Conceptio › Archive › arXiv CS
arXiv CSopen access

On Identifying Adversarial Intent Injection in AI-Native 6G Networks

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

On Identifying Adversarial Intent Injection in AI-Native 6G Networks Nilesh Charkraborty1 , Petar Djukic2 , Burak Kantarci1 1

University of Ottawa, Ottawa, ON, Canada Nokia Bell Labs, 600 March Road, Kanata, ON K2K 2E6, Canada 1 {nchakrab, burak.kantarci}@uottawa.ca, 2 [email protected]

arXiv:2609.12144v1 [cs.NI] 10 Sep 2026

2

Abstract—AI-native 6G networks have brought IntentBased Networking (IBN) to the forefront, enabling high-level goals to be translated into network configurations. However, this abstraction opens new attack surfaces, primarily adversarial intent injection, where malicious policies are disguised within benign intent flows. The detection of attack instances might become significantly more difficult if the adversaries adopt a stealthy mode of malicious intent injection. With all these in mind, we first define a fine-grained threat model that facilitates the threat of malicious intent injection in an AI-native network. Alongside, we investigate four malicious intent injection strategies− stealth-mode, random distribution, increasing frequency, and decreasing frequency− and propose a dual-path detection framework: (i) a CNN using TF-IDF features for supervised malicious intent detection, and (ii) an AutoEncoder trained exclusively on benign data for one-class malicious intent detection. Our evaluation demonstrates strong detection performance, with accuracy improving to 0.97 (≈ 9% gain) and F1-score to 0.98 (≈ 36% gain) over the state-of-the-art baseline. Index Terms− AI-Native Networks, Intent, Adversarial Intent Injection, Threat Detection, Network Security

I. Introduction With the rapid evolution of next-generation networks, the network landscape is shifting towards higher levels of automation, adaptability, and intelligence [1]. Among the emerging paradigms, Intent-Based Networking (IBN) has attracted significant attention for its ability to translate high-level declarative intents into complex configurations [2], [3]. Intents are typically represented in machinereadable formats such as JSON structures or service templates like TOSCA. In addition, several industry initiatives have proposed domain-specific intent languages, including the TM Forum Intent Ontology and related frameworks developed within telecom standardization bodies such as GSMA. By leveraging artificial intelligence and natural language processing (NLP), IBN enables network operators to specify desired outcomes without dealing with low-level implementation details. The system interprets, assembles, and translates these intents into concrete network policies, thereby enabling streamlined management, improved agility, and reduced operational overhead [4], [5]. However, this abstraction also introduces new security challenges. As IBN frameworks increasingly rely on automation and semantic parsing, they become exposed to a

new class of risks-particularly adversarial or unauthorized intent injections, where malicious configurations closely mimic legitimate ones, undermining system integrity [6], [7]. For example, in [8] the authors consider a scenario in which a legitimate application installs an intent to establish connectivity between two hosts. An adversary with access to the intent interface may submit a second intent that mimics the original policy but with a different identifier or priority. When the controller processes this new intent, it may overwrite or interfere with the flow rules associated with the legitimate one. By subsequently withdrawing the malicious intent, the attacker can silently remove the corresponding forwarding rules, leaving the original intent logically present in the controller but functionally ineffective in the data plane. Therefore, such threats, if undetected, can lead to undesirable behaviors ranging from misconfigurations to sophisticated cyberattacks. These concerns highlight the importance of building robust IBN systems that are not only intelligent and efficient but also, resilient to manipulation and adversarial exploitation. In this paper, we consider a threat model where attackers inject malicious intents into the benign flow of intent traffic using varying frequency patterns- such as stealth-mode injection or gradual increases in malicious activity. These strategies rely on subtle manipulations of contextual dependencies across sequences of intents, where malicious behaviors emerge from the distribution and timing behaviour [9] of injected intents. To the best of our knowledge, this is the first work to explore the possibility of such threats by considering the distribution patterns of malicious intents as contextual cues, and to detect adversarial attempts from the flow of intent traffic. Based on this primary motivation, the contributions of this paper are as follows. Contribution 1: We propose a comprehensive adversarial threat model targeting the intent acquisition stage of the IBN pipeline. To emulate realistic attack scenarios, we generate a diverse intent dataset capturing four malicious injection strategies: stealth, random, decreasing frequency, and increasing frequency, where frequency is explicitly modeled as a practical threat dimension [10].

Contribution 2: We introduce a dual-path detection framework that leverages TF-IDF [11]-based features with (i) a supervised CNN classifier and (ii) a one-class AutoEncoder trained exclusively on benign intent sequences. Both models employ a sliding window-based temporal representation to segment intent streams into contextaware windows, enabling the detection of localized and temporally correlated adversarial manipulations. Despite being trained exclusively on benign data, the AutoEncoder achieves strong performance, with accuracy and F1 -score exceeding 0.85 in most scenarios, indicating its effectiveness in detecting previously unseen threat patterns [12]. The supervised CNN further enhances performance, achieving accuracy and F1-scores above 0.95 in several cases. The remainder of the paper is organized as follows. Section II establishes the proposed threat model and reviews the related work for gap identification. Section III details the construction of the threat detection models, followed by their performance evaluation in Section IV. Finally, Section V presents concluding remarks. II. Background and Related Work This section first unveils the proposed threat model targeting the intent acquisition stage of the IBN pipeline. Following this, we examine state-of-the-art methods closely related to our work to identify any existing gaps. A. Threat Model In IBN systems, where intents are expressed in formats such as JSON or TOSCA, an adversary can inject malicious intents into benign flows by exploiting the intent ingestion layer or vulnerable APIs [6]. By crafting configurations that closely resemble legitimate requests, these malicious intents evade detection. With the increasing prevalence of API-related threats [13], compromised APIs significantly amplify the risk of unauthorized policy injection. Fig. 1 illustrates this scenario, where an attacker uses a compromised API key to inject intents that may cause denial of service, privilege escalation [14], traffic redirection [15], or persistent backdoors [16], while appearing as routine updates. We consider four injection strategies with distinct temporal characteristics: (i) stealth injection, where malicious intents follow a Poisson arrival process with a fixed rate; (ii) increasing-frequency injection, where the rate of malicious intents grows over time; (iii) decreasingfrequency injection, where the rate gradually declines; and (iv) random injection, where malicious intents are uniformly distributed across the stream without a predefined arrival model. These strategies capture diverse adversarial behaviors and introduce a temporal dimension to intent injection.

Has Access

Intent Assembly & Normalization Layer

Policy Generation & Harmonization Layer

Intent Parsing & Understand -ing Layer

Policy Translation & Deployment Layer

Intent Ingestion Layer

Network Infrastructure Layer

Compromised API Key Entry point to AI-native network Attacker

Malicious JSON code

Feedback & Monitoring Layer

Fig. 1: Threat model−Malicious intent injection through vulnerable API B. Related work IBN has started gaining traction as a promising paradigm for automating and simplifying network management by translating high-level, goal-oriented intents into low-level configurations [17]. Although most early research in IBN has focused on intent formulation, orchestration, and operational efficiency [4], [18], to date, only limited work has explored the associated security risks arising from intent-driven network automation. For example, Bringhenti et al. [19] present a comprehensive survey of automation challenges in network security, emphasizing the need for context-aware validation mechanisms. Kim et al. [20] highlight that the separation between high-level intents and low-level configurations in IBN introduces a semantic gap that can be exploited by adversaries. Trizio et al. [6] propose a rule-based malicious intent detection approach for enterprise networks, where outof-scope intents are classified as malicious. However, this work primarily focuses on static rule-level analysis and does not consider temporal variations or stealthy injection strategies, thereby limiting its ability to capture contextual information. Phantom Link attacks further highlight temporal vulnerabilities, where adversaries exploit flow installation delays without altering or manipulating the intents themselves [21]. To the best of our knowledge, this work is among the first to emphasize context-based malicious intent detection by varying injection strategies across datasets. Although the intent content remains fixed, the positional context−the sequence and spacing of malicious samples−captures adversarial behaviors such as stealthy probing and bursty attacks [22]. Overall, our approach models, simulates, and detects adversarial intent injections with diverse temporal profiles, exposing an underexplored vulnerability and informing potential detection mechanisms [23]. III. Methodology We propose a context-aware detection framework for identifying malicious intent injections in IBN by analyz-

ing sequences of intents and their distribution patterns, capturing adversarial behaviors not observable at the individual intent level. TF-IDF-based feature extraction is used as the foundation for two complementary models: • CNN-based classification (supervised) • AutoEncoder-based reconstruction (one-class) Compared to dense embeddings such as Word2Vec, which require large corpora and may blur discrete policy actions (e.g., treating ALLOW, BYPASS, and ENFORCE as semantically similar despite distinct operational meanings), TF-IDF preserves term distinctiveness, enabling more discriminative modeling of intent features. A 1D CNN is employed due to the sliding-window design with limited context, where detecting short-range dependencies is critical. In contrast, models such as LSTMs target longer temporal dependencies, introduce higher parameter complexity, and are more prone to overfitting under limited data. CNNs, through weight sharing and architectural simplicity, provide an efficient and well-generalizing alternative. To support detection under limited attack knowledge, a Conv1D AutoEncoder is trained on TF-IDF sequences using sliding windows to learn the temporal structure of benign intent flows. During inference, deviations caused by malicious injection patterns (e.g., stealthy or bursty behavior) are identified via reconstruction error. Unlike traditional one-class methods such as Isolation Forest, One-Class SVM, or k-means, which operate on independent samples, the proposed approach captures localized sequential dependencies, improving sensitivity to subtle temporal anomalies while maintaining efficiency and generalizability. A. Supervised Model The intent dataset, consisting of text-based descriptions with each record labeled malicious (1) or safe (0), serves as the input for the supervised algorithm, which follows the key steps outlined below. Step 1: The intents are converted into numerical vectors using TF-IDF vectorization, with a vocabulary size limited to 500 features. This captures term-level importance across the corpus. Step 2: To incorporate contextual information, a sliding window of size six is applied across the TF-IDF matrix to generate input sequences. Each sequence is labeled as malicious if any rule within the window is malicious, following a max-label logic. Step 3: The sequences are split into training (75%) and testing (25%) sets using a fixed random seed (41). Step 4: To mitigate label imbalance, we compute class weights (Wc ) by employing the following equation and apply them during training to give more emphasis to the minority class as Wc = ns /(nc × ntc ) where ns denotes the total number of training samples, nc represents the number of unique classes and ntc denotes number of training samples belonging to the class c.

Step 5: 1D CNN architecture is optimized for the detection of temporal patterns in short intent sequences. Step 6: To further address class imbalance and focus on hard-to-classify samples, we use focal loss with the following formulation: L(ytrue , ypred ) = −α(1 − pt )γ log(pt ) where pt is the predicted probability for the true class, α is the weighting factor to balance classes, and γ is the focusing parameter that down-weights easy examples. Step 7: The CNN is trained using the Adam optimizer and the defined focal loss. Step 8: During inference, an elevated decision threshold is applied to reduce false positives. The model is evaluated using standard performance metrics, including accuracy, precision, recall, and F1-score. B. One-class learning Model This model follows an encoder-decoder architecture and repeats Step 1 to Step 3 from Section III-A. The following three functional features can represent the remaining workflow of this model. Encoder: The encoder employs one-dimensional convolutions to extract localized semantic-temporal patterns from intent sequences, followed by normalization and pooling to stabilize training and reduce dimensionality. A fully connected layer projects the result into a compact latent representation capturing the most salient features. Decoder: The decoder reconstructs the original input from the latent representation using fully connected layers, reshaping the output to the original sequence format with a bounded activation to preserve normalization. Reconstruction loss: During inference, the AutoEncoder computes the mean absolute reconstruction error for each intent window. A detection threshold is set using a highpercentile reconstruction loss from benign windows; windows exceeding this threshold are flagged as anomalous, indicating potential malicious intent injection. IV. Performance Evaluation Alongside a detailed description of the intent dataset, this section presents the results of our experiments conducted on it. We also compare our findings with those reported in [6], which, to the best of our knowledge, is the only existing work closely related to our contribution. We begin by highlighting the key characteristics and structure of the developed dataset. A. Dataset Introduction We construct a dataset of 1,100 network intents (250 malicious, 850 benign), partially assisted by a pre-trained LLM, comparable in scale to the proprietary dataset of 755 intents reported in [6]. Malicious intents are generated under four adversarial conditions. Fig. 2 illustrates the distribution using t-SNE, where intents are encoded via TF-IDF and projected into two dimensions. To systematically generate malicious samples, we curate 20 manually verified base intents covering realistic threat scenarios,

0DOLFLRXV %HQLJQ í

í









(a) Stealth ⟨#B = 76; #M = 1019⟩

0DOLFLRXV %HQLJQ í

í







(b) Random ⟨#B = 289; #M = 806⟩

0DOLFLRXV %HQLJQ í

í







(c) Increasing Frequency ⟨#B = 97; #M = 998⟩

including DoS, phishing, malware deployment, data exfiltration, and unauthorized access across firewall policies, AI-driven modules, and QoS control. Each base intent is expanded into nine variants that preserve the underlying attack objective while modifying attributes such as action semantics, routing strategy, logging configuration, and endpoint identifiers. Unlike surface-level linguistic variation, this process introduces protocol- and operation-level transformations, incorporating evasive behaviors such as encrypted tunneling, passive monitoring, delayed or limited logging, and adversarial routing. For example, ACTION:DROP with LOG:ENABLED is transformed into ACTION:NULLROUTE with LOG:LIMITEDMODE, while phishing intents using ROUTING:OVERRIDE are re-expressed via REDIRECTION:ENABLED with INSPECTION:SKIPPED. These transformations emulate realistic obfuscation strategies while preserving attack semantics. To model contextual ambiguity, we intentionally introduce label noise by relabeling 40 malicious intents as benign and 90 benign intents as malicious based on plausible operational interpretations. This results in a final dataset of 250 malicious and 850 benign intents and forces detection models to rely on semantic reasoning rather than surface patterns. To ensure the absence of trivial keyword-based cues, we perform a statistical analysis using Chi-square and Fisher’s Exact tests [24] over a dictionary of 916 keywords (excluding numerals and stopwords). Keywords are categorized as strong (88), weak (31), or non-discriminative (797) based on statistical significance (p < 0.05) and prevalence. A rule-based classifier using only strong discriminators achieves 0.79 accuracy, 0.96 precision, 0.10 recall, and 0.18 F1-score on the full dataset. The low recall confirms that explicit keywords are insufficient for reliable detection, highlighting the need for context-aware approaches. To characterize malicious intent injection patterns, we model the number of benign intents between consecutive malicious ones as a discrete random variable X. Assuming independent gaps governed by a Poisson process, the probability of observing k benign samples before the next malicious intent is λk e−λ , k = 0, 1, 2, . . . (1) k! For each dataset, we identify malicious intent positions and compute the number of intervening benign samples, whose mean defines the Poisson rate parameter λ, representing the expected benign gap between malicious injections. This provides a strategy-specific and interpretable measure of injection spacing, enabling comparative analysis across attack strategies. The estimated rate parameters are found to be λ ≈ 3.40 (stealth), λ ≈ 3.41 (random), λ ≈ 1.08 (decreasing frequency), and λ ≈ 3.01 (increasing frequency). The estimated values of λ indicate that the stealth, random, and increasingP (X = k) =

0DOLFLRXV %HQLJQ í

í







(d) Decreasing Frequency ⟨#B = 575; #M = 520⟩

Fig. 2: t-SNE visualization: For 1095 windows of window size six, distribution of benign and malicious intents across datasets with underlying temporal dependencies impacting both training and testing phases. #B and #M denote the number of benign (blue) and malicious (red) samples, respectively.

C. Comparative Results We compare the proposed CNN and AutoEncoder models with the DIET classifier proposed by Trizio et al. [6], which is the closest existing baseline for malicious intent detection in IBN. Since the dataset contains a larger proportion of benign samples, accuracy alone may not fully reflect detection effectiveness. Therefore, Table II also reports precision, recall, and F1-score, which provide a more informative evaluation under class imbalance. As shown in Table II, both proposed models outperform the DIET classifier [6], particularly in recall and F1-score. Although DIET maintains moderate precision across all distributions, its recall remains low (0.49–0.60), indicating that many malicious intents remain undetected. The

Accuracy

0.75 Sth Rand Inc Dec

0.50 0.25 0.00

1

2

3

4

Window Size

5

6

5

6

(a) Accuracy (1D CNN)

1.00

Accuracy

Each intent is encoded using TF-IDF, producing a weighted feature representation that captures both semantic tokens (e.g., mfa_auth, validate) and numeric fields (e.g., IP subfields, ports). Table I presents representative examples with their top contributing terms, highlighting recurring discriminative features. To model short-range dependencies, encoded intents are grouped into sequences using a sliding window of size 1 to 6, where a sequence is labeled as malicious if it contains at least one malicious intent. As shown in Fig. 3, increasing the window size improves accuracy and F1-score for both supervised and one-class models, indicating the importance of temporal context. For supervised detection, sequences are processed using a 1D CNN with a Conv1D layer (64 filters, kernel size 3), followed by batch normalization, global max pooling, dropout (0.5), and dense layers (16-unit ReLU, sigmoid output). The model is trained using focal loss (α = 0.25, γ = 2.0) with class weighting to address imbalance, for 10 epochs with batch size 16. A prediction threshold of 0.7 is used to reduce false positives. For one-class detection, a convolutional autoencoder is trained exclusively on benign sequences. The encoder consists of a Conv1D layer (256 filters, kernel size 3), batch normalization, global max pooling, and a 32-dimensional latent layer, with a mirrored decoder for reconstruction. Training uses MSE loss and Adam optimizer for 10 epochs (batch size 16). During inference, samples are classified as malicious if their reconstruction loss exceeds the 85th percentile of benign losses. Table II summarizes the results. Under the AutoEncoder, stealth-mode injection yields the lowest recall (0.66), leaving approximately 34% of malicious samples undetected. For the CNN, random injection is most evasive, with a recall of 0.76. Both models perform best under increasing-frequency injection, achieving recall values of 0.96 (CNN) and 0.98 (AutoEncoder).

0.75 Sth Rand Inc Dec

0.50 0.25 0.00

1

2

3

4

Window Size

(b) Accuracy (AutoEncoder)

1.00

F1 Score

B. Evaluation Results

1.00

0.75 Sth Rand Inc Dec

0.50 0.25 0.00

1

2

3

4

Window Size

5

6

(c) F1-score (1D CNN)

1.00

F1 Score

frequency strategies exhibit similar and relatively sparse injection spacing, whereas the decreasing-frequency strategy produces significantly denser malicious injections.

0.75 Sth Rand Inc Dec

0.50 0.25 0.00

1

2

3

4

Window Size

5

6

(d) F1-score (AutoEncoder)

Fig. 3: Impact of window size on model performance (accuracy and F1-score) under four malicious intent distributions

proposed CNN consistently achieves strong performance across all four distributions, with the highest F1-score

TABLE I: Top eight TF-IDF terms and their corresponding weights for each of three representative network intents Ind

Intent

TF-IDF Terms (weight)

1

’type’: ’AI-Driven Security’, ’action’: ’ACTION:VALIDATE; SECURE:MFA_AUTH; LOG:ENABLED;’, ’source’: ’10.37.197.121’, ’destination’: ’192.168.86.200’, ’port’: 5000, ’log’: True

197 (0.387), 121 (0.357), 37 (0.357), 86 (0.354), 200 (0.325), 5000 (0.222), mfa_auth (0.210), validate (0.210)

2

’type’: ’QoS Control’, ’action’: ’ACTION:VALIDATE; SECURE:MFA_AUTH; LOG:ENABLED;’, ’source’: ’10.74.232.208’, ’destination’: ’192.168.85.202’, ’port’: 8443, ’log’: True

3

74 (0.370), 85 (0.370), 202 (0.363), 208 (0.363), 232 (0.353), mfa_auth (0.208), validate (0.208), 8443 (0.207) 105 (0.391), 252 (0.377), 153 (0.352), 177 (0.352), 219 (0.346), 8443 (0.206), anomaly_detection (0.202), monitor (0.198)

’type’: ’SLA Compliance’, ’action’: ’ACTION:MONITOR; AI-SECURITY:ANOMALY DETECTION; LOG:ENABLED;’, ’source’: ’10.177.252.219’, ’destination’: ’192.168.105.153’, ’port’: 8443, ’log’: True

Acknowldgement This work is supported in part by Mitacs Accelerate program under project number IT43178, and in part by the Natural Sciences and Engineering Research Council of Canada under the Discovery and CREATE TRAVERSAL programs. References

TABLE II: Performance comparison of the proposed AutoEncoder and CNN models against the DIET classifier under four malicious intent distributions. Accuracy (Acc), Precision (P), Recall (R), and F1-score (F1) are reported. The symbol ↑ indicates the best-performing method for each metric under a given distribution. AutoEncoder

Distribution Stealth Random Increasing Decreasing

Acc

P

R

0.68 0.86 0.96 0.89

0.98↑ 0.93 0.97 0.83

0.66 0.87↑ 0.98↑ 0.96↑

CNN F1

Acc

P

DIET [6] R

F1

Acc

P

R

Experimental results show that the CNN achieves consistently strong performance across all scenarios (average recall 0.89, F1-score 0.93), while the AutoEncoder is particularly effective against increasing and decreasing injection strategies (average recall 0.87, F1-score 0.89). Future work will extend the dataset with more diverse and nuanced JSON-based policy configurations to better reflect real-world IBN environments. We also plan to improve interpretability through explainable AI techniques, enabling greater transparency and trust in detection decisions. These directions aim to support more adaptive and secure IBN frameworks against evolving adversarial strategies in autonomous 6G networks.

F1

0.79 0.88 0.97 0.90↑ 0.93↑ 0.88 0.84 0.54 0.65 0.90↑ 0.82 0.99↑ 0.76 0.86 0.88 0.86 0.59 0.70 0.98↑ 0.97↑ 0.99↑ 0.96 0.97 0.89 0.90 0.60 0.72 0.88 0.97↑ 0.98↑ 0.93 0.95↑ 0.88 0.93 0.49 0.64

under the stealth and decreasing-frequency settings, and near-best performance under the remaining cases. The AutoEncoder, despite being trained only on benign samples, also performs competitively and achieves the highest recall under the random, increasing-frequency, and decreasingfrequency settings. This suggests that sequence-based anomaly detection can effectively capture deviations from benign intent-flow patterns even without exposure to malicious samples during training. To summarize, these results highlight the advantage of sequence-aware, context-based modeling over the single-intent classification approach used by DIET [6]. V. Conclusion and Future Work This work addresses adversarial intent injection in AInative 6G networks by introducing a threat model focused on the intent acquisition stage of the IBN pipeline. We construct a dataset covering four attack distributions and propose a dual-path detection framework combining supervised (CNN) and one-class (AutoEncoder) models.

[1] N. Tu, S. Nam, and J. W.-K. Hong, “Intent-Based Network Configuration Using Large Language Models,” International Journal of Network Management, vol. 35, no. 1, pp. 1–14, 2025. [2] K. Yao, D. Chen, J. P. Jeong, Q. Wu, C. Yang, L. M. Contreras, and G. Fioccola, “Use Cases and Practices for Intent-Based Networking,” IETF, Tech. Rep., 2025, WIP. [Online]. Available: https://datatracker.ietf.org/doc/draft-irtfnmrg-ibn-usecases/00/ [3] S. K. Perepu, J. P. Martins, R. Souza, and K. Dey, “Intent-Based Multi-Agent Reinforcement Learning for Service Assurance in Cellular Networks,” in IEEE Globecom, 2022, pp. 2879–2884. [4] A. S. Jacobs, R. J. Pfitscher, R. H. Ribeiro, R. A. Ferreira, L. Z. Granville, W. Willinger, and S. G. Rao, “Hey, Lumi! Using Natural Language for Intent-Based Network Management,” in USENIX Annual Technical Conference (ATC), 2021, pp. 625– 639. [5] A. Leivadeas and M. Falkner, “A Survey on Intent-based Networking,” IEEE Comm Surveys & Tutorials, vol. 25, no. 1, pp. 625–655, 2022. [6] F. de Trizio, G. Sciddurlo, D. Rutigliano, G. Piro, and G. Boggia, “A Novel Malicious Intent Detection Approach in IntentBased Enterprise Networks,” in Intl. Conf. on Network and Service Man., 2024, pp. 1–7. [7] U. Uchechi Izuazu, M. Bensalem, and A. Jukan, “A Secured Intent-Based Networking (sIBN) with Data-Driven Time-Aware Intrusion Detection,” arXiv e-prints, pp. arXiv–2511, 2025. [8] J. Kim, B. E. Ujcich, and D. J. Tian, “INTENDER: Fuzzing Intent-Based Networking with Intent-State Transition Guidance,” in USENIX Security Symposium (USENIX Security 23), 2023, pp. 4463–4480. [9] Y. Sharon, D. Berend, Y. Liu, A. Shabtai, and Y. Elovici, “TANTRA: Timing-Based Adversarial Network Traffic Reshaping Attack,” IEEE Trans on Info. Forensics and Sec., vol. 17, pp. 3225–3237, 2022. [10] G. Zhang, J. Li, O. Bamisile, D. Cai, W. Hu, and Q. Huang, “Spatio-temporal Correlation-based False Data Injection Attack Detection Using Deep Convolutional Neural Network,” IEEE Transactions on Smart Grid, vol. 13, no. 1, pp. 750–761, 2021. [11] S. Nam, J.-H. Yoo, and J. W.-K. Hong, “Log-TF-IDF for Anomaly Detection in Network Switches,” in NOMS 20242024 IEEE Network Operations and Management Symposium. IEEE, 2024, pp. 1–9.

[12] A. A. Mohamed, A. Al-Saleh, S. K. Sharma, and G. G. Tejani, “Zero-day Exploits Detection with Adaptive WavePCAAutoencoder (AWPA) Adaptive Hybrid Exploit Detection Network (AHEDNet),” Scientific Reports, vol. 15, no. 1, p. 4036, 2025. [13] Akamai Technologies, “New study finds 84% of security professionals experienced an api security incident in the past year,” https://www.akamai.com/newsroom/press-release/newstudy-finds-84-of-security-professionals-experienced-an-apisecurity-incident-in-the-past-year, 2024, accessed: 2025-04-28. [14] N. Pecka, L. Ben Othmane, and A. Valani, “Privilege Escalation Attack Scenarios on the DevOps Pipeline within a Kubernetes Environment,” in Intl. Conf. on Software and System Processes and International Conference on Global Software Engineering, 2022, pp. 45–49. [15] X. Feng, Q. Li, K. Sun, Z. Qian, G. Zhao, X. Kuang, C. Fu, and K. Xu, “{Off-Path} Network Traffic Manipulation via Revitalized {ICMP} Redirect Attacks,” in 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 2619–2636. [16] T. Liu, Y. Zhang, Z. Feng, Z. Yang, C. Xu, D. Man, and W. Yang, “Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning,” in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38, no. 19, 2024, pp. 21 359–21 367. [17] M. Xie, P. H. Gomes, J. Niemöller, and J. P. Waldemar, “IntentDriven Management for Multi-Vertical End-to-End Network Slicing Services,” in IEEE Globecom Workshops. IEEE, 2022,

pp. 1285–1291. [18] J. Mcnamara, D. Camps-Mur, M. Goodarzi, H. Frank, L. Chinchilla-Romero, F. Cañellas, A. Fernández-Fernández, and S. Yan, “NLP Powered Intent Based Network Management for Private 5G Networks,” IEEE Access, vol. 11, pp. 36 642– 36 657, 2023. [19] D. Bringhenti, G. Marchetto, R. Sisto, and F. Valenza, “Automation for Network Security Configuration: State of the Art and Research Trends,” ACM Computing Surveys, vol. 56, no. 3, pp. 1–37, 2023. [20] J. Kim, H. Okhravi, D. Tian, and B. E. Ujcich, “Security challenges of intent-based networking,” Communications of the ACM, vol. 67, no. 7, pp. 56–65, 2024. [21] B. Weintraub, J. Kim, R. Tao, C. Nita-Rotaru, H. Okhravi, D. Tian, and B. E. Ujcich, “Exploiting Temporal Vulnerabilities for Unauthorized Access in Intent-Based Networking,” in ACM SIGSAC Conf. on Computer and Communications Security, 2024, pp. 3630–3644. [22] P. Kulkarni and A. Namer, “Temporal Context Awareness: A Defense Framework Against Multi-turn Manipulation Attacks on Large Language Models,” arXiv preprint arXiv:2503.15560, 2025. [23] W. Wu, C. Zhou, M. Li, H. Wu, H. Zhou, N. Zhang, X. S. Shen, and W. Zhuang, “AI-native Network Slicing for 6G Networks,” IEEE Wireless Communications, vol. 29, no. 1, pp. 96–103, 2022. [24] A. Agresti, Categorical Data Analysis. John Wiley & Sons, 2013.

Record · ID 919326 · SHA-256 15cf893b623c03b9
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.