Skip to main navigation Skip to search Skip to main content

A Lightweight Language-Model-Driven Agentic Framework for Intrusion Prediction, Detection, and Mitigation in 6G-Enabled IoT Networks

  • Alaeddine Diaf
  • , Abdelaziz Amara Korba
  • , Wael Jaafar
  • , Nour Elislem Karabadji
  • , Yacine Ghamri-Doudane
  • Badji Mokhtar University
  • Computer Science Department
  • German University of Technology
  • National Higher School of Technology and Engineering
  • Laboratoire De Technologies Des Systèmes Énergétiques (LTSE) E3360100
  • Université de La Rochelle

Research output: Contribution to journalJournal Articlepeer-review

Abstract

The extensive deployment of Internet of Things (IoT) devices in emerging 6G-enabled environments, characterized by massive connectivity, distributed edge intelligence, and ultra-low-latency communication, allows cyber threats to evade detection until malicious activities manifest. Conventional intrusion detection systems remain fundamentally reactive, identifying threats only after suspicious patterns become observable in network traffic, which hinders both proactive threat anticipation and timely mitigation. To address these limitations, this paper proposes a role-based multi-agent cybersecurity framework for 6G-enabled IoT networks that enables proactive intrusion prediction, real-time detection, and knowledge-driven threat mitigation. The framework establishes a coordinated defense loop composed of three specialized agents: (i) a prediction agent that leverages Small Language Models (SLMs) to model packet-level temporal dependencies and proactively forecast malicious traffic sequences, (ii) a detection agent that performs real-time traffic classification using a lightweight gradient boosting model suitable for low-latency edge environments, and (iii) a knowledge graph-driven mitigation agent that maps detected threats to corresponding defensive countermeasures. Extensive evaluation on the CICIoT2023 dataset demonstrates the effectiveness of the proposed framework, achieving 98.24% accuracy in proactive packet-level detection using forecasted packets and 99.94% accuracy in real-time flow-based detection. The proposed framework combines structured multi-agent coordination, low-latency inference, and knowledge-driven response, making it a promising step toward scalable and intelligent cybersecurity management in 6G-enabled IoT networks.

Original languageEnglish
Pages (from-to)10178-10192
Number of pages15
JournalIEEE Open Journal of the Communications Society
Volume7
DOIs
Publication statusPublished - 2026

!!!Keywords

  • agentic AI
  • attack mitigation
  • autonomous cyber defense
  • intrusion prediction
  • IoT
  • LLMs
  • Security
  • SLMs

Fingerprint

Dive into the research topics of 'A Lightweight Language-Model-Driven Agentic Framework for Intrusion Prediction, Detection, and Mitigation in 6G-Enabled IoT Networks'. These topics are generated from the title and abstract of the publication. Together, they form a unique fingerprint.

Cite this