CRJul 10

Impact of Benign Connectivity Variations on Intrusion Detection for Encrypted OPC UA Traffic in Industrial Private 5G Networks

arXiv:2607.096595.6
Predicted impact top 61% in CR · last 90 daysOriginality Synthesis-oriented
AI Analysis

It highlights a practical vulnerability for industrial network operators using ML-based IDS in private 5G, but the findings are incremental and confirm known issues.

This paper investigates how benign connectivity variations in private 5G networks affect ML-based intrusion detection for encrypted OPC UA traffic, finding that legitimate events increase false positives and anomaly scores correlate with control-plane activity.

Machine learning (ML)-based intrusion detection systems (IDSs) are increasingly used to monitor encrypted industrial communication. However, their behavior under realistic private 5G operating conditions remains insufficiently understood. This paper investigates the impact of benign connectivity variations on ML-based IDSs for encrypted Open Platform Communications Unified Architecture (OPC UA) traffic in industrial private 5G networks. Experimental results show that legitimate connectivity events can noticeably increase false positive activity despite the absence of attacks. Furthermore, elevated IDS anomaly scores frequently coincide with periods of control-plane (CP) activity associated with these events. The findings highlight the importance of considering CP context when interpreting IDS outputs in industrial private 5G environments.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes