Alert management
SLM agents in cellular networks expedite alert handling, reducing manual intervention and resource use, enhancing network efficiency and availability.
Patent Information
- Application Number
- PCT/FI2025/050247
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-16
- Filing Date
- 2025-05-14
- Publication Date
- 2025-11-20
AI Technical Summary
Existing systems in cellular communication networks struggle with inefficient and time-consuming manual handling of system alerts, leading to prolonged outages and resource wastage.
Implementing small language model (SLM) agents trained to process and respond to specific types of alerts, generating configuration intents or updates to automatically reconfigure the network, with the option for human oversight.
Faster alert response times, reduced resource consumption, and improved network availability by automating alert management, minimizing human intervention and potential errors.
Smart Images

Figure FI2025050247_20112025_PF_FP_ABST
Abstract
Description
ALERT MANAGEMENTFIELD
[0001] The present disclosure relates to managing system alerts using small language models, for example in the context of cellular communication networks.BACKGROUND
[0002] Cellular communication networks comprise nodes in the radio access network, RAN, and in the core network, CN, which are tasked with performing various roles in the overall network. Operating conditions of these nodes change over time in dependence of communication load, component faults, software errors and interoperability problems. Operating conditions may change also in nodes of other systems, such as fixed communication networks and industrial installations.
[0003] Such nodes are typically configured to issue alerts when their operating condition changes, the alerts being sent to a queue or other handling mechanism of the system, such that operators can take appropriate action as a response to the change in operating condition in the node.SUMMARY
[0004] According to some aspects, there is provided the subject-matter of the independent claims. Some embodiments are defined in the dependent claims.
[0005] According to a first aspect of the present disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to store plural small language model, SLM, agents, each SLM agent being configuredto provide responses to alerts of a specific type which originate in a system, process an alert from the system by selecting an SLM agent and providing the alert to the selected SLM agent to obtain from the selected SLM agent a response to the alert, and re-configure the system with the response.
[0006] According to a second aspect of the present disclosure, there is provided a method comprising storing plural small language models, SLM agent, each SLM agent being configured to provide responses to alerts of a specific type which originate in a system, processing an alert from the system by selecting an SLM agent and providing the alert to the selected SLM agent to obtain from the selected SLM agent a response to the alert, and reconfiguring the system with the response.
[0007] According to a third aspect of the present disclosure, there is provided an apparatus comprising means for storing plural small language models, SLM agent, each SLM agent being configured to provide responses to alerts of a specific type which originate in a system, processing an alert from the system by selecting an SLM agent and providing the alert to the selected SLM agent to obtain from the selected SLM agent a response to the alert, and re-configuring the system with the response.
[0008] According to a fourth aspect of the present disclosure, there is provided a non- transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor, cause an apparatus to at least store plural small language models, SLM agents, each SLM agent being configured to provide responses to alerts of a specific type which originate in a system, process an alert from the system by selecting an SLM agent and providing the alert to the selected SLM agent to obtain from the selected SLM agent a response to the alert, and re-configure the system with the response.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] FIGURE 1 illustrates an example system in accordance with at least some embodiments of the present invention;
[0010] FIGURE 2 illustrates an example solution in accordance with at least some embodiments of the present invention;
[0011] FIGURE 3 illustrates an example apparatus capable of supporting at least some embodiments of the present invention;
[0012] FIGURE 4 illustrates signalling in accordance with at least some embodiments of the present invention;
[0013] FIGURE 5 is a signalling diagram of an example embodiment of the invention, and
[0014] FIGURE 6 is a flow graph of a method in accordance with at least some embodiments of the present invention.EMBODIMENTS
[0015] Described herein are mechanisms to handle alerts in a system, such as a cellular communication network, using a small language model, SLM, agents. These SLM agents are trained to handle alerts which originate in the system by processing them to generate a response to the alert. The response may be used to handle the alert by re-configuring one or more aspects of the system. The response may take the form of a configuration intent expressed in natural language to be parsed into technical configuration information, or the response may take the form of configuration information usable as such in re-configuring the system, such as the cellular communication network, for example. The response may comprise a software update, for example source code to be used in a software update. The SLM agents may be configured to obtain contextual information on a current state of the system and to generate the response based at least in part also on this contextual information. Thus technical benefits are obtained in that the time required in generating the response is reduced compared to a situation where human operators generate the response after analysing the alert. The response may be implemented in the system automatically, or only after approval from human operators, depending on the embodiment. Actions taken in response to alerts based on the generated response may include, for example, resetting an affected node to a default state, updating software in the node, or re-configuring operating parameters, such as frequency used, in the node.
[0016] FIGURE 1 illustrates an example system in accordance with at least some embodiments. The example shown in FIGURE 1 is a cellular system, but the herein disclosedmethods are not limited to being applied in a cellular context but may be applied alternatively in e.g. a system such as a fixed communication network or an industrial process installation, such as a nuclear power station. FIGURE 1 illustrates a radio access network, RAN, 102, comprising plural base stations, which are configured to operate in accordance with a cellular communication standard, such as long term evolution, LTE, or fifth generation, 5G, also known as New Radio, NR, both as specified by the 3rdgeneration partnership project, 3GPP. Where a non-cellular system is used, access nodes, such as access points, corresponding to base stations of RAN 102 may be configured in accordance with a non-cellular communication standard such as wireless local area network, WLAN, or worldwide interoperability for microwave access, WiMAX, for example. In some embodiments, RAN 102 is absent, in these cases the network, NW, may be a wire-line network based on Ethernet or Diameter, for example.
[0017] Base stations of RAN 102 are coupled with core network nodes of core network 103 via links, which may comprise wire-line connections, for example. A few such links are illustrated in FIGURE 1. Core network nodes 110, 120, 130, 140 and 150 may comprise mobility management entities, MME, serving gateways, S-GW, access and mobility management functions, AMF, subscriber information registers, policy enforcement entities, switching nodes, alert management functions and / or network exposure functions, for example. The core network may comprise a gateway 160, enabling communication with further networks, via at least one inter-network link. Some aggregate networks may have more than one core network, which are then connected to each other using at least one communication link.
[0018] Further, in the illustrated example situation, base stations of RAN 102 are in wireless radio communication with user equipments, UEs 101. Each UE may comprise, for example, a smartphone, feature phone, tablet or laptop computer, Intemet-of-Things, loT, node, smart wearable or a connected car connectivity module, for example. Naturally, separate UEs need not be of a same type. The UEs are configured to operate using a same cellular communication standard, or standards, as the base station(s), to obtain interoperability.
[0019] Core network nodes of core network 103 may be standalone physical nodes, running on a dedicated computing substrate, or they, or at least some of them, may be virtualized network nodes, such that more than one virtualized network node may run on asame physical computing substrate. Virtualized network nodes may be migrated from one physical computing substrate to another, for example to perform load balancing between the computing substrates, or to enable software or hardware updating of the computing substrates themselves. Another reason for migrating virtualized network nodes, or their traffic, is to enable repairs in physical hardware used to run the respective node. Core network 103 may comprise both standalone physical nodes and virtualized network nodes. In addition to the physical computing substrates, also virtualized and standalone physical nodes may be updated or otherwise re-configured. Re-configuring may comprise, for example, changing at least one operating parameter or updating to a different software version. Examples of operating parameters include traffic filters, frequencies, frequency reuse patterns, prioritization rules, routing tables, routing policies and bandwidth caps affecting coverage areas, individual subscribers or subscriber classes.
[0020] Nodes of the system, such as RAN 102 nodes and core network 103 nodes, may be configured to automatically, without user intervention, generate alerts, which comprise a timestamp which indicates, in a time of the system or an external time reference, when the alert was generated in response to a change in an operating condition of the node. The alerts further comprise indications of an event the record relates to. The event may be a non-error event or an error event, wherein examples of benign events include new registrations of UEs into the system, successful handovers, measured interference levels and network utilization rates. Examples of error events include a dropped call, a failed UE authorization, a timed-out protocol connection, a failed network procedure, maximum capacity reached and a timed-out random access process. An example of a failed network procedure is a re-configuration process between core network 103 and a base station in RAN 102, which begins but which does not successfully complete, resulting in failure when a timer of the re-configuration process expires. In some embodiments all alerts are of the error type and benign events are not reported in the system using alerts.
[0021] Alerts generated by nodes of the network, such as RAN 102 nodes or CN 103 nodes, comprise indications in the form of technical characteristics relating to the node. For example, they may comprise indications of a node model or manufacturer, identifiers of one or more nodes participating in a process to which the alert relates. An alert may comprise at least one error code which assists in debugging the cause of the alert. A single failure in the network may cause a number of alerts to be generated as a direct and / or indirect consequence. For example in case a base station fails completely due to e.g. a lightningstrike, all protocol connections traversing the base station will be disconnected, causing a number of alerts to be generated from nodes communicating with the failed base station. Further, attempts to re-configure the failed base station from the core network will also fail, causing yet further alerts relating to the failure. In such a case, the alerts generated as a result may all share, among other indications, an identifier of the failed base station as one of the network elements involved in the situation underlying the alert. This identifier may be used to collect these alerts together, such that the identifier acts as a defining characteristic in the set of alerts relating to the failure of the base station. These alerts may then be set in a time order in a time series based on the timestamps of these alerts, for example. The moment the base station failed will be observable in this time series as a time after which the number of alerts is greatly increased compared to the time period before this moment.
[0022] Alerts comprise system alerts and service alerts. These can be created by systems and / or software that monitor the health and the state of the system, such as a network, for example. In case a malfunction happens, and the system becomes unhealthy, alerts are generated which are sent to data alert pipelines, alert queues or ticketing systems, for example. Thus the alerts in a queue comprise information on the technical state of the system.
[0023] In the system of FIGURE 1, one of the core network nodes 110, 120, 130, 140, 150 may be an apparatus configured to process alerts originating in the cellular communication network. Alerts may be raised from servers, system platforms, customerfacing services, core network nodes or base stations, for example. Alerts may be conveyed to this node, which uses plural SLM agents which have been trained to handle alerts from the cellular communication network (or other system). SLM agents can be trained to understand dynamic contextual data and to provide responses to alerts, such as code and configuration updates, configuration intents, and / or reset instructions. For example, the SLM agents may be trained using a set of alerts recorded historically, together with a set of humanoperator generated responses to the alerts. Each SLM agent is trained to handle alerts of a specific type, such that a suitable SLM agent may be selected when an alert arrives, to handle the alert. In at least some embodiments, different SLM agents are trained to handle different types of alerts. This selecting may be based on contents of the alert. Further, the training data may include documentation of the network, tooling documentation and source code of software running in the network. Thus the SLM agents may be trained to generate a meaningful response to a new alert which approximates a response that human operatorswould create. Different alert types may include, for example, base station alerts, UE alerts, core -network alerts, timeout alerts, load status alerts and authentication failure alerts.
[0024] One way to handle the alerts using SLM agents is, that each SLM agent is trained to handle one aspect of handling alerts. Multiple SLM agents may then work together in handling alerts in cooperation with each other, with one SLM agent processing the alert to obtain the response, and another SLM agent accessing information from the system to feed to the SLM agent which generates the response, for example.
[0025] An advantage of the SLM agents is that they may generate the response much faster than humans would, as humans would need to think about the problem underlying the alert, and possibly communicate among themselves. The SLM agents may be trained using historical alerts from the specific system in question, or from a similar system. In some cases, the historical alerts used in the training comprise both alerts from the specific system and from one or more similar systems. The SLM agents may be re-trained with new data to keep them up-to-date with changes in the system, such as a cellular communication network. The re-training may be performed, for example, at a fixed time interval such as weekly or monthly.
[0026] SLMs are scaled-down versions of large language model, LLM, systems, designed to interpret various kinds of information depending on the application. Despite their more compact size, SLMs may, when trained, be capable of handling information using only a fraction of the resources required by LLMs. In particular, individual SLMs, that is, SLM agents, may be capable within a more restricted problem space than LLMs. SLMs are thus well suited to handling alerts from automated systems, which are not general language items but the alerts follow pre-defined format rules and relate to the system in question. In general, SLMs require less training data to train since their tasks are more specialized, and likewise SLMs require substantially less processing resources, thus providing technical effects compared to using LLMs.
[0027] Human operators of the system may include, for example, system operators, service operators, DevOps engineers, on-call engineers, base station operators, and / or base station maintenance personnel. An SLM agent as used herein may have millions, tens of millions, hundreds of millions up to a billion parameters. An LLM may have several billion to more than a hundred billion parameters.
[0028] A technical advantage and effect of a faster generation of the response is that the network can respond to alerts faster, which increases an effective utilization rate of the network as parts of the network remain in an outage or error state for shorter periods of time. Development and training of smaller language models takes less amount of data and shortens development time. Further, compared to LLM solutions using SLM agents provide the advantages, that a footprint of training and running SLMs is smaller, leading to more efficient resource use, reduced electricity use and smaller carbon footprint. Development and training of domain experts can be divided to SLM specialist agents that have subject experience of the problem domain, leading to more efficient model evaluation and development as this can be done by domain experts. SLM agents with domain-specific responsibilities require less permissions and abilities to connect to company assets. Each service is given only the minimum required permissions to access and implement changes to assets. This reduces potential attack surfaces and misuse opportunities of the services. The domains here correspond to specific aspects of the system, such as the RAN 102 and CN 103, for example, authentication issues or inter-base station communication.
[0029] Once the response to the alert is obtained from a suitable, selected SLM agent, it is usable in re-configuring the network to respond to the alert, such as, for example, remedying an underlying cause of the alert, or at least reducing the effects of the underlying cause. The re-configuring may be performed without human intervention, that is, automatically, or alternatively the re-configuring is performed only after human operators have accepted the response generated by the SLM agent. In case the response is a configuration intent, it may be provided to a parser which converts the configuration intent into actionable, technical configuration information, such as parameters, usable in modifying operating parameter(s) of the system. An intent as such may be information which does not comprise explicit configuration parameters, rather it may comprise a description of what is sought to be accomplished by re-configuration, such as making a specific cell smaller. The parser may then determine which configuration information is needed to accomplish the aim expressed in the intent, and the determined configuration information may be sent to nodes to accomplish the re-configuration.
[0030] The SLM agent selected to handle the alert may be configured to not rely on only the training with historical alerts in the generation of the response based on the received alert. In detail, the SLM agent may be configured to use at least one information source distinct from the SLM agent itself in the generation of the response to the alert. Suchinformation sources distinct from the SLM agent may include one or more of: a current state of the system, such as cellular communication network, an alert management guideline, source code of software running in the system, such as cellular communication network, and a node of the system, such as, for example, the node which originated the alert which is being processed. Source code may be available in case it is openly available, such as open-source code, in case the system is controlled by a same entity as operates the SLM agents, or if the entity controlling the SLM agent has produced the software running in the system. In particular, an information source distinct from the selected SLM agent that the selected SLM agent can use when generating a response to the alert is a queue of as of yet unprocessed alerts that have been generated from the network. These alerts often comprise useful information of the state of the network. The alert management guideline is useful in that it may be updated, which will affect the way the SLM agent processes alerts but this does not require re-training the SLM agent. This is a quick way to fine-tune the operation of the SLM agent.
[0031] Of interest is that in addition to, or alternatively to, the afore-mentioned information source(s), the selected SLM agent may utilize another SLM agent in the generation of the response to the alert. This is useful, for example, when a fault affects or is generated from more than one node, or more than one type of hardware or software problem. In particular, the selected SLM agent may provide a query to the another SLM agent, receive a response from the another SLM agent and generate the response to the alert based at least in part on the response from the another SLM agent.
[0032] The current state of the cellular communication network may comprise the information on alerts in queue waiting to be handled, information on nodes which are in fault conditions, information on load statuses of parts of the network, information on ongoing power outages and / or information on ongoing service or system availability problems. Accessing source code or configuration of software used in the network facilitates generation, by the selected SLM agent, of responses to alerts such that the responses include software updates. The software update may be generated by the SLM agent by generating new source code, which may be compiled and sent to the network as a software update. This may take place automatically without user intervention.
[0033] When querying a node for more information, the SLM agent may be empowered to obtain more detail on the alert, providing the benefit that the response is moreaccurate in addressing the underlying cause of the alert. The node queried may be the node which originated the alert, as mentioned above, or a correspondent node of the node which originated the alert. The correspondent node has context information of protocol connections with the node which originated the alert, such context information being potentially useful in analysing the alert as it contains more data than is in the alert itself. When the node which originated the alert is queried, it may provide one or more internal logs, which likely comprise highly relevant information pertaining to the underlying cause of the alert.
[0034] One tool the SLM agent may be configured to use in interfacing with the information source distinct from the SLM agent is retrieval augmented generation, RAG. This involves augmenting the SLM agent with document retrieval, for example using a vector database. Given a query, RAG involves calling a document retriever to retrieve the most relevant document, usually measured by first encoding the query and the documents into vectors, then finding the documents with vectors closest in Euclidean space to the query vector. The SLM agent then generates a response based on the alert, the training data used in training the SLM agent and the retrieved document or documents. RAG may be used by the SLM agent to access more than one information source distinct from the SLM agent in the generation of a single response to a single alert. For example, the SLM agent may use RAG to access the node which originated the alert (or a correspondent node thereof), a current state of the network and an alert management guideline when generating a single response to a single alert.
[0035] As noted above, the response may comprise a software update to a node, or nodes, of the system. Additionally or alternatively, the response may comprise a configuration change of at least one operating parameter of the system, and / or a new software module to be installed in a node of the system. Examples of operating parameters include traffic filters, routing tables, prioritization rules, operating frequencies, and various timing parameters. The response may comprise one or more change to a service other than the one which generated the alert, in case this other service is affected by the cause of the alert, or by the response. The response may comprise a system-wide parameter change, such as a modification of a timeout value used in a specific protocol connection type, such as transmission control protocol, TCP, or real-time transport protocol, RTP.
[0036] In a cellular communication network, the node running the selected SLM agent may be configured to provide the response to a simulator to check if the response is valid inthe cellular communication network, and to only perform the re-configuring of the cellular communication network with the response if the simulator indicates the response is valid. The simulator is a function configured to simulate the operation of at least a part of the cellular communication network, using software or a mix of software and hardware elements. The simulator may be run in the core network 103, or in an external system, for example. Using the simulator provides the benefit, that erroneous responses the selected SLM agent may occasionally produce are not sent to the cellular communication network for re-configuring that system, which might cause yet further problems and alerts. In other words, the quality of the alert management system is increased by the use of the simulator. The providing of the response to the simulator, the running of the simulator, and the reconfiguring when the response is validated as valid in the simulator may be performed without human intervention, automating the alert management system and resulting in substantial savings in time and system availability. In case the simulator indicates the response is not valid, the apparatus, that is the node running the SLM agents, may be configured to reject the response and inform human operators.
[0037] Performing the re-configuring without human intervention automates, for instance, correction of common configuration mistakes, server and container system resource allocations, and bugs in code that may interrupt live services. The SLM agents, or an apparatus configured to select the SLM agent to handle the alert, may be configured to identify alerts which are originated based on complex problems, and it may be configured to forward such alerts to human operators for analysis rather than perform the automatic reconfiguration of the system described herein.
[0038] Alternatively to informing human operators and rejecting the response, the node running the apparatus running the SLM agents may be configured to provide, responsive to the simulator indicating the response is not valid, the response to the selected SLM agent together with the alert and an error message from the simulator, to obtain a second response from the selected SLM agent, and to use the second response to perform the re-configuring of the cellular communication network as a response to an indication of validity returned by the simulator as a response the second response being provided to it as input. This iterative process may be repeated a few times to seek to obtain a valid response. In case a preconfigured maximum number of iterations is reached without the simulator indicating a response provided to it is valid, the iterating may be stopped and the alert be referred to human operators. While this would incur delays, the system would still overallprovide dramatic savings in time if a significant proportion of incoming alerts are nonetheless successfully handled by the SLM agent(s) without human intervention. Handling of alerts by human operators may require debugging multiple services, source code, and systems to find the root cause for a problem. If an issue is known, a playbook may be searched for any possible known solutions. In case of an unknown issue, manual debugging, configuration and programming for resolving the issue may be required. These investigations take more time depending on how familiar or unfamiliar the environment is for the human operator.
[0039] The simulator used to validate the responses may implement end-to-end, E2E, testing for running a production-like environment, including but not limited to components, hardware and systems and executing the desired technical and business functionalities to validate that all desired functions of a system work as intended. The simulator may be, for example, a mix of software simulating elements of the system, and actual hardware system components interfaced with the simulator software.
[0040] In case the response fails in the cellular communication network, the apparatus running the SLM agents, or another node, may be configured to roll the network back to a state preceding the re-configuration with the response from the SLM agent(s). In such a case, the issue may be referred to human operators.
[0041] Overall, therefore, benefits are obtained in that time spent in manual investigation and debugging is reduced. Further, an aggregated information and working solution is obtained via the SLM agents, further training the model may be conducted for the future in case similar issues arise. As the SLM agent is not static and does not rely exclusively on pre-trained information, service connectivity and data retrieval capabilities can provide more variety of support and enrichment of alert information with up-to-date data from live systems and services. In particular, alerts stemming from already known issue types can be solved faster when a working solution is generated and validated automatically without human intervention, reducing the time spent on investigation work. For visibility and a history trail of automation activities, human operators can monitor and follow the activity of the automation to see what issues were resolved and how they were resolved.
[0042] FIGURE 2 illustrates an example solution in accordance with at least some embodiments of the present invention. This figure relates in particular to embodiments where the system is a cellular communications network. The selected SLM agent 210 is illustratedat the top. The selected SLM agent 210 may access operating manuals 220 of the cellular communication network, source codes 230 of software running in nodes of the network, 235 runtime configurations active in the network, guidelines and playbooks 240 of the network, metadata 250 of systems and platforms comprised in the cellular communication network, service integration connectivity information 260 of the network. The service integration connectivity information 260 may further comprise logs 270 of services and connections, and back-end application programming interfaces, APIs, metadata 280.
[0043] Manuals 220, source codes 230, guidelines 240 and metadata 250 may be included in training data used to train selected SLM agent 210 to prepare the responses responsive to the alerts.
[0044] FIGURE 3 illustrates an example apparatus capable of supporting at least some embodiments of the present invention. Illustrated is device 300, which may comprise, for example, an apparatus running a core network node, the apparatus being configured to run the SLM agents, or another apparatus, such as a server connected with the core network, the server being configured to run the SLM agents. Comprised in device 300 is processor 310, which may comprise, for example, a single- or multi-core processor wherein a single-core processor comprises one processing core and a multi-core processor comprises more than one processing core. Processor 310 may comprise, in general, a control device. Processor 310 may comprise more than one processor. When processor 310 comprises more than one processor, device 300 may be a distributed device wherein processing of tasks takes place in more than one physical unit. Processor 310 may be a control device. A processing core may comprise, for example, a Cortex- A8 processing core manufactured by ARM Holdings or a Zen processing core designed by Advanced Micro Devices Corporation. A processing core or processor may be, or may comprise, at least one qubit. Processor 310 may comprise at least one AMD Opteron and / or Intel Core processor. Processor 310 may comprise at least one application-specific integrated circuit, ASIC. Processor 310 may comprise at least one field-programmable gate array, LPGA. Processor 310, optionally together with memory and computer instructions, may be means for performing method steps in device 300, such as storing, processing and re-configuring, for example. Processor 310 may be configured, at least in part by computer instructions, to perform actions.
[0045] Device 300 may comprise memory 320. Memory 320 may comprise randomaccess memory and / or permanent memory. Memory 320 may comprise at least one RAMchip. Memory 320 may be a computer readable medium. Memory 320 may comprise solid- state, magnetic, optical and / or holographic memory, for example. Memory 320 may be at least in part accessible to processor 310. Memory 320 may be at least in part comprised in processor 310. Memory 320 may be means for storing information. Memory 320 may comprise computer instructions that processor 310 is configured to execute. When computer instructions configured to cause processor 310 to perform certain actions are stored in memory 320, and device 300 overall is configured to run under the direction of processor 310 using computer instructions from memory 320, processor 310 and / or its at least one processing core may be considered to be configured to perform said certain actions. Memory 320 may be at least in part external to device 300 but accessible to device 300. Memory 320 may be transitory or non-transitory. The term “non-transitory”, as used herein, is a limitation of the medium itself (that is, tangible, not a signal) as opposed to a limitation on data storage persistency (for example, RAM vs. ROM).
[0046] Device 300 may comprise a transmitter 330. Device 300 may comprise a receiver 340. Transmitter 330 and receiver 340 may be configured to transmit and receive, respectively, information in accordance with at least one cellular or non-cellular standard. Transmitter 330 may comprise more than one transmitter. Receiver 340 may comprise more than one receiver. Transmitter 330 and / or receiver 340 may be configured to operate in accordance with a suitable communication arrangement, such as Ethernet or Diameter, for example.
[0047] Device 300 may comprise user interface, UI, 360. UI 360 may comprise at least one of a display, a keyboard, a touchscreen, a vibrator arranged to signal to a user by causing device 300 to vibrate, a speaker or a microphone. A user may be able to operate device 300 via UI 360, for example to configure SLM or alert management parameters, to manage digital files stored in memory 320 or on a cloud accessible via transmitter 330 and receiver 340.
[0048] Processor 310 may be furnished with a transmitter arranged to output information from processor 310, via electrical leads internal to device 300, to other devices comprised in device 300. Such a transmitter may comprise a serial bus transmitter arranged to, for example, output information via at least one electrical lead to memory 320 for storage therein. Alternatively to a serial bus, the transmitter may comprise a parallel bus transmitter. Likewise processor 310 may comprise a receiver arranged to receive information inprocessor 310, via electrical leads internal to device 300, from other devices comprised in device 300. Such a receiver may comprise a serial bus receiver arranged to, for example, receive information via at least one electrical lead from receiver 340 for processing in processor 310. Alternatively to a serial bus, the receiver may comprise a parallel bus receiver. Device 300 may comprise further devices not illustrated in FIGURE 3.
[0049] Processor 310, memory 320, transmitter 330, receiver 340, and / or UI 360 may be interconnected by electrical leads internal to device 300 in a multitude of different ways. For example, each of the aforementioned devices may be separately connected to a master bus internal to device 300, to allow for the devices to exchange information. However, as the skilled person will appreciate, this is only one example and depending on the embodiment various ways of interconnecting at least two of the aforementioned devices may be selected without departing from the scope of the present invention.
[0050] FIGURE 4 illustrates a solution in accordance with at least some embodiments of the present invention. In the solution of FIGURE 4, alerts concerning a cellular communication network 450 are received in monitoring service 420 from nodes of network 450 originating the alerts. Monitoring service 420 monitors nodes and services of the network 450. The alerts are provided from monitoring service 420 to alert queue 430, from which they are fed to SEM node 410 either directly, or via ticketing system 440. The connection between queue 430 and SLM node 410 is thus optional in nature, as indicated also by the dashed-line nature of the arrow between these two elements 430, 410. Human operators 4100 may observe alerts in the ticketing system 440 and, optionally, act on them, for example when SLM node 410 informs human operators 4100 that their attention is needed, as described herein above.
[0051] SLM node 410 is configured to run agent services coordinator 412, tester 414, operator 416, documenter 418 and developer 419. Coordinator 412 handles coordination between multiple agent services, their status and output. Operator 416 handles company server assets and their configuration and logs. It also handles the operation and management of base station configuration and operations. Tester 414 handles the validation of the output of developer 419. Developer 419 handles code analysis and generation. It has access to company code assets and version control. Documenter 418 handles analysing and responding to queries of internal company knowledge base, responding to queries from theDeveloper and Base Station Maintainer. Developer 419 may comprise the plural SLM agents configured to handle alerts.
[0052] Network 450 produces logs to logging system 470, from where these logs are available to the SLM agents of SLM node 410, along with other information sources, as described herein above. An example of such other information sources is backend connectivity 480, which may be used to query e.g. servers and services. Simulator 460, which may be an end-to-end simulator, is used as described herein above to validate responses generated by selected SLM agents. Validated responses may be implemented from SLM node 410 to the network 450, as illustrated in FIGURE 4.
[0053] FIGURE 5 is a signalling diagram of an example embodiment of the invention.Along the vertical axes are, from left to right, in terms of FIGURE 4, coordinator 412, developer 419, operator 416, tester 414 and documenter 418. Time advances from the top toward the bottom.
[0054] In phase 510, an alert is notified to coordinator 412. In response, phase 520, coordinator 412 requests for log and service analysis from operator 416. In phase 530, operator 416 analyses logs, for example by querying logging system 470 of FIGURE 4, and obtaining contextual data from a back-end server. Operator 416 responds in phase 540 to the request of phase 520. In phase 550, coordinator 412 obtains a documentation analysis on the issue underlying the alert of phase 510 from documenter 418. Documenter 418 obtains contextual data from system documentation and returns, still in phase 550, a report on known solutions or probably documented information on the issue underlying the alert of phase 510, to coordinator 412.
[0055] In phase 560 coordinator 412 requests a resolution on the issue from developer 419. Coordinator 412 may be tasked with selecting an SLM agent to handle the alert, or then developer 419 performs this selection. Responsively, in phase 570, developer 419 generates the response to the alert, using an SLM agent selected to handle the alert. Developer 419 may request and use e.g. configuration data and / or source code in the generation of the response with the selected SLM agent. In phase 580 developer 419 submits the generated response for testing to tester 414. In response, phase 590, tester runs a validation of the response using simulator 460 of FIGURE 4. A result of the validation is returned from tester 414 to developer 419 in phase 5100.
[0056] In phase 5110, if the validation indicates the response is valid in the system, developer 419 submits the response for implementation by e.g. sending it to a version control system. The response is then used to re-configure the system, such as, for example, a cellular communication network or other communication system.
[0057] In case device state modification or configuration is required, coordinator 412 may request operator 416 to modify the system state. Operator 416 may then request information about the system from documenter 418. Operator 416 may then check the current configuration of the system either from version control or by connecting to the system and examining the current state. Documenter 418 returns collected information about the system. Operator 416 may analyse the documentation for possible resolutions and attempts to create a solution. After implementing a solution, the operator 416 submits the configuration changes to the tester for validation. In case validation is successful, the solution is deployed. In case validation fails, operator 416 reattempts the solution by examining the response from the tester. The system may be further monitored for signs of successful or failed signals.
[0058] FIGURE 6 is a flow graph of a method in accordance with at least some embodiments of the present invention. The phases of the illustrated method may be performed in device 110, an auxiliary device or a personal computer, for example, or in a control device configured to control the functioning thereof, when installed therein.
[0059] Phase 610 comprises storing plural small language model, SLM, agents, each SLM agent being configured to provide responses to alerts of a specific type which originate in a system. Phase 620 comprises processing an alert from the system by selecting an SLM agent and providing the alert to the selected SLM agent to obtain from the selected SLM agent a response to the alert. Finally, phase 630 comprises re-configuring the system with the response. As is discussed herein above, the system may be a cellular communication network, for example. Being configured to provide the responses comprises being trained to provide the responses.
[0060] It is to be understood that the embodiments of the invention disclosed are not limited to the particular structures, process steps, or materials disclosed herein, but are extended to equivalents thereof as would be recognized by those ordinarily skilled in the relevant arts. It should also be understood that terminology employed herein is used for the purpose of describing particular embodiments only and is not intended to be limiting.
[0061] Reference throughout this specification to one embodiment or an embodiment means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present invention. Thus, appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Where reference is made to a numerical value using a term such as, for example, about or substantially, the exact numerical value is also disclosed.
[0062] As used herein, a plurality of items, structural elements, compositional elements, and / or materials may be presented in a common list for convenience. However, these lists should be construed as though each member of the list is individually identified as a separate and unique member. Thus, no individual member of such list should be construed as a de facto equivalent of any other member of the same list solely based on their presentation in a common group without indications to the contrary. In addition, various embodiments and example of the present invention may be referred to herein along with alternatives for the various components thereof. It is understood that such embodiments, examples, and alternatives are not to be construed as de facto equivalents of one another, but are to be considered as separate and autonomous representations of the present invention.
[0063] Furthermore, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the preceding description, numerous specific details are provided, such as examples of lengths, widths, shapes, etc., to provide a thorough understanding of embodiments of the invention. One skilled in the relevant art will recognize, however, that the invention can be practiced without one or more of the specific details, or with other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the invention.
[0064] While the forgoing examples are illustrative of the principles of the present invention in one or more particular applications, it will be apparent to those of ordinary skill in the art that numerous modifications in form, usage and details of implementation can be made without the exercise of inventive faculty, and without departing from the principles and concepts of the invention. Accordingly, it is not intended that the invention be limited, except as by the claims set forth below.
[0065] The verbs “to comprise” and “to include” are used in this document as openlimitations that neither exclude nor require the existence of also un-recited features. The features recited in depending claims are mutually freely combinable unless otherwise explicitly stated. Furthermore, it is to be understood that the use of "a" or "an", that is, a singular form, throughout this document does not exclude a plurality.
[0066] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.INDUSTRIAL APPLICABILITY
[0067] At least some embodiments of the present invention find industrial application in alert handling in systems, such as communication networks, for example.ACRONYMS LISTLLM large language modelSLM small language model RAG retrieval augmented generationRTP real-time transport protocolTCP transmission control protocolREFERENCE SIGNS LISTCITATION LISTHughes, Alyssa (12 December 2023). "Phi-2: The surprising power of small language models". Microsoft Research. Retrieved 13 December 2023.
Claims
CLAIMS:
1. An apparatus (300) comprising at least one processing core (310) and at least one memory (320) storing instructions that, when executed by the at least one processing core (310), cause the apparatus (300) at least to:- store (610) plural small language model, SLM, agents (210), each SLM agent (210) being configured to provide responses to alerts of a specific type which originate in a system;- process (620) an alert from the system by selecting, based on contents of the alert, an SLM agent (210) and providing the alert to the selected SLM agent (210) to obtain from the selected SLM agent (210) a response to the alert, and- re-configure (630) the system with the response to remedy a cause of the alert, wherein the system is a cellular telecommunication network (450) and the reconfiguring (630) comprises changing at least one operating parameter of the cellular telecommunication network (450).
2. The apparatus (300) according to claim 1, further configured to obtain the response to the alert from the selected SLM agent (210) by enabling the selected SLM agent (210) to communicate with at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210), using retrieval-augmented generation to generate the response to the alert.
3. The apparatus (300) according to claim 2, wherein the at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210) comprises information representing a current state of the system.
4. The apparatus (300) according to claim 2 or 3, wherein the at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210) comprises an alert management guideline (240).
5. The apparatus (300) according to any of claims 2 - 4, wherein the at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210) comprises source code (230) of software running in the system.
6. The apparatus (300) according to any of claims 2 - 5, wherein the at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210) comprises a node of the system.
7. The apparatus (300) according to claim 6, wherein the node of system is a node which originated the alert.
8. The apparatus (300) according to any of claims 1 - 7, wherein the response comprises one or more of the following: a software update for at least a part of system, and a new software module to be installed in the system.
9. The apparatus (300) according to any of claims 1 - 8, further configured to provide the response to a simulator (460) to check if the response is valid in the system, and to only perform the re-configuring (630) of the system with the response if the simulator (460) indicates the response is valid.
10. The apparatus (300) according to claim 9, further configured to provide, responsive to the simulator (460) indicating the response is not valid, the response to the selected SLM agent (210) together with an error message from the simulator (460), to obtain a second response, and to use the second response to perform the re-configuring (630) of the system.
11. The apparatus (300) according to any of claims 1 - 10, configured to perform the reconfiguring (630) of the system with the response without human intervention.
12. The apparatus (300) according to claims 1 - 10, configured to perform the re-configuring (630) of the system with the response responsive to a human operator accepting the response.
13. A method comprising:- storing (610) plural small language models, SLM agent (210), each SLM agent (210) being configured to provide responses to alerts of a specific type which originate in a system;- processing (620) an alert from the system by selecting, based on contents of the alert, an SLM agent (210) and providing the alert to the selected SLM agent (210) to obtain from the selected SLM agent (210) a response to the alert, and- re-configuring (630) the system with the response to remedy a cause of the alert, wherein the system is a cellular telecommunication network (450) and the reconfiguring (630) comprises changing at least one operating parameter of the cellular telecommunication network (450).
14. The method according to claim 13, further comprising obtaining the response to the alert from the selected SLM agent (210) by enabling the selected SLM agent (210) to communicate with at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210), using retrieval-augmented generation to generate the response to the alert15. The method according to claim 14, wherein the at least one information source (220, 230, 235, 240, 250, 260, 270, 280) distinct from the selected SLM agent (210) comprises one or more of the following: information representing a current state of the system, an alert management guideline (240), source code (230) of software running in the system, or a node of the system.
16. A non-transitory computer readable medium having stored thereon a set of computer readable instructions that, when executed by at least one processor (310), cause an apparatus (300) to at least:- store (610) plural small language models, SLM agents (210), each SLM agent (210) being configured to provide responses to alerts of a specific type which originate in a system;- process (620) an alert from the system by selecting, based on contents of the alert, an SLM agent (210) and providing the alert to the selected SLM agent (210) to obtain from the selected SLM agent (210) a response to the alert, and- re-configure (630) the system with the response to remedy a cause of the alert, wherein the system is a cellular telecommunication network (450) and the reconfiguring (630) comprises changing at least one operating parameter of the cellular telecommunication network (450).