
Quan Peng, Shan Wang, Jian Wang, Hu Shi, JingNi Chen, PeiHao Song · Computer Networks 2026 · 2026
DOI: 10.1016/j.comnet.2026.112666
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Mobile communication networks are rapidly evolving toward 5G and Non-Terrestrial Networks (NTN). However, the Long Term Evolution (LTE) protocol stack still carries critical control-plane procedures in 5G Non-Standalone (NSA) deployments and Low Earth Orbit (LEO) satellite Direct-to-Cell services. This backward compatibility leaves LTE mobility-management procedures exposed to Fake Base Station (FBS) and signal overshadowing threats. In particular, attackers can tamper with unprotected Non-Access Stratum (NAS) and Radio Resource Control (RRC) semantics, such as reject causes and security-capability fields, without necessarily disrupting physical-layer synchronization. Existing detectors based on physical-layer fingerprints or coarse state-machine rules are therefore insufficient for fine-grained Layer-3 (L3) semantic attacks. To address this problem, this paper proposes the AI-Driven Attack Detector (ADAD), a domain-knowledge-driven L3 detection framework. ADAD introduces GRUAtt2FW (Gated Recurrent Unit with Attention and Two Feature-Weighting stages), which integrates protocol-expert priors with temporal attention to prevent critical low-frequency attack fields from being diluted by high-variance identifiers in massive logs. To mitigate the lack of interpretability in deep learning models, we further use general and domain-specific Large Language Models (LLMs) as an offline semantic-diagnosis module. We construct a hybrid dataset containing legitimate, FBS, and overshadowing scenarios, incorporating empirical Over-The-Air (OTA) laboratory data and public benchmarks. Experimental results show that GRUAtt2FW achieves F1-Scores of 90.0% and 93.1% on NAS and RRC independent test sets, respectively, with average per-sequence detection latency of 1.22 ms for NAS and 2.82 ms for RRC on the evaluated CPU platform. The RRC false positive rate (FPR) is reduced to 2.0%. These results indicate that domain-guided feature weighting improves L3 semantic attack detection, while the LLM module is used for post-hoc semantic diagnosis rather than online inference.
No comments yet — start the discussion below.