{"id":"https://openalex.org/W4415971006","doi":"https://doi.org/10.1109/tnse.2025.3629983","title":"AI-on-RAN for Cyber Defense: An XAI-LLM Framework for Interpretable Anomaly Detection","display_name":"AI-on-RAN for Cyber Defense: An XAI-LLM Framework for Interpretable Anomaly Detection","publication_year":2025,"publication_date":"2025-11-06","ids":{"openalex":"https://openalex.org/W4415971006","doi":"https://doi.org/10.1109/tnse.2025.3629983"},"language":null,"primary_location":{"id":"doi:10.1109/tnse.2025.3629983","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnse.2025.3629983","pdf_url":null,"source":{"id":"https://openalex.org/S2484352698","display_name":"IEEE Transactions on Network Science and Engineering","issn_l":"2327-4697","issn":["2327-4697","2334-329X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network Science and Engineering","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5093111414","display_name":"Sotiris Chatzimiltis","orcid":"https://orcid.org/0000-0002-4980-2608"},"institutions":[{"id":"https://openalex.org/I28290843","display_name":"University of Surrey","ror":"https://ror.org/00ks66431","country_code":"GB","type":"education","lineage":["https://openalex.org/I28290843"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Sotiris Chatzimiltis","raw_affiliation_strings":["5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K"],"raw_orcid":"https://orcid.org/0000-0002-4980-2608","affiliations":[{"raw_affiliation_string":"5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K","institution_ids":["https://openalex.org/I28290843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022893278","display_name":"Mohammad Shojafar","orcid":"https://orcid.org/0000-0003-3284-5086"},"institutions":[{"id":"https://openalex.org/I28290843","display_name":"University of Surrey","ror":"https://ror.org/00ks66431","country_code":"GB","type":"education","lineage":["https://openalex.org/I28290843"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Mohammad Shojafar","raw_affiliation_strings":["5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K"],"raw_orcid":"https://orcid.org/0000-0003-3284-5086","affiliations":[{"raw_affiliation_string":"5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K","institution_ids":["https://openalex.org/I28290843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028862760","display_name":"Mahdi Boloursaz Mashhadi","orcid":"https://orcid.org/0000-0001-9948-9165"},"institutions":[{"id":"https://openalex.org/I28290843","display_name":"University of Surrey","ror":"https://ror.org/00ks66431","country_code":"GB","type":"education","lineage":["https://openalex.org/I28290843"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Mahdi Boloursaz Mashhadi","raw_affiliation_strings":["5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K"],"raw_orcid":"https://orcid.org/0000-0001-9948-9165","affiliations":[{"raw_affiliation_string":"5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K","institution_ids":["https://openalex.org/I28290843"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5032549075","display_name":"Rahim Tafazolli","orcid":"https://orcid.org/0000-0002-6062-8639"},"institutions":[{"id":"https://openalex.org/I28290843","display_name":"University of Surrey","ror":"https://ror.org/00ks66431","country_code":"GB","type":"education","lineage":["https://openalex.org/I28290843"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Rahim Tafazolli","raw_affiliation_strings":["5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K"],"raw_orcid":"https://orcid.org/0000-0002-6062-8639","affiliations":[{"raw_affiliation_string":"5G/6GIC, Institute for Communication Systems (ICS), University of Surrey, Guildford, U.K","institution_ids":["https://openalex.org/I28290843"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5093111414"],"corresponding_institution_ids":["https://openalex.org/I28290843"],"apc_list":null,"apc_paid":null,"fwci":2.1733,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.91086934,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":"13","issue":null,"first_page":"3301","last_page":"3319"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.4424999952316284,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.4424999952316284,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.14489999413490295,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.11729999631643295,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7379000186920166},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7300000190734863},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.6736999750137329},{"id":"https://openalex.org/keywords/controller","display_name":"Controller (irrigation)","score":0.42640000581741333},{"id":"https://openalex.org/keywords/sequence","display_name":"Sequence (biology)","score":0.4203999936580658},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.382099986076355},{"id":"https://openalex.org/keywords/multivariate-statistics","display_name":"Multivariate statistics","score":0.32280001044273376}],"concepts":[{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7379000186920166},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7300000190734863},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7110999822616577},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.6736999750137329},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.51910001039505},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.49470001459121704},{"id":"https://openalex.org/C203479927","wikidata":"https://www.wikidata.org/wiki/Q5165939","display_name":"Controller (irrigation)","level":2,"score":0.42640000581741333},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.42489999532699585},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.4203999936580658},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.382099986076355},{"id":"https://openalex.org/C161584116","wikidata":"https://www.wikidata.org/wiki/Q1952580","display_name":"Multivariate statistics","level":2,"score":0.32280001044273376},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.3098999857902527},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.3021000027656555},{"id":"https://openalex.org/C151406439","wikidata":"https://www.wikidata.org/wiki/Q186588","display_name":"Time series","level":2,"score":0.2957000136375427},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.29120001196861267},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.28290000557899475},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.28130000829696655},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.257099986076355}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tnse.2025.3629983","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnse.2025.3629983","pdf_url":null,"source":{"id":"https://openalex.org/S2484352698","display_name":"IEEE Transactions on Network Science and Engineering","issn_l":"2327-4697","issn":["2327-4697","2334-329X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network Science and Engineering","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G6288601437","display_name":"CHEDDAR: Communications Hub for Empowering Distributed clouD computing Applications and Research - TMF uplift","funder_award_id":"EP/Y037421/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G8444387157","display_name":"CHEDDAR: Communications Hub For Empowering Distributed ClouD Computing Applications And Research","funder_award_id":"EP/X040518/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":83,"referenced_works":["https://openalex.org/W1591261915","https://openalex.org/W1985987493","https://openalex.org/W2148143831","https://openalex.org/W2516809705","https://openalex.org/W2896827527","https://openalex.org/W3006912911","https://openalex.org/W3093410479","https://openalex.org/W3121453273","https://openalex.org/W3136375527","https://openalex.org/W3142062746","https://openalex.org/W3206160551","https://openalex.org/W4205618214","https://openalex.org/W4211123510","https://openalex.org/W4285248859","https://openalex.org/W4313116287","https://openalex.org/W4313591247","https://openalex.org/W4317796310","https://openalex.org/W4321016094","https://openalex.org/W4321606864","https://openalex.org/W4328053442","https://openalex.org/W4361010174","https://openalex.org/W4378365142","https://openalex.org/W4382249075","https://openalex.org/W4385269797","https://openalex.org/W4387870064","https://openalex.org/W4387871162","https://openalex.org/W4388948449","https://openalex.org/W4389779297","https://openalex.org/W4390659158","https://openalex.org/W4390826948","https://openalex.org/W4391093675","https://openalex.org/W4391582407","https://openalex.org/W4391986380","https://openalex.org/W4392902389","https://openalex.org/W4394586044","https://openalex.org/W4394625946","https://openalex.org/W4396817219","https://openalex.org/W4399205915","https://openalex.org/W4399283298","https://openalex.org/W4399310894","https://openalex.org/W4399338566","https://openalex.org/W4400811247","https://openalex.org/W4401070271","https://openalex.org/W4401247017","https://openalex.org/W4401366983","https://openalex.org/W4401508167","https://openalex.org/W4401539961","https://openalex.org/W4402340420","https://openalex.org/W4402742293","https://openalex.org/W4402742350","https://openalex.org/W4402897233","https://openalex.org/W4403052641","https://openalex.org/W4403938349","https://openalex.org/W4404035584","https://openalex.org/W4404240613","https://openalex.org/W4404469447","https://openalex.org/W4404627583","https://openalex.org/W4404918643","https://openalex.org/W4405014713","https://openalex.org/W4405578422","https://openalex.org/W4406090087","https://openalex.org/W4406230518","https://openalex.org/W4406861326","https://openalex.org/W4407168795","https://openalex.org/W4407943083","https://openalex.org/W4408016758","https://openalex.org/W4408017321","https://openalex.org/W4408047557","https://openalex.org/W4408519728","https://openalex.org/W4408913906","https://openalex.org/W4409221719","https://openalex.org/W4410086870","https://openalex.org/W4410857897","https://openalex.org/W4410985905","https://openalex.org/W4411160947","https://openalex.org/W4411232491","https://openalex.org/W4412030696","https://openalex.org/W4412877051","https://openalex.org/W4413554179","https://openalex.org/W4413904443","https://openalex.org/W4414406064","https://openalex.org/W4414416643","https://openalex.org/W4414594130"],"related_works":[],"abstract_inverted_index":{"Next":[0],"generation":[1],"Radio":[2],"Access":[3],"Networks":[4],"(RANs)":[5],"introduce":[6],"programmability,":[7],"intelligence,":[8],"and":[9,22,36,115,161],"near":[10],"real-time":[11],"control":[12],"through":[13],"intelligent":[14],"controllers,":[15],"enabling":[16],"enhanced":[17],"security":[18],"within":[19,77],"the":[20,78],"RAN":[21,52,81],"across":[23],"broader":[24],"5G/6G":[25],"infrastructures.":[26],"This":[27],"paper":[28],"presents":[29],"a":[30],"comprehensive":[31],"survey":[32],"highlighting":[33],"opportunities,":[34],"challenges,":[35],"research":[37],"gaps":[38],"for":[39],"Large":[40],"Language":[41],"Model":[42],"(LLM)-assisted":[43],"explainable":[44],"(XAI)":[45],"Intrusion":[46],"Detection":[47],"Systems":[48],"(IDS)":[49],"in":[50],"future":[51],"environments.":[53],"Motivated":[54],"by":[55],"this,":[56],"we":[57,106],"propose":[58],"an":[59],"LLM":[60],"interpretable":[61,162],"anomaly":[62],"detection":[63,149],"system":[64],"leveraging":[65],"multivariate":[66],"time":[67],"series":[68],"Key":[69],"Performance":[70],"Measures":[71],"(KPMs),":[72],"extracted":[73],"from":[74],"E2":[75],"nodes,":[76],"Near":[79],"Real-Time":[80],"Intelligent":[82],"Controller":[83],"(Near-RT":[84],"RIC).":[85],"A":[86],"sequence":[87],"classification":[88],"model":[89],"is":[90],"trained":[91],"to":[92,117,125,133],"identify":[93],"malicious":[94],"User":[95],"Equipment":[96],"(UE)":[97],"behavior":[98],"based":[99],"on":[100,138],"these":[101],"KPMs.":[102],"To":[103],"enhance":[104],"transparency,":[105],"apply":[107],"post-hoc":[108],"local":[109],"explainability":[110],"methods":[111],"such":[112],"as":[113],"LIME":[114],"SHAP":[116],"interpret":[118],"individual":[119],"predictions.":[120],"Furthermore,":[121],"LLMs":[122],"are":[123],"employed":[124],"convert":[126],"technical":[127],"explanations":[128],"into":[129],"natural-language":[130],"insights":[131],"accessible":[132],"non-expert":[134],"users.":[135],"Experimental":[136],"results":[137],"real":[139],"5G":[140],"network":[141],"KPMs":[142],"demonstrate":[143],"that":[144],"our":[145],"framework":[146],"achieves":[147],"high":[148],"accuracy":[150],"(macro":[151],"F1-score":[152],"<inline-formula":[153],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[154],"xmlns:xlink=\"http://www.w3.org/1999/xlink\"><tex-math":[155],"notation=\"LaTeX\">$&gt;$</tex-math></inline-formula>":[156],"0.96)":[157],"while":[158],"delivering":[159],"actionable":[160],"outputs.":[163]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2025-12-12T23:16:27.785689","created_date":"2025-11-06T00:00:00"}
