Methods for ai / ml model detectability and watermarking

CN122804231APending Publication Date: 2026-09-22INTERDIGITAL PATENT HOLDINGS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480088035.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-12-23
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

这可能导致AI/ML模型的输出不正确或不可靠,或者AI/ML模型的性能的劣化

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122804231A_ABST
    Figure CN122804231A_ABST
Patent Text Reader

Abstract

Various methods, processes, and systems are provided for the detectability and watermarking of artificial intelligence (AI) and / or machine learning (ML) models. A wireless transmit / receive unit (WTRU) receives an AI / ML model, first configuration information for inference, and second configuration information for watermark extraction from a network. The WTRU determines triggering events and / or triggering conditions associated with watermark extraction. The WTRU extracts the watermark from the AI / ML model based on the triggering events. The WTRU transmits watermark information indicating the extracted watermark to the network. The WTRU can jointly perform inference and watermark extraction based on first and second inputs to the AI / ML model. The WTRU can also perform inference and watermark extraction separately. The WTRU can receive a second input from the network. The WTRU can determine the first input based on one or more measurements.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications This application claims the benefit of U.S. Provisional Application No. 63 / 615,011, filed December 27, 2023, the contents of which are incorporated herein by reference. Background Technology

[0002] The use of artificial intelligence (AI) and machine learning (ML) has enabled widespread application across various smart devices. However, concerns regarding the security and accuracy of the various AI / ML models used in these applications have increased. This is because the use of AI / ML models carries the risk of unauthorized access, theft, tampering with the models, or alteration of the data used by the models. This could lead to incorrect or unreliable outputs from the AI / ML models, or degradation of their performance. Furthermore, unauthorized copying or redistribution of proprietary AI / ML models could result in intellectual property (IP) theft. Therefore, the integrity and accuracy of AI / ML models are crucial for maintaining the reliability and security of smart devices and wireless networks. Summary of the Invention

[0003] In various embodiments, a wireless transmit / receive unit (WTRU) is provided. The WTRU includes a memory, a transceiver, and a processor. The transceiver is configured to receive from a network an artificial intelligence (AI) / machine learning (ML) model, first configuration information associated with performing inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model. The transceiver is also configured to transmit the watermark information to the network. The processor is configured to detect the occurrence of at least one triggering event associated with the watermark. The processor is also configured to extract the watermark from the AI / ML model based on at least one triggering event using at least the second configuration information. The processor is further configured to generate watermark information indicating the extracted watermark.

[0004] In various embodiments, a method for use in a WTRU is provided. The method includes receiving an AI / ML model from a network, first configuration information associated with performing inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model. The method also includes detecting the occurrence of at least one triggering event associated with the watermark. The method further includes extracting the watermark from the AI / ML model based on the at least one triggering event using at least the second configuration information. The method also includes sending watermark information representing the extracted watermark to the network.

[0005] In an embodiment, the watermark is embedded in one or more of the following: one or more weights of the AI / ML model, or one or more activation functions of the AI / ML model.

[0006] In this embodiment, the WTRU applies a first input to the AI / ML model to generate an inference output based at least on the first configuration information. The WTRU applies a second input to the AI / ML model to generate watermark information based at least on the second configuration information.

[0007] In this embodiment, the inferred output and watermark information are jointly generated and sent.

[0008] In this embodiment, the inference output and watermark information are generated and sent separately.

[0009] In an embodiment, the second configuration information indicates one or more of the following: watermark type, filtering configuration, preprocessing configuration, or extraction function configuration.

[0010] In an embodiment, the preprocessing configuration indicates one or more processes, including: floating-point precision or fixed-point precision, one or more floor functions or one or more ceiling functions, or one or more permutation modes or one or more interleaving modes.

[0011] In an embodiment, the filtering configuration indicates one or more of the following: one or more coordinates of a watermark, one or more coordinates of one or more activation functions, or one or more threshold weights for selecting one or more weights of an AI / ML model.

[0012] In an embodiment, the extraction function configuration indicates one or more extraction functions, including: a hash function, statistical analysis of the inferred output, a sign extraction function or an amplitude extraction function, a sign flipping function, or a value-based selection function or a threshold-based selection function.

[0013] In this embodiment, WTRU selects one or more weights or one or more activation functions of the AI / ML model based on a filtering configuration. WTRU performs one or more processes on the one or more weights or one or more activation functions based on a preprocessing configuration. WTRU extracts the watermark by applying one or more extraction functions based on an extraction function configuration.

[0014] In an embodiment, detecting the occurrence of at least one triggering event includes receiving from the network an indication of at least one triggering event associated with at least one of the following: monitoring the performance of the AI / ML model, updating the AI / ML model, or one or more network conditions.

[0015] In this embodiment, watermark information is sent to the network using one or more of the following: Media Access Control (MAC) Control Element (CE), Radio Resource Control (RRC) message, or Physical Uplink Control Channel (PUCCH), etc. Attached Figure Description

[0016] A more detailed understanding can be obtained from the following description given by way of example in conjunction with the accompanying drawings, in which the same reference numerals denote the same elements.

[0017] Figure 1A This is a system diagram illustrating an example communication system in which one or more of the disclosed embodiments may be implemented.

[0018] Figure 1B It is shown that, according to the embodiment, it is possible to Figure 1A The system diagram shown is of an example wireless transmit / receive unit (WTRU) used in the communication system.

[0019] Figure 1C It is shown that, according to the embodiment, it is possible to Figure 1A The system diagram shows an example radio access network (RAN) and an example core network (CN) used in the communication system shown.

[0020] Figure 1D It is shown that, according to the embodiment, it is possible to Figure 1A The system diagram shows another example RAN and another example CN used in the communication system shown.

[0021] Figure 2 This is a flowchart of a method for extracting and reporting watermarks according to an embodiment.

[0022] Figure 3 This is a flowchart of an input-based functional watermarking method according to an embodiment, including joint inference and watermarking.

[0023] Figure 4 This is a flowchart of an input-based functional watermarking method according to an embodiment, including separate inference and watermarking.

[0024] Figure 5 This is a diagram of the system architecture according to an embodiment.

[0025] Figure 6 It is a diagram of joint inference and watermarking with implicit watermarking according to an embodiment.

[0026] Figure 7 This is a diagram based on a separate inference and watermark from an embodiment. Detailed Implementation

[0027] As discussed in this paper, one or more abbreviations from the following (non-exhaustive) list shown in Table 1 may be used: ACK confirm BLER Block error rate BWP Bandwidth section CAP Channel access priority CAPC Channel access priority level CCA Free channel assessment CCE Control channel elements CE Control elements CG Configuration permission or cell group CP Cyclic prefix CP-OFDM Standard OFDM (depending on the cycle prefix) CQI Channel quality indicator CRC Cyclic Redundancy Check CSI Channel state information CW Competition window CWS Competition window size CO Channel occupancy DAI Downlink Allocation Index DCI Downlink control information DFI Downlink feedback information DG Dynamic permission DL downlink DM-RS Demodulation reference signal DRB Data radio bearer eLAA Enhanced licensed assisted access FeLAA Further enhanced licensed assisted access HARQ Hybrid Automatic Repeat Request LAA Licensed assisted access LBT Listen first, then speak LTE Long-term evolution, for example, from 3GPP LTE R8 and above NACK Negation ACK MCS Modulation and encoding / decoding schemes MIMO Multiple Input Multiple Output NR New Radio OFDM Orthogonal Frequency Division Multiplexing PHY physical layer PID Process ID PO Paging occasions PRACH Physical Random Access Channel PSS Main synchronization signal RA Random access (or procedure) RACH Random Access Channel RAR Random access response RCU Central Unit of Radio Access Network RF Radio front end RLF Radio link failure RLM Radio link monitoring RNTI Radio network identifier RO RACH occasion RRC Radio Resource Control RRM Radio resource management RS Reference signal RSRP Reference signal received power RSSI Received signal strength indicator SDU Service Data Unit SRS Detection reference signal SS Synchronization signal SSS Auxiliary synchronization signal SWG Switching intervals (in separate subframes) SPS Semi-persistent scheduling SUL Supplement uplink TB Transport block TBS Transfer block size TRP Send / receive point TSC Time-sensitive communication TSN Time-sensitive networking UL uplink URLLC Ultra-reliable and low-latency communication WBWP Wide bandwidth portion WLAN Wireless LAN and related technologies (IEEE 802.xx domain) Table 1.

[0028] Figure 1AThis diagram illustrates an example communication system 100 in which one or more of the disclosed embodiments may be implemented. The communication system 100 may be a multiple access system that provides content such as voice, data, video, messaging, and broadcasting to multiple wireless users. The communication system 100 enables multiple wireless users to access this content by sharing system resources, including wireless bandwidth. For example, the communication system 100 may employ one or more channel access methods, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Zero-Tail Unique Word Discrete Fourier Transform Spread Spectrum OFDM (ZT-UW-DFT-S-OFDM), Unique Word OFDM (UW-OFDM), Resource Block Filtered OFDM, Filter Bank Multicarrier (FBMC), etc.

[0029] like Figure 1A As shown, the communication system 100 may include wireless transceiver units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104, a core network (CN) 106, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112. However, it should be understood that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. For example, WTRUs 102a, 102b, 102c, and 102d (any of which can be referred to as a Station (STA)) can be configured to transmit and / or receive wireless signals and can include User Equipment (UE), mobile stations, fixed or mobile subscriber units, subscription-based units, pagers, cellular phones, personal digital assistants (PDAs), smartphones, laptops, netbooks, personal computers, wireless sensors, hotspots or Mi-Fi devices, Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating on commercial and / or industrial wireless networks, etc. Any of WTRUs 102a, 102b, 102c, and 102d can be interchangeably referred to as a UE.

[0030] The communication system 100 may also include base station 114a and / or base station 114b. Each of base stations 114a and 114b may be any type of device configured to wirelessly interface with at least one of WTRUs 102a, 102b, 102c, and 102d to facilitate access to one or more communication networks (e.g., CN 106, Internet 110, and / or other networks 112). For example, base stations 114a and 114b may be base transceiver stations (BTS), NodeBs, eNodeBs (eNBs), home node Bs, home eNodeBs, next-generation NodeBs (e.g., gNode Bs (gNBs)), new radio (NR) NodeBs, site controllers, access points (APs), wireless routers, etc. Although base stations 114a and 114b are each described as a single element, it should be understood that base stations 114a and 114b may include any number of interconnected base station and / or network elements.

[0031] Base station 114a may be part of RAN 104, and may also include other base stations and / or network elements (not shown), such as base station controllers (BSCs), radio network controllers (RNCs), relay nodes, etc. Base station 114a and / or base station 114b may be configured to transmit and / or receive radio signals on one or more carrier frequencies, which may be referred to as cells (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage of a specific geographic area, which may be relatively fixed or may change over time. A cell may also be divided into cell sectors. For example, the cell associated with base station 114a may be divided into three sectors. Therefore, in an embodiment, base station 114a may include three transceivers, i.e., one transceiver per sector of the cell. In an embodiment, base station 114a may employ multiple-input multiple-output (MIMO) technology and may utilize multiple transceivers for each sector of the cell. For example, beamforming may be used to transmit and / or receive signals in a desired spatial direction.

[0032] Base stations 114a and 114b can communicate with one or more of WTRUs 102a, 102b, 102c, and 102d via air interface 116. Air interface 116 can be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). Any suitable radio access technology (RAT) can be used to establish air interface 116.

[0033] More specifically, as described above, the communication system 100 can be a multiple access system and can employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, etc. For example, base stations 114a and WTRUs 102a, 102b, and 102c in RAN 104 can implement radio technologies such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which can establish an air interface 116 using Wideband CDMA (WCDMA). WCDMA can include communication protocols such as High-Speed ​​Packet Access (HSPA) and / or evolved HSPA (HSPA+). HSPA can include High-Speed ​​Downlink (DL) Packet Access (HSDPA) and / or High-Speed ​​Uplink (UL) Packet Access (HSUPA).

[0034] In the embodiment, base station 114a and WTRUs 102a, 102b, 102c can implement radio technologies such as evolved UMTS terrestrial radio access (E-UTRA), which can use Long Term Evolution (LTE) and / or Advanced LTE (LTE-A) and / or Advanced LTE Pro (LTE-A Pro) to establish air interface 116.

[0035] In the embodiment, base station 114a and WTRUs 102a, 102b, 102c can implement radio technologies such as NR radio access, which can use NR to establish air interface 116.

[0036] In this embodiment, base station 114a and WTRUs 102a, 102b, and 102c can implement multiple radio access technologies. For example, base station 114a and WTRUs 102a, 102b, and 102c can jointly implement LTE radio access and NR radio access, for example, using the dual connectivity (DC) principle. Therefore, the air interface used by WTRUs 102a, 102b, and 102c can be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., eNBs and gNBs).

[0037] In other embodiments, base station 114a and WTRUs 102a, 102b, and 102c can implement radio technologies such as IEEE 802.11 (i.e., Wi-Fi), IEEE 802.16 (i.e., WiMAX), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Provisional Standard 2000 (IS-2000), Provisional Standard 95 (IS-95), Provisional Standard 856 (IS-856), Global System for Mobile Communications (GSM), Enhanced Data Rate GSM Evolution (EDGE), and GSM EDGE (GERAN).

[0038] For example, Figure 1A Base station 114b can be a wireless router, home node B, home eNodeB, or access point, and can utilize any suitable RAT to facilitate wireless connectivity in a local area, such as commercial locations, homes, vehicles, campuses, industrial facilities, air corridors (e.g., for use by drones), roads, etc. In one embodiment, base station 114b and WTRUs 102c and 102d can implement radio technologies such as IEEE 802.11 to establish a wireless local area network (WLAN). In another embodiment, base station 114b and WTRUs 102c and 102d can implement radio technologies such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, base station 114b and WTRUs 102c and 102d can utilize cellular-based RATs (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, etc.) to establish a picocell or femtocell. Figure 1A As shown, base station 114b can be directly connected to Internet 110. Therefore, it is not required that base station 114b access Internet 110 via CN 106.

[0039] RAN 104 can communicate with CN 106, which can be any type of network configured to provide voice, data, application, and / or Voice over Internet Protocol (VoIP) services to one or more of WTRUs 102a, 102b, 102c, and 102d. Data can have different Quality of Service (QoS) requirements, such as different throughput requirements, latency requirements, fault tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, etc. CN 106 can provide call control, billing services, location-based services, prepaid calling, internet connectivity, video distribution, and / or perform advanced security functions such as user authentication. Although in Figure 1AAs not shown, but it should be understood that RAN 104 and / or CN 106 can communicate directly or indirectly with other RANs that use the same RAT as RAN 104 or a different RAT. For example, in addition to connecting to RAN 104, which may utilize NR radio technology, CN 106 can also communicate with another RAN (not shown) that uses GSM, UMTS, CDMA2000, WiMAX, E-UTRA, or WiFi radio technology.

[0040] CN 106 can also serve as a gateway for WTRUs 102a, 102b, 102c, and 102d to access PSTN 108, the Internet 110, and / or other networks 112. PSTN 108 may include a circuit-switched telephone network providing Common Old-Style Telephone Service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices using common communication protocols such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and / or Internet Protocol (IP) from the TCP / IP Internet Protocol suite. Network 112 may include wired and / or wireless communication networks owned and / or operated by other service providers. For example, network 112 may include another CN connected to one or more RANs, which may use the same RAT as RAN 104 or a different RAT.

[0041] Some or all of the WTRUs 102a, 102b, 102c, and 102d in the communication system 100 may include multi-mode capabilities (e.g., WTRUs 102a, 102b, 102c, and 102d may include multiple transceivers for communicating with different wireless networks via different wireless links). For example... Figure 1A The WTRU 102c shown can be configured to communicate with a base station 114a that can employ cellular-based radio technology and with a base station 114b that can employ IEEE 802 radio technology.

[0042] Figure 1B This is a system diagram illustrating example WTRU 102. (See diagram below.) Figure 1B As shown, WTRU 102 may include a processor 118, a transceiver 120, a transmitting / receiving element 122, a speaker / microphone 124, a keyboard 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power supply 134, a Global Positioning System (GPS) chipset 136, and / or other peripheral devices 138, etc. It should be understood that WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with the embodiments.

[0043] Processor 118 can be a general-purpose processor, a special-purpose processor, a conventional processor, a digital signal processor (DSP), multiple microprocessors, one or more microprocessors associated with a DSP core, a controller, a microcontroller, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), any other type of integrated circuit (IC), a state machine, etc. Processor 118 can perform signal encoding / decoding, data processing, power control, input / output processing, and / or any other functions that enable WTRU 102 to operate in a wireless environment. Processor 118 can be coupled to transceiver 120, and transceiver 120 can be coupled to transmitting / receiving element 122. Although Figure 1B While processor 118 and transceiver 120 are described as separate components, it should be understood that processor 118 and transceiver 120 may be integrated together in an electronic package or chip.

[0044] Transmitting / receiving element 122 can be configured to transmit signals to or receive signals from a base station (e.g., base station 114a) via air interface 116. For example, in one embodiment, transmitting / receiving element 122 can be an antenna configured to transmit and / or receive RF signals. In another embodiment, transmitting / receiving element 122 can be a transmitter / detector, for example, configured to transmit and / or receive IR, UV, or visible light signals. In yet another embodiment, transmitting / receiving element 122 can be configured to transmit and / or receive both RF and optical signals. It should be understood that transmitting / receiving element 122 can be configured to transmit and / or receive any combination of wireless signals.

[0045] Although the transmitting / receiving element 122 is in Figure 1B While described as a single element, WTRU 102 may include any number of transmitting / receiving elements 122. More specifically, WTRU 102 may employ MIMO technology. Therefore, in an embodiment, WTRU 102 may include two or more transmitting / receiving elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals via air interface 116.

[0046] Transceiver 120 can be configured to modulate signals to be transmitted by transmitting / receiving element 122 and demodulate signals received by transmitting / receiving element 122. As described above, WTRU 102 can have multi-mode capability. Therefore, for example, transceiver 120 may include multiple transceivers to enable WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11.

[0047] The processor 118 of WTRU 102 can be coupled to a speaker / microphone 124, a keyboard 126, and / or a display / touchpad 128 (e.g., a liquid crystal display (LCD) unit or an organic light-emitting diode (OLED) display unit) and can receive user input data therefrom. The processor 118 can also output user data to the speaker / microphone 124, keyboard 126, and / or display / touchpad 128. Furthermore, the processor 118 can access and store information from any type of suitable memory (e.g., non-removable memory 130 and / or removable memory 132). Non-removable memory 130 may include random access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. Removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital storage (SD) card, etc. In other embodiments, the processor 118 can access and store information from memory that is not physically located on WTRU 102 (e.g., on a server or home computer (not shown)).

[0048] The processor 118 can receive power from the power supply 134 and can be configured to distribute and / or control power to other components in the WTRU 102. The power supply 134 can be any suitable device for powering the WTRU 102. For example, the power supply 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, etc.

[0049] The processor 118 may also be coupled to a GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) about the current location of the WTRU 102. In addition to, or instead of, information from the GPS chipset 136, the WTRU 102 may receive location information from base stations (e.g., base stations 114a, 114b) via air interface 116, and / or determine its location based on the timing of signals received from two or more nearby base stations. It should be understood that the WTRU 102 may acquire location information using any suitable location determination method while remaining consistent with the embodiments.

[0050] The processor 118 may be further coupled to other peripheral devices 138, which may include one or more software and / or hardware modules providing additional features, functions, and / or wired or wireless connectivity. For example, peripheral devices 138 may include accelerometers, electronic compasses, satellite transceivers, digital cameras (for photos and / or video), Universal Serial Bus (USB) ports, vibration devices, television transceivers, hands-free headsets, Bluetooth® modules, FM radio units, digital music players, media players, video game player modules, internet browsers, virtual reality and / or augmented reality (VR / AR) devices, activity trackers, etc. Peripheral devices 138 may include one or more sensors. Sensors may be one or more of the following: gyroscopes, accelerometers, Hall effect sensors, magnetometers, orientation sensors, proximity sensors, temperature sensors, time sensors; geolocation sensors; altimeters, light sensors, touch sensors, magnetometers, barometers, attitude sensors, biosensors, humidity sensors, etc.

[0051] WTRU 102 may include a full-duplex radio for which the transmission and reception of some or all signals (e.g., associated with a specific subframe of both UL (e.g., for transmission) and DL (e.g., for reception)) may be concurrent and / or simultaneous. The full-duplex radio may include an interference management unit to reduce and / or substantially eliminate self-interference via hardware (e.g., a choke) or via signal processing by a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, WTRU 102 may include a half-duplex radio for which the transmission and reception of some or all signals (e.g., associated with a specific subframe of either UL (e.g., for transmission) or DL ​​(e.g., for reception) may be concurrent and / or simultaneous.

[0052] Figure 1C This is a system diagram illustrating RAN 104 and CN 106 according to an embodiment. As described above, RAN 104 can communicate with WTRUs 102a, 102b, and 102c via air interface 116 using E-UTRA radio technology. RAN 104 can also communicate with CN 106.

[0053] RAN 104 may include eNode-Bs 160a, 160b, and 160c; however, it should be understood that RAN 104 may include any number of eNode-Bs while remaining consistent with the embodiments. eNode-Bs 160a, 160b, and 160c may each include one or more transceivers for communicating with WTRUs 102a, 102b, and 102c via air interface 116. In the embodiments, eNode-Bs 160a, 160b, and 160c may implement MIMO technology. Therefore, for example, eNode-B 160a may use multiple antennas to transmit and / or receive radio signals from WTRU 102a.

[0054] Each of the eNode-B 160a, 160b, and 160c can be associated with a specific cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, and user scheduling in the UL and / or DL, etc. Figure 1C As shown, eNode-B 160a, 160b, and 160c can communicate with each other via the X2 interface.

[0055] Figure 1C The CN 106 shown may include a Mobility Management Entity (MME) 162, a Serving Gateway (SGW) 164, and a Packet Data Network (PDN) Gateway (PGW) 166. Although the foregoing elements are described as part of CN 106, it should be understood that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0056] The MME 162 can connect to each eNode-B 162a, 162b, 162c in RAN 104 via the S1 interface and can be used as a control node. For example, the MME 162 can be responsible for authenticating users of WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a specific serving gateway during the initial attachment of WTRUs 102a, 102b, 102c, etc. The MME 162 can provide control plane functions for handover between RAN 104 and other RANs (not shown) employing other radio technologies (such as GSM and / or WCDMA).

[0057] The SGW 164 can connect to each eNode B 160a, 160b, or 160c in RAN 104 via the S1 interface. The SGW 164 can typically route and forward user data packets to / from WTRUs 102a, 102b, or 102c. The SGW 164 can perform other functions, such as anchoring the user plane during inter-eNode B handover; triggering paging when DL data is available for WTRUs 102a, 102b, or 102c; and managing and storing the context of WTRUs 102a, 102b, or 102c.

[0058] The SGW 164 can connect to the PGW 166, which can provide WTRU 102a, 102b, and 102c with access to packet-switched networks such as Internet 110, to facilitate communication between WTRU 102a, 102b, 102c and IP-enabled devices.

[0059] CN 106 can facilitate communication with other networks. For example, CN 106 can provide WTRU 102a, 102b, and 102c with access to a circuit-switched network such as PSTN 108 to facilitate communication between WTRU 102a, 102b, and 102c and traditional landline communication equipment. For example, CN 106 may include, or be able to communicate with, an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) that serves as an interface between CN 106 and PSTN 108. Furthermore, CN 106 can provide WTRU 102a, 102b, and 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers.

[0060] Despite WTRU in Figure 1A-1D While described as a wireless terminal, it is conceivable that, in some representative embodiments, such a terminal may use (e.g., temporarily or permanently) a wired communication interface with a communication network.

[0061] In a representative embodiment, the other network 112 may be a WLAN.

[0062] A WLAN in Infrastructure Basic Services Set (BSS) mode can have an access point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP can access or peer into a distributed system (DS) or another type of wired / wireless network that carries traffic into and / or out of the BSS. Traffic originating outside the BSS destined for a STA can be delivered to the AP via it. Traffic originating from a STA destined for a destination outside the BSS can be sent to the AP for delivery to the appropriate destination. For example, traffic between STAs within the BSS can be sent via the AP, where the source STA can send traffic to the AP, and the AP can deliver traffic to the destination STA. Traffic between STAs within the BSS can be considered and / or referred to as peering traffic. Peering traffic can be sent between source and destination STAs (e.g., directly between them) using Direct Link Establishment (DLS). In some representative embodiments, the DLS can use 802.11e DLS or 802.11z Tunneled DLS (TDLS). A WLAN using the Standalone BSS (IBSS) mode may not have an access point (AP), and STAs within the IBSS or using the IBSS (e.g., all STAs) can communicate directly with each other. The IBSS communication mode is sometimes referred to as the "self-organizing" communication mode in this document.

[0063] When operating in 802.11ac infrastructure mode or a similar mode, the AP can transmit beacons on a fixed channel (e.g., the primary channel). The primary channel can be of a fixed width (e.g., a 20 MHz bandwidth) or a dynamically configured width. The primary channel can be the operating channel of the BSS and can be used by the STA to establish a connection with the AP. In some representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) can be implemented, for example in an 802.11 system. For CSMA / CA, each STA, including the AP, can sense the primary channel. If a particular STA senses / detects and / or determines that the primary channel is busy, that particular STA can back off. A single STA (e.g., only one station) can transmit at any given time within a given BSS.

[0064] High-throughput (HT) STAs can communicate using a 40MHz wide channel, for example, by combining a primary 20MHz channel with adjacent or non-adjacent 20MHz channels.

[0065] Very High Throughput (VHT) STAs can support channels with widths of 20MHz, 40MHz, 80MHz, and / or 160MHz. 40MHz and / or 80MHz channels can be formed by combining consecutive 20MHz channels. A 160MHz channel can be formed by combining eight consecutive 20MHz channels, or by combining two non-consecutive 80MHz channels, which can be referred to as an 80+80 configuration. For the 80+80 configuration, after channel coding, the data passes through a segment resolver, which splits the data into two streams. Each stream can be processed separately using Inverse Fast Fourier Transform (IFFT) and time-domain processing. These streams can be mapped onto the two 80MHz channels, and the data can be transmitted by the transmitting STA. At the receiver of the receiving STA, the operation of the 80+80 configuration described above can be reversed, and the combined data can be sent to the Media Access Control (MAC).

[0066] 802.11af and 802.11ah support operating modes below 1 GHz. The channel operating bandwidth and carrier in 802.11af and 802.11ah are reduced compared to those used in 802.11n and 802.11ac. 802.11af supports 5 MHz, 10 MHz, and 20 MHz bandwidths in the TV Blank (TVWS) spectrum, while 802.11ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz using non-TVWS. According to a representative embodiment, 802.11ah may support metering-type control / machine-type communication (MTC), such as MTC devices in macro coverage areas. MTC devices may have certain capabilities, such as limited capabilities, including supporting (e.g., only supporting) certain and / or limited bandwidths. MTC devices may include batteries with a battery life exceeding a threshold (e.g., to maintain very long battery life).

[0067] WLAN systems that can support multiple channels and channel bandwidths (e.g., 802.11n, 802.11ac, 802.11af, and 802.11ah) include a channel that can be designated as the primary channel. The bandwidth of the primary channel can be equal to the maximum common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel can be set and / or limited by one of the STAs operating in the BSS that supports the minimum bandwidth operating mode. In the 802.11ah example, for STAs that support (e.g., only support) the 1MHz mode (e.g., MTC type devices), the primary channel can be 1MHz wide, even if the AP and other STAs in the BSS support 2MHz, 4MHz, 8MHz, 16MHz, and / or other channel bandwidth operating modes. Carrier Sense and / or Network Allocation Vector (NAV) settings can depend on the status of the primary channel. If the primary channel is busy, for example due to STAs (only supporting the 1MHz operating mode) sending to the AP, all available bands can be considered busy, even if most available bands remain idle.

[0068] In the United States, the available frequency band for 802.11ah is from 902MHz to 928MHz. In South Korea, the available frequency band is from 917.5MHz to 923.5MHz. In Japan, the available frequency band is from 916.5MHz to 927.5MHz. The total available bandwidth for 802.11ah is 6MHz to 26MHz, depending on the country code.

[0069] Figure 1D This is a system diagram illustrating RAN 104 and CN 106 according to an embodiment. As described above, RAN 104 can communicate with WTRUs 102a, 102b, and 102c via air interface 116 using NR radio technology. RAN 104 can also communicate with CN 106.

[0070] RAN 104 may include gNBs 180a, 180b, and 180c; however, it should be understood that RAN 104 may include any number of gNBs while remaining consistent with the embodiments. gNBs 180a, 180b, and 180c may each include one or more transceivers for communicating with WTRUs 102a, 102b, and 102c via air interface 116. In the embodiments, gNBs 180a, 180b, and 180c may implement MIMO technology. For example, gNBs 180a and 180b may utilize beamforming to transmit signals to and / or receive signals from gNBs 180a, 180b, and 180c. Therefore, for example, gNB 180a may use multiple antennas to transmit and / or receive radio signals from WTRU 102a. In embodiments, gNBs 180a, 180b, and 180c can implement carrier aggregation technology. For example, gNB 180a can transmit multiple component carriers (not shown) to WTRU 102a. A subset of these component carriers can be on unlicensed spectrum, while the remaining component carriers can be on licensed spectrum. In embodiments, gNBs 180a, 180b, and 180c can implement Coordinated Multipoint (CoMP) technology. For example, WTRU 102a can receive coordinated transmissions from gNBs 180a and 180b (and / or gNB 180c).

[0071] WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using transmissions associated with scalable digitization. For example, OFDM symbol spacing and / or OFDM subcarrier spacing can vary for different transmissions, different cells, and / or different portions of the radio transmission spectrum. WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using subframes or transmission time intervals (TTIs) of various or scalable lengths (e.g., containing different numbers of OFDM symbols and / or continuously varying lengths of absolute time).

[0072] gNBs 180a, 180b, and 180c can be configured to communicate with WTRUs 102a, 102b, and 102c in standalone and / or non-standalone configurations. In standalone configuration, WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c without simultaneously accessing other RANs (e.g., eNode-Bs 160a, 160b, and 160c). In standalone configuration, WTRUs 102a, 102b, and 102c can utilize one or more gNBs 180a, 180b, and 180c as mobility anchors. In standalone configuration, WTRUs 102a, 102b, and 102c can communicate with gNBs 180a, 180b, and 180c using signals in unlicensed frequency bands. In a non-standalone configuration, WTRUs 102a, 102b, and 102c can communicate / connect with gNBs 180a, 180b, and 180c, while also communicating / connecting with another RAN such as eNode-Bs 160a, 160b, and 160c. For example, WTRUs 102a, 102b, and 102c can implement DC principles to communicate substantially simultaneously with one or more gNBs 180a, 180b, and 180c, as well as one or more eNode-Bs 160a, 160b, and 160c. In a non-standalone configuration, eNode-Bs 160a, 160b, and 160c can be used as mobility anchors for WTRUs 102a, 102b, and 102c, and gNBs 180a, 180b, and 180c can provide additional coverage and / or throughput for serving WTRUs 102a, 102b, and 102c.

[0073] Each of gNBs 180a, 180b, and 180c can be associated with a specific cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, user scheduling in UL and / or DL, network slicing support, interoperability between DC, NR, and E-UTRA, routing user plane data to User Plane Functions (UPF) 184a and 184b, and routing control plane information to Access and Mobility Management Functions (AMF) 182a and 182b, etc. Figure 1D As shown, gNB 180a, 180b, and 180c can communicate with each other via the Xn interface.

[0074] Figure 1DThe CN 106 shown may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. Although the foregoing elements are described as part of CN 106, it should be understood that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0075] AMF 182a and 182b can connect to one or more gNBs 180a, 180b, and 180c in RAN 104 via the N2 interface and can be used as control nodes. For example, AMF 182a and 182b can be responsible for authenticating users of WTRU 102a, 102b, and 102c, supporting network slicing (e.g., handling different Protocol Data Unit (PDU) sessions with different requirements), selecting specific SMF 183a and 183b, managing registration areas, terminating Non-Access Stratum (NAS) signaling, mobility management, and so on. AMF 182a and 182b can use network slicing to customize CN support for WTRU 102a, 102b, and 102c based on the service type used by WTRU 102a, 102b, and 102c. For example, different network slices can be established for different use cases (e.g., services relying on Ultra Reliable Low Latency (URLLC) access, services relying on Enhanced Massive Mobile Broadband (eMBB) access, services for MTC access, etc.). AMF 182a and 182b can provide control plane functions for handover between RAN 104 and other RANs (not shown) that employ other radio technologies (such as LTE, LTE-A, LTE-A Pro and / or non-3GPP access technologies, such as WiFi).

[0076] SMFs 183a and 183b can connect to AMFs 182a and 182b in CN 106 via the N11 interface. SMFs 183a and 183b can also connect to UPFs 184a and 184b in CN 106 via the N4 interface. SMFs 183a and 183b can select and control UPFs 184a and 184b, and configure the routing of services through UPFs 184a and 184b. SMFs 183a and 183b can perform other functions, such as managing and allocating UE IP addresses, managing PDU sessions, controlling policy enforcement and QoS, and providing DL data notifications. PDU session types can be IP-based, non-IP-based, Ethernet-based, etc.

[0077] UPF 184a and 184b can be connected to one or more gNBs 180a, 180b, and 180c in RAN 104 via the N3 interface. This interface can provide WTRU 102a, 102b, and 102c with access to a packet-switched network (e.g., Internet 110) to facilitate communication between WTRU 102a, 102b, 102c and IP-enabled devices. UPF 184 and 184b can perform other functions such as routing and forwarding packets, enforcing user plane policies, supporting multi-destination PDU sessions, handling user plane QoS, buffering DL packets, and providing mobility anchoring.

[0078] CN 106 can facilitate communication with other networks. For example, CN 106 may include, or be able to communicate with, an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) serving as an interface between CN 106 and PSTN 108. Furthermore, CN 106 can provide WTRUs 102a, 102b, and 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers. In an embodiment, WTRUs 102a, 102b, and 102c can be connected to local DNs 185a and 185b via UPFs 184a and 184b through the N3 interface to UPFs 184a and 184b and the N6 interface between UPFs 184a and 184b and DNs 185a and 185b.

[0079] Given Figure 1A-1D as well as Figure 1A-1D As described in the corresponding descriptions herein, one or all of the functions described for one or more of the WTRU 102a-d, base station 114a-b, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF183a-b, DN 185a-b, and / or any other device described herein (one or more) may be performed by one or more emulation devices (not shown). An emulation device may be one or more devices configured to emulate one or more of the functions described herein. For example, an emulation device may be used to test other devices and / or simulate network and / or WTRU functions.

[0080] Simulation devices can be designed to perform one or more tests on other devices in laboratory and / or carrier network environments. For example, one or more simulation devices can perform one or more or all functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network to test other devices within the communication network. One or more simulation devices can perform one or more or all functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network. Simulation devices can be directly coupled to another device for testing and / or testing purposes that can be performed using over-the-air wireless communication.

[0081] One or more emulation devices may perform one or more functions, including all functions, rather than being implemented / deployed as part of a wired and / or wireless communication network. For example, emulation devices may be used in test scenarios outside of deployment (e.g., testing) wired and / or wireless communication networks and / or test laboratories to implement testing of one or more components. One or more emulation devices may be test equipment. Emulation devices may transmit and / or receive data using direct RF coupling and / or wireless communication via RF circuitry (e.g., which may include one or more antennas).

[0082] In various embodiments of this disclosure, one or more methods, systems and / or techniques are provided for detecting one or more artificial intelligence (AI) and / or machine learning (ML) models (referred to as "AI / ML"), for AI / ML watermarking, and / or for multi-vendor AI / ML interoperability.

[0083] In an embodiment, the WTRU may receive a trigger for reporting watermark information associated with an AI / ML model, determine the watermark information in response to the trigger, and send the determined watermark information.

[0084] In an embodiment, the WTRU may receive one or more of the following: a proprietary AI / ML model, first configuration information, and / or second configuration information. The first configuration information may be associated with inference. The second configuration information may be associated with watermark extraction. The WTRU may also receive triggers instructing the sending and / or reporting of watermark information. The WTRU may extract the watermark from the AI / ML model based on at least one of the first or second configuration information. The WTRU may report (e.g., send) the watermark information.

[0085] In an embodiment, the WTRU may receive a first part of the configuration (and / or first configuration information) and a second part of the configuration (and / or second configuration information). The first part of the configuration may be associated with inference, while the second part of the configuration may be associated with a watermark. The WTRU may also receive and / or determine a first part of the input (e.g., a first input) and / or a second part of the input (e.g., a second input). The WTRU may apply the first part of the input (e.g., the first input) and / or the second part of the input (e.g., the second input) to an AI / ML model to determine a first output and a second output. The second output may be a function of the first part of the input (e.g., the first input), the second part of the input (e.g., the second input), and the AI / ML model. The WTRU may report and / or send watermark information based on the second output.

[0086] For one or more WTRUs supporting one or more proprietary AI / ML models (e.g., intra-vendor and / or inter-vendor AI / ML models, etc.), this disclosure describes various embodiments of one or more methods, systems, and / or techniques for watermarking one or more proprietary AI / ML models. In embodiments, methods for detecting the use of one or more proprietary AI / ML models are provided. In embodiments, methods for implementing watermark filtering, extraction, preprocessing, and / or reporting are provided. In embodiments, methods for input-based functional watermarking and / or verification are provided.

[0087] AI can be broadly defined as the behavior exhibited by machines. Behavior can, for example, mimic one or more cognitive functions, such as, but not limited to, sensing, reasoning, adaptation, and / or action.

[0088] ML can refer to a variety of algorithms and / or techniques based on learning from experience (i.e., data) to solve problems without explicit programming (i.e., configuring a set of rules). ML can be considered a subset of AI. Different ML paradigms can be envisioned based on the nature of the data and / or the feedback available for learning algorithms. In examples, supervised learning methods may include learning a function that maps inputs to outputs based on a set of labeled training examples, where each training example can be a pair of inputs and corresponding outputs. In examples, unsupervised learning methods may include detecting one or more patterns in data without pre-existing labels. In examples, reinforcement learning methods may include performing a sequence of actions in an environment to maximize cumulative rewards. In some examples, a combination of the above methods and / or interpolation may be used to apply one or more ML algorithms. In examples, semi-supervised learning methods may utilize a combination of a small amount of labeled data and a large amount of unlabeled data during training. In this case, semi-supervised learning can lie between unsupervised learning (i.e., training data without labels) and supervised learning (i.e., training data with only labels).

[0089] Deep learning (DL) can refer to a class of ML algorithms that employ artificial neural networks (specifically deep neural networks (DNNs)) and can be loosely inspired by various biological systems. DNNs are a special type of ML model inspired by the human brain, where the input is linearly transformed and passed multiple times through one or more non-linear activation functions. DNNs consist of multiple layers, each containing linear transformations and multiple non-linear activation functions. DNNs can be trained using training data via backpropagation. DNNs can be used in various domains, such as speech, vision, and / or natural language processing, and for various ML settings, including supervised, unsupervised, and semi-supervised settings. AI / ML-based methods and / or processes can refer to achieving one or more behaviors and / or fulfilling one or more requirements through data-driven learning without explicit configuration of the sequence of action steps. AI / ML-based methods enable the learning of one or more complex behaviors that may be difficult to specify and / or achieve using conventional methods.

[0090] In AI / ML model transfer, the entities and / or nodes used to train the AI / ML model (e.g., training entities and / or training nodes) may differ from the entities and / or nodes that can be used for inference using the AI / ML model (e.g., inference entities and / or inference nodes). For deployment purposes, the AI / ML model may be stored in entities and / or nodes (e.g., storage entities and / or storage nodes) before being delivered to the inference entities and / or inference nodes. AI / ML model transfer can refer to delivering the AI / ML model from training entities, training nodes, storage entities and / or storage nodes to inference entities and / or inference nodes. AI / ML model transfer can also refer to delivering the AI / ML model from training entities and / or training nodes to storage entities and / or storage nodes. In the example, one or more of the training entities and / or training nodes, storage entities and / or storage nodes, and / or inference entities and / or inference nodes may belong to different vendors and / or manufacturers. In the example, entities and / or nodes can refer to WTRU, gNB, Location Management Function (LMF), Network Data Analysis Function (NWDAF), core network function, and / or logical functions described for one or more AI / ML operations. Different options for AI / ML model transfer can be considered based on signaling format, model format, model storage location, and / or model training location. In the example, the signaling format can be top-down, implementation-based, and / or standardized signaling. In the example, model transfer can use one or more of RRC signaling, Non-Access Stratum (NAS) signaling, LTE Location Protocol (LPP) signaling, and / or User Plane (UP) data. In the example, the model storage location can be outside or within the 3GPP network. In the example, the training location can be the WTRU side, NW side, and / or a neutral (and / or third-party) site. In the example, the AI / ML model can be transferred in proprietary, open, and / or 3GPP-defined formats. When a single AI / ML model cannot be well generalized to multiple scenarios, configurations, and / or sites, AI / ML model migration may be beneficial for handling site-, scenario-, and / or configuration-specific models.

[0091] For proprietary AI / ML models, there are many practical issues and / or aspects related to their deployment. A proprietary AI / ML model is an AI / ML model whose implementation can be protected by the intellectual property (IP) of the owner and / or vendor. This approach can be applied to AI / ML models on the WTRU side, where the owners of the proprietary AI / ML models are different vendors, and it can also be applied to one or more single-sided AI / ML models as well as one or more dual-sided AI / ML models, such as an autoencoder (AE) shared by the encoder and the WTRU.

[0092] In addition, there may be various considerations related to proprietary AI / ML models, including security aspects of sharing proprietary AI / ML models, detectability of the owner's inferences, prevention of model theft, and / or model forgery.

[0093] In this example, the method can be implemented in 5G NR to intelligently manage complex use cases, solve one or more system optimization problems, and / or improve the user experience in 5G systems and other systems. In this example, a functional framework supporting AI-enabled RAN intelligence can be provided within the RAN domain. This AI-enabled intelligence framework can be used in various use cases and / or implementations, such as, but not limited to, network power saving, load balancing, and / or mobility optimization.

[0094] Various use cases can be implemented in 3GPP, such as, but not limited to, CSI feedback enhancement, beam management (BM), and / or positioning. However, for different (existing and future) use cases, there are many practical and exposed problems and challenges in regular 3GPP systems that make the AI / ML framework fully functional. This is because the challenges faced by regular 3GPP systems are related to proprietary and multi-vendor AI / ML models. For example, AI / ML models may not be generalized across different WTRU and / or network (NW) vendors, scenarios, sites, configurations, and other implementation considerations. Therefore, AI / ML models need to be trained at the NW or by a third party before being transferred to the WTRU for inference. To help ensure the security and ownership of AI / ML models from different vendors (such as NW vendors, operators, and / or third parties), AI / ML models are typically obtained through legitimate means, enabling the WTRU to prove and verify access to the AI / ML model. Furthermore, attackers may tamper with AI / ML models, leading to undesirable behavior by the WTRU and impacting not only that specific WTRU but also overall NW performance. Therefore, secure sharing and detection of proprietary AI / ML models are required. Various embodiments of this disclosure provide one or more of the following: secure sharing and detection of proprietary AI / ML models; verification of the transfer and / or access to proprietary model identifiers (IDs); detectability of proprietary AI / ML model usage; prevention of the risk of sharing models between unauthorized and / or unverified devices and / or suppliers; security of proprietary AI / ML models, for example, against model theft and model forgery; and / or protection of proprietary AI / ML models from attacks and model tampering.

[0095] Figure 2 This is a flowchart of a method for extracting and reporting watermarks according to one or more embodiments. The method can be executed by a WTRU. The WTRU can receive a proprietary AI / ML model and first configuration information for inference, and second configuration information for watermark extraction.

[0096] At 210, the WTRU receives a trigger to send watermark information. The WTRU receives a proprietary AI / ML model from the NW. This is because one or more watermark information items can be embedded in (a subset of) model weights and / or activation functions.

[0097] In the example, the watermark information could indicate that the model weights were pruned and / or modified after training (e.g., by flipping the sign, by multiplying them by a factor, and / or by adding a bias, etc.).

[0098] In the example, the watermark information can indicate that during training, the loss function can have a regularizer such that the watermark is applied and captured on a set of weights, and / or the regularizer applies one or more predefined statistical distributions on a set of weights.

[0099] In the example, the watermark information can be embedded in one or more activation functions, which output one or more predefined values ​​when triggered by a pre-configured bit string and / or sequence header, etc.

[0100] In the example, the location (i.e., depth) of the activation function of one or more indices can represent a watermark.

[0101] In the example, the watermark can be based on a WTRU request and / or can be initiated by NW.

[0102] The WTRU can receive first configuration information for inference and second configuration information for watermark extraction. The configuration for watermark extraction (e.g., the second configuration information) can include one or more of the following: watermark type, filtering configuration, preprocessing configuration, and / or extraction function configuration, etc. The watermark type can indicate whether the watermark is embedded in one or more weights and / or embedded in one or more activation functions, etc. The filtering configuration can include one or more of the following: one or more coordinates of the watermark (e.g., one or more depths and / or positions of the weights, etc.); one or more coordinates of the embedding function; and / or one or more magnitude thresholds associated with the selection of a subset of weights (e.g., one or more threshold weights) (e.g., maximum threshold and / or minimum threshold). The preprocessing configuration can include one or more floating-point and / or fixed-point precisions. For example, the WTRU can be configured with specific floating-point precisions, such as half (binary 16), single (binary 32), double (binary 64), and / or binary 128, etc. The WTRU can be configured with specific fixed-point precisions; for example, floating-point numbers (e.g., weights) can be represented by integers multiplied by a fixed scaling factor. Preprocessing configurations may include floor functions and / or ceiling functions. For example, WTRU may be configured with specific floor and / or ceiling functions, such as one or more maximum and / or minimum thresholds (e.g., maximum and / or minimum threshold weights, etc.) that allow filtered values ​​to be replaced with one or more maximum and / or minimum thresholds if one or more weights are higher than and / or lower than thresholds associated with one or more configured ceiling and / or floor functions. Preprocessing configurations may include one or more permutation and / or interleaving patterns. For example, WTRU may be configured with permutations described by permutation vectors and / or matrices.

[0103] In the example, the watermark extraction function configuration may include one or more of the following: hash function (e.g., one or more inputs may be model and / or sub-model parameters, and the output may be the extracted watermark, etc.), one or more statistics of one or more layers (e.g., probability density function (PDF), etc.), sign and / or magnitude extraction function, sign flipping function, and / or value-based (and / or threshold-based) selection function, etc.

[0104] The WTRU can receive triggers that report watermark information. Triggers can be based on one or more conditions determined by the WTRU. In the example, a trigger can be based on performance monitoring (e.g., short-term or long-term performance degradation based on a threshold performance). In the example, a trigger can be based on model selection and / or activation, fine-tuning, model update and / or transfer, and / or fallback to normal, etc. Triggers can be based on one or more mobility events, such as handover (HO), conditional handover (CHO), etc., at the time of a failure event (e.g., beam failure), during initial access (e.g., in msg3 or after RRC connection establishment), and / or during an RRC state change (e.g., RRC recovery), etc. Triggers can be based on indicated reception, such as Media Access Control (MAC) Control Element (CE) and / or aperiodic requests and / or Radio Resource Control (RRC) reconfiguration, etc. Triggers can be based on reporting configuration, such as periodic reporting and / or aperiodic reporting at one or more predefined times or conditions, etc.

[0105] At 220, WTRU determines the watermark based on the configuration (e.g., second configuration information). WTRU can select one or more model weights and / or one or more activation functions by applying filtering based on the filtering configuration. WTRU can perform preprocessing by applying one or more preprocessing functions to one or more selected weights and / or one or more selected activation functions based on the preprocessing configuration. WTRU can extract watermark information by applying one or more extraction functions to one or more preprocessing quantities (e.g., one or more preprocessing weights and / or one or more preprocessing activation functions, etc.).

[0106] At 230, the WTRU reports and sends the watermark information. The WTRU can send the extracted watermark information to the NW. For example, the WTRU can use one or more of the following to send the extracted watermark: MAC CE, Physical Uplink Control Channel (PUCCH), RRC msg (e.g., WTRU Auxiliary Information (UAI), WTRU Uplink (UL) Information, etc.).

[0107] Figure 3 This is a flowchart of a method for an input-based functional watermarking including joint inference / watermarking, according to one or more embodiments. The method can be performed by a WTRU.

[0108] WTRU can receive a first part of the configuration and a second part of the configuration. The first part of the configuration can be associated with inference, while the second part of the configuration can be associated with watermarking. WTRU can apply the first part of the input and / or the second part of the input to an AI / ML model, determine the first output and the second output, and then report the watermark information and the inference output.

[0109] In 310, the WTRU can receive AI / ML models (e.g., proprietary AI / ML models) from the network. The receipt of AI / ML models (e.g., proprietary AI / ML models) can be based on a request sent by the WTRU to the NW and / or can be initiated by the NW.

[0110] The WTRU can also receive configuration for inference. The configuration for inference may include a first input portion and a second input portion. The first input portion may be based on one or more measurements of the WTRU and / or one or more use case-specific inputs, such as the channel matrix in the case of CSI compression.

[0111] The second input portion can be based on NW configuration and / or indication. In the example, the second input portion can indicate a pre-configured signature (and / or the second input can include a pre-configured signature). In the example, the second input can include and / or can indicate one or more of the following: a unique proprietary digital signature, a hash representing a proprietary WTRU vendor, a WTRU-specific signature, and / or a vendor-specific signature, etc. In the example, for example, the second input portion can include and / or can indicate a header or bit string sequence, such as a model-specific header with predefined outputs, and / or a model-specific header as side information, etc. In the example, the second input portion can include and / or can indicate a pseudo-random sequence generated based on the NW configuration. In the example, the second input portion can include and / or can indicate one or more coordinates of one or more specific output units associated with one or more layers, and / or one or more coordinates of one or more specific output units associated with one or more activation functions, etc.

[0112] In the example, the configuration may include parameters (e.g., length) for the first input portion and / or the second input portion.

[0113] In the example, the configuration of the second input portion may include further information associated with the second input portion, such as the length of the bit string header, the quantization type (e.g., uniform or non-uniform), and / or the number of quantization bits, etc.

[0114] In step 320, WTRU can determine the second input portion based on configuration and / or instructions. During inference, WTRU can apply the first and second input portions to the AI / ML model and determine the first and second output portions.

[0115] In the example, the second output can be a function of the second input part, the first input part, and / or the AI / ML model, etc.

[0116] In the example, the second output portion could be the inference output, the output of a SoftMax function (and / or other activation function) layer, the output of one or more pre-configured neurons, and / or the output of one or more pre-configured layers (e.g., add and norm).

[0117] In the example, the second output portion can be watermark information determined by WTRU. In the example, the second output can include one or more scores and / or distributions associated with one or more specific output units, such as one or more SoftMax outputs and / or any other scoring function. In the example, the second output portion can be intermediate inference outputs of one or more activation functions and / or layers.

[0118] In the example, WTRU can apply different quantizations to the first and second outputs. Alternatively, WTRU can apply the default second input portion and discard the report from the second output portion during normal operation.

[0119] In 330, the WTRU can send a first and / or a second output portion to the gNB. In the example, the WTRU can always send the first output portion. The WTRU can determine whether to send the second output portion based on whether a condition (e.g., a trigger condition) is met and / or whether a trigger event occurs.

[0120] Figure 4 This is a flowchart of an input-based functional watermarking method including a separate inference / watermark, according to one or more embodiments. The method can be performed by a WTRU.

[0121] At 410, the WTRU can receive AI / ML models (e.g., proprietary AL / ML models) from the network. WTRU reception can be based on a request sent by the WTRU to the NW and / or can be initiated by the NW. The WTRU can receive two configurations for inference: a first configuration and a second configuration. The first inference configuration can apply inputs (e.g., a first input and / or a first input portion, etc.) based on WTRU measurements and / or use case-specific inputs (e.g., a channel matrix in the case of CSI compression). The second inference configuration can apply inputs (e.g., a second input and / or a second input portion, etc.) based on NW configurations (e.g., a pre-configured signature, header and / or bit string sequence, and / or a pseudo-random sequence generated based on the NW configuration). The pre-configured signature can include and / or indicate a unique proprietary digital signature, a hash representing a proprietary AI / ML model and / or the WTRU vendor, a WTRU-specific signature and / or a vendor-specific signature, etc. The second inference can include and / or may indicate a header and / or bit string sequence, a pseudo-random sequence generated based on the NW configuration, etc.

[0122] The WTRU can receive triggers to send watermark information. In the example, the trigger can be based on one or more conditions determined by the WTRU, examples of which include, but are not limited to, performance monitoring (e.g., short-term and / or long-term performance degradation based on threshold performance); model selection and / or activation; model fine-tuning; model update and / or transfer; fallback to normal; mobile events, such as HO, CHO, etc.; reception based on indications (e.g., MAC CE) once a failure event occurs (e.g., beam failure, etc.), during initial access (e.g., in msg3 and / or after RRC connection establishment); during RRC state changes (e.g., RRC recovery); non-periodic requests; RRC reconfiguration; and / or configurations, such as periodic reporting, etc.

[0123] At 420, upon determining that the watermark triggering condition is met, the WTRU can apply second configuration information (i.e., select one input from multiple inputs based on conditions such as slot number, frame number, and / or a counter for the watermarking process), and at 430, the WTRU can perform inference, and at 440, determine a second output. In the example, when the second input is applied, the second output can be the inferred output, the output of a SoftMax (and / or other activation function) layer, the output of one or more pre-configured neurons, or the output of one or more pre-configured layers (add and norm). The WTRU can apply different quantizations to the second output. At 450, the WTRU can send the second output to the gNB.

[0124] One or more aspects or features disclosed herein are common to some or all of the embodiments disclosed herein. For example, one or more embodiments of detectability of proprietary AI / ML models and / or watermarking of proprietary AI / ML models are described in this disclosure. More specifically, one or more embodiments of methods and / or processes for verifying access, watermark extraction, and watermark reporting are described. Furthermore, one or more embodiments of methods for one or more input-based functional watermarking, and one or more processes for verifying and reporting watermark information are described.

[0125] In the example, a proprietary AI / ML model may include one or more AI / ML models whose owners and / or proprietors may claim intellectual property rights within the AI / ML model. Examples of owners and / or proprietors include single entities such as NW, suppliers, and / or operators. Proprietary AI / ML models may require transfer, copying, sharing, downloading, and / or the use of additional processes.

[0126] In the example, the first input portion may include the inference input of the AI / ML model. The first input portion may include one or more measurements of WTRU that can be processed by the AI / ML model, which may be use case specific (e.g., for CSI enhancement, the first input portion may be the complete original channel matrix and / or the eigenvectors of the channel matrix, etc.).

[0127] In the example, the second input portion may include input to the AI / ML model, which may be associated with a watermark. The second input portion may include watermark extraction input, which can be used to enable the AI / ML model to output a watermark to be reported and / or used to verify access.

[0128] In the example, the first output of the AI / ML model may include and / or may indicate the inferred output. The first output part may be a function of the first input part.

[0129] In the example, the second output of the AI / ML model may include and / or may indicate an output carrying watermark information, which may be reported and / or sent to enable the proprietary AI / ML model to verify WTRU access. The second output portion may be a function of the first input portion, the second input portion, and / or the AI / ML model.

[0130] In the example, the detectability and verification of the AI / ML model can be based on one or more watermarking techniques. Watermarking can include a process of embedding identifying information into some raw data (and / or AI / ML model) to request and / or verify ownership and / or copyright without affecting the use of the data and / or AI / ML model. Watermarking can also be used to achieve detectability of proprietary AI / ML model usage and can leverage different aspects related to how the watermark is embedded in the AI / ML model, verification of access, capacity, authentication, and / or uniqueness.

[0131] In one example, which is an implementation of one or more embodiments described herein, the NW vendor can train a proprietary AI / ML model (which can be one-sided or two-sided). The NW can determine that the use of the AI / ML model at the WTRU needs to be verified and detected. The NW can determine and / or design the content of the watermark by including vendor-specific information and / or training data-related information. The content of the watermark can be linked to auxiliary inputs, i.e., a set of applicable conditions.

[0132] AI / ML models can be shared online and / or offline, and WTRU can be pre-configured with inference inputs and watermarked inputs, and / or can explicitly receive configurations, for example, after model fine-tuning, after model download, and / or after model activation.

[0133] The WTRU may need to verify watermarks and access AI / ML models, which may come from another vendor. The WTRU may perform one or more processes and / or exchange signaling with the NW to achieve AI / ML model verification and initialization via watermark preprocessing and / or postprocessing, watermark filtering and / or extraction, and / or reporting of watermark information.

[0134] The WTRU may or may not receive activation commands for performing inference. Activation commands can be received when the WTRU has verified access to the proprietary AI / ML model. For example, the WTRU may receive activation commands when the verification process is successful, or when the WTRU has been certified and authorized to use the AI / ML model. Deactivation commands can be received in cases where the access verification process fails, such as if the WTRU reports an invalid watermark, if the WTRU is no longer able to access updated and / or fine-tuned models, or if the WTRU vendor is no longer a legitimate vendor using the proprietary AI / ML model.

[0135] The common benefits of one or more embodiments disclosed herein include proprietary AI / ML model detectability (i.e., enabling owners to detect that an AI / ML model is being used by another device and / or vendor), access verification of proprietary AI / ML model use through watermark verification (extraction and / or filtering) and reporting, prevention of model instance theft and unverified sharing, protection of proprietary AI / ML models from model theft and forgery, protection of AI / ML model IP while ensuring accountability, and making access to and use of proprietary models unique to the instance and specific to one or more predefined conditions (e.g., WTRU-specific, vendor-specific, or verified instances of AI / ML models linked to specific applicable conditions).

[0136] Regarding the triggering of watermark determination and / or reporting, in one or more solutions, one or more triggering conditions may refer to one or more events and / or conditions, and WTRU may determine, extract and / or report watermark information based on these events and / or conditions.

[0137] In the example, events and / or conditions can be pre-configured for the WTRU. In more examples, events and / or conditions may include, but are not limited to, one or more of the following: measurement-based conditions, model performance-based conditions, model operation-based conditions, WTRU state-based conditions, and / or WTRU mobility-based conditions, etc.

[0138] In the examples, the WTRU can be configured to determine, extract, and / or report watermark information based on the performance of the AI / ML model. For example, the WTRU can trigger a watermark report when the performance of the AI / ML model falls below a pre-configured threshold. In the examples, the WTRU can trigger a watermark report when the performance change of the AI / ML model exceeds a threshold performance. Threshold performance can be pre-configured for the WTRU and / or the AI / ML model. In the examples, the threshold performance can be configured specifically for the WTRU. In the examples, the threshold performance can be configured specifically for the use case. In the examples, the WTRU can export the performance of the AI / ML model over a pre-configured time period. The WTRU can be configured with one or more conditions associated with short-term and / or long-term performance monitoring. In the examples, the WTRU can be configured with different behaviors associated with watermark reporting based on the type of performance monitoring. For example, the WTRU can be configured to trigger a one-time watermark report when the performance of the AI / ML model based on short-term monitoring falls below a first threshold performance. In another example, the WTRU can be configured to trigger periodic and / or semi-persistent watermark reports when the performance of the AI / ML model based on long-term monitoring falls below a threshold.

[0139] In the examples, the WTRU can be configured to determine, extract, and / or report watermark information based on the operational state of the AI / ML model. In the examples, the WTRU can trigger a watermark report when an AI / ML model is selected for inference, when the AI / ML model is activated, when the AI / ML model is updated, when the AI / ML model is fine-tuned, when a new AI / ML model is downloaded, and when a fallback from an AI / ML model operation to a regular operation is triggered.

[0140] In embodiments, the WTRU can be configured to determine, extract, and / or report watermark information based on mobility events. In examples, the WTRU can trigger watermark reporting upon mobility events including regular handover, conditional handover, and / or Low Layer Triggered Mobility (LTM) events. In examples, the WTRU can be explicitly configured to report watermark information in signaling associated with a mobility process (e.g., in RRC configuration, MAC CE, and / or L1 signaling, etc.). In one solution, the WTRU can be configured to trigger watermark reporting during initial access. In examples, the WTRU can report watermark information in msg3. In embodiments, the WTRU can be configured with one or more AI / ML models for potential activation in RRC reconfiguration messages. The WTRU can determine watermark information upon receiving an RRC reconfiguration message for one or more indicated AI / ML models. The WTRU can report watermark information associated with one or more AI / ML models in an RRC reconfiguration completion message. In examples, the WTRU can trigger watermark reporting upon detecting a radio link failure. In examples, the WTRU can trigger watermark reporting upon detecting a beam failure. In the example, the WTRU can trigger a watermark report based on factors such as radio link monitoring status and / or beam failure instance counters. In the example, the WTRU can trigger a watermark report during an RRC status change. For example, the WTRU can trigger a watermark report during an RRC recovery process. In the example, the WTRU can send watermark information in RRC recovery request and / or RRC recovery complete messages.

[0141] In the example, the WTRU can be configured to determine, extract, and / or report watermark information based on network commands. For example, the WTRU can receive network commands in MAC CE and / or L1 signaling or RRC signaling. In the example, the WTRU can receive indications and / or commands from the gNB and / or network to determine and / or send watermark information associated with one or more AI / ML models. In the example, the WTRU can report watermark information in MAC CE, L1, and / or RRC signaling. If more than one type of watermark information is reported, the WTRU can include one or more identifiers associated with the one or more AI / ML models for which the watermark is sent.

[0142] In the example, the WTRU can be configured to periodically determine, retrieve, and / or report watermark information. For example, the WTRU can be configured to determine, retrieve, and / or report watermark information when timer Tr expires. In the example, the value of timer Tr can be configured by one or more higher-level (e.g., RRC) signaling. In the embodiment, the WTRU can derive the value of timer Tr based on one or more other configurations and / or conditions. In the example, the value of timer Tr can be derived based on the WTRU activity state (e.g., DRX cycle and / or its parameterization).

[0143] In the example, the WTRU can be configured to report watermark information during the security mode command process. For example, when a security mode command is received from the network, the WTRU can derive one or more access stratum (AS) keys. In the example, once the security mode command message has passed the integrity protection check, the WTRU can derive the watermark information. The WTRU can be configured to report the watermark information along with the security mode completion message. In an embodiment, the WTRU can report the watermark information after AS security has been activated.

[0144] Regarding the WTRU process for extracting and / or reporting watermarks, in one example, the watermark may be embedded in the AI / ML model, for example, during the model training process. In another example, the AI / ML model may be trained by the owner by adding vendor-specific inputs and / or digital signatures as side information, where the inferred output produces a fingerprint that can be captured and associated with the proprietary AI / ML model. In yet another example, the watermark may be determined and / or designed after training the AI / ML model, for example, by truncating the AI / ML model based on configuration (e.g., removing a set of layers, activations, and / or neurons, etc.) and / or modifying one or more AI / ML model parameters (e.g., by flipping the sign of one or more configuration weights of the AI / ML model). In another example, the watermark may be captured within the structure of the AI / ML model by adding a specific regularizer to the loss function (which penalizes a set of weights if it exceeds one or more predefined thresholds). One or more weights involved in the trained AI / ML model may have one or more vendor-specific measurements, which may include sign, magnitude, value, and / or statistical distribution, etc.

[0145] Before applying one or more inputs to an AI / ML model and processing them through filtering and / or applying extraction functions, WTRU may apply one or more preprocessing procedures and / or one or more preprocessing functions to one or more inputs. Before reporting the inferred output and watermark information, WTRU may apply one or more postprocessing procedures and / or one or more postprocessing functions to one or more outputs of the AI / ML model.

[0146] Figure 5 It is a diagram of a system architecture according to one or more embodiments.

[0147] In 510, WTRU can receive proprietary AI / ML models, where the reception of proprietary AI / ML models can be initiated by NW and / or based on WTRU requests. In the example, only a subset of the AI / ML model (e.g., one or more parts and / or functions, etc.) can be received, and in another option, the entire AI / ML model can be received, for example, with one or more modified weights.

[0148] In this embodiment, a proprietary watermark can be embedded and / or captured in one or more weights and / or one or more activation functions of a subset of the AI / ML model weights. In the example, after training, one or more model weights can be pruned and / or modified (e.g., by sign flipping and / or by multiplying the model weights by a factor and / or adding bias, etc.) to generate one or more modified weights. In the example, during training, the loss function can have a regularizer that allows watermarking to be implemented and / or captured based on that set of weights, and / or the regularizer applies one or more predefined statistical distributions based on that set of weights. For example, L1, L2, and / or L1 / L2 regularizers can be used in the loss function to adjust the set of weights or maintain the set of weights within a specific range and / or interval.

[0149] In the example, the loss function can be any differentiable function, depending on the use case. In the example, the activation function can generate one or more predefined values ​​when triggered by a pre-configured bit string or sequence header. The location of the activation function at one or more indices (e.g., precise location or approximate location (e.g., depth)) can represent the watermark. For example, the location of a layer in a DNN model can be given by integers indicating the precise coordinates of the layer; for example, in an AI / ML model with two hidden layers and a subsequent activation function layer, the location of the activation function can be given by three (0 for the input layer). More generally, WTRU can be configured with one or more rules and / or parameters to determine a subset of weights from the AI / ML model. In the example, one or more rules can include implicitly and / or explicitly indicating the indices, locations, and / or localizations of the model weight set associated with watermark extraction.

[0150] Upon receiving a proprietary AI / ML model (and / or a subset thereof), the WTRU can be pre-configured and / or can receive first configuration information for inference and second configuration information for watermark extraction. The first inference configuration can be use case-specific, while the second configuration information associated with watermark extraction can include one or more of the following: watermark type, filtering configuration, preprocessing configuration, and / or one or more extraction function configurations.

[0151] For inference, at 520, preprocessing can be applied to the first input. At 530, the AI / ML model can use the preprocessed first input to generate the first output. At 540, postprocessing can be applied to the output to generate the inferred output. In the example, the inferred output can be sent to the NW for authentication and / or verification performed at 570.

[0152] In the examples, watermark types may include, but are not limited to, one or more watermarks embedded in the set of weights, embedded in one or more activation functions, embedded in a sub-model, and / or feature-based embeddings.

[0153] In example 550, the filtering configuration may include one or more coordinates of a watermark, such as the depth and position of weights and / or a set of coordinates. In the example, the filtering configuration may include one or more coordinates of one or more activation functions. In the example, the filtering configuration may include a maximum magnitude threshold and / or a minimum magnitude threshold for selecting one or more subsets of weights. In the example, the filtering configuration may be granular, such as different thresholds associated with different sets of locations. In the example, the filtering configuration may include an indication of a subgraph of the AI / ML model. For example, a subset of the AI / ML model may be indicated in the filtering configuration. In another example, the filtering configuration may include an indication to prune one or more portions of the AI / ML model, i.e., modifying weights by one or more zeros and preserving the remaining subset.

[0154] In the example, preprocessing configurations may include floating-point and / or fixed-point precision, floor and / or ceiling functions, permutation and / or interleaving modes, etc. WTRU can be configured with specific floating-point precision, such as half (binary 16), single (binary 32), double (binary 64), and / or binary 128, etc. WTRU can be configured with specific fixed-point precision; for example, floating-point numbers (e.g., weights) can be represented by integers multiplied by a fixed scaling factor. WTRU can be configured with specific floor and / or ceiling functions; for example, maximum and / or minimum thresholds can be configured such that if one or more weights are higher than and / or lower than one or more thresholds associated with the configured ceiling and / or floor functions, one or more filter values ​​can be replaced with the maximum and / or minimum thresholds. WTRU can be configured with permutations described by permutation vectors and / or matrices, etc.

[0155] In 560, the extraction function configuration may include one or more of the following: hash functions (e.g., hash functions that take model and / or sub-model parameters as input and watermark as input); one or more statistics, such as one or more layers (e.g., PDF, etc.); symbol and / or magnitude extraction functions; symbol flipping functions; and / or value-based and / or threshold-based selection functions, etc.

[0156] In the example, WTRU can determine the watermark from the proprietary AI / ML model by performing selection based on the filtering configuration, and can extract the watermark after performing preprocessing.

[0157] The selection of a watermark can be based on the selection of one or more model weights, layers, and / or activation functions. Selection can be based on one or more coordinates indicated in the filtering configuration, such as indications of one or more layer depths, positions, indices, and / or activation function depths, and / or the exact (or near-exact) locations of one or more neurons within one or more layers. In embodiments, selection can also be based on one or more minimum and / or maximum thresholds for filtering and / or selecting subsets of neurons with one or more weights that are less than and / or greater than one or more corresponding thresholds indicated in the configuration.

[0158] The WTRU can preprocess filtered watermark information. The WTRU can preprocess watermark information by applying one or a set of predefined operators and / or functions. For example, the WTRU can use floor and / or ceiling functions or specific filters, and / or based on floating-point precision limitations included in the preprocessing configuration. In an embodiment, the WTRU can perform preprocessing on filtered watermark information by applying permutation and / or interleaving functions, where one or more function parameters can be included in the preprocessing configuration.

[0159] WTRU can apply a configured extraction function to preprocessed filtered watermark information. In an embodiment, WTRU can apply a configured hash function (received in the extraction function configuration), where the input is the preprocessed watermark information and the output is a hash value and / or hash code computed by the hash function, which maps the input information to a unique hash code (which may be fixed-length and / or variable-length, etc.). In the example, the proprietary AI / ML model can be assumed to be trained on a training dataset with one or more additional inputs from the configuration, where the inputs may be, for example, vendor-specific IDs and / or hashes, and the AI / ML model output depends on the inputs and / or the model, etc.

[0160] In the example, WTRU can apply one or more pre-configured statistical measurements to the pre-processed filtered watermark information, such as the cumulative distribution function (CDF) and / or PDF, measurements of one or more layers, one or more ensembles, or neurons (after preprocessing). In the example, WTRU can use extraction functions based on the sign and / or magnitude of the filtered information, such as a sign-flipping function, a sign-based selection function, and / or a magnitude-based selection function. In the example, WTRU can use extraction functions based on one or more thresholds. WTRU can select values ​​from the filtered watermark information that satisfy one or more pre-configured thresholds. In another example, WTRU can select values ​​within a specific pre-configured interval, where the interval configuration can be included in the extraction function configuration.

[0161] A WTRU can be configured to determine a watermark used to verify the legitimate use of a proprietary AI / ML model. The WTRU can be configured to instruct and / or report extracted watermarks associated with the proprietary AI / ML model. In examples, the watermark report may be referred to as an AI / ML watermark report and / or AI / ML watermark feedback, etc. The watermark report can be periodic, semi-persistent, and / or event-triggered, etc. For example, the WTRU can be configured to send the watermark based on one or more pre-configured triggering events and / or triggering conditions. In examples, triggering conditions may include one or more parameters, such as, but not limited to, when the AI / ML model is switched and / or changed; when one or more parts of the AI / ML model (e.g., one or more weights and / or activation functions) are updated; when the AI / ML model is disabled and reactivated after multiple time slots; when the performance of the AI / ML model changes due to one or more pre-configured threshold performance (e.g., increases or decreases); and / or based on a successful RRC configuration. In embodiments, the WTRU can be configured to report watermark information based on one or more triggers described herein.

[0162] In the examples, the extracted watermarks can be sent and / or indicated in different formats. For instance, the format in which watermark information is reported and / or sent can depend on the watermark extraction configuration. In one example, if a filter-based configuration is used for watermark extraction, the watermark can be reported in a first watermark report format, such as an index from one of several predefined indices associated with the filter configuration. In another example, if a preprocessing-based configuration is used, the watermark can be reported in a second watermark report format, such as the identifier of the extracted interleaving pattern.

[0163] In one example, the WTRU can be configured to report the extracted watermark in a feedback message. The WTRU can report the extracted watermark in a MACCE. In another example, the WTRU can report the watermark in an L1 feedback (e.g., on a PUCCH resource). In another example, the WTRU can report the extracted watermark in one or more PUSCH resources. In yet another example, the WTRU can send watermark feedback via uplink control information (UCI). In yet another example, watermark information can be reported in an RRC message. In this example, watermark feedback can be associated with multiple watermarks, where each watermark can be associated with a different proprietary AI / ML model.

[0164] The WTRU can be configured to receive verification as a response to the indicated watermark. For example, the WTRU can receive an activation command. An activation command can be received if the reported watermark is valid, i.e., the watermark verification process is successful. The WTRU can use an AI / ML model to perform inference upon receiving the activation command. In another embodiment, the WTRU can receive a deactivation command in the event of verification failure, such as when the reported watermark is no longer valid and / or the reported watermark is incorrect. This may mean that the WTRU cannot use the AI / ML model for inference. The WTRU can be configured to attempt to re-extract and resend the watermark information a second time. In another option, the WTRU can be configured with a maximum number of watermark feedback instances and / or reports. If the WTRU fails to extract the watermark within the allowed maximum number of attempts, the WTRU may not be allowed to use the AI / ML model and / or attempt to extract the watermark within a given amount of time.

[0165] During operation, the WTRU can receive a proprietary AI / ML model and first configuration information for inference, as well as second configuration information for watermark extraction. The WTRU can also receive triggers to send watermark information. The WTRU can determine the watermark based on the configuration. Upon receiving a trigger, the WTRU can report the watermark information.

[0166] WTRU can receive AI / ML models and / or proprietary AI / ML models from NW. One or more watermarking information can be embedded in one or more model weights (and / or subsets of model weights) and / or one or more activation functions. In the example, after training, one or more model weights can be pruned and / or modified (e.g., by sign flipping and / or by multiplying one or more weights by a factor and / or adding bias to one or more weights). In the example, during training, the loss function can have a regularizer that allows watermarking to be implemented and / or captured on that set of weights, and / or the regularizer implements one or more predefined statistical distributions on that set of weights. In the example, when triggered by a pre-configured bit string and / or sequence header, the embedded activation function can output one or more predefined values. In the example, the location (i.e., depth) of the activation function at one or more indices can represent the watermark. Reception of one or more AI / ML models and / or one or more proprietary AI / ML models can be based on a WTRU request and / or can be initiated by NW.

[0167] The WTRU can receive first configuration information for inference and second configuration information for watermark extraction. The watermark extraction configuration may include one or more of the following: watermark type, filtering configuration, preprocessing configuration, and / or extraction configuration.

[0168] The watermark type can be embedded in one or more weights and / or in one or more activation functions. The filtering configuration may include one or more coordinates of the watermark (e.g., the depth and / or position of one or more weights), one or more coordinates of one or more embedding functions, and / or magnitude thresholds for selecting a subset of weights (e.g., maximum magnitude threshold and / or minimum magnitude threshold, etc.).

[0169] Preprocessing configurations can include floating-point and / or fixed-point precision. In the example, WTRU can be configured with one or more specific floating-point precisions, such as half (binary 16), single (binary 32), double (binary 64), binary 128, etc. WTRU can be configured with one or more specific fixed-point precisions; for example, floating-point numbers (e.g., weights) can be represented by integers multiplied by a fixed scaling factor. WTRU can be configured with specific floor and / or ceiling functions; for example, maximum and / or minimum thresholds can be configured such that if one or more weights are higher than and / or exceed the maximum and / or minimum thresholds associated with the configured floor and / or ceiling functions, one or more filter values ​​are replaced with the maximum and / or minimum thresholds. WTRU can be configured with permutations described by permutation vectors and / or matrices.

[0170] Extraction function configurations can include hash functions (inputs can be model and / or sub-model parameters, and outputs can be watermarks), statistics for one or more layers (e.g., PDF…), sign and / or magnitude extraction functions, sign flipping functions, value-based and / or threshold-based selection functions, etc.

[0171] The WTRU can receive triggers to send watermark information. Watermark reports can be initiated by the WTRU based on one or more conditions, such as, but not limited to, performance monitoring (e.g., short-term and / or long-term performance degradation based on threshold performance), model selection and / or activation, fine-tuning, model update and / or transfer, fallback to normal, such as one or more mobility events (e.g., but not limited to HO, CHO, etc.), failure events (e.g., beam failure, etc.), initial access (e.g., in msg3 and / or after RRC connection establishment, etc.), RRC state change (e.g., RRC recovery, etc.), NW trigger (e.g., MAC CE), non-periodic requests, RRC reconfiguration, and / or periodicity.

[0172] In the example, WTRU can select one or more model weights and / or one or more activations by applying filtering based on the filtering configuration, thereby determining the watermark. In the example, WTRU can perform preprocessing on one or more selected weights based on the preprocessing configuration; and / or extract watermark information by applying an extraction function to the amount of preprocessing. In the example, WTRU can send the extracted watermark in MAC CE, PUCCH, and / or RRC msg (e.g., UAI and / or WTRU UL information), etc.

[0173] Watermarks can be embedded in AI / ML models so that the model's output can indicate watermark information when predefined values ​​are applied as input. In the example, the embedding can be applied during the AI / ML model training process. For example, the model can be trained by an owner by adding vendor-specific inputs and / or digital signatures as side information items. The inference output can generate a fingerprint that can be captured and / or associated with a proprietary AI / ML model. In the example, the watermark can be determined and / or designed after the AI / ML model has been trained, for example, by truncating the AI / ML model according to its configuration (e.g., removing sets of layers, activations, and / or neurons), and / or modifying the AI / ML model parameters (e.g., by flipping the sign of the configuration weights of the AI / ML model). In the example, the NW can embed a predetermined input header, digital signature, and / or hash representing the watermark, where the watermark information can be captured in the model output. Furthermore, in the example, the watermark captured in the output can be compressed using a pre-configured hash function, and only the hash code can be reported.

[0174] WTRU can be configured with an AI / ML model enabled for watermarking. The AI / ML model for watermarking can be configured to receive a single input vector and / or multiple input vectors and / or one or more input vectors with multiple parts.

[0175] In the example, the AI / ML model at the WTRU can be configured to receive two input vectors and / or tensors (i.e., receiver inputs in both parts). The first input part can be application- and / or task-specific and can represent inputs specific to the task for which the AI / ML model is trained. For example, the AI / ML model can be configured for a CSI compression task, and the first input can be a CSI tensor. In another example, the AI / ML model can be trained to perform a CSI prediction task, and the first input can be a set of multiple past CSI tensors. The second input part can be associated with enabling watermarking operations and / or can be configured by the network and / or can be configured and / or defined by an entity that has ownership and / or title to the AI / ML model.

[0176] In one embodiment, the second input portion at the WTRU can be configured as a unique proprietary digital signature associated with a specific AI / ML model. In another embodiment, the digital signature can be specific to the WTRU and / or specific to the WTRU vendor.

[0177] In the example, the network can be configured with an input sequence that can be preprocessed at the WTRU using a mapping function defined by the network to receive a second input to the AI / ML model.

[0178] In the example, the second input portion at WTRU can be configured as a sequence of bit strings. The bit strings can be model-specific headers with predefined outputs, or they can include model-specific side information.

[0179] In an embodiment, the second input portion may be a part of the AI / ML model (e.g., one or more additional weights, biases, and / or masks, etc.), which can activate the AI / ML model and / or enable the regular operation of the AI / ML model.

[0180] In the example, the WTRU can be configured with a second input portion, where the input can be a pseudo-random sequence generated by the network using network configuration as a seed and / or using one or more environmental parameters (e.g., channel state, signal-to-noise ratio (SNR), Doppler and / or delay spread, etc.) as a seed.

[0181] In an embodiment, the WTRU may be configured with a second input portion, which may serve as an indication of one or more coordinates and / or positions of one or more specific output units associated with one or more specific layers. Alternatively, the input may serve as an indication of one or more coordinates and / or positions of one or more specific output units associated with one or more activation functions.

[0182] Furthermore, the WTRU can be configured with the length of a first input and / or a first input portion, and the length of a second input and / or a second input portion. These lengths can be fixed and / or variable and / or reconfigurable after configuration. The WTRU can receive configurations in RRC signaling (e.g., RRC establishment and / or RRC reconfiguration, etc.).

[0183] Furthermore, the second input portion can be configured to use one or more additional error-correcting bits for quantization and / or potentially for protection and / or encoding. Therefore, the WTRU can be configured to decode and / or undo any quantization and / or error-correcting information. Configuration may include quantization type (e.g., scalar quantization, vector quantization, uniform quantization, and / or non-uniform quantization), length, and / or number of bits, etc.

[0184] Figure 6 It is a graph with a joint inference / watermarking having an implicit watermark according to one or more embodiments. Figure 6 The diagram illustrates an AI / ML model 610, a first input 620, a second input 630, and an output 640. In this example, the AI / ML model 610 at the WTRU can be configured to receive only one input vector and / or tensor at a given time. The WTRU can also be configured to perform two inferences using two different model inputs (the first input 620 and / or the second input 630). The first input 620 can relate to the application and / or task associated with the AI / ML model 610. For example, for an AI / ML-based CSI compression task, the first input 620 could correspond to a CSI tensor. The second input 630 can relate to evaluating watermark information. The network can configure the second input 630 at the WTRU as a unique proprietary digital signature specifically assigned by the network for the WTRU and / or the AI / ML model 610 and / or the vendor. Alternatively, the network can configure the second input 630 at the WTRU as a header and / or bit string sequence and / or a pseudo-random sequence.

[0185] For joint inference and / or watermarking, the AI / ML model 610 on the WTRU side can use the second configuration information to determine the second input 630. The WTRU can use the second input to perform inference. During inference, the WTRU can apply the first input 620 and / or the second input 630 and determine an output 640 including a first output portion and a second output portion. The first output portion can be the inference output, and the second output portion can be a function of the second input portion, the first input portion, and / or the AI / ML model 610, etc.

[0186] In the example, the second output can be an inferred output, where the watermark can be implicitly captured in the output. In an embodiment, the proprietary AI / ML model can be trained on a dataset using specific (e.g., NW and / or vendor-specific) side information and / or one or more additional inputs. The side information can be a watermark configuration included in the second configuration information. In another example, the proprietary AI / ML model can be trained on a dataset with different configurations and / or combinations of one or more configurations or one or more applicable conditions. Watermark verification can be scenario-specific and can provide different watermarks unique to the instance as defined by one or more applicable conditions at the WTRU. In this case, the WTRU can first report one or more applicable conditions before triggering the watermark verification process and receiving the second part of the configuration. In another embodiment, the side information can be WTRU-specific and / or WTRU vendor-specific, thereby achieving instance-specific uniqueness and more robust detectability of the watermark.

[0187] In another example, the second output portion may be the output of a predetermined activation function, such as one or more SoftMax scores. In this example, the activation function and / or the index of the activation unit may be indicated in the configuration. In another example, during inference, the WTRU may include the output of one or more specific layers and / or units in the second output portion. In this example, the output of one or more pre-configured neurons (e.g., one or more indices of one or more neurons) may be indicated in the second configuration information. Further examples include the output of one or more pre-configured layers; the WTRU may be configured to have greater granularity, e.g., to output one or more subsets of different layers of an AI / ML model; symbols for one or more sets of processing units (neurons), etc.

[0188] In another embodiment, the watermark information can be captured and explicitly reported. For example, AI / ML can be trained in a way that systematically correlates the watermark information with the inferred output. In an embodiment, the WTRU can be configured to apply post-processing, such as copying and / or interleaving a second part of the output.

[0189] The WTRU can apply different quantization functions to the first and second output portions. In an embodiment, the WTRU can receive a quantization configuration (e.g., uniform or non-uniform quantization bits) for each output portion (i.e., for inferring the output and / or watermark information reporting output).

[0190] In this embodiment, the WTRU may be configured with a default second input portion containing a watermark, such as WTRU and / or vendor-specific, for use when the WTRU is not triggered to report watermark information. In this embodiment, the WTRU may disable the reporting process for the second output during normal operation. In this case, the WTRU can use the first input portion and / or the default second input portion to perform inference and can output the inference result. The WTRU may activate such reporting if it is not triggered to report the watermark, for example, when access verification is not required, and / or when the WTRU has been authenticated.

[0191] For standalone inference / watermarking, the WTRU may not be required to implicitly and / or send the watermark during inference. In an embodiment, before applying the AI / ML model for inference, the WTRU may apply first configuration information to a proprietary AI / ML model to generate watermark information. The WTRU may apply a second inference configuration, wherein the WTRU may select an input from multiple inputs based on one or more predefined conditions, such as, but not limited to, slot number, frame number, and / or sliding window.

[0192] In the example, the WTRU can be configured with a set of time slot numbers, each with a different input for the watermark. The WTRU can report the time slot number and then apply a second inference configuration corresponding to the second inference input.

[0193] In the example, the WTRU can be configured statically or dynamically with multiple frames, each with equal or different lengths. The WTRU can select an input based on the current frame. The WTRU can be configured with a dynamic frame counter that increments after each watermark verification of the AI / ML model. The WTRU can use the frame counter to move frames and / or switch the second inference input based on the new frame.

[0194] For a sliding window, such as one based on an incrementing counter as the second inference input is applied to the model, WTRU can slide the window accordingly to select a new second inference input.

[0195] WTRU can perform inference using selected inference inputs and can determine a second output for capturing the watermark. For example, the second output can be one or more of the following: inference output, the output of any one or more pre-configured intermediate layers (e.g., activation functions and / or layers), one or more outputs of one or more pre-configured neurons, etc. In the example, the second output could be the statistical distribution of one or more layers, such as the CDF and / or PDF of one or more layers. Assuming the inference input for watermark verification is configured by the model owner, the owner can know the statistical distribution. One or more layers and granularity for reporting statistical measurements can be indicated in the second inference configuration.

[0196] In an embodiment, the WTRU may use different quantization methods on the second inference output before reporting the watermark information. Using different quantization methods can achieve more robust protection of the watermark. In the example, the WTRU may receive a second inference configuration, which may include a quantization configuration. In an embodiment, the quantization method (and / or quantization scheme) may be dynamically configured relative to channel conditions and / or one or more applicable conditions of the WTRU. In another embodiment, the WTRU may choose appropriate quantization without reporting one or more conditions.

[0197] Figure 7 It is a figure with a separate inference / watermark based on one or more embodiments. Figure 7 The diagram shows an AI / ML model 710, an input 720 based on second configuration information, and watermark information 730 as the output of the AI / ML model 710.

[0198] The WTRU can perform joint and / or individual inference / watermarking. The WTRU can report watermark information 730 and inference output. In an embodiment, the WTRU can be configured to report watermark information 730 upon receiving one or more triggers.

[0199] When the WTRU is triggered to determine and report a watermark, the WTRU can report a first output portion (e.g., inferred output) and a second output portion (e.g., including the extracted watermark). The WTRU can indicate one or more parameters associated with the first and / or second output portions to the NW. In an example, the indication may include one or more of the following: whether the second output portion is included in the report, the size (length) of the first output portion, the size (length) of the second output portion, the quantization type and / or quantization bit depth of the first output portion, the quantization type and / or quantization bit depth of the second output portion, and the type of the reported second output portion (e.g., the output of one or more predetermined activation functions and / or the output of one or more specific layers, etc.).

[0200] The WTRU may use one or more UL permissions to report the second output portion (e.g., watermark information) and parameter indications via a UL data channel (e.g., PUSCH). The first output portion may be reported using one or more configured measurement reporting mechanisms.

[0201] When one or more trigger conditions are not met, the WTRU can report the first output portion (i.e., the inferred output) to the NW. In the example, when one or more trigger conditions are met, the WTRU can report the second output portion (i.e., the watermark information) to the NW. In the example, when one or more trigger conditions are met and the reported instances of the first output portion overlap, the WTRU can report both the first and second output portions (i.e., the watermark information) to the NW.

[0202] When the WTRU performs inference and watermark extraction respectively, the WTRU can report the second output portion (e.g., the watermark extracted using the second inference configuration). The WTRU can (e.g., additionally) send indications of one or more parameters associated with the second output portion. Indications may include one or more of the following: the size (length) of the second output portion, conditions that trigger watermark transmission, and / or the quantization type and quantization bit depth of the second output portion. For example, upon receiving UL approval, the WTRU can use the uplink data channel to report the second output portion and / or one or more associated parameters via indications.

[0203] When the WTRU receives an indication from the NW that the watermark has been correctly verified, the WTRU can apply a first inference configuration and perform inference on a first input portion (e.g., one or more WTRU measurements, such as, but not limited to, the original channel matrix and / or channel eigenvectors). The WTRU can report the corresponding inference output (i.e., the first output portion) to the NW.

[0204] In operation, the WTRU can receive a first part configuration and a second part configuration for inference, where the second part configuration can be associated with a watermark. The WTRU can apply the first and second part inputs to an AI / ML model, determine the first and second outputs, and then report the watermark information and the inference output.

[0205] In the joint inference / watermarking method, the WTRU can receive an AI / ML model (e.g., a proprietary AI / ML model) from the network based on a WTRU request and / or upon NW initiation. The WTRU can receive a configuration for inference. The configuration may include a first input portion and a second input portion. The first input portion may be based on one or more WTRU measurements and / or one or more use case-specific inputs, such as a channel matrix in the case of CSI compression. The second input portion may be based on the NW configuration, such as a pre-configured signature (e.g., a unique proprietary digital signature), a hash representing the owner and / or WTRU vendor, a WTRU-specific signature or vendor-specific signature, a header or bit string sequence (e.g., an AI / ML model-specific header with predefined outputs, and / or a model-specific header as a side information item, a pseudo-random sequence generated based on the NW configuration, one or more coordinates of one or more specific output units associated with one or more layers, and / or one or more coordinates of one or more specific output units associated with one or more activation functions, etc.).

[0206] The configuration may include the lengths of the first and second parts. The configuration of the second part may include other information related to the second part, such as the length of the bit string header, the quantization type (e.g., uniform or non-uniform), the number of quantization bits, etc.

[0207] WTRU can determine the second input based on the second configuration information.

[0208] During inference, WTRU can apply the first and second input components to the AI / ML model and determine the first and second output components. The second output can be a function of the second input component, the first input component, and / or the AI / ML model.

[0209] The second output can be the inference output, the output of a SoftMax (and / or other activation function) layer, the output of one or more pre-configured neurons, and / or the output of one or more pre-configured layers (add and norm).

[0210] WTRU can explicitly report watermarks, such as one or more scores and / or distributions associated with one or more specific output units (e.g., SoftMax outputs and / or any other scoring functions), and / or one or more activation functions and / or intermediate inference outputs of one or more layers.

[0211] WTRU can apply different quantizations to the first and second parts. WTRU can apply the default second input part and / or discard the second output part report during normal operation, and perform a watermark reporting process when a trigger condition is detected.

[0212] The WTRU can send both the first and second output portions to the gNB. In the example, for instance, if the WTRU is not triggered, the second output portion may not need to be sent.

[0213] In operation, during standalone inference / watermarking, the WTRU can receive an AI / ML model (e.g., a proprietary AI / ML model) from the network based on a WTRU request and / or be initiated by the NW. The WTRU can receive two configurations for inference, including a first inference configuration and a second inference configuration.

[0214] The first inference configuration may apply the first input based on one or more WTRU measurements and / or one or more use case-specific inputs (e.g., the channel matrix in the case of CSI compression).

[0215] The second inference configuration can apply the second input based on the NW configuration. The second inference configuration may include one or more of the following: a pre-configured signature (e.g., a unique proprietary digital signature), a hash representing the owner and WTRU vendor, a WTRU-specific signature, a vendor-specific signature, a header or bit string sequence, and / or a pseudo-random sequence generated based on the NW configuration.

[0216] The WTRU can receive triggers to send watermark information. The WTRU can initiate watermark reporting based on conditions (e.g., based on performance monitoring (e.g., short-term or long-term performance degradation based on thresholds), based on model selection and / or activation, based on fine-tuning, based on model updates and / or transfers, based on fallback to normal, such as based on mobility events (e.g., HO, CHO, etc.), failure events (e.g., beam failure), during initial access (e.g., in msg3 and / or after RRC connection establishment), and / or during RRC state changes (e.g., RRC recovery), based on NW triggers (e.g., MAC CE or non-periodic requests or RRC reconfiguration), and / or periodically, etc.).

[0217] Upon receiving and / or detecting the occurrence of a watermark trigger condition, the WTRU may apply a second inference configuration (i.e., select one input from multiple inputs based on the watermark trigger condition, such as a slot number and / or frame number and / or counter for the watermarking process), perform inference, and / or determine a second output.

[0218] When a second input is applied, the second output can be the inferred output, the output of a SoftMax (and / or other activation function) layer, the output of one or more pre-configured neurons, and / or the output of one or more pre-configured layers (add and norm). WTRU can apply different quantizations to the second output. WTRU can send the second output to gNB. WTRU can apply a first inference configuration, perform inference, determine a first output, and send the output to gNB.

[0219] Although the features and elements have been described above in specific combinations, those skilled in the art will understand that each feature or element can be used alone or in any combination with other features and elements. Furthermore, the methods described herein can be implemented in a computer program, software, or firmware, which is contained in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted via wired or wireless connections) and computer-readable storage media. Examples of computer-readable storage media include, but are not limited to, read-only memory (ROM), random access memory (RAM), registers, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, magneto-optical media, and optical media such as CD-ROMs and digital multifunction discs (DVDs). A processor associated with the software can be used to implement a radio frequency transceiver used in a WTRU, UE, terminal, base station, RNC, or any host computer.

Claims

1. A wireless transceiver unit (WTRU), comprising: processor; and Transceiver, wherein the processor and transceiver are configured as follows: The system receives an artificial intelligence (AI) / machine learning (ML) model from the network, first configuration information associated with performing inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model. Detect the occurrence of at least one triggering event associated with the watermark. Using at least a second configuration information, extract the watermark from the AI / ML model based on the occurrence of at least one detected triggering event. Generate watermark information indicating the extracted watermark, and Send the watermark information to the network.

2. The WTRU of claim 1, wherein the watermark is embedded in one or more of the following: One or more weights of the AI / ML model, or One or more activation functions for an AI / ML model.

3. The WTRU according to claim 2, wherein, The processor is also configured to: The first input is applied to the AI / ML model to generate inference output based at least on the first configuration information, and The second input is applied to the AI / ML model to generate watermark information based at least on the second configuration information.

4. The WTRU of claim 3, wherein the inferred output and watermark information are jointly generated and transmitted.

5. The WTRU according to claim 3, wherein the inference output and the watermark information are generated and sent respectively.

6. The WTRU according to claim 3, wherein, The second configuration information indicates one or more of the following: Watermark type Filter configuration, Preprocessing configuration, or Extract function configuration.

7. The WTRU of claim 6, wherein the preprocessing configuration indicates one or more processes comprising: Floating-point precision or fixed-point precision One or more floor functions or one or more ceiling functions, or One or more permutation patterns or one or more interleaving patterns.

8. The WTRU of claim 7, wherein the filtering configuration indicates one or more of the following: One or more coordinates of the watermark, One or more coordinates of one or more activation functions in an AI / ML model, or One or more threshold weights are used to select one or more weights for the AI / ML model.

9. The WTRU of claim 8, wherein the extraction function configuration indicates one or more extraction functions, comprising: Hash function, Statistical analysis of inference output, Symbol extraction function or magnitude extraction function sign-flipping function, or Value-based selection functions or threshold-based selection functions.

10. The WTRU according to claim 9, wherein, The processor is also configured to: Based on the filtering configuration, select one or more weights or one or more activation functions for the AI / ML model. Based on the preprocessing configuration, one or more procedures are performed on one or more weights or one or more activation functions, and Watermarks can be extracted by applying one or more extraction functions based on the extraction function configuration.

11. The WTRU of claim 1, wherein detecting the occurrence of at least one triggering event comprises receiving from the network an indication of at least one triggering event associated with one or more of the following: Monitor the performance of AI / ML models. Update AI / ML models, or One or more network conditions.

12. The WTRU of claim 1, wherein the watermark information is sent to the network using one or more of the following: Media Access Control (MAC) Control Element (CE). Radio Resource Control (RRC) message, or Physical Uplink Control Channel (PUCCH) resources.

13. A method for use in a wireless transmit / receive unit (WTRU), the method comprising: Receive an artificial intelligence (AI) / machine learning (ML) model from the network, first configuration information associated with performing inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model; Detect the occurrence of at least one triggering event related to the watermark; Use at least a second configuration information to extract watermarks from AI / ML models based on at least one triggering event; and Send watermark information to the network indicating the watermark to be extracted.

14. The method of claim 13, wherein the watermark is embedded in one or more of the following: One or more weights of the AI / ML model, or One or more activation functions for an AI / ML model.

15. The method according to claim 14, further comprising: The first input is applied to the AI / ML model to generate inference output based at least on the first configuration information; and The second input is applied to the AI / ML model to generate watermark information based at least on the second configuration information.

16. The method of claim 15, wherein the inferred output and the watermark information are jointly generated and transmitted.

17. The method of claim 15, wherein the inference output and the watermark information are generated and sent respectively.

18. The method of claim 15, wherein the second configuration information includes one or more of the following: Watermark type Filter configuration, Preprocessing configuration, or Extract function configuration.

19. The method according to claim 18, further comprising: Based on the filtering configuration, select one or more weights or one or more activation functions of the AI / ML model; Based on the preprocessing configuration, perform one or more procedures on one or more weights or one or more activation functions; and Watermarks can be extracted by applying one or more extraction functions based on the extraction function configuration.

20. The method of claim 13, wherein detecting the occurrence of at least one triggering event comprises receiving from the network an indication of at least one triggering event associated with one or more of the following: Monitor the performance of AI / ML models. Update AI / ML models, or One or more network conditions.