{"id":"https://openalex.org/W7126061385","doi":"https://doi.org/10.1109/nfv-sdn66355.2025.11349498","title":"Large Language Models for Out-of-Distribution Attack Detection in 6G Networks","display_name":"Large Language Models for Out-of-Distribution Attack Detection in 6G Networks","publication_year":2025,"publication_date":"2025-11-10","ids":{"openalex":"https://openalex.org/W7126061385","doi":"https://doi.org/10.1109/nfv-sdn66355.2025.11349498"},"language":null,"primary_location":{"id":"doi:10.1109/nfv-sdn66355.2025.11349498","is_oa":false,"landing_page_url":"https://doi.org/10.1109/nfv-sdn66355.2025.11349498","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Network Function Virtualization and Software-Defined Networking (NFV-SDN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5124169468","display_name":"Emmanouil Atsilmis","orcid":null},"institutions":[{"id":"https://openalex.org/I4210094138","display_name":"University of West Attica","ror":"https://ror.org/00r2r5k05","country_code":"GR","type":"education","lineage":["https://openalex.org/I4210094138"]}],"countries":["GR"],"is_corresponding":true,"raw_author_name":"Emmanouil Atsilmis","raw_affiliation_strings":["University of West Attica Aigaleo,Dept. of Information and Computer Engineering,Attica,Greece"],"affiliations":[{"raw_affiliation_string":"University of West Attica Aigaleo,Dept. of Information and Computer Engineering,Attica,Greece","institution_ids":["https://openalex.org/I4210094138"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074388101","display_name":"Dimitris Uzunidis","orcid":"https://orcid.org/0000-0002-9993-5230"},"institutions":[{"id":"https://openalex.org/I4210094138","display_name":"University of West Attica","ror":"https://ror.org/00r2r5k05","country_code":"GR","type":"education","lineage":["https://openalex.org/I4210094138"]}],"countries":["GR"],"is_corresponding":false,"raw_author_name":"Dimitrios Uzunidis","raw_affiliation_strings":["University of West Attica Aigaleo,Dept. of Electrical and Electronics Engineering,Attica,Greece"],"affiliations":[{"raw_affiliation_string":"University of West Attica Aigaleo,Dept. of Electrical and Electronics Engineering,Attica,Greece","institution_ids":["https://openalex.org/I4210094138"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5011492909","display_name":"Panagiotis Karkazis","orcid":"https://orcid.org/0000-0003-4971-826X"},"institutions":[{"id":"https://openalex.org/I4210094138","display_name":"University of West Attica","ror":"https://ror.org/00r2r5k05","country_code":"GR","type":"education","lineage":["https://openalex.org/I4210094138"]}],"countries":["GR"],"is_corresponding":false,"raw_author_name":"Panagiotis Karkazis","raw_affiliation_strings":["University of West Attica Aigaleo,Dept. of Information and Computer Engineering,Attica,Greece"],"affiliations":[{"raw_affiliation_string":"University of West Attica Aigaleo,Dept. of Information and Computer Engineering,Attica,Greece","institution_ids":["https://openalex.org/I4210094138"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5124169468"],"corresponding_institution_ids":["https://openalex.org/I4210094138"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.75226781,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.5490000247955322,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.5490000247955322,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.04259999841451645,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10273","display_name":"IoT and Edge/Fog Computing","score":0.03590000048279762,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.685699999332428},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.579800009727478},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4560999870300293},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.43290001153945923},{"id":"https://openalex.org/keywords/internet-control-message-protocol","display_name":"Internet Control Message Protocol","score":0.40049999952316284},{"id":"https://openalex.org/keywords/precision-and-recall","display_name":"Precision and recall","score":0.37139999866485596},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.3499999940395355}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7569000124931335},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.685699999332428},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.579800009727478},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4560999870300293},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.43290001153945923},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.41200000047683716},{"id":"https://openalex.org/C195219913","wikidata":"https://www.wikidata.org/wiki/Q13162","display_name":"Internet Control Message Protocol","level":3,"score":0.40049999952316284},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39890000224113464},{"id":"https://openalex.org/C81669768","wikidata":"https://www.wikidata.org/wiki/Q2359161","display_name":"Precision and recall","level":2,"score":0.37139999866485596},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35420000553131104},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.3499999940395355},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3278999924659729},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.325300008058548},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.32420000433921814},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.30550000071525574},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3021000027656555},{"id":"https://openalex.org/C2983254600","wikidata":"https://www.wikidata.org/wiki/Q1096907","display_name":"Power grid","level":3,"score":0.3010999858379364},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.2904999852180481},{"id":"https://openalex.org/C100660578","wikidata":"https://www.wikidata.org/wiki/Q18733","display_name":"Recall","level":2,"score":0.2849000096321106},{"id":"https://openalex.org/C74256435","wikidata":"https://www.wikidata.org/wiki/Q134052","display_name":"Flood myth","level":2,"score":0.2833000123500824},{"id":"https://openalex.org/C2780741293","wikidata":"https://www.wikidata.org/wiki/Q4818019","display_name":"Attack patterns","level":3,"score":0.2556999921798706}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/nfv-sdn66355.2025.11349498","is_oa":false,"landing_page_url":"https://doi.org/10.1109/nfv-sdn66355.2025.11349498","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Network Function Virtualization and Software-Defined Networking (NFV-SDN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W2970641574","https://openalex.org/W2978631110","https://openalex.org/W3084798277","https://openalex.org/W4288043987","https://openalex.org/W4387870160","https://openalex.org/W4388494848","https://openalex.org/W4391582407","https://openalex.org/W4399929809","https://openalex.org/W4401634451","https://openalex.org/W4404739647","https://openalex.org/W4405304659","https://openalex.org/W4406258979","https://openalex.org/W4410857897"],"related_works":[],"abstract_inverted_index":{"In":[0],"this":[1],"paper":[2],"we":[3,76],"exploit":[4],"and":[5,58,113],"discuss":[6],"the":[7,20,29,56,69,72,119],"ability":[8],"of":[9,22,71,83,127],"Large":[10],"Language":[11],"Models":[12],"(LLMs)":[13],"in":[14],"detecting":[15],"out-of-distribution":[16],"(OOD)":[17],"attacks":[18],"within":[19],"context":[21],"6G":[23],"networks,":[24],"by":[25],"applying":[26],"them":[27],"to":[28,50,55,59,132],"5G-NIDD,":[30],"an":[31],"openly-accessible":[32],"dataset.":[33],"The":[34,44],"study":[35],"benchmarks":[36],"three":[37],"LLM-based":[38],"against":[39],"a":[40,78,124,136],"non-LLM":[41,137],"(LightGBM)":[42,139],"method.":[43],"data":[45],"samples":[46],"are":[47,95],"properly":[48],"converted":[49],"text":[51],"before":[52,62],"being":[53,63],"fed":[54],"LLMs":[57],"feature":[60],"vectors":[61],"injected":[64],"into":[65],"LightGBM.":[66],"To":[67],"assess":[68],"accuracy":[70],"four":[73],"models\u2019":[74],"predictions,":[75],"employ":[77],"leave-one-attack-out":[79,141],"approach,":[80],"allowing":[81],"evaluation":[82],"each":[84],"model\u2019s":[85],"performance":[86],"on":[87],"completely":[88],"unseen":[89],"attack":[90,93],"types.":[91],"Eight":[92],"types":[94],"evaluated,":[96],"namely":[97],"UDP":[98,109],"Flood,":[99,101],"HTTP":[100],"Slowrate":[102],"DoS,":[103],"TCP":[104],"Connect":[105],"Scan,":[106,108,110],"SYN":[107,111],"Flood":[112],"ICMP":[114],"Flood.":[115],"Results":[116],"demonstrate":[117],"that":[118],"proposed":[120],"method":[121],"can":[122],"achieve":[123],"malicious":[125],"recall":[126],"around":[128],"76%,":[129],"with":[130],"up":[131],"5%":[133],"improvement":[134],"over":[135],"baseline":[138],"under":[140],"OOD":[142],"protocol.":[143]},"counts_by_year":[],"updated_date":"2026-02-01T03:34:12.195049","created_date":"2026-01-30T00:00:00"}
