Double Identity – Defending the 6G Digital Twin from Cyber Attacks: PoC#8 in the MARE Project

The concept of a “Digital Twin” is rapidly becoming one of the most transformative technologies in the 6G era. By creating a real-time, virtual replica of a physical network, operators can test updates, predict failures and optimize performance without ever risking disruption to the actual service. It is the ultimate sandbox – a safe environment where the future can be rehearsed.

But what if the sandbox itself becomes a trap?

This is the important question addressed by Proof of Concept 8 (PoC#8) within the MARE project, titled “SNDT: Secure Network Digital Twin”. While Digital Twins are designed to protect the physical network from operational risks, PoC#8 investigates a new frontier of cyber threats:

Attacks that target the Digital Twin itself to blind, mislead, or compromise the physical infrastructure it mirrors.

The Risk: When the Mirror Lies

A Network Digital Twin (NDT) relies on a constant, two-way stream of data. It ingests real-time telemetry from the physical network to stay accurate, and it sends configuration commands back to the physical network based on its simulations. This close synchronization between the two systems creates a unique vulnerability.

If an attacker can compromise the Digital Twin, they don’t need to hack the physical network directly. They can launch a “man-in-the-middle” attack on the synchronization link, injecting false data to make the physical network look healthy when it is failing, or vice versa.

Even more dangerously, they could manipulate the Digital Twin’s simulation logic, causing it to recommend harmful configuration changes – like turning off security protocols or overloading a server, which the physical network then executes. In this scenario, the Digital Twin evolves from a helpful tool into a “Trojan Horse” that carries out the attacker’s will.

How PoC#8 Secures the Virtual Replica

PoC#8 is developing a specialized security shield for this precise problem. It treats the Digital Twin as critical infrastructure that requires its own dedicated defense system.

The solution will use MARE’s modular architecture to build a resilient synchronization channel between the physical and virtual worlds. Key innovations include:

  • Synchronization Integrity Checks: The system will continuously monitor the data flowing between the physical network and its Digital Twin. Using advanced cryptographic verification, it will ensure that the telemetry feeding the Digital Twin has not been tampered with and that the commands coming back are authentic.
  • Behavioral Anomaly Detection: By using AI-driven analysis, PoC#8 will be able to detect when the Digital Twin is behaving “out of character.” If the Digital Twin suddenly suggests a configuration change that contradicts historical safety patterns or physical reality, the system flags it as a potential compromise.
  • Isolation Protocols: If a threat is detected, the PoC demonstrates how to instantly sever the control link. This “kill switch” will ensure that a compromised Digital Twin is cut off before it can push malicious commands to the live network, containing the damage to the virtual realm.

Why this matters for 6G

As we move toward Zero-Touch Service Management, where networks run themselves with minimal human oversight, the Digital Twin will be the brain behind many automated decisions.

PoC#8 is vital because it ensures that this brain remains sane and secure. By validating the integrity of the Digital Twin, MARE is enabling operators to use this powerful technology with confidence. It guarantees that the Digital Twin remains what it was always meant to be – a safe simulation tool for innovation and network management, not a backdoor for destruction.

Through PoC#8, MARE is proving that we can secure both the physical networks of the future, and the virtual worlds that will guide them.