Accounting privacy budgeting in a network and scheduler help in enhancing privacy
Patent Information
- Application Number
- PCT/IB2024/061301
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-17
- Filing Date
- 2024-11-13
- Publication Date
- 2025-07-03
AI Technical Summary
Existing communication systems face challenges in ensuring data privacy during service requests in a network, particularly in federated learning scenarios, where the privacy of user equipment (UE) data is at risk due to the processing of service requests.
The implementation of a method where user equipment (UE) transmits a privacy budget to the core network function, which selects the UE capable of processing service requests while maintaining guaranteed privacy. This involves determining whether the privacy cost of processing a service request exceeds the privacy budget, and either processing the request or requesting an increased privacy budget if necessary.
This approach effectively enhances privacy in communication networks by ensuring that service requests are only processed within the predetermined privacy budget, thereby protecting user data and maintaining privacy guarantees.
Smart Images

Figure IB2024061301_03072025_PF_FP_ABST
Abstract
Description
[0001] ACCOUNTING PRIVACY BUDGETING IN A NETWORK AND SCHEDULER HELP IN ENHANCING PRIVACY FIELD The present application relates to a method, apparatus, system and computer program for performing accounting privacy budgeting in a network and in particular, but not exclusively to, a method, apparatus, system and computer program for performing accounting privacy budgeting in a network during training of a model using federated learning. BACKGROUND A communication system can be seen as a facility that enables communications between two or more entities such as terminals, and / or other nodes, or provides connected services to entities. A communication system can include communication networks and one or more compatible terminals (otherwise known as communication devices). Communications may carry, for example, voice, video, electronic mail (email), text message, multimedia data and / or content data and so on. Non-limiting examples of connected services provided by the communications system may comprise enhanced mobile broadband, ultra-reliable low latency communications, mission-critical communications, massive internet of things (IoT), and multimedia services. In a communication system at least a part of communications between at least two entities occurs over a wireless link. Examples of networks in a communication system are public land mobile networks (PLMN), radio access networks such as terrestrial radio access networks or non-terrestrial radio access networks (e.g., satellite networks) and different wireless local networks, for example wireless local area networks (WLAN). Radio access networks can include cells and are therefore often referred to as cellular networks. A terminal may be referred to as user equipment (UE) or user device. A terminal is provided with an appropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other terminals. The terminal may access a carrier provided by a base station, for example a base station of a radio access network, and transmit and / or receive communications on the carrier. A communication system and associated compatible terminals typically operate in accordance with a given standard or specification which sets out what various network entities of the communication system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for communications are also typically defined. Fourth generation (4G) wireless mobile telecommunications technology, also known as Long Term Evolution (LTE) technology, was designed to provide high-capacity mobile multimedia with high data rates particularly for human interaction. Next generation or fifth generation (5G) technology is intended to be used not only for human interaction, but also for machine type communications in so-called Internet of Things (IoT) networks. While 5G networks are intended to enable massive IoT services (e.g., very large numbers of limited capacity devices) and mission-critical IoT services (e.g., requiring high reliability), improvements over legacy mobile communication services are supported in the form of enhanced mobile broadband (eMBB) services providing improved wireless Internet access for mobile devices. In an example communication system, user equipment (5G UE in a 5G network or, more broadly, a UE) such as a mobile terminal (subscriber) communicates over an air interface with a base station or access point of an access network referred to as a 5G AN in a 5G network. The access point (e.g., gNB) is illustratively part of an access network of the communication system. For example, in a 5G network, the access network referred to as a 5G AN is described in 5G Technical Specification (TS) 23.501, entitled “Technical Specification Group Services and System Aspects; System Architecture for the 5G System,” and TS 23.502, entitled “Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS),” the disclosures of which are incorporated by reference herein in their entireties. In general, the access point (e.g., gNB) provides access for the UE to a core network (CN or 5GC), which then provides access for the UE to other UEs and / or a data network such as a packet data network (e.g., Internet). TS 23.501 goes on to define a 5G Service-Based Architecture (SBA) which models services as network functions (NFs) that communicate with each other using representational state transfer application programming interfaces (Restful APIs). Furthermore, TS 33.501, entitled “Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System,” the disclosure of which is incorporated by reference herein in its entirety, further describes security management details associated with a 5G network. Security management is an important consideration in any communication network environment. However, due to continuing attempts to improve the architectures and protocols associated with a 5G network in order to increase network efficiency and / or subscriber convenience, security management issues associated with data exchanged in the communication network environment can present a significant challenge. For example, implementing data privacy algorithms in the communication network environment is a technical challenge. SUMMARY According to an aspect, there is provided an apparatus for a user equipment implementing privacy guarantees with respect to service requests from a communications network for supplying data, the apparatus comprising means for: transmitting to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receiving a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtaining the privacy cost associated with the processing of the service request; determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. The means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget may be for: when the privacy cost associated with the processing of the service request is greater than the privacy budget: requesting a privacy budget tolerance increase request for the network function; obtaining an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. The means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget may be for: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: performing the service request to generate data; transmitting the generated data to the network function; and transmitting to the core network function an updated privacy budget based on the privacy cost. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. The apparatus may comprise or may be comprised in the user equipment. According to a second aspect there is provided an apparatus for a core network function for controlling privacy in communications network, the apparatus comprising means for: receiving from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receiving from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmitting to the at least one network function a list of user equipment comprising user equipment for processing the service request. The means may be further for transmitting to the at least one network function privacy budget information associated with user equipment on the list of user equipment. The means may be further for receiving at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. The apparatus may comprise or may be comprised in the core network function. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. According to a third aspect there is provided an apparatus for a network function for generating service requests for data from at least one user equipment within a communications network, the network function comprising means for: transmitting to a core network function a discovery request associated with a service request for data from at least one user equipment; receiving from the core network function a list of user equipment comprising user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. The means may be further for receiving from the core network function privacy budget information associated with user equipment on the list of user equipment. The means may be further for: receiving a privacy budget tolerance increase request from at least one user equipment; and transmitting an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. The means for selecting and / or scheduling at least one user equipment from the list of user equipment may be for at least one of: randomly selecting and / or scheduling the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. The core network function may be a unified data management (UDM). The apparatus may comprise or may be comprised in the network function. The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. According to a fourth aspect there is provided a method for a user equipment implementing privacy guarantees with respect to service requests from a communications network for supplying data, the method comprising: transmitting to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receiving a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtaining the privacy cost associated with the processing of the service request; determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. Processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget may comprise: when the privacy cost associated with the processing of the service request is greater than the privacy budget: requesting a privacy budget tolerance increase request for the network function; obtaining an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. Processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget may comprise: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: performing the service request to generate data; transmitting the generated data to the network function; and transmitting to the core network function an updated privacy budget based on the privacy cost. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. The apparatus may comprise or may be comprised in the user equipment. According to a fifth aspect there is provided a method for an apparatus for a core network function for controlling privacy in communications network, the method comprising: receiving from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receiving from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmitting to the at least one network function a list of user equipment comprising user equipment for processing the service request. The method may further comprise transmitting to the at least one network function privacy budget information associated with user equipment on the list of user equipment. The method may further comprise receiving at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. The method may be comprised in the core network function. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. According to a sixth aspect there is provided a method for an apparatus for a network function for generating service requests for data from at least one user equipment within a communications network, the method comprising: transmitting to a core network function a discovery request associated with a service request for data from at least one user equipment; receiving from the core network function a list of user equipment comprising user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. The method may further comprise receiving from the core network function privacy budget information associated with user equipment on the list of user equipment. The method may further comprise: receiving a privacy budget tolerance increase request from at least one user equipment; and transmitting an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. Selecting and / or scheduling at least one user equipment from the list of user equipment may comprise at least one of: randomly selecting and / or scheduling the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. The core network function may be a unified data management (UDM). The method may be comprised in the network function. The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. According to a seventh aspect there is provided an apparatus for a user equipment configured to implement privacy guarantees with respect to service requests from a communications network for supplying data, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receive a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtain the privacy cost associated with the processing of the service request; determine whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. The apparatus caused to process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget may be caused to: when the privacy cost associated with the processing of the service request is greater than the privacy budget: request a privacy budget tolerance increase request for the network function; obtain an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. The apparatus caused to process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget may be caused to: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: perform the service request to generate data; transmit the generated data to the network function; and transmit to the core network function an updated privacy budget based on the privacy cost. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. The apparatus may comprise or may be comprised in the user equipment. According to an eighth aspect there is provided an apparatus for a core network function configured to control privacy in communications network, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receive from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimate a privacy budget or cost associated with processing the service request; determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmit to the at least one network function a list of user equipment comprising user equipment for processing the service request. The apparatus may be further caused to transmit to the at least one network function privacy budget information associated with user equipment on the list of user equipment. The apparatus may be further caused to receive at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. The apparatus may comprise or be comprised in the core network function. The core network function may be a unified data management (UDM). The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. According to a ninth aspect there is provided an apparatus for a network function configured to generate service requests for data from at least one user equipment within a communications network, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit to a core network function a discovery request associated with a service request for data from at least one user equipment; receive from the core network function a list of user equipment comprising user equipment for processing the service request; select and / or schedule at least one user equipment from the list of user equipment; and transmit to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. The apparatus may be further caused to receive from the core network function privacy budget information associated with user equipment on the list of user equipment. The apparatus may be further caused to: receive a privacy budget tolerance increase request from at least one user equipment; and transmit an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. The apparatus caused to select and / or schedule at least one user equipment from the list of user equipment may be caused to perform at least one of: randomly select and / or schedule the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; select and / or schedule the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or select and / or schedule the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. The core network function may be a unified data management (UDM). The apparatus may comprise or be comprised in the network function. The network function may be one of: a core network model training function; or a radio access network model training function. The core network model training function may be a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). The service request may comprise one of: a federated learning model request; a training data request; or a collaborative training request. The privacy budget may comprise one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. According to some further aspects there is provided a computer readable medium comprising program instructions for causing an apparatus to perform at least the methods as disclosed above. According to some additional aspects there is provided a system comprising means for: receiving a privacy budget, wherein the privacy budget is a parameter defining how much data is acceptable to transmit; transmitting a discovery request associated with a service request for data; receiving a discovery request associated with a service request for data; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget; transmitting a list of user equipment for processing the service request; receiving the list of user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. A system comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive a privacy budget, wherein the privacy budget is a parameter defining how much data is acceptable to transmit; transmit a discovery request associated with a service request for data; receive a discovery request associated with a service request for data; estimate a privacy budget or cost associated with processing the service request; determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget; transmit a list of user equipment for processing the service request; receive the list of user equipment for processing the service request; select and / or schedule at least one user equipment from the list of user equipment; and transmit to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. An apparatus comprising means for performing the actions of the method as described above. An apparatus configured to perform the actions of the method as described above. A computer program comprising program instructions for causing a computer to perform the method as described above. A computer program product stored on a medium may cause an apparatus to perform the method as described herein. According to an aspect, there is provided a non-transitory or a transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method according to any of the preceding aspects. In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above. DESCRIPTION OF FIGURES Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which: Fig. 1 shows a representation of a network system according to some example embodiments; Fig. 2 shows a representation of a control apparatus according to some example embodiments; Fig.3 shows a representation of an apparatus according to some example embodiments; Figs. 4a to 4c show a signaling framework showing communicating and managing a UE total privacy budget with the network; and Figs. 5 and 6 show graphs of example scheduling improvements in privacy budget control; Fig. 7 shows a schematic view of an example gNB comprising scheduler and DP according to some embodiments; Fig.8 shows a schematic view of an example DP as shown in Fig.7; and Figs.9 to 11 show a schematic view of example schedulers as shown in Fig.7 according to some embodiments. DETAILED DESCRIPTION In the following certain embodiments are explained with reference to apparatuses capable of communication with a communication system serving such apparatuses. Before explaining in detail the exemplifying embodiments, certain general principles of a communication system, for example a 5G communication system, that includes an access network (AN) and a core network, and apparatuses (e.g., terminals served by the communication system are briefly explained with reference to Figures 1, 2 and 3 to assist in understanding the technology underlying the described examples. Figure 1 shows a schematic representation of a 5G wireless communication system (5GS). The 5GS may be comprised of a radio access network (RAN) (e.g., a 5G radio access network (5G-RAN) or a next generation radio access network (NG-RAN), a 5G core network (5GC), one or more application functions (AFs) and a more data network (DN). In some embodiments, an AF is a customer of the 5GC and is connected to a user plane function (UPF) of the 5GC via the DN and to network functions (NFs) of the 5GC via a network exposure function (NEF) of the 5GC. In some embodiments, the AF is a trusted application function and hence the trusted AF is implemented in the 5GC and connected to directly to other NFs of the 5GC. The AF may include functionality to perform training using federated learning and to select terminals (such as the UE) connected to the 5GC that participate in FL as described in further detail below. It will be appreciated that although only one UPF is shown in Figure 1, the 5GS may be composed of a chain of UFPs that include a UPF anchor that connects to the DN. The connections between the AF and the NEF and the UPF (or the AF and the NFs of the 5GC, are via interfaces defined in the 3GPP standard. The 5GC may comprise for instance the following network functions (NFs) (otherwise referred to as network entities): Network Slice Selection Function (NSSF); Network Exposure Function (NEF); Network Repository Function (NRF); Network Data Analytics Function (NWDAF), Policy Control Function (PCF); Unified Data Management (UDM); Authentication Server Function (AUSF); an Access and Mobility Management Function (AMF); and Session Management Function (SMF). The NFs of the 5GC may have a service-based architecture as described in TR 23.501 of the 3GPP standard. NF services that may be offered by the NFs of the 5GC and service-based interfaces for the NFs of the 5GC are described in 3GPP standard, and in particular in TR 23.501 and 23.502 of the 3GPP standard. Access to the 5GC by terminals may be done more generally via an access network, such as a 5G radio access network (5G-RAN). The 5G-RAN may comprise one or more base stations (e.g., gNodeBs (gNBs)). The gNBs of the 5G-RAN may include a gNB distributed unit connected to a gNB central unit, and remote radio heads connected to the gNB distributed units. In some embodiments, the one or more base stations of the 5G-RAN may be Evolved NodeB eNodeB (eNB). In some embodiments, the 5G-RAN may be a 3GPP radio access network (e.g. a RAN that operates using NR or LTE radio access technology as defined in the 3GPP standard). Although Figure 1 illustrates a 5G-RAN, it will be appreciated by a person skilled in the art that access to the 5GC may be done via any wireless or wired access network, such as a non-3GPP access network (e.g., an untrusted wireless local area network (WLAN) which access the 5GC via a Non-3GPP Interworking Function (N3IWF), a trusted WLAN which accesses the 5GC via a Trusted Non-3GPP Gateway Function (TNGF), or a wireline network which accesses the 5GC via a Wireline Access Gateway function (W-AGF)). A non-3GPP access network is an access network that is not configured to communicate directly with a core network with an architecture and operations defined in the 3GPP standard. Figure 2 illustrates an example of an apparatus 200 that may implement one or more NFs of the 5GC illustrated in Figure 1. The apparatus 200 may comprise at least one random access memory (RAM) 211a, at least one read only memory (ROM) 211b, at least one processor 212, 213 and a network interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211b. The at least one processor 212, 213 may be configured to execute software code 215. The software code 215 may for example include instructions to perform actions or operations of one or more NFs of the 5GC. In some embodiments, the software code 215 may include instructions to perform one or more actions or operations related to federated learning (FL) or privacy budget control in accordance with aspects of the present disclosure. The software code 215 may be stored in the ROM 211b. The apparatus 200 may implement one or more NFs of the 5GC and may be interconnected with another apparatus 200 implementing one or more other NFs of the 5GC. In such embodiments, the apparatuses 200 may be part of a distributed computing system. In some embodiments, each NF of the 5GC may be implemented on a single apparatus 200. In such embodiments, the apparatus 200 may be a cloud computing system. Figure 3 illustrates an example of an apparatus 300 illustrated on Figure 1. The apparatus 300 may be any wireless communication device capable of sending and receiving radio signals. Non-limiting examples of an apparatus 300 comprise a terminal, a wireless communication device, user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (IoT) communication device or any combinations of these or the like. The apparatus 300 may be configured to communicate with base stations (e.g., a NG-eNB or a gNB) of an access network, such as the 5G-RAN and the 5GC via the base stations of the 5G-RAN using non-access stratum (NAS) signalling, for example, to communicate of data. The communications may include or carry one or more of voice, electronic mail (email), text message, multimedia, data, machine data and so on. The apparatus 300 may receive wireless signals (e.g., radio or cellular signals) over an air or radio interface 307 (generally referred to as a Uu interface) via appropriate apparatus 306 for receiving the wireless signals and may transmit wireless signals e.g., radio or cellular signals) via appropriate apparatus for transmitting the wireless signals. In Figure 3 the apparatus 306 includes one or more antennas (or an antenna array comprising a plurality of antennas) and a transceiver and is designated schematically by block 306. The apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement comprising one or more antennas. The antenna arrangement may be arranged internally or externally to the mobile device. The apparatus 300 may include at least one processor 301, at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access networks, such as the 5G-RAN, and other apparatuses 300. The at least one processor 301 is coupled to the RAM 311a and the ROM 311b. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example include instructions which when executed by the at least one processor 301 perform one or more actions or operations of present aspects. The software code 308 may be stored in the ROM 311b. The at least one processor 301, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 304. The terminal 300 may optionally have a user interface such as key pad 305, touch sensitive display screen or touch sensitive pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device. Control or configuration of such communication systems has conventionally been implemented by control mechanisms which operate based on defined rules. To improve network performance (i.e., perform of networks in a communication system, such as a 5GS), control mechanisms implementing machine learning (ML) models have been proposed wherein network and / or management data from many network entities of the communication system can be processed by the ML models to generate suitable control outputs for such communication systems. Training of a machine learning (ML) model is centralized. The network and / or management data is collected by network entities (generally referred to as distributed nodes) and provided to one single network entity (generally referred to as a central node) to use the received data to train the ML model. To minimize the amount of data exchanged between distributed nodes and the central node (where the training of a model (generally referred to as model training hereinafter) is usually implemented) and to reduce loss of privacy of data for each node, a model can be trained using Federated Learning (FL). In FL, instead of training a model at the central node using the centralized data, the central node provides a global model comprising parameters or data to the distributed nodes and each of the distributed nodes performs local training of a local model (referred to hereinafter a local model training) using a dataset comprising data of the distributed node during an iteration of FL. In other words, each distributed node has a dataset (referred to hereinafter as a local dataset) and trains a local model using its own local dataset (i.e., performs local model training). In the following disclosure the terms local training and local model training are interchangeable. For each iteration of FL each distributed node then sends its local training results (e.g., the ‘learned’ parameters of its local model) to the central node. During each iteration of FL, the central node receives local training results for the local models from the distributed nodes and combines or aggregates the local training results to obtain new global model parameters or data (global training results for the global model). The local training results may comprise values for the parameters of the local models and the global training results may comprise aggregated values for the parameters of the global model. The new global model parameters or data (e.g., the aggregated received local training parameter values) can then, in a further iteration of FL, be sent to the distributed nodes and the distributed nodes use these ‘new’ global model parameters as the parameters of their local models and perform further local training of the local models to learn new local model parameters. This process can be repeated until the values of parameters of the global model are optimized. The process of training the local models at the different distributed nodes is known to persons skilled in the art and is thus not described in further detail. For example Federated learning, and local and global models are described further within Konecný, Jakub, H. B. McMahan and Daniel Ramage. “Federated Optimization: Distributed Optimization Beyond the Datacenter.” ArXiv abs / 1511.03575 (2015). As mentioned above one issue which is addressed but not absolutely solved is one of guaranteeing privacy with respect to information provided by the device or UE (for example the information in the form of the local model provided by the UE). One approach to attempt to measure and control privacy and privacy leakage (where over time the UE provides enough information that enables a third party to identify the UE or determine information considered to be private by the user of the UE) is differential privacy. Differential privacy (DP), as discussed in Dwork, C., McSherry, F., Nissim, K. and Smith, A. Calibrating noise to sensitivity in private data analysis. Theory of cryptography conference 2006. was originally proposed to provide a formal guarantee of privacy in cases where commonly used anonymization techniques (such as k-anonymity and l-divergence) are not sufficient or cannot be employed. DP is a statistical technique which when employed with respect to an algorithm or data guarantees that the privacy of individuals in the data set stays protected no matter how the output of the algorithm or the data is further processed. The original motivation for proposing this strong definition of privacy came from the observation that combining data from different sources can break privacy. A DP guarantee provides a mathematical upper bound for the risk of leaking information about an individual data source. The DP guarantee allows a precise level of acceptable individual level risk to be quantified. DP is described using probability theory and mathematically the definition can be as follows. Two data sets X and Y are neighbours if it is possible to obtain one by replacing a single data entry in the other. Let ^ > 0 and ^ ∈ [0,1] (^ and δ are DP parameters). A randomisedfunction ^^^^ ∶ ^^ → ℝ is ^^, ^^-DP or if for every pair of neighbouring data sets X andY and for every outcome ^ ⊂ ℝ there is:ℙ^^^^^ ∈ ^^ ≤ ^^ℙ^^^^^ ∈ ^^ + ^.The parameter ^ can be interpreted as the probability of a total data breach, and the smaller the ^, the less probable it is to tell whether the output originated from ^ or ^. In other words, the smaller the values of ^ and ^ the less probable it is to notice the presence of any individual and the mechanism is more privacy-preserving. When ^ = 0, then the DP mechanism is specified as ^-DP. Consider, for example, arandomised response: If the data output is a lie yes / no answer with probability 0.5, it is possibleto calculate that the above definition is satisfied for ^ = log 3. If the probability of lying pincreases, privacy increases and ^ get smaller (specifically, then ^ = log^^^ ^ ^. In some cases we have to allow non-zero ^ (e.g. when adding Gaussian noise). In discrete output randomized functions where the data is described by integers 1,…,n, and the private mechanism M takes as an input data and randomly outputs !, such that the data ! is output probability "#$. Then the mechanism M is ^-DP for ^= m^*(+$ax# m (,a #x ) log^). * + This formula can be interpreted that for all outputs !, ^^gives an upper bound for the ratio of probabilities for the output originating from^and,. If this ratio is close to 1 (i.e., if ^ is close to 0), the given any pairs of inputs^and,, the eavesdropping adversary cannot tell where the output originated from. In other words this provides a very strong definition of privacy (this worst-case adversary is very strong). Additionally the DP mechanism maintains this same statistical protection for all post-processing of this randomization, i.e., no matter how the output is processed, the adversary cannot distinguish whether the output originated from^or,with more certainty than is described by the parameter ^. The following examples describe how DP can be employed to assist preserving the privacy of users while allowing data sets comprising privacy sensitive information to be disclosed by the UEs (for example by contributing data sets, with added random noise, to a machine learning (ML) solution such as federated learning (FL)). In the following examples the privacy budget of each device or UE is considered. The privacy budget for each UE comprising a total amount of information leakage which is allowed for one or more types of data sets. In some examples an amount of noise to be added can be determined based ondifferential privacy (DP), in particular on ^^, δ^-DP, wherein smaller values of ^ correspond toa smaller privacy loss when disclosing a data set protected by DP, and smaller values of δ correspond to a smaller probability of drastic privacy loss such as enabling discovery of entire original data sets. Smaller values of ^ and δ also correspond to lower statistical accuracy of the disclosed data compared to the original data. There is broad consensus that ε values in the low single digits (i.e.0 < ε < 5) represent a conservative choice, and provides strong privacy protection. Furthermore larger ε values (i.e. 5 < ε < 20) also can provide robust privacy protection in a variety of settings and additionally in some contexts, even higher values of ε (i.e. ε > 20) may still provide meaningful privacy protection, In the examples discussed herein a network function (NF) / application function (AF) (e.g. NWDAF), is configured to collect data from UEs or other entities in the network which produce or possess privacy sensitive data. The collected data is processed, and the results of the processing is shared with a third party, other UEs, or more generally the public. Since the processed data, for example an AI / ML model, can leak information, a privacy enhancing technology (PET) based on Differential Privacy (DP) monitoring can be employed, for each release of the data, or function of the data. This monitoring can measure privacy leakage by^^, δ^-DP. The smaller the values of ^^, δ^ the less data is leaked. For instance, if a UEparticipates in FL training of a centralized model, the leakage of total privacy would be theaggregation of all the instances of data releases with ^^, δ^-DP. The monitoring and control asdiscussed herein can be called privacy budgeting. In these examples a privacy budget is a parameter that a UE (or any entity which takes part in UDMs data collection for any NF / AF purpose) is configured to communicate with the network. The privacy budget can in some embodiments define a total amount of private data leakage (or privacy leakage) which the user believes is acceptable. In some embodiments the current privacy leakage is monitored and any further leakage determined to check whether any further privacy leakage will cause a current or total leakage (for a data type) to exceed the budget and determine whether the data can be released. Thus for example the following examples or embodiments describe a signaling framework that enables each UE to be able to communicate their total privacy budget to the core network functions for example a via AMF, MTLF and NWDAF. This privacy budget information can be employed in the network functions (NFs) as a criterion for selecting whether a certain UE can be employed for a particular service, for example for AI / ML training. Additionally in some embodiments both the UE and the Network is enabled to communicate their estimated remaining privacy budget during the implementation of the service or training process in order that the privacy budget is not exceeded. In some embodiments the use of the privacy budget can be used in some implementations, for example to control the operation of a scheduler in the gNB for selecting UEs to implement the service. In other words the scheduler within a gNB can be employed as a privacy enhancing technology (PET) by computing the enhancing as sub-sampling or consider the remaining budget of a UE to select / schedule the UE at a given time in addition to the traditional criteria for scheduling. A privacy budget differs from a privacy target value or privacy loss / leakage. When a function is computed over the same dataset multiple times, at each given time then there is a leaking of some private information. With Privacy Enhancing Technologies such as Differential Privacy, this leakage is limited in a provable mathematical manner. However, throughout time or a process (e.g. Federated Learning training cycle), then there may be too much leakage of data. Therefore, it is in the UE’s and Network’s interest to not only define how much leakage they have at each time, but also, how much total leakage of information is there, in other words to specify a privacy budget. With respect to Fig. 4a is shown a first part of a signaling diagram example where (in this embodiment) a UE is configured to initiate a privacy budget defining operation. Additionally this example shows signaling between core network functions or nodes (and between access and core network functions or nodes) enabling a service to be assigned to UEs with available privacy budget to implement the service. Thus, for example, as shown by 401 a UE 300 is configured to implement an initial registration operation with a 5G core network function 406. The registration comprises UE privacy budget information defining a privacy budget. The 5G core network function 406 in some embodiments can be a UDM. The privacy budget information can, in some embodiments, be generic and be applied to all data types or may comprise data budgets for separate or different categories or data types. For example the privacy budget information can comprise a separate privacy budget parameter or element for a data type named “advertisement” or privacy budget parameter or element for other third party services, for example localization while defining further or different privacy budget parameter or element for a “network optimization” data type. In some embodiments the network (or 5G core network function 406) is configured to respond with a ‘ok confirmation’ message as shown by 403. The ok confirmation is a confirmation of acceptance of the privacy budget information. At some point a core network function, for example a 5G core model training function, (such as a NWDAF) 404 or a RAN node function, for example a RAN node model training function 404, is configured to generate a discovery request for establishing which UEs are able to service a request. For example as shown by 405 a model training function in the Core (5G core model training function 404) sends a discovery request for the service from the UE. In some embodiments the request can be either for FL model training, or training data, or collaborative training. Additionally as shown by 407 a model training function in the RAN (RAN node model training function 400) sends a discovery request for the service from the UE. As described above the request can be either for FL model training, or training data, or collaborative training. The discovery request can be received by the 5G core NF 406, for example a UDM or any other Core NF, which has access to the received UE privacy budget and can determine an approximate privacy expenditure per request received. In other words the 5G core NF 406 is configured, as shown by 409, to determine an approximate privacy budget / cost needed to service the received requests and then further identify any or which UE(s) are able to service the request based upon their earlier signaled privacy budget. It is understood that the privacy budget can also be different based upon the actual or specific request. For instance, a privacy budget / cost will be highest in the case of requesting actual training data, followed by the requesting for collaborated training, and then least in the case of FL and completed locally trained ML model at the UE. Following the determination, as shown by 409, the NF 406 can be caused to respond to the request, with a UE list (and in some embodiments with the identified UE associated respective privacy budget corresponding to the category of service / model training needed) to the requesting node (Core ML training function or RAN Node or AF). Thus, for example, in response to the request as shown by 405 the 5G core NF 406 is configured to generate a response, as shown by 411, to the 5G core node (5G core model training function 404) with the UE list and optionally the respective privacy budget for the UEs on the list. Also, in response to the request as shown by 407 the 5G core NF 406 is configured to generate a response, as shown by 413, to the RAN node (RAN node model training function 400) with the UE list and optionally the respective privacy budget for the UEs on the list. The model training node, having received the UE list (and optionally the respective privacy budgets for the UEs) is configured to schedule or select from the list one or more UEs. Then the model training node can send a request to UE with the information to implement the service. For example the information can comprise an exact ML model to be trained, or FL operation or the training data needed for performing training at the network. For example the 5G core node (5G core model training function 404) as shown by 515 is configured to transmit to the UE selected or scheduled from the list a request comprising information for performing the requested service. Additionally there is shown by 517 the RAN node (RAN model training function 400) transmitting to the UE selected or scheduled from the list a request comprising information for performing the requested service. With respect to Figure 4b is shown signaling and operations following the signaling from the receipt at the UE of the information for performing the requested service. For example, based upon the request received, the UE 300 calculates or determines the privacy budget needed or privacy cost to service that request as shown by 421. The privacy budget can in some embodiments be modified based on the exact data needed for training, the type of training service (for instance complete training data or FL process), and also the ML training category (for instance advertisement or network optimization). The UE can then, as shown by 422, determine whether the service request can be completed within the available privacy budget (in other words determine whether the calculated privacy budget / cost for service is less than or more than the remaining privacy budget). The UE, as shown by 423a, having determined or calculated that the service request can be completed within the available privacy budget (privacy budget / cost for service < remaining privacy budget) then perform the request. The service having being performed, the UE can be configured to transmit to the origin of the request, in this example the 5G core model training function 404 the response comprising the results, as shown by 425a. Additionally the UE can be configured to update, as shown by 427a, the remaining privacy budget and transmit to the 5G core network function 406, for example the UDM, the updated privacy budget after the completion of the service request. This can result in the 5G core network function 406, as shown by 429a, updating the stored privacy budget information for the UE. With respect to Figure 4c is shown further signaling and operations following the UE can then, as shown by 422, determining whether the service request can be completed within the available privacy budget (in other words determine whether the calculated privacy budget / cost for service is less than or more than the remaining privacy budget). In this example the determination is that the service request can not be completed within the available privacy budget. The following operation is, as shown by 423b, if the service request cannot be completed within the available privacy budget (or that the calculated privacy budget / cost > remaining privacy budget) then the UE generates a privacy budget tolerance increase request. The privacy budget tolerance increase request can then be transmitted, as shown by 431b, to the origin or the request which in this example the 5G core model training function 404. The model training function, in this example the 5G core model training function 404, can then process, as shown by 433b, the privacy budget tolerance increase request. This processing can be an acceptance where the privacy tolerance level (budget) can be increased (for instance from medium to high) or can be rejected where the current privacy tolerance level is maintained. Then the model training function, in this example the 5G core model training function 404, as shown by 435b, is configured to respond to the request. For example the response can comprise an increase in the privacy requirement (with optionally the new increased privacy budget level) or a response indicating a rejected request. This response is transmitted back to the UE 300. The UE 300 is configured to handle the response. For example, as shown by 437b, where the response is a increase privacy requirement response then the UE increases the privacy level and service the original request if the new increased privacy budget allows the service request to be performed. Once the original service request is performed then the operations 425a and 427a can be performed the UE transmits to the origin of the request, in this example the 5G core model training function 404 the response comprising the results and update the remaining privacy budget and transmit to the 5G core network function 406, for example the UDM, the updated privacy budget after the completion of the service request. Although not shown in these figures following the UE can furthermore in some embodiments, following the determination of whether a service request can be completed within the available privacy budget then where the service request cannot be completed within the available privacy budget (calculated privacy budge / cost > remaining privacy budget) then the UE generates a response to the original request indicating that the request cannot be serviced. In such a way, as shown in Figures 4a to 4c, a communications system can assist the UE to maintain privacy by implementing the ‘privacy budget’ embodiments as indicated. Additionally, in some embodiments, the ‘privacy budget’ implementation can be extended to the scheduling or selecting of the UE by the network functions (for example the access network node or gNB / BS) to provide further Privacy amplification. In some embodiments an enhanced scheduler can be employed to improve privacy. For example in the following examples the gNB / BS is a semi-trusted entity (in other words a entity which is “nice but curious”), where the results of FL or UE data shared with AF / NF is shared via gNB to public (NWDAF, NF, AF, …). Additionally in the following examples the UE privatizes its own data before uploading using an off-the-shelf local DP. The following two schedulers are shown, a Round Robin (RR) Scheduler and a simplified Semi Persistent scheduler (Random Channel Scheduler, RCS). Additionally there are shown two example embodiments implementing privacy amplification with these schedulers. A first example embodiment is the implementation of a RR scheduler with so called shuffling amplification and a second example embodiment is a RCS scheduler with so called subsampling amplification. With respect to implementing data collection with a RR scheduler, a privacy amplification effect can be obtained from shuffling noisy messages. As indicated previously a training function (for example a RAN node model training function) can receive a response from the 5G core NF with a UE list (where the response can further optionally comprise the respective privacy budget for each UE on the list). The RR scheduler can then be configured to select or schedule from this list UEs. Then requests can be generated for these selected and scheduled UEs (for example a measurement request to be serviced by the UE). In these embodiments the RR scheduler is configured to schedule all devices (or UEs) in a single round, but in random order. This can be done one by one or in batches and / or blocks. For example where the available UE IDs are mapped down to 0--15: [0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15] Then an example RR scheduler can be configured to schedule all devices (or UEs) in a single round, but in random order [4, 5, 14, 1, 0, 6, 9, 3, 8, 12, 7, 13, 15, 2, 11, 10] If in the result all the identifiers of the devices are removed, there is additional randomness / indistinguishability brought by the random order. The local noise of the UEs or devices gives some indistinguishability for observing the effect of changing a single UEs message, and that indistinguishability is amplified by the random permutation. The additional randomness brought by the random order can be analyzed mathematically to get a formal DP guarantee. This analysis is equivalent to analyzing so called shufflers. For example Figure 5 shows an graph of example two levels of local noise based on non-randomized 501 and randomized 503 scheduling, resulting in local epsilons ~ 4.6 and 2.2 respectively and how the privacy guarantee epsilon is lowered when the number of devices grow (the noisy messages get more ‘lost in the crowd’). The epsilons are calculated using the mathematical techniques expressed in Feldman, Vitaly, Audra McMillan, and Kunal Talwar. "Hiding among the clones: A simple and nearly optimal analysis of privacy amplification by shuffling." 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS). IEEE, 2022, and Feldman, V., McMillan, A., and Talwar, K. (2023). Stronger privacy amplification by shuffling for Rényi and approximate differential privacy. In Proceedings of the 2023 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA), pages 4966–4981. SIAM. The value of epsilon on the y-axis depicts the worst-case privacy risk of observing the effect of a single UE in the output of the scheduler. Unlike in the summation, all the individual messages can be seen in the output (without any identifiers), which also helps removing malicious messages. Additionally the scheduler can be arranged in terms of scheduling in rounds. For example the earlier scenario with UE IDs mapped down to 0--15: [0, 1, 2, 3, ,4 ,5 ,6, 7, 8, 9, 10, 11, 12, 13, 14, 15] can be mapped according to the following selections at rounds 1 to 4 Selected UE at Selected UE at Selected UE at Selected UE at round 1 round 2 round 3 round 4 4 12 15 8 9 3 1 0 10 5 2 6 11 14 7 2 In some embodiments there can be employed a scheduler which is configured where the channel conditions per UE are randomized (at least with respect to the observer of the schedulers output). In these embodiments the scheduler selects or schedules UEs based on the channel conditions (which can be considered to be therefore random). If the scheduler (seemingly randomly) picks / devices from a population of 0 devices or UEs, then the subsampling amplification results can compute or determine the privacy guarantees for the final result. Thus when all the identifiers of the devices are removed, there is additional randomness / indistinguishability brought by the random subsampling. In other words a local noise of the devices gives some indistinguishability for observing a change in a single message, and that indistinguishability is amplified by the random subsampling. This can be shown in Figure 6 where the same example as shown in Figure 5 where there are two levels of local noise, resulting in local epsilons ~ 2.2 shown by plot 503 and 4.6 shown by plot 501. From a population of n devices, there can be a random sampling of 1%. For this 1% random subset, we reduce any identifiers and show as a result the random permutation of the messages. This shows how plots 505 and 507 show where the privacy guarantee epsilon is lowered (compared to plots 501 and 503 respectively) when the number of devices increase. In such embodiments the single noisy messages get even more ‘lost in the crowd’ by the combining of subsampling and shuffling amplification. In some embodiments these results can be reflected in Semi Persistence Scheduler implementations. A schematic view of an example gNB or suitable RAN node or function for implementing a RAN is shown with respect to Figure 7. Figure 7 for example shows the gNB 711 which is configured to receive local DP additions 701 and further output to the Network core or application function or network functions. The gNB 711 is shown comprising the scheduler 713, which is configured to implement the scheduling functions described above and later herein for selecting and scheduling the UE or devices for implementing the service requests. The gNB 711 can further comprise additional DP module 715 which is configured to apply further or additional DP in a manner as described with respect to Fig.8. Fig.8 for example shows the additional DP module 715. The additional DP module 715 in some embodiments comprises a total DP measurer / determiner 801 configured to measure the total DP from the scheduler and any additional local DP. A determined total DP can be passed to the total DP controller 803 which is configured to determine whether the total DP is sufficient. If the total DP is sufficient then the scheduler output is implemented. However where the toral DP is determined not to be sufficient then then the additional DP controller 805 is configured to control the scheduler to perform additional sub-sampling or implement any further DP enhancing mechanisms. The further subsampling from the scheduler’s results can be based on a Rényi DP (RDP) accounting.
[0002] at arises from conditions that are seemingly random to the observer of the schedulers output. Each UE can be assumed to be sampled with a fixed probability 1 to the scheduling round. Using a RDP amplification the privacy amplification of this random subsampling can be achieved, in particular the RDP parameters for the output are obtained, assuming each UEis sampled with a fixed probability 1. These RDP parameters can be converted to ^^, ^^-DPguarantees using the formulas above. Thus if needed, the further subsampling from the result of this subsampling in case the additional DP module determines that the total DP is not strong enough. In other words that There is a first computing of the ^′^3^-values obtained by subsampling with a fixed probability 1^. Then replace thus obtained ^′^3^-values in place of ^^!^’s, and evaluate the expression with a sampling probability 1,. Thus it is possible to control via 1, how low the final ^^, ^^-DP guarantees can be. Soif the randomness of sampling with probability 1^comes from random channel conditions(which cannot be directly affected), it is to adjust the final ^^, ^^-DP guarantees viaadjusting 1,for the second sampling. In some embodiments the scheduler is configured to implement scheduling based on the type of potential request to be serviced and the privacy budget of the UE. Thus in some embodiments the scheduling is configured to employ the privacy budgeting information of the UEs in a gNB for scheduling, while doing Federated Learning for a NF / AF in the network. In a wireless scheduler 713, the function of scheduling the UEs for resource allocation depends on aspects such as the UE’s instantaneous channel, in UE’s budget for Data speed and some fairness factor. However, having privacy budget in mind, it is possible to implement more effective schedules using the budgeting data for scheduling. For example a schematic view of an example scheduler 713 is shown in Figure 9. The scheduler 713 is configured to receive the privacy budget of the UE 911, the UE channel state information 913, the targeted BLER / latency 915, and the number of times the UE has been scheduled before (N) 917. The scheduler 713 furthermore can comprise a FL training determiner / scheduler controller 900 which is configured to determine whether the scheduler is currently scheduling for a federated learning FL application or another application. In some embodiments the FL training determiner / scheduler controller 900 is configured to control a conventional scheduler 901 to schedule selections of UEs in non-FL applications and to control a privacy aware scheduler 903 to schedule selections of UEs in FL applications. Thus for example a federated learning can be implemented where the gNB is collecting data / models / gradients for training of an neural network (NN) from multiple UEs. The problem arises when some UEs might perform the updates with larger latency. Usually, these updates can be safely ignored and included in a next or further round of Backpropagation. However, this might not be possible to implement when considering the privacy budget of the UEs. Although the above examples enable that privacy could be better protected and enhanced, when the number of UEs (independent data points) are large. A privacy aware scheduler 903 is configured to schedule UEs with very low privacy budget when the number of active UEs in a round of FL training update is large. Conversely, the UEs with high remaining Privacy budget can in some embodiments be scheduled when there are no low- budget UE are available or when the number of participating UEs are small. Figure 10, for example shows the priority order determination based on the channel data information ChU, latency f, and number of times scheduled before values N and the privacy budget of UE PbU for the conventional scheduler 901 and the privacy aware scheduler 903. Furthermore in some embodiments a conventional scheduler 901 can be modified to implement a privacy aware scheduler, as shown in Figure 11. In this example, the scheduler comprises a UE filter 1101. The UE filter 1101 is configured to remove UE’s with a very small privacy budget from being scheduled. This could, for example, be implemented by checking the privacy budgets of each scheduler. If the budget is not enough to finish one complete or whole round of backpropagation of the gradients updates, then the identified UEs are removed from the Scheduling list. The pseudo code for implementing the filter can for example be as follows If in FL_mode: For each j in PbU do: If j>= T_fl: UE_Schedule_list =UE_schedul_list+j Where PbU is the list of privacy budgets of the UE’s provided by the 5G Core and or the UE directly The FL_mode is the mode of operation where FL training is implemented T_fl is a threshold indicating the privacy budget needed for that specific FL UE_schedul_list is the list of eligible UEs to participate on the specific FL It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities. It is noted that whilst some embodiments have been described in relation to 5G systems, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for radio access and core networks, radio access technologies and standards, embodiments may be applied to any other suitable forms of communication systems that implement other radio access technologies than those illustrated and described herein. It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention. In general, the various embodiments, the FL aggregator may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof. As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.” This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device. The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer- executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it. Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media. The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples. Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate. The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various embodiments of the disclosure. The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed. As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0003] EXAMPLE CLAUSES Example embodiments may be considered in view of the following clauses. Clause 1. An apparatus for a user equipment implementing privacy guarantees with respect to service requests from a communications network for supplying data, the apparatus comprising means for: transmitting to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receiving a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtaining the privacy cost associated with the processing of the service request; determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. Clause 2. The apparatus as in clause 1, wherein the means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget is for: when the privacy cost associated with the processing of the service request is greater than the privacy budget: requesting a privacy budget tolerance increase request for the network function; obtaining an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. Clause 3. The apparatus as in clauses 1 or 2, wherein the means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget is for: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: performing the service request to generate data; transmitting the generated data to the network function; and transmitting to the core network function an updated privacy budget based on the privacy cost. Clause 4. The apparatus as in any of clauses 1 to 3, wherein the core network function is a unified data management (UDM). Clause 5. The apparatus as in any of clauses 1 to 4, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 6. The apparatus as in clause 5, wherein the core network model training function comprises a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 7. The apparatus as in any of clauses 1 to 6, wherein the service request comprises one of: a federated learning model request; a training data request; or collaborative training request. Clause 8. The apparatus as in any of clauses 1 to 7, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 9. The apparatus as in any of clauses 1 to 8, wherein the apparatus comprises or may be comprised in the user equipment. Clause 10. An apparatus for a core network function for controlling privacy in communications network, the apparatus comprising means for: receiving from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receiving from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmitting to the at least one network function a list of user equipment comprising user equipment for processing the service request. Clause 11. The apparatus as in clause 10, wherein the means is further for transmitting to the at least one network function privacy budget information associated with user equipment on the list of user equipment. Clause 12. The apparatus as in any of clauses 10 or 11, wherein the means is further for receiving at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. Clause 13. The apparatus as in any of clauses 10 to 12, wherein the apparatus comprises or be comprised in the core network function. Clause 14. The apparatus as in any of clauses 10 to 13, wherein the core network function is a unified data management (UDM). Clause 15. The apparatus as in any of clauses 10 to 14, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 16. The apparatus as in any of clauses 10 to 15, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 17. The apparatus as in any of clauses 10 to 16, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 18. The apparatus as in clauses 10 to 17, wherein the privacy budget comprises one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. Clause 19. An apparatus for a network function for generating service requests for data from at least one user equipment within a communications network, the network function comprising means for: transmitting to a core network function a discovery request associated with a service request for data from at least one user equipment; receiving from the core network function a list of user equipment comprising user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. Clause 20. The apparatus as in clause 19, wherein the means is further for receiving from the core network function privacy budget information associated with user equipment on the list of user equipment. Clause 21. The apparatus as in any of clauses 19 or 20, wherein the means is further for: receiving a privacy budget tolerance increase request from at least one user equipment; and transmitting an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. Clause 22. The apparatus as in any of clauses 19 to 21, wherein the means for selecting and / or scheduling at least one user equipment from the list of user equipment is for at least one of: randomly selecting and / or scheduling the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. Clause 23. The apparatus as in any of clauses 19 to 22, wherein the core network function may be a unified data management (UDM). Clause 24. The apparatus as in any of causes 19 to 23, wherein the apparatus comprises or is comprised in the network function. Clause 25. The apparatus as in any of clauses 19 to 24, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 26. The apparatus as in any of clauses 19 to 25, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 27. The apparatus as in any of clauses 19 to 26, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 28. The apparatus as in any of clauses 19 to 27, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 29. A method for a user equipment implementing privacy guarantees with respect to service requests from a communications network for supplying data, the method comprising: transmitting to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receiving a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtaining the privacy cost associated with the processing of the service request; determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. Clause 30. The method as in clause 29, wherein processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget comprises: when the privacy cost associated with the processing of the service request is greater than the privacy budget: requesting a privacy budget tolerance increase request for the network function; obtaining an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. Clause 31. The method as in any of clauses 29 or 30, wherein processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget comprises: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: performing the service request to generate data; transmitting the generated data to the network function; and transmitting to the core network function an updated privacy budget based on the privacy cost. Clause 32. The method as in any of clauses 29 to 31, wherein the core network function is a unified data management (UDM). Clause 33. The method as in any of clauses 29 to 32, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 34. The method as in any of clauses 29 to 33, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 35. The method as in any of clauses 29 to 34, wherein the service request comprises one of: a federated learning model request; a training data request; or collaborative training request. Clause 36. The method as in any of clauses 29 to 35, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 37. The method as in any of clauses 29 to 36, wherein the apparatus comprises or comprised in the user equipment. Clause 38. A method for an apparatus for a core network function for controlling privacy in communications network, the method comprising: receiving from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receiving from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmitting to the at least one network function a list of user equipment comprising user equipment for processing the service request. Clause 39. The method as in clause 38, further comprising transmitting to the at least one network function privacy budget information associated with user equipment on the list of user equipment. Clause 40. The method as in any of clauses 38 or 39, further comprising receiving at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. Clause 41. The method as in any of clauses 38 to 40, is comprised in the core network function. Clause 42. The method as in any of clauses 38 to 41, wherein the core network function is a unified data management (UDM). Clause 43. The method as in any of clauses 38 to 42, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 44. The method as in any of clauses 38 to 43, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 45. The method as in any of clauses 38 to 44, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 46. The method as in any of clauses 38 to 45, wherein the privacy budget comprises one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. Clause 47. A method for an apparatus for a network function for generating service requests for data from at least one user equipment within a communications network, the method comprising: transmitting to a core network function a discovery request associated with a service request for data from at least one user equipment; receiving from the core network function a list of user equipment comprising user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. Clause 48. The method as in clause 47, further comprising receiving from the core network function privacy budget information associated with user equipment on the list of user equipment. Clause 49. The method as in any of clauses 47 or 48, further comprises: receiving a privacy budget tolerance increase request from at least one user equipment; and transmitting an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. Clause 50. The method as in any of clauses 47 to 49, wherein selecting and / or scheduling at least one user equipment from the list of user equipment comprises at least one of: randomly selecting and / or scheduling the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. Clause 51. The method as in any of clauses 47 to 50, wherein the core network function is a unified data management (UDM). Clause 52. The method as in any of clauses 47 to 51, is comprised in the network function. Clause 53. The method as in any of clauses 47 to 52, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 54. The method as in any of clauses 47 to 53, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 55. The method as in any of clauses 47 to 53, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 56. The method as in any of clauses 47 to 54, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 57. An apparatus for a user equipment configured to implement privacy guarantees with respect to service requests from a communications network for supplying data, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receive a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtain the privacy cost associated with the processing of the service request; determine whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget. Clause 58. The apparatus as in clause 57, caused to process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget is caused to: when the privacy cost associated with the processing of the service request is greater than the privacy budget: request a privacy budget tolerance increase request for the network function; obtain an increased privacy budget; and further determine whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget. Clause 59. The apparatus as in any of clauses 57 or 58, caused to process the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget is caused to: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: perform the service request to generate data; transmit the generated data to the network function; and transmit to the core network function an updated privacy budget based on the privacy cost. Clause 60. The apparatus as in any of clauses 57 to 59, wherein the core network function is a unified data management (UDM). Clause 61. The apparatus as in any of clauses 57 to 60, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 62. The apparatus as in any of clauses 57 to 61, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 63. The apparatus as in any of clauses 57 to 62, wherein the service request comprises one of: a federated learning model request; a training data request; or collaborative training request. Clause 64. The apparatus as in any of clauses 57 to 63, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 65. The apparatus as in any of clauses 57 to 64, comprises or is comprised in the user equipment. Clause 66. An apparatus for a core network function configured to control privacy in communications network, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit; receive from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimate a privacy budget or cost associated with processing the service request; determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmit to the at least one network function a list of user equipment comprising user equipment for processing the service request. Clause 67. The apparatus as in clause 66, further caused to transmit to the at least one network function privacy budget information associated with user equipment on the list of user equipment. Clause 68. The apparatus as in any of clauses 66 or 57, further caused to receive at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request. Clause 69. The apparatus as in any of clauses 66 to 68, comprises or is comprised in the core network function. Clause 70. The apparatus as in any of clauses 66 to 69, wherein the core network function is a unified data management (UDM). Clause 71. The apparatus as in any of clauses 66 to 70, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 72. The apparatus as in any of clauses 66 to 71, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 73. The apparatus as in any of clauses 66 to 72, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 74. The apparatus as in any of clauses 66 to 73, wherein the privacy budget comprises one of: a privacy budget associated with all data types; at least two privacy budgets, each privacy budget associated with a data type. Clause 75. An apparatus for a network function configured to generate service requests for data from at least one user equipment within a communications network, the apparatus comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit to a core network function a discovery request associated with a service request for data from at least one user equipment; receive from the core network function a list of user equipment comprising user equipment for processing the service request; select and / or schedule at least one user equipment from the list of user equipment; and transmit to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. Clause 76. The apparatus as in clause 75, is further caused to receive from the core network function privacy budget information associated with user equipment on the list of user equipment. Clause 77. The apparatus as in any of clauses 75 or 76, is further caused to: receive a privacy budget tolerance increase request from at least one user equipment; and transmit an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget. Clause 78. The apparatus as in any of clauses 75 to 77, caused to select and / or schedule at least one user equipment from the list of user equipment is caused to perform at least one of: randomly select and / or schedule the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; select and / or schedule the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or select and / or schedule the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment. Clause 79. The apparatus as in any of clauses 75 to 78, wherein the core network function may be a unified data management (UDM). Clause 80. The apparatus as in any of clauses 75 to 79, wherein the apparatus comprises or is comprised in the network function. Clause 81. The apparatus as in any of clauses 75 to 80, wherein the network function is one of: a core network model training function; or a radio access network model training function. Clause 82. The apparatus as in any of clauses 75 to 81, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF). Clause 83. The apparatus as in any of clauses 75 to 82, wherein the service request comprises one of: a federated learning model request; a training data request; or a collaborative training request. Clause 84. The apparatus as in any of clauses 75 to 83, wherein the privacy budget comprises one of: a privacy budget associated with all data types; or at least two privacy budgets, each privacy budget associated with a data type. Clause 85. A computer readable medium comprising program instructions for causing an apparatus to perform at least the method as in any of clauses 29 to 37, 38 to 46 or 47 to 56. Clause 86. A system comprising means for: receiving a privacy budget, wherein the privacy budget is a parameter defining how much data is acceptable to transmit; transmitting a discovery request associated with a service request for data; receiving a discovery request associated with a service request for data; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget; transmitting a list of user equipment for processing the service request; receiving the list of user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data. Clause 87. A system comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive a privacy budget, wherein the privacy budget is a parameter defining how much data is acceptable to transmit; transmit a discovery request associated with a service request for data; receive a discovery request associated with a service request for data; estimate a privacy budget or cost associated with processing the service request; determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget; transmit a list of user equipment for processing the service request; receive the list of user equipment for processing the service request; select and / or schedule at least one user equipment from the list of user equipment; and transmit to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data.
Claims
CLAIMS 1. An apparatus for a user equipment implementing privacy guarantees with respect to service requests from a communications network for supplying data, the apparatus comprising means for: transmitting to a core network function a privacy budget, wherein the privacy budget at least in part causes the core network function to select the user equipment as being able to process a service request and maintain a guaranteed privacy; receiving a service request from a network function, wherein a processing of the service request being associated with a privacy cost; obtaining the privacy cost associated with the processing of the service request; determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget.
2. The apparatus as claimed in claim 1, wherein the means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget is for: when the privacy cost associated with the processing of the service request is greater than the privacy budget: requesting a privacy budget tolerance increase request for the network function; obtaining an increased privacy budget; and further determining whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than or less than the increased privacy budget.
3. The apparatus as claimed in any of claims 1 or 2, wherein the means for processing the service request based on the determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, or increased privacy budget is for: when the privacy cost associated with the processing of the service request is less than the privacy budget or increased privacy budget: performing the service request to generate data; transmitting the generated data to the network function; and transmitting to the core network function an updated privacy budget based on the privacy cost.
4. The apparatus as claimed in any of claims 1 to 3, wherein the core network function is a unified data management (UDM).
5. The apparatus as claimed in any of claims 1 to 4, wherein the network function is one of: a core network model training function; or a radio access network model training function.
6. The apparatus as claimed in claim 5, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF).
7. The apparatus as claimed in any of claims 1 to 6, wherein the service request comprises one of: a federated learning model request; a training data request; or collaborative training request.
8. An apparatus for a core network function for controlling privacy in communications network, the apparatus comprising means for: receiving from at least one user equipment a privacy budget, wherein the privacy budget is a parameter defining how much data the at least one user equipment believes is acceptable to transmit;receiving from at least one network function a discovery request associated with a service request for data from at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user equipment; transmitting to the at least one network function a list of user equipment comprising user equipment for processing the service request.
9. The apparatus as claimed in claim 8, wherein the means is further for transmitting to the at least one network function privacy budget information associated with user equipment on the list of user equipment.
10. The apparatus as claimed in any of claims 8 or 9, wherein the means is further for receiving at least one updated privacy budget associated with at least one user equipment following the at least one user equipment implementing the service request.
11. The apparatus as claimed in any of claims 8 or 10, wherein the apparatus comprises or is comprised in the core network function.
12. The apparatus as claimed in any of claims 8 to 11, wherein the core network function is a unified data management (UDM).
13. The apparatus as claimed in any of claims 8 to 12, wherein the network function is one of: a core network model training function; or a radio access network model training function.
14. The apparatus as claimed in claim 13, wherein the core network model training function is a model training logical function (MTLF) comprised in a network data analytics function (NWDAF).
15. An apparatus for a network function for generating service requests for data from at least one user equipment within a communications network, the network function comprising means for: transmitting to a core network function a discovery request associated with a service request for data from at least one user equipment; receiving from the core network function a list of user equipment comprising user equipment for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipment; and transmitting to the selected and / or scheduled at least one user equipment from the list of user equipment the service request for data.
16. The apparatus as claimed in claim 15, wherein the means is further for receiving from the core network function privacy budget information associated with user equipment on the list of user equipment.
17. The apparatus as claimed in any of claims 15 or 16, wherein the means is further for: receiving a privacy budget tolerance increase request from at least one user equipment; and transmitting an increased privacy budget to the at least one user equipment or a response rejecting an increased privacy budget.
18. The apparatus as claimed in any of claims 15 to 17, wherein the means for selecting and / or scheduling at least one user equipment from the list of user equipment is for at least one of: randomly selecting and / or scheduling the at least one user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least one further sub-sampling of the user equipment from the list of user equipment, to decrease a privacy cost or budget associated with processing the service request; or selecting and / or scheduling the at least one user equipment from the list of user equipment based on at least an associated privacy budget of the user equipment.
19. The apparatus as claimed in any of claims 15 to 18, wherein the core network function is a unified data management (UDM).
20. The apparatus as claimed in any of claims 15 to 19, wherein the apparatus comprises or is comprised in the network function.
Citation Information
Patent Citations
Model aggregation training method and device
CN116029390A
Method for selecting local entities for federated learning training
WO2023186271A1