Tech

UCD NetsLab founder on the future of network security

Published

on

Its a misconception that cybersecurity can simply be added once a new technology is complete.

Prof Dr Madhusanka Liyanage’s work at University College Dublin involves researching how future communication networks can be secured and reinforced.

Liyanage’s academic career has taken him across the world, beginning with a degree in electronic and telecommunication engineering at the University of Moratuwa in Sri Lanka, then postgraduate courses in telecommunications engineering at the Asian Institute of Technology in Thailand and ubiquitous networking and computing at Université de Nice Sophia Antipolis in France.

Following this, he completed his Doctor of Science in Technology at the University of Oulu in Finland, focusing on scalable security in communication networks. Today, he works as a professor of network security at UCD and leads the University’s NetsLab – which he founded – where he work across the future network security.

Advertisement

“A major part of my work is also building research communities. I have supervised and mentored researchers at different career stages, contributed to international standardisation and cybersecurity activities, and worked closely with industry,” he says.

“I am particularly interested in ensuring that research does not remain only in academic publications but progresses towards technologies, standards and commercial solutions that can have a real-world impact.”

What inspired you to become a researcher?

I have loved mathematics since childhood. It was something that came naturally to me, and I particularly enjoyed solving difficult problems and finding answers that were not immediately obvious.

One experience that had a strong influence on me was representing Sri Lanka at the International Mathematical Olympiad (IMO) in Athens in 2004. It gave me the opportunity to meet talented young mathematicians from around the world and experience an international scientific community at a very young age. I have also always loved travelling, meeting people and experiencing different cultures, so that experience showed me how science could open doors to the wider world.

Advertisement

Looking back, research fits my personality very naturally. I enjoy discovering new things and working on problems where the answer is not already known. I also value the independence research gives me to choose important problems, develop my own ideas and pursue areas that genuinely interest me.

Research also combines two things I particularly enjoy: travelling with a purpose and collaborating globally. Academic work has allowed me to visit many countries, work with researchers from different cultures and build international collaborations around shared scientific challenges.

Can you tell us about the research you’re currently working on?

My main research focus is the security and privacy of future mobile networks. A significant part of this work is now moving towards AI-native security and autonomous network resilience.

Future networks will increasingly use AI not simply as an application running over the network, but as part of the network itself. AI will help networks optimise resources, detect attacks, make decisions and potentially respond to security incidents automatically.

Advertisement

I currently coordinate ‘Shield-6G’, a major European research project developing security technologies for future 6G networks. One of our ambitions is to move from networks that simply detect cyberattacks towards networks that can understand threats, assess their impact and autonomously adapt their defences.

At the same time, my research is evolving towards what I describe as sustainable security-by-design. Security mechanisms themselves can consume significant computing power and energy. For example, large AI models, continuous cybersecurity monitoring, federated learning and post-quantum cryptography can all impose additional computational and energy costs.

My current research therefore asks a broader question: How do we build 6G systems that are secure, intelligent and resilient, while also being sustainable, explainable, legally compliant and economically practical?

We are investigating areas including energy-efficient AI security, federated and distributed intelligence, explainable cybersecurity, post-quantum security, zero-trust architectures and regulatory compliance.

Advertisement

This work is very interdisciplinary. My team collaborates with researchers in AI, cybersecurity, telecommunications, distributed systems and privacy, as well as telecommunications operators, technology companies, SMEs and international research partners.

In your opinion, why is your research important?

6G is expected to become part of the fundamental digital infrastructure supporting society in the 2030s and beyond.

We are not simply talking about faster mobile phones. Future networks could support autonomous transport, industrial automation, connected healthcare, digital twins, intelligent cities, robotics, immersive applications and enormous numbers of interconnected devices.

That also means that a cybersecurity failure could have consequences far beyond losing access to the internet. A compromised communication network could potentially disrupt transportation, healthcare, energy systems or other critical infrastructure.

Advertisement

At the same time, the nature of cyberattacks is changing. Attackers can also use AI to automate attacks, discover vulnerabilities, manipulate data or target the AI models controlling future networks.

This is why I believe security must be designed into 6G from the beginning, rather than added after the technology has been developed.

There is also a question of trust. If an AI system automatically blocks a service, isolates part of a network or makes another security-critical decision, operators and users need to understand why that decision was made. Security therefore has to include not only protection against attacks but also explainability, privacy, accountability, resilience and regulatory compliance.

Ultimately, my research is about making sure that society can benefit from the enormous opportunities offered by future connectivity without compromising security, privacy or trust.

Advertisement
Tell us about your work as the director of NetsLab

I founded and lead the Network Softwarization and Security Labs (NetsLab) at UCD, with a primary focus on security and privacy for future 5G and 6G communication networks.

One thing I am particularly proud of is that NetsLab has developed into a highly international research environment and one of the world’s leading 5G/6G security research labs. Our researchers span Ireland, Finland, Sri Lanka, India and Belgium, and we work closely with both academic and industrial partners across the globe.

An important aspect of NetsLab is combining theoretical research with real experimentation. We have developed a private mobile network and a 5G/6G AI-RAN research testbed at UCD, which allows researchers to evaluate new cybersecurity and networking technologies under realistic conditions rather than relying entirely on simulations.

We also actively encourage joint experimentation with industry. Companies can work with our researchers to integrate technologies into the testbed, conduct experiments, validate cybersecurity solutions and investigate how new ideas perform in realistic mobile-network environments. This provides an important bridge between academic research and industrial deployment.

Advertisement

I also see my role as Director as being much broader than managing projects. I want NetsLab to be an environment where PhD students and early-career researchers can develop their own ideas, lead research activities, collaborate internationally, work directly with industry and, where appropriate, take their research towards commercialisation. Building researchers is as important to me as building technology.

What commercial applications do you foresee for your research?

Commercialisation is already becoming an important outcome of our research, rather than something I see only as a future possibility. NetsLab has already been the home for several start-ups.

One example is GenShield AI, where research in AI-driven cybersecurity is being translated into practical tools for testing and protecting AI-enabled systems. We are currently progressing the technology and developing products that can move beyond research prototypes towards solutions that organisations can actually deploy.

Another good example is Luxima, which shows how we can take expertise developed in AI, automation, data management and trustworthy digital systems and apply it well beyond our traditional telecommunications and cybersecurity domains. The platform uses AI to automate EU Digital Product Passports, including filling missing product and sustainability information and integrating with existing business systems such as ERP and GS1 platforms.

Advertisement

For me, this is an important example of how research expertise can cross disciplinary boundaries and be transformed into practical solutions for entirely different industries. It also demonstrates how the knowledge we develop through research can create new commercial opportunities in areas such as sustainability, regulatory compliance and digital product traceability..

Looking ahead, I see several particularly strong commercial opportunities. One is AI-based anomaly detection. Future networks will generate enormous amounts of operational and security data, making it increasingly difficult for human teams to manually identify sophisticated attacks or abnormal behaviour.

Intelligent systems capable of continuously learning what constitutes normal behaviour and detecting deviations could become an important component of future telecommunications and critical-infrastructure security.

Another major opportunity is post-quantum cybersecurity testing. Organisations will eventually need to understand whether their existing systems, devices and applications are prepared for the transition to quantum-resistant cryptography.

Advertisement

This creates opportunities for platforms that can test cryptographic readiness, identify vulnerabilities, evaluate post-quantum algorithms and support organisations during the migration towards quantum-safe systems. There are also strong opportunities around AI security testing, explainable cybersecurity, privacy-preserving federated learning, zero-trust architectures and Security-as-a-Service.

Our objective is therefore not simply to publish research. Where appropriate, I want to see our research progress through the entire innovation pipeline – from an academic idea, to an experimental prototype, to testbed validation, intellectual property, a commercial product and ultimately a technology that organisations can use.

What are some of the biggest challenges you face as a researcher in your field?

One of the biggest challenges is that the technology and the threat landscape are developing simultaneously.

We are trying to secure networks that do not fully exist yet. Researchers are currently defining 6G architectures while AI technologies, quantum computing, cloud-edge systems and cybersecurity threats are all evolving at extraordinary speed.

Advertisement

A second challenge is balancing competing requirements. The most secure solution is not necessarily practical if it introduces excessive latency, requires enormous computing resources or consumes too much energy. Future security therefore has to balance protection, performance, scalability, energy consumption and cost.

AI creates another difficult challenge. AI can make cybersecurity significantly more adaptive and autonomous, but AI systems themselves can be attacked, manipulated or deceived. If we allow AI to make security-critical decisions, we also need mechanisms to explain, audit and challenge those decisions.

Post-quantum security presents a similar problem. Moving towards quantum-resistant cryptography is necessary, but introducing new cryptographic mechanisms across billions of devices and complex communication infrastructures will be a major engineering challenge.

Finally, research in this area cannot happen in isolation. Solutions have to work across different vendors, technologies and regulatory environments. That means researchers must increasingly work with industry, standards organisations, policymakers and other disciplines alongside traditional academic research.

Advertisement
You’ve had a wealth of experience studying across universities globally. Has that shaped how you approach your research work? 

Absolutely. I have studied and worked in several countries, including Sri Lanka, Thailand, France, Finland and Ireland, and I have collaborated extensively with universities and researchers across many other parts of the world.

That experience has given me much more than academic knowledge. It has allowed me to experience different cultures, different approaches to research and different ways of working.

Research culture can vary significantly between regions. Expectations around independence, teamwork, communication, supervision, deadlines and research quality are not necessarily identical everywhere. Working in different systems has helped me understand the strengths of these different approaches and, importantly, understand the expectations and working styles of researchers and students coming from different backgrounds.

It has also helped me establish a very strong international network. Many collaborations that started through studying, visiting universities or working with researchers in different countries have developed into long-term research partnerships, joint publications, student exchanges and international research projects.

Advertisement

This experience is particularly valuable when leading a multinational research group. NetsLab includes researchers from many different cultural and educational backgrounds. Understanding these differences helps me create a more balanced team, communicate expectations clearly and provide different researchers with the type of support they need to perform at their best.

I have also learned that there is no single research culture that has all the answers. Different systems have different strengths. I try to combine the best elements I have experienced – strong scientific standards, independence, collaboration, openness, practical experimentation and international engagement.

Ultimately, working across different countries has made me a much more internationally minded researcher and has helped me build the diverse, multinational research environment that we have today.

Are there any common misconceptions about this area of research? How would you address them?

Advertisement

One misconception is that 6G simply means a faster version of 5G.

Speed will be only one aspect of 6G. The bigger transformation is likely to come from intelligence, automation and the integration of communication, sensing, computing and AI. Networks themselves will increasingly make decisions and adapt to their environments.

Another misconception is that cybersecurity can simply be added once a new technology is complete. History repeatedly shows us that this approach is extremely difficult and expensive. Security, privacy and resilience need to be considered during the architectural design process.

There is also sometimes an assumption that AI will solve cybersecurity automatically. AI is extremely powerful, but it introduces its own vulnerabilities. AI models can be poisoned, manipulated, deceived or biased. An intelligent defence system therefore also needs to be secured.

Advertisement

And finally, perfect security does not exist. The objective is not to build a network that can never be attacked. The aim is to build systems that can prevent as many attacks as possible, detect attacks quickly, understand what is happening, limit the damage and recover rapidly.

That idea of resilience will become increasingly important as networks become more autonomous.

What are some of the areas of research you’d like to see tackled in the years ahead?

One of the most important areas for me is resilience and autonomous networks.

Advertisement

Future networks will become too large, dynamic and complex to depend entirely on humans responding manually to every cybersecurity incident. I would like to see networks evolve from systems that simply detect attacks and generate alerts towards systems that can detect, understand, respond to and recover from attacks autonomously.

The important word here is resilience. It may not always be possible to prevent every attack. Future systems therefore need the ability to continue operating during an attack, isolate compromised components, reorganise themselves, recover services and learn from what happened.

This becomes particularly interesting as AI agents become part of network operations. We could eventually have networks in which intelligent agents continuously monitor the infrastructure, analyse threats and coordinate defensive actions. However, those autonomous decisions must themselves be secure, explainable and subject to appropriate human oversight.

The second major area I would like to see accelerated is post-quantum security and crypto-agility.

Advertisement

Many communication systems being designed today may still be operational when sufficiently powerful quantum computers become available. We therefore need to prepare those systems now. The challenge is not simply inventing post-quantum algorithms; it is understanding how to deploy them across enormous, heterogeneous infrastructures containing billions of devices.

Crypto-agility will be particularly important. Future systems should be able to change cryptographic algorithms and security mechanisms without requiring the entire infrastructure to be replaced. Ideally, networks should be capable of identifying cryptographic weaknesses and migrating towards stronger mechanisms in a controlled and increasingly automated way.

Beyond these two areas, I see major opportunities in AI security, privacy-preserving distributed intelligence, explainable cybersecurity, sustainable security and automated regulatory compliance.

My longer-term vision is a future communication network that is not simply fast and intelligent, but secure, resilient, autonomous, quantum-ready and trustworthy by design.

Advertisement

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version