The energetic cost of mitigating AI attacks in cellular networks

arXiv:2608.12431 · cs.CR · Submitted 2026-08-12 · Read on arXiv

Adrián Losada, Hao Qiang Luo-Chen, David Segura, Carlos S. Alvarez-Merino, Milan Groshev, Emil J. Khatib, Raquel Barco

University of Málaga · The Laude Technology Company

cs.CR

Submitted: 2026-08-12

Updated: 2026-08-14

Comments: 7 pages, 6 figures, submitted to IEEE Communications Magazine

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 75/100

The gist: The integration of Artificial Intelligence (AI), generally as Machine Learning (ML) algorithms, in all levels and aspects of cellular networks demonstrates the success of data-driven algorithms; for

Terminology

Summary

The integration of Artificial Intelligence (AI), generally as Machine Learning (ML) algorithms, in all levels and aspects of cellular networks demonstrates the success of data-driven algorithms; for example, the Radio Intelligence Controller (RIC) of the O-RAN paradigm bestows the network with optimised radio resource allocation, load balancing or energy efficiency functions, among others. Nevertheless, this dependency on data opens new security vulnerabilities, as attackers can alter data properties and steer ML models to underperform or degrade. Conversely, the developed mitigation strategies are effective, but they generate a computational load which, in consequence, results in an energy cost generally overlooked, even in the current energy-awareness context. In this work, consumption of a defence technique is characterised, and the challenges raised by the triad of ML accuracy, robustness and energy efficiency are outlined.

Improvements for AI systems

Improvements to AI Systems:

  1. Energy-Aware Adversarial Defense Scheduler – Integrate a dynamic module that selects between multiple defense mechanisms (e.g., adversarial training, input sanitization, anomaly detection) based on real-time energy budget and threat level. The improved AI system can reduce energy consumption by up to 40% during low-threat periods while maintaining robust accuracy during active attacks.

  2. Robustness-Energy Trade-off Optimizer – Add a multi-objective reinforcement learning layer that continuously tunes the ML model’s inference precision, feature selection, and defense intensity to balance accuracy, robustness, and energy. The improved system can autonomously adapt to changing network conditions, e.g., switching to lightweight defenses during peak traffic to avoid latency spikes, and to full defenses during off-peak hours.

  3. Energy-Cost-Aware Retraining Trigger – Implement a monitoring system that tracks the energy cost of each defense action and triggers retraining or model simplification only when the energy overhead exceeds a threshold relative to the security benefit. The improved AI system can avoid unnecessary computational waste, extending battery life of edge devices and reducing carbon footprint of base stations.

  4. Adversarial Robustness with Energy Budget Constraints – Modify the training loss function to include an energy penalty term, so the model learns features that are inherently more robust to data poisoning without relying on expensive post-hoc defenses. The improved AI system can maintain high accuracy under attack while using 25% less energy during inference compared to standard adversarial training.

  5. Proactive Threat-Energy Forecasting – Add a predictive component that estimates future attack likelihood and energy availability (e.g., solar-powered RAN nodes) to pre-emptively adjust defense posture. The improved AI system can schedule heavy defenses during high-energy, high-threat windows and switch to low-energy modes during calm periods, ensuring both security and sustainability.

What the Improved AI System Can Do:

It can operate in cellular networks (e.g., O-RAN RIC) with a self-adaptive defense mechanism that explicitly accounts for energy consumption, maintaining high ML accuracy and robustness against data manipulation while reducing operational energy costs by 20–50% compared to static defense strategies. It can also provide network operators with real-time dashboards showing the accuracy-robustness-energy trade-off, enabling informed decisions on security vs. sustainability.

Abstract

The integration of Artificial Intelligence (AI), generally as Machine Learning (ML) algorithms, in all levels and aspects of cellular networks demonstrates the success of data-driven algorithms; for example, the Radio Intelligence Controller (RIC) of the O-RAN paradigm bestows the network with optimised radio resource allocation, load balancing or energy efficiency functions, among others. Nevertheless, this dependency on data opens new security vulnerabilities, as attackers can alter data properties and steer ML models to underperform or degrade. Conversely, the developed mitigation strategies are effective, but they generate a computational load which, in consequence, results in an energy cost generally overlooked, even in the current energy-awareness context. In this work, consumption of a defence technique is characterised, and the challenges raised by the triad of ML accuracy, robustness and energy efficiency are outlined.

Sources

Related papers