University of Portsmouth unveils V5GIDS intrusion detection framework for 5G networks
Researchers at the University of Portsmouth have developed V5GIDS, an AI-driven intrusion detection framework designed to operate as a virtualized network function within the ETSI NFV MANO ecosystem. The system utilizes federated learning and a two-stage detection pipeline to secure 5G infrastructures while minimizing telemetry bandwidth requirements.
Key Takeaways
- V5GIDS employs a two-stage pipeline combining convolutional autoencoders for feature extraction and random forests for rapid classification.
- The framework operates as a Virtualized Network Function (VNF), allowing for automated lifecycle management via standard orchestration protocols.
- Federated learning architecture permits distributed training across multiple nodes, sharing only model updates to preserve privacy and reduce bandwidth.
- Prototype testing against the CIC-IDS2017 and CIC-BCCC-NRC-TabularAttacks-2024 datasets confirmed high detection accuracy with minimal resource overhead.
Why It Matters
This development addresses the critical gap between theoretical AI security models and the operational constraints of software-defined 5G environments. By aligning with ETSI NFV MANO standards, the framework allows security to scale as a native network function rather than a bolt-on appliance, which is essential for low-latency edge computing. For the streaming ecosystem, this ensures that high-bandwidth video traffic remains protected without the performance degradation typically caused by exhaustive telemetry collection. The industry should monitor the public source code release to see if major telecommunications vendors adopt these federated learning principles for zero-touch service management.
Additional Context
The push to embed AI-driven security directly into virtualized 5G architectures is gaining momentum across the telecom ecosystem. In June 2026, Ericsson launched its AI in RAN commercial software subscription, claiming up to 20% higher downlink throughput and up to 10% better spectral efficiency across more than 15 live deployments, signaling that operators are moving from isolated AI pilots to production-grade deployments on live networks. Verizon disclosed that its 60,000-site vRAN is now applying agentic AI to planned configuration changes, service assurance, and network optimization, while publicly calling for industry-wide interoperability standards for agentic systems. This operational shift toward AI-native network functions creates the deployment environment where frameworks like V5GIDS could find commercial relevance. Nokia has emerged as the most aggressive vendor in stacking agentic AI components for autonomous network operations. At DTW Ignite 2026 in Copenhagen, Nokia teamed up with Google Cloud to build six specialized Gemini-powered agents targeting alarms, KPIs, anomaly detection, and remediation, with plans to launch the agentic platform in Google Cloud Marketplace in September. Nokia claims operators deploying these agents can slash network problem-solving times by 50% to 80%. Separately, Nokia announced work with AWS and Databricks to build the data, cloud, and control layers for its Autonomous Network Fabric, positioning the fabric as an operating system spanning radio, core, transport, and service domains. Nokia reports that operators using its autonomous networks portfolio are achieving automation rates higher than 90% and service interruption periods of one minute per year or fewer. The competitive divergence between Ericsson and Nokia on AI-RAN architecture has direct implications for how security functions like V5GIDS would integrate into operator stacks. Nokia's entire RAN strategy is now built on its close partnership with Nvidia, cemented by the chipmaker's $1 billion investment, with Layer 1 RAN functions designed to run on Nvidia's CUDA platform and GPUs. Ericsson, by contrast, is pursuing AI optimization on existing baseband silicon without requiring new GPU hardware. This architectural split means that any federated learning-based intrusion detection system must demonstrate compatibility with both GPU-accelerated and traditional baseband environments to achieve broad operator adoption. The absence of standardized protocols for agentic command and control across multi-vendor networks, as highlighted by Verizon's public call for interoperability standards, remains the critical bottleneck that academic frameworks like V5GIDS must navigate before commercial deployment.
Read full article at bioengineer.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source