User device data privacy protection during machine learning model training

By defining and applying privacy levels in 5G communication networks and utilizing differential privacy mechanisms to protect user equipment data, the privacy protection issue during machine learning model training is resolved, and the security and compliance of data exchange are achieved.

CN121925656APending Publication Date: 2026-04-24NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2024-09-24
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In 5G communication networks, protecting the privacy of user device data during machine learning model training faces challenges, especially the risk of privacy leaks during data exchange.

Method used

By defining and applying selected privacy levels between user equipment and communication network entities, differential privacy mechanisms are used to protect user equipment data during machine learning model training, including the application and mapping of privacy parameters on both the user equipment and network sides.

Benefits of technology

It effectively protects user device data privacy, reduces the risk of privacy leaks, complies with data privacy regulations, and improves the security and reliability of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121925656A_ABST
    Figure CN121925656A_ABST
Patent Text Reader

Abstract

The invention relates to user device data privacy protection during machine learning model training. Techniques are disclosed for protecting privacy for user equipment during machine learning model training in a communication network environment. In one example, from the perspective of a user device, a method includes sending a selected privacy level from the user device to a communication network with which the communication network is participating in a machine learning model training process. The method also includes receiving, at the user device, one or more privacy parameters corresponding to the selected privacy level. The method further includes applying, by the user equipment, one or more privacy parameters to data to be sent to the communication network. In addition to the technical scheme of the user equipment side, the invention also provides a technical scheme of the communication network side, which is used for protecting the privacy of the data of the user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This field generally relates to communication networks, and more specifically, but not excluding, to security management in such communication networks. Background Technology

[0002] This section provides information that can help to better understand aspects of the invention. Therefore, the statements in this section should be read in this light and should not be construed as an admission of what is present in the prior art or what is not present in the prior art.

[0003] Fourth-generation (4G) wireless mobile telecommunications technology (also known as Long Term Evolution (LTE) technology) is designed to provide high-capacity mobile multimedia with high data rates, particularly for human interaction. Next-generation or fifth-generation (5G) technology is designed not only for human interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.

[0004] While 5G networks are designed to enable large-scale IoT services (e.g., a very large number of limited-capacity devices) and mission-critical IoT services (e.g., requiring high reliability), they also support improvements to traditional mobile communication services in the form of enhanced mobile broadband (eMBB) services, thereby providing improved wireless internet access for mobile devices.

[0005] In the example communication system, user equipment such as a mobile terminal (subscriber) (5G UE in a 5G network, or more broadly, UE) communicates via an air interface with a base station or access point of the access network (referred to as 5G AN) in the 5G network. An access point (e.g., gNB) is illustratively part of the access network of the communication system.

[0006] For example, in 5G networks, the access network referred to as 5G AN is described in 5G Technical Specification (TS) 23.501 entitled "Technical Specification Group Services and System Aspects; System Architecture for 5G Systems" and TS 23.502 entitled "Technical Specification Group Services and System Aspects; Procedures for 5G Systems (5GS)," the disclosures of which are incorporated herein by reference in their entirety. Typically, an access point (e.g., gNB) provides the UE with access to the core network (CN or 5GC), and the core network (CN or 5GC) then provides the UE with access to other UEs and / or data networks (such as packet data networks (e.g., the Internet)).

[0007] TS 23.501 further defines the 5G service-based architecture (SBA), which models services as network functions (NFs) that communicate with each other using a RESTful API for representational state transitions.

[0008] In addition, TS33.501, entitled “Technical Specification Group Services and Systems Aspects; Security Architecture and Procedures for 5G Systems,” the contents of which are incorporated herein by reference in their entirety, also describes security management details associated with 5G networks.

[0009] Security management is a critical consideration in any communications network environment. However, as efforts continue to improve the architecture and protocols associated with 5G networks to enhance network efficiency and / or subscriber convenience, the security management of data exchanged within these environments can present significant challenges. For example, implementing data privacy algorithms in communications network environments is a technical challenge. Summary of the Invention

[0010] The illustrative embodiments provide techniques for protecting the privacy of user equipment data during the training of machine learning models in a communication network environment.

[0011] In one illustrative embodiment, from the perspective of a user equipment, a method includes: sending a selected privacy level from the user equipment to a communication network, the user equipment being involved in a machine learning model training process with the communication network. The method further includes: receiving, at the user equipment, one or more privacy parameters corresponding to the selected privacy level. The method also includes: the user equipment applying the one or more privacy parameters to data to be transmitted to the communication network.

[0012] In another illustrative embodiment, from the perspective of a communication network entity, a method includes: receiving a selected privacy level from a user equipment at the communication network entity, the communication network entity being involved in a machine learning model training process with the user equipment. The method further includes: determining one or more privacy parameters corresponding to the selected privacy level by the communication network entity.

[0013] In yet another illustrative embodiment, from the perspective of a machine learning model training management function, a method includes: at the machine learning model training management function, receiving from a communication network entity one or more privacy parameters corresponding to a selected privacy level associated with a user device participating in the machine learning model training process. The method further includes: at the machine learning model training management function, receiving data from the user device. The method also includes: the machine learning model training management function applying the one or more privacy parameters to the data received from the user device.

[0014] Further illustrative embodiments are provided in the form of a non-transitory computer-readable medium in which executable program code is implemented, which, when executed by a processor, causes the processor to perform the above-described steps and / or other steps, operations, etc. Further illustrative embodiments include means having a processor and memory configured to perform the above-described and / or other steps, operations, etc. Some illustrative embodiments include systems configured to perform the above-described steps and / or other steps, operations, etc. Additionally, some illustrative embodiments include means or systems that include components for performing the above-described steps and / or other steps, operations, etc.

[0015] Advantageously, the illustrative embodiments provide user device data privacy protection techniques during various machine learning model training scenarios where leakage of privacy-sensitive data may occur.

[0016] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the following detailed description. Attached Figure Description

[0017] Figure 1 The illustration depicts a communication network environment in which one or more illustrative embodiments can be implemented.

[0018] Figure 2 The illustrations depict user equipment and entities that can implement one or more illustrative embodiments.

[0019] Figure 3 The illustration depicts a procedure for protecting the privacy of user equipment data during the training of a machine learning model in a communication network environment, according to an illustrative embodiment.

[0020] Figure 4 The illustration depicts a procedure for protecting the privacy of user equipment data during the training of a machine learning model in a communication network environment, according to another illustrative embodiment. Detailed Implementation

[0021] This document will illustrate embodiments in conjunction with example communication systems and related techniques for security management within those systems. However, it should be understood that the scope of the claims is not limited to the specific types of communication systems and / or processes disclosed. Embodiments can be implemented in a variety of other types of communication systems using alternative processes and operations. For example, although illustrated in the context of wireless cellular systems utilizing 3GPP system elements such as 3GPP Next Generation Systems (5G), the disclosed embodiments are directly applicable to a variety of other types of communication systems, such as 6G communication systems.

[0022] According to illustrative embodiments implemented in a 5G communication system environment, one or more 3GPP Technical Specifications (TS) and Technical Reports (TRs) can provide further explanations of network elements / functions and / or operations that can interact with parts of the technical solutions of this invention (e.g., 3GPP TS23.501, TS 23.502, and TS 33.501 referenced above). Other 3GPP TS / TR documents can provide additional details that will be recognized by those skilled in the art, such as 3GPP TS23.288 entitled "Technical Specification Group Services and System Aspects; Architectural Enhancements for 5G Systems (5GS) to Support Network Data Analytics Services," the disclosure of which is incorporated herein by reference in its entirety. Note that 3GPP TS / TR documents are non-limiting examples of communication network standards (e.g., specifications, procedures, reports, requirements, recommendations, etc.). However, while well applicable to 5G-related 3GPP standards, embodiments are not necessarily intended to be limited to any particular standard.

[0023] It should be understood that in some illustrative embodiments, the terms 5G network, etc. (e.g., 5G system, 5G communication system, 5G environment, 5G communication environment, etc.) can be understood to include all or part of the access network and all or part of the core network. However, the terms 5G network, etc. may sometimes be used interchangeably with the terms 5GC network, etc., without loss of generality, as those skilled in the art will understand any distinction.

[0024] Before describing the illustrative embodiments, the following will be... Figure 1 and Figure 2 A general description of some of the key components of a 5G network within the context of [the context].

[0025] Figure 1 A communication system 100 in which illustrative embodiments are implemented is shown. It should be understood that the elements shown in the communication system 100 are intended to represent some of the main functions provided within the system (e.g., control plane functions, user plane functions, etc.). Therefore, Figure 1 The boxes shown refer to specific elements in a 5G network that provide some of these key functions. However, other network elements can be used to implement some or all of the key functions represented. Additionally, it should be understood that... Figure 1 Not all the functions of a 5G network are depicted. Instead, at least some functions are shown to aid in the explanation of illustrative embodiments. Subsequent figures may depict additional elements / functions (i.e., network entities).

[0026] Therefore, as shown, the communication system 100 includes a user equipment (UE) 102 communicating with an access point 104 via an air interface 103. It should be understood that the UE 102 can communicate with the 5GC network via one or more other types of access points besides a gNB (e.g., access functions, networks, etc.). By way of example only, the access point 104 can be any 5G access network (gNB), an untrusted non-3GPP access network using non-3GPP interoperability functions (N3IWF), a trusted non-3GPP network using trusted non-3GPP gateway functions (TNGF), or a wired access using wired access gateway functions (W-AGF), or it can correspond to a traditional access point (e.g., an eNB). Furthermore, as will be further explained in the illustrative embodiments described herein, the access point 104 can be a wireless local area network (WLAN) access point.

[0027] UE 102 may be a mobile station, and such a mobile station may include, for example, a mobile phone, a computer, an IoT device, or any other type of communication device. Therefore, the term "user equipment" as used herein is intended to be interpreted broadly to encompass various types of mobile stations, subscriber stations, or more generally, communication devices, including combinations such as data cards inserted into laptops or other devices such as smartphones. Such communication devices are also intended to encompass devices commonly referred to as access terminals.

[0028] In one illustrative embodiment, UE 102 comprises a Universal Integrated Circuit Card (UICC) portion and a Mobile Equipment (ME) portion. The UICC is the user-related portion of the UE and includes at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores a persistent subscription identifier and its associated key, which are used to uniquely identify and authenticate subscribers seeking network access. The ME is the user-independent portion of the UE and includes Terminal Equipment (TE) functionality and various Mobile Terminal (MT) functions. Alternative illustrative embodiments may not use UICC-based authentication (e.g., a Non-Public (NPN) network).

[0029] Note that in one example, the Permanent Subscription Identifier (IMSI) is a unique International Mobile Subscriber Identity (IMSI) for the UE. In one embodiment, the IMSI is a fixed 15-bit length and consists of a 3-digit Mobile Country Code (MCC), a 3-digit Mobile Network Code (MNC), and a 9-digit Mobile Station Identifier Number (MSIN). In 5G communication systems, the IMSI is referred to as the Permanent Subscription Identifier (SUPI). When the IMSI is used as the SUPI, the MSIN provides the subscriber identity. Therefore, typically only the MSIN portion of the IMSI needs to be encrypted. The MNC and MCC portions of the IMSI provide routing information used by the serving network to route to the correct home network. When the MSIN of the SUPI is encrypted, it is called the Subscription Hidden Identifier (SUCI). Another example of the SUPI uses the Network Access Identifier (NAI). NAIs are commonly used in IoT communications.

[0030] Access point 104 is illustratively part of the radio access network or RAN of communication system 100. Such a radio access network may include, for example, a 5G system with multiple base stations. More generally, components of the radio access network may be considered as “radio access entities”.

[0031] Furthermore, the access point 104 in this illustrative embodiment is operatively coupled to the Access and Mobility Management Function (AMF / SEAF) 106. In 5G networks, AMF / SEAF particularly supports Mobility Management (MM) and Security Anchor Point (SEAF) functions.

[0032] The AMF / SEAF 106 in this illustrative embodiment is operatively coupled to other network functions 108 (e.g., services using other network functions 108). As shown, some of these other network functions 108 include, but are not limited to, the Authentication Server Function (AUSF), Unified Data Management (UDM) function, Application Function (AF), and Network Data Analysis Function (NWDAF). These listed examples of network functions are typically implemented in the UE subscriber's home network, as explained further below. Note that in a 5GC network, the 4G functionality of the HSS (Home Subscriber Server) is split into AUSF, UDM, and Unified Data Repository (UDR, not explicitly shown) functions. Typically, AUSF authenticates the UE and provides any necessary encryption keys, while UDR stores user data and UDM manages user data. AF opens the application layer for interaction with 5G NFs and network resources. NWDAF is a 5G network function that collects data from various 5GC network functions, application functions, and operation, management, and maintenance (OAM) systems and operation support systems. NWDAF is configured to facilitate the production and consumption of 5GC data, as well as the generation of analytical insights and the taking of actions based on those insights. It is also recognized that third-party applications are enabled to operate in conjunction with one or more network functions within 5GC.

[0033] Other network functions 108 may include network functions that can act as service producers (NFp) and / or service consumers (NFc). Note that any network function can be a service producer for one service and a service consumer for another service. Furthermore, when the service being provided includes data, the data-providing NFp is referred to as a data producer, and the data-requesting NFc is referred to as a data consumer. A data producer can also be an NF that generates data by modifying or otherwise processing data generated by another NF. Note that an NF can be more generally considered as a "network entity".

[0034] Note that a UE (such as UE 102) typically subscribes to a network known as the Home Public Land Mobile Network (HPLMN), where some or all of functions 106 and 108 reside. Alternatively, the UE (such as UE 102) can receive services from an NPN where these functions can reside. The HPLMN is also known as the Home Environment (HE). If the UE is roaming (not in the HPLMMN), it typically connects to a Visited Public Land Mobile Network (VPLMN), also known as the Visited Network, and the network currently serving the UE is also known as the Serving Network. In roaming scenarios, some of functions 106 and 108 may reside in the VPLMN, in which case the functions in the VPLMN communicate with the functions in the HPLMMN as needed. However, in non-roaming scenarios, access and mobility management function 106 and other network functions 108 reside in the same communication network (i.e., the HPLMMN). Unless otherwise specified, the embodiments described herein are not necessarily limited to which functions reside in which PLMN (i.e., HPLMN or VPLMN).

[0035] Access point 104 is also operatively coupled (via one or more of functions 106 and / or 108) to session management function (SMF) 110, which is operatively coupled to user plane function (UPF) 112. UPF 112 is operatively coupled to a packet data network (e.g., Internet 114). Note that the thicker solid line in this figure represents the user plane (UP) of the communication network, compared to the thinner solid line representing the control plane (CP). It should be understood that... Figure 1 The network (e.g., the Internet) 114 in the diagram may additionally or alternatively represent other network infrastructure, including but not limited to cloud computing infrastructure and / or edge computing infrastructure. Other typical operations and functions of such network elements are not described herein, as they are not the focus of this illustrative embodiment and can be found in appropriate 3GPP 5G documentation. Note that the functions illustrated in 106, 108, 110, and 112 are examples of network functions (NFs).

[0036] It should be understood that this particular arrangement of system elements is merely an example, and additional or alternative elements of other types and arrangements may be used to implement the communication system in other embodiments. For example, in other embodiments, the communication system 100 may include other elements / functions not explicitly shown herein.

[0037] therefore, Figure 1 The arrangement shown is merely one example configuration for a wireless cellular system, and many alternative configurations of system components can be used. For example, although in Figure 1The embodiments shown depict only a single element / function, but this is merely for simplicity and clarity of description. The given alternative embodiments may, of course, include a greater number of such system elements, as well as additional or alternative elements of the type typically associated with conventional system implementations.

[0038] It should also be noted that, although Figure 1 While system components are illustrated as single functional blocks, the various subnetworks constituting a 5G network are partitioned into so-called network slices. A network slice (network partition) is a logical network that provides specific network capabilities and characteristics to support a corresponding service type, optionally utilizing Network Function Virtualization (NFV) over a common physical infrastructure. Utilizing NFV, network slices are instantiated based on the needs of a given service (e.g., eMBB service, large-scale IoT service, and mission-critical service). Therefore, a network slice or function is instantiated when an instance of it is created. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices within the underlying physical infrastructure. UE 102 is configured to access one or more of these services via access point 104.

[0039] Figure 2 This is a block diagram illustrating the computational architecture of various participants in a method according to an illustrative embodiment. More specifically, system 200 is shown to include user equipment (UE) 202 and multiple entities 204-1, ..., 204-N. For example, in the illustrative embodiment and referring back to reference... Figure 1 UE 202 may represent UE 102, while entities 204-1, ..., 204-N may represent functions 106 and 108 (i.e., network entities, such as but not limited to AMF, NWDAF, UDM), and access point 104 (i.e., radio access entities, such as but not limited to RAN nodes or gNBs). It should be understood that UE 202 and entities 204-1, ..., 204-N are configured to interact to provide security management and other technologies described herein.

[0040] User equipment 202 includes a processor 212 coupled to memory 216 and interface circuitry 210. The processor 212 of user equipment 202 includes a security management processing module 214, which can be implemented at least partially in the form of software executed by the processor. The security management processing module 214 performs security management as described in conjunction with the following figures and other sections herein. The memory 216 of user equipment 202 includes a security management storage module 218, which stores data generated or otherwise used during security management operations.

[0041] Each entity in the entity set (individually or collectively referred to herein as 204) includes a processor 222 (222-1, ..., 222-N) coupled to memories 226 (226-1, ..., 226-N) and interface circuitry 220 (220-1, ..., 220-n). Each processor 222 of each entity 204 includes a security management processing module 224 (224-1, ..., 224-N), which may be implemented at least partially in the form of software executed by the processor 222. The security management processing module 224 performs security management operations as described in conjunction with the following figures and other sections herein. Each memory 226 of each entity 204 includes a security management storage module 228 (228-1, ..., 228-N) storing data generated or otherwise used during security management operations.

[0042] Processors 212 and 222 may include, for example, microprocessors, such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs), or other types of processing devices, as well as portions or combinations of these elements.

[0043] Memory 216 and 226 can be used to store one or more software programs executed by the respective processors 212 and 222 to implement at least a portion of the functions described herein. For example, software code executed by processors 212 and 222 can be used to implement, in a direct manner, security management operations and other functions as described in conjunction with the following figures and other sections herein.

[0044] One of the given memories in memories 216 and 226 can therefore be considered as an example of a computer program product more generally referred to herein or, more generally, a computer or processor-readable (non-transitory or storage) medium in which executable program code is implemented. Other examples of computer or processor-readable media may include, in any combination, magnetic disks or other types of magnetic or optical media. Illustrative embodiments may include articles of manufacture containing such computer program products or other computer or processor-readable media.

[0045] Furthermore, memories 216 and 226 may more specifically include, for example, electronic random access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory, such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM), or ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be interpreted broadly and may additionally or alternatively include, for example, read-only memory (ROM), disk-based memory, or other types of storage devices, and portions or combinations thereof.

[0046] Interface circuit systems 210 and 220 illustratively include transceivers or other communication hardware or firmware that allow associated system elements to communicate with each other in the manner described herein.

[0047] from Figure 2 As can be clearly seen, user equipment 202 and multiple entities 204, as security management participants, are configured to communicate with each other via their respective interface circuit systems 210 and 220. This communication involves each participant sending data to one or more of the other participants and / or receiving data from one or more of the other participants. The term "data" as used herein is intended to be interpreted broadly to cover any type of information that can be sent between participants, including but not limited to identity data, key pairs, key indicators, tokens, secrets, security management messages, registration request / response messages and data, request / response messages, authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.

[0048] It should be understood that Figure 2 The specific arrangement of components shown is merely an example, and various alternative configurations may be used in other embodiments. For example, any given network element / function and / or access point may be configured to incorporate additional or alternative components and support other communication protocols.

[0049] Other system components (such as access point 104, SMF 110, and UPF 112) can each be configured to include components such as processors, memory, and network interfaces. Furthermore, entities (such as third-party applications and network operators) can participate in the methods described herein via computing devices configured to include components such as processors, memory, and network interfaces. These components and devices do not need to be implemented on separate, independent processing platforms, but can, for example, represent different functional portions of a single, common processing platform.

[0050] More generally, Figure 2 This can be considered as representing a processing device configured to provide appropriate security management functions and operatively coupled to each other in a communication system. By way of example only, all or part of each of the UE 202 and the plurality of entities 204 (e.g., processor and memory) can be considered as examples of components for performing one or more operations, one or more steps, one or more functions, one or more processes, etc., as described herein.

[0051] As mentioned above, 3GPP TS 23.501 defines the 5GC network architecture as service-based, for example, service-based architecture (SBA). It is recognized in this document that when deploying different NFs, there may be many situations where an NF may need to interact with entities outside the SBA-based 5GC network (e.g., including (multiple) corresponding PLMNs, such as HPLMN and VPLMN). Therefore, as used herein, the term "internal" illustratively refers to operations and / or communications within the SBA-based 5GC network (e.g., SBA-based interfaces), while the term "external" illustratively refers to operations and / or communications outside the SBA-based 5GC network (non-SBA interfaces).

[0052] Given the above general description of some characteristics of 5GC networks, the problems of existing security methods for protecting the privacy of UE data during the training of machine learning (ML) models in a communication network environment will now be described below, along with technical solutions proposed according to illustrative embodiments.

[0053] While not limited to this, communication network environments can employ data privacy mechanisms such as differential privacy. Differential privacy provides guarantees of privacy for exchanged data at the cost of reducing the precision of the utility function required for the data. Randomizing the function of the data (function perturbation), purely randomizing the original data (input perturbation), or randomizing the output of the function (output perturbation) are widely used differential privacy mechanisms. This paper recognizes that differential privacy mechanisms can be improved if it is known which function to compute. In other words, this paper recognizes that knowledge of the function can improve both utility and privacy.

[0054] Differential privacy was initially proposed to provide a formal guarantee of privacy when commonly used anonymization techniques (such as k-anonymity and l-diversity) were insufficient. Differential privacy is a statistical property that ensures the privacy of individuals within a dataset remains protected once an algorithm or data is protected with differential privacy, regardless of how the output of the algorithm or data is further processed. The initial motivation for proposing this strict definition of privacy stemmed from the observation that combining data from different sources can compromise privacy. For example, the U.S. Census Bureau has adopted differential privacy for privacy protection, and several major customer data-driven companies use it. Differential privacy can also help comply with data privacy regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

[0055] Differential privacy guarantees a mathematical upper bound on the risk of leaking information about individuals and allows users to quantify the precise level of acceptable personal-level risk. Differential privacy is described using probability theory and is mathematically defined as follows. Assume two datasets... X and YThey are adjacent if one dataset is obtained by replacing a single data entry in another dataset. Let... ε >0 and δ Î [0, 1]( ε and δ (This is the differential privacy parameter). The randomization function is: for( ε , δ -DP (where DP stands for differential privacy), or if for each pair of adjacent datasets X and Y And for each result We have:

[0056] parameter δ This can be interpreted as the probability of complete data corruption, and ε The smaller the value, the less likely it is to distinguish whether the output originates from the dataset. X ,still Y That is, the less likely it is to notice the presence of any individual, the better the mechanism protects privacy.

[0057] In some mechanisms of differential privacy, the number of dataset entries and the need to provide certain levels ( ε , δ There exists a fundamental relationship between the noise variance of data points and the data size. This relationship introduces the concept of the small data size problem, where the more data there is, the less noise is needed to protect individual privacy. This problem arises in a federated learning setting where N sites (each with D data points) publish their datasets as a function. If each user adds noise proportional to the size of their own dataset to protect their privacy, the noise variance of the final aggregated dataset on the network side will be significantly greater than that of all Σ data points. n D n =ND are all at a central point and ( ε , δ The case of DP is N times larger. Some techniques have been developed to collect this data without compromising the privacy and security of the dataset; however, most of them either assume a trusted third party or they use homomorphic encryption, which is very computationally expensive.

[0058] Furthermore, this paper recognizes the benefits of using differential privacy in wireless networks. For example, differential privacy can be used to protect the signaling required for communication between UEs participating in the NWDAF and third-party artificial intelligence / machine learning (AI / ML) engines or neural network model trainers. More specifically, model training via the NWDAF Model Training Logic Function (MTLF) has been described in TS 23.288 cited above. Moreover, proposals for cross-domain machine learning exist, in which the UE and RAN and / or the UE and 5G core collaboratively train ML models. Therefore, it can be recognized that such cross-domain ML proposals have a direct impact on UE data privacy for both training data sharing and model training. More specifically, there are recognized privacy breaches during the ML model training process.

[0059] The illustrative embodiments address the above and other technical challenges and / or deficiencies in existing UE data privacy methods in communication network environments by providing UE privacy protection techniques during various ML model training scenarios where leakage of privacy-sensitive data may occur.

[0060] Examples of some scenarios in which illustrative embodiments can be implemented will now be described. However, it should be understood that the UE data privacy protection techniques described herein are not limited to these example scenarios and can be appropriately applied to other scenarios.

[0061] For example, in the first scenario, suppose the UE uses its privacy-sensitive data to train an ML model and provides the trained ML model to a RAN node (e.g., gNB) or 5G core, and a malicious or curious entity may attempt to reconstruct the training data that the UE used during model training.

[0062] In the second scenario, assume the UE partially trains the ML model (in the case of joint ML training between the UE and the 5G core network) and only sends the model parameters to the communication network. Even so, the 5G core network can use the received model parameters to discover training data already used by the UE with a certain probability. This also applies to federated learning.

[0063] In the third scenario, the UE sends the raw training data to be used for model training to the RAN node (e.g., gNB) or the 5G core network.

[0064] The illustrative embodiments utilize the following various technical solutions to address the above scenarios and other privacy issues: (i) network-side technical solutions, wherein privacy mechanisms are applied at the communication network; and (ii) UE-side technical solutions, wherein privacy mechanisms are applied at the UE itself.

[0065] If in Figure 3As further illustrated in the context, in the network-side technical solution, the UE first defines its required privacy level. The privacy level can be alternatively or additionally set by the network operator based on regulatory requirements or categories trained on ML models. The network then translates this privacy requirement into the actual privacy configuration parameters required by the implemented privacy mechanism. For example, as explained above, if the system uses differential privacy as a mechanism, the privacy level is translated into the corresponding value. ε and δ Once the privacy value is defined, it is pushed to the 5G core ML training management NF and / or the RAN node that performs model training, so that when privacy-sensitive data of the UE is received, the RAN node / 5G core applies the privacy configuration before initiating the model training process.

[0066] If in Figure 4 As further illustrated in the context, in the UE-side technical solution, these privacy configurations are pushed directly to the UE by the 5G core network, and privacy applications occur on the UE side itself before sending data or ML models to the 5G core network.

[0067] Figure 3 The illustration depicts a procedure 300 for protecting the privacy of user equipment data during the training of a machine learning model in a communication network environment, according to an illustrative embodiment. More specifically, as shown, procedure 300 (e.g., a network-side technical solution) relates to a UE 302, a RAN node model training management function 304, an AMF 306, a 5G core model training management function (e.g., NWDAF) 308, and a 5G core NF (e.g., a UDM or another NF) 310.

[0068] In step 1, UE 302 sets privacy level requirements (e.g., set to low, medium, or high) when performing initial registration with the 5G core network. In some embodiments, UE 302 may share its privacy level requirements with the 5G core network via one or more methods (e.g., Short Message Service (SMS), subscriber portal, subscriber care call, etc.).

[0069] In step 2, the 5G core network (e.g., 5G core NF 310) sends a confirmation message to UE 302 that it has received the privacy level requirements.

[0070] In step 3, the 5G core network internally maps the privacy level requirements for UE 302 to technical privacy parameters. More specifically, the 5G core network (such as UDM or another NF's 5G core NF 310) maps the nominal privacy level (e.g., low, medium, high) to the technical privacy level (e.g., mapped to...). ε , δ(-DP) and store it. For example, given a privacy level for a specific policy (e.g., low, medium, high), and if differential privacy is a privacy enhancement technique (PET), then the specific use cases for the service can be as follows: (( ε , δ )-DP1, ( ε , δ )-DP2, ( ε , δ )-DP3).

[0071] In step 4, based on the policies / regulations of the 5G core network operator, the network operator updates or stores different privacy levels for each subscriber and each data use case. For example, if the use case is advertising services, the network's mapping of the UE's nominal privacy level is set to high security, i.e., a high privacy level. However, if the use case is network performance improvement, the network's goal is the minimum possible privacy level.

[0072] In steps 5a / 5b, the RAN node (e.g., gNB) model training management function 304 receives the privacy level of UE 302 stored in 5G core NF 310 (e.g., UDM) via AMF 306 (5b), or the 5G core model training management function 308 (e.g., NWDAF) receives the privacy level of UE 302 directly from 5G core NF 310 (5a).

[0073] To this end, the RAN node model training management function 304 can request privacy data from the 5G core NF 310, and the 5G core NF 310 provides this privacy data. Alternatively, as part of UE registration, the 5G core NF 310 can provide privacy data to the AMF 306, and the AMF 306 can provide privacy data to the RAN node model training management function 304. Similarly, the NWDAF or other 5G core NFs can also obtain this from the UDM, or the UDM can push it to the NWDAF / 5G core NF.

[0074] In steps 6a / 6b, UE 302 sends privacy-sensitive data (complete training data / raw data or trained model parameters) to the 5G core model training management function 308 (6a) or the RAN node model training management function 304 (6b) via a secure interface. In some embodiments, the 5G core network can request privacy-sensitive data from UE 302, and UE 302 provides the privacy-sensitive data in response to the request.

[0075] In step 7, the model training management function of the RAN node (304) or the 5G core network (308) applies a privacy protection mechanism using the information received from steps 5a / 5b after receiving sensitive data from the UE. This privacy enhancement is applied to the training data itself (before initiating ML model training) or to the machine learning model parameters sent by the UE 302. The gNB / network enhances the privacy of the data based on the most stringent requirements (e.g., minimum ε) from all UEs. For example, the model training management function of the RAN node (304) or the model training management function of the 5G core network (308) trains the complete model after applying the received privacy configuration to the UE training data, or trains the remainder of the model (in the case of a two-sided model) or aggregates the ML model parameters (in the case of federated learning) after applying the privacy mechanism to the received model parameters.

[0076] In step 8, the 5G core model training management function 308 sends a privacy-preserving, trained ML model to the UE 302.

[0077] Now go to Figure 4 The illustration depicts a procedure 400 for protecting the privacy of user equipment data during the training of a machine learning model in a communication network environment, according to another illustrative embodiment. More specifically, as shown, procedure 400 (e.g., a UE-side technical solution) relates to UE 402, RAN node model training management function 404, AMF 406, 5G core model training management function (e.g., NWDAF) 408, and 5G core NF (e.g., UDM) 410.

[0078] Steps 1, 2, 3 and 4 in program 400 are performed in the same or similar manner as steps 1, 2, 3 and 4 in program 300.

[0079] In step 5, once the subscription data for UE 402 is updated at a privacy level, the 5G core NF 410 sends a policy (e.g., one or more privacy parameters) to UE 402 via UE Parameter Update (UPU) or Policy Control Function (PCF) to indicate what privacy should be applied when the ML model is running at UE 402 or when data from UE 402 is exposed to the 5G core network. In some embodiments, one or more of the RAN node model training management function 404 and the 5G core model training management function 408 may also receive policies (e.g., one or more privacy parameters).

[0080] In step 6, once UE 402 receives the privacy policy, UE 402 applies the privacy level to the training data before using the training data to train the ML model or before sending the raw training data to the 5G core network, or UE 402 applies the privacy policy to the model parameters before sending the model parameters to the 5G core network for collaborative training or federated learning.

[0081] In steps 7a / 7b, UE 402 sends the protected privacy, trained data / model parameters / complete trained ML model to RAN node model training management function 404 or 5G core model training management function 408.

[0082] As used herein, it should be understood that in some embodiments, the term "communication network" may include two or more independent communication networks. Furthermore, the specific processing operations and other system functionalities described herein in conjunction with schematic diagrams are presented by way of illustrative example only and should not be construed as limiting the scope of this disclosure in any way. Alternative embodiments may use other types of processing operations and messaging protocols. For example, in other embodiments, the order of steps may be changed, or certain steps may be performed at least partially simultaneously rather than sequentially. Furthermore, one or more steps may be repeated periodically, or instances of multiple methods may be executed in parallel with each other.

[0083] It should be emphasized again that the various embodiments described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, configuration and usage procedures, messaging protocols, and message formats than those described in the exemplary embodiments above. These, and many other alternative embodiments within the scope of the appended claims, will be apparent to those skilled in the art.

[0084] As used herein, “at least one of the following: ”, “at least one of ”, “one or more of ”, and similar expressions, where the list of two or more elements is connected by “and” or “or”, means at least any one element, or at least any two or more elements, or at least all elements.

Claims

1. An apparatus comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: The device sends a selected privacy level to the communication network, and is participating in the machine learning model training process together with the communication network. Receive one or more privacy parameters corresponding to the selected privacy level; and The one or more privacy parameters are applied to the data that will be sent to the communication network.

2. The apparatus of claim 1, wherein the data to which the one or more privacy parameters are applied includes at least one of: machine learning model training data; one or more machine learning model parameters; and a trained machine learning model.

3. The apparatus of claim 1 or 2, wherein the one or more privacy parameters are associated with a privacy mechanism.

4. The apparatus according to any one of claims 1 to 3, wherein the privacy level sent by the apparatus is one of a plurality of privacy levels selectable based on a communication network service for which the machine learning model training process is being performed.

5. The apparatus according to any one of claims 1 to 4, wherein the apparatus is further configured to: send the data to the machine learning model training management function of the communication network after the application of the one or more privacy parameters.

6. The apparatus of claim 5, wherein the machine learning model training function of the communication network is a core network entity.

7. The apparatus according to claim 6, wherein the core network entity is a network function.

8. The apparatus according to claim 7, wherein the network function is a network data analysis function.

9. The apparatus according to claim 8, wherein the network data analysis function includes a model training logic function.

10. The apparatus according to any one of claims 1 to 4, wherein the apparatus is further configured to: after the application of the one or more privacy parameters, send the data to a machine learning model training management function of a wireless access network associated with the communication network.

11. The apparatus according to any one of claims 1 to 10, wherein the apparatus comprises a user equipment, or the apparatus is included in a user equipment.

12. A method comprising: The user equipment sends a selected privacy level to the communication network, and the user equipment is participating in the machine learning model training process together with the communication network. At the user equipment, one or more privacy parameters corresponding to the selected privacy level are received; as well as The user equipment applies one or more privacy parameters to the data to be sent to the communication network.

13. The method of claim 12, wherein the data to which the one or more privacy parameters are applied includes at least one of: machine learning model training data; one or more machine learning model parameters; and a trained machine learning model.

14. The method of claim 12 or 13, wherein the one or more privacy parameters are associated with a privacy mechanism.

15. The method according to any one of claims 12 to 14, wherein the privacy level sent by the user equipment is one of a plurality of privacy levels selectable based on a communication network service for which the machine learning model training process is being performed.

16. An apparatus comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: The device receives a selected privacy level from the user equipment and is participating in a machine learning model training process with the user equipment based on the communication network. as well as Determine one or more privacy parameters corresponding to the selected privacy level.

17. The apparatus of claim 16, wherein the apparatus is further configured to: send the one or more privacy parameters to the user equipment.

18. The apparatus of claim 16 or 17, wherein the apparatus is further configured to send the one or more privacy parameters to one or more of: a machine learning model training management function of the communication network; and a machine learning model training management function of a radio access network associated with the communication network.

19. The apparatus according to any one of claims 16 to 18, wherein the apparatus is further configured to: determine the one or more privacy parameters corresponding to the selected privacy level by accessing a mapping from privacy level to privacy parameters based on a privacy policy.

20. The apparatus according to any one of claims 16 to 19, wherein the apparatus comprises a core network entity, or the apparatus is included in a core network entity.

21. The apparatus of claim 20, wherein the core network entity is a network function.

22. The apparatus of claim 21, wherein the network function is unified data management.

23. A method comprising: At the communication network entity, a selected privacy level is received from the user equipment, and the communication network entity is participating in the machine learning model training process together with the user equipment. as well as The communication network entity determines one or more privacy parameters corresponding to the selected privacy level.

24. The method of claim 23, further comprising: The one or more privacy parameters are sent from the communication network entity to the user equipment.

25. The method according to claim 23 or 24, further comprising: Sending one or more of the privacy parameters from the communication network entity to one or more of the following: machine learning model training management functions of the communication network; And machine learning model training management functions for the wireless access network associated with the communication network.

26. The method of any one of claims 23 to 25, wherein determining the one or more privacy parameters corresponding to the selected privacy level further comprises: Based on the privacy policy, access the mapping from privacy levels to privacy parameters.

27. An apparatus comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: Receive one or more privacy parameters from a communication network entity that correspond to a selected privacy level associated with a user device participating in the machine learning model training process; Receive data from the user equipment; as well as The one or more privacy parameters are applied to the data received from the user device.

28. The apparatus of claim 27, wherein the apparatus includes a machine learning model training management function, or the apparatus is included in a machine learning model training management function.

29. The apparatus of claim 28, wherein the machine learning model training management function is a core network entity.

30. The apparatus of claim 29, wherein the core network entity is a network function.

31. The apparatus according to claim 30, wherein the network function is a network data analysis function.

32. The apparatus according to claim 31, wherein the network data analysis function includes a model training logic function.

33. The apparatus of claim 28, wherein the machine learning model training management function is a wireless access network entity.

34. A method comprising: At the machine learning model training management function, one or more privacy parameters corresponding to a selected privacy level are received from the communication network entity, the selected privacy level being associated with the user equipment participating in the machine learning model training process; Data is received from the user equipment at the machine learning model training management function; as well as The machine learning model training management function applies one or more privacy parameters to the data received from the user device.

35. An apparatus comprising: The device is used to send components with a selected privacy level to a communication network, and is participating in a machine learning model training process with the communication network. A component for receiving one or more privacy parameters corresponding to the selected privacy level; as well as A component for applying the one or more privacy parameters to data to be sent to the communication network.

36. An apparatus comprising: For receiving components with a selected privacy level from a user equipment, the device is participating in a machine learning model training process with the user equipment according to a communication network; as well as A component for determining one or more privacy parameters corresponding to the selected privacy level.

37. An apparatus comprising: A component for receiving one or more privacy parameters from a communication network entity corresponding to a selected privacy level, the selected privacy level being associated with a user device participating in a machine learning model training process; Components for receiving data from the user equipment; as well as A component for applying the one or more privacy parameters to the data received from the user equipment.

38. A computer-readable non-transitory medium comprising program instructions stored thereon, the program instructions being configured to perform at least the method according to any one of claims 12 to 15, 23 to 26, or 34.

39. A computer-readable medium comprising program instructions stored thereon, the program instructions being configured to perform at least the method according to any one of claims 12 to 15, 23 to 26, or 34.

40. A computer program comprising instructions for performing at least any one of claims 12 to 15, 23 to 26, or 34.

41. A system comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the system to at least: Send the selected privacy level to the communication network that participates in the machine learning model training process with the user device; Receive one or more privacy parameters corresponding to the selected privacy level; Apply the one or more privacy parameters to the data to be sent to the communication network; The selected privacy level is received by the communication network that participates in the machine learning model training process with the user equipment. Determine one or more privacy parameters corresponding to the selected privacy level; Receive one or more privacy parameters corresponding to the selected privacy level, which is associated with the user device participating in the machine learning model training process; Receive data from the user equipment; as well as The one or more privacy parameters are applied to the data received from the user device.

42. A system comprising: Components with selected privacy levels are used to send to the communication network that participates in the machine learning model training process with the user device; A component for receiving one or more privacy parameters corresponding to the selected privacy level; A component for applying the one or more privacy parameters to data to be sent to the communication network; Components for receiving a selected privacy level based on the communication network that participates in the machine learning model training process with the user equipment; Components for determining one or more privacy parameters corresponding to the selected privacy level; A component for receiving one or more privacy parameters corresponding to the selected privacy level, the selected privacy level being associated with the user equipment participating in the machine learning model training process; Components for receiving data from the user equipment; as well as A component for applying the one or more privacy parameters to the data received from the user equipment.