privacy challenges that extend beyond conventional data confidentiality concerns. Adversaries may infer sensitive contextual information, reconstruct user intentions, exploit semantic knowledge bases, or correlate semantic metadata across multiple sources to reveal private information. Furthermore, the integration of foundation models, edge intelligence, and distributed AI systems into semantic communication frameworks amplifies the risks of privacy leakage and unauthorized inference. Table 18 summarizes the major privacy threats associated with Semantic Communications in AI-native 6G networks. 4.5
Security Management and Identity Threats
Security management is a fundamental pillar of AI-native 6G networks, enabling secure interactions among users, devices, AI agents, edge platforms, network functions, and service providers across highly heterogeneous and decentralized environments. Unlike previous generations, 6G networks are expected to operate through autonomous decision-making, distributed intelligence, cross-domain service orchestration, and pervasive connectivity, making traditional security mechanisms insufficient. Consequently, future networks will increasingly rely on advanced technologies such as Intelligent Zero Trust Architectures (ZTA), Post-Quantum Cryptography (PQC), and Secure Attestation mechanisms to establish, evaluate, and maintain trust throughout the network life cycle. However, these technologies also introduce new attack surfaces, including identity spoofing, credential compromise, quantum-era cryptographic threats, and attacks on trusted execution environments. The following subsections examine the major security and privacy threats associated with these security management technologies in AI-native 6G networks. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
19
Table 18. Major Privacy Threats in Semantic Communications for AI-Native 6G Networks
Threat Description Semantic Information Leak- Sensitive information is inferred from transage [99, 119] mitted semantic representations rather than raw data. Context Inference Attacks Adversaries exploit semantic context and [39, 99] knowledge graphs to infer user activities and behaviors. Semantic Reconstruction Attackers reconstruct original content from Attacks [111] semantic embeddings or latent representations. Knowledge Base Poisoning Manipulation of shared semantic knowl[99] edge repositories used for semantic reasoning and communication. Cross-Domain Correlation Semantic information from multiple doAttacks [39] mains is correlated to identify users or reveal hidden relationships. Metadata and Intent Leak- Semantic transmission reveals user goals, age [99, 39] interests, and communication intent even when payload data remain protected. LLM-Assisted Semantic In- Foundation models exploit semantic conference [116] tent to infer private attributes beyond the transmitted information.
Potential Impact Disclosure of private user intentions, preferences, and contextual information. Unauthorized profiling and behavioral tracking. Exposure of sensitive personal and operational information. Incorrect inference and privacy violations. Identity linkage and re-identification risks. Loss of user privacy and sensitive information disclosure. Large-scale privacy leakage and profiling.
Table 19. Major Security Management Threats in Intelligent Zero Trust Architectures for AI-Native 6G Networks
Threat Identity Spoofing [11, 71] Access Control Manipulation [97] Cross-Domain Authorization Attacks [34] Adversarial AI Attacks [118, 129] Behavioral Profile Manipulation [118] Privacy Leakage [71, 32] Credential and Key Compromise [11, 78]
Description Impersonation of legitimate users, devices, or AI agents. Abuse or modification of adaptive authorization policies. Exploitation of trust relationships across multiple administrative domains. Poisoning or evasion attacks targeting AIassisted security decisions. Falsification of contextual or behavioral attributes used for continuous verification. Exposure of identity and behavioral information collected for security monitoring. Theft or compromise of authentication credentials and cryptographic keys.
Potential Impact Unauthorized access and security breaches. Privilege escalation and policy violations. Unauthorized resource access and service compromise. Incorrect threat detection and access decisions. Compromised risk assessment and trust evaluation. Disclosure of sensitive user and operational data. Loss of authentication integrity and secure communications.
4.5.1 Intelligent Zero Trust Architecture (iZTA) Security Management Threats: Intelligent Zero Trust Architecture (iZTA) is emerging as a fundamental security management paradigm for AI-native 6G networks, where billions of users, devices, AI agents, network functions, and services interact across highly heterogeneous and decentralized environments. Unlike Manuscript submitted to ACM
20
Barua, et al. Table 20. Major Security Management Threats in Post-Quantum Cryptography for AI-Native 6G Networks
Threat Harvest-Now, DecryptLater [67] Quantum Cryptanalytic Attacks [100, 89]
Description Adversaries store encrypted traffic for future decryption using quantum computers. Quantum algorithms such as Shor’s algorithm threaten RSA- and ECC-based cryptography. Implementation Attacks [6, Side-channel, fault-injection, or timing at13] tacks targeting PQC implementations. Migration and Interoper- Security weaknesses arising during migraability Risks [72, 28] tion from classical to post-quantum cryptography. Key Management Attacks Compromise of cryptographic keys and cre[7] dential management systems supporting PQC deployments. Crypto-Agility Failures [72] Inability to rapidly replace or update cryptographic algorithms in evolving threat environments. Hybrid Architecture Ex- Attacks targeting interactions between ploitation [25, 130] classical and post-quantum cryptographic mechanisms.
Potential Impact Loss of long-term confidentiality and sensitive information exposure. Compromise of authentication, key exchange, and digital signatures. Secret key leakage and cryptographic compromise. Service disruption and configuration vulnerabilities. Unauthorized access and loss of communication security. Long-term exposure to emerging cryptographic vulnerabilities. Reduction of overall system security and trustworthiness.
traditional perimeter-based security approaches, iZTA adopts the principle of “never trust, always verify,” enabling continuous authentication, authorization, and adaptive access control based on real-time risk assessment and behavioral analytics [11, 71]. The integration of AI into ZTA further enables dynamic policy enforcement, automated threat detection, and context-aware security orchestration across terrestrial, aerial, satellite, and edge domains. However, the increasing reliance on AI-driven decision making, decentralized identity systems, and cross-domain access management introduces new security challenges. Adversaries may exploit identity mechanisms, manipulate access control policies, compromise trust evaluation processes, or target AI-assisted security functions to bypass security controls and gain unauthorized access. Table 19 summarizes the major security management threats associated with iZTA in AI-native 6G networks. 4.5.2 Post-Quantum Cryptography Threats: Post-Quantum Cryptography (PQC) is emerging as a critical security management technology for AI-native 6G networks due to the growing threat posed by quantum computers to conventional public-key cryptographic schemes. Future 6G ecosystems will support long-lived services involving autonomous systems, digital twins, critical infrastructures, and AI-driven applications, where the confidentiality and integrity of data must be preserved over extended periods. In this context, adversaries may exploit “harvest-now, decrypt-later” strategies by collecting encrypted communications today and decrypting them once large-scale quantum computers become available [67, 100]. To address these risks, NIST-standardized post-quantum algorithms such as Kyber and Dilithium are being integrated into next-generation communication systems [7]. However, the transition to PQC introduces new security challenges related to cryptographic migration, implementation vulnerabilities, key management, interoperability, and crypto-agility. Table 20 summarizes the major security management threats associated with PQC deployment in AI-native 6G networks. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
21
Table 21. Major Security Management Threats in Secure Boot and Remote Attestation for AI-Native 6G Networks
Threat Firmware Tampering [96]
Description Modification of firmware or bootloader components before system initialization. Attestation Forgery [20] Generation of false attestation reports to impersonate trusted platforms. Trusted Execution Environ- Exploitation of vulnerabilities in TEEs and ment Attacks [65] hardware security modules. Supply Chain Compromise Insertion of malicious hardware, firmware, [106] or software during manufacturing or deployment. Virtualization and Con- Manipulation of virtual machines, containtainer Attacks [101] ers, or network functions hosted on attested platforms. AI Model Integrity Attacks Modification of AI models or inference [123] pipelines after deployment. Credential and Key Com- Theft of attestation keys, certificates, or platpromise [55] form credentials.
Potential Impact Execution of malicious code and platform compromise. Unauthorized access and trust violations. Compromise of protected data and execution environments. Persistent backdoors and system-wide compromise. Service disruption and integrity violations. Incorrect autonomous decisions and degraded trustworthiness. Loss of trust and authentication failures.
4.5.3 Secure Boot and Remote Attestation Threats: Secure Boot and Remote Attestation are emerging as critical security management mechanisms for AI-native 6G networks, enabling the verification of platform integrity across distributed edge, cloud, and network infrastructures. Secure Boot ensures that devices and network functions execute only authenticated and trusted software during startup, while Remote Attestation allows external entities to verify the integrity and configuration of hardware, firmware, operating systems, virtualized network functions, and AI services [96, 20]. In AI-native 6G environments, these mechanisms are particularly important for securing edge intelligence platforms, O-RAN components, digital twins, autonomous agents, and cloud-native network functions. However, the increasing scale, virtualization, and decentralization of future networks introduce new attack surfaces targeting attestation protocols, trusted execution environments, firmware integrity, and supply-chain trust. Consequently, compromising platform integrity can enable attackers to bypass security controls, manipulate AI services, and gain persistent access to critical network resources. Table 21 summarizes the major security management threats associated with Secure Boot and Remote Attestation in AI-native 6G networks. 5
Countermeasures and Open Challenges
The cross-layer threat taxonomy presented in the previous section demonstrates that security and privacy risks in AI-native 6G networks extend beyond individual technologies and propagate across interconnected layers. Addressing these threats therefore requires a unified set of countermeasures that provide coordinated protection throughout the network life cycle. Guided by the proposed unified security and privacy framework, this section discusses mapping of layered threats to countermeasures, the key cross-layer security functions—including identity and access management, security orchestration and automation, AI governance and assurance, privacy governance and compliance, and standards harmonization—and outlines the open challenges that remain toward achieving secure, trustworthy, and interoperable AI-native 6G ecosystems. Manuscript submitted to ACM
22
Barua, et al. Table 22. Mapping of Layered Threats to Countermeasures in AI-Native 6G Networks
Threat Layer Infrastructure Threats
Representative Threats RIS attacks, JCAS information leakage, NTN spoofing and jamming, XL-MIMO eavesdropping Network & Architec- O-RAN interface attacks, nettural Threats work slice breaches, MEC compromise, intent manipulation AI Threats Data poisoning, adversarial attacks, model extraction, agent manipulation, model inversion Privacy Threats Location tracking, inference attacks, digital twin leakage, behavioral profiling, metadata leakage Security Management Identity spoofing, credential Threats compromise, cryptographic attacks, platform integrity violations
5.1
Key Countermeasures Physical Layer Security (PLS), secure beamforming, secure sensing, authentication mechanisms, spectrum protection, anti-jamming techniques Identity and Access Management, Intelligent ZTA, secure APIs, network isolation, remote attestation, secure orchestration and automation AI Governance and Assurance, secure model life cycle management, adversarial training, explainable AI, federated learning security, continuous model monitoring Differential Privacy, Federated Learning, Homomorphic Encryption, secure multiparty computation, privacy governance and compliance, data minimization Identity and Access Management, Post-Quantum Cryptography, Secure Boot, Remote Attestation, continuous verification, credential management
Mapping of Layered Threats to Countermeasures in AI-Native 6G Networks
The diverse threat landscape of AI-native 6G networks necessitates a multi-layered and coordinated defense strategy. As shown in Table 22, threats arising across infrastructure, network and architectural, AI, privacy, and security management domains require corresponding security and privacy mechanisms tailored to their unique characteristics. While infrastructure threats can be mitigated through physical-layer security and secure communication techniques, network and architectural threats require robust identity management, access control, and security orchestration mechanisms. Similarly, AI-related threats demand governance and assurance frameworks to ensure the robustness, transparency, and trustworthiness of intelligent systems. Privacy threats necessitate privacy-enhancing technologies and regulatory compliance mechanisms, whereas security management threats require advanced cryptographic protections, platform integrity verification, and continuous authentication. Collectively, these countermeasures provide the foundation for the proposed unified security and privacy framework, enabling end-to-end protection across heterogeneous AI-native 6G environments. Table 22 illustrates how the diverse threats identified across the proposed cross-layer taxonomy can be mitigated through a set of complementary security and privacy mechanisms. While individual countermeasures address specific vulnerabilities within particular domains, effective protection of AI-native 6G networks requires coordinated security functions that operate across multiple layers. Consequently, the following subsections discuss four key cross-layer security functions—Identity and Access Management, Security Orchestration and Automation, AI Governance and Assurance, and Privacy Governance and Compliance—which collectively form the foundation of the proposed unified security and privacy framework. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks 5.2
23
Cross-Layer Countermeasure-Identity and Access Management
Identity and Access Management (IAM) serves as a foundational countermeasure for mitigating cross-layer security threats in AI-native 6G networks by enabling continuous authentication, authorization, and access control across heterogeneous users, devices, AI agents, and network functions. As 6G ecosystems become increasingly decentralized and autonomous, robust IAM mechanisms are essential for preventing identity spoofing, unauthorized access, privilege escalation, and cross-domain security breaches. Emerging approaches such as iZTA, decentralized identity management, multi-factor authentication (MFA), and continuous verification provide adaptive and context-aware access control capabilities suitable for dynamic 6G environments [11, 71, 32]. Furthermore, integrating IAM with remote attestation, credential management, and AI-assisted risk assessment can strengthen trust establishment and secure interactions across infrastructure, network, AI, privacy, and security management domains [97, 118]. Despite significant advances in identity and access management, several challenges remain for AI-native 6G networks. First, the massive scale and heterogeneity of 6G ecosystems, encompassing terrestrial, aerial, satellite, edge, and AIdriven domains, make unified identity management and interoperability across administrative boundaries a difficult task. Second, continuous authentication and context-aware access control may introduce substantial signaling and computational overhead, particularly for resource-constrained devices and ultra-low-latency applications. Third, the increasing adoption of autonomous AI agents, digital twins, and multi-agent systems necessitates new identity frameworks capable of securely managing machine-to-machine interactions while preserving privacy and accountability. Addressing these challenges will be critical for realizing scalable, interoperable, and trustworthy identity and access management in AI-native 6G networks.
5.3
Cross-Layer Countermeasure-Security Orchestration and Automation
Security Orchestration and Automation (SOA) is a key enabler for managing the complexity of AI-native 6G networks, where security decisions must be coordinated across heterogeneous infrastructures, network domains, AI systems, and privacy-sensitive applications. By integrating automated threat detection, policy enforcement, incident response, and life cycle management, SOA enables real-time adaptation to evolving cyber threats while reducing operational overhead. Emerging frameworks such as Zero-Touch Service Management (ZSM), intent-driven security management, and AI-assisted orchestration facilitate autonomous security operations through continuous monitoring and dynamic policy updates [47, 73]. Furthermore, security orchestration can enhance cross-domain visibility and enable coordinated responses to attacks spanning infrastructure, network, AI, and privacy layers, thereby improving the resilience and adaptability of future 6G ecosystems [85, 11]. Despite its potential, several challenges hinder the realization of effective security orchestration and automation in AInative 6G networks. Firstly, achieving interoperability among heterogeneous technologies, vendors, and administrative domains remains difficult due to differing security policies, interfaces, and operational requirements. Secondly, the increasing reliance on AI-driven orchestration introduces risks associated with adversarial manipulation, explainability, and accountability of automated security decisions. Thirdly, ensuring real-time threat detection and coordinated response across highly distributed environments, including edge, cloud, terrestrial, and non-terrestrial networks, presents significant scalability challenges. Finally, balancing automation with human oversight remains an open issue, particularly in safety-critical scenarios where incorrect security decisions may have widespread operational consequences. Manuscript submitted to ACM
24
Barua, et al.
5.4
Cross-Layer Countermeasure-AI Governance and Assurance
AI Governance and Assurance play a critical role in mitigating security and privacy threats arising from the widespread integration of artificial intelligence into AI-native 6G networks. As AI technologies such as federated learning, foundation models, AI-RAN, multi-agent systems, and digital twins become integral to network operations, ensuring their trustworthiness and robustness is essential. AI governance establishes policies, accountability mechanisms, and regulatory controls for the development, deployment, and operation of AI systems, while AI assurance focuses on validating their security, reliability, explainability, and resilience against adversarial manipulation. Techniques such as explainable AI (XAI), model auditing, adversarial robustness testing, secure model life cycle management, and continuous monitoring can help mitigate risks including data poisoning, model evasion, privacy leakage, and autonomous decision manipulation [117, 4, 2, 36]. By providing transparency, accountability, and risk-aware AI management, AI governance and assurance strengthen the security and trustworthiness of AI-enabled 6G ecosystems. Despite growing interest in trustworthy AI, several challenges remain for AI governance and assurance in AI-native 6G networks. Firstly, the distributed and autonomous nature of AI systems operating across edge, cloud, terrestrial, and non-terrestrial domains complicates monitoring, auditing, and accountability. Secondly, ensuring robustness against emerging adversarial attacks on foundation models, federated learning systems, and multi-agent environments remains an active research challenge. Thirdly, achieving explainability and transparency for large-scale AI models while maintaining operational efficiency is difficult, particularly in real-time network management scenarios. Finally, the absence of harmonized standards and governance frameworks for AI security, privacy, and accountability creates challenges for interoperability, regulatory compliance, and cross-domain trust in future 6G ecosystems. 5.5
Cross-Layer Countermeasure-Privacy Governance and Compliance
Privacy Governance and Compliance are essential for addressing the growing privacy risks introduced by AI-native 6G networks, where massive volumes of personal, contextual, sensing, and operational data are continuously collected, processed, and shared across distributed environments. Emerging technologies such as JCAS, digital twins, edge intelligence, foundation models, and immersive XR applications significantly increase the risk of unauthorized data collection, inference attacks, identity linkage, and behavioral profiling. Privacy governance establishes policies, accountability mechanisms, and data management practices that ensure the lawful and ethical use of data, while compliance frameworks provide adherence to regulatory requirements such as GDPR, AI governance regulations, and sector-specific privacy standards [17, 19, 90]. Furthermore, privacy-enhancing technologies, including differential privacy, federated learning, homomorphic encryption, secure multiparty computation, and data minimization techniques, can help mitigate privacy risks while supporting intelligent 6G services [22, 116]. By integrating technical, organizational, and regulatory safeguards, privacy governance and compliance contribute to building trustworthy and privacy-preserving AI-native 6G ecosystems. Despite significant advances in privacy-preserving technologies and regulatory frameworks, several challenges remain for privacy governance in AI-native 6G networks. Firstly, the convergence of communication, sensing, computing, and AI creates complex data ecosystems where personal and contextual information may be collected and inferred without explicit user awareness. Secondly, balancing privacy protection with the need for real-time intelligence, personalization, and autonomous decision making remains a major challenge, particularly in latency-sensitive applications. Thirdly, ensuring consistent privacy policies and regulatory compliance across multiple jurisdictions, operators, and service providers is difficult in globally interconnected 6G environments. Finally, emerging technologies such as digital twins, Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
25
Table 23. Standards Harmonization Matrix for Security and Privacy in AI-Native 6G Networks Security/Privacy Func- 3GPP tion Identity Management ✓
ETSI
ITU
NIST
IETF
O-RAN
AI-RAN
P
P
–
P
P
–
Zero Trust Architecture
P
✓
–
✓
–
✓
–
AI Security & Assurance
P
✓✓
–
P
–
✓
✓
AI Agent Security
–
✓
–
–
–
P
✓
Privacy Protection
P
✓✓
✓
–
✓
P
–
JCAS Security
P
✓✓
P
–
–
–
–
NTN Security
P
P
✓
–
–
–
–
Network Slicing Security
✓✓
✓
–
–
–
P
✓
O-RAN Security
P
P
–
–
–
✓✓
P
Post-Quantum Security
P
✓
✓
✓✓
P
P
–
Physical Layer Security
P
✓
P
–
–
–
–
Gap Analysis Lack of unified cross-domain identity framework for terrestrial, NTN, and AI-native environments. No harmonized implementation model across 6G ecosystems. Absence of standardized AI assurance and model trustworthiness framework. Significant standardization gap for autonomous AI agents. Lack of unified privacy governance and consent management mechanisms. Fragmented approaches to sensing security and privacy. No common trust architecture across terrestrial and non-terrestrial domains. Limited interoperability guidance for cross-domain slice security. O-RAN controls are not fully aligned with 3GPP security models. Lack of migration and interoperability roadmap. Not systematically integrated into standards frameworks.
Legend: ✓✓ = Strong focus, ✓ = Explicit coverage, P = Partial coverage, – = Limited or no explicit coverage.
foundation models, and multi-agent systems introduce new forms of privacy leakage and inference risks that are not yet fully addressed by existing governance frameworks and standards. 5.6
Cross-Layer Countermeasure-Standardization Harmonization Analysis
The realization of secure and trustworthy AI-native 6G networks requires coordinated standardization across multiple organizations, including 3GPP, ETSI, ITU, National Institute of Standards and Technology (NIST), IETF, the O-RAN Alliance, and the AI-RAN Alliance. These organizations collectively address security for communication infrastructures, cloud-native architectures, AI systems, privacy-preserving technologies, and post-quantum cryptography. Beyond formal standardization bodies, several policy and strategic initiatives are shaping the security and privacy landscape of AI-native 6G. Recent examples include Global Coalition on Telecommunications (GCOT) [109] Security and Resilience Principles for 6G, which advocate security-by-design, trustworthy AI, supply-chain security, interoperability, and resilience as foundational requirements for future networks. Similarly, the ITU International Mobile Telecommunications (IMT)-2030 Framework, the NIST AI security and post-quantum cryptography initiatives, the NGMN 6G architecture vision, and the European 6G Smart Networks and Services Industry Association (6G-IA) vision emphasize secure, trustworthy, and interoperable AI-native communication systems. Collectively, these initiatives complement technical standards by providing policy guidance and strategic direction for the evolution of secure 6G ecosystems. Manuscript submitted to ACM
26
Barua, et al. Table 24. Proposed Harmonization Priorities for AI-Native 6G Security and Privacy
Domain AI Security
Current State ETSI SAI, O-RAN, and AI-RAN address AI security independently. Early work emerging in ETSI ENI and AI-RAN.
Key Challenge Inconsistent AI trust, assurance, and risk assessment mechanisms. No security baseline for autonomous AI agents.
Security efforts split between ITU and 3GPP. JCAS Security ETSI and 3GPP have initiated JCASrelated activities. Identity Management Multiple identity approaches exist across standards. Network Slicing Security mechanisms defined independently by multiple organizations. Post-Quantum Secu- NIST, ETSI, ITU, and 3GPP actively rity pursuing PQC migration. Privacy Governance Privacy mechanisms differ across organizations and use cases.
Lack of common trust model across space-air-ground networks. Privacy, consent, and sensing data protection remain fragmented. Fragmented credentials and trust anchors. Cross-domain slice security and trust interoperability.
Proposed Harmonization Direction Develop a unified AI assurance and certification framework for AI-native 6G. Establish standards for agent authentication, trust, explainability, and accountability. Develop unified NTN trust, authentication, and key-management framework. Define common sensing privacy and authorization framework. Introduce federated identity and decentralized trust architecture. Standardize end-to-end slice trust and isolation policies.
Lack of coordinated deployment roadmap. No common privacy model for AI-native and sensing-enabled networks.
Develop interoperable migration and crypto-agility guidelines. Harmonize privacy-preserving architectures, consent management, and data governance.
AI Agents NTN Security
Table 23 summarizes the current coverage of key security and privacy functions across major standardization bodies, while Table 24 identifies the corresponding harmonization priorities for AI-native 6G networks. Although significant progress has been made, important gaps remain in AI assurance, AI-agent security, Joint Communication and Sensing (JCAS) privacy, Non-Terrestrial Networks (NTN) trust, cross-domain identity management, and post-quantum migration. Moreover, many security mechanisms continue to evolve independently, increasing the risk of inconsistent trust models, privacy frameworks, and interoperability challenges. Future standardization efforts should therefore prioritize unified approaches for AI governance, federated identity management, privacy-preserving sensing, cryptoagility, and end-to-end security across heterogeneous terrestrial and non-terrestrial environments, while aligning with emerging policy initiatives. 6
Future Research Directions
The unified security and privacy framework presented in this survey establishes a holistic foundation for addressing crosslayer security challenges in AI-native 6G networks. However, realizing secure, trustworthy, and globally interoperable 6G ecosystems requires continued advances beyond the proposed framework. Several promising research directions are outlined below. • Framework Validation and Intelligent Security Orchestration: Future work should focus on validating the proposed framework through large-scale testbeds, digital twins, and AI-native network platforms. In addition to experimental evaluation, intelligent security orchestration capable of correlating threats, countermeasures, and security policies across infrastructure, network, AI, privacy, and management layers will be essential for practical deployment. • Trustworthy and Autonomous Security: Future AI-native networks should evolve toward self-protecting and self-healing security architectures capable of continuous risk assessment, adaptive policy enforcement, and autonomous incident response. Achieving this vision requires trustworthy AI, explainable decision making, secure multi-agent collaboration, and human oversight to ensure transparency and accountability. Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks
27
• Global Standards Convergence and Security Certification: Future research should bridge the gap between technical solutions and global deployment by translating harmonized security principles into interoperable standards, certification frameworks, and common trust models. Strengthening collaboration among standards organizations, industry alliances, and emerging policy initiatives will be critical to ensuring secure, interoperable, and resilient AI-native 6G ecosystems. • Security Benchmarks and Quantitative Evaluation: The lack of standardized security benchmarks limits objective comparison of emerging protection mechanisms for AI-native 6G. Future research should establish common datasets, attack models, evaluation metrics, and reproducible benchmarking platforms to assess the effectiveness, scalability, and interoperability of cross-layer security solutions. 7
Conclusion
AI-native 6G networks will enable unprecedented levels of intelligence, automation, and connectivity by integrating advanced communication, computing, sensing, and AI technologies. However, this convergence also introduces a highly complex and evolving security and privacy landscape, characterized by threats spanning infrastructure, network architectures, AI systems, privacy-sensitive applications, and security management mechanisms. In this paper, we presented a comprehensive survey of security and privacy challenges in AI-native 6G networks. We first highlighted the fragmentation of security and privacy requirements across emerging technologies, architectures, AI frameworks, and standards. To address this challenge, we proposed a unified security and privacy framework and developed a cross-layer threat taxonomy covering infrastructure, network and architectural, AI, privacy, and security management domains. Furthermore, we mapped key threats to corresponding countermeasures and discussed the role of standards harmonization in enabling interoperable and trustworthy 6G ecosystems. Our analysis demonstrates that securing AI-native 6G networks requires a holistic and cross-layer approach rather than isolated technology-specific solutions. Future advancements in trustworthy AI, autonomous security orchestration, privacy-preserving intelligence, quantum-resilient cryptography, and standards harmonization will be critical to realizing secure, resilient, and trustworthy next-generation communication networks. Acknowledgment This work is supported by EPSRC and DSIT funded project - CHEDDAR: Communications Hub For Empowering Distributed Cloud Computing Applications And Research (EP/X040518/1), (EP/Y037421/1) and EPSRC funded project REMOTE (EP/Y019229/1). All content was critically reviewed and verified by the authors. References [1] [2] [3] [4] [5] [6] [7]
Shimaa A Abdel Hakeem, Hanan H Hussein, and HyungWon Kim. 2022. Security requirements and challenges of 6g technologies and applications. Sensors, 22, 5, 1969. EU Artificial Intelligence Act. 2024. The eu artificial intelligence act. European Union. Ijaz Ahmad, Shahriar Shahabuddin, Tanesh Kumar, Jude Okwuibe, Andrei Gurtov, and Mika Ylianttila. 2019. Security for 5g and beyond. IEEE Communications Surveys & Tutorials, 21, 4, 3682–3722. NIST AI. 2023. Artificial intelligence risk management framework (ai rmf 1.0). URL: https://nvlpubs. nist. gov/nistpubs/ai/nist. ai, 100–1. Henrik Åkesson and Diana Pamela Moya Osorio. 2024. Privacy-preserving framework for cell-free mimo isac systems. arXiv preprint arXiv:2409.12874. Gorjan Alagic et al. 2020. Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process. NIST Interagency/Internal Report (NISTIR) 8309. National Institute of Standards and Technology. doi:10.6028/NIST.IR.8309. Gorjan Alagic et al. 2022. Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process. NIST Interagency/Internal Report (NISTIR) 8413. National Institute of Standards and Technology. doi:10.6028/NIST.IR.8413. Manuscript submitted to ACM
28 [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23]
[24] [25] [26]
[27]
[28] [29] [30] [31] [32] [33] [34]
Barua, et al. Sebastien Andreina, Giorgia Azzurra Marson, Helen Möllering, and Ghassan Karame. 2021. Baffle: backdoor detection via feedback-based federated learning. In 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS), 852–863. doi:10.1109/ICDCS51616.2021.00086. Chafika Benzaid and Tarik Taleb. 2020. Zsm security: threat surface and best practices. IEEE Network, 34, 3, 124–133. Ferhat Ozgur Catak, Murat Kuzlu, Evren Catak, Umit Cali, and Devrim Unal. 2022. Security concerns on machine learning solutions for 6g networks in mmwave beam prediction. Physical Communication, 52, 101626. Xu Chen, Wei Feng, Ning Ge, and Yan Zhang. 2023. Zero trust architecture for 6g security. IEEE Network, 38, 4, 224–232. Guanjie Cheng, Yan Chen, Shuiguang Deng, Honghao Gao, and Jianwei Yin. 2021. A blockchain-based mutual authentication scheme for collaborative edge computing. IEEE Transactions on Computational Social Systems, 9, 1, 146–158. Kanza Cherkaoui Dekkaki, Igor Tasic, and Maria-Dolores Cano. 2024. Exploring post-quantum cryptography: review and directions for the transition process. Technologies, 12, 12, 241. doi:10.3390/technologies12120241. Arsenia Chorti, André Noll Barreto, Stefan Köpsell, Marco Zoli, Marwa Chafii, Philippe Sehier, Gerhard Fettweis, and H Vincent Poor. 2022. Context-aware security for 6g wireless: the role of physical layer security. IEEE Communications Standards Magazine, 6, 1, 102–108. Alexander Clemm, Mohamed Faten Zhani, and Raouf Boutaba. 2020. Network management 2030: operations and control of network 2030 services. Journal of Network and Systems Management, 28, 4, 721–750. Mingyao Cui, Linglong Dai, Zhaocheng Wang, Shidong Zhou, and Ning Ge. 2022. Near-field rainbow: wideband beam training for xl-mimo. IEEE Transactions on Wireless Communications, 22, 6, 3899–3912. Bart Custers, Alan M Sears, Francien Dechesne, Ilina Georgieva, Tommaso Tani, and Simone Van der Hof. 2019. EU personal data protection in policy and practice. Vol. 29. Springer. Badhan Chandra Das, M Hadi Amini, and Yanzhao Wu. 2025. Security and privacy challenges of large language models: a survey. ACM Computing Surveys, 57, 6, 1–39. Prajnamaya Dass, Sonika Ujjwal, Jiri Novotny, Yevhen Zolotavkin, Zakaria Laaroussi, and Stefan Köpsell. 2024. Addressing privacy concerns in joint communication and sensing for 6g networks: challenges and prospects. In Annual Privacy Forum. Springer, 87–111. Avani Dave, Nilanjan Banerjee, and Chintan Patel. 2020. Sracare: secure remote attestation with code authentication and resilience engine. In 2020 IEEE international conference on embedded software and systems (ICESS). IEEE, 1–8. Chamitha De Alwis, Pawani Porambage, Kapal Dev, Thippa Reddy Gadekallu, and Madhusanka Liyanage. 2023. A survey on network slicing security: attacks, challenges, solutions and research directions. IEEE Communications Surveys & Tutorials. Cynthia Dwork, Aaron Roth, et al. 2014. The algorithmic foundations of differential privacy. Foundations and Trends® in Theoretical Computer Science, 9, 3–4, 211–407. Antonio Matencio Escolar, Jorge Bernal Bernabe, Jose Maria Alcaraz Calero, Qi Wang, and Antonio Skarmeta. 2024. Network slicing as 6g security mechanism to mitigate cyber-attacks: the rigourous approach. In 2024 IEEE 10th International Conference on Network Softwarization (NetSoft). IEEE, 387–392. Eslam Farsimadan, Leila Moradi, and Francesco Palmieri. 2025. A review on security challenges in v2x communications technology for vanets. IEEE Access. Alexey K. Fedorov. 2023. Deploying hybrid quantum-secured infrastructure for applications: when quantum and post-quantum can work together. Frontiers in Quantum Science and Technology, 2, 1164428. doi:10.3389/frqst.2023.1164428. Hailin Feng, Thippa Reddy Gadekallu, Yuchao Xia, Yongkang Zhao, Zhihao Wen, Jijing Cai, Pronaya Bhattacharya, Kai Fang, and Madhusanka Liyanage. 2026. Agentic ai security in 6g networks: a survey of emerging attack vectors, vulnerabilities, and defenses. IEEE Open Journal of the Communications Society. Mohamed Amine Ferrag, Othmane Friha, Burak Kantarci, Norbert Tihanyi, Lucas Cordeiro, Merouane Debbah, Djallel Hamouda, Muna AlHawawreh, and Kim-Kwang Raymond Choo. 2023. Edge learning for 6g-enabled internet of things: a comprehensive survey of vulnerabilities, datasets, and defenses. IEEE Communications Surveys & Tutorials, 25, 4, 2654–2713. European Union Agency for Cybersecurity (ENISA). 2021. Post-Quantum Cryptography: Current State and Quantum Mitigation. Tech. rep. ENISA. https://www.enisa.europa.eu/publications/post-quantum-cryptography-current-state-and-quantum-mitigation. Xenofon Foukas, Georgios Patounas, Ahmed Elmokashfi, and Mahesh K Marina. 2017. Network slicing in 5g: survey and challenges. IEEE communications magazine, 55, 5, 94–100. 2023. Framework and overall objectives of the future development of IMT for 2030 and beyond. Tech. rep. Recommendation ITU-R M.2160. International Telecommunication Union, Radiocommunication Sector (ITU-R). https://www.itu.int/en/ITU-R/Pages/default.aspx. Wenjie Fu, Huandong Wang, Chen Gao, Guanghua Liu, Yong Li, and Tao Jiang. 2024. Membership inference attacks against fine-tuned large language models via self-prompt calibration. Advances in Neural Information Processing Systems, 37, 134981–135010. Sandro Rodriguez Garzon, Hakan Yildiz, and Axel Küpper. 2022. Decentralized identifiers and self-sovereign identity in 6g. IEEE Network, 36, 4, 142–148. Jiahui Geng, Yongli Mou, Qing Li, Feifei Li, Oya Beyan, Stefan Decker, and Chunming Rong. 2023. Improved gradient inversion attacks and defenses in federated learning. IEEE Transactions on Big Data, 1–13. doi:10.1109/TBDATA.2023.3239116. Mir Ghoraishi et al. [n. d.] Itrust6g: zero-trust security for 6g networks. methods, 5, 6.
Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks [35]
[36] [37] [38] [39] [40] [41] [42] [43]
[44] [45] [46] [47] [48] [49] [50] [51] [52] [53] [54] [55] [56] [57] [58] [59] [60] [61] [62]
29
Harald Gjermundrød, Ioanna Dionysiou, and Kyriakos Costa. 2016. Privacytracker: a privacy-by-design gdpr-compliant framework with verifiable data traceability controls. In Current Trends in Web Engineering: ICWE 2016 International Workshops, DUI, TELERISE, SoWeMine, and Liquid Web, Lugano, Switzerland, June 6-9, 2016. Revised Selected Papers 16. Springer, 3–15. Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. (2015). https://arxiv.org/abs/14 12.6572 arXiv: 1412.6572 [stat.ML]. Joshua Groen, Salvatore D’Oro, Utku Demir, Leonardo Bonati, Michele Polese, Tommaso Melodia, and Kaushik Chowdhury. 2024. Implementing and evaluating security in o-ran: interfaces, intelligence, and platforms. IEEE Network, 39, 1, 227–234. Onur Günlü, Matthieu Bloch, Rafael F Schaefer, and Aylin Yener. 2022. Secure joint communication and sensing. In 2022 IEEE International Symposium on Information Theory (ISIT). IEEE, 844–849. Shaolong Guo, Yuntao Wang, Ning Zhang, Zhou Su, Tom H Luan, Zhiyi Tian, and Xuemin Shen. 2024. A survey on semantic communication networks: architecture, security, and privacy. IEEE communications surveys & tutorials, 27, 5, 2860–2894. Ehsan Hallaji, Roozbeh Razavi-Far, and Mehrdad Saif. 2022. Federated and transfer learning: a survey on adversaries and defense mechanisms. In Federated and Transfer Learning. Springer, 29–55. Ehsan Hallaji, Roozbeh Razavi-Far, Mehrdad Saif, and Enrique Herrera-Viedma. 2023. Label noise analysis meets adversarial training: a defense against label poisoning in federated learning. Knowledge-Based Systems, 266, 110384. doi:https://doi.org/10.1016/j.knosys.2023.110384. Eric Hanselman. 2020. Security Benefits of Open Virtualized RAN. Tech. rep. 451 Research, (May 2020). https://www.cisco.com/c/dam/en/us/solu tions/service-provider/pdfs/5g-network-architecture/white-paper-sp-open-vran-security-benefits.pdf. Asim Ul Haq, Seyed Salar Sefati, Syed Junaid Nawaz, Albena Mihovska, and Michail J. Beliatis. 2025. Need of uavs and physical layer security in next-generation non-terrestrial wireless networks: potential challenges and open issues. IEEE Open Journal of Vehicular Technology, 6, 554–595. doi:10.1109/OJVT.2025.3525781. Hexa-X-II Consortium. 2023. Deliverable D1.2 – 6G Use Cases and Requirements. Technical Report D1.2. Hexa-X-II Project, (Dec. 2023). https://hexa-x-ii.eu/wp-content/uploads/2024/01/Hexa-X-II_D1.2.pdf. A. Iqbal, M. L. Tham, Y. J. Wong, A. A. Al-Habashna, G. Wainer, Y. X. Zhu, and T. Dagiuklas. 2023. Empowering non-terrestrial networks with artificial intelligence: a survey. IEEE Access, 11, 100986–101006. Fauzia Irram, Mudassar Ali, Muhammad Naeem, and Shahid Mumtaz. 2022. Physical layer security for beyond 5g/6g networks: emerging technologies and future directions. Journal of Network and Computer Applications, 206, 103431. 2023. ISG ZSM Activity Report 2023. Tech. rep. ETSI ISG ZSM. https://www.etsi.org/committee-activity/activity-report-zsm. Weiqiang Jin, Hongyang Du, Biao Zhao, Xingwu Tian, Bohang Shi, and Guang Yang. 2025. A comprehensive survey on multi-agent cooperative decision-making: scenarios, approaches, challenges and perspectives. arXiv preprint arXiv:2503.13415. Waqas Khalid, Muhammad Atif Ur Rehman, Trinh Van Chien, Zeeshan Kaleem, Howon Lee, and Heejung Yu. 2023. Reconfigurable intelligent surface for physical layer security in 6g-iot: designs, issues, and advances. IEEE Internet of Things Journal, 11, 2, 3599–3613. Akmal Khan, Amini Hikmatullah, and Masud Jabir. 2026. Hybrid 5g 6g atomic laser networks for quantum resilient non terrestrial connectivity. Discover Quantum Science, 2, 1, 9. Latif U Khan, Zhu Han, Walid Saad, Ekram Hossain, Mohsen Guizani, and Choong Seon Hong. 2022. Digital twin of wireless systems: overview, taxonomy, challenges, and opportunities. IEEE Communications Surveys and Tutorials, 24, 4, 2230–2254. Siyavushkhon Kholmatov, Seongsik Cho, Song Chong, and Kyunghan Lee. 2026. Toward ai-on-ran: enabling on-ran edge intelligence for ai-native 6g networks. IEEE Network. Myoungsu Kim, Insu Oh, Kangbin Yim, Mahdi Sahlabadi, and Zarina Shukur. 2023. Security of 6g-enabled vehicle-to-everything communication in emerging federated learning and blockchain technologies. IEEE Access, 12, 33972–34001. Joonas Kokkoniemi, Alexandros-Apostolos A Boulogeorgos, Mubarak Aminu, Janne Lehtomäki, Angeliki Alexiou, and Markku Juntti. 2020. Impact of beam misalignment on thz wireless systems. Nano Communication Networks, 24, 100302. Ilia Lebedev, Kyle Hogan, and Srinivas Devadas. 2018. Secure boot and remote attestation in the sanctum processor. In 2018 IEEE 31st Computer Security Foundations Symposium (CSF). IEEE, 46–60. Aris Leivadeas and Matthias Falkner. 2022. A survey on intent-based networking. IEEE Communications Surveys & Tutorials, 25, 1, 625–655. Peng Li and Jianing Du. 2025. Brand design data security and privacy protection under 6g network slicing architecture. International Journal of Network Management, 35, 2, e70009. Qinbin Li et al. 2024. Llm-pbe: assessing data privacy in large language models. arXiv preprint arXiv:2408.12787. Yang Liu, Yan Kang, Tianyuan Zou, Yanhong Pu, Yuanqin He, Xiaozhou Ye, Ye Ouyang, Ya-Qin Zhang, and Qiang Yang. 2024. Vertical federated learning: concepts, advances, and challenges. IEEE Transactions on Knowledge and Data Engineering. Madhusanka Liyanage, An Braeken, Shahriar Shahabuddin, and Pasika Ranaweera. 2023. Open ran security: challenges and opportunities. Journal of Network and Computer Applications, 214, 103621. Shihang Lu et al. 2024. Integrated sensing and communications: recent advances and ten open challenges. IEEE Internet of Things Journal, 11, 11, 19094–19120. Xiaozhen Lu, Liang Xiao, Pengmin Li, Xiangyang Ji, Chenren Xu, Shui Yu, and Weihua Zhuang. 2023. Reinforcement learning-based physical cross-layer security and privacy in 6g. IEEE Communications Surveys & Tutorials, 25, 1, 425–466. doi:10.1109/COMST.2022.3224279. Manuscript submitted to ACM
30 [63] [64] [65]
[66] [67] [68] [69] [70] [71] [72]
[73] [74] [75] [76] [77] [78]
[79] [80] [81] [82] [83] [84] [85] [86]
[87] [88] [89] [90]
Barua, et al. Bomin Mao, Jiajia Liu, Yingying Wu, and Nei Kato. 2023. Security and privacy on 6g network edge: a survey. IEEE communications surveys & tutorials, 25, 2, 1095–1127. Sasa Maric, Rasil Baidar, Robert Abbas, and Sam Reisenfeld. 2025. System security framework for 5g advanced/6g iot integrated terrestrial network-non-terrestrial network (tn-ntn) with ai-enabled cloud security. arXiv preprint arXiv:2508.05707. Jämes Ménétrey, Christian Göttel, Anum Khurshid, Marcelo Pasin, Pascal Felber, Valerio Schiavoni, and Shahid Raza. 2022. Attestation mechanisms for trusted execution environments demystified. In IFIP International Conference on Distributed Applications and Interoperable Systems. Springer, 95–113. Miroslav Mitev, Arsenia Chorti, H Vincent Poor, and Gerhard P Fettweis. 2023. What physical layer security can do for 6g security. IEEE Open Journal of Vehicular Technology, 4, 375–388. Michele Mosca. 2018. Cybersecurity in an era with quantum computers: will we be ready? IEEE Security & Privacy, 16, 5, 38–41. Lorenzo Mucchi et al. 2021. Physical-layer security in 6g networks. IEEE Open Journal of the Communications Society, 2, 1901–1914. Hyeran Mun, Kyusuk Han, Ernesto Damiani, Hyun Ku Yeun, Tae-Yeon Kim, Luigi Martino, and Chan Yeob Yeun. 2025. A comprehensive survey on digital twin: focusing on security threats and requirements. IEEE Access, 13, 73362–73390. doi:10.1109/ACCESS.2025.3563621. Faisal Naeem, Mansoor Ali, Georges Kaddoum, Chongwen Huang, and Chau Yuen. 2023. Security and privacy for reconfigurable intelligent surface in 6g: a review of prospective applications and challenges. IEEE Open Journal of the Communications Society, 4, 1196–1217. Nurun Nahar, Karl Andersson, Olov Schelén, and Saguna Saguna. 2024. A survey on zero trust architecture: applications and challenges of 6g networks. IEEE Access. William Newhouse et al. 2023. Migration to Post-Quantum Cryptography: Preparation and Strategy. NIST Special Publication 1800-38B. Preliminary Draft. National Institute of Standards and Technology, (Dec. 2023). https://www.nccoe.nist.gov/sites/default/files/2023-12/pqc-migr ation-nist-sp-1800-38b-preliminary-draft.pdf. Cong T Nguyen et al. 2024. Emerging technologies for 6g non-terrestrial-networks: from academia to industrial applications. IEEE Open Journal of the Communications Society. Dinh C Nguyen, Ming Ding, Pubudu N Pathirana, Aruna Seneviratne, Jun Li, and H Vincent Poor. 2021. Federated learning for internet of things: a comprehensive survey. IEEE Communications Surveys & Tutorials, 23, 3, 1622–1658. Huan X Nguyen, Ramona Trestian, Duc To, and Mallik Tatipamula. 2021. Digital twin for 5g and beyond. IEEE Communications Magazine, 59, 2, 10–15. Tam Nguyen, Moses Ndebugre, and Dheeraj Arremsetty. 2026. Security considerations for multi-agent systems. arXiv preprint arXiv:2603.09002. Van-Linh Nguyen, Po-Ching Lin, Bo-Chao Cheng, Ren-Hung Hwang, and Ying-Dar Lin. 2021. Security and privacy for 6g: a survey on prospective technologies and challenges. IEEE Communications Surveys & Tutorials, 23, 4, 2384–2428. Nonso Okika, Gift Aruchi Nwatuzie, Hamed Salam Olarinoye, Augustine A Nwaka, Emmanuel Igba, and Roland Dunee. 2025. Assessing the vulnerability of traditional and post-quantum cryptographic systems through penetration testing and strengthening cyber defenses with zero trust security in the era of quantum computing. International Journal of Innovative Science and Research Technology, 10, 2. OPPO. 2025. 6g security architecture: intelligent security built on zero trust. https://www.oppo.com/content/dam/oppo/common/mkt/footer /OPPO-6G-Security-WhitePaper-EN.pdf. Diana Pamela Moya Osorio, Ijaz Ahmad, José David Vega Sánchez, Andrei Gurtov, Johan Scholliers, Matti Kutila, and Pawani Porambage. 2022. Towards 6g-enabled internet of vehicles: security and privacy. IEEE Open Journal of the Communications Society, 3, 82–105. Diana PM Osorio, Bidushi Barua, Karl-Ludwig Besser, Henry Blue, Prajnamaya Dass, and Pawani Porambage. 2025. The rise of networked isac: emerging aspects and challenges. IEEE Open Journal of the Communications Society. OWASP Foundation. 2025. LLM01:2025 Prompt Injection. Accessed: 2026-06-25. OWASP GenAI Security Project, (2025). https://genai.owasp.org/l lmrisk/llm01-prompt-injection/. Yidan Pan, Lei Lei, Gaoqing Shen, Xinting Zhang, and Pan Cao. 2025. A survey on digital twin networks: architecture, technologies, applications and open issues. IEEE Internet of Things Journal, 1–1. doi:10.1109/JIOT.2025.3565265. Michele Polese, Leonardo Bonati, Salvatore D’oro, Stefano Basagni, and Tommaso Melodia. 2023. Understanding o-ran: architecture, interfaces, algorithms, security, and research challenges. IEEE Communications Surveys & Tutorials, 25, 2, 1376–1411. Pawani Porambage, Maria Christopoulou, Bin Han, Mohammad Asif Habibi, Hanna Bogucka, and Pawel Kryszkiewicz. 2024. Security, privacy, and trust for open radio access networks in 6g. IEEE Open Journal of the Communications Society. Pawani Porambage, Gürkan Gür, Diana Pamela Moya Osorio, Madhusanka Livanage, and Mika Ylianttila. 2021. 6g security challenges and potential solutions. In 2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), 622–627. doi:10.1109 /EuCNC/6GSummit51104.2021.9482609. Pawani Porambage, Gürkan Gür, Diana Pamela Moya Osorio, Madhusanka Liyanage, Andrei Gurtov, and Mika Ylianttila. 2021. The roadmap to 6g security and privacy. IEEE Open Journal of the Communications Society, 2, 1094–1122. Pawani Porambage, Jude Okwuibe, Madhusanka Liyanage, Mika Ylianttila, and Tarik Taleb. 2018. Survey on multi-access edge computing for internet of things realization. IEEE Communications Surveys & Tutorials, 20, 4, 2961–2991. John Preskill. 2018. Quantum computing in the nisq era and beyond. Quantum, 2, 79. Kaiqian Qu, Jia Ye, Xuran Li, and Shuaishuai Guo. 2024. Privacy and security in ubiquitous integrated sensing and communication: threats, challenges and future directions. IEEE Internet of Things Magazine, 7, 4, 52–58.
Manuscript submitted to ACM
Toward a Unified Security and Privacy Framework for AI-Native 6G Networks [91] [92]
[93] [94] [95] [96] [97] [98] [99] [100] [101] [102] [103] [104] [105] [106] [107] [108] [109] [110]
[111] [112] [113] [114] [115] [116] [117]
31
Bosen Rao, Jiale Zhang, Di Wu, Chengcheng Zhu, Xiaobing Sun, and Bing Chen. 2024. Privacy inference attack and defense in centralized and federated learning: a comprehensive survey. IEEE Transactions on Artificial Intelligence, 1–22. doi:10.1109/TAI.2024.3363670. Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and Zico Kolter. 2020. Certified robustness to label-flipping attacks via randomized smoothing. In Proceedings of the 37th International Conference on Machine Learning (Proceedings of Machine Learning Research). Hal Daumé III and Aarti Singh, (Eds.) Vol. 119. PMLR, (13–18 Jul 2020), 8230–8241. https://proceedings.mlr.press/v119/rosenfeld20b.html. Pietro Ruiu, Michele Nitti, Virginia Pilloni, Marinella Cadoni, Enrico Grosso, and Mauro Fadda. 2024. Metaverse & human digital twin: digital identity, biometrics, and privacy in the future virtual worlds. Multimodal Technologies and Interaction, 8, 6, 48. Walid Saad, Mehdi Bennis, and Mingzhe Chen. 2019. A vision of 6g wireless systems: applications, trends, technologies, and open research problems. IEEE Network, 34, 3, 134–142. Yousef Sanjalawe, Salam Fraihat, Salam Al-E’Mari, Mosleh Abualhaj, Sharif Makhadmeh, and Emran Alzubi. 2025. A review of 6g and ai convergence: enhancing communication networks with artificial intelligence. IEEE Open Journal of the Communications Society, 6, 2308–2355. Steffen Schulz, André Schaller, Florian Kohnhäuser, and Stefan Katzenbeisser. 2017. Boot attestation: secure remote reporting with off-the-shelf iot sensors. In European Symposium on Research in Computer Security. Springer, 437–455. Hichem Sedjelmaci, Kamel Tourki, and Nirwan Ansari. 2023. Enabling 6g security: the synergy of zero trust architecture and artificial intelligence. IEEE Network, 38, 3, 171–177. Muhammad J Shehab, Youssef Aly, Ahmed Badawy, Amr Mohamed, Mahmoud Barhamgi, and Saeed Salem. 2025. O-cloud security: a comprehensive survey of threats, mitigation strategies, and future directions. IEEE Open Journal of the Communications Society. Meng Shen, Jing Wang, Hongyang Du, Dusit Niyato, Xiangyun Tang, Jiawen Kang, Yaoling Ding, and Liehuang Zhu. 2023. Secure semantic communications: challenges, approaches, and opportunities. IEEE Network, 38, 4, 197–206. Peter W. Shor. 1997. Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM Journal on Computing, 26, 5, 1484–1509. Federico Sierra-Arriaga, Rodrigo Branco, and Ben Lee. 2020. Security issues and challenges for virtualization technologies. ACM Computing Surveys (CSUR), 53, 2, 1–37. Sanaz Soltani, Mohammad Shojafar, Rahim Taheri, and Rahim Tafazolli. 2022. Can open and ai-enabled 6g ran be secured? IEEE Consumer Electronics Magazine, 11, 6, 11–12. Jose M Such, Agustín Espinosa, and Ana García-Fornes. 2014. A survey of privacy in multi-agent systems. The Knowledge Engineering Review, 29, 3, 314–344. Yu Sun, Zheng Liu, Jian Cui, Jianhua Liu, Kailang Ma, and Jianwei Liu. 2024. Client-side gradient inversion attack in federated learning using secure aggregation. IEEE Internet of Things Journal, 11, 17, 28774–28786. doi:10.1109/JIOT.2024.3405939. Jani Suomalainen and Ijaz Ahmad. 2024. Cybersecurity for machines in satellite–terrestrial networks. Integration of MTC and Satellites for IoT toward 6G Era, 245–271. Zhuoran Tan, Shameem Puthiya Parambath, Christos Anagnostopoulos, Jeremy Singer, and Angelos K Marnerides. 2025. Advanced persistent threats based on supply chain vulnerabilities: challenges, solutions, and future directions. IEEE Internet of Things Journal, 12, 6, 6371–6395. Theodoros Tsourdinis, Nikos Makris, Thanasis Korakis, and Serge Fdida. 2024. Ai-driven network intrusion detection and resource allocation in real-world o-ran 5g networks. In Proceedings of the 30th Annual International Conference on Mobile Computing and Networking, 1842–1849. Muhammad Tukur, Jens Schneider, Mowafa Househ, Ahmed Haruna Dokoro, Usman Idris Ismail, Muhammad Dawaki, and Marco Agus. 2023. The metaverse digital environments: a scoping review of the challenges, privacy and security issues. Frontiers in big Data, 6, 1301812. Efosa Udinmwen. 2026. ’the technological innovation anticipated from 6g...will require fundamental protections and mitigations to be considered’: governments look to secure 6g networks — despite them not even really existing yet’. (Mar. 2026). Apostol Vassilev, Alina Oprea, Alie Fordyce, Hyrum Anderson, Xander Davies, and Maia Hamin. 2025. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations. NIST Trustworthy and Responsible AI Report NIST AI 100-2e2025. National Institute of Standards and Technology (NIST), Gaithersburg, MD, USA. doi:10.6028/NIST.AI.100-2e2025. Yanhu Wang, Shuaishuai Guo, Yiqin Deng, Haixia Zhang, and Yuguang Fang. 2024. Privacy-preserving task-oriented semantic communications against model inversion attacks. IEEE Transactions on Wireless Communications, 23, 8, 10150–10165. Yifei Wang, Dizhan Xue, Shengjie Zhang, and Shengsheng Qian. 2024. Badagent: inserting and activating backdoor attacks in llm agents. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), 9811–9827. Yuntao Wang, Zhou Su, Shaolong Guo, Minghui Dai, Tom H. Luan, and Yiliang Liu. 2023. A survey on digital twins: architecture, enabling technologies, security and privacy, and future prospects. IEEE Internet of Things Journal, 10, 17, 14965–14987. doi:10.1109/JIOT.2023.3263909. Yuntao Wang, Zhou Su, Ning Zhang, Rui Xing, Dongxiao Liu, Tom H Luan, and Xuemin Shen. 2022. A survey on metaverse: fundamentals, security, and privacy. IEEE communications surveys & tutorials, 25, 1, 319–352. Zhaodong Wang et al. 2025. Intent-driven network management with multi-agent llms: the confucius framework. In Proceedings of the ACM SIGCOMM 2025 Conference, 347–362. Zhenyi Wang and Siyu Luan. 2026. Ai security in the foundation model era: a comprehensive survey from a unified perspective. (2026). https://arxiv.org/abs/2603.24857. Zhenyi Wang and Siyu Luan. 2026. Ai security in the foundation model era: a comprehensive survey from a unified perspective. arXiv preprint arXiv:2603.24857. Manuscript submitted to ACM
32 [118] [119]
[120] [121] [122] [123] [124]
[125] [126] [127] [128] [129] [130] [131] [132] [133] [134] [135] [136]
Barua, et al. Yu Chih Wei and Tak Wai Yu. 2023. Zero trust framework in financial sector: the handling of machine learning based trust management. In 2023 International Conference on Consumer Electronics-Taiwan (ICCE-Taiwan). IEEE, 211–212. Dongwook Won, Geeranuch Woraphonbenjakul, Ayalneh Bitew Wondmagegn, Anh-Tien Tran, Donghyun Lee, Demeke Shumeye Lakew, and Sungrae Cho. 2024. Resource management, security, and privacy issues in semantic communications: a survey. IEEE Communications Surveys & Tutorials, 27, 3, 1758–1797. Yiwen Wu, Ke Zhang, and Yan Zhang. 2021. Digital twin networks: a survey. IEEE Internet of Things Journal, 8, 18, 13789–13804. Young Wu, Jeremy McMahan, Xiaojin Zhu, and Qiaomin Xie. 2023. Reward poisoning attacks on offline multi-agent reinforcement learning. In Proceedings of the aaai conference on artificial intelligence number 9. Vol. 37, 10426–10434. Yinhao Xiao, Yizhen Jia, Chunchi Liu, Xiuzhen Cheng, Jiguo Yu, and Weifeng Lv. 2019. Edge computing security: state of the art and challenges. Proceedings of the IEEE, 107, 8, 1608–1631. Wenpeng Xing, Minghao Li, Mohan Li, and Meng Han. 2026. Towards robust and secure embodied ai: a survey on vulnerabilities and attacks. ACM Computing Surveys, 58, 12, 1–36. Jindan Xu, Chau Yuen, Chongwen Huang, Naveed Ul Hassan, George C Alexandropoulos, Marco Di Renzo, and Mérouane Debbah. 2023. Reconfiguring wireless environments via intelligent surfaces for 6g: reflection, modulation, and security. Science China Information Sciences, 66, 3, 130304. Qiben Yan, Huacheng Zeng, Tingting Jiang, Ming Li, Wenjing Lou, and Y Thomas Hou. 2016. Jamming resilient communication using mimo interference cancellation. IEEE Transactions on Information Forensics and Security, 11, 7, 1486–1499. Mengmeng Yang et al. 2024. From 5g to 6g: a survey on security, privacy, and standardization pathways. (2024). https://arxiv.org/abs/2410.21986 arXiv: 2410.21986 [cs.CR]. Sibo Yi, Yule Liu, Zhen Sun, Tianshuo Cong, Xinlei He, Jiaxing Song, Ke Xu, and Qi Li. 2024. Jailbreak attacks and defenses against large language models: a survey. arXiv preprint arXiv:2407.04295. Liangqi Yuan, Ziran Wang, Lichao Sun, S Yu Philip, and Christopher G Brinton. 2024. Decentralized federated learning: a survey and perspective. IEEE Internet of Things Journal. Demostenes Zegarra Rodriguez, Ogobuchi Daniel Okey, Siti Sarah Maidin, Ekikere Umoren Udo, and Joao Henrique Kleinschmidt. 2023. Attentive transformer deep learning algorithm for intrusion detection on iot systems using automatic xplainable feature selection. Plos one, 18, 10, e0286652. Peng Zeng, Debdeep Bandyopadhyay, Juan A. M. Méndez, et al. 2024. Practical hybrid pqc-qkd protocols with enhanced security and performance. arXiv preprint arXiv:2411.01086. https://arxiv.org/pdf/2411.01086.pdf. Zhe Zhang, Chensi Zhang, Chengjun Jiang, Fan Jia, Jianhua Ge, and Fengkui Gong. 2021. Improving physical layer security for reconfigurable intelligent surface aided noma 6g networks. IEEE Transactions on Vehicular Technology, 70, 5, 4451–4463. Zhengquan Zhang, Yue Xiao, Zheng Ma, Ming Xiao, Zhiguo Ding, Xianfu Lei, George K Karagiannidis, and Pingzhi Fan. 2019. 6g wireless networks: vision, requirements, architecture, and key technologies. IEEE vehicular technology magazine, 14, 3, 28–41. Kaixiang Zhao, Lincan Li, Kaize Ding, Neil Zhenqiang Gong, Yue Zhao, and Yushun Dong. 2025. A survey on model extraction attacks and defenses for large language models. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2, 6227–6236. Can Zheng, Yuhan Cao, Xiaoning Dong, and Tianxing He. 2025. Demonstrations of integrity attacks in multi-agent systems. arXiv preprint arXiv:2506.04572. Yihe Zhou, Tao Ni, Wei-Bin Lee, and Qingchuan Zhao. 2025. A survey on backdoor threats in large language models (llms): attacks, defenses, and evaluations. arXiv preprint arXiv:2502.05224. Guangxu Zhu, Zhonghao Lyu, Xiang Jiao, Peixi Liu, Mingzhe Chen, Jie Xu, Shuguang Cui, and Ping Zhang. 2023. Pushing ai to wireless network edge: an overview on integrated sensing, communication, and computation towards 6g. Science China Information Sciences, 66, 3, 130301.
Manuscript submitted to ACM