[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84137-en":3,"doc-seo-84137-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84137,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","ORAN-DEFEND Subspace Detection and Sanitization of Backdoor DRL xApps in Open RAN","Open Radio Access Networks (O-RAN) delegate near-real-time control to third-party deep reinforcement learning (DRL) xApps, expanding the supply-chain attack surface. ORAN-DEFEND defends a frozen potentially compromised xApp without retraining by sanitizing each KPI window through projection onto a safe subspace estimated from a few trusted clean rollouts via SVD. Analytically and empirically, recovery is guaranteed when trigger energy concentrates in the orthogonal complement, using E⊥ energy fraction as a quantified boundary. On COLORAN, four distinct DRL backdoor attacks achieve 100% return recovery and ≥99.5% defense success under the subspace assumption, and an ablation reveals a linear-projection limit.","ORAN-DEFEND: Subspace Detection and Sanitization of Backdoor DRL xApps in Open RAN  \nMd Raihan Uddin, Fatemeh Lotfi, Tolunay Seyfi, Fatemeh Afghah  \nDepartment of Electrical and Computer Engineering, Clemson University, Clemson, SC, USA {uddin2,flotfi,tseyfi,fafghah}@clemson.edu  \narXiv :2607 .06647v 1 [ cs .CR] 7 Jul 2026  \nAbstract—Open Radio Access Networks (O-RAN) increasingly delegate near-real-time control to deep reinforcement learning (DRL) xApps obtained from third-party vendors, creating a new supply-chain attack surface. A backdoor policy behaves optimally until an adversary injects a covert trigger into the observed key performance indicator (KPI) telemetry, at which point it issues harmful control actions that degrade quality of service (QoS). We present ORAN-DEFEND, a retraining-free wrapper that sanitizes a frozen, potentially compromised xApp by projecting each KPI window onto a safe subspace estimated from a small number of trusted clean rollouts via singular value decomposition (SVD). We establish, both analytically and empirically, a precise recovery condition: the defense succeeds if the trigger energy concentrates in the orthogonal complement of the safe subspace, and we quantify this boundary through the trigger’s E ⊥ energy fraction. On the Colosseum COLORAN dataset, we evaluate four structurally distinct DRL backdoor attacks, like TrojDRL, SleeperNets, BadRL, and Q-Incept, spanning inner-loop and outer-loop poisoning regimes and demonstrate 100% return recovery and ≥ 99.5% defense success rate across all four when the subspace assumption holds. A geometry ablation reveals an intrinsic and previously uncharacterized limit of any linear projection defense: when the trigger collocates with the legitimate signal, the E ⊥ energy fraction governs recovery monotonically, and the linear residual detector collapses to chance even while anonlinear classifier retains perfect separability.  \nIndex Terms—O-RAN, reinforcement learning security, backdoor attacks, subspace sanitization, trustworthy AI, xApp.  \nI. INTRODUCTION  \nThe Open Radio Access Network (O-RAN) initiative disaggregates the cellular radio access network into vendor-neutral, software-defined components coordinated by RAN Intelligent Controllers (RICs) [1] . The Near Real-Time RIC (Near-RT RIC) executes xApps closed-loop control applications that consume telemetry from the key performance indicator (KPI) of the user equipment (UE) and make decisions regarding the scheduling, beam-management and allocation of radio resources on timescales 10 ms – 1 s. Deep reinforcement learning (DRL) has emerged as the dominant framework for synthesizing these xApp policies, owing to its capacity to optimize long-horizon quality-of-service (QoS) objectives directly from telemetry without an explicit network model [2]–[6] . The computational cost of training high-performing DRL agents, however, substantially exceeds what individual operators can sustain, driving a growing market in pretrained xApp policies distributed by third-party vendors and open model repositories. This procurement model introduces a qualitatively new attack surface.  \nA. Related Work  \nBackdoor attacks in Machine Learning. Backdoor attacks, first demonstrated by BadNets [7], insert a hidden trigger-label association during training so that a compromised  \nThis work is supported by National Science Foundation under Grant Numbers CNS-2202972, CNS-2318726, and CNS-2232048 .  \nmodel behaves normally on clean inputs but maps triggerstamped inputs to an attacker-chosen output. Trojaning attacks [8] extend this to internal neuron manipulation. The threat is acute whenever users obtain pretrained models from untrusted sources.  \nBackdoor Attacks in Deep Reinforcement Learning.  \nExtending backdoors to DRL is non-trivial: the adversary must corrupt the agent’s policy rather than a static classifier, and harm manifests through long-horizon cumulative return rather than a single misclassification. In what fo","cbCaikbALLORiTHD","https://ap.wps.com/l/cbCaikbALLORiTHD","pdf",408147,5,1,6,"English","en",105,"# Introduction\n## Related Work\n## Motivation and Contributions","[{\"question\":\"What supply-chain threat does ORAN-DEFEND address in Open RAN?\",\"answer\":\"ORAN control can be compromised when third-party vendors supply backdoored DRL xApps. The backdoor remains optimal until an adversary injects a covert trigger into KPI telemetry, then outputs harmful control actions that degrade QoS.\"},{\"question\":\"How does ORAN-DEFEND sanitize a potentially compromised DRL xApp without retraining?\",\"answer\":\"It wraps the frozen xApp with a projection-based sanitizer. Each KPI window is projected onto a safe subspace estimated from a small set of trusted clean rollouts using SVD.\"},{\"question\":\"Under what condition does the defense recover the correct behavior against backdoor triggers?\",\"answer\":\"The defense succeeds when the trigger energy concentrates in the orthogonal complement of the safe subspace. The paper quantifies the boundary using the trigger’s E⊥ energy fraction and shows recovery performance on the COLORAN dataset across multiple attacks.\"}]",1784193259,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"oran-defend-subspace-detection-and-sanitization-of-backdoor-drl-xapps-in-open-ran","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/oran-defend-subspace-detection-and-sanitization-of-backdoor-drl-xapps-in-open-ran/84137/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What supply-chain threat does ORAN-DEFEND address in Open RAN?","Question",{"text":76,"@type":77},"ORAN control can be compromised when third-party vendors supply backdoored DRL xApps. The backdoor remains optimal until an adversary injects a covert trigger into KPI telemetry, then outputs harmful control actions that degrade QoS.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does ORAN-DEFEND sanitize a potentially compromised DRL xApp without retraining?",{"text":81,"@type":77},"It wraps the frozen xApp with a projection-based sanitizer. Each KPI window is projected onto a safe subspace estimated from a small set of trusted clean rollouts using SVD.",{"name":83,"@type":74,"acceptedAnswer":84},"Under what condition does the defense recover the correct behavior against backdoor triggers?",{"text":85,"@type":77},"The defense succeeds when the trigger energy concentrates in the orthogonal complement of the safe subspace. The paper quantifies the boundary using the trigger’s E⊥ energy fraction and shows recovery performance on the COLORAN dataset across multiple attacks.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,114,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":20,"slug":137},19,"General","general"]