Real-time network anomaly detection in O-RAN using deep learning on streaming big data

Main Article Content

Satya Sumanth Vanapalli

sumanthvanapalli074@gmail.com

https://orcid.org/0009-0006-5993-3456
Rajesh Polepogu

rajeshpolepogu@vrsiddhartha.ac.in

https://orcid.org/0000-0003-3440-9296
Parish Venkata Kumar K

kpvk@vrsiddhartha.ac.in

https://orcid.org/0000-0002-0454-4908
Vijayasankar Anumala

vijayasankar.anumala@gmail.com

https://orcid.org/0000-0002-1483-1708
Vinodh Babu Panguluri

panguluri.v@gmail.com

https://orcid.org/0000-0003-2911-1479
Lakshmi Narayana Jammula

Jln_9976@yahoo.com

https://orcid.org/0009-0006-6551-4434
Brahmaiah Madamanchi

madamanchib@gmail.com

https://orcid.org/0000-0001-9938-9914
Sravani Duvvu

sravani.duvvu35@gmail.com

Bhanusree Nanduri

bhanusree.nanduri2005@gmail.com

https://orcid.org/0009-0009-3976-4159
Syam Sundar Musinala

musinalasyamsundar2004@gmail.com

https://orcid.org/0009-0006-5993-3456

Abstract

The growing adoption of Open Radio Access Network (O-RAN) architecture in next-generation wireless systems offers unprecedented flexibility and openness, enabling real-time control and intelligent network functions. However, the decentralized and multi-vendor nature of O-RAN also increases the surface for network anomalies, including service degradations, misconfigurations, cyber threats, and radio interference. Traditional monitoring tools lack the scalability and responsiveness to process heterogeneous, high-velocity telemetry from RAN Intelligent Controllers (RICs), Distributed Units (DUs), and User Equipment (UE). This research proposes a novel real-time anomaly detection framework that integrates streaming big data pipelines with deep learning-based temporal models to detect and localize anomalies within the O-RAN ecosystem. Leveraging platforms like Apache Kafka and Apache Flink for high-throughput data ingestion and processing, the system applies Long Short-Term Memory (LSTM) and Temporal Convolutional Networks (TCNs) to learn temporal behavior from real-time Key Performance Indicators (KPIs), signal logs, and E2 interface events. The model is trained using both real and synthetic datasets generated from O-RAN emulators and validated in an emulated 5G environment with open-source xApps. Additionally, the framework incorporates an adaptive feedback mechanism between the Near-Real-Time RIC and Non-Real-Time RIC via A1 and E2 interfaces, enabling continuous learning and dynamic policy adaptation. The proposed solution demonstrates over 95% anomaly detection accuracy with sub-second latency, outperforming traditional statistical baselines. This work provides a scalable, vendor-agnostic, and future-proof anomaly detection system for intelligent RAN management, marking a significant step toward self-healing and self-optimizing networks in 5G and beyond.

Keywords:

O-RAN, anomaly detection, streaming big data, LSTM, TCN, real-time monitoring

References

Article Details

Vanapalli, S. S., Polepogu, R., K, P. V. K., Anumala, V., Panguluri, V. B., Jammula, L. N., Madamanchi, B., Duvvu, S., Nanduri, B., & Musinala, S. S. (2026). Real-time network anomaly detection in O-RAN using deep learning on streaming big data. Informatyka, Automatyka, Pomiary W Gospodarce I Ochronie Środowiska, 16(3), 150-158. https://doi.org/10.35784/iapgos.8233