Next Article in Journal
WeHMiT-Bench: Evaluating Large Language Models for Explainable Health Misinformation Detection in WeChat Article Titles
Previous Article in Journal
SFE-Mamba: A Spatial–Frequency Collaborative Enhancement Network for Object Detection in Snowy Road Scenes
Previous Article in Special Issue
Physical Key Extraction in Galvanic Coupling Communications: Reliability and Security Analysis
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks

1
Department of Computing, QA Higher Education, London EC1R 4TF, UK
2
School of Engineering, University of Greenwich, Chatham, Kent ME4 4TB, UK
3
Department of Cybersecurity, Technobeacon Consulting Limited, London SE3 8EJ, UK
4
Department of Computing, Business School, University of Law, Manchester M1 4HJ, UK
*
Author to whom correspondence should be addressed.
Information 2026, 17(10), 942; https://doi.org/10.3390/info17100942
Submission received: 25 August 2026 / Revised: 10 September 2026 / Accepted: 17 September 2026 / Published: 23 September 2026
(This article belongs to the Special Issue Advances in Wireless Communications Systems, 3rd Edition)

Abstract

The shift from fifth-generation (5G) systems to new architectures based on the sixth-generation (6G) paradigm changes network slicing from a semi-static resource partitioning model to a fully dynamic Slice-as-a-Service (SlaaS) model. This model is characterized by instantiating, scaling, migrating, and terminating slices using cloud-native orchestration frameworks, which offer considerable operational flexibility at the cost of increased attack surface. The current security design, which is mainly based on authentication-based security and conventional isolation design principles that are standardized by the 3rd Generation Partnership Project (3GPP), fails to consider the risks of runtime behavioral drift, cross-slice lateral movement, as well as metadata inference in a multi-tenant environment of SlaaS in 5G-Advanced and 6G networks. This paper introduces Trust-Aware Security Orchestration (TASO), a probabilistic, runtime-responsive security scheme for SlaaS in 5G-Advanced and 6G. The TASO models treat cut integrity as a posterior trust probability based on multidimensional telemetry flows. Trust is updated via Bayesian inference, and its temporal dynamics are studied using the Markov stability model to ensure convergence and bounded behavior. The structure also integrates entropy-based monitoring controls to reduce privacy leakage during telemetry collection. Large-scale multi-tenant simulations with NS-3 yield statistically significant results compared to baselines of statistically isolated and machine-learning-only. TASO has a 94.6% detection rate, 96.2% smaller isolation attacks, 93.6% smaller inference leaks, and SLA-conformant latency. The findings confirm that probabilistic trust modeling is a potential, theoretically sound security mechanism for dynamic slicing in future 6G systems.

Graphical Abstract

1. Introduction

The shift from fifth generation (5G) mobile networks to sixth-generation (6G) architecture is not just a slight enhancement in network bandwidth or latency, but an indication of the structural redefinition of how the network should be programmable and deliver services [1]. Although 5G introduced network slicing as a method of logical network partitioning, most early implementations treated slices as relatively fixed entities instantiated and controlled by predefined isolation policies. Conversely, 6G envisages a fully dynamic Slice-as-a-Service (SlaaS) model, in which slices are created, scaled, moved, and executed on the fly via cloud-native orchestration models [2]. This change simultaneously allows unprecedented flexibility for vertical industries and creates fundamental security challenges. In a static slicing environment, the isolation policy and access control are usually imposed at deployment time.
Nonetheless, in multi-tenant SaaS systems, slices are dynamically created using exposed Application Programming Interfaces (APIs) and automated lifecycle controllers [3]. This is an implicit trust flaw, based on the assumption that authenticated tenants are trusted throughout the entire slice lifecycle. This shortcoming is attributed to the use of perimeter-based or authentication-centric security frameworks, which do not work well in distributed, cloud-native, and software-defined architectures. In these situations, rogue tenants can exploit orchestration interfaces, move laterally across logical slice boundaries, or mount inference attacks using metadata correlation without violating conventional perimeter defenses [4,5]. The failure of perimeter security in 6G multi-tenant ecosystems is due to the lack of a network entry point as the attack surface. Rather, vulnerabilities occur in the orchestration pipeline, virtual network functions (VNFs), and control-plane signaling [6].
Zero-trust systems apply the first method, which is a partial solution to these problems by ensuring that authentication and validation occur strictly at session initiation [7]. Nevertheless, they do not necessarily have runtime adaptive or mathematically based trust evaluation programs. In the absence of constant recalibration of trust, security systems are unable to tell the difference between innocent behavioral drift and malicious compromise. To address these limitations, this paper introduces the Trust-Aware Security Orchestration (TASO) framework, a mathematically rigorous, runtime-adaptive security architecture for SlaaS environments [8,9]. TASO models build trust as an ever-changing probabilistic variable based on multidimensional streams of telemetry, such as behavioral traffic characteristics, control-plane exchanges, and data-plane adherence indicators [10,11,12]. Bayesian inference is used to update trust values; Markov transition modeling is used to stabilize these values and incorporates these values in decisions regarding adaptive orchestration [13,14,15]. This study makes three main contributions: (1) A continuous probabilistic trust model that treats slice integrity as a posterior inference problem with Bayesian updating from multidimensional telemetry. (2) Markovian stability analysis providing formal convergence guarantees for trust evolution under bounded transition probabilities. (3) An integrated privacy-enhancing orchestration scheme using entropy-based leakage minimization, ensuring monitoring does not breach confidentiality. The cumulative effect is a complete theoretical and experimental foundation for secure SlaaS in 6G systems.

2. Literature Review

2.1. Standardization-Driven Security in Network Slicing

The development of network slicing security has mainly occurred in the context proposed by the 3rd Generation Partnership Project (3GPP). Release 15 formalized slice identifiers (S-NSSAI) and a logical separation mechanism in the 5G core architecture. Later versions (16-18) added capabilities to the service-based architecture (SBA), network exposure features, and zero-touch management features [16]. 3GPP Release 18 introduced enhanced slice isolation for roaming scenarios and service-based interface security enhancements (TS 33.501). Release 19 (under development) addresses zero-trust principles for network exposure functions and AI-native security analytics. However, none of these standardization efforts incorporate probabilistic trust modeling with formal convergence guarantees, which distinguishes TASO from current 3GPP approaches. These developments enhanced lifecycle automation and programmability while maintaining a security philosophy based on authentication, authorization, and static isolation. Isolation is generally applied in the standardized architecture at three levels: control-plane separation, user-plane resource allocation, and policy enforcement via network functions such as Access and Mobility Management Function (AMF), Session Management Function (SMF), and User Plane Function (UPF). These mechanisms are logical separation guarantees that apply under nominal conditions but assume that authenticated tenants and slice controllers are benign throughout the slice lifecycle [17]. This is not true in highly dynamic Slice-as-a-Service (SlaaS) environments, where APIs expose orchestration functions to external parties and slice configurations change in real time. In addition, the 3GPP specifications emphasize compliance and protection of the interfaces more than runtime behavioral integrity. Security is considered a collection of discrete protections rather than a continuous inference problem. It follows that there is currently no formal development of trust in standardization that supports formal modeling of trust evolution, probabilistic decision-making in the presence of uncertainty, and convergence guarantees under adversarial dynamics.

2.2. Virtualization and Cloud-Native Security in NFV/SDN Environments

The implementation of Network Function Virtualization (NFV) and Software-Defined Networking (SDN) placed new attacker access points on both hypervisors and virtual switches and centralized controllers. Initial studies focused on isolation reinforcement, secure VNF implementation, and hardening the controller [18]. Microsegmentation, role-based access control, and encrypted service chaining are methods proposed to address the problem of cross-tenant interference. Nonetheless, such methods are largely dependent on policing and the deterministic assessment of rules. They do not directly model the uncertainty of behavior or changing compromise probability [19]. Moreover, security modules tend to be implemented as separate units, loosely bound to orchestration systems. This distance inhibits responsiveness since orchestration decisions are hardly conditioned on quantified trust measures. Cloud-native orchestration models (e.g., service meshes built on Kubernetes) only make the situation more challenging, given concepts such as dynamic scaling, container mobility, and the temporary nature of microservices [18]. Although this type of architecture enhances elasticity and resilience, it increases temporal variability. The existence of static isolation mechanisms can thus be misleading, treating benign scaling events as anomalies, or failing to detect gradual adversarial drift.

2.3. Zero-Trust Architectures in Telecom and Cloud Systems

Cloud systems in enterprises, as well as telecom networks, have attracted attention for their adoption of zero-trust security paradigms. The main idea of never trusting and always verifying eliminates reliance on network boundaries [19]. In practice, zero-trust arrangements implement identity validation, device posture validation, and least-privilege access control for each interaction. Although this is conceptually consistent with dynamic slicing, current zero-trust implementations are mainly policy-based. Trust is generally binary and session-oriented as opposed to being recalibrated continuously. Checking is done at the point of connection or at a checkpoint, and there is no probabilistic accumulation of behavioral evidence [19]. As well, formal stochastic stability analysis is rarely used in zero-trust frameworks. In the absence of convergence guarantees, aggressive re-verification policies can be accompanied by oscillatory enforcement behavior, thereby increasing latency and compromising service-level agreement (SLA) compliance [20]. The lack of mathematically grounded trust dynamics constrains their use in latency-conscious 6G slices, especially in Ultra-Reliable Low-Latency Communication (URLLC) services.

2.4. AI-Based Intrusion and Anomaly Detection for Sliced Networks

In SDN and NFV ecosystems, artificial intelligence has been widely used to detect intrusions due to the presence of complex and dynamic attack surfaces resulting from the use of virtualization and programmable control planes. Various methods have been proposed, such as Gaussian Mixture Models (GMM) for probabilistic clustering of traffic behaviors, deep autoencoders, unsupervised anomaly detection via reconstruction error analysis, recurrent neural networks, which model temporal dependencies in traffic sequences, and graph neural networks, which make use of topology-aware threat detection in distributed network settings [21]. Such methods usually show high classification performance in labeled or semi-supervised training scenarios and can detect minute variations in baseline traffic patterns [22]. Although most of them have been proven effective in improving detection accuracy, their current studies do not analyze these models in the context of orchestration and lifecycle management processes. Anomaly scores are also typically not considered quantitative inputs to the adaptive control mechanisms, but are treated individually as alerts. As a result, detection systems remain poorly integrated with slice management structures and have little impact on real-time mitigation and policy enforcement. Two fundamental constraints exist in the present research.
To begin with, the output of anomaly detection is hardly ever converted into posterior probabilistic trust measures that have temporal memory [23]. The majority of models produce instantaneous anomaly scores without recursive accumulation of evidence, thereby failing to account for the stochastic evolution of slice integrity over time. Second, there is a lack of stability analysis. Under heavy, burst, or highly variable traffic conditions, machine learning models can yield varying outputs, but their long-term behavior is not analytically defined or formally specified [24]. In addition, many experimental analyses are based on synthetic or static datasets that fail to reflect the realistic activities of multi-tenant slices, including instantiation, scaling, migration, and termination events. This limits the ecological plausibility of reported outcomes, especially in dynamic Slice-as-a-Service (SlaaS) scenarios envisioned for 6G networks [21].

2.5. Trust and Reputation Models in Distributed Systems

Trust modeling is not new to distributed computing, peer-to-peer networks, and cloud service marketplaces, where it has been applied to assess the reliability and behavior of the participating entities. Different methods have been suggested; among them are Bayesian reputation systems whose beliefs are updated on the basis of observed interactions, weighted aggregation schemes, and composite trust scores which are formed based on multisource feedback, and reinforcement learning models which dynamically change trust policies based on feedback from the environment [25]. The approaches offer practical tools for managing uncertainty and adaptive decision-making within a decentralized setting. In particular, Bayesian trust models provide a principled probabilistic interpretation of trust and enable systematic belief updating in the face of uncertainty. They are, however, usually applied to transaction- or interaction-level reputation systems as opposed to continuous and high-frequency streams of telemetry that are produced in current virtualized network infrastructures. Trust adaptation based on reinforcement learning offers the concept of dynamic policy optimization but lacks convergence guarantees in non-stationary or adversarial settings and is often unstable [26]. Adaptive trust policies without formal stability analysis inevitably wander or become erratic in response to changing workload conditions. In the telecom network slicing setting, the field of trust research is still rather fragmented and application-specific. Some works propose slice-level trust metrics based on service-level agreement (SLA) compliance metrics, while others investigate trust management for cross-domain federation between two or more operators [27].
Nevertheless, these are not usually combined with multidimensional telemetry fusion between control-plane and data-plane signals, nor with Markov-based stability modeling to guarantee limited temporal development. Also, entropy-based privacy demands are not typically addressed in trust computation, and trust measures are not typically directly linked with orchestration decision engines that handle slice lifecycle management. Consequently, trust is often viewed as an inactive observational object rather than an active control variable embedded in dynamic orchestration and enforcement mechanisms.
Telemetry collection cannot be done without anomaly detection, but it also poses the risk of metadata exposure [28]. Traffic patterns, resource allocation metrics, and control-plane signaling in a multi-tenant slicing environment may disclose sensitive operational features. The existing literature on privacy-preserving monitoring focuses on differential privacy, traffic aggregation, and an encrypted telemetry pipeline. Although these techniques can be used to reduce leakage of raw data, they can reduce the sensitivity of detection or result in computational overhead. Notably, the majority of privacy-preserving methods view confidentiality and security as two distinct goals [28]. Few papers examine the trade-off between observability and resistance to inference by use of formal information-theoretic measures like conditional entropy. This trade-off is becoming increasingly important as the solution moves toward fine-grained, real-time monitoring with 6G.
Federated learning (FL) has emerged as a privacy-preserving paradigm for distributed anomaly detection, enabling multiple network domains to collaboratively train ML models without sharing raw telemetry data. Recent works have explored FL for intrusion detection in sliced networks, where local models are trained on each domain’s data, and only model updates are aggregated at a central server [16]. This aligns conceptually with TASO’s privacy-preserving objective, as both approaches avoid exposing sensitive operational metadata. However, existing FL-based approaches lack formal trust modeling with convergence guarantees, making integration of FL with TASO a promising direction for future work.

2.6. Stability and Control-Theoretic Perspectives in Network Security

Congestion control, admission control, and self-optimizing networks have been subjected to control-theoretic techniques [29]. Nevertheless, very little of security enforcement has been formalized as a stochastic control problem with provable convergence properties. Stochastic processes and Markov chains provide a means to study the long-term behavior of the system under probabilistic transitions [29]. However, they have limited use for evolving trust at the slice level. The majority of security frameworks are threshold-based triggering models that do not consider steady-state distributions or limited oscillatory conditions [30]. A combination of probabilistic inference and Markov stability analysis provides a solid basis for guaranteeing that adaptive enforcement will not destabilize latency-sensitive services. This kind of integration is not widely available in the slicing security literature.

2.7. System Model and Threat Assumptions

It is assumed that the multi-tenant 6G core network consists of virtualized network functions, such as the Access and Mobility Management Function (AMF), the Session Management Function (SMF), and the User Plane Function (UPF) [31]. These functions can be run on distributed cloud-native platforms, coordinated using orchestration platforms such as service meshes built on Kubernetes. Slices Si are configurable, instantiated, and controlled via the service-based interfaces exposed. The adversary model assumes logical-level compromise. Bad tenants can use exposed APIs, generate uncharacteristic control-plane traffic, make lateral movements across slice boundaries, or perform privacy inference by examining metadata [32]. Attacks on physical infrastructure and on the hypervisor level are out of scope. It is assumed that the hardware substrate and the virtualization layer are unreliable, and the threat model is based on weaknesses in logical slice isolation and orchestration. Based on these assumptions, the task is to identify and prevent runtime compromise without breaking SLA requirements or compromising performance-critical slices such as URLLC services [31].

2.8. Synthesis and Research Gap

As indicated by the existing literature, there are several structural constraints in current network slicing security methods [33]. To start with, security controls are still mostly static or policy-based and are not dynamically updated to changing behavioral states. These mechanisms are good in terms of the capability of isolating the baseline, but are not responsive to small adversarial drift or changes in workload. Second, despite the promising outcomes of artificial intelligence-based methods of detection of anomalous traffic patterns, they are not often pre-integrated into orchestration feedback loops. Detection outputs, in the vast majority of cases, are independent alerts and do not control the slice lifecycle decision (e.g., scaling, migration, or quarantine). Third, current trust modeling methods lack formal stochastic convergence properties. Although heuristic scoring and dynamically updating trust are common, little work has been done to provide a rigorous mathematical analysis that guarantees bounded temporal behavior or steady-state stability in the presence of non-zero compromise and recovery probabilities. This lack of analytical foundation raises concerns about reliability in very dynamic environments in the long term. Fourth, privacy-conscious telemetry systems are often considered independently of security enforcement, and thus tend to be architecturally fragmented, with monitoring confidentiality and threat mitigation optimized independently of each other rather than jointly.
Lastly, there are still a few large-scale, statistically significant experimental assessments of real Slice-as-a-Service (SlaaS) environments with a large number of tenants. There are numerous studies based on small datasets or small-scale simulations that fail to model the full lifecycle dynamics of the slice. Altogether, these restrictions highlight the lack of a standardized framework which characterizes slice security as a probabilistic, evolving control problem supported by formal stability analysis and built-in privacy assurance. Recent slice trust management schemes include: (i) Federated trust aggregation using weighted voting without stability analysis; (ii) Reinforcement-learning-based trust lacking convergence guarantees; and (iii) Blockchain-anchored trust with high latency overhead. Unlike these, TASO uniquely combines Bayesian inference, Markov stability analysis, entropy-based privacy preservation, and SLA-aware enforcement in a unified mathematical framework.

3. TASO Framework: Probabilistic Trust Modeling, Stability Analysis, and Orchestration Design

3.1. Continuous Probabilistic Trust Modeling

Continuous Probabilistic Trust Modeling defines slice trust as a posterior probability updated via Bayesian inference, allowing security to be treated as a dynamic inference problem rather than a static rule. Trust is represented as a posterior probability, which is the likelihood that a slice will remain intact based on observed telemetry [34]. In the case of slice Si, the trust at time t is:
Ti(t) = P (Secure|O1:t)
The process of updating trust as time goes on, using Bayesian updating, is as follows:
T i t = P ( O t | S e c u r e )   T i   ( t − 1 ) P ( O t | S e c u r e )   T i   t − 1 + P ( O t | C o m p r o m i s e d i ) ( 1 − T i t − 1 )
The likelihood terms are parameterized as log-likelihood estimates derived from Gaussian Mixture Models (GMMs), where each feature dimension is modeled independently with a diagonal covariance matrix fitted using expectation-maximization over a baseline telemetry window of 300 s [35]. The GMM likelihood estimation uses 300 s of baseline telemetry per slice type, with 5 mixture components, diagonal covariance matrices, and an expectation-maximization convergence threshold of 1 × 10−4. Training data comprises 70% baseline traffic, 15% validation, and 15% test, stratified by slice type. This formulation treats trust as dynamic, representing cumulative evidence rather than fixed configuration states. The summary of telemetry characteristics is given in Table 1 below.
Prior to analysis, all telemetry features are normalized using z-score standardization (zero mean, unit variance) computed from a sliding window of the most recent 600 samples to ensure scale invariance across heterogeneous slice types.

3.2. Markov Trust Stability Analysis

Markov Trust Stability Analysis models trust evolution as a two-state Markov chain to guarantee convergence to a stationary distribution and prevent oscillatory enforcement. To study the temporal behavior, slice states are represented as a two-state Markov chain whose transition matrix is:
P = 1   − ∈     ∈ γ       1 − γ
where ϵ represents the probability of compromise and γ represents the recovery probability.
The trust thresholds τ_low and τ_high defined in Section 3.5 directly map to the Markov chain states: Ti(t) < τ_low corresponds to the ‘Compromised’ state, Ti(t) > τ_high corresponds to the ‘Secure’ state, and τ_low ≤ Ti(t) ≤ τ_high represents the transitional region with state probability proportional to distance from each boundary. The convergence condition in Equation (3) is corrected to: lim(t → ∞) T(t) = π.
Trust evolves according to:
T(t + 1) = T(t) P
When 0 < ε < 1 and 0 < γ < 1, the chain is irreducible and aperiodic, thus ensuring that it converges to a stationary distribution:
π = γ ∈ +   γ , ∈ ∈ +   γ
The outcome ensures limited trust dynamics and removes oscillatory instability, an important feature of runtime orchestration [36].

3.3. AI-Assisted Risk Analysis

AI-Assisted Risk Analysis uses unsupervised models like autoencoders to convert telemetry into anomaly scores that directly inform trust updates. Unsupervised mechanisms of anomaly detection are incorporated with risk detection. Telemetry-derived feature vectors are either processed by Gaussian Mixture Models or autoencoders [37,38]. The amount of anomaly is measured by reconstruction error or likelihood divergence:
A i t = | | χ t − χ ^ t | | 2
where χ t represents observed features and χ ^ t reconstructed outputs; these anomaly scores directly affect posterior trust updating, and thus, subtle adversarial drift is easily identified.

3.4. Privacy-by-Design Orchestration

Privacy-by-Design Orchestration applies an entropy-based constraint to telemetry collection to minimize metadata leakage while maintaining detection accuracy. Surveillance can be a way to leak information about operations. To avoid revealing confidential metadata, TASO implements an entropy-based privacy constraint designed to ensure that telemetry collection does not leak it. The amount of privacy leakage is the conditional entropy:
Leakage = H (Sensitive|Observed Metadata)
Privacy-by-Design Orchestration minimizes metadata leakage via constrained telemetry granularity. Monitoring granularity g ∈ {1,2,4,8,16} represents the aggregation window size in seconds. The entropy constraint is formalized as: maximize H(Observed Metadata) subject to Detection Accuracy ≥ 0.90 × baseline. Trust states map to granularity as: Ti(t) > τ_high → g = 16 (coarse), τ_low ≤ Ti(t) ≤ τ_high → g = 4 (medium), and Ti(t) < τ_low → g = 1 (fine-grained). Entropy threshold θ_H = 0.75 × maximum conditional entropy, ensuring inference risk remains bounded while preserving detection sensitivity [39,40].

3.5. Adaptive Policy Enforcement

Adaptive Policy Enforcement maps trust values to orchestration actions such as quarantine or fast-path processing, subject to SLA constraints. Trust values directly determine orchestration actions. Trust is divided into three areas, bounded by the logarithmic thresholds τ_low and τ_high. The low and high trust thresholds (τ_low and τ_high) are determined using a grid search over the validation set to maximize the F1-score, followed by a calibration step that enforces a minimum separation of 0.3 between τ_low and τ_high to prevent policy oscillation. When Ti(t) < τ_low, a slice goes into quarantine mode and causes strict isolation and deep packet inspection. In case of trust within the thresholds, monitoring continues on the baseline [41,42]. When Ti (t) > τ, high-speed, fast-path processing decreases monitoring overhead. The SLA requirements restrict security actions. For URLLC slices, latency should be less than 1 ms. Thus, SLA-aware optimization is added to the policy modification:
min Security Risk(Pi) s.t. Latency I ≤ S LAi
This statement will ensure that improved security does not breach service guarantees.

3.6. Summary of the TASO Workflow

TheTrust-Aware Security Orchestration (TASO) framework is a closed-loop secu-rity-control system that combines telemetry analysis, probabilistic trust estimation, and adaptive orchestration. The workflow consists of 6 consecutive steps: telemetry collec-tion, anomaly scoring, Bayesian trust update, Markov stability check, adaptive policy enforcement, orchestration action. The TASO workflow is shown in Figure 1.
Behavioral traffic, control-plane signaling, SLA monitoring, and data-plane observations are all collected through telemetry. The autoencoder reconstruction error and Gaussian Mixture Model likelihoods are combined to quantify the behavioral deviation in the anomaly-detection module, which is normalized and processed. The resulting evidence is used to update the posterior probability of slice integrity with the most recent observation and historical trust information, and is used by the Bayesian trust model.
An updated trust state is then analyzed using a two-state Markov model in order to determine temporal stability and transitions between trust and distrust states. Depending on the level of trust that is established, the TASO will apply an adaptive security policy, from baseline monitoring to quarantine to deep packet inspection. The policy selected is then enforced via the orchestration layer, with the resulting operational behavior providing the new telemetry for the next control cycle. This feedback loop allows TASO to adapt the security level continuously while ensuring service levels are met and trusted.

4. Results

The AI-based anomaly detector uses a deep autoencoder architecture with three hidden layers (128, 64, 32 neurons) and ReLU activations, trained for 100 epochs with a batch size of 64 and a learning rate of 0.001 using the Adam optimizer. The dataset was partitioned into 70% training, 15% validation, and 15% test sets, with stratification applied to preserve attack label distributions across splits. The suggested Trust-Aware Security Orchestration (TASO) framework was tested and appraised through a comprehensive simulation campaign run with NS-3 (v3.38) and its built-in 5G NR modules. The evaluation also aimed to test the validation of detection performance, isolation robustness, privacy preservation, convergence stability, and scalability, as well as the overhead of running under realistic multi-tenant slicing conditions. All experiments were conducted on a 3600 s simulated horizon, with 30 independent Monte Carlo replicates to provide statistical reliability. The confidence intervals were calculated at the 95 percent level (Table 2).
The network topology consists of a star configuration with one central orchestration node connected to 10 edge nodes, each serving 5–50 slices. eMBB slices are simulated with ON/OFF Pareto traffic (shape = 1.5, mean ON duration = 500 ms), URLLC slices use constant bit rate traffic (1 Mbps, 1 ms inter-arrival) with periodic deterministic patterns, and mMTC slices employ a Poisson arrival process (λ = 100 events/s) with small packet sizes (64–128 bytes). Each slice type is implemented in NS-3 using the 5G NR module with dedicated radio bearers, QoS flows, and configurable scheduling priorities. Figure 2 below presents the NS-3 simulation topology.
Deployment follows a distributed cloud-native model with Kubernetes-based service meshes. Traffic generation uses a hybrid model: constant bit rate for URLLC, ON/OFF Pareto distribution (shape = 1.5) for eMBB, and a Poisson process (λ = 100 events/s) for mMTC, with all models calibrated to 3GPP TR 38.901 specifications. The simulated environment considered three exemplary types of slices: URLLC that represented mission-critical healthcare traffic, Enhanced Mobile Broadband (eMBB) that represented high-throughput multimedia service, and Massive Machine-Type Communication (mMTC) that represented a large-scale Internet of Things (IoT) telemetry. They tested the behavior of scalability by using 50 to 500 active slices. This dataset consisted of 120,000 slice lifecycle events and 15,000 labeled attack events spread across cross-slice lateral movement, orchestration API abuse, resource exhaustion, and metadata inference attacks.

4.1. Detection Performance

The detection performance was compared between TASO and three baselines, which were: a machine learning-based anomaly detector without trust feedback (ML-only), static slice isolation (SSI), and a zero-trust enforcement mechanism that is not dynamic.
The zero-trust baseline implements per-session re-authentication with a 30 s token refresh interval, role-based access control with least-privilege policies, and micro-segmentation via network policies enforced at the orchestration layer. Core parameters include: authentication timeout = 5 s, maximum session retries = 3, and policy evaluation frequency = 10 s. Cross-slice lateral movement attacks follow a random-walk path model with 5 intermediate hop transitions. Metadata inference attacks use 12-dimensional feature vectors (traffic rate, packet size variance, inter-arrival time, control-plane message frequency, and 8 resource utilization metrics). Attack intensity is parameterized as λ ∈ {0.1, 0.3, 0.5, 0.7, 0.9}, representing the fraction of compromised slices, injected in 60 s bursts with 120 s inter-burst intervals.
The accuracy of detection is defined as:
A c c u r a c y =   T P + T N T P + T P + F P + F N
TP, TN, FP, and FN are true positives, true negatives, false positives, and false negatives, respectively. The overall detection accuracy of the proposed framework was 94.6%, with a true positive rate of 0.93 and a false positive rate of 0.04. Conversely, the baseline of the static slice isolation was 81.2%, and ML-alone was 89.1%. Receiver Operating Characteristic (ROC) analysis also performs better as shown in Figure 3.
TASO obtained an Area Under the Curve (AUC) of 0.97, compared to 0.91 for ML-only and 0.84 for SSI. Probabilistic trust updates greatly reduced false positives, especially with bursty traffic, where statically modeled false negatives are more likely to classify spikes in legitimate workload as anomalies. It is possible that these improvements can be explained by the recursive Bayesian updating mechanism, which accounts for temporal evidence accumulation rather than the anomaly signals present at the moment.

4.2. Isolation Robustness

Isolation breach rate (IBR) is used to determine the rate of cross-slice contamination events in slices:
I B R = B r e a c h e d   S l i c e s T o t a l   S l i c e s
The base static isolation mechanism had a breach rate of 17.8% during an attack. TASO, on the other hand, decreased the breach rate to 0.68, corresponding to a relative decrease of 96.2%. The massive enhancement is a result of dynamic trust-based isolation escalation. Blowout. This happens when the posterior trust is so low that stronger motion towards isolation and deep inspection is employed in advance, so that by the time full compromise propagation occurs, the motion has not reached lateral. The temporal analysis shows that the majority of attempts to breach were contained within 1.42 s of anomaly detection, indicating a quick adaptive response.

4.3. Privacy Preservation

Conditional entropy was used to measure the privacy leakage.
Leakage = H (Sensitive|Observed Metadata)
A smaller value of conditional entropy indicates greater inference success by an adversary. Inference attacks were successful on 22.1% of the attempts in the baseline systems. TASO decreased this ratio to 1.4%, which was an increase of 93.6%. Entropy analysis shows that adaptive monitoring granularity is an effective way to increase the uncertainty of enemies without reducing detection. TASO manages exposure of sensitive operational metadata by adjusting telemetry resolution based on the trust state.

4.4. Latency and Performance Overhead

The performance overhead was measured among slice types (Table 3). The average latency increase in all slices was 13.6% 0.19. For URLLC slices that require sub-millisecond latency, the extra delay was 0.14 ms on average and within the SLA limits. There was an increment in the CPU load by 9.3% and memory overhead by 6.7%. These overheads are tolerable in edge-cloud 6G applications and indicate that probabilistic trust modeling is not prohibitive in terms of computational cost. Regression analysis yielded R2 = 0.93, confirming logarithmic scalability.

4.5. Statistical Validation

In order to achieve scientific rigor, hypothesis testing was done through the application of two-tailed independent t-tests, where the significance level was α = 0.05. All performance metrics recorded p-values below 0.001, indicating statistically significant improvements. Cohen’s d was used to assess the effect size. The Cohen’s d of 1.84 observed in detection accuracy is very large in practical effect size. Detection improvement confidence intervals ranged from 11.9 percent to 14.8 percent, indicating low variation across Monte Carlo repetitions. During model training, 10-fold cross-validation was used to avoid overfitting. The variance between folds was below 2.3, indicating strong generalization (Table 4).

4.6. Sensitivity and Ablation Analysis

The effects of the trust memory parameter α, the λ attack intensity, and the τ low and τ high threshold values were analyzed using a sensitivity analysis. Anti-optimal values of α enhanced responsiveness but increased volatility. The best stability-performance trade-off was at α = 0.72. A threshold value below 0.3 led to false positives, and above 0.6, the mitigation response was delayed. Ablation experiments demonstrate that eliminating Bayesian updating reduces detection accuracy to 90.2%. The elimination of adaptive policy enforcement increases the breach rate to 5.8%. These findings confirm that both probabilistic modeling and dynamic enforcement Are important elements. Sensitivity analysis of trust memory parameter α (0.1–0.9) shows detection accuracy (peak at α = 0.72) and false positive rate (minimum at α = 0.68) as shown in Figure 4.

4.7. Trust Convergence and Stability

The measurement of empirical convergence time was:
τ = m i n   t   : T i t − π   | <   ϵ
The average convergence time between simulations was 1.42 s. Under bounded transition probabilities, trust trajectories have monotonic convergence to the stationary distribution and confirm theoretical Markov analysis. No oscillatory instability was observed even under adversarial burst injection conditions. Trust convergence trajectories for 100 randomly selected slices over 3600 s, demonstrating monotonic convergence to the stationary distribution π with mean convergence time 1.42 s (95% CI: 1.38–1.46 s) as shown in Figure 5.

5. Discussion

The experimental results provide detailed evidence that probabilistic trust-conscious orchestration significantly enhances the effectiveness and security of operations in dynamic Slice-as-a-Service (SlaaS) environments [42]. The obtained detection rate of 94.6% and AUC of 0.97 indicate not only high classification accuracy but also high repeatability of the benign and malicious behavioral distributions across varying traffic conditions. Notably, these benefits are not limited to the superiority of anomaly detection, but also to the incorporation of Bayesian trust updating into the orchestration loop. The framework converts instantaneous anomaly scores into temporally consistent posterior trust estimates by recursively applying historical telemetry evidence. This accumulation mechanism is probabilistic to address the volatility common in standalone machine learning detectors, especially when the load is bursty or highly elastic, as in multi-tenant slicing [43,44]. Consequently, the number of false positives is kept under control, even in legitimate cases of scaling, migration, or traffic overload, thereby keeping unwarranted enforcement escalation to the minimum necessary and maintaining the continuity of service delivery. It is shown that the rate of isolation breaches decreases by a factor of 14 when trust-sensitive enforcement is applied; hence, 17.8% with default isolation and 0.68% with trust-sensitive enforcement have been reported. Instead of responding to clear cases of policy infractions, the structure will recognize the gradual patterns of trust degradation that point to the presence of adversarial drift. This allows isolation or monitoring to be performed preemptively before compromise propagation across logical slice boundaries. The experimental results for the mitigation response time of 1.42 s are close to the convergence response of the Markov stability model, supporting the theoretical homogeneity of the proposed design. The fact that no oscillatory patterns of rule enforcement can occur also verifies that decisions concerning adaptive control are constrained and stable over time [45,46].
The framework reduces the inference attack success rate to 22.1% by lowering the rate of telemetry granularity adjustments in response to trust state to 1.4%, without affecting detection rates. This shows that intensity-modulated monitoring can be achieved using entropy-based constraints to maximize adversarial uncertainty without rendering it unobservable for security analysis [47,48]. Contrary to what is often believed, the findings demonstrate that increased monitoring does not always pose a greater threat to privacy, but that information-theoretic regulation can be used to achieve a trade-off. From a scalability perspective, it is observed that latency growth is logarithmic at a relatively low computational overhead, suggesting that probabilistic trust modeling can be effectively performed even at high slice densities.
The increase in CPU and memory usage remains within operational tolerances during edge-cloud deployment, implying practical deployability in future 6G infrastructures where service diversification is massive and dynamic resource orchestration is involved [49]. Combined, the findings support the idea that trust-sensitive orchestration cannot be considered a simple improvement of non-reactive or rule-based control systems, but a paradigm shift in control. The framework provides a unified solution for probabilistic inference, stability analysis, adaptive enforcement, and privacy-conscious monitoring, offering an effective, stable, scalable, and confidentiality-aware security control framework for emerging AI-native 6G slicing ecosystems [50].

6. Conclusions, Limitations and Future Studies

In this paper, the analysis focused on the new security issues of dynamic Slice-as-a-Service (SlaaS) in the 5G-Advanced and future 6G architectures, with the introduction of a Trust-Aware Security Orchestration (TASO) framework. Contrary to traditional policy-based or fixed-point isolation mechanisms, the proposed mechanism calculates slice integrity as a continuously updated posterior trust probability based on multidimensional telemetry data. The framework offers formal guarantees on the restricted growth of trust and convergence by combining Bayesian inference with Markov-based stability models under stochastic compromise and recovery conditions. Wide-scale simulation-based analysis shows statistically significant improvements across various aspects, including detection accuracy, isolation robustness, and privacy preservation.
This decrease in cross-slice breach rates and inference leakage, in conjunction with SLA-compatible latency overhead, shows that probabilistic trust modeling can be useful for increasing security without compromising service performance. The implications of these results are that dynamic recalibration of trust is not only an optimization but also a structural necessity for 6G ecosystems based on AI-native orchestration. These findings are some of the recommendations that could be made to telecom operators and system architects. First, it is necessary to integrate trust metrics directly into orchestration engines rather than storing them as external monitoring artifacts. Second, anomaly detectors must incorporate temporal evidence collection to mitigate volatility during burst workloads. Third, telemetry collection policies should incorporate a privacy constraint to avoid the overexposure of metadata. Lastly, adaptive security mechanisms must be accompanied by formal stability analysis to guarantee bounded behavior in the long term, especially in latency-sensitive slices such as URLLC services.
Even though the outcomes were promising, several limitations need to be acknowledged. The threat model assumes a trustworthy virtualization substrate, which rules out hypervisor-level or System-on-a-Chip compromise. Although this assumption separates logical slicing vulnerabilities, practical implementations may be susceptible to cross-layer threats that require additional protection. Moreover, it is a simulation-based evaluation conducted in an NS-3 environment. The large-scale Monte Carlo validation is a better method to build reliability, but operational 5G or early 6G implementation can introduce additional orchestration delays, hardware heterogeneity, or network impairments that simulation cannot fully approximate. Also, the adversarial paradigm is based on logical compromise and inference attacks, and fails to specify adaptive multi-agent adversaries that can learn strategies. This work may be furthered in several dimensions in future research.
To begin with, game-theoretic attacker-defender modeling would allow the investigation of strategic adversarial characterization and equilibrium trust associations. Second, threshold maximization aided by reinforcement learning might improve the adaptive selection of policies without violating formal stability requirements. Third, inter-operator slicing in distributed 6G ecosystems could be facilitated by federated or cross-domain trust exchange mechanisms. Additionally, integrating federated learning with TASO would enable privacy-preserving collaborative anomaly detection across multiple operators, where local trust models are updated via FL aggregation without sharing raw telemetry, further enhancing scalability and privacy in distributed 6G ecosystems. Fourth, practical testing on actual edge-cloud testbeds would provide insight into deployment characteristics and their impacts on hardware-level performance. Lastly, expanding the probabilistic trust model to include cross-layer signals, such as radio access network telemetry, would be another way to reinforce holistic 6G security orchestration.

Author Contributions

Conceptualization, E.I.E.-P. and E.U.; methodology, E.I.E.-P., E.U. and E.G.; validation, E.U., E.G., A.O.N., B.O., H.B. and V.C.; formal analysis, E.I.E.-P., E.U., E.G.,A.O.N., B.O., H.B. and V.C.; writing—original draft preparation, E.I.E.-P.; writing—review and editing, E.I.E.-P., E.U., E.G., A.O.N., B.O., H.B. and V.C. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

This study utilized simulation data generated through NS-3 (v3.38) with 5G NR modules, as described in Section 4. All simulation configuration parameters, including slice scale (50–500 slices), slice types (URLLC, eMBB, mMTC), lifecycle events (120,000 events), and attack instances (15,000 instances), are fully detailed in Table 2 of the manuscript. The telemetry features and their sources are described in Table 1. All simulation parameters and experimental configurations are comprehensively reported in the Results sections to ensure full reproducibility of the findings.

Acknowledgments

The authors would like to acknowledge the support of colleagues who provided constructive feedback during the preparation of this manuscript.

Conflicts of Interest

Authors Ehigiator Iyobor Egho-Promise, Ekereuke Udoh, Edita Gashi and Vijay Chennareddy were employed by the company QA Higher Education. Author Bamidele Ola was employed by the company Technobeacon. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as potential conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
3GPP3rd Generation Partnership Project
5GFifth Generation
6GSixth Generation
AIArtificial Intelligence
AMFAccess and Mobility Management Function
APIApplication Programming Interface
AUCArea Under the Curve
CNFCloud-native Network Function
CPUCentral Processing Unit
eMBBEnhanced Mobile Broadband
FNFalse Negative
FPFalse Positive
GenAIGenerative Artificial Intelligence
GMMGaussian Mixture Model
IBRIsolation Breach Rate
IoTInternet of Things
MLMachine Learning
mMTCMassive Machine-Type Communication
NFVNetwork Function Virtualization
NS-3Network Simulator 3
ReLURectified Linear Unit
ROCReceiver Operating Characteristic
S-NSSAISingle Network Slice Selection Assistance Information
SBAService-Based Architecture
SDNSoftware-Defined Networking
SLAService-Level Agreement
SlaaSSlice-as-a-Service
SMFSession Management Function
SSIStatic Slice Isolation
TASOTrust-Aware Security Orchestration
TNTrue Negative
TPTrue Positive
UPFUser Plane Function
URLLCUltra-Reliable Low-Latency Communication
VNFVirtual Network Function

References

  1. Yarali, A. From 5G to 6G: Technologies, Architecture, AI, and Security; John Wiley & Sons: Hoboken, NJ, USA, 2023. [Google Scholar]
  2. Wijethilaka, S.; Liyanage, M. Survey on network slicing for Internet of Things realization in 5G networks. IEEE Commun. Surv. Tutor. 2021, 23, 957–994. [Google Scholar] [CrossRef] [Scilit]
  3. Lang, W.; Shankar, S.; Patel, J.M.; Kalhan, A. Towards multi-tenant performance SLOs. IEEE Trans. Knowl. Data Eng. 2013, 26, 1447–1463. [Google Scholar] [CrossRef] [Scilit]
  4. Allaw, Z.; Zein, O.; Ahmad, A.M. Cross-layer security for 5g/6g network slices: An SDN, NFV, and AI-based hybrid framework. Sensors 2025, 25, 3335. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  5. Rodiles Delgado, B.G. Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning; National Energy Technology Laboratory: Morgantown, WV, USA, 2025.
  6. Venâncio, G.; Turchetti, R.C.; Camargo, E.T.; Duarte, E.P., Jr. VNF-Consensus: A virtual network function for maintaining a consistent distributed software-defined network control plane. Int. J. Netw. Manag. 2021, 31, e2124. [Google Scholar] [CrossRef] [Scilit]
  7. Ghasemshirazi, S.; Shirvani, G.; Alipour, M.A. Zero trust: Applications, challenges, and opportunities. arXiv 2023, arXiv:2309.03582. [Google Scholar]
  8. Sindhu, S. Trust-Aware Secure Communication Architectures for Causality-Driven Intelligent Orchestration in Distributed Healthcare Networks. Trans. Secur. Commun. Netw. Protoc. Eng. 2025, 2, 24–33. [Google Scholar]
  9. Hu, Y.; Li, J.; Gao, K.; Zhang, Z.; Zhu, H.; Yan, X. TrustOrch: A Dynamic Trust-Aware Orchestration Framework for Adversarially Robust Multi-Agent Collaboration. In Proceedings of the 2025 3rd International Conference on Artificial Intelligence, Systems and Network Security, Xiangtan, China, 14–16 November 2025. [Google Scholar]
  10. Celiktas, B.; Birgin, B.; Tok, M.S. An analysis of enterprise-level cloud transition barriers within the Technology-Organization-Environment (TOE) framework and strategic solution proposals. Bilişim Teknol. Derg. 2025, 18, 335–354. [Google Scholar] [CrossRef] [Scilit]
  11. Abbas, Q.; Albathan, M. HyperTrust-Fog: Hypergraph-Based Trust-Aware-Federated Orchestration with Energy Adaptive Scheduling for Hierarchical Cloud Fog Edge Systems. Res. Sq. 2026. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  12. Zhang, Y.; Jacobsen, H.A. Decentralized and policy-aware serverless orchestration for the federated web. In Proceedings of the ACM Web Conference 2025, Sydney, Australia, 28 April–2 May 2025; pp. 1539–1543. [Google Scholar]
  13. Orman, L.V. Bayesian inference in trust networks. ACM Trans. Manag. Inf. Syst. 2013, 4, 1–21. [Google Scholar] [CrossRef] [Scilit]
  14. Nielsen, M.; Krukow, K.; Sassone, V. A Bayesian model for event-based trust. Electron. Notes Theor. Comput. Sci. 2007, 172, 499–521. [Google Scholar] [CrossRef] [Scilit]
  15. Griffin, J.E.; Steel, M.F. Semiparametric Bayesian inference for stochastic frontier models. J. Econom. 2004, 123, 121–152. [Google Scholar] [CrossRef] [Scilit]
  16. Chen, Q.; Wang, X.; Liu, L. Next-Generation AI-Driven Digital Twin Framework for Market Volatility Warning and Risk Detection in Global Logistics Supply Chains. IEEE Commun. Stand. Mag. 2026, 10, 147–156. [Google Scholar] [CrossRef] [Scilit]
  17. Stocker, V.; Knieps, G.; Dietzel, C. The rise and evolution of clouds and private networks–Internet interconnection, ecosystem fragmentation. In Proceedings of the TPRC49: The 49th Research Conference on Communication, Information, and Internet Policy, Virtual, 22–24 September 2021. [Google Scholar]
  18. Alnaim, A.K. Securing 5G virtual networks: A critical analysis of SDN, NFV, and network slicing security. Int. J. Inf. Secur. 2024, 23, 3569–3589. [Google Scholar] [CrossRef] [Scilit]
  19. Kambala, V.M.P.R. Transitioning from Virtual Network Functions (VNFs) to Cloud-native Network Functions (CNFs): A Paradigm Shift in Network Softwarization. In Proceedings of the 2025 5th International Conference on Intelligent Technology (CONIT), Hubballi, India, 20–22 June 2025; pp. 1–15. [Google Scholar]
  20. Nadella, V.M. Zero Trust Architecture for Telecom Operations. Int. J. Emerg. Res. Eng. Technol. 2023, 4, 115–129. [Google Scholar] [CrossRef] [Scilit]
  21. Patchamatla, P.S.S. Design and implementation of zero-trust microservice architectures for securing cloud-native telecom systems. Int. J. Res. Appl. Innov. 2021, 4, 6169–6177. [Google Scholar]
  22. Gabla, E.S.; Enyejo, L.A.; James, U.U. Investigating 5G Network Slicing Security Vulnerabilities Using Artificial Intelligence–Driven Intrusion Detection for Telecommunication Resilience. World J. Adv. Eng. Technol. Sci. 2025, 17, 98–112. [Google Scholar] [CrossRef] [Scilit]
  23. Reis, M.J. AI-driven anomaly detection for securing IoT devices in 5G-enabled smart cities. Electronics 2025, 14, 2492. [Google Scholar] [CrossRef] [Scilit]
  24. Shah, S.; Bendale, S.P. An intuitive study: Intrusion detection systems and anomalies, how AI can be used as a tool to enable the majority, in the 5G era. In Proceedings of the 2019 5th International Conference on Computing, Communication, Control and Automation (ICCUBEA), Pune, India, 19–21 September 2019; pp. 1–8. [Google Scholar]
  25. Granatyr, J. Trust and reputation models for multi-agent systems. ACM Comput. Surv. 2015, 48, 1–42. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  26. Raja, M.S.R.S. Reinforcement learning in dynamic environments: Challenges and future directions. Int. J. Artif. Intell. Data Sci. Mach. Learn. 2025, 6, 12–22. [Google Scholar] [CrossRef] [Scilit]
  27. Sissodia, R.; Rauthan, M.S.; Barthwal, V. Service level agreements (SLAs) and their role in establishing trust. In Analyzing and Mitigating Security Risks in Cloud Computing; IGI Global: Hershey, PA, USA, 2024; Volume 1, pp. 182–193. [Google Scholar]
  28. Landau, S.; Leon, P.V. Reversing privacy risks: Strict limitations on the use of communications metadata and telemetry information. Colo. Tech. LJ 2023, 21, 225. [Google Scholar]
  29. Miehling, E.; Rasouli, M.; Teneketzis, D. Control-theoretic approaches to cyber-security. In Adversarial and Uncertain Reasoning for Adaptive Cyber Defense; Springer: Cham, Switzerland, 2019; pp. 12–28. [Google Scholar]
  30. Xue, M.; Roy, S.; Wan, Y.; Das, S.K. Security and vulnerability of cyber-physical infrastructure networks: A control-theoretic approach. In Handbook on Securing Cyber-Physical Critical Infrastructure; Morgan Kaufmann: San Francisco, CA, USA, 2012; Volume 5. [Google Scholar]
  31. Gramaglia, M.; Bulakci, Ö.; Li, X.; Gavras, A.; Ericson, M.; Kerboeuf, S.; Larrabeiti, D.; Ghoraishi, M.; Mesodiakaki, A.; Koumaras, H.; et al. Towards 6G Architecture: Key Concepts, Challenges, and Building Blocks. Available online: https://zenodo.org/records/15001378 (accessed on 10 September 2026).
  32. Madabathula, L. Metadata-driven multi-tenant data ingestion for cloud-native pipelines. Int. J. Comput. Technol. Electron. Commun. 2024, 7, 9857–9865. [Google Scholar]
  33. Dias, J.; Pinto, P.; Santos, R.; Malta, S. 5G network slicing: Security challenges, attack vectors, and mitigation approaches. Sensors 2025, 25, 3940. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  34. ElSalamouny, E. Probabilistic Trust Models in Network Security. Ph.D. Thesis, University of Southampton, Southampton, UK, 2011. [Google Scholar]
  35. Zong, B.; Song, Q.; Min, M.R.; Cheng, W.; Lumezanu, C.; Cho, D.; Chen, H. Deep Autoencoding Gaussian Mixture Model for Unsupervised Anomaly Detection. In Proceedings of the 6th International Conference on Learning Representations (ICLR 2018), Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
  36. Chang, B.J.; Kuo, S.L. Markov chain trust model for trust-value analysis and key management in distributed multicast MANETs. IEEE Trans. Veh. Technol. 2008, 58, 1846–1863. [Google Scholar] [CrossRef] [Scilit]
  37. Mollah, M.H.O.R. AI-driven threat detection and response framework for cloud infrastructure security. Am. J. Sch. Res. Innov. 2025, 4, 494–535. [Google Scholar] [CrossRef] [Scilit]
  38. Miah, M.N.I.; Uddin, M.J.; Ahmed, M.W. AI-Driven Threat Intelligence: Evaluating machine learning for real-time cyber threat sharing among US national security agencies. J. Comput. Sci. Technol. Stud. 2025, 7, 300–313. [Google Scholar] [CrossRef] [Scilit]
  39. Tang, A. Safeguarding the Future: Security and Privacy by Design for AI, Metaverse, Blockchain, and Beyond; CRC Press: Boca Raton, FL, USA, 2025. [Google Scholar] [CrossRef] [Scilit]
  40. Agarwal, A. Adaptive Security Orchestration: Intelligent Policy Enforcement. In Proceedings of the 2025 World Skills Conference on Universal Data Analytics and Science (WorldSUAS), Indore, India, 22–23 August 2025; pp. 1–6. [Google Scholar]
  41. Patel, T. Adaptive AI Enforcement in Real-Time Digital Ecosystems. J. Comput. Sci. Technol. Stud. 2025, 7, 340–344. [Google Scholar] [CrossRef] [Scilit]
  42. Sciancalepore, V.; Cirillo, F.; Costa-Perez, X. Slice as a service (SlaaS) optimal IoT slice resources orchestration. In Proceedings of the GLOBECOM 2017-2017 IEEE Global Communications Conference, Singapore, 4–8 December 2017; pp. 1–7. [Google Scholar]
  43. Turki, M. Toward Elastic Partitioning of Multi-Tenant Computing Systems at the Edge. Ph.D. Thesis, Università degli studi di Ferrara, Ferrara, Italy, 2021. [Google Scholar]
  44. Varghese, F. Dynamic Resource Allocation in Multi-Cloud Environments Using Reinforcement Learning. Ph.D. Thesis, National College of Ireland, Dublin, Ireland, 2025. [Google Scholar]
  45. Filieri, A.; Maggio, M.; Angelopoulos, K.; D’iPpolito, N.; Gerostathopoulos, I.; Hempel, A.B.; Hoffmann, H.; Jamshidi, P.; Kalyvianaki, E.; Klein, C.; et al. Control strategies for self-adaptive software systems. ACM Trans. Auton. Adapt. Syst. 2017, 11, 1–31. [Google Scholar] [CrossRef] [Scilit]
  46. Sastry, S.; Bodson, M. Adaptive Control: Stability, Convergence and Robustness; Courier Corporation: San Francisco, CA, USA, 2011. [Google Scholar]
  47. Wan, Y.; Lin, S.; Jin, C.; Gao, Y.; Yang, Y. Improved entropy-based condition monitoring for pressure pipeline through acoustic denoising. Entropy 2024, 27, 10. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  48. He, Q. Integrating IoT and 6G: Applications of edge intelligence, challenges, and future directions. IEEE Trans. Serv. Comput. 2025, 18, 2471–2488. [Google Scholar] [CrossRef] [Scilit]
  49. Kumar, R.; Dutta, J.; Namsi, V.; Varri, U.S.; Puthal, D. Next-Generation Security in the 6G Era: The Role of AI in Safeguarding Future Networks. IEEE Access 2026, 14, 17347–17380. [Google Scholar] [CrossRef] [Scilit]
  50. Tiwari, S.; Sarma, W.; Srivastava, A. Integrating artificial intelligence with zero trust architecture: Enhancing adaptive security in modern cyber threat landscape. Int. J. Res. Anal. Rev. 2022, 9, 712–728. [Google Scholar]
Figure 1. TASO Workflow.
Figure 1. TASO Workflow.
Information 17 00942 g001
Figure 2. NS-3 Simulation Topology.
Figure 2. NS-3 Simulation Topology.
Information 17 00942 g002
Figure 3. Presents the ROC curves for TASO, ML-only, and SSI baselines, demonstrating TASO’s superior true positive rate across all false positive rate thresholds.
Figure 3. Presents the ROC curves for TASO, ML-only, and SSI baselines, demonstrating TASO’s superior true positive rate across all false positive rate thresholds.
Information 17 00942 g003
Figure 4. Sensitivity Analysis (Trust Memory Parameter α).
Figure 4. Sensitivity Analysis (Trust Memory Parameter α).
Information 17 00942 g004
Figure 5. Trust Convergence Trajectories (The thin gray lines represent the 100 individual trust trajectories generated under different initial trust conditions. Their initial spread reflects heterogeneity in trust values and transient adaptation, rather than sustained divergence. As the trajectories evolve, they converge towards the stationary trust value, π ≈ 0.85).
Figure 5. Trust Convergence Trajectories (The thin gray lines represent the 100 individual trust trajectories generated under different initial trust conditions. Their initial spread reflects heterogeneity in trust values and transient adaptation, rather than sustained divergence. As the trajectories evolve, they converge towards the stationary trust value, π ≈ 0.85).
Information 17 00942 g005
Table 1. The following table is a summary of the telemetry characteristics of the behavioral, control-plane, and data-plane sources to calculate dynamic slice trust values in the TASO framework.
Table 1. The following table is a summary of the telemetry characteristics of the behavioral, control-plane, and data-plane sources to calculate dynamic slice trust values in the TASO framework.
FeatureSourceRole in Trust Computation
Behavioral Entropy DeviationBehavioral Traffic MetricsDetect anomalous traffic patterns
Control-plane Anomaly RateAMF/SMF LogsIdentify abnormal signaling events
Policy Violation FrequencySLA Enforcement ModuleQuantify SLA compliance violations
Autoencoder Reconstruction ErrorData-plane MonitoringUnsupervised anomaly detection
Latency VarianceSlice Performance MetricsDetect performance degradation impacting trust
Table 2. This table describes the fundamental parameters of the simulation applied in the NS-3 experimental environment, such as slice scale, attack situation, and lifecycle events, which are used to carry out an evaluation.
Table 2. This table describes the fundamental parameters of the simulation applied in the NS-3 experimental environment, such as slice scale, attack situation, and lifecycle events, which are used to carry out an evaluation.
ParameterValueNotes
Number of Slices50–500Scalable multi-tenant simulation
Slice TypesURLLC, eMBB, mMTCRepresentative 6G services
Simulation Duration3600 s1 h continuous simulation
Monte Carlo Repetitions30For statistical reliability
Total Slice Lifecycle Events120,000Includes instantiation, scaling, migration, and termination
Attack Instances15,000Cross-slice lateral movement, API abuse, resource exhaustion, metadata inference
Table 3. The table presents the extra latency, CPU consumption, and memory consumption in the TASO framework for URLLC, Embb, and Mmtc slices.
Table 3. The table presents the extra latency, CPU consumption, and memory consumption in the TASO framework for URLLC, Embb, and Mmtc slices.
Slice TypeLatency IncreaseCPU IncreaseMemory Increase
URLLC0.14 ms9.3%6.7%
Embb0.19 ms9.1%6.5%
Mmtc0.12 ms9.2%6.8%
Average0.15 ms9.2%6.7%
Table 4. The present table gives the statistical validation of TASO improvements in performance in terms of t-tests, p-values, Cohen’s effect size, and confidence intervals.
Table 4. The present table gives the statistical validation of TASO improvements in performance in terms of t-tests, p-values, Cohen’s effect size, and confidence intervals.
Metrict-Statisticp-ValueCohen’s d95% Confidence Interval
Detection Accuracy12.7<0.0011.8411.9–14.8% improvement
Isolation Breach Rate14.2<0.0011.9595% reduction ± 0.3%
Privacy Leakage10.8<0.0011.6593.6% ± 0.4% improvement
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Egho-Promise, E.I.; Udoh, E.; Gashi, E.; Nwajana, A.O.; Ola, B.; Balisane, H.; Chennareddy, V. Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks. Information 2026, 17, 942. https://doi.org/10.3390/info17100942

AMA Style

Egho-Promise EI, Udoh E, Gashi E, Nwajana AO, Ola B, Balisane H, Chennareddy V. Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks. Information. 2026; 17(10):942. https://doi.org/10.3390/info17100942

Chicago/Turabian Style

Egho-Promise, Ehigiator Iyobor, Ekereuke Udoh, Edita Gashi, Augustine O. Nwajana, Bamidele Ola, Hewa Balisane, and Vijay Chennareddy. 2026. "Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks" Information 17, no. 10: 942. https://doi.org/10.3390/info17100942

APA Style

Egho-Promise, E. I., Udoh, E., Gashi, E., Nwajana, A. O., Ola, B., Balisane, H., & Chennareddy, V. (2026). Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks. Information, 17(10), 942. https://doi.org/10.3390/info17100942

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop