Federated learning with client data privacy protection and implication checking

By combining federated learning and efficient parameter fine-tuning with customer privacy protection mechanisms, the problem of AI/ML model training data shortage and privacy constraints in industrial environments is solved, enabling effective training and use of ML models while ensuring data privacy.

CN122491541APending Publication Date: 2026-07-31ABB (SCHWEIZ) AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ABB (SCHWEIZ) AG
Filing Date
2026-01-27
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In industrial environments, AI/ML-based models struggle to effectively construct and formalize process design information for use in engineering tools due to a shortage of training data and customer data privacy constraints.

Method used

By employing federated learning combined with the Parameter Efficient Fine-Tuning (PEFT) method, and applying customer privacy protection mechanisms such as differential privacy and homomorphic encryption, the source of information is verified through implication checks to ensure that the information comes only from the data of the corresponding customer.

Benefits of technology

While ensuring customer data privacy, effectively train and use ML models, simplify access to private data, reduce bandwidth requirements, and improve training efficiency and data confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122491541A_ABST
    Figure CN122491541A_ABST
Patent Text Reader

Abstract

Federated learning leveraging customer data privacy protection and implication checks is disclosed. A method for training and using ML models on customer engineering data in an industrial environment with enhanced customer privacy protection is provided. The method includes, during the training phase of the ML model: obtaining customer engineering data from customer project data associated with customers; training an ML model on the customer engineering data using federated ML; applying customer privacy protection mechanisms to information inferred by the ML model, and when using the ML model for inference: verifying, by using an implication check method, that information inferred by the ML model and determined by the ML model to be associated with a customer is obtained from the customer engineering data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to federated learning, for example, for P&A engineering, with customer data privacy protection and implication checks. More specifically, this invention relates to a method for training machine learning models on customer engineering data in an industrial environment using enhanced customer privacy protection. The invention also relates to data processing apparatus, data processing systems, computer-readable media, computer program products, and uses in industrial environments. Background Technology

[0002] In industrial environments, automation engineering for process automation systems remains a highly manual process due to limited support for the interpretation and processing of process design specification documents. While digital data exchange standards do exist between process and automation engineering, these formats are rarely used and therefore fail to unlock the enormous automation potential within automation engineering.

[0003] Currently, models based on artificial intelligence and / or machine learning (AI / ML) for industrial environments have been developed to construct and formalize multimodal unstructured process design information in formats such as PDF, Excel, and Word, and make it available for use with state-of-the-art engineering tools for the long-established “automation automation”.

[0004] However, such AI / ML-based models only understand that they will be applied to a limited or labeled extended domain, and for such currently developed models, the shortage of training data needs to be overcome. At the same time, however, such AI / ML-based models must comply with the client's data privacy constraints.

[0005] More specifically, to further improve the AI / ML-based models used to process a wide range of engineering design specification documents from Process Automation – Process Industries (PA – PI), where PI includes, for example, mining, food & beverage, data centers, etc., and Process Automation – Energy Industries (PA – EN), for example, oil & gas, chemical / refinery, etc., it is necessary to train the AI / ML-based models on further customer data. So far, they have only understood the domain as a limited or previously labeled extension, and we will need to overcome the shortage of training data while simultaneously adhering to customer data privacy constraints, especially in industrial environments.

[0006] However, customer data privacy is an issue and hinders further training of AI / ML-based models.

[0007] Therefore, in the context of industrial applications, there is the question of how to improve AI / ML-based models for constructing and / or formalizing process design information, and how to make this process design information available to engineering tools, while complying with customer data privacy constraints.

[0008] Therefore, there is room for improvement and a need to improve AI / ML-based models used to construct and / or formalize process design information and to make this process design information available to engineering tools, while complying with customer data privacy constraints. Summary of the Invention

[0009] In view of the foregoing, the purpose of this disclosure is to overcome at least some of the potential drawbacks of compliance with customer data privacy constraints in the application of AI / ML-based models used to construct and / or formalize process design information and to make such process design information available to engineering tools.

[0010] Therefore, to address one or more of these drawbacks, in a first aspect, a computer-implemented method is provided for training and using a machine learning (ML) model on customer engineering data in an industrial environment with enhanced customer privacy protections. The method includes, during the training phase of the ML model: obtaining customer engineering data from customer project data associated with the customer; training the ML model on the customer engineering data using federated ML; thereby fine-tuning the ML model using a fine-tuning method (it should be noted that fine-tuning can be understood as part of the training, and fine-tuning is optional); and applying user privacy protection mechanisms to the information inferred by the ML model. The method also includes, during the use phase of the ML model for inference, i.e., using an implication check method, verifying that the information inferred by the ML model and determined by the ML model to be associated with the customer was obtained from the customer project data. More specifically, verifying that the information inferred by the ML model and determined by the ML model to be associated with the customer was obtained from the customer project data and not from another customer's project data.

[0011] It should be noted that the expression “training phase” means that the ML model is trained, and the expression “when using the ML model for inference” means that the trained ML model, i.e. the ML model obtained as a result of the training phase, is applied to several tasks, such as verification as outlined in the first aspect.

[0012] Federated ML is well-known. For example, federated ML can be understood as an ML setup in which several entities participate in solving a learning problem. These entities do not exchange data with each other, or at least not directly.

[0013] These fine-tuning methods are well known, as outlined in more detail below.

[0014] Several such customer privacy protection mechanisms are well-known, as outlined in more detail below.

[0015] The expression "inference information" can also be understood as "derived information" or "obtained information".

[0016] These essential inspection methods are well known, as outlined in more detail below.

[0017] The advantage of the approach based on the first aspect lies in its ability to overcome the problem of limited data for training ML models while adhering to given constraints, such as customer privacy constraints in an industrial environment. Therefore, by using federated learning, ML models can be trained on data from different customers, such as distributed customers (in the sense of probability distribution customers or customer data) and / or customers from EN and PI, which simplifies access to private data. Furthermore, by using fine-tuning methods, such as parameter efficient fine-tuning (PEFT), training effort can be handled efficiently, significantly reducing bandwidth without exposing the full model weights of the ML model to be fine-tuned, but only exposing "PEFT-low-rank adapters" or similar methods. Moreover, customer data privacy can be guaranteed, for example, because no data from customer A (or the first customer) to whom the ML model is trained is leaked to customer B (or the second customer) during the inference phase of the ML model (i.e., the usage phase).

[0018] It should be noted that customer A can also be called the first customer (and vice versa), and customer B can also be called the second customer (and vice versa).

[0019] According to some examples of this disclosure, fine-tuning an ML model using fine-tuning methods may include fine-tuning the ML model by using one of the following: parameter efficiency fine-tuning (PEFT), low rank adaptation-PEFT (LoRA-PEFT), and pruning.

[0020] Therefore, different alternatives are available and can be appropriately selected to enable efficient handling of training efforts, which significantly reduces bandwidth without exposing the full model weights of the ML model for fine-tuning.

[0021] According to some examples of the present invention, applying a customer privacy protection mechanism may include applying one of the following: differential privacy (DP), homomorphic encryption, and autoencoder.

[0022] Regarding differential privacy (DP), it's important to note that DP is a robust mathematical framework designed to protect individual privacy while allowing analysis of datasets. It is particularly relevant in machine learning, where models often rely on sensitive data used for training. DP ensures that including or excluding data from individual individuals does not significantly affect the model's output, thus protecting personal or general confidential information.

[0023] Therefore, different alternatives are available and can be selected as appropriate / suitable to protect the customer's personal privacy.

[0024] According to some examples of this disclosure, verification using an implication checking method may include verification by using one of the following: implication checking based on natural language reasoning (NLI) and verification by one of the methods based on inverse retrieval augmentation (RAG).

[0025] Regarding Reverse Retrieval Augmentation (RAG), it should be noted that once a potential (preliminary) output or result has been generated or obtained by, for example, an ML model intended for output to customer A (or the first customer), the reverse RAG component has the task of checking whether the information contained in the output or result can actually be inferred, retrieved, or derived (or inferred, retrieved, or derived) from the original customer-owned data owned by customer A. Only if the expected output or result to be provided to a particular customer can be derived from the corresponding customer's data will it become the final output or result. If it cannot be derived from the data of each customer, this means it has been leaked from the data of some other customer, and therefore it is prohibited from being output. In doing so, it is guaranteed that no other customer's data is exposed, i.e., it is guaranteed that no data of customer B (or the second customer) is exposed to customer A.

[0026] Therefore, customer privacy protection has been improved.

[0027] According to some examples of this disclosure, the method may further include: determining whether fine-tuning the ML model is worthwhile for the client; and if it is determined that fine-tuning the ML model is worthwhile, performing fine-tuning of the ML model using a fine-tuning method. Fine-tuning is determined to be worthwhile if it is expected that the ML model will be enhanced with additional knowledge based on the fine-tuning.

[0028] It should be noted that fine-tuning can often be time-consuming and therefore expensive. Therefore, if the expected benefits from fine-tuning are deemed worthwhile, then fine-tuning can be performed. One aspect of considering whether fine-tuning is beneficial, useful, or valuable is whether the ML model is expected to be enhanced by additional knowledge, i.e., whether the ML model can be improved.

[0029] Therefore, if a specific gain is desired, it can only incur the cost and time of fine-tuning. This improves resource efficiency during the training phase.

[0030] According to some examples of this disclosure, a customer can be a first customer or customer A as described above. Customer engineering data and / or customer project data can be associated with the first customer or customer A, but not with a second customer, i.e., not with customer B as described above. For example, customer engineering data and / or customer project data can be associated only with the first customer or customer A, and not with other customers. Customer engineering data and / or customer project data may include engineering data from one or more engineering projects from the first customer (customer A), but not engineering data from engineering projects from the second customer (customer B), i.e., no engineering data from engineering projects from any other customer.

[0031] Therefore, it further enhances data confidentiality.

[0032] According to some examples of this disclosure, customer engineering data can be probability distribution customer engineering data, which includes different information in the customer engineering data and associated with the customer that appears with different probabilities.

[0033] In this context, "probability distribution in customer engineering data" refers to a "probability distribution," not in the sense of a "distribution across customers." For example, a "probability distribution" refers to how many symbols of type A there are, how many symbols of type B there are, how many symbols of other types, etc. This can result in, for example, a Gaussian or normal distribution. Such a distribution can be considered during the training and inference phases of an ML model to avoid bias. For example, if there are 10,000 symbols of type A and very few of type B in the training data, the ML model will very likely learn that type A is "almost always" true, regardless of what the symbols appear to be. To avoid this, probability distributions help to balance this. This can be considered in customer engineering data using probability distributions. This is why and how, for example, a "federated average" mechanism might be needed to balance (i.e., consider) this sometimes strongly biased distribution.

[0034] According to some examples of this disclosure, the method may further include: identifying the probability distribution of the probability distribution customer-engineered data by using a distribution identifier component. The method may also include unifying and / or scaling the probability distribution of the probability distribution customer-engineered data by using a data-selection-based distribution unifier and / or a data-selection-based distribution scaler. The method may further include training an ML model on the unified and / or scaled probability distribution customer-engineered data.

[0035] Therefore, probability distribution customer engineering data can be processed and used more effectively and appropriately for training purposes. Consequently, the performance of ML models is further improved.

[0036] According to some examples of this disclosure, if it is verified that the information was obtained from customer project data, the method may further include providing the information. For example, it may be verified or determined that the information was obtained only from customer project data and not from another customer's project data. And if it is verified that at least part of the information was not obtained from customer project data, the method may further include not providing the information. For example, it may be verified or determined that at least part or at least fragment of the information was not obtained from customer project data; that is, it may not be excluded, or there may be an opportunity to obtain at least part or at least fragment of the information from another customer's project data. For example, the chance of obtaining at least part or at least fragment of the information from another customer's project data may be higher than a predetermined threshold, such as the chance may be higher than 0% (similarly, obtaining at least part or a fragment of information from another customer's project data may be excluded with less than 100% certainty).

[0037] Therefore, compliance with data confidentiality requirements has been further strengthened.

[0038] According to some examples of this disclosure, a customer can be a first customer or a customer A as described above. If it is verified that the information is obtained from customer item data associated with the first customer and no second customer (e.g., customer B as described above), i.e., no other customer, the method may also include providing the information to the first customer. If it is verified that at least part of the information is obtained from customer item data associated with a second customer, i.e., any other customer, rather than with the first customer, the method may also include not providing the information to the first customer.

[0039] Therefore, compliance with data confidentiality requirements has been further strengthened.

[0040] According to a second aspect, a data processing apparatus is provided. The data processing apparatus includes one or more processors configured to perform the method of the first aspect.

[0041] According to a third aspect, a data processing system is provided. The data processing system includes the data processing apparatus of the second aspect. Additionally or optionally, the data processing system includes means for performing the method of the first aspect.

[0042] According to the fourth aspect, an industrial plant is provided that includes the data processing equipment of the second aspect and / or the data processing system of the third aspect.

[0043] Based on several examples, "industrial plant" can refer to an industrial facility, autonomous industrial plant, or industrial production facility that includes one or more pipelines, production lines, and / or assembly lines for converting one or more isolates into products and / or for assembling one or more components into, for example, a final product. Based on several examples, it can refer to an industrial plant in the petroleum industry, natural gas industry, mining industry, chemical industry, wind and electricity industry, or food and beverage industry.

[0044] According to a fifth aspect, a computer-readable medium is provided comprising instructions that, when executed by a computing system, cause the computing system to perform the method of the first aspect. The computer-readable medium may be temporary or non-temporary, volatile or non-volatile.

[0045] According to a sixth aspect, a computer program product including instructions is provided, which, when executed by a computing system, enable or cause the computing system to perform the method of the first aspect. The computer program product may include a computer-readable medium comprising the instructions of the computer program product.

[0046] According to the seventh aspect, the use of at least one of the following is provided: the ML model trained in the first aspect, the method in the first aspect, the data processing apparatus in the second aspect, the data processing system in the third aspect, the industrial plant in the fourth aspect, the computer-readable medium in the fifth aspect, and the computer program product in the sixth aspect.

[0047] Each of the following aspects—the method in the first aspect, the data processing equipment in the second aspect, the data processing system in the third aspect, the industrial plant in the fourth aspect, the computer-readable medium in the fifth aspect, the computer program product in the sixth aspect, and the use in the seventh aspect—is advantageous in several respects. That is, each of these aspects is advantageous because it can contribute to overcoming the problem of limited data for training ML models while adhering to given constraints, such as customer privacy constraints in an industrial environment. Therefore, by using federated learning, it is possible to train ML models on data from different customers, such as distributed customers (in the sense of probability distribution customers or customer data) and / or from customers from EN and PI, which simplifies access to private data. Furthermore, by using fine-tuning methods, such as Parameter Effective Fine-Tuning (PEFT), the training effort can be handled efficiently, significantly reducing bandwidth without exposing the full model weights of the ML model to be fine-tuned, but only exposing the “PEFT-low-rank adapter” or similar methods. Moreover, customer data privacy can be guaranteed, for example, because no data from customer A (or the first customer) to whom the ML model is trained is disclosed to customer B (or the second customer) during the inference phase of the ML model (i.e., the use phase).

[0048] The optional features of the first aspect can form part of any one of the second to seventh aspects, with necessary modifications.

[0049] The fifth aspect is a computer-readable medium on which the computer program product of the sixth aspect can be stored.

[0050] As used herein, the term “acquire” can include, for example, receiving from another system, device, (AI / ML) model, or process; receiving via interaction with a user; loading or retrieving from storage or memory; measuring or capturing using sensors or other data acquisition devices; receiving or acquiring results from one or more data processing steps.

[0051] The indefinite articles “one” or “a” do not exclude multiples. Furthermore, unless otherwise specified or clearly indicated from the context that it is in the singular form, the articles “one” and “a” as used herein should generally be interpreted as meaning “one or more”.

[0052] Unless otherwise stated, or clearly apparent from the context, the phrases “one or more of A, B, and C,” “at least one of A, B, and C,” and “A, B, and / or C” as used herein are intended to represent all possible permutations of one or more of the listed items. That is, the phrase “A and / or B” means (A), (B), or (A and B), while the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0053] The term "comprising" does not exclude other elements or steps. Furthermore, the terms "including," "comprises," "having," etc., are used interchangeably herein.

[0054] This invention may include one or more aspects, instances, or features, either individually or in combination, whether specifically disclosed in the combination or individually. Any optional feature or sub-aspect of one of the foregoing aspects may suitably be applied to any other aspect.

[0055] The above aspects will become apparent and clarified with reference to the detailed description provided below. Attached Figure Description

[0056] A detailed description will now be given by way of example only, with reference to the accompanying drawings, in which:

[0057] Figure 1 Examples of AI-based methods for constructing and formalizing multimodal unstructured process design information, according to some examples of this disclosure, are shown;

[0058] Figure 2 Federated learning for settings with PEFT, customer privacy protection, and participation checks is illustrated according to some examples of this disclosure;

[0059] Figure 3 Examples of the provisions of this disclosure are shown. Figure 2 On the other hand, the settings;

[0060] Figure 4 Flowcharts illustrating methods according to some examples of this disclosure are shown; and

[0061] Figure 5 A block diagram illustrating a data processing apparatus according to some examples of this disclosure is shown. Detailed Implementation

[0062] In industrial environments, automation engineering for process automation systems remains a highly manual task due to limited support for the interpretation and processing of process design specification documents.

[0063] Currently, models based on artificial intelligence and / or machine learning (AI / ML) for industrial environments have been developed to construct and formalize multimodal unstructured process design information in formats such as PDF, Excel, and Word, and to make it available for use with state-of-the-art engineering tools for the long-established “automationization” approach.

[0064] Examples of this AI / ML-based model are in Figure 1 The diagram illustrates that, in Figure 1 The examples shown are provided for illustrative purposes and are not intended to limit this disclosure. Figure 1 This is shown in the system and / or ML model.

[0065] In more detail, Figure 1 An AI-based method and prototype, “Engineering Data Funnel” (EDF) 140, is illustrated. This device, currently developed by the inventors, is used to construct and formalize multimodal unstructured process design information in formats such as PDF, Excel, and Word, making it usable for use with state-of-the-art engineering tools for the long-established “automationization” process. Some examples of this disclosure can be described through examples of EDF 140; however, it should be noted that the data processing apparatus and systems (as well as computer program products, computer-readable media, industrial plants, and uses) disclosed herein according to some examples of this disclosure are transferable, applicable, or usable / for other (generative) AI-related projects and applications.

[0066] Therefore, now refer to Figure 1 , Figure 1 Examples of AI-based methods, according to some examples of this disclosure, are shown for constructing and formalizing multimodal unstructured process design information. In other words, Figure 1EDF 140 is shown, which can be understood as an artificial intelligence (AI) based information processing system for processing input data or input documents (such as engineering design specification documents) into a fully structured representation according to some examples of this disclosure.

[0067] More specifically, according to Figure 1 The EDF system 100 illustrates three different types of input documents or engineering design specification documents: a first specification document 110 includes text information, a second specification document 120 includes images or topological diagrams of several connection symbols, and a third specification document 130 includes tables. Specification documents 110, 120, and 130 can be understood as input documents entered into EDF 140. Specification documents 110, 120, and 130 can be data formats; for example, the first specification document 100 can be in Word format, the second specification document 120 can be in PDF format, and the third specification document 130 can be in Excel format. However, specification documents are not limited to these types of formats. Generally speaking, specification documents 110, 120, and 130 can represent, for example, unstructured data obtained from an EPC (Engineering, Procurement, and Construction) project.

[0068] Each specification document 110, 120, and 130 includes one or more pieces of information. For example, the first specification document 110 includes multiple pieces of information related to tanks, reactors, and valves, i.e., text information. Furthermore, the second specification document 120 includes multiple pieces of information related to tanks, reactors, and valves, i.e., connecting symbols. Additionally, the third specification document 130 includes multiple pieces of information related to tanks, reactors, and valves, i.e., the content of rows, columns, or cells in a table.

[0069] Specification documents 110, 120, and 130 are entered (in such a way as...) Figure 1 The data (in steps S110, S120, and S130) are transmitted to EDF 140 and processed by EDF 140. As a result of the processing, in S140, EDF 140 outputs a structured representation.

[0070] In the processing of EDF 140, the information segments for tanks, reactors and valves are identified in specification documents 110, 120 and 130.

[0071] The structured representation obtained from EDF 140 can be understood as a representation of federated information available from specification documents 110, 120, and 130. Alternatively, the structured representation obtained from EDF 140 can be understood as a representation of the corresponding structured representation for each specification document 110, 120, and 130. As an example solely for improving understandability, EDF 140 can identify from the second specification document 120, based on image processing, that a tank can be connected to a valve and that the valve can be further connected to a reactor. However, since the second specification document 120 may be of low quality—for example, the image may be pixelated—connecting the tank to the reactor via the valve may be of low determinism. From the first specification document 110, EDF 140 can, for example, know with greater certainty that the tank is indeed connected to the reactor via a valve, and from the third specification document 130, EDF 140 can, for example, know with specific certainty the possible types of the tank and the possible types of the reactor. Therefore, for example, it can be understood that the structured representation of the target structured representation can include, with relatively higher determinism, a tank connected to a reactor via a valve, and the tank and reactor can be of some type.

[0072] Typically, one or more structured representations can be output by EDF 140 in different ways or formats, such as in structured visualizations 150 or structured text information 160, like JSON files.

[0073] More specifically, EDF 140 or EDF system 100 may include, among other things, a visual model trained to recognize components and / or symbols and connections in an input document, such as in P&ID documents similar to the first and second specification documents 110 and 120, for example as a PDF file, an image file. Additionally or optionally, EDF 140 or EDF system 100 may include a language model trained to process text in a control narrative document, such as in input documents like specification documents 110, 120, and 130, for example in a PDF file, text, a text file, or a table.

[0074] In the above example, specification documents 110, 120, and 130 may be associated with the same customer and may be associated with customer engineering data from customer engineering data associated with the same customer (e.g., the first customer or customer A). Furthermore, specification documents 110, 120, and 130 may be associated only with the same customer and therefore may not be associated with any other customer, i.e., not with a second customer or customer B.

[0075] However, during the use or reasoning phase of EDF 140, when specification documents 110, 120, and 130 are associated with different customers (however, this is not possible), for example, with a first customer and at least a second customer who can operate similar industrial plants, such combination or federated processing of specification documents 110, 120, and 130 in EDF 140 as described above may not be permitted due to customer data privacy requirements or constraints. Alternatively, in other words, when specification documents 110, 120, and 130 are associated with different customers, such combination or federated processing of specification documents 110, 120, and 130 in EDF 140 as described above may violate customer data privacy requirements or constraints.

[0076] However, this may be far more relevant during the training phase of EDF 140. For example, it can be assumed that the aforementioned processes for federalizing specification documents 110, 120, and 130 occur during the training of EDF 140. In other words, the training data for training EDF 140 could include specification documents 110, 120, and 130. If specification documents 110, 120, and 130 are associated with different customers, conflicts with customer data privacy requirements or constraints may arise.

[0077] Therefore, improvements are needed.

[0078] Based on some examples in this disclosure, to further advance EDF 140 to handle a wide range of engineering design specification documents from PA-PI and PA-EN, the EDF base model needs to be trained on further customer data. The EDF base model may only interpret the domain as a limited or previously labeled extension, and therefore may need to overcome the shortage of training data while complying with customer data privacy constraints. Therefore, customer data privacy often prevents further training of EDF 140 or AI / ML models.

[0079] Therefore, based on some examples of this disclosure, a method is disclosed that combines federated learning of distributed customer data with generative AI and parameter efficient fine-tuning (PEFT) approaches, and also applies methods for customer data privacy protection, such as differential privacy and homomorphic encryption or autoencoders, to train P&A engineering ML models on confidential customer data from PA-EN and PA-PI enterprises, while ensuring that no confidential data from the first customer is accidentally disclosed to a second customer during ML model inference. Additional filtering, mandatory checks, or reverse generative AI verification components can verify that all information in the ML model inference is actually found in the corresponding customer's project data (rather than in project data from another customer).

[0080] Based on several examples disclosed herein, it addresses the problem of training AI systems on customer data while ensuring that no other customer data is exposed to corresponding other customers. Therefore, ML models can be trained on distributed customer (engineered) data using federated ML, customer privacy protection mechanisms, and enhanced enforcement checks, ensuring that no confidential customer data is unnecessarily exposed, such as... Figure 2 As illustrated in the diagram.

[0081] Figure 2 The following are examples of setups for federated learning with PEFT, customer privacy protection, and participation checks, according to this disclosure. For example, five different customers 201a, 202a, 203a, 204a, and 205a are shown, each associated with corresponding customer data and corresponding customer project data. For each customer, the acquired data is subjected to a value assessment (VA) or corresponding VAs 201b, 202b, 203b, 204b, and 205b, i.e., determining whether fine-tuning is worthwhile, for DP or corresponding DPs 201c, 202c, 203c, 204c, and 205c, and may be subjected to PEFT or corresponding PEFTs 201d, 202d, 203d, 204d, and 205d before being stored / uploaded to server 206, for example, during the training phase of ML model 209. During the use or inference phase of ML model 209, mandatory checks (or, for example, anti-RAG verification) 207 can be applied to verify, for example, whether the output 208 to be output to customer 201a can only be derived from data obtained from customer 201a. For example, refer to Figure 2 The global model 209 shown can be a reference. Figure 1 EDF 140 is shown.

[0082] exist Figure 2 In the diagram, the arrows pointing from client / client 201a to 205a to server 206 indicate uploads from client / client 201a to 205a to server 206, while the arrows pointing from server 206 to client / client 201a to 205a indicate broadcasts from server 206 to client / client 201a to 205a. These arrows... Figure 3 It is more visible in the middle.

[0083] More specifically, based on some examples of this disclosure, for the training phase, with federated learning, in the case of applying differential privacy, the model weights can have noise added to all parameters to make data recovery more difficult or even impossible. Adding additional methods, such as encryption, or autoencoders for dimensionality reduction, i.e., sending only the reduced embedding layers, can make recovering confidential data even more difficult. For the inference phase, in addition, additional filters, "forced checks," or "reverse resistance" systems can be added to allow only LLM outputs for a particular client, which can effectively only be derived from the given data of that specific client, thus guaranteeing that data from other clients is not exposed. Similarly, LLM outputs that cannot be derived from only the given data of a specific client are not allowed.

[0084] Therefore, based on some examples of this disclosure, the following techniques can be used: federated AI with i) evaluation of the value (VA) of client-side fine-tuning of knowledge of the entire model, ii) efficient parameter fine-tuning, such as the PEFT-LoRA method or alternative methods, iii) client privacy protection, such as using DP, and iv) confirmation based on "mandatory checks" or "inverse RAG".

[0085] Based on some examples of this disclosure, in other words, it discloses the combination of federated learning with generative AI and PEFT methods, and also the application of methods for protecting customer data privacy, such as differential privacy and homomorphic encryption or autoencoders. To train a P&A engineering ML model on confidential customer data from PA-EN and PA-PI enterprises, for example, according to... Figure 1 This EDF 140 ensures that no confidential data from the first client is accidentally leaked to the second client during ML model inference. An additional Generate AI requirement inspection component, or "reverse RAG" component, can verify that all information from the ML model inference is actually found in the corresponding client's project data, and then only allows further processing or exposure of the ML model inference information, such as as part of the generated output of the ML model.

[0086] In the settings proposed according to some examples of this disclosure, if fine-tuning of the customer's data is worthwhile—that is, whether the overall model will be enhanced with "additional knowledge" or not—as part of the value assessment (VA), then each customer can optionally be examined at the level of embedded representation, for example, relative to their private data. In the case of fine-tuning, i.e., when it is worthwhile to use positive VA, then PEFT will help reduce computational cost and bandwidth. DP, for example, with calibrated noise, will take care of ensuring and formally promoting customer data privacy. "Forced inspection" or "inverse RAG" can check that all information for ML model inference is actually found in the corresponding customer's project data.

[0087] Based on some examples of this disclosure, in the disclosed methods or system settings, there are apparently no restrictions on the data processing, ML model training, and ML model inference for PEFT, DP, and task checking / inverse RAG for a single project, but rather on the selection or set of projects for a single client, or even all projects for a single client. This means that, for example, a first client or client A should benefit from ML model training on engineering data from several projects of the first client (the integrated group). And it may only be important that the data and / or knowledge of the first client is not exposed to another client, such as a second client or client B; rather, the data and / or knowledge obtained should be accessible when processing other projects of the first client.

[0088] Based on some examples in this disclosure, more specifically, to examine whether fine-tuning customer data is worthwhile—that is, to enhance the overall model with “additional knowledge”—the data distribution of the respective customer should be considered. Therefore, the embedding representations of the training data for the base model and the corresponding (private) training data for a particular customer (e.g., customer X) can be examined and compared. Overlaps or differences in the embedding representations can then be considered, such as the density and / or sparsity of clusters in the embedding representations, or the corresponding intra-cluster or inter-cluster distances. Furthermore, it may be necessary to compare the knowledge depth of the clusters, regardless of whether the two clusters are uniformly distributed. This can help determine whether the embedding model already possesses sufficient knowledge. Fine-tuning the (private) data of customer X based on these differences, for example, in terms of density, sparsity, intra-cluster / inter-cluster distances, may then be particularly beneficial and thus extend the capabilities of the entire model. In other words, if these metrics are very similar, fine-tuning will yield only minor gains, and only when they are considerably different will fine-tuning be beneficial and therefore considered valuable. It should be noted that this check may indicate optional steps that might occur on the client side, thus avoiding the exposure of private training data.

[0089] Based on some examples of this disclosure, as an alternative to PEFT, which is a class of methods as detailed below, other methods exist, such as "model pruning," as mentioned herein as a class of methods as detailed below, in order to allow for less computational effort and lower bandwidth, for example, when exchanging model weights with clients. These methods may require ensuring that the pruned edges are the same, i.e., consistent, across all distributed clients, thus having the same positive impact on computation and bandwidth.

[0090] PEF can include additional methods, adapter methods, selective methods, soft hint methods, and reparameterization-based methods, as explained in more detail, for example, in the literature V. Lialin, V. Deshpande, and A. R. Umshisky; “Scaling down to scaling up: a guide to parameter-efficient fine-tuning”, arXiv: 2303.15647v2, 22. November 2024.

[0091] Pruning can be understood as the process of removing weighted connections in a neural network to reduce the storage size of the ML model and increase its inference speed.

[0092] Based on some examples of this disclosure and reference Figure 3 , Figure 3 It shows that according to Figure 2 Another aspect of the setup is to note the following considerations regarding data distribution. Specifically, to address potentially unknown, arbitrary imbalances in specific data distributions across different client sides, methods such as federated averaging (fedavg) 301, Q-federated averaging (QFedAvg) 302, or federated adam (fedadam) 303 can be used to enhance the data distribution based on... Figure 2 The setting shown is 200. Furthermore, according to some examples of this disclosure, based on... Figure 3 System 300 may include a distribution identifier component on the customer side without exposing the risk of private customer data, and a data-based distribution unifier and / or scaler to address unequal and / or unbalanced distributions. For example, PA-EN customer data and its based models, or model components (e.g., Iora matrices), may be weighted more strongly than PA-PI customer data to account for customer / business ratios, such as EN: 80%, PI: 15%, MP: 5%, where MP may represent an example partitioning of process automation, such as ocean and port.

[0093] Based on some examples of this disclosure, the provided solution is able to:

[0094] - Use federated learning to train AI / ML-based models (e.g., based on...) Figure 1 The AI / ML-based model (EDF 140) simplifies access to private data regarding data from different customers, even from “distributed” customers (in the sense of “probability distribution” as outlined above) and from, for example, EN and PI.

[0095] - Use the PEFT method to efficiently handle training effort, for example, to reduce bandwidth without exposing the ML model;

[0096] - Ensure customer data privacy, that is, during inference using the ML model, no data from the first customer is leaked to the second customer, for example, the ML model was trained on the first customer.

[0097] Therefore, based on some examples of this disclosure, federated generative AI with industry-specific AI / ML models, which are not necessarily base models, are provided for training generative AI models on distributed customer data. An optional step is also provided to check and evaluate the values ​​of the fine-tuning of the overall ML model based on the corresponding customer data at the embedded representation level, in terms of whether to enhance the overall model with “additional knowledge.” Parametrically efficient fine-tuning or equivalent methods are also provided for P&A engineering customers and their (engineering design specifications) data to reduce computational workload and bandwidth on the customer side, ensure customer privacy protection, and provide “mandatory checks” or “reverse RAG” verification.

[0098] Now for reference Figure 4 , Figure 4 A flowchart illustrating a method according to some examples of this disclosure is shown. This method is used to train and utilize ML models on customer engineering data with increased customer privacy protection in an industrial environment. The ML model can be as shown in the reference... Figure 1 EDF 140 shown and / or as referenced Figure 2 The global model 209 is shown. Customer engineering data may include, as referenced... Figure 1 The specification documents shown are 110, 120, and 130.

[0099] This method begins at S400.

[0100] During the training phase of an ML model:

[0101] In S410, the method includes obtaining customer engineering data from customer project data associated with the customer. The customer can be, for example... Figure 1 One of the customers shown, from 201a to 205a.

[0102] In S420, the method involves training an ML model on customer engineering data using federated ML.

[0103] As part of the training in S420, in S420a (referred to as S420a for the sake of clarity that fine-tuning is part of training), the method may optionally include fine-tuning the ML model using fine-tuning methods, such as... Figure 2 The PEFT values ​​(201d, 202d, 203d, 204d, 205d) are shown. For example, according to some examples of this disclosure, if it is determined to be worthwhile, fine-tuning can be performed, as referenced above. Figure 2 and3 As outlined.

[0104] As an additional part of the training in S420, in S420b (designated S420b for the sake of illustrative purposes of understanding that the application is part of the training), the method includes applying customer privacy protection mechanisms to information inferred by the ML model, such as... Figure 2 The DPs shown are (201c, 202c, 203c, 204c, 205c).

[0105] When using ML models for inference:

[0106] In S430, the method includes using an implication check method to verify that information inferred by the ML model and determined by the ML model to be associated with the customer is obtained from customer project data. Figure 2 The example shown for task check 207 is the application of reverse RAG verification.

[0107] This method ends at S440.

[0108] Now for reference Figure 5 , Figure 5 A block diagram schematically illustrating a data processing apparatus 500 according to some examples of the present disclosure is shown. Specifically, according to some examples of the present disclosure, a data processing apparatus 500 is provided for training and using ML models on customer engineering data in an industrial environment, with increased customer privacy protection. The data processing apparatus 500 includes one or more processors 501 configured to perform operations according to... Figure 2 Or the method shown in 3 and / or the execution as described above (refer to the reference). Figure 4 The method described.

[0109] Based on some examples of this disclosure, the data processing device 500 may include, as referenced above. Figure 1 Overview of the device used as EDF 140.

[0110] More specifically, based on various examples, it is configured to execute Figure 4The data processing device 500 of the method may include processing circuitry, processing functions, processing means, processing units, or a processor 501, which enables the data processing device 500 to participate in training and inference of ML models on customer engineering data, wherein customer privacy protection is added in an industrial context. The processor 501 may include one or more processing portions or functions, wherein the processing portions or functions may be provided as one or more physical or virtual entities. The data processing device 500 may include one or more communication interfaces 502. The data processing device 500 may also include a memory or memory unit 503 for storing data, programs, and / or instructions to be executed by the processor. The memory 503 may be internal to the data processing device 500 or external to the data processing device 500, such as at a cloud server. The processor 501 may include one or more portions that enable the data processing device 500 to perform, for example... Figure 4 The method. According to several embodiments of the present invention, the obtaining portion 510 can be configured to according to Figure 4 The S410 performs this operation, and the training portion 520 can be configured to... Figure 4 The S420 performs this training, and the fine-tuning part of the 520a can be configured to... Figure 4 The S420a performs this fine-tuning, and the application section 520b can be configured to adapt to... Figure 4 The S420b executes this application, and the verification section 530 can be configured to... Figure 4 The S430 performs this verification.

[0111] Based on some examples of this disclosure, the various parts of the data processing device 500 can also be understood as means for performing specific functions.

[0112] Based on some examples of this disclosure, a data processing system is provided for training and inferring ML models about customer engineering data in an industrial environment, leveraging enhanced customer privacy protections. The data processing system includes... Figure 5 Data processing equipment 500 and / or including devices for performing operations according to Figure 4 The apparatus for the method. The system can be as follows: Figure 2 and 3 The system shown is 200 or 300.

[0113] Based on some examples of this disclosure, provisions are provided including those based on Figure 5 The data processing equipment 500 and / or the data processing system described above are used in an industrial plant. The industrial plant may be an industrial plant where ML models are trained and / or where trained ML models are used or used for inference.

[0114] Based on some examples of this disclosure, a computer-readable medium including instructions is provided that, when executed by a computing system, cause the computing system to perform the above-mentioned references. Figure 2 Or the method and / or execution described in or as per reference 3 Figure 4 The method described herein. The computer-readable medium may be temporary or non-temporary, volatile or non-volatile.

[0115] Based on some examples of this disclosure, a computer program product including instructions is provided that, when executed by a computing system, enable or cause the computing system to perform the above-mentioned references. Figure 2 Or the method and / or execution indicated in reference 3 Figure 4 The methods outlined herein. A computer program product may include a computer-readable medium that includes instructions for the computer program product. The computer-readable medium described above may store the computer program product thereon.

[0116] According to some examples of this disclosure, use of data processing apparatus 500, data processing system as described above, industrial plant as described above, computer-readable medium as described above, and / or computer program product as described above is provided. In particular, references are provided. Figure 4 The outlined methods are used to train and use ML models in industrial environments with increased protection of customer privacy.

[0117] refer to Figure 2 , 3 The optional features of the methods outlined in 4 may be incorporated into data processing equipment 500, data processing systems, industrial plants, computer-readable media, computer program products and uses, with necessary modifications.

[0118] Any unit, module, circuit, or method described herein may be implemented using hardware, software, and / or firmware configured to perform any of the operations described herein. Hardware may include one or more processor cores, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc. Software may be implemented as software packages, code, instructions, instruction sets, and / or data recorded on at least one transient or non-transient computer-readable storage medium. Firmware may be implemented as hard-coded data in code, instructions, or instruction sets and / or memory devices (e.g., non-volatile memory devices).

[0119] If implemented in software, these functions can be stored on or transmitted on a computer-readable medium as one or more instructions or code on that medium. Computer-readable media includes computer-readable storage media. A computer-readable storage medium can be any available storage medium accessible to a computer. By way of example, and not limitation, such a computer-readable storage medium may include FLASH storage media, RAM, ROM, EEPROM, CD-ROM or other optical disc storage, disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and is accessible to a computer. Disks and optical discs as used herein include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs (BDs), where disks typically reproduce data magnetically, while optical discs typically reproduce data optically using lasers. Furthermore, the propagation of signals can be included within the scope of computer-readable storage media. Computer-readable media also includes communication media, which includes any medium that facilitates the transfer of a computer program from one place to another. For example, a connection can be a communication medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of communication media. Combinations of the above should also be included within the scope of computer-readable media.

[0120] The applicant discloses, in isolation, each individual feature described herein, and any combination of two or more such features, to the extent that such features or combinations can be implemented as a whole based on the description as a whole, according to common general knowledge of those skilled in the art, regardless of whether such features or combinations of features solve any problem disclosed herein, and not to limit the scope of the claims. The applicant notes that aspects of the invention may include any such individual feature or combination of features.

[0121] It should be noted that embodiments of the present invention are described with reference to different categories. In particular, some examples are described with reference to methods, while other examples are described with reference to apparatus. However, those skilled in the art will conclude from the specification that, unless otherwise stated, any combination of features relating to features of different categories, in addition to any combination of features belonging to one category, is also considered to be disclosed in this application. However, all features can be combined to provide more synergistic effects than a simple summation of features.

[0122] While the invention has been detailed and described in the accompanying drawings and the foregoing description, such description is to be considered exemplary rather than limiting. The invention is not limited to the disclosed embodiments. Other variations of the disclosed embodiments will be understood and implemented by those skilled in the art through study of the drawings, the disclosure, and the appended claims.

[0123] The fact that certain measures are described in mutually different dependent claims does not imply that combinations of these measures cannot be used advantageously.

[0124] Any reference numerals in the claims should not be construed as limiting the scope.

Claims

1. A method for training and using machine learning (ML) models on customer engineering data in an industrial environment with enhanced customer privacy protections, the method comprising: During the training phase of the ML model, The customer engineering data is obtained from customer project data associated with the customer (S410); The ML model is trained on the customer's engineering data using federated ML (S420); A customer privacy protection mechanism (S420b) is applied to the information inferred from the ML model. as well as When using the ML model for inference... The information inferred by the ML model and determined by the ML model to be associated with the customer is verified (S430) by using an implication check method, which is used to confirm that the information is obtained from the customer project data.

2. The method according to claim 1, wherein the method further comprises: The ML model is fine-tuned (S420a) using a fine-tuning method. Fine-tuning the ML model using fine-tuning methods includes: fine-tuning the ML model by using one of the following: parameter efficiency fine-tuning PEFT, low-rank adaptive PEFT, LoRA-PEFT, and pruning.

3. The method according to claim 1 or 2, wherein applying the customer privacy protection mechanism includes: Apply one of the following: Differential Privacy DP, Homomorphic Encryption, and Autoencoder.

4. The method according to any one of claims 1 to 3, wherein verification using the implication check method comprises: Verification is performed using one of the following: implication checking based on Natural Language Inference (NLI) and a method for generating RAGs based on inverse retrieval enhancement.

5. The method according to any one of claims 2 to 4, further comprising: Determine whether fine-tuning the ML model is worthwhile for the customer; as well as If it is determined that fine-tuning the ML model is worthwhile, then the fine-tuning of the ML model is performed using the fine-tuning method. If it is expected that the ML model will be enhanced with additional knowledge based on the fine-tuning, then the fine-tuning is deemed worthwhile.

6. The method according to any one of claims 1 to 5, The customer mentioned above is the first customer, and Wherein the customer engineering data and / or the customer project data are associated with the first customer and there is no second customer, and The customer engineering data and / or the customer project data include engineering data from one or more engineering projects from the first customer, but do not include engineering data from engineering projects from the second customer.

7. The method according to any one of claims 1 to 6, wherein the customer engineering data is probability distribution customer engineering data, wherein different information included in the customer engineering data and different information associated with the customer appear with different probabilities in the probability distribution customer engineering data.

8. The method according to claim 7, further comprising: The probability distribution of the customer engineering data is identified by using a distribution identification component; The probability distribution of the customer engineering data is unified and / or scaled by using a data-selection-based distribution unifier and / or a data-selection-based distribution scaler; as well as Train the ML model on customer-engineered data with a uniform and / or scaled probability distribution.

9. The method according to any one of claims 1 to 8, wherein If it is verified that the information was obtained from the customer project data, the method further includes: Provide the aforementioned information, and If it is verified that at least a portion of the information was not obtained from the customer project data, the method further includes: not providing the information.

10. The method of claim 9, wherein the customer is a first customer, and If it is verified that the information was obtained from customer project data associated with the first customer and there is no second customer, the method further includes: Provide the information to the first customer, and If it is verified that at least a portion of the information was obtained from additional customer project data associated with the second customer but not with the first customer, the method further includes: not providing the information to the first customer.

11. A data processing apparatus (500) comprising one or more processors configured to perform the method according to any one of claims 1 to 10.

12. A computer program product comprising instructions that, when executed by a computing system, enable and / or cause the computing system to perform the method according to any one of claims 1 to 10.

13. A computer-readable medium having a computer program product according to claim 12 stored thereon.

14. The use of the ML model obtained during the training phase according to claim 1 for processing customer engineering data in an industrial environment with enhanced customer privacy protection.