GN5-2 Intelligent Networks: The Rise of Generative AI in Network Management
Abstract
Generative AI is reshaping the landscape of network management, enabling systems that analyse and create configurations, reason on fault resolutions and traffic patterns, and proactively respond to emerging threats. This white paper provides a state-of-the-art review of the use of generative AI through the scope of the FCAPS framework. The aim is to present and highlight current capabilities and research directions, as well as identify the challenges of integrating these technologies into real-world networks.
Full text
© GÉANT Association on behalf of the GN5-2 project. The research leading to these results has received funding from the European Union’s Horizon Europe research and innovation programme under Grant Agreement No. 101194278 (GN5-2). Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. The European Union cannot be held responsible for them. 13-10-2025 Intelligent Networks: The Rise of Generative AI in Network Management Grant Agreement No.: 101194278 Work Package: WP6 Task Item: T1 Nature of Document: White Paper Dissemination Level: PU Document ID: GN5-2-25-11LABC Authors: Sonja Filiposka (UKIM); Dimitrios Pantazatos (NTUA); Pavle Vuletić (UoB); Vincent Burkard (FAU); Claudia Torres Perez (i2Cat); Ivana Golub (PCSS) Abstract Generative AI is reshaping the landscape of network management, enabling systems that analyse and create configurations, reason on fault resolutions and traffic patterns, and proactively respond to emerging threats. This white paper provides a state-of-the-art review of the use of generative AI through the scope of the FCAPS framework. The aim is to present and highlight current capabilities and research directions, as well as identify the challenges of integrating these technologies into real-world networks.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC ii Contents Executive Summary 1 1 Introduction 2 1.1 Enter Generative AI 2 1.2 Why They Matter for Network Management 2 1.3 Aim and Organisation of This Review 3 1.4 Scope and Methodology 3 2 Evolution of Generative AI in Networking 4 2.1 Generative AI Models for Network Management 4 2.2 Benefits and Challenges 5 3 Fault Management 7 3.1 Opportunities for Generative AI 7 3.2 Review of GenAI Techniques and Models 8 3.3 Strengths and Open Challenges 9 4 Configuration Management 10 4.1 Opportunities for Generative AI 10 4.2 Review of GenAI Techniques and Models 12 4.3 Strengths and Open Challenges 15 5 Accounting Management 17 6 Performance Management 18 6.1 Opportunities for Generative AI 18 6.2 Review of GenAI Techniques and Models 19 6.3 Strengths and Open Challenges 20 7 Security Management 22 7.1 Opportunities for Generative AI 22 7.2 Review of GenAI Techniques and Models 23 7.3 Strengths and Open Challenges 25 8 AI Tools for Network Management 26 8.1 Fault, Configuration, and Performance Management 27 8.2 Generative AI Tools for Security Management 33 9 Conclusions 37 Glossary 39 References 41
Contents Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC iii Figures Figure 3.1: Opportunities for GenAI in fault management 7 Figure 4.1: Potential uses of GenAI in configuration management 11 Figure 6.1: Potential uses of GenAI in network performance management 18 Tables Table 3.1: Comparative summary of recent papers on the topic of GenAI for fault management 8 Table 4.1: Comparative summary of recent papers on the topic of GenAI for configuration management 14 Table 6.1: Comparative summary of recent papers on the topic of GenAI for performance management 19 Table 7.1: Comparative summary of recent papers on GenAI for security management 24 Table 8.1: Classification of fault, configuration, and performance management tools based on GenAI 30 Table 8.2: Classification of security management tools 36
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 1 Executive Summary The recent shift to programmable infrastructure and policy-driven control has created new possibilities for dynamic, distributed, and service-rich network environments. However, this flexibility comes hand in hand with increasing management complexity. Operators are now responsible for a constantly changing ecosystem of devices, services, and constraints. Under these circumstances, traditional network automation and orchestration tools can benefit from the adoption of rapidly emerging Artificial Intelligence (AI)-based tools to help efficiently rise to the new generation of challenges. This white paper examines how Generative Artificial Intelligence (GenAI) is emerging as a potential supporting solution for the next generation of network management systems. Unlike traditional AI, which predicts or classifies based on input data, GenAI models can generate new, context-aware outputs. This ability enables them to synthesise configurations, simulate faults, and reinterpret telemetry into natural-language explanations. We provide a survey of the current state of GenAI research and available and emerging tools structured around the ISO FCAPS1 network management model. We examine how models such as Large Language Models (LLMs), Generative Adversarial Networks (GANs), Variational Autoencoders (VAEs), and Diffusion Models are being applied to networking problems, and we analyse their potential applicability to real-world problems. The research and tools summary analysis shows that GenAI application in network management looks promising. Research teams report high success rates in configuration generation and fault simulation, with LLM-based systems now reliably translating high-level intent into vendor-specific command syntax. GANs and VAEs are improving the availability and diversity of training data, while diffusion models are emerging as tools for QoSaware policy synthesis. Hybrid approaches are beginning to show how these models can work together to address complex, multi-step operational tasks. Across the FCAPS management areas – Fault, Configuration, Accounting, Performance and Security – the most mature and advanced applications of generative AI can be found in configuration and security management. In configuration, LLMs demonstrate strong potential in generating accurate, vendor-specific configurations from natural-language input. In security, generative models create realistic threat scenarios, synthetic attack traces, and anomaly datasets. Fault management is also evolving with generative models that simulate rare faults, generate plausible system logs, and support root cause analysis through co-pilot-style interfaces. In performance management, the use of generative models shows promise in traffic pattern generation, load forecasting, and adaptive retraining, although operational integration remains limited. Accounting management, in contrast, remains the least developed domain, but transferable techniques from other application domains indicate high potential for future development. It must be noted, however, that GenAI also introduces new challenges and responsibilities. Outputs must be validated and explainable, systems need to be integrated carefully into production environments, and the limits of synthetic data must be understood. 1 FCAPS is the ISO Telecommunications Management Network model and framework for network management. FCAPS stands for ‘Fault, Configuration, Accounting, Performance and Security’, management categories into which the ISO model defines network management tasks.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 2 1 Introduction Modern communication infrastructures are no longer monolithic stacks of routers and switches. They span heterogeneous radio, optical and cloud domains, and are orchestrated through layers of intent-driven automation. As a result, administrators must cope with dynamic traffic patterns, rapid service onboarding and ever-shorter control-loop deadlines—challenges that strain rule-based workflows and even classical predictive analytics [1] [2]. These pressures are fuelling demand for more intelligent, adaptive and proactive network-management solutions: platforms that can forecast faults, synthesise remediation policies, and optimise resources before users notice a problem. Early deployments already pair intent engines with machine-learning classifiers, but their effectiveness is often capped by the need for balanced training data and painstaking feature engineering [1]. 1.1 Enter Generative AI Generative artificial intelligence refers to models that not only predict labels from data but also create plausible new samples that follow the same underlying distribution. Where traditional AI answers “what is this packet?”, a generative model can answer “what other packets could exist in this scenario?” and then synthesise them. Prominent families include [3] [4]: • Large-Language Models (LLMs) that transform text or code sequences. • Generative Adversarial Networks (GANs) that learn to hallucinate realistic traffic traces or sensor readings. • Variational Autoencoders (VAEs) that embed network states into smooth latent spaces for anomaly detection or configuration search. • Diffusion models, which are made robust for constrained optimisation tasks such as wireless contract generation by their iterative denoising. 1.2 Why They Matter for Network Management Generative models excel when labelled data are scarce, objectives are multi-modal, or the solution space is too ample for exhaustive search [5], which are exactly the pain points of next-generation network operations. Recent studies show diffusion models drafting QoS-aware incentive contracts [6], GANs rebalancing heavily skewed intrusion datasets [7], and LLM co-pilots guiding human operators through complex root-cause analyses [8]. Crucially, pretrained models such as GPT-4, LLaMA-3 or Code-LLM can be fine-tuned on modest domain traces, dramatically lowering entry barriers for operators.
Introduction Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 3 1.3 Aim and Organisation of This Review This article surveys how generative AI is reshaping network management. We: • Define the landscape of generative techniques and summarise their theoretical advantages over purely predictive ML. • Map recent contributions to the classic ISO FCAPS matrix—Fault, Configuration, Accounting, Performance, Security—highlighting where GenAI delivers measurable gains and where gaps remain. • Identify cross-cutting trends and open challenges, including data-centric AI pipelines, adversarial robustness and ethical considerations. • Review contemporary commercial and open-source tools in the area of GenAI for network management. • Distil lessons for practitioners and outline future research directions towards fully autonomous, selfdriving networks. 1.4 Scope and Methodology In the first part of the analysis, we focus on peer-reviewed papers and influential preprints (2018-2025) that explicitly employ generative models for network-management tasks. Sources were selected through research searches using combinations of “generative”, “GAN”, “diffusion”, “LLM”, with “network management”, “orchestration” and FCAPS keywords. Studies were retained if they (i) reported quantitative results on real or emulated networks, (ii) targeted at least one FCAPS function, and (iii) offered code, data or methodological clarity sufficient for reproduction. In the second part, we focus on the analysis of both open-source and commercial tools within the fields of AIOps (Artificial Intelligence for IT Operations) and network performance management. In the remainder of this white paper, Section 2 offers a concise primer on generative modelling; Sections 3-7 analyse the contributions of GenAI to network management by FCAPS pillar; Section 8 is devoted to an overview of the existing commercial and open-source GenAI tools in the domain of network management; and Section 9 concludes with a summary of the research outlook and key practitioner takeaways.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 4 2 Evolution of Generative AI in Networking The use of AI in network management has evolved through several key phases [9]. Initially, automation was implemented using rule-based systems that offered fixed logic encoded by network engineers to trigger alarms, apply templates, or activate controls. These systems worked well for predictable scenarios but lacked adaptability to changes. The next wave came with machine learning (ML), where models could learn patterns from data, such as identifying anomalies or predicting link failures. These ML approaches are still very effective in specific tasks, but they are largely reactive and much dependent on labelled data and statically chosen features. The latest shift in network management approaches is toward generative AI, which enables models not just to classify or predict but to create. Generative AI can synthesise configurations, simulate traffic, draft documentation, and interact in natural language. Hence, this shift marks a fundamental transformation in how automation and decision-making can be approached in network operations. Unlike earlier systems that operated within predefined boundaries, generative models can propose novel, context-aware solutions tailored to unseen conditions. This allows automation to move beyond static playbooks and into adaptive workflows that can evolve with the network. In decision-making, GenAI enables faster exploration of alternatives, extended “what-if” analysis, and human-friendly interaction through conversational interfaces. It introduces the possibility of co-piloted operations, where AI assists rather than replaces human experts to reduce response times and enhance control-loop effectiveness. This evolution from rigid rules to reactive learning and on to proactive synthesis is changing the design of network management systems, aligning automation more closely with operator intent, operational risk, and service-level objectives. 2.1 Generative AI Models for Network Management Generative AI models are mainly designed to produce new outputs that are coherent, realistic, and consistent with learned information. In the context of network management, these outputs may include configuration scripts, synthetic traffic patterns, fault logs, anomaly scenarios, or natural-language summaries [10]. Among the most widely explored families of generative models are Large Language Models (LLMs), Generative Adversarial Networks (GANs), Variational Autoencoders (VAEs), and diffusion models. Each offers unique mechanisms and advantages for addressing different challenges in network operations. Large Language Models, or LLMs [11], are built on the so-called transformer architecture, which enables them to process long sequences by learning the relationships between tokens using self-attention mechanisms. Trained on massive corpora that include natural language, programming code, and technical documentation, LLMs are very good at contextual reasoning and generating (predicting) coherent sequences of structured or unstructured text. In the networking context, LLMs can be applied to translate operator intent into CLI commands, generate vendor-specific configuration templates, explain alarm outputs in plain language, or assist operators through interactive chat interfaces. There are several ways to tailor LLMs for specific networking use cases. Prompt engineering is the simplest method, involving carefully crafted input queries that guide the model’s behaviour without modifying its internal configuration. Using fine-tuning, one can retrain the model using domain-specific examples, including
Evolution of Generative AI in Networking Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 5 configurations, annotated incident logs, or policy documents. This tactic lets the model specialise in tasks relevant to a particular network environment. A third strategy is Retrieval-Augmented Generation (RAG), which integrates the LLM with an external knowledge source, such as a network documentation repository. At inference time, the system retrieves relevant context (for example, a recent ticket or device specification) and feeds it to the LLM, allowing for more accurate, specific and up-to-date responses. Generative Adversarial Networks [12] operate through an adversarial framework involving two neural networks: a generator, which produces synthetic data, and a discriminator, which attempts to distinguish generated data from real examples. As both networks learn simultaneously, the generator improves its ability to produce highfidelity samples. In network management, GANs have been widely adopted for generating synthetic traffic data, simulating rare fault conditions, and producing labelled intrusion examples for training security systems. These capabilities are especially valuable in scenarios where real-world data is limited or imbalanced, such as training datasets for anomaly detection or failure prediction. Although GANs can achieve impressive realism, they require careful calibration to avoid problems such as mode collapse, where the generator learns to produce only a narrow subset of outputs rather than covering the whole variety of the training data. Variational Autoencoders [13] are probabilistic models that learn a compact, latent-space representation of the input data. An encoder maps inputs to this space, while a decoder reconstructs them, allowing for controlled sampling and interpolation between valid states. VAEs have found application in modelling the distribution of valid configurations, detecting anomalies via reconstruction error, and generating intermediate network states for smooth policy transitions. Their structure encourages interpretability and stability, making them especially useful in environments where explainability and safety are critical. Diffusion models [14] are a newer class of generative models. They function by gradually adding noise to input data through multiple steps, then learning to reverse this process to generate structured outputs. This iterative denoising mechanism leads to high-quality results and allows for precise control over the generative process. In network operations, diffusion models show promise in synthesising configurations that meet specific performance or QoS (Quality of Service) constraints and generating policies under operational constraints. While they offer strong robustness and control, diffusion models are more computationally intensive than other generative approaches. An increasingly important direction in the application of generative AI is the combination of these model types into hybrid pipelines. Examples of these hybrid approaches include: • LLM + GAN, where an LLM generates fault narratives or operator instructions based on synthetic logs produced by a GAN. • LLM + VAE, where a VAE maps the valid configuration space and an LLM converts operator intent into traversable latent vectors. • LLM + RAG + diffusion, where an LLM uses retrieval to ground configuration goals, which are then passed to a diffusion model to synthesise a matching configuration under QoS constraints. 2.2 Benefits and Challenges The application of generative AI in network management can introduce several key benefits across technical, operational, and human-centric dimensions, offering capabilities that go well beyond the limitations of rulebased or purely predictive systems. One of the most immediate advantages is scalability. Once trained or adapted, generative models can produce valid device configurations, synthetic data samples and diagnostic suggestions fast, at scale and on demand. This eliminates many of the repetitive, manual, time-consuming tasks currently implemented by operations teams, particularly during large-scale deployments, migrations or testing.
Evolution of Generative AI in Networking Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 6 Generative models can offer greater adaptability, especially in scenarios with little labelled data, high system dynamics or anomalies. In these cases, generative AI can respond flexibly to the changing conditions even in the face of system states that it has never seen before. Another key benefit lies in interactivity. LLMs allow operators to engage with network systems using natural language. This can dramatically lower the barrier to automation, especially for teams that lack expertise in scripting and development skills. This interaction also improves transparency, allowing the operators to request explanations instead of blindly trusting a black-box execution. LLMs can also simulate changes or query compliance status in conversational form, enabling the practical development of AI co-pilot systems that support human decision-making. Generative models further support faster prototyping and simulation. Models such as GANs or diffusion architectures can generate synthetic traffic traces, emulate rare network events, or simulate operating scenarios under policy constraints. This is especially useful for stress-testing, evaluating SLAs under future load conditions, or training models without risking live infrastructure. Because generative models can create diverse and controllable scenarios, they are powerful tools for “what-if” analysis in performance, fault or capacity planning. However, as is often the case, generative AI can be a double-edged sword – despite the advantages it offers in network management, there are also important challenges and risks associated with its use. One key concern is the validity and safety of generated outputs. Even small inaccuracies in automatically generated configurations or security responses can lead to outages or compliance violations. LLMs, for example, may hallucinate seemingly valid but, unfortunately, incorrect commands if not carefully prompted. Similarly, GANs might produce unrealistic traffic patterns if trained on biased or insufficient data. These issues showcase the need for robust post-generation validation mechanisms, safety constraints, and, in many cases, human-inthe-loop review. Another significant challenge is explainability. Many generative models operate as black boxes, providing limited insight into why a specific output was generated. This creates a considerable problem for production environments where accountability, traceability, and auditability are essential. Operators would be reluctant to trust or adopt generative outputs that cannot be explained, especially in domains such as security or policy enforcement. Integration complexity is additionally challenging when it comes to generative AI models and their need to interact with other systems, real-time data sources, orchestration pipelines, and monitoring platforms. Successful implementation requires technical compatibility and operational alignment to ensure that the AIgenerated outputs can be consumed, validated, and acted upon. Concerns exist regarding the use of synthetic data. Poorly calibrated generative pipelines can introduce bias, artefacts, or unrealistic conditions into model training. This can degrade the performance of the rest of the systems and potentially increase inaccuracies or unfairness instead of fixing the issues. Ensuring realistic representation in the generated data remains an open research area. The following sections examine how generative AI capabilities are applied within the FCAPS framework domains (Fault, Configuration, Accounting, Performance, and Security management). In each domain, we highlight which model families are most prevalent, what tasks they support, and how their integration enhances the intelligence, autonomy and resilience of network management systems. While generative AI introduces tremendous benefits to network management, such as automation, simulation, reasoning and interaction, it also brings risks and challenges that will be explored in more detail across the FCAPS domains.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 13 Reference Approach Experiment Setup Success Level Key Findings Generative AI for Low-Level NETCONF Configuration in Network Management Based on YANG Models [19] LLMs with YANG Models integration Network with 7 hosts, 2 switches and 2 routers. Tests based on 12 relatively simple configuration scenarios. Best model (GPT-4o with pipeline) achieved 57% valid tests. No scenario is always correct; more complex scenarios are always wrong. Problems include missing or misused XML tags, incorrect tree hierarchy, and syntax errors. LLMs show promise for NETCONF configuration generation, but are not yet mature enough for complex industrial applications. A Novel LLM Architecture for Intelligent System Configuration [20] LLM-based intelligent chatbot architecture with RAG and function calling 3 domain-specific tasks with 30 sample conversations each: static NAT conf, fake server conf, assistant API conf The success rate is 100% for NAT and 50% for server conf. Assistant API conf requires postprocessing and future work. LLM architectures show potential for learning assistance. IBN with natural language is defined as a future step. NetConfEval: Can LLMs Facilitate Network Configuration? [21] LLM, GPT-4 Network size varies from 33 routers to 2 for routing (OSPF, RIP, BGP) using emulation. Input: max 3200 network high-level requirements. Tasks: generating formal specification, generating API calls, developing routing algorithms, and generating low-level configuration (max 10 lines) GPT4 achieves almost 100% accuracy, but all models are bad at complex conflict detection. Nativefunction calling does not perform as well. Models cannot directly calculate routing paths using the shortest-path policy for a network of 10 devices. GPT4 can accurately generate routing code when given feedback. Error-free low-level configurations in only 1 of 3 runs. With RAG, it can reach 100% accuracy, but not for OSPF. LLMs show potential in facilitating various network configuration tasks, but complex tasks need to be split into smaller subtasks, task-specific verifiers are needed, and humans must still be in the loop. Large Language Models for Zero Touch Network Configuration Management [22] Local LLM (Zephyr-7b) with verification and orchestration modules Network: a partial mesh topology with four Cisco routers and two hosts. Dataset with 90 resources. Configuration intents divided into four types (conf properties, routing, ACL, tunnel conf). LLM-NetCFG correctly classified and generated the correct configuration for 92.2% of requirements. Successful handling of non-complex intents in 5-7 minutes. LLM-NetCFG demonstrates the capability of generating and verifying network configurations based on natural language intents. LLMs can be used to design ZSM self-configuration agents. Towards Intent-based Network Management for the 6G System adopting Multimodal Generative AI [23] LLMs with industry-ready standard templates: TM Forum and GSMA Open Gateway Network: Patras5G testbed [24] Input: 3 classes (massive IoT, ultra-low latency comm, enhanced mobile broadband) with five prompts each. Proof of concept works. Proof of concept translation of highlevel intent into network configurations (TMF Service Order provided to OpenSlice OSS that uses the Operate API to push the configuration). Mobile Network Configuration Recommendation Using Deep Generative Graph Neural Network [25] Deep Generative Graph Neural Network (GNN) with Siamese architecture compared to Graph Auto-Encoder (GAE) Datasets from 2 networks created using collected information from multiple eNBs and gNBs, combining LTE and NR attributes. GAE excels in unsupervised learning from nonconfiguration data (99.1% acc), S-GNN is more accurate in supervised scenarios (92.1% acc), but may face challenges in adapting network configuration changes. Deep Generative GNNs can recommend network configuration parameters and detect misconfigurations.
Configuration Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 14 Reference Approach Experiment Setup Success Level Key Findings Making Network Configuration Human Friendly [26] LLM, GPT-4 Network: 7 P4 switches with two hosts Task: MPLS routing Capable of handling up to 40 requirements per prompt accurately; for higher numbers, it becomes unstable. In some experiments, generated configs are semantically correct, but contain some syntax errors. No complete accuracy evaluation provided. NETBUDDY can generate working P4 and BGP configurations from high-level requirements. LLMNDC: A Novel Approach for Network Device Configuration based on Fine-tuned Large Language Models [27] Fine-tuned LLMs Network: Huawei and Cisco devices Task: query communication knowledge and generate configuration suggestions. Fine-tuned model effectively generates accurate configurations for various network devices, demonstrating improved performance over baseline models. Fine-tuned LLMs can provide configuration recommendations for network devices. Automation of Network Configuration Generation Using Large Language Models [28] Extract keywords using NER, send to LLM, map to key-values and standardise the orch API. Input: different tariff plans of 27+ operators from which five information elements are identified. Output: API call to network orchestrator that forms the relevant configuration. A fine-tuned GPT-3.5 model with an input filter attained a perfect F1 score of 1, compared to 0.962 without it. The Llama2-7B model also showed significant improvements with the input filter. LLM-based pipeline converts input tariff plans and other additional parameters to related configuration and provisions complex networks. Can LLMs Understand Computer Networks? Towards a Virtual System Administrator [29] Evaluation framework testing six LLMs (proprietary and open source) on tasks: topology analysis, IP recognition, and path computation. 3 networks: 2 devices, 3 routers and 5 subnets; 12 nodes and 15 subnets. 13 different tasks divided into 4 groups: topology, drawing, addresses, and paths. Zero-shot Bing achieved a mean 79% accuracy; opensource models showed lower performance (Llama 2 is worst with 37% mean accuracy), especially on complex networks. LLMs can effectively handle basic network tasks in simple topologies, but their performance declines with increased complexity. Prompt engineering can enhance accuracy. What do LLMs need to Synthesize Correct Router Configurations? [30] Verified Prompt Programming— combining GPT-4 with automated verifiers and localised feedback mechanisms. Task 1: Translate Cisco to Juniper configuration, including BGP, OSPF, prefix lists, and route maps. Task 2: Generate router configs for a given network topology based on local policies. Leverage of 10x for Juniper translation, and 6x for implementing the no-transit policy. Stand-alone works badly, making elementary errors that can bring networks down. LLMs alone are insufficient for accurate configuration synthesis; integrating verifiers and providing modular, localised feedback substantially improves outcomes. S-Witch: Switch Configuration Assistant with LLM and Prompt Engineering [31] Combines an LLM with a digital network twin (in GNS3) to generate and verify switch configurations through prompt engineering. Network: 3 routers, 2 switches, 5 hosts Input: high-level requirements in natural language. IP allocation was incorrect for some of the devices. Blocking traffic with ACL was successful. Setting up VLAN was with mixed success: trunk mode works only if explicitly specified. Integrating LLMs with network digital twins and prompt engineering can automate configuration tasks, but additional methods, such as RAG, must be used to overcome limitations. Table 4.1: Comparative summary of recent papers on the topic of GenAI for configuration management
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 15 The majority of recent papers on using generative AI for network configuration focus on LLMs. For example, the study Generative AI for Low-Level NETCONF Configuration Management combines LLMs with structured YANG models and natural language to generate NETCONF-compliant XML configurations. Another example is Towards Intent-Based Network Management for the 6G Era [23], which uses LLMs in combination with standardised TM Forum and ETSI templates to transform high-level policy intent into complete configurations. Newly developed co-pilot systems, such as in A Novel LLM Architecture for Intelligent System Configuration [20] and Can LLMs Understand Computer Networks? [29], implement retrieval-augmented generation to assist users. These systems first fetch relevant examples or prior configurations from a knowledge base and then use the LLM to generate context-aware suggestions. This provides for more reliable solutions and a clearer audit trail. Another variation is presented in Large Language Models for Zero Touch Network Configuration Management, which leverages a locally deployed LLM that can handle non-complex configuration tasks using on-premise orchestration. Together, these approaches demonstrate the flexibility of generative AI across centralised and distributed deployment models. Several approaches go beyond general-purpose models by using fine-tuned LLMs trained on domain-specific data. For instance, LLMNDC fine-tunes LLMs to generate network device configurations with improved accuracy, and the study Automation of Network Configuration Generation Using Large Language Models applied a namedentity recognition (NER) preprocessing step to extract relevant information from user inputs before mapping to configurations using an LLM. Another notable example is S-Witch, which combines an LLM with a network digital twin and rule-based validation system to generate executable and verified CLI commands for commercial switches. In some cases, prompt design and post-processing are key to success. What Do LLMs Need to Synthesize Correct Router Configurations? presents a Verified Prompt Programming approach, which combines high-precision natural-language prompts with post-generation validation. Making Network Configuration Human-Friendly translates high-level policies into valid P4 and BGP configurations through a proof-of-concept LLM pipeline. In fact, most systems employ some form of preprocessing before input reaches the model. This may include translating user input into structured prompts, retrieving similar examples, validating syntax constraints, or inserting vendor context. These steps are critical to model performance, ensuring outputs are aligned with operational goals and syntax standards. Evaluation methods vary but often include performance benchmarking across models (NetConfEval, Can LLMs Understand Computer Networks?), task-specific experiments using real-world configuration sets (LLMNDC, SWitch), or cross-vendor translation tests [30]. These evaluations highlight the progress made and the limitations that still need to be addressed. Regarding success rates, results show moderate to high accuracy depending on task complexity and preprocessing quality. While performance is promising for straightforward configuration tasks, success levels decline in cases involving complex logic, multi-vendor abstraction, or ambiguous policy intent. 4.3 Strengths and Open Challenges Generative AI offers a powerful new paradigm for simplifying and accelerating network configuration workflows. Across the reviewed studies, a consistent strength is the ability of models, especially fine-tuned LLMs and retrieval-augmented systems, to translate high-level, human-friendly inputs into actionable configurations for real-world network devices. In use cases such as NETCONF, P4/BGP, and 5G provisioning, generative systems reduce the need for manual scripting and allow engineers to express intent in natural language, with the AI handling syntax, formatting, and vendor-specific conventions. Across nearly all of the reviewed studies, there is a consistent emphasis on preprocessing and input structuring before LLMs are invoked. Whether parsing user intent into formal templates, selecting vendor context, retrieving
Configuration Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 16 past configuration examples, or encoding relevant policies, this preprocessing step dramatically improves AIgenerated outputs' quality, relevance, and safety. It also addresses a key limitation of generic LLMs—their lack of awareness of operational constraints or enterprise-specific standards. This layered approach, where preprocessing enriches the input and postprocessing validates the output, is emerging as a best practice in realworld AI-in-the-loop deployments. A consistent and important design principle across all studies is the emphasis on keeping humans in the loop as a deliberate architectural choice. The reviewed systems incorporate co-pilot models that support, rather than replace, engineers. Most tools rely on interactive prompts, output previews, and configuration suggestions rather than automatic enforcement. Several papers also underline the limitations of current models, such as occasional hallucinations, vendor-specific misunderstandings or ambiguous intent interpretation, which further necessitate human oversight. In more advanced systems, AI-generated configurations undergo additional verification steps or policy checks before deployment, reinforcing the engineer's role as the final authority. The reviewed work also shows that generative AI can adapt to diverse environments, from programmable switches and 5G service platforms to multi-vendor routing backbones. This versatility is enabled by fine-tuning, task-specific preprocessing, and modular design, allowing generative systems to understand context, retrieve relevant knowledge, and tailor their outputs accordingly. Despite these promising capabilities, several challenges and limitations persist. A key concern, echoed in papers like NetConfEval, Can LLMs Understand Computer Networks?, and What Do LLMs Need to Synthesise Correct Router Configurations?, is that LLMs can often produce syntactically correct but semantically flawed configurations. The accuracy and reliability of LLMs still vary significantly based on the complexity and ambiguity of the input, especially in multi-domain or mission-critical environments. Many models struggle with nuanced requirements, edge cases, or uncommon syntax variations. Without adequate prompting, context, or validation, models may hallucinate commands, misinterpret policy intent, or mix configuration styles from different vendors. Another recurring issue is generalisation and reliability. Many models perform well in narrow or controlled benchmarks but struggle in real-world scenarios where edge cases and inconsistent documentation are common. Papers like Making Network Configuration Human-Friendly and LLMNDC show that fine-tuning improves accuracy, but also emphasise that training data quality and diversity remain a great problem in this area. Moreover, compliance and auditability are areas where current tools fall short. While some systems incorporate policy-aware validation, there is no unified framework for aligning AI-generated outputs with enterprise governance, change management practices, or external compliance standards. This gap raises concerns about accountability, especially in regulated or safety-critical environments. Finally, explainability and trust are pressing challenges, as many LLMs still function as black boxes. Understanding why a model proposed a specific configuration or verifying that it fully aligns with the original intent remains complex problems, especially for users without deep AI expertise. In summary, generative AI systems for network configuration are evolving quickly, with clear strengths in flexibility, time savings, and usability. However, they are not yet production-ready for fully autonomous deployment in most environments. As these tools move closer to deployment, questions around accountability, explainability, and safe rollout of configurations at scale remain largely unresolved. Addressing these gaps will be critical to ensure that generative AI becomes not only a helpful assistant but also a trusted and integral part of network automation workflows.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 17 5 Accounting Management Network accounting refers to the monitoring, measuring, and analysing of resource usage across a network, typically for billing, cost optimisation, auditing, and service-level enforcement. It is central in usage-based pricing models, dynamic charging schemes, and performance-linked service guarantees. Traditional network accounting systems rely on predefined rules and structured records, such as call detail records (CDRs) or IP flow data, and are often limited in their ability to adapt to evolving service models and user behaviours. Despite the growing interest in applying Generative AI across network operations, current academic research reveals a notable gap in its application where network accounting management, specifically in usage-based billing, dynamic charging models, and revenue assurance are concerned. To date, no peer-reviewed studies that explicitly focus on using GenAI for accounting tasks in a networking context have been identified. However, related work in financial accounting [32], automated billing systems, and predictive analytics for revenue forecasting [33] demonstrates the potential of LLMs, VAEs, and GANs for generating synthetic transaction data, detecting anomalies, and producing explainable summaries. Although these techniques are primarily developed for financial applications in other domains, they could be adapted to improve the transparency, scalability, and automation in network accounting systems [34] [35]. Future research must validate their effectiveness in network environments where data heterogeneity, regulatory compliance, and real-time constraints introduce unique challenges.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 18 6 Performance Management Performance management in networking systems focuses on ensuring the availability, responsiveness and efficiency of network resources. It involves monitoring and optimising key performance indicators such as throughput, latency, jitter, and reliability. These metrics are critical for meeting service-level agreements and user expectations. Traditional tools, while effective in stable environments, struggle to adapt to the increasing complexity of traffic patterns, dynamic service topologies, and multi-access network layers. Recent advances in Generative AI offer new mechanisms for addressing these challenges. By learning latent performance structures from traffic data, simulating network behaviours under diverse loads, and supporting adaptive decision-making, generative models are beginning to reshape how performance is inferred, predicted and optimised across modern networks. 6.1 Opportunities for Generative AI Generative AI opens new pathways for more adaptive, efficient, and predictive network performance management. A key opportunity lies in forecasting traffic and performance patterns using generative time-series models. By learning from historical data, these models can anticipate spikes, congestion, or degradation, allowing for proactive adjustments before service levels are impacted. Another emerging area is the generation of performance visualisations and summaries using LLMs. When integrated with telemetry data, LLMs can produce human-readable performance dashboards, trend analyses, and anomaly reports, reducing interpretation overhead and enhancing visibility in complex environments. Figure 6.1: Potential uses of GenAI in network performance management Generative models also play a role in adaptive resource management. In domains such as network slicing and optical networks, GAN-enhanced reinforcement learning systems can simulate varied traffic conditions and help optimise decisions under constraints such as bandwidth limits, routing rules, or SLA targets. This leads to more stable resource allocation and better handling of dynamic usage patterns. Finally, generative AI provides tools for automated retraining and performance maintenance in ML-based systems. By simulating performance drift or injecting synthetic workloads, generative models can help identify when retraining is necessary and reduce the operational cost of keeping predictive systems up to date.
Performance Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 19 This way, GenAI goes beyond monitoring performance to actively shape traffic via simulation, prediction, explanation, and control. 6.2 Review of GenAI Techniques and Models There are still relatively few published research papers focusing specifically on GenAI’s application to network performance management. The existing literature offers promising starting points, but this remains an emerging research area with considerable room for future exploration. The selected papers demonstrate a diverse application of generative AI techniques across network performance management scenarios, ranging from QoS inference to adaptive retraining and optical network optimisation. Together, they showcase how generative models can improve performance prediction, resource control, and system robustness. Reference Approach Experiment Setup Success Level Key Findings Deep Generative Model and Its Applications in Efficient Wireless Network Management: A Tutorial and Case Study [36] Using Deep Generation Models for improving the efficiency of wireless network management Case study: simulation of mobile user behaviour and ArtificialIntelligence Generated Content (AIGC) incentive contracts under QoS constraints. The approach achieves stable contract generation, enabling clients to always obtain positive utilities while maintaining high generation quality. Deep generative models, particularly diffusion models, can be applied to optimise QoS-constrained wireless service models through incentive design. Deep-Q: Trafficdriven QoS Inference using Deep Generative Network [37] Deep generative network for direct inference of QoS metrics from raw traffic traces (VAE + LSTM) Network testbeds of two different topologies: data centre network with six switches and overlay an IP network with 8 servers. Deep-Q achieves on average 28% lower inference errors than VAE. Keeps a stable average inference error below 15% in all cases. To achieve a high inference accuracy, combine VAE’s advantage of stable training performance and high modelling accuracy of GANs. Generative-AI for AI/ML Model Adaptive Retraining in Beyond 5G Networks [38] Generative AIbased (VAEs + GANs) framework to trigger ML model retraining based on drift detection and relevance analysis Evaluated for two usecases: QoS prediction over the O-RAN software community platform, and network slicing using a real-time dataset. Reduced model retraining overhead while maintaining >95% performance accuracy. GenAI supports adaptive ML pipeline management by simulating performance degradation patterns for proactive retraining. GAN-powered Deep Distributional Reinforcement Learning for Resource Management in Network Slicing [39] GAN-enhanced deep distributional Q network [40] for managing resource allocation across network slices Simulated multi-slice network with varying traffic and SLA constraints. A RAN scenario with 3 service types (VoLTE, video, and URLLC) and 3 slices in each BS. 100 registered subscribers. Duelling GAN-DDQN performs significantly better, improving system utility, bandwidth allocation, and offering a Service Satisfaction Ratio of 1. It is non-trivial to optimise multiple conflicting objectives, even when using cutting-edge algorithms. OpticGAI: Generative AIaided Deep Reinforcement Learning for Optical Networks Optimization [41] AI-generated policy design paradigm for optical networks Representative 14-node NSFNET topology. Analysed 2 NP-hard problems (RWA, RMSA). Achieved the highest reward and lowest blocking rate on RWA and RMSA problems across benchmarks. Integrating advanced generative models into reinforcement learning frameworks offers significant promise for enhancing performance in network optimisation tasks. Table 6.1: Comparative summary of recent papers on the topic of GenAI for performance management
Performance Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 20 Deep Generative Model and Its Applications in Efficient Wireless Network Management offers a high-level tutorial and case study, showing how diffusion models can simulate mobile user behaviour and design contracts that optimise wireless service delivery under QoS constraints. This paper sets the foundation for using generative models in performance-aligned incentive design. The authors recommend using diffusion models, GANs, and VAEs to model user demand, spatial-temporal traffic patterns, and mobility trends in environments where labelled data is limited or expensive to collect. Their proposed approach involves training these models on historical network data to learn user behaviour and generate future scenarios that reflect diverse QoS demands. These synthetic samples can then guide contract design, resource allocation, and service-level planning in a way that anticipates usage patterns rather than simply reacting to them. Deep-Q presents an early but influential application of a deep generative model to directly infer QoS metrics from raw traffic traces. It avoids traditional rule-based modelling and demonstrates that generative networks can accurately reconstruct and understand network performance features from passive observations. In Generative-AI for AI/ML Model Adaptive Retraining, the focus is on sustaining ML model performance over time. Here, GenAI is used to simulate performance degradation, detect relevance drift, and trigger retraining when network behaviour shifts, thus enabling more robust predictive pipelines for 5G slicing. GAN-powered Deep Distributional Reinforcement Learning addresses performance through dynamic resource allocation in network slicing. It shows how GAN-generated synthetic samples can accelerate policy learning, leading to faster convergence and more stable performance even under traffic fluctuation. The idea presented in the paper is that the GAN can learn and then generate realistic synthetic data. The synthetic samples improve the sample efficiency of the learning process and help the DRL agent form more robust policies early in training. In this way, better adaptation to variability in traffic and service demand can be achieved, which is important in 5G slicing, where conditions change rapidly and decisions must be made with incomplete or delayed feedback. OpticGAI targets optical networks, combining generative learning with deep reinforcement techniques to optimise complex problems like routing and spectrum allocation. It achieves strong empirical results, including reduced blocking rates and better resource efficiency, illustrating GenAI’s ability to guide real-time decisionmaking under performance constraints. Two common threads emerge across these models: predictive performance tuning and network simulation. Generative models are used to anticipate future behaviour (e.g., retraining triggers, user contract outcomes) and simulate hard-to-observe conditions such as rare loads. From a practical standpoint, the advantages include support for proactive scaling, more informed load balancing, and enhanced decision-making under uncertainty. However, trade-offs remain. The models require high-quality, representative training data, particularly for traffic synthesis and dynamic policy learning. Additionally, their computational overhead must be carefully managed to ensure their use in production environments. 6.3 Strengths and Open Challenges Generative AI shows clear strengths in addressing performance management tasks that involve prediction, adaptation, and optimisation under dynamic network conditions. In particular, generative models are used to anticipate traffic loads, simulate user behaviour, infer quality metrics, and support intelligent decision-making frameworks. One of the most consistent advantages is support for proactive performance tuning. Time-series generative models and diffusion-based techniques forecast conditions such as traffic spikes, enabling systems to pre-empt congestion and adjust resource allocation before degradation occurs. This shifts performance management from reactive intervention to anticipatory control.
Performance Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 21 Another strength is the ability to support complex decision-making under uncertainty. In reinforcement learning settings, GAN-generated synthetic samples help accelerate training and improve policy stability for problems such as network slicing and spectrum assignment. This leads to more efficient resource use and better adherence to performance guarantees. However, several open challenges remain. One is the need for high-quality training data, both in terms of representativeness and structure. Many generative models rely on detailed traffic traces or labelled performance metrics, which are not always readily available or may require extensive preprocessing. Another issue that needs to be taken into account is computational cost. While generative methods have demonstrated strong performance in simulation and training, their deployment in real-time network environments must contend with latency, scalability, and energy efficiency constraints. Finally, the lack of standardised benchmarks and evaluation scenarios makes it difficult to compare results and generalise the findings to diverse network settings. As the field matures, more systematic validation and crossenvironment testing will be needed to ensure the reliability and transferability of generative approaches to performance management.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 22 7 Security Management Within the FCAPS framework, security management involves safeguarding every network layer against threats and unauthorised access. Its scope spans users and identities, data in motion and at rest, network and compute infrastructure, and the operational telemetry that drives incident response. However, it also ensures confidentiality, integrity, availability and authenticity across enterprise, cloud, edge, and industrial IoT environments. Generative AI now expands how this mandate can be met. By learning the fine-grained patterns of normal and malicious behaviour, generative models can support a variety of cybersecurity applications, such as: • Creating realistic attack traffic for testing and evaluation purposes. • Crafting detection rules directly from high-level threat descriptions. • Powering anomaly-detection engines that surface novel intrusions with fewer false alarms. These capabilities move security management from reactive, rule-driven processes toward proactive, adaptive defence, while also introducing new challenges around model robustness, privacy and governance. 7.1 Opportunities for Generative AI Generative AI instantly transforms security management by allowing defenders to imagine attacks before they happen and translate high-level threat knowledge into machine-enforceable defences. Because models such as GANs, VAEs, diffusion transformers and LLMs can learn the fine statistical structure of network traffic, log events and malware artefacts, they are uniquely suited to two long-standing pain points: (i) the chronic shortage of labelled examples for rare or never-before-seen intrusions, and (ii) the slow, error-prone process of turning prose-level intelligence into concrete detection logic. The first opportunity lies in synthetic attack generation. A generative model trained on even a handful of real intrusions can emit complete packet captures, NetFlow records, or multivariate sensor traces that convincingly reproduce timing, size, protocol mix and payload quirks while varying non-critical fields so the output is not a carbon copy of the source data [42] [43]. Security teams replay these synthetic traces through sandboxes, continuous-integration pipelines or replica networks to stress-test intrusion-detection and prevention systems under conditions that rarely occur in production logs: low-and-slow reconnaissance, polymorphic data exfiltration, multi-stage lateral movement, bursty DDoS floods, or coordinated IoT botnet surges. Because the generator labels every packet or log line as they are produced, it delivers perfectly annotated datasets that balance minority classes without exposing live infrastructure to risk. In operational environments, this practice has already cut weeks out of model-retraining cycles and revealed blind spots that signature-only defences had missed, especially in cloud, 5G core, industrial-control and smart-city deployments where the attack surface changes faster than policies can be written by hand. The second opportunity is prompt-based rule generation. Large language models can ingest a brief, plain-English threat description and optional context, such as PCAPs (packet-capture files that record raw network traffic), log excerpts, or asset inventories, and emit ready-to-deploy detection code for multiple enforcement layers. For deep-packet-inspection engines like Suricata and Snort, the model writes rules that define protocols, offsets, byte patterns, flow direction, thresholds and metadata in each engine’s native, keyword-rich syntax. Runtime
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 29 Tool FCAPS Generative Features Description C / O NetBrain's Self-Service Chatbot [55] F/C/P/S • Natural-language network troubleshooting • LLM to streamline user interactions • Natural-language processing Uses user-input natural language, combined with a no-code library of pre-built network automation units to manage infrastructure and diagnose and resolve issues. Retrieves real-time data from network devices through APIs, uses dynamic topology maps for reference, and verifies against established configuration baselines. The chatbot provides automated, context-sensitive troubleshooting and remediation via a conversational interface. C Atera's AI-Powered IT Management Platform (AI CoPilot Assistant) [56] F/C/P/S • Script generation • Troubleshooting assistant • AI ticket triage • Anomaly detection • Remote access security Uses input data such as device health metrics, ticket histories, remote session logs, knowledge base articles, endpoint security info and natural-language prompts. It utilises this data to produce scripts, identify problems, and automate ticket processing. C ServiceNow IT Infrastructure Management [57] F/C/P/S • Natural-language interaction • Article generation • Automated incident summarisation • Policy and workflow generation Provides real-time monitoring, predictive analytics, and intelligent automation to optimise infrastructure performance, detect anomalies, and proactively address potential issues. The tool collects device input data from multiple sources, such as network discovery protocols (SNMP, WMI, SSH), its Configuration Management Database, integrations with third-party monitoring tools, and telemetry data from network devices. C OpenAI Codex* [58] F/C/P/S • Natural-language processing • Reads and edits files • Runs commands Built on a fine-tuned version of GPT-3 to understand and generate code in various programming languages. It acts as an autonomous code assistant, as the code can be debugged, refactored, and tested within sandboxed environments. C Broadcom DX Operational Observability [59] F/P • Generative AI summarisation for services • Natural-language filtering Simplifies the understanding of complex incidents, makes data filtering intuitive for nontechnical users, and accelerates the triage process. C XenonStack GenAI for NOC [60] F/P/C • Anomaly detection Gathers data from applications, infrastructure, network logs, metrics and events to train ML models and detect anomalies. C
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 30 Tool FCAPS Generative Features Description C / O NetGPT [61] F/C/P • Natural-language troubleshooting assistant • Device interaction chatbot • LLM interface NetGPT employs a collaborative cloud-edge methodology, optimising the deployment of LLMs based on their computational capacities, allowing efficient processing of network traffic data. O LangChain* [62] F/C/P • Script generation • Natural-language device configuration Designed to build applications powered by LLMs, including AI assistants, internal copilots, and automation tools across network management domains. Tested in multiple studies enabling interaction with 3GPP documentation and supporting generation and structuring of dataset metadata [63], along with a LangChain-based network management assistant that adapts to network baselines [64], demonstrating utility not only in operational monitoring but also documentation, compliance and decision-support. O PydanticAI* [65] F/C/P • Agentic orchestration • Streaming response generation Supports different models (e.g., Gemini, OpenAI, Ollama). Leverages Pydantic models to define and enforce the output schema of an LLM with a model-agnostic architecture. O Google’s Agent Development Kit (ADK) [66] F/C/P • Multi-agent orchestration • Tool-based reasoning and execution • Agent-to-agent communication protocols A Python toolkit for building and evaluating multi-agent AI systems through their step-bystep execution trajectories. Enables agents to collaborate on complex tasks. O MS AutoGen* [67] F/C/P • Multi-agent conversation and collaboration • Code execution • Autonomous problem-solving Allows the creation of multiple AI agents to communicate and collaborate to solve complex problems. Supports enhanced LLM inference APIs. O * Tool not designed as a direct network management tool. However, it is a comprehensive framework for developing AI-powered applications that can be used for network management. Table 8.1: Classification of fault, configuration, and performance management tools based on GenAI
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 31 Cisco AI Network Analytics, Generative AI Policy Assistant Cisco AI Network Analytics [68] is an application embedded into Cisco DNA Center. The tool focuses on intelligent issue detection and analysis to enhance the network performance management functionalities of Cisco DNA Center, identifying network events and sending them to the Cisco cloud. AI-driven baselining is employed to analyse the network behaviour of a specific network environment, learning the baseline network behaviour and using it as a reference to identify performance issues. Unusual network patterns and their causes (e.g., connection issues, application experience issues) are identified by an AI-driven anomaly detection feature. Furthermore, the tool offers comparative analytics by comparing a specific KPI from the analysed network with another network. Another powerful tool relying on generative AI is Cisco AI Assistant [69], which utilises conversational AI for IT and security operations. The assistant leverages its capabilities to generate AI-driven insights for devices, applications and networks, guaranteeing data protection and privacy. The user can ask questions and request information such as “Give a person access to a specific app”, “Show me WAN port usage”, “How can I troubleshoot the alert “DHCP no leases”?”, or “What are the group policies currently configured?”. By automating repetitive tasks, identifying problems at an early stage and suggesting measures in the areas of performance, security, and configuration, Cisco AI Assistant improves efficiency, reliability and protection while enhancing network intelligence. The tool applies to the following FCAPS management domains: • Fault management: It helps to simplify root cause analysis using a conversational interface for troubleshooting. • Configuration management: The assistant can automate a variety of setup tasks to reduce routine network management processes. It provides proactive suggestions to enhance network reliability and stability, and helps users understand and manage group policies, client policies, and network-wide policy configurations. • Performance management: It provides real-time visibility and understanding of the network and suggestions to enhance network reliability. • Security management: The assistant aids in troubleshooting security appliances, firewall rules, VPN configurations, and network security events. Juniper Mist AI Juniper Mist AI [70] is a tool designed for AI-driven operations, using AI at the core. The platform enables advanced capabilities, real-time optimisation, and autonomous issue resolution. Its features include data collection from telemetry and user state and decision-making. The tool utilises conversational and generative AI capabilities to provide proactive insights, explain anomalies, and suggest potential fixes in natural language, enhancing operators’ troubleshooting capabilities. Network performance can be monitored to identify bottlenecks and address usage issues. Mist AI uses a cloud-native, microservices-based architecture that is scalable, open, and API-driven. The GenAI-based Marvis AI Assistant [71] is integrated with the Juniper Mist AI platform, providing a chat interface with real-time responses and acting as a co-pilot to respond to issues. Marvis AI Assistant draws on historical information from Juniper’s public-facing knowledge base and employs NLP to optimise experience in
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 32 wired and wireless access, SD-WAN, and WAN domains. Agentic AI capabilities are provided by leveraging multiple agents and user feedback. The assistant can answer direct questions about network state, recommend proactive actions, and provide support for configuration management. This serves to reduce mean time to resolution (MTTR), reduce human effort by correlating data to derive conclusions, and ensure a seamless and smooth user experience. The tool offers a dashboard view of high-impact network issues at an organisational level. The tool applies to the following FCAPS management domains [72]: • Fault management: The tool provides automated root cause analysis, intelligent alert correlation, a conversational interface for troubleshooting, and automated remediation script generation/execution. • Configuration management: Juniper Mist AI supports self-configuring networks for faster deployment, and Agentic AI can continuously monitor and adjust network configurations to optimise performance, security, and resource utilisation in real time. • Performance management: The tool enables network administrators to define SLAs and monitor them in real time. • Security management: It offers integrated security and control, with a unified Mist dashboard delivering Zero Trust at scale through consolidated management and consistent policy enforcement. Its AI-native security unifies AIOps, networking, and security to provide complete environment visibility and insights into the network implications of security actions. Agentic AI can also proactively identify and neutralise cyber threats. Fortinet: FortiManager / FortiAnalyzer / FortiMonitor / FortiAI Fortinet is a cybersecurity company specialising in the protection of corporate networks, data centres, cloud environments and end devices. The company’s software portfolio has adapted in light of the ever-increasing threat of complex cyberattacks, as well as the constant development of GenAI. Numerous GenAI software extensions, including script generation, IoT device analysis and SD-WAN troubleshooting, have created a compact system that can be used in all areas of the FCAPS framework. These features take as input the device configurations, security policies, protocols, network topology, and user prompts to automate and optimise network management. However, most of these features are limited to Fortinet products, especially in terms of configuration, as Fortinet software and hardware are not designed to manage third-party devices nor support other vendors' configurations, protocols, and security models. The most important Fortinet software extensions apply to the FCAPS framework as follows: • Fault management: FortiManager and FortiAnalyzer offer capabilities to detect, isolate, and report faults across the network. These systems monitor hardware status, network traffic, and system logs in real time, generating alerts for anomalies, failures, or potential threats. Faults can be automatically logged, prioritised, and escalated based on severity, with an LLM on hand for troubleshooting to minimise downtime. • Configuration management: FortiManager offers configuration management simplification, offering centralised control for managing configurations across various Fortinet devices. From one interface, administrators can create, alter, deploy, and back up configurations via an LLM. This guarantees consistent policy application, and minimises human errors and the need for expert knowledge.
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 33 • Performance management: Extensions like FortiManager, FortiAnalyzer and FortiMonitor support performance management through real-time monitoring, traffic analytics, and reporting features. These systems can track CPU, memory, and bandwidth usage across Fortinet devices, and monitor network latency and uptime. The system then uses this data to optimise network routing with SD-WAN performance metrics and identify traffic bottlenecks or underperforming links. • Security management: FortiManager, FortiAnalyzer and FortAI provide continuous monitoring, threat assessment, policy implementation, and incident management to protect infrastructure against cyberattacks like malware, ransomware, phishing, and zero-day exploits. Administrators can define and apply security policies consistently across all Fortinet devices from a single management platform with natural language via an LLM. The system constantly observes network traffic and device activities to detect threats immediately, automatically initiating responses like blocking harmful traffic or isolating compromised systems. 8.2 Generative AI Tools for Security Management The expansion of GenAI is not only affecting application development but also allowing the production of more sophisticated hacker and attack tools. This leads to AI-driven attacks and an expanded attack surface from cloud to IoT devices. To counter this, AI-based security tools are being developed. This means that the market is developing towards countering AI with AI. These tools are designed: • To protect generative AI systems from attacks and misuse such as prompt injections (malicious inputs aimed to manipulate AI responses) [73]. • To analyse massive volumes of data rapidly, automatically generating threat reports and summaries. • To simulate attacks to test the defences of networks (Red-Teaming). It is also possible to enhance existing security tools with generative AI – for example, a network traffic analyser with a dedicated log output could be used to configure an LLM through the Model Context Protocol (MCP)3. An MCP server is a central system that manages and distributes context information between LLMs, AI agents or tools. It enables structured, real-time communication and context sharing, often used in multi-agent systems, AI orchestration, or tool-using environments. This section describes some of the available AI-based tools used not just to enhance network security, but also to strengthen AI models and applications through the AI output, reasoning, and action validation. There are also overlaps with other FCAPS management domains, especially with Performance management, because in most cases, security problems can be analysed using network data or data traffic in general, such as in the case of a DDoS attack. Performance management in GenAI-based security tools focuses on maintaining fast and scalable analysis of large security data streams. This ensures that models deliver accurate and reliable threat detection. Therefore, commercial GenAI security tools depend somewhat on the Performance management domain. But there is a significant difference with these tools: firstly, there are tools with limited LLM interaction where users can only ask monitoring questions – “What happened in my network and what are your suggestions?” Other tools offer the possibility to configure the network directly with LLM input to a limited extent, i.e., “I have a security problem here, do something about it!” These tools are marked in the FCAPS column in the following table with “S” or “S/C” respectively. It is impossible to cover all generative AI tools for security management in one table, as this field is one of very active current development. Thus, Table 8.2 lists notable examples of commercial and open-source security management tools that underline the market’s direction towards LLMs. 3 The Model Context Protocol (MCP) is a communication protocol designed to manage and share contextual information between AI models, tools, or systems in a structured, standardised way.
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 34 Tool FCAPS Generative Features Description C / O Microsoft Security Pilot [74] S/C/P • Natural-language querying and configuration via LLM • Real-time malware analysis Uses data from organisation's security tools, Microsoft’s global threat intelligence, and contextspecific information via secure plugins to analyse and respond to threats. C Charlotte AI [75] S/C/P • Natural-language querying and configuration via LLM • Multi-agent architecture • Threat detection and response Uses input data from three main sources: Falcon platform telemetry (e.g., endpoint and cloud activity), CrowdStrike threat intelligence (tracking adversaries and attacks), and expert-validated content from services like Falcon Complete and OverWatch. These inputs provide real-time, high-fidelity context for accurate threat detection and response. C Darktrace ActiveAI Security Platform [76] S/P • Natural-language querying via LLM • Threat detection and response • Self-learning AI Utilises input data from various sources within the enterprise, such as network traffic, endpoints, cloud services, email systems, identity management systems, and third-party integrations. Builds behavioural baselines and detects anomalies using self-learning AI on this telemetry. C Zscaler Zero Trust Exchange [77] S/P • Natural-language querying via LLM • Prompt classification and inspection • Threat detection and prevention Uses a wide range of telemetry, including network, application, device, and SaaS traffic as input data. Incremental training of AI models for policy recommendations, breach prediction, and secure generative AI controls is performed using these inputs in conjunction with external security and business systems. C SentinelOne Purple AI [78] S/C/P • Natural-language querying and configuration via LLM; multilingual support • Threat hunting • Autonomous investigations Uses real-time telemetry including endpoint, cloud, identity, and network security events across both native and third-party log sources. It also includes threat intelligence, automated neuralnetwork-based detections, and enriched metadata, which power its generative AI capabilities for natural-language threat hunting and investigation. C Tenable ExposureAI [79] S/P • Natural-language querying via LLM • Attack path summarisation • Specific mitigation guidance Uses input data from the Tenable Exposure Graph, including over 1 trillion exposures, configuration findings, assets, and vulnerability data across IT, cloud, and operational technology environments. This data powers its generative AI to support risk analysis, search, remediation workflows and attack path summarisation. C
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 35 Tool FCAPS Generative Features Description C / O Coralogix [80] S/P • Natural-language querying via LLM • Real-time observability • AI safety focus (including prompt injections & hallucinations) Utilises input data derived from logs, metrics, traces, and security telemetry from various applications and cloud infrastructure, along with vectorised observability records, model evaluation metadata and real-time security alerts to facilitate semantic search, anomaly detection and AI governance. C Lakera Guard [81] S/P • Natural-language explanations (no LLM) • Prompt injection protection • Real-time threat detection • Red Team simulations Ingests all LLM interactions, including user inputs, system prompts, and model outputs, passing them through detectors for prompt injection attacks, jailbreaks, content violations and malicious links. It uses continuous Red Teaming, where data is used to train and update its detection models, enabling real-time protection against evolving GenAI threats. C Calypso AI [82] S/C • Natural-language querying and configuration (scanners) via LLM • Real-time adaption of scanners • Red Team simulations Monitors and scans user prompts and AI responses in real time to identify risks such as prompt injections, Personal Identifiable Information (PII) leaks, toxic content and sensitive business data. It employs both built-in and customisable scanners via LLM. It supports Red Teams within a controlled environment to test LLM vulnerabilities. These data help refine custom scanners and strengthening model defences against real-world threats. C Lasso Security [83] S/C • Cybersecurity solution for LLM • Securing and monitoring AI interactions • Red Team simulations Examines the prompts and outputs of LLM interactions to identify sensitive data, implement security measures, and avert risks such as PII exposure or IP leaks. It also supports automated red teams by simulating adversarial attacks to identify vulnerabilities in AI workflows. C LlamaFirewall [84] S • Prompt injection protection • Monitoring agents in real time • Insecure code prevention Examines all data traversing GenAI pipelines, including user prompts, external content, agent reasoning and produced outputs, to prevent security threats such as prompt injections, goal hijacking, and insecure code. It is completely open source and does not require purchasing API access for any LLM to use the core features. However, there are some community extensions that rely on OpenAI's moderation API, which does require an OpenAI API Key, but this is completely optional. O Adversarial Robustness Toolbox (ART) [85] S • Ensures robustness against adversarial inputs for generative models (such as evasion, poisoning, extraction and inference attacks) Supports a wide range of input data types, such as images, audio, video, and text. Its purpose is to assess and improve the robustness of models by creating adversarial examples and evaluating defences within different machine learning frameworks. It is completely open source and free to use. O
AI Tools for Network Management Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 36 Tool FCAPS Generative Features Description C / O Garak [86] S • Focus on LLM security: prompt injections, jailbreaks, etc. • Red Team simulations Employs crafted adversarial prompts to evaluate GenAI models for weaknesses such as hallucinations, prompt injection, and data leakage. Examines the model’s replies to detect flaws and enhance Red-Team strategies. It is an open source tool, but offers a commercial enterprise version that includes advanced features like managed Red‑Team services, enterprise-only probes, compliance reporting and historical benchmarking. O Zeek (Enhanced with AI) [87] [88] S/P • Network traffic analyser with detailed log output • Can be used as input for an MCP server for LLM interaction Uses network traffic data as its primary input, analysing it to generate detailed logs about connections, protocols, files, and other artefacts. It can also ingest external structured data (e.g., logs or tables) to enhance detection and correlation capabilities. This detailed log output can be used to configure an LLM through an MCP server. Zeek is open source, but to use it together with an LLM or to build an MCP server, purchasing API access to an LLM may be required. O Cybersecurity AI [89] [90] S/P • Red Team simulations • Modular agent design To simulate attacks, it requires input data like details of the target system, network traffic, vulnerability databases, and tailored exploit scripts. Its outputs consist of reconnaissance reports, logs of exploit attempts, traces of agent activity, and detailed findings from Red Team assessments. It is generally open source, but leveraging external LLMs for scoring, reasoning, or attack generation requires API keys, where purchase may be required. O Table 8.2: Classification of security management tools
Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 37 9 Conclusions This white paper examined GenAI's rapidly growing role in network management, providing an in-depth analysis of its applications across the FCAPS framework: Fault, Configuration, Accounting, Performance and Security. The review of recently published research showed that GenAI is beginning to reshape operational paradigms across all FCAPS areas. Configuration and Security management are the most advanced in adoption and capability. LLMs are reliably used in configuration management to convert operator intent into structured, vendor-specific commands. This can significantly reduce the overhead of managing multi-vendor environments and help avoid misconfigurations. In security, generative models such as GANs and diffusion models enable the creation of synthetic attack traces, Red-Team scenarios, and fine-grained intrusion-detection training data. These developments enable more agile, adversary-aware defence mechanisms previously difficult to prototype or test. Fault management is following closely behind. Research has shown that detection pipelines can be trained more effectively and made more resilient to unseen failure types by using generative models to simulate rare or complex incidents. LLMs are also playing a growing role in this space, assisting with log summarisation, naturallanguage diagnosis, and co-pilot-style operator interaction. However, challenges remain in validating fault predictions in real time and ensuring they are explainable and actionable. In performance management, generative models simulate time-series traffic patterns, enable predictive scaling, and optimise resources via generative reinforcement learning. These techniques show strong potential for data centre orchestration, network slicing, and 5G/6G edge optimisation. However, practical deployments are still rare, and the field needs more robust mechanisms for integrating generative outputs into live orchestration pipelines without compromising stability or latency. Accounting management is currently the least explored FCAPS area regarding generative AI applications. While some underlying techniques, such as automated report generation, summarisation of usage patterns, and policy-aware document drafting, have been demonstrated in related fields like finance and billing automation, dedicated research in the networking context remains limited. Nevertheless, there is a lot of potential, particularly in combining generative models with logs, telemetry, and cost models to streamline chargeback, forecasting, and SLA verification processes. One consistent theme across all FCAPS areas is that the most effective solutions often rely on hybrid model architectures. For instance, pairing LLMs with GAN-generated training data improves classification robustness, while combining VAEs with LLM prompts enables constrained but human-interpretable configuration synthesis. Similarly, integrating RAG with policy rulebases allows for more factual, verifiable outputs. These architectures enable generative AI to become part of modular pipelines in complex real-world network operations. However, challenges remain. Generative models can produce plausible but invalid outputs. In a networked system, even a small error in a configuration or a misinterpreted alert can lead to outages, degraded QoS, or security vulnerabilities. The issue of explainability is a problem, especially for GANs and diffusion models, which offer little interpretability out of the box. Furthermore, operational constraints such as latency, integration with other systems, and compliance requirements limit where and how generative AI can be applied in production environments.
Conclusions Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 38 Future steps must include developing safeguards and best practices to address these risks. These include humanin-the-loop oversight for critical decisions, post-generation validation layers, training on high-quality and diverse datasets, and using constraint-aware generation techniques. Equally important is the need for benchmarking frameworks and open evaluation datasets that allow results to be compared transparently and fairly across different deployments. A key consideration is the selection of an appropriate network management solution. The selection requires consideration of stakeholders’ specific needs, available resources, and directions. For instance, while open source solutions are often free of charge for developers, they demand higher technical proficiency for successful deployment, customisation, and troubleshooting. Furthermore, the level of support required must be carefully considered. Commercial solutions generally provide dedicated vendor support, whereas open-source tools depend more on community support. Current market offerings primarily concentrate on real-time performance monitoring, advanced observability, traffic engineering, dynamic resource allocation, and predictive capacity planning. The leading vendors often provide dynamic dashboard generation, unified data insights, proactive resource optimisation, simulations of user connections, dynamic configuration adjustments and performance monitoring in their solutions. These GenAI capabilities enable network configuration to be adjusted dynamically and manually with simple human language via LLMs, optimise traffic flow and forecast future needs, moving the industry toward more autonomous and self-healing operations that meet the escalating demands of modern IT infrastructures and the exponential growth of data. Generative AI has the potential to shift our perception of automation, transforming it into an adaptive approach based on data-driven systems that can learn and create. Realising this vision requires collaboration between researchers, vendors, operators, and standardisation bodies to ensure that GenAI becomes a trustworthy, sustainable pillar of modern network operations.
References Intelligent Networks: The Rise of Generative AI in Network Management Document ID: GN5-2-25-11LABC 45 [76] Darktrace ActiveAI Security Platform – https://www.darktrace.com [77] Zscaler Zero Trust Exchange – https://www.zscaler.com/ [78] SentinelOne Purple AI – https://www.sentinelone.com/ [79] Tenable ExposureAI – https://www.tenable.com [80] Coralogix – https://coralogix.com/ [81] Lakera Guard – https://www.lakera.ai/lakera-guard [82] Calypso AI – https://calypsoai.com/ [83] Lasso Security – https://www.lasso.security [84] LlamaFirewall – https://meta-llama.github.io/PurpleLlama/LlamaFirewall/ [85] Adversarial Robustness Toolbox (ART) – https://github.com/Trusted-AI/adversarial-robustnesstoolbox?tab=readme-ov-file [86] Garak – https://github.com/NVIDIA/garak?tab=readme-ov-file [87] Zeek – https://docs.zeek.org/en/current/about.html [88] Zeek-MCP – https://mcpmarket.com/server/zeek [89] Cybersecurity AI framework for AI Security – https://github.com/aliasrobotics/cai?tab=readme-ovfile#-milestones [90] Mayoral-Vilches, V., Navarrete-Lozano, L.J., et al. 2025. ‘CAI: An Open, Bug Bounty-Ready Cybersecurity AI’. arXiv preprint arXiv:2504.06017. https://doi.org/10.48550/arXiv.2504.06017