That seems like a great dataset for some statistical analysis, but unfortunately we aren't even told how large the subsets are. (The figure of 590 million is from a news report about the leak.) So it's hard to tell how large the problem is, and how it compares to other companies or countries.
The results are presented as three profiles based on three CVs from the leak, but edited to obscure their identity. It's only mentioned in the conclusion that the profiles are actually composites, which I take to mean that they combine information from multiple CVs each. That's unfortunate, because many of the claims rely on one and the same person being involved in multiple activities. We'll have to trust the author that those modifications do not embellish anything.
The three profiles are:
1. A software engineer in Huawei QA since 2011 who from 2012 on also held a research and teaching position with the PLA's National University of Defense Technology, working on signals, remote management and scripting. The paper claims that this places them within a branch of the Strategic Support Forces (who are responsible e.g. for cyber warfare). It's not clear to me whether that's something specific to that person, or whether any similar research at NUDT is classed that way. NUDT also does civilian research, e.g. Microsoft was criticized for publishing a paper on beauty estimation co-authored with NUDT researchers: https://ecommons.udayton.edu/cgi/viewcontent.cgi?article=107...
2. A Huawei engineer who was responsible for building lawful interception capabilities, working on roll-outs in multiple countries. He served as a representative for the Chinese Ministry of State Security on one project "likely guaranteeing project specifications". The author tries to imply that this was to grant the MSS access to other countries' networks, but alternatively Huawei simply has product managers responsible for communication with the law enforcement agencies doing the intercepting in their own country's networks. The author also tries to link that person to a "backdoor" in infrastructure of Vodafone Italy. However, Vodafone has denied the allegiations in the Bloomberg article he cites: https://www.bbc.com/news/business-48103430
3. A network engineer who developed civilian and high-security military communication systems at CASTC, then worked at China Unicom for a year and then went to Huawei to lead network expansion projects. At CASTC, he gained expertise using Cisco and Nortel switches. The author construes this to imply that he assisted in espionage attempts involving fake Cisco routers.
Of the three, I'm going to classify 1. as harmless research (otherwise Microsoft is just as implicated as Huawei) and 3. as "person with security clearance changes jobs". 2. however at least supports this part of the paper's conclusion: "the institutional relationship between Huawei and Chinese state security services directly contradicts Huawei claims that they have no relationship with these services." Huawei should probably clarify those statements to mean that the relationship doesn't grant Chinese security services access to other countries' data.