TY - GEN
T1 - A Zero-Touch O-RAN Framework for Federated Few-Shot IDS with LLM-Oracle Verification
AU - Albaseer, Abdullatif
AU - Hamood, Moqbel
AU - Al-Sabri, Raeed
AU - Abdallah, Mohamed
AU - Al-Fuqaha, Ala
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - This paper presents FFS-ORAN-IDS, a federated few-shot intrusion-detection framework that secures streaming traffic in Open Radio Access Networks (O-RAN) while respecting their stringent latency and resource constraints. The framework addresses the twin challenges of scarce attack labels and heterogeneous data, where naïve pseudo-label injection without sufficient confidence propagates errors, large-scale labeling of streaming traffic is impractical, and inherent uncertainty often requires costly human intervention. FFS-ORAN-IDS combines three coordinated x-functional blocks: a confidence-adaptive curriculum that releases pseudo-labels only when local TabTransformers are reliable, a diversity filter that retains the most informative uncertain packets, and a token-budgeted large-language-model (LLM) oracle that verifies the remaining hard samples. A mixed-integer optimization jointly governs curriculum pacing, sampling size, and Oracle LLM calls so that each federated round minimizes detection loss, propagation error, and LLM token cost under per-round resource caps. We train FFS-ORAN-IDS in two stages: an initial few-shot phase that fits the TabTransformer on the scarce ground-truth packets, followed by iterative rounds that refine the model with oracle-verified pseudo-labels. Experimental evaluation on the CIC-IDS 2018 benchmark shows that the proposed framework improves detection accuracy by 6%, reduces label-error propagation by 20%, and lowers energy consumption by 40% in the most label-constrained scenarios.
AB - This paper presents FFS-ORAN-IDS, a federated few-shot intrusion-detection framework that secures streaming traffic in Open Radio Access Networks (O-RAN) while respecting their stringent latency and resource constraints. The framework addresses the twin challenges of scarce attack labels and heterogeneous data, where naïve pseudo-label injection without sufficient confidence propagates errors, large-scale labeling of streaming traffic is impractical, and inherent uncertainty often requires costly human intervention. FFS-ORAN-IDS combines three coordinated x-functional blocks: a confidence-adaptive curriculum that releases pseudo-labels only when local TabTransformers are reliable, a diversity filter that retains the most informative uncertain packets, and a token-budgeted large-language-model (LLM) oracle that verifies the remaining hard samples. A mixed-integer optimization jointly governs curriculum pacing, sampling size, and Oracle LLM calls so that each federated round minimizes detection loss, propagation error, and LLM token cost under per-round resource caps. We train FFS-ORAN-IDS in two stages: an initial few-shot phase that fits the TabTransformer on the scarce ground-truth packets, followed by iterative rounds that refine the model with oracle-verified pseudo-labels. Experimental evaluation on the CIC-IDS 2018 benchmark shows that the proposed framework improves detection accuracy by 6%, reduces label-error propagation by 20%, and lowers energy consumption by 40% in the most label-constrained scenarios.
KW - Federated Learning
KW - Few-Shot Learning
KW - Intrusion Detection Systems
KW - Large Language Models
KW - O-RAN
UR - https://www.scopus.com/pages/publications/105036315644
U2 - 10.1109/GLOBECOM59602.2025.11432014
DO - 10.1109/GLOBECOM59602.2025.11432014
M3 - Conference contribution
AN - SCOPUS:105036315644
T3 - Proceedings - IEEE Global Communications Conference, GLOBECOM
SP - 3170
EP - 3175
BT - GLOBECOM 2025 - 2025 IEEE Global Communications Conference
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2025 IEEE Global Communications Conference, GLOBECOM 2025
Y2 - 8 December 2025 through 12 December 2025
ER -