Model management method and device

By using model inference and training functional entities to label or eliminate suspicious data during the AI ​​model update process in the wireless field, the virus attack security threat faced by AI models is solved, reducing data security risks and improving the training accuracy of the model.

CN120075810APending Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311636277.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

AI models in the wireless field face security threats at all stages of their life cycle, mainly including poisoning attacks, resulting in increased data security risks.

Method used

By obtaining a collection of communication data used to update the first machine learning model, the model inference function entity and the model training function entity use processing strategies to label or eliminate suspicious data, avoiding adverse effects on model training and reducing data security risks.

Benefits of technology

It effectively reduces the data security risks of AI models in the wireless field, prevents the negative impact of poisoning attacks on model training, and ensures the training accuracy and business reliability of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075810A_ABST
    Figure CN120075810A_ABST
Patent Text Reader

Abstract

The invention provides a model management method and device, belongs to the technical field of communication, and is used for reducing the data security risk of an AI model in the wireless field. The method comprises the following steps: acquiring a first communication data set for updating a first machine learning model, and sending a second communication data set to a model training functional entity; wherein the first processing strategy comprises a first loss threshold value, and the first machine learning model is used for managing the wireless communication service. The second communication data set is obtained after suspicious data in the first communication data set is processed according to the first processing strategy, and the suspicious data is wireless communication data with the loss value larger than a first loss threshold value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and in particular, to a method and apparatus for managing a model. Background Art

[0002] To improve the intelligence and automation level of the network, artificial intelligence (AI) and machine learning (ML) technologies are being increasingly applied to the wireless field. Multiple fields, including the management domain, the core network (CN) domain, and the radio access network (RAN) domain, are researching how to apply AI / ML technologies to enable network intelligence.

[0003] However, AI models in the wireless field face security threats at all stages of their life cycle, mainly including but not limited to poisoning attacks. Therefore, how to reduce the data security risk of AI models in the wireless field is a hot research issue currently. Summary of the Invention

[0004] Embodiments of this application provide a method and apparatus for managing a model to reduce the data security risk of AI models in the wireless field.

[0005] To achieve the above object, this application adopts the following technical solutions:

[0006] In a first aspect, a method for managing a model is provided, which is applied to a model inference functional entity. The method includes: obtaining a first communication data set for updating a first machine learning model, and sending a second communication data set to a model training functional entity. The first processing policy includes a first loss threshold, and the first machine learning model is used to manage wireless communication services. The second communication data set is obtained by performing a processing operation on suspicious data in the first communication data set according to the first processing policy, and the suspicious data is wireless communication data with a loss value greater than the first loss threshold.

[0007] The first machine learning model may be an AI beam management, or a beam selection model, or may also be a model for other management scenarios in wireless communication, such as a downlink / uplink data volume prediction model, a channel fading change prediction model, a CSI feedback model, an AI-assisted positioning model, etc., which is not specifically limited herein.

[0008] The first communication data set may include wireless communication data between an access network device and multiple terminals. Specifically, it may include data such as reference signal received power (RSRP), channel state information matrix, and channel impulse response, which are used for service guarantee in the wireless communication process. In addition, the first communication data set may also include tags. The tags can be used to mark the true values of the wireless communication data in the corresponding scenarios and can be selected according to the actual situation. Taking the RSRP in the beam management scenario of AI as an example, the wireless communication data may include the RSRP and the beam identifier corresponding to the RSRP. The tag can be used to mark whether the beam indicated by the beam identifier is the best beam corresponding to the RSRP. For example, the tag includes two values, 0 / 1. Among them, 1 indicates that the beam indicated by the beam identifier is the best beam corresponding to the RSRP, and 0 indicates that the beam indicated by the beam identifier is not the best beam corresponding to the RSRP.

[0009] According to the method described in the first aspect, since the main purpose of the poisoning attack is to affect the training effect during the model retraining update process and reduce its training accuracy, that is, the loss value of the updated model on the poisoned data is relatively large. Accordingly, the model inference functional entity can determine the data with a loss value greater than the first loss threshold in the first communication data set as suspicious data, or data suspected of a poisoning attack, and perform processing to avoid adverse effects on the training of the first machine learning model and reduce the data security risk of the AI model in the wireless field.

[0010] In a possible design solution, the processing operation includes a marking operation. The marking operation refers to adding an easily recognizable mark to the suspicious data for subsequent identification of which data is suspicious, so as to avoid the suspicious data affecting the retraining of the first machine learning model and ensure the effect of model retraining.

[0011] Optionally, before performing the marking operation, the method described in the first aspect further includes: determining that the proportion of suspicious data in the first communication data set is greater than the first proportion threshold.

[0012] In a possible design solution, the processing operation includes an exclusion operation. The exclusion operation refers to excluding the suspicious data from the first communication data set to avoid retraining the first machine learning model with the suspicious data subsequently and ensure the effect of model retraining.

[0013] Optionally, before performing the exclusion operation, the method further includes: determining that the proportion of suspicious data in the first communication data set is less than or equal to the first proportion threshold.

[0014] It can be understood that the first proportional threshold can represent the upper limit of the proportion of suspicious data allowed in the communication data set for normal training of the model. That is to say, if the proportion of suspicious data in the communication data set is less than or equal to the first proportional threshold, it means that the number of suspicious data is not too large. Even if this part of the suspicious data is removed, the sample size of the normal data remaining in the communication data set can still complete the normal training of the machine learning model. Therefore, the model inference functional entity can perform the removal operation. On the contrary, if the proportion of suspicious data in the communication data set is greater than the first proportional threshold, it means that the proportion of the number of suspicious data is too large. If this part of the suspicious data is removed rashly, the sample size of the normal data may not be able to support the normal training of the machine learning model. Therefore, the model inference functional entity can perform a marking operation to decide whether the model training functional entity should use or remove these suspicious data.

[0015] Optionally, the first processing strategy may include the first proportional threshold. That is, the first proportional threshold can be dynamically configured along with the first processing strategy to enable dynamic adjustment according to actual requirements. Alternatively, the first proportional threshold can also be pre-configured locally in the model inference functional entity to avoid the overhead caused by configuration.

[0016] In a possible design solution, the first processing strategy can indicate a processing operation.

[0017] In a possible design solution, the method described in the first aspect further includes: receiving the first processing strategy from the model management functional entity. That is, the first processing strategy can also be dynamically configured by a network element / entity in the management domain to enable dynamic adjustment according to actual requirements. Alternatively, the first processing strategy can also be pre-configured locally in the model inference functional entity to avoid the overhead caused by configuration.

[0018] In a possible design solution, obtaining the first communication data set for updating the first machine learning model includes: receiving first indication information from the model training functional entity, and according to the first indication information, receiving wireless communication data from multiple terminals. The first indication information is used to indicate that the first machine learning model needs to be updated to achieve on-demand acquisition and avoid redundancy.

[0019] Optionally, the model inference functional entity is deployed on an access network device. For example, the model inference functional entity is deployed on the Open Central Unit (O-CU) or Open Distributed Unit (O-DU) of the access network device, or it can also be deployed on any other possible device form of the network element / device, and this is not limited.

[0020] In a possible design solution, the method described in the first aspect may further include: processing the first communication data set through a first machine learning model to determine the suspicious data in the first communication data set. That is, the model inference functional entity may use the first machine learning model to perform inference calculations on the first communication data set to determine the suspicious data therein.

[0021] In a possible design solution, after sending the second communication data set to the model training functional entity, the method described in the first aspect may further include: receiving second indication information from the model training functional entity, and obtaining a second machine learning model according to the second indication information. The second indication information is used to indicate the second machine learning model, and the second machine learning model is obtained by updating the first machine learning model, thus realizing the update of the machine learning model and avoiding the impact on the actual business due to the reduction of the model accuracy.

[0022] In the second aspect, a method for managing a model is provided, which is applied to a model training functional entity and includes: obtaining a second communication data set for updating the first machine learning model, and updating the first machine learning model according to a third communication data set. The first machine learning model is used to manage wireless communication services. The third communication data set is obtained by performing an elimination operation on the error data in the second communication data set according to a second processing strategy. The second processing strategy includes a third loss threshold. If the first machine learning model is updated using the error data, the loss value of the updated machine learning model for processing wireless communication data is greater than the third loss threshold.

[0023] According to the method described in the second aspect, since the main purpose of the poisoning attack is to affect the training effect during the model retraining and update process, resulting in a decrease in its training accuracy and a relatively large loss value of the updated model on the poisoned data. Accordingly, the model training functional entity can also adopt a similar method as the above model inference functional entity to determine the data with a loss value greater than the first loss threshold in the first communication data set as error data, such as the data of the poisoning attack, and eliminate it to avoid adverse effects on the training of the first machine learning model and reduce the data security risk of the AI model in the wireless field.

[0024] In a possible design solution, the elimination operation refers to eliminating the error data from the second communication data set.

[0025] Optionally, the rejection operation specifically refers to removing the incorrect data from the suspiciously marked data from the second communication data set. The suspiciously marked data (or suspicious data) is wireless communication data in the second communication data set with a loss value greater than the loss threshold. It can be understood that since the computing power of the model training functional entity is more powerful than that of the model inference functional entity, when the model inference functional entity cannot distinguish which data in the suspicious data is normal data and which data is poisoning attack data, the model training functional entity can remove the truly poisoning attack data from the suspicious data through a more refined rejection operation, and use the normal data in the suspicious data for model training to improve the utilization efficiency of the training data.

[0026] Optionally, the method described in the second aspect further includes: dividing the suspiciously marked data into M data subsets, where M is an integer greater than 1; updating the first machine learning model using the i-th data subset among the M data subsets to obtain the i-th updated machine learning model, where i iterates from 1 to M; processing the test data using the i-th updated machine learning model to obtain the i-th test result; if the loss value of the test data in the i-th test result is greater than the third loss threshold, determining that the i-th data subset is incorrect data, otherwise, determining that the i-th data subset is not incorrect data. It can be seen that by dividing the suspicious data into multiple data subsets, it is possible to achieve rejection of incorrect data at the granularity of data subsets. Compared with rejecting all the suspicious data, the granularity is finer and normal data can be retained.

[0027] Optionally, the second processing strategy may indicate the rejection operation.

[0028] Optionally, the method described in the second aspect further includes: receiving the second processing strategy from the model management functional entity, that is, the second processing strategy can also be dynamically configured by the network element / entity in the management domain to enable dynamic adjustment according to actual requirements. Alternatively, the second processing strategy can also be pre-configured locally in the model training functional entity to avoid the overhead caused by configuration.

[0029] Optionally, before obtaining the second communication data set for updating the first machine learning model, the method described in the second aspect may further include: sending a first indication message to the model inference functional entity. Obtaining the second communication data set for updating the first machine learning model includes: receiving the second communication data set from the model inference functional entity; where the first indication message is used to indicate that the first machine learning model needs to be updated to achieve on-demand acquisition and avoid redundancy.

[0030] Further, sending first indication information to the model inference functional entity includes: sending first indication information to the model inference functional entity according to a first condition. The first condition includes at least one of the following: having currently entered the next update cycle of the machine learning model to achieve periodic dynamic updates, the prediction accuracy of the machine learning model being lower than an accuracy threshold, in which case the model needs to be updated to improve its accuracy, or the proportion of suspicious data in the wireless communication data obtained last time for updating the machine learning model being greater than a second proportion threshold, and the remaining time until the end of the machine learning model update being greater than a threshold duration, which can be the sum of the duration required to obtain the wireless communication data for updating the machine learning model and the duration required to update the machine learning model. In this way, the effect of this model update can be ensured by re-obtaining the data.

[0031] Further, the method described in the second aspect may further include: sending a second loss threshold to the model inference functional entity, where the second loss threshold may be smaller than the loss threshold pre-configured by the model inference functional entity, such as the first loss threshold, to relax the threshold for defining suspicious data by the model inference functional entity and ensure that more normal data can be collected for training.

[0032] Further, the second processing strategy also indicates the first condition.

[0033] Further, before updating the first machine learning model according to the third communication data set, the method described in the second aspect may further include: determining to update the first machine learning model according to a second condition, where the second condition means that the proportion of suspicious data in the communication data set is less than or equal to the second proportion threshold. That is to say, the second proportion threshold can represent the upper limit of the proportion of data suspected of poisoning attacks allowed for normal training in the communication data set. In practice, if the proportion of suspicious data in the second communication data set is less than or equal to the second proportion threshold, it means that the number of suspicious data is not too large. Even if this part of the suspicious data is removed, the remaining data in the second communication data set can still complete the normal training of the first machine learning model. Therefore, the model inference functional entity can perform the removal operation.

[0034] Further, the second processing strategy also indicates the second condition.

[0035] Optionally, the second processing strategy includes the second proportion threshold.

[0036] In a possible design, after updating the first machine learning model according to the third communication data set, the method described in the second aspect may further include: sending second indication information to the model inference functional entity; where the second indication information is used to indicate the second machine learning model, and the second machine learning model is obtained by updating the first machine learning model.

[0037] In a possible design solution, the model training functional entity is deployed on the access network device, and the second communication data set includes the wireless communication data between the access network device and multiple terminals.

[0038] It can be understood that for the technical effects of the method described in the second aspect, reference can also be made to the relevant introduction in the method described in the first aspect, which will not be elaborated here.

[0039] In a third aspect, a method for managing a model is provided, which is applied to a model management functional entity and includes: obtaining a first processing strategy of a first machine learning model and sending the first processing strategy to a model inference functional entity. Among them, the first machine learning model is used to manage wireless communication services, the first machine learning model is deployed on the model inference functional entity, the first processing strategy includes a first loss threshold, and the first processing strategy can be used to perform processing operations on suspicious data in the communication data set used to update the machine learning model. The suspicious data is data with a loss value greater than the first loss threshold.

[0040] In a possible design solution, the processing operation includes a marking operation, and the marking operation refers to adding a mark that is convenient for identification to the suspicious data.

[0041] In a possible design solution, the processing operation includes an elimination operation, and the elimination operation refers to removing the suspicious data from the communication data set.

[0042] In a possible design solution, the first processing strategy includes a first ratio threshold.

[0043] In a possible design solution, the first processing strategy indicates the processing operation.

[0044] In a possible design solution, the method described in the third aspect may further include: obtaining a second processing strategy of the first machine learning model and sending the second processing strategy to a model training functional entity for updating the first machine learning model. Among them, the second processing strategy can be used to perform an elimination operation on the error data in the communication data set used to update the machine learning model. The second processing strategy includes a third loss threshold. If the machine learning model is updated using the error data, the loss value of the updated machine learning model for processing wireless communication data is greater than the third loss threshold.

[0045] Optionally, the elimination operation refers to removing the error data from the communication data set.

[0046] In a possible design solution, the elimination operation specifically refers to removing the error data from the suspicious data marked in the communication data set. The suspicious data marked is the wireless communication data in the communication data set with a loss value greater than the loss threshold.

[0047] Optionally, the second processing strategy indicates a rejection operation.

[0048] Optionally, the second processing strategy further indicates that a set of communication data needs to be obtained according to a first condition, where the first condition includes at least one of the following: the current has entered the next update cycle of the machine learning model, the prediction accuracy of the machine learning model is lower than an accuracy threshold, or the proportion of suspicious data in the wireless communication data obtained last time for updating the machine learning model is greater than a second proportion threshold, and the remaining time until the end of the machine learning model update is greater than a threshold time; the threshold time is the sum of the time required to obtain the wireless communication data for updating the machine learning model and the time required to update the machine learning model.

[0049] Optionally, the second processing strategy further indicates that the machine learning model needs to be updated according to a second condition, where the second condition refers to that the proportion of data marked as suspicious in the set of communication data is less than or equal to the second proportion threshold.

[0050] Optionally, the second processing strategy includes a second proportion threshold.

[0051] It can be understood that the technical effects of the method described in the second aspect can also refer to the relevant introductions in the methods described in the first aspect and the second aspect, and will not be elaborated here.

[0052] In a fourth aspect, a communication device is provided, and the communication device includes a module for executing the method described in any one of the first aspect to the third aspect above.

[0053] In a possible design, the communication device described in the fourth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fourth aspect to communicate with other communication devices.

[0054] In a possible design, the communication device described in the fourth aspect may further include a memory. The memory may be integrated with the processor or may be separately provided. The memory may be used to store instructions related to the method described in any one of the first aspect to the third aspect.

[0055] In the embodiments of the present application, the communication device described in the fourth aspect may be a network device, or a chip (system) or other components or assemblies that can be disposed in the network device, or a device including the network device.

[0056] It can be understood that the technical effects of the device described in the fourth aspect can also refer to the relevant introductions of the methods described in any one of the first aspect to the third aspect above, and will not be elaborated.

[0057] In a fifth aspect, a communication device is provided. The communication device includes: a processor coupled to a memory, the processor being configured to execute instructions stored in the memory to cause the communication device to perform the method described in any one of the first to third aspects.

[0058] In a possible design, the communication device according to the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device according to the fifth aspect to communicate with other communication devices.

[0059] In the embodiments of the present application, the communication device according to the fifth aspect may be the network device described in any one of the first to third aspects, or a chip (system) or other component or assembly that can be disposed in the network device, or a device including the network device.

[0060] In addition, the technical effects of the communication device according to the fifth aspect may refer to the technical effects of the method described in any one of the first to third aspects, which will not be elaborated here.

[0061] In a sixth aspect, a communication device is provided, including: a processor and a memory; the memory is configured to store instructions, and when the processor executes the instructions, the communication device is caused to perform the method described in any one of the first to third aspects.

[0062] In a possible design, the communication device according to the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device according to the sixth aspect to communicate with other communication devices.

[0063] In the embodiments of the present application, the communication device according to the sixth aspect may be the network device described in any one of the first to third aspects, or a chip (system) or other component or assembly that can be disposed in the network device, or a device including the network device.

[0064] In addition, the technical effects of the communication device according to the sixth aspect may refer to the technical effects of the method described in any one of the first to third aspects, which will not be elaborated here.

[0065] In a seventh aspect, a chip is provided, the chip including: a controller and an interface circuit, wherein the controller is configured to interact with other devices through the interface circuit to perform the method described in any one of the first to third aspects.

[0066] In an eighth aspect, a communication system is provided. The communication system includes at least one of the following: a model inference functional entity for performing the method described in the first aspect, a model training functional entity for performing the method described in the second aspect, or a model management functional entity for performing the method described in the third aspect.

[0067] In a ninth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored computer program or instruction, and when the computer program or instruction is run, the method described in any one of the first to third aspects is executed.

[0068] In a tenth aspect, a computer program product is provided, including a computer program or instruction, and when the computer program or instruction is run, the method described in any one of the first to third aspects is executed. Description of the Drawings

[0069] Figure 1 It is a schematic diagram of the neuron structure of the DNN;

[0070] Figure 2 It is a schematic diagram of the network architecture of the DNN;

[0071] Figure 3 It is a schematic diagram of the process of AI beam management;

[0072] Figure 4 It is a schematic diagram of the architecture of the communication system provided by the embodiment of the present application Figure 1 ;

[0073] Figure 5 It is a schematic diagram of the architecture of the communication system provided by the embodiment of the present application Figure 2 ;

[0074] Figure 6 It is a schematic diagram of the process of the model management method provided by the embodiment of the present application Figure 1 ;

[0075] Figure 7 It is a schematic diagram of the process of the model management method provided by the embodiment of the present application Figure 2 ;

[0076] Figure 8 It is a schematic diagram of the process of the model management method provided by the embodiment of the present application Figure 3 ;

[0077] Figure 9 It is a schematic diagram of the structure of the communication device provided by the embodiment of the present application Figure 1 ;

[0078] Figure 10 It is a schematic diagram of the structure of the communication device provided by the embodiment of the present application Figure 2 。 Detailed implementation manners

[0079] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle networking communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, worldwide interoperability for microwave access (WiMAX) communication systems, fifth-generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 5.5G, sixth-generation (6G) mobile communication systems, etc.

[0080] For ease of understanding, the technical terms involved in the embodiments of the present application will be introduced first below.

[0081] To improve the intelligence and automation levels of the network, artificial intelligence (AI) and machine learning (ML) technologies are being applied in more and more fields. Multiple fields, including the management domain, the core network (CN) domain, and the radio access network (RAN) domain, are researching how to use AI / ML technologies to enable network intelligence. Currently, the 3rd Generation Partnership Project (3GPP) working group has multiple related topics for network intelligence under research. To support the use of models in the network, it is necessary to study the life cycle management of models. The model management topic (study on artificial intelligence / machine learning, AIMLMGMT) of 3GPP SA5 was successfully approved and discussions have started, focusing on the life cycle management of models in 5GS (including the management domain, RAN domain, and core network domain), including capabilities such as model training, inference, performance evaluation, deployment, testing, and updating.

[0082] Use cases of AI models in the current 3GPP standards include channel state information (CSI) feedback in RAN1, positioning and beam management, and energy-saving management, load balancing, and mobility optimization in RAN3. The model lifecycle management processes for the above use cases are roughly the same. For ease of understanding, the working process is described in detail using AI-beam management as an example.

[0083] AI-based beam management:

[0084] Machine learning is an important technical approach to realizing artificial intelligence. Machine learning can be divided into supervised learning, unsupervised learning, and reinforcement learning.

[0085] Supervised learning is based on the collected sample values and sample labels. Using machine learning algorithms, it learns the mapping relationship from sample values to sample labels and expresses the learned mapping relationship using a machine learning model. The process of training a machine learning model is the process of learning this mapping relationship. For example, in signal detection, the received signal with noise is the sample, and the corresponding true constellation point of this signal is the label. Machine learning expects to learn the mapping relationship between the sample and the label through training, that is, to make the machine learning model learn a signal detector. During training, the model parameters are optimized by calculating the error between the predicted value of the model and the true label. Once the mapping relationship is learned, the learned mapping can be used to predict the label of each new sample. The mapping relationship learned by supervised learning can include linear mapping and non-linear mapping. According to the type of label, the learning tasks can be divided into classification tasks and regression tasks.

[0086] Unsupervised learning only relies on the collected sample values and uses algorithms to discover the internal patterns of the samples by itself. In unsupervised learning, there is a type of algorithm that uses the samples themselves as the supervision signal, that is, the model learns the mapping relationship from samples to samples, which is called self-supervised learning. During training, the model parameters are optimized by calculating the error between the predicted value of the model and the samples themselves. Self-supervised learning can be used in applications such as signal compression and decompression recovery. Common algorithms include autoencoders and generative adversarial networks, etc.

[0087] Reinforcement learning is different from supervised learning and is a type of algorithm that learns strategies to solve problems by interacting with the environment. Different from supervised and unsupervised learning, there are no explicit "correct" action label data in reinforcement learning problems. The algorithm needs to interact with the environment to obtain the reward signal feedback from the environment, and then adjust the decision-making actions to obtain a larger numerical value of the reward signal. In downlink power control, for example, the reinforcement learning model adjusts the downlink transmission power of each user according to the total system throughput rate fed back by the wireless network, and thus expects to obtain a higher system throughput rate. The goal of reinforcement learning is also to learn the mapping relationship between the environmental state and the optimal decision-making actions. However, because the labels of "correct actions" cannot be obtained in advance, the network cannot be optimized by calculating the error between the actions and the "correct actions". The training of reinforcement learning is achieved through iterative interactions with the environment.

[0088] Deep neural network (DNN) is a specific implementation form of machine learning. According to the universal approximation theorem, in theory, neural networks can approximate any continuous function, enabling neural networks to have the ability to learn any mapping. Traditional communication systems need to rely on rich expert knowledge to design communication modules, while deep learning communication systems based on DNN can automatically discover implicit pattern structures from large datasets, establish the mapping relationship between data, and obtain performance superior to traditional modeling methods.

[0089] The idea of DNN comes from the neuron structure of the brain tissue. Each neuron performs a weighted sum operation on its input values and generates an output by passing the weighted sum result through a non-linear function.

[0090] For example Figure 1 as shown, it can be assumed that the input of the neuron is x = [x 0 , …, x n , the weights corresponding to the input are d = [d 0 , …, d n , the bias of the weighted sum is b, and the form of the non-linear function can be diversified. For example, it can be the maximum value function of max{0, x}. In this way, the execution effect of a neuron can be The weights of each neuron are the so-called model parameters of DNN. The model parameters can be optimized through the training process, enabling DNN to have the ability to extract data features and express mapping relationships. DNN generally uses supervised learning or unsupervised learning strategies to optimize the model parameters.

[0091] For example Figure 2As shown, a DNN generally has a multi-layer structure. Each layer of the DNN can contain multiple neurons. After the input layer of the DNN processes the received values through neurons, it transmits them to the intermediate hidden layer. The DNN generally has more than one hidden layer, and the hidden layer often directly affects the ability to extract information and fit functions. Increasing the number of hidden layers of the DNN or expanding the width of each layer can improve the function fitting ability of the DNN. Then, after the hidden layer of the DNN processes the received values through neurons, it transmits the calculation results to the final output layer to generate the final output of the DNN.

[0092] According to the construction method of the network, DNNs can be divided into feed forward neural networks (FNNs), convolutional neural networks (CNNs), and recurrent neural networks (RNNs).

[0093] The characteristic of the FNN network is that neurons between adjacent layers are fully connected in pairs, which makes the FNN usually require a large amount of storage space and leads to a high computational complexity.

[0094] A CNN is a neural network specifically designed to process data with a similar grid structure. For example, time series data (discrete sampling on the time axis) and image data (two-dimensional discrete sampling) can both be considered data with a similar grid structure. The CNN does not perform operations using all the input information at once, but instead uses a fixed-size window to intercept part of the information for convolution operations, which greatly reduces the computational amount of model parameters. In addition, according to the different types of information intercepted by the window (such as people and objects in the same picture being different types of information), each window can use different convolution kernels for operations, which enables the CNN to better extract the features of the input data.

[0095] An RNN is a type of DNN network that utilizes feedback time series information. Its input includes the new input value at the current moment and its own output value at the previous moment. The RNN is suitable for obtaining sequence features that are relevant in time and is particularly applicable to applications such as speech recognition and channel coding and decoding.

[0096] The above FNN, CNN, and RNN are common neural network structures, and these network structures are all constructed based on neurons. In fact, there can also be other types or structures of neural networks, which will not be elaborated here. In addition, the neural network mentioned in the embodiments of this application can also be replaced with any other possible expressions, such as neural network model, network model, AI model, AI network model, etc., and there is no limitation in this regard.

[0097] After beam management introduces an AI model, the terminal can predict which beams can be used as the best beams based on the AI model, thereby further reducing the overhead of beam management. As time goes by, the data distribution of the AI model changes, resulting in an increase in the model prediction error. This phenomenon is called model drift. To solve the model drift problem, it is usually necessary to retrain the model regularly with new data to maintain the prediction performance of the model.

[0098] The following specifically describes the model update process of AI-based beam management.

[0099] As Figure 3 shown, the specific process is as follows:

[0100] Steps 1-3: The RAN device collects training data for training or retraining. For example, the RAN device first performs a full beam scan to determine the reference signal receiving power (RSRP) and the corresponding best beam identifier (ID) for the UE, and then feeds them back to the RAN device.

[0101] Step 4: The RAN device trains the AI model. For example, the RAN device can perform forward calculation and backward feedback propagation based on the collected training data until the model converges, that is, an AI model that can be used for predicting the best beam ID is obtained.

[0102] Steps 5-7: The RAN device predicts possible best beam IDs through the AI model. For example, the RAN device first performs the first round of sparse beam scanning. For instance, the base station can send 8 beams with different directions in the horizontal direction and also 8 beams with different directions in the vertical direction, a total of 64 beams. The sparse beams can be selected from these 64 beams, and the number is usually 1 / 4 of the total number of beams. In the first round of sparse beam scanning, the terminal can use the beam to receive the measurement resources sent by the RAN device through the sparse beams to determine the measurement results, such as RSRP, and then feed them back to the RAN device. The RAN device can input the measurement results into the AI model to obtain K beam IDs. These K beams are the beams that the AI model predicts are most likely to become the best beams, and the value of K can be pre-configured in the AI model, such as 3, 4, or 5, etc.

[0103] Steps 8-9, the RAN device determines the best beam ID. The RAN device uses the above-mentioned determined K beams to send measurement resources. Correspondingly, the terminal can use the beam to receive the measurement resources sent by the RAN device through the K beams to determine the measurement results, and finally report the measurement resources corresponding to the best beam to the RAN device.

[0104] However, AI models in the wireless field face security threats at all stages of their life cycle, mainly including but not limited to poisoning attacks. For example, the training data of AI models in the wireless field is generally taken from the existing network. Therefore, there is a security risk that an adversary can inject poisoned sample points into the data collected from the existing network, resulting in a decrease in the accuracy of the trained model. Taking the above-mentioned AI beam management as an example, a fake UE held by the adversary reports deliberately forged poisoned data (such as false RSRP) to the RAN device, which is collected as training data for model update, and then a wrong prediction model is trained, such as a wrong classification boundary, ultimately leading to a decrease in the prediction performance of the (re-)trained model.

[0105] In addition, 3GPP also discussed the trustworthy management of AI models in the wireless field in Phase R18. 3GPP made clear requirements for the trustworthy management of AI models in TR28.908: Trustworthy management should be added in the model training, testing, and inference stages to enhance the robustness and security of AI models, and the AI models should be updated and maintained regularly. The current 3GPP standards mainly manage data collection, including: specifying the management specifications for data collection, annotation, processing, etc. and the protection of user privacy. However, these measures are not specifically for the trustworthy management of wireless AI models, so the effect is not significant, and the security vulnerabilities existing in the models themselves have not been studied deeply, so there is no defense strategy for wireless field AI models.

[0106] Therefore, to reduce the above-mentioned security risks in the wireless field, it is necessary to take necessary security protection measures in multiple stages of the model life cycle, such as training, deployment, and update, to improve the security of the model.

[0107] In view of the above technical problems, the embodiments of this application propose the following technical solutions.

[0108] Next, the technical solutions in this application will be described in conjunction with the accompanying drawings.

[0109] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to achieve the indication of specific information by relying on the arrangement order of each piece of information pre-agreed (such as protocol regulations), thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common parts of each piece of information and uniformly indicate them to reduce the indication overhead caused by separately indicating the same information.

[0110] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above description, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0111] It should be understood that the information to be indicated can be sent as a whole, or can be divided into multiple sub-information and sent separately, and the sending cycles and / or sending times of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. Among them, the sending cycles and / or sending times of these sub-information can be pre-defined, such as pre-defined according to the protocol, or can be configured by the sending device by sending configuration information to the receiving device.

[0112] "Sending information" in the present application can be understood as one device sending information to another device, or, it can also be understood as a logical module inside the device sending information to another logical module. For example, "a network device sends information" can be understood as the network device sending information to another device (such as a terminal or another network device), or, it can be understood as logical module 1 in the network device sending information to logical module 2 in the network device.

[0113] In this application, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as a logic module within a device receiving information from another logic module. For example, "a network device receiving information" can be understood as the network device receiving information from another device (such as a terminal or another network device), or it can be understood as logic module 1 in the network device receiving information from logic module 2 in the network device.

[0114] In this application, "sending information to... (such as a terminal)" or the relevant schematic in the drawings can be understood as the destination of the information being the terminal. It can include directly or indirectly sending information to the terminal. "Receiving information from... (such as a terminal)" or "receiving information sent from... (such as a terminal)" or "receiving the information sent by... (such as a terminal)", or the relevant schematic in the drawings can be understood as the source of the information being the terminal, and it can include directly or indirectly receiving information from the terminal. Necessary processing may be performed on the information between the source and destination of the information transmission, such as format changes, etc., but the destination can understand the valid information from the source. Similar expressions in this application can be understood similarly, and will not be elaborated here.

[0115] "Pre - definition" or "pre - configuration" can be achieved by pre - saving corresponding codes, tables, or other means that can be used to indicate relevant information in the device. The embodiments of this application do not limit the specific implementation methods thereof. Among them, "saving" can refer to saving in one or more memories. The one or more memories can be set separately, or integrated in an encoder, decoder, processor, or communication device. The one or more memories can also be partially set separately and partially integrated in the decoder, processor, or communication device. The type of the memory can be any form of storage medium, and the embodiments of this application do not limit this.

[0116] The "protocol" involved in the embodiments of this application can refer to a protocol family in the communication field, a standard protocol with a frame structure similar to that of a protocol family, or a relevant protocol applied to future communication systems. The embodiments of this application do not make specific limitations on this.

[0117] In the embodiments of this application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the device making corresponding processing under a certain objective situation, not limiting time, and do not require the device to have a judgment action during implementation, nor does it mean there are other limitations.

[0118] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of the present application is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first" and "second" do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0119] The network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0120] To facilitate the understanding of the embodiments of the present application, first, a communication system will be used as an example to detail the communication system applicable to the embodiments of the present application.

[0121] As Figure 4 shown, exemplary, this communication system mainly includes at least one of the following: a model training functional entity, a model inference functional entity, and a model management functional entity.

[0122] The model training functional entity can also be simply referred to as the training function, or any other possible naming. It is mainly responsible for AI model training and generates an AI model after the training is completed. The model inference functional entity can also be simply referred to as the inference function, or any other possible naming. It is mainly responsible for AI model inference, inputting data into the model to obtain corresponding predicted outputs. The model management functional entity can also be simply referred to as the management function, or any other possible naming. It is mainly responsible for model management, including performance management, update management, deployment management, etc.

[0123] Figure 5 It is a schematic diagram of the application scenario of this communication system, as Figure 5 shown in (a) of. For the service-oriented architecture, the management service (MnS) producer can provide management services externally. The management service consumer can call the management service. The management service producer can have the AI / ML model training functional entity and the inference function. That is, the model training functional entity and the model inference functional entity can be deployed in the management service producer, or in other words, corresponding to the management service producer. The model management functional entity can be deployed in the management service consumer, or in other words, corresponding to the management service consumer.

[0124] As Figure 5 shown in (b) of. Taking the management domain and the business domain as examples, the network management system (NMS) and the element management system (EMS) both belong to the devices in the management domain. The NMS is mainly responsible for the operation, management, and maintenance functions of the network. For example, it manages the EMS and can be called a cross-domain management system. The EMS is mainly used to manage one or more network elements of a certain category. For example, it manages the network elements in the business domain, such as AN network elements (such as RAN devices) or CN network elements, and can also be called a domain management system or a single-domain management system. The NMS / EMS can be traditional cross-domain / single-domain network management devices, or, they can also be a partial management function set of cross-domain management / single-domain management. Or, the NMS and the EMS can also be collectively referred to as the 3GPP management system, or the Operations Administration and Maintenance (OAM) module.

[0125] The model management functional entity can be deployed in the NMS / EMS. The model training functional entity is deployed in the EMS. The model inference functional entity can be correspondingly deployed in the RAN device or the CN network element. Alternatively, both the model training functional entity and the model inference functional entity can be deployed in the RAN device or the CN network element. For example, the model training functional entity is deployed in the mobile intelligent engine (MIF), and the inference function may be deployed in the central unit (CU) or the distributed unit (DU), that is, the model training functional entity and the model inference functional entity are respectively deployed in two modules in the gNB. Alternatively, in the O-RAN standard architecture, a possible deployment solution for the model training functional entity is to deploy it in the O-RAN non real time RAN intelligent controller (Non-RT RIC) or the O-RAN near real time RAN intelligent controller (Near-RT RIC), and a possible deployment solution for the model inference functional entity is to deploy it in the O-RAN central unit (O-CU) or the O-RAN distributed unit (O-DU) in the gNB.

[0126] It can be understood that the EMS, RAN device, and CN network element can also correspond to the Figure 5 management service producers in, and the NMS can also correspond to the Figure 5 management service consumers in.

[0127] Next, in combination with Figures 6 - 8 , the interaction process between each network element / device in the above communication system will be specifically introduced through method embodiments. The model management method provided in the embodiments of the present application can be applied to the above communication system and specifically applied to various scenarios mentioned in the above communication system, which will be specifically introduced below.

[0128] Figure 6 FIG. is a schematic flowchart of the model management method provided in the embodiments of the present application. The model management method is applicable to the above communication system and mainly involves the interaction between the model inference functional entity and the model training functional entity. It can be understood that the method in the embodiments of the present application involves retraining of the model. In the following text, if not specifically stated, "training" mentioned below can be understood as "retraining".

[0129] As Figure 6 shown, the process of the model management method is as follows:

[0130] S601. The model inference functional entity obtains a first communication data set for updating the first machine learning model.

[0131] The machine learning model (denoted as the first machine learning model) can be used to manage wireless communication services, or to ensure wireless communication services. For example, the first machine learning model can be an AI beam management model, or a beam selection model, or it can also be a model for other management scenarios in wireless communication, such as a downlink / uplink data volume prediction model, a channel fading change prediction model, a CSI feedback model, an AI-assisted positioning model, etc., and no specific limitation is made here. The type of the first machine learning model can be DNN, specifically it can be FNN, CNN, or RNN, and of course it can also be other types of models, and the embodiments of this application do not make specific restrictions.

[0132] The first communication data set can be a set of wireless communication data collected and fed back by the terminal. For example, it includes the wireless communication data between the access network device corresponding to the model inference function and multiple terminals, and specifically can include data such as reference signal received power (RSRP), channel state information matrix, channel impulse response, etc., for ensuring the services in the wireless communication process. In addition, the first communication data set can also include labels. The labels can be used to mark the true values of the wireless communication data in the corresponding scenarios, and can be selected according to the actual situation. Taking the RSRP in the AI beam management scenario as an example, other scenarios can be understood by reference and will not be elaborated here. The wireless communication data can include the RSRP and the beam identifier corresponding to the RSRP. The label can be used to mark whether the beam indicated by the beam identifier is the best beam corresponding to the RSRP. For example, the label includes two values of 0 / 1, where 1 indicates that the beam indicated by the beam identifier is the best beam corresponding to the RSRP, and 0 indicates that the beam indicated by the beam identifier is not the best beam corresponding to the RSRP. The first communication data set may contain suspicious data with a loss value greater than the first loss threshold. If the proportion of the suspicious data in the first communication data set exceeds the first proportion threshold, the model inference functional entity can eliminate it. Otherwise, the model inference functional entity can only mark it. Specifically, reference can also be made to the relevant introduction in S602 below and will not be elaborated here.

[0133] The model inference functional entity can be triggered by other devices to obtain the first communication data set. For example, the model training functional entity can send the first indication information to the model inference functional entity. The model inference functional entity receives the first indication information from the model training functional entity, and according to the first indication information, receives wireless communication data from multiple terminals to obtain the first communication data set, so as to achieve on-demand acquisition and avoid redundancy.

[0134] Among them, the first indication information can be used to indicate that the first machine learning model needs to be updated. For example, the first indication information can carry the identifier of the first machine learning model to indicate that the first machine learning model needs to be updated, or the first indication information can have an associated relationship with the identifier of the first machine learning model. When the model inference functional entity receives the first indication information, it knows that the associated first machine learning model needs to be updated. Of course, there can be other implementation manners for the first indication information, which are not limited in the embodiments of the present application. The first indication information can be carried in any possible signaling / message, which is also not limited in the embodiments of the present application. In addition, the first indication information can also indicate other parameters, such as the type of data to be collected, such as whether the beam corresponding to RSRP is the best beam, the location of the terminal, etc., or the amount of data to be collected.

[0135] The model training functional entity can send the first indication information to the model inference functional entity according to the first condition, and the first condition can include at least one of the following: condition A, condition B, or condition C, which are introduced separately below.

[0136] Condition A: It has currently entered the next update cycle of the machine learning model.

[0137] The model training functional entity can dynamically update the machine learning model periodically. The model training functional entity can determine the cycle for updating the machine learning model and determine that it has currently entered the next update cycle of the machine learning model, so as to collect the data required for updating the first machine learning model this time, such as the first communication data set, by sending the first indication information. In addition, the cycle for updating the machine learning model can be obtained by the model training functional entity from the model management functional entity in advance. For specific reference, please refer to the relevant introduction below and will not be elaborated here.

[0138] Condition B: The prediction accuracy of the machine learning model is lower than the accuracy threshold, so it is necessary to update the model to improve the model accuracy.

[0139] Among them, the prediction accuracy of the machine learning model can characterize the performance of the machine learning model, and can also be referred to as the accuracy of the machine learning model. When the prediction accuracy of the machine learning model is lower than the accuracy threshold, it is necessary to update it so that the machine learning model can adapt to the current environment and improve the accuracy. Therefore, the model training functional entity can obtain the prediction accuracy of the first machine learning model from the model inference functional entity. If the prediction accuracy of the first machine learning model is lower than the accuracy threshold, the model training function collects the data required for updating the first machine learning model this time by sending the first indication information. In addition, the accuracy threshold can be obtained by the model training functional entity from the model management functional entity in advance. For specific reference, please refer to the relevant introduction below and will not be elaborated here.

[0140] Condition C: The proportion of suspicious data in the wireless communication data obtained last time for updating the machine learning model is greater than the second proportion threshold, and the remaining time until the end of the machine learning model update is greater than the threshold time.

[0141] The second proportion threshold can also represent the upper limit of the proportion of suspicious data allowed in the communication data set for normal training. If the proportion of suspicious data in the wireless communication data obtained last time for updating the machine learning model is greater than the second proportion threshold, that is, exceeding the upper limit, it means that the sample size of normal data is insufficient to complete the current update of the first machine learning model. Therefore, the model training functional entity can determine the remaining time until the end of the model update in this cycle based on the maximum waiting time for this update and the time already spent on local update. The model training functional entity can estimate whether the time required to re-collect data and update the model is less than or equal to the remaining time. If it is less than or equal to the remaining time, the model training functional entity can collect the data required for updating the first machine learning model this time by sending the first indication information, so as to ensure the effect of this model update by re-obtaining data. Otherwise, if it is greater than the remaining time, the model training functional entity can determine that this update fails. In addition, the maximum waiting time can be obtained by the model training functional entity from the model management functional entity in advance. For specific reference, please refer to the relevant introduction below and will not be elaborated here.

[0142] It can be understood that Condition A and Condition B are applicable not only to the situation where the model inference functional entity marks suspicious data, but also to the situation where the model inference functional entity eliminates suspicious data. For specific reference, please refer to the relevant introduction of S602 below and will not be elaborated here. Condition C can be only applicable to the situation where the model inference functional entity marks suspicious data. In other words, if the model training functional entity knows in advance that the model inference functional entity marks suspicious data, then the model training functional entity can analyze the wireless communication data obtained from the model inference functional entity according to Condition C. For specific reference, please refer to the relevant introduction of S602 below and will not be elaborated here either.

[0143] Optionally, when Condition C is applicable, the model training functional entity can also send a second loss threshold to the model inference functional entity. Correspondingly, the model inference functional entity can receive the second loss threshold from the model training functional entity. Among them, the second loss threshold can be less than the loss threshold pre-configured by the model inference functional entity, such as the first loss threshold, to relax the threshold for the model inference functional entity to define suspicious data and ensure that re-collection can provide more normal data for training. In addition, the second loss threshold can be sent together with the first indication information, such as in the same signaling or message, or can also be sent separately, and this is not limited.

[0144] S602, the model training functional entity sends the second communication data set to the model training functional entity.

[0145] The second communication data set can be obtained by performing a processing operation on the suspicious data in the first communication data set according to the first processing strategy. For example, it also includes the wireless communication data between the access network device and multiple terminals. The first processing strategy can be used to perform a processing operation on the data (such as suspicious data) in the communication data set for updating the machine learning model.

[0146] Suspicious data can be considered as data suspected of poisoning attacks. Specifically, it can be wireless communication data with a loss value less than or equal to a loss threshold (denoted as the first loss threshold). For example, an attacker of a poisoning attack can maliciously change the label of the wireless communication data, resulting in a relatively large loss value during training, which affects model convergence. Therefore, the loss value of the wireless communication data can, to a certain extent, reflect whether the data is data of a poisoning attack. Thus, the wireless communication data with a loss value greater than the loss threshold in the communication data set can be considered as data suspected of poisoning attacks, that is, suspicious data. Conversely, if the loss value of the wireless communication data in the communication data set is less than or equal to the first loss threshold, then the wireless communication data can be considered as normal data, or data that is not a poisoning attack, that is, normal data is also wireless communication data with a loss value less than or equal to the first loss threshold. In addition, how to determine the loss value of the wireless communication data can refer to the relevant introduction below and will not be elaborated here.

[0147] The first loss threshold can be indicated by the first processing strategy. For example, the first processing strategy can explicitly indicate the first loss threshold, such as including the first loss threshold. That is, the first ratio threshold can be dynamically configured along with the first processing strategy to enable dynamic adjustment according to actual needs. Or, the first processing strategy can also implicitly indicate the first loss threshold. For example, the first processing strategy is associated with the first loss threshold management. Obtaining the first processing strategy means that the first loss threshold needs to be used. At this time, the first ratio threshold can also be pre-configured locally in the model inference functional entity to avoid the overhead brought by configuration. The value of the first loss threshold can be a value between 0 and 1, such as 0.4, 0.5, 0.6, etc. The specific value can be selected according to the actual situation and is not limited here.

[0148] Processing operations can be used to mark suspicious data or eliminate suspicious data. For example, processing operations may include a marking operation, which means adding an easily recognizable mark to suspicious data, or tagging, so that it can be identified later which data is suspicious data, avoiding the impact of suspicious data on the retraining of the first machine learning model and ensuring the effect of model retraining. For instance, the sending end adds a corresponding mark to suspicious data, which can be a special cell, character, or field, and the sending end does not add this mark to normal data. The receiving end can determine whether the received wireless communication data is suspicious data or normal data by judging whether the received wireless communication data has this mark. Processing operations can also include an elimination operation, denoted as elimination operation #1. Elimination operation #1 means eliminating suspicious data from the communication data set, such as deleting or releasing, to avoid using suspicious data to retrain the first machine learning model later and ensuring the effect of model retraining.

[0149] The marking operation can be executed when the proportion of suspicious data in the communication data set used to update the machine learning model is greater than or equal to the first proportion threshold. Conversely, elimination operation #1 can be executed when the proportion of suspicious data in the communication data set used to update the machine learning model is less than the first proportion threshold. Among them, the first proportion threshold can represent the upper limit of the proportion of suspicious data allowed for normal training in this communication data set. That is to say, if the proportion of suspicious data in the communication data set is less than or equal to the first proportion threshold, it means that the number of suspicious data is not too large. Even if this part of the suspicious data is eliminated, the sample size of the remaining normal data in this communication data set can still complete the normal training of the machine learning model. Therefore, the model inference functional entity can execute elimination operation #1. Conversely, if the proportion of suspicious data in the communication data set is greater than the first proportion threshold, it means that the proportion of the number of suspicious data is too large. If this part of the suspicious data is rashly and directly eliminated, the sample size of the normal data may not be able to support the normal training of the machine learning model. Therefore, the model inference functional entity can execute the marking operation to let the model training functional entity decide whether to use or eliminate these suspicious data. Of course, the marking operation or elimination operation #1 can also be executed by default, such as executing the marking operation by default, or executing elimination operation #1 by default.

[0150] The first processing strategy can also indicate the processing operation, such as explicitly or implicitly indicating this processing operation. The specific implementation principle can be understood with reference to the above and will not be elaborated here.

[0151] It should be understood that the first processing strategy is an exemplary naming, and it can also be replaced with any possible naming, such as the first trusted processing strategy, or the first training data processing strategy, etc. The embodiments of this application do not make any restrictions.

[0152] In the embodiments of the present application, the model inference functional entity may process the first communication data set through the first machine learning model to determine the suspicious data in the first communication data set. That is to say, the model inference functional entity may use the first machine learning model to perform inference calculations on the first communication data set to determine the suspicious data therein. For example, the model inference functional entity may process the first communication data set according to the first processing strategy using the first machine learning model, obtain the processing results of each wireless communication data in the first communication data set, and determine the loss value of each wireless communication data according to the processing results of each wireless communication data and the label of each wireless communication data, so as to determine the wireless communication data with a loss value greater than the first loss threshold as suspicious data.

[0153] For ease of understanding, still taking the beam management scenario of AI as an example, other scenarios can be understood by reference and will not be elaborated. The processing result of wireless communication data #1 may be the probability that the beam corresponding to RSRP#1 is the best beam, such as 0.8. If the label of RSRP#1 indicates that the beam corresponding to RSRP#1 is the best beam, that is, the label is 1, then the loss value of wireless communication data #1 is 0.2. Similarly, the processing result of wireless communication data #2 may be the probability that the beam corresponding to RSRP#2 is the best beam, such as 0.7. If the label of RSRP#2 indicates that the beam corresponding to RSRP#2 is not the best beam, that is, the label is 0, then the loss value of wireless communication data #2 is 0.7. Assuming that the first loss threshold is 0.4, then wireless communication data #1 is normal data and wireless communication data #2 is suspicious data. That is to say, usually, the processing result of the data should be close to the label of the data. If the difference between the processing result of the data and the label of the data is large, it may be that the poisoning attacker deliberately tampers with the label of the data, such as tampering with the beam corresponding to RSRP#2 being the best beam to the beam corresponding to RSRP#2 not being the best beam to affect the training of the model. Therefore, by setting the first loss threshold, the suspicious data that may be label-tampered can be screened out.

[0154] The model inference functional entity can also determine the proportion of suspicious data in the first communication data set according to the first processing strategy. For example, according to the above introduction to the processing operations, if the model inference functional entity determines that the proportion of suspicious data in the first communication data set is greater than the first proportion threshold, the model inference functional entity can perform a marking operation, such as adding an easily recognizable mark to the suspicious data in the first communication data set, to obtain a second communication data set; if the model inference functional entity determines that the proportion of suspicious data in the first communication data set is less than or equal to the first proportion threshold, the model inference functional entity can perform an elimination operation #1, such as eliminating the suspicious data in the first communication data set, to obtain a second communication data set. Then, the model inference functional entity can send the second communication data set to the model training functional entity, such as sending a signaling / message carrying the second communication data set, which can specifically be an existing signaling / message or a newly defined signaling / message, and there is no limitation on this. Correspondingly, the model training functional entity can obtain the second communication data set, such as receiving the second communication data set from the model inference functional entity.

[0155] Optionally, if the model inference functional entity obtains a second loss threshold from the model training functional entity, the model inference functional entity can use the second loss threshold to replace the first loss threshold and use the second loss threshold to determine the suspicious data in the first communication data set.

[0156] It can be understood that the model training functional entity performing a marking operation or an elimination operation #1 according to the proportion of suspicious data in the communication data set is only an example and is not limited. For example, the model training functional entity can default to performing a marking operation, or can also default to performing an elimination operation #1.

[0157] For the model training functional entity, the model training functional entity can determine whether the second communication data set is obtained by performing an elimination operation #1 or by performing an elimination operation #1. If the second communication data set is obtained by performing an elimination operation #1, such as a communication data set from which suspicious data has been eliminated, the model training functional entity can perform the following S603; otherwise, if the second communication data set is obtained by performing an elimination operation #1, such as a communication data set in which suspicious data has been marked, the model training functional entity can perform the following S604, which will be introduced separately below.

[0158] S603, the model training functional entity updates the first machine learning model according to the second communication data set.

[0159] The model training functional entity can use the second communication data set to train the first machine learning model, and when convergence is reached, determine that the training is over, and obtain an updated machine learning model, denoted as the second machine learning model.

[0160] S604, the model training functional entity updates the first machine learning model according to the third communication data set.

[0161] The third communication data set can be obtained by performing an elimination operation (denoted as elimination operation #2) on the suspicious data or error data in the second communication data set according to the second processing strategy. The second processing strategy can be used to perform the elimination operation #2 on the suspicious data or error data in the communication data set for updating the machine learning model. For example, the second processing strategy can indicate the elimination operation #2, such as explicitly or implicitly indicating the elimination operation #2. The specific implementation principle can also be understood by referring to the above text and will not be elaborated here. The error data can be data for poisoning attacks. Its characteristic can be that if the first machine learning model is updated using the error data, the effect of the updated machine learning model in processing wireless communication data is not good, and its loss value is usually relatively large, such as greater than the third loss threshold.

[0162] The following specifically introduces whether the model training functional entity performs the elimination operation #2 on the suspicious data or the error data.

[0163] Exemplarily, the second processing strategy can also indicate a second condition, such as explicitly or implicitly indicating the second condition. The specific implementation principle can also be understood by referring to the above text and will not be elaborated here. The second condition can refer to that the proportion of suspicious data in the communication data set is less than or equal to the second proportion threshold. In this way, the model training functional entity can determine whether to update the first machine learning model according to the second condition.

[0164] If the proportion of suspicious data in the second communication data set is less than or equal to the second proportion threshold, it means that the number of suspicious data is not too large yet. Even if this part of the suspicious data is eliminated, the sample size of the remaining normal data in the second communication data set can still complete the normal training of the first machine learning model. Therefore, the model inference functional entity can perform the elimination operation #2, such as eliminating the suspicious data in the second communication data set.

[0165] If the proportion of suspicious data in the second communication data set is greater than the second proportion threshold, it means that if this part of the suspicious data is eliminated, the sample size of the remaining normal data in the second communication data set may not be able to complete the normal training of the first machine learning model. Therefore, the model training functional entity can, according to the above first condition, such as condition C, select to re-obtain the wireless communication data for updating the machine learning model, that is, return to execute S601. Or, the model training functional entity can also choose to eliminate the error data from the second communication data set, specifically, it can eliminate the error data in the suspicious data from the second communication data set, which is specifically introduced below.

[0166] For example, the second processing strategy may include a third loss threshold. The model training functional entity may determine which data in the suspicious data are incorrect data based on the third loss threshold. Exemplarily, the model training functional entity divides the suspicious data into M data subsets. M is an integer greater than 1, and its value can be set according to the actual situation, which is not limited herein. The model training functional entity may update the first machine learning model using the i-th data subset among the M data subsets, where i ranges from 1 to M, to obtain the i-th updated machine learning model. The model training functional entity may process the test data using the i-th updated machine learning model, where i ranges from 1 to M, to obtain the i-th test result. Among them, the test data may include wireless communication data pre-configured by the model training functional entity for testing the model training effect. If the loss value of the test data in the i-th test result is greater than the third loss threshold, the model training functional entity determines that the i-th data subset is incorrect data; otherwise, the model training functional entity determines that the i-th data subset is not incorrect data.

[0167] That is to say, since the role of the data in the poisoning attack is to affect model training, the model training functional entity may use the suspicious data to pre-train the machine learning model so as to determine the suspicious data that has no effect on model training as incorrect data according to the training results. For example, when using normal data to train the machine learning model, since the training will cause the machine learning model to converge, using the updated machine learning model to process the test data, the processing result should be relatively close to the corresponding label, that is, the loss value is small. For example, the processing result is a probability value of 0.9, the label is 1, and the loss value is small at 0.1. If incorrect data is used to train the machine learning model, since the incorrect data will inhibit the convergence of the machine learning model, when using the updated machine learning model to process the test data, the difference between its processing result and the corresponding label will be relatively large. For example, the processing result is a probability value of 0.7, the label is 1, and the loss value is relatively large at 0.3. At this time, if the third loss threshold is set to 0.2, the model training functional entity can distinguish between normal data and incorrect data.

[0168] It should be understood that by dividing suspicious data into multiple data subsets, it is also possible to eliminate erroneous data at the granularity of data subsets. Compared with eliminating all suspicious data, its granularity is finer and normal data can be retained. In addition, since the computing power of the model training functional entity is more powerful than that of the model reasoning functional entity, when the model reasoning functional entity cannot distinguish which data in the suspicious data is normal data and which data is poisoned attack data, the model training functional entity can eliminate the data in the suspicious data that is truly poisoned attack data through a more refined elimination operation, and use the normal data in the suspicious data for model training to improve the utilization efficiency of the training data. Of course, the model training functional entity determining erroneous data from suspicious data is only an example. For example, the model training functional entity can also divide the second communication data set into multiple data subsets and determine erroneous data therefrom.

[0169] After performing elimination operation #2 on suspicious data or erroneous data in the second communication data set, the model training functional entity can use the normal data in the second communication data set to train the first machine learning model, and when convergence is reached, determine the end of training to obtain a second machine learning model.

[0170] It should be understood that the second processing strategy is an exemplary name, which can also be replaced by any possible name, such as a second trusted processing strategy, or a second training data processing strategy, etc., which is not limited in the embodiments of the present application. In addition, the second processing strategy can also indicate the above-mentioned first condition, such as explicitly or implicitly indicating the first condition. The specific implementation principle can also be understood by referring to the above, and will not be repeated here.

[0171] It should also be understood that since the main purpose of poisoning attacks is to affect the training effect of the model and reduce its training accuracy, the main function of the poisoning attack data is to suppress the convergence effect of model training, that is, the loss value of the training model is relatively large. Accordingly, the model training functional entity can also adopt a similar method to the above-mentioned model reasoning functional entity to determine the data in the first communication data set whose loss value is greater than the first loss threshold as erroneous data, such as poisoning attack data, and remove it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.

[0172] In summary, since the main purpose of poisoning attacks is to affect the training effect during the model retraining and updating process, so that its training accuracy is reduced, that is, the loss value of the updated model on the poisoned data is relatively large. Accordingly, the model reasoning function entity can determine the data in the first communication data set whose loss value is greater than the first loss threshold as suspicious data, or data suspected of being poisoned, and process it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.

[0173] In addition, the model training functional entity can also determine the data with a loss value greater than the first loss threshold in the first communication data set as incorrect data, such as data of poisoning attacks, in a similar manner to the above-mentioned model inference functional entity, and eliminate it to avoid adverse effects on the training of the first machine learning model and reduce the data security risk of the AI model in the wireless field.

[0174] Combined with the above method, in the first possible design solution, the method may further include: the model management functional entity can obtain the first processing policy of the first machine learning model and send the first processing policy to the model inference functional entity. Correspondingly, the model inference functional entity can receive the first processing policy from the model management functional entity, that is, the first processing policy can also be dynamically configured by the network element / entity in the management domain to achieve dynamic adjustment according to actual requirements.

[0175] Among them, the model management functional entity can pre-configure or pre-define the first processing policy locally. The model management functional entity can obtain the first processing policy from the local at any possible timing, such as when it is the timing to issue the first processing policy currently, or when the model management functional entity learns that the model inference functional entity currently needs to obtain the first processing policy, such as the first processing policy has not been configured for the model inference functional entity in advance, etc. Then, the model management functional entity can send the first processing policy to the model inference functional entity, such as sending a signaling / message carrying the first processing policy, which can specifically be an existing signaling / message or a newly defined signaling / message, and there is no limitation on this. Correspondingly, the model inference functional entity can obtain the first processing policy by receiving and parsing these signaling / messages.

[0176] Of course, the model inference functional entity can also pre-configure or pre-define the first processing policy locally to avoid the overhead brought by the configuration. The model inference functional entity can obtain the first processing policy from the local at any possible timing, such as when the first communication data set has been obtained currently, so it is necessary to obtain the first processing policy from the local to process the first communication data set, or the model inference functional entity can also periodically obtain the first processing policy from the local.

[0177] Combined with the above method, in the second possible design solution, the method may further include: the model management functional entity can obtain the second processing policy of the first machine learning model and send the second processing policy to the model training functional entity. Correspondingly, the model training functional entity can receive the second processing policy from the model management functional entity.

[0178] Among them, the model management functional entity can pre-configure or pre-define a second processing policy locally. The model management functional entity can obtain the second processing policy from the local at any possible timing, such as when it is the timing for issuing the second processing policy currently, or when the model management functional entity learns that the model training functional entity currently needs to obtain the second processing policy, such as when the second processing policy has not been configured for the model training functional entity in advance, etc. Then, the model management functional entity can send the second processing policy to the model training functional entity, such as sending a signaling / message carrying the second processing policy, which can specifically be an existing signaling / message or a newly defined signaling / message, and there is no restriction on this. Correspondingly, the model training functional entity can obtain the second processing policy by receiving and parsing these signaling / messages.

[0179] Of course, the model training functional entity can also pre-configure or pre-define a second processing policy locally. The model training functional entity can obtain the second processing policy from the local at any possible timing, such as when the second communication data set has been obtained currently, so it is necessary to obtain the second processing policy from the local to process the second communication data set, or the model inference functional entity can also periodically obtain the second processing policy from the local.

[0180] Combined with the above method, in the third possible design solution, after S603 or S604, the method can further include: the model training functional entity sends second indication information to the model inference functional entity. Correspondingly, the model inference functional entity receives the second indication information from the model training functional entity and, according to the second indication information, obtains a second machine learning model. Among them, the second indication information can be used to indicate the second machine learning model, such as carrying the identifier and address information of the second machine learning model. The second machine learning model is obtained by updating the first machine learning model, thus realizing the update of the machine learning model and avoiding the impact on the actual business due to the reduction of the model accuracy.

[0181] The above combination Figure 6 has introduced the overall process of the model management method provided by the embodiments of the present application. The following combination Figures 7 - 8 will detail the specific processes of the model management method provided by the embodiments of the present application in various scenarios.

[0182] Scenario 1:

[0183] Figure 7 is a flowchart illustration of the model management method provided by the embodiments of the present application Figure 2 . Exemplarily, the model management method is mainly applicable to the communication between the model inference functional entity, the model training functional entity, and the model management functional entity. Among them, the model management functional entity can be deployed in the EMS / NMS, and the model training functional entity and the model inference functional entity can be deployed to access network devices, such as gNB.

[0184] Specifically, as Figure 7 shown, the process of the model management method is as follows:

[0185] S701, the model management functional entity sends a first processing policy to the model inference functional entity.

[0186] The first processing policy may include at least one of the following: the identifier of the machine learning model, or the first loss threshold. Among them, the identifier of the machine learning model is the unique identifier of the model, used to distinguish different machine learning models, and after the machine learning model is updated, the identifier of the machine learning model before the update can be reused. That is, the above-mentioned first machine learning model and the second machine learning model can share the same identifier of the machine learning model. In addition, the specific implementation of the first loss threshold can also refer to the relevant introduction of the method shown above Figure 6 and will not be elaborated here.

[0187] S702, the model management functional entity sends a second processing policy to the model training functional entity.

[0188] The second processing policy may include at least one of the following: the identifier of the machine learning model, the first condition, the second condition, or the second ratio threshold. The specific implementation can also refer to the relevant introduction of the method shown above Figure 6 and will not be elaborated here.

[0189] Optionally, the second processing policy may also include at least one of the following: update period, update threshold, accuracy threshold, or maximum waiting duration. Among them, the update period can indicate how often the machine learning model needs to be retrained and updated to prevent the impact of model drift on the prediction accuracy and ensure that the model always has a high prediction accuracy. The update threshold is the threshold that the performance of the machine learning model update needs to reach, and the update action of the model is implemented only when the performance of the retrained model meets the update threshold. In one implementation, the update threshold may indicate the minimum value of the performance of the machine learning model obtained by retraining, that is, the update action is implemented only when the performance of the retrained model exceeds the update threshold; in another implementation, the update threshold may indicate the minimum value of the model performance gain, that is, the update action is implemented only when the difference between the performance of the retrained model and the performance of the model before training exceeds the update threshold. The accuracy threshold can indicate the lowest level of the prediction accuracy that the retrained model needs to reach, and the model with a prediction accuracy lower than this accuracy threshold is considered not to be trained yet and needs to continue the training operation. The maximum waiting duration can be the maximum duration required for a model update. If the update has not been completed after this time, the update needs to be paused.

[0190] S703, the model training functional entity sends a first indication message to the model inference functional entity.

[0191] Among them, the model training functional entity can send the first indication information to the model inference functional entity according to condition A or condition B in the first condition. For the specific implementation, reference can also be made to the relevant introduction above, which will not be elaborated here.

[0192] S704. The model inference functional entity obtains the second communication data set.

[0193] The model inference functional entity can, according to the first indication information, obtain the first communication data set from multiple terminals, and perform a marking operation on the suspicious data in the first communication data set whose loss value is greater than the first loss threshold according to the first processing strategy, so as to obtain the second communication data set.

[0194] In addition, for the specific implementation of S704, reference can also be made to the relevant introduction of S602 above, which will not be elaborated here.

[0195] S705. The model inference functional entity sends the second communication data set to the model training functional entity.

[0196] S706. The model training functional entity performs an elimination operation on the suspicious data in the second communication data set.

[0197] The model training functional entity can, according to the second processing strategy, such as the second condition, determine that the proportion of the suspicious data in the second communication data set is less than the second proportion threshold, so as to perform an elimination operation on the suspicious data in the second communication data set.

[0198] S707. The model training functional entity sends the first indication information to the model inference functional entity.

[0199] Among them, the model training functional entity can send the first indication information to the model inference functional entity according to condition C in the first condition. For the specific implementation, reference can also be made to the relevant introduction above, which will not be elaborated here.

[0200] S708. The model training functional entity sends the second loss threshold to the model inference functional entity.

[0201] The second loss threshold can be sent together with the first indication information in S707, or can also be sent separately.

[0202] It can be understood that S708 is an optional step. The model training functional entity can also not send the second loss threshold, and the model inference functional entity continues to use the previously configured first loss threshold to determine the suspicious data.

[0203] In addition, in the case where S707 is executed, the process of this method returns to execute S704 again.

[0204] S709. The model training functional entity trains the first machine learning model using the normal data in the second communication data set to obtain the second machine learning model.

[0205] S710. The model training functional entity sends the second indication information to the model inference functional entity.

[0206] Among them, the second indication information can be used to indicate the second machine learning model. For the specific implementation, reference can also be made to the relevant introduction of the above method, which will not be elaborated here.

[0207] S711. The model training functional entity sends the third indication information to the model management functional entity.

[0208] Among them, the third indication information can be used to report the successful model update, and can specifically include at least one of the following: the identifier of the second machine learning model, the model version, and the update time. Among them, the model version can indicate the updated model, such as the version of the second machine learning model, and the update time can indicate the time when the model update occurs or is completed.

[0209] Scenario 2:

[0210] Figure 8 It is a schematic flow of the model management method provided by the embodiments of this application. Figure 3 . Exemplarily, this model management method is mainly applicable to the communication between the model inference functional entity, the model training functional entity, and the model management functional entity. Among them, both the model management functional entity and the model training functional entity can be deployed in the EMS / NMS, but their deployments can be decoupled. For example, the model training functional entity can be separately deployed in the AI training function module in the EMS / NMS. The model inference functional entity can be deployed to the access network device, such as the gNB.

[0211] Specifically, as Figure 8 shown, the flow of this model management method is as follows:

[0212] S801. The model management functional entity sends the first processing policy to the model inference functional entity.

[0213] The first processing policy can include at least one of the following: the identifier of the machine learning model, the first loss threshold, or the first ratio threshold. For the specific implementation, reference can also be made to the relevant introduction of the method Figure 6 shown above, which will not be elaborated here.

[0214] S802. The model management functional entity sends the second processing policy to the model training functional entity.

[0215] The second processing strategy may include at least one of the following: an identifier of a machine learning model, a first condition, a second condition, a third loss threshold, or a second ratio threshold. The specific implementation may also refer to the above Figure 6 The related introduction of the method shown will not be repeated here.

[0216] Optionally, the second processing strategy may also include at least one of the following: an update cycle, an update threshold, an accuracy threshold, or a maximum waiting time. For specific implementation, reference may also be made to the relevant introduction of S702 above, which will not be described in detail here.

[0217] S803: The model training functional entity sends first indication information to the model reasoning functional entity.

[0218] Among them, the model training functional entity can send the first indication information to the model reasoning functional entity according to condition A or condition B in the first condition. The specific implementation can also refer to the above-mentioned related introduction, which will not be repeated here.

[0219] S804, the model training function entity obtains a second communication data set.

[0220] The model training function entity may obtain a first communication data set from multiple terminals according to the first indication information. At this time, the model training function entity may determine the proportion of suspicious data in the first communication data set according to the first processing strategy. If the proportion of suspicious data is less than or equal to the first ratio threshold, the model training function entity may remove the suspicious data in the first communication data set to obtain a second communication data set; if the proportion of suspicious data is greater than the first ratio threshold, the model training function entity may mark the suspicious data in the first communication data set to obtain a second communication data set.

[0221] In addition, the specific implementation of S704 can also refer to the relevant introduction of S602 above, which will not be repeated here.

[0222] S805: The model training functional entity sends a second communication data set to the model training functional entity.

[0223] It can be understood that if the second communication data set is a communication data set from which suspicious data has been removed, the model training function entity executes S806, otherwise, if the second communication data set is a communication data set from which suspicious data has been marked, the model training function entity executes S807-S808.

[0224] S806, the model training functional entity uses the second communication data set to train the first machine learning model to obtain a second machine learning model.

[0225] The specific implementation of S806 can also refer to the relevant introduction of S603 above, which will not be repeated here.

[0226] S807, the model training functional entity performs an elimination operation on the error data in the second communication data set to obtain a third communication data set.

[0227] S808, the model training functional entity uses the third communication data set to train the first machine learning model to obtain a second machine learning model.

[0228] For the specific implementation of S807 - S808, reference can also be made to the relevant introduction of S604 above, which will not be elaborated here.

[0229] S809, the model training functional entity sends second indication information to the model inference functional entity.

[0230] The second indication information can be used to indicate the second machine learning model. For the specific implementation, reference can also be made to the relevant introduction of the above method, which will not be elaborated here.

[0231] S810, the model training functional entity sends third indication information to the model management functional entity.

[0232] For the specific implementation of S810, reference can also be made to the relevant introduction of S711 above, which will not be elaborated here.

[0233] It can be understood that in the above Scenario 2, the model training functional entity and the model management functional entity can also be replaced by those deployed in Non - RT RIC or Near - RT RIC, and the model inference functional entity can also be replaced by O - CU deployed in O - RAN or O - DU of O - RAN.

[0234] The above Figures 6 - 8 has elaborated in detail the model management method provided by the embodiments of this application. The following Figures 9 - 10 will elaborate in detail the communication device for executing the model management method provided by the embodiments of this application.

[0235] Figure 9 is the structural schematic Figure 1 of the communication device provided by the embodiments of this application. Exemplarily, as Figure 9 shown, the communication device 900 includes: a transceiver module 901 and a processing module 902. For the sake of convenience of description, Figure 9 only the main components of this communication device are shown.

[0236] Among them, the transceiver module 901 is used to execute the transceiver function of the method shown above Figures 6 - 8 , and the processing module 902 is used to execute other functions of the method shown above Figures 6 - 8 except for the transceiver function.

[0237] Optionally, the transceiver module 901 may include a sending module ( Figure 9(not shown in the figure) and a receiving module ( Figure 9 (not shown in the figure). Among them, the sending module is used to implement the sending function of the communication device 900, and the receiving module is used to implement the receiving function of the communication device 900.

[0238] Optionally, the communication device 900 may further include a storage module ( Figure 9 (not shown in the figure), and the storage module stores programs or instructions. When the processing module 902 executes the programs or instructions, the communication device 900 can execute the functions in the above Figures 6 - 8 shown method.

[0239] It can be understood that the communication device 900 can be a terminal or a network device, or a chip (system) or other components or assemblies that can be set in a terminal or a network device, or a device including a terminal or a network device. The present application does not limit this.

[0240] In addition, the technical effects of the communication device 900 can refer to the technical effects of the management method of the Figures 6 - 8 shown model, which will not be elaborated here.

[0241] Figure 10 This is a schematic structural diagram of the communication device provided by the embodiment of the present application Figure 2 . Exemplarily, the communication device can be a terminal, or a chip (system) or other components or assemblies that can be set in a terminal. As Figure 10 shown, the communication device 1000 may include a processor 1001. Optionally, the communication device 1000 may further include a memory 1002 and / or a transceiver 1003. Among them, the processor 1001 is coupled to the memory 1002 and the transceiver 1003, and can be connected through a communication bus, for example.

[0242] Next, combined with Figure 10 each component of the communication device 1000 will be specifically introduced:

[0243] Among them, the processor 1001 is the control center of the communication device 1000, and can be a single processor or a collective term for multiple processing elements. For example, the processor 1001 is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or an integrated circuit configured to implement the embodiments of the present application, for example: one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs).

[0244] Optionally, the processor 1001 can execute various functions of the communication device 1000 by running or executing software programs stored in the memory 1002 and calling data stored in the memory 1002, such as executing the Figures 6 - 8 management method of the model shown above.

[0245] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as Figure 10 the CPU0 and CPU1 shown in

[0246] In a specific implementation, as an embodiment, the communication device 1000 may also include multiple processors, such as Figure 10 the processor 1001 and the processor 1004 shown in

[0247] Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0248] Among them, the memory 1002 is used to store the software program for executing the solution of this application and is controlled by the processor 1001 for execution. The specific implementation manner may refer to the above method embodiments and will not be elaborated here. Figure 10 Optionally, the memory 1002 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited thereto. The memory 1002 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through the interface circuit of the communication device 1000 (

[0249] A transceiver 1003 is used for communication with other communication devices. For example, if the communication device 1000 is a terminal, the transceiver 1003 can be used to communicate with a network device or another terminal device. Another example is that if the communication device 1000 is a network device, the transceiver 1003 can be used to communicate with a terminal or another network device.

[0250] Optionally, the transceiver 1003 may include a receiver and a transmitter ( Figure 10 not shown separately in []). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0251] Optionally, the transceiver 1003 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through an interface circuit ( Figure 10 not shown in []) of the communication device 1000. The embodiments of the present application do not make specific limitations on this.

[0252] It can be understood that Figure 10 the structure of the communication device 1000 shown in [] does not constitute a limitation on the communication device. The actual communication device may include more or fewer components than shown in the figure, or combine certain components, or have a different component layout.

[0253] In addition, the technical effects of the communication device 1000 can refer to the technical effects of the method described in the above method embodiments and will not be elaborated here.

[0254] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0255] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0256] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0257] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.

[0258] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0259] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution is prior or subsequent. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0260] Those of ordinary skill in the art will realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0261] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0262] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0263] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0264] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0265] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0266] As described above, the above are only the specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for managing a model, characterized in that, applied to a model inference functional entity, including: obtaining a first communication data set for updating a first machine learning model, where the first machine learning model is used to manage wireless communication services; sending a second communication data set to a model training functional entity, where the second communication data set is obtained by performing a processing operation on suspicious data in the first communication data set according to a first processing strategy, the first processing strategy includes a first loss threshold, and the suspicious data is wireless communication data with a loss value greater than the first loss threshold.

2. The method according to claim 1, characterized in that, the processing operation includes a marking operation, and the marking operation refers to adding an easily recognizable mark to the suspicious data.

3. The method according to claim 2, characterized in that, before performing the marking operation, the method further includes: determining that the proportion of suspicious data in the first communication data set is greater than a first proportion threshold.

4. The method according to claim 1, characterized in that, the processing operation includes an elimination operation, and the elimination operation refers to eliminating the suspicious data from the first communication data set.

5. The method according to claim 4, characterized in that, before performing the elimination operation, the method further includes: determining that the proportion of suspicious data in the first communication data set is less than or equal to a first proportion threshold.

6. The method according to claim 3 or 4, characterized in that, the first processing strategy includes the first proportion threshold.

7. The method according to any one of claims 1-6, characterized in that, the first processing strategy instructs the processing operation.

8. The method according to any one of claims 1-7, characterized in that, the method further includes: receiving the first processing strategy from a model management functional entity.

9. The method according to claim 8, characterized in that, the model inference functional entity is deployed on the access network device.

10. The method according to claim 8 or 9, characterized in that, the model inference functional entity is deployed on an Open Central Unit O-CU or an Open Distribution Unit O-DU of the access network device.

11. The method according to any one of claims 1-10, characterized in that, after sending the second communication data set to the model training functional entity, the method further includes: receiving second indication information from the model training functional entity; wherein, the second indication information is used to indicate a second machine learning model, and the second machine learning model is obtained by updating the first machine learning model; obtaining the second machine learning model according to the second indication information.

12. A method for managing a model, characterized in that, applied to a model training functional entity, including: obtaining a second communication data set for updating a first machine learning model, where the first machine learning model is used to manage wireless communication services; Update the first machine learning model according to the third communication data set, where the third communication data set is obtained by performing an elimination operation on the error data in the second communication data set according to a second processing strategy, and the second processing strategy includes a third loss threshold. If the error data is used to update the first machine learning model, the loss value of the updated machine learning model for processing wireless communication data is greater than the third loss threshold.

13. The method according to claim 12, wherein, the elimination operation refers to eliminating the error data from the second communication data set.

14. The method according to claim 13, wherein, the elimination operation specifically refers to eliminating the error data in the data marked as suspicious from the second communication data set, and the data marked as suspicious is wireless communication data in the second communication data set with a loss value greater than the loss threshold.

15. The method according to any one of claims 12-14, wherein, the second processing strategy instructs the elimination operation.

16. The method according to any one of claims 12-15, wherein, the method further includes: receiving the second processing strategy from the model management functional entity.

17. The method according to any one of claims 12-16, wherein, before obtaining the second communication data set for updating the first machine learning model, the method further includes: sending first indication information to the model inference functional entity, where the first indication information is used to indicate that the first machine learning model needs to be updated; The obtaining of the second communication data set for updating the first machine learning model includes: receiving the second communication data set from the model inference functional entity.

18. The method according to claim 17, wherein, the sending of the first indication information to the model inference functional entity includes; sending the first indication information to the model inference functional entity according to a first condition, where the first condition includes at least one of the following: currently entering the next update cycle of the machine learning model, the prediction accuracy of the machine learning model being lower than the accuracy threshold, or the proportion of suspicious data in the wireless communication data obtained last time for updating the machine learning model being greater than the second ratio threshold, and the remaining time until the end of the machine learning model update is greater than the threshold duration; the threshold duration is the sum of the time required to obtain the wireless communication data for updating the machine learning model and the time required to update the machine learning model.

19. The method according to claim 18, wherein, the method further includes: sending a second loss threshold to the model inference functional entity.

20. The method according to claim 18 or 19, wherein, the second processing strategy also instructs the first condition.

21. The method according to any one of claims 18-20, wherein, before updating the first machine learning model according to the third communication data set, the method further includes: Determine to update the first machine learning model according to a second condition, where the second condition means that the proportion of suspicious data in the communication data set is less than or equal to the second proportional threshold.

22. The method according to claim 21, wherein, the second processing policy further indicates the second condition.

23. The method according to any one of claims 18-22, wherein, the second processing policy includes the second proportional threshold.

24. The method according to any one of claims 12-23, wherein, after updating the first machine learning model according to the third communication data set, the method further includes: sending second indication information to the model inference functional entity; wherein the second indication information is used to indicate a second machine learning model, and the second machine learning model is obtained by updating the first machine learning model.

25. The method according to any one of claims 12-24, wherein, the model training functional entity is deployed on an access network device, and the second communication data set includes wireless communication data between the access network device and multiple terminals.

26. A method for managing a model, wherein, applied to a model management functional entity, includes: obtaining a first processing policy of a first machine learning model, where the first machine learning model is used to manage wireless communication services, the first machine learning model is deployed on a model inference functional entity, the first processing policy includes a first loss threshold, and the first processing policy can be used to perform a processing operation on suspicious data in a communication data set for updating the machine learning model, and the suspicious data is data with a loss value greater than the first loss threshold; sending the first processing policy to the model inference functional entity.

27. The method according to claim 26, wherein, the method further includes; obtaining a second processing policy of the first machine learning model, where the second processing policy can be used to perform an elimination operation on error data in a communication data set for updating the machine learning model, the second processing policy includes a third loss threshold, and if the error data is used to update the machine learning model, the loss value of the updated machine learning model for processing wireless communication data is greater than the third loss threshold; sending the second processing policy to a model training functional entity for updating the first machine learning model.

28. A communication device, wherein, the device includes: a module for executing the method according to any one of claims 1-27.

29. A communication device, wherein, the communication device includes: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device is enabled to execute the method according to any one of claims 1-27.

30. A computer-readable storage medium, wherein, The computer-readable storage medium includes a computer program or instructions, which, when run on a computer, cause the computer to execute the method according to any one of claims 1-27.

Citation Information

Cited By

  • Model management method and apparatus

    EP4797760A1

  • Model management method and apparatus

    WO2025113079A1