[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82448-en":3,"doc-seo-82448-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82448,7971461741311,"Ophelia","https://ap-avatar.wpscdn.com/avatar/74000253aff267980c6?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345379180704826",8,"Research & Report","Impact of Benign Connectivity Variations on Intrusion Detection for Encrypted OPC UA Traffic in Industrial Private 5G Networks","Machine learning–based intrusion detection systems for encrypted industrial communication are increasingly deployed, yet their behavior in realistic private 5G operating conditions is not well understood. This paper studies how benign connectivity variations affect ML-based IDS performance for encrypted OPC UA traffic in industrial private 5G networks. Experimental results show legitimate connectivity events can substantially increase false positives even without attacks, and elevated anomaly scores often align with control-plane activity.","IMPACT OF BENIGN CONNECTIVITY VARIATIONS ON INTRUSION DETECTION FOR ENCRYPTED OPC UA TRAFFIC IN INDUSTRIAL  \nPRIVATE 5G NETWORKS  \nA PREPRINT  \narXiv :2607 .09659v 1 [ cs .CR] 10 Jul 2026  \n Song Son Ha  \nElectrical Measurement Engineering Helmut-Schmidt-University Hamburg, Germany [song.ha@hsu-hh.de](song.ha@hsu-hh.de)  \n Henry Beuster  \nElectrical Measurement Engineering Helmut-Schmidt-University Hamburg, Germany [henry.beuster@hsu-hh.de](henry.beuster@hsu-hh.de)  \n Florian Foerster  \nInstitute for Innovative Safety and Security Technical University of Applied Sciences Augsburg Augsburg, Germany [florian.foerster@tha.de](florian.foerster@tha.de)  \nTim Kittel  \nipoque GmbH A Rohde & Schwarz company Leipzig, Germany [tim.kittel@rohde-schwarz.com](tim.kittel@rohde-schwarz.com)  \n Dominik Merli  \nInstitute for Innovative Safety and Security Technical University of Applied Sciences Augsburg Augsburg, Germany [dominik.merli@tha.de](dominik.merli@tha.de)  \nGerd Scholl  \nElectrical Measurement Engineering Helmut-Schmidt-University Hamburg, Germany [gerd.scholl@hsu-hh.de](gerd.scholl@hsu-hh.de)  \nJuly 10, 2026  \nABSTRACT  \n1 Machine learning (ML)-based intrusion detection systems (IDSs) are increasingly used to monitor encrypted industrial communication. However, their behavior under realistic private 5G operating conditions remains insufficiently understood. This paper investigates the impact of benign connectivity variations on ML-based IDSs for encrypted Open Platform Communications Unified Architecture (OPC UA) traffic in industrial private 5G networks. Experimental results show that legitimate connectivity events can noticeably increase false positive activity despite the absence of attacks.  \nFurthermore, elevated IDS anomaly scores frequently coincide with periods of control-plane (CP) activity associated with these events. The findings highlight the importance of considering CP context when interpreting IDS outputs in industrial private 5G environments.  \n1 Introduction  \nThe increasing adoption of private 5G networks in industrial environments enables flexible and reliable connectivity for a wide range of industrial applications. In these environments, OPC UA is widely used to support industrial communication and commonly employs message-level security mechanisms to protect sensitive industrial data flows [1] . While such protection enhances confidentiality, it also limits the effectiveness of traditional IDSs that rely on payload inspection. ML-based IDSs have therefore emerged as promising solutions for OPC UA intrusion detection. However, these systems are typically trained under baseline conditions, an assumption that rarely holds in private 5G  \n1This is the author’s version of a paper that has been accepted for presentation at the 31st IEEE International Conference on Emerging Technologies and Factory Automation (ETFA 2026), to be held in Västerås, Sweden, on September 08–11, 2026 .  \ndeployments where benign connectivity variations, such as UE reconnection procedures, PDU session resets, and temporary connectivity interruptions, may occur during normal operation. Although these events are not malicious, they can alter traffic patterns and potentially increase false positive rates (FPR) . This work investigates the impact of benign connectivity variations on ML-based IDS outputs for encrypted OPC UA traffic in the absence of attacks. The results show that benign connectivity variations increase false positive activity and that elevated IDS anomaly scores frequently coincide with periods of CP activity. These findings highlight the importance of considering CP context when interpreting IDS outputs in industrial private 5G environments.  \nThe remainder of this paper is organized as follows. Section 2 reviews related work, Sections 3 and 4 describe the methodology and experimental setup, Section 5 presents the evaluation results, and Section 6 concludes the paper and outlines future work.  \n2 Related Work  \nMonitoring app","cbCaid0ZBHu9wP71","https://ap.wps.com/l/cbCaid0ZBHu9wP71","pdf",189203,3,1,7,"English","en",105,"# Abstract\n# Introduction\n# Related Work\n# Proposed Methodology\n## Experimental Workflow","[{\"question\":\"Why can benign connectivity events increase IDS false positives for encrypted OPC UA traffic?\",\"answer\":\"Benign connectivity variations change observable traffic patterns even without attacks, causing the ML-based IDS—trained on baseline conditions—to flag normal behavior as anomalous, which raises the false positive activity.\"},{\"question\":\"What role does control-plane (CP) activity play in IDS outputs?\",\"answer\":\"Elevated IDS anomaly scores frequently coincide with control-plane activity periods associated with connectivity events. This indicates CP context is important when interpreting IDS results in private 5G environments.\"},{\"question\":\"How is encrypted OPC UA traffic used for the machine learning IDS evaluation?\",\"answer\":\"Encrypted OPC UA traffic is segmented into consecutive 5-second time windows, converted into statistical feature vectors for the IDS, and assessed under controlled benign connectivity variation scenarios to measure the impact on false positive rate.\"}]",1784180435,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"impact-of-benign-connectivity-variations-on-intrusion-detection-for-encrypted-opc-ua-traffic-in-industrial-private-5g-networks","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/impact-of-benign-connectivity-variations-on-intrusion-detection-for-encrypted-opc-ua-traffic-in-industrial-private-5g-networks/82448/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why can benign connectivity events increase IDS false positives for encrypted OPC UA traffic?","Question",{"text":75,"@type":76},"Benign connectivity variations change observable traffic patterns even without attacks, causing the ML-based IDS—trained on baseline conditions—to flag normal behavior as anomalous, which raises the false positive activity.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What role does control-plane (CP) activity play in IDS outputs?",{"text":80,"@type":76},"Elevated IDS anomaly scores frequently coincide with control-plane activity periods associated with connectivity events. This indicates CP context is important when interpreting IDS results in private 5G environments.",{"name":82,"@type":73,"acceptedAnswer":83},"How is encrypted OPC UA traffic used for the machine learning IDS evaluation?",{"text":84,"@type":76},"Encrypted OPC UA traffic is segmented into consecutive 5-second time windows, converted into statistical feature vectors for the IDS, and assessed under controlled benign connectivity variation scenarios to measure the impact on false positive rate.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]