Abstract
The rise of 5G networks has introduced new security challenges, particularly in detecting and mitigating dynamic traffic anomalies, adversarial threats, and large-scale cyberattacks. Traditional Machine learning-based Intrusion Detection Systems (IDS) suffer from high latency, poor adaptability, and privacy risks due to centralized data aggregation. To address these issues, we propose FedLLMGuard as a novel framework integrating Federated Learning (FL) with Large Language Models (LLM) for real-time privacy-preserving and adaptive anomaly detection in5G networks. Our method uses FL for decentralized learning while utilizing LLM for contextual traffic analysis and interoperability. Moreover, our framework introduces the CorruptNet adversarial attack, a novel poisoning strategy targeting FL-based anomaly detection, ensuring robustness evaluation under adversarial conditions. We evaluate our model against three methods –Random Forest, LSTM, and PSO Autoencoder LSTM – using three benchmark datasets: TII-SSRC-23, CICDDoS2019, and NF-UNSW-NB15. Experimental results demonstrate that FedLLMGuard outperformed all models, whether subjected to the CorruptNet adversarial attack or not. Under the CorruptNet attack, it achieves an accuracy of 98.64%, a false positive rate of only 2.16%, and ultra-low detection latency (0.0113s). These results underscore FedLLMGuard’s capacity to detect threats rapidly, mitigate attacks effectively, and sustain high accuracy while ensuring data privacy, making it a scalable and resource-efficient security solution for 5G networks.
| Original language | English |
|---|---|
| Article number | 111473 |
| Number of pages | 16 |
| Journal | Computer Networks |
| Volume | 269 |
| Early online date | 26 Jun 2025 |
| DOIs | |
| Publication status | Published - 1 Sept 2025 |
Keywords
- 5G networks
- Federated learning
- Large language models
- Network traffic anomalies
- Privacy
Fingerprint
Dive into the research topics of 'FedLLMGuard: A federated large language model for anomaly detection in 5G networks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver