北京交通大学电子信息工程学院移动专用网络国家工程技术研究中心,北京 100044
黄奥然(1999- ),男,北京交通大学电子信息工程学院博士生,主要研究方向为智能体网络、网络安全。
周华春(1965- ),男,博士,北京交通大学电子信息工程学院副院长、博士生导师,主要研究方向为智能通信、移动互联网、大模型技术、网络安全与卫星网络。
闫竟夫(1996- ),男,北京交通大学电子信息工程学院博士生,主要研究方向为网络安全、智能通信。
范晓静(1999- ),女,北京交通大学电子信息工程学院博士生,主要研究方向为网络安全、卫星网络。
收稿:2026-02-05,
修回:2026-03-16,
录用:2026-04-09,
网络首发:2026-07-21,
纸质出版:2026-06-20
移动端阅览
黄奥然,周华春,闫竟夫等.面向6G智能体网络的行为安全协同架构[J].电信科学,2026,42(06):1-20.
Huang Aoran,Zhou Huachun,Yan Jingfu,et al.A collaborative behavior security architecture for 6G agent networks[J].Telecommunications Science,2026,42(06):1-20.
黄奥然,周华春,闫竟夫等.面向6G智能体网络的行为安全协同架构[J].电信科学,2026,42(06):1-20. DOI: 10.11959/j.issn.1000-0801.DXKX260089.
Huang Aoran,Zhou Huachun,Yan Jingfu,et al.A collaborative behavior security architecture for 6G agent networks[J].Telecommunications Science,2026,42(06):1-20. DOI: 10.11959/j.issn.1000-0801.DXKX260089.
随着6G网络的演进,网络恶意行为呈现长期潜伏、持续渗透的特点,网络行为安全分析面临多路并行、证据分散、难以观察等挑战。针对6G网络中的行为安全防护需求,提出了“三层三域”多智能体协同网络架构。该架构分为感知层、编排层和执行层三大层级,并依托智能域、知识域、工具域的跨域协同,支撑网络行为安全分析的实现。在此基础上,给出了智能体与知识域、工具域交互的域通信协议,并结合A2A(agent-to-agent)协议,规范了多智能体协同开展网络行为安全分析的流程。最后以高级持续威胁(advanced persistent threat,APT)攻击场景下的攻击链构建任务作为网络行为分析实例,基于Clearscope-e3和Clearscope-e5数据集验证了所提架构能有效支撑6G智能体网络中的网络行为安全分析。
With the evolution of 6G networks
malicious network behaviors are characterized by long-term lurking and persistent penetration. Accordingly
network behavior security analysis faces challenges such as parallel multi-path activities
fragmented evidence
and stealthy behaviors. To address the behavioral security protection requirements in 6G networks
a “three-layer
three-domain” multi-agent collaborative network architecture was proposed. This architecture was divided into three layers: the perception layer
the orchestration layer
and the execution layer. By leveraging cross-domain collaboration among the intelligence domain
knowledge domain
and tool domain
the implementation of network behavioral security analysis was supported. On this basis
a domain communication protocol for the interaction between agents and both the knowledge domain and the tool domain was specified. Together with the A2A protocol
a standardized workflow for multi-agent collaborative network behavioral security analysis was established. Finally
using the attack chain construction task under an advanced persistent threat (APT) attack scenario as an instance of network behavioral analysis
the effectiveness of the proposed architecture in supporting network behavioral security analysis in 6G agent networks was validated based on the Clearscope-e3 and Clearscope-e5 datasets.
Chai J J , Zhao Z J , Zhu Y H , et al . A survey of cooperative multi-agent reinforcement learning for multi-task scenarios [J ] . Artificial Intelligence Science and Engineering , 2025 , 1 ( 2 ): 98 - 121 .
Wang C X , You X H , Gao X Q , et al . On the road to 6G: visions, requirements, key technologies, and testbeds [J ] . IEEE Communications Surveys & Tutorials , 2023 , 25 ( 2 ): 905 - 974 .
Li Y H , Wang H Z , Min G Y , et al . A flexible and scalable multi-agent learning framework for dynamic RAN slicing in 6G native-AI networks [J ] . IEEE Transactions on Mobile Computing , 2026 , 25 ( 5 ): 7258 - 7273 .
Yang L , Naser S , Shami A , et al . Toward zero touch networks: cross-layer automated security solutions for 6G wireless networks [J ] . IEEE Transactions on Communications , 2025 , 73 ( 9 ): 7650 - 7679 .
TR 22.870: 2025 Study on 6G use cases and service requirements [S ] .
TR 38.914: 2025 Study on 6G scenarios and requirements [S ] .
Aly A , Iqbal S , Youssef A , et al . MEGR-APT: a memory-efficient APT hunting system based on attack representation learning [J ] . IEEE Transactions on Information Forensics and Security , 2024 , 19 : 5257 - 5271 .
Li T , Liu X M , Qiao W , et al . T-trace: constructing the APTs provenance graphs through multiple syslogs correlation [J ] . IEEE Transactions on Dependable and Secure Computing , 2024 , 21 ( 3 ): 1179 - 1195 .
Zhao J , Yan Q B , Liu X D , et al . Cyber threat intelligence modeling based on heterogeneous graph convolutional network [C ] // Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) . 2020 : 241 - 256 .
Ur Rehman M , Ahmadi H , Ul Hassan W . Flash: a comprehensive approach to intrusion detection via provenance graph representation learning [C ] // Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP) . Piscataway : IEEE Press , 2024 : 3552 - 3570 .
Golec M , Khamayseh Y , Melhem S B , et al . LLM-driven APT detection for 6G wireless networks: a systematic review and taxonomy [PP ] . V2. arXiv ( 2025-06-23 )[ 2026-02-04 ] . arXiv: 2505.18846 .
Dai C , Wang Y Z , Wu T Y , et al . Robust multi-agent reinforcement learning for physical layer security communication in RIS-assisted UAV-enabled ISAC networks [J ] . IEEE Transactions on Network Science and Engineering , 2025 , 13 : 4969 - 4984 .
Zakir Khan M , Ge Y , Mollel M , et al . RFSensingGPT: a multi-modal RAG-enhanced framework for integrated sensing and communications intelligence in 6G networks [J ] . IEEE Transactions on Cognitive Communications and Networking , 2026 , 12 : 298 - 311 .
Wang Y , Yang C G , Li T , et al . A survey on intent-driven end-to-end 6G mobile communication system [J ] . IEEE Communications Surveys & Tutorials , 2026 , 28 : 882 - 915 .
Cheng S , Wang Z Y , Feng F Z , et al . IFresher: information freshening for mobile augmented reality with multi-agent reinforcement learning in edge computing [J ] . IEEE Transactions on Mobile Computing , 2025 , 24 ( 11 ): 11703 - 11716 .
Liang Y Z , Jiang R H , Wei B S , et al . MAMoE: a multi-agent mixture-of-experts framework for LLM-assisted 3D object reconstruction and transmission [J ] . IEEE Transactions on Network Science and Engineering , 2026 , 13 : 3862 - 3878 .
Gui J S , Li Z Y , Zhang J J , et al . Multi-heterogeneous-agent DRL for efficient congestion control with reward redistribution in space-air-ground integrated networks [J ] . IEEE Transactions on Network Science and Engineering , 2026 , 13 : 3035 - 3052 .
Batool I , Fouda M M , Ismail M , et al . AMADRL: privacy-aware attention-based multiagent deep reinforcement learning for optimizing spectral allocation in 6G vehicular networks [J ] . IEEE Internet of Things Journal , 2026 , 13 ( 3 ): 4792 - 4808 .
Chatzistefanidis I , Leone A , Nikaein N . Maestro: LLM-driven collaborative automation of intent-based 6G networks [J ] . IEEE Networking Letters , 2024 , 6 ( 4 ): 227 - 231 .
Mekrache A , Ksentini A , Verikoukis C . Intent-based management of next-generation networks: an LLM-centric approach [J ] . IEEE Network , 2024 , 38 ( 5 ): 29 - 36 .
Yao Z , Tang Z Q , Yang W M , et al . Enhancing LLM QoS through cloud-edge collaboration: a diffusion-based multi-agent reinforcement learning approach [J ] . IEEE Transactions on Services Computing , 2025 , 18 ( 3 ): 1412 - 1427 .
Zhou L , Deng X F , Wang Z , et al . Semantic information extraction and multi-agent communication optimization based on generative pre-trained transformer [J ] . IEEE Transactions on Cognitive Communications and Networking , 2025 , 11 ( 2 ): 725 - 737 .
Liu J L , Chen K Q , Liu R Y , et al . Alice-SLAM: accurate and lite-communication collaborative SLAM for resource-constrained multi-agent [J ] . IEEE Journal on Selected Areas in Communications , 2025 , 43 ( 12 ): 4076 - 4090 .
Chang H G , Liu Y M , Sheng Z G . Distributed multi-agent reinforcement learning for collaborative path planning and scheduling in blockchain-based cognitive Internet of vehicles [J ] . IEEE Transactions on Vehicular Technology , 2024 , 73 ( 5 ): 6301 - 6317 .
Yan S M , Shi L , Bu X H , et al . Barycentric coordination-based flocking behavior for nonlinear multi-agent systems with cooperation-competition interactions [J ] . IEEE Control Systems Letters , 2025 , 9 : 2351 - 2356 .
Liu J D , Li T , Wang Q Y , et al . Unleashing collaborative potentials: multifaceted collaboration among agents in multitask Internet of things networks [J ] . IEEE Internet of Things Journal , 2025 , 12 ( 14 ): 28121 - 28135 .
Lai J Y , Liu H S , Xu G Y , et al . Joint computation offloading and resource allocation for LEO satellite networks using hierarchical multi-agent reinforcement learning [J ] . IEEE Transactions on Cognitive Communications and Networking , 2025 , 11 ( 4 ): 2554 - 2567 .
Chen X , Xiao B H , Lin X Y , et al . Multi-agent collaboration for vehicular task offloading using federated deep reinforcement learning [J ] . IEEE Transactions on Mobile Computing , 2025 , 24 ( 9 ): 8856 - 8871 .
Yang T T , Feng P , Guo Q X , et al . AutoHMA-LLM: efficient task coordination and execution in heterogeneous multi-agent systems using hybrid large language models [J ] . IEEE Transactions on Cognitive Communications and Networking , 2025 , 11 ( 2 ): 987 - 998 .
Matsumoto D , Watarai K , Okada S , et al . A2A routing service with MCP integration: bridging security, auditability, and governance in AI agent systems [C ] // Proceedings of the 2025 IEEE International Conference on Computing (ICOCO) . Piscataway : IEEE Press , 2025 : 60 - 65 .
Feng H F , Zhang W T , Liu Y , et al . GNN-enabled multi-agent DRL for adaptive path selection in multi-network domains [J ] . IEEE Transactions on Network Science and Engineering , 2026 , 13 : 130 - 145 .
Huang A R , Yan J F , Fan X J , et al . Multi-scenario cloud–edge collaborative DDoS detection in LLM-enabled AIoT [J ] . IEEE Transactions on Network Science and Engineering , 2026 , 13 : 3790 - 3809 .
Huo X , Liu M X . Encrypted decentralized multi-agent optimization for privacy preservation in cyber-physical systems [J ] . IEEE Transactions on Industrial Informatics , 2023 , 19 ( 1 ): 750 - 761 .
Wen X R , Wen J B , Xiao M , et al . Defending against network attacks for secure AI agent migration in vehicular metaverses [J ] . IEEE Internet of Things Journal , 2026 , 13 ( 3 ): 4153 - 4166 .
Chen J L , Lan X L , Zhang Q Q , et al . Defending against APT attacks in cloud computing environments using grouped multiagent deep reinforcement learning [J ] . IEEE Internet of Things Journal , 2025 , 12 ( 12 ): 19459 - 19470 .
Hmimou Y , Tabaa M , Khiat A , et al . A multi-agent system for cybersecurity threat detection and correlation using large language models [J ] . IEEE Access , 2025 , 13 : 150199 - 150215 .
国家互联网应急中心 . 关于国家授时中心遭受美国国家安全局网络攻击事件的技术分析报告 [R ] . 2025 .
CNCERT . Technical analysis report on the cyberattack against the National Time Service Center by the U.S. National Security Agency [R ] . 2025 .
Nour B , Pourzandi M , Debbabi M . Threatify: APT threat variant generation using graph-based machine learning [J ] . IEEE Transactions on Network and Service Management , 2025 , 22 ( 5 ): 3978 - 3994 .
Mukherjee K , Kantarcioglu M . LLM-driven provenance forensics for threat investigation and detection [PP ] . V2. arXiv ( 2025-11-17 )[ 2026-02-04 ] . arXiv: 2508.21323 .
Siriwardhana Y , Porambage P , Liyanage M , et al . AI and 6G security: opportunities and challenges [C ] // Proceedings of the 2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit) . Piscataway : IEEE Press , 2021 : 616 - 621 .
Hossain M N , Milajerdi S M , Wang J A , et al . SLEUTH: real-time attack scenario reconstruction from COTS audit data [C ] // Proceedings of the 26th USENIX Security Symposium (USENIX Security 17). 2017 : 487 - 504 .
0
浏览量
0
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621