Method, apparatus and computer program

By processing the data set of user equipment in the network function of the communication network and calculating the difference in the loss function, the application of the differential privacy mechanism is verified, and the problem of difficulty in effectively verifying privacy requests in the prior art is solved, and effective protection of user equipment privacy is achieved.

CN120021209APending Publication Date: 2025-05-20NOKIA NETWORKS OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411634814.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-17
Filing Date
2024-11-15
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

In communication networks, it is difficult for the prior art to effectively verify whether the privacy requests of user equipment are respected, especially how to ensure the application of differential privacy mechanisms during the training of machine learning models.

Method used

By storing and processing a data set of user equipment in the network function, including the first data that has been provided to the network function and the second data that has not been provided, the machine learning model is used to train and calculate the difference in the loss function to determine whether the difference privacy mechanism has been applied to the first data.

Benefits of technology

It realizes effective verification of user equipment privacy requests in communication networks, ensuring that the differential privacy mechanism is applied during the training of machine learning model, thereby protecting the privacy of user equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120021209A_ABST
    Figure CN120021209A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a method, an apparatus, and a computer program. An apparatus comprising: means for storing a data set comprising first data and second data for at least one user equipment, the first data having been provided to a network function and the second data having not been provided to the network function; means for storing ground live tags for the first data and the second data; means for sending data set-based information to a network function; means for receiving, from the network function, information for determining a first value of a loss function; means for receiving, from the network function, information for determining a second value of the loss function; means for determining a difference between the first value of the loss function and the second value of the loss function; and means for comparing the difference to a threshold to determine whether the difference privacy mechanism is applied to the first data before the network function trains the machine learning model based on the first data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments of the present disclosure relate to methods, apparatuses, systems, and computer programs for communication networks. Some examples can be used for privacy auditing. Background Art

[0002] A communication network can be regarded as a facility that enables communication between two or more communication devices or provides access of a communication device to a data network. A mobile or wireless communication network is an example of a communication network. A communication device can be provided with services via an application server.

[0003] Such communication networks operate according to standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). An example of a standard is the so-called 5G (Fifth Generation) standard provided by 3GPP. Summary of the Invention

[0004] Some example embodiments of the present disclosure will be described with respect to certain aspects. These aspects are not intended to indicate the key or essential features of the embodiments of the present disclosure, nor are they intended to limit its scope. Given the present disclosure, other features, aspects, and elements will be readily apparent to those skilled in the art.

[0005] According to some examples, an apparatus includes: means for storing a data set including first data and second data for at least one user equipment, wherein the first data has been provided to a network function and the second data has not been provided to the network function, and wherein the network function trains a machine learning model based on the first data; means for storing ground truth labels for the first data and the second data; means for sending information based on the data set to the network function; means for receiving, from the network function, information for determining a first value of a loss function, the first value of the loss function indicating a difference between the ground truth label of the first data and at least one predicted ground truth label of the first data determined by the network function using the machine learning model; means for receiving, from the network function, information for determining a second value of the loss function, the second value of the loss function indicating a difference between the ground truth label of the second data and at least one predicted ground truth label of the second data determined by the network function using the machine learning model; means for determining a difference between the first value of the loss function and the second value of the loss function; means for comparing the difference with a threshold to determine whether a differential privacy mechanism has been applied to the first data before the network function trains the machine learning model based on the first data.

[0006] According to some examples, the information for determining the first value of the loss function includes the predicted label for the first data and the information for determining the first value of the loss function includes the predicted label for the second data, and the apparatus includes: a component for determining the first value of the loss function based on the predicted label for the first data and the ground truth label for the first data; a component for determining the first value of the loss function based on the predicted label for the second data and the ground truth label for the second data.

[0007] According to some examples, the apparatus includes: a component for sending the predicted label for the first data to a network function, wherein the information for determining the first value of the loss function includes: the predicted label for the first data and the first value of the loss function; a component for sending the predicted label for the second data to a network function, wherein the information for determining the second value of the loss function includes the predicted label for the first data and the second value of the loss function.

[0008] According to some examples, the data set is stored in a first matrix, and wherein the apparatus includes: a component for swapping columns of the first matrix with a second matrix to provide a third matrix; a component for storing the second matrix; wherein the information based on the data set includes the third matrix.

[0009] According to some examples, the information for determining the second value of the loss function apparatus includes a fourth matrix, and wherein the apparatus includes: a component for using the third matrix to swap columns of the fourth matrix to correspond to the order of the columns of the first matrix.

[0010] According to some examples, the apparatus includes: a component for sending an instruction to increase the privacy level of the differential privacy mechanism for the first data to a network function when it is determined that the differential privacy mechanism is not applied to the first data.

[0011] According to some examples, the first data set and / or the second data set includes at least one of the following: temperature measurements from at least one user equipment during a first time period; location data for at least one user equipment during a second time period.

[0012] According to some examples, the apparatus includes a 5G core network function.

[0013] According to some examples, the network function includes a Network Data Analytics Function (NWDAF).

[0014] According to one aspect, a device is provided that includes at least one processor and at least one memory. The at least one memory stores instructions that, when executed by the at least one processor, cause the device to at least perform the following: store a data set including first data and second data for at least one user equipment, where the first data has been provided to a network function and the second data has not been provided to the network function, and where the network function trains a machine learning model based on the first data; store components for ground truth labels for the first data and the second data; send information based on the data set to the network function; receive information for determining a first value of a loss function from the network function, the first value of the loss function indicating a difference between the ground truth label of the first data and at least one predicted ground truth label of the first data determined by the network function using the machine learning model; receive information for determining a second value of the loss function from the network function, the second value of the loss function indicating a difference between the ground truth label of the second data and at least one predicted ground truth label of the second data determined by the network function using the machine learning model; determine a difference between the first value of the loss function and the second value of the loss function; compare the difference with a threshold to determine whether a differential privacy mechanism was applied to the first data before the network function trained the machine learning model based on the first data.

[0015] According to some examples, the information for determining the first value of the loss function includes a predicted label for the first data and the information for determining the first value of the loss function includes a predicted label for the second data, and the at least one processor may be configured to cause the device to perform: determine the first value of the loss function based on the predicted label for the first data and the ground truth label for the first data; determine the first value of the loss function based on the predicted label for the second data and the ground truth label for the second data.

[0016] According to some examples, the at least one processor may be configured to cause the device to perform: send the predicted label for the first data to the network function, where the information for determining the first value of the loss function includes the predicted label for the first data and the first value of the loss function; send the predicted label for the second data to the network function, where the information for determining the second value of the loss function includes the predicted label for the first data and the second value of the loss function.

[0017] According to some examples, the data set is stored in a first matrix, and the at least one processor may be configured to cause the device to perform: swap columns of the first matrix using a second matrix to provide a third matrix; store the second matrix; where the information based on the data set includes the third matrix.

[0018] According to some examples, the information for determining the second value of the loss function apparatus includes a fourth matrix, and at least one processor may be configured to cause the apparatus to perform: using a third matrix to swap columns of the fourth matrix to correspond to the order of the columns of the first matrix.

[0019] According to some examples, at least one processor may be configured to cause the apparatus to perform: when determining that the differential privacy mechanism is not applied to the first data, sending an instruction to a network function to increase the privacy level of the differential privacy mechanism for the first data.

[0020] According to some examples, the first data set and / or the second data set includes at least one of the following: temperature measurements from at least one user equipment during a first time period; location data for at least one user equipment during a second time period.

[0021] According to some examples, the apparatus includes a 5G core network function.

[0022] According to some examples, the network function includes a Network Data Analytics Function (NWDAF).

[0023] According to one aspect, a method is provided, including: storing a data set including first data and second data for at least one user equipment, where the first data has been provided to a network function and the second data has not been provided to the network function, and where the network function trains a machine learning model based on the first data; a component for storing ground truth labels for the first data and the second data; sending information based on the data set to the network function; receiving, from the network function, information for determining a first value of a loss function, the first value of the loss function indicating a difference between the ground truth label of the first data and at least one predicted ground truth label of the first data determined by the network function using the machine learning model; receiving, from the network function, information for determining a second value of the loss function, the second value of the loss function indicating a difference between the ground truth label of the second data and at least one predicted ground truth label of the second data determined by the network function using the machine learning model; determining a difference between the first value of the loss function and the second value of the loss function; comparing the difference with a threshold to determine whether the differential privacy mechanism was applied to the first data before the network function trained the machine learning model based on the first data.

[0024] According to some examples, the information for determining the first value of the loss function includes a predicted label for the first data and the information for determining the first value of the loss function includes a predicted label for the second data, and the method includes: determining the first value of the loss function based on the predicted label for the first data and the ground truth label for the first data; determining the first value of the loss function based on the predicted label for the second data and the ground truth label for the second data.

[0025] According to some examples, the method includes: sending a prediction label for first data to a network function, wherein the information for determining a first value of a loss function includes the prediction label for the first data and the first value of the loss function; sending a prediction label for second data to the network function, wherein the information for determining a second value of the loss function includes the prediction label for the first data and the second value of the loss function.

[0026] According to some examples, a data set is stored in a first matrix, and the method includes: using a second matrix to swap columns of the first matrix to provide a third matrix; storing the second matrix; wherein the information based on the data set includes the third matrix.

[0027] According to some examples, the information for determining a second value of a loss function device includes a fourth matrix, and the method includes: using a third matrix to swap columns of the fourth matrix to correspond to the order of the columns of the first matrix.

[0028] According to some examples, the method includes: sending an instruction to a network function to increase a privacy level of a differential privacy mechanism for first data when it is determined that the differential privacy mechanism is not applied to the first data.

[0029] According to some examples, the first data set and / or the second data set includes at least one of the following: temperature measurements from at least one user equipment during a first time period; location data for at least one user equipment during a second time period.

[0030] According to some examples, the method is performed by a 5G core network function.

[0031] According to some examples, the network function includes a Network Data and Analytics Function (NWDAF).

[0032] According to one aspect, there is provided a computer-readable medium including instructions that, when executed by a device, cause the device to at least perform the following: store a data set including first data and second data for at least one user equipment, where the first data has been provided to a network function and the second data has not been provided to the network function, and where the network function trains a machine learning model based on the first data; store components for ground truth labels for the first data and the second data; send information based on the data set to the network function; receive, from the network function, information for determining a first value of a loss function, the first value of the loss function indicating a difference between the ground truth label of the first data and at least one predicted ground truth label of the first data determined by the network function using the machine learning model; receive, from the network function, information for determining a second value of the loss function, the second value of the loss function indicating a difference between the ground truth label of the second data and at least one predicted ground truth label of the second data determined by the network function using the machine learning model; determine a difference between the first value of the loss function and the second value of the loss function; compare the difference with a threshold to determine whether a differential privacy mechanism was applied to the first data before the network function trained the machine learning model based on the first data.

[0033] According to one aspect, there is provided a non-transitory computer-readable medium including program instructions that, when executed by a device, cause the device to perform a method according to any of the foregoing aspects at least.

[0034] Above, many different embodiments have been described. It should be understood that additional embodiments may be provided by any combination of any two or more of the above embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Some example embodiments will now be described, by way of non-limiting and illustrative examples only, with reference to the accompanying drawings, in which:

[0036] Figure 1 A representation of a fifth-generation communication system is shown;

[0037] Figure 2 A first example algorithm is shown;

[0038] Figure 3 A second example algorithm is shown;

[0039] Figure 4 Results of an example simulation are shown;

[0040] Figure 5 An example method is shown;

[0041] Figure 6 A representation of a device of a communication system according to some example embodiments is shown Figure 1 is shown;

[0042] Figure 7 shows a representation of an apparatus in accordance with some example embodiments; and

[0043] Figure 8 shows a schematic diagram of a non - volatile memory medium storing instructions which, when executed by a processor, permit the processor to perform one or more steps of the methods disclosed herein. Detailed Description

[0044] In a communication network, the network may be required to maintain a certain level of privacy of the identity of a user equipment (UE). For example, a request may be sent from the UE, or may be requested by another entity in the network. The request may be to at least partially protect the UE's privacy using privacy - enhancing technologies (PET) or by anonymizing data from the UE. Some examples described herein provide methods, systems, and computer programs for verifying whether a privacy request for a UE is respected in the network. For example, the network may respect the request by receiving the privacy request, processing the privacy request, and successfully implementing the condition(s) in the privacy request.

[0045] After verifying whether the privacy request is respected, the verification result may be provided to the UE. In some examples, the verification result may be provided to other network entities. This is useful in communication networks (such as 5G, 6G networks) that include software or components from different operators and where inter - operator UE privacy verification is required (e.g., so that one operator can determine whether another operator is correctly respecting UE privacy requests).

[0046] In the following, various example embodiments will be explained with reference to a communication device capable of communicating with a communication system. Before explaining the embodiments of the methods and apparatuses of the present disclosure in detail, the fifth - generation communication system (5GS), its access network and core network (5GC), and the communication device are briefly explained Figure 1 is briefly explained.

[0047] Figure 1 shows a schematic diagram of a 5G communication system (5GS). The 5GS may include a user equipment (UE), an access network (such as a 5G radio access network (5G - RAN) or a next - generation radio access network (NG - RAN)), a 5G core network (5GC), and one or more application functions. The application functions may be deployed in the 5GS as trusted application functions, or may be deployed or hosted on one or more application servers of a data network. Such application functions are non - trusted application functions. The 5GS connects the UE to the data network, the access network, and the 5GC (e.g., the UPF of the 5GC).

[0048] 5G-RAN may include one or more radio access nodes, such as gNodeB (gNB). A gNB may include one or more gNodeB (gNB) distributed units connected to a centralized unit of one or more gNodeB (gNB).

[0049] 5GC may include the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM); Application Function (AF); Authentication Server Function (AUSF); Access and Mobility Management Function (AMF); Session Management Function (SMF), and User Plane Function (UPF). Figure 1 Also shown are various interfaces (N1, N2, etc.) that can be implemented between the various elements of the system.

[0050] Some examples consider the joint training of ML models that utilize differential privacy (DP). Generally, in the DP federated learning (FL) method, noise (with a certain tractable distribution, such as Gaussian) is added to the model updates to enhance privacy.

[0051] Consider the DP version of the gradient descent algorithm. DP Gradient Descent (DP-GD) differs from GD such that the sample gradients of a stochastic mini-batch are clipped to have an L 2 norm of at most C (a predefined constant), and Gaussian noise with variance σ 2 is added to the sum of the gradients. One iteration of the algorithm is given by:

[0052]

[0053] where θ represents the model parameters represented as a d-dimensional vector, and each element of the noise vector Z j is distributed as and η represents the learning rate and N represents the total number of data points.

[0054] The DP mechanism that can be analyzed here is the total noisy gradient:

[0055]

[0056] (ε,δ)-DP guarantees (Dwork, C., McSherry, F., Nissim, K., & Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4 - 7, 2006. Proceedings 3 (pp. 265 - 284). Springer Berlin Heidelberg) are obtained, for example, by parsing the bounds.

[0057]

[0058] Generally speaking, in the DP method, the overall privacy guarantee depends on the sensitivity of the local function f i (X i ) and the total variance of the added noise. δ can be a fixed value. The value of δ can be very small (e.g., 1 / n, where N is the total size of the dataset). The value of ε characterizes the privacy protection level and is determined by various parameters (here only determined by the noise level since delta is fixed). However, without some computationally and architecturally demanding processes, the only participant who knows whether user i has added their share of the noise is user i. Suppose only m users (m < n) actually add noise. Then the epsilon of this model will be higher than the epsilon promised by the server providing the DP mechanism times.

[0059] Consider an example where there is a collusive attack between n - 1 users and the server such that the n - 1 users send some vectors known to the server that will reveal the noise message completely to the nth user, i.e., the message y n will have (ε,δ)-DP protection, with ε given by the following

[0060]

[0061] This is higher than the ε that will be promised by the server times.

[0062] The example performs an audit by determining whether the machine learning model used in the network has been trained using training data that respects privacy requests for UE identities. This can be performed by comparing the loss values or prediction accuracy measurements of the machine learning model used for training when using the training data and when using the test data. The test data has not been processed using PET or anonymized. When the training data has not been processed using PET (e.g., anonymized data or removal of at least some user-identifiable data), when the trained ML model performs predictions using the training data and the test data, the trained ML model should perform better on the training data than on the test data. Thus, a threshold / statistical test scheme can analyze how much better the trained ML model performs predictions on the training data than on the test data to determine whether the training data has been processed using PET as required.

[0063] Examples related to auditing privacy. This can be performed by a network function, which is described herein as a Privacy Audit Network Function (PANF). In some examples, the PANF is a core network function.

[0064] The PANF can be used to detect the presence of DP mechanisms when training data sets at AI / ML network functions (NFs) / application functions (AFs) (e.g., Network Data Analytics Function (NWDAF)). In the methods described herein, the PANF does not need to have access to the weights of the trained network, so the AI / ML NF / AF can be considered a black box. This is useful when the trained NN is private, such that it may be infeasible for some parties to obtain access to the trained NN (e.g., the trained NN may be a trade secret).

[0065] The method requires the following data sets to be provided by the owner:

[0066] 1) A set of unprocessed (raw) training data sets, which are given to the AI / ML trainer NF.

[0067] 2) A set of unprocessed (raw) test data sets, which have not been given to the AI / ML trainer.

[0068] An example algorithm that can be performed at the PANF is shown in Figure 2 The operations performed by the PANF 202 can be used to determine whether DP has been used on the data used to train the AI model (e.g., neural network (NN)) at the NF / AF 200 (e.g., NWDAF).

[0069] At 204, the PANF 202 stores the raw training data and the raw test data in the raw data set X = [x s : x r , where xs Includes training data, and x r Includes test data. The original training data set includes the data given to the AI / ML trainer NF200. The original test data includes the data that has not been given to the AI / ML trainer. The original training data and the original test data can be collected from a group of UEs to determine the AI / ML model for making predictions for that group of UEs. The PANF 202 may also have access to the labels Y = [y s ; y r for the original data set. These labels Y can be regarded as the ground truth labels.

[0070] At 206, the original data set X = [x s : x r T is randomly shuffled. The data from different UEs is randomly shuffled. The shuffling includes randomly swapping the columns of the matrix X. The (multiple) shuffling keys can be stored locally at 202. For example, the shuffled original data can include X p = XP, where P is the shuffling matrix.

[0071] At 208, the PANF 202 sends X p to the network function 200, where the trained AI model / NN is stored. At 208, the PANF 202 requests a prediction from the trained AI model to predict the label Y p ’ = F(X p ). Since the data has been shuffled, it is difficult for the network function 200 to determine which UE is being tested / audited. This can prevent the data from being tampered with by the network function 200.

[0072] At 210, the PANF 202 uses the (multiple) shuffling keys stored at the PANF 202 to unshuffle the output Y p ’ and reorders the output in the same order as X. This can be performed using the following operation: [All_UE_Training; All_UE_Test] data: Y’ = Y p ’P -1 = [y’ s : y’ r T .

[0073] At 210, the PANF 202 can calculate the loss function of the predicted Y’ and the corresponding ground truth label Y to determine the value of the loss function for the training data L 1 and the value of the loss function for the test data L 2 . This can be performed using the following operation.

[0074] ​​a. Loss_All_UE_Training: L 1 = L(y’ s , y s )

[0075] b. Loss_All_UE_Test L 2 = L(y’ r , y r )

[0076] At 212, PANF 202 determines whether L 1 - L 2 > T dp , where T dp is a threshold used to determine whether DP has been used to train the AI model at NF / AF 200. If L_1 – L_2 > T dp : No DP has been used. Otherwise: DP has been used.

[0077] Threshold T dp can be empirically implemented by PANF 202 by trying different numbers of data sets, NN outputs, and by varying the privacy levels (∈, δ). Threshold T dp can be determined experimentally.

[0078] An example algorithm that can be executed at PANF is shown in Figure 3 . Figure 3 The method of Figure 2 is similar to the method of

[0079] except that the loss value is determined at NF / AF 300 (e.g., NWDAF). The operations performed by PANF 302 can be used to determine whether DP has been used on the data used to train the AI model (e.g., neural network (NN)) at NF / AF 300 (e.g., NWDAF). s : x r T where x s includes training data, and x r includes test data. The original training data set includes the data given to the AI / ML trainer NF300. The original test data includes the data not yet given to the AI / ML trainer. The original training data and the original test data can be collected from a group of UEs to determine an AI / ML model for making predictions for that group of UEs. PANF 302 can also access the labels Y = [y s ; y r T ​​These tags Y can be regarded as ground truth tags.

[0080] At 306, the original dataset X = [x s : x r T is randomly shuffled. Data from different UEs is randomly shuffled. The shuffling includes randomly swapping the columns of the matrix X. The (multiple) shuffling keys can be locally stored at 302. For example, the shuffled original data may include X p = XP, where P is the shuffling matrix.

[0081] At 306, the tags Y are also shuffled using the same (multiple) shuffling key (P). The shuffling includes randomly swapping the columns of the matrix Y. For example, the shuffled original data may include Y p = YP, where P is the shuffling matrix.

[0082] At 308, the PANF 302 sends X p and Y p to the network function 300, where the trained AI model / NN is stored. At 308, the PANF 302 requests that the value for the loss function be provided from the trained AI model to predict L p = L(Y′ p , Y p ). Since the data has been shuffled, it is difficult for the network function 300 to determine which UE is being tested / audited. This can prevent the data from being tampered with by the network function 300.

[0083] At 310, the PANF 302 uses the (multiple) shuffling key stored in the PANF 302 to unshuffle the output L p and reorders the output in the same order as X. This can be performed using the following operation: unshuffle the output according to the shuffling key and also reorder it: [All_UE_Training; All_UE_Test] data: L = L p P -1 = [L 1 : L 2 T

[0084] At 314, the PANF 302 determines whether L 1 - L 2 > T dp , where T dp is the threshold for determining whether DP has been used to train the AI model at the NF / AF 300. If L_1 – L_2 > T dp : No DP has been used. Otherwise: DP has been used. ​​

[0085] Threshold T dp can be empirically implemented by the PANF 302 by trying different numbers of data sets, NN outputs, and by varying the privacy levels (∈, δ). Threshold T dp can be determined experimentally.

[0086] An explanation is given below for using the difference between the loss values for the original training data and for the original test data as an indicator that DP has been used for the AI model.

[0087] Assume there is a deterministic discrete-valued scoring function l that depends on the model parameters and a single data element x. Assume the model parameters are the output of an algorithm M(D) trained on a data set D. Let D + denote the data set that includes x, and let D - denote the data set where x is replaced by another data element.

[0088] By the post-processing property of DP, we have

[0089] Pr(l(M(D + ), x) = k) ≤ e ∈ Pr(l(M(D _ ), x) = k) + δ

[0090] where (∈, δ) gives the DP guarantee for M, and "Pr" is the probability.

[0091] Let D denote the actual training data set, and let A train and A test correspondingly denote the audit training and test sets. That is, A train is part of D, while A test is not. Both support m data elements. The above DP property indicates that the distributions

[0092] X = l(M(D), x) x ~ A train ,

[0093] and

[0094] Y = l(M(D), x) x ~ A test

[0095] should be (∈, δ)-close to each other. Additionally, the means

[0096]

[0097] and

[0098]

[0099] And approximately follows a normal distribution that obeys the law of large numbers. We know that the (∈,δ)-distance between two Gaussian distributions with equal variances depends only on their distance divided by the standard deviation. Therefore, we use the quantity as a heuristic indicator

[0100]

[0101] This value should actually be directly related to the lower bound of the (∈,δ)-guarantee of mechanism M. The larger the indicator value, the weaker the privacy guarantee of M.

[0102] The simulation results are as Figure 4 shown.

[0103] Consider a classification problem where the last layer (fully connected layer) of a Resnet-18 network is trained (He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image identification. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (pp. 770-778).). The network has been pre-trained using a subset of Imagenet (Deng, J., Dong, W., Socher, R., Li, L. J., Li, K., & Fei-Fei, L. (June 2009). Imagenet: A large-scale hierarchical image database. 2009 IEEE Conference on Computer Vision and Pattern Recognition (pp. 248-255). IEEE). The weights are obtained from the Torchvision library. Consider using the training split (50,000 samples) of the CIFAR-10 image dataset.

[0104] This layer is trained using DP-Stochastic Gradient Descent (DP-SGD) with a batch size of 1000 and different noise levels σ, such that different privacy levels ε are provided.

[0105] 1000 samples are randomly drawn from the training data as the "audit training set", and only 1000 samples are drawn as the "audit test set". The "audit training set" is part of the training data for the model, excluding the "audit test set". We measure the average loss of these two audit sets along the training iterations and calculate the above indicator.

[0106] Using three different values of the noise scale σ, the following can be observed. Three different noise scales σ result in three different formal ε-guarantees after 100 training runs (for δ = 10 -5) Here, ε = 1.0 represents a strong privacy protection level, while ε = 5.0 represents an intermediate privacy protection level. By observing the value of the indicator, it can be inferred whether DP exists. We set the threshold based on running experiments using similar datasets. For example, in the case where the aggregator has promised an intermediate DP guarantee, we can set 0.5 as the threshold.

[0107] Figure 5 An example method flow is shown. The method can be executed by, for example, a network function (such as PANF 202, 302). The method can be executed by a core network function.

[0108] At 500, the method includes storing a dataset including first data and second data for at least one user equipment, where the first data has been provided to the network function, while the second data has not been provided to the network function, and where the network function trains a machine learning model based on the first data.

[0109] At 502, the method includes storing ground truth labels for the first data and the second data.

[0110] At 504, the method includes sending information based on the dataset to the network function.

[0111] At 506, the method includes receiving, from the network function, information for determining a first value of a loss function, where the first value of the loss function indicates the difference between the ground truth label of the first data and at least one predicted ground truth label of the first data determined by the network function using the machine learning model.

[0112] At 508, the method includes receiving, from the network function, information for determining a second value of the loss function, where the second value of the loss function indicates the difference between the ground truth label of the second data and at least one predicted ground truth label of the second data determined by the network function using the machine learning model.

[0113] At 510, the method includes determining the difference between the first value of the loss function and the second value of the loss function.

[0114] At 512, the method includes comparing the difference with a threshold to determine whether the differential privacy mechanism is applied to the first data before the network function trains the machine learning model based on the first data.

[0115] Figure 6 Shows Figures 1 to 5An example of an apparatus 600 for one or more network functions as shown. The apparatus 600 may include at least one random access memory (RAM) 611a, at least one read-only memory (ROM) 611b, at least one processor 612, 613, and a network interface 614. The at least one processor 612, 613 may be coupled to the RAM 611a and the ROM 611b. The at least one processor 612, 613 may be configured to execute appropriate software code 615. Execution of the software code 615 may, for example, cause the apparatus to perform operations for one or more network functions. The software code 615 may be stored in the ROM 611b. The apparatus 600 may be interconnected with another apparatus 600 to control other network functions of the 5GC. In some embodiments, one or more network functions of the 5GC are deployed or hosted on the apparatus 600. In alternative embodiments, two or more functions of the 5GC may share one apparatus 600.

[0116] Figure 7 An example of a communication device 700 is shown, such as Figure 1 the terminal as shown. The communication device 700 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of the communication device 900 include a user equipment, a mobile station (MS) or a mobile device, such as a mobile phone or a so-called "smartphone", a computer provided with a wireless interface card or other wireless interface facilities (e.g., a USB dongle), a personal data assistant (PDA) or a tablet computer provided with wireless communication capabilities, a machine type communication (MTC) device, an Internet of Things (IoT) type communication device, or any combination of such devices, etc. The communication device 900 may include a transceiver for sending and / or receiving, for example, wireless signals (e.g., radio signals) carrying communications. The communication may be one or more of voice, email, text messages, multimedia data, machine data, etc.

[0117] The communication device 700 may receive wireless signals (e.g., radio signals) via an appropriate device for reception over the air or a radio interface 707, and may send radio signals via an appropriate device for sending radio signals. In Figure 7 it, the transceiver is schematically designated by block 706. The transceiver 706 may include, for example, a radio part and an associated antenna arrangement. The antenna arrangement may be arranged inside or outside the mobile device, and may include one or more antenna elements. The antenna arrangement may be a multiple-input multiple-output (MIMO) antenna.

[0118] The communication device 700 may be provided with at least one processor 701, at least one memory ROM 702a, at least one RAM 702b, and other possible components 703 for software and hardware assistance in performing the tasks it is designed to perform, including accessing and communicating with an access network (e.g., Figure 1 the 5G-RAN or NG-RAN shown in

[0119] and other communication devices). The at least one processor 701 is coupled to the RAM 702b and the ROM 702a. The at least one processor 701 may be configured to execute appropriate software code 708. The software code 708 may, for example, allow the performance of one or more operations of the communication device. The software code 708 may be stored in the ROM 702a.

[0120] Figure 8 A schematic representation of non-volatile storage media 800a (e.g., a computer optical disc (CD) or a digital versatile disc (DVD)) and 800b (e.g., a universal serial bus (USB) memory stick) is shown, storing instructions and / or parameters 802, which, when executed by a processor, allow the processor to perform one or more steps of any method flow described herein.

[0121] It should be understood that the references to various network functions above (e.g., to the AMF, SMF, TNF, etc.) may include means for performing at least some of the functions associated with those network functions. In addition, the means including the network functions may include virtual network function instances of the network functions.

[0122] It should be understood that these means may include or be coupled to other units or modules, etc. used for or for transmitting and / or receiving, such as radio components or radio heads. Although these means have been described as one entity, different modules and memories may be implemented in one or more physical or logical entities.

[0123] It should be noted that although some embodiments have been described in relation to 5G networks, similar principles can be applied to other networks and communication systems. Thus, although certain embodiments have been described above by way of example with reference to certain exemplary architectures for wireless networks, technologies, and standards, the embodiments can be applied to any other suitable form of communication system other than the communication systems shown and described herein.

[0124] It should also be noted herein that although exemplary embodiments have been described above, various variations and modifications can be made to the disclosed solutions without departing from the scope of the invention.

[0125] As used herein, “at least one of the following elements: <list of two or more elements>” and “at least one of <list of two or more elements>” and similar phrasings, where the list of two or more elements is joined by “and” or “or”, means at least any one of the elements, or at least two or more of the elements, or at least all of the elements.

[0126] In general, the various embodiments can be implemented in hardware or in dedicated circuits, software, logic, or any combination thereof. Certain aspects of the present disclosure can be implemented in hardware, while other aspects can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, but the present disclosure is not limited thereto. Although the various aspects of the present disclosure can be illustrated and described in terms of block diagrams, flowcharts, or other graphical representations, it will be fully understood that, by way of non-limiting example, the blocks, devices, systems, technologies, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general purpose hardware or controllers, or other computing devices, or some combination thereof.

[0127] As used herein, the term “circuitry” can refer to one or more or all of the following: (a) only hardware circuit implementations (such as, implemented only in analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as, as applicable:

[0128] (i) combinations of (one or more) analog and / or digital hardware circuits with software / firmware and

[0129] (ii) any portion of (one or more) hardware processors having software (including (one or more) digital signal processors), the software, and (one or more) memories (which work together to cause a device, such as a mobile phone or server, to perform various functions) and (c) (one or more) hardware circuits and / or (one or more) processors, such as (one or more) microprocessors or a portion of (one or more) microprocessors, that require software (e.g., firmware) to operate, but where the software may not be present when operation does not require it.

[0130] This definition of circuitry applies to all uses of the term "component" in this document, including any claims. As a further example, as used herein, the term circuitry also encompasses implementations of only hardware circuits or processors (or multiple processors) or portions of hardware circuits or processors and their (or their) attendant software and / or firmware. The term circuitry also encompasses, for example, baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or network devices if applicable to a particular claim element.

[0131] Embodiments of the present disclosure may be implemented by computer software executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. Computer software, or a program (also referred to as a program product), includes software routines, applets, and / or macros and may be stored in any device-readable data storage medium, and they include program instructions for performing particular tasks. A computer program product may include one or more computer-executable components that are configured to perform embodiments when the program is run. The one or more computer-executable components may be at least one software code or portions thereof.

[0132] Furthermore, in this regard, it should be noted that any block of the logical flow in the figures may represent a program step, or interconnected logical circuits, blocks, and functions, or a combination of program steps and logical circuits, blocks, and functions. Software may be stored in physical media such as memory chips or memory blocks implemented within a processor, magnetic media (which is associated with hard disks or floppy disks), and optical media (such as, for example, DVDs and their data variants CD). The physical media is a non-transitory medium.

[0133] The term "non-transitory" as used herein is a limitation of the medium itself (i.e., tangible, rather than a signal), rather than a limitation of data storage persistence (e.g., RAM versus ROM).

[0134] The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor may be of any type suitable for the local technical environment and, as a non-limiting example, may include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), gate-level circuits, and processors based on multi-core processor architectures.

[0135] Various example embodiments of the present disclosure may be practiced in various components, such as integrated circuit modules. The design of an integrated circuit is generally a highly automated process. Sophisticated and powerful software tools can be used to transform a logic-level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0136] The scope of protection sought for the various example embodiments of the present disclosure is defined by the independent claims. Example embodiments and features thereof (if any) described in the present disclosure that do not fall within the scope of the independent claims should be construed as examples that help in understanding the various example embodiments of the present disclosure.

[0137] The foregoing description has provided a complete and informative description of the various example embodiments of the present disclosure by way of non-limiting and illustrative examples. However, various modifications and adaptations may become apparent to those skilled in the relevant art when read in conjunction with the accompanying drawings and the claims. However, all such modifications of such and similar teachings will still fall within the scope of the various example embodiments of the present disclosure as set forth in the claims. By way of non-limiting and illustrative examples, there are additional example embodiments, including combinations of one or more example embodiments with any other example embodiments previously discussed.

Claims

1. An apparatus for privacy auditing, comprising at least one processor and at least one memory, wherein the at least one memory stores instructions, and when the instructions are executed by the at least one processor, the apparatus at least performs: storing (500) a data set for at least one user device, comprising first data and second data, wherein during training of a machine learning model, the first data has been provided to a network function and the second data has not yet been provided to the network function, and wherein the network function trains the machine learning model based on the first data; storing (502) ground truth labels for the first data and the second data; sending (504) a representation of the data set to the network function; receiving (506) information from the network function for determining a first value of a loss function, the first value of the loss function indicating: a difference between the ground truth label for the first data and at least one predicted ground truth label for the first data determined by the network function using the machine learning model; receiving (508) information from the network function for determining a second value of the loss function, the second value of the loss function indicating: a difference between the ground truth label for the second data and at least one predicted ground truth label for the second data determined by the network function using the machine learning model; determining (510) a difference between the first value of the loss function and the second value of the loss function; The difference is compared to a threshold (512) to determine whether a differential privacy mechanism is applied to the first data before the network function trains the machine learning model based on the first data.

2. The apparatus of claim 1 , wherein the information used to determine the first value of the loss function comprises: a predicted tag for the first data, and a predicted tag for the second data, and wherein the at least one processor and the at least one memory store instructions that, when executed by the at least one processor, cause the apparatus to at least further perform: determining the first value of the loss function based on the predicted label for the first data and the ground truth label for the first data; The first value of the loss function is determined based on the predicted label for the second data and the ground truth label for the second data.

3. The apparatus of claim 1 , wherein the at least one processor and the at least one memory store instructions that, when executed by the at least one processor, cause the apparatus to at least further perform: sending the predicted label for the first data to the network function, wherein the information used to determine the first value of the loss function includes: the predicted label for the first data, and the first value of the loss function; The predicted label for the second data is sent to the network function, wherein the information used to determine the second value of the loss function includes: the predicted label for the first data, and the second value of the loss function.

4. The apparatus of claim 1 , wherein the data set is stored in a first matrix, and wherein the at least one processor and the at least one memory store instructions that, when executed by the at least one processor, cause the apparatus to further perform at least: swapping columns of the first matrix using a second matrix to provide a third matrix; storing the second matrix; Wherein the representation of the data set comprises the third matrix.

5. The apparatus of claim 4, wherein the information for determining the second value of the loss function apparatus comprises a fourth matrix, and wherein the at least one processor and the at least one memory store instructions that, when executed by the at least one processor, cause the apparatus to further at least: The columns of the fourth matrix are swapped using the third matrix to correspond to the order of the columns of the first matrix.

6. An apparatus according to any preceding claim, wherein the at least one processor and the at least one memory store instructions which, when executed by the at least one processor, cause the apparatus to at least further perform: When it is determined that the differential privacy mechanism is not applied to the first data, an instruction is sent to the network function to increase the privacy level of the differential privacy mechanism for the first data.

7. The apparatus according to any one of claims 1 to 5, wherein the first data set and / or the second data set comprises at least one of the following: temperature measurements from at least one user device during a first time period; Position data for at least one user device during a second time period.

8. An apparatus according to any one of claims 1 to 5, wherein the apparatus comprises a 5G core network function.

9. The apparatus according to any one of claims 1 to 5, wherein the network functions include a network data and analysis function (NWDAF).

10. A method for privacy auditing, comprising: storing (500) a data set for at least one user device, comprising first data and second data, wherein during training of a machine learning model, the first data has been provided to a network function and the second data has not yet been provided to the network function, and wherein the network function trains the machine learning model based on the first data; storing (502) ground truth labels for the first data and the second data; sending (504) a representation of the data set to the network function; receiving (506) information from the network function for determining a first value of a loss function, the first value of the loss function indicating: a difference between the ground truth label for the first data and at least one predicted ground truth label for the first data determined by the network function using the machine learning model; receiving (508) information from the network function for determining a second value of the loss function, the second value of the loss function indicating: a difference between the ground truth label for the second data and at least one predicted ground truth label for the second data determined by the network function using the machine learning model; determining (510) a difference between the first value of the loss function and the second value of the loss function; The difference is compared to a threshold (512) to determine whether a differential privacy mechanism is applied to the first data before the network function trains the machine learning model based on the first data.

11. The method of claim 10, wherein the information used to determine the first value of the loss function comprises: a predicted label for the first data, and a predicted label for the second data, and wherein the method comprises: determining the first value of the loss function based on the predicted label for the first data and the ground truth label for the first data; The first value of the loss function is determined based on the predicted label for the second data and the ground truth label for the second data.

12. The method according to claim 10, wherein the method comprises: sending the predicted label for the first data to the network function, wherein the information used to determine the first value of the loss function includes: the predicted label for the first data, and the first value of the loss function; The predicted label for the second data is sent to the network function, wherein the information used to determine the second value of the loss function includes: the predicted label for the first data, and the second value of the loss function.

13. A method according to any one of claims 10 to 12, wherein the data set is stored in a first matrix, and wherein the method comprises: swapping columns of the first matrix using a second matrix to provide a third matrix; storing the second matrix; Wherein the representation of the data set comprises the third matrix.

14. The method of claim 13, wherein the information used to determine the second value of the loss function comprises a fourth matrix, and wherein the method comprises: The columns of the fourth matrix are swapped using the third matrix to correspond to the order of the columns of the first matrix.

15. A computer program for privacy auditing, comprising instructions stored thereon, the instructions for performing at least the following: storing (500) a data set for at least one user device, comprising first data and second data, wherein the first data has been provided to a network function and the second data has not yet been provided to the network function, and wherein the network function trains a machine learning model based on the first data; storing (502) ground truth labels for the first data and the second data; sending (504) a representation of the data set to the network function; receiving (506) information from the network function for determining a first value of a loss function, the first value of the loss function indicating: a difference between the ground truth label for the first data and at least one predicted ground truth label for the first data determined by the network function using the machine learning model; receiving (508) information from the network function for determining a second value of the loss function, the second value of the loss function indicating: a difference between the ground truth label for the second data and at least one predicted ground truth label for the second data determined by the network function using the machine learning model; determining (510) a difference between the first value of the loss function and the second value of the loss function; The difference is compared to a threshold (512) to determine whether a differential privacy mechanism is applied to the first data before the network function trains the machine learning model based on the first data.