O-RAN is a new, open, adaptive, and intelligent RAN architecture. Motivated by the success of artificial intelligence in other domains, O-RAN strives to leverage machine learning (ML) to automatically and efficiently manage network resources in diverse use cases such as traffic steering, quality of experience prediction, and anomaly detection. Unfortunately, it has been shown that ML-based systems are vulnerable to an attack technique referred to as adversarial machine learning (AML). This special kind of attack has already been demonstrated in recent studies and in multiple domains. In this paper, we present a systematic AML threat analysis for O-RAN. We start by reviewing relevant ML use cases and analyzing the different ML workflow deployment scenarios in O-RAN. Then, we define the threat model, identifying potential adversaries, enumerating their adversarial capabilities, and analyzing their main goals. Next, we explore the various AML threats associated with O-RAN and review a large number of attacks that can be performed to realize these threats and demonstrate an AML attack on a traffic steering model. In addition, we analyze and propose various AML countermeasures for mitigating the identified threats. Finally, based on the identified AML threats and countermeasures, we present a methodology and a tool for performing risk assessment for AML attacks for a specific ML use case in O-RAN.
翻译:O-RAN是一种新型、开放、自适应且智能化的无线接入网络架构。受人工智能在其他领域成功应用的启发,O-RAN致力于利用机器学习(ML)在流量引导、体验质量预测和异常检测等多种场景中自动高效地管理网络资源。然而,研究表明基于ML的系统易受一种被称为对抗性机器学习(AML)的攻击技术影响。这种特殊攻击已在近期研究及多个领域中得到验证。本文对O-RAN进行了系统性的AML威胁分析。我们首先梳理相关ML用例,分析O-RAN中不同的ML工作流部署场景。随后定义威胁模型,识别潜在攻击者,列举其对抗能力,并分析其主要目标。接着,我们探讨与O-RAN相关的各类AML威胁,回顾大量可实现这些威胁的攻击方法,并在流量引导模型上演示AML攻击。此外,我们分析并提出多种缓解已识别威胁的AML对策。最后,基于已识别的AML威胁与对策,我们提出一种针对O-RAN中特定ML用例进行AML攻击风险评估的方法与工具。