Source-linked AI summary

Security and privacy for 6G: A survey on prospective technologies and challenges

Van-Linh Nguyen, Po-Ching Lin, Bo-Chao Cheng, Ren-Hung Hwang, Ying-Dar Lin

arXiv:2108.11861v2cs.CRcs.NI

TL;DR

6G security and privacy research remains largely conceptual despite diverse threats across integrated networks, novel technologies, and expanding user information. This survey systematically reviews prospective technologies and defenses across physical, connection, and service layers, drawing lessons from existing architectures. It identifies inherited vulnerabilities and new threat vectors, while highlighting several promising protection techniques.

  • Problem

    6G must address diverse threats, novel technologies, and expanding accessible user information, but its security and privacy issues remain largely conceptual.

  • Method

    The survey systematically reviews 6G security and privacy issues across physical, connection, and service layers, using lessons from existing architectures and state-of-the-art defenses.

  • Results

    The survey identifies inherited vulnerabilities and new threat vectors, including location exposure in THz systems, attacks on pervasive intelligence, and risks to molecular communications and network slicing.

  • Takeaways & Limitations

    Promising protections include physical-layer security, deep network slicing, quantum-safe communications, AI security, platform-agnostic and adaptive security, distributed ledgers, and differential privacy.

Abstract

from arXiv · show

Sixth-generation (6G) mobile networks will have to cope with diverse threats on a space-air-ground integrated network environment, novel technologies, and an accessible user information explosion. However, for now, security and privacy issues for 6G remain largely in concept. This survey provides a systematic overview of security and privacy issues based on prospective technologies for 6G in the physical, connection, and service layers, as well as through lessons learned from the failures of existing security architectures and state-of-the-art defenses. Two key lessons learned are as follows. First, other than inheriting vulnerabilities from the previous generations, 6G has new threat vectors from new radio technologies, such as the exposed location of radio stripes in ultra-massive MIMO systems at Terahertz bands and attacks against pervasive intelligence. Second, physical layer protection, deep network slicing, quantum-safe communications, artificial intelligence (AI) security, platform-agnostic security, real-time adaptive security, and novel data protection mechanisms such as distributed ledgers and differential privacy are the top promising techniques to mitigate the attack magnitude and personal data breaches substantially.

I. INTRODUCTION

6G security and privacy research remains early, while broader connectivity, heterogeneous networks, and pervasive devices create serious risks. This survey systematically reviews those issues across three network layers, architecture, prospective technologies, privacy models, and AI impacts.

  • Motivation: 6G’s expanded connectivity and heterogeneous space-air-ground-sea applications may expose sensitive personal information and create risks extending beyond financial or reputational loss.Connected implants, autonomous systems, and accessible user information raise concerns including health-record leaks and potentially life-threatening attacks.
  • Research gap: Research on 6G security and privacy is still at an early stage, with existing work focused mainly on IoT, 4G/5G, specific technologies, or fragmented 6G surveys.Many fundamental 6G network components remain undefined, limiting the available related work.
  • Survey scope and method: The survey classifies attacks and defenses across physical, connection, and service layers to provide a holistic view of 6G security and privacy challenges.The approach is intended to help operators and developers address attacks affecting fundamental protocols and applications.
  • Survey scope and method: The work examines both inherited security issues in legacy technologies and emerging risks in futuristic technologies such as THz communications.Its scope spans security architecture, layer-specific technologies, privacy-enhancing models, and AI’s impact.
  • Contributions: The survey learns from prior attacks and protocol flaws to identify security upgrades and remaining challenges for 6G.Unfixed vulnerabilities can become targets for 6G upgrades or foundations for future research.
  • Contributions: The article presents a comprehensive survey of prospective 6G security and privacy technologies across all layers and core architecture.The authors describe it as a first thorough review spanning security architecture, specific layer technologies, and AI’s impact.

III. SECURITY ISSUES AND THE EVOLUTION OF SECURITY ARCHITECTURE IN LEGACY MOBILE NETWORKS

The survey traces how mobile-network security evolved from severe early vulnerabilities through 4G and 5G enhancements, while emphasizing that legacy weaknesses and new protocol flaws remain relevant to 6G.

  • Review methodology: The survey uses failures and lessons from existing architectures and legacy technologies to assess attacks, privacy issues, and potential 6G enhancements.This approach frames historical vulnerabilities as inputs for anticipating future security and privacy requirements.
  • 1G–3G: 1G provided neither security nor privacy, while attacks introduced in 2G and 3G, including signaling DoS and energy depletion, remain unresolved.Downgrade attacks could force devices onto 2G, enabling man-in-the-middle attacks and IMSI-based location tracking.
  • 4G: 4G significantly enhanced security over 3G through EPS-AKA improvements, stronger interconnection protections, and cipher and integrity mechanisms.Despite these upgrades, fake serving networks and VoLTE keystream reuse enabled tracking, call decryption, spoofing, denial-of-service, and financial theft.
  • 5G: 5G added service-based architecture security and a unified authentication framework supporting both 3GPP and non-3GPP access networks.The unified platform allows one authentication execution before movement to another access network without reauthentication.
  • 5G: 5G protects subscriber identities better than 4G by using SUCI, an encrypted form of SUPI, during authentication.The permanent identifier is no longer sent over 5G networks in plaintext.
  • 5G vulnerabilities: 5G-AKA still has security weaknesses, including weak agreement between subscribers and serving networks caused by a missing binding assumption between serving and home networks.This flaw could allow an attacker to transfer network billing to another user.

C. Network deployment strategies’ impact on security architecture and security transition

6G deployment may use standalone or non-standalone strategies, with different cost, capability, and security-transition implications. Legacy vulnerabilities and unresolved attacks remain relevant during migration, especially when older infrastructure or protocols are retained.

  • Deployment strategies: Non-standalone deployment costs less and reuses existing facilities, whereas standalone deployment requires high CAPEX but provides the new standard’s full capacity.Non-standalone deployment connects the new standard through older infrastructure; standalone connects new base stations directly to the core network.
  • Inherited vulnerabilities: Legacy networks exhibit attacks including signalling DoS, authentication-server DDoS, energy depletion, user tracking, cloning, impersonation, paging disruption, and voice or SMS abuse.The supplied attack summaries include attacks across generations, with several marked as unresolved or only partially fixed.
  • Inherited vulnerabilities: Some attacks exploit weak authentication, insecure wireless channels, protocol bugs, downgrade procedures, leaked session information, or unencrypted paging data.The table notes that attack fixes vary, including “Yes,” “No,” and “Partially fixed” statuses.
  • Security transition: Non-standalone 5G uses 4G-LTE as the master radio access technology and 5G-NR as the secondary technology through dual connectivity.User equipment connects to both radios during the transition procedure.
  • Security transition: Optional confidentiality protection in dual authentication can expose non-standalone deployments to exploitation when it is not configured correctly.

D. Lessons learned from the security issues and enhancement from 1G to 5G for 6G security

The survey uses shortcomings in earlier cellular generations to identify security lessons for 6G. It emphasizes persistent protocol and resource limitations, risks introduced by new applications and compatibility, and the need to review security architecture and requirements systematically.

  • Persistent vulnerabilities: Signalling DoS, authentication-server DDoS, energy depletion, and user tracking are attacks expected to remain problematic in 6G.
  • Persistent vulnerabilities: Weak authentication, limited radio resources, and underlying protocol flaws are generic challenges across network generations.Perfectly fixing these issues remains difficult.
  • New applications: New applications can introduce vulnerabilities, as illustrated by keystream reuse in two successive VoLTE calls.
  • Compatibility: Supporting legacy devices can expose earlier vulnerabilities through downgrade attacks and requires careful dual-network authentication and identity management.The cited example involves forcing 4G-LTE devices onto 2G/3G networks to collect IMSIs and track locations.
  • Review approach: The review classifies 6G attacks and defenses across physical, connection, and service layers, covering enabling technologies and security requirements.This layer-based approach is intended to support operators and developers addressing specific high-risk attacks.

A. 6G applications, network vision, and potential security threats that impact on 6G security and privacy

6G is envisioned as a highly capable, heterogeneous network supporting expanded services, pervasive computing, and space-air-ground-sea integration. These capabilities introduce unresolved deployment, energy, protocol, and wireless-security challenges alongside new application and technology risks.

  • Network vision: 6G targets speeds over 1Tbps, latency under 1ms, and energy efficiency 10-100 times better than 5G.The roadmap places 6G in a typical 10-year evolution cycle and links it to sustainability goals and the Internet of Senses.
  • Network vision: 6G connection networks may provide personalized Network as a Service through intent-based networking, softwarization, cloudization, deep slicing, and function virtualization.
  • Applications and services: Beyond enhanced 5G services, 6G is expected to support long-distance high-mobility and extremely low-power communications, plus XR, digital twins, tactile Internet, medical nanorobots, automated driving, and holographic telepresence.
  • Integrated networks: Space-air-ground-sea integration combines satellites, high-altitude platforms, terrestrial base stations, and ships to provide broad coverage and high-rate, reliable transmission.Typical links include satellite-ground, satellite-aerial, inter-satellite, aerial-sea, aerial-ground, ground-sea, and ship-to-ship connections.
  • Technology constraints: Many 6G technologies remain early-stage, while terabit-per-second processing, quantum computing, and edge-server deployment present energy or maturity constraints.The technology comparison identifies high energy consumption, unrealized quantum computers, and incomplete edge deployment as challenges.
  • Integrated networks: Integration still requires protocol optimization for propagation delay, heterogeneous RAN capabilities, and service continuity across terrestrial and non-terrestrial systems.Infrastructure sharing among operators is also identified as critical.
  • Security challenges: Wireless attacks such as jamming and signalling DoS can degrade signals, interrupt communications, and delay messages in critical applications.

C. Overview of several security and privacy issues on typical

6G applications face varied security and privacy requirements because heterogeneous, autonomous connectivity expands both attack surfaces and sensitive user data exposure. The survey organizes these issues and proposed architectural upgrades across applications and security layers.

  • Application-level issues: Different 6G applications impose different security requirements and face distinct attacks, although some threats affect many services.Signalling DoS attacks, for example, can overload and degrade nearly all services.
  • Application-level issues: 6G’s heterogeneous connectivity and massive device scale require more automated and interoperable security approaches than conventional IT security.Examples of relevant attacks include DoS, eavesdropping, vulnerability exploitation, and spoofing.
  • Security architecture: The envisioned 6G architecture expands beyond 5G through new authentication models, cryptographic schemes, and physical-layer security for deep-sliced and open programmable networks.Candidate mechanisms include 6G-AKA, quantum-safe cryptography, and physical-layer protection against impersonation.
  • Security architecture: Passwordless biometric authentication, eSIM or non-SIM identity models, quantum-resistant encryption, homomorphic encryption, and end-to-end policy-based security are proposed 6G upgrades.Homomorphic encryption supports operations on encrypted data without decryption, while policy-based security targets personalization and micro-deployment flexibility.
  • Security architecture: Open authentication protocols are needed to support heterogeneous non-terrestrial interfaces, including satellite and maritime communications.The expansion to space-air-ground-sea networks may require standards beyond EAP-AKA and EAP-TLS.
  • Security architecture: Blockchain and distributed ledgers are proposed for mutual trust, privacy preservation, single-failure disruption prevention, and more reliable communication among key entities.Their large memory, computation, and energy requirements remain a significant deployment limitation.

F. Summary of lessons learned from key possible changes of 6G security

The survey’s lessons learned emphasize extending 5G security while adapting authentication, physical-layer protection, and privacy mechanisms to 6G’s broader environment. It also identifies imperfect channel knowledge and cooperative attackers as continuing obstacles.

  • Lessons learned: 6G will retain important 5G security features while extending them for space-air-ground-sea networks and broader multi-access convergence.The 5G-AKA framework requires additional security capabilities as coverage expands.
  • Lessons learned: Unified authentication, passwordless access, and open security models are presented as future directions, but comprehensive deployment across all applications requires long-term effort.The survey recommends implementing needed features first and expanding them as infrastructure becomes ready.
  • Physical-layer security: Physical-layer security exploits wireless-channel characteristics such as fading and noise to improve confidentiality and provide lightweight authentication.Its low complexity is particularly relevant to constrained 6G devices.
  • Remaining challenges: Physical-layer protections can address attacks affecting many applications, but covert channels may still enable data leakage or system intrusion.Upper-layer responses include detecting dangerous ports and anomalous signals or blocking vulnerable protocols.
  • Physical-layer security: Frequency hopping, artificial noise or friendly jamming, physical key generation, and secrecy-capacity-oriented precoding are surveyed as defenses against wireless attacks.These methods introduce randomness, interference, or channel-derived keys to hinder eavesdropping and related attacks.
  • Remaining challenges: Imperfect or partial eavesdropper channel-state information undermines defenses that assume complete CSI, while cooperative eavesdroppers remain difficult to detect.Transforming uncertain CSI constraints into deterministic ones is identified as one potential research direction.

B. Security in 6G Large Intelligent Surface

The survey examines LIS/IRS, holographic radio, NOMA, THz, and VLC as prospective 6G technologies with security benefits and distinct attack surfaces. Directionality and channel control can hinder interception, but localization, collusion, and immature defenses remain concerns.

  • LIS/IRS and emerging radios: LIS/IRS uses programmable reflecting elements to tune signal phase shifts and enhance communication performance, making it relevant to dense THz networks.Its controller provides an intelligent, programmable radio environment.
  • LIS/IRS and emerging radios: IRS-based transmission can provide secure communication links through multipath propagation, while NOMA increases simultaneous users by allocating power according to signal strength.The survey also identifies NOMA as a 5G technology that may support 6G massive connectivity.
  • LIS/IRS and emerging radios: Holographic radio uses software- or photonics-defined antenna arrays to generate directional beams with LIS assistance, but its security research and hardware implementations remain immature.The technology avoids conventional phase shifters and active amplification in beam steering.
  • THz communications: THz links’ narrow coverage and high directionality can increase resistance to jamming and eavesdropping, while wide-range frequency hopping reduces signal detectability.Successful jamming may require high-power bandwidth and short distance to the receiver.
  • THz communications: Reflectors can still redirect LOS THz radiation around obstacles, allowing wiretapping behind buildings; coordinated adversaries remain especially difficult to counter.Re-verifying attacks during device hand-off adds complexity.
  • THz communications: THz centimeter-level localization can expose user locations and behavioral information, creating a trade-off between privacy and communication optimization.Compromised access points may become surveillance devices, while constrained devices make privacy protection harder.
  • VLC communications: VLC/LiFi offers small coverage and wall-impenetrable LOS links that can improve security relative to prior wireless systems, but multi-eavesdropper collusion remains an open problem.Optical jamming and spatial modulation with zero-forcing precoding are surveyed as mitigation approaches.

G. Security in 6G Molecular communications

Molecular communications introduce distinctive security and privacy risks because nanodevices may operate in or near human bodies and use unconventional communication mechanisms. The survey identifies preliminary biochemical defenses but emphasizes that research and real-world validation remain limited.

  • Molecular communication: Molecular communication uses chemical signals or molecules to connect nano- and cell-scale entities instead of electronic or optical signals.The technology supports envisioned Internet of Nano-Things and extremely low-power communications, including healthcare and industrial monitoring applications.
  • Threats: Embedded nanodevices may leak healthcare information, while Internet connectivity can expose bio-machines to remote attacks.Potential consequences include malfunctioning devices harming the body or nano-robots damaging blood vessels.
  • Defenses: Existing wireless-security solutions cannot simply be applied because molecular communications have different network structures and interactions.Preliminary work considers biochemical cryptography using DNA/RNA information or protein structures to encode information integrity.
  • Open challenges: Research on preventing attacks and data breaches in molecular communications remains at an early stage.Ethical concerns make real attacks against hosts or human bodies less attractive to conduct.
  • Related physical-layer protections: Physical-layer technologies are presented as tools for mitigating spoofing messages and tampering with physical data bits across network and application layers.The survey discusses physical-layer authentication, key generation, and coding as relevant approaches.
  • Related physical-layer protections: Physical-layer authentication can be degraded by CSI estimation errors, low SNR, overlapping CSIs, and compromised training data.Multi-attribute multi-observation techniques are suggested to reduce bias and improve detection performance.

I. Summary of lessons learned from physical layer security

The survey’s physical-layer lessons emphasize environmental awareness, stronger authentication, quantum-safe migration, and careful balancing of security with energy and deployment costs. These priorities address both emerging 6G attack surfaces and inherited weaknesses in authentication and cryptographic systems.

  • Physical-layer lessons: Eavesdropping is the most common physical-layer threat, while maximizing channel secrecy rate is the favored defense.High directionality in joint communication and radar may make subscriber location exposure a major privacy concern.
  • Physical-layer lessons: Environmental monitoring is critical because rain, fog, obstacles, or attacker-released particles can scatter THz/VLC signals and aid eavesdropping.Multi-attribute multi-observation sensing can support adaptive beamforming and routing to reinforce security.
  • Physical-layer lessons: AI-aided physical-layer security is constrained by the lack of rigorous public datasets for testing detection performance.The survey identifies datasets as an Achilles’ heel for this research direction.
  • Connection-layer lessons: 6G AKA must strengthen authentication among serving networks, subscribers, and home networks to address session-key binding and subscriber-tracking risks.A stronger home-network and serving-network binding is described as a way to prevent associating KSEAF with the wrong SUPI.
  • Connection-layer lessons: Quantum-safe communication can combine enhanced existing ciphersuites, post-quantum algorithms, and eventually QKD as deployment and standardization progress.QKD offers quantum-physics-based security, but long-distance deployment remains technically challenging because of repeater requirements.
  • Connection-layer lessons: Mandatory end-to-end encryption and quantum-safe upgrades face uncertain feasibility because of transmission overhead, standardization time, deployment cost, and energy consumption.Increasing key sizes or processed data amounts can sharply raise encryption energy consumption, conflicting with 6G energy-efficiency goals.

C. Enhanced Security Edge Protection Proxy (SEPP) for securing interconnect between 6G networks: Roaming Security

The survey describes roaming protection through upgraded SEPP and TLS-based mechanisms, while identifying broader trust and distributed-ledger approaches for inter-network security. Deployment remains constrained by protocol vulnerabilities, computation, governance, regulation, and energy costs.

  • Roaming security: SEPP protects home-serving-network interconnections through end-to-end authentication, integrity, and confidentiality for roaming messages.SEPP uses signatures and encryption, with JSON Web Encryption protecting N32 exchanges against eavesdropping and replay attacks.
  • Roaming security: Future TLS-based roaming protection must address protocol vulnerabilities such as downgrade attacks to insecure previous versions.The widespread use of TLS makes identifying and addressing future TLS weaknesses a major challenge.
  • Trust and distributed ledgers: Trust networks are expected to preserve valuable information sharing while preventing fake or misbehaving sources and keeping undesirable events unlikely.Trust is framed as an assumption that interacting communication parties act consistently and faithfully.
  • Trust and distributed ledgers: Blockchain and distributed-ledger security remains immature because computation and communication burdens combine with unclear governance, regulation, and energy-intensive operation.These constraints are expected to delay practical deployment despite available mitigation proposals.
  • Software-defined networking: SDN and SD-WAN face DoS/DDoS and insider-adversary threats, while SD-WAN protection may involve IPsec, VPN tunnels, enhanced firewalls, and micro-segmentation.Because SD-WAN is still developing, the effectiveness of pure SDN protection methods remains unclear.
  • Network slicing: Network slicing can logically isolate security problems across RAN and core slices, but enforcing independent policies while meeting every slice’s KPI requirements remains open.End-to-end slicing specifications and automatic-deployment frameworks are not yet defined.

2) Virtualized RAN, Cloud-RAN, and Open RAN:

Virtualized and open RAN architectures promise modularity, reduced interdependence, and new security controls, while endpoint and service-layer protections remain essential. Their adoption is constrained by processing, investment, software, interoperability, and governance challenges.

  • Virtualized and open RAN: vRAN and Open RAN improve security prospects through virtualization, modularity, and reduced interdependencies.Virtualized baseband functions run on commodity servers rather than vendor-specific physical hardware.
  • Virtualized and open RAN: vRAN requires faster baseband processing for increasingly complex beam-space data, creating higher computational demands and CAPEX investment.High-frequency signal processing also makes fading and attenuation more demanding.
  • Virtualized and open RAN: Open-source RAN code can expose vulnerabilities when it is not appropriately designed and intensively inspected by security experts.Vulnerabilities may be easier for attackers to locate without reverse engineering and can propagate across dependent components.
  • Endpoints and gateways: Core-network security gateways inspect bidirectional traffic and include firewalls, WAFs, IDS, API protection, antivirus, and VPN systems.In 5G, an AMF-side gateway inspects traffic between the RAN and AMF; 6G gateways will require further development.
  • Service and PKI security: Quantum-safe schemes and distributed-ledger PKIs are prospective upgrades, but standardization, compatibility, computation, and energy costs remain unresolved.Blockchain-based PKIs can reduce reliance on centralized certificate authorities while improving scalability and reliability for 6G applications.
  • Service and endpoint security: Firewalls, IDS, and moving-target-defense systems will retain their roles in 6G but require greater automation and new capabilities.The survey treats their continued use as compatible with evolving network protection needs.
  • Service and application security: AKMA remains constrained by the lack of application models and business cases and by the need for close cooperation between network operators and application providers.Roaming interconnection security is also identified as an important issue.

C. 6G biometric authentication for 6G-enabled IoT and implantable devices

6G biometric authentication is presented as a password-free access mechanism for wearable, implantable, and other services, with multimodal and THz-based approaches improving authentication potential. However, biometric leakage and spoofing remain major concerns, while related service-security protocols and encryption also require upgrades for 6G ecosystems.

  • Biometric authentication: Biometric authentication can remove complicated codes and passwords, benefiting wearable devices, implantable equipment, and users with disabilities.It is considered a prospective technology for 6G service-layer access.
  • Biometric authentication: THz imaging and multimodal biometrics can distinguish artificial fingers and provide higher accuracy and flexibility than single biometric forms.THz imaging can identify superficial skin traits or faces, while multimodal combinations improve authentication capability.
  • Biometric authentication: Brain- and heart-signal authentication, including remote heartbeat identification at 200m, is expected to be more fraud-resistant than conventional methods.Individual cardiac signatures are described as unique and difficult to alter or disguise.
  • Remaining challenges: Biometric systems remain exposed to personal-information leakage, safety, ethical, and spoofing risks involving forged or synthetic biometric samples.Mass exposure of sensitive traits such as fingerprints could enable surveillance and abuse.
  • Service authorization: OAuth 3.0 is proposed as mandatory for 6G end-to-end service authorization, but it remains a concept proposal with features still under consideration.The proposal targets key proofing, multi-user delegation, and multidevice processing in complex 6G ecosystems.
  • Secure communication: HTTP/3 over QUIC can provide faster, more reliable transmission for low-latency applications, but UDP deployment and 0-RTT mismatches introduce security challenges.Potential issues include blocked UDP traffic, impaired inspection by deployed infrastructure, and replay attacks.

G. Liquid software security: a step to 6G platform-agnostic security

The survey presents liquid software and platform-agnostic security as ways to protect heterogeneous 6G computing nodes across edge and fog environments. It also identifies AI-enabled security automation, open standards, and stronger service protections as priorities, while noting unresolved deployment and insider-threat challenges.

  • Liquid software security: 6G liquid software extends cross-device application and data mobility to heterogeneous computing nodes such as edge servers.The strategy builds on partial support across tablets, smartphones, and wearable devices.
  • Remaining challenges: Service security must address insider attacks, where authorized provider staff may abuse and leak stored user data.Distributed backups, auditing, timestamps, and signatures are proposed responses.
  • Service-layer priorities: Service-layer upgrades prioritize application authentication, intelligent security-as-a-service, and platform-agnostic security.The survey identifies these as central targets of ongoing 6G research.
  • Platform-agnostic security: Platform-agnostic security with edge and fog intelligence can simplify security implementation and accelerate updates across distributed computing nodes.Softwarization and cloudization-based security solutions are identified as likely enablers.
  • AI-enabled security: AI is applied across 6G layers for behavior verification, attack prediction, radio and computing control, recovery prioritization, and malicious-traffic filtering.Examples include CNN-, DRL-, autoencoder-, DNN-, CNN-, LSTM-, DBN-, RBM-, and autoencoder-based approaches.
  • AI-enabled security: AI security research remains largely exploratory, focusing on enhancing conventional defenses or expanding their detection capability.Prospective directions include generative, distributed, federated, unsupervised, transfer, and meta-learning approaches.
  • Remaining challenges: AI deployment faces adversarial attacks and unresolved online-processing costs from heavy computation and substantial training time.Successful attacks against AI-controlled network components could disrupt packet forwarding or bypass malicious-traffic controls.

B. AI as a target: Security attacks against 6G AI-empowered engines and defense approaches

AI systems supporting 6G can themselves be attacked through manipulated data, algorithms, models, and deployment outputs. The survey reviews attack examples and defenses including diverse-data training, model comparison, blockchain, high-performance computing, output protection, and ethics-oriented safeguards.

  • Attack surface: AI systems in 6G are vulnerable to white-box, gray-box, and black-box attacks targeting training data, algorithms, or hyper-parameters.The attacker’s available knowledge determines the attack setting.
  • Attack types: Data poisoning inserts wrongly labelled data or altered inputs, algorithm poisoning manipulates distributed updates, and model poisoning replaces deployed models.Data poisoning is described as especially challenging because outdoor inputs are widely accessible.
  • Defense approaches: Potential defenses include high-performance computing, blockchain protection of local data and models, adversarial-model detection, output obfuscation, and prediction purification.One method compares predictions on original and squeezed inputs to identify contaminated samples.
  • Attack examples: 6G AI attacks include manipulated traffic-sign imagery against autonomous driving and falsified updates influencing edge resource allocation or traffic scheduling.These examples represent physical poisoning and algorithm attacks against AI-based systems.
  • Defense approaches: Training AI models with multiple dataset types can help determine whether an algorithm is adversarial.This defense concept is illustrated for AI protection in Figure 24.
  • AI weaponization: AI can also weaponize attacks through sensor-fusion evasion, autonomous-vehicle manipulation, concealed malware, facial recognition, and geolocation.The survey notes that research on such attacks in 6G communications remains at an early stage.

D. Summary of lessons learned from AI’s impact on 6G security

The survey finds that AI can improve detection, prediction, automation, and security performance across 6G layers, but it is not sufficient for every security problem. It therefore emphasizes combining AI with non-AI protections while addressing explainability, data, privacy, and abuse risks.

  • Lessons learned: AI can enhance security performance and automate malicious-traffic detection and filtering across physical, connection, and service layers.The reviewed applications range from physical coding to radio-control optimization and service access control.
  • Lessons learned: Quantum-safe encryption, secure communication protocols, and network slicing remain important non-AI technologies for 6G security isolation and protection.AI is described as valuable but not a universal solution.
  • Lessons learned: Current AI security methods can detect attack patterns or predict attack probabilities but cannot explain why attacks occur or establish causal relationships.Causal and generative learning are identified as future directions requiring substantial training data and improved models.
  • Lessons learned: AI-based security requires large datasets, extensive data cleaning, and improved learning models to support causal prediction and prevention.Meta-learning and reinforcement learning are proposed candidates, although data preparation remains laborious.
  • Lessons learned: AI can be abused to evade detection, conduct reconnaissance, and create autonomous weapons targeting people or systems.The survey treats AI’s offensive use as a distinct security and ethics concern.
  • Privacy implications: 6G privacy becomes more urgent because connected devices expose sensitive medical information and dense THz localization can support centimeter-level surveillance.The survey also notes that privacy preservation is increasingly tied to legal requirements and organizational trust.
  • Privacy approaches: Pseudonymization, secure multiparty computation, and differential privacy provide complementary approaches for hiding identities, protecting distributed inputs, and filtering individual queries.Differential privacy aggregates data and adds noise or randomness to retrieved results.

C. Privacy challenges

6G privacy preservation faces financial, resource, oversight, and implementation challenges as connected devices and data-driven services expand. The survey identifies privacy-enhancing technologies, but notes that their weaknesses must be addressed for feasible deployment.

  • Implementing privacy preservation can impose substantial organizational costs for encryption, anonymization, equipment, and software customization.
  • Resource-constrained wearables and IoT sensors often lack strong authentication and security mechanisms while collecting location and health information.
  • Limited oversight leaves users with little control over data collection, while penalties may occur only after major breaches.
  • Blockchain, federated or distributed learning, quantum homomorphic encryption, and differential privacy are prospective privacy-enhancing technologies for 6G.Their flaws, including resistance to insider attacks, still require attention.
  • The survey assesses prospective security and privacy technologies using automation, trustworthiness, privacy, reliability, and openness, including transitional deployment paths.Examples include temporary quantum-resistant ciphersuites before quantum-safe TLS and distributed subscription after nuSIM or non-ID management.

3) Enhancing privacy technologies that satisfy GDPR:

6G privacy technologies must balance data protection with the complexity, computation, and learning needs of heterogeneous networks. The paper also identifies real-time protection, architectural simplicity, supply-chain integrity, and backward compatibility as unresolved security requirements.

  • Enhancing privacy technologies that satisfy GDPR:: Privacy challenges will probably worsen as network complexity and application diversity increase across 6G.
  • Enhancing privacy technologies that satisfy GDPR:: Blockchain, distributed learning, federated learning, homomorphic encryption, and differential privacy can support personal-data protection, GDPR compliance, and information mining.Their feasibility still requires enhancements and stress tests in real network environments.
  • Open challenges and issues: 6G security must preserve strict timing and predictability for latency-sensitive applications such as autonomous vehicles, industrial automation, and telesurgery.
  • Open challenges and issues: Simplifying security architecture is difficult because expanded coverage, diverse services, and different protection requirements increase design complexity.
  • Open challenges and issues: Supply-chain security requires mechanisms such as blockchain, AI, and physical security to detect corrupted components and validate equipment authenticity.
  • Open challenges and issues: Backward compatibility remains necessary for non-stand-alone deployment but can expose old vulnerabilities during 6G interoperation.
  • Open challenges and issues: Prospective 6G protections still face major real-time and energy-efficiency challenges, which may leave security services below their intended requirements.
  • Open challenges and issues: Open RAN and open-source security are identified as important initiatives for improving supply-chain security.
Loading 2108.11861v2…