Communication method, device and system
By introducing a model that detects adversarial samples into the communication network, the problem of performance degradation of AI model due to input adversarial samples in the inference stage is solved, and the identification and prevention of adversarial samples are realized, ensuring network performance.
Patent Information
- Application Number
- CN202311604240.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the inference stage of the AI model, if adversarial samples are input, it may lead to a decline in the performance of the AI model, which will affect the network performance.
By introducing a model that detects adversarial samples in the communication network, the first network element acquires adversarial samples and trains the detection model, sends the model to the second network element for identifying adversarial samples at the inference stage.
Effectively identify and prevent adversarial samples from affecting the inference performance of the AI model, thereby ensuring network performance.
Smart Images

Figure CN120050198A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to communication methods, devices, and systems. Background Art
[0002] With the development of communication technologies, it is considered to introduce artificial intelligence (AI) into wireless communication systems to improve network performance. Among them, the AI model is the core in AI application scenarios.
[0003] Currently, after the AI model is trained, it can be sent to the corresponding node for inference. In the inference stage, the corresponding result output by the AI model based on the input data (which can also be called input samples) can be used to adjust the network policy. However, in the inference stage, the AI model may be input with adversarial samples. Adversarial samples refer to samples that change features to avoid model detection. If the AI model is input with adversarial samples, it may not be able to output the correct result, resulting in a decline in the inference performance of the AI model. Summary of the Invention
[0004] Embodiments of this application provide communication methods, devices, and systems that can identify adversarial samples input to the AI model in the inference stage to avoid a decline in the performance of the AI model.
[0005] In a first aspect, a communication method is provided. This method can be executed by a first network element, or by a component of the first network element (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can implement all or part of the functions of the first network element. Hereinafter, taking the first network element as the execution subject of this method as an example for description, this method includes: The first network element obtains adversarial samples and trains a first model according to the adversarial samples. Then, the first network element sends the first model to a second network element. The first model is used to detect whether the inference data of the AI model is an adversarial sample.
[0006] Based on the communication method provided by the embodiments of this application, a model for detecting adversarial samples can be introduced into the AI application scenario of the communication network, and it can be identified whether the inference data is an adversarial sample in the inference stage of the AI model, thereby avoiding a reduction in the performance of the AI model and ensuring network performance.
[0007] In a possible design, this method further includes: The first network element obtains training data and generates adversarial samples according to the training data.
[0008] Based on this solution, the first network element can train the first model based on the adversarial samples generated by itself, which can ensure network security.
[0009] In a possible design, the first network element trains the first model based on adversarial samples, including: the first network element generates explainable artificial intelligence (XAI) feature samples according to the adversarial samples, and trains the first model according to the XAI feature samples. Among them, the XAI feature samples include values representing the feature importance of the adversarial samples; or, the XAI feature samples include values representing the unit importance of the AI model.
[0010] In a possible design, the method further includes: the first network element sends the second model to the second network element. Among them, the XAI feature samples are generated by the second model, and the second model is used to explain the AI model.
[0011] Based on this solution, the second model can be used to generate XAI feature samples and explain the AI model, which can help people understand the output of the AI model and whether the output of the AI model is reliable.
[0012] In a possible design, the method further includes: the first network element sends the AI model to the second network element. Among them, the AI model is associated with the first model.
[0013] Based on this solution, after receiving the AI model, the second network element can know, according to the association relationship with the first model, that the first model is used to detect the inference data of the AI model.
[0014] In a possible design, the method further includes: the first network element receives the adversarial samples detected by the second network element.
[0015] In a possible design, the method further includes: the first network element receives the identification information of the AI model from the second network element. Among them, the AI model is associated with the first model.
[0016] Based on this solution, the first network element can determine, according to the identification information of the AI model, that the received adversarial samples are detected by the first model associated with the AI model.
[0017] In a possible design, the method further includes: the first network element retrains the first model according to the adversarial samples detected by the second network element.
[0018] Based on this solution, the first network element can retrain the first model according to the detected adversarial samples to improve the performance of the first model.
[0019] In a possible design, the method further includes: the first network element sends the first parameter to the second network element, and the first parameter is used to indicate the threshold of the first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
[0020] Based on this solution, the number of adversarial samples detected can be counted by the first counter, which is convenient for counting adversarial samples.
[0021] In a possible design, the method further includes: the first network element receives information of a terminal device from the second network element. The first network element de-registers the terminal device according to the information of the terminal device.
[0022] Based on this solution, the first network element can de-register the terminal device that sends adversarial samples to the second network element, preventing the terminal device from continuing to send adversarial samples to the second network element.
[0023] In a second aspect, a communication method is provided. This method can be executed by the second network element, or by components of the second network element (such as a processor, a chip, or a chip system, etc.), or can also be implemented by a logic module or software that can implement all or part of the functions of the second network element. Hereinafter, taking the second network element as the execution entity of this method as an example for description, the method includes: the second network element obtains a first model and inference data. Then, the second network element detects whether the inference data input to the AI model is an adversarial sample according to the first model.
[0024] Based on the communication method provided in the embodiments of this application, a model for detecting adversarial samples can be introduced in the AI application scenario of a communication network, and it can be determined whether the inference data is an adversarial sample during the inference stage of the AI model, thereby avoiding a reduction in the performance of the AI model and ensuring network performance.
[0025] In a possible design, when the second network element detects whether the inference data input to the AI model is an adversarial sample according to the first model, it includes: the second network element inputs the output result of the AI model into the first model, and detects whether the inference data is an adversarial sample according to the output result of the first model.
[0026] In a possible design, when the second network element detects whether the inference data input to the AI model is an adversarial sample according to the first model, it includes: the second network element obtains an XAI feature sample according to the output result of the AI model. The second network element then inputs the XAI feature sample into the first model, and detects whether the inference data is an adversarial sample according to the output result of the first model. Among them, the XAI feature sample includes a value representing the feature importance of the inference data; or, the XAI feature sample includes a value representing the unit importance of the AI model.
[0027] Based on this solution, multiple ways to detect whether the inference data of the AI model is an adversarial sample according to the first model are provided, and a suitable way can be selected according to actual requirements.
[0028] In a possible design, the method further includes: a second network element obtains a second model, where the second model is used to generate XAI feature samples.
[0029] Based on this solution, the second model can be used to generate XAI feature samples and interpret the AI model, which can help personnel understand the output of the AI model and whether the output of the AI model is reliable.
[0030] In a possible design, the method further includes: if a first condition is satisfied, the second network element performs at least one of the following: releases the connection with the terminal device, sends the detected adversarial sample to the first network element, or sends the information of the terminal device to the third network element.
[0031] Based on this solution, the second network element can perform subsequent actions to protect network security when a certain condition is satisfied.
[0032] In a possible design, the first condition is: the inference data detected from the terminal device is an adversarial sample; or, the first condition is: the first counter corresponding to the terminal device reaches a threshold; where each time the inference data detected from the terminal device is an adversarial sample, the current value of the first counter is incremented by one.
[0033] Based on this solution, when the second network element detects that the inference data from the terminal device is an adversarial sample or detects that the inference data from the terminal device reaches a certain number of times, it can perform at least one of releasing the connection with the terminal device, sending the detected adversarial sample to the first network element, or sending the information of the terminal device to the third network element, thereby avoiding the terminal device from continuing to send adversarial samples and protecting network security.
[0034] In a possible design, the threshold is preset. Or, the threshold is configured by the first network element.
[0035] In a possible design, the method further includes: the second network element obtains an AI model. Wherein, the AI model is associated with the first model.
[0036] Based on this solution, after the second network element obtains the AI model, it can know that the first model is used to detect the inference data of the AI model according to the association relationship with the first model.
[0037] In a third aspect, a communication device is provided for implementing the above various methods. The communication device includes corresponding modules, units, or means for implementing the above methods, and the modules, units, or means can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0038] In some possible designs, the communication device may include a transceiver module and a processing module. The transceiver module, which may also be referred to as a transceiver unit, is used to implement the sending and / or receiving functions in the first aspect or the second aspect and any possible implementation manners thereof. The transceiver module may be composed of a transceiver circuit, a transceiver, a transceiver, or a communication interface. The processing module may be used to implement the processing function in the first aspect or the second aspect and any possible implementation manners thereof.
[0039] In some possible designs, the transceiver module includes a sending module and a receiving module, which are respectively used to implement the sending and receiving functions in the first aspect or the second aspect and any possible implementation manners thereof.
[0040] In a fourth aspect, a communication device is provided, including: a processor and a communication interface; the communication interface is used to communicate with a module outside the communication device; the processor is used to execute a computer program or instruction so that the communication device executes the method in any of the above aspects.
[0041] In a fifth aspect, a communication device is provided, including: at least one processor; the processor is used to execute a computer program or instruction stored in a memory so that the communication device executes the method in any of the above aspects. In a possible implementation, the memory may be coupled to the processor, or may be independent of the processor. In a possible implementation, the communication device further includes the memory. Optionally, the memory and the processor are integrated together.
[0042] In the third aspect to the fifth aspect, the communication device may be the first network element in the first aspect or any implementation manner in the first aspect, or a device including the first network element, or a device included in the first network element, such as a chip or a chip system. Or, the communication device may be the second network element in the second aspect or any implementation manner in the second aspect, or a device including the second network element, or a device included in the second network element, such as a chip or a chip system.
[0043] In a sixth aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When it runs on a communication device, the communication device can execute the method in any of the above aspects or any of its implementation manners.
[0044] In a seventh aspect, a computer program product including instructions is provided. When it runs on a communication device, the communication device can execute the method in any of the above aspects or any of its implementation manners.
[0045] In an eighth aspect, a communication device (for example, the communication device may be a chip or a chip system) is provided. The communication device includes a processor configured to implement the functions involved in any of the above aspects or any of its implementation manners.
[0046] In some possible designs, the communication device includes a memory configured to store necessary program instructions and data.
[0047] In some possible designs, when the device is a chip system, it may be composed of chips or may also include chips and other discrete devices.
[0048] It can be understood that when the communication device provided in any of the third aspect to the fifth aspect is a chip, the above-mentioned sending action / function can be understood as output, and the above-mentioned receiving action / function can be understood as input.
[0049] Among them, for the technical effects brought by any implementation manner in the third aspect to the eighth aspect, reference can be made to the technical effects brought by the corresponding implementation manners in the first aspect to the fourth aspect, which will not be elaborated here.
[0050] It should be noted that, on the premise that the solutions do not conflict, all possible implementation manners of any one of the above aspects can be combined.
[0051] In a ninth aspect, a communication system is provided. The communication system includes a first network element that executes the method of the first aspect and a second network element that executes the method of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 It is a schematic diagram of a framework for the application of AI in the NR system;
[0053] Figure 2 It is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
[0054] Figure 3 It is a schematic flowchart of a communication method provided by an embodiment of the present application Figure 1 ;
[0055] Figure 4 It is a schematic flowchart of a communication method provided by an embodiment of the present application Figure 2 ;
[0056] Figure 5 It is a schematic diagram of the composition of a communication device provided by an embodiment of the present application;
[0057] Figure 6 It is a schematic diagram of the hardware structure of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0058] To facilitate the understanding of the technical solutions of the embodiments of this application, a brief introduction to the related technologies of the embodiments of this application is given as follows first.
[0059] 1. AI in the communication system:
[0060] AI technology is a technology that performs complex calculations by simulating the human brain. With the development of communication technology and AI technology, the industry has proposed that AI can be applied in the communication system to improve network performance and user experience.
[0061] In the application scenario where AI is applied to the communication system, after the AI model is trained, it can be sent to the corresponding node for inference. In the inference stage, the AI model can output a network-related prediction result or network policy based on the input data (which can also be called an input sample). Currently, the 3rd Generation Partnership Project (3GPP) has designed several basic application scenarios for the application of AI on the radio access network (RAN) side, such as network energy saving, load balancing, and mobility optimization. Taking the network energy saving scenario as an example, the AI model can use the data collected in the network to predict the energy efficiency and load status of the network, thereby helping the system dynamically configure energy saving policies to maintain the balance between system performance and energy efficiency and reduce energy consumption.
[0062] Figure 1 FIG. is a schematic diagram of a possible framework for the application of AI in the new radio (NR) system. As Figure 1As shown in the figure, the data source module can collect and store data from different entities in the network (such as base stations and terminal devices), serving as a database for AI model training and data analysis and inference. The model training host module can analyze the training data provided by the data source module and train the AI model. The trained AI model can be deployed or updated to the model inference host module. The model inference host module can use the AI model provided by the model training host module and, based on the inference data provided by the data source module, output reasonable predictions for network operation or relevant adjusted policies. Optionally, after using the AI model, the model inference host can also feedback the performance of the AI model to the model training module. The actor module can uniformly plan relevant policy adjustments and send the adjusted network policies to multiple network entities for operation. At the same time, after applying the adjusted network policies, the data source module can collect and store data in the network again. The actor module can also collect the specific performance of the network after applying the adjusted network policies, such as the values of some relevant metrics, and feedback the specific performance of the network together with the adjusted network policies to the data source module.
[0063] Among them, Figure 1 The different modules shown in the figure can be deployed on different entities. Or, they can also be deployed on the same entity.
[0064] It can be understood that Figure 1 The modules shown in the figure and the interaction schematic between the modules are logical modules and logical interaction schematics given for the convenience of understanding the application of AI in the communication system, and do not mean that in actual applications, there must be Figure 1 interactions between the modules shown in the figure. For example, assume that in an actual application scenario, a certain module integrates Figure 1 the functions of the model inference host module and the actor module in the figure, then there is no Figure 1 step of transmitting the output result between the model inference host module and the actor module shown in the figure.
[0065] 2. Explainable Artificial Intelligence (XAI):
[0066] XAI is a method and technology for generating accurate and interpretable AI models, which can explain why and how AI algorithms make specific decisions so that the results of AI solutions can be understood by humans. There are two options for interpretable AI models. One is to select a model with a simple structure that is easy to interpret and then train it. The trained model itself has good interpretability and is easy for humans to understand its decisions. The other is to train a complex high-performance model and then develop interpretability techniques for explanation. Based on these two options, XAI methods can be divided into pre-explanation and post-explanation. Among them, pre-explanation focuses on designing interpretable AI models, and post-explanation focuses on using a simple model to fit the AI model to be explained, so as to evaluate the importance of the features of the input samples of the AI model to be explained.
[0067] The above introduced the application of AI models in communication systems. However, AI models may be attacked and their performance may be degraded. In the inference stage, an attacker can change the features of the input samples to avoid the detection of the model, and such samples are called adversarial samples. The AI model may output adversarial samples, resulting in incorrect output results and degraded performance. Moreover, in the application scenario where the AI model is applied to a communication network, if adversarial samples cannot be recognized and the output results of the AI model after using the input adversarial samples are used to adjust the network policy, the network performance may deteriorate. Based on this problem, this application provides a communication method, device and system, which can identify adversarial samples in the inference stage, thereby avoiding the attack of adversarial samples on the AI model.
[0068] The following introduces the specific implementation of the communication method provided in the embodiments of this application. In the description of the embodiments of this application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of this application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression means any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, to facilitate a clear description of the technical solutions in the embodiments of this application, in the embodiments of this application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.
[0069] In the embodiments of this application, "indication" can include direct indication and indirect indication, and can also include explicit indication and implicit indication. If the information indicated by a certain piece of information is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre - agreed. For example, it is also possible to achieve the indication of specific information by relying on the arrangement order of each piece of information pre - agreed (such as stipulated in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common part of each piece of information and indicate it uniformly to reduce the indication overhead caused by separately indicating the same information.
[0070] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. Moreover, the sending periods and / or sending timings of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. Among them, the sending periods and / or sending timings of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.
[0071] In the embodiments of the present application, "predefined", "predetermined", "preconfigured" or "pre-configured" can be implemented by pre-saving corresponding codes, tables or other means that can be used to indicate relevant information in the device. For example, it can be burned into the device when the device leaves the factory, or configured when first accessing the network. The embodiments of the present application do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially separately provided and partially integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, which is not limited in the embodiments of the present application.
[0072] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "when" all refer to that the device will perform corresponding processing under a certain objective situation, which does not limit the time, and does not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.
[0073] In the embodiments of the present application, "sending information to... (taking the second network element as an example)" can be understood as the destination of the information is the second network element. It can include directly or indirectly sending information to the second network element. "Receiving information from... (taking the first network element as an example)" can be understood as the source of the information is the first network element, and it can include directly or indirectly receiving information from the first network element. Necessary processing may be performed on the information between the source and the destination of the information sending, such as format change, etc., but the destination can understand the valid information from the source. Similar expressions in the embodiments of the present application can be understood similarly and will not be elaborated here.
[0074] The technical solution provided by this application can be used in various communication systems, such as Long Term Evolution (LTE) systems, 4th generation (4G) mobile communication systems, 5th generation (5G) mobile communication systems and their evolved systems, Non-Terrestrial Network (NTN) systems, Vehicle-to-Everything (V2X) systems, systems with hybrid networking of LTE and NR, or Device-to-Device (D2D) systems, Machine-to-Machine (M2M) communication systems, Internet of Things (IoT), and future next-generation communication systems, such as 6th generation (6G) mobile communication systems, etc. In addition, the term "system" can be interchanged with "network".
[0075] It should be noted that the network architecture and service scenarios described in the embodiments of this application are for more clearly explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those of ordinary skill in the art can know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of this application are equally applicable to similar technical problems.
[0076] It should be noted that the names of the network elements appearing in this article are only possible exemplary names. If the actual names of the network elements in subsequent communication networks (such as 6G networks) are different from the names appearing in this article, it will not affect the application of the communication method provided by the embodiments of this application.
[0077] Figure 2 It is a schematic diagram of the architecture of a possible and non-limiting communication system applicable to the embodiments of this application. As Figure 2 shown, the communication system 10 includes a Radio Access Network (RAN) 100 and a Core Network (CN) 200. The RAN 100 includes at least one RAN node (such as Figure 2 110a and 110b in Figure 2 , collectively referred to as 110) and at least one terminal device (such as Figure 2etc. (not shown in the figure). The terminal device 120 is connected to the RAN node 110 wirelessly. The RAN node 110 is connected to the core network 200 wirelessly or wiredly. The core network devices in the core network 200 and the RAN nodes 110 in the RAN 100 can be different physical devices respectively, or can be the same physical device integrating the core network logic function and the radio access network logic function.
[0078] Optionally, as Figure 2 shown, the communication system 10 may further include the Internet 300.
[0079] All or part of the functions of the network elements (such as RAN nodes 110, core network elements, etc.) in the embodiments of the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The network elements in the embodiments of the present application can also be logical nodes, logical modules or software that can implement all or part of the network element functions.
[0080] The RAN 100 can be a 3GPP-related cellular system. For example, 4G, 5G mobile communication systems, or future evolved systems (such as 6G mobile communication systems). The RAN 100 can also be an open radio access network (O-RAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The RAN 100 can also be a communication system integrating two or more of the above systems.
[0081] The RAN node 110, sometimes also called an access network device, a RAN entity or an access node, etc., constitutes a part of the communication system to help the terminal device achieve wireless access. Multiple RAN nodes 110 in the communication system 10 can be of the same type of nodes or different types of nodes. In some scenarios, the roles of the RAN node 110 and the terminal device 120 are relative. For example, Figure 2 in the network element 120i can be a helicopter or a drone, which can be configured as a mobile base station. For those terminal devices 120j accessing the RAN 100 through the network element 120i, the network element 120i is a base station; but for the base station 110a, the network element 120i is a terminal device. The RAN node 110 and the terminal device 120 are sometimes both called communication devices. For example, Figure 2 the network elements 110a and 110b in the figure can be understood as communication devices with base station functions, and the network elements 120a - 120j can be understood as communication devices with terminal functions.
[0082] In one possible scenario, a RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation nodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. A RAN node may be a macro base station (e.g. Figure 2 110a in), micro base stations or indoor stations (such as Figure 2 110b in the example above), a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, the RAN node may also be a server, a wearable device, a vehicle or an onboard device, etc. For example, the access network device in the V2X technology may be a road side unit (RSU).
[0083] All or part of the functions of the RAN node in the embodiment of the present application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (e.g., a cloud platform). The RAN node in the embodiment of the present application may also be a logical node, a logical module, or software that can implement all or part of the RAN node functions.
[0084] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU) or a remote radio head (RRH).
[0085] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU may also be referred to as O-CU (Open CU), the DU may also be referred to as O-DU, the CU-CP may also be referred to as O-CU-CP, the CU-UP may also be referred to as O-CU-UP, and the RU may also be referred to as O-RU. For the convenience of description, the embodiments of this application use CU, CU-CP, CU-UP, DU, and RU as examples for description. Any unit in the CU (or CU-CP, CU-UP), DU, and RU in the embodiments of this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0086] The terminal device may also be referred to as a terminal, user equipment (UE), mobile station, mobile terminal, etc. The terminal device can be widely applied to various scenarios, such as D2D, V2X communication, machine-type communication (MTC), Internet of Things, virtual reality (VR), augmented reality (AR), industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearables, smart transportation, or smart city, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a robotic arm, a smart home device, etc. The embodiments of this application do not limit the device form of the terminal device.
[0087] Optionally, the core network 200 may include an operation administration and maintenance (OAM) network element access and a mobility management function (AMF), or other network elements. Among them, the OAM network element is mainly responsible for analyzing, predicting, planning, and configuring the daily network and services, as well as performing daily operation activities such as testing and fault management of the network and services. The AMF network element is responsible for functions such as authentication, authorization, registration, mobility management, and connection management of the terminal device.
[0088] In the embodiments of the present application, the communication system 10 may include an AI module. Among them, the AI module is a module with machine learning computing capabilities. In a wireless communication system, the AI module may be located on the core network side, such as in an OAM network element, or on the RAN side, such as in a gNB or CU, or in a terminal device, or may be a separate network element entity. Exemplarily, if the AI module becomes a separate network element entity, this entity may be referred to as an artificial intelligence controller (artificial intelligence controller, AIC) (it may also have other names, which are not limited in the embodiments of the present application). Optionally, in a wireless communication system, the AI module may perform a series of AI calculations such as model establishment, training approximation, and reinforcement learning based on input data (optionally, network operation data provided by the RAN side or monitored by core network elements, such as network load, channel quality, etc.). The trained model provided by the AI module has the function of predicting network changes, such as load prediction, quality of service (QoS) prediction, etc. In addition, the AI module may also perform policy reasoning based on the prediction results of the network by the trained model to obtain reasonable network policies. For example, the AI module may perform policy reasoning from the perspectives of network energy saving or mobility optimization based on the prediction results output by the model to obtain energy saving policies or mobility optimization policies, etc.
[0089] In a possible scenario, the communication system 10 may include the architecture as Figure 1 shown. For example, the AI module may include Figure 1 the model training management module or the model inference management module in
[0090] In a possible scenario, when the AI module is located in a core network element (such as an OAM network element), its communication with the RAN node may reuse the current northbound interface. When the AI module is located in a RAN node (such as a gNB or CU), its communication with the RAN node, terminal device, or core network element may reuse the current F1, Xn, Uu, etc. interfaces. When the AI module is an independent network entity, communication links with core network elements, RAN nodes, or terminal devices, etc., such as wired links or wireless links, may be established.
[0091] Next, in combination with Figure 1 the architecture shown and Figure 2 the communication system shown, the communication method provided in the embodiments of the present application will be described.
[0092] It should be noted that in the following embodiments of the present application, the names of each network element, the names of the messages exchanged between each network element, the names of each parameter, or the names of each piece of information, etc. are only examples, and in other embodiments, they may also be other names, and the methods provided in the present application do not make specific limitations on this.
[0093] It can be understood that in the embodiments of the present application, each network element or entity may execute some or all of the steps in the embodiments of the present application. These steps or operations are only examples, and the embodiments of the present application may also execute other operations or various deformations of the operations. In addition, each step may be executed in a different order presented in the embodiments of the present application, and it is possible not to execute all the operations in the embodiments of the present application.
[0094] See Figure 3 , the communication method provided by the embodiments of the present application includes steps S301 - S303:
[0095] S301. The first network element obtains adversarial samples and trains a first model according to the adversarial samples. Wherein, the first model is used to detect whether the inference data of the AI model is an adversarial sample.
[0096] Regarding the acquisition of adversarial samples, the embodiments of the present application do not limit the specific implementation manner, and the following introduces possible implementations provided by the embodiments of the present application.
[0097] In one possible implementation, the first network element may generate adversarial samples according to the acquired training data. In one possible way of this implementation, the first network element may apply an attack algorithm (such as the fast gradient sign method, distributed adversarial attack, deep fool, Jacobian - based saliency map attack, etc.) to add perturbations to the normal training data, that is, modify the numerical values corresponding to one or more features of the training data, and input the training data after adding perturbations into the AI model. If the output result of the AI model does not match the expectation, it can be considered that the training data after adding perturbations is an adversarial sample. Further, the first network element may collect adversarial samples to form an adversarial sample set.
[0098] Among them, the output result of the AI model not matching the expectation may be that the sample label of the output result does not match the sample label of the normal training data. Or, it may be that the value of the output result is not within the expected range, etc. Based on different types of the output results of the AI model, there can be various different judgment methods on whether the output result of the AI model matches the expectation, and the embodiments of the present application do not limit this.
[0099] For example, assume that the output result of the AI model is the prediction of the base station load, and the normal output result should be less than a threshold. If the output result of the AI model is higher than the threshold after inputting the data, it can be considered that the input data is an adversarial sample.
[0100] If the sample label of the normal training data is QoS, and after inputting the training data after adding perturbations into the AI model, the sample label of the output result of the AI model is load, which is different from QoS, it can be considered that this training data after adding perturbations is an adversarial sample.
[0101] Optionally, in this implementation, the first network element may obtain training data from other network elements or terminal devices. The embodiments of the present application do not limit from which network element or network elements the first network element specifically obtains the training data. In a possible scenario, the first network element may obtain training data from the second network element. The second network element will be specifically introduced below and will not be elaborated here for the time being.
[0102] Optionally, in this implementation, the training data obtained by the first network element may be data or information related to the network. For example, a RAN node (such as a base station within the management scope of the first network element) may send RAN-side data or information for training to the first network element. The RAN-side data or information for training may be reported by the terminal device to the RAN node (for example, the terminal device reports the measurement result obtained based on the measurement configuration to the RAN node), local to the RAN node, or may also be derived by the RAN node based on data or information from the terminal device or other RAN nodes. For example, the RAN-side data or information for training may include the resource status of the RAN node, the power consumption status of the RAN node, the traffic information of the terminal device, the reference signal received power (RSRP), reference signal received quality (RSRQ), or signal interference noise ratio (SINR) of the serving cell and / or neighboring cells measured by the terminal device, etc. For another example, a core network element may send network-related data or information obtained by the core network element, such as the QoS information of the terminal device, to the first network element.
[0103] In another possible implementation, the first network element may obtain adversarial samples from other network elements or terminal devices. For example, the first network element may receive adversarial samples from a core network element. For another example, the first network element may receive adversarial samples from a third party.
[0104] In the embodiments of the present application, the adversarial samples may be used to train the first model. The trained first model may detect whether the inference data input to the AI model is an adversarial sample. That is, the output result of the first model may indicate whether the inference data input to the AI model is an adversarial sample.
[0105] For example, the output result of the first model may be 0 or 1. 0 represents that the inference data of the AI model is not an adversarial sample (it may also represent normal inference data), and 1 represents that the inference data of the AI model is an adversarial sample.
[0106] Regarding the training of the first model based on adversarial samples, the embodiments of this application do not limit the specific implementation. The following introduces the possible implementations provided by the embodiments of this application.
[0107] In one possible implementation, the first network element can input the adversarial sample into the AI model and train the first model according to the output result of the AI model. For example, if the adversarial sample is input into the AI model, the first network element can input the output result of the AI model into the first model to obtain the output result of the first model. If the output result of the first model indicates an adversarial sample, it means that the first model detects correctly.
[0108] Optionally, the first network element can perform supervised training on the first model by combining normal training data and adversarial samples.
[0109] Exemplarily, the first network element can set sample labels for the normal training data and the adversarial samples respectively. The sample label can indicate whether the data is normal training data or an adversarial sample. For example, the value of the sample label being 0 indicates normal training data, and the value being 1 indicates an adversarial sample. The first network element inputs the normal training data or the adversarial sample into the AI model to obtain the output result of the AI model, and then inputs the output result of the AI model into the first model. After obtaining the output result of the first model, it can compare the output result of the first model with the sample label of the data input into the AI model to determine whether the first model detects correctly. For example, if the output result of the first model indicates an adversarial sample and the sample label of the data input into the AI model also indicates an adversarial sample, then the first model detects correctly. If the output result of the first model indicates normal training data and the sample label of the data input into the AI model also indicates normal training data, then the first model detects correctly.
[0110] In another possible implementation, the first network element can generate XAI feature samples based on the adversarial samples and train the first model according to the XAI feature samples. For example, if the adversarial sample is input into the AI model, the first network element can generate XAI feature samples according to the output result of the AI model and input the XAI feature samples into the first model to obtain the output result of the first model. If the output result of the first model indicates an adversarial sample, it means that the first model detects correctly.
[0111] Among them, the XAI feature samples may include values representing the feature importance of adversarial samples. For example, the XAI feature samples may include Shapley Additive Explanations (SHAP) values. Alternatively, the XAI feature samples may include values representing the unit importance of the AI model. For example, assuming the AI model is a neural network model, the XAI feature samples may include the SHAP values of the neurons in the hidden layer of the neural network, and the hidden layer is, for example, the penultimate layer of the neural network, that is, the hidden layer adjacent to the output layer.
[0112] Optionally, the first network element may also generate XAI feature samples based on normal training data, and may combine the XAI feature samples generated based on adversarial samples to perform supervised training on the first model. Among them, the XAI feature samples generated based on normal training data may include values representing the feature importance of normal training data or values representing the unit importance of the AI model. For specific details, reference may be made to the above introduction of XAI feature samples, and details will not be elaborated here.
[0113] Exemplarily, the first network element may set sample labels for normal training data and adversarial samples respectively. The first network element inputs the normal training data or adversarial samples into the AI model, obtains the output result of the AI model, and then generates XAI feature samples based on the output result of the AI model. After the first network element inputs the XAI feature samples into the first model and obtains the output result of the first model, it may compare the output result of the first model with the sample label of the data input into the AI model to determine whether the first model detects correctly.
[0114] Optionally, the XAI feature samples may be generated by a second model. The first network element may input the adversarial samples or normal training data into the AI model, and input the output result of the AI model into the second model to obtain the XAI feature samples output by the second model.
[0115] Among them, the second model may be used to explain the AI model and may also be referred to as an XAI model.
[0116] The embodiments of the present application do not limit the specific manner in which the first network element obtains the second model. For example, the first network element may train to obtain the second model. Alternatively, the first network element may also obtain the second model from other network elements. Alternatively, the second model may be preset in the first network element (for example, the operator or a third party deploys the second model in the first network element).
[0117] Optionally, the first network element may send the second model to the second network element.
[0118] In addition, the AI model used by the first network element when training the first model can be trained by the first network element. The first network element can train the AI model according to the acquired training data. Alternatively, the AI model can also be obtained by the first network element from other network elements, such as core network elements, third-party network elements, etc.
[0119] Exemplarily, the third-party network element can be the server of a manufacturer providing over-the-top (OTT) services that bypasses the operator.
[0120] S302. The first network element sends the first model to the second network element. Correspondingly, the second network element receives the first model.
[0121] In a possible implementation, the first network element can send the first model to the second network element when the first model meets certain conditions. Exemplarily, the first network element can send the first model to the second network element when the detection accuracy or detection accuracy rate of the first model reaches a threshold (for example, reaches 99%).
[0122] S303. If the second network element needs to input inference data into the AI model for inference, the second network element can detect whether the inference data is an adversarial sample according to the first model.
[0123] Based on the communication method provided in the embodiments of the present application, a model for detecting adversarial samples can be introduced in the AI application scenario of the communication network, so that adversarial samples input into the AI model can be identified in the inference stage, avoiding the performance degradation of the AI model and ensuring network performance.
[0124] Optionally, the inference data obtained by the second network element can be data or information related to the network. For example, the terminal device can send the measurement results of some parameters to the second network element, such as the traffic information, QoS parameters, energy consumption status, etc. of the terminal device, as inference data. For another example, a RAN node (such as a base station adjacent to the second network element) can send RAN-side data or information to the second network element as inference data. These RAN-side data or information for inference can be local to the RAN node, or can also be derived by the RAN node according to data or information from the terminal device or other RAN nodes. For example, the RAN-side data or information for inference can include the historical information of the terminal device (such as the location, QoS parameters or performance information of the historically switched terminal device), the resource status of the RAN node or the energy consumption status of the RAN node. For another example, the core network element can send the data or information related to the network obtained by the core network element to the second network element, such as the QoS information of the terminal device.
[0125] For detecting whether the inference data of the AI model is an adversarial sample, the second network element can determine whether the inference data is an adversarial sample based on the output result of the AI model obtained by inputting the inference data into the AI model and the first model. The following introduces possible implementations provided by this application.
[0126] In one possible implementation, the second network element can input the output result of the AI model into the first model and determine whether the inference data is an adversarial sample based on the output result of the first model. This implementation can specifically refer to the introduction of training the first model in S301 above and will not be elaborated here.
[0127] In another possible implementation, the second network element can obtain an XAI feature sample based on the output result of the AI model. The second network element then inputs the XAI feature sample into the first model and determines whether the inference data is an adversarial sample based on the output result of the first model. Among them, the XAI feature sample can include a value representing the feature importance of the inference data or a value representing the unit importance of the AI model. Optionally, in this implementation, the second network element can receive the second model from the first network element and generate the XAI feature sample based on the second model. This implementation can specifically refer to the introduction of training the first model in S301 above and will not be elaborated here.
[0128] Optionally, the AI model used by the second network element can be sent by the first network element to the second network element. In this case, the AI model sent by the first network element to the second network element is the AI model used by the first network element when training the first model. Or, the second network element can also obtain the AI model from other network elements. Or, the AI model can also be pre-configured in the second network element.
[0129] Among them, the embodiments of this application do not limit the timing of the first network element sending the first model to the second network element and the second network element obtaining the AI model. For example, assuming that the AI model is sent by the first network element to the second network element, the first network element can first send the AI model to the second network element through one or more messages, and then send the first model and the AI model to the second network element.
[0130] Among them, in one possible case, in order for the second network element to know that it can use the first model to detect the inference data of the AI model, the AI model can be associated with the first model.
[0131] Exemplarily, the first network element can send the first model and the AI model to the second network element together, so that the first model and the AI model can be naturally associated.
[0132] Exemplarily, it is assumed that the AI model obtained by the second network element can be identified by identification information, such as a model identification number (modelIdentity document, model ID). When the first network element sends the first model to the second network element, it can send the identification information of the AI model together with the first model to the second network element. Thus, the second network element can associate the first model with the AI model according to the identification information of the AI model.
[0133] Optionally, if the first network element also sends a second model to the second network element, the embodiments of the present application do not limit the timing sequence among the first network element sending the second model to the second network element, the first network element sending the first model to the second network element, and the second network element obtaining the AI model. For example, the first network element can send the first model, the second model, and the AI model to the second network element simultaneously. Another example is that the first network element can first send the AI model to the second network element, and then send the first model and the second model.
[0134] Optionally, if the first network element also sends a second model to the second network element, the second model can be associated with the AI model. Exemplarily, the AI model obtained by the second network element can be identified by identification information. When the first network element sends the second model to the second network element, it can send the identification information of the AI model together with the second model to the second network element. Thus, the second network element can associate the second model with the AI model according to the identification information of the AI model. Another example is that the first network element can send the AI model and the second model to the second network element simultaneously, so that the second model and the AI model can be naturally associated.
[0135] The above introduces that the second network element determines whether the inference data of the AI model is an adversarial sample according to the first model. The following introduces the possible situations after the second network element determines whether the inference data of the AI model is an adversarial sample according to the first model.
[0136] In a possible scenario, if the second network element determines that the inference data of the AI model is an adversarial sample, the second network element can ignore the output result of the AI model, that is, the second network element will not perform subsequent actions according to the output result. If the second network element determines that the inference data of the AI model is not an adversarial sample but normal inference data, the second network element can further perform subsequent actions according to the output result of the AI model. Optionally, the subsequent actions can be at least one of the actions such as sending the output result of the AI model to the network element responsible for unified network policy planning, adjusting relevant network policies, or sending relevant network policies to the corresponding network elements.
[0137] For example, assume that the output result of the AI model is a prediction of the load of the second network element. The second network element can decide whether to perform actions such as resource management based on the output result of the AI according to the judgment on whether the inference data of the AI model is an adversarial sample. For example, if the second network element determines that the predicted value of the load output by the AI model is higher than the threshold for determining whether the load is balanced, and the inference data input to the AI model is not an adversarial sample, the second network element can switch some terminal devices to an adjacent RAN node.
[0138] For another example, assume that the output result of the AI model is a prediction of the QoS of the terminal device. The second network element can decide whether to perform actions such as mobility management of the terminal device based on the output result of the AI according to the judgment on whether the inference data of the AI model is an adversarial sample.
[0139] Based on this solution, if it is identified that the inference data of the AI model is an adversarial sample, the network element using the AI model can refuse to adopt or execute the corresponding inference result to avoid deterioration of the network system performance.
[0140] In a possible scenario, the second network element can send the detected adversarial sample to the first network element when the first condition is met.
[0141] Optionally, the first condition can be: an adversarial sample is detected. That is, as long as the second network element detects an adversarial sample, it will send the detected adversarial sample to the first network element.
[0142] Alternatively, the second network element can maintain a corresponding counter for the device (such as a RAN node, a core network element, or a terminal device) that provides the inference data. When the second network element first detects that the inference data from a certain device is an adversarial sample, the initial value of the counter corresponding to the device is added or subtracted by a preset value (for example, it can be incremented by 1), and each time the inference data from the device is detected as an adversarial sample, the current value of the counter corresponding to the device is added or subtracted by the preset value (for example, it can be incremented by 1). In this case, the first condition can be: the counter corresponding to the device reaches the threshold. That is, if the counter corresponding to a certain device reaches the threshold, the second network element will send the adversarial sample from the device to the first network element.
[0143] Exemplarily, assume that the counter maintained by the second network element for a certain terminal device is called the first counter. The initial value of the first counter is 0, and the threshold is 5. Each time the second network element detects that the inference data from the terminal device is an adversarial sample, the first counter is incremented by 1. When the second network element detects 5 times that the inference data from the terminal device is an adversarial sample, the value of the first counter reaches the threshold 5, and the second network element sends the 5 detected adversarial samples to the first network element.
[0144] Optionally, the threshold of the counter can be preset. Alternatively, it can also be configured by the first network element or other network elements. For example, the first network element can send a first parameter to the second network element, and the first parameter is used to indicate the threshold of the counter.
[0145] Alternatively, the first condition can be that the value of one or more network-related metrics is higher or lower than the corresponding threshold. Among them, in the first condition, the value of the network-related metric can be measured, for example, measured by the second network element, or for another example, the measured metric value sent by the terminal device or other network elements to the second network element. Or, in the first condition, the value of the network-related metric can also be the prediction result output by the AI model.
[0146] Exemplarily, the first condition can be that the load of the network is higher than the corresponding threshold, the throughput of the network is lower than the corresponding threshold, or the energy consumption of the network is higher than the corresponding threshold, etc.
[0147] Optionally, when the second network element sends the adversarial sample to the first network element, it can also send the identification information of the AI model. After receiving the identification information of the AI model and the adversarial sample, the first network element can determine the first model associated with the AI model according to the identification information of the AI model, so as to determine that the adversarial sample is detected by the first model.
[0148] Optionally, if the first network element receives the adversarial sample detected by the second network element, the first network element can retrain the first model according to the received adversarial sample.
[0149] In a possible scenario, if the above first condition is satisfied and the detected adversarial sample comes from the terminal device, the second network element can release the connection with the terminal device. For example, assume that the second network element is a RAN node. If the second network element detects that the inference data from a certain terminal device is an adversarial sample, the second network element can release the radio resource control (RRC) connection with the terminal device.
[0150] In a possible scenario, if the above first condition is satisfied and the detected adversarial sample comes from the terminal device, the second network element can send the information of the terminal device to the third network element. In this scenario, when the second network element sends the information of the terminal device to the third network element, it can indicate that the terminal device is the terminal device that sends the adversarial sample.
[0151] Among them, the third network element and the first network element can be different network elements or the same network element. For example, the first network element can be an OAM network element, and the third network element can be an AMF network element. Or, the first network element and the third network element can be the same AMF network element.
[0152] Exemplarily, the information of the terminal device may be the identification information of the terminal device, such as a globally unique temporary identifier (GUTI), a subscription permanent identifier (SUPI), or a unique identifier of the terminal device on the Xn interface within a next generation RAN node (NG-RAN node UE XnAP ID).
[0153] Optionally, if the third network element receives the information of the terminal device from the second network element, the third network element may deregister the terminal device. For example, assuming that the third network element is an AMF network element, the third network element may delete the registration information of the terminal device (such as deleting information such as the authorization information of the terminal device) to deregister the terminal device.
[0154] Optionally, if the third network element receives the information of the terminal device from the second network element, the third network element may reject the connection request of the terminal device. For example, assuming that the third network element is a RAN node, the third network element may reject the request of the terminal device when the terminal device requests to access the serving cell.
[0155] It can be understood that in the above embodiments, if the first condition is met, there is no dependency relationship between different steps that the second network element can execute, and the second network element may execute one or more of the above steps. That is to say, if the first condition is met, the second network element may execute at least one of the following: sending the detected adversarial sample to the first network element, releasing the connection with the terminal device, or sending the information of the terminal device to the third network element. And, if the second network element executes multiple steps above, the embodiments of the present application do not limit the timing between different steps, and the second network element may execute different steps successively or simultaneously.
[0156] In a possible scenario, the first network element may also update the first model and / or the second model through the corresponding solutions in the above embodiments, and send the updated first model and / or the second model to the second network element.
[0157] Optionally, the network elements in the above embodiments, such as the first network element, the second network element, or the third network element, may be core network elements or RAN nodes, and the embodiments of the present application do not limit this.
[0158] In a possible scenario, the first network element, the second network element, or the third network element may include the AI module introduced above.
[0159] In a possible scenario, the first network element may include the model training management module introduced above. The second network element may include the model inference management module introduced above. Optionally, the second network element may further include the actor module introduced above.
[0160] Taking the first network element as the OAM network element and the second network element as the RAN node as an example, a possible exemplary process of the embodiments of the present application will be introduced. As Figure 4 shown, the exemplary process includes the following steps:
[0161] S401. The RAN node sends a measurement configuration to the UE, which is used to instruct the UE to perform a measurement process and report the measurement results. Correspondingly, the UE receives the measurement configuration.
[0162] S402. The UE obtains the measurement results according to the measurement configuration and reports the measurement results to the RAN node. Correspondingly, the RAN node receives the measurement results.
[0163] Exemplarily, the UE may measure the frequency points and beams indicated in the measurement configuration, and the obtained measurement results may include RSRP, RSRQ, SINR, etc. of the serving cell and / or neighboring cells.
[0164] S403. The RAN node uses the measurement results reported by the UE together with other data for training as training data and sends it to the OAM network element. Correspondingly, the OAM network element receives the training data.
[0165] Among them, the other data for training may be the information local to the RAN node, or the information derived by the RAN node according to the information from the UE or neighboring RAN nodes, such as the resource status of the RAN node, the energy consumption status of the gNB, or the traffic information of the UE.
[0166] S404. The OAM network element trains an AI model based on the training data reported by the RAN node. The AI model can be used for one or more tasks, or it can be understood that the AI model can be used to implement one or more functions. For example, the AI model can be used to predict the load information of the RAN node, predict the QoS information of the UE, etc.
[0167] S405. The OAM network element obtains adversarial samples.
[0168] Among them, optionally, the OAM network element may generate adversarial samples based on the normal training data reported by the RAN node. Or, the OAM network element may also obtain adversarial samples from other network nodes, which is not limited in this application.
[0169] S406. The OAM network element trains a first model based on the training data and the adversarial samples.
[0170] Among them, in one possible implementation, OAM can label the normal training data and adversarial samples with sample labels respectively, generate XAI feature samples through the second model, and perform supervised training on the first model based on the XAI feature samples and sample labels.
[0171] For the specific details of S405 - S406, reference can be made to the above introduction of S301, which will not be elaborated here.
[0172] S407. The OAM network element sends the AI model and the first model to the RAN node. Correspondingly, the RAN node receives the AI model and the first model. Among them, the AI model and the first model sent by the OAM network element can be those obtained after the initial training is completed, or the updated AI model and the first model.
[0173] Among them, in one possible implementation, the OAM network element can first send the AI model through one or more messages, and then send the first model, and the model ID of the first model and the AI model are sent together. After receiving the AI model and the first model, the RAN node can associate the first model with the AI model according to the model ID.
[0174] Among them, optionally, corresponding to the possible implementation of generating XAI feature samples through the second model in the above S406, in S407, the OAM network element can also send the second model to the RAN node. The OAM network element can send the second model together with the AI model, or first send the AI model, and then send the second model and the model ID.
[0175] S408. The UE reports the data for inference to the RAN node, such as measurement results. For specific details, reference can be made to S402.
[0176] Among them, optionally, the RAN node can also receive the data for inference from the adjacent RAN node. Exemplarily, the adjacent RAN node can send information such as UE historical information, resource status of the adjacent RAN node, and energy efficiency of the adjacent RAN node to the RAN node. Correspondingly, the RAN node receives the inference data.
[0177] S409. The RAN node inputs the inference data into the AI model, performs model inference and outputs the result or decision. And, the RAN node judges whether the inference data is an adversarial sample according to the inference data, the output result of the AI model and the first model. If it is judged as an adversarial sample, the RAN node ignores the current output result.
[0178] Optionally, corresponding to the possible implementation of training based on XAI feature samples in S406 above, the RAN node may generate XAI feature samples through a second model, input the XAI feature samples into the first model, and determine whether the inference data input to the AI model is an adversarial sample according to the output result of the first model.
[0179] Optionally, this exemplary process may further include S410: The RAN node maintains a counter with an initial value of 0 for each UE. If the inference data from the UE is detected as an adversarial sample, the value of the counter corresponding to the UE is incremented by one. The maximum value of the counter can also be understood as the maximum number of times the RAN node detects an adversarial sample.
[0180] Among them, the maximum value of the counter can be preset or configured by the OAM network element / AMF network element.
[0181] Optionally, this exemplary process may further include S411: If the RAN node detects that the inference data from the UE is an adversarial sample, the connection with the UE is released.
[0182] Among them, optionally, S411 may be triggered when the value of the counter corresponding to the UE reaches the maximum value.
[0183] Optionally, this exemplary process may further include S412: If the RAN node detects that the inference data from the UE is an adversarial sample, the adversarial sample is sent to the OAM network element. Correspondingly, the OAM network element receives the adversarial sample.
[0184] Optionally, the OAM network element may retrain the first model based on the received adversarial sample.
[0185] Among them, optionally, S412 may be triggered when the value of the counter corresponding to the UE reaches the maximum value.
[0186] Optionally, this exemplary process may further include S413 ( Figure 4 not shown in the figure): If the RAN node detects that the inference data from the UE is an adversarial sample, the information of the UE is sent to the AMF network element. Correspondingly, after receiving the information of the UE, the AMF network element de-registers the UE.
[0187] Among them, optionally, S413 may be triggered when the value of the counter corresponding to the UE reaches the maximum value.
[0188] Optionally, this exemplary process may further include S414 ( Figure 4(not shown in the figure): If the RAN node detects that the inference data from the UE is an adversarial sample, it sends the information of the UE to the adjacent RAN node. Correspondingly, after receiving the information of the UE, if the UE requests to establish a connection subsequently, the adjacent RAN node can reject the request.
[0189] Optionally, S414 may be triggered when the value of the counter corresponding to the UE reaches the maximum value.
[0190] For the specific details of S407 - S414, reference may be made to the above introduction of S302 - S303, and details will not be elaborated here.
[0191] In addition, the above embodiments take the interaction between the first network element and the second network element as an example to introduce the communication method provided in the embodiments of the present application. In a possible scenario, the communication method provided in the embodiments of the present application can be applied not only to network elements but also to terminal devices. For example, the second network element in the above embodiments can also be replaced by a terminal device, and the communication method executed by the second network element can also be adaptively executed by the terminal device.
[0192] The above mainly introduces the solution provided in the embodiments of the present application from the perspective of the interaction between various network elements. Correspondingly, the embodiments of the present application also provide a communication device, which is used to implement the above various methods. The communication device can be each of the network elements in the above method embodiments, or a device including each of the above network elements, or a component applicable to each of the above network elements. It can be understood that in order to implement the above functions, the communication device includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, combining the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0193] The embodiments of the present application can divide the functional modules of the communication device according to the above method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be understood that the division of modules in the embodiments of the present application is illustrative, only a logical functional division, and there may be other division methods in actual implementation.
[0194] Figure 5The schematic structural diagram of a communication device 500 is shown. The communication device 500 includes a processing module 501 and a transceiver module 502. Optionally, the communication device 500 may further include a storage module 503. The transceiver module 502, which may also be referred to as a transceiver unit, is used to implement the transceiver function. For example, it may be a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0195] Taking the communication device 500 as the first network element in the above embodiment as an example, in a possible implementation:
[0196] The processing module 501 is used to obtain adversarial samples and train the first model according to the adversarial samples. The transceiver module 502 is used to send the first model to the second network element. Among them, the first model is used to detect whether the inference data of the AI model is an adversarial sample.
[0197] Optionally, the processing module 501 is further used to obtain training data and generate adversarial samples according to the training data.
[0198] Optionally, the processing module 501 trains the first model according to the adversarial samples, including: generating XAI feature samples according to the adversarial samples, and training the first model according to the XAI feature samples. Among them, the XAI feature samples include values representing the feature importance of the adversarial samples; or, the XAI feature samples include values representing the unit importance of the AI model.
[0199] Optionally, the transceiver module 502 is further used to send a second model to the second network element. Among them, the XAI feature samples are generated by the second model, and the second model is used to interpret the AI model.
[0200] Optionally, the transceiver module 502 is further used to send the AI model to the second network element. Among them, the AI model is associated with the first model.
[0201] Optionally, the transceiver module 502 is further used to receive the adversarial samples detected by the second network element.
[0202] Optionally, the transceiver module 502 is further used to receive the identification information of the AI model from the second network element. Among them, the AI model is associated with the first model.
[0203] Optionally, the processing module 501 is further used to retrain the first model according to the adversarial samples detected by the second network element.
[0204] Optionally, the transceiver module 502 is further used to send a first parameter to the second network element. The first parameter is used to indicate the threshold of a first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
[0205] Optionally, the transceiver module 502 is further configured to receive information of a terminal device from a second network element. The processing module 501 is further configured to de-register the terminal device according to the information of the terminal device.
[0206] Taking the communication device 500 as the second network element in the above embodiment as an example, in a possible implementation:
[0207] The transceiver module 502 is configured to obtain a first model and inference data. The processing module 501 is configured to detect whether the inference data input to the AI model is an adversarial sample according to the first model.
[0208] Optionally, the processing module 501 detecting whether the inference data input to the AI model is an adversarial sample according to the first model includes: inputting the output result of the AI model into the first model, and detecting whether the inference data is an adversarial sample according to the output result of the first model.
[0209] Optionally, the processing module 501 detecting whether the inference data input to the AI model is an adversarial sample according to the first model includes: obtaining an XAI feature sample according to the output result of the AI model. Inputting the XAI feature sample into the first model, and detecting whether the inference data is an adversarial sample according to the output result of the first model. Wherein, the XAI feature sample includes a value representing the feature importance of the inference data; or, the XAI feature sample includes a value representing the unit importance of the AI model.
[0210] Optionally, the transceiver module 502 is further configured to obtain a second model, where the second model is used to generate the XAI feature sample.
[0211] Optionally, if a first condition is satisfied, the processing module 501 or the transceiver module 502 is further configured to perform at least one of the following: release the connection with the terminal device, send the detected adversarial sample to the first network element, or send the information of the terminal device to the third network element.
[0212] Optionally, the first condition is: detecting that the inference data from the terminal device is an adversarial sample; or, the first condition is: the first counter corresponding to the terminal device reaches a threshold; wherein, each time it is detected that the inference data from the terminal device is an adversarial sample, the current value of the first counter is incremented by one.
[0213] Optionally, the threshold is preset. Or, the threshold is configured by the first network element.
[0214] Optionally, the transceiver module 502 is further configured to obtain an AI model. Wherein, the AI model is associated with the first model.
[0215] Wherein, all the relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be elaborated here.
[0216] Optionally, Figure 5 the modules in may also be referred to as units. For example, the processing module may be referred to as the processing unit, and the transceiver module may be referred to as the transceiver unit. Additionally, in Figure 5 the embodiments shown, the names of the respective units may also not be the names shown in the figures. For example, the transceiver module may also be referred to as the communication module or communication unit.
[0217] Figure 5 If the respective units in are implemented in the form of software functional modules and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The storage media storing the computer software product include: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0218] In the embodiments of the present application, the communication device 500 is presented in the form of dividing each functional module in an integrated manner. Here, the "module" may refer to an application-specific integrated circuit (ASIC), a circuit, a processor and a memory that execute one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0219] In a simple embodiment, those skilled in the art can envision that the communication device 500 may adopt Figure 6 the form of the communication device shown.
[0220] As Figure 6 shown, the communication device 600 includes one or more processors 601, a communication line 602, and at least one communication interface ( Figure 6 in is merely exemplary and is described by taking the communication interface 604 and one processor 601 as an example), and optionally may further include a memory 603.
[0221] The processor 601 may be a general-purpose central processing unit (CPU), a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the solution of the present application.
[0222] The communication line 602 may include a path for connecting different components.
[0223] The communication interface 604 may be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, terminals, wireless local area networks (WLANs), etc. For example, the transceiver module may be a device such as a transceiver or a transceiver. Optionally, the communication interface 604 may also be a transceiver circuit or an input / output interface located within the processor 601 for implementing signal input and signal output of the processor.
[0224] The memory 603 may be a device with storage functions. For example, it may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or it may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited to this. The memory may exist independently and be connected to the processor through the communication line 602. The memory may also be integrated with the processor.
[0225] Among them, the memory 603 is used to store computer execution instructions for executing the solution of the present application, and is controlled by the processor 601 to execute. The processor 601 is used to execute the computer execution instructions stored in the memory 603, thereby implementing the communication method provided in the embodiments of the present application.
[0226] Alternatively, optionally, in the embodiments of the present application, it may also be that the processor 601 executes the functions related to processing in the communication method provided in the following embodiments of the present application, and the communication interface 604 is responsible for communicating with other devices or communication networks. The embodiments of the present application do not make specific limitations on this.
[0227] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, and the embodiments of the present application do not make specific limitations thereon.
[0228] In a specific implementation, as an embodiment, the processor 601 may include one or more CPUs, such as Figure 6 CPU0 and CPU1 in
[0229] In a specific implementation, as an embodiment, the communication device 600 may include multiple processors, such as Figure 6 processor 601 and processor 607 in
[0230] Each of these processors may be a single-core processor or a multi-core processor. The processors herein may include, but are not limited to, at least one of the following: CPU, microprocessor, digital signal processing (DSP) processor, microcontroller unit (MCU), or various computing devices that run software such as artificial intelligence processors. Each computing device may include one or more cores for executing software instructions for arithmetic operations or processing.
[0231] The above-mentioned communication device 600 may sometimes also be referred to as a communication equipment, which may be a general-purpose device or a dedicated device. For example, the communication device 600 may be the first network element, the second network element in the foregoing, or a device having a Figure 6 similar structure in
[0232] In addition, Figure 6 the composition structure shown in Figure 6In addition to the components shown, the communication device 600 may include more or fewer components than those shown, or combine certain components, or have a different component arrangement.
[0233] Optionally, Figure 5 the functions / implementation processes of the transceiver module 502 and the processing module 501 in Figure 6 may be implemented by the processor 601 in the communication device 600 shown calling computer-executable instructions stored in the memory 603. Or, Figure 5 the function / implementation process of the processing module 501 in Figure 6 may be implemented by the processor 601 in the communication device 600 shown calling computer-executable instructions stored in the memory 603, Figure 5 and the function / implementation process of the transceiver module 502 in Figure 6 may be implemented by the communication interface 604 in the communication device 600 shown.
[0234] It should be understood that one or more of the above modules or units may be implemented in software, hardware, or a combination of both. When any of the above modules or units is implemented in software, the software exists in the form of computer program instructions and is stored in the memory. The processor may be used to execute the program instructions and implement the above method flow. The processor may be built into the SoC or ASIC, or may be an independent semiconductor chip. In addition to the cores in the processor for executing software instructions for arithmetic or processing, it may further include necessary hardware accelerators, such as FPGA, programmable logic device (PLD), or logic circuits for implementing dedicated logic operations.
[0235] When the above modules or units are implemented in hardware, the hardware may be any one or any combination of CPU, microprocessor, DSP chip, MCU, artificial intelligence processor, ASIC, SoC, FPGA, PLD, dedicated digital circuit, hardware accelerator, or non-integrated discrete device, which may run the necessary software or execute the above method flow without relying on software.
[0236] Optionally, an embodiment of the present application further provides a communication device (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the method in any of the above method embodiments. In a possible design, the communication device further includes a memory. The memory is used to store necessary program instructions and data, and the processor may call the program code stored in the memory to instruct the communication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the communication device. When the communication device is a chip system, it may be composed of chips or may include chips and other discrete devices. The embodiments of the present application do not make specific limitations on this.
[0237] Optionally, an embodiment of the present application further provides a computer-readable storage medium storing a computer program or instructions. When the computer program or instructions run on a communication device, the communication device can execute the method described in any of the above method embodiments or any of its implementation manners.
[0238] Optionally, an embodiment of the present application further provides a communication system including the network device described in the above method embodiment and the terminal device described in the above method embodiment.
[0239] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by the computer or a data storage device such as a server or data center including one or more integrated media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state drive (SSD)), etc.
[0240] Although the present application has been described in conjunction with various embodiments herein, however, during the implementation of the claimed application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0241] Although the present application has been described in connection with specific features and their embodiments, it will be apparent that various modifications and combinations can be made without departing from the scope of the present application. Accordingly, this specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.
Claims
1. A communication method, It is characterized in that The method comprises: Obtain an adversarial sample, and train a first model based on the adversarial sample; the first model is used to detect whether the inference data of the artificial intelligence AI model is an adversarial sample; Sending the first model to the second network element.
2. The method according to claim 1, It is characterized in that The method further comprises: Get training data; The adversarial sample is generated according to the training data.
3. The method according to claim 1 or 2, It is characterized in that The step of training a first model according to the adversarial sample comprises: Generate an explainable artificial intelligence XAI feature sample according to the adversarial sample; the XAI feature sample includes a value representing the feature importance of the adversarial sample; or, the XAI feature sample includes a value representing the unit importance of the AI model; The first model is trained according to the XAI feature samples.
4. The method according to claim 3, It is characterized in that The method further comprises: A second model is sent to the second network element, the XAI feature sample is generated by the second model, and the second model is used to interpret the AI model.
5. The method according to any one of claims 1 to 4, It is characterized in that The method further comprises: Sending the AI model to the second network element; wherein the AI model is associated with the first model.
6. The method according to any one of claims 1 to 5, It is characterized in that The method further comprises: Receive the adversarial sample detected by the second network element.
7. The method according to claim 6, It is characterized in that The method further comprises: Receive identification information of the AI model from the second network element; wherein the AI model is associated with the first model.
8. The method according to claim 6 or 7, It is characterized in that The method further comprises: Retraining the first model according to the adversarial samples detected by the second network element.
9. The method according to any one of claims 1 to 8, It is characterized in that The method further comprises: A first parameter is sent to the second network element, where the first parameter is used to indicate a threshold of a first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
10. The method according to any one of claims 1 to 9, It is characterized in that The method further comprises: receiving information from a terminal device of the second network element; Deregister the terminal device.
11. A communication method, It is characterized in that The method comprises: Obtaining a first model and inference data; According to the first model, detect whether the inference data input into the artificial intelligence AI model is an adversarial sample.
12. The method according to claim 11, It is characterized in that The detecting, according to the first model, whether the inference data input into the artificial intelligence AI model is an adversarial sample comprises: The output result of the AI model is input into the first model, and based on the output result of the first model, it is detected whether the inference data is an adversarial sample.
13. The method according to claim 11, It is characterized in that The detecting, according to the first model, whether the inference data input into the artificial intelligence AI model is an adversarial sample comprises: According to the output result of the AI model, an explainable artificial intelligence XAI feature sample is obtained; wherein the XAI feature sample includes a value representing the feature importance of the reasoning data; or the XAI feature sample includes a value representing the unit importance of the AI model; The XAI feature sample is input into the first model, and based on the output result of the first model, it is detected whether the inference data is an adversarial sample.
14. The method according to claim 13, It is characterized in that The method further comprises: A second model is obtained, where the second model is used to generate an XAI feature sample.
15. The method according to any one of claims 11 to 14, It is characterized in that The method further comprises: If the first condition is met, perform at least one of the following: Release the connection with the terminal device; Sending the detected adversarial sample to the first network element; or, Send the terminal device information to the third network element.
16. The method according to claim 15, It is characterized in that The first condition is: detecting that the inference data from the terminal device is an adversarial sample; or The first condition is that a first counter corresponding to the terminal device reaches a threshold; wherein each time the inference data from the terminal device is detected as an adversarial sample, the current value of the first counter is increased by one.
17. The method according to claim 16, It is characterized in that The threshold is preset; or, the threshold is configured by the first network element.
18. The method according to any one of claims 11 to 17, It is characterized in that The method further comprises: Obtain the AI model; wherein the AI model is associated with the first model.
19. A communication device, It is characterized in that The communication device comprises: a module for executing the method according to any one of claims 1-10; or the communication device comprises a module for executing the method according to any one of claims 11-18.
20. A communication device, It is characterized in that The communication device comprises: a processor; the processor is used to execute a computer program or instruction stored in a memory, so that the communication device executes the method according to any one of claims 1-10 or 11-18.
21. A chip system, It is characterized in that include: processor and interface circuits; The interface circuit is used to receive computer execution instructions and transmit them to the processor; The processor is configured to execute the computer-executable instructions so as to enable the communication device to perform the method according to any one of claims 1-10 or 11-18.
22. A computer-readable storage medium, It is characterized in that The computer-readable storage medium includes a computer program or an instruction. When the computer program or the instruction is executed on a computer, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 18 is executed.
23. A computer program product, It is characterized in that The computer program product comprises instructions, and when the instructions are executed on a computer, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 18 is executed.
24. A communication system, It is characterized in that The communication system comprises a first network element and a second network element; wherein the first network element is used to execute the method according to any one of claims 1-10, and the second network element is used to execute the method according to any one of claims 11-18.