Home / Current Issue / Paper 1722869
Machine Learning Techniques for Intrusion Detection Systems in 5G and Beyond Networks: A Systematic Literature Review
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
DOI: 10.64388/IREV10I3-1722869
Abstract
5G and subsequent network systems are designed with a number of these features like super-fast data transfer, ultra-low latency, huge number of connections, cloud network, multi-access edge computing, and network function virtualization. But also, they are the primary cause of the proliferation of cyber-attacks and the evolution of intelligent intrusion detection system. The manuscript describes a comprehensive review of the literature concerning the application of machine learning to intrusions detection systems in 5G and beyond networks. The survey includes various kinds of models, datasets, categories of attack, validation methods, assessment metrics, deployment readiness, explainability and privacy considerations. Studies published between 2020 and 2026 were examined using PRISMA-guided selection and structured data extraction method. Findings from 21 reviewed studies show that empirical ML/DL evaluation studies accounted for 42.9%, review or survey syntheses accounted for 23.8%, federated or transfer learning studies accounted for 19.0%, and dataset/testbed studies accounted for 14.3%. Representative benchmark accuracies ranged from 64.1% for application-layer PFCP detection to 100.0% for binary 5G-NIDD classification. The paper concludes that no single model is universally best; rather, technique selection should depend on the type of attack, the quality of validation, the amount of latency, the scalability, privacy, and explainability, to determine the most appropriate approach.
Keywords
5G Security, Beyond 5G, Intrusion Detection System, Machine Learning, Deep Learning, Federated Learning, PRISMA, and Systematic Literature Review.
References
[1] 3rd Generation Partnership Project, “3GPP TS 33.501 V18.10.0: Security architecture and procedures for 5G system,” ETSI, 2025.
[2] European Union Agency for Cybersecurity, “ENISA threat landscape for 5G networks,” ENISA, 2020.
[3] A. Aldweesh, A. Derhab, and A. Z. Emam, “Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues,” Knowledge-Based Systems, vol. 189, 105124, 2020, doi: 10.1016/j.knosys.2019.105124.
[4] P. Dini, A. Elhanashi, A. Begni, S. Saponara, Q. Zheng, and K. Gasmi, “Overview on intrusion detection systems design exploiting machine learning for networking cybersecurity,” Applied Sciences, vol. 13, no. 13, 7507, 2023, doi: 10.3390/app13137507.
[5] A. Imanbayev, S. Tynymbayev, R. Odarchenko, S. Gnatyuk, R. Berdibayev, A. Baikenov, and N. Kaniyeva, “Research of machine learning algorithms for the development of intrusion detection systems in 5G mobile networks and beyond,” Sensors, vol. 22, no. 24, 9957, 2022, doi: 10.3390/s22249957.
[6] S. Samarakoon, Y. Siriwardhana, P. Porambage, M. Liyanage, S.-Y. Chang, J. Kim, J. Kim, and M. Ylianttila, “5G-NIDD: A comprehensive network intrusion detection dataset generated over 5G wireless network,” arXiv, 2022, doi: 10.48550/arXiv.2212.01298.
[7] P. V. A. Alves et al., “Machine learning applied to anomaly detection on 5G O-RAN architecture,” Procedia Computer Science, vol. 222, pp. 81-93, 2023, doi: 10.1016/j.procs.2023.08.146.
[8] Y. Siriwardhana et al., “Descriptor: 5G wireless network intrusion detection dataset (5G-NIDD),” IEEE Data Descriptions, vol. 2, pp. 358-369, 2025, doi: 10.1109/IEEEDATA.2025.3592888.
[9] B. Kitchenham and S. Charters, “Guidelines for performing systematic literature reviews in software engineering,” EBSE Technical Report EBSE-2007-01, Keele University and Durham University, 2007.
[10] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, n71, 2021, doi: 10.1136/bmj.n71.
[11] M. A. Bouke and A. Abdullah, “An empirical assessment of ML models for 5G network intrusion detection: A data leakage-free approach,” e-Prime - Advances in Electrical Engineering, Electronics and Energy, vol. 8, 100590, 2024, doi: 10.1016/j.prime.2024.100590.
[12] P. Radoglou-Grammatikis et al., “5GCIDS: An intrusion detection system for 5G core with AI and explainability mechanisms,” in Proc. IEEE Globecom Workshops, 2023, pp. 353-358, doi: 10.1109/GCWkshps58843.2023.10464667.
[13] A. Moubayed, “A complete EDA and DL pipeline for softwarized 5G network intrusion detection,” Future Internet, vol. 16, no. 9, 331, 2024, doi: 10.3390/fi16090331.
[14] B. Farzaneh, N. Shahriar, A. H. Al Muktadir, M. S. Towhid, and M. S. Khosravani, “DTL-5G: Deep transfer learning-based DDoS attack detection in 5G and beyond networks,” Computer Communications, vol. 228, 107927, 2024, doi: 10.1016/j.comcom.2024.107927.
[15] H. Rezaei, R. Taheri, E. Nowroozi, M. Hajizadeh, S. Shiaeles, and T. Bauschert, “A survey on security and privacy in federated learning-based intrusion detection systems for 5G and beyond networks,” IEEE Open Journal of the Communications Society, vol. 7, pp. 253-300, 2025, doi: 10.1109/OJCOMS.2025.3644477.
[16] C. Hamroun, A. Fladenmuller, M. Pariente, and G. Pujolle, “Intrusion detection in 5G and Wi-Fi networks: A survey of current methods, challenges and perspectives,” IEEE Access, vol. 13, pp. 40950-40976, 2025, doi: 10.1109/ACCESS.2025.3546338.
[17] K. Noor, A. L. Imoize, C.-T. Li, and C.-Y. Weng, “A review of machine learning and transfer learning strategies for intrusion detection systems in 5G and beyond,” Mathematics, vol. 13, no. 7, 1088, 2025, doi: 10.3390/math13071088.
[18] K. He, D. D. Kim, and M. R. Asghar, “Adversarial machine learning for network intrusion detection systems: A comprehensive survey,” IEEE Communications Surveys & Tutorials, vol. 25, no. 1, pp. 538-566, 2023, doi: 10.1109/COMST.2022.3233793.
[19] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conference, 2015, pp. 1-6, doi: 10.1109/MilCIS.2015.7348942.
[20] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. International Conference on Information Systems Security and Privacy, 2018, pp. 108-116, doi: 10.5220/0006639801080116.
[21] Francis Onojah, Prof. Prema Kirubakaran, Dr. Ridwan Kolapo, Dr.Temitope Olufunmi Atoyebi, Dr. R. Renuga Dev. Improving DDoS Detection in Software-Defined Networks through a Hybrid Machine Learning 2025, Department of Information Technology, Nile University of Nigeria. Abuja.Nigeria Iconic Research and Engineering Journals, Volume 9, Issue 3, ISSN: 2456-8880
How to cite this paper
@article{1722869,
author = {Elijah Abayomi Olaniyi, Temitope Olufunmi Atoyebi, Ridwan Kolapo, Prema A. Kirubakaran},
title = {Machine Learning Techniques for Intrusion Detection Systems in 5G and Beyond Networks: A Systematic Literature Review},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {969-975},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722869.pdf},
abstract = {5G and subsequent network systems are designed with a number of these features like super-fast data transfer, ultra-low latency, huge number of connections, cloud network, multi-access edge computing, and network function virtualization. But also, they are the primary cause of the proliferation of cyber-attacks and the evolution of intelligent intrusion detection system. The manuscript describes a comprehensive review of the literature concerning the application of machine learning to intrusions detection systems in 5G and beyond networks. The survey includes various kinds of models, datasets, categories of attack, validation methods, assessment metrics, deployment readiness, explainability and privacy considerations. Studies published between 2020 and 2026 were examined using PRISMA-guided selection and structured data extraction method. Findings from 21 reviewed studies show that empirical ML/DL evaluation studies accounted for 42.9%, review or survey syntheses accounted for 23.8%, federated or transfer learning studies accounted for 19.0%, and dataset/testbed studies accounted for 14.3%. Representative benchmark accuracies ranged from 64.1% for application-layer PFCP detection to 100.0% for binary 5G-NIDD classification. The paper concludes that no single model is universally best; rather, technique selection should depend on the type of attack, the quality of validation, the amount of latency, the scalability, privacy, and explainability, to determine the most appropriate approach.},
keywords = {5G Security, Beyond 5G, Intrusion Detection System, Machine Learning, Deep Learning, Federated Learning, PRISMA, and Systematic Literature Review.},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1722869}
}