Yuhui Wang (Department of Electrical and Computer Engineering, University of Michigan-Dearborn), Xingqi Wu (Department of Electrical and Computer Engineering, University of Michigan-Dearborn), Junaid Farooq (Department of Electrical and Computer Engineering, University of Michigan-Dearborn), Juntao Chen (Department of Computer and Information Sciences, Fordham University)

Large language models (LLMs) are increasingly being integrated into Open Radio Access Network (O-RAN) control loops to enable intent driven automation for resource management and network slicing. However, deploying LLMs within the Near-Real-Time RAN Intelligent Controller (Near- RT RIC) introduces a new control plane vulnerability. Because LLM driven xApps process untrusted telemetry and shared state information, adversaries can exploit prompt injection attacks to manipulate control logic, resulting in unauthorized resource allocation and slice isolation violations. This paper presents PROMPTGUARD, a Zero Trust (ZT) prompting framework for securing LLM driven O-RAN control. PROMPTGUARD is realized as a semantic verification xApp that enforces continuous intent validation on all LLM bound inputs by treating every prompt as potentially adversarial. We implement PROMPTGUARD on the OpenAI Cellular (OAIC) platform and evaluate its effectiveness against multiple prompt injection attacks under strict latency constraints. Results show that PROMPTGUARD mitigates adversarial prompts with high accuracy while preserving the O-RAN latency requirements, establishing ZT prompting as a foundational security primitive for AI-native RANs.

View More Papers

Breaking Isolation: A New Perspective on Hypervisor Exploitation via...

Gaoning Pan (Hangzhou Dianzi University & Zhejiang Provincial Key Laboratory of Sensitive Data Security and Confidentiality Governance), Yiming Tao (Zhejiang University), Qinying Wang (EPFL and Zhejiang University), Chunming Wu (Zhejiang University), Mingde Hu (Hangzhou Dianzi University & Zhejiang Provincial Key Laboratory of Sensitive Data Security and Confidentiality Governance), Yizhi Ren (Hangzhou Dianzi University & Zhejiang…

Read More

Distributed Broadcast Encryption for Confidential Interoperability across Private Blockchains

Angelo De Caro (IBM Research Zurich), Kaoutar Elkhiyaoui (IBM Research Zurich), Sandeep Nishad (IBM Research India), Sikhar Patranabis (IBM Research India), Venkatraman Ramakrishna (IBM Research India)

Read More

ReFuzz: Reusing Tests for Processor Fuzzing with Contextual Bandits

Chen Chen (Texas A&M University, USA), Zaiyan Xu (Texas A&M University, USA), Mohamadreza Rostami (Technische Universitat Darmstadt, Germany), David Liu (Texas A&M University, USA), Dileep Kalathil (Texas A&M University, USA), Ahmad-Reza Sadeghi (Technische Universitat Darmstadt, Germany), Jeyavijayan (JV) Rajendran (Texas A&M University, USA)

Read More