Anomaly Detection Using Machine Learning for Robotics Environments on 5G Networks
Abstract
1. Introduction
- The design and implementation of a standalone anomaly detection system for robotics environments on 5G networks, incorporating supervised and unsupervised algorithms.
- The design of adversary emulation as security tests for both availability and integrity attacks, particularized to Modbus over the TCP communication protocol.
- Investigate the effectiveness of each model at capturing attacks in terms of recall, accuracy, precision, and other relevant metrics.
2. Background
2.1. URSIM
2.2. Data Transportation Layer
2.2.1. Modbus Protocol
2.2.2. Apache Kafka
2.2.3. gRPC Protocol
3. Materials and Methods
3.1. Infrastructure Details
3.1.1. Field Device
3.1.2. Gateway
3.1.3. MEC
3.1.4. Cloud
3.2. Machine Learning Model Selection and Working Flow
3.2.1. Supervised Learning
3.2.2. Unsupervised Learning
3.3. Adversary Emulation
4. Results
4.1. Availability Attacks
- The first two, T0806 and T0814, represent active Denial-of-Service (DoS) scenarios targeting the control and telemetry channels. In the multiple-register-write attack, ModTester continuously issued unauthorized write commands to several Modbus registers, progressively saturating the communication channel. Similarly, the TCP SYN flood attack generated a large number of half-open TCP connections, exhausting the network and processing resources. As these attacks persisted, the robotic system exhibited gradual performance degradation. The command execution latency increased, control loops became unstable, and system resources such as CPU utilization, memory, and network buffers experienced significant strain. Ultimately, both attacks led to complete system unresponsiveness and service collapse.
- In contrast, the other two attacks—T0846 and T0885—were passive or semi-passive reconnaissance operations. The network sniffing attack collected communication packets and telemetry data without actively disrupting the ongoing process, while the connection-to-a-universally-known-port technique probed network services to identify accessible endpoints and potential entry points. These activities provided valuable information on the infrastructure and network configuration of the system, but did not produce observable effects on the dynamics of the process or the availability of the system during execution.
4.2. Integrity Attacks
- In the false-data-injection scenario (T1565), ModTester inserted spurious sensor readings and forged actuator feedback into the telemetry stream that the robotic arm sent to the Gateway; the attacker’s manipulations were concentrated at the Gateway entry point so that the data recorded downstream (at the Gateway, MEC, and Cloud logging services) no longer reflected the true physical state of the robot.
- The MiTM scenario (T0830) involved intercepting and altering messages in transit specifically at or immediately before the Gateway: control commands and sensor reports were modified before being forwarded to downstream components. In both cases, the controller continued to issue the intended trajectory commands, while the recorded process logs and monitoring feeds diverged from the true system behavior as observed in the robotic arm.
5. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Lessi, C.C.; Gavrielides, A.; Solina, V.; Qiu, R.; Nicoletti, L.; Li, D. 5G and Beyond 5G Technologies Enabling Industry 5.0: Network Applications for Robotic. Procedia Comput. Sci. 2024, 232, 675–687. [Google Scholar] [CrossRef] [Scilit]
- Asavasirikulkij, C.; Mathong, C.; Sinthumongkolchai, T.; Chancharoen, R.; Asdomwised, W. Low Latency Peer to Peer Robot Wireless Communication with Edge Computing. In 2021 IEEE 11th International Conference on System Engineering and Technology, ICSET 2021-Proceedings; IEEE: Piscataway, NJ, USA, 2021; pp. 100–105. [Google Scholar] [CrossRef] [Scilit]
- Kadena, E.; Dai Nguyen, H.P.; Ruiz, L. Mobile Robots: An Overview of Data and Security. In Proceedings of the 7th International Conference on Information Systems Security and Privacy ICISSP; SciTePress: Setúbal, Portugal, 2021; pp. 291–299. [Google Scholar] [CrossRef] [Scilit]
- Lacava, G.; Marotta, A.; Martinelli, F.; Saracino, A.; La Marra, A.; Gil-Uriarte, E.; Mayoral-Vilches, V. Cybsersecurity issues in robotics. J. Wirel. Mob. Netw. Ubiquitous Comput. Dependable Appl. (JoWUA) 2021, 12, 1–28. [Google Scholar] [CrossRef]
- Jiang, X.; Lora, M.; Chattopadhyay, S. An Experimental Analysis of Security Vulnerabilities in Industrial IoT Devices. ACM Trans. Internet Technol. 2020, 20, 16. [Google Scholar] [CrossRef] [Scilit]
- Mittal, M.; Kumar, K.; Behal, S. Deep learning approaches for detecting DDoS attacks: A systematic review. Soft Comput. 2023, 27, 13039–13075. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Ziegler, V.; Schneider, P.; Viswanathan, H.; Montag, M.; Kanugovi, S.; Rezaki, A. Security and Trust in the 6G Era. IEEE Access 2021, 9, 142314–142327. [Google Scholar] [CrossRef] [Scilit]
- Shafique, K.; Khawaja, B.A.; Sabir, F.; Qazi, S.; Mustaqim, M. Internet of Things (IoT) for Next-Generation Smart Systems: A Review of Current Challenges, Future Trends and Prospects for Emerging 5G-IoT Scenarios. IEEE Access 2020, 8, 23022–23040. [Google Scholar] [CrossRef] [Scilit]
- Botta, A.; Rotbei, S.; Zinno, S.; Ventre, G. Cyber security of robots: A comprehensive survey. Intell. Syst. Appl. 2023, 18, 200237. [Google Scholar] [CrossRef] [Scilit]
- Ness, S.; Eswarakrishnan, V.; Sridharan, H.; Shinde, V.; Venkata Prasad Janapareddy, N.; Dhanawat, V. Anomaly Detection in Network Traffic Using Advanced Machine Learning Techniques. IEEE Access 2025, 13, 16133–16149. [Google Scholar] [CrossRef] [Scilit]
- Riggs, H.; Tufail, S.; Parvez, I.; Tariq, M.; Khan, M.A.; Amir, A.; Vuda, K.V.; Sarwat, A.I. Impact, Vulnerabilities, and Mitigation Strategies for Cyber-Secure Critical Infrastructure. Sensors 2023, 23, 4060. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Yaacoub, J.P.A.; Noura, H.N.; Salman, O.; Chehab, A. Robotics cyber security: Vulnerabilities, attacks, countermeasures, and recommendations. Int. J. Inf. Secur. 2022, 21, 115–158. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Sangoleye, F.; Johnson, J.; Eleni Tsiropoulou, E. Intrusion Detection in Industrial Control Systems Based on Deep Reinforcement Learning. IEEE Access 2024, 12, 151444–151459. [Google Scholar] [CrossRef] [Scilit]
- Apruzzese, G.; Laskov, P.; Montes de Oca, E.; Mallouli, W.; Brdalo Rapa, L.; Grammatopoulos, A.V.; Di Franco, F. The Role of Machine Learning in Cybersecurity. Digit. Threat. 2023, 4, 8. [Google Scholar] [CrossRef] [Scilit]
- Adejimi, A.; Sodiya, A.; Ojesanmi, O.; Falana, O.; Tinubu, C. A Dynamic Intrusion Detection System for Critical Information Infrastructure. Sci. Afr. 2023, 21, e01817. [Google Scholar] [CrossRef] [Scilit]
- ISO/IEC 30141:2024; Internet of Things (IoT)—Reference Architecture. ISO/IEC: Geneva, Switzerland, 2024.
- Collaborative Robotic Automation|Universal Robots Cobots. Available online: https://www.universal-robots.com/ (accessed on 4 February 2026).
- Universal Robots Offline Simulator Limits 2023. Available online: https://www.universal-robots.com/download/software-e-series/simulator-non-linux/offline-simulator-e-series-ur-sim-for-non-linux-5126-lts/ (accessed on 4 February 2026).
- Figueroa-Lorenzo, S.; Añorga, J.; Arrizabalaga, S. A survey of IIoT protocols: A measure of vulnerability risk analysis based on CVSS. ACM Comput. Surv. (CSUR) 2020, 53, 1–53. [Google Scholar] [CrossRef] [Scilit]
- Chen, B.; Pattanaik, N.; Goulart, A.; Butler-Purry, K.L.; Kundur, D. Implementing attacks for modbus/TCP protocol in a real-time cyber physical system test bed. In Proceedings-CQR 2015: 2015 IEEE International Workshop Technical Committee on Communications Quality and Reliability; Curran Associates, Inc.: Red Hook, NY, USA, 2015. [Google Scholar] [CrossRef] [Scilit]
- Bhatia, S.; Kush, N.S.; Djamaludin, C.; Akande, A.J.; Foo, E. Practical modbus flooding attack and detection. In Proceedings of the Twelfth Australasian Information Security Conference (AISC 2014); Conferences in Research and Practice in Information Technology; Australian Computer Society: Sydney, Australia, 2014; Volume 149, pp. 57–65. [Google Scholar]
- Kreps, J.; Narkhede, N.; Rao, J. Kafka: A distributed messaging system for log processing. In Proceedings of the NetDB, Athens, Greece, 12 June 2011; Volume 11, pp. 1–7. [Google Scholar]
- Wang, X.; Zhao, H.; Zhu, J. GRPC: A communication cooperation mechanism in distributed systems. SIGOPS Oper. Syst. Rev. 1993, 27, 75–86. [Google Scholar] [CrossRef] [Scilit]
- Machaka, V.; Figueroa-Lorenzo, S.; Arrizabalaga, S.; Hernantes, J. Comparative analysis of the standalone and Hybrid SDN solutions for early detection of network channel attacks in Industrial Control Systems: A WWTP case study. Internet Things 2024, 28, 101413. [Google Scholar] [CrossRef] [Scilit]

| Sensor Category | Sub-Category | Variables (Units) | Count |
|---|---|---|---|
| Kinematic State | Joint Angle | Base, Shoulder, Elbow, Wrist1, Wrist2, Wrist3 (mrad) | 6 |
| Joint Velocity | Base, Shoulder, Elbow, Wrist1, Wrist2, Wrist3 (mrad/s) | 6 | |
| Joint Revolution | Base, Shoulder, Elbow, Wrist1, Wrist2, Wrist3 (Count) | 6 | |
| Position | x, y (Position Units) | 2 | |
| Subtotal (Kinematic) | 20 | ||
| Dynamic Profile | Joint Current | Base, Shoulder, Elbow, Wrist1, Wrist2, Wrist3 (mA) | 6 |
| System and Tool Status | Robot Current, I/O Current, Tool Current (mA), Tool State (Status) | 4 | |
| Subtotal (Dynamic) | 10 | ||
| Thermal Profile | Joint Temperature | Base, Shoulder, Elbow, Wrist1, Wrist2, Wrist3 (°C) | 6 |
| Tool Temperature | Tool Temperature (°C) | 1 | |
| Subtotal (Thermal) | 7 | ||
| Total sensor variables | 37 | ||
| ID | Name | Description |
|---|---|---|
| T0806 | Brute Force I/O | Adversaries may repetitively or successively change I/O point values to perform an action. Brute Force I/O may be achieved by changing either a range of I/O point values or a single point value repeatedly to manipulate a process function. |
| T0846 | Remote System Discovery | Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network. |
| T0814 | Denial of Service | Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality. |
| T0885 | Commonly Used Port | Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection. |
| T0830 | Adversary-in-the-Middle | Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks. |
| T1565 | Data Manipulation | Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. |
| Principle | Tactic | Tool |
|---|---|---|
| Availability | T0806 | ModTester DOS Multiple Register Write Attack |
| T0814 | ModTester DOS TCP SYN flood attack | |
| T0846 | ModTester Network sniffing | |
| T0885 | ModTester Connection to a universally known port | |
| Integrity | T1565 | ModTester Data corruption via False Data Injection |
| T0830 | ModTester MiTM |
| ML Type | ML Model | Accuracy | Precision | Recall | F1 | Train Time (s) |
|---|---|---|---|---|---|---|
| Supervised | LightGBM | 0.867 | 0.993 | 0.806 | 0.890 | 0.658 |
| Supervised | XGBoost | 0.865 | 0.994 | 0.803 | 0.888 | 0.457 |
| Supervised | R.F. | 0.864 | 0.994 | 0.801 | 0.887 | 0.872 |
| Supervised | Dense NN | 0.864 | 0.994 | 0.801 | 0.887 | 40.857 |
| Unsupervised | LOF | 0.827 | 0.944 | 0.694 | 0.800 | 0.239 |
| Unsupervised | Autoencoder | 0.832 | 0.991 | 0.671 | 0.800 | 98.821 |
| Unsupervised | OC-SVM | 0.823 | 0.933 | 0.697 | 0.798 | 0.064 |
| Unsupervised | iForest | 0.823 | 0.933 | 0.696 | 0.797 | 3.103 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Dean Oses, M.; Domec Paz, A.; Figueroa-Lorenzo, S.; Arrizabalaga, S.; Rodriguez-Jorge, R. Anomaly Detection Using Machine Learning for Robotics Environments on 5G Networks. Technologies 2026, 14, 108. https://doi.org/10.3390/technologies14020108
Dean Oses M, Domec Paz A, Figueroa-Lorenzo S, Arrizabalaga S, Rodriguez-Jorge R. Anomaly Detection Using Machine Learning for Robotics Environments on 5G Networks. Technologies. 2026; 14(2):108. https://doi.org/10.3390/technologies14020108
Chicago/Turabian StyleDean Oses, Mikel, Aitor Domec Paz, Santiago Figueroa-Lorenzo, Saioa Arrizabalaga, and Ricardo Rodriguez-Jorge. 2026. "Anomaly Detection Using Machine Learning for Robotics Environments on 5G Networks" Technologies 14, no. 2: 108. https://doi.org/10.3390/technologies14020108
APA StyleDean Oses, M., Domec Paz, A., Figueroa-Lorenzo, S., Arrizabalaga, S., & Rodriguez-Jorge, R. (2026). Anomaly Detection Using Machine Learning for Robotics Environments on 5G Networks. Technologies, 14(2), 108. https://doi.org/10.3390/technologies14020108

