Model management method and apparatus
By labeling or eliminating suspicious data in the communication data collection in the AI model management method in the wireless field, the poison attack security threat faced by the AI model is solved, the data security risks are reduced and the model training effect is ensured.
Patent Information
- Application Number
- PCT/CN2024/129151
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-10-31
- Publication Date
- 2025-06-05
AI Technical Summary
AI models in the wireless field face security threats at all stages of their life cycle, mainly including poisoning attacks, resulting in increased data security risks.
By implementing a management method between the model inference functional entity and the model training functional entity, obtain a collection of communication data used to update the machine learning model, and label or remove suspicious data according to the processing strategy to avoid affecting model training.
It reduces the data security risks of AI models in the wireless field, prevents the negative impact of poisoning attacks on model training, and ensures the effect of model retraining.
Smart Images

Figure CN2024129151_05062025_PF_FP_ABST
Abstract
Description
Model management method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 30, 2023, with application number 202311636277.9 and application name “Model Management Method and Device”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and in particular to a model management method and device. Background Art
[0003] To improve the intelligence and automation of networks, artificial intelligence (AI) and machine learning (ML) technologies are being increasingly applied to the wireless field. Research is underway in multiple domains, including the management domain, core network (CN), and radio access network (RAN), to explore how to apply AI / ML technologies to enable network intelligence.
[0004] However, AI models in the wireless field face security threats at all stages of their lifecycle, including but not limited to poisoning attacks. Therefore, how to reduce the data security risks of AI models in the wireless field is a hot topic of current research.
[0005] Summary of the Invention
[0006] Embodiments of the present application provide a model management method and device to reduce data security risks of AI models in the wireless field.
[0007] To achieve the above objectives, this application adopts the following technical solutions:
[0008] In a first aspect, a model management method is provided, applied to a model inference functional entity. The method comprises: obtaining a first communication data set for updating a first machine learning model, and sending a second communication data set to a model training functional entity. The first processing strategy includes a first loss threshold, and the first machine learning model is used to manage wireless communication services. The second communication data set is obtained by performing a processing operation on suspicious data in the first communication data set according to the first processing strategy. The suspicious data is wireless communication data with a loss value greater than the first loss threshold.
[0009] The first machine learning model can be an AI beam management, or a beam selection model, or it can be a model of other management scenarios in wireless communications, such as a downlink / uplink data volume estimation model, a channel fading change estimation model, a CSI feedback model, an AI-assisted positioning model, etc. There is no specific limitation on this.
[0010] The first communication data set may include wireless communication data between the access network device and multiple terminals, and may specifically include reference signal received power (RSRP), channel state information matrix, channel impulse response and other data to ensure the service of the wireless communication process. In addition, the first communication data set may also include a label. The label can be used to mark the true value of the wireless communication data in the corresponding scenario, and can be selected according to the actual situation. Taking RSRP in the beam management scenario of AI as an example, the wireless communication data may include RSRP and the beam identifier corresponding to the RSRP. The label can be used to mark whether the beam indicated by the beam identifier is the best beam corresponding to the RSRP. For example, the label includes two values 0 / 1, where 1 indicates that the beam indicated by the beam identifier is the best beam corresponding to the RSRP, and 0 indicates that the beam indicated by the beam identifier is not the best beam corresponding to the RSRP.
[0011] According to the method described in the first aspect, since the main purpose of the poisoning attack is to affect the training effect during the model retraining and updating process, thereby reducing its training accuracy, that is, the loss value of the updated model on the poisoned data is relatively large. Accordingly, the model reasoning function entity can determine the data in the first communication data set whose loss value is greater than the first loss threshold as suspicious data, or data suspected of being poisoned, and process it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.
[0012] In one possible design scheme, the processing operation includes a labeling operation, which refers to adding an identifiable label to the suspicious data to subsequently identify which data is suspicious data, prevent the suspicious data from affecting the retraining of the first machine learning model, and ensure the effectiveness of the model retraining.
[0013] Optionally, before performing the marking operation, the method described in the first aspect further includes: determining that a proportion of suspicious data in the first communication data set is greater than a first proportion threshold.
[0014] In one possible design scheme, the processing operation includes a removal operation, which refers to removing suspicious data from the first communication data set to avoid subsequent use of suspicious data to retrain the first machine learning model, thereby ensuring the effectiveness of model retraining.
[0015] Optionally, before performing the elimination operation, the method further includes: determining whether a proportion of suspicious data in the first communication data set is less than or equal to a first proportion threshold.
[0016] It can be understood that the first ratio threshold can represent the upper limit of the proportion of suspicious data allowed by the normal training model in the communication data set. That is to say, if the proportion of suspicious data in the communication data set is less than or equal to the first ratio threshold, it means that the number of suspicious data is not too large. Even if this part of suspicious data is removed, the sample size of normal data remaining in the communication data set can complete the normal training of the machine learning model. Therefore, the model reasoning functional entity can perform a removal operation. On the contrary, if the proportion of suspicious data in the communication data set is greater than the first ratio threshold, it means that the number of suspicious data accounts for too much. If this part of suspicious data is directly removed rashly, the sample size of normal data may not be able to support the normal training of the machine learning model. Therefore, the model reasoning functional entity can perform a marking operation to help the model training functional entity decide whether to use or remove these suspicious data.
[0017] Optionally, the first processing strategy may include a first ratio threshold. That is, the first ratio threshold may be dynamically configured along with the first processing strategy to enable dynamic adjustment based on actual needs. Alternatively, the first ratio threshold may be pre-configured locally in the model inference functional entity to avoid configuration overhead.
[0018] In one possible design solution, the first processing strategy may indicate a processing operation.
[0019] In one possible design, the method of the first aspect further includes receiving the first processing policy from the model management functional entity. Specifically, the first processing policy may be dynamically configured by a network element / entity in the management domain to enable dynamic adjustment based on actual needs. Alternatively, the first processing policy may be pre-configured locally in the model reasoning functional entity to avoid configuration overhead.
[0020] In one possible design, obtaining a first communication data set for updating a first machine learning model includes receiving first indication information from a model training function entity, and receiving wireless communication data from multiple terminals based on the first indication information. The first indication information indicates that the first machine learning model needs to be updated, thereby enabling on-demand acquisition and avoiding redundancy.
[0021] Optionally, the model reasoning functional entity is deployed on an access network device. For example, the model reasoning functional entity is deployed on an open centralized unit (O-CU) or an open distributed unit (O-DU) of the access network device, or may be deployed on a network element / device of any other possible device form factor, without limitation.
[0022] In one possible design, the method of the first aspect may further include: processing the first communication data set using a first machine learning model to determine suspicious data in the first communication data set. In other words, the model inference function may use the first machine learning model to perform inference calculations on the first communication data set to determine suspicious data therein.
[0023] In one possible design, after sending the second communication data set to the model training functional entity, the method described in the first aspect may further include: receiving second indication information from the model training functional entity, and obtaining a second machine learning model based on the second indication information. The second indication information is used to indicate the second machine learning model, and the second machine learning model is obtained by updating the first machine learning model. This enables the machine learning model to be updated, avoiding the impact on actual business operations caused by reduced model accuracy.
[0024] In a second aspect, a model management method is provided, which is applied to a model training functional entity, comprising: obtaining a second communication data set for updating a first machine learning model, and updating the first machine learning model based on a third communication data set. The first machine learning model is used to manage wireless communication services. The third communication data set is obtained by removing erroneous data from the second communication data set according to a second processing strategy, wherein the second processing strategy includes a third loss threshold. If the erroneous data is used to update the first machine learning model, the loss value of the wireless communication data processed by the updated machine learning model is greater than the third loss threshold.
[0025] According to the method described in the second aspect, since the main purpose of the poisoning attack is to affect the training effect during the model retraining and updating process, thereby reducing its training accuracy, the loss value of the updated model on the poisoned data is relatively large. Accordingly, the model training functional entity can also adopt a similar method to the above-mentioned model reasoning functional entity to determine the data in the first communication data set with a loss value greater than the first loss threshold as erroneous data, such as poisoned attack data, and remove it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.
[0026] In a possible design solution, the removal operation refers to removing erroneous data from the second communication data set.
[0027] Optionally, the elimination operation specifically refers to eliminating erroneous data in the data marked as suspicious from the second communication data set, and the data marked as suspicious (or suspicious data) is wireless communication data in the second communication data set whose loss value is greater than the loss threshold. It can be understood that since the computing power of the model training functional entity is more powerful than the model reasoning functional entity, when the model reasoning functional entity is unable to distinguish which data in the suspicious data is normal data and which data is poisoning attack data, the model training functional entity can use a more sophisticated elimination operation to eliminate the data in the suspicious data that is actually poisoning attack data, and use the normal data in the suspicious data for model training to improve the utilization efficiency of training data.
[0028] Optionally, the method described in the second aspect further includes: dividing the data marked as suspicious into M data subsets, where M is an integer greater than 1; using the i-th data subset in the M data subsets to update the first machine learning model to obtain the i-th updated machine learning model, where i traverses 1 to M; using the i-th updated machine learning model to process the test data to obtain the i-th test result; if the loss value of the test data in the i-th test result is greater than a third loss threshold, then determining that the i-th data subset is erroneous data; otherwise, determining that the i-th data subset is not erroneous data. It can be seen that by dividing the suspicious data into multiple data subsets, it is possible to eliminate erroneous data at the granularity of data subsets. Compared with eliminating all suspicious data, the granularity is finer and normal data can be retained.
[0029] Alternatively, the second processing strategy may indicate a cull operation.
[0030] Optionally, the method described in the second aspect further includes: receiving a second processing policy from the model management functional entity. That is, the second processing policy may also be dynamically configured by a network element / entity in the management domain to enable dynamic adjustment based on actual needs. Alternatively, the second processing policy may also be pre-configured locally in the model training functional entity to avoid configuration overhead.
[0031] Optionally, before obtaining the second communication data set for updating the first machine learning model, the method described in the second aspect may further include: sending first indication information to the model inference functional entity. Obtaining the second communication data set for updating the first machine learning model includes: receiving the second communication data set from the model inference functional entity; wherein the first indication information is used to indicate that the first machine learning model needs to be updated, thereby achieving on-demand acquisition and avoiding redundancy.
[0032] Furthermore, sending a first indication message to the model inference functional entity includes: sending a first indication message to the model inference functional entity according to a first condition. The first condition includes at least one of the following: the next update cycle of the machine learning model has been entered to achieve periodic dynamic updates, the prediction accuracy of the machine learning model is lower than the accuracy threshold, so it is necessary to improve the model accuracy by updating the model, or the proportion of suspicious data in the wireless communication data used to update the machine learning model last obtained is greater than the second proportion threshold, and the time remaining from the end of the machine learning model update is greater than the threshold time, which can be the sum of the time required to obtain the wireless communication data used to update the machine learning model and the time required to update the machine learning model. In this way, the effect of this model update can be guaranteed by re-acquiring data.
[0033] Furthermore, the method described in the second aspect may also include: sending a second loss threshold to the model reasoning functional entity, and the second loss threshold may be smaller than the loss threshold pre-configured by the model reasoning functional entity, such as the first loss threshold, to relax the suspicious data threshold defined by the model reasoning functional entity, and ensure that re-collection can provide more normal data for training.
[0034] Furthermore, the second processing strategy also indicates the first condition.
[0035] Furthermore, before updating the first machine learning model according to the third communication data set, the method described in the second aspect may also include: determining to update the first machine learning model according to a second condition, wherein the second condition refers to that the proportion of suspicious data in the communication data set is less than or equal to a second ratio threshold. In other words, the second ratio threshold can represent the upper limit of the proportion of data suspected of poisoning attacks allowed for normal training in the communication data set. In practice, if the proportion of suspicious data in the second communication data set is less than or equal to the second ratio threshold, it means that the number of suspicious data is not too large, and even if this part of suspicious data is eliminated, the remaining data in the second communication data set can complete the normal training of the first machine learning model, so the model inference function entity can perform the elimination operation.
[0036] Furthermore, the second processing strategy further indicates a second condition.
[0037] Optionally, the second processing strategy includes a second ratio threshold.
[0038] In one possible design scheme, after updating the first machine learning model according to the third communication data set, the method described in the second aspect may also include: sending second indication information to the model inference function entity; wherein the second indication information is used to indicate the second machine learning model, and the second machine learning model is obtained by updating the first machine learning model.
[0039] In one possible design scheme, the model training functional entity is deployed on the access network device, and the second communication data set includes wireless communication data between the access network device and multiple terminals.
[0040] It can be understood that the technical effects of the method described in the second aspect can also refer to the relevant introduction of the method described in the first aspect, and will not be repeated here.
[0041] According to a third aspect, a model management method is provided, which is applied to a model management functional entity, and includes: obtaining a first processing strategy for a first machine learning model, and sending the first processing strategy to a model inference functional entity. The first machine learning model is used to manage wireless communication services, and the first machine learning model is deployed in the model inference functional entity. The first processing strategy includes a first loss threshold, and the first processing strategy can be used to perform a processing operation on suspicious data in a communication data set used to update the machine learning model, where the suspicious data is data with a loss value greater than the first loss threshold.
[0042] In a possible design solution, the processing operation includes a marking operation, which refers to adding a mark to the suspicious data for easy identification.
[0043] In one possible design, the processing operation includes a removal operation, where the removal operation refers to removing suspicious data from the communication data set.
[0044] In one possible design solution, the first processing strategy includes a first ratio threshold.
[0045] In one possible design, the first processing strategy indicates a processing operation.
[0046] In one possible design, the method described in the third aspect may further include obtaining a second processing strategy for the first machine learning model and sending the second processing strategy to a model training function entity used to update the first machine learning model. The second processing strategy can be used to remove erroneous data from a communication data set used to update the machine learning model. The second processing strategy includes a third loss threshold. If the machine learning model is updated using erroneous data, the loss value of the updated machine learning model processing wireless communication data is greater than the third loss threshold.
[0047] Optionally, the removal operation refers to removing erroneous data from the communication data set.
[0048] In one possible design, the removal operation specifically refers to removing erroneous data in the data marked as suspicious from the communication data set, where the data marked as suspicious is wireless communication data in the communication data set whose loss value is greater than a loss threshold.
[0049] Optionally, the second processing strategy indicates a culling operation.
[0050] Optionally, the second processing strategy also indicates that a communication data set needs to be obtained according to a first condition, wherein the first condition includes at least one of the following: the next update cycle of the machine learning model has been entered, the prediction accuracy of the machine learning model is lower than the accuracy threshold, or the proportion of suspicious data in the last wireless communication data obtained for updating the machine learning model is greater than a second proportion threshold, and the current time remaining to the end of the machine learning model update is greater than the threshold time; the threshold time is the sum of the time required to obtain the wireless communication data for updating the machine learning model and the time required to update the machine learning model.
[0051] Optionally, the second processing strategy also indicates that it is necessary to determine whether to update the machine learning model based on a second condition, wherein the second condition refers to that the proportion of data marked as suspicious in the communication data set is less than or equal to a second proportion threshold.
[0052] Optionally, the second processing strategy includes a second ratio threshold.
[0053] It can be understood that the technical effects of the method described in the second aspect can also refer to the relevant introductions in the methods described in the first and second aspects, and will not be repeated here.
[0054] In a fourth aspect, a communication device is provided, comprising a module for executing the method described in any one of the first to third aspects.
[0055] In one possible design solution, the communication device described in the fourth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fourth aspect to communicate with other communication devices.
[0056] In one possible design, the communication device described in the fourth aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store instructions related to the method of any one of the first to third aspects.
[0057] In an embodiment of the present application, the communication device described in the fourth aspect may be a network device, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0058] It can be understood that the technical effects of the device described in the fourth aspect can also refer to the relevant introduction of the method in any of the first to third aspects above, and will not be repeated here.
[0059] In a fifth aspect, a communication device is provided, comprising: a processor coupled to a memory, the processor configured to execute instructions stored in the memory, so that the communication device executes the method described in any one of the first to third aspects.
[0060] In one possible design solution, the communication device described in the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fifth aspect to communicate with other communication devices.
[0061] In an embodiment of the present application, the communication device described in the fifth aspect can be the network device described in any one of the first to third aspects, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0062] In addition, the technical effects of the communication device described in the fifth aspect can refer to the technical effects of the methods described in any one of the first to third aspects, and will not be repeated here.
[0063] In a sixth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store instructions, and when the processor executes the instructions, the communication device executes the method described in any one of the first to third aspects.
[0064] In one possible design solution, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.
[0065] In an embodiment of the present application, the communication device described in the sixth aspect can be the network device described in any one of the first to third aspects, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0066] In addition, the technical effects of the communication device described in the sixth aspect can refer to the technical effects of the methods described in any one of the first to third aspects, and will not be repeated here.
[0067] In a seventh aspect, a chip is provided, comprising: a controller and an interface circuit, wherein the controller is used to interact with other devices through the interface circuit to execute the method described in any one of the first to third aspects.
[0068] In an eighth aspect, a communication system is provided. The communication system includes at least one of the following: a model reasoning functional entity for executing the method described in the first aspect, a model training functional entity for executing the method described in the second aspect, or a model management functional entity for executing the method described in the third aspect.
[0069] In a ninth aspect, a computer-readable storage medium is provided, which includes a computer program or instruction stored therein, and when the computer program or instruction is executed, the method described in any one of the first to third aspects is executed.
[0070] In a tenth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed, enables the method described in any one of the first to third aspects to be executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Figure 1 is a schematic diagram of the neuron structure of DNN;
[0072] Figure 2 is a schematic diagram of the network architecture of DNN;
[0073] Figure 3 is a schematic diagram of the AI beam management process;
[0074] FIG4 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;
[0075] FIG5 is a second schematic diagram of the architecture of the communication system provided in an embodiment of the present application;
[0076] FIG6 is a flow chart of a model management method according to an embodiment of the present application;
[0077] FIG7 is a second flow chart of the model management method provided in an embodiment of the present application;
[0078] FIG8 is a third flow chart of the model management method provided in an embodiment of the present application;
[0079] FIG9 is a first structural diagram of a communication device provided in an embodiment of the present application;
[0080] FIG10 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0081] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, fifth-generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 5.5G and sixth-generation (6G) mobile communication systems.
[0082] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.
[0083] To improve network intelligence and automation, artificial intelligence (AI) and machine learning (ML) technologies are being applied in an increasing number of fields. Research is underway in multiple domains, including the management domain, core network (CN), and radio access network (RAN) domains, to explore how to apply AI / ML technologies to enable network intelligence. Currently, the 3rd Generation Partnership Project (3GPP) working group is researching several topics related to network intelligence. To support the use of models in the network, research is needed on model lifecycle management. The 3GPP SA5 study on artificial intelligence / machine learning (AIMLMGMT) has been successfully approved and discussions have begun. The focus is on model lifecycle management in the 5GS (including the management domain, RAN domain, and core network domain), encompassing capabilities such as model training, inference, performance evaluation, deployment, testing, and updates.
[0084] Current 3GPP standard use cases for AI models include channel state information (CSI) feedback, positioning, and beam management in RAN1, and energy conservation, load balancing, and mobility optimization in RAN3. The model lifecycle management processes for these use cases are largely similar, so for ease of understanding, we'll use AI-beam management as an example to describe the workflow in detail.
[0085] AI-based beam management:
[0086] Machine learning is an important technical approach to achieving artificial intelligence. Machine learning can be divided into supervised learning, unsupervised learning, and reinforcement learning.
[0087] Supervised learning uses a machine learning algorithm to learn the mapping relationship between sample values and sample labels based on collected sample values and sample labels. This learned mapping relationship is then expressed using a machine learning model. The process of training a machine learning model is the process of learning this mapping relationship. For example, in signal detection, a noisy received signal is a sample, and the true constellation point corresponding to this signal is the label. Through training, machine learning aims to learn the mapping relationship between samples and labels, essentially enabling the machine learning model to learn a signal detector. During training, the model parameters are optimized by calculating the error between the model's predicted values and the true labels. Once the mapping relationship is learned, it can be used to predict the label of each new sample. The mapping relationship learned by supervised learning can include linear and nonlinear mappings. Learning tasks can be categorized into classification and regression tasks based on the type of label.
[0088] Unsupervised learning relies solely on collected sample values, using algorithms to discover inherent patterns within them. One type of unsupervised learning algorithm uses the samples themselves as supervisory signals, meaning the model learns the mapping from one sample to another. This is called self-supervised learning. During training, the model parameters are optimized by calculating the error between the model's predictions and the samples themselves. Self-supervised learning can be used in signal compression and decompression recovery applications. Common algorithms include autoencoders and generative adversarial networks.
[0089] Reinforcement learning, unlike supervised learning, is a type of algorithm that learns problem-solving strategies through interaction with the environment. Unlike supervised and unsupervised learning, reinforcement learning problems lack explicit label data for "correct" actions. Instead, the algorithm must interact with the environment to obtain reward signals from the environment, and then adjust its decision-making actions to maximize the reward signal value. For example, in downlink power control, the reinforcement learning model adjusts the downlink transmit power of each user based on the overall system throughput fed back by the wireless network, hoping to achieve higher system throughput. The goal of reinforcement learning is also to learn the mapping between environmental states and optimal decision-making actions. However, because the labels for "correct actions" are not available in advance, network optimization cannot be achieved by calculating the error between actions and "correct actions." Reinforcement learning training is achieved through iterative interaction with the environment.
[0090] Deep neural networks (DNNs) are a specific implementation of machine learning. According to the universal approximation theorem, neural networks can theoretically approximate any continuous function, enabling them to learn arbitrary mappings. Traditional communication systems require extensive expert knowledge to design communication modules. However, DNN-based deep learning communication systems can automatically discover implicit patterns in massive data sets and establish mapping relationships between data, achieving performance superior to traditional modeling methods.
[0091] The idea of DNN is derived from the neuron structure of the brain. Each neuron performs a weighted sum operation on its input values and generates an output through a nonlinear function.
[0092] As shown in Figure 1, for example, we can assume that the input of the neural network is x = [x0, ..., x n ], and the weight corresponding to the input is d=[d0,…,d n ], the bias of the weighted sum is b, and the form of the nonlinear function can be diversified, such as the maximum value function of max{0,x}. In this way, the execution effect of a neuron can be The weights of each neuron are known as the DNN model parameters. These parameters can be optimized through training, enabling the DNN to extract data features and express mapping relationships. DNNs typically use supervised or unsupervised learning strategies to optimize model parameters.
[0093] As shown in Figure 2, a DNN typically has a multi-layered structure, with each layer containing multiple neurons. The DNN's input layer processes the received values through neurons and then passes them to the intermediate hidden layer. DNNs typically have more than one hidden layer, which directly impacts the ability to extract information and fit functions. Increasing the number of hidden layers or increasing the width of each layer can improve the DNN's function fitting capabilities. The DNN's hidden layer then processes the received values through neurons and passes the calculation results to the final output layer, generating the DNN's final output.
[0094] According to the network construction method, DNN can be divided into feed forward neural network (FNN), convolutional neural network (CNN) and recurrent neural network (RNN).
[0095] The characteristic of FNN network is that neurons in adjacent layers are fully connected to each other, which makes FNN usually require a large amount of storage space and leads to high computational complexity.
[0096] CNN is a neural network specifically designed to process data with a grid-like structure. For example, time series data (discrete sampling along the time axis) and image data (discrete sampling along two dimensions) can both be considered grid-like data. CNNs do not utilize all input information at once for computation. Instead, they use a fixed-size window to intercept a portion of the information for convolution operations, significantly reducing the computational complexity of model parameters. Furthermore, depending on the type of information intercepted by the window (e.g., people and objects in an image represent different types of information), each window can use a different convolution kernel, enabling CNNs to better extract features from the input data.
[0097] RNNs are a type of DNN that utilizes feedback time series information. Their input consists of a new input value at the current moment and their own output value at the previous moment. RNNs are suitable for capturing temporally correlated sequence features and are particularly well-suited for applications such as speech recognition and channel coding.
[0098] The above-mentioned FNN, CNN, and RNN are common neural network structures, which are all constructed based on neurons. In fact, there can also be other types or structures of neural networks, which will not be described in detail. In addition, the neural network mentioned in the embodiments of the present application can also be replaced by any other possible expression, such as a neural network model, a network model, an AI model, an AI network model, etc., without limitation.
[0099] When AI models are introduced into beam management, terminals can use them to predict which beams are optimal, further reducing beam management overhead. Over time, AI models experience changes in data distribution, leading to increased model prediction errors. This phenomenon is known as model drift. To address model drift, it is typically necessary to periodically retrain the model with new data to maintain its predictive performance.
[0100] The following describes in detail the model update process of AI-based beam management.
[0101] As shown in Figure 3, the specific process is as follows:
[0102] Steps 1-3: The RAN device collects training data for training or retraining. For example, the RAN device first performs a full beam scan, allowing the UE to determine the reference signal receiving power (RSRP) and the corresponding optimal beam identifier (ID), and then feeds it back to the RAN device.
[0103] Step 4: The RAN device trains the AI model. For example, the RAN device can perform forward calculations and backward feedback propagation based on the collected training data until the model converges, resulting in a trained AI model that can be used to predict the optimal beam ID.
[0104] Steps 5-7: The RAN device uses the AI model to predict the possible optimal beam ID. For example, the RAN device first performs the first round of sparse beam scanning. For example, the base station can send 8 beams with different directions horizontally and 8 beams with different directions vertically, for a total of 64 beams. Sparse beams can be selected from these 64 beams, and their number is typically 1 / 4 of the total number of beams. In the first round of sparse beam scanning, the terminal can use the beam to receive the measurement resources sent by the RAN device via the sparse beam to determine the measurement results, such as RSRP, and feedback them to the RAN device. The RAN device can input the measurement results into the AI model to obtain K beam IDs. These K beams are the beams that the AI model predicts are most likely to be the optimal beams. The value of K can be pre-configured by the AI model, such as 3, 4, or 5.
[0105] In steps 8 and 9, the RAN device determines the optimal beam ID. The RAN device uses the K beams determined above to send measurement resources. Correspondingly, the terminal can use the beam to receive the measurement resources sent by the RAN device via the K beams to determine the measurement results, and ultimately report the measurement resources corresponding to the optimal beam to the RAN device.
[0106] However, AI models in the wireless field face security threats at every stage of their lifecycle, including but not limited to poisoning attacks. For example, training data for AI models in the wireless field is generally obtained from live networks. Therefore, there is a security risk that an adversary could inject poisoned sample points into the data collected from the live network, causing the accuracy of the trained model to degrade. Taking the aforementioned AI beam management as an example, a fake UE controlled by the adversary would report deliberately forged poisoned data (such as false RSRP) to the RAN equipment. This data would be collected as training data for model updates, thereby training an erroneous prediction model, such as incorrect classification boundaries, ultimately leading to a decrease in the prediction performance of the (re)trained model.
[0107] Furthermore, 3GPP also discussed trusted management of AI models in the wireless domain during the Release 18 phase. In TR 28.908, 3GPP explicitly mandated trusted management of AI models: trusted management should be implemented during model training, testing, and inference to enhance the robustness and security of AI models, and AI models should be regularly updated and maintained. Current 3GPP standards primarily manage data collection, including specifying management specifications for data collection, labeling, and processing, as well as protecting user privacy. However, these measures, while not specifically addressing trusted management of wireless AI models, have been ineffective. Furthermore, they lack in-depth research into the security vulnerabilities inherent in the models themselves, resulting in a lack of defense strategies for wireless AI models.
[0108] Therefore, in order to reduce the above-mentioned security risks in the wireless field, necessary security protection measures need to be taken at multiple stages of the model life cycle, such as training, deployment, and updating, to improve the security of the model.
[0109] In response to the above technical problems, the embodiments of the present application propose the following technical solutions.
[0110] The technical solution in this application will be described below with reference to the accompanying drawings.
[0111] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0112] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0113] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.
[0114] In this application, "sending information" can be understood as one device sending information to another device, or as one logic module within a device sending information to another logic module. For example, "a network device sending information" can be understood as a network device sending information to another device (such as a terminal or other network device), or as logic module 1 within a network device sending information to logic module 2 within the network device.
[0115] In this application, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as a logic module within a device receiving information from another logic module. For example, "a network device receiving information" can be understood as the network device receiving information from another device (such as a terminal or other network device), or it can be understood as logic module 1 in the network device receiving information from logic module 2 in the network device.
[0116] In this application, "sending information to... (e.g., a terminal)" or the related illustrations in the accompanying drawings can be understood as the destination end of the information being the terminal. This can include sending information to the terminal directly or indirectly. "Receiving information from... (e.g., a terminal)" or "receiving information from... (e.g., a terminal)" or "receiving information sent by (e.g., a terminal)", or the related illustrations in the accompanying drawings can be understood as the source end of the information being the terminal, which can include receiving information from the terminal directly or indirectly. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.
[0117] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0118] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.
[0119] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0120] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0121] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0122] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using a communication system as an example.
[0123] As shown in FIG4 , exemplarily, the communication system mainly includes at least one of the following: a model training functional entity, a model reasoning functional entity, and a model management functional entity.
[0124] The model training function, also known as the training function or any other possible name, is responsible for AI model training and generating the AI model after training. The model inference function, also known as the inference function or any other possible name, is responsible for AI model inference, inputting data into the model to obtain the corresponding predicted output. The model management function, also known as the management function or any other possible name, is responsible for model management, including performance management, update management, and deployment management.
[0125] Figure 5 is a schematic diagram of the application scenario of the communication system. As shown in (a) of Figure 5, for the service-oriented architecture, a management service (MnS) producer (MnS producer) can provide management services to the outside world. A management service consumer (MnS consumer) can call management services. The management service producer can have AI / ML model training functional entities and inference functions. That is, the model training functional entity and the model inference functional entity can be deployed in the management service producer, or correspond to the management service producer. The model management functional entity can be deployed in the management service consumer, or correspond to the management service consumer.
[0126] As shown in (b) of Figure 5, taking the management domain and service domain as an example, the network management system (NMS) and the element management system (EMS) both belong to the management domain. The NMS is mainly responsible for the operation, management and maintenance functions of the network. For example, if it manages the EMS, it can be called a cross-domain management system. The EMS is mainly used to manage one or more network elements of a certain category, such as the management of network elements in the service domain, for example, AN network elements (such as RAN equipment) or CN network elements, and can also be called a domain management system or a single-domain management system. The NMS / EMS can be a traditional cross-domain / single-domain network management device, or it can be a partial management function set of cross-domain management / single-domain management. Alternatively, the NMS and EMS can also be collectively referred to as a 3GPP management system, or an Operations Administration and Maintenance (OAM) module.
[0127] The model management functional entity can be deployed in the NMS / EMS, the model training functional entity is deployed in the EMS, and the model inference functional entity can be deployed in the RAN equipment or CN network element. Alternatively, both the model training functional entity and the model inference functional entity can be deployed in the RAN equipment or CN network element. For example, the model training functional entity is deployed in the mobile intelligent engine (MIF), while the inference function may be deployed in the converged network element (central unit, CU) or distributed unit (distributed unit, DU). That is, the model training functional entity and the model inference functional entity are deployed in two modules in the gNB respectively. Alternatively, in the O-RAN standard architecture, one possible deployment solution for the model training functional entity is to deploy it in the O-RAN non real time RAN intelligent controller (Non-RT RIC) or the O-RAN near real time RAN intelligent controller (Near-RT RIC), while one possible deployment solution for the model inference functional entity is to deploy it in the O-RAN converged network element (O-CU) or the O-RAN distributed unit (O-DU) in the gNB.
[0128] It can be understood that the EMS, RAN equipment and CN network elements can also correspond to the management service producers in Figure 5, and the NMS can also correspond to the management service consumer in Figure 5.
[0129] The following will be combined with Figures 6-8 to specifically describe the interaction process between each network element / device in the above communication system through a method embodiment. The model management method provided in the embodiment of the present application can be applied to the above communication system and specifically applied to the various scenarios mentioned in the above communication system, which are described in detail below.
[0130] Figure 6 is a flow chart of the model management method provided in an embodiment of the present application. This model management method is applicable to the above-mentioned communication system and mainly involves the interaction between the model reasoning functional entity and the model training functional entity. It can be understood that the method of the embodiment of the present application involves retraining of the model. In the following text, unless otherwise specified, the "training" mentioned below can be understood as "retraining."
[0131] As shown in Figure 6, the process of the management method of this model is as follows:
[0132] S601, the model reasoning functional entity obtains a first communication data set for updating a first machine learning model.
[0133] The machine learning model (referred to as the first machine learning model) can be used to manage wireless communication services, or to ensure wireless communication services. For example, the first machine learning model can be AI beam management, or a beam selection model, or it can also be a model for other management scenarios in wireless communication, such as a downlink / uplink data volume estimation model, a channel fading change estimation model, a CSI feedback model, an AI-assisted positioning model, etc., without specific limitation. The type of the first machine learning model can be DNN, specifically FNN, CNN, or RNN, and of course it can also be other types of models, and the embodiments of the present application do not impose specific restrictions.
[0134] The first communication data set may be a set of wireless communication data collected and fed back by the terminal, such as wireless communication data between an access network device corresponding to a model inference function and multiple terminals, and may specifically include reference signal received power (RSRP), a channel state information matrix, a channel impulse response and other data for service assurance during the wireless communication process. In addition, the first communication data set may also include a label, which may be used to mark the true value of the wireless communication data in the corresponding scenario, and may be selected according to actual conditions. Taking RSRP in the beam management scenario of AI as an example, other scenarios can be understood by reference and will not be described in detail. The wireless communication data may include RSRP and a beam identifier corresponding to the RSRP. The label may be used to mark whether the beam indicated by the beam identifier is the best beam corresponding to the RSRP. For example, the label includes two values 0 / 1, where 1 indicates that the beam indicated by the beam identifier is the best beam corresponding to the RSRP, and 0 indicates that the beam indicated by the beam identifier is not the best beam corresponding to the RSRP. The first communication data set may contain suspicious data with a loss value greater than the first loss threshold. If the proportion of suspicious data in the first communication data set exceeds the first proportion threshold, the model reasoning function entity can eliminate it. Otherwise, the model reasoning function entity can only mark it. For details, please refer to the relevant introduction in S602 below, which will not be repeated here.
[0135] The model inference function entity may be triggered by another device to obtain the first communication data set. For example, the model training function entity may send first indication information to the model inference function entity. The model inference function entity receives the first indication information from the model training function entity and, based on the first indication information, receives wireless communication data from multiple terminals to obtain the first communication data set, thereby achieving on-demand acquisition and avoiding redundancy.
[0136] Among them, the first indication information can be used to indicate that the first machine learning model needs to be updated. For example, the first indication information can carry the identifier of the first machine learning model to indicate that the first machine learning model needs to be updated, or the first indication information can be associated with the identifier of the first machine learning model, and when the model reasoning function entity receives the first indication information, it knows that its associated first machine learning model needs to be updated. Of course, the first indication information can also be implemented in other ways, and the embodiments of the present application are not limited. The first indication information can be carried in any possible signaling / message, and the embodiments of the present application are not limited. In addition, the first indication information can also indicate other parameters, such as the type of data that needs to be collected, such as whether the beam corresponding to RSRP is the optimal beam, the location of the terminal, etc., or the amount of data that needs to be collected.
[0137] The model training functional entity may send first indication information to the model reasoning functional entity based on a first condition, where the first condition may include at least one of the following: condition A, condition B, or condition C, which are introduced below respectively.
[0138] Condition A: The machine learning model has entered its next update cycle.
[0139] The model training functional entity can dynamically update the machine learning model periodically. The model training functional entity can update the cycle of the machine learning model and determine that it has entered the next update cycle of the machine learning model, thereby collecting the data required for updating the first machine learning model by issuing a first indication message, such as a first communication data set. In addition, the cycle for updating the machine learning model can be obtained in advance by the model training functional entity from the model management functional entity. For details, please refer to the relevant introduction below and will not be repeated here.
[0140] Condition B: The prediction accuracy of the machine learning model is lower than the accuracy threshold, so it is necessary to improve the model accuracy by updating the model.
[0141] Among them, the prediction accuracy of the machine learning model can characterize the performance of the machine learning model, and can also be called the accuracy of the machine learning model. When the prediction accuracy of the machine learning model is lower than the accuracy threshold, it is necessary to update the machine learning model to adapt to the current environment and improve the accuracy. Therefore, the model training functional entity can obtain the prediction accuracy of the first machine learning model from the model reasoning functional entity. If the prediction accuracy of the first machine learning model is lower than the accuracy threshold, the model training function collects the data required for this update of the first machine learning model by issuing a first indication message. In addition, the accuracy threshold can be obtained in advance by the model training functional entity from the model management functional entity. For details, please refer to the relevant introduction below, which will not be repeated here.
[0142] Condition C: The proportion of suspicious data in the wireless communication data last obtained for updating the machine learning model is greater than the second proportion threshold, and the time remaining until the end of the machine learning model update is greater than the threshold time.
[0143] The second ratio threshold can also represent the upper limit of the proportion of suspicious data in the communication data set allowed for normal training. If the proportion of suspicious data in the wireless communication data used to update the machine learning model obtained last time is greater than the second ratio threshold, that is, exceeds the upper limit, it means that the sample size of normal data is insufficient to complete the update of the first machine learning model this time. Therefore, the model training functional entity can determine the remaining time from the end of the model update of this cycle based on the maximum waiting time of this update and the time spent on local update. The model training functional entity can estimate whether the time required to re-collect data and update the model is less than or equal to the remaining time. If it is less than or equal to the remaining time, the model training functional entity can collect the data required for updating the first machine learning model again by issuing a first indication message to ensure the effect of this model update by re-acquiring data. Otherwise, if it is greater than the remaining time, the model training functional entity can determine that this update has failed. In addition, the maximum waiting time can be obtained in advance by the model training functional entity from the model management functional entity. For details, please refer to the relevant introduction below and will not be repeated here.
[0144] It can be understood that conditions A and B apply not only to the case where the model reasoning functional entity marks suspicious data, but also to the case where the model reasoning functional entity removes suspicious data. For details, please refer to the relevant introduction of S602 below, which will not be repeated here. Condition C can only apply to the case where the model reasoning functional entity marks suspicious data. In other words, if the model training functional entity knows in advance that the model reasoning functional entity is marking suspicious data, then the model training functional entity can analyze the wireless communication data obtained from the model reasoning functional entity based on condition C. For details, please refer to the relevant introduction of S602 below, which will not be repeated here.
[0145] Optionally, when condition C applies, the model training functional entity may also send a second loss threshold to the model reasoning functional entity, and accordingly, the model reasoning functional entity may receive the second loss threshold from the model training functional entity. The second loss threshold may be smaller than the loss threshold pre-configured by the model reasoning functional entity, such as the first loss threshold, to relax the threshold for suspicious data defined by the model reasoning functional entity and ensure that re-collection can provide more normal data for training. In addition, the second loss threshold may be issued together with the first indication information, such as in the same signaling or message, or may be issued separately, without limitation.
[0146] S602: The model training function entity sends a second communication data set to the model training function entity.
[0147] The second communication data set may be obtained by performing a processing operation on suspicious data in the first communication data set according to the first processing strategy, such as also including wireless communication data between the access network device and multiple terminals. The first processing strategy can be used to perform a processing operation on data (such as suspicious data) in the communication data set used to update the machine learning model.
[0148] Suspicious data can be considered as data suspected of being poisoned, specifically wireless communication data with a loss value less than or equal to a loss threshold (denoted as the first loss threshold). For example, a poisoning attacker can maliciously change the label of the wireless communication data, resulting in a relatively large loss value for training, affecting model convergence. Therefore, the loss value of the wireless communication data can reflect to a certain extent whether the data is poisoned data, and thus the wireless communication data with a loss value greater than the loss threshold in the communication data set can be considered as suspected poisoned data, that is, suspicious data. Conversely, if the loss value of the wireless communication data in the communication data set is less than or equal to the first loss threshold, the wireless communication data can be considered as normal data, or not poisoned data, that is, normal data is also wireless communication data with a loss value less than or equal to the first loss threshold. In addition, how to determine the loss value of wireless communication data can refer to the relevant introduction below, which will not be repeated here.
[0149] The first loss threshold can be indicated by the first processing strategy. For example, the first processing strategy can explicitly indicate the first loss threshold, such as including the first loss threshold, that is, the first ratio threshold can be dynamically configured along with the first processing strategy to achieve dynamic adjustment according to actual needs. Alternatively, the first processing strategy can also implicitly indicate the first loss threshold, such as the first processing strategy and the first loss threshold management, obtaining the first processing strategy means that the first loss threshold needs to be used. At this time, the first ratio threshold can also be pre-configured locally in the model inference functional entity to avoid the overhead brought by the configuration. The value of the first loss threshold can be a value between 0 and 1, such as 0.4, 0.5, 0.6, etc. The specific value can be selected according to the actual situation and there is no restriction on this.
[0150] Processing operations can be used to mark suspicious data or remove suspicious data. For example, processing operations may include marking operations, which refers to adding an identifiable mark to the suspicious data, or marking it, so as to subsequently identify which data is suspicious data, avoid the suspicious data from affecting the retraining of the first machine learning model, and ensure the effect of model retraining. For example, the sending end adds a corresponding mark to the suspicious data, which can be a special cell, character, or field, and the sending end does not add the mark to normal data. The receiving end can determine whether the received wireless communication data has the mark to determine whether the wireless communication data is suspicious data or normal data. Processing operations can also include removal operations, recorded as removal operation #1, which refers to removing suspicious data from the communication data set, such as deleting or releasing it, to avoid the subsequent use of suspicious data to retrain the first machine learning model, and ensure the effect of model retraining.
[0151] The marking operation can be performed if the proportion of suspicious data in the communication data set used to update the machine learning model is greater than or equal to a first ratio threshold. Conversely, the elimination operation #1 can be performed if the proportion of suspicious data in the communication data set used to update the machine learning model is less than the first ratio threshold. The first ratio threshold may represent the upper limit of the proportion of suspicious data in the communication data set allowed for normal training. In other words, if the proportion of suspicious data in the communication data set is less than or equal to the first ratio threshold, it indicates that the number of suspicious data is not too large. Even if this suspicious data is eliminated, the sample size of normal data remaining in the communication data set is sufficient to complete normal training of the machine learning model. Therefore, the model inference function entity can perform the elimination operation #1. Conversely, if the proportion of suspicious data in the communication data set is greater than the first ratio threshold, it indicates that the number of suspicious data is too large. If this suspicious data is eliminated directly, the sample size of normal data may not be sufficient to complete normal training of the machine learning model. Therefore, the model inference function entity can perform the marking operation to help the model training function entity decide whether to use or eliminate this suspicious data. Of course, the marking operation or the culling operation #1 may also be performed by default, such as performing the marking operation by default, or performing the culling operation #1 by default.
[0152] The first processing strategy may also indicate a processing operation, such as explicitly or implicitly indicating the processing operation. The specific implementation principle can be understood by referring to the above and will not be described in detail here.
[0153] It should be understood that the first processing strategy is an exemplary name, which can also be replaced by any possible name, such as the first trusted processing strategy, or the first training data processing strategy, etc., and the embodiments of the present application do not limit it.
[0154] In an embodiment of the present application, the model reasoning functional entity may process the first communication data set through the first machine learning model to determine suspicious data in the first communication data set. That is, the model reasoning functional entity may use the first machine learning model to perform inference calculations on the first communication data set to determine the suspicious data therein. For example, the model reasoning functional entity may use the first machine learning model to process the first communication data set according to the first processing strategy to obtain a processing result for each wireless communication data in the first communication data set, and determine the loss value of each wireless communication data based on the processing result of each wireless communication data and the label of each wireless communication data, thereby determining the wireless communication data whose loss value is greater than the first loss threshold as suspicious data.
[0155] For ease of understanding, we will still use the AI beam management scenario as an example. Other scenarios can be understood by reference and will not be elaborated on. The processing result of wireless communication data #1 can be the probability that the beam corresponding to RSRP #1 is the optimal beam, such as 0.8. If the label of RSRP #1 indicates that the beam corresponding to RSRP #1 is the optimal beam, that is, the label is 1, then the loss value of wireless communication data #1 is 0.2. Similarly, the processing result of wireless communication data #2 can be the probability that the beam corresponding to RSRP #2 is the optimal beam, such as 0.7. If the label of RSRP #2 indicates that the beam corresponding to RSRP #2 is not the optimal beam, that is, the label is 0, then the loss value of wireless communication data #2 is 0.7. Assuming that the first loss threshold is 0.4, then wireless communication data #1 is normal data and wireless communication data #2 is suspicious data. In other words, data processing results should generally be close to the data label. If the data processing results differ significantly from the data label, it could be that a poisoning attacker has intentionally tampered with the data label, for example, changing the beam corresponding to RSRP#2 from being the optimal beam to not being the optimal beam, thereby affecting model training. Therefore, by setting the first loss threshold, suspicious data that may have been tampered with can be screened out.
[0156] The model reasoning functional entity may also determine the proportion of suspicious data in the first communication data set based on the first processing strategy. For example, according to the above description of the processing operation, if the model reasoning functional entity determines that the proportion of suspicious data in the first communication data set is greater than the first ratio threshold, the model reasoning functional entity may perform a marking operation, such as adding an identifiable mark to the suspicious data in the first communication data set to obtain a second communication data set; if the model reasoning functional entity determines that the proportion of suspicious data in the first communication data set is less than or equal to the first ratio threshold, the model reasoning functional entity may perform a removal operation #1, such as removing the suspicious data from the first communication data set to obtain a second communication data set. Then, the model reasoning functional entity may send the second communication data set to the model training functional entity, such as sending a signaling / message carrying the second communication data set, which may be an existing signaling / message or a newly defined signaling / message, without limitation. Accordingly, the model training functional entity may obtain the second communication data set, such as receiving the second communication data set from the model reasoning functional entity.
[0157] Optionally, if the model reasoning function entity obtains a second loss threshold from the model training function entity, the model reasoning function entity may use the second loss threshold to replace the first loss threshold, and use the second loss threshold to determine suspicious data in the first communication data set.
[0158] It is understood that the model training function entity performing the marking operation or the elimination operation #1 based on the proportion of suspicious data in the communication data set is only an example and is not intended to be limiting. For example, the model training function entity may perform the marking operation by default, or may also perform the elimination operation #1 by default.
[0159] The model training functional entity may determine whether the second communication data set is obtained by executing elimination operation #1 or by executing elimination operation #2. If the second communication data set is obtained by executing elimination operation #1, such as a communication data set from which suspicious data has been eliminated, the model training functional entity may execute S603 as follows. Otherwise, if the second communication data set is obtained by executing elimination operation #1, such as a communication data set from which suspicious data has been marked, the model training functional entity may execute S604 as follows, which are described separately below.
[0160] S603, the model training functional entity updates the first machine learning model according to the second communication data set.
[0161] The model training functional entity can use the second communication data set to train the first machine learning model, and when convergence is reached, determine that the training is completed, and obtain an updated machine learning model, which is recorded as the second machine learning model.
[0162] S604, the model training functional entity updates the first machine learning model according to the third communication data set.
[0163] The third communication data set can be obtained by performing a removal operation (denoted as removal operation #2) on suspicious data or erroneous data in the second communication data set according to the second processing strategy. The second processing strategy can be used to perform removal operation #2 on suspicious data or erroneous data in the communication data set used to update the machine learning model. For example, the second processing strategy may indicate removal operation #2, such as explicitly or implicitly indicating removal operation #2. The specific implementation principle can also be understood with reference to the above and will not be repeated here. The erroneous data may be data from a poisoning attack, and its characteristic may be that if the erroneous data is used to update the first machine learning model, the updated machine learning model will not be effective in processing wireless communication data, and its loss value is usually relatively large, such as greater than the third loss threshold.
[0164] The following specifically introduces whether the model training functional entity performs the elimination operation #2 on suspicious data or erroneous data.
[0165] Exemplarily, the second processing strategy may further indicate a second condition, such as explicitly or implicitly indicating the second condition. The specific implementation principles can also be understood with reference to the above and are not further described here. The second condition may refer to the percentage of suspicious data in the communication data set being less than or equal to a second ratio threshold. Thus, the model training functional entity may determine whether to update the first machine learning model based on the second condition.
[0166] If the proportion of suspicious data in the second communication data set is less than or equal to the second ratio threshold, it means that the number of suspicious data is not too large. Even if this part of the suspicious data is eliminated, the sample size of normal data remaining in the second communication data set can complete the normal training of the first machine learning model. Therefore, the model inference function entity can perform elimination operation #2, such as eliminating the suspicious data in the second communication data set.
[0167] If the proportion of suspicious data in the second communication data set is greater than the second ratio threshold, it means that if this part of the suspicious data is removed, the sample size of the normal data remaining in the second communication data set may not be able to complete the normal training of the first machine learning model. Therefore, the model training functional entity can choose to re-acquire the wireless communication data for updating the machine learning model according to the above-mentioned first condition, such as condition C, that is, return to execute S601. Alternatively, the model training functional entity can also choose to remove the erroneous data from the second communication data set, specifically, to remove the erroneous data in the suspicious data from the second communication data set, which is described in detail below.
[0168] For example, the second processing strategy may include a third loss threshold. The model training functional entity may determine which data in the suspicious data is erroneous data through the third loss threshold. Exemplarily, the model training functional entity divides the suspicious data into M data subsets. M is an integer greater than 1, and its value can be set according to actual conditions and is not limited thereto. The model training functional entity may use the i-th data subset in the M data subsets to update the first machine learning model, i traverses from 1 to M, and obtains the i-th updated machine learning model. The model training functional entity may use the i-th updated machine learning model to process the test data, i traverses from 1 to M, and obtains the i-th test result. The test data may include wireless communication data pre-configured by the model training functional entity for testing the model training effect. If the loss value of the test data in the i-th test result is greater than the third loss threshold, the model training functional entity determines that the i-th data subset is erroneous data; otherwise, the model training functional entity determines that the i-th data subset is not erroneous data.
[0169] That is, since poisoned data affects model training, the model training functional entity can use suspicious data to pre-train the machine learning model. This allows the model to identify suspicious data that has no effect on model training as erroneous data based on the training results. For example, when training a machine learning model with normal data, since training will cause the model to converge, the updated machine learning model processing test data should produce results that are relatively close to the corresponding label, i.e., a smaller loss value. For example, if the processing result is a probability value of 0.9 and a label of 1, the loss value is as small as 0.1. If the machine learning model is trained with erroneous data, since the erroneous data will inhibit the convergence of the machine learning model, the processing result of the updated machine learning model processing test data will differ significantly from the corresponding label. For example, if the processing result is a probability value of 0.7 and a label of 1, the loss value is as small as 0.3. In this case, if the third loss threshold is set to 0.2, the model training functional entity can distinguish between normal data and erroneous data.
[0170] It should be understood that by dividing the suspicious data into multiple data subsets, it is also possible to eliminate erroneous data at the granularity of data subsets. Compared with eliminating all suspicious data, the granularity is finer and normal data can be retained. In addition, since the computing power of the model training functional entity is more powerful than that of the model reasoning functional entity, when the model reasoning functional entity is unable to distinguish which data in the suspicious data are normal data and which data are poisoning attack data, the model training functional entity can use a more refined elimination operation to eliminate the data in the suspicious data that are truly poisoning attacks, and use the normal data in the suspicious data for model training to improve the utilization efficiency of the training data. Of course, the determination of erroneous data from the suspicious data by the model training functional entity is only an example. For example, the model training functional entity can also divide the second communication data set into multiple data subsets and determine the erroneous data therefrom.
[0171] After performing elimination operation #2 on suspicious data or erroneous data in the second communication data set, the model training functional entity can use the normal data in the second communication data set to train the first machine learning model, and when convergence is reached, determine that the training is completed to obtain the second machine learning model.
[0172] It should be understood that the second processing strategy is an exemplary name and can be replaced with any other possible name, such as a second trusted processing strategy or a second training data processing strategy, without limitation in the present embodiment. Furthermore, the second processing strategy can also indicate the first condition described above, such as explicitly or implicitly indicating the first condition. The specific implementation principles can also be understood by referring to the above and will not be elaborated here.
[0173] It should also be understood that since the main purpose of a poisoning attack is to affect the training effect of the model and reduce its training accuracy, the main function of the poisoning attack data is to suppress the convergence effect of the model training, that is, the loss value of the training model is relatively large. Accordingly, the model training functional entity can also adopt a similar method to the above-mentioned model reasoning functional entity to determine the data in the first communication data set with a loss value greater than the first loss threshold as erroneous data, such as poisoning attack data, and remove it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.
[0174] In summary, since the main purpose of a poisoning attack is to affect the training effect during the model retraining and updating process, thereby reducing its training accuracy, that is, the updated model has a relatively large loss value on the poisoned data. Accordingly, the model reasoning function entity can identify data in the first communication data set whose loss value is greater than the first loss threshold as suspicious data, or data suspected of being poisoned, and process it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.
[0175] In addition, the model training functional entity can also adopt a method similar to the above-mentioned model inference functional entity to determine the data in the first communication data set whose loss value is greater than the first loss threshold as erroneous data, such as poison attack data, and eliminate it to avoid adverse effects on the training of the first machine learning model and reduce the data security risks of AI models in the wireless field.
[0176] In conjunction with the above method, in a first possible design solution, the method may further include: the model management function entity may obtain a first processing strategy for the first machine learning model and send the first processing strategy to the model reasoning function entity. Accordingly, the model reasoning function entity may receive the first processing strategy from the model management function entity. That is, the first processing strategy may also be dynamically configured by the network element / entity of the management domain to enable dynamic adjustment based on actual needs.
[0177] Among them, the model management functional entity can pre-configure or pre-define the first processing strategy locally. The model management functional entity can obtain the first processing strategy from the local at any possible time, such as when the current time is the time to issue the first processing strategy, or when the model management functional entity learns that the model reasoning functional entity currently needs to obtain the first processing strategy, such as when the first processing strategy has not been configured for the model reasoning functional entity in advance. Then, the model management functional entity can send the first processing strategy to the model reasoning functional entity, such as sending a signaling / message carrying the first processing strategy, which can be an existing signaling / message or a newly defined signaling / message, and there is no restriction on this. Accordingly, the model reasoning functional entity can obtain the first processing strategy by receiving and parsing these signaling / messages.
[0178] Of course, the model reasoning function entity may also pre-configure or pre-define the first processing strategy locally to avoid configuration overhead. The model reasoning function entity may obtain the first processing strategy locally at any possible opportunity, such as when the first communication data set has been obtained and the first processing strategy needs to be obtained locally to process the first communication data set. Alternatively, the model reasoning function entity may periodically obtain the first processing strategy locally.
[0179] In combination with the above method, in a second possible design solution, the method may further include: the model management functional entity may obtain a second processing strategy for the first machine learning model and send the second processing strategy to the model training functional entity. Accordingly, the model training functional entity may receive the second processing strategy from the model management functional entity.
[0180] Among them, the model management functional entity can pre-configure or pre-define the second processing strategy locally. The model management functional entity can obtain the second processing strategy from the local at any possible time, such as when the current time is the time to issue the second processing strategy, or when the model management functional entity learns that the model training functional entity currently needs to obtain the second processing strategy, such as when the second processing strategy has not been configured for the model training functional entity in advance. Then, the model management functional entity can send the second processing strategy to the model training functional entity, such as sending a signaling / message carrying the second processing strategy, which can be an existing signaling / message or a newly defined signaling / message, and there is no restriction on this. Accordingly, the model training functional entity can obtain the second processing strategy by receiving and parsing these signaling / messages.
[0181] Of course, the model training functional entity may also pre-configure or pre-define the second processing strategy locally. The model training functional entity may obtain the second processing strategy locally at any possible opportunity, such as when the second communication data set has been obtained and the second processing strategy needs to be obtained locally to process the second communication data set. Alternatively, the model inference functional entity may periodically obtain the second processing strategy locally.
[0182] In combination with the above method, in a third possible design scheme, after S603 or S604, the method may further include: the model training functional entity sends second indication information to the model reasoning functional entity; accordingly, the model reasoning functional entity receives the second indication information from the model training functional entity and obtains a second machine learning model based on the second indication information. The second indication information can be used to indicate the second machine learning model, such as carrying the identification and address information of the second machine learning model, and the second machine learning model is obtained by updating the first machine learning model. In this way, the machine learning model is updated to avoid the impact on actual business due to reduced model accuracy.
[0183] The above describes the arrangement process of the model management method provided by the embodiment of the present application in conjunction with Figure 6. The following describes in detail the specific process of the model management method provided by the embodiment of the present application in various scenarios in conjunction with Figures 7-8.
[0184] Scenario 1:
[0185] Figure 7 is a second flow diagram of a model management method provided in an embodiment of the present application. This model management method is primarily applicable to communication between a model inference functional entity, a model training functional entity, and a model management functional entity. The model management functional entity can be deployed in an EMS / NMS, while the model training functional entity and the model inference functional entity can be deployed in access network equipment, such as a gNB.
[0186] Specifically, as shown in FIG7 , the process of the management method of the model is as follows:
[0187] S701: The model management functional entity sends a first processing strategy to the model reasoning functional entity.
[0188] The first processing strategy may include at least one of the following: an identifier of the machine learning model, or a first loss threshold. The identifier of the machine learning model is a unique identifier of the model, used to distinguish different machine learning models, and the identifier of the machine learning model before the update can be reused after the machine learning model is updated. That is, the first machine learning model and the second machine learning model can share the same machine learning model identifier. In addition, the specific implementation of the first loss threshold can also refer to the relevant introduction of the method shown in Figure 6 above, which will not be repeated here.
[0189] S702: The model management functional entity sends a second processing strategy to the model training functional entity.
[0190] The second processing strategy may include at least one of the following: an identifier of a machine learning model, a first condition, a second condition, or a second ratio threshold. The specific implementation may also refer to the relevant introduction of the method shown in Figure 6 above, which will not be repeated here.
[0191] Optionally, the second processing strategy may further include at least one of the following: an update cycle, an update threshold, an accuracy threshold, or a maximum waiting time. The update cycle may indicate how often the machine learning model needs to be retrained and updated to prevent model drift from affecting prediction accuracy and ensure that the model consistently maintains high prediction accuracy. The update threshold is the threshold that the machine learning model's update performance must reach; the model update is not initiated until the retrained model's performance meets the update threshold. In one implementation, the update threshold may indicate the minimum performance value of the retrained machine learning model; that is, the update is not initiated until the retrained model's performance exceeds the update threshold. In another implementation, the update threshold may indicate the minimum performance gain of the model; that is, the update is not initiated until the difference between the retrained model's performance and the pre-training model's performance exceeds the update threshold. The accuracy threshold may indicate the minimum level of prediction accuracy that the retrained model must achieve; models below this accuracy threshold are considered incomplete and require continued training. The maximum waiting time may indicate the maximum duration required for a model update; if the update is not completed after this time, the update is paused.
[0192] S703: The model training functional entity sends first indication information to the model reasoning functional entity.
[0193] Among them, the model training functional entity can send the first indication information to the model reasoning functional entity according to condition A or condition B in the first condition. The specific implementation can also refer to the above-mentioned relevant introduction and will not be repeated here.
[0194] S704: The model reasoning function entity obtains a second communication data set.
[0195] The model reasoning function entity can obtain a first communication data set from multiple terminals based on the first indication information, and perform a marking operation on suspicious data in the first communication data set whose loss value is greater than the first loss threshold according to the first processing strategy to obtain a second communication data set.
[0196] In addition, the specific implementation of S704 can also refer to the relevant introduction of S602 above, which will not be repeated here.
[0197] S705: The model reasoning function entity sends a second communication data set to the model training function entity.
[0198] S706: The model training function entity performs a removal operation on suspicious data in the second communication data set.
[0199] The model training functional entity can determine, based on a second processing strategy, such as a second condition, that the proportion of suspicious data in the second communication data set is less than a second proportion threshold, thereby performing a removal operation on the suspicious data in the second communication data set.
[0200] S707: The model training functional entity sends first indication information to the model reasoning functional entity.
[0201] Among them, the model training functional entity can send the first indication information to the model reasoning functional entity according to condition C in the first condition. The specific implementation can also refer to the above-mentioned relevant introduction and will not be repeated here.
[0202] S708: The model training functional entity sends a second loss threshold to the model reasoning functional entity.
[0203] The second loss threshold may be delivered together with the first indication information in S707, or may be delivered separately.
[0204] It can be understood that S708 is an optional step, and the model training functional entity may not send the second loss threshold, and the model reasoning functional entity continues to use the pre-configured first loss threshold to determine suspicious data.
[0205] Furthermore, when S707 is executed, the flow of the method returns to execute S704 again.
[0206] S709, the model training function entity uses the normal data in the second communication data set to train the first machine learning model to obtain a second machine learning model.
[0207] S710: The model training functional entity sends second indication information to the model reasoning functional entity.
[0208] Among them, the second indication information can be used to indicate the second machine learning model. The specific implementation can also refer to the relevant introduction of the above method, which will not be repeated here.
[0209] S711, the model training functional entity sends third indication information to the model management functional entity.
[0210] The third indication information may be used to report a successful model update and may specifically include at least one of the following: an identifier of the second machine learning model, a model version, and an update time. The model version may indicate the updated model, such as the version of the second machine learning model, and the update time may indicate the time when the model update occurred or was completed.
[0211] Scenario 2:
[0212] Figure 8 is a flow chart of the third embodiment of the model management method provided in the embodiment of the present application. For example, the model management method is mainly applicable to the communication between the model reasoning functional entity, the model training functional entity, and the model management functional entity. The model management functional entity and the model training functional entity can both be deployed in the EMS / NMS, but their deployment can be decoupled. For example, the model training functional entity can be deployed separately in the AI training functional module in the EMS / NMS. The model reasoning functional entity can be deployed in access network equipment, such as gNB.
[0213] Specifically, as shown in FIG8 , the process of the management method of the model is as follows:
[0214] S801: The model management functional entity sends a first processing strategy to the model reasoning functional entity.
[0215] The first processing strategy may include at least one of the following: an identifier of a machine learning model, a first loss threshold, or a first ratio threshold. The specific implementation may also refer to the relevant introduction of the method shown in FIG6 above, which will not be repeated here.
[0216] S802: The model management functional entity sends a second processing strategy to the model training functional entity.
[0217] The second processing strategy may include at least one of the following: an identifier of a machine learning model, a first condition, a second condition, a third loss threshold, or a second ratio threshold. The specific implementation may also refer to the relevant introduction of the method shown in Figure 6 above, which will not be repeated here.
[0218] Optionally, the second processing strategy may further include at least one of the following: an update cycle, an update threshold, an accuracy threshold, or a maximum waiting time. For specific implementation, reference may be made to the above description of S702 and will not be repeated here.
[0219] S803: The model training functional entity sends first indication information to the model reasoning functional entity.
[0220] Among them, the model training functional entity can send the first indication information to the model reasoning functional entity according to condition A or condition B in the first condition. The specific implementation can also refer to the above-mentioned relevant introduction and will not be repeated here.
[0221] S804: The model training functional entity obtains a second communication data set.
[0222] The model training function entity may obtain a first communication data set from multiple terminals based on the first indication information. At this point, the model training function entity may determine the proportion of suspicious data in the first communication data set based on the first processing strategy. If the proportion of suspicious data is less than or equal to a first ratio threshold, the model training function entity may remove the suspicious data from the first communication data set to obtain a second communication data set. If the proportion of suspicious data is greater than the first ratio threshold, the model training function entity may mark the suspicious data in the first communication data set to obtain a second communication data set.
[0223] In addition, the specific implementation of S704 can also refer to the relevant introduction of S602 above, which will not be repeated here.
[0224] S805: The model training function entity sends a second communication data set to the model training function entity.
[0225] It can be understood that if the second communication data set is a communication data set from which suspicious data has been removed, the model training function entity executes S806; otherwise, if the second communication data set is a communication data set from which suspicious data has been marked, the model training function entity executes S807-S808.
[0226] S806, the model training functional entity uses the second communication data set to train the first machine learning model to obtain a second machine learning model.
[0227] The specific implementation of S806 can also refer to the relevant introduction of S603 above, which will not be repeated here.
[0228] S807: The model training function entity performs a removal operation on the erroneous data in the second communication data set to obtain a third communication data set.
[0229] S808, the model training functional entity uses the third communication data set to train the first machine learning model to obtain a second machine learning model.
[0230] The specific implementation of S807-S808 can also refer to the relevant introduction of S604 above, which will not be repeated here.
[0231] S809: The model training functional entity sends second indication information to the model reasoning functional entity.
[0232] The second indication information can be used to indicate the second machine learning model. The specific implementation can also refer to the relevant introduction of the above method, which will not be repeated here.
[0233] S810, the model training functional entity sends third indication information to the model management functional entity.
[0234] The specific implementation of S810 can also refer to the relevant introduction of S711 above, which will not be repeated here.
[0235] It can be understood that in the above scenario 2, the model training functional entity and the model management functional entity can also be replaced by being deployed in Non-RT RIC or Near-RT RIC, and the model reasoning functional entity can also be replaced by being deployed in O-CU of O-RAN or O-DU of O-RAN.
[0236] The above describes in detail the model management method provided by the embodiment of the present application in conjunction with Figures 6 to 8. The following describes in detail the communication device for executing the model management method provided by the embodiment of the present application in conjunction with Figures 9 and 10.
[0237] Figure 9 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 9 , the communication device 900 includes a transceiver module 901 and a processing module 902. For ease of illustration, Figure 9 only shows the main components of the communication device.
[0238] The transceiver module 901 is used to perform the transceiver function of the method shown in FIG. 6 to FIG. 8 , and the processing module 902 is used to perform other functions of the method shown in FIG. 6 to FIG. 8 except the transceiver function.
[0239] Optionally, the transceiver module 901 may include a sending module (not shown in FIG9 ) and a receiving module (not shown in FIG9 ). The sending module is used to implement the sending function of the communication device 900 , and the receiving module is used to implement the receiving function of the communication device 900 .
[0240] Optionally, the communication device 900 may further include a storage module (not shown in FIG. 9 ) storing a program or instruction. When the processing module 902 executes the program or instruction, the communication device 900 may perform the functions of the method shown in FIG. 6 to FIG. 8 .
[0241] It can be understood that the communication device 900 can be a terminal or a network device, or a chip (system) or other parts or components that can be set in a terminal or a network device, or a device that includes a terminal or a network device. This application does not limit this.
[0242] In addition, the technical effects of the communication device 900 can refer to the technical effects of the model management method shown in Figures 6 to 8, and will not be repeated here.
[0243] Figure 10 is a second structural diagram of a communication device provided in an embodiment of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other component or assembly that can be provided in a terminal. As shown in Figure 10, the communication device 1000 may include a processor 1001. Optionally, the communication device 1000 may further include a memory 1002 and / or a transceiver 1003. The processor 1001 is coupled to the memory 1002 and the transceiver 1003, such as by a communication bus.
[0244] The following is a detailed introduction to the various components of the communication device 1000 in conjunction with FIG10 :
[0245] The processor 1001 is the control center of the communication device 1000 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1001 can be one or more central processing units (CPUs), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0246] Optionally, the processor 1001 can execute various functions of the communication device 1000 by running or executing software programs stored in the memory 1002 and calling data stored in the memory 1002, such as executing the management method of the model shown in Figures 6 to 8 above.
[0247] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG10 .
[0248] In a specific implementation, as an embodiment, the communication device 1000 may also include multiple processors, such as the processor 1001 and the processor 1004 shown in FIG10 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0249] The memory 1002 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 1001. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0250] Alternatively, the memory 1002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 via an interface circuit (not shown in FIG. 10 ) of the communication device 1000. This embodiment of the present application does not specifically limit this.
[0251] Transceiver 1003 is used for communication with other communication devices. For example, if communication device 1000 is a terminal, transceiver 1003 can be used to communicate with a network device or another terminal device. For another example, if communication device 1000 is a network device, transceiver 1003 can be used to communicate with a terminal or another network device.
[0252] Optionally, the transceiver 1003 may include a receiver and a transmitter (not shown separately in FIG10 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0253] Optionally, the transceiver 1003 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through an interface circuit (not shown in FIG. 10 ) of the communication device 1000 . This embodiment of the present application does not specifically limit this.
[0254] It is understandable that the structure of the communication device 1000 shown in FIG10 does not constitute a limitation on the communication device, and an actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0255] In addition, the technical effects of the communication device 1000 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.
[0256] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0257] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0258] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0259] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0260] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0261] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0262] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0263] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0264] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0265] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0266] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0267] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0268] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A model management method, characterized in that: Applied to model reasoning functional entities, including: Acquire a first communication data set for updating a first machine learning model, wherein the first machine learning model is used to manage wireless communication services; A second communication data set is sent to the model training functional entity, where the second communication data set is obtained by performing a processing operation on suspicious data in the first communication data set according to a first processing strategy, where the first processing strategy includes a first loss threshold, and the suspicious data is wireless communication data having a loss value greater than the first loss threshold.
2. The method according to claim 1, characterized in that The processing operation includes a marking operation, and the marking operation refers to adding a mark for easy identification to the suspicious data.
3. The method according to claim 2, characterized in that Before performing the marking operation, the method further includes: determining that a proportion of suspicious data in the first communication data set is greater than a first proportion threshold.
4. The method according to claim 1, characterized in that: The processing operation includes a removal operation, and the removal operation refers to removing the suspicious data from the first communication data set.
5. The method according to claim 4, characterized in that Before performing the elimination operation, the method further includes: determining that a proportion of suspicious data in the first communication data set is less than or equal to a first proportion threshold.
6. The method according to claim 3 or 4, characterized in that: The first processing strategy includes the first ratio threshold.
7. The method according to any one of claims 1 to 6, characterized in that: The first processing strategy indicates the processing operation.
8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: The first processing strategy is received from a model management function.
9. The method according to claim 8, characterized in that The model reasoning function entity is deployed on the access network device.
10. The method according to claim 8 or 9, characterized in that: The model reasoning functional entity is deployed on the open centralized unit O-CU or the open distributed unit O-DU of the access network device.
11. The method according to any one of claims 1 to 10, characterized in that After sending the second communication data set to the model training function entity, the method further includes: Receive second indication information from the model training function entity; wherein the second indication information is used to indicate a second machine learning model, and the second machine learning model is obtained by updating the first machine learning model; According to the second indication information, obtain the second machine learning model.
12. A model management method, characterized in that: Applied to model training functional entities, including: Acquire a second communication data set for updating a first machine learning model, wherein the first machine learning model is used to manage wireless communication services; The first machine learning model is updated according to a third communication data set, wherein the third communication data set is obtained by performing a elimination operation on erroneous data in the second communication data set according to a second processing strategy, and the second processing strategy includes a third loss threshold. If the erroneous data is used to update the first machine learning model, then the loss value of the wireless communication data processed by the updated machine learning model is greater than the third loss threshold.
13. The method according to claim 12, characterized in that The removing operation refers to removing the erroneous data from the second communication data set.
14. The method according to claim 13, characterized in that The elimination operation specifically refers to eliminating the erroneous data in the data marked as suspicious from the second communication data set, and the data marked as suspicious is the wireless communication data in the second communication data set whose loss value is greater than a loss threshold.
15. The method according to any one of claims 12 to 14, characterized in that: The second processing strategy indicates the culling operation.
16. The method according to any one of claims 12 to 15, characterized in that: The method further comprises: The second processing strategy is received from a model management function.
17. The method according to any one of claims 12 to 16, characterized in that: Before obtaining the second communication data set for updating the first machine learning model, the method further includes: Sending first indication information to the model reasoning function entity, wherein the first indication information is used to indicate that the first machine learning model needs to be updated; The obtaining of a second communication data set for updating the first machine learning model comprises: The second communication data set is received from the model reasoning function.
18. The method according to claim 17, characterized in that The sending of the first indication information to the model reasoning function entity includes: According to the first condition, the first indication information is sent to the model inference functional entity, wherein the first condition includes at least one of the following: the next update cycle of the machine learning model has been entered, the prediction accuracy of the machine learning model is lower than the accuracy threshold, or the proportion of suspicious data in the wireless communication data last obtained for updating the machine learning model is greater than the second proportion threshold, and the current remaining time until the end of the machine learning model update is greater than the threshold time; the threshold time is the sum of the time required to obtain the wireless communication data for updating the machine learning model and the time required to update the machine learning model.
19. The method according to claim 18, characterized in that The method further comprises: A second loss threshold is sent to the model reasoning function entity.
20. The method according to claim 18 or 19, characterized in that The second processing strategy also indicates the first condition.
21. The method according to any one of claims 18 to 20, characterized in that Before updating the first machine learning model according to the third communication data set, the method further includes: According to a second condition, determine to update the first machine learning model, wherein the second condition refers to that the proportion of suspicious data in the communication data set is less than or equal to the second proportion threshold.
22. The method according to claim 21, characterized in that The second processing strategy also indicates the second condition.
23. The method according to any one of claims 18 to 22, characterized in that The second processing strategy includes the second ratio threshold.
24. The method according to any one of claims 12 to 23, characterized in that: After updating the first machine learning model according to the third communication data set, the method further includes: Send second indication information to the model reasoning functional entity; wherein the second indication information is used to indicate a second machine learning model, and the second machine learning model is obtained by updating the first machine learning model.
25. The method according to any one of claims 12 to 24, characterized in that: The model training functional entity is deployed on an access network device, and the second communication data set includes wireless communication data between the access network device and multiple terminals.
26. A model management method, characterized in that: Applicable to model management functional entities, including: Obtaining a first processing strategy for a first machine learning model, wherein the first machine learning model is used to manage wireless communication services, the first machine learning model is deployed in a model reasoning function entity, the first processing strategy includes a first loss threshold, and the first processing strategy can be used to perform a processing operation on suspicious data in a communication data set used to update the machine learning model, the suspicious data being data whose loss value is greater than the first loss threshold; The first processing strategy is sent to the model reasoning function entity.
27. The method according to claim 26, characterized in that The method further comprises: Obtaining a second processing strategy for the first machine learning model, wherein the second processing strategy can be used to perform a removal operation on erroneous data in a communication data set used to update the machine learning model, the second processing strategy includes a third loss threshold, and if the erroneous data is used to update the machine learning model, then the loss value of the updated machine learning model in processing the wireless communication data is greater than the third loss threshold; The second processing strategy is sent to a model training functional entity used to update the first machine learning model.
28. A communication device, characterized in that: The apparatus comprises: a module for executing the method as claimed in any one of claims 1-27.
29. A communication device, characterized in that: The communication device comprises: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device executes the method according to any one of claims 1-27.
30. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 27.
Citation Information
Patent Citations
Model management method and device
CN120075810A
Machine learning training data poisoning attack defense method
CN111914256A
Method, device and system for defending machine learning model from being attacked and medium
CN112613580A
Text backdoor defense method for cleaning data
CN113918717A
Model determination method and device
CN115712829A