As we transition into the era of ultra-fast 5G and emerging 6G technologies, our world is becoming more connected than ever. From smart factories to autonomous cars, next-generation mobile networks are the invisible backbone of modern life.
However, this massive expansion comes with a major catch!
It creates a much larger target for cybercriminals.
Among the most dangerous threats are Distributed Denial of Service (DDoS) attacks, which overwhelm networks with massive floods of fake traffic to crash vital services.
Defending against these attacks is traditionally tricky. Testing defense systems on live networks is incredibly risky because a false alarm or a heavy security test could accidentally shut down services for real users. On the other hand, training artificial intelligence (AI) to spot these threats usually relies on outdated or unrealistic data.
Enter the "Network Digital Twin"
To solve this dilemma, a team of researchers from the National Centre for Scientific Research “DEMOKRITOS” in Greece has developed a groundbreaking solution. They created a Network Digital Twin (NDT) – a perfect, real-time virtual clone of a physical mobile network.
Think of it as an advanced digital flight simulator for cybersecurity. This virtual sandbox mirrors the exact layout, behavior and traffic patterns of the real network. Because it is completely separated from actual users, researchers can safely unleash severe cyberattacks inside the digital clone to see exactly how the network reacts, entirely risk-free.
How the Breakthrough Works
Using this virtual clone, the team simulated two destructive types of traffic-flooding attacks – one targeting connection backlogs and the other targeting data routing paths. They used the rich data generated by these safe simulations to train an advanced AI model. Because the digital twin is continuously synchronized with a real-world network, the AI learned from highly realistic, up-to-date information rather than old, synthetic datasets.
Once the AI was fully trained in the virtual world, the researchers deployed it onto a real, physical 5G network testbed. The results were spectacular:
The AI successfully detected and classified the cyberattacks with an astonishing 99% accuracy rate.
Why this work Matters
The novelty and importance of this research lie in its proactive, zero-risk approach to digital safety:
- Zero-Risk Testing: Security teams can safely emulate cutting-edge cyber threats without any risk of disrupting live, everyday communication services.
- Hyper-Realistic AI Training: By using a twin that dynamically updates alongside the real network, the AI is trained on incredibly accurate data, making it far more robust against evolving tactics.
- Bridging Virtual and Real Worlds: The study proves that an AI trained entirely in a digital sandbox can seamlessly step into the real world to protect physical infrastructure.
By creating a safe, highly accurate environment to train the digital guardians of tomorrow, this research marks a massive step forward in ensuring our future 6G world remains safe, stable and uninterrupted.
Publication Details
Cyber defense framework for 5G/6G using a Network Digital Twin
Authors: Ioannis Vasalos, Efstathios Zaragkas, Athina Vekraki, Maria Christopoulou, Michail Alexandros Kourtis, George Xilouris, Nikos Dimitriou
MARE Partner: National Centre For Scientific Research Demokritos (NCSRD)
Publication:
Abstract: With the rapid evolution of 5G and emerging 6G networks, ensuring security against DDoS threats remains a pressing challenge, particularly due to expanded attack surfaces across the edge–cloud continuum and heterogeneous edge devices. Traditional security mechanisms struggle to provide proactive, scalable, and low-risk detection and classification solutions in such highly dynamic environments. This paper proposes a Network Digital Twin (NDT)–driven framework for DDoS detection, analysis, and classification in 5G/6G networks, leveraging a synchronized digital twin for safe attack emulation and AI/ML-based anomaly detection. We implement and validate the framework on a real 5G testbed combined with an operational NDT platform, demonstrating that the NDT accurately reproduces network behavior under both normal and attack conditions and validating its efficacy for DT-driven, adaptive security in next-generation mobile systems.

