• Home
  • About MARE
    • Project Overview
    • Objectives & Impact
  • News
    • Latest News
    • Press Releases
    • Newsletter
    • Blogspot
  • Events
    • 1st MARE Webinar
    • 6G Threat Landscape and Mitigation: The MARE Approach
  • Partners
  • Proof of Concepts
  • Resources
    • Presentations
    • Publications
    • Open Access Datasets
    • Posters
    • Dissemination & Communication Material
    • Videos
  • Contact
  • Home
  • About MARE
    • Project Overview
    • Objectives & Impact
  • News
    • Latest News
    • Press Releases
    • Newsletter
    • Blogspot
  • Events
    • 1st MARE Webinar
    • 6G Threat Landscape and Mitigation: The MARE Approach
  • Partners
  • Proof of Concepts
  • Resources
    • Presentations
    • Publications
    • Open Access Datasets
    • Posters
    • Dissemination & Communication Material
    • Videos
  • Contact

Mirroring the Future: How AI is Creating Safe Playgrounds for 6G Networks

Blog

Have you ever wondered how engineers test defenses against massive cyberattacks without accidentally taking down the real networks we rely on every day? As 5G and the emerging 6G networks evolve into the critical, AI-native backbone of our digital infrastructure, they are growing incredibly complex. Consequently, the risk and financial cost of testing new orchestration policies or security mechanisms directly on live, functioning systems have become prohibitive. To solve this, researchers are turning to “Network Digital Twins” (NDTs), which are virtual replicas that mirror the behavior of real networks, providing a risk-free sandbox for vital experiments without touching production. Moving Beyond Rough Sketches While the concept of a digital twin isn’t entirely new, earlier versions have often acted like rough sketches. Current solutions frequently focus on general, coarse performance predictions rather than accurately replicating the chaotic, high-fidelity reality of dynamic traffic patterns. A newly published breakthrough is changing that landscape entirely. Researchers have developed an advanced, AI-native Network Digital Twin engine based on a “Graph Transformer” and designed to deeply analyze and reconstruct the intricate, second-by-second spatio-temporal dynamics of 5G traffic. Instead of just estimating how a network might behave, this AI meticulously learns the underlying statistical structure and natural rhythms of benign, everyday activities -such as streaming a video, and contrasts them with the aggressive, overwhelming data floods typical of a Distributed Denial-of-Service (DDoS) cyberattack. Unprecedented Accuracy in Simulation The results of this new approach are genuinely groundbreaking. In rigorous experimental tests using comprehensive telemetry from a real 5G testbed, this AI model achieved an astounding accuracy score of over 98% (with R-squared scores up to 0.9839) in replicating network traffic. It significantly outperformed older, traditional AI baselines, like Long Short-Term Memory (LSTM) networks, proving its unique ability to perfectly mimic the heartbeat of a real network. When the digital twin simulates an attack, it accurately reproduces the exact data spikes, bottlenecks and signal drops that would occur in reality, preserving the underlying probability distributions and variance of real-world telemetry. A Risk-Free Future for Cybersecurity The true novelty of this work lies in this unprecedented level of fidelity. It creates a reusable, secure testing environment capable of generating realistic network traffic traces entirely on demand, without needing access to an actual live network’s measurements. This innovation represents a massive leap forward for European cybersecurity research, directly supporting the advanced objectives of collaborative efforts like the MARE project. By providing a genuinely risk-free, highly accurate virtual replica, this digital twin empowers researchers and engineers to safely evaluate robust mitigation strategies, performance and control policies. Ultimately, this foundational work ensures that as we move into the hyper-connected era of 6G, our critical digital ecosystems will remain remarkably resilient and secure. Publication Details Conformal Prediction and Risk-Based Optimization of Service Continuity in 6G Edge Networks Authors: Athina Vekraki, Maria Christopoulou, Ioannis Vasalos, Michail Alexandros Kourtis, Athanasia Alonisioti, George Xilouris MARE Partner: National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: As 5G and emerging 6G networks evolve into highly complex, AI-native infrastructures, the risk and cost of testing new orchestration policies or security mechanisms on live systems become prohibitive. Network Digital Twins (NDTs) have emerged as a critical paradigm for providing risk-free virtual replicas; however, current solutions often focus on coarse performance prediction rather than the high-fidelity replication of dynamic traffic patterns. In this paper, we present an AI-native NDT engine based on Graph Transformers designed to reconstruct the intricate spatio-temporal dynamics of 5G traffic. Using a comprehensive dataset from an Amarisoft-based testbed, we model network telemetry as a k-hop temporal line graph to capture the underlying statistical structure and bitrate oscillations of individual User Equipments (UEs) across both benign streaming and Distributed Denial-of-Service (DDoS) traffic regimes. Experimental results demonstrate that our Graph Transformer architecture achieves high-fidelity reconstruction with R^2 scores up to 0.9839, significantly outperforming traditional Long Short-Term Memory (LSTM) baselines. Furthermore, strong alignment in Cumulative Distribution Function (CDF) analysis confirms the model’s ability to preserve the underlying probability distributions and variance of real-world telemetry. This work provides a foundation for high-fidelity traffic synthesis and reproducible security analysis in future 6G ecosystems.

27 May, 2026 / 0 Comments
read more

Securing Tomorrow’s Connected World: The HORSE and MARE Vision for 6G

Blog

Imagine a world where your mobile internet is fast enough to download an entire high-definition movie in a fraction of a second, where driverless cars communicate with traffic lights flawlessly and where complex remote surgeries happen smoothly across continents. This is the incredible promise of 6G, the next generation of wireless technology. However, as our physical and digital worlds become deeply intertwined, the networks we rely on become prime targets for sophisticated cyberattacks. Traditional security measures, which were designed for older generations of technology, simply will not be able to keep pace with the massive scale and complexity of 6G. To address this urgent challenge, an international team of expert researchers from Italy, Spain and Greece has proposed a groundbreaking solution. In their newly published paper, they unveil the collaborative vision of two pioneering initiatives supported by The European Smart Networks and Services Joint Undertaking (SNS JU) – the HORSE and MARE projects. Their goal is to completely reinvent how we protect mobile networks, shifting from rigid, old-school defense methods to a dynamic system built specifically for the 6G era. The Innovation: Shifting to Programmable Security The core innovation of this research lies in a concept known as “programmable security”. Traditionally, network security operated much like a physical brick wall – static, rigid and incredibly difficult to alter once built. If an entirely new type of cyber threat emerged, modifying that wall took significant time, leaving the network temporarily exposed. The HORSE and MARE projects replace this outdated wall with a smart, software-driven shield. This digital shield can automatically reshape, reprogram and upgrade itself in real-time to neutralize emerging threats the moment they appear. A Global Digital Bodyguard to Protect our Daily Lives What makes this work uniquely novel is the introduction of a dedicated “security plane” within the 6G network architecture. Think of this as an autonomous digital bodyguard focused entirely on network safety. Instead of individual applications or devices scrambling to defend themselves, this centralized bodyguard monitors the entire system. Furthermore, because future networks will span multiple global operators and service providers, this framework is built to operate transparently across different organizational boundaries. It allows diverse stakeholders to share threat intelligence and deploy defenses seamlessly without compromising user privacy or network performance. Why this is Essential Why does this matter to the general public? In the near future, 6G will power critical infrastructure, including automated hospitals, smart energy grids and emergency response systems. A security breach in a 6G network won’t just mean a leaked password. It could disrupt vital real-world services. By making security proactive, adaptable and deeply embedded into the network’s DNA, the HORSE and MARE projects ensure that our hyper-connected future remains safe, resilient and trustworthy for everyone. Thanks to this pioneering research, the invisible infrastructure supporting our daily lives will be ready to defend itself against the threats of tomorrow. Publication Details Programmable Security for 6G Mobile Networks: The vision of HORSE and MARE projects Authors: Fabrizio Granelli, Eva Rodriguez, Xavier Masip-Bruin, Ioannis Vasalos, George Xilouris MARE Partners: Consorzio Nazionale Interuniversitario per le Telecomunicazioni (CNIT) Universitat Politècnica de Catalunya (UPC) National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: In 6G, effective protection mechanisms must be inherently cross-layer and adaptive. In this context, the HORSE and MARE projects align with this vision by proposing an adaptable and extensible approach based on a 6G service provisioning platform. This approach introduces a novel security plane built upon a well-defined set of open and programmable security functions, delivered as enablers within the 6G architecture. It operates transparently across multi-domain and multistakeholder environments, while efficiently handling emerging threats. As such, it enables the dynamic orchestration of security strategies to efficiently address novel and evolving attacks.

27 May, 2026 / 0 Comments
read more

Securing the Future: How Virtual Clones Are Protecting 5G and 6G Networks

Blog

As we transition into the era of ultra-fast 5G and emerging 6G technologies, our world is becoming more connected than ever. From smart factories to autonomous cars, next-generation mobile networks are the invisible backbone of modern life. However, this massive expansion comes with a major catch! It creates a much larger target for cybercriminals. Among the most dangerous threats are Distributed Denial of Service (DDoS) attacks, which overwhelm networks with massive floods of fake traffic to crash vital services. Defending against these attacks is traditionally tricky. Testing defense systems on live networks is incredibly risky because a false alarm or a heavy security test could accidentally shut down services for real users. On the other hand, training artificial intelligence (AI) to spot these threats usually relies on outdated or unrealistic data. Enter the “Network Digital Twin” To solve this dilemma, a team of researchers from the National Centre for Scientific Research “DEMOKRITOS” in Greece has developed a groundbreaking solution. They created a Network Digital Twin (NDT) – a perfect, real-time virtual clone of a physical mobile network. Think of it as an advanced digital flight simulator for cybersecurity. This virtual sandbox mirrors the exact layout, behavior and traffic patterns of the real network. Because it is completely separated from actual users, researchers can safely unleash severe cyberattacks inside the digital clone to see exactly how the network reacts, entirely risk-free. How the Breakthrough Works Using this virtual clone, the team simulated two destructive types of traffic-flooding attacks – one targeting connection backlogs and the other targeting data routing paths. They used the rich data generated by these safe simulations to train an advanced AI model. Because the digital twin is continuously synchronized with a real-world network, the AI learned from highly realistic, up-to-date information rather than old, synthetic datasets. Once the AI was fully trained in the virtual world, the researchers deployed it onto a real, physical 5G network testbed. The results were spectacular: The AI successfully detected and classified the cyberattacks with an astonishing 99% accuracy rate. Why this work Matters The novelty and importance of this research lie in its proactive, zero-risk approach to digital safety: Zero-Risk Testing: Security teams can safely emulate cutting-edge cyber threats without any risk of disrupting live, everyday communication services. Hyper-Realistic AI Training: By using a twin that dynamically updates alongside the real network, the AI is trained on incredibly accurate data, making it far more robust against evolving tactics. Bridging Virtual and Real Worlds: The study proves that an AI trained entirely in a digital sandbox can seamlessly step into the real world to protect physical infrastructure. By creating a safe, highly accurate environment to train the digital guardians of tomorrow, this research marks a massive step forward in ensuring our future 6G world remains safe, stable and uninterrupted. Publication Details Cyber defense framework for 5G/6G using a Network Digital Twin Authors: Ioannis Vasalos, Efstathios Zaragkas, Athina Vekraki, Maria Christopoulou, Michail Alexandros Kourtis, George Xilouris, Nikos Dimitriou MARE Partner: National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: With the rapid evolution of 5G and emerging 6G networks, ensuring security against DDoS threats remains a pressing challenge, particularly due to expanded attack surfaces across the edge–cloud continuum and heterogeneous edge devices. Traditional security mechanisms struggle to provide proactive, scalable, and low-risk detection and classification solutions in such highly dynamic environments. This paper proposes a Network Digital Twin (NDT)–driven framework for DDoS detection, analysis, and classification in 5G/6G networks, leveraging a synchronized digital twin for safe attack emulation and AI/ML-based anomaly detection. We implement and validate the framework on a real 5G testbed combined with an operational NDT platform, demonstrating that the NDT accurately reproduces network behavior under both normal and attack conditions and validating its efficacy for DT-driven, adaptive security in next-generation mobile systems.

27 May, 2026 / 0 Comments
read more

Security Sharing in a Network of Networks: PoC#11 in the MARE Project

Blog

Future digital services will not rely on a single, isolated network. Instead, 6G ecosystems will consist of many interconnected networks operated by different stakeholders – such as mobile operators, cloud providers, edge platforms, private enterprise networks and vertical industries. Together, these form what is often referred to as a “Network of Networks”. While this interconnection enables powerful new services and seamless connectivity, it also introduces significant security challenges. A weakness in one network can quickly affect others and isolated security mechanisms are no longer sufficient. PoC#11 will addresses this challenge by exploring how security information can be safely and effectively shared across multiple interconnected networks. Why Security Sharing is Essential in 6G In today’s networks, security monitoring and incident response are often handled within a single administrative domain. In future 6G environments, this approach becomes inadequate. Services may span several networks and attacks can propagate across network boundaries. For example, a threat detected in one operator’s network may be relevant to neighbouring networks or partner infrastructures. If this information is not shared in a timely and trustworthy manner, other networks will remain vulnerable. PoC#11 addresses this issue by exploring mechanisms that allow collaboration between networks, without compromising autonomy, privacy, or commercial boundaries. What does “Security Sharing” mean? Security sharing does not mean giving full access to internal systems. Instead, PoC#11 focuses on controlled exchange of relevant security insights, such as: Indicators of malicious activity, Threat alerts, Risk assessments, High-level situational awareness. The goal is to ensure that networks can learn from each other’s observations, improving collective resilience while maintaining local control. Challenges of Sharing Security Information Sharing security data across networks is not trivial. Different networks may use different technologies, policies and security tools. There are also concerns related to: Data confidentiality, Trust between stakeholders, Liability and responsibility, Compliance with regulations. PoC#11 will explore how these challenges can be addressed by defining clear interfaces, policies and trust models that regulate what information is shared, with whom and under what conditions. What PoC#11 will Demonstrate PoC#11 will demonstrate how security-related information can be exchanged between networks in a structured and controlled way. Instead of just raw data, networks can share processed and meaningful security signals that can be acted upon without revealing sensitive internal details. By correlating shared information with local observations, each network will be able to gain a more complete picture of ongoing threats. This will enable earlier detection of coordinated or large-scale attacks that might otherwise go unnoticed when networks operate in isolation. Supporting Coordinated Responses Another key aspect of PoC#11 is showing how shared security insights can support coordinated responses. When multiple networks are affected by similar threats, aligned mitigation actions can reduce overall impact and prevent attackers from simply moving from one network to another. Importantly, PoC#11 does not assume centralised control. Each network remains responsible for its own decisions, while benefiting from shared awareness and collective intelligence. Why this Matters for Future Services Many future services enabled by 6G – such as cross-border connectivity, smart transportation systems, industrial automation and emergency communications, depend on multiple networks working together seamlessly. Security weaknesses in any part of this chain can undermine service reliability and user trust. PoC#11 shows how security sharing can become a foundational capability for such services, enabling cooperation without sacrificing independence. A key Building block for Trustworthy 6G Ecosystems Within the MARE project, PoC#11 will highlight the importance of moving beyond siloed security approaches. By enabling networks to share relevant security information responsibly, it supports the creation of resilient, trustworthy and cooperative 6G ecosystems. As networks become more interconnected, security can no longer be addressed alone. PoC#11 demonstrates how collaboration, supported by clear governance and intelligent mechanisms, will be essential for protecting the digital infrastructure of the future.

24 May, 2026 / 0 Comments
read more

Secure Exposure of Network Capabilities in Future 6G Networks: PoC#10 in the MARE Project

Blog

Modern mobile networks are no longer closed systems used only for connectivity. In 5G and future 6G networks, operators increasingly expose selected network capabilities to external applications through standardised APIs (Application Programming Interfaces). This openness enables innovation to occur – applications can request network information, optimise performance, support smart mobility, or deliver new digital services specifically designed twardso user needs. However, opening up network capabilities also introduces new security and privacy risks. PoC#10 focuses on understanding these risks and demonstrating how future networks can expose capabilities securely, without compromising trust, reliability, or user data. Why Network Exposure Matters Network capability exposure allows third-party developers, vertical industries and service providers to interact directly with the network. For example, an application may request information about network conditions, subscribe to performance events, or trigger specific network behaviours. This creates exciting and innovative opportunities, however, it also increases the attack surface of the network. APIs become new entry points that attackers may exploit if these are not properly protected. PoC#10 investigates how these risks can be addressed in a structured and automated way. Key Threats Addressed in PoC#10 PoC#10 focuses on several realistic threat scenarios that arise when network capabilities are exposed. These include: Sensitive data leakage, where poorly protected APIs accidentally reveal confidential information such as subscriber data, network configurations, or operational logs. Unauthorised access, where attackers attempt to use exposed interfaces without proper permissions. Privilege escalation, where an application gains access to capabilities beyond what it is allowed to use. API abuse, including excessive or malicious requests that may disrupt network operations. These threats are particularly critical in future 6G environments, where networks are more dynamic, cloud-native and distributed across central and edge infrastructures. What PoC#10 will Demonstrate PoC#10 will demonstrate how exposed network capabilities can be protected through continuous monitoring, strong access control and intelligent analysis. Instead of relying on static rules alone, the PoC will show how network interactions can be observed in real time. Telemetry data, access logs and configuration changes can be continuously collected and analysed to identify suspicious behaviour early. This allows the network to detect misuse before it escalates into a serious incident. A key aspect of PoC#10 is enforcing who can access what and under which conditions. Applications and users will be authenticated and authorised using established identity and access management mechanisms. Communication with exposed APIs will be protected through encryption, ensuring that data cannot be easily intercepted or manipulated. Seeing the Network as a Whole One of the challenges in securing exposed network capabilities is understanding how different components, interfaces and services are connected. PoC#10 considers this, by correlating data from multiple sources and building a unified view of network interactions. By linking operational data, access policies and runtime behaviour, the system can identify inconsistencies, misconfigurations, or unexpected access patterns. This makes it easier to spot issues such as legacy interfaces that should no longer be exposed, or applications using capabilities in unexpected ways. Responding to Threats Automatically Detection by its own is not sufficient in highly dynamic networks. PoC#10 will also demonstrate how automated responses can be triggered when a security issue is identified. Depending on the situation, the network may: Restrict or revoke access to certain APIs, Enforce stricter policies, Generate alerts for operators, Adjust exposure rules dynamically. These actions will help protect against security incidents, containing them quickly and reducing the risk of service disruption or data leakage. Why this is Important for the Future As 6G networks become platforms for digital innovation, secure exposure of network capabilities will be essential. Without proper safeguards, openness could undermine trust in the network and limit adoption by industries and public services. PoC#10 will demonstrate how MARE contributes to building secure, transparent and controllable network exposure mechanisms. By combining monitoring, policy enforcement and intelligent analytics, future networks can remain open to innovation while staying resilient against misuse and attacks.

24 May, 2026 / 0 Comments
read more

Defending future Networks from DDoS Attacks at the Edge: PoC#9 in the MARE Project

Blog

As mobile networks evolve towards 6G, they are becoming more distributed, more open and more connected to the world around us. Edge devices – such as smartphones, IoT sensors, connected vehicles and local computing nodes, will play a crucial role in delivering low-latency services for smart cities, industry, healthcare, entertainment and other fields. However, this growing “edge” of the network also introduces new security challenges. PoC#9 focuses on one of the most serious and well-known cyber threats – that of Distributed Denial of Service (DDoS) attacks, specifically those launched from compromised edge devices – also referred to as X-Edge devices. Why DDoS Attacks are Changing in 6G Networks A DDoS attack works by overwhelming parts of a network with excessive traffic, making services slow, unreliable, or completely unavailable for legitimate users. In earlier network generations, these attacks often originated outside the network. In 5G and beyond, the situation is far more complex. In modern mobile networks, devices at the edge of the network are already authenticated and trusted by the network. If such devices are compromised or misused, they can generate malicious traffic from inside the system. This makes attacks harder to detect and block – especially when many devices act together while appearing to behave normally. PoC#9 addresses this challenge by studying how DDoS attacks can originate from large numbers of edge devices and how future networks can detect and respond to them effectively. What will PoC#9 Demonstrate? The PoC will explore a realistic scenario where compromised edge devices generate large volumes of traffic aimed at critical network components. These devices may: Send sudden traffic bursts, Repeatedly reconnect to the network, Generate abnormal service requests. Such behaviour can overload essential network functions responsible for handling user data and mobility. This can result in slow internet access, dropped connections, or complete service outages for everyday users. PoC#9 will demonstrate how these attacks impact both: The user plane, which carries data such as video streams or web traffic, The control plane, which manages network access, mobility and session setup. Detecting Abnormal Behaviour Early A key aspect of PoC#9 is showing how abnormal behaviour can be detected early, before a DDoS attack causes major disruption. The PoC uses advanced network analytics that continuously monitor how devices behave. In addition to looking for known attack signatures, the system also observes for patterns such as: Unusual traffic volumes, Unexpected mobility behaviour (such as frequent cell switching), Sudden spikes in signalling activity. By analysing these indicators across many devices at once, the network can identify suspicious groups of devices rather than treating each one in isolation. From Detection to Response Detection alone is not enough. PoC#9 will also demonstrate how the network can dynamically respond to an attack – once it is identified. Depending on the nature and severity of the threat, mitigation actions include: Limiting traffic rates from suspicious devices, Isolating compromised edge nodes, Protecting key network interfaces from overload, Continuously monitoring whether countermeasures are effective. It is important to take into account that these actions are designed to minimise disruption for legitimate users while containing the attack. Why this Matters As 6G networks move towards highly distributed architectures with massive numbers of connected devices, DDoS attacks from the edge are likely to become more frequent and more complex. PoC#9 will show how combining continuous monitoring, intelligent analytics and automated response mechanisms can help future networks remain resilient. By addressing DDoS threats at the edge, MARE contributes to building more reliable, trustworthy and secure mobile networks, capable of supporting the critical digital services that society will increasingly depend on.

24 May, 2026 / 0 Comments
read more

Double Identity – Defending the 6G Digital Twin from Cyber Attacks: PoC#8 in the MARE Project

Blog

The concept of a “Digital Twin” is rapidly becoming one of the most transformative technologies in the 6G era. By creating a real-time, virtual replica of a physical network, operators can test updates, predict failures and optimize performance without ever risking disruption to the actual service. It is the ultimate sandbox – a safe environment where the future can be rehearsed. But what if the sandbox itself becomes a trap? This is the important question addressed by Proof of Concept 8 (PoC#8) within the MARE project, titled “SNDT: Secure Network Digital Twin”. While Digital Twins are designed to protect the physical network from operational risks, PoC#8 investigates a new frontier of cyber threats: Attacks that target the Digital Twin itself to blind, mislead, or compromise the physical infrastructure it mirrors. The Risk: When the Mirror Lies A Network Digital Twin (NDT) relies on a constant, two-way stream of data. It ingests real-time telemetry from the physical network to stay accurate, and it sends configuration commands back to the physical network based on its simulations. This close synchronization between the two systems creates a unique vulnerability. If an attacker can compromise the Digital Twin, they don’t need to hack the physical network directly. They can launch a “man-in-the-middle” attack on the synchronization link, injecting false data to make the physical network look healthy when it is failing, or vice versa. Even more dangerously, they could manipulate the Digital Twin’s simulation logic, causing it to recommend harmful configuration changes – like turning off security protocols or overloading a server, which the physical network then executes. In this scenario, the Digital Twin evolves from a helpful tool into a “Trojan Horse” that carries out the attacker’s will. How PoC#8 Secures the Virtual Replica PoC#8 is developing a specialized security shield for this precise problem. It treats the Digital Twin as critical infrastructure that requires its own dedicated defense system. The solution will use MARE’s modular architecture to build a resilient synchronization channel between the physical and virtual worlds. Key innovations include: Synchronization Integrity Checks: The system will continuously monitor the data flowing between the physical network and its Digital Twin. Using advanced cryptographic verification, it will ensure that the telemetry feeding the Digital Twin has not been tampered with and that the commands coming back are authentic. Behavioral Anomaly Detection: By using AI-driven analysis, PoC#8 will be able to detect when the Digital Twin is behaving “out of character.” If the Digital Twin suddenly suggests a configuration change that contradicts historical safety patterns or physical reality, the system flags it as a potential compromise. Isolation Protocols: If a threat is detected, the PoC demonstrates how to instantly sever the control link. This “kill switch” will ensure that a compromised Digital Twin is cut off before it can push malicious commands to the live network, containing the damage to the virtual realm. Why this matters for 6G As we move toward Zero-Touch Service Management, where networks run themselves with minimal human oversight, the Digital Twin will be the brain behind many automated decisions. PoC#8 is vital because it ensures that this brain remains sane and secure. By validating the integrity of the Digital Twin, MARE is enabling operators to use this powerful technology with confidence. It guarantees that the Digital Twin remains what it was always meant to be – a safe simulation tool for innovation and network management, not a backdoor for destruction. Through PoC#8, MARE is proving that we can secure both the physical networks of the future, and the virtual worlds that will guide them.

24 May, 2026 / 0 Comments
read more

Trust, but Verify – Why 6G AI needs a background Check: PoC#7 in the MARE Project

Blog

Artificial Intelligence (AI) is set to be the engine of the 6G revolution. From optimizing network traffic to managing cybersecurity, we will be reliant on AI-driven systems. But as more of these intelligent algorithms enter our lives, an important question arises: Can we actually trust them? This is the focus of Proof of Concept 7 (PoC#7) within the MARE project, titled “Trustworthy Operation of AI”. While other security measures protect the network from hackers, PoC#7 protects the network from unreliable intelligence, ensuring that the AI models making life-or-death decisions are accurate, ethical and uncompromised. The Hidden Risk: When AI goes Rogue In a complex 6G environment, AI models are not static, but continuously learn and evolve. However, they are also vulnerable. An AI model can “drift” over time, losing accuracy as real-world conditions change, or it can be poisoned by malicious data during training. Even worse, an AI component might technically “work” but make decisions that are biased or violate privacy rules. If a network operator blindly trusts a compromised AI model, the consequences could be severe – from service outages to privacy breaches and beyond. The challenge is that traditional security tools scan for viruses, not for “bad decisions” or “model drift.” How PoC#7 builds a Trust Score PoC#7 introduces a Trust Scoring Engine that acts as a background check for every AI component in a network. It enforces a “Zero Trust” approach, meaning no AI is trusted by default. Instead, every model must earn its trust through continuous verification. The solution evaluates AI based on three critical pillars: Technical Robustness: Is the AI performing accurately? The system runs continuous tests to ensure the model isn’t making confident guesses about data it doesn’t understand. Data Integrity: Is the data fueling the AI clean? Using various techniques, the system verifies that the datasets used for training haven’t been secretly tampered with or corrupted. Operational Reliability: Is the model behaving normally? A data sanitation pipeline detects outliers and anomalous entries that could indicate a glitch or an attack. A “Credit Score” for AI All these checks are aggregated into a single AI Trustworthiness Score – which acts as a credit score for software. If an AI model’s score drops below a certain threshold – perhaps because its accuracy is fading or its data source looks suspicious, the MARE Security Plane takes immediate action. The Adaptive Security & Privacy Orchestrator (ASPO) can automatically quarantine the untrustworthy model, trigger a retraining process, or alert human operators. This “closes the loop,” ensuring that only high-quality, verified intelligence is allowed to steer the network. Why This Matters for the Future As 6G integrates into critical sectors like healthcare and autonomous transportation, we need more than just smart networks – we need accountable ones. PoC#7 provides the framework to measure and manage that accountability. By validating the integrity of AI across its entire lifecycle – from data ingestion to final decision, MARE is building a foundation where we can confidently use the power of AI, knowing that a sophisticated digital safety net is always watching.

24 May, 2026 / 0 Comments
read more

When Analytics go Rogue – Protecting the 6G from Poisoned Data – PoC#6 in the MARE Project

Blog

In the upcoming era of 6G networks, data isn’t just traffic – it is also intelligence. Future networks will rely on advanced systems like the Network Data Analytics Function (NWDAF) to automatically optimize performance, manage resources and predict faults. These systems will be used to make critical decisions based on the data they ingest. But what happens if the data lie? This is the challenge addressed by Proof of Concept 6 (PoC#6), titled ” Security effects of tampered data ingestion by NWDAF”. The PoC will investigate the threat of analytics poisoning, where attackers feed malicious data into a network’s analytics engine to manipulate its decisions from the inside out. The Danger: Poisoning the Well Imagine a navigation app that directs you into traffic jams because someone secretly fed it fake location reports. A similar risk can also exist for 6G networks.  The NWDAF is a system which collects events and analytics from various network elements to understand the state of the system. An attacker – whether that is an insider or an external malicious entity, could inject “poisoned” data into this data stream. By subtly altering performance metrics or fabricating event logs, they can trick the analytics engine into falsely identifying problems that don’t exist or ignoring threats which are real! This intervention could force the network to make harmful automated decisions, such as cutting off legitimate users or opening security holes for further attacks.  How PoC#6 will filter the Poison PoC#6 is building a Zero Touch Security Framework (ZTSF) designed to detect and filter out this corrupted data before it can do harm. The solution focuses on continuous verification of the analytics pipeline, ensuring that the “data fuel” entering the engine is pure and correct. The defense strategy involves three key layers: Telemetry Anomaly Detection: The system analyzes the normalized data streams entering the analytics function. It looks for statistical irregularities – which are metrics that don’t add up or patterns that deviate from normal operations, and generates a relevant security alert. Defense Orchestration: The generated security alert is mapped to a specific predefined CACAO-compliant mitigation Playbook. A dedicated playbook interpreter processes this workflow and formulates standardized, OpenC2-compliant execution commands. Automated Mitigation: Guided by the predefined playbook workflow, the interpreter can gather additional threat context to autonomously determine the optimal mitigation strategy. The resulting mitigation decisions are then enacted by triggering specific endpoints on a Security Enhanced NWDAF, neutralizing the data poisoning threat without human intervention. Ensuring Trustworthy Intelligence As 6G networks become more autonomous, the integrity of their data is essential. If we cannot trust the data, we cannot trust the network’s decisions. PoC#6 provides a critical safety mechanism for the AI-driven future of 6G. By proving that we can identify and reject manipulated analytics in real-time, MARE is ensuring that the network’s intelligence remains robust and accurate. This work guarantees that when 6G systems optimize your connection, they are acting on facts, not fiction – keeping the network efficient reliable, and secure.

24 May, 2026 / 0 Comments
read more

Securing the Intent: Protecting the Brain of 6G Networks – PoC#5 in the MARE Project

Blog

As we envision the future of 6G, the sheer complexity of the network – connecting billions of devices, from smart city sensors to autonomous vehicles, makes manual management of networks impossible. To address this complexity, researchers and network engineers introduced a revolutionary concept called Intent-Based Networking (IBN). Instead of engineers writing thousands of lines specifying how to configure the network devices, they simply provide a high-level “intent,” such as “ensure low latency for all emergency vehicles in this sector”. The network’s “brain” and “intelligence, then automatically figures out how to make that happen. But what if someone tries to trick or attack this system? This is the core challenge addressed by Proof of Concept 5 (PoC#5). The Vulnerability: When the Network is Misled An IBN relies on a constant stream of data, known as telemetry, to understand its current state. It looks at metrics like CPU usage, link data-rate and usage, latency and connection quality to decide if it is meeting the user’s needs and intent. The danger lies in data tampering. If an attacker can secretly alter these telemetry streams, they can feed the IBN system false information. For example, by making the network believe a certain path is congested when it is not, an attacker could force the system to redirect sensitive traffic through a compromised server. Because the network thinks it is following the right intent, this “poisoning” of the system’s knowledge base can be incredibly difficult to spot. It’s the digital equivalent of changing the road signs to force a self-driving car into a trap. How PoC#5 Guards the Network’s Intent PoC#5 is developing a specialized security framework to ensure that the data the network uses to make decisions is authentic and untampered. It does not just look at the network traffic – it looks at the integrity of the management system itself. The solution implemented in PoC#5 will use a series of DOTs to create a multi-layered defense: Knowledge Base Integrity: The PoC will also seek to protect the IBN knowledge base, protecting the system from potential internal threats which could cause disruption to network operations when erroneous intents – altered by an adversary, are applied in a network Authenticity Validation: The system will verify that telemetry data is coming from a legitimate, authorized source. Anomaly Detection for Telemetry: Using advanced AI, the system will monitor the telemetry streams themselves. If the data being reported doesn’t match the physical reality of the hardware, or is found to be anomalous, it will flag this as a potential tampering attempt. The Impact: A Network which can be Managed with Confidence The goal of PoC#5 is to make Intent-Based Networking as secure as it is smart. By validating the correctness of telemetry used in the decision-making process, coupled with protecting the IBN knowledge base, MARE ensures that when an operator sets an “intent,” the network carries it out correctly – void of any adversarial manipulation. This work is essential for the trustworthiness of 6G. As we move toward a world where critical infrastructure are managed by automated systems, we must be certain that the “intent” of human operators cannot be hijacked by malicious actors. Through PoC#5, MARE is ensuring that the intelligence of 6G remains a tool for progress, protected against the threats of the digital age.

24 May, 2026 / 0 Comments
read more

Posts pagination

1 2 Next
EUROPEAN PARTNERSHIP

Co-funded by the European Union

MARE project has received funding from the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union’s Horizon Europe research and innovation programme under Grant Agreement No 101191436

© MARE Project 2025

Privacy Policy

Cookies Policy

X-twitter Linkedin Youtube Mastodon
zenodoWhite