Multi-domain Anomaly Detection in 5G Networks Through Continuous Dynamic Graphs

Thomas Hoger PhD defense

Soutenance

29.09.26 - 29.09.26

To address emerging quality-of-service requirements and support new use cases, the 5G paradigm represents a major shift from traditional network architectures. The core network is evolving from a monolithic system, in which each network function is statically tied to dedicated hardware, toward a flexible, software-based, virtualized architecture. Similar to microservice-oriented systems, network functions can now be dynamically deployed, scaled, and removed according to operational needs, bringing 5G architectures closer to modern distributed systems. However, this transformation also introduces new security challenges. The virtualization and distribution of network functions expand the attack surface and enable the emergence of novel threats. Some of these attacks can be carried out using only a handful of abnormal packets, making them particularly difficult to detect using traditional intrusion detection approaches based on volumetric features or predefined signatures. As a result, securing next-generation networks requires moving beyond conventional metric-driven methods and adopting packet-level approaches capable of jointly analyzing packet contents, temporal context, and interaction patterns within network communications. To capture these semantic, sequential, and relational dimensions, this thesis introduces a novel framework based on Continuous Dynamic Graphs. This representation enables a fine-grained modeling of the evolving structure of network communications while leveraging the expressive power of Graph Neural Networks (GNNs). The proposed approach effectively detects subtle and previously hard-to-identify anomalies while providing a high degree of interpretability, a key requirement for security analysis and operational deployment.

published on 02.09.26